patches.lists.linux.dev archive mirror
 help / color / mirror / Atom feed
* [PATCH 7.2 000/556] 7.2.5-rc1 review
@ 2026-09-09 13:34 Greg Kroah-Hartman
  2026-09-09 13:34 ` [PATCH 7.2 001/556] net: skbuff: dont skb_tx_error() the source skb in skb_zerocopy() Greg Kroah-Hartman
                   ` (568 more replies)
  0 siblings, 569 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:34 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, linux-kernel, torvalds, akpm, linux,
	shuah, patches, lkft-triage, pavel, jonathanh, f.fainelli,
	sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr

This is the start of the stable review cycle for the 7.2.5 release.
There are 556 patches in this series, all will be posted as a response
to this one.  If anyone has any issues with these being applied, please
let me know.

Responses should be made by Fri, 11 Sep 2026 13:40:31 +0000.
Anything received after that time might be too late.

The whole patch series can be found in one patch at:
	https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.2.5-rc1.gz
or in the git tree and branch at:
	git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.2.y
and the diffstat can be found below.

thanks,

greg k-h

-------------
Pseudo-Shortlog of commits:

Greg Kroah-Hartman <gregkh@linuxfoundation.org>
    Linux 7.2.5-rc1

Farhan Ali <alifm@linux.ibm.com>
    PCI: Allow per function PCI slots to fix slot reset on s390

Farhan Ali <alifm@linux.ibm.com>
    PCI: Introduce PCI_SLOT_PLACEHOLDER constant for slot_nr placeholder value

SJ Park <sj@kernel.org>
    mm/damon/vaddr: drop last same folio access check optimization

SJ Park <sj@kernel.org>
    mm/damon/paddr: drop last same folio access check reuse optimization

SJ Park <sj@kernel.org>
    mm/damon/ops-common: use nr_accesses moving sum for quota score

SJ Park <sj@kernel.org>
    mm/damon/core: avoid infinite kdamond_merge_regions() internal loop

Fan Wu <fanwu01@zju.edu.cn>
    power: supply: ab8500_fg: fix use-after-free on remove

Pan Chuang <panchuang@vivo.com>
    power: supply: ab8500_fg: Remove redundant dev_err()/dev_err_probe()

Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
    remoteproc: qcom: pas: Guard dtb metadata release with dtb_pas_id check

Chuck Lever <cel@kernel.org>
    rpcrdma: arm rn_done before publishing the notification

Jiri Olsa <jolsa@kernel.org>
    bpf: Disable preemption in bpf_get_stackid

Jiri Olsa <jolsa@kernel.org>
    bpf: Use stack id functions instead of __bpf_get_stackid

Jiri Olsa <jolsa@kernel.org>
    bpf: Factor stackid_new_bucket from __bpf_get_stackid

Jiri Olsa <jolsa@kernel.org>
    bpf: Factor stackid_fastpath function from __bpf_get_stackid

Jiri Olsa <jolsa@kernel.org>
    bpf: Factor stackid_init function from __bpf_get_stackid

Abdifatah Suruur <suruurism@gmail.com>
    ksmbd: fix use-after-free in oplock break notification

Mohamed Ahmed <mohamedahmedegypt2001@gmail.com>
    drm/nouveau/gsp: fix vblank interrupts on GB20x

Mohamed Ahmed <mohamedahmedegypt2001@gmail.com>
    drm/nouveau/disp: fix head state readback on GB20x

Mohamed Ahmed <mohamedahmedegypt2001@gmail.com>
    drm/nouveau/disp: fix HDMI GCP AVMute register offsets on GB20x

Mohamed Ahmed <mohamedahmedegypt2001@gmail.com>
    drm/nouveau/disp: fix HDMI vendor infoframes on GB20x

Mohamed Ahmed <mohamedahmedegypt2001@gmail.com>
    drm/nouveau/disp: route GSP-RM display MMIO through nvkm_disp_func hooks

Mohamed Ahmed <mohamedahmedegypt2001@gmail.com>
    drm/nouveau/disp: move the GSP HDMI GCP AVMute write to engine/disp

Mohamed Ahmed <mohamedahmedegypt2001@gmail.com>
    drm/nouveau/disp: move GSP head-timing ISR and vblank helpers to tu102.c

Zhenhao Wan <whi4ed0g@gmail.com>
    drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE

Zhenhao Wan <whi4ed0g@gmail.com>
    drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE

Zhenhao Wan <whi4ed0g@gmail.com>
    drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op

Faith Ekstrand <faith.ekstrand@collabora.com>
    drm/nouveau: Use write-combined maps for coherent

Marek Czernohous <marek@czernohous.de>
    drm/nouveau: unsubscribe the channel-kill event before the fence context

Mohamed Ahmed <mohamedahmedegypt2001@gmail.com>
    drm/nouveau/gsp: use per-version DP_CONFIG_STREAM params on r570 firmware

Zhenhao Wan <whi4ed0g@gmail.com>
    drm/nouveau/dmem: fix mismatched DMA unmap size for large folios

Zhenhao Wan <whi4ed0g@gmail.com>
    drm/nouveau/dmem: fix callocated underflow on large folio split

Matthew Brost <matthew.brost@intel.com>
    drm/pagemap: Fix folio allocation fallback and use-after-put

Shixiong Ou <oushixiong@kylinos.cn>
    drm/sysfb: ofdrm: Fix is_avivo() constant comparison bug

Shixiong Ou <oushixiong@kylinos.cn>
    drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation

Thomas Zimmermann <tzimmermann@suse.de>
    drm/sysfb: simpledrm: Improve stride validation

Thomas Zimmermann <tzimmermann@suse.de>
    drm/sysfb: simpledrm: Improve panel-size validation

Thomas Zimmermann <tzimmermann@suse.de>
    drm/sysfb: simpledrm: Improve framebuffer-size validation

Sunday Clement <Sunday.Clement@amd.com>
    drm/amdkfd: Reject zero-sized AQL queue allocations after size halving

Vladimir Marioukhine <Vladimir.Marioukhine@amd.com>
    drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore

Xiaogang Chen <xiaogang.chen@amd.com>
    drm/amdkfd: Fix the case that vm range is hole at svm_migrate_copy_to_vram

Mario Limonciello <mario.limonciello@amd.com>
    drm/amdkfd: fix scope of mqd_mgr dereference in pqm_debugfs_mqds

Xiaogang Chen <xiaogang.chen@amd.com>
    drm/amdkfd: Fix error path at svm_migrate_copy_to_ram

Priya Hosur <Priya.Hosur@amd.com>
    drm/amdkfd: Add TLB flush after MES queue eviction/suspension

Sunil Khatri <sunil.khatri@amd.com>
    drm/amdgpu: use AMDGPU_GPU_PAGE_SHIFT instead of PAGE_SHIFT

Sunil Khatri <sunil.khatri@amd.com>
    drm/amdgpu: update the fw version for gfx12 userqueues

Sunil Khatri <sunil.khatri@amd.com>
    drm/amdgpu: update the fw version for gfx11 userqueues

Kanala Ramalingeswara Reddy <Kanala.RamalingeswaraReddy@amd.com>
    drm/amdgpu: Skip accessing psp rum time db for APUs

Jesse Zhang <Jesse.Zhang@amd.com>
    drm/amdgpu: force complete the MES ring fences on reset

Jesse Zhang <Jesse.Zhang@amd.com>
    drm/amdgpu: force complete the KIQ ring fences on reset

Sunil Khatri <sunil.khatri@amd.com>
    drm/amdgpu: fix Idle BOs list in VM debugfs status info

Sunil Khatri <sunil.khatri@amd.com>
    drm/amdgpu: fix byte/dword unit mismatch in coredump IB dump

Guangshuo Li <lgs201920130244@gmail.com>
    drm/amdgpu: fix autosuspend cleanup during removal

Yang Wang <kevinyang.wang@amd.com>
    drm/amdgpu: Disable runtime PM for externally attached dGPUs

Xiang Liu <xiang.liu@amd.com>
    drm/amdgpu: clamp the isolation index for rings outside a partition

Pierre-Eric Pelloux-Prayer <pierre-eric.pelloux-prayer@amd.com>
    drm/amdgpu: delay ttm buffer func enablement on xgmi

Yang Wang <kevinyang.wang@amd.com>
    drm/amdgpu: check thunderbolt before switcheroo registration

Matthew Brost <matthew.brost@intel.com>
    drm/ttm: Drop tt->restore after successful restore

Thadeu Lima de Souza Cascardo <cascardo@igalia.com>
    drm: Fix drm_crtc_commit leak if signaled when PAGE_FLIP_EVENT is used

Kavan Smith <kavansmith82@gmail.com>
    drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value

Tao Yu <tao1.yu@intel.com>
    drm/gud: validate TV mode names before creating enum property

Deepanshu Kartikey <kartikey406@gmail.com>
    drm/gud: NUL-terminate TV mode names read from the device

David (Ming Qiang) Wu <David.Wu3@amd.com>
    drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check

Alex Deucher <alexander.deucher@amd.com>
    drm/amdgpu/gfx8: only apply compute quantums to KCQs

Roman Li <Roman.Li@amd.com>
    drm/amd/display: Set gpuvm min page size to 4K on dcn35/36

Austin Zheng <Austin.Zheng@amd.com>
    drm/amd/display: Remove const Qualifier From Non-Pointer Fields

Harry Wentland <harry.wentland@amd.com>
    drm/amd/display: validate plane degamma LUT size for private color prop

Timur Kristóf <timur.kristof@gmail.com>
    drm/amd/display: Fix HPD consideration for VGA/LVDS connectors on DCE

Linkai Gong <gonglinkai@kylinos.cn>
    drm/amd/display: fix dc_lock leak on GPU reset error paths

Harry Wentland <harry.wentland@amd.com>
    drm/amd/display: avoid divide-by-zero in __is_lut_linear()

Thomas Zimmermann <tzimmermann@suse.de>
    drm/hibmc: Use drm_atomic_helper_check_plane_state()

Thomas Zimmermann <tzimmermann@suse.de>
    drm/hibmc: Fix list of formats on the primary plane

Lyude Paul <lyude@redhat.com>
    drm/nouveau/disp/r535: Add scanline position support + head state support

Amit Barzilai <amit.barzilai22@gmail.com>
    drm/ssd130x: fix column and row end address in partial updates in ssd133x

Wentao Liang <vulab@iscas.ac.cn>
    drm/sun4i: fix refcount leak in sun4i_backend_init_sat()

Amit Barzilai <amit.barzilai22@gmail.com>
    drm/ssd130x: fix column and row end address in partial updates for ssd132x

Deepanshu Kartikey <kartikey406@gmail.com>
    drm/i915: Guard against NULL driver_data in i915_pci_probe()

Nemesa Garg <nemesa.garg@intel.com>
    drm/i915/display: Clear SEL_FETCH_PLANE_CTL on plane disable

Danilo Krummrich <dakr@kernel.org>
    drm: fix race between partial drm_dev_register() failure and ioctl

Johan Hovold <johan@kernel.org>
    drm/panel-edp: fix i2c adapter leak on probe failure

Johan Hovold <johan@kernel.org>
    drm/bridge: dw-hdmi: fix i2c adapter leak on probe failure

Osama Abdelkader <osama.abdelkader@gmail.com>
    drm/panthor: fix firmware control interface bounds checks

Osama Abdelkader <osama.abdelkader@gmail.com>
    drm/panthor: harden firmware build-info bounds checks

Matthew Auld <matthew.auld@intel.com>
    drm/xe/vram: report FLAT_CCS base misalignment

Bob Zhou <bobzhou2@amd.com>
    drm/amdgpu: avoid force-completing uninitialized UVD rings

Thomas Hellström <thomas.hellstrom@linux.intel.com>
    drm/amdgpu: Fix init ordering in amdgpu_vram_mgr_init()

Chao Yu <chao@kernel.org>
    f2fs: fix to zero post-EOF data when extending file size

Chao Yu <chao@kernel.org>
    f2fs: fix to pass folio->index to f2fs_sanity_check_node_footer()

Chao Yu <chao@kernel.org>
    f2fs: fix to reclaim space in f2fs_allocate_pinning_section()

Chen Changcheng <chenchangcheng@kylinos.cn>
    f2fs: fix valid block count leak on data block allocation failure

Wenjie Qi <qwjhust@gmail.com>
    f2fs: protect critical_task_priority updates with s_umount

Chao Yu <chao@kernel.org>
    f2fs: fix to clear dirty flag on folio in error path

Chao Yu <chao@kernel.org>
    f2fs: fix to off-by-one issue in f2fs_zero_post_eof_page()

Chao Yu <chao@kernel.org>
    f2fs: fix to return -EFSCORRUPTED in f2fs_get_node_info() correctly

Zhan Xusheng <zhanxusheng1024@gmail.com>
    f2fs: fix i_size when pinned fallocate partially fails

Chao Yu <chao@kernel.org>
    f2fs: fix to avoid potential deadloop in f2fs_fsync_node_pages()

Daeho Jeong <daehojeong@google.com>
    f2fs: fix to migrate all curseg types during free_segment_range

Wenjie Qi <qwjhust@gmail.com>
    f2fs: avoid NULL checkpoint thread access in sysfs

Zhaoyang Huang <zhaoyang.huang@unisoc.com>
    f2fs: fix folio_nr_pages() race after put in large folio invalidate

Guanghui Yang <3497809730@qq.com>
    f2fs: fix dentry folio leak in find_in_level

Chao Yu <chao@kernel.org>
    f2fs: embed f2fs_gc_kthread in f2fs_sb_info

Chao Yu <chao@kernel.org>
    f2fs: fix to avoid potential section-unaligned pinfile

Zhan Xusheng <zhanxusheng1024@gmail.com>
    f2fs: don't drop the top folio order in the f2fs_iostat tracepoint

Wenjie Qi <qwjhust@gmail.com>
    f2fs: limit recovery filename logging to stored length

Wenjie Qi <qwjhust@gmail.com>
    f2fs: return writeback error from collapse range

Zhan Xusheng <zhanxusheng1024@gmail.com>
    f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set()

Joanne Chang <joannechien@google.com>
    f2fs: dirty directory inodes on mtime/ctime update

Wenjie Qi <qwjhust@gmail.com>
    f2fs: validate MOVE_RANGE destination size

Chao Yu <chao@kernel.org>
    f2fs: fix to avoid move_range and defragment on device_alias file

Wenjie Qi <qwjhust@gmail.com>
    f2fs: only redirty pinned folios in redirty_blocks

Hao-Qun Huang <alvinhuang0603@gmail.com>
    f2fs: reject overlapping move range after len expansion

Wenjie Qi <qwjhust@gmail.com>
    f2fs: return symlink writeback errors

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Skip NVMe LS reject IOCB when FW not started

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Zero-init bsg stack buffers to avoid info leak

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Use coherent DMA buffer for D_Port diagnostics

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Hold vport_slock for host map update in report ID acquisition

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Drop vport reference under lock in report ID acquisition

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Fix NVMe abort reference leak on repeated abort

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Avoid req_q_map double-read in qla2x00_error_entry()

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Avoid double completion in async IOCB timeout

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Quiesce response IRQ before freeing request queue

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Fix response queue over-consumption in __qla_consume_iocb()

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Don't query firmware state while chip is down

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Fix FCE trace enable parsing in debugfs

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state()

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Fix cs84xx use-after-free on host teardown

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Serialize flash version read in reset handler

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions()

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Zero dport diagnostics buffer to avoid info leak

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Check entry_status in qla24xx_modify_vp_config()

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Initialize NVMe abort_work once at submission

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition()

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Fix BSG job leak on validate flash image error path

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Fix Name Server logout detection on FWI2 adapters

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: edif: Fix NULL pointer deref in RX SA delete check

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Bound i2c->length in I2C bsg handlers

Nilesh Javali <njavali@marvell.com>
    scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers

Jackson Lee <jackson.lee@chipsnmedia.com>
    media: chips-media: wave5: Resume device before setting EOS flag

Jackson Lee <jackson.lee@chipsnmedia.com>
    media: chips-media: wave5: Fix pipeline stall when queuing fails

Jackson Lee <jackson.lee@chipsnmedia.com>
    media: chips-media: wave5: Defer job_finish() only when a DEC_PIC was queued

Jackson Lee <jackson.lee@chipsnmedia.com>
    media: chips-media: wave5: Add timeout while stop_streaming

Jackson Lee <jackson.lee@chipsnmedia.com>
    media: chips-media: wave5: avoid skipping device_run while VPU has work

Jackson Lee <jackson.lee@chipsnmedia.com>
    media: chips-media: wave5: Set inst->std during default format initialization

Jackson Lee <jackson.lee@chipsnmedia.com>
    media: chips-media: wave5: Guard bit depth check with initial_info_obtained

Wangao Wang <wangao.wang@oss.qualcomm.com>
    media: qcom: iris: fix missing hfi_id in gen1 GOP_SIZE cap

Hungyu Lin <dennylin0707@gmail.com>
    media: qcom: iris: use disable_irq() during power-off

Dikshita Agarwal <dikshita.agarwal@oss.qualcomm.com>
    media: qcom: iris: fix state-change debug log printing stale value

Ruoyu Wang <ruoyuw560@gmail.com>
    media: zoran: Avoid freeing a registered video_device twice

Arash Golgol <arash.golgol@gmail.com>
    media: vimc: fix pixel format lookup in enum_framesizes

Uday Khare <udaykhare77@gmail.com>
    media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure

Mohammed EL Kadiri <med08elkadiri@gmail.com>
    media: venus: fix payload size calculation in parse_raw_formats()

Mohammed EL Kadiri <med08elkadiri@gmail.com>
    media: venus: fix payload size returned by parse_caps() and parse_alloc_mode()

Biren Pandya <birenpandya@gmail.com>
    media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link

Ming Qian <ming.qian@oss.nxp.com>
    media: v4l2-ctrls: Allow unknown HDR10 white point and luminance

Michael Bommarito <michael.bommarito@gmail.com>
    media: v4l2-ctrls: validate HEVC EXT SPS RPS counts

Xu Rao <raoxu@uniontech.com>
    media: v4l2-async: avoid deleting unlinked ASC entry on link error

Fan Wu <fanwu01@zju.edu.cn>
    media: ti: vpe: quiesce overflow recovery before freeing streams

Ilya Krutskih <devsec@tpz.ru>
    media: tda18250: fix possible integer overflow

Guangshuo Li <lgs201920130244@gmail.com>
    media: saa7164: fix cleanup on resource allocation failure

Lei Huang <huanglei@kylinos.cn>
    media: s2255: check firmware size before reading trailing marker

HyeongJun An <sammiee5311@gmail.com>
    media: s2255: bound JPEG frame size before copying into the buffer

Tommaso Merciai <tommaso.merciai.xr@bp.renesas.com>
    media: rzg2l-cru: Align bytesperline to hardware DMA stride requirement

Valery Borovsky <vebohr@gmail.com>
    media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure

Valery Borovsky <vebohr@gmail.com>
    media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak

Michael Bommarito <michael.bommarito@gmail.com>
    media: rkvdec: hevc: guard INTER_REF_PIC_SET_PRED index underflow

Michael Bommarito <michael.bommarito@gmail.com>
    media: rkvdec: hevc: tighten EXT SPS RPS control dimensions

Narasimharao Vadlamudi <ahmisaranrao@gmail.com>
    media: rkvdec: Propagate platform_get_irq() errors

Sven Püschel <s.pueschel@pengutronix.de>
    media: rockchip: rga: don't change RGB quantization

Myeonghun Pak <mhun512@gmail.com>
    media: rc: sunxi-cir: Unregister rc device on probe failure

David Carlier <devnexen@gmail.com>
    media: mali-c55: Fix scaler factor overflow for large crop sizes

David Carlier <devnexen@gmail.com>
    media: mali-c55: Fix AEXP IHIST disable bit shift

David Carlier <devnexen@gmail.com>
    media: mali-c55: Fix clock leak on reset deassert failure

David Carlier <devnexen@gmail.com>
    media: mali-c55: fix dropped last AEC histogram zone weight

Guoniu Zhou <guoniu.zhou@oss.nxp.com>
    media: nxp: imx8-isi: Use BIT_ULL() for 64-bit stream masks

Guoniu Zhou <guoniu.zhou@oss.nxp.com>
    media: nxp: imx8-isi: Correct color map between V4L2 and ISI

Guoniu Zhou <guoniu.zhou@oss.nxp.com>
    media: nxp: imx8-isi: Fix stream ID validation bypass in crossbar routing

Johan Hovold <johan@kernel.org>
    media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup

Guangshuo Li <lgs201920130244@gmail.com>
    media: platform: mtk-mdp3: Fix SCP device refcounting

Christian Hewitt <christianshewitt@gmail.com>
    media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common

Bryan O'Donoghue <bryan.odonoghue@linaro.org>
    media: iris: Enumerate cap->bus_info to differentiate between encoder and decoder

José María Martín <jmmartinf@hotmail.com>
    media: ipu-bridge: check all DMI entries when overriding sensor rotation

Cong Nguyen <congnt264@gmail.com>
    media: intel/ipu6: fix async notifier cleanup leak on parse error

Dave Stevenson <dave.stevenson@raspberrypi.com>
    media: imx355: Avoid calling imx355_power_off twice in error path

Benjamin Mugnier <benjamin.mugnier@foss.st.com>
    media: i2c: vd55g1: Fix media bus code initialization

Benjamin Mugnier <benjamin.mugnier@foss.st.com>
    media: i2c: vd55g1: Fix manual digital gain on color variant

Richard Leitner <richard.leitner@linux.dev>
    media: i2c: ov9282: restore flash duration calculation

Biren Pandya <birenpandya@gmail.com>
    media: i2c: ov7740: fix use-after-destroy in remove

Biren Pandya <birenpandya@gmail.com>
    media: i2c: ov02a10: fix endpoint parsing use-after-free

Narasimharao Vadlamudi <ahmisaranrao@gmail.com>
    media: i2c: imx415: Return test pattern write errors

Narasimharao Vadlamudi <ahmisaranrao@gmail.com>
    media: i2c: imx415: Release runtime PM reference on VBLANK error

Martin Hecht <mhecht73@gmail.com>
    media: i2c: alvium: Fix: Correct name of register in alvium_set_ctrl_auto_exposure

Shuangpeng Bai <shuangpeng.kernel@gmail.com>
    media: go7007: defer the ALSA v4l2 put until card release

Jiangong.Han <jiangong.han@windriver.com>
    media: em28xx: fix use-after-free of dev_next->devlist on disconnect

Diego Fernando Mancera Gomez <diegomancera.dev@gmail.com>
    media: em28xx: defer audio-only extension registration

Guoniu Zhou <guoniu.zhou@oss.nxp.com>
    media: dt-bindings: nxp,imx8-isi: Drop fsl,blk-ctrl requirement for i.MX8ULP

Fan Wu <fanwu01@zju.edu.cn>
    media: cx23885: cancel NetUP CI work before teardown

Bryam Vargas <hexlabsecurity@proton.me>
    media: cx231xx: reject geometry changes while the VBI queue is busy

Ruoyu Wang <ruoyuw560@gmail.com>
    media: cobalt: Avoid freeing ALSA private data twice

Dawei Feng <dawei.feng@seu.edu.cn>
    media: cedrus: fix memory leak in cedrus_init_ctrls()

Ruoyu Wang <ruoyuw560@gmail.com>
    media: cec: Serialize exclusive follower delivery

Yi Ding <yi.s.ding@gmail.com>
    media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid debugfs clash

Hans Verkuil <hverkuil+cisco@kernel.org>
    media: cec: extron-da-hd-4k-plus: add sanity check

Biren Pandya <birenpandya@gmail.com>
    media: cec: disable delayed work before freeing an interrupted transmit

Jonas Karlman <jonas@kwiboo.se>
    media: cec: core: Fix kmemleak due to missed rc_free_device() call

Eugen Hristev <ehristev@kernel.org>
    media: bcm2835-unicam: Fix pipeline wrong validation for unpacked formats

Ming Qian <ming.qian@oss.nxp.com>
    media: amphion: Remove obsolete frame_count check in venc_start_session

Valery Borovsky <vebohr@gmail.com>
    media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref

Danilo Krummrich <dakr@kernel.org>
    rust: drm: ioctl: fix unbounded lifetimes in ioctl handler arguments

Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
    LoongArch: Avoid preempt count underflow without probe

Wentao Guan <guanwentao@uniontech.com>
    LoongArch: Do not save/restore percpu base register in rethook trampoline

Nathan Chancellor <nathan@kernel.org>
    LoongArch: Do not select HAVE_RUST when KASAN is enabled

Bibo Mao <maobibo@loongson.cn>
    LoongArch: Fix acpi_package_ids[] array overflow

Tiezhu Yang <yangtiezhu@loongson.cn>
    LoongArch: BPF: Fix off-by-one error for insn_is_cast_user()

Tiezhu Yang <yangtiezhu@loongson.cn>
    LoongArch: BPF: Move arena register slot below TCC context

Tiezhu Yang <yangtiezhu@loongson.cn>
    LoongArch: Expand module virtual address space to 2GB

Tiezhu Yang <yangtiezhu@loongson.cn>
    LoongArch: BPF: Refactor jump offset calculation in tail call

Tiezhu Yang <yangtiezhu@loongson.cn>
    LoongArch: BPF: Optimize redundant TCC loads in epilogue

Han Gao <gaohan@iscas.ac.cn>
    LoongArch: Add DIRECT_MAP_PHYSMEM_END definition

Zeng Chi <zengchi@kylinos.cn>
    LoongArch: KVM: Validate MSI data before routing it to EIOINTC

Zeng Chi <zengchi@kylinos.cn>
    LoongArch: KVM: Preserve memslot arch flags on KVM_MR_FLAGS_ONLY

Chaithanya Lagisetty <nagachaithanya9911@gmail.com>
    LoongArch: KVM: Free init resources if kvm_init() fails

Tao Cui <cuitao@kylinos.cn>
    LoongArch: KVM: Fix TOCTOU race on pv_features

Chaithanya Lagisetty <nagachaithanya9911@gmail.com>
    LoongArch: KVM: Fix resource leak in kvm_loongarch_env_init() error path

Chaithanya Lagisetty <nagachaithanya9911@gmail.com>
    LoongArch: KVM: Add unregister helpers for the KVM interrupt devices

Zeng Chi <zengchi@kylinos.cn>
    LoongArch: KVM: Fix PC double advance in kernel MMIO read fast path

Bibo Mao <maobibo@loongson.cn>
    LoongArch: KVM: Fix uninitialized stack variable issue with dmsintc

Bibo Mao <maobibo@loongson.cn>
    LoongArch: KVM: Set vcpu->cpu before IN_GUEST_MODE is set

Marc Zyngier <maz@kernel.org>
    KVM: arm64: Correctly cap TLBI Range to the architural limit

Fuad Tabba <fuad.tabba@linux.dev>
    KVM: arm64: vgic-its: Don't dereference a NULL collection on ITT save

Fuad Tabba <fuad.tabba@linux.dev>
    KVM: arm64: vgic: Reset in_kernel on private IRQ allocation failure

Kajetan Puchalski <kajetan.puchalski@arm.com>
    KVM: arm64: vgic: Fix detection of MI on no pending LR

Qihang <q.h.hack.winter@gmail.com>
    KVM: arm64: vgic-v3: take an LPI reference in vgic_v3_save_pending_tables

Marc Zyngier <maz@kernel.org>
    KVM: arm64: Sign-extend VA for range-based TLBI invalidation

Marc Zyngier <maz@kernel.org>
    KVM: arm64: Remove VM-wide VNCR mapping counter

Marc Zyngier <maz@kernel.org>
    KVM: arm64: Make VNCR invalidation participate in MMU invalidation retry

Marc Zyngier <maz@kernel.org>
    KVM: arm64: Handle VNCR TLB invalidation race with vcpu_put() VNCR unmapping

Marc Zyngier <maz@kernel.org>
    KVM: arm64: Correctly handle end of VA space TLBI invalidation

Marc Zyngier <maz@kernel.org>
    KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation

Marc Zyngier <maz@kernel.org>
    KVM: arm64: Consider SCTLR_EL2.M when mapping the L1 VNCR page

Christian Borntraeger <borntraeger@linux.ibm.com>
    KVM: s390: Restore sigset on error path

Christian Borntraeger <borntraeger@linux.ibm.com>
    KVM: s390: pv: Fix rc/rrc offset for PVM_DUMP

Christian Borntraeger <borntraeger@linux.ibm.com>
    KVM: s390: keyop: use mmu_lock to read gmap->asce

Christian Borntraeger <borntraeger@linux.ibm.com>
    KVM: s390: Fix memory corruption by not reinjecting CK machine checks

Christian Borntraeger <borntraeger@linux.ibm.com>
    KVM: s390: Zero initialize irq in reinject_machine_check

Christian Borntraeger <borntraeger@linux.ibm.com>
    KVM: s390: Zero initialize data structures for inject_pfault_token

Christian Borntraeger <borntraeger@linux.ibm.com>
    KVM: s390: Take srcu when importing watchpoint data

Christian Borntraeger <borntraeger@linux.ibm.com>
    KVM: s390: Free guest debug data on vcpu destroy

Christian Borntraeger <borntraeger@linux.ibm.com>
    KVM: s390: Fix old_data leak in guest debug error path

Christian Borntraeger <borntraeger@linux.ibm.com>
    KVM: s390: Fix memory leak in guest debug handling

Christian Borntraeger <borntraeger@linux.ibm.com>
    KVM: s390: Fix length check __import_wp_info()

Yosry Ahmed <yosry@kernel.org>
    KVM: x86: Move enabling EFER.SVME and EFER.LMSLE to generic EFER setup

Sean Christopherson <seanjc@google.com>
    KVM: x86: Ensure runtime reads of disabled_quirks are resolved once

Sean Christopherson <seanjc@google.com>
    KVM: x86: Serialize writes to disabled_quirks using kvm->lock

Carlos López <clopez@suse.de>
    KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock

Phil Rosenthal <phil@phil.gs>
    KVM: x86/mmu: Consume the locked rmap value in the lockless rmap walk

Sean Christopherson <seanjc@google.com>
    KVM: x86/mmu: Use CMPXCHG when clearing Accessed bit in TDP MMU

Yosry Ahmed <yosry@kernel.org>
    KVM: nVM: Ensure INVVPID is emulated on the correct physical CPU

Yosry Ahmed <yosry@kernel.org>
    KVM: nVMX: Service local TLB flushes on failed nested VM-Enter

Sean Christopherson <seanjc@google.com>
    KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit

Sean Christopherson <seanjc@google.com>
    KVM: nVMX: Decouple INVVPID operand checks from flushing of vpid02

Yosry Ahmed <yosry@kernel.org>
    KVM: nVMX: Always flush vpid02 on first use

Amit Machhiwal <amachhiw@linux.ibm.com>
    KVM: PPC: Book3S HV: Validate arch_compat against host compatibility mode

Nikhil Gautam <nikhilgtr@gmail.com>
    iio: light: opt4001: Fix reversed GENMASK() arguments in fault count mask

Nikhil Gautam <nikhilgtr@gmail.com>
    iio: light: opt4001: Reject integration times with a non-zero seconds part

Nikhil Gautam <nikhilgtr@gmail.com>
    iio: light: opt4001: Fix incompatible pointer type passed to div_u64_rem()

Nikhil Gautam <nikhilgtr@gmail.com>
    iio: light: opt4001: Fix power down clearing bits of the wrong register

Vidhu Sarwal <vidhu.linux@gmail.com>
    iio: light: opt4060: Fix incorrect register name in threshold read error message

Vidhu Sarwal <vidhu.linux@gmail.com>
    iio: light: opt4060: Reject integration times with a non-zero seconds part

Paul Geurts <paul.geurts@prodrive-technologies.com>
    iio: ti-ads7138: Disable STATS_EN bit while reading conversion results

Sanjay Chitroda <sanjayembeddedse@gmail.com>
    iio: temperature: hid-sensor-temperature: switch to non-devm iio_device_register()

Cong Nguyen <congnt264@gmail.com>
    iio: srf04: fix pm_runtime handling on probe error path

Can Peng <pengcan@kylinos.cn>
    iio: pressure: mpl115: Fix runtime PM cleanup

Rupesh Majhi <zoone.rupert@gmail.com>
    iio: pressure: dps310: fix NULL pointer dereference on ACPI probe

Vidhu Sarwal <vidhu.linux@gmail.com>
    iio: light: ltrf216a: fix runtime PM reference leak in error path

Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
    iio: light: gp2ap002: Disable regulators on resume failure

Giorgi Tchankvetadze <giorgi@tchankvetadze.com>
    iio: light: cm32181: return zero after writing calibscale

Moksh Panicker <mokshpanicker.7@gmail.com>
    iio: light: apds9306: fix PM reference leak in apds9306_read_data()

Francesco Lavra <flavra@baylibre.com>
    iio: imu: st_lsm6dsx: Update enable mask when using sensor fusion

Cong Nguyen <congnt264@gmail.com>
    iio: gyro: mpu3050: fix sign of raw angular velocity readings

Joshua Crofts <joshua.crofts1@gmail.com>
    iio: dac: mcp47feb02: add missing 'select REGMAP_I2C' to Kconfig

Erick Henrique <erick.henrique.rodrigues@usp.br>
    iio: dac: m62332: Fix regulator reference count imbalance

Can Peng <pengcan@kylinos.cn>
    iio: dac: ad5446: fix OF module device table

Babanpreet Singh <bbnpreetsingh@gmail.com>
    iio: dac: ad3552r-hs: fix scnprintf() buffer bound in data source show

Linmao Li <lilinmao@kylinos.cn>
    iio: chemical: sgp30: Handle IAQ thread creation failure

Fan Wu <fanwu01@zju.edu.cn>
    iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF

Moksh Panicker <mokshpanicker.7@gmail.com>
    iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable

Lars-Peter Clausen <lars@metafoo.de>
    iio: buffer: Tie IIO dma fence lock lifetime to the fence

Lars-Peter Clausen <lars@metafoo.de>
    iio: buffer: Make IIO DMA fence release RCU-safe

Lars-Peter Clausen <lars@metafoo.de>
    iio: buffer: Fix potential use-after-free in anonymous buffer release

Cong Nguyen <congnt264@gmail.com>
    iio: adc: pac1921: fix wrong channel used in trigger handler read

Joshua Crofts <joshua.crofts1@gmail.com>
    iio: adc: max34408: add missing 'select REGMAP_I2C' to Kconfig

Joshua Crofts <joshua.crofts1@gmail.com>
    iio: adc: max14001: add missing 'select REGMAP' to Kconfig

Antoniu Miclaus <antoniu.miclaus@analog.com>
    iio: adc: adi-axi-adc: add data size support for AD408X backend

Antoniu Miclaus <antoniu.miclaus@analog.com>
    iio: adc: ad4080: configure backend data size

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: tas2783-sdw: sort the register default table

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: tas2783-sdw: drop duplicate reg_default entry

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: tas2780: sort the register default table

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: tas2764: sort the register default table

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: tas2552: sort the register default table

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: sti-sas: sort the register default table

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: sgtl5000: sort the register default table

WenTao Liang <vulab@iscas.ac.cn>
    ASoC: samsung: aries_audio_probe: double of_node_put due to direct assignment without of_node_get

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: rt721-sdca-sdw: sort the register default table

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: rt715: sort the register default table

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: rt715-sdca: sort the register default tables

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: rt715-sdca: drop duplicate reg_default entries

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: rt712-sdca-sdw: sort the register default table

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: rt712-sdca-dmic: sort the register default table

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: rt711: sort the register default table

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: rt711-sdca: sort the register default tables

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: rt700: sort the register default table

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: rt700: drop duplicate reg_default entry

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: rt298: sort the register default table

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: rt286: sort the register default table

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: rt274: sort the register default table

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: rt1318: sort the register default table

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: rt1318-sdw: sort the register default table

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: rt1316-sdw: sort the register default table

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: rt1017-sdca-sdw: sort the register default table

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: pm4125-sdw: sort the register default table

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: pcm512x: sort the register default table

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: ml26124: sort the register default table

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: max9860: sort the register default table

Binbin Zhou <zhoubinbin@loongson.cn>
    ASoC: loongson: Fix error handling in ACPI property parsing

Haoxiang Li <haoxiang_li2024@163.com>
    AsoC: intel: sst: fix PCI device reference leak on probe failure

Haoxiang Li <haoxiang_li2024@163.com>
    ASoC: hdac_hda: Fix hlink refcount leak on component registration failure

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: fsl_easrc: sort the register default table

wangdicheng <wangdicheng@kylinos.cn>
    ASoC: fsl_easrc: Use div64_u64 for 64-by-64 division

Haoxiang Li <haoxiang_li2024@163.com>
    ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: cx2072x: sort the register default table

Runyu Xiao <runyu.xiao@seu.edu.cn>
    ASoC: cs35l34: drain threaded IRQ before runtime suspend

Runyu Xiao <runyu.xiao@seu.edu.cn>
    ASoC: cs35l33: drain threaded IRQ before runtime suspend

Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
    ASoC: adau1761: sort the register default table

Linkai Gong <gonglinkai@kylinos.cn>
    i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure

Stephan Gerhold <stephan.gerhold@linaro.org>
    clk: qcom: gcc-mdm9607: Drop incorrect BIMC PLL and related clocks

Stephan Gerhold <stephan.gerhold@linaro.org>
    clk: qcom: gcc-mdm9607: Fix halt_reg for gcc_apss_axi_clk

Stephan Gerhold <stephan@gerhold.net>
    clk: qcom: gcc-mdm9607: Fix enable_reg for gcc_blsp1_sleep_clk

Stephan Gerhold <stephan@gerhold.net>
    clk: qcom: gcc-mdm9607: Drop incorrect system_noc_bfdcd_clk_src

Stephan Gerhold <stephan@gerhold.net>
    clk: qcom: gcc-mdm9607: Drop incorrect apss_tcu_clk_src

Heiko Stuebner <heiko.stuebner@cherry.de>
    clk: rockchip: rk3588: Don't change PLL rates when setting dclk_vop2_src

Stephan Gerhold <stephan.gerhold@linaro.org>
    clk: qcom: gcc-msm8939: Fix enable_reg for gcc_blsp1_sleep_clk

Stephan Gerhold <stephan.gerhold@linaro.org>
    clk: qcom: gcc-msm8916: Fix enable_reg for gcc_blsp1_sleep_clk

Pedro Kopper <pedro.kopper@microchip.com>
    clk: microchip: mpfs: fix regmap_update_bits() mask/val order

Martin Blumenstingl <martin.blumenstingl@googlemail.com>
    clk: meson: align gxbb_32k_clk_sel number of parents with actual count

Akari Tsuyukusa <akkun11.open@gmail.com>
    clk: mediatek: mt8196: Select REGMAP_MMIO for vlpckgen

Pavel Löbl <pavel@loebl.cz>
    clk: clocking-wizard: fix integer overflow in rate calculation

Sven Eckelmann <sven@narfation.org>
    batman-adv: bla: prevent CRC corruptions after claim flush

Sven Eckelmann <sven@narfation.org>
    batman-adv: bla: fix freeing of claims on meshif deletion

Sven Eckelmann <sven@narfation.org>
    batman-adv: dat: avoid unaligned fault in IP extraction

Sven Eckelmann <sven@narfation.org>
    batman-adv: mcast: linearize skbuff for packet generation

Sven Eckelmann <sven@narfation.org>
    batman-adv: mcast: ensure unshared skb for multicast packets

Sven Eckelmann <sven@narfation.org>
    batman-adv: fix TX priority extraction for BATADV_FORW_MCAST

Zhiling Zou <zhilinz@nebusec.ai>
    batman-adv: fix stale receive device on merged fragments

Pengpeng Hou <pengpeng@iscas.ac.cn>
    mtd: rawnand: validate ONFI extended parameter page sections

James Hilliard <james.hilliard1@gmail.com>
    mtd: rawnand: sunxi: fix H6/H616 controller timings

James Hilliard <james.hilliard1@gmail.com>
    mtd: rawnand: sunxi: describe tADL and tWHR delays

James Hilliard <james.hilliard1@gmail.com>
    mtd: rawnand: sunxi: group controller delay tables

Miquel Raynal (DAVE) <miquel.raynal@bootlin.com>
    mtd: rawnand: pl353: Make sure we use the monolithic helpers for raw accesses

Pengpeng Hou <pengpeng@iscas.ac.cn>
    mtd: nand: realtek-ecc: add missing MODULE_DEVICE_TABLE()

Xu Rao <raoxu@uniontech.com>
    mtd: mtdoops: free page bitmap when the backing MTD is removed

Pengpeng Hou <pengpeng@iscas.ac.cn>
    mtd: afs: validate v2 image info bounds

Anthony Krowiak <akrowiak@linux.ibm.com>
    s390/vfio-ap: Fix required lock not held during update of ap_matrix_mdev object

Anthony Krowiak <akrowiak@linux.ibm.com>
    s390/vfio-ap: fix potential use of uninitialized apm_filtered bitmap

Anthony Krowiak <akrowiak@linux.ibm.com>
    s390/vfio-ap: Fix NULL deref in status_show() during queue probe

Anthony Krowiak <akrowiak@linux.ibm.com>
    s390/vfio-ap: Fix missing lock required to access list of ap_matrix_mdev objects

Anthony Krowiak <akrowiak@linux.ibm.com>
    s390/vfio-ap: Fix hot-unplug skipped when last AP adapter or domain removed

Anthony Krowiak <akrowiak@linux.ibm.com>
    s390/vfio-ap: Fix dereference matrix_mdev->kvm without checking for NULL

Anthony Krowiak <akrowiak@linux.ibm.com>
    s390/vfio-ap: Fix control domain removal in vfio_ap_mdev_cfg_remove

Anthony Krowiak <akrowiak@linux.ibm.com>
    s390/vfio-ap: Fix stale do_remove flag across iterations in vfio_ap_mdev_cfg_remove

Anthony Krowiak <akrowiak@linux.ibm.com>
    s390/vfio-ap: fix stale pqap_hook pointer on error in vfio_ap_mdev_set_kvm()

Sourabh Jain <sourabhjain@linux.ibm.com>
    powerpc/crash: stop watchdogs before booting kdump kernel

Sourabh Jain <sourabhjain@linux.ibm.com>
    powerpc/pseries: Move H_WATCHDOG definitions to a common header

Sourabh Jain <sourabhjain@linux.ibm.com>
    powerpc/pseries: Handle and log pseries-wdt registration failures

Muchun Song <muchun.song@linux.dev>
    powerpc/mm: fix wrong addr_pfn tracking in compound vmemmap population

Jinjie Ruan <ruanjinjie@huawei.com>
    powerpc/kexec_file: Prevent kexec range truncation

Jinjie Ruan <ruanjinjie@huawei.com>
    powerpc/kexec_file: Fix null-ptr-def in extra size calculation

Helge Deller <deller@gmx.de>
    parisc: Fix alignment of asm statements in head.S

Pei Xiao <xiaopei01@kylinos.cn>
    parisc: eisa: Fix infinite loop when parsing invalid IRQ value

Bryam Vargas <hexlabsecurity@proton.me>
    nvdimm/btt: reject an arena whose nfree is below the lane count

Narek Jilavyan <njilav@gmail.com>
    mm/hugetlb_cgroup: call page_counter_set_max() outside VM_BUG_ON()

Longlong Xia <xialonglong@kylinos.cn>
    mm/hugetlb: keep max_huge_pages when dissolving surplus folios

Sourav Panda <souravpanda@google.com>
    mm/hugetlb_cma: fix null nodemask dereference in hugetlb_cma_alloc_frozen_folio

Wupeng Ma <mawupeng1@huawei.com>
    mm/hugetlb: fix missing migratable flag on same-node hugetlb migration

Hui Su <sh_def@163.com>
    mm/migrate_device: avoid out-of-bounds writes for compound folios

Baolin Wang <baolin.wang@linux.alibaba.com>
    mm: fix incorrect vm_flags usage when checking allowable orders for tmpfs

Abel Vesa <abel.vesa@oss.qualcomm.com>
    Revert "pmdomain: qcom: rpmhpd: Add missing MXC and MMCX power domains for Eliza"

Eric Dumazet <edumazet@google.com>
    Revert "once: don't use a work queue to reset sleepable static key"

caina <caina@uniontech.com>
    Revert "irqchip/mbigen: Fix mbigen node address layout"

Christian Marangi <ansuelsmth@gmail.com>
    pmdomain: airoha: fix unselectable AIROHA_CPU_PM_DOMAIN kconfig

Shivam Kumar <kumar.shivam43666@gmail.com>
    nvmet-tcp: reject unsolicited H2CData PDUs

Shivam Kumar <kumar.shivam43666@gmail.com>
    nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU

Kazuki Hanai <hnkz.64@gmail.com>
    nvmet-auth: Synchronize timeout work during SQ teardown

Chao Shi <coshi036@gmail.com>
    nvme: skip the zoned limits update if the zone info query failed

Tristan Madani <tristan@talencesecurity.com>
    nvme: add missing SRCU grace period in error path

Yehyeong Lee <yhlee@isslab.korea.ac.kr>
    nvme-tcp: check the data direction of a C2HData PDU

Niklas Cassel <cassel@kernel.org>
    nvme-fc: fix double free of fabrics options when nvme_add_ctrl() fails

Xu Rao <raoxu@uniontech.com>
    nvme-fabrics: fix DHCHAP secret leak on parse failure

GuoHan Zhao <zhaoguohan@kylinos.cn>
    accel/ethosu: fix job completion fence cleanup

GuoHan Zhao <zhaoguohan@kylinos.cn>
    accel/ethosu: check MMIO mapping errors in probe

Taimuraz Kaitmazov <taimuraz@kaitmazov.com>
    accel/amdxdna: return early from a zero-length flush

Vincent Donnefort <vdonnefort@google.com>
    ring-buffer: Allow splice reads on static buffers

Takashi Iwai <tiwai@suse.de>
    ALSA: pcm: Fix race between non-atomic ops and trigger-start

Runyu Xiao <runyu.xiao@seu.edu.cn>
    ALSA: harmony: initialize locks before requesting IRQ

HyeongJun An <sammiee5311@gmail.com>
    ALSA: rawmidi: Return the error from snd_rawmidi_input_params()

Khushit Shah <khushit.shah@nutanix.com>
    arm64: errata: pass REVIDR when matching target implementation CPUs

Fuad Tabba <fuad.tabba@linux.dev>
    arm64: Don't read GMID_EL1 when MTE is disabled

Karl Mehltretter <kmehltretter@gmail.com>
    arm64: mm: Fix the lockless page-table walk in show_pte()

Guangshuo Li <lgs201920130244@gmail.com>
    i2c: qcom-cci: fix autosuspend cleanup

Ahmad Byagowi <ahmadexp@gmail.com>
    i2c: mux: Fix channel node leak on adapter add failure

Vasileios Almpanis <vasilisalmpanis@gmail.com>
    i2c: core: fix debugfs UAF on adapter removal

Kathiravan Thirumoorthy <kathiravan.thirumoorthy@oss.qualcomm.com>
    i2c: qcom-geni: update frequency table to fix timing parameters

Hongbo Yao <andy.xu@hj-micro.com>
    i2c: designware: Enable interrupt mask workaround for HJMC3001

Yilin Zhang <yilinzhang@moonshot.ai>
    perf: Fix use-after-free when perf mmap() revival races with the last munmap()

Haiyong Sun <sunhaiyong@loongson.cn>
    perf build: Add clang and rust target flags for LoongArch

Sizhe Liu <liusizhe5@huawei.com>
    perf hisi-ptt: Fix PTT trace TLP header parsing

Viktor Malik <vmalik@redhat.com>
    perf trace: Refactor augmented_raw_syscalls using bpf_for

Viktor Malik <vmalik@redhat.com>
    perf trace: Factor out BPF loop body

Dapeng Mi <dapeng1.mi@linux.intel.com>
    perf/x86/intel: Remove anythread_deprecated bit from perf_capabilities

Dapeng Mi <dapeng1.mi@linux.intel.com>
    perf/x86/intel: Fix kernel address leakages in LBR stack

Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
    rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers

Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
    rtc: rzn1: Handle unset alarm weekday in rzn1_rtc_read_alarm

Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
    rtc: rzn1: Fix weekday underflow when alarm crosses month boundary

Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
    rtc: rzn1: Handle EPROBE_DEFER for optional pps interrupt

Shakeel Butt <shakeel.butt@linux.dev>
    memcg: make the v1 soft limit knob inert

Shakeel Butt <shakeel.butt@linux.dev>
    memcg: bypass the reclaim and oom killer for dying tasks once oom_reaper is done

Shakeel Butt <shakeel.butt@linux.dev>
    memcg: keep folio's objcg same as its node

Eric Dumazet <edumazet@google.com>
    mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave()

Usama Arif <usama.arif@linux.dev>
    mm/huge_memory: transfer the pmd dirty bit to the folio on zap

Baineng Shou <shoubaineng@gmail.com>
    misc: fastrpc: don't publish fd before copy_to_user() succeeds

Masami Hiramatsu (Google) <mhiramat@kernel.org>
    kprobes: Protect kprobe_blacklist with RCU

Ju Nan <junan76@163.com>
    irqchip/stm32mp-exti: Fix the unit of the hwspinlock timeout

Bradley Morgan <brads@mainlining.org>
    ima: Check for ERR_PTR from dentry_path() in validate_hash_algo()

Hajo Noerenberg <hajo-linux-ide@noerenberg.de>
    ata: ahci: work around lost interrupts on Marvell 88SE61xx

Max Kellermann <max.kellermann@ionos.com>
    ceph: lock mutex in ceph_mds_check_access()

Hui Su <sh_def@163.com>
    bpf: Fix infinite loop in pcpu_freelist push with one possible CPU

Chen Pei <cp0613@linux.alibaba.com>
    bpf, riscv: Make arena support depend on ZACAS

Damien Le Moal <dlemoal@kernel.org>
    block: flag zoned disks with GENHD_FL_NO_PART

Ulf Hansson <ulf.hansson@oss.qualcomm.com>
    cpuidle: psci: Fix support for probe deferral by dropping the faux device

Linkai Gong <gonglinkai@kylinos.cn>
    cpuidle: dt_idle_genpd: kfree() the original name allocation

Koichiro Den <den@valinux.co.jp>
    dmaengine: dw-edma: Mark emulated IRQ as level-triggered

Koichiro Den <den@valinux.co.jp>
    dmaengine: dw-edma: Initialize IRQ data before requesting IRQs

Koichiro Den <den@valinux.co.jp>
    dmaengine: dw-edma: Complete descriptors before pausing

Koichiro Den <den@valinux.co.jp>
    dmaengine: dw-edma: Fix HDMA channel status register access

Martin Kaiser <martin@kaiser.cx>
    dmaengine: fsl-edma: tracing: no ptr dereference during log output

Aneesh Kumar K.V (Arm) <aneesh.kumar@kernel.org>
    dma-direct: return struct page from dma_direct_alloc_from_pool()

Baineng Shou <shoubaineng@gmail.com>
    dma-buf: dma-heap: don't publish fd before copy_to_user() succeeds

Mikulas Patocka <mpatocka@redhat.com>
    dm: fix resume-vs-remove race

Mikulas Patocka <mpatocka@redhat.com>
    dm: fix race when loading and unloading a table

Ibrahim Hashimov <security@auditcode.ai>
    HID: wacom: validate report length in wacom_intuos_pro2_bt_irq

Wei Jie Law <98lawweijie@gmail.com>
    HID: rmi: fix OOB access with undersized RMI reports

Shen Yongchao <grayhat@foxmail.com>
    HID: bpf: serialize device reference release in struct_ops destroy path

Steven Rostedt <rostedt@goodmis.org>
    ftrace: Synchronize the initialization of ftrace_ops

Steven Rostedt <rostedt@goodmis.org>
    ftrace: Take trace_array reference before accessing its ftrace_ops

Sebastian Andrzej Siewior <bigeasy@linutronix.de>
    futex: Provide rt_mutex_.*_schedule() equivalents for futex scheduling

Yao Kai <yaokai34@huawei.com>
    futex: Prevent rcuwait use-after-free during requeue PI

Lorenzo Stoakes (ARM) <ljs@kernel.org>
    mm/secretmem: properly account locked pages

SJ Park <sj@kernel.org>
    mm/damon/core: initialize damos->last_applied

SJ Park <sj@kernel.org>
    mm/damon/core: handle region split failure in apply_min_nr_regions()

SJ Park <sj@kernel.org>
    mm/damon/core-kunit: skip wrong region walk in commit_target_regions()

SJ Park <sj@kernel.org>
    mm/damon/core-kunit: skip wrong quota goal walk in commit_quota_goals()

SJ Park <sj@kernel.org>
    mm/damon/core-kunit: skip wrong dest walk in commit_dests_for()

SJ Park <sj@kernel.org>
    mm/damon/core-kunit: handle region split failure in filter_out()

SJ Park <sj@kernel.org>
    mm/damon/core-kunit: check region count before testing in split_at()

SJ Park <sj@kernel.org>
    mm/damon/sysfs: kobject_del() target (normal), context and kdamond dirs

SJ Park <sj@kernel.org>
    mm/damon/sysfs: kobject_del() region and target (error) dirs

SJ Park <sj@kernel.org>
    mm/damon/sysfs-schemes: kobject_del() scheme region dirs

SJ Park <sj@kernel.org>
    mm/damon/sysfs-schemes: kobject_del() scheme quota goal dirs

SJ Park <sj@kernel.org>
    mm/damon/sysfs-schemes: kobject_del() scheme filter dirs

SJ Park <sj@kernel.org>
    mm/damon/sysfs-schemes: kobject_del() scheme dirs

SJ Park <sj@kernel.org>
    mm/damon/sysfs-schemes: kobject_del() scheme action destination dirs

SJ Park <sj@kernel.org>
    samples/damon/wsse: stop and free damon ctx when damon_call() fails

SJ Park <sj@kernel.org>
    samples/damon/wsse: handle damon_start() failure

SJ Park <sj@kernel.org>
    samples/damon/prcl: stop and free damon ctx when damon_call() fails

SJ Park <sj@kernel.org>
    samples/damon/prcl: handle damon_start() failure

SJ Park <sj@kernel.org>
    samples/damon/mtier: handle damon_stop() failure

SJ Park <sj@kernel.org>
    samples/damon/mtier: handle damon_start() failure

SJ Park <sj@kernel.org>
    mm/damon/vaddr-kunit: check region count in three_regions test

SJ Park <sj@kernel.org>
    mm/damon/tests/core-kunit: catch test failure in test_merge_regions_of()

SJ Park <sj@kernel.org>
    mm/damon/sysfs: read ops_id only once in damon_sysfs_apply_inputs()

SJ Park <sj@kernel.org>
    mm/damon/sysfs: read addr_unit only once in damon_sysfs_apply_inputs()

Song Hu <husong@kylinos.cn>
    Docs/ABI/damon: fix typo in intervals_goal sysfs path

Runyu Xiao <runyu.xiao@seu.edu.cn>
    scsi: pm8001: Use rollback index when freeing MSI-X vectors

Thomas Lamprecht <t.lamprecht@proxmox.com>
    scsi: megaraid_sas: Limit NVMe request size to the PRP chain frame

Rahul Chandelkar <rc@rexion.ai>
    scsi: bsg: Fix TOCTOU in io_uring passthrough command setup

Yang Xiuwei <yangxiuwei@kylinos.cn>
    scsi: bsg: Cap io_uring sense copy to max_response_len

Sujal Tuladhar <sujaltuladhar1231@gmail.com>
    scsi: target: iscsi: Reserve a terminator byte for the login payload

Honghui Jiang <jiang_hh2019@163.com>
    spi: Fix DMA mapping ownership on partial map failure

Can Peng <pengcan@kylinos.cn>
    spi: bcmbca-hsspi: disable clocks on resume failure

Can Peng <pengcan@kylinos.cn>
    spi: bcm63xx: disable clock on resume failure

Can Peng <pengcan@kylinos.cn>
    spi: bcm63xx-hsspi: disable clocks on resume failure

Viken Dadhaniya <viken.dadhaniya@oss.qualcomm.com>
    soc: qcom: geni-se: Use HW PROG_RAM_DEPTH to validate firmware size

Paul Louvel <paul.louvel@bootlin.com>
    soc: fsl: qe: Add chained_irq_{enter,exit}() calls in cascade handler

Kanishka De Silva <kpskanna1915@gmail.com>
    ublk: clear VM_MAYWRITE on read-only ublk char device mmap

Bryan Lim <foxieflakey@gmail.com>
    userfaultfd: reset err to be 0 when move_pages_ptes succeeded

Steven Rostedt <rostedt@goodmis.org>
    tracing: Take trace_array reference when opening options file

Steven Rostedt <rostedt@goodmis.org>
    tracing: Have show_event_filters/triggers files take trace array ref

Masami Hiramatsu (Google) <mhiramat@kernel.org>
    tracing/probes: Fix anon_stack check for unnamed bitfields in btf_find_struct_member

Can Peng <pengcan@kylinos.cn>
    thermal/drivers/qoriq: Disable clock on resume failure

Can Peng <pengcan@kylinos.cn>
    thermal/drivers/imx: Disable clock on runtime resume failure

Arthur Gautier <baloo@superbaloo.net>
    xhci: fix lost bounce buffers on TDs spanning several ring segments

Muhammad Bilal <meatuni001@gmail.com>
    staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie()

Muhammad Bilal <meatuni001@gmail.com>
    staging: rtl8723bs: fix OOB read in rtw_action_frame_parse()

Muhammad Bilal <meatuni001@gmail.com>
    staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr()

Jeffin Philip <jeffinphilip14@gmail.com>
    usb: gadget: fix null pointer dereference in usb_put_function_instance()

Lovekesh Solanki <lovekeshsolanki00@gmail.com>
    USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl()

Jeffin Philip <jeffinphilip14@gmail.com>
    usb: gadget: f_midi: initialize work in f_midi_alloc()

Ivy Lopez <skunkolee@gmail.com>
    usb: gadget: f_midi2: fix use-after-free in string attribute show path

Jeffin Philip <jeffinphilip14@gmail.com>
    usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers()

Aleksandr Nogikh <nogikh@google.com>
    usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs

Jameson Thies <jthies@google.com>
    usb: typec: ucsi: displayport: Fix OOB altmode array index

Sven Peter <sven@kernel.org>
    usb: typec: tipd: Fix Thunderbolt altmode VDOs for cd321x

Amit Sunil Dhamne <amitsd@google.com>
    usb: typec: tcpm: constrain TCPM_SOURCING_VBUS event handling

Fan Wu <fanwu01@zju.edu.cn>
    usb: typec: qcom-pmic: cancel reset_work on stop

Fan Wu <fanwu01@zju.edu.cn>
    usb: typec: qcom-pmic-typec: drain cc_debounce_dwork if port_start() fails

Fan Wu <fanwu01@zju.edu.cn>
    usb: typec: qcom-pmic-typec: disable cc_debounce_dwork on stop

Marek Vasut <marex@nabladev.com>
    usb: typec: mux: Fix typec_switch_match()

Marek Vasut <marex@nabladev.com>
    usb: typec: mux: avoid duplicated mux switches

Chang Wu <kunjinkao.jp@gmail.com>
    usb: typec: hd3ss3220: track VBUS enable state per consumer

Myeonghun Pak <mhun512@gmail.com>
    usb: storage: realtek_cr: fix use-after-free on disconnect

Elson Serrao <elson.serrao@oss.qualcomm.com>
    usb: dwc3: clear forceRM when issuing EndTransfer

Radhey Shyam Pandey <radhey.shyam.pandey@amd.com>
    usb: dwc3: google: Initialise probe properties with DWC3_DEFAULT_PROPERTIES

Andy Shevchenko <andriy.shevchenko@linux.intel.com>
    usb: f_mass_storage: Bump local buffer size in fsg_common_create_luns()

Pawel Laszczak <pawell@cadence.com>
    usb: cdnsp: fix wakeup from S3 after controller context loss

Liu Qi <liuqi@longcheer.com>
    usb-storage: ene_ub6250: fix race between scan work and probe

Shuangpeng Bai <shuangpeng.kernel@gmail.com>
    media: usbtv: keep device alive while ALSA card exists

Stephan Gerhold <stephan@gerhold.net>
    clk: qcom: gcc-mdm9607: Increase delay for USB PHY reset

HyeongJun An <sammiee5311@gmail.com>
    ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output()

Griffin Kroah-Hartman <griffin@kroah.com>
    usb: image: mdc800: change kmalloc() to kzalloc()

Hari Mishal <harimishal1@gmail.com>
    drm/amd/display: fix division by zero in get_estimated_bw()

Chuck Lever <cel@kernel.org>
    NFSD: Prevent client use-after-free during blocked-lock reaping

Chuck Lever <cel@kernel.org>
    NFSD: Prevent client use-after-free during close_lru reaping

Chuck Lever <cel@kernel.org>
    NFSD: Consolidate the revocation-path client unpin

Chuck Lever <cel@kernel.org>
    NFSD: Prevent client use-after-free during export state revocation

Chuck Lever <cel@kernel.org>
    NFSD: Guard admin state-revocation walks with NFSD_NET_UP

Chuck Lever <cel@kernel.org>
    NFSD: Annotate caller preconditions for the state-table walkers

Sean Christopherson <seanjc@google.com>
    KVM: SEV: Forcefully invalidate SNP VMSA if its backing gmem page is zapped

Sean Christopherson <seanjc@google.com>
    KVM: x86/mmu: Use split "zap all fast" helpers when invalidating memslot

Sean Christopherson <seanjc@google.com>
    KVM: x86/mmu: Split kvm_mmu_zap_all_fast() into "front" and "back" halves

Sean Christopherson <seanjc@google.com>
    KVM: x86/mmu: Fold kvm_mmu_zap_memslot() into kvm_arch_flush_shadow_memslot()

Rong Zhang <i@rong.moe>
    ACPI: battery: Protect all properties with a separated mutex

Rong Zhang <i@rong.moe>
    ACPI: battery: Use kstrtoul() over sscanf("%lu\n")

Doruk Tan Ozturk <doruk@0sec.ai>
    HID: sony: clean up device list on probe failure

Rosalie Wanders <rosalie@mailbox.org>
    HID: sony: use guard() and scoped_guard()

Sam Edwards <cfsworks@gmail.com>
    ceph: properly decrypt filenames in vmalloc() buffers

David Carlier <devnexen@gmail.com>
    zram: fix slot lock bit position on big-endian 64-bit

Sebastian Andrzej Siewior <bigeasy@linutronix.de>
    zram: move lockmap to be per-zram instead per table

Neill Kapron <nkapron@google.com>
    usb: gadget: f_fs: Fix Use-After-Free in AIO error path

Gabriel Prostitis <prostitisgabriel@gmail.com>
    USB: gadget: ffs: fix mm lifetime handling

Brendan Jackman <brendan.jackman@linux.dev>
    mm/page_alloc: don't spin_trylock() in NMI on UP

Linus Torvalds <torvalds@linux-foundation.org>
    drm/xe: Don't hand out the flat CCS storage as usable VRAM

HE WEI(ギカク) <skyexpoc@gmail.com>
    fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list()

Norbert Szetei <norbert@doyensec.com>
    net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy()


-------------

Diffstat:

 Documentation/ABI/testing/sysfs-kernel-mm-damon    |   8 +-
 Documentation/admin-guide/cgroup-v1/memory.rst     |  49 +----
 .../devicetree/bindings/media/nxp,imx8-isi.yaml    |   4 +-
 Documentation/trace/hisi-ptt.rst                   |  28 +--
 .../media/v4l/ext-ctrls-colorimetry.rst            |  12 +-
 Makefile                                           |   4 +-
 arch/arm64/include/asm/cpu.h                       |   1 +
 arch/arm64/include/asm/cpufeature.h                |   7 -
 arch/arm64/include/asm/kvm_host.h                  |   3 -
 arch/arm64/include/asm/kvm_nested.h                |  20 ++
 arch/arm64/kernel/cpu_errata.c                     |   2 +-
 arch/arm64/kernel/cpufeature.c                     |  33 +++-
 arch/arm64/kernel/cpuinfo.c                        |   2 +-
 arch/arm64/kvm/at.c                                |   2 -
 arch/arm64/kvm/hyp/vhe/switch.c                    |   3 +-
 arch/arm64/kvm/nested.c                            | 139 +++++++++-----
 arch/arm64/kvm/sys_regs.c                          |  11 ++
 arch/arm64/kvm/vgic/vgic-init.c                    |   1 +
 arch/arm64/kvm/vgic/vgic-its.c                     |   8 +
 arch/arm64/kvm/vgic/vgic-v3-nested.c               |   2 +-
 arch/arm64/kvm/vgic/vgic-v3.c                      |  12 +-
 arch/arm64/mm/fault.c                              |  12 +-
 arch/loongarch/Kconfig                             |   2 +-
 arch/loongarch/include/asm/kvm_dmsintc.h           |   1 +
 arch/loongarch/include/asm/kvm_eiointc.h           |   1 +
 arch/loongarch/include/asm/kvm_host.h              |   1 +
 arch/loongarch/include/asm/kvm_ipi.h               |   1 +
 arch/loongarch/include/asm/kvm_pch_pic.h           |   1 +
 arch/loongarch/include/asm/pgtable.h               |   9 +-
 arch/loongarch/kernel/acpi.c                       |   3 +-
 arch/loongarch/kernel/kprobes.c                    |   3 +
 arch/loongarch/kernel/rethook_trampoline.S         |   2 -
 arch/loongarch/kvm/exit.c                          |   1 -
 arch/loongarch/kvm/intc/dmsintc.c                  |   8 +-
 arch/loongarch/kvm/intc/eiointc.c                  |   5 +
 arch/loongarch/kvm/intc/ipi.c                      |   5 +
 arch/loongarch/kvm/intc/pch_pic.c                  |   8 +
 arch/loongarch/kvm/main.c                          |  39 +++-
 arch/loongarch/kvm/mmu.c                           |  10 +
 arch/loongarch/kvm/vcpu.c                          |   8 +-
 arch/loongarch/kvm/vm.c                            |   1 +
 arch/loongarch/mm/init.c                           |  17 +-
 arch/loongarch/net/bpf_jit.c                       |  40 ++--
 arch/parisc/kernel/head.S                          |   1 +
 arch/powerpc/include/asm/papr-watchdog.h           |  64 +++++++
 arch/powerpc/include/asm/reg.h                     |  12 ++
 arch/powerpc/kexec/file_load_64.c                  |   2 +-
 arch/powerpc/kexec/ranges.c                        |  12 +-
 arch/powerpc/kvm/book3s_hv.c                       |  15 +-
 arch/powerpc/kvm/powerpc.c                         |   6 +
 arch/powerpc/mm/book3s64/radix_pgtable.c           |   7 +-
 arch/powerpc/platforms/pseries/setup.c             |  28 ++-
 arch/riscv/net/bpf_jit_comp64.c                    |  10 +-
 arch/s390/include/asm/nmi.h                        |   3 +
 arch/s390/kernel/nmi.c                             |   5 +-
 arch/s390/kvm/guestdbg.c                           |   9 +-
 arch/s390/kvm/interrupt.c                          |  26 +--
 arch/s390/kvm/kvm-s390.c                           |  22 ++-
 arch/x86/events/intel/core.c                       |  10 +-
 arch/x86/events/intel/lbr.c                        |  12 +-
 arch/x86/events/perf_event.h                       |   2 +-
 arch/x86/include/asm/kvm-x86-ops.h                 |   4 +
 arch/x86/include/asm/kvm_host.h                    |   6 +
 arch/x86/kvm/hyperv.c                              |  25 ++-
 arch/x86/kvm/mmu/mmu.c                             | 107 ++++++-----
 arch/x86/kvm/mmu/tdp_iter.h                        |   7 +
 arch/x86/kvm/mmu/tdp_mmu.c                         |  20 +-
 arch/x86/kvm/svm/sev.c                             |  80 ++++++--
 arch/x86/kvm/svm/svm.c                             |   6 +-
 arch/x86/kvm/svm/svm.h                             |   2 +
 arch/x86/kvm/vmx/nested.c                          |  75 ++++----
 arch/x86/kvm/x86.c                                 |  17 +-
 arch/x86/kvm/x86.h                                 |   2 +-
 block/genhd.c                                      |   7 +
 drivers/accel/amdxdna/amdxdna_gem.c                |   3 +
 drivers/accel/ethosu/ethosu_drv.c                  |   2 +
 drivers/accel/ethosu/ethosu_job.c                  |  10 +-
 drivers/acpi/battery.c                             | 155 +++++++++++-----
 drivers/ata/ahci.c                                 |  49 +++++
 drivers/block/ublk_drv.c                           |   6 +
 drivers/block/zram/zram_drv.c                      |  27 ++-
 drivers/block/zram/zram_drv.h                      |  16 +-
 drivers/clk/mediatek/Kconfig                       |   1 +
 drivers/clk/meson/gxbb.c                           |   2 +-
 drivers/clk/microchip/clk-mpfs.c                   |   2 +-
 drivers/clk/qcom/gcc-mdm9607.c                     | 182 +-----------------
 drivers/clk/qcom/gcc-msm8916.c                     |   5 +-
 drivers/clk/qcom/gcc-msm8939.c                     |   5 +-
 drivers/clk/rockchip/clk-rk3588.c                  |   2 +-
 drivers/clk/xilinx/clk-xlnx-clock-wizard.c         |   4 +-
 drivers/cpuidle/cpuidle-psci.c                     |  42 ++---
 drivers/cpuidle/dt_idle_genpd.c                    |   3 +-
 drivers/dma-buf/dma-buf.c                          |  20 ++
 drivers/dma-buf/dma-heap.c                         |  80 ++++----
 drivers/dma/dw-edma/dw-edma-core.c                 |  24 ++-
 drivers/dma/dw-edma/dw-hdma-v0-core.c              |   2 +-
 drivers/dma/fsl-edma-trace.h                       |   4 +-
 drivers/gpu/drm/amd/amdgpu/amdgpu_amdkfd_gpuvm.c   |   7 +
 drivers/gpu/drm/amd/amdgpu/amdgpu_dev_coredump.c   |   6 +-
 drivers/gpu/drm/amd/amdgpu/amdgpu_device.c         |  59 +++++-
 drivers/gpu/drm/amd/amdgpu/amdgpu_drv.c            |   1 +
 drivers/gpu/drm/amd/amdgpu/amdgpu_psp.c            |   6 +
 drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c            |   3 +-
 drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c             |   8 +-
 drivers/gpu/drm/amd/amdgpu/amdgpu_vram_mgr.c       |   7 +-
 drivers/gpu/drm/amd/amdgpu/amdgpu_xgmi.c           |   3 +
 drivers/gpu/drm/amd/amdgpu/gfx_v11_0.c             |   8 +-
 drivers/gpu/drm/amd/amdgpu/gfx_v12_0.c             |   8 +-
 drivers/gpu/drm/amd/amdgpu/gfx_v8_0.c              |   8 +-
 drivers/gpu/drm/amd/amdgpu/vcn_v3_0.c              |  10 +-
 drivers/gpu/drm/amd/amdgpu/vcn_v4_0.c              |  10 +-
 drivers/gpu/drm/amd/amdkfd/kfd_chardev.c           |   3 +-
 .../gpu/drm/amd/amdkfd/kfd_device_queue_manager.c  |  23 ++-
 drivers/gpu/drm/amd/amdkfd/kfd_migrate.c           |  56 ++++--
 .../gpu/drm/amd/amdkfd/kfd_process_queue_manager.c |  12 +-
 drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c  |   6 +
 .../drm/amd/display/amdgpu_dm/amdgpu_dm_color.c    |  13 ++
 .../dml21/src/dml2_core/dml2_core_shared_types.h   |   4 +-
 .../display/dc/dml2_0/dml2_translation_helper.c    |   1 +
 drivers/gpu/drm/amd/display/dc/link/link_factory.c |   2 +-
 .../display/dc/link/protocols/link_dp_dpia_bw.c    |   5 +
 drivers/gpu/drm/bridge/synopsys/dw-hdmi.c          |   3 +-
 drivers/gpu/drm/drm_atomic_uapi.c                  |   2 +
 drivers/gpu/drm/drm_drv.c                          |  34 +++-
 drivers/gpu/drm/drm_pagemap.c                      | 128 ++++++++++---
 drivers/gpu/drm/gud/gud_connector.c                |  12 +-
 drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_de.c     |  54 ++----
 drivers/gpu/drm/i915/display/intel_cursor.c        |  15 +-
 drivers/gpu/drm/i915/display/skl_universal_plane.c |  15 +-
 drivers/gpu/drm/i915/i915_pci.c                    |   3 +
 drivers/gpu/drm/msm/dsi/dsi_host.c                 |  12 ++
 drivers/gpu/drm/nouveau/include/nvkm/engine/disp.h |   1 +
 drivers/gpu/drm/nouveau/nouveau_chan.c             |   9 +-
 drivers/gpu/drm/nouveau/nouveau_dmem.c             |  18 +-
 drivers/gpu/drm/nouveau/nouveau_sgdma.c            |   4 +-
 drivers/gpu/drm/nouveau/nouveau_uvmm.c             |   6 +-
 drivers/gpu/drm/nouveau/nvkm/engine/device/base.c  |  10 +-
 drivers/gpu/drm/nouveau/nvkm/engine/disp/Kbuild    |   1 +
 drivers/gpu/drm/nouveau/nvkm/engine/disp/ga102.c   |  13 +-
 drivers/gpu/drm/nouveau/nvkm/engine/disp/gb202.c   | 191 +++++++++++++++++++
 drivers/gpu/drm/nouveau/nvkm/engine/disp/gv100.c   |   4 +-
 drivers/gpu/drm/nouveau/nvkm/engine/disp/head.h    |   4 +
 drivers/gpu/drm/nouveau/nvkm/engine/disp/ior.h     |   1 +
 drivers/gpu/drm/nouveau/nvkm/engine/disp/priv.h    |  17 ++
 drivers/gpu/drm/nouveau/nvkm/engine/disp/tu102.c   |  86 ++++++++-
 .../gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/disp.c | 129 ++++++-------
 .../gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/disp.c |  64 +++++++
 .../gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/gsp.c  |   9 +
 .../nouveau/nvkm/subdev/gsp/rm/r570/nvrm/disp.h    |   2 +
 drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/rm.h    |   5 +
 drivers/gpu/drm/panel/panel-edp.c                  |  19 +-
 drivers/gpu/drm/panthor/panthor_fw.c               |  22 ++-
 drivers/gpu/drm/solomon/ssd130x.c                  |   9 +-
 drivers/gpu/drm/sun4i/sun4i_backend.c              |   2 +-
 drivers/gpu/drm/sysfb/ofdrm.c                      |   8 +-
 drivers/gpu/drm/sysfb/simpledrm.c                  |  74 ++++++--
 drivers/gpu/drm/ttm/ttm_pool.c                     |  15 +-
 drivers/gpu/drm/xe/xe_vram.c                       |  26 ++-
 drivers/hid/bpf/hid_bpf_struct_ops.c               |  17 +-
 drivers/hid/hid-rmi.c                              |  46 ++++-
 drivers/hid/hid-sony.c                             |  87 ++++-----
 drivers/hid/wacom_wac.c                            |  13 ++
 drivers/i2c/busses/i2c-designware-platdrv.c        |   2 +-
 drivers/i2c/busses/i2c-qcom-cci.c                  |  11 +-
 drivers/i2c/busses/i2c-qcom-geni.c                 |   4 +-
 drivers/i2c/i2c-core-base.c                        |   6 +
 drivers/i2c/i2c-mux.c                              |   1 +
 drivers/i2c/muxes/i2c-demux-pinctrl.c              |   1 +
 drivers/iio/adc/Kconfig                            |   2 +
 drivers/iio/adc/ad4080.c                           |   5 +
 drivers/iio/adc/adi-axi-adc.c                      |  30 +++
 drivers/iio/adc/pac1921.c                          |   2 +-
 drivers/iio/adc/ti-ads7138.c                       |  42 ++++-
 drivers/iio/chemical/atlas-sensor.c                |  19 +-
 drivers/iio/chemical/sgp30.c                       |   3 +
 drivers/iio/dac/Kconfig                            |   1 +
 drivers/iio/dac/ad3552r-hs.c                       |   2 +-
 drivers/iio/dac/ad5446-i2c.c                       |   2 +-
 drivers/iio/dac/m62332.c                           |  17 +-
 drivers/iio/gyro/mpu3050-core.c                    |   2 +-
 drivers/iio/imu/st_lsm6dsx/st_lsm6dsx_fusion.c     |   5 +
 drivers/iio/industrialio-buffer.c                  |  38 ++--
 drivers/iio/light/apds9306.c                       |   8 +-
 drivers/iio/light/cm32181.c                        |   2 +-
 drivers/iio/light/gp2ap002.c                       |  10 +-
 drivers/iio/light/ltrf216a.c                       |   3 +-
 drivers/iio/light/opt4001.c                        |  37 ++--
 drivers/iio/light/opt4060.c                        |   5 +-
 drivers/iio/pressure/dps310.c                      |   3 +-
 drivers/iio/pressure/mpl115.c                      |  11 +-
 drivers/iio/proximity/srf04.c                      |   1 +
 drivers/iio/temperature/hid-sensor-temperature.c   |   3 +-
 drivers/irqchip/irq-mbigen.c                       |  20 +-
 drivers/irqchip/irq-stm32mp-exti.c                 |   4 +-
 drivers/md/dm.c                                    |  14 +-
 drivers/media/cec/core/cec-adap.c                  |  10 +-
 drivers/media/cec/core/cec-core.c                  |   2 -
 drivers/media/cec/platform/meson/ao-cec-g12a.c     |   1 +
 .../extron-da-hd-4k-plus/extron-da-hd-4k-plus.c    |   3 +-
 drivers/media/dvb-frontends/rtl2832_sdr.c          |  23 ++-
 drivers/media/i2c/alvium-csi2.c                    |   2 +-
 drivers/media/i2c/imx355.c                         |   3 +-
 drivers/media/i2c/imx415.c                         |   4 +-
 drivers/media/i2c/ov02a10.c                        |  12 +-
 drivers/media/i2c/ov7740.c                         |   4 +-
 drivers/media/i2c/ov9282.c                         |   3 +-
 drivers/media/i2c/vd55g1.c                         |  32 +++-
 drivers/media/i2c/video-i2c.c                      |   8 +-
 drivers/media/pci/cobalt/cobalt-alsa-main.c        |   1 -
 drivers/media/pci/cx23885/cimax2.c                 |   1 +
 drivers/media/pci/intel/ipu-bridge.c               |   8 +-
 drivers/media/pci/intel/ipu6/ipu6-isys.c           |   1 +
 drivers/media/pci/saa7164/saa7164-core.c           |   8 +-
 drivers/media/pci/zoran/zoran_card.c               |   2 +-
 drivers/media/platform/amphion/venc.c              |   2 -
 .../media/platform/arm/mali-c55/mali-c55-core.c    |   2 +
 .../media/platform/arm/mali-c55/mali-c55-params.c  |   1 +
 .../platform/arm/mali-c55/mali-c55-registers.h     |   2 +-
 .../media/platform/arm/mali-c55/mali-c55-resizer.c |   2 +-
 drivers/media/platform/broadcom/bcm2835-unicam.c   |   3 +-
 .../platform/chips-media/wave5/wave5-vpu-dec.c     |  64 +++++--
 .../platform/chips-media/wave5/wave5-vpu-enc.c     |   6 +-
 .../platform/chips-media/wave5/wave5-vpuconfig.h   |   2 +-
 .../media/platform/mediatek/mdp3/mtk-mdp3-core.c   |   6 +-
 .../platform/nxp/imx8-isi/imx8-isi-crossbar.c      |   6 +-
 .../media/platform/nxp/imx8-isi/imx8-isi-video.c   |   2 +-
 drivers/media/platform/qcom/iris/iris_ctrls.c      |   2 +-
 drivers/media/platform/qcom/iris/iris_hfi_gen1.c   |  16 +-
 .../platform/qcom/iris/iris_platform_common.h      |   1 -
 drivers/media/platform/qcom/iris/iris_state.c      |   2 +-
 drivers/media/platform/qcom/iris/iris_vidc.c       |  11 +-
 drivers/media/platform/qcom/iris/iris_vpu_common.c |   2 +-
 drivers/media/platform/qcom/venus/hfi_parser.c     |   9 +-
 .../media/platform/renesas/rzg2l-cru/rzg2l-video.c |   5 +
 drivers/media/platform/rockchip/rga/rga3-hw.c      |  12 +-
 .../platform/rockchip/rkvdec/rkvdec-hevc-common.c  |   3 +
 drivers/media/platform/rockchip/rkvdec/rkvdec.c    |   8 +-
 drivers/media/platform/ti/vpe/vip.c                |  37 +++-
 drivers/media/rc/sunxi-cir.c                       |   9 +-
 drivers/media/test-drivers/vimc/vimc-capture.c     |   4 +-
 drivers/media/tuners/tda18250.c                    |   4 +-
 drivers/media/usb/airspy/airspy.c                  |  19 +-
 drivers/media/usb/cx231xx/cx231xx-video.c          |   4 +-
 drivers/media/usb/em28xx/em28xx-cards.c            |   3 +-
 drivers/media/usb/em28xx/em28xx-core.c             |   2 +
 drivers/media/usb/go7007/snd-go7007.c              |  10 +-
 drivers/media/usb/s2255/s2255drv.c                 |  11 ++
 drivers/media/usb/usbtv/usbtv-audio.c              |  11 ++
 drivers/media/v4l2-core/v4l2-async.c               |   1 -
 drivers/media/v4l2-core/v4l2-ctrls-core.c          |  64 +++++--
 drivers/media/v4l2-core/v4l2-fwnode.c              |   2 +
 drivers/misc/fastrpc.c                             |  16 +-
 drivers/mtd/mtdoops.c                              |   3 +
 drivers/mtd/nand/ecc-realtek.c                     |   1 +
 drivers/mtd/nand/raw/nand_onfi.c                   |  27 ++-
 drivers/mtd/nand/raw/pl35x-nand-controller.c       |   5 +-
 drivers/mtd/nand/raw/sunxi_nand.c                  | 113 +++++++++---
 drivers/mtd/parsers/afs.c                          |   7 +
 drivers/nvdimm/btt.c                               |   8 +
 drivers/nvme/host/core.c                           |  24 ++-
 drivers/nvme/host/fabrics.c                        |   2 +
 drivers/nvme/host/fc.c                             |  26 ++-
 drivers/nvme/host/tcp.c                            |   7 +
 drivers/nvme/target/auth.c                         |   6 +
 drivers/nvme/target/core.c                         |   2 +-
 drivers/nvme/target/nvmet.h                        |   2 +
 drivers/nvme/target/tcp.c                          |  10 +
 drivers/parisc/eisa.c                              |   5 +
 drivers/pci/hotplug/pnv_php.c                      |   2 +-
 drivers/pci/hotplug/rpaphp_slot.c                  |   2 +-
 drivers/pci/pci.c                                  |   5 +-
 drivers/pci/slot.c                                 |  50 +++--
 drivers/pmdomain/mediatek/Kconfig                  |   5 +-
 drivers/pmdomain/qcom/rpmhpd.c                     |   4 -
 drivers/power/supply/ab8500_fg.c                   |  32 ++--
 drivers/remoteproc/qcom_q6v5_pas.c                 |  13 +-
 drivers/rtc/rtc-rzn1.c                             |  30 ++-
 drivers/s390/crypto/vfio_ap_ops.c                  | 203 ++++++++++++++-------
 drivers/scsi/megaraid/megaraid_sas_base.c          |  13 +-
 drivers/scsi/pm8001/pm8001_init.c                  |   4 +-
 drivers/scsi/qla2xxx/qla_attr.c                    |   6 +-
 drivers/scsi/qla2xxx/qla_bsg.c                     |  46 +++--
 drivers/scsi/qla2xxx/qla_dbg.c                     |   2 +-
 drivers/scsi/qla2xxx/qla_dfs.c                     |   4 +-
 drivers/scsi/qla2xxx/qla_edif.c                    |   3 +
 drivers/scsi/qla2xxx/qla_gs.c                      |   4 +-
 drivers/scsi/qla2xxx/qla_init.c                    |  61 ++++++-
 drivers/scsi/qla2xxx/qla_inline.h                  |  13 ++
 drivers/scsi/qla2xxx/qla_isr.c                     |  39 +++-
 drivers/scsi/qla2xxx/qla_mbx.c                     |  28 ++-
 drivers/scsi/qla2xxx/qla_nvme.c                    |  31 +++-
 drivers/scsi/qla2xxx/qla_os.c                      |  14 +-
 drivers/scsi/scsi_bsg.c                            |  47 +++--
 drivers/soc/fsl/qe/qe_ports_ic.c                   |   7 +
 drivers/soc/qcom/qcom-geni-se.c                    |  24 +--
 drivers/spi/spi-bcm63xx-hsspi.c                    |   8 +-
 drivers/spi/spi-bcm63xx.c                          |   6 +-
 drivers/spi/spi-bcmbca-hsspi.c                     |   8 +-
 drivers/spi/spi.c                                  |  34 ++--
 drivers/staging/media/meson/vdec/vdec.c            |   4 +-
 drivers/staging/media/sunxi/cedrus/cedrus.c        |   4 +-
 drivers/staging/rtl8723bs/core/rtw_ieee80211.c     |   7 +
 drivers/staging/rtl8723bs/core/rtw_mlme.c          |   3 +
 drivers/target/iscsi/iscsi_target_login.c          |   2 +-
 drivers/thermal/imx_thermal.c                      |   9 +-
 drivers/thermal/qoriq_thermal.c                    |  13 +-
 drivers/usb/cdns3/cdnsp-gadget.c                   | 111 ++++++++++-
 drivers/usb/cdns3/cdnsp-gadget.h                   |   1 +
 drivers/usb/cdns3/cdnsp-mem.c                      |  98 ++++------
 drivers/usb/dwc3/dwc3-google.c                     |   1 +
 drivers/usb/dwc3/ep0.c                             |   2 +-
 drivers/usb/dwc3/gadget.c                          |  21 ++-
 drivers/usb/gadget/function/f_fs.c                 |  31 +++-
 drivers/usb/gadget/function/f_mass_storage.c       |   5 +-
 drivers/usb/gadget/function/f_midi.c               |   2 +-
 drivers/usb/gadget/function/f_midi2.c              |  17 +-
 drivers/usb/gadget/functions.c                     |   2 +-
 drivers/usb/gadget/legacy/inode.c                  |   3 +-
 drivers/usb/host/xhci-ring.c                       |  32 +++-
 drivers/usb/image/mdc800.c                         |   4 +-
 drivers/usb/storage/ene_ub6250.c                   |   2 +
 drivers/usb/storage/realtek_cr.c                   |   9 +-
 drivers/usb/typec/hd3ss3220.c                      |   9 +-
 drivers/usb/typec/mux.c                            |  21 ++-
 .../usb/typec/tcpm/qcom/qcom_pmic_typec_pdphy.c    |   2 +
 drivers/usb/typec/tcpm/qcom/qcom_pmic_typec_port.c |   5 +
 drivers/usb/typec/tcpm/tcpm.c                      |  28 ++-
 drivers/usb/typec/tipd/core.c                      |  17 +-
 drivers/usb/typec/tipd/tps6598x.h                  |   4 +-
 drivers/usb/typec/ucsi/displayport.c               |   2 +-
 drivers/watchdog/pseries-wdt.c                     |  53 +-----
 fs/ceph/crypto.c                                   |  50 +++--
 fs/ceph/mds_client.c                               |  12 +-
 fs/ceph/mds_client.h                               |   1 +
 fs/f2fs/data.c                                     |   8 +-
 fs/f2fs/debug.c                                    |   4 -
 fs/f2fs/dir.c                                      |   7 +-
 fs/f2fs/f2fs.h                                     |  29 ++-
 fs/f2fs/file.c                                     | 170 +++++++++++++----
 fs/f2fs/gc.c                                       |  38 ++--
 fs/f2fs/gc.h                                       |  27 +--
 fs/f2fs/inline.c                                   |   2 +-
 fs/f2fs/iostat.c                                   |   6 +
 fs/f2fs/namei.c                                    |  17 +-
 fs/f2fs/node.c                                     |  10 +-
 fs/f2fs/recovery.c                                 |  41 +++--
 fs/f2fs/segment.c                                  |  18 +-
 fs/f2fs/super.c                                    |   4 +-
 fs/f2fs/sysfs.c                                    |  30 +--
 fs/f2fs/xattr.c                                    |   2 +-
 fs/nfsd/nfs4proc.c                                 |   5 +
 fs/nfsd/nfs4state.c                                | 118 ++++++++----
 fs/nfsd/nfsctl.c                                   |   6 +-
 fs/ntfs3/frecord.c                                 |  20 +-
 fs/smb/server/oplock.c                             |  79 ++++++--
 include/linux/dma-buf.h                            |   1 +
 include/linux/ftrace.h                             |   5 +-
 include/linux/kprobes.h                            |   1 +
 include/linux/kvm_host.h                           |   1 +
 include/linux/pci.h                                |   8 +-
 include/linux/sched/rt.h                           |   2 +
 include/linux/sched/user.h                         |   3 +-
 include/linux/soc/qcom/geni-se.h                   |   4 +
 include/trace/events/f2fs.h                        |  20 +-
 kernel/bpf/percpu_freelist.c                       |  35 +++-
 kernel/bpf/percpu_freelist.h                       |   1 +
 kernel/bpf/stackmap.c                              | 173 ++++++++++++------
 kernel/dma/direct.c                                |  18 +-
 kernel/events/core.c                               |  20 +-
 kernel/futex/pi.c                                  |  16 +-
 kernel/futex/requeue.c                             |  12 +-
 kernel/kprobes.c                                   |  14 +-
 kernel/locking/rtmutex_api.c                       |   2 +
 kernel/sched/core.c                                |  16 ++
 kernel/trace/ftrace.c                              |  70 ++++---
 kernel/trace/ring_buffer.c                         |  11 +-
 kernel/trace/trace.c                               |  67 ++++++-
 kernel/trace/trace.h                               |   5 +-
 kernel/trace/trace_btf.c                           |  12 +-
 kernel/trace/trace_events.c                        |  28 ++-
 kernel/trace/trace_functions.c                     |   2 +-
 kernel/trace/trace_stack.c                         |   2 +-
 lib/once.c                                         |   2 +-
 mm/damon/core.c                                    |  27 ++-
 mm/damon/ops-common.c                              |   5 +-
 mm/damon/paddr.c                                   |  20 +-
 mm/damon/sysfs-schemes.c                           |  18 +-
 mm/damon/sysfs.c                                   |  29 ++-
 mm/damon/tests/core-kunit.h                        |  33 +++-
 mm/damon/tests/vaddr-kunit.h                       |   5 +
 mm/damon/vaddr.c                                   |  34 +---
 mm/huge_memory.c                                   |   2 +
 mm/hugetlb.c                                       |  20 +-
 mm/hugetlb_cgroup.c                                |   7 +-
 mm/hugetlb_cma.c                                   |  21 ++-
 mm/khugepaged.c                                    |   6 -
 mm/madvise.c                                       |   8 +
 mm/memcontrol-v1.c                                 |  43 +++--
 mm/memcontrol.c                                    | 113 ++++++++++--
 mm/mempolicy.c                                     |   2 +-
 mm/migrate_device.c                                |  18 ++
 mm/page_alloc.c                                    |   6 +-
 mm/secretmem.c                                     | 116 +++++++++++-
 mm/userfaultfd.c                                   |   4 +-
 net/batman-adv/bridge_loop_avoidance.c             |  15 +-
 net/batman-adv/distributed-arp-table.c             |   8 +-
 net/batman-adv/main.c                              |   4 +
 net/batman-adv/mesh-interface.c                    |   7 +-
 net/batman-adv/multicast_forw.c                    |   7 +-
 net/core/skbuff.c                                  |   5 +-
 net/sunrpc/xprtrdma/ib_client.c                    |  26 ++-
 rust/kernel/drm/ioctl.rs                           |   6 +
 samples/damon/mtier.c                              |  14 +-
 samples/damon/prcl.c                               |  11 +-
 samples/damon/wsse.c                               |  11 +-
 security/integrity/ima/ima_appraise.c              |   2 +
 sound/core/pcm_native.c                            |   2 +
 sound/core/rawmidi.c                               |   2 +-
 sound/parisc/harmony.c                             |   6 +-
 sound/soc/codecs/adau1761.c                        |  34 ++--
 sound/soc/codecs/cs35l33.c                         |  14 +-
 sound/soc/codecs/cs35l34.c                         |  14 +-
 sound/soc/codecs/cx2072x.c                         | 134 +++++++-------
 sound/soc/codecs/hdac_hda.c                        |   4 +-
 sound/soc/codecs/max9860.c                         |   2 +-
 sound/soc/codecs/ml26124.c                         |   4 +-
 sound/soc/codecs/pcm512x.c                         |  40 ++--
 sound/soc/codecs/pm4125-sdw.c                      |   2 +-
 sound/soc/codecs/rt1017-sdca-sdw.h                 |  10 +-
 sound/soc/codecs/rt1316-sdw.c                      |   2 +-
 sound/soc/codecs/rt1318-sdw.c                      |   2 +-
 sound/soc/codecs/rt1318.c                          |   4 +-
 sound/soc/codecs/rt274.c                           |   8 +-
 sound/soc/codecs/rt286.c                           |  14 +-
 sound/soc/codecs/rt298.c                           |  14 +-
 sound/soc/codecs/rt700-sdw.h                       |  11 +-
 sound/soc/codecs/rt711-sdca-sdw.h                  |   6 +-
 sound/soc/codecs/rt711-sdw.h                       |  10 +-
 sound/soc/codecs/rt712-sdca-dmic.h                 |   6 +-
 sound/soc/codecs/rt712-sdca-sdw.h                  |  11 +-
 sound/soc/codecs/rt715-sdca-sdw.h                  |  48 +++--
 sound/soc/codecs/rt715-sdw.h                       |  32 ++--
 sound/soc/codecs/rt721-sdca-sdw.h                  |  44 ++---
 sound/soc/codecs/sgtl5000.c                        |   2 +-
 sound/soc/codecs/sti-sas.c                         |   2 +-
 sound/soc/codecs/tas2552.c                         |  14 +-
 sound/soc/codecs/tas2764.c                         |   2 +-
 sound/soc/codecs/tas2780.c                         |   2 +-
 sound/soc/codecs/tas2783-sdw.c                     | 177 +++++++++---------
 sound/soc/fsl/fsl_easrc.c                          |   8 +-
 sound/soc/fsl/mpc5200_psc_i2s.c                    |   1 +
 sound/soc/intel/atom/sst/sst_pci.c                 |   4 +-
 sound/soc/loongson/loongson_card.c                 |   6 +-
 sound/soc/samsung/aries_wm8994.c                   |   1 +
 sound/usb/midi.c                                   |   2 +
 tools/perf/Makefile.config                         |   2 +
 .../util/bpf_skel/augmented_raw_syscalls.bpf.c     | 155 ++++++++++------
 .../util/hisi-ptt-decoder/hisi-ptt-pkt-decoder.c   |  47 ++---
 .../util/hisi-ptt-decoder/hisi-ptt-pkt-decoder.h   |  12 ++
 tools/testing/selftests/mm/memfd_secret.c          |  30 +--
 virt/kvm/guest_memfd.c                             |   4 +
 461 files changed, 5681 insertions(+), 2746 deletions(-)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 001/556] net: skbuff: dont skb_tx_error() the source skb in skb_zerocopy()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
@ 2026-09-09 13:34 ` Greg Kroah-Hartman
  2026-09-09 13:34 ` [PATCH 7.2 002/556] fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list() Greg Kroah-Hartman
                   ` (567 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:34 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ilya Maximets, Norbert Szetei,
	Willem de Bruijn, Paolo Abeni, Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Norbert Szetei <norbert@doyensec.com>

[ Upstream commit 8ece906150128d5ec2462aabcc978c568433eca4 ]

skb_zerocopy() copies frags from @from into @to. On an
skb_orphan_frags() failure it calls skb_tx_error(@from), a destructive
operation on the source skb the copy helper does not own. That completes
@from's zerocopy uarg and clears SKBFL_ALL_ZEROCOPY, including the
SKBFL_SHARED_FRAG page-ownership marker.

Both callers already report the failure on their own drop path.
nfnetlink_queue does it at nla_put_failure, and Open vSwitch does it in
the flow-miss drop arm of ovs_dp_process_packet(), so nothing is lost by
dropping it here.

On Open vSwitch's OVS_ACTION_ATTR_USERSPACE path the skb is not freed on
this error: do_execute_actions() ignores output_userspace()'s return
value and, unless the upcall was the last action, keeps forwarding the
same skb through the flow's remaining actions. The uarg is completed
while that skb is still in flight, telling the producer its buffers are
free, and SKBFL_SHARED_FRAG is cleared on an skb the rest of the stack
still handles. That flag is what makes esp_input() call skb_cow_data()
instead of decrypting in place, so a later local ESP delivery can
decrypt over frags the skb does not own privately.

Leave error reporting to the callers.

Fixes: 36d5fe6a0007 ("core, nfqueue, openvswitch: Orphan frags in skb_zerocopy and handle errors")
Cc: stable@vger.kernel.org
Suggested-by: Ilya Maximets <i.maximets@ovn.org>
Signed-off-by: Norbert Szetei <norbert@doyensec.com>
Reviewed-by: Ilya Maximets <i.maximets@ovn.org>
Reviewed-by: Willem de Bruijn <willemb@google.com>
Link: https://patch.msgid.link/6E3A780D-FB87-421F-9964-B1D457D7D106@doyensec.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
[ 7.2 and earlier do not have the put_page() call on the error path ]
Signed-off-by: Ilya Maximets <i.maximets@ovn.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
 net/core/skbuff.c | 5 ++---
 1 file changed, 2 insertions(+), 3 deletions(-)

diff --git a/net/core/skbuff.c b/net/core/skbuff.c
index 71bb4a3b57763..04776a1123342 100644
--- a/net/core/skbuff.c
+++ b/net/core/skbuff.c
@@ -3910,10 +3910,9 @@ skb_zerocopy(struct sk_buff *to, struct sk_buff *from, int len, int hlen)
 
 	skb_len_add(to, len + plen);
 
-	if (unlikely(skb_orphan_frags(from, GFP_ATOMIC))) {
-		skb_tx_error(from);
+	if (unlikely(skb_orphan_frags(from, GFP_ATOMIC)))
 		return -ENOMEM;
-	}
+
 	skb_zerocopy_clone(to, from, GFP_ATOMIC);
 
 	for (i = 0; i < skb_shinfo(from)->nr_frags; i++) {
-- 
2.53.0




^ permalink raw reply related	[flat|nested] 570+ messages in thread

* [PATCH 7.2 002/556] fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
  2026-09-09 13:34 ` [PATCH 7.2 001/556] net: skbuff: dont skb_tx_error() the source skb in skb_zerocopy() Greg Kroah-Hartman
@ 2026-09-09 13:34 ` Greg Kroah-Hartman
  2026-09-09 13:34 ` [PATCH 7.2 003/556] drm/xe: Dont hand out the flat CCS storage as usable VRAM Greg Kroah-Hartman
                   ` (566 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:34 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches,
	HE WEI(ギカク),
	Konstantin Komarov

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: HE WEI(ギカク) <skyexpoc@gmail.com>

commit 7c4841e2a62794a3bab7c1ff0540580f387e377f upstream.

ni_create_attr_list() allocates a fixed buffer of al_aligned(record_size)
(== record_size) bytes and then walks every attribute of the primary MFT
record, writing one ATTR_LIST_ENTRY per attribute and advancing the cursor
by le_size(name_len), with no check against the end of the buffer; the
total size is only computed after the loop.

A minimum-size resident attribute occupies SIZEOF_RESIDENT (0x18 = 24)
bytes on disk, but an unnamed attribute expands to le_size(0) (0x20 = 32)
bytes in the list.  Because the number of attributes in a record is not
bounded (mi_enum_attr() accepts arbitrarily many equal-type, nameless
minimum-size attributes), a crafted record packed with such attributes
produces a list larger than record_size and overflows the heap buffer.

This is reachable from a crafted, loop-mounted NTFS image: opening the file
and adding an attribute (e.g. via setxattr) drives ntfs_set_ea() ->
ni_insert_resident() -> ni_insert_attr() -> ni_ins_attr_ext() ->
ni_create_attr_list().

  BUG: KASAN: slab-out-of-bounds in ni_create_attr_list+0xc48/0x1058
  Write of size 4 at addr ffff000008984c00 by task setfattr/345
   ni_create_attr_list+0xc48/0x1058
   ni_ins_attr_ext+0x510/0x7c0
   ni_insert_attr+0x3f8/0x70c
   ni_insert_resident+0xc8/0x3b0
   ntfs_set_ea+0x66c/0xd28
   ntfs_setxattr+0x4d8/0x5b0
   __arm64_sys_setxattr+0xa4/0x124
  Allocated by task 345:
   ni_create_attr_list+0x188/0x1058
  The buggy address belongs to the cache kmalloc-1k of size 1024
  (the write lands at object+1024).

Size the buffer from the actual attributes instead of assuming a single
record_size is always enough.

Fixes: 4342306f0f0d ("fs/ntfs3: Add file operations and implementation")
Reported-by: HE WEI(ギカク) <skyexpoc@gmail.com>
Signed-off-by: HE WEI(ギカク) <skyexpoc@gmail.com>
Signed-off-by: Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/ntfs3/frecord.c |   20 ++++++++++++++++----
 1 file changed, 16 insertions(+), 4 deletions(-)

--- a/fs/ntfs3/frecord.c
+++ b/fs/ntfs3/frecord.c
@@ -768,10 +768,23 @@ int ni_create_attr_list(struct ntfs_inod
 	rs = sbi->record_size;
 
 	/*
-	 * Skip estimating exact memory requirement.
-	 * Looks like one record_size is always enough.
+	 * Compute the exact size of the attribute list.  Each attribute in the
+	 * record yields one ATTR_LIST_ENTRY of le_size(name_len) bytes.  The
+	 * minimum on-disk attribute is SIZEOF_RESIDENT (0x18) bytes, but an
+	 * unnamed one expands to le_size(0) (0x20) here, so a record crafted
+	 * with many such attributes needs more than a single record_size; the
+	 * previous fixed kzalloc(record_size) could therefore be overflowed by
+	 * an attacker-controlled record.
 	 */
-	le = kzalloc(al_aligned(rs), GFP_NOFS);
+	lsize = 0;
+	attr = NULL;
+	while ((attr = mi_enum_attr(ni, &ni->mi, attr)))
+		lsize += le_size(attr->name_len);
+
+	if (!lsize)
+		return -EINVAL;
+
+	le = kzalloc(al_aligned(lsize), GFP_NOFS);
 	if (!le)
 		return -ENOMEM;
 
@@ -781,7 +794,6 @@ int ni_create_attr_list(struct ntfs_inod
 	attr = NULL;
 	nb = 0;
 	free_b = 0;
-	attr = NULL;
 
 	for (; (attr = mi_enum_attr(ni, &ni->mi, attr)); le = Add2Ptr(le, sz)) {
 		sz = le_size(attr->name_len);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 003/556] drm/xe: Dont hand out the flat CCS storage as usable VRAM
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
  2026-09-09 13:34 ` [PATCH 7.2 001/556] net: skbuff: dont skb_tx_error() the source skb in skb_zerocopy() Greg Kroah-Hartman
  2026-09-09 13:34 ` [PATCH 7.2 002/556] fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list() Greg Kroah-Hartman
@ 2026-09-09 13:34 ` Greg Kroah-Hartman
  2026-09-09 13:34 ` [PATCH 7.2 004/556] mm/page_alloc: dont spin_trylock() in NMI on UP Greg Kroah-Hartman
                   ` (565 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:34 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Linus Torvalds

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Linus Torvalds <torvalds@linux-foundation.org>

commit 818bebeb63dd6bf5f4e07e145f6cdbace520a34c upstream.

get_flat_ccs_offset() reads the base of the flat CCS storage from the
hardware, scales it by the number of enabled L3 nodes, and rounds the
result up to 128K.  Everything below that offset is then handed to the
VRAM allocator as usable memory.

Rounding a limit that means "usable memory ends here" upwards publishes
whatever lies between the real base and the rounded one as free memory,
and that memory belongs to the compression hardware.  The scaled value
has no reason to be 128K aligned, and on a Battlemage G21 with 16 GiB it
is not:

	flat CCS base: raw 0x3fafff800, rounded 0x3fb000000

so the last 2 KiB of page 0x3fafff000 is CCS storage, in the allocator's
pool.  Whatever is allocated there gets that tail overwritten by the
compression hardware, which needs no page-table entry, no buffer object
and no GPU submission to do it, and does it before userspace exists.

On this machine a Mesa VM's level-3 page table landed on that page on
every cold boot.  It lost the entry covering the compositor's
batch-buffer heap, so the compositor's first submission faulted fetching
its batch and gdm restarted it forever: a black screen on an otherwise
working machine.  Restarting gdm cleared it because the next VM's page
tables were allocated somewhere else.

Round down instead, to the page size the allocator works in.  On this
machine that excludes exactly one page.

Reading the reserved page afterwards shows what had been writing it:

	[369] 0xcccc000000000000
	[371] 0xcc77000000000000
	[373] 0xcccc000000000000
	[375] 0xcc77000000000000

compression metadata, two bytes per sixteen, sitting where the driver
used to hand out memory.

The assertion that should have caught this compares the offset against
GSMBASE - ccs_size for equality.  That value is 128K aligned, so it
agrees with the rounded-up offset precisely when the base is not
aligned - the check cannot fail in the case it exists to catch, and is
compiled out unless CONFIG_DRM_XE_DEBUG is set.  Replace it with one
that can fail: CCS storage must not run into GSM.

[ And this was a debug session from hell, enormously helped by an AI
  doing much of the grunt-work.

  I'd like to call it my tireless helper, but the AI several times
  stated flat out that this was impossible and unsolvable and that we
  should just write a report about it.

  I suspect those things have been trained by people who may not be
  quite as stubborn as I am.

  But while the AI was ready to give up several times, it did keep
  adding debug code and analyzing it faithfully when I pushed. So credit
  where credit is due and I let the AI write the commit message above.

  This is basically a one-liner fixing a bogus "round_up()" to a
  "round_down()", but there were 24 patches adding more and more debug
  information to this, and 18 kernel boot to finally narrow it down to
  this.   - Linus ]

Fixes: 37173392741c ("drm/xe/vram: fix ccs offset calculation")
Cc: stable@kernel.org
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/xe/xe_vram.c |   23 ++++++++++++++++++-----
 1 file changed, 18 insertions(+), 5 deletions(-)

--- a/drivers/gpu/drm/xe/xe_vram.c
+++ b/drivers/gpu/drm/xe/xe_vram.c
@@ -89,12 +89,25 @@ static int get_flat_ccs_offset(struct xe
 		offset = offset_hi << 32; /* HW view bits 39:32 */
 		offset |= offset_lo << 6; /* HW view bits 31:6 */
 		offset *= num_enabled; /* convert to SW view */
-		offset = round_up(offset, SZ_128K); /* SW must round up to nearest 128K */
 
-		/* We don't expect any holes */
-		xe_assert_msg(xe, offset == (xe_mmio_read64_2x32(&gt_to_tile(gt)->mmio, GSMBASE) -
-					     ccs_size),
-			      "Hole between CCS and GSM.\n");
+		/*
+		 * Everything below this offset is handed to the VRAM
+		 * allocator, so it has to be the *first* address the
+		 * compression hardware owns, rounded down.  Rounding it up
+		 * publishes CCS storage as free memory.
+		 */
+		offset = round_down(offset, SZ_4K);
+
+		/*
+		 * CCS storage must not run into GSM.  The old check compared
+		 * the offset against GSMBASE - ccs_size for equality, which
+		 * could not fail: that value is 128K aligned, so it agreed
+		 * with the rounded-up offset even when the base was not 128K
+		 * aligned - exactly the case this fixes.
+		 */
+		xe_assert_msg(xe, offset + ccs_size <=
+			      xe_mmio_read64_2x32(&gt_to_tile(gt)->mmio, GSMBASE),
+			      "CCS overlaps GSM.\n");
 	} else {
 		reg = xe_gt_mcr_unicast_read_any(gt, XEHP_FLAT_CCS_BASE_ADDR);
 		offset = (u64)REG_FIELD_GET(XEHP_FLAT_CCS_PTR, reg) * SZ_64K;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 004/556] mm/page_alloc: dont spin_trylock() in NMI on UP
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (2 preceding siblings ...)
  2026-09-09 13:34 ` [PATCH 7.2 003/556] drm/xe: Dont hand out the flat CCS storage as usable VRAM Greg Kroah-Hartman
@ 2026-09-09 13:34 ` Greg Kroah-Hartman
  2026-09-09 13:34 ` [PATCH 7.2 005/556] USB: gadget: ffs: fix mm lifetime handling Greg Kroah-Hartman
                   ` (564 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:34 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Brendan Jackman, sashiko-bot,
	Vlastimil Babka (SUSE), Harry Yoo (Oracle), Brendan Jackman,
	Alexei Starovoitov, Johannes Weiner, Michal Hocko,
	Sebastian Andrzej Siewior, Shakeel Butt, Steven Rostedt,
	Suren Baghdasaryan, Zi Yan, Andrew Morton, Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Brendan Jackman <jackmanb@google.com>

[ Upstream commit 3105ae628fb785d48b49256468be4f21a7b3cfc0 ]

Patch series "mm/page_alloc: fixes for free_pages_nolock() on RT/UP".

Pre-existing bugs found by Sashiko during review of this other series:
https://lore.kernel.org/all/20260703-alloc-trylock-v5-0-c87b714e19d3@google.com/

I have not reproduced these bugs, and I suspect there is no real-world
user that is affected by them.

This patch (of 2):

As noted in can_spin_trylock(), using this is unsafe in this context.
commit 620b46ed6ae17 ("mm/page_alloc: return NULL early from
alloc_frozen_pages_nolock() in NMI on UP") fixed this on the alloc side
but missed the free side.

Impact: If BPF programs using these features in NMI (probably tracing) are
present on non-SMP builds this might crash the kernel and is probably
exploitable by local attackers for privilege escalation.

Link: https://lore.kernel.org/20260715-alloc-nolock-fixes-v1-0-fadc49952dda@google.com
Link: https://lore.kernel.org/20260715-alloc-nolock-fixes-v1-1-fadc49952dda@google.com
Fixes: 8c57b687e833 ("mm, bpf: Introduce free_pages_nolock()")
Signed-off-by: Brendan Jackman <jackmanb@google.com>
Reported-by: sashiko-bot@kernel.org
Closes: https://sashiko.dev/#/patchset/20260703-alloc-trylock-v5-0-c87b714e19d3%40google.com?part=18
Reviewed-by: Vlastimil Babka (SUSE) <vbabka@kernel.org>
Reviewed-by: Harry Yoo (Oracle) <harry@kernel.org>
Cc: Brendan Jackman <brendan.jackman@linux.dev>
Cc: Alexei Starovoitov <ast@kernel.org>
Cc: Johannes Weiner <hannes@cmpxchg.org>
Cc: Michal Hocko <mhocko@suse.com>
Cc: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Cc: Shakeel Butt <shakeel.butt@linux.dev>
Cc: Steven Rostedt <rostedt@goodmis.org>
Cc: Suren Baghdasaryan <surenb@google.com>
Cc: Zi Yan <ziy@nvidia.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/page_alloc.c |    6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

--- a/mm/page_alloc.c
+++ b/mm/page_alloc.c
@@ -2967,8 +2967,10 @@ static void __free_frozen_pages(struct p
 		migratetype = MIGRATE_MOVABLE;
 	}
 
-	if (unlikely((fpi_flags & FPI_TRYLOCK) && IS_ENABLED(CONFIG_PREEMPT_RT)
-		     && (in_nmi() || in_hardirq()))) {
+	if (unlikely((fpi_flags & FPI_TRYLOCK) &&
+		     ((IS_ENABLED(CONFIG_PREEMPT_RT) &&
+		       (in_nmi() || in_hardirq())) ||
+		      (!IS_ENABLED(CONFIG_SMP) && in_nmi())))) {
 		add_page_to_zone_llist(zone, page, order);
 		return;
 	}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 005/556] USB: gadget: ffs: fix mm lifetime handling
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (3 preceding siblings ...)
  2026-09-09 13:34 ` [PATCH 7.2 004/556] mm/page_alloc: dont spin_trylock() in NMI on UP Greg Kroah-Hartman
@ 2026-09-09 13:34 ` Greg Kroah-Hartman
  2026-09-09 13:34 ` [PATCH 7.2 006/556] usb: gadget: f_fs: Fix Use-After-Free in AIO error path Greg Kroah-Hartman
                   ` (563 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:34 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Gabriel Prostitis, Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Gabriel Prostitis <prostitisgabriel@gmail.com>

[ Upstream commit 5eb5c72c72fef76cb765ef1669b62b6a3ba1bfc8 ]

io_data stores a pointer to the submitting task's mm_struct,
but does not currently hold a reference to it while async
requests are pending.

This can result in a use-after-free if the task exits before
completion handling finishes.

Take a reference with mmgrab() when queuing the read request
and release it with mmdrop() on request completion.

Reported-by: Gabriel Prostitis <prostitisgabriel@gmail.com>
Signed-off-by: Gabriel Prostitis <prostitisgabriel@gmail.com>
Link: https://patch.msgid.link/20260601-mm-uaf-fix-v2-1-3c942a707bce@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Stable-dep-of: e78dcb1f7ec2 ("usb: gadget: f_fs: Fix Use-After-Free in AIO error path")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/usb/gadget/function/f_fs.c |   27 ++++++++++++++++++++-------
 1 file changed, 20 insertions(+), 7 deletions(-)

--- a/drivers/usb/gadget/function/f_fs.c
+++ b/drivers/usb/gadget/function/f_fs.c
@@ -873,9 +873,15 @@ static void ffs_user_copy_worker(struct
 	bool kiocb_has_eventfd = io_data->kiocb->ki_flags & IOCB_EVENTFD;
 
 	if (io_data->read && ret > 0) {
-		kthread_use_mm(io_data->mm);
-		ret = ffs_copy_to_iter(io_data->buf, ret, &io_data->data);
-		kthread_unuse_mm(io_data->mm);
+		if (mmget_not_zero(io_data->mm)) {
+			kthread_use_mm(io_data->mm);
+			ret = ffs_copy_to_iter(io_data->buf, ret, &io_data->data);
+			kthread_unuse_mm(io_data->mm);
+			mmput(io_data->mm);
+		} else {
+			ret = -EFAULT;
+		}
+		mmdrop(io_data->mm);
 	}
 
 	io_data->kiocb->ki_complete(io_data->kiocb, ret);
@@ -1270,16 +1276,20 @@ static ssize_t ffs_epfile_write_iter(str
 
 	kiocb->private = p;
 
-	if (p->aio)
+	if (p->aio) {
+		mmgrab(p->mm);
 		kiocb_set_cancel_fn(kiocb, ffs_aio_cancel);
+	}
 
 	res = ffs_epfile_io(kiocb->ki_filp, p);
 	if (res == -EIOCBQUEUED)
 		return res;
-	if (p->aio)
+	if (p->aio) {
+		mmdrop(p->mm);
 		kfree(p);
-	else
+	} else {
 		*from = p->data;
+	}
 	return res;
 }
 
@@ -1314,14 +1324,17 @@ static ssize_t ffs_epfile_read_iter(stru
 
 	kiocb->private = p;
 
-	if (p->aio)
+	if (p->aio) {
+		mmgrab(p->mm);
 		kiocb_set_cancel_fn(kiocb, ffs_aio_cancel);
+	}
 
 	res = ffs_epfile_io(kiocb->ki_filp, p);
 	if (res == -EIOCBQUEUED)
 		return res;
 
 	if (p->aio) {
+		mmdrop(p->mm);
 		kfree(p->to_free);
 		kfree(p);
 	} else {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 006/556] usb: gadget: f_fs: Fix Use-After-Free in AIO error path
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (4 preceding siblings ...)
  2026-09-09 13:34 ` [PATCH 7.2 005/556] USB: gadget: ffs: fix mm lifetime handling Greg Kroah-Hartman
@ 2026-09-09 13:34 ` Greg Kroah-Hartman
  2026-09-09 13:34 ` [PATCH 7.2 007/556] zram: move lockmap to be per-zram instead per table Greg Kroah-Hartman
                   ` (562 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:34 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Xingyu Jin, Neill Kapron,
	Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Neill Kapron <nkapron@google.com>

[ Upstream commit e78dcb1f7ec271449c54984dc90c62a5ba272de7 ]

In ffs_epfile_write_iter() and ffs_epfile_read_iter(), when ffs_epfile_io()
fails with an error other than -EIOCBQUEUED, the io_data structure (`p`) is
freed. However, for AIO operations, the kiocb cancel function was already
armed and kiocb->private was set to `p`.

If a concurrent cancel operation (such as sys_io_cancel()) executes after
ffs_epfile_io() fails but before the function frees `p`, a Use-After-Free
can occur when the cancellation handler accesses the freed pointer.

To securely fix this race condition, we must properly un-arm the
cancellation. Invoking `kiocb->ki_complete()` does exactly this by
acquiring `ctx->ctx_lock` and safely removing the kiocb from the active
sequence. In doing so, it ensures that a parallel io_cancel can no longer
discover the kiocb, effectively closing the race window.

We then return -EIOCBQUEUED to notify the VFS layer that the kiocb has been
consumed and it should avoid attempting to complete the request again or
triggering subsequent completion handlers.

Fixes: de2080d41b5d ("gadget/function/f_fs.c: close leaks")
Cc: stable@vger.kernel.org
Reported-by: Xingyu Jin <xingyuj@google.com>
Assisted-by: Antigravity:gemini-3.1-pro
Signed-off-by: Neill Kapron <nkapron@google.com>
Link: https://patch.msgid.link/20260724235100.106011-1-nkapron@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/usb/gadget/function/f_fs.c |    4 ++++
 1 file changed, 4 insertions(+)

--- a/drivers/usb/gadget/function/f_fs.c
+++ b/drivers/usb/gadget/function/f_fs.c
@@ -1285,8 +1285,10 @@ static ssize_t ffs_epfile_write_iter(str
 	if (res == -EIOCBQUEUED)
 		return res;
 	if (p->aio) {
+		kiocb->ki_complete(kiocb, res);
 		mmdrop(p->mm);
 		kfree(p);
+		return -EIOCBQUEUED;
 	} else {
 		*from = p->data;
 	}
@@ -1334,9 +1336,11 @@ static ssize_t ffs_epfile_read_iter(stru
 		return res;
 
 	if (p->aio) {
+		kiocb->ki_complete(kiocb, res);
 		mmdrop(p->mm);
 		kfree(p->to_free);
 		kfree(p);
+		return -EIOCBQUEUED;
 	} else {
 		*to = p->data;
 	}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 007/556] zram: move lockmap to be per-zram instead per table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (5 preceding siblings ...)
  2026-09-09 13:34 ` [PATCH 7.2 006/556] usb: gadget: f_fs: Fix Use-After-Free in AIO error path Greg Kroah-Hartman
@ 2026-09-09 13:34 ` Greg Kroah-Hartman
  2026-09-09 13:34 ` [PATCH 7.2 008/556] zram: fix slot lock bit position on big-endian 64-bit Greg Kroah-Hartman
                   ` (561 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:34 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sebastian Andrzej Siewior,
	Sergey Senozhatsky, Jens Axboe, Minchan Kim, Andrew Morton,
	Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sebastian Andrzej Siewior <bigeasy@linutronix.de>

[ Upstream commit dbb7ba9c7fa81a48ed2a108ad684cf3655f3ae4b ]

Patch series "zram: lockmap tweaks".

This patch (of 2):

The zram object contains an array zram_table_entry.  Each one has a `lock'
variable and each has a matching struct lockdep_map.  This mimics a struct
mutex.

It uses always the same key for all lockdep_map instances.  This makes it
look like the same lock to lockdep.  Therefore it could be reduced to have
one lockdep_map per struct zram.

Use only one struct lockdep_map per struct zram.

Link: https://lore.kernel.org/20260714141300.3945672-1-bigeasy@linutronix.de
Link: https://lore.kernel.org/20260714141300.3945672-2-bigeasy@linutronix.de
Signed-off-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Reviewed-by: Sergey Senozhatsky <senozhatsky@chromium.org>
Tested-by: Sergey Senozhatsky <senozhatsky@chromium.org>
Cc: Jens Axboe <axboe@kernel.dk>
Cc: Minchan Kim <minchan@kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Stable-dep-of: a8b5875741d4 ("zram: fix slot lock bit position on big-endian 64-bit")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/block/zram/zram_drv.c |   21 +++++++++------------
 drivers/block/zram/zram_drv.h |    2 +-
 2 files changed, 10 insertions(+), 13 deletions(-)

--- a/drivers/block/zram/zram_drv.c
+++ b/drivers/block/zram/zram_drv.c
@@ -57,14 +57,12 @@ static size_t huge_class_size;
 static const struct block_device_operations zram_devops;
 
 static void slot_free(struct zram *zram, u32 index);
-#define slot_dep_map(zram, index) (&(zram)->table[(index)].dep_map)
 
-static void slot_lock_init(struct zram *zram, u32 index)
+static void slot_lock_init(struct zram *zram)
 {
 	static struct lock_class_key __key;
 
-	lockdep_init_map(slot_dep_map(zram, index), "zram->table[index].lock",
-			 &__key, 0);
+	lockdep_init_map(&zram->table_lock_map, "zram->table[index].lock", &__key, 0);
 }
 
 /*
@@ -84,8 +82,8 @@ static __must_check bool slot_trylock(st
 	unsigned long *lock = &zram->table[index].__lock;
 
 	if (!test_and_set_bit_lock(ZRAM_ENTRY_LOCK, lock)) {
-		mutex_acquire(slot_dep_map(zram, index), 0, 1, _RET_IP_);
-		lock_acquired(slot_dep_map(zram, index), _RET_IP_);
+		mutex_acquire(&zram->table_lock_map, 0, 1, _RET_IP_);
+		lock_acquired(&zram->table_lock_map, _RET_IP_);
 		return true;
 	}
 
@@ -96,16 +94,16 @@ static void slot_lock(struct zram *zram,
 {
 	unsigned long *lock = &zram->table[index].__lock;
 
-	mutex_acquire(slot_dep_map(zram, index), 0, 0, _RET_IP_);
+	mutex_acquire(&zram->table_lock_map, 0, 0, _RET_IP_);
 	wait_on_bit_lock(lock, ZRAM_ENTRY_LOCK, TASK_UNINTERRUPTIBLE);
-	lock_acquired(slot_dep_map(zram, index), _RET_IP_);
+	lock_acquired(&zram->table_lock_map, _RET_IP_);
 }
 
 static void slot_unlock(struct zram *zram, u32 index)
 {
 	unsigned long *lock = &zram->table[index].__lock;
 
-	mutex_release(slot_dep_map(zram, index), _RET_IP_);
+	mutex_release(&zram->table_lock_map, _RET_IP_);
 	clear_and_wake_up_bit(ZRAM_ENTRY_LOCK, lock);
 }
 
@@ -1989,7 +1987,7 @@ static void zram_meta_free(struct zram *
 
 static bool zram_meta_alloc(struct zram *zram, u64 disksize)
 {
-	size_t num_pages, index;
+	size_t num_pages;
 
 	num_pages = disksize >> PAGE_SHIFT;
 	zram->table = vzalloc(array_size(num_pages, sizeof(*zram->table)));
@@ -2006,8 +2004,7 @@ static bool zram_meta_alloc(struct zram
 	if (!huge_class_size)
 		huge_class_size = zs_huge_class_size(zram->mem_pool);
 
-	for (index = 0; index < num_pages; index++)
-		slot_lock_init(zram, index);
+	slot_lock_init(zram);
 
 	return true;
 }
--- a/drivers/block/zram/zram_drv.h
+++ b/drivers/block/zram/zram_drv.h
@@ -74,7 +74,6 @@ struct zram_table_entry {
 #endif
 		} attr;
 	};
-	struct lockdep_map dep_map;
 };
 
 struct zram_stats {
@@ -107,6 +106,7 @@ struct zram_stats {
 
 struct zram {
 	struct zram_table_entry *table;
+	struct lockdep_map table_lock_map;
 	struct zs_pool *mem_pool;
 	struct zcomp *comps[ZRAM_MAX_COMPS];
 	struct zcomp_params params[ZRAM_MAX_COMPS];



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 008/556] zram: fix slot lock bit position on big-endian 64-bit
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (6 preceding siblings ...)
  2026-09-09 13:34 ` [PATCH 7.2 007/556] zram: move lockmap to be per-zram instead per table Greg Kroah-Hartman
@ 2026-09-09 13:34 ` Greg Kroah-Hartman
  2026-09-09 13:34 ` [PATCH 7.2 009/556] ceph: properly decrypt filenames in vmalloc() buffers Greg Kroah-Hartman
                   ` (560 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:34 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Carlier, Sergey Senozhatsky,
	Minchan Kim, Andrew Morton, Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Carlier <devnexen@gmail.com>

[ Upstream commit a8b5875741d416703e19ad8eeac6fce8a12bd6e4 ]

The slot lock is a bit operation on the whole __lock word, which flags and
ac_time alias as two u32s.  On little-endian the lock bit lands in the
position ZRAM_ENTRY_LOCK reserves in flags, so the aliasing works out.  On
64-bit big-endian it lands in ac_time instead: with
ZRAM_TRACK_ENTRY_ACTIME enabled, storing the access time from
mark_slot_accessed() or slot_free() wipes out the held lock bit, letting
another CPU take the same slot lock; an access time value with that bit
set makes the slot look locked forever.

Shift the lock bit into the flags half of the word on big-endian 64-bit.

Link: https://lore.kernel.org/20260810202241.2436603-1-devnexen@gmail.com
Fixes: 2e8ff2f51dde ("zram: use u32 for entry ac_time tracking")
Signed-off-by: David Carlier <devnexen@gmail.com>
Reviewed-by: Sergey Senozhatsky <senozhatsky@chromium.org>
Cc: Minchan Kim <minchan@kernel.org>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/block/zram/zram_drv.c |    6 +++---
 drivers/block/zram/zram_drv.h |   14 ++++++++++++++
 2 files changed, 17 insertions(+), 3 deletions(-)

--- a/drivers/block/zram/zram_drv.c
+++ b/drivers/block/zram/zram_drv.c
@@ -81,7 +81,7 @@ static __must_check bool slot_trylock(st
 {
 	unsigned long *lock = &zram->table[index].__lock;
 
-	if (!test_and_set_bit_lock(ZRAM_ENTRY_LOCK, lock)) {
+	if (!test_and_set_bit_lock(ZRAM_ENTRY_LOCK_BIT, lock)) {
 		mutex_acquire(&zram->table_lock_map, 0, 1, _RET_IP_);
 		lock_acquired(&zram->table_lock_map, _RET_IP_);
 		return true;
@@ -95,7 +95,7 @@ static void slot_lock(struct zram *zram,
 	unsigned long *lock = &zram->table[index].__lock;
 
 	mutex_acquire(&zram->table_lock_map, 0, 0, _RET_IP_);
-	wait_on_bit_lock(lock, ZRAM_ENTRY_LOCK, TASK_UNINTERRUPTIBLE);
+	wait_on_bit_lock(lock, ZRAM_ENTRY_LOCK_BIT, TASK_UNINTERRUPTIBLE);
 	lock_acquired(&zram->table_lock_map, _RET_IP_);
 }
 
@@ -104,7 +104,7 @@ static void slot_unlock(struct zram *zra
 	unsigned long *lock = &zram->table[index].__lock;
 
 	mutex_release(&zram->table_lock_map, _RET_IP_);
-	clear_and_wake_up_bit(ZRAM_ENTRY_LOCK, lock);
+	clear_and_wake_up_bit(ZRAM_ENTRY_LOCK_BIT, lock);
 }
 
 static inline bool init_done(struct zram *zram)
--- a/drivers/block/zram/zram_drv.h
+++ b/drivers/block/zram/zram_drv.h
@@ -15,6 +15,7 @@
 #ifndef _ZRAM_DRV_H_
 #define _ZRAM_DRV_H_
 
+#include <asm/byteorder.h>
 #include <linux/rwsem.h>
 #include <linux/zsmalloc.h>
 
@@ -58,6 +59,19 @@ enum zram_pageflags {
 };
 
 /*
+ * The slot lock is a bit-wait lock on the whole __lock word, while
+ * flags and ac_time alias that word as two u32s.  The lock bit must
+ * land in the slot that ZRAM_ENTRY_LOCK reserves in attr.flags; on
+ * 64-bit big-endian the flags word maps to the upper half of __lock,
+ * so the bit position has to be shifted up.
+ */
+#if defined(CONFIG_64BIT) && defined(__BIG_ENDIAN)
+#define ZRAM_ENTRY_LOCK_BIT  (ZRAM_ENTRY_LOCK + 32)
+#else
+#define ZRAM_ENTRY_LOCK_BIT  ZRAM_ENTRY_LOCK
+#endif
+
+/*
  * Allocated for each disk page.  We use bit-lock (ZRAM_ENTRY_LOCK bit
  * of flags) to save memory.  There can be plenty of entries and standard
  * locking primitives (e.g. mutex) will significantly increase sizeof()



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 009/556] ceph: properly decrypt filenames in vmalloc() buffers
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (7 preceding siblings ...)
  2026-09-09 13:34 ` [PATCH 7.2 008/556] zram: fix slot lock bit position on big-endian 64-bit Greg Kroah-Hartman
@ 2026-09-09 13:34 ` Greg Kroah-Hartman
  2026-09-09 13:34 ` [PATCH 7.2 010/556] HID: sony: use guard() and scoped_guard() Greg Kroah-Hartman
                   ` (559 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:34 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sam Edwards, Alex Markuze,
	Ilya Dryomov, Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sam Edwards <cfsworks@gmail.com>

[ Upstream commit e939fc6a7bd969a58a150b7f188c1047138403e3 ]

The fscrypt subsystem uses the scatterlist crypto API, inheriting its
requirement that any buffers are in the linear mapping region. However,
the messenger client uses kvmalloc() to create buffers for messages,
which will occasionally place those buffers in the vmalloc() region when
physical memory fragmentation doesn't permit a large enough kmalloc().
The various callers of ceph_fname_to_usr() directly pass (slices of) raw
messages from the MDS without considering that the messages may be in
vmalloc() buffers, resulting in oopses especially on non-x86 platforms
(see 'Closes:' for more details and a reproducer).

Make ceph_fname_to_usr() explicitly tolerant of vmalloc()-allocated
fname->ctext, fname->name, and/or oname->name buffers, using `tname`
(which, when non-null, must be a linear address; when null, is briefly
allocated as necessary) as a bounce buffer to avoid passing any
inappropriate addresses to fscrypt_fname_disk_to_usr().

Additionally change parse_reply_info_readdir() -- the only function to
supply its own `tname` -- to follow the new "tname must never come from
vmalloc()" rule by passing NULL when the message is not in the linear
region. Though this causes a per-dentry kmalloc()+kfree(), this overhead
exists only when processing the minority of messages that spill into
vmalloc(). My (crude) testing puts this at only about 1 in 8,000 readdir
messages. Still, if the overhead proves unreasonable in the future, it
is easy enough to mitigate: a future change could allocate a bounce
buffer in parse_reply_info_readdir() and use that as `tname` instead.

Cc: stable@vger.kernel.org # 888d33b208bd: ceph: pass fscrypt `tname` buffers directly
Cc: stable@vger.kernel.org
Fixes: 457117f077c6 ("ceph: add helpers for converting names for userland presentation")
Closes: https://lore.kernel.org/ceph-devel/20260415034020.11530-1-CFSworks@gmail.com/
Signed-off-by: Sam Edwards <CFSworks@gmail.com>
Reviewed-by: Alex Markuze <amarkuze@redhat.com>
Signed-off-by: Ilya Dryomov <idryomov@gmail.com>
[ adapted raw tname buffer access to the existing struct fscrypt_str interface ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/ceph/crypto.c     |   50 +++++++++++++++++++++++++++++++++++++++-----------
 fs/ceph/mds_client.c |    8 ++++++--
 2 files changed, 45 insertions(+), 13 deletions(-)

--- a/fs/ceph/crypto.c
+++ b/fs/ceph/crypto.c
@@ -298,6 +298,11 @@ out:
  * Otherwise, base64 decode the string, and then ask fscrypt to format it
  * for userland presentation.
  *
+ * Though the fscrypt/crypto subsystems broadly expect all buffers to be in the
+ * linear-mapped region, this function slightly relaxes those requirements:
+ * fname->ctext, fname->name, and oname->name may be vmalloc(), but not
+ * tname->name.
+ *
  * Returns 0 on success or negative error code on error.
  */
 int ceph_fname_to_usr(const struct ceph_fname *fname, struct fscrypt_str *tname,
@@ -305,11 +310,15 @@ int ceph_fname_to_usr(const struct ceph_
 {
 	struct inode *dir = fname->dir;
 	struct fscrypt_str _tname = FSTR_INIT(NULL, 0);
+	struct fscrypt_str _oname;
 	struct fscrypt_str iname;
 	char *name = fname->name;
 	int name_len = fname->name_len;
 	int ret;
 
+	if (WARN_ON_ONCE(tname && is_vmalloc_addr(tname->name)))
+		return -EIO;
+
 	/* Sanity check that the resulting name will fit in the buffer */
 	if (fname->name_len > NAME_MAX || fname->ctext_len > NAME_MAX)
 		return -EIO;
@@ -350,31 +359,50 @@ int ceph_fname_to_usr(const struct ceph_
 		goto out_inode;
 	}
 
+	if ((!tname || !tname->name) &&
+	    (fname->ctext_len == 0 ||
+	     unlikely(is_vmalloc_addr(fname->ctext)) ||
+	     unlikely(is_vmalloc_addr(oname->name)))) {
+		ret = fscrypt_fname_alloc_buffer(NAME_MAX, &_tname);
+		if (ret)
+			goto out_inode;
+		tname = &_tname;
+	}
+
 	if (fname->ctext_len == 0) {
 		int declen;
 
-		if (!tname) {
-			ret = fscrypt_fname_alloc_buffer(NAME_MAX, &_tname);
-			if (ret)
-				goto out_inode;
-			tname = &_tname;
-		}
-
-		declen = base64_decode(name, name_len,
-				       tname->name, false, BASE64_IMAP);
+		declen = base64_decode(name, name_len, tname->name, false,
+				       BASE64_IMAP);
 		if (declen <= 0) {
 			ret = -EIO;
 			goto out;
 		}
 		iname.name = tname->name;
 		iname.len = declen;
+	} else if (unlikely(is_vmalloc_addr(fname->ctext))) {
+		memcpy(tname->name, fname->ctext, fname->ctext_len);
+
+		iname.name = tname->name;
+		iname.len = fname->ctext_len;
 	} else {
 		iname.name = fname->ctext;
 		iname.len = fname->ctext_len;
 	}
 
-	ret = fscrypt_fname_disk_to_usr(dir, 0, 0, &iname, oname);
-	if (!ret && (dir != fname->dir)) {
+	_oname.name = unlikely(is_vmalloc_addr(oname->name)) ?
+		      tname->name : oname->name;
+	_oname.len = oname->len;
+
+	ret = fscrypt_fname_disk_to_usr(dir, 0, 0, &iname, &_oname);
+	if (ret)
+		goto out;
+
+	if (unlikely(is_vmalloc_addr(oname->name)))
+		memcpy(oname->name, _oname.name, _oname.len);
+	oname->len = _oname.len;
+
+	if (dir != fname->dir) {
 		char tmp_buf[BASE64_CHARS(NAME_MAX)];
 
 		name_len = snprintf(tmp_buf, sizeof(tmp_buf), "_%.*s_%llu",
--- a/fs/ceph/mds_client.c
+++ b/fs/ceph/mds_client.c
@@ -541,9 +541,13 @@ static int parse_reply_info_readdir(void
 			 * to do the base64_decode in-place. It's
 			 * safe because the decoded string should
 			 * always be shorter, which is 3/4 of origin
-			 * string.
+			 * string. If this message was allocated with
+			 * vmalloc() (happens, but rarely), leave it
+			 * NULL and let ceph_fname_to_usr() allocate
+			 * suitable temporary working space instead.
 			 */
-			tname.name = _name;
+			if (likely(!is_vmalloc_addr(_name)))
+				tname.name = _name;
 
 			/*
 			 * Set oname to _name too, and this will be



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 010/556] HID: sony: use guard() and scoped_guard()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (8 preceding siblings ...)
  2026-09-09 13:34 ` [PATCH 7.2 009/556] ceph: properly decrypt filenames in vmalloc() buffers Greg Kroah-Hartman
@ 2026-09-09 13:34 ` Greg Kroah-Hartman
  2026-09-09 13:34 ` [PATCH 7.2 011/556] HID: sony: clean up device list on probe failure Greg Kroah-Hartman
                   ` (558 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:34 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Rosalie Wanders, Jiri Kosina,
	Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Rosalie Wanders <rosalie@mailbox.org>

[ Upstream commit da4f817ad273bca9aefd8636d347a8c101069111 ]

This replaces the spin_lock_irqsave() and spin_unlock_irqrestore() calls
with the RAII guard() and scoped_guard().

Signed-off-by: Rosalie Wanders <rosalie@mailbox.org>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Stable-dep-of: 7c65699a3a31 ("HID: sony: clean up device list on probe failure")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/hid/hid-sony.c |   62 ++++++++++++++++++++-----------------------------
 1 file changed, 26 insertions(+), 36 deletions(-)

--- a/drivers/hid/hid-sony.c
+++ b/drivers/hid/hid-sony.c
@@ -29,6 +29,7 @@
  * There will be no PIN request from the device.
  */
 
+#include <linux/cleanup.h>
 #include <linux/device.h>
 #include <linux/hid.h>
 #include <linux/module.h>
@@ -569,14 +570,12 @@ static void sony_set_leds(struct sony_sc
 static inline void sony_schedule_work(struct sony_sc *sc,
 				      enum sony_worker which)
 {
-	unsigned long flags;
-
 	switch (which) {
 	case SONY_WORKER_STATE:
-		spin_lock_irqsave(&sc->lock, flags);
-		if (!sc->defer_initialization && sc->state_worker_initialized)
-			schedule_work(&sc->state_worker);
-		spin_unlock_irqrestore(&sc->lock, flags);
+		scoped_guard(spinlock_irqsave, &sc->lock) {
+			if (!sc->defer_initialization && sc->state_worker_initialized)
+				schedule_work(&sc->state_worker);
+		}
 		break;
 	}
 }
@@ -949,7 +948,6 @@ static const u8 *sony_report_fixup(struc
 static void sixaxis_parse_report(struct sony_sc *sc, u8 *rd, int size)
 {
 	static const u8 sixaxis_battery_capacity[] = { 0, 1, 25, 50, 75, 100 };
-	unsigned long flags;
 	int offset;
 	u8 index;
 	u8 battery_capacity;
@@ -972,10 +970,10 @@ static void sixaxis_parse_report(struct
 		battery_status = POWER_SUPPLY_STATUS_DISCHARGING;
 	}
 
-	spin_lock_irqsave(&sc->lock, flags);
-	sc->battery_capacity = battery_capacity;
-	sc->battery_status = battery_status;
-	spin_unlock_irqrestore(&sc->lock, flags);
+	scoped_guard(spinlock_irqsave, &sc->lock) {
+		sc->battery_capacity = battery_capacity;
+		sc->battery_status = battery_status;
+	}
 
 	if (sc->quirks & SIXAXIS_CONTROLLER) {
 		int val;
@@ -1092,7 +1090,6 @@ static void rb4_ps5_guitar_parse_report(
 	u8 battery_data;
 	u8 battery_capacity;
 	u8 battery_status;
-	unsigned long flags;
 
 	/*
 	 * Rock Band 4 PS5 guitars have whammy and
@@ -1132,10 +1129,10 @@ static void rb4_ps5_guitar_parse_report(
 		break;
 	}
 
-	spin_lock_irqsave(&sc->lock, flags);
-	sc->battery_capacity = battery_capacity;
-	sc->battery_status = battery_status;
-	spin_unlock_irqrestore(&sc->lock, flags);
+	scoped_guard(spinlock_irqsave, &sc->lock) {
+		sc->battery_capacity = battery_capacity;
+		sc->battery_status = battery_status;
+	}
 
 	input_sync(sc->input_dev);
 }
@@ -1869,15 +1866,14 @@ static int sony_battery_get_property(str
 				     union power_supply_propval *val)
 {
 	struct sony_sc *sc = power_supply_get_drvdata(psy);
-	unsigned long flags;
 	int ret = 0;
 	u8 battery_capacity;
 	int battery_status;
 
-	spin_lock_irqsave(&sc->lock, flags);
-	battery_capacity = sc->battery_capacity;
-	battery_status = sc->battery_status;
-	spin_unlock_irqrestore(&sc->lock, flags);
+	scoped_guard(spinlock_irqsave, &sc->lock) {
+		battery_capacity = sc->battery_capacity;
+		battery_status = sc->battery_status;
+	}
 
 	switch (psp) {
 	case POWER_SUPPLY_PROP_PRESENT:
@@ -1959,10 +1955,9 @@ static inline int sony_compare_connectio
 static int sony_check_add_dev_list(struct sony_sc *sc)
 {
 	struct sony_sc *entry;
-	unsigned long flags;
 	int ret;
 
-	spin_lock_irqsave(&sony_dev_list_lock, flags);
+	guard(spinlock_irqsave)(&sony_dev_list_lock);
 
 	list_for_each_entry(entry, &sony_device_list, list_node) {
 		ret = memcmp(sc->mac_address, entry->mac_address,
@@ -1976,26 +1971,23 @@ static int sony_check_add_dev_list(struc
 				"controller with MAC address %pMR already connected\n",
 				sc->mac_address);
 			}
-			goto unlock;
+			goto out;
 		}
 	}
 
 	ret = 0;
 	list_add(&(sc->list_node), &sony_device_list);
 
-unlock:
-	spin_unlock_irqrestore(&sony_dev_list_lock, flags);
+out:
 	return ret;
 }
 
 static void sony_remove_dev_list(struct sony_sc *sc)
 {
-	unsigned long flags;
-
 	if (sc->list_node.next) {
-		spin_lock_irqsave(&sony_dev_list_lock, flags);
-		list_del(&(sc->list_node));
-		spin_unlock_irqrestore(&sony_dev_list_lock, flags);
+		scoped_guard(spinlock_irqsave, &sony_dev_list_lock) {
+			list_del(&(sc->list_node));
+		}
 	}
 }
 
@@ -2123,12 +2115,10 @@ static inline void sony_init_output_repo
 
 static inline void sony_cancel_work_sync(struct sony_sc *sc)
 {
-	unsigned long flags;
-
 	if (sc->state_worker_initialized) {
-		spin_lock_irqsave(&sc->lock, flags);
-		sc->state_worker_initialized = 0;
-		spin_unlock_irqrestore(&sc->lock, flags);
+		scoped_guard(spinlock_irqsave, &sc->lock) {
+			sc->state_worker_initialized = 0;
+		}
 		cancel_work_sync(&sc->state_worker);
 	}
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 011/556] HID: sony: clean up device list on probe failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (9 preceding siblings ...)
  2026-09-09 13:34 ` [PATCH 7.2 010/556] HID: sony: use guard() and scoped_guard() Greg Kroah-Hartman
@ 2026-09-09 13:34 ` Greg Kroah-Hartman
  2026-09-09 13:34 ` [PATCH 7.2 012/556] ACPI: battery: Use kstrtoul() over sscanf("%lu\n") Greg Kroah-Hartman
                   ` (557 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:34 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Doruk Tan Ozturk, Jiri Kosina,
	Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Doruk Tan Ozturk <doruk@0sec.ai>

[ Upstream commit 7c65699a3a311198a07659a614fe64d45924839e ]

sony_input_configured() adds some controllers to sony_device_list before
HID core registers their input devices. input_register_device() can fail
after the callback returns successfully. sony_probe() then observes that
HID_CLAIMED_INPUT is clear and unwinds, but only stops the HID hardware.
The devres-managed sony_sc is freed while its list node remains linked, so
the next matching controller traverses freed memory.

Initialize the list node and device ID to inactive states. Make list
removal idempotent and run the driver-private cleanup on every probe
failure path. This also makes a second cleanup safe when
sony_input_configured() already unwound a partial initialization before
sony_probe() handles the missing input claim.

Found by 0sec (https://0sec.ai) using automated source analysis;
verified against the HID input registration and probe unwind paths.

Fixes: 4f967f6d7374 ("HID: sony: Fix memory issue when connecting device using both Bluetooth and USB")
Cc: stable@vger.kernel.org
Reported-by: Doruk Tan Ozturk <doruk@0sec.ai>
Link: https://lore.kernel.org/linux-input/20260724143925.007D61F00A3A@smtp.kernel.org/
Assisted-by: 0sec:multi-model
Signed-off-by: Doruk Tan Ozturk <doruk@0sec.ai>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/hid/hid-sony.c |   33 +++++++++++++++++----------------
 1 file changed, 17 insertions(+), 16 deletions(-)

--- a/drivers/hid/hid-sony.c
+++ b/drivers/hid/hid-sony.c
@@ -1984,11 +1984,10 @@ out:
 
 static void sony_remove_dev_list(struct sony_sc *sc)
 {
-	if (sc->list_node.next) {
-		scoped_guard(spinlock_irqsave, &sony_dev_list_lock) {
-			list_del(&(sc->list_node));
-		}
-	}
+	guard(spinlock_irqsave)(&sony_dev_list_lock);
+
+	if (!list_empty(&sc->list_node))
+		list_del_init(&sc->list_node);
 }
 
 static int sony_get_bt_devaddr(struct sony_sc *sc)
@@ -2123,6 +2122,13 @@ static inline void sony_cancel_work_sync
 	}
 }
 
+static void sony_cleanup(struct sony_sc *sc)
+{
+	sony_cancel_work_sync(sc);
+	sony_remove_dev_list(sc);
+	sony_release_device_id(sc);
+}
+
 static int sony_input_configured(struct hid_device *hdev,
 					struct hid_input *hidinput)
 {
@@ -2296,9 +2302,7 @@ static int sony_input_configured(struct
 err_close:
 	hid_hw_close(hdev);
 err_stop:
-	sony_cancel_work_sync(sc);
-	sony_remove_dev_list(sc);
-	sony_release_device_id(sc);
+	sony_cleanup(sc);
 	return ret;
 }
 
@@ -2322,6 +2326,8 @@ static int sony_probe(struct hid_device
 		return -ENOMEM;
 
 	spin_lock_init(&sc->lock);
+	INIT_LIST_HEAD(&sc->list_node);
+	sc->device_id = -1;
 
 	sc->quirks = quirks;
 	hid_set_drvdata(hdev, sc);
@@ -2350,6 +2356,7 @@ static int sony_probe(struct hid_device
 	ret = hid_hw_start(hdev, connect_mask);
 	if (ret) {
 		hid_err(hdev, "hw start failed\n");
+		sony_cleanup(sc);
 		return ret;
 	}
 
@@ -2404,7 +2411,7 @@ static int sony_probe(struct hid_device
 
 err:
 	usb_free_urb(sc->ghl_urb);
-
+	sony_cleanup(sc);
 	hid_hw_stop(hdev);
 	return ret;
 }
@@ -2421,13 +2428,7 @@ static void sony_remove(struct hid_devic
 	}
 
 	hid_hw_close(hdev);
-
-	sony_cancel_work_sync(sc);
-
-	sony_remove_dev_list(sc);
-
-	sony_release_device_id(sc);
-
+	sony_cleanup(sc);
 	hid_hw_stop(hdev);
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 012/556] ACPI: battery: Use kstrtoul() over sscanf("%lu\n")
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (10 preceding siblings ...)
  2026-09-09 13:34 ` [PATCH 7.2 011/556] HID: sony: clean up device list on probe failure Greg Kroah-Hartman
@ 2026-09-09 13:34 ` Greg Kroah-Hartman
  2026-09-09 13:34 ` [PATCH 7.2 013/556] ACPI: battery: Protect all properties with a separated mutex Greg Kroah-Hartman
                   ` (556 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:34 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Avraham Hollander, Rong Zhang,
	Rafael J. Wysocki, Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Rong Zhang <i@rong.moe>

[ Upstream commit 57346c4d78d38b357dbe9ef16d3f63bf4610c039 ]

It is more preferred to use kstrto*() to parse a single number. The
function family properly returns an errno on error and is the correct
mechanism to parse data from sysfs.

The number base is set to 10 in order not to break the ABI.

Tested-by: Avraham Hollander <anhollander516@gmail.com>
Signed-off-by: Rong Zhang <i@rong.moe>
Link: https://patch.msgid.link/20260718-b4-acpi-battery-notification-v4-2-599c8ed1072f@rong.moe
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Stable-dep-of: 9e409f1dff78 ("ACPI: battery: Protect all properties with a separated mutex")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/acpi/battery.c |    8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

--- a/drivers/acpi/battery.c
+++ b/drivers/acpi/battery.c
@@ -668,9 +668,13 @@ static ssize_t acpi_battery_alarm_store(
 {
 	unsigned long x;
 	struct acpi_battery *battery = to_acpi_battery(dev_get_drvdata(dev));
+	int err;
 
-	if (sscanf(buf, "%lu\n", &x) == 1)
-		battery->alarm = x/1000;
+	err = kstrtoul(buf, 10, &x);
+	if (err)
+		return err;
+
+	battery->alarm = x / 1000;
 	if (acpi_battery_present(battery))
 		acpi_battery_set_alarm(battery);
 	return count;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 013/556] ACPI: battery: Protect all properties with a separated mutex
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (11 preceding siblings ...)
  2026-09-09 13:34 ` [PATCH 7.2 012/556] ACPI: battery: Use kstrtoul() over sscanf("%lu\n") Greg Kroah-Hartman
@ 2026-09-09 13:34 ` Greg Kroah-Hartman
  2026-09-09 13:34 ` [PATCH 7.2 014/556] KVM: x86/mmu: Fold kvm_mmu_zap_memslot() into kvm_arch_flush_shadow_memslot() Greg Kroah-Hartman
                   ` (555 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:34 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Rick, Avraham Hollander, Rong Zhang,
	Rafael J. Wysocki, Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Rong Zhang <i@rong.moe>

[ Upstream commit 9e409f1dff7841634e4b101111d6427f979c0aac ]

The acpi_battery_get_property() callback calls acpi_battery_get_state()
without any lock held. On some devices, it happens that the property
cache has expired before a uevent reaches userspace, triggering
simultaneous attempts to evaluate _BST. See [1] for an analysis to sysrq
stacktraces on one of the these devices.

In a few cases, including when the AML is sleeping or acquiring a mutex,
ACPICA drops the namespace and interpreter locks and allows the
evaluation of _BST to start while another task is still evaluating it.
This could somehow confuse the interpreter and lead to chaos in AML
mutexes on some devices, see [2] for an example.

Not holding the lock is also prone to race conditions, for example:

                CPU0                | 	         CPU1
acpi_battery_get_property()         |
  acpi_battery_get_state()          |
    [update_time expired]           |
    extract_package()               | acpi_battery_get_property()
    battery->update_time = jiffies  |   acpi_battery_get_state()
    kfree()                         |     [up to date]
                                    |   [read capacity_now]
    [fix capacity_now due to quirk] |

where CPU1 gets raw capacity_now before CPU0 fixes it to a meaningful
value.

The existing mutex update_lock is not applicapable for
acpi_battery_get_property(), as some code path could call or wait for
acpi_battery_get_property() while holding update_lock.

Therefore, introduce a mutex called property_lock to protect all
accesses to battery properties, so that acpi_battery_get_property() can
take the advantage of the mutex and synchronize itself. With the mutex,
acpi_battery_get_state() are synchronized in all code paths calling it,
and its cache mechanism can always clamp the frequency of _BST
evaluations according to cache_time.

The helper function acpi_battery_handle_discharging() for quirky devices
has to be inlined due to the change, as the mutex must be unlocked
before calling the expensive power_supply_is_system_supplied() helper
function.

Fixes: 86bfd21a0baf ("ACPI: battery: Drop redundant locking")
Reported-by: Rick <rickk1166@gmail.com>
Closes: https://bugzilla.kernel.org/show_bug.cgi?id=221065#c85 [1]
Reported-by: Avraham Hollander <anhollander516@gmail.com>
Tested-by: Avraham Hollander <anhollander516@gmail.com>
Closes: https://lore.kernel.org/linux-acpi/CAP1mzZReJCn6df5DwEPu-JCQUyr=Pu1cg5xKCMttWZkHCQtVmQ@mail.gmail.com [2]
Signed-off-by: Rong Zhang <i@rong.moe>
Cc: All applicable <stable@vger.kernel.org>
Link: https://patch.msgid.link/20260809-b4-acpi-battery-notification-v5-1-788d54fa2e35@rong.moe
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/acpi/battery.c |  147 +++++++++++++++++++++++++++++++++----------------
 1 file changed, 101 insertions(+), 46 deletions(-)

--- a/drivers/acpi/battery.c
+++ b/drivers/acpi/battery.c
@@ -15,6 +15,7 @@
 #include <linux/jiffies.h>
 #include <linux/kernel.h>
 #include <linux/list.h>
+#include <linux/lockdep.h>
 #include <linux/module.h>
 #include <linux/mutex.h>
 #include <linux/platform_device.h>
@@ -97,6 +98,9 @@ struct acpi_battery {
 	struct device *phys_dev;
 	struct notifier_block pm_nb;
 	struct list_head list;
+	unsigned long flags;
+
+	struct mutex property_lock; /* Protects properties below. */
 	unsigned long update_time;
 	int revision;
 	int rate_now;
@@ -123,7 +127,6 @@ struct acpi_battery {
 	char oem_info[MAX_STRING_LENGTH];
 	int state;
 	int power_unit;
-	unsigned long flags;
 };
 
 #define to_acpi_battery(x) power_supply_get_drvdata(x)
@@ -180,20 +183,6 @@ static bool acpi_battery_is_degraded(str
 		battery->full_charge_capacity < battery->design_capacity;
 }
 
-static int acpi_battery_handle_discharging(struct acpi_battery *battery)
-{
-	/*
-	 * Some devices wrongly report discharging if the battery's charge level
-	 * was above the device's start charging threshold atm the AC adapter
-	 * was plugged in and the device thus did not start a new charge cycle.
-	 */
-	if ((battery_ac_is_broken || power_supply_is_system_supplied()) &&
-	    battery->rate_now == 0)
-		return POWER_SUPPLY_STATUS_NOT_CHARGING;
-
-	return POWER_SUPPLY_STATUS_DISCHARGING;
-}
-
 static int acpi_battery_get_property(struct power_supply *psy,
 				     enum power_supply_property psp,
 				     union power_supply_propval *val)
@@ -201,15 +190,41 @@ static int acpi_battery_get_property(str
 	int full_capacity = ACPI_BATTERY_VALUE_UNKNOWN, ret = 0;
 	struct acpi_battery *battery = to_acpi_battery(psy);
 
-	if (acpi_battery_present(battery)) {
-		/* run battery update only if it is present */
-		acpi_battery_get_state(battery);
-	} else if (psp != POWER_SUPPLY_PROP_PRESENT)
-		return -ENODEV;
+	/* run battery update only if it is present */
+	if (!acpi_battery_present(battery)) {
+		switch (psp) {
+		case POWER_SUPPLY_PROP_PRESENT:
+			val->intval = 0;
+			return 0;
+		default:
+			return -ENODEV;
+		}
+	}
+
+	mutex_lock(&battery->property_lock);
+
+	acpi_battery_get_state(battery);
+
 	switch (psp) {
 	case POWER_SUPPLY_PROP_STATUS:
+		/*
+		 * Some devices wrongly report discharging if the battery's charge level
+		 * was above the device's start charging threshold atm the AC adapter
+		 * was plugged in and the device thus did not start a new charge cycle.
+		 */
 		if (battery->state & ACPI_BATTERY_STATE_DISCHARGING)
-			val->intval = acpi_battery_handle_discharging(battery);
+			if (battery->rate_now != 0) {
+				val->intval = POWER_SUPPLY_STATUS_DISCHARGING;
+			} else if (battery_ac_is_broken) {
+				val->intval = POWER_SUPPLY_STATUS_NOT_CHARGING;
+			} else {
+				mutex_unlock(&battery->property_lock);
+
+				val->intval = power_supply_is_system_supplied()
+					? POWER_SUPPLY_STATUS_NOT_CHARGING
+					: POWER_SUPPLY_STATUS_DISCHARGING;
+				return 0;
+			}
 		else if (battery->state & ACPI_BATTERY_STATE_CHARGING)
 			/* Validate the status by checking the current. */
 			if (battery->rate_now != ACPI_BATTERY_VALUE_UNKNOWN &&
@@ -311,6 +326,8 @@ static int acpi_battery_get_property(str
 	default:
 		ret = -EINVAL;
 	}
+
+	mutex_unlock(&battery->property_lock);
 	return ret;
 }
 
@@ -533,6 +550,8 @@ static int acpi_battery_get_info(struct
 	int use_bix;
 	int result = -ENODEV;
 
+	lockdep_assert_held(&battery->property_lock);
+
 	if (!acpi_battery_present(battery))
 		return 0;
 
@@ -572,6 +591,8 @@ static int acpi_battery_get_state(struct
 	acpi_status status = 0;
 	struct acpi_buffer buffer = { ACPI_ALLOCATE_BUFFER, NULL };
 
+	lockdep_assert_held(&battery->property_lock);
+
 	if (!acpi_battery_present(battery))
 		return 0;
 
@@ -625,6 +646,8 @@ static int acpi_battery_set_alarm(struct
 {
 	acpi_status status = 0;
 
+	lockdep_assert_held(&battery->property_lock);
+
 	if (!acpi_battery_present(battery) ||
 	    !test_bit(ACPI_BATTERY_ALARM_PRESENT, &battery->flags))
 		return -ENODEV;
@@ -642,6 +665,8 @@ static int acpi_battery_set_alarm(struct
 
 static int acpi_battery_init_alarm(struct acpi_battery *battery)
 {
+	lockdep_assert_held(&battery->property_lock);
+
 	/* See if alarms are supported, and if so, set default */
 	if (!acpi_has_method(battery->device->handle, "_BTP")) {
 		clear_bit(ACPI_BATTERY_ALARM_PRESENT, &battery->flags);
@@ -659,6 +684,8 @@ static ssize_t acpi_battery_alarm_show(s
 {
 	struct acpi_battery *battery = to_acpi_battery(dev_get_drvdata(dev));
 
+	guard(mutex)(&battery->property_lock);
+
 	return sysfs_emit(buf, "%d\n", battery->alarm * 1000);
 }
 
@@ -674,6 +701,8 @@ static ssize_t acpi_battery_alarm_store(
 	if (err)
 		return err;
 
+	guard(mutex)(&battery->property_lock);
+
 	battery->alarm = x / 1000;
 	if (acpi_battery_present(battery))
 		acpi_battery_set_alarm(battery);
@@ -858,12 +887,17 @@ static int sysfs_add_battery(struct acpi
 		.no_wakeup_source = true,
 	};
 	bool full_cap_broken = false;
+	int power_unit;
 
-	if (!ACPI_BATTERY_CAPACITY_VALID(battery->full_charge_capacity) &&
-	    !ACPI_BATTERY_CAPACITY_VALID(battery->design_capacity))
-		full_cap_broken = true;
+	scoped_guard(mutex, &battery->property_lock) {
+		power_unit = battery->power_unit;
 
-	if (battery->power_unit == ACPI_BATTERY_POWER_UNIT_MA) {
+		if (!ACPI_BATTERY_CAPACITY_VALID(battery->full_charge_capacity) &&
+		    !ACPI_BATTERY_CAPACITY_VALID(battery->design_capacity))
+			full_cap_broken = true;
+	}
+
+	if (power_unit == ACPI_BATTERY_POWER_UNIT_MA) {
 		if (full_cap_broken) {
 			battery->bat_desc.properties =
 			    charge_battery_full_cap_broken_props;
@@ -917,6 +951,9 @@ static void sysfs_remove_battery(struct
 static void find_battery(const struct dmi_header *dm, void *private)
 {
 	struct acpi_battery *battery = (struct acpi_battery *)private;
+
+	lockdep_assert_held(&battery->property_lock);
+
 	/* Note: the hardcoded offsets below have been extracted from
 	 * the source code of dmidecode.
 	 */
@@ -948,6 +985,8 @@ static void find_battery(const struct dm
  */
 static void acpi_battery_quirks(struct acpi_battery *battery)
 {
+	lockdep_assert_held(&battery->property_lock);
+
 	if (test_bit(ACPI_BATTERY_QUIRK_PERCENTAGE_CAPACITY, &battery->flags))
 		return;
 
@@ -1000,30 +1039,38 @@ static void acpi_battery_quirks(struct a
 static int acpi_battery_update(struct acpi_battery *battery, bool resume)
 {
 	int result = acpi_battery_get_status(battery);
+	bool wakeup;
 
 	if (result)
 		return result;
 
 	if (!acpi_battery_present(battery)) {
 		sysfs_remove_battery(battery);
-		battery->update_time = 0;
+		scoped_guard(mutex, &battery->property_lock)
+			battery->update_time = 0;
 		return 0;
 	}
 
 	if (resume)
 		return 0;
 
-	if (!battery->update_time) {
-		result = acpi_battery_get_info(battery);
+	scoped_guard(mutex, &battery->property_lock) {
+		if (!battery->update_time) {
+			result = acpi_battery_get_info(battery);
+			if (result)
+				return result;
+			acpi_battery_init_alarm(battery);
+		}
+
+		result = acpi_battery_get_state(battery);
 		if (result)
 			return result;
-		acpi_battery_init_alarm(battery);
-	}
+		acpi_battery_quirks(battery);
 
-	result = acpi_battery_get_state(battery);
-	if (result)
-		return result;
-	acpi_battery_quirks(battery);
+		wakeup = ((battery->state & ACPI_BATTERY_STATE_CRITICAL) ||
+			  (test_bit(ACPI_BATTERY_ALARM_PRESENT, &battery->flags) &&
+			   (battery->capacity_now <= battery->alarm)));
+	}
 
 	if (!battery->bat) {
 		result = sysfs_add_battery(battery);
@@ -1035,9 +1082,7 @@ static int acpi_battery_update(struct ac
 	 * Wakeup the system if battery is critical low
 	 * or lower than the alarm level
 	 */
-	if ((battery->state & ACPI_BATTERY_STATE_CRITICAL) ||
-	    (test_bit(ACPI_BATTERY_ALARM_PRESENT, &battery->flags) &&
-	     (battery->capacity_now <= battery->alarm)))
+	if (wakeup)
 		acpi_pm_wakeup_event(battery->phys_dev);
 
 	return result;
@@ -1050,12 +1095,14 @@ static void acpi_battery_refresh(struct
 	if (!battery->bat)
 		return;
 
-	power_unit = battery->power_unit;
+	scoped_guard(mutex, &battery->property_lock) {
+		power_unit = battery->power_unit;
 
-	acpi_battery_get_info(battery);
+		acpi_battery_get_info(battery);
 
-	if (power_unit == battery->power_unit)
-		return;
+		if (power_unit == battery->power_unit)
+			return;
+	}
 
 	/* The battery has changed its reporting units. */
 	sysfs_remove_battery(battery);
@@ -1110,17 +1157,21 @@ static int battery_notify(struct notifie
 		} else {
 			int result;
 
-			result = acpi_battery_get_info(battery);
-			if (result)
-				return result;
+			scoped_guard(mutex, &battery->property_lock) {
+				result = acpi_battery_get_info(battery);
+				if (result)
+					return result;
+			}
 
 			result = sysfs_add_battery(battery);
 			if (result)
 				return result;
 		}
 
-		acpi_battery_init_alarm(battery);
-		acpi_battery_get_state(battery);
+		scoped_guard(mutex, &battery->property_lock) {
+			acpi_battery_init_alarm(battery);
+			acpi_battery_get_state(battery);
+		}
 	}
 
 	return 0;
@@ -1262,6 +1313,10 @@ static int acpi_battery_probe(struct pla
 	if (result)
 		return result;
 
+	result = devm_mutex_init(&pdev->dev, &battery->property_lock);
+	if (result)
+		return result;
+
 	if (acpi_has_method(battery->device->handle, "_BIX"))
 		set_bit(ACPI_BATTERY_XINFO_PRESENT, &battery->flags);
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 014/556] KVM: x86/mmu: Fold kvm_mmu_zap_memslot() into kvm_arch_flush_shadow_memslot()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (12 preceding siblings ...)
  2026-09-09 13:34 ` [PATCH 7.2 013/556] ACPI: battery: Protect all properties with a separated mutex Greg Kroah-Hartman
@ 2026-09-09 13:34 ` Greg Kroah-Hartman
  2026-09-09 13:34 ` [PATCH 7.2 015/556] KVM: x86/mmu: Split kvm_mmu_zap_all_fast() into "front" and "back" halves Greg Kroah-Hartman
                   ` (554 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:34 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michael Roth, Sean Christopherson,
	Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sean Christopherson <seanjc@google.com>

[ Upstream commit 06d38eaa78fdac1cc889f261fa420eba8e9caa1a ]

Fold kvm_mmu_zap_memslot() into its sole caller so that its GFN range
structure can be used to trigger guest_memfd invalidations regardless of
whether KVM will do a partial or full zap of the MMU.

No functional change intended.

Cc: stable@vger.kernel.org # 6.12.x
Reviewed-by: Michael Roth <michael.roth@amd.com>
Link: https://patch.msgid.link/20260709204948.1988414-8-seanjc@google.com
Signed-off-by: Sean Christopherson <seanjc@google.com>
Stable-dep-of: d1a3c2162334 ("KVM: SEV: Forcefully invalidate SNP VMSA if its backing gmem page is zapped")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/x86/kvm/mmu/mmu.c |   35 +++++++++++++++--------------------
 1 file changed, 15 insertions(+), 20 deletions(-)

--- a/arch/x86/kvm/mmu/mmu.c
+++ b/arch/x86/kvm/mmu/mmu.c
@@ -7535,8 +7535,14 @@ out_flush:
 	kvm_mmu_remote_flush_or_zap(kvm, &invalid_list, flush);
 }
 
-static void kvm_mmu_zap_memslot(struct kvm *kvm,
-				struct kvm_memory_slot *slot)
+static inline bool kvm_memslot_flush_zap_all(struct kvm *kvm)
+{
+	return kvm->arch.vm_type == KVM_X86_DEFAULT_VM &&
+	       kvm_check_has_quirk(kvm, KVM_X86_QUIRK_SLOT_ZAP_ALL);
+}
+
+void kvm_arch_flush_shadow_memslot(struct kvm *kvm,
+				   struct kvm_memory_slot *slot)
 {
 	struct kvm_gfn_range range = {
 		.slot = slot,
@@ -7547,25 +7553,14 @@ static void kvm_mmu_zap_memslot(struct k
 	};
 	bool flush;
 
-	write_lock(&kvm->mmu_lock);
-	flush = kvm_unmap_gfn_range(kvm, &range);
-	kvm_mmu_zap_memslot_pages_and_flush(kvm, slot, flush);
-	write_unlock(&kvm->mmu_lock);
-}
-
-static inline bool kvm_memslot_flush_zap_all(struct kvm *kvm)
-{
-	return kvm->arch.vm_type == KVM_X86_DEFAULT_VM &&
-	       kvm_check_has_quirk(kvm, KVM_X86_QUIRK_SLOT_ZAP_ALL);
-}
-
-void kvm_arch_flush_shadow_memslot(struct kvm *kvm,
-				   struct kvm_memory_slot *slot)
-{
-	if (kvm_memslot_flush_zap_all(kvm))
+	if (kvm_memslot_flush_zap_all(kvm)) {
 		kvm_mmu_zap_all_fast(kvm);
-	else
-		kvm_mmu_zap_memslot(kvm, slot);
+	} else {
+		write_lock(&kvm->mmu_lock);
+		flush = kvm_unmap_gfn_range(kvm, &range);
+		kvm_mmu_zap_memslot_pages_and_flush(kvm, slot, flush);
+		write_unlock(&kvm->mmu_lock);
+	}
 }
 
 void kvm_mmu_invalidate_mmio_sptes(struct kvm *kvm, u64 gen)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 015/556] KVM: x86/mmu: Split kvm_mmu_zap_all_fast() into "front" and "back" halves
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (13 preceding siblings ...)
  2026-09-09 13:34 ` [PATCH 7.2 014/556] KVM: x86/mmu: Fold kvm_mmu_zap_memslot() into kvm_arch_flush_shadow_memslot() Greg Kroah-Hartman
@ 2026-09-09 13:34 ` Greg Kroah-Hartman
  2026-09-09 13:34 ` [PATCH 7.2 016/556] KVM: x86/mmu: Use split "zap all fast" helpers when invalidating memslot Greg Kroah-Hartman
                   ` (553 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:34 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michael Roth, Sean Christopherson,
	Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sean Christopherson <seanjc@google.com>

[ Upstream commit b27622c4eeb125814081baaefe9175191be5b94d ]

Split kvm_mmu_zap_all_fast() into a "front half" and a "back half", where
the front half is everything that runs with mmu_lock held for write, and
the back half is the code that runs outside of mmu_lock.  This will allow
putting more code inside kvm_arch_flush_shadow_memslot()'s critical section
without having to take mmu_lock twice in quick succession.

No functional change intended.

Cc: stable@vger.kernel.org # 6.12.x
Reviewed-by: Michael Roth <michael.roth@amd.com>
Link: https://patch.msgid.link/20260709204948.1988414-9-seanjc@google.com
Signed-off-by: Sean Christopherson <seanjc@google.com>
Stable-dep-of: d1a3c2162334 ("KVM: SEV: Forcefully invalidate SNP VMSA if its backing gmem page is zapped")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/x86/kvm/mmu/mmu.c |   37 +++++++++++++++++++++++++------------
 1 file changed, 25 insertions(+), 12 deletions(-)

--- a/arch/x86/kvm/mmu/mmu.c
+++ b/arch/x86/kvm/mmu/mmu.c
@@ -6896,20 +6896,11 @@ restart:
 	kvm_mmu_commit_zap_page(kvm, &invalid_list);
 }
 
-/*
- * Fast invalidate all shadow pages and use lock-break technique
- * to zap obsolete pages.
- *
- * It's required when memslot is being deleted or VM is being
- * destroyed, in these cases, we should ensure that KVM MMU does
- * not use any resource of the being-deleted slot or all slots
- * after calling the function.
- */
-static void kvm_mmu_zap_all_fast(struct kvm *kvm)
+static void __kvm_mmu_zap_all_fast_front_half(struct kvm *kvm)
 {
 	lockdep_assert_held(&kvm->slots_lock);
+	lockdep_assert_held_write(&kvm->mmu_lock);
 
-	write_lock(&kvm->mmu_lock);
 	trace_kvm_mmu_zap_all_fast(kvm);
 
 	/*
@@ -6946,8 +6937,12 @@ static void kvm_mmu_zap_all_fast(struct
 	kvm_make_all_cpus_request(kvm, KVM_REQ_MMU_FREE_OBSOLETE_ROOTS);
 
 	kvm_zap_obsolete_pages(kvm);
+}
 
-	write_unlock(&kvm->mmu_lock);
+static void __kvm_mmu_zap_all_fast_back_half(struct kvm *kvm)
+{
+	lockdep_assert_held(&kvm->slots_lock);
+	lockdep_assert_not_held(&kvm->mmu_lock);
 
 	/*
 	 * Zap the invalidated TDP MMU roots, all SPTEs must be dropped before
@@ -6961,6 +6956,24 @@ static void kvm_mmu_zap_all_fast(struct
 		kvm_tdp_mmu_zap_invalidated_roots(kvm, true);
 }
 
+/*
+ * Fast invalidate all shadow pages and use lock-break technique
+ * to zap obsolete pages.
+ *
+ * It's required when memslot is being deleted or VM is being
+ * destroyed, in these cases, we should ensure that KVM MMU does
+ * not use any resource of the being-deleted slot or all slots
+ * after calling the function.
+ */
+static void kvm_mmu_zap_all_fast(struct kvm *kvm)
+{
+	write_lock(&kvm->mmu_lock);
+	__kvm_mmu_zap_all_fast_front_half(kvm);
+	write_unlock(&kvm->mmu_lock);
+
+	__kvm_mmu_zap_all_fast_back_half(kvm);
+}
+
 int kvm_mmu_init_vm(struct kvm *kvm)
 {
 	int r, i;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 016/556] KVM: x86/mmu: Use split "zap all fast" helpers when invalidating memslot
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (14 preceding siblings ...)
  2026-09-09 13:34 ` [PATCH 7.2 015/556] KVM: x86/mmu: Split kvm_mmu_zap_all_fast() into "front" and "back" halves Greg Kroah-Hartman
@ 2026-09-09 13:34 ` Greg Kroah-Hartman
  2026-09-09 13:34 ` [PATCH 7.2 017/556] KVM: SEV: Forcefully invalidate SNP VMSA if its backing gmem page is zapped Greg Kroah-Hartman
                   ` (552 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:34 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michael Roth, Sean Christopherson,
	Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sean Christopherson <seanjc@google.com>

[ Upstream commit db095727ff5739f4f46ee641ee6ef450032886db ]

Manually invoke the front half and back half of the "zap all fast" flow
when invalidating a memslot so that mmu_lock is acquired at function scope
in kvm_arch_flush_shadow_memslot().   This will allow putting more code
inside the critical section without having to take mmu_lock twice in quick
succession.

Opportunistically open code checking whether or not to do the fast zap, to
discourage removing the local "zap_all" in a future cleanup, i.e. to ensure
the SLOT_ZAP_ALL quirk is queried exactly once.  Processing the front half
but not the back half of the fast zap (if SLOT_ZAP_ALL were disabled
concurrently) would result in KVM unnecessarily keeping invalid TDP MMU
roots until the VM is destroyed.

No functional change intended.

Cc: stable@vger.kernel.org # 6.12.x
Reviewed-by: Michael Roth <michael.roth@amd.com>
Link: https://patch.msgid.link/20260709204948.1988414-10-seanjc@google.com
Signed-off-by: Sean Christopherson <seanjc@google.com>
Stable-dep-of: d1a3c2162334 ("KVM: SEV: Forcefully invalidate SNP VMSA if its backing gmem page is zapped")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/x86/kvm/mmu/mmu.c |   21 +++++++++++----------
 1 file changed, 11 insertions(+), 10 deletions(-)

--- a/arch/x86/kvm/mmu/mmu.c
+++ b/arch/x86/kvm/mmu/mmu.c
@@ -7548,12 +7548,6 @@ out_flush:
 	kvm_mmu_remote_flush_or_zap(kvm, &invalid_list, flush);
 }
 
-static inline bool kvm_memslot_flush_zap_all(struct kvm *kvm)
-{
-	return kvm->arch.vm_type == KVM_X86_DEFAULT_VM &&
-	       kvm_check_has_quirk(kvm, KVM_X86_QUIRK_SLOT_ZAP_ALL);
-}
-
 void kvm_arch_flush_shadow_memslot(struct kvm *kvm,
 				   struct kvm_memory_slot *slot)
 {
@@ -7564,16 +7558,23 @@ void kvm_arch_flush_shadow_memslot(struc
 		.may_block = true,
 		.attr_filter = KVM_FILTER_PRIVATE | KVM_FILTER_SHARED,
 	};
+	bool zap_all = kvm->arch.vm_type == KVM_X86_DEFAULT_VM &&
+		       kvm_check_has_quirk(kvm, KVM_X86_QUIRK_SLOT_ZAP_ALL);
 	bool flush;
 
-	if (kvm_memslot_flush_zap_all(kvm)) {
-		kvm_mmu_zap_all_fast(kvm);
+	write_lock(&kvm->mmu_lock);
+
+	if (zap_all) {
+		__kvm_mmu_zap_all_fast_front_half(kvm);
 	} else {
-		write_lock(&kvm->mmu_lock);
 		flush = kvm_unmap_gfn_range(kvm, &range);
 		kvm_mmu_zap_memslot_pages_and_flush(kvm, slot, flush);
-		write_unlock(&kvm->mmu_lock);
 	}
+
+	write_unlock(&kvm->mmu_lock);
+
+	if (zap_all)
+		__kvm_mmu_zap_all_fast_back_half(kvm);
 }
 
 void kvm_mmu_invalidate_mmio_sptes(struct kvm *kvm, u64 gen)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 017/556] KVM: SEV: Forcefully invalidate SNP VMSA if its backing gmem page is zapped
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (15 preceding siblings ...)
  2026-09-09 13:34 ` [PATCH 7.2 016/556] KVM: x86/mmu: Use split "zap all fast" helpers when invalidating memslot Greg Kroah-Hartman
@ 2026-09-09 13:34 ` Greg Kroah-Hartman
  2026-09-09 13:34 ` [PATCH 7.2 018/556] NFSD: Annotate caller preconditions for the state-table walkers Greg Kroah-Hartman
                   ` (551 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:34 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Hyunwoo Kim, Tom Lendacky,
	Michael Roth, Jörg Rödel, Fuad Tabba, Ackerley Tng,
	Sean Christopherson, Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sean Christopherson <seanjc@google.com>

[ Upstream commit d1a3c216233413f57f5341a9b878b7e2dde7e785 ]

Wire up a gmem_invalidate_range() call for SNP VMs, and use it to force
vCPUs to reload/recheck their guest-provided VMSA if the backing gmem
page is being invalidated, e.g. is being PUNCH_HOLE'd.  Use the same core
logic to handle invalidations as VMX does for the APIC-access page, as the
two concepts are nearly identical: shove the physical address of a page
into the vCPU's control structure:

 1. Snapshot the invalidation sequence counter
 2. Grab the pfn (from guest_memfd in this case)
 3. Acquire mmu_lock for read
 4. Re-request reload if retry is needed, otherwise commit the change.

Note, the re-request action in #4 is necessary as KVM's retry logic is
fuzzy, i.e. can get false positives.  If the guest_memfd page has been
dropped, at some point a subsequent reload will fail to get a PFN from
guest_memfd, and KVM will fail KVM_RUN.  If the retry was due to a false
positive, KVM will retry until there are no relevant MMU notifier events
(and will retry in the "outer" loop, i.e. will drop locks and resched as
needed).

Note #2!  Take care to invalidate the VMSA when a relevant memslot is
DELETED or MOVED, as invalidations in response to PUNCH_HOLE are predicated
on memslot bindings (KVM doesn't know what GFN range(s) to invalidate
without a binding).  And more importantly, the VMSA mapping requires a
memslot, i.e. must be invalidated if its memslots disappears, regardless of
the state of the underlying guest_memfd inode.

Failure to invalidate the vCPU's control.vmsa_pa (which is checked by
pre_sev_run()) can prevent KVM from properly freeing the page as firmware
will reject the RMPUPDATE to reclaim the page with FAIL_INUSE if the vCPU
is actively running, i.e. if VMSA page is in-use.  That in turn leads to an
RMP #PF on the next use, as the page will still be assigned to the SNP VM.

  SEV-SNP: RMPUPDATE failed for PFN 78d198, pg_level: 1, ret: 3
  SEV-SNP: PFN 0x78d198, RMP entry: [0xfff0000000144001 - 0x000000000000000f]
  CPU: 3 UID: 0 PID: 31345 Comm: sev_snp_vmsa_pu Tainted: G     U     O
  Tainted: [U]=USER, [O]=OOT_MODULE
  Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 34.86.0-102 01/25/2026
  Call Trace:
   <TASK>
   dump_stack_lvl+0x54/0x70
   rmpupdate+0x12c/0x140
   rmp_make_shared+0x3b/0x60
   sev_gmem_invalidate+0xe0/0x170 [kvm_amd]
   delete_from_page_cache_batch+0x1d8/0x220
   truncate_inode_pages_range+0x120/0x3d0
   kvm_gmem_fallocate+0x19a/0x270 [kvm]
   vfs_fallocate+0x1bc/0x1f0
   __x64_sys_fallocate+0x48/0x70
   do_syscall_64+0x10a/0x480
   entry_SYSCALL_64_after_hwframe+0x4b/0x53
  RIP: 0033:0x496c7e
   </TASK>
  ------------[ cut here ]------------
  SEV: Failed to update RMP entry for PFN 0x78d198 error -14
  WARNING: arch/x86/kvm/svm/sev.c:5160 at sev_gmem_invalidate+0x126/0x170 [kvm_amd], CPU#3: sev_snp_vmsa_pu/31345
  CPU: 3 UID: 0 PID: 31345 Comm: sev_snp_vmsa_pu Tainted: G     U     O
  Tainted: [U]=USER, [O]=OOT_MODULE
  Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 34.86.0-102 01/25/2026
  RIP: 0010:sev_gmem_invalidate+0x12b/0x170 [kvm_amd]
  Call Trace:
   <TASK>
   delete_from_page_cache_batch+0x1d8/0x220
   truncate_inode_pages_range+0x120/0x3d0
   kvm_gmem_fallocate+0x19a/0x270 [kvm]
   vfs_fallocate+0x1bc/0x1f0
   __x64_sys_fallocate+0x48/0x70
   do_syscall_64+0x10a/0x480
   entry_SYSCALL_64_after_hwframe+0x4b/0x53
  RIP: 0033:0x496c7e
   </TASK>
  irq event stamp: 20689
  hardirqs last  enabled at (20699): [<ffffffff8e76092c>] __console_unlock+0x5c/0x60
  hardirqs last disabled at (20708): [<ffffffff8e760911>] __console_unlock+0x41/0x60
  softirqs last  enabled at (20722): [<ffffffff8e6cd74e>] __irq_exit_rcu+0x7e/0x140
  softirqs last disabled at (20717): [<ffffffff8e6cd74e>] __irq_exit_rcu+0x7e/0x140
  ---[ end trace 0000000000000000 ]---
  BUG: unable to handle page fault for address: ffff99a64d198000
  #PF: supervisor write access in kernel mode
  #PF: error_code(0x80000003) - RMP violation
  PGD 13eb001067 P4D 13eb001067 PUD 78d1d1063 PMD 1184e0063 PTE 800000078d198163
  SEV-SNP: PFN 0x78d198, RMP entry: [0x6030000000144001 - 0x000000000000000f]
  Oops: Oops: 0003 [#1] SMP
  CPU: 3 UID: 0 PID: 31407 Comm: highlanderd_hea Tainted: G     U  W  O
  Tainted: [U]=USER, [W]=WARN, [O]=OOT_MODULE
  Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 34.86.0-102 01/25/2026
  RIP: 0010:prep_new_page+0x67/0x220
  Call Trace:
   <TASK>
   get_page_from_freelist+0x1c40/0x1c70
   __alloc_frozen_pages_noprof+0xca/0x1f0
   alloc_pages_mpol+0x10b/0x1b0
   alloc_pages_noprof+0x81/0x90
   pte_alloc_one+0x1b/0xd0
   do_pte_missing+0xdf/0x1020
   handle_mm_fault+0x7c7/0xb20
   do_user_addr_fault+0x268/0x6b0
   exc_page_fault+0x67/0xa0
   asm_exc_page_fault+0x26/0x30
  RIP: 0033:0x4a6b1e
   </TASK>
  gsmi: Log Shutdown Reason 0x03
  CR2: ffff99a64d198000
  ---[ end trace 0000000000000000 ]---
  RIP: 0010:prep_new_page+0x67/0x220

Drop the pseudo-TODO comment about needing to pin the page if guest_memfd
every supports migration, as integrating with invalidations events means
KVM will Just Work if/when page migration is ever supported (assuming SNP
hardware supports migrating VMSA pages).

Note #3, invalidate() and invalidate_range() have _completely_ different
semantics; the new invalidate_range() is a true invalidation, whereas the
existing invalidate() is really a "make shared" operation.  Ignore the
confusing naming and poor Kconfig bundling for the moment to minimize the
delta for LTS kernels, the mess will be cleaned up shortly.

Reported-by: Hyunwoo Kim <imv4bel@gmail.com>
Closes: https://lore.kernel.org/all/aimMWzAf5b3luM0b@v4bel
Fixes: e366f92ea99e ("KVM: SEV: Support SEV-SNP AP Creation NAE event")
Cc: stable@vger.kernel.org
Cc: Tom Lendacky <thomas.lendacky@amd.com>
Cc: Michael Roth <michael.roth@amd.com>
Cc: Jörg Rödel <joro@8bytes.org>
Cc: Fuad Tabba <tabba@google.com>
Cc: Ackerley Tng <ackerleytng@google.com>
Reviewed-by: Michael Roth <michael.roth@amd.com>
Link: https://patch.msgid.link/20260709204948.1988414-11-seanjc@google.com
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/x86/include/asm/kvm-x86-ops.h |    4 +
 arch/x86/include/asm/kvm_host.h    |    6 ++
 arch/x86/kvm/mmu/mmu.c             |    5 ++
 arch/x86/kvm/svm/sev.c             |   80 +++++++++++++++++++++++++++++++------
 arch/x86/kvm/svm/svm.c             |    2 
 arch/x86/kvm/svm/svm.h             |    2 
 arch/x86/kvm/x86.c                 |    6 ++
 include/linux/kvm_host.h           |    1 
 virt/kvm/guest_memfd.c             |    4 +
 9 files changed, 99 insertions(+), 11 deletions(-)

--- a/arch/x86/include/asm/kvm-x86-ops.h
+++ b/arch/x86/include/asm/kvm-x86-ops.h
@@ -134,6 +134,7 @@ KVM_X86_OP_OPTIONAL(mem_enc_unregister_r
 KVM_X86_OP_OPTIONAL(vm_copy_enc_context_from)
 KVM_X86_OP_OPTIONAL(vm_move_enc_context_from)
 KVM_X86_OP_OPTIONAL(guest_memory_reclaimed)
+KVM_X86_OP_OPTIONAL(reload_vmsa)
 KVM_X86_OP(get_feature_msr)
 KVM_X86_OP(check_emulate_instruction)
 KVM_X86_OP(apic_init_signal_blocked)
@@ -148,6 +149,9 @@ KVM_X86_OP_OPTIONAL(alloc_apic_backing_p
 KVM_X86_OP_OPTIONAL_RET0(gmem_prepare)
 KVM_X86_OP_OPTIONAL_RET0(gmem_max_mapping_level)
 KVM_X86_OP_OPTIONAL(gmem_invalidate)
+#ifdef CONFIG_HAVE_KVM_ARCH_GMEM_INVALIDATE
+KVM_X86_OP_OPTIONAL(gmem_invalidate_range)
+#endif
 #endif
 
 #undef KVM_X86_OP
--- a/arch/x86/include/asm/kvm_host.h
+++ b/arch/x86/include/asm/kvm_host.h
@@ -128,6 +128,8 @@
 	KVM_ARCH_REQ_FLAGS(31, KVM_REQUEST_WAIT | KVM_REQUEST_NO_WAKEUP)
 #define KVM_REQ_HV_TLB_FLUSH \
 	KVM_ARCH_REQ_FLAGS(32, KVM_REQUEST_WAIT | KVM_REQUEST_NO_WAKEUP)
+#define KVM_REQ_VMSA_PAGE_RELOAD \
+	KVM_ARCH_REQ_FLAGS(33, KVM_REQUEST_WAIT | KVM_REQUEST_NO_WAKEUP)
 #define KVM_REQ_UPDATE_PROTECTED_GUEST_STATE \
 	KVM_ARCH_REQ_FLAGS(34, KVM_REQUEST_WAIT)
 
@@ -1985,6 +1987,7 @@ struct kvm_x86_ops {
 	int (*vm_copy_enc_context_from)(struct kvm *kvm, unsigned int source_fd);
 	int (*vm_move_enc_context_from)(struct kvm *kvm, unsigned int source_fd);
 	void (*guest_memory_reclaimed)(struct kvm *kvm);
+	void (*reload_vmsa)(struct kvm_vcpu *vcpu);
 
 	int (*get_feature_msr)(u32 msr, u64 *data);
 
@@ -2009,6 +2012,9 @@ struct kvm_x86_ops {
 	void *(*alloc_apic_backing_page)(struct kvm_vcpu *vcpu);
 	int (*gmem_prepare)(struct kvm *kvm, kvm_pfn_t pfn, gfn_t gfn, int max_order);
 	void (*gmem_invalidate)(kvm_pfn_t start, kvm_pfn_t end);
+#ifdef CONFIG_HAVE_KVM_ARCH_GMEM_INVALIDATE
+	void (*gmem_invalidate_range)(struct kvm *kvm, struct kvm_gfn_range *range);
+#endif
 	int (*gmem_max_mapping_level)(struct kvm *kvm, kvm_pfn_t pfn, bool is_private);
 };
 
--- a/arch/x86/kvm/mmu/mmu.c
+++ b/arch/x86/kvm/mmu/mmu.c
@@ -7564,6 +7564,11 @@ void kvm_arch_flush_shadow_memslot(struc
 
 	write_lock(&kvm->mmu_lock);
 
+#ifdef CONFIG_HAVE_KVM_ARCH_GMEM_INVALIDATE
+	if (slot->gmem.file)
+		kvm_arch_gmem_invalidate_range(kvm, &range);
+#endif
+
 	if (zap_all) {
 		__kvm_mmu_zap_all_fast_front_half(kvm);
 	} else {
--- a/arch/x86/kvm/svm/sev.c
+++ b/arch/x86/kvm/svm/sev.c
@@ -4021,19 +4021,25 @@ static int snp_begin_psc(struct vcpu_svm
 	return snp_do_psc(svm);
 }
 
-static void sev_snp_reload_vmsa(struct kvm_vcpu *vcpu, gpa_t gpa)
+static void __sev_snp_reload_vmsa(struct kvm_vcpu *vcpu, gpa_t gpa)
 {
 	struct vcpu_svm *svm = to_svm(vcpu);
 	struct kvm_memory_slot *slot;
+	struct kvm *kvm = vcpu->kvm;
 	gfn_t gfn = gpa_to_gfn(gpa);
+	unsigned long mmu_seq;
 	struct page *page;
 	kvm_pfn_t pfn;
 
 	lockdep_assert_held(&svm->sev_es.snp_vmsa_mutex);
 
-	/* Clear use of the VMSA. */
+	/*
+	 * Clear use of the VMSA.  Ensure snp_guest_vmsa_gpa is written exactly
+	 * once, as it is read locklessly when responding to gfn invalidations.
+	 * Pairs with the READ_ONCE() in sev_gmem_invalidate_range().
+	 */
 	svm->vmcb->control.vmsa_pa = INVALID_PAGE;
-	svm->sev_es.snp_guest_vmsa_gpa = INVALID_PAGE;
+	WRITE_ONCE(svm->sev_es.snp_guest_vmsa_gpa, INVALID_PAGE);
 
 	/*
 	 * When replacing the VMSA during SEV-SNP AP creation,
@@ -4048,6 +4054,9 @@ static void sev_snp_reload_vmsa(struct k
 	if (!slot)
 		return;
 
+	mmu_seq = kvm->mmu_invalidate_seq;
+	smp_rmb();
+
 	/*
 	 * The new VMSA will be private memory guest memory, so retrieve the
 	 * PFN from the gmem backend.
@@ -4066,15 +4075,20 @@ static void sev_snp_reload_vmsa(struct k
 	 */
 	svm->sev_es.snp_has_guest_vmsa = true;
 
-	/* Use the new VMSA */
-	svm->sev_es.snp_guest_vmsa_gpa = gpa;
-	svm->vmcb->control.vmsa_pa = pfn_to_hpa(pfn);
-
+	read_lock(&kvm->mmu_lock);
 	/*
-	 * gmem pages aren't currently migratable, but if this ever changes
-	 * then care should be taken to ensure svm->sev_es.vmsa is pinned
-	 * through some other means.
+	 * Save the guest-provided GPA.  If retry is needed, then KVM will try
+	 * again with the same GPA.  If the VMSA is usable, then KVM needs to
+	 * track the GPA so that the VMSA can be reloaded if the backing page
+	 * for the GPA is invalidated.
 	 */
+	svm->sev_es.snp_guest_vmsa_gpa = gpa;
+	if (mmu_invalidate_retry_gfn(kvm, mmu_seq, gfn))
+		kvm_make_request(KVM_REQ_VMSA_PAGE_RELOAD, vcpu);
+	else
+		svm->vmcb->control.vmsa_pa = pfn_to_hpa(pfn);
+	read_unlock(&kvm->mmu_lock);
+
 	kvm_release_page_clean(page);
 }
 
@@ -4100,7 +4114,7 @@ static void sev_snp_init_protected_guest
 	gpa = svm->sev_es.snp_pending_vmsa_gpa;
 	svm->sev_es.snp_pending_vmsa_gpa = INVALID_PAGE;
 
-	sev_snp_reload_vmsa(vcpu, gpa);
+	__sev_snp_reload_vmsa(vcpu, gpa);
 
 	/*
 	 * Mark the vCPU as runnable for CREATE requests, indicated by a valid
@@ -4112,6 +4126,15 @@ static void sev_snp_init_protected_guest
 		kvm_set_mp_state(vcpu, KVM_MP_STATE_RUNNABLE);
 }
 
+void sev_snp_reload_vmsa(struct kvm_vcpu *vcpu)
+{
+	struct vcpu_sev_es_state *sev_es = &to_svm(vcpu)->sev_es;
+
+	guard(mutex)(&sev_es->snp_vmsa_mutex);
+
+	__sev_snp_reload_vmsa(vcpu, sev_es->snp_guest_vmsa_gpa);
+}
+
 static int sev_snp_ap_creation(struct vcpu_svm *svm)
 {
 	struct kvm_sev_info *sev = to_kvm_sev_info(svm->vcpu.kvm);
@@ -5241,6 +5264,41 @@ next_pfn:
 	}
 }
 
+void sev_gmem_invalidate_range(struct kvm *kvm, struct kvm_gfn_range *range)
+{
+	struct kvm_vcpu *vcpu;
+	unsigned long i;
+
+	lockdep_assert_held_write(&kvm->mmu_lock);
+
+	/*
+	 * An unstable result for "is SNP" is a-ok here, thanks to mmu_lock.
+	 * The vCPU's VMSA GPA is invalidated before the vCPU is made visible
+	 * to other tasks, and can only become valid while holding mmu_lock,
+	 * after the VM is fully committed to being an SNP VM.
+	 */
+	if (!____sev_snp_guest(kvm))
+		return;
+
+	kvm_for_each_vcpu(i, vcpu, kvm) {
+		/*
+		 * Read snp_guest_vmsa_gpa without taking the vCPU's VMSA mutex
+		 * (or its generic mutex) as mmu_lock is held, i.e. this task
+		 * can't sleep.  The VMSA is invalidated outside of mmu_lock,
+		 * but can only become valid inside of mmu_lock, i.e. the below
+		 * can get false positives, but not false negatives.  A false
+		 * positive is benign, as a spurious request simply forces the
+		 * vCPU to re-establish its VMSA.
+		 */
+		gpa_t gpa = READ_ONCE(to_svm(vcpu)->sev_es.snp_guest_vmsa_gpa);
+
+		if (VALID_PAGE(gpa) &&
+		    gpa_to_gfn(gpa) >= range->start &&
+		    gpa_to_gfn(gpa) < range->end)
+			kvm_make_request_and_kick(KVM_REQ_VMSA_PAGE_RELOAD, vcpu);
+	}
+}
+
 int sev_gmem_max_mapping_level(struct kvm *kvm, kvm_pfn_t pfn, bool is_private)
 {
 	int level, rc;
--- a/arch/x86/kvm/svm/svm.c
+++ b/arch/x86/kvm/svm/svm.c
@@ -5463,12 +5463,14 @@ struct kvm_x86_ops svm_x86_ops __initdat
 	.mem_enc_register_region = sev_mem_enc_register_region,
 	.mem_enc_unregister_region = sev_mem_enc_unregister_region,
 	.guest_memory_reclaimed = sev_guest_memory_reclaimed,
+	.reload_vmsa = sev_snp_reload_vmsa,
 
 	.vm_copy_enc_context_from = sev_vm_copy_enc_context_from,
 	.vm_move_enc_context_from = sev_vm_move_enc_context_from,
 
 	.gmem_prepare = sev_gmem_prepare,
 	.gmem_invalidate = sev_gmem_invalidate,
+	.gmem_invalidate_range = sev_gmem_invalidate_range,
 	.gmem_max_mapping_level = sev_gmem_max_mapping_level,
 #endif
 	.check_emulate_instruction = svm_check_emulate_instruction,
--- a/arch/x86/kvm/svm/svm.h
+++ b/arch/x86/kvm/svm/svm.h
@@ -997,6 +997,7 @@ static inline struct page *snp_safe_allo
 {
 	return snp_safe_alloc_page_node(numa_node_id(), GFP_KERNEL_ACCOUNT);
 }
+void sev_snp_reload_vmsa(struct kvm_vcpu *vcpu);
 
 int sev_vcpu_create(struct kvm_vcpu *vcpu);
 void sev_free_vcpu(struct kvm_vcpu *vcpu);
@@ -1011,6 +1012,7 @@ extern unsigned int max_sev_asid;
 void sev_handle_rmp_fault(struct kvm_vcpu *vcpu, gpa_t gpa, u64 error_code);
 int sev_gmem_prepare(struct kvm *kvm, kvm_pfn_t pfn, gfn_t gfn, int max_order);
 void sev_gmem_invalidate(kvm_pfn_t start, kvm_pfn_t end);
+void sev_gmem_invalidate_range(struct kvm *kvm, struct kvm_gfn_range *range);
 int sev_gmem_max_mapping_level(struct kvm *kvm, kvm_pfn_t pfn, bool is_private);
 struct vmcb_save_area *sev_decrypt_vmsa(struct kvm_vcpu *vcpu);
 void sev_free_decrypted_vmsa(struct kvm_vcpu *vcpu, struct vmcb_save_area *vmsa);
--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -11278,6 +11278,8 @@ static int vcpu_enter_guest(struct kvm_v
 				goto out;
 			}
 		}
+		if (kvm_check_request(KVM_REQ_VMSA_PAGE_RELOAD, vcpu))
+			kvm_x86_call(reload_vmsa)(vcpu);
 	}
 
 	if (kvm_check_request(KVM_REQ_EVENT, vcpu) || req_int_win ||
@@ -14142,6 +14144,10 @@ void kvm_arch_gmem_invalidate(kvm_pfn_t
 {
 	kvm_x86_call(gmem_invalidate)(start, end);
 }
+void kvm_arch_gmem_invalidate_range(struct kvm *kvm, struct kvm_gfn_range *range)
+{
+	kvm_x86_call(gmem_invalidate_range)(kvm, range);
+}
 #endif
 #endif
 
--- a/include/linux/kvm_host.h
+++ b/include/linux/kvm_host.h
@@ -2608,6 +2608,7 @@ long kvm_gmem_populate(struct kvm *kvm,
 
 #ifdef CONFIG_HAVE_KVM_ARCH_GMEM_INVALIDATE
 void kvm_arch_gmem_invalidate(kvm_pfn_t start, kvm_pfn_t end);
+void kvm_arch_gmem_invalidate_range(struct kvm *kvm, struct kvm_gfn_range *range);
 #endif
 
 #ifdef CONFIG_KVM_GENERIC_PRE_FAULT_MEMORY
--- a/virt/kvm/guest_memfd.c
+++ b/virt/kvm/guest_memfd.c
@@ -185,6 +185,10 @@ static void __kvm_gmem_invalidate_start(
 		}
 
 		flush |= kvm_mmu_unmap_gfn_range(kvm, &gfn_range);
+
+#ifdef CONFIG_HAVE_KVM_ARCH_GMEM_INVALIDATE
+		kvm_arch_gmem_invalidate_range(kvm, &gfn_range);
+#endif
 	}
 
 	if (flush)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 018/556] NFSD: Annotate caller preconditions for the state-table walkers
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (16 preceding siblings ...)
  2026-09-09 13:34 ` [PATCH 7.2 017/556] KVM: SEV: Forcefully invalidate SNP VMSA if its backing gmem page is zapped Greg Kroah-Hartman
@ 2026-09-09 13:34 ` Greg Kroah-Hartman
  2026-09-09 13:34 ` [PATCH 7.2 019/556] NFSD: Guard admin state-revocation walks with NFSD_NET_UP Greg Kroah-Hartman
                   ` (550 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:34 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jeff Layton, Chuck Lever,
	Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chuck Lever <cel@kernel.org>

[ Upstream commit 5f367f05481d56be90f8c13eee4cb421cd7af2d8 ]

The state-table walkers now assert nfsd_mutex with
lockdep_assert_held() and document the nfsd_mutex / nn->nfsd_serv
precondition in a Context: kdoc section, so the next caller added to
this path cannot silently reintroduce the same use-after-free.

Reviewed-by: Jeff Layton <jlayton@kernel.org>
Link: https://patch.msgid.link/20260613-unlock-filesystem-uaf-v1-3-462b9bec8c84@kernel.org
Signed-off-by: Chuck Lever <cel@kernel.org>
Stable-dep-of: 2f3e6638aebc ("NFSD: Guard admin state-revocation walks with NFSD_NET_UP")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/nfsd/nfs4proc.c  |    6 ++++++
 fs/nfsd/nfs4state.c |   16 +++++++++++++++-
 2 files changed, 21 insertions(+), 1 deletion(-)

--- a/fs/nfsd/nfs4proc.c
+++ b/fs/nfsd/nfs4proc.c
@@ -1597,6 +1597,11 @@ static bool nfsd4_copy_on_sb(const struc
  * nfsd4_cancel_copy_by_sb - cancel async copy operations on @sb
  * @net: net namespace containing the copy operations
  * @sb: targeted superblock
+ *
+ * Context: Caller must hold nfsd_mutex with nn->nfsd_serv confirmed
+ *          non-NULL.  nfs4_state_destroy_net() frees conf_id_hashtbl
+ *          at server shutdown without clearing the pointer, so a
+ *          walk without these guarantees iterates freed slab memory.
  */
 void nfsd4_cancel_copy_by_sb(struct net *net, struct super_block *sb)
 {
@@ -1606,6 +1611,7 @@ void nfsd4_cancel_copy_by_sb(struct net
 	unsigned int idhashval;
 	LIST_HEAD(to_cancel);
 
+	lockdep_assert_held(&nfsd_mutex);
 	spin_lock(&nn->client_lock);
 	for (idhashval = 0; idhashval < CLIENT_HASH_SIZE; idhashval++) {
 		struct list_head *head = &nn->conf_id_hashtbl[idhashval];
--- a/fs/nfsd/nfs4state.c
+++ b/fs/nfsd/nfs4state.c
@@ -1944,14 +1944,21 @@ static void revoke_one_stid(struct nfsd_
  * being released.  Thus nfsd will no longer prevent the filesystem from being
  * unmounted.
  *
- * The clients which own the states will subsequently being notified that the
+ * The clients which own the states will subsequently be notified that the
  * states have been "admin-revoked".
+ *
+ * Context: Caller must hold nfsd_mutex with nn->nfsd_serv confirmed
+ *          non-NULL.  nfs4_state_destroy_net() frees conf_id_hashtbl
+ *          at server shutdown without clearing the pointer, so a
+ *          walk without these guarantees iterates freed slab memory.
  */
 void nfsd4_revoke_states(struct nfsd_net *nn, struct super_block *sb)
 {
 	unsigned int idhashval;
 	unsigned int sc_types;
 
+	lockdep_assert_held(&nfsd_mutex);
+
 	sc_types = SC_TYPE_OPEN | SC_TYPE_LOCK | SC_TYPE_DELEG | SC_TYPE_LAYOUT;
 
 	spin_lock(&nn->client_lock);
@@ -2030,12 +2037,19 @@ static struct nfs4_stid *find_one_export
  *
  * Userspace (exportfs -u) sends this after removing the last client
  * for a path, enabling the underlying filesystem to be unmounted.
+ *
+ * Context: Caller must hold nfsd_mutex with nn->nfsd_serv confirmed
+ *          non-NULL.  nfs4_state_destroy_net() frees conf_id_hashtbl
+ *          at server shutdown without clearing the pointer, so a
+ *          walk without these guarantees iterates freed slab memory.
  */
 void nfsd4_revoke_export_states(struct nfsd_net *nn, const struct path *path)
 {
 	unsigned int idhashval;
 	unsigned int sc_types;
 
+	lockdep_assert_held(&nfsd_mutex);
+
 	sc_types = SC_TYPE_OPEN | SC_TYPE_LOCK | SC_TYPE_DELEG | SC_TYPE_LAYOUT;
 
 	spin_lock(&nn->client_lock);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 019/556] NFSD: Guard admin state-revocation walks with NFSD_NET_UP
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (17 preceding siblings ...)
  2026-09-09 13:34 ` [PATCH 7.2 018/556] NFSD: Annotate caller preconditions for the state-table walkers Greg Kroah-Hartman
@ 2026-09-09 13:34 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 020/556] NFSD: Prevent client use-after-free during export state revocation Greg Kroah-Hartman
                   ` (549 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:34 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, XIAO WU, Jeff Layton, Chuck Lever,
	Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chuck Lever <cel@kernel.org>

[ Upstream commit 2f3e6638aebc0ab8afb8b4e9816ea9a1cad85378 ]

Writing to /proc/fs/nfsd/unlock_filesystem, or sending the
NFSD_CMD_UNLOCK_FILESYSTEM or NFSD_CMD_UNLOCK_EXPORT netlink command,
walks the NFSv4 client hash tables to revoke open state and cancel
async COPY operations.  All three handlers gate that walk on
nn->nfsd_serv, but a listener added via portlist or netlink
listener_set sets nn->nfsd_serv before any nfsd thread starts.
nfsd_startup_net() has not yet allocated nn->conf_id_hashtbl, so the
walkers dereference a NULL table.  A local administrator with
CAP_SYS_ADMIN can crash the kernel this way without ever starting the
server.

nn->nfsd_serv is set when the service is created, which precedes
table allocation.  NFSD_NET_UP instead brackets the window where the
tables are live: set at the end of nfsd_startup_net() and cleared in
nfsd_shutdown_net() after they are freed, both under nfsd_mutex.
Gating the three unlock paths on NFSD_NET_UP fixes the startup-time
NULL dereference while preserving the earlier post-shutdown
use-after-free fix.

Reported-by: XIAO WU <xiaowu.417@qq.com>
Fixes: 1ac3629bf012 ("nfsd: prepare for supporting admin-revocation of state")
Cc: stable@vger.kernel.org
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Link: https://patch.msgid.link/20260621162551.2469460-1-cel@kernel.org
Signed-off-by: Chuck Lever <cel@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/nfsd/nfs4proc.c  |    7 +++----
 fs/nfsd/nfs4state.c |   14 ++++++--------
 fs/nfsd/nfsctl.c    |    6 +++---
 3 files changed, 12 insertions(+), 15 deletions(-)

--- a/fs/nfsd/nfs4proc.c
+++ b/fs/nfsd/nfs4proc.c
@@ -1598,10 +1598,9 @@ static bool nfsd4_copy_on_sb(const struc
  * @net: net namespace containing the copy operations
  * @sb: targeted superblock
  *
- * Context: Caller must hold nfsd_mutex with nn->nfsd_serv confirmed
- *          non-NULL.  nfs4_state_destroy_net() frees conf_id_hashtbl
- *          at server shutdown without clearing the pointer, so a
- *          walk without these guarantees iterates freed slab memory.
+ * Context: Caller must hold nfsd_mutex with NFSD_NET_UP set.  Outside
+ *          that window nn->conf_id_hashtbl is unallocated or freed,
+ *          so the walk would dereference a NULL or dangling pointer.
  */
 void nfsd4_cancel_copy_by_sb(struct net *net, struct super_block *sb)
 {
--- a/fs/nfsd/nfs4state.c
+++ b/fs/nfsd/nfs4state.c
@@ -1947,10 +1947,9 @@ static void revoke_one_stid(struct nfsd_
  * The clients which own the states will subsequently be notified that the
  * states have been "admin-revoked".
  *
- * Context: Caller must hold nfsd_mutex with nn->nfsd_serv confirmed
- *          non-NULL.  nfs4_state_destroy_net() frees conf_id_hashtbl
- *          at server shutdown without clearing the pointer, so a
- *          walk without these guarantees iterates freed slab memory.
+ * Context: Caller must hold nfsd_mutex with NFSD_NET_UP set.  Outside
+ *          that window nn->conf_id_hashtbl is unallocated or freed,
+ *          so the walk would dereference a NULL or dangling pointer.
  */
 void nfsd4_revoke_states(struct nfsd_net *nn, struct super_block *sb)
 {
@@ -2038,10 +2037,9 @@ static struct nfs4_stid *find_one_export
  * Userspace (exportfs -u) sends this after removing the last client
  * for a path, enabling the underlying filesystem to be unmounted.
  *
- * Context: Caller must hold nfsd_mutex with nn->nfsd_serv confirmed
- *          non-NULL.  nfs4_state_destroy_net() frees conf_id_hashtbl
- *          at server shutdown without clearing the pointer, so a
- *          walk without these guarantees iterates freed slab memory.
+ * Context: Caller must hold nfsd_mutex with NFSD_NET_UP set.  Outside
+ *          that window nn->conf_id_hashtbl is unallocated or freed,
+ *          so the walk would dereference a NULL or dangling pointer.
  */
 void nfsd4_revoke_export_states(struct nfsd_net *nn, const struct path *path)
 {
--- a/fs/nfsd/nfsctl.c
+++ b/fs/nfsd/nfsctl.c
@@ -299,7 +299,7 @@ static ssize_t write_unlock_fs(struct fi
 	error = nlmsvc_unlock_all_by_sb(path.dentry->d_sb);
 	mutex_lock(&nfsd_mutex);
 	nn = net_generic(netns(file), nfsd_net_id);
-	if (nn->nfsd_serv) {
+	if (test_bit(NFSD_NET_UP, &nn->flags)) {
 		nfsd4_cancel_copy_by_sb(netns(file), path.dentry->d_sb);
 		nfsd4_revoke_states(nn, path.dentry->d_sb);
 	} else {
@@ -2424,7 +2424,7 @@ int nfsd_nl_unlock_filesystem_doit(struc
 	error = nlmsvc_unlock_all_by_sb(path.dentry->d_sb);
 
 	mutex_lock(&nfsd_mutex);
-	if (nn->nfsd_serv) {
+	if (test_bit(NFSD_NET_UP, &nn->flags)) {
 		nfsd4_cancel_copy_by_sb(net, path.dentry->d_sb);
 		nfsd4_revoke_states(nn, path.dentry->d_sb);
 	} else {
@@ -2471,7 +2471,7 @@ int nfsd_nl_unlock_export_doit(struct sk
 		return error;
 
 	mutex_lock(&nfsd_mutex);
-	if (nn->nfsd_serv) {
+	if (test_bit(NFSD_NET_UP, &nn->flags)) {
 		nfsd_file_close_export(net, &path);
 		nfsd4_revoke_export_states(nn, &path);
 	} else



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 020/556] NFSD: Prevent client use-after-free during export state revocation
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (18 preceding siblings ...)
  2026-09-09 13:34 ` [PATCH 7.2 019/556] NFSD: Guard admin state-revocation walks with NFSD_NET_UP Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 021/556] NFSD: Consolidate the revocation-path client unpin Greg Kroah-Hartman
                   ` (548 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, NeilBrown, Jeff Layton, Chuck Lever,
	Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chuck Lever <cel@kernel.org>

[ Upstream commit 2108de53568a64936a0da3e04d85c35df98d3fb6 ]

nfsd4_revoke_export_states() has the same use-after-free as
nfsd4_revoke_states(): it drops nn->client_lock across
revoke_one_stid() and the following read of clp->cl_minorversion, but
the stateid reference it holds does not pin the client.  A teardown
racing the dropped lock can free the client while revoke_one_stid()
still dereferences it.

exportfs -u drives this path through NFSD_CMD_UNLOCK_EXPORT, so an
administrator removing an export can race a client expiry.

Skip a client that is already expiring and otherwise pin it with
cl_rpc_users under client_lock before dropping the lock, matching
nfsd4_revoke_states().

Fixes: 2eac189bb059 ("NFSD: Add NFSD_CMD_UNLOCK_EXPORT netlink command")
Reviewed-by: NeilBrown <neil@brown.name>
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Link: https://patch.msgid.link/20260709-cel-v4-4-1d519d9be0cb@kernel.org
Signed-off-by: Chuck Lever <cel@kernel.org>
Stable-dep-of: 2330b788d732 ("NFSD: Prevent client use-after-free during close_lru reaping")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/nfsd/nfs4state.c |   13 ++++++++++---
 1 file changed, 10 insertions(+), 3 deletions(-)

--- a/fs/nfsd/nfs4state.c
+++ b/fs/nfsd/nfs4state.c
@@ -2056,10 +2056,14 @@ void nfsd4_revoke_export_states(struct n
 		struct nfs4_client *clp;
 	retry:
 		list_for_each_entry(clp, head, cl_idhash) {
-			struct nfs4_stid *stid = find_one_export_stid(
-							clp, path,
-							sc_types);
+			struct nfs4_stid *stid;
+
+			/* Skip or pin clp as in nfsd4_revoke_states(). */
+			if (is_client_expired(clp))
+				continue;
+			stid = find_one_export_stid(clp, path, sc_types);
 			if (stid) {
+				atomic_inc(&clp->cl_rpc_users);
 				spin_unlock(&nn->client_lock);
 				revoke_one_stid(nn, clp, stid);
 				nfs4_put_stid(stid);
@@ -2067,6 +2071,9 @@ void nfsd4_revoke_export_states(struct n
 				if (clp->cl_minorversion == 0)
 					nn->nfs40_last_revoke =
 						ktime_get_boottime_seconds();
+				if (atomic_dec_and_test(&clp->cl_rpc_users) &&
+				    is_client_expired(clp))
+					wake_up_all(&expiry_wq);
 				goto retry;
 			}
 		}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 021/556] NFSD: Consolidate the revocation-path client unpin
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (19 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 020/556] NFSD: Prevent client use-after-free during export state revocation Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 022/556] NFSD: Prevent client use-after-free during close_lru reaping Greg Kroah-Hartman
                   ` (547 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, NeilBrown, Jeff Layton, Chuck Lever,
	Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chuck Lever <cel@kernel.org>

[ Upstream commit 3308cf3f11ed23c79f9f3f90b34bbbad3e3a6ea9 ]

The client use-after-free fixes in the state-revocation paths left
four open-coded copies of one idiom: drop a cl_rpc_users pin without
renewing the client's lease, waking force_expire_client() when the
last pin drops on a client it is tearing down.  The accompanying "do
not renew" rationale was documented at only one of the four sites.

put_client_renew_locked() and put_client_renew() already carry the
same pin-drop logic, but they renew a non-expired client's lease and
so would resurrect the client whose state is being revoked.  Factor
the common pin-drop into __put_client_locked(), parameterized by
whether to renew.  The renew helpers pass true; the new
put_client_no_renew_locked() and put_client_no_renew() pass false and
carry the revocation paths, which must not revive the client they are
tearing down.  No change in behavior.

Reviewed-by: NeilBrown <neil@brown.name>
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Link: https://patch.msgid.link/20260709-cel-v4-6-1d519d9be0cb@kernel.org
Signed-off-by: Chuck Lever <cel@kernel.org>
Stable-dep-of: 2330b788d732 ("NFSD: Prevent client use-after-free during close_lru reaping")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/nfsd/nfs4state.c |   69 ++++++++++++++++++++++++++++++----------------------
 1 file changed, 41 insertions(+), 28 deletions(-)

--- a/fs/nfsd/nfs4state.c
+++ b/fs/nfsd/nfs4state.c
@@ -202,18 +202,28 @@ renew_client_locked(struct nfs4_client *
 	clp->cl_state = NFSD4_ACTIVE;
 }
 
+/*
+ * Finish a cl_rpc_users unpin with the client_lock held. A
+ * revocation walk clears @renew so the client whose state it is
+ * revoking is not revived; every other caller renews the lease of
+ * a still-active client.
+ */
+static void __put_client_locked(struct nfs4_client *clp, bool renew)
+{
+	if (is_client_expired(clp))
+		wake_up_all(&expiry_wq);
+	else if (renew)
+		renew_client_locked(clp);
+}
+
 static void put_client_renew_locked(struct nfs4_client *clp)
 {
 	struct nfsd_net *nn = net_generic(clp->net, nfsd_net_id);
 
 	lockdep_assert_held(&nn->client_lock);
 
-	if (!atomic_dec_and_test(&clp->cl_rpc_users))
-		return;
-	if (!is_client_expired(clp))
-		renew_client_locked(clp);
-	else
-		wake_up_all(&expiry_wq);
+	if (atomic_dec_and_test(&clp->cl_rpc_users))
+		__put_client_locked(clp, true);
 }
 
 static void put_client_renew(struct nfs4_client *clp)
@@ -222,10 +232,27 @@ static void put_client_renew(struct nfs4
 
 	if (!atomic_dec_and_lock(&clp->cl_rpc_users, &nn->client_lock))
 		return;
-	if (!is_client_expired(clp))
-		renew_client_locked(clp);
-	else
-		wake_up_all(&expiry_wq);
+	__put_client_locked(clp, true);
+	spin_unlock(&nn->client_lock);
+}
+
+static void put_client_no_renew_locked(struct nfs4_client *clp)
+{
+	struct nfsd_net *nn = net_generic(clp->net, nfsd_net_id);
+
+	lockdep_assert_held(&nn->client_lock);
+
+	if (atomic_dec_and_test(&clp->cl_rpc_users))
+		__put_client_locked(clp, false);
+}
+
+static void put_client_no_renew(struct nfs4_client *clp)
+{
+	struct nfsd_net *nn = net_generic(clp->net, nfsd_net_id);
+
+	if (!atomic_dec_and_lock(&clp->cl_rpc_users, &nn->client_lock))
+		return;
+	__put_client_locked(clp, false);
 	spin_unlock(&nn->client_lock);
 }
 
@@ -1991,9 +2018,7 @@ void nfsd4_revoke_states(struct nfsd_net
 					 */
 					nn->nfs40_last_revoke =
 						ktime_get_boottime_seconds();
-				if (atomic_dec_and_test(&clp->cl_rpc_users) &&
-				    is_client_expired(clp))
-					wake_up_all(&expiry_wq);
+				put_client_no_renew_locked(clp);
 				goto retry;
 			}
 		}
@@ -2071,9 +2096,7 @@ void nfsd4_revoke_export_states(struct n
 				if (clp->cl_minorversion == 0)
 					nn->nfs40_last_revoke =
 						ktime_get_boottime_seconds();
-				if (atomic_dec_and_test(&clp->cl_rpc_users) &&
-				    is_client_expired(clp))
-					wake_up_all(&expiry_wq);
+				put_client_no_renew_locked(clp);
 				goto retry;
 			}
 		}
@@ -7205,9 +7228,7 @@ retry:
 				nfsd4_drop_revoked_stid(stid);
 				nfs4_put_stid(stid);
 				spin_lock(&nn->client_lock);
-				if (atomic_dec_and_test(&clp->cl_rpc_users) &&
-				    is_client_expired(clp))
-					wake_up_all(&expiry_wq);
+				put_client_no_renew_locked(clp);
 				goto retry;
 			}
 		spin_unlock(&clp->cl_lock);
@@ -7280,15 +7301,7 @@ nfs4_laundromat(struct nfsd_net *nn)
 		clp = dp->dl_stid.sc_client;
 		list_del_init(&dp->dl_recall_lru);
 		revoke_delegation(dp);
-		/*
-		 * Unpin without renewing: put_client_renew() would
-		 * renew the reaped client's lease.
-		 */
-		if (atomic_dec_and_lock(&clp->cl_rpc_users, &nn->client_lock)) {
-			if (is_client_expired(clp))
-				wake_up_all(&expiry_wq);
-			spin_unlock(&nn->client_lock);
-		}
+		put_client_no_renew(clp);
 	}
 
 	spin_lock(&nn->client_lock);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 022/556] NFSD: Prevent client use-after-free during close_lru reaping
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (20 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 021/556] NFSD: Consolidate the revocation-path client unpin Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 023/556] NFSD: Prevent client use-after-free during blocked-lock reaping Greg Kroah-Hartman
                   ` (546 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jeff Layton, Chuck Lever,
	Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chuck Lever <cel@kernel.org>

[ Upstream commit 2330b788d732f43668b965b3105b37ceb276dfea ]

An nfs4_openowner left on nn->close_lru after its final CLOSE keeps
its last closed stateid in oo_last_closed_stid, holding only a raw
pointer to its nfs4_client. The laundromat reaps timed-out entries,
drops nn->client_lock, and calls nfs4_put_stid(), which dereferences
the client through cl_lock. Nothing pins the client across that
window, so a concurrent force_expire_client() can free it and
nfs4_put_stid() reads freed memory. __destroy_client() hits the same
race, walking clp->cl_openowners without cl_lock.

Pin the client with cl_rpc_users before dropping client_lock, and
skip clients already expiring. __destroy_client() then cleans up its
own close_lru entries through release_last_closed_stateid(), so
teardown no longer races the laundromat.

Fixes: 217526e7ecc9 ("nfsd: protect the close_lru list and oo_last_closed_stid with client_lock")
Cc: stable@vger.kernel.org
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Link: https://patch.msgid.link/20260709-cel-v4-8-1d519d9be0cb@kernel.org
Signed-off-by: Chuck Lever <cel@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/nfsd/nfs4state.c |    5 +++++
 1 file changed, 5 insertions(+)

--- a/fs/nfsd/nfs4state.c
+++ b/fs/nfsd/nfs4state.c
@@ -7311,11 +7311,16 @@ nfs4_laundromat(struct nfsd_net *nn)
 		if (!state_expired(&lt, oo->oo_time))
 			break;
 		list_del_init(&oo->oo_close_lru);
+		clp = oo->oo_owner.so_client;
+		if (is_client_expired(clp))
+			continue;
 		stp = oo->oo_last_closed_stid;
 		oo->oo_last_closed_stid = NULL;
+		atomic_inc(&clp->cl_rpc_users);
 		spin_unlock(&nn->client_lock);
 		nfs4_put_stid(&stp->st_stid);
 		spin_lock(&nn->client_lock);
+		put_client_no_renew_locked(clp);
 	}
 	spin_unlock(&nn->client_lock);
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 023/556] NFSD: Prevent client use-after-free during blocked-lock reaping
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (21 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 022/556] NFSD: Prevent client use-after-free during close_lru reaping Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 024/556] drm/amd/display: fix division by zero in get_estimated_bw() Greg Kroah-Hartman
                   ` (545 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jeff Layton, Chuck Lever,
	Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chuck Lever <cel@kernel.org>

[ Upstream commit 9026932ac8be4d0ae01db47f23619a98cc57b671 ]

A bare lock owner -- its only remaining reference a blocked lock on
nn->blocked_locks_lru -- holds a raw pointer to its nfs4_client but
no reference keeping the client alive. When the per-net laundromat
reaps such a lock, freeing the nbl drops the owner reference
held through flc_owner, and the final nfs4_put_stateowner()
takes the client's cl_lock. Because the laundromat detaches the
nbl first, __destroy_client() no longer finds it, so a concurrent
force_expire_client() can free the client before nfs4_put_stateowner()
runs, dereferencing cl_lock in freed memory.

Pin the client with cl_rpc_users before dropping
nn->blocked_locks_lock, and skip clients already expiring, whose
blocked locks __destroy_client() frees while holding an owner
reference. Take nn->client_lock outside nn->blocked_locks_lock.
Every other site holds nn->blocked_locks_lock as a leaf, acquiring
no further lock, so placing nn->client_lock outside it cannot form
a lock-order cycle.

Fixes: 7919d0a27f1e ("nfsd: add a LRU list for blocked locks")
Cc: stable@vger.kernel.org
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Link: https://patch.msgid.link/20260709-cel-v4-7-1d519d9be0cb@kernel.org
Signed-off-by: Chuck Lever <cel@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/nfsd/nfs4state.c |   23 ++++++++++++++++++++---
 1 file changed, 20 insertions(+), 3 deletions(-)

--- a/fs/nfsd/nfs4state.c
+++ b/fs/nfsd/nfs4state.c
@@ -353,6 +353,16 @@ free_blocked_lock(struct nfsd4_blocked_l
 	kref_put(&nbl->nbl_kref, free_nbl);
 }
 
+/* A blocked lock's flc_owner is its nfs4_lockowner. */
+static struct nfs4_client *
+nbl_client(struct nfsd4_blocked_lock *nbl)
+{
+	struct nfs4_lockowner *lo;
+
+	lo = (struct nfs4_lockowner *)nbl->nbl_lock.c.flc_owner;
+	return lo->lo_owner.so_client;
+}
+
 static void
 remove_blocked_locks(struct nfs4_lockowner *lo)
 {
@@ -7336,22 +7346,29 @@ nfs4_laundromat(struct nfsd_net *nn)
 	 * indefinitely once the lock does become free.
 	 */
 	BUG_ON(!list_empty(&reaplist));
+	spin_lock(&nn->client_lock);
 	spin_lock(&nn->blocked_locks_lock);
-	while (!list_empty(&nn->blocked_locks_lru)) {
-		nbl = list_first_entry(&nn->blocked_locks_lru,
-					struct nfsd4_blocked_lock, nbl_lru);
+	list_for_each_safe(pos, next, &nn->blocked_locks_lru) {
+		nbl = list_entry(pos, struct nfsd4_blocked_lock, nbl_lru);
 		if (!state_expired(&lt, nbl->nbl_time))
 			break;
+		clp = nbl_client(nbl);
+		if (is_client_expired(clp))
+			continue;
+		atomic_inc(&clp->cl_rpc_users);
 		list_move(&nbl->nbl_lru, &reaplist);
 		list_del_init(&nbl->nbl_list);
 	}
 	spin_unlock(&nn->blocked_locks_lock);
+	spin_unlock(&nn->client_lock);
 
 	while (!list_empty(&reaplist)) {
 		nbl = list_first_entry(&reaplist,
 					struct nfsd4_blocked_lock, nbl_lru);
+		clp = nbl_client(nbl);
 		list_del_init(&nbl->nbl_lru);
 		free_blocked_lock(nbl);
+		put_client_no_renew(clp);
 	}
 #ifdef CONFIG_NFSD_V4_2_INTER_SSC
 	/* service the server-to-server copy delayed unmount list */



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 024/556] drm/amd/display: fix division by zero in get_estimated_bw()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (22 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 023/556] NFSD: Prevent client use-after-free during blocked-lock reaping Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 025/556] usb: image: mdc800: change kmalloc() to kzalloc() Greg Kroah-Hartman
                   ` (544 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Alex Hung, Hari Mishal, Alex Deucher

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Hari Mishal <harimishal1@gmail.com>

commit f63de9054da858d57054474c32464106f8375e0d upstream.

get_estimated_bw() divides by link->dpia_bw_alloc_config.bw_granularity,
which is zeroed by reset_bw_alloc_struct() and only populated once
DP_TUNNELING_BW_ALLOC_CAP_CHANGED has been handled.

link_dp_dpia_handle_bw_alloc_status(), the DPCD interrupt handler,
calls get_estimated_bw() whenever DP_TUNNELING_ESTIMATED_BW_CHANGED
is set, independently of whether DP_TUNNELING_BW_ALLOC_CAP_CHANGED
has ever fired for that link. A connected USB4/DPIA tunneling device
that reports an estimated-bandwidth change before ever reporting a
capability change drives a division by zero in this IRQ path.

link_dpia_send_bw_alloc_request() already guards the same
bw_granularity division; add the identical guard here rather than
introducing a new pattern.

Fixes: 8e5cfe547bf3 ("drm/amd/display: upstream link_dp_dpia_bw.c")
Reviewed-by: Alex Hung <alex.hung@amd.com>
Assisted-by: gkh_clanker_t1000
Signed-off-by: Hari Mishal <harimishal1@gmail.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit f2a961457c33dc34223aad5c9e8971de34a4eed3)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/display/dc/link/protocols/link_dp_dpia_bw.c |    5 +++++
 1 file changed, 5 insertions(+)

--- a/drivers/gpu/drm/amd/display/dc/link/protocols/link_dp_dpia_bw.c
+++ b/drivers/gpu/drm/amd/display/dc/link/protocols/link_dp_dpia_bw.c
@@ -103,6 +103,11 @@ static int get_estimated_bw(struct dc_li
 {
 	uint8_t bw_estimated_bw = 0;
 
+	if (link->dpia_bw_alloc_config.bw_granularity == 0) {
+		DC_LOG_ERROR("%s: BW granularity is zero!\n", __func__);
+		return 0;
+	}
+
 	core_link_read_dpcd(
 			link,
 			ESTIMATED_BW,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 025/556] usb: image: mdc800: change kmalloc() to kzalloc()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (23 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 024/556] drm/amd/display: fix division by zero in get_estimated_bw() Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 026/556] ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output() Greg Kroah-Hartman
                   ` (543 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Griffin Kroah-Hartman

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Griffin Kroah-Hartman <griffin@kroah.com>

commit 2430eb81e44111b30eeb5273bbcf8b24ca517ef9 upstream.

Change the kmalloc() calls in usb_mdc800_init() for irq_urb_buffer and
download_urb_buffer to kzalloc(), avoiding potential stack leaks if a
shorter message is received in mdc800_usb_irq() and
mdc800_usb_download_notify()

Assisted-by: gkh_clanker_t1000
Cc: stable <stable@kernel.org>
Signed-off-by: Griffin Kroah-Hartman <griffin@kroah.com>
Link: https://patch.msgid.link/20260819-usb_misc_random-v1-1-43a0dcee3a32@kroah.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/usb/image/mdc800.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/drivers/usb/image/mdc800.c
+++ b/drivers/usb/image/mdc800.c
@@ -1000,13 +1000,13 @@ static int __init usb_mdc800_init (void)
 	mdc800->downloaded = 0;
 	mdc800->written = 0;
 
-	mdc800->irq_urb_buffer=kmalloc (8, GFP_KERNEL);
+	mdc800->irq_urb_buffer=kzalloc (8, GFP_KERNEL);
 	if (!mdc800->irq_urb_buffer)
 		goto cleanup_on_fail;
 	mdc800->write_urb_buffer=kmalloc (8, GFP_KERNEL);
 	if (!mdc800->write_urb_buffer)
 		goto cleanup_on_fail;
-	mdc800->download_urb_buffer=kmalloc (64, GFP_KERNEL);
+	mdc800->download_urb_buffer=kzalloc (64, GFP_KERNEL);
 	if (!mdc800->download_urb_buffer)
 		goto cleanup_on_fail;
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 026/556] ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (24 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 025/556] usb: image: mdc800: change kmalloc() to kzalloc() Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 027/556] clk: qcom: gcc-mdm9607: Increase delay for USB PHY reset Greg Kroah-Hartman
                   ` (542 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, HyeongJun An, Takashi Iwai

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: HyeongJun An <sammiee5311@gmail.com>

commit e4637ce34607f1733a34a57294966d26b263e626 upstream.

The snd_usbmidi_us122l_output() picks a count of 2 on anything slower
than high speed and never relates it to ep->max_transfer.  The URB
buffer holds exactly max_transfer bytes, so a device declaring a one
byte bulk endpoint takes two bytes from snd_rawmidi_transmit(), and the
memset that pads the rest computes 1 - 2 in int and wraps to SIZE_MAX.

Only 0x800e and 0x800f are pinned to nine bytes.  The US-122MKII at
0x0644:0x8021 falls to the default and takes usb_maxpacket(), which the
USB core only clamps downward.

The akai and novation output ops in this file were given the same guard
recently.  Do the same here.

Fixes: 030a07e44129 ("ALSA: Add USB US122L driver")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-5
Signed-off-by: HyeongJun An <sammiee5311@gmail.com>
Link: https://patch.msgid.link/20260901090409.1478573-1-sammiee5311@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/usb/midi.c |    2 ++
 1 file changed, 2 insertions(+)

--- a/sound/usb/midi.c
+++ b/sound/usb/midi.c
@@ -971,6 +971,8 @@ static void snd_usbmidi_us122l_output(st
 	default:
 		count = 2;
 	}
+	if (ep->max_transfer < count)
+		return;
 	count = snd_rawmidi_transmit(ep->ports[0].substream,
 				     urb->transfer_buffer,
 				     count);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 027/556] clk: qcom: gcc-mdm9607: Increase delay for USB PHY reset
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (25 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 026/556] ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output() Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 028/556] media: usbtv: keep device alive while ALSA card exists Greg Kroah-Hartman
                   ` (541 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Stephan Gerhold,
	Bjorn Andersson

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Stephan Gerhold <stephan@gerhold.net>

commit c99bc8e83848358bd4a0436e4bdae5b7919babb2 upstream.

To conform to the specifications of the USB PHY, the reset signal should be
asserted for at least 10us. Guarantee that by increasing the delay for the
USB2_HS_PHY_ONLY_BCR reset control similar to commit dcc6c9fb7128 ("clk:
qcom: gcc-msm8909: Increase delay for USB PHY reset").

Cc: stable@vger.kernel.org
Fixes: 48b7253264ea ("clk: qcom: Add MDM9607 GCC driver")
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Stephan Gerhold <stephan@gerhold.net>
Link: https://lore.kernel.org/r/20260706-qcom-clk-mdm9607-fixes-v2-5-745565101869@linaro.org
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/clk/qcom/gcc-mdm9607.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/clk/qcom/gcc-mdm9607.c
+++ b/drivers/clk/qcom/gcc-mdm9607.c
@@ -1567,7 +1567,7 @@ static const struct qcom_reset_map gcc_m
 	[USB_HS_HSIC_BCR] = { 0x3d05c },
 	[GCC_MSS_RESTART] = { 0x3e000 },
 	[USB_HS_BCR] = { 0x41000 },
-	[USB2_HS_PHY_ONLY_BCR] = { 0x41034 },
+	[USB2_HS_PHY_ONLY_BCR] = { .reg = 0x41034, .udelay = 15 },
 	[QUSB2_PHY_BCR] = { 0x4103c },
 };
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 028/556] media: usbtv: keep device alive while ALSA card exists
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (26 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 027/556] clk: qcom: gcc-mdm9607: Increase delay for USB PHY reset Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 029/556] usb-storage: ene_ub6250: fix race between scan work and probe Greg Kroah-Hartman
                   ` (540 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Shuangpeng Bai, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Shuangpeng Bai <shuangpeng.kernel@gmail.com>

commit fc530fe168bb2b745a93f553ad21fc25fd9cba3d upstream.

The ALSA PCM callbacks store the driver state in pcm->private_data. An
open PCM file can outlive USB disconnect because usbtv_audio_free() uses
snd_card_free_when_closed(). The disconnect path can then drop the V4L2
device reference and free struct usbtv before ALSA releases the substream,
so a later close dereferences freed memory in snd_usbtv_pcm_close().

Take a V4L2 device reference for the ALSA card and drop it from the card
private_free callback. This keeps struct usbtv valid until ALSA has closed
the remaining files and freed the card.

Closes: https://lore.kernel.org/r/178144969601.60470.4852887710381872458@gmail.com
Fixes: 63ddf68de52e ("[media] usbtv: add audio support")
Cc: stable@vger.kernel.org
Signed-off-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/usb/usbtv/usbtv-audio.c |   11 +++++++++++
 1 file changed, 11 insertions(+)

--- a/drivers/media/usb/usbtv/usbtv-audio.c
+++ b/drivers/media/usb/usbtv/usbtv-audio.c
@@ -317,6 +317,13 @@ static const struct snd_pcm_ops snd_usbt
 	.pointer = snd_usbtv_pointer,
 };
 
+static void usbtv_audio_card_free(struct snd_card *card)
+{
+	struct usbtv *usbtv = card->private_data;
+
+	v4l2_device_put(&usbtv->v4l2_dev);
+}
+
 int usbtv_audio_init(struct usbtv *usbtv)
 {
 	int rv;
@@ -331,6 +338,10 @@ int usbtv_audio_init(struct usbtv *usbtv
 	if (rv < 0)
 		return rv;
 
+	v4l2_device_get(&usbtv->v4l2_dev);
+	card->private_data = usbtv;
+	card->private_free = usbtv_audio_card_free;
+
 	strscpy(card->driver, usbtv->dev->driver->name, sizeof(card->driver));
 	strscpy(card->shortname, "usbtv", sizeof(card->shortname));
 	snprintf(card->longname, sizeof(card->longname),



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 029/556] usb-storage: ene_ub6250: fix race between scan work and probe
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (27 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 028/556] media: usbtv: keep device alive while ALSA card exists Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 030/556] usb: cdnsp: fix wakeup from S3 after controller context loss Greg Kroah-Hartman
                   ` (539 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+22ea20ef3afb6785b122, stable,
	Liu Qi, Alan Stern

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Liu Qi <liuqi@longcheer.com>

commit 445fc368c6bc73eff0aeb3818cf5f355facfbb16 upstream.

ene_ub6250_probe() calls usb_stor_probe2(), which starts the usb-storage
infrastructure and schedules the delayed scan work.  The driver then
calls ene_get_card_type(), which sends an ENE command through
ene_send_scsi_cmd() and the usb-storage bulk transfer helpers.

Both the delayed scan work, through usb_stor_Bulk_max_lun(), and
ene_get_card_type() use us->current_urb.  The scan work serializes this
access with us->dev_mutex, but the ENE card-type probe does not.  If the
scan work runs while ene_get_card_type() is still using us->current_urb,
usb_submit_urb() warns that the URB is already active.

Serialize ene_get_card_type() with us->dev_mutex, matching the locking
used by the scan path.

Reported-by: syzbot+22ea20ef3afb6785b122@syzkaller.appspotmail.com
Cc: stable <stable@kernel.org>
Closes: https://syzkaller.appspot.com/bug?extid=22ea20ef3afb6785b122
Assisted-by: Qwen:Qwen3.6
Signed-off-by: Liu Qi <liuqi@longcheer.com>
Acked-by: Alan Stern <stern@rowland.harvard.edu>
Link: https://patch.msgid.link/20260821090416.1247127-1-liuqi@longcheer.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/usb/storage/ene_ub6250.c |    2 ++
 1 file changed, 2 insertions(+)

--- a/drivers/usb/storage/ene_ub6250.c
+++ b/drivers/usb/storage/ene_ub6250.c
@@ -2357,7 +2357,9 @@ static int ene_ub6250_probe(struct usb_i
 		return result;
 
 	/* probe card type */
+	mutex_lock(&us->dev_mutex);
 	result = ene_get_card_type(us, REG_CARD_STATUS, info->bbuf);
+	mutex_unlock(&us->dev_mutex);
 	if (result != USB_STOR_XFER_GOOD) {
 		usb_stor_disconnect(intf);
 		return USB_STOR_TRANSPORT_ERROR;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 030/556] usb: cdnsp: fix wakeup from S3 after controller context loss
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (28 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 029/556] usb-storage: ene_ub6250: fix race between scan work and probe Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 031/556] usb: f_mass_storage: Bump local buffer size in fsg_common_create_luns() Greg Kroah-Hartman
                   ` (538 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Pawel Laszczak, Peter Chen

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pawel Laszczak <pawell@cadence.com>

commit eae6460f617382044c5afe5ef202f4d8b2c099b5 upstream.

CDNSP controller may lose its runtime register programming across S3
suspend/resume, depending on SoC power domain configuration. After
resume the operational and interrupter registers may contain reset
values, which prevents the gadget side from recovering correctly and
breaks wakeup from S3.

Fix this by detecting whether the controller lost its register context
after resume and handling both cases:
- If context was lost (CFG_3XPORT_U1_PIPE_CLK_GATE_EN set or power
  lost): reset the controller and reprogram the state required for
  normal operation, including the command ring, DCBAA pointer, doorbell
  base, event ring, ERST base/size and event ring dequeue pointer.
- If context was retained: restart the controller directly without
  reprogramming registers. Issue a wakeup if the link was in U3 before
  suspend.

Move the basic controller register programming out of the one-time memory
initialization path and make it reusable from the resume path. Also
separate ring allocation from ring initialization so that rings can be
reinitialized without reallocating DMA memory.

Always perform the full suspend sequence regardless of the current link
state. Previously, if the device was already in U3, the suspend callback
returned early without stopping the controller, which could lead to
commands being issued on a disabled slot during resume.

Fixes: 3d82904559f4 ("usb: cdnsp: cdns3 Add main part of Cadence USBSSP DRD Driver")
Cc: stable <stable@kernel.org>
Signed-off-by: Pawel Laszczak <pawell@cadence.com>
Acked-by: Peter Chen <peter.chen@kernel.org>
Link: https://patch.msgid.link/20260820-suspend_resume_fix-v3-1-5a713098b977@cadence.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/usb/cdns3/cdnsp-gadget.c |  111 +++++++++++++++++++++++++++++++++++++--
 drivers/usb/cdns3/cdnsp-gadget.h |    1 
 drivers/usb/cdns3/cdnsp-mem.c    |   98 ++++++++++++----------------------
 3 files changed, 142 insertions(+), 68 deletions(-)

--- a/drivers/usb/cdns3/cdnsp-gadget.c
+++ b/drivers/usb/cdns3/cdnsp-gadget.c
@@ -1338,7 +1338,6 @@ static int cdnsp_run(struct cdnsp_device
 
 	cdnsp_gadget_ep0_desc.wMaxPacketSize = cpu_to_le16(512);
 
-
 	ret = cdnsp_start(pdev);
 	if (ret) {
 		ret = -ENODEV;
@@ -1837,6 +1836,82 @@ static void cdnsp_get_rev_cap(struct cdn
 		 readl(&pdev->rev_cap->tx_buff_size));
 }
 
+static void cdnsp_set_event_deq(struct cdnsp_device *pdev)
+{
+	dma_addr_t deq;
+	u64 temp;
+
+	deq = cdnsp_trb_virt_to_dma(pdev->event_ring->deq_seg,
+				    pdev->event_ring->dequeue);
+
+	/* Update controller event ring dequeue pointer */
+	temp = cdnsp_read_64(&pdev->ir_set->erst_dequeue);
+	temp &= ERST_PTR_MASK;
+
+	/*
+	 * Don't clear the EHB bit (which is RW1C) because
+	 * there might be more events to service.
+	 */
+	temp &= ~ERST_EHB;
+
+	cdnsp_write_64(((u64)deq & (u64)~ERST_PTR_MASK) | temp,
+		       &pdev->ir_set->erst_dequeue);
+}
+
+static void cdnsp_add_interrupter(struct cdnsp_device *pdev)
+{
+	u64 erst_base;
+	u32 erst_size;
+
+	/* Set ERST count with the number of entries in the segment table. */
+	erst_size = readl(&pdev->ir_set->erst_size);
+	erst_size &= ERST_SIZE_MASK;
+	erst_size |= ERST_NUM_SEGS;
+	writel(erst_size, &pdev->ir_set->erst_size);
+
+	/* Set the segment table base address. */
+	erst_base = cdnsp_read_64(&pdev->ir_set->erst_base);
+	erst_base &= ERST_PTR_MASK;
+	erst_base |= (pdev->erst.erst_dma_addr & (u64)~ERST_PTR_MASK);
+	cdnsp_write_64(erst_base, &pdev->ir_set->erst_base);
+
+	/* Set the event ring dequeue address. */
+	cdnsp_set_event_deq(pdev);
+}
+
+/* Set up basic CDNSP registers */
+static void cdnsp_init(struct cdnsp_device *pdev)
+{
+	unsigned int val;
+	u64 val_64;
+
+	val = readl(&pdev->op_regs->config_reg);
+	val |= ((val & ~MAX_DEVS) | CDNSP_DEV_MAX_SLOTS) | CONFIG_U3E;
+	writel(val, &pdev->op_regs->config_reg);
+
+	/* Initialize the Command ring */
+	cdnsp_ring_init(pdev, pdev->cmd_ring);
+
+	/* Set the address in the Command Ring Control register */
+	val_64 = cdnsp_read_64(&pdev->op_regs->cmd_ring);
+	val_64 = (val_64 & (u64)CMD_RING_RSVD_BITS) |
+		 (pdev->cmd_ring->first_seg->dma & (u64)~CMD_RING_RSVD_BITS) |
+		 pdev->cmd_ring->cycle_state;
+	cdnsp_write_64(val_64, &pdev->op_regs->cmd_ring);
+
+	/* Set Device Context Base Address Array pointer */
+	cdnsp_write_64(pdev->dcbaa->dma, &pdev->op_regs->dcbaa_ptr);
+
+	/* Set Doorbell array pointer */
+	val = readl(&pdev->cap_regs->db_off);
+	val &= DBOFF_MASK;
+	pdev->dba = (void __iomem *)pdev->cap_regs + val;
+
+	/* Initialize the Primary interrupter */
+	cdnsp_ring_init(pdev, pdev->event_ring);
+	cdnsp_add_interrupter(pdev);
+}
+
 static int cdnsp_gen_setup(struct cdnsp_device *pdev)
 {
 	int ret;
@@ -1902,6 +1977,8 @@ static int cdnsp_gen_setup(struct cdnsp_
 	if (ret)
 		return ret;
 
+	cdnsp_init(pdev);
+
 	/*
 	 * Software workaround for U1: after transition
 	 * to U1 the controller starts gating clock, and in some cases,
@@ -2031,9 +2108,6 @@ static int cdnsp_gadget_suspend(struct c
 	struct cdnsp_device *pdev = cdns->gadget_dev;
 	unsigned long flags;
 
-	if (pdev->link_state == XDEV_U3)
-		return 0;
-
 	spin_lock_irqsave(&pdev->lock, flags);
 	cdnsp_disconnect_gadget(pdev);
 	cdnsp_stop(pdev);
@@ -2047,12 +2121,38 @@ static int cdnsp_gadget_resume(struct cd
 	struct cdnsp_device *pdev = cdns->gadget_dev;
 	enum usb_device_speed max_speed;
 	unsigned long flags;
+	bool context_lost;
+	u32 val;
 	int ret;
 
 	if (!pdev->gadget_driver)
 		return 0;
 
 	spin_lock_irqsave(&pdev->lock, flags);
+	val = readl(&pdev->port3x_regs->mode_2);
+	context_lost = !!(val & CFG_3XPORT_U1_PIPE_CLK_GATE_EN) || lost_power;
+
+	if (context_lost) {
+		cdnsp_halt(pdev);
+		cdnsp_set_apb_timeout_value(pdev);
+
+		/* Reset the internal controller memory state and registers. */
+		ret = cdnsp_reset(pdev);
+		if (ret)
+			goto unlock;
+
+		val = readl(&pdev->port3x_regs->mode_2);
+		val &= ~CFG_3XPORT_U1_PIPE_CLK_GATE_EN;
+		writel(val, &pdev->port3x_regs->mode_2);
+
+		cdnsp_clear_cmd_ring(pdev);
+
+		memset(pdev->event_ring->first_seg->trbs, 0,
+		       sizeof(union cdnsp_trb) * (TRBS_PER_SEGMENT));
+
+		cdnsp_init(pdev);
+	}
+
 	max_speed = pdev->gadget_driver->max_speed;
 
 	/* Limit speed if necessary. */
@@ -2060,9 +2160,10 @@ static int cdnsp_gadget_resume(struct cd
 
 	ret = cdnsp_run(pdev, max_speed);
 
-	if (pdev->link_state == XDEV_U3)
+	if (!context_lost && pdev->link_state == XDEV_U3)
 		__cdnsp_gadget_wakeup(pdev);
 
+unlock:
 	spin_unlock_irqrestore(&pdev->lock, flags);
 
 	return ret;
--- a/drivers/usb/cdns3/cdnsp-gadget.h
+++ b/drivers/usb/cdns3/cdnsp-gadget.h
@@ -1510,6 +1510,7 @@ int cdnsp_endpoint_init(struct cdnsp_dev
 int cdnsp_ring_expansion(struct cdnsp_device *pdev,
 			 struct cdnsp_ring *ring,
 			 unsigned int num_trbs, gfp_t flags);
+void cdnsp_ring_init(struct cdnsp_device *pdev, struct cdnsp_ring *ring);
 struct cdnsp_ring *cdnsp_dma_to_transfer_ring(struct cdnsp_ep *ep, u64 address);
 int cdnsp_alloc_stream_info(struct cdnsp_device *pdev,
 			    struct cdnsp_ep *pep,
--- a/drivers/usb/cdns3/cdnsp-mem.c
+++ b/drivers/usb/cdns3/cdnsp-mem.c
@@ -394,13 +394,6 @@ static struct cdnsp_ring *cdnsp_ring_all
 	if (ret)
 		goto fail;
 
-	/* Only event ring does not use link TRB. */
-	if (type != TYPE_EVENT)
-		ring->last_seg->trbs[TRBS_PER_SEGMENT - 1].link.control |=
-			cpu_to_le32(LINK_TOGGLE);
-
-	cdnsp_initialize_ring_info(ring);
-	trace_cdnsp_ring_alloc(ring);
 	return ring;
 fail:
 	kfree(ring);
@@ -603,6 +596,7 @@ int cdnsp_alloc_stream_info(struct cdnsp
 		if (!cur_ring)
 			goto cleanup_rings;
 
+		cdnsp_ring_init(pdev, cur_ring);
 		cur_ring->stream_id = cur_stream;
 		cur_ring->trb_address_map = &stream_info->trb_address_map;
 
@@ -698,6 +692,8 @@ static int cdnsp_alloc_priv_device(struc
 	if (!pdev->eps[0].ring)
 		goto fail;
 
+	cdnsp_ring_init(pdev, pdev->eps[0].ring);
+
 	/* Point to output device context in dcbaa. */
 	pdev->dcbaa->dev_context_ptrs[1] = cpu_to_le64(pdev->out_ctx.dma);
 	pdev->cmd.in_ctx = &pdev->in_ctx;
@@ -991,6 +987,8 @@ int cdnsp_endpoint_init(struct cdnsp_dev
 	if (!pep->ring)
 		return -ENOMEM;
 
+	cdnsp_ring_init(pdev, pep->ring);
+
 	pep->skip = false;
 
 	/* Fill the endpoint context */
@@ -1096,28 +1094,6 @@ void cdnsp_mem_cleanup(struct cdnsp_devi
 	pdev->active_port = NULL;
 }
 
-static void cdnsp_set_event_deq(struct cdnsp_device *pdev)
-{
-	dma_addr_t deq;
-	u64 temp;
-
-	deq = cdnsp_trb_virt_to_dma(pdev->event_ring->deq_seg,
-				    pdev->event_ring->dequeue);
-
-	/* Update controller event ring dequeue pointer */
-	temp = cdnsp_read_64(&pdev->ir_set->erst_dequeue);
-	temp &= ERST_PTR_MASK;
-
-	/*
-	 * Don't clear the EHB bit (which is RW1C) because
-	 * there might be more events to service.
-	 */
-	temp &= ~ERST_EHB;
-
-	cdnsp_write_64(((u64)deq & (u64)~ERST_PTR_MASK) | temp,
-		       &pdev->ir_set->erst_dequeue);
-}
-
 static void cdnsp_add_in_port(struct cdnsp_device *pdev,
 			      struct cdnsp_port *port,
 			      __le32 __iomem *addr)
@@ -1226,6 +1202,36 @@ static int cdnsp_setup_port_arrays(struc
 	return 0;
 }
 
+static void cdnsp_initialize_ring_segments(struct cdnsp_device *pdev, struct cdnsp_ring *ring)
+{
+	struct cdnsp_segment *seg;
+
+	/* Only event ring does not use link TRB. */
+	if (ring->type == TYPE_EVENT)
+		return;
+
+	seg = ring->first_seg;
+
+	while (seg) {
+		struct cdnsp_segment *next = seg->next;
+
+		cdnsp_link_segments(pdev, seg, next, ring->type);
+		if (next == ring->first_seg)
+			break;
+
+		seg = next;
+	}
+
+	ring->last_seg->trbs[TRBS_PER_SEGMENT - 1].link.control |= cpu_to_le32(LINK_TOGGLE);
+}
+
+void cdnsp_ring_init(struct cdnsp_device *pdev, struct cdnsp_ring *ring)
+{
+	cdnsp_initialize_ring_segments(pdev, ring);
+	cdnsp_initialize_ring_info(ring);
+	trace_cdnsp_ring_alloc(ring);
+}
+
 /*
  * Initialize memory for CDNSP (one-time init).
  *
@@ -1237,10 +1243,8 @@ int cdnsp_mem_init(struct cdnsp_device *
 {
 	struct device *dev = pdev->dev;
 	int ret = -ENOMEM;
-	unsigned int val;
 	dma_addr_t dma;
 	u32 page_size;
-	u64 val_64;
 
 	/*
 	 * Use 4K pages, since that's common and the minimum the
@@ -1248,10 +1252,6 @@ int cdnsp_mem_init(struct cdnsp_device *
 	 */
 	page_size = 1 << 12;
 
-	val = readl(&pdev->op_regs->config_reg);
-	val |= ((val & ~MAX_DEVS) | CDNSP_DEV_MAX_SLOTS) | CONFIG_U3E;
-	writel(val, &pdev->op_regs->config_reg);
-
 	/*
 	 * Doorbell array must be physically contiguous
 	 * and 64-byte (cache line) aligned.
@@ -1263,8 +1263,6 @@ int cdnsp_mem_init(struct cdnsp_device *
 
 	pdev->dcbaa->dma = dma;
 
-	cdnsp_write_64(dma, &pdev->op_regs->dcbaa_ptr);
-
 	/*
 	 * Initialize the ring segment pool.  The ring must be a contiguous
 	 * structure comprised of TRBs. The TRBs must be 16 byte aligned,
@@ -1290,17 +1288,6 @@ int cdnsp_mem_init(struct cdnsp_device *
 	if (!pdev->cmd_ring)
 		goto destroy_device_pool;
 
-	/* Set the address in the Command Ring Control register */
-	val_64 = cdnsp_read_64(&pdev->op_regs->cmd_ring);
-	val_64 = (val_64 & (u64)CMD_RING_RSVD_BITS) |
-		 (pdev->cmd_ring->first_seg->dma & (u64)~CMD_RING_RSVD_BITS) |
-		 pdev->cmd_ring->cycle_state;
-	cdnsp_write_64(val_64, &pdev->op_regs->cmd_ring);
-
-	val = readl(&pdev->cap_regs->db_off);
-	val &= DBOFF_MASK;
-	pdev->dba = (void __iomem *)pdev->cap_regs + val;
-
 	/* Set ir_set to interrupt register set 0 */
 	pdev->ir_set = &pdev->run_regs->ir_set[0];
 
@@ -1317,21 +1304,6 @@ int cdnsp_mem_init(struct cdnsp_device *
 	if (ret)
 		goto free_event_ring;
 
-	/* Set ERST count with the number of entries in the segment table. */
-	val = readl(&pdev->ir_set->erst_size);
-	val &= ERST_SIZE_MASK;
-	val |= ERST_NUM_SEGS;
-	writel(val, &pdev->ir_set->erst_size);
-
-	/* Set the segment table base address. */
-	val_64 = cdnsp_read_64(&pdev->ir_set->erst_base);
-	val_64 &= ERST_PTR_MASK;
-	val_64 |= (pdev->erst.erst_dma_addr & (u64)~ERST_PTR_MASK);
-	cdnsp_write_64(val_64, &pdev->ir_set->erst_base);
-
-	/* Set the event ring dequeue address. */
-	cdnsp_set_event_deq(pdev);
-
 	ret = cdnsp_setup_port_arrays(pdev);
 	if (ret)
 		goto free_erst;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 031/556] usb: f_mass_storage: Bump local buffer size in fsg_common_create_luns()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (29 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 030/556] usb: cdnsp: fix wakeup from S3 after controller context loss Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 032/556] usb: dwc3: google: Initialise probe properties with DWC3_DEFAULT_PROPERTIES Greg Kroah-Hartman
                   ` (537 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Alan Stern, Andy Shevchenko

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Andy Shevchenko <andriy.shevchenko@linux.intel.com>

commit 9f6f095beec82a80daa666a3b2186a5b95841e9a upstream.

GCC (Debian 14.2.0-19) is not happy about the buffer size:

drivers/usb/gadget/function/f_mass_storage.c:2970:48: error: ‘%d’ directive output may be truncated writing between 1 and 9 bytes into a region of size 5 [-Werror=format-truncation=]

Bump the size to get it enough for all possible values.

Note, although cfg->nluns is limited to FSG_MAX_LUNS (16), the compiler
doesn't realize this and complains about the buffer size.

Also note, the existing comment is wrong as size 8 for the whole buffer
doesn't cover 100 mil numbers, hence drop it altogether.

Fixes: b27c08c953e9 ("usb: gadget: f_mass_storage: create lun creation helpers for use in fsg_common_init")
Cc: stable <stable@kernel.org>
Acked-by: Alan Stern <stern@rowland.harvard.edu>
Signed-off-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
Link: https://patch.msgid.link/20260817161239.1448582-1-andriy.shevchenko@linux.intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/usb/gadget/function/f_mass_storage.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/usb/gadget/function/f_mass_storage.c
+++ b/drivers/usb/gadget/function/f_mass_storage.c
@@ -2961,7 +2961,7 @@ EXPORT_SYMBOL_GPL(fsg_common_create_lun)
 
 int fsg_common_create_luns(struct fsg_common *common, struct fsg_config *cfg)
 {
-	char buf[8]; /* enough for 100000000 different numbers, decimal */
+	char buf[14];
 	int i, rc;
 
 	fsg_common_remove_luns(common);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 032/556] usb: dwc3: google: Initialise probe properties with DWC3_DEFAULT_PROPERTIES
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (30 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 031/556] usb: f_mass_storage: Bump local buffer size in fsg_common_create_luns() Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 033/556] usb: dwc3: clear forceRM when issuing EndTransfer Greg Kroah-Hartman
                   ` (536 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, stable, Radhey Shyam Pandey,
	Thinh Nguyen

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Radhey Shyam Pandey <radhey.shyam.pandey@amd.com>

commit 6b2a674fcc953378e5e750d47a888bbe51229de5 upstream.

dwc3_google_probe() zero initialises struct dwc3_probe_data and never
assigns its properties member. The unspecified state of gsbuscfg0_reqinfo
is encoded as DWC3_GSBUSCFG0_REQINFO_UNSPECIFIED (0xffffffff), not as
zero, so dwc3_get_software_properties() reads the zeroed field as a value
the glue explicitly requested:

	if (properties->gsbuscfg0_reqinfo !=
	    DWC3_GSBUSCFG0_REQINFO_UNSPECIFIED) {
		dwc->gsbuscfg0_reqinfo = properties->gsbuscfg0_reqinfo;
		return;
	}

Two things follow. dwc3_config_soc_bus() programs GSBUSCFG0.REQINFO with
zero on hardware that never asked for it, and the early return skips the
walk over the parent devices, so a swnode or device tree supplied
snps,gsbuscfg0-reqinfo would be ignored.

Assign DWC3_DEFAULT_PROPERTIES so the unset fields carry their unspecified
sentinels and the controller is left alone.

Fixes: 8995a37371bf ("usb: dwc3: Add Google Tensor SoC DWC3 glue driver")
Cc: stable <stable@kernel.org>
Signed-off-by: Radhey Shyam Pandey <radhey.shyam.pandey@amd.com>
Acked-by: Thinh Nguyen <Thinh.Nguyen@synopsys.com>
Link: https://patch.msgid.link/20260819182158.1351869-1-radhey.shyam.pandey@amd.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/usb/dwc3/dwc3-google.c |    1 +
 1 file changed, 1 insertion(+)

--- a/drivers/usb/dwc3/dwc3-google.c
+++ b/drivers/usb/dwc3/dwc3-google.c
@@ -442,6 +442,7 @@ static int dwc3_google_probe(struct plat
 	probe_data.dwc = &google->dwc;
 	probe_data.res = res;
 	probe_data.ignore_clocks_and_resets = true;
+	probe_data.properties = DWC3_DEFAULT_PROPERTIES;
 	ret = dwc3_core_probe(&probe_data);
 	if (ret)  {
 		ret = dev_err_probe(dev, ret, "failed to register DWC3 Core\n");



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 033/556] usb: dwc3: clear forceRM when issuing EndTransfer
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (31 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 032/556] usb: dwc3: google: Initialise probe properties with DWC3_DEFAULT_PROPERTIES Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 034/556] usb: storage: realtek_cr: fix use-after-free on disconnect Greg Kroah-Hartman
                   ` (535 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Elson Serrao, Thinh Nguyen

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Elson Serrao <elson.serrao@oss.qualcomm.com>

commit b58e6200450d350314db0ecda7d6d1bde3281e80 upstream.

The forceRM bit of the DEPCMD register controls the behavior of the
EndTransfer command used to stop an active transfer. Older DWC3
programming guide revisions recommended setting forceRM=1 when
issuing EndTransfer. Newer programming guide revisions recommend
issuing EndTransfer with forceRM cleared.

With forceRM=1 on DWC_usb31 v2.00a and v2.10a controllers, a transfer
aborted through the ep_dequeue path was observed to remain active
after EndTransfer completion. A subsequent StartTransfer issued on the
same endpoint triggered writes associated with the aborted transfer.
This resulted in an SMMU fault because the transfer buffer had already
been unmapped during EndTransfer command-completion cleanup.

Using forceRM=0 eliminates the issue. Although older DWC3 programming
guide revisions recommended setting forceRM=1, no issues are known
from using forceRM=0. Clear forceRM when issuing EndTransfer to provide
consistent EndTransfer behavior and align with newer programming guide
recommendations.

Fixes: 1e43c86d84fb ("usb: dwc3: core: Add DWC31 version 2.00a controller")
Cc: stable <stable@kernel.org>
Signed-off-by: Elson Serrao <elson.serrao@oss.qualcomm.com>
Acked-by: Thinh Nguyen <Thinh.Nguyen@synopsys.com>
Link: https://patch.msgid.link/20260813151456.867008-1-elson.serrao@oss.qualcomm.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/usb/dwc3/ep0.c    |    2 +-
 drivers/usb/dwc3/gadget.c |   21 +++++++++++++--------
 2 files changed, 14 insertions(+), 9 deletions(-)

--- a/drivers/usb/dwc3/ep0.c
+++ b/drivers/usb/dwc3/ep0.c
@@ -304,7 +304,7 @@ void dwc3_ep0_out_start(struct dwc3 *dwc
 
 		dwc3_ep->flags &= ~DWC3_EP_DELAY_STOP;
 		if (dwc->connected)
-			dwc3_stop_active_transfer(dwc3_ep, true, true);
+			dwc3_stop_active_transfer(dwc3_ep, false, true);
 		else
 			dwc3_remove_requests(dwc, dwc3_ep, -ESHUTDOWN);
 	}
--- a/drivers/usb/dwc3/gadget.c
+++ b/drivers/usb/dwc3/gadget.c
@@ -1004,7 +1004,7 @@ static int __dwc3_gadget_ep_enable(struc
 			 * controller to generate an ERDY to initiate the
 			 * stream.
 			 */
-			dwc3_stop_active_transfer(dep, true, true);
+			dwc3_stop_active_transfer(dep, false, true);
 
 			/*
 			 * All stream eps will reinitiate stream on NoStream
@@ -1032,7 +1032,7 @@ void dwc3_remove_requests(struct dwc3 *d
 {
 	struct dwc3_request		*req;
 
-	dwc3_stop_active_transfer(dep, true, false);
+	dwc3_stop_active_transfer(dep, false, false);
 
 	/* If endxfer is delayed, avoid unmapping requests */
 	if (dep->flags & DWC3_EP_DELAY_STOP)
@@ -1720,7 +1720,7 @@ static int __dwc3_gadget_kick_transfer(s
 		if (ret == -EAGAIN)
 			return ret;
 
-		dwc3_stop_active_transfer(dep, true, true);
+		dwc3_stop_active_transfer(dep, false, true);
 
 		list_for_each_entry_safe(req, tmp, &dep->started_list, list)
 			dwc3_gadget_move_cancelled_request(req, DWC3_REQUEST_STATUS_DEQUEUED);
@@ -1757,6 +1757,11 @@ static int __dwc3_gadget_get_frame(struc
  * the controller won't update the TRB progress on command
  * completion. It also won't clear the HWO bit in the TRB.
  * The command will also not complete immediately in that case.
+ *
+ * Older programming guide revisions recommended setting ForceRM to 1
+ * when ending a transfer. Newer programming guide revisions now
+ * recommend keeping ForceRM cleared, and TRBs are properly updated
+ * on command completion.
  */
 static int __dwc3_stop_active_transfer(struct dwc3_ep *dep, bool force, bool interrupt)
 {
@@ -1882,7 +1887,7 @@ static int dwc3_gadget_start_isoc_quirk(
 		 * to wait for the next XferNotReady to test the command again
 		 */
 		if (cmd_status == 0) {
-			dwc3_stop_active_transfer(dep, true, true);
+			dwc3_stop_active_transfer(dep, false, true);
 			return 0;
 		}
 	}
@@ -2165,7 +2170,7 @@ static int dwc3_gadget_ep_dequeue(struct
 			struct dwc3_request *t;
 
 			/* wait until it is processed */
-			dwc3_stop_active_transfer(dep, true, true);
+			dwc3_stop_active_transfer(dep, false, true);
 
 			/*
 			 * Remove any started request if the transfer is
@@ -2242,7 +2247,7 @@ int __dwc3_gadget_ep_set_halt(struct dwc
 			return 0;
 		}
 
-		dwc3_stop_active_transfer(dep, true, true);
+		dwc3_stop_active_transfer(dep, false, true);
 
 		list_for_each_entry_safe(req, tmp, &dep->started_list, list)
 			dwc3_gadget_move_cancelled_request(req, DWC3_REQUEST_STATUS_STALLED);
@@ -3357,7 +3362,7 @@ static void dwc3_nostream_work(struct wo
 		dwc3_send_gadget_generic_command(dwc, cmd, dep->number);
 	} else {
 		dep->flags |= DWC3_EP_DELAY_START;
-		dwc3_stop_active_transfer(dep, true, true);
+		dwc3_stop_active_transfer(dep, false, true);
 		spin_unlock_irqrestore(&dwc->lock, flags);
 		return;
 	}
@@ -3715,7 +3720,7 @@ static bool dwc3_gadget_endpoint_trbs_co
 	if (usb_endpoint_xfer_isoc(dep->endpoint.desc) &&
 		list_empty(&dep->started_list) &&
 		(list_empty(&dep->pending_list) || status == -EXDEV))
-		dwc3_stop_active_transfer(dep, true, true);
+		dwc3_stop_active_transfer(dep, false, true);
 	else if (dwc3_gadget_ep_should_continue(dep))
 		if (__dwc3_gadget_kick_transfer(dep) == 0)
 			no_started_trb = false;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 034/556] usb: storage: realtek_cr: fix use-after-free on disconnect
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (32 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 033/556] usb: dwc3: clear forceRM when issuing EndTransfer Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 035/556] usb: typec: hd3ss3220: track VBUS enable state per consumer Greg Kroah-Hartman
                   ` (534 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Ijae Kim, Myeonghun Pak

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Myeonghun Pak <mhun512@gmail.com>

commit 4ffee1aebb0c0ffcda9faffd17834ea9b00d42cc upstream.

realtek_cr_destructor() calls timer_delete() before the chip containing
the timer is freed. The timer callback may still be running and can
rearm itself, resulting in a use-after-free.

Use timer_shutdown_sync() to wait for the callback and prevent further
rearming. Do this unconditionally because ss_en may be changed after
the timer is armed.

Move timer_setup() into init_realtek_cr() so the timer is initialized
before any failure path can invoke the destructor.

Found by static analysis.

Fixes: e931830bb877 ("Realtek cr: Add autosuspend function.")
Cc: stable <stable@kernel.org>
Co-developed-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
Link: https://patch.msgid.link/20260727123414.44700-1-mhun512@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/usb/storage/realtek_cr.c |    9 ++++-----
 1 file changed, 4 insertions(+), 5 deletions(-)

--- a/drivers/usb/storage/realtek_cr.c
+++ b/drivers/usb/storage/realtek_cr.c
@@ -916,7 +916,6 @@ static int realtek_cr_autosuspend_setup(
 	us->proto_handler = rts51x_invoke_transport;
 
 	chip->timer_expires = 0;
-	timer_setup(&chip->rts51x_suspend_timer, rts51x_suspend_timer_fn, 0);
 	fw5895_init(us);
 
 	/* enable autosuspend function of the usb device */
@@ -934,10 +933,7 @@ static void realtek_cr_destructor(void *
 		return;
 
 #ifdef CONFIG_REALTEK_AUTOPM
-	if (ss_en) {
-		timer_delete(&chip->rts51x_suspend_timer);
-		chip->timer_expires = 0;
-	}
+	timer_shutdown_sync(&chip->rts51x_suspend_timer);
 #endif
 	kfree(chip->status);
 }
@@ -982,6 +978,9 @@ static int init_realtek_cr(struct us_dat
 
 	us->extra = chip;
 	us->extra_destructor = realtek_cr_destructor;
+#ifdef CONFIG_REALTEK_AUTOPM
+	timer_setup(&chip->rts51x_suspend_timer, rts51x_suspend_timer_fn, 0);
+#endif
 	us->max_lun = chip->max_lun = rts51x_get_max_lun(us);
 	chip->us = us;
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 035/556] usb: typec: hd3ss3220: track VBUS enable state per consumer
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (33 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 034/556] usb: storage: realtek_cr: fix use-after-free on disconnect Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 036/556] usb: typec: mux: avoid duplicated mux switches Greg Kroah-Hartman
                   ` (533 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, stable, Chang Wu, Heikki Krogerus,
	Jan Remmet, Krishna Kurapati

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chang Wu <kunjinkao.jp@gmail.com>

commit c9a48db776d7184981630ecc01a3ad30a8f7dc24 upstream.

regulator_is_enabled() reports the aggregate regulator state, not
whether this consumer holds an enable reference. If another consumer
enables VBUS first, the driver can skip its own regulator_enable() call
and later attempt to drop a reference it never acquired, triggering an
unbalanced regulator disable warning.

Track successful enable and disable calls locally. Keep the state
unchanged when an operation fails so a later role or ID notification
retries the operation while this consumer keeps balanced references.

Fixes: b3f9d6e491fd ("usb: typec: hd3ss3220: Check if regulator needs to be switched")
Cc: stable <stable@kernel.org>
Link: https://github.com/qualcomm-linux/kernel/issues/472
Signed-off-by: Chang Wu <kunjinkao.jp@gmail.com>
Reviewed-by: Heikki Krogerus <heikki.krogerus@linux.intel.com>
Tested-by: Jan Remmet <j.remmet@phytec.de>
Reviewed-by: Krishna Kurapati <krishna.kurapati@oss.qualcomm.com>
Link: https://patch.msgid.link/20260819152027.90994-1-kunjinkao.jp@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/usb/typec/hd3ss3220.c | 9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

diff --git a/drivers/usb/typec/hd3ss3220.c b/drivers/usb/typec/hd3ss3220.c
index d0de5a2488f9..4eec90c82bae 100644
--- a/drivers/usb/typec/hd3ss3220.c
+++ b/drivers/usb/typec/hd3ss3220.c
@@ -62,6 +62,7 @@ struct hd3ss3220 {
 	int id_irq;
 
 	struct regulator *vbus;
+	bool vbus_enabled;
 };
 
 static int hd3ss3220_set_power_opmode(struct hd3ss3220 *hd3ss3220, int power_opmode)
@@ -208,7 +209,7 @@ static void hd3ss3220_regulator_control(struct hd3ss3220 *hd3ss3220, bool on)
 {
 	int ret;
 
-	if (regulator_is_enabled(hd3ss3220->vbus) == on)
+	if (hd3ss3220->vbus_enabled == on)
 		return;
 
 	if (on)
@@ -216,9 +217,13 @@ static void hd3ss3220_regulator_control(struct hd3ss3220 *hd3ss3220, bool on)
 	else
 		ret = regulator_disable(hd3ss3220->vbus);
 
-	if (ret)
+	if (ret) {
 		dev_err(hd3ss3220->dev,
 			"vbus regulator %s failed: %d\n", on ? "enable" : "disable", ret);
+		return;
+	}
+
+	hd3ss3220->vbus_enabled = on;
 }
 
 static void hd3ss3220_set_role(struct hd3ss3220 *hd3ss3220)
-- 
2.55.0




^ permalink raw reply related	[flat|nested] 570+ messages in thread

* [PATCH 7.2 036/556] usb: typec: mux: avoid duplicated mux switches
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (34 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 035/556] usb: typec: hd3ss3220: track VBUS enable state per consumer Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 037/556] usb: typec: mux: Fix typec_switch_match() Greg Kroah-Hartman
                   ` (532 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, stable, Sebastian Reichel,
	Marek Vasut, Jens Glathe, Heikki Krogerus

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Marek Vasut <marex@nabladev.com>

commit d50b6442bef66abbe4694f918f8ad013f81d75cf upstream.

Some devices use combo PHYs (i.e. USB3 + DisplayPort), which also
handle the lane muxing. These PHYs are referenced twice from
the USB-C connector (USB super-speed lines and SBU/AUX lines)
resulting in the mux being configured twice. Avoid this by
dropping duplicates.

This is a re-application of b145c3f29d62 ("usb: typec: mux: avoid
duplicated mux switches"), with fix derived from usb: typec: mux:
Fix typec_switch_match() .

Fixes: f576c75f95a5 ("Revert "usb: typec: mux: avoid duplicated mux switches"")
Cc: stable <stable@kernel.org>
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
Co-developed-by: Sebastian Reichel <sebastian.reichel@collabora.com>
Signed-off-by: Marek Vasut <marex@nabladev.com>
Tested-by: Jens Glathe <jens.glathe@oldschoolsolutions.biz>
Reviewed-by: Heikki Krogerus <heikki.krogerus@linux.intel.com>
Link: https://patch.msgid.link/20260822072556.490594-1-marex@nabladev.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/usb/typec/mux.c |   17 +++++++++++++++--
 1 file changed, 15 insertions(+), 2 deletions(-)

--- a/drivers/usb/typec/mux.c
+++ b/drivers/usb/typec/mux.c
@@ -275,7 +275,9 @@ static int mux_fwnode_match(struct devic
 static void *typec_mux_match(const struct fwnode_handle *fwnode,
 			     const char *id, void *data)
 {
+	struct typec_mux_dev **mux_devs = data;
 	struct device *dev;
+	int i;
 
 	/*
 	 * Device graph (OF graph) does not give any means to identify the
@@ -290,8 +292,18 @@ static void *typec_mux_match(const struc
 
 	dev = class_find_device(&typec_mux_class, NULL, fwnode,
 				mux_fwnode_match);
+	if (!dev)
+		return ERR_PTR(-EPROBE_DEFER);
+
+	/* Skip duplicates */
+	for (i = 0; i < TYPEC_MUX_MAX_DEVS; i++)
+		if (to_typec_mux_dev(dev) == mux_devs[i]) {
+			put_device(dev);
+			return NULL;
+		}
 
-	return dev ? to_typec_mux_dev(dev) : ERR_PTR(-EPROBE_DEFER);
+
+	return to_typec_mux_dev(dev);
 }
 
 /**
@@ -316,7 +328,8 @@ struct typec_mux *fwnode_typec_mux_get(s
 		return ERR_PTR(-ENOMEM);
 
 	count = fwnode_connection_find_matches(fwnode, "mode-switch",
-					       NULL, typec_mux_match,
+					       (void **)mux_devs,
+					       typec_mux_match,
 					       (void **)mux_devs,
 					       ARRAY_SIZE(mux_devs));
 	if (count <= 0) {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 037/556] usb: typec: mux: Fix typec_switch_match()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (35 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 036/556] usb: typec: mux: avoid duplicated mux switches Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 038/556] usb: typec: qcom-pmic-typec: disable cc_debounce_dwork on stop Greg Kroah-Hartman
                   ` (531 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, stable, Marek Vasut,
	Sebastian Reichel, Jens Glathe, Heikki Krogerus

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Marek Vasut <marex@nabladev.com>

commit dea99705bc8fcda12590cfeeae6d2ba47a7ef572 upstream.

The fwnode_typec_switch_get() sporadically returns NULL instead of an
-EPROBE_DEFER for orientation-switch described in DT. This makes it
impossible to discern whether the DT does describe an orientation-switch
which did not probe yet, or whether the DT does not describe the switch.
This happens with gpio-sbu-mux connected to an I2C GPIO expander.

The class_find_device() on typec_switch_match() may return NULL in case
the mux did not probe just yet early on boot. The sw_devs[] array can be
empty on boot as well. If these two conditions occur, then the conditional
if (to_typec_switch_dev(dev) == sw_devs[i]) evaluates to true and the match
function returns NULL, which propagates to fwnode_typec_switch_get() which
makes it look as if the orientation-switch was not described in DT.

This is incorrect, because the mux driver will probe a bit later on, but
at that point, the caller of fwnode_typec_switch_get() already got the
NULL return value. The NULL return value also does not trigger IS_ERR(),
therefore the caller driver interprets this as if the orientation-switch
is not described in DT, and does not return -EPROBE_DEFER to try again,
even if it should.

Fix this by checking the class_find_device() return value, and return
-EPROBE_DEFER if it is NULL right away. If the return value is not NULL,
perform the deduplication test, and if that test passes, consider the
return value to be already non-NULL.

Fixes: a53b4f9c51a9 ("usb: typec: mux: avoid duplicated orientation switches")
Cc: stable <stable@kernel.org>
Signed-off-by: Marek Vasut <marex@nabladev.com>
Reviewed-by: Sebastian Reichel <sebastian.reichel@collabora.com>
Tested-by: Jens Glathe <jens.glathe@oldschoolsolutions.biz>
Reviewed-by: Heikki Krogerus <heikki.krogerus@linux.intel.com>
Link: https://patch.msgid.link/20260817182302.146546-1-marex@nabladev.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/usb/typec/mux.c |    4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

--- a/drivers/usb/typec/mux.c
+++ b/drivers/usb/typec/mux.c
@@ -57,6 +57,8 @@ static void *typec_switch_match(const st
 	 */
 	dev = class_find_device(&typec_mux_class, NULL, fwnode,
 				switch_fwnode_match);
+	if (!dev)
+		return ERR_PTR(-EPROBE_DEFER);
 
 	/* Skip duplicates */
 	for (i = 0; i < TYPEC_MUX_MAX_DEVS; i++)
@@ -65,7 +67,7 @@ static void *typec_switch_match(const st
 			return NULL;
 		}
 
-	return dev ? to_typec_switch_dev(dev) : ERR_PTR(-EPROBE_DEFER);
+	return to_typec_switch_dev(dev);
 }
 
 /**



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 038/556] usb: typec: qcom-pmic-typec: disable cc_debounce_dwork on stop
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (36 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 037/556] usb: typec: mux: Fix typec_switch_match() Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 039/556] usb: typec: qcom-pmic-typec: drain cc_debounce_dwork if port_start() fails Greg Kroah-Hartman
                   ` (530 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Fan Wu, Heikki Krogerus, stable

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Fan Wu <fanwu01@zju.edu.cn>

commit 263f7d61a4201cde16849b2d016251806e7418be upstream.

cc_debounce_dwork is queued from the set_cc() and start_toggling()
callbacks, which run from TCPM's kthread worker.  port_stop() returns
before tcpm_unregister_port() destroys that worker.  Flushing the worker
during unregister may therefore run a callback which queues the delayed
work after port_stop() has returned.

The delayed work can then run after devres has freed pmic_typec_port.

Use disable_delayed_work_sync() in port_stop() to cancel a pending
instance and prevent the TCPM callbacks from queueing another one.

This issue was found by an in-house static analysis tool.

Fixes: a4422ff22142 ("usb: typec: qcom: Add Qualcomm PMIC Type-C driver")
Cc: stable <stable@kernel.org>  # v6.10+
Assisted-by: Codex:gpt-5.6
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Acked-by: Heikki Krogerus <heikki.krogerus@linux.intel.com>
Link: https://patch.msgid.link/20260820135307.153773-2-fanwu01@zju.edu.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/usb/typec/tcpm/qcom/qcom_pmic_typec_port.c |    2 ++
 1 file changed, 2 insertions(+)

--- a/drivers/usb/typec/tcpm/qcom/qcom_pmic_typec_port.c
+++ b/drivers/usb/typec/tcpm/qcom/qcom_pmic_typec_port.c
@@ -693,6 +693,8 @@ static void qcom_pmic_typec_port_stop(st
 
 	for (i = 0; i < pmic_typec_port->nr_irqs; i++)
 		disable_irq(pmic_typec_port->irq_data[i].irq);
+
+	disable_delayed_work_sync(&pmic_typec_port->cc_debounce_dwork);
 }
 
 int qcom_pmic_typec_port_probe(struct platform_device *pdev,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 039/556] usb: typec: qcom-pmic-typec: drain cc_debounce_dwork if port_start() fails
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (37 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 038/556] usb: typec: qcom-pmic-typec: disable cc_debounce_dwork on stop Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 040/556] usb: typec: qcom-pmic: cancel reset_work on stop Greg Kroah-Hartman
                   ` (529 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Bryan ODonoghue, Fan Wu,
	Heikki Krogerus, stable

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Fan Wu <fanwu01@zju.edu.cn>

commit c9273c83885835dbd1e8835d5665dfb8503d65e0 upstream.

cc_debounce_dwork can be queued before port_start() fails:
tcpm_register_port() runs first, and its state machine may invoke
set_cc() or start_toggling() from the TCPM worker.  The error path then
calls tcpm_unregister_port(), whose worker flush may queue the delayed
work before devres frees pmic_typec_port.

Disable and drain the delayed work directly at port_start()'s error
exit.  Do not use port_stop() for this path: its IRQs use IRQF_NO_AUTOEN
and are enabled only after a successful port_start().

This issue was found by an in-house static analysis tool.

Fixes: a4422ff22142 ("usb: typec: qcom: Add Qualcomm PMIC Type-C driver")
Cc: stable <stable@kernel.org>  # v6.10+
Suggested-by: Bryan O'Donoghue <bryan.odonoghue@linaro.org>
Assisted-by: Codex:gpt-5.6
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Acked-by: Heikki Krogerus <heikki.krogerus@linux.intel.com>
Link: https://patch.msgid.link/20260820135307.153773-3-fanwu01@zju.edu.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/usb/typec/tcpm/qcom/qcom_pmic_typec_port.c |    3 +++
 1 file changed, 3 insertions(+)

--- a/drivers/usb/typec/tcpm/qcom/qcom_pmic_typec_port.c
+++ b/drivers/usb/typec/tcpm/qcom/qcom_pmic_typec_port.c
@@ -683,6 +683,9 @@ static int qcom_pmic_typec_port_start(st
 		enable_irq(pmic_typec_port->irq_data[i].irq);
 
 done:
+	if (ret)
+		disable_delayed_work_sync(&pmic_typec_port->cc_debounce_dwork);
+
 	return ret;
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 040/556] usb: typec: qcom-pmic: cancel reset_work on stop
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (38 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 039/556] usb: typec: qcom-pmic-typec: drain cc_debounce_dwork if port_start() fails Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 041/556] usb: typec: tcpm: constrain TCPM_SOURCING_VBUS event handling Greg Kroah-Hartman
                   ` (528 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, stable, Fan Wu, Konrad Dybcio,
	Bryan ODonoghue, Heikki Krogerus

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Fan Wu <fanwu01@zju.edu.cn>

commit 7b0df6efd143f8085bdb68778a013a46f1349913 upstream.

pdphy_stop() disables IRQs but leaves reset_work pending.  If the IRQ
handler schedules it just before disable_irq(), the work runs after
remove() frees the struct via devm.

Call cancel_work_sync() after disabling IRQs to close the window.

This issue was found by an in-house static analysis tool.

Fixes: a4422ff22142 ("usb: typec: qcom: Add Qualcomm PMIC Type-C driver")
Cc: stable <stable@kernel.org>
Assisted-by: Codex:gpt-5.6
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Bryan O'Donoghue <bryan.odonoghue@linaro.org>
Reviewed-by: Heikki Krogerus <heikki.krogerus@linux.intel.com>
Link: https://patch.msgid.link/20260819161448.76597-1-fanwu01@zju.edu.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/usb/typec/tcpm/qcom/qcom_pmic_typec_pdphy.c |    2 ++
 1 file changed, 2 insertions(+)

--- a/drivers/usb/typec/tcpm/qcom/qcom_pmic_typec_pdphy.c
+++ b/drivers/usb/typec/tcpm/qcom/qcom_pmic_typec_pdphy.c
@@ -543,6 +543,8 @@ static void qcom_pmic_typec_pdphy_stop(s
 	for (i = 0; i < pmic_typec_pdphy->nr_irqs; i++)
 		disable_irq(pmic_typec_pdphy->irq_data[i].irq);
 
+	cancel_work_sync(&pmic_typec_pdphy->reset_work);
+
 	qcom_pmic_typec_pdphy_reset_on(pmic_typec_pdphy);
 
 	regulator_disable(pmic_typec_pdphy->vdd_pdphy);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 041/556] usb: typec: tcpm: constrain TCPM_SOURCING_VBUS event handling
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (39 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 040/556] usb: typec: qcom-pmic: cancel reset_work on stop Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 042/556] usb: typec: tipd: Fix Thunderbolt altmode VDOs for cd321x Greg Kroah-Hartman
                   ` (527 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, stable, Amit Sunil Dhamne,
	Badhri Jagan Sridharan, Heikki Krogerus

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Amit Sunil Dhamne <amitsd@google.com>

commit cd3b9cea675bbfebc223f007dc2f4e79524fa54c upstream.

When a sink detach occurs while waiting for TX send status, the old
TCPM_SOURCING_VBUS event along with TCPM_VBUS_EVENT and TCPM_CC_EVENT
can be queued in port->pd_events. Because TCPM_SOURCING_VBUS is
evaluated after TCPM_VBUS_EVENT and TCPM_CC_EVENT in
tcpm_pd_event_handler(), a stale TCPM_SOURCING_VBUS event can override
the detach handling and incorrectly set port->vbus_source and
port->vbus_present to true.

Add a state guard to check that the port is either operating as a
Source (tcpm_port_is_source(port)) or in a Fast Role Swap (FRS) state
up to FR_SWAP_SNK_SRC_SOURCE_VBUS_APPLIED before processing
TCPM_SOURCING_VBUS. Otherwise, discard and log the event.

Log snippet for error condition before fix:
[72792.204955] state change SRC_ATTACHED -> SRC_STARTUP [rev3 NONE_AMS]
[72792.204960] sourcing vbus
[72792.204962] VBUS on
[72792.204970] AMS POWER_NEGOTIATION start
[72792.204974] cc:=4
[72792.205319] state change SRC_STARTUP -> AMS_START [rev3 POWER_NEGOTIATION]
[72792.205325] state change AMS_START -> SRC_SEND_CAPABILITIES [rev3 POWER_NEGOTIATION]
[72792.205332] PD TX, header: 0x11a1
[72792.216911] PD TX complete, status: 2
[72792.216957] pending state change SRC_SEND_CAPABILITIES -> SRC_SEND_CAPABILITIES @ 150 ms [rev3 POWER_NEGOTIATION]
[72792.218005] VBUS off
[72792.218013] pending state change SRC_SEND_CAPABILITIES -> SNK_UNATTACHED @ 650 ms [rev3 POWER_NEGOTIATION]
[72792.218020] VBUS VSAFE0V
[72792.218024] state change SRC_SEND_CAPABILITIES -> SNK_UNATTACHED [rev3 POWER_NEGOTIATION]
[72792.218458] CC1: 2 -> 0, CC2: 0 -> 0 [state SNK_UNATTACHED, polarity 0, disconnected]
[72792.218467] VBUS on --> VBUS left on
[72792.218980] disable vbus discharge ret:0
[72792.235193] Start toggling

After fix:
[ 1195.291691] state change SRC_ATTACHED -> SRC_STARTUP [rev3 NONE_AMS]
[ 1195.291698] sourcing vbus
[ 1195.291700] VBUS on
[ 1195.291707] AMS POWER_NEGOTIATION start
[ 1195.291710] cc:=4
[ 1195.291758] state change SRC_STARTUP -> AMS_START [rev3 POWER_NEGOTIATION]
[ 1195.291794] state change AMS_START -> SRC_SEND_CAPABILITIES [rev3 POWER_NEGOTIATION]
[ 1195.291798] PD TX, header: 0x11a1
[ 1195.297056] PD TX complete, status: 2
[ 1195.297092] pending state change SRC_SEND_CAPABILITIES -> SRC_SEND_CAPABILITIES @ 150 ms [rev3 POWER_NEGOTIATION]
[ 1195.297177] VBUS off
[ 1195.297184] pending state change SRC_SEND_CAPABILITIES -> SNK_UNATTACHED @ 650 ms [rev3 POWER_NEGOTIATION]
[ 1195.297227] CC1: 2 -> 0, CC2: 0 -> 0 [state SRC_SEND_CAPABILITIES, polarity 0, disconnected]
[ 1195.307469] cc:=2
[ 1195.307544] pending state change SRC_SEND_CAPABILITIES -> SNK_UNATTACHED @ 650 ms [rev3 POWER_NEGOTIATION]
[ 1195.307555] Discarding sourcing vbus! Invalid state SRC_SEND_CAPABILITIES
[ 1195.957636] state change SRC_SEND_CAPABILITIES -> SNK_UNATTACHED [delayed 650 ms]
[ 1195.957732] disable vbus discharge ret:0
[ 1195.970196] Start toggling
[ 1195.970468] VBUS off
[ 1196.051637] VBUS off
[ 1196.051642] VBUS VSAFE0V

Fixes: 8dc4bd073663 ("usb: typec: tcpm: Add support for Sink Fast Role SWAP(FRS)")
Cc: stable <stable@kernel.org>
Assisted-by: Gemini:gemini-3.1-pro
Signed-off-by: Amit Sunil Dhamne <amitsd@google.com>
Reviewed-by: Badhri Jagan Sridharan <badhri@google.com>
Acked-by: Heikki Krogerus <heikki.krogerus@linux.intel.com>
Link: https://patch.msgid.link/20260827-sourcing-vbus-v1-1-9be1aca991a0@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/usb/typec/tcpm/tcpm.c |   28 ++++++++++++++++++++++------
 1 file changed, 22 insertions(+), 6 deletions(-)

--- a/drivers/usb/typec/tcpm/tcpm.c
+++ b/drivers/usb/typec/tcpm/tcpm.c
@@ -6921,16 +6921,32 @@ static void tcpm_pd_event_handler(struct
 			}
 		}
 		if (events & TCPM_SOURCING_VBUS) {
-			tcpm_log(port, "sourcing vbus");
 			/*
 			 * In fast role swap case TCPC autonomously sources vbus. Set vbus_source
-			 * true as TCPM wouldn't have called tcpm_set_vbus.
+			 * true conditionally as TCPM wouldn't have called tcpm_set_vbus.
+			 * If TCPM calls tcpm_set_vbus to source vbus, vbus_source would already
+			 * be true.
 			 *
-			 * When vbus is sourced on the command on TCPM i.e. TCPM called
-			 * tcpm_set_vbus to source vbus, vbus_source would already be true.
+			 * When TCPM_FRS_EVENT and TCPM_SOURCING_VBUS arrive simultaneously,
+			 * handling TCPM_FRS_EVENT above transitions the state to AMS_START
+			 * with upcoming_state FR_SWAP_SEND.
 			 */
-			port->vbus_source = true;
-			_tcpm_pd_vbus_on(port);
+
+			if (tcpm_port_is_source(port) ||
+			    tcpm_port_is_debug_source(port) ||
+			    (port->state == AMS_START && port->upcoming_state == FR_SWAP_SEND) ||
+			    port->state == FR_SWAP_SEND ||
+			    port->state == FR_SWAP_SEND_TIMEOUT ||
+			    port->state == FR_SWAP_SNK_SRC_TRANSITION_TO_OFF ||
+			    port->state == FR_SWAP_SNK_SRC_NEW_SINK_READY ||
+			    port->state == FR_SWAP_SNK_SRC_SOURCE_VBUS_APPLIED) {
+				tcpm_log(port, "sourcing vbus");
+				port->vbus_source = true;
+				_tcpm_pd_vbus_on(port);
+			} else {
+				tcpm_log(port, "Discarding sourcing vbus! Invalid state %s",
+					 tcpm_states[port->state]);
+			}
 		}
 		if (events & TCPM_PORT_CLEAN) {
 			tcpm_log(port, "port clean");



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 042/556] usb: typec: tipd: Fix Thunderbolt altmode VDOs for cd321x
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (40 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 041/556] usb: typec: tcpm: constrain TCPM_SOURCING_VBUS event handling Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 043/556] usb: typec: ucsi: displayport: Fix OOB altmode array index Greg Kroah-Hartman
                   ` (526 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, stable, Sven Peter, Rafay,
	Heikki Krogerus

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sven Peter <sven@kernel.org>

commit e24e3370356bddb65d667985a332b5f8aeeb5f97 upstream.

The Intel VID status register is actually 9 bytes long and doesn't
contain the raw VDOs but only the upper 16bits for device mode and enter
mode. Shift those two fields into place and reconstruct the cable
discover mode VDO from the data status register instead since it's not
directly accessible. With this fixed now the correct VDOs are forwarded
to the PHY and the to-be-submitted Thunderbolt/USB4 native host interface
so that the right mode can be negotiated and the link actually comes up.

Link: https://www.ti.com/lit/ug/slvubh2b/slvubh2b.pdf
Fixes: 0b31c978935f ("usb: typec: tipd: Read USB4, Thunderbolt and DisplayPort status for cd321x")
Fixes: 82432bbfb9e8 ("usb: typec: tipd: Handle mode transitions for CD321x")
Cc: stable <stable@kernel.org>
Signed-off-by: Sven Peter <sven@kernel.org>
Tested-by: Rafay <ahmedrafay888@gmail.com>
Acked-by: Heikki Krogerus <heikki.krogerus@linux.intel.com>
Link: https://patch.msgid.link/20260813-b4-tipd-vdo-fix-v1-1-70317f2cd554@kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/usb/typec/tipd/core.c     |   17 +++++++++++++----
 drivers/usb/typec/tipd/tps6598x.h |    4 ++--
 2 files changed, 15 insertions(+), 6 deletions(-)

--- a/drivers/usb/typec/tipd/core.c
+++ b/drivers/usb/typec/tipd/core.c
@@ -114,7 +114,6 @@ struct tps6598x_intel_vid_status_reg {
 	__le32 attention_vdo;
 	__le16 enter_vdo;
 	__le16 device_mode;
-	__le16 cable_mode;
 } __packed;
 
 /* Standard Task return codes */
@@ -700,9 +699,19 @@ static void cd321x_typec_update_mode(str
 		   cd321x->state.mode == TYPEC_TBT_MODE)
 			return;
 
-		tbt_data.cable_mode = le16_to_cpu(st->intel_vid_status.cable_mode);
-		tbt_data.device_mode = le16_to_cpu(st->intel_vid_status.device_mode);
-		tbt_data.enter_vdo = le16_to_cpu(st->intel_vid_status.enter_vdo);
+		tbt_data.cable_mode = TBT_MODE |
+			TBT_SET_CABLE_SPEED(TPS_DATA_STATUS_TBT_CABLE_SPEED(st->data_status)) |
+			TBT_SET_CABLE_ROUNDED(TPS_DATA_STATUS_TBT_CABLE_GEN(st->data_status));
+		if (st->data_status & TPS_DATA_STATUS_OPTICAL_CABLE)
+			tbt_data.cable_mode |= TBT_CABLE_OPTICAL;
+		if (st->data_status & TPS_DATA_STATUS_ACTIVE_LINK_TRAIN)
+			tbt_data.cable_mode |= TBT_CABLE_LINK_TRAINING;
+		if (st->data_status & TPS_DATA_STATUS_ACTIVE_CABLE)
+			tbt_data.cable_mode |= TBT_CABLE_ACTIVE_PASSIVE;
+		tbt_data.device_mode = TBT_MODE |
+			(u32)le16_to_cpu(st->intel_vid_status.device_mode) << 16;
+		tbt_data.enter_vdo =
+			(u32)le16_to_cpu(st->intel_vid_status.enter_vdo) << 16;
 		cd321x->state.alt = cd321x->port_altmode_tbt;
 		cd321x->state.mode = TYPEC_TBT_MODE;
 		cd321x->state.data = &tbt_data;
--- a/drivers/usb/typec/tipd/tps6598x.h
+++ b/drivers/usb/typec/tipd/tps6598x.h
@@ -206,10 +206,10 @@
 #define TPS_DATA_STATUS_DP_PIN_ASSIGNMENT(x) \
 	TPS_FIELD_GET(TPS_DATA_STATUS_DP_PIN_ASSIGNMENT_MASK, (x))
 #define TPS_DATA_STATUS_TBT_CABLE_SPEED_MASK   GENMASK(27, 25)
-#define TPS_DATA_STATUS_TBT_CABLE_SPEED \
+#define TPS_DATA_STATUS_TBT_CABLE_SPEED(x) \
 	TPS_FIELD_GET(TPS_DATA_STATUS_TBT_CABLE_SPEED_MASK, (x))
 #define TPS_DATA_STATUS_TBT_CABLE_GEN_MASK     GENMASK(29, 28)
-#define TPS_DATA_STATUS_TBT_CABLE_GEN \
+#define TPS_DATA_STATUS_TBT_CABLE_GEN(x) \
 	TPS_FIELD_GET(TPS_DATA_STATUS_TBT_CABLE_GEN_MASK, (x))
 
 /* Map data status to DP spec assignments */



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 043/556] usb: typec: ucsi: displayport: Fix OOB altmode array index
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (41 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 042/556] usb: typec: tipd: Fix Thunderbolt altmode VDOs for cd321x Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 044/556] usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs Greg Kroah-Hartman
                   ` (525 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jameson Thies, Benson Leung

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jameson Thies <jthies@google.com>

commit 04cec690b1fd9d1c4c314b91a10d8c68a3acfe18 upstream.

The UCSI displayport driver indexes the connector's port altmode array
with the GET_CURRENT_CAM response after checking it is not 0xff. The
port altmode array is UCSI_MAX_ALTMODES elements long. If the PPM
returns an invalid GET_CURRENT_CAM response above UCSI_MAX_ALTMODES and
not equal to 0xff, the kernel may crash with an array index OOB error.

Update the UCSI displayport driver to verify the current cam is less
than UCSI_MAX_ALTMODES before accessing the port altmode array.

Fixes: af8622f6a585 ("usb: typec: ucsi: Support for DisplayPort alt mode")
Cc: stable@vger.kernel.org
Signed-off-by: Jameson Thies <jthies@google.com>
Reviewed-by: Benson Leung <bleung@chromium.org>
Link: https://patch.msgid.link/20260825234545.2076049-1-jthies@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/usb/typec/ucsi/displayport.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/usb/typec/ucsi/displayport.c
+++ b/drivers/usb/typec/ucsi/displayport.c
@@ -74,7 +74,7 @@ static int ucsi_displayport_enter(struct
 		cur = 0xff;
 	}
 
-	if (cur != 0xff) {
+	if (cur < UCSI_MAX_ALTMODES) {
 		ret = dp->con->port_altmode[cur] == alt ? 0 : -EBUSY;
 		goto err_unlock;
 	}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 044/556] usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (42 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 043/556] usb: typec: ucsi: displayport: Fix OOB altmode array index Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 045/556] usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers() Greg Kroah-Hartman
                   ` (524 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, stable, syzbot+bbb6dad313f4aaa8da6b,
	Aleksandr Nogikh, Takashi Iwai

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Aleksandr Nogikh <nogikh@google.com>

commit f0efaf1872949e96d213c8e910fd9517f7d7c406 upstream.

A null-pointer dereference occurs in f_midi2_free_ep_reqs() when attempting
to clean up an endpoint that was never initialized.

When configuring the MIDI 2.0 gadget via configfs and setting the block
direction to SNDRV_UMP_DIR_INPUT, the initialization of the midi1_ep_out
endpoint is explicitly skipped during the gadget bind phase
(f_midi2_bind()). As a result, the usb_ep->card field remains NULL.

Later, when the host sets the alternate setting, f_midi2_set_alt()
unconditionally stops both the IN and OUT endpoints by calling
f_midi2_stop_eps(), which in turn calls f_midi2_free_ep_reqs() for both
endpoints. When f_midi2_free_ep_reqs() is called for the uninitialized
midi1_ep_out, it attempts to dereference usb_ep->card to determine the
number of requests to free, leading to a crash.

Fix this by using usb_ep->num_reqs instead of usb_ep->card->info.num_reqs
in f_midi2_free_ep_reqs(). usb_ep->num_reqs is correctly set during
f_midi2_init_ep() and remains 0 if the endpoint was never initialized,
safely avoiding the loop. For consistency, apply the same change to
f_midi2_alloc_ep_reqs().

Oops: general protection fault, probably for non-canonical address
0xdffffc00000000ee: 0000 [#1] SMP KASAN NOPTI
KASAN: null-ptr-deref in range [0x0000000000000770-0x0000000000000777]
...
RIP: 0010:f_midi2_free_ep_reqs drivers/usb/gadget/function/f_midi2.c:1166
[inline]
RIP: 0010:f_midi2_stop_eps+0x28e/0x4d0
drivers/usb/gadget/function/f_midi2.c:1246
...
Call Trace:
 <TASK>
 f_midi2_set_alt+0x11c/0xf00 drivers/usb/gadget/function/f_midi2.c:1296
 composite_setup+0x1ffd/0x3480 drivers/usb/gadget/composite.c:1933
 configfs_composite_setup+0xbd/0x100 drivers/usb/gadget/configfs.c:1877

Fixes: 8b645922b223 ("usb: gadget: Add support for USB MIDI 2.0 function driver")
Cc: stable <stable@kernel.org>
Assisted-by: Gemini:gemini-3.5-flash Gemini:gemini-3.1-pro-preview syzbot
Reported-by: syzbot+bbb6dad313f4aaa8da6b@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=bbb6dad313f4aaa8da6b
Link: https://syzkaller.appspot.com/ai_job?id=8ce30b1a-8cf7-4e38-bcf7-1f69e6f6313f
Signed-off-by: Aleksandr Nogikh <nogikh@google.com>
Reviewed-by: Takashi Iwai <tiwai@suse.de>
Closes: https://syzkaller.appspot.com/bug?extid=01a17afb30637396955e
Link: https://patch.msgid.link/cafe65f4-e1bb-46a3-901d-732814b861b2@mail.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/usb/gadget/function/f_midi2.c |    5 ++---
 1 file changed, 2 insertions(+), 3 deletions(-)

--- a/drivers/usb/gadget/function/f_midi2.c
+++ b/drivers/usb/gadget/function/f_midi2.c
@@ -1145,7 +1145,7 @@ static int f_midi2_alloc_ep_reqs(struct
 	if (!usb_ep->reqs)
 		return -EINVAL;
 
-	for (i = 0; i < midi2->info.num_reqs; i++) {
+	for (i = 0; i < usb_ep->num_reqs; i++) {
 		if (usb_ep->reqs[i].req)
 			continue;
 		usb_ep->reqs[i].req = alloc_ep_req(usb_ep->usb_ep,
@@ -1160,10 +1160,9 @@ static int f_midi2_alloc_ep_reqs(struct
 /* Free allocated requests */
 static void f_midi2_free_ep_reqs(struct f_midi2_usb_ep *usb_ep)
 {
-	struct f_midi2 *midi2 = usb_ep->card;
 	int i;
 
-	for (i = 0; i < midi2->info.num_reqs; i++) {
+	for (i = 0; i < usb_ep->num_reqs; i++) {
 		if (!usb_ep->reqs[i].req)
 			continue;
 		free_ep_req(usb_ep->usb_ep, usb_ep->reqs[i].req);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 045/556] usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (43 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 044/556] usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 046/556] usb: gadget: f_midi2: fix use-after-free in string attribute show path Greg Kroah-Hartman
                   ` (523 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+791be35f1fbcc85d06d7, stable,
	Jeffin Philip, Alan Stern

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jeffin Philip <jeffinphilip14@gmail.com>

commit 2c0f5ca48674a5b5f9fa4a9c3325aa48053af0bc upstream.

Previously fsg_num_buffers_validate() was removed as it was not
necessary due to Kconfig setting the limits for n from 2 to 256 with
default as 2. However, setting the page content in such a way that
kstrtou8() reflects n value as either 0 or 1 bypasses these
restrictions leading to a null pointer dereference if n is 0. Fix
this by adding a check for n < 2 and returning -EINVAL if n is
either 0 or 1 consistent with Kconfig logic.

Reported-by: syzbot+791be35f1fbcc85d06d7@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=791be35f1fbcc85d06d7
Fixes: fe5a6c48fd95 ("usb: gadget: storage: get rid of fsg_num_buffers_validate()")
Cc: stable <stable@kernel.org>
Signed-off-by: Jeffin Philip <jeffinphilip14@gmail.com>
Acked-by: Alan Stern <stern@rowland.harvard.edu>
Link: https://patch.msgid.link/20260818035904.10324-1-jeffinphilip14@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/usb/gadget/function/f_mass_storage.c |    3 +++
 1 file changed, 3 insertions(+)

--- a/drivers/usb/gadget/function/f_mass_storage.c
+++ b/drivers/usb/gadget/function/f_mass_storage.c
@@ -2748,6 +2748,9 @@ int fsg_common_set_num_buffers(struct fs
 	struct fsg_buffhd *bh, *buffhds;
 	int i;
 
+	if (n < 2)
+		return -EINVAL;
+
 	buffhds = kzalloc_objs(*buffhds, n);
 	if (!buffhds)
 		return -ENOMEM;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 046/556] usb: gadget: f_midi2: fix use-after-free in string attribute show path
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (44 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 045/556] usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers() Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 047/556] usb: gadget: f_midi: initialize work in f_midi_alloc() Greg Kroah-Hartman
                   ` (522 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+2280f1cca5e6b0c353e4, stable,
	Ivy Lopez, Takashi Iwai

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ivy Lopez <skunkolee@gmail.com>

commit fed0aa7c6eaedc6c0d4e362fc91724aa47be4a7b upstream.

f_midi2_opts_str_show() takes the string lock internally, but its
callers dereference the opts->info.<field> pointer before calling it,
outside the lock. This races with f_midi2_opts_str_store(), which
frees the old string under opts->lock when the attribute is written
concurrently, the show path can read a pointer that gets freed
before the lock inside str_show() is even taken.

Change f_midi2_opts_str_show() to take a pointer to the string field,
matching the existing pattern in f_midi2_opts_str_store(), and
dereference it only after the lock is held. Update all three callers
(iface_name, block name, and the EP string option macro) accordingly.

Reported-by: syzbot+2280f1cca5e6b0c353e4@syzkaller.appspotmail.com
Cc: stable <stable@kernel.org>
Closes: https://syzkaller.appspot.com/bug?extid=2280f1cca5e6b0c353e4
Signed-off-by: Ivy Lopez <skunkolee@gmail.com>
Reviewed-by: Takashi Iwai <tiwai@suse.de>
Link: https://patch.msgid.link/20260816005434.34018-1-skunkolee@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/usb/gadget/function/f_midi2.c |   12 ++++++------
 1 file changed, 6 insertions(+), 6 deletions(-)

--- a/drivers/usb/gadget/function/f_midi2.c
+++ b/drivers/usb/gadget/function/f_midi2.c
@@ -2177,13 +2177,13 @@ end:
 
 /* generic show/store for string */
 static ssize_t f_midi2_opts_str_show(struct f_midi2_opts *opts,
-				     const char *str, char *page)
+				     const char **strp, char *page)
 {
 	int result = 0;
 
 	mutex_lock(&opts->lock);
-	if (str)
-		result = scnprintf(page, PAGE_SIZE, "%s\n", str);
+	if (*strp)
+		result = scnprintf(page, PAGE_SIZE, "%s\n", *strp);
 	mutex_unlock(&opts->lock);
 	return result;
 }
@@ -2277,7 +2277,7 @@ static ssize_t f_midi2_block_opts_name_s
 {
 	struct f_midi2_block_opts *opts = to_f_midi2_block_opts(item);
 
-	return f_midi2_opts_str_show(opts->ep->opts, opts->info.name, page);
+	return f_midi2_opts_str_show(opts->ep->opts, &opts->info.name, page);
 }
 
 static ssize_t f_midi2_block_opts_name_store(struct config_item *item,
@@ -2434,7 +2434,7 @@ static ssize_t f_midi2_ep_opts_##name##_
 					     char *page)		\
 {									\
 	struct f_midi2_ep_opts *opts = to_f_midi2_ep_opts(item);	\
-	return f_midi2_opts_str_show(opts->opts, opts->info.name, page);\
+	return f_midi2_opts_str_show(opts->opts, &opts->info.name, page);\
 }									\
 									\
 static ssize_t f_midi2_ep_opts_##name##_store(struct config_item *item,	\
@@ -2589,7 +2589,7 @@ static ssize_t f_midi2_opts_iface_name_s
 {
 	struct f_midi2_opts *opts = to_f_midi2_opts(item);
 
-	return f_midi2_opts_str_show(opts, opts->info.iface_name, page);
+	return f_midi2_opts_str_show(opts, &opts->info.iface_name, page);
 }
 
 static ssize_t f_midi2_opts_iface_name_store(struct config_item *item,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 047/556] usb: gadget: f_midi: initialize work in f_midi_alloc()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (45 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 046/556] usb: gadget: f_midi2: fix use-after-free in string attribute show path Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 048/556] USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl() Greg Kroah-Hartman
                   ` (521 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+d5fa3d224505c8610702, stable,
	Jeffin Philip, Takashi Iwai

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jeffin Philip <jeffinphilip14@gmail.com>

commit 7e07d3e4c389217d7d7171d80edf2e23ac70f1ea upstream.

f_midi_alloc initializes free_ref to 1 and it can only be incremented
when a sound card is registered via f_midi_register_card().
f_midi_register_card() is only called in f_midi_bind() which actually
performs INIT_WORK. If f_midi_bind() is never run, work is not
initialized and the if condition in f_midi_free becomes true,
this results in a warning later in __flush_work as work->func = 0.
Fix this by moving INIT_WORK from f_midi_bind() to f_midi_alloc().

Reported-by: syzbot+d5fa3d224505c8610702@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=d5fa3d224505c8610702
Fixes: 8653d71ce376 ("usb/gadget: f_midi: Replace tasklet with work")
Cc: stable <stable@kernel.org>
Signed-off-by: Jeffin Philip <jeffinphilip14@gmail.com>
Reviewed-by: Takashi Iwai <tiwai@suse.de>
Link: https://patch.msgid.link/20260815054006.102325-1-jeffinphilip14@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/usb/gadget/function/f_midi.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/usb/gadget/function/f_midi.c
+++ b/drivers/usb/gadget/function/f_midi.c
@@ -879,7 +879,6 @@ static int f_midi_bind(struct usb_config
 	int status, n, jack = 1, i = 0, endpoint_descriptor_index = 0;
 
 	midi->gadget = cdev->gadget;
-	INIT_WORK(&midi->work, f_midi_in_work);
 	status = f_midi_register_card(midi);
 	if (status < 0)
 		goto fail_register;
@@ -1377,6 +1376,7 @@ static struct usb_function *f_midi_alloc
 		status = -ENOMEM;
 		goto midi_free;
 	}
+	INIT_WORK(&midi->work, f_midi_in_work);
 	midi->out_ports = opts->out_ports;
 	midi->index = opts->index;
 	midi->buflen = opts->buflen;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 048/556] USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (46 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 047/556] usb: gadget: f_midi: initialize work in f_midi_alloc() Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 049/556] usb: gadget: fix null pointer dereference in usb_put_function_instance() Greg Kroah-Hartman
                   ` (520 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, stable, Eulgyu Kim, Jaeyoung Chung,
	Lovekesh Solanki, Alan Stern

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lovekesh Solanki <lovekeshsolanki00@gmail.com>

commit dd0eed9e165b1a6292f49e622e3dd0b7d99b106d upstream.

gadget_dev_ioctl() reads dev->gadget before acquiring dev->lock, but
dev->state is checked after acquiring the lock. Therefore a concurrent
bind can change the device state between these operations, which can
leave ioctl with a stale NULL gadget pointer and causing a NULL pointer
dereference at gadget->ops->ioctl.

Read dev->gadget while holding dev->lock so that the gadget pointer
and device state are sampled consistently.

Cc: stable <stable@kernel.org>
Reported-by: Eulgyu Kim <eulgyukim@snu.ac.kr>
Link: https://lore.kernel.org/all/20260824113510.1141236-1-jjy600901@snu.ac.kr/
Reported-by: Jaeyoung Chung <jjy600901@snu.ac.kr>
Link: https://lore.kernel.org/all/20260824113510.1141236-1-jjy600901@snu.ac.kr/
Signed-off-by: Lovekesh Solanki <lovekeshsolanki00@gmail.com>
Reviewed-by: Alan Stern <stern@rowland.harvard.edu>
Link: https://patch.msgid.link/20260825171343.459630-1-lovekeshsolanki00@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/usb/gadget/legacy/inode.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/drivers/usb/gadget/legacy/inode.c
+++ b/drivers/usb/gadget/legacy/inode.c
@@ -1251,10 +1251,11 @@ out:
 static long gadget_dev_ioctl (struct file *fd, unsigned code, unsigned long value)
 {
 	struct dev_data		*dev = fd->private_data;
-	struct usb_gadget	*gadget = dev->gadget;
+	struct usb_gadget	*gadget;
 	long ret = -ENOTTY;
 
 	spin_lock_irq(&dev->lock);
+	gadget = dev->gadget;
 	if (dev->state == STATE_DEV_OPENED ||
 			dev->state == STATE_DEV_UNBOUND) {
 		/* Not bound to a UDC */



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 049/556] usb: gadget: fix null pointer dereference in usb_put_function_instance()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (47 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 048/556] USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl() Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 050/556] staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr() Greg Kroah-Hartman
                   ` (519 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+fd6ef980cf1c722be639, stable,
	Jeffin Philip

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jeffin Philip <jeffinphilip14@gmail.com>

commit 6e74ac5c596fd246e37eadfc354567179ccbe9aa upstream.

usb_put_function_instance() attempts to dereference fd inside fi struct
to get mod in uvc_alloc_inst() error path. However, fd is not allocated
until later in try_get_usb_function_instance() after allocating fi in
uvc_alloc_inst() and thus guranteed to be null in error path. Fix this
by adding a null check for fi->fd that returns if fd is null.

Reported-by: syzbot+fd6ef980cf1c722be639@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=fd6ef980cf1c722be639
Fixes: 0062f6e56f70 ("usb: gadget: add a forward pointer from usb_function to its "instance"")
Cc: stable <stable@kernel.org>
Signed-off-by: Jeffin Philip <jeffinphilip14@gmail.com>
Link: https://patch.msgid.link/20260816061712.15547-1-jeffinphilip14@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/usb/gadget/functions.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/usb/gadget/functions.c
+++ b/drivers/usb/gadget/functions.c
@@ -70,7 +70,7 @@ void usb_put_function_instance(struct us
 {
 	struct module *mod;
 
-	if (!fi)
+	if (!fi || !fi->fd)
 		return;
 
 	mod = fi->fd->mod;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 050/556] staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (48 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 049/556] usb: gadget: fix null pointer dereference in usb_put_function_instance() Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 051/556] staging: rtl8723bs: fix OOB read in rtw_action_frame_parse() Greg Kroah-Hartman
                   ` (518 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Muhammad Bilal

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Muhammad Bilal <meatuni001@gmail.com>

commit 99aa998dec83ba180822f70e6d48a514fc81c20d upstream.

rtw_get_wps_attr() walks WPS attributes inside a WPS IE taken from
a wireless management frame. For each candidate attribute it only
checks that the fixed 4-byte attribute header (2-byte ID + 2-byte
length) fits inside the IE:

	if (attr_ptr + 4 > wps_ie + wps_ielen)
		break;
	u16 attr_id = get_unaligned_be16(attr_ptr);
	u16 attr_data_len = get_unaligned_be16(attr_ptr + 2);
	u16 attr_len = attr_data_len + 4;

attr_data_len (and therefore attr_len) is read directly from the
wire and is never checked against the remaining bytes in the IE
before being used as the size of:

	memcpy(buf_attr, attr_ptr, attr_len);

Since attr_len is fully attacker controlled (0 to 65535+4), this is
both a heap OOB read of wps_ie, and, more seriously, a stack buffer
overflow at several call sites where buf_attr is a single-byte
stack variable, e.g. rtw_get_wps_attr_content()'s callers passing
WPS_ATTR_SELECTED_REGISTRAR into a stack "u8 sr"/"u8
selected_registrar" (drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c,
drivers/staging/rtl8723bs/core/rtw_mlme_ext.c). A crafted WPS IE in a
beacon or probe response processed during scanning can therefore
smash the stack of the parsing thread.

rtw_get_wps_attr_content() itself has no independent length check
and simply trusts the attr_len it gets back from rtw_get_wps_attr(),
so fixing the bound here also fixes that caller.

The "attr_ptr + 4 > wps_ie + wps_ielen" header check above was added
by commit 1463ca3ec6601 ("staging: rtl8723bs: fix OOB reads in
rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr()"), which
bounded the fixed header but never extended the check to cover the
variable-length attribute data that follows it. Add that missing
check before attr_len is used as a memcpy() length or accepted as a
match.

Fixes: 554c0a3abf216 ("staging: Add rtl8723bs sdio wifi driver")
Cc: stable@vger.kernel.org
Signed-off-by: Muhammad Bilal <meatuni001@gmail.com>
Link: https://patch.msgid.link/20260728125456.32359-2-meatuni001@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/staging/rtl8723bs/core/rtw_ieee80211.c |    4 ++++
 1 file changed, 4 insertions(+)

--- a/drivers/staging/rtl8723bs/core/rtw_ieee80211.c
+++ b/drivers/staging/rtl8723bs/core/rtw_ieee80211.c
@@ -737,6 +737,10 @@ u8 *rtw_get_wps_attr(u8 *wps_ie, uint wp
 		u16 attr_data_len = get_unaligned_be16(attr_ptr + 2);
 		u16 attr_len = attr_data_len + 4;
 
+		/* Reject attributes whose claimed length runs past the IE */
+		if (attr_ptr + attr_len > wps_ie + wps_ielen)
+			break;
+
 		if (attr_id == target_attr_id) {
 			target_attr_ptr = attr_ptr;
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 051/556] staging: rtl8723bs: fix OOB read in rtw_action_frame_parse()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (49 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 050/556] staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr() Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 052/556] staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie() Greg Kroah-Hartman
                   ` (517 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Muhammad Bilal

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Muhammad Bilal <meatuni001@gmail.com>

commit ff917923f4fb9c83717ba135ee47d7e4c1567bb7 upstream.

rtw_action_frame_parse() takes a frame_len parameter but never
actually checks it before indexing into the frame body:

	const u8 *frame_body = frame + sizeof(struct ieee80211_hdr_3addr);
	...
	c = frame_body[0];
	...
	a = frame_body[1];

frame_body already points 24 bytes (sizeof(struct
ieee80211_hdr_3addr)) into frame, so reading frame_body[0] and
frame_body[1] requires frame_len >= 26. A management action frame
shorter than that (e.g. exactly 24 bytes, the minimum a malicious
peer can send) causes a 1-2 byte out-of-bounds read.

This is reachable from rtw_cfg80211_monitor_if_xmit_entry() and
cfg80211_rtw_mgmt_tx() in ioctl_cfg80211.c, both of which pass
attacker/user-influenced frame buffers and lengths straight through.

Add the missing length check before frame_body is dereferenced.

Fixes: 554c0a3abf216 ("staging: Add rtl8723bs sdio wifi driver")
Cc: stable@vger.kernel.org
Signed-off-by: Muhammad Bilal <meatuni001@gmail.com>
Link: https://patch.msgid.link/20260728125456.32359-3-meatuni001@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/staging/rtl8723bs/core/rtw_ieee80211.c |    3 +++
 1 file changed, 3 insertions(+)

--- a/drivers/staging/rtl8723bs/core/rtw_ieee80211.c
+++ b/drivers/staging/rtl8723bs/core/rtw_ieee80211.c
@@ -1149,6 +1149,9 @@ int rtw_action_frame_parse(const u8 *fra
 	u8 c;
 	u8 a = ACT_PUBLIC_MAX;
 
+	if (frame_len < sizeof(struct ieee80211_hdr_3addr) + 2)
+		return false;
+
 	fc = le16_to_cpu(((struct ieee80211_hdr_3addr *)frame)->frame_control);
 
 	if ((fc & (IEEE80211_FCTL_FTYPE | IEEE80211_FCTL_STYPE)) !=



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 052/556] staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (50 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 051/556] staging: rtl8723bs: fix OOB read in rtw_action_frame_parse() Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 053/556] xhci: fix lost bounce buffers on TDs spanning several ring segments Greg Kroah-Hartman
                   ` (516 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Muhammad Bilal

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Muhammad Bilal <meatuni001@gmail.com>

commit 28a289beaf226b30b1e6e7d7b1a2946fe2d6e852 upstream.

rtw_restruct_wmm_ie() scans in_ie for a WMM IE with:

	while (i < in_len) {
		...
		if (i + 5 < in_len && in_ie[i] == 0xDD && ...) {
			...
			break;
		}
		i += (in_ie[i + 1] + 2); /* to the next IE element */
	}

When the "i + 5 < in_len" match check fails simply because i is
within 5 bytes of the end of the buffer (i.e. no WMM IE was found
near the tail of in_ie), execution falls through to
"i += (in_ie[i + 1] + 2)", which reads in_ie[i + 1]. If i == in_len
- 1 at that point, this is a 1-byte out-of-bounds read of an
attacker-influenced IE buffer built from association/scan data.

Commit a75281626fc8f ("staging: rtl8723bs: fix potential
out-of-bounds read in rtw_restruct_wmm_ie") added the "i + 5 <
in_len" guard to the match condition itself, but did not add an
equivalent guard before the fallthrough advance, so the same class
of OOB read remained reachable through the non-matching path.

Add an explicit bounds check before advancing to the next IE.

Fixes: 554c0a3abf216 ("staging: Add rtl8723bs sdio wifi driver")
Cc: stable@vger.kernel.org
Signed-off-by: Muhammad Bilal <meatuni001@gmail.com>
Link: https://patch.msgid.link/20260728125456.32359-4-meatuni001@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/staging/rtl8723bs/core/rtw_mlme.c |    3 +++
 1 file changed, 3 insertions(+)

--- a/drivers/staging/rtl8723bs/core/rtw_mlme.c
+++ b/drivers/staging/rtl8723bs/core/rtw_mlme.c
@@ -1980,6 +1980,9 @@ int rtw_restruct_wmm_ie(struct adapter *
 			break;
 		}
 
+		if (i + 1 >= in_len)
+			break;
+
 		i += (in_ie[i + 1] + 2); /*  to the next IE element */
 	}
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 053/556] xhci: fix lost bounce buffers on TDs spanning several ring segments
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (51 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 052/556] staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie() Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 054/556] thermal/drivers/imx: Disable clock on runtime resume failure Greg Kroah-Hartman
                   ` (515 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michal Pecio, Arthur Gautier,
	Mathias Nyman

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arthur Gautier <baloo@superbaloo.net>

commit ff44dfb03a293bf30e31f98772a1dd316a6071d1 upstream.

When a TD reaches a link TRB with data that is not aligned to the
endpoint's wMaxPacketSize, xhci_align_td() stages the unalignable tail
through the bounce buffer of the ring segment holding that link TRB.
xhci_unmap_td_bounce_buffer() later unmaps it and, for IN transfers,
copies the data back into the URB's buffer.

The enqueue path records the segment that was bounced in td->bounce_seg,
under the assumption that a TD never spans more than two ring segments.
That assumption does not hold: a TD large enough to span three or more
segments crosses several link TRBs and can be bounced at each of them.
Only the last one survives in td->bounce_seg, so every earlier bounce
buffer is neither copied back nor DMA unmapped.

The URB still completes with actual_length equal to the requested length
and no error, so the transfer looks successful while a wMaxPacketSize
sized hole in the destination buffer silently keeps its previous
contents. It also leaks a DMA mapping per dropped bounce.

Any sufficiently large and fragmented bulk transfer can hit this. It was
found with a USB mass storage device behind xHCI backing a dm-verity
target with 512 byte hash blocks, where the stale data is detected rather
than silently consumed. The device enumerates as SuperSpeed, so
wMaxPacketSize is 1024, while dm-bufio issues one 512 byte bio per hash
block. verity_prefetch_io() makes the block layer merge hundreds of them
into a single request of up to 512 scatterlist entries of 512 bytes each.
At 256 TRBs per ring segment such a TD spans three segments, and every
segment boundary falls on an odd multiple of 512, i.e. unaligned to
wMaxPacketSize. dm-bufio then caches a hash block holding stale data and
dm-verity declares the metadata block corrupted:

  device-mapper: verity: 8:2: metadata block 10850 is corrupted

A reproducer running this under qemu is available at
https://github.com/baloo/xhci-verity

The bounce state (bounce_buf, bounce_dma, bounce_len, bounce_offs)
already lives on the ring segment, so there is nothing extra to track.
Keep recording the last bounced segment in td->bounce_seg and, on
completion, walk the segments from td->start_seg up to it, unmapping
every segment that still has a pending bounce.

Stopping at td->bounce_seg rather than td->end_seg matters: a bounce
implies the TD continues past that segment's link TRB, so bounce_seg is
always strictly before end_seg, and a later TD may already have started
in end_seg and been bounced there. Walking that far would copy a foreign
bounce buffer into this URB and unmap it twice. It also keeps the walk
correct if a TD ever wraps the whole ring so that end_seg == start_seg.

[mn: Add ring->num_segs check to prevent unlikely infinite for loop.]

Fixes: f9c589e142d0 ("xhci: TD-fragment, align the unsplittable case with a bounce buffer")
Cc: stable@vger.kernel.org
Suggested-by: Michal Pecio <michal.pecio@gmail.com>
Signed-off-by: Arthur Gautier <baloo@superbaloo.net>
Signed-off-by: Mathias Nyman <mathias.nyman@linux.intel.com>
Link: https://patch.msgid.link/20260831090448.95644-4-mathias.nyman@linux.intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/usb/host/xhci-ring.c |   32 ++++++++++++++++++++++++--------
 1 file changed, 24 insertions(+), 8 deletions(-)

--- a/drivers/usb/host/xhci-ring.c
+++ b/drivers/usb/host/xhci-ring.c
@@ -842,21 +842,18 @@ static void xhci_giveback_urb_in_irq(str
 	usb_hcd_giveback_urb(hcd, urb, status);
 }
 
-static void xhci_unmap_td_bounce_buffer(struct xhci_hcd *xhci,
-		struct xhci_ring *ring, struct xhci_td *td)
+static void xhci_unmap_one_bounce_buffer(struct xhci_hcd *xhci,
+		struct xhci_ring *ring, struct xhci_td *td,
+		struct xhci_segment *seg)
 {
 	struct device *dev = xhci_to_hcd(xhci)->self.sysdev;
-	struct xhci_segment *seg = td->bounce_seg;
 	struct urb *urb = td->urb;
 	size_t len;
 
-	if (!ring || !seg || !urb)
-		return;
-
 	if (usb_urb_dir_out(urb)) {
 		dma_unmap_single(dev, seg->bounce_dma, ring->bounce_buf_len,
 				 DMA_TO_DEVICE);
-		return;
+		goto done;
 	}
 
 	dma_unmap_single(dev, seg->bounce_dma, ring->bounce_buf_len,
@@ -872,10 +869,29 @@ static void xhci_unmap_td_bounce_buffer(
 		memcpy(urb->transfer_buffer + seg->bounce_offs, seg->bounce_buf,
 		       seg->bounce_len);
 	}
+done:
 	seg->bounce_len = 0;
 	seg->bounce_offs = 0;
 }
 
+static void xhci_unmap_td_bounce_buffer(struct xhci_hcd *xhci,
+		struct xhci_ring *ring, struct xhci_td *td)
+{
+	struct xhci_segment *seg;
+	int i = 0;
+
+	if (!td->bounce_seg || !ring || !td->urb)
+		return;
+
+	/* td->bounce_seg is the last one bounced, unmap them all */
+	for (seg = td->start_seg; i++ < ring->num_segs; seg = seg->next) {
+		if (seg->bounce_len)
+			xhci_unmap_one_bounce_buffer(xhci, ring, td, seg);
+		if (seg == td->bounce_seg)
+			break;
+	}
+}
+
 static void xhci_td_cleanup(struct xhci_hcd *xhci, struct xhci_td *td,
 			    struct xhci_ring *ep_ring, int status)
 {
@@ -3688,7 +3704,7 @@ int xhci_queue_bulk_tx(struct xhci_hcd *
 						  &trb_buff_len,
 						  ring->enq_seg)) {
 					send_addr = ring->enq_seg->bounce_dma;
-					/* assuming TD won't span 2 segs */
+					/* TD bounced at least, and last on this seg */
 					td->bounce_seg = ring->enq_seg;
 				}
 			}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 054/556] thermal/drivers/imx: Disable clock on runtime resume failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (52 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 053/556] xhci: fix lost bounce buffers on TDs spanning several ring segments Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 055/556] thermal/drivers/qoriq: Disable clock on " Greg Kroah-Hartman
                   ` (514 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Can Peng, Daniel Lezcano, Frank Li

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Can Peng <pengcan@kylinos.cn>

commit bcc6d886e5006a4656901d2d7fb6a215c96068a0 upstream.

imx_thermal_runtime_resume() enables the thermal clock before
powering up the sensor and enabling measurements.

If either regmap_write() fails, the function returns with the clock
still enabled. This leaves the clock enable count unbalanced after a
failed runtime resume.

Disable the clock on those failure paths before returning the error.

Fixes: 4cf2ddf16e17 ("thermal/drivers/imx: Implement runtime PM support")
Cc: stable@vger.kernel.org
Signed-off-by: Can Peng <pengcan@kylinos.cn>
Signed-off-by: Daniel Lezcano <daniel.lezcano@kernel.org>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260722084909.463437-1-pengcan@kylinos.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/thermal/imx_thermal.c |    9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

--- a/drivers/thermal/imx_thermal.c
+++ b/drivers/thermal/imx_thermal.c
@@ -832,12 +832,12 @@ static int imx_thermal_runtime_resume(st
 	ret = regmap_write(map, socdata->sensor_ctrl + REG_CLR,
 			   socdata->power_down_mask);
 	if (ret)
-		return ret;
+		goto disable_clk;
 
 	ret = regmap_write(map, socdata->sensor_ctrl + REG_SET,
 			   socdata->measure_temp_mask);
 	if (ret)
-		return ret;
+		goto disable_clk;
 
 	/*
 	 * According to the temp sensor designers, it may require up to ~17us
@@ -846,6 +846,11 @@ static int imx_thermal_runtime_resume(st
 	usleep_range(20, 50);
 
 	return 0;
+
+disable_clk:
+	clk_disable_unprepare(data->thermal_clk);
+
+	return ret;
 }
 
 static const struct dev_pm_ops imx_thermal_pm_ops = {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 055/556] thermal/drivers/qoriq: Disable clock on resume failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (53 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 054/556] thermal/drivers/imx: Disable clock on runtime resume failure Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 056/556] tracing/probes: Fix anon_stack check for unnamed bitfields in btf_find_struct_member Greg Kroah-Hartman
                   ` (513 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Can Peng, Daniel Lezcano

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Can Peng <pengcan@kylinos.cn>

commit fcbf9964b67a6d6704c50ed28daa24c3b164f01c upstream.

qoriq_tmu_resume() enables the TMU clock before clearing the
power-down bit and enabling monitoring.

If either register update fails, the function returns with the clock
still enabled. This leaves the clock enable count unbalanced after a
failed resume.

Disable the clock on those failure paths before returning the error.

Fixes: 51904045d4aa ("thermal: qoriq: Add clock operations")
Cc: stable@vger.kernel.org
Signed-off-by: Can Peng <pengcan@kylinos.cn>
Signed-off-by: Daniel Lezcano <daniel.lezcano@kernel.org>
Link: https://patch.msgid.link/20260722075625.452684-1-pengcan@kylinos.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/thermal/qoriq_thermal.c |   13 +++++++++++--
 1 file changed, 11 insertions(+), 2 deletions(-)

--- a/drivers/thermal/qoriq_thermal.c
+++ b/drivers/thermal/qoriq_thermal.c
@@ -415,11 +415,20 @@ static int qoriq_tmu_resume(struct devic
 	if (data->ver > TMU_VER1) {
 		ret = regmap_clear_bits(data->regmap, REGS_TMR, TMR_CMD);
 		if (ret)
-			return ret;
+			goto disable_clk;
 	}
 
 	/* Enable monitoring */
-	return regmap_update_bits(data->regmap, REGS_TMR, TMR_ME, TMR_ME);
+	ret = regmap_update_bits(data->regmap, REGS_TMR, TMR_ME, TMR_ME);
+	if (ret)
+		goto disable_clk;
+
+	return 0;
+
+disable_clk:
+	clk_disable_unprepare(data->clk);
+
+	return ret;
 }
 
 static DEFINE_SIMPLE_DEV_PM_OPS(qoriq_tmu_pm_ops,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 056/556] tracing/probes: Fix anon_stack check for unnamed bitfields in btf_find_struct_member
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (54 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 055/556] thermal/drivers/qoriq: Disable clock on " Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 057/556] tracing: Have show_event_filters/triggers files take trace array ref Greg Kroah-Hartman
                   ` (512 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Masami Hiramatsu (Google),
	Steven Rostedt

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Masami Hiramatsu (Google) <mhiramat@kernel.org>

commit f36d94a20ca185bcadef3a10b980cd2cfd72d53a upstream.

btf_find_struct_member() traverses into nested anonymous structures
and unions by pushing members with !member->name_off onto anon_stack.
However, it does not consider the unnamed bitfields (e.g. `int : 5`
or `unsigned int : 0`) which also have member->name_off == 0.

If such an unnamed bitfield is pushed to anon_stack, the
btf_find_struct_member() return an error even if there are other
valid entries in anon_stack.

To fix this, only push unnamed struct/union members to anon_stack.
Also move the btf_type_is_struct() check to the entry of this function
because now it is sure only struct/union are pushed to anon_stack.

Link: https://lore.kernel.org/all/178827249775.123716.7813217688423513612.stgit@devnote2/

Fixes: 302db0f5b3d8 ("tracing/probes: Add a function to search a member of a struct/union")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/all/20260830143859.D56991F00A3D@smtp.kernel.org/
Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Reviewed-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 kernel/trace/trace_btf.c |   12 ++++++------
 1 file changed, 6 insertions(+), 6 deletions(-)

--- a/kernel/trace/trace_btf.c
+++ b/kernel/trace/trace_btf.c
@@ -74,24 +74,24 @@ const struct btf_member *btf_find_struct
 {
 	struct btf_anon_stack *anon_stack;
 	const struct btf_member *member;
+	const struct btf_type *mtype;
 	u32 tid, cur_offset = 0;
 	const char *name;
 	int i, top = 0;
 
+	if (!btf_type_is_struct(type))
+		return ERR_PTR(-EINVAL);
+
 	anon_stack = kzalloc_objs(*anon_stack, BTF_ANON_STACK_MAX);
 	if (!anon_stack)
 		return ERR_PTR(-ENOMEM);
 
 retry:
-	if (!btf_type_is_struct(type)) {
-		member = ERR_PTR(-EINVAL);
-		goto out;
-	}
-
 	for_each_member(i, type, member) {
 		if (!member->name_off) {
 			/* Anonymous union/struct: push it for later use */
-			if (btf_type_skip_modifiers(btf, member->type, &tid) &&
+			mtype = btf_type_skip_modifiers(btf, member->type, &tid);
+			if (mtype && btf_type_is_struct(mtype) &&
 			    top < BTF_ANON_STACK_MAX) {
 				anon_stack[top].tid = tid;
 				anon_stack[top++].offset =



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 057/556] tracing: Have show_event_filters/triggers files take trace array ref
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (55 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 056/556] tracing/probes: Fix anon_stack check for unnamed bitfields in btf_find_struct_member Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 058/556] tracing: Take trace_array reference when opening options file Greg Kroah-Hartman
                   ` (511 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Farhad Alemi, Aaron Tomlin,
	Steven Rostedt

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Steven Rostedt <rostedt@goodmis.org>

commit f4a771cc684c7354b6200147f7252c58d17408ff upstream.

The newly added files show_event_filters and show_event_triggers that show
all filters or triggers that are set within the trace array do not take a
reference for the trace array it is showing. Without taking a reference,
the trace_array may be freed via "rmdir" while a task is reading one of
theses files. Those files iterate all the events within an instance
(trace_array) and nothing prevents that instance from being freed while
its data is being read. This causes a use-after-free crash.

Have the open of both those files take the trace_array reference via the
trace_array_get() that prevents the trace_array from being freed while the
files are opened.

Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260828094153.17b95037@gandalf.local.home
Fixes: 729757b96a662 ("tracing: Add show_event_filters to expose active event filters")
Fixes: 6a80838814eea ("tracing: Add show_event_triggers to expose active event triggers")
Reported-by: Farhad Alemi <farhad.alemi@berkeley.edu>
Closes: https://lore.kernel.org/all/CA+0ovCjerKZJLwXScM9bF2ga2rLi4_XOpUfK41NDbENpeu98jA@mail.gmail.com/
Reviewed-by: Aaron Tomlin <atomlin@atomlin.com>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 kernel/trace/trace_events.c |   28 ++++++++++++++++++++++++----
 1 file changed, 24 insertions(+), 4 deletions(-)

--- a/kernel/trace/trace_events.c
+++ b/kernel/trace/trace_events.c
@@ -2654,14 +2654,14 @@ static const struct file_operations ftra
 	.open = ftrace_event_show_filters_open,
 	.read = seq_read,
 	.llseek = seq_lseek,
-	.release = seq_release,
+	.release = ftrace_event_release,
 };
 
 static const struct file_operations ftrace_show_event_triggers_fops = {
 	.open = ftrace_event_show_triggers_open,
 	.read = seq_read,
 	.llseek = seq_lseek,
-	.release = seq_release,
+	.release = ftrace_event_release,
 };
 
 static const struct file_operations ftrace_set_event_pid_fops = {
@@ -2819,7 +2819,17 @@ ftrace_event_set_open(struct inode *inod
 static int
 ftrace_event_show_filters_open(struct inode *inode, struct file *file)
 {
-	return ftrace_event_open(inode, file, &show_show_event_filters_seq_ops);
+	struct trace_array *tr = inode->i_private;
+	int ret;
+
+	ret = tracing_check_open_get_tr(tr);
+	if (ret)
+		return ret;
+
+	ret = ftrace_event_open(inode, file, &show_show_event_filters_seq_ops);
+	if (ret < 0)
+		trace_array_put(tr);
+	return ret;
 }
 
 /**
@@ -2833,7 +2843,17 @@ ftrace_event_show_filters_open(struct in
 static int
 ftrace_event_show_triggers_open(struct inode *inode, struct file *file)
 {
-	return ftrace_event_open(inode, file, &show_show_event_triggers_seq_ops);
+	struct trace_array *tr = inode->i_private;
+	int ret;
+
+	ret = tracing_check_open_get_tr(tr);
+	if (ret)
+		return ret;
+
+	ret = ftrace_event_open(inode, file, &show_show_event_triggers_seq_ops);
+	if (ret < 0)
+		trace_array_put(tr);
+	return ret;
 }
 
 static int



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 058/556] tracing: Take trace_array reference when opening options file
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (56 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 057/556] tracing: Have show_event_filters/triggers files take trace array ref Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 059/556] userfaultfd: reset err to be 0 when move_pages_ptes succeeded Greg Kroah-Hartman
                   ` (510 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, sashiko-bot, Steven Rostedt

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Steven Rostedt <rostedt@goodmis.org>

commit f2951ebd15c36a1ea4820a7f0cbb0b5f1c028b73 upstream.

The options files do not take the trace_array reference for the options
they represent. This could cause a use-after-free kernel crash if one of
these files is opened by one task and another task removes the instance
that the option is for. Because it doesn't take a reference upon opening,
it will not stop the removal which will free the options descriptor that
is being used.

As the options are somewhat dynamic in their creation at boot up, each
file represents a flag in the trace_array. The trace_array has an array of
indexes to represent each of these flags that is stored in the
trace_flags_index array. The address of the index array element is used to
pass to the inode->i_private pointer. Then that element is read which
holds the index (which represents the flag) and then the index is used to
calculate the trace_array descriptor from its trace_flags_index array.

One issue is that the index element can not be referenced until the
trace_array's reference is taken. To handle this, create a new helper
function called: trace_array_options_get() that will iterate all the
existing trace_arrays in the ftrace_trace_arrays list (under the
trace_types_lock), and compare the passed in address of the index element
with the entire array of the trace_array's trace_flags_index array.
If it matches, then up the corresponding trace_array's reference and
return.

Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260902121918.5a9e9d1b@gandalf.local.home
Fixes: 577b785f55168 ("tracing: add tracer dependent options to options directory")
Reported-by: sashiko-bot@kernel.org
Closes: https://lore.kernel.org/linux-trace-kernel/20260828135858.2AC501F000E9@smtp.kernel.org/
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 kernel/trace/trace.c |   67 +++++++++++++++++++++++++++++++++++++++++++++++----
 1 file changed, 63 insertions(+), 4 deletions(-)

--- a/kernel/trace/trace.c
+++ b/kernel/trace/trace.c
@@ -7840,11 +7840,70 @@ trace_options_core_write(struct file *fi
 	return cnt;
 }
 
+/*
+ * The tr_index is the address of a trace_array->trace_flags_index[]
+ * element that holds the index of the trace flag. But since the
+ * trace_array reference has not been taken yet, it cannot be referenced
+ * as it could have been freed by a rmdir of the instance the trace_array
+ * represents.
+ *
+ * Search the list of trace_arrays and compare the tr_index to the
+ * address of the entire trace_array trace_flags_index array for each
+ * trace_array in the list. If one is matched, then take the reference
+ * and return it. If not, the trace_array no longer exits.
+ */
+static int trace_array_options_get(void *tr_index)
+{
+	struct trace_array *tr;
+	int ret;
+
+	ret = security_locked_down(LOCKDOWN_TRACEFS);
+	if (ret)
+		return ret;
+
+	if (tracing_disabled)
+		return -ENODEV;
+
+	guard(mutex)(&trace_types_lock);
+	list_for_each_entry(tr, &ftrace_trace_arrays, list) {
+		if (tr_index >= (void *)&tr->trace_flags_index[0] &&
+		    tr_index < (void *)&tr->trace_flags_index[TRACE_FLAGS_MAX_SIZE])
+			return __trace_array_get(tr);
+	}
+	return -ENODEV;
+}
+
+static int trace_options_open(struct inode *inode, struct file *filp)
+{
+	void *tr_index = inode->i_private;
+
+	if (trace_array_options_get(tr_index) < 0)
+		return -ENODEV;
+
+	filp->private_data = tr_index;
+
+	return 0;
+}
+
+static int trace_options_release(struct inode *inode, struct file *filp)
+{
+	void *tr_index = filp->private_data;
+	struct trace_array *tr;
+	unsigned int index;
+
+	get_tr_index(tr_index, &tr, &index);
+
+	trace_array_put(tr);
+
+	return 0;
+}
+
 static const struct file_operations trace_options_core_fops = {
-	.open = tracing_open_generic,
-	.read = trace_options_core_read,
-	.write = trace_options_core_write,
-	.llseek = generic_file_llseek,
+	.open		= trace_options_open,
+	.read		= trace_options_core_read,
+	.write		= trace_options_core_write,
+	.llseek		= generic_file_llseek,
+	.release	= trace_options_release,
 };
 
 struct dentry *trace_create_file(const char *name,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 059/556] userfaultfd: reset err to be 0 when move_pages_ptes succeeded
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (57 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 058/556] tracing: Take trace_array reference when opening options file Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 060/556] ublk: clear VM_MAYWRITE on read-only ublk char device mmap Greg Kroah-Hartman
                   ` (509 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Bryan Lim, Suren Baghdasaryan,
	Mike Rapoport (Microsoft), Peter Xu, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bryan Lim <foxieflakey@gmail.com>

commit f025ca73decda1f895a4b80b961d3bc88825298a upstream.

During move_pages() operation, when move_pages_ptes() returns EAGAIN, the
error code is not cleared even after we processed it.  This leads to a
successful retry but then the same pages are retried again due to the
stale error code.  This time move fails because pages are already moved,
loop is terminated and move_pages() reports a failure.  Clear the error
code once we processes EAGAIN.

Link: https://lore.kernel.org/e1e0b5f8-c3c6-0537-670b-4397f822f980@gmail.com
Fixes: 50944692052b ("userfaultfd: opportunistic TLB-flush batching for present pages in MOVE")
Assisted-by: ChatGPT:GPT-5.6-Luna
Signed-off-by: Bryan Lim <foxieflakey@gmail.com>
Reviewed-by: Suren Baghdasaryan <surenb@google.com>
Acked-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Cc: Peter Xu <peterx@redhat.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/userfaultfd.c |    4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

--- a/mm/userfaultfd.c
+++ b/mm/userfaultfd.c
@@ -2085,8 +2085,10 @@ static ssize_t move_pages(struct userfau
 		}
 
 		if (err) {
-			if (err == -EAGAIN)
+			if (err == -EAGAIN) {
+				err = 0;
 				continue;
+			}
 			break;
 		}
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 060/556] ublk: clear VM_MAYWRITE on read-only ublk char device mmap
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (58 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 059/556] userfaultfd: reset err to be 0 when move_pages_ptes succeeded Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 061/556] soc: fsl: qe: Add chained_irq_{enter,exit}() calls in cascade handler Greg Kroah-Hartman
                   ` (508 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Kanishka De Silva, Ming Lei,
	Jens Axboe

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Kanishka De Silva <kpskanna1915@gmail.com>

commit 6e2b571b0a54755b06e092501913e1dfefe75d6c upstream.

ublk_ch_mmap() rejects mmap requests with VM_WRITE set, but never
clears VM_MAYWRITE on the resulting read-only mapping. This allows
a userspace daemon to mmap the per-queue command buffer PROT_READ,
then upgrade it to PROT_WRITE via mprotect(), since VM_MAYWRITE was
never cleared.

The command buffer holds struct ublksrv_io_desc entries that are
kernel-written ABI; a writable mapping lets an unprivileged daemon
process corrupt fields such as addr, op_flags, nr_sectors, and
start_sector.

Same bug class as the drm/panthor and drm/vc4 VM_MAYWRITE fixes, and
the 2026-08-13 ptp/vmclock fix (a5edadbae57e).

Verified via mprotect() PoC: before the fix, a PROT_READ mapping can
be upgraded to PROT_READ|PROT_WRITE and a write into the command
buffer corrupts io_desc fields (confirmed under KASAN). After the
fix, mprotect() returns -EACCES.

Fixes: 3fee8d7599e1 ("ublk_drv: add io_uring based userspace block driver")
Cc: stable@vger.kernel.org
Signed-off-by: Kanishka De Silva <kpskanna1915@gmail.com>
Reviewed-by: Ming Lei <tom.leiming@gmail.com>
Link: https://patch.msgid.link/20260830070133.559-1-kpskanna1915@gmail.com
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/block/ublk_drv.c |    6 ++++++
 1 file changed, 6 insertions(+)

--- a/drivers/block/ublk_drv.c
+++ b/drivers/block/ublk_drv.c
@@ -2651,6 +2651,12 @@ static int ublk_ch_mmap(struct file *fil
 	if (vma->vm_flags & VM_WRITE)
 		return -EPERM;
 
+	/*
+	 * The per-queue command buffer is kernel-written ABI; prevent
+	 * the daemon from upgrading to writable via mprotect().
+	 */
+	vm_flags_clear(vma, VM_MAYWRITE);
+
 	end = UBLKSRV_CMD_BUF_OFFSET + ub->dev_info.nr_hw_queues * max_sz;
 	if (phys_off < UBLKSRV_CMD_BUF_OFFSET || phys_off >= end)
 		return -EINVAL;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 061/556] soc: fsl: qe: Add chained_irq_{enter,exit}() calls in cascade handler
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (59 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 060/556] ublk: clear VM_MAYWRITE on read-only ublk char device mmap Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 062/556] soc: qcom: geni-se: Use HW PROG_RAM_DEPTH to validate firmware size Greg Kroah-Hartman
                   ` (507 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Paul Louvel, stable,
	Christophe Leroy (CS GROUP)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Paul Louvel <paul.louvel@bootlin.com>

commit 7e47fe56415847732419ca8cef9307bf111dd368 upstream.

Wrap the cascade handler body with chained_irq_{enter,exit}() to
properly inform the parent IRQ chip that a chained interrupt is being
serviced.

Fixes: f0bcd784e1b76 ("soc: fsl: qe: Add an interrupt controller for QUICC Engine Ports")
Signed-off-by: Paul Louvel <paul.louvel@bootlin.com>
Cc: stable@kernel.org
Reviewed-by: Christophe Leroy (CS GROUP) <chleroy@kernel.org>
Link: https://lore.kernel.org/r/20260708-qe-pic-gpios-v2-1-1972044cfbd1@bootlin.com
Signed-off-by: Christophe Leroy (CS GROUP) <chleroy@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/soc/fsl/qe/qe_ports_ic.c |    7 +++++++
 1 file changed, 7 insertions(+)

--- a/drivers/soc/fsl/qe/qe_ports_ic.c
+++ b/drivers/soc/fsl/qe/qe_ports_ic.c
@@ -6,6 +6,7 @@
  */
 
 #include <linux/irq.h>
+#include <linux/irqchip/chained_irq.h>
 #include <linux/irqdomain.h>
 #include <linux/platform_device.h>
 
@@ -79,7 +80,13 @@ static int qepic_get_irq(struct irq_desc
 
 static void qepic_cascade(struct irq_desc *desc)
 {
+	struct irq_chip *chip = irq_desc_get_chip(desc);
+
+	chained_irq_enter(chip, desc);
+
 	generic_handle_irq(qepic_get_irq(desc));
+
+	chained_irq_exit(chip, desc);
 }
 
 static int qepic_host_map(struct irq_domain *h, unsigned int virq, irq_hw_number_t hw)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 062/556] soc: qcom: geni-se: Use HW PROG_RAM_DEPTH to validate firmware size
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (60 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 061/556] soc: fsl: qe: Add chained_irq_{enter,exit}() calls in cascade handler Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 063/556] spi: bcm63xx-hsspi: disable clocks on resume failure Greg Kroah-Hartman
                   ` (506 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Viken Dadhaniya,
	Bjorn Andersson

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Viken Dadhaniya <viken.dadhaniya@oss.qualcomm.com>

commit 522bfb4f33c0930b3d14d5c5ee80bc93a883b544 upstream.

The hardcoded MAX_GENI_CFG_RAMn_CNT limit is not accurate for all SoCs:
some targets have less CFG RAM than the constant implies, while others
like QCS615 need more entries than the old limit of 455 allowed, causing
valid firmware to be rejected at load time.

Rather than hardcoding a constant, read PROG_RAM_DEPTH from SE_HW_PARAM_2
at runtime to get the actual CFG RAM depth of the hardware instance and
use that as the upper bound for firmware size validation.

Fixes: d4bf06592ad6 ("soc: qcom: geni-se: Add support to load QUP SE Firmware via Linux subsystem")
Cc: stable@vger.kernel.org
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Viken Dadhaniya <viken.dadhaniya@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260702-qup-se-increase-ram-cnt-v3-1-80b363373a5b@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/soc/qcom/qcom-geni-se.c  |   24 +++++++++++++-----------
 include/linux/soc/qcom/geni-se.h |    4 ++++
 2 files changed, 17 insertions(+), 11 deletions(-)

--- a/drivers/soc/qcom/qcom-geni-se.c
+++ b/drivers/soc/qcom/qcom-geni-se.c
@@ -154,8 +154,6 @@ struct se_fw_hdr {
 /*Magic numbers*/
 #define SE_MAGIC_NUM			0x57464553
 
-#define MAX_GENI_CFG_RAMn_CNT		455
-
 #define MI_PBT_NON_PAGED_SEGMENT	0x0
 #define MI_PBT_HASH_SEGMENT		0x2
 #define MI_PBT_NOTUSED_SEGMENT		0x3
@@ -1224,24 +1222,27 @@ EXPORT_SYMBOL_GPL(geni_se_resources_init
 
 /**
  * geni_find_protocol_fw() - Locate and validate SE firmware for a protocol.
- * @dev: Pointer to the device structure.
+ * @se: Pointer to the serial engine structure.
  * @fw: Pointer to the firmware image.
  * @protocol: Expected serial engine protocol type.
  *
  * Identifies the appropriate firmware image or configuration required for a
- * specific communication protocol instance running on a  Qualcomm GENI
- * controller.
+ * specific communication protocol instance running on a Qualcomm GENI
+ * controller. Validates the firmware size against the hardware PROG_RAM_DEPTH
+ * read from SE_HW_PARAM_2.
  *
  * Return: pointer to a valid 'struct se_fw_hdr' if found, or NULL otherwise.
  */
-static struct se_fw_hdr *geni_find_protocol_fw(struct device *dev, const struct firmware *fw,
+static struct se_fw_hdr *geni_find_protocol_fw(struct geni_se *se, const struct firmware *fw,
 					       enum geni_se_protocol_type protocol)
 {
+	struct device *dev = se->dev;
 	const struct elf32_hdr *ehdr;
 	const struct elf32_phdr *phdrs;
 	const struct elf32_phdr	*phdr;
 	struct se_fw_hdr *sefw;
 	u32 fw_end, cfg_idx_end, cfg_val_end;
+	u32 prog_ram_depth;
 	u16 fw_size;
 	int i;
 
@@ -1300,10 +1301,11 @@ static struct se_fw_hdr *geni_find_proto
 			sefw->fw_size_in_items = cpu_to_le16(fw_size);
 		}
 
-		if (fw_size >= MAX_GENI_CFG_RAMn_CNT) {
-			dev_err(dev,
-				"Firmware size (%u) exceeds max allowed RAMn count (%u)\n",
-				fw_size, MAX_GENI_CFG_RAMn_CNT);
+		prog_ram_depth = FIELD_GET(PROG_RAM_DEPTH_MSK,
+					   readl_relaxed(se->base + SE_HW_PARAM_2));
+		if (fw_size >= prog_ram_depth) {
+			dev_err(dev, "Firmware size (%u) exceeds RAM size (%u)\n",
+				fw_size, prog_ram_depth);
 			continue;
 		}
 
@@ -1427,7 +1429,7 @@ static int geni_load_se_fw(struct geni_s
 	int ret;
 	struct se_fw_hdr *hdr;
 
-	hdr = geni_find_protocol_fw(se->dev, fw, protocol);
+	hdr = geni_find_protocol_fw(se, fw, protocol);
 	if (!hdr)
 		return -EINVAL;
 
--- a/include/linux/soc/qcom/geni-se.h
+++ b/include/linux/soc/qcom/geni-se.h
@@ -124,6 +124,7 @@ struct geni_se {
 #define SE_DMA_RX_FSM_RST		0xd58
 #define SE_HW_PARAM_0			0xe24
 #define SE_HW_PARAM_1			0xe28
+#define SE_HW_PARAM_2			0xe2c
 
 /* GENI_FORCE_DEFAULT_REG fields */
 #define FORCE_DEFAULT	BIT(0)
@@ -291,6 +292,9 @@ struct geni_se {
 #define RX_FIFO_DEPTH_MSK		GENMASK(21, 16)
 #define RX_FIFO_DEPTH_SHFT		16
 
+/* SE_HW_PARAM_2 fields */
+#define PROG_RAM_DEPTH_MSK		GENMASK(10, 0)
+
 #define HW_VER_MAJOR_MASK		GENMASK(31, 28)
 #define HW_VER_MAJOR_SHFT		28
 #define HW_VER_MINOR_MASK		GENMASK(27, 16)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 063/556] spi: bcm63xx-hsspi: disable clocks on resume failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (61 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 062/556] soc: qcom: geni-se: Use HW PROG_RAM_DEPTH to validate firmware size Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 064/556] spi: bcm63xx: disable clock " Greg Kroah-Hartman
                   ` (505 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Can Peng, Kursad Oney, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Can Peng <pengcan@kylinos.cn>

commit 3b0cee02664041aea7e4f787c66cb86c82eb4e97 upstream.

bcm63xx_hsspi_resume() enables the HSSPI clock, and optionally the PLL
clock, before restarting the SPI controller queue.

If spi_controller_resume() fails, the function currently reports success
and leaves those clocks enabled. Propagate the error and disable the
clocks before returning.

Fixes: 142168eba9dc ("spi: bcm63xx-hsspi: add bcm63xx HSSPI driver")
Cc: stable@vger.kernel.org
Signed-off-by: Can Peng <pengcan@kylinos.cn>
Reviewed-by: Kursad Oney <kursad.oney@broadcom.com>
Link: https://patch.msgid.link/20260804072017.860974-1-pengcan@kylinos.cn
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/spi/spi-bcm63xx-hsspi.c |    8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

--- a/drivers/spi/spi-bcm63xx-hsspi.c
+++ b/drivers/spi/spi-bcm63xx-hsspi.c
@@ -915,7 +915,13 @@ static int bcm63xx_hsspi_resume(struct d
 		}
 	}
 
-	spi_controller_resume(host);
+	ret = spi_controller_resume(host);
+	if (ret) {
+		if (bs->pll_clk)
+			clk_disable_unprepare(bs->pll_clk);
+		clk_disable_unprepare(bs->clk);
+		return ret;
+	}
 
 	return 0;
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 064/556] spi: bcm63xx: disable clock on resume failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (62 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 063/556] spi: bcm63xx-hsspi: disable clocks on resume failure Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 065/556] spi: bcmbca-hsspi: disable clocks " Greg Kroah-Hartman
                   ` (504 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Can Peng, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Can Peng <pengcan@kylinos.cn>

commit 2b62c2c134fa32d9d3a9e7323c8ac74518eeb4ac upstream.

bcm63xx_spi_resume() enables the controller clock before restarting the
SPI controller queue.

If spi_controller_resume() fails, the function currently reports success
and leaves the clock enabled. Propagate the error and disable the clock
before returning.

Fixes: b42dfed83d95 ("spi: add Broadcom BCM63xx SPI controller driver")
Cc: stable@vger.kernel.org
Signed-off-by: Can Peng <pengcan@kylinos.cn>
Link: https://patch.msgid.link/20260804071831.860784-1-pengcan@kylinos.cn
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/spi/spi-bcm63xx.c |    6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

--- a/drivers/spi/spi-bcm63xx.c
+++ b/drivers/spi/spi-bcm63xx.c
@@ -650,7 +650,11 @@ static int bcm63xx_spi_resume(struct dev
 	if (ret)
 		return ret;
 
-	spi_controller_resume(host);
+	ret = spi_controller_resume(host);
+	if (ret) {
+		clk_disable_unprepare(bs->clk);
+		return ret;
+	}
 
 	return 0;
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 065/556] spi: bcmbca-hsspi: disable clocks on resume failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (63 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 064/556] spi: bcm63xx: disable clock " Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 066/556] spi: Fix DMA mapping ownership on partial map failure Greg Kroah-Hartman
                   ` (503 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Can Peng, Kursad Oney, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Can Peng <pengcan@kylinos.cn>

commit d2f5a606710ad70c341dc609430a20a5645618d5 upstream.

bcmbca_hsspi_resume() enables the HSSPI clock, and optionally the PLL
clock, before restarting the SPI controller queue.

If spi_controller_resume() fails, the function currently reports success
and leaves those clocks enabled. Propagate the error and disable the
clocks before returning.

Fixes: a38a2233f23b ("spi: bcmbca-hsspi: Add driver for newer HSSPI controller")
Cc: stable@vger.kernel.org
Signed-off-by: Can Peng <pengcan@kylinos.cn>
Reviewed-by: Kursad Oney <kursad.oney@broadcom.com>
Link: https://patch.msgid.link/20260804071904.860842-1-pengcan@kylinos.cn
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/spi/spi-bcmbca-hsspi.c |    8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

--- a/drivers/spi/spi-bcmbca-hsspi.c
+++ b/drivers/spi/spi-bcmbca-hsspi.c
@@ -594,7 +594,13 @@ static int bcmbca_hsspi_resume(struct de
 		}
 	}
 
-	spi_controller_resume(host);
+	ret = spi_controller_resume(host);
+	if (ret) {
+		if (bs->pll_clk)
+			clk_disable_unprepare(bs->pll_clk);
+		clk_disable_unprepare(bs->clk);
+		return ret;
+	}
 
 	return 0;
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 066/556] spi: Fix DMA mapping ownership on partial map failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (64 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 065/556] spi: bcmbca-hsspi: disable clocks " Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 067/556] scsi: target: iscsi: Reserve a terminator byte for the login payload Greg Kroah-Hartman
                   ` (502 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Honghui Jiang, Andy Shevchenko,
	Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Honghui Jiang <jiang_hh2019@163.com>

commit 367cea239fc93094e5c16a72724800e0358f5c46 upstream.

If RX mapping fails after TX mapping succeeds, __spi_map_msg() unmaps
TX but leaves tx_sg_mapped set. If TX mapping fails on a later
transfer, mappings created for earlier transfers remain active.

In both cases, cur_{tx,rx}_dma_dev have not yet been updated because they
are assigned only after every transfer has been mapped. The subsequent
spi_unmap_msg() may therefore unmap the TX mapping again or release
earlier mappings using a NULL or stale device. Using a NULL device can
trigger an oops. An empty SG table does not prevent the NULL dereference
because dma_unmap_sg_attrs() accesses the device before checking the
entry count.

Publish both mapping devices before mapping starts and unwind all
failures through __spi_unmap_msg(). This clears the mapping flags and
releases each mapping once with the device that created it.

Publishing the devices before the loop also refreshes them when no
transfer needs mapping. No mapping flag is set in that case, so current
users do not use the pointers as mapping owners.

Fixes: e289df82344f ("spi: Rework per message DMA mapped flag to be per transfer")
Cc: stable@vger.kernel.org
Signed-off-by: Honghui Jiang <jiang_hh2019@163.com>
Reviewed-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
Link: https://patch.msgid.link/20260814031419.43378-2-jiang_hh2019@163.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/spi/spi.c |   34 ++++++++++++++++++----------------
 1 file changed, 18 insertions(+), 16 deletions(-)

--- a/drivers/spi/spi.c
+++ b/drivers/spi/spi.c
@@ -1231,6 +1231,8 @@ void spi_unmap_buf(struct spi_controller
 	spi_unmap_buf_attrs(ctlr, dev, sgt, dir, 0);
 }
 
+static int __spi_unmap_msg(struct spi_controller *ctlr, struct spi_message *msg);
+
 static int __spi_map_msg(struct spi_controller *ctlr, struct spi_message *msg)
 {
 	struct device *tx_dev, *rx_dev;
@@ -1254,7 +1256,13 @@ static int __spi_map_msg(struct spi_cont
 	else
 		rx_dev = ctlr->dev.parent;
 
-	ret = -ENOMSG;
+	/*
+	 * Store the devices before mapping so partial failures can be unwound
+	 * with the device that created each mapping.
+	 */
+	ctlr->cur_tx_dma_dev = tx_dev;
+	ctlr->cur_rx_dma_dev = rx_dev;
+
 	list_for_each_entry(xfer, &msg->transfers, transfer_list) {
 		/* The sync is done before each transfer. */
 		unsigned long attrs = DMA_ATTR_SKIP_CPU_SYNC;
@@ -1267,8 +1275,8 @@ static int __spi_map_msg(struct spi_cont
 						(void *)xfer->tx_buf,
 						xfer->len, DMA_TO_DEVICE,
 						attrs);
-			if (ret != 0)
-				return ret;
+			if (ret)
+				goto unwind;
 
 			xfer->tx_sg_mapped = true;
 		}
@@ -1277,25 +1285,19 @@ static int __spi_map_msg(struct spi_cont
 			ret = spi_map_buf_attrs(ctlr, rx_dev, &xfer->rx_sg,
 						xfer->rx_buf, xfer->len,
 						DMA_FROM_DEVICE, attrs);
-			if (ret != 0) {
-				spi_unmap_buf_attrs(ctlr, tx_dev,
-						&xfer->tx_sg, DMA_TO_DEVICE,
-						attrs);
-
-				return ret;
-			}
+			if (ret)
+				goto unwind;
 
 			xfer->rx_sg_mapped = true;
 		}
 	}
-	/* No transfer has been mapped, bail out with success */
-	if (ret)
-		return 0;
-
-	ctlr->cur_rx_dma_dev = rx_dev;
-	ctlr->cur_tx_dma_dev = tx_dev;
 
 	return 0;
+
+unwind:
+	__spi_unmap_msg(ctlr, msg);
+
+	return ret;
 }
 
 static int __spi_unmap_msg(struct spi_controller *ctlr, struct spi_message *msg)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 067/556] scsi: target: iscsi: Reserve a terminator byte for the login payload
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (65 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 066/556] spi: Fix DMA mapping ownership on partial map failure Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 068/556] scsi: bsg: Cap io_uring sense copy to max_response_len Greg Kroah-Hartman
                   ` (501 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sujal Tuladhar,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sujal Tuladhar <sujaltuladhar1231@gmail.com>

commit f4825922d2fb371e2b969697d792077f1b62b62c upstream.

iscsi_target_check_login_request() rejects a login PDU whose
DataSegmentLength exceeds MAX_KEY_VALUE_PAIRS, but the test is '>' and
login->req_buf is allocated with exactly MAX_KEY_VALUE_PAIRS
bytes. Since iscsit_get_login_rx() receives payload_length + padding
bytes, where

	padding = ((-payload_length) & 3);

any payload_length from 8189 to 8192 fills the whole 8192 byte
buffer. The write stays in bounds, but no byte is left for a NUL
terminator.

The buffer is subsequently consumed as a C string. In the CHAP path
chap_check_algorithm() calls kstrdup(a_str), and extract_param() calls
strstr(in_buf, pattern) followed by strlen_semi(), none of which take a
length. convert_null_to_semi() additionally rewrites every embedded NUL
to ';', so even a payload made of well formed NUL separated key=value
records is left without a terminator. These walk past the end of the
object into adjacent slab memory. It is reachable by an unauthenticated
initiator against a portal configured for CHAP; when authentication is
not required iscsi_login_zero_tsih_s2() rewrites AuthMethod to None and
the CHAP path is never entered.

Allocate one extra byte. kzalloc() zeroes it and nothing ever writes to
it, as every writer copies to offset 0 for at most MAX_KEY_VALUE_PAIRS
bytes, so the buffer is always terminated.

Fixes: e48354ce078c ("iscsi-target: Add iSCSI fabric support for target v4.1")
Assisted-by: Claude Opus5 (custom harness)
Cc: stable@vger.kernel.org
Signed-off-by: Sujal Tuladhar <sujaltuladhar1231@gmail.com>
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/target/iscsi/iscsi_target_login.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/target/iscsi/iscsi_target_login.c
+++ b/drivers/target/iscsi/iscsi_target_login.c
@@ -47,7 +47,7 @@ static struct iscsi_login *iscsi_login_i
 	login->conn = conn;
 	login->first_request = 1;
 
-	login->req_buf = kzalloc(MAX_KEY_VALUE_PAIRS, GFP_KERNEL);
+	login->req_buf = kzalloc(MAX_KEY_VALUE_PAIRS + 1, GFP_KERNEL);
 	if (!login->req_buf) {
 		pr_err("Unable to allocate memory for response buffer.\n");
 		goto out_login;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 068/556] scsi: bsg: Cap io_uring sense copy to max_response_len
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (66 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 067/556] scsi: target: iscsi: Reserve a terminator byte for the login payload Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 069/556] scsi: bsg: Fix TOCTOU in io_uring passthrough command setup Greg Kroah-Hartman
                   ` (500 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yang Xiuwei,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yang Xiuwei <yangxiuwei@kylinos.cn>

commit ece06de726737e887dc0225c8283477624f8ae21 upstream.

Completion copied scmd->sense_len to the user response buffer without
honoring max_response_len. After a valid sense, the midlayer sets
sense_len to the real length (up to SCSI_SENSE_BUFFERSIZE), so a smaller
user buffer was overrun.

Fixes: 7b6d3255e7f8 ("scsi: bsg: add io_uring passthrough handler")
Cc: stable@vger.kernel.org
Signed-off-by: Yang Xiuwei <yangxiuwei@kylinos.cn>
Link: https://patch.msgid.link/20260817080730.967879-2-yangxiuwei@kylinos.cn
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/scsi_bsg.c |    8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

--- a/drivers/scsi/scsi_bsg.c
+++ b/drivers/scsi/scsi_bsg.c
@@ -18,6 +18,7 @@ struct scsi_bsg_uring_cmd_pdu {
 	struct bio *bio;		/* mapped user buffer, unmap in task work */
 	struct request *req;		/* block request, freed in task work */
 	u64 response_addr;		/* user space response buffer address */
+	u32 max_response_len;		/* user response buffer size */
 };
 static_assert(sizeof(struct scsi_bsg_uring_cmd_pdu) <= sizeof_field(struct io_uring_cmd, pdu));
 
@@ -45,8 +46,8 @@ static void scsi_bsg_uring_task_cb(struc
 	if (scsi_status_is_check_condition(scmd->result)) {
 		driver_status = DRIVER_SENSE;
 		if (pdu->response_addr)
-			sense_len_wr = min_t(u8, scmd->sense_len,
-					     SCSI_SENSE_BUFFERSIZE);
+			sense_len_wr = min_t(unsigned int, pdu->max_response_len,
+					     scmd->sense_len);
 	}
 
 	if (sense_len_wr) {
@@ -155,8 +156,7 @@ static int scsi_bsg_uring_cmd(struct req
 	}
 
 	pdu->response_addr = cmd->response;
-	scmd->sense_len = cmd->max_response_len ?
-		min(cmd->max_response_len, SCSI_SENSE_BUFFERSIZE) : SCSI_SENSE_BUFFERSIZE;
+	pdu->max_response_len = cmd->max_response_len;
 
 	if (cmd->dout_xfer_len || cmd->din_xfer_len) {
 		ret = scsi_bsg_map_user_buffer(req, ioucmd, issue_flags, gfp_mask);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 069/556] scsi: bsg: Fix TOCTOU in io_uring passthrough command setup
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (67 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 068/556] scsi: bsg: Cap io_uring sense copy to max_response_len Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 070/556] scsi: megaraid_sas: Limit NVMe request size to the PRP chain frame Greg Kroah-Hartman
                   ` (499 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Rahul Chandelkar, Yang Xiuwei,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Rahul Chandelkar <rc@rexion.ai>

commit 4b3c5965fca99f62d31c963294bd5b23cc488e97 upstream.

scsi_bsg_uring_cmd() reads bsg_uring_cmd from the shared mmap'd SQE.
Userspace can change a field after we check it and before we use it.
request_len is the sharp case: it can grow past sizeof(scmd->cmnd) after
the bound check and overflow scmd->cmnd in copy_from_user().

READ_ONCE() the SQE fields we check or use into locals before use.

Fixes: 7b6d3255e7f8 ("scsi: bsg: add io_uring passthrough handler")
Cc: stable@vger.kernel.org
Link: https://lore.kernel.org/r/20260527105931.3950913-1-rc@rexion.ai
Signed-off-by: Rahul Chandelkar <rc@rexion.ai>
Co-developed-by: Yang Xiuwei <yangxiuwei@kylinos.cn>
Signed-off-by: Yang Xiuwei <yangxiuwei@kylinos.cn>
Link: https://patch.msgid.link/20260817080730.967879-3-yangxiuwei@kylinos.cn
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/scsi_bsg.c | 39 +++++++++++++++++++++++++--------------
 1 file changed, 25 insertions(+), 14 deletions(-)

diff --git a/drivers/scsi/scsi_bsg.c b/drivers/scsi/scsi_bsg.c
index b3c4b1063d6f..5eec248a77a6 100644
--- a/drivers/scsi/scsi_bsg.c
+++ b/drivers/scsi/scsi_bsg.c
@@ -77,12 +77,10 @@ static enum rq_end_io_ret scsi_bsg_uring_cmd_done(struct request *req,
 
 static int scsi_bsg_map_user_buffer(struct request *req,
 				    struct io_uring_cmd *ioucmd,
-				    unsigned int issue_flags, gfp_t gfp_mask)
+				    unsigned int issue_flags, gfp_t gfp_mask,
+				    bool is_write, u64 buf_addr,
+				    unsigned long buf_len)
 {
-	const struct bsg_uring_cmd *cmd = io_uring_sqe128_cmd(ioucmd->sqe, struct bsg_uring_cmd);
-	bool is_write = cmd->dout_xfer_len > 0;
-	u64 buf_addr = is_write ? cmd->dout_xferp : cmd->din_xferp;
-	unsigned long buf_len = is_write ? cmd->dout_xfer_len : cmd->din_xfer_len;
 	struct iov_iter iter;
 	int ret;
 
@@ -105,21 +103,28 @@ static int scsi_bsg_uring_cmd(struct request_queue *q, struct io_uring_cmd *iouc
 			       unsigned int issue_flags, bool open_for_write)
 {
 	struct scsi_bsg_uring_cmd_pdu *pdu = scsi_bsg_uring_cmd_pdu(ioucmd);
-	const struct bsg_uring_cmd *cmd = io_uring_sqe128_cmd(ioucmd->sqe, struct bsg_uring_cmd);
+	const struct bsg_uring_cmd *cmd =
+		io_uring_sqe128_cmd(ioucmd->sqe, struct bsg_uring_cmd);
 	struct scsi_cmnd *scmd;
 	struct request *req;
 	blk_mq_req_flags_t blk_flags = 0;
 	gfp_t gfp_mask = GFP_KERNEL;
+	u64 request = READ_ONCE(cmd->request);
+	u32 request_len = READ_ONCE(cmd->request_len);
+	u64 dout_xferp = READ_ONCE(cmd->dout_xferp);
+	u32 dout_xfer_len = READ_ONCE(cmd->dout_xfer_len);
+	u64 din_xferp = READ_ONCE(cmd->din_xferp);
+	u32 din_xfer_len = READ_ONCE(cmd->din_xfer_len);
 	int ret;
 
 	if (cmd->protocol != BSG_PROTOCOL_SCSI ||
 	    cmd->subprotocol != BSG_SUB_PROTOCOL_SCSI_CMD)
 		return -EINVAL;
 
-	if (!cmd->request || cmd->request_len == 0)
+	if (!request || request_len == 0)
 		return -EINVAL;
 
-	if (cmd->dout_xfer_len && cmd->din_xfer_len) {
+	if (dout_xfer_len && din_xfer_len) {
 		pr_warn_once("BIDI support in bsg has been removed.\n");
 		return -EOPNOTSUPP;
 	}
@@ -132,20 +137,20 @@ static int scsi_bsg_uring_cmd(struct request_queue *q, struct io_uring_cmd *iouc
 		gfp_mask = GFP_NOWAIT;
 	}
 
-	req = scsi_alloc_request(q, cmd->dout_xfer_len ?
+	req = scsi_alloc_request(q, dout_xfer_len ?
 				 REQ_OP_DRV_OUT : REQ_OP_DRV_IN, blk_flags);
 	if (IS_ERR(req))
 		return PTR_ERR(req);
 
 	scmd = blk_mq_rq_to_pdu(req);
-	if (cmd->request_len > sizeof(scmd->cmnd)) {
+	if (request_len > sizeof(scmd->cmnd)) {
 		ret = -EINVAL;
 		goto out_free_req;
 	}
-	scmd->cmd_len = cmd->request_len;
+	scmd->cmd_len = request_len;
 	scmd->allowed = SG_DEFAULT_RETRIES;
 
-	if (copy_from_user(scmd->cmnd, uptr64(cmd->request), cmd->request_len)) {
+	if (copy_from_user(scmd->cmnd, uptr64(request), request_len)) {
 		ret = -EFAULT;
 		goto out_free_req;
 	}
@@ -158,8 +163,14 @@ static int scsi_bsg_uring_cmd(struct request_queue *q, struct io_uring_cmd *iouc
 	pdu->response_addr = cmd->response;
 	pdu->max_response_len = cmd->max_response_len;
 
-	if (cmd->dout_xfer_len || cmd->din_xfer_len) {
-		ret = scsi_bsg_map_user_buffer(req, ioucmd, issue_flags, gfp_mask);
+	if (dout_xfer_len || din_xfer_len) {
+		bool is_write = dout_xfer_len > 0;
+		u64 buf_addr = is_write ? dout_xferp : din_xferp;
+		unsigned long buf_len = is_write ? dout_xfer_len : din_xfer_len;
+
+		ret = scsi_bsg_map_user_buffer(req, ioucmd, issue_flags,
+					       gfp_mask, is_write, buf_addr,
+					       buf_len);
 		if (ret)
 			goto out_free_req;
 		pdu->bio = req->bio;
-- 
2.55.0




^ permalink raw reply related	[flat|nested] 570+ messages in thread

* [PATCH 7.2 070/556] scsi: megaraid_sas: Limit NVMe request size to the PRP chain frame
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (68 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 069/556] scsi: bsg: Fix TOCTOU in io_uring passthrough command setup Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 071/556] scsi: pm8001: Use rollback index when freeing MSI-X vectors Greg Kroah-Hartman
                   ` (498 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Lukasz Magiera, Mira Limbeck,
	Martin K. Petersen, Thomas Lamprecht, Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Thomas Lamprecht <t.lamprecht@proxmox.com>

commit af8c27375733fb6a6df9fa484cda77cc3dd0cb80 upstream.

megasas_make_prp_nvme() builds a command's PRP list in cmd->sg_frame, a
DMA pool buffer of instance->max_chain_frame_sz bytes, spending one
entry per NVMe page of the transfer plus one per page of the buffer for
the chain pointer. The loop runs until the transfer is described and
never checks the buffer bound.

max_hw_sectors comes straight from the MDTS the firmware reports for the
drive. On drives with a large MDTS the only thing keeping the list
inside the buffer was the block layer default of 1280 KiB, which needs
320 entries, which fit into a 4 KiB frame as that holds 512. But since
commit 9b8b84879d4a ("block: Increase BLK_DEF_MAX_SECTORS_CAP") that
default is 4 MiB, and such a transfer needs 1025 entries, so the list
runs a full page past the end of the frame:

  sd 1:0:1:0: [sdb] tag#630 page boundary ptr_sgl: 0x00000000ba62d13f
  BUG: unable to handle page fault for address: ff663bcb81e7c000
  #PF: supervisor write access in kernel mode
  #PF: error_code(0x0002) - not-present page
  RIP: 0010:megasas_build_and_issue_cmd_fusion+0xeaa/0x1870 [megaraid_sas]

If the page after the frame happens to be mapped, the overrun does not
fault but silently corrupts the neighbouring pool entry, which is
another in-flight command's PRP list.

Cap max_hw_sectors at what the chain frame can describe, less one page
for transfers that do not start on a page boundary and so need one entry
more. This is the megaraid_sas counterpart of commit 04631f55afc5
("scsi: mpt3sas: Limit NVMe request size to 2 MiB"), but derives the
limit from max_chain_frame_sz rather than hardcoding it.

Cc: stable@vger.kernel.org
Fixes: 9b8b84879d4a ("block: Increase BLK_DEF_MAX_SECTORS_CAP")
Reported-by: Lukasz Magiera <me@magik.net>
Closes: https://lore.kernel.org/all/GPhsSM0vkgyIrs0DIZ62qeUZX7X4RxwQXVKiuvMx-lHQVSPDxpztUyQOGS0xikqvJ-Z94hMV-dW_5KN_0CX2hsfV7kTf_t0MTf6vdAAaSEc=@magik.net/
Reported-by: Mira Limbeck <m.limbeck@proxmox.com>
Closes: https://lore.kernel.org/all/d171cc76-bf25-48ce-b482-d344669dfc24@proxmox.com/
Suggested-by: Martin K. Petersen <martin.petersen@oracle.com>
Link: https://lore.kernel.org/all/yq17bmzd5jr.fsf@ca-mkp.ca.oracle.com/
Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
Closes: https://lore.kernel.org/linux-scsi/20260827182106.535D61F000E9@smtp.kernel.org
Link: https://patch.msgid.link/20260827175743.734593-1-t.lamprecht@proxmox.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/megaraid/megaraid_sas_base.c |   13 ++++++++++++-
 1 file changed, 12 insertions(+), 1 deletion(-)

--- a/drivers/scsi/megaraid/megaraid_sas_base.c
+++ b/drivers/scsi/megaraid/megaraid_sas_base.c
@@ -1973,12 +1973,23 @@ megasas_set_nvme_device_properties(struc
 {
 	struct megasas_instance *instance;
 	u32 mr_nvme_pg_size;
+	u64 max_prp_io;
 
 	instance = (struct megasas_instance *)sdev->host->hostdata;
 	mr_nvme_pg_size = max_t(u32, instance->nvme_page_size,
 				MR_DEFAULT_NVME_PAGE_SIZE);
 
-	lim->max_hw_sectors = max_io_size / 512;
+	/*
+	 * megasas_make_prp_nvme() builds the PRP list in cmd->sg_frame without
+	 * bounding it against that buffer, and spends one entry per page of
+	 * it on the chain pointer. Cap the transfer at what the buffer holds,
+	 * less one page for lists that start off a page boundary.
+	 */
+	max_prp_io = (u64)((instance->max_chain_frame_sz / sizeof(u64)) -
+			   (instance->max_chain_frame_sz / mr_nvme_pg_size) - 1) *
+		     mr_nvme_pg_size;
+
+	lim->max_hw_sectors = min_t(u64, max_io_size, max_prp_io) >> SECTOR_SHIFT;
 	lim->virt_boundary_mask = mr_nvme_pg_size - 1;
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 071/556] scsi: pm8001: Use rollback index when freeing MSI-X vectors
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (69 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 070/556] scsi: megaraid_sas: Limit NVMe request size to the PRP chain frame Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 072/556] Docs/ABI/damon: fix typo in intervals_goal sysfs path Greg Kroah-Hartman
                   ` (497 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Runyu Xiao, Jack Wang,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Runyu Xiao <runyu.xiao@seu.edu.cn>

commit 3f92a64545165bdbb36dee8fa35626b295463313 upstream.

pm8001_request_msix() unwinds previously registered handlers with
free_irq() when request_irq() fails. The rollback loop uses the failing
index i for every iteration instead of the already registered vector
index j.

That passes the wrong IRQ/dev_id pair to free_irq() and leaves the
earlier handlers installed. Use j for both pci_irq_vector() and the
matching irq_vector entry in the rollback loop.

Fixes: a76037ff3479 ("scsi: pm8001: switch to pci_irq_alloc_vectors")
Cc: stable@vger.kernel.org
Assisted-by: Codex:GPT-5
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Acked-by: Jack Wang <jinpu.wang@cloud.ionos.com>
Link: https://patch.msgid.link/20260824113618.2239100-1-runyu.xiao@seu.edu.cn
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/pm8001/pm8001_init.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/drivers/scsi/pm8001/pm8001_init.c
+++ b/drivers/scsi/pm8001/pm8001_init.c
@@ -1029,8 +1029,8 @@ static u32 pm8001_request_msix(struct pm
 			&(pm8001_ha->irq_vector[i]));
 		if (rc) {
 			for (j = 0; j < i; j++) {
-				free_irq(pci_irq_vector(pm8001_ha->pdev, i),
-					&(pm8001_ha->irq_vector[i]));
+				free_irq(pci_irq_vector(pm8001_ha->pdev, j),
+					 &pm8001_ha->irq_vector[j]);
 			}
 			pci_free_irq_vectors(pm8001_ha->pdev);
 			break;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 072/556] Docs/ABI/damon: fix typo in intervals_goal sysfs path
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (70 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 071/556] scsi: pm8001: Use rollback index when freeing MSI-X vectors Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 073/556] mm/damon/sysfs: read addr_unit only once in damon_sysfs_apply_inputs() Greg Kroah-Hartman
                   ` (496 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Song Hu, SJ Park, David Hildenbrand,
	Liam R. Howlett, Lorenzo Stoakes, Michal Hocko, Mike Rapoport,
	Suren Baghdasaryan, Vlastimil Babka, Jonathan Corbet,
	Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Song Hu <husong@kylinos.cn>

commit 1b492fc82368399123413c937f13da6ed312ee4d upstream.

Patch series "Docs/ABI/damon: sysfs ABI document fixes and additions", v2.

This series fixes typos and fills in missing entries in the DAMON sysfs
ABI document (Documentation/ABI/testing/sysfs-kernel-mm-damon).

Patch 1 fixes a path typo, "intrvals_goal" -> "intervals_goal", in four
What: entries; the documented path points to a non-existent directory, so
it is Cc'ed to stable.

Patch 2 fixes two further typos ("WDate:", "manimum").

Patches 3 and 4 add ABI entries that exist in the kernel and are already
described in usage.rst but are missing from the canonical ABI document:
the 'update_tuned_intervals' state command (patch 3) and the
'tried_regions/<R>/probes/<P>/hits' file (patch 4).


This patch (of 4):

The ABI document spells the DAMON sysfs directory as "intrvals_goal"
(missing 'e') in four What: entries, but the kernel creates it as
"intervals_goal" (mm/damon/sysfs.c).  Following the documented path
therefore yields a non-existent directory.

Link: https://lore.kernel.org/20260714140117.94147-1-sj@kernel.org
Link: https://lore.kernel.org/20260714140117.94147-2-sj@kernel.org
Fixes: e2b23dc62369 ("Docs/ABI/damon: document intervals auto-tuning ABI")
Signed-off-by: Song Hu <husong@kylinos.cn>
Reviewed-by: SJ Park <sj@kernel.org>
Signed-off-by: SJ Park <sj@kernel.org>
Cc: David Hildenbrand <david@kernel.org>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Lorenzo Stoakes <ljs@kernel.org>
Cc: Michal Hocko <mhocko@suse.com>
Cc: Mike Rapoport <rppt@kernel.org>
Cc: Suren Baghdasaryan <surenb@google.com>
Cc: Vlastimil Babka <vbabka@kernel.org>
Cc: Jonathan Corbet <corbet@lwn.net>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 Documentation/ABI/testing/sysfs-kernel-mm-damon |    8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

--- a/Documentation/ABI/testing/sysfs-kernel-mm-damon
+++ b/Documentation/ABI/testing/sysfs-kernel-mm-damon
@@ -112,7 +112,7 @@ Description:	Writing a value to this fil
 		DAMON context in microseconds as the value.  Reading this file
 		returns the value.
 
-What:		/sys/kernel/mm/damon/admin/kdamonds/<K>/contexts/<C>/monitoring_attrs/intervals/intrvals_goal/access_bp
+What:		/sys/kernel/mm/damon/admin/kdamonds/<K>/contexts/<C>/monitoring_attrs/intervals/intervals_goal/access_bp
 Date:		Feb 2025
 Contact:	SJ Park <sj@kernel.org>
 Description:	Writing a value to this file sets the monitoring intervals
@@ -120,7 +120,7 @@ Description:	Writing a value to this fil
 		the given time interval (aggrs in same directory), in bp
 		(1/10,000).  Reading this file returns the value.
 
-What:		/sys/kernel/mm/damon/admin/kdamonds/<K>/contexts/<C>/monitoring_attrs/intervals/intrvals_goal/aggrs
+What:		/sys/kernel/mm/damon/admin/kdamonds/<K>/contexts/<C>/monitoring_attrs/intervals/intervals_goal/aggrs
 Date:		Feb 2025
 Contact:	SJ Park <sj@kernel.org>
 Description:	Writing a value to this file sets the time interval to achieve
@@ -128,14 +128,14 @@ Description:	Writing a value to this fil
 		access events ratio (access_bp in same directory) within.
 		Reading this file returns the value.
 
-What:		/sys/kernel/mm/damon/admin/kdamonds/<K>/contexts/<C>/monitoring_attrs/intervals/intrvals_goal/min_sample_us
+What:		/sys/kernel/mm/damon/admin/kdamonds/<K>/contexts/<C>/monitoring_attrs/intervals/intervals_goal/min_sample_us
 Date:		Feb 2025
 Contact:	SJ Park <sj@kernel.org>
 Description:	Writing a value to this file sets the minimum value of
 		auto-tuned sampling interval in microseconds.  Reading this
 		file returns the value.
 
-What:		/sys/kernel/mm/damon/admin/kdamonds/<K>/contexts/<C>/monitoring_attrs/intervals/intrvals_goal/max_sample_us
+What:		/sys/kernel/mm/damon/admin/kdamonds/<K>/contexts/<C>/monitoring_attrs/intervals/intervals_goal/max_sample_us
 Date:		Feb 2025
 Contact:	SJ Park <sj@kernel.org>
 Description:	Writing a value to this file sets the maximum value of



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 073/556] mm/damon/sysfs: read addr_unit only once in damon_sysfs_apply_inputs()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (71 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 072/556] Docs/ABI/damon: fix typo in intervals_goal sysfs path Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 074/556] mm/damon/sysfs: read ops_id " Greg Kroah-Hartman
                   ` (495 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit ab4d9358e32316fa39b5f1f5360292135978c3d9 upstream.

damon_sysfs_apply_inputs() reads addr_unit twice.  It could race with
addr_unit_store().  As a result, the min_region_sz could wrongly be set
up.  Read it once.

The user impact is trivial.  Sane users ain't update the parameter in
parallel.  Even if it happens, the DAMON core layer handles the wrong
min_region_sz (!is_power_of_2()).  Even if somehow the race ended up
making a min_region_sz that is different from the user's intention but
still valid, only monitoring itself runs differently than expected.  No
critical consequences like kernel panic or memory corruption happen.

The issue was discovered [1] by Sashiko.

Link: https://lore.kernel.org/20260715031002.108504-6-sj@kernel.org
Link: https://lore.kernel.org/20260714142950.100711-1-sj@kernel.org [1]
Fixes: 540a2aebc657 ("mm/damon/sysfs: implement addr_unit file under context dir")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: <stable@vger.kernel.org> # 6.18.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/damon/sysfs.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/mm/damon/sysfs.c
+++ b/mm/damon/sysfs.c
@@ -2047,11 +2047,11 @@ static int damon_sysfs_apply_inputs(stru
 	err = damon_select_ops(ctx, sys_ctx->ops_id);
 	if (err)
 		return err;
-	ctx->addr_unit = sys_ctx->addr_unit;
+	ctx->addr_unit = READ_ONCE(sys_ctx->addr_unit);
 	/* addr_unit is respected by only DAMON_OPS_PADDR */
 	if (sys_ctx->ops_id == DAMON_OPS_PADDR)
 		ctx->min_region_sz = max(
-				DAMON_MIN_REGION_SZ / sys_ctx->addr_unit, 1);
+				DAMON_MIN_REGION_SZ / ctx->addr_unit, 1);
 	ctx->pause = sys_ctx->pause;
 	err = damon_sysfs_set_attrs(ctx, sys_ctx->attrs);
 	if (err)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 074/556] mm/damon/sysfs: read ops_id only once in damon_sysfs_apply_inputs()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (72 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 073/556] mm/damon/sysfs: read addr_unit only once in damon_sysfs_apply_inputs() Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 075/556] mm/damon/tests/core-kunit: catch test failure in test_merge_regions_of() Greg Kroah-Hartman
                   ` (494 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit 5adaaa28be8a79ddd7e103b171f9d6e14e7fc26e upstream.

damon_sysfs_apply_inputs() reads ops_id twice.  It could race with
ops_id_store().  As a result, the min_region_sz could wrongly be set up.
Read it once.

The user impact is trivial.  Sane users ain't update the parameter in
parallel.  Even if it happens, the DAMON core layer handles the wrong
min_region_sz (!is_power_of_2()).  Even if somehow the race ended up
making a min_region_sz that is different from the user's intention but
still valid, only monitoring itself runs differently than expected.  No
critical consequences like kernel panic or memory corruption happen

The issue was discovered [1] by Sashiko.

Link: https://lore.kernel.org/20260715031002.108504-7-sj@kernel.org
Link: https://lore.kernel.org/20260703172417.95426-1-sj@kernel.org [1]
Fixes: 8d009da32f13 ("mm/damon/sysfs: set damon_ctx->min_sz_region only for paddr use case")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: <stable@vger.kernel.org> # 6.18.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/damon/sysfs.c |    6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

--- a/mm/damon/sysfs.c
+++ b/mm/damon/sysfs.c
@@ -2042,14 +2042,16 @@ static inline bool damon_sysfs_kdamond_r
 static int damon_sysfs_apply_inputs(struct damon_ctx *ctx,
 		struct damon_sysfs_context *sys_ctx)
 {
+	enum damon_ops_id ops_id;
 	int err;
 
-	err = damon_select_ops(ctx, sys_ctx->ops_id);
+	ops_id = READ_ONCE(sys_ctx->ops_id);
+	err = damon_select_ops(ctx, ops_id);
 	if (err)
 		return err;
 	ctx->addr_unit = READ_ONCE(sys_ctx->addr_unit);
 	/* addr_unit is respected by only DAMON_OPS_PADDR */
-	if (sys_ctx->ops_id == DAMON_OPS_PADDR)
+	if (ops_id == DAMON_OPS_PADDR)
 		ctx->min_region_sz = max(
 				DAMON_MIN_REGION_SZ / ctx->addr_unit, 1);
 	ctx->pause = sys_ctx->pause;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 075/556] mm/damon/tests/core-kunit: catch test failure in test_merge_regions_of()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (73 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 074/556] mm/damon/sysfs: read ops_id " Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 076/556] mm/damon/vaddr-kunit: check region count in three_regions test Greg Kroah-Hartman
                   ` (493 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit b640708929aa956235866bf7717d89018c661083 upstream.

KUNIT_EXPECT_EQ() does not abort the execution of test code when the
expectation is not met.  But damon_test_merge_regions_of() code after its
initial KUNIT_EXPECT_EQ() call assumes the expectation is met.  It does a
per-region test with a hard-coded number of regions that is correct only
if the expectation was met.  As a result, __nth_region_of() could return
NULL, and the test code can dereference NULL pointers.  Fix the issue by
catching the expectation failure and skip the per-region tests.

The user impact on realistic setups should be negligible, as it is a unit
test.

The issue was discovered [1] by Sashiko.

Link: https://lore.kernel.org/20260715031002.108504-3-sj@kernel.org
Link: https://lore.kernel.org/20260710144937.26981-1-sj@kernel.org [1]
Fixes: 17ccae8bb5c9 ("mm/damon: add kunit tests")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: <stable@vger.kernel.org> # 5.15.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/damon/tests/core-kunit.h |    3 +++
 1 file changed, 3 insertions(+)

--- a/mm/damon/tests/core-kunit.h
+++ b/mm/damon/tests/core-kunit.h
@@ -259,11 +259,14 @@ static void damon_test_merge_regions_of(
 	damon_merge_regions_of(t, 9, 9999);
 	/* 0-112, 114-130, 130-156, 156-170, 170-230, 230-10170 */
 	KUNIT_EXPECT_EQ(test, damon_nr_regions(t), 6u);
+	if (damon_nr_regions(t) != 6)
+		goto out;
 	for (i = 0; i < 6; i++) {
 		r = __nth_region_of(t, i);
 		KUNIT_EXPECT_EQ(test, r->ar.start, saddrs[i]);
 		KUNIT_EXPECT_EQ(test, r->ar.end, eaddrs[i]);
 	}
+out:
 	damon_free_target(t);
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 076/556] mm/damon/vaddr-kunit: check region count in three_regions test
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (74 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 075/556] mm/damon/tests/core-kunit: catch test failure in test_merge_regions_of() Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 077/556] samples/damon/mtier: handle damon_start() failure Greg Kroah-Hartman
                   ` (492 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Brendan Higgins,
	Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit 5fea07e460874c8c7cf00f728efbe22abc62c8d8 upstream.

damon_do_test_apply_three_regions() iterates regions after
damon_set_regions() call assuming the function would succeed at setting
the number of regions the same to the expected one.  It might have failed.
In this case, __nth_region_of() in the iteration could return NULL and
NULL dereference can happen in the test.

The consequent user impact (NULL dereference) is quite bad.  The realistic
user impact would be limited, though.  It would affect only test run
setups.

Fix it by testing if the number of regions was also changed as expected
and exit early for the failure.

The issue was discovered [1] by Sashiko.

Link: https://lore.kernel.org/20260718001442.87129-4-sj@kernel.org
Link: https://lore.kernel.org/20260713144757.39740-1-sj@kernel.org [1]
Fixes: 17ccae8bb5c9 ("mm/damon: add kunit tests")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: Brendan Higgins <brendan.higgins@linux.dev>
Cc: <stable@vger.kernel.org> # 5.15.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/damon/tests/vaddr-kunit.h |    5 +++++
 1 file changed, 5 insertions(+)

--- a/mm/damon/tests/vaddr-kunit.h
+++ b/mm/damon/tests/vaddr-kunit.h
@@ -158,12 +158,17 @@ static void damon_do_test_apply_three_re
 		kunit_skip(test, "second damon_set_regions() fail");
 	}
 
+	KUNIT_EXPECT_EQ(test, damon_nr_regions(t), nr_expected / 2);
+	if (damon_nr_regions(t) != nr_expected / 2)
+		goto out;
+
 	for (i = 0; i < nr_expected / 2; i++) {
 		r = __nth_region_of(t, i);
 		KUNIT_EXPECT_EQ(test, r->ar.start, expected[i * 2]);
 		KUNIT_EXPECT_EQ(test, r->ar.end, expected[i * 2 + 1]);
 	}
 
+out:
 	damon_destroy_target(t, NULL);
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 077/556] samples/damon/mtier: handle damon_start() failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (75 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 076/556] mm/damon/vaddr-kunit: check region count in three_regions test Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 078/556] samples/damon/mtier: handle damon_stop() failure Greg Kroah-Hartman
                   ` (491 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Zenghui Yu, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit c7230d08ee79b13127bd2b45a3648d361ac912fc upstream.

damon_sample_mtier_start() callers assume it will clean up resources when
it fails.  And the function does the cleanup for context buildup failures.
However, it is not doing the cleanup for damon_start() failure.

As a result, when damon_start() fails, it could leak the memory for DAMON
context.  Also, if damon_start() fails for only the second context, the
first context will indefinitely run, and avoid starting other DAMON
contexts since it is running in the exclusive mode.  Stop possibly started
DAMON context and free the contexts in case of the failure to fix the
issues.

Note that the issue can reliably be reproduced because the module calls
damon_start() in the exclusive mode.  For example,

    $ sudo damo start
    $ echo Y | sudo tee /sys/module/damon_sample_mtier/parameters/enabled
    $ sudo cat /proc/allocinfo | grep damon_new_ctx

Because the first command is running another DAMON instance, the second
command fails the damon_start() call because the new DAMON instance cannot
exclusively run.  And without this fix, by repeating the second and the
third commands above, we can show the memory consumption is only
increasing due to the leaks.  It requires the sudo permission though.

The issue was discovered [1] by Sashiko.

Link: https://lore.kernel.org/20260628215447.96166-4-sj@kernel.org
Link: https://lore.kernel.org/20260608112455.274231F00893@smtp.kernel.org [1]
Fixes: 82a08bde3cf7 ("samples/damon: implement a DAMON module for memory tiering")
Signed-off-by: SJ Park <sj@kernel.org>
Reviewed-by: Zenghui Yu <zenghui.yu@linux.dev>
Cc: <stable@vger.kernel.org> # 6.16.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 samples/damon/mtier.c |   11 ++++++++++-
 1 file changed, 10 insertions(+), 1 deletion(-)

--- a/samples/damon/mtier.c
+++ b/samples/damon/mtier.c
@@ -180,6 +180,7 @@ free_out:
 static int damon_sample_mtier_start(void)
 {
 	struct damon_ctx *ctx;
+	int err;
 
 	ctx = damon_sample_mtier_build_ctx(true);
 	if (!ctx)
@@ -191,7 +192,15 @@ static int damon_sample_mtier_start(void
 		return -ENOMEM;
 	}
 	ctxs[1] = ctx;
-	return damon_start(ctxs, 2, true);
+	err = damon_start(ctxs, 2, true);
+	if (!err)
+		return 0;
+
+	if (damon_is_running(ctxs[0]))
+		damon_stop(ctxs, 1);
+	damon_destroy_ctx(ctxs[0]);
+	damon_destroy_ctx(ctxs[1]);
+	return err;
 }
 
 static void damon_sample_mtier_stop(void)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 078/556] samples/damon/mtier: handle damon_stop() failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (76 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 077/556] samples/damon/mtier: handle damon_start() failure Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:35 ` [PATCH 7.2 079/556] samples/damon/prcl: handle damon_start() failure Greg Kroah-Hartman
                   ` (490 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Zenghui Yu, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit 9dc5b6d66fd51b103eff21ed0df3e292f489ebc0 upstream.

damon_sample_mtier_stop() assumes its damon_stop() call will always
successfully stops the two DAMON contexts.  Hence it deallocates the two
DAMON contexts after the damon_stop() call.  However, if a given context
is already stopped, damon_stop() fails and returns an error while letting
the DAMON contexts that have not yet stopped keep running.  This kind of
unexpected early DAMON context stops could happen due to memory allocation
failures in kdamond_fn().  Because damon_sample_mtier_stop() just
deallocates all DAMON contexts with damon_target and damon_region objects
that are linked to the contexts, the execution of the unstopped DAMON
context (kdamond) ends up using the memory that freed (use-after-free).
Fix the issue by separating the damon_stop() to be invoked per context.

Note that DAMON_SYSFS also allows multiple DAMON contexts execution.  But,
it calls damon_stop() for each context one by one.  Hence this issue is
only in mtier.

For the long term, it would be better to refactor damon_stop() to always
ensure stopping all contexts regardless of the failures in the middle.
Make this fix in the current way, though, to keep it simple and easy to
backport.  I will do the refactoring later.

The issue was discovered [1] by Sashiko.

Link: https://lore.kernel.org/20260628215447.96166-5-sj@kernel.org
Link: https://lore.kernel.org/20260609014219.3013-1-sj@kernel.org [1]
Fixes: 82a08bde3cf7 ("samples/damon: implement a DAMON module for memory tiering")
Signed-off-by: SJ Park <sj@kernel.org>
Reviewed-by: Zenghui Yu <zenghui.yu@linux.dev>
Cc: <stable@vger.kernel.org> # 6.16.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 samples/damon/mtier.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/samples/damon/mtier.c
+++ b/samples/damon/mtier.c
@@ -205,7 +205,8 @@ static int damon_sample_mtier_start(void
 
 static void damon_sample_mtier_stop(void)
 {
-	damon_stop(ctxs, 2);
+	damon_stop(ctxs, 1);
+	damon_stop(&ctxs[1], 1);
 	damon_destroy_ctx(ctxs[0]);
 	damon_destroy_ctx(ctxs[1]);
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 079/556] samples/damon/prcl: handle damon_start() failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (77 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 078/556] samples/damon/mtier: handle damon_stop() failure Greg Kroah-Hartman
@ 2026-09-09 13:35 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 080/556] samples/damon/prcl: stop and free damon ctx when damon_call() fails Greg Kroah-Hartman
                   ` (489 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:35 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Zenghui Yu, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit 8b724349229bb6ebbf781178be011ba9bc2cca57 upstream.

damon_sample_prcl_start() callers assume it will clean up resources when
it fails.  And the function does the cleanup for context buildup failures.
However, it is not doing the cleanup for damon_start() failure.  As a
result, when damon_start() fails, it leaks the memory for DAMON context.
Free the context in case of the failure to fix the issues.

Note that the issue can reliably be reproduced because the module calls
damon_start() in the exclusive mode.  For example,

    $ sudo damo start
    $ echo $$ | sudo tee /sys/module/damon_sample_prcl/parameters/target_pid
    $ echo Y | sudo tee /sys/module/damon_sample_prcl/parameters/enabled
    $ sudo cat /proc/allocinfo | grep damon_new_ctx

Because the first command is running another DAMON instance, the third
command fails the damon_start() call because the new DAMON instance cannot
exclusively run.  And without this fix, by repeating the third and the
fourth commands above, we can show the memory consumption is only
increasing due to the leaks.  It requires the sudo permission though.

The issue was discovered [1] by Sashiko.

Link: https://lore.kernel.org/20260628215447.96166-3-sj@kernel.org
Link: https://lore.kernel.org/20260609145814.70163-1-sj@kernel.org [1]
Fixes: 2aca254620a8 ("samples/damon: introduce a skeleton of a smaple DAMON module for proactive reclamation")
Signed-off-by: SJ Park <sj@kernel.org>
Reviewed-by: Zenghui Yu <zenghui.yu@linux.dev>
Cc: <stable@vger.kernel.org> # 6.14.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 samples/damon/prcl.c |    4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

--- a/samples/damon/prcl.c
+++ b/samples/damon/prcl.c
@@ -106,8 +106,10 @@ static int damon_sample_prcl_start(void)
 	damon_set_schemes(ctx, &scheme, 1);
 
 	err = damon_start(&ctx, 1, true);
-	if (err)
+	if (err) {
+		damon_destroy_ctx(ctx);
 		return err;
+	}
 
 	repeat_call_control.data = ctx;
 	return damon_call(ctx, &repeat_call_control);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 080/556] samples/damon/prcl: stop and free damon ctx when damon_call() fails
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (78 preceding siblings ...)
  2026-09-09 13:35 ` [PATCH 7.2 079/556] samples/damon/prcl: handle damon_start() failure Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 081/556] samples/damon/wsse: handle damon_start() failure Greg Kroah-Hartman
                   ` (488 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Zenghui Yu, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit a73fa45d3f0f42c446ae55c5799e3d5ef044cd5d upstream.

damon_sample_prcl_start() calls damon_call() right after damon_start() is
succeeded.  The kdamond that has started by the damon_start() could be
terminated by itself before or in the middle of the damon_call()
execution.  There could be multiple reasons for such a stop including
monitoring target process termination and kdamond_fn() internal memory
allocation failures.  In the case, damon_call() will fail and return an
error without cleaning up the DAMON context object.  The
damon_sample_prcl_start() caller assumes it would clean up the object,
though.  When the user requests to start DAMON again,
damon_sample_prcl_start() is called again, allocates a new DAMON context
object and overwrites the pointer for the previous object.  As a result,
the previous context object is leaked.

Safely stop the kdamond and deallocate the context object when the failure
is returned.  Note that the kdamond should be stopped first, because
damon_call() failure means not complete termination of the kdamond but
only the fact that the termination process has started.

The user impact shouldn't be that significant because the race is not easy
to happen, and only up to one DAMON context object can be leaked per race.

The issue was discovered [1] by Sashiko.

Link: https://lore.kernel.org/20260628215447.96166-7-sj@kernel.org
Link: https://lore.kernel.org/20260610035214.4850-1-sj@kernel.org [1]
Fixes: a6c33f1054e3 ("samples/damon/prcl: use damon_call() repeat mode instead of damon_callback")
Signed-off-by: SJ Park <sj@kernel.org>
Reviewed-by: Zenghui Yu <zenghui.yu@linux.dev>
Cc: <stable@vger.kernel.org> # 6.17.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 samples/damon/prcl.c |    7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

--- a/samples/damon/prcl.c
+++ b/samples/damon/prcl.c
@@ -112,7 +112,12 @@ static int damon_sample_prcl_start(void)
 	}
 
 	repeat_call_control.data = ctx;
-	return damon_call(ctx, &repeat_call_control);
+	err = damon_call(ctx, &repeat_call_control);
+	if (err) {
+		damon_stop(&ctx, 1);
+		damon_destroy_ctx(ctx);
+	}
+	return err;
 }
 
 static void damon_sample_prcl_stop(void)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 081/556] samples/damon/wsse: handle damon_start() failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (79 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 080/556] samples/damon/prcl: stop and free damon ctx when damon_call() fails Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 082/556] samples/damon/wsse: stop and free damon ctx when damon_call() fails Greg Kroah-Hartman
                   ` (487 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Zenghui Yu, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit e4742be45ea45bf554399ce89a09f71e525d7981 upstream.

Patch series "samples/damon: handle damon_{start,stop}() failures".

All DAMON sample modules are not correctly handling failures from
damon_start().  Among those, mtier also has an additional problem for
handling of damon_stop() failures.  wsse and prcl also have a problem in
their damon_call() failure handling.  As a result, memory leaks, next
DAMON operation disruptions, and use-after-free can happen.  Fix those.

Note that only the damon_start() failure caused issues can reliably be
reproduced.  Reproducing those issues require the admin permission,
though.


This patch (of 6):

damon_sample_wsse_start() callers assume it will clean up resources when
it fails.  And the function does the cleanup for context buildup failures.
However, it is not doing the cleanup for damon_start() failure.  As a
result, when damon_start() fails, it leaks the memory for DAMON context.
Free the context in case of the failure to fix the issues.

Note that the issue can reliably be reproduced because the module calls
damon_start() in the exclusive mode.  For example,

    $ sudo damo start
    $ echo $$ | sudo tee /sys/module/damon_sample_wsse/parameters/target_pid
    $ echo Y | sudo tee /sys/module/damon_sample_wsse/parameters/enabled
    $ sudo cat /proc/allocinfo | grep damon_new_ctx

Because the first command is running another DAMON instance, the third
command fails the damon_start() call because the new DAMON instance cannot
exclusively run.  And without this fix, by repeating the third and the
fourth commands above, we can show the memory consumption is only
increasing due to the leaks.  It requires the sudo permission though.

The issue was discovered [1] by Sashiko.

Link: https://lore.kernel.org/20260628215447.96166-2-sj@kernel.org
Link: https://lore.kernel.org/20260609145814.70163-1-sj@kernel.org [1]
Fixes: b757c6cfc696 ("samples/damon/wsse: start and stop DAMON as the user requests")
Signed-off-by: SJ Park <sj@kernel.org>
Reviewed-by: Zenghui Yu <zenghui.yu@linux.dev>
Cc: <stable@vger.kernel.org> # 6.14.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 samples/damon/wsse.c |    4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

--- a/samples/damon/wsse.c
+++ b/samples/damon/wsse.c
@@ -87,8 +87,10 @@ static int damon_sample_wsse_start(void)
 	target->pid = target_pidp;
 
 	err = damon_start(&ctx, 1, true);
-	if (err)
+	if (err) {
+		damon_destroy_ctx(ctx);
 		return err;
+	}
 	repeat_call_control.data = ctx;
 	return damon_call(ctx, &repeat_call_control);
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 082/556] samples/damon/wsse: stop and free damon ctx when damon_call() fails
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (80 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 081/556] samples/damon/wsse: handle damon_start() failure Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 083/556] mm/damon/sysfs-schemes: kobject_del() scheme action destination dirs Greg Kroah-Hartman
                   ` (486 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Zenghui Yu, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit a2c6fa6c23ad87c61e1379b05dc05cf5fed4bf8d upstream.

damon_sample_wsse_start() calls damon_call() right after damon_start() is
succeeded.  The kdamond that has started by the damon_start() could be
terminated by itself before or in the middle of the damon_call()
execution.  There could be multiple reasons for such a stop including
monitoring target process termination and kdamond_fn() internal memory
allocation failures.  In the case, damon_call() will fail and return an
error without cleaning up the DAMON context object.  The
damon_sample_wsse_start() caller assumes it would clean up the object,
though.  When the user requests to start DAMON again,
damon_sample_wsse_start() is called again, allocates a new DAMON context
object and overwrites the pointer for the previous object.  As a result,
the previous context object is leaked.

Safely stop the kdamond and deallocate the context object when the failure
is returned.  Note that the kdamond should be stopped first, because
damon_call() failure means not complete termination of the kdamond but
only the fact that the termination process has started.

The user impact shouldn't be that significant because the race is not easy
to happen, and only up to one DAMON context object can be leaked per race.

The issue was discovered [1] by Sashiko.

Link: https://lore.kernel.org/20260628215447.96166-6-sj@kernel.org
Link: https://lore.kernel.org/20260610034828.4632-1-sj@kernel.org [1]
Fixes: cc9c1b8c205b ("samples/damon/wsse: use damon_call() repeat mode instead of damon_callback")
Signed-off-by: SJ Park <sj@kernel.org>
Reviewed-by: Zenghui Yu <zenghui.yu@linux.dev>
Cc: <stable@vger.kernel.org> # 6.17.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 samples/damon/wsse.c |    7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

--- a/samples/damon/wsse.c
+++ b/samples/damon/wsse.c
@@ -92,7 +92,12 @@ static int damon_sample_wsse_start(void)
 		return err;
 	}
 	repeat_call_control.data = ctx;
-	return damon_call(ctx, &repeat_call_control);
+	err = damon_call(ctx, &repeat_call_control);
+	if (err) {
+		damon_stop(&ctx, 1);
+		damon_destroy_ctx(ctx);
+	}
+	return err;
 }
 
 static void damon_sample_wsse_stop(void)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 083/556] mm/damon/sysfs-schemes: kobject_del() scheme action destination dirs
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (81 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 082/556] samples/damon/wsse: stop and free damon ctx when damon_call() fails Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 084/556] mm/damon/sysfs-schemes: kobject_del() scheme dirs Greg Kroah-Hartman
                   ` (485 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit 286380c78bc51e6c578621b9ae660bf9e5ad2563 upstream.

On CONFIG_DEBUG_KOBJECT_RELEASE enabled kernel, lack of kobject_del()
could cause directories creation failures due to the name conflicts.  Fix
those issues for scheme action destination directories by adding
kobject_del() calls.

Link: https://lore.kernel.org/20260628220121.97360-8-sj@kernel.org
Fixes: 2cd0bf85a203 ("mm/damon/sysfs-schemes: implement DAMOS action destinations directory")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: <stable@vger.kernel.org> # 6.17.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/damon/sysfs-schemes.c |    4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

--- a/mm/damon/sysfs-schemes.c
+++ b/mm/damon/sysfs-schemes.c
@@ -2138,8 +2138,10 @@ static void damos_sysfs_dests_rm_dirs(
 	struct damos_sysfs_dest **dests_arr = dests->dests_arr;
 	int i;
 
-	for (i = 0; i < dests->nr; i++)
+	for (i = 0; i < dests->nr; i++) {
+		kobject_del(&dests_arr[i]->kobj);
 		kobject_put(&dests_arr[i]->kobj);
+	}
 	dests->nr = 0;
 	kfree(dests_arr);
 	dests->dests_arr = NULL;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 084/556] mm/damon/sysfs-schemes: kobject_del() scheme dirs
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (82 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 083/556] mm/damon/sysfs-schemes: kobject_del() scheme action destination dirs Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 085/556] mm/damon/sysfs-schemes: kobject_del() scheme filter dirs Greg Kroah-Hartman
                   ` (484 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit 05fb6ac98c49be870c5f9ccdfdf95f0107e564ae upstream.

On CONFIG_DEBUG_KOBJECT_RELEASE enabled kernel, lack of kobject_del()
could cause directories creation failures due to the name conflicts.  Fix
those issues for scheme directories by adding kobject_del() calls.

Link: https://lore.kernel.org/20260628220121.97360-4-sj@kernel.org
Fixes: 7e84b1f8212a ("mm/damon/sysfs: support DAMON-based Operation Schemes")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: <stable@vger.kernel.org> # 5.18.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/damon/sysfs-schemes.c |    5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

--- a/mm/damon/sysfs-schemes.c
+++ b/mm/damon/sysfs-schemes.c
@@ -2683,6 +2683,7 @@ void damon_sysfs_schemes_rm_dirs(struct
 
 	for (i = 0; i < schemes->nr; i++) {
 		damon_sysfs_scheme_rm_dirs(schemes_arr[i]);
+		kobject_del(&schemes_arr[i]->kobj);
 		kobject_put(&schemes_arr[i]->kobj);
 	}
 	schemes->nr = 0;
@@ -2724,13 +2725,15 @@ static int damon_sysfs_schemes_add_dirs(
 			goto out;
 		err = damon_sysfs_scheme_add_dirs(scheme);
 		if (err)
-			goto out;
+			goto del_out;
 
 		schemes_arr[i] = scheme;
 		schemes->nr++;
 	}
 	return 0;
 
+del_out:
+	kobject_del(&scheme->kobj);
 out:
 	damon_sysfs_schemes_rm_dirs(schemes);
 	kobject_put(&scheme->kobj);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 085/556] mm/damon/sysfs-schemes: kobject_del() scheme filter dirs
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (83 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 084/556] mm/damon/sysfs-schemes: kobject_del() scheme dirs Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 086/556] mm/damon/sysfs-schemes: kobject_del() scheme quota goal dirs Greg Kroah-Hartman
                   ` (483 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit 3c453bddacd4c04ecb38cf79dbfa41e7dfe0531b upstream.

On CONFIG_DEBUG_KOBJECT_RELEASE enabled kernel, lack of kobject_del()
could cause directories creation failures due to the name conflicts.  Fix
those issues for scheme filter directories by adding kobject_del() calls.

Link: https://lore.kernel.org/20260628220121.97360-6-sj@kernel.org
Fixes: 472e2b70eda6 ("mm/damon/sysfs-schemes: connect filter directory and filters directory")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: <stable@vger.kernel.org> # 6.3.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/damon/sysfs-schemes.c |    4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

--- a/mm/damon/sysfs-schemes.c
+++ b/mm/damon/sysfs-schemes.c
@@ -911,8 +911,10 @@ static void damon_sysfs_scheme_filters_r
 	struct damon_sysfs_scheme_filter **filters_arr = filters->filters_arr;
 	int i;
 
-	for (i = 0; i < filters->nr; i++)
+	for (i = 0; i < filters->nr; i++) {
+		kobject_del(&filters_arr[i]->kobj);
 		kobject_put(&filters_arr[i]->kobj);
+	}
 	filters->nr = 0;
 	kfree(filters_arr);
 	filters->filters_arr = NULL;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 086/556] mm/damon/sysfs-schemes: kobject_del() scheme quota goal dirs
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (84 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 085/556] mm/damon/sysfs-schemes: kobject_del() scheme filter dirs Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 087/556] mm/damon/sysfs-schemes: kobject_del() scheme region dirs Greg Kroah-Hartman
                   ` (482 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit 0d4397ca921ceaf80fc3eca4c8194812ff79a979 upstream.

On CONFIG_DEBUG_KOBJECT_RELEASE enabled kernel, lack of kobject_del()
could cause directories creation failures due to the name conflicts.  Fix
those issues for scheme quota goal directories by adding kobject_del()
calls.

Link: https://lore.kernel.org/20260628220121.97360-7-sj@kernel.org
Fixes: 7f262da0a30d ("mm/damon/sysfs-schemes: implement files for scheme quota goals setup")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: <stable@vger.kernel.org> # 6.8.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/damon/sysfs-schemes.c |    4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

--- a/mm/damon/sysfs-schemes.c
+++ b/mm/damon/sysfs-schemes.c
@@ -1462,8 +1462,10 @@ static void damos_sysfs_quota_goals_rm_d
 	struct damos_sysfs_quota_goal **goals_arr = goals->goals_arr;
 	int i;
 
-	for (i = 0; i < goals->nr; i++)
+	for (i = 0; i < goals->nr; i++) {
+		kobject_del(&goals_arr[i]->kobj);
 		kobject_put(&goals_arr[i]->kobj);
+	}
 	goals->nr = 0;
 	kfree(goals_arr);
 	goals->goals_arr = NULL;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 087/556] mm/damon/sysfs-schemes: kobject_del() scheme region dirs
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (85 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 086/556] mm/damon/sysfs-schemes: kobject_del() scheme quota goal dirs Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 088/556] mm/damon/sysfs: kobject_del() region and target (error) dirs Greg Kroah-Hartman
                   ` (481 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit f3ec3271210781c255e737498b84d5790e8176b4 upstream.

On CONFIG_DEBUG_KOBJECT_RELEASE enabled kernel, lack of kobject_del()
could cause directories creation failures due to the name conflicts.  Fix
those issues for scheme region directories by adding kobject_del() calls.

This issue was discovered [1] by Sashiko, though its analysis was
partially incorrect.

Link: https://lore.kernel.org/20260628220121.97360-5-sj@kernel.org
Link: https://lore.kernel.org/20260517205828.6204-1-sj@kernel.org [1]
Fixes: 9277d0367ba1 ("mm/damon/sysfs-schemes: implement scheme region directory")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: <stable@vger.kernel.org> # 6.2.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/damon/sysfs-schemes.c |    1 +
 1 file changed, 1 insertion(+)

--- a/mm/damon/sysfs-schemes.c
+++ b/mm/damon/sysfs-schemes.c
@@ -332,6 +332,7 @@ static void damon_sysfs_scheme_regions_r
 	list_for_each_entry_safe(r, next, &regions->regions_list, list) {
 		damos_sysfs_region_rm_dirs(r);
 		list_del(&r->list);
+		kobject_del(&r->kobj);
 		kobject_put(&r->kobj);
 		regions->nr_regions--;
 	}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 088/556] mm/damon/sysfs: kobject_del() region and target (error) dirs
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (86 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 087/556] mm/damon/sysfs-schemes: kobject_del() scheme region dirs Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 089/556] mm/damon/sysfs: kobject_del() target (normal), context and kdamond dirs Greg Kroah-Hartman
                   ` (480 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit 2603ef6f6ec3d3f7de2d6a07e7c9a683cebac419 upstream.

On CONFIG_DEBUG_KOBJECT_RELEASE enabled kernel, lack of kobject_del()
could cause directories creation failures due to the name conflicts.  Fix
those issues for the normal creation path of region directories and the
error path of target directories, by adding kobject_del() calls.

Link: https://lore.kernel.org/20260628220121.97360-3-sj@kernel.org
Fixes: 2031b14ea757 ("mm/damon/sysfs: support the physical address space monitoring")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: <stable@vger.kernel.org> # 5.18.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/damon/sysfs.c |    8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

--- a/mm/damon/sysfs.c
+++ b/mm/damon/sysfs.c
@@ -105,8 +105,10 @@ static void damon_sysfs_regions_rm_dirs(
 	struct damon_sysfs_region **regions_arr = regions->regions_arr;
 	int i;
 
-	for (i = 0; i < regions->nr; i++)
+	for (i = 0; i < regions->nr; i++) {
+		kobject_del(&regions_arr[i]->kobj);
 		kobject_put(&regions_arr[i]->kobj);
+	}
 	regions->nr = 0;
 	kfree(regions_arr);
 	regions->regions_arr = NULL;
@@ -369,13 +371,15 @@ static int damon_sysfs_targets_add_dirs(
 
 		err = damon_sysfs_target_add_dirs(target);
 		if (err)
-			goto out;
+			goto del_out;
 
 		targets_arr[i] = target;
 		targets->nr++;
 	}
 	return 0;
 
+del_out:
+	kobject_del(&target->kobj);
 out:
 	damon_sysfs_targets_rm_dirs(targets);
 	kobject_put(&target->kobj);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 089/556] mm/damon/sysfs: kobject_del() target (normal), context and kdamond dirs
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (87 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 088/556] mm/damon/sysfs: kobject_del() region and target (error) dirs Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 090/556] mm/damon/core-kunit: check region count before testing in split_at() Greg Kroah-Hartman
                   ` (479 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit 263af33a72d1995ae6cdc22b08d527e2bda17259 upstream.

Patch series "mm/damon/sysfs: kobject_del() directories that users can
create/remove".

DAMON sysfs interface allows users to create and remove arbitrary number
of directories on sysfs, using a few files having 'nr_' prefix.  For
example, 'nr_kdamonds'.  When the user writes a number 'N' to the files,
directories having name starting from '0' to 'N - 1' are created in the
same directory.  The pre-existing number-named directories are removed
before creating the new directories.

For the removal of the existing directories, DAMON sysfs interface use
only kobject_put().  Because DAMON sysfs interface is the only kernel
component that manages the directories, there is no problem in normal
situations.  However, if CONFIG_DEBUG_KOBJECT_RELEASE is enabled, the
removal of dirs are delayed.  Let's suppose a user writes a non-zero
number to the 'nr_*' files while there are pre-existing number-named
directories, on the config enabled kernel.  DAMON sysfs interface
decreases the reference counts of the existing directories and immediately
creates new directories.  Because the removal of the sysfs directories is
delayed, it shows some pre-existing directories of the same names when it
tries to create the new directories, and fails.

For example, the issue can be triggered like below:

    # grep DEBUG_KOBJECT_RELEASE /boot/config-$(uname -r)
    CONFIG_DEBUG_KOBJECT_RELEASE=y
    # ls
    nr_kdamonds
    # echo 1 > nr_kdamonds
    # echo 1 > nr_kdamonds
    bash: echo: write error: File exists
    # dmesg
    [...]
    [  300.880458] kobject: kobject_add_internal failed for 0 with -EEXIST, don't try to register things with the same name in the same directory.
    [...]

Some of the error handling paths of the directories also lack the
kobject_del() call.  If the user uses nr_* file right after the errors,
similar issues can happen.

This doesn't cause catastrophic issues like kernel panics or memory
corruptions.  Users can work around by removing all directories first
(write 0 to the nr_* files) and then create new directories after
confirming the old directories are gone.  But, this is definitely a bug
that causes a bad user experience.

Fix the issues by calling kobject_del() before creating new directories.


This patch (of 11)

On CONFIG_DEBUG_KOBJECT_RELEASE enabled kernel, lack of kobject_del()
could cause directories creation failures due to the name conflicts.  Fix
those issues for normal creation paths of target, context and kdamond
directories, and error paths of context and kdamond directories by adding
kobject_del() calls.

Note that this fix for target directories is not complete since it has a
similar issue in the damon_sysfs_targets_add_dirs() error path.  Because
the normal path issue and the error path issue are introduced by different
commits, this commit is fixing only the normal path issue.  A commit for
the error path will be added next.

Link: https://lore.kernel.org/20260628220121.97360-1-sj@kernel.org
Link: https://lore.kernel.org/20260628220121.97360-2-sj@kernel.org
Fixes: c951cd3b8901 ("mm/damon: implement a minimal stub for sysfs-based DAMON interface")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: <stable@vger.kernel.org> # 5.18.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/damon/sysfs.c |   11 +++++++++--
 1 file changed, 9 insertions(+), 2 deletions(-)

--- a/mm/damon/sysfs.c
+++ b/mm/damon/sysfs.c
@@ -333,6 +333,7 @@ static void damon_sysfs_targets_rm_dirs(
 
 	for (i = 0; i < targets->nr; i++) {
 		damon_sysfs_target_rm_dirs(targets_arr[i]);
+		kobject_del(&targets_arr[i]->kobj);
 		kobject_put(&targets_arr[i]->kobj);
 	}
 	targets->nr = 0;
@@ -1644,6 +1645,7 @@ static void damon_sysfs_contexts_rm_dirs
 
 	for (i = 0; i < contexts->nr; i++) {
 		damon_sysfs_context_rm_dirs(contexts_arr[i]);
+		kobject_del(&contexts_arr[i]->kobj);
 		kobject_put(&contexts_arr[i]->kobj);
 	}
 	contexts->nr = 0;
@@ -1682,13 +1684,15 @@ static int damon_sysfs_contexts_add_dirs
 
 		err = damon_sysfs_context_add_dirs(context);
 		if (err)
-			goto out;
+			goto del_out;
 
 		contexts_arr[i] = context;
 		contexts->nr++;
 	}
 	return 0;
 
+del_out:
+	kobject_del(&context->kobj);
 out:
 	damon_sysfs_contexts_rm_dirs(contexts);
 	kobject_put(&context->kobj);
@@ -2505,6 +2509,7 @@ static void damon_sysfs_kdamonds_rm_dirs
 
 	for (i = 0; i < kdamonds->nr; i++) {
 		damon_sysfs_kdamond_rm_dirs(kdamonds_arr[i]);
+		kobject_del(&kdamonds_arr[i]->kobj);
 		kobject_put(&kdamonds_arr[i]->kobj);
 	}
 	kdamonds->nr = 0;
@@ -2559,13 +2564,15 @@ static int damon_sysfs_kdamonds_add_dirs
 
 		err = damon_sysfs_kdamond_add_dirs(kdamond);
 		if (err)
-			goto out;
+			goto del_out;
 
 		kdamonds_arr[i] = kdamond;
 		kdamonds->nr++;
 	}
 	return 0;
 
+del_out:
+	kobject_del(&kdamond->kobj);
 out:
 	damon_sysfs_kdamonds_rm_dirs(kdamonds);
 	kobject_put(&kdamond->kobj);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 090/556] mm/damon/core-kunit: check region count before testing in split_at()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (88 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 089/556] mm/damon/sysfs: kobject_del() target (normal), context and kdamond dirs Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 091/556] mm/damon/core-kunit: handle region split failure in filter_out() Greg Kroah-Hartman
                   ` (478 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Brendan Higgins,
	Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit 9b18ef3c3aa1ce24176e340061caf15fa2742564 upstream.

damon_test_split_at() test next region that is assumed to be created by
damon_split_region_at() invocation.  But the split might fail.  In this
case, the succeeding test may dereference invalid pointers returned by
damon_next_region().

The invalid pointer may not cause a really bad user impact, because of the
implementation detail.  It would only read wrong contents in the belonging
damon_target struct.  Depending on the future change of the offset from
the link header to the accessing field, this could also be really
dangerous, though.  Still, the realistic user impact would be limited.  It
would affect only test run setups.

Fix it by testing if the number of regions was also changed as expected
and exit early for the failure.

The issue was discovered [1] by Sashiko.

Link: https://lore.kernel.org/20260718001442.87129-3-sj@kernel.org
Link: https://lore.kernel.org/20260714142352.100478-1-sj@kernel.org [1]
Fixes: 17ccae8bb5c9 ("mm/damon: add kunit tests")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: Brendan Higgins <brendan.higgins@linux.dev>
Cc: <stable@vger.kernel.org> # 5.15.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/damon/tests/core-kunit.h |    5 +++++
 1 file changed, 5 insertions(+)

--- a/mm/damon/tests/core-kunit.h
+++ b/mm/damon/tests/core-kunit.h
@@ -157,6 +157,10 @@ static void damon_test_split_at(struct k
 	r->age = 10;
 	damon_add_region(r, t);
 	damon_split_region_at(t, r, 25);
+	KUNIT_EXPECT_EQ(test, damon_nr_regions(t), 2);
+	if (damon_nr_regions(t) != 2)
+		goto out;
+
 	KUNIT_EXPECT_EQ(test, r->ar.start, 0ul);
 	KUNIT_EXPECT_EQ(test, r->ar.end, 25ul);
 
@@ -169,6 +173,7 @@ static void damon_test_split_at(struct k
 	KUNIT_EXPECT_EQ(test, r->last_nr_accesses, r_new->last_nr_accesses);
 	KUNIT_EXPECT_EQ(test, r->age, r_new->age);
 
+out:
 	damon_free_target(t);
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 091/556] mm/damon/core-kunit: handle region split failure in filter_out()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (89 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 090/556] mm/damon/core-kunit: check region count before testing in split_at() Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 092/556] mm/damon/core-kunit: skip wrong dest walk in commit_dests_for() Greg Kroah-Hartman
                   ` (477 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Brendan Higgins,
	Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit 3423fe70395210e2f0cd795270292f6a27cd57b5 upstream.

damos_test_filter_out() test checks if damos_filter_match() of an address
filter splits the region as expected under a given condition.  But, the
test continued regardless of the split successes.  As a result, the later
part of the test could dereference invalid pointers that returned from
damon_next_region().  Further, it could corrupt memory from
damon_destroy_region().

The consequent user impact (memory corruption) is quite bad.  The
realistic user impact would be limited, though.  It would affect only test
run setups.

Fix it by exiting early for the number of regions test failure.

The issue was discovered [1] by Sashiko.

Link: https://lore.kernel.org/20260718001442.87129-5-sj@kernel.org
Link: https://lore.kernel.org/20260714142352.100478-1-sj@kernel.org [1]
Fixes: 26713c890875 ("mm/damon/core-test: add a unit test for __damos_filter_out()")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: Brendan Higgins <brendan.higgins@linux.dev>
Cc: <stable@vger.kernel.org> # 6.6.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/damon/tests/core-kunit.h |    5 +++++
 1 file changed, 5 insertions(+)

--- a/mm/damon/tests/core-kunit.h
+++ b/mm/damon/tests/core-kunit.h
@@ -1259,6 +1259,8 @@ static void damos_test_filter_out(struct
 	KUNIT_EXPECT_EQ(test, r->ar.start, 1);
 	KUNIT_EXPECT_EQ(test, r->ar.end, 2);
 	KUNIT_EXPECT_EQ(test, damon_nr_regions(t), 2);
+	if (damon_nr_regions(t) != 2)
+		goto out;
 	r2 = damon_next_region(r);
 	KUNIT_EXPECT_EQ(test, r2->ar.start, 2);
 	KUNIT_EXPECT_EQ(test, r2->ar.end, 4);
@@ -1273,11 +1275,14 @@ static void damos_test_filter_out(struct
 	KUNIT_EXPECT_EQ(test, r->ar.start, 2);
 	KUNIT_EXPECT_EQ(test, r->ar.end, 6);
 	KUNIT_EXPECT_EQ(test, damon_nr_regions(t), 2);
+	if (damon_nr_regions(t) != 2)
+		goto out;
 	r2 = damon_next_region(r);
 	KUNIT_EXPECT_EQ(test, r2->ar.start, 6);
 	KUNIT_EXPECT_EQ(test, r2->ar.end, 8);
 	damon_destroy_region(r2, t);
 
+out:
 	damon_free_target(t);
 	damos_free_filter(f);
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 092/556] mm/damon/core-kunit: skip wrong dest walk in commit_dests_for()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (90 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 091/556] mm/damon/core-kunit: handle region split failure in filter_out() Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 093/556] mm/damon/core-kunit: skip wrong quota goal walk in commit_quota_goals() Greg Kroah-Hartman
                   ` (476 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Brendan Higgins,
	Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit 7e2f2c41b27f64caad6599073aaa0ccdd08745e1 upstream.

damos_test_commit_dests_for() traverse damos action destinations after
damos_commit_dests().  It assumes damos_commit_dests() made expected
numbers of destinations for source and destination structures.  It might
not.  Because the traversal is made based on destination struct length, it
could do out of bounds access for source value expectation.

The consequent user impact (out-of-bound access ) is quite bad.  The
realistic user impact would be limited, though.  It would affect only test
run setups.

Fix it by exiting early for the number of regions test failure.

The issue was discovered [1] by Sashiko.

Link: https://lore.kernel.org/20260718001442.87129-6-sj@kernel.org
Link: https://lore.kernel.org/20260713144757.39740-1-sj@kernel.org [1]
Fixes: eec573b8dd65 ("mm/damon/tests/core-kunit: add damos_commit_dests() test")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: Brendan Higgins <brendan.higgins@linux.dev>
Cc: <stable@vger.kernel.org> # 6.19.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/damon/tests/core-kunit.h |    2 ++
 1 file changed, 2 insertions(+)

--- a/mm/damon/tests/core-kunit.h
+++ b/mm/damon/tests/core-kunit.h
@@ -902,6 +902,8 @@ static void damos_test_commit_dests_for(
 	skip = false;
 
 	KUNIT_EXPECT_EQ(test, dst.nr_dests, src_nr_dests);
+	if (dst.nr_dests != src_nr_dests)
+		goto out;
 	for (i = 0; i < dst.nr_dests; i++) {
 		KUNIT_EXPECT_EQ(test, dst.node_id_arr[i], src_node_id_arr[i]);
 		KUNIT_EXPECT_EQ(test, dst.weight_arr[i], src_weight_arr[i]);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 093/556] mm/damon/core-kunit: skip wrong quota goal walk in commit_quota_goals()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (91 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 092/556] mm/damon/core-kunit: skip wrong dest walk in commit_dests_for() Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 094/556] mm/damon/core-kunit: skip wrong region walk in commit_target_regions() Greg Kroah-Hartman
                   ` (475 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Brendan Higgins,
	Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit 867bbe6dbd5a68eb58e79cc7f068a6cf184c40d8 upstream.

damos_test_commit_quota_goals_for() traverses damos quota goals after
damos_commit_quota_goals() call.  It assumes damos_commit_quota_goals()
made expected numbers of goals.  It might not.  Because the traversal is
made based on destination struct length, it could do out of bounds access
for source expectation value array.

The consequent user impact (out-of-bound access ) is quite bad.  The
realistic user impact would be limited though.  It would affect only test
run setups.

Fix it by testing if the number of goals was also changed as expected and
exit early for the failure.

The issue was discovered [1] by Sashiko.

Link: https://lore.kernel.org/20260718001442.87129-7-sj@kernel.org
Link: https://lore.kernel.org/20260713144757.39740-1-sj@kernel.org [1]
Fixes: d9adfb8a28e7 ("mm/damon/tests/core-kunit: add damos_commit_quota_goals() test")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: Brendan Higgins <brendan.higgins@linux.dev>
Cc: <stable@vger.kernel.org> # 6.19.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/damon/tests/core-kunit.h |    9 +++++++++
 1 file changed, 9 insertions(+)

--- a/mm/damon/tests/core-kunit.h
+++ b/mm/damon/tests/core-kunit.h
@@ -733,6 +733,7 @@ static void damos_test_commit_quota_goal
 	struct damos_quota_goal *goal, *next;
 	bool skip = true;
 	int i;
+	int nr_dst = 0, nr_src = 0;
 
 	INIT_LIST_HEAD(&dst.goals);
 	INIT_LIST_HEAD(&src.goals);
@@ -755,6 +756,14 @@ static void damos_test_commit_quota_goal
 
 	damos_commit_quota_goals(&dst, &src);
 
+	damos_for_each_quota_goal(goal, &dst)
+		nr_dst++;
+	damos_for_each_quota_goal(goal, &src)
+		nr_src++;
+	KUNIT_EXPECT_EQ(test, nr_dst, nr_src);
+	if (nr_dst != nr_src)
+		goto out;
+
 	i = 0;
 	damos_for_each_quota_goal(goal, (&dst)) {
 		KUNIT_EXPECT_EQ(test, goal->metric, src_goals[i].metric);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 094/556] mm/damon/core-kunit: skip wrong region walk in commit_target_regions()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (92 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 093/556] mm/damon/core-kunit: skip wrong quota goal walk in commit_quota_goals() Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 095/556] mm/damon/core: handle region split failure in apply_min_nr_regions() Greg Kroah-Hartman
                   ` (474 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Brendan Higgins,
	Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit 488cf81c49955f83b7682dda880e9920c173e617 upstream.

damon_test_commit_target_regions_for() traverses expected values array
after damon_commit_target_regions() call.  It assumes
damon_commit_target_regions() made expected number of regions.  It might
not.  Because the traversal is made based on the region count, it could do
out of bounds access to the expectation value array.

The consequent user impact (out-of-bound access) is quite bad.  The
realistic user impact would be limited, though.  It would affect only test
run setups.

Fix it by testing if the number of regions was also changed as expected
and exit early for the failure.

The issue was discovered [1] by Sashiko.

Link: https://lore.kernel.org/20260718001442.87129-8-sj@kernel.org
Link: https://lore.kernel.org/20260713144757.39740-1-sj@kernel.org [1]
Fixes: 603f67eb91e0 ("mm/damon/tests/core-kunit: add damon_commit_target_regions() test")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: Brendan Higgins <brendan.higgins@linux.dev>
Cc: <stable@vger.kernel.org> # 6.19.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/damon/tests/core-kunit.h |    9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

--- a/mm/damon/tests/core-kunit.h
+++ b/mm/damon/tests/core-kunit.h
@@ -1171,14 +1171,19 @@ static void damon_test_commit_target_reg
 		kunit_skip(test, "src target setup fail");
 	}
 	damon_commit_target_regions(dst_target, src_target, 1);
+
+	KUNIT_EXPECT_EQ(test, damon_nr_regions(dst_target), nr_expect_regions);
+	if (damon_nr_regions(dst_target) != nr_expect_regions)
+		goto out;
+
 	i = 0;
 	damon_for_each_region(r, dst_target) {
 		KUNIT_EXPECT_EQ(test, r->ar.start, expect_start_end[i][0]);
 		KUNIT_EXPECT_EQ(test, r->ar.end, expect_start_end[i][1]);
 		i++;
 	}
-	KUNIT_EXPECT_EQ(test, damon_nr_regions(dst_target), nr_expect_regions);
-	KUNIT_EXPECT_EQ(test, i, nr_expect_regions);
+
+out:
 	damon_free_target(dst_target);
 	damon_free_target(src_target);
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 095/556] mm/damon/core: handle region split failure in apply_min_nr_regions()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (93 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 094/556] mm/damon/core-kunit: skip wrong region walk in commit_target_regions() Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 096/556] mm/damon/core: initialize damos->last_applied Greg Kroah-Hartman
                   ` (473 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit c608748607620f331196ed0ba9fe4017892c1457 upstream.

damon_apply_min_nr_regions() repeatedly split each region until its size
becomes small enough to meet the user-defined low limit of the number of
regions.  The loop assumes the split operation (damon_split_region_at())
will always succeed and create the new region.  But the operation could
silently fail for memory allocation failures, for example.

If such failure happens and the region was the last region, the linked
list-based next region fetching returns invalid pointer.  As a result,
invalid memory dereference and corruption could happen.  Even if the
corner case is handled, it imposes stress to the allocator by trying split
regions for other targets.  Fix the issue by breaking all the loops for
any region split failure.

This means there could be a min_nr_regions violation.  It will only rarely
happen since the allocation is arguably too small to fail.  Even if it
happens, it is only temporal.  damon_apply_min_nr_regions() will be called
again after the aggregation interval.

The user impact of the issue should be minor, since the allocation is
arguably too small to fail.  But, it could still theoretically happen, and
the consequence is very bad.

This issue was discovered [1] by Sashiko.

Link: https://lore.kernel.org/20260719155442.88794-1-sj@kernel.org
Link: https://lore.kernel.org/20260717011834.120715-1-sj@kernel.org [1]
Fixes: b1029f29eb1d ("mm/damon/core: split regions for min_nr_regions")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: <stable@vger.kernel.org> # 7.1.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/damon/core.c |   13 +++++++++----
 1 file changed, 9 insertions(+), 4 deletions(-)

--- a/mm/damon/core.c
+++ b/mm/damon/core.c
@@ -1670,7 +1670,7 @@ static unsigned long damon_region_sz_lim
 	return sz;
 }
 
-static void damon_split_region_at(struct damon_target *t,
+static int damon_split_region_at(struct damon_target *t,
 				  struct damon_region *r, unsigned long sz_r);
 
 /*
@@ -1696,11 +1696,13 @@ static unsigned long damon_apply_min_nr_
 	damon_for_each_target(t, ctx) {
 		damon_for_each_region_safe(r, next, t) {
 			while (damon_sz_region(r) > max_region_sz) {
-				damon_split_region_at(t, r, max_region_sz);
+				if (damon_split_region_at(t, r, max_region_sz))
+					goto out;
 				r = damon_next_region(r);
 			}
 		}
 	}
+out:
 	return max_region_sz;
 }
 
@@ -3194,8 +3196,10 @@ static void damon_verify_split_region_at
  *
  * r		the region to be split
  * sz_r		size of the first sub-region that will be made
+ *
+ * Return: 0 on success, negative error code otherwise.
  */
-static void damon_split_region_at(struct damon_target *t,
+static int damon_split_region_at(struct damon_target *t,
 				  struct damon_region *r, unsigned long sz_r)
 {
 	struct damon_region *new;
@@ -3203,7 +3207,7 @@ static void damon_split_region_at(struct
 	damon_verify_split_region_at(r, sz_r);
 	new = damon_new_region(r->ar.start + sz_r, r->ar.end);
 	if (!new)
-		return;
+		return -ENOMEM;
 
 	r->ar.end = new->ar.start;
 
@@ -3215,6 +3219,7 @@ static void damon_split_region_at(struct
 	memcpy(new->probe_hits, r->probe_hits, sizeof(r->probe_hits));
 
 	damon_insert_region(new, r, damon_next_region(r), t);
+	return 0;
 }
 
 /* Split every region in the given target into 'nr_subs' regions */



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 096/556] mm/damon/core: initialize damos->last_applied
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (94 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 095/556] mm/damon/core: handle region split failure in apply_min_nr_regions() Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 097/556] mm/secretmem: properly account locked pages Greg Kroah-Hartman
                   ` (472 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Brendan Higgins,
	Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit af5f76aeb9c9aa9c77d5e1d94e0ee4618c805239 upstream.

Patch series "mm/damon: fix uninitialized DAMOS field and kunit exec
expectation bugs".

Fix a few Sashiko-found unurgent bugs.  Patch 1 fixes use of uninitialized
damos->last_applied field.  Patches 2-7 fix DAMON kunit tests that do
invalid memory access under test failures.

The bugs are better to be fixed and eventually merged into stable@ kernel.
That said, the fixes are arguably not urgent.  Patch 1 only introduces
negligible DAMOS efficiency degradation in occasional cases.  Kunit fixes
could introduce quite bad consequences but those are test code that affect
only test run setups.


This patch (of 7):

Multiple DAMON regions could exist across a folio.  If they fulfill the
condition to apply a DAMOS scheme, the scheme could be applied multiple
times to the folio.  To avoid this, each DAMOS scheme stores the folio
that the scheme was applied to last time in the damos->last_applied field
and skips repeatedly applying the same scheme to the same folio.

The field is being used without initialization, though.  Hence, the
mechanism could wrongly skip applying a scheme to a folio at the very
first time of DAMOS run.

The user impact is trivial.  DAMON might unexpectedly skip applying DAMOS
action for one folio for the first time per scheme.  In the DAMON's
best-effort world, this is never a real problem.  No critical consequences
such as kernel panic or memory corruption happen.

It is a clear bug, though, and the fix is straightforward.  Fix the issue
by initializing the field in DAMOS scheme creation function,
damon_new_scheme().

The issue was discovered [1] by Sashiko.

Link: https://lore.kernel.org/20260718001442.87129-1-sj@kernel.org
Link: https://lore.kernel.org/20260718001442.87129-2-sj@kernel.org
Link: https://lore.kernel.org/20260714055436.120034-1-sj@kernel.org [1]
Fixes: 94ba17adaba0 ("mm/damon: avoid applying DAMOS action to same entity multiple times")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: Brendan Higgins <brendan.higgins@linux.dev>
Cc: <stable@vger.kernel.org> # 6.15.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/damon/core.c |    1 +
 1 file changed, 1 insertion(+)

--- a/mm/damon/core.c
+++ b/mm/damon/core.c
@@ -579,6 +579,7 @@ struct damos *damon_new_scheme(struct da
 	INIT_LIST_HEAD(&scheme->ops_filters);
 	scheme->stat = (struct damos_stat){};
 	scheme->max_nr_snapshots = 0;
+	scheme->last_applied = NULL;
 	INIT_LIST_HEAD(&scheme->list);
 
 	scheme->quota = *(damos_quota_init(quota));



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 097/556] mm/secretmem: properly account locked pages
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (95 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 096/556] mm/damon/core: initialize damos->last_applied Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 098/556] futex: Prevent rcuwait use-after-free during requeue PI Greg Kroah-Hartman
                   ` (471 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Lorenzo Stoakes (ARM), Daehyeon Ko,
	Mike Rapoport (Microsoft), David Hildenbrand (Arm),
	Alexei Starovoitov, David S. Miller, Hagen Paul Pfeifer,
	Jakub Kacinski, James Bottomley, Jesper Dangaard Brouer,
	John Fastabend, Liam R. Howlett, Michal Hocko, Stanislav Fomichev,
	Suren Baghdasaryan, Vlastimil Babka, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lorenzo Stoakes (ARM) <ljs@kernel.org>

commit 97d34aa65c29cca85e3e9050f4c936389b38a054 upstream.

secretmem accounts folios by treating memory as if it were mlock()'d and
thus limited by the RLIMIT_MEMLOCK limit.

However the folios are unevictable and remain so until the inode is
evicted, eliminating usual mlock() semantics - mapping folios then
unmapping them does not clear their unevictable state, since it depends on
AS_UNEVICTABLE, not PG_mlocked.

A user can therefore easily work around the RLIMIT_MEMLOCK limit - simply
map then unmap and VmLck no longer counts the secretmem range.  Worse,
folios are not accounted in the process's RSS, meaning the OOM killer
won't know to kill the process.

Repeatedly mapping/unmapping (or forking) can then result in the
consumption of all available system memory with unevictable folios and
cause system instability.

A secretmem fd can be passed between processes and over fork so a
per-process limit simply does not make sense, so follow the precedent set
by io_uring, perf, skbuff, iommufd and xdp by tracking the number of
locked pages in user_struct->locked_vm.

Since the scope tracked is actually inode lifetime, the RLIMIT_MEMLOCK
applies per-user not per-process, so it doesn't make sense to bypass for
users with CAP_IPC_LOCK, therefore remove this bypass.

There is simply no reason to carry on marking the mapping as mlock()'d
since it's misleading and the lifecycle is now correctly handled, so
remove this too.

Note that secretmem does not support any form of truncation (including
hole punching) and the folios are unreclaimable, so the folios need only
be accounted on fault and unaccounted on inode destruction.

__secretmem_account_pages() is more or less a duplicate of the code that
io_uring etc.  use, but since this is a bug fix that needs backporting,
defer any de-duplication efforts to a follow-up.

test_mlock_limit() asserts mlock_future_ok() on mmap(), however this has
been removed, so remove the test altogether for the fix.  A new test will
be sent separately for upstream.

Link: https://lore.kernel.org/20260826-secretmem-accounting-v3-1-94cb04399510@kernel.org
Fixes: 1507f51255c9 ("mm: introduce memfd_secret system call to create "secret" memory areas")
Signed-off-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Reported-by: Daehyeon Ko <4ncienth@gmail.com>
Closes: https://lore.kernel.org/linux-mm/20260813225328.2010303-1-4ncienth@gmail.com/
Reviewed-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Acked-by: David Hildenbrand (Arm) <david@kernel.org>
Tested-by: Daehyeon Ko <4ncienth@gmail.com>
Cc: Alexei Starovoitov <ast@kernel.org>
Cc: David Hildenbrand <david@kernel.org>
Cc: David S. Miller <davem@davemloft.net>
Cc: Hagen Paul Pfeifer <hagen@jauu.net>
Cc: Jakub Kacinski <kuba@kernel.org>
Cc: James Bottomley <james.bottomley@HansenPartnership.com>
Cc: Jesper Dangaard Brouer <hawk@kernel.org>
Cc: John Fastabend <john.fastabend@gmail.com>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Michal Hocko <mhocko@suse.com>
Cc: Stanislav Fomichev <sdf@fomichev.me>
Cc: Suren Baghdasaryan <surenb@google.com>
Cc: Vlastimil Babka <vbabka@kernel.org>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 include/linux/sched/user.h                |    3 
 mm/secretmem.c                            |  116 +++++++++++++++++++++++++++---
 tools/testing/selftests/mm/memfd_secret.c |   30 -------
 3 files changed, 110 insertions(+), 39 deletions(-)

--- a/include/linux/sched/user.h
+++ b/include/linux/sched/user.h
@@ -25,7 +25,8 @@ struct user_struct {
 
 #if defined(CONFIG_PERF_EVENTS) || defined(CONFIG_BPF_SYSCALL) || \
 	defined(CONFIG_NET) || defined(CONFIG_IO_URING) || \
-	defined(CONFIG_VFIO_PCI_ZDEV_KVM) || IS_ENABLED(CONFIG_IOMMUFD)
+	defined(CONFIG_VFIO_PCI_ZDEV_KVM) || IS_ENABLED(CONFIG_IOMMUFD) || \
+	defined(CONFIG_SECRETMEM)
 	atomic_long_t locked_vm;
 #endif
 #ifdef CONFIG_WATCH_QUEUE
--- a/mm/secretmem.c
+++ b/mm/secretmem.c
@@ -18,6 +18,8 @@
 #include <linux/secretmem.h>
 #include <linux/set_memory.h>
 #include <linux/sched/signal.h>
+#include <linux/sched/user.h>
+#include <linux/cred.h>
 
 #include <uapi/linux/magic.h>
 
@@ -47,10 +49,69 @@ bool secretmem_active(void)
 	return !!atomic_read(&secretmem_users);
 }
 
+struct secretmem_inode_state {
+	struct user_struct	*user;
+	atomic_long_t		nr_pages_accounted;
+};
+
+static bool __secretmem_account_pages(struct user_struct *user,
+		unsigned long nr_pages)
+{
+	unsigned long page_limit, cur_pages, new_pages;
+
+	if (!nr_pages)
+		return true;
+
+	page_limit = rlimit(RLIMIT_MEMLOCK) >> PAGE_SHIFT;
+
+	cur_pages = atomic_long_read(&user->locked_vm);
+	do {
+		new_pages = cur_pages + nr_pages;
+		if (new_pages > page_limit)
+			return false;
+	} while (!atomic_long_try_cmpxchg(&user->locked_vm,
+					  &cur_pages, new_pages));
+	return true;
+}
+
+static bool secretmem_account_folio(struct secretmem_inode_state *state,
+		const struct folio *folio)
+{
+	const unsigned long nr_pages = folio_nr_pages(folio);
+
+	if (!__secretmem_account_pages(state->user, nr_pages))
+		return false;
+
+	atomic_long_add(nr_pages, &state->nr_pages_accounted);
+	return true;
+}
+
+static void __secretmem_unaccount_pages(struct secretmem_inode_state *state,
+		unsigned long nr_pages)
+{
+	atomic_long_sub(nr_pages, &state->user->locked_vm);
+	atomic_long_sub(nr_pages, &state->nr_pages_accounted);
+}
+
+static void secretmem_unaccount_folio(struct secretmem_inode_state *state,
+		struct folio *folio)
+{
+	__secretmem_unaccount_pages(state, folio_nr_pages(folio));
+}
+
+static void secretmem_unaccount_all_folios(struct secretmem_inode_state *state)
+{
+	const unsigned long nr_pages_accounted =
+		atomic_long_read(&state->nr_pages_accounted);
+
+	__secretmem_unaccount_pages(state, nr_pages_accounted);
+}
+
 static vm_fault_t secretmem_fault(struct vm_fault *vmf)
 {
 	struct address_space *mapping = vmf->vma->vm_file->f_mapping;
 	struct inode *inode = file_inode(vmf->vma->vm_file);
+	struct secretmem_inode_state *state = inode->i_private;
 	pgoff_t offset = vmf->pgoff;
 	gfp_t gfp = vmf->gfp_mask;
 	unsigned long addr;
@@ -72,8 +133,15 @@ retry:
 			goto out;
 		}
 
+		if (!secretmem_account_folio(state, folio)) {
+			folio_put(folio);
+			ret = VM_FAULT_SIGBUS;
+			goto out;
+		}
+
 		err = set_direct_map_invalid_noflush(folio_page(folio, 0));
 		if (err) {
+			secretmem_unaccount_folio(state, folio);
 			folio_put(folio);
 			ret = vmf_error(err);
 			goto out;
@@ -82,6 +150,7 @@ retry:
 		__folio_mark_uptodate(folio);
 		err = filemap_add_folio(mapping, folio, offset, gfp);
 		if (unlikely(err)) {
+			secretmem_unaccount_folio(state, folio);
 			/*
 			 * If a split of large page was required, it
 			 * already happened when we marked the page invalid
@@ -112,22 +181,30 @@ static const struct vm_operations_struct
 	.fault = secretmem_fault,
 };
 
+static void secretmem_destroy_inode_priv(struct inode *inode)
+{
+	struct secretmem_inode_state *state = inode->i_private;
+
+	secretmem_unaccount_all_folios(state);
+	free_uid(state->user);
+	kfree(state);
+	inode->i_private = NULL;
+}
+
 static int secretmem_release(struct inode *inode, struct file *file)
 {
 	atomic_dec(&secretmem_users);
+	secretmem_destroy_inode_priv(inode);
+
 	return 0;
 }
 
 static int secretmem_mmap_prepare(struct vm_area_desc *desc)
 {
-	const unsigned long len = vma_desc_size(desc);
-
 	if (!vma_desc_test_any(desc, VMA_SHARED_BIT, VMA_MAYSHARE_BIT))
 		return -EINVAL;
 
-	vma_desc_set_flags(desc, VMA_LOCKED_BIT, VMA_DONTDUMP_BIT);
-	if (!mlock_future_ok(desc->mm, /*is_vma_locked=*/ true, len))
-		return -EAGAIN;
+	vma_desc_set_flags(desc, VMA_DONTDUMP_BIT);
 	desc->vm_ops = &secretmem_vm_ops;
 
 	return 0;
@@ -187,20 +264,40 @@ static const struct inode_operations sec
 
 static struct vfsmount *secretmem_mnt;
 
+static int secretmem_init_inode_priv(struct inode *inode)
+{
+	struct secretmem_inode_state *state;
+
+	state = kzalloc_obj(*state);
+	if (!state)
+		return -ENOMEM;
+
+	state->user = get_uid(current_user());
+	inode->i_private = state;
+	return 0;
+}
+
 static struct file *secretmem_file_create(unsigned long flags)
 {
 	struct file *file;
 	struct inode *inode;
 	const char *anon_name = "[secretmem]";
+	int err;
 
 	inode = anon_inode_make_secure_inode(secretmem_mnt->mnt_sb, anon_name, NULL);
 	if (IS_ERR(inode))
 		return ERR_CAST(inode);
 
+	err = secretmem_init_inode_priv(inode);
+	if (err)
+		goto err_free_inode;
+
 	file = alloc_file_pseudo(inode, secretmem_mnt, "secretmem",
 				 O_RDWR | O_LARGEFILE, &secretmem_fops);
-	if (IS_ERR(file))
-		goto err_free_inode;
+	if (IS_ERR(file)) {
+		err = PTR_ERR(file);
+		goto err_free_priv;
+	}
 
 	mapping_set_gfp_mask(inode->i_mapping, GFP_HIGHUSER);
 	mapping_set_unevictable(inode->i_mapping);
@@ -215,10 +312,11 @@ static struct file *secretmem_file_creat
 	atomic_inc(&secretmem_users);
 
 	return file;
-
+err_free_priv:
+	secretmem_destroy_inode_priv(inode);
 err_free_inode:
 	iput(inode);
-	return file;
+	return ERR_PTR(err);
 }
 
 SYSCALL_DEFINE1(memfd_secret, unsigned int, flags)
--- a/tools/testing/selftests/mm/memfd_secret.c
+++ b/tools/testing/selftests/mm/memfd_secret.c
@@ -57,33 +57,6 @@ static void test_file_apis(int fd)
 		pass("file IO is blocked as expected\n");
 }
 
-static void test_mlock_limit(int fd)
-{
-	size_t len;
-	char *mem;
-
-	len = mlock_limit_cur;
-	if (len % page_size != 0)
-		len = (len/page_size) * page_size;
-
-	mem = mmap(NULL, len, prot, mode, fd, 0);
-	if (mem == MAP_FAILED) {
-		fail("unable to mmap secret memory\n");
-		return;
-	}
-	munmap(mem, len);
-
-	len = mlock_limit_max * 2;
-	mem = mmap(NULL, len, prot, mode, fd, 0);
-	if (mem != MAP_FAILED) {
-		fail("unexpected mlock limit violation\n");
-		munmap(mem, len);
-		return;
-	}
-
-	pass("mlock limit is respected\n");
-}
-
 static void test_vmsplice(int fd, const char *desc)
 {
 	ssize_t transferred;
@@ -297,7 +270,7 @@ static void prepare(void)
 				   strerror(errno));
 }
 
-#define NUM_TESTS 6
+#define NUM_TESTS 5
 
 int main(int argc, char *argv[])
 {
@@ -319,7 +292,6 @@ int main(int argc, char *argv[])
 	if (ftruncate(fd, page_size))
 		ksft_exit_fail_msg("ftruncate failed: %s\n", strerror(errno));
 
-	test_mlock_limit(fd);
 	test_file_apis(fd);
 	/*
 	 * We have to run the first vmsplice test before any secretmem page was



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 098/556] futex: Prevent rcuwait use-after-free during requeue PI
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (96 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 097/556] mm/secretmem: properly account locked pages Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 099/556] futex: Provide rt_mutex_.*_schedule() equivalents for futex scheduling Greg Kroah-Hartman
                   ` (470 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yao Kai, Sebastian Andrzej Siewior,
	Thomas Gleixner

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yao Kai <yaokai34@huawei.com>

commit a3b8d46fe401cba3a5c46dea610e6eb3dc15370e upstream.

On PREEMPT_RT, FUTEX_CMP_REQUEUE_PI can trigger a KASAN report
(slab-out-of-bounds) in futex_requeue_pi_complete() invocation of
rcuwait_wake_up().

The futex_q used by futex_wait_requeue_pi() is allocated on the waiter's
stack. An early wakeup can race with a PI requeue as follows:

        waiter                          requeue task
        ------                          ------------
futex_wait_requeue_pi()
  futex_do_wait()
    schedule()
                                       futex_requeue
                                         futex_proxy_trylock_atomic()
                                           futex_requeue_pi_prepare()
                                            Q_REQUEUE_PI_NONE -> Q_REQUEUE_PI_IN_PROGRESS
* timeout/ signal wakes waiter *
  futex_requeue_pi_wakeup_sync()
   Q_REQUEUE_PI_IN_PROGRESS -> Q_REQUEUE_PI_WAIT
                                           requeue_pi_wake_futex
                                             futex_requeue_pi_complete()
                                               cmpxchg Q_REQUEUE_PI_WAIT -> Q_REQUEUE_PI_LOCKED
    rcuwait_wait_event()
      if (atomic_read(&q->requeue_state) != Q_REQUEUE_PI_WAIT)
       break /* no schedule() */

 /* q.pi_state->owner == current */
 futex_private_hash_put()
 /* return from syscall */
                                              rcuwait_wake_up(&q->requeue_wait)
                                                /* q is gone */

futex_requeue_pi_complete() publishes Q_REQUEUE_PI_LOCKED before
calling rcuwait_wake_up(). The waiter observes this state in
rcuwait_wait_event() before invoking schedule() in rcuwait_wait_event().
Here, the waiter is free leave the syscall before requeue task can
complete the wake.

To address this race skip rcuwait_wake_up() in the Q_REQUEUE_PI_LOCKED
case.
This state is only published by requeue_pi_wake_futex(), which saves
q->task before futex_requeue_pi_complete() and wakes the waiter via
wake_up_state().

This wake is intended to wake the waiter from its futex_do_wait() sleep.
If the waiter is still sleeping there, it can not get into the
Q_REQUEUE_PI_WAIT state (and require this removed wake).
Should the waiter be woken up from futex_do_wait() by other means (as in
this example) and sleep in futex_requeue_pi_wakeup_sync() then the
wake_up_state() from requeue_pi_wake_futex() will wake it, too.
Should the waiter task terminate before wake_up_state() had a chance to
wake the task then the task pointer does not become invalid because the
futex_hash_bucket::lock is held and the task pointer is RCU protected.

[bigeasy: Updated comment and commit message]

Fixes: 07d91ef510fb1 ("futex: Prevent requeue_pi() lock nesting issue on RT")
Signed-off-by: Yao Kai <yaokai34@huawei.com>
Signed-off-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Reviewed-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260901135453.3121948-3-bigeasy@linutronix.de
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 kernel/futex/requeue.c |   12 ++++++++++--
 1 file changed, 10 insertions(+), 2 deletions(-)

--- a/kernel/futex/requeue.c
+++ b/kernel/futex/requeue.c
@@ -154,8 +154,16 @@ static inline void futex_requeue_pi_comp
 	} while (!atomic_try_cmpxchg(&q->requeue_state, &old, new));
 
 #ifdef CONFIG_PREEMPT_RT
-	/* If the waiter interleaved with the requeue let it know */
-	if (unlikely(old == Q_REQUEUE_PI_WAIT))
+	/*
+	 * The waiter in futex_requeue_pi_wakeup_sync() can interleave with the
+	 * wake below: It will assign Q_REQUEUE_PI_IN_PROGRESS and here it will
+	 * be updated to Q_REQUEUE_PI_LOCKED (locked = 1). The rcuwait_wait_event()
+	 * will already read Q_REQUEUE_PI_LOCKED and skip the schedule() invocation,
+	 * leading to an access of futex_q::requeue_wait after the waiter returned.
+	 * In this case only we skip the wake here and rely on following wake in
+	 * requeue_pi_wake_futex() to perform the wake if needed.
+	 */
+	if (unlikely(old == Q_REQUEUE_PI_WAIT) && new != Q_REQUEUE_PI_LOCKED)
 		rcuwait_wake_up(&q->requeue_wait);
 #endif
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 099/556] futex: Provide rt_mutex_.*_schedule() equivalents for futex scheduling
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (97 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 098/556] futex: Prevent rcuwait use-after-free during requeue PI Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 100/556] ftrace: Take trace_array reference before accessing its ftrace_ops Greg Kroah-Hartman
                   ` (469 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yao Kai, Sebastian Andrzej Siewior,
	Thomas Gleixner

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sebastian Andrzej Siewior <bigeasy@linutronix.de>

commit 912edebe8501a36c6bedcef03bd238ab90a7e060 upstream.

There is rt_mutex_{pre|post}_schedule() around
rt_mutex_wait_proxy_lock() to ensure that sched_submit_work()/
sched_update_worker() is invoked before we schedule out and block on
rt_mutex while waiting for it become available.

The reason is that blocking on rt_mutex assigns a pi_waiter for the PI
chain and sched_submit_work() will also assign a pi_waiter if it blocks
on lock but a this point we already have a waiter assigned.
We can't skip sched_submit_work() entirely because I/O relies on the
fact that I/O queue is flushed while it blocks on a sleeping lock.
Therefore sched_submit_work() is moved before we block on the lock.

Sleeping lock in this context means mutex or rw_semaphore not spinlock_t
on PREEMPT_RT. Because the mutex abstraction on PREEMPT_RT uses the same
abstraction as the futex proxy lock, the futex code ended up using
rt_mutex_{pre|post}_schedule(), too.
Using it is/ was just to keep the task_struct::sched_rt_mutex assertion
happy. Futex proxy lock is used only in the syscall context of a task.
At this point it never got any I/O that needs to be flushed and it can't
be a workqueue that needs to notify that it will be scheduled out.
Therefore sched_submit_work() does nothing here.

By mistake futex_wait_requeue_pi() -> rt_mutex_wait_proxy_lock() did not
get the rt_mutex_{pre|post}_schedule() annotation. This was not noticed
because in this callchain the lock is (usually) not contended and so
rt_mutex_slowlock_block() does not schedule, triggering the assert.

Adding rt_mutex_pre_schedule() here looks wrong (as noted by PeterZ)
because at this point there is a pi_waiter recorded and invoking
sched_submit_work() with a possible lock contention would be wrong.

Add rt_mutex_futex_{pre|post}_schedule() which toggles the
sched_rt_mutex assert and does not involve sched_submit_work(). Add
asserts here to ensure that sched_submit_work() would do nothing. Use it
only in futex proxy lock case which is rt_mutex_wait_proxy_lock().
Remove it from futex_lock_pi().

Fixes: d14f9e930b90 ("locking/rtmutex: Use rt_mutex specific scheduler helpers")
Reported-by: Yao Kai <yaokai34@huawei.com>
Signed-off-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260901135453.3121948-2-bigeasy@linutronix.de
Closes: https://lore.kernel.org/all/20260717084922.4153317-2-yaokai34@huawei.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 include/linux/sched/rt.h     |    2 ++
 kernel/futex/pi.c            |   16 +++-------------
 kernel/locking/rtmutex_api.c |    2 ++
 kernel/sched/core.c          |   16 ++++++++++++++++
 4 files changed, 23 insertions(+), 13 deletions(-)

--- a/include/linux/sched/rt.h
+++ b/include/linux/sched/rt.h
@@ -52,8 +52,10 @@ static inline bool rt_or_dl_task_policy(
 
 #ifdef CONFIG_RT_MUTEXES
 extern void rt_mutex_pre_schedule(void);
+extern void rt_mutex_futex_pre_schedule(void);
 extern void rt_mutex_schedule(void);
 extern void rt_mutex_post_schedule(void);
+extern void rt_mutex_futex_post_schedule(void);
 
 /*
  * Must hold either p->pi_lock or task_rq(p)->lock.
--- a/kernel/futex/pi.c
+++ b/kernel/futex/pi.c
@@ -1070,17 +1070,11 @@ retry_private:
 		 * Caution; releasing @hb in-scope. The hb->lock is still locked
 		 * while the reference is dropped. The reference can not be dropped
 		 * after the unlock because if a user initiated resize is in progress
-		 * then we might need to wake him. This can not be done after the
-		 * rt_mutex_pre_schedule() invocation. The hb will remain valid because
-		 * the thread, performing resize, will block on hb->lock during
-		 * the requeue.
+		 * then we might need to wake him. The hb will remain valid
+		 * because the thread, performing resize, will block on
+		 * hb->lock during the requeue.
 		 */
 		futex_private_hash_put(no_free_ptr(hbr.fph));
-		/*
-		 * Must be done before we enqueue the waiter, here is unfortunately
-		 * under the hb lock, but that *should* work because it does nothing.
-		 */
-		rt_mutex_pre_schedule();
 
 		rt_mutex_init_waiter(&rt_waiter);
 
@@ -1146,10 +1140,6 @@ cleanup:
 		 * the
 		 */
 		futex_q_lockptr_lock(&q);
-		/*
-		 * Waiter is unqueued.
-		 */
-		rt_mutex_post_schedule();
 no_block:
 		/*
 		 * Fixup the pi_state owner and possibly acquire the lock if we
--- a/kernel/locking/rtmutex_api.c
+++ b/kernel/locking/rtmutex_api.c
@@ -423,6 +423,7 @@ int __sched rt_mutex_wait_proxy_lock(str
 {
 	int ret;
 
+	rt_mutex_futex_pre_schedule();
 	raw_spin_lock_irq(&lock->wait_lock);
 	/* sleep on the mutex */
 	set_current_state(TASK_INTERRUPTIBLE);
@@ -433,6 +434,7 @@ int __sched rt_mutex_wait_proxy_lock(str
 	 */
 	fixup_rt_mutex_waiters(lock, true);
 	raw_spin_unlock_irq(&lock->wait_lock);
+	rt_mutex_futex_post_schedule();
 
 	return ret;
 }
--- a/kernel/sched/core.c
+++ b/kernel/sched/core.c
@@ -7633,6 +7633,17 @@ void rt_mutex_pre_schedule(void)
 	sched_submit_work(current);
 }
 
+/*
+ * Used within the futex syscall context, skips sched_submit_work() because none
+ * its work will be done. Asserts ensure that it is indeed the case.
+ */
+void rt_mutex_futex_pre_schedule(void)
+{
+	lockdep_assert(!(current->flags & (PF_WQ_WORKER | PF_IO_WORKER)));
+	lockdep_assert(!current->plug);
+	lockdep_assert(!fetch_and_set(current->sched_rt_mutex, 1));
+}
+
 void rt_mutex_schedule(void)
 {
 	lockdep_assert(current->sched_rt_mutex);
@@ -7645,6 +7656,11 @@ void rt_mutex_post_schedule(void)
 	lockdep_assert(fetch_and_set(current->sched_rt_mutex, 0));
 }
 
+void rt_mutex_futex_post_schedule(void)
+{
+	lockdep_assert(fetch_and_set(current->sched_rt_mutex, 0));
+}
+
 /*
  * rt_mutex_setprio - set the current priority of a task
  * @p: task to boost



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 100/556] ftrace: Take trace_array reference before accessing its ftrace_ops
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (98 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 099/556] futex: Provide rt_mutex_.*_schedule() equivalents for futex scheduling Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 101/556] ftrace: Synchronize the initialization of ftrace_ops Greg Kroah-Hartman
                   ` (468 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Breno Leitao, Steven Rostedt

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Steven Rostedt <rostedt@goodmis.org>

commit 9100191e5acb2e5ea2313f436667bb5fce129f47 upstream.

The trace instance files set_ftrace_filter and set_ftrace_notrace was
updated to work with specific trace instances (trace_arrays). The issue is
that when these files are opened, there is a small race window where it
will use the ftrace_ops from the inode->private pointer to get a reference
to the trace_array and then take its reference. The problem is that the
ftrace_ops itself could be freed. If the rmdir on the instance happens at
the same time the set_ftrace_filter file is opened, the rmdir could have
also freed the ftrace_ops and referencing it will cause a use-after-free
bug and crash the kernel.

Instead, pass in the trace_array as the file private data (NULL for the
top level instance), and then pass both the trace_array and the ftrace_ops
to the ftrace_regex_open() function. If the trace_array is NULL, then it
just uses the ftrace_ops without the need to take its reference (like
normal). If the ftrace_ops is NULL, that is only the case for the top
level instance and the global_ops can be used.

This allows the trace_array to have its reference incremented before
touching the ftrace_ops that could also be freed when the instance is.

Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260828223901.29e26edb@robin
Fixes: 591dffdade9f0 ("ftrace: Allow for function tracing instance to filter functions")
Reported-by: Breno Leitao <leitao@debian.org>
Tested-by: Breno Leitao <leitao@debian.org>
Closes: https://lore.kernel.org/all/apGORjltZgAiAYHT@gmail.com/
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 include/linux/ftrace.h         |    5 ++-
 kernel/trace/ftrace.c          |   57 ++++++++++++++++++++++++++---------------
 kernel/trace/trace.h           |    5 ++-
 kernel/trace/trace_functions.c |    2 -
 kernel/trace/trace_stack.c     |    2 -
 5 files changed, 45 insertions(+), 26 deletions(-)

--- a/include/linux/ftrace.h
+++ b/include/linux/ftrace.h
@@ -866,8 +866,9 @@ unsigned long ftrace_get_addr_new(struct
 unsigned long ftrace_get_addr_curr(struct dyn_ftrace *rec);
 
 extern ftrace_func_t ftrace_trace_function;
+struct trace_array;
 
-int ftrace_regex_open(struct ftrace_ops *ops, int flag,
+int ftrace_regex_open(struct trace_array *tr, struct ftrace_ops *ops, int flag,
 		  struct inode *inode, struct file *file);
 ssize_t ftrace_filter_write(struct file *file, const char __user *ubuf,
 			    size_t cnt, loff_t *ppos);
@@ -1077,7 +1078,7 @@ static inline unsigned long ftrace_locat
  * have them defined when ftrace is not enabled, but these
  * functions may still be called. Use a macro instead of inline.
  */
-#define ftrace_regex_open(ops, flag, inod, file) ({ -ENODEV; })
+#define ftrace_regex_open(tr, ops, flag, inode, file) ({ -ENODEV; })
 #define ftrace_set_early_filter(ops, buf, enable) do { } while (0)
 #define ftrace_set_filter_ip(ops, ip, remove, reset) ({ -ENODEV; })
 #define ftrace_set_filter_ips(ops, ips, cnt, remove, reset) ({ -ENODEV; })
--- a/kernel/trace/ftrace.c
+++ b/kernel/trace/ftrace.c
@@ -4677,7 +4677,8 @@ ftrace_avail_addrs_open(struct inode *in
 
 /**
  * ftrace_regex_open - initialize function tracer filter files
- * @ops: The ftrace_ops that hold the hash filters
+ * @tr: The trace_array that holds the ftrace_ops [optional]
+ * @ops: The ftrace_ops that hold the hash filters [optional]
  * @flag: The type of filter to process
  * @inode: The inode, usually passed in to your open routine
  * @file: The file, usually passed in to your open routine
@@ -4691,26 +4692,45 @@ ftrace_avail_addrs_open(struct inode *in
  * tracing_lseek() should be used as the lseek routine, and
  * release must call ftrace_regex_release().
  *
+ * Note, If @tr is not NULL, its reference has to be taken before
+ *       @ops may be referenced.
+ *       If @ops is NULL and @tr is not, then @tr->ops is used.
+ *       If @tr is NULL and @ops is not then @ops->private is uesd for @tr.
+ *       If both @tr and @ops are NULL, then the &global_ops is
+ *         to be used, and @tr will be the global_ops.private pointer.
+ *
  * Returns: 0 on success or a negative errno value on failure
  */
 int
-ftrace_regex_open(struct ftrace_ops *ops, int flag,
+ftrace_regex_open(struct trace_array *tr, struct ftrace_ops *ops, int flag,
 		  struct inode *inode, struct file *file)
 {
-	struct ftrace_iterator *iter;
+	struct ftrace_iterator *iter = NULL;
 	struct ftrace_hash *hash;
 	struct list_head *mod_head;
-	struct trace_array *tr = ops->private;
-	int ret = -ENOMEM;
-
-	ftrace_ops_init(ops);
+	int ret = -ENODEV;
 
 	if (unlikely(ftrace_disabled))
 		return -ENODEV;
 
+	if (!tr) {
+		if (!ops)
+			ops = &global_ops;
+		tr = ops->private;
+	}
+
 	if (tracing_check_open_get_tr(tr))
 		return -ENODEV;
 
+	if (!ops)
+		ops = tr->ops;
+
+	if (WARN_ON_ONCE(!ops))
+		goto out;
+
+	ftrace_ops_init(ops);
+
+	ret = -ENOMEM;
 	iter = kzalloc_obj(*iter);
 	if (!iter)
 		goto out;
@@ -4788,21 +4808,19 @@ ftrace_regex_open(struct ftrace_ops *ops
 static int
 ftrace_filter_open(struct inode *inode, struct file *file)
 {
-	struct ftrace_ops *ops = inode->i_private;
+	struct trace_array *tr = inode->i_private;
 
-	/* Checks for tracefs lockdown */
-	return ftrace_regex_open(ops,
-			FTRACE_ITER_FILTER | FTRACE_ITER_DO_PROBES,
-			inode, file);
+	return ftrace_regex_open(tr, NULL,
+				 FTRACE_ITER_FILTER | FTRACE_ITER_DO_PROBES,
+				 inode, file);
 }
 
 static int
 ftrace_notrace_open(struct inode *inode, struct file *file)
 {
-	struct ftrace_ops *ops = inode->i_private;
+	struct trace_array *tr = inode->i_private;
 
-	/* Checks for tracefs lockdown */
-	return ftrace_regex_open(ops, FTRACE_ITER_NOTRACE,
+	return ftrace_regex_open(tr, NULL, FTRACE_ITER_NOTRACE,
 				 inode, file);
 }
 
@@ -7492,15 +7510,15 @@ static const struct file_operations ftra
 };
 #endif /* CONFIG_FUNCTION_GRAPH_TRACER */
 
-void ftrace_create_filter_files(struct ftrace_ops *ops,
+void ftrace_create_filter_files(struct trace_array *tr,
 				struct dentry *parent)
 {
 
 	trace_create_file("set_ftrace_filter", TRACE_MODE_WRITE, parent,
-			  ops, &ftrace_filter_fops);
+			  tr, &ftrace_filter_fops);
 
 	trace_create_file("set_ftrace_notrace", TRACE_MODE_WRITE, parent,
-			  ops, &ftrace_notrace_fops);
+			  tr, &ftrace_notrace_fops);
 }
 
 /*
@@ -7525,7 +7543,6 @@ void ftrace_destroy_filter_files(struct
 
 static __init int ftrace_init_dyn_tracefs(struct dentry *d_tracer)
 {
-
 	trace_create_file("available_filter_functions", TRACE_MODE_READ,
 			d_tracer, NULL, &ftrace_avail_fops);
 
@@ -7538,7 +7555,7 @@ static __init int ftrace_init_dyn_tracef
 	trace_create_file("touched_functions", TRACE_MODE_READ,
 			d_tracer, NULL, &ftrace_touched_fops);
 
-	ftrace_create_filter_files(&global_ops, d_tracer);
+	ftrace_create_filter_files(NULL, d_tracer);
 
 #ifdef CONFIG_FUNCTION_GRAPH_TRACER
 	trace_create_file("set_graph_function", TRACE_MODE_WRITE, d_tracer,
--- a/kernel/trace/trace.h
+++ b/kernel/trace/trace.h
@@ -1340,7 +1340,7 @@ extern void clear_ftrace_function_probes
 int register_ftrace_command(struct ftrace_func_command *cmd);
 int unregister_ftrace_command(struct ftrace_func_command *cmd);
 
-void ftrace_create_filter_files(struct ftrace_ops *ops,
+void ftrace_create_filter_files(struct trace_array *tr,
 				struct dentry *parent);
 void ftrace_destroy_filter_files(struct ftrace_ops *ops);
 
@@ -1363,11 +1363,12 @@ static inline void clear_ftrace_function
 {
 }
 
+static inline void ftrace_create_filter_files(struct trace_array *tr,
+					      struct dentry *parent) { }
 /*
  * The ops parameter passed in is usually undefined.
  * This must be a macro.
  */
-#define ftrace_create_filter_files(ops, parent) do { } while (0)
 #define ftrace_destroy_filter_files(ops) do { } while (0)
 #endif /* CONFIG_FUNCTION_TRACER && CONFIG_DYNAMIC_FTRACE */
 
--- a/kernel/trace/trace_functions.c
+++ b/kernel/trace/trace_functions.c
@@ -101,7 +101,7 @@ int ftrace_create_function_files(struct
 		return ret;
 	}
 
-	ftrace_create_filter_files(tr->ops, parent);
+	ftrace_create_filter_files(tr, parent);
 
 	return 0;
 }
--- a/kernel/trace/trace_stack.c
+++ b/kernel/trace/trace_stack.c
@@ -499,7 +499,7 @@ stack_trace_filter_open(struct inode *in
 	struct ftrace_ops *ops = inode->i_private;
 
 	/* Checks for tracefs lockdown */
-	return ftrace_regex_open(ops, FTRACE_ITER_FILTER,
+	return ftrace_regex_open(NULL, ops, FTRACE_ITER_FILTER,
 				 inode, file);
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 101/556] ftrace: Synchronize the initialization of ftrace_ops
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (99 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 100/556] ftrace: Take trace_array reference before accessing its ftrace_ops Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 102/556] HID: bpf: serialize device reference release in struct_ops destroy path Greg Kroah-Hartman
                   ` (467 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, sashiko-bot, Steven Rostedt

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Steven Rostedt <rostedt@goodmis.org>

commit 4617721c502b2ddaa4e324e86da4997edf738fa5 upstream.

There's some internal state that ftrace_ops needs to have set, but since
it can be declared outside of the ftrace.c code, it calls
ftrace_ops_init() on the ops in every global function. The issue is that
if two tasks call it on the same ops at the same time it is possible to
have the initialization of one corrupt the initialization of the other
call.

Create a ops_mutex to use to synchronize every initialization of the
ftrace_ops. The mutex is taken within checking the ftrace_ops flag that
states it was initializied but the flag is checked again after the mutex
has been taken. Checking first outside the mutex allows it to shortcut
having to take the mutex. But then the check needs to be done again after
the mute is taken in case of races.

Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260902095501.6b59af20@gandalf.local.home
Fixes: f04f24fb7e48d ("ftrace, kprobes: Fix a deadlock on ftrace_regex_lock")
Reported-by: sashiko-bot@kernel.org
Close: https://lore.kernel.org/all/20260829025528.49A831F000E9@smtp.kernel.org/
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 kernel/trace/ftrace.c |   13 +++++++++++--
 1 file changed, 11 insertions(+), 2 deletions(-)

--- a/kernel/trace/ftrace.c
+++ b/kernel/trace/ftrace.c
@@ -75,6 +75,8 @@
 	.func_hash		= &opsname.local_hash,			\
 	.local_hash.regex_lock	= __MUTEX_INITIALIZER(opsname.local_hash.regex_lock), \
 	.subop_list		= LIST_HEAD_INIT(opsname.subop_list),
+/* Used only to synchronize the initialization of ftrace_ops */
+static DEFINE_MUTEX(ops_mutex);
 #else
 #define INIT_OPS_HASH(opsname)
 #endif
@@ -159,11 +161,18 @@ const struct ftrace_ops ftrace_nop_ops =
 static inline void ftrace_ops_init(struct ftrace_ops *ops)
 {
 #ifdef CONFIG_DYNAMIC_FTRACE
-	if (!(ops->flags & FTRACE_OPS_FL_INITIALIZED)) {
+	unsigned long flags = smp_load_acquire(&ops->flags);
+
+	if (!(flags & FTRACE_OPS_FL_INITIALIZED)) {
+		guard(mutex)(&ops_mutex);
+		/* Could have been initialized before lock taken */
+		if (unlikely(ops->flags & FTRACE_OPS_FL_INITIALIZED))
+			return;
 		mutex_init(&ops->local_hash.regex_lock);
 		INIT_LIST_HEAD(&ops->subop_list);
 		ops->func_hash = &ops->local_hash;
-		ops->flags |= FTRACE_OPS_FL_INITIALIZED;
+		flags = ops->flags | FTRACE_OPS_FL_INITIALIZED;
+		smp_store_release(&ops->flags, flags);
 	}
 #endif
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 102/556] HID: bpf: serialize device reference release in struct_ops destroy path
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (100 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 101/556] ftrace: Synchronize the initialization of ftrace_ops Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 103/556] HID: rmi: fix OOB access with undersized RMI reports Greg Kroah-Hartman
                   ` (466 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Shen Yongchao, Benjamin Tissoires

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Shen Yongchao <grayhat@foxmail.com>

commit 9cdc7e6dc7a99ad7311ad5e7c145f2b9ce4e24b0 upstream.

__hid_bpf_ops_destroy_device() and hid_bpf_unreg() can race on the
same registration reference, double-putting struct hid_device and
freeing it while hid_destroy_device() still uses it.  Serialize the
remove/NULL decision under hdev->bpf.prog_list_lock so exactly one
path releases each registration reference: unreg re-checks ops->hdev
under the lock and returns without putting when the destroy path
already cleared it; all put_device() calls happen after the lock is
dropped, which is safe because a concurrent unreg then observes
ops->hdev == NULL under the lock.

Background: each successful attach (hid_bpf_ops_reg) acquires one
device reference (hid_get_device()).  Two paths can release it:

- device destruction: hid_destroy_device() -> hid_bpf_destroy_device()
  -> __hid_bpf_ops_destroy_device(), which walks hdev->bpf.prog_list
  under rcu_read_lock() and drops one reference per attached program;
- BPF link release: bpf map delete (no BPF_F_LINK) synchronously calls
  st_ops->unreg() -> hid_bpf_unreg(), which drops the reference for
  its own registration.

The coordination handshake (e->hdev = NULL on the destroy side vs
"if (!hdev) return" on the unreg side) is a TOCTOU check: the two
paths run under different lock domains (rcu_read_lock vs
prog_list_lock), so a concurrent unreg can read ops->hdev as
non-NULL, block on prog_list_lock, and then proceed while the
destroy traversal executes - both paths then drop the same
reference.  The refcount reaches zero legitimately (each decrement
is individually valid), so no refcount_t saturation fires: the
device is simply freed while the transport is still inside
hid_destroy_device(), and subsequent teardown touches freed memory.

The fix serializes the remove/NULL decision under prog_list_lock on
both sides and moves the destroy-side puts outside the lock.  With
the lock held, plain reads/writes of ops->hdev are sufficient; no
READ_ONCE/WRITE_ONCE are added, keeping the patch minimal.

Unlocked-read safety: the unlocked read of ops->hdev at the top of
hid_bpf_unreg() cannot touch a freed device, because the unreg path
itself still holds this registration's reference (released only by
its own hid_put_device() after the lock is dropped), and a destroy
traversal that already cleared ops->hdev makes the lock-internal
re-check return early without any put.  At most one of the two
paths releases each registration reference.

Fixes: ebc0d8093e8c ("HID: bpf: implement HID-BPF through bpf_struct_ops")
Cc: stable@vger.kernel.org
Signed-off-by: Shen Yongchao <grayhat@foxmail.com>
Assisted-by: Hermes:kimi-k3
Signed-off-by: Benjamin Tissoires <bentiss@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/hid/bpf/hid_bpf_struct_ops.c |   17 +++++++++++++----
 1 file changed, 13 insertions(+), 4 deletions(-)

--- a/drivers/hid/bpf/hid_bpf_struct_ops.c
+++ b/drivers/hid/bpf/hid_bpf_struct_ops.c
@@ -250,6 +250,11 @@ static void hid_bpf_unreg(void *kdata, s
 
 	mutex_lock(&hdev->bpf.prog_list_lock);
 
+	if (!ops->hdev) {
+		mutex_unlock(&hdev->bpf.prog_list_lock);
+		return;
+	}
+
 	list_del_rcu(&ops->list);
 	synchronize_srcu(&hdev->bpf.srcu);
 	ops->hdev = NULL;
@@ -310,13 +315,17 @@ static struct bpf_struct_ops bpf_hid_bpf
 void __hid_bpf_ops_destroy_device(struct hid_device *hdev)
 {
 	struct hid_bpf_ops *e;
+	int count = 0;
 
-	rcu_read_lock();
-	list_for_each_entry_rcu(e, &hdev->bpf.prog_list, list) {
-		hid_put_device(hdev);
+	mutex_lock(&hdev->bpf.prog_list_lock);
+	list_for_each_entry(e, &hdev->bpf.prog_list, list) {
 		e->hdev = NULL;
+		count++;
 	}
-	rcu_read_unlock();
+	mutex_unlock(&hdev->bpf.prog_list_lock);
+
+	while (count--)
+		hid_put_device(hdev);
 }
 
 static int __init hid_bpf_struct_ops_init(void)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 103/556] HID: rmi: fix OOB access with undersized RMI reports
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (101 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 102/556] HID: bpf: serialize device reference release in struct_ops destroy path Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 104/556] HID: wacom: validate report length in wacom_intuos_pro2_bt_irq Greg Kroah-Hartman
                   ` (465 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Wei Jie Law, Jiri Kosina

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wei Jie Law <98lawweijie@gmail.com>

commit 4956993bb3befdf791d71a4952d8d13bcfd44c7b upstream.

The hid-rmi driver sizes its writeReport/readReport buffer purely from
the report descriptor supplied by the device, with no minimum bound:

	data->input_report_size  = hid_report_len(input_report);
	data->output_report_size = hid_report_len(output_report);
	alloc_size = data->output_report_size + data->input_report_size;
	data->writeReport = devm_kzalloc(&hdev->dev, alloc_size, GFP_KERNEL);
	data->readReport = data->writeReport + data->output_report_size;

but then reads and writes fixed offsets into it.  A device declaring a
1-byte output and a 1-byte input report makes hid_report_len() return 2
for each, so alloc_size is 4, while rmi_set_page() -- reached
unconditionally at probe time through rmi_input_configured() -- stores
writeReport[4] and rmi_hid_read_block() stores writeReport[0..5].  Since
readReport lives at writeReport + output_report_size, those stores also
corrupt the window the next reply is parsed out of.

The read path is worse: the copy length comes from readReport[1], which
the device fills in and can be up to 255, and the copy starts at
&readReport[2] with no regard for input_report_size, so it runs past the
end of the allocation into adjacent slab objects.  This does not even
need a lying device -- rmi_f01_probe() issues a fixed 21-byte register
read, so any device declaring an input report smaller than 23 bytes
reads out of bounds even when it answers truthfully.  Those bytes become
the register values the RMI core acts on: rmi_f01_probe() prints them to
the kernel log as the product id and exports them through the mode 0444
sysfs attribute of the same name, and rmi_driver_set_irq_bits() sends
them back to the device as the interrupt mask, so an undersized report
descriptor leaks heap contents both to unprivileged userspace and to the
device itself.

The write path has no bound either: rmi_hid_write_block() copies an
unbounded len to &writeReport[4], and the largest caller a device can
drive at probe time is rmi_driver_set_irq_bits(), whose length is
derived from the interrupt source counts the device declares in its Page
Description Table.

Finally, the read loop cannot terminate on a zero-length reply: such a
reply copies nothing and advances neither bytes_read nor bytes_needed,
and because a reply did arrive the one second wait_event_timeout() does
not fire either, so a device answering 0 forever keeps the loop running
inside the probe worker with page_mutex held.  khungtaskd does not
notice, because every reply wakes the task.

Reject reports too small for what the driver builds -- 6 output bytes
for the write reports and 3 input bytes for the read handshake -- at
probe time, clamp the write and the read copy to the report sizes the
device declared, and treat a zero-length reply as an error.  A device
refused this way is started as an ordinary HID device, like one that
does not carry the RMI report ids at all.

RMI_DEVICE must not be left set in device_flags on that path, because
rmi_input_configured() would then run the RMI setup and reach
rmi_set_page(), which writes the writeReport buffer the refusal just
skipped allocating.  The bit can arrive set: rmi_probe() copies
id->driver_data into device_flags before the report checks, and a bind
through the new_id sysfs attribute can supply driver_data with
RMI_DEVICE (BIT(0)) set.  Strip the bit where driver_data is copied, so
RMI_DEVICE keeps meaning exactly "this probe validated the reports"; the
three jumps to start that predate this patch are covered as well.

The error path also clears RMI_READ_DATA_PENDING on its way out, because
that flag is what the wait at the top of the loop tests: leaving it set
would make every later wait_event_timeout() return immediately on the
stale reply and kill the read path for the rest of the device's life.

Clamping does not regress working hardware: the read loop already
handles a reply carrying fewer bytes than requested, and a write longer
than the output report was overrunning the buffer already.

Verified on v6.12.69 and on v6.12.105 built with CONFIG_KASAN=y and
booted kasan_multi_shot, whose hid-rmi.c is identical to mainline here.
An emulated RMI4 device driven over /dev/uhid, and the same device again
over dummy_hcd plus raw-gadget, give identical results:

  BUG: KASAN: slab-out-of-bounds in rmi_hid_read_block+0x409/0x750 [hid_rmi]
  Read of size 21 at addr ffff88800bf33bba by task kworker/0:3/285
   __asan_memcpy+0x23/0x60
   rmi_hid_read_block+0x409/0x750 [hid_rmi]
   rmi_f01_probe+0x5dd/0x1dc0 [rmi_core]

  BUG: KASAN: slab-out-of-bounds in rmi_hid_write_block+0x1a9/0x350 [hid_rmi]
  Write of size 35 at addr ffff88810a2b24ac by task kworker/1:10/666
   __asan_memcpy+0x3c/0x60
   rmi_hid_write_block+0x1a9/0x350 [hid_rmi]
   rmi_driver_set_irq_bits+0x1f6/0x4d0 [rmi_core]
   rmi_driver_probe+0x636/0xbf0 [rmi_core]
   rmi_input_configured+0x184/0x2e0 [hid_rmi]
   rmi_probe+0x952/0xcf0 [hid_rmi]

and, for the zero-length reply, a probe worker left in D state in
rmi_hid_read_block() after 225 replies at 200 ms intervals.

After this change the undersized descriptor is refused at probe with
"rmi reports too small (out=2 in=2)", the oversized read and write are
both rejected, the zero-length reply fails the read with -EIO while
later reads on the same device keep working, and a device declaring
reports large enough for a 21-byte register read still probes normally
and reports its real product id.  A device bound through new_id with
RMI_DEVICE in its driver_data no longer reaches rmi_set_page() with an
unallocated writeReport either.

Link: https://lore.kernel.org/linux-input/20260822121007.153988-1-98lawweijie@gmail.com/
Link: https://lore.kernel.org/linux-input/00a489f38b240624dcb5a4bae36a53fcba9cfb47.1787549195.git.98lawweijie@gmail.com/
Link: https://lore.kernel.org/linux-input/20260824122708.76168-1-98lawweijie@gmail.com/
Link: https://lore.kernel.org/linux-input/20260825060954.104890-1-98lawweijie@gmail.com/
Fixes: 9fb6bf02e3ad ("HID: rmi: introduce RMI driver for Synaptics touchpads")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-5
Assisted-by: GLM:glm-5.3
Signed-off-by: Wei Jie Law <98lawweijie@gmail.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/hid/hid-rmi.c |   46 +++++++++++++++++++++++++++++++++++++++++++---
 1 file changed, 43 insertions(+), 3 deletions(-)

--- a/drivers/hid/hid-rmi.c
+++ b/drivers/hid/hid-rmi.c
@@ -235,7 +235,23 @@ static int rmi_hid_read_block(struct rmi
 				break;
 			}
 
-			read_input_count = data->readReport[1];
+			read_input_count = min_t(int, data->readReport[1],
+						 data->input_report_size - 2);
+			if (!read_input_count) {
+				/*
+				 * A zero length reply advances neither
+				 * bytes_read nor bytes_needed, and because a
+				 * reply did arrive the wait above does not
+				 * time out either, so a device answering 0
+				 * forever would spin here indefinitely with
+				 * page_mutex held.
+				 */
+				hid_warn(hdev, "%s: zero-length read reply\n",
+					 __func__);
+				clear_bit(RMI_READ_DATA_PENDING, &data->flags);
+				ret = -EIO;
+				break;
+			}
 			memcpy(buf + bytes_read, &data->readReport[2],
 				min(read_input_count, bytes_needed));
 
@@ -271,6 +287,11 @@ static int rmi_hid_write_block(struct rm
 			goto exit;
 	}
 
+	if (len + 4 > data->output_report_size) {
+		ret = -EINVAL;
+		goto exit;
+	}
+
 	data->writeReport[0] = RMI_WRITE_REPORT_ID;
 	data->writeReport[1] = len;
 	data->writeReport[2] = addr & 0xFF;
@@ -666,8 +687,16 @@ static int rmi_probe(struct hid_device *
 		return ret;
 	}
 
-	if (id->driver_data)
-		data->device_flags = id->driver_data;
+	/*
+	 * RMI_DEVICE can only mean "this probe validated the RMI reports and
+	 * allocated writeReport": every bail-out to start below skips that
+	 * allocation, and device_flags left carrying RMI_DEVICE from
+	 * driver_data would send rmi_input_configured() into rmi_set_page()
+	 * with writeReport still NULL.  A bind through the new_id sysfs
+	 * attribute can supply driver_data with the bit set, so do not let
+	 * driver_data grant it.
+	 */
+	data->device_flags = id->driver_data & ~RMI_DEVICE;
 
 	/*
 	 * Check for the RMI specific report ids. If they are misisng
@@ -696,6 +725,17 @@ static int rmi_probe(struct hid_device *
 
 	data->output_report_size = hid_report_len(output_report);
 
+	/*
+	 * The write reports built by this driver occupy 6 bytes and the read
+	 * handshake looks at the first 3 bytes of an input report, so refuse
+	 * to drive a device whose reports cannot hold them.
+	 */
+	if (data->output_report_size < 6 || data->input_report_size < 3) {
+		hid_err(hdev, "rmi reports too small (out=%u in=%u)\n",
+			data->output_report_size, data->input_report_size);
+		goto start;
+	}
+
 	data->device_flags |= RMI_DEVICE;
 	alloc_size = data->output_report_size + data->input_report_size;
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 104/556] HID: wacom: validate report length in wacom_intuos_pro2_bt_irq
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (102 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 103/556] HID: rmi: fix OOB access with undersized RMI reports Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 105/556] dm: fix race when loading and unloading a table Greg Kroah-Hartman
                   ` (464 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ibrahim Hashimov, Jason Gerecke,
	Jiri Kosina

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ibrahim Hashimov <security@auditcode.ai>

commit a8e04f3f894ccb52cfcd7e60125a9f35da4a616d upstream.

wacom_intuos_pro2_bt_irq() receives the wire report length in `len`
but never consults it before parsing. After the report-id gate it
unconditionally calls wacom_intuos_pro2_bt_pen() and then, selected by
features.type, a fixed chain of sub-parsers, none of which receive
`len`:

	wacom_intuos_pro2_bt_pen(wacom);
	if (type == INTUOSP2_BT || type == INTUOSP2S_BT) {
		wacom_intuos_pro2_bt_touch(wacom);
		wacom_intuos_pro2_bt_pad(wacom);
		wacom_intuos_pro2_bt_battery(wacom);
	} else {
		wacom_intuos_gen3_bt_pad(wacom);
		wacom_intuos_gen3_bt_battery(wacom);
	}

Each sub-parser dereferences wacom->data at fixed offsets. The furthest
byte touched on each branch is:

  INTUOSP2_BT / INTUOSP2S_BT: wacom_intuos_pro2_bt_pad() reads data[285]
	(the touchring byte), so the report must be at least 286 bytes;
  INTUOSHT3_BT ("gen3"): wacom_intuos_gen3_bt_battery() reads data[45],
	so the report must be at least 46 bytes.

features.type is selected from the VID/PID id_table entry and
wacom_setup_device_quirks() force-registers the pen/pad/touch inputs
for that type independent of the report descriptor, so a malicious or
malfunctioning paired/spoofed Bluetooth peripheral can advertise that
VID/PID and send an undersized report that still satisfies the
data[0] == 0x80/0x81 gate. The driver then reads past the received
report and forwards the bytes to userspace via evdev (MSC_SERIAL /
ABS_MISC / ABS_WHEEL on the pen and pad input nodes), an out-of-bounds
read with a concrete userspace read-back channel, and a true
out-of-bounds read on transports whose backing buffer is sized to the
(small) report descriptor rather than a fixed-size staging buffer.

This is the same class of bug commit 2f1763f62909 ("HID: wacom: fix
out-of-bounds read in wacom_intuos_bt_irq") already hardened in the
sibling wacom_intuos_bt_irq(), which guards each report id against its
minimum length before parsing.

Guard wacom_intuos_pro2_bt_irq() the same way: before parsing, reject
reports shorter than the furthest offset the selected branch actually
dereferences, warn, and bail out. Because the whole pen/touch/pad/
battery chain runs unconditionally per branch, a single up-front check
against the maximum offset (286 bytes for INTUOSP2_BT/INTUOSP2S_BT,
46 bytes for the gen3 branch) bounds every sub-parser. Returning 0 on
a short report also skips those calls for the same malformed report,
which is the safe, conservative behavior.

Fixes: 4922cd26f03c ("HID: wacom: Support 2nd-gen Intuos Pro's Bluetooth classic interface")
Cc: stable@vger.kernel.org
Signed-off-by: Ibrahim Hashimov <security@auditcode.ai>
Assisted-by: AuditCode-AI:2026.07
Acked-by: Jason Gerecke <jason.gerecke@wacom.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/hid/wacom_wac.c |   13 +++++++++++++
 1 file changed, 13 insertions(+)

--- a/drivers/hid/wacom_wac.c
+++ b/drivers/hid/wacom_wac.c
@@ -1548,6 +1548,19 @@ static int wacom_intuos_pro2_bt_irq(stru
 		return 0;
 	}
 
+	if (wacom->features.type == INTUOSP2_BT ||
+	    wacom->features.type == INTUOSP2S_BT) {
+		if (len < 286) {
+			dev_warn(wacom->pen_input->dev.parent,
+				 "Pro2 BT report too short: %zu bytes\n", len);
+			return 0;
+		}
+	} else if (len < 46) {
+		dev_warn(wacom->pen_input->dev.parent,
+			 "Pro2 BT report too short: %zu bytes\n", len);
+		return 0;
+	}
+
 	wacom_intuos_pro2_bt_pen(wacom);
 	if (wacom->features.type == INTUOSP2_BT ||
 	    wacom->features.type == INTUOSP2S_BT) {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 105/556] dm: fix race when loading and unloading a table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (103 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 104/556] HID: wacom: validate report length in wacom_intuos_pro2_bt_irq Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 106/556] dm: fix resume-vs-remove race Greg Kroah-Hartman
                   ` (463 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Mikulas Patocka

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mikulas Patocka <mpatocka@redhat.com>

commit 5380c7f6335cc6d77eb77d065105e81155c4d9d3 upstream.

If the userspace calls two concurrent table load ioctls and one of them
succeeds and the other fails, there is a race condition because
dm_setup_md_queue walks &md->table_devices without any lock. If the walk
races with dm_table_destroy -> free_devices -> dm_put_table_device, there
is access to invalid memory.

Fix this race by extending the lock over the list walk.

Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/md/dm.c |   12 ++++++++----
 1 file changed, 8 insertions(+), 4 deletions(-)

--- a/drivers/md/dm.c
+++ b/drivers/md/dm.c
@@ -2630,9 +2630,10 @@ int dm_setup_md_queue(struct mapped_devi
 	 */
 	mutex_lock(&md->table_devices_lock);
 	r = add_disk(md->disk);
-	mutex_unlock(&md->table_devices_lock);
-	if (r)
+	if (r) {
+		mutex_unlock(&md->table_devices_lock);
 		return r;
+	}
 
 	/*
 	 * Register the holder relationship for devices added before the disk
@@ -2643,18 +2644,21 @@ int dm_setup_md_queue(struct mapped_devi
 		if (r)
 			goto out_undo_holders;
 	}
+	mutex_unlock(&md->table_devices_lock);
 
 	r = dm_sysfs_init(md);
 	if (r)
-		goto out_undo_holders;
+		goto lock_out_undo_holders;
 
 	md->type = type;
+
 	return 0;
 
+lock_out_undo_holders:
+	mutex_lock(&md->table_devices_lock);
 out_undo_holders:
 	list_for_each_entry_continue_reverse(td, &md->table_devices, list)
 		bd_unlink_disk_holder(td->dm_dev.bdev, md->disk);
-	mutex_lock(&md->table_devices_lock);
 	del_gendisk(md->disk);
 	mutex_unlock(&md->table_devices_lock);
 	return r;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 106/556] dm: fix resume-vs-remove race
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (104 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 105/556] dm: fix race when loading and unloading a table Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 107/556] dma-buf: dma-heap: dont publish fd before copy_to_user() succeeds Greg Kroah-Hartman
                   ` (462 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Mikulas Patocka

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mikulas Patocka <mpatocka@redhat.com>

commit 44b43ec132f1cf3275ecc182d0c82f50c3c4c3d5 upstream.

If the user issues the resume ioctl and the remove ioctl at the same
time, it may be possible that the device is resumed after it is suspended
in __dm_destroy. The result is that the table is destroyed without
calling the postsuspend method.

Dm targets expect that they may be removed only after the postsuspend
method method was called. If we break this expectation, it can cause
misbehavior in various targets. For example - in the dm-integrity target,
the reboot notifier is not unregistered, leading to use-after-free.

Fix this bug by refusing to resume if the device is being destroyed.

Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/md/dm.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/md/dm.c
+++ b/drivers/md/dm.c
@@ -3144,7 +3144,7 @@ retry:
 	r = -EINVAL;
 	mutex_lock_nested(&md->suspend_lock, SINGLE_DEPTH_NESTING);
 
-	if (!dm_suspended_md(md))
+	if (!dm_suspended_md(md) || test_bit(DMF_FREEING, &md->flags))
 		goto out;
 
 	if (dm_suspended_internally_md(md)) {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 107/556] dma-buf: dma-heap: dont publish fd before copy_to_user() succeeds
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (105 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 106/556] dm: fix resume-vs-remove race Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 108/556] dma-direct: return struct page from dma_direct_alloc_from_pool() Greg Kroah-Hartman
                   ` (461 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, T.J. Mercier, Christian König,
	Sumit Semwal, Baineng Shou

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Baineng Shou <shoubaineng@gmail.com>

commit 30d0aff2c65a277135cfd8ea28fa1ee75e0ea4e0 upstream.

DMA_HEAP_IOCTL_ALLOC allocates a dma-buf and installs an fd into the
caller's fd table via dma_buf_fd() -> fd_install() before
dma_heap_ioctl() copies the result back to userspace.  If the trailing
copy_to_user() fails, userspace never learns the fd number, but the
fd (and the underlying dma-buf reference) are already visible to
other threads in the same process and are leaked for the lifetime of
the process.

The obvious "close it on the failure path" fix is unsafe: once
fd_install() has run, another thread can already dup() the fd, send
it via SCM_RIGHTS, or close() it and let its number be reused, so a
subsequent close_fd() from the ioctl path can operate on an unrelated
file.  This was pointed out by Christian König on v1 [1].

Restructure the allocation path so that fd_install() is the last,
unfailable step of a successful ioctl:

  1. heap->ops->allocate()      creates the dma_buf.
  2. get_unused_fd_flags()      reserves an fd number in the caller's
                                fd table without publishing it, so
                                no other thread can observe it.
  3. copy_to_user()             delivers the fd number to userspace;
                                on failure the fd is returned with
                                put_unused_fd() and the dma_buf
                                reference is dropped with
                                dma_buf_put(), leaving no user-
                                visible state behind.
  4. dma_buf_fd_install()       publishes the fd and emits the
                                trace_dma_buf_fd tracepoint -- from
                                here on the ioctl cannot fail.

A new dma_buf_fd_install() helper is introduced in dma-buf.c to wrap
fd_install() together with the DMA_BUF_TRACE() call, preserving the
export tracing that dma_buf_fd() provides.  dma_heap_ioctl_allocate()
is refactored to return the struct dma_buf * directly (returning
ERR_PTR on failure) so the caller holds the dmabuf reference across
steps 3 and 4.

The failure at step 3 is easily reachable from userspace: pass a
struct dma_heap_allocation_data that lives in a page whose protection
is flipped to PROT_READ between copy_from_user() and copy_to_user()
(e.g. via mprotect()).  Before this change each such ioctl leaks one
dmabuf fd; after it, the fd table is unchanged on failure and only
/dev/dma_heap/<name> remains open.

No UAPI or heap-driver interface change.

[1] https://lore.kernel.org/dri-devel/175e98de-f414-47d7-81c1-c0fe0a8f7f62@amd.com/

Fixes: c02a81fba74f ("dma-buf: Add dma-buf heaps framework")
Cc: stable@vger.kernel.org
Reviewed-by: T.J. Mercier <tjmercier@google.com>
Acked-by: Christian König <christian.koenig@amd.com>
Acked-by: Sumit Semwal <sumit.semwal@linaro.org>
Signed-off-by: Baineng Shou <shoubaineng@gmail.com>
Link: https://lore.kernel.org/r/20260817050457.1005285-2-shoubaineng@gmail.com
Signed-off-by: Christian König <christian.koenig@amd.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/dma-buf/dma-buf.c  |   20 +++++++++++
 drivers/dma-buf/dma-heap.c |   80 ++++++++++++++++++++++-----------------------
 include/linux/dma-buf.h    |    1 
 3 files changed, 61 insertions(+), 40 deletions(-)

--- a/drivers/dma-buf/dma-buf.c
+++ b/drivers/dma-buf/dma-buf.c
@@ -804,6 +804,26 @@ int dma_buf_fd(struct dma_buf *dmabuf, i
 EXPORT_SYMBOL_NS_GPL(dma_buf_fd, "DMA_BUF");
 
 /**
+ * dma_buf_fd_install - install a reserved fd for a dma-buf
+ * @dmabuf:	[in]	pointer to dma_buf
+ * @fd:		[in]	fd reserved with get_unused_fd_flags()
+ *
+ * Publishes a previously reserved fd into the caller's fd table.
+ * Must only be called after all fallible work (e.g. copy_to_user)
+ * has succeeded, as it cannot be undone safely once called.
+ *
+ * The caller is responsible for having emitted the trace event
+ * (via dma_buf_fd() or get_unused_fd_flags() + this function)
+ * before calling this.
+ */
+void dma_buf_fd_install(struct dma_buf *dmabuf, int fd)
+{
+	DMA_BUF_TRACE(trace_dma_buf_fd, dmabuf, fd);
+	fd_install(fd, dmabuf->file);
+}
+EXPORT_SYMBOL_NS_GPL(dma_buf_fd_install, "DMA_BUF");
+
+/**
  * dma_buf_get - returns the struct dma_buf related to an fd
  * @fd:	[in]	fd associated with the struct dma_buf to be returned
  *
--- a/drivers/dma-buf/dma-heap.c
+++ b/drivers/dma-buf/dma-heap.c
@@ -55,33 +55,6 @@ MODULE_PARM_DESC(mem_accounting,
 		 "Enable cgroup-based memory accounting for dma-buf heap allocations (default=false).");
 EXPORT_SYMBOL_NS_GPL(mem_accounting, "DMA_BUF_HEAP");
 
-static int dma_heap_buffer_alloc(struct dma_heap *heap, size_t len,
-				 u32 fd_flags,
-				 u64 heap_flags)
-{
-	struct dma_buf *dmabuf;
-	int fd;
-
-	/*
-	 * Allocations from all heaps have to begin
-	 * and end on page boundaries.
-	 */
-	len = PAGE_ALIGN(len);
-	if (!len)
-		return -EINVAL;
-
-	dmabuf = heap->ops->allocate(heap, len, fd_flags, heap_flags);
-	if (IS_ERR(dmabuf))
-		return PTR_ERR(dmabuf);
-
-	fd = dma_buf_fd(dmabuf, fd_flags);
-	if (fd < 0) {
-		dma_buf_put(dmabuf);
-		/* just return, as put will call release and that will free */
-	}
-	return fd;
-}
-
 static int dma_heap_open(struct inode *inode, struct file *file)
 {
 	struct dma_heap *heap;
@@ -99,30 +72,42 @@ static int dma_heap_open(struct inode *i
 	return 0;
 }
 
-static long dma_heap_ioctl_allocate(struct file *file, void *data)
+static struct dma_buf *dma_heap_ioctl_allocate(struct file *file, void *data)
 {
 	struct dma_heap_allocation_data *heap_allocation = data;
 	struct dma_heap *heap = file->private_data;
+	struct dma_buf *dmabuf;
 	int fd;
+	size_t len;
 
 	if (heap_allocation->fd)
-		return -EINVAL;
+		return ERR_PTR(-EINVAL);
 
 	if (heap_allocation->fd_flags & ~DMA_HEAP_VALID_FD_FLAGS)
-		return -EINVAL;
+		return ERR_PTR(-EINVAL);
 
 	if (heap_allocation->heap_flags & ~DMA_HEAP_VALID_HEAP_FLAGS)
-		return -EINVAL;
+		return ERR_PTR(-EINVAL);
+
+	len = PAGE_ALIGN(heap_allocation->len);
+	if (!len)
+		return ERR_PTR(-EINVAL);
 
-	fd = dma_heap_buffer_alloc(heap, heap_allocation->len,
-				   heap_allocation->fd_flags,
-				   heap_allocation->heap_flags);
-	if (fd < 0)
-		return fd;
+	dmabuf = heap->ops->allocate(heap, len, heap_allocation->fd_flags,
+				     heap_allocation->heap_flags);
+
+	if (IS_ERR(dmabuf))
+		return dmabuf;
+
+	fd = get_unused_fd_flags(heap_allocation->fd_flags);
+	if (fd < 0) {
+		dma_buf_put(dmabuf);
+		return ERR_PTR(fd);
+	}
 
 	heap_allocation->fd = fd;
 
-	return 0;
+	return dmabuf;
 }
 
 static unsigned int dma_heap_ioctl_cmds[] = {
@@ -138,6 +123,8 @@ static long dma_heap_ioctl(struct file *
 	unsigned int in_size, out_size, drv_size, ksize;
 	int nr = _IOC_NR(ucmd);
 	int ret = 0;
+	int fd;
+	struct dma_buf *dmabuf;
 
 	if (nr >= ARRAY_SIZE(dma_heap_ioctl_cmds))
 		return -EINVAL;
@@ -174,15 +161,28 @@ static long dma_heap_ioctl(struct file *
 
 	switch (kcmd) {
 	case DMA_HEAP_IOCTL_ALLOC:
-		ret = dma_heap_ioctl_allocate(file, kdata);
+		dmabuf = dma_heap_ioctl_allocate(file, kdata);
+
+		if (IS_ERR(dmabuf)) {
+			ret = PTR_ERR(dmabuf);
+			break;
+		}
+
+		fd = ((struct dma_heap_allocation_data *)kdata)->fd;
+		if (copy_to_user((void __user *)arg, kdata, out_size) != 0) {
+			put_unused_fd(fd);
+			dma_buf_put(dmabuf);
+			ret = -EFAULT;
+		} else {
+			dma_buf_fd_install(dmabuf, fd);
+		}
+
 		break;
 	default:
 		ret = -ENOTTY;
 		goto err;
 	}
 
-	if (copy_to_user((void __user *)arg, kdata, out_size) != 0)
-		ret = -EFAULT;
 err:
 	if (kdata != stack_kdata)
 		kfree(kdata);
--- a/include/linux/dma-buf.h
+++ b/include/linux/dma-buf.h
@@ -567,6 +567,7 @@ void dma_buf_unpin(struct dma_buf_attach
 struct dma_buf *dma_buf_export(const struct dma_buf_export_info *exp_info);
 
 int dma_buf_fd(struct dma_buf *dmabuf, int flags);
+void dma_buf_fd_install(struct dma_buf *dmabuf, int fd);
 struct dma_buf *dma_buf_get(int fd);
 void dma_buf_put(struct dma_buf *dmabuf);
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 108/556] dma-direct: return struct page from dma_direct_alloc_from_pool()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (106 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 107/556] dma-buf: dma-heap: dont publish fd before copy_to_user() succeeds Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 109/556] dmaengine: fsl-edma: tracing: no ptr dereference during log output Greg Kroah-Hartman
                   ` (460 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michael Kelley, Mostafa Saleh,
	Jason Gunthorpe, Aneesh Kumar K.V (Arm), Marek Szyprowski

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Aneesh Kumar K.V (Arm) <aneesh.kumar@kernel.org>

commit 94a04ad732c9f8b9554270fc4038a06737de5c22 upstream.

Commit 5b138c534fda ("dma-direct: factor out a dma_direct_alloc_from_pool
helper") changed dma_direct_alloc_from_pool() to return the CPU address
from dma_alloc_from_pool(). That fits dma_direct_alloc(), but
dma_direct_alloc_pages() also uses the helper and expects a struct page *.

Fix this by making dma_direct_alloc_from_pool() return the struct page *
again, and pass the CPU address back through an out-parameter for the
dma_direct_alloc() caller.

Fixes: 5b138c534fda ("dma-direct: factor out a dma_direct_alloc_from_pool helper")
Cc: stable@vger.kernel.org
Tested-by: Michael Kelley <mhklinux@outlook.com>
Tested-by: Mostafa Saleh <smostafa@google.com>
Reviewed-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Aneesh Kumar K.V (Arm) <aneesh.kumar@kernel.org>
Reviewed-by: Mostafa Saleh <smostafa@google.com>
Link: https://lore.kernel.org/r/20260717180442.110954-2-aneesh.kumar@kernel.org
Signed-off-by: Marek Szyprowski <m.szyprowski@samsung.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 kernel/dma/direct.c |   18 ++++++++++--------
 1 file changed, 10 insertions(+), 8 deletions(-)

--- a/kernel/dma/direct.c
+++ b/kernel/dma/direct.c
@@ -164,22 +164,21 @@ static bool dma_direct_use_pool(struct d
 	return !gfpflags_allow_blocking(gfp) && !is_swiotlb_for_alloc(dev);
 }
 
-static void *dma_direct_alloc_from_pool(struct device *dev, size_t size,
-		dma_addr_t *dma_handle, gfp_t gfp)
+static struct page *dma_direct_alloc_from_pool(struct device *dev, size_t size,
+		dma_addr_t *dma_handle, void **cpu_addr, gfp_t gfp)
 {
 	struct page *page;
 	u64 phys_limit;
-	void *ret;
 
 	if (WARN_ON_ONCE(!IS_ENABLED(CONFIG_DMA_COHERENT_POOL)))
 		return NULL;
 
 	gfp |= dma_direct_optimal_gfp_mask(dev, &phys_limit);
-	page = dma_alloc_from_pool(dev, size, &ret, gfp, dma_coherent_ok);
+	page = dma_alloc_from_pool(dev, size, cpu_addr, gfp, dma_coherent_ok);
 	if (!page)
 		return NULL;
 	*dma_handle = phys_to_dma_direct(dev, page_to_phys(page));
-	return ret;
+	return page;
 }
 
 static void *dma_direct_alloc_no_mapping(struct device *dev, size_t size,
@@ -247,8 +246,11 @@ void *dma_direct_alloc(struct device *de
 	 * the atomic pools instead if we aren't allowed block.
 	 */
 	if ((remap || force_dma_unencrypted(dev)) &&
-	    dma_direct_use_pool(dev, gfp))
-		return dma_direct_alloc_from_pool(dev, size, dma_handle, gfp);
+	    dma_direct_use_pool(dev, gfp)) {
+		page = dma_direct_alloc_from_pool(dev, size, dma_handle,
+						  &ret, gfp);
+		return page ? ret : NULL;
+	}
 
 	/* we always manually zero the memory once we are done */
 	page = __dma_direct_alloc_pages(dev, size, gfp & ~__GFP_ZERO, true);
@@ -357,7 +359,7 @@ struct page *dma_direct_alloc_pages(stru
 	void *ret;
 
 	if (force_dma_unencrypted(dev) && dma_direct_use_pool(dev, gfp))
-		return dma_direct_alloc_from_pool(dev, size, dma_handle, gfp);
+		return dma_direct_alloc_from_pool(dev, size, dma_handle, &ret, gfp);
 
 	page = __dma_direct_alloc_pages(dev, size, gfp, false);
 	if (!page)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 109/556] dmaengine: fsl-edma: tracing: no ptr dereference during log output
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (107 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 108/556] dma-direct: return struct page from dma_direct_alloc_from_pool() Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 110/556] dmaengine: dw-edma: Fix HDMA channel status register access Greg Kroah-Hartman
                   ` (459 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Steven Rostedt, Martin Kaiser,
	Frank Li, Vinod Koul

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Martin Kaiser <martin@kaiser.cx>

commit 2ea04dca8e627f722caa7a2037cfbae0257f3501 upstream.

The fsl edma events store a pointer to a struct fsl_edma_engine in the
ringbuffer and dereference it when a log entry is printed. At this time,
the pointer may no longer be valid.

Event injection can be used to trigger a crash:

$ cd /sys/kernel/tracing
$ echo 'value = 0' > events/fsl_edma/edma_writeb/inject
$ cat trace

The log output needs only edma->membase. Add a membase field at the end
of the event and use the new field for log output. Keep the existing
fields for backward compatibility.

Fixes: 11102d0c343b ("dmaengine: fsl-edma: add trace event support")
Cc: stable@vger.kernel.org
Reviewed-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Martin Kaiser <martin@kaiser.cx>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260718130024.341243-1-martin@kaiser.cx
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/dma/fsl-edma-trace.h |    4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

--- a/drivers/dma/fsl-edma-trace.h
+++ b/drivers/dma/fsl-edma-trace.h
@@ -19,14 +19,16 @@ DECLARE_EVENT_CLASS(edma_log_io,
 		__field(struct fsl_edma_engine *, edma)
 		__field(void __iomem *, addr)
 		__field(u32, value)
+		__field(void __iomem *, membase)
 	),
 	TP_fast_assign(
 		__entry->edma = edma;
 		__entry->addr = addr;
 		__entry->value = value;
+		__entry->membase = edma->membase;
 	),
 	TP_printk("offset %08x: value %08x",
-		(u32)(__entry->addr - __entry->edma->membase), __entry->value)
+		(u32)(__entry->addr - __entry->membase), __entry->value)
 );
 
 DEFINE_EVENT(edma_log_io, edma_readl,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 110/556] dmaengine: dw-edma: Fix HDMA channel status register access
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (108 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 109/556] dmaengine: fsl-edma: tracing: no ptr dereference during log output Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 111/556] dmaengine: dw-edma: Complete descriptors before pausing Greg Kroah-Hartman
                   ` (458 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Frank Li, Koichiro Den, Vinod Koul

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Koichiro Den <den@valinux.co.jp>

commit ef1b080e03acc83d5bde841da67036985acd50dc upstream.

GET_CH_32() takes the direction before the channel ID, but
dw_hdma_v0_core_ch_status() passed them in the opposite order. This can
make the status callback read another HDMA channel status register.

Use the same argument order as the other HDMA register accesses.

Fixes: e74c39573d35 ("dmaengine: dw-edma: Add support for native HDMA")
Cc: stable@vger.kernel.org
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Koichiro Den <den@valinux.co.jp>
Link: https://patch.msgid.link/20260717180639.2643243-2-den@valinux.co.jp
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/dma/dw-edma/dw-hdma-v0-core.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/dma/dw-edma/dw-hdma-v0-core.c
+++ b/drivers/dma/dw-edma/dw-hdma-v0-core.c
@@ -79,7 +79,7 @@ static enum dma_status dw_hdma_v0_core_c
 	u32 tmp;
 
 	tmp = FIELD_GET(HDMA_V0_CH_STATUS_MASK,
-			GET_CH_32(dw, chan->id, chan->dir, ch_stat));
+			GET_CH_32(dw, chan->dir, chan->id, ch_stat));
 
 	if (tmp == 1)
 		return DMA_IN_PROGRESS;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 111/556] dmaengine: dw-edma: Complete descriptors before pausing
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (109 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 110/556] dmaengine: dw-edma: Fix HDMA channel status register access Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 112/556] dmaengine: dw-edma: Initialize IRQ data before requesting IRQs Greg Kroah-Hartman
                   ` (457 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Frank Li, Koichiro Den, Vinod Koul

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Koichiro Den <den@valinux.co.jp>

commit c154060016a9db2ac889bfdb0a3c1322f9be8ded upstream.

If PAUSE is requested while the final burst of a descriptor is in
flight, the DONE interrupt takes the PAUSE path without checking whether
the descriptor has been depleted. The depleted descriptor remains on the
issued list and the channel enters EDMA_ST_PAUSE.

On resume, dw_edma_start_transfer() can select that depleted descriptor
again even though no burst remains, leaving the channel in an invalid
busy state.

Check for descriptor completion before acknowledging PAUSE. If there is
no work to start on resume, leave the channel idle. Also ignore DONE
interrupts while the channel is paused so a stale or repeated interrupt
cannot change its state or start queued work.

Fixes: e63d79d1ffcd ("dmaengine: Add Synopsys eDMA IP core driver")
Cc: stable@vger.kernel.org
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Koichiro Den <den@valinux.co.jp>
Link: https://patch.msgid.link/20260717180639.2643243-5-den@valinux.co.jp
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/dma/dw-edma/dw-edma-core.c |   20 ++++++++++++++------
 1 file changed, 14 insertions(+), 6 deletions(-)

--- a/drivers/dma/dw-edma/dw-edma-core.c
+++ b/drivers/dma/dw-edma/dw-edma-core.c
@@ -297,7 +297,8 @@ static int dw_edma_device_resume(struct
 		err = -EPERM;
 	} else {
 		chan->status = EDMA_ST_BUSY;
-		dw_edma_start_transfer(chan);
+		if (!dw_edma_start_transfer(chan))
+			chan->status = EDMA_ST_IDLE;
 	}
 
 	return err;
@@ -655,10 +656,16 @@ static void dw_edma_done_interrupt(struc
 	unsigned long flags;
 
 	spin_lock_irqsave(&chan->vc.lock, flags);
+	if (chan->status == EDMA_ST_PAUSE) {
+		spin_unlock_irqrestore(&chan->vc.lock, flags);
+		return;
+	}
+
 	vd = vchan_next_desc(&chan->vc);
 	if (vd) {
 		switch (chan->request) {
 		case EDMA_REQ_NONE:
+		case EDMA_REQ_PAUSE:
 			desc = vd2dw_edma_desc(vd);
 			if (!desc->chunks_alloc) {
 				dw_hdma_set_callback_result(vd,
@@ -667,6 +674,12 @@ static void dw_edma_done_interrupt(struc
 				vchan_cookie_complete(vd);
 			}
 
+			if (chan->request == EDMA_REQ_PAUSE) {
+				chan->request = EDMA_REQ_NONE;
+				chan->status = EDMA_ST_PAUSE;
+				break;
+			}
+
 			/* Continue transferring if there are remaining chunks or issued requests.
 			 */
 			chan->status = dw_edma_start_transfer(chan) ? EDMA_ST_BUSY : EDMA_ST_IDLE;
@@ -679,11 +692,6 @@ static void dw_edma_done_interrupt(struc
 			chan->status = EDMA_ST_IDLE;
 			break;
 
-		case EDMA_REQ_PAUSE:
-			chan->request = EDMA_REQ_NONE;
-			chan->status = EDMA_ST_PAUSE;
-			break;
-
 		default:
 			break;
 		}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 112/556] dmaengine: dw-edma: Initialize IRQ data before requesting IRQs
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (110 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 111/556] dmaengine: dw-edma: Complete descriptors before pausing Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 113/556] dmaengine: dw-edma: Mark emulated IRQ as level-triggered Greg Kroah-Hartman
                   ` (456 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Frank Li, Koichiro Den, Vinod Koul

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Koichiro Den <den@valinux.co.jp>

commit 647217abea849d3d45f8cb0b8ee5b78d50f26985 upstream.

dw_edma_irq_request() passes struct dw_edma_irq to request_irq() before
dw_edma_channel_setup() fills the back pointer. A shared interrupt can
therefore enter the handler with dw_irq->dw still NULL, leading to a
NULL pointer dereference.

Set the back pointer before installing each handler.

Fixes: e63d79d1ffcd ("dmaengine: Add Synopsys eDMA IP core driver")
Cc: stable@vger.kernel.org
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Koichiro Den <den@valinux.co.jp>
Link: https://patch.msgid.link/20260721062815.4117887-5-den@valinux.co.jp
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/dma/dw-edma/dw-edma-core.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/drivers/dma/dw-edma/dw-edma-core.c
+++ b/drivers/dma/dw-edma/dw-edma-core.c
@@ -937,7 +937,6 @@ static int dw_edma_channel_setup(struct
 		else
 			irq->rd_mask |= BIT(chan->id);
 
-		irq->dw = dw;
 		memcpy(&chan->msi, &irq->msi, sizeof(chan->msi));
 
 		dev_vdbg(dev, "MSI:\t\tChannel %s[%u] addr=0x%.8x%.8x, data=0x%.8x\n",
@@ -1018,6 +1017,7 @@ static int dw_edma_irq_request(struct dw
 	if (chip->nr_irqs == 1) {
 		/* Common IRQ shared among all channels */
 		irq = chip->ops->irq_vector(dev, 0);
+		dw->irq[0].dw = dw;
 		err = request_irq(irq, dw_edma_interrupt_common,
 				  IRQF_SHARED, dw->name, &dw->irq[0]);
 		if (err) {
@@ -1040,6 +1040,7 @@ static int dw_edma_irq_request(struct dw
 
 		for (i = 0; i < (*wr_alloc + *rd_alloc); i++) {
 			irq = chip->ops->irq_vector(dev, i);
+			dw->irq[i].dw = dw;
 			err = request_irq(irq,
 					  i < *wr_alloc ?
 						dw_edma_interrupt_write :



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 113/556] dmaengine: dw-edma: Mark emulated IRQ as level-triggered
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (111 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 112/556] dmaengine: dw-edma: Initialize IRQ data before requesting IRQs Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 114/556] cpuidle: dt_idle_genpd: kfree() the original name allocation Greg Kroah-Hartman
                   ` (455 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Niklas Cassel, Koichiro Den,
	Frank Li, Manivannan Sadhasivam, Vinod Koul

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Koichiro Den <den@valinux.co.jp>

commit 0d995da5fb97e8c312834575604d4423eb6225b7 upstream.

The interrupt-emulation virtual IRQ uses handle_level_irq(), but the IRQ
descriptor has not been marked with IRQ_LEVEL.

The interrupt emulation is somewhat unusual: the eDMA interrupt handlers
dispatch the virtual IRQ for every edma_int[] interrupt because software
cannot reliably tell an interrupt-emulation event from one caused solely
by DONE/ABORT status. If an interrupt arrives before the doorbell
handler is registered for the virtual IRQ, the IRQ core marks it
pending. When the IRQ is later started, check_irq_resend() treats it as
non-level and replays the pending interrupt, causing the newly
registered handler to run for a stale event.

Mark the virtual IRQ with IRQ_LEVEL so the stale pending state is
cleared without being replayed. This was observed in pci_endpoint_test
as two doorbell handler calls when the DMA-variant test ran before
DOORBELL_TEST.

Fixes: d9d5e1bdd180 ("dmaengine: dw-edma: Add virtual IRQ for interrupt-emulation doorbells")
Cc: stable@vger.kernel.org
Reported-by: Niklas Cassel <cassel@kernel.org>
Closes: https://lore.kernel.org/r/ampndLtU32ODmncX@ryzen
Tested-by: Niklas Cassel <cassel@kernel.org>
Signed-off-by: Koichiro Den <den@valinux.co.jp>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Manivannan Sadhasivam <mani@kernel.org>
Link: https://patch.msgid.link/20260730160701.3550710-1-den@valinux.co.jp
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/dma/dw-edma/dw-edma-core.c |    1 +
 1 file changed, 1 insertion(+)

--- a/drivers/dma/dw-edma/dw-edma-core.c
+++ b/drivers/dma/dw-edma/dw-edma-core.c
@@ -763,6 +763,7 @@ static int dw_edma_emul_irq_alloc(struct
 		return virq;
 
 	irq_set_chip_and_handler(virq, &dw_edma_emul_irqchip, handle_level_irq);
+	irq_set_status_flags(virq, IRQ_LEVEL);
 	irq_set_chip_data(virq, dw);
 	irq_set_noprobe(virq);
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 114/556] cpuidle: dt_idle_genpd: kfree() the original name allocation
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (112 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 113/556] dmaengine: dw-edma: Mark emulated IRQ as level-triggered Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 115/556] cpuidle: psci: Fix support for probe deferral by dropping the faux device Greg Kroah-Hartman
                   ` (454 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Linkai Gong, Ulf Hansson

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Linkai Gong <gonglinkai@kylinos.cn>

commit 2b0ac85512b7f67479127b2713254490662eb13d upstream.

dt_idle_pd_alloc() kasprintf()s the full node path, then points
pd->name at kbasename() of that string. dt_idle_pd_free() kfree()s
pd->name, which is no longer the start of the allocation.

Copy the basename instead.

Fixes: 9d976d6721df ("cpuidle: Factor-out power domain related code from PSCI domain driver")
Signed-off-by: Linkai Gong <gonglinkai@kylinos.cn>
Cc: stable@vger.kernel.org
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/cpuidle/dt_idle_genpd.c |    3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

--- a/drivers/cpuidle/dt_idle_genpd.c
+++ b/drivers/cpuidle/dt_idle_genpd.c
@@ -99,7 +99,7 @@ struct generic_pm_domain *dt_idle_pd_all
 	if (!pd)
 		goto out;
 
-	pd->name = kasprintf(GFP_KERNEL, "%pOF", np);
+	pd->name = kstrdup(kbasename(of_node_full_name(np)), GFP_KERNEL);
 	if (!pd->name)
 		goto free_pd;
 
@@ -112,7 +112,6 @@ struct generic_pm_domain *dt_idle_pd_all
 		goto free_name;
 
 	pd->free_states = pd_free_states;
-	pd->name = kbasename(pd->name);
 	pd->states = states;
 	pd->state_count = state_count;
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 115/556] cpuidle: psci: Fix support for probe deferral by dropping the faux device
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (113 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 114/556] cpuidle: dt_idle_genpd: kfree() the original name allocation Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 116/556] block: flag zoned disks with GENHD_FL_NO_PART Greg Kroah-Hartman
                   ` (453 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Abel Vesa, Ulf Hansson, Ulf Hansson

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ulf Hansson <ulf.hansson@oss.qualcomm.com>

commit 0606f2114e2dc88fe293858fd991cda2688b8c3a upstream.

At the conversion to the faux driver/device we broke the support for probe
deferral. In hindsight, the move to the faux device seems questionable, as
it simply makes the code more complicated and for no good reason.

To fix the support for the probe deferral let's therefore restore the old
code and drop the faux device.

Fixes: af5376a77e87 ("cpuidle: psci: Transition to the faux device interface")
Fixes: 5836ebeb4a2b ("cpuidle: psci: Avoid initializing faux device if no DT idle states are present")
Fixes: 39cdf87a97fd ("cpuidle: psci: Fix uninitialized variable in dt_idle_state_present()")
Cc: stable@vger.kernel.org
Reviewed-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
Signed-off-by: Ulf Hansson <ulf.hansson@oss.qualcomm.com>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/cpuidle/cpuidle-psci.c |   42 +++++++++++++++--------------------------
 1 file changed, 16 insertions(+), 26 deletions(-)

--- a/drivers/cpuidle/cpuidle-psci.c
+++ b/drivers/cpuidle/cpuidle-psci.c
@@ -16,7 +16,7 @@
 #include <linux/kernel.h>
 #include <linux/module.h>
 #include <linux/of.h>
-#include <linux/device/faux.h>
+#include <linux/platform_device.h>
 #include <linux/psci.h>
 #include <linux/pm_domain.h>
 #include <linux/pm_runtime.h>
@@ -428,14 +428,14 @@ deinit:
  * to register cpuidle driver then rollback to cancel all CPUs
  * registration.
  */
-static int psci_cpuidle_probe(struct faux_device *fdev)
+static int psci_cpuidle_probe(struct platform_device *pdev)
 {
 	int cpu, ret;
 	struct cpuidle_driver *drv;
 	struct cpuidle_device *dev;
 
 	for_each_present_cpu(cpu) {
-		ret = psci_idle_init_cpu(&fdev->dev, cpu);
+		ret = psci_idle_init_cpu(&pdev->dev, cpu);
 		if (ret)
 			goto out_fail;
 	}
@@ -455,36 +455,26 @@ out_fail:
 	return ret;
 }
 
-static struct faux_device_ops psci_cpuidle_ops = {
+static struct platform_driver psci_cpuidle_driver = {
 	.probe = psci_cpuidle_probe,
+	.driver = {
+		.name = "psci-cpuidle",
+	},
 };
 
-static bool __init dt_idle_state_present(void)
-{
-	struct device_node *cpu_node __free(device_node) =
-			of_cpu_device_node_get(cpumask_first(cpu_possible_mask));
-	if (!cpu_node)
-		return false;
-
-	struct device_node *state_node __free(device_node) =
-			of_get_cpu_state_node(cpu_node, 0);
-	if (!state_node)
-		return false;
-
-	return !!of_match_node(psci_idle_state_match, state_node);
-}
-
 static int __init psci_idle_init(void)
 {
-	struct faux_device *fdev;
+	struct platform_device *pdev;
+	int ret;
 
-	if (!dt_idle_state_present())
-		return 0;
+	ret = platform_driver_register(&psci_cpuidle_driver);
+	if (ret)
+		return ret;
 
-	fdev = faux_device_create("psci-cpuidle", NULL, &psci_cpuidle_ops);
-	if (!fdev) {
-		pr_err("Failed to create psci-cpuidle device\n");
-		return -ENODEV;
+	pdev = platform_device_register_simple("psci-cpuidle", -1, NULL, 0);
+	if (IS_ERR(pdev)) {
+		platform_driver_unregister(&psci_cpuidle_driver);
+		return PTR_ERR(pdev);
 	}
 
 	return 0;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 116/556] block: flag zoned disks with GENHD_FL_NO_PART
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (114 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 115/556] cpuidle: psci: Fix support for probe deferral by dropping the faux device Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 117/556] bpf, riscv: Make arena support depend on ZACAS Greg Kroah-Hartman
                   ` (452 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Damien Le Moal, Bart Van Assche,
	Hannes Reinecke, Christoph Hellwig, Hannes Reinecke, Jens Axboe

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Damien Le Moal <dlemoal@kernel.org>

commit 3f9c7a108c0e8f14425384912017071b71341e3b upstream.

Zoned block devices do not support partitions. However, the partition
table is nevertheless still inspected, and any partition found ignored
with a warning in add_partition(). While this is generally not a problem,
and in fact beneficial to the user as it indicates an invalid use of a
zoned block device, scanning for a partition table on the device may
result in issuing read operations to offline zones (e.g. after a disk head
is depopulated for disks that support head management operations).

Since partitions are ignored anyway, completely disable partition scanning
for zoned gendisks by setting the flag GENHD_FL_NO_PART in __add_disk().
The existing check in add_partition() is left as-is to ensure that we
still get a warning if for whatever reason, despite GENHD_FL_NO_PART, we
still endup trying to add partitions.

Flagging zoned disks with GENHD_FL_NO_PART also has the benefit to expose
through sysfs the ext_range attribute with the value of 1 instead of the
default DISK_MAX_PARTS, thus correctly advertizing the fact that zoned
disks do not support partitions.

Fixes: 5eac3eb30c9a ("block: Remove partition support for zoned block devices")
Cc: stable@vger.kernel.org
Signed-off-by: Damien Le Moal <dlemoal@kernel.org>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Hannes Reinecke <hare@suse.de>
Link: https://patch.msgid.link/20260831025050.667758-1-dlemoal@kernel.org
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 block/genhd.c |    7 +++++++
 1 file changed, 7 insertions(+)

--- a/block/genhd.c
+++ b/block/genhd.c
@@ -448,6 +448,13 @@ static int __add_disk(struct device *par
 	}
 
 	/*
+	 * We do not support partitions with zoned block devices, so do not try
+	 * to scan the partitions table.
+	 */
+	if (blk_queue_is_zoned(disk->queue))
+		disk->flags |= GENHD_FL_NO_PART;
+
+	/*
 	 * If the driver provides an explicit major number it also must provide
 	 * the number of minors numbers supported, and those will be used to
 	 * setup the gendisk.



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 117/556] bpf, riscv: Make arena support depend on ZACAS
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (115 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 116/556] block: flag zoned disks with GENHD_FL_NO_PART Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 118/556] bpf: Fix infinite loop in pcpu_freelist push with one possible CPU Greg Kroah-Hartman
                   ` (451 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Chen Pei, Pu Lehui,
	Björn Töpel, Kumar Kartikeya Dwivedi

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chen Pei <cp0613@linux.alibaba.com>

commit 536b523b407397c8d3967c020ce7aad70a0ea030 upstream.

The arena range tree allocates its nodes with kmalloc_nolock() since
commit f8c67d8550ee ("bpf: Use kmalloc_nolock() in range tree").
kmalloc_nolock() requires slab caches with cmpxchg128 support
(__CMPXCHG_DOUBLE); on riscv cmpxchg128 is provided by the ZACAS
extension. On systems without ZACAS every arena map creation fails
with a misleading -ENOMEM.

Report the missing support instead: make bpf_jit_supports_arena()
return system_has_cmpxchg128() where it is defined, so arena map
creation fails with -EOPNOTSUPP on systems without ZACAS. The macro
is only defined when both CONFIG_RISCV_ISA_ZACAS and
CONFIG_TOOLCHAIN_HAS_ZACAS are enabled, so guard it with #ifdef the
same way mm/slab.h consumes it, and reject arena otherwise. This
matches how arena BPF_CMPXCHG instructions are already gated on ZACAS
in bpf_jit_supports_insn().

Fixes: f8c67d8550ee ("bpf: Use kmalloc_nolock() in range tree")
Signed-off-by: Chen Pei <cp0613@linux.alibaba.com>
Acked-by: Pu Lehui <pulehui@huawei.com>
Acked-by: Björn Töpel <bjorn@kernel.org>
Cc: stable@vger.kernel.org
Link: https://lore.kernel.org/bpf/20260902061451.1416-1-cp0613@linux.alibaba.com
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/riscv/net/bpf_jit_comp64.c |   10 +++++++++-
 1 file changed, 9 insertions(+), 1 deletion(-)

--- a/arch/riscv/net/bpf_jit_comp64.c
+++ b/arch/riscv/net/bpf_jit_comp64.c
@@ -2114,7 +2114,15 @@ bool bpf_jit_supports_ptr_xchg(void)
 
 bool bpf_jit_supports_arena(void)
 {
-	return true;
+	/*
+	 * The arena range tree uses kmalloc_nolock(), which needs
+	 * cmpxchg128, provided by ZACAS on riscv.
+	 */
+#ifdef system_has_cmpxchg128
+	return system_has_cmpxchg128();
+#else
+	return false;
+#endif
 }
 
 bool bpf_jit_supports_insn(struct bpf_insn *insn, bool in_arena)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 118/556] bpf: Fix infinite loop in pcpu_freelist push with one possible CPU
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (116 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 117/556] bpf, riscv: Make arena support depend on ZACAS Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 119/556] ceph: lock mutex in ceph_mds_check_access() Greg Kroah-Hartman
                   ` (450 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Hui Su, Kumar Kartikeya Dwivedi

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Hui Su <sh_def@163.com>

commit efebf6496685c93150df5bb0794363ae70c5f58a upstream.

__pcpu_freelist_push() can loop forever when only one CPU is possible
and an NMI re-enters pcpu_freelist_push() while the interrupted context
holds that CPU's freelist lock.

After the current-CPU fast path fails, the fallback loop walks
cpu_possible_mask while skipping the current CPU. With CONFIG_SMP=n, or
when an SMP kernel is limited to one possible CPU with nr_cpus=1 or
possible_cpus=1, there are no other possible CPUs to examine. The loop
therefore makes no lock acquisition attempt and can never make progress.

The following stack was observed on a UP system:

  NMI context:
    pcpu_freelist_push
    free_htab_elem
    htab_map_delete_elem
    [perf-event BPF program]
    __perf_event_overflow
    perf_event_nmi_handler
    exc_nmi

  Interrupted context:
    __pcpu_freelist_push
    pcpu_freelist_push
    free_htab_elem
    htab_map_delete_elem
    [raw_tp/sys_enter BPF program]
    __bpf_trace_sys_enter
    do_syscall_64

raw_res_spin_lock() detects the same-CPU recursive acquisition and
returns -EDEADLK, but the subsequent fallback loop has no candidate head
on a system with one possible CPU.

Restore the extra fallback head that existed before the rqspinlock
conversion. Keep the current-CPU fast path, then try the other possible
CPUs and finally the extra head. The additional head lets a push, which
cannot fail without losing a preallocated element, make progress when the
only per-CPU head is held by the interrupted context.

Also check the extra head from the pop path so that nodes placed there
can be reused.

Fixes: f2ac0e5d1c4d ("bpf: Convert percpu_freelist.c to rqspinlock")
Signed-off-by: Hui Su <sh_def@163.com>
Cc: stable@vger.kernel.org
Link: https://lore.kernel.org/bpf/20260806175600.1993595-1-sh_def@163.com
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 kernel/bpf/percpu_freelist.c |   35 +++++++++++++++++++++++++++--------
 kernel/bpf/percpu_freelist.h |    1 +
 2 files changed, 28 insertions(+), 8 deletions(-)

--- a/kernel/bpf/percpu_freelist.c
+++ b/kernel/bpf/percpu_freelist.c
@@ -17,6 +17,8 @@ int pcpu_freelist_init(struct pcpu_freel
 		raw_res_spin_lock_init(&head->lock);
 		head->first = NULL;
 	}
+	raw_res_spin_lock_init(&s->extralist.lock);
+	s->extralist.first = NULL;
 	return 0;
 }
 
@@ -46,22 +48,28 @@ void __pcpu_freelist_push(struct pcpu_fr
 			struct pcpu_freelist_node *node)
 {
 	struct pcpu_freelist_head *head;
-	int cpu;
+	int cpu, this_cpu;
 
 	if (___pcpu_freelist_push(this_cpu_ptr(s->freelist), node))
 		return;
 
+	this_cpu = raw_smp_processor_id();
 	while (true) {
-		for_each_cpu_wrap(cpu, cpu_possible_mask, raw_smp_processor_id()) {
-			if (cpu == raw_smp_processor_id())
+		for_each_cpu_wrap(cpu, cpu_possible_mask, this_cpu) {
+			if (cpu == this_cpu)
 				continue;
+
 			head = per_cpu_ptr(s->freelist, cpu);
-			if (raw_res_spin_lock(&head->lock))
-				continue;
-			pcpu_freelist_push_node(head, node);
-			raw_res_spin_unlock(&head->lock);
-			return;
+			if (___pcpu_freelist_push(head, node))
+				return;
 		}
+
+		/*
+		 * Push cannot fail. Use the extra list when none of the
+		 * per-CPU freelists can accept the node.
+		 */
+		if (___pcpu_freelist_push(&s->extralist, node))
+			return;
 	}
 }
 
@@ -117,6 +125,17 @@ static struct pcpu_freelist_node *___pcp
 		}
 		raw_res_spin_unlock(&head->lock);
 	}
+
+	/* Per-CPU lists are empty or unavailable, try the extra list. */
+	head = &s->extralist;
+	if (!READ_ONCE(head->first))
+		return NULL;
+	if (raw_res_spin_lock(&head->lock))
+		return NULL;
+	node = head->first;
+	if (node)
+		WRITE_ONCE(head->first, node->next);
+	raw_res_spin_unlock(&head->lock);
 	return node;
 }
 
--- a/kernel/bpf/percpu_freelist.h
+++ b/kernel/bpf/percpu_freelist.h
@@ -14,6 +14,7 @@ struct pcpu_freelist_head {
 
 struct pcpu_freelist {
 	struct pcpu_freelist_head __percpu *freelist;
+	struct pcpu_freelist_head extralist;
 };
 
 struct pcpu_freelist_node {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 119/556] ceph: lock mutex in ceph_mds_check_access()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (117 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 118/556] bpf: Fix infinite loop in pcpu_freelist push with one possible CPU Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 120/556] ata: ahci: work around lost interrupts on Marvell 88SE61xx Greg Kroah-Hartman
                   ` (449 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Max Kellermann, Alex Markuze,
	Ilya Dryomov

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Max Kellermann <max.kellermann@ionos.com>

commit a61c6ae1dae2611082b831b4aaa780878099c012 upstream.

MDS session OPEN handling replaces mdsc->s_cap_auths under
mdsc->mutex, freeing the previous array and its strings.

ceph_mds_check_access() traverses this array without holding the
mutex.  A concurrent session reopen can therefore free the array while
it is being inspected, resulting in a use-after-free like this:

  Unable to handle kernel paging request at virtual address 003aaad64b2c8bb9
  [...]
  Internal error: Oops: 0000000096000004 [#1]  SMP
  Modules linked in:
  CPU: 56 UID: 2953037534 PID: 1253231 Comm: php-cgi8.4 Not tainted 6.18.45-i2-ampere #1146 NONE
  [..]
  pc : ceph_mds_check_access+0xd4/0x550
  lr : ceph_mds_check_access+0xc8/0x550
  [...]
  Call trace:
   ceph_mds_check_access+0xd4/0x550 (P)
   ceph_atomic_open+0x138/0xbe8
   path_openat+0xa24/0xfa8
   do_filp_open+0x94/0x158
   do_sys_openat2+0x88/0xf8

Cc: stable@vger.kernel.org
Fixes: 596afb0b8933 ("ceph: add ceph_mds_check_access() helper")
Signed-off-by: Max Kellermann <max.kellermann@ionos.com>
Reviewed-by: Alex Markuze <amarkuze@redhat.com>
Signed-off-by: Ilya Dryomov <idryomov@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/ceph/mds_client.c |    4 ++++
 fs/ceph/mds_client.h |    1 +
 2 files changed, 5 insertions(+)

--- a/fs/ceph/mds_client.c
+++ b/fs/ceph/mds_client.c
@@ -6593,11 +6593,13 @@ int ceph_mds_check_access(struct ceph_md
 	doutc(cl, "tpath '%s', mask %d, caller_uid %d, caller_gid %d\n",
 	      tpath, mask, caller_uid, caller_gid);
 
+	mutex_lock(&mdsc->mutex);
 	for (i = 0; i < mdsc->s_cap_auths_num; i++) {
 		struct ceph_mds_cap_auth *s = &mdsc->s_cap_auths[i];
 
 		err = ceph_mds_auth_match(mdsc, s, cred, tpath);
 		if (err < 0) {
+			mutex_unlock(&mdsc->mutex);
 			put_cred(cred);
 			return err;
 		} else if (err > 0) {
@@ -6619,6 +6621,7 @@ int ceph_mds_check_access(struct ceph_md
 	doutc(cl, "root_squash_perms %d, rw_perms_s %p\n", root_squash_perms,
 	      rw_perms_s);
 	if (root_squash_perms && rw_perms_s == NULL) {
+		mutex_unlock(&mdsc->mutex);
 		doutc(cl, "access allowed\n");
 		return 0;
 	}
@@ -6633,6 +6636,7 @@ int ceph_mds_check_access(struct ceph_md
 		      !!(mask & MAY_READ), !!(mask & MAY_WRITE));
 	}
 	doutc(cl, "access denied\n");
+	mutex_unlock(&mdsc->mutex);
 	return -EACCES;
 }
 
--- a/fs/ceph/mds_client.h
+++ b/fs/ceph/mds_client.h
@@ -604,6 +604,7 @@ struct ceph_mds_client {
 	struct rw_semaphore     pool_perm_rwsem;
 	struct rb_root		pool_perm_tree;
 
+	/* protected by mutex */
 	u32			 s_cap_auths_num;
 	struct ceph_mds_cap_auth *s_cap_auths;
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 120/556] ata: ahci: work around lost interrupts on Marvell 88SE61xx
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (118 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 119/556] ceph: lock mutex in ceph_mds_check_access() Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 121/556] ima: Check for ERR_PTR from dentry_path() in validate_hash_algo() Greg Kroah-Hartman
                   ` (448 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Hajo Noerenberg, Damien Le Moal,
	Pali Rohar, Niklas Cassel

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Hajo Noerenberg <hajo-linux-ide@noerenberg.de>

commit dc3565a4ae538e584e5e63b3b3cd1eaf502593c1 upstream.

ahci_single_level_irq_intr() services the ports first and clears the
global HOST_IRQ_STAT afterwards, as recommended by AHCI 1.1 section
10.6.2.  The Marvell 88SE6111/6121/6145 family stops reporting interrupts
for a port when HOST_IRQ_STAT is cleared while PxIS still holds bits:
PxIS keeps its content, HOST_IRQ_STAT reads back as 0, the port is never
looked at again, and the command in flight only ends in a timeout.

Measured on a Seagate Blackarmor NAS440 (Marvell 88F6281 Kirkwood,
88SE6121 rev B2 behind PCIe) by polling the AHCI registers from userspace
while an IDENTIFY was outstanding:

  t=303.046  irqs 127  PxIS 0x00000000  PxCI 0x00000001
             IDENTIFY issued
  t=303.057  irqs 128  PxIS 0x00000020  PxCI 0x00000000
             CI cleared, DPS set, one interrupt taken
             ... PxIS stays 0x00000020, HOST_IRQ_STAT stays 0 ...
  t~308.05   qc timeout after 5000 msecs

The command had completed - PxCI was clear and PxIS had DPS set - so
ahci_qc_complete() would have completed it.  It never got the chance
because the handler read HOST_IRQ_STAT as 0 and returned IRQ_NONE.

Marvell's own driver for these chips clears the two registers in the
opposite order and says so ("clear global before channel"), and
ahci_xgene handles its broken edge latch the same way.  Since the
reordering costs at most one spurious interrupt per valid one on
conforming controllers, do it in a private interrupt handler selected for
board_ahci_mv instead of changing libahci for everyone.

With this applied, SATA-2 and SATA-3 disks work at 3.0 Gbps on the
88SE6121 without the drive-side 1.5 Gbps jumper that was needed before.
Time from link up to a successful IDENTIFY:

  WDC WD5000AADS-00S9B0  port 0    7 ms  (never identified before)
  WDC WD3202ABYS-01B7A0  port 1   28 ms
  WDC WD30EFRX-68EUZN0   port 1  200 ms  (3 TB, HPA detection ok)

Only the 88SE6121 was tested; board_ahci_mv also covers the 88SE6145,
which Marvell's driver treats identically.

Fixes: cd70c26617f4 ("[libata] AHCI: Add support for Marvell AHCI-like chips (initially 6145)")
Cc: stable@vger.kernel.org
Link: https://lore.kernel.org/linux-ide/db6b48b7-d69a-564b-24f0-75fbd6a9e543@noerenberg.de/
Link: https://bugzilla.kernel.org/show_bug.cgi?id=216094
Signed-off-by: Hajo Noerenberg <hajo-linux-ide@noerenberg.de>
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Acked-by: Pali Rohar <pali@kernel.org>
Link: https://lore.kernel.org/r/20260831124303.920391-1-hajo-linux-ide@noerenberg.de
Signed-off-by: Niklas Cassel <cassel@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/ata/ahci.c |   49 +++++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 49 insertions(+)

--- a/drivers/ata/ahci.c
+++ b/drivers/ata/ahci.c
@@ -2614,6 +2614,51 @@ static irqreturn_t ahci_thunderx_irq_han
 }
 #endif
 
+/*
+ * The Marvell 88SE6111/6121/6145 ("Thor") family stops reporting interrupts
+ * for a port when HOST_IRQ_STAT is cleared while PxIS still holds bits: PxIS
+ * keeps its content, HOST_IRQ_STAT reads back as 0, the port is never looked
+ * at again and the command in flight only ends in a timeout.  On a 88SE6121
+ * this makes every SATA-2 or SATA-3 disk fail to IDENTIFY, while SATA-1 disks
+ * happen to win the race often enough to work.
+ *
+ * Clearing the host status before servicing the ports avoids it.  Marvell's
+ * own driver for these chips does the same and says so ("clear global before
+ * channel"), and ahci_xgene handles its broken edge latch the same way.  The
+ * price is at most one spurious interrupt per valid one, which is why this is
+ * not the generic behaviour - see AHCI 1.1 section 10.6.2.
+ *
+ * Link: https://bugzilla.kernel.org/show_bug.cgi?id=216094
+ */
+static irqreturn_t ahci_mv_irq_handler(int irq, void *dev_instance)
+{
+	struct ata_host *host = dev_instance;
+	struct ahci_host_priv *hpriv = host->private_data;
+	void __iomem *mmio = hpriv->mmio;
+	unsigned int rc;
+	u32 irq_stat, irq_masked;
+
+	irq_stat = readl(mmio + HOST_IRQ_STAT);
+	if (!irq_stat)
+		return IRQ_NONE;
+
+	irq_masked = irq_stat & hpriv->port_map;
+
+	spin_lock(&host->lock);
+
+	/*
+	 * Use the unmasked value to clear the interrupt, as a spurious pending
+	 * event on a dummy port might cause a screaming IRQ.
+	 */
+	writel(irq_stat, mmio + HOST_IRQ_STAT);
+
+	rc = ahci_handle_port_intr(host, irq_masked);
+
+	spin_unlock(&host->lock);
+
+	return IRQ_RETVAL(rc);
+}
+
 static void ahci_remap_check(struct pci_dev *pdev, int bar,
 		struct ahci_host_priv *hpriv)
 {
@@ -2917,6 +2962,10 @@ static int ahci_init_one(struct pci_dev
 		return -ENOMEM;
 	hpriv->flags |= (unsigned long)pi.private_data;
 
+	/* the Marvell "Thor" family needs HOST_IRQ_STAT cleared first */
+	if (board_id == board_ahci_mv)
+		hpriv->irq_handler = ahci_mv_irq_handler;
+
 	/* MCP65 revision A1 and A2 can't do MSI */
 	if (board_id == board_ahci_mcp65 &&
 	    (pdev->revision == 0xa1 || pdev->revision == 0xa2))



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 121/556] ima: Check for ERR_PTR from dentry_path() in validate_hash_algo()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (119 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 120/556] ata: ahci: work around lost interrupts on Marvell 88SE61xx Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 122/556] irqchip/stm32mp-exti: Fix the unit of the hwspinlock timeout Greg Kroah-Hartman
                   ` (447 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+5ebeb3089ea6439c37be,
	Bradley Morgan, Mimi Zohar

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bradley Morgan <brads@mainlining.org>

commit 8861f6d5c0678a7c5089c7b272509fc5931b8437 upstream.

dentry_path() returns ERR_PTR(-ENAMETOOLONG) when the path exceeds the
buffer. validate_hash_algo() passes the result straight to
integrity_audit_msg() without checking. ERR_PTR is not NULL, so
integrity_audit_message() sees a valid pointer and calls strlen() on
it, which faults:

    BUG: unable to handle page fault for address: ffffffffffffffdc
    RIP: 0010:strlen+0x30/0xa0
    Call Trace:
     audit_log_untrustedstring+0x19/0x30
     integrity_audit_message+0x366/0x4f0
     ima_inode_setxattr+0x512/0x5f0

Check for IS_ERR() and use NULL instead, which makes the audit message
skip the name= field instead of crashing.

Fixes: 4f2946aa0c45 ("IMA: introduce a new policy option func=SETXATTR_CHECK")
Cc: stable@vger.kernel.org
Reported-by: syzbot+5ebeb3089ea6439c37be@syzkaller.appspotmail.com
Link: https://lore.kernel.org/all/6a8f89e5.1d9ded08.62e62.00bf.GAE@google.com/
Signed-off-by: Bradley Morgan <brads@mainlining.org>
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 security/integrity/ima/ima_appraise.c |    2 ++
 1 file changed, 2 insertions(+)

--- a/security/integrity/ima/ima_appraise.c
+++ b/security/integrity/ima/ima_appraise.c
@@ -748,6 +748,8 @@ static int validate_hash_algo(struct den
 		return -EACCES;
 
 	path = dentry_path(dentry, pathbuf, PATH_MAX);
+	if (IS_ERR(path))
+		path = NULL;
 
 	integrity_audit_msg(AUDIT_INTEGRITY_DATA, d_inode(dentry), path,
 			    "set_data", errmsg, -EACCES, 0);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 122/556] irqchip/stm32mp-exti: Fix the unit of the hwspinlock timeout
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (120 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 121/556] ima: Check for ERR_PTR from dentry_path() in validate_hash_algo() Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 123/556] kprobes: Protect kprobe_blacklist with RCU Greg Kroah-Hartman
                   ` (446 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ju Nan, Thomas Gleixner, Radu Rendec,
	Antonio Borneo

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ju Nan <junan76@163.com>

commit d31fbbade43f880b7e59e2b3a72722fe2725d93f upstream.

HWSPNLCK_TIMEOUT is passed to hwspin_lock_timeout_in_atomic(), whose
timeout argument is in milliseconds, not microseconds:

  atomic_delay += HWSPINLOCK_RETRY_DELAY_US;
  if (atomic_delay > to * 1000)
          return -ETIMEDOUT;

So stm32mp_exti_set_type() asks for a 1 second timeout where the comment
next to the macro says it wants 1 millisecond. The semaphore is polled
with udelay() from a section that holds chip_data->rlock, a
raw_spinlock_t, so preemption stays disabled for the whole wait on every
configuration, PREEMPT_RT included.

The hwspinlock core documents this explicitly:

  If the mode is HWLOCK_IN_ATOMIC (called from an atomic context) the
  timeout is handled with busy-waiting delays, hence shall not exceed
  few msecs.

Fixes: 5257169ade8c ("irqchip/stm32-exti: Use the hwspin_lock_timeout_in_atomic() API")
Signed-off-by: Ju Nan <junan76@163.com>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Reviewed-by: Radu Rendec <radu@rendec.net>
Reviewed-by: Antonio Borneo <antonio.borneo@foss.st.com>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260821024756.24927-2-junan76@163.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/irqchip/irq-stm32mp-exti.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/drivers/irqchip/irq-stm32mp-exti.c
+++ b/drivers/irqchip/irq-stm32mp-exti.c
@@ -22,7 +22,7 @@
 
 #define IRQS_PER_BANK			32
 
-#define HWSPNLCK_TIMEOUT		1000 /* usec */
+#define HWSPNLCK_TIMEOUT_MS		1
 
 #define EXTI_EnCIDCFGR(n)		(0x180 + (n) * 4)
 #define EXTI_HWCFGR1			0x3f0
@@ -376,7 +376,7 @@ static int stm32mp_exti_set_type(struct
 	raw_spin_lock(&chip_data->rlock);
 
 	if (hwlock) {
-		err = hwspin_lock_timeout_in_atomic(hwlock, HWSPNLCK_TIMEOUT);
+		err = hwspin_lock_timeout_in_atomic(hwlock, HWSPNLCK_TIMEOUT_MS);
 		if (err) {
 			pr_err("%s can't get hwspinlock (%d)\n", __func__, err);
 			goto unlock;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 123/556] kprobes: Protect kprobe_blacklist with RCU
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (121 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 122/556] irqchip/stm32mp-exti: Fix the unit of the hwspinlock timeout Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 124/556] misc: fastrpc: dont publish fd before copy_to_user() succeeds Greg Kroah-Hartman
                   ` (445 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Masami Hiramatsu (Google)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Masami Hiramatsu (Google) <mhiramat@kernel.org>

commit 0c4256196b3a105307e2235fbfd85e768bbcdd0f upstream.

__within_kprobe_blacklist() traverses kprobe_blacklist without holding
kprobe_mutex. When a module is unloaded, kprobe_remove_area_blacklist()
removes blacklist entries and immediately frees them with kfree().
A concurrent call to within_kprobe_blacklist() can therefore dereference
freed memory.

Furthermore, within_kprobe_blacklist() can be called in atomic or
non-preemptible contexts where the sleeping kprobe_mutex cannot be taken.

Protect kprobe_blacklist with RCU. Use guard(rcu)() and
list_for_each_entry_rcu() for traversal, list_add_tail_rcu() for
insertions, list_del_rcu() for deletions, and kfree_rcu() to reclaim
entries safely after a grace period.

Link: https://lore.kernel.org/all/178810004323.64882.16493230858653316962.stgit@devnote2/

Fixes: 376e242429bf ("kprobes: Introduce NOKPROBE_SYMBOL() macro to maintain kprobes blacklist")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/all/20260807155802.F06041F000E9@smtp.kernel.org/
Assisted-by: Antigravity:gemini-3.7-flash
Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 include/linux/kprobes.h |    1 +
 kernel/kprobes.c        |   14 ++++++++++----
 2 files changed, 11 insertions(+), 4 deletions(-)

--- a/include/linux/kprobes.h
+++ b/include/linux/kprobes.h
@@ -181,6 +181,7 @@ struct kprobe_blacklist_entry {
 	struct list_head list;
 	unsigned long start_addr;
 	unsigned long end_addr;
+	struct rcu_head rcu;
 };
 
 #ifdef CONFIG_KPROBES
--- a/kernel/kprobes.c
+++ b/kernel/kprobes.c
@@ -1447,8 +1447,14 @@ static bool __within_kprobe_blacklist(un
 	/*
 	 * If 'kprobe_blacklist' is defined, check the address and
 	 * reject any probe registration in the prohibited area.
+	 * Note: this can return true during transition period where
+	 * (start_addr, end_addr) in the black list is shrinking
+	 * but old entry has not been removed yet. This is acceptable
+	 * because the worst case is that we reject more probes than
+	 * we should.
 	 */
-	list_for_each_entry(ent, &kprobe_blacklist, list) {
+	guard(rcu)();
+	list_for_each_entry_rcu(ent, &kprobe_blacklist, list) {
 		if (addr >= ent->start_addr && addr < ent->end_addr)
 			return true;
 	}
@@ -2509,7 +2515,7 @@ int kprobe_add_ksym_blacklist(unsigned l
 	ent->start_addr = entry;
 	ent->end_addr = entry + size;
 	INIT_LIST_HEAD(&ent->list);
-	list_add_tail(&ent->list, &kprobe_blacklist);
+	list_add_tail_rcu(&ent->list, &kprobe_blacklist);
 
 	return (int)size;
 }
@@ -2603,8 +2609,8 @@ static void kprobe_remove_area_blacklist
 	list_for_each_entry_safe(ent, n, &kprobe_blacklist, list) {
 		if (ent->start_addr < start || ent->start_addr >= end)
 			continue;
-		list_del(&ent->list);
-		kfree(ent);
+		list_del_rcu(&ent->list);
+		kfree_rcu(ent, rcu);
 	}
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 124/556] misc: fastrpc: dont publish fd before copy_to_user() succeeds
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (122 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 123/556] kprobes: Protect kprobe_blacklist with RCU Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 125/556] mm/huge_memory: transfer the pmd dirty bit to the folio on zap Greg Kroah-Hartman
                   ` (444 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Christian König, Sumit Semwal,
	Baineng Shou

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Baineng Shou <shoubaineng@gmail.com>

commit a4a1a2bfcb29785292d634d7787edc6fb550714d upstream.

fastrpc_ioctl_alloc_dmabuf() calls dma_buf_fd() which installs the fd
into the caller's fd table before copy_to_user() copies the fd number
back to userspace.  If copy_to_user() fails, the fd is already visible
to other threads in the same process but the ioctl returns -EFAULT.
The existing comment in the code even acknowledges the problem:

  "The usercopy failed, but we can't do much about it, as dma_buf_fd()
   already called fd_install()..."

Now that dma_buf_fd_install() is available (introduced to fix the same
issue in dma-heap), apply the same pattern here: reserve the fd with
get_unused_fd_flags(), attempt copy_to_user(), and only on success call
dma_buf_fd_install() to publish it atomically with the tracepoint.  On
copy_to_user() failure, put_unused_fd() and dma_buf_put() cleanly
unwind without any user-visible side effects.

Fixes: 6cffd79504ce ("misc: fastrpc: Add support for dmabuf exporter")
Cc: stable@vger.kernel.org
Acked-by: Christian König <christian.koenig@amd.com>
Acked-by: Sumit Semwal <sumit.semwal@linaro.org>
Signed-off-by: Baineng Shou <shoubaineng@gmail.com>
Link: https://lore.kernel.org/r/20260817050457.1005285-3-shoubaineng@gmail.com
Signed-off-by: Christian König <christian.koenig@amd.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/misc/fastrpc.c |   16 ++++++----------
 1 file changed, 6 insertions(+), 10 deletions(-)

--- a/drivers/misc/fastrpc.c
+++ b/drivers/misc/fastrpc.c
@@ -1712,24 +1712,20 @@ static int fastrpc_dmabuf_alloc(struct f
 		return err;
 	}
 
-	bp.fd = dma_buf_fd(buf->dmabuf, O_ACCMODE);
+	bp.fd = get_unused_fd_flags(O_ACCMODE);
 	if (bp.fd < 0) {
 		dma_buf_put(buf->dmabuf);
-		return -EINVAL;
+		return bp.fd;
 	}
 
 	if (copy_to_user(argp, &bp, sizeof(bp))) {
-		/*
-		 * The usercopy failed, but we can't do much about it, as
-		 * dma_buf_fd() already called fd_install() and made the
-		 * file descriptor accessible for the current process. It
-		 * might already be closed and dmabuf no longer valid when
-		 * we reach this point. Therefore "leak" the fd and rely on
-		 * the process exit path to do any required cleanup.
-		 */
+		put_unused_fd(bp.fd);
+		dma_buf_put(buf->dmabuf);
 		return -EFAULT;
 	}
 
+	dma_buf_fd_install(buf->dmabuf, bp.fd);
+
 	return 0;
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 125/556] mm/huge_memory: transfer the pmd dirty bit to the folio on zap
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (123 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 124/556] misc: fastrpc: dont publish fd before copy_to_user() succeeds Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 126/556] mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave() Greg Kroah-Hartman
                   ` (443 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Usama Arif, David Hildenbrand (Arm),
	Kiryl Shutsemau, Hugh Dickins, Lance Yang, Zi Yan,
	Lorenzo Stoakes (ARM), Baolin Wang, Barry Song, Dev Jain,
	Johannes Weiner, Liam R. Howlett, Nhat Pham, Rik van Riel,
	Ryan Roberts, Shakeel Butt, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Usama Arif <usama.arif@linux.dev>

commit fe6cf984939d8e12cb33a99673c8d026c5135e68 upstream.

zap_huge_pmd_folio() propagates the pmd young bit to the folio for the
file case, but not the dirty bit.  The pte path does propagate it, in
zap_present_folio_ptes() and so does the pmd split path, in
__split_huge_pmd_locked().

For most file mappings the omission is harmless, because writing to a
shared file mapping goes through page_mkwrite(), which dirties the folio.
tmpfs is different: it has no page_mkwrite(), and vma_wants_writenotify()
is false for it, so a *read* fault on a MAP_SHARED tmpfs mapping installs
a writable pmd via do_read_fault().  do_read_fault() does not call
fault_dirty_shared_page(), so subsequent stores through that mapping set
only the hardware dirty bit in the pmd and never call folio_mark_dirty().
A shmem folio allocated by a fault is marked uptodate but not dirty (see
the clear: block in shmem_get_folio_gfp()), so PG_dirty is never set at
all.

Unmapping such a folio - munmap(), or exit_mmap() when the process dies -
then loses the only record that it was written, because zap_huge_pmd()
drops the pmd without transferring the dirty bit.  Reclaim afterwards sees
a clean shmem folio: the whole swap-out block in shrink_folio_list() is
inside "if (folio_test_dirty(folio))", so pageout() is skipped and the
folio falls into __remove_mapping().  There, folio_is_file_lru() is false
for a swapbacked folio, so no shadow entry is created and
__filemap_remove_folio(folio, NULL) simply empties the i_pages slot.  The
data is freed without ever being written to swap, and the next fault on
that index returns a freshly zeroed folio.

This is silent data loss for any process that keeps state in a MAP_SHARED
tmpfs segment across an unmap - for example a cache handed from one
process generation to the next through /dev/shm.  It requires the folio to
be PMD-mapped, so it only shows up once shmem THP is enabled (which is
what we did in Meta fleet and started noticing crashes); with THP off the
pte path transfers the dirty bit correctly.  It also only becomes visible
when swap is enabled, because with no swap device shmem folios (which are
on the anon LRU) are not scanned by reclaim at all, so the clean folio is
never dropped.

Reproduced on x86_64 with a tmpfs mounted huge=within_size: read-fault a
2MB-backed region, write a known pattern through the resulting mapping,
munmap, force reclaim of the cgroup, then re-map and read back.  Without
this patch the region reads back as zeros and vmstat shows zswpout 0 - the
data was discarded rather than swapped.  With this patch the region reads
back correctly and the pages are swapped out as expected.  With
huge=never, or when the first touch is a write, the test passes either
way.

Link: https://lore.kernel.org/20260819101222.3732660-1-usama.arif@linux.dev
Fixes: b5072380eb61 ("thp: support file pages in zap_huge_pmd()")
Signed-off-by: Usama Arif <usama.arif@linux.dev>
Acked-by: David Hildenbrand (Arm) <david@kernel.org>
Reviewed-by: Kiryl Shutsemau <kas@kernel.org>
Acked-by: Hugh Dickins <hughd@google.com>
Tested-by: Lance Yang <lance.yang@linux.dev>
Reviewed-by: Zi Yan <ziy@nvidia.com>
Reviewed-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Reviewed-by: Baolin Wang <baolin.wang@linux.alibaba.com>
Cc: Barry Song <baohua@kernel.org>
Cc: Dev Jain <dev.jain@arm.com>
Cc: Johannes Weiner <hannes@cmpxchg.org>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Nhat Pham <nphamcs@gmail.com>
Cc: Rik van Riel <riel@surriel.com>
Cc: Ryan Roberts <ryan.roberts@arm.com>
Cc: Shakeel Butt <shakeel.butt@linux.dev>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/huge_memory.c |    2 ++
 1 file changed, 2 insertions(+)

--- a/mm/huge_memory.c
+++ b/mm/huge_memory.c
@@ -2414,6 +2414,8 @@ static void zap_huge_pmd_folio(struct mm
 		add_mm_counter(mm, mm_counter_file(folio),
 			       -HPAGE_PMD_NR);
 
+		if (is_present && pmd_dirty(pmdval))
+			folio_mark_dirty(folio);
 		if (is_present && pmd_young(pmdval) &&
 		    likely(vma_has_recency(vma)))
 			folio_mark_accessed(folio);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 126/556] mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (124 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 125/556] mm/huge_memory: transfer the pmd dirty bit to the folio on zap Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 127/556] memcg: keep folios objcg same as its node Greg Kroah-Hartman
                   ` (442 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Eric Dumazet,
	syzbot+0dbf6d295b3350944f0b, Andrew Morton, Gregory Price (Meta),
	David Hildenbrand (Arm), Alistair Popple, Byungchul Park,
	Huang, Ying, Joshua Hahn, Matthew Brost, Rakie Kim, Zi Yan

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eric Dumazet <edumazet@google.com>

commit 540e583b66d6402bf556fde5e53c817a54c1afe5 upstream.

syzbot reported a sleeping function called from invalid context splat in
bucket_table_alloc().

When rhashtable_insert_slow() rehashes the table under rcu_read_lock(), it
calls bucket_table_alloc(..., GFP_ATOMIC | __GFP_NOWARN).  If the bucket
table allocation uses vmalloc, __vmalloc_node_range_noprof() invokes
vm_area_alloc_pages() -> alloc_pages_bulk_mempolicy_noprof() with the
passed GFP_ATOMIC flags.

If the current task has an MPOL_WEIGHTED_INTERLEAVE mempolicy,
alloc_pages_bulk_weighted_interleave() is called and currently hardcodes
GFP_KERNEL when allocating the temporary weights array, triggering a
might_alloc() splat in atomic/RCU contexts.

Pass the gfp flags (masked with GFP_RECLAIM_MASK to strip page-allocator
zone modifiers like __GFP_HIGHMEM) received by
alloc_pages_bulk_weighted_interleave() to kmalloc() instead of hardcoding
GFP_KERNEL.  Since the weights buffer is immediately initialized in full,
kmalloc() is sufficient.

Link: https://lore.kernel.org/20260821170407.3721004-1-edumazet@google.com
Fixes: fa3bea4e1f82 ("mm/mempolicy: introduce MPOL_WEIGHTED_INTERLEAVE for weighted interleaving")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reported-by: syzbot+0dbf6d295b3350944f0b@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/lkml/6a88837e.ae6ddae5.3da009.0040.GAE@google.com/T/#u
Reviewed-by: Andrew Morton <akpm@linux-foundation.org>
Reviewed-by: Gregory Price (Meta) <gourry@gourry.net>
Acked-by: David Hildenbrand (Arm) <david@kernel.org>
Cc: Alistair Popple <apopple@nvidia.com>
Cc: Byungchul Park <byungchul@sk.com>
Cc: "Huang, Ying" <ying.huang@linux.alibaba.com>
Cc: Joshua Hahn <joshua.hahnjy@gmail.com>
Cc: Matthew Brost <matthew.brost@intel.com>
Cc: Rakie Kim <rakie.kim@sk.com>
Cc: Zi Yan <ziy@nvidia.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/mempolicy.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/mm/mempolicy.c
+++ b/mm/mempolicy.c
@@ -2676,7 +2676,7 @@ static unsigned long alloc_pages_bulk_we
 	prev_node = node;
 
 	/* create a local copy of node weights to operate on outside rcu */
-	weights = kzalloc(nr_node_ids, GFP_KERNEL);
+	weights = kmalloc(nr_node_ids, gfp & GFP_RECLAIM_MASK);
 	if (!weights)
 		return total_allocated;
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 127/556] memcg: keep folios objcg same as its node
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (125 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 126/556] mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave() Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 128/556] memcg: bypass the reclaim and oom killer for dying tasks once oom_reaper is done Greg Kroah-Hartman
                   ` (441 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Johannes Weiner, Shakeel Butt,
	Karl Erik Hofseth, Muchun Song, Qi Zheng, Michal Hocko,
	Roman Gushchin, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Shakeel Butt <shakeel.butt@linux.dev>

commit bf4ade7dbd76d4ec8697840e4ebb15ed77c5ec26 upstream.

memcg_reparent_objcgs() has an inherent assumption that a folio's objcg is
the objcg of the folio's node.  Folio migration across nodes breaks that
assumption: the new folio simply inherits the old folio's objcg while
living on a different node.

Once the assumption is broken, the reparenting of the folio's objcg and
the reparenting of the folio's LRU list are no longer atomic.
memcg_reparent_objcgs() handles one node per iteration and drops all the
locks in between, so the objcg gets reparented in the iteration for the
objcg's node while the LRU list gets spliced in the iteration for the
folio's node.  Any LRU operation on that folio in between resolves its
lruvec through the objcg, and thus takes the lru_lock of the wrong memcg,
not the lru_lock of the list the folio is actually on.

Fix this by selecting the objcg by folio_nid() at charge time, and by
re-deriving it for the destination node in mem_cgroup_migrate() and
mem_cgroup_replace_folio().

Link: https://lore.kernel.org/20260807142406.443516-1-shakeel.butt@linux.dev
Fixes: f1cf8d2f36dc ("mm: memcontrol: eliminate the problem of dying memory cgroup for LRU folios")
Signed-off-by: Johannes Weiner <hannes@cmpxchg.org>
Signed-off-by: Shakeel Butt <shakeel.butt@linux.dev>
Reported-by: Karl Erik Hofseth <karl.e.hofseth@opoint.com>
Closes: https://lore.kernel.org/all/anMmd1ADrDVwMO6v@work/
Co-developed-by: Johannes Weiner <hannes@cmpxchg.org>
Acked-by: Muchun Song <muchun.song@linux.dev>
Acked-by: Qi Zheng <qi.zheng@linux.dev>
Cc: Michal Hocko <mhocko@suse.com>
Cc: Roman Gushchin <roman.gushchin@linux.dev>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/memcontrol.c |  100 ++++++++++++++++++++++++++++++++++++++++++++++----------
 1 file changed, 83 insertions(+), 17 deletions(-)

--- a/mm/memcontrol.c
+++ b/mm/memcontrol.c
@@ -2907,10 +2907,9 @@ struct mem_cgroup *mem_cgroup_from_virt(
 	return folio_memcg_check(virt_to_folio(p));
 }
 
-static struct obj_cgroup *__get_obj_cgroup_from_memcg(struct mem_cgroup *memcg)
+static struct obj_cgroup *__get_obj_cgroup_from_memcg(struct mem_cgroup *memcg,
+						      int nid)
 {
-	int nid = numa_node_id();
-
 	for (; memcg; memcg = parent_mem_cgroup(memcg)) {
 		struct obj_cgroup *objcg = rcu_dereference(memcg->nodeinfo[nid]->objcg);
 
@@ -2921,12 +2920,13 @@ static struct obj_cgroup *__get_obj_cgro
 	return NULL;
 }
 
-static inline struct obj_cgroup *get_obj_cgroup_from_memcg(struct mem_cgroup *memcg)
+static inline struct obj_cgroup *get_obj_cgroup_from_memcg(struct mem_cgroup *memcg,
+							   int nid)
 {
 	struct obj_cgroup *objcg;
 
 	rcu_read_lock();
-	objcg = __get_obj_cgroup_from_memcg(memcg);
+	objcg = __get_obj_cgroup_from_memcg(memcg, nid);
 	rcu_read_unlock();
 
 	return objcg;
@@ -2970,7 +2970,7 @@ static struct obj_cgroup *current_objcg_
 
 		rcu_read_lock();
 		memcg = mem_cgroup_from_task(current);
-		objcg = __get_obj_cgroup_from_memcg(memcg);
+		objcg = __get_obj_cgroup_from_memcg(memcg, numa_node_id());
 		rcu_read_unlock();
 
 		/*
@@ -5133,7 +5133,7 @@ static int charge_memcg(struct folio *fo
 	int ret = 0;
 	struct obj_cgroup *objcg;
 
-	objcg = get_obj_cgroup_from_memcg(memcg);
+	objcg = get_obj_cgroup_from_memcg(memcg, folio_nid(folio));
 	/* Do not account at the root objcg level. */
 	if (!obj_cgroup_is_root(objcg))
 		ret = try_charge_memcg(memcg, gfp, folio_nr_pages(folio));
@@ -5332,6 +5332,46 @@ void __mem_cgroup_uncharge_folios(struct
 		uncharge_batch(&ug);
 }
 
+/*
+ * An LRU folio must hold the objcg belonging to its own node.
+ *
+ * memcg_reparent_objcgs() reparents a dying cgroup one node at a time: the
+ * folios on that node's LRU lists move to the parent and that node's objcg is
+ * redirected to the parent, atomically under the node's lru_lock.
+ * folio_lruvec_lock() relies on this to provide a stable folio<->lruvec
+ * binding. If a folio holds another node's objcg, its list membership and its
+ * lruvec resolution change in separate lock sections, and an LRU operation in
+ * between can re-add the folio to, and strand it on, the LRU list of a dead
+ * memcg.
+ *
+ * So when migration transfers the memcg state to a folio on another node,
+ * re-derive the objcg for the destination node. If the memcg is dying and the
+ * destination node has already been reparented, the lookup walks up to the
+ * nearest live ancestor - which is also where that node's LRU lists went.
+ *
+ * Returns the objcg to commit to @new, with a reference for the caller.
+ */
+static struct obj_cgroup *get_migration_objcg(struct folio *old,
+					      struct folio *new)
+{
+	struct obj_cgroup *old_objcg, *new_objcg;
+	int new_nid = folio_nid(new);
+
+	old_objcg = get_obj_cgroup_from_folio(old);
+
+	if (folio_nid(old) == new_nid)
+		return old_objcg;
+
+	rcu_read_lock();
+	new_objcg = __get_obj_cgroup_from_memcg(obj_cgroup_memcg(old_objcg),
+						new_nid);
+	rcu_read_unlock();
+
+	obj_cgroup_put(old_objcg);
+
+	return new_objcg;
+}
+
 /**
  * mem_cgroup_replace_folio - Charge a folio's replacement.
  * @old: Currently circulating folio.
@@ -5360,21 +5400,28 @@ void mem_cgroup_replace_folio(struct fol
 	if (folio_memcg_charged(new))
 		return;
 
-	objcg = folio_objcg(old);
-	VM_WARN_ON_ONCE_FOLIO(!objcg, old);
-	if (!objcg)
+	VM_WARN_ON_ONCE_FOLIO(!folio_objcg(old), old);
+	if (!folio_objcg(old))
 		return;
 
+	objcg = get_migration_objcg(old, new);
+
 	rcu_read_lock();
 	memcg = obj_cgroup_memcg(objcg);
-	/* Force-charge the new page. The old one will be freed soon */
+
+	/*
+	 * Force-charge the new page. The old one will be freed soon.
+	 *
+	 * The rootness of the committed objcg decides whether the final
+	 * uncharge of @new goes through the page counters (see
+	 * uncharge_folio()); charge them only if the uncharge will.
+	 */
 	if (!obj_cgroup_is_root(objcg)) {
 		page_counter_charge(&memcg->memory, nr_pages);
 		if (do_memsw_account())
 			page_counter_charge(&memcg->memsw, nr_pages);
 	}
 
-	obj_cgroup_get(objcg);
 	commit_charge(new, objcg);
 	memcg1_commit_charge(new, memcg);
 	rcu_read_unlock();
@@ -5386,14 +5433,15 @@ void mem_cgroup_replace_folio(struct fol
  * @new: Replacement folio.
  *
  * Transfer the memcg data from the old folio to the new folio for migration.
- * The old folio's data info will be cleared. Note that the memory counters
- * will remain unchanged throughout the process.
+ * The old folio's data info will be cleared. The memory counters remain
+ * unchanged, unless the charge moves out of a fully reparented ancestry
+ * and has to be settled (see below).
  *
  * Both folios must be locked, @new->mapping must be set up.
  */
 void mem_cgroup_migrate(struct folio *old, struct folio *new)
 {
-	struct obj_cgroup *objcg;
+	struct obj_cgroup *objcg, *new_objcg;
 
 	VM_BUG_ON_FOLIO(!folio_test_locked(old), old);
 	VM_BUG_ON_FOLIO(!folio_test_locked(new), new);
@@ -5414,12 +5462,30 @@ void mem_cgroup_migrate(struct folio *ol
 	if (!objcg)
 		return;
 
-	/* Transfer the charge and the objcg ref */
-	commit_charge(new, objcg);
+	new_objcg = get_migration_objcg(old, new);
+
+	/*
+	 * @old was charged through a non-root objcg, so its charge is in the
+	 * page counters. If the re-derivation walked up to the root objcg -
+	 * @old's entire ancestry is dying and already reparented - the final
+	 * uncharge of @new will skip the page counters (see uncharge_folio()).
+	 * Settle them now: this is @old's eventual uncharge, moved up to the
+	 * point where its charge record ends.
+	 */
+	if (obj_cgroup_is_root(new_objcg) && !obj_cgroup_is_root(objcg)) {
+		rcu_read_lock();
+		memcg_uncharge(obj_cgroup_memcg(objcg), folio_nr_pages(old));
+		rcu_read_unlock();
+	}
+
+	commit_charge(new, new_objcg);
 
 	/* Warning should never happen, so don't worry about refcount non-0 */
 	WARN_ON_ONCE(folio_unqueue_deferred_split(old));
 	old->memcg_data = 0;
+
+	/* @new holds its own reference now, drop @old's */
+	obj_cgroup_put(objcg);
 }
 
 DEFINE_STATIC_KEY_FALSE(memcg_sockets_enabled_key);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 128/556] memcg: bypass the reclaim and oom killer for dying tasks once oom_reaper is done
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (126 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 127/556] memcg: keep folios objcg same as its node Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 129/556] memcg: make the v1 soft limit knob inert Greg Kroah-Hartman
                   ` (440 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Shakeel Butt, Johannes Weiner,
	Michal Hocko, David Rientjes, Muchun Song, Nhat Pham,
	Rik van Riel, Roman Gushchin, Suren Baghdasaryan, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Shakeel Butt <shakeel.butt@linux.dev>

commit 6b0d1083364fc8e7cc2f7d1f93ee3ee78f4d52f7 upstream.

At Meta, we are seeing instances where an OOM killed job is stuck in the
exit path for several hours.  In one particular case, the job was stuck
for more than 8 hours and I had to manually remove the memory.max limits
to allow the process to exit.

The job was a single process job and had ~55 GiB memory.max and zswap
enabled.  It had almost 0 anon in memory and ~111 GiB in zswap compressed
to ~51 GiB zswap pool (i.e.  almost all of memory.current was zswap).
Nothing was left on the LRUs to reclaim.

On further inspection, I observed ~20k threads of that process stuck with
the following stack:

[<0>] mem_cgroup_out_of_memory+0x4e/0xa0
[<0>] charge_memcg+0x8bf/0x990
[<0>] mem_cgroup_swapin_charge_folio+0x4e/0x80
[<0>] __read_swap_cache_async+0x10c/0x260
[<0>] swapin_readahead+0x116/0x3f0
[<0>] do_swap_page+0x13c/0x1ce0
[<0>] handle_mm_fault+0x61d/0x11f0
[<0>] do_user_addr_fault+0x3e7/0x6d0
[<0>] exc_page_fault+0x8f/0x110
[<0>] asm_exc_page_fault+0x22/0x30
[<0>] __get_user_8+0x14/0x20
[<0>] futex_cleanup+0x27/0x1c0
[<0>] futex_exit_release+0x47/0x60
[<0>] do_exit+0x107/0x940
[<0>] do_group_exit+0x81/0xa0
[<0>] get_signal+0x2b1/0x6e0
[<0>] arch_do_signal_or_restart+0x1a/0x1c0
[<0>] exit_to_user_mode_loop+0xa8/0x1c0
[<0>] do_syscall_64+0x152/0x250
[<0>] entry_SYSCALL_64_after_hwframe+0x4b/0x53

In addition the dmesg was filled with "Out of memory and no killable
processes..." messages.

I have no idea why oom reaper was not able to reap/unmap the process.  My
guess is that since oom reaper tries to acquire mmap_lock in read mode
limited number of times and then gives up, there might be a thread of that
process which had mmap_lock in write mode at that time.

My initial suspicion was the futex_cleanup and kernel page fault causing
infinite fault and charge retries but that was put to rest in previous
discussions happened on similar problem [1].

My current theory is that it is just a simple slow serialization behind
the oom_lock.  Unlike page allocator, memcg charge code takes the oom_lock
without the "try".  Though memcg oom code uses mutex_lock_killable(), note
that in the call stack get_signal() consumes SIGKILL (or
sigdelset(SIGKILL)) before calling do_group_exit().  So this
mutex_lock_killable() is just a mutex_lock() here.  Therefore 10s of
thousands of threads are waiting on oom_lock and one by one they get
-EFAULT from get_user() in the futex cleanup code and bails out.

Discussion from [1] led to commit a75ffa26122b ("memcg, oom: do not bypass
oom killer for dying tasks") which routes dying tasks into the OOM path
precisely so the oom_reaper can reap their mm and free the memory
asynchronously.  But the reaper is best-effort and one-shot: if it cannot
take mmap_lock for read (e.g.  a sibling thread holds it for write) it
sets MMF_OOM_SKIP and never retries, leaving only the glacial
oom_lock-serialized synchronous drain.

Once MMF_OOM_SKIP is set there is no more asynchronous reclaim coming for
the mm, so a dying task charging against it has nothing left to wait for:
it frees its memory only once it finishes exiting.  Running reclaim and
the (no-victim) OOM killer for it is then pointless, and doing it for 10s
of thousands of exiting threads is what serializes them behind oom_lock.
So before reclaim, if current is an OOM victim whose reaper is done, fail
the charge.

Reproduced with 20k threads, each parking a robust futex head on its own
zswapped page, OOM-group-killed while a sibling holds mmap_lock for write
so the reaper gives up and sets MMF_OOM_SKIP.  Tested on next-20260728 and
baseline show ~90 seconds exit time while with the patch the exit time
reduced to ~3 seconds.

Link: https://lore.kernel.org/20260729024612.3369005-1-shakeel.butt@linux.dev
Link: https://lore.kernel.org/7a4e5591f45df455e6a485fc5400989569d3d22d.camel@surriel.com/ [1]
Signed-off-by: Shakeel Butt <shakeel.butt@linux.dev>
Acked-by: Johannes Weiner <hannes@cmpxchg.org>
Acked-by: Michal Hocko <mhocko@suse.com>
Cc: David Rientjes <rientjes@google.com>
Cc: Muchun Song <muchun.song@linux.dev>
Cc: Nhat Pham <nphamcs@gmail.com>
Cc: Rik van Riel <riel@surriel.com>
Cc: Roman Gushchin <roman.gushchin@linux.dev>
Cc: Suren Baghdasaryan <surenb@google.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/memcontrol.c |   13 +++++++++++++
 1 file changed, 13 insertions(+)

--- a/mm/memcontrol.c
+++ b/mm/memcontrol.c
@@ -2648,6 +2648,19 @@ retry:
 	if (!gfpflags_allow_blocking(gfp_mask))
 		goto nomem;
 
+	/*
+	 * OOM victim still needs to charge memory to exit. OOM reaper should
+	 * help but it might fail on mmap_lock contention. If the victim is a
+	 * large thread group then all exiting threads might compete on oom_lock
+	 * just to learn that there is nothing really killable anymore. Bail
+	 * out early and fail the charge to expedite their exit. They are
+	 * considered fully reclaimed by the oom reaper and they shouldn't
+	 * contribute further charges.
+	 */
+	if (tsk_is_oom_victim(current) &&
+	    mm_flags_test(MMF_OOM_SKIP, current->signal->oom_mm))
+		goto nomem;
+
 	__memcg_memory_event(mem_over_limit, MEMCG_MAX, allow_spinning);
 	raised_max_event = true;
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 129/556] memcg: make the v1 soft limit knob inert
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (127 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 128/556] memcg: bypass the reclaim and oom killer for dying tasks once oom_reaper is done Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 130/556] rtc: rzn1: Handle EPROBE_DEFER for optional pps interrupt Greg Kroah-Hartman
                   ` (439 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Shakeel Butt,
	syzbot+12ee2725d5fde63a9c96, Michal Hocko, Axel Rasmussen,
	Barry Song, David Hildenbrand, Johannes Weiner, Kairui Song,
	Lorenzo Stoakes, Muchun Song, Roman Gushchin, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Shakeel Butt <shakeel.butt@linux.dev>

commit a3417097fb107cea3358b19bcbb4eb655fd67f8c upstream.

The v1 soft limit has been deprecated since v6.12 and nobody has reported
depending on it.  Start the removal by decoupling the interface from the
implementation: keep memory.soft_limit_in_bytes, but ignore writes to it
and always report the maximum value on read similar to what
memory.kmem.limit_in_bytes already does.

Writes are still parsed, so malformed input keeps returning -EINVAL.  The
knob now also behaves the same everywhere: it used to return -EOPNOTSUPP
on PREEMPT_RT, where soft limit reclaim has always been disabled.

This also fixes the syzbot report linked below.  Soft limit reclaim is the
only caller that runs shrink_lruvec() from kswapd against a specific
memcg, so it is the only way to reach lru_gen_shrink_lruvec() and in turn
set_mm_walk(), which warns when called from kswapd.

Link: https://lore.kernel.org/20260811203203.3456029-2-shakeel.butt@linux.dev
Signed-off-by: Shakeel Butt <shakeel.butt@linux.dev>
Reported-by: syzbot+12ee2725d5fde63a9c96@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/all/6a7a6929.b50370da.49fe0.005e.GAE@google.com/
Acked-by: Michal Hocko <mhocko@suse.com>
Cc: Axel Rasmussen <axelrasmussen@google.com>
Cc: Barry Song <baohua@kernel.org>
Cc: David Hildenbrand <david@kernel.org>
Cc: Johannes Weiner <hannes@cmpxchg.org>
Cc: Kairui Song <kasong@tencent.com>
Cc: Lorenzo Stoakes <ljs@kernel.org>
Cc: Muchun Song <muchun.song@linux.dev>
Cc: Roman Gushchin <roman.gushchin@linux.dev>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 Documentation/admin-guide/cgroup-v1/memory.rst |   49 +++----------------------
 mm/memcontrol-v1.c                             |   43 +++++++++++++--------
 2 files changed, 32 insertions(+), 60 deletions(-)

--- a/Documentation/admin-guide/cgroup-v1/memory.rst
+++ b/Documentation/admin-guide/cgroup-v1/memory.rst
@@ -47,7 +47,6 @@ Features:
  - pages are linked to per-memcg LRU exclusively, and there is no global LRU.
  - optionally, memory+swap usage can be accounted and limited.
  - hierarchical accounting
- - soft limit
  - moving (recharging) account at moving a task is selectable.
  - usage threshold notifier
  - memory pressure notifier
@@ -76,10 +75,9 @@ Brief summary of control files.
  memory.memsw.failcnt		     show the number of memory+Swap hits limits
  memory.max_usage_in_bytes	     show max memory usage recorded
  memory.memsw.max_usage_in_bytes     show max memory+Swap usage recorded
- memory.soft_limit_in_bytes	     set/show soft limit of memory usage
-				     This knob is not available on CONFIG_PREEMPT_RT systems.
-                                     This knob is deprecated and shouldn't be
-                                     used.
+ memory.soft_limit_in_bytes	     This knob is deprecated and has no effect.
+                                     Writes are ignored and reads always
+                                     return the maximum value.
  memory.stat			     show various statistics
  memory.use_hierarchy		     set/show hierarchical account enabled
                                      This knob is deprecated and shouldn't be
@@ -340,9 +338,6 @@ memory.kmem.usage_in_bytes, or in a sepa
 The main "kmem" counter is fed into the main counter, so kmem charges will
 also be visible from the user counter.
 
-Currently no soft limit is implemented for kernel memory. It is future work
-to trigger slab reclaim when those limits are reached.
-
 2.7.1 Current Kernel Memory resources accounted
 -----------------------------------------------
 
@@ -710,42 +705,10 @@ For compatibility reasons writing 1 to m
 
 THIS IS DEPRECATED!
 
-Soft limits allow for greater sharing of memory. The idea behind soft limits
-is to allow control groups to use as much of the memory as needed, provided
-
-a. There is no memory contention
-b. They do not exceed their hard limit
-
-When the system detects memory contention or low memory, control groups
-are pushed back to their soft limits. If the soft limit of each control
-group is very high, they are pushed back as much as possible to make
-sure that one control group does not starve the others of memory.
-
-Please note that soft limits is a best-effort feature; it comes with
-no guarantees, but it does its best to make sure that when memory is
-heavily contended for, memory is allocated based on the soft limit
-hints/setup. Currently soft limit based reclaim is set up such that
-it gets invoked from balance_pgdat (kswapd).
-
-7.1 Interface
--------------
+Writing to memory.soft_limit_in_bytes has no effect and reading it will
+always return the maximum value.
 
-Soft limits can be setup by using the following commands (in this example we
-assume a soft limit of 256 MiB)::
-
-	# echo 256M > memory.soft_limit_in_bytes
-
-If we want to change this to 1G, we can at any time use::
-
-	# echo 1G > memory.soft_limit_in_bytes
-
-.. note::
-       Soft limits take effect over a long period of time, since they involve
-       reclaiming memory for balancing between memory cgroups
-
-.. note::
-       It is recommended to set the soft limit always below the hard limit,
-       otherwise the hard limit will take precedence.
+Use memory.low and memory.min in cgroup v2 instead.
 
 .. _cgroup-v1-memory-move-charges:
 
--- a/mm/memcontrol-v1.c
+++ b/mm/memcontrol-v1.c
@@ -95,7 +95,6 @@ enum {
 	RES_LIMIT,
 	RES_MAX_USAGE,
 	RES_FAILCNT,
-	RES_SOFT_LIMIT,
 };
 
 #ifdef CONFIG_LOCKDEP
@@ -1589,6 +1588,30 @@ static int mem_cgroup_hierarchy_write(st
 	return -EINVAL;
 }
 
+static u64 mem_cgroup_soft_limit_read(struct cgroup_subsys_state *css,
+				      struct cftype *cft)
+{
+	return (u64)PAGE_COUNTER_MAX * PAGE_SIZE;
+}
+
+static ssize_t mem_cgroup_soft_limit_write(struct kernfs_open_file *of,
+					   char *buf, size_t nbytes, loff_t off)
+{
+	unsigned long nr_pages;
+	int ret;
+
+	ret = page_counter_memparse(strstrip(buf), "-1", &nr_pages);
+	if (ret)
+		return ret;
+
+	pr_warn_once("soft_limit_in_bytes is deprecated and will be removed. "
+		     "Writing any value to this file has no effect. "
+		     "Please report your usecase to linux-mm@kvack.org if you "
+		     "depend on this functionality.\n");
+
+	return nbytes;
+}
+
 static u64 mem_cgroup_read_u64(struct cgroup_subsys_state *css,
 			       struct cftype *cft)
 {
@@ -1625,8 +1648,6 @@ static u64 mem_cgroup_read_u64(struct cg
 		return (u64)counter->watermark * PAGE_SIZE;
 	case RES_FAILCNT:
 		return counter->failcnt;
-	case RES_SOFT_LIMIT:
-		return (u64)READ_ONCE(memcg->soft_limit) * PAGE_SIZE;
 	default:
 		BUG();
 	}
@@ -1721,17 +1742,6 @@ static ssize_t mem_cgroup_write(struct k
 			break;
 		}
 		break;
-	case RES_SOFT_LIMIT:
-		if (IS_ENABLED(CONFIG_PREEMPT_RT)) {
-			ret = -EOPNOTSUPP;
-		} else {
-			pr_warn_once("soft_limit_in_bytes is deprecated and will be removed. "
-				     "Please report your usecase to linux-mm@kvack.org if you "
-				     "depend on this functionality.\n");
-			WRITE_ONCE(memcg->soft_limit, nr_pages);
-			ret = 0;
-		}
-		break;
 	}
 	return ret ?: nbytes;
 }
@@ -2085,9 +2095,8 @@ struct cftype mem_cgroup_legacy_files[]
 	},
 	{
 		.name = "soft_limit_in_bytes",
-		.private = MEMFILE_PRIVATE(_MEM, RES_SOFT_LIMIT),
-		.write = mem_cgroup_write,
-		.read_u64 = mem_cgroup_read_u64,
+		.write = mem_cgroup_soft_limit_write,
+		.read_u64 = mem_cgroup_soft_limit_read,
 	},
 	{
 		.name = "failcnt",



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 130/556] rtc: rzn1: Handle EPROBE_DEFER for optional pps interrupt
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (128 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 129/556] memcg: make the v1 soft limit knob inert Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 131/556] rtc: rzn1: Fix weekday underflow when alarm crosses month boundary Greg Kroah-Hartman
                   ` (438 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Lad Prabhakar, Wolfram Sang,
	Alexandre Belloni

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>

commit 708546aa39560a11cf44c7ba99492c8395a6c2fb upstream.

Check for -EPROBE_DEFER from platform_get_irq_byname_optional() and handle
the deferred probe request properly.

Although the "pps" interrupt is optional, an error code of -EPROBE_DEFER
indicates that the interrupt subsystem is not yet ready. Intercept this
specific error condition, assign it to the return value, and jump to the
dis_runtime_pm label to avoid ignoring a valid probe deferral.

Fixes: eea7791e00f33 ("rtc: rzn1: implement one-second accuracy for alarms")
Cc: stable@vger.kernel.org
Signed-off-by: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
Reviewed-by: Wolfram Sang <wsa+renesas@sang-engineering.com>
Tested-by: Wolfram Sang <wsa+renesas@sang-engineering.com>
Link: https://patch.msgid.link/20260821211032.13554-3-prabhakar.mahadev-lad.rj@bp.renesas.com
Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/rtc/rtc-rzn1.c |    4 ++++
 1 file changed, 4 insertions(+)

--- a/drivers/rtc/rtc-rzn1.c
+++ b/drivers/rtc/rtc-rzn1.c
@@ -464,6 +464,10 @@ static int rzn1_rtc_probe(struct platfor
 	}
 
 	irq = platform_get_irq_byname_optional(pdev, "pps");
+	if (irq == -EPROBE_DEFER) {
+		ret = irq;
+		goto dis_runtime_pm;
+	}
 	if (irq >= 0)
 		ret = devm_request_irq(&pdev->dev, irq, rzn1_rtc_1s_irq, 0, "RZN1 RTC 1s", rtc);
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 131/556] rtc: rzn1: Fix weekday underflow when alarm crosses month boundary
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (129 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 130/556] rtc: rzn1: Handle EPROBE_DEFER for optional pps interrupt Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 132/556] rtc: rzn1: Handle unset alarm weekday in rzn1_rtc_read_alarm Greg Kroah-Hartman
                   ` (437 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Lad Prabhakar, Wolfram Sang,
	Alexandre Belloni

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>

commit 022a2839a52006531804a8db55d3228084400b48 upstream.

rzn1_rtc_set_alarm() calculates the alarm weekday from the difference
between the alarm day and the current day of the month. When the alarm
crosses a month boundary, this difference can become negative. Since
days_ahead is unsigned, it underflows and results in an incorrect
weekday being programmed into RZN1_RTC_ALW.

The RTC core already provides a fully populated struct rtc_time for
the alarm, including the correct tm_wday. Use tm->tm_wday directly
instead of recalculating the weekday from the day-of-month.

This avoids the underflow and ensures alarms scheduled across a month
boundary use the correct weekday.

Fixes: b5ad1bf00d2c4 ("rtc: rzn1: Add alarm support")
Cc: stable@vger.kernel.org
Signed-off-by: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
Suggested-by: Wolfram Sang <wsa+renesas@sang-engineering.com>
Reviewed-by: Wolfram Sang <wsa+renesas@sang-engineering.com>
Tested-by: Wolfram Sang <wsa+renesas@sang-engineering.com>
Link: https://patch.msgid.link/20260821211032.13554-4-prabhakar.mahadev-lad.rj@bp.renesas.com
Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/rtc/rtc-rzn1.c |    7 +------
 1 file changed, 1 insertion(+), 6 deletions(-)

--- a/drivers/rtc/rtc-rzn1.c
+++ b/drivers/rtc/rtc-rzn1.c
@@ -260,7 +260,6 @@ static int rzn1_rtc_set_alarm(struct dev
 	struct rzn1_rtc *rtc = dev_get_drvdata(dev);
 	struct rtc_time *tm = &alrm->time, tm_now;
 	unsigned long alarm, farest;
-	unsigned int days_ahead, wday;
 	int ret;
 
 	ret = rzn1_rtc_read_time(dev, &tm_now);
@@ -273,13 +272,9 @@ static int rzn1_rtc_set_alarm(struct dev
 	if (time_after(alarm, farest))
 		return -ERANGE;
 
-	/* Convert alarm day into week day */
-	days_ahead = tm->tm_mday - tm_now.tm_mday;
-	wday = (tm_now.tm_wday + days_ahead) % 7;
-
 	writel(bin2bcd(tm->tm_min), rtc->base + RZN1_RTC_ALM);
 	writel(bin2bcd(tm->tm_hour), rtc->base + RZN1_RTC_ALH);
-	writel(BIT(wday), rtc->base + RZN1_RTC_ALW);
+	writel(BIT(tm->tm_wday), rtc->base + RZN1_RTC_ALW);
 
 	rtc->tm_alarm = alrm->time;
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 132/556] rtc: rzn1: Handle unset alarm weekday in rzn1_rtc_read_alarm
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (130 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 131/556] rtc: rzn1: Fix weekday underflow when alarm crosses month boundary Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 133/556] rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers Greg Kroah-Hartman
                   ` (436 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Lad Prabhakar, Wolfram Sang,
	Alexandre Belloni

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>

commit 457b5dbce31209e65e1184716ed3af59cb1c0372 upstream.

RZN1_RTC_ALW is a weekday bitmask where bit N represents weekday N.
When no alarm has been configured, the register has its power-on-reset
value of zero.

rzn1_rtc_read_alarm() uses fls() to convert the weekday bitmask into a
weekday number. When RZN1_RTC_ALW is zero, fls(0) returns zero and
fls(wday) - 1 evaluates to -1. This invalid weekday is then used to
calculate the alarm date and can either leave tm_wday set to -1 or
produce a fabricated alarm date.

Treat a zero RZN1_RTC_ALW value as an unset alarm weekday and return
without calculating the alarm date. Move reading RZN1_RTC_CTL1 before
this check so that alrm->enabled is updated for both configured and
unconfigured alarms.

Fixes: b5ad1bf00d2c4 ("rtc: rzn1: Add alarm support")
Cc: stable@vger.kernel.org
Signed-off-by: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
Reviewed-by: Wolfram Sang <wsa+renesas@sang-engineering.com>
Tested-by: Wolfram Sang <wsa+renesas@sang-engineering.com>
Link: https://patch.msgid.link/20260821211032.13554-5-prabhakar.mahadev-lad.rj@bp.renesas.com
Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/rtc/rtc-rzn1.c |   16 ++++++++++++----
 1 file changed, 12 insertions(+), 4 deletions(-)

--- a/drivers/rtc/rtc-rzn1.c
+++ b/drivers/rtc/rtc-rzn1.c
@@ -234,13 +234,24 @@ static int rzn1_rtc_read_alarm(struct de
 	if (ret)
 		return ret;
 
+	ctl1 = readl(rtc->base + RZN1_RTC_CTL1);
+	alrm->enabled = !!(ctl1 & (RZN1_RTC_CTL1_ALME | RZN1_RTC_CTL1_1SE));
+
 	min = readl(rtc->base + RZN1_RTC_ALM);
 	hour = readl(rtc->base + RZN1_RTC_ALH);
-	wday = readl(rtc->base + RZN1_RTC_ALW);
 
 	tm->tm_sec = 0;
 	tm->tm_min = bcd2bin(min);
 	tm->tm_hour = bcd2bin(hour);
+
+	/*
+	 * If wday is zero, no bit is set in RZN1_RTC_ALW. This is the
+	 * register's power-on reset value.
+	 */
+	wday = readl(rtc->base + RZN1_RTC_ALW);
+	if (!wday)
+		return 0;
+
 	delta_days = ((fls(wday) - 1) - tm->tm_wday + 7) % 7;
 	tm->tm_wday = fls(wday) - 1;
 
@@ -249,9 +260,6 @@ static int rzn1_rtc_read_alarm(struct de
 		rtc_time64_to_tm(alarm, tm);
 	}
 
-	ctl1 = readl(rtc->base + RZN1_RTC_CTL1);
-	alrm->enabled = !!(ctl1 & (RZN1_RTC_CTL1_ALME | RZN1_RTC_CTL1_1SE));
-
 	return 0;
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 133/556] rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (131 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 132/556] rtc: rzn1: Handle unset alarm weekday in rzn1_rtc_read_alarm Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 134/556] perf/x86/intel: Fix kernel address leakages in LBR stack Greg Kroah-Hartman
                   ` (435 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Lad Prabhakar, Wolfram Sang,
	Alexandre Belloni

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>

commit 51458d5b0a1cfb1b6013400abc95aadf16ed2a57 upstream.

rzn1_rtc_set_alarm() updates RZN1_RTC_ALM, RZN1_RTC_ALH and
RZN1_RTC_ALW using separate MMIO writes without first disabling the
alarm interrupt. If a previous alarm is still enabled, the interrupt
can fire while the alarm registers contain a mixture of old and newly
written values.

Fix this by disabling the alarm interrupt before reprogramming ALM, ALH
and ALW with a call to rzn1_rtc_alarm_irq_enable().

Fixes: b5ad1bf00d2c4 ("rtc: rzn1: Add alarm support")
Cc: stable@vger.kernel.org
Signed-off-by: Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
Reviewed-by: Wolfram Sang <wsa+renesas@sang-engineering.com>
Tested-by: Wolfram Sang <wsa+renesas@sang-engineering.com>
Link: https://patch.msgid.link/20260821211032.13554-7-prabhakar.mahadev-lad.rj@bp.renesas.com
Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/rtc/rtc-rzn1.c |    5 +++++
 1 file changed, 5 insertions(+)

--- a/drivers/rtc/rtc-rzn1.c
+++ b/drivers/rtc/rtc-rzn1.c
@@ -280,6 +280,11 @@ static int rzn1_rtc_set_alarm(struct dev
 	if (time_after(alarm, farest))
 		return -ERANGE;
 
+	/* Disable alarm interrupts before reprogramming the alarm. */
+	ret = rzn1_rtc_alarm_irq_enable(dev, 0);
+	if (ret)
+		return ret;
+
 	writel(bin2bcd(tm->tm_min), rtc->base + RZN1_RTC_ALM);
 	writel(bin2bcd(tm->tm_hour), rtc->base + RZN1_RTC_ALH);
 	writel(BIT(tm->tm_wday), rtc->base + RZN1_RTC_ALW);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 134/556] perf/x86/intel: Fix kernel address leakages in LBR stack
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (132 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 133/556] rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 135/556] perf/x86/intel: Remove anythread_deprecated bit from perf_capabilities Greg Kroah-Hartman
                   ` (434 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ian Rogers, Dapeng Mi,
	Peter Zijlstra (Intel)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dapeng Mi <dapeng1.mi@linux.intel.com>

commit e2b0575900ff72aa82748af96e7bd564ade5157a upstream.

Before Arch LBR gained CPL filtering support, a user-only branch stack
could still contain kernel addresses. As a result, kernel branch records
may be exposed to user space even when PERF_SAMPLE_BRANCH_USER is
requested.

For example, on Intel Tiger Lake, the following command can still report
SYSRET/ERET entries with kernel-space from addresses:

$ ./perf record -e cycles:p -o - --branch-filter any,save_type,u -- \
 	./perf bench syscall basic --loop 1000 | \
	./perf script -i - --fields brstack|tr ' ' '\n'| \
	grep -E '0x[89a-f][0-9a-f]{15}'

    Total time: 0.000 [sec]

      0.219000 usecs/op
     4,566,210 ops/sec
[ perf record: Woken up 1 times to write data ]
[ perf record: Captured and wrote 0.551 MB - ]
0xffffffff93c001c8/0x7f12a2b1d647/P/-/-/16959/SYSRET/-
0xffffffff93c001c8/0x7f12a2b1d5c2/P/-/-/17535/SYSRET/-
0xffffffff93c01928/0x7f12a2861000/P/-/-/6719/ERET/-
0xffffffff93c01928/0x7f12a297a000/P/-/-/8575/ERET/-

The problem is that intel_pmu_lbr_filter() does not fully validate the
privilege level of sampled entries. It filters some mismatches based on
the branch type and the to address, but it does not reject entries whose
from address violates the requested branch privilege filter.

Fix this by extending software filtering to validate both from and to
addresses against br_sel. Any LBR entry contains kernel address does not
match the requested user filter is dropped. This prevents kernel
addresses from appearing in user-only branch stacks.

Fixes: 47125db27e47 ("perf/x86/intel/lbr: Support Architectural LBR")
Reported-by: Ian Rogers <irogers@google.com>
Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260616044654.3468742-5-dapeng1.mi@linux.intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/x86/events/intel/lbr.c |   12 +++++++++---
 1 file changed, 9 insertions(+), 3 deletions(-)

--- a/arch/x86/events/intel/lbr.c
+++ b/arch/x86/events/intel/lbr.c
@@ -1213,7 +1213,7 @@ intel_pmu_lbr_filter(struct cpu_hw_event
 {
 	u64 from, to;
 	int br_sel = cpuc->br_sel;
-	int i, j, type, to_plm;
+	int i, j, type, from_plm, to_plm;
 	bool compress = false;
 
 	/* if sampling all branches, then nothing to filter */
@@ -1245,8 +1245,14 @@ intel_pmu_lbr_filter(struct cpu_hw_event
 				type |= X86_BR_NO_TX;
 		}
 
-		/* if type does not correspond, then discard */
-		if (type == X86_BR_NONE || (br_sel & type) != type) {
+		from_plm = kernel_ip(from) ? X86_BR_KERNEL : X86_BR_USER;
+		/*
+		 * If type does not correspond, then discard.
+		 * Specifically reject entries whose from address is in
+		 * kernel space when only X86_BR_USER is requested.
+		 */
+		if (type == X86_BR_NONE || (br_sel & type) != type ||
+		    (!(br_sel & X86_BR_KERNEL) && (from_plm & X86_BR_KERNEL))) {
 			cpuc->lbr_entries[i].from = 0;
 			compress = true;
 		}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 135/556] perf/x86/intel: Remove anythread_deprecated bit from perf_capabilities
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (133 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 134/556] perf/x86/intel: Fix kernel address leakages in LBR stack Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 136/556] perf trace: Factor out BPF loop body Greg Kroah-Hartman
                   ` (433 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Namhyung Kim, Dapeng Mi,
	Peter Zijlstra (Intel), Zide Chen, Thomas Falcon

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dapeng Mi <dapeng1.mi@linux.intel.com>

commit 8767b4d73018bd3143f4c55b672064fad292f11b upstream.

AnyThread mode deprecation is enumerated by CPUID.0AH:EDX[15] instead of
PERF_CAPABILITIES MSR. It's not a good practice to define a bit to
represent "anythread deprecation" in perf_capabilities. It leads to the
anythread_deprecated bit could be overwritten by the real value of
PERF_CAPABILITIES MSR, just like the below code in update_pmu_cap() does.

if (!intel_pmu_broken_perf_cap()) {
	/* Perf Metric (Bit 15) and PEBS via PT (Bit 16) are hybrid enumeration */
	rdmsrq(MSR_IA32_PERF_CAPABILITIES, hybrid(pmu, intel_cap).capabilities);
}

It leads to the anythread_deprecated bit is cleared to 0 and the "any"
attribute is incorrectly shown in the /sys/devices/cpu/format/ folder on
these support Perfmon v6 platforms, like Clearwater Forest.

$ grep . /sys/devices/cpu/format/*
/sys/devices/cpu/format/acr_mask:config2:0-63
/sys/devices/cpu/format/any:config:21
/sys/devices/cpu/format/cmask:config:24-31

So remove the anythread_deprecated bit from perf_capabilities structure
and directly depends on CPUID.0AH:EDX[15] to judge if anythread is
deprecated.

Fixes: cadbaa039b99 ("perf/x86/intel: Make anythread filter support conditional")
Reported-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Reviewed-by: Zide Chen <zide.chen@intel.com>
Reviewed-by: Thomas Falcon <thomas.falcon@intel.com>
Acked-by: Namhyung Kim <namhyung@kernel.org>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260616044654.3468742-2-dapeng1.mi@linux.intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/x86/events/intel/core.c |   10 +++-------
 arch/x86/events/perf_event.h |    2 +-
 2 files changed, 4 insertions(+), 8 deletions(-)

--- a/arch/x86/events/intel/core.c
+++ b/arch/x86/events/intel/core.c
@@ -7947,12 +7947,6 @@ __init int intel_pmu_init(void)
 
 	x86_add_quirk(intel_arch_events_quirk); /* Install first, so it runs last */
 
-	if (version >= 5) {
-		x86_pmu.intel_cap.anythread_deprecated = edx.split.anythread_deprecated;
-		if (x86_pmu.intel_cap.anythread_deprecated)
-			pr_cont(" AnyThread deprecated, ");
-	}
-
 	/* The perf side of core PMU is ready to support the mediated vPMU. */
 	x86_get_pmu(smp_processor_id())->capabilities |= PERF_PMU_CAP_MEDIATED_VPMU;
 
@@ -8829,8 +8823,10 @@ __init int intel_pmu_init(void)
 				      &x86_pmu.intel_ctrl);
 
 	/* AnyThread may be deprecated on arch perfmon v5 or later */
-	if (x86_pmu.intel_cap.anythread_deprecated)
+	if (version >= 5 && edx.split.anythread_deprecated) {
 		x86_pmu.format_attrs = intel_arch_formats_attr;
+		pr_cont("AnyThread deprecated, ");
+	}
 
 	intel_pmu_check_event_constraints_all(NULL);
 
--- a/arch/x86/events/perf_event.h
+++ b/arch/x86/events/perf_event.h
@@ -668,7 +668,7 @@ union perf_capabilities {
 		u64	perf_metrics:1;
 		u64	pebs_output_pt_available:1;
 		u64	pebs_timing_info:1;
-		u64	anythread_deprecated:1;
+		u64	__reserved:1;
 		u64	rdpmc_metrics_clear:1;
 	};
 	u64	capabilities;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 136/556] perf trace: Factor out BPF loop body
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (134 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 135/556] perf/x86/intel: Remove anythread_deprecated bit from perf_capabilities Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 137/556] perf trace: Refactor augmented_raw_syscalls using bpf_for Greg Kroah-Hartman
                   ` (432 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Viktor Malik, Namhyung Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Viktor Malik <vmalik@redhat.com>

commit acff3e1a9cc29a6a039b76b81a438c56016bc0e3 upstream.

The BPF program in augmented_raw_syscalls uses a for loop to iterate all
syscall arguments. The loop body is quite complex and often poses
problems for the BPF verifier. As a preparation step for addressing this
issue, factor out the loop body into a separate function.

Signed-off-by: Viktor Malik <vmalik@redhat.com>
Cc: stable@vger.kernel.org
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 tools/perf/util/bpf_skel/augmented_raw_syscalls.bpf.c |  128 ++++++++++--------
 1 file changed, 73 insertions(+), 55 deletions(-)

--- a/tools/perf/util/bpf_skel/augmented_raw_syscalls.bpf.c
+++ b/tools/perf/util/bpf_skel/augmented_raw_syscalls.bpf.c
@@ -429,15 +429,80 @@ static bool pid_filter__has(struct pids_
 	return bpf_map_lookup_elem(pids, &pid) != NULL;
 }
 
+/*
+ * Determine what type of argument and how many bytes to read from user space, using the
+ * value in the beauty_map. This is the relation of parameter type and its corresponding
+ * value in the beauty map, and how many bytes we read eventually:
+ *
+ * string: 1			      -> size of string
+ * struct: size of struct	      -> size of struct
+ * buffer: -1 * (index of paired len) -> value of paired len (maximum: TRACE_AUG_MAX_BUF)
+ */
+static inline int augment_arg(struct syscall_enter_args *args, int i,
+			      unsigned int *beauty_map,
+			      struct augmented_arg *payload_offset)
+{
+	int index, value_size = sizeof(struct augmented_arg) - offsetof(struct augmented_arg, value);
+	s64 aug_size, size;
+	bool augmented;
+	void *arg;
+
+	arg = (void *)args->args[i];
+	augmented = false;
+	size = beauty_map[i];
+	aug_size = size; /* size of the augmented data read from user space */
+
+	if (size == 0 || arg == NULL)
+		return 0;
+
+	if (size == 1) { /* string */
+		aug_size = bpf_probe_read_user_str(payload_offset->value, value_size, arg);
+		/* minimum of 0 to pass the verifier */
+		if (aug_size < 0)
+			aug_size = 0;
+
+		augmented = true;
+	} else if (size > 0 && size <= value_size) { /* struct */
+		if (!bpf_probe_read_user(payload_offset->value, size, arg))
+			augmented = true;
+	} else if ((int)size < 0 && size >= -6) { /* buffer */
+		index = -(size + 1);
+		barrier_var(index); // Prevent clang (noticed with v18) from removing the &= 7 trick.
+		index &= 7;	    // Satisfy the bounds checking with the verifier in some kernels.
+		aug_size = args->args[index] > TRACE_AUG_MAX_BUF ? TRACE_AUG_MAX_BUF : args->args[index];
+
+		if (aug_size > 0) {
+			if (!bpf_probe_read_user(payload_offset->value, aug_size, arg))
+				augmented = true;
+		}
+	}
+
+	/* Augmented data size is limited to sizeof(augmented_arg->unnamed union with value field) */
+	if (aug_size > value_size)
+		aug_size = value_size;
+
+	/* write data to payload */
+	if (augmented) {
+		int written = offsetof(struct augmented_arg, value) + aug_size;
+
+		if (written < 0 || written > sizeof(struct augmented_arg))
+			return -1;
+
+		payload_offset->size = aug_size;
+		return written;
+	}
+
+	return 0;
+}
+
 static int augment_sys_enter(void *ctx, struct syscall_enter_args *args)
 {
-	bool augmented, do_output = false;
-	int zero = 0, index, value_size = sizeof(struct augmented_arg) - offsetof(struct augmented_arg, value);
+	bool do_output = false;
+	int zero = 0, written;
 	u64 output = 0; /* has to be u64, otherwise it won't pass the verifier */
-	s64 aug_size, size;
 	unsigned int nr, *beauty_map;
 	struct beauty_payload_enter *payload;
-	void *arg, *payload_offset;
+	void *payload_offset;
 
 	/* fall back to do predefined tail call */
 	if (args == NULL)
@@ -457,58 +522,11 @@ static int augment_sys_enter(void *ctx,
 	/* copy the sys_enter header, which has the syscall_nr */
 	__builtin_memcpy(&payload->args, args, sizeof(struct syscall_enter_args));
 
-	/*
-	 * Determine what type of argument and how many bytes to read from user space, using the
-	 * value in the beauty_map. This is the relation of parameter type and its corresponding
-	 * value in the beauty map, and how many bytes we read eventually:
-	 *
-	 * string: 1			      -> size of string
-	 * struct: size of struct	      -> size of struct
-	 * buffer: -1 * (index of paired len) -> value of paired len (maximum: TRACE_AUG_MAX_BUF)
-	 */
 	for (int i = 0; i < 6; i++) {
-		arg = (void *)args->args[i];
-		augmented = false;
-		size = beauty_map[i];
-		aug_size = size; /* size of the augmented data read from user space */
-
-		if (size == 0 || arg == NULL)
-			continue;
-
-		if (size == 1) { /* string */
-			aug_size = bpf_probe_read_user_str(((struct augmented_arg *)payload_offset)->value, value_size, arg);
-			/* minimum of 0 to pass the verifier */
-			if (aug_size < 0)
-				aug_size = 0;
-
-			augmented = true;
-		} else if (size > 0 && size <= value_size) { /* struct */
-			if (!bpf_probe_read_user(((struct augmented_arg *)payload_offset)->value, size, arg))
-				augmented = true;
-		} else if ((int)size < 0 && size >= -6) { /* buffer */
-			index = -(size + 1);
-			barrier_var(index); // Prevent clang (noticed with v18) from removing the &= 7 trick.
-			index &= 7;	    // Satisfy the bounds checking with the verifier in some kernels.
-			aug_size = args->args[index] > TRACE_AUG_MAX_BUF ? TRACE_AUG_MAX_BUF : args->args[index];
-
-			if (aug_size > 0) {
-				if (!bpf_probe_read_user(((struct augmented_arg *)payload_offset)->value, aug_size, arg))
-					augmented = true;
-			}
-		}
-
-		/* Augmented data size is limited to sizeof(augmented_arg->unnamed union with value field) */
-		if (aug_size > value_size)
-			aug_size = value_size;
-
-		/* write data to payload */
-		if (augmented) {
-			int written = offsetof(struct augmented_arg, value) + aug_size;
-
-			if (written < 0 || written > sizeof(struct augmented_arg))
-				return 1;
-
-			((struct augmented_arg *)payload_offset)->size = aug_size;
+		written = augment_arg(args, i, beauty_map, (struct augmented_arg *)payload_offset);
+		if (written < 0)
+			return 1;
+		if (written > 0) {
 			output += written;
 			payload_offset += written;
 			do_output = true;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 137/556] perf trace: Refactor augmented_raw_syscalls using bpf_for
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (135 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 136/556] perf trace: Factor out BPF loop body Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 138/556] perf hisi-ptt: Fix PTT trace TLP header parsing Greg Kroah-Hartman
                   ` (431 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Viktor Malik, Andrii Nakryiko,
	Namhyung Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Viktor Malik <vmalik@redhat.com>

commit ea6992784d65ef2c01f3525217dbf3a44afa9917 upstream.

The loop for processing syscall args in augment_raw_syscalls has a
history of breaking with Clang updates, see e.g. commit 013eb043f37b
("perf trace: Fix BPF loading failure (-E2BIG)") from Clang 15 to 16.

Now, a similar thing happened between Clang 21 and 22. While the issue
is mitigated on the main line by a recent verifier update, it remains
broken on the 6.12 and 6.18 stable branches:

    [linux-6.18.y]# sudo perf trace true
    libbpf: prog 'sys_enter': BPF program load failed: -E2BIG
    libbpf: prog 'sys_enter': -- BEGIN PROG LOAD LOG --
    [...]
    BPF program is too large. Processed 1000001 insn
    processed 1000001 insns (limit 1000000) max_states_per_insn 40 total_states 37941 peak_states 232 mark_read 0
    -- END PROG LOAD LOG --
    libbpf: prog 'sys_enter': failed to load: -E2BIG
    libbpf: failed to load object 'augmented_raw_syscalls_bpf'
    libbpf: failed to load BPF skeleton 'augmented_raw_syscalls_bpf': -E2BIG
    Error: failed to get syscall or beauty map fd
    [...]

The reason is that the loop is quite complex and the BPF verifier often
struggles to prove that it terminates.

Fix the issue by replacing the standard for loop with the bpf_for macro,
which uses a numeric BPF iterator. This should prevent future breakages
of this kind since the verifier has a much easier job proving that the
loop terminates.

Small adjustments were necessary for the loop to make it work.  The main
problem is that the verifier sometimes has problems with bpf_for loops
that use a carry-over state, such as the `payload_offset` and `output`
vars here, since the verifier tries to track their values too precisely
and cannot prove loop convergence. To resolve the issue, we (1)
explicitly recompute `payload_offset` in every iteration and (2) use a
trick with adding a global zero to `output` to help the verifier forget
its precise state and use a range instead.

Finally, to keep backwards compatibility with older kernel versions that
don't have bpf_for (i.e. numeric iterators), fall back to standard loop.

Signed-off-by: Viktor Malik <vmalik@redhat.com>
Cc: stable@vger.kernel.org
Suggested-by: Andrii Nakryiko <andrii@kernel.org>
Fixes: a68fd6a6cdd3 ("perf trace: Collect augmented data using BPF")
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 tools/perf/util/bpf_skel/augmented_raw_syscalls.bpf.c |   47 +++++++++++++-----
 1 file changed, 35 insertions(+), 12 deletions(-)

--- a/tools/perf/util/bpf_skel/augmented_raw_syscalls.bpf.c
+++ b/tools/perf/util/bpf_skel/augmented_raw_syscalls.bpf.c
@@ -429,6 +429,8 @@ static bool pid_filter__has(struct pids_
 	return bpf_map_lookup_elem(pids, &pid) != NULL;
 }
 
+u64 ZERO = 0;
+
 /*
  * Determine what type of argument and how many bytes to read from user space, using the
  * value in the beauty_map. This is the relation of parameter type and its corresponding
@@ -440,9 +442,10 @@ static bool pid_filter__has(struct pids_
  */
 static inline int augment_arg(struct syscall_enter_args *args, int i,
 			      unsigned int *beauty_map,
-			      struct augmented_arg *payload_offset)
+			      struct beauty_payload_enter *payload, u64 offset)
 {
 	int index, value_size = sizeof(struct augmented_arg) - offsetof(struct augmented_arg, value);
+	struct augmented_arg *payload_offset;
 	s64 aug_size, size;
 	bool augmented;
 	void *arg;
@@ -455,6 +458,12 @@ static inline int augment_arg(struct sys
 	if (size == 0 || arg == NULL)
 		return 0;
 
+	/* bounds check for the verifier */
+	if (offset > sizeof(payload->aug_args) - sizeof(payload->aug_args[0]))
+		return -1;
+	barrier_var(offset);
+	payload_offset = (struct augmented_arg *)((void *)&payload->aug_args + offset);
+
 	if (size == 1) { /* string */
 		aug_size = bpf_probe_read_user_str(payload_offset->value, value_size, arg);
 		/* minimum of 0 to pass the verifier */
@@ -498,11 +507,10 @@ static inline int augment_arg(struct sys
 static int augment_sys_enter(void *ctx, struct syscall_enter_args *args)
 {
 	bool do_output = false;
-	int zero = 0, written;
+	int i, zero = 0, written;
 	u64 output = 0; /* has to be u64, otherwise it won't pass the verifier */
 	unsigned int nr, *beauty_map;
 	struct beauty_payload_enter *payload;
-	void *payload_offset;
 
 	/* fall back to do predefined tail call */
 	if (args == NULL)
@@ -514,7 +522,6 @@ static int augment_sys_enter(void *ctx,
 
 	/* set up payload for output */
 	payload        = bpf_map_lookup_elem(&beauty_payload_enter_map, &zero);
-	payload_offset = (void *)&payload->aug_args;
 
 	if (beauty_map == NULL || payload == NULL)
 		return 1;
@@ -522,14 +529,30 @@ static int augment_sys_enter(void *ctx,
 	/* copy the sys_enter header, which has the syscall_nr */
 	__builtin_memcpy(&payload->args, args, sizeof(struct syscall_enter_args));
 
-	for (int i = 0; i < 6; i++) {
-		written = augment_arg(args, i, beauty_map, (struct augmented_arg *)payload_offset);
-		if (written < 0)
-			return 1;
-		if (written > 0) {
-			output += written;
-			payload_offset += written;
-			do_output = true;
+	if (bpf_ksym_exists(bpf_iter_num_new)) {
+		bpf_for(i, 0, 6) {
+			written = augment_arg(args, i, beauty_map, payload, output);
+			if (written < 0)
+				return 1;
+			if (written > 0) {
+				output += written;
+				/*
+				 * guide the verifier to forget range of `output`, which
+				 * helps to prove convergence of the loop
+				 */
+				output += ZERO;
+				do_output = true;
+			}
+		}
+	} else {
+		for (i = 0; i < 6; i++) {
+			written = augment_arg(args, i, beauty_map, payload, output);
+			if (written < 0)
+				return 1;
+			if (written > 0) {
+				output += written;
+				do_output = true;
+			}
 		}
 	}
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 138/556] perf hisi-ptt: Fix PTT trace TLP header parsing
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (136 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 137/556] perf trace: Refactor augmented_raw_syscalls using bpf_for Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:36 ` [PATCH 7.2 139/556] perf build: Add clang and rust target flags for LoongArch Greg Kroah-Hartman
                   ` (430 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, James Clark, Sizhe Liu, Namhyung Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sizhe Liu <liusizhe5@huawei.com>

commit 2b8a2e5d424f0b3369054305d0bf6a5b9faee6c1 upstream.

TLP Headers traced by HiSilicon PCIe tune and trace device (PTT) in
4DW format are shown in the document as below:
bits [31:30] [ 29:25 ][24][23][22][21][    20:11   ][    10:0    ]
     |-----|---------|---|---|---|---|-------------|-------------|
DW0  [ Fmt ][  Type  ][T9][T8][TH][SO][   Length   ][    Time    ]
DW1  [                     Header DW1                            ]
DW2  [                     Header DW2                            ]
DW3  [                     Header DW3                            ]

Problem:
The DW0 bit field layout of the hisi_ptt_4dw union does not match the
actual bit ordering in little-endian memory, causing incorrect field
decoding.

Test on Kunpeng 930 SOC, generating data flow with `iperf` commands:
- server side:
    iperf -s
- client side:
    iperf -c $ip_addr -t 30

Trace the TLP headers with hisi_ptt on server side at the same time:
  perf record -e hisi_ptt12_0/type=4,filter=0x05101,direction=2,format=0/ \
  --max-size 50M -o perf.data &
The trace aims to capture completion TLPs, learn more in the document:
  https://docs.kernel.org/trace/hisi-ptt.html

Decode perf.data with hisi_ptt decoder:
  perf report -D

The hisi_ptt decoder produces the following result:
[...perf headers and other information]
. ... HISI PTT data: size 8388608 bytes
.  00000000: 68 87 20 94                                 Format 3 Type 1a T9 0 T8 1 TH 1 SO 1 Length 10 Time 4a1
.  00000004: 40 00 00 00                                 Header DW1
.  00000008: 40 00 01 51                                 Header DW2
.  0000000c: 00 00 00 00                                 Header DW3
[...other hisi_ptt TLP headers]

According to PCIe r5.0 sec 2.2.1, the Fmt & Type of Cpl/CplD is supposed
to be 8b'00001010' / 8b'01001010'
However, the Format & Type decoder analyzing result is 8b'01111010'.
It does not match field encodings of any TLP.

Correct decoder result should be:
[...perf headers and other information]
. ... HISI PTT data: size 8388608 bytes
.  00000000: 94 20 87 68                                 Format 2 Type a T9 0 T8 0 TH 0 SO 1 Length 10 Time 768
.  00000004: 00 00 00 40                                 Header DW1
.  00000008: 51 01 00 40                                 Header DW2
.  0000000c: 00 00 00 00                                 Header DW3
[...other hisi_ptt TLP headers]

To solve the problem:
1. Drop the union and C bitfield struct, store the raw DW value in
a plain uint32_t, and extract the fields with FIELD_GET() against
GENMASK/BIT masks declared in the header so they can be reused by
other translation units. The masks are portable across endianness and
compilers.

2. Print all DW hex values in big-endian byte order for readability,
matching the bit field layout shown in the 4DW format diagram.

3. Read the DW value with get_unaligned_le32() instead of an unaligned
pointer cast, avoiding both strict-aliasing violations and
alignment hazards on hosts that do not support unaligned access.

Cc: stable@vger.kernel.org
Fixes: 5e91e57e6809 ("perf auxtrace arm64: Add support for parsing HiSilicon PCIe Trace packet")
Reviewed-by: James Clark <james.clark@linaro.org>
Signed-off-by: Sizhe Liu <liusizhe5@huawei.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 Documentation/trace/hisi-ptt.rst                        |   28 ++++-----
 tools/perf/util/hisi-ptt-decoder/hisi-ptt-pkt-decoder.c |   47 ++++++++--------
 tools/perf/util/hisi-ptt-decoder/hisi-ptt-pkt-decoder.h |   12 ++++
 3 files changed, 50 insertions(+), 37 deletions(-)

--- a/Documentation/trace/hisi-ptt.rst
+++ b/Documentation/trace/hisi-ptt.rst
@@ -285,20 +285,20 @@ according to the format described previo
     [...perf headers and other information]
     . ... HISI PTT data: size 4194304 bytes
     .  00000000: 00 00 00 00                                 Prefix
-    .  00000004: 01 00 00 60                                 Header DW0
-    .  00000008: 0f 1e 00 01                                 Header DW1
-    .  0000000c: 04 00 00 00                                 Header DW2
-    .  00000010: 40 00 81 02                                 Header DW3
-    .  00000014: 33 c0 04 00                                 Time
+    .  00000004: 60 00 00 01                                 Header DW0
+    .  00000008: 01 00 1e 0f                                 Header DW1
+    .  0000000c: 00 00 00 04                                 Header DW2
+    .  00000010: 02 81 00 40                                 Header DW3
+    .  00000014: 00 04 c0 33                                 Time
     .  00000020: 00 00 00 00                                 Prefix
-    .  00000024: 01 00 00 60                                 Header DW0
-    .  00000028: 0f 1e 00 01                                 Header DW1
-    .  0000002c: 04 00 00 00                                 Header DW2
-    .  00000030: 40 00 81 02                                 Header DW3
-    .  00000034: 02 00 00 00                                 Time
+    .  00000024: 60 00 00 01                                 Header DW0
+    .  00000028: 01 00 1e 0f                                 Header DW1
+    .  0000002c: 00 00 00 04                                 Header DW2
+    .  00000030: 02 81 00 40                                 Header DW3
+    .  00000034: 00 00 00 02                                 Time
     .  00000040: 00 00 00 00                                 Prefix
-    .  00000044: 01 00 00 60                                 Header DW0
-    .  00000048: 0f 1e 00 01                                 Header DW1
-    .  0000004c: 04 00 00 00                                 Header DW2
-    .  00000050: 40 00 81 02                                 Header DW3
+    .  00000044: 60 00 00 01                                 Header DW0
+    .  00000048: 01 00 1e 0f                                 Header DW1
+    .  0000004c: 00 00 00 04                                 Header DW2
+    .  00000050: 02 81 00 40                                 Header DW3
     [...]
--- a/tools/perf/util/hisi-ptt-decoder/hisi-ptt-pkt-decoder.c
+++ b/tools/perf/util/hisi-ptt-decoder/hisi-ptt-pkt-decoder.c
@@ -10,6 +10,8 @@
 #include <endian.h>
 #include <byteswap.h>
 #include <linux/bitops.h>
+#include <linux/kernel.h>
+#include <linux/unaligned.h>
 #include <stdarg.h>
 
 #include "../color.h"
@@ -73,29 +75,20 @@ static const char * const hisi_ptt_4dw_p
 	[HISI_PTT_4DW_HEAD3]	= "Header DW3",
 };
 
-union hisi_ptt_4dw {
-	struct {
-		uint32_t format : 2;
-		uint32_t type : 5;
-		uint32_t t9 : 1;
-		uint32_t t8 : 1;
-		uint32_t th : 1;
-		uint32_t so : 1;
-		uint32_t len : 10;
-		uint32_t time : 11;
-	};
-	uint32_t value;
-};
-
 static void hisi_ptt_print_pkt(const unsigned char *buf, int pos, const char *desc)
 {
 	const char *color = PERF_COLOR_BLUE;
+	uint8_t byte;
+	uint32_t dw;
 	int i;
 
+	dw = get_unaligned_le32(buf + pos);
 	printf(".");
 	color_fprintf(stdout, color, "  %08x: ", pos);
-	for (i = 0; i < HISI_PTT_FIELD_LENTH; i++)
-		color_fprintf(stdout, color, "%02x ", buf[pos + i]);
+	for (i = 0; i < HISI_PTT_FIELD_LENTH; i++) {
+		byte = (dw >> (24 - i * 8)) & 0xFF;
+		color_fprintf(stdout, color, "%02x ", byte);
+	}
 	for (i = 0; i < HISI_PTT_MAX_SPACE_LEN; i++)
 		color_fprintf(stdout, color, "   ");
 	color_fprintf(stdout, color, "  %s\n", desc);
@@ -122,22 +115,30 @@ static int hisi_ptt_8dw_kpt_desc(const u
 static void hisi_ptt_4dw_print_dw0(const unsigned char *buf, int pos)
 {
 	const char *color = PERF_COLOR_BLUE;
-	union hisi_ptt_4dw dw0;
+	uint8_t byte;
+	uint32_t dw;
 	int i;
 
-	dw0.value = *(uint32_t *)(buf + pos);
+	dw = get_unaligned_le32(buf + pos);
 	printf(".");
 	color_fprintf(stdout, color, "  %08x: ", pos);
-	for (i = 0; i < HISI_PTT_FIELD_LENTH; i++)
-		color_fprintf(stdout, color, "%02x ", buf[pos + i]);
+	for (i = 0; i < HISI_PTT_FIELD_LENTH; i++) {
+		byte = (dw >> (24 - i * 8)) & 0xFF;
+		color_fprintf(stdout, color, "%02x ", byte);
+	}
 	for (i = 0; i < HISI_PTT_MAX_SPACE_LEN; i++)
 		color_fprintf(stdout, color, "   ");
 
 	color_fprintf(stdout, color,
 		      "  %s %x %s %x %s %x %s %x %s %x %s %x %s %x %s %x\n",
-		      "Format", dw0.format, "Type", dw0.type, "T9", dw0.t9,
-		      "T8", dw0.t8, "TH", dw0.th, "SO", dw0.so, "Length",
-		      dw0.len, "Time", dw0.time);
+		      "Format", FIELD_GET(HISI_PTT_HEAD0_4DW_FORMAT, dw),
+		      "Type", FIELD_GET(HISI_PTT_HEAD0_4DW_TYPE, dw),
+		      "T9", FIELD_GET(HISI_PTT_HEAD0_4DW_T9, dw),
+		      "T8", FIELD_GET(HISI_PTT_HEAD0_4DW_T8, dw),
+		      "TH", FIELD_GET(HISI_PTT_HEAD0_4DW_TH, dw),
+		      "SO", FIELD_GET(HISI_PTT_HEAD0_4DW_SO, dw),
+		      "Length", FIELD_GET(HISI_PTT_HEAD0_4DW_LEN, dw),
+		      "Time", FIELD_GET(HISI_PTT_HEAD0_4DW_TIME, dw));
 }
 
 static int hisi_ptt_4dw_kpt_desc(const unsigned char *buf, int pos)
--- a/tools/perf/util/hisi-ptt-decoder/hisi-ptt-pkt-decoder.h
+++ b/tools/perf/util/hisi-ptt-decoder/hisi-ptt-pkt-decoder.h
@@ -9,12 +9,24 @@
 
 #include <stddef.h>
 #include <stdint.h>
+#include <linux/bits.h>
+#include <linux/bitfield.h>
 
 #define HISI_PTT_8DW_CHECK_MASK		GENMASK(31, 11)
 #define HISI_PTT_IS_8DW_PKT		GENMASK(31, 11)
 #define HISI_PTT_MAX_SPACE_LEN		10
 #define HISI_PTT_FIELD_LENTH		4
 
+/* Header DW0 fields for 4DW format */
+#define HISI_PTT_HEAD0_4DW_TIME		GENMASK_U32(10, 0)
+#define HISI_PTT_HEAD0_4DW_LEN		GENMASK_U32(20, 11)
+#define HISI_PTT_HEAD0_4DW_SO		BIT_U32(21)
+#define HISI_PTT_HEAD0_4DW_TH		BIT_U32(22)
+#define HISI_PTT_HEAD0_4DW_T8		BIT_U32(23)
+#define HISI_PTT_HEAD0_4DW_T9		BIT_U32(24)
+#define HISI_PTT_HEAD0_4DW_TYPE		GENMASK_U32(29, 25)
+#define HISI_PTT_HEAD0_4DW_FORMAT	GENMASK_U32(31, 30)
+
 enum hisi_ptt_pkt_type {
 	HISI_PTT_4DW_PKT,
 	HISI_PTT_8DW_PKT,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 139/556] perf build: Add clang and rust target flags for LoongArch
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (137 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 138/556] perf hisi-ptt: Fix PTT trace TLP header parsing Greg Kroah-Hartman
@ 2026-09-09 13:36 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 140/556] perf: Fix use-after-free when perf mmap() revival races with the last munmap() Greg Kroah-Hartman
                   ` (429 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:36 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Miguel Ojeda, Dmitrii Dolgov,
	Haiyong Sun, WANG Rui, Huacai Chen

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Haiyong Sun <sunhaiyong@loongson.cn>

commit a2628ce4ddb6873e35380a42396d17a66e704a1a upstream.

Add missing CLANG_TARGET_FLAGS_loongarch and RUST_TARGET_FLAGS_loongarch
so that perf can be built with clang and enable rust cross compilation.

Cc: stable@vger.kernel.org
Acked-by: Miguel Ojeda <ojeda@kernel.org>
Acked-by: Dmitrii Dolgov <9erthalion6@gmail.com>
Signed-off-by: Haiyong Sun <sunhaiyong@loongson.cn>
Signed-off-by: WANG Rui <wangrui@loongson.cn>
Signed-off-by: Huacai Chen <chenhuacai@loongson.cn>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 tools/perf/Makefile.config |    2 ++
 1 file changed, 2 insertions(+)

--- a/tools/perf/Makefile.config
+++ b/tools/perf/Makefile.config
@@ -27,6 +27,7 @@ CFLAGS += -fno-strict-aliasing
 ifeq ($(CC_NO_CLANG), 0)
   CLANG_TARGET_FLAGS_arm	:= arm-linux-gnueabi
   CLANG_TARGET_FLAGS_arm64	:= aarch64-linux-gnu
+  CLANG_TARGET_FLAGS_loongarch	:= loongarch64-linux-gnu
   CLANG_TARGET_FLAGS_m68k	:= m68k-linux-gnu
   CLANG_TARGET_FLAGS_mips	:= mipsel-linux-gnu
   CLANG_TARGET_FLAGS_powerpc	:= powerpc64le-linux-gnu
@@ -1142,6 +1143,7 @@ ifndef NO_RUST
   ifneq ($(CROSS_COMPILE),)
     RUST_TARGET_FLAGS_arm	:= arm-unknown-linux-gnueabi
     RUST_TARGET_FLAGS_arm64	:= aarch64-unknown-linux-gnu
+    RUST_TARGET_FLAGS_loongarch	:= loongarch64-unknown-linux-gnu
     RUST_TARGET_FLAGS_m68k	:= m68k-unknown-linux-gnu
     RUST_TARGET_FLAGS_mips	:= mipsel-unknown-linux-gnu
     RUST_TARGET_FLAGS_powerpc	:= powerpc64le-unknown-linux-gnu



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 140/556] perf: Fix use-after-free when perf mmap() revival races with the last munmap()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (138 preceding siblings ...)
  2026-09-09 13:36 ` [PATCH 7.2 139/556] perf build: Add clang and rust target flags for LoongArch Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 141/556] i2c: designware: Enable interrupt mask workaround for HJMC3001 Greg Kroah-Hartman
                   ` (428 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Kimi Security Team, Peter Zijlstra,
	Weiming Shi, Yilin Zhang

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yilin Zhang <yilinzhang@moonshot.ai>

commit 58a8108bc73de0740d5b88150465d6690ea5f85f upstream.

perf_mmap_close() drops rb->mmap_count *without* holding
event->mmap_mutex (the refcount_dec_and_test() right before the
refcount_dec_and_mutex_lock() of event->mmap_count). A concurrent
perf_mmap_rb() can slot its entire "revival" path into that window
(perf_mmap holds event->mmap_mutex for its whole duration, including
rb_alloc):

  munmap side (perf_mmap_close)          mmap side (perf_mmap_rb)
  -----------------------------------    --------------------------------
  rb->mmap_count 1 -> 0   (no lock)      (holds event->mmap_mutex)
                                         inc_not_zero(rb->mmap_count) fails
                                         ring_buffer_attach(event, NULL)
                                         rb_alloc() + attach new rb
                                         refcount_set(&event->mmap_count, 1)
  lock; event->mmap_count 1 -> 0
  ring_buffer_attach(event, NULL)
  ring_buffer_put() -> frees the *new* rb

The revival's refcount_set(&event->mmap_count, 1) is an invisible
1 -> 1 write: the close frees the just-revived buffer although the
other process still has it mapped -- a page-level use-after-free
allowing local privilege escalation to root by any unprivileged user
(default kernel.perf_event_paranoid=2).

Swap the order of the two counter updates: event->mmap_count is
dropped first via refcount_dec_and_mutex_lock(), so its 1 -> 0
transition and the ring_buffer_attach() stay serialized with
perf_mmap(). rb->mmap_count == 0 then implies every event using the
buffer is detached already, so the result of the rb->mmap_count drop
can gate the remaining teardown directly and detach_rest is no longer
needed.

An earlier fix for this race from Kyle Zeng and David Lee takes
event->mmap_mutex around both counter updates [0]; here the not-last
close stays lockless.

Fixes: 59741451b49c ("perf: Identify the 0->1 transition for event::mmap_count")
Reported-by: Kimi Security Team <bug-report@moonshot.ai>
Suggested-by: Peter Zijlstra <peterz@infradead.org>
Co-developed-by: Weiming Shi <shiweiming@moonshot.ai>
Signed-off-by: Weiming Shi <shiweiming@moonshot.ai>
Signed-off-by: Yilin Zhang <yilinzhang@moonshot.ai>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Link: https://lore.kernel.org/linux-perf-users/20260804060931.711308-1-david.lee@trailofbits.com/ [0]
Cc: <stable@vger.kernel.org>
Cc: stable@vger.kernel.org # 6.18+
Link: https://patch.msgid.link/20260831162155.1437652-1-yilinzhang@moonshot.ai
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 kernel/events/core.c |   20 ++++++++++----------
 1 file changed, 10 insertions(+), 10 deletions(-)

--- a/kernel/events/core.c
+++ b/kernel/events/core.c
@@ -7029,7 +7029,6 @@ static void perf_mmap_close(struct vm_ar
 	mapped_f unmapped = get_mapped(event, event_unmapped);
 	struct perf_buffer *rb = ring_buffer_get(event);
 	struct user_struct *mmap_user = rb->mmap_user;
-	bool detach_rest = false;
 
 	/* FIXIES vs perf_pmu_unregister() */
 	if (unmapped)
@@ -7060,17 +7059,18 @@ static void perf_mmap_close(struct vm_ar
 		mutex_unlock(&rb->aux_mutex);
 	}
 
-	if (refcount_dec_and_test(&rb->mmap_count))
-		detach_rest = true;
-
-	if (!refcount_dec_and_mutex_lock(&event->mmap_count, &event->mmap_mutex))
-		goto out_put;
-
-	ring_buffer_attach(event, NULL);
-	mutex_unlock(&event->mmap_mutex);
+	/*
+	 * Drop references in reverse order of perf_mmap() to prevent
+	 * rb revival after rb->mmap_count reaches zero.
+	 */
+	if (refcount_dec_and_mutex_lock(&event->mmap_count,
+					&event->mmap_mutex)) {
+		ring_buffer_attach(event, NULL);
+		mutex_unlock(&event->mmap_mutex);
+	}
 
 	/* If there's still other mmap()s of this buffer, we're done. */
-	if (!detach_rest)
+	if (!refcount_dec_and_test(&rb->mmap_count))
 		goto out_put;
 
 	/*



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 141/556] i2c: designware: Enable interrupt mask workaround for HJMC3001
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (139 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 140/556] perf: Fix use-after-free when perf mmap() revival races with the last munmap() Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 142/556] i2c: qcom-geni: update frequency table to fix timing parameters Greg Kroah-Hartman
                   ` (427 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Hongbo Yao, Mika Westerberg,
	Andi Shyti

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Hongbo Yao <andy.xu@hj-micro.com>

commit 77549d01edecc20da73c8599e14648877198ce9b upstream.

On HJMicro ARM64 servers, the DesignWare I2C controller does not
retrigger a pending interrupt if the interrupt status changes after
the current status bits have been cleared.

The issue is exposed under heavy system load when the corresponding
SPI is routed across sockets to a core in the remote socket. The
interrupt is then lost and the I2C transfer times out.

Enable ACCESS_INTR_MASK for HJMC3001. This toggles DW_IC_INTR_MASK
before returning from the interrupt handler and retriggers any
pending interrupt.

Fixes: 6816ce57c479 ("i2c: designware: Add a new ACPI HID for HJMC01 I2C controller")
Signed-off-by: Hongbo Yao <andy.xu@hj-micro.com>
Cc: <stable@vger.kernel.org> # v6.13+
Acked-by: Mika Westerberg <mika.westerberg@linux.intel.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260826070547.268672-1-andy.xu@hj-micro.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/i2c/busses/i2c-designware-platdrv.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/i2c/busses/i2c-designware-platdrv.c
+++ b/drivers/i2c/busses/i2c-designware-platdrv.c
@@ -272,7 +272,7 @@ static const struct acpi_device_id dw_i2
 	{ "HISI02A1", 0 },
 	{ "HISI02A2", 0 },
 	{ "HISI02A3", 0 },
-	{ "HJMC3001", 0 },
+	{ "HJMC3001", ACCESS_INTR_MASK },
 	{ "HYGO0010", ACCESS_INTR_MASK },
 	{ "INT33C2", 0 },
 	{ "INT33C3", 0 },



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 142/556] i2c: qcom-geni: update frequency table to fix timing parameters
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (140 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 141/556] i2c: designware: Enable interrupt mask workaround for HJMC3001 Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 143/556] i2c: core: fix debugfs UAF on adapter removal Greg Kroah-Hartman
                   ` (426 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Kathiravan Thirumoorthy,
	Mukesh Savaliya, Konrad Dybcio, Andi Shyti

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Kathiravan Thirumoorthy <kathiravan.thirumoorthy@oss.qualcomm.com>

commit a4f3fbccb65de757569686baaf2b72e329096aba upstream.

In IPQ5424, to meet the setup and hold timing requirements in the
standard mode, update the frequency table with the values recommended by
HW design team.

Also remove the stray space in the I2C_MAX_FAST_MODE_FREQ entry.

Fixes: 85c34532849d ("i2c: qcom-geni: fix I2C frequency table to achieve accurate bus rates")
Fixes: 506bb2ab0075 ("i2c: qcom-geni: Support systems with 32MHz serial engine clock")
Signed-off-by: Kathiravan Thirumoorthy <kathiravan.thirumoorthy@oss.qualcomm.com>
Cc: <stable@vger.kernel.org> # v6.13+
Reviewed-by: Mukesh Savaliya <mukesh.savaliya@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260812-ipq5424_i2c_scl_updates-v2-1-e09cd39d01d7@oss.qualcomm.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/i2c/busses/i2c-qcom-geni.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/drivers/i2c/busses/i2c-qcom-geni.c
+++ b/drivers/i2c/busses/i2c-qcom-geni.c
@@ -177,8 +177,8 @@ static const struct geni_i2c_clk_fld gen
 
 /* source_clock = 32 MHz */
 static const struct geni_i2c_clk_fld geni_i2c_clk_map_32mhz[] = {
-	{ I2C_MAX_STANDARD_MODE_FREQ, 8, 14, 18, 38 },
-	{ I2C_MAX_FAST_MODE_FREQ, 4,  3, 9, 19 },
+	{ I2C_MAX_STANDARD_MODE_FREQ, 12, 9, 10, 26 },
+	{ I2C_MAX_FAST_MODE_FREQ, 4, 3, 9, 19 },
 	{ I2C_MAX_FAST_MODE_PLUS_FREQ, 2, 3, 5, 15 },
 	{}
 };



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 143/556] i2c: core: fix debugfs UAF on adapter removal
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (141 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 142/556] i2c: qcom-geni: update frequency table to fix timing parameters Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 144/556] i2c: mux: Fix channel node leak on adapter add failure Greg Kroah-Hartman
                   ` (425 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+23ad911c819b923238b7,
	Vasileios Almpanis, Andi Shyti

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Vasileios Almpanis <vasilisalmpanis@gmail.com>

commit b15b548d52b43ba8ac4652bc2c7244a8dd1e9622 upstream.

i2c_del_adapter() frees the adapter's debugfs directory before it
unregisters the adapter device, but the new_device sysfs attribute
stays writable until device_del(). A write racing with removal still
reaches i2c_device_probe(), which passes the freed adap->debugfs to
debugfs_create_dir() as the new client's parent:

  BUG: KASAN: slab-use-after-free in lookup_noperm_common+0x407/0x430
  Read of size 4 at addr ffff88803ef87810 by task syz.0.61/6090
   lookup_noperm_common+0x407/0x430
   simple_start_creating+0x9c/0x110
   debugfs_start_creating+0xdb/0x1a0
   debugfs_create_dir+0x24/0x350
   i2c_device_probe+0x814/0xbf0

It's technically possible to create a client after i2c_deregister_clients
has run. That client will never be unregistered and make
wait_for_completion hang.

Close the window by removing the new_device attribute at the start of
i2c_del_adapter(). device_remove_file() will drain any clients left.

Fixes: 73febd775bdb ("i2c: create debugfs entry per adapter")
Reported-by: syzbot+23ad911c819b923238b7@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=23ad911c819b923238b7
Signed-off-by: Vasileios Almpanis <vasilisalmpanis@gmail.com>
Cc: <stable@vger.kernel.org> # v6.8+
Tested-by: syzbot+23ad911c819b923238b7@syzkaller.appspotmail.com
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260812-i2c-v2-1-5efaab4c3334@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/i2c/i2c-core-base.c |    6 ++++++
 1 file changed, 6 insertions(+)

--- a/drivers/i2c/i2c-core-base.c
+++ b/drivers/i2c/i2c-core-base.c
@@ -1815,6 +1815,12 @@ void i2c_del_adapter(struct i2c_adapter
 		return;
 	}
 
+	/*
+	 * This drains any in-flight writers, so all
+	 * clients will be caught by i2c_deregister_clients().
+	 */
+	device_remove_file(&adap->dev, &dev_attr_new_device);
+
 	i2c_acpi_remove_space_handler(adap);
 
 	i2c_deregister_clients(adap);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 144/556] i2c: mux: Fix channel node leak on adapter add failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (142 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 143/556] i2c: core: fix debugfs UAF on adapter removal Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 145/556] i2c: qcom-cci: fix autosuspend cleanup Greg Kroah-Hartman
                   ` (424 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Ahmad Byagowi, Peter Rosin,
	Andi Shyti

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ahmad Byagowi <ahmadexp@gmail.com>

commit 385c7af4e3b95d0769fd211831674e83b16a2ebf upstream.

i2c_mux_add_adapter() takes a reference to the Device Tree channel node
before registering the new adapter. If adapter registration fails, the
error path frees the private data without dropping that reference.

Release the channel node before freeing the private data.

Fixes: bc45449b1444 ("i2c/of: Automatically populate i2c mux busses from device tree data.")
Signed-off-by: Ahmad Byagowi <ahmadexp@gmail.com>
Cc: <stable@vger.kernel.org> # v3.5+
Acked-by: Peter Rosin <peda@lysator.liu.se>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/b3e46bbee781b3cb4029aca9a71316cc5e36dc17.1787502619.git.ahmadexp@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/i2c/i2c-mux.c |    1 +
 1 file changed, 1 insertion(+)

--- a/drivers/i2c/i2c-mux.c
+++ b/drivers/i2c/i2c-mux.c
@@ -408,6 +408,7 @@ int i2c_mux_add_adapter(struct i2c_mux_c
 	return 0;
 
 err_free_priv:
+	of_node_put(priv->adap.dev.of_node);
 	kfree(priv);
 	return ret;
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 145/556] i2c: qcom-cci: fix autosuspend cleanup
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (143 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 144/556] i2c: mux: Fix channel node leak on adapter add failure Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 146/556] arm64: mm: Fix the lockless page-table walk in show_pte() Greg Kroah-Hartman
                   ` (423 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Vladimir Zapolskiy,
	Loic Poulain, Andi Shyti

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Guangshuo Li <lgs201920130244@gmail.com>

commit f98d4986482151a835b521a734722fe8dc5ca37d upstream.

cci_probe() calls pm_runtime_use_autosuspend(), but the remove path
does not call the matching pm_runtime_dont_use_autosuspend() before
disabling runtime PM.

If the autosuspend delay is set to a negative value while autosuspend
is enabled, the runtime PM core increments usage_count to prevent
runtime suspend. Without undoing the autosuspend setting during
teardown, this reference is not dropped and usage_count remains
unbalanced.

Use devm_pm_runtime_set_active_enabled() to manage the runtime PM
state. Its managed cleanup disables autosuspend and runtime PM and
restores the suspended state on probe failure and driver removal.
Remove the now redundant manual runtime PM cleanup.

This issue was found by manual code inspection.

Fixes: e517526195de ("i2c: Add Qualcomm CCI I2C driver")
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Cc: <stable@vger.kernel.org> # v5.8+
Reviewed-by: Vladimir Zapolskiy <vladimir.zapolskiy@linaro.org>
Reviewed-by: Loic Poulain <loic.poulain@oss.qualcomm.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260812094425.3515179-1-lgs201920130244@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/i2c/busses/i2c-qcom-cci.c |   11 ++++-------
 1 file changed, 4 insertions(+), 7 deletions(-)

--- a/drivers/i2c/busses/i2c-qcom-cci.c
+++ b/drivers/i2c/busses/i2c-qcom-cci.c
@@ -595,9 +595,11 @@ static int cci_probe(struct platform_dev
 		goto disable_clocks;
 
 	pm_runtime_set_autosuspend_delay(dev, MSEC_PER_SEC);
+	ret = devm_pm_runtime_set_active_enabled(dev);
+	if (ret)
+		goto disable_clocks;
+
 	pm_runtime_use_autosuspend(dev);
-	pm_runtime_set_active(dev);
-	pm_runtime_enable(dev);
 
 	for (i = 0; i < cci->data->num_masters; i++) {
 		if (!cci->master[i].cci)
@@ -613,8 +615,6 @@ static int cci_probe(struct platform_dev
 	return 0;
 
 error_i2c:
-	pm_runtime_disable(dev);
-	pm_runtime_dont_use_autosuspend(dev);
 
 	for (--i ; i >= 0; i--) {
 		if (cci->master[i].cci) {
@@ -640,9 +640,6 @@ static void cci_remove(struct platform_d
 			cci_halt(cci, i);
 		}
 	}
-
-	pm_runtime_disable(&pdev->dev);
-	pm_runtime_set_suspended(&pdev->dev);
 }
 
 static const struct cci_data cci_v1_data = {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 146/556] arm64: mm: Fix the lockless page-table walk in show_pte()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (144 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 145/556] i2c: qcom-cci: fix autosuspend cleanup Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 147/556] arm64: Dont read GMID_EL1 when MTE is disabled Greg Kroah-Hartman
                   ` (422 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Will Deacon

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Karl Mehltretter <kmehltretter@gmail.com>

commit a77644d009dece1104b6fcc6e322b0e4503db0d6 upstream.

show_pte() walks page tables locklessly and can run with interrupts
enabled. A concurrent teardown can free a table page while it is being
walked. It can also clear a parent entry after show_pte() checked it; the
regular pXd_offset() helpers then reread the cleared entry and can derive a
bogus lower-level pointer and fault again.

Use the lockless offset helpers with the saved parent entries, as
gup_fast() does, and pass the saved PMD to pte_offset_map().

For task page tables, arm64 selects MMU_GATHER_RCU_TABLE_FREE. Disable
local interrupts around the walk to hold off RCU-deferred table frees and
block the tlb_remove_table_sync_one() IPI until the walk is finished.

Place the IRQ guard after the header print. This does not make the output a
consistent snapshot, but prevents the task page-table walk from
dereferencing a released table page or deriving a pointer from a different
parent value.

Fixes: 1d18c47c735e ("arm64: MMU fault handling and page table management")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/arm64/mm/fault.c |   12 ++++++++----
 1 file changed, 8 insertions(+), 4 deletions(-)

--- a/arch/arm64/mm/fault.c
+++ b/arch/arm64/mm/fault.c
@@ -16,6 +16,7 @@
 #include <linux/mm.h>
 #include <linux/hardirq.h>
 #include <linux/init.h>
+#include <linux/irqflags.h>
 #include <linux/kasan.h>
 #include <linux/kprobes.h>
 #include <linux/uaccess.h>
@@ -154,6 +155,9 @@ static void show_pte(unsigned long addr)
 	pr_alert("%s pgtable: %luk pages, %llu-bit VAs, pgdp=%016lx\n",
 		 mm == &init_mm ? "swapper" : "user", PAGE_SIZE / SZ_1K,
 		 vabits_actual, mm_to_pgd_phys(mm));
+
+	guard(irqsave)();
+
 	pgdp = pgd_offset(mm, addr);
 	pgd = READ_ONCE(*pgdp);
 	pr_alert("[%016lx] pgd=%016llx", addr, pgd_val(pgd));
@@ -167,25 +171,25 @@ static void show_pte(unsigned long addr)
 		if (pgd_none(pgd) || pgd_bad(pgd))
 			break;
 
-		p4dp = p4d_offset(pgdp, addr);
+		p4dp = p4d_offset_lockless(pgdp, pgd, addr);
 		p4d = READ_ONCE(*p4dp);
 		pr_cont(", p4d=%016llx", p4d_val(p4d));
 		if (p4d_none(p4d) || p4d_bad(p4d))
 			break;
 
-		pudp = pud_offset(p4dp, addr);
+		pudp = pud_offset_lockless(p4dp, p4d, addr);
 		pud = READ_ONCE(*pudp);
 		pr_cont(", pud=%016llx", pud_val(pud));
 		if (pud_none(pud) || pud_bad(pud))
 			break;
 
-		pmdp = pmd_offset(pudp, addr);
+		pmdp = pmd_offset_lockless(pudp, pud, addr);
 		pmd = READ_ONCE(*pmdp);
 		pr_cont(", pmd=%016llx", pmd_val(pmd));
 		if (pmd_none(pmd) || pmd_bad(pmd))
 			break;
 
-		ptep = pte_offset_map(pmdp, addr);
+		ptep = pte_offset_map(&pmd, addr);
 		if (!ptep)
 			break;
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 147/556] arm64: Dont read GMID_EL1 when MTE is disabled
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (145 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 146/556] arm64: mm: Fix the lockless page-table walk in show_pte() Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 148/556] arm64: errata: pass REVIDR when matching target implementation CPUs Greg Kroah-Hartman
                   ` (421 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Fuad Tabba, Catalin Marinas,
	Will Deacon

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Fuad Tabba <fuad.tabba@linux.dev>

commit 5445d64199626974269fcdf347769ad44b0bb53b upstream.

__cpuinfo_store_cpu() gates the GMID_EL1 read on the raw
ID_AA64PFR1_EL1, so it reads the register even when the kernel has
disabled MTE (CONFIG_ARM64_MTE=n or arm64.nomte). KVM sets HCR_EL2.TID5
in that case, and pKVM injects an UNDEF the host cannot handle:

  Internal error: Oops - Undefined instruction: 0000000002000000 [#1]  SMP
  pc : __cpuinfo_store_cpu+0xf4/0x264
  Kernel panic - not syncing: Attempted to kill the idle task!

Only pKVM reaches it, and only after a CPU is offlined and brought back
online: its CPU_ON relay sets the host HCR before the CPU enters EL1,
while plain nVHE sets it at CPUHP_AP_KVM_ONLINE.

Gate the read on the CPU's own ID_AA64PFR1_EL1 with the command-line
override applied, and on CONFIG_ARM64_MTE, which no register reflects.
The boot CPU stores its registers before init_cpu_features() strips an
unsafe override, so clamp against the hardware value here too.

Fixes: f35abcbb8a084 ("KVM: arm64: Trap MTE access and discovery when MTE is disabled")
Cc: stable@vger.kernel.org
Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev>
Reviewed-by: Catalin Marinas <catalin.marinas@arm.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/arm64/include/asm/cpu.h        |    1 +
 arch/arm64/include/asm/cpufeature.h |    7 -------
 arch/arm64/kernel/cpufeature.c      |   33 +++++++++++++++++++++++++++++----
 arch/arm64/kernel/cpuinfo.c         |    2 +-
 4 files changed, 31 insertions(+), 12 deletions(-)

--- a/arch/arm64/include/asm/cpu.h
+++ b/arch/arm64/include/asm/cpu.h
@@ -78,5 +78,6 @@ void __init cpuinfo_store_boot_cpu(void)
 void __init init_cpu_features(struct cpuinfo_arm64 *info);
 void update_cpu_features(int cpu, struct cpuinfo_arm64 *info,
 				 struct cpuinfo_arm64 *boot);
+bool gmid_el1_accessible(const struct cpuinfo_arm64 *info);
 
 #endif /* __ASM_CPU_H */
--- a/arch/arm64/include/asm/cpufeature.h
+++ b/arch/arm64/include/asm/cpufeature.h
@@ -627,13 +627,6 @@ static inline bool id_aa64pfr1_mpamfrac(
 	return val > 0;
 }
 
-static inline bool id_aa64pfr1_mte(u64 pfr1)
-{
-	u32 val = cpuid_feature_extract_unsigned_field(pfr1, ID_AA64PFR1_EL1_MTE_SHIFT);
-
-	return val >= ID_AA64PFR1_EL1_MTE_MTE2;
-}
-
 void __init setup_boot_cpu_features(void);
 void __init setup_system_features(void);
 void __init setup_user_features(void);
--- a/arch/arm64/kernel/cpufeature.c
+++ b/arch/arm64/kernel/cpufeature.c
@@ -1176,6 +1176,33 @@ static bool detect_ftr_has_mpam(void)
 	return id_aa64pfr0_mpam(pfr0) || id_aa64pfr1_mpamfrac(pfr1);
 }
 
+bool gmid_el1_accessible(const struct cpuinfo_arm64 *info)
+{
+	const struct arm64_ftr_bits *ftrp;
+	s64 mte, ovr;
+	u64 ftr_mask;
+
+	/* No ID register reflects CONFIG_ARM64_MTE. */
+	if (!IS_ENABLED(CONFIG_ARM64_MTE))
+		return false;
+
+	for (ftrp = ftr_id_aa64pfr1; ftrp->width; ftrp++) {
+		if (ftrp->shift == ID_AA64PFR1_EL1_MTE_SHIFT)
+			break;
+	}
+
+	ftr_mask = arm64_ftr_mask(ftrp);
+	mte = arm64_ftr_value(ftrp, info->reg_id_aa64pfr1);
+
+	/* The boot CPU runs before init_cpu_ftr_reg() strips unsafe overrides. */
+	if ((id_aa64pfr1_override.mask & ftr_mask) == ftr_mask) {
+		ovr = arm64_ftr_value(ftrp, id_aa64pfr1_override.val);
+		mte = arm64_ftr_safe_value(ftrp, ovr, mte);
+	}
+
+	return mte >= ID_AA64PFR1_EL1_MTE_MTE2;
+}
+
 void __init init_cpu_features(struct cpuinfo_arm64 *info)
 {
 	/* Before we start using the tables, make sure it is sorted */
@@ -1228,7 +1255,7 @@ void __init init_cpu_features(struct cpu
 		init_cpu_ftr_reg(SYS_MPAMIDR_EL1, info->reg_mpamidr);
 	}
 
-	if (id_aa64pfr1_mte(info->reg_id_aa64pfr1))
+	if (gmid_el1_accessible(info))
 		init_cpu_ftr_reg(SYS_GMID_EL1, info->reg_gmid);
 }
 
@@ -1490,11 +1517,9 @@ void update_cpu_features(int cpu,
 	 * they read/write depends on the GMID_EL1.BS field. Check that the
 	 * value is the same on all CPUs.
 	 */
-	if (IS_ENABLED(CONFIG_ARM64_MTE) &&
-	    id_aa64pfr1_mte(info->reg_id_aa64pfr1)) {
+	if (gmid_el1_accessible(info))
 		taint |= check_update_ftr_reg(SYS_GMID_EL1, cpu,
 					      info->reg_gmid, boot->reg_gmid);
-	}
 
 	/*
 	 * If we don't have AArch32 at all then skip the checks entirely
--- a/arch/arm64/kernel/cpuinfo.c
+++ b/arch/arm64/kernel/cpuinfo.c
@@ -502,7 +502,7 @@ static void __cpuinfo_store_cpu(struct c
 	info->reg_id_aa64smfr0 = read_cpuid(ID_AA64SMFR0_EL1);
 	info->reg_id_aa64fpfr0 = read_cpuid(ID_AA64FPFR0_EL1);
 
-	if (id_aa64pfr1_mte(info->reg_id_aa64pfr1))
+	if (gmid_el1_accessible(info))
 		info->reg_gmid = read_cpuid(GMID_EL1);
 
 	if (id_aa64pfr0_32bit_el0(info->reg_id_aa64pfr0))



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 148/556] arm64: errata: pass REVIDR when matching target implementation CPUs
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (146 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 147/556] arm64: Dont read GMID_EL1 when MTE is disabled Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 149/556] ALSA: rawmidi: Return the error from snd_rawmidi_input_params() Greg Kroah-Hartman
                   ` (420 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Khushit Shah, Zenghui Yu (Huawei),
	Marc Zyngier, Shameer Kolothum, Will Deacon

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Khushit Shah <khushit.shah@nutanix.com>

commit 5541432e09dc2031978188f3e8a00b9fc78cf097 upstream.

When target implementation CPUs are provided, is_affected_midr_range()
accidentally passed the MIDR as both arguments to __is_affected_midr_range(),
so the REVIDR mask check operated on the wrong register.

Pass REVIDR as intended.

Fixes: 86edf6bdcf05 ("smccc/kvm_guest: Enable errata based on implementation CPUs")
Cc: stable@vger.kernel.org
Signed-off-by: Khushit Shah <khushit.shah@nutanix.com>
Reviewed-by: Zenghui Yu (Huawei) <zenghui.yu@linux.dev>
Acked-by: Marc Zyngier <maz@kernel.org>
Reviewed-by: Shameer Kolothum <skolothumtho@nvidia.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/arm64/kernel/cpu_errata.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/arch/arm64/kernel/cpu_errata.c
+++ b/arch/arm64/kernel/cpu_errata.c
@@ -82,7 +82,7 @@ is_affected_midr_range(const struct arm6
 
 	for (i = 0; i < target_impl_cpu_num; i++) {
 		if (__is_affected_midr_range(entry, target_impl_cpus[i].midr,
-					     target_impl_cpus[i].midr))
+					     target_impl_cpus[i].revidr))
 			return true;
 	}
 	return false;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 149/556] ALSA: rawmidi: Return the error from snd_rawmidi_input_params()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (147 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 148/556] arm64: errata: pass REVIDR when matching target implementation CPUs Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 150/556] ALSA: harmony: initialize locks before requesting IRQ Greg Kroah-Hartman
                   ` (419 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, HyeongJun An, Takashi Iwai

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: HyeongJun An <sammiee5311@gmail.com>

commit f4a23e17d84fd2a152d9e12369761934e1af0ee8 upstream.

The snd_rawmidi_input_params() computes err for the three invalid mode
combinations and for resize_runtime_buffer(), applies the new framing
and clock type only when err is zero, and then returns 0 anyway.  A
caller that asked for parameters the kernel rejected is told the change
succeeded, and the substream keeps its old buffer.

The open_mutex conversion turned the early returns into assignments.
It handled the output sibling correctly, which still returns err, and
left this one behind.

Fixes: 94b98194b62e ("ALSA: rawmidi: Take open_mutex around parameter changes")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-5
Signed-off-by: HyeongJun An <sammiee5311@gmail.com>
Link: https://patch.msgid.link/20260902125058.19499-1-sammiee5311@gmail.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/core/rawmidi.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/sound/core/rawmidi.c
+++ b/sound/core/rawmidi.c
@@ -782,7 +782,7 @@ int snd_rawmidi_input_params(struct snd_
 		substream->framing = framing;
 		substream->clock_type = clock_type;
 	}
-	return 0;
+	return err;
 }
 EXPORT_SYMBOL(snd_rawmidi_input_params);
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 150/556] ALSA: harmony: initialize locks before requesting IRQ
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (148 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 149/556] ALSA: rawmidi: Return the error from snd_rawmidi_input_params() Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 151/556] ALSA: pcm: Fix race between non-atomic ops and trigger-start Greg Kroah-Hartman
                   ` (418 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Runyu Xiao, Takashi Iwai

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Runyu Xiao <runyu.xiao@seu.edu.cn>

commit 33abb7491e89285a41565670945293dda841afc4 upstream.

snd_harmony_create() registers the IRQ before initializing h->lock and
h->mixer_lock. A pending interrupt can invoke the handler while these
locks are uninitialized.

Initialize both locks before requesting the IRQ so the handler always
sees valid lock state.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Assisted-by: Codex:GPT-5
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Link: https://patch.msgid.link/20260830063411.2215691-1-runyu.xiao@seu.edu.cn
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/parisc/harmony.c |    6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

--- a/sound/parisc/harmony.c
+++ b/sound/parisc/harmony.c
@@ -868,6 +868,9 @@ snd_harmony_create(struct snd_card *card
 		goto free_and_ret;
 	}
 		
+	spin_lock_init(&h->mixer_lock);
+	spin_lock_init(&h->lock);
+
 	err = request_irq(padev->irq, snd_harmony_interrupt, 0,
 			  "harmony", h);
 	if (err) {
@@ -877,9 +880,6 @@ snd_harmony_create(struct snd_card *card
 	}
 	h->irq = padev->irq;
 
-	spin_lock_init(&h->mixer_lock);
-	spin_lock_init(&h->lock);
-
 	err = snd_device_new(card, SNDRV_DEV_LOWLEVEL, h, &ops);
 	if (err < 0)
 		goto free_and_ret;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 151/556] ALSA: pcm: Fix race between non-atomic ops and trigger-start
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (149 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 150/556] ALSA: harmony: initialize locks before requesting IRQ Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 152/556] ring-buffer: Allow splice reads on static buffers Greg Kroah-Hartman
                   ` (417 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+225231fce6755d40d078,
	Takashi Iwai

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Takashi Iwai <tiwai@suse.de>

commit acac7b5e07349a9d10d78873afb4b93cd1dc721f upstream.

We protect the races of the concurrent state transitions between
atomic PCM ops, but the checks between the non-atomic ops (hw_params,
hw_free and prepare) and the atomic ops aren't perfect; there is a
check of the conflicting PCM state at the beginning of hw_params & co,
but the atomic PCM ops can be still issued during the non-atomic PCM
operations.  An example such scenario is that a thread A re-issues the
PREPARE or HW_PARAMS for the already prepared stream, while another
thread B triggers the PCM start in the middle of the prepare
operation.  Although this usually doesn't lead to much serious issues,
it can give some inconsistency as reported by syzkaller (such as
ODEBUG warning).

There are various atomic PCM ops, and basically the only problem is
the PCM start as it operates from the PREPARED state.  Other trigger
commands (stop, etc) are for the running or the other special state,
hence they are filtered as pre-condition.

This patch is for preventing the PCM trigger-start during the non-
atomic operations in order to address the problems above.
Fortunately, the hw_params, hw_free and prepare operations call
snd_pcm_buffer_access_lock(), and this can be used for checking the
concurrent operations at the PCM trigger -- which sets the
runtime->buffer_accessing to a negative (if possible), so the PCM
trigger just needs to check the runtime->buffer_accessing value; if
it's negative, it means the concurrent non-atomic PCM ops is running.

Reported-by: syzbot+225231fce6755d40d078@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/6a8f0de8.1d9ded08.62e62.00b5.GAE@google.com
Cc: <stable@vger.kernel.org>
Link: https://patch.msgid.link/20260828115542.3999-1-tiwai@suse.de
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/core/pcm_native.c |    2 ++
 1 file changed, 2 insertions(+)

--- a/sound/core/pcm_native.c
+++ b/sound/core/pcm_native.c
@@ -1468,6 +1468,8 @@ static int snd_pcm_pre_start(struct snd_
 	struct snd_pcm_runtime *runtime = substream->runtime;
 	if (runtime->state != SNDRV_PCM_STATE_PREPARED)
 		return -EBADFD;
+	if (atomic_read(&runtime->buffer_accessing) < 0)
+		return -EBADFD; /* during hw_params, hw_free or prepare */
 	if (substream->stream == SNDRV_PCM_STREAM_PLAYBACK &&
 	    !snd_pcm_playback_data(substream))
 		return -EPIPE;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 152/556] ring-buffer: Allow splice reads on static buffers
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (150 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 151/556] ALSA: pcm: Fix race between non-atomic ops and trigger-start Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 153/556] accel/amdxdna: return early from a zero-length flush Greg Kroah-Hartman
                   ` (416 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Vincent Donnefort, Steven Rostedt

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Vincent Donnefort <vdonnefort@google.com>

commit 6365c44a824ff138e7926413932bb5c2e28a4c8c upstream.

ring_buffer_read_page() rejects splice (full=1) reads on static buffers
(that is user-mapped, persistent or remote) because !read check assumes
unread pages must be swapped. However for those buffers we have no other
choice than memcpy the data.

For the memcpy case, only return an error when the writer is still on
the reader page for the splice interface to wait.

Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260901155445.1475405-2-vdonnefort@google.com
Fixes: 117c39200d9d ("ring-buffer: Introducing ring-buffer mapping functions")
Signed-off-by: Vincent Donnefort <vdonnefort@google.com>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 kernel/trace/ring_buffer.c |   11 ++---------
 1 file changed, 2 insertions(+), 9 deletions(-)

--- a/kernel/trace/ring_buffer.c
+++ b/kernel/trace/ring_buffer.c
@@ -7182,15 +7182,8 @@ int ring_buffer_read_page(struct trace_b
 		unsigned int event_size;
 		unsigned int flags = 0;
 
-		/*
-		 * If a full page is expected, this can still be returned
-		 * if there's been a previous partial read and the
-		 * rest of the page can be read and the commit page is off
-		 * the reader page.
-		 */
-		if (full &&
-		    (!read || (len < (size - read)) ||
-		     cpu_buffer->reader_page == cpu_buffer->commit_page))
+		/* If a full page is requested, it cannot be the commit page */
+		if (full && cpu_buffer->reader_page == cpu_buffer->commit_page)
 			return -1;
 
 		if (len > (size - read))



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 153/556] accel/amdxdna: return early from a zero-length flush
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (151 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 152/556] ring-buffer: Allow splice reads on static buffers Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 154/556] accel/ethosu: check MMIO mapping errors in probe Greg Kroah-Hartman
                   ` (415 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Taimuraz Kaitmazov, Lizhi Hou

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Taimuraz Kaitmazov <taimuraz@kaitmazov.com>

commit dc14753664240cedf669623b27ae9922b0618b25 upstream.

SYNC_BO does not constrain its size, so a request for zero bytes reaches
drm_clflush_virt_range(), which ends with an unconditional
clflushopt(end - 1). For an empty range that is the byte before the
mapping, and abo->mem.kva comes from vmap(), so the access lands in the
guard page below the vmalloc area and faults:

  BUG: unable to handle page fault for address: ffffd16fbbc70fff
  #PF: supervisor read access in kernel mode
  Oops: Oops: 0000 [#1] SMP NOPTI
  CPU: 7 UID: 1000 Comm: sync_bo_probe
  RIP: 0010:drm_clflush_virt_range+0x3c/0x70
  Call Trace:
   amdxdna_drm_sync_bo_ioctl+0x124/0x430 [amdxdna]
   drm_ioctl+0x301/0x4c0
   __x64_sys_ioctl+0x115/0x2f0
   do_syscall_64+0xa6/0x3d0

Any process that can open the render node can do this. Reproduced 3 of 3
times on a Strix Point NPU (1022:17f0), by calling SYNC_BO with size 0 on
an AMDXDNA_BO_SHARE object. The import arm takes the same request but
flushes the whole scatterlist, so it survives it.

Nothing needs flushing for an empty range, so answer before choosing a
path.

Fixes: e252e3f3488a ("accel/amdxdna: Revise device bo creation and free")
Cc: stable@vger.kernel.org
Signed-off-by: Taimuraz Kaitmazov <taimuraz@kaitmazov.com>
Reviewed-by: Lizhi Hou <lizhi.hou@amd.com>
Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
Link: https://patch.msgid.link/20260817230655.356785-1-taimuraz@kaitmazov.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/accel/amdxdna/amdxdna_gem.c |    3 +++
 1 file changed, 3 insertions(+)

--- a/drivers/accel/amdxdna/amdxdna_gem.c
+++ b/drivers/accel/amdxdna/amdxdna_gem.c
@@ -1247,6 +1247,9 @@ static int amdxdna_flush_bo(struct amdxd
 		return -EINVAL;
 
 	size = min(abo->mem.size, end) - offset;
+	if (!size)
+		return 0;
+
 	if (is_import_bo(abo))
 		drm_clflush_sg(abo->base.sgt);
 	else if (amdxdna_gem_vmap(abo))



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 154/556] accel/ethosu: check MMIO mapping errors in probe
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (152 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 153/556] accel/amdxdna: return early from a zero-length flush Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 155/556] accel/ethosu: fix job completion fence cleanup Greg Kroah-Hartman
                   ` (414 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, GuoHan Zhao, Rob Herring (Arm)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: GuoHan Zhao <zhaoguohan@kylinos.cn>

commit 7ab64476a610fe65858fdc37c7a30caa13e334ac upstream.

devm_platform_ioremap_resource() returns an error pointer when the register
resource cannot be mapped. ethosu_probe() stores it and continues until
initialization dereferences it through MMIO accessors.

Return the mapping error before initializing the device.

Fixes: 5a5e9c0228e6 ("accel: Add Arm Ethos-U NPU driver")
Cc: stable@vger.kernel.org
Signed-off-by: GuoHan Zhao <zhaoguohan@kylinos.cn>
Link: https://patch.msgid.link/20260716065219.931088-1-zhaoguohan@kylinos.cn
Signed-off-by: Rob Herring (Arm) <robh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/accel/ethosu/ethosu_drv.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/accel/ethosu/ethosu_drv.c b/drivers/accel/ethosu/ethosu_drv.c
index ed9c748a54ad..b2901eb8a7a0 100644
--- a/drivers/accel/ethosu/ethosu_drv.c
+++ b/drivers/accel/ethosu/ethosu_drv.c
@@ -342,6 +342,8 @@ static int ethosu_probe(struct platform_device *pdev)
 	dma_set_mask_and_coherent(&pdev->dev, DMA_BIT_MASK(40));
 
 	ethosudev->regs = devm_platform_ioremap_resource(pdev, 0);
+	if (IS_ERR(ethosudev->regs))
+		return PTR_ERR(ethosudev->regs);
 
 	ethosudev->num_clks = devm_clk_bulk_get_all(&pdev->dev, &ethosudev->clks);
 	if (ethosudev->num_clks < 0)
-- 
2.55.0




^ permalink raw reply related	[flat|nested] 570+ messages in thread

* [PATCH 7.2 155/556] accel/ethosu: fix job completion fence cleanup
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (153 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 154/556] accel/ethosu: check MMIO mapping errors in probe Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 156/556] nvme-fabrics: fix DHCHAP secret leak on parse failure Greg Kroah-Hartman
                   ` (413 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, GuoHan Zhao,
	Rob Herring (Arm)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: GuoHan Zhao <zhaoguohan@kylinos.cn>

commit 2d2a3adc91950f9a18829dadc7317fb5180a15c5 upstream.

ethosu_ioctl_submit_job() allocates done_fence before validating buffer
handles. Errors after allocation call ethosu_job_err_cleanup(), which frees
the job but leaks the uninitialized fence.

A scheduler dependency error also lets ethosu_job_run() return before
dma_fence_init(). Normal cleanup then passes a zeroed refcount to
dma_fence_put().

Release done_fence in the common cleanup path and use
dma_fence_was_initialized() to distinguish initialized fences from raw
allocations.

Fixes: 5a5e9c0228e6 ("accel: Add Arm Ethos-U NPU driver")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://sashiko.dev/#/patchset/20260716065219.931088-1-zhaoguohan@kylinos.cn?part=1
Signed-off-by: GuoHan Zhao <zhaoguohan@kylinos.cn>
Link: https://patch.msgid.link/20260717061145.1478139-6-zhaoguohan@kylinos.cn
[robh: also fix goto]
Signed-off-by: Rob Herring (Arm) <robh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/accel/ethosu/ethosu_job.c | 10 ++++++++--
 1 file changed, 8 insertions(+), 2 deletions(-)

diff --git a/drivers/accel/ethosu/ethosu_job.c b/drivers/accel/ethosu/ethosu_job.c
index 1e2465279aae..1e4b65f62933 100644
--- a/drivers/accel/ethosu/ethosu_job.c
+++ b/drivers/accel/ethosu/ethosu_job.c
@@ -152,6 +152,13 @@ static void ethosu_job_err_cleanup(struct ethosu_job *job)
 
 	drm_gem_object_put(job->cmd_bo);
 
+	if (job->done_fence) {
+		if (dma_fence_was_initialized(job->done_fence))
+			dma_fence_put(job->done_fence);
+		else
+			dma_fence_free(job->done_fence);
+	}
+
 	kfree(job);
 }
 
@@ -162,7 +169,6 @@ static void ethosu_job_cleanup(struct kref *ref)
 
 	pm_runtime_put_autosuspend(job->dev->base.dev);
 
-	dma_fence_put(job->done_fence);
 	dma_fence_put(job->inference_done_fence);
 
 	ethosu_job_err_cleanup(job);
@@ -393,7 +399,7 @@ static int ethosu_ioctl_submit_job(struct drm_device *dev, struct drm_file *file
 	ejob->done_fence = kzalloc_obj(*ejob->done_fence);
 	if (!ejob->done_fence) {
 		ret = -ENOMEM;
-		goto out_cleanup_job;
+		goto out_put_job;
 	}
 
 	ret = drm_sched_job_init(&ejob->base,
-- 
2.55.0




^ permalink raw reply related	[flat|nested] 570+ messages in thread

* [PATCH 7.2 156/556] nvme-fabrics: fix DHCHAP secret leak on parse failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (154 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 155/556] accel/ethosu: fix job completion fence cleanup Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 157/556] nvme-fc: fix double free of fabrics options when nvme_add_ctrl() fails Greg Kroah-Hartman
                   ` (412 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Christoph Hellwig, Xu Rao,
	Keith Busch

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Xu Rao <raoxu@uniontech.com>

commit afdee49a1b88ed9bb44e2b30e855297c169bcc53 upstream.

nvmf_parse_options() duplicates dhchap_secret and dhchap_ctrl_secret
with match_strdup() before validating the DHHC-1: representation.

If validation fails, the parser returns -EINVAL before the temporary
string in p is assigned to opts->dhchap_secret or
opts->dhchap_ctrl_secret. nvmf_create_ctrl() subsequently frees opts,
but nvmf_free_options() cannot release the unassigned temporary string.
Each rejected option therefore leaks one allocation.

This is easy to miss because valid secrets transfer ownership to opts
and are freed normally, while the malformed-secret path still returns
the expected -EINVAL to userspace.

With CONFIG_NVME_HOST_AUTH enabled, the leak is reachable before the
required-option checks and transport lookup. No NVMe-oF target or
working transport connection is required; for example, repeatedly
writing

	dhchap_secret=BAD

or

	dhchap_ctrl_secret=BAD

to /dev/nvme-fabrics deterministically takes the leaking parse path.

Free the temporary string before leaving both validation error paths.
Use kfree_sensitive() because the copied option may contain secret
material even when its representation is rejected, matching the
sensitive cleanup used for stored DHCHAP secrets.

Fixes: f50fff73d620 ("nvme: implement In-Band authentication")
Cc: stable@vger.kernel.org
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Xu Rao <raoxu@uniontech.com>
Signed-off-by: Keith Busch <kbusch@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/nvme/host/fabrics.c |    2 ++
 1 file changed, 2 insertions(+)

--- a/drivers/nvme/host/fabrics.c
+++ b/drivers/nvme/host/fabrics.c
@@ -1028,6 +1028,7 @@ static int nvmf_parse_options(struct nvm
 			}
 			if (strlen(p) < 11 || strncmp(p, "DHHC-1:", 7)) {
 				pr_err("Invalid DH-CHAP secret %s\n", p);
+				kfree_sensitive(p);
 				ret = -EINVAL;
 				goto out;
 			}
@@ -1042,6 +1043,7 @@ static int nvmf_parse_options(struct nvm
 			}
 			if (strlen(p) < 11 || strncmp(p, "DHHC-1:", 7)) {
 				pr_err("Invalid DH-CHAP secret %s\n", p);
+				kfree_sensitive(p);
 				ret = -EINVAL;
 				goto out;
 			}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 157/556] nvme-fc: fix double free of fabrics options when nvme_add_ctrl() fails
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (155 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 156/556] nvme-fabrics: fix DHCHAP secret leak on parse failure Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 158/556] nvme-tcp: check the data direction of a C2HData PDU Greg Kroah-Hartman
                   ` (411 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+f58e57380a6083c4041d,
	Niklas Cassel, Rihyeon Kim, Hannes Reinecke, Keith Busch

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Niklas Cassel <cassel@kernel.org>

commit 56e6279266f6962bb2d38a54397e3c605165b0c5 upstream.

nvmf_create_ctrl() owns the fabrics options and frees them whenever
->create_ctrl() returns an error, so a transport must not free them on
its own error paths.  nvme-fc tracks this by testing ctrl->ctrl.opts in
nvme_fc_ctrl_free(), which requires nvme_fc_init_ctrl() to clear that
pointer on every error exit.

The coupling is implicit, and commit 1a9e218195a5 ("nvme: split device
add from initialization") broke it by adding a second error exit.  When
nvme_add_ctrl() fails, nvme_fc_init_ctrl() jumps to out_put_ctrl:, past
the "ctrl->ctrl.opts = NULL" that only sits on the fail_ctrl: path, so
nvme_fc_ctrl_free() frees the options and nvmf_create_ctrl() frees them
a second time:

  BUG: KASAN: slab-use-after-free in nvmf_free_options+0x30/0x190
   nvmf_free_options+0x30/0x190 drivers/nvme/host/fabrics.c:1284
   nvmf_create_ctrl drivers/nvme/host/fabrics.c:1374 [inline]
  Freed by task 5534:
   nvme_fc_ctrl_free drivers/nvme/host/fc.c:2374 [inline]
   nvme_fc_init_ctrl+0xe17/0x1450 drivers/nvme/host/fc.c:3605

nvme_add_ctrl() fails when dev_set_name() cannot allocate, so this is
reachable under memory pressure or fault injection.  Without KASAN the
options are freed twice.

Rather than clear the pointer on the second exit as well, derive
ownership the way nvme-tcp, nvme-rdma and nvme-loop do, from list
membership: their free_ctrl leaves the options alone unless the
controller made it onto the transport list.

The list cannot simply be populated on the success path as it is there.
nvme-fc runs the initial connect synchronously via flush_delayed_work(),
and the controller has to be reachable on rport->ctrl_list for the whole
of it: nvme_fc_unregister_remoteport() needs to find it to signal
connectivity loss, nvme_fc_match_disconn_ls() matches an incoming
Disconnect Association LS against ctrl->association_id, which is only
assigned during that window, nvme_fc_resume_controller() needs it on
remoteport re-registration, and nvme_fc_existing_controller() uses it to
reject a duplicate connect racing the one in flight.

Keep the insertion where it is and add a fail_unlist: label, falling
into fail_ctrl:, for the error paths that run after it.  The earlier
error paths never reach the insertion and keep using fail_ctrl:
directly, so the list is only touched where the controller is actually
on it.

nvme_fc_ctrl_free() cannot use the plain "goto free_ctrl" the other
transports use, because it still has to put_device(), release the rport
reference and free the ida entry for resources taken before the
insertion.  Sample list_empty() under rport->lock instead.

ctrl->ctrl.opts also stays valid for the whole teardown now.  That is
not the bug being fixed, but it removes some fragility around the old
idiom: nvme_free_ctrl() calls nvme_auth_free() before ->free_ctrl(), and
ctrl_max_dhchaps() dereferences ctrl->opts without a NULL check when
ctrl->dhchap_ctxs is set, which nvme-fc permits since NVMF_ALLOWED_OPTS
allows the dhchap options.  The nvme sysfs attributes that dereference
ctrl->opts, such as hostnqn and address, evaluate their is_visible()
test once at device_add() time and stay readable until
cdev_device_del().

Fixes: 1a9e218195a5 ("nvme: split device add from initialization")
Cc: stable@vger.kernel.org
Reported-by: syzbot+f58e57380a6083c4041d@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=f58e57380a6083c4041d
Signed-off-by: Niklas Cassel <cassel@kernel.org>
Tested-by: Rihyeon Kim <rihyeon8648@gmail.com>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Signed-off-by: Keith Busch <kbusch@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/nvme/host/fc.c |   26 ++++++++++++++++++++------
 1 file changed, 20 insertions(+), 6 deletions(-)

--- a/drivers/nvme/host/fc.c
+++ b/drivers/nvme/host/fc.c
@@ -2358,9 +2358,15 @@ nvme_fc_ctrl_free(struct kref *ref)
 	struct nvme_fc_ctrl *ctrl =
 		container_of(ref, struct nvme_fc_ctrl, ref);
 	unsigned long flags;
+	bool owns_opts;
 
-	/* remove from rport list */
+	/*
+	 * Presence on the rport list means nvme_fc_init_ctrl() completed,
+	 * and with it ownership of the fabrics options passed to it. If it
+	 * failed instead, the options still belong to nvmf_create_ctrl().
+	 */
 	spin_lock_irqsave(&ctrl->rport->lock, flags);
+	owns_opts = !list_empty(&ctrl->ctrl_list);
 	list_del(&ctrl->ctrl_list);
 	spin_unlock_irqrestore(&ctrl->rport->lock, flags);
 
@@ -2370,7 +2376,7 @@ nvme_fc_ctrl_free(struct kref *ref)
 	nvme_fc_rport_put(ctrl->rport);
 
 	ida_free(&nvme_fc_ctrl_cnt, ctrl->cnum);
-	if (ctrl->ctrl.opts)
+	if (owns_opts)
 		nvmf_free_options(ctrl->ctrl.opts);
 	kfree(ctrl);
 }
@@ -3569,14 +3575,14 @@ nvme_fc_init_ctrl(struct device *dev, st
 	if (!nvme_change_ctrl_state(&ctrl->ctrl, NVME_CTRL_CONNECTING)) {
 		dev_err(ctrl->ctrl.device,
 			"NVME-FC{%d}: failed to init ctrl state\n", ctrl->cnum);
-		goto fail_ctrl;
+		goto fail_unlist;
 	}
 
 	if (!queue_delayed_work(nvme_wq, &ctrl->connect_work, 0)) {
 		dev_err(ctrl->ctrl.device,
 			"NVME-FC{%d}: failed to schedule initial connect\n",
 			ctrl->cnum);
-		goto fail_ctrl;
+		goto fail_unlist;
 	}
 
 	flush_delayed_work(&ctrl->connect_work);
@@ -3587,14 +3593,22 @@ nvme_fc_init_ctrl(struct device *dev, st
 
 	return &ctrl->ctrl;
 
+fail_unlist:
+	/*
+	 * Leaving the list hands the options back to nvmf_create_ctrl();
+	 * see nvme_fc_ctrl_free().  Re-init so that list_empty() there
+	 * reports the controller as unlisted.
+	 */
+	spin_lock_irqsave(&rport->lock, flags);
+	list_del_init(&ctrl->ctrl_list);
+	spin_unlock_irqrestore(&rport->lock, flags);
+
 fail_ctrl:
 	nvme_change_ctrl_state(&ctrl->ctrl, NVME_CTRL_DELETING);
 	cancel_work_sync(&ctrl->ioerr_work);
 	cancel_work_sync(&ctrl->ctrl.reset_work);
 	cancel_delayed_work_sync(&ctrl->connect_work);
 
-	ctrl->ctrl.opts = NULL;
-
 	if (ctrl->ctrl.admin_tagset)
 		nvme_remove_admin_tag_set(&ctrl->ctrl);
 	/* initiate nvme ctrl ref counting teardown */



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 158/556] nvme-tcp: check the data direction of a C2HData PDU
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (156 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 157/556] nvme-fc: fix double free of fabrics options when nvme_add_ctrl() fails Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 159/556] nvme: add missing SRCU grace period in error path Greg Kroah-Hartman
                   ` (410 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Christoph Hellwig, Yehyeong Lee,
	Keith Busch

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yehyeong Lee <yhlee@isslab.korea.ac.kr>

commit f83af377c148f6ad94b41c0e8313f12adf45e1c1 upstream.

nvme_tcp_handle_c2h_data() finds the request by command id and checks
that it has a payload, but it does not check that the command asked for
data to be read.  A controller that answers a write command with C2HData
therefore reaches nvme_tcp_recv_data(), where _copy_to_iter() hits
WARN_ON_ONCE(i->data_source) and returns 0.  The receive path turns that
into -EFAULT and resets the controller.

No data is copied, so this is not memory corruption.  What a controller
gets is a kernel warning it can raise at will, which is fatal on a host
booted with panic_on_warn.

The send path already knows the direction - it consults rq_data_dir()
when it builds a command - and nvme_tcp_handle_r2t() checks the length
and the offset of the request it names.  The C2HData path does not check
the direction at all.

Reject a C2HData PDU whose command is not a read.  Rejecting it fails
the command and resets the controller, as the neighbouring check in this
function does; what goes away is the warning.

  [    6.885580] ------------[ cut here ]------------
  [    6.886457] WARNING: lib/iov_iter.c:193 at _copy_to_iter+0x289/0x1330, CPU#0: kworker/0:1H/71
  [    6.888137] CPU: 0 UID: 0 PID: 71 Comm: kworker/0:1H Not tainted 7.2.0-rc5-NVMETCP-gf5098b6bae76 #1 PREEMPT(lazy)
  [    6.891165] Workqueue: nvme_tcp_wq nvme_tcp_io_work
  [    6.891875] RIP: 0010:_copy_to_iter+0x289/0x1330
  [    6.903739] Call Trace:
  [    6.904085]  <TASK>
  [    6.909254]  __skb_datagram_iter+0x433/0x820
  [    6.911026]  skb_copy_datagram_iter+0x37/0x120
  [    6.911622]  nvme_tcp_recv_skb+0xa07/0x4320
  [    6.913378]  __tcp_read_sock+0x1ab/0x810
  [    6.915788]  nvme_tcp_try_recv+0x152/0x1e0
  [    6.918222]  nvme_tcp_io_work+0x1e4/0x6c0
  [    6.926906]  </TASK>
  [    6.927226] ---[ end trace 0000000000000000 ]---
  [    6.927878] nvme nvme0: queue 1 failed to copy request 0x71 data
  [    6.928709] nvme nvme0: receive failed:  -14

Fixes: 3f2304f8c6d6 ("nvme-tcp: add NVMe over TCP host driver")
Cc: stable@vger.kernel.org
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
Signed-off-by: Keith Busch <kbusch@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/nvme/host/tcp.c |    7 +++++++
 1 file changed, 7 insertions(+)

--- a/drivers/nvme/host/tcp.c
+++ b/drivers/nvme/host/tcp.c
@@ -682,6 +682,13 @@ static int nvme_tcp_handle_c2h_data(stru
 		return -ENOENT;
 	}
 
+	if (rq_data_dir(rq) != READ) {
+		dev_err(queue->ctrl->ctrl.device,
+			"queue %d tag %#x unexpected data for a write\n",
+			nvme_tcp_queue_id(queue), rq->tag);
+		return -EIO;
+	}
+
 	req = blk_mq_rq_to_pdu(rq);
 	if (!blk_rq_payload_bytes(rq) || !req->curr_bio || !req->data_len) {
 		dev_err(queue->ctrl->ctrl.device,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 159/556] nvme: add missing SRCU grace period in error path
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (157 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 158/556] nvme-tcp: check the data direction of a C2HData PDU Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 160/556] nvme: skip the zoned limits update if the zone info query failed Greg Kroah-Hartman
                   ` (409 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Tristan Madani, Sagi Grimberg,
	John Garry, Christoph Hellwig, Keith Busch

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tristan Madani <tristan@talencesecurity.com>

commit ef248d5de4469fb6bbaf8dbe0c4c47800080d648 upstream.

nvme_alloc_ns() error path at out_unlink_ns removes ns from the
namespace head siblings list with list_del_rcu(&ns->siblings) but
does not wait for SRCU readers before freeing the namespace struct.
Multipath code iterates the head->list under srcu_read_lock() in
nvme_find_path() and nvme_mpath_revalidate_paths(), so a concurrent
reader can still hold a reference to ns when kfree(ns) runs.

The normal removal path in nvme_ns_remove() correctly calls
synchronize_srcu(&ns->head->srcu) after list_del_rcu() to wait for
in-progress readers. Add the same grace period in the error path.

Fixes: ed754e5deeb1 ("nvme: track shared namespaces")
Cc: stable@vger.kernel.org
Signed-off-by: Tristan Madani <tristan@talencesecurity.com>
Reviewed-by: Sagi Grimberg <sagi@grimberg.me>
Reviewed-by: John Garry <john.g.garry@oracle.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Keith Busch <kbusch@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/nvme/host/core.c |    3 +++
 1 file changed, 3 insertions(+)

--- a/drivers/nvme/host/core.c
+++ b/drivers/nvme/host/core.c
@@ -4295,6 +4295,9 @@ static void nvme_alloc_ns(struct nvme_ct
 			last_path = true;
 	}
 	mutex_unlock(&ctrl->subsys->lock);
+
+	/* guarantee not available in head->list */
+	synchronize_srcu(&ns->head->srcu);
 	if (last_path)
 		nvme_put_ns_head(ns->head);
 	nvme_put_ns_head(ns->head);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 160/556] nvme: skip the zoned limits update if the zone info query failed
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (158 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 159/556] nvme: add missing SRCU grace period in error path Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 161/556] nvmet-auth: Synchronize timeout work during SQ teardown Greg Kroah-Hartman
                   ` (408 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Weidong Zhu, Keith Busch,
	Christoph Hellwig, Chao Shi

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chao Shi <coshi036@gmail.com>

commit 3838e80fcfb32e62baffb63c6dc0a60153665a4d upstream.

nvme_query_zone_info() returns either a negative errno or a positive
NVMe status code, but nvme_update_ns_info_block() only tests for the
negative case:

	ret = nvme_query_zone_info(ns, lbaf, &zi);
	if (ret < 0)
		goto out;

If the device fails the Identify Namespace (I/O Command Set specific)
command, or the Identify Controller command issued by
nvme_set_max_append(), the positive status falls through and setup
continues with the zero-initialized zone info.  nvme_update_zone_info()
then marks the queue zoned with chunk_sectors and ns->head->zsze set to
zero.

blk_validate_zoned_limits() does not check chunk_sectors, so the limits
commit succeeds.  blk_revalidate_disk_zones() does reject the zero zone
size, but by then the limits are live and nothing rolls them back, so
I/O keeps being submitted to a zoned queue with a zero zone size and
disk_zone_no() shifts by ilog2(0):

  nvme0n1: Invalid non power of two zone size (0)
  UBSAN: shift-out-of-bounds in include/linux/blkdev.h:747:16
  shift exponent -1 is negative
   disk_zone_no include/linux/blkdev.h:747 [inline]
   bio_straddles_zones include/linux/blkdev.h:1058 [inline]
   blk_zone_wplug_handle_write block/blk-zoned.c:1423 [inline]
   blk_zone_plug_bio.cold+0x25/0x1c8 block/blk-zoned.c:1605
   blk_mq_submit_bio+0x18fb/0x2870 block/blk-mq.c:3196
   submit_bh_wbc+0x575/0x740 fs/buffer.c:2824
   __block_write_full_folio+0x728/0xdd0 fs/buffer.c:1933

Any device, firmware or NVMe-oF target that fails this one command
reaches this.

Skip the zoned limits update in that case, and log which of the two
things happened: during a revalidation the queue keeps the zone
geometry it was last validated with, and on a first scan the namespace
is registered without zoned limits, so that it is still available as a
handle for admin commands.  Neither of the paths in
nvme_query_zone_info() that return a positive status logs anything, so
the failure would otherwise be silent.

zi.zone_size is an exact indicator: every path that returns a positive
status returns before it is assigned, and after that the only failure
left is -ENODEV, which the caller already handles.

Found by FuzzNvme.
Fixes: c85c9ab926a5 ("nvme: split nvme_update_zone_info")
Cc: stable@vger.kernel.org
Cc: Weidong Zhu <weizhu@fiu.edu>
Suggested-by: Keith Busch <kbusch@kernel.org>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Chao Shi <coshi036@gmail.com>
Signed-off-by: Keith Busch <kbusch@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/nvme/host/core.c |   21 +++++++++++++++++++--
 1 file changed, 19 insertions(+), 2 deletions(-)

--- a/drivers/nvme/host/core.c
+++ b/drivers/nvme/host/core.c
@@ -2447,9 +2447,26 @@ static int nvme_update_ns_info_block(str
 	if (!nvme_update_disk_info(ns, id, nvm, &lim))
 		capacity = 0;
 
+	/*
+	 * A failed zone info query leaves zi zero-initialized, so skip the
+	 * zoned limits update instead of configuring the queue from it.
+	 * During a revalidation that keeps the zone geometry the queue was
+	 * last validated with; on a first scan the namespace is registered
+	 * without zoned limits, so that it is still available as a handle
+	 * for admin commands.
+	 */
 	if (IS_ENABLED(CONFIG_BLK_DEV_ZONED) &&
-	    ns->head->ids.csi == NVME_CSI_ZNS)
-		nvme_update_zone_info(ns, &lim, &zi);
+	    ns->head->ids.csi == NVME_CSI_ZNS) {
+		if (zi.zone_size)
+			nvme_update_zone_info(ns, &lim, &zi);
+		else
+			dev_warn(ns->ctrl->device,
+				 "zone info query failed for nsid %u, %s\n",
+				 ns->head->ns_id,
+				 blk_queue_is_zoned(ns->disk->queue) ?
+				 "keeping the previous zone limits" :
+				 "not enabling zoned mode");
+	}
 
 	if ((ns->ctrl->vwc & NVME_CTRL_VWC_PRESENT) && !info->no_vwc)
 		lim.features |= BLK_FEAT_WRITE_CACHE | BLK_FEAT_FUA;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 161/556] nvmet-auth: Synchronize timeout work during SQ teardown
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (159 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 160/556] nvme: skip the zoned limits update if the zone info query failed Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 162/556] nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU Greg Kroah-Hartman
                   ` (407 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Kazuki Hanai, Sagi Grimberg,
	Christoph Hellwig, Keith Busch

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Kazuki Hanai <hnkz.64@gmail.com>

commit eaa948c0e19b1bb2d93262207bca0c3d19cc3406 upstream.

nvmet_auth_sq_free() cancels auth_expired_work with
cancel_delayed_work(). If the work has already started, cancellation does
not wait for the callback. Transport teardown can consequently free or
reuse the queue containing struct nvmet_sq while
nvmet_auth_expired_work() still accesses that SQ.

Add a teardown-specific helper that synchronously drains the delayed work
before freeing authentication state, and use it from nvmet_sq_destroy().
Keep the non-synchronous helper for in-band authentication state cleanup,
where the SQ owner remains alive.

Fixes: 1a70200f404a ("nvmet-auth: expire authentication sessions")
Cc: stable@vger.kernel.org
Signed-off-by: Kazuki Hanai <hnkz.64@gmail.com>
Reviewed-by: Sagi Grimberg <sagi@grimberg.me>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Keith Busch <kbusch@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/nvme/target/auth.c  |    6 ++++++
 drivers/nvme/target/core.c  |    2 +-
 drivers/nvme/target/nvmet.h |    2 ++
 3 files changed, 9 insertions(+), 1 deletion(-)

--- a/drivers/nvme/target/auth.c
+++ b/drivers/nvme/target/auth.c
@@ -238,6 +238,12 @@ void nvmet_auth_sq_free(struct nvmet_sq
 	sq->dhchap_skey = NULL;
 }
 
+void nvmet_auth_sq_destroy(struct nvmet_sq *sq)
+{
+	cancel_delayed_work_sync(&sq->auth_expired_work);
+	nvmet_auth_sq_free(sq);
+}
+
 void nvmet_destroy_auth(struct nvmet_ctrl *ctrl)
 {
 	ctrl->shash_id = 0;
--- a/drivers/nvme/target/core.c
+++ b/drivers/nvme/target/core.c
@@ -977,7 +977,7 @@ void nvmet_sq_destroy(struct nvmet_sq *s
 	wait_for_completion(&sq->confirm_done);
 	wait_for_completion(&sq->free_done);
 	percpu_ref_exit(&sq->ref);
-	nvmet_auth_sq_free(sq);
+	nvmet_auth_sq_destroy(sq);
 	nvmet_cq_put(sq->cq);
 
 	/*
--- a/drivers/nvme/target/nvmet.h
+++ b/drivers/nvme/target/nvmet.h
@@ -915,6 +915,7 @@ u8 nvmet_setup_auth(struct nvmet_ctrl *c
 void nvmet_auth_sq_init(struct nvmet_sq *sq);
 void nvmet_destroy_auth(struct nvmet_ctrl *ctrl);
 void nvmet_auth_sq_free(struct nvmet_sq *sq);
+void nvmet_auth_sq_destroy(struct nvmet_sq *sq);
 int nvmet_setup_dhgroup(struct nvmet_ctrl *ctrl, u8 dhgroup_id);
 bool nvmet_check_auth_status(struct nvmet_req *req);
 int nvmet_auth_host_hash(struct nvmet_req *req, u8 *response,
@@ -941,6 +942,7 @@ static inline void nvmet_auth_sq_init(st
 }
 static inline void nvmet_destroy_auth(struct nvmet_ctrl *ctrl) {};
 static inline void nvmet_auth_sq_free(struct nvmet_sq *sq) {};
+static inline void nvmet_auth_sq_destroy(struct nvmet_sq *sq) {};
 static inline bool nvmet_check_auth_status(struct nvmet_req *req)
 {
 	return true;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 162/556] nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (160 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 161/556] nvmet-auth: Synchronize timeout work during SQ teardown Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 163/556] nvmet-tcp: reject unsolicited H2CData PDUs Greg Kroah-Hartman
                   ` (406 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Shivam Kumar, Sagi Grimberg,
	Keith Busch

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Shivam Kumar <kumar.shivam43666@gmail.com>

commit 14cc5a7e77731497d5bea70f3bb05df7eda982e4 upstream.

nvmet_tcp_try_recv_pdu() reads a PDU header into the fixed 128-byte
queue->pdu union, then computes the remaining payload length as

	queue->left = hdr->hlen - queue->offset + hdgst;

and reads that many more bytes into &queue->pdu + queue->offset, without
ever bounding the result against sizeof(queue->pdu).

A struct nvme_tcp_icreq_pdu is itself 128 bytes, exactly the size of the
union. Once a header digest has been negotiated (hdgst = 4), a second
ICReq passes the hlen == nvmet_tcp_pdu_size() check but yields
queue->left = 128 - 8 + 4 = 124, so bytes 8..132 are written into the
128-byte buffer -- 4 bytes past its end, over queue->hdr_digest and
queue->data_digest. Those bytes are attacker-controlled (an ICReq
carries no digest), and the duplicate ICReq is only rejected later,
after the overflow. A remote unauthenticated host can thus corrupt
kernel memory adjacent to the receive buffer.

Reject any PDU whose declared length would read past the end of
queue->pdu before the second recv.

Fixes: 872d26a391da ("nvmet-tcp: add NVMe over TCP target driver")
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Shivam Kumar <kumar.shivam43666@gmail.com>
Cc: stable@vger.kernel.org
Reviewed-by: Sagi Grimberg <sagi@grimberg.me>
Signed-off-by: Keith Busch <kbusch@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/nvme/target/tcp.c |    2 ++
 1 file changed, 2 insertions(+)

--- a/drivers/nvme/target/tcp.c
+++ b/drivers/nvme/target/tcp.c
@@ -1244,6 +1244,8 @@ recv:
 		}
 
 		queue->left = hdr->hlen - queue->offset + hdgst;
+		if (queue->left > sizeof(queue->pdu) - queue->offset)
+			return -EPROTO;
 		goto recv;
 	}
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 163/556] nvmet-tcp: reject unsolicited H2CData PDUs
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (161 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 162/556] nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 164/556] pmdomain: airoha: fix unselectable AIROHA_CPU_PM_DOMAIN kconfig Greg Kroah-Hartman
                   ` (405 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sagi Grimberg, Shivam Kumar,
	Keith Busch

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Shivam Kumar <kumar.shivam43666@gmail.com>

commit db62b35cbca052860c519cbcabe7650708528738 upstream.

nvmet_tcp_handle_h2c_data_pdu() accepts an H2CData PDU after only checking
that its TTAG is a valid in-range command index and that the command's
data buffers are mapped. It never checks that the target has actually
solicited that data by sending an R2T for the command.

A remote host can abuse this. It submits a write command that takes the
R2T path and, before the target transmits the R2T, sends an H2CData PDU
for that command's tag. The data completes the command early, and when
the command then fails synchronously (e.g. a length mismatch caught by
nvmet_check_transfer_len()), it is completed a second time. Each
completion calls nvmet_tcp_queue_response(), so the same command is added
to queue->resp_list twice while it is still linked; the second llist_add()
makes the node point to itself (lentry->next == lentry).

nvmet_tcp_process_resp_list() then walks that self-referential node and
adds the command to resp_send_list twice. With CONFIG_DEBUG_LIST this
trips the "list_add double add" check (kernel BUG); without it the loop
never terminates and the nvmet_tcp workqueue wedges (soft-lockup). It is
remotely triggerable and needs no authentication on an allow_any_host
subsystem.

Track whether an R2T has been transmitted for a command and reject an
H2CData PDU that arrives before it. The flag is cleared on command reuse
(nvmet_tcp_get_cmd() zeroes cmd->flags) and stays set across the multiple
H2CData PDUs of a single solicited transfer.

Fixes: 872d26a391da ("nvmet-tcp: add NVMe over TCP target driver")
Cc: stable@vger.kernel.org
Reviewed-by: Sagi Grimberg <sagi@grimberg.me>
Signed-off-by: Shivam Kumar <kumar.shivam43666@gmail.com>
Signed-off-by: Keith Busch <kbusch@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/nvme/target/tcp.c |    8 ++++++++
 1 file changed, 8 insertions(+)

--- a/drivers/nvme/target/tcp.c
+++ b/drivers/nvme/target/tcp.c
@@ -103,6 +103,7 @@ enum nvmet_tcp_recv_state {
 
 enum {
 	NVMET_TCP_F_INIT_FAILED = (1 << 0),
+	NVMET_TCP_F_R2T_SENT	= (1 << 1),
 };
 
 struct nvmet_tcp_cmd {
@@ -776,6 +777,7 @@ static int nvmet_try_send_r2t(struct nvm
 		return -EAGAIN;
 
 	cmd->queue->snd_cmd = NULL;
+	cmd->flags |= NVMET_TCP_F_R2T_SENT;
 	return 1;
 }
 
@@ -1009,6 +1011,12 @@ static int nvmet_tcp_handle_h2c_data_pdu
 		cmd = &queue->connect;
 	}
 
+	if (unlikely(!(cmd->flags & NVMET_TCP_F_R2T_SENT))) {
+		pr_err("queue %d: unsolicited H2CData (ttag %u)\n",
+		       queue->idx, data->ttag);
+		goto err_proto;
+	}
+
 	if (le32_to_cpu(data->data_offset) != cmd->rbytes_done) {
 		pr_err("ttag %u unexpected data offset %u (expected %u)\n",
 			data->ttag, le32_to_cpu(data->data_offset),



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 164/556] pmdomain: airoha: fix unselectable AIROHA_CPU_PM_DOMAIN kconfig
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (162 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 163/556] nvmet-tcp: reject unsolicited H2CData PDUs Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 165/556] Revert "irqchip/mbigen: Fix mbigen node address layout" Greg Kroah-Hartman
                   ` (404 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Christian Marangi, Abel Vesa,
	Ulf Hansson

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christian Marangi <ansuelsmth@gmail.com>

commit 6d94c47a2e3a38170a0a141547e4c52fbe232cc3 upstream.

The AIROHA_CPU_PM_DOMAIN config was wrongly guarded under the Mediatek PM
Domains menu and was unselectable.

Move it outside the menu so it's now visible and correctly selectable by
default on Airoha SoC.

Cc: stable@vger.kernel.org
Fixes: 82e703dd438b ("pmdomain: airoha: Add Airoha CPU PM Domain support")
Signed-off-by: Christian Marangi <ansuelsmth@gmail.com>
Reviewed-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/pmdomain/mediatek/Kconfig |    5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

--- a/drivers/pmdomain/mediatek/Kconfig
+++ b/drivers/pmdomain/mediatek/Kconfig
@@ -43,9 +43,12 @@ config MTK_MFG_PM_DOMAIN
 	  This driver is required for the Mali GPU to work at all on MT8196 and
 	  MT6991.
 
+endmenu
+
 config AIROHA_CPU_PM_DOMAIN
 	tristate "Airoha CPU power domain"
 	default ARCH_AIROHA
+	depends on ARCH_AIROHA || COMPILE_TEST
 	depends on HAVE_ARM_SMCCC
 	depends on PM
 	select PM_GENERIC_DOMAINS
@@ -54,5 +57,3 @@ config AIROHA_CPU_PM_DOMAIN
 
 	  CPU frequency and power is controlled by ATF with SMC command to
 	  set performance states.
-
-endmenu



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 165/556] Revert "irqchip/mbigen: Fix mbigen node address layout"
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (163 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 164/556] pmdomain: airoha: fix unselectable AIROHA_CPU_PM_DOMAIN kconfig Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 166/556] Revert "once: dont use a work queue to reset sleepable static key" Greg Kroah-Hartman
                   ` (403 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Marc Zyngier, caina, Thomas Gleixner,
	Yipeng Zou

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: caina <caina@uniontech.com>

commit e67091609cf85962f64391c1b0f93d4cbfcd4e22 upstream.

This reverts commit 6be6cba9c4371d27f78d900ccfe34bb880d9ee20.

Commit 6be6cba9c437 ("irqchip/mbigen: Fix mbigen node address layout")
appears to cause a regression on Hi1616.

On-board hns NIC has two ports, enahisic2i0 and enahisic2i1, both
behind mbigen-v2.  Port 0 works; port 1 cannot pass any traffic.

Their interrupt pins fall on different mbigen nodes:

  enahisic2i0: pins 1152-1198 -> all in node 9
  enahisic2i1: pins 1200-1246 -> node 9 (1200-1215) + node 10 (1216-1246)

  (nid = (hwirq - 64) / 128 + 1; pin 1215 = node 9, pin 1216 = node 10)

/proc/interrupts shows the break happens exactly at the node boundary:

  enahisic2i1-rx0  pin 1200  count 102   <- node 9
  enahisic2i1-rx5  pin 1215  count   1   <- node 9, last pin
  enahisic2i1-tx5  pin 1216  count   0   <- node 10, first pin
  enahisic2i1-rx6  pin 1218  count   0   <- node 10
  ...all node 10 pins stay at zero.

Port 0 (entirely node 9) is unaffected.  Reverting the commit restores
normal operation.

The commit assumes CLEAR occupies a full 4 KB page at [0xa000, 0xb000)
and collides with node 10, so node 10+ gets shifted by 0x1000.

But get_mbigen_clear_reg() uses flat, chip-wide addressing -- it never
multiplies by the node ID:

    *addr = (hwirq / 32) * 4 + REG_MBIGEN_CLEAR_OFFSET;  /* 0xa000 */

Over the valid hwirq range [64, 1407], CLEAR only spans 0xa008-0xa0af
(168 bytes).  Node 10's registers are:

    TYPE: 0xa000-0xa00f  (16 B)   overlaps CLEAR by 8 B (0xa008-0xa00f)
    VEC:  0xa200-0xa3ff  (512 B)  no overlap with CLEAR

Shifting the whole page moves VEC from 0xa200 to 0xb200.  The hardware
reads the event ID from the fixed silicon address 0xa200 on interrupt
firing, but software wrote it to 0xb200 -- so the hardware gets an
uninitialised value and the interrupt is lost.

The only real overlap is 8 bytes of TYPE.  It can only trigger when a
single mbigen instance has devices on both node 1 (CLEAR 0xa008) and
node 10 (TYPE 0xa008).  On Hi1616 those nodes are on separate mbigen
instances, so it never triggers.

Fixes: 6be6cba9c4371d27f78d900ccfe34bb880d9ee20 ("irqchip/mbigen: Fix mbigen node address layout")
Suggested-by: Marc Zyngier <maz@kernel.org>
Signed-off-by: caina <caina@uniontech.com>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Acked-by: Yipeng Zou <zouyipeng@huawei.com>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260821091720.16665-1-caina@uniontech.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/irqchip/irq-mbigen.c |   20 ++++----------------
 1 file changed, 4 insertions(+), 16 deletions(-)

--- a/drivers/irqchip/irq-mbigen.c
+++ b/drivers/irqchip/irq-mbigen.c
@@ -64,20 +64,6 @@ struct mbigen_device {
 	void __iomem		*base;
 };
 
-static inline unsigned int get_mbigen_node_offset(unsigned int nid)
-{
-	unsigned int offset = nid * MBIGEN_NODE_OFFSET;
-
-	/*
-	 * To avoid touched clear register in unexpected way, we need to directly
-	 * skip clear register when access to more than 10 mbigen nodes.
-	 */
-	if (nid >= (REG_MBIGEN_CLEAR_OFFSET / MBIGEN_NODE_OFFSET))
-		offset += MBIGEN_NODE_OFFSET;
-
-	return offset;
-}
-
 static inline unsigned int get_mbigen_vec_reg(irq_hw_number_t hwirq)
 {
 	unsigned int nid, pin;
@@ -86,7 +72,8 @@ static inline unsigned int get_mbigen_ve
 	nid = hwirq / IRQS_PER_MBIGEN_NODE + 1;
 	pin = hwirq % IRQS_PER_MBIGEN_NODE;
 
-	return pin * 4 + get_mbigen_node_offset(nid) + REG_MBIGEN_VEC_OFFSET;
+	return pin * 4 + nid * MBIGEN_NODE_OFFSET
+			+ REG_MBIGEN_VEC_OFFSET;
 }
 
 static inline void get_mbigen_type_reg(irq_hw_number_t hwirq,
@@ -101,7 +88,8 @@ static inline void get_mbigen_type_reg(i
 	*mask = 1 << (irq_ofst % 32);
 	ofst = irq_ofst / 32 * 4;
 
-	*addr = ofst + get_mbigen_node_offset(nid) + REG_MBIGEN_TYPE_OFFSET;
+	*addr = ofst + nid * MBIGEN_NODE_OFFSET
+		+ REG_MBIGEN_TYPE_OFFSET;
 }
 
 static inline void get_mbigen_clear_reg(irq_hw_number_t hwirq,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 166/556] Revert "once: dont use a work queue to reset sleepable static key"
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (164 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 165/556] Revert "irqchip/mbigen: Fix mbigen node address layout" Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 167/556] Revert "pmdomain: qcom: rpmhpd: Add missing MXC and MMCX power domains for Eliza" Greg Kroah-Hartman
                   ` (402 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Eric Dumazet, Shinichiro Kawasaki,
	Tony Luck, Reinette Chatre, Keith Busch, Nilay Shroff,
	Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eric Dumazet <edumazet@google.com>

commit 0ba6912f7e974045dcdd170f022cba19247e00bc upstream.

This reverts commit e8eef69a99f185e75909adb24ab93d706e07bf27.

While DO_ONCE_SLEEPABLE() is used from sleepable/process context, callers
may still be holding arbitrary subsystem locks.

For instance, __inet_hash_connect() uses get_random_sleepable_once() which
invokes DO_ONCE_SLEEPABLE() while holding the socket lock (sk_lock):

  lock_sock(sk)
    __inet_hash_connect()
      get_random_sleepable_once()
        DO_ONCE_SLEEPABLE()
          __do_once_sleepable_done()
            static_branch_disable()
              static_key_disable()
                cpus_read_lock()

Calling static_branch_disable() directly from __do_once_sleepable_done()
causes static_key_disable() to synchronously acquire cpus_read_lock()
(cpu_hotplug_lock) and jump_label_mutex inside the caller's lock context.

This introduces an unwanted lockdep dependency:
  sk_lock -> cpu_hotplug_lock

Because cpu_hotplug_lock depends on fs_reclaim (via workqueue CPU bringup
allocating memory with GFP_KERNEL), and storage/block layers (such as
NVMe-TCP) acquire sk_lock during I/O dispatch, lockdep reports circular
locking dependencies:

  set->srcu -> sk_lock -> cpu_hotplug_lock -> fs_reclaim -> q_usage_counter -> elevator_lock -> set->srcu

This false positive previously prompted commit 19bdb70c77d3 ("nvme-tcp:
lockdep: use dynamic lockdep keys per socket instance") to work around the
warning using per-socket dynamic keys in NVMe-TCP.  That in turn broke
asynchronous socket teardown and caused syzbot warnings in
tcp_tsq_handler().

Restoring once_disable_jump() in __do_once_sleepable_done() ensures that
static_branch_disable() is executed asynchronously from a system workqueue
without holding the caller's locks.

Link: https://lore.kernel.org/20260825142515.1965654-1-edumazet@google.com
Fixes: e8eef69a99f1 ("once: don't use a work queue to reset sleepable static key")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Closes: https://lore.kernel.org/lkml/ao0mwtt8ePAINFni@shinhome/
Reported-by: Shin'ichiro Kawasaki <shinichiro.kawasaki@wdc.com>
Cc: Tony Luck <tony.luck@intel.com>
Cc: Reinette Chatre <reinette.chatre@intel.com>
Cc: Keith Busch <kbusch@kernel.org>
Cc: Nilay Shroff <nilay@linux.ibm.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 lib/once.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/lib/once.c
+++ b/lib/once.c
@@ -93,6 +93,6 @@ void __do_once_sleepable_done(bool *done
 {
 	*done = true;
 	mutex_unlock(&once_mutex);
-	static_branch_disable(once_key);
+	once_disable_jump(once_key, mod);
 }
 EXPORT_SYMBOL(__do_once_sleepable_done);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 167/556] Revert "pmdomain: qcom: rpmhpd: Add missing MXC and MMCX power domains for Eliza"
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (165 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 166/556] Revert "once: dont use a work queue to reset sleepable static key" Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 168/556] mm: fix incorrect vm_flags usage when checking allowable orders for tmpfs Greg Kroah-Hartman
                   ` (401 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Abel Vesa, Ulf Hansson

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Abel Vesa <abel.vesa@oss.qualcomm.com>

commit 9fca7779ad18538188d640b1fdcfea924459542c upstream.

This reverts commit b48a0a0a76ccecec60f0568e2af4d89994b08bec, which
wrongfully added the MXC and MMCX power domains on Eliza.

Even though they are indeed available in cmd-db, which has been the source
of information for adding these two, at hardware level they are not
actually wired up. Therefore they need to be dropped.

Fixes: b48a0a0a76cc ("pmdomain: qcom: rpmhpd: Add missing MXC and MMCX power domains for Eliza")
Signed-off-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
Cc: stable@vger.kernel.org
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/pmdomain/qcom/rpmhpd.c |    4 ----
 1 file changed, 4 deletions(-)

--- a/drivers/pmdomain/qcom/rpmhpd.c
+++ b/drivers/pmdomain/qcom/rpmhpd.c
@@ -245,13 +245,9 @@ static struct rpmhpd *eliza_rpmhpds[] =
 	[RPMHPD_GFX] = &gfx,
 	[RPMHPD_LCX] = &lcx,
 	[RPMHPD_LMX] = &lmx,
-	[RPMHPD_MMCX] = &mmcx,
-	[RPMHPD_MMCX_AO] = &mmcx_ao,
 	[RPMHPD_MSS] = &mss,
 	[RPMHPD_MX] = &mx,
 	[RPMHPD_MX_AO] = &mx_ao,
-	[RPMHPD_MXC] = &mxc,
-	[RPMHPD_MXC_AO] = &mxc_ao,
 	[RPMHPD_NSP] = &nsp,
 };
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 168/556] mm: fix incorrect vm_flags usage when checking allowable orders for tmpfs
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (166 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 167/556] Revert "pmdomain: qcom: rpmhpd: Add missing MXC and MMCX power domains for Eliza" Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 169/556] mm/migrate_device: avoid out-of-bounds writes for compound folios Greg Kroah-Hartman
                   ` (400 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Baolin Wang, Lance Yang,
	Lorenzo Stoakes (ARM), Zi Yan, Barry Song, David Hildenbrand,
	Dev Jain, Hugh Dickins, Liam R. Howlett, Ryan Roberts,
	Vlastimil Babka, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Baolin Wang <baolin.wang@linux.alibaba.com>

commit 2fd4e7693674b17807a6d082feb01a3fbf86f5f8 upstream.

Lance reported that when nothing else causes the mm to be considered for
khugepaged collapse, an MADV_HUGEPAGE-advised tmpfs VMA alone does not
trigger scanning.

After commit 6beeab870e70 ("mm: shmem: move shmem_huge_global_enabled()
into shmem_allowable_huge_orders()"), the shmem/tmpfs allowable order
check reads vma->flags directly.  However, when MADV_HUGEPAGE is handled,
khugepaged_enter_vma() is called before the VMA's flags have been updated,
so the check uses stale flags and incorrectly rejects the VMA for
collapse.  As a result, khugepaged does not collapse the tmpfs file into
PMD order in time.

Fix this by calling khugepaged_enter_vma() with the new VMA flags in
madvise_update_vma().  Meanwhile we can remove the khugepaged_enter_vma()
in hugepage_madvise().

Link: https://lore.kernel.org/7d5b5eb27be798f89d563b06254c947ff53db0b2.1787020910.git.baolin.wang@linux.alibaba.com
Fixes: 6beeab870e70 ("mm: shmem: move shmem_huge_global_enabled() into shmem_allowable_huge_orders()")
Signed-off-by: Baolin Wang <baolin.wang@linux.alibaba.com>
Reported-by: Lance Yang <lance.yang@linux.dev>
Closes: https://lore.kernel.org/all/20260815181632.21453-1-lance.yang@linux.dev/
Suggested-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Reviewed-by: Zi Yan <ziy@nvidia.com>
Reviewed-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Cc: Barry Song <baohua@kernel.org>
Cc: David Hildenbrand <david@kernel.org>
Cc: Dev Jain <dev.jain@arm.com>
Cc: Hugh Dickins <hughd@google.com>
Cc: Lance Yang <lance.yang@linux.dev>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Ryan Roberts <ryan.roberts@arm.com>
Cc: Vlastimil Babka <vbabka@kernel.org>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/khugepaged.c |    6 ------
 mm/madvise.c    |    8 ++++++++
 2 files changed, 8 insertions(+), 6 deletions(-)

--- a/mm/khugepaged.c
+++ b/mm/khugepaged.c
@@ -452,12 +452,6 @@ int hugepage_madvise(struct vm_area_stru
 	case MADV_HUGEPAGE:
 		*vm_flags &= ~VM_NOHUGEPAGE;
 		*vm_flags |= VM_HUGEPAGE;
-		/*
-		 * If the vma become good for khugepaged to scan,
-		 * register it here without waiting a page fault that
-		 * may not happen any time soon.
-		 */
-		khugepaged_enter_vma(vma, *vm_flags);
 		break;
 	case MADV_NOHUGEPAGE:
 		*vm_flags &= ~VM_HUGEPAGE;
--- a/mm/madvise.c
+++ b/mm/madvise.c
@@ -177,6 +177,14 @@ static int madvise_update_vma(vm_flags_t
 	/* vm_flags is protected by the mmap_lock held in write mode. */
 	vma_start_write(vma);
 	vma->flags = new_vma_flags;
+	/*
+	 * If the vma become good for khugepaged to scan,
+	 * register it here without waiting a page fault that
+	 * may not happen any time soon.
+	 */
+	if (vma_flags_test(&new_vma_flags, VMA_HUGEPAGE_BIT))
+		khugepaged_enter_vma(vma, vma_flags_to_legacy(new_vma_flags));
+
 	if (set_new_anon_name)
 		return replace_anon_vma_name(vma, anon_name);
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 169/556] mm/migrate_device: avoid out-of-bounds writes for compound folios
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (167 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 168/556] mm: fix incorrect vm_flags usage when checking allowable orders for tmpfs Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 170/556] mm/hugetlb: fix missing migratable flag on same-node hugetlb migration Greg Kroah-Hartman
                   ` (399 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Hui Su, Alistair Popple,
	Balbir Singh, Byungchul Park, David Hildenbrand, Gregory Price,
	Huang, Ying, Joshua Hahn, Matthew Brost, Rakie Kim, Zi Yan,
	Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Hui Su <sh_def@163.com>

commit dc41e961a269f2ca4196e669d6d8e05480899cd4 upstream.

migrate_device_range() and migrate_device_pfns() clear the entries
following a compound folio so that the PFN arrays retain their
page-granular representation.

If a compound folio extends beyond the end of the caller-provided range,
the loops clear all following folio entries without limiting them to the
number of slots remaining in the npages-sized array, causing an
out-of-bounds write.

Do not proceed with a compound folio if its page-granular representation
does not fit entirely in the remaining PFN array.  If this happens, drop
any reference and lock acquired for the folio, clear the remaining
entries, and stop collecting.

Observed with a KASAN x86 QEMU kernel using the HMM migrate_anon_huge_zero
selftest.  Closing /dev/hmm_dmirror0 after migrating an anonymous huge
page to device memory exercises:

  dmirror_fops_release()
    -> dmirror_device_evict_chunk()
      -> migrate_device_range()

Link: https://lore.kernel.org/20260817120758.669807-3-sh_def@163.com
Fixes: a30b48bf1b24 ("mm/migrate_device: implement THP migration of zone device pages")
Signed-off-by: Hui Su <sh_def@163.com>
Cc: Alistair Popple <apopple@nvidia.com>
Cc: Balbir Singh <balbirs@nvidia.com>
Cc: Byungchul Park <byungchul@sk.com>
Cc: David Hildenbrand <david@kernel.org>
Cc: Gregory Price <gourry@gourry.net>
Cc: "Huang, Ying" <ying.huang@linux.alibaba.com>
Cc: Joshua Hahn <joshua.hahnjy@gmail.com>
Cc: Matthew Brost <matthew.brost@intel.com>
Cc: Rakie Kim <rakie.kim@sk.com>
Cc: Zi Yan <ziy@nvidia.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/migrate_device.c |   18 ++++++++++++++++++
 1 file changed, 18 insertions(+)

--- a/mm/migrate_device.c
+++ b/mm/migrate_device.c
@@ -1413,6 +1413,15 @@ int migrate_device_range(unsigned long *
 
 		src_pfns[i] = migrate_device_pfn_lock(pfn);
 		nr = folio_nr_pages(folio);
+		if (nr > npages - i) {
+			if (src_pfns[i] & MIGRATE_PFN_MIGRATE) {
+				folio_unlock(folio);
+				folio_put(folio);
+			}
+			memset(&src_pfns[i], 0,
+			       (npages - i) * sizeof(*src_pfns));
+			break;
+		}
 		if (nr > 1) {
 			src_pfns[i] |= MIGRATE_PFN_COMPOUND;
 			for (j = 1; j < nr; j++)
@@ -1447,6 +1456,15 @@ int migrate_device_pfns(unsigned long *s
 
 		src_pfns[i] = migrate_device_pfn_lock(src_pfns[i]);
 		nr = folio_nr_pages(folio);
+		if (nr > npages - i) {
+			if (src_pfns[i] & MIGRATE_PFN_MIGRATE) {
+				folio_unlock(folio);
+				folio_put(folio);
+			}
+			memset(&src_pfns[i], 0,
+			       (npages - i) * sizeof(*src_pfns));
+			break;
+		}
 		if (nr > 1) {
 			src_pfns[i] |= MIGRATE_PFN_COMPOUND;
 			for (j = 1; j < nr; j++)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 170/556] mm/hugetlb: fix missing migratable flag on same-node hugetlb migration
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (168 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 169/556] mm/migrate_device: avoid out-of-bounds writes for compound folios Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 171/556] mm/hugetlb_cma: fix null nodemask dereference in hugetlb_cma_alloc_frozen_folio Greg Kroah-Hartman
                   ` (398 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Wupeng Ma, David Hildenbrand (Arm),
	Baolin Wang, Muchun Song, Oscar Salvador, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wupeng Ma <mawupeng1@huawei.com>

commit 8ee1ef0f2f8ce29338f4ab00a3d344c010208058 upstream.

Commit ba23f58de896 ("mm/migrate: don't call
folio_putback_active_hugetlb() on dst hugetlb folio") moved setting of the
migratable flag and active-list placement from
folio_putback_active_hugetlb(dst) into move_hugetlb_state(), so that the
freshly allocated destination folio is handled where allocation is known
to have succeeded.

Unfortunately, the new code was appended after the existing
temporary-folio block in move_hugetlb_state(), which contains an early
return added earlier by commit 5af1ab1d24e08 ("mm/hugetlb: optimize the
surplus state transfer code in move_hugetlb_state()"):

  if (folio_test_hugetlb_temporary(new_folio)) {
      ...
      if (new_nid == old_nid)
          return;                       <-- skips the new code
      ...
  }

  /* added by ba23f58 */
  folio_set_hugetlb_migratable(new_folio);
  list_move_tail(&new_folio->lru, ...&h->hugepage_activelist);

When the destination folio is temporary (i.e.  the hugetlb pool was
exhausted and the migration callback fell back to
alloc_migrate_hugetlb_folio()) and the migration does not cross a node --
the common case, and always true on a single-NUMA system --
move_hugetlb_state() returns before setting the migratable flag or adding
the new folio to the active list.  The destination folio is then installed
in the page table but cannot be isolated afterwards, since
folio_isolate_hugetlb() rejects folios without the migratable flag; a
subsequent soft-offline, hard-offline or memory-hotplug offline of that
folio fails with -EBUSY.

This was reproduced on a single-NUMA arm64 VM: a second MADV_SOFT_OFFLINE
on an already-migrated hugetlb page returned EBUSY and logged "hugepage
isolation failed".

Keep the surplus adjustment, which is the only part that depends on the
node crossing, guarded by `if (new_nid != old_nid)', while making the
migratable flag and active-list placement unconditional.  This preserves
the cleanup intent of ba23f58 and closes the early-return hole.

Link: https://lore.kernel.org/20260707110254.3147686-1-mawupeng1@huawei.com
Fixes: ba23f58de896 ("mm/migrate: don't call folio_putback_active_hugetlb() on dst hugetlb folio")
Signed-off-by: Wupeng Ma <mawupeng1@huawei.com>
Acked-by: David Hildenbrand (Arm) <david@kernel.org>
Cc: Baolin Wang <baolin.wang@linux.alibaba.com>
Cc: Muchun Song <muchun.song@linux.dev>
Cc: Oscar Salvador <osalvador@suse.de>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/hugetlb.c |   14 +++++++-------
 1 file changed, 7 insertions(+), 7 deletions(-)

--- a/mm/hugetlb.c
+++ b/mm/hugetlb.c
@@ -7243,14 +7243,14 @@ void move_hugetlb_state(struct folio *ol
 		 * There is no need to transfer the per-node surplus state
 		 * when we do not cross the node.
 		 */
-		if (new_nid == old_nid)
-			return;
-		spin_lock_irq(&hugetlb_lock);
-		if (h->surplus_huge_pages_node[old_nid]) {
-			h->surplus_huge_pages_node[old_nid]--;
-			h->surplus_huge_pages_node[new_nid]++;
+		if (new_nid != old_nid) {
+			spin_lock_irq(&hugetlb_lock);
+			if (h->surplus_huge_pages_node[old_nid]) {
+				h->surplus_huge_pages_node[old_nid]--;
+				h->surplus_huge_pages_node[new_nid]++;
+			}
+			spin_unlock_irq(&hugetlb_lock);
 		}
-		spin_unlock_irq(&hugetlb_lock);
 	}
 
 	/*



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 171/556] mm/hugetlb_cma: fix null nodemask dereference in hugetlb_cma_alloc_frozen_folio
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (169 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 170/556] mm/hugetlb: fix missing migratable flag on same-node hugetlb migration Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 172/556] mm/hugetlb: keep max_huge_pages when dissolving surplus folios Greg Kroah-Hartman
                   ` (397 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sourav Panda, Muchun Song,
	Anshuman Khandual, David Hildenbrand, Frank van der Linden,
	Greg Thelen, Johannes Weiner, Kefeng Wang, Michal Hocko,
	Oscar Salvador, Rik van Riel, SeongJae Park, Shakeel Butt,
	Suren Baghdasaryan, Vlastimil Babka, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sourav Panda <souravpanda@google.com>

commit 7b8a8ae4dd176a232e973017d2aa3c536a7275e2 upstream.

alloc_buddy_hugetlb_folio_with_mpol() can pass a NULL nodemask to
alloc_fresh_hugetlb_folio() as a fallback to allocate from all nodes.  If
order is gigantic, alloc_fresh_hugetlb_folio() propagates the NULL
nodemask down to hugetlb_cma_alloc_frozen_folio() via
alloc_gigantic_frozen_folio().

Additionally, hugetlb_cma_alloc_frozen_folio() previously attempted
allocation on hugetlb_cma[nid] without verifying if nid is included in the
caller's nodemask.  Adding a node_isset(nid, *nodemask) check ensures the
initial preferred node allocation honors the memory policy / nodemask.

However, hugetlb_cma_alloc_frozen_folio() dereferences the nodemask in
node_isset(nid, *nodemask) and for_each_node_mask(node, *nodemask),
leading to a null pointer dereference kernel panic when nodemask is NULL.

Fix this by checking if nodemask is NULL in
hugetlb_cma_alloc_frozen_folio() and defaulting it to
cpuset_current_mems_allowed.  Enclose the allocation attempts within the
cpuset seqcount retry loop so that if the cpuset changes concurrently
during allocation, the attempts are retried using the updated nodemask.
This ensures that the initial node check and fallback loop safely honor
the task's cpuset without violating cpuset constraints or causing NULL
pointer dereferences or unexpected allocation failures.

>From a userspace perspective, this bug allows an unprivileged user to
crash the kernel (trigger a panic) by requesting a gigantic hugepage
allocation with MPOL_PREFERRED_MANY on a system where CMA is only
configured on a subset of NUMA nodes.

This can be reproduced by booting a VM with two NUMA nodes, restricting
CMA to Node 1 (e.g., hugetlb_cma=1:1G default_hugepagesz=1G hugepagesz=1G
hugepages=0), and running a program that allocates a 1GB hugepage area
without reserving, restricts allocation to Node 0 using mbind() with
MPOL_PREFERRED_MANY, and triggers a page fault:

  void *ptr = mmap(NULL, 1UL << 30, PROT_READ | PROT_WRITE,
                   MAP_PRIVATE | MAP_ANONYMOUS | MAP_HUGETLB |
                   MAP_HUGE_1GB | MAP_NORESERVE, -1, 0);
  unsigned long nodemask = 1; /* Node 0 */
  mbind(ptr, 1UL << 30, MPOL_PREFERRED_MANY, &nodemask,
        sizeof(nodemask) * 8, 0);
  memset(ptr, 0, 1UL << 30); /* Trigger fault */

This results in a NULL pointer dereference:

  BUG: kernel NULL pointer dereference, address: 0000000000000000
  #PF: supervisor read access in kernel mode
  #PF: error_code(0x0000) - not-present page
  Oops: Oops: 0000 [#1] SMP NOPTI
  RIP: 0010:hugetlb_cma_alloc_frozen_folio+0x75/0x120
  Call Trace:
   <TASK>
   only_alloc_fresh_hugetlb_folio.isra.0+0x2c/0x160
   alloc_surplus_hugetlb_folio+0x6d/0x100
   alloc_hugetlb_folio+0x3c5/0x660
   hugetlb_no_page+0x3d9/0x650

Link: https://lore.kernel.org/20260811052909.475635-1-souravpanda@google.com
Fixes: eb02f14c4a2b ("mm/hugetlb: allow overcommitting gigantic hugepages")
Signed-off-by: Sourav Panda <souravpanda@google.com>
Reviewed-by: Muchun Song <muchun.song@linux.dev>
Reviewed-by: Anshuman Khandual <anshuman.khandual@arm.com>
Cc: David Hildenbrand <david@kernel.org>
Cc: Frank van der Linden <fvdl@google.com>
Cc: Greg Thelen <gthelen@google.com>
Cc: Johannes Weiner <hannes@cmpxchg.org>
Cc: Kefeng Wang <wangkefeng.wang@huawei.com>
Cc: Michal Hocko <mhocko@suse.com>
Cc: Oscar Salvador <osalvador@suse.de>
Cc: Rik van Riel <riel@surriel.com>
Cc: SeongJae Park <sj@kernel.org>
Cc: Shakeel Butt <shakeel.butt@linux.dev>
Cc: Suren Baghdasaryan <surenb@google.com>
Cc: Vlastimil Babka <vbabka@suse.cz>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/hugetlb_cma.c |   21 ++++++++++++++++++---
 1 file changed, 18 insertions(+), 3 deletions(-)

--- a/mm/hugetlb_cma.c
+++ b/mm/hugetlb_cma.c
@@ -3,6 +3,7 @@
 #include <linux/mm.h>
 #include <linux/cma.h>
 #include <linux/compiler.h>
+#include <linux/cpuset.h>
 #include <linux/mm_inline.h>
 
 #include <asm/page.h>
@@ -30,15 +31,25 @@ struct folio *hugetlb_cma_alloc_frozen_f
 	int node;
 	struct folio *folio;
 	struct page *page = NULL;
+	const nodemask_t *nmask;
+	unsigned int cpuset_mems_cookie;
 
 	if (!hugetlb_cma_size)
 		return NULL;
 
-	if (hugetlb_cma[nid])
+retry_cpuset:
+	if (!nodemask) {
+		cpuset_mems_cookie = read_mems_allowed_begin();
+		nmask = &cpuset_current_mems_allowed;
+	} else {
+		nmask = nodemask;
+	}
+
+	if (hugetlb_cma[nid] && node_isset(nid, *nmask))
 		page = cma_alloc_frozen_compound(hugetlb_cma[nid], order);
 
 	if (!page && !(gfp_mask & __GFP_THISNODE)) {
-		for_each_node_mask(node, *nodemask) {
+		for_each_node_mask(node, *nmask) {
 			if (node == nid || !hugetlb_cma[node])
 				continue;
 
@@ -48,8 +59,12 @@ struct folio *hugetlb_cma_alloc_frozen_f
 		}
 	}
 
-	if (!page)
+	if (!page) {
+		if (!nodemask &&
+		    unlikely(read_mems_allowed_retry(cpuset_mems_cookie)))
+			goto retry_cpuset;
 		return NULL;
+	}
 
 	folio = page_folio(page);
 	folio_set_hugetlb_cma(folio);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 172/556] mm/hugetlb: keep max_huge_pages when dissolving surplus folios
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (170 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 171/556] mm/hugetlb_cma: fix null nodemask dereference in hugetlb_cma_alloc_frozen_folio Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 173/556] mm/hugetlb_cgroup: call page_counter_set_max() outside VM_BUG_ON() Greg Kroah-Hartman
                   ` (396 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Longlong Xia, Muchun Song,
	David Hildenbrand, Jinjiang Tu, Oscar Salvador, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Longlong Xia <xialonglong@kylinos.cn>

commit 267bede12d3b108ca29997ce280e927a570ec97f upstream.

dissolve_free_hugetlb_folio() can remove a free folio as surplus when its
node has surplus pages.  In that case remove_hugetlb_folio() decrements
both nr_huge_pages and surplus_huge_pages, leaving the persistent pool
size unchanged.

Updating max_huge_pages as if a persistent folio had been removed can
therefore corrupt the persistent pool target and underflow it when
max_huge_pages is zero.  Keep max_huge_pages unchanged for surplus folios,
including the vmemmap restoration rollback path.

Link: https://lore.kernel.org/20260814083027.1419487-1-xialonglong2025@163.com
Fixes: cb402bbdabca ("mm/hugetlb: fix surplus pages in dissolve_free_huge_page()")
Assisted-by: Codex:gpt-5.6-sol
Signed-off-by: Longlong Xia <xialonglong@kylinos.cn>
Reviewed-by: Muchun Song <muchun.song@linux.dev>
Cc: David Hildenbrand <david@kernel.org>
Cc: Jinjiang Tu <tujinjiang@huawei.com>
Cc: Longlong Xia <xialonglong@kylinos.cn>
Cc: Oscar Salvador <osalvador@suse.de>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/hugetlb.c |    6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

--- a/mm/hugetlb.c
+++ b/mm/hugetlb.c
@@ -2002,7 +2002,8 @@ retry:
 		if (h->surplus_huge_pages_node[folio_nid(folio)])
 			adjust_surplus = true;
 		remove_hugetlb_folio(h, folio, adjust_surplus);
-		h->max_huge_pages--;
+		if (!adjust_surplus)
+			h->max_huge_pages--;
 		spin_unlock_irq(&hugetlb_lock);
 
 		/*
@@ -2022,7 +2023,8 @@ retry:
 			if (rc) {
 				spin_lock_irq(&hugetlb_lock);
 				add_hugetlb_folio(h, folio, adjust_surplus);
-				h->max_huge_pages++;
+				if (!adjust_surplus)
+					h->max_huge_pages++;
 				goto out;
 			}
 		} else {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 173/556] mm/hugetlb_cgroup: call page_counter_set_max() outside VM_BUG_ON()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (171 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 172/556] mm/hugetlb: keep max_huge_pages when dissolving surplus folios Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 174/556] nvdimm/btt: reject an arena whose nfree is below the lane count Greg Kroah-Hartman
                   ` (395 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Narek Jilavyan, Muchun Song,
	David Hildenbrand, Oscar Salvador, Shakeel Butt, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Narek Jilavyan <njilav@gmail.com>

commit eedc8474d469a2e88f4dc61f8cfe05c147478b43 upstream.

hugetlb_cgroup_css_alloc() rounds the counter limit down to a multiple of
the huge page size and then applies it inside an assertion:

	VM_BUG_ON(page_counter_set_max(fault, limit));
	VM_BUG_ON(page_counter_set_max(rsvd, limit));

With CONFIG_DEBUG_VM=n, VM_BUG_ON(cond) is BUILD_BUG_ON_INVALID(cond),
i.e.  ((void)(sizeof((__force long)(cond)))), whose operand is never
evaluated.  page_counter_set_max() is not a predicate - it performs
xchg(&counter->max, nr_pages) - so on every non-debug kernel the limit is
never applied and the counters keep page_counter_init()'s
PAGE_COUNTER_MAX.

That is user-visible, because hugetlb_cgroup_read_u64_max() recomputes the
same rounded value and uses equality as its "unlimited" sentinel.
PAGE_COUNTER_MAX is LONG_MAX / PAGE_SIZE = 2251799813685247, which is odd,
so round_down() really does change it and the two sides disagree.  With
CONFIG_DEBUG_VM=n:

	$ cat /sys/fs/cgroup/t/hugetlb.2MB.max
	9223372036854771712

and with this patch:

	$ cat /sys/fs/cgroup/t/hugetlb.2MB.max
	max

A debug option should not change cgroup output.

Call the function, then assert the result, as v6.12 did.  Use
VM_WARN_ON_ONCE() rather than restoring VM_BUG_ON(): the two are identical
under CONFIG_DEBUG_VM=n, and checkpatch asks that new code not use BUG()
variants.

Link: https://lore.kernel.org/20260817103433.191266-1-njilav@gmail.com
Fixes: 0e2759afcaf9 ("page_counter: track failcnt only for legacy cgroups")
Signed-off-by: Narek Jilavyan <njilav@gmail.com>
Reviewed-by: Muchun Song <muchun.song@linux.dev>
Cc: David Hildenbrand <david@kernel.org>
Cc: Oscar Salvador <osalvador@suse.de>
Cc: Shakeel Butt <shakeel.butt@linux.dev>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/hugetlb_cgroup.c |    7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)

--- a/mm/hugetlb_cgroup.c
+++ b/mm/hugetlb_cgroup.c
@@ -97,6 +97,7 @@ static void hugetlb_cgroup_init(struct h
 		struct page_counter *fault, *fault_parent = NULL;
 		struct page_counter *rsvd, *rsvd_parent = NULL;
 		unsigned long limit;
+		int ret;
 
 		if (parent_h_cgroup) {
 			fault_parent = hugetlb_cgroup_counter_from_cgroup(
@@ -118,8 +119,10 @@ static void hugetlb_cgroup_init(struct h
 		limit = round_down(PAGE_COUNTER_MAX,
 				   pages_per_huge_page(&hstates[idx]));
 
-		VM_BUG_ON(page_counter_set_max(fault, limit));
-		VM_BUG_ON(page_counter_set_max(rsvd, limit));
+		ret = page_counter_set_max(fault, limit);
+		VM_WARN_ON_ONCE(ret);
+		ret = page_counter_set_max(rsvd, limit);
+		VM_WARN_ON_ONCE(ret);
 	}
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 174/556] nvdimm/btt: reject an arena whose nfree is below the lane count
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (172 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 173/556] mm/hugetlb_cgroup: call page_counter_set_max() outside VM_BUG_ON() Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 175/556] parisc: eisa: Fix infinite loop when parsing invalid IRQ value Greg Kroah-Hartman
                   ` (394 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Bryam Vargas, Alison Schofield

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bryam Vargas <hexlabsecurity@proton.me>

commit 6a1f2e5ed9267ca19187038ac635393c165213ac upstream.

The BTT info block's nfree field, the number of reserve free blocks, is
read from the medium without validation.  btt_freelist_init() and
btt_rtt_init() size the per-lane freelist[] and rtt[] arrays by nfree,
but the I/O path indexes them by the lane from nd_region_acquire_lane(),
which is bounded by nd_region->num_lanes (ND_MAX_LANES), not by nfree.
A crafted or foreign arena whose nfree is below the lane count makes
freelist[lane]/rtt[lane] run past the allocation: an out-of-bounds write.

btt.rst documents the nlanes = min(nfree, num_cpus) invariant, which the
code does not currently honor: num_lanes is ND_MAX_LANES regardless of
nfree.  Reject an arena whose nfree is below num_lanes at discovery,
before the per-lane arrays are allocated, enforcing that invariant.

Fixes: 5212e11fde4d ("nd_btt: atomic sector updates")
Cc: stable@vger.kernel.org
Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me>
Reviewed-by: Alison Schofield <alison.schofield@intel.com>
Tested-by: Alison Schofield <alison.schofield@intel.com>
Link: https://patch.msgid.link/20260620-b4-disp-88b2514b-v1-1-3834e707d232@proton.me
Signed-off-by: Alison Schofield <alison.schofield@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/nvdimm/btt.c |    8 ++++++++
 1 file changed, 8 insertions(+)

--- a/drivers/nvdimm/btt.c
+++ b/drivers/nvdimm/btt.c
@@ -883,6 +883,14 @@ static int discover_arenas(struct btt *b
 		arena->external_lba_start = cur_nlba;
 		parse_arena_meta(arena, super, cur_off);
 
+		if (arena->nfree < btt->nd_region->num_lanes) {
+			dev_err(to_dev(arena),
+				"nfree %u smaller than lane count %d\n",
+				arena->nfree, btt->nd_region->num_lanes);
+			ret = -ENODEV;
+			goto out;
+		}
+
 		ret = log_set_indices(arena);
 		if (ret) {
 			dev_err(to_dev(arena),



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 175/556] parisc: eisa: Fix infinite loop when parsing invalid IRQ value
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (173 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 174/556] nvdimm/btt: reject an arena whose nfree is below the lane count Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 176/556] parisc: Fix alignment of asm statements in head.S Greg Kroah-Hartman
                   ` (393 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Pei Xiao, Helge Deller

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pei Xiao <xiaopei01@kylinos.cn>

commit 8b585431a16cfb9d8f2955a9fa0787ce3dceb3c2 upstream.

When an invalid value is passed via the "eisa_irq_edge=" kernel
command line parameter (e.g. "eisa_irq_edge=16,5"), eisa_irq_setup()
prints an error message and continues without advancing the current
position.  As a result the same invalid value is parsed again and
again, causing an infinite loop while the kernel boots.

Advance to the next comma-separated entry, or stop parsing when there
is no next entry, before continuing so that the remaining entries are
processed normally.

Signed-off-by: Pei Xiao <xiaopei01@kylinos.cn>
Cc: stable@vger.kernel.org
Signed-off-by: Helge Deller <deller@gmx.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/parisc/eisa.c |    5 +++++
 1 file changed, 5 insertions(+)

--- a/drivers/parisc/eisa.c
+++ b/drivers/parisc/eisa.c
@@ -442,6 +442,11 @@ static int __init eisa_irq_setup(char *s
 		val = (int) simple_strtoul(cur, &pe, 0);
 		if (val > 15 || val < 0) {
 			printk(KERN_ERR "eisa: EISA irq value are 0-15\n");
+			cur = strchr(cur, ',');
+			if (cur)
+				cur++;
+			else
+				break;
 			continue;
 		}
 		if (val == 2) {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 176/556] parisc: Fix alignment of asm statements in head.S
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (174 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 175/556] parisc: eisa: Fix infinite loop when parsing invalid IRQ value Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 177/556] powerpc/kexec_file: Fix null-ptr-def in extra size calculation Greg Kroah-Hartman
                   ` (392 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Helge Deller

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Helge Deller <deller@gmx.de>

commit 04cf68c9a76e3c6b67ad056a66a14923abf85925 upstream.

All assembler statements need to be 4-byte aligned. Prevent a possible
misalignment if someone changes the preceeding string and it's length is
then suddenly not a multiple of 4 any longer.

Cc: stable@vger.kernel.org
Signed-off-by: Helge Deller <deller@gmx.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/parisc/kernel/head.S |    1 +
 1 file changed, 1 insertion(+)

--- a/arch/parisc/kernel/head.S
+++ b/arch/parisc/kernel/head.S
@@ -105,6 +105,7 @@ $iodc_panic:
 	or		%r10,%r10,%r10	/* qemu idle sleep */
 msg1:	.ascii "Can't boot kernel which was built for PA8x00 CPUs on this machine.\r\n"
 msg1_end:
+	.align 4
 
 $cpu_ok:
 #endif



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 177/556] powerpc/kexec_file: Fix null-ptr-def in extra size calculation
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (175 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 176/556] parisc: Fix alignment of asm statements in head.S Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 178/556] powerpc/kexec_file: Prevent kexec range truncation Greg Kroah-Hartman
                   ` (391 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jinjie Ruan, Sourabh Jain,
	Madhavan Srinivasan

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jinjie Ruan <ruanjinjie@huawei.com>

commit 761eda315a6e1fda3e8e2185b28430771fb1ac29 upstream.

A static Sashiko AI review identified a potential NULL pointer
dereference in kexec_extra_fdt_size_ppc64().

On platforms without any reserved memory regions,
get_reserved_memory_ranges() can return 0 while leaving 'rmem'
unallocated as NULL. Passing it directly leads to a kernel panic when
evaluating 'rmem->nr_ranges'.

Add a NULL check for 'rmem' to prevent this crash.

Cc: stable@vger.kernel.org
Fixes: 0d3ff067331e ("powerpc/kexec_file: fix extra size calculation for kexec FDT")
Signed-off-by: Jinjie Ruan <ruanjinjie@huawei.com>
Reviewed-by: Sourabh Jain <sourabhjain@linux.ibm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Link: https://patch.msgid.link/20260729012948.2797865-3-ruanjinjie@huawei.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/powerpc/kexec/file_load_64.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/arch/powerpc/kexec/file_load_64.c
+++ b/arch/powerpc/kexec/file_load_64.c
@@ -664,7 +664,7 @@ unsigned int kexec_extra_fdt_size_ppc64(
 		extra_size += (cpu_nodes - boot_cpu_node_count) * cpu_node_size();
 
 	/* Consider extra space for reserved memory ranges if any */
-	if (rmem->nr_ranges > 0)
+	if (rmem && rmem->nr_ranges > 0)
 		extra_size += sizeof(struct fdt_reserve_entry) * rmem->nr_ranges;
 
 	return extra_size + kdump_extra_fdt_size_ppc64(image, cpu_nodes);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 178/556] powerpc/kexec_file: Prevent kexec range truncation
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (176 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 177/556] powerpc/kexec_file: Fix null-ptr-def in extra size calculation Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 179/556] powerpc/mm: fix wrong addr_pfn tracking in compound vmemmap population Greg Kroah-Hartman
                   ` (390 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jinjie Ruan, Sourabh Jain,
	Madhavan Srinivasan

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jinjie Ruan <ruanjinjie@huawei.com>

commit fa40f9dbdd4af53e7445d9135b5b207eb8adf372 upstream.

Sashiko AI review pointed out the following issue.

The __merge_memory_ranges() function incorrectly handles overlapping
memory ranges when merging them. Although sort_memory_ranges() sorts all
ranges by their start address in ascending order beforehand, the merge
logic remains defective in two ways:

1. It compares the current range's start against the previous element (i-1)
   instead of the running target index (idx)

2. It unconditionally overwrites 'ranges[idx].end' with 'ranges[i].end'.

This logic flaw leads to critical memory truncation when a larger memory
range completely subsumes subsequent smaller ranges.

For example, consider a sorted input array with three ranges:
  Range A (idx=0): [0x1000 - 0x9000]
  Range B (i=1):   [0x2000 - 0x5000] (completely inside Range A)
  Range C (i=2):   [0x6000 - 0x8000] (completely inside Range A)

1. When i=1 (Range B):
   ranges[1].start (0x2000) <= ranges[0].end + 1 (0x9001) is TRUE.
   The code executes: ranges[0].end = ranges[1].end, which erroneously
   shrinks Range A's end from 0x9000 down to 0x5000.

2. When i=2 (Range C):
   ranges[2].start (0x6000) <= ranges[1].end + 1 (0x5001) is FALSE.
   The code falls into the else block, creating a broken new range.

As a result, valid memory fragments [0x5001 - 0x5fff] and [0x8001 - 0x9000]
are completely lost from the kexec exclude lists, potentially allowing
the crash kernel to overwrite active memory, causing data corruption
or crashes.

Fix this by ensuring the start of the current range is compared against the
end of the active merged range (idx), and use max() to safely prevent the
outer boundary from being truncated.

Cc: stable@vger.kernel.org
Fixes: 180adfc532a8 ("powerpc/kexec_file: Add helper functions for getting memory ranges")
Signed-off-by: Jinjie Ruan <ruanjinjie@huawei.com>
Reviewed-by: Sourabh Jain <sourabhjain@linux.ibm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Link: https://patch.msgid.link/20260729012948.2797865-4-ruanjinjie@huawei.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/powerpc/kexec/ranges.c |   12 +++++-------
 1 file changed, 5 insertions(+), 7 deletions(-)

--- a/arch/powerpc/kexec/ranges.c
+++ b/arch/powerpc/kexec/ranges.c
@@ -21,6 +21,7 @@
 #include <linux/of.h>
 #include <linux/slab.h>
 #include <linux/memblock.h>
+#include <linux/minmax.h>
 #include <linux/crash_core.h>
 #include <asm/sections.h>
 #include <asm/kexec_ranges.h>
@@ -105,19 +106,16 @@ static void __merge_memory_ranges(struct
 	struct range *ranges;
 	int i, idx;
 
-	if (!mem_rngs)
+	if (!mem_rngs || mem_rngs->nr_ranges <= 1)
 		return;
 
 	idx = 0;
-	ranges = &(mem_rngs->ranges[0]);
+	ranges = mem_rngs->ranges;
 	for (i = 1; i < mem_rngs->nr_ranges; i++) {
-		if (ranges[i].start <= (ranges[i-1].end + 1))
-			ranges[idx].end = ranges[i].end;
+		if (ranges[i].start <= (ranges[idx].end + 1))
+			ranges[idx].end = max(ranges[idx].end, ranges[i].end);
 		else {
 			idx++;
-			if (i == idx)
-				continue;
-
 			ranges[idx] = ranges[i];
 		}
 	}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 179/556] powerpc/mm: fix wrong addr_pfn tracking in compound vmemmap population
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (177 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 178/556] powerpc/kexec_file: Prevent kexec range truncation Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 180/556] powerpc/pseries: Handle and log pseries-wdt registration failures Greg Kroah-Hartman
                   ` (389 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Muchun Song, Oscar Salvador,
	Ritesh Harjani (IBM), Aneesh Kumar K.V, David Hildenbrand,
	Frank van der Linden, Liam R. Howlett, Lorenzo Stoakes,
	Madhavan Srinivasan, Michael Ellerman, Mike Rapoport (Microsoft),
	Nicholas Piggin, Oscar Salvador (SUSE), Usama Arif,
	Vlastimil Babka, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Muchun Song <songmuchun@bytedance.com>

commit 89a4ae32764172468dea303eb6ae90fe6c859712 upstream.

vmemmap_populate_compound_pages() uses addr_pfn to determine the PFN
offset within a compound page and to decide whether the current vmemmap
slot should be populated as a head page mapping or should reuse a tail
page mapping.

However, addr_pfn is advanced manually in parallel with addr.  The loop
itself progresses in vmemmap address space, so each PAGE_SIZE step in addr
covers PAGE_SIZE / sizeof(struct page) struct page slots.  Since addr_pfn
is compared against nr_pages in data-PFN units, it should advance by the
same number of PFNs.  The existing manual increments do not match that and
therefore do not reliably track the PFN corresponding to the current addr.

As a result, pfn_offset can be computed from the wrong PFN and the code
can make the head/tail decision for the wrong compound-page position.

Fix this by deriving addr_pfn directly from the current vmemmap address
instead of carrying it as loop state.

Link: https://lore.kernel.org/20260612035903.2468601-4-songmuchun@bytedance.com
Fixes: f2b79c0d7968 ("powerpc/book3s64/radix: add support for vmemmap optimization for radix")
Signed-off-by: Muchun Song <songmuchun@bytedance.com>
Acked-by: Oscar Salvador <osalvador@suse.de>
Reviewed-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Cc: "Aneesh Kumar K.V" <aneesh.kumar@linux.ibm.com>
Cc: David Hildenbrand <david@kernel.org>
Cc: Frank van der Linden <fvdl@google.com>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Lorenzo Stoakes <ljs@kernel.org>
Cc: Madhavan Srinivasan <maddy@linux.ibm.com>
Cc: Michael Ellerman <mpe@ellerman.id.au>
Cc: Mike Rapoport (Microsoft) <rppt@kernel.org>
Cc: Nicholas Piggin <npiggin@gmail.com>
Cc: Oscar Salvador (SUSE) <osalvador@kernel.org>
Cc: Usama Arif <usama.arif@linux.dev>
Cc: Vlastimil Babka <vbabka@kernel.org>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/powerpc/mm/book3s64/radix_pgtable.c |    7 +------
 1 file changed, 1 insertion(+), 6 deletions(-)

--- a/arch/powerpc/mm/book3s64/radix_pgtable.c
+++ b/arch/powerpc/mm/book3s64/radix_pgtable.c
@@ -1314,7 +1314,6 @@ int __meminit vmemmap_populate_compound_
 	 * covering out both edges.
 	 */
 	unsigned long addr;
-	unsigned long addr_pfn = start_pfn;
 	unsigned long next;
 	pgd_t *pgd;
 	p4d_t *p4d;
@@ -1335,7 +1334,6 @@ int __meminit vmemmap_populate_compound_
 
 		if (pmd_leaf(READ_ONCE(*pmd))) {
 			/* existing huge mapping. Skip the range */
-			addr_pfn += (PMD_SIZE >> PAGE_SHIFT);
 			next = pmd_addr_end(addr, end);
 			continue;
 		}
@@ -1348,11 +1346,11 @@ int __meminit vmemmap_populate_compound_
 			 * page whose VMEMMAP_RESERVE_NR pages were mapped and
 			 * this request fall in those pages.
 			 */
-			addr_pfn += 1;
 			next = addr + PAGE_SIZE;
 			continue;
 		} else {
 			unsigned long nr_pages = pgmap_vmemmap_nr(pgmap);
+			unsigned long addr_pfn = page_to_pfn((struct page *)addr);
 			unsigned long pfn_offset = addr_pfn - ALIGN_DOWN(addr_pfn, nr_pages);
 			pte_t *tail_page_pte;
 
@@ -1376,7 +1374,6 @@ int __meminit vmemmap_populate_compound_
 				if (!pte)
 					return -ENOMEM;
 
-				addr_pfn += 2;
 				next = addr + 2 * PAGE_SIZE;
 				continue;
 			}
@@ -1392,7 +1389,6 @@ int __meminit vmemmap_populate_compound_
 					return -ENOMEM;
 				vmemmap_verify(pte, node, addr, addr + PAGE_SIZE);
 
-				addr_pfn += 1;
 				next = addr + PAGE_SIZE;
 				continue;
 			}
@@ -1402,7 +1398,6 @@ int __meminit vmemmap_populate_compound_
 				return -ENOMEM;
 			vmemmap_verify(pte, node, addr, addr + PAGE_SIZE);
 
-			addr_pfn += 1;
 			next = addr + PAGE_SIZE;
 			continue;
 		}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 180/556] powerpc/pseries: Handle and log pseries-wdt registration failures
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (178 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 179/556] powerpc/mm: fix wrong addr_pfn tracking in compound vmemmap population Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 181/556] powerpc/pseries: Move H_WATCHDOG definitions to a common header Greg Kroah-Hartman
                   ` (388 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ritesh Harjani (IBM), Sourabh Jain,
	Madhavan Srinivasan

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sourabh Jain <sourabhjain@linux.ibm.com>

commit e65b526affa621b50646cafdf6b06505af07032e upstream.

The pseries watchdog initialization registers the pseries-wdt platform
device using platform_device_register_simple(), but currently ignores
its return value.

Check the returned pointer for errors, log a descriptive error message
when registration fails, and propagate the failure code to the caller.
This avoids silently ignoring platform device registration failures.

Cc: stable@vger.kernel.org
Reviewed-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Signed-off-by: Sourabh Jain <sourabhjain@linux.ibm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Link: https://patch.msgid.link/20260727053416.276317-3-sourabhjain@linux.ibm.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/powerpc/platforms/pseries/setup.c |   14 ++++++++++++--
 1 file changed, 12 insertions(+), 2 deletions(-)

--- a/arch/powerpc/platforms/pseries/setup.c
+++ b/arch/powerpc/platforms/pseries/setup.c
@@ -191,8 +191,18 @@ static void __init fwnmi_init(void)
  */
 static __init int pseries_wdt_init(void)
 {
-	if (firmware_has_feature(FW_FEATURE_WATCHDOG))
-		platform_device_register_simple("pseries-wdt", 0, NULL, 0);
+	struct platform_device *pdev;
+
+	if (!firmware_has_feature(FW_FEATURE_WATCHDOG))
+		return 0;
+
+	pdev = platform_device_register_simple("pseries-wdt", 0, NULL, 0);
+
+	if (IS_ERR(pdev)) {
+		pr_err("Failed to register pseries-wdt platform device\n");
+		return PTR_ERR(pdev);
+	}
+
 	return 0;
 }
 machine_subsys_initcall(pseries, pseries_wdt_init);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 181/556] powerpc/pseries: Move H_WATCHDOG definitions to a common header
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (179 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 180/556] powerpc/pseries: Handle and log pseries-wdt registration failures Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 182/556] powerpc/crash: stop watchdogs before booting kdump kernel Greg Kroah-Hartman
                   ` (387 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ritesh Harjani (IBM), Sourabh Jain,
	Madhavan Srinivasan

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sourabh Jain <sourabhjain@linux.ibm.com>

commit 516a254918453ec99660201263d01189c082332c upstream.

The H_WATCHDOG input and output definitions are currently local to the
pseries watchdog driver. The next patch in this series also needs these
definitions to issue H_WATCHDOG hypercalls outside the watchdog driver.

Move the H_WATCHDOG definitions to a new common header,
asm/papr-watchdog.h, so they can be shared without duplicating the
PAPR watchdog definitions.

No functional changes.

Cc: stable@vger.kernel.org
Suggested-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Signed-off-by: Sourabh Jain <sourabhjain@linux.ibm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Link: https://patch.msgid.link/20260727053416.276317-2-sourabhjain@linux.ibm.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/powerpc/include/asm/papr-watchdog.h |   58 +++++++++++++++++++++++++++++++
 drivers/watchdog/pseries-wdt.c           |   53 ----------------------------
 2 files changed, 59 insertions(+), 52 deletions(-)
 create mode 100644 arch/powerpc/include/asm/papr-watchdog.h

--- /dev/null
+++ b/arch/powerpc/include/asm/papr-watchdog.h
@@ -0,0 +1,58 @@
+/* SPDX-License-Identifier: GPL-2.0-only */
+
+#ifndef _ASM_POWERPC_PAPR_WATCHDOG_H
+#define _ASM_POWERPC_PAPR_WATCHDOG_H
+
+/*
+ * H_WATCHDOG Input
+ *
+ * R4: "flags":
+ *
+ *         Bits 48-55: "operation"
+ */
+#define PSERIES_WDTF_OP_START	0x100UL		/* start timer */
+#define PSERIES_WDTF_OP_STOP	0x200UL		/* stop timer */
+#define PSERIES_WDTF_OP_QUERY	0x300UL		/* query timer capabilities */
+
+/*
+ *         Bits 56-63: "timeoutAction" (for "Start Watchdog" only)
+ */
+#define PSERIES_WDTF_ACTION_HARD_POWEROFF	0x1UL	/* poweroff */
+#define PSERIES_WDTF_ACTION_HARD_RESTART	0x2UL	/* restart */
+#define PSERIES_WDTF_ACTION_DUMP_RESTART	0x3UL	/* dump + restart */
+
+/*
+ * H_WATCHDOG Output
+ *
+ * R3: Return code
+ *
+ *     H_SUCCESS    The operation completed.
+ *
+ *     H_BUSY	    The hypervisor is too busy; retry the operation.
+ *
+ *     H_PARAMETER  The given "flags" are somehow invalid.  Either the
+ *                  "operation" or "timeoutAction" is invalid, or a
+ *                  reserved bit is set.
+ *
+ *     H_P2         The given "watchdogNumber" is zero or exceeds the
+ *                  supported maximum value.
+ *
+ *     H_P3         The given "timeoutInMs" is below the supported
+ *                  minimum value.
+ *
+ *     H_NOOP       The given "watchdogNumber" is already stopped.
+ *
+ *     H_HARDWARE   The operation failed for ineffable reasons.
+ *
+ *     H_FUNCTION   The H_WATCHDOG hypercall is not supported by this
+ *                  hypervisor.
+ *
+ * R4:
+ *
+ * - For the "Query Watchdog Capabilities" operation, a 64-bit
+ *   structure:
+ */
+#define PSERIES_WDTQ_MIN_TIMEOUT(cap)	(((cap) >> 48) & 0xffff)
+#define PSERIES_WDTQ_MAX_NUMBER(cap)	(((cap) >> 32) & 0xffff)
+
+#endif /* _ASM_POWERPC_PAPR_WATCHDOG_H */
--- a/drivers/watchdog/pseries-wdt.c
+++ b/drivers/watchdog/pseries-wdt.c
@@ -12,61 +12,10 @@
 #include <linux/platform_device.h>
 #include <linux/time64.h>
 #include <linux/watchdog.h>
+#include <asm/papr-watchdog.h>
 
 #define DRV_NAME "pseries-wdt"
 
-/*
- * H_WATCHDOG Input
- *
- * R4: "flags":
- *
- *         Bits 48-55: "operation"
- */
-#define PSERIES_WDTF_OP_START	0x100UL		/* start timer */
-#define PSERIES_WDTF_OP_STOP	0x200UL		/* stop timer */
-#define PSERIES_WDTF_OP_QUERY	0x300UL		/* query timer capabilities */
-
-/*
- *         Bits 56-63: "timeoutAction" (for "Start Watchdog" only)
- */
-#define PSERIES_WDTF_ACTION_HARD_POWEROFF	0x1UL	/* poweroff */
-#define PSERIES_WDTF_ACTION_HARD_RESTART	0x2UL	/* restart */
-#define PSERIES_WDTF_ACTION_DUMP_RESTART	0x3UL	/* dump + restart */
-
-/*
- * H_WATCHDOG Output
- *
- * R3: Return code
- *
- *     H_SUCCESS    The operation completed.
- *
- *     H_BUSY	    The hypervisor is too busy; retry the operation.
- *
- *     H_PARAMETER  The given "flags" are somehow invalid.  Either the
- *                  "operation" or "timeoutAction" is invalid, or a
- *                  reserved bit is set.
- *
- *     H_P2         The given "watchdogNumber" is zero or exceeds the
- *                  supported maximum value.
- *
- *     H_P3         The given "timeoutInMs" is below the supported
- *                  minimum value.
- *
- *     H_NOOP       The given "watchdogNumber" is already stopped.
- *
- *     H_HARDWARE   The operation failed for ineffable reasons.
- *
- *     H_FUNCTION   The H_WATCHDOG hypercall is not supported by this
- *                  hypervisor.
- *
- * R4:
- *
- * - For the "Query Watchdog Capabilities" operation, a 64-bit
- *   structure:
- */
-#define PSERIES_WDTQ_MIN_TIMEOUT(cap)	(((cap) >> 48) & 0xffff)
-#define PSERIES_WDTQ_MAX_NUMBER(cap)	(((cap) >> 32) & 0xffff)
-
 static const unsigned long pseries_wdt_action[] = {
 	[0] = PSERIES_WDTF_ACTION_HARD_POWEROFF,
 	[1] = PSERIES_WDTF_ACTION_HARD_RESTART,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 182/556] powerpc/crash: stop watchdogs before booting kdump kernel
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (180 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 181/556] powerpc/pseries: Move H_WATCHDOG definitions to a common header Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 183/556] s390/vfio-ap: fix stale pqap_hook pointer on error in vfio_ap_mdev_set_kvm() Greg Kroah-Hartman
                   ` (386 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mahesh Kumar G, Ritesh Harjani (IBM),
	Sourabh Jain, Madhavan Srinivasan

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sourabh Jain <sourabhjain@linux.ibm.com>

commit fb43ba4256543ce18ca0540fc37022bda438a293 upstream.

On pseries LPAR systems, watchdog timers configured from userspace can
remain active after a kernel panic. When a panic triggers kdump, the
crashing kernel jumps directly to the kdump kernel without stopping
active watchdogs. As a result, the watchdogs remain active after the
kdump kernel starts.

If dump capture takes longer than the watchdog timeout, PHYP resets the
LPAR before the dump is fully captured, causing dump capture to fail.

Fix this by issuing the `H_WATCHDOG` hcall during the crash shutdown
sequence to stop all active watchdogs before booting the kdump kernel.

Cc: stable@vger.kernel.org
Fixes: 69472ffa6575 ("watchdog/pseries-wdt: initial support for H_WATCHDOG-based watchdog timers")
Reported-by: Mahesh Kumar G <mahe657@linux.ibm.com>
Suggested-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Reviewed-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Signed-off-by: Sourabh Jain <sourabhjain@linux.ibm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Link: https://patch.msgid.link/20260727053416.276317-4-sourabhjain@linux.ibm.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/powerpc/include/asm/papr-watchdog.h |    6 ++++++
 arch/powerpc/platforms/pseries/setup.c   |   14 ++++++++++++++
 2 files changed, 20 insertions(+)

--- a/arch/powerpc/include/asm/papr-watchdog.h
+++ b/arch/powerpc/include/asm/papr-watchdog.h
@@ -22,6 +22,12 @@
 #define PSERIES_WDTF_ACTION_DUMP_RESTART	0x3UL	/* dump + restart */
 
 /*
+ * R5: "watchdogNumber":
+ *       PAPR says use -1 (all ones) to stop all watchdogs.
+ */
+#define PSERIES_WDT_NUM_ALL	((unsigned long)-1)
+
+/*
  * H_WATCHDOG Output
  *
  * R3: Return code
--- a/arch/powerpc/platforms/pseries/setup.c
+++ b/arch/powerpc/platforms/pseries/setup.c
@@ -77,6 +77,7 @@
 #include <asm/dtl.h>
 #include <asm/hvconsole.h>
 #include <asm/setup.h>
+#include <asm/papr-watchdog.h>
 
 #include "pseries.h"
 
@@ -185,6 +186,16 @@ static void __init fwnmi_init(void)
 #endif
 }
 
+static void pseries_crash_stop_watchdogs(void)
+{
+	long rc;
+
+	rc = plpar_hcall_norets_notrace(H_WATCHDOG, PSERIES_WDTF_OP_STOP,
+					PSERIES_WDT_NUM_ALL);
+	if (rc != H_SUCCESS && rc != H_NOOP)
+		pr_warn("Could not stop watchdogs before kdump rc=%ld\n", rc);
+}
+
 /*
  * Affix a device for the first timer to the platform bus if
  * we have firmware support for the H_WATCHDOG hypercall.
@@ -203,6 +214,9 @@ static __init int pseries_wdt_init(void)
 		return PTR_ERR(pdev);
 	}
 
+	if (crash_shutdown_register(pseries_crash_stop_watchdogs))
+		pr_warn("Could not register watchdog crash shutdown handler\n");
+
 	return 0;
 }
 machine_subsys_initcall(pseries, pseries_wdt_init);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 183/556] s390/vfio-ap: fix stale pqap_hook pointer on error in vfio_ap_mdev_set_kvm()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (181 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 182/556] powerpc/crash: stop watchdogs before booting kdump kernel Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 184/556] s390/vfio-ap: Fix stale do_remove flag across iterations in vfio_ap_mdev_cfg_remove Greg Kroah-Hartman
                   ` (385 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Matthew Rosato, Anthony Krowiak,
	Christian Borntraeger, Claudio Imbrenda

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Anthony Krowiak <akrowiak@linux.ibm.com>

commit 4400270ec0348d05dc0439d8f0130853ce7f9e20 upstream.

In vfio_ap_mdev_set_kvm(), kvm->arch.crypto.pqap_hook is set to
&matrix_mdev->pqap_hook before the update locks are acquired and the
mdev list is checked for a conflicting assignment. If another mdev is
already attached to the same KVM instance, the function returns -EPERM
without restoring the hook pointer, leaving kvm->arch.crypto.pqap_hook
pointing at the failing matrix_mdev instead of the mdev that legitimately
owns the KVM.

Since matrix_mdev->kvm is never set on this error path,
vfio_ap_mdev_unset_kvm() will not clean up the hook when matrix_mdev
is later closed. If matrix_mdev is subsequently freed, any PQAP
instruction executed by the guest will dereference the stale pointer
through pqap_hook_rwsem, resulting in a use-after-free.

Since kvm->arch.crypto.pqap_hook is only set in the vfio_ap_mdev_set_kvm()
function and is cleared in the vfio_ap_mdev_unset_kvm() function, a check
for 'kvm->arch.crypto.pqap_hook != NULL' is all that is needed to determine
whether it belongs to another mdev. This will alleviate the need to iterate
the matrix_dev->mdev_list list to see if the kvm object is assigned to
another mdev.This was introduced in v3 to alleviate the need to take the
mdevs_lock while iterating the list; however, this did not prevent a
potential race condition.

The pqap_hook_rwsem(write) is now performed inside
get_update_locks_for_kvm(), which is updated to acquire
pqap_hook_rwsem(write) between kvm->lock and mdevs_lock. This ordering
is consistent with the PQAP intercept path, which acquires pqap_hook_rwsem
in read mode while srcu is held under vcpu->mutex, establishing the
dependency: kvm->lock -> vcpu->mutex -> srcu -> pqap_hook_rwsem(read).

The pqap_hook_rwsem is now released inside the
release_update_locks_for_kvm(), which is updated to release
pqap_hook_rwsem(write) between mdevs_lock and kvm->lock.

Additionally, kvm_put_kvm() in vfio_ap_mdev_unset_kvm() is moved
after release_update_locks_for_kvm(). Previously it was called while
kvm->lock was held; if it were ever the last reference, kvm_destroy_vm()
would run under kvm->lock, which would deadlock.

Fixes: 86956e70761b3 ("s390/vfio-ap: replace open coded locks for VFIO_GROUP_NOTIFY_SET_KVM notification")
Cc: stable@vger.kernel.org
Co-developed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Signed-off-by: Matthew Rosato <mjrosato@linux.ibm.com>
Signed-off-by: Anthony Krowiak <akrowiak@linux.ibm.com>
Acked-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Message-ID: <20260806173435.105044-1-akrowiak@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/s390/crypto/vfio_ap_ops.c |   45 ++++++++++++++++----------------------
 1 file changed, 20 insertions(+), 25 deletions(-)

--- a/drivers/s390/crypto/vfio_ap_ops.c
+++ b/drivers/s390/crypto/vfio_ap_ops.c
@@ -48,15 +48,19 @@ static void vfio_ap_mdev_reset_queue(str
  * 1. matrix_dev->guests_lock: required to use the KVM pointer to update a KVM
  *			       guest's APCB.
  * 2. kvm->lock:	       required to update a guest's APCB
- * 3. matrix_dev->mdevs_lock:  required to access data stored in a matrix_mdev
+ * 3. kvm->arch.crypto.pqap_hook_rwsem: required to update pqap_hook and
+ *					serialize against PQAP intercepts
+ * 4. matrix_dev->mdevs_lock:  required to access data stored in a matrix_mdev
  *
- * Note: If @kvm is NULL, the KVM lock will not be taken.
+ * Note: If @kvm is NULL, the KVM lock and pqap_hook_rwsem will not be taken.
  */
 static inline void get_update_locks_for_kvm(struct kvm *kvm)
 {
 	mutex_lock(&matrix_dev->guests_lock);
-	if (kvm)
+	if (kvm) {
 		mutex_lock(&kvm->lock);
+		down_write(&kvm->arch.crypto.pqap_hook_rwsem);
+	}
 	mutex_lock(&matrix_dev->mdevs_lock);
 }
 
@@ -68,16 +72,19 @@ static inline void get_update_locks_for_
  *
  * The proper unlocking order is:
  * 1. matrix_dev->mdevs_lock
- * 2. kvm->lock
- * 3. matrix_dev->guests_lock
+ * 2. kvm->arch.crypto.pqap_hook_rwsem
+ * 3. kvm->lock
+ * 4. matrix_dev->guests_lock
  *
- * Note: If @kvm is NULL, the KVM lock will not be released.
+ * Note: If @kvm is NULL, the KVM lock and pqap_hook_rwsem will not be released.
  */
 static inline void release_update_locks_for_kvm(struct kvm *kvm)
 {
 	mutex_unlock(&matrix_dev->mdevs_lock);
-	if (kvm)
+	if (kvm) {
+		up_write(&kvm->arch.crypto.pqap_hook_rwsem);
 		mutex_unlock(&kvm->lock);
+	}
 	mutex_unlock(&matrix_dev->guests_lock);
 }
 
@@ -1821,26 +1828,17 @@ static const struct attribute_group *vfi
 static int vfio_ap_mdev_set_kvm(struct ap_matrix_mdev *matrix_mdev,
 				struct kvm *kvm)
 {
-	struct ap_matrix_mdev *m;
-
 	if (kvm->arch.crypto.crycbd) {
-		down_write(&kvm->arch.crypto.pqap_hook_rwsem);
-		kvm->arch.crypto.pqap_hook = &matrix_mdev->pqap_hook;
-		up_write(&kvm->arch.crypto.pqap_hook_rwsem);
-
 		get_update_locks_for_kvm(kvm);
-
-		list_for_each_entry(m, &matrix_dev->mdev_list, node) {
-			if (m != matrix_mdev && m->kvm == kvm) {
-				release_update_locks_for_kvm(kvm);
-				return -EPERM;
-			}
+		if (kvm->arch.crypto.pqap_hook) {
+			release_update_locks_for_kvm(kvm);
+			return -EPERM;
 		}
+		kvm->arch.crypto.pqap_hook = &matrix_mdev->pqap_hook;
 
 		kvm_get_kvm(kvm);
 		matrix_mdev->kvm = kvm;
 		vfio_ap_mdev_update_guest_apcb(matrix_mdev);
-
 		release_update_locks_for_kvm(kvm);
 	}
 
@@ -1883,18 +1881,15 @@ static void vfio_ap_mdev_unset_kvm(struc
 	struct kvm *kvm = matrix_mdev->kvm;
 
 	if (kvm && kvm->arch.crypto.crycbd) {
-		down_write(&kvm->arch.crypto.pqap_hook_rwsem);
-		kvm->arch.crypto.pqap_hook = NULL;
-		up_write(&kvm->arch.crypto.pqap_hook_rwsem);
-
 		get_update_locks_for_kvm(kvm);
+		kvm->arch.crypto.pqap_hook = NULL;
 
 		kvm_arch_crypto_clear_masks(kvm);
 		vfio_ap_mdev_reset_queues(matrix_mdev);
-		kvm_put_kvm(kvm);
 		matrix_mdev->kvm = NULL;
 
 		release_update_locks_for_kvm(kvm);
+		kvm_put_kvm(kvm);
 	}
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 184/556] s390/vfio-ap: Fix stale do_remove flag across iterations in vfio_ap_mdev_cfg_remove
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (182 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 183/556] s390/vfio-ap: fix stale pqap_hook pointer on error in vfio_ap_mdev_set_kvm() Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 185/556] s390/vfio-ap: Fix control domain removal " Greg Kroah-Hartman
                   ` (384 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Anthony Krowiak, Matthew Rosato,
	Christian Borntraeger

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Anthony Krowiak <akrowiak@linux.ibm.com>

commit b1f092d94f621307927f145e3cc31893da51fc08 upstream.

The do_remove flag in vfio_ap_mdev_cfg_remove() is initialised to zero
before the loop that iterates over the list of matrix mdevs, but is
never reset at the start of each iteration. Since do_remove is
OR-accumulated across iterations, a positive result from one mdev
carries over to subsequent mdevs.

The fix is to set the do_remove flag with the first call to bitmap_and;
for example: do_remove = bitmap_an rather than do_remove |= bitmap_and.

Fixes: eeb386aeb5b7 ("s390/vfio-ap: handle config changed and scan complete notification")
Cc: stable@vger.kernel.org
Signed-off-by: Anthony Krowiak <akrowiak@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/s390/crypto/vfio_ap_ops.c |    8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

--- a/drivers/s390/crypto/vfio_ap_ops.c
+++ b/drivers/s390/crypto/vfio_ap_ops.c
@@ -2598,15 +2598,15 @@ static void vfio_ap_mdev_cfg_remove(unsi
 	DECLARE_BITMAP(aprem, AP_DEVICES);
 	DECLARE_BITMAP(aqrem, AP_DOMAINS);
 	DECLARE_BITMAP(cdrem, AP_DOMAINS);
-	int do_remove = 0;
+	int do_remove;
 
 	list_for_each_entry(matrix_mdev, &matrix_dev->mdev_list, node) {
 		mutex_lock(&matrix_mdev->kvm->lock);
 		mutex_lock(&matrix_dev->mdevs_lock);
 
-		do_remove |= bitmap_and(aprem, ap_remove,
-					  matrix_mdev->matrix.apm,
-					  AP_DEVICES);
+		do_remove = bitmap_and(aprem, ap_remove,
+				       matrix_mdev->matrix.apm,
+				       AP_DEVICES);
 		do_remove |= bitmap_and(aqrem, aq_remove,
 					  matrix_mdev->matrix.aqm,
 					  AP_DOMAINS);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 185/556] s390/vfio-ap: Fix control domain removal in vfio_ap_mdev_cfg_remove
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (183 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 184/556] s390/vfio-ap: Fix stale do_remove flag across iterations in vfio_ap_mdev_cfg_remove Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 186/556] s390/vfio-ap: Fix dereference matrix_mdev->kvm without checking for NULL Greg Kroah-Hartman
                   ` (383 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Anthony Krowiak, Matthew Rosato,
	Christian Borntraeger

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Anthony Krowiak <akrowiak@linux.ibm.com>

commit 6b8a02e216f6b520cc029e43ddc83956605135d5 upstream.

The vfio_ap_config_remove function uses the bitmap_andnot function to clear
bits from the matrix_mdev->matrix.adm bitmap (specifies the control domains
assigned to the mdev). This prevents the explicitly unplugged control
domains from being removed the KVM guest. The bitmap_and function is used
instead.

Fixes: eeb386aeb5b7c ("s390/vfio-ap: handle config changed and scan complete notification")
Cc: stable@vger.kernel.org
Signed-off-by: Anthony Krowiak <akrowiak@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/s390/crypto/vfio_ap_ops.c |    6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

--- a/drivers/s390/crypto/vfio_ap_ops.c
+++ b/drivers/s390/crypto/vfio_ap_ops.c
@@ -2610,9 +2610,9 @@ static void vfio_ap_mdev_cfg_remove(unsi
 		do_remove |= bitmap_and(aqrem, aq_remove,
 					  matrix_mdev->matrix.aqm,
 					  AP_DOMAINS);
-		do_remove |= bitmap_andnot(cdrem, cd_remove,
-					     matrix_mdev->matrix.adm,
-					     AP_DOMAINS);
+		do_remove |= bitmap_and(cdrem, cd_remove,
+					matrix_mdev->matrix.adm,
+					AP_DOMAINS);
 
 		if (do_remove)
 			vfio_ap_mdev_hot_unplug_cfg(matrix_mdev, aprem, aqrem,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 186/556] s390/vfio-ap: Fix dereference matrix_mdev->kvm without checking for NULL
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (184 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 185/556] s390/vfio-ap: Fix control domain removal " Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 187/556] s390/vfio-ap: Fix hot-unplug skipped when last AP adapter or domain removed Greg Kroah-Hartman
                   ` (382 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Anthony Krowiak, Matthew Rosato,
	Christian Borntraeger

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Anthony Krowiak <akrowiak@linux.ibm.com>

commit d50346801b4f144e42b49cd4f1496010498ab114 upstream.

The ap_driver structure has two fields which are function pointers to
callbacks:

* .on_config_changed: called at the start of the AP bus scan function to
                      notify the device driver that the host AP
                      configuration has changed and the associated AP
                      devices will be added or removed accordingly. This
                      gives the implementor a chance to evaluate the
                      configuration changes and respond to them before
                      the associated devices are added or removed.

* .on_scan_complete:  Called at the end of the AP bus scan function to
                      notify the device driver that the host AP
                      configuration has changed and the AP devices have
                      been added or removed accordingly. This gives the
                      implementor the opportunity to respond to the
                      changes after the associated devices are added or
                      removed.

These two callbacks are implemented in the vfio_ap device driver via the
vfio_ap_on_cfg_changed and vfio_ap_on_scan_complete functions respectively.

Within the call stack of these two callback functions the
matrix_mdev->kvm->lock mutex is taken without checking whether
matrix_mdev->kvm is NULL or not. If matrix_mdev->kvm has never been set,
trying to take the lock will trigger a NULL pointer dereference. This patch
adds checks for matrix_mdev->kvm == NULL before taking the
matrix_mdev->kvm->lock mutex.

Note that the matrix_mdev->kvm->lock mutex taken in the
vfio_ap_mdev_hot_plug_config function is moved to the calling function
along with the matrix_dev->mdevs_lock which is needed there to access
the fields of the matrix_mdev. It makes little sense to make the change
the check for matrix_mdev->kvm there before taking the kvm->lock
mutex only to have to move it out via another patch, so it is done in
this patch.

It is important to make note of the following:
1. The matrix_dev->guests_lock is acquired at the start of both callback
   functions. This ensures that matrix_mdev will not be removed via the
   vfio_ap_mdev_remove function because it too takes matrix_dev_guests_lock
   before removing the object; so, matrix_mdev will be available for the
   duration of the callback functions.

2. The matrix_dev->mdevs_lock mutex must be taken in order to access
   fields within the matrix_mdev structure

3. matrix_mdev->kvm->lock mutex must be taken before the
   matrix_dev->mdevs_lock to prevent a lockdep splat.

4: The kvm->lock must be held while plugging the guest's AP configuration
   into its SIE state description via the vfio_ap_mdev_update_guest_apcb
   function.

5. The vfio_ap_mdev_update_guest_apcb checks matrix_mdev->kvm to verify it
   is not NULL before doing the hot plug of the guest's AP configuration.

Fixes: eeb386aeb5b7c ("s390/vfio-ap: handle config changed and scan complete notification")
Cc: stable@vger.kernel.org
Signed-off-by: Anthony Krowiak <akrowiak@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/s390/crypto/vfio_ap_ops.c |   39 +++++++++++++++++++++++++++++---------
 1 file changed, 30 insertions(+), 9 deletions(-)

--- a/drivers/s390/crypto/vfio_ap_ops.c
+++ b/drivers/s390/crypto/vfio_ap_ops.c
@@ -2600,8 +2600,20 @@ static void vfio_ap_mdev_cfg_remove(unsi
 	DECLARE_BITMAP(cdrem, AP_DOMAINS);
 	int do_remove;
 
+	/*
+	 * It is safe to traverse this list here because the
+	 * required guard - matrix_dev->guests_lock - is taken in the
+	 * vfio_ap_on_cfg_changed function prior to this function getting
+	 * called.
+	 */
 	list_for_each_entry(matrix_mdev, &matrix_dev->mdev_list, node) {
-		mutex_lock(&matrix_mdev->kvm->lock);
+		/*
+		 * The mdevs_lock must be held to access fields within matrix_mdev,
+		 * and kvm->lock must be taken before mdevs_lock to satisfy the lock
+		 * ordering requirement and prevent a lockdep splat.
+		 */
+		if (matrix_mdev->kvm)
+			mutex_lock(&matrix_mdev->kvm->lock);
 		mutex_lock(&matrix_dev->mdevs_lock);
 
 		do_remove = bitmap_and(aprem, ap_remove,
@@ -2619,7 +2631,8 @@ static void vfio_ap_mdev_cfg_remove(unsi
 						    cdrem);
 
 		mutex_unlock(&matrix_dev->mdevs_lock);
-		mutex_unlock(&matrix_mdev->kvm->lock);
+		if (matrix_mdev->kvm)
+			mutex_unlock(&matrix_mdev->kvm->lock);
 	}
 }
 
@@ -2816,9 +2829,6 @@ static void vfio_ap_mdev_hot_plug_cfg(st
 	DECLARE_BITMAP(apm_filtered, AP_DEVICES);
 	bool filter_domains, filter_adapters, filter_cdoms, do_hotplug = false;
 
-	mutex_lock(&matrix_mdev->kvm->lock);
-	mutex_lock(&matrix_dev->mdevs_lock);
-
 	filter_adapters = bitmap_intersects(matrix_mdev->matrix.apm,
 					    matrix_mdev->apm_add, AP_DEVICES);
 	filter_domains = bitmap_intersects(matrix_mdev->matrix.aqm,
@@ -2836,9 +2846,6 @@ static void vfio_ap_mdev_hot_plug_cfg(st
 		vfio_ap_mdev_update_guest_apcb(matrix_mdev);
 
 	reset_queues_for_apids(matrix_mdev, apm_filtered);
-
-	mutex_unlock(&matrix_dev->mdevs_lock);
-	mutex_unlock(&matrix_mdev->kvm->lock);
 }
 
 void vfio_ap_on_scan_complete(struct ap_config_info *new_config_info,
@@ -2849,15 +2856,29 @@ void vfio_ap_on_scan_complete(struct ap_
 	mutex_lock(&matrix_dev->guests_lock);
 
 	list_for_each_entry(matrix_mdev, &matrix_dev->mdev_list, node) {
+		/*
+		 * The mdevs_lock must be held to access fields within matrix_mdev,
+		 * and kvm->lock must be taken before mdevs_lock to satisfy the lock
+		 * ordering requirement and prevent a lockdep splat.
+		 */
+		if (matrix_mdev->kvm)
+			mutex_lock(&matrix_mdev->kvm->lock);
+		mutex_lock(&matrix_dev->mdevs_lock);
+
 		if (bitmap_empty(matrix_mdev->apm_add, AP_DEVICES) &&
 		    bitmap_empty(matrix_mdev->aqm_add, AP_DOMAINS) &&
 		    bitmap_empty(matrix_mdev->adm_add, AP_DOMAINS))
-			continue;
+			goto do_unlock;
 
 		vfio_ap_mdev_hot_plug_cfg(matrix_mdev);
 		bitmap_clear(matrix_mdev->apm_add, 0, AP_DEVICES);
 		bitmap_clear(matrix_mdev->aqm_add, 0, AP_DOMAINS);
 		bitmap_clear(matrix_mdev->adm_add, 0, AP_DOMAINS);
+
+do_unlock:
+		mutex_unlock(&matrix_dev->mdevs_lock);
+		if (matrix_mdev->kvm)
+			mutex_unlock(&matrix_mdev->kvm->lock);
 	}
 
 	mutex_unlock(&matrix_dev->guests_lock);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 187/556] s390/vfio-ap: Fix hot-unplug skipped when last AP adapter or domain removed
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (185 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 186/556] s390/vfio-ap: Fix dereference matrix_mdev->kvm without checking for NULL Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 188/556] s390/vfio-ap: Fix missing lock required to access list of ap_matrix_mdev objects Greg Kroah-Hartman
                   ` (381 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Anthony Krowiak, Matthew Rosato,
	Christian Borntraeger

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Anthony Krowiak <akrowiak@linux.ibm.com>

commit 917f509bfb88048094dbb85c4e9dbc4d6fe4a886 upstream.

The vfio_ap_mdev_hot_unplug_cfg() function uses the return value of
bitmap_andnot() to determine whether the guest APCB needs to be updated.
However, bitmap_andnot() returns false when the resulting destination
bitmap is empty. This means that if the only adapter, domain or control
domain assigned to an mdev is removed from the host's AP configuration,
the bit is correctly cleared from the shadow APCB, but bitmap_andnot()
returns false because the result is an empty bitmap. Consequently,
do_hotplug remains 0 and vfio_ap_mdev_update_guest_apcb() is never called,
leaving the KVM guest with stale hardware access to the unplugged AP
devices.

Fix this by replacing the bitmap_andnot() return value check with
bitmap_intersects() to determine whether the shadow APCB actually
overlaps with the removal mask. If there is an intersection, call
bitmap_andnot() solely for its side effect of clearing the bits, then
unconditionally set do_hotplug to trigger the guest APCB update.

Fixes: eeb386aeb5b7c ("s390/vfio-ap: handle config changed and scan complete notification")
Cc: stable@vger.kernel.org
Signed-off-by: Anthony Krowiak <akrowiak@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/s390/crypto/vfio_ap_ops.c |   30 +++++++++++++++++-------------
 1 file changed, 17 insertions(+), 13 deletions(-)

--- a/drivers/s390/crypto/vfio_ap_ops.c
+++ b/drivers/s390/crypto/vfio_ap_ops.c
@@ -2554,24 +2554,28 @@ static void vfio_ap_mdev_hot_unplug_cfg(
 					unsigned long *aqrem,
 					unsigned long *cdrem)
 {
-	int do_hotplug = 0;
+	bool do_hotplug = false;
 
-	if (!bitmap_empty(aprem, AP_DEVICES)) {
-		do_hotplug |= bitmap_andnot(matrix_mdev->shadow_apcb.apm,
-					    matrix_mdev->shadow_apcb.apm,
-					    aprem, AP_DEVICES);
+	if (bitmap_intersects(matrix_mdev->shadow_apcb.apm, aprem, AP_DEVICES)) {
+		bitmap_andnot(matrix_mdev->shadow_apcb.apm,
+			      matrix_mdev->shadow_apcb.apm,
+			      aprem, AP_DEVICES);
+		do_hotplug = true;
 	}
 
-	if (!bitmap_empty(aqrem, AP_DOMAINS)) {
-		do_hotplug |= bitmap_andnot(matrix_mdev->shadow_apcb.aqm,
-					    matrix_mdev->shadow_apcb.aqm,
-					    aqrem, AP_DEVICES);
+	if (bitmap_intersects(matrix_mdev->shadow_apcb.aqm, aqrem, AP_DOMAINS)) {
+		bitmap_andnot(matrix_mdev->shadow_apcb.aqm,
+			      matrix_mdev->shadow_apcb.aqm,
+			      aqrem, AP_DOMAINS);
+		do_hotplug = true;
 	}
 
-	if (!bitmap_empty(cdrem, AP_DOMAINS))
-		do_hotplug |= bitmap_andnot(matrix_mdev->shadow_apcb.adm,
-					    matrix_mdev->shadow_apcb.adm,
-					    cdrem, AP_DOMAINS);
+	if (bitmap_intersects(matrix_mdev->shadow_apcb.adm, cdrem, AP_DOMAINS)) {
+		bitmap_andnot(matrix_mdev->shadow_apcb.adm,
+			      matrix_mdev->shadow_apcb.adm,
+			      cdrem, AP_DOMAINS);
+		do_hotplug = true;
+	}
 
 	if (do_hotplug)
 		vfio_ap_mdev_update_guest_apcb(matrix_mdev);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 188/556] s390/vfio-ap: Fix missing lock required to access list of ap_matrix_mdev objects
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (186 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 187/556] s390/vfio-ap: Fix hot-unplug skipped when last AP adapter or domain removed Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 189/556] s390/vfio-ap: Fix NULL deref in status_show() during queue probe Greg Kroah-Hartman
                   ` (380 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Anthony Krowiak, Matthew Rosato,
	Christian Borntraeger

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Anthony Krowiak <akrowiak@linux.ibm.com>

commit 7fa61c29850d05e40ca9ed41bfdf57673023f581 upstream.

In order to traverse or add/remove ap_matrix_mdev objects in the
matrix_dev->mdev_list, the matrix_dev->guests_lock mutex must be held.
There are two functions that access the list without holding the mutex:

vfio_ap_mdev_probe function
~~~~~~~~~~~~~~~~~~~~~~~~~~~
The vfio_ap_mdev_probe function uses the matrix_dev->mdevs_lock
mutex to guard the add of a newly created ap_matrix_mdev object to the
matrix_dev->mdev_list. This mutex does not protect list access; its purpose
is to guard against concurrent access to fields contained in an
ap_matrix_mdev object. This could lead to kernel memory corruption or
use-after-free if another mdev is created or removed concurrently.

The adding of an ap_matrix_mdev object to matrix_dev->mdev_list
is now guarded by the matrix_dev->guests_lock which is the correct
way to protect against concurrent mdev_list access.

Also removed the following two lines of code because the matrix_mdev is
allocated via vfio_alloc_device macro which uses kzalloc, so req_trigger
and cfg_chg_trigger are already zero-initialised when the struct is
allocated before the call to vfio_register_emulated_iommu_dev. This
prevents a window whereby these triggers are set to NULL after
the device is exposed to userspace.

matrix_mdev->req_trigger = NULL;
matrix_mdev->cfg_chg_trigger = NULL;

vfio_ap_mdev_for_queue function
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
The status_show function that supports display of the status attribute of
the devices in /sys/bus/ap/devices calls the vfio_ap_mdev_for_queue
function which iterates the matrix_dev->mdev_list to find the object
representing the queue device whose status is to be displayed. In order to
traverse this list, the matrix_dev->guests_lock mutex must be held.

To fix this, the guests_lock mutex is taken prior to taking the
matrix_dev->mdevs_lock mutex in the status_show function. It is taken
there rather than the vfio_ap_mdev_for_queue function - where it is
needed - because it must be taken prior to the mdevs_lock mutex in order to
adhere to the proper locking order and prevent a lockdep splat; also
because the mdevs_lock is needed there to access fields within
the matrix_mdev object in that function.

See the vfio-ap-locking.rst in the linux kernel tree.

Fixes: 2c1ee8983aa3 ("s390/vfio-ap: prepare for dynamic update of guest's APCB on queue probe/remove")
Cc: stable@vger.kernel.org
Signed-off-by: Anthony Krowiak <akrowiak@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/s390/crypto/vfio_ap_ops.c |   27 +++++++++++++++++++++++----
 1 file changed, 23 insertions(+), 4 deletions(-)

--- a/drivers/s390/crypto/vfio_ap_ops.c
+++ b/drivers/s390/crypto/vfio_ap_ops.c
@@ -807,12 +807,17 @@ static int vfio_ap_mdev_probe(struct mde
 	ret = vfio_register_emulated_iommu_dev(&matrix_mdev->vdev);
 	if (ret)
 		goto err_put_vdev;
-	matrix_mdev->req_trigger = NULL;
-	matrix_mdev->cfg_chg_trigger = NULL;
+
+	/*
+	 * Take the matrix_dev->guests_lock mutex before adding the matrix_mdev
+	 * to the mdev_list. All functions that traverse the list must also hold
+	 * this lock to guard against additions to or removals from the list
+	 * while it is being traversed.
+	 */
+	mutex_lock(&matrix_dev->guests_lock);
 	dev_set_drvdata(&mdev->dev, matrix_mdev);
-	mutex_lock(&matrix_dev->mdevs_lock);
 	list_add(&matrix_mdev->node, &matrix_dev->mdev_list);
-	mutex_unlock(&matrix_dev->mdevs_lock);
+	mutex_unlock(&matrix_dev->guests_lock);
 	return 0;
 
 err_put_vdev:
@@ -2292,6 +2297,8 @@ static struct ap_matrix_mdev *vfio_ap_md
 	unsigned long apid = AP_QID_CARD(q->apqn);
 	unsigned long apqi = AP_QID_QUEUE(q->apqn);
 
+	lockdep_assert_held(&matrix_dev->guests_lock);
+
 	list_for_each_entry(matrix_mdev, &matrix_dev->mdev_list, node) {
 		if (test_bit_inv(apid, matrix_mdev->matrix.apm) &&
 		    test_bit_inv(apqi, matrix_mdev->matrix.aqm))
@@ -2311,6 +2318,7 @@ static ssize_t status_show(struct device
 	struct ap_matrix_mdev *matrix_mdev;
 	struct ap_device *apdev = to_ap_dev(dev);
 
+	mutex_lock(&matrix_dev->guests_lock);
 	mutex_lock(&matrix_dev->mdevs_lock);
 	q = dev_get_drvdata(&apdev->device);
 	matrix_mdev = vfio_ap_mdev_for_queue(q);
@@ -2338,6 +2346,7 @@ static ssize_t status_show(struct device
 	}
 
 	mutex_unlock(&matrix_dev->mdevs_lock);
+	mutex_unlock(&matrix_dev->guests_lock);
 
 	return nchars;
 }
@@ -2760,6 +2769,12 @@ static void vfio_ap_mdev_cfg_add(unsigne
 
 	vfio_ap_filter_apid_by_qtype(apm_add, aqm_add);
 
+	/*
+	 * It is safe to traverse this list here because the
+	 * required guard - matrix_dev->guests_lock - is taken in the
+	 * vfio_ap_on_cfg_changed function prior to this function getting
+	 * called.
+	 */
 	list_for_each_entry(matrix_mdev, &matrix_dev->mdev_list, node) {
 		bitmap_and(matrix_mdev->apm_add,
 			   matrix_mdev->matrix.apm, apm_add, AP_DEVICES);
@@ -2819,6 +2834,10 @@ void vfio_ap_on_cfg_changed(struct ap_co
 	if (!cur_cfg_info || !prev_cfg_info)
 		return;
 
+	/*
+	 * Take the guests_lock mutex here to guard access to the
+	 * matrix_dev->mdev_list in the two functions called below.
+	 */
 	mutex_lock(&matrix_dev->guests_lock);
 
 	vfio_ap_mdev_on_cfg_remove(cur_cfg_info, prev_cfg_info);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 189/556] s390/vfio-ap: Fix NULL deref in status_show() during queue probe
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (187 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 188/556] s390/vfio-ap: Fix missing lock required to access list of ap_matrix_mdev objects Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 190/556] s390/vfio-ap: fix potential use of uninitialized apm_filtered bitmap Greg Kroah-Hartman
                   ` (379 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Anthony Krowiak, Matthew Rosato,
	Christian Borntraeger

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Anthony Krowiak <akrowiak@linux.ibm.com>

commit dd6f4ef6f8a37412909ad787c837332fb070159c upstream.

When vfio_ap_mdev_probe_queue() creates the sysfs attribute group,
the queue's driver data has not yet been set. A concurrent read of
the 'status' attribute can therefore call dev_get_drvdata() and
get NULL, which is then passed directly to
vfio_ap_mdev_for_queue() where q->apqn is unconditionally
dereferenced, causing a NULL pointer dereference.

Fix this by acquiring the update locks before calling
sysfs_create_group(). The status_show() function acquires
guests_lock before reading the driver data, so any concurrent
read will block until after dev_set_drvdata() has been called
and the update locks are released.

As a bonus, the APQN no longer needs to be read from the queue
struct after allocation — it can be read directly from apdev
before allocation and stored in a local variable, which is then
assigned to q->apqn once the allocation succeeds.

Fixes: 260f3ea141382 ("s390/vfio-ap: move probe and remove callbacks to vfio_ap_ops.c")
Cc: stable@vger.kernel.org
Signed-off-by: Anthony Krowiak <akrowiak@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/s390/crypto/vfio_ap_ops.c |   33 +++++++++++++++++++++++++++++----
 1 file changed, 29 insertions(+), 4 deletions(-)

--- a/drivers/s390/crypto/vfio_ap_ops.c
+++ b/drivers/s390/crypto/vfio_ap_ops.c
@@ -2321,6 +2321,23 @@ static ssize_t status_show(struct device
 	mutex_lock(&matrix_dev->guests_lock);
 	mutex_lock(&matrix_dev->mdevs_lock);
 	q = dev_get_drvdata(&apdev->device);
+
+	/*
+	 * Make sure the drvdata has been set before proceeding. There is a
+	 * possibility that the drvdata was not set if the vfio_ap_queue object
+	 * could not be allocated when the queue device was probed. In that case,
+	 * the locks used in vfio_ap_mdev_probe_queue() are released prior to
+	 * removing the sysfs status attribute to avoid a lockdep
+	 * splat. That opens a very small window where the status attribute is
+	 * still available without the vfio_ap_queue object having been
+	 * stored in the device drvdata. In that case, indicate the queue is not
+	 * assigned.
+	 */
+	if (!q) {
+		nchars = sysfs_emit(buf, "%s\n", AP_QUEUE_UNASSIGNED);
+		goto done;
+	}
+
 	matrix_mdev = vfio_ap_mdev_for_queue(q);
 
 	/* If the queue is assigned to the matrix mediated device, then
@@ -2345,6 +2362,7 @@ static ssize_t status_show(struct device
 		nchars = sysfs_emit(buf, "%s\n", AP_QUEUE_UNASSIGNED);
 	}
 
+done:
 	mutex_unlock(&matrix_dev->mdevs_lock);
 	mutex_unlock(&matrix_dev->guests_lock);
 
@@ -2419,14 +2437,17 @@ void vfio_ap_mdev_unregister(void)
 
 int vfio_ap_mdev_probe_queue(struct ap_device *apdev)
 {
-	int ret;
+	int ret, apqn;
 	struct vfio_ap_queue *q;
 	DECLARE_BITMAP(apm_filtered, AP_DEVICES);
 	struct ap_matrix_mdev *matrix_mdev;
 
+	apqn = to_ap_queue(&apdev->device)->qid;
+	matrix_mdev = get_update_locks_by_apqn(apqn);
+
 	ret = sysfs_create_group(&apdev->device.kobj, &vfio_queue_attr_group);
 	if (ret)
-		return ret;
+		goto err_release_locks;
 
 	q = kzalloc_obj(*q);
 	if (!q) {
@@ -2434,11 +2455,10 @@ int vfio_ap_mdev_probe_queue(struct ap_d
 		goto err_remove_group;
 	}
 
-	q->apqn = to_ap_queue(&apdev->device)->qid;
+	q->apqn = apqn;
 	q->saved_isc = VFIO_AP_ISC_INVALID;
 	memset(&q->reset_status, 0, sizeof(q->reset_status));
 	INIT_WORK(&q->reset_work, apq_reset_check);
-	matrix_mdev = get_update_locks_by_apqn(q->apqn);
 
 	if (matrix_mdev) {
 		vfio_ap_mdev_link_queue(matrix_mdev, q);
@@ -2467,8 +2487,13 @@ done:
 	return ret;
 
 err_remove_group:
+	release_update_locks_for_mdev(matrix_mdev);
 	sysfs_remove_group(&apdev->device.kobj, &vfio_queue_attr_group);
 	return ret;
+
+err_release_locks:
+	release_update_locks_for_mdev(matrix_mdev);
+	return ret;
 }
 
 void vfio_ap_mdev_remove_queue(struct ap_device *apdev)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 190/556] s390/vfio-ap: fix potential use of uninitialized apm_filtered bitmap
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (188 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 189/556] s390/vfio-ap: Fix NULL deref in status_show() during queue probe Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 191/556] s390/vfio-ap: Fix required lock not held during update of ap_matrix_mdev object Greg Kroah-Hartman
                   ` (378 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Anthony Krowiak, Matthew Rosato,
	Christian Borntraeger

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Anthony Krowiak <akrowiak@linux.ibm.com>

commit bf09b9d7cd7890bc3a3b7eb63d5ece15f88bfde7 upstream.

The DECLARE_BITMAP(apm_filtered, AP_DEVICES) macro allocates the bitmap
on the stack without zero-initializing it.

In vfio_ap_mdev_hot_plug_cfg(), the vfio_ap_mdev_filter_matrix() function
is only called to initialize and populate apm_filtered if either
filter_adapters or filter_domains is true. If the hot plug configuration
change only adds control domains (meaning filter_cdoms is true, but
filter_adapters and filter_domains are both false),
vfio_ap_mdev_filter_matrix() is bypassed.

Consequently, apm_filtered is passed to reset_queues_for_apids() with
uninitialized stack garbage. This can cause reset_queues_for_apids() to
interpret arbitrary stack garbage bits as valid APIDs to reset, potentially
performing unintended guest hardware queue resets.

Fix this by zero-initializing the apm_filtered bitmap at the beginning of
vfio_ap_mdev_hot_plug_cfg() using bitmap_zero().

Fixes: eeb386aeb5b7c ("s390/vfio-ap: handle config changed and scan complete notification")
Cc: stable@vger.kernel.org
Signed-off-by: Anthony Krowiak <akrowiak@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/s390/crypto/vfio_ap_ops.c |    9 +++++++++
 1 file changed, 9 insertions(+)

--- a/drivers/s390/crypto/vfio_ap_ops.c
+++ b/drivers/s390/crypto/vfio_ap_ops.c
@@ -2877,6 +2877,15 @@ static void vfio_ap_mdev_hot_plug_cfg(st
 	DECLARE_BITMAP(apm_filtered, AP_DEVICES);
 	bool filter_domains, filter_adapters, filter_cdoms, do_hotplug = false;
 
+	/*
+	 * Zero out the apm_filtered bitmap in case there are no adapters or
+	 * domains to be added, but only control domains. In that case,
+	 * vfio_ap_mdev_filter_matrix() - which initializes apm_filtered - will
+	 * not get called and the reset_queues_for_apids will crash because it
+	 * will access an uninitialized bitmap.
+	 */
+	bitmap_zero(apm_filtered, AP_DEVICES);
+
 	filter_adapters = bitmap_intersects(matrix_mdev->matrix.apm,
 					    matrix_mdev->apm_add, AP_DEVICES);
 	filter_domains = bitmap_intersects(matrix_mdev->matrix.aqm,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 191/556] s390/vfio-ap: Fix required lock not held during update of ap_matrix_mdev object
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (189 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 190/556] s390/vfio-ap: fix potential use of uninitialized apm_filtered bitmap Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 192/556] mtd: afs: validate v2 image info bounds Greg Kroah-Hartman
                   ` (377 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Anthony Krowiak, Matthew Rosato,
	Christian Borntraeger

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Anthony Krowiak <akrowiak@linux.ibm.com>

commit 5883528250be57fa92270459b33603ff52de0a91 upstream.

In the vfio_ap_mdev_cfg_add function, the apm_add, aqm_add and adm_add
fields of an ap_matrix_mdev object fields are modified while not holding
the matrix_dev->mdevs_lock. This lock must be held while making these
to guard against a race condition with another caller that may be
concurrently modifying these fields or any of the fields in the
matrix_mdev->matrix.

Fixes: eeb386aeb5b7c ("s390/vfio-ap: handle config changed and scan complete notification")
Cc: stable@vger.kernel.org
Signed-off-by: Anthony Krowiak <akrowiak@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/s390/crypto/vfio_ap_ops.c |    8 ++++++++
 1 file changed, 8 insertions(+)

--- a/drivers/s390/crypto/vfio_ap_ops.c
+++ b/drivers/s390/crypto/vfio_ap_ops.c
@@ -2801,12 +2801,20 @@ static void vfio_ap_mdev_cfg_add(unsigne
 	 * called.
 	 */
 	list_for_each_entry(matrix_mdev, &matrix_dev->mdev_list, node) {
+		/*
+		 * The mdevs_lock must be held in order to access fields
+		 * within matrix_mdev
+		 */
+		mutex_lock(&matrix_dev->mdevs_lock);
+
 		bitmap_and(matrix_mdev->apm_add,
 			   matrix_mdev->matrix.apm, apm_add, AP_DEVICES);
 		bitmap_and(matrix_mdev->aqm_add,
 			   matrix_mdev->matrix.aqm, aqm_add, AP_DOMAINS);
 		bitmap_and(matrix_mdev->adm_add,
 			   matrix_mdev->matrix.adm, adm_add, AP_DEVICES);
+
+		mutex_unlock(&matrix_dev->mdevs_lock);
 	}
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 192/556] mtd: afs: validate v2 image info bounds
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (190 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 191/556] s390/vfio-ap: Fix required lock not held during update of ap_matrix_mdev object Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 193/556] mtd: mtdoops: free page bitmap when the backing MTD is removed Greg Kroah-Hartman
                   ` (376 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Linus Walleij,
	Miquel Raynal

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pengpeng Hou <pengpeng@iscas.ac.cn>

commit e9290031f736e99ad17c25c00311c92c266843b7 upstream.

The AFS v2 parser uses footer[8] to locate the image information block
inside the current erase block, then uses the image information
region_count to walk entries from a fixed local array. The footer offset
and region count come from flash contents and are not checked against the
erase block or the local image-info array before use.

Reject v2 entries whose image information offset would underflow the
erase block calculation, and reject region counts that cannot fit in the
local image-info array before walking region entries.

Fixes: b7cf5e2830bb ("mtd: afs: add v2 partition parsing")
Cc: stable@vger.kernel.org
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Acked-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/mtd/parsers/afs.c |    7 +++++++
 1 file changed, 7 insertions(+)

--- a/drivers/mtd/parsers/afs.c
+++ b/drivers/mtd/parsers/afs.c
@@ -235,6 +235,9 @@ static int afs_parse_v2_partition(struct
 	pr_debug("Parsing v2 partition @%08x-%08x\n",
 		 off, off + mtd->erasesize);
 
+	if (mtd->erasesize < sizeof(footer))
+		return -EINVAL;
+
 	/* First read the footer */
 	ptr = off + mtd->erasesize - sizeof(footer);
 	ret = mtd_read(mtd, ptr, sizeof(footer), &sz, (u_char *)footer);
@@ -245,6 +248,8 @@ static int afs_parse_v2_partition(struct
 	}
 	name = (char *) &footer[0];
 	version = footer[9];
+	if (footer[8] > mtd->erasesize - sizeof(footer))
+		return -EINVAL;
 	ptr = off + mtd->erasesize - sizeof(footer) - footer[8];
 
 	pr_debug("found image \"%s\", version %08x, info @%08x\n",
@@ -278,6 +283,8 @@ static int afs_parse_v2_partition(struct
 	entrypoint = imginfo[pad];
 	attributes = imginfo[pad+1];
 	region_count = imginfo[pad+2];
+	if (region_count > (ARRAY_SIZE(imginfo) - pad - 3) / 4)
+		return -EINVAL;
 	block_start = imginfo[20];
 	block_end = imginfo[21];
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 193/556] mtd: mtdoops: free page bitmap when the backing MTD is removed
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (191 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 192/556] mtd: afs: validate v2 image info bounds Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 194/556] mtd: nand: realtek-ecc: add missing MODULE_DEVICE_TABLE() Greg Kroah-Hartman
                   ` (375 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Xu Rao, Miquel Raynal

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Xu Rao <raoxu@uniontech.com>

commit 956e7da12c114f13c63d126ab1d79c3b6a819060 upstream.

mtdoops_notify_add() allocates oops_page_used when the configured MTD
device is registered.  mtdoops_notify_remove() detaches from that device
but leaves the bitmap allocated.  If the same MTD device is later
registered again, the add path allocates a new bitmap and overwrites the
old pointer, leaking one vmalloc allocation per remove/add cycle.

This is only visible when the backing MTD device can disappear and be
registered again while mtdoops remains loaded, so the usual static MTD
case does not expose it.

Free the bitmap after unregistering the dumper and flushing the pending
workers, then clear the pointer and page count before a later attach can
allocate fresh state.  Clearing the pointer also keeps the module exit
path from freeing the same bitmap a second time after a remove event.

Fixes: be95745f0167 ("mtd: mtdoops: keep track of used/unused pages in an array")
Cc: stable@vger.kernel.org
Signed-off-by: Xu Rao <raoxu@uniontech.com>
Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/mtd/mtdoops.c |    3 +++
 1 file changed, 3 insertions(+)

--- a/drivers/mtd/mtdoops.c
+++ b/drivers/mtd/mtdoops.c
@@ -392,6 +392,9 @@ static void mtdoops_notify_remove(struct
 	cxt->mtd = NULL;
 	flush_work(&cxt->work_erase);
 	flush_work(&cxt->work_write);
+	vfree(cxt->oops_page_used);
+	cxt->oops_page_used = NULL;
+	cxt->oops_pages = 0;
 }
 
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 194/556] mtd: nand: realtek-ecc: add missing MODULE_DEVICE_TABLE()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (192 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 193/556] mtd: mtdoops: free page bitmap when the backing MTD is removed Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 195/556] mtd: rawnand: pl353: Make sure we use the monolithic helpers for raw accesses Greg Kroah-Hartman
                   ` (374 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Miquel Raynal

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pengpeng Hou <pengpeng@iscas.ac.cn>

commit 5b2444b4d575d8117809c57801562ef37ca2d4af upstream.

The Realtek external ECC engine driver has an OF match table wired into
its platform driver, but the table is not exported with
MODULE_DEVICE_TABLE().

When the driver is built as a module, the missing OF module alias
prevents automatic module loading from the compatible string.

Add the missing MODULE_DEVICE_TABLE() entry.

Fixes: 3148d0e5b1c5 ("mtd: nand: realtek-ecc: Add Realtek external ECC engine support")
Cc: stable@vger.kernel.org
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/mtd/nand/ecc-realtek.c |    1 +
 1 file changed, 1 insertion(+)

--- a/drivers/mtd/nand/ecc-realtek.c
+++ b/drivers/mtd/nand/ecc-realtek.c
@@ -450,6 +450,7 @@ static const struct of_device_id rtl_ecc
 	},
 	{ /* sentinel */ },
 };
+MODULE_DEVICE_TABLE(of, rtl_ecc_of_ids);
 
 static struct platform_driver rtl_ecc_driver = {
 	.driver	= {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 195/556] mtd: rawnand: pl353: Make sure we use the monolithic helpers for raw accesses
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (193 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 194/556] mtd: nand: realtek-ecc: add missing MODULE_DEVICE_TABLE() Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 196/556] mtd: rawnand: sunxi: group controller delay tables Greg Kroah-Hartman
                   ` (373 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Andrea Scian, Miquel Raynal (DAVE),
	Michal Simek

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Miquel Raynal (DAVE) <miquel.raynal@bootlin.com>

commit 80ecacd054ffeb60cd28e46ed5cd6bd0d2de318b upstream.

Any access not using the hardware ECC engine should be monolithic
because the controller has its very own way of handling the end of a
transaction during operation configuration, so we cannot easily make
repeated reads.

This has the side effect of fixing support for software ECC engines.

Suggested-by: Andrea Scian <andrea.scian@dave.eu>
Cc: stable@vger.kernel.org
Fixes: 08d8c62164a3 ("mtd: rawnand: pl353: Add support for the ARM PL353 SMC NAND controller")
Signed-off-by: Miquel Raynal (DAVE) <miquel.raynal@bootlin.com>
Acked-by: Michal Simek <michal.simek@amd.com>
Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/mtd/nand/raw/pl35x-nand-controller.c |    5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

--- a/drivers/mtd/nand/raw/pl35x-nand-controller.c
+++ b/drivers/mtd/nand/raw/pl35x-nand-controller.c
@@ -914,7 +914,6 @@ static int pl35x_nand_init_hw_ecc_contro
 	chip->ecc.steps = mtd->writesize / chip->ecc.size;
 	chip->ecc.read_page = pl35x_nand_read_page_hwecc;
 	chip->ecc.write_page = pl35x_nand_write_page_hwecc;
-	chip->ecc.write_page_raw = nand_monolithic_write_page_raw;
 	pl35x_smc_set_ecc_pg_size(nfc, chip, mtd->writesize);
 
 	nfc->ecc_buf = devm_kmalloc(nfc->dev, chip->ecc.bytes * chip->ecc.steps,
@@ -981,7 +980,6 @@ static int pl35x_nand_attach_chip(struct
 	case NAND_ECC_ENGINE_TYPE_NONE:
 	case NAND_ECC_ENGINE_TYPE_SOFT:
 		dev_dbg(nfc->dev, "Using software ECC (Hamming 1-bit/512B)\n");
-		chip->ecc.write_page_raw = nand_monolithic_write_page_raw;
 		break;
 	case NAND_ECC_ENGINE_TYPE_ON_HOST:
 		dev_dbg(nfc->dev, "Using hardware ECC\n");
@@ -995,6 +993,9 @@ static int pl35x_nand_attach_chip(struct
 		return -EINVAL;
 	}
 
+	chip->ecc.read_page_raw = nand_monolithic_read_page_raw;
+	chip->ecc.write_page_raw = nand_monolithic_write_page_raw;
+
 	return 0;
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 196/556] mtd: rawnand: sunxi: group controller delay tables
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (194 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 195/556] mtd: rawnand: pl353: Make sure we use the monolithic helpers for raw accesses Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 197/556] mtd: rawnand: sunxi: describe tADL and tWHR delays Greg Kroah-Hartman
                   ` (372 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, James Hilliard, Miquel Raynal

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: James Hilliard <james.hilliard1@gmail.com>

commit 9f2e033754c6c023150f184b4e72bbcc5d6eea13 upstream.

The tWB and tRHW timing field encodings are controller properties, but
they currently live in standalone lookup tables.

Group them in a timing descriptor selected through the controller
capability data. Point every existing controller at the legacy values so
this is a pure preparation change.

Fixes: 88fd4e4deae8 ("mtd: rawnand: sunxi: Add support for H616 nand controller")
Cc: stable@vger.kernel.org
Signed-off-by: James Hilliard <james.hilliard1@gmail.com>
Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/mtd/nand/raw/sunxi_nand.c |   36 ++++++++++++++++++++++++++++--------
 1 file changed, 28 insertions(+), 8 deletions(-)

--- a/drivers/mtd/nand/raw/sunxi_nand.c
+++ b/drivers/mtd/nand/raw/sunxi_nand.c
@@ -237,6 +237,14 @@ struct sunxi_nand_hw_ecc {
 	u32 ecc_ctl;
 };
 
+#define SUNXI_NFC_TIMING_STEPS	4
+
+/* Delay arrays contain internal NDFC clock cycles for field values 0 to 3. */
+struct sunxi_nfc_timings {
+	s32 tWB[SUNXI_NFC_TIMING_STEPS];
+	s32 tRHW[SUNXI_NFC_TIMING_STEPS];
+};
+
 /**
  * struct sunxi_nand_chip - stores NAND chip device related information
  *
@@ -301,6 +309,7 @@ static inline struct sunxi_nand_chip *to
  *			bytes to write
  * @nuser_data_tab:	Size of @user_data_len_tab
  * @sram_size:		Size of the NAND controller SRAM
+ * @timings:		Controller timing characteristics
  */
 struct sunxi_nfc_caps {
 	bool has_mdma;
@@ -327,6 +336,7 @@ struct sunxi_nfc_caps {
 	unsigned int nuser_data_tab;
 	unsigned int max_ecc_steps;
 	int sram_size;
+	const struct sunxi_nfc_timings *timings;
 };
 
 /**
@@ -1667,8 +1677,10 @@ static int sunxi_nfc_hw_ecc_write_oob(st
 	return nand_prog_page_end_op(nand);
 }
 
-static const s32 tWB_lut[] = {6, 12, 16, 20};
-static const s32 tRHW_lut[] = {4, 8, 12, 20};
+static const struct sunxi_nfc_timings sun4i_a10_nfc_timings = {
+	.tWB = { 6, 12, 16, 20 },
+	.tRHW = { 4, 8, 12, 20 },
+};
 
 static int _sunxi_nand_lookup_timing(const s32 *lut, int lut_size, u32 duration,
 		u32 clk_period)
@@ -1693,6 +1705,7 @@ static int sunxi_nfc_setup_interface(str
 {
 	struct sunxi_nand_chip *sunxi_nand = to_sunxi_nand(nand);
 	struct sunxi_nfc *nfc = to_sunxi_nfc(sunxi_nand->nand.controller);
+	const struct sunxi_nfc_timings *nfc_timings = nfc->caps->timings;
 	const struct nand_sdr_timings *timings;
 	u32 min_clk_period = 0;
 	s32 tWB, tADL, tWHR, tRHW, tCAD;
@@ -1763,8 +1776,10 @@ static int sunxi_nfc_setup_interface(str
 		min_clk_period = DIV_ROUND_UP(timings->tWC_min, 2);
 
 	/* T16 - T19 + tCAD */
-	if (timings->tWB_max > (min_clk_period * 20))
-		min_clk_period = DIV_ROUND_UP(timings->tWB_max, 20);
+	if (timings->tWB_max >
+	    (min_clk_period * nfc_timings->tWB[SUNXI_NFC_TIMING_STEPS - 1]))
+		min_clk_period = DIV_ROUND_UP(timings->tWB_max,
+					      nfc_timings->tWB[SUNXI_NFC_TIMING_STEPS - 1]);
 
 	if (timings->tADL_min > (min_clk_period * 32))
 		min_clk_period = DIV_ROUND_UP(timings->tADL_min, 32);
@@ -1772,8 +1787,10 @@ static int sunxi_nfc_setup_interface(str
 	if (timings->tWHR_min > (min_clk_period * 32))
 		min_clk_period = DIV_ROUND_UP(timings->tWHR_min, 32);
 
-	if (timings->tRHW_min > (min_clk_period * 20))
-		min_clk_period = DIV_ROUND_UP(timings->tRHW_min, 20);
+	if (timings->tRHW_min >
+	    (min_clk_period * nfc_timings->tRHW[SUNXI_NFC_TIMING_STEPS - 1]))
+		min_clk_period = DIV_ROUND_UP(timings->tRHW_min,
+					      nfc_timings->tRHW[SUNXI_NFC_TIMING_STEPS - 1]);
 
 	/*
 	 * In non-EDO, tREA should be less than tRP to guarantee that the
@@ -1789,7 +1806,7 @@ static int sunxi_nfc_setup_interface(str
 	if (timings->tREA_max > min_clk_period && !timings->tRLOH_min)
 		min_clk_period = timings->tREA_max;
 
-	tWB  = sunxi_nand_lookup_timing(tWB_lut, timings->tWB_max,
+	tWB  = sunxi_nand_lookup_timing(nfc_timings->tWB, timings->tWB_max,
 					min_clk_period);
 	if (tWB < 0) {
 		dev_err(nfc->dev, "unsupported tWB\n");
@@ -1808,7 +1825,7 @@ static int sunxi_nfc_setup_interface(str
 		return -EINVAL;
 	}
 
-	tRHW = sunxi_nand_lookup_timing(tRHW_lut, timings->tRHW_min,
+	tRHW = sunxi_nand_lookup_timing(nfc_timings->tRHW, timings->tRHW_min,
 					min_clk_period);
 	if (tRHW < 0) {
 		dev_err(nfc->dev, "unsupported tRHW\n");
@@ -2595,6 +2612,7 @@ static const struct sunxi_nfc_caps sunxi
 	.nstrengths = ARRAY_SIZE(sunxi_ecc_strengths_a10),
 	.max_ecc_steps = 16,
 	.sram_size = 1024,
+	.timings = &sun4i_a10_nfc_timings,
 };
 
 static const struct sunxi_nfc_caps sunxi_nfc_a23_caps = {
@@ -2617,6 +2635,7 @@ static const struct sunxi_nfc_caps sunxi
 	.nstrengths = ARRAY_SIZE(sunxi_ecc_strengths_a10),
 	.max_ecc_steps = 16,
 	.sram_size = 1024,
+	.timings = &sun4i_a10_nfc_timings,
 };
 
 static const struct sunxi_nfc_caps sunxi_nfc_h616_caps = {
@@ -2641,6 +2660,7 @@ static const struct sunxi_nfc_caps sunxi
 	.nuser_data_tab = ARRAY_SIZE(sunxi_user_data_len_h6),
 	.max_ecc_steps = 32,
 	.sram_size = 8192,
+	.timings = &sun4i_a10_nfc_timings,
 };
 
 static const struct of_device_id sunxi_nfc_ids[] = {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 197/556] mtd: rawnand: sunxi: describe tADL and tWHR delays
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (195 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 196/556] mtd: rawnand: sunxi: group controller delay tables Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 198/556] mtd: rawnand: sunxi: fix H6/H616 controller timings Greg Kroah-Hartman
                   ` (371 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, James Hilliard, Miquel Raynal

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: James Hilliard <james.hilliard1@gmail.com>

commit 147f2a5743f8864bfc265654b1856af11c8c0031 upstream.

The tADL and tWHR timing fields use four encoded delays, but the driver
currently derives their values with a shift. This hides the actual
controller timing characteristics and lets the clock solver select a
32-cycle delay that the fields cannot encode.

Describe the legacy 7, 15, 23 and 31 cycle thresholds explicitly and use
the tables for both clock selection and field lookup. This prepares the
driver for controllers with different encodings.

Fixes: 88fd4e4deae8 ("mtd: rawnand: sunxi: Add support for H616 nand controller")
Cc: stable@vger.kernel.org
Signed-off-by: James Hilliard <james.hilliard1@gmail.com>
Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/mtd/nand/raw/sunxi_nand.c |   32 +++++++++++++++++++++-----------
 1 file changed, 21 insertions(+), 11 deletions(-)

--- a/drivers/mtd/nand/raw/sunxi_nand.c
+++ b/drivers/mtd/nand/raw/sunxi_nand.c
@@ -242,6 +242,8 @@ struct sunxi_nand_hw_ecc {
 /* Delay arrays contain internal NDFC clock cycles for field values 0 to 3. */
 struct sunxi_nfc_timings {
 	s32 tWB[SUNXI_NFC_TIMING_STEPS];
+	s32 tADL[SUNXI_NFC_TIMING_STEPS];
+	s32 tWHR[SUNXI_NFC_TIMING_STEPS];
 	s32 tRHW[SUNXI_NFC_TIMING_STEPS];
 };
 
@@ -1679,6 +1681,8 @@ static int sunxi_nfc_hw_ecc_write_oob(st
 
 static const struct sunxi_nfc_timings sun4i_a10_nfc_timings = {
 	.tWB = { 6, 12, 16, 20 },
+	.tADL = { 7, 15, 23, 31 },
+	.tWHR = { 7, 15, 23, 31 },
 	.tRHW = { 4, 8, 12, 20 },
 };
 
@@ -1781,11 +1785,15 @@ static int sunxi_nfc_setup_interface(str
 		min_clk_period = DIV_ROUND_UP(timings->tWB_max,
 					      nfc_timings->tWB[SUNXI_NFC_TIMING_STEPS - 1]);
 
-	if (timings->tADL_min > (min_clk_period * 32))
-		min_clk_period = DIV_ROUND_UP(timings->tADL_min, 32);
-
-	if (timings->tWHR_min > (min_clk_period * 32))
-		min_clk_period = DIV_ROUND_UP(timings->tWHR_min, 32);
+	if (timings->tADL_min >
+	    (min_clk_period * nfc_timings->tADL[SUNXI_NFC_TIMING_STEPS - 1]))
+		min_clk_period = DIV_ROUND_UP(timings->tADL_min,
+					      nfc_timings->tADL[SUNXI_NFC_TIMING_STEPS - 1]);
+
+	if (timings->tWHR_min >
+	    (min_clk_period * nfc_timings->tWHR[SUNXI_NFC_TIMING_STEPS - 1]))
+		min_clk_period = DIV_ROUND_UP(timings->tWHR_min,
+					      nfc_timings->tWHR[SUNXI_NFC_TIMING_STEPS - 1]);
 
 	if (timings->tRHW_min >
 	    (min_clk_period * nfc_timings->tRHW[SUNXI_NFC_TIMING_STEPS - 1]))
@@ -1813,16 +1821,18 @@ static int sunxi_nfc_setup_interface(str
 		return tWB;
 	}
 
-	tADL = DIV_ROUND_UP(timings->tADL_min, min_clk_period) >> 3;
-	if (tADL > 3) {
+	tADL = sunxi_nand_lookup_timing(nfc_timings->tADL,
+					timings->tADL_min, min_clk_period);
+	if (tADL < 0) {
 		dev_err(nfc->dev, "unsupported tADL\n");
-		return -EINVAL;
+		return tADL;
 	}
 
-	tWHR = DIV_ROUND_UP(timings->tWHR_min, min_clk_period) >> 3;
-	if (tWHR > 3) {
+	tWHR = sunxi_nand_lookup_timing(nfc_timings->tWHR,
+					timings->tWHR_min, min_clk_period);
+	if (tWHR < 0) {
 		dev_err(nfc->dev, "unsupported tWHR\n");
-		return -EINVAL;
+		return tWHR;
 	}
 
 	tRHW = sunxi_nand_lookup_timing(nfc_timings->tRHW, timings->tRHW_min,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 198/556] mtd: rawnand: sunxi: fix H6/H616 controller timings
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (196 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 197/556] mtd: rawnand: sunxi: describe tADL and tWHR delays Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:37 ` [PATCH 7.2 199/556] mtd: rawnand: validate ONFI extended parameter page sections Greg Kroah-Hartman
                   ` (370 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, James Hilliard, Miquel Raynal

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: James Hilliard <james.hilliard1@gmail.com>

commit 15a3cbce32994141252bb4ecfe3ff3a5d22d0b4f upstream.

The NAND timing calculation assumes that command and address setup and
hold intervals T1-T4, T7 and T11 each take one controller clock. It also
uses the original A10 delay encodings for tWB, tADL, tWHR and tRHW.

The H6/H616 NDFC defines the setup and hold intervals as two internal
clock cycles and uses different delay encodings. Add the H616 timing
characteristics and select them through the controller capability data so
the clock solver and timing fields match the hardware.

Fixes: 88fd4e4deae8 ("mtd: rawnand: sunxi: Add support for H616 nand controller")
Cc: stable@vger.kernel.org
Signed-off-by: James Hilliard <james.hilliard1@gmail.com>
Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/mtd/nand/raw/sunxi_nand.c |   49 +++++++++++++++++++++++++++-----------
 1 file changed, 36 insertions(+), 13 deletions(-)

--- a/drivers/mtd/nand/raw/sunxi_nand.c
+++ b/drivers/mtd/nand/raw/sunxi_nand.c
@@ -241,6 +241,8 @@ struct sunxi_nand_hw_ecc {
 
 /* Delay arrays contain internal NDFC clock cycles for field values 0 to 3. */
 struct sunxi_nfc_timings {
+	/* Internal clock cycles used by T1-T4, T7 and T11. */
+	u8 setup_cycles;
 	s32 tWB[SUNXI_NFC_TIMING_STEPS];
 	s32 tADL[SUNXI_NFC_TIMING_STEPS];
 	s32 tWHR[SUNXI_NFC_TIMING_STEPS];
@@ -1680,12 +1682,21 @@ static int sunxi_nfc_hw_ecc_write_oob(st
 }
 
 static const struct sunxi_nfc_timings sun4i_a10_nfc_timings = {
+	.setup_cycles = 1,
 	.tWB = { 6, 12, 16, 20 },
 	.tADL = { 7, 15, 23, 31 },
 	.tWHR = { 7, 15, 23, 31 },
 	.tRHW = { 4, 8, 12, 20 },
 };
 
+static const struct sunxi_nfc_timings sun50i_h616_nfc_timings = {
+	.setup_cycles = 2,
+	.tWB = { 28, 44, 60, 76 },
+	.tADL = { 0, 12, 28, 44 },
+	.tWHR = { 0, 12, 28, 44 },
+	.tRHW = { 8, 24, 40, 56 },
+};
+
 static int _sunxi_nand_lookup_timing(const s32 *lut, int lut_size, u32 duration,
 		u32 clk_period)
 {
@@ -1720,20 +1731,28 @@ static int sunxi_nfc_setup_interface(str
 		return -ENOTSUPP;
 
 	/* T1 <=> tCLS */
-	if (timings->tCLS_min > min_clk_period)
-		min_clk_period = timings->tCLS_min;
+	if (timings->tCLS_min >
+	    min_clk_period * nfc_timings->setup_cycles)
+		min_clk_period = DIV_ROUND_UP(timings->tCLS_min,
+					      nfc_timings->setup_cycles);
 
 	/* T2 <=> tCLH */
-	if (timings->tCLH_min > min_clk_period)
-		min_clk_period = timings->tCLH_min;
+	if (timings->tCLH_min >
+	    min_clk_period * nfc_timings->setup_cycles)
+		min_clk_period = DIV_ROUND_UP(timings->tCLH_min,
+					      nfc_timings->setup_cycles);
 
 	/* T3 <=> tCS */
-	if (timings->tCS_min > min_clk_period)
-		min_clk_period = timings->tCS_min;
+	if (timings->tCS_min >
+	    min_clk_period * nfc_timings->setup_cycles)
+		min_clk_period = DIV_ROUND_UP(timings->tCS_min,
+					      nfc_timings->setup_cycles);
 
 	/* T4 <=> tCH */
-	if (timings->tCH_min > min_clk_period)
-		min_clk_period = timings->tCH_min;
+	if (timings->tCH_min >
+	    min_clk_period * nfc_timings->setup_cycles)
+		min_clk_period = DIV_ROUND_UP(timings->tCH_min,
+					      nfc_timings->setup_cycles);
 
 	/* T5 <=> tWP */
 	if (timings->tWP_min > min_clk_period)
@@ -1744,8 +1763,10 @@ static int sunxi_nfc_setup_interface(str
 		min_clk_period = timings->tWH_min;
 
 	/* T7 <=> tALS */
-	if (timings->tALS_min > min_clk_period)
-		min_clk_period = timings->tALS_min;
+	if (timings->tALS_min >
+	    min_clk_period * nfc_timings->setup_cycles)
+		min_clk_period = DIV_ROUND_UP(timings->tALS_min,
+					      nfc_timings->setup_cycles);
 
 	/* T8 <=> tDS */
 	if (timings->tDS_min > min_clk_period)
@@ -1760,8 +1781,10 @@ static int sunxi_nfc_setup_interface(str
 		min_clk_period = DIV_ROUND_UP(timings->tRR_min, 3);
 
 	/* T11 <=> tALH */
-	if (timings->tALH_min > min_clk_period)
-		min_clk_period = timings->tALH_min;
+	if (timings->tALH_min >
+	    min_clk_period * nfc_timings->setup_cycles)
+		min_clk_period = DIV_ROUND_UP(timings->tALH_min,
+					      nfc_timings->setup_cycles);
 
 	/* T12 <=> tRP */
 	if (timings->tRP_min > min_clk_period)
@@ -2670,7 +2693,7 @@ static const struct sunxi_nfc_caps sunxi
 	.nuser_data_tab = ARRAY_SIZE(sunxi_user_data_len_h6),
 	.max_ecc_steps = 32,
 	.sram_size = 8192,
-	.timings = &sun4i_a10_nfc_timings,
+	.timings = &sun50i_h616_nfc_timings,
 };
 
 static const struct of_device_id sunxi_nfc_ids[] = {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 199/556] mtd: rawnand: validate ONFI extended parameter page sections
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (197 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 198/556] mtd: rawnand: sunxi: fix H6/H616 controller timings Greg Kroah-Hartman
@ 2026-09-09 13:37 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 200/556] batman-adv: fix stale receive device on merged fragments Greg Kroah-Hartman
                   ` (369 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:37 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Miquel Raynal

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pengpeng Hou <pengpeng@iscas.ac.cn>

commit e5e415262330bd70f983e091d8919d9dcd99e475 upstream.

nand_flash_detect_ext_param_page() allocates the length declared by the
ONFI parameter page, then treats the data as a fixed header followed by
variable-length sections. It reads that header and advances over sections
without first proving that the fixed page and each current section fit in
the allocation.

Reject pages shorter than the fixed header, track the remaining variable
area while walking sections, and require the ECC section to contain every
field read from struct onfi_ext_ecc_info. Use device-scoped diagnostics
that identify the malformed ONFI section.

Fixes: 6dcbe0cdd83f ("mtd: get the ECC info from the Extended Parameter Page")
Cc: stable@vger.kernel.org
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/mtd/nand/raw/nand_onfi.c |   27 +++++++++++++++++++++++++--
 1 file changed, 25 insertions(+), 2 deletions(-)

--- a/drivers/mtd/nand/raw/nand_onfi.c
+++ b/drivers/mtd/nand/raw/nand_onfi.c
@@ -35,16 +35,21 @@ static int nand_flash_detect_ext_param_p
 					    struct nand_onfi_params *p)
 {
 	struct nand_device *base = &chip->base;
+	struct mtd_info *mtd = nand_to_mtd(chip);
 	struct nand_ecc_props requirements;
 	struct onfi_ext_param_page *ep;
 	struct onfi_ext_section *s;
 	struct onfi_ext_ecc_info *ecc;
+	size_t remaining, section_len;
 	uint8_t *cursor;
 	int ret;
 	int len;
 	int i;
 
 	len = le16_to_cpu(p->ext_param_page_length) * 16;
+	if (len < sizeof(*ep))
+		return -EINVAL;
+
 	ep = kmalloc(len, GFP_KERNEL);
 	if (!ep)
 		return -ENOMEM;
@@ -77,11 +82,29 @@ static int nand_flash_detect_ext_param_p
 
 	/* find the ECC section. */
 	cursor = (uint8_t *)(ep + 1);
+	remaining = len - sizeof(*ep);
 	for (i = 0; i < ONFI_EXT_SECTION_MAX; i++) {
 		s = ep->sections + i;
-		if (s->type == ONFI_SECTION_TYPE_2)
+		section_len = s->length * 16;
+		if (section_len > remaining) {
+			dev_dbg(&mtd->dev,
+				"ONFI extended parameter section %d exceeds page\n",
+				i);
+			goto ext_out;
+		}
+
+		if (s->type == ONFI_SECTION_TYPE_2) {
+			if (section_len < sizeof(*ecc)) {
+				dev_dbg(&mtd->dev,
+					"ONFI extended parameter ECC section %d is too short\n",
+					i);
+				goto ext_out;
+			}
 			break;
-		cursor += s->length * 16;
+		}
+
+		cursor += section_len;
+		remaining -= section_len;
 	}
 	if (i == ONFI_EXT_SECTION_MAX) {
 		pr_debug("We can not find the ECC section.\n");



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 200/556] batman-adv: fix stale receive device on merged fragments
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (198 preceding siblings ...)
  2026-09-09 13:37 ` [PATCH 7.2 199/556] mtd: rawnand: validate ONFI extended parameter page sections Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 201/556] batman-adv: fix TX priority extraction for BATADV_FORW_MCAST Greg Kroah-Hartman
                   ` (368 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Vega, Zhiling Zou, Sven Eckelmann

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhiling Zou <zhilinz@nebusec.ai>

commit ad46c907d7d9975a285c1e89a4adde652eaa93f5 upstream.

Fragment reassembly reuses the skb from the highest-numbered buffered
fragment as the merged packet. When that fragment was received on a hard
interface which is deleted before the chain completes, the merged skb can
re-enter the receive path with a stale skb->dev and skb_iif.

batadv_batman_skb_recv() passes such merged packets through the normal
receive handlers again. DAT and bridge loop avoidance both derive the ARP
header length from skb->dev, so they can dereference the freed net_device
before the packet reaches the local mesh interface.

Refresh the receive device metadata from the current receive device before
running the packet handlers. This keeps internally reinjected merged
fragments consistent with the normal receive path after hard interface
teardown.

Fixes: 610bfc6bc99b ("batman-adv: Receive fragmented packets and merge")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Signed-off-by: Zhiling Zou <zhilinz@nebusec.ai>
Signed-off-by: Sven Eckelmann <sven@narfation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/batman-adv/main.c |    4 ++++
 1 file changed, 4 insertions(+)

--- a/net/batman-adv/main.c
+++ b/net/batman-adv/main.c
@@ -450,6 +450,10 @@ int batadv_batman_skb_recv(struct sk_buf
 	if (!skb)
 		goto err_put;
 
+	/* Merged fragments re-enter here with reused skb metadata. */
+	skb->dev = dev;
+	skb->skb_iif = dev->ifindex;
+
 	/* packet should hold at least type and version */
 	if (unlikely(!pskb_may_pull(skb, 2)))
 		goto err_free;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 201/556] batman-adv: fix TX priority extraction for BATADV_FORW_MCAST
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (199 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 200/556] batman-adv: fix stale receive device on merged fragments Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 202/556] batman-adv: mcast: ensure unshared skb for multicast packets Greg Kroah-Hartman
                   ` (367 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Sven Eckelmann

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sven Eckelmann <sven@narfation.org>

commit 7aedb59b80993c912ab45ce24386a2775150962b upstream.

batadv_mcast_forw_mode_by_count() pushs the skb->data for BATADV_FORW_MCAST
forwarding via batadv_mcast_forw_mcsend(). But the
batadv_skb_set_priority() expects the ethernet header directly before
(skb->data + offset). With the moved skb->data, just some random data would
be accessed to get the priority data.

Move the batadv_skb_set_priority() before the decision about the handling
multicast packets and potential header modifications.

Cc: stable@vger.kernel.org
Fixes: 90039133221e ("batman-adv: mcast: implement multicast packet generation")
Signed-off-by: Sven Eckelmann <sven@narfation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/batman-adv/mesh-interface.c |    7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)

--- a/net/batman-adv/mesh-interface.c
+++ b/net/batman-adv/mesh-interface.c
@@ -260,6 +260,8 @@ static netdev_tx_t batadv_interface_tx(s
 	if (batadv_compare_eth(ethhdr->h_dest, ectp_addr))
 		goto dropped;
 
+	batadv_skb_set_priority(skb, 0);
+
 	gw_mode = READ_ONCE(bat_priv->gw.mode);
 	if (is_multicast_ether_addr(ethhdr->h_dest)) {
 		/* if gw mode is off, broadcast every packet */
@@ -293,6 +295,9 @@ static netdev_tx_t batadv_interface_tx(s
 
 send:
 		if (do_bcast && !is_broadcast_ether_addr(ethhdr->h_dest)) {
+			/* WARNING batadv_mcast_forw_mode might add more headers
+			 * in front of the skb. and might even reallocate the skb
+			 */
 			forw_mode = batadv_mcast_forw_mode(bat_priv, skb, vid,
 							   &mcast_is_routable);
 			switch (forw_mode) {
@@ -310,8 +315,6 @@ send:
 		}
 	}
 
-	batadv_skb_set_priority(skb, 0);
-
 	/* ethernet packet should be broadcasted */
 	if (do_bcast) {
 		primary_if = batadv_primary_if_get_selected(bat_priv);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 202/556] batman-adv: mcast: ensure unshared skb for multicast packets
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (200 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 201/556] batman-adv: fix TX priority extraction for BATADV_FORW_MCAST Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 203/556] batman-adv: mcast: linearize skbuff for packet generation Greg Kroah-Hartman
                   ` (366 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Sven Eckelmann

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sven Eckelmann <sven@narfation.org>

commit 82bf207f48ebb7a38157f1d91dac884fc9b8cfd8 upstream.

When a packet is transmitted via a batman-adv interface and has already
enough room for the header then nothing will make sure that the skbuff is
unshared. But it is not allowed to modify a currently shared skbuff.

Always make sure that the pskb_expand_head() is not only called for a too
small header but also for shared skbuffs.

Cc: stable@vger.kernel.org
Fixes: 90039133221e ("batman-adv: mcast: implement multicast packet generation")
Signed-off-by: Sven Eckelmann <sven@narfation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/batman-adv/multicast_forw.c |    3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

--- a/net/batman-adv/multicast_forw.c
+++ b/net/batman-adv/multicast_forw.c
@@ -1100,8 +1100,7 @@ static int batadv_mcast_forw_expand_head
 		return -EINVAL;
 	}
 
-	if (skb_headroom(skb) < hdr_size &&
-	    pskb_expand_head(skb, hdr_size, 0, GFP_ATOMIC) < 0)
+	if (skb_cow(skb, hdr_size) < 0)
 		return -ENOMEM;
 
 	return 0;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 203/556] batman-adv: mcast: linearize skbuff for packet generation
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (201 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 202/556] batman-adv: mcast: ensure unshared skb for multicast packets Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 204/556] batman-adv: dat: avoid unaligned fault in IP extraction Greg Kroah-Hartman
                   ` (365 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Sven Eckelmann

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sven Eckelmann <sven@narfation.org>

commit 6a30a59e2660afd03c975f1b8eae6a2301161197 upstream.

batadv_mcast_forw_packet() and batadv_mcast_forw_scrape() is not only
called (indirectly) by the unsharing+linearizing batadv_recv_mcast_packet()
handler. When it is called (indirectly) by batadv_mcast_forw_mcsend() then
it will be unshared but not linearized. The SKB_LINEAR_ASSERT() can
therefore cause a fatal BUG().

The linearization should happen during the expansion of the head because
the scrape function can be hit already during the initial
batadv_mcast_forw_mode() selection code:

* batadv_interface_tx
* batadv_mcast_forw_mode
* batadv_mcast_forw_mode_by_count()
* batadv_mcast_forw_push()
  -> calls batadv_mcast_forw_expand_head() before everything else
* batadv_mcast_forw_push_tvlvs()
* batadv_mcast_forw_push_dests()
* batadv_mcast_forw_push_adjust_padding()
* batadv_mcast_forw_scrape()

Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-bot@kernel.org>
Fixes: 90039133221e ("batman-adv: mcast: implement multicast packet generation")
Signed-off-by: Sven Eckelmann <sven@narfation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/batman-adv/multicast_forw.c |    4 ++++
 1 file changed, 4 insertions(+)

--- a/net/batman-adv/multicast_forw.c
+++ b/net/batman-adv/multicast_forw.c
@@ -1103,6 +1103,10 @@ static int batadv_mcast_forw_expand_head
 	if (skb_cow(skb, hdr_size) < 0)
 		return -ENOMEM;
 
+	/* batadv_mcast_forw_scrape() + batadv_mcast_forw_packet() require linearized skb */
+	if (skb_linearize(skb) < 0)
+		return -ENOMEM;
+
 	return 0;
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 204/556] batman-adv: dat: avoid unaligned fault in IP extraction
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (202 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 203/556] batman-adv: mcast: linearize skbuff for packet generation Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 205/556] batman-adv: bla: fix freeing of claims on meshif deletion Greg Kroah-Hartman
                   ` (364 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Sven Eckelmann

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sven Eckelmann <sven@narfation.org>

commit 0121afa52cdb88cfb4d5d7bd126a23a9100121d8 upstream.

Independent of the alignment of the ARP packet in the SKB, either the
batadv_arp_ip_src or the batadv_arp_ip_dst will have an unaligned access
(on HW without native unaligned read support).

Use get_unaligned() to handle this properly on all architectures.

Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-bot@kernel.org>
Fixes: 5c3a0e553593 ("batman-adv: Distributed ARP Table - add ARP parsing functions")
Signed-off-by: Sven Eckelmann <sven@narfation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/batman-adv/distributed-arp-table.c |    8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

--- a/net/batman-adv/distributed-arp-table.c
+++ b/net/batman-adv/distributed-arp-table.c
@@ -250,7 +250,10 @@ static u8 *batadv_arp_hw_src(struct sk_b
  */
 static __be32 batadv_arp_ip_src(struct sk_buff *skb, int hdr_size)
 {
-	return *(__force __be32 *)(batadv_arp_hw_src(skb, hdr_size) + ETH_ALEN);
+	u8 *src = batadv_arp_hw_src(skb, hdr_size) + ETH_ALEN;
+	__be32 *ip = (__force __be32 *)src;
+
+	return get_unaligned(ip);
 }
 
 /**
@@ -275,8 +278,9 @@ static u8 *batadv_arp_hw_dst(struct sk_b
 static __be32 batadv_arp_ip_dst(struct sk_buff *skb, int hdr_size)
 {
 	u8 *dst = batadv_arp_hw_src(skb, hdr_size) + ETH_ALEN * 2 + 4;
+	__be32 *ip = (__force __be32 *)dst;
 
-	return *(__force __be32 *)dst;
+	return get_unaligned(ip);
 }
 
 /**



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 205/556] batman-adv: bla: fix freeing of claims on meshif deletion
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (203 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 204/556] batman-adv: dat: avoid unaligned fault in IP extraction Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 206/556] batman-adv: bla: prevent CRC corruptions after claim flush Greg Kroah-Hartman
                   ` (363 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Sven Eckelmann

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sven Eckelmann <sven@narfation.org>

commit 8d128c932bced74e3b1625ba3d7c78ef122a88a7 upstream.

When the mesh interface is getting deleted, then
batadv_bla_del_backbone_claims() (via batadv_bla_purge_backbone_gw()) could
make sure that all claims gets removed. But this function is only executed
when bat_priv->bla.claim_hash is not NULL. And since batadv_bla_free() is
always setting it to NULL before it is (indirectly) called, it was never
actually executed.

But the batadv_bla_purge_claims() -> batadv_handle_unclaim() is at the
moment too fragile because the BLA code is not handling the rehashing in
batadv_bla_update_orig_address(). The stored backbone address doesn't have
to be the one actually used for the hash bucket selection during the
initial adding of the backbone. The batadv_handle_unclaim() can therefore
fail to find the respective backbone for the unclaim and then stop the
deletion.

But the actual backbone_gw object is not needed for the unclaim because all
relevant information is always provided by the caller. And the check for
the existence of the backbone_gw doesn't provide any additional security
check for the deletion of a claim.

Cc: stable@kernel.org
Fixes: 23721387c409 ("batman-adv: add basic bridge loop avoidance code")
Signed-off-by: Sven Eckelmann <sven@narfation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/batman-adv/bridge_loop_avoidance.c |   10 +---------
 1 file changed, 1 insertion(+), 9 deletions(-)

--- a/net/batman-adv/bridge_loop_avoidance.c
+++ b/net/batman-adv/bridge_loop_avoidance.c
@@ -942,26 +942,18 @@ static bool batadv_handle_unclaim(struct
 				  const u8 *backbone_addr, const u8 *claim_addr,
 				  unsigned short vid)
 {
-	struct batadv_bla_backbone_gw *backbone_gw;
-
 	/* unclaim in any case if it is our own */
 	if (primary_if && batadv_compare_eth(backbone_addr,
 					     primary_if->net_dev->dev_addr))
 		batadv_bla_send_claim(bat_priv, claim_addr, vid,
 				      BATADV_CLAIM_TYPE_UNCLAIM);
 
-	backbone_gw = batadv_backbone_hash_find(bat_priv, backbone_addr, vid);
-
-	if (!backbone_gw)
-		return true;
-
 	/* this must be an UNCLAIM frame */
 	batadv_dbg(BATADV_DBG_BLA, bat_priv,
 		   "%s(): UNCLAIM %pM on vid %d (sent by %pM)...\n", __func__,
-		   claim_addr, batadv_print_vid(vid), backbone_gw->orig);
+		   claim_addr, batadv_print_vid(vid), backbone_addr);
 
 	batadv_bla_del_claim(bat_priv, claim_addr, vid);
-	batadv_backbone_gw_put(backbone_gw);
 	return true;
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 206/556] batman-adv: bla: prevent CRC corruptions after claim flush
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (204 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 205/556] batman-adv: bla: fix freeing of claims on meshif deletion Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 207/556] clk: clocking-wizard: fix integer overflow in rate calculation Greg Kroah-Hartman
                   ` (362 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Sven Eckelmann

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sven Eckelmann <sven@narfation.org>

commit 89f3502ff6878798be96461b2eebd64ba3c3874c upstream.

When batadv_bla_del_backbone_claims() tried to remove all claims of a
backbone, it sets the CRC to 0. It assumes that the it had the last
reference of the claims because batadv_claim_release() (which runs after
the last reference was released), is XORing the crc16 of the claim address
with the backbone CRC.

If there would be a parallel holder of any of these references, it could
happen that the backbone CRC is (0 ^ crc16(delayed_released_claim)). Which
is the wrong starting point for the new claims it may receive when the
remote answers the claim request from batadv_bla_send_request().

This reinitializations can be completely dropped to avoid this problem.
batadv_claim_release() will take care of fixing the backbone CRC.

Cc: stable@vger.kernel.org
Fixes: 23721387c409 ("batman-adv: add basic bridge loop avoidance code")
Signed-off-by: Sven Eckelmann <sven@narfation.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/batman-adv/bridge_loop_avoidance.c |    5 -----
 1 file changed, 5 deletions(-)

--- a/net/batman-adv/bridge_loop_avoidance.c
+++ b/net/batman-adv/bridge_loop_avoidance.c
@@ -324,11 +324,6 @@ batadv_bla_del_backbone_claims(struct ba
 		}
 		spin_unlock_bh(list_lock);
 	}
-
-	/* all claims gone, initialize CRC */
-	spin_lock_bh(&backbone_gw->crc_lock);
-	backbone_gw->crc = BATADV_BLA_CRC_INIT;
-	spin_unlock_bh(&backbone_gw->crc_lock);
 }
 
 /**



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 207/556] clk: clocking-wizard: fix integer overflow in rate calculation
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (205 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 206/556] batman-adv: bla: prevent CRC corruptions after claim flush Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 208/556] clk: mediatek: mt8196: Select REGMAP_MMIO for vlpckgen Greg Kroah-Hartman
                   ` (361 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Pale Löbl, Brian Masney

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pavel Löbl <pavel@loebl.cz>

commit 4adf593c6fc5aed4639add011f71a074a1bd3966 upstream.

When using driver on Zynq-7000 (32-bit) determine_rate calculation
overflows. For instance requesting 32MHz with 100MHz parent clock
results in 100000000*(4*1000+0) 32-bit multiplication.

Replace the expression with mult_frac which is already used in
clk_wzrd_recalc_ratef.

Cc: stable@vger.kernel.org
Fixes: 7681f64e6404 ("clk: clocking-wizard: calculate dividers fractional parts")
Signed-off-by: Pale Löbl <pavel@loebl.cz>
Reviewed-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/clk/xilinx/clk-xlnx-clock-wizard.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/drivers/clk/xilinx/clk-xlnx-clock-wizard.c
+++ b/drivers/clk/xilinx/clk-xlnx-clock-wizard.c
@@ -663,8 +663,8 @@ static int clk_wzrd_determine_rate_all(s
 	d = divider->d;
 	o = divider->o;
 
-	req->rate = div_u64(req->best_parent_rate * (m * 1000 + divider->m_frac),
-			    d * (o * 1000 + divider->o_frac));
+	req->rate = mult_frac(req->best_parent_rate, m * 1000 + divider->m_frac,
+			      d * (o * 1000 + divider->o_frac));
 	return 0;
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 208/556] clk: mediatek: mt8196: Select REGMAP_MMIO for vlpckgen
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (206 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 207/556] clk: clocking-wizard: fix integer overflow in rate calculation Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 209/556] clk: meson: align gxbb_32k_clk_sel number of parents with actual count Greg Kroah-Hartman
                   ` (360 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Akari Tsuyukusa, Brian Masney,
	AngeloGioacchino Del Regno

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Akari Tsuyukusa <akkun11.open@gmail.com>

commit f63aecdb45e9dd19c340fd62df698374d95b9024 upstream.

The MediaTek MT8196 vlpckgen clock driver uses
__devm_regmap_init_mmio_clk() by devm_regmap_init_mmio(),
which is defined in drivers/base/regmap/regmap-mmio.c.
However, the driver's Kconfig entry does not select REGMAP_MMIO.
This causes a linker error when REGMAP_MMIO is not enabled.

Fix this by selecting REGMAP_MMIO in the Kconfig entry.

Fixes: 2f8b3ae6f0cb ("clk: mediatek: Add MT8196 vlpckgen clock support")
Cc: stable@vger.kernel.org
Signed-off-by: Akari Tsuyukusa <akkun11.open@gmail.com>
Reviewed-by: Brian Masney <bmasney@redhat.com>
Reviewed-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
Signed-off-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/clk/mediatek/Kconfig |    1 +
 1 file changed, 1 insertion(+)

--- a/drivers/clk/mediatek/Kconfig
+++ b/drivers/clk/mediatek/Kconfig
@@ -1006,6 +1006,7 @@ config COMMON_CLK_MT8196
 	tristate "Clock driver for MediaTek MT8196"
 	depends on ARM64 || COMPILE_TEST
 	select COMMON_CLK_MEDIATEK
+	select REGMAP_MMIO
 	default ARCH_MEDIATEK
 	help
 	  This driver supports MediaTek MT8196 basic clocks.



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 209/556] clk: meson: align gxbb_32k_clk_sel number of parents with actual count
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (207 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 208/556] clk: mediatek: mt8196: Select REGMAP_MMIO for vlpckgen Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 210/556] clk: microchip: mpfs: fix regmap_update_bits() mask/val order Greg Kroah-Hartman
                   ` (359 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Christian Hewitt,
	Martin Blumenstingl, Jerome Brunet

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Martin Blumenstingl <martin.blumenstingl@googlemail.com>

commit 628b6fee9fca292f12d07f0f1bcf1edefa949d81 upstream.

The following out-of-bounds read has been observed by Christian on a
GXBB WeTek Hub:
==================================================================
BUG: KASAN: global-out-of-bounds in __clk_register+0x1b70/0x2418
Read of size 8 at addr ffffd66320cf88e0 by task swapper/0/1

CPU: 0 UID: 0 PID: 1 Comm: swapper/0 Not tainted 7.0.0-rc5 #1 PREEMPT
Hardware name: WeTek Hub (DT)
Call trace:
 show_stack+0x14/0x20 (C)
 dump_stack_lvl+0x74/0x94
 print_report+0x164/0x4b0
 kasan_report+0x98/0xd8
 __asan_report_load8_noabort+0x1c/0x24
 __clk_register+0x1b70/0x2418
 devm_clk_hw_register+0x74/0x15c
 meson_clkc_init+0xd4/0x20c
 meson_clkc_syscon_probe+0x5c/0x94
 platform_probe+0xbc/0x17c
 really_probe+0x184/0x844
 __driver_probe_device+0x154/0x35c
 driver_probe_device+0x60/0x188
 __driver_attach+0x168/0x4a0
 bus_for_each_dev+0xec/0x180
 driver_attach+0x38/0x58
 bus_add_driver+0x238/0x4c0
 driver_register+0x150/0x388
 __platform_driver_register+0x54/0x7c
 gxbb_clkc_driver_init+0x18/0x20
 do_one_initcall+0xb8/0x340
 kernel_init_freeable+0x49c/0x52c
 kernel_init+0x24/0x148
 ret_from_fork+0x10/0x20

The buggy address belongs to the variable:
 gxbb_32k_clk_parents+0x60/0x400

The buggy address belongs to a vmalloc virtual mapping
The buggy address belongs to the physical page:

Memory state around the buggy address:
 ffffd66320cf8780: 00 00 00 00 f9 f9 f9 f9 00 f9 f9 f9 f9 f9 f9 f9
 ffffd66320cf8800: 00 04 f9 f9 f9 f9 f9 f9 00 04 f9 f9 f9 f9 f9 f9
>ffffd66320cf8880: 00 00 00 00 00 00 00 00 00 00 00 00 f9 f9 f9 f9
                                                       ^
 ffffd66320cf8900: 00 01 f9 f9 f9 f9 f9 f9 00 06 f9 f9 f9 f9 f9 f9
 ffffd66320cf8980: 00 00 02 f9 f9 f9 f9 f9 00 00 02 f9 f9 f9 f9 f9
==================================================================

Commit 7915d7d5407c ("clk: amlogic: gxbb: drop non existing 32k clock
parent") dropped a non-existing clock parent from the gxbb_32k_clk_sel
mux but didn't adjust the hard-coded num_parents field. Fix the actual
number of parents of that mux by using ARRAY_SIZE instead (avoiding
similar problems in future).

Fixes: 7915d7d5407c ("clk: amlogic: gxbb: drop non existing 32k clock parent")
Reported-by: Christian Hewitt <christianshewitt@gmail.com>
Cc: stable@vger.kernel.org
Tested-by: Christian Hewitt <christianshewitt@gmail.com>
Signed-off-by: Martin Blumenstingl <martin.blumenstingl@googlemail.com>
Link: https://patch.msgid.link/20260623201956.1324992-1-martin.blumenstingl@googlemail.com
Signed-off-by: Jerome Brunet <jbrunet@baylibre.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/clk/meson/gxbb.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/clk/meson/gxbb.c
+++ b/drivers/clk/meson/gxbb.c
@@ -1393,7 +1393,7 @@ static struct clk_regmap gxbb_32k_clk_se
 		.name = "32k_clk_sel",
 		.ops = &clk_regmap_mux_ops,
 		.parent_data = gxbb_32k_clk_parents,
-		.num_parents = 4,
+		.num_parents = ARRAY_SIZE(gxbb_32k_clk_parents),
 		.flags = CLK_SET_RATE_PARENT,
 	},
 };



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 210/556] clk: microchip: mpfs: fix regmap_update_bits() mask/val order
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (208 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 209/556] clk: meson: align gxbb_32k_clk_sel number of parents with actual count Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 211/556] clk: qcom: gcc-msm8916: Fix enable_reg for gcc_blsp1_sleep_clk Greg Kroah-Hartman
                   ` (358 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Pedro Kopper, Conor Dooley,
	Stephen Boyd

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pedro Kopper <pedro.kopper@microchip.com>

commit fbfa013eeac299ecc015cb14fa40e382a23fb489 upstream.

mpfs_cfg_clk_set_rate() passes the mask and value arguments to
regmap_update_bits() in the wrong order. The resulting write becomes
reg = orig_reg | val, causing bits to not be cleared if the clock
divider changes.

Pass the arguments in the correct order so the divider field is updated
as intended.

Fixes: c6f2dddfa7f9 ("clk: microchip: mpfs: use regmap for clocks")
Signed-off-by: Pedro Kopper <pedro.kopper@microchip.com>
Reviewed-by: Conor Dooley <conor.dooley@microchip.com>
Cc: stable@vger.kernel.org
Signed-off-by: Stephen Boyd <sboyd@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/clk/microchip/clk-mpfs.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/clk/microchip/clk-mpfs.c
+++ b/drivers/clk/microchip/clk-mpfs.c
@@ -285,7 +285,7 @@ static int mpfs_cfg_clk_set_rate(struct
 
 	mask = clk_div_mask(cfg->width) << cfg->shift;
 	val = divider_setting << cfg->shift;
-	regmap_update_bits(cfg->map, cfg->map_offset, val, mask);
+	regmap_update_bits(cfg->map, cfg->map_offset, mask, val);
 
 	return 0;
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 211/556] clk: qcom: gcc-msm8916: Fix enable_reg for gcc_blsp1_sleep_clk
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (209 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 210/556] clk: microchip: mpfs: fix regmap_update_bits() mask/val order Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 212/556] clk: qcom: gcc-msm8939: " Greg Kroah-Hartman
                   ` (357 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Stephan Gerhold,
	Bjorn Andersson

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Stephan Gerhold <stephan.gerhold@linaro.org>

commit c5339edc6abb601ea10df910ea0b1592fa1016f3 upstream.

According to the APQ8016E TRM, the GCC_BLSP1_SLEEP_CBCR register is
read-only and only has the CLK_OFF bit to check if the clock is running.
This is a shared vote clock, the correct way to enable it is to vote for
BLSP1_SLEEP_CLK_ENA (BIT(9)) in GCC_APCS_CLOCK_BRANCH_ENA_VOTE (0x45004).

Cc: stable@vger.kernel.org
Fixes: 3966fab8b6ab ("clk: qcom: Add MSM8916 Global Clock Controller support")
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Stephan Gerhold <stephan.gerhold@linaro.org>
Link: https://lore.kernel.org/r/20260706-qcom-clk-mdm9607-fixes-v2-1-745565101869@linaro.org
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/clk/qcom/gcc-msm8916.c |    5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

--- a/drivers/clk/qcom/gcc-msm8916.c
+++ b/drivers/clk/qcom/gcc-msm8916.c
@@ -1589,9 +1589,10 @@ static struct clk_branch gcc_blsp1_ahb_c
 
 static struct clk_branch gcc_blsp1_sleep_clk = {
 	.halt_reg = 0x01004,
+	.halt_check = BRANCH_HALT_VOTED,
 	.clkr = {
-		.enable_reg = 0x01004,
-		.enable_mask = BIT(0),
+		.enable_reg = 0x45004,
+		.enable_mask = BIT(9),
 		.hw.init = &(struct clk_init_data){
 			.name = "gcc_blsp1_sleep_clk",
 			.parent_data = &(const struct clk_parent_data){



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 212/556] clk: qcom: gcc-msm8939: Fix enable_reg for gcc_blsp1_sleep_clk
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (210 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 211/556] clk: qcom: gcc-msm8916: Fix enable_reg for gcc_blsp1_sleep_clk Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 213/556] clk: rockchip: rk3588: Dont change PLL rates when setting dclk_vop2_src Greg Kroah-Hartman
                   ` (356 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Stephan Gerhold,
	Bjorn Andersson

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Stephan Gerhold <stephan.gerhold@linaro.org>

commit fc611445b021262b0d4ace6f716a360663816287 upstream.

MSM8939 is similar to MSM8916, where the GCC_BLSP1_SLEEP_CBCR register is
read-only and only has the CLK_OFF bit to check if the clock is running.
This is a shared vote clock, the correct way to enable it is to vote for
BLSP1_SLEEP_CLK_ENA (BIT(9)) in GCC_APCS_CLOCK_BRANCH_ENA_VOTE (0x45004).

Cc: stable@vger.kernel.org
Fixes: 1664014e4679 ("clk: qcom: gcc-msm8939: Add MSM8939 Generic Clock Controller")
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Stephan Gerhold <stephan.gerhold@linaro.org>
Link: https://lore.kernel.org/r/20260706-qcom-clk-mdm9607-fixes-v2-2-745565101869@linaro.org
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/clk/qcom/gcc-msm8939.c |    5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

--- a/drivers/clk/qcom/gcc-msm8939.c
+++ b/drivers/clk/qcom/gcc-msm8939.c
@@ -1929,9 +1929,10 @@ static struct clk_branch gcc_blsp1_ahb_c
 
 static struct clk_branch gcc_blsp1_sleep_clk = {
 	.halt_reg = 0x01004,
+	.halt_check = BRANCH_HALT_VOTED,
 	.clkr = {
-		.enable_reg = 0x01004,
-		.enable_mask = BIT(0),
+		.enable_reg = 0x45004,
+		.enable_mask = BIT(9),
 		.hw.init = &(struct clk_init_data){
 			.name = "gcc_blsp1_sleep_clk",
 			.ops = &clk_branch2_ops,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 213/556] clk: rockchip: rk3588: Dont change PLL rates when setting dclk_vop2_src
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (211 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 212/556] clk: qcom: gcc-msm8939: " Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 214/556] clk: qcom: gcc-mdm9607: Drop incorrect apss_tcu_clk_src Greg Kroah-Hartman
                   ` (355 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Heiko Stuebner, Quentin Schulz,
	Chris Morgan, Heiko Stuebner

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Heiko Stuebner <heiko.stuebner@cherry.de>

commit 13b10571cc353448275365ede1a5396d20dfe839 upstream.

dclk_vop2_src currently has the CLK_SET_RATE_PARENT flag set, which is
very different from dclk_vop0_src or dclk_vop1_src, which don't have it.

With this flag in dclk_vop2_src, actually setting the clock then results
in a lot of other peripherals breaking, because setting the rate results
in the PLL source getting changed:

[   14.898718] clk_core_set_rate_nolock: setting rate for dclk_vop2 to 152840000
[   15.155017] clk_change_rate: setting rate for pll_gpll to 1680000000
[ clk adjusting every gpll user ]

This includes possibly the other vops, i2s, spdif and even the uarts.
Among other possible things, this breaks the uart console on a board
I use. Sometimes it recovers later on, but there will be a big block
of garbled output for a while at least.

Shared PLLs should not be changed by individual users, so drop this flag
from dclk_vop2_src.

Fixes: f1c506d152ff ("clk: rockchip: add clock controller for the RK3588")
Cc: stable@vger.kernel.org
Tested-by: Quentin Schulz <quentin.schulz@cherry.de> # RK3588 Tiger w/ DP
Signed-off-by: Heiko Stuebner <heiko.stuebner@cherry.de>
Reviewed-by: Quentin Schulz <quentin.schulz@cherry.de>
Tested-by: Chris Morgan <macromorgan@hotmail.com>
Link: https://patch.msgid.link/20260304121426.1184680-2-heiko@sntech.de
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/clk/rockchip/clk-rk3588.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/clk/rockchip/clk-rk3588.c
+++ b/drivers/clk/rockchip/clk-rk3588.c
@@ -2102,7 +2102,7 @@ static struct rockchip_clk_branch rk3588
 	COMPOSITE(DCLK_VOP1_SRC, "dclk_vop1_src", gpll_cpll_v0pll_aupll_p, 0,
 			RK3588_CLKSEL_CON(111), 14, 2, MFLAGS, 9, 5, DFLAGS,
 			RK3588_CLKGATE_CON(52), 11, GFLAGS),
-	COMPOSITE(DCLK_VOP2_SRC, "dclk_vop2_src", gpll_cpll_v0pll_aupll_p, CLK_SET_RATE_PARENT | CLK_SET_RATE_NO_REPARENT,
+	COMPOSITE(DCLK_VOP2_SRC, "dclk_vop2_src", gpll_cpll_v0pll_aupll_p, CLK_SET_RATE_NO_REPARENT,
 			RK3588_CLKSEL_CON(112), 5, 2, MFLAGS, 0, 5, DFLAGS,
 			RK3588_CLKGATE_CON(52), 12, GFLAGS),
 	COMPOSITE_NODIV(DCLK_VOP0, "dclk_vop0", dclk_vop0_p,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 214/556] clk: qcom: gcc-mdm9607: Drop incorrect apss_tcu_clk_src
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (212 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 213/556] clk: rockchip: rk3588: Dont change PLL rates when setting dclk_vop2_src Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 215/556] clk: qcom: gcc-mdm9607: Drop incorrect system_noc_bfdcd_clk_src Greg Kroah-Hartman
                   ` (354 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Stephan Gerhold,
	Bjorn Andersson

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Stephan Gerhold <stephan@gerhold.net>

commit 38d06956f60675f906dc3f5b70b3b52103b86a7d upstream.

This clock does not exist on the specified address on MDM9607.
Reading/writing the registers always results in 0 or crashes. The math in
the frequency table is also broken. GPLL2 on MDM9607 runs at 480 MHz, so:

 - F(155000000, P_GPLL2, 6, 0, 0), // 480 MHz/6 = 80 MHz, not 155 MHz
 - F(310000000, P_GPLL2, 3, 0, 0), // 480 MHz/3 = 160 MHz, not 310 MHz

Presumably, this definition was mistakenly copied as-is from gcc-msm8916
(which uses 930 MHz for GPLL2). There are no branch consumers of this root
clock inside gcc-mdm9607 (notably, gcc_apss_tcu_clk has bimc_ddr_clk_src as
parent instead of this clock), so we can just drop it.

It seems like this clock does exist on this SoC on a different address, but
since there is no user and reference code for it, it is still better to
drop it.

Cc: stable@vger.kernel.org
Fixes: 48b7253264ea ("clk: qcom: Add MDM9607 GCC driver")
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Stephan Gerhold <stephan@gerhold.net>
Link: https://lore.kernel.org/r/20260706-qcom-clk-mdm9607-fixes-v2-6-745565101869@linaro.org
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/clk/qcom/gcc-mdm9607.c |   35 -----------------------------------
 1 file changed, 35 deletions(-)

--- a/drivers/clk/qcom/gcc-mdm9607.c
+++ b/drivers/clk/qcom/gcc-mdm9607.c
@@ -158,20 +158,6 @@ static const struct clk_parent_data gcc_
 	{ .hw = &gpll2.clkr.hw },
 };
 
-static const struct parent_map gcc_xo_gpll0_gpll1_gpll2_map[] = {
-	{ P_XO, 0 },
-	{ P_GPLL0, 1 },
-	{ P_GPLL1, 2 },
-	{ P_GPLL2, 3 },
-};
-
-static const struct clk_parent_data gcc_xo_gpll0_gpll1_gpll2[] = {
-	{ .fw_name = "xo" },
-	{ .hw = &gpll0.clkr.hw },
-	{ .hw = &gpll1_vote.hw },
-	{ .hw = &gpll2.clkr.hw },
-};
-
 static const struct freq_tbl ftbl_apss_ahb_clk[] = {
 	F(19200000, P_XO, 1, 0, 0),
 	F(50000000, P_GPLL0, 16, 0, 0),
@@ -674,26 +660,6 @@ static struct clk_rcg2 sdcc2_apps_clk_sr
 	},
 };
 
-static const struct freq_tbl ftbl_gcc_apss_tcu_clk[] = {
-	F(155000000, P_GPLL2, 6, 0, 0),
-	F(310000000, P_GPLL2, 3, 0, 0),
-	F(400000000, P_GPLL0, 2, 0, 0),
-	{ }
-};
-
-static struct clk_rcg2 apss_tcu_clk_src = {
-	.cmd_rcgr = 0x1207c,
-	.hid_width = 5,
-	.parent_map = gcc_xo_gpll0_gpll1_gpll2_map,
-	.freq_tbl = ftbl_gcc_apss_tcu_clk,
-	.clkr.hw.init = &(struct clk_init_data){
-		.name = "apss_tcu_clk_src",
-		.parent_data = gcc_xo_gpll0_gpll1_gpll2,
-		.num_parents = 4,
-		.ops = &clk_rcg2_ops,
-	},
-};
-
 static const struct freq_tbl ftbl_gcc_usb_hs_system_clk[] = {
 	F(19200000, P_XO, 1, 0, 0),
 	F(57140000, P_GPLL0, 14, 0, 0),
@@ -1511,7 +1477,6 @@ static struct clk_regmap *gcc_mdm9607_cl
 	[PDM2_CLK_SRC] = &pdm2_clk_src.clkr,
 	[SDCC1_APPS_CLK_SRC] = &sdcc1_apps_clk_src.clkr,
 	[SDCC2_APPS_CLK_SRC] = &sdcc2_apps_clk_src.clkr,
-	[APSS_TCU_CLK_SRC] = &apss_tcu_clk_src.clkr,
 	[USB_HS_SYSTEM_CLK_SRC] = &usb_hs_system_clk_src.clkr,
 	[GCC_BLSP1_AHB_CLK] = &gcc_blsp1_ahb_clk.clkr,
 	[GCC_BLSP1_SLEEP_CLK] = &gcc_blsp1_sleep_clk.clkr,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 215/556] clk: qcom: gcc-mdm9607: Drop incorrect system_noc_bfdcd_clk_src
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (213 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 214/556] clk: qcom: gcc-mdm9607: Drop incorrect apss_tcu_clk_src Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 216/556] clk: qcom: gcc-mdm9607: Fix enable_reg for gcc_blsp1_sleep_clk Greg Kroah-Hartman
                   ` (353 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Stephan Gerhold,
	Bjorn Andersson

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Stephan Gerhold <stephan@gerhold.net>

commit 17784427df923a0573a7ea83f9198456ff1ec1a5 upstream.

This clock does not exist on MDM9607. Reading/writing the registers always
results in 0.

Presumably, this definition was mistakenly copied from gcc-msm8916. On
MSM8916, this root clock is used for multimedia subsystems (camera,
display, video). MDM9607 has none of that, so this clock was probably
omitted in the hardware.

There are no users inside gcc-mdm9607, so we can just drop it.

Cc: stable@vger.kernel.org
Fixes: 48b7253264ea ("clk: qcom: Add MDM9607 GCC driver")
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Stephan Gerhold <stephan@gerhold.net>
Link: https://lore.kernel.org/r/20260706-qcom-clk-mdm9607-fixes-v2-7-745565101869@linaro.org
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/clk/qcom/gcc-mdm9607.c |   13 -------------
 1 file changed, 13 deletions(-)

--- a/drivers/clk/qcom/gcc-mdm9607.c
+++ b/drivers/clk/qcom/gcc-mdm9607.c
@@ -240,18 +240,6 @@ static struct clk_rcg2 pcnoc_bfdcd_clk_s
 	},
 };
 
-static struct clk_rcg2 system_noc_bfdcd_clk_src = {
-	.cmd_rcgr = 0x26004,
-	.hid_width = 5,
-	.parent_map = gcc_xo_gpll0_bimc_map,
-	.clkr.hw.init = &(struct clk_init_data){
-		.name = "system_noc_bfdcd_clk_src",
-		.parent_data = gcc_xo_gpll0_bimc,
-		.num_parents = ARRAY_SIZE(gcc_xo_gpll0_bimc),
-		.ops = &clk_rcg2_ops,
-	},
-};
-
 static const struct freq_tbl ftbl_gcc_blsp1_qup1_6_i2c_apps_clk[] = {
 	F(19200000, P_XO, 1, 0, 0),
 	F(50000000, P_GPLL0, 16, 0, 0),
@@ -1450,7 +1438,6 @@ static struct clk_regmap *gcc_mdm9607_cl
 	[BIMC_PLL_VOTE] = &bimc_pll_vote,
 	[BIMC_DDR_CLK_SRC] = &bimc_ddr_clk_src.clkr,
 	[PCNOC_BFDCD_CLK_SRC] = &pcnoc_bfdcd_clk_src.clkr,
-	[SYSTEM_NOC_BFDCD_CLK_SRC] = &system_noc_bfdcd_clk_src.clkr,
 	[APSS_AHB_CLK_SRC] = &apss_ahb_clk_src.clkr,
 	[BLSP1_QUP1_I2C_APPS_CLK_SRC] = &blsp1_qup1_i2c_apps_clk_src.clkr,
 	[BLSP1_QUP1_SPI_APPS_CLK_SRC] = &blsp1_qup1_spi_apps_clk_src.clkr,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 216/556] clk: qcom: gcc-mdm9607: Fix enable_reg for gcc_blsp1_sleep_clk
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (214 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 215/556] clk: qcom: gcc-mdm9607: Drop incorrect system_noc_bfdcd_clk_src Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 217/556] clk: qcom: gcc-mdm9607: Fix halt_reg for gcc_apss_axi_clk Greg Kroah-Hartman
                   ` (352 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Stephan Gerhold,
	Bjorn Andersson

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Stephan Gerhold <stephan@gerhold.net>

commit 944d0fb38cffe57a1d1ebf82c5c077bad82dcdbb upstream.

MDM9607 is similar to MSM8909, where the GCC_BLSP1_SLEEP_CBCR register is
read-only and only has the CLK_OFF bit to check if the clock is running.
This is a shared vote clock, the correct way to enable it is to vote for
BLSP1_SLEEP_CLK_ENA (BIT(9)) in GCC_APCS_CLOCK_BRANCH_ENA_VOTE (0x45004).

Cc: stable@vger.kernel.org
Fixes: 48b7253264ea ("clk: qcom: Add MDM9607 GCC driver")
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Stephan Gerhold <stephan@gerhold.net>
Link: https://lore.kernel.org/r/20260706-qcom-clk-mdm9607-fixes-v2-3-745565101869@linaro.org
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/clk/qcom/gcc-mdm9607.c |    5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

--- a/drivers/clk/qcom/gcc-mdm9607.c
+++ b/drivers/clk/qcom/gcc-mdm9607.c
@@ -744,9 +744,10 @@ static struct clk_branch gcc_blsp1_ahb_c
 
 static struct clk_branch gcc_blsp1_sleep_clk = {
 	.halt_reg = 0x1004,
+	.halt_check = BRANCH_HALT_VOTED,
 	.clkr = {
-		.enable_reg = 0x1004,
-		.enable_mask = BIT(0),
+		.enable_reg = 0x45004,
+		.enable_mask = BIT(9),
 		.hw.init = &(struct clk_init_data){
 			.name = "gcc_blsp1_sleep_clk",
 			.parent_data = &(const struct clk_parent_data){



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 217/556] clk: qcom: gcc-mdm9607: Fix halt_reg for gcc_apss_axi_clk
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (215 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 216/556] clk: qcom: gcc-mdm9607: Fix enable_reg for gcc_blsp1_sleep_clk Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 218/556] clk: qcom: gcc-mdm9607: Drop incorrect BIMC PLL and related clocks Greg Kroah-Hartman
                   ` (351 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Taniya Das, Konrad Dybcio,
	Stephan Gerhold, Bjorn Andersson

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Stephan Gerhold <stephan.gerhold@linaro.org>

commit ca7e6cc30cde4f0cbeff2e205a84bedf431e9156 upstream.

gcc_apss_axi_clk specifies a halt_reg of 0x4601c, but this is already used
by gcc_apss_ahb_clk. The correct value according to the downstream driver
is 0x46020.

Cc: stable@vger.kernel.org
Fixes: 48b7253264ea ("clk: qcom: Add MDM9607 GCC driver")
Reviewed-by: Taniya Das <taniya.das@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Stephan Gerhold <stephan.gerhold@linaro.org>
Link: https://lore.kernel.org/r/20260706-qcom-clk-mdm9607-fixes-v2-4-745565101869@linaro.org
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/clk/qcom/gcc-mdm9607.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/clk/qcom/gcc-mdm9607.c
+++ b/drivers/clk/qcom/gcc-mdm9607.c
@@ -1414,7 +1414,7 @@ static struct clk_branch gcc_apss_ahb_cl
 };
 
 static struct clk_branch gcc_apss_axi_clk = {
-	.halt_reg = 0x4601c,
+	.halt_reg = 0x46020,
 	.halt_check = BRANCH_HALT_VOTED,
 	.clkr = {
 		.enable_reg = 0x45004,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 218/556] clk: qcom: gcc-mdm9607: Drop incorrect BIMC PLL and related clocks
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (216 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 217/556] clk: qcom: gcc-mdm9607: Fix halt_reg for gcc_apss_axi_clk Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 219/556] i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure Greg Kroah-Hartman
                   ` (350 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Stephan Gerhold, Konrad Dybcio,
	Bjorn Andersson

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Stephan Gerhold <stephan.gerhold@linaro.org>

commit e111ddda092ad961870a634e4c9263c10a3e8485 upstream.

The gcc-mdm9607 driver was originally based on gcc-msm8916, but a closer
match nowadays is gcc-msm8909. Looking at the differences between
gcc-mdm9607 and gcc-msm8909, there is quite some confusion around the
definitions for the BIMC PLL.

It turns out the BIMC PLL on MDM9607 is actually an Alpha PLL just like on
MSM8909. We can vote for it using BIT(2), which explains why BIT(3) was
used for GPLL2.

In practice, the BIMC PLL is exclusively controlled by the RPM firmware and
Linux should not touch it. So far, it was defined to model the full clock
hierarchy, but even in read-only mode with CLK_GET_RATE_NOCACHE this is
problematic since the RPM will silently change the clock parents without
notifying Linux about it. The clock framework reads the clock parent only
once during boot, so the resulting rates will still be often wrong.

Follow the example of more recent SoCs and drop the BIMC PLL and all
remaining related clocks to avoid reporting stale status data. This means
we cannot determine the rate of these clocks anymore. This is not a big
problem in practice, since these are NoC-related clocks that are
independently managed through the interconnect subsystem.

Cc: stable@vger.kernel.org
Fixes: 48b7253264ea ("clk: qcom: Add MDM9607 GCC driver")
Signed-off-by: Stephan Gerhold <stephan.gerhold@linaro.org>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260706-qcom-clk-mdm9607-fixes-v2-8-745565101869@linaro.org
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/clk/qcom/gcc-mdm9607.c |  125 -----------------------------------------
 1 file changed, 1 insertion(+), 124 deletions(-)

--- a/drivers/clk/qcom/gcc-mdm9607.c
+++ b/drivers/clk/qcom/gcc-mdm9607.c
@@ -26,7 +26,6 @@
 
 enum {
 	P_XO,
-	P_BIMC,
 	P_GPLL0,
 	P_GPLL1,
 	P_GPLL2,
@@ -121,7 +120,7 @@ static struct clk_alpha_pll gpll2_early
 	.regs = clk_alpha_pll_regs[CLK_ALPHA_PLL_TYPE_DEFAULT],
 	.clkr = {
 		.enable_reg = 0x45000,
-		.enable_mask = BIT(3), /* Yeah, apparently it's not 2 */
+		.enable_mask = BIT(3), /* BIT(2) is used for BIMC PLL */
 		.hw.init = &(struct clk_init_data)
 		{
 			.name = "gpll2_early",
@@ -178,68 +177,6 @@ static struct clk_rcg2 apss_ahb_clk_src
 	},
 };
 
-static struct clk_pll bimc_pll = {
-	.l_reg = 0x23004,
-	.m_reg = 0x23008,
-	.n_reg = 0x2300c,
-	.config_reg = 0x23010,
-	.mode_reg = 0x23000,
-	.status_reg = 0x2301c,
-	.status_bit = 17,
-	.clkr.hw.init = &(struct clk_init_data){
-		.name = "bimc_pll",
-		.parent_data = &(const struct clk_parent_data){
-			.fw_name = "xo",
-		},
-		.num_parents = 1,
-		.ops = &clk_pll_ops,
-	},
-};
-
-static struct clk_regmap bimc_pll_vote = {
-	.enable_reg = 0x45000,
-	.enable_mask = BIT(3),
-	.hw.init = &(struct clk_init_data){
-		.name = "bimc_pll_vote",
-		.parent_hws = (const struct clk_hw *[]){ &bimc_pll.clkr.hw },
-		.num_parents = 1,
-		.ops = &clk_pll_vote_ops,
-	},
-};
-
-static const struct parent_map gcc_xo_gpll0_bimc_map[] = {
-	{ P_XO, 0 },
-	{ P_GPLL0, 1 },
-	{ P_BIMC, 2 },
-};
-
-static const struct clk_parent_data gcc_xo_gpll0_bimc[] = {
-	{ .fw_name = "xo" },
-	{ .hw = &gpll0.clkr.hw },
-	{ .hw = &bimc_pll_vote.hw },
-};
-
-static const struct freq_tbl ftbl_pcnoc_bfdcd_clk_src[] = {
-	F(19200000, P_XO, 1, 0, 0),
-	F(50000000, P_GPLL0, 16, 0, 0),
-	F(100000000, P_GPLL0, 8, 0, 0),
-	{ }
-};
-
-static struct clk_rcg2 pcnoc_bfdcd_clk_src = {
-	.cmd_rcgr = 0x27000,
-	.freq_tbl = ftbl_pcnoc_bfdcd_clk_src,
-	.hid_width = 5,
-	.parent_map = gcc_xo_gpll0_bimc_map,
-	.clkr.hw.init = &(struct clk_init_data){
-		.name = "pcnoc_bfdcd_clk_src",
-		.parent_data = gcc_xo_gpll0_bimc,
-		.num_parents = ARRAY_SIZE(gcc_xo_gpll0_bimc),
-		.ops = &clk_rcg2_ops,
-		.flags = CLK_IS_CRITICAL,
-	},
-};
-
 static const struct freq_tbl ftbl_gcc_blsp1_qup1_6_i2c_apps_clk[] = {
 	F(19200000, P_XO, 1, 0, 0),
 	F(50000000, P_GPLL0, 16, 0, 0),
@@ -735,8 +672,6 @@ static struct clk_branch gcc_blsp1_ahb_c
 		.enable_mask = BIT(10),
 		.hw.init = &(struct clk_init_data){
 			.name = "gcc_blsp1_ahb_clk",
-			.parent_hws = (const struct clk_hw *[]){ &pcnoc_bfdcd_clk_src.clkr.hw },
-			.num_parents = 1,
 			.ops = &clk_branch2_ops,
 		},
 	},
@@ -1038,8 +973,6 @@ static struct clk_branch gcc_boot_rom_ah
 		.enable_mask = BIT(7),
 		.hw.init = &(struct clk_init_data){
 			.name = "gcc_boot_rom_ahb_clk",
-			.parent_hws = (const struct clk_hw *[]){ &pcnoc_bfdcd_clk_src.clkr.hw },
-			.num_parents = 1,
 			.ops = &clk_branch2_ops,
 		},
 	},
@@ -1053,9 +986,6 @@ static struct clk_branch gcc_crypto_ahb_
 		.enable_mask = BIT(0),
 		.hw.init = &(struct clk_init_data){
 			.name = "gcc_crypto_ahb_clk",
-			.parent_hws = (const struct clk_hw *[]){ &pcnoc_bfdcd_clk_src.clkr.hw },
-			.num_parents = 1,
-			.flags = CLK_SET_RATE_PARENT,
 			.ops = &clk_branch2_ops,
 		},
 	},
@@ -1069,9 +999,6 @@ static struct clk_branch gcc_crypto_axi_
 		.enable_mask = BIT(1),
 		.hw.init = &(struct clk_init_data){
 			.name = "gcc_crypto_axi_clk",
-			.parent_hws = (const struct clk_hw *[]){ &pcnoc_bfdcd_clk_src.clkr.hw },
-			.num_parents = 1,
-			.flags = CLK_SET_RATE_PARENT,
 			.ops = &clk_branch2_ops,
 		},
 	},
@@ -1145,9 +1072,6 @@ static struct clk_branch gcc_mss_cfg_ahb
 		.enable_mask = BIT(0),
 		.hw.init = &(struct clk_init_data){
 			.name = "gcc_mss_cfg_ahb_clk",
-			.parent_hws = (const struct clk_hw *[]){ &pcnoc_bfdcd_clk_src.clkr.hw },
-			.num_parents = 1,
-			.flags = CLK_SET_RATE_PARENT,
 			.ops = &clk_branch2_ops,
 		},
 	},
@@ -1175,9 +1099,6 @@ static struct clk_branch gcc_pdm_ahb_clk
 		.enable_mask = BIT(0),
 		.hw.init = &(struct clk_init_data){
 			.name = "gcc_pdm_ahb_clk",
-			.parent_hws = (const struct clk_hw *[]){ &pcnoc_bfdcd_clk_src.clkr.hw },
-			.num_parents = 1,
-			.flags = CLK_SET_RATE_PARENT,
 			.ops = &clk_branch2_ops,
 		},
 	},
@@ -1191,9 +1112,6 @@ static struct clk_branch gcc_prng_ahb_cl
 		.enable_mask = BIT(8),
 		.hw.init = &(struct clk_init_data){
 			.name = "gcc_prng_ahb_clk",
-			.parent_hws = (const struct clk_hw *[]){ &pcnoc_bfdcd_clk_src.clkr.hw },
-			.num_parents = 1,
-			.flags = CLK_SET_RATE_PARENT,
 			.ops = &clk_branch2_ops,
 		},
 	},
@@ -1206,9 +1124,6 @@ static struct clk_branch gcc_sdcc1_ahb_c
 		.enable_mask = BIT(0),
 		.hw.init = &(struct clk_init_data){
 			.name = "gcc_sdcc1_ahb_clk",
-			.parent_hws = (const struct clk_hw *[]){ &pcnoc_bfdcd_clk_src.clkr.hw },
-			.num_parents = 1,
-			.flags = CLK_SET_RATE_PARENT,
 			.ops = &clk_branch2_ops,
 		},
 	},
@@ -1236,9 +1151,6 @@ static struct clk_branch gcc_sdcc2_ahb_c
 		.enable_mask = BIT(0),
 		.hw.init = &(struct clk_init_data){
 			.name = "gcc_sdcc2_ahb_clk",
-			.parent_hws = (const struct clk_hw *[]){ &pcnoc_bfdcd_clk_src.clkr.hw },
-			.num_parents = 1,
-			.flags = CLK_SET_RATE_PARENT,
 			.ops = &clk_branch2_ops,
 		},
 	},
@@ -1259,19 +1171,6 @@ static struct clk_branch gcc_sdcc2_apps_
 	},
 };
 
-static struct clk_rcg2 bimc_ddr_clk_src = {
-	.cmd_rcgr = 0x32004,
-	.hid_width = 5,
-	.parent_map = gcc_xo_gpll0_bimc_map,
-	.clkr.hw.init = &(struct clk_init_data){
-		.name = "bimc_ddr_clk_src",
-		.parent_data = gcc_xo_gpll0_bimc,
-		.num_parents = 3,
-		.ops = &clk_rcg2_ops,
-		.flags = CLK_GET_RATE_NOCACHE,
-	},
-};
-
 static struct clk_branch gcc_mss_q6_bimc_axi_clk = {
 	.halt_reg = 0x49004,
 	.clkr = {
@@ -1279,9 +1178,6 @@ static struct clk_branch gcc_mss_q6_bimc
 		.enable_mask = BIT(0),
 		.hw.init = &(struct clk_init_data){
 			.name = "gcc_mss_q6_bimc_axi_clk",
-			.parent_hws = (const struct clk_hw *[]){ &bimc_ddr_clk_src.clkr.hw },
-			.num_parents = 1,
-			.flags = CLK_SET_RATE_PARENT,
 			.ops = &clk_branch2_ops,
 		},
 	},
@@ -1295,8 +1191,6 @@ static struct clk_branch gcc_apss_tcu_cl
 		.enable_mask = BIT(1),
 		.hw.init = &(struct clk_init_data){
 			.name = "gcc_apss_tcu_clk",
-			.parent_hws = (const struct clk_hw *[]){ &bimc_ddr_clk_src.clkr.hw },
-			.num_parents = 1,
 			.ops = &clk_branch2_ops,
 		},
 	},
@@ -1310,9 +1204,6 @@ static struct clk_branch gcc_smmu_cfg_cl
 		.enable_mask = BIT(12),
 		.hw.init = &(struct clk_init_data){
 			.name = "gcc_smmu_cfg_clk",
-			.parent_hws = (const struct clk_hw *[]){ &pcnoc_bfdcd_clk_src.clkr.hw },
-			.num_parents = 1,
-			.flags = CLK_SET_RATE_PARENT,
 			.ops = &clk_branch2_ops,
 		},
 	},
@@ -1360,9 +1251,6 @@ static struct clk_branch gcc_usb_hs_phy_
 		.enable_mask = BIT(0),
 		.hw.init = &(struct clk_init_data){
 			.name = "gcc_usb_hs_phy_cfg_ahb_clk",
-			.parent_hws = (const struct clk_hw *[]){ &pcnoc_bfdcd_clk_src.clkr.hw },
-			.num_parents = 1,
-			.flags = CLK_SET_RATE_PARENT,
 			.ops = &clk_branch2_ops,
 		},
 	},
@@ -1375,9 +1263,6 @@ static struct clk_branch gcc_usb_hs_ahb_
 		.enable_mask = BIT(0),
 		.hw.init = &(struct clk_init_data){
 			.name = "gcc_usb_hs_ahb_clk",
-			.parent_hws = (const struct clk_hw *[]){ &pcnoc_bfdcd_clk_src.clkr.hw },
-			.num_parents = 1,
-			.flags = CLK_SET_RATE_PARENT,
 			.ops = &clk_branch2_ops,
 		},
 	},
@@ -1406,8 +1291,6 @@ static struct clk_branch gcc_apss_ahb_cl
 		.enable_mask = BIT(14),
 		.hw.init = &(struct clk_init_data){
 			.name = "gcc_apss_ahb_clk",
-			.parent_hws = (const struct clk_hw *[]){ &pcnoc_bfdcd_clk_src.clkr.hw },
-			.num_parents = 1,
 			.ops = &clk_branch2_ops,
 		},
 	},
@@ -1421,8 +1304,6 @@ static struct clk_branch gcc_apss_axi_cl
 		.enable_mask = BIT(13),
 		.hw.init = &(struct clk_init_data){
 			.name = "gcc_apss_axi_clk",
-			.parent_hws = (const struct clk_hw *[]){ &pcnoc_bfdcd_clk_src.clkr.hw },
-			.num_parents = 1,
 			.ops = &clk_branch2_ops,
 		},
 	},
@@ -1435,10 +1316,6 @@ static struct clk_regmap *gcc_mdm9607_cl
 	[GPLL1_VOTE] = &gpll1_vote,
 	[GPLL2] = &gpll2.clkr,
 	[GPLL2_EARLY] = &gpll2_early.clkr,
-	[BIMC_PLL] = &bimc_pll.clkr,
-	[BIMC_PLL_VOTE] = &bimc_pll_vote,
-	[BIMC_DDR_CLK_SRC] = &bimc_ddr_clk_src.clkr,
-	[PCNOC_BFDCD_CLK_SRC] = &pcnoc_bfdcd_clk_src.clkr,
 	[APSS_AHB_CLK_SRC] = &apss_ahb_clk_src.clkr,
 	[BLSP1_QUP1_I2C_APPS_CLK_SRC] = &blsp1_qup1_i2c_apps_clk_src.clkr,
 	[BLSP1_QUP1_SPI_APPS_CLK_SRC] = &blsp1_qup1_spi_apps_clk_src.clkr,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 219/556] i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (217 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 218/556] clk: qcom: gcc-mdm9607: Drop incorrect BIMC PLL and related clocks Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 220/556] ASoC: adau1761: sort the register default table Greg Kroah-Hartman
                   ` (349 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Linkai Gong, Andi Shyti

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Linkai Gong <gonglinkai@kylinos.cn>

commit 62edb8ca0aa44517cc23cfa26cd8a51f15ea92fe upstream.

of_parse_phandle() takes a reference on the parent node. If a later
devm_kstrdup() fails, err_rollback only releases nodes for indices
0..i-1, so the current node is leaked.

of_node_put() the current parent before rolling back.

Fixes: 7c0195fa9a9e ("i2c: mux: demux-pinctrl: check the return value of devm_kstrdup()")
Signed-off-by: Linkai Gong <gonglinkai@kylinos.cn>
Cc: <stable@vger.kernel.org> # v6.6+
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260813095617.2246320-1-gonglinkai@kylinos.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/i2c/muxes/i2c-demux-pinctrl.c |    1 +
 1 file changed, 1 insertion(+)

--- a/drivers/i2c/muxes/i2c-demux-pinctrl.c
+++ b/drivers/i2c/muxes/i2c-demux-pinctrl.c
@@ -247,6 +247,7 @@ static int i2c_demux_pinctrl_probe(struc
 		props[i].value = devm_kstrdup(&pdev->dev, "ok", GFP_KERNEL);
 		if (!props[i].name || !props[i].value) {
 			err = -ENOMEM;
+			of_node_put(adap_np);
 			goto err_rollback;
 		}
 		props[i].length = 3;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 220/556] ASoC: adau1761: sort the register default table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (218 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 219/556] i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 221/556] ASoC: cs35l33: drain threaded IRQ before runtime suspend Greg Kroah-Hartman
                   ` (348 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Nuno Sá,
	Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit cc606b6c2328b4864885db6afcad7e78c0ac7a73 upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

The table lists the ADAU1761 specific registers (0x4008 and up) before
the block shared with the ADAU1381/ADAU1781, which starts at
ADAU17X1_CLOCK_CONTROL (0x4000), so bsearch() descends into the wrong
half and 28 of the 52 entries are unreachable.
regcache_reg_needs_sync() then cannot compare them against their default
and reports that a sync is needed, so they are written to the device on
every regcache_sync() even when they were never touched.

Sort the table by register address.

Fixes: dab464b60b24 ("ASoC: Add ADAU1361/ADAU1761 audio CODEC support")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Acked-by: Nuno Sá <nuno.sa@analog.com>
Link: https://patch.msgid.link/20260805122713.11376-1-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/adau1761.c |   34 +++++++++++++++++-----------------
 1 file changed, 17 insertions(+), 17 deletions(-)

--- a/sound/soc/codecs/adau1761.c
+++ b/sound/soc/codecs/adau1761.c
@@ -68,23 +68,33 @@
 #define ADAU1761_FIRMWARE "adau1761.bin"
 
 static const struct reg_default adau1761_reg_defaults[] = {
-	{ ADAU1761_DEJITTER,			0x03 },
+	{ ADAU17X1_CLOCK_CONTROL,		0x00 },
+	{ ADAU17X1_PLL_CONTROL,			0x00 },
 	{ ADAU1761_DIGMIC_JACKDETECT,		0x00 },
+	{ ADAU17X1_REC_POWER_MGMT,		0x00 },
 	{ ADAU1761_REC_MIXER_LEFT0,		0x00 },
 	{ ADAU1761_REC_MIXER_LEFT1,		0x00 },
 	{ ADAU1761_REC_MIXER_RIGHT0,		0x00 },
 	{ ADAU1761_REC_MIXER_RIGHT1,		0x00 },
 	{ ADAU1761_LEFT_DIFF_INPUT_VOL,		0x00 },
+	{ ADAU1761_RIGHT_DIFF_INPUT_VOL,	0x00 },
+	{ ADAU17X1_MICBIAS,			0x00 },
 	{ ADAU1761_ALC_CTRL0,			0x00 },
 	{ ADAU1761_ALC_CTRL1,			0x00 },
 	{ ADAU1761_ALC_CTRL2,			0x00 },
 	{ ADAU1761_ALC_CTRL3,			0x00 },
-	{ ADAU1761_RIGHT_DIFF_INPUT_VOL,	0x00 },
-	{ ADAU1761_PLAY_LR_MIXER_LEFT,		0x00 },
+	{ ADAU17X1_SERIAL_PORT0,		0x00 },
+	{ ADAU17X1_SERIAL_PORT1,		0x00 },
+	{ ADAU17X1_CONVERTER0,			0x00 },
+	{ ADAU17X1_CONVERTER1,			0x00 },
+	{ ADAU17X1_ADC_CONTROL,			0x00 },
+	{ ADAU17X1_LEFT_INPUT_DIGITAL_VOL,	0x00 },
+	{ ADAU17X1_RIGHT_INPUT_DIGITAL_VOL,	0x00 },
 	{ ADAU1761_PLAY_MIXER_LEFT0,		0x00 },
 	{ ADAU1761_PLAY_MIXER_LEFT1,		0x00 },
 	{ ADAU1761_PLAY_MIXER_RIGHT0,		0x00 },
 	{ ADAU1761_PLAY_MIXER_RIGHT1,		0x00 },
+	{ ADAU1761_PLAY_LR_MIXER_LEFT,		0x00 },
 	{ ADAU1761_PLAY_LR_MIXER_RIGHT,		0x00 },
 	{ ADAU1761_PLAY_MIXER_MONO,		0x00 },
 	{ ADAU1761_PLAY_HP_LEFT_VOL,		0x00 },
@@ -93,20 +103,6 @@ static const struct reg_default adau1761
 	{ ADAU1761_PLAY_LINE_RIGHT_VOL,		0x00 },
 	{ ADAU1761_PLAY_MONO_OUTPUT_VOL,	0x00 },
 	{ ADAU1761_POP_CLICK_SUPPRESS,		0x00 },
-	{ ADAU1761_JACK_DETECT_PIN,		0x00 },
-	{ ADAU1761_CLK_ENABLE0,			0x00 },
-	{ ADAU1761_CLK_ENABLE1,			0x00 },
-	{ ADAU17X1_CLOCK_CONTROL,		0x00 },
-	{ ADAU17X1_PLL_CONTROL,			0x00 },
-	{ ADAU17X1_REC_POWER_MGMT,		0x00 },
-	{ ADAU17X1_MICBIAS,			0x00 },
-	{ ADAU17X1_SERIAL_PORT0,		0x00 },
-	{ ADAU17X1_SERIAL_PORT1,		0x00 },
-	{ ADAU17X1_CONVERTER0,			0x00 },
-	{ ADAU17X1_CONVERTER1,			0x00 },
-	{ ADAU17X1_LEFT_INPUT_DIGITAL_VOL,	0x00 },
-	{ ADAU17X1_RIGHT_INPUT_DIGITAL_VOL,	0x00 },
-	{ ADAU17X1_ADC_CONTROL,			0x00 },
 	{ ADAU17X1_PLAY_POWER_MGMT,		0x00 },
 	{ ADAU17X1_DAC_CONTROL0,		0x00 },
 	{ ADAU17X1_DAC_CONTROL1,		0x00 },
@@ -114,12 +110,16 @@ static const struct reg_default adau1761
 	{ ADAU17X1_SERIAL_PORT_PAD,		0xaa },
 	{ ADAU17X1_CONTROL_PORT_PAD0,		0xaa },
 	{ ADAU17X1_CONTROL_PORT_PAD1,		0x00 },
+	{ ADAU1761_JACK_DETECT_PIN,		0x00 },
+	{ ADAU1761_DEJITTER,			0x03 },
 	{ ADAU17X1_DSP_SAMPLING_RATE,		0x01 },
 	{ ADAU17X1_SERIAL_INPUT_ROUTE,		0x00 },
 	{ ADAU17X1_SERIAL_OUTPUT_ROUTE,		0x00 },
 	{ ADAU17X1_DSP_ENABLE,			0x00 },
 	{ ADAU17X1_DSP_RUN,			0x00 },
 	{ ADAU17X1_SERIAL_SAMPLING_RATE,	0x00 },
+	{ ADAU1761_CLK_ENABLE0,			0x00 },
+	{ ADAU1761_CLK_ENABLE1,			0x00 },
 };
 
 static const DECLARE_TLV_DB_SCALE(adau1761_sing_in_tlv, -1500, 300, 1);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 221/556] ASoC: cs35l33: drain threaded IRQ before runtime suspend
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (219 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 220/556] ASoC: adau1761: sort the register default table Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 222/556] ASoC: cs35l34: " Greg Kroah-Hartman
                   ` (347 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Runyu Xiao, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Runyu Xiao <runyu.xiao@seu.edu.cn>

commit e074c12c428c633e079154301207a6079a208583 upstream.

cs35l33_runtime_suspend() currently switches the codec into
regcache_cache_only(true) and powers it down without first quiescing the
threaded IRQ registered by devm_request_threaded_irq(). That leaves a
window where cs35l33_irq_thread() can still run after suspend has closed
off live register access.

A running system can reach this during runtime PM while the driver still
has critical fault IRQs unmasked. If the threaded handler runs in that
window, it reads volatile INT_STATUS_1/2 after cache_only has been
enabled, ignores the regmap_read() failures, and can still drive the
AMP_SHORT_RLS, CAL_ERR_RLS, OTE_RLS, and OTW_RLS release paths.

Use disable_irq() before entering cache_only/power-off so any in-flight
threaded handler is drained and no new IRQ thread can run during the
suspended state. Re-enable the IRQ only after runtime_resume() has
restored live register access with regcache_sync(). Since probe only
warns if devm_request_threaded_irq() fails, track whether the IRQ was
actually installed before disabling or re-enabling it.

Fixes: 3333cb7187b9 ("ASoC: cs35l33: Initial commit of the cs35l33 CODEC driver.")
Cc: stable@vger.kernel.org
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Link: https://patch.msgid.link/20260611161553.3378721-2-runyu.xiao@seu.edu.cn
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/cs35l33.c |   14 ++++++++++++--
 1 file changed, 12 insertions(+), 2 deletions(-)

--- a/sound/soc/codecs/cs35l33.c
+++ b/sound/soc/codecs/cs35l33.c
@@ -40,6 +40,7 @@ struct cs35l33_private {
 	struct regmap *regmap;
 	struct gpio_desc *reset_gpio;
 	bool amp_cal;
+	bool irq_requested;
 	int mclk_int;
 	struct regulator_bulk_data core_supplies[2];
 	int num_core_supplies;
@@ -881,6 +882,9 @@ static int cs35l33_runtime_resume(struct
 		goto err;
 	}
 
+	if (cs35l33->irq_requested)
+		enable_irq(to_i2c_client(dev)->irq);
+
 	return 0;
 
 err:
@@ -900,6 +904,10 @@ static int cs35l33_runtime_suspend(struc
 	/* redo the calibration in next power up */
 	cs35l33->amp_cal = false;
 
+	/* Drain and block the threaded IRQ before cache_only/power-off. */
+	if (cs35l33->irq_requested)
+		disable_irq(to_i2c_client(dev)->irq);
+
 	regcache_cache_only(cs35l33->regmap, true);
 	regcache_mark_dirty(cs35l33->regmap);
 	regulator_bulk_disable(cs35l33->num_core_supplies,
@@ -1154,10 +1162,12 @@ static int cs35l33_i2c_probe(struct i2c_
 	}
 
 	ret = devm_request_threaded_irq(&i2c_client->dev, i2c_client->irq, NULL,
-			cs35l33_irq_thread, IRQF_ONESHOT | IRQF_TRIGGER_LOW,
-			"cs35l33", cs35l33);
+				cs35l33_irq_thread, IRQF_ONESHOT | IRQF_TRIGGER_LOW,
+				"cs35l33", cs35l33);
 	if (ret != 0)
 		dev_warn(&i2c_client->dev, "Failed to request IRQ: %d\n", ret);
+	else
+		cs35l33->irq_requested = true;
 
 	/* We could issue !RST or skip it based on AMP topology */
 	cs35l33->reset_gpio = devm_gpiod_get_optional(&i2c_client->dev,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 222/556] ASoC: cs35l34: drain threaded IRQ before runtime suspend
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (220 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 221/556] ASoC: cs35l33: drain threaded IRQ before runtime suspend Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 223/556] ASoC: cx2072x: sort the register default table Greg Kroah-Hartman
                   ` (346 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Runyu Xiao, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Runyu Xiao <runyu.xiao@seu.edu.cn>

commit 4105a4c0678b2808fc8046b60321b4f1cc7dae75 upstream.

cs35l34_runtime_suspend() currently switches the codec into
regcache_cache_only(true), asserts reset low, and powers the device off
without first quiescing the threaded IRQ registered by
devm_request_threaded_irq(). That leaves a window where
cs35l34_irq_thread() can still run after suspend has removed live
hardware access.

A running system can reach this during runtime PM while the driver still
has critical fault IRQs unmasked. If the threaded handler runs in that
window, it reads volatile INT_STATUS_1..4 after cache_only has been
enabled, ignores the regmap_read() failures, and can still execute the
PROT_RELEASE_CTL release sequence or the BST fault power-down writes.

Use disable_irq() before entering cache_only/reset-low/power-off so any
in-flight threaded handler is drained and no new IRQ thread can run
while the device is suspended. Re-enable the IRQ only after
runtime_resume() has restored live register access with regcache_sync().
Since probe only logs request_threaded_irq() failures and keeps going,
track whether the IRQ was actually installed before disabling or
re-enabling it.

Fixes: c1124c09e103 ("ASoC: cs35l34: Initial commit of the cs35l34 CODEC driver.")
Cc: stable@vger.kernel.org
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Link: https://patch.msgid.link/20260611161553.3378721-3-runyu.xiao@seu.edu.cn
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/cs35l34.c |   14 ++++++++++++--
 1 file changed, 12 insertions(+), 2 deletions(-)

--- a/sound/soc/codecs/cs35l34.c
+++ b/sound/soc/codecs/cs35l34.c
@@ -45,6 +45,7 @@ struct  cs35l34_private {
 	int num_core_supplies;
 	int mclk_int;
 	bool tdm_mode;
+	bool irq_requested;
 	struct gpio_desc *reset_gpio;	/* Active-low reset GPIO */
 };
 
@@ -1032,10 +1033,12 @@ static int cs35l34_i2c_probe(struct i2c_
 	}
 
 	ret = devm_request_threaded_irq(&i2c_client->dev, i2c_client->irq, NULL,
-			cs35l34_irq_thread, IRQF_ONESHOT | IRQF_TRIGGER_LOW,
-			"cs35l34", cs35l34);
+				cs35l34_irq_thread, IRQF_ONESHOT | IRQF_TRIGGER_LOW,
+				"cs35l34", cs35l34);
 	if (ret != 0)
 		dev_err(&i2c_client->dev, "Failed to request IRQ: %d\n", ret);
+	else
+		cs35l34->irq_requested = true;
 
 	cs35l34->reset_gpio = devm_gpiod_get_optional(&i2c_client->dev,
 				"reset", GPIOD_OUT_LOW);
@@ -1140,6 +1143,9 @@ static int cs35l34_runtime_resume(struct
 		dev_err(dev, "Failed to restore register cache\n");
 		goto err;
 	}
+
+	if (cs35l34->irq_requested)
+		enable_irq(to_i2c_client(dev)->irq);
 	return 0;
 err:
 	regcache_cache_only(cs35l34->regmap, true);
@@ -1153,6 +1159,10 @@ static int cs35l34_runtime_suspend(struc
 {
 	struct cs35l34_private *cs35l34 = dev_get_drvdata(dev);
 
+	/* Drain and block the threaded IRQ before cache_only/power-off. */
+	if (cs35l34->irq_requested)
+		disable_irq(to_i2c_client(dev)->irq);
+
 	regcache_cache_only(cs35l34->regmap, true);
 	regcache_mark_dirty(cs35l34->regmap);
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 223/556] ASoC: cx2072x: sort the register default table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (221 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 222/556] ASoC: cs35l34: " Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 224/556] ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure Greg Kroah-Hartman
                   ` (345 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit b927853f70078262780a4e623631584a25eb7284 upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

The table is grouped by function rather than by address: for every node
the amplifier gain registers (0x41c0, 0x45c0, ...) are listed before the
power state and stream format registers of the same node (0x4014,
0x4414, ...).  This leaves 75 of the 132 entries unreachable.
regcache_reg_needs_sync() then cannot compare them against their default
and reports that a sync is needed, so they are written to the device on
every regcache_sync() even when they were never touched.

Sort the table by register address.

Fixes: a497a4363706 ("ASoC: Add support for Conexant CX2072X CODEC")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805122811.13713-3-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/cx2072x.c |  122 ++++++++++++++++++++++-----------------------
 1 file changed, 61 insertions(+), 61 deletions(-)

--- a/sound/soc/codecs/cx2072x.c
+++ b/sound/soc/codecs/cx2072x.c
@@ -96,51 +96,60 @@ static const struct reg_default cx2072x_
 	{ CX2072X_GPIO_WAKE, 0x00000000 },
 	{ CX2072X_GPIO_UM_ENABLE, 0x00000000 },
 	{ CX2072X_GPIO_STICKY_MASK, 0x00000000 },
-	{ CX2072X_DAC1_CONVERTER_FORMAT, 0x00000031 },
-	{ CX2072X_DAC1_AMP_GAIN_RIGHT, 0x0000004a },
-	{ CX2072X_DAC1_AMP_GAIN_LEFT, 0x0000004a },
 	{ CX2072X_DAC1_POWER_STATE, 0x00000433 },
 	{ CX2072X_DAC1_CONVERTER_STREAM_CHANNEL, 0x00000000 },
 	{ CX2072X_DAC1_EAPD_ENABLE, 0x00000000 },
-	{ CX2072X_DAC2_CONVERTER_FORMAT, 0x00000031 },
-	{ CX2072X_DAC2_AMP_GAIN_RIGHT, 0x0000004a },
-	{ CX2072X_DAC2_AMP_GAIN_LEFT, 0x0000004a },
+	{ CX2072X_DAC1_AMP_GAIN_RIGHT, 0x0000004a },
+	{ CX2072X_DAC1_AMP_GAIN_LEFT, 0x0000004a },
+	{ CX2072X_DAC1_CONVERTER_FORMAT, 0x00000031 },
 	{ CX2072X_DAC2_POWER_STATE, 0x00000433 },
 	{ CX2072X_DAC2_CONVERTER_STREAM_CHANNEL, 0x00000000 },
-	{ CX2072X_ADC1_CONVERTER_FORMAT, 0x00000031 },
+	{ CX2072X_DAC2_AMP_GAIN_RIGHT, 0x0000004a },
+	{ CX2072X_DAC2_AMP_GAIN_LEFT, 0x0000004a },
+	{ CX2072X_DAC2_CONVERTER_FORMAT, 0x00000031 },
+	{ CX2072X_ADC1_CONNECTION_SELECT_CONTROL, 0x00000000 },
+	{ CX2072X_ADC1_POWER_STATE, 0x00000433 },
+	{ CX2072X_ADC1_CONVERTER_STREAM_CHANNEL, 0x00000000 },
 	{ CX2072X_ADC1_AMP_GAIN_RIGHT_0, 0x0000004a },
-	{ CX2072X_ADC1_AMP_GAIN_LEFT_0, 0x0000004a },
 	{ CX2072X_ADC1_AMP_GAIN_RIGHT_1, 0x0000004a },
-	{ CX2072X_ADC1_AMP_GAIN_LEFT_1, 0x0000004a },
 	{ CX2072X_ADC1_AMP_GAIN_RIGHT_2, 0x0000004a },
-	{ CX2072X_ADC1_AMP_GAIN_LEFT_2, 0x0000004a },
 	{ CX2072X_ADC1_AMP_GAIN_RIGHT_3, 0x0000004a },
-	{ CX2072X_ADC1_AMP_GAIN_LEFT_3, 0x0000004a },
 	{ CX2072X_ADC1_AMP_GAIN_RIGHT_4, 0x0000004a },
-	{ CX2072X_ADC1_AMP_GAIN_LEFT_4, 0x0000004a },
 	{ CX2072X_ADC1_AMP_GAIN_RIGHT_5, 0x0000004a },
-	{ CX2072X_ADC1_AMP_GAIN_LEFT_5, 0x0000004a },
 	{ CX2072X_ADC1_AMP_GAIN_RIGHT_6, 0x0000004a },
+	{ CX2072X_ADC1_AMP_GAIN_LEFT_0, 0x0000004a },
+	{ CX2072X_ADC1_AMP_GAIN_LEFT_1, 0x0000004a },
+	{ CX2072X_ADC1_AMP_GAIN_LEFT_2, 0x0000004a },
+	{ CX2072X_ADC1_AMP_GAIN_LEFT_3, 0x0000004a },
+	{ CX2072X_ADC1_AMP_GAIN_LEFT_4, 0x0000004a },
+	{ CX2072X_ADC1_AMP_GAIN_LEFT_5, 0x0000004a },
 	{ CX2072X_ADC1_AMP_GAIN_LEFT_6, 0x0000004a },
-	{ CX2072X_ADC1_CONNECTION_SELECT_CONTROL, 0x00000000 },
-	{ CX2072X_ADC1_POWER_STATE, 0x00000433 },
-	{ CX2072X_ADC1_CONVERTER_STREAM_CHANNEL, 0x00000000 },
-	{ CX2072X_ADC2_CONVERTER_FORMAT, 0x00000031 },
+	{ CX2072X_ADC1_CONVERTER_FORMAT, 0x00000031 },
+	{ CX2072X_ADC2_CONNECTION_SELECT_CONTROL, 0x00000000 },
+	{ CX2072X_ADC2_POWER_STATE, 0x00000433 },
+	{ CX2072X_ADC2_CONVERTER_STREAM_CHANNEL, 0x00000000 },
 	{ CX2072X_ADC2_AMP_GAIN_RIGHT_0, 0x0000004a },
-	{ CX2072X_ADC2_AMP_GAIN_LEFT_0, 0x0000004a },
 	{ CX2072X_ADC2_AMP_GAIN_RIGHT_1, 0x0000004a },
-	{ CX2072X_ADC2_AMP_GAIN_LEFT_1, 0x0000004a },
 	{ CX2072X_ADC2_AMP_GAIN_RIGHT_2, 0x0000004a },
+	{ CX2072X_ADC2_AMP_GAIN_LEFT_0, 0x0000004a },
+	{ CX2072X_ADC2_AMP_GAIN_LEFT_1, 0x0000004a },
 	{ CX2072X_ADC2_AMP_GAIN_LEFT_2, 0x0000004a },
-	{ CX2072X_ADC2_CONNECTION_SELECT_CONTROL, 0x00000000 },
-	{ CX2072X_ADC2_POWER_STATE, 0x00000433 },
-	{ CX2072X_ADC2_CONVERTER_STREAM_CHANNEL, 0x00000000 },
+	{ CX2072X_ADC2_CONVERTER_FORMAT, 0x00000031 },
+	{ CX2072X_MIXER_POWER_STATE, 0x00000433 },
+	{ CX2072X_MIXER_GAIN_RIGHT_0, 0x0000004a },
+	{ CX2072X_MIXER_GAIN_RIGHT_1, 0x0000004a },
+	{ CX2072X_MIXER_GAIN_LEFT_0, 0x0000004a },
+	{ CX2072X_MIXER_GAIN_LEFT_1, 0x0000004a },
 	{ CX2072X_PORTA_CONNECTION_SELECT_CTRL, 0x00000000 },
 	{ CX2072X_PORTA_POWER_STATE, 0x00000433 },
 	{ CX2072X_PORTA_PIN_CTRL, 0x000000c0 },
 	{ CX2072X_PORTA_UNSOLICITED_RESPONSE, 0x00000000 },
 	{ CX2072X_PORTA_PIN_SENSE, 0x00000000 },
 	{ CX2072X_PORTA_EAPD_BTL, 0x00000002 },
+	{ CX2072X_PORTG_CONNECTION_SELECT_CTRL, 0x00000000 },
+	{ CX2072X_PORTG_POWER_STATE, 0x00000433 },
+	{ CX2072X_PORTG_PIN_CTRL, 0x00000040 },
+	{ CX2072X_PORTG_EAPD_BTL, 0x00000002 },
 	{ CX2072X_PORTB_POWER_STATE, 0x00000433 },
 	{ CX2072X_PORTB_PIN_CTRL, 0x00000000 },
 	{ CX2072X_PORTB_UNSOLICITED_RESPONSE, 0x00000000 },
@@ -148,43 +157,16 @@ static const struct reg_default cx2072x_
 	{ CX2072X_PORTB_EAPD_BTL, 0x00000002 },
 	{ CX2072X_PORTB_GAIN_RIGHT, 0x00000000 },
 	{ CX2072X_PORTB_GAIN_LEFT, 0x00000000 },
-	{ CX2072X_PORTC_POWER_STATE, 0x00000433 },
-	{ CX2072X_PORTC_PIN_CTRL, 0x00000000 },
-	{ CX2072X_PORTC_GAIN_RIGHT, 0x00000000 },
-	{ CX2072X_PORTC_GAIN_LEFT, 0x00000000 },
 	{ CX2072X_PORTD_POWER_STATE, 0x00000433 },
 	{ CX2072X_PORTD_PIN_CTRL, 0x00000020 },
 	{ CX2072X_PORTD_UNSOLICITED_RESPONSE, 0x00000000 },
 	{ CX2072X_PORTD_PIN_SENSE, 0x00000000 },
 	{ CX2072X_PORTD_GAIN_RIGHT, 0x00000000 },
 	{ CX2072X_PORTD_GAIN_LEFT, 0x00000000 },
-	{ CX2072X_PORTE_CONNECTION_SELECT_CTRL, 0x00000000 },
-	{ CX2072X_PORTE_POWER_STATE, 0x00000433 },
-	{ CX2072X_PORTE_PIN_CTRL, 0x00000040 },
-	{ CX2072X_PORTE_UNSOLICITED_RESPONSE, 0x00000000 },
-	{ CX2072X_PORTE_PIN_SENSE, 0x00000000 },
-	{ CX2072X_PORTE_EAPD_BTL, 0x00000002 },
-	{ CX2072X_PORTE_GAIN_RIGHT, 0x00000000 },
-	{ CX2072X_PORTE_GAIN_LEFT, 0x00000000 },
-	{ CX2072X_PORTF_POWER_STATE, 0x00000433 },
-	{ CX2072X_PORTF_PIN_CTRL, 0x00000000 },
-	{ CX2072X_PORTF_UNSOLICITED_RESPONSE, 0x00000000 },
-	{ CX2072X_PORTF_PIN_SENSE, 0x00000000 },
-	{ CX2072X_PORTF_GAIN_RIGHT, 0x00000000 },
-	{ CX2072X_PORTF_GAIN_LEFT, 0x00000000 },
-	{ CX2072X_PORTG_POWER_STATE, 0x00000433 },
-	{ CX2072X_PORTG_PIN_CTRL, 0x00000040 },
-	{ CX2072X_PORTG_CONNECTION_SELECT_CTRL, 0x00000000 },
-	{ CX2072X_PORTG_EAPD_BTL, 0x00000002 },
-	{ CX2072X_PORTM_POWER_STATE, 0x00000433 },
-	{ CX2072X_PORTM_PIN_CTRL, 0x00000000 },
-	{ CX2072X_PORTM_CONNECTION_SELECT_CTRL, 0x00000000 },
-	{ CX2072X_PORTM_EAPD_BTL, 0x00000002 },
-	{ CX2072X_MIXER_POWER_STATE, 0x00000433 },
-	{ CX2072X_MIXER_GAIN_RIGHT_0, 0x0000004a },
-	{ CX2072X_MIXER_GAIN_LEFT_0, 0x0000004a },
-	{ CX2072X_MIXER_GAIN_RIGHT_1, 0x0000004a },
-	{ CX2072X_MIXER_GAIN_LEFT_1, 0x0000004a },
+	{ CX2072X_PORTC_POWER_STATE, 0x00000433 },
+	{ CX2072X_PORTC_PIN_CTRL, 0x00000000 },
+	{ CX2072X_PORTC_GAIN_RIGHT, 0x00000000 },
+	{ CX2072X_PORTC_GAIN_LEFT, 0x00000000 },
 	{ CX2072X_SPKR_DRC_ENABLE_STEP, 0x040065a4 },
 	{ CX2072X_SPKR_DRC_CONTROL, 0x007b0024 },
 	{ CX2072X_SPKR_DRC_TEST, 0x00000000 },
@@ -195,12 +177,15 @@ static const struct reg_default cx2072x_
 	{ CX2072X_I2SPCM_CONTROL3, 0x00000000 },
 	{ CX2072X_I2SPCM_CONTROL4, 0x00000000 },
 	{ CX2072X_I2SPCM_CONTROL5, 0x00000000 },
-	{ CX2072X_I2SPCM_CONTROL6, 0x00000000 },
 	{ CX2072X_UM_INTERRUPT_CRTL_E, 0x00000000 },
+	{ CX2072X_I2SPCM_CONTROL6, 0x00000000 },
+	{ CX2072X_DIGITAL_TEST16, 0x00000021 },
+	{ CX2072X_DIGITAL_TEST17, 0x00000018 },
+	{ CX2072X_DIGITAL_TEST18, 0x00000024 },
+	{ CX2072X_DIGITAL_TEST19, 0x00000001 },
+	{ CX2072X_DIGITAL_TEST20, 0x00000002 },
 	{ CX2072X_CODEC_TEST2, 0x00000000 },
 	{ CX2072X_CODEC_TEST9, 0x00000004 },
-	{ CX2072X_CODEC_TEST20, 0x00000600 },
-	{ CX2072X_CODEC_TEST26, 0x00000208 },
 	{ CX2072X_ANALOG_TEST4, 0x00000000 },
 	{ CX2072X_ANALOG_TEST5, 0x00000000 },
 	{ CX2072X_ANALOG_TEST6, 0x0000059a },
@@ -215,11 +200,26 @@ static const struct reg_default cx2072x_
 	{ CX2072X_DIGITAL_TEST11, 0x00000000 },
 	{ CX2072X_DIGITAL_TEST12, 0x00000084 },
 	{ CX2072X_DIGITAL_TEST15, 0x00000077 },
-	{ CX2072X_DIGITAL_TEST16, 0x00000021 },
-	{ CX2072X_DIGITAL_TEST17, 0x00000018 },
-	{ CX2072X_DIGITAL_TEST18, 0x00000024 },
-	{ CX2072X_DIGITAL_TEST19, 0x00000001 },
-	{ CX2072X_DIGITAL_TEST20, 0x00000002 },
+	{ CX2072X_CODEC_TEST20, 0x00000600 },
+	{ CX2072X_CODEC_TEST26, 0x00000208 },
+	{ CX2072X_PORTE_CONNECTION_SELECT_CTRL, 0x00000000 },
+	{ CX2072X_PORTE_POWER_STATE, 0x00000433 },
+	{ CX2072X_PORTE_PIN_CTRL, 0x00000040 },
+	{ CX2072X_PORTE_UNSOLICITED_RESPONSE, 0x00000000 },
+	{ CX2072X_PORTE_PIN_SENSE, 0x00000000 },
+	{ CX2072X_PORTE_EAPD_BTL, 0x00000002 },
+	{ CX2072X_PORTE_GAIN_RIGHT, 0x00000000 },
+	{ CX2072X_PORTE_GAIN_LEFT, 0x00000000 },
+	{ CX2072X_PORTF_POWER_STATE, 0x00000433 },
+	{ CX2072X_PORTF_PIN_CTRL, 0x00000000 },
+	{ CX2072X_PORTF_UNSOLICITED_RESPONSE, 0x00000000 },
+	{ CX2072X_PORTF_PIN_SENSE, 0x00000000 },
+	{ CX2072X_PORTF_GAIN_RIGHT, 0x00000000 },
+	{ CX2072X_PORTF_GAIN_LEFT, 0x00000000 },
+	{ CX2072X_PORTM_CONNECTION_SELECT_CTRL, 0x00000000 },
+	{ CX2072X_PORTM_POWER_STATE, 0x00000433 },
+	{ CX2072X_PORTM_PIN_CTRL, 0x00000000 },
+	{ CX2072X_PORTM_EAPD_BTL, 0x00000002 },
 };
 
 /*



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 224/556] ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (222 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 223/556] ASoC: cx2072x: sort the register default table Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 225/556] ASoC: fsl_easrc: Use div64_u64 for 64-by-64 division Greg Kroah-Hartman
                   ` (344 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Haoxiang Li, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Haoxiang Li <haoxiang_li2024@163.com>

commit 3a89ddcf0c3d9a068631e8c24d5c9e81d1e6512a upstream.

mpc5200_audio_dma_create() creates the DMA resources before registering
the component. If snd_soc_register_component() fails, the function
returns directly and leaves the DMA resources allocated.

Call mpc5200_audio_dma_destroy() before returning from this error path.

Fixes: f515b67381de ("ASoC: fsl: mpc5200 combine psc_dma platform data")
Cc: stable@vger.kernel.org
Signed-off-by: Haoxiang Li <haoxiang_li2024@163.com>
Link: https://patch.msgid.link/20260622094822.926166-1-haoxiang_li2024@163.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/fsl/mpc5200_psc_i2s.c |    1 +
 1 file changed, 1 insertion(+)

--- a/sound/soc/fsl/mpc5200_psc_i2s.c
+++ b/sound/soc/fsl/mpc5200_psc_i2s.c
@@ -170,6 +170,7 @@ static int psc_i2s_of_probe(struct platf
 					psc_i2s_dai, ARRAY_SIZE(psc_i2s_dai));
 	if (rc != 0) {
 		pr_err("Failed to register DAI\n");
+		mpc5200_audio_dma_destroy(op);
 		return rc;
 	}
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 225/556] ASoC: fsl_easrc: Use div64_u64 for 64-by-64 division
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (223 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 224/556] ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 226/556] ASoC: fsl_easrc: sort the register default table Greg Kroah-Hartman
                   ` (343 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, wangdicheng, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: wangdicheng <wangdicheng@kylinos.cn>

commit a46ccc71877e962783e0fffa105e41615904c511 upstream.

Fix a coccinelle warning about do_div() truncating a 64-bit divisor:

sound/soc/fsl/fsl_easrc.c:2061:2-8: WARNING: do_div() does a 64-by-32 division, please consider using div64_u64 instead.

In fsl_easrc_m2m_calc_out_len(), val1 is computed as:

  val1 = (u64)in_rate << frac_bits;   // frac_bits up to 39
  do_div(val1, out_rate);
  val1 += (s64)ctx_priv->ratio_mod << (frac_bits - 31);
  val1 = val1 >> 12;

In the worst case (in_rate=384000, out_rate=8000, frac_bits=39):
  val1 = 384000 << 39 / 8000 = 26,388,279,068,672
  val1 >> 12 = 6,440,497,829  (33 bits, exceeds 32-bit range)

val1 is then used as the divisor in do_div(val2, val1), where
do_div() silently truncates it to 32 bits, producing incorrect
results. Use div64_u64() to perform a proper 64-by-64 division.

Fixes: 955ac624058f ("ASoC: fsl_easrc: Add EASRC ASoC CPU DAI drivers")
Cc: stable@vger.kernel.org
Signed-off-by: wangdicheng <wangdicheng@kylinos.cn>
Link: https://patch.msgid.link/20260717091542.721877-4-wangdich9700@163.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/fsl/fsl_easrc.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/sound/soc/fsl/fsl_easrc.c
+++ b/sound/soc/fsl/fsl_easrc.c
@@ -2058,7 +2058,7 @@ static int fsl_easrc_m2m_calc_out_len(st
 		/* right shift 12 bit to make ratio in 32bit space */
 		val2 = (u64)in_samples << (frac_bits - 12);
 		val1 = val1 >> 12;
-		do_div(val2, val1);
+		val2 = div64_u64(val2, val1);
 		out_samples = val2;
 
 		out_length = out_samples * out_width * channels;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 226/556] ASoC: fsl_easrc: sort the register default table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (224 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 225/556] ASoC: fsl_easrc: Use div64_u64 for 64-by-64 division Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 227/556] ASoC: hdac_hda: Fix hlink refcount leak on component registration failure Greg Kroah-Hartman
                   ` (342 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit 84c5d79aebe6c45e12e3112d14e68972f33c210a upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

The four REG_EASRC_RRL() entries are listed as a block before the four
REG_EASRC_RRH() ones, but the two registers of a context alternate in
the address map (RRL(n) at 0x110 + 8 * n, RRH(n) at 0x114 + 8 * n).
This leaves REG_EASRC_RRL(1), REG_EASRC_RRL(2) and REG_EASRC_RRL(3)
unreachable.  regcache_reg_needs_sync() then cannot compare them against
their default and reports that a sync is needed, so they are written to
the device on every regcache_sync() even when they were never touched.

Sort the table by register address.

Fixes: 955ac624058f ("ASoC: fsl_easrc: Add EASRC ASoC CPU DAI drivers")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805122728.12362-3-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/fsl/fsl_easrc.c |    6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

--- a/sound/soc/fsl/fsl_easrc.c
+++ b/sound/soc/fsl/fsl_easrc.c
@@ -1711,12 +1711,12 @@ static const struct reg_default fsl_easr
 	{REG_EASRC_SFS(2),	0x00000000},
 	{REG_EASRC_SFS(3),	0x00000000},
 	{REG_EASRC_RRL(0),	0x00000000},
-	{REG_EASRC_RRL(1),	0x00000000},
-	{REG_EASRC_RRL(2),	0x00000000},
-	{REG_EASRC_RRL(3),	0x00000000},
 	{REG_EASRC_RRH(0),	0x00000000},
+	{REG_EASRC_RRL(1),	0x00000000},
 	{REG_EASRC_RRH(1),	0x00000000},
+	{REG_EASRC_RRL(2),	0x00000000},
 	{REG_EASRC_RRH(2),	0x00000000},
+	{REG_EASRC_RRL(3),	0x00000000},
 	{REG_EASRC_RRH(3),	0x00000000},
 	{REG_EASRC_RUC(0),	0x00000000},
 	{REG_EASRC_RUC(1),	0x00000000},



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 227/556] ASoC: hdac_hda: Fix hlink refcount leak on component registration failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (225 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 226/556] ASoC: fsl_easrc: sort the register default table Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 228/556] AsoC: intel: sst: fix PCI device reference leak on probe failure Greg Kroah-Hartman
                   ` (341 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Haoxiang Li, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Haoxiang Li <haoxiang_li2024@163.com>

commit 6ad4892c4f5cb437a928a02f5b7d37d496aa9268 upstream.

hdac_hda_dev_probe() gets the HDA link with snd_hdac_ext_bus_link_get()
before registering the ASoC component. If component registration fails,
the function returns without dropping the link reference.

Always call snd_hdac_ext_bus_link_put() after the registration attempt so
the reference taken during probe is balanced on both success and failure.

Fixes: 6bae5ea94989 ("ASoC: hdac_hda: add asoc extension for legacy HDA codec drivers")
Cc: stable@vger.kernel.org
Signed-off-by: Haoxiang Li <haoxiang_li2024@163.com>
Link: https://patch.msgid.link/20260622145645.1184986-1-haoxiang_li2024@163.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/hdac_hda.c |    4 +---
 1 file changed, 1 insertion(+), 3 deletions(-)

--- a/sound/soc/codecs/hdac_hda.c
+++ b/sound/soc/codecs/hdac_hda.c
@@ -642,10 +642,8 @@ static int hdac_hda_dev_probe(struct hda
 						&hdac_hda_codec, hdac_hda_dais,
 						ARRAY_SIZE(hdac_hda_dais));
 
-	if (ret < 0) {
+	if (ret < 0)
 		dev_err(&hdev->dev, "%s: failed to register HDA codec %d\n", __func__, ret);
-		return ret;
-	}
 
 	snd_hdac_ext_bus_link_put(hdev->bus, hlink);
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 228/556] AsoC: intel: sst: fix PCI device reference leak on probe failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (226 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 227/556] ASoC: hdac_hda: Fix hlink refcount leak on component registration failure Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 229/556] ASoC: loongson: Fix error handling in ACPI property parsing Greg Kroah-Hartman
                   ` (340 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Haoxiang Li, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Haoxiang Li <haoxiang_li2024@163.com>

commit 016f29997ebd29d6ab59c8162ce0e7f73bd1e517 upstream.

intel_sst_probe() takes a reference to the PCI device with pci_dev_get().
If sst_platform_get_resources() fails afterwards, the probe error path
cleans up the driver context but does not drop the PCI device reference.

Add a pci_dev_put() error path for failures after pci_dev_get().

Fixes: f533a035e4da ("ASoC: Intel: mrfld - create separate module for pci part")
Cc: stable@vger.kernel.org
Signed-off-by: Haoxiang Li <haoxiang_li2024@163.com>
Link: https://patch.msgid.link/20260622091620.897478-1-haoxiang_li2024@163.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/intel/atom/sst/sst_pci.c |    4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

--- a/sound/soc/intel/atom/sst/sst_pci.c
+++ b/sound/soc/intel/atom/sst/sst_pci.c
@@ -130,13 +130,15 @@ static int intel_sst_probe(struct pci_de
 	sst_drv_ctx->pci = pci_dev_get(pci);
 	ret = sst_platform_get_resources(sst_drv_ctx);
 	if (ret < 0)
-		goto do_free_drv_ctx;
+		goto do_put_pci;
 
 	pci_set_drvdata(pci, sst_drv_ctx);
 	sst_configure_runtime_pm(sst_drv_ctx);
 
 	return ret;
 
+do_put_pci:
+	pci_dev_put(sst_drv_ctx->pci);
 do_free_drv_ctx:
 	sst_context_cleanup(sst_drv_ctx);
 	dev_err(sst_drv_ctx->dev, "Probe failed with %d\n", ret);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 229/556] ASoC: loongson: Fix error handling in ACPI property parsing
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (227 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 228/556] AsoC: intel: sst: fix PCI device reference leak on probe failure Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 230/556] ASoC: max9860: sort the register default table Greg Kroah-Hartman
                   ` (339 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Binbin Zhou, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Binbin Zhou <zhoubinbin@loongson.cn>

commit 0eb0e3c623ac1da8b85d518043fef7660af7805d upstream.

In loongson_card_parse_acpi(), the return value of
device_property_read_string() for the `codec-dai-name` property was
ignored. If the property is missing or invalid, an uninitialized pointer
would be used later, potentially leading to undefined behavior.

Fix this by checking the return value and propagating the error
appropriately.

Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/cover.1780538113.git.zhoubinbin@loongson.cn?part=5
Fixes: ddb538a3004b ("ASoC: loongson: Factor out loongson_card_acpi_find_device() function")
Signed-off-by: Binbin Zhou <zhoubinbin@loongson.cn>
Link: https://patch.msgid.link/08e44a54708eae053be148524346bb8dfcd55b03.1782439646.git.zhoubinbin@loongson.cn
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/loongson/loongson_card.c |    6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

--- a/sound/soc/loongson/loongson_card.c
+++ b/sound/soc/loongson/loongson_card.c
@@ -91,7 +91,7 @@ static int loongson_card_parse_acpi(stru
 	const char *codec_dai_name;
 	struct acpi_device *adev;
 	struct device *phy_dev;
-	int i;
+	int i, ret;
 
 	/* fixup platform name based on reference node */
 	adev = loongson_card_acpi_find_device(card, "cpu");
@@ -108,7 +108,9 @@ static int loongson_card_parse_acpi(stru
 		return -ENOENT;
 	snprintf(codec_name, sizeof(codec_name), "i2c-%s", acpi_dev_name(adev));
 
-	device_property_read_string(card->dev, "codec-dai-name", &codec_dai_name);
+	ret = device_property_read_string(card->dev, "codec-dai-name", &codec_dai_name);
+	if (ret)
+		return ret;
 
 	for (i = 0; i < card->num_links; i++) {
 		loongson_dai_links[i].platforms->name = dev_name(phy_dev);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 230/556] ASoC: max9860: sort the register default table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (228 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 229/556] ASoC: loongson: Fix error handling in ACPI property parsing Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 231/556] ASoC: ml26124: " Greg Kroah-Hartman
                   ` (338 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit 5c4cf173b7eba9bd1e8824b75380412cae2e026b upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

MAX9860_PWRMAN (0x10) is listed as the first entry, before
MAX9860_INTEN (0x02), which makes MAX9860_INTEN unreachable.
regcache_reg_needs_sync() then cannot compare it against its default and
reports that a sync is needed, so it is written to the device on every
regcache_sync() even when it was never touched.

Sort the table by register address.

Fixes: 3b2af7f79968 ("ASoC: max9860: new driver")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805122811.13713-4-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/max9860.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/sound/soc/codecs/max9860.c
+++ b/sound/soc/codecs/max9860.c
@@ -48,7 +48,6 @@ static int max9860_dvddio_event(struct n
 }
 
 static const struct reg_default max9860_reg_defaults[] = {
-	{ MAX9860_PWRMAN,       0x00 },
 	{ MAX9860_INTEN,        0x00 },
 	{ MAX9860_SYSCLK,       0x00 },
 	{ MAX9860_AUDIOCLKHIGH, 0x00 },
@@ -62,6 +61,7 @@ static const struct reg_default max9860_
 	{ MAX9860_MICGAIN,      0x00 },
 	{ MAX9860_MICADC,       0x00 },
 	{ MAX9860_NOISEGATE,    0x00 },
+	{ MAX9860_PWRMAN,       0x00 },
 };
 
 static bool max9860_readable(struct device *dev, unsigned int reg)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 231/556] ASoC: ml26124: sort the register default table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (229 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 230/556] ASoC: max9860: sort the register default table Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 232/556] ASoC: pcm512x: " Greg Kroah-Hartman
                   ` (337 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit d4d0e6e2355a6fe6517e5a0c3d9a0b8ab073b0b6 upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

The Mic Select Control register (0xe8) is listed in the analog path
control group, between 0x5a and 0x60, which makes it unreachable.
regcache_reg_needs_sync() then cannot compare it against its default and
reports that a sync is needed, so it is written to the device on every
regcache_sync() even when it was never touched.

Move the entry to the end of the table, where it belongs by address.

Fixes: d808fe9f3e7f ("ASoC: Add LAPIS Semiconductor ML26124 driver")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805122811.13713-2-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/ml26124.c |    4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

--- a/sound/soc/codecs/ml26124.c
+++ b/sound/soc/codecs/ml26124.c
@@ -224,7 +224,6 @@ static const struct reg_default ml26124_
 	/* Analog Path Control Register */
 	{0x54, 0x00},	/* Speaker AMP Output Control */
 	{0x5a, 0x00},	/* Mic IF Control */
-	{0xe8, 0x01},	/* Mic Select Control */
 
 	/* Audio Interface Control Register */
 	{0x60, 0x00},	/* SAI-Trans Control */
@@ -287,6 +286,9 @@ static const struct reg_default ml26124_
 	{0xd0, 0x01},	/* VIDEO AMP Gain Control */
 	{0xd2, 0x01},	/* VIDEO AMP Setup 1 */
 	{0xd4, 0x01},	/* VIDEO AMP Control2 */
+
+	/* Analog Path Control Register */
+	{0xe8, 0x01},	/* Mic Select Control */
 };
 
 /* Get sampling rate value of sampling rate setting register (0x0) */



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 232/556] ASoC: pcm512x: sort the register default table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (230 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 231/556] ASoC: ml26124: " Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 233/556] ASoC: pm4125-sdw: " Greg Kroah-Hartman
                   ` (336 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit 767d9ae714e3e9b0ae86237c410fbfca7056570a upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

PCM512x_AUTO_MUTE (page 0, register 59) is listed before
PCM512x_ERROR_DETECT (page 0, register 37) and PCM512x_VCOM_CTRL_2
(page 1, register 9) is listed before the page 0 clocking block, so the
bsearch() descends into the wrong half of the table.  24 of the 45
entries are unreachable, among them every PLL coefficient and clock
divider default.  regcache_reg_needs_sync() then cannot compare them
against their default and reports that a sync is needed, so they are
written to the device on every regcache_sync() even when they were
never touched.

Sort the table by register address.

Fixes: 5a3af1293194 ("ASoC: pcm512x: Add PCM512x driver")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805104149.9795-2-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/pcm512x.c |   40 ++++++++++++++++++++--------------------
 1 file changed, 20 insertions(+), 20 deletions(-)

--- a/sound/soc/codecs/pcm512x.c
+++ b/sound/soc/codecs/pcm512x.c
@@ -78,28 +78,10 @@ static const struct reg_default pcm512x_
 	{ PCM512x_POWER,             0x00 },
 	{ PCM512x_MUTE,              0x00 },
 	{ PCM512x_DSP,               0x00 },
-	{ PCM512x_PLL_REF,           0x00 },
-	{ PCM512x_DAC_REF,           0x00 },
-	{ PCM512x_DAC_ROUTING,       0x11 },
-	{ PCM512x_DSP_PROGRAM,       0x01 },
-	{ PCM512x_CLKDET,            0x00 },
-	{ PCM512x_AUTO_MUTE,         0x00 },
-	{ PCM512x_ERROR_DETECT,      0x00 },
-	{ PCM512x_DIGITAL_VOLUME_1,  0x00 },
-	{ PCM512x_DIGITAL_VOLUME_2,  0x30 },
-	{ PCM512x_DIGITAL_VOLUME_3,  0x30 },
-	{ PCM512x_DIGITAL_MUTE_1,    0x22 },
-	{ PCM512x_DIGITAL_MUTE_2,    0x00 },
-	{ PCM512x_DIGITAL_MUTE_3,    0x07 },
-	{ PCM512x_OUTPUT_AMPLITUDE,  0x00 },
-	{ PCM512x_ANALOG_GAIN_CTRL,  0x00 },
-	{ PCM512x_UNDERVOLTAGE_PROT, 0x00 },
-	{ PCM512x_ANALOG_MUTE_CTRL,  0x00 },
-	{ PCM512x_ANALOG_GAIN_BOOST, 0x00 },
-	{ PCM512x_VCOM_CTRL_1,       0x00 },
-	{ PCM512x_VCOM_CTRL_2,       0x01 },
 	{ PCM512x_BCLK_LRCLK_CFG,    0x00 },
 	{ PCM512x_MASTER_MODE,       0x7c },
+	{ PCM512x_PLL_REF,           0x00 },
+	{ PCM512x_DAC_REF,           0x00 },
 	{ PCM512x_GPIO_DACIN,        0x00 },
 	{ PCM512x_GPIO_PLLIN,        0x00 },
 	{ PCM512x_SYNCHRONIZE,       0x10 },
@@ -117,8 +99,26 @@ static const struct reg_default pcm512x_
 	{ PCM512x_FS_SPEED_MODE,     0x00 },
 	{ PCM512x_IDAC_1,            0x01 },
 	{ PCM512x_IDAC_2,            0x00 },
+	{ PCM512x_ERROR_DETECT,      0x00 },
 	{ PCM512x_I2S_1,             0x02 },
 	{ PCM512x_I2S_2,             0x00 },
+	{ PCM512x_DAC_ROUTING,       0x11 },
+	{ PCM512x_DSP_PROGRAM,       0x01 },
+	{ PCM512x_CLKDET,            0x00 },
+	{ PCM512x_AUTO_MUTE,         0x00 },
+	{ PCM512x_DIGITAL_VOLUME_1,  0x00 },
+	{ PCM512x_DIGITAL_VOLUME_2,  0x30 },
+	{ PCM512x_DIGITAL_VOLUME_3,  0x30 },
+	{ PCM512x_DIGITAL_MUTE_1,    0x22 },
+	{ PCM512x_DIGITAL_MUTE_2,    0x00 },
+	{ PCM512x_DIGITAL_MUTE_3,    0x07 },
+	{ PCM512x_OUTPUT_AMPLITUDE,  0x00 },
+	{ PCM512x_ANALOG_GAIN_CTRL,  0x00 },
+	{ PCM512x_UNDERVOLTAGE_PROT, 0x00 },
+	{ PCM512x_ANALOG_MUTE_CTRL,  0x00 },
+	{ PCM512x_ANALOG_GAIN_BOOST, 0x00 },
+	{ PCM512x_VCOM_CTRL_1,       0x00 },
+	{ PCM512x_VCOM_CTRL_2,       0x01 },
 };
 
 static bool pcm512x_readable(struct device *dev, unsigned int reg)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 233/556] ASoC: pm4125-sdw: sort the register default table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (231 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 232/556] ASoC: pcm512x: " Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 234/556] ASoC: rt1017-sdca-sdw: " Greg Kroah-Hartman
                   ` (335 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit 8dd18d9956bfd74531bfd7088e59586e3e115789 upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

PM4125_SWR_HPHPA_HD2 (0x3090) is listed before
PM4125_ANA_HPHPA_SPARE_CTL (0x308e), which makes the latter unreachable.
regcache_reg_needs_sync() then cannot compare it against its default and
reports that a sync is needed, so it is written to the device on every
regcache_sync() even when it was never touched.

Sort the table by register address.

Fixes: 8ad529484937 ("ASoC: codecs: add new pm4125 audio codec driver")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805113911.21723-1-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/pm4125-sdw.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/sound/soc/codecs/pm4125-sdw.c
+++ b/sound/soc/codecs/pm4125-sdw.c
@@ -126,8 +126,8 @@ static const struct reg_default pm4125_d
 	{ PM4125_ANA_HPHPA_FSM_CLK,              0x12 },
 	{ PM4125_ANA_HPHPA_L_GAIN,               0x00 },
 	{ PM4125_ANA_HPHPA_R_GAIN,               0x00 },
-	{ PM4125_SWR_HPHPA_HD2,                  0x1B },
 	{ PM4125_ANA_HPHPA_SPARE_CTL,            0x02 },
+	{ PM4125_SWR_HPHPA_HD2,                  0x1B },
 	{ PM4125_ANA_SURGE_EN,                   0x38 },
 	{ PM4125_ANA_COMBOPA_CTL,                0x35 },
 	{ PM4125_ANA_COMBOPA_CTL_4,              0x84 },



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 234/556] ASoC: rt1017-sdca-sdw: sort the register default table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (232 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 233/556] ASoC: pm4125-sdw: " Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 235/556] ASoC: rt1316-sdw: " Greg Kroah-Hartman
                   ` (334 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit 5b48ce0356b134155722a61f7196516a7c2e66c5 upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

rt1017_sdca_reg_defaults[] places the SDCA controls before the lower
vendor registers instead, so the binary search does not find 4 of its
entries.  regcache_reg_needs_sync() then cannot compare those against
their default and reports that a sync is needed, so they are written to
the device on every regcache_sync() even when they were never touched.

Sort the table by register address.

Fixes: 2b7aecd58528 ("ASoC: rt1017: Add RT1017 SDCA amplifier driver")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805090240.16991-15-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/rt1017-sdca-sdw.h |   10 +++++-----
 1 file changed, 5 insertions(+), 5 deletions(-)

--- a/sound/soc/codecs/rt1017-sdca-sdw.h
+++ b/sound/soc/codecs/rt1017-sdca-sdw.h
@@ -165,19 +165,19 @@ static const struct reg_default rt1017_s
 	{ 0xdb09, 0x0f },
 	{ 0xdb0a, 0xff },
 	{ 0xdb14, 0x00 },
-
-	{ SDW_SDCA_CTL(FUNC_NUM_SMART_AMP, RT1017_SDCA_ENT_UDMPU21,
-			RT1017_SDCA_CTL_UDMPU_CLUSTER, 0), 0x00 },
 	{ SDW_SDCA_CTL(FUNC_NUM_SMART_AMP, RT1017_SDCA_ENT_FU,
 			RT1017_SDCA_CTL_FU_MUTE, 0x01), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_SMART_AMP, RT1017_SDCA_ENT_XU22,
 			RT1017_SDCA_CTL_BYPASS, 0), 0x01 },
-	{ SDW_SDCA_CTL(FUNC_NUM_SMART_AMP, RT1017_SDCA_ENT_CS21,
-			RT1017_SDCA_CTL_FS_INDEX, 0), 0x09 },
 	{ SDW_SDCA_CTL(FUNC_NUM_SMART_AMP, RT1017_SDCA_ENT_PDE23,
 			RT1017_SDCA_CTL_REQ_POWER_STATE, 0), 0x03 },
 	{ SDW_SDCA_CTL(FUNC_NUM_SMART_AMP, RT1017_SDCA_ENT_PDE22,
 			RT1017_SDCA_CTL_REQ_POWER_STATE, 0), 0x03 },
+
+	{ SDW_SDCA_CTL(FUNC_NUM_SMART_AMP, RT1017_SDCA_ENT_UDMPU21,
+			RT1017_SDCA_CTL_UDMPU_CLUSTER, 0), 0x00 },
+	{ SDW_SDCA_CTL(FUNC_NUM_SMART_AMP, RT1017_SDCA_ENT_CS21,
+			RT1017_SDCA_CTL_FS_INDEX, 0), 0x09 },
 };
 
 #endif /* __RT1017_SDW_H__ */



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 235/556] ASoC: rt1316-sdw: sort the register default table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (233 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 234/556] ASoC: rt1017-sdca-sdw: " Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 236/556] ASoC: rt1318-sdw: " Greg Kroah-Hartman
                   ` (333 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit 7b48eccfbb9bf15e9b7377a5296bfd01815c62d8 upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

rt1316_reg_defaults[] is not in address order, so the binary search does
not find one of its entries.  regcache_reg_needs_sync() then cannot
compare it against its default and reports that a sync is needed, so it
is written to the device on every regcache_sync() even when it was never
touched.

Sort the table by register address.

Fixes: 2b719fd20f32 ("ASoC: rt1316: Add RT1316 SDCA vendor-specific driver")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805090240.16991-16-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/rt1316-sdw.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/sound/soc/codecs/rt1316-sdw.c
+++ b/sound/soc/codecs/rt1316-sdw.c
@@ -59,13 +59,13 @@ static const struct reg_default rt1316_r
 	{ 0xd101, 0x00 },
 	{ 0xd102, 0x30 },
 	{ 0xd103, 0x00 },
-	{ SDW_SDCA_CTL(FUNC_NUM_SMART_AMP, RT1316_SDCA_ENT_UDMPU21, RT1316_SDCA_CTL_UDMPU_CLUSTER, 0), 0x00 },
 	{ SDW_SDCA_CTL(FUNC_NUM_SMART_AMP, RT1316_SDCA_ENT_FU21, RT1316_SDCA_CTL_FU_MUTE, CH_L), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_SMART_AMP, RT1316_SDCA_ENT_FU21, RT1316_SDCA_CTL_FU_MUTE, CH_R), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_SMART_AMP, RT1316_SDCA_ENT_XU24, RT1316_SDCA_CTL_BYPASS, 0), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_SMART_AMP, RT1316_SDCA_ENT_PDE23, RT1316_SDCA_CTL_REQ_POWER_STATE, 0), 0x03 },
 	{ SDW_SDCA_CTL(FUNC_NUM_SMART_AMP, RT1316_SDCA_ENT_PDE22, RT1316_SDCA_CTL_REQ_POWER_STATE, 0), 0x03 },
 	{ SDW_SDCA_CTL(FUNC_NUM_SMART_AMP, RT1316_SDCA_ENT_PDE24, RT1316_SDCA_CTL_REQ_POWER_STATE, 0), 0x03 },
+	{ SDW_SDCA_CTL(FUNC_NUM_SMART_AMP, RT1316_SDCA_ENT_UDMPU21, RT1316_SDCA_CTL_UDMPU_CLUSTER, 0), 0x00 },
 };
 
 static const struct reg_sequence rt1316_blind_write[] = {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 236/556] ASoC: rt1318-sdw: sort the register default table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (234 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 235/556] ASoC: rt1316-sdw: " Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 237/556] ASoC: rt1318: " Greg Kroah-Hartman
                   ` (332 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit 3673b33633a5daf2f52aff03b57f7b25352fe234 upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

rt1318_reg_defaults[] is not in address order, so the binary search does
not find 3 of its entries.  regcache_reg_needs_sync() then cannot compare
those against their default and reports that a sync is needed, so they
are written to the device on every regcache_sync() even when they were
never touched.

Sort the table by register address.

Fixes: 6ad73a2b42ea ("ASoC: rt1318: Add RT1318 SDCA vendor-specific driver")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805090240.16991-18-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/rt1318-sdw.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/sound/soc/codecs/rt1318-sdw.c
+++ b/sound/soc/codecs/rt1318-sdw.c
@@ -235,10 +235,10 @@ static const struct reg_default rt1318_r
 	{ 0xf805, 0x00 },
 	{ 0xf806, 0x07 },
 	{ 0xf807, 0xff },
-	{ SDW_SDCA_CTL(FUNC_NUM_SMART_AMP, RT1318_SDCA_ENT_UDMPU21, RT1318_SDCA_CTL_UDMPU_CLUSTER, 0), 0x00 },
 	{ SDW_SDCA_CTL(FUNC_NUM_SMART_AMP, RT1318_SDCA_ENT_FU21, RT1318_SDCA_CTL_FU_MUTE, CH_L), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_SMART_AMP, RT1318_SDCA_ENT_FU21, RT1318_SDCA_CTL_FU_MUTE, CH_R), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_SMART_AMP, RT1318_SDCA_ENT_PDE23, RT1318_SDCA_CTL_REQ_POWER_STATE, 0), 0x03 },
+	{ SDW_SDCA_CTL(FUNC_NUM_SMART_AMP, RT1318_SDCA_ENT_UDMPU21, RT1318_SDCA_CTL_UDMPU_CLUSTER, 0), 0x00 },
 	{ SDW_SDCA_CTL(FUNC_NUM_SMART_AMP, RT1318_SDCA_ENT_CS21, RT1318_SDCA_CTL_SAMPLE_FREQ_INDEX, 0), 0x09 },
 };
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 237/556] ASoC: rt1318: sort the register default table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (235 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 236/556] ASoC: rt1318-sdw: " Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 238/556] ASoC: rt274: " Greg Kroah-Hartman
                   ` (331 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit 2a8e4b7114f6493314348bda7e3d2141d218ef61 upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

The 0xdd93 and 0xdd94 entries are listed after 0xddc8 in rt1318_reg[],
which leaves them unreachable for the binary search.
regcache_reg_needs_sync() then cannot compare them against their default
and reports that a sync is needed, so they are written to the device on
every regcache_sync() even when they were never touched.

Sort the table by register address.

Fixes: fe1ff61487ac ("ASoC: rt1318: Add RT1318 audio amplifier driver")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805090240.16991-17-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/rt1318.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/sound/soc/codecs/rt1318.c
+++ b/sound/soc/codecs/rt1318.c
@@ -337,6 +337,8 @@ static const struct reg_default rt1318_r
 	{ 0xdd08, 0x40 },
 	{ 0xdd12, 0x00 },
 	{ 0xdd35, 0x00 },
+	{ 0xdd93, 0x00 },
+	{ 0xdd94, 0x64 },
 	{ 0xddb5, 0x00 },
 	{ 0xddb6, 0x40 },
 	{ 0xddb7, 0x00 },
@@ -345,8 +347,6 @@ static const struct reg_default rt1318_r
 	{ 0xddc6, 0x00 },
 	{ 0xddc7, 0x00 },
 	{ 0xddc8, 0x00 },
-	{ 0xdd93, 0x00 },
-	{ 0xdd94, 0x64 },
 	{ 0xdf00, 0x00 },
 	{ 0xdf5f, 0x00 },
 	{ 0xdf60, 0x00 },



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 238/556] ASoC: rt274: sort the register default table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (236 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 237/556] ASoC: rt1318: " Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 239/556] ASoC: rt286: " Greg Kroah-Hartman
                   ` (330 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit 6a147d177819b0d831831d19fbb9c23f08a03734 upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

Four entries were appended to the end of rt274_reg[] instead of being
inserted at their sorted position, which leaves 7 of the 33 entries
unreachable for the binary search.  regcache_reg_needs_sync() then cannot
compare them against their default and reports that a sync is needed, so
they are written to the device on every regcache_sync() even when they were
never touched.

Sort the table by register address.

Fixes: c7e79b2b2d2d ("ASoC: rt274: add rt274 codec driver")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805090240.16991-2-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/rt274.c |    8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

--- a/sound/soc/codecs/rt274.c
+++ b/sound/soc/codecs/rt274.c
@@ -184,8 +184,10 @@ static const struct reg_default rt274_re
 	{ 0x0023a000, 0x00000057 },
 	{ 0x00270500, 0x00000400 },
 	{ 0x00370500, 0x00000400 },
+	{ 0x00830000, 0x00000097 },
 	{ 0x00870500, 0x00000400 },
 	{ 0x00920000, 0x00000031 },
+	{ 0x00930000, 0x00000097 },
 	{ 0x00935000, 0x00000097 },
 	{ 0x00936000, 0x00000097 },
 	{ 0x00970500, 0x00000400 },
@@ -195,10 +197,12 @@ static const struct reg_default rt274_re
 	{ 0x00c37000, 0x00000400 },
 	{ 0x00c37100, 0x00000400 },
 	{ 0x01270500, 0x00000400 },
+	{ 0x01270700, 0x00000000 },
 	{ 0x01370500, 0x00000400 },
 	{ 0x01371f00, 0x411111f0 },
 	{ 0x01937000, 0x00000000 },
 	{ 0x01970500, 0x00000400 },
+	{ 0x01970700, 0x00000020 },
 	{ 0x02050000, 0x0000001b },
 	{ 0x02139000, 0x00000080 },
 	{ 0x0213a000, 0x00000080 },
@@ -207,10 +211,6 @@ static const struct reg_default rt274_re
 	{ 0x02170700, 0x00000000 },
 	{ 0x02270100, 0x00000000 },
 	{ 0x02370100, 0x00000000 },
-	{ 0x01970700, 0x00000020 },
-	{ 0x00830000, 0x00000097 },
-	{ 0x00930000, 0x00000097 },
-	{ 0x01270700, 0x00000000 },
 };
 
 static bool rt274_volatile_register(struct device *dev, unsigned int reg)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 239/556] ASoC: rt286: sort the register default table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (237 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 238/556] ASoC: rt274: " Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 240/556] ASoC: rt298: " Greg Kroah-Hartman
                   ` (329 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit c30771968b5355617843a0ddfa0b9dcbcfd3ea84 upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

Four entries were appended to the end of rt286_reg[] instead of being
inserted at their sorted position and the 0x01470100 entry is listed after
0x01470c00, which leaves 7 of the 39 entries unreachable for the binary
search.  regcache_reg_needs_sync() then cannot compare them against their
default and reports that a sync is needed, so they are written to the
device on every regcache_sync() even when they were never touched.

Sort the table by register address.

Fixes: 07cf7cbadb4d ("ASoC: add RT286 CODEC driver")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805090240.16991-3-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/rt286.c |   12 ++++++------
 1 file changed, 6 insertions(+), 6 deletions(-)

--- a/sound/soc/codecs/rt286.c
+++ b/sound/soc/codecs/rt286.c
@@ -77,8 +77,10 @@ static const struct reg_default rt286_re
 	{ 0x0023a000, 0x0000007f },
 	{ 0x00270500, 0x00000400 },
 	{ 0x00370500, 0x00000400 },
+	{ 0x00830000, 0x000000c3 },
 	{ 0x00870500, 0x00000400 },
 	{ 0x00920000, 0x00000031 },
+	{ 0x00930000, 0x000000c3 },
 	{ 0x00935000, 0x000000c3 },
 	{ 0x00936000, 0x000000c3 },
 	{ 0x00970500, 0x00000400 },
@@ -88,16 +90,18 @@ static const struct reg_default rt286_re
 	{ 0x00c37000, 0x00000000 },
 	{ 0x00c37100, 0x00000080 },
 	{ 0x01270500, 0x00000400 },
+	{ 0x01270700, 0x00000000 },
 	{ 0x01370500, 0x00000400 },
 	{ 0x01371f00, 0x411111f0 },
 	{ 0x01439000, 0x00000080 },
 	{ 0x0143a000, 0x00000080 },
-	{ 0x01470700, 0x00000000 },
+	{ 0x01470100, 0x00000000 },
 	{ 0x01470500, 0x00000400 },
+	{ 0x01470700, 0x00000000 },
 	{ 0x01470c00, 0x00000000 },
-	{ 0x01470100, 0x00000000 },
 	{ 0x01837000, 0x00000000 },
 	{ 0x01870500, 0x00000400 },
+	{ 0x01870700, 0x00000020 },
 	{ 0x02050000, 0x00000000 },
 	{ 0x02139000, 0x00000080 },
 	{ 0x0213a000, 0x00000080 },
@@ -106,10 +110,6 @@ static const struct reg_default rt286_re
 	{ 0x02170700, 0x00000000 },
 	{ 0x02270100, 0x00000000 },
 	{ 0x02370100, 0x00000000 },
-	{ 0x01870700, 0x00000020 },
-	{ 0x00830000, 0x000000c3 },
-	{ 0x00930000, 0x000000c3 },
-	{ 0x01270700, 0x00000000 },
 };
 
 static bool rt286_volatile_register(struct device *dev, unsigned int reg)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 240/556] ASoC: rt298: sort the register default table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (238 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 239/556] ASoC: rt286: " Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 241/556] ASoC: rt700: drop duplicate reg_default entry Greg Kroah-Hartman
                   ` (328 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit aa4c472b0f4a469c2e4599406fa4cff9de3e02bd upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

Four entries were appended to the end of rt298_reg[] instead of being
inserted at their sorted position and the 0x01470100 entry is listed after
0x01470c00, which leaves 7 of the 39 entries unreachable for the binary
search.  regcache_reg_needs_sync() then cannot compare them against their
default and reports that a sync is needed, so they are written to the
device on every regcache_sync() even when they were never touched.

Sort the table by register address.

Fixes: 6adcafae6ed2 ("ASoC: add rt298 codec driver")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805090240.16991-4-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/rt298.c |   12 ++++++------
 1 file changed, 6 insertions(+), 6 deletions(-)

--- a/sound/soc/codecs/rt298.c
+++ b/sound/soc/codecs/rt298.c
@@ -78,8 +78,10 @@ static const struct reg_default rt298_re
 	{ 0x0023a000, 0x0000007f },
 	{ 0x00270500, 0x00000400 },
 	{ 0x00370500, 0x00000400 },
+	{ 0x00830000, 0x000000c3 },
 	{ 0x00870500, 0x00000400 },
 	{ 0x00920000, 0x00000031 },
+	{ 0x00930000, 0x000000c3 },
 	{ 0x00935000, 0x000000c3 },
 	{ 0x00936000, 0x000000c3 },
 	{ 0x00970500, 0x00000400 },
@@ -89,16 +91,18 @@ static const struct reg_default rt298_re
 	{ 0x00c37000, 0x00000000 },
 	{ 0x00c37100, 0x00000080 },
 	{ 0x01270500, 0x00000400 },
+	{ 0x01270700, 0x00000000 },
 	{ 0x01370500, 0x00000400 },
 	{ 0x01371f00, 0x411111f0 },
 	{ 0x01439000, 0x00000080 },
 	{ 0x0143a000, 0x00000080 },
-	{ 0x01470700, 0x00000000 },
+	{ 0x01470100, 0x00000000 },
 	{ 0x01470500, 0x00000400 },
+	{ 0x01470700, 0x00000000 },
 	{ 0x01470c00, 0x00000000 },
-	{ 0x01470100, 0x00000000 },
 	{ 0x01837000, 0x00000000 },
 	{ 0x01870500, 0x00000400 },
+	{ 0x01870700, 0x00000020 },
 	{ 0x02050000, 0x00000000 },
 	{ 0x02139000, 0x00000080 },
 	{ 0x0213a000, 0x00000080 },
@@ -107,10 +111,6 @@ static const struct reg_default rt298_re
 	{ 0x02170700, 0x00000000 },
 	{ 0x02270100, 0x00000000 },
 	{ 0x02370100, 0x00000000 },
-	{ 0x01870700, 0x00000020 },
-	{ 0x00830000, 0x000000c3 },
-	{ 0x00930000, 0x000000c3 },
-	{ 0x01270700, 0x00000000 },
 };
 
 static bool rt298_volatile_register(struct device *dev, unsigned int reg)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 241/556] ASoC: rt700: drop duplicate reg_default entry
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (239 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 240/556] ASoC: rt298: " Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 242/556] ASoC: rt700: sort the register default table Greg Kroah-Hartman
                   ` (327 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit 90ad6a29809dc53e8c1af23fc51bafe2133da035 upstream.

rt700_reg_defaults[] lists register 0x7303 twice with the same value.  The
identical rt711 table has the entry only once, so this is a copy-paste
error.

Drop the duplicate.  No functional change, regcache_lookup_reg() only ever
finds one of the two entries.

Fixes: 7d2a5f9ae41e ("ASoC: rt700: add rt700 codec driver")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805090240.16991-5-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/rt700-sdw.h |    1 -
 1 file changed, 1 deletion(-)

--- a/sound/soc/codecs/rt700-sdw.h
+++ b/sound/soc/codecs/rt700-sdw.h
@@ -313,7 +313,6 @@ static const struct reg_default rt700_re
 	{ 0x3122, 0x0000 },
 	{ 0x3123, 0x0000 },
 	{ 0x7303, 0x0057 },
-	{ 0x7303, 0x0057 },
 	{ 0x8383, 0x0057 },
 	{ 0x7308, 0x0097 },
 	{ 0x8388, 0x0097 },



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 242/556] ASoC: rt700: sort the register default table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (240 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 241/556] ASoC: rt700: drop duplicate reg_default entry Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 243/556] ASoC: rt711-sdca: sort the register default tables Greg Kroah-Hartman
                   ` (326 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit 18f21e34493b812d9c8ab9f083871470b016bed4 upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

At the end of rt700_reg_defaults[] the 0x83xx entries are interleaved with
the 0x73xx entries they belong to, which leaves 6 of the entries
unreachable for the binary search.  regcache_reg_needs_sync() then cannot
compare them against their default and reports that a sync is needed, so
they are written to the device on every regcache_sync() even when they were
never touched.

Sort the table by register address.

Fixes: 7d2a5f9ae41e ("ASoC: rt700: add rt700 codec driver")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805090240.16991-6-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/rt700-sdw.h |   10 +++++-----
 1 file changed, 5 insertions(+), 5 deletions(-)

--- a/sound/soc/codecs/rt700-sdw.h
+++ b/sound/soc/codecs/rt700-sdw.h
@@ -313,16 +313,16 @@ static const struct reg_default rt700_re
 	{ 0x3122, 0x0000 },
 	{ 0x3123, 0x0000 },
 	{ 0x7303, 0x0057 },
-	{ 0x8383, 0x0057 },
 	{ 0x7308, 0x0097 },
-	{ 0x8388, 0x0097 },
 	{ 0x7309, 0x0097 },
-	{ 0x8389, 0x0097 },
 	{ 0x7312, 0x0000 },
-	{ 0x8392, 0x0000 },
 	{ 0x7313, 0x0000 },
-	{ 0x8393, 0x0000 },
 	{ 0x7319, 0x0000 },
+	{ 0x8383, 0x0057 },
+	{ 0x8388, 0x0097 },
+	{ 0x8389, 0x0097 },
+	{ 0x8392, 0x0000 },
+	{ 0x8393, 0x0000 },
 	{ 0x8399, 0x0000 },
 	{ 0x75201a, 0x8003 },
 	{ 0x752045, 0x5289 },



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 243/556] ASoC: rt711-sdca: sort the register default tables
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (241 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 242/556] ASoC: rt700: sort the register default table Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 244/556] ASoC: rt711: sort the register default table Greg Kroah-Hartman
                   ` (325 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit b8fdd467bb5d2eb89b665331065e9e3ade964a3e upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

Both tables group the entries by SDCA entity instead: in
rt711_sdca_reg_defaults[] the CS01 sample frequency index is listed before
the FU05 controls (1 of 54 entries unreachable), and in
rt711_sdca_mbq_defaults[] the MIC_ARRAY FU1E volumes are listed before the
JACK_CODEC FU0F volumes (2 of 25 entries unreachable).
regcache_reg_needs_sync() then cannot compare those against their default
and reports that a sync is needed, so they are written to the device on
every regcache_sync() even when they were never touched.

Sort both tables by register address.

Fixes: 7ad4d237e7c4 ("ASoC: rt711-sdca: Add RT711 SDCA vendor-specific driver")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805090240.16991-8-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/rt711-sdca-sdw.h |    6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

--- a/sound/soc/codecs/rt711-sdca-sdw.h
+++ b/sound/soc/codecs/rt711-sdca-sdw.h
@@ -58,12 +58,12 @@ static const struct reg_default rt711_sd
 	{ 0x2f0f, 0x00 },
 	{ 0x2f50, 0x03 },
 	{ 0x2f5a, 0x00 },
-	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT711_SDCA_ENT_CS01, RT711_SDCA_CTL_SAMPLE_FREQ_INDEX, 0), 0x09 },
 	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT711_SDCA_ENT_USER_FU05, RT711_SDCA_CTL_FU_MUTE, CH_L), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT711_SDCA_ENT_USER_FU05, RT711_SDCA_CTL_FU_MUTE, CH_R), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT711_SDCA_ENT_USER_FU0F, RT711_SDCA_CTL_FU_MUTE, CH_L), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT711_SDCA_ENT_USER_FU0F, RT711_SDCA_CTL_FU_MUTE, CH_R), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT711_SDCA_ENT_PDE28, RT711_SDCA_CTL_REQ_POWER_STATE, 0), 0x03 },
+	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT711_SDCA_ENT_CS01, RT711_SDCA_CTL_SAMPLE_FREQ_INDEX, 0), 0x09 },
 	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT711_SDCA_ENT_USER_FU1E, RT711_SDCA_CTL_FU_MUTE, CH_L), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT711_SDCA_ENT_USER_FU1E, RT711_SDCA_CTL_FU_MUTE, CH_R), 0x01 },
 };
@@ -86,14 +86,14 @@ static const struct reg_default rt711_sd
 	{ 0x610003f, 0xff12 },
 	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT711_SDCA_ENT_USER_FU05, RT711_SDCA_CTL_FU_VOLUME, CH_L), 0x00 },
 	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT711_SDCA_ENT_USER_FU05, RT711_SDCA_CTL_FU_VOLUME, CH_R), 0x00 },
-	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT711_SDCA_ENT_USER_FU1E, RT711_SDCA_CTL_FU_VOLUME, CH_L), 0x00 },
-	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT711_SDCA_ENT_USER_FU1E, RT711_SDCA_CTL_FU_VOLUME, CH_R), 0x00 },
 	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT711_SDCA_ENT_USER_FU0F, RT711_SDCA_CTL_FU_VOLUME, CH_L), 0x00 },
 	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT711_SDCA_ENT_USER_FU0F, RT711_SDCA_CTL_FU_VOLUME, CH_R), 0x00 },
 	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT711_SDCA_ENT_PLATFORM_FU44, RT711_SDCA_CTL_FU_CH_GAIN, CH_L), 0x00 },
 	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT711_SDCA_ENT_PLATFORM_FU44, RT711_SDCA_CTL_FU_CH_GAIN, CH_R), 0x00 },
 	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT711_SDCA_ENT_PLATFORM_FU15, RT711_SDCA_CTL_FU_CH_GAIN, CH_L), 0x00 },
 	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT711_SDCA_ENT_PLATFORM_FU15, RT711_SDCA_CTL_FU_CH_GAIN, CH_R), 0x00 },
+	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT711_SDCA_ENT_USER_FU1E, RT711_SDCA_CTL_FU_VOLUME, CH_L), 0x00 },
+	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT711_SDCA_ENT_USER_FU1E, RT711_SDCA_CTL_FU_VOLUME, CH_R), 0x00 },
 };
 
 #endif /* __RT711_SDW_SDCA_H__ */



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 244/556] ASoC: rt711: sort the register default table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (242 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 243/556] ASoC: rt711-sdca: sort the register default tables Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 245/556] ASoC: rt712-sdca-dmic: " Greg Kroah-Hartman
                   ` (324 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit 55fe63530772fe95a99abe9497872975f3161a56 upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

At the end of rt711_reg_defaults[] the 0x83xx entries are interleaved with
the 0x73xx entries they belong to, which leaves 5 of the 269 entries
unreachable for the binary search.  regcache_reg_needs_sync() then cannot
compare them against their default and reports that a sync is needed, so
they are written to the device on every regcache_sync() even when they were
never touched.

Sort the table by register address.

Fixes: 320b8b0d13b8 ("ASoC: rt711: add rt711 codec driver")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805090240.16991-7-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/rt711-sdw.h |   10 +++++-----
 1 file changed, 5 insertions(+), 5 deletions(-)

--- a/sound/soc/codecs/rt711-sdw.h
+++ b/sound/soc/codecs/rt711-sdw.h
@@ -256,16 +256,16 @@ static const struct reg_default rt711_re
 	{ 0x3122, 0x00 },
 	{ 0x3123, 0x00 },
 	{ 0x7303, 0x57 },
-	{ 0x8383, 0x57 },
 	{ 0x7308, 0x97 },
-	{ 0x8388, 0x97 },
 	{ 0x7309, 0x97 },
-	{ 0x8389, 0x97 },
 	{ 0x7312, 0x00 },
-	{ 0x8392, 0x00 },
 	{ 0x7313, 0x00 },
-	{ 0x8393, 0x00 },
 	{ 0x7319, 0x00 },
+	{ 0x8383, 0x57 },
+	{ 0x8388, 0x97 },
+	{ 0x8389, 0x97 },
+	{ 0x8392, 0x00 },
+	{ 0x8393, 0x00 },
 	{ 0x8399, 0x00 },
 	{ 0x752008, 0xa807 },
 	{ 0x752009, 0x1029 },



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 245/556] ASoC: rt712-sdca-dmic: sort the register default table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (243 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 244/556] ASoC: rt711: sort the register default table Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 246/556] ASoC: rt712-sdca-sdw: " Greg Kroah-Hartman
                   ` (323 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit b9339ee3fccc79e751a2f7bde42c5dd57b38b2a9 upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

rt712_sdca_dmic_reg_defaults[] is grouped by SDCA entity instead, so the
binary search does not find 3 of its entries.  regcache_reg_needs_sync()
then cannot compare those against their default and reports that a sync
is needed, so they are written to the device on every regcache_sync()
even when they were never touched.

Sort the table by register address.

Fixes: 63a511284c9e ("ASoC: rt712-sdca: Add RT712 SDCA driver for Mic topology")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805090240.16991-9-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/rt712-sdca-dmic.h |    6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

--- a/sound/soc/codecs/rt712-sdca-dmic.h
+++ b/sound/soc/codecs/rt712-sdca-dmic.h
@@ -36,6 +36,7 @@ struct rt712_sdca_dmic_kctrl_priv {
 #define CH_03	0x03
 #define CH_04	0x04
 
+/* must stay sorted by register address, regcache_lookup_reg() does a bsearch() */
 static const struct reg_default rt712_sdca_dmic_reg_defaults[] = {
 	{ 0x201a, 0x00 },
 	{ 0x201b, 0x00 },
@@ -72,15 +73,16 @@ static const struct reg_default rt712_sd
 	{ 0x2f59, 0x07 },
 	{ 0x3201, 0x01 },
 	{ 0x320c, 0x00 },
-	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT712_SDCA_ENT_IT26, RT712_SDCA_CTL_VENDOR_DEF, 0), 0x00 },
 	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT712_SDCA_ENT_USER_FU1E, RT712_SDCA_CTL_FU_MUTE, CH_01), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT712_SDCA_ENT_USER_FU1E, RT712_SDCA_CTL_FU_MUTE, CH_02), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT712_SDCA_ENT_USER_FU1E, RT712_SDCA_CTL_FU_MUTE, CH_03), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT712_SDCA_ENT_USER_FU1E, RT712_SDCA_CTL_FU_MUTE, CH_04), 0x01 },
-	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT712_SDCA_ENT_CS1F, RT712_SDCA_CTL_SAMPLE_FREQ_INDEX, 0), 0x09 },
 	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT712_SDCA_ENT_CS1C, RT712_SDCA_CTL_SAMPLE_FREQ_INDEX, 0), 0x09 },
+	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT712_SDCA_ENT_CS1F, RT712_SDCA_CTL_SAMPLE_FREQ_INDEX, 0), 0x09 },
+	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT712_SDCA_ENT_IT26, RT712_SDCA_CTL_VENDOR_DEF, 0), 0x00 },
 };
 
+/* must stay sorted by register address, regcache_lookup_reg() does a bsearch() */
 static const struct reg_default rt712_sdca_dmic_mbq_defaults[] = {
 	{ 0x0590001e, 0x0020 },
 	{ 0x06100000, 0x0010 },



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 246/556] ASoC: rt712-sdca-sdw: sort the register default table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (244 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 245/556] ASoC: rt712-sdca-dmic: " Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 247/556] ASoC: rt715-sdca: drop duplicate reg_default entries Greg Kroah-Hartman
                   ` (322 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit efd430c4d0426e60fbec400c5a8ce62d886f6e21 upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

rt712_sdca_reg_defaults[] is grouped by SDCA function instead, so the
binary search does not find 4 of its entries.  regcache_reg_needs_sync()
then cannot compare those against their default and reports that a sync
is needed, so they are written to the device on every regcache_sync()
even when they were never touched.

One of them is the Mic Array Clock Source 0x1C Sample Frequency Index
control, which a part without that function rejects:

  soundwire_intel.link.0: Msg ignored for Slave 6, addr: 0x8e00

Sort the table by register address.

Fixes: 936abb09c1c7 ("ASoC: rt712-sdca: add the function for version B")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805090240.16991-10-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/rt712-sdca-sdw.h |   11 ++++++-----
 1 file changed, 6 insertions(+), 5 deletions(-)

--- a/sound/soc/codecs/rt712-sdca-sdw.h
+++ b/sound/soc/codecs/rt712-sdca-sdw.h
@@ -11,21 +11,21 @@
 #include <linux/regmap.h>
 #include <linux/soundwire/sdw_registers.h>
 
+/* must stay sorted by register address, regcache_lookup_reg() does a bsearch() */
 static const struct reg_default rt712_sdca_reg_defaults[] = {
-
-	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT712_SDCA_ENT_CS01, RT712_SDCA_CTL_SAMPLE_FREQ_INDEX, 0), 0x09 },
-	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT712_SDCA_ENT_CS11, RT712_SDCA_CTL_SAMPLE_FREQ_INDEX, 0), 0x09 },
 	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT712_SDCA_ENT_USER_FU05, RT712_SDCA_CTL_FU_MUTE, CH_01), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT712_SDCA_ENT_USER_FU05, RT712_SDCA_CTL_FU_MUTE, CH_02), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT712_SDCA_ENT_USER_FU0F, RT712_SDCA_CTL_FU_MUTE, CH_01), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT712_SDCA_ENT_USER_FU0F, RT712_SDCA_CTL_FU_MUTE, CH_02), 0x01 },
-	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT712_SDCA_ENT_PDE40, RT712_SDCA_CTL_REQ_POWER_STATE, 0), 0x03 },
 	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT712_SDCA_ENT_PDE12, RT712_SDCA_CTL_REQ_POWER_STATE, 0), 0x03 },
-	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT712_SDCA_ENT_CS1C, RT712_SDCA_CTL_SAMPLE_FREQ_INDEX, 0), 0x09 },
+	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT712_SDCA_ENT_CS01, RT712_SDCA_CTL_SAMPLE_FREQ_INDEX, 0), 0x09 },
+	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT712_SDCA_ENT_CS11, RT712_SDCA_CTL_SAMPLE_FREQ_INDEX, 0), 0x09 },
+	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT712_SDCA_ENT_PDE40, RT712_SDCA_CTL_REQ_POWER_STATE, 0), 0x03 },
 	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT712_SDCA_ENT_USER_FU1E, RT712_SDCA_CTL_FU_MUTE, CH_01), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT712_SDCA_ENT_USER_FU1E, RT712_SDCA_CTL_FU_MUTE, CH_02), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT712_SDCA_ENT_USER_FU1E, RT712_SDCA_CTL_FU_MUTE, CH_03), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT712_SDCA_ENT_USER_FU1E, RT712_SDCA_CTL_FU_MUTE, CH_04), 0x01 },
+	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT712_SDCA_ENT_CS1C, RT712_SDCA_CTL_SAMPLE_FREQ_INDEX, 0), 0x09 },
 	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT712_SDCA_ENT_CS1F, RT712_SDCA_CTL_SAMPLE_FREQ_INDEX, 0), 0x09 },
 	{ SDW_SDCA_CTL(FUNC_NUM_AMP, RT712_SDCA_ENT_USER_FU06, RT712_SDCA_CTL_FU_MUTE, CH_01), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_AMP, RT712_SDCA_ENT_USER_FU06, RT712_SDCA_CTL_FU_MUTE, CH_02), 0x01 },
@@ -34,6 +34,7 @@ static const struct reg_default rt712_sd
 	{ SDW_SDCA_CTL(FUNC_NUM_AMP, RT712_SDCA_ENT_OT23, RT712_SDCA_CTL_VENDOR_DEF, 0), 0x00 },
 };
 
+/* must stay sorted by register address, regcache_lookup_reg() does a bsearch() */
 static const struct reg_default rt712_sdca_mbq_defaults[] = {
 	{ 0x2000004, 0xaa01 },
 	{ 0x200000e, 0x21e0 },



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 247/556] ASoC: rt715-sdca: drop duplicate reg_default entries
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (245 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 246/556] ASoC: rt712-sdca-sdw: " Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 248/556] ASoC: rt715-sdca: sort the register default tables Greg Kroah-Hartman
                   ` (321 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit c9875bba469c19ad7f771b91b1e4c6f1c0f0a07d upstream.

The last two entries of rt715_reg_defaults_sdca[] repeat the ADC7_27 volume
mute controls for CH_01 and CH_02, which are already listed a few lines
above with the same value.

Drop the duplicates.  No functional change, regcache_lookup_reg() only ever
finds one of the two copies.

Fixes: 20d17057f0a8 ("ASoC: rt715-sdca: Add RT715 sdca vendor-specific driver")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805090240.16991-12-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/rt715-sdca-sdw.h |    4 ----
 1 file changed, 4 deletions(-)

--- a/sound/soc/codecs/rt715-sdca-sdw.h
+++ b/sound/soc/codecs/rt715-sdca-sdw.h
@@ -102,10 +102,6 @@ static const struct reg_default rt715_re
 		RT715_SDCA_SMPU_TRIG_EN_CTRL, CH_00), 0x02 },
 	{ SDW_SDCA_CTL(FUN_MIC_ARRAY, RT715_SDCA_SMPU_TRIG_ST_EN,
 		RT715_SDCA_SMPU_TRIG_ST_CTRL, CH_00), 0x00 },
-	{ SDW_SDCA_CTL(FUN_MIC_ARRAY, RT715_SDCA_FU_ADC7_27_VOL,
-		RT715_SDCA_FU_MUTE_CTRL, CH_01), 0x01 },
-	{ SDW_SDCA_CTL(FUN_MIC_ARRAY, RT715_SDCA_FU_ADC7_27_VOL,
-		RT715_SDCA_FU_MUTE_CTRL, CH_02), 0x01 },
 };
 
 static const struct reg_default rt715_mbq_reg_defaults_sdca[] = {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 248/556] ASoC: rt715-sdca: sort the register default tables
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (246 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 247/556] ASoC: rt715-sdca: drop duplicate reg_default entries Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 249/556] ASoC: rt715: sort the register default table Greg Kroah-Hartman
                   ` (320 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit 61a0321e4bc2ff9ecb38cda7d5a32ffacef71a75 upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

Both tables group the entries by SDCA entity instead: in
rt715_reg_defaults_sdca[] the CX_CLK_SEL control is listed before the
ADC8_9, ADC10_11 and ADC7_27 mute controls (7 of 78 entries unreachable),
and in rt715_mbq_reg_defaults_sdca[] the AMIC_GAIN_EN CH_08 entry is listed
before the DMIC_GAIN_EN entries (1 of 32 entries unreachable).
regcache_reg_needs_sync() then cannot compare those against their default
and reports that a sync is needed, so they are written to the device on
every regcache_sync() even when they were never touched.

Sort both tables by register address.

Fixes: 20d17057f0a8 ("ASoC: rt715-sdca: Add RT715 sdca vendor-specific driver")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805090240.16991-13-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/rt715-sdca-sdw.h |    8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

--- a/sound/soc/codecs/rt715-sdca-sdw.h
+++ b/sound/soc/codecs/rt715-sdca-sdw.h
@@ -76,8 +76,6 @@ static const struct reg_default rt715_re
 	{ 0x2f52, 0x01 },
 	{ 0x2f5a, 0x02 },
 	{ 0x2f5b, 0x05 },
-	{ SDW_SDCA_CTL(FUN_MIC_ARRAY, RT715_SDCA_CX_CLK_SEL_EN,
-		RT715_SDCA_CX_CLK_SEL_CTRL, CH_00), 0x1 },
 	{ SDW_SDCA_CTL(FUN_MIC_ARRAY, RT715_SDCA_FU_ADC8_9_VOL,
 		RT715_SDCA_FU_MUTE_CTRL, CH_01), 0x01 },
 	{ SDW_SDCA_CTL(FUN_MIC_ARRAY, RT715_SDCA_FU_ADC8_9_VOL,
@@ -98,6 +96,8 @@ static const struct reg_default rt715_re
 		RT715_SDCA_FU_MUTE_CTRL, CH_01), 0x01 },
 	{ SDW_SDCA_CTL(FUN_MIC_ARRAY, RT715_SDCA_FU_ADC7_27_VOL,
 		RT715_SDCA_FU_MUTE_CTRL, CH_02), 0x01 },
+	{ SDW_SDCA_CTL(FUN_MIC_ARRAY, RT715_SDCA_CX_CLK_SEL_EN,
+		RT715_SDCA_CX_CLK_SEL_CTRL, CH_00), 0x1 },
 	{ SDW_SDCA_CTL(FUN_MIC_ARRAY, RT715_SDCA_SMPU_TRIG_ST_EN,
 		RT715_SDCA_SMPU_TRIG_EN_CTRL, CH_00), 0x02 },
 	{ SDW_SDCA_CTL(FUN_MIC_ARRAY, RT715_SDCA_SMPU_TRIG_ST_EN,
@@ -145,8 +145,6 @@ static const struct reg_default rt715_mb
 		RT715_SDCA_FU_DMIC_GAIN_CTRL, CH_06), 0x00 },
 	{ SDW_SDCA_CTL(FUN_MIC_ARRAY, RT715_SDCA_FU_AMIC_GAIN_EN,
 		RT715_SDCA_FU_DMIC_GAIN_CTRL, CH_07), 0x00 },
-	{ SDW_SDCA_CTL(FUN_MIC_ARRAY, RT715_SDCA_FU_AMIC_GAIN_EN,
-		RT715_SDCA_FU_DMIC_GAIN_CTRL, CH_08), 0x00 },
 	{ SDW_SDCA_CTL(FUN_MIC_ARRAY, RT715_SDCA_FU_DMIC_GAIN_EN,
 		RT715_SDCA_FU_DMIC_GAIN_CTRL, CH_01), 0x00 },
 	{ SDW_SDCA_CTL(FUN_MIC_ARRAY, RT715_SDCA_FU_DMIC_GAIN_EN,
@@ -161,6 +159,8 @@ static const struct reg_default rt715_mb
 		RT715_SDCA_FU_DMIC_GAIN_CTRL, CH_06), 0x00 },
 	{ SDW_SDCA_CTL(FUN_MIC_ARRAY, RT715_SDCA_FU_DMIC_GAIN_EN,
 		RT715_SDCA_FU_DMIC_GAIN_CTRL, CH_07), 0x00 },
+	{ SDW_SDCA_CTL(FUN_MIC_ARRAY, RT715_SDCA_FU_AMIC_GAIN_EN,
+		RT715_SDCA_FU_DMIC_GAIN_CTRL, CH_08), 0x00 },
 	{ SDW_SDCA_CTL(FUN_MIC_ARRAY, RT715_SDCA_FU_DMIC_GAIN_EN,
 		RT715_SDCA_FU_DMIC_GAIN_CTRL, CH_08), 0x00 },
 };



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 249/556] ASoC: rt715: sort the register default table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (247 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 248/556] ASoC: rt715-sdca: sort the register default tables Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 250/556] ASoC: rt721-sdca-sdw: " Greg Kroah-Hartman
                   ` (319 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit d729804a92dc4e74b8fb69da162f74660ea64385 upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

At the end of rt715_reg_defaults[] the 0x82xx and 0x83xx entries are
interleaved with the 0x72xx and 0x73xx entries they belong to, and 0x385e
is listed before 0x3859.  This leaves 25 of the 323 entries unreachable for
the binary search.  regcache_reg_needs_sync() then cannot compare them
against their default and reports that a sync is needed, so they are
written to the device on every regcache_sync() even when they were never
touched.

Sort the table by register address.

Fixes: d1ede0641b05 ("ASoC: rt715: add RT715 codec driver")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805090240.16991-11-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/rt715-sdw.h |   32 ++++++++++++++++----------------
 1 file changed, 16 insertions(+), 16 deletions(-)

--- a/sound/soc/codecs/rt715-sdw.h
+++ b/sound/soc/codecs/rt715-sdw.h
@@ -281,8 +281,8 @@ static const struct reg_default rt715_re
 	{ 0x371b, 0x00 },
 	{ 0x371d, 0x00 },
 	{ 0x3729, 0x00 },
-	{ 0x385e, 0x00 },
 	{ 0x3859, 0x00 },
+	{ 0x385e, 0x00 },
 	{ 0x4c12, 0x411111f0 },
 	{ 0x4c13, 0x411111f0 },
 	{ 0x4c1d, 0x411111f0 },
@@ -300,36 +300,36 @@ static const struct reg_default rt715_re
 	{ 0x4f1d, 0x411111f0 },
 	{ 0x4f29, 0x411111f0 },
 	{ 0x7207, 0x00 },
-	{ 0x8287, 0x00 },
 	{ 0x7208, 0x00 },
-	{ 0x8288, 0x00 },
 	{ 0x7209, 0x00 },
-	{ 0x8289, 0x00 },
 	{ 0x7227, 0x00 },
-	{ 0x82a7, 0x00 },
 	{ 0x7307, 0x97 },
-	{ 0x8387, 0x97 },
 	{ 0x7308, 0x97 },
-	{ 0x8388, 0x97 },
 	{ 0x7309, 0x97 },
-	{ 0x8389, 0x97 },
 	{ 0x7312, 0x00 },
-	{ 0x8392, 0x00 },
 	{ 0x7313, 0x00 },
-	{ 0x8393, 0x00 },
 	{ 0x7318, 0x00 },
-	{ 0x8398, 0x00 },
 	{ 0x7319, 0x00 },
-	{ 0x8399, 0x00 },
 	{ 0x731a, 0x00 },
-	{ 0x839a, 0x00 },
 	{ 0x731b, 0x00 },
-	{ 0x839b, 0x00 },
 	{ 0x731d, 0x00 },
-	{ 0x839d, 0x00 },
 	{ 0x7327, 0x97 },
-	{ 0x83a7, 0x97 },
 	{ 0x7329, 0x00 },
+	{ 0x8287, 0x00 },
+	{ 0x8288, 0x00 },
+	{ 0x8289, 0x00 },
+	{ 0x82a7, 0x00 },
+	{ 0x8387, 0x97 },
+	{ 0x8388, 0x97 },
+	{ 0x8389, 0x97 },
+	{ 0x8392, 0x00 },
+	{ 0x8393, 0x00 },
+	{ 0x8398, 0x00 },
+	{ 0x8399, 0x00 },
+	{ 0x839a, 0x00 },
+	{ 0x839b, 0x00 },
+	{ 0x839d, 0x00 },
+	{ 0x83a7, 0x97 },
 	{ 0x83a9, 0x00 },
 	{ 0x752039, 0xa500 },
 };



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 250/556] ASoC: rt721-sdca-sdw: sort the register default table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (248 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 249/556] ASoC: rt715: sort the register default table Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 251/556] ASoC: samsung: aries_audio_probe: double of_node_put due to direct assignment without of_node_get Greg Kroah-Hartman
                   ` (318 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit 70e0481c196e4822e683bca384e6bda89d944839 upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

rt721_sdca_reg_defaults[] is grouped by SDCA function instead, so the
binary search does not find 12 of its entries.  regcache_reg_needs_sync()
then cannot compare those against their default and reports that a sync
is needed, so they are written to the device on every regcache_sync()
even when they were never touched.

Sort the table by register address.

Fixes: 86ce355c1f9a ("ASoC: rt721-sdca: Add RT721 SDCA driver")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805090240.16991-14-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/rt721-sdca-sdw.h |   28 ++++++++++++++--------------
 1 file changed, 14 insertions(+), 14 deletions(-)

--- a/sound/soc/codecs/rt721-sdca-sdw.h
+++ b/sound/soc/codecs/rt721-sdca-sdw.h
@@ -29,14 +29,6 @@ static const struct reg_default rt721_sd
 	{ 0x2f5b, 0x07 },
 	{ 0x2f5c, 0x27 },
 	{ 0x2f5d, 0x07 },
-	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT721_SDCA_ENT_CS01,
-		RT721_SDCA_CTL_SAMPLE_FREQ_INDEX, 0), 0x09 },
-	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT721_SDCA_ENT_CS11,
-		RT721_SDCA_CTL_SAMPLE_FREQ_INDEX, 0), 0x09 },
-	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT721_SDCA_ENT_PDE12,
-		RT721_SDCA_CTL_REQ_POWER_STATE, 0), 0x03 },
-	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT721_SDCA_ENT_PDE40,
-		RT721_SDCA_CTL_REQ_POWER_STATE, 0), 0x03 },
 	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT721_SDCA_ENT_USER_FU05,
 		RT721_SDCA_CTL_FU_MUTE, CH_L), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT721_SDCA_ENT_USER_FU05,
@@ -45,6 +37,14 @@ static const struct reg_default rt721_sd
 		RT721_SDCA_CTL_FU_MUTE, CH_L), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT721_SDCA_ENT_USER_FU0F,
 		RT721_SDCA_CTL_FU_MUTE, CH_R), 0x01 },
+	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT721_SDCA_ENT_PDE12,
+		RT721_SDCA_CTL_REQ_POWER_STATE, 0), 0x03 },
+	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT721_SDCA_ENT_CS01,
+		RT721_SDCA_CTL_SAMPLE_FREQ_INDEX, 0), 0x09 },
+	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT721_SDCA_ENT_CS11,
+		RT721_SDCA_CTL_SAMPLE_FREQ_INDEX, 0), 0x09 },
+	{ SDW_SDCA_CTL(FUNC_NUM_JACK_CODEC, RT721_SDCA_ENT_PDE40,
+		RT721_SDCA_CTL_REQ_POWER_STATE, 0), 0x03 },
 	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT721_SDCA_ENT_USER_FU1E,
 		RT721_SDCA_CTL_FU_MUTE, CH_01), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT721_SDCA_ENT_USER_FU1E,
@@ -53,30 +53,30 @@ static const struct reg_default rt721_sd
 		RT721_SDCA_CTL_FU_MUTE, CH_03), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT721_SDCA_ENT_USER_FU1E,
 		RT721_SDCA_CTL_FU_MUTE, CH_04), 0x01 },
+	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT721_SDCA_ENT_PDE2A,
+		RT721_SDCA_CTL_REQ_POWER_STATE, 0), 0x03 },
 	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT721_SDCA_ENT_CS1F,
 		RT721_SDCA_CTL_SAMPLE_FREQ_INDEX, 0), 0x09 },
 	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT721_SDCA_ENT_IT26,
 		RT721_SDCA_CTL_VENDOR_DEF, 0), 0x00 },
-	{ SDW_SDCA_CTL(FUNC_NUM_MIC_ARRAY, RT721_SDCA_ENT_PDE2A,
-		RT721_SDCA_CTL_REQ_POWER_STATE, 0), 0x03 },
-	{ SDW_SDCA_CTL(FUNC_NUM_AMP, RT721_SDCA_ENT_CS31,
-		RT721_SDCA_CTL_SAMPLE_FREQ_INDEX, 0), 0x09 },
 	{ SDW_SDCA_CTL(FUNC_NUM_AMP, RT721_SDCA_ENT_USER_FU06,
 		RT721_SDCA_CTL_FU_MUTE, CH_L), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_AMP, RT721_SDCA_ENT_USER_FU06,
 		RT721_SDCA_CTL_FU_MUTE, CH_R), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_AMP, RT721_SDCA_ENT_PDE23,
 		RT721_SDCA_CTL_REQ_POWER_STATE, 0), 0x03 },
-	{ SDW_SDCA_CTL(FUNC_NUM_AMP, RT721_SDCA_ENT_OT23,
-		RT721_SDCA_CTL_VENDOR_DEF, 0), 0x00 },
 	{ SDW_SDCA_CTL(FUNC_NUM_AMP, RT721_SDCA_ENT_PDE23,
 		RT721_SDCA_CTL_FU_MUTE, CH_01), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_AMP, RT721_SDCA_ENT_PDE23,
 		RT721_SDCA_CTL_FU_MUTE, CH_02), 0x01 },
+	{ SDW_SDCA_CTL(FUNC_NUM_AMP, RT721_SDCA_ENT_CS31,
+		RT721_SDCA_CTL_SAMPLE_FREQ_INDEX, 0), 0x09 },
 	{ SDW_SDCA_CTL(FUNC_NUM_AMP, RT721_SDCA_ENT_FU55,
 		RT721_SDCA_CTL_FU_MUTE, CH_01), 0x01 },
 	{ SDW_SDCA_CTL(FUNC_NUM_AMP, RT721_SDCA_ENT_FU55,
 		RT721_SDCA_CTL_FU_MUTE, CH_02), 0x01 },
+	{ SDW_SDCA_CTL(FUNC_NUM_AMP, RT721_SDCA_ENT_OT23,
+		RT721_SDCA_CTL_VENDOR_DEF, 0), 0x00 },
 };
 
 static const struct reg_default rt721_sdca_mbq_defaults[] = {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 251/556] ASoC: samsung: aries_audio_probe: double of_node_put due to direct assignment without of_node_get
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (249 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 250/556] ASoC: rt721-sdca-sdw: " Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 252/556] ASoC: sgtl5000: sort the register default table Greg Kroah-Hartman
                   ` (317 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, WenTao Liang, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: WenTao Liang <vulab@iscas.ac.cn>

commit fb5d1b1c5f8a920ee697545fa6dee16825085717 upstream.

In aries_audio_probe(), aries_dai[0].platforms->of_node is assigned the
same pointer as aries_dai[0].cpus->of_node (from of_parse_phandle)
without calling of_node_get(). When the sound card is deregistered, the
ASoC framework calls of_node_put() on both cpus->of_node and
platforms->of_node, causing a double put on the same node and a refcount
underflow.

Add of_node_get(aries_dai[0].cpus->of_node) before the assignment.

Cc: stable@vger.kernel.org
Fixes: 7a3a7671fa6c ("ASoC: samsung: Add driver for Aries boards")
Signed-off-by: WenTao Liang <vulab@iscas.ac.cn>
Link: https://patch.msgid.link/20260627035251.60172-1-vulab@iscas.ac.cn
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/samsung/aries_wm8994.c |    1 +
 1 file changed, 1 insertion(+)

--- a/sound/soc/samsung/aries_wm8994.c
+++ b/sound/soc/samsung/aries_wm8994.c
@@ -658,6 +658,7 @@ static int aries_audio_probe(struct plat
 		goto out;
 	}
 
+	of_node_get(aries_dai[0].cpus->of_node);
 	aries_dai[0].platforms->of_node = aries_dai[0].cpus->of_node;
 
 	/* Set CPU of_node for BT DAI */



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 252/556] ASoC: sgtl5000: sort the register default table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (250 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 251/556] ASoC: samsung: aries_audio_probe: double of_node_put due to direct assignment without of_node_get Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 253/556] ASoC: sti-sas: " Greg Kroah-Hartman
                   ` (316 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit 437fbdeb60693b8f2e8250d44d29e513a95df298 upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

SGTL5000_CHIP_SHORT_CTRL (0x003c) is listed before
SGTL5000_CHIP_ANA_TEST2 (0x003a), which makes the former unreachable.
regcache_reg_needs_sync() then cannot compare it against its default and
reports that a sync is needed, so it is written to the device on every
regcache_sync() even when it was never touched.

Sort the table by register address.

Fixes: 29aa37cddfb9 ("ASoC: sgtl5000: Fix the cache handling")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805122728.12362-2-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/sgtl5000.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/sound/soc/codecs/sgtl5000.c
+++ b/sound/soc/codecs/sgtl5000.c
@@ -56,8 +56,8 @@ static const struct reg_default sgtl5000
 	{ SGTL5000_CHIP_PLL_CTRL,		0x5000 },
 	{ SGTL5000_CHIP_CLK_TOP_CTRL,		0x0000 },
 	{ SGTL5000_CHIP_ANA_STATUS,		0x0000 },
-	{ SGTL5000_CHIP_SHORT_CTRL,		0x0000 },
 	{ SGTL5000_CHIP_ANA_TEST2,		0x0000 },
+	{ SGTL5000_CHIP_SHORT_CTRL,		0x0000 },
 	{ SGTL5000_DAP_CTRL,			0x0000 },
 	{ SGTL5000_DAP_PEQ,			0x0000 },
 	{ SGTL5000_DAP_BASS_ENHANCE,		0x0040 },



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 253/556] ASoC: sti-sas: sort the register default table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (251 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 252/556] ASoC: sgtl5000: sort the register default table Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 254/556] ASoC: tas2552: " Greg Kroah-Hartman
                   ` (315 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit bbd73fb224caa1badfe2aa338fe9c9dcf40a6e96 upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

STIH407_AUDIO_DAC_CTRL (0xa8) is listed before
STIH407_AUDIO_GLUE_CTRL (0xa4), which makes the latter unreachable.
regcache_reg_needs_sync() then cannot compare it against its default and
reports that a sync is needed, so it is written to the device on every
regcache_sync() even when it was never touched.

Sort the table by register address.

Fixes: 165a57a3df02 ("ASoC: sti-sas: clean legacy in sti-sas")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805122811.13713-5-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/sti-sas.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/sound/soc/codecs/sti-sas.c
+++ b/sound/soc/codecs/sti-sas.c
@@ -44,8 +44,8 @@ enum {
 };
 
 static const struct reg_default stih407_sas_reg_defaults[] = {
-	{ STIH407_AUDIO_DAC_CTRL, 0x000000000 },
 	{ STIH407_AUDIO_GLUE_CTRL, 0x00000040 },
+	{ STIH407_AUDIO_DAC_CTRL, 0x000000000 },
 };
 
 struct sti_dac_audio {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 254/556] ASoC: tas2552: sort the register default table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (252 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 253/556] ASoC: sti-sas: " Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 255/556] ASoC: tas2764: " Greg Kroah-Hartman
                   ` (314 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit 1cc0cb62d306bb7c42e3d4649863df7c279ac850 upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

TAS2552_OUTPUT_DATA (0x07), TAS2552_PDM_CFG (0x11), TAS2552_PGA_GAIN
(0x12) and TAS2552_BOOST_APT_CTRL (0x14) are listed before
TAS2552_RESERVED_0D (0x0d), TAS2552_LIMIT_RATE_HYS (0x0e) and
TAS2552_CFG_2 (0x02), which leaves 7 of the 21 entries unreachable.
regcache_reg_needs_sync() then cannot compare them against their
default and reports that a sync is needed, so they are written to the
device on every regcache_sync() even when they were never touched.

Sort the table by register address.

Fixes: 5df7f71d5cdf ("ASoC: tas2552: Support TI TAS2552 Amplifier")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805104149.9795-3-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/tas2552.c |   14 +++++++-------
 1 file changed, 7 insertions(+), 7 deletions(-)

--- a/sound/soc/codecs/tas2552.c
+++ b/sound/soc/codecs/tas2552.c
@@ -31,25 +31,25 @@
 
 static const struct reg_default tas2552_reg_defs[] = {
 	{TAS2552_CFG_1, 0x22},
+	{TAS2552_CFG_2, 0xef},
 	{TAS2552_CFG_3, 0x80},
 	{TAS2552_DOUT, 0x00},
-	{TAS2552_OUTPUT_DATA, 0xc0},
-	{TAS2552_PDM_CFG, 0x01},
-	{TAS2552_PGA_GAIN, 0x00},
-	{TAS2552_BOOST_APT_CTRL, 0x0f},
-	{TAS2552_RESERVED_0D, 0xbe},
-	{TAS2552_LIMIT_RATE_HYS, 0x08},
-	{TAS2552_CFG_2, 0xef},
 	{TAS2552_SER_CTRL_1, 0x00},
 	{TAS2552_SER_CTRL_2, 0x00},
+	{TAS2552_OUTPUT_DATA, 0xc0},
 	{TAS2552_PLL_CTRL_1, 0x10},
 	{TAS2552_PLL_CTRL_2, 0x00},
 	{TAS2552_PLL_CTRL_3, 0x00},
 	{TAS2552_BTIP, 0x8f},
 	{TAS2552_BTS_CTRL, 0x80},
+	{TAS2552_RESERVED_0D, 0xbe},
+	{TAS2552_LIMIT_RATE_HYS, 0x08},
 	{TAS2552_LIMIT_RELEASE, 0x04},
 	{TAS2552_LIMIT_INT_COUNT, 0x00},
+	{TAS2552_PDM_CFG, 0x01},
+	{TAS2552_PGA_GAIN, 0x00},
 	{TAS2552_EDGE_RATE_CTRL, 0x40},
+	{TAS2552_BOOST_APT_CTRL, 0x0f},
 	{TAS2552_VBAT_DATA, 0x00},
 };
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 255/556] ASoC: tas2764: sort the register default table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (253 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 254/556] ASoC: tas2552: " Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 256/556] ASoC: tas2780: " Greg Kroah-Hartman
                   ` (313 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit e7643c3f7eb3292f8a98c2ddbf46ba78d848b83d upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

TAS2764_DVC (0x1a) is listed before TAS2764_CHNL_0 (0x03), which makes
it unreachable.  regcache_reg_needs_sync() then cannot compare it
against its default and reports that a sync is needed, so it is written
to the device on every regcache_sync() even when it was never touched.

Sort the table by register address.

Fixes: 827ed8a0fa50 ("ASoC: tas2764: Add the driver for the TAS2764")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805104149.9795-4-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/tas2764.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/sound/soc/codecs/tas2764.c
+++ b/sound/soc/codecs/tas2764.c
@@ -897,13 +897,13 @@ static const struct reg_default tas2764_
 	{ TAS2764_PAGE, 0x00 },
 	{ TAS2764_SW_RST, 0x00 },
 	{ TAS2764_PWR_CTRL, 0x1a },
-	{ TAS2764_DVC, 0x00 },
 	{ TAS2764_CHNL_0, 0x28 },
 	{ TAS2764_TDM_CFG0, 0x09 },
 	{ TAS2764_TDM_CFG1, 0x02 },
 	{ TAS2764_TDM_CFG2, 0x0a },
 	{ TAS2764_TDM_CFG3, 0x10 },
 	{ TAS2764_TDM_CFG5, 0x42 },
+	{ TAS2764_DVC, 0x00 },
 	{ TAS2764_INT_CLK_CFG, 0x19 },
 };
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 256/556] ASoC: tas2780: sort the register default table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (254 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 255/556] ASoC: tas2764: " Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 257/556] ASoC: tas2783-sdw: drop duplicate reg_default entry Greg Kroah-Hartman
                   ` (312 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit e725093e9e53db9298e38e7332a44dcaac2fd135 upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

TAS2780_DVC (0x1a) is listed before TAS2780_CHNL_0 (0x03), which makes
it unreachable.  regcache_reg_needs_sync() then cannot compare it
against its default and reports that a sync is needed, so it is written
to the device on every regcache_sync() even when it was never touched.

Sort the table by register address.

Fixes: eae9f9ce181b ("ASoC: add tas2780 driver")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805104149.9795-5-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/tas2780.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/sound/soc/codecs/tas2780.c
+++ b/sound/soc/codecs/tas2780.c
@@ -527,13 +527,13 @@ static const struct reg_default tas2780_
 	{ TAS2780_PAGE, 0x00 },
 	{ TAS2780_SW_RST, 0x00 },
 	{ TAS2780_PWR_CTRL, 0x1a },
-	{ TAS2780_DVC, 0x00 },
 	{ TAS2780_CHNL_0, 0x00 },
 	{ TAS2780_TDM_CFG0, 0x09 },
 	{ TAS2780_TDM_CFG1, 0x02 },
 	{ TAS2780_TDM_CFG2, 0x0a },
 	{ TAS2780_TDM_CFG3, 0x10 },
 	{ TAS2780_TDM_CFG5, 0x42 },
+	{ TAS2780_DVC, 0x00 },
 };
 
 static const struct regmap_range_cfg tas2780_regmap_ranges[] = {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 257/556] ASoC: tas2783-sdw: drop duplicate reg_default entry
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (255 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 256/556] ASoC: tas2780: " Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 258/556] ASoC: tas2783-sdw: sort the register default table Greg Kroah-Hartman
                   ` (311 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit ceba07ca24fab54e0e38ec96d196fca3e638d671 upstream.

TAS2783_AMP_LEVEL is defined as TASDEV_REG_SDW(0x0, 0x00, 0x03), so
tas2783_reg_default[] lists that register twice.  Drop the open coded
second entry.

Fixes: 4cc9bd8d7b32 ("ASoc: tas2783A: Add soundwire based codec driver")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805091327.23944-1-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/tas2783-sdw.c |    1 -
 1 file changed, 1 deletion(-)

--- a/sound/soc/codecs/tas2783-sdw.c
+++ b/sound/soc/codecs/tas2783-sdw.c
@@ -106,7 +106,6 @@ struct tas2783_prv {
 
 static const struct reg_default tas2783_reg_default[] = {
 	{TAS2783_AMP_LEVEL, 0x28},
-	{TASDEV_REG_SDW(0, 0, 0x03), 0x28},
 	{TASDEV_REG_SDW(0, 0, 0x04), 0x21},
 	{TASDEV_REG_SDW(0, 0, 0x05), 0x41},
 	{TASDEV_REG_SDW(0, 0, 0x06), 0x00},



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 258/556] ASoC: tas2783-sdw: sort the register default table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (256 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 257/556] ASoC: tas2783-sdw: drop duplicate reg_default entry Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:38 ` [PATCH 7.2 259/556] iio: adc: ad4080: configure backend data size Greg Kroah-Hartman
                   ` (310 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>

commit b45fc97ebcfb27ec250025329a4f79ce5e327ec3 upstream.

reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch().  See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").

tas2783_reg_default[] is grouped by SDCA entity name instead, so the
binary search does not find 120 of its 196 entries.
regcache_reg_needs_sync() then cannot compare those against their default
and reports that a sync is needed, so they are written to the device on
every regcache_sync() even when they were never touched.

Sort the table by register address.

Fixes: 4cc9bd8d7b32 ("ASoc: tas2783A: Add soundwire based codec driver")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805091327.23944-2-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 sound/soc/codecs/tas2783-sdw.c |  170 ++++++++++++++++++++---------------------
 1 file changed, 85 insertions(+), 85 deletions(-)

--- a/sound/soc/codecs/tas2783-sdw.c
+++ b/sound/soc/codecs/tas2783-sdw.c
@@ -141,6 +141,7 @@ static const struct reg_default tas2783_
 	{TASDEV_REG_SDW(0, 0, 0x41), 0x14},
 	{TASDEV_REG_SDW(0, 0, 0x5c), 0x19},
 	{TASDEV_REG_SDW(0, 0, 0x5d), 0x80},
+	{TASDEV_REG_SDW(0, 0, 0x60), 0x21},
 	{TASDEV_REG_SDW(0, 0, 0x63), 0x48},
 	{TASDEV_REG_SDW(0, 0, 0x65), 0x08},
 	{TASDEV_REG_SDW(0, 0, 0x66), 0xb2},
@@ -156,7 +157,6 @@ static const struct reg_default tas2783_
 	{TASDEV_REG_SDW(0, 0, 0x73), 0x08},
 	{TASDEV_REG_SDW(0, 0, 0x75), 0xe0},
 	{TASDEV_REG_SDW(0, 0, 0x7a), 0x60},
-	{TASDEV_REG_SDW(0, 0, 0x60), 0x21},
 	{TASDEV_REG_SDW(0, 1, 0x02), 0x00},
 	{TASDEV_REG_SDW(0, 1, 0x17), 0xc0},
 	{TASDEV_REG_SDW(0, 1, 0x19), 0x60},
@@ -175,63 +175,44 @@ static const struct reg_default tas2783_
 	{TASDEV_REG_SDW(0, 0xfd, 0x39), 0x00},
 	{TASDEV_REG_SDW(0, 0xfd, 0x3e), 0x00},
 	{TASDEV_REG_SDW(0, 0xfd, 0x45), 0x00},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_CS21, 0x02, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_CS21, 0x10, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_CS24, 0x02, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_CS24, 0x10, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_CS26, 0x02, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_CS26, 0x10, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_CS28, 0x02, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_CS28, 0x10, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_CS127, 0x02, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_CS127, 0x10, 0), 0x0},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU21, 0x01, 1), 0x1},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU21, 0x02, 1), 0x9c00},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU23, 0x01, 0), 0x1},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU23, 0x01, 1), 0x1},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU23, 0x0b, 1), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU23, 0x10, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU26, 0x01, 1), 0x1},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU26, 0x01, 0), 0x1},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU26, 0x01, 1), 0x1},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU26, 0x0b, 1), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU26, 0x10, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU127, 0x01, 0), 0x1},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU127, 0x01, 1), 0x1},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU127, 0x01, 2), 0x1},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU127, 0x0b, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU127, 0x0b, 1), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU127, 0x0b, 2), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU127, 0x10, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_XU22, 0x01, 0), 0x1},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_XU22, 0x06, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_XU22, 0x07, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_XU22, 0x08, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_XU22, 0x09, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_XU22, 0x0a, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_CS24, 0x02, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_CS21, 0x02, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_CS26, 0x02, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_CS28, 0x02, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_PDE23, 0x1, 0), 0x3},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_SAPU29, 0x05, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_PPU21, 0x06, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_PPU26, 0x06, 0), 0x0},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_IT21, 0x04, 0), 0x0},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_IT21, 0x08, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_IT21, 0x10, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_IT21, 0x11, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_IT29, 0x04, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_IT29, 0x08, 0), 0x0},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_IT26, 0x04, 0), 0x0},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_IT26, 0x08, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_IT26, 0x10, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_IT26, 0x11, 0), 0x0},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_IT28, 0x04, 0), 0x0},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_IT28, 0x08, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_IT28, 0x10, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_IT28, 0x11, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_IT29, 0x04, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_IT29, 0x08, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_IT29, 0x10, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_IT29, 0x11, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU21, 0x01, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU21, 0x04, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU21, 0x05, 0), 0x1},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU21, 0x08, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU21, 0x10, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU21, 0x11, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU21, 0x12, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU26, 0x01, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU26, 0x04, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU26, 0x05, 0), 0x1},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU26, 0x08, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU26, 0x10, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU26, 0x11, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU26, 0x12, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT24, 0x04, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT24, 0x08, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT23, 0x04, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT23, 0x08, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT25, 0x04, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT25, 0x08, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT28, 0x04, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT28, 0x08, 0), 0x0},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MU26, 0x01, 0), 0x0},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MU26, 0x01, 1), 0x0},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MU26, 0x01, 2), 0x0},
@@ -241,19 +222,60 @@ static const struct reg_default tas2783_
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MU26, 0x01, 6), 0x0},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MU26, 0x01, 7), 0x0},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MU26, 0x06, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT23, 0x04, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT23, 0x08, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT24, 0x04, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT24, 0x08, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT127, 0x04, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT127, 0x08, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU127, 0x01, 0), 0x1},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU127, 0x01, 1), 0x1},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU127, 0x01, 2), 0x1},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU127, 0x0b, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU127, 0x0b, 1), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU127, 0x0b, 2), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_CS127, 0x02, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU21, 0x01, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU21, 0x04, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU21, 0x05, 0), 0x1},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU21, 0x08, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU26, 0x01, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU26, 0x04, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU26, 0x05, 0), 0x1},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU26, 0x08, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU23, 0x10, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU26, 0x10, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_XU22, 0x10, 0), 0x1},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_XU22, 0x12, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_XU22, 0x13, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_XU22, 0x14, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_XU22, 0x15, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_XU22, 0x16, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_CS24, 0x10, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_CS21, 0x10, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_CS26, 0x10, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_CS28, 0x10, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_PDE23, 0x10, 0), 0x3},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_UDMPU23, 0x10, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_SAPU29, 0x10, 0), 0x1},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_SAPU29, 0x11, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_SAPU29, 0x12, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_PPU21, 0x10, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_PPU21, 0x11, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_PPU21, 0x12, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_PPU21, 0x13, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_PPU26, 0x10, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_PPU26, 0x11, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_PPU26, 0x12, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_PPU26, 0x13, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_TG23, 0x10, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_IT21, 0x10, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_IT21, 0x11, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_IT29, 0x10, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_IT29, 0x11, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_IT26, 0x10, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_IT26, 0x11, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_IT28, 0x10, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_IT28, 0x11, 0), 0x0},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT24, 0x11, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT25, 0x04, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT25, 0x08, 0), 0x0},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT25, 0x11, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT28, 0x04, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT28, 0x08, 0), 0x0},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT28, 0x11, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT127, 0x04, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT127, 0x08, 0), 0x0},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT127, 0x11, 0), 0x0},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT127, 0x12, 0), 0x0},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT127, 0x12, 1), 0x0},
@@ -263,6 +285,14 @@ static const struct reg_default tas2783_
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT127, 0x12, 5), 0x0},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT127, 0x12, 6), 0x0},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT127, 0x12, 7), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_FU127, 0x10, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_CS127, 0x10, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU21, 0x10, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU21, 0x11, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU21, 0x12, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU26, 0x10, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU26, 0x11, 0), 0x0},
+	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_MFPU26, 0x12, 0), 0x0},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT127, 0x12, 8), 0x0},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT127, 0x12, 9), 0x0},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT127, 0x12, 0xa), 0x0},
@@ -271,36 +301,6 @@ static const struct reg_default tas2783_
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT127, 0x12, 0xd), 0x0},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT127, 0x12, 0xe), 0x0},
 	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_OT127, 0x12, 0xf), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_PDE23, 0x1, 0), 0x3},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_PDE23, 0x10, 0), 0x3},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_PPU21, 0x06, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_PPU21, 0x10, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_PPU21, 0x11, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_PPU21, 0x12, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_PPU21, 0x13, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_PPU26, 0x06, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_PPU26, 0x10, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_PPU26, 0x11, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_PPU26, 0x12, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_PPU26, 0x13, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_SAPU29, 0x05, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_SAPU29, 0x10, 0), 0x1},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_SAPU29, 0x11, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_SAPU29, 0x12, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_TG23, 0x10, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_XU22, 0x01, 0), 0x1},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_XU22, 0x06, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_XU22, 0x07, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_XU22, 0x08, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_XU22, 0x09, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_XU22, 0x0a, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_XU22, 0x10, 0), 0x1},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_XU22, 0x12, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_XU22, 0x13, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_XU22, 0x14, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_XU22, 0x15, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_XU22, 0x16, 0), 0x0},
-	{SDW_SDCA_CTL(1, TAS2783_SDCA_ENT_UDMPU23, 0x10, 0), 0x0},
 };
 
 static const struct reg_sequence tas2783_init_seq[] = {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 259/556] iio: adc: ad4080: configure backend data size
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (257 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 258/556] ASoC: tas2783-sdw: sort the register default table Greg Kroah-Hartman
@ 2026-09-09 13:38 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 260/556] iio: adc: adi-axi-adc: add data size support for AD408X backend Greg Kroah-Hartman
                   ` (309 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:38 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Antoniu Miclaus, David Lechner,
	Stable, Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Antoniu Miclaus <antoniu.miclaus@analog.com>

commit d39afd249d1ef5cb03b6f1dc22a68e6385de413d upstream.

The AXI backend needs to know the ADC word width in order to pack the
sample data correctly on the bus. During channel setup, program the
backend packet format via iio_backend_data_size_set() using the channel
resolution, so the data is transferred according to the device's
realbits.

The backend packet format field defaults to 20-bit packing, so the
20-bit parts (AD4080/AD4081/AD4082, AD4880) were unaffected. The 16-bit
(AD4083/AD4084/AD4085, AD4884) and 14-bit (AD4086/AD4087/AD4088) parts,
however, were left packing data at the wrong width, producing corrupt
buffered captures.

Fixes: 6c3e7265734b ("iio: adc: ad4080: add support for AD4084")
Signed-off-by: Antoniu Miclaus <antoniu.miclaus@analog.com>
Reviewed-by: David Lechner <dlechner@baylibre.com>
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/adc/ad4080.c |    5 +++++
 1 file changed, 5 insertions(+)

--- a/drivers/iio/adc/ad4080.c
+++ b/drivers/iio/adc/ad4080.c
@@ -697,6 +697,11 @@ static int ad4080_setup_channel(struct a
 	if (ret)
 		return ret;
 
+	ret = iio_backend_data_size_set(st->back[ch],
+					st->info->channels[0].scan_type.realbits);
+	if (ret)
+		return ret;
+
 	if (!st->lvds_cnv_en)
 		return 0;
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 260/556] iio: adc: adi-axi-adc: add data size support for AD408X backend
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (258 preceding siblings ...)
  2026-09-09 13:38 ` [PATCH 7.2 259/556] iio: adc: ad4080: configure backend data size Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 261/556] iio: adc: max14001: add missing select REGMAP to Kconfig Greg Kroah-Hartman
                   ` (308 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Antoniu Miclaus, David Lechner,
	Stable, Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Antoniu Miclaus <antoniu.miclaus@analog.com>

commit 60f6f7fd5f89c7f55991c5dc59f3ccc74cd6efd7 upstream.

The AD408X AXI core can pack the sample data on the bus using different
word widths. Expose this through the data_size_set backend operation so
that frontends can program the packet format field (bits 3:2 of the
CNTRL_3 register) according to the ADC resolution: 20-bit, 16-bit and
14-bit map to packet format values 0, 1 and 2 respectively.

Signed-off-by: Antoniu Miclaus <antoniu.miclaus@analog.com>
Reviewed-by: David Lechner <dlechner@baylibre.com>
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/adc/adi-axi-adc.c |   30 ++++++++++++++++++++++++++++++
 1 file changed, 30 insertions(+)

--- a/drivers/iio/adc/adi-axi-adc.c
+++ b/drivers/iio/adc/adi-axi-adc.c
@@ -53,6 +53,10 @@
 #define   AXI_AD485X_PACKET_FORMAT_24BIT	0x1
 #define   AXI_AD485X_PACKET_FORMAT_32BIT	0x2
 #define   AXI_AD408X_CNTRL_3_FILTER_EN_MSK	BIT(0)
+#define   AXI_AD408X_CNTRL_3_PACKET_FORMAT_MSK	GENMASK(3, 2)
+#define   AXI_AD408X_PACKET_FORMAT_20BIT	0x0
+#define   AXI_AD408X_PACKET_FORMAT_16BIT	0x1
+#define   AXI_AD408X_PACKET_FORMAT_14BIT	0x2
 
 #define ADI_AXI_ADC_REG_SYNC_STATUS		0x0068
 #define   ADI_AXI_ADC_SYNC_STATUS_ADC_SYNC_MSK	BIT(0)
@@ -436,6 +440,31 @@ static int axi_adc_ad408x_filter_type_se
 				 AXI_AD408X_CNTRL_3_FILTER_EN_MSK);
 }
 
+static int axi_adc_ad408x_data_size_set(struct iio_backend *back,
+					unsigned int size)
+{
+	struct adi_axi_adc_state *st = iio_backend_get_priv(back);
+	unsigned int val;
+
+	switch (size) {
+	case 20:
+		val = AXI_AD408X_PACKET_FORMAT_20BIT;
+		break;
+	case 16:
+		val = AXI_AD408X_PACKET_FORMAT_16BIT;
+		break;
+	case 14:
+		val = AXI_AD408X_PACKET_FORMAT_14BIT;
+		break;
+	default:
+		return -EINVAL;
+	}
+
+	return regmap_update_bits(st->regmap, ADI_AXI_ADC_REG_CNTRL_3,
+				  AXI_AD408X_CNTRL_3_PACKET_FORMAT_MSK,
+				  FIELD_PREP(AXI_AD408X_CNTRL_3_PACKET_FORMAT_MSK, val));
+}
+
 static int axi_adc_ad408x_interface_data_align(struct iio_backend *back,
 					       u32 timeout_us)
 {
@@ -659,6 +688,7 @@ static const struct iio_backend_ops adi_
 	.free_buffer = axi_adc_free_buffer,
 	.data_sample_trigger = axi_adc_data_sample_trigger,
 	.filter_type_set = axi_adc_ad408x_filter_type_set,
+	.data_size_set = axi_adc_ad408x_data_size_set,
 	.interface_data_align = axi_adc_ad408x_interface_data_align,
 	.num_lanes_set = axi_adc_num_lanes_set,
 	.debugfs_reg_access = iio_backend_debugfs_ptr(axi_adc_reg_access),



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 261/556] iio: adc: max14001: add missing select REGMAP to Kconfig
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (259 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 260/556] iio: adc: adi-axi-adc: add data size support for AD408X backend Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 262/556] iio: adc: max34408: add missing select REGMAP_I2C " Greg Kroah-Hartman
                   ` (307 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Joshua Crofts, Andy Shevchenko,
	Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Joshua Crofts <joshua.crofts1@gmail.com>

commit b7c969d0d445c415b8e9f32627d7e8f092c7e916 upstream.

The Kconfig entry for the MAX14001 is missing a 'select REGMAP',
causing build failures.

Fixes: 59795109fa67 ("iio: adc: max14001: New driver")
Cc: stable@vger.kernel.org
Signed-off-by: Joshua Crofts <joshua.crofts1@gmail.com>
Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/adc/Kconfig |    1 +
 1 file changed, 1 insertion(+)

--- a/drivers/iio/adc/Kconfig
+++ b/drivers/iio/adc/Kconfig
@@ -1076,6 +1076,7 @@ config MAX1363
 config MAX14001
 	tristate "Analog Devices MAX14001/MAX14002 ADC driver"
 	depends on SPI
+	select REGMAP
 	help
 	  Say yes here to build support for Analog Devices MAX14001/MAX14002
 	  Configurable, Isolated 10-bit ADCs for Multi-Range Binary Inputs.



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 262/556] iio: adc: max34408: add missing select REGMAP_I2C to Kconfig
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (260 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 261/556] iio: adc: max14001: add missing select REGMAP to Kconfig Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 263/556] iio: adc: pac1921: fix wrong channel used in trigger handler read Greg Kroah-Hartman
                   ` (306 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Joshua Crofts, Andy Shevchenko,
	Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Joshua Crofts <joshua.crofts1@gmail.com>

commit 947f1079074a260ba200419d5cba6b8549d5ac0c upstream.

The Kconfig entry for the MAX34408 is missing a 'select REGMAP_I2C',
causing build failures.

Fixes: cf27775838c5 ("iio: adc: Add driver support for MAX34408/9")
Cc: stable@vger.kernel.org
Signed-off-by: Joshua Crofts <joshua.crofts1@gmail.com>
Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/adc/Kconfig |    1 +
 1 file changed, 1 insertion(+)

--- a/drivers/iio/adc/Kconfig
+++ b/drivers/iio/adc/Kconfig
@@ -1087,6 +1087,7 @@ config MAX14001
 config MAX34408
 	tristate "Maxim max34408/max344089 ADC driver"
 	depends on I2C
+	select REGMAP_I2C
 	help
 	  Say yes here to build support for Maxim max34408/max34409 current sense
 	  monitor with 8-bits ADC interface with overcurrent delay/threshold and



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 263/556] iio: adc: pac1921: fix wrong channel used in trigger handler read
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (261 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 262/556] iio: adc: max34408: add missing select REGMAP_I2C " Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 264/556] iio: buffer: Fix potential use-after-free in anonymous buffer release Greg Kroah-Hartman
                   ` (305 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Cong Nguyen, Matteo Martelli,
	David Lechner, Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Cong Nguyen <congnt264@gmail.com>

commit 3364c56b20c1c496bdb8c8df32f96a9947dbf98e upstream.

pac1921_trigger_handler() walks the enabled channels with
iio_for_each_active_channel(), which yields the scan index (bit) of each
active channel, while ch is a separate counter used to pack the samples
contiguously into the scan buffer.

The register to read was looked up with the packing counter instead of
the scan index:

	ret = pac1921_read_res(priv, idev->channels[ch].address, &val);

pac1921_channels[] is ordered by scan index, so channels[bit] is the
channel that is actually enabled, whereas channels[ch] is merely the
ch-th array entry. These coincide only when the enabled channels form a
contiguous prefix (e.g. all channels enabled). With a sparse scan mask -
for example when only the power channel (scan index 3) is enabled - the
handler reads the wrong register (VBUS instead of VPOWER) and pushes it
to userspace as the enabled channel's data.

Index the channel array by the scan index (bit) to read the correct
register, keeping ch only for contiguous packing into the scan buffer.

Fixes: 371f778b83cd ("iio: adc: add support for pac1921")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4
Signed-off-by: Cong Nguyen <congnt264@gmail.com>
Acked-by: Matteo Martelli <matteomartelli3@gmail.com>
Reviewed-by: David Lechner <dlechner@baylibre.com>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/adc/pac1921.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/iio/adc/pac1921.c
+++ b/drivers/iio/adc/pac1921.c
@@ -1037,7 +1037,7 @@ static irqreturn_t pac1921_trigger_handl
 	iio_for_each_active_channel(idev, bit) {
 		u16 val;
 
-		ret = pac1921_read_res(priv, idev->channels[ch].address, &val);
+		ret = pac1921_read_res(priv, idev->channels[bit].address, &val);
 		if (ret)
 			goto done;
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 264/556] iio: buffer: Fix potential use-after-free in anonymous buffer release
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (262 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 263/556] iio: adc: pac1921: fix wrong channel used in trigger handler read Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 265/556] iio: buffer: Make IIO DMA fence release RCU-safe Greg Kroah-Hartman
                   ` (304 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Lars-Peter Clausen, Andy Shevchenko,
	Stable, Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lars-Peter Clausen <lars@metafoo.de>

commit 6288b593e76eb10329326f2cd51e32557203b9e5 upstream.

An anonymous buffer handle holds a reference to the underlying IIO device.
The reference is dropped in the buffer handle's release function. If the
device has been removed, either through unbind or hot-unplug, the buffer
handle might hold the last reference.

The release function takes the mutex for the buffer using a guard, which
means the unlock happens after all the code in the function, including
`iio_device_put()`. If the anonymous buffer holds the last reference this
might free both the IIO device and the buffer, which contains the mutex,
leading to use-after-free when the mutex is unlocked.

Fix this by using a scoped guard just around the buffer dmabuf list access,
making sure the mutex is unlocked before releasing the IIO device.

Version 10 of the patch that introduced this issue used this exact scheme
of first unlocking and then dropping the reference [1]. During review it
was suggested to use a guard instead, and version 11 made that change [2].

Reported-by: codex:gpt-5.6
Fixes: 3e26d9f08fbe ("iio: core: Add new DMABUF interface infrastructure")
Signed-off-by: Lars-Peter Clausen <lars@metafoo.de>
Link: https://lore.kernel.org/linux-iio/20240605110845.86740-4-paul@crapouillou.net #[1]
Link: https://lore.kernel.org/linux-iio/20240618100302.72886-4-paul@crapouillou.net #[2]
Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com>
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/industrialio-buffer.c |   16 ++++++++++------
 1 file changed, 10 insertions(+), 6 deletions(-)

--- a/drivers/iio/industrialio-buffer.c
+++ b/drivers/iio/industrialio-buffer.c
@@ -1619,12 +1619,16 @@ static int iio_buffer_chrdev_release(str
 
 	wake_up(&buffer->pollq);
 
-	guard(mutex)(&buffer->dmabufs_mutex);
-
-	/* Close all attached DMABUFs */
-	list_for_each_entry_safe(priv, tmp, &buffer->dmabufs, entry) {
-		list_del_init(&priv->entry);
-		iio_buffer_dmabuf_put(priv->attach);
+	/*
+	 * The mutex must be unlocked before iio_device_put(), which might drop the
+	 * last reference and free the buffer.
+	 */
+	scoped_guard(mutex, &buffer->dmabufs_mutex) {
+		/* Close all attached DMABUFs */
+		list_for_each_entry_safe(priv, tmp, &buffer->dmabufs, entry) {
+			list_del_init(&priv->entry);
+			iio_buffer_dmabuf_put(priv->attach);
+		}
 	}
 
 	kfree(ib);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 265/556] iio: buffer: Make IIO DMA fence release RCU-safe
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (263 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 264/556] iio: buffer: Fix potential use-after-free in anonymous buffer release Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 266/556] iio: buffer: Tie IIO dma fence lock lifetime to the fence Greg Kroah-Hartman
                   ` (303 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Lars-Peter Clausen, Stable,
	Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lars-Peter Clausen <lars@metafoo.de>

commit 8662e56c31cf23b61ca3d11b516efb94c35b8026 upstream.

The `dma_fence` documentation states that if a custom release
implementation is provided, the `dma_fence` object must be freed in an
RCU-safe way. The current `iio_dma_fence` implementation uses `kfree()`,
which might result in a use-after-free.

Remove the custom `release` implementation. This makes the DMA fence core
fall back to `dma_fence_free()`, which calls `kfree_rcu()` on the fence.
This requires that the fence be the first member of `struct iio_dma_fence`.

Using the default release method for extended DMA fence structures is a
common pattern.

Reported-by: codex:gpt-5.6
Fixes: 3e26d9f08fbe ("iio: core: Add new DMABUF interface infrastructure")
Signed-off-by: Lars-Peter Clausen <lars@metafoo.de>
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/industrialio-buffer.c |   13 ++++---------
 1 file changed, 4 insertions(+), 9 deletions(-)

--- a/drivers/iio/industrialio-buffer.c
+++ b/drivers/iio/industrialio-buffer.c
@@ -57,6 +57,10 @@ struct iio_dmabuf_priv {
 };
 
 struct iio_dma_fence {
+	/*
+	 * Must remain the first member so the default release callback can pass
+	 * the fence directly to dma_fence_free().
+	 */
 	struct dma_fence base;
 	struct iio_dmabuf_priv *priv;
 	struct work_struct work;
@@ -1831,18 +1835,9 @@ iio_buffer_dma_fence_get_driver_name(str
 	return "iio";
 }
 
-static void iio_buffer_dma_fence_release(struct dma_fence *fence)
-{
-	struct iio_dma_fence *iio_fence =
-		container_of(fence, struct iio_dma_fence, base);
-
-	kfree(iio_fence);
-}
-
 static const struct dma_fence_ops iio_buffer_dma_fence_ops = {
 	.get_driver_name	= iio_buffer_dma_fence_get_driver_name,
 	.get_timeline_name	= iio_buffer_dma_fence_get_driver_name,
-	.release		= iio_buffer_dma_fence_release,
 };
 
 static int iio_buffer_enqueue_dmabuf(struct iio_dev_buffer_pair *ib,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 266/556] iio: buffer: Tie IIO dma fence lock lifetime to the fence
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (264 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 265/556] iio: buffer: Make IIO DMA fence release RCU-safe Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 267/556] iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable Greg Kroah-Hartman
                   ` (302 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Lars-Peter Clausen, Stable,
	Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lars-Peter Clausen <lars@metafoo.de>

commit f25ec4627d935dedfb5fe83bd2c2678cdcc19611 upstream.

The `iio_dma_fence` implementation currently uses a lock embedded in the
`iio_dmabuf_priv`. But the `iio_dma_fence` can outlive the
`iio_dmabuf_priv`, which can cause a use-after-free.

Tie the lifetime of the lock to the lifetime of the fence by embedding them
in the same struct.

We can't just hold a reference to the `iio_dmabuf_priv` from the
`iio_dma_fence` since `iio_buffer_dmabuf_release()` might sleep and the
fence release callback is not allowed to sleep.

Note that the `dma_fence` framework now has an internal lock that gets used
when the passing `NULL` for `lock` in `dma_fence_init()`, but in order to
allow this patch to be backportable use an external lock.

Reported-by: codex:gpt-5.6
Fixes: 3e26d9f08fbe ("iio: core: Add new DMABUF interface infrastructure")
Signed-off-by: Lars-Peter Clausen <lars@metafoo.de>
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/industrialio-buffer.c |    9 ++++-----
 1 file changed, 4 insertions(+), 5 deletions(-)

--- a/drivers/iio/industrialio-buffer.c
+++ b/drivers/iio/industrialio-buffer.c
@@ -47,9 +47,6 @@ struct iio_dmabuf_priv {
 
 	u64 context;
 
-	/* Spinlock used for locking the dma_fence */
-	spinlock_t lock;
-
 	struct dma_buf_attachment *attach;
 	struct sg_table *sgt;
 	enum dma_data_direction dir;
@@ -62,6 +59,7 @@ struct iio_dma_fence {
 	 * the fence directly to dma_fence_free().
 	 */
 	struct dma_fence base;
+	spinlock_t lock; /* protects base */
 	struct iio_dmabuf_priv *priv;
 	struct work_struct work;
 };
@@ -1710,7 +1708,6 @@ static int iio_buffer_attach_dmabuf(stru
 	if (!priv)
 		return -ENOMEM;
 
-	spin_lock_init(&priv->lock);
 	priv->context = dma_fence_context_alloc(1);
 
 	dmabuf = dma_buf_get(fd);
@@ -1891,6 +1888,8 @@ static int iio_buffer_enqueue_dmabuf(str
 		goto err_attachment_put;
 	}
 
+	spin_lock_init(&fence->lock);
+
 	fence->priv = priv;
 
 	seqno = atomic_add_return(1, &priv->seqno);
@@ -1901,7 +1900,7 @@ static int iio_buffer_enqueue_dmabuf(str
 	 * the dma_fence.
 	 */
 	dma_fence_init(&fence->base, &iio_buffer_dma_fence_ops,
-		       &priv->lock, priv->context, seqno);
+		       &fence->lock, priv->context, seqno);
 
 	ret = iio_dma_resv_lock(dmabuf, nonblock);
 	if (ret)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 267/556] iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (265 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 266/556] iio: buffer: Tie IIO dma fence lock lifetime to the fence Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 268/556] iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF Greg Kroah-Hartman
                   ` (301 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Moksh Panicker, Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Moksh Panicker <mokshpanicker.7@gmail.com>

commit bcd3f72e26314edfce7eaf8d7160b3119c7b7fed upstream.

atlas_buffer_postenable() acquires a runtime PM reference with
pm_runtime_resume_and_get() but returns the result of
atlas_set_interrupt() directly. If atlas_set_interrupt() fails,
the runtime PM reference is leaked and the device can never
autosuspend.

Add pm_runtime_put_autosuspend() on the error path to balance
the reference.

Fixes: 0e4f336f50de ("iio: chemical: atlas-sensor: Balance runtime pm + pm_runtime_resume_and_get()")
Cc: stable@vger.kernel.org
Signed-off-by: Moksh Panicker <mokshpanicker.7@gmail.com>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/chemical/atlas-sensor.c |    6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

--- a/drivers/iio/chemical/atlas-sensor.c
+++ b/drivers/iio/chemical/atlas-sensor.c
@@ -412,7 +412,11 @@ static int atlas_buffer_postenable(struc
 	if (ret)
 		return ret;
 
-	return atlas_set_interrupt(data, true);
+	ret = atlas_set_interrupt(data, true);
+	if (ret)
+		pm_runtime_put_autosuspend(&data->client->dev);
+
+	return ret;
 }
 
 static int atlas_buffer_predisable(struct iio_dev *indio_dev)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 268/556] iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (266 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 267/556] iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 269/556] iio: chemical: sgp30: Handle IAQ thread creation failure Greg Kroah-Hartman
                   ` (300 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Fan Wu, Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Fan Wu <fanwu01@zju.edu.cn>

commit be61c8c6252671ecf1fee0ad90f87669e0be1e20 upstream.

The atlas driver requests its hardware data-ready IRQ with
devm_request_threaded_irq(); its threaded handler queues an irq_work,
atlas_work_handler(), that calls iio_trigger_poll(data->trig).

The IRQ is devm-managed, so free_irq() runs from the devres unwind after
atlas_remove() returns without flushing that irq_work.  Once a buffer is
enabled, conversion-complete IRQs keep firing and queueing it; a pending
irq_work can therefore run after the unwind has freed atlas_data/indio_dev
and the trigger, when atlas_work_handler() derives the atlas_data pointer
via container_of() and dereferences data->trig, a use-after-free.

Call iio_trigger_poll_nested() directly from the threaded handler instead
of bouncing through irq_work.  free_irq() then drains the threaded handler,
closing the window; other iio drivers with a threaded data-ready IRQ do the
same (e.g. bmi270).

This issue was found by an in-house static analysis tool.

Fixes: 7103b99b031c ("iio: chemical: atlas-ph-sensor: reorg driver to allow multiple chips")
Cc: stable@vger.kernel.org # v6.4+
Assisted-by: Codex:gpt-5.6
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/chemical/atlas-sensor.c |   13 +------------
 1 file changed, 1 insertion(+), 12 deletions(-)

--- a/drivers/iio/chemical/atlas-sensor.c
+++ b/drivers/iio/chemical/atlas-sensor.c
@@ -13,7 +13,6 @@
 #include <linux/mutex.h>
 #include <linux/err.h>
 #include <linux/irq.h>
-#include <linux/irq_work.h>
 #include <linux/i2c.h>
 #include <linux/regmap.h>
 #include <linux/iio/iio.h>
@@ -87,7 +86,6 @@ struct atlas_data {
 	struct iio_trigger *trig;
 	const struct atlas_device *chip;
 	struct regmap *regmap;
-	struct irq_work work;
 	unsigned int interrupt_enabled;
 	/* 96-bit data + 32-bit pad + 64-bit timestamp */
 	__be32 buffer[6] __aligned(8);
@@ -440,13 +438,6 @@ static const struct iio_buffer_setup_ops
 	.predisable = atlas_buffer_predisable,
 };
 
-static void atlas_work_handler(struct irq_work *work)
-{
-	struct atlas_data *data = container_of(work, struct atlas_data, work);
-
-	iio_trigger_poll(data->trig);
-}
-
 static irqreturn_t atlas_trigger_handler(int irq, void *private)
 {
 	struct iio_poll_func *pf = private;
@@ -473,7 +464,7 @@ static irqreturn_t atlas_interrupt_handl
 	struct iio_dev *indio_dev = private;
 	struct atlas_data *data = iio_priv(indio_dev);
 
-	irq_work_queue(&data->work);
+	iio_trigger_poll_nested(data->trig);
 
 	return IRQ_HANDLED;
 }
@@ -669,8 +660,6 @@ static int atlas_probe(struct i2c_client
 		goto unregister_trigger;
 	}
 
-	init_irq_work(&data->work, atlas_work_handler);
-
 	if (client->irq > 0) {
 		/* interrupt pin toggles on new conversion */
 		ret = devm_request_threaded_irq(&client->dev, client->irq,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 269/556] iio: chemical: sgp30: Handle IAQ thread creation failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (267 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 268/556] iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 270/556] iio: dac: ad3552r-hs: fix scnprintf() buffer bound in data source show Greg Kroah-Hartman
                   ` (299 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Linmao Li, Joshua Crofts, Stable,
	Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Linmao Li <lilinmao@kylinos.cn>

commit 1135d6875d2dbda3f6ec718f3421a6ce4378bd63 upstream.

kthread_run() can fail and return an error pointer, but sgp_probe() stores
it and returns success, so the device is registered without its IAQ thread
and sgp_remove() later passes the error pointer to kthread_stop(). Return
the error from probe instead.

Fixes: ce514124161a ("iio: chemical: sgp30: Support Sensirion SGP30/SGPC3 sensors")
Signed-off-by: Linmao Li <lilinmao@kylinos.cn>
Reviewed-by: Joshua Crofts <joshua.crofts1@gmail.com>
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/chemical/sgp30.c |    3 +++
 1 file changed, 3 insertions(+)

--- a/drivers/iio/chemical/sgp30.c
+++ b/drivers/iio/chemical/sgp30.c
@@ -548,6 +548,9 @@ static int sgp_probe(struct i2c_client *
 
 	data->iaq_thread = kthread_run(sgp_iaq_threadfn, data,
 				       "%s-iaq", data->client->name);
+	if (IS_ERR(data->iaq_thread))
+		return dev_err_probe(dev, PTR_ERR(data->iaq_thread),
+				     "failed to start IAQ thread\n");
 
 	return 0;
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 270/556] iio: dac: ad3552r-hs: fix scnprintf() buffer bound in data source show
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (268 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 269/556] iio: chemical: sgp30: Handle IAQ thread creation failure Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 271/556] iio: dac: ad5446: fix OF module device table Greg Kroah-Hartman
                   ` (298 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Babanpreet Singh, Stable,
	Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Babanpreet Singh <bbnpreetsingh@gmail.com>

commit f2c5c76306fadb834dd5ea76cab0b7cd447e6035 upstream.

ad3552r_hs_show_data_source_avail() formats the available data source
names into a 128-byte stack buffer, but bounds each scnprintf() with
PAGE_SIZE instead of the buffer size, so the bound does not protect
the destination at all.

This cannot overflow today - dbgfs_attr_source[] has two entries,
"normal" and "ramp-16bit", 18 bytes formatted - but the bound stops
protecting the stack the day the table grows. Use sizeof(buf) so the
bound matches the destination.

Found by smatch:

  drivers/iio/dac/ad3552r-hs.c:593 ad3552r_hs_show_data_source_avail()
  error: scnprintf() 'buf[len]' too small (128 vs 4096)

Fixes: b1c5d68ea66e ("iio: dac: ad3552r-hs: add support for internal ramp")
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Babanpreet Singh <bbnpreetsingh@gmail.com>
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/dac/ad3552r-hs.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/iio/dac/ad3552r-hs.c
+++ b/drivers/iio/dac/ad3552r-hs.c
@@ -590,7 +590,7 @@ static ssize_t ad3552r_hs_show_data_sour
 	int i;
 
 	for (i = 0; i < ARRAY_SIZE(dbgfs_attr_source); i++) {
-		len += scnprintf(buf + len, PAGE_SIZE - len, "%s ",
+		len += scnprintf(buf + len, sizeof(buf) - len, "%s ",
 				 dbgfs_attr_source[i]);
 	}
 	buf[len - 1] = '\n';



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 271/556] iio: dac: ad5446: fix OF module device table
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (269 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 270/556] iio: dac: ad3552r-hs: fix scnprintf() buffer bound in data source show Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 272/556] iio: dac: m62332: Fix regulator reference count imbalance Greg Kroah-Hartman
                   ` (297 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Can Peng, Joshua Crofts,
	Andy Shevchenko, Stable, Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Can Peng <pengcan@kylinos.cn>

commit a3c03cf36a083893dedad928915471dc8c10692e upstream.

The ad5446 I2C driver exports its OF match table with
MODULE_DEVICE_TABLE(OF, ...).

The device table type is used by modpost when generating module aliases,
and scripts/mod/file2alias.c matches the lowercase "of" type.  Using
"OF" prevents the OF table from being recognized, so no OF module alias is
generated for the I2C driver.

Use the lowercase "of" type so OF-based module autoloading works.

Fixes: 876d94024087 ("iio: dac: ad5446: Separate I2C/SPI into different drivers")
Signed-off-by: Can Peng <pengcan@kylinos.cn>
Reviewed-by: Joshua Crofts <joshua.crofts1@gmail.com>
Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com>
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/dac/ad5446-i2c.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/iio/dac/ad5446-i2c.c
+++ b/drivers/iio/dac/ad5446-i2c.c
@@ -83,7 +83,7 @@ static const struct of_device_id ad5446_
 	{ .compatible = "adi,ad5622", .data = &ad5622_chip_info },
 	{ }
 };
-MODULE_DEVICE_TABLE(OF, ad5446_i2c_of_ids);
+MODULE_DEVICE_TABLE(of, ad5446_i2c_of_ids);
 
 static struct i2c_driver ad5446_i2c_driver = {
 	.driver = {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 272/556] iio: dac: m62332: Fix regulator reference count imbalance
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (270 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 271/556] iio: dac: ad5446: fix OF module device table Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 273/556] iio: dac: mcp47feb02: add missing select REGMAP_I2C to Kconfig Greg Kroah-Hartman
                   ` (296 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Erick Henrique,
	Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Erick Henrique <erick.henrique.rodrigues@usp.br>

commit a130404ce0b69ca1438126bd81c1985d3b4d2e6f upstream.

m62332_set_value() enables the Vcc regulator on every write of a
non-zero value and disables it on every write of zero, without tracking
the channel's current state. Because the regulator is reference counted,
changing a channel directly from one non-zero value to another enables
it more than once, while a later write of zero disables it only once.
The reference count never returns to zero and the regulator is left
enabled indefinitely.

Only enable the regulator on the transition from zero to non-zero, and
only disable it on the transition from non-zero to zero, using the
previously stored channel value to detect the edge. Balance the
regulator on the I2C error path so the reference count stays consistent
if the write fails.

Fixes: b87b0c0f81e8 ("iio: add m62332 DAC driver")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260418130322.106769-1-erick.henrique.rodrigues%40usp.br
Cc: stable@vger.kernel.org
Signed-off-by: Erick Henrique <erick.henrique.rodrigues@usp.br>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/dac/m62332.c |   17 ++++++++++++-----
 1 file changed, 12 insertions(+), 5 deletions(-)

--- a/drivers/iio/dac/m62332.c
+++ b/drivers/iio/dac/m62332.c
@@ -32,6 +32,7 @@ static int m62332_set_value(struct iio_d
 {
 	struct m62332_data *data = iio_priv(indio_dev);
 	struct i2c_client *client = data->client;
+	bool enabling, disabling;
 	u8 outbuf[2];
 	int res;
 
@@ -43,7 +44,10 @@ static int m62332_set_value(struct iio_d
 
 	mutex_lock(&data->mutex);
 
-	if (val) {
+	enabling = val && !data->raw[channel];
+	disabling = !val && data->raw[channel];
+
+	if (enabling) {
 		res = regulator_enable(data->vcc);
 		if (res)
 			goto out;
@@ -52,14 +56,17 @@ static int m62332_set_value(struct iio_d
 	res = i2c_master_send(client, outbuf, ARRAY_SIZE(outbuf));
 	if (res >= 0 && res != ARRAY_SIZE(outbuf))
 		res = -EIO;
-	if (res < 0)
+	if (res < 0) {
+		if (enabling)
+			regulator_disable(data->vcc);
 		goto out;
+	}
 
-	data->raw[channel] = val;
-
-	if (!val)
+	if (disabling)
 		regulator_disable(data->vcc);
 
+	data->raw[channel] = val;
+
 	mutex_unlock(&data->mutex);
 
 	return 0;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 273/556] iio: dac: mcp47feb02: add missing select REGMAP_I2C to Kconfig
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (271 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 272/556] iio: dac: m62332: Fix regulator reference count imbalance Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 274/556] iio: gyro: mpu3050: fix sign of raw angular velocity readings Greg Kroah-Hartman
                   ` (295 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Joshua Crofts, Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Joshua Crofts <joshua.crofts1@gmail.com>

commit 739aac87638f06fcf851df41ecd52d30ab7b0570 upstream.

The Kconfig entry for the MCP47FEB02 is missing a 'select REGMAP_I2C',
causing build failures.

Fixes: bf394cc80369 ("iio: dac: adding support for Microchip MCP47FEB02")
Cc: stable@vger.kernel.org
Signed-off-by: Joshua Crofts <joshua.crofts1@gmail.com>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/dac/Kconfig |    1 +
 1 file changed, 1 insertion(+)

--- a/drivers/iio/dac/Kconfig
+++ b/drivers/iio/dac/Kconfig
@@ -552,6 +552,7 @@ config MCP4728
 config MCP47FEB02
 	tristate "MCP47F(E/V)B01/02/04/08/11/12/14/18/21/22/24/28 DAC driver"
 	depends on I2C
+	select REGMAP_I2C
 	help
 	  Say yes here if you want to build the driver for the Microchip:
 	  - 8-bit DAC:



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 274/556] iio: gyro: mpu3050: fix sign of raw angular velocity readings
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (272 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 273/556] iio: dac: mcp47feb02: add missing select REGMAP_I2C to Kconfig Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 275/556] iio: imu: st_lsm6dsx: Update enable mask when using sensor fusion Greg Kroah-Hartman
                   ` (294 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Cong Nguyen, Linus Walleij,
	Joshua Crofts, David Lechner, Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Cong Nguyen <congnt264@gmail.com>

commit 06fab97602fe400bea843176f485bbac07a668e2 upstream.

The MPU-3050 gyroscope output registers hold 16-bit two's complement
values; the angular velocity channels are declared with .sign = 's'.
When mpu3050_read_raw() handles IIO_CHAN_INFO_RAW it reads the register
via a big-endian regmap_bulk_read() and assigns it with:

	*val = be16_to_cpu(raw_val);

be16_to_cpu() yields an unsigned 16-bit quantity, so negative rates
(bit 15 set) are reported to userspace as large positive integers
(e.g. -1 becomes 65535) instead of the correct negative value.

Cast to s16 before the assignment, matching the temperature channel a
few lines above which already handles the sign correctly.

Fixes: 3904b28efb2c ("iio: gyro: Add driver for the MPU-3050 gyroscope")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4
Signed-off-by: Cong Nguyen <congnt264@gmail.com>
Reviewed-by: Linus Walleij <linusw@kernel.org>
Reviewed-by: Joshua Crofts <joshua.crofts1@gmail.com>
Reviewed-by: David Lechner <dlechner@baylibre.com>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/gyro/mpu3050-core.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/iio/gyro/mpu3050-core.c
+++ b/drivers/iio/gyro/mpu3050-core.c
@@ -356,7 +356,7 @@ static int mpu3050_read_raw(struct iio_d
 				goto out_read_raw_unlock;
 			}
 
-			*val = be16_to_cpu(raw_val);
+			*val = (s16)be16_to_cpu(raw_val);
 			ret = IIO_VAL_INT;
 
 			goto out_read_raw_unlock;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 275/556] iio: imu: st_lsm6dsx: Update enable mask when using sensor fusion
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (273 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 274/556] iio: gyro: mpu3050: fix sign of raw angular velocity readings Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 276/556] iio: light: apds9306: fix PM reference leak in apds9306_read_data() Greg Kroah-Hartman
                   ` (293 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Francesco Lavra, Lorenzo Bianconi,
	Stable, Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Francesco Lavra <flavra@baylibre.com>

commit 4a56c646e1bd4f22a2dcd65ef3723af957c651a9 upstream.

The enable_mask struct member keeps track of which sensors are enabled in
the IMU. When enabling and disabling the sensor fusion functionality, the
driver does not properly update this struct member. This prevents a correct
calculation of the number of samples that should be read from the hardware
FIFO; as a result, reads from the FIFO can be unnecessarily split into
multiple transactions, some of which can read past the FIFO length.

Fixes: cd4e1141bff8 ("iio: imu: st_lsm6dsx: Add support for rotation sensor")
Signed-off-by: Francesco Lavra <flavra@baylibre.com>
Acked-by: Lorenzo Bianconi <lorenzo@kernel.org>
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/imu/st_lsm6dsx/st_lsm6dsx_fusion.c |    5 +++++
 1 file changed, 5 insertions(+)

--- a/drivers/iio/imu/st_lsm6dsx/st_lsm6dsx_fusion.c
+++ b/drivers/iio/imu/st_lsm6dsx/st_lsm6dsx_fusion.c
@@ -112,6 +112,11 @@ int st_lsm6dsx_fusion_set_enable(struct
 		return err;
 	}
 
+	if (enable)
+		hw->enable_mask |= BIT(ST_LSM6DSX_ID_FUSION);
+	else
+		hw->enable_mask &= ~BIT(ST_LSM6DSX_ID_FUSION);
+
 	return st_lsm6dsx_fusion_page_disable(hw);
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 276/556] iio: light: apds9306: fix PM reference leak in apds9306_read_data()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (274 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 275/556] iio: imu: st_lsm6dsx: Update enable mask when using sensor fusion Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 277/556] iio: light: cm32181: return zero after writing calibscale Greg Kroah-Hartman
                   ` (292 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Moksh Panicker, Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Moksh Panicker <mokshpanicker.7@gmail.com>

commit d378fceaafd79e0dc59d3546bda251a3058062c0 upstream.

apds9306_read_data() calls pm_runtime_resume_and_get() but several
error paths return directly without calling pm_runtime_put_autosuspend(),
leaking the runtime PM reference and preventing the device from
autosuspending.

Use PM_RUNTIME_ACQUIRE_AUTOSUSPEND() and PM_RUNTIME_ACQUIRE_ERR() to
automatically handle runtime PM reference release on all return paths.

Fixes: 620d1e6c7a3f ("iio: light: Add support for APDS9306 Light Sensor")
Signed-off-by: Moksh Panicker <mokshpanicker.7@gmail.com>
Cc: stable@vger.kernel.org
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/light/apds9306.c |    8 +++-----
 1 file changed, 3 insertions(+), 5 deletions(-)

--- a/drivers/iio/light/apds9306.c
+++ b/drivers/iio/light/apds9306.c
@@ -469,9 +469,9 @@ static int apds9306_read_data(struct apd
 	int status = 0;
 	u8 buff[3];
 
-	ret = pm_runtime_resume_and_get(data->dev);
-	if (ret)
-		return ret;
+	PM_RUNTIME_ACQUIRE_AUTOSUSPEND(data->dev, pm);
+	if (PM_RUNTIME_ACQUIRE_ERR(&pm))
+		return PM_RUNTIME_ACQUIRE_ERR(&pm);
 
 	ret = regmap_field_read(rf->intg_time, &intg_time_idx);
 	if (ret)
@@ -535,8 +535,6 @@ static int apds9306_read_data(struct apd
 
 	*val = get_unaligned_le24(&buff);
 
-	pm_runtime_put_autosuspend(data->dev);
-
 	return 0;
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 277/556] iio: light: cm32181: return zero after writing calibscale
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (275 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 276/556] iio: light: apds9306: fix PM reference leak in apds9306_read_data() Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 278/556] iio: light: gp2ap002: Disable regulators on resume failure Greg Kroah-Hartman
                   ` (291 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Giorgi Tchankvetadze, Joshua Crofts,
	Stable, Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Giorgi Tchankvetadze <giorgi@tchankvetadze.com>

commit 8756acd30919a3e9f547ea4a1d4b7f7895f4d340 upstream.

The write_raw callback is documented to return 0 on success or a
negative error code.  However, the IIO_CHAN_INFO_CALIBSCALE case
returns 'val' (the user-supplied value) instead of 0.

Fix it by returning 0 on success, matching the behavior of other
calibscale implementations in the subsystem.

Fixes: 971672c0b3cc ("iio: add Capella CM32181 ambient light sensor driver.")
Signed-off-by: Giorgi Tchankvetadze <giorgi@tchankvetadze.com>
Reviewed-by: Joshua Crofts <joshua.crofts1@gmail.com>
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/light/cm32181.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/iio/light/cm32181.c
+++ b/drivers/iio/light/cm32181.c
@@ -368,7 +368,7 @@ static int cm32181_write_raw(struct iio_
 	switch (mask) {
 	case IIO_CHAN_INFO_CALIBSCALE:
 		cm32181->calibscale = val;
-		return val;
+		return 0;
 	case IIO_CHAN_INFO_INT_TIME:
 		ret = cm32181_write_als_it(cm32181, val2);
 		return ret;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 278/556] iio: light: gp2ap002: Disable regulators on resume failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (276 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 277/556] iio: light: cm32181: return zero after writing calibscale Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 279/556] iio: light: ltrf216a: fix runtime PM reference leak in error path Greg Kroah-Hartman
                   ` (290 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Laxman Acharya Padhya, Linus Walleij,
	Stable, Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Laxman Acharya Padhya <acharyalaxman8848@gmail.com>

commit a41000ba3a230bed1e422f283486ff8f77fe0d30 upstream.

If enabling VIO fails after VDD has been enabled, runtime resume
returns without disabling VDD. Likewise, if device reinitialization
fails, both supplies remain enabled. The runtime PM core keeps the
device suspended when its resume callback fails, so the supplies must
be restored to the suspended state.

Disable the supplies enabled by the callback before returning an error.

Fixes: 97d642e23037 ("iio: light: Add a driver for Sharp GP2AP002x00F")
Assisted-by: Codex:gpt-5
Signed-off-by: Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
Reviewed-by: Linus Walleij <linusw@kernel.org>
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/light/gp2ap002.c |   10 ++++++++--
 1 file changed, 8 insertions(+), 2 deletions(-)

--- a/drivers/iio/light/gp2ap002.c
+++ b/drivers/iio/light/gp2ap002.c
@@ -669,7 +669,7 @@ static int gp2ap002_runtime_resume(struc
 	ret = regulator_enable(gp2ap002->vio);
 	if (ret) {
 		dev_err(dev, "failed to enable VIO regulator in resume path\n");
-		return ret;
+		goto out_disable_vdd;
 	}
 
 	msleep(20);
@@ -677,13 +677,19 @@ static int gp2ap002_runtime_resume(struc
 	ret = gp2ap002_init(gp2ap002);
 	if (ret) {
 		dev_err(dev, "re-initialization failed\n");
-		return ret;
+		goto out_disable_vio;
 	}
 
 	/* Re-activate the IRQ */
 	enable_irq(gp2ap002->irq);
 
 	return 0;
+
+out_disable_vio:
+	regulator_disable(gp2ap002->vio);
+out_disable_vdd:
+	regulator_disable(gp2ap002->vdd);
+	return ret;
 }
 
 static DEFINE_RUNTIME_DEV_PM_OPS(gp2ap002_dev_pm_ops, gp2ap002_runtime_suspend,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 279/556] iio: light: ltrf216a: fix runtime PM reference leak in error path
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (277 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 278/556] iio: light: gp2ap002: Disable regulators on resume failure Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 280/556] iio: pressure: dps310: fix NULL pointer dereference on ACPI probe Greg Kroah-Hartman
                   ` (289 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Vidhu Sarwal, Joshua Crofts, Stable,
	Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Vidhu Sarwal <vidhu.linux@gmail.com>

commit c132aef0e757a39036b1d40faf0569f2e343b13e upstream.

ltrf216a_get_lux() acquires a runtime PM reference by calling
ltrf216a_set_power_state(data, true). However, if
ltrf216a_read_data() fails, the function returns immediately without
dropping the reference.

This leaves the runtime PM usage count unbalanced, preventing the device
from autosuspending after a failed read.

Fix this by releasing the runtime PM reference before returning from the
error path.

Fixes: 83f0bcd40d5c ("iio: light: Add support for ltrf216a sensor")
Signed-off-by: Vidhu Sarwal <vidhu.linux@gmail.com>
Reviewed-by: Joshua Crofts <joshua.crofts1@gmail.com>
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/light/ltrf216a.c |    3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

--- a/drivers/iio/light/ltrf216a.c
+++ b/drivers/iio/light/ltrf216a.c
@@ -247,11 +247,10 @@ static int ltrf216a_get_lux(struct ltrf2
 		return ret;
 
 	greendata = ltrf216a_read_data(data, LTRF216A_ALS_DATA_0);
+	ltrf216a_set_power_state(data, false);
 	if (greendata < 0)
 		return greendata;
 
-	ltrf216a_set_power_state(data, false);
-
 	lux = greendata * data->info->lux_multiplier * LTRF216A_WIN_FAC;
 
 	return lux;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 280/556] iio: pressure: dps310: fix NULL pointer dereference on ACPI probe
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (278 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 279/556] iio: light: ltrf216a: fix runtime PM reference leak in error path Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 281/556] iio: pressure: mpl115: Fix runtime PM cleanup Greg Kroah-Hartman
                   ` (288 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Rupesh Majhi, Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Rupesh Majhi <zoone.rupert@gmail.com>

commit 26e9213898fc949923188ef0aeea31fc87708836 upstream.

When the device is enumerated through its ACPI HID (IFX3100),
i2c_client_get_device_id() returns NULL: the ACPI-derived client name
does not match the driver's i2c_device_id table. dps310_probe() then
dereferences that NULL pointer in "iio->name = id->name" and crashes the
kernel during probe.

The IIO device name is always "dps310", so set it directly and drop the
now-unused device-id lookup.

Fixes: 72ff282819d0 ("iio: pressure: dps310: Add ACPI HID table")
Cc: stable@vger.kernel.org
Signed-off-by: Rupesh Majhi <zoone.rupert@gmail.com>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/pressure/dps310.c |    3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

--- a/drivers/iio/pressure/dps310.c
+++ b/drivers/iio/pressure/dps310.c
@@ -845,7 +845,6 @@ static const struct iio_info dps310_info
 
 static int dps310_probe(struct i2c_client *client)
 {
-	const struct i2c_device_id *id = i2c_client_get_device_id(client);
 	struct dps310_data *data;
 	struct iio_dev *iio;
 	int rc;
@@ -858,7 +857,7 @@ static int dps310_probe(struct i2c_clien
 	data->client = client;
 	mutex_init(&data->lock);
 
-	iio->name = id->name;
+	iio->name = DPS310_DEV_NAME;
 	iio->channels = dps310_channels;
 	iio->num_channels = ARRAY_SIZE(dps310_channels);
 	iio->info = &dps310_info;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 281/556] iio: pressure: mpl115: Fix runtime PM cleanup
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (279 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 280/556] iio: pressure: dps310: fix NULL pointer dereference on ACPI probe Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 282/556] iio: srf04: fix pm_runtime handling on probe error path Greg Kroah-Hartman
                   ` (287 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, jonathan.cameron, Can Peng

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Can Peng <pengcan@kylinos.cn>

commit 0b5e142ced4bcf20532da051934bd694d1bbd470 upstream.

mpl115_probe() enables runtime PM when a shutdown GPIO is present and
then returns the result of devm_iio_device_register(). If registration
fails, runtime PM remains enabled and autosuspend remains selected.

The same unmanaged runtime PM state is also left behind on driver
unbind, as the IIO device registration is managed but the runtime PM
setup is not.

Use devm_pm_runtime_enable() so runtime PM is disabled automatically on
probe failure and driver unbind, and check pm_runtime_set_active() so
setup errors are reported.

Set the autosuspend parameters before enabling runtime PM. Once probe
has completed, the driver core queues an idle request for the device, so
an explicit pm_runtime_get_noresume()/pm_runtime_put() pair is not
needed to start autosuspend.

Fixes: 0c3a333524a3 ("iio: pressure: mpl115: Implementing low power mode by shutdown gpio")
Cc: stable@vger.kernel.org
Suggested-by: jonathan.cameron@oss.qualcomm.com
Signed-off-by: Can Peng <pengcan@kylinos.cn>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/pressure/mpl115.c |   11 +++++++----
 1 file changed, 7 insertions(+), 4 deletions(-)

--- a/drivers/iio/pressure/mpl115.c
+++ b/drivers/iio/pressure/mpl115.c
@@ -203,9 +203,9 @@ int mpl115_probe(struct device *dev, con
 
 	if (data->shutdown) {
 		/* Enable runtime PM */
-		pm_runtime_get_noresume(dev);
-		pm_runtime_set_active(dev);
-		pm_runtime_enable(dev);
+		ret = pm_runtime_set_active(dev);
+		if (ret)
+			return ret;
 
 		/*
 		 * As the device takes 3 ms to come up with a fresh
@@ -215,7 +215,10 @@ int mpl115_probe(struct device *dev, con
 		 */
 		pm_runtime_set_autosuspend_delay(dev, 2000);
 		pm_runtime_use_autosuspend(dev);
-		pm_runtime_put(dev);
+
+		ret = devm_pm_runtime_enable(dev);
+		if (ret)
+			return ret;
 
 		dev_dbg(dev, "low-power mode enabled");
 	} else



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 282/556] iio: srf04: fix pm_runtime handling on probe error path
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (280 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 281/556] iio: pressure: mpl115: Fix runtime PM cleanup Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 283/556] iio: temperature: hid-sensor-temperature: switch to non-devm iio_device_register() Greg Kroah-Hartman
                   ` (286 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Cong Nguyen, Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Cong Nguyen <congnt264@gmail.com>

commit a40b2e7a17f26e38ab054363c9c7cde149588357 upstream.

When pm_runtime_set_active() fails during probe, the driver logs the
error and unregisters the IIO device, but then falls through and still
calls pm_runtime_enable() before returning the error.

Since probe returns an error, srf04_remove() is never called, so
runtime PM is left enabled without a matching pm_runtime_disable().
This leaks the enable and triggers an "Unbalanced pm_runtime_enable!"
warning on a subsequent bind of the device.

Return the error right after unregistering the IIO device so that
runtime PM is not enabled on the failure path.

Fixes: 2251157b335b ("iio: srf04: add power management feature")
Cc: stable@vger.kernel.org
Signed-off-by: Cong Nguyen <congnt264@gmail.com>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/proximity/srf04.c |    1 +
 1 file changed, 1 insertion(+)

--- a/drivers/iio/proximity/srf04.c
+++ b/drivers/iio/proximity/srf04.c
@@ -330,6 +330,7 @@ static int srf04_probe(struct platform_d
 		if (ret) {
 			dev_err(data->dev, "pm_runtime_set_active: %d\n", ret);
 			iio_device_unregister(indio_dev);
+			return ret;
 		}
 
 		pm_runtime_enable(data->dev);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 283/556] iio: temperature: hid-sensor-temperature: switch to non-devm iio_device_register()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (281 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 282/556] iio: srf04: fix pm_runtime handling on probe error path Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 284/556] iio: ti-ads7138: Disable STATS_EN bit while reading conversion results Greg Kroah-Hartman
                   ` (285 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Maxwell Doose, Andy Shevchenko,
	Sanjay Chitroda, Srinivas Pandruvada, Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sanjay Chitroda <sanjayembeddedse@gmail.com>

commit 967d066f5334740f656577bc51c381a1bb707b61 upstream.

Avoid using devm_iio_device_register(), as this driver requires explicit
error handling and teardown ordering.

With devm_iio_device_register(), IIO device remains registered until the
devres cleanup phase. However, driver's remove() callback removes the
sensor hub callback and trigger support. This can create a race window
where IIO device is still visible and read_raw() requests are issued.
These requests might call sensor_hub_input_attr_get_raw_value(), which
waits up to 5 seconds for a response from the sensor hub callback that
has already been removed.

Add an explicit iio_device_unregister() call in the teardown path to
ensure deterministic cleanup, so that userspace can no longer access the
device once backend resources begin to be dismantled.

Fixes: 59d0f2da3569 ("iio: hid: Add temperature sensor support")
Cc: stable@vger.kernel.org
Reviewed-by: Maxwell Doose <m32285159@gmail.com>
Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com>
Signed-off-by: Sanjay Chitroda <sanjayembeddedse@gmail.com>
Acked-by: Srinivas Pandruvada <srinivas.pandruvada@linux.intel.com>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/temperature/hid-sensor-temperature.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/drivers/iio/temperature/hid-sensor-temperature.c
+++ b/drivers/iio/temperature/hid-sensor-temperature.c
@@ -243,7 +243,7 @@ static int hid_temperature_probe(struct
 	if (ret)
 		goto error_remove_trigger;
 
-	ret = devm_iio_device_register(indio_dev->dev.parent, indio_dev);
+	ret = iio_device_register(indio_dev);
 	if (ret)
 		goto error_remove_callback;
 
@@ -263,6 +263,7 @@ static void hid_temperature_remove(struc
 	struct iio_dev *indio_dev = platform_get_drvdata(pdev);
 	struct temperature_state *temp_st = iio_priv(indio_dev);
 
+	iio_device_unregister(indio_dev);
 	sensor_hub_remove_callback(hsdev, HID_USAGE_SENSOR_TEMPERATURE);
 	hid_sensor_remove_trigger(indio_dev, &temp_st->common_attributes);
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 284/556] iio: ti-ads7138: Disable STATS_EN bit while reading conversion results
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (282 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 283/556] iio: temperature: hid-sensor-temperature: switch to non-devm iio_device_register() Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 285/556] iio: light: opt4060: Reject integration times with a non-zero seconds part Greg Kroah-Hartman
                   ` (284 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Paul Geurts, David Lechner, Stable,
	Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Paul Geurts <paul.geurts@prodrive-technologies.com>

commit bcb721c1bcb02ab225b3937bf131a0bc6fc1fecd upstream.

There is a data race in reading the STATS registers, resulting in wrong
data being read. When the data in the RECENT register switches between
0x24F0 and 0x2500, occasionally value 0x2400 or 0x25F0 is read. This
happens when the value is updated in between reading MSB and LSB.

The data sheet says: "Until a new conversion result is available,
previous values can be read from the statistics registers. Before
reading the statistics registers, set STATS_EN to 0 to prevent any
updates to this register block." As the STATS_EN is currently not
cleared, the values of the stats registers might change mid read,
giving faulty values.

Disable the STATS_EN bit before reading one of the statistics registers to
make sure the device does not update the register mid read. This is
applicable to registers MAX_CHn_xSB, MIN_CHn_xSB and RECENT_CHn_xSB.

This means reading one of the statistics registers resets the MAX and
MIN registers. This is unfortunate, but necessary to get correct data
from the device.

Signed-off-by: Paul Geurts <paul.geurts@prodrive-technologies.com>
Fixes: 024b08fee342 ("iio: adc: Add driver for ADS7128 / ADS7138")
Reviewed-by: David Lechner <dlechner@baylibre.com>
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/adc/ti-ads7138.c |   42 +++++++++++++++++++++++++++++++++---------
 1 file changed, 33 insertions(+), 9 deletions(-)

--- a/drivers/iio/adc/ti-ads7138.c
+++ b/drivers/iio/adc/ti-ads7138.c
@@ -227,6 +227,26 @@ static int ads7138_osr_to_bits(int osr)
 	return -EINVAL;
 }
 
+static int ads7138_read_statistics(const struct i2c_client *client, u8 reg,
+				   u8 *out_values, u8 length)
+{
+	int ret;
+
+	/* Disable statistics update so the value is not updated mid read */
+	ret = ads7138_i2c_clear_bit(client, ADS7138_REG_GENERAL_CFG,
+				    ADS7138_GENERAL_CFG_STATS_EN);
+	if (ret)
+		return ret;
+
+	ret = ads7138_i2c_read_block(client, reg, out_values, length);
+	if (ret)
+		return ret;
+
+	/* Enable statistics update after read */
+	return ads7138_i2c_set_bit(client, ADS7138_REG_GENERAL_CFG,
+				   ADS7138_GENERAL_CFG_STATS_EN);
+}
+
 static int ads7138_read_raw(struct iio_dev *indio_dev,
 			    struct iio_chan_spec const *chan, int *val,
 			    int *val2, long mask)
@@ -236,28 +256,32 @@ static int ads7138_read_raw(struct iio_d
 	u8 values[2];
 
 	switch (mask) {
+	/*
+	 * Reading the statistics registers reinitializes them. This is
+	 * unfortunate but necessary to prevent data races.
+	 */
 	case IIO_CHAN_INFO_RAW:
-		ret = ads7138_i2c_read_block(data->client,
-					     ADS7138_REG_RECENT_LSB_CH(chan->channel),
-					     values, ARRAY_SIZE(values));
+		ret = ads7138_read_statistics(data->client,
+					      ADS7138_REG_RECENT_LSB_CH(chan->channel),
+					      values, ARRAY_SIZE(values));
 		if (ret)
 			return ret;
 
 		*val = get_unaligned_le16(values);
 		return IIO_VAL_INT;
 	case IIO_CHAN_INFO_PEAK:
-		ret = ads7138_i2c_read_block(data->client,
-					     ADS7138_REG_MAX_LSB_CH(chan->channel),
-					     values, ARRAY_SIZE(values));
+		ret = ads7138_read_statistics(data->client,
+					      ADS7138_REG_MAX_LSB_CH(chan->channel),
+					      values, ARRAY_SIZE(values));
 		if (ret)
 			return ret;
 
 		*val = get_unaligned_le16(values);
 		return IIO_VAL_INT;
 	case IIO_CHAN_INFO_TROUGH:
-		ret = ads7138_i2c_read_block(data->client,
-					     ADS7138_REG_MIN_LSB_CH(chan->channel),
-					     values, ARRAY_SIZE(values));
+		ret = ads7138_read_statistics(data->client,
+					      ADS7138_REG_MIN_LSB_CH(chan->channel),
+					      values, ARRAY_SIZE(values));
 		if (ret)
 			return ret;
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 285/556] iio: light: opt4060: Reject integration times with a non-zero seconds part
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (283 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 284/556] iio: ti-ads7138: Disable STATS_EN bit while reading conversion results Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 286/556] iio: light: opt4060: Fix incorrect register name in threshold read error message Greg Kroah-Hartman
                   ` (283 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Vidhu Sarwal, Stable,
	Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Vidhu Sarwal <vidhu.linux@gmail.com>

commit b7e6e9af0d723afdec92364d5e7e064eeef44c8e upstream.

When setting the integration time, opt4060_write_raw() only uses
val2 and ignores val. As a result, a write such as 1.000600 is
accepted and programmed as 600 us, silently discarding the whole
seconds part.

Since all supported integration times are less than one second, any
non-zero val represents an invalid input. Reject such values instead
of silently accepting them.

Fixes: 0c6db4506ad0 ("iio: light: Add support for TI OPT4060 color sensor")
Signed-off-by: Vidhu Sarwal <vidhu.linux@gmail.com>
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/light/opt4060.c |    3 +++
 1 file changed, 3 insertions(+)

--- a/drivers/iio/light/opt4060.c
+++ b/drivers/iio/light/opt4060.c
@@ -632,6 +632,9 @@ static int opt4060_write_raw(struct iio_
 
 	switch (mask) {
 	case IIO_CHAN_INFO_INT_TIME:
+		if (val)
+			return -EINVAL;
+
 		int_time = opt4060_als_time_to_index(val2);
 		if (int_time < 0)
 			return int_time;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 286/556] iio: light: opt4060: Fix incorrect register name in threshold read error message
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (284 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 285/556] iio: light: opt4060: Reject integration times with a non-zero seconds part Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 287/556] iio: light: opt4001: Fix power down clearing bits of the wrong register Greg Kroah-Hartman
                   ` (282 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Vidhu Sarwal, Stable,
	Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Vidhu Sarwal <vidhu.linux@gmail.com>

commit ad367638212a9f2495ecfa59c886f0cfb7934e9c upstream.

opt4060_get_thresholds() correctly reads OPT4060_THRESHOLD_HIGH, but
logs "Failed to read THRESHOLD_LOW." if the read fails. This is a
copy-and-paste mistake, as the preceding low-threshold read already uses
the correct error message.

Update the error message to reference OPT4060_THRESHOLD_HIGH.

Fixes: 0c6db4506ad0 ("iio: light: Add support for TI OPT4060 color sensor")
Signed-off-by: Vidhu Sarwal <vidhu.linux@gmail.com>
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/light/opt4060.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/iio/light/opt4060.c
+++ b/drivers/iio/light/opt4060.c
@@ -808,7 +808,7 @@ static int opt4060_get_thresholds(struct
 
 	ret = regmap_read(chip->regmap, OPT4060_THRESHOLD_HIGH, &regval);
 	if (ret) {
-		dev_err(chip->dev, "Failed to read THRESHOLD_LOW.\n");
+		dev_err(chip->dev, "Failed to read THRESHOLD_HIGH.\n");
 		return ret;
 	}
 	*th_hi = opt4060_calc_val_from_th_reg(regval);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 287/556] iio: light: opt4001: Fix power down clearing bits of the wrong register
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (285 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 286/556] iio: light: opt4060: Fix incorrect register name in threshold read error message Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 288/556] iio: light: opt4001: Fix incompatible pointer type passed to div_u64_rem() Greg Kroah-Hartman
                   ` (281 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jonathan Cameron, Nikhil Gautam,
	Andy Shevchenko, Stable, Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nikhil Gautam <nikhilgtr@gmail.com>

commit 3b2cd82c524c75a2173f2e3f874652a75f81cd1d upstream.

opt4001_power_down() intends to clear the operating mode bits in the
CTRL register but reads OPT4001_DEVICE_ID instead of OPT4001_CTRL, so
the value written back to CTRL contains device ID bits rather than the
current configuration.

Fix and simplify this by using regmap_clear_bits() on the CTRL register
directly in the devm action, and drop opt4001_power_down() which has no
other users.

Suggested-by: Jonathan Cameron <jic23@kernel.org>
Fixes: 9a9608418292 ("iio: light: Add support for TI OPT4001 light sensor")
Signed-off-by: Nikhil Gautam <nikhilgtr@gmail.com>
Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com>
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/light/opt4001.c |   27 ++++-----------------------
 1 file changed, 4 insertions(+), 23 deletions(-)

--- a/drivers/iio/light/opt4001.c
+++ b/drivers/iio/light/opt4001.c
@@ -222,33 +222,14 @@ static int opt4001_set_conf(struct opt40
 	return ret;
 }
 
-static int opt4001_power_down(struct opt4001_chip *chip)
-{
-	struct device *dev = &chip->client->dev;
-	int ret;
-	unsigned int reg;
-
-	ret = regmap_read(chip->regmap, OPT4001_DEVICE_ID, &reg);
-	if (ret) {
-		dev_err(dev, "Failed to read configuration\n");
-		return ret;
-	}
-
-	/* MODE_OFF is 0x0 so just set bits to 0 */
-	reg &= ~OPT4001_CTRL_OPER_MODE_MASK;
-
-	ret = regmap_write(chip->regmap, OPT4001_CTRL, reg);
-	if (ret)
-		dev_err(dev, "Failed to set configuration to power down\n");
-
-	return ret;
-}
-
 static void opt4001_chip_off_action(void *data)
 {
 	struct opt4001_chip *chip = data;
+	int ret;
 
-	opt4001_power_down(chip);
+	ret = regmap_clear_bits(chip->regmap, OPT4001_CTRL, OPT4001_CTRL_OPER_MODE_MASK);
+	if (ret)
+		dev_err(&chip->client->dev, "Failed to power down\n");
 }
 
 static const struct iio_chan_spec opt4001_channels[] = {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 288/556] iio: light: opt4001: Fix incompatible pointer type passed to div_u64_rem()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (286 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 287/556] iio: light: opt4001: Fix power down clearing bits of the wrong register Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 289/556] iio: light: opt4001: Reject integration times with a non-zero seconds part Greg Kroah-Hartman
                   ` (280 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Nikhil Gautam, Andy Shevchenko,
	Stable, Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nikhil Gautam <nikhilgtr@gmail.com>

commit afa28741c9a2cf6edb2e41e25ff146a562160bb3 upstream.

div_u64_rem() takes a u32 * for the remainder but is passed val2, which
is an int *. There is no functional impact as int and u32 have the same
size and representation on all supported architectures and the remainder
is always smaller than the divisor, so it fits in the positive range of
int. Fix the type mismatch by using a local u32 for the remainder and
assigning the result to *val2.

Fixes: 9a9608418292 ("iio: light: Add support for TI OPT4001 light sensor")
Signed-off-by: Nikhil Gautam <nikhilgtr@gmail.com>
Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com>
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/light/opt4001.c |    5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

--- a/drivers/iio/light/opt4001.c
+++ b/drivers/iio/light/opt4001.c
@@ -173,6 +173,7 @@ static int opt4001_read_lux_value(struct
 	u8 crc;
 	u8 calc_crc;
 	u64 lux_raw;
+	u32 rem;
 	int ret;
 
 	ret = regmap_read(chip->regmap, OPT4001_LIGHT1_MSB, &light1);
@@ -199,8 +200,8 @@ static int opt4001_read_lux_value(struct
 
 	lux_raw = lux_raw << exp;
 	lux_raw = lux_raw * chip->chip_info->mul;
-	*val = div_u64_rem(lux_raw, chip->chip_info->div, val2);
-	*val2 = *val2 * 100;
+	*val = div_u64_rem(lux_raw, chip->chip_info->div, &rem);
+	*val2 = rem * 100;
 
 	return IIO_VAL_INT_PLUS_NANO;
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 289/556] iio: light: opt4001: Reject integration times with a non-zero seconds part
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (287 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 288/556] iio: light: opt4001: Fix incompatible pointer type passed to div_u64_rem() Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 290/556] iio: light: opt4001: Fix reversed GENMASK() arguments in fault count mask Greg Kroah-Hartman
                   ` (279 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Nikhil Gautam, Andy Shevchenko,
	Stable, Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nikhil Gautam <nikhilgtr@gmail.com>

commit d0f21621f8b2b46661ea066d20705dbf7253db87 upstream.

opt4001_write_raw() only looks at val2 when setting the integration
time, so a write such as 1.000600 is silently accepted as 600 us.
Return -EINVAL if val is non-zero.

Fixes: 9a9608418292 ("iio: light: Add support for TI OPT4001 light sensor")
Signed-off-by: Nikhil Gautam <nikhilgtr@gmail.com>
Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com>
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/light/opt4001.c |    3 +++
 1 file changed, 3 insertions(+)

--- a/drivers/iio/light/opt4001.c
+++ b/drivers/iio/light/opt4001.c
@@ -269,6 +269,9 @@ static int opt4001_write_raw(struct iio_
 
 	switch (mask) {
 	case IIO_CHAN_INFO_INT_TIME:
+		if (val)
+			return -EINVAL;
+
 		int_time = opt4001_als_time_to_index(val2);
 		if (int_time < 0)
 			return int_time;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 290/556] iio: light: opt4001: Fix reversed GENMASK() arguments in fault count mask
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (288 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 289/556] iio: light: opt4001: Reject integration times with a non-zero seconds part Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 291/556] KVM: PPC: Book3S HV: Validate arch_compat against host compatibility mode Greg Kroah-Hartman
                   ` (278 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Nikhil Gautam, Andy Shevchenko,
	Stable, Jonathan Cameron

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nikhil Gautam <nikhilgtr@gmail.com>

commit d64bfd9f3352b9d9bdeca06de1a0a1c1bd47b896 upstream.

GENMASK(h, l) requires h >= l, but OPT4001_CTRL_FAULT_COUNT is defined
as GENMASK(0, 1). The define is currently unused so there is no
functional impact, but fix it before anyone builds on it, and add the
_MASK suffix for consistency with the neighbouring definitions.

Fixes: 9a9608418292 ("iio: light: Add support for TI OPT4001 light sensor")
Signed-off-by: Nikhil Gautam <nikhilgtr@gmail.com>
Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com>
Cc: <Stable@vger.kernel.org>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/iio/light/opt4001.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/iio/light/opt4001.c
+++ b/drivers/iio/light/opt4001.c
@@ -39,7 +39,7 @@
 #define OPT4001_CTRL_OPER_MODE_MASK      GENMASK(5, 4)
 #define OPT4001_CTRL_LATCH_MASK          GENMASK(3, 3)
 #define OPT4001_CTRL_INT_POL_MASK        GENMASK(2, 2)
-#define OPT4001_CTRL_FAULT_COUNT         GENMASK(0, 1)
+#define OPT4001_CTRL_FAULT_COUNT_MASK    GENMASK(1, 0)
 
 /* OPT4001 constants */
 #define OPT4001_DEVICE_ID_VAL            0x121



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 291/556] KVM: PPC: Book3S HV: Validate arch_compat against host compatibility mode
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (289 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 290/556] iio: light: opt4001: Fix reversed GENMASK() arguments in fault count mask Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 292/556] KVM: nVMX: Always flush vpid02 on first use Greg Kroah-Hartman
                   ` (277 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Vaibhav Jain, Anushree Mathur,
	Gautam Menghani, Ritesh Harjani (IBM),
	Mukesh Kumar Chaurasiya (IBM), Amit Machhiwal,
	Madhavan Srinivasan

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Amit Machhiwal <amachhiw@linux.ibm.com>

commit 884ea0283f4effac97ee8f451464a7d1be480d7c upstream.

On IBM POWER systems, newer processor generations can operate in
compatibility modes corresponding to earlier generations. This becomes
relevant for nested virtualization, where nested KVM guests may need to
run with a specific processor compatibility level.

Currently, when running a nested KVM guest (L2) inside a Power11 pSeries
logical partition (L1) booted in Power10 compatibility mode, the guest
fails to boot while setting 'arch_compat'. This happens because the CPU
class is derived from the hardware PVR (via mfspr()), which reflects the
physical processor generation (Power11), rather than the effective
compatibility mode (Power10).

As a result, userspace may request a Power11 arch_compat for the L2
guest. However, the L1 partition, running in Power10 compatibility, has
only negotiated support up to Power10 with the Power Hypervisor (L0).
When H_GUEST_SET_STATE is invoked with a Power11 Logical PVR, the
hypervisor rejects the request, leading to a late guest boot failure:

  KVM-NESTEDv2: couldn't set guest wide elements
  [..KVM reg dump..]

This situation should be detected earlier and rejected by KVM. Without
proper validation, if userspace ignores the error, the guest may continue
to boot in Power11 raw mode on a Power10 compatibility host, which should
not be allowed.

Introduce a validation mechanism that detects unsupported arch_compat
values early in the guest initialization path. When an unsupported
arch_compat is requested (e.g., Power11 on a Power10 compatibility mode
host), kvmppc_set_arch_compat() uses cpu_has_feature(CPU_FTR_P11_PVR) to
detect the mismatch and sets arch_compat to PVR_ARCH_INVALID (0xffffffff).
This sentinel value is architecturally safe: PAPR specifies that valid
logical PVR values must have 0x0f as the first byte, ensuring 0xffffffff
lies permanently outside the specification-defined range. Setting this
value triggers kvmppc_sanity_check() to mark the vCPU as invalid by
setting vcpu->arch.sane to false. On the next vCPU run, kvmppc_vcpu_run_hv()
checks this flag and returns -EINVAL, preventing the guest from running
with an invalid processor compatibility configuration.

With this, when a Power11 arch_compat is requested on a Power10
compatibility mode host, the guest fails early during boot with:

  error: kvm run failed Invalid argument

This provides a much clearer failure mode compared to the previous
behavior where the guest could boot in Power11 raw mode (if userspace
ignored the error) or fail late during H_GUEST_SET_STATE.

Suggested-by: Vaibhav Jain <vaibhav@linux.ibm.com>
Reviewed-by: Vaibhav Jain <vaibhav@linux.ibm.com>
Tested-by: Anushree Mathur <anushree.mathur@linux.ibm.com>
Acked-by: Gautam Menghani <gautam@linux.ibm.com>
Cc: stable@vger.kernel.org # v6.13+
Reviewed-by: Ritesh Harjani (IBM) <ritesh.list@gmail.com>
Reviewed-by: Mukesh Kumar Chaurasiya (IBM) <mkchauras@gmail.com>
Signed-off-by: Amit Machhiwal <amachhiw@linux.ibm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Link: https://patch.msgid.link/20260714175432.86388-1-amachhiw@linux.ibm.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/powerpc/include/asm/reg.h |   12 ++++++++++++
 arch/powerpc/kvm/book3s_hv.c   |   15 ++++++++++++++-
 arch/powerpc/kvm/powerpc.c     |    6 ++++++
 3 files changed, 32 insertions(+), 1 deletion(-)

--- a/arch/powerpc/include/asm/reg.h
+++ b/arch/powerpc/include/asm/reg.h
@@ -1357,6 +1357,18 @@
 #define PVR_ARCH_31	0x0f000006
 #define PVR_ARCH_31_P11	0x0f000007
 
+/*
+ * Kernel-internal sentinel for invalid processor compatibility modes.
+ * PAPR specifies that the first byte of a valid logical PVR value is
+ * 0x0f. So 0xffffffff lies permanently outside the PAPR-defined range
+ * and is safe to repurpose. KVM stores it in vcpu->arch.arch_compat
+ * when userspace requests an unsupported compatibility mode (e.g.,
+ * Power11 PVR on a Power11 host booted in Power10 compat).
+ * kvmppc_sanity_check() detects this and prevents the vCPU from
+ * running with an unsupported arch_compat.
+ */
+#define PVR_ARCH_INVALID	0xffffffff
+
 /* Macros for setting and retrieving special purpose registers */
 #ifndef __ASSEMBLER__
 
--- a/arch/powerpc/kvm/book3s_hv.c
+++ b/arch/powerpc/kvm/book3s_hv.c
@@ -446,7 +446,19 @@ static int kvmppc_set_arch_compat(struct
 			guest_pcr_bit = PCR_ARCH_300;
 			break;
 		case PVR_ARCH_31:
+			guest_pcr_bit = PCR_ARCH_31;
+			break;
 		case PVR_ARCH_31_P11:
+			/*
+			 * Need to check this for ISA 3.1, as Power10 and
+			 * Power11 share the same PCR. For any subsequent ISA
+			 * versions, this will be taken care of by the guest vs
+			 * host PCR comparison below.
+			 */
+			if (!cpu_has_feature(CPU_FTR_P11_PVR)) {
+				arch_compat = PVR_ARCH_INVALID;
+				goto out;
+			}
 			guest_pcr_bit = PCR_ARCH_31;
 			break;
 		default:
@@ -469,6 +481,7 @@ static int kvmppc_set_arch_compat(struct
 			return -EINVAL;
 	}
 
+out:
 	spin_lock(&vc->lock);
 	vc->arch_compat = arch_compat;
 	kvmhv_nestedv2_mark_dirty(vcpu, KVMPPC_GSID_LOGICAL_PVR);
@@ -479,7 +492,7 @@ static int kvmppc_set_arch_compat(struct
 	vc->pcr = (host_pcr_bit - guest_pcr_bit) | PCR_MASK;
 	spin_unlock(&vc->lock);
 
-	return 0;
+	return kvmppc_sanity_check(vcpu);
 }
 
 static void kvmppc_dump_regs(struct kvm_vcpu *vcpu)
--- a/arch/powerpc/kvm/powerpc.c
+++ b/arch/powerpc/kvm/powerpc.c
@@ -258,6 +258,12 @@ int kvmppc_sanity_check(struct kvm_vcpu
 	if (!vcpu->arch.pvr)
 		goto out;
 
+#if defined(CONFIG_KVM_BOOK3S_HV_POSSIBLE)
+	if (vcpu->arch.vcore &&
+	    vcpu->arch.vcore->arch_compat == PVR_ARCH_INVALID)
+		goto out;
+#endif
+
 	/* PAPR only works with book3s_64 */
 	if ((vcpu->arch.cpu_type != KVM_CPU_3S_64) && vcpu->arch.papr_enabled)
 		goto out;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 292/556] KVM: nVMX: Always flush vpid02 on first use
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (290 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 291/556] KVM: PPC: Book3S HV: Validate arch_compat against host compatibility mode Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 293/556] KVM: nVMX: Decouple INVVPID operand checks from flushing of vpid02 Greg Kroah-Hartman
                   ` (276 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yosry Ahmed, Kai Huang, Jim Mattson,
	Sean Christopherson

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yosry Ahmed <yosry@kernel.org>

commit f0772389413dce9657c7d6950abf3edbbd511356 upstream.

Make sure vpid02 is always flushed on first use by setting last_vpid=0
when allocating vpid02.  nested_vmx_transition_tlb_flush() will always
detect a VPID change on first VM-Enter after VMXON, because VPID=0 in
vmcs12 is not allowed if L1 enables VPID.

This avoids using stale TLB entries from a previous lifetime of the
VPID, that might have been associated with a different vCPU (or a
completely different VM).

Note that last_vpid is already being initialized as 0 when the vCPU is
created, but it is not reset when vpid02 is freed on VMXOFF. Hence, the
problem can only occur if L1 does VMXOFF -> VMXON, runs an L2, and KVM
happens to reuse a VPID that has TLB entries on the physical CPU.

Cc: stable@vger.kernel.org
Signed-off-by: Yosry Ahmed <yosry@kernel.org>
Reviewed-by: Kai Huang <kai.huang@intel.com>
Reviewed-by: Jim Mattson <jmattson@google.com>
Link: https://patch.msgid.link/20260616214652.2157032-2-yosry@kernel.org
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/x86/kvm/vmx/nested.c |   10 ++++++++++
 1 file changed, 10 insertions(+)

--- a/arch/x86/kvm/vmx/nested.c
+++ b/arch/x86/kvm/vmx/nested.c
@@ -1326,6 +1326,9 @@ static void nested_vmx_transition_tlb_fl
 	 * is the VPID incorporated into the MMU context.  I.e. KVM must assume
 	 * that the new vpid12 has never been used and thus represents a new
 	 * guest ASID that cannot have entries in the TLB.
+	 *
+	 * Note, last_vpid is initialized as 0, so the first nested VM-Enter
+	 * after VMXON will always flush the TLB to avoid using stale entries.
 	 */
 	if (is_vmenter && vmcs12->virtual_processor_id != vmx->nested.last_vpid) {
 		vmx->nested.last_vpid = vmcs12->virtual_processor_id;
@@ -5432,6 +5435,13 @@ static int enter_vmx_operation(struct kv
 
 	vmx->nested.vpid02 = allocate_vpid();
 
+	/*
+	 * Clear last_vpid to ensure that the VPID is flushed on the first
+	 * nested VM-Enter. Otherwise, stale TLB entries from a previous life of
+	 * the VPID (e.g. different vCPU or even different VM) could be used.
+	 */
+	vmx->nested.last_vpid = 0;
+
 	vmx->nested.vmcs02_initialized = false;
 	vmx->nested.vmxon = true;
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 293/556] KVM: nVMX: Decouple INVVPID operand checks from flushing of vpid02
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (291 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 292/556] KVM: nVMX: Always flush vpid02 on first use Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 294/556] KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit Greg Kroah-Hartman
                   ` (275 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yosry Ahmed, Kai Huang,
	Sean Christopherson

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sean Christopherson <seanjc@google.com>

commit 32912404b4b1ee98400744941c78f019a63d6e8f upstream.

Separate the INVVPID operand checks from the actual flushing of vpid02 so
the flushing can be adjusted to do the right thing when vmcs02  was last
loaded on a different pCPU, without having to duplicate the logic across
multiple case-statements.

Opportunistically let the VM-Fail paths poke out past 80 chars.

No functional change intended.

Cc: stable@vger.kernel.org
Signed-off-by: Yosry Ahmed <yosry@kernel.org>
Reviewed-by: Kai Huang <kai.huang@intel.com>
Link: https://patch.msgid.link/20260616214652.2157032-3-yosry@kernel.org
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/x86/kvm/vmx/nested.c |   43 +++++++++++++------------------------------
 1 file changed, 13 insertions(+), 30 deletions(-)

--- a/arch/x86/kvm/vmx/nested.c
+++ b/arch/x86/kvm/vmx/nested.c
@@ -6069,7 +6069,6 @@ static int handle_invvpid(struct kvm_vcp
 		u64 vpid;
 		u64 gla;
 	} operand;
-	u16 vpid02;
 	int r, gpr_index;
 
 	if (!(vmx->nested.msrs.secondary_ctls_high &
@@ -6104,8 +6103,15 @@ static int handle_invvpid(struct kvm_vcp
 		return kvm_handle_memory_failure(vcpu, r, &e);
 
 	if (operand.vpid >> 16)
-		return nested_vmx_fail(vcpu,
-			VMXERR_INVALID_OPERAND_TO_INVEPT_INVVPID);
+		return nested_vmx_fail(vcpu, VMXERR_INVALID_OPERAND_TO_INVEPT_INVVPID);
+
+	if (type != VMX_VPID_EXTENT_ALL_CONTEXT && !operand.vpid)
+		return nested_vmx_fail(vcpu, VMXERR_INVALID_OPERAND_TO_INVEPT_INVVPID);
+
+	/* LAM doesn't apply to addresses that are inputs to TLB invalidation. */
+	if (type == VMX_VPID_EXTENT_INDIVIDUAL_ADDR &&
+	    is_noncanonical_invlpg_address(operand.gla, vcpu))
+		return nested_vmx_fail(vcpu, VMXERR_INVALID_OPERAND_TO_INVEPT_INVVPID);
 
 	/*
 	 * Always flush the effective vpid02, i.e. never flush the current VPID
@@ -6113,33 +6119,10 @@ static int handle_invvpid(struct kvm_vcp
 	 * VMCS, and so whether or not the current vmcs12 has VPID enabled is
 	 * irrelevant (and there may not be a loaded vmcs12).
 	 */
-	vpid02 = nested_get_vpid02(vcpu);
-	switch (type) {
-	case VMX_VPID_EXTENT_INDIVIDUAL_ADDR:
-		/*
-		 * LAM doesn't apply to addresses that are inputs to TLB
-		 * invalidation.
-		 */
-		if (!operand.vpid ||
-		    is_noncanonical_invlpg_address(operand.gla, vcpu))
-			return nested_vmx_fail(vcpu,
-				VMXERR_INVALID_OPERAND_TO_INVEPT_INVVPID);
-		vpid_sync_vcpu_addr(vpid02, operand.gla);
-		break;
-	case VMX_VPID_EXTENT_SINGLE_CONTEXT:
-	case VMX_VPID_EXTENT_SINGLE_NON_GLOBAL:
-		if (!operand.vpid)
-			return nested_vmx_fail(vcpu,
-				VMXERR_INVALID_OPERAND_TO_INVEPT_INVVPID);
-		vpid_sync_context(vpid02);
-		break;
-	case VMX_VPID_EXTENT_ALL_CONTEXT:
-		vpid_sync_context(vpid02);
-		break;
-	default:
-		WARN_ON_ONCE(1);
-		return kvm_skip_emulated_instruction(vcpu);
-	}
+	if (type == VMX_VPID_EXTENT_INDIVIDUAL_ADDR)
+		vpid_sync_vcpu_addr(nested_get_vpid02(vcpu), operand.gla);
+	else
+		vpid_sync_context(nested_get_vpid02(vcpu));
 
 	/*
 	 * Sync the shadow page tables if EPT is disabled, L1 is invalidating



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 294/556] KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (292 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 293/556] KVM: nVMX: Decouple INVVPID operand checks from flushing of vpid02 Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 295/556] KVM: nVMX: Service local TLB flushes on failed nested VM-Enter Greg Kroah-Hartman
                   ` (274 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Yosry Ahmed, Sean Christopherson

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sean Christopherson <seanjc@google.com>

commit 11722439fb206c88e6f31be54173efa9880b4ccb upstream.

Always check and clear KVM_REQ_GET_NESTED_STATE_PAGES when emulating a
nested VM-Exit to ensure the request is cleared, even when KVM was built
with CONFIG_KVM_HYPERV=n, as KVM subtly relies on the "check" to clear
the flag and thus avoid double-mapping the vmcs12 pages, e.g. if KVM
manages to bail from VM-Enter without processing the request, and then
emulates VMLAUNCH or VMRESUME.

Fixes: b4f69df0f65e ("KVM: x86: Make Hyper-V emulation optional")
Cc: stable@vger.kernel.org
Reported-by: Yosry Ahmed <yosry@kernel.org>
Reviewed-by: Yosry Ahmed <yosry@kernel.org>
Link: https://patch.msgid.link/20260724004757.131420-2-seanjc@google.com
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/x86/kvm/vmx/nested.c |    5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

--- a/arch/x86/kvm/vmx/nested.c
+++ b/arch/x86/kvm/vmx/nested.c
@@ -5076,8 +5076,9 @@ void __nested_vmx_vmexit(struct kvm_vcpu
 	/* trying to cancel vmlaunch/vmresume is a bug */
 	kvm_warn_on_nested_run_pending(vcpu);
 
-#ifdef CONFIG_KVM_HYPERV
+	/* Note, "checking" the request also clears the request. */
 	if (kvm_check_request(KVM_REQ_GET_NESTED_STATE_PAGES, vcpu)) {
+#ifdef CONFIG_KVM_HYPERV
 		/*
 		 * KVM_REQ_GET_NESTED_STATE_PAGES is also used to map
 		 * Enlightened VMCS after migration and we still need to
@@ -5085,8 +5086,8 @@ void __nested_vmx_vmexit(struct kvm_vcpu
 		 * the first L2 run.
 		 */
 		(void)nested_get_evmcs_page(vcpu);
-	}
 #endif
+	}
 
 	/* Service pending TLB flush requests for L2 before switching to L1. */
 	kvm_service_local_tlb_flush_requests(vcpu);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 295/556] KVM: nVMX: Service local TLB flushes on failed nested VM-Enter
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (293 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 294/556] KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 296/556] KVM: nVM: Ensure INVVPID is emulated on the correct physical CPU Greg Kroah-Hartman
                   ` (273 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sean Christopherson, Yosry Ahmed,
	Sashiko

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yosry Ahmed <yosry@kernel.org>

commit 05a0b701d1089fb57beeb8982f23c3bbafe0fa8b upstream.

KVM services local TLB flushes on "full" nested VM-Exits (through
__nested_vmx_vmexit()), but not if a nested VM-Enter fails (e.g. due to
failed VMCS checks in nested_vmx_enter_non_root_mode()).

However, it is possible that KVM had queued TLB flushes that need to be
performed, even if the nested VM-Enter was not successful. For example,
if VPID is disabled for L2 (via nested_vmx_transition_tlb_flush(), or if
via the MSR load lists, as the SDM says:

  If any MSR is being loaded in such a way that would architecturally
  require a TLB flush, the TLBs are updated so that, after VM entry, the
  logical processor will not use any translations that were cached before
  the transition.

The SDM is unclear about when the TLB flush should occur, and whether or
not a failed VM entry would flush the TLB, so it is safer to always
do the TLB flush in this case.

More concretely, KVM also updates the last VPID L1 used for L2 in
nested_vmx_transition_tlb_flush() (i.e. last_vpid), even if the VM entry
ultimately fails. With the current code, KVM could miss a TLB flush if
L1 changes L2's VPID, then does a failed VM entry followed by a
successful one, as the failed VM entry would update last_vpid but not
actually flush the TLB. Servicing local TLB flushes on failed VM entries
makes sure that the TLB is always flushed when last_vpid is updated.

Fixes: 5c614b3583e7 ("KVM: nVMX: nested VPID emulation")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-bot@kernel.org> # Internal review
Suggested-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Yosry Ahmed <yosry@kernel.org>
Link: https://patch.msgid.link/20260722230128.1587363-1-yosry@kernel.org
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/x86/kvm/vmx/nested.c |    8 ++++++++
 1 file changed, 8 insertions(+)

--- a/arch/x86/kvm/vmx/nested.c
+++ b/arch/x86/kvm/vmx/nested.c
@@ -3763,6 +3763,14 @@ enum nvmx_vmentry_status nested_vmx_ente
 vmentry_fail_vmexit_guest_mode:
 	if (vmcs12->cpu_based_vm_exec_control & CPU_BASED_USE_TSC_OFFSETTING)
 		vcpu->arch.tsc_offset -= vmcs12->tsc_offset;
+
+	/*
+	 * Handle any TLB flush requests that were queued for L2 if KVM made it
+	 * far enough along to switch to L2 context.  Note, loading host state
+	 * will generate any flushes for L1 required by VM-Exit.
+	 */
+	kvm_service_local_tlb_flush_requests(vcpu);
+
 	leave_guest_mode(vcpu);
 
 vmentry_fail_vmexit:



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 296/556] KVM: nVM: Ensure INVVPID is emulated on the correct physical CPU
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (294 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 295/556] KVM: nVMX: Service local TLB flushes on failed nested VM-Enter Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 297/556] KVM: x86/mmu: Use CMPXCHG when clearing Accessed bit in TDP MMU Greg Kroah-Hartman
                   ` (272 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yosry Ahmed, Kai Huang,
	Sean Christopherson

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yosry Ahmed <yosry@kernel.org>

commit 6d00e67326d831e6e610933a3800712f4ffe6ec1 upstream.

When emulating INVVPID, KVM executes INVVPID on the physical CPU using
vpid02 (instead of the L1 assigned VPID), after doing some validations
on the operands. However, it is possible that the physical CPU KVM
executes INVVPID on is different from the CPU L2 is running on.

For example, in the following scenario:
- L2 runs on CPU #1 and exits to L1 (vmx->nested.vmcs02.cpu=1)
- L1 migrates to CPU #2 and executes INVVPID
- KVM executes INVVPID on CPU #2
- L1 migrates back to CPU #1 and runs L2 (vmx->nested.vmcs02.cpu=1)

The TLB entries on CPU #1 are never invalidated, because INVVPID was
executed on CPU #2, and vmcs02 never ran on a different pCPU (i.e.
vmx_vcpu_load_vmcs() will *not* request KVM_REQ_TLB_FLUSH).

Ensure that INVVPID is being executed on the same pCPU that L2 last ran
on, and if not, fallback to clearing last_vpid=0 to trigger a full VPID
flush on the next nested VM-Enter (as KVM will detect L1 using a
different VPID for L2). If L2 ends up running on a different pCPU, KVM
will flush the TLB anyway through vmx_vcpu_load_vmcs().

Cc: stable@vger.kernel.org
Signed-off-by: Yosry Ahmed <yosry@kernel.org>
Reviewed-by: Kai Huang <kai.huang@intel.com>
Link: https://patch.msgid.link/20260616214652.2157032-4-yosry@kernel.org
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/x86/kvm/vmx/nested.c |   11 ++++++++++-
 1 file changed, 10 insertions(+), 1 deletion(-)

--- a/arch/x86/kvm/vmx/nested.c
+++ b/arch/x86/kvm/vmx/nested.c
@@ -6079,6 +6079,7 @@ static int handle_invvpid(struct kvm_vcp
 		u64 gla;
 	} operand;
 	int r, gpr_index;
+	int cpu;
 
 	if (!(vmx->nested.msrs.secondary_ctls_high &
 	      SECONDARY_EXEC_ENABLE_VPID) ||
@@ -6127,11 +6128,19 @@ static int handle_invvpid(struct kvm_vcp
 	 * and never explicitly flush vpid01.  INVVPID targets a VPID, not a
 	 * VMCS, and so whether or not the current vmcs12 has VPID enabled is
 	 * irrelevant (and there may not be a loaded vmcs12).
+	 *
+	 * If vmcs02 was last loaded on a different pCPU, then defer the flush
+	 * by invalidating the nested VPID tracking to ensure that KVM performs
+	 * the invalidation on the correct pCPU.
 	 */
-	if (type == VMX_VPID_EXTENT_INDIVIDUAL_ADDR)
+	cpu = get_cpu();
+	if (cpu != vmx->nested.vmcs02.cpu)
+		vmx->nested.last_vpid = 0;
+	else if (type == VMX_VPID_EXTENT_INDIVIDUAL_ADDR)
 		vpid_sync_vcpu_addr(nested_get_vpid02(vcpu), operand.gla);
 	else
 		vpid_sync_context(nested_get_vpid02(vcpu));
+	put_cpu();
 
 	/*
 	 * Sync the shadow page tables if EPT is disabled, L1 is invalidating



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 297/556] KVM: x86/mmu: Use CMPXCHG when clearing Accessed bit in TDP MMU
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (295 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 296/556] KVM: nVM: Ensure INVVPID is emulated on the correct physical CPU Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 298/556] KVM: x86/mmu: Consume the locked rmap value in the lockless rmap walk Greg Kroah-Hartman
                   ` (271 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Kai Huang, James Houghton,
	Sean Christopherson

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sean Christopherson <seanjc@google.com>

commit 3d679b7cb31f74bf2303123ce4ee3266eeee999a upstream.

Use LOCK CMPXCHG instead of LOCK AND to clear the Accessed bit when aging
SPTEs in the TDP MMU, as doing a LOCK AND can corrupt a FROZEN SPTE and
allow a third CPU to effectively overwrite the FROZEN SPTE.  As pointed
out by AI of some kind, because the magic FROZEN_SPTE value is a "full"
SPTE, not a single bit, and includes the Accessed bit, clearing the
Accessed bit in a FROZEN SPTE will result in is_frozen_spte() getting a
false negative.

E.g. if CPU0 freezes an SPTE, and CPU1 clears the Accessed bit in the
frozen SPTE, then CPU2 could come along and overwrite the frozen SPTE with
a shadow-present SPTE.

Thankfully, the false negative is largely benign, because outside of TDX,
which doesn't support aging, KVM only freezes leaf SPTEs when removing an
upper level shadow page.  So while KVM could clobber a frozen SPTE back to
a shadow-present SPTE, and could even use the new SPTE, the subsequent TLB
flush will make the orphaned, shadow-present SPTE unreachable.  Failure to
ever zap the orphaned leaf SPTE would show up in KVM's stats, but otherwise
is benign (because KVM no longer keeps an elevated refcount for leaf SPTEs).

Opportunistically add a comment to warn future developers away from using
kvm_tdp_mmu_write_spte_atomic() and tdp_mmu_clear_spte_bits_atomic(), as
they are generally unsafe.  Keep the helpers, e.g. instead of open-coding
the atomic64_fetch_and() in tdp_mmu_clear_spte_bits(), as scary warnings
usually are more effective deterrent against recidivism than removal of the
dangerous code.

Alternatively, KVM could use different bits for the magic FROZEN_SPTE value,
e.g. setting the Dirty bits (with effective IPAT and Global aliases) would
likely be "ok", as IPAT/Global are extremely unlikely to be cleared without
doing a full SPTE write, and KVM's clearing of Dirty bits shares logic with
Write-Protection, which must do a full SPTE write (via cmpxchg64() in the
TDP MMU) to ensure KVM isn't clobbering state.  But there is zero reason to
carry that risk (beyond stubbornness in wanting to preserve a "cute" idea),
as the cost of LOCK CMPXCHG and LOCK AND are within 1-2 uops of each other
on modern hardware.

Fixes: b146a9b34aed ("KVM: x86/mmu: Age TDP MMU SPTEs without holding mmu_lock")
Cc: stable@vger.kernel.org
Reviewed-by: Kai Huang <kai.huang@intel.com>
Reviewed-by: James Houghton <jthoughton@google.com>
Link: https://patch.msgid.link/20260728002236.869865-2-seanjc@google.com
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/x86/kvm/mmu/tdp_iter.h |    7 +++++++
 arch/x86/kvm/mmu/tdp_mmu.c  |   20 +++++++++-----------
 2 files changed, 16 insertions(+), 11 deletions(-)

--- a/arch/x86/kvm/mmu/tdp_iter.h
+++ b/arch/x86/kvm/mmu/tdp_iter.h
@@ -19,6 +19,13 @@ static inline u64 kvm_tdp_mmu_read_spte(
 	return READ_ONCE(*rcu_dereference(sptep));
 }
 
+/*
+ * WARNING!  mmu_lock must be held for write when using the "write atomic" or
+ * "clear bits atomic" APIs, otherwise KVM could overwrite the "wrong" old SPTE
+ * value, i.e. clobber an update from a different CPU.  The only exception is
+ * when KVM is freezing a leaf SPTE for removal, in which case KVM doesn't care
+ * about the exact old SPTE value (KVM will react to the actual old value).
+ */
 static inline u64 kvm_tdp_mmu_write_spte_atomic(tdp_ptep_t sptep, u64 new_spte)
 {
 	KVM_MMU_WARN_ON(is_ept_ve_possible(new_spte));
--- a/arch/x86/kvm/mmu/tdp_mmu.c
+++ b/arch/x86/kvm/mmu/tdp_mmu.c
@@ -1334,19 +1334,17 @@ static void kvm_tdp_mmu_age_spte(struct
 	if (WARN_ON_ONCE(is_mirror_sptep(iter->sptep)))
 		return;
 
-	if (spte_ad_enabled(iter->old_spte)) {
-		iter->old_spte = tdp_mmu_clear_spte_bits_atomic(iter->sptep,
-								shadow_accessed_mask);
+	if (spte_ad_enabled(iter->old_spte))
 		new_spte = iter->old_spte & ~shadow_accessed_mask;
-	} else {
+	else
 		new_spte = mark_spte_for_access_track(iter->old_spte);
-		/*
-		 * It is safe for the following cmpxchg to fail. Leave the
-		 * Accessed bit set, as the spte is most likely young anyway.
-		 */
-		if (__tdp_mmu_set_spte_atomic(kvm, iter, new_spte))
-			return;
-	}
+
+	/*
+	 * Don't bother retrying if another CPU modified the SPTE, the SPTE is
+	 * either being zapped or is likely still in-use, i.e. is still young.
+	 */
+	if (__tdp_mmu_set_spte_atomic(kvm, iter, new_spte))
+		return;
 
 	trace_kvm_tdp_mmu_spte_changed(iter->as_id, iter->gfn, iter->level,
 				       iter->old_spte, new_spte);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 298/556] KVM: x86/mmu: Consume the locked rmap value in the lockless rmap walk
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (296 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 297/556] KVM: x86/mmu: Use CMPXCHG when clearing Accessed bit in TDP MMU Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 299/556] KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock Greg Kroah-Hartman
                   ` (270 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Sean Christopherson, Phil Rosenthal

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Phil Rosenthal <phil@phil.gs>

commit e428f9779a43737d830111238816f1928b07aefb upstream.

__kvm_rmap_lock() deliberately elides the rmap lock when it observes an
empty rmap.  In that case kvm_rmap_lock_readonly() also re-enables
preemption and returns zero, so the caller holds neither the rmap lock
nor a preemption reference.  The elision documents the invariant it
relies on:

	 * Elide the lock if the rmap is empty, as lockless walkers (read-only
	 * mode) don't need to (and can't) walk an empty rmap, nor can they add
	 * entries to the rmap.  I.e. the only paths that process empty rmaps
	 * do so while holding mmu_lock for write, and are mutually exclusive.

kvm_rmap_age_gfn_range() ignores the returned value and unconditionally
enters for_each_rmap_spte_lockless().  The iterator started with
rmap_get_first(), which re-reads rmap_head->val rather than using the
value returned by the lock.  If a writer populates the rmap between the
lock's read and the iterator's re-read, the aging path walks the newly
installed rmap without holding its lock.

For a KVM_RMAP_MANY rmap this leaves the walker following a
pte_list_desc chain that it never locked.  A writer holding mmu_lock for
write may free that chain (e.g. kvm_zap_all_rmap_sptes() on the recycle
path, or any rmap zap) via kmem_cache_free() while the walk is in
progress, giving a slab use-after-free.  Nothing serialises the two: the
aging path runs without mmu_lock when CONFIG_KVM_MMU_LOCKLESS_AGING=y,
and the rmap lock that would otherwise exclude the writer was elided.
Because the empty path re-enables preemption, the interval between the
two reads can span an arbitrary scheduling delay.

Fix the class of bug by having the lockless walk consume the value
returned by the lock instead of re-reading the rmap.  Split
rmap_get_first() into __rmap_get_first(), which starts an iterator from
an already-read rmap value, and make for_each_rmap_spte_lockless() take
that value and call __rmap_get_first() directly.
kvm_rmap_age_gfn_range() passes the value returned by
kvm_rmap_lock_readonly(): when the lock was elided the value is zero,
__rmap_get_first() returns NULL, and the walk is skipped.  No lockless
walker re-reads the rmap, so the lock-elision invariant cannot be
violated, and no lock()-without-paired-unlock() path is added to the
aging code.

Fixes: af3b6a9eba48 ("KVM: x86/mmu: Walk rmaps (shadow MMU) without holding mmu_lock when aging gfns")
Suggested-by: Sean Christopherson <seanjc@google.com>
Cc: stable@vger.kernel.org
Signed-off-by: Phil Rosenthal <phil@phil.gs>
Link: https://patch.msgid.link/20260720-rmap-age-elided-submit-v2-1-668973030d47@phil.gs
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/x86/kvm/mmu/mmu.c |   33 +++++++++++++++++++--------------
 1 file changed, 19 insertions(+), 14 deletions(-)

--- a/arch/x86/kvm/mmu/mmu.c
+++ b/arch/x86/kvm/mmu/mmu.c
@@ -1245,18 +1245,9 @@ struct rmap_iterator {
 	int pos;			/* index of the sptep */
 };
 
-/*
- * Iteration must be started by this function.  This should also be used after
- * removing/dropping sptes from the rmap link because in such cases the
- * information in the iterator may not be valid.
- *
- * Returns sptep if found, NULL otherwise.
- */
-static u64 *rmap_get_first(struct kvm_rmap_head *rmap_head,
-			   struct rmap_iterator *iter)
+static u64 *__rmap_get_first(unsigned long rmap_val,
+			     struct rmap_iterator *iter)
 {
-	unsigned long rmap_val = kvm_rmap_get(rmap_head);
-
 	if (!rmap_val)
 		return NULL;
 
@@ -1271,6 +1262,19 @@ static u64 *rmap_get_first(struct kvm_rm
 }
 
 /*
+ * Iteration must be started by this function.  This should also be used after
+ * removing/dropping sptes from the rmap link because in such cases the
+ * information in the iterator may not be valid.
+ *
+ * Returns sptep if found, NULL otherwise.
+ */
+static u64 *rmap_get_first(struct kvm_rmap_head *rmap_head,
+			   struct rmap_iterator *iter)
+{
+	return __rmap_get_first(kvm_rmap_get(rmap_head), iter);
+}
+
+/*
  * Must be used with a valid iterator: e.g. after rmap_get_first().
  *
  * Returns sptep if found, NULL otherwise.
@@ -1304,8 +1308,9 @@ static u64 *rmap_get_next(struct rmap_it
 	__for_each_rmap_spte(_rmap_head_, _iter_, _sptep_)			\
 		if (!WARN_ON_ONCE(!is_shadow_present_pte(*(_sptep_))))	\
 
-#define for_each_rmap_spte_lockless(_rmap_head_, _iter_, _sptep_, _spte_)	\
-	__for_each_rmap_spte(_rmap_head_, _iter_, _sptep_)			\
+#define for_each_rmap_spte_lockless(_rmap_val_, _iter_, _sptep_, _spte_)	\
+	for (_sptep_ = __rmap_get_first(_rmap_val_, _iter_);			\
+	     _sptep_; _sptep_ = rmap_get_next(_iter_))				\
 		if (is_shadow_present_pte(_spte_ = mmu_spte_get_lockless(sptep)))
 
 static void drop_spte(struct kvm *kvm, u64 *sptep)
@@ -1743,7 +1748,7 @@ static bool kvm_rmap_age_gfn_range(struc
 			rmap_head = gfn_to_rmap(gfn, level, range->slot);
 			rmap_val = kvm_rmap_lock_readonly(rmap_head);
 
-			for_each_rmap_spte_lockless(rmap_head, &iter, sptep, spte) {
+			for_each_rmap_spte_lockless(rmap_val, &iter, sptep, spte) {
 				if (!is_accessed_spte(spte))
 					continue;
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 299/556] KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (297 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 298/556] KVM: x86/mmu: Consume the locked rmap value in the lockless rmap walk Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 300/556] KVM: x86: Serialize writes to disabled_quirks using kvm->lock Greg Kroah-Hartman
                   ` (269 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Vitaly Kuznetsov,
	syzbot+3d5461510f8dc4adfe30, Carlos López,
	Sean Christopherson

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Carlos López <clopez@suse.de>

commit 0ca49fbd2883cd53d32d85b50feef17fa04d0fbf upstream.

Fix an issue where userspace or the guest can program an Hyper-V
synthetic timer to have a deadline in the past via integer overflow,
preventing the CPU from making progress and triggering an RCU stall.

Hyper-V's SynIC exposes 4 per-vCPU synthetic timers to the
guest, which are emulated by KVM. Each is programmed through the
HV_X64_MSR_STIMERi_CONFIG and HV_X64_MSR_STIMERi_COUNT MSRs. Depending
on CONFIG, COUNT represents either the absolute expiration time or the
period of a periodic timer, both expressed in 100ns ticks. These timers
may be set both by the guest (WRMSR) and the host (KVM_SET_MSRS).

When the timer is enabled, stimer_start() translates COUNT to an
absolute monotonic deadline and arms an hrtimer. If COUNT is set to a
value close to U64_MAX, the deadline calculation can overflow.

    ktime_add_ns(ktime_now, 100 * (stimer->exp_time - time_now))

This can result in a CPU livelock. stimer_start() arms the timer
via hrtimer_start() with a deadline in the past, which causes it to
immediately fire. The stimer callback then raises KVM_RQ_HV_STIMER, with
the intention of causing KVM to deliver a synthetic interrupt on the
next vCPU guest enter.

Then, once userspace issues KVM_RUN, vcpu_enter_guest() consumes the
request, calling kvm_hv_process_stimers(). This would normally disable
the timer via stimer_expiration() once the deadline is in the past.
However, the deadline comparison is done between the KVM reference
counter and stime->exp_time, which is a big value close to U64_MAX, so
this never happens for a few thousand years.

kvm_hv_process_timers() then re-arms the timer via stimer_start(), since
it was not disabled, which again fires immediately. Before entering
the guest, kvm_vcpu_exit_request() checks kvm_request_pending(),
which returns true due to the newly raised KVM_REQ_HV_STIMER. Then
vcpu_enter_guest() aborts the guest entry, returning early into
vcpu_run(), which loops back again into vcpu_enter_guest(), restarting
the cycle.

Since there are no manual yields in this loop, a task with SCHED_FIFO
may starve RCU grace-period kthreads, which exposes the stalls found
by syzcaller:

    rcu: INFO: rcu_preempt detected stalls on CPUs/tasks:
    rcu:    (detected by 1, t=10502 jiffies, g=14269, q=1142 ncpus=2)
    rcu: All QSes seen, last rcu_preempt kthread activity 10500 (4294965239-4294954739), jiffies_till_next_fqs=1, root ->qsmask 0x0
    rcu: rcu_preempt kthread starved for 10500 jiffies! g14269 f0x2 RCU_GP_WAIT_FQS(5) ->state=0x0 ->cpu=0
    rcu:    Unless rcu_preempt kthread gets sufficient CPU time, OOM is now expected behavior.
        ( ... )
    Call Trace:
     <IRQ>
     __run_hrtimer kernel/time/hrtimer.c:1773 [inline]
     __hrtimer_run_queues+0x408/0xc30 kernel/time/hrtimer.c:1841
     hrtimer_interrupt+0x45b/0xaa0 kernel/time/hrtimer.c:1903
     local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1045 [inline]
     __sysvec_apic_timer_interrupt+0x102/0x3e0 arch/x86/kernel/apic/apic.c:1062
     instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1056 [inline]
     sysvec_apic_timer_interrupt+0xa1/0xc0 arch/x86/kernel/apic/apic.c:1056
     </IRQ>
     <TASK>
     asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:697
    RIP: 0010:__raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:152 [inline]
    RIP: 0010:_raw_spin_unlock_irqrestore+0xa8/0x110 kernel/locking/spinlock.c:194
    Code: 74 05 e8 0b f4 5f f6 48 c7 44 24 20 00 00 00 00 9c 8f 44 24 20 f6 44 24 21 02 75 4f f7 c3 00 02 00 00 74 01 fb bf 01 00 00 00 <e8> 23 6b 27 f6 65 8b 05 7c 60 5a 07 85 c0 74 40 48 c7 04 24 0e 36
    RSP: 0018:ffffc900040a7320 EFLAGS: 00000206
    RAX: 5de15cb931505900 RBX: 0000000000000a06 RCX: 5de15cb931505900
    RDX: 0000000000000007 RSI: ffffffff8daa9dc3 RDI: 0000000000000001
    RBP: ffffc900040a73b0 R08: ffffffff8fc3d077 R09: 1ffffffff1f87a0e
    R10: dffffc0000000000 R11: fffffbfff1f87a0f R12: dffffc0000000000
    R13: 0000000000000000 R14: ffff8880b8628240 R15: 1ffff92000814e64
     hrtimer_start include/linux/hrtimer.h:259 [inline]
     stimer_start arch/x86/kvm/hyperv.c:682 [inline]
     kvm_hv_process_stimers+0xd0a/0x16a0 arch/x86/kvm/hyperv.c:893
     vcpu_enter_guest arch/x86/kvm/x86.c:11193 [inline]
     vcpu_run+0x2240/0x76b0 arch/x86/kvm/x86.c:11639
     kvm_arch_vcpu_ioctl_run+0x1148/0x1c90 arch/x86/kvm/x86.c:11984
     kvm_vcpu_ioctl+0x99a/0xed0 virt/kvm/kvm_main.c:4492
     vfs_ioctl fs/ioctl.c:51 [inline]
     __do_sys_ioctl fs/ioctl.c:597 [inline]
     __se_sys_ioctl+0xfc/0x170 fs/ioctl.c:583
     do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
     do_syscall_64+0xfa/0xf80 arch/x86/entry/syscall_64.c:94
     entry_SYSCALL_64_after_hwframe+0x77/0x7f
    RIP: 0033:0x7f635278f749
    Code: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48
    RSP: 002b:00007f635365c038 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
    RAX: ffffffffffffffda RBX: 00007f63529e5fa0 RCX: 00007f635278f749
    RDX: 0000000000000000 RSI: 000000000000ae80 RDI: 0000000000000005
    RBP: 00007f6352813f91 R08: 0000000000000000 R09: 0000000000000000
    R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
    R13: 00007f63529e6038 R14: 00007f63529e5fa0 R15: 00007ffd5b219358
     </TASK>

Fix this by clamping the deadline computation to KTIME_MAX, which
preserves the intent of arming a timer very far in the future.
ktime_add_safe() already does this type of clamping, so use it after
checking that that multiplying by the 100ns time tick also does not
overflow.

Reviewed-by: Vitaly Kuznetsov <vkuznets@redhat.com>
Reported-by: syzbot+3d5461510f8dc4adfe30@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=3d5461510f8dc4adfe30
Fixes: 1f4b34f825e8 ("kvm/x86: Hyper-V SynIC timers")
Cc: stable@vger.kernel.org
Signed-off-by: Carlos López <clopez@suse.de>
Link: https://patch.msgid.link/20260714133212.3916611-3-clopez@suse.de
[sean: tag for stable]
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/x86/kvm/hyperv.c |   25 ++++++++++++++++++-------
 1 file changed, 18 insertions(+), 7 deletions(-)

--- a/arch/x86/kvm/hyperv.c
+++ b/arch/x86/kvm/hyperv.c
@@ -627,6 +627,18 @@ static enum hrtimer_restart stimer_timer
 }
 
 /*
+ * Translate a stimer expiry given in 100ns reference ticks into an
+ * an absolute deadline. Saturates on overflow.
+ */
+static ktime_t stimer_add_delta(ktime_t now, u64 delta_100ns)
+{
+	if (delta_100ns >= KTIME_MAX / 100)
+		return KTIME_MAX;
+
+	return ktime_add_safe(now, 100 * delta_100ns);
+}
+
+/*
  * stimer_start() assumptions:
  * a) stimer->count is not equal to 0
  * b) stimer->config has HV_STIMER_ENABLE flag
@@ -635,6 +647,7 @@ static int stimer_start(struct kvm_vcpu_
 {
 	u64 time_now;
 	ktime_t ktime_now;
+	ktime_t deadline;
 
 	time_now = get_time_ref_counter(hv_stimer_to_vcpu(stimer)->kvm);
 	ktime_now = ktime_get();
@@ -657,10 +670,8 @@ static int stimer_start(struct kvm_vcpu_
 					stimer->index,
 					time_now, stimer->exp_time);
 
-		hrtimer_start(&stimer->timer,
-			      ktime_add_ns(ktime_now,
-					   100 * (stimer->exp_time - time_now)),
-			      HRTIMER_MODE_ABS);
+		deadline = stimer_add_delta(ktime_now, stimer->exp_time - time_now);
+		hrtimer_start(&stimer->timer, deadline, HRTIMER_MODE_ABS);
 		return 0;
 	}
 	stimer->exp_time = stimer->count;
@@ -679,9 +690,9 @@ static int stimer_start(struct kvm_vcpu_
 					   stimer->index,
 					   time_now, stimer->count);
 
-	hrtimer_start(&stimer->timer,
-		      ktime_add_ns(ktime_now, 100 * (stimer->count - time_now)),
-		      HRTIMER_MODE_ABS);
+	deadline = stimer_add_delta(ktime_now, stimer->count - time_now);
+	hrtimer_start(&stimer->timer, deadline, HRTIMER_MODE_ABS);
+
 	return 0;
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 300/556] KVM: x86: Serialize writes to disabled_quirks using kvm->lock
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (298 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 299/556] KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 301/556] KVM: x86: Ensure runtime reads of disabled_quirks are resolved once Greg Kroah-Hartman
                   ` (268 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Michael Roth, Sean Christopherson

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sean Christopherson <seanjc@google.com>

commit ba76b23ed36ab230fc2577aba24f65851114902f upstream.

Protect writes to disabled_quirks with kvm->lock to ensure KVM doesn't
clobber state in the unlikely scenario that userspace disables disparate
quirks from multiple tasks.  More importantly, this will allow wrapping
accesses with {READ,WRITE}_ONCE without "needing" to also guard the writer
with a useless and confusing READ_ONCE (since the RMW wouldn't be atomic
anyways).

Ideally, KVM would disallow disabling quirks once quirks are "live", but
that would be a potentially breaking userspace ABI change, and while all
existing quirks are fully live only after vCPUs have been created, several
MMU-related quirks, IGNORE_GUEST_PAT and SLOT_ZAP_ALL, are partially live
at all times.  Because populating MMUs requires a vCPU, the guest-visible
behavior of IGNORE_GUEST_PAT and SLOT_ZAP_ALL requires a vCPU, but for KVM
itself, processing the quirk (or not) has functional impact, i.e. for all
intents and purposes, KVM can't prevent those quirks from being disabled
after they've been consumed.

Cc: stable@vger.kernel.org # 6.12.x
Reviewed-by: Michael Roth <michael.roth@amd.com>
Link: https://patch.msgid.link/20260709204948.1988414-6-seanjc@google.com
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/x86/kvm/x86.c |    2 ++
 1 file changed, 2 insertions(+)

--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -6736,7 +6736,9 @@ int kvm_vm_ioctl_enable_cap(struct kvm *
 			break;
 		fallthrough;
 	case KVM_CAP_DISABLE_QUIRKS:
+		mutex_lock(&kvm->lock);
 		kvm->arch.disabled_quirks |= cap->args[0] & kvm_caps.supported_quirks;
+		mutex_unlock(&kvm->lock);
 		r = 0;
 		break;
 	case KVM_CAP_SPLIT_IRQCHIP: {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 301/556] KVM: x86: Ensure runtime reads of disabled_quirks are resolved once
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (299 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 300/556] KVM: x86: Serialize writes to disabled_quirks using kvm->lock Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 302/556] KVM: x86: Move enabling EFER.SVME and EFER.LMSLE to generic EFER setup Greg Kroah-Hartman
                   ` (267 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Michael Roth, Sean Christopherson

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sean Christopherson <seanjc@google.com>

commit ed15cb21999217e549414c128b4a0485debf6278 upstream.

Wrap the sole reader of disabled_quirks with READ_ONCE(), and wrap the
post-VM-creation write to disabled_quirks with WRITE_ONCE(), to ensure
checking the status of a quirk doesn't re-read disabled_quirks *if* the
caller needs such a guarantee.  This will allow splitting the "fast" MMU
zap into front and back halves, without potentially skipping the back
half if SLOT_ZAP_ALL were concurrently disabled (which would be "fine" in
the current code base, but far from ideal).

Cc: stable@vger.kernel.org # 6.12.x
Reviewed-by: Michael Roth <michael.roth@amd.com>
Link: https://patch.msgid.link/20260709204948.1988414-7-seanjc@google.com
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/x86/kvm/x86.c |    3 ++-
 arch/x86/kvm/x86.h |    2 +-
 2 files changed, 3 insertions(+), 2 deletions(-)

--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -6737,7 +6737,8 @@ int kvm_vm_ioctl_enable_cap(struct kvm *
 		fallthrough;
 	case KVM_CAP_DISABLE_QUIRKS:
 		mutex_lock(&kvm->lock);
-		kvm->arch.disabled_quirks |= cap->args[0] & kvm_caps.supported_quirks;
+		WRITE_ONCE(kvm->arch.disabled_quirks,
+			   kvm->arch.disabled_quirks | (cap->args[0] & kvm_caps.supported_quirks));
 		mutex_unlock(&kvm->lock);
 		r = 0;
 		break;
--- a/arch/x86/kvm/x86.h
+++ b/arch/x86/kvm/x86.h
@@ -367,7 +367,7 @@ static inline bool vcpu_match_mmio_gpa(s
 
 static inline bool kvm_check_has_quirk(struct kvm *kvm, u64 quirk)
 {
-	return !(kvm->arch.disabled_quirks & quirk);
+	return !(READ_ONCE(kvm->arch.disabled_quirks) & quirk);
 }
 
 static __always_inline void kvm_request_l1tf_flush_l1d(void)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 302/556] KVM: x86: Move enabling EFER.SVME and EFER.LMSLE to generic EFER setup
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (300 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 301/556] KVM: x86: Ensure runtime reads of disabled_quirks are resolved once Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 303/556] KVM: s390: Fix length check __import_wp_info() Greg Kroah-Hartman
                   ` (266 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Sean Christopherson, Yosry Ahmed

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yosry Ahmed <yosry@kernel.org>

commit 6ccc19d4c1eb97a994180af8afcab58422cb409d upstream.

Move SVM-specific EFER bit enablement to generic x86 code, with the rest
of EFER bit enablement. Unifying the code for EFER bit enablement allows
for a later change to re-initialize EFER bits on module init.

No functional change intended.

Cc: stable@vger.kernel.org
Suggested-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Yosry Ahmed <yosry@kernel.org>
Link: https://patch.msgid.link/20260713181020.2735367-2-yosry@kernel.org
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/x86/kvm/svm/svm.c |    4 ----
 arch/x86/kvm/x86.c     |    6 ++++++
 2 files changed, 6 insertions(+), 4 deletions(-)

--- a/arch/x86/kvm/svm/svm.c
+++ b/arch/x86/kvm/svm/svm.c
@@ -5658,10 +5658,6 @@ static __init int svm_hardware_setup(voi
 
 	if (nested) {
 		pr_info("Nested Virtualization enabled\n");
-		kvm_enable_efer_bits(EFER_SVME);
-		if (!boot_cpu_has(X86_FEATURE_EFER_LMSLE_MBZ))
-			kvm_enable_efer_bits(EFER_LMSLE);
-
 		r = nested_svm_init_msrpm_merge_offsets();
 		if (r)
 			return r;
--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -10015,6 +10015,12 @@ static void kvm_setup_efer_caps(void)
 
 	if (kvm_cpu_cap_has(X86_FEATURE_AUTOIBRS))
 		kvm_enable_efer_bits(EFER_AUTOIBRS);
+
+	if (kvm_cpu_cap_has(X86_FEATURE_SVM)) {
+		kvm_enable_efer_bits(EFER_SVME);
+		if (!boot_cpu_has(X86_FEATURE_EFER_LMSLE_MBZ))
+			kvm_enable_efer_bits(EFER_LMSLE);
+	}
 }
 
 static inline void kvm_ops_update(struct kvm_x86_init_ops *ops)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 303/556] KVM: s390: Fix length check __import_wp_info()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (301 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 302/556] KVM: x86: Move enabling EFER.SVME and EFER.LMSLE to generic EFER setup Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 304/556] KVM: s390: Fix memory leak in guest debug handling Greg Kroah-Hartman
                   ` (265 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Christian Borntraeger,
	Claudio Imbrenda

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christian Borntraeger <borntraeger@linux.ibm.com>

commit 4c07680a467e2f7697245bcd11691bffb2a6f0ed upstream.

struct kvm_hw_breakpoint::len is a __u64 that is fully controlled by user
space. This is then assigned to wp_info->len, which is an int. The bounds
check is done on the truncated value while the allocation uses the
untruncated one:

	wp_info->len = bp_data->len;
	[...]
	if (wp_info->len < 0 || wp_info->len > MAX_WP_SIZE)
		return -EINVAL;

	wp_info->old_data = kmalloc(bp_data->len, GFP_KERNEL_ACCOUNT);

Use the validated value for the allocation as intended. Without this
fix userspace can trigger >4GB allocations which will fail and result
in a WARN due to MAX_PAGE_ORDER.

Fixes: 27291e2165b6 ("KVM: s390: hardware support for guest debugging")
Cc: stable@vger.kernel.org
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Message-ID: <20260805110455.7200-9-borntraeger@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/s390/kvm/guestdbg.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/arch/s390/kvm/guestdbg.c
+++ b/arch/s390/kvm/guestdbg.c
@@ -184,7 +184,7 @@ static int __import_wp_info(struct kvm_v
 	if (wp_info->len < 0 || wp_info->len > MAX_WP_SIZE)
 		return -EINVAL;
 
-	wp_info->old_data = kmalloc(bp_data->len, GFP_KERNEL_ACCOUNT);
+	wp_info->old_data = kmalloc(wp_info->len, GFP_KERNEL_ACCOUNT);
 	if (!wp_info->old_data)
 		return -ENOMEM;
 	/* try to backup the original value */



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 304/556] KVM: s390: Fix memory leak in guest debug handling
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (302 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 303/556] KVM: s390: Fix length check __import_wp_info() Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 305/556] KVM: s390: Fix old_data leak in guest debug error path Greg Kroah-Hartman
                   ` (264 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Christian Borntraeger,
	Matthew Rosato, Claudio Imbrenda

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christian Borntraeger <borntraeger@linux.ibm.com>

commit 121ea1de927c8b9bfdf53c31cad27b86d5de0293 upstream.

bp_data is freed only for the error case by kfree(bp_data).
Every successful KVM_SET_GUEST_DEBUG will leak bp_data.

Fixes: 27291e2165b6 ("KVM: s390: hardware support for guest debugging")
Cc: stable@vger.kernel.org
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Reviewed-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Message-ID: <20260805110455.7200-5-borntraeger@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/s390/kvm/guestdbg.c |    1 +
 1 file changed, 1 insertion(+)

--- a/arch/s390/kvm/guestdbg.c
+++ b/arch/s390/kvm/guestdbg.c
@@ -267,6 +267,7 @@ int kvm_s390_import_bp_data(struct kvm_v
 	vcpu->arch.guestdbg.hw_bp_info = bp_info;
 	vcpu->arch.guestdbg.nr_hw_wp = nr_wp;
 	vcpu->arch.guestdbg.hw_wp_info = wp_info;
+	kfree(bp_data);
 	return 0;
 error:
 	kfree(bp_data);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 305/556] KVM: s390: Fix old_data leak in guest debug error path
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (303 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 304/556] KVM: s390: Fix memory leak in guest debug handling Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 306/556] KVM: s390: Free guest debug data on vcpu destroy Greg Kroah-Hartman
                   ` (263 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Christian Borntraeger,
	Matthew Rosato, Claudio Imbrenda

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christian Borntraeger <borntraeger@linux.ibm.com>

commit aa9c8e8baf1e765fa65b93212522c636f25d846f upstream.

__import_wp_info() allocates a per-watchpoint old_data buffer to back up
the original guest memory contents. If a later watchpoint of the same
KVM_SET_GUEST_DEBUG request fails to import, kvm_s390_import_bp_data()
jumps to the error label, which frees the wp_info array but not the
old_data buffers of the entries that were imported successfully. Up to
MAX_BP_COUNT - 1 buffers of up to MAX_WP_SIZE bytes are leaked per failed
request, and the request can be repeated.

Create error handling for cleaning up all created old_data memory
areas.

Fixes: 27291e2165b6 ("KVM: s390: hardware support for guest debugging")
Cc: stable@vger.kernel.org
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Reviewed-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Message-ID: <20260805110455.7200-6-borntraeger@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/s390/kvm/guestdbg.c |    6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

--- a/arch/s390/kvm/guestdbg.c
+++ b/arch/s390/kvm/guestdbg.c
@@ -252,7 +252,7 @@ int kvm_s390_import_bp_data(struct kvm_v
 			ret = __import_wp_info(vcpu, &bp_data[i],
 					       &wp_info[nr_wp]);
 			if (ret)
-				goto error;
+				goto error_wp;
 			nr_wp++;
 			break;
 		case KVM_HW_BP:
@@ -269,6 +269,10 @@ int kvm_s390_import_bp_data(struct kvm_v
 	vcpu->arch.guestdbg.hw_wp_info = wp_info;
 	kfree(bp_data);
 	return 0;
+
+error_wp:
+	while (nr_wp--)
+		kfree(wp_info[nr_wp].old_data);
 error:
 	kfree(bp_data);
 	kfree(wp_info);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 306/556] KVM: s390: Free guest debug data on vcpu destroy
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (304 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 305/556] KVM: s390: Fix old_data leak in guest debug error path Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 307/556] KVM: s390: Take srcu when importing watchpoint data Greg Kroah-Hartman
                   ` (262 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Christian Borntraeger,
	Matthew Rosato, Claudio Imbrenda

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christian Borntraeger <borntraeger@linux.ibm.com>

commit e7f698b09d4a7c36b299acf680fc50fe868e2bcd upstream.

kvm_s390_clear_bp_data() is only called from
kvm_arch_vcpu_ioctl_set_guest_debug(), i.e. when user space changes or
disables debugging. A vCPU that is destroyed while hardware breakpoints
are still armed - the normal case when the VMM just exits or crashes -
leaks hw_bp_info, hw_wp_info and all old_data buffers, since generic KVM
frees the vCPU right after kvm_arch_vcpu_destroy().

That is bounded by MAX_BP_COUNT entries, so roughly 8 KiB per vCPU, but
it is unbounded over VM lifetimes. The allocations are
GFP_KERNEL_ACCOUNT, so the charge also outlives the exiting process and
pins dying memcgs.

Fix by clearing the debug data on vCPU destruction. Calling it
unconditionally is fine: struct kvm_vcpu is zero allocated, so for a vCPU
that never enabled debugging the counters are 0 and the pointers NULL.

Fixes: 27291e2165b6 ("KVM: s390: hardware support for guest debugging")
Cc: stable@vger.kernel.org
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Reviewed-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Message-ID: <20260805110455.7200-8-borntraeger@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/s390/kvm/kvm-s390.c |    1 +
 1 file changed, 1 insertion(+)

--- a/arch/s390/kvm/kvm-s390.c
+++ b/arch/s390/kvm/kvm-s390.c
@@ -3410,6 +3410,7 @@ void kvm_arch_vcpu_destroy(struct kvm_vc
 	trace_kvm_s390_destroy_vcpu(vcpu->vcpu_id);
 	kvm_s390_clear_local_irqs(vcpu);
 	kvm_clear_async_pf_completion_queue(vcpu);
+	kvm_s390_clear_bp_data(vcpu);
 	if (!kvm_is_ucontrol(vcpu->kvm))
 		sca_del_vcpu(vcpu);
 	kvm_s390_update_topology_change_report(vcpu->kvm, 1);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 307/556] KVM: s390: Take srcu when importing watchpoint data
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (305 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 306/556] KVM: s390: Free guest debug data on vcpu destroy Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 308/556] KVM: s390: Zero initialize data structures for inject_pfault_token Greg Kroah-Hartman
                   ` (261 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Christian Borntraeger,
	Claudio Imbrenda

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christian Borntraeger <borntraeger@linux.ibm.com>

commit a4e482def8533ebace517d9f67f1465841b1f982 upstream.

__import_wp_info() backs up the original guest memory contents of a
watchpoint with read_guest_abs(), which is kvm_read_guest() and therefore
resolves the memslot via __kvm_memslots(). That requires kvm->srcu (or
kvm->slots_lock) to be held, otherwise a concurrent memslot update can
free the memslots array under us once its SRCU grace period has elapsed.

As this is not fast path, following lock ordering (mutex first, then
srcu) take the big hammer and hold the srcu for the full import.

Fixes: 27291e2165b6 ("KVM: s390: hardware support for guest debugging")
Cc: stable@vger.kernel.org
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Message-ID: <20260805110455.7200-7-borntraeger@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/s390/kvm/kvm-s390.c |    6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

--- a/arch/s390/kvm/kvm-s390.c
+++ b/arch/s390/kvm/kvm-s390.c
@@ -4249,8 +4249,10 @@ int kvm_arch_vcpu_ioctl_set_guest_debug(
 		/* enforce guest PER */
 		kvm_s390_set_cpuflags(vcpu, CPUSTAT_P);
 
-		if (dbg->control & KVM_GUESTDBG_USE_HW_BP)
-			rc = kvm_s390_import_bp_data(vcpu, dbg);
+		if (dbg->control & KVM_GUESTDBG_USE_HW_BP) {
+			scoped_guard(srcu, &vcpu->kvm->srcu)
+				rc = kvm_s390_import_bp_data(vcpu, dbg);
+		}
 	} else {
 		kvm_s390_clear_cpuflags(vcpu, CPUSTAT_P);
 		vcpu->arch.guestdbg.last_bp = 0;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 308/556] KVM: s390: Zero initialize data structures for inject_pfault_token
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (306 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 307/556] KVM: s390: Take srcu when importing watchpoint data Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 309/556] KVM: s390: Zero initialize irq in reinject_machine_check Greg Kroah-Hartman
                   ` (260 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Christian Borntraeger,
	Matthew Rosato, Claudio Imbrenda

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christian Borntraeger <borntraeger@linux.ibm.com>

commit 4e2c7f7cbc27418f9a290399b986c1b85ff93b90 upstream.

__kvm_inject_pfault_token() only sets .type and .u.ext.ext_params2 of
the on-stack struct kvm_s390_irq but the full ext substructure is copied
into the cpu local variable on inject. ext_params and pad contain stale
stack values.

Interrupt delivery only uses ext_params2, so nothing leaks to the guest,
but a host user can use the migration ioctls to get to the data.

Fix by zero-initializing the irq struct.
Do the same for the inti data structure.

Fixes: 383d0b050106 ("KVM: s390: handle pending local interrupts via bitmap")
Cc: stable@vger.kernel.org
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Reviewed-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Message-ID: <20260805110455.7200-3-borntraeger@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/s390/kvm/kvm-s390.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/arch/s390/kvm/kvm-s390.c
+++ b/arch/s390/kvm/kvm-s390.c
@@ -4477,8 +4477,8 @@ int kvm_s390_try_set_tod_clock(struct kv
 static void __kvm_inject_pfault_token(struct kvm_vcpu *vcpu, bool start_token,
 				     unsigned long token)
 {
-	struct kvm_s390_interrupt inti;
-	struct kvm_s390_irq irq;
+	struct kvm_s390_interrupt inti = {};
+	struct kvm_s390_irq irq = {};
 	struct kvm_s390_interrupt_info *inti_mem = NULL;
 	int ret = 0;
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 309/556] KVM: s390: Zero initialize irq in reinject_machine_check
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (307 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 308/556] KVM: s390: Zero initialize data structures for inject_pfault_token Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 310/556] KVM: s390: Fix memory corruption by not reinjecting CK machine checks Greg Kroah-Hartman
                   ` (259 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Christian Borntraeger,
	Matthew Rosato, Claudio Imbrenda

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christian Borntraeger <borntraeger@linux.ibm.com>

commit b239410c7653ff6781d4cf1d63cfc52a1bb71788 upstream.

kvm_s390_reinject_machine_check() fills cr14, mcic, ext_damage_code and
failing_storage_address of the on-stack struct kvm_s390_irq, but struct
kvm_s390_mchk_info also has a pad word and a 16 byte fixed_logout array.
struct mcck_volatile_info carries no logout data, so there is nothing to
copy there and both stay whatever was on the stack.

__inject_mchk() then memcpy()s fixed_logout into the vcpu local
interrupt state unconditionally. This will reach the guest during
deliver and userspace during migration.

Reflecting zeroes is the correct behaviour here, as KVM has no logout
data for a reinjected machine check.

This needs a host machine check while the cpu is in SIE so not trivial
to trigger.

Fixes: 4d62fcc0b692 ("KVM: s390: Inject machine check into the guest")
Cc: stable@vger.kernel.org
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Reviewed-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Message-ID: <20260805110455.7200-4-borntraeger@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/s390/kvm/interrupt.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/arch/s390/kvm/interrupt.c
+++ b/arch/s390/kvm/interrupt.c
@@ -3109,7 +3109,7 @@ void kvm_s390_reinject_machine_check(str
 				     struct mcck_volatile_info *mcck_info)
 {
 	struct kvm_s390_interrupt_info inti;
-	struct kvm_s390_irq irq;
+	struct kvm_s390_irq irq = {};
 	struct kvm_s390_mchk_info *mchk;
 	union mci mci;
 	__u64 cr14 = 0;         /* upper bits are not used */



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 310/556] KVM: s390: Fix memory corruption by not reinjecting CK machine checks
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (308 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 309/556] KVM: s390: Zero initialize irq in reinject_machine_check Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 311/556] KVM: s390: keyop: use mmu_lock to read gmap->asce Greg Kroah-Hartman
                   ` (258 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Christian Borntraeger,
	Heiko Carstens, Claudio Imbrenda

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christian Borntraeger <borntraeger@linux.ibm.com>

commit 546dde823a36d7283dcf46127c2f3d093443860f upstream.

Channel-subsystem damage machine checks are for the host channel
subsystem. The guest channel subsystem is emulated in the userspace VMM.
There is no point in forwarding such machine checks into the guest.

This also simplifies the machine check reinjection and avoids kfree of a
stack variable as reported by sashiko.  There might be still machine
checks that have the ck bit set with another bit (like instruction
damage), mask out the CK bit in s390_backup_mcck_info(), like the CP and
ED bits already are.

Fixes: 4d62fcc0b692 ("KVM: s390: Inject machine check into the guest")
Cc: stable@vger.kernel.org
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Acked-by: Heiko Carstens <hca@linux.ibm.com>
Acked-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Message-ID: <20260806145835.31818-1-borntraeger@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/s390/include/asm/nmi.h |    3 +++
 arch/s390/kernel/nmi.c      |    5 +----
 arch/s390/kvm/interrupt.c   |   24 ++++++++----------------
 3 files changed, 12 insertions(+), 20 deletions(-)

--- a/arch/s390/include/asm/nmi.h
+++ b/arch/s390/include/asm/nmi.h
@@ -22,6 +22,7 @@
 #define MCCK_CODE_SYSTEM_DAMAGE		BIT(63)
 #define MCCK_CODE_EXT_DAMAGE		BIT(63 - 5)
 #define MCCK_CODE_CP			BIT(63 - 9)
+#define MCCK_CODE_CK			BIT(63 - 11)
 #define MCCK_CODE_STG_ERROR		BIT(63 - 16)
 #define MCCK_CODE_STG_KEY_ERROR		BIT(63 - 18)
 #define MCCK_CODE_STG_DEGRAD		BIT(63 - 19)
@@ -33,6 +34,8 @@
 #define MCCK_CODE_FC_VALID		BIT(63 - 43)
 #define MCCK_CODE_CPU_TIMER_VALID	BIT(63 - 46)
 
+#define MCCK_CODE_NO_GUEST	(MCCK_CODE_CP | MCCK_CODE_EXT_DAMAGE | MCCK_CODE_CK)
+
 #ifndef __ASSEMBLER__
 
 union mci {
--- a/arch/s390/kernel/nmi.c
+++ b/arch/s390/kernel/nmi.c
@@ -344,8 +344,7 @@ static void notrace s390_backup_mcck_inf
 
 	sie_page = container_of(sie_block, struct sie_page, sie_block);
 	mcck_backup = &sie_page->mcck_info;
-	mcck_backup->mcic = get_lowcore()->mcck_interruption_code &
-				~(MCCK_CODE_CP | MCCK_CODE_EXT_DAMAGE);
+	mcck_backup->mcic = get_lowcore()->mcck_interruption_code & ~MCCK_CODE_NO_GUEST;
 	mcck_backup->ext_damage_code = get_lowcore()->external_damage_code;
 	mcck_backup->failing_storage_address = get_lowcore()->failing_storage_address;
 }
@@ -357,8 +356,6 @@ NOKPROBE_SYMBOL(s390_backup_mcck_info);
 #define ED_STP_ISLAND	6	/* External damage STP island check */
 #define ED_STP_SYNC	7	/* External damage STP sync check */
 
-#define MCCK_CODE_NO_GUEST	(MCCK_CODE_CP | MCCK_CODE_EXT_DAMAGE)
-
 /*
  * machine check handler.
  */
--- a/arch/s390/kvm/interrupt.c
+++ b/arch/s390/kvm/interrupt.c
@@ -3108,9 +3108,7 @@ static int set_adapter_int(struct kvm_ke
 void kvm_s390_reinject_machine_check(struct kvm_vcpu *vcpu,
 				     struct mcck_volatile_info *mcck_info)
 {
-	struct kvm_s390_interrupt_info inti;
 	struct kvm_s390_irq irq = {};
-	struct kvm_s390_mchk_info *mchk;
 	union mci mci;
 	__u64 cr14 = 0;         /* upper bits are not used */
 	int rc;
@@ -3129,20 +3127,14 @@ void kvm_s390_reinject_machine_check(str
 	if (mci.w)
 		cr14 |= CR14_WARNING_SUBMASK;
 
-	mchk = mci.ck ? &inti.mchk : &irq.u.mchk;
-	mchk->cr14 = cr14;
-	mchk->mcic = mcck_info->mcic;
-	mchk->ext_damage_code = mcck_info->ext_damage_code;
-	mchk->failing_storage_address = mcck_info->failing_storage_address;
-	if (mci.ck) {
-		/* Inject the floating machine check */
-		inti.type = KVM_S390_MCHK;
-		rc = __inject_vm(vcpu->kvm, &inti);
-	} else {
-		/* Inject the machine check to specified vcpu */
-		irq.type = KVM_S390_MCHK;
-		rc = kvm_s390_inject_vcpu(vcpu, &irq);
-	}
+	irq.u.mchk.cr14 = cr14;
+	irq.u.mchk.mcic = mcck_info->mcic;
+	irq.u.mchk.ext_damage_code = mcck_info->ext_damage_code;
+	irq.u.mchk.failing_storage_address = mcck_info->failing_storage_address;
+
+	/* Inject the machine check to specified vcpu */
+	irq.type = KVM_S390_MCHK;
+	rc = kvm_s390_inject_vcpu(vcpu, &irq);
 	WARN_ON_ONCE(rc);
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 311/556] KVM: s390: keyop: use mmu_lock to read gmap->asce
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (309 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 310/556] KVM: s390: Fix memory corruption by not reinjecting CK machine checks Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 312/556] KVM: s390: pv: Fix rc/rrc offset for PVM_DUMP Greg Kroah-Hartman
                   ` (257 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Christian Borntraeger,
	Claudio Imbrenda

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christian Borntraeger <borntraeger@linux.ibm.com>

commit da07a751efa4583385f9f0f47113549fe8871242 upstream.

Every other dat_* consumer in this file (kvm_s390_get_skeys,
set_skeys, get_cmma_bits, set_cmma_bits, MEM_CLR_CMMA,
kvm_s390_fixup_prefix, kvm_test_age_gfn, kvm_age_gfn) reads
kvm->arch.gmap->asce *inside* the mmu_lock read-side. keyop is the only
outlier.

gmap->asce is mutated under write_lock(mmu_lock) by gmap_set_limit()
and keyop might use a stale asce value for walking as KVM_S390_KEYOP
and KVM_S390_VM_MEM_LIMIT_SIZE can run concurrently. This can result
in memory corruption.

Fixes: 0ee4ddc1647b ("KVM: s390: Storage key manipulation IOCTL")
Cc: stable@vger.kernel.org
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Message-ID: <20260811153738.206885-2-borntraeger@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/s390/kvm/kvm-s390.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/arch/s390/kvm/kvm-s390.c
+++ b/arch/s390/kvm/kvm-s390.c
@@ -562,11 +562,12 @@ static void __kvm_s390_exit(void)
 static int kvm_s390_keyop(struct kvm_s390_mmu_cache *mc, struct kvm *kvm, int op,
 			  unsigned long addr, union skey skey)
 {
-	union asce asce = kvm->arch.gmap->asce;
 	gfn_t gfn = gpa_to_gfn(addr);
+	union asce asce;
 	int r;
 
 	guard(read_lock)(&kvm->mmu_lock);
+	asce = kvm->arch.gmap->asce;
 
 	switch (op) {
 	case KVM_S390_KEYOP_SSKE:



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 312/556] KVM: s390: pv: Fix rc/rrc offset for PVM_DUMP
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (310 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 311/556] KVM: s390: keyop: use mmu_lock to read gmap->asce Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 313/556] KVM: s390: Restore sigset on error path Greg Kroah-Hartman
                   ` (256 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Christian Borntraeger,
	Claudio Imbrenda

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christian Borntraeger <borntraeger@linux.ibm.com>

commit 1e3c8e7b3465fb8a49d3623d2d0f449c0b5b48f3 upstream.

The rc/rrc value is copied to the cmd location of the cmd in the kvm_pv_cmd
structure. Fix the offset.

Fixes: 8aba09588d2a ("KVM: s390: Add CPU dump functionality")
Cc: stable@vger.kernel.org
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Message-ID: <20260811153738.206885-4-borntraeger@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/s390/kvm/kvm-s390.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/arch/s390/kvm/kvm-s390.c
+++ b/arch/s390/kvm/kvm-s390.c
@@ -5736,7 +5736,7 @@ long kvm_arch_vcpu_ioctl(struct file *fi
 		r = kvm_s390_handle_pv_vcpu_dump(vcpu, &cmd);
 
 		/* Always copy over UV rc / rrc data */
-		if (copy_to_user((__u8 __user *)argp, &cmd.rc,
+		if (copy_to_user(argp + offsetof(struct kvm_pv_cmd, rc), &cmd.rc,
 				 sizeof(cmd.rc) + sizeof(cmd.rrc)))
 			r = -EFAULT;
 		break;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 313/556] KVM: s390: Restore sigset on error path
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (311 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 312/556] KVM: s390: pv: Fix rc/rrc offset for PVM_DUMP Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 314/556] KVM: arm64: Consider SCTLR_EL2.M when mapping the L1 VNCR page Greg Kroah-Hartman
                   ` (255 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Christian Borntraeger,
	Claudio Imbrenda

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christian Borntraeger <borntraeger@linux.ibm.com>

commit c44d36d8e6501c4934412d9014e5e02da9efdb8f upstream.

kvm_sigset_activate() installs vcpu->sigset via sigprocmask() and
stashes the caller's mask in current->real_blocked; only
kvm_sigset_deactivate() restores it.

For KVM_RUN on a STOPPED vcpu the error path will not restore the
userspace mask.  Re-arrange the error handling to also restore the
signal mask.

Fixes: 6352e4d2dd9a3 ("KVM: s390: implement KVM_(S|G)ET_MP_STATE for user space state control")
Cc: stable@vger.kernel.org
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Message-ID: <20260811153738.206885-5-borntraeger@linux.ibm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/s390/kvm/kvm-s390.c |    6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

--- a/arch/s390/kvm/kvm-s390.c
+++ b/arch/s390/kvm/kvm-s390.c
@@ -5073,7 +5073,7 @@ int kvm_arch_vcpu_ioctl_run(struct kvm_v
 		pr_err_ratelimited("can't run stopped vcpu %d\n",
 				   vcpu->vcpu_id);
 		rc = -EINVAL;
-		goto out;
+		goto out_sigset;
 	}
 
 	kernel_fpu_begin(&fpu, KERNEL_FPC | KERNEL_VXR);
@@ -5103,9 +5103,11 @@ int kvm_arch_vcpu_ioctl_run(struct kvm_v
 	store_regs(vcpu);
 	kernel_fpu_end(&fpu, KERNEL_FPC | KERNEL_VXR);
 
+	vcpu->stat.exit_userspace++;
+
+out_sigset:
 	kvm_sigset_deactivate(vcpu);
 
-	vcpu->stat.exit_userspace++;
 out:
 	vcpu_put(vcpu);
 	return rc;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 314/556] KVM: arm64: Consider SCTLR_EL2.M when mapping the L1 VNCR page
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (312 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 313/556] KVM: s390: Restore sigset on error path Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 315/556] KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation Greg Kroah-Hartman
                   ` (254 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Marc Zyngier, Oliver Upton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Marc Zyngier <maz@kernel.org>

commit 8c774604b6ecaca495fa3d27c21593269627f48f upstream.

We record a VNCR TLB even when SCTLR_EL2.M is 0 in order to make
our life easier. But this is not something that the architecture
anticipate.

As a consequence, a hypervisor is free to set VNCR_EL2 to
some PA when SCTLR_EL2.M==0, use it to run a guest which indirectly
accesses the VNCR page, then eventually set SCTLR_EL2.M==1 with
the same VA. Yes, this is odd, but apparently legal.

A common trick in HW is to invalidate the TLBs on SCTLR_ELx.M being
flipped. But doing this is a not a good idea for us (we'd need to
trap SCTLR accesses), and wouldn't scale as we nest deeper.

Instead, use the fact that the S1 MMU being off at the point of
translation is cached in our TLB, and if it doesn't match the current
MMU state, leave the VNCR unmapped.

Fixes: 2a359e072596f ("KVM: arm64: nv: Handle mapping of VNCR_EL2 at EL2")
Signed-off-by: Marc Zyngier <maz@kernel.org>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260806091026.620700-4-maz@kernel.org
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/arm64/include/asm/kvm_nested.h |    7 +++++++
 arch/arm64/kvm/at.c                 |    2 --
 arch/arm64/kvm/nested.c             |    4 ++++
 3 files changed, 11 insertions(+), 2 deletions(-)

--- a/arch/arm64/include/asm/kvm_nested.h
+++ b/arch/arm64/include/asm/kvm_nested.h
@@ -388,6 +388,8 @@ struct s1_walk_result {
 	bool	failed;
 };
 
+#define S1_MMU_DISABLED		(-127)
+
 static inline void fail_s1_walk(struct s1_walk_result *wr, u8 fst, bool s1ptw)
 {
 	wr->fst		= fst;
@@ -396,6 +398,11 @@ static inline void fail_s1_walk(struct s
 	wr->failed	= true;
 }
 
+static inline bool s1_walk_translated(struct s1_walk_result *wr)
+{
+	return wr->level != S1_MMU_DISABLED;
+}
+
 int __kvm_translate_va(struct kvm_vcpu *vcpu, struct s1_walk_info *wi,
 		       struct s1_walk_result *wr, u64 va);
 int __kvm_find_s1_desc_level(struct kvm_vcpu *vcpu, u64 va, u64 ipa,
--- a/arch/arm64/kvm/at.c
+++ b/arch/arm64/kvm/at.c
@@ -11,8 +11,6 @@
 #include <asm/kvm_mmu.h>
 #include <asm/lsui.h>
 
-#define S1_MMU_DISABLED		(-127)
-
 static int get_ia_size(struct s1_walk_info *wi)
 {
 	return 64 - wi->txsz;
--- a/arch/arm64/kvm/nested.c
+++ b/arch/arm64/kvm/nested.c
@@ -1568,6 +1568,10 @@ static void kvm_map_l1_vncr(struct kvm_v
 	if (!vt->valid)
 		return;
 
+	/* We cache the MMU state in the TLB. Check that it matches. */
+	if (!!(vcpu_read_sys_reg(vcpu, SCTLR_EL2) & SCTLR_ELx_M) != s1_walk_translated(&vt->wr))
+		return;
+
 	if (read_vncr_el2(vcpu) != vt->gva)
 		return;
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 315/556] KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (313 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 314/556] KVM: arm64: Consider SCTLR_EL2.M when mapping the L1 VNCR page Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 316/556] KVM: arm64: Correctly handle end of VA space TLBI invalidation Greg Kroah-Hartman
                   ` (253 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Hyunwoo Kim, Marc Zyngier,
	Oliver Upton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Marc Zyngier <maz@kernel.org>

commit 8053393680d4fa3eb962667d2be95dd39f0940e5 upstream.

Computing the effects of a TLB invalidation involves looking at
the size of the mapping cached by the TLB. For S1 mappings such as
VNCR, this is deducted from the combination of the base granule size
and the mapping level.

However, this implies that the S1 MMU is *on*. When the MMU is off,
we indicate this with the level being set to a "creative" value of
-127 (S1_MMU_DISABLED).

This ends-up being misinterpreted by pgshift_level_to_ttl() as it
doesn't handle negative levels at all (the level is immediately cast
to a u8 and only the bottom two bits considered), leading to an
invalidation size of 0. Not helpful.

Tidy-up pgshift_level_to_ttl() to handle these negative levels, and
ttl_to_size() to always return SZ_1G when no valid TTL is present.
This allows the removal of open-coded checks for similar situations.

Note that the check for a negative value not explicitely checking for
S1_MMU_DISABLED is deliberate, so that actual negative levels introduced
with LVA2 and D128 can take the same path if we ever support them.

Fixes: 7270cc9157f47 ("KVM: arm64: nv: Handle VNCR_EL2 invalidation from MMU notifiers")
Reported-by: Hyunwoo Kim <imv4bel@gmail.com>
Link: https://lore.kernel.org/r/ameGoxbn2wzBq2kL@v4bel
Signed-off-by: Marc Zyngier <maz@kernel.org>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260806091026.620700-3-maz@kernel.org
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/arm64/kvm/nested.c |   26 +++++++++++++++++++-------
 1 file changed, 19 insertions(+), 7 deletions(-)

--- a/arch/arm64/kvm/nested.c
+++ b/arch/arm64/kvm/nested.c
@@ -506,7 +506,7 @@ int kvm_walk_nested_s2(struct kvm_vcpu *
 	return ret;
 }
 
-static unsigned int ttl_to_size(u8 ttl)
+static unsigned int __ttl_to_size(u8 ttl)
 {
 	int level = ttl & 3;
 	int gran = (ttl >> 2) & 3;
@@ -562,10 +562,22 @@ static unsigned int ttl_to_size(u8 ttl)
 	return max_size;
 }
 
-static u8 pgshift_level_to_ttl(u16 shift, u8 level)
+static unsigned int ttl_to_size(u8 ttl)
+{
+	return __ttl_to_size(ttl) ?: SZ_1G;
+}
+
+static u8 pgshift_level_to_ttl(u16 shift, s8 level)
 {
 	u8 ttl;
 
+	/*
+	 * If we don't have a proper level, fallback to the maximum
+	 * size.
+	 */
+	if (level < 0)
+		return 0;
+
 	switch(shift) {
 	case 12:
 		ttl = TLBI_TTL_TG_4K;
@@ -676,7 +688,11 @@ unsigned long compute_tlb_inval_range(st
 		ttl = get_guest_mapping_ttl(mmu, addr);
 	}
 
-	max_size = ttl_to_size(ttl);
+	/*
+	 * Don't use the default 1GB fallback, as we can adapt to the
+	 * max mapping size we allow at S2.
+	 */
+	max_size = __ttl_to_size(ttl);
 
 	if (!max_size) {
 		/* Compute the maximum extent of the invalidation */
@@ -1126,8 +1142,6 @@ static void compute_s1_tlbi_range(struct
 	case OP_TLBI_VALE1OSNXS:
 		scope->type = TLBI_VA;
 		scope->size = ttl_to_size(FIELD_GET(TLBI_TTL_MASK, val));
-		if (!scope->size)
-			scope->size = SZ_1G;
 		scope->va = tlbi_va_s1_to_va(val) & ~(scope->size - 1);
 		scope->asid = FIELD_GET(TLBIR_ASID_MASK, val);
 		break;
@@ -1154,8 +1168,6 @@ static void compute_s1_tlbi_range(struct
 	case OP_TLBI_VAALE1OSNXS:
 		scope->type = TLBI_VAA;
 		scope->size = ttl_to_size(FIELD_GET(TLBI_TTL_MASK, val));
-		if (!scope->size)
-			scope->size = SZ_1G;
 		scope->va = tlbi_va_s1_to_va(val) & ~(scope->size - 1);
 		break;
 	case OP_TLBI_RVAE2:



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 316/556] KVM: arm64: Correctly handle end of VA space TLBI invalidation
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (314 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 315/556] KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 317/556] KVM: arm64: Handle VNCR TLB invalidation race with vcpu_put() VNCR unmapping Greg Kroah-Hartman
                   ` (252 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Yuan Yao, Marc Zyngier, Oliver Upton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Marc Zyngier <maz@kernel.org>

commit 34af2c3e31f91a739dc175459fdbd99ed952b457 upstream.

Our TLB invalidation by VA code is based on comparing two ranges,
one defined by the TLB, and one defined by the TLBI instruction.

Each range is defined by a start and a size. However, the way the
comparison is done doesn't account for address rollover, as it
compares an address with (base + size). This works nicely until
this expression represent the last page/block in the TTBR1 VA space,
as the result is a big fat 0. And a failed TLB invalidation.

Rewrite the comparison in a way that is immune to the address
rollover (making the end address inclusive instead of exclusive),
and move this into a common helper that is used by both VA and IPA
invalidations, as suggested by Hyunwoo Kim (although the IPA version
didn't suffer from this particular problem, obviously).

Fixes: 4ffa72ad8f37e ("KVM: arm64: nv: Add S1 TLB invalidation primitive for VNCR_EL2")
Reviewed-by: Yuan Yao <yaoyuan@linux.alibaba.com>
Signed-off-by: Marc Zyngier <maz@kernel.org>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260806091026.620700-5-maz@kernel.org
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/arm64/kvm/nested.c |   43 +++++++++++++++++++------------------------
 1 file changed, 19 insertions(+), 24 deletions(-)

--- a/arch/arm64/kvm/nested.c
+++ b/arch/arm64/kvm/nested.c
@@ -1001,6 +1001,20 @@ static void invalidate_vncr(struct vncr_
 		clear_fixmap(vncr_fixmap(vt->cpu));
 }
 
+static bool vncr_tlb_intersects(struct vncr_tlb *vt, u64 addr,
+				u64 scope_start, u64 scope_size)
+{
+	u64 tlb_size, tlb_start, tlb_end, scope_end;
+
+	tlb_size = ttl_to_size(pgshift_level_to_ttl(vt->wi.pgshift, vt->wr.level));
+
+	tlb_start = addr & ~(tlb_size - 1);
+	tlb_end = tlb_start + tlb_size - 1;
+	scope_end = scope_start + scope_size - 1;
+
+	return !(tlb_end < scope_start || tlb_start > scope_end);
+}
+
 /*
  * VNCR TLB invalidation occurs from MMU notifiers or TLBI instructions, and
  * either can race against a vcpu not being onlined yet (no pseudo-TLB
@@ -1023,19 +1037,9 @@ static void kvm_invalidate_vncr_ipa(stru
 	if (!kvm_has_feat(kvm, ID_AA64MMFR4_EL1, NV_frac, NV2_ONLY))
 		return;
 
-	kvm_for_each_vncr_tlb(i, vcpu, vt, kvm) {
-		u64 ipa_start, ipa_end, ipa_size;
-
-		ipa_size = ttl_to_size(pgshift_level_to_ttl(vt->wi.pgshift,
-							    vt->wr.level));
-		ipa_start = vt->wr.pa & ~(ipa_size - 1);
-		ipa_end = ipa_start + ipa_size;
-
-		if (ipa_end <= start || ipa_start >= end)
-			continue;
-
-		invalidate_vncr(vt);
-	}
+	kvm_for_each_vncr_tlb(i, vcpu, vt, kvm)
+		if (vncr_tlb_intersects(vt, vt->wr.pa, start, end - start))
+			invalidate_vncr(vt);
 }
 
 struct s1e2_tlbi_scope {
@@ -1061,28 +1065,19 @@ static void invalidate_vncr_va(struct kv
 	lockdep_assert_held_write(&kvm->mmu_lock);
 
 	kvm_for_each_vncr_tlb(i, vcpu, vt, kvm) {
-		u64 va_start, va_end, va_size;
-
-		va_size = ttl_to_size(pgshift_level_to_ttl(vt->wi.pgshift,
-							   vt->wr.level));
-		va_start = vt->gva & ~(va_size - 1);
-		va_end = va_start + va_size;
-
 		switch (scope->type) {
 		case TLBI_ALL:
 			break;
 
 		case TLBI_VA:
-			if (va_end <= scope->va ||
-			    va_start >= (scope->va + scope->size))
+			if (!vncr_tlb_intersects(vt, vt->gva, scope->va, scope->size))
 				continue;
 			if (vt->wr.nG && vt->wr.asid != scope->asid)
 				continue;
 			break;
 
 		case TLBI_VAA:
-			if (va_end <= scope->va ||
-			    va_start >= (scope->va + scope->size))
+			if (!vncr_tlb_intersects(vt, vt->gva, scope->va, scope->size))
 				continue;
 			break;
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 317/556] KVM: arm64: Handle VNCR TLB invalidation race with vcpu_put() VNCR unmapping
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (315 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 316/556] KVM: arm64: Correctly handle end of VA space TLBI invalidation Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 318/556] KVM: arm64: Make VNCR invalidation participate in MMU invalidation retry Greg Kroah-Hartman
                   ` (251 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Marc Zyngier, Yuan Yao,
	Oliver Upton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Marc Zyngier <maz@kernel.org>

commit 38640bc32be3fcf9526d477155bc19d3f146231f upstream.

While VNCR TLB invalidation always occurs under the MMU lock,
vcpu_put() doesn't, while it unmaps the VNCR page.

The problem is that the invalidation evaluates vncr_tlb::cpu to
decide whether an unmapping needs to take place (cpu != -1) before
performing it. On the other hand, this_cpu_reset_vncr_fixmap()
unconditionally unmaps if L1_VNCR_MAPPED is set.

These two obviously can race, with a TOCTOU pattern on the TLBI
path, and a BUG_ON() on the vcpu_put() path. And the two can end-up
calling vncr_fixmap(-1), with extra lethal effects.

Move the reset of vncr_tlb::cpu to -1 to a common function, and make
this update atomic so that only a single thread can reset the field
and perform the corresponding unmap. The vcpu_put() still need to
unconditionally unmap the current VNCR to close another ugly race.

Finally, the assignment of vncr_tlb::cpu is moved to be kept in sync
with the actual mapping, similar to L1_VNCR_MAPPED being set.

Fixes: 7270cc9157f47 ("KVM: arm64: nv: Handle VNCR_EL2 invalidation from MMU notifiers")
Reported-by: sashiko-bot@kernel.org
Link: https://lore.kernel.org/r/20260801130237.0FD8F1F00ACA@smtp.kernel.org
Signed-off-by: Marc Zyngier <maz@kernel.org>
Cc: stable@vger.kernel.org
Reviewed-by: Yuan Yao <yaoyuan@linux.alibaba.com>
Link: https://patch.msgid.link/20260806091026.620700-6-maz@kernel.org
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/arm64/kvm/nested.c |   42 ++++++++++++++++++++++++++++++++----------
 1 file changed, 32 insertions(+), 10 deletions(-)

--- a/arch/arm64/kvm/nested.c
+++ b/arch/arm64/kvm/nested.c
@@ -27,7 +27,7 @@ struct vncr_tlb {
 	bool			hpa_writable;
 
 	/* -1 when not mapped on a CPU */
-	int			cpu;
+	atomic_t		cpu;
 
 	/*
 	 * true if the TLB is valid. Can only be changed with the
@@ -895,16 +895,40 @@ void kvm_vcpu_load_hw_mmu(struct kvm_vcp
 	}
 }
 
+/*
+ * Unmapping an L1 VNCR can happen concurrently without the mmu lock being
+ * effective (vcpu_put() vs TLBI handling). The atomic_xchg below ensures
+ * that only one CPU sets it to -1 while getting a valid CPU number back.
+ */
+static int unmap_l1_vncr(struct vncr_tlb *vt)
+{
+	int cpu = atomic_xchg_relaxed(&vt->cpu, -1);
+
+	if (cpu != -1)
+		clear_fixmap(vncr_fixmap(cpu));
+
+	return cpu;
+}
+
 static void this_cpu_reset_vncr_fixmap(struct kvm_vcpu *vcpu)
 {
 	if (!host_data_test_flag(L1_VNCR_MAPPED))
 		return;
 
-	BUG_ON(vcpu->arch.vncr_tlb->cpu != smp_processor_id());
 	BUG_ON(is_hyp_ctxt(vcpu));
 
-	clear_fixmap(vncr_fixmap(vcpu->arch.vncr_tlb->cpu));
-	vcpu->arch.vncr_tlb->cpu = -1;
+	/*
+	 * Unconditionally unmap the local VNCR if we have lost the race
+	 * against a concurrent TLBI. Otherwise we could end-up running
+	 * another vcpu with VNCR still mapped if the TLBI thread is
+	 * preempted between the exchange and the clear_fixmap().
+	 *
+	 * Note that we do not care about the TLBI nuking the fixmap behind
+	 * the back of an running vcpu. This will only generate a fault and
+	 * possibly a retranslation.
+	 */
+	if (unmap_l1_vncr(vcpu->arch.vncr_tlb) == -1)
+		clear_fixmap(vncr_fixmap(smp_processor_id()));
 	host_data_clear_flag(L1_VNCR_MAPPED);
 	atomic_dec(&vcpu->kvm->arch.vncr_map_count);
 }
@@ -997,8 +1021,7 @@ u16 get_asid_by_regime(struct kvm_vcpu *
 static void invalidate_vncr(struct vncr_tlb *vt)
 {
 	vt->valid = false;
-	if (vt->cpu != -1)
-		clear_fixmap(vncr_fixmap(vt->cpu));
+	unmap_l1_vncr(vt);
 }
 
 static bool vncr_tlb_intersects(struct vncr_tlb *vt, u64 addr,
@@ -1454,7 +1477,7 @@ static int kvm_translate_vncr(struct kvm
 		vt->hpa = pfn << PAGE_SHIFT;
 		vt->hpa_writable = writable;
 		vt->valid = true;
-		vt->cpu = -1;
+		atomic_set(&vt->cpu, -1);
 
 		kvm_make_request(KVM_REQ_MAP_L1_VNCR_EL2, vcpu);
 		kvm_release_faultin_page(vcpu->kvm, page, false, vt->wr.pw && vt->hpa_writable);
@@ -1585,8 +1608,6 @@ static void kvm_map_l1_vncr(struct kvm_v
 	if (vt->wr.nG && get_asid_by_regime(vcpu, TR_EL20) != vt->wr.asid)
 		return;
 
-	vt->cpu = smp_processor_id();
-
 	if (vt->hpa_writable && vt->wr.pw && vt->wr.pr)
 		prot = PAGE_KERNEL;
 	else if (vt->wr.pr)
@@ -1601,7 +1622,8 @@ static void kvm_map_l1_vncr(struct kvm_v
 	 * FIXME: WO doesn't work at all, need POE support in the kernel.
 	 */
 	if (pgprot_val(prot) != pgprot_val(PAGE_NONE)) {
-		__set_fixmap(vncr_fixmap(vt->cpu), vt->hpa, prot);
+		atomic_set(&vt->cpu, smp_processor_id());
+		__set_fixmap(vncr_fixmap(atomic_read(&vt->cpu)), vt->hpa, prot);
 		host_data_set_flag(L1_VNCR_MAPPED);
 		atomic_inc(&vcpu->kvm->arch.vncr_map_count);
 	}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 318/556] KVM: arm64: Make VNCR invalidation participate in MMU invalidation retry
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (316 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 317/556] KVM: arm64: Handle VNCR TLB invalidation race with vcpu_put() VNCR unmapping Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:39 ` [PATCH 7.2 319/556] KVM: arm64: Remove VM-wide VNCR mapping counter Greg Kroah-Hartman
                   ` (250 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, sashiko-bot, Marc Zyngier,
	Oliver Upton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Marc Zyngier <maz@kernel.org>

commit 2b7324f3a0c1072b9d578b8d42f199506753f26e upstream.

A VNCR TLB invalidation can occur on one vcpu while another vcpu is
faulting in this same page. Without correctly handling this, we can
end up with the following scenario:

- vcpu A walks the PTs to translate VNCR
- before vcpu A is able to grab the MMU lock to insert the TLB,
  vcpu B updates the S1 PTs with an invalid entry, and issues
  a TLBI S1E2 for this VA
- vcpu A inserts the TLB for something that is now invalid

This isn't a new problem, and we manage S2 by having the MMU notifier
to bump up mmu_invalidate_seq on invalidation so that the fault can be
replayed.

We can perform something similar here, and extend invalidate_vncr_va() to
update the same counter, clearly indicating that the context has
changed under our feet. This is safe as the invalidation always happen
while holding the MMU lock for write, and that we sample the sequence
number before walking S1.

Fixes: 4ffa72ad8f37e ("KVM: arm64: nv: Add S1 TLB invalidation primitive for VNCR_EL2")
Reported-by: sashiko-bot@kernel.org
Link: https://lore.kernel.org/r/20260801130454.5D9F11F00AC4@smtp.kernel.org
Signed-off-by: Marc Zyngier <maz@kernel.org>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260806091026.620700-8-maz@kernel.org
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/arm64/kvm/nested.c |   21 ++++++++++++++++++---
 1 file changed, 18 insertions(+), 3 deletions(-)

--- a/arch/arm64/kvm/nested.c
+++ b/arch/arm64/kvm/nested.c
@@ -1060,6 +1060,12 @@ static void kvm_invalidate_vncr_ipa(stru
 	if (!kvm_has_feat(kvm, ID_AA64MMFR4_EL1, NV_frac, NV2_ONLY))
 		return;
 
+	/*
+	 * Note that invalidating the VNCR on the back of an MMU notifier
+	 * doesn't require messing with the invalidation counter for a
+	 * parallel walk. The notifier itself will have bumped the counter,
+	 * making sure we rewalk.
+	 */
 	kvm_for_each_vncr_tlb(i, vcpu, vt, kvm)
 		if (vncr_tlb_intersects(vt, vt->wr.pa, start, end - start))
 			invalidate_vncr(vt);
@@ -1087,6 +1093,15 @@ static void invalidate_vncr_va(struct kv
 
 	lockdep_assert_held_write(&kvm->mmu_lock);
 
+	/*
+	 * We might be performing a parallel S1 walk, so bump up the
+	 * invalidation counter even in the absence of an actual VNCR TLB
+	 * invalidation, as this could indicate that the guest has gone
+	 * through a BBM sequence.
+	 */
+	kvm->mmu_invalidate_seq++;
+	smp_wmb();
+
 	kvm_for_each_vncr_tlb(i, vcpu, vt, kvm) {
 		switch (scope->type) {
 		case TLBI_ALL:
@@ -1421,15 +1436,15 @@ static int kvm_translate_vncr(struct kvm
 
 	va =  read_vncr_el2(vcpu);
 
+	mmu_seq = vcpu->kvm->mmu_invalidate_seq;
+	smp_rmb();
+
 	ret = __kvm_translate_va(vcpu, &vt->wi, &vt->wr, va);
 	if (ret)
 		return ret;
 
 	write_fault = kvm_is_write_fault(vcpu);
 
-	mmu_seq = vcpu->kvm->mmu_invalidate_seq;
-	smp_rmb();
-
 	gfn = vt->wr.pa >> PAGE_SHIFT;
 	memslot = gfn_to_memslot(vcpu->kvm, gfn);
 	if (!memslot) {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 319/556] KVM: arm64: Remove VM-wide VNCR mapping counter
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (317 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 318/556] KVM: arm64: Make VNCR invalidation participate in MMU invalidation retry Greg Kroah-Hartman
@ 2026-09-09 13:39 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 320/556] KVM: arm64: Sign-extend VA for range-based TLBI invalidation Greg Kroah-Hartman
                   ` (249 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:39 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yuan Yao, Marc Zyngier,
	Lorenzo Stoakes (ARM), Oliver Upton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Marc Zyngier <maz@kernel.org>

commit c55bc773b6e814406658fae7dc5c15f639ed816e upstream.

The global VNCR mapping counter is used to decide whether an L1
provided VNCR page is mapped in L0 on any CPU at the point of
dealing with a TLB invalidation. It is incremented when a mapping
is made in the fixmap, and decremented when unmapped.

As it turns out, this tracking has several flaws:

- we are trying to invalidate TLBs, and the mapping is only an
  opportunistic consequence of the TLB. Checking this counter to
  decide whether a TLB needs to be invalidated may result in missed
  invalidations.

- an L1 vcpu invalidating its own TLB (a very likely case) will not
  succeed in invalidating the VNCR pseudo TLB because that page is
  not mapped in L0 at this stage.

Given that this tracking fails at delivering the minimum guarantees
that are required and is only a performance optimisation, remove it
completely.

Fixes: 4ffa72ad8f37e ("KVM: arm64: nv: Add S1 TLB invalidation primitive for VNCR_EL2")
Reviewed-by: Yuan Yao <yaoyuan@linux.alibaba.com>
Signed-off-by: Marc Zyngier <maz@kernel.org>
Cc: stable@vger.kernel.org
Acked-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Link: https://patch.msgid.link/20260806091026.620700-2-maz@kernel.org
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/arm64/include/asm/kvm_host.h |    3 ---
 arch/arm64/kvm/hyp/vhe/switch.c   |    3 +--
 arch/arm64/kvm/nested.c           |    3 ---
 3 files changed, 1 insertion(+), 8 deletions(-)

--- a/arch/arm64/include/asm/kvm_host.h
+++ b/arch/arm64/include/asm/kvm_host.h
@@ -411,9 +411,6 @@ struct kvm_arch {
 	/* Masks for VNCR-backed and general EL2 sysregs */
 	struct kvm_sysreg_masks	*sysreg_masks;
 
-	/* Count the number of VNCR_EL2 currently mapped */
-	atomic_t vncr_map_count;
-
 	/*
 	 * For an untrusted host VM, 'pkvm.handle' is used to lookup
 	 * the associated pKVM instance in the hypervisor.
--- a/arch/arm64/kvm/hyp/vhe/switch.c
+++ b/arch/arm64/kvm/hyp/vhe/switch.c
@@ -427,8 +427,7 @@ static bool kvm_hyp_handle_tlbi_el2(stru
 	 * If we have to check for any VNCR mapping being invalidated,
 	 * go back to the slow path for further processing.
 	 */
-	if (vcpu_el2_e2h_is_set(vcpu) && vcpu_el2_tge_is_set(vcpu) &&
-	    atomic_read(&vcpu->kvm->arch.vncr_map_count))
+	if (vcpu_el2_e2h_is_set(vcpu) && vcpu_el2_tge_is_set(vcpu))
 		return false;
 
 	__kvm_skip_instr(vcpu);
--- a/arch/arm64/kvm/nested.c
+++ b/arch/arm64/kvm/nested.c
@@ -48,7 +48,6 @@ void kvm_init_nested(struct kvm *kvm)
 {
 	kvm->arch.nested_mmus = NULL;
 	kvm->arch.nested_mmus_size = 0;
-	atomic_set(&kvm->arch.vncr_map_count, 0);
 }
 
 static int init_nested_s2_mmu(struct kvm *kvm, struct kvm_s2_mmu *mmu)
@@ -930,7 +929,6 @@ static void this_cpu_reset_vncr_fixmap(s
 	if (unmap_l1_vncr(vcpu->arch.vncr_tlb) == -1)
 		clear_fixmap(vncr_fixmap(smp_processor_id()));
 	host_data_clear_flag(L1_VNCR_MAPPED);
-	atomic_dec(&vcpu->kvm->arch.vncr_map_count);
 }
 
 void kvm_vcpu_put_hw_mmu(struct kvm_vcpu *vcpu)
@@ -1640,7 +1638,6 @@ static void kvm_map_l1_vncr(struct kvm_v
 		atomic_set(&vt->cpu, smp_processor_id());
 		__set_fixmap(vncr_fixmap(atomic_read(&vt->cpu)), vt->hpa, prot);
 		host_data_set_flag(L1_VNCR_MAPPED);
-		atomic_inc(&vcpu->kvm->arch.vncr_map_count);
 	}
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 320/556] KVM: arm64: Sign-extend VA for range-based TLBI invalidation
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (318 preceding siblings ...)
  2026-09-09 13:39 ` [PATCH 7.2 319/556] KVM: arm64: Remove VM-wide VNCR mapping counter Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 321/556] KVM: arm64: vgic-v3: take an LPI reference in vgic_v3_save_pending_tables Greg Kroah-Hartman
                   ` (248 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, sashiko-bot, Marc Zyngier,
	Oliver Upton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Marc Zyngier <maz@kernel.org>

commit 2393470085649f0b973ecceb26fe8fc71edde0c1 upstream.

When the decode_range_tlbi() helper was moved to be used for S1 TLBIs,
the required sign extension was omitted. Add it.

As a result, special care must be taken to not overflow PA bits when
this is used for S2 invalidation.

Fixes: 85bba00425ae0 ("KVM: arm64: nv: Move TLBI range decoding to a helper")
Reported-by: sashiko-bot@kernel.org
Link: https://lore.kernel.org/r/20260801130337.EB2BA1F00AC4@smtp.kernel.org
Signed-off-by: Marc Zyngier <maz@kernel.org>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260806091026.620700-7-maz@kernel.org
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/arm64/include/asm/kvm_nested.h |    7 +++++++
 arch/arm64/kvm/sys_regs.c           |   11 +++++++++++
 2 files changed, 18 insertions(+)

--- a/arch/arm64/include/asm/kvm_nested.h
+++ b/arch/arm64/include/asm/kvm_nested.h
@@ -291,6 +291,13 @@ static inline u64 decode_range_tlbi(u64
 
 	base	= (val & GENMASK(36, 0)) << shift;
 
+	/*
+	 * We only deal with at most 48bit VA/IPA, so 48 is where we
+	 * sign-extend from. Should we support FEAT_L{VP}A* at some point,
+	 * this will need to be revisited.
+	 */
+	base	= (u64)sign_extend64(base, 48);
+
 	if (asid)
 		*asid = FIELD_GET(TLBIR_ASID_MASK, val);
 
--- a/arch/arm64/kvm/sys_regs.c
+++ b/arch/arm64/kvm/sys_regs.c
@@ -4057,6 +4057,7 @@ static bool handle_ripas2e1is(struct kvm
 	u32 sys_encoding = sys_insn(p->Op0, p->Op1, p->CRn, p->CRm, p->Op2);
 	u64 vttbr = vcpu_read_sys_reg(vcpu, VTTBR_EL2);
 	u64 base, range;
+	int pa_bits;
 
 	if (!kvm_supported_tlbi_ipas2_op(vcpu, sys_encoding))
 		return undef_access(vcpu, p, r);
@@ -4068,6 +4069,16 @@ static bool handle_ripas2e1is(struct kvm
 	 */
 	base = decode_range_tlbi(p->regval, &range, NULL);
 
+	/*
+	 * Ignore TLBIs that start out of PA_bits range, and cap the
+	 * invalidation to the [base:bit(PA_bits)] interval.
+	 */
+	pa_bits = kvm_get_pa_bits(vcpu->kvm);
+	if (fls64(base) > pa_bits)
+		return true;
+
+	range = min(range, BIT_ULL(pa_bits) - base);
+
 	kvm_s2_mmu_iterate_by_vmid(vcpu->kvm, get_vmid(vttbr),
 				   &(union tlbi_info) {
 					   .range = {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 321/556] KVM: arm64: vgic-v3: take an LPI reference in vgic_v3_save_pending_tables
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (319 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 320/556] KVM: arm64: Sign-extend VA for range-based TLBI invalidation Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 322/556] KVM: arm64: vgic: Fix detection of MI on no pending LR Greg Kroah-Hartman
                   ` (247 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Qihang, Marc Zyngier, Oliver Upton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Qihang <q.h.hack.winter@gmail.com>

commit f5b8f203bfc07a5a257dff859e66d2c500f9f509 upstream.

vgic_v3_save_pending_tables() iterates dist->lpi_xa using xa_for_each()
and dereferences the returned struct vgic_irq in the loop body without
holding a reference on the LPI.

The xarray iterator only provides temporary RCU coverage while looking up
the current entry. That is not sufficient for this loop body, which reads
fields from struct vgic_irq and performs guest memory accesses before the
iteration completes.

A concurrent path can trigger this race: the irqfd cached injection path
(vgic_its_inject_cached_translation) obtains a transient LPI reference
via vgic_its_check_cache() without holding kvm->lock, vcpu->mutex,
config_lock, or its_lock. If guest ITS DISCARD then drops the cache and
ITE references under its_lock, the transient inject reference may become
the final one. When vgic_put_irq() drops it, the LPI is erased from
lpi_xa and freed via kfree_rcu(). Meanwhile, vgic_v3_save_pending_tables()
may still hold a stale pointer obtained from the xarray iterator and
dereference it after the RCU grace period completes.

Fix this by re-fetching each iterated LPI via vgic_get_irq(), which takes
a stable reference, and dropping it with vgic_put_irq() on all paths.
This matches the pattern already used by other lpi_xa iterators in the
vgic ITS code.

Cc: stable@vger.kernel.org
Signed-off-by: Qihang <q.h.hack.winter@gmail.com>
Reviewed-by: Marc Zyngier <maz@kernel.org>
Link: https://patch.msgid.link/20260807025534.34125-1-q.h.hack.winter@gmail.com
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/arm64/kvm/vgic/vgic-v3.c |   12 +++++++++---
 1 file changed, 9 insertions(+), 3 deletions(-)

--- a/arch/arm64/kvm/vgic/vgic-v3.c
+++ b/arch/arm64/kvm/vgic/vgic-v3.c
@@ -617,9 +617,13 @@ int vgic_v3_save_pending_tables(struct k
 		bool is_pending;
 		bool stored;
 
+		irq = vgic_get_irq(kvm, index);
+		if (!irq)
+			continue;
+
 		vcpu = irq->target_vcpu;
 		if (!vcpu)
-			continue;
+			goto put_irq;
 
 		pendbase = GICR_PENDBASER_ADDRESS(vcpu->arch.vgic_cpu.pendbaser);
 
@@ -630,7 +634,7 @@ int vgic_v3_save_pending_tables(struct k
 		if (ptr != last_ptr) {
 			ret = kvm_read_guest_lock(kvm, ptr, &val, 1);
 			if (ret)
-				goto out;
+				goto put_irq;
 			last_ptr = ptr;
 		}
 
@@ -642,7 +646,7 @@ int vgic_v3_save_pending_tables(struct k
 			vgic_v4_get_vlpi_state(irq, &is_pending);
 
 		if (stored == is_pending)
-			continue;
+			goto put_irq;
 
 		if (is_pending)
 			val |= 1 << bit_nr;
@@ -650,6 +654,8 @@ int vgic_v3_save_pending_tables(struct k
 			val &= ~(1 << bit_nr);
 
 		ret = vgic_write_guest_lock(kvm, ptr, &val, 1);
+put_irq:
+		vgic_put_irq(kvm, irq);
 		if (ret)
 			goto out;
 	}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 322/556] KVM: arm64: vgic: Fix detection of MI on no pending LR
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (320 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 321/556] KVM: arm64: vgic-v3: take an LPI reference in vgic_v3_save_pending_tables Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 323/556] KVM: arm64: vgic: Reset in_kernel on private IRQ allocation failure Greg Kroah-Hartman
                   ` (246 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Kajetan Puchalski, Marc Zyngier,
	Oliver Upton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Kajetan Puchalski <kajetan.puchalski@arm.com>

commit a342faadc5acbd5d9fd894fd4499d4fd614dfcf6 upstream.

As per the ARM GICv3 spec, the maintenance interrupt identified by
ICH_MISR_EL2.NP is asserted when it is enabled and no List register is
in pending state. This is further described in the document as "no List
registers with the State field set to 0b01 (pending)". By checking only
the pending bit of the LR (bit 62), KVM currently asserts the MI when
there are no LRs in "pending" or "pending and active" states.
Fix the detection logic to consider only the "pending" state.

Cc: stable@vger.kernel.org
Fixes: 96c2f03311de ("KVM: arm64: nv: Plumb handling of GICv3 EL2 accesses")
Signed-off-by: Kajetan Puchalski <kajetan.puchalski@arm.com>
Reviewed-by: Marc Zyngier <maz@kernel.org>
Link: https://patch.msgid.link/20260810102923.2426475-2-kajetan.puchalski@arm.com
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/arm64/kvm/vgic/vgic-v3-nested.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/arch/arm64/kvm/vgic/vgic-v3-nested.c
+++ b/arch/arm64/kvm/vgic/vgic-v3-nested.c
@@ -152,7 +152,7 @@ static void vgic_compute_mi_state(struct
 			eisr |= BIT(i);
 		if (!(lr & ICH_LR_STATE))
 			elrsr |= BIT(i);
-		pend |= (lr & ICH_LR_PENDING_BIT);
+		pend |= (lr & ICH_LR_STATE) == ICH_LR_PENDING_BIT;
 	}
 
 	mi_state->eisr	= eisr;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 323/556] KVM: arm64: vgic: Reset in_kernel on private IRQ allocation failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (321 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 322/556] KVM: arm64: vgic: Fix detection of MI on no pending LR Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 324/556] KVM: arm64: vgic-its: Dont dereference a NULL collection on ITT save Greg Kroah-Hartman
                   ` (245 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Fuad Tabba, Marc Zyngier,
	Oliver Upton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Fuad Tabba <fuad.tabba@linux.dev>

commit 43347154e7ab642474c886bc54ad090166c0d9c9 upstream.

kvm_vgic_create() sets vgic.in_kernel before allocating the per-vCPU
private IRQs, but the allocation-failure path resets only vgic_model and
leaves in_kernel set. As irqchip_in_kernel() is !!in_kernel, the VM is
left with an in-kernel irqchip but no model, and the -EEXIST guard at the
top of kvm_vgic_create() rejects every retry, so userspace cannot recover
from a transient -ENOMEM.

Reset in_kernel alongside vgic_model on the failure path.

Fixes: 9435c1e1431003 ("KVM: arm64: gic: Set vgic_model before initing private IRQs")
Cc: stable@vger.kernel.org
Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev>
Acked-by: Marc Zyngier <maz@kernel.org>
Link: https://patch.msgid.link/20260802150845.3485757-1-fuad.tabba@linux.dev
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/arm64/kvm/vgic/vgic-init.c |    1 +
 1 file changed, 1 insertion(+)

--- a/arch/arm64/kvm/vgic/vgic-init.c
+++ b/arch/arm64/kvm/vgic/vgic-init.c
@@ -176,6 +176,7 @@ int kvm_vgic_create(struct kvm *kvm, u32
 		}
 
 		kvm->arch.vgic.vgic_model = 0;
+		kvm->arch.vgic.in_kernel = false;
 		goto out_unlock;
 	}
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 324/556] KVM: arm64: vgic-its: Dont dereference a NULL collection on ITT save
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (322 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 323/556] KVM: arm64: vgic: Reset in_kernel on private IRQ allocation failure Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 325/556] KVM: arm64: Correctly cap TLBI Range to the architural limit Greg Kroah-Hartman
                   ` (244 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Fuad Tabba, Oliver Upton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Fuad Tabba <fuad.tabba@linux.dev>

commit c6c156d931c33b92362383cf76f6d6e1291dcbfe upstream.

MAPC with V=0 drops ite->collection but leaves the ITE on the device's
ITT list, and vgic_its_save_ite() dereferences it unconditionally. A
guest that issues MAPD, MAPTI and then MAPC(V=0) therefore oopses the
host when the VMM issues KVM_DEV_ARM_ITS_SAVE_TABLES to migrate it.
That sequence is UNPREDICTABLE per the architecture, but KVM already
handles the resulting state in the translate, MOVI and DISCARD paths.

Save a zeroed entry, which vgic_its_restore_ite() reads back as
invalid. Skipping the ITE instead would leave the ITT slot holding
whatever is in guest memory, and restore rejects an entry naming a
collection the restored collection table does not have.

Fixes: eff484e0298da ("KVM: arm64: vgic-its: ITT save and restore")
Cc: stable@vger.kernel.org
Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev>
Link: https://patch.msgid.link/20260807104102.2410744-2-fuad.tabba@linux.dev
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/arm64/kvm/vgic/vgic-its.c |    8 ++++++++
 1 file changed, 8 insertions(+)

--- a/arch/arm64/kvm/vgic/vgic-its.c
+++ b/arch/arm64/kvm/vgic/vgic-its.c
@@ -2119,6 +2119,14 @@ static int vgic_its_save_ite(struct vgic
 	u32 next_offset;
 	u64 val;
 
+	/*
+	 * MAPC with V=0 keeps the ITEs mapped but drops their collection,
+	 * and with it the ICID. Save a zeroed entry, which the restore path
+	 * reads back as invalid.
+	 */
+	if (!ite->collection)
+		return vgic_its_write_entry_lock(its, gpa, 0ULL, ite);
+
 	next_offset = compute_next_eventid_offset(&dev->itt_head, ite);
 	val = ((u64)next_offset << KVM_ITS_ITE_NEXT_SHIFT) |
 	       ((u64)ite->irq->intid << KVM_ITS_ITE_PINTID_SHIFT) |



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 325/556] KVM: arm64: Correctly cap TLBI Range to the architural limit
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (323 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 324/556] KVM: arm64: vgic-its: Dont dereference a NULL collection on ITT save Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 326/556] LoongArch: KVM: Set vcpu->cpu before IN_GUEST_MODE is set Greg Kroah-Hartman
                   ` (243 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Wei-Lin Chang, Marc Zyngier,
	Oliver Upton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Marc Zyngier <maz@kernel.org>

commit 69a598288195947a1662b53de702eb6976af96b7 upstream.

TLB Invalidation by Range has a fairly powerful way of encoding pretty
large ranges in a small number of bits. This range can be based on an
arbitrary VA, which means it is pretty easy for a guest to generate an
overflow should the hypervisor be naive enough to add the range to the
base...

Make sure the range is capped to the limit dictated by the address bit
that determines the VA range. For an IPA invalidation, this is further
corrected down the line to ignore the upper range.

Fixes: 4ffa72ad8f37e ("KVM: arm64: nv: Add S1 TLB invalidation primitive for VNCR_EL2")
Reported-by: Wei-Lin Chang <weilin.chang@arm.com>
Link: https://lore.kernel.org/r/yifz3wn5gk5sr6mapi32trgk5m5kp33bquctsjmkifebnsnndt@fix6u4rthx4g
Signed-off-by: Marc Zyngier <maz@kernel.org>
Cc: stable@vger.kernel.org
Reviewed-by: Wei-Lin Chang <weilin.chang@arm.com>
Link: https://patch.msgid.link/20260810170616.746100-1-maz@kernel.org
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/arm64/include/asm/kvm_nested.h |    6 ++++++
 1 file changed, 6 insertions(+)

--- a/arch/arm64/include/asm/kvm_nested.h
+++ b/arch/arm64/include/asm/kvm_nested.h
@@ -305,6 +305,12 @@ static inline u64 decode_range_tlbi(u64
 	num	= FIELD_GET(GENMASK(43, 39), val);
 	*range	= __TLBI_RANGE_PAGES(num, scale) << shift;
 
+	/* Cap the range to the correct half of the address space */
+	if (!(base & BIT(48)))
+		*range = min(*range, (BIT(48) - base));
+	else
+		*range = min(*range, ~base + 1);
+
 	return base;
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 326/556] LoongArch: KVM: Set vcpu->cpu before IN_GUEST_MODE is set
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (324 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 325/556] KVM: arm64: Correctly cap TLBI Range to the architural limit Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 327/556] LoongArch: KVM: Fix uninitialized stack variable issue with dmsintc Greg Kroah-Hartman
                   ` (242 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Bibo Mao, Huacai Chen

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bibo Mao <maobibo@loongson.cn>

commit 32d05564a6128d59ea876cf9078fe6866a809e14 upstream.

In function kvm_make_vcpu_request(), it will send IPI to physical CPU
when vCPU is in IN_GUEST_MODE mode. And physical CPU is set in function
kvm_check_vpid(), thus it should be called before IN_GUEST_MODE is set.
Otherwise IPI will send to wrong old physical CPU where vCPU is running.

Cc: stable@vger.kernel.org
Fixes: 2fc3bd86db4b ("LoongArch: KVM: Implement basic vcpu interfaces")
Signed-off-by: Bibo Mao <maobibo@loongson.cn>
Signed-off-by: Huacai Chen <chenhuacai@loongson.cn>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/loongarch/kvm/vcpu.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/arch/loongarch/kvm/vcpu.c
+++ b/arch/loongarch/kvm/vcpu.c
@@ -300,10 +300,10 @@ static int kvm_pre_enter_guest(struct kv
 		 */
 		local_irq_disable();
 		kvm_deliver_exception(vcpu);
+		kvm_check_vpid(vcpu);
 		/* Make sure the vcpu mode has been written */
 		smp_store_mb(vcpu->mode, IN_GUEST_MODE);
 		kvm_deliver_intr(vcpu);
-		kvm_check_vpid(vcpu);
 
 		/*
 		 * Called after function kvm_check_vpid()



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 327/556] LoongArch: KVM: Fix uninitialized stack variable issue with dmsintc
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (325 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 326/556] LoongArch: KVM: Set vcpu->cpu before IN_GUEST_MODE is set Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 328/556] LoongArch: KVM: Fix PC double advance in kernel MMIO read fast path Greg Kroah-Hartman
                   ` (241 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Bibo Mao, Huacai Chen

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bibo Mao <maobibo@loongson.cn>

commit 81aa3a58b542ed88819115c80a17acd86eacb89d upstream.

Variable vector[] is declared on stack in function dmsintc_inject_irq()
and sometimes it is used without initialized. Here fix this issue.

Cc: stable@vger.kernel.org
Fixes: 03de5eecb0f0 ("LoongArch: KVM: Add DMSINTC inject msi to vCPU")
Signed-off-by: Bibo Mao <maobibo@loongson.cn>
Signed-off-by: Huacai Chen <chenhuacai@loongson.cn>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/loongarch/kvm/intc/dmsintc.c |    3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

--- a/arch/loongarch/kvm/intc/dmsintc.c
+++ b/arch/loongarch/kvm/intc/dmsintc.c
@@ -19,8 +19,7 @@ void dmsintc_inject_irq(struct kvm_vcpu
 
 	for (i = 0; i < 4; i++) {
 		old = atomic64_read(&(ds->vector_map[i]));
-		if (old)
-			vector[i] = atomic64_xchg(&(ds->vector_map[i]), 0);
+		vector[i] = old ? atomic64_xchg(&(ds->vector_map[i]), 0) : 0;
 	}
 
 	if (vector[0]) {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 328/556] LoongArch: KVM: Fix PC double advance in kernel MMIO read fast path
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (326 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 327/556] LoongArch: KVM: Fix uninitialized stack variable issue with dmsintc Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 329/556] LoongArch: KVM: Add unregister helpers for the KVM interrupt devices Greg Kroah-Hartman
                   ` (240 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Bibo Mao, Tao Cui, Zeng Chi,
	Huacai Chen

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zeng Chi <zengchi@kylinos.cn>

commit fd4021529faa931818186b6e83bd46f5de7517eb upstream.

In the in-kernel MMIO read fast path of kvm_emu_mmio_read(),
kvm_complete_mmio_read() already advances the guest PC via update_pc().
The explicit update_pc() call right after it advances the PC a second
time, so PC moves forward by 8 bytes instead of 4, and the instruction
following the MMIO read is silently skipped.

The user space MMIO read completion path in kvm_arch_vcpu_ioctl_run()
calls kvm_complete_mmio_read() only once, and the MMIO write fast path
advances the PC exactly once as well.

Here remove the redundant update_pc() so the kernel MMIO read fast path
advances the PC by a single instruction.

Cc: stable@vger.kernel.org
Fixes: 80edf90831a2 ("LoongArch: KVM: Add sign extension with kernel MMIO read emulation")
Reviewed-by: Bibo Mao <maobibo@loongson.cn>
Reviewed-by: Tao Cui <cuitao@kylinos.cn>
Signed-off-by: Zeng Chi <zengchi@kylinos.cn>
Signed-off-by: Huacai Chen <chenhuacai@loongson.cn>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/loongarch/kvm/exit.c |    1 -
 1 file changed, 1 deletion(-)

--- a/arch/loongarch/kvm/exit.c
+++ b/arch/loongarch/kvm/exit.c
@@ -481,7 +481,6 @@ int kvm_emu_mmio_read(struct kvm_vcpu *v
 		srcu_read_unlock(&vcpu->kvm->srcu, idx);
 		if (!ret) {
 			kvm_complete_mmio_read(vcpu, run);
-			update_pc(&vcpu->arch);
 			vcpu->mmio_needed = 0;
 			return EMULATE_DONE;
 		}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 329/556] LoongArch: KVM: Add unregister helpers for the KVM interrupt devices
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (327 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 328/556] LoongArch: KVM: Fix PC double advance in kernel MMIO read fast path Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 330/556] LoongArch: KVM: Fix resource leak in kvm_loongarch_env_init() error path Greg Kroah-Hartman
                   ` (239 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Bibo Mao, Chaithanya Lagisetty,
	Huacai Chen

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chaithanya Lagisetty <nagachaithanya9911@gmail.com>

commit 4af22177032ab2357bf551fbfcdebc8fd9f2502d upstream.

The IPI/EIOINTC/PCH-PIC/DMSINTC KVM devices each have a helper that
registers their kvm_device_ops, but there is no counterpart to remove
them, so a caller that needs to undo a registration has to open-code
kvm_unregister_device_ops() with the matching device type.

Add kvm_loongarch_unregister_{ipi,eiointc,pch_pic,dmsintc}_device()
next to the existing register helpers. kvm_unregister_device_ops() is a
no-op when the corresponding device type is not currently registered.

No functional change, as there are no callers yet.

Cc: stable@vger.kernel.org
Suggested-by: Bibo Mao <maobibo@loongson.cn>
Reviewed-by: Bibo Mao <maobibo@loongson.cn>
Signed-off-by: Chaithanya Lagisetty <nagachaithanya9911@gmail.com>
Signed-off-by: Huacai Chen <chenhuacai@loongson.cn>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/loongarch/include/asm/kvm_dmsintc.h |    1 +
 arch/loongarch/include/asm/kvm_eiointc.h |    1 +
 arch/loongarch/include/asm/kvm_ipi.h     |    1 +
 arch/loongarch/include/asm/kvm_pch_pic.h |    1 +
 arch/loongarch/kvm/intc/dmsintc.c        |    5 +++++
 arch/loongarch/kvm/intc/eiointc.c        |    5 +++++
 arch/loongarch/kvm/intc/ipi.c            |    5 +++++
 arch/loongarch/kvm/intc/pch_pic.c        |    5 +++++
 8 files changed, 24 insertions(+)

--- a/arch/loongarch/include/asm/kvm_dmsintc.h
+++ b/arch/loongarch/include/asm/kvm_dmsintc.h
@@ -20,6 +20,7 @@ struct dmsintc_state {
 };
 
 int kvm_loongarch_register_dmsintc_device(void);
+void kvm_loongarch_unregister_dmsintc_device(void);
 void dmsintc_inject_irq(struct kvm_vcpu *vcpu);
 int dmsintc_set_irq(struct kvm *kvm, u64 addr, int data, int level);
 int dmsintc_deliver_msi_to_vcpu(struct kvm *kvm, struct kvm_vcpu *vcpu, u32 vector, int level);
--- a/arch/loongarch/include/asm/kvm_eiointc.h
+++ b/arch/loongarch/include/asm/kvm_eiointc.h
@@ -79,6 +79,7 @@ struct loongarch_eiointc {
 };
 
 int kvm_loongarch_register_eiointc_device(void);
+void kvm_loongarch_unregister_eiointc_device(void);
 void eiointc_set_irq(struct loongarch_eiointc *s, int irq, int level);
 
 #endif /* __ASM_KVM_EIOINTC_H */
--- a/arch/loongarch/include/asm/kvm_ipi.h
+++ b/arch/loongarch/include/asm/kvm_ipi.h
@@ -41,5 +41,6 @@ struct ipi_state {
 #define IOCSR_ANY_SEND		0x158
 
 int kvm_loongarch_register_ipi_device(void);
+void kvm_loongarch_unregister_ipi_device(void);
 
 #endif
--- a/arch/loongarch/include/asm/kvm_pch_pic.h
+++ b/arch/loongarch/include/asm/kvm_pch_pic.h
@@ -70,6 +70,7 @@ struct loongarch_pch_pic {
 
 struct kvm_kernel_irq_routing_entry;
 int kvm_loongarch_register_pch_pic_device(void);
+void kvm_loongarch_unregister_pch_pic_device(void);
 void pch_pic_set_irq(struct loongarch_pch_pic *s, int irq, int level);
 int pch_msi_set_irq(struct kvm *kvm, struct kvm_kernel_irq_routing_entry *e, int level);
 
--- a/arch/loongarch/kvm/intc/dmsintc.c
+++ b/arch/loongarch/kvm/intc/dmsintc.c
@@ -179,3 +179,8 @@ int kvm_loongarch_register_dmsintc_devic
 {
 	return kvm_register_device_ops(&kvm_dmsintc_dev_ops, KVM_DEV_TYPE_LOONGARCH_DMSINTC);
 }
+
+void kvm_loongarch_unregister_dmsintc_device(void)
+{
+	kvm_unregister_device_ops(KVM_DEV_TYPE_LOONGARCH_DMSINTC);
+}
--- a/arch/loongarch/kvm/intc/eiointc.c
+++ b/arch/loongarch/kvm/intc/eiointc.c
@@ -691,3 +691,8 @@ int kvm_loongarch_register_eiointc_devic
 {
 	return kvm_register_device_ops(&kvm_eiointc_dev_ops, KVM_DEV_TYPE_LOONGARCH_EIOINTC);
 }
+
+void kvm_loongarch_unregister_eiointc_device(void)
+{
+	kvm_unregister_device_ops(KVM_DEV_TYPE_LOONGARCH_EIOINTC);
+}
--- a/arch/loongarch/kvm/intc/ipi.c
+++ b/arch/loongarch/kvm/intc/ipi.c
@@ -466,3 +466,8 @@ int kvm_loongarch_register_ipi_device(vo
 {
 	return kvm_register_device_ops(&kvm_ipi_dev_ops, KVM_DEV_TYPE_LOONGARCH_IPI);
 }
+
+void kvm_loongarch_unregister_ipi_device(void)
+{
+	kvm_unregister_device_ops(KVM_DEV_TYPE_LOONGARCH_IPI);
+}
--- a/arch/loongarch/kvm/intc/pch_pic.c
+++ b/arch/loongarch/kvm/intc/pch_pic.c
@@ -500,3 +500,8 @@ int kvm_loongarch_register_pch_pic_devic
 {
 	return kvm_register_device_ops(&kvm_pch_pic_dev_ops, KVM_DEV_TYPE_LOONGARCH_PCHPIC);
 }
+
+void kvm_loongarch_unregister_pch_pic_device(void)
+{
+	kvm_unregister_device_ops(KVM_DEV_TYPE_LOONGARCH_PCHPIC);
+}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 330/556] LoongArch: KVM: Fix resource leak in kvm_loongarch_env_init() error path
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (328 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 329/556] LoongArch: KVM: Add unregister helpers for the KVM interrupt devices Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 331/556] LoongArch: KVM: Fix TOCTOU race on pv_features Greg Kroah-Hartman
                   ` (238 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Bibo Mao, Chaithanya Lagisetty,
	Huacai Chen

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chaithanya Lagisetty <nagachaithanya9911@gmail.com>

commit 910132bc7d72f26a8b288c2a38c32445a48d5be0 upstream.

kvm_loongarch_env_init() allocates the per-CPU kvm_context (vmcs) and
kvm_loongarch_ops, registers the perf callbacks, and then registers
the IPI/EIOINTC/PCH-PIC/DMSINTC KVM devices. If any of those device
registrations fails, the function returned the error directly, leaving
everything acquired so far in place: vmcs and kvm_loongarch_ops are
never freed, the perf callbacks stay registered, and all previously
registered KVM device operations remain registered. kvm_loongarch_init()
propagates the errors without calling kvm_loongarch_env_exit(), so
nothing else cleans up either.

Unwind the error path in reverse order of registration, so that each
failure only undoes what had actually been set up. Use the same helpers
in kvm_loongarch_env_exit() to remove the device registrations during
normal teardown as well.

Cc: stable@vger.kernel.org
Fixes: c532de5a67a7 ("LoongArch: KVM: Add IPI device support")
Reviewed-by: Bibo Mao <maobibo@loongson.cn>
Signed-off-by: Chaithanya Lagisetty <nagachaithanya9911@gmail.com>
Signed-off-by: Huacai Chen <chenhuacai@loongson.cn>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/loongarch/kvm/main.c |   33 +++++++++++++++++++++++++++++----
 1 file changed, 29 insertions(+), 4 deletions(-)

--- a/arch/loongarch/kvm/main.c
+++ b/arch/loongarch/kvm/main.c
@@ -385,27 +385,52 @@ static int kvm_loongarch_env_init(void)
 	/* Register LoongArch IPI interrupt controller interface. */
 	ret = kvm_loongarch_register_ipi_device();
 	if (ret)
-		return ret;
+		goto err_env;
 
 	/* Register LoongArch EIOINTC interrupt controller interface. */
 	ret = kvm_loongarch_register_eiointc_device();
 	if (ret)
-		return ret;
+		goto err_ipi;
 
 	/* Register LoongArch PCH-PIC interrupt controller interface. */
 	ret = kvm_loongarch_register_pch_pic_device();
 	if (ret)
-		return ret;
+		goto err_eiointc;
 
 	/* Register LoongArch DMSINTC interrupt contrroller interface */
-	if (cpu_has_msgint)
+	if (cpu_has_msgint) {
 		ret = kvm_loongarch_register_dmsintc_device();
+		if (ret)
+			goto err_pch_pic;
+	}
+
+	return 0;
+
+err_pch_pic:
+	kvm_loongarch_unregister_pch_pic_device();
+err_eiointc:
+	kvm_loongarch_unregister_eiointc_device();
+err_ipi:
+	kvm_loongarch_unregister_ipi_device();
+err_env:
+	kvm_unregister_perf_callbacks();
+	kfree(kvm_loongarch_ops);
+	kvm_loongarch_ops = NULL;
+	free_percpu(vmcs);
+	vmcs = NULL;
 
 	return ret;
 }
 
 static void kvm_loongarch_env_exit(void)
 {
+	if (cpu_has_msgint)
+		kvm_loongarch_unregister_dmsintc_device();
+
+	kvm_loongarch_unregister_pch_pic_device();
+	kvm_loongarch_unregister_eiointc_device();
+	kvm_loongarch_unregister_ipi_device();
+
 	if (vmcs)
 		free_percpu(vmcs);
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 331/556] LoongArch: KVM: Fix TOCTOU race on pv_features
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (329 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 330/556] LoongArch: KVM: Fix resource leak in kvm_loongarch_env_init() error path Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 332/556] LoongArch: KVM: Free init resources if kvm_init() fails Greg Kroah-Hartman
                   ` (237 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Bibo Mao, Tao Cui, Huacai Chen

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tao Cui <cuitao@kylinos.cn>

commit 9296375902579f9b0e456bbb76e5cf179e5a4e0b upstream.

In kvm_loongarch_cpucfg_set_attr() the check-then-set on
kvm->arch.pv_features is lockless, so two vCPUs can race past the
validation and set different values. Add a spinlock to protect it.

Cc: stable@vger.kernel.org
Reviewed-by: Bibo Mao <maobibo@loongson.cn>
Signed-off-by: Tao Cui <cuitao@kylinos.cn>
Signed-off-by: Huacai Chen <chenhuacai@loongson.cn>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/loongarch/include/asm/kvm_host.h |    1 +
 arch/loongarch/kvm/vcpu.c             |    6 +++++-
 arch/loongarch/kvm/vm.c               |    1 +
 3 files changed, 7 insertions(+), 1 deletion(-)

--- a/arch/loongarch/include/asm/kvm_host.h
+++ b/arch/loongarch/include/asm/kvm_host.h
@@ -125,6 +125,7 @@ struct kvm_arch {
 	unsigned int  pte_shifts[MAX_PGTABLE_LEVELS];
 	unsigned int  root_level;
 	spinlock_t    phyid_map_lock;
+	spinlock_t    pv_setting_lock;
 	struct kvm_phyid_map  *phyid_map;
 	/* Enabled PV features */
 	unsigned long pv_features;
--- a/arch/loongarch/kvm/vcpu.c
+++ b/arch/loongarch/kvm/vcpu.c
@@ -1165,10 +1165,14 @@ static int kvm_loongarch_cpucfg_set_attr
 			return -EINVAL;
 
 		/* All vCPUs need set the same PV features */
+		spin_lock(&kvm->arch.pv_setting_lock);
 		if ((kvm->arch.pv_features & LOONGARCH_PV_FEAT_UPDATED)
-				&& ((kvm->arch.pv_features & valid) != val))
+				&& ((kvm->arch.pv_features & valid) != val)) {
+			spin_unlock(&kvm->arch.pv_setting_lock);
 			return -EINVAL;
+		}
 		kvm->arch.pv_features = val | LOONGARCH_PV_FEAT_UPDATED;
+		spin_unlock(&kvm->arch.pv_setting_lock);
 		return 0;
 	default:
 		return -ENXIO;
--- a/arch/loongarch/kvm/vm.c
+++ b/arch/loongarch/kvm/vm.c
@@ -76,6 +76,7 @@ int kvm_arch_init_vm(struct kvm *kvm, un
 		return -ENOMEM;
 	}
 	spin_lock_init(&kvm->arch.phyid_map_lock);
+	spin_lock_init(&kvm->arch.pv_setting_lock);
 
 	kvm_init_vmcs(kvm);
 	kvm_vm_init_features(kvm);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 332/556] LoongArch: KVM: Free init resources if kvm_init() fails
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (330 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 331/556] LoongArch: KVM: Fix TOCTOU race on pv_features Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 333/556] LoongArch: KVM: Preserve memslot arch flags on KVM_MR_FLAGS_ONLY Greg Kroah-Hartman
                   ` (236 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Bibo Mao, Chaithanya Lagisetty,
	Huacai Chen

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chaithanya Lagisetty <nagachaithanya9911@gmail.com>

commit f7a1064cce3b100b54780c68529176232d8eb01e upstream.

kvm_loongarch_init() calls kvm_loongarch_env_init() to allocate the
per-CPU kvm_context (vmcs) and kvm_loongarch_ops and to register the
perf callbacks, and then calls kvm_init(). If kvm_init() fails its
result is returned directly, but since module_init() does not run the
module_exit() stuff on failure, so kvm_loongarch_env_exit() is never
called and those resources are leaked.

So call kvm_loongarch_env_exit() when kvm_init() fails, matching the
teardown-on-failure pattern used by riscv_kvm_init().

Cc: stable@vger.kernel.org
Fixes: 2bd6ac687261 ("LoongArch: KVM: Implement kvm module related interface")
Reviewed-by: Bibo Mao <maobibo@loongson.cn>
Signed-off-by: Chaithanya Lagisetty <nagachaithanya9911@gmail.com>
Signed-off-by: Huacai Chen <chenhuacai@loongson.cn>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/loongarch/kvm/main.c |    6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

--- a/arch/loongarch/kvm/main.c
+++ b/arch/loongarch/kvm/main.c
@@ -453,7 +453,11 @@ static int kvm_loongarch_init(void)
 	if (r)
 		return r;
 
-	return kvm_init(sizeof(struct kvm_vcpu), 0, THIS_MODULE);
+	r = kvm_init(sizeof(struct kvm_vcpu), 0, THIS_MODULE);
+	if (r)
+		kvm_loongarch_env_exit();
+
+	return r;
 }
 
 static void kvm_loongarch_exit(void)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 333/556] LoongArch: KVM: Preserve memslot arch flags on KVM_MR_FLAGS_ONLY
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (331 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 332/556] LoongArch: KVM: Free init resources if kvm_init() fails Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 334/556] LoongArch: KVM: Validate MSI data before routing it to EIOINTC Greg Kroah-Hartman
                   ` (235 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Tao Cui, Bibo Mao, Zeng Chi,
	Huacai Chen

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zeng Chi <zengchi@kylinos.cn>

commit 27a9bfee3bbcb3cabb77797354f07e0e44e49831 upstream.

kvm_arch_prepare_memory_region() computes new->arch.flags, i.e. whether
a memslot is KVM_MEM_HUGEPAGE_CAPABLE or KVM_MEM_HUGEPAGE_INCAPABLE,
only for KVM_MR_CREATE and KVM_MR_MOVE, and returns early for every
other change. But the generic code allocates a zeroed memslot for every
change and never copies old->arch, so after a KVM_MR_FLAGS_ONLY update,
e.g. toggling KVM_MEM_LOG_DIRTY_PAGES for live migration, the active
memslot has arch.flags == 0.

With both flags clear, fault_supports_huge_mapping() falls through to
the alignment check on the HVA range alone, which no longer verifies
that the GPA and HVA have the same offset within a PMD. A memslot that
was marked KVM_MEM_HUGEPAGE_INCAPABLE because of a GPA/HVA offset
mismatch can then be mapped with PMD entries on read faults, and since
kvm_map_page() aligns the gfn and the pfn independently, the guest ends
up accessing the wrong host pages, exactly the "d -> f, e -> g" case
described in the comment above the check.

Carry the arch flags over from the old memslot for KVM_MR_FLAGS_ONLY,
as the GPA, HVA and size are guaranteed to be unchanged for that case.

Cc: stable@vger.kernel.org
Fixes: 7ab6fb505b2a ("LoongArch: KVM: Optimization for memslot hugepage checking")
Tested-by: Tao Cui <cuitao@kylinos.cn>
Reviewed-by: Tao Cui <cuitao@kylinos.cn>
Reviewed-by: Bibo Mao <maobibo@loongson.cn>
Signed-off-by: Zeng Chi <zengchi@kylinos.cn>
Signed-off-by: Huacai Chen <chenhuacai@loongson.cn>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/loongarch/kvm/mmu.c |   10 ++++++++++
 1 file changed, 10 insertions(+)

--- a/arch/loongarch/kvm/mmu.c
+++ b/arch/loongarch/kvm/mmu.c
@@ -383,6 +383,16 @@ int kvm_arch_prepare_memory_region(struc
 	hva_t hva_start;
 	size_t size, gpa_offset, hva_offset;
 
+	/*
+	 * The generic code allocates a fresh, zeroed memslot for every change,
+	 * so the arch flags computed below must be carried over when only the
+	 * userspace flags change, e.g. when dirty logging is toggled.
+	 */
+	if (change == KVM_MR_FLAGS_ONLY) {
+		new->arch = old->arch;
+		return 0;
+	}
+
 	if ((change != KVM_MR_MOVE) && (change != KVM_MR_CREATE))
 		return 0;
 	/*



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 334/556] LoongArch: KVM: Validate MSI data before routing it to EIOINTC
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (332 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 333/556] LoongArch: KVM: Preserve memslot arch flags on KVM_MR_FLAGS_ONLY Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 335/556] LoongArch: Add DIRECT_MAP_PHYSMEM_END definition Greg Kroah-Hartman
                   ` (234 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Tao Cui, Bibo Mao, Zeng Chi,
	Huacai Chen

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zeng Chi <zengchi@kylinos.cn>

commit 501514d6ebd2111c353a1296f25dbe22fbd64657 upstream.

pch_msi_set_irq() passes e->msi.data straight into eiointc_set_irq() as
the irq number. The MSI data comes from userspace, that either via a
KVM_IRQ_ROUTING_MSI entry set with KVM_SET_GSI_ROUTING (used by irqfd
and KVM_IRQ_LINE) or directly via KVM_SIGNAL_MSI, and is never checked
against EIOINTC_IRQS.

eiointc_set_irq() uses the value with __set_bit()/__clear_bit() on the
256-bit isr bitmap, eiointc_update_irq() then indexes sw_coremap[] and
the per-cpu coreisr/sw_coreisr bitmaps with it. Therefore a data value
>= 256 reads and writes memory past the end of those arrays, i.e. any
process holding a VM fd can corrupt kernel memory beyond the allocation
of loongarch_eiointc.

Reject MSI data that doesn't fit in the EIOINTC irq space. The DMSINTC
path is unaffected as it decodes the vector from the address and masks
it.

Cc: stable@vger.kernel.org
Fixes: 1928254c5ccb ("LoongArch: KVM: Add irqfd support")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/all/20260531140921.1B1181F00893@smtp.kernel.org/
Reviewed-by: Tao Cui <cuitao@kylinos.cn>
Reviewed-by: Bibo Mao <maobibo@loongson.cn>
Signed-off-by: Zeng Chi <zengchi@kylinos.cn>
Signed-off-by: Huacai Chen <chenhuacai@loongson.cn>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/loongarch/kvm/intc/pch_pic.c |    3 +++
 1 file changed, 3 insertions(+)

--- a/arch/loongarch/kvm/intc/pch_pic.c
+++ b/arch/loongarch/kvm/intc/pch_pic.c
@@ -78,6 +78,9 @@ int pch_msi_set_irq(struct kvm *kvm, str
 		return dmsintc_set_irq(kvm, msg_addr, e->msi.data, level);
 	}
 
+	if (e->msi.data >= EIOINTC_IRQS)
+		return -EINVAL;
+
 	eiointc_set_irq(kvm->arch.eiointc, e->msi.data, level);
 
 	return 0;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 335/556] LoongArch: Add DIRECT_MAP_PHYSMEM_END definition
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (333 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 334/556] LoongArch: KVM: Validate MSI data before routing it to EIOINTC Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 336/556] LoongArch: BPF: Optimize redundant TCC loads in epilogue Greg Kroah-Hartman
                   ` (233 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Han Gao, Huacai Chen

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Han Gao <gaohan@iscas.ac.cn>

commit 2677f97a67fdbc62a82ce1faa67791f54451d36f upstream.

get_free_mem_region() and mhp_get_pluggable_range() bound their search
to DIRECT_MAP_PHYSMEM_END. LoongArch does not define it, so the fallback
in include/linux/mm.h applies: under CONFIG_SPARSEMEM_VMEMMAP it is
(1ULL << MAX_PHYSMEM_BITS) - 1, a compile-time constant that does not
adapt to the CPU's physical address space bits (cpu_pabits, probed from
CPUCFG1).

The vmemmap window only covers physical space below 2^(cpu_pabits+1)
(i.e. VMEMMAP_SIZE), so on CPUs with fewer physical address bits than
MAX_PHYSMEM_BITS the fallback allows get_free_mem_region() to return
a ZONE_DEVICE region outside the vmemmap window; vmemmap_populate() then
wraps the memmap range around and maps it into low memory, silently
corrupting the page tables. The same search also picked the top-of-
address-space region that crashed memmap_init_zone_device() with amdkfd
on Loongson-3C6000 in 6.16 [1]; the commit 2969b42c8f99 ("LoongArch/mm:
align vmemmap to maximal folio size") keeps that region in bounds on
current Loongson-3C6000 configs, but CPUs with smaller cpu_pabits (e.g.
the Loongson-2K series) are still affected.

Define DIRECT_MAP_PHYSMEM_END as the vmemmap-covered physical range,
(1ULL << (cpu_pabits + 1)) - 1, capped at (1ULL << MAX_PHYSMEM_BITS) - 1
under CONFIG_SPARSEMEM, similar to the commit f3336b48cf9d ("riscv: mm:
Define DIRECT_MAP_PHYSMEM_END").

[1] https://lore.kernel.org/amd-gfx/20250814032153.227285-1-jeffbai@aosc.io/

Cc: stable@vger.kernel.org # v6.13+
Signed-off-by: Han Gao <gaohan@iscas.ac.cn>
Signed-off-by: Huacai Chen <chenhuacai@loongson.cn>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/loongarch/include/asm/pgtable.h |    7 +++++++
 1 file changed, 7 insertions(+)

--- a/arch/loongarch/include/asm/pgtable.h
+++ b/arch/loongarch/include/asm/pgtable.h
@@ -125,6 +125,13 @@ struct vm_area_struct;
 
 #endif
 
+/* Needed to limit get_free_mem_region() */
+#ifndef CONFIG_SPARSEMEM
+#define DIRECT_MAP_PHYSMEM_END ((1ULL << (cpu_pabits + 1)) - 1)
+#else
+#define DIRECT_MAP_PHYSMEM_END min((1ULL << (cpu_pabits + 1)) - 1, (1ULL << MAX_PHYSMEM_BITS) - 1)
+#endif
+
 #define ptep_get(ptep) READ_ONCE(*(ptep))
 #define pmdp_get(pmdp) READ_ONCE(*(pmdp))
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 336/556] LoongArch: BPF: Optimize redundant TCC loads in epilogue
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (334 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 335/556] LoongArch: Add DIRECT_MAP_PHYSMEM_END definition Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 337/556] LoongArch: BPF: Refactor jump offset calculation in tail call Greg Kroah-Hartman
                   ` (232 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Tiezhu Yang, Huacai Chen

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tiezhu Yang <yangtiezhu@loongson.cn>

commit fd3cb1bfeb9d98618bd709bfee9c1133e9f189e6 upstream.

The legacy epilogue implementation pops the tail call counter (TCC)
context via a redundant double-load pattern. It first decrements the
load_offset by 2 slots to fetch 'tcc_ptr', and then immediately bumps
it back up by 1 slot to load the original 'tcc' value into REG_TCC,
unnecessarily overwriting the register.

Optimize this sequence by adjusting the load_offset by only 1 slot.
This aligns the offset directly with the higher stack slot containing
the entry TCC counter (or caller state), allowing us to restore the
REG_TCC register safely with a single load.

This removes one redundant instruction from the epilogue hot path,
improves code readability, and ensures the correct TCC register context
is handed back cleanly upon normal return.

Cc: stable@vger.kernel.org
Fixes: c0fcc955ff82 ("LoongArch: BPF: Fix the tailcall hierarchy")
Fixes: ef54c517a937 ("LoongArch: BPF: Implement PROBE_MEM32 pseudo instructions")
Signed-off-by: Tiezhu Yang <yangtiezhu@loongson.cn>
Signed-off-by: Huacai Chen <chenhuacai@loongson.cn>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/loongarch/net/bpf_jit.c |   10 ++--------
 1 file changed, 2 insertions(+), 8 deletions(-)

--- a/arch/loongarch/net/bpf_jit.c
+++ b/arch/loongarch/net/bpf_jit.c
@@ -246,14 +246,8 @@ static void __build_epilogue(struct jit_
 		emit_insn(ctx, ldd, REG_ARENA, LOONGARCH_GPR_SP, load_offset);
 	}
 
-	/*
-	 * When push into the stack, follow the order of tcc then tcc_ptr.
-	 * When pop from the stack, first pop tcc_ptr then followed by tcc.
-	 */
-	load_offset -= 2 * sizeof(long);
-	emit_insn(ctx, ldd, REG_TCC, LOONGARCH_GPR_SP, load_offset);
-
-	load_offset += sizeof(long);
+	/* Only restore the TCC state into REG_TCC from the higher slot */
+	load_offset -= sizeof(long);
 	emit_insn(ctx, ldd, REG_TCC, LOONGARCH_GPR_SP, load_offset);
 
 	emit_insn(ctx, addid, LOONGARCH_GPR_SP, LOONGARCH_GPR_SP, stack_adjust);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 337/556] LoongArch: BPF: Refactor jump offset calculation in tail call
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (335 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 336/556] LoongArch: BPF: Optimize redundant TCC loads in epilogue Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 338/556] LoongArch: Expand module virtual address space to 2GB Greg Kroah-Hartman
                   ` (231 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Tiezhu Yang, Huacai Chen

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tiezhu Yang <yangtiezhu@loongson.cn>

commit 37d545d12f21c4d50612ecaebd7ae1e5bf91b2d8 upstream.

The old macro-based jmp_offset calculation derives the jump distance
from a stale prior-pass code stride, which can lead to wrong branch
offsets and soft lockups under extra JIT passes.

Fix this by calculating the offset directly on the absolute target:
"ctx->offset[insn + 1] - ctx->idx".

To avoid a false 16-bit range check abort during size estimation, add
a "ctx->image == NULL" guard to inject a safe dummy offset.

Cc: stable@vger.kernel.org
Fixes: cd39d9e6b7e4 ("LoongArch: BPF: Fix jump offset calculation in tailcall")
Signed-off-by: Tiezhu Yang <yangtiezhu@loongson.cn>
Signed-off-by: Huacai Chen <chenhuacai@loongson.cn>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/loongarch/net/bpf_jit.c |   12 ++++--------
 1 file changed, 4 insertions(+), 8 deletions(-)

--- a/arch/loongarch/net/bpf_jit.c
+++ b/arch/loongarch/net/bpf_jit.c
@@ -284,17 +284,13 @@ bool bpf_jit_supports_far_kfunc_call(voi
 
 static int emit_bpf_tail_call(struct jit_ctx *ctx, int insn)
 {
-	int off, tc_ninsn = 0;
+	int off, jmp_offset;
 	int tcc_ptr_off = BPF_TAIL_CALL_CNT_PTR_STACK_OFF(ctx->stack_size);
 	u8 a1 = LOONGARCH_GPR_A1;
 	u8 a2 = LOONGARCH_GPR_A2;
 	u8 t1 = LOONGARCH_GPR_T1;
 	u8 t2 = LOONGARCH_GPR_T2;
 	u8 t3 = LOONGARCH_GPR_T3;
-	const int idx0 = ctx->idx;
-
-#define cur_offset (ctx->idx - idx0)
-#define jmp_offset (tc_ninsn - (cur_offset))
 
 	/*
 	 * a0: &ctx
@@ -304,12 +300,12 @@ static int emit_bpf_tail_call(struct jit
 	 * if (index >= array->map.max_entries)
 	 *	 goto out;
 	 */
-	tc_ninsn = insn ? ctx->offset[insn+1] - ctx->offset[insn] : ctx->offset[0];
 	emit_zext_32(ctx, a2, true);
 
 	off = offsetof(struct bpf_array, map.max_entries);
 	emit_insn(ctx, ldwu, t1, a1, off);
 	/* bgeu $a2, $t1, jmp_offset */
+	jmp_offset = ctx->image ? (ctx->offset[insn + 1] - ctx->idx) : 0;
 	if (emit_tailcall_jmp(ctx, BPF_JGE, a2, t1, jmp_offset) < 0)
 		goto toofar;
 
@@ -320,6 +316,7 @@ static int emit_bpf_tail_call(struct jit
 	emit_insn(ctx, ldd, REG_TCC, LOONGARCH_GPR_SP, tcc_ptr_off);
 	emit_insn(ctx, ldd, t3, REG_TCC, 0);
 	emit_insn(ctx, addid, t2, LOONGARCH_GPR_ZERO, MAX_TAIL_CALL_CNT);
+	jmp_offset = ctx->image ? (ctx->offset[insn + 1] - ctx->idx) : 0;
 	if (emit_tailcall_jmp(ctx, BPF_JSGE, t3, t2, jmp_offset) < 0)
 		goto toofar;
 
@@ -334,6 +331,7 @@ static int emit_bpf_tail_call(struct jit
 	off = offsetof(struct bpf_array, ptrs);
 	emit_insn(ctx, ldd, t2, t2, off);
 	/* beq $t2, $zero, jmp_offset */
+	jmp_offset = ctx->image ? (ctx->offset[insn + 1] - ctx->idx) : 0;
 	if (emit_tailcall_jmp(ctx, BPF_JEQ, t2, LOONGARCH_GPR_ZERO, jmp_offset) < 0)
 		goto toofar;
 
@@ -349,8 +347,6 @@ static int emit_bpf_tail_call(struct jit
 toofar:
 	pr_info_once("tail_call: jump too far\n");
 	return -1;
-#undef cur_offset
-#undef jmp_offset
 }
 
 static void emit_store_stack_imm64(struct jit_ctx *ctx, int reg, int stack_off, u64 imm64)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 338/556] LoongArch: Expand module virtual address space to 2GB
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (336 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 337/556] LoongArch: BPF: Refactor jump offset calculation in tail call Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 339/556] LoongArch: BPF: Move arena register slot below TCC context Greg Kroah-Hartman
                   ` (230 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Tiezhu Yang, Huacai Chen

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tiezhu Yang <yangtiezhu@loongson.cn>

commit 18210a104bb97e28c26dc31fd9fc7b5c381fec62 upstream.

The current 256MB module virtual address space is easily exhausted when
loading massive graphics drivers such as amdgpu along with the large
unstripped symbol tables, resulting in allocation failures of "execmem:
unable to allocate memory".

Thus, expand the module virtual address space to 2GB while keeping
the current normal code model '-mcmodel=normal', rather than using the
medium code model '-mcmodel=medium'. This approach avoids the extra
performance overhead and larger binary size of forcing every function
call into a 2-instruction sequence of 'pcaddu18i + jirl'.

Given that individual module code segments rarely exceed 128MB, most
jumps remain fast direct calls by using the bl instruction. For the
long-distance jumps exceeding the +/-128MB limit, apply_r_larch_b26()
emits PLT entries, while signed_imm_check() guarantees the run-time
safety by rejecting any out-of-bound instruction offsets.

There is still a risk that the distance between .init.text and .text of
the same module exceeds 128MB. So we divide the 2GB virtual space to be
two sub-regions: the first 256MB is for module text, and the rest is for
module data.

Cc: stable@vger.kernel.org
Signed-off-by: Tiezhu Yang <yangtiezhu@loongson.cn>
Signed-off-by: Huacai Chen <chenhuacai@loongson.cn>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/loongarch/include/asm/pgtable.h |    2 +-
 arch/loongarch/mm/init.c             |   17 ++++++++++++++---
 2 files changed, 15 insertions(+), 4 deletions(-)

--- a/arch/loongarch/include/asm/pgtable.h
+++ b/arch/loongarch/include/asm/pgtable.h
@@ -96,7 +96,7 @@ struct vm_area_struct;
 #ifdef CONFIG_64BIT
 
 #define MODULES_VADDR	(vm_map_base + PCI_IOSIZE + (2 * PAGE_SIZE))
-#define MODULES_END	(MODULES_VADDR + SZ_256M)
+#define MODULES_END	(MODULES_VADDR + SZ_2G) /* 256MB for text, rest for data */
 
 #ifdef CONFIG_KFENCE
 #define KFENCE_AREA_SIZE	(((CONFIG_KFENCE_NUM_OBJECTS + 1) * 2 + 2) * PAGE_SIZE)
--- a/arch/loongarch/mm/init.c
+++ b/arch/loongarch/mm/init.c
@@ -237,15 +237,26 @@ pte_t invalid_pte_table[PTRS_PER_PTE] __
 EXPORT_SYMBOL(invalid_pte_table);
 
 #if defined(CONFIG_EXECMEM) && defined(MODULES_VADDR)
+#define MODULES_TEXT_START (MODULES_VADDR)
+#define MODULES_TEXT_END   (MODULES_VADDR + SZ_256M)
+#define MODULES_DATA_START (MODULES_VADDR + SZ_256M)
+#define MODULES_DATA_END   (MODULES_END)
+
 static struct execmem_info execmem_info __ro_after_init;
 
 struct execmem_info __init *execmem_arch_setup(void)
 {
 	execmem_info = (struct execmem_info){
 		.ranges = {
-			[EXECMEM_DEFAULT] = {
-				.start	= MODULES_VADDR,
-				.end	= MODULES_END,
+			[EXECMEM_MODULE_TEXT] = {
+				.start	= MODULES_TEXT_START,
+				.end	= MODULES_TEXT_END,
+				.pgprot	= PAGE_KERNEL,
+				.alignment = 1,
+			},
+			[EXECMEM_MODULE_DATA] = {
+				.start	= MODULES_DATA_START,
+				.end	= MODULES_DATA_END,
 				.pgprot	= PAGE_KERNEL,
 				.alignment = 1,
 			},



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 339/556] LoongArch: BPF: Move arena register slot below TCC context
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (337 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 338/556] LoongArch: Expand module virtual address space to 2GB Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 340/556] LoongArch: BPF: Fix off-by-one error for insn_is_cast_user() Greg Kroah-Hartman
                   ` (229 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Tiezhu Yang, Huacai Chen

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tiezhu Yang <yangtiezhu@loongson.cn>

commit cd7e356b07a27e91394838cf3fb655862b519294 upstream.

Currently, the stack layout places the optional arena register slot
above the tail call counter context. When arena_vm_start is dynamically
enabled, it shifts the relative offset of the tcc_ptr slot within the
stack frame, causing hardcoded tracking macros to mismatch and leading
to memory misalignment or corruption potentially.

To fix this, move the arena register save and restore sequences below
the tail call counter context slots in both build_prologue() and the
epilogue.

Update __build_epilogue() to insert a proper offset decrement to safely
skip the unneeded tcc_ptr reading block while accurately aligning with
the relocated arena slot at the very bottom.

With this patch, the tcc_ptr slot is always positioned at a fixed
distance directly underneath the base callee-saved registers that is
independent of whether the arena features are on.

Cc: stable@vger.kernel.org
Fixes: ef54c517a937 ("LoongArch: BPF: Implement PROBE_MEM32 pseudo instructions")
Signed-off-by: Tiezhu Yang <yangtiezhu@loongson.cn>
Signed-off-by: Huacai Chen <chenhuacai@loongson.cn>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/loongarch/net/bpf_jit.c | 20 +++++++++++++-------
 1 file changed, 13 insertions(+), 7 deletions(-)

diff --git a/arch/loongarch/net/bpf_jit.c b/arch/loongarch/net/bpf_jit.c
index b0c39d45d6a6..fd5f8c4e5360 100644
--- a/arch/loongarch/net/bpf_jit.c
+++ b/arch/loongarch/net/bpf_jit.c
@@ -124,6 +124,9 @@ static void prepare_bpf_tail_call_cnt(struct jit_ctx *ctx, int *store_offset)
  *                            |           tcc           |
  *                            +-------------------------+
  *                            |           tcc_ptr       |
+ *                            +-------------------------+
+ *                            |           arena         |
+ *                            |         (optional)      |
  *                            +-------------------------+ <--BPF_REG_FP
  *                            |  prog->aux->stack_depth |
  *                            |        (optional)       |
@@ -145,7 +148,7 @@ static void build_prologue(struct jit_ctx *ctx)
 	stack_adjust += sizeof(long) * 2;
 
 	if (ctx->arena_vm_start)
-		stack_adjust += 8;
+		stack_adjust += sizeof(long);
 
 	stack_adjust = round_up(stack_adjust, 16);
 	stack_adjust += bpf_stack_adjust;
@@ -194,13 +197,13 @@ static void build_prologue(struct jit_ctx *ctx)
 	store_offset -= sizeof(long);
 	emit_insn(ctx, std, LOONGARCH_GPR_S5, LOONGARCH_GPR_SP, store_offset);
 
+	prepare_bpf_tail_call_cnt(ctx, &store_offset);
+
 	if (ctx->arena_vm_start) {
 		store_offset -= sizeof(long);
 		emit_insn(ctx, std, REG_ARENA, LOONGARCH_GPR_SP, store_offset);
 	}
 
-	prepare_bpf_tail_call_cnt(ctx, &store_offset);
-
 	emit_insn(ctx, addid, LOONGARCH_GPR_FP, LOONGARCH_GPR_SP, stack_adjust);
 
 	if (bpf_stack_adjust)
@@ -241,15 +244,18 @@ static void __build_epilogue(struct jit_ctx *ctx, bool is_tail_call)
 	load_offset -= sizeof(long);
 	emit_insn(ctx, ldd, LOONGARCH_GPR_S5, LOONGARCH_GPR_SP, load_offset);
 
+	/* Only restore the TCC state into REG_TCC from the higher slot */
+	load_offset -= sizeof(long);
+	emit_insn(ctx, ldd, REG_TCC, LOONGARCH_GPR_SP, load_offset);
+
+	/* Skip the unused local 'tcc_ptr' slot to align with arena */
+	load_offset -= sizeof(long);
+
 	if (ctx->arena_vm_start) {
 		load_offset -= sizeof(long);
 		emit_insn(ctx, ldd, REG_ARENA, LOONGARCH_GPR_SP, load_offset);
 	}
 
-	/* Only restore the TCC state into REG_TCC from the higher slot */
-	load_offset -= sizeof(long);
-	emit_insn(ctx, ldd, REG_TCC, LOONGARCH_GPR_SP, load_offset);
-
 	emit_insn(ctx, addid, LOONGARCH_GPR_SP, LOONGARCH_GPR_SP, stack_adjust);
 
 	if (!is_tail_call) {
-- 
2.55.0




^ permalink raw reply related	[flat|nested] 570+ messages in thread

* [PATCH 7.2 340/556] LoongArch: BPF: Fix off-by-one error for insn_is_cast_user()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (338 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 339/556] LoongArch: BPF: Move arena register slot below TCC context Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 341/556] LoongArch: Fix acpi_package_ids[] array overflow Greg Kroah-Hartman
                   ` (228 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Tiezhu Yang, Huacai Chen

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tiezhu Yang <yangtiezhu@loongson.cn>

commit 30419a0aa128135a81be917eaa3bd2f1a10c9ca3 upstream.

In the LoongArch BPF JIT code, the branch offset represents the number
of instructions. An offset of 1 means the target of the "beq" is the
current PC plus 1 instruction (PC + 4 bytes). This matches the exact
same path as the sequential non-branch execution, the "or" instruction
is always executed for the cast_user JIT arm in build_insn().

If the pointer is not NULL, there is no side effect. But if the pointer
is NULL, it is incorrectly combined with the base address and turns into
a non-zero address, meaning a zero arena offset no longer casts to NULL.

Fix this by changing the branch offset from 1 to 2, which properly skips
the "or" instruction and jumps directly to the "move_reg" instruction if
the pointer is NULL, ensuring the destination register is safely cleared
to 0.

Cc: stable@vger.kernel.org
Fixes: 4fdb5dd8aeba ("LoongArch: BPF: Implement bpf_addr_space_cast instruction")
Signed-off-by: Tiezhu Yang <yangtiezhu@loongson.cn>
Signed-off-by: Huacai Chen <chenhuacai@loongson.cn>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/loongarch/net/bpf_jit.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/arch/loongarch/net/bpf_jit.c
+++ b/arch/loongarch/net/bpf_jit.c
@@ -734,7 +734,7 @@ static int build_insn(const struct bpf_i
 			move_reg(ctx, t1, src);
 			emit_zext_32(ctx, t1, true);
 			move_imm(ctx, dst, (ctx->user_vm_start >> 32) << 32, false);
-			emit_insn(ctx, beq, t1, LOONGARCH_GPR_ZERO, 1);
+			emit_insn(ctx, beq, t1, LOONGARCH_GPR_ZERO, 2);
 			emit_insn(ctx, or, t1, dst, t1);
 			move_reg(ctx, dst, t1);
 			break;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 341/556] LoongArch: Fix acpi_package_ids[] array overflow
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (339 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 340/556] LoongArch: BPF: Fix off-by-one error for insn_is_cast_user() Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 342/556] LoongArch: Do not select HAVE_RUST when KASAN is enabled Greg Kroah-Hartman
                   ` (227 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Tao Cui, Bibo Mao, Huacai Chen

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bibo Mao <maobibo@loongson.cn>

commit 2a2367d46d7a4ee4122b7a86e57125542dbbe963 upstream.

With LoongArch virt machine, a typical setting is one core per socket,
there will max 256 sockets (packages) on one VM. With PPTT acpi table,
array acpi_package_ids[] will be overflowed.

Here change the array size of acpi_package_ids[] with the max value of
MAX_PACKAGES and KVM_MAX_VCPUS.

Cc: stable@vger.kernel.org # 6.7+
Fixes: 4e8f58620f67 ("LoongArch: Retrieve CPU package ID from PPTT when available")
Reviewed-by: Tao Cui <cuitao@kylinos.cn>
Signed-off-by: Bibo Mao <maobibo@loongson.cn>
Signed-off-by: Huacai Chen <chenhuacai@loongson.cn>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/loongarch/kernel/acpi.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/arch/loongarch/kernel/acpi.c
+++ b/arch/loongarch/kernel/acpi.c
@@ -13,6 +13,7 @@
 #include <linux/export.h>
 #include <linux/irq.h>
 #include <linux/irqdomain.h>
+#include <linux/kvm_host.h>
 #include <linux/memblock.h>
 #include <linux/of_fdt.h>
 #include <linux/serial_core.h>
@@ -202,7 +203,7 @@ static void __init acpi_process_madt(voi
 
 int pptt_enabled;
 static int acpi_nr_packages;
-static int acpi_package_ids[MAX_PACKAGES];
+static int acpi_package_ids[MAX(MAX_PACKAGES, KVM_MAX_VCPUS)];
 
 int __init parse_acpi_topology(void)
 {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 342/556] LoongArch: Do not select HAVE_RUST when KASAN is enabled
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (340 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 341/556] LoongArch: Fix acpi_package_ids[] array overflow Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 343/556] LoongArch: Do not save/restore percpu base register in rethook trampoline Greg Kroah-Hartman
                   ` (226 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Miguel Ojeda, Nathan Chancellor,
	Huacai Chen

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nathan Chancellor <nathan@kernel.org>

commit 63b6a48c951d63bf39d44603ada48a987ccf66eb upstream.

After commit 2625480a1bf7 ("hardening: Default randstruct off with rust
for better allmodconfig support"), which allows Rust to be enabled for
allmodconfig, ARCH=loongarch allmodconfig starts failing with:

  error: kernel-address sanitizer is not supported for this target

  error: aborting due to 1 previous error

  make[4]: *** [rust/Makefile:741: rust/core.o] Error 1

For the same reason as the commit 84a0f7caafc679f7 ("ARM: Do not select
HAVE_RUST when KASAN is enabled"), do not select HAVE_RUST when KASAN
is enabled until the loongarch64-unknown-none-softfloat target in rustc
supports KASAN.

Cc: stable@vger.kernel.org
Fixes: 90868ff9cade ("LoongArch: Enable initial Rust support")
Acked-by: Miguel Ojeda <ojeda@kernel.org>
Signed-off-by: Nathan Chancellor <nathan@kernel.org>
Signed-off-by: Huacai Chen <chenhuacai@loongson.cn>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/loongarch/Kconfig |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/arch/loongarch/Kconfig
+++ b/arch/loongarch/Kconfig
@@ -175,7 +175,7 @@ config LOONGARCH
 	select HAVE_RELIABLE_STACKTRACE if UNWINDER_ORC
 	select HAVE_RETHOOK
 	select HAVE_RSEQ
-	select HAVE_RUST
+	select HAVE_RUST if !KASAN
 	select HAVE_SAMPLE_FTRACE_DIRECT
 	select HAVE_SAMPLE_FTRACE_DIRECT_MULTI
 	select HAVE_SETUP_PER_CPU_AREA if NUMA



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 343/556] LoongArch: Do not save/restore percpu base register in rethook trampoline
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (341 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 342/556] LoongArch: Do not select HAVE_RUST when KASAN is enabled Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 344/556] LoongArch: Avoid preempt count underflow without probe Greg Kroah-Hartman
                   ` (225 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Wentao Guan, Huacai Chen

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wentao Guan <guanwentao@uniontech.com>

commit c3f2feace5e4f4b01b68b9f947b19adb4155c32e upstream.

The rethook trampoline saves $r21 ($u0), the percpu base, into its frame
at entry and restores it at exit. Inbetween rethook_trampoline_handler()
may schedule via preempt_enable_notrace().

If the task migrates to another CPU, the frame's $r21 holds the old
CPU's percpu base, and restoring it poisons $r21 on the new CPU. Until
the next user->kernel transition heals $r21, all this_cpu_*() accesses
(runqueues, RCU per-CPU data, timer tick programming, FPU ownership)
hit the wrong CPU's percpu area.

Under kretprobe-heavy preemptible load this can corrupt scheduler and
timer state: scheduling-while-atomic splats, wrong-CPU RCU warnings,
WARN_ON_ONCE(rq != this_rq()) in nohz_balance_exit_idle(), and CPUs
parking in the idle loop with the constant timer never re-armed (hard
lockup). Reproduces on a Loongson-3A6000 with kretprobes on VFS paths
plus heavy file churn (OS install / unsquashfs).

By convention $r21 always holds the current CPU's percpu base in kernel
mode: SAVE_SOME() at exception entry reloads it only when coming from
user mode, and RESTORE_SOME() restores it only when returning to user
mode; the context-switch path never writes it. Therefore the live $r21
at trampoline exit is already correct, and nothing inbetween can change
it legitimately (kernel C code cannot write a global register variable).
The same flaw existed even in the pre-rethook kretprobe trampoline since
v6.3; it was carried over when rethook replaced it. Drop both the save
and the restore here. Drop the restore is enough to solve the issue, and
drop the save is to keep the code tidy and no need to clear it.

Cc: stable@vger.kernel.org # v6.3+
Fixes: 3f5536860086d ("LoongArch: Add kretprobes support")
Assisted-by: Kimi:Kimi-K3 # debug and root-cause analysis
Signed-off-by: Wentao Guan <guanwentao@uniontech.com>
Signed-off-by: Huacai Chen <chenhuacai@loongson.cn>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/loongarch/kernel/rethook_trampoline.S |    2 --
 1 file changed, 2 deletions(-)

--- a/arch/loongarch/kernel/rethook_trampoline.S
+++ b/arch/loongarch/kernel/rethook_trampoline.S
@@ -24,7 +24,6 @@
 	cfi_st	t6, PT_R18
 	cfi_st	t7, PT_R19
 	cfi_st	t8, PT_R20
-	cfi_st	u0, PT_R21
 	cfi_st	fp, PT_R22
 	cfi_st	s0, PT_R23
 	cfi_st	s1, PT_R24
@@ -59,7 +58,6 @@
 	cfi_ld	t6, PT_R18
 	cfi_ld	t7, PT_R19
 	cfi_ld	t8, PT_R20
-	cfi_ld	u0, PT_R21
 	cfi_ld	fp, PT_R22
 	cfi_ld	s0, PT_R23
 	cfi_ld	s1, PT_R24



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 344/556] LoongArch: Avoid preempt count underflow without probe
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (342 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 343/556] LoongArch: Do not save/restore percpu base register in rethook trampoline Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 345/556] rust: drm: ioctl: fix unbounded lifetimes in ioctl handler arguments Greg Kroah-Hartman
                   ` (224 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jérémy Jean, Huacai Chen

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>

commit 72ce4b24676e8b3b75376c4c559dd81c1ac52d5a upstream.

LoongArch uses break 11 for the breakpoint placed after an instruction
that Kprobes executes out of line. Since userspace can issue the same
break instruction, do_bp() can reach kprobe_singlestep_handler() when
there is no current probe.

The handler actually returns false in this case, but it first calls
preempt_enable_no_resched(). The corresponding preempt_disable() is done
by kprobe_breakpoint_handler() on a real Kprobe hit, so it has not run
here. As a result, an ordinary userspace breakpoint (code 11) underflows
the current task's preempt count.

This also makes in_interrupt() return true until the task schedules. One
visible consequence is the socket cgroup attribution: cgroup_sk_alloc()
treats the allocation as interrupt context and assigns the socket to the
root cgroup. A socket opened from the SIGTRAP handler can then avoid a
BPF_CGROUP_INET_SOCK_CREATE policy attached to the task's own cgroup.

Return as soon as kprobe_running() reports no active probe.

The same check has appeared in [PATCH v10 2/4] of the original LoongArch
Kprobes series, but was dropped before the feature reached mainline.

Cc: stable@vger.kernel.org
Fixes: 6d4cc40fb5f5 ("LoongArch: Add kprobes support")
Link: https://lore.kernel.org/loongarch/1670575981-14389-3-git-send-email-yangtiezhu@loongson.cn/
Assisted-by: Codex:gpt-5
Signed-off-by: Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
Signed-off-by: Huacai Chen <chenhuacai@loongson.cn>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 arch/loongarch/kernel/kprobes.c |    3 +++
 1 file changed, 3 insertions(+)

--- a/arch/loongarch/kernel/kprobes.c
+++ b/arch/loongarch/kernel/kprobes.c
@@ -275,6 +275,9 @@ bool kprobe_singlestep_handler(struct pt
 	struct kprobe_ctlblk *kcb = get_kprobe_ctlblk();
 	unsigned long addr = instruction_pointer(regs);
 
+	if (!cur)
+		return false;
+
 	if (cur && (kcb->kprobe_status & (KPROBE_HIT_SS | KPROBE_REENTER)) &&
 	    ((unsigned long)&cur->ainsn.insn[1] == addr)) {
 		restore_local_irqflag(kcb, regs);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 345/556] rust: drm: ioctl: fix unbounded lifetimes in ioctl handler arguments
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (343 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 344/556] LoongArch: Avoid preempt count underflow without probe Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 346/556] media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref Greg Kroah-Hartman
                   ` (223 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Gary Guo,
	Alexandre Courbot, Lyude Paul, Deborah Brouwer, Danilo Krummrich

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Danilo Krummrich <dakr@kernel.org>

commit 68b151bc6145dea3db5598ebaf4b776cd205e395 upstream.

References to dev, data, and file in the declare_drm_ioctls! macro are
created via unsafe pointer dereferences, producing unbounded lifetimes.
If an ioctl handler explicitly annotates its parameters with 'static,
the compiler accepts this, allowing the handler to stash references that
outlive the ioctl call.

Fix this by adding a higher-ranked function pointer coercion that
enforces the handler accepts universally quantified lifetimes:

  let _: for<'a> fn(&'a _, &'a mut _, &'a _) -> _ = $func;

Since the handler must be coercible to a function pointer accepting any
lifetime 'a, it can no longer demand 'static on any parameter.

Cc: stable@vger.kernel.org
Fixes: 9a69570682b1 ("rust: drm: ioctl: Add DRM ioctl abstraction")
Reported-by: sashiko-bot@kernel.org
Closes: https://lore.kernel.org/all/20260620011346.A47D01F000E9@smtp.kernel.org/
Suggested-by: Gary Guo <gary@garyguo.net>
Reviewed-by: Alexandre Courbot <acourbot@nvidia.com>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Tested-by: Deborah Brouwer <deborah.brouwer@collabora.com>
Link: https://patch.msgid.link/20260628145406.2107056-2-dakr@kernel.org
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 rust/kernel/drm/ioctl.rs |    6 ++++++
 1 file changed, 6 insertions(+)

--- a/rust/kernel/drm/ioctl.rs
+++ b/rust/kernel/drm/ioctl.rs
@@ -135,6 +135,12 @@ macro_rules! declare_drm_ioctls {
                             // dev/file match the current driver these ioctls are being declared
                             // for, and it's not clear how to enforce this within the type system.
                             let dev = $crate::drm::device::Device::from_raw(raw_dev);
+
+                            // Enforce that the handler accepts higher-ranked
+                            // lifetimes, preventing it from requiring 'static
+                            // references that could escape this scope.
+                            let _: for<'a> fn(&'a _, &'a mut _, &'a _) -> _ = $func;
+
                             // SAFETY: The ioctl argument has size `_IOC_SIZE(cmd)`, which we
                             // asserted above matches the size of this type, and all bit patterns of
                             // UAPI structs must be valid.



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 346/556] media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (344 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 345/556] rust: drm: ioctl: fix unbounded lifetimes in ioctl handler arguments Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 347/556] media: amphion: Remove obsolete frame_count check in venc_start_session Greg Kroah-Hartman
                   ` (222 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Hans Verkuil, Valery Borovsky

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Valery Borovsky <vebohr@gmail.com>

commit 2f378dc45e685fc825d2dd08e7864666d6fcc009 upstream.

airspy_disconnect() clears s->udev under v4l2_lock, but
airspy_stop_streaming() unconditionally calls airspy_ctrl_msg() and
airspy_free_stream_bufs() afterwards. If a streaming user closes the
device after disconnect, stop_streaming() runs and dereferences the
NULL s->udev:

  airspy_stop_streaming()
    airspy_ctrl_msg(s, CMD_RECEIVER_MODE, 0, 0, NULL, 0)
      usb_sndctrlpipe(s->udev, 0)         /* NULL deref */
    airspy_free_stream_bufs(s)
      usb_free_coherent(s->udev, ...)     /* NULL deref */

The airspy driver uses vb2_fop_release() in its file_operations, so
replace video_unregister_device(&s->vdev) with
vb2_video_unregister_device(&s->vdev) and move it before clearing
s->udev. vb2_video_unregister_device() releases the vb2 queue, which
synchronously runs airspy_stop_streaming() if streaming is active, so
the URBs, coherent DMA stream buffers and the hardware stop control
message all execute while s->udev is still valid.

vb2_video_unregister_device() locks vdev->queue->lock (vb_queue_lock)
internally, and stop_streaming() locks v4l2_lock, so the previous outer
mutex_lock(&s->vb_queue_lock) / mutex_lock(&s->v4l2_lock) pair around
the unregister sequence would self-deadlock and has been removed. A
short v4l2_lock critical section around s->udev = NULL remains so any
ioctl path that still holds the file descriptor sees coherent state.

Issue identified by automated review of the INV-003 series at
https://sashiko.dev/

Fixes: 634fe5033951 ("[media] airspy: AirSpy SDR driver")
Cc: stable@vger.kernel.org
Suggested-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Valery Borovsky <vebohr@gmail.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/usb/airspy/airspy.c |   17 ++++++++++++-----
 1 file changed, 12 insertions(+), 5 deletions(-)

--- a/drivers/media/usb/airspy/airspy.c
+++ b/drivers/media/usb/airspy/airspy.c
@@ -464,14 +464,21 @@ static void airspy_disconnect(struct usb
 
 	dev_dbg(s->dev, "\n");
 
-	mutex_lock(&s->vb_queue_lock);
+	/*
+	 * vb2_video_unregister_device() releases the vb2 queue, which
+	 * triggers airspy_stop_streaming() if streaming is active.
+	 * stop_streaming() dereferences s->udev via airspy_ctrl_msg() and
+	 * airspy_free_stream_bufs(), so it must run before s->udev is
+	 * cleared. vb2_video_unregister_device() locks vb_queue_lock
+	 * internally and stop_streaming() locks v4l2_lock, so neither may
+	 * be held by the caller.
+	 */
+	v4l2_device_disconnect(&s->v4l2_dev);
+	vb2_video_unregister_device(&s->vdev);
+
 	mutex_lock(&s->v4l2_lock);
-	/* No need to keep the urbs around after disconnection */
 	s->udev = NULL;
-	v4l2_device_disconnect(&s->v4l2_dev);
-	video_unregister_device(&s->vdev);
 	mutex_unlock(&s->v4l2_lock);
-	mutex_unlock(&s->vb_queue_lock);
 
 	v4l2_device_put(&s->v4l2_dev);
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 347/556] media: amphion: Remove obsolete frame_count check in venc_start_session
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (345 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 346/556] media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 348/556] media: bcm2835-unicam: Fix pipeline wrong validation for unpacked formats Greg Kroah-Hartman
                   ` (221 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ming Qian, Frank Li,
	Nicolas Dufresne, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ming Qian <ming.qian@oss.nxp.com>

commit 2be6ee86385badab95b1bace984735bde6e0fec0 upstream.

The dev_err() log warning about no input when starting was originally
meaningful when min_queued_buffers was set, as it indicated an abnormal
condition. However, since commit 5633ec763a2a ("media: amphion: Drop
min_queued_buffers assignment") removed the min_queued_buffers
assignment, having frame_count == 0 at start is a normal condition.

Remove this misleading log that no longer serves any purpose.

Fixes: 5633ec763a2a ("media: amphion: Drop min_queued_buffers assignment")
Cc: stable@vger.kernel.org
Signed-off-by: Ming Qian <ming.qian@oss.nxp.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/amphion/venc.c |    2 --
 1 file changed, 2 deletions(-)

--- a/drivers/media/platform/amphion/venc.c
+++ b/drivers/media/platform/amphion/venc.c
@@ -973,8 +973,6 @@ static int venc_start_session(struct vpu
 	venc->ready_count = 0;
 	venc->stopped = false;
 	vpu_process_output_buffer(inst);
-	if (venc->frame_count == 0)
-		dev_err(inst->dev, "[%d] there is no input when starting\n", inst->id);
 
 	return 0;
 error:



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 348/556] media: bcm2835-unicam: Fix pipeline wrong validation for unpacked formats
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (346 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 347/556] media: amphion: Remove obsolete frame_count check in venc_start_session Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 349/556] media: cec: core: Fix kmemleak due to missed rc_free_device() call Greg Kroah-Hartman
                   ` (220 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Eugen Hristev, Jai Luthra,
	Dave Stevenson, Sakari Ailus

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eugen Hristev <ehristev@kernel.org>

commit 4f26c8345dbfa92f19078c788be1b9bfd425ed60 upstream.

The commit
08f9794d9b79 ("media: bcm2835-unicam: Fix RGB format / mbus code association")
introduced a check to see whether the format requested is the same as the
fourcc in the format list.

However, this breaks the case when userspace requested an unpacked fourcc,
e.g. RG10.

Unicam can work with or without unpacking pixels, e.g. pRAA or RG10, depending
on what userspace requests.
In the unpacking case, a dedicated register is being set.

If the userspace requests pRAA, this works, because the check validates the
pipeline:

v4l2-ctl -d /dev/video0 --set-fmt-video=width=3280,height=2464,pixelformat=pRAA \
 --stream-mmap --stream-count=1 --stream-to=frame.raw

but, with
v4l2-ctl -d /dev/video0 --set-fmt-video=width=3280,height=2464,pixelformat=RG10 \
--stream-mmap --stream-count=1 --stream-to=frame.raw

unicam complains at validation level:

image: format mismatch: 0x300f <=> RG10 little-endian (0x30314752)

This should work, because MEDIA_BUS_FMT_SRGGB10_1X10 can be packed into either
RG10 or pRAA depending on the packing register.

To fix this, modified the condition check to also allow in the case when
requested format (fmt->pixelformat) is equal to fmtinfo->unpacked_fourcc.

Fixes: 08f9794d9b79 ("media: bcm2835-unicam: Fix RGB format / mbus code association")
Cc: stable@vger.kernel.org
Signed-off-by: Eugen Hristev <ehristev@kernel.org>
Reviewed-by: Jai Luthra <jai.luthra@ideasonboard.com>
Reviewed-by: Dave Stevenson <dave.stevenson@raspberrypi.com>
[Sakari Ailus: Added Cc: stable.]
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/broadcom/bcm2835-unicam.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/drivers/media/platform/broadcom/bcm2835-unicam.c
+++ b/drivers/media/platform/broadcom/bcm2835-unicam.c
@@ -2158,7 +2158,8 @@ static int unicam_video_link_validate(st
 		 * In order to allow the applications using the old behaviour to
 		 * run, let's accept the old combination, but warn about it.
 		 */
-		if (fmtinfo->fourcc != fmt->pixelformat) {
+		if (fmt->pixelformat != fmtinfo->fourcc &&
+		    fmt->pixelformat != fmtinfo->unpacked_fourcc) {
 			if ((fmt->pixelformat == V4L2_PIX_FMT_BGR24 &&
 			     format->code == MEDIA_BUS_FMT_BGR888_1X24) ||
 			    (fmt->pixelformat == V4L2_PIX_FMT_RGB24 &&



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 349/556] media: cec: core: Fix kmemleak due to missed rc_free_device() call
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (347 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 348/556] media: bcm2835-unicam: Fix pipeline wrong validation for unpacked formats Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 350/556] media: cec: disable delayed work before freeing an interrupted transmit Greg Kroah-Hartman
                   ` (219 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jonas Karlman, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jonas Karlman <jonas@kwiboo.se>

commit a24ba0653f7154e671dc8d2bf64682ab2d042792 upstream.

The commit dccc0c3ddf8f ("media: rc: fix race between unregister and
urb/irq callbacks") removed the implicit call to rc_free_device() from
rc_unregister_device(). However, the commit missed to remove the NULL
assignment of adap->rc that is now causing rc_free_device() to never be
called on an allocated rc device.

kmemleak reports following after e.g. dw-hdmi unbind:

unreferenced object 0xffff00010ac10000 (size 4096):
  comm "kworker/u16:1", pid 39, jiffies 4294897739
  hex dump (first 32 bytes):
    20 23 4b 0a 01 00 ff ff 08 00 c1 0a 01 00 ff ff   #K.............
    08 00 c1 0a 01 00 ff ff 00 00 00 00 00 00 00 00  ................
  backtrace (crc e11baccc):
    kmemleak_alloc+0x38/0x44
    __kmalloc_cache_noprof+0x4a8/0x5e0
    rc_allocate_device+0x48/0x2a0
    cec_allocate_adapter+0x3ac/0x800
    dw_hdmi_cec_probe+0x264/0x634
    platform_probe+0xc0/0x188
    really_probe+0x4a4/0x8e0
    __driver_probe_device+0x2f8/0x440
    driver_probe_device+0x60/0x160
    __device_attach_driver+0x1a0/0x2a0
    bus_for_each_drv+0x100/0x1a0
    __device_attach+0x174/0x350
    device_initial_probe+0x90/0xb0
    bus_probe_device+0x4c/0x120
    device_add+0xdec/0x116c
    platform_device_add+0x354/0x598

Remove the assignment of adap->rc to NULL to let cec_delete_adapter()
free the allocated rc device after last user of the cec device exits to
fix the kmemleak.

Fixes: dccc0c3ddf8f ("media: rc: fix race between unregister and urb/irq callbacks")
Cc: stable@vger.kernel.org
Signed-off-by: Jonas Karlman <jonas@kwiboo.se>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/cec/core/cec-core.c |    2 --
 1 file changed, 2 deletions(-)

--- a/drivers/media/cec/core/cec-core.c
+++ b/drivers/media/cec/core/cec-core.c
@@ -371,9 +371,7 @@ void cec_unregister_adapter(struct cec_a
 		return;
 
 #ifdef CONFIG_MEDIA_CEC_RC
-	/* Note: rc_unregister also calls rc_free */
 	rc_unregister_device(adap->rc);
-	adap->rc = NULL;
 #endif
 	debugfs_remove_recursive(adap->cec_dir);
 #ifdef CONFIG_CEC_NOTIFIER



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 350/556] media: cec: disable delayed work before freeing an interrupted transmit
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (348 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 349/556] media: cec: core: Fix kmemleak due to missed rc_free_device() call Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 351/556] media: cec: extron-da-hd-4k-plus: add sanity check Greg Kroah-Hartman
                   ` (218 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+051024d603432b4ab395,
	Hillf Danton, Biren Pandya, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Biren Pandya <birenpandya@gmail.com>

commit 0fbd5c2327020858c45b2d1c65775d64cdeca523 upstream.

cec_transmit_msg_fh() drops adap->lock to wait for a blocking transmit in
wait_for_completion_killable(). If that wait is interrupted by a signal,
cancel_delayed_work_sync() can run before the CEC kthread arms the reply
timeout via schedule_delayed_work(&data->work) in cec_transmit_done_ts().
The work is then armed after the cancel, and the data is freed with its
delayed_work still pending:

  ODEBUG: free active (active state 0) object: ... hint: cec_wait_timeout

Use disable_delayed_work_sync(): it cancels the work and disables it, so
the later schedule_delayed_work() becomes a no-op and the work cannot be
re-armed. The data is freed right after, so it need not be re-enabled.

Fixes: 490d84f6d73c ("media: cec: forgot to cancel delayed work")
Reported-by: syzbot+051024d603432b4ab395@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=051024d603432b4ab395
Suggested-by: Hillf Danton <hdanton@sina.com>
Cc: stable@vger.kernel.org
Signed-off-by: Biren Pandya <birenpandya@gmail.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/cec/core/cec-adap.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/media/cec/core/cec-adap.c
+++ b/drivers/media/cec/core/cec-adap.c
@@ -965,7 +965,7 @@ int cec_transmit_msg_fh(struct cec_adapt
 	 */
 	mutex_unlock(&adap->lock);
 	err = wait_for_completion_killable(&data->c);
-	cancel_delayed_work_sync(&data->work);
+	disable_delayed_work_sync(&data->work);
 	mutex_lock(&adap->lock);
 
 	if (err)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 351/556] media: cec: extron-da-hd-4k-plus: add sanity check
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (349 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 350/556] media: cec: disable delayed work before freeing an interrupted transmit Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 352/556] media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid debugfs clash Greg Kroah-Hartman
                   ` (217 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Hans Verkuil, Sean Young

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Hans Verkuil <hverkuil+cisco@kernel.org>

commit abac9820b26b5cfcb01eb79efe2abdd0ac7e07c3 upstream.

Add check to prevent overflowing msg.msg[] in case the incoming data
is malformed.

Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Reviewed-by: Sean Young <sean@mess.org>
Fixes: 056f2821b631 ("media: cec: extron-da-hd-4k-plus: add the Extron DA HD 4K Plus CEC driver")
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/cec/usb/extron-da-hd-4k-plus/extron-da-hd-4k-plus.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/drivers/media/cec/usb/extron-da-hd-4k-plus/extron-da-hd-4k-plus.c
+++ b/drivers/media/cec/usb/extron-da-hd-4k-plus/extron-da-hd-4k-plus.c
@@ -657,7 +657,8 @@ static void extron_process_received(stru
 	if (!port || port->disconnected)
 		return;
 
-	if (len < 5 || (len - 2) % 3 || data[len - 2] != '*')
+	if (len < 5 || ((len - 2) / 3 > sizeof(msg.msg)) ||
+	    (len - 2) % 3 || data[len - 2] != '*')
 		goto malformed;
 
 	while (*data != '*') {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 352/556] media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid debugfs clash
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (350 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 351/556] media: cec: extron-da-hd-4k-plus: add sanity check Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 353/556] media: cec: Serialize exclusive follower delivery Greg Kroah-Hartman
                   ` (216 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Yi Ding, Neil Armstrong,
	Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yi Ding <yi.s.ding@gmail.com>

commit 172c5a7d81deb922ddedd1bc920751c7fed6c43c upstream.

The driver registers two regmaps on the same platform device: an MMIO
regmap for the AO CEC registers, and an indirect regmap (using
reg_read()/reg_write() callbacks) for the CEC controller core registers.
Neither regmap_config sets a .name, so both default their debugfs
directory to the device name and collide:

  debugfs: 'ff800280.cec' already exists in 'regmap'

Because of the clash the second regmap's debugfs directory fails to
register, so its registers can no longer be inspected via debugfs.

Give the indirect CEC core regmap a distinct name. The two debugfs
directories then become "<dev>.cec" and "<dev>.cec-core". This only
affects debugfs naming; register access is unchanged.

Tested on an ODROID-N2 (Amlogic S922X): the warning is gone and both
/sys/kernel/debug/regmap/ff800280.cec and ff800280.cec-core are present.

Fixes: b7778c46683c ("media: platform: meson: Add Amlogic Meson G12A AO CEC Controller driver")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Yi Ding <yi.s.ding@gmail.com>
Reviewed-by: Neil Armstrong <neil.armstrong@linaro.org>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/cec/platform/meson/ao-cec-g12a.c |    1 +
 1 file changed, 1 insertion(+)

--- a/drivers/media/cec/platform/meson/ao-cec-g12a.c
+++ b/drivers/media/cec/platform/meson/ao-cec-g12a.c
@@ -405,6 +405,7 @@ static int meson_ao_cec_g12a_write(void
 }
 
 static const struct regmap_config meson_ao_cec_g12a_cec_regmap_conf = {
+	.name = "core",
 	.reg_bits = 8,
 	.val_bits = 8,
 	.reg_read = meson_ao_cec_g12a_read,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 353/556] media: cec: Serialize exclusive follower delivery
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (351 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 352/556] media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid debugfs clash Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 354/556] media: cedrus: fix memory leak in cedrus_init_ctrls() Greg Kroah-Hartman
                   ` (215 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Ruoyu Wang, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ruoyu Wang <ruoyuw560@gmail.com>

commit 1924d0788caa6c66fd320dd4704fae99487fd2c7 upstream.

cec_receive_notify() reads the exclusive follower pointer without the
adapter lock. Serialize the no-follower check and message delivery
against mode changes and release.

Fixes: 9881fe0ca187 ("[media] cec: add HDMI CEC framework (adapter)")
Cc: stable@vger.kernel.org
Signed-off-by: Ruoyu Wang <ruoyuw560@gmail.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/cec/core/cec-adap.c |    8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

--- a/drivers/media/cec/core/cec-adap.c
+++ b/drivers/media/cec/core/cec-adap.c
@@ -2219,9 +2219,13 @@ static int cec_receive_notify(struct cec
 		 * Unprocessed messages are aborted if userspace isn't doing
 		 * any processing either.
 		 */
+		mutex_lock(&adap->lock);
 		if (!is_broadcast && !is_reply && !adap->follower_cnt &&
-		    !adap->cec_follower && msg->msg[1] != CEC_MSG_FEATURE_ABORT)
+		    !adap->cec_follower && msg->msg[1] != CEC_MSG_FEATURE_ABORT) {
+			mutex_unlock(&adap->lock);
 			return cec_feature_abort(adap, msg);
+		}
+		mutex_unlock(&adap->lock);
 		break;
 	}
 
@@ -2234,10 +2238,12 @@ skip_processing:
 	 * Send to the exclusive follower if there is one, otherwise send
 	 * to all followers.
 	 */
+	mutex_lock(&adap->lock);
 	if (adap->cec_follower)
 		cec_queue_msg_fh(adap->cec_follower, msg);
 	else
 		cec_queue_msg_followers(adap, msg);
+	mutex_unlock(&adap->lock);
 	return 0;
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 354/556] media: cedrus: fix memory leak in cedrus_init_ctrls()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (352 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 353/556] media: cec: Serialize exclusive follower delivery Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 355/556] media: cobalt: Avoid freeing ALSA private data twice Greg Kroah-Hartman
                   ` (214 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dawei Feng, Jernej Skrabec,
	Dan Carpenter, Nicolas Dufresne, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dawei Feng <dawei.feng@seu.edu.cn>

commit 9df2fbe563194da1967a5db083442186c1323efe upstream.

In cedrus_init_ctrls(), the V4L2 control handler is initialized before
allocating memory for ctx->ctrls. If this allocation fails, the function
returns -ENOMEM without freeing the previously allocated handler
resources, leading to a memory leak.

Fix this by calling v4l2_ctrl_handler_free() on the ctx->ctrls allocation
failure path.

The bug was first flagged by an experimental analysis tool we are
developing for kernel memory-management bugs while analyzing
v6.13-rc1. The tool is still under development and is not yet publicly
available. Manual inspection confirms that the bug is still
present in v7.1.1.

An x86_64 allyesconfig build showed no new warnings. As we do not have an
Allwinner SoC or board with a Cedrus VPU available to test with, no
runtime testing was able to be performed.

Fixes: 50e761516f2b ("media: platform: Add Cedrus VPU decoder driver")
Cc: stable@vger.kernel.org
Signed-off-by: Dawei Feng <dawei.feng@seu.edu.cn>
Acked-by: Jernej Skrabec <jernej.skrabec@gmail.com>
Reviewed-by: Dan Carpenter <error27@gmail.com>
Signed-off-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/staging/media/sunxi/cedrus/cedrus.c |    4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

--- a/drivers/staging/media/sunxi/cedrus/cedrus.c
+++ b/drivers/staging/media/sunxi/cedrus/cedrus.c
@@ -285,8 +285,10 @@ static int cedrus_init_ctrls(struct cedr
 	ctrl_size = sizeof(ctrl) * CEDRUS_CONTROLS_COUNT + 1;
 
 	ctx->ctrls = kzalloc(ctrl_size, GFP_KERNEL);
-	if (!ctx->ctrls)
+	if (!ctx->ctrls) {
+		v4l2_ctrl_handler_free(hdl);
 		return -ENOMEM;
+	}
 
 	j = 0;
 	for (i = 0; i < CEDRUS_CONTROLS_COUNT; i++) {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 355/556] media: cobalt: Avoid freeing ALSA private data twice
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (353 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 354/556] media: cedrus: fix memory leak in cedrus_init_ctrls() Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 356/556] media: cx231xx: reject geometry changes while the VBI queue is busy Greg Kroah-Hartman
                   ` (213 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Ruoyu Wang, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ruoyu Wang <ruoyuw560@gmail.com>

commit 3a7d6b9c4cb5ac18cbd3f1c7f8c7b159c42ba0b1 upstream.

snd_cobalt_card_create() stores cobsc in sc->private_data and installs
snd_cobalt_card_private_free() as sc->private_free. From that point,
snd_card_free(sc) releases cobsc through the ALSA card cleanup path.

If cobalt_alsa_init() fails after snd_cobalt_card_create(), the
err_exit_free path calls snd_card_free(sc) and then kfree(cobsc). That
second free releases the same object again.

Remove the explicit kfree(cobsc) and leave ownership with the ALSA card.

This issue was found by a static analysis checker and confirmed by
manual source review.

Fixes: 85756a069c55 ("[media] cobalt: add new driver")
Cc: stable@vger.kernel.org
Signed-off-by: Ruoyu Wang <ruoyuw560@gmail.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/pci/cobalt/cobalt-alsa-main.c |    1 -
 1 file changed, 1 deletion(-)

--- a/drivers/media/pci/cobalt/cobalt-alsa-main.c
+++ b/drivers/media/pci/cobalt/cobalt-alsa-main.c
@@ -135,7 +135,6 @@ int cobalt_alsa_init(struct cobalt_strea
 err_exit_free:
 	if (sc != NULL)
 		snd_card_free(sc);
-	kfree(cobsc);
 err_exit:
 	return ret;
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 356/556] media: cx231xx: reject geometry changes while the VBI queue is busy
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (354 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 355/556] media: cobalt: Avoid freeing ALSA private data twice Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 357/556] media: cx23885: cancel NetUP CI work before teardown Greg Kroah-Hartman
                   ` (212 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Bryam Vargas, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bryam Vargas <hexlabsecurity@proton.me>

commit 627a121c15fe05a541f44d86016294b80bada75d upstream.

vidioc_s_fmt_vid_cap() and vidioc_s_std() change the device-wide
dev->width / dev->norm but only refuse the change when the *video* queue
(dev->vidq) is busy. The VBI queue (dev->vbiq) shares that same geometry:
cx231xx_init_vbi_isoc() latches dma_q->lines_per_field from dev->norm,
the VBI videobuf2 plane is sized from dev->width / dev->norm in
vbi_queue_setup() and vbi_buf_prepare(), and cx231xx_do_vbi_copy() then
recomputes the destination offset from the *live* dev->width and the
latched lines_per_field on every URB completion:

	offset = lines_completed * (dev->width << 1) + ...;
	if (dma_q->current_field == 2)
		offset += dev->width * 2 * dma_q->lines_per_field;
	memcpy(plane + offset, p_buffer, lencopy);

Because the VBI node shares video_ioctl_ops with the video node, an
application can size a small VBI plane (REQBUFS/QBUF with a small width,
or with the NTSC standard), then enlarge dev->width (or switch dev->norm
to PAL) through the video node while the VBI stream is running -- the
change is allowed because only dev->vidq is checked -- and let the device
deliver a field-2 VBI payload. cx231xx_do_vbi_copy() now computes the
offset with the larger geometry and memcpy()s past the end of the smaller
plane that was already allocated, a heap out-of-bounds write whose offset
is attacker-chosen and whose contents come from the device. The
per-field guard in cx231xx_copy_vbi_line() does not help: it bounds the
copy against the latched lines_per_field, not the plane's real capacity,
and vb2 does not re-run buf_prepare() for an already prepared buffer.

Refuse the format/standard change when the VBI queue is busy as well, so
the geometry cannot change underneath an allocated VBI buffer.

Fixes: 7c617138b825 ("media: cx231xx: convert to the vb2 framework")
Cc: stable@vger.kernel.org
Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/usb/cx231xx/cx231xx-video.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/drivers/media/usb/cx231xx/cx231xx-video.c
+++ b/drivers/media/usb/cx231xx/cx231xx-video.c
@@ -898,7 +898,7 @@ static int vidioc_s_fmt_vid_cap(struct f
 	if (rc)
 		return rc;
 
-	if (vb2_is_busy(&dev->vidq)) {
+	if (vb2_is_busy(&dev->vidq) || vb2_is_busy(&dev->vbiq)) {
 		dev_err(dev->dev, "%s: queue busy\n", __func__);
 		return -EBUSY;
 	}
@@ -933,7 +933,7 @@ static int vidioc_s_std(struct file *fil
 	if (dev->norm == norm)
 		return 0;
 
-	if (vb2_is_busy(&dev->vidq))
+	if (vb2_is_busy(&dev->vidq) || vb2_is_busy(&dev->vbiq))
 		return -EBUSY;
 
 	dev->norm = norm;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 357/556] media: cx23885: cancel NetUP CI work before teardown
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (355 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 356/556] media: cx231xx: reject geometry changes while the VBI queue is busy Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 358/556] media: dt-bindings: nxp,imx8-isi: Drop fsl,blk-ctrl requirement for i.MX8ULP Greg Kroah-Hartman
                   ` (211 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Fan Wu, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Fan Wu <fanwu01@zju.edu.cn>

commit 4e143d662ca94888b494b2427fc9e34494eb933a upstream.

netup_ci_exit() frees a netup_ci_state while its work item,
netup_read_ci_status(), may still be pending or running on the system
workqueue. The worker obtains the state with container_of() and
dereferences it, so it must not outlive the state.

netup_ci_init() queues the initial status read, and CI GPIO interrupts
subsequently queue the same work from netup_ci_slot_status(). During
remove, cx23885_finidev() calls free_irq() before the CI device is
unregistered. free_irq() prevents further IRQ handlers from running,
but does not drain work queued previously, so the worker can run after
netup_ci_exit() frees the state.

Call cancel_work_sync() before dvb_ca_en50221_release() and kfree().

This issue was found by an in-house static analysis tool.

Fixes: c184dcd28233 ("V4L/DVB (10798): Add CIMax(R) SP2 Common Interface code for NetUP Dual DVB-S2 CI card")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5.6
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/pci/cx23885/cimax2.c |    1 +
 1 file changed, 1 insertion(+)

--- a/drivers/media/pci/cx23885/cimax2.c
+++ b/drivers/media/pci/cx23885/cimax2.c
@@ -528,6 +528,7 @@ void netup_ci_exit(struct cx23885_tsport
 	if (NULL == state->ca.data)
 		return;
 
+	cancel_work_sync(&state->work);
 	dvb_ca_en50221_release(&state->ca);
 	kfree(state);
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 358/556] media: dt-bindings: nxp,imx8-isi: Drop fsl,blk-ctrl requirement for i.MX8ULP
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (356 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 357/556] media: cx23885: cancel NetUP CI work before teardown Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 359/556] media: em28xx: defer audio-only extension registration Greg Kroah-Hartman
                   ` (210 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Guoniu Zhou, Laurent Pinchart,
	Conor Dooley, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Guoniu Zhou <guoniu.zhou@oss.nxp.com>

commit fc312f830d8df6c082bd6f7250aa5c0ff063eea4 upstream.

The i.MX8ULP variant does not require the fsl,blk-ctrl property. Add
fsl,imx8ulp-isi to the exception list alongside fsl,imx91-isi.

Fixes: 288517a3c6c9 ("dt-bindings: media: nxp,imx8-isi: Add i.MX8ULP ISI compatible string")
Cc: stable@vger.kernel.org
Signed-off-by: Guoniu Zhou <guoniu.zhou@oss.nxp.com>
Reviewed-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Acked-by: Conor Dooley <conor.dooley@microchip.com>
Link: https://patch.msgid.link/20260424-csi2_imx8ulp-v12-1-da148eabc035@oss.nxp.com
Signed-off-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 Documentation/devicetree/bindings/media/nxp,imx8-isi.yaml |    4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

--- a/Documentation/devicetree/bindings/media/nxp,imx8-isi.yaml
+++ b/Documentation/devicetree/bindings/media/nxp,imx8-isi.yaml
@@ -117,7 +117,9 @@ allOf:
         compatible:
           not:
             contains:
-              const: fsl,imx91-isi
+              enum:
+                - fsl,imx8ulp-isi
+                - fsl,imx91-isi
     then:
       required:
         - fsl,blk-ctrl



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 359/556] media: em28xx: defer audio-only extension registration
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (357 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 358/556] media: dt-bindings: nxp,imx8-isi: Drop fsl,blk-ctrl requirement for i.MX8ULP Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 360/556] media: em28xx: fix use-after-free of dev_next->devlist on disconnect Greg Kroah-Hartman
                   ` (209 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+a11c46f37ee083a73deb,
	Fedor Pchelkin, Diego Fernando Mancera Gomez, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Diego Fernando Mancera Gomez <diegomancera.dev@gmail.com>

commit 95f76f51937fdfb0fc1e14cae606b1ef574a56f3 upstream.

The audio-only path registers extensions while probing the primary device.
For a dual-TS board, this happens before dev_next is created. The duplicate
device inherits is_audio_only and is then independently inserted into
em28xx_devlist.

The list is intended to contain only primary devices: extension operations
reach the secondary device through dev_next. The independently linked
secondary can be freed during disconnect while its list node remains
reachable, resulting in a use-after-free.

Defer audio-only extension registration to the module-request work item. It
runs only after probing has completed construction of the optional
secondary device, so only the primary is registered and extension callbacks
reach the secondary through dev_next.

Fixes: 4a089668ef22 ("media: em28xx-cards: rework the em28xx probing code")
Cc: stable@vger.kernel.org
Reported-by: syzbot+a11c46f37ee083a73deb@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/all/66ec3c83.050a0220.29194.002f.GAE@google.com/T/
Suggested-by: Fedor Pchelkin <pchelkin@ispras.ru>
Signed-off-by: Diego Fernando Mancera Gomez <diegomancera.dev@gmail.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/usb/em28xx/em28xx-cards.c |    3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

--- a/drivers/media/usb/em28xx/em28xx-cards.c
+++ b/drivers/media/usb/em28xx/em28xx-cards.c
@@ -3651,6 +3651,7 @@ static void request_module_async(struct
 	 * intf. Don't register extensions twice on those devices.
 	 */
 	if (dev->is_audio_only) {
+		em28xx_init_extension(dev);
 #if defined(CONFIG_MODULES) && defined(MODULE)
 		request_module("em28xx-alsa");
 #endif
@@ -3884,8 +3885,6 @@ static int em28xx_init_dev(struct em28xx
 			retval = -ENODEV;
 			goto err_deinit_media;
 		}
-		em28xx_init_extension(dev);
-
 		return 0;
 	}
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 360/556] media: em28xx: fix use-after-free of dev_next->devlist on disconnect
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (358 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 359/556] media: em28xx: defer audio-only extension registration Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 361/556] media: go7007: defer the ALSA v4l2 put until card release Greg Kroah-Hartman
                   ` (208 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+99d6c66dbbc484f50e1c,
	Jiangong.Han, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jiangong.Han <jiangong.han@windriver.com>

commit 826915b6b65e2d3251e7248ea54289a22d748c84 upstream.

When a device with has_dual_ts=1 is probed and the is_audio_only path
is taken, both dev and dev->dev_next are added to the global
em28xx_devlist via em28xx_init_extension(). However, during disconnect,
em28xx_close_extension(dev) only calls list_del(&dev->devlist), leaving
dev->dev_next->devlist still linked in the global list. When dev_next is
subsequently freed via kref_put(), its devlist entry becomes a dangling
pointer in em28xx_devlist. The next device probe that calls
em28xx_init_extension() triggers a list corruption BUG when list_add_tail
detects the freed node.

This bug was exposed by commit a368ecde8a50 ("USB: core: Fix duplicate
endpoint bug by clearing reserved bits in the descriptor") which clears
reserved bits in bEndpointAddress during endpoint parsing. This causes
fuzzed endpoint addresses like 0xf3 to be normalized to 0x83, which
em28xx interprets as a vendor audio endpoint, enabling the
is_audio_only + has_dual_ts code path that was previously unreachable
with such descriptors.

Fix this by removing dev->dev_next->devlist from the global list in
em28xx_close_extension() before the device is freed.

Fixes: f410b4093fdd ("media: em28xx: split up em28xx_dvb_init to reduce stack size")
Cc: stable@vger.kernel.org
Reported-by: syzbot+99d6c66dbbc484f50e1c@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=99d6c66dbbc484f50e1c
Signed-off-by: Jiangong.Han <jiangong.han@windriver.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/usb/em28xx/em28xx-core.c |    2 ++
 1 file changed, 2 insertions(+)

--- a/drivers/media/usb/em28xx/em28xx-core.c
+++ b/drivers/media/usb/em28xx/em28xx-core.c
@@ -1265,6 +1265,8 @@ void em28xx_close_extension(struct em28x
 			ops->fini(dev);
 		}
 	}
+	if (dev->dev_next)
+		list_del(&dev->dev_next->devlist);
 	list_del(&dev->devlist);
 	mutex_unlock(&em28xx_devlist_mutex);
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 361/556] media: go7007: defer the ALSA v4l2 put until card release
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (359 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 360/556] media: em28xx: fix use-after-free of dev_next->devlist on disconnect Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 362/556] media: i2c: alvium: Fix: Correct name of register in alvium_set_ctrl_auto_exposure Greg Kroah-Hartman
                   ` (207 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Shuangpeng Bai, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Shuangpeng Bai <shuangpeng.kernel@gmail.com>

commit 1bd456afeb8a515137e567967069fce6f8fcd23e upstream.

go7007_snd_init() already takes a v4l2_device reference for the ALSA
side, but go7007_snd_remove() drops it immediately after calling
snd_card_free_when_closed().

That is too early when a userspace process still has the capture PCM open.
The ALSA card and its PCM callbacks remain alive until the last file is
closed, so the release path can still reach struct go7007 through
pcm->private_data and call go7007_snd_hw_free() after the V4L2 release path
has freed the object.

Move the matching v4l2_device_put() to the ALSA card private_free callback
so the existing ALSA reference covers the whole deferred card lifetime.

Closes: https://lore.kernel.org/r/178144969601.60470.6005237146425573205@gmail.com
Fixes: d5d3a7cc127d ("[media] go7007: fix unregister/disconnect handling")
Cc: stable@vger.kernel.org
Signed-off-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/usb/go7007/snd-go7007.c |   10 +++++++++-
 1 file changed, 9 insertions(+), 1 deletion(-)

--- a/drivers/media/usb/go7007/snd-go7007.c
+++ b/drivers/media/usb/go7007/snd-go7007.c
@@ -195,6 +195,13 @@ static const struct snd_device_ops go700
 	.dev_free	= go7007_snd_free,
 };
 
+static void go7007_snd_card_free(struct snd_card *card)
+{
+	struct go7007 *go = card->private_data;
+
+	v4l2_device_put(&go->v4l2_dev);
+}
+
 int go7007_snd_init(struct go7007 *go)
 {
 	static int dev;
@@ -245,6 +252,8 @@ int go7007_snd_init(struct go7007 *go)
 	gosnd->substream = NULL;
 	go->snd_context = gosnd;
 	v4l2_device_get(&go->v4l2_dev);
+	gosnd->card->private_data = go;
+	gosnd->card->private_free = go7007_snd_card_free;
 	++dev;
 
 	return 0;
@@ -263,7 +272,6 @@ int go7007_snd_remove(struct go7007 *go)
 
 	snd_card_disconnect(gosnd->card);
 	snd_card_free_when_closed(gosnd->card);
-	v4l2_device_put(&go->v4l2_dev);
 	return 0;
 }
 EXPORT_SYMBOL(go7007_snd_remove);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 362/556] media: i2c: alvium: Fix: Correct name of register in alvium_set_ctrl_auto_exposure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (360 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 361/556] media: go7007: defer the ALSA v4l2 put until card release Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 363/556] media: i2c: imx415: Release runtime PM reference on VBLANK error Greg Kroah-Hartman
                   ` (206 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Martin Hecht, Sakari Ailus

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Martin Hecht <mhecht73@gmail.com>

commit 58ca8a0bff9e78841a39863474b96e59ef60da19 upstream.

Write value for auto-exposure into correct register REG_BCRM_EXPOSURE_AUTO_RW
instead of wrong register REG_BCRM_WHITE_BALANCE_AUTO_RW.

Fixes: 0a7af872915e ("media: i2c: Add support for alvium camera")
Cc: stable@vger.kernel.org
Signed-off-by: Martin Hecht <mhecht73@gmail.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/i2c/alvium-csi2.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/media/i2c/alvium-csi2.c
+++ b/drivers/media/i2c/alvium-csi2.c
@@ -1290,7 +1290,7 @@ static int alvium_set_ctrl_auto_exposure
 	struct device *dev = &alvium->i2c_client->dev;
 	int ret;
 
-	ret = alvium_write_hshake(alvium, REG_BCRM_WHITE_BALANCE_AUTO_RW,
+	ret = alvium_write_hshake(alvium, REG_BCRM_EXPOSURE_AUTO_RW,
 				  on ? 0x02 : 0x00);
 	if (ret) {
 		dev_err(dev, "Fail to set autoexposure reg\n");



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 363/556] media: i2c: imx415: Release runtime PM reference on VBLANK error
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (361 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 362/556] media: i2c: alvium: Fix: Correct name of register in alvium_set_ctrl_auto_exposure Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 364/556] media: i2c: imx415: Return test pattern write errors Greg Kroah-Hartman
                   ` (205 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michael Riesch,
	Narasimharao Vadlamudi, Sakari Ailus

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Narasimharao Vadlamudi <ahmisaranrao@gmail.com>

commit bea3001e0f32527a291444e527e84a7ea9b546d4 upstream.

The VBLANK path returned immediately when programming VMAX failed after
pm_runtime_get_if_in_use() had taken a runtime PM reference. Break out of
the switch instead so the common pm_runtime_put() path is used.

Fixes: 3bcae55ab96a ("media: i2c: imx415: Add read/write control of VBLANK")
Cc: stable@vger.kernel.org
Reviewed-by: Michael Riesch <michael.riesch@collabora.com>
Signed-off-by: Narasimharao Vadlamudi <ahmisaranrao@gmail.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/i2c/imx415.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/media/i2c/imx415.c
+++ b/drivers/media/i2c/imx415.c
@@ -720,7 +720,7 @@ static int imx415_s_ctrl(struct v4l2_ctr
 		ret = cci_write(sensor->regmap, IMX415_VMAX,
 				format->height + ctrl->val, NULL);
 		if (ret)
-			return ret;
+			break;
 		/*
 		 * Exposure is set based on VMAX which has just changed, so
 		 * program exposure register as well



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 364/556] media: i2c: imx415: Return test pattern write errors
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (362 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 363/556] media: i2c: imx415: Release runtime PM reference on VBLANK error Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 365/556] media: i2c: ov02a10: fix endpoint parsing use-after-free Greg Kroah-Hartman
                   ` (204 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Michael Riesch,
	Narasimharao Vadlamudi, Sakari Ailus

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Narasimharao Vadlamudi <ahmisaranrao@gmail.com>

commit 8cd5735b88d76dda80b089031747b6f18ee0bca2 upstream.

imx415_set_testpattern() accumulates failures from cci_write(), but drops
the value and always returns success. Return the accumulated error so V4L2
reports failures to userspace.

Fixes: d5df1c7f3f83 ("media: i2c: imx415: Convert to new CCI register access helpers")
Cc: stable@vger.kernel.org
Reviewed-by: Michael Riesch <michael.riesch@collabora.com>
Signed-off-by: Narasimharao Vadlamudi <ahmisaranrao@gmail.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/i2c/imx415.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/media/i2c/imx415.c
+++ b/drivers/media/i2c/imx415.c
@@ -686,7 +686,7 @@ static int imx415_set_testpattern(struct
 		cci_write(sensor->regmap, IMX415_DIG_CLP_MODE, 0x01, &ret);
 		cci_write(sensor->regmap, IMX415_WRJ_OPEN, 0x01, &ret);
 	}
-	return 0;
+	return ret;
 }
 
 static int imx415_s_ctrl(struct v4l2_ctrl *ctrl)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 365/556] media: i2c: ov02a10: fix endpoint parsing use-after-free
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (363 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 364/556] media: i2c: imx415: Return test pattern write errors Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 366/556] media: i2c: ov7740: fix use-after-destroy in remove Greg Kroah-Hartman
                   ` (203 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Biren Pandya, Vladimir Zapolskiy,
	Sakari Ailus

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Biren Pandya <birenpandya@gmail.com>

commit 94971ba0592ca77ec99b292226a4b398763315b8 upstream.

The ov02a10_check_hwcfg() function calls fwnode_handle_put(ep)
immediately after allocating and parsing the endpoint. However, it
subsequently calls fwnode_property_read_u32() using the same 'ep'
handle, leading to a potential use-after-free.

Additionally, reading the optional 'ovti,mipi-clock-voltage' property
used to overwrite the 'ret' variable. If the property was missing,
'ret' would become negative, and this failure code would be incorrectly
returned at the end of the function, causing probe to fail entirely.

Fix the use-after-free by moving fwnode_property_read_u32() before
the endpoint is parsed and freed. Avoid the error leak by not
assigning the result of fwnode_property_read_u32() to 'ret'.

Fixes: 91807efbe8ec ("media: i2c: add OV02A10 image sensor driver")
Cc: stable@vger.kernel.org
Signed-off-by: Biren Pandya <birenpandya@gmail.com>
Reviewed-by: Vladimir Zapolskiy <vladimir.zapolskiy@linaro.org>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/i2c/ov02a10.c |   12 +++++-------
 1 file changed, 5 insertions(+), 7 deletions(-)

--- a/drivers/media/i2c/ov02a10.c
+++ b/drivers/media/i2c/ov02a10.c
@@ -820,18 +820,16 @@ static int ov02a10_check_hwcfg(struct de
 	if (!ep)
 		return -ENXIO;
 
+	/* Optional indication of MIPI clock voltage unit */
+	if (!fwnode_property_read_u32(ep, "ovti,mipi-clock-voltage",
+				      &clk_volt))
+		ov02a10->mipi_clock_voltage = clk_volt;
+
 	ret = v4l2_fwnode_endpoint_alloc_parse(ep, &bus_cfg);
 	fwnode_handle_put(ep);
 	if (ret)
 		return ret;
 
-	/* Optional indication of MIPI clock voltage unit */
-	ret = fwnode_property_read_u32(ep, "ovti,mipi-clock-voltage",
-				       &clk_volt);
-
-	if (!ret)
-		ov02a10->mipi_clock_voltage = clk_volt;
-
 	for (i = 0; i < ARRAY_SIZE(link_freq_menu_items); i++) {
 		for (j = 0; j < bus_cfg.nr_of_link_frequencies; j++) {
 			if (link_freq_menu_items[i] ==



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 366/556] media: i2c: ov7740: fix use-after-destroy in remove
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (364 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 365/556] media: i2c: ov02a10: fix endpoint parsing use-after-free Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 367/556] media: i2c: ov9282: restore flash duration calculation Greg Kroah-Hartman
                   ` (202 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Biren Pandya, Sakari Ailus

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Biren Pandya <birenpandya@gmail.com>

commit 5d1b3dea5a44124bab6c14a2d71b977dabed54e7 upstream.

The ov7740_remove() function had a severe teardown order bug where it
destroyed the driver's mutex before freeing the V4L2 control handler
which relies on that mutex, leading to a use-after-destroy kernel panic.
Furthermore, the driver explicitly called v4l2_ctrl_handler_free() and
mutex_destroy() sequentially, but then called ov7740_free_controls()
which invokes both of them a second time, resulting in a double-free.

This patch fixes the issue by unregistering the subdevice first, and
relying exclusively on ov7740_free_controls() to safely tear down the
mutex and control handler in the correct order.

Fixes: 39c5c4471b8d ("media: i2c: Add the ov7740 image sensor driver")
Cc: stable@vger.kernel.org
Signed-off-by: Biren Pandya <birenpandya@gmail.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/i2c/ov7740.c |    4 +---
 1 file changed, 1 insertion(+), 3 deletions(-)

--- a/drivers/media/i2c/ov7740.c
+++ b/drivers/media/i2c/ov7740.c
@@ -1116,10 +1116,8 @@ static void ov7740_remove(struct i2c_cli
 	struct v4l2_subdev *sd = i2c_get_clientdata(client);
 	struct ov7740 *ov7740 = container_of(sd, struct ov7740, subdev);
 
-	mutex_destroy(&ov7740->mutex);
-	v4l2_ctrl_handler_free(ov7740->subdev.ctrl_handler);
-	media_entity_cleanup(&ov7740->subdev.entity);
 	v4l2_async_unregister_subdev(sd);
+	media_entity_cleanup(&ov7740->subdev.entity);
 	ov7740_free_controls(ov7740);
 
 	pm_runtime_get_sync(&client->dev);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 367/556] media: i2c: ov9282: restore flash duration calculation
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (365 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 366/556] media: i2c: ov7740: fix use-after-destroy in remove Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 368/556] media: i2c: vd55g1: Fix manual digital gain on color variant Greg Kroah-Hartman
                   ` (201 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Xiaolei Wang, Richard Leitner,
	Sakari Ailus

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Richard Leitner <richard.leitner@linux.dev>

commit d836f57e8ab971c1cd3b607d9e466513f654e644 upstream.

The migration to CCI helpers made V4L2_CID_FLASH_DURATION write the
requested duration directly to OV9282_REG_STROBE_FRAME_SPAN, dropping
the conversion from microseconds to the register value.

This made flash strobes too long and produced overly bright frames.
Restore the missing calculation so flash duration is programmed
correctly again.

Fixes: 273f52f3cbec ("media: i2c: ov9282: Convert to CCI register access helpers")
Cc: Xiaolei Wang <xiaolei.wang@windriver.com>
Cc: stable@vger.kernel.org
Signed-off-by: Richard Leitner <richard.leitner@linux.dev>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/i2c/ov9282.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/drivers/media/i2c/ov9282.c
+++ b/drivers/media/i2c/ov9282.c
@@ -648,7 +648,8 @@ static int ov9282_set_ctrl(struct v4l2_c
 				      ctrl->val ? OV9282_OUTPUT_ENABLE6_STROBE : 0, NULL);
 		break;
 	case V4L2_CID_FLASH_DURATION:
-		ret = cci_write(ov9282->regmap, OV9282_REG_STROBE_FRAME_SPAN, ctrl->val, NULL);
+		ret = cci_write(ov9282->regmap, OV9282_REG_STROBE_FRAME_SPAN,
+				ov9282_us_to_flash_duration(ov9282, ctrl->val), NULL);
 		break;
 	default:
 		dev_err(ov9282->dev, "Invalid control %d", ctrl->id);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 368/556] media: i2c: vd55g1: Fix manual digital gain on color variant
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (366 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 367/556] media: i2c: ov9282: restore flash duration calculation Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 369/556] media: i2c: vd55g1: Fix media bus code initialization Greg Kroah-Hartman
                   ` (200 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jacopo Mondi, Benjamin Mugnier,
	Sakari Ailus

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Benjamin Mugnier <benjamin.mugnier@foss.st.com>

commit 113a84d6ba739d333eef2a595e3ccd4f97a306c2 upstream.

Apply digital gain to all channels, each channel representing a color.

Cc: stable@vger.kernel.org
Fixes: e138e7f00042 ("media: i2c: vd55g1: Add support for vd65g4 RGB variant")
Reviewed-by: Jacopo Mondi <jacopo.mondi@ideasonboard.com>
Signed-off-by: Benjamin Mugnier <benjamin.mugnier@foss.st.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/i2c/vd55g1.c |   16 +++++++++++++---
 1 file changed, 13 insertions(+), 3 deletions(-)

--- a/drivers/media/i2c/vd55g1.c
+++ b/drivers/media/i2c/vd55g1.c
@@ -60,7 +60,10 @@
 #define VD55G1_PATGEN_ENABLE				BIT(0)
 #define VD55G1_REG_MANUAL_ANALOG_GAIN			CCI_REG8(0x0501)
 #define VD55G1_REG_MANUAL_COARSE_EXPOSURE		CCI_REG16_LE(0x0502)
-#define VD55G1_REG_MANUAL_DIGITAL_GAIN			CCI_REG16_LE(0x0504)
+#define VD55G1_REG_MANUAL_DIGITAL_GAIN_CH0		CCI_REG16_LE(0x0504)
+#define VD55G1_REG_MANUAL_DIGITAL_GAIN_CH1		CCI_REG16_LE(0x0506)
+#define VD55G1_REG_MANUAL_DIGITAL_GAIN_CH2		CCI_REG16_LE(0x0508)
+#define VD55G1_REG_MANUAL_DIGITAL_GAIN_CH3		CCI_REG16_LE(0x050a)
 #define VD55G1_REG_APPLIED_COARSE_EXPOSURE		CCI_REG16_LE(0x00e8)
 #define VD55G1_REG_APPLIED_ANALOG_GAIN			CCI_REG16_LE(0x00ea)
 #define VD55G1_REG_APPLIED_DIGITAL_GAIN			CCI_REG16_LE(0x00ec)
@@ -850,9 +853,16 @@ static int vd55g1_update_expo_cluster(st
 		vd55g1_write(sensor, VD55G1_REG_MANUAL_ANALOG_GAIN,
 			     sensor->again_ctrl->val, &ret);
 
-	if (!is_auto && sensor->dgain_ctrl->is_new)
-		vd55g1_write(sensor, VD55G1_REG_MANUAL_DIGITAL_GAIN,
+	if (!is_auto && sensor->dgain_ctrl->is_new) {
+		vd55g1_write(sensor, VD55G1_REG_MANUAL_DIGITAL_GAIN_CH0,
 			     sensor->dgain_ctrl->val, &ret);
+		vd55g1_write(sensor, VD55G1_REG_MANUAL_DIGITAL_GAIN_CH1,
+			     sensor->dgain_ctrl->val, &ret);
+		vd55g1_write(sensor, VD55G1_REG_MANUAL_DIGITAL_GAIN_CH2,
+			     sensor->dgain_ctrl->val, &ret);
+		vd55g1_write(sensor, VD55G1_REG_MANUAL_DIGITAL_GAIN_CH3,
+			     sensor->dgain_ctrl->val, &ret);
+	}
 
 	return ret;
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 369/556] media: i2c: vd55g1: Fix media bus code initialization
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (367 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 368/556] media: i2c: vd55g1: Fix manual digital gain on color variant Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 370/556] media: imx355: Avoid calling imx355_power_off twice in error path Greg Kroah-Hartman
                   ` (199 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Benjamin Mugnier, Sakari Ailus

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Benjamin Mugnier <benjamin.mugnier@foss.st.com>

commit e4a4f2e3b9bc65e0b82ae8c3a2945955870df36f upstream.

In the driver initialization, the index of the default media bus code
from the supported media bus code array is passed directly to the
vd55g1_get_fmt_code() function instead of the proper media bus code.

This works correctly as a proper media bus code is set after
initialization but could not have been the case. This also resulted in
mutliple "Unsupported mbus format" error messages.

Retrieve the media bus code from the media bus code array, and pass this
media bus code to vd55g1_get_fmt_code() instead of the code index.

Rename VD55G1_MBUS_CODE_DEF to VD55G1_MBUS_CODE_IDX_DEF and
VD55G1_MODE_DEF to VD55G1_MODE_IDX_DEF while at it to avoid future
confusions. Display the guilty error code in warning message.

Cc: stable@vger.kernel.org
Fixes: e138e7f00042 ("media: i2c: vd55g1: Add support for vd65g4 RGB variant")
Signed-off-by: Benjamin Mugnier <benjamin.mugnier@foss.st.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/i2c/vd55g1.c |   16 ++++++++++------
 1 file changed, 10 insertions(+), 6 deletions(-)

--- a/drivers/media/i2c/vd55g1.c
+++ b/drivers/media/i2c/vd55g1.c
@@ -117,9 +117,8 @@
 
 #define VD55G1_WIDTH					804
 #define VD55G1_HEIGHT					704
-#define VD55G1_MODE_DEF					0
+#define VD55G1_MODE_IDX_DEF				0
 #define VD55G1_NB_GPIOS					4
-#define VD55G1_MBUS_CODE_DEF				0
 #define VD55G1_DGAIN_DEF				256
 #define VD55G1_AGAIN_DEF				19
 #define VD55G1_EXPO_MAX_TERM				64
@@ -637,7 +636,7 @@ static u32 vd55g1_get_fmt_code(struct vd
 				goto adapt_bayer_pattern;
 		}
 	}
-	dev_warn(sensor->dev, "Unsupported mbus format\n");
+	dev_warn(sensor->dev, "Unsupported mbus format: 0x%x\n", code);
 
 	return code;
 
@@ -1357,6 +1356,7 @@ static int vd55g1_init_state(struct v4l2
 {
 	struct vd55g1 *sensor = to_vd55g1(sd);
 	struct v4l2_subdev_format fmt = { 0 };
+	int code;
 	struct v4l2_subdev_route routes[] = {
 		{ .flags = V4L2_SUBDEV_ROUTE_FL_ACTIVE }
 	};
@@ -1371,9 +1371,13 @@ static int vd55g1_init_state(struct v4l2
 	if (ret)
 		return ret;
 
-	vd55g1_update_pad_fmt(sensor, &vd55g1_supported_modes[VD55G1_MODE_DEF],
-			      vd55g1_get_fmt_code(sensor, VD55G1_MBUS_CODE_DEF),
-			      &fmt.format);
+	if (sensor->id == VD55G1_MODEL_ID_VD55G1)
+		code = vd55g1_mbus_formats_mono[0];
+	else
+		code = vd55g1_mbus_formats_bayer[0][0];
+	vd55g1_update_pad_fmt(sensor,
+			      &vd55g1_supported_modes[VD55G1_MODE_IDX_DEF],
+			      vd55g1_get_fmt_code(sensor, code), &fmt.format);
 
 	return vd55g1_set_pad_fmt(sd, sd_state, &fmt);
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 370/556] media: imx355: Avoid calling imx355_power_off twice in error path
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (368 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 369/556] media: i2c: vd55g1: Fix media bus code initialization Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 371/556] media: intel/ipu6: fix async notifier cleanup leak on parse error Greg Kroah-Hartman
                   ` (198 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Dave Stevenson, Sakari Ailus

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dave Stevenson <dave.stevenson@raspberrypi.com>

commit ee737bc3ccae7dc713ccaa83ffa46080c6031b3e upstream.

If v4l2_async_register_subdev_sensor failed, then the sensor had
already been powered down by pm_runtime_idle, but the error path
then also explicitly called imx355_power_off as well. That left
an imbalance in the regulator and clock calls.

Call pm_runtime_idle only after v4l2_async_register_subdev_sensor
succeeds to avoid this.

Fixes: efa5fe19c0a9 ("media: imx355: Enable runtime PM before registering async sub-device")
Cc: stable@vger.kernel.org
Signed-off-by: Dave Stevenson <dave.stevenson@raspberrypi.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/i2c/imx355.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/drivers/media/i2c/imx355.c
+++ b/drivers/media/i2c/imx355.c
@@ -1822,12 +1822,13 @@ static int imx355_probe(struct i2c_clien
 	 */
 	pm_runtime_set_active(imx355->dev);
 	pm_runtime_enable(imx355->dev);
-	pm_runtime_idle(imx355->dev);
 
 	ret = v4l2_async_register_subdev_sensor(&imx355->sd);
 	if (ret < 0)
 		goto error_media_entity_runtime_pm;
 
+	pm_runtime_idle(imx355->dev);
+
 	return 0;
 
 error_media_entity_runtime_pm:



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 371/556] media: intel/ipu6: fix async notifier cleanup leak on parse error
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (369 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 370/556] media: imx355: Avoid calling imx355_power_off twice in error path Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 372/556] media: ipu-bridge: check all DMI entries when overriding sensor rotation Greg Kroah-Hartman
                   ` (197 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Cong Nguyen, Sakari Ailus

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Cong Nguyen <congnt264@gmail.com>

commit abb1f808ceab5a3275f8a6b4e37cff17f9f781c1 upstream.

isys_notifier_init() calls v4l2_async_nf_init() and then adds fwnode
remote subdevs in a loop with v4l2_async_nf_add_fwnode_remote(). If an
endpoint parse or add fails partway through the loop, it jumps to
err_parse and returns without calling v4l2_async_nf_cleanup(), leaking
every v4l2_async_connection already added to the notifier's waiting
list.

The register-failure path just below already cleans up correctly, and
the caller only tears the notifier down (isys_notifier_cleanup()) once
isys_notifier_init() has returned success. Clean up the notifier on the
parse error path too.

Fixes: f50c4ca0a820 ("media: intel/ipu6: add the main input system driver")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4
Signed-off-by: Cong Nguyen <congnt264@gmail.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/pci/intel/ipu6/ipu6-isys.c |    1 +
 1 file changed, 1 insertion(+)

--- a/drivers/media/pci/intel/ipu6/ipu6-isys.c
+++ b/drivers/media/pci/intel/ipu6/ipu6-isys.c
@@ -761,6 +761,7 @@ static int isys_notifier_init(struct ipu
 
 err_parse:
 		fwnode_handle_put(ep);
+		v4l2_async_nf_cleanup(&isys->notifier);
 		return ret;
 	}
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 372/556] media: ipu-bridge: check all DMI entries when overriding sensor rotation
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (370 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 371/556] media: intel/ipu6: fix async notifier cleanup leak on parse error Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 373/556] media: iris: Enumerate cap->bus_info to differentiate between encoder and decoder Greg Kroah-Hartman
                   ` (196 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, José María Martín,
	Sakari Ailus

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: José María Martín <jmmartinf@hotmail.com>

commit 4900cad020c0580dfb1be27776ff10a4ef110cfa upstream.

A machine can have more than one sensor whose rotation needs to be
overridden, which takes one upside_down_sensor_dmi_ids[] entry per
sensor, all sharing the same DMI match but with different ACPI HIDs in
driver_data.

ipu_bridge_parse_rotation() uses dmi_first_match(), which always stops
at the first entry matching the running machine, so any further entry
for the same machine is unreachable and only one sensor per machine can
ever be corrected.

Walk the whole table and match every entry for the running machine
against the sensor's ACPI HID instead.

Fixes: b75710155a82 ("media: ipu-bridge: Add DMI quirk for Dell XPS laptops with upside down sensors")
Cc: stable@vger.kernel.org
Signed-off-by: José María Martín <jmmartinf@hotmail.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/pci/intel/ipu-bridge.c |    8 +++++---
 1 file changed, 5 insertions(+), 3 deletions(-)

--- a/drivers/media/pci/intel/ipu-bridge.c
+++ b/drivers/media/pci/intel/ipu-bridge.c
@@ -298,9 +298,11 @@ static u32 ipu_bridge_parse_rotation(str
 {
 	const struct dmi_system_id *dmi_id;
 
-	dmi_id = dmi_first_match(upside_down_sensor_dmi_ids);
-	if (dmi_id && acpi_dev_hid_match(adev, dmi_id->driver_data))
-		return 180;
+	/* A machine may have one entry per sensor, so check all matches. */
+	for (dmi_id = dmi_first_match(upside_down_sensor_dmi_ids); dmi_id;
+	     dmi_id = dmi_first_match(dmi_id + 1))
+		if (acpi_dev_hid_match(adev, dmi_id->driver_data))
+			return 180;
 
 	switch (ssdb->degree) {
 	case IPU_SENSOR_ROTATION_NORMAL:



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 373/556] media: iris: Enumerate cap->bus_info to differentiate between encoder and decoder
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (371 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 372/556] media: ipu-bridge: check all DMI entries when overriding sensor rotation Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 374/556] media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common Greg Kroah-Hartman
                   ` (195 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Bryan ODonoghue, Dmitry Baryshkov,
	Bryan ODonoghue

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bryan O'Donoghue <bryan.odonoghue@linaro.org>

commit 94ef75095d5e76df848a2e5508d71a4532a6ce23 upstream.

commit 66c744e28b69 ("media: venus: assign unique bus_info strings for
encoder and decoder") introduced the naming convention
plat:node-addr:video-codec{enc|dec}. Right now Iris does not replicate this
naming convention.

When we do v4l2-ctrl --list -devices we see:
Iris Decoder (platform:aa00000.video-codec):
	/dev/video0
	/dev/video1

Enumerate the bus_info field of the capabilities structure for namespace
parity and appropriate differentiation:
Iris Decoder (plat:aa00000.video-codec:dec):
	/dev/video0

Iris Encoder (plat:aa00000.video-codec:enc):
	/dev/video1

Fixes: 5ad964ad5656 ("media: iris: Initialize and deinitialize encoder instance structure")
Cc: stable@vger.kernel.org
Signed-off-by: Bryan O'Donoghue <bryan.odonoghue@linaro.org>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Bryan O'Donoghue <bod@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/qcom/iris/iris_vidc.c |   11 +++++++++--
 1 file changed, 9 insertions(+), 2 deletions(-)

--- a/drivers/media/platform/qcom/iris/iris_vidc.c
+++ b/drivers/media/platform/qcom/iris/iris_vidc.c
@@ -449,14 +449,21 @@ static int iris_enum_frameintervals(stru
 
 static int iris_querycap(struct file *filp, void *fh, struct v4l2_capability *cap)
 {
+	struct iris_core *core = video_drvdata(filp);
 	struct iris_inst *inst = iris_get_inst(filp);
+	char *info;
 
 	strscpy(cap->driver, IRIS_DRV_NAME, sizeof(cap->driver));
 
-	if (inst->domain == DECODER)
+	if (inst->domain == DECODER) {
 		strscpy(cap->card, "Iris Decoder", sizeof(cap->card));
-	else
+		info = "dec";
+	} else {
 		strscpy(cap->card, "Iris Encoder", sizeof(cap->card));
+		info = "enc";
+	}
+	snprintf(cap->bus_info, sizeof(cap->bus_info),
+		 "plat:%s:%s", dev_name(core->dev), info);
 
 	return 0;
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 374/556] media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (372 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 373/556] media: iris: Enumerate cap->bus_info to differentiate between encoder and decoder Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 375/556] media: platform: mtk-mdp3: Fix SCP device refcounting Greg Kroah-Hartman
                   ` (194 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Christian Hewitt, Nicolas Dufresne,
	Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Christian Hewitt <christianshewitt@gmail.com>

commit 20aa934ace6917262ff579a73ec018d06a7bad1c upstream.

When VIDIOC_TRY_FMT is called with an unsupported pixel format on the
OUTPUT queue, vdec_try_fmt_common() falls back to V4L2_PIX_FMT_MPEG2.
However, if a distro has locally patched MPEG2 support out (as it has
been broken for some time) the platform format table does not contain
MPEG2 so find_format() returns NULL and the subsequent dereference of
fmt_out->max_width triggers a NULL pointer dereference.

Fix this by falling back to the first format in the platform's format
array instead of hardcoding V4L2_PIX_FMT_MPEG2. This is always valid
since every platform defines at least one format.

Fixes: 3e7f51bd9607 ("media: meson: add v4l2 m2m video decoder driver")
Cc: stable@vger.kernel.org
Signed-off-by: Christian Hewitt <christianshewitt@gmail.com>
Reviewed-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/staging/media/meson/vdec/vdec.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/drivers/staging/media/meson/vdec/vdec.c
+++ b/drivers/staging/media/meson/vdec/vdec.c
@@ -504,8 +504,8 @@ vdec_try_fmt_common(struct amvdec_sessio
 	case V4L2_BUF_TYPE_VIDEO_OUTPUT_MPLANE:
 		fmt_out = find_format(fmts, size, pixmp->pixelformat);
 		if (!fmt_out) {
-			pixmp->pixelformat = V4L2_PIX_FMT_MPEG2;
-			fmt_out = find_format(fmts, size, pixmp->pixelformat);
+			pixmp->pixelformat = fmts[0].pixfmt;
+			fmt_out = &fmts[0];
 		}
 		break;
 	case V4L2_BUF_TYPE_VIDEO_CAPTURE_MPLANE:



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 375/556] media: platform: mtk-mdp3: Fix SCP device refcounting
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (373 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 374/556] media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 376/556] media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup Greg Kroah-Hartman
                   ` (193 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Johan Hovold,
	Nicolas Dufresne, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Guangshuo Li <lgs201920130244@gmail.com>

commit 55793e4665b7f15151e6f5ab51ca980e73abed5d upstream.

mdp_probe() first tries to get the SCP handle with scp_get(). When that
fails, it falls back to looking up the SCP platform device with
__get_pdev_by_id() and then reads its driver data.

The fallback lookup returns the platform device with a reference, just
like scp_get() does. However, the fallback path currently drops that
reference immediately after platform_get_drvdata(). The driver later
still calls scp_put(mdp->scp) unconditionally from the probe error path
and from mdp_video_device_release(), which drops the SCP device
reference again.

Keep the fallback reference until the existing scp_put() call, so that
the fallback path follows the same ownership rules as the scp_get()
path.

Fixes: 8f6f3aa21517 ("media: platform: mtk-mdp3: fix device leaks at probe")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Reviewed-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/mediatek/mdp3/mtk-mdp3-core.c |    1 -
 1 file changed, 1 deletion(-)

--- a/drivers/media/platform/mediatek/mdp3/mtk-mdp3-core.c
+++ b/drivers/media/platform/mediatek/mdp3/mtk-mdp3-core.c
@@ -294,7 +294,6 @@ static int mdp_probe(struct platform_dev
 			goto err_destroy_clock_wq;
 		}
 		mdp->scp = platform_get_drvdata(mm_pdev);
-		put_device(&mm_pdev->dev);
 	}
 
 	mdp->rproc_handle = scp_get_rproc(mdp->scp);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 376/556] media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (374 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 375/556] media: platform: mtk-mdp3: Fix SCP device refcounting Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 377/556] media: nxp: imx8-isi: Fix stream ID validation bypass in crossbar routing Greg Kroah-Hartman
                   ` (192 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Moudy Ho, Johan Hovold,
	Nicolas Dufresne, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit 90368323fb244da0504e3da37a182f8e89bcc3b9 upstream.

Add the missing sanity check after looking up the SCP to avoid
dereferencing a NULL-pointer in case its driver has not yet been bound.

Fixes: 61890ccaefaf ("media: platform: mtk-mdp3: add MediaTek MDP3 driver")
Cc: stable@vger.kernel.org	# 6.1
Cc: Moudy Ho <moudy.ho@mediatek.com>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/mediatek/mdp3/mtk-mdp3-core.c |    5 +++++
 1 file changed, 5 insertions(+)

--- a/drivers/media/platform/mediatek/mdp3/mtk-mdp3-core.c
+++ b/drivers/media/platform/mediatek/mdp3/mtk-mdp3-core.c
@@ -296,6 +296,11 @@ static int mdp_probe(struct platform_dev
 		mdp->scp = platform_get_drvdata(mm_pdev);
 	}
 
+	if (!mdp->scp) {
+		ret = -EPROBE_DEFER;
+		goto err_destroy_clock_wq;
+	}
+
 	mdp->rproc_handle = scp_get_rproc(mdp->scp);
 	dev_dbg(&pdev->dev, "MDP rproc_handle: %p", mdp->rproc_handle);
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 377/556] media: nxp: imx8-isi: Fix stream ID validation bypass in crossbar routing
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (375 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 376/556] media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 378/556] media: nxp: imx8-isi: Correct color map between V4L2 and ISI Greg Kroah-Hartman
                   ` (191 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Guoniu Zhou, Laurent Pinchart,
	Frank Li, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Guoniu Zhou <guoniu.zhou@oss.nxp.com>

commit 795bd2863591f2fee33fab8f10cf9c383c94342e upstream.

The crossbar routing validation has a critical bug where it validates
the wrong routing table, allowing userspace to bypass validation entirely.

The __mxc_isi_crossbar_set_routing() function is called to validate and
apply a new routing table from userspace. However, the validation loop
iterates over state->routing (the currently active routing table) instead
of the routing parameter (the new table being validated):

    for_each_active_route(&state->routing, route) {

This means userspace can submit any invalid routing configuration and it
will pass validation as long as the currently active routing is valid.
This is a security issue as it allows userspace to configure routes that
violate hardware constraints, potentially causing undefined hardware
behavior.

Fix by validating the routing table that will actually be applied.

Fixes: cf21f328fcaf ("media: nxp: Add i.MX8 ISI driver")
Cc: stable@vger.kernel.org
Signed-off-by: Guoniu Zhou <guoniu.zhou@oss.nxp.com>
Reviewed-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260720-isi-v2-1-45845bc5d4fa@oss.nxp.com
Signed-off-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/nxp/imx8-isi/imx8-isi-crossbar.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/media/platform/nxp/imx8-isi/imx8-isi-crossbar.c
+++ b/drivers/media/platform/nxp/imx8-isi/imx8-isi-crossbar.c
@@ -107,7 +107,7 @@ static int __mxc_isi_crossbar_set_routin
 		return ret;
 
 	/* The memory input can be routed to the first pipeline only. */
-	for_each_active_route(&state->routing, route) {
+	for_each_active_route(routing, route) {
 		if (route->sink_pad == xbar->num_sinks - 1 &&
 		    route->source_pad != xbar->num_sinks) {
 			dev_dbg(xbar->isi->dev,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 378/556] media: nxp: imx8-isi: Correct color map between V4L2 and ISI
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (376 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 377/556] media: nxp: imx8-isi: Fix stream ID validation bypass in crossbar routing Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:40 ` [PATCH 7.2 379/556] media: nxp: imx8-isi: Use BIT_ULL() for 64-bit stream masks Greg Kroah-Hartman
                   ` (190 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Guoniu Zhou, Laurent Pinchart,
	Frank Li, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Guoniu Zhou <guoniu.zhou@oss.nxp.com>

commit 4640ec1cb0121473867e7a6850c7449340dcd428 upstream.

Fix the ISI input format for the color map V4L2_PIX_FMT_XBGR32 in
memory-to-memory mode.

Fixes: cf21f328fcaf ("media: nxp: Add i.MX8 ISI driver")
Cc: stable@vger.kernel.org
Signed-off-by: Guoniu Zhou <guoniu.zhou@oss.nxp.com>
Tested-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Reviewed-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260720-isi-v2-5-45845bc5d4fa@oss.nxp.com
Signed-off-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/nxp/imx8-isi/imx8-isi-video.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/media/platform/nxp/imx8-isi/imx8-isi-video.c
+++ b/drivers/media/platform/nxp/imx8-isi/imx8-isi-video.c
@@ -151,7 +151,7 @@ static const struct mxc_isi_format_info
 		.fourcc		= V4L2_PIX_FMT_XBGR32,
 		.type		= MXC_ISI_VIDEO_CAP | MXC_ISI_VIDEO_M2M_OUT
 				| MXC_ISI_VIDEO_M2M_CAP,
-		.isi_in_format	= CHNL_MEM_RD_CTRL_IMG_TYPE_XBGR8,
+		.isi_in_format	= CHNL_MEM_RD_CTRL_IMG_TYPE_XRGB8,
 		.isi_out_format	= CHNL_IMG_CTRL_FORMAT_XRGB888,
 		.mem_planes	= 1,
 		.color_planes	= 1,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 379/556] media: nxp: imx8-isi: Use BIT_ULL() for 64-bit stream masks
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (377 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 378/556] media: nxp: imx8-isi: Correct color map between V4L2 and ISI Greg Kroah-Hartman
@ 2026-09-09 13:40 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 380/556] media: mali-c55: fix dropped last AEC histogram zone weight Greg Kroah-Hartman
                   ` (189 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:40 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Guoniu Zhou, Laurent Pinchart,
	Frank Li, Loic Poulain, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Guoniu Zhou <guoniu.zhou@oss.nxp.com>

commit 77e60a2c5d824ad2d493f53dc17137ae065753fe upstream.

Use BIT_ULL() instead of BIT() for u64 stream masks to avoid incorrect
results on 32-bit architectures when stream IDs are 32 or greater.

Fixes: cf21f328fcaf ("media: nxp: Add i.MX8 ISI driver")
Cc: stable@vger.kernel.org
Signed-off-by: Guoniu Zhou <guoniu.zhou@oss.nxp.com>
Reviewed-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Loic Poulain <loic.poulain@oss.qualcomm.com>
Link: https://patch.msgid.link/20260728-isi-v5-1-1d22ab91602a@oss.nxp.com
Signed-off-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/nxp/imx8-isi/imx8-isi-crossbar.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/drivers/media/platform/nxp/imx8-isi/imx8-isi-crossbar.c
+++ b/drivers/media/platform/nxp/imx8-isi/imx8-isi-crossbar.c
@@ -145,10 +145,10 @@ mxc_isi_crossbar_xlate_streams(struct mx
 	 */
 	for_each_active_route(&state->routing, route) {
 		if (route->source_pad != source_pad ||
-		    !(source_streams & BIT(route->source_stream)))
+		    !(source_streams & BIT_ULL(route->source_stream)))
 			continue;
 
-		sink_streams |= BIT(route->sink_stream);
+		sink_streams |= BIT_ULL(route->sink_stream);
 		sink_pad = route->sink_pad;
 	}
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 380/556] media: mali-c55: fix dropped last AEC histogram zone weight
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (378 preceding siblings ...)
  2026-09-09 13:40 ` [PATCH 7.2 379/556] media: nxp: imx8-isi: Use BIT_ULL() for 64-bit stream masks Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 381/556] media: mali-c55: Fix clock leak on reset deassert failure Greg Kroah-Hartman
                   ` (188 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Carlier, Jacopo Mondi,
	Daniel Scally, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Carlier <devnexen@gmail.com>

commit fb9b87145624eedaf3d50edac9b11d707494cb5b upstream.

The 15x15 AEC histogram metering grid has 225 per-zone weights, packed
by userspace as a u8 array. The driver writes the first 56 registers
(zones 0 through 223) in a loop, then handles the final register on its
own to keep static analysers from flagging the array access.

That separate path computes the address and value for the 225th weight
(the bottom-right zone) but never issues the register write, so the zone
keeps its stale or default weight. Any non-default weight userspace sets
for the last zone is silently ignored, skewing auto-exposure metering.
Both the AEXP_HIST_WEIGHTS and AEXP_IHIST_WEIGHTS blocks are affected as
they share this handler.

Issue the missing write, masking the value as the loop does.

Fixes: 01535ea08674 ("media: platform: Add mali-c55 parameters video node")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: David Carlier <devnexen@gmail.com>
Reviewed-by: Jacopo Mondi <jacopo.mondi@ideasonboard.com>
Reviewed-by: Daniel Scally <dan.scally@ideasonboard.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/arm/mali-c55/mali-c55-params.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/media/platform/arm/mali-c55/mali-c55-params.c b/drivers/media/platform/arm/mali-c55/mali-c55-params.c
index de0e9d898db7..33e2232ec8f5 100644
--- a/drivers/media/platform/arm/mali-c55/mali-c55-params.c
+++ b/drivers/media/platform/arm/mali-c55/mali-c55-params.c
@@ -212,6 +212,7 @@ mali_c55_params_aexp_hist_weights(struct mali_c55 *mali_c55,
 
 	val = params->zone_weights[MALI_C55_MAX_ZONES - 1];
 	addr = base + MALI_C55_AEXP_HIST_ZONE_WEIGHTS_OFFSET + (4 * 56);
+	mali_c55_ctx_write(mali_c55, addr, val & MALI_C55_AEXP_HIST_ZONE_WEIGHT_MASK);
 }
 
 static void mali_c55_params_digital_gain(struct mali_c55 *mali_c55,
-- 
2.55.0




^ permalink raw reply related	[flat|nested] 570+ messages in thread

* [PATCH 7.2 381/556] media: mali-c55: Fix clock leak on reset deassert failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (379 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 380/556] media: mali-c55: fix dropped last AEC histogram zone weight Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 382/556] media: mali-c55: Fix AEXP IHIST disable bit shift Greg Kroah-Hartman
                   ` (187 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Carlier, Daniel Scally,
	Jacopo Mondi, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Carlier <devnexen@gmail.com>

commit f499befeb668436b67bdb2b610b34db57732703f upstream.

__mali_c55_power_on() enables the clocks before deasserting the resets,
but bails out on a deassert failure without disabling them again. Both
callers treat a failed power-on as already cleaned up, so the clocks are
left enabled.

Disable them on the error path.

Fixes: d5f281f3dd29 ("media: mali-c55: Add Mali-C55 ISP driver")
Cc: stable@vger.kernel.org
Signed-off-by: David Carlier <devnexen@gmail.com>
Reviewed-by: Daniel Scally <dan.scally@ideasonboard.com>
Reviewed-by: Jacopo Mondi <jacopo.mondi@ideasonboard.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/arm/mali-c55/mali-c55-core.c |    2 ++
 1 file changed, 2 insertions(+)

--- a/drivers/media/platform/arm/mali-c55/mali-c55-core.c
+++ b/drivers/media/platform/arm/mali-c55/mali-c55-core.c
@@ -698,6 +698,8 @@ static int __mali_c55_power_on(struct ma
 					  mali_c55->resets);
 	if (ret) {
 		dev_err(mali_c55->dev, "failed to deassert resets\n");
+		clk_bulk_disable_unprepare(ARRAY_SIZE(mali_c55->clks),
+					   mali_c55->clks);
 		return ret;
 	}
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 382/556] media: mali-c55: Fix AEXP IHIST disable bit shift
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (380 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 381/556] media: mali-c55: Fix clock leak on reset deassert failure Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 383/556] media: mali-c55: Fix scaler factor overflow for large crop sizes Greg Kroah-Hartman
                   ` (186 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Carlier, Jacopo Mondi,
	Daniel Scally, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Carlier <devnexen@gmail.com>

commit 9a2925b823d541a23b8330f80056e6cca78c7677 upstream.

The post-Iridix auto-exposure histogram disable bit in
MALI_C55_REG_METERING_CONFIG is bit 16, but MALI_C55_AEXP_IHIST_DISABLE
was defined with a shift of 12, copied from the AEXP_HIST definition
above it. As the value is masked with the BIT(16) disable mask when it
is programmed, the result is always zero and the disable bit is never
set. The IHIST can therefore never be disabled, neither at ISP init nor
via a parameters block flagged V4L2_ISP_PARAMS_FL_BLOCK_DISABLE, and the
hardware keeps producing histogram statistics that userspace believes
are switched off.

Use a shift of 16 so the disable request takes effect.

Fixes: d5f281f3dd29 ("media: mali-c55: Add Mali-C55 ISP driver")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: David Carlier <devnexen@gmail.com>
Reviewed-by: Jacopo Mondi <jacopo.mondi@ideasonboard.com>
Reviewed-by: Daniel Scally <dan.scally@ideasonboard.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/arm/mali-c55/mali-c55-registers.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/media/platform/arm/mali-c55/mali-c55-registers.h b/drivers/media/platform/arm/mali-c55/mali-c55-registers.h
index f098effde7b4..4cd13b702d9f 100644
--- a/drivers/media/platform/arm/mali-c55/mali-c55-registers.h
+++ b/drivers/media/platform/arm/mali-c55/mali-c55-registers.h
@@ -173,7 +173,7 @@ enum mali_c55_interrupts {
 #define MALI_C55_AEXP_HIST_SWITCH_MASK			GENMASK(14, 13)
 #define MALI_C55_AEXP_HIST_SWITCH(x)			((x) << 13)
 #define MALI_C55_AEXP_IHIST_DISABLE_MASK		BIT(16)
-#define MALI_C55_AEXP_IHIST_DISABLE			(0x01 << 12)
+#define MALI_C55_AEXP_IHIST_DISABLE			(0x01 << 16)
 #define MALI_C55_AEXP_SRC_MASK				BIT(24)
 
 #define MALI_C55_REG_TPG_CH0				0x18ed8
-- 
2.55.0




^ permalink raw reply related	[flat|nested] 570+ messages in thread

* [PATCH 7.2 383/556] media: mali-c55: Fix scaler factor overflow for large crop sizes
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (381 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 382/556] media: mali-c55: Fix AEXP IHIST disable bit shift Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 384/556] media: rc: sunxi-cir: Unregister rc device on probe failure Greg Kroah-Hartman
                   ` (185 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David Carlier, Daniel Scally,
	Linus Walleij, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David Carlier <devnexen@gmail.com>

commit 2447c768cb5dfb9f52630b82d419e2b24fee27a3 upstream.

The horizontal and vertical scaling factors multiply the crop dimensions
by MALI_C55_RSZ_SCALER_FACTOR, a Q4.20 factor of (1 << 20). Both operands
are 32-bit, so the multiplication wraps before the result is stored in
the u64 scale variables. For any crop dimension of 4096 or more (the
maximum is 8192) the value overflows; an 8192 to 4096 downscale yields a
TINC of zero, so the scaler never advances and the output is corrupted.

Define MALI_C55_RSZ_SCALER_FACTOR as a 64-bit constant so the
multiplication is performed in 64-bit.

Fixes: d5f281f3dd29 ("media: mali-c55: Add Mali-C55 ISP driver")
Cc: stable@vger.kernel.org
Signed-off-by: David Carlier <devnexen@gmail.com>
Reviewed-by: Daniel Scally <dan.scally@ideasonboard.com>
Reviewed-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/arm/mali-c55/mali-c55-resizer.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/media/platform/arm/mali-c55/mali-c55-resizer.c b/drivers/media/platform/arm/mali-c55/mali-c55-resizer.c
index c4f46651dcee..6706939b4a90 100644
--- a/drivers/media/platform/arm/mali-c55/mali-c55-resizer.c
+++ b/drivers/media/platform/arm/mali-c55/mali-c55-resizer.c
@@ -15,7 +15,7 @@
 #include "mali-c55-registers.h"
 
 /* Scaling factor in Q4.20 format. */
-#define MALI_C55_RSZ_SCALER_FACTOR	(1U << 20)
+#define MALI_C55_RSZ_SCALER_FACTOR	BIT_ULL(20)
 
 #define MALI_C55_RSZ_COEFS_BANKS	8
 #define MALI_C55_RSZ_COEFS_ENTRIES	64
-- 
2.55.0




^ permalink raw reply related	[flat|nested] 570+ messages in thread

* [PATCH 7.2 384/556] media: rc: sunxi-cir: Unregister rc device on probe failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (382 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 383/556] media: mali-c55: Fix scaler factor overflow for large crop sizes Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 385/556] media: rockchip: rga: dont change RGB quantization Greg Kroah-Hartman
                   ` (184 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Ijae Kim, Myeonghun Pak, Sean Young

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Myeonghun Pak <mhun512@gmail.com>

commit 479aa6fa8c50f1052f1451326ef7d4d586d340c3 upstream.

After rc_register_device() succeeds, later probe failures must undo the
registration with rc_unregister_device(). The current error path jumps to
the allocation cleanup label and only calls rc_free_device(), leaving the
rc device registration and resources created by rc_register_device()
behind.

Add a registered-device unwind label for the IRQ lookup, IRQ request, and
hardware initialization failure paths. Keep rc_free_device() for failures
before rc_register_device() succeeds.

Fixes: b4e3e59fb59c ("[media] rc: add sunxi-ir driver")
Cc: stable@vger.kernel.org
Co-developed-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
Signed-off-by: Sean Young <sean@mess.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/rc/sunxi-cir.c |    9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

--- a/drivers/media/rc/sunxi-cir.c
+++ b/drivers/media/rc/sunxi-cir.c
@@ -344,22 +344,25 @@ static int sunxi_ir_probe(struct platfor
 	ir->irq = platform_get_irq(pdev, 0);
 	if (ir->irq < 0) {
 		ret = ir->irq;
-		goto exit_free_dev;
+		goto exit_unregister_dev;
 	}
 
 	ret = devm_request_irq(dev, ir->irq, sunxi_ir_irq, 0, SUNXI_IR_DEV, ir);
 	if (ret) {
 		dev_err(dev, "failed request irq\n");
-		goto exit_free_dev;
+		goto exit_unregister_dev;
 	}
 
 	ret = sunxi_ir_hw_init(dev);
 	if (ret)
-		goto exit_free_dev;
+		goto exit_unregister_dev;
 
 	dev_info(dev, "initialized sunXi IR driver\n");
 	return 0;
 
+exit_unregister_dev:
+	rc_unregister_device(ir->rc);
+
 exit_free_dev:
 	rc_free_device(ir->rc);
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 385/556] media: rockchip: rga: dont change RGB quantization
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (383 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 384/556] media: rc: sunxi-cir: Unregister rc device on probe failure Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 386/556] media: rkvdec: Propagate platform_get_irq() errors Greg Kroah-Hartman
                   ` (183 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sven Püschel, Nicolas Dufresne,
	Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sven Püschel <s.pueschel@pengutronix.de>

commit 7acc334cf038b5ac1a7ee480d3ec59d288d2f5f3 upstream.

Don't change the quantization of an RGB format when converting between
RGB and YUV with the RGA3. As the RGA3 only supports doing conversions
to full range YUV with BT601, it wants to announce it through
try_fmt/s_fmt.

As it is only relevant, when converting between RGB and YUV, it's
guarded by a given condition. But the condition also causes the
RGB format quantization to be adjusted to limited range, which
is incorrect.

Therefore simplify the condition to only apply when the current format
is a YUV format. Also document the reason for checking if the other
format is an RGB format.

Fixes: 24a63d4c9d3c ("media: rockchip: rga: add rga3 support")
Cc: stable@vger.kernel.org
Signed-off-by: Sven Püschel <s.pueschel@pengutronix.de>
Reviewed-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/rockchip/rga/rga3-hw.c | 12 ++++++++----
 1 file changed, 8 insertions(+), 4 deletions(-)

diff --git a/drivers/media/platform/rockchip/rga/rga3-hw.c b/drivers/media/platform/rockchip/rga/rga3-hw.c
index ca1c268303dd..c4a71306278b 100644
--- a/drivers/media/platform/rockchip/rga/rga3-hw.c
+++ b/drivers/media/platform/rockchip/rga/rga3-hw.c
@@ -450,10 +450,14 @@ static void *rga3_adjust_and_map_format(struct rga_ctx *ctx,
 	other_format = is_output ? &ctx->out.pix : &ctx->in.pix;
 	other_format_info = v4l2_format_info(other_format->pixelformat);
 
-	if ((v4l2_is_format_rgb(format_info) &&
-	     v4l2_is_format_yuv(other_format_info)) ||
-	    (v4l2_is_format_yuv(format_info) &&
-	     v4l2_is_format_rgb(other_format_info))) {
+	/*
+	 * Only apply the quantization restrictions when we need to
+	 * convert between RGB and YUV. Otherwise there is no point
+	 * to limit the quantization for operations like scaling or
+	 * rotations.
+	 */
+	if (v4l2_is_format_yuv(format_info) &&
+	    v4l2_is_format_rgb(other_format_info)) {
 		/*
 		 * The RGA3 only supports BT601, BT709 and BT2020 RGB<->YUV conversions
 		 * Additionally BT709 and BT2020 only support limited range YUV.
-- 
2.55.0




^ permalink raw reply related	[flat|nested] 570+ messages in thread

* [PATCH 7.2 386/556] media: rkvdec: Propagate platform_get_irq() errors
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (384 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 385/556] media: rockchip: rga: dont change RGB quantization Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 387/556] media: rkvdec: hevc: tighten EXT SPS RPS control dimensions Greg Kroah-Hartman
                   ` (182 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Narasimharao Vadlamudi,
	Detlev Casanova, Nicolas Dufresne, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Narasimharao Vadlamudi <ahmisaranrao@gmail.com>

commit c37aca64206fafe938119e801a3fd10a537a051f upstream.

platform_get_irq() returns a positive IRQ number on success and a
negative error code on failure. It no longer returns zero. The driver
currently returns -ENXIO for all failures, which loses useful errors
such as -EPROBE_DEFER.

Return the error from platform_get_irq() directly.

Fixes: cd33c830448b ("media: rkvdec: Add the rkvdec driver")
Cc: stable@vger.kernel.org
Signed-off-by: Narasimharao Vadlamudi <ahmisaranrao@gmail.com>
Reviewed-by: Detlev Casanova <detlev.casanova@collabora.com>
Signed-off-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/rockchip/rkvdec/rkvdec.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/drivers/media/platform/rockchip/rkvdec/rkvdec.c
+++ b/drivers/media/platform/rockchip/rkvdec/rkvdec.c
@@ -1818,8 +1818,8 @@ static int rkvdec_probe(struct platform_
 	vb2_dma_contig_set_max_seg_size(&pdev->dev, DMA_BIT_MASK(32));
 
 	irq = platform_get_irq(pdev, 0);
-	if (irq <= 0)
-		return -ENXIO;
+	if (irq < 0)
+		return irq;
 
 	ret = devm_request_threaded_irq(&pdev->dev, irq, NULL,
 					rkvdec_irq_handler, IRQF_ONESHOT,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 387/556] media: rkvdec: hevc: tighten EXT SPS RPS control dimensions
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (385 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 386/556] media: rkvdec: Propagate platform_get_irq() errors Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 388/556] media: rkvdec: hevc: guard INTER_REF_PIC_SET_PRED index underflow Greg Kroah-Hartman
                   ` (181 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Detlev Casanova, Michael Bommarito,
	Nicolas Dufresne, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Michael Bommarito <michael.bommarito@gmail.com>

commit f0b9d7e5be061b4858279d451f5a6ad0ed20b1be upstream.

The VDPU381 HEVC driver registers V4L2_CID_STATELESS_HEVC_EXT_SPS_ST_RPS
and V4L2_CID_STATELESS_HEVC_EXT_SPS_LT_RPS with .cfg.dims = { 65 }, but
the HEVC spec caps num_short_term_ref_pic_sets at 64 (ITU-T H.265 7.4.8)
and num_long_term_ref_pics_sps at 32 (7.4.3.2.1). The hardware descriptor
table (struct rkvdec_rps) sizes match those spec limits: refs[32] and
short_term_ref_sets[64].

Reduce the dims to { 64 } and { 32 } respectively so the V4L2 control
framework rejects oversized payloads before any driver code runs.

Fixes: c9a59dc2acc7 ("media: rkvdec: Add HEVC support for the VDPU381 variant")
Cc: stable@vger.kernel.org
Suggested-by: Detlev Casanova <detlev.casanova@collabora.com>
Assisted-by: Claude:claude-opus-4-7
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Reviewed-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/rockchip/rkvdec/rkvdec.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/drivers/media/platform/rockchip/rkvdec/rkvdec.c
+++ b/drivers/media/platform/rockchip/rkvdec/rkvdec.c
@@ -278,12 +278,12 @@ static const struct rkvdec_ctrl_desc vdp
 	{
 		.cfg.id = V4L2_CID_STATELESS_HEVC_EXT_SPS_ST_RPS,
 		.cfg.ops = &rkvdec_ctrl_ops,
-		.cfg.dims = { 65 },
+		.cfg.dims = { 64 },
 	},
 	{
 		.cfg.id = V4L2_CID_STATELESS_HEVC_EXT_SPS_LT_RPS,
 		.cfg.ops = &rkvdec_ctrl_ops,
-		.cfg.dims = { 65 },
+		.cfg.dims = { 32 },
 	},
 };
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 388/556] media: rkvdec: hevc: guard INTER_REF_PIC_SET_PRED index underflow
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (386 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 387/556] media: rkvdec: hevc: tighten EXT SPS RPS control dimensions Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 389/556] media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak Greg Kroah-Hartman
                   ` (180 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Detlev Casanova, Michael Bommarito,
	Nicolas Dufresne, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Michael Bommarito <michael.bommarito@gmail.com>

commit 052c5ed5a1d96a6b24fd50ccda16fc6841ee7ca3 upstream.

st_ref_pic_set_prediction() computes the reference RPS index as
st_rps_idx - (delta_idx_minus1 + 1) per HEVC spec equation 7-59.
Both operands are u8, so when delta_idx_minus1 + 1 exceeds the
current index the subtraction wraps and the subsequent array access
at calculated_rps_st_sets[ref_rps_idx] reads far out of bounds.

A userspace V4L2 client that can open the RKVDEC m2m decoder can
submit an EXT_SPS_ST_RPS control with INTER_REF_PIC_SET_PRED set
and delta_idx_minus1 crafted to trigger the underflow.

Reject the entry early when the reference index would underflow.

Fixes: c9a59dc2acc7 ("media: rkvdec: Add HEVC support for the VDPU381 variant")
Cc: stable@vger.kernel.org
Suggested-by: Detlev Casanova <detlev.casanova@collabora.com>
Assisted-by: Claude:claude-opus-4-7
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Reviewed-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/rockchip/rkvdec/rkvdec-hevc-common.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/media/platform/rockchip/rkvdec/rkvdec-hevc-common.c b/drivers/media/platform/rockchip/rkvdec/rkvdec-hevc-common.c
index f89602075121..9c4a6093af32 100644
--- a/drivers/media/platform/rockchip/rkvdec/rkvdec-hevc-common.c
+++ b/drivers/media/platform/rockchip/rkvdec/rkvdec-hevc-common.c
@@ -209,6 +209,9 @@ static void st_ref_pic_set_prediction(struct rkvdec_hevc_run *run, int idx,
 	int i, j;
 	int dPoc;
 
+	if ((unsigned int)rps_data->delta_idx_minus1 + 1 > idx)
+		return;
+
 	ref_rps_idx = st_rps_idx - (rps_data->delta_idx_minus1 + 1); /* 7-59 */
 	delta_rps = (1 - 2 * rps_data->delta_rps_sign) *
 		   (rps_data->abs_delta_rps_minus1 + 1); /* 7-60 */
-- 
2.55.0




^ permalink raw reply related	[flat|nested] 570+ messages in thread

* [PATCH 7.2 389/556] media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (387 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 388/556] media: rkvdec: hevc: guard INTER_REF_PIC_SET_PRED index underflow Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 390/556] media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure Greg Kroah-Hartman
                   ` (179 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Hans Verkuil, Valery Borovsky

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Valery Borovsky <vebohr@gmail.com>

commit dabb047c62668f280998e29117c55e41aabac336 upstream.

rtl2832_sdr_remove() runs on USB disconnect and clears dev->udev to
NULL before any pending streaming teardown has run. When user space
later closes its file descriptor, vb2 calls rtl2832_sdr_stop_streaming()
which in turn calls rtl2832_sdr_free_stream_bufs(). That helper releases
each coherent buffer with:

    usb_free_coherent(dev->udev, dev->buf_size,
                      dev->buf_list[dev->buf_num],
                      dev->dma_addr[dev->buf_num]);

usb_free_coherent() returns immediately when its dev argument is NULL,
so every DMA stream buffer that was live at disconnect is silently
leaked. The URBs allocated in rtl2832_sdr_alloc_urbs() outlive the
device for the same reason.

The rtl2832_sdr driver uses vb2_fop_release() in its file_operations,
so replace video_unregister_device(&dev->vdev) with
vb2_video_unregister_device(&dev->vdev) and move it before clearing
dev->udev. vb2_video_unregister_device() releases the vb2 queue, which
synchronously runs rtl2832_sdr_stop_streaming() if streaming is active,
so URBs and coherent DMA stream buffers are freed while dev->udev is
still valid.

vb2_video_unregister_device() locks vdev->queue->lock (vb_queue_lock)
internally, and stop_streaming() locks v4l2_lock, so the previous outer
mutex_lock(&dev->vb_queue_lock) / mutex_lock(&dev->v4l2_lock) pair
around the unregister sequence would self-deadlock and has been removed.
A short v4l2_lock critical section around dev->udev = NULL remains so
any ioctl path that still holds the file descriptor sees coherent state.

Issue identified by automated review of the INV-003 series at
https://sashiko.dev/

Fixes: 771138920eaf ("[media] rtl2832_sdr: Realtek RTL2832 SDR driver module")
Cc: stable@vger.kernel.org
Suggested-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Valery Borovsky <vebohr@gmail.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/dvb-frontends/rtl2832_sdr.c |   18 +++++++++++++-----
 1 file changed, 13 insertions(+), 5 deletions(-)

--- a/drivers/media/dvb-frontends/rtl2832_sdr.c
+++ b/drivers/media/dvb-frontends/rtl2832_sdr.c
@@ -1477,14 +1477,22 @@ static void rtl2832_sdr_remove(struct pl
 
 	dev_dbg(&pdev->dev, "\n");
 
-	mutex_lock(&dev->vb_queue_lock);
+	/*
+	 * vb2_video_unregister_device() releases the vb2 queue, which
+	 * triggers rtl2832_sdr_stop_streaming() if streaming is active.
+	 * stop_streaming() uses dev->udev to free URBs and coherent DMA
+	 * stream buffers via usb_free_coherent(), so it must run before
+	 * dev->udev is cleared. vb2_video_unregister_device() locks
+	 * vb_queue_lock internally and stop_streaming() locks v4l2_lock,
+	 * so neither may be held by the caller.
+	 */
+	v4l2_device_disconnect(&dev->v4l2_dev);
+	vb2_video_unregister_device(&dev->vdev);
+
 	mutex_lock(&dev->v4l2_lock);
-	/* No need to keep the urbs around after disconnection */
 	dev->udev = NULL;
-	v4l2_device_disconnect(&dev->v4l2_dev);
-	video_unregister_device(&dev->vdev);
 	mutex_unlock(&dev->v4l2_lock);
-	mutex_unlock(&dev->vb_queue_lock);
+
 	v4l2_device_put(&dev->v4l2_dev);
 	module_put(pdev->dev.parent->driver->owner);
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 390/556] media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (388 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 389/556] media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 391/556] media: rzg2l-cru: Align bytesperline to hardware DMA stride requirement Greg Kroah-Hartman
                   ` (178 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Valery Borovsky, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Valery Borovsky <vebohr@gmail.com>

commit fe50cdaebf12cd32ff9a44d92bfd6fbc2300dbd4 upstream.

rtl2832_sdr_start_streaming() calls rtl2832_sdr_alloc_stream_bufs(),
rtl2832_sdr_alloc_urbs() and rtl2832_sdr_submit_urbs() in sequence and
shares a single err: label that only unlocks the mutex and returns.
When alloc_urbs() succeeds but submit_urbs() fails, or when alloc_urbs()
itself returns -ENOMEM after alloc_stream_bufs() has already succeeded,
the URBs and/or the coherent DMA stream buffers stay allocated while
streaming reports failure to vb2. Two latent defects follow on the next
VIDIOC_STREAMON:

1) rtl2832_sdr_alloc_stream_bufs() unconditionally resets dev->buf_num
   to 0 and overwrites dev->buf_list[]/dev->dma_addr[], permanently
   leaking the coherent DMA memory allocated by the previous attempt.

2) rtl2832_sdr_alloc_urbs() never resets dev->urbs_initialized and only
   increments it. After a second successful pass urbs_initialized can
   exceed MAX_BULK_BUFS, so the subsequent rtl2832_sdr_free_urbs() walks
   from urbs_initialized - 1 down to 0 and reads past the end of
   dev->urb_list[], passing garbage pointers to usb_free_urb().

Mirror the teardown that stop_streaming() already performs: on the error
path call rtl2832_sdr_free_urbs() and rtl2832_sdr_free_stream_bufs()
before unlocking. Both helpers are idempotent (free_urbs kills and zeros
urbs_initialized; free_stream_bufs is gated on URB_BUF and clears the
buf_num counter), so partial-failure paths and the no-allocation paths
remain safe.

Issue identified by automated review of the INV-003 series at
https://sashiko.dev/

Fixes: 771138920eaf ("[media] rtl2832_sdr: Realtek RTL2832 SDR driver module")
Cc: stable@vger.kernel.org
Signed-off-by: Valery Borovsky <vebohr@gmail.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/dvb-frontends/rtl2832_sdr.c |    3 +++
 1 file changed, 3 insertions(+)

--- a/drivers/media/dvb-frontends/rtl2832_sdr.c
+++ b/drivers/media/dvb-frontends/rtl2832_sdr.c
@@ -906,9 +906,12 @@ static int rtl2832_sdr_start_streaming(s
 		goto err;
 
 	mutex_unlock(&dev->v4l2_lock);
+
 	return 0;
 
 err:
+	rtl2832_sdr_free_urbs(dev);
+	rtl2832_sdr_free_stream_bufs(dev);
 	rtl2832_sdr_cleanup_queued_bufs(dev, VB2_BUF_STATE_QUEUED);
 	mutex_unlock(&dev->v4l2_lock);
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 391/556] media: rzg2l-cru: Align bytesperline to hardware DMA stride requirement
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (389 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 390/556] media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 392/556] media: s2255: bound JPEG frame size before copying into the buffer Greg Kroah-Hartman
                   ` (177 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Tommaso Merciai, Jacopo Mondi,
	Sakari Ailus

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tommaso Merciai <tommaso.merciai.xr@bp.renesas.com>

commit 56c29fa3ee666197516a231e75aed789ae9c530d upstream.

The RZ/G3E CRU programs the line stride via the AMnIS register, whose
IS field encodes the value in units of 128 bytes. If bytesperline is
not a multiple of 128, the division truncates and the hardware uses a
wrong stride, causing horizontal banding.

Commit ace92ccef0c9 ("media: platform: rzg2l-cru: Use v4l2_fill_pixfmt()")
replaced the open-coded aligned calculation with v4l2_fill_pixfmt(),
which sets no alignment, reintroducing the issue.

Round bytesperline up to RZG2L_CRU_STRIDE_ALIGN and recompute
sizeimage when info->has_stride is set. RZ/G2L has no AMnIS register
and keeps the values from v4l2_fill_pixfmt() unchanged.

Fixes: ace92ccef0c9 ("media: platform: rzg2l-cru: Use v4l2_fill_pixfmt()")
Cc: stable@vger.kernel.org
Signed-off-by: Tommaso Merciai <tommaso.merciai.xr@bp.renesas.com>
Reviewed-by: Jacopo Mondi <jacopo.mondi@ideasonboard.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/renesas/rzg2l-cru/rzg2l-video.c |    5 +++++
 1 file changed, 5 insertions(+)

--- a/drivers/media/platform/renesas/rzg2l-cru/rzg2l-video.c
+++ b/drivers/media/platform/renesas/rzg2l-cru/rzg2l-video.c
@@ -851,6 +851,11 @@ static void rzg2l_cru_format_align(struc
 
 	v4l2_fill_pixfmt(pix, pix->pixelformat, pix->width, pix->height);
 
+	if (info->has_stride) {
+		pix->bytesperline = ALIGN(pix->bytesperline, RZG2L_CRU_STRIDE_ALIGN);
+		pix->sizeimage = pix->bytesperline * pix->height;
+	}
+
 	dev_dbg(cru->dev, "Format %ux%u bpl: %u size: %u\n",
 		pix->width, pix->height, pix->bytesperline, pix->sizeimage);
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 392/556] media: s2255: bound JPEG frame size before copying into the buffer
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (390 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 391/556] media: rzg2l-cru: Align bytesperline to hardware DMA stride requirement Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 393/556] media: s2255: check firmware size before reading trailing marker Greg Kroah-Hartman
                   ` (176 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, HyeongJun An, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: HyeongJun An <sammiee5311@gmail.com>

commit e504cc888f42999dd76b6a43788c422610f2aad2 upstream.

s2255_fillbuff() memcpy()s vc->jpg_size bytes of a captured JPEG/MJPEG
frame into the vb2 plane.  vc->jpg_size is taken verbatim from the
S2255_MARKER_FRAME header the device sends (pdword[4] in save_frame())
and, unlike the frame payload length just above it, is never bounded:

	payload = le32_to_cpu(pdword[3]);
	if (payload > vc->req_image_size)	/* payload is checked ... */
		return -EINVAL;
	vc->pkt_size = payload;
	vc->jpg_size = le32_to_cpu(pdword[4]);	/* ... jpg_size is not */

A malicious or malfunctioning device can therefore report a jpg_size
larger than the destination vb2 plane, and the memcpy() writes past it.
jpg_size is a signed int, so a value with the top bit set also turns
into a huge length.

Reject a frame whose jpg_size is negative or exceeds the plane size
before copying it.

Fixes: 38f993ad8b1f ("V4L/DVB (8125): This driver adds support for the Sensoray 2255 devices.")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: HyeongJun An <sammiee5311@gmail.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/usb/s2255/s2255drv.c |    6 ++++++
 1 file changed, 6 insertions(+)

--- a/drivers/media/usb/s2255/s2255drv.c
+++ b/drivers/media/usb/s2255/s2255drv.c
@@ -617,6 +617,12 @@ static void s2255_fillbuff(struct s2255_
 			break;
 		case V4L2_PIX_FMT_JPEG:
 		case V4L2_PIX_FMT_MJPEG:
+			if (jpgsize < 0 ||
+			    jpgsize > vb2_plane_size(&buf->vb.vb2_buf, 0)) {
+				dprintk(dev, 1, "bad JPEG frame size %d\n",
+					jpgsize);
+				break;
+			}
 			vb2_set_plane_payload(&buf->vb.vb2_buf, 0, jpgsize);
 			memcpy(vbuf, tmpbuf, jpgsize);
 			break;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 393/556] media: s2255: check firmware size before reading trailing marker
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (391 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 392/556] media: s2255: bound JPEG frame size before copying into the buffer Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 394/556] media: saa7164: fix cleanup on resource allocation failure Greg Kroah-Hartman
                   ` (175 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Lei Huang, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lei Huang <huanglei@kylinos.cn>

commit 330f2936ab768c7215322a476f033143e8891d28 upstream.

s2255_probe() reads a 4-byte marker and version from the last 8 bytes
of the firmware blob (fw->data[fw_size - 8] and [fw_size - 4]). If the
firmware file is shorter than 8 bytes, fw_size - 8 underflows and the
access reads out of bounds. Validate the firmware size before indexing.

Fixes: 14d962602c8b ("V4L/DVB (8752): s2255drv: firmware improvement patch")
Cc: stable@vger.kernel.org
Signed-off-by: Lei Huang <huanglei@kylinos.cn>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/usb/s2255/s2255drv.c |    5 +++++
 1 file changed, 5 insertions(+)

--- a/drivers/media/usb/s2255/s2255drv.c
+++ b/drivers/media/usb/s2255/s2255drv.c
@@ -2283,6 +2283,11 @@ static int s2255_probe(struct usb_interf
 	}
 	/* check the firmware is valid */
 	fw_size = dev->fw_data->fw->size;
+	if (fw_size < 8) {
+		dev_err(&interface->dev, "Firmware invalid: too small.\n");
+		retval = -ENODEV;
+		goto errorFWMARKER;
+	}
 	pdata = (__le32 *) &dev->fw_data->fw->data[fw_size - 8];
 
 	if (*pdata != S2255_FW_MARKER) {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 394/556] media: saa7164: fix cleanup on resource allocation failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (392 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 393/556] media: s2255: check firmware size before reading trailing marker Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 395/556] media: tda18250: fix possible integer overflow Greg Kroah-Hartman
                   ` (174 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Guangshuo Li <lgs201920130244@gmail.com>

commit 28e84c6e2e6753ed238ea097b2842a32a6a6879b upstream.

saa7164_dev_setup() adds the device to the global saa7164_devlist before
requesting the PCI BAR memory regions.

If get_resources() fails, saa7164_dev_setup() decrements the device count
and returns an error, but leaves the device on saa7164_devlist. The probe
error path then frees the device, leaving a dangling entry on the global
list.

Reuse the existing MMIO mapping error path to remove the device from
saa7164_devlist and decrement the device count before returning.

Also release BAR0 if it was successfully requested but the BAR2 request
fails.

Fixes: 443c1228d505 ("V4L/DVB (12923): SAA7164: Add support for the NXP SAA7164 silicon")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/pci/saa7164/saa7164-core.c |    8 +++++---
 1 file changed, 5 insertions(+), 3 deletions(-)

--- a/drivers/media/pci/saa7164/saa7164-core.c
+++ b/drivers/media/pci/saa7164/saa7164-core.c
@@ -878,6 +878,9 @@ static int get_resources(struct saa7164_
 		if (request_mem_region(pci_resource_start(dev->pci, 2),
 			pci_resource_len(dev->pci, 2), dev->name))
 			return 0;
+
+		release_mem_region(pci_resource_start(dev->pci, 0),
+				   pci_resource_len(dev->pci, 0));
 	}
 
 	printk(KERN_ERR "%s: can't get MMIO memory @ 0x%llx or 0x%llx\n",
@@ -1000,8 +1003,7 @@ static int saa7164_dev_setup(struct saa7
 		       dev->name, dev->pci->subsystem_vendor,
 		       dev->pci->subsystem_device);
 
-		saa7164_devcount--;
-		return -ENODEV;
+		goto err_devlist;
 	}
 
 	/* PCI/e allocations */
@@ -1039,7 +1041,7 @@ err_ioremap_bar2:
 	iounmap(dev->lmmio);
 err_ioremap_bar0:
 	release_resources(dev);
-
+err_devlist:
 	scoped_guard(mutex, &devlist) {
 		list_del(&dev->devlist);
 	}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 395/556] media: tda18250: fix possible integer overflow
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (393 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 394/556] media: saa7164: fix cleanup on resource allocation failure Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 396/556] media: ti: vpe: quiesce overflow recovery before freeing streams Greg Kroah-Hartman
                   ` (173 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Ilya Krutskih, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ilya Krutskih <devsec@tpz.ru>

commit 6dd8e257f7cafda7fbf10d81b3c55c9bba4825f4 upstream.

Integer overflow may occur, when variable exp equals to zero. Result
of shift 1 << (exp - 1) may then leads to undefined behavior.

Fixes: 148abd3b5b14 ("media: tda18250: support for new silicon tuner")
Cc: stable@vger.kernel.org
Signed-off-by: Ilya Krutskih <devsec@tpz.ru>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/tuners/tda18250.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/drivers/media/tuners/tda18250.c
+++ b/drivers/media/tuners/tda18250.c
@@ -440,8 +440,8 @@ static int tda18250_pll_calc(struct dvb_
 		goto err;
 
 	exp = (uval & 0x70) >> 4;
-	if (exp > 5)
-		exp = 0;
+	if (exp == 0 || exp > 5)
+		exp = 1;
 	lopd = 1 << (exp - 1);
 	scale = uval & 0x0f;
 	fvco = lopd * scale * ((c->frequency / 1000) + dev->if_frequency);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 396/556] media: ti: vpe: quiesce overflow recovery before freeing streams
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (394 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 395/556] media: tda18250: fix possible integer overflow Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 397/556] media: v4l2-async: avoid deleting unlinked ASC entry on link error Greg Kroah-Hartman
                   ` (172 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Fan Wu, Yemike Abhilash Chandra,
	Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Fan Wu <fanwu01@zju.edu.cn>

commit aeaacc3001449d44b4ab7da56331121d1f3b137b upstream.

The VIP overflow recovery worker is armed from the hardirq handler when a
FIFO overflow is detected, and the list-complete path looks the stream up
through the VPDMA list private pointer. Both keep touching stream, port
and device state; the recovery worker also resets the parser and VPDMA,
repopulates the descriptor list, and re-enables the per-list IRQs.

vip_stop_streaming() masks and clears the per-list IRQs, but it neither
synchronizes the hardirq handler nor disables recovery_work. An overflow
IRQ that has already queued recovery_work, or a list-complete IRQ in
flight when the stream is torn down, can therefore still dereference the
stream after its resources are released: the descriptor list is freed by
vip_release_stream() on file release, and the stream itself by
free_stream() on unbind/remove.

Drain the recovery worker and the IRQ handler at both teardown points
through a shared vip_quiesce_stream() helper, before any stream-owned
resource is released. disable_work_sync() cancels pending recovery_work,
drains a running instance, and raises its disable depth, so a subsequent
schedule_work() issued by a racing IRQ handler is rejected at the
workqueue scheduler: recovery_work cannot be requeued after
disable_work_sync() takes effect. The worker may still re-enable the
per-list IRQs before disable_work_sync() returns; disable_irqs() then
masks those sources and synchronize_irq() waits for any in-flight handler
that still dereferences stream state. In vip_stop_streaming() the helper
runs before the parser is stopped, since a worker drained by
disable_work_sync() may re-enable the parser before exiting and would
otherwise undo the stop. recovery_work is created disabled and enabled in
vip_start_streaming() before IRQs, pairing the enable with the teardown
disable across the streaming lifecycle.

This issue was found by an in-house static analysis tool and confirmed
by manual code review.

Fixes: fc2873aa4a21 ("media: ti: vpe: Add the VIP driver")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5.6
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Reviewed-by: Yemike Abhilash Chandra <y-abhilashchandra@ti.com>
Tested-by: Yemike Abhilash Chandra <y-abhilashchandra@ti.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/ti/vpe/vip.c |   37 ++++++++++++++++++++++++++++++++----
 1 file changed, 33 insertions(+), 4 deletions(-)

--- a/drivers/media/platform/ti/vpe/vip.c
+++ b/drivers/media/platform/ti/vpe/vip.c
@@ -815,6 +815,22 @@ static void clear_irqs(struct vip_dev *d
 	vpdma_clear_list_stat(dev->shared->vpdma, irq_num, dev->slice_id);
 }
 
+/*
+ * Quiesce recovery work and per-list IRQs before releasing stream resources.
+ * disable_work_sync() prevents the overflow handler from requeueing recovery
+ * work. Mask and synchronize IRQs afterwards because a running worker may
+ * have re-enabled them before exiting.
+ */
+static void vip_quiesce_stream(struct vip_stream *stream)
+{
+	struct vip_dev *dev = stream->port->dev;
+
+	disable_work_sync(&stream->recovery_work);
+	disable_irqs(dev, dev->slice_id, stream->list_num);
+	clear_irqs(dev, dev->slice_id, stream->list_num);
+	synchronize_irq(dev->irq);
+}
+
 static void populate_desc_list(struct vip_stream *stream)
 {
 	struct vip_port *port = stream->port;
@@ -2429,6 +2445,7 @@ static int vip_start_streaming(struct vb
 		goto err;
 
 	stream->num_recovery = 0;
+	enable_work(&stream->recovery_work);
 
 	clear_irqs(dev, dev->slice_id, stream->list_num);
 	enable_irqs(dev, dev->slice_id, stream->list_num);
@@ -2453,13 +2470,17 @@ static void vip_stop_streaming(struct vb
 	struct vip_dev *dev = port->dev;
 	int ret;
 
+	/*
+	 * A running recovery worker may re-enable the parser, so quiesce it
+	 * and its IRQ handler before stopping the parser or releasing the
+	 * descriptor list.
+	 */
+	vip_quiesce_stream(stream);
+
 	vip_parser_stop_imm(port, true);
 	vip_enable_parser(port, false);
 	unset_fmt_params(stream);
 
-	disable_irqs(dev, dev->slice_id, stream->list_num);
-	clear_irqs(dev, dev->slice_id, stream->list_num);
-
 	if (port->subdev) {
 		ret = v4l2_subdev_call(port->subdev, video, s_stream, 0);
 		if (ret)
@@ -3075,6 +3096,8 @@ static int alloc_stream(struct vip_port
 		goto do_free_hwlist;
 
 	INIT_WORK(&stream->recovery_work, vip_overflow_recovery_work);
+	/* Start disabled; vip_start_streaming() enables it before IRQs. */
+	disable_work(&stream->recovery_work);
 
 	INIT_LIST_HEAD(&stream->vidq);
 
@@ -3140,6 +3163,13 @@ static void free_stream(struct vip_strea
 		return;
 
 	dev = stream->port->dev;
+	/*
+	 * Quiesce the IRQ handler and recovery worker, then drop the stream
+	 * from cap_streams[], before releasing stream-owned resources.
+	 */
+	vip_quiesce_stream(stream);
+	stream->port->cap_streams[stream->stream_id] = NULL;
+
 	/* Free up the Drop queue */
 	list_for_each_safe(pos, q, &stream->dropq) {
 		buf = list_entry(pos,
@@ -3151,7 +3181,6 @@ static void free_stream(struct vip_strea
 
 	video_unregister_device(stream->vfd);
 	vpdma_hwlist_release(dev->shared->vpdma, stream->list_num);
-	stream->port->cap_streams[stream->stream_id] = NULL;
 	kfree(stream);
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 397/556] media: v4l2-async: avoid deleting unlinked ASC entry on link error
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (395 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 396/556] media: ti: vpe: quiesce overflow recovery before freeing streams Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 398/556] media: v4l2-ctrls: validate HEVC EXT SPS RPS counts Greg Kroah-Hartman
                   ` (171 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Xu Rao, Sakari Ailus

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Xu Rao <raoxu@uniontech.com>

commit 47d82b605351c0e04f6365e42c8ffe2fcfdba615 upstream.

v4l2_async_match_notify() creates ancillary media links before adding
asc->asc_subdev_entry to sd->asc_list.

If ancillary link creation fails, the function jumps to
err_call_unbind while asc_subdev_entry has not been linked yet. Async
connections are zero-allocated, so the list entry still has NULL next
and prev pointers on this path. Calling list_del() on it can therefore
dereference NULL instead of returning the original link creation error.

Do not delete asc_subdev_entry from err_call_unbind. There is no list
insertion to undo on this path; the bound callback and sub-device
registration are the operations that need to be rolled back.

Fixes: 28a1295795d8 ("media: v4l: async: Allow multiple connections between entities")
Cc: stable@vger.kernel.org
Signed-off-by: Xu Rao <raoxu@uniontech.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/v4l2-core/v4l2-async.c |    1 -
 1 file changed, 1 deletion(-)

--- a/drivers/media/v4l2-core/v4l2-async.c
+++ b/drivers/media/v4l2-core/v4l2-async.c
@@ -392,7 +392,6 @@ static int v4l2_async_match_notify(struc
 
 err_call_unbind:
 	v4l2_async_nf_call_unbind(notifier, sd, asc);
-	list_del(&asc->asc_subdev_entry);
 
 err_unregister_subdev:
 	if (registered)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 398/556] media: v4l2-ctrls: validate HEVC EXT SPS RPS counts
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (396 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 397/556] media: v4l2-async: avoid deleting unlinked ASC entry on link error Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 399/556] media: v4l2-ctrls: Allow unknown HDR10 white point and luminance Greg Kroah-Hartman
                   ` (170 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Detlev Casanova, Michael Bommarito,
	Nicolas Dufresne, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Michael Bommarito <michael.bommarito@gmail.com>

commit 796b5c6d4f1615d59d5d8fe5a38fae6bfdfe878e upstream.

The HEVC SPS control carries the short-term and long-term RPS counts
that decoder drivers use to walk the matching EXT SPS dynamic arrays.
Reject SPS values that exceed the HEVC limits of 64 short-term sets and
32 long-term references so drivers cannot later index beyond those
controls.

Also reject EXT SPS ST RPS entries whose negative or positive picture
counts exceed the 16-entry arrays, or whose combined delta-POC count
exceeds the HEVC DPB maximum.

Fixes: c9a59dc2acc7 ("media: rkvdec: Add HEVC support for the VDPU381 variant")
Cc: stable@vger.kernel.org
Suggested-by: Detlev Casanova <detlev.casanova@collabora.com>
Assisted-by: Claude:claude-opus-4-7
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Reviewed-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/v4l2-core/v4l2-ctrls-core.c |   15 +++++++++++++++
 1 file changed, 15 insertions(+)

--- a/drivers/media/v4l2-core/v4l2-ctrls-core.c
+++ b/drivers/media/v4l2-core/v4l2-ctrls-core.c
@@ -16,6 +16,9 @@
 
 static const union v4l2_ctrl_ptr ptr_null;
 
+#define V4L2_HEVC_MAX_SHORT_TERM_REF_PIC_SETS	64
+#define V4L2_HEVC_MAX_LONG_TERM_REF_PICS_SPS	32
+
 static void fill_event(struct v4l2_event *ev, struct v4l2_ctrl *ctrl,
 		       u32 changes)
 {
@@ -1214,6 +1217,10 @@ static int std_validate_compound(const s
 	case V4L2_CTRL_TYPE_HEVC_SPS:
 		p_hevc_sps = p;
 
+		if (p_hevc_sps->num_short_term_ref_pic_sets >
+		    V4L2_HEVC_MAX_SHORT_TERM_REF_PIC_SETS)
+			return -EINVAL;
+
 		if (!(p_hevc_sps->flags & V4L2_HEVC_SPS_FLAG_PCM_ENABLED)) {
 			p_hevc_sps->pcm_sample_bit_depth_luma_minus1 = 0;
 			p_hevc_sps->pcm_sample_bit_depth_chroma_minus1 = 0;
@@ -1224,6 +1231,9 @@ static int std_validate_compound(const s
 		if (!(p_hevc_sps->flags &
 		      V4L2_HEVC_SPS_FLAG_LONG_TERM_REF_PICS_PRESENT))
 			p_hevc_sps->num_long_term_ref_pics_sps = 0;
+		else if (p_hevc_sps->num_long_term_ref_pics_sps >
+			 V4L2_HEVC_MAX_LONG_TERM_REF_PICS_SPS)
+			return -EINVAL;
 		break;
 
 	case V4L2_CTRL_TYPE_HEVC_PPS:
@@ -1280,6 +1290,11 @@ static int std_validate_compound(const s
 
 		if (p_hevc_st_rps->flags & ~V4L2_HEVC_EXT_SPS_ST_RPS_FLAG_INTER_REF_PIC_SET_PRED)
 			return -EINVAL;
+		if (p_hevc_st_rps->num_negative_pics > 16 ||
+		    p_hevc_st_rps->num_positive_pics > 16 ||
+		    p_hevc_st_rps->num_negative_pics +
+		    p_hevc_st_rps->num_positive_pics > 16)
+			return -EINVAL;
 		break;
 
 	case V4L2_CTRL_TYPE_HEVC_EXT_SPS_LT_RPS:



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 399/556] media: v4l2-ctrls: Allow unknown HDR10 white point and luminance
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (397 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 398/556] media: v4l2-ctrls: validate HEVC EXT SPS RPS counts Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 400/556] media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link Greg Kroah-Hartman
                   ` (169 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Ming Qian, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ming Qian <ming.qian@oss.nxp.com>

commit 49af0c7cad889f7dabe5cf080b019392066122a3 upstream.

SMPTE ST 2086 defines the nominal ranges for mastering display
chromaticity and luminance values. Its Annex A also documents that
CTA 861-G uses zero maximum and minimum luminance values to signal
that the corresponding values are unknown, and the xy chromaticity
coordinate (0, 0) to signal that the white point chromaticity is
unknown.

The V4L2 HDR10 mastering display compound control currently rejects
these values. Consequently, an unknown white point or luminance value
prevents the entire compound control from being updated, making the
other valid mastering display metadata unavailable to userspace.

Accept (0, 0) as an unknown white point and zero as an unknown maximum
or minimum mastering luminance. Continue to reject partially zero white
point coordinates and non-zero values outside the nominal ranges.
Display primary validation remains unchanged.

Document the newly accepted unknown values in the V4L2 userspace API.

Fixes: 1ad0de78e794 ("media: v4l: Add HDR10 static metadata controls")
Cc: stable@vger.kernel.org
Signed-off-by: Ming Qian <ming.qian@oss.nxp.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 Documentation/userspace-api/media/v4l/ext-ctrls-colorimetry.rst |   12 ++
 drivers/media/v4l2-core/v4l2-ctrls-core.c                       |   49 ++++++----
 2 files changed, 44 insertions(+), 17 deletions(-)

--- a/Documentation/userspace-api/media/v4l/ext-ctrls-colorimetry.rst
+++ b/Documentation/userspace-api/media/v4l/ext-ctrls-colorimetry.rst
@@ -80,15 +80,25 @@ Colorimetry Control IDs
       - ``white_point_x``
       - Specifies the normalized x chromaticity coordinate of the white
         point of the mastering display in increments of 0.00002.
+        When both ``white_point_x`` and ``white_point_y`` are zero,
+        the white point chromaticity is unknown. If either coordinate is
+        non-zero, both coordinates shall be within their valid ranges.
     * - __u16
       - ``white_point_y``
       - Specifies the normalized y chromaticity coordinate of the white
         point of the mastering display in increments of 0.00002.
+        When both ``white_point_x`` and ``white_point_y`` are zero,
+        the white point chromaticity is unknown. If either coordinate is
+        non-zero, both coordinates shall be within their valid ranges.
     * - __u32
       - ``max_luminance``
       - Specifies the nominal maximum display luminance of the mastering
         display in units of 0.0001 cd/m\ :sup:`2`.
+        A value of zero indicates that the nominal maximum display
+        luminance is unknown.
     * - __u32
       - ``min_luminance``
-      - specifies the nominal minimum display luminance of the mastering
+      - Specifies the nominal minimum display luminance of the mastering
         display in units of 0.0001 cd/m\ :sup:`2`.
+        A value of zero indicates that the nominal minimum display
+        luminance is unknown.
--- a/drivers/media/v4l2-core/v4l2-ctrls-core.c
+++ b/drivers/media/v4l2-core/v4l2-ctrls-core.c
@@ -1322,24 +1322,41 @@ static int std_validate_compound(const s
 				return -EINVAL;
 		}
 
-		if (p_hdr10_mastering->white_point_x <
-			V4L2_HDR10_MASTERING_WHITE_POINT_X_LOW ||
-		    p_hdr10_mastering->white_point_x >
-			V4L2_HDR10_MASTERING_WHITE_POINT_X_HIGH ||
-		    p_hdr10_mastering->white_point_y <
-			V4L2_HDR10_MASTERING_WHITE_POINT_Y_LOW ||
-		    p_hdr10_mastering->white_point_y >
-			V4L2_HDR10_MASTERING_WHITE_POINT_Y_HIGH)
+		/*
+		 * SMPTE ST 2086 Annex A documents that CTA 861-G uses
+		 * (0, 0) to indicate that the white point chromaticity
+		 * is unknown.
+		 */
+		if (p_hdr10_mastering->white_point_x ||
+		    p_hdr10_mastering->white_point_y) {
+			if (p_hdr10_mastering->white_point_x <
+				V4L2_HDR10_MASTERING_WHITE_POINT_X_LOW ||
+			    p_hdr10_mastering->white_point_x >
+				V4L2_HDR10_MASTERING_WHITE_POINT_X_HIGH ||
+			    p_hdr10_mastering->white_point_y <
+				V4L2_HDR10_MASTERING_WHITE_POINT_Y_LOW ||
+			    p_hdr10_mastering->white_point_y >
+				V4L2_HDR10_MASTERING_WHITE_POINT_Y_HIGH)
+				return -EINVAL;
+		}
+
+		/*
+		 * SMPTE ST 2086 Annex A documents that CTA 861-G uses zero
+		 * maximum and minimum luminance values to indicate that
+		 * the corresponding values are unknown.
+		 */
+		if (p_hdr10_mastering->max_display_mastering_luminance &&
+		    (p_hdr10_mastering->max_display_mastering_luminance <
+				V4L2_HDR10_MASTERING_MAX_LUMA_LOW ||
+		     p_hdr10_mastering->max_display_mastering_luminance >
+				V4L2_HDR10_MASTERING_MAX_LUMA_HIGH))
 			return -EINVAL;
 
-		if (p_hdr10_mastering->max_display_mastering_luminance <
-			V4L2_HDR10_MASTERING_MAX_LUMA_LOW ||
-		    p_hdr10_mastering->max_display_mastering_luminance >
-			V4L2_HDR10_MASTERING_MAX_LUMA_HIGH ||
-		    p_hdr10_mastering->min_display_mastering_luminance <
-			V4L2_HDR10_MASTERING_MIN_LUMA_LOW ||
-		    p_hdr10_mastering->min_display_mastering_luminance >
-			V4L2_HDR10_MASTERING_MIN_LUMA_HIGH)
+		if (p_hdr10_mastering->min_display_mastering_luminance &&
+		    (p_hdr10_mastering->min_display_mastering_luminance <
+				V4L2_HDR10_MASTERING_MIN_LUMA_LOW ||
+		     p_hdr10_mastering->min_display_mastering_luminance >
+				V4L2_HDR10_MASTERING_MIN_LUMA_HIGH))
 			return -EINVAL;
 
 		/* The following restriction comes from ITU-T Rec. H.265 spec */



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 400/556] media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (398 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 399/556] media: v4l2-ctrls: Allow unknown HDR10 white point and luminance Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 401/556] media: venus: fix payload size returned by parse_caps() and parse_alloc_mode() Greg Kroah-Hartman
                   ` (168 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Biren Pandya, Sakari Ailus

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Biren Pandya <birenpandya@gmail.com>

commit a6e86efd7f85e519bf48417f41923f8bd51f1597 upstream.

In v4l2_fwnode_parse_link(), the remote endpoint fwnode reference is
acquired using fwnode_graph_get_remote_endpoint(). This reference is
properly released in the error paths, but it is leaked on the success
path.

Add the missing fwnode_handle_put() before returning 0 to prevent the
reference leak.

Signed-off-by: Biren Pandya <birenpandya@gmail.com>
Fixes: ca50c197bd96 ("[media] v4l: fwnode: Support generic fwnode for parsing standardised properties")
Cc: stable@vger.kernel.org
[Sakari Ailus: Fix subject prefix and coding style a little.]
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/v4l2-core/v4l2-fwnode.c |    2 ++
 1 file changed, 2 insertions(+)

--- a/drivers/media/v4l2-core/v4l2-fwnode.c
+++ b/drivers/media/v4l2-core/v4l2-fwnode.c
@@ -633,6 +633,8 @@ int v4l2_fwnode_parse_link(struct fwnode
 	if (!link->remote_node)
 		goto err_put_remote_endpoint;
 
+	fwnode_handle_put(fwnode);
+
 	return 0;
 
 err_put_remote_endpoint:



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 401/556] media: venus: fix payload size returned by parse_caps() and parse_alloc_mode()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (399 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 400/556] media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 402/556] media: venus: fix payload size calculation in parse_raw_formats() Greg Kroah-Hartman
                   ` (167 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mohammed EL Kadiri, Dmitry Baryshkov,
	Bryan ODonoghue

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mohammed EL Kadiri <med08elkadiri@gmail.com>

commit a51cea23e409278f6e2ea072280aba93cc1dd75e upstream.

parse_caps() and parse_alloc_mode() return only the size of their fixed
header fields, excluding the flexible array payload. hfi_parser() uses
this return value to advance through the firmware response buffer, so
underreporting causes parser desynchronization.

Return the full consumed size (header + entries), matching the correct
pattern used by parse_profile_level().

Fixes: 9edaaa8e3e15 ("media: venus: hfi_parser: refactor hfi packet parsing logic")
Cc: stable@vger.kernel.org
Signed-off-by: Mohammed EL Kadiri <med08elkadiri@gmail.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Bryan O'Donoghue <bod@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/qcom/venus/hfi_parser.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/drivers/media/platform/qcom/venus/hfi_parser.c
+++ b/drivers/media/platform/qcom/venus/hfi_parser.c
@@ -85,7 +85,7 @@ parse_alloc_mode(struct venus_core *core
 		type++;
 	}
 
-	return sizeof(*mode);
+	return mode->num_entries * sizeof(u32) + sizeof(*mode);
 }
 
 static void fill_profile_level(struct hfi_plat_caps *cap, const void *data,
@@ -146,7 +146,7 @@ parse_caps(struct venus_core *core, u32
 	for_each_codec(core->caps, ARRAY_SIZE(core->caps), codecs, domain,
 		       fill_caps, caps_arr, num_caps);
 
-	return sizeof(*caps);
+	return num_caps * sizeof(*cap) + sizeof(u32);
 }
 
 static void fill_raw_fmts(struct hfi_plat_caps *cap, const void *fmts,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 402/556] media: venus: fix payload size calculation in parse_raw_formats()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (400 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 401/556] media: venus: fix payload size returned by parse_caps() and parse_alloc_mode() Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 403/556] media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure Greg Kroah-Hartman
                   ` (166 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mohammed EL Kadiri, Dmitry Baryshkov,
	Bryan ODonoghue

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mohammed EL Kadiri <med08elkadiri@gmail.com>

commit bd595b745eb770e80347c31ffc25351046935305 upstream.

The consumed size is computed after the loop using the num_planes value
from the last iteration for all entries. When entries have different
plane counts, this produces an incorrect total.

Accumulate the actual size during the loop instead.

Fixes: 9edaaa8e3e15 ("media: venus: hfi_parser: refactor hfi packet parsing logic")
Cc: stable@vger.kernel.org
Signed-off-by: Mohammed EL Kadiri <med08elkadiri@gmail.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Bryan O'Donoghue <bod@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/qcom/venus/hfi_parser.c |    5 ++---
 1 file changed, 2 insertions(+), 3 deletions(-)

--- a/drivers/media/platform/qcom/venus/hfi_parser.c
+++ b/drivers/media/platform/qcom/venus/hfi_parser.c
@@ -171,7 +171,7 @@ parse_raw_formats(struct venus_core *cor
 	u32 entries = fmt->format_entries;
 	unsigned int i = 0;
 	u32 num_planes = 0;
-	u32 size;
+	u32 size = 2 * sizeof(u32);
 
 	while (entries) {
 		num_planes = pinfo->num_planes;
@@ -186,6 +186,7 @@ parse_raw_formats(struct venus_core *cor
 		if (pinfo->num_planes > MAX_PLANES)
 			break;
 
+		size += sizeof(*constr) * num_planes + 2 * sizeof(u32);
 		pinfo = (void *)pinfo + sizeof(*constr) * num_planes +
 			2 * sizeof(u32);
 		entries--;
@@ -193,8 +194,6 @@ parse_raw_formats(struct venus_core *cor
 
 	for_each_codec(core->caps, ARRAY_SIZE(core->caps), codecs, domain,
 		       fill_raw_fmts, rawfmts, i);
-	size = fmt->format_entries * (sizeof(*constr) * num_planes + 2 * sizeof(u32))
-		+ 2 * sizeof(u32);
 
 	return size;
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 403/556] media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (401 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 402/556] media: venus: fix payload size calculation in parse_raw_formats() Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 404/556] media: vimc: fix pixel format lookup in enum_framesizes Greg Kroah-Hartman
                   ` (165 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Uday Khare, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Uday Khare <udaykhare77@gmail.com>

commit 76e379754ba618989f6215be608d5c04774a611d upstream.

kthread_run() returns an ERR_PTR on failure, not NULL.
When start_streaming() fails, data->kthread_vid_cap is left holding
this error pointer instead of being cleared.

This causes two subsequent bugs:
1. A future call to start_streaming() sees a non-NULL kthread_vid_cap
   and returns 0 (success) immediately, without actually starting the
   capture thread.
2. A call to stop_streaming() checks 'kthread_vid_cap == NULL' which
   is false for an error pointer, and proceeds to call kthread_stop()
   on the error pointer, leading to a kernel crash.

Fix this by resetting kthread_vid_cap to NULL on failure before
jumping to the error path.

Fixes: 5cebaac60974 ("media: video-i2c: add video-i2c driver")
Cc: stable@vger.kernel.org
Signed-off-by: Uday Khare <udaykhare77@gmail.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/i2c/video-i2c.c |    8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

--- a/drivers/media/i2c/video-i2c.c
+++ b/drivers/media/i2c/video-i2c.c
@@ -522,8 +522,12 @@ static int start_streaming(struct vb2_qu
 	data->kthread_vid_cap = kthread_run(video_i2c_thread_vid_cap, data,
 					    "%s-vid-cap", data->v4l2_dev.name);
 	ret = PTR_ERR_OR_ZERO(data->kthread_vid_cap);
-	if (!ret)
-		return 0;
+	if (ret) {
+		data->kthread_vid_cap = NULL;
+		goto error_rpm_put;
+	}
+
+	return 0;
 
 error_rpm_put:
 	pm_runtime_put_autosuspend(dev);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 404/556] media: vimc: fix pixel format lookup in enum_framesizes
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (402 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 403/556] media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 405/556] media: zoran: Avoid freeing a registered video_device twice Greg Kroah-Hartman
                   ` (164 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Arash Golgol, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Arash Golgol <arash.golgol@gmail.com>

commit ad4c65fa30cfb00e2e06adae9a8eb407086eaa66 upstream.

vimc_capture_enum_framesizes() looks up the requested format using
vimc_pix_map_by_code(), which searches the pix map table by media
bus code (MEDIA_BUS_FMT_*).

However, v4l2_frmsizeenum::pixel_format holds a V4L2 pixel format
(V4L2_PIX_FMT_*), not a media bus code, so valid pixel formats end
up being rejected with -EINVAL.

Fix this by using vimc_pix_map_by_pixelformat() instead, which
performs the lookup by pixel format as the ioctl expects.

Fixes: 09c41a23a2e2 ("media: Revert "media: vimc: propagate pixel format in the stream"")
Cc: stable@vger.kernel.org
Signed-off-by: Arash Golgol <arash.golgol@gmail.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/test-drivers/vimc/vimc-capture.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/drivers/media/test-drivers/vimc/vimc-capture.c
+++ b/drivers/media/test-drivers/vimc/vimc-capture.c
@@ -175,8 +175,8 @@ static int vimc_capture_enum_framesizes(
 	if (fsize->index)
 		return -EINVAL;
 
-	/* Only accept code in the pix map table */
-	vpix = vimc_pix_map_by_code(fsize->pixel_format);
+	/* Only accept pixel_format in the pix map table */
+	vpix = vimc_pix_map_by_pixelformat(fsize->pixel_format);
 	if (!vpix)
 		return -EINVAL;
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 405/556] media: zoran: Avoid freeing a registered video_device twice
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (403 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 404/556] media: vimc: fix pixel format lookup in enum_framesizes Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 406/556] media: qcom: iris: fix state-change debug log printing stale value Greg Kroah-Hartman
                   ` (163 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Ruoyu Wang, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Ruoyu Wang <ruoyuw560@gmail.com>

commit 0735e0b5a96761a9ce277a238e834008ad92a0a5 upstream.

zoran_init_video_device() installs zoran_vdev_release() as the
video_device release callback through zoran_template. After
video_register_device() succeeds, video_unregister_device() drops the
registered video_device reference and the V4L2 core eventually invokes
that release callback, which kfree()s the video_device.

zoran_exit_video_devices() called video_unregister_device() and then
kfree(zr->video_dev), so device teardown could free the same
video_device twice.

Remove the direct kfree() and clear the cached pointer after
unregistering. The pre-registration failure path keeps its manual free
because the video_device was not registered there.

This issue was found by a static analysis checker and confirmed by
manual source review.

Fixes: 82e3a496eb56 ("media: staging: media: zoran: move videodev alloc")
Cc: stable@vger.kernel.org
Signed-off-by: Ruoyu Wang <ruoyuw560@gmail.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/pci/zoran/zoran_card.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/media/pci/zoran/zoran_card.c
+++ b/drivers/media/pci/zoran/zoran_card.c
@@ -885,7 +885,7 @@ static int zoran_init_video_device(struc
 static void zoran_exit_video_devices(struct zoran *zr)
 {
 	video_unregister_device(zr->video_dev);
-	kfree(zr->video_dev);
+	zr->video_dev = NULL;
 }
 
 static int zoran_init_video_devices(struct zoran *zr)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 406/556] media: qcom: iris: fix state-change debug log printing stale value
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (404 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 405/556] media: zoran: Avoid freeing a registered video_device twice Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 407/556] media: qcom: iris: use disable_irq() during power-off Greg Kroah-Hartman
                   ` (162 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Bryan ODonoghue, Konrad Dybcio,
	Dikshita Agarwal, Vishnu Reddy, Bryan ODonoghue

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Dikshita Agarwal <dikshita.agarwal@oss.qualcomm.com>

commit 460d3257a6dffc7f0bf58009daeb7e0b6eb2d9d3 upstream.

The state‑change debug log in iris_inst_change_state() always prints the
same value for the old and new state, rendering it useless for
debugging. This happens because the state is updated before the log is
emitted.

Log the transition before updating the state so the previous value is
preserved, consistent with the existing sub‑state handling.

Fixes: 11712ce70f8e ("media: iris: implement vb2 streaming ops")
Reviewed-by: Bryan O'Donoghue <bryan.odonoghue@linaro.org>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Dikshita Agarwal <dikshita.agarwal@oss.qualcomm.com>
Signed-off-by: Vishnu Reddy <busanna.reddy@oss.qualcomm.com>
Cc: stable@vger.kernel.org
Signed-off-by: Bryan O'Donoghue <bod@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/qcom/iris/iris_state.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/media/platform/qcom/iris/iris_state.c
+++ b/drivers/media/platform/qcom/iris/iris_state.c
@@ -60,9 +60,9 @@ int iris_inst_change_state(struct iris_i
 		return -EINVAL;
 
 change_state:
-	inst->state = request_state;
 	dev_dbg(inst->core->dev, "state changed from %x to %x\n",
 		inst->state, request_state);
+	inst->state = request_state;
 
 	return 0;
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 407/556] media: qcom: iris: use disable_irq() during power-off
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (405 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 406/556] media: qcom: iris: fix state-change debug log printing stale value Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 408/556] media: qcom: iris: fix missing hfi_id in gen1 GOP_SIZE cap Greg Kroah-Hartman
                   ` (161 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Dmitry Baryshkov,
	Hungyu Lin, Bryan ODonoghue, Bryan ODonoghue

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Hungyu Lin <dennylin0707@gmail.com>

commit b9c2215bdedc9c532a7e9d57ec49ee1b6381f863 upstream.

The IRQ is registered as a threaded IRQ.

Using disable_irq_nosync() in iris_vpu_power_off() does not wait
for an already queued threaded IRQ handler to complete before
returning.

As a result, a threaded IRQ handler may still run after the VPU has
been powered down and access hardware registers after power-off.

Replace disable_irq_nosync() with disable_irq() so the power-off path
waits for any in-flight threaded IRQ handler to complete before
returning.

Fixes: bb8a95aa038e ("media: iris: implement power management")
Cc: stable@vger.kernel.org
Suggested-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Hungyu Lin <dennylin0707@gmail.com>
Reviewed-by: Bryan O'Donoghue <bryan.odonoghue@linaro.org>
Signed-off-by: Bryan O'Donoghue <bod@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/qcom/iris/iris_vpu_common.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/media/platform/qcom/iris/iris_vpu_common.c
+++ b/drivers/media/platform/qcom/iris/iris_vpu_common.c
@@ -237,7 +237,7 @@ void iris_vpu_power_off(struct iris_core
 	iris_unset_icc_bw(core);
 
 	if (!iris_vpu_watchdog(core, core->intr_status))
-		disable_irq_nosync(core->irq);
+		disable_irq(core->irq);
 }
 
 int iris_vpu_power_on_controller(struct iris_core *core)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 408/556] media: qcom: iris: fix missing hfi_id in gen1 GOP_SIZE cap
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (406 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 407/556] media: qcom: iris: use disable_irq() during power-off Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 409/556] media: chips-media: wave5: Guard bit depth check with initial_info_obtained Greg Kroah-Hartman
                   ` (160 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Vishnu Reddy, Wangao Wang,
	Vikash Garodia, Bryan ODonoghue

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wangao Wang <wangao.wang@oss.qualcomm.com>

commit 5eebacbc9a38e1019854ea5f86e367a4d5116387 upstream.

Add hfi_id to gen1 encoder GOP_SIZE cap and replace the set function,
remove the redundant INTRA_PERIOD cap.

Fixes: d22037f3fd33 ("media: iris: Set platform capabilities to firmware for encoder video device")

Reviewed-by: Vishnu Reddy <busanna.reddy@oss.qualcomm.com>
Signed-off-by: Wangao Wang <wangao.wang@oss.qualcomm.com>
Reviewed-by: Vikash Garodia <vikash.garodia@oss.qualcomm.com>
Cc: stable@vger.kernel.org
Signed-off-by: Bryan O'Donoghue <bod@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/qcom/iris/iris_ctrls.c           |    2 +-
 drivers/media/platform/qcom/iris/iris_hfi_gen1.c        |   16 ++++------------
 drivers/media/platform/qcom/iris/iris_platform_common.h |    1 -
 3 files changed, 5 insertions(+), 14 deletions(-)

--- a/drivers/media/platform/qcom/iris/iris_ctrls.c
+++ b/drivers/media/platform/qcom/iris/iris_ctrls.c
@@ -1293,7 +1293,7 @@ int iris_set_use_and_mark_ltr(struct iri
 int iris_set_intra_period(struct iris_inst *inst, enum platform_inst_fw_cap_type cap_id)
 {
 	const struct iris_hfi_session_ops *hfi_ops = inst->hfi_session_ops;
-	u32 gop_size = inst->fw_caps[GOP_SIZE].value;
+	u32 gop_size = inst->fw_caps[cap_id].value;
 	u32 b_frame = inst->fw_caps[B_FRAME].value;
 	u32 hfi_id = inst->fw_caps[cap_id].hfi_id;
 	struct hfi_intra_period intra_period;
--- a/drivers/media/platform/qcom/iris/iris_hfi_gen1.c
+++ b/drivers/media/platform/qcom/iris/iris_hfi_gen1.c
@@ -171,7 +171,9 @@ static const struct platform_inst_fw_cap
 		.max = (1 << 16) - 1,
 		.step_or_mask = 1,
 		.value = 30,
-		.set = iris_set_u32
+		.hfi_id = HFI_PROPERTY_CONFIG_VENC_INTRA_PERIOD,
+		.flags = CAP_FLAG_OUTPUT_PORT,
+		.set = iris_set_intra_period,
 	},
 	{
 		.cap_id = ENTROPY_MODE,
@@ -240,7 +242,7 @@ static const struct platform_inst_fw_cap
 		.step_or_mask = 1,
 		.value = 0,
 		.hfi_id = HFI_PROPERTY_PARAM_VENC_INTRA_REFRESH,
-		.flags = CAP_FLAG_OUTPUT_PORT,
+		.flags = CAP_FLAG_OUTPUT_PORT | CAP_FLAG_DYNAMIC_ALLOWED,
 		.set = iris_set_ir_period_gen1,
 	},
 	{
@@ -282,16 +284,6 @@ static const struct platform_inst_fw_cap
 		.flags = CAP_FLAG_OUTPUT_PORT,
 	},
 	{
-		.cap_id = INTRA_PERIOD,
-		.min = 0,
-		.max = 1,
-		.step_or_mask = 1,
-		.value = 0,
-		.hfi_id = HFI_PROPERTY_CONFIG_VENC_INTRA_PERIOD,
-		.flags = CAP_FLAG_OUTPUT_PORT,
-		.set = iris_set_intra_period,
-	},
-	{
 		.cap_id = LAYER_ENABLE,
 		.min = 0,
 		.max = 1,
--- a/drivers/media/platform/qcom/iris/iris_platform_common.h
+++ b/drivers/media/platform/qcom/iris/iris_platform_common.h
@@ -165,7 +165,6 @@ enum platform_inst_fw_cap_type {
 	USE_LTR,
 	MARK_LTR,
 	B_FRAME,
-	INTRA_PERIOD,
 	LAYER_ENABLE,
 	LAYER_TYPE_H264,
 	LAYER_TYPE_HEVC,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 409/556] media: chips-media: wave5: Guard bit depth check with initial_info_obtained
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (407 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 408/556] media: qcom: iris: fix missing hfi_id in gen1 GOP_SIZE cap Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 410/556] media: chips-media: wave5: Set inst->std during default format initialization Greg Kroah-Hartman
                   ` (159 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jackson Lee, Nas Chung,
	Nicolas Dufresne, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jackson Lee <jackson.lee@chipsnmedia.com>

commit 1551386934ad43d934c3bb7317929207e1edcd6a upstream.

When CAPTURE STREAMON is called before the VPU has completed sequence
initialization (initial_info_obtained == false), the initial_info fields
contain uninitialized data. The driver checks
luma_bitdepth and rejects anything other than 8-bit, so garbage values
(e.g. 15) cause STREAMON to fail spuriously.

This is reproducible with the following multi-threaded test scenario:
  1. Allocate 2 CAPTURE buffers.
  2. Call STREAMON on the CAPTURE queue.
  3. Call DQBUF, which blocks waiting for a decoded frame.
  4. A second thread calls STREAMOFF on the CAPTURE queue.
  5. The blocked DQBUF should be released, allowing graceful termination.

At step 2, STREAMON reads uninitialized luma_bitdepth and rejects the
stream, causing the test to fail.

Fix this by checking initial_info_obtained before accessing the bit
depth fields, so the validation is only performed when the sequence
info has actually been parsed by the VPU.

Fixes: 035371c9e509 ("media: chips-media: wave5: Fix timeout while testing 10bit hevc fluster")
Cc: stable@vger.kernel.org
Signed-off-by: Jackson Lee <jackson.lee@chipsnmedia.com>
Signed-off-by: Nas Chung <nas.chung@chipsnmedia.com>
Reviewed-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c
+++ b/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c
@@ -1403,6 +1403,7 @@ static int wave5_vpu_dec_start_streaming
 	} else if (q->type == V4L2_BUF_TYPE_VIDEO_CAPTURE_MPLANE) {
 		struct dec_initial_info *initial_info =
 			&inst->codec_info->dec_info.initial_info;
+		struct dec_info *p_dec_info = &inst->codec_info->dec_info;
 
 		if (inst->state == VPU_INST_STATE_STOP)
 			ret = switch_state(inst, VPU_INST_STATE_INIT_SEQ);
@@ -1410,6 +1411,7 @@ static int wave5_vpu_dec_start_streaming
 			goto return_buffers;
 
 		if (inst->state == VPU_INST_STATE_INIT_SEQ &&
+		    p_dec_info->initial_info_obtained &&
 		    inst->dev->product_code == WAVE521C_CODE) {
 			if (initial_info->luma_bitdepth != 8) {
 				dev_info(inst->dev->dev, "%s: no support for %d bit depth",
@@ -1418,7 +1420,6 @@ static int wave5_vpu_dec_start_streaming
 				goto return_buffers;
 			}
 		}
-
 	}
 	pm_runtime_put_autosuspend(inst->dev->dev);
 	return ret;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 410/556] media: chips-media: wave5: Set inst->std during default format initialization
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (408 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 409/556] media: chips-media: wave5: Guard bit depth check with initial_info_obtained Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 411/556] media: chips-media: wave5: avoid skipping device_run while VPU has work Greg Kroah-Hartman
                   ` (158 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jackson Lee, Nas Chung,
	Nicolas Dufresne, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jackson Lee <jackson.lee@chipsnmedia.com>

commit cfcefc5a996f6a00b310c963b5f811430f28a30a upstream.

When the encoder is opened, wave5_set_default_format() sets up the
default capture format (e.g. H.264) but does not initialize inst->std.
As a result, inst->std remains zero, which does not match any valid
encoder codec.

If STREAMON is called before the user explicitly calls S_FMT on the
capture queue — as v4l2-compliance does in testBlockingDQBuf — the
codec/product check in wave5_vpu_enc_init_seq() fails with
"Unsupported encoder-codec & product combination" because inst->std
is neither W_HEVC_ENC nor W_AVC_ENC, returning -EOPNOTSUPP.

Fix this by setting inst->std via wave5_to_vpu_std() in
wave5_set_default_format(), so that the codec type is always consistent
with the default capture pixel format from the moment the instance is
opened.

Fixes: 9707a6254a8a ("media: chips-media: wave5: Add the v4l2 layer")
Cc: stable@vger.kernel.org
Signed-off-by: Jackson Lee <jackson.lee@chipsnmedia.com>
Signed-off-by: Nas Chung <nas.chung@chipsnmedia.com>
Reviewed-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/chips-media/wave5/wave5-vpu-enc.c |    6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

--- a/drivers/media/platform/chips-media/wave5/wave5-vpu-enc.c
+++ b/drivers/media/platform/chips-media/wave5/wave5-vpu-enc.c
@@ -1494,7 +1494,8 @@ static const struct vb2_ops wave5_vpu_en
 	.stop_streaming = wave5_vpu_enc_stop_streaming,
 };
 
-static void wave5_set_default_format(struct v4l2_pix_format_mplane *src_fmt,
+static void wave5_set_default_format(struct vpu_instance *inst,
+				     struct v4l2_pix_format_mplane *src_fmt,
 				     struct v4l2_pix_format_mplane *dst_fmt)
 {
 	src_fmt->pixelformat = enc_fmt_list[VPU_FMT_TYPE_RAW][0].v4l2_pix_fmt;
@@ -1506,6 +1507,7 @@ static void wave5_set_default_format(str
 	wave5_update_pix_fmt(dst_fmt, VPU_FMT_TYPE_CODEC,
 			     W5_DEF_ENC_PIC_WIDTH, W5_DEF_ENC_PIC_HEIGHT,
 			     &enc_frmsize[VPU_FMT_TYPE_CODEC]);
+	inst->std = wave5_to_vpu_std(dst_fmt->pixelformat, inst->type);
 }
 
 static int wave5_vpu_enc_queue_init(void *priv, struct vb2_queue *src_vq, struct vb2_queue *dst_vq)
@@ -1770,7 +1772,7 @@ static int wave5_vpu_open_enc(struct fil
 	inst->v4l2_fh.ctrl_handler = v4l2_ctrl_hdl;
 	v4l2_ctrl_handler_setup(v4l2_ctrl_hdl);
 
-	wave5_set_default_format(&inst->src_fmt, &inst->dst_fmt);
+	wave5_set_default_format(inst, &inst->src_fmt, &inst->dst_fmt);
 	inst->conf_win.width = inst->dst_fmt.width;
 	inst->conf_win.height = inst->dst_fmt.height;
 	inst->colorspace = V4L2_COLORSPACE_REC709;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 411/556] media: chips-media: wave5: avoid skipping device_run while VPU has work
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (409 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 410/556] media: chips-media: wave5: Set inst->std during default format initialization Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 412/556] media: chips-media: wave5: Add timeout while stop_streaming Greg Kroah-Hartman
                   ` (157 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jackson Lee, Nas Chung,
	Nicolas Dufresne, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jackson Lee <jackson.lee@chipsnmedia.com>

commit 8c5a74a24cbbba9142e38c463c96435d316149ce upstream.

The decoder stalls because empty_queue is set to true even when the
m2m context still has pending commands. As a result, device_run is
never invoked, the m2m source queue fills up, and userspace (e.g.
Chromium) can no longer queue new bitstream buffers to the V4L2
driver.

Fix this by querying the VPU queue status via DEC_GET_QUEUE_STATUS
before deciding whether to skip device_run. Only skip when the
VPU's instance_queue_count equals the number of ready source
buffers in the v4l2-m2m context, which indicates that there is
genuinely no new work to perform. Otherwise, proceed with issuing
a decode command so that the VPU can continue draining its internal
queue.

Fixes: a176ac5e701f ("media: chips-media: wave5: Improve performance of decoder")
Cc: stable@vger.kernel.org
Signed-off-by: Jackson Lee <jackson.lee@chipsnmedia.com>
Signed-off-by: Nas Chung <nas.chung@chipsnmedia.com>
Reviewed-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 .../media/platform/chips-media/wave5/wave5-vpu-dec.c   | 10 +++++++---
 1 file changed, 7 insertions(+), 3 deletions(-)

diff --git a/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c b/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c
index 01d1368b2965..6c6e86b09b40 100644
--- a/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c
+++ b/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c
@@ -1663,9 +1663,13 @@ static void wave5_vpu_dec_device_run(void *priv)
 		} else if (!inst->eos &&
 				inst->queuing_num == 0 &&
 				inst->state == VPU_INST_STATE_PIC_RUN) {
-			dev_dbg(inst->dev->dev, "%s: no bitstream for feeding, so skip ", __func__);
-			inst->empty_queue = true;
-			goto finish_job_and_return;
+			wave5_vpu_dec_give_command(inst, DEC_GET_QUEUE_STATUS, &q_status);
+			if (q_status.instance_queue_count == v4l2_m2m_num_src_bufs_ready(m2m_ctx)) {
+				dev_dbg(inst->dev->dev, "%s: no bitstream, skip\n",
+					__func__);
+				inst->empty_queue = true;
+				goto finish_job_and_return;
+			}
 		}
 	}
 
-- 
2.55.0




^ permalink raw reply related	[flat|nested] 570+ messages in thread

* [PATCH 7.2 412/556] media: chips-media: wave5: Add timeout while stop_streaming
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (410 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 411/556] media: chips-media: wave5: avoid skipping device_run while VPU has work Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 413/556] media: chips-media: wave5: Defer job_finish() only when a DEC_PIC was queued Greg Kroah-Hartman
                   ` (156 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jackson Lee, Nas Chung,
	Nicolas Dufresne, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jackson Lee <jackson.lee@chipsnmedia.com>

commit 2ae7faed2e60d6d07d9efdd962d20dcb15330ced upstream.

When stop_streaming is called, an infinite loop may occur in some cases.
Add a bounded poll of the queue status: loop until the queues drain,
sleeping briefly between polls, and bail out once VPU_DEC_STOP_TIMEOUT
elapses.

Fixes: 9707a6254a8a ("media: chips-media: wave5: Add the v4l2 layer")
Cc: stable@vger.kernel.org
Signed-off-by: Jackson Lee <jackson.lee@chipsnmedia.com>
Signed-off-by: Nas Chung <nas.chung@chipsnmedia.com>
Reviewed-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c   |   15 +++++++------
 drivers/media/platform/chips-media/wave5/wave5-vpuconfig.h |    2 -
 2 files changed, 10 insertions(+), 7 deletions(-)

--- a/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c
+++ b/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c
@@ -5,6 +5,7 @@
  * Copyright (C) 2021-2023 CHIPS&MEDIA INC
  */
 
+#include <linux/delay.h>
 #include <linux/pm_runtime.h>
 #include "wave5-helper.h"
 
@@ -1537,15 +1538,15 @@ static void wave5_vpu_dec_stop_streaming
 {
 	struct vpu_instance *inst = vb2_get_drv_priv(q);
 	struct v4l2_m2m_ctx *m2m_ctx = inst->v4l2_fh.m2m_ctx;
-
-	bool check_cmd = TRUE;
+	unsigned long timeout;
 
 	dev_dbg(inst->dev->dev, "%s: type: %u\n", __func__, q->type);
 	pm_runtime_resume_and_get(inst->dev->dev);
 	inst->empty_queue = true;
-	while (check_cmd) {
+
+	timeout = jiffies + msecs_to_jiffies(VPU_DEC_STOP_TIMEOUT);
+	while (true) {
 		struct queue_status_info q_status;
-		struct dec_output_info dec_output_info;
 
 		wave5_vpu_dec_give_command(inst, DEC_GET_QUEUE_STATUS, &q_status);
 		if ((inst->state == VPU_INST_STATE_STOP ||
@@ -1554,8 +1555,10 @@ static void wave5_vpu_dec_stop_streaming
 			q_status.report_queue_count == 0)
 			break;
 
-		if (wave5_vpu_dec_get_output_info(inst, &dec_output_info))
-			dev_dbg(inst->dev->dev, "there is no output info\n");
+		if (time_after(jiffies, timeout))
+			break;
+
+		usleep_range(1000, 2000);
 	}
 
 	v4l2_m2m_update_stop_streaming_state(m2m_ctx, q);
--- a/drivers/media/platform/chips-media/wave5/wave5-vpuconfig.h
+++ b/drivers/media/platform/chips-media/wave5/wave5-vpuconfig.h
@@ -59,7 +59,7 @@
 //  application specific configuration
 #define VPU_ENC_TIMEOUT                 60000
 #define VPU_DEC_TIMEOUT                 60000
-#define VPU_DEC_STOP_TIMEOUT            10
+#define VPU_DEC_STOP_TIMEOUT            300
 
 // for WAVE encoder
 #define USE_SRC_PRP_AXI         0



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 413/556] media: chips-media: wave5: Defer job_finish() only when a DEC_PIC was queued
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (411 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 412/556] media: chips-media: wave5: Add timeout while stop_streaming Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 414/556] media: chips-media: wave5: Fix pipeline stall when queuing fails Greg Kroah-Hartman
                   ` (155 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jackson Lee, Nas Chung,
	Nicolas Dufresne, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jackson Lee <jackson.lee@chipsnmedia.com>

commit b694ba0a5526a69f78a6924982b1553154ccfd73 upstream.

Decoder instances sharing a VPU also share one v4l2_m2m job slot, released
when the running context calls v4l2_m2m_job_finish(). While draining,
device_run() defers job_finish() once EOS is sent (sent_eos), expecting a
later finish_decode() (from a DEC_PIC completion IRQ) to release the slot.

But the m2m core checks job_ready() only when a job is queued, not when it
is dispatched. A job queued while draining can run after finish_decode()
has already moved the instance to STOP and sent EOS. device_run() then runs
in STOP, issues no DEC_PIC, yet still skips job_finish() - so no IRQ, no
finish_decode(), and the shared slot is leaked, stalling every instance.
With several v4l2h264dec instances in parallel, GStreamer hangs at EOS.

Track whether the run actually queued a DEC_PIC (cmd_issued) and defer
job_finish() only then. Otherwise finish the job immediately

Fixes: a176ac5e701f ("media: chips-media: wave5: Improve performance of decoder")
Cc: stable@vger.kernel.org
Signed-off-by: Jackson Lee <jackson.lee@chipsnmedia.com>
Signed-off-by: Nas Chung <nas.chung@chipsnmedia.com>
Reviewed-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 .../media/platform/chips-media/wave5/wave5-vpu-dec.c | 12 +++++++++++-
 1 file changed, 11 insertions(+), 1 deletion(-)

diff --git a/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c b/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c
index 93f7b724d86c..f33c00cb801b 100644
--- a/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c
+++ b/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c
@@ -1655,6 +1655,7 @@ static void wave5_vpu_dec_device_run(void *priv)
 	struct queue_status_info q_status;
 	u32 fail_res = 0;
 	int ret = 0;
+	bool cmd_issued = false;
 
 	dev_dbg(inst->dev->dev, "%s: Fill the ring buffer with new bitstream data", __func__);
 	pm_runtime_resume_and_get(inst->dev->dev);
@@ -1752,6 +1753,7 @@ static void wave5_vpu_dec_device_run(void *priv)
 			inst->retry = false;
 			if (!inst->eos)
 				inst->queuing_num--;
+			cmd_issued = true;
 		}
 		break;
 	default:
@@ -1769,8 +1771,16 @@ static void wave5_vpu_dec_device_run(void *priv)
 	 * in power and CPU time.
 	 * If EOS is passed, device_run will not call job_finish no more, it is called
 	 * only if HW is idle status in order to reduce overhead.
+	 *
+	 * Deferring job_finish() is only safe when this run actually queued a
+	 * DEC_PIC command (cmd_issued): that guarantees a completion IRQ, and
+	 * thus a later finish_decode(), will release the shared job slot. When
+	 * device_run() is entered with no command to issue (e.g. a job that was
+	 * queued while draining but reached the STOP state by the time it ran),
+	 * no IRQ follows, so finish the job here to avoid leaking the slot and
+	 * stalling every instance sharing the VPU.
 	 */
-	if (!inst->sent_eos)
+	if (!inst->sent_eos || !cmd_issued)
 		v4l2_m2m_job_finish(inst->v4l2_m2m_dev, m2m_ctx);
 }
 
-- 
2.55.0




^ permalink raw reply related	[flat|nested] 570+ messages in thread

* [PATCH 7.2 414/556] media: chips-media: wave5: Fix pipeline stall when queuing fails
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (412 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 413/556] media: chips-media: wave5: Defer job_finish() only when a DEC_PIC was queued Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 415/556] media: chips-media: wave5: Resume device before setting EOS flag Greg Kroah-Hartman
                   ` (154 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jackson Lee, Nas Chung,
	Nicolas Dufresne, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jackson Lee <jackson.lee@chipsnmedia.com>

commit e3a80073d99c376176d81013335cd355af576be2 upstream.

The Wave5 decoder calls v4l2_m2m_job_finish() immediately in device_run()
after submitting frames to firmware. When the firmware completes those
frames and the queue drains to zero, finish_decode() has no active M2M
job to finish, so v4l2_m2m_schedule_next_job() is never called and the
decoder stalls.

Call v4l2_m2m_try_schedule() in finish_decode() when the firmware queue
empties to ensure the framework always schedules the next device_run().

Fixes: a176ac5e701f ("media: chips-media: wave5: Improve performance of decoder")
Cc: stable@vger.kernel.org
Signed-off-by: Jackson Lee <jackson.lee@chipsnmedia.com>
Signed-off-by: Nas Chung <nas.chung@chipsnmedia.com>
Reviewed-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c b/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c
index f33c00cb801b..1817b83c5884 100644
--- a/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c
+++ b/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c
@@ -475,7 +475,10 @@ static void wave5_vpu_dec_finish_decode(struct vpu_instance *inst)
 			v4l2_m2m_job_finish(inst->v4l2_m2m_dev, m2m_ctx);
 	}
 
-	inst->queuing_fail = false;
+	if (inst->queuing_fail) {
+		inst->queuing_fail = false;
+		v4l2_m2m_try_schedule(m2m_ctx);
+	}
 }
 
 static int wave5_vpu_dec_querycap(struct file *file, void *fh, struct v4l2_capability *cap)
-- 
2.55.0




^ permalink raw reply related	[flat|nested] 570+ messages in thread

* [PATCH 7.2 415/556] media: chips-media: wave5: Resume device before setting EOS flag
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (413 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 414/556] media: chips-media: wave5: Fix pipeline stall when queuing fails Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 416/556] scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers Greg Kroah-Hartman
                   ` (153 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Jackson Lee, Nas Chung,
	Nicolas Dufresne, Hans Verkuil

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jackson Lee <jackson.lee@chipsnmedia.com>

commit a52e6f7923c17a672135b485ffd96fbd72f46267 upstream.

Setting the EOS flag talks to the firmware via send_firmware_command(),
which accesses VPU registers. Both the STREAMOFF path
(wave5_vpu_dec_job_abort()) and the V4L2_DEC_CMD_STOP path
(wave5_vpu_dec_stop()) can run while the device is runtime suspended, so
those register accesses hit powered-down hardware and the SoC raises an
asynchronous SError, panicking the kernel:

  SError Interrupt on CPU3, code 0x00000000bf000000 -- SError
   send_firmware_command+0x2c/0x160 [wave5]
   wave5_vpu_dec_set_bitstream_flag+0x6c/0x80 [wave5]
   wave5_vpu_dec_update_bitstream_buffer+0x80/0xec [wave5]
   wave5_vpu_dec_job_abort+0x44/0xa0 [wave5]
   v4l2_m2m_cancel_job+0x110/0x19c [v4l2_mem2mem]
   v4l2_m2m_streamoff+0x24/0x140 [v4l2_mem2mem]

Resume the device with pm_runtime_resume_and_get() around the EOS
firmware command and release it with pm_runtime_put_autosuspend(),
matching the runtime PM handling already done in
wave5_vpu_dec_device_run().

Fixes: 9707a6254a8a ("media: chips-media: wave5: Add the v4l2 layer")
Cc: stable@vger.kernel.org
Signed-off-by: Jackson Lee <jackson.lee@chipsnmedia.com>
Signed-off-by: Nas Chung <nas.chung@chipsnmedia.com>
Reviewed-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Nicolas Dufresne <nicolas.dufresne@collabora.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c |   19 +++++++++++++++
 1 file changed, 19 insertions(+)

--- a/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c
+++ b/drivers/media/platform/chips-media/wave5/wave5-vpu-dec.c
@@ -823,7 +823,15 @@ static int wave5_vpu_dec_stop(struct vpu
 		 * calls do not block on a mutex while inside this spinlock.
 		 */
 		spin_unlock_irqrestore(&inst->state_spinlock, flags);
+		/*
+		 * V4L2_DEC_CMD_STOP can arrive while the device is runtime
+		 * suspended (e.g. on pipeline teardown). Setting the EOS flag
+		 * accesses VPU registers via send_firmware_command(), so the
+		 * device must be resumed first to avoid an asynchronous SError.
+		 */
+		pm_runtime_resume_and_get(inst->dev->dev);
 		ret = wave5_vpu_dec_set_eos_on_firmware(inst);
+		pm_runtime_put_autosuspend(inst->dev->dev);
 		if (ret)
 			return ret;
 
@@ -1797,11 +1805,22 @@ static void wave5_vpu_dec_job_abort(void
 	if (ret)
 		return;
 
+	/*
+	 * job_abort() runs from the STREAMOFF path and may be called while the
+	 * device is runtime suspended. Setting the EOS flag talks to the
+	 * firmware (send_firmware_command() accesses VPU registers), so the
+	 * device must be resumed first; otherwise the register access faults
+	 * with an asynchronous SError.
+	 */
+	pm_runtime_resume_and_get(inst->dev->dev);
+
 	ret = wave5_vpu_dec_set_eos_on_firmware(inst);
 	if (ret)
 		dev_warn(inst->dev->dev,
 			 "Setting EOS for the bitstream, fail: %d\n", ret);
 
+	pm_runtime_put_autosuspend(inst->dev->dev);
+
 	v4l2_m2m_job_finish(inst->v4l2_m2m_dev, m2m_ctx);
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 416/556] scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (414 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 415/556] media: chips-media: wave5: Resume device before setting EOS flag Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 417/556] scsi: qla2xxx: Bound i2c->length in I2C " Greg Kroah-Hartman
                   ` (152 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Nilesh Javali,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit b47d4a1547d9ef21b2e9d1a739fe2204d4be05dc upstream.

The FRU and I2C bsg handlers stage their transfer in a DMA_POOL_SIZE
(256-byte) bounce buffer obtained from dma_pool_alloc(), which does not
zero the allocation. They initialize only a few leading bytes before
handing the buffer to qla2x00_write_sfp().

qla2x00_write_sfp() can override the transfer length with a user-supplied
value:

	if (len == 1)
		opt |= BIT_0;
	if (opt & BIT_0)
		len = *sfp;

*sfp is the first byte of the (user-controlled) payload, so len can grow
up to 255. The device then DMA-reads len bytes from the 256-byte pool
buffer. Since only a small prefix was written
(e.g. MAX_FRU_SIZE == 36 bytes for a FRU version, one byte for a FRU
status register), the hardware reads past the initialized region and
writes up to ~219 bytes of stale DMA-pool heap memory to the device
flash.

Allocate the buffer with dma_pool_zalloc() in all five FRU/I2C handlers
so any bytes beyond the initialized data are zero rather than stale heap
contents.

Fixes: 697a4bc69159 ("[SCSI] qla2xxx: Provide method for updating I2C attached VPD.")
Fixes: 9ebb5d9c69f1 ("[SCSI] qla2xxx: Add I2C BSG interface.")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-dev@google.com>
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Link: https://patch.msgid.link/20260730155838.2119230-32-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_bsg.c |   10 +++++-----
 1 file changed, 5 insertions(+), 5 deletions(-)

--- a/drivers/scsi/qla2xxx/qla_bsg.c
+++ b/drivers/scsi/qla2xxx/qla_bsg.c
@@ -1567,7 +1567,7 @@ qla2x00_update_fru_versions(struct bsg_j
 	struct qla_image_version *image;
 	uint32_t count;
 	dma_addr_t sfp_dma;
-	void *sfp = dma_pool_alloc(ha->s_dma_pool, GFP_KERNEL, &sfp_dma);
+	void *sfp = dma_pool_zalloc(ha->s_dma_pool, GFP_KERNEL, &sfp_dma);
 
 	if (!sfp) {
 		bsg_reply->reply_data.vendor_reply.vendor_rsp[0] =
@@ -1618,7 +1618,7 @@ qla2x00_read_fru_status(struct bsg_job *
 	uint8_t bsg[DMA_POOL_SIZE];
 	struct qla_status_reg *sr = (void *)bsg;
 	dma_addr_t sfp_dma;
-	uint8_t *sfp = dma_pool_alloc(ha->s_dma_pool, GFP_KERNEL, &sfp_dma);
+	uint8_t *sfp = dma_pool_zalloc(ha->s_dma_pool, GFP_KERNEL, &sfp_dma);
 
 	if (!sfp) {
 		bsg_reply->reply_data.vendor_reply.vendor_rsp[0] =
@@ -1669,7 +1669,7 @@ qla2x00_write_fru_status(struct bsg_job
 	uint8_t bsg[DMA_POOL_SIZE];
 	struct qla_status_reg *sr = (void *)bsg;
 	dma_addr_t sfp_dma;
-	uint8_t *sfp = dma_pool_alloc(ha->s_dma_pool, GFP_KERNEL, &sfp_dma);
+	uint8_t *sfp = dma_pool_zalloc(ha->s_dma_pool, GFP_KERNEL, &sfp_dma);
 
 	if (!sfp) {
 		bsg_reply->reply_data.vendor_reply.vendor_rsp[0] =
@@ -1716,7 +1716,7 @@ qla2x00_write_i2c(struct bsg_job *bsg_jo
 	uint8_t bsg[DMA_POOL_SIZE];
 	struct qla_i2c_access *i2c = (void *)bsg;
 	dma_addr_t sfp_dma;
-	uint8_t *sfp = dma_pool_alloc(ha->s_dma_pool, GFP_KERNEL, &sfp_dma);
+	uint8_t *sfp = dma_pool_zalloc(ha->s_dma_pool, GFP_KERNEL, &sfp_dma);
 
 	if (!sfp) {
 		bsg_reply->reply_data.vendor_reply.vendor_rsp[0] =
@@ -1762,7 +1762,7 @@ qla2x00_read_i2c(struct bsg_job *bsg_job
 	uint8_t bsg[DMA_POOL_SIZE];
 	struct qla_i2c_access *i2c = (void *)bsg;
 	dma_addr_t sfp_dma;
-	uint8_t *sfp = dma_pool_alloc(ha->s_dma_pool, GFP_KERNEL, &sfp_dma);
+	uint8_t *sfp = dma_pool_zalloc(ha->s_dma_pool, GFP_KERNEL, &sfp_dma);
 
 	if (!sfp) {
 		bsg_reply->reply_data.vendor_reply.vendor_rsp[0] =



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 417/556] scsi: qla2xxx: Bound i2c->length in I2C bsg handlers
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (415 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 416/556] scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 418/556] scsi: qla2xxx: edif: Fix NULL pointer deref in RX SA delete check Greg Kroah-Hartman
                   ` (151 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Nilesh Javali,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit 0918ee2c0eeb4d7f45b82b3dc11e65c2d9b7ad59 upstream.

struct qla_i2c_access carries a 16-bit length field alongside a fixed
64-byte buffer:

	struct qla_i2c_access {
		uint16_t device, offset, option, length;
		uint8_t  buffer[0x40];
	} __packed;

qla2x00_write_i2c() and qla2x00_read_i2c() use the user-supplied
i2c->length without any bounds check. i2c is overlaid on a 256-byte
on-stack buffer and sfp is a 256-byte DMA-pool buffer, so a length up to
65535 overruns both:

  - write: memcpy(sfp, i2c->buffer, i2c->length) over-reads the stack and
    over-writes the sfp heap buffer, and qla2x00_write_sfp() then DMAs
    i2c->length bytes out of the 256-byte buffer.
  - read: qla2x00_read_sfp() DMAs i2c->length bytes into the 256-byte sfp,
    then memcpy(i2c->buffer, sfp, i2c->length) overflows the 64-byte
    buffer inside the on-stack array.

A caller holding CAP_SYS_RAWIO can use this to corrupt the heap and the
kernel stack. Reject requests whose length exceeds the buffer before any
copy or DMA transfer in both handlers.

Fixes: 9ebb5d9c69f1 ("[SCSI] qla2xxx: Add I2C BSG interface.")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-dev@google.com>
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Link: https://patch.msgid.link/20260730155838.2119230-33-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_bsg.c |   12 ++++++++++++
 1 file changed, 12 insertions(+)

--- a/drivers/scsi/qla2xxx/qla_bsg.c
+++ b/drivers/scsi/qla2xxx/qla_bsg.c
@@ -1727,6 +1727,12 @@ qla2x00_write_i2c(struct bsg_job *bsg_jo
 	sg_copy_to_buffer(bsg_job->request_payload.sg_list,
 	    bsg_job->request_payload.sg_cnt, i2c, sizeof(*i2c));
 
+	if (i2c->length > sizeof(i2c->buffer)) {
+		bsg_reply->reply_data.vendor_reply.vendor_rsp[0] =
+		    EXT_STATUS_INVALID_PARAM;
+		goto dealloc;
+	}
+
 	memcpy(sfp, i2c->buffer, i2c->length);
 	rval = qla2x00_write_sfp(vha, sfp_dma, sfp,
 	    i2c->device, i2c->offset, i2c->length, i2c->option);
@@ -1773,6 +1779,12 @@ qla2x00_read_i2c(struct bsg_job *bsg_job
 	sg_copy_to_buffer(bsg_job->request_payload.sg_list,
 	    bsg_job->request_payload.sg_cnt, i2c, sizeof(*i2c));
 
+	if (i2c->length > sizeof(i2c->buffer)) {
+		bsg_reply->reply_data.vendor_reply.vendor_rsp[0] =
+		    EXT_STATUS_INVALID_PARAM;
+		goto dealloc;
+	}
+
 	rval = qla2x00_read_sfp(vha, sfp_dma, sfp,
 		i2c->device, i2c->offset, i2c->length, i2c->option);
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 418/556] scsi: qla2xxx: edif: Fix NULL pointer deref in RX SA delete check
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (416 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 417/556] scsi: qla2xxx: Bound i2c->length in I2C " Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 419/556] scsi: qla2xxx: Fix Name Server logout detection on FWI2 adapters Greg Kroah-Hartman
                   ` (150 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Nilesh Javali, Hannes Reinecke,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit c20ee380ca59c5a8646750c4849969a815924e2e upstream.

qla_chk_edif_rx_sa_delete_pending() obtains the SCSI command via
GET_CMD_SP(sp) and immediately dereferences cmd->sc_data_direction.
That command pointer can be NULL: the firmware may post a status
completion for a command that has already been returned or aborted.  The
caller qla2x00_status_entry() acknowledges this on the very same status
path, re-fetching GET_CMD_SP(sp) and bailing out with the "Command
already returned" message when it is NULL -- but that check runs only
after qla_chk_edif_rx_sa_delete_pending() has already dereferenced the
pointer, so a NULL cmd crashes the kernel in interrupt context.

Return early when cmd is NULL, before touching cmd->sc_data_direction.

Fixes: dd30706e73b7 ("scsi: qla2xxx: edif: Add key update")
Cc: stable@vger.kernel.org
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Link: https://patch.msgid.link/20260723050413.3897522-47-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_edif.c |    3 +++
 1 file changed, 3 insertions(+)

--- a/drivers/scsi/qla2xxx/qla_edif.c
+++ b/drivers/scsi/qla2xxx/qla_edif.c
@@ -3492,6 +3492,9 @@ void qla_chk_edif_rx_sa_delete_pending(s
 	struct scsi_cmnd *cmd = GET_CMD_SP(sp);
 	uint32_t handle;
 
+	if (!cmd)
+		return;
+
 	handle = (uint32_t)LSW(sts24->handle);
 
 	/* find out if this status iosb is for a scsi read */



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 419/556] scsi: qla2xxx: Fix Name Server logout detection on FWI2 adapters
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (417 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 418/556] scsi: qla2xxx: edif: Fix NULL pointer deref in RX SA delete check Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 420/556] scsi: qla2xxx: Fix BSG job leak on validate flash image error path Greg Kroah-Hartman
                   ` (149 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Nilesh Javali, Hannes Reinecke,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit eb137255fd7aa834c4d639ae7b5e9e8ecf3a4fb2 upstream.

In the CS_PORT_LOGGED_OUT case of qla2x00_chk_ms_status(), the
FWI2-capable branch compared ms_pkt->loop_id.extended against NPH_SNS to
decide whether the Name Server had logged out. On FWI2 and later
adapters the response is a ct_entry_24xx / ct_entry_24xx_ext, where
loop_id.extended (via the legacy ms_iocb_entry_t view) aliases offset 8,
which is comp_status, not nport_handle (offset 10). As this code runs
under CS_PORT_LOGGED_OUT, the field read back 0x29 (CS_PORT_LOGGED_OUT)
and the comparison against NPH_SNS (0x7fc) was always false.

As a result the driver never recognized a Name Server logout on FWI2/
29xx adapters: it returned the generic QLA_FUNCTION_FAILED instead of
QLA_NOT_LOGGED_IN and skipped setting LOOP_RESYNC_NEEDED /
LOCAL_LOOP_UPDATE, so the fabric rediscovery triggered by an SNS logout
did not happen.

Read nport_handle from the ct_entry_24xx layout (offset 10) instead.
nport_handle is at the same offset in ct_entry_24xx and
ct_entry_24xx_ext, so a single cast covers 24xx-class and 29xx. The
non-FWI2 branch keeps using loop_id.extended, which is correct for the
ms_iocb_entry_t response on those adapters.

Fixes: b98ae0d748db ("scsi: qla2xxx: Fix name server relogin")
Cc: stable@vger.kernel.org
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Link: https://patch.msgid.link/20260723050413.3897522-48-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_gs.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/drivers/scsi/qla2xxx/qla_gs.c
+++ b/drivers/scsi/qla2xxx/qla_gs.c
@@ -157,8 +157,8 @@ qla2x00_chk_ms_status(scsi_qla_host_t *v
 			break;
 		case CS_PORT_LOGGED_OUT:
 			if (IS_FWI2_CAPABLE(ha)) {
-				if (le16_to_cpu(ms_pkt->loop_id.extended) ==
-				    NPH_SNS)
+				if (le16_to_cpu(((struct ct_entry_24xx *)
+				    ms_pkt)->nport_handle) == NPH_SNS)
 					lid_is_sns = true;
 			} else {
 				if (le16_to_cpu(ms_pkt->loop_id.extended) ==



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 420/556] scsi: qla2xxx: Fix BSG job leak on validate flash image error path
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (418 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 419/556] scsi: qla2xxx: Fix Name Server logout detection on FWI2 adapters Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 421/556] scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition() Greg Kroah-Hartman
                   ` (148 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Nilesh Javali, Hannes Reinecke,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit 0fb52cc632464b0cd07f970341330466d772efe1 upstream.

qla28xx_validate_flash_image() returns QLA_SUCCESS (0) unconditionally,
telling the FC BSG transport (fc_bsg_host_dispatch()) that the driver
owns and will complete the request. But bsg_job_done() is guarded by "if
(!rval)", so on the error path (rval == -EINVAL) neither the driver nor
the transport completes the job. The request dangles until it times out,
leaking block layer resources.

Commit c2c68225b145 ("scsi: qla2xxx: Fix bsg_done() causing double
free") added the "if (!rval)" guard to a batch of BSG handlers. That is
correct for handlers that also return the error code (the transport then
completes the job once via fail_host_msg), but this function returns
QLA_SUCCESS unconditionally, so the guard turned a correct single
completion into a leak.

Always call bsg_job_done(): bsg_reply->result is DID_OK and the error is
reported in vendor_rsp[0], and since the function returns 0 the
transport will not complete the job a second time.

Fixes: c2c68225b145 ("scsi: qla2xxx: Fix bsg_done() causing double free")
Cc: stable@vger.kernel.org
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Link: https://patch.msgid.link/20260723050413.3897522-55-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_bsg.c |    5 ++---
 1 file changed, 2 insertions(+), 3 deletions(-)

--- a/drivers/scsi/qla2xxx/qla_bsg.c
+++ b/drivers/scsi/qla2xxx/qla_bsg.c
@@ -3377,9 +3377,8 @@ static int qla28xx_validate_flash_image(
 	bsg_reply->result = DID_OK << 16;
 	bsg_reply->reply_payload_rcv_len = 0;
 	bsg_job->reply_len = sizeof(struct fc_bsg_reply);
-	if (!rval)
-		bsg_job_done(bsg_job, bsg_reply->result,
-			     bsg_reply->reply_payload_rcv_len);
+	bsg_job_done(bsg_job, bsg_reply->result,
+		     bsg_reply->reply_payload_rcv_len);
 
 	return QLA_SUCCESS;
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 421/556] scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (419 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 420/556] scsi: qla2xxx: Fix BSG job leak on validate flash image error path Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 422/556] scsi: qla2xxx: Initialize NVMe abort_work once at submission Greg Kroah-Hartman
                   ` (147 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Nilesh Javali, Hannes Reinecke,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit 793cedee296fd819bfadc2a7ec4d52faf9c09a0a upstream.

In the format 1 path, the virtual port is located on ha->vp_list while
holding vport_slock, but the lock is dropped before vp is used:
qla_update_host_map() is called and VP_IDX_ACQUIRED/REGISTER_FC4_NEEDED/
REGISTER_FDMI_NEEDED are set on vp. No reference is taken across that
window, so a concurrent qla24xx_deallocate_vp_id() can tear the vport
down and free it, leading to a use-after-free.

Take a vport reference (vref_count) under vport_slock when the matching
vp is found, and drop it after the last use of
vp. qla24xx_deallocate_vp_id() waits for vref_count to reach zero before
unlinking and freeing the vport, so the pointer stays valid. This
matches the reference idiom already used by the other ha->vp_list
traversals.

Fixes: 2c3dfe3f6ad8 ("[SCSI] qla2xxx: add support for NPIV")
Cc: stable@vger.kernel.org
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Link: https://patch.msgid.link/20260723050413.3897522-51-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_mbx.c |    3 +++
 1 file changed, 3 insertions(+)

--- a/drivers/scsi/qla2xxx/qla_mbx.c
+++ b/drivers/scsi/qla2xxx/qla_mbx.c
@@ -4203,6 +4203,7 @@ qla24xx_report_id_acquisition(scsi_qla_h
 			list_for_each_entry(vp, &ha->vp_list, list) {
 				if (rptid_entry->vp_idx == vp->vp_idx) {
 					found = 1;
+					atomic_inc(&vp->vref_count);
 					break;
 				}
 			}
@@ -4220,6 +4221,8 @@ qla24xx_report_id_acquisition(scsi_qla_h
 			set_bit(VP_IDX_ACQUIRED, &vp->vp_flags);
 			set_bit(REGISTER_FC4_NEEDED, &vp->dpc_flags);
 			set_bit(REGISTER_FDMI_NEEDED, &vp->dpc_flags);
+
+			atomic_dec(&vp->vref_count);
 		}
 		set_bit(VP_DPC_NEEDED, &vha->dpc_flags);
 		qla2xxx_wake_dpc(vha);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 422/556] scsi: qla2xxx: Initialize NVMe abort_work once at submission
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (420 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 421/556] scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition() Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 423/556] scsi: qla2xxx: Check entry_status in qla24xx_modify_vp_config() Greg Kroah-Hartman
                   ` (146 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Nilesh Javali, Hannes Reinecke,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit 7e85f6dbc85616de2172bce8eaf84b387a723cd1 upstream.

qla_nvme_fcp_abort() and qla_nvme_ls_abort() ran INIT_WORK() on
priv->abort_work immediately before schedule_work(). INIT_WORK()
reinitializes the work_struct, resetting its list head and clearing the
pending bit. If an abort is issued more than once for the same command
(for example, concurrent transport teardown and a timeout-driven abort),
the second INIT_WORK() reinitializes a work item that is already queued,
which can corrupt the workqueue list and lead to crashes or a looping
worker.

Initialize priv->abort_work once at command submission, next to the
existing per-command spin_lock_init(&priv->cmd_lock), and leave only
schedule_work() in the abort paths. schedule_work() already does nothing
when the work item is still pending, so a repeated abort no longer
disturbs an in-flight work item. The command is not returned to the
transport until the final kref_put()/release callback runs after
abort_work has completed, so the work item is idle before priv is reused
and the single submission-time INIT_WORK() is safe.

Fixes: e473b3074104 ("scsi: qla2xxx: Add FC-NVMe abort processing")
Cc: stable@vger.kernel.org
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Link: https://patch.msgid.link/20260723050413.3897522-52-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_nvme.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/drivers/scsi/qla2xxx/qla_nvme.c
+++ b/drivers/scsi/qla2xxx/qla_nvme.c
@@ -463,7 +463,6 @@ static void qla_nvme_ls_abort(struct nvm
 	}
 	spin_unlock_irqrestore(&priv->cmd_lock, flags);
 
-	INIT_WORK(&priv->abort_work, qla_nvme_abort_work);
 	schedule_work(&priv->abort_work);
 }
 
@@ -501,6 +500,7 @@ static int qla_nvme_ls_req(struct nvme_f
 	priv->sp = sp;
 	kref_init(&sp->cmd_kref);
 	spin_lock_init(&priv->cmd_lock);
+	INIT_WORK(&priv->abort_work, qla_nvme_abort_work);
 	nvme = &sp->u.iocb_cmd;
 	priv->fd = fd;
 	nvme->u.nvme.desc = fd;
@@ -545,7 +545,6 @@ static void qla_nvme_fcp_abort(struct nv
 	}
 	spin_unlock_irqrestore(&priv->cmd_lock, flags);
 
-	INIT_WORK(&priv->abort_work, qla_nvme_abort_work);
 	schedule_work(&priv->abort_work);
 }
 
@@ -811,6 +810,7 @@ static int qla_nvme_post_cmd(struct nvme
 
 	kref_init(&sp->cmd_kref);
 	spin_lock_init(&priv->cmd_lock);
+	INIT_WORK(&priv->abort_work, qla_nvme_abort_work);
 	sp->priv = priv;
 	priv->sp = sp;
 	sp->type = SRB_NVME_CMD;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 423/556] scsi: qla2xxx: Check entry_status in qla24xx_modify_vp_config()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (421 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 422/556] scsi: qla2xxx: Initialize NVMe abort_work once at submission Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 424/556] scsi: qla2xxx: Zero dport diagnostics buffer to avoid info leak Greg Kroah-Hartman
                   ` (145 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Nilesh Javali, Hannes Reinecke,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit 9101c51649f5b6773a97bf5271785c948589ea1d upstream.

The Modify VP Config completion handler labelled its first error branch
"error status" but tested vpmod->comp_status instead of
vpmod->entry_status. Because CS_COMPLETE is 0, the following
"comp_status != CS_COMPLETE" branch duplicated that test and was dead
code, and entry_status was never examined at all.

When firmware rejects the IOCB early it sets entry_status while leaving
comp_status zero. As the IOCB is allocated with dma_pool_zalloc(), both
comp_status branches evaluate false and the handler falls through to the
success path, calling fc_vport_set_state(FC_VPORT_INITIALIZING) for a
configuration the firmware never accepted. This can leave the virtual
port enabled on top of an invalid config and surface later as login
timeouts or follow-on firmware errors.

Test entry_status in the first branch, matching qla_ctrlvp_completed()
and the login/logout/abort/reset IOCB handlers; the comp_status branch
then becomes the live completion-status check.

Fixes: 2c3dfe3f6ad8 ("[SCSI] qla2xxx: add support for NPIV")
Cc: stable@vger.kernel.org
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Link: https://patch.msgid.link/20260723050413.3897522-50-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_mbx.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/drivers/scsi/qla2xxx/qla_mbx.c
+++ b/drivers/scsi/qla2xxx/qla_mbx.c
@@ -4333,10 +4333,10 @@ qla24xx_modify_vp_config(scsi_qla_host_t
 	if (rval != QLA_SUCCESS) {
 		ql_dbg(ql_dbg_mbx, vha, 0x10bd,
 		    "Failed to issue VP config IOCB (%x).\n", rval);
-	} else if (vpmod->comp_status != 0) {
+	} else if (vpmod->entry_status != 0) {
 		ql_dbg(ql_dbg_mbx, vha, 0x10be,
 		    "Failed to complete IOCB -- error status (%x).\n",
-		    vpmod->comp_status);
+		    vpmod->entry_status);
 		rval = QLA_FUNCTION_FAILED;
 	} else if (vpmod->comp_status != cpu_to_le16(CS_COMPLETE)) {
 		ql_dbg(ql_dbg_mbx, vha, 0x10bf,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 424/556] scsi: qla2xxx: Zero dport diagnostics buffer to avoid info leak
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (422 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 423/556] scsi: qla2xxx: Check entry_status in qla24xx_modify_vp_config() Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 425/556] scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions() Greg Kroah-Hartman
                   ` (144 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Nilesh Javali, Hannes Reinecke,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit a152edab3854f01dd2daf3eaf8f32cbabdb3834e upstream.

qla2x00_do_dport_diagnostics() allocates the qla_dport_diag response
buffer with kmalloc_obj() (non-zeroing) and, on success, copies the full
sizeof(*dd) back to user space via sg_copy_from_buffer(). The inbound
sg_copy_to_buffer() only fills as many bytes as the user request payload
provides, and qla26xx_dport_diagnostics() zeroes only dd->buf. The
options and unused[] fields are therefore copied out uninitialized,
leaking kernel heap contents to user space.

Allocate with kzalloc_obj(), matching qla2x00_do_dport_diagnostics_v2().

Fixes: ec89146215d1 ("qla2xxx: Add bsg interface to support D_Port Diagnostics.")
Cc: stable@vger.kernel.org
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Link: https://patch.msgid.link/20260723050413.3897522-54-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_bsg.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/scsi/qla2xxx/qla_bsg.c
+++ b/drivers/scsi/qla2xxx/qla_bsg.c
@@ -2407,7 +2407,7 @@ qla2x00_do_dport_diagnostics(struct bsg_
 	    !IS_QLA28XX(vha->hw))
 		return -EPERM;
 
-	dd = kmalloc_obj(*dd);
+	dd = kzalloc_obj(*dd);
 	if (!dd) {
 		ql_log(ql_log_warn, vha, 0x70db,
 		    "Failed to allocate memory for dport.\n");



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 425/556] scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (423 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 424/556] scsi: qla2xxx: Zero dport diagnostics buffer to avoid info leak Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 426/556] scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject Greg Kroah-Hartman
                   ` (143 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Nilesh Javali, Hannes Reinecke,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit de62cf265dbe309f34f144a6cdbca9240317727e upstream.

qla2x00_update_fru_versions() copies the user-supplied BSG request into
a fixed 256-byte stack buffer (bsg[DMA_POOL_SIZE]) and then iterates
list->count times over the qla_image_version array embedded in that
buffer, advancing the image pointer each iteration. count is taken
directly from user input with no upper bound, while only (DMA_POOL_SIZE
- sizeof(list->count)) / sizeof(struct qla_image_version) = 6 entries
actually fit. A larger count walks the image pointer off the end of the
stack buffer, reading adjacent kernel stack memory and sending it to the
device via qla2x00_write_sfp().

Reject requests whose declared count does not fit in the buffer.

Fixes: 697a4bc69159 ("[SCSI] qla2xxx: Provide method for updating I2C attached VPD.")
Cc: stable@vger.kernel.org
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Link: https://patch.msgid.link/20260723050413.3897522-56-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_bsg.c |    7 +++++++
 1 file changed, 7 insertions(+)

--- a/drivers/scsi/qla2xxx/qla_bsg.c
+++ b/drivers/scsi/qla2xxx/qla_bsg.c
@@ -1580,6 +1580,13 @@ qla2x00_update_fru_versions(struct bsg_j
 
 	image = list->version;
 	count = list->count;
+
+	if (struct_size(list, version, count) > sizeof(bsg)) {
+		bsg_reply->reply_data.vendor_reply.vendor_rsp[0] =
+		    EXT_STATUS_INVALID_PARAM;
+		goto dealloc;
+	}
+
 	while (count--) {
 		memcpy(sfp, &image->field_info, sizeof(image->field_info));
 		rval = qla2x00_write_sfp(vha, sfp_dma, sfp,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 426/556] scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (424 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 425/556] scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions() Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 427/556] scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation Greg Kroah-Hartman
                   ` (142 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Nilesh Javali, Hannes Reinecke,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit f743488e4a203049f27ec5d8cd0caccc483af01e upstream.

qla_nvme_ls_reject_iocb() allocates from and advances the request ring
through __qla2x00_alloc_iocbs() (which assumes the hardware_lock is
held) and qla2x00_start_iocbs() (which advances the ring and rings the
request-in doorbell), but takes no lock itself. Two of its callers
invoke it without the producer lock held:

 - qla_nvme_xmt_ls_rsp(), the NVMe-FC .xmt_ls_rsp transport callback, on
   its error path, and

 - qla2xxx_process_purls_pkt(), run from the purex work/DPC context.

Both use ha->base_qpair, whose qp_lock_ptr is hardware_lock, so they can
run concurrently with normal I/O submission on the base ring and corrupt
the ring producer state, leading to duplicated or dropped commands. The
third caller, qla2xxx_process_purls_iocb(), runs inside
qla24xx_process_response_queue() with the qpair lock already held and is
safe; that is also why the lock cannot be taken inside the helper itself
(it would recursively re-acquire hardware_lock on the response path).

Take qp_lock_ptr around the two unlocked callers and document the helper
as caller-locked. Both run in process context, so spin_lock_irqsave() is
used and nothing in the locked region sleeps.

Fixes: 875386b98857 ("scsi: qla2xxx: Add Unsolicited LS Request and Response Support for NVMe")
Cc: stable@vger.kernel.org
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Link: https://patch.msgid.link/20260723050413.3897522-53-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_nvme.c |   10 ++++++++++
 1 file changed, 10 insertions(+)

--- a/drivers/scsi/qla2xxx/qla_nvme.c
+++ b/drivers/scsi/qla2xxx/qla_nvme.c
@@ -374,6 +374,7 @@ static int qla_nvme_xmt_ls_rsp(struct nv
 	srb_t *sp;
 	int rval = QLA_FUNCTION_FAILED;
 	uint8_t cnt = 0;
+	unsigned long flags;
 
 	if (!fcport || fcport->deleted)
 		goto out;
@@ -440,7 +441,9 @@ out:
 	a.vp_idx = vha->vp_idx;
 	a.nport_handle = uctx->nport_handle;
 	a.xchg_address = uctx->exchange_address;
+	spin_lock_irqsave(ha->base_qpair->qp_lock_ptr, flags);
 	qla_nvme_ls_reject_iocb(vha, ha->base_qpair, &a, true);
+	spin_unlock_irqrestore(ha->base_qpair->qp_lock_ptr, flags);
 	kfree(uctx);
 	return rval;
 }
@@ -1127,6 +1130,10 @@ static void qla_nvme_lsrjt_pt_iocb(struc
 	lsrjt_iocb->rx_byte_count = 0;
 }
 
+/*
+ * Allocates from and advances the request ring, so the caller must hold
+ * qp->qp_lock_ptr (the response-queue caller already holds it).
+ */
 static int
 qla_nvme_ls_reject_iocb(struct scsi_qla_host *vha, struct qla_qpair *qp,
 			struct qla_nvme_lsrjt_pt_arg *a, bool is_xchg_terminate)
@@ -1183,6 +1190,7 @@ qla2xxx_process_purls_pkt(struct scsi_ql
 {
 	struct qla_nvme_unsol_ctx *uctx = item->purls_context;
 	struct qla_nvme_lsrjt_pt_arg a;
+	unsigned long flags;
 	int ret = 1;
 
 #if (IS_ENABLED(CONFIG_NVME_FC))
@@ -1195,7 +1203,9 @@ qla2xxx_process_purls_pkt(struct scsi_ql
 		a.vp_idx = vha->vp_idx;
 		a.nport_handle = uctx->nport_handle;
 		a.xchg_address = uctx->exchange_address;
+		spin_lock_irqsave(vha->hw->base_qpair->qp_lock_ptr, flags);
 		qla_nvme_ls_reject_iocb(vha, vha->hw->base_qpair, &a, true);
+		spin_unlock_irqrestore(vha->hw->base_qpair->qp_lock_ptr, flags);
 		list_del(&uctx->elem);
 		kfree(uctx);
 	}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 427/556] scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (425 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 426/556] scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 428/556] scsi: qla2xxx: Serialize flash version read in reset handler Greg Kroah-Hartman
                   ` (141 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Nilesh Javali,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit ebfd35c64433821bd5619a6d07ccc2df8b5b1de3 upstream.

ha->msix_count is u16, but ha->max_req_queues, ha->max_rsp_queues and
ha->max_qpairs are u8. Deriving the queue count as
"ha->max_req_queues = ha->msix_count - 1" therefore truncates: a board
(or a misconfigured/malicious hot-plugged device) advertising 257 MSI-X
vectors yields msix_count - 1 == 256, which truncates to 0. An MSI-X
count of 1 zeroes it as well, and in target mode the subsequent
"ha->max_req_queues--" then underflows 0 to 255.

When the count is 0, qla2x00_alloc_queues() calls
kzalloc_objs(struct req_que *, 0), which returns ZERO_SIZE_PTR. That is
not NULL, so the allocation check passes and the following
"ha->req_q_map[0] = req" dereferences ZERO_SIZE_PTR, corrupting memory
or crashing the kernel.

Add qla_calc_queue_count() to clamp the derived value into
[1, QLA_MAX_QUEUES - 1] so it always fits in u8 and is never zero, and
use it at all three derivation sites (qla25xx_iospace_config(),
qla83xx_iospace_config() and qla24xx_enable_msix()). Also guard the
target-mode decrement so it cannot reintroduce a zero (which would in
turn underflow max_qpairs).

Fixes: d74595278f4a ("scsi: qla2xxx: Add multiple queue pair functionality.")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-dev@google.com>
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Link: https://patch.msgid.link/20260730155838.2119230-2-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_inline.h |   13 +++++++++++++
 drivers/scsi/qla2xxx/qla_isr.c    |    4 ++--
 drivers/scsi/qla2xxx/qla_os.c     |    6 +++---
 3 files changed, 18 insertions(+), 5 deletions(-)

--- a/drivers/scsi/qla2xxx/qla_inline.h
+++ b/drivers/scsi/qla2xxx/qla_inline.h
@@ -54,6 +54,19 @@ qla2x00_debounce_register(volatile __le1
 	return (first);
 }
 
+static inline u8
+qla_calc_queue_count(u16 msix_count)
+{
+	/*
+	 * Request/response queues are bounded by the MSI-X vector count less
+	 * the mailbox vector.  These counters are u8, so a board advertising
+	 * e.g. 257 vectors would truncate msix_count - 1 (256) to 0 and hand
+	 * kzalloc_objs() a zero count (ZERO_SIZE_PTR), faulting on the first
+	 * ha->req_q_map[0] store.  Clamp into [1, QLA_MAX_QUEUES - 1].
+	 */
+	return clamp_t(u16, msix_count - 1, 1, QLA_MAX_QUEUES - 1);
+}
+
 static inline void
 qla2x00_poll(struct rsp_que *rsp)
 {
--- a/drivers/scsi/qla2xxx/qla_isr.c
+++ b/drivers/scsi/qla2xxx/qla_isr.c
@@ -4548,10 +4548,10 @@ qla24xx_enable_msix(struct qla_hw_data *
 		ha->msix_count = ret;
 		/* Recalculate queue values */
 		if (ha->mqiobase && (ql2xmqsupport || ql2xnvmeenable)) {
-			ha->max_req_queues = ha->msix_count - 1;
+			ha->max_req_queues = qla_calc_queue_count(ha->msix_count);
 
 			/* ATIOQ needs 1 vector. That's 1 less QPair */
-			if (QLA_TGT_MODE_ENABLED())
+			if (QLA_TGT_MODE_ENABLED() && ha->max_req_queues > 1)
 				ha->max_req_queues--;
 
 			ha->max_rsp_queues = ha->max_req_queues;
--- a/drivers/scsi/qla2xxx/qla_os.c
+++ b/drivers/scsi/qla2xxx/qla_os.c
@@ -2127,7 +2127,7 @@ skip_pio:
 		ha->msix_count = msix + 1;
 		/* Max queues are bounded by available msix vectors */
 		/* MB interrupt uses 1 vector */
-		ha->max_req_queues = ha->msix_count - 1;
+		ha->max_req_queues = qla_calc_queue_count(ha->msix_count);
 		ha->max_rsp_queues = ha->max_req_queues;
 		/* Queue pairs is the max value minus the base queue pair */
 		ha->max_qpairs = ha->max_rsp_queues - 1;
@@ -2213,10 +2213,10 @@ qla83xx_iospace_config(struct qla_hw_dat
 		 */
 		if (ql2xmqsupport || ql2xnvmeenable) {
 			/* MB interrupt uses 1 vector */
-			ha->max_req_queues = ha->msix_count - 1;
+			ha->max_req_queues = qla_calc_queue_count(ha->msix_count);
 
 			/* ATIOQ needs 1 vector. That's 1 less QPair */
-			if (QLA_TGT_MODE_ENABLED())
+			if (QLA_TGT_MODE_ENABLED() && ha->max_req_queues > 1)
 				ha->max_req_queues--;
 
 			ha->max_rsp_queues = ha->max_req_queues;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 428/556] scsi: qla2xxx: Serialize flash version read in reset handler
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (426 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 427/556] scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 429/556] scsi: qla2xxx: Fix cs84xx use-after-free on host teardown Greg Kroah-Hartman
                   ` (140 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Nilesh Javali,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit f606ed93de0c4f1e7e3618779e9fad731455314a upstream.

The "update cache versions without reset" sysfs reset operation (0x20261)
calls get_flash_version(), which reads hardware flash registers, without
holding ha->optrom_mutex. The VPD update path serializes the same call
under optrom_mutex, so this reset path can interleave its flash register
accesses with a concurrent VPD or optrom flash operation and corrupt the
reads.

Hold ha->optrom_mutex across the get_flash_version() call to match the
VPD update path.

Fixes: 8c2cf7d4e387 ("[SCSI] qla2xxx: Add a new interface to update versions.")
Reported-by: Sashiko <sashiko-dev@google.com>
Cc: stable@vger.kernel.org
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Link: https://patch.msgid.link/20260730155838.2119230-4-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_attr.c |    2 ++
 1 file changed, 2 insertions(+)

--- a/drivers/scsi/qla2xxx/qla_attr.c
+++ b/drivers/scsi/qla2xxx/qla_attr.c
@@ -816,7 +816,9 @@ qla2x00_sysfs_write_reset(struct file *f
 			    "Unable to allocate memory for VPD information update.\n");
 			return -ENOMEM;
 		}
+		mutex_lock(&ha->optrom_mutex);
 		ha->isp_ops->get_flash_version(vha, tmp_data);
+		mutex_unlock(&ha->optrom_mutex);
 		vfree(tmp_data);
 		break;
 	}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 429/556] scsi: qla2xxx: Fix cs84xx use-after-free on host teardown
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (427 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 428/556] scsi: qla2xxx: Serialize flash version read in reset handler Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 430/556] scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump Greg Kroah-Hartman
                   ` (139 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Nilesh Javali,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit 33d102102d925357c5fd172dd6672a27d74b3215 upstream.

qla84xx_put_chip() drops the last reference to ha->cs84xx and frees it via
__qla84xx_chip_release() without clearing ha->cs84xx. During teardown it ran
before scsi_remove_host(), which is what removes the 84xx_fw_version host
sysfs attribute. A concurrent read of that attribute in the window between
the two calls executes qla24xx_84xx_fw_version_show(), which dereferences
the freed ha->cs84xx, resulting in a use-after-free.

Move qla84xx_put_chip() to after scsi_remove_host() in both
qla2x00_remove_one() and qla2x00_disable_board_on_pci_error(). Once
scsi_remove_host() returns, the sysfs attribute is gone and kernfs has
drained any in-flight show(), so no reader can touch cs84xx; the put still
runs before the host and ha are freed.

Fixes: fe1b806f4f71 ("[SCSI] qla2xxx: Refactor shutdown code so some functionality can be reused.")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-dev@google.com>
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Link: https://patch.msgid.link/20260730155838.2119230-7-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_os.c |    8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

--- a/drivers/scsi/qla2xxx/qla_os.c
+++ b/drivers/scsi/qla2xxx/qla_os.c
@@ -3933,8 +3933,6 @@ qla2x00_remove_one(struct pci_dev *pdev)
 
 	qla2x00_dfs_remove(base_vha);
 
-	qla84xx_put_chip(base_vha);
-
 	/* Disable timer */
 	if (base_vha->timer_active)
 		qla2x00_stop_timer(base_vha);
@@ -3959,6 +3957,8 @@ qla2x00_remove_one(struct pci_dev *pdev)
 
 	scsi_remove_host(base_vha->host);
 
+	qla84xx_put_chip(base_vha);
+
 	qla2x00_free_device(base_vha);
 
 	qla2x00_clear_drv_active(ha);
@@ -6828,8 +6828,6 @@ qla2x00_disable_board_on_pci_error(struc
 
 	qla2x00_dfs_remove(base_vha);
 
-	qla84xx_put_chip(base_vha);
-
 	if (base_vha->timer_active)
 		qla2x00_stop_timer(base_vha);
 
@@ -6847,6 +6845,8 @@ qla2x00_disable_board_on_pci_error(struc
 
 	scsi_remove_host(base_vha->host);
 
+	qla84xx_put_chip(base_vha);
+
 	base_vha->flags.init_done = 0;
 	qla25xx_delete_queues(base_vha);
 	qla2x00_free_fcports(base_vha);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 430/556] scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (428 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 429/556] scsi: qla2xxx: Fix cs84xx use-after-free on host teardown Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 431/556] scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state() Greg Kroah-Hartman
                   ` (138 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Nilesh Javali,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit 53298efcbbb0f0438366d45cb7ed7e6d93dd5531 upstream.

qla2x00_free_fce_trace() freed and cleared ha->fce while holding only
fce_mutex. The firmware-dump consumers qla27xx_fwdt_entry_t264() and
qla25xx_copy_fce() read ha->fce (NULL check followed by a copy of the
buffer) under hardware_lock and never take fce_mutex. A debugfs FCE
disable could therefore free the DMA buffer between a dump's NULL check
and its copy, resulting in a use-after-free.

Unpublish ha->fce under hardware_lock, then release the lock and free
the DMA buffer (dma_free_coherent() may sleep). A concurrent dump either
completes its check and copy with the buffer still valid, or observes
ha->fce == NULL and skips it.

Fixes: 841df27d619e ("scsi: qla2xxx: Move FCE Trace buffer allocation to user control")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-dev@google.com>
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Link: https://patch.msgid.link/20260730155838.2119230-11-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_init.c |   20 ++++++++++++++++++--
 1 file changed, 18 insertions(+), 2 deletions(-)

--- a/drivers/scsi/qla2xxx/qla_init.c
+++ b/drivers/scsi/qla2xxx/qla_init.c
@@ -3764,11 +3764,27 @@ int qla2x00_alloc_fce_trace(scsi_qla_hos
 
 void qla2x00_free_fce_trace(struct qla_hw_data *ha)
 {
-	if (!ha->fce)
+	void *fce;
+	dma_addr_t fce_dma;
+	unsigned long flags;
+
+	/*
+	 * Unpublish ha->fce under hardware_lock so a firmware dump in
+	 * progress (which reads ha->fce under the same lock) cannot race
+	 * with the buffer being freed.
+	 */
+	spin_lock_irqsave(&ha->hardware_lock, flags);
+	if (!ha->fce) {
+		spin_unlock_irqrestore(&ha->hardware_lock, flags);
 		return;
-	dma_free_coherent(&ha->pdev->dev, FCE_SIZE, ha->fce, ha->fce_dma);
+	}
+	fce = ha->fce;
+	fce_dma = ha->fce_dma;
 	ha->fce = NULL;
 	ha->fce_dma = 0;
+	spin_unlock_irqrestore(&ha->hardware_lock, flags);
+
+	dma_free_coherent(&ha->pdev->dev, FCE_SIZE, fce, fce_dma);
 }
 
 static void



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 431/556] scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (429 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 430/556] scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 432/556] scsi: qla2xxx: Fix FCE trace enable parsing in debugfs Greg Kroah-Hartman
                   ` (137 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Nilesh Javali,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit 9efaa782845b4d5fb3e01242be0d06ebc7428d8f upstream.

The mbx_cmd_t is allocated on the stack but left uninitialized.
qla2x00_mailbox_command() has several early-return paths (PCI permanent
failure, device failed, EEH busy, ISP abort pending, mailbox access
timeout, purge mbox) that return without writing the input mailbox
registers back into mcp->mb[]. qla2x00_get_firmware_state() then
unconditionally copies mcp->mb[1..6] (and mb[12]) into the caller's
states[] array regardless of the return value.

On such a failure the copied values are uninitialized kernel stack
memory, which is then exposed to userspace via the fw_state and
mpi_fw_state sysfs handlers. Zero the mailbox struct so a failed query
yields deterministic zeroed state instead of leaking stack contents.

Fixes: 4d4df1932b6b ("[SCSI] qla2xxx: Add ISP84XX support.")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-dev@google.com>
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Link: https://patch.msgid.link/20260730155838.2119230-9-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_mbx.c |    2 ++
 1 file changed, 2 insertions(+)

--- a/drivers/scsi/qla2xxx/qla_mbx.c
+++ b/drivers/scsi/qla2xxx/qla_mbx.c
@@ -2262,6 +2262,8 @@ qla2x00_get_firmware_state(scsi_qla_host
 	if (!ha->flags.fw_started)
 		return QLA_FUNCTION_FAILED;
 
+	memset(&mc, 0, sizeof(mc));
+
 	mcp->mb[0] = MBC_GET_FIRMWARE_STATE;
 	mcp->out_mb = MBX_0;
 	if (IS_FWI2_CAPABLE(vha->hw))



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 432/556] scsi: qla2xxx: Fix FCE trace enable parsing in debugfs
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (430 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 431/556] scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state() Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 433/556] scsi: qla2xxx: Dont query firmware state while chip is down Greg Kroah-Hartman
                   ` (136 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Nilesh Javali,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit b7368687e3d11f51392d3c4774ec0263d5fbf31f upstream.

qla2x00_dfs_fce_write() called kstrtoul() with a NULL result pointer,
so a successful parse would dereference NULL and oops. Worse, the int
return value (0 on success, negative errno on failure) was assigned to
the unsigned long enable flag, inverting the intended logic: a valid
number was treated as "disable" while a parse failure enabled FCE.

Parse the value into enable and propagate parse errors to userspace.

Fixes: 841df27d619e ("scsi: qla2xxx: Move FCE Trace buffer allocation to user control")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-dev@google.com>
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Link: https://patch.msgid.link/20260730155838.2119230-10-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_dfs.c |    4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

--- a/drivers/scsi/qla2xxx/qla_dfs.c
+++ b/drivers/scsi/qla2xxx/qla_dfs.c
@@ -510,7 +510,9 @@ qla2x00_dfs_fce_write(struct file *file,
 		return PTR_ERR(buf);
 	}
 
-	enable = kstrtoul(buf, 0, 0);
+	rc = kstrtoul(buf, 0, &enable);
+	if (rc)
+		goto out_free;
 	rc = count;
 
 	mutex_lock(&ha->fce_mutex);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 433/556] scsi: qla2xxx: Dont query firmware state while chip is down
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (431 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 432/556] scsi: qla2xxx: Fix FCE trace enable parsing in debugfs Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 434/556] scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path Greg Kroah-Hartman
                   ` (135 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Nilesh Javali,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit e0cebe20dcffbed9c078fe30e2d18cd5046d9eff upstream.

qla2x00_fw_state_show() initializes rval to QLA_FUNCTION_FAILED and jumps
to the out: label when the chip is down or EEH is busy. The out: block
then re-issued qla2x00_get_firmware_state() because rval != QLA_SUCCESS,
defeating the chip-down/EEH-busy guards and issuing a mailbox command
(outside optrom_mutex) during ISP reset or PCI error recovery, which can
hang the adapter. It also turned a normal in-lock mailbox failure into a
second unsynchronized mailbox attempt.

Make the out: fallback only mark the firmware state as unknown. The
mailbox is now issued at most once, inside optrom_mutex, and only when
the chip is up and not EEH-busy.

Fixes: b6faaaf796d7 ("scsi: qla2xxx: Serialize mailbox request")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-dev@google.com>
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Link: https://patch.msgid.link/20260730155838.2119230-8-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_attr.c |    4 +---
 1 file changed, 1 insertion(+), 3 deletions(-)

--- a/drivers/scsi/qla2xxx/qla_attr.c
+++ b/drivers/scsi/qla2xxx/qla_attr.c
@@ -1662,10 +1662,8 @@ qla2x00_fw_state_show(struct device *dev
 	rval = qla2x00_get_firmware_state(vha, state);
 	mutex_unlock(&vha->hw->optrom_mutex);
 out:
-	if (rval != QLA_SUCCESS) {
+	if (rval != QLA_SUCCESS)
 		memset(state, -1, sizeof(state));
-		rval = qla2x00_get_firmware_state(vha, state);
-	}
 
 	return scnprintf(buf, PAGE_SIZE, "0x%x 0x%x 0x%x 0x%x 0x%x 0x%x\n",
 	    state[0], state[1], state[2], state[3], state[4], state[5]);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 434/556] scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (432 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 433/556] scsi: qla2xxx: Dont query firmware state while chip is down Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 435/556] scsi: qla2xxx: Fix response queue over-consumption in __qla_consume_iocb() Greg Kroah-Hartman
                   ` (134 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Nilesh Javali,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit 0f41d07d72f2245208c45374ca8d0a1846cad667 upstream.

qla2x00_status_entry() filters out non-TYPE_SRB entries and the
SRB_NVME_CMD, SRB_BIDI_CMD and SRB_TM_CMD types, then falls through to a
SCSI fast path that assumes the command is an SRB_SCSI_CMD. The first
thing on that path, qla_chk_edif_rx_sa_delete_pending(), and the
subsequent handling both evaluate GET_CMD_SP(sp), i.e. sp->u.scmd.cmd.

The srb u union overlays the SCSI command pointer with other command
layouts (bsg_job, iocb_cmd). If firmware delivers an unexpected
STATUS_TYPE IOCB for a non-SCSI handle, sp->u.scmd.cmd can read as a
non-NULL garbage pointer, bypassing the NULL checks in
qla_chk_edif_rx_sa_delete_pending() and at the cp == NULL test, and
leading to a wild pointer dereference.

Reject any SRB whose type is not SRB_SCSI_CMD before entering the fast
path. The outstanding_cmds slot is left untouched so a genuinely
non-SCSI command still completes through its proper handler.

Fixes: dd30706e73b7 ("scsi: qla2xxx: edif: Add key update")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-dev@google.com>
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Link: https://patch.msgid.link/20260730155838.2119230-19-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_dbg.c |    2 +-
 drivers/scsi/qla2xxx/qla_isr.c |    8 ++++++++
 2 files changed, 9 insertions(+), 1 deletion(-)

--- a/drivers/scsi/qla2xxx/qla_dbg.c
+++ b/drivers/scsi/qla2xxx/qla_dbg.c
@@ -16,7 +16,7 @@
  * |                              |                    | 0x2127-0x2128  |
  * | Queue Command and IO tracing |       0x3074       | 0x300b         |
  * |                              |                    | 0x3027-0x3028  |
- * |                              |                    | 0x303d-0x3041  |
+ * |                              |                    | 0x303e-0x3041  |
  * |                              |                    | 0x302e,0x3033  |
  * |                              |                    | 0x3036,0x3038  |
  * |                              |                    | 0x303a		|
--- a/drivers/scsi/qla2xxx/qla_isr.c
+++ b/drivers/scsi/qla2xxx/qla_isr.c
@@ -3406,6 +3406,14 @@ qla2x00_status_entry(scsi_qla_host_t *vh
 		return;
 	}
 
+	/* Everything below is the SCSI fast path; reject other SRB types. */
+	if (sp->type != SRB_SCSI_CMD) {
+		ql_dbg(ql_dbg_io, vha, 0x303d,
+		    "Unexpected SRB type %x for status IOCB, sp %p.\n",
+		    sp->type, sp);
+		return;
+	}
+
 	/* Fast path completion. */
 	qla_chk_edif_rx_sa_delete_pending(vha, sp, sts24);
 	sp->qpair->cmd_completion_cnt++;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 435/556] scsi: qla2xxx: Fix response queue over-consumption in __qla_consume_iocb()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (433 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 434/556] scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 436/556] scsi: qla2xxx: Quiesce response IRQ before freeing request queue Greg Kroah-Hartman
                   ` (133 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Nilesh Javali,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit 3ba019bdd89d931499d9476456b5d9c7ab7fa753 upstream.

qla24xx_process_response_queue() advances ring_ptr past the head IOCB
before dispatching, so by the time __qla_consume_iocb() runs, ring_ptr
already points at the first continuation IOCB. The function however
looped purex->entry_count times starting at ring_ptr. As entry_count
includes the head, this consumed one entry too many: it stamped
RESPONSE_PROCESSED on the next, unrelated IOCB and advanced the ring
past it, silently dropping a legitimate firmware response. The head
IOCB's signature was also never marked.

Mark the head processed and account for it, then consume only the
entry_count - 1 continuation IOCBs, matching __qla_copy_purex_to_buffer().

Fixes: fac2807946c1 ("scsi: qla2xxx: edif: Add extraction of auth_els from the wire")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-dev@google.com>
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Link: https://patch.msgid.link/20260730155838.2119230-14-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_isr.c |   11 +++++++++++
 1 file changed, 11 insertions(+)

--- a/drivers/scsi/qla2xxx/qla_isr.c
+++ b/drivers/scsi/qla2xxx/qla_isr.c
@@ -205,6 +205,17 @@ void __qla_consume_iocb(struct scsi_qla_
 	struct purex_entry_24xx *purex = *pkt;
 
 	entry_count_remaining = purex->entry_count;
+
+	/*
+	 * The caller already advanced ring_ptr past the head IOCB, so mark
+	 * the head processed and account for it here, then consume only the
+	 * continuation IOCBs that follow.
+	 */
+	((response_t *)purex)->signature = RESPONSE_PROCESSED;
+	/* flush signature */
+	wmb();
+	--entry_count_remaining;
+
 	while (entry_count_remaining > 0) {
 		new_pkt = rsp_q->ring_ptr;
 		*pkt = new_pkt;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 436/556] scsi: qla2xxx: Quiesce response IRQ before freeing request queue
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (434 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 435/556] scsi: qla2xxx: Fix response queue over-consumption in __qla_consume_iocb() Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 437/556] scsi: qla2xxx: Avoid double completion in async IOCB timeout Greg Kroah-Hartman
                   ` (132 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Nilesh Javali,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit 505753ec2594c6af09a601f0dd60be7d840c1d2d upstream.

qla2xxx_delete_qpair() deletes the request queue before the response
queue. qla25xx_delete_req_que() frees the request queue memory
(kfree(req) in qla25xx_free_req_que()), but the response-queue MSI-X is
only released later, in qla25xx_free_rsp_que(). In that window the
response interrupt can still fire, qla2xxx_msix_rsp_q() queues
qpair->q_work, and qla_do_work() -> qla24xx_process_response_queue()
dereferences the now-freed rsp->req (LOGINOUT/CT/ELS entries and the
status path), a use-after-free.

The cancel_work_sync() added for the qpair teardown lives in the
response free path, which runs after the request queue is already freed,
so it does not protect rsp->req.

Release the response-queue interrupt and flush qpair->q_work before
deleting the request queue, so no late completion can reach the freed
request queue. Clearing have_irq makes the subsequent
qla25xx_free_rsp_que() skip its free_irq(), and the firmware
queue-delete order (request then response) is preserved; the
request-delete mailbox completes on the default vector and is unaffected
by dropping the qpair response interrupt early.

Fixes: d74595278f4a ("scsi: qla2xxx: Add multiple queue pair functionality.")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-dev@google.com>
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Link: https://patch.msgid.link/20260730155838.2119230-18-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_init.c |   17 +++++++++++++++++
 1 file changed, 17 insertions(+)

--- a/drivers/scsi/qla2xxx/qla_init.c
+++ b/drivers/scsi/qla2xxx/qla_init.c
@@ -10042,11 +10042,28 @@ int qla2xxx_delete_qpair(struct scsi_qla
 {
 	int ret = QLA_FUNCTION_FAILED;
 	struct qla_hw_data *ha = qpair->hw;
+	struct rsp_que *rsp = qpair->rsp;
 
 	qpair->delete_in_progress = 1;
 
 	qla_free_buf_pool(qpair);
 
+	/*
+	 * The response-queue interrupt schedules qla_do_work(), which
+	 * dereferences qpair->rsp->req.  Release the interrupt and flush
+	 * any pending work before the request queue is freed below so a
+	 * late completion cannot touch the freed request queue.  The
+	 * firmware queue-delete order (request then response) is kept.
+	 */
+	if (rsp && rsp->msix && rsp->msix->have_irq) {
+		free_irq(rsp->msix->vector, rsp->msix->handle);
+		rsp->msix->have_irq = 0;
+		rsp->msix->in_use = 0;
+		rsp->msix->handle = NULL;
+	}
+	if (rsp && ha->wq)
+		cancel_work_sync(&qpair->q_work);
+
 	ret = qla25xx_delete_req_que(vha, qpair->req);
 	if (ret != QLA_SUCCESS)
 		goto fail;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 437/556] scsi: qla2xxx: Avoid double completion in async IOCB timeout
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (435 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 436/556] scsi: qla2xxx: Quiesce response IRQ before freeing request queue Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 438/556] scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read Greg Kroah-Hartman
                   ` (131 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Nilesh Javali,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit bb45bc4bd53c95a7bf6f782577b5ede94c0f8aa8 upstream.

qla2x00_async_iocb_timeout() tries to abort a timed-out async IOCB. When
qla24xx_async_abort_cmd() fails, both the SRB_LOGIN_CMD path and the
SRB_CTRL_VP/default path scan outstanding_cmds[] for the SRB and then
call sp->done(sp, QLA_FUNCTION_TIMEOUT) unconditionally, without checking
whether the SRB was actually found and removed.

If the response ISR completes the same handle first, it removes the SRB
under qp_lock_ptr and runs sp->done() -> complete(sp->comp). The
submitter qla24xx_control_vp() wakes from wait_for_completion(), clears
sp->comp, drops its reference and returns, reclaiming the on-stack
completion. The timer reference keeps the SRB alive across the timeout
handler, but not the submitter's stack. The timeout then issues a second
sp->done() -> qla_ctrlvp_sp_done(), which evaluates "if (sp->comp)
complete(sp->comp)"; with the pointer loaded before the submitter's NULL
store, complete() writes into the freed stack frame, a use-after-free.

Track whether this path removed the SRB from outstanding_cmds and only
call sp->done() when it did, so the command is completed exactly once by
whichever path owns it. This mirrors the sp_found guard already used in
qla24xx_abort_iocb_timeout().

Fixes: f6145e86d21f ("scsi: qla2xxx: Fix race between switch cmd completion and timeout")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-dev@google.com>
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Link: https://patch.msgid.link/20260730155838.2119230-21-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_init.c |   24 +++++++++++++++++++++---
 1 file changed, 21 insertions(+), 3 deletions(-)

--- a/drivers/scsi/qla2xxx/qla_init.c
+++ b/drivers/scsi/qla2xxx/qla_init.c
@@ -228,7 +228,7 @@ qla2x00_async_iocb_timeout(void *data)
 	srb_t *sp = data;
 	fc_port_t *fcport = sp->fcport;
 	struct srb_iocb *lio = &sp->u.iocb_cmd;
-	int rc, h;
+	int rc, h, found;
 	unsigned long flags;
 
 	if (fcport) {
@@ -251,6 +251,7 @@ qla2x00_async_iocb_timeout(void *data)
 			lio->u.logio.data[1] =
 				lio->u.logio.flags & SRB_LOGIN_RETRIED ?
 				QLA_LOGIO_LOGIN_RETRIED : 0;
+			found = 0;
 			spin_lock_irqsave(sp->qpair->qp_lock_ptr, flags);
 			for (h = 1; h < sp->qpair->req->num_outstanding_cmds;
 			    h++) {
@@ -258,11 +259,19 @@ qla2x00_async_iocb_timeout(void *data)
 				    sp) {
 					sp->qpair->req->outstanding_cmds[h] =
 					    NULL;
+					found = 1;
 					break;
 				}
 			}
 			spin_unlock_irqrestore(sp->qpair->qp_lock_ptr, flags);
-			sp->done(sp, QLA_FUNCTION_TIMEOUT);
+			/*
+			 * Only complete the command if this path removed it
+			 * from outstanding_cmds.  Otherwise the ISR already
+			 * completed it and a second sp->done() would race the
+			 * submitter's freeing of the on-stack completion.
+			 */
+			if (found)
+				sp->done(sp, QLA_FUNCTION_TIMEOUT);
 		}
 		break;
 	case SRB_LOGOUT_CMD:
@@ -275,6 +284,7 @@ qla2x00_async_iocb_timeout(void *data)
 	default:
 		rc = qla24xx_async_abort_cmd(sp, false);
 		if (rc) {
+			found = 0;
 			spin_lock_irqsave(sp->qpair->qp_lock_ptr, flags);
 			for (h = 1; h < sp->qpair->req->num_outstanding_cmds;
 			    h++) {
@@ -282,11 +292,19 @@ qla2x00_async_iocb_timeout(void *data)
 				    sp) {
 					sp->qpair->req->outstanding_cmds[h] =
 					    NULL;
+					found = 1;
 					break;
 				}
 			}
 			spin_unlock_irqrestore(sp->qpair->qp_lock_ptr, flags);
-			sp->done(sp, QLA_FUNCTION_TIMEOUT);
+			/*
+			 * Only complete the command if this path removed it
+			 * from outstanding_cmds.  Otherwise the ISR already
+			 * completed it and a second sp->done() would race the
+			 * submitter's freeing of the on-stack completion.
+			 */
+			if (found)
+				sp->done(sp, QLA_FUNCTION_TIMEOUT);
 		}
 		break;
 	}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 438/556] scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (436 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 437/556] scsi: qla2xxx: Avoid double completion in async IOCB timeout Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:41 ` [PATCH 7.2 439/556] scsi: qla2xxx: Avoid req_q_map double-read in qla2x00_error_entry() Greg Kroah-Hartman
                   ` (130 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Nilesh Javali,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit ca6d880d6c70cb7946e7b3e05d7285f271b6d99e upstream.

In qla2x00_status_entry(), the FWI2 status path advances sense_data and
shrinks par_sense_len by rsp_info_len:

	if (IS_FWI2_CAPABLE(ha)) {
		sense_data += rsp_info_len;
		par_sense_len -= rsp_info_len;
	}

rsp_info_len is a 32-bit value taken directly from the target's FCP
response (sf.rsp_data_len), while par_sense_len is the IOCB data area
size (28 bytes for 24xx, 60 bytes for 29xx). A hostile or buggy target
reporting an rsp_info_len larger than par_sense_len makes the unsigned
subtraction underflow to a huge value and advances sense_data out of
bounds.

The underflowed par_sense_len then defeats the cap in
qla2x00_handle_sense():

	if (sense_len > par_sense_len)
		sense_len = par_sense_len;
	memcpy(cp->sense_buffer, sense_data, sense_len);

so the memcpy reads up to SCSI_SENSE_BUFFERSIZE bytes from the
out-of-bounds sense_data pointer, leaking adjacent response-ring/heap
memory into the command's sense buffer.

Clamp rsp_info_len to par_sense_len before the subtraction so
par_sense_len can never underflow and sense_data stays within the IOCB
data area. The fix sits before the comp_status switch, covering both
qla2x00_handle_sense() call sites.

Fixes: 5544213be7b4 ("[SCSI] qla2xxx: Correct extended sense-data handling.")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-dev@google.com>
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Link: https://patch.msgid.link/20260730155838.2119230-16-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_isr.c |   12 ++++++++++++
 1 file changed, 12 insertions(+)

--- a/drivers/scsi/qla2xxx/qla_isr.c
+++ b/drivers/scsi/qla2xxx/qla_isr.c
@@ -3482,6 +3482,18 @@ qla2x00_status_entry(scsi_qla_host_t *vh
 	if (scsi_status & SS_RESPONSE_INFO_LEN_VALID) {
 		/* Sense data lies beyond any FCP RESPONSE data. */
 		if (IS_FWI2_CAPABLE(ha)) {
+			/*
+			 * A hostile or buggy target may report an
+			 * rsp_info_len larger than the IOCB data area.
+			 * Clamp it so the par_sense_len subtraction cannot
+			 * underflow and walk sense_data out of bounds.
+			 */
+			if (rsp_info_len > par_sense_len) {
+				ql_log(ql_log_warn, fcport->vha, 0x3107,
+				       "Truncating bogus rsp_info_len 0x%x to 0x%x.\n",
+				       rsp_info_len, par_sense_len);
+				rsp_info_len = par_sense_len;
+			}
 			sense_data += rsp_info_len;
 			par_sense_len -= rsp_info_len;
 		}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 439/556] scsi: qla2xxx: Avoid req_q_map double-read in qla2x00_error_entry()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (437 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 438/556] scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read Greg Kroah-Hartman
@ 2026-09-09 13:41 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 440/556] scsi: qla2xxx: Fix NVMe abort reference leak on repeated abort Greg Kroah-Hartman
                   ` (129 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:41 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Nilesh Javali,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit deb8abde83a799d2501f3977f6d6051000253f5e upstream.

qla2x00_error_entry() reads ha->req_q_map[que] twice: once for the NULL
check and again when assigning it to req. The map slot is cleared by
qla25xx_free_req_que() (ha->req_q_map[que_id] = NULL under mq_lock)
during queue teardown, while the response-queue interrupt that drives
qla2x00_error_entry() is still registered (the IRQ is released later in
qla25xx_free_rsp_que()). If the slot is set to NULL between the two
reads, req becomes NULL and is dereferenced.

Read the slot once into req and NULL-check the local before use. mq_lock
is a mutex and cannot be taken from interrupt context, so the single
read plus local check is the appropriate fix for the reported NULL
dereference.

Fixes: a6fe35c052c4 ("[SCSI] qla2xxx: Avoid invalid request queue dereference for bad response packets.")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-dev@google.com>
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Link: https://patch.msgid.link/20260730155838.2119230-17-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_isr.c |    4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

--- a/drivers/scsi/qla2xxx/qla_isr.c
+++ b/drivers/scsi/qla2xxx/qla_isr.c
@@ -3809,10 +3809,12 @@ qla2x00_error_entry(scsi_qla_host_t *vha
 	    "iocb type %xh with error status %xh, handle %xh, rspq id %d\n",
 	    pkt->entry_type, pkt->entry_status, pkt->handle, rsp->id);
 
-	if (que >= ha->max_req_queues || !ha->req_q_map[que])
+	if (que >= ha->max_req_queues)
 		goto fatal;
 
 	req = ha->req_q_map[que];
+	if (!req)
+		goto fatal;
 
 	if (pkt->entry_status & RF_BUSY)
 		res = DID_BUS_BUSY << 16;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 440/556] scsi: qla2xxx: Fix NVMe abort reference leak on repeated abort
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (438 preceding siblings ...)
  2026-09-09 13:41 ` [PATCH 7.2 439/556] scsi: qla2xxx: Avoid req_q_map double-read in qla2x00_error_entry() Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 441/556] scsi: qla2xxx: Drop vport reference under lock in report ID acquisition Greg Kroah-Hartman
                   ` (128 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Nilesh Javali,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit 06b5b2a5d499323f1c3256ead35798e8e3d15e60 upstream.

qla_nvme_ls_abort() and qla_nvme_fcp_abort() take a command reference with
kref_get_unless_zero() and then call schedule_work() on priv->abort_work,
ignoring its return value. qla_nvme_abort_work() runs once and drops
exactly one reference via kref_put(&sp->cmd_kref, sp->put_fn).

Since the per-abort INIT_WORK() was moved to submission time,
schedule_work() now returns false when the work is already pending, for
example on a concurrent transport teardown and timeout-driven abort of
the same command. In that case the reference taken for the second abort
is never released because the work still executes only once, leaking a
reference. The command is then never returned to the NVMe-FC transport,
which can hang the port.

Drop the reference when schedule_work() returns false, so each
kref_get_unless_zero() is balanced regardless of whether the work was
newly queued. The held reference keeps priv->sp valid for the put.

Fixes: 7e85f6dbc856 ("scsi: qla2xxx: Initialize NVMe abort_work once at submission")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-dev@google.com>
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Link: https://patch.msgid.link/20260730155838.2119230-25-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_nvme.c |    6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

--- a/drivers/scsi/qla2xxx/qla_nvme.c
+++ b/drivers/scsi/qla2xxx/qla_nvme.c
@@ -466,7 +466,8 @@ static void qla_nvme_ls_abort(struct nvm
 	}
 	spin_unlock_irqrestore(&priv->cmd_lock, flags);
 
-	schedule_work(&priv->abort_work);
+	if (!schedule_work(&priv->abort_work))
+		kref_put(&priv->sp->cmd_kref, priv->sp->put_fn);
 }
 
 static int qla_nvme_ls_req(struct nvme_fc_local_port *lport,
@@ -548,7 +549,8 @@ static void qla_nvme_fcp_abort(struct nv
 	}
 	spin_unlock_irqrestore(&priv->cmd_lock, flags);
 
-	schedule_work(&priv->abort_work);
+	if (!schedule_work(&priv->abort_work))
+		kref_put(&priv->sp->cmd_kref, priv->sp->put_fn);
 }
 
 static inline int qla2x00_start_nvme_mq(srb_t *sp)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 441/556] scsi: qla2xxx: Drop vport reference under lock in report ID acquisition
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (439 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 440/556] scsi: qla2xxx: Fix NVMe abort reference leak on repeated abort Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 442/556] scsi: qla2xxx: Hold vport_slock for host map update " Greg Kroah-Hartman
                   ` (127 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Nilesh Javali,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit 1154b16439ffc562f9461494c4508c63446eb684 upstream.

qla24xx_report_id_acquisition() format-1 handling takes the vport
reference under vport_slock but drops it outside the lock, after setting
vp->vp_flags and vp->dpc_flags:

	set_bit(VP_IDX_ACQUIRED, &vp->vp_flags);
	set_bit(REGISTER_FC4_NEEDED, &vp->dpc_flags);
	set_bit(REGISTER_FDMI_NEEDED, &vp->dpc_flags);

	atomic_dec(&vp->vref_count);

Neither set_bit() nor atomic_dec() imply a memory barrier, so on a weakly
ordered architecture the decrement can become visible before the flag
stores. qla24xx_deallocate_vp_id() polls vref_count under vport_slock and
unlinks the vport once it reads zero, after which qla24xx_vport_delete()
frees it via scsi_host_put(). The poller could therefore observe
vref_count == 0 early and tear the vport down while the pending vp_flags/
dpc_flags stores land on freed memory.

Drop the reference under vport_slock, as is done for the matching
increment and by every other vref_count user. The unlock release pairs
with the deallocate poller's lock acquire so the flag stores are ordered
before vref_count == 0 can be observed.

Fixes: 793cedee296f ("scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition()")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-dev@google.com>
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Link: https://patch.msgid.link/20260730155838.2119230-23-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_mbx.c |    2 ++
 1 file changed, 2 insertions(+)

--- a/drivers/scsi/qla2xxx/qla_mbx.c
+++ b/drivers/scsi/qla2xxx/qla_mbx.c
@@ -4224,7 +4224,9 @@ qla24xx_report_id_acquisition(scsi_qla_h
 			set_bit(REGISTER_FC4_NEEDED, &vp->dpc_flags);
 			set_bit(REGISTER_FDMI_NEEDED, &vp->dpc_flags);
 
+			spin_lock_irqsave(&ha->vport_slock, flags);
 			atomic_dec(&vp->vref_count);
+			spin_unlock_irqrestore(&ha->vport_slock, flags);
 		}
 		set_bit(VP_DPC_NEEDED, &vha->dpc_flags);
 		qla2xxx_wake_dpc(vha);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 442/556] scsi: qla2xxx: Hold vport_slock for host map update in report ID acquisition
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (440 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 441/556] scsi: qla2xxx: Drop vport reference under lock in report ID acquisition Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 443/556] scsi: qla2xxx: Use coherent DMA buffer for D_Port diagnostics Greg Kroah-Hartman
                   ` (126 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Nilesh Javali,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit 7944039ba9cb5c3a935d17c91004e3b8649ff58e upstream.

qla24xx_report_id_acquisition() format-1 handling drops vport_slock after
taking the vport reference and then calls qla_update_host_map() without
the lock. That reaches qla_update_vp_map(), which mutates the ha->host_map
btree via btree_insert32()/btree_update32()/btree_remove32() and is
documented to require vport_slock to be held by the caller. Running it
unlocked can race concurrent host_map updates and corrupt the btree.

The format-2 path in the same function already wraps its host_map update
(SET_AL_PA) in vport_slock; the format-1 path is the lone outlier.

Hold vport_slock across the format-1 qla_update_host_map() call to honor
the documented locking contract. The vref_count taken in the loop keeps
the vport valid, so this only adds the missing host_map serialization.

Fixes: 430eef03a763 ("scsi: qla2xxx: Relocate/rename vp map")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-dev@google.com>
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Link: https://patch.msgid.link/20260730155838.2119230-24-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_mbx.c |    2 ++
 1 file changed, 2 insertions(+)

--- a/drivers/scsi/qla2xxx/qla_mbx.c
+++ b/drivers/scsi/qla2xxx/qla_mbx.c
@@ -4214,7 +4214,9 @@ qla24xx_report_id_acquisition(scsi_qla_h
 			if (!found)
 				return;
 
+			spin_lock_irqsave(&ha->vport_slock, flags);
 			qla_update_host_map(vp, id);
+			spin_unlock_irqrestore(&ha->vport_slock, flags);
 
 			/*
 			 * Cannot configure here as we are still sitting on the



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 443/556] scsi: qla2xxx: Use coherent DMA buffer for D_Port diagnostics
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (441 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 442/556] scsi: qla2xxx: Hold vport_slock for host map update " Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 444/556] scsi: qla2xxx: Zero-init bsg stack buffers to avoid info leak Greg Kroah-Hartman
                   ` (125 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Nilesh Javali,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit 7c4f3f50d83af4545efaa99b3d0d46fb8d52031e upstream.

qla26xx_dport_diagnostics() streaming-maps the caller's result buffer with
dma_map_single(). The bsg path passes &dd->buf from the __packed struct
qla_dport_diag, where buf lands at a 2-byte offset and shares cachelines
with the surrounding options/unused fields. Mapping such a misaligned
sub-buffer violates the DMA API requirement that streaming buffers be
cacheline aligned and not share a cacheline with other data, and can
corrupt data on non-DMA-coherent architectures.

Allocate a dedicated DMA-coherent buffer inside qla26xx_dport_diagnostics()
for the mailbox command and copy the result back into the caller's buffer.
This removes the streaming map of the misaligned sub-buffer entirely; the
caller's buffer is now only a plain CPU buffer, so its packing no longer
matters.

Fixes: ec89146215d1 ("qla2xxx: Add bsg interface to support D_Port Diagnostics.")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-dev@google.com>
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Link: https://patch.msgid.link/20260730155838.2119230-29-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_mbx.c |   15 +++++++--------
 1 file changed, 7 insertions(+), 8 deletions(-)

--- a/drivers/scsi/qla2xxx/qla_mbx.c
+++ b/drivers/scsi/qla2xxx/qla_mbx.c
@@ -6499,6 +6499,7 @@ qla26xx_dport_diagnostics(scsi_qla_host_
 	mbx_cmd_t mc;
 	mbx_cmd_t *mcp = &mc;
 	dma_addr_t dd_dma;
+	void *dd;
 
 	if (!IS_QLA83XX(vha->hw) && !IS_QLA27XX(vha->hw) &&
 	    !IS_QLA28XX(vha->hw))
@@ -6507,15 +6508,12 @@ qla26xx_dport_diagnostics(scsi_qla_host_
 	ql_dbg(ql_dbg_mbx + ql_dbg_verbose, vha, 0x119f,
 	    "Entered %s.\n", __func__);
 
-	dd_dma = dma_map_single(&vha->hw->pdev->dev,
-	    dd_buf, size, DMA_FROM_DEVICE);
-	if (dma_mapping_error(&vha->hw->pdev->dev, dd_dma)) {
-		ql_log(ql_log_warn, vha, 0x1194, "Failed to map dma buffer.\n");
+	dd = dma_alloc_coherent(&vha->hw->pdev->dev, size, &dd_dma, GFP_KERNEL);
+	if (!dd) {
+		ql_log(ql_log_warn, vha, 0x1194, "Failed to allocate dma buffer.\n");
 		return QLA_MEMORY_ALLOC_FAILED;
 	}
 
-	memset(dd_buf, 0, size);
-
 	mcp->mb[0] = MBC_DPORT_DIAGNOSTICS;
 	mcp->mb[1] = options;
 	mcp->mb[2] = MSW(LSD(dd_dma));
@@ -6537,8 +6535,9 @@ qla26xx_dport_diagnostics(scsi_qla_host_
 		    "Done %s.\n", __func__);
 	}
 
-	dma_unmap_single(&vha->hw->pdev->dev, dd_dma,
-	    size, DMA_FROM_DEVICE);
+	memcpy(dd_buf, dd, size);
+
+	dma_free_coherent(&vha->hw->pdev->dev, size, dd, dd_dma);
 
 	return rval;
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 444/556] scsi: qla2xxx: Zero-init bsg stack buffers to avoid info leak
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (442 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 443/556] scsi: qla2xxx: Use coherent DMA buffer for D_Port diagnostics Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 445/556] scsi: qla2xxx: Skip NVMe LS reject IOCB when FW not started Greg Kroah-Hartman
                   ` (124 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Nilesh Javali,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit b93d3bb3afe1b44489927de1eb4e66e8536a5935 upstream.

Several bsg handlers stage their request/reply in an uninitialized 256-byte
on-stack buffer (uint8_t bsg[DMA_POOL_SIZE]) and fill it via
sg_copy_to_buffer(), which only copies as many bytes as the user-supplied
request payload. When the request is shorter than the structure, the
remainder of the buffer is left holding stale stack data.

qla2x00_read_fru_status() and qla2x00_read_i2c() then copy the full
structure back to the reply payload with sg_copy_from_buffer(), leaking the
uninitialized stack bytes to user space. The write/update paths do not copy
the buffer back, but can feed uninitialized fields to the device.

Zero the stack buffer at declaration in all five handlers, mirroring the
heap kzalloc() approach, so short requests can no longer expose stale
memory.

Fixes: 697a4bc69159 ("[SCSI] qla2xxx: Provide method for updating I2C attached VPD.")
Fixes: 9ebb5d9c69f1 ("[SCSI] qla2xxx: Add I2C BSG interface.")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-dev@google.com>
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Link: https://patch.msgid.link/20260730155838.2119230-30-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_bsg.c |   10 +++++-----
 1 file changed, 5 insertions(+), 5 deletions(-)

--- a/drivers/scsi/qla2xxx/qla_bsg.c
+++ b/drivers/scsi/qla2xxx/qla_bsg.c
@@ -1562,7 +1562,7 @@ qla2x00_update_fru_versions(struct bsg_j
 	scsi_qla_host_t *vha = shost_priv(host);
 	struct qla_hw_data *ha = vha->hw;
 	int rval = 0;
-	uint8_t bsg[DMA_POOL_SIZE];
+	uint8_t bsg[DMA_POOL_SIZE] = {};
 	struct qla_image_version_list *list = (void *)bsg;
 	struct qla_image_version *image;
 	uint32_t count;
@@ -1622,7 +1622,7 @@ qla2x00_read_fru_status(struct bsg_job *
 	scsi_qla_host_t *vha = shost_priv(host);
 	struct qla_hw_data *ha = vha->hw;
 	int rval = 0;
-	uint8_t bsg[DMA_POOL_SIZE];
+	uint8_t bsg[DMA_POOL_SIZE] = {};
 	struct qla_status_reg *sr = (void *)bsg;
 	dma_addr_t sfp_dma;
 	uint8_t *sfp = dma_pool_zalloc(ha->s_dma_pool, GFP_KERNEL, &sfp_dma);
@@ -1673,7 +1673,7 @@ qla2x00_write_fru_status(struct bsg_job
 	scsi_qla_host_t *vha = shost_priv(host);
 	struct qla_hw_data *ha = vha->hw;
 	int rval = 0;
-	uint8_t bsg[DMA_POOL_SIZE];
+	uint8_t bsg[DMA_POOL_SIZE] = {};
 	struct qla_status_reg *sr = (void *)bsg;
 	dma_addr_t sfp_dma;
 	uint8_t *sfp = dma_pool_zalloc(ha->s_dma_pool, GFP_KERNEL, &sfp_dma);
@@ -1720,7 +1720,7 @@ qla2x00_write_i2c(struct bsg_job *bsg_jo
 	scsi_qla_host_t *vha = shost_priv(host);
 	struct qla_hw_data *ha = vha->hw;
 	int rval = 0;
-	uint8_t bsg[DMA_POOL_SIZE];
+	uint8_t bsg[DMA_POOL_SIZE] = {};
 	struct qla_i2c_access *i2c = (void *)bsg;
 	dma_addr_t sfp_dma;
 	uint8_t *sfp = dma_pool_zalloc(ha->s_dma_pool, GFP_KERNEL, &sfp_dma);
@@ -1772,7 +1772,7 @@ qla2x00_read_i2c(struct bsg_job *bsg_job
 	scsi_qla_host_t *vha = shost_priv(host);
 	struct qla_hw_data *ha = vha->hw;
 	int rval = 0;
-	uint8_t bsg[DMA_POOL_SIZE];
+	uint8_t bsg[DMA_POOL_SIZE] = {};
 	struct qla_i2c_access *i2c = (void *)bsg;
 	dma_addr_t sfp_dma;
 	uint8_t *sfp = dma_pool_zalloc(ha->s_dma_pool, GFP_KERNEL, &sfp_dma);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 445/556] scsi: qla2xxx: Skip NVMe LS reject IOCB when FW not started
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (443 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 444/556] scsi: qla2xxx: Zero-init bsg stack buffers to avoid info leak Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 446/556] f2fs: return symlink writeback errors Greg Kroah-Hartman
                   ` (123 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko, Nilesh Javali,
	Martin K. Petersen (Oracle)

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nilesh Javali <njavali@marvell.com>

commit f7e46ebffc5781aab3f1f5a5d4350addbb5833f4 upstream.

qla_nvme_xmt_ls_rsp() bails out to the out: label when firmware is not
started (!ha->flags.fw_started), but the out: path unconditionally calls
qla_nvme_ls_reject_iocb(), which ends in qla2x00_start_iocbs() and an
unconditional doorbell write to the request queue in-pointer register.
This rings the firmware doorbell and queues an IOCB that stopped or
resetting firmware cannot consume, and touches MMIO during the reset/EEH
window where fw_started is also clear.

Only emit the LS reject IOCB (and ring the doorbell) when fw_started is
set; otherwise just clean up and return. The post-allocation failure
cases (SRB alloc / qla2x00_start_sp() failure) run with firmware started
and still send the reject. Apply the same guard to the reject emission
in qla2xxx_process_purls_pkt().

Fixes: 875386b98857 ("scsi: qla2xxx: Add Unsolicited LS Request and Response Support for NVMe")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-dev@google.com>
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Link: https://patch.msgid.link/20260730155838.2119230-26-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/scsi/qla2xxx/qla_nvme.c |   19 +++++++++++++------
 1 file changed, 13 insertions(+), 6 deletions(-)

--- a/drivers/scsi/qla2xxx/qla_nvme.c
+++ b/drivers/scsi/qla2xxx/qla_nvme.c
@@ -441,9 +441,11 @@ out:
 	a.vp_idx = vha->vp_idx;
 	a.nport_handle = uctx->nport_handle;
 	a.xchg_address = uctx->exchange_address;
-	spin_lock_irqsave(ha->base_qpair->qp_lock_ptr, flags);
-	qla_nvme_ls_reject_iocb(vha, ha->base_qpair, &a, true);
-	spin_unlock_irqrestore(ha->base_qpair->qp_lock_ptr, flags);
+	if (ha->flags.fw_started) {
+		spin_lock_irqsave(ha->base_qpair->qp_lock_ptr, flags);
+		qla_nvme_ls_reject_iocb(vha, ha->base_qpair, &a, true);
+		spin_unlock_irqrestore(ha->base_qpair->qp_lock_ptr, flags);
+	}
 	kfree(uctx);
 	return rval;
 }
@@ -1205,9 +1207,14 @@ qla2xxx_process_purls_pkt(struct scsi_ql
 		a.vp_idx = vha->vp_idx;
 		a.nport_handle = uctx->nport_handle;
 		a.xchg_address = uctx->exchange_address;
-		spin_lock_irqsave(vha->hw->base_qpair->qp_lock_ptr, flags);
-		qla_nvme_ls_reject_iocb(vha, vha->hw->base_qpair, &a, true);
-		spin_unlock_irqrestore(vha->hw->base_qpair->qp_lock_ptr, flags);
+		if (vha->hw->flags.fw_started) {
+			spin_lock_irqsave(vha->hw->base_qpair->qp_lock_ptr,
+					  flags);
+			qla_nvme_ls_reject_iocb(vha, vha->hw->base_qpair, &a,
+						true);
+			spin_unlock_irqrestore(vha->hw->base_qpair->qp_lock_ptr,
+					       flags);
+		}
 		list_del(&uctx->elem);
 		kfree(uctx);
 	}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 446/556] f2fs: return symlink writeback errors
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (444 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 445/556] scsi: qla2xxx: Skip NVMe LS reject IOCB when FW not started Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 447/556] f2fs: reject overlapping move range after len expansion Greg Kroah-Hartman
                   ` (122 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Wenjie Qi, Chao Yu,
	Jaegeuk Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wenjie Qi <qwjhust@gmail.com>

commit a2c73a7a677afdaa8b16d775188f9ef5cfbfd8b2 upstream.

F2FS writes long symlink data with page_symlink() and then flushes the
symlink mapping to reduce the chance of exposing a broken symlink.

That flush result is currently ignored. If the writeback fails, symlink()
still returns success even though the symlink is not durable and the same
operation can already surface -EIO through syncfs().

Return the writeback error to userspace and skip the dirsync flush once the
symlink data flush has failed.

Fixes: d0cae97cb600 ("f2fs: flush symlink path to avoid broken symlink after POR")
Cc: stable@kernel.org
Signed-off-by: Wenjie Qi <qiwenjie@xiaomi.com>
Reviewed-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/f2fs/namei.c |   11 ++++++-----
 1 file changed, 6 insertions(+), 5 deletions(-)

--- a/fs/f2fs/namei.c
+++ b/fs/f2fs/namei.c
@@ -707,15 +707,16 @@ err_out:
 	 * performance regression.
 	 */
 	if (!err) {
-		filemap_write_and_wait_range(inode->i_mapping, 0,
-							disk_link.len - 1);
+		err = filemap_write_and_wait_range(inode->i_mapping, 0,
+						   disk_link.len - 1);
 
-		if (IS_DIRSYNC(dir))
+		if (!err && IS_DIRSYNC(dir))
 			f2fs_sync_fs(sbi->sb, 1);
-	} else {
-		f2fs_unlink(dir, dentry);
 	}
 
+	if (err)
+		f2fs_unlink(dir, dentry);
+
 	f2fs_balance_fs(sbi, true);
 	goto out_free_encrypted_link;
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 447/556] f2fs: reject overlapping move range after len expansion
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (445 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 446/556] f2fs: return symlink writeback errors Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 448/556] f2fs: only redirty pinned folios in redirty_blocks Greg Kroah-Hartman
                   ` (121 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Hao-Qun Huang, Chao Yu, Jaegeuk Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Hao-Qun Huang <alvinhuang0603@gmail.com>

commit 28c1ef094e7c86977d9bf570dc0362fc54e36437 upstream.

F2FS_IOC_MOVE_RANGE treats a zero length as a request to move data
from pos_in to EOF. However, the same-file overlap check runs before
that expansion, so a request with len == 0 bypasses the overlap
rejection added for same-file moves.

For example, with a four-block file, moving from block 0 to block 1
with len == 0 is accepted by the old check because pos_in + len is
still pos_in at that point. The code then expands len to cover the
rest of the file and calls __exchange_data_block() on overlapping
source and destination ranges in the same inode, which is the
data-corruption case the overlap check was meant to reject.

Move the overlap check after the source range has been validated and
len == 0 has been expanded, so it sees the effective length. This is a
no-op for non-zero len (the value is unchanged there) and keeps the
existing early return for identical positions.

Fixes: d95fd91c1ac1 ("f2fs: exclude special cases for f2fs_move_file_range")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-fable-5
Signed-off-by: Hao-Qun Huang <alvinhuang0603@gmail.com>
Reviewed-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/f2fs/file.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/fs/f2fs/file.c
+++ b/fs/f2fs/file.c
@@ -3144,8 +3144,6 @@ static int f2fs_move_file_range(struct f
 	if (src == dst) {
 		if (pos_in == pos_out)
 			return 0;
-		if (pos_out > pos_in && pos_out < pos_in + len)
-			return -EINVAL;
 	}
 
 	inode_lock(src);
@@ -3171,6 +3169,8 @@ static int f2fs_move_file_range(struct f
 		goto out_unlock;
 	if (len == 0)
 		olen = len = src->i_size - pos_in;
+	if (src == dst && pos_out > pos_in && pos_out < pos_in + len)
+		goto out_unlock;
 	if (pos_in + len == src->i_size)
 		len = ALIGN(src->i_size, F2FS_BLKSIZE) - pos_in;
 	if (len == 0) {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 448/556] f2fs: only redirty pinned folios in redirty_blocks
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (446 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 447/556] f2fs: reject overlapping move range after len expansion Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 449/556] f2fs: fix to avoid move_range and defragment on device_alias file Greg Kroah-Hartman
                   ` (120 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Wenjie Qi, Chao Yu,
	Jaegeuk Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wenjie Qi <qwjhust@gmail.com>

commit 85171332742e741ccd6f401c69b6e0d698119e72 upstream.

redirty_blocks() pins folios with read_cache_folio() and then walks the
same range again with filemap_lock_folio() to redirty them and drop the
references it took.

Commit 5951fee46bef ("f2fs: Use a folio in redirty_blocks()") changed
the second pass to a do/while loop. If read_cache_folio() fails before
anything is pinned, page_idx does not advance but the cleanup loop still
runs once.

If readahead has already populated the failed folio in page cache, that
extra iteration finds it and folio_put_refs(folio, 2) drops one
reference too many. Later drop_caches or reclaim can then report
"BUG: Bad page state".

Only redirty the range that was pinned successfully.

Fixes: 5951fee46bef ("f2fs: Use a folio in redirty_blocks()")
Cc: stable@kernel.org
Assisted-by: Codex:gpt-5.5
Signed-off-by: Wenjie Qi <qiwenjie@xiaomi.com>
Reviewed-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/f2fs/file.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/fs/f2fs/file.c
+++ b/fs/f2fs/file.c
@@ -4473,7 +4473,7 @@ static int redirty_blocks(struct inode *
 		page_idx = folio_next_index(folio);
 	} while (page_len < len);
 
-	do {
+	while (redirty_idx < page_idx) {
 		folio = filemap_lock_folio(mapping, redirty_idx);
 
 		/* It will never fail, when folio has pinned above */
@@ -4486,7 +4486,7 @@ static int redirty_blocks(struct inode *
 		redirty_idx = folio_next_index(folio);
 		folio_unlock(folio);
 		folio_put_refs(folio, 2);
-	} while (redirty_idx < page_idx);
+	}
 
 	return ret;
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 449/556] f2fs: fix to avoid move_range and defragment on device_alias file
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (447 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 448/556] f2fs: only redirty pinned folios in redirty_blocks Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 450/556] f2fs: validate MOVE_RANGE destination size Greg Kroah-Hartman
                   ` (119 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Chao Yu, Jaegeuk Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chao Yu <chao@kernel.org>

commit 1b4db09b7f10895dc1a0bc32704c7de05188fb1d upstream.

It's forbidden to migrate blocks of device alias file.

Cc: stable@kernel.org
Fixes: 128d333f0dff ("f2fs: introduce device aliasing file")
Signed-off-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/f2fs/file.c |    6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

--- a/fs/f2fs/file.c
+++ b/fs/f2fs/file.c
@@ -3083,6 +3083,9 @@ static int f2fs_ioc_defragment(struct fi
 	if (f2fs_readonly(sbi->sb))
 		return -EROFS;
 
+	if (IS_DEVICE_ALIASING(inode))
+		return -EOPNOTSUPP;
+
 	if (copy_from_user(&range, (struct f2fs_defragment __user *)arg,
 							sizeof(range)))
 		return -EFAULT;
@@ -3135,7 +3138,8 @@ static int f2fs_move_file_range(struct f
 	if (!S_ISREG(src->i_mode) || !S_ISREG(dst->i_mode))
 		return -EINVAL;
 
-	if (IS_ENCRYPTED(src) || IS_ENCRYPTED(dst))
+	if (IS_ENCRYPTED(src) || IS_ENCRYPTED(dst) ||
+		IS_DEVICE_ALIASING(src) || IS_DEVICE_ALIASING(dst))
 		return -EOPNOTSUPP;
 
 	if (pos_out < 0 || pos_in < 0)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 450/556] f2fs: validate MOVE_RANGE destination size
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (448 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 449/556] f2fs: fix to avoid move_range and defragment on device_alias file Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 451/556] f2fs: dirty directory inodes on mtime/ctime update Greg Kroah-Hartman
                   ` (118 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Wenjie Qi, Chao Yu,
	Jaegeuk Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wenjie Qi <qwjhust@gmail.com>

commit e533889fc26aea0cd83c90327063f272061dd820 upstream.

F2FS_IOC_MOVE_RANGE checks the source range, but not the destination end
before updating i_size. A source hole can expose this: __clone_blkaddrs()
skips NULL_ADDR entries and returns success, so the caller can still extend
the destination inode with unchecked pos_out + len.

Reject destination overflow and use inode_newsize_ok() before extending
the destination inode.

Fixes: 4dd6f977fc77 ("f2fs: support an ioctl to move a range of data blocks")
Cc: stable@kernel.org
Assisted-by: Codex:gpt-5.5
Signed-off-by: Wenjie Qi <qiwenjie@xiaomi.com>
Reviewed-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/f2fs/file.c |   16 ++++++++++++----
 1 file changed, 12 insertions(+), 4 deletions(-)

--- a/fs/f2fs/file.c
+++ b/fs/f2fs/file.c
@@ -3124,8 +3124,9 @@ static int f2fs_move_file_range(struct f
 	struct inode *dst = file_inode(file_out);
 	struct f2fs_sb_info *sbi = F2FS_I_SB(src);
 	struct f2fs_lock_context lc;
-	size_t olen = len, dst_max_i_size = 0;
-	size_t dst_osize;
+	size_t olen = len;
+	loff_t dst_max_i_size = 0;
+	loff_t dst_osize, dst_end;
 	int ret;
 
 	if (file_in->f_path.mnt != file_out->f_path.mnt ||
@@ -3183,8 +3184,15 @@ static int f2fs_move_file_range(struct f
 	}
 
 	dst_osize = dst->i_size;
-	if (pos_out + olen > dst->i_size)
-		dst_max_i_size = pos_out + olen;
+	if (olen > LLONG_MAX - pos_out)
+		goto out_unlock;
+	dst_end = pos_out + olen;
+	if (dst_end > dst->i_size) {
+		ret = inode_newsize_ok(dst, dst_end);
+		if (ret)
+			goto out_unlock;
+		dst_max_i_size = dst_end;
+	}
 
 	/* verify the end result is block aligned */
 	if (!IS_ALIGNED(pos_in, F2FS_BLKSIZE) ||



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 451/556] f2fs: dirty directory inodes on mtime/ctime update
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (449 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 450/556] f2fs: validate MOVE_RANGE destination size Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 452/556] f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set() Greg Kroah-Hartman
                   ` (117 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Joanne Chang, Chao Yu, Jaegeuk Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Joanne Chang <joannechien@google.com>

commit 9ec09d5f4b317a417c8655c14056f70cbe71eb6c upstream.

Xfstests generic/547 sometimes fail with mismatched directory metadata
before and after a power failure. This happens because when a directory
entry is added, renamed, or deleted, its mtime and ctime are updated and
the inode is marked dirty via
f2fs_mark_inode_dirty_sync(dir, sync=false). The sync=false flag means
the dirty inode is not added to the global DIRTY_META list. Therefore,
subsequent checkpoints skip flushing these updated directory blocks,
causing directory timestamps to revert to stale values after a sudden
power failure.

Address this by changing the dirtying parameter to sync=true during
directory entry mutations and renames. This forces F2FS to immediately
queue the updated directory blocks on the global DIRTY_META list,
ensuring timestamps are committed to checkpoints.

Fixes: 7c45729a4d6d ("f2fs: keep dirty inodes selectively for checkpoint")
Cc: stable@vger.kernel.org
Signed-off-by: Joanne Chang <joannechien@google.com>
Reviewed-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/f2fs/dir.c    |    6 +++---
 fs/f2fs/inline.c |    2 +-
 fs/f2fs/namei.c  |    6 +++---
 3 files changed, 7 insertions(+), 7 deletions(-)

--- a/fs/f2fs/dir.c
+++ b/fs/f2fs/dir.c
@@ -460,7 +460,7 @@ void f2fs_set_link(struct inode *dir, st
 	folio_mark_dirty(folio);
 
 	inode_set_mtime_to_ts(dir, inode_set_ctime_current(dir));
-	f2fs_mark_inode_dirty_sync(dir, false);
+	f2fs_mark_inode_dirty_sync(dir, true);
 	f2fs_folio_put(folio, true);
 }
 
@@ -615,7 +615,7 @@ void f2fs_update_parent_metadata(struct
 		clear_inode_flag(inode, FI_NEW_INODE);
 	}
 	inode_set_mtime_to_ts(dir, inode_set_ctime_current(dir));
-	f2fs_mark_inode_dirty_sync(dir, false);
+	f2fs_mark_inode_dirty_sync(dir, true);
 
 	if (F2FS_I(dir)->i_current_depth != current_depth)
 		f2fs_i_depth_write(dir, current_depth);
@@ -927,7 +927,7 @@ void f2fs_delete_entry(struct f2fs_dir_e
 	f2fs_folio_put(folio, true);
 
 	inode_set_mtime_to_ts(dir, inode_set_ctime_current(dir));
-	f2fs_mark_inode_dirty_sync(dir, false);
+	f2fs_mark_inode_dirty_sync(dir, true);
 
 	if (inode)
 		f2fs_drop_nlink(dir, inode);
--- a/fs/f2fs/inline.c
+++ b/fs/f2fs/inline.c
@@ -732,7 +732,7 @@ void f2fs_delete_inline_entry(struct f2f
 	f2fs_folio_put(folio, true);
 
 	inode_set_mtime_to_ts(dir, inode_set_ctime_current(dir));
-	f2fs_mark_inode_dirty_sync(dir, false);
+	f2fs_mark_inode_dirty_sync(dir, true);
 
 	if (inode)
 		f2fs_drop_nlink(dir, inode);
--- a/fs/f2fs/namei.c
+++ b/fs/f2fs/namei.c
@@ -1077,7 +1077,7 @@ static int f2fs_rename(struct mnt_idmap
 	f2fs_up_write(&F2FS_I(old_inode)->i_sem);
 
 	inode_set_ctime_current(old_inode);
-	f2fs_mark_inode_dirty_sync(old_inode, false);
+	f2fs_mark_inode_dirty_sync(old_inode, true);
 
 	f2fs_delete_entry(old_entry, old_folio, old_dir, NULL);
 	old_folio = NULL;
@@ -1247,7 +1247,7 @@ static int f2fs_cross_rename(struct inod
 		f2fs_i_links_write(old_dir, old_nlink > 0);
 		f2fs_up_write(&F2FS_I(old_dir)->i_sem);
 	}
-	f2fs_mark_inode_dirty_sync(old_dir, false);
+	f2fs_mark_inode_dirty_sync(old_dir, true);
 
 	/* update directory entry info of new dir inode */
 	f2fs_set_link(new_dir, new_entry, new_folio, old_inode);
@@ -1266,7 +1266,7 @@ static int f2fs_cross_rename(struct inod
 		f2fs_i_links_write(new_dir, new_nlink > 0);
 		f2fs_up_write(&F2FS_I(new_dir)->i_sem);
 	}
-	f2fs_mark_inode_dirty_sync(new_dir, false);
+	f2fs_mark_inode_dirty_sync(new_dir, true);
 
 	if (F2FS_OPTION(sbi).fsync_mode == FSYNC_MODE_STRICT) {
 		f2fs_add_ino_entry(sbi, old_dir->i_ino, TRANS_DIR_INO);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 452/556] f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (450 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 451/556] f2fs: dirty directory inodes on mtime/ctime update Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 453/556] f2fs: return writeback error from collapse range Greg Kroah-Hartman
                   ` (116 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Zhan Xusheng, Chao Yu, Jaegeuk Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhan Xusheng <zhanxusheng1024@gmail.com>

commit a54ffce4637acb0db8e695188a6c7f99f14c3576 upstream.

f2fs_xattr_advise_set() calls inode_owner_or_capable() with &nop_mnt_idmap
before allowing the "system.advise" xattr to be set, instead of the idmap
that the VFS passes to the ->set() handler.

f2fs supports idmapped mounts, so on such a mount this checks the caller's
fsuid against the unmapped on-disk owner rather than the mapped owner: the
actual owner can be wrongly denied with -EPERM and an unrelated caller
wrongly allowed.  Pass the handler's idmap instead.

Fixes: 01beba7957a2 ("fs: port inode_owner_or_capable() to mnt_idmap")
Cc: stable@vger.kernel.org
Signed-off-by: Zhan Xusheng <zhanxusheng@xiaomi.com>
Reviewed-by: Chao Yu <chao@kernel.org>
Acked-by: Christian Brauner (Amutable) <braurg>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/f2fs/xattr.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/fs/f2fs/xattr.c
+++ b/fs/f2fs/xattr.c
@@ -119,7 +119,7 @@ static int f2fs_xattr_advise_set(const s
 	unsigned char old_advise = F2FS_I(inode)->i_advise;
 	unsigned char new_advise;
 
-	if (!inode_owner_or_capable(&nop_mnt_idmap, inode))
+	if (!inode_owner_or_capable(idmap, inode))
 		return -EPERM;
 	if (value == NULL)
 		return -EINVAL;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 453/556] f2fs: return writeback error from collapse range
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (451 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 452/556] f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set() Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 454/556] f2fs: limit recovery filename logging to stored length Greg Kroah-Hartman
                   ` (115 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Wenjie Qi, Chao Yu,
	Jaegeuk Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wenjie Qi <qwjhust@gmail.com>

commit f8a4108800254d6f7b2755515fbbd9d0caac561e upstream.

f2fs_collapse_range() writes back pages moved by f2fs_do_collapse(),
but ignores the return value. If writeback fails, the ioctl can still
truncate page cache, shrink blocks, and report success.

Return the error before truncating page cache or updating the file size.

Fixes: b4ace3370324 ("f2fs: support FALLOC_FL_COLLAPSE_RANGE")
Cc: stable@kernel.org
Assisted-by: Codex:gpt-5.5
Signed-off-by: Wenjie Qi <qiwenjie@xiaomi.com>
Reviewed-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/f2fs/file.c |    5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

--- a/fs/f2fs/file.c
+++ b/fs/f2fs/file.c
@@ -1617,11 +1617,14 @@ static int f2fs_collapse_range(struct in
 
 	/* write out all moved pages, if possible */
 	filemap_invalidate_lock(inode->i_mapping);
-	filemap_write_and_wait_range(inode->i_mapping, offset, LLONG_MAX);
+	ret = filemap_write_and_wait_range(inode->i_mapping, offset, LLONG_MAX);
+	if (ret)
+		goto out_unlock;
 	truncate_pagecache(inode, offset);
 
 	new_size = i_size_read(inode) - len;
 	ret = f2fs_truncate_blocks(inode, new_size, true);
+out_unlock:
 	filemap_invalidate_unlock(inode->i_mapping);
 	if (!ret)
 		f2fs_i_size_write(inode, new_size);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 454/556] f2fs: limit recovery filename logging to stored length
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (452 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 453/556] f2fs: return writeback error from collapse range Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 455/556] f2fs: dont drop the top folio order in the f2fs_iostat tracepoint Greg Kroah-Hartman
                   ` (114 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Wenjie Qi, Chao Yu,
	Jaegeuk Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wenjie Qi <qwjhust@gmail.com>

commit 01027b2fcb74dade59fb833b51023f6593b6a9a2 upstream.

F2FS stores recovery filenames as a length plus a fixed-size i_name
buffer.  The buffer is not NUL-terminated, but recover_inode() and
recover_dentry() print it with %s.

For a 255-byte filename, recovery logging can read past i_name into the
following raw inode fields.

Print the name with a precision bounded by i_namelen and F2FS_NAME_LEN.

Fixes: f356fe0cba0e ("f2fs: add debug msgs in the recovery routine")
Cc: stable@kernel.org
Assisted-by: Codex:gpt-5.5
Signed-off-by: Wenjie Qi <qiwenjie@xiaomi.com>
Reviewed-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/f2fs/recovery.c |   41 +++++++++++++++++++++++++++--------------
 1 file changed, 27 insertions(+), 14 deletions(-)

--- a/fs/f2fs/recovery.c
+++ b/fs/f2fs/recovery.c
@@ -158,6 +158,22 @@ static int init_recovered_filename(const
 	return 0;
 }
 
+static const char *recover_printable_name(struct inode *inode,
+					  struct f2fs_inode *raw,
+					  int *name_len)
+{
+	static const char encrypted_name[] = "<encrypted>";
+
+	if (file_enc_name(inode)) {
+		*name_len = sizeof(encrypted_name) - 1;
+		return encrypted_name;
+	}
+
+	*name_len = min_t(unsigned int, le32_to_cpu(raw->i_namelen),
+			  F2FS_NAME_LEN);
+	return raw->i_name;
+}
+
 static int recover_dentry(struct inode *inode, struct folio *ifolio,
 						struct list_head *dir_list)
 {
@@ -170,7 +186,8 @@ static int recover_dentry(struct inode *
 	struct inode *dir, *einode;
 	struct fsync_inode_entry *entry;
 	int err = 0;
-	char *name;
+	const char *name;
+	int name_len;
 
 	entry = get_fsync_inode(dir_list, pino);
 	if (!entry) {
@@ -229,12 +246,9 @@ retry:
 out_put:
 	f2fs_folio_put(folio, false);
 out:
-	if (file_enc_name(inode))
-		name = "<encrypted>";
-	else
-		name = raw_inode->i_name;
-	f2fs_notice(F2FS_I_SB(inode), "%s: ino = %x, name = %s, dir = %llu, err = %d",
-		    __func__, ino_of_node(ifolio), name,
+	name = recover_printable_name(inode, raw_inode, &name_len);
+	f2fs_notice(F2FS_I_SB(inode), "%s: ino = %x, name = %.*s, dir = %llu, err = %d",
+		    __func__, ino_of_node(ifolio), name_len, name,
 		    IS_ERR(dir) ? 0 : dir->i_ino, err);
 	return err;
 }
@@ -282,7 +296,8 @@ static int recover_inode(struct inode *i
 {
 	struct f2fs_inode *raw = F2FS_INODE(folio);
 	struct f2fs_inode_info *fi = F2FS_I(inode);
-	char *name;
+	const char *name;
+	int name_len;
 	int err;
 
 	inode->i_mode = le16_to_cpu(raw->i_mode);
@@ -331,13 +346,11 @@ static int recover_inode(struct inode *i
 
 	f2fs_mark_inode_dirty_sync(inode, true);
 
-	if (file_enc_name(inode))
-		name = "<encrypted>";
-	else
-		name = F2FS_INODE(folio)->i_name;
+	name = recover_printable_name(inode, raw, &name_len);
 
-	f2fs_notice(F2FS_I_SB(inode), "recover_inode: ino = %x, name = %s, inline = %x",
-		    ino_of_node(folio), name, raw->i_inline);
+	f2fs_notice(F2FS_I_SB(inode), "%s: ino = %x, name = %.*s, inline = %x",
+		    __func__, ino_of_node(folio), name_len, name,
+		    raw->i_inline);
 	return 0;
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 455/556] f2fs: dont drop the top folio order in the f2fs_iostat tracepoint
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (453 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 454/556] f2fs: limit recovery filename logging to stored length Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 456/556] f2fs: fix to avoid potential section-unaligned pinfile Greg Kroah-Hartman
                   ` (113 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Zhan Xusheng, Chao Yu, Jaegeuk Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhan Xusheng <zhanxusheng1024@gmail.com>

commit 575f6f8ef2abe8552af96e42c65d70964db53563 upstream.

The f2fs_iostat tracepoint stores the per-order read folio counts in a
fixed-size array and prints a fixed number of buckets, both hardcoded to
11. The sysfs iostat accounting array is instead sized by NR_PAGE_ORDERS
(= MAX_PAGE_ORDER + 1), which is not always 11:

	arm64 16K pages -> MAX_PAGE_ORDER 11 -> NR_PAGE_ORDERS 12
	arm64 64K pages -> MAX_PAGE_ORDER 13 -> NR_PAGE_ORDERS 14

f2fs enables large folios for immutable, non-compressed files, and the
read folio order is bounded by MAX_PAGECACHE_ORDER, i.e.
min(MAX_XAS_ORDER, PREFERRED_MAX_PAGECACHE_ORDER). With THP enabled this
reaches order 11 on 16K/64K base-page kernels (MAX_XAS_ORDER caps it at
11). So an order-11 read folio is possible there and is accounted into
index 11 of the array.

On those configurations the sysfs file reports the order-11 count
correctly, but the tracepoint silently drops it: the memcpy is capped at
min(NR_PAGE_ORDERS, 11), so index 11 is never copied and the trace
disagrees with sysfs. There is no memory-safety issue, only the order-11
bucket missing from the trace; 4K-page kernels (NR_PAGE_ORDERS == 11,
max order <= 9) are unaffected.

Size the array and the printed buckets by a ceiling that covers the
largest possible NR_PAGE_ORDERS (14) with headroom, and add a
BUILD_BUG_ON() so any future growth of NR_PAGE_ORDERS fails the build
loudly instead of silently truncating again. The human-readable
"order=count" output is preserved.

Fixes: cb8ff3ead9a3 ("f2fs: add page-order information for large folio reads in iostat")
Cc: stable@vger.kernel.org
Signed-off-by: Zhan Xusheng <zhanxusheng@xiaomi.com>
Reviewed-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/f2fs/iostat.c            |  6 ++++++
 include/trace/events/f2fs.h | 20 ++++++++++++++++----
 2 files changed, 22 insertions(+), 4 deletions(-)

diff --git a/fs/f2fs/iostat.c b/fs/f2fs/iostat.c
index ae265e3e9b2c..12d4e18a6a50 100644
--- a/fs/f2fs/iostat.c
+++ b/fs/f2fs/iostat.c
@@ -332,6 +332,12 @@ void f2fs_destroy_iostat_processing(void)
 
 int f2fs_init_iostat(struct f2fs_sb_info *sbi)
 {
+	/*
+	 * The f2fs_iostat tracepoint emits a fixed number of read folio order
+	 * buckets; make sure every order fits so none is silently dropped.
+	 */
+	BUILD_BUG_ON(NR_PAGE_ORDERS > F2FS_IOSTAT_RD_FOLIO_ORDERS);
+
 	/* init iostat info */
 	spin_lock_init(&sbi->iostat_lock);
 	spin_lock_init(&sbi->iostat_lat_lock);
diff --git a/include/trace/events/f2fs.h b/include/trace/events/f2fs.h
index 270c1a2c24c4..1dd9fc5afc46 100644
--- a/include/trace/events/f2fs.h
+++ b/include/trace/events/f2fs.h
@@ -2114,6 +2114,14 @@ DEFINE_EVENT(f2fs_zip_end, f2fs_decompress_pages_end,
 );
 
 #ifdef CONFIG_F2FS_IOSTAT
+/*
+ * Number of read folio order buckets emitted by the f2fs_iostat tracepoint.
+ * TP_printk() cannot loop, so the field count is fixed here and must be >=
+ * the largest possible NR_PAGE_ORDERS (14 on arm64 with 64K pages). The
+ * BUILD_BUG_ON() in f2fs_update_read_folio_count() enforces this.
+ */
+#define F2FS_IOSTAT_RD_FOLIO_ORDERS	16
+
 TRACE_EVENT(f2fs_iostat,
 
 	TP_PROTO(struct f2fs_sb_info *sbi, unsigned long long *iostat,
@@ -2151,7 +2159,7 @@ TRACE_EVENT(f2fs_iostat,
 		__field(unsigned long long,	fs_mrio)
 		__field(unsigned long long,	fs_discard)
 		__field(unsigned long long,	fs_reset_zone)
-		__array(unsigned long long,	read_folio_count, 11)
+		__array(unsigned long long,	read_folio_count, F2FS_IOSTAT_RD_FOLIO_ORDERS)
 	),
 
 	TP_fast_assign(
@@ -2186,7 +2194,8 @@ TRACE_EVENT(f2fs_iostat,
 		__entry->fs_reset_zone	= iostat[FS_ZONE_RESET_IO];
 		memset(__entry->read_folio_count, 0, sizeof(__entry->read_folio_count));
 		memcpy(__entry->read_folio_count, read_folio_count,
-				sizeof(unsigned long long) * min_t(int, NR_PAGE_ORDERS, 11));
+				sizeof(unsigned long long) *
+				min_t(int, NR_PAGE_ORDERS, F2FS_IOSTAT_RD_FOLIO_ORDERS));
 	),
 
 	TP_printk("dev = (%d,%d), "
@@ -2201,7 +2210,8 @@ TRACE_EVENT(f2fs_iostat,
 		"fs [data=%llu, (gc_data=%llu, cdata=%llu), "
 		"node=%llu, meta=%llu], "
 		"read_folio_count [0=%llu, 1=%llu, 2=%llu, 3=%llu, 4=%llu, "
-		"5=%llu, 6=%llu, 7=%llu, 8=%llu, 9=%llu, 10=%llu]",
+		"5=%llu, 6=%llu, 7=%llu, 8=%llu, 9=%llu, 10=%llu, 11=%llu, "
+		"12=%llu, 13=%llu, 14=%llu, 15=%llu]",
 		show_dev(__entry->dev), __entry->app_wio, __entry->app_dio,
 		__entry->app_bio, __entry->app_mio, __entry->app_bcdio,
 		__entry->app_mcdio, __entry->fs_dio, __entry->fs_cdio,
@@ -2218,7 +2228,9 @@ TRACE_EVENT(f2fs_iostat,
 		__entry->read_folio_count[4], __entry->read_folio_count[5],
 		__entry->read_folio_count[6], __entry->read_folio_count[7],
 		__entry->read_folio_count[8], __entry->read_folio_count[9],
-		__entry->read_folio_count[10])
+		__entry->read_folio_count[10], __entry->read_folio_count[11],
+		__entry->read_folio_count[12], __entry->read_folio_count[13],
+		__entry->read_folio_count[14], __entry->read_folio_count[15])
 );
 
 #ifndef __F2FS_IOSTAT_LATENCY_TYPE
-- 
2.55.0




^ permalink raw reply related	[flat|nested] 570+ messages in thread

* [PATCH 7.2 456/556] f2fs: fix to avoid potential section-unaligned pinfile
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (454 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 455/556] f2fs: dont drop the top folio order in the f2fs_iostat tracepoint Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 457/556] f2fs: embed f2fs_gc_kthread in f2fs_sb_info Greg Kroah-Hartman
                   ` (112 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, stable, Daeho Jeong, Chao Yu,
	Jaegeuk Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chao Yu <chao@kernel.org>

commit d0a481fad5c7a3a56ecf54a099651216869f4d0a upstream.

Blocks of pinfile may not aligned to section size due to wrong use
on pinfile, result in heavy overhead of GC, let avoid this by
adding additional check condition in f2fs_setattr().

- truncate -s 8mb pinfile
: random checkpoint may persist filesize w/ inode
- fallocate -o 0 -l 8mb pinfile
 - f2fs_fallocate
  - f2fs_expand_inode_data
   - f2fs_allocate_pinning_section
   - f2fs_map_blocks
    - f2fs_map_lock
    - __allocate_data_block
    - file_need_truncate
    : w/ FADVISE_TRUNC_BIT, we can expect unaligned mapping can be
      truncated while open() if f2fs is not umount abnormally
    - f2fs_map_unlock
    : following f2fs checkpoint and sudden power-cut

- mount
- open pinfile
 - f2fs_file_open
  - finish_preallocate_blocks
   - truncate_setsize
   : filesize is 8mb
   - f2fs_truncate
   : can only truncate block outside filesize, rather than truncating
     unaligned blocks inside filesize

Fixes: f5a53edcf01e ("f2fs: support aligned pinned file")
Cc: stable@kernel.org
Cc: Daeho Jeong <daehojeong@google.com>
Signed-off-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/f2fs/file.c |   28 +++++++++++++++++-----------
 1 file changed, 17 insertions(+), 11 deletions(-)

--- a/fs/f2fs/file.c
+++ b/fs/f2fs/file.c
@@ -1107,17 +1107,23 @@ int f2fs_setattr(struct mnt_idmap *idmap
 			!IS_ALIGNED(attr->ia_size,
 			F2FS_BLK_TO_BYTES(fi->i_cluster_size)))
 			return -EINVAL;
-		/*
-		 * To prevent scattered pin block generation, we don't allow
-		 * smaller/equal size unaligned truncation for pinned file.
-		 * We only support overwrite IO to pinned file, so don't
-		 * care about larger size truncation.
-		 */
-		if (f2fs_is_pinned_file(inode) &&
-			attr->ia_size <= i_size_read(inode) &&
-			!IS_ALIGNED(attr->ia_size,
-			F2FS_BLK_TO_BYTES(CAP_BLKS_PER_SEC(sbi))))
-			return -EINVAL;
+
+		if (f2fs_is_pinned_file(inode)) {
+			/*
+			 * It may break section-aligned fallocate recovery
+			 * mechanism, so do not allow larger size truncation.
+			 */
+			if (attr->ia_size > i_size_read(inode))
+				return -EINVAL;
+			/*
+			 * To prevent scattered pin block generation, we don't
+			 * allow smaller/equal size unaligned truncation for
+			 * pinned file.
+			 */
+			else if (!IS_ALIGNED(attr->ia_size,
+				F2FS_BLK_TO_BYTES(CAP_BLKS_PER_SEC(sbi))))
+				return -EINVAL;
+		}
 	}
 
 	if (is_quota_modification(idmap, inode, attr)) {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 457/556] f2fs: embed f2fs_gc_kthread in f2fs_sb_info
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (455 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 456/556] f2fs: fix to avoid potential section-unaligned pinfile Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 458/556] f2fs: fix dentry folio leak in find_in_level Greg Kroah-Hartman
                   ` (111 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Chao Yu, Jaegeuk Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chao Yu <chao@kernel.org>

commit 3d7bca9d583793bb7d0bac0d95a24ddd2e129eed upstream.

Instead of allocating f2fs_gc_kthread dynamically, embed it in
f2fs_sb_info. This simplifies lifetime management and prepares for
fixing race conditions during teardown.

- __sbi_store			- remount|shutdown
				 - f2fs_stop_gc_thread
 - access sbi->gc_thread
				  - sbi->gc_thread = NULL
 - access sbi->gc_thread->f2fs_gc_task

Fixes: 52190933c37a ("f2fs: sysfs: introduce critical_task_priority")
Fixes: 7950e9ac638e ("f2fs: stop gc/discard thread after fs shutdown")
Cc: stable@kernel.org
Signed-off-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/f2fs/debug.c   |    4 ----
 fs/f2fs/f2fs.h    |   29 ++++++++++++++++++++++++++++-
 fs/f2fs/gc.c      |   36 +++++++++++++++---------------------
 fs/f2fs/gc.h      |   29 ++---------------------------
 fs/f2fs/segment.c |    9 ++++-----
 fs/f2fs/super.c   |    4 ++--
 fs/f2fs/sysfs.c   |   22 +++++++++++-----------
 7 files changed, 62 insertions(+), 71 deletions(-)

--- a/fs/f2fs/debug.c
+++ b/fs/f2fs/debug.c
@@ -352,10 +352,6 @@ static void update_mem_info(struct f2fs_
 get_cache:
 	si->cache_mem = 0;
 
-	/* build gc */
-	if (sbi->gc_thread)
-		si->cache_mem += sizeof(struct f2fs_gc_kthread);
-
 	/* build merge flush thread */
 	if (SM_I(sbi)->fcc_info)
 		si->cache_mem += sizeof(struct flush_cmd_control);
--- a/fs/f2fs/f2fs.h
+++ b/fs/f2fs/f2fs.h
@@ -1748,6 +1748,33 @@ struct decompress_io_ctx {
 #define MAX_COMPRESS_LOG_SIZE		8
 #define MAX_COMPRESS_WINDOW_SIZE(log_size)	((PAGE_SIZE) << (log_size))
 
+struct f2fs_gc_kthread {
+	struct task_struct *f2fs_gc_task;
+	wait_queue_head_t gc_wait_queue_head;
+
+	/* for gc sleep time */
+	unsigned int urgent_sleep_time;
+	unsigned int min_sleep_time;
+	unsigned int max_sleep_time;
+	unsigned int no_gc_sleep_time;
+
+	/* for changing gc mode */
+	bool gc_wake;
+
+	/* for GC_MERGE mount option */
+	wait_queue_head_t fggc_wq;		/*
+						 * caller of f2fs_balance_fs()
+						 * will wait on this wait queue.
+						 */
+
+	/* for gc control for zoned devices */
+	unsigned int no_zoned_gc_percent;
+	unsigned int boost_zoned_gc_percent;
+	unsigned int valid_thresh_ratio;
+	unsigned int boost_gc_multiple;
+	unsigned int boost_gc_greedy;
+};
+
 struct f2fs_sb_info {
 	struct super_block *sb;			/* pointer to VFS super block */
 	struct proc_dir_entry *s_proc;		/* proc entry */
@@ -1883,7 +1910,7 @@ struct f2fs_sb_info {
 						 * semaphore for GC, avoid
 						 * race between GC and GC or CP
 						 */
-	struct f2fs_gc_kthread	*gc_thread;	/* GC thread */
+	struct f2fs_gc_kthread gc_thread;	/* GC thread */
 	struct atgc_management am;		/* atgc management */
 	unsigned int cur_victim_sec;		/* current victim section num */
 	unsigned int gc_mode;			/* current GC state */
--- a/fs/f2fs/gc.c
+++ b/fs/f2fs/gc.c
@@ -31,9 +31,9 @@ static unsigned int count_bits(const uns
 static int gc_thread_func(void *data)
 {
 	struct f2fs_sb_info *sbi = data;
-	struct f2fs_gc_kthread *gc_th = sbi->gc_thread;
-	wait_queue_head_t *wq = &sbi->gc_thread->gc_wait_queue_head;
-	wait_queue_head_t *fggc_wq = &sbi->gc_thread->fggc_wq;
+	struct f2fs_gc_kthread *gc_th = &sbi->gc_thread;
+	wait_queue_head_t *wq = &sbi->gc_thread.gc_wait_queue_head;
+	wait_queue_head_t *fggc_wq = &sbi->gc_thread.fggc_wq;
 	unsigned int wait_ms;
 	struct f2fs_gc_control gc_control = {
 		.victim_segno = NULL_SEGNO,
@@ -193,13 +193,9 @@ next:
 
 int f2fs_start_gc_thread(struct f2fs_sb_info *sbi)
 {
-	struct f2fs_gc_kthread *gc_th;
+	struct f2fs_gc_kthread *gc_th = &sbi->gc_thread;
 	dev_t dev = sbi->sb->s_bdev->bd_dev;
 
-	gc_th = f2fs_kmalloc(sbi, sizeof(struct f2fs_gc_kthread), GFP_KERNEL);
-	if (!gc_th)
-		return -ENOMEM;
-
 	gc_th->urgent_sleep_time = DEF_GC_THREAD_URGENT_SLEEP_TIME;
 	gc_th->valid_thresh_ratio = DEF_GC_THREAD_VALID_THRESH_RATIO;
 	gc_th->boost_gc_multiple = BOOST_GC_MULTIPLE;
@@ -221,16 +217,14 @@ int f2fs_start_gc_thread(struct f2fs_sb_
 
 	gc_th->gc_wake = false;
 
-	sbi->gc_thread = gc_th;
-	init_waitqueue_head(&sbi->gc_thread->gc_wait_queue_head);
-	init_waitqueue_head(&sbi->gc_thread->fggc_wq);
-	sbi->gc_thread->f2fs_gc_task = kthread_run(gc_thread_func, sbi,
+	init_waitqueue_head(&gc_th->gc_wait_queue_head);
+	init_waitqueue_head(&gc_th->fggc_wq);
+	gc_th->f2fs_gc_task = kthread_run(gc_thread_func, sbi,
 			"f2fs_gc-%u:%u", MAJOR(dev), MINOR(dev));
 	if (IS_ERR(gc_th->f2fs_gc_task)) {
 		int err = PTR_ERR(gc_th->f2fs_gc_task);
 
-		kfree(gc_th);
-		sbi->gc_thread = NULL;
+		gc_th->f2fs_gc_task = NULL;
 		return err;
 	}
 
@@ -241,14 +235,14 @@ int f2fs_start_gc_thread(struct f2fs_sb_
 
 void f2fs_stop_gc_thread(struct f2fs_sb_info *sbi)
 {
-	struct f2fs_gc_kthread *gc_th = sbi->gc_thread;
+	struct f2fs_gc_kthread *gc_th = &sbi->gc_thread;
 
-	if (!gc_th)
+	if (!gc_th->f2fs_gc_task)
 		return;
+
 	kthread_stop(gc_th->f2fs_gc_task);
+	gc_th->f2fs_gc_task = NULL;
 	wake_up_all(&gc_th->fggc_wq);
-	kfree(gc_th);
-	sbi->gc_thread = NULL;
 }
 
 static int select_gc_type(struct f2fs_sb_info *sbi, int gc_type)
@@ -796,7 +790,7 @@ int f2fs_get_victim(struct f2fs_sb_info
 	if (one_time) {
 		p.one_time_gc = one_time;
 		if (has_enough_free_secs(sbi, 0, NR_PERSISTENT_LOG))
-			valid_thresh_ratio = sbi->gc_thread->valid_thresh_ratio;
+			valid_thresh_ratio = sbi->gc_thread.valid_thresh_ratio;
 	}
 
 retry:
@@ -1807,9 +1801,9 @@ static int do_garbage_collect(struct f2f
 
 			if (f2fs_sb_has_blkzoned(sbi) &&
 					!has_enough_free_blocks(sbi,
-					sbi->gc_thread->boost_zoned_gc_percent))
+					sbi->gc_thread.boost_zoned_gc_percent))
 				window_granularity *=
-					sbi->gc_thread->boost_gc_multiple;
+					sbi->gc_thread.boost_gc_multiple;
 
 			end_segno = start_segno + window_granularity;
 		}
--- a/fs/f2fs/gc.h
+++ b/fs/f2fs/gc.h
@@ -45,32 +45,7 @@
 
 #define NR_GC_CHECKPOINT_SECS (3)	/* data/node/dentry sections */
 
-struct f2fs_gc_kthread {
-	struct task_struct *f2fs_gc_task;
-	wait_queue_head_t gc_wait_queue_head;
-
-	/* for gc sleep time */
-	unsigned int urgent_sleep_time;
-	unsigned int min_sleep_time;
-	unsigned int max_sleep_time;
-	unsigned int no_gc_sleep_time;
-
-	/* for changing gc mode */
-	bool gc_wake;
-
-	/* for GC_MERGE mount option */
-	wait_queue_head_t fggc_wq;		/*
-						 * caller of f2fs_balance_fs()
-						 * will wait on this wait queue.
-						 */
-
-	/* for gc control for zoned devices */
-	unsigned int no_zoned_gc_percent;
-	unsigned int boost_zoned_gc_percent;
-	unsigned int valid_thresh_ratio;
-	unsigned int boost_gc_multiple;
-	unsigned int boost_gc_greedy;
-};
+
 
 struct gc_inode_list {
 	struct list_head ilist;
@@ -197,6 +172,6 @@ static inline bool need_to_boost_gc(stru
 {
 	if (f2fs_sb_has_blkzoned(sbi))
 		return !has_enough_free_blocks(sbi,
-				sbi->gc_thread->boost_zoned_gc_percent);
+				sbi->gc_thread.boost_zoned_gc_percent);
 	return has_enough_invalid_blocks(sbi);
 }
--- a/fs/f2fs/segment.c
+++ b/fs/f2fs/segment.c
@@ -452,15 +452,14 @@ void f2fs_balance_fs(struct f2fs_sb_info
 	f2fs_submit_merged_write(sbi, DATA);
 	f2fs_submit_all_merged_ipu_writes(sbi);
 
-	if (test_opt(sbi, GC_MERGE) && sbi->gc_thread &&
-				sbi->gc_thread->f2fs_gc_task) {
+	if (test_opt(sbi, GC_MERGE) && sbi->gc_thread.f2fs_gc_task) {
 		DEFINE_WAIT(wait);
 
-		prepare_to_wait(&sbi->gc_thread->fggc_wq, &wait,
+		prepare_to_wait(&sbi->gc_thread.fggc_wq, &wait,
 					TASK_UNINTERRUPTIBLE);
-		wake_up(&sbi->gc_thread->gc_wait_queue_head);
+		wake_up(&sbi->gc_thread.gc_wait_queue_head);
 		io_schedule();
-		finish_wait(&sbi->gc_thread->fggc_wq, &wait);
+		finish_wait(&sbi->gc_thread.fggc_wq, &wait);
 	} else {
 		struct f2fs_gc_control gc_control = {
 			.victim_segno = NULL_SEGNO,
--- a/fs/f2fs/super.c
+++ b/fs/f2fs/super.c
@@ -2943,11 +2943,11 @@ static int __f2fs_remount(struct fs_cont
 	if ((flags & SB_RDONLY) ||
 			(F2FS_OPTION(sbi).bggc_mode == BGGC_MODE_OFF &&
 			!test_opt(sbi, GC_MERGE))) {
-		if (sbi->gc_thread) {
+		if (sbi->gc_thread.f2fs_gc_task) {
 			f2fs_stop_gc_thread(sbi);
 			need_restart_gc = true;
 		}
-	} else if (!sbi->gc_thread) {
+	} else if (!sbi->gc_thread.f2fs_gc_task) {
 		err = f2fs_start_gc_thread(sbi);
 		if (err)
 			goto restore_opts;
--- a/fs/f2fs/sysfs.c
+++ b/fs/f2fs/sysfs.c
@@ -75,7 +75,7 @@ static ssize_t f2fs_sbi_show(struct f2fs
 static unsigned char *__struct_ptr(struct f2fs_sb_info *sbi, int struct_type)
 {
 	if (struct_type == GC_THREAD)
-		return (unsigned char *)sbi->gc_thread;
+		return (unsigned char *)&sbi->gc_thread;
 	else if (struct_type == SM_INFO)
 		return (unsigned char *)SM_I(sbi);
 	else if (struct_type == DCC_INFO)
@@ -664,20 +664,20 @@ out:
 			sbi->gc_mode = GC_NORMAL;
 		} else if (t == 1) {
 			sbi->gc_mode = GC_URGENT_HIGH;
-			if (sbi->gc_thread) {
-				sbi->gc_thread->gc_wake = true;
+			if (sbi->gc_thread.f2fs_gc_task) {
+				sbi->gc_thread.gc_wake = true;
 				wake_up_interruptible_all(
-					&sbi->gc_thread->gc_wait_queue_head);
+					&sbi->gc_thread.gc_wait_queue_head);
 				wake_up_discard_thread(sbi, true);
 			}
 		} else if (t == 2) {
 			sbi->gc_mode = GC_URGENT_LOW;
 		} else if (t == 3) {
 			sbi->gc_mode = GC_URGENT_MID;
-			if (sbi->gc_thread) {
-				sbi->gc_thread->gc_wake = true;
+			if (sbi->gc_thread.f2fs_gc_task) {
+				sbi->gc_thread.gc_wake = true;
 				wake_up_interruptible_all(
-					&sbi->gc_thread->gc_wait_queue_head);
+					&sbi->gc_thread.gc_wait_queue_head);
 			}
 		} else {
 			return -EINVAL;
@@ -934,14 +934,14 @@ out:
 	if (!strcmp(a->attr.name, "gc_boost_gc_multiple")) {
 		if (t < 1 || t > SEGS_PER_SEC(sbi))
 			return -EINVAL;
-		sbi->gc_thread->boost_gc_multiple = (unsigned int)t;
+		sbi->gc_thread.boost_gc_multiple = (unsigned int)t;
 		return count;
 	}
 
 	if (!strcmp(a->attr.name, "gc_boost_gc_greedy")) {
 		if (t > GC_GREEDY)
 			return -EINVAL;
-		sbi->gc_thread->boost_gc_greedy = (unsigned int)t;
+		sbi->gc_thread.boost_gc_greedy = (unsigned int)t;
 		return count;
 	}
 
@@ -989,8 +989,8 @@ out:
 		if (sbi->cprc_info.f2fs_issue_ckpt)
 			set_user_nice(sbi->cprc_info.f2fs_issue_ckpt,
 					PRIO_TO_NICE(sbi->critical_task_priority));
-		if (sbi->gc_thread && sbi->gc_thread->f2fs_gc_task)
-			set_user_nice(sbi->gc_thread->f2fs_gc_task,
+		if (sbi->gc_thread.f2fs_gc_task)
+			set_user_nice(sbi->gc_thread.f2fs_gc_task,
 					PRIO_TO_NICE(sbi->critical_task_priority));
 		return count;
 	}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 458/556] f2fs: fix dentry folio leak in find_in_level
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (456 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 457/556] f2fs: embed f2fs_gc_kthread in f2fs_sb_info Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 459/556] f2fs: fix folio_nr_pages() race after put in large folio invalidate Greg Kroah-Hartman
                   ` (110 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Chao Yu, Guanghui Yang, Jaegeuk Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Guanghui Yang <3497809730@qq.com>

commit cca7d3e30bf30333314e31bc70b9a739f1342167 upstream.

find_in_level() gets a dentry folio with f2fs_find_data_folio() before
calling find_in_block().  If find_in_block() returns an error, the
function stores the error in res_folio and breaks out of the loop without
dropping the dentry folio.

This leaks the folio reference on the find_in_block() error path.  Drop
the dentry folio before returning the error to the caller.

Fixes: 7ad08a58bf67 ("f2fs: Handle casefolding with Encryption")
Cc: stable@vger.kernel.org
Reviewed-by: Chao Yu <chao@kernel.org>
Signed-off-by: Guanghui Yang <3497809730@qq.com>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/f2fs/dir.c |    1 +
 1 file changed, 1 insertion(+)

--- a/fs/f2fs/dir.c
+++ b/fs/f2fs/dir.c
@@ -320,6 +320,7 @@ start_find_bucket:
 
 		de = find_in_block(dir, dentry_folio, fname, &max_slots, use_hash);
 		if (IS_ERR(de)) {
+			f2fs_folio_put(dentry_folio, false);
 			*res_folio = ERR_CAST(de);
 			de = NULL;
 			break;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 459/556] f2fs: fix folio_nr_pages() race after put in large folio invalidate
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (457 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 458/556] f2fs: fix dentry folio leak in find_in_level Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 460/556] f2fs: avoid NULL checkpoint thread access in sysfs Greg Kroah-Hartman
                   ` (109 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, stable, Chao Yu, Zhaoyang Huang,
	Jaegeuk Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhaoyang Huang <zhaoyang.huang@unisoc.com>

commit 0dab71381f1b4d12dc2056f8bd5aaa9d93ce9082 upstream.

Our v6.18 based Android system is continuely suffering livelock and bad
page stat as shown in[1] which related to broken xarray slot status. By
investigating big folio operations within f2fs, we find below races and
fix it by get the nr_pages before drop the refcount and folio_lock.

f2fs_get_read_data_folio() calls f2fs_folio_put() before
folio_nr_pages() when invalidating a large folio from the page cache.
That unlocks the folio and drops the caller reference, leaving a window
where a concurrent truncate or folio split can shrink the compound folio
or free it before the invalidate range is computed. An undersized range
then leaves split sub-folios in mapping->i_pages, which can later
interact badly with truncate and reclaim (stale xarray entries and bad
page state when folio->mapping no longer matches the mapping being
truncated).

[1]
PID: 2594     TASK: ffffff8169b81580  CPU: 7    COMMAND: "Thread-3"
 #0 [ffffffc08ef2b8a0] xas_load at ffffffe52d1f42a4
 #1 [ffffffc08ef2b900] find_get_entries at ffffffe52c185798
 #2 [ffffffc08ef2bb60] truncate_inode_pages_range at ffffffe52c19e83c
 #3 [ffffffc08ef2bbc0] truncate_inode_pages_final at ffffffe52c19ec2c
 #4 [ffffffc08ef2bc20] f2fs_evict_inode at ffffffe52c4c8400
 #5 [ffffffc08ef2bcc0] evict at ffffffe52c2de9f4
 #6 [ffffffc08ef2bd00] iput at ffffffe52c2db1b4
 #7 [ffffffc08ef2bd30] dentry_unlink_inode at ffffffe52c2d7204
 #8 [ffffffc08ef2bd50] __dentry_kill at ffffffe52c2d3dcc
 #9 [ffffffc08ef2bd80] dput at ffffffe52c2d3c3c
 #10 [ffffffc08ef2bda0] __fput at ffffffe52c2b0a7c
 #11 [ffffffc08ef2bde0] ____fput at ffffffe52c2b1034
 #12 [ffffffc08ef2bdf0] task_work_run at ffffffe52beea200
 #13 [ffffffc08ef2be20] exit_to_user_mode_loop at ffffffe52bfbc17c
 #14 [ffffffc08ef2be80] el0_svc at ffffffe52d1f8e54
 #15 [ffffffc08ef2beb0] el0t_64_sync_handler at ffffffe52d1f8d10

Cc: stable@kernel.org
Fixes: 05e65c14ea59 ("f2fs: support large folio for immutable non-compressed case")
Reviewed-by: Chao Yu <chao@kernel.org>
Signed-off-by: Zhaoyang Huang <zhaoyang.huang@unisoc.com>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/f2fs/data.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/fs/f2fs/data.c b/fs/f2fs/data.c
index 62ea74e65db8..042ed8ad9cc3 100644
--- a/fs/f2fs/data.c
+++ b/fs/f2fs/data.c
@@ -1323,10 +1323,11 @@ struct folio *f2fs_get_read_data_folio(struct inode *inode, pgoff_t index,
 
 	if (folio_test_large(folio)) {
 		pgoff_t folio_index = mapping_align_index(mapping, index);
+		unsigned long nr_pages = folio_nr_pages(folio);
 
 		f2fs_folio_put(folio, true);
 		invalidate_inode_pages2_range(mapping, folio_index,
-				folio_index + folio_nr_pages(folio) - 1);
+				folio_index + nr_pages - 1);
 		f2fs_schedule_timeout(DEFAULT_SCHEDULE_TIMEOUT);
 		goto retry;
 	}
-- 
2.55.0




^ permalink raw reply related	[flat|nested] 570+ messages in thread

* [PATCH 7.2 460/556] f2fs: avoid NULL checkpoint thread access in sysfs
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (458 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 459/556] f2fs: fix folio_nr_pages() race after put in large folio invalidate Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 461/556] f2fs: fix to migrate all curseg types during free_segment_range Greg Kroah-Hartman
                   ` (108 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Wenjie Qi, Chao Yu,
	Jaegeuk Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wenjie Qi <qwjhust@gmail.com>

commit 5cb33b00c8fbb6e8f1fa3d281c3036d5f7c7c41f upstream.

checkpoint_merge can be enabled even when no checkpoint merge thread is
running. A read-only mount is one case: f2fs does not start
f2fs_issue_ckpt there, but ckpt_thread_ioprio is still writable through
sysfs.

The ckpt_thread_ioprio store path updates the saved ioprio value and,
when checkpoint_merge is enabled, calls set_task_ioprio() for the
checkpoint thread. If cprc->f2fs_issue_ckpt is NULL, that dereferences a
NULL task pointer.

Protect ckpt_thread_ioprio sysfs writes with s_umount as well, so the
checkpoint thread cannot disappear under the store path while updating
its ioprio.

Fixes: e65920661708 ("f2fs: add ckpt_thread_ioprio sysfs node")
Cc: stable@kernel.org
Signed-off-by: Wenjie Qi <qiwenjie@xiaomi.com>
Reviewed-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/f2fs/sysfs.c |    7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)

--- a/fs/f2fs/sysfs.c
+++ b/fs/f2fs/sysfs.c
@@ -557,7 +557,7 @@ out:
 			return -EINVAL;
 
 		cprc->ckpt_thread_ioprio = IOPRIO_PRIO_VALUE(class, level);
-		if (test_opt(sbi, MERGE_CHECKPOINT)) {
+		if (cprc->f2fs_issue_ckpt) {
 			ret = set_task_ioprio(cprc->f2fs_issue_ckpt,
 					cprc->ckpt_thread_ioprio);
 			if (ret)
@@ -1007,13 +1007,14 @@ static ssize_t f2fs_sbi_store(struct f2f
 	ssize_t ret;
 	bool gc_entry = (!strcmp(a->attr.name, "gc_urgent") ||
 					a->struct_type == GC_THREAD);
+	bool thread_entry = !strcmp(a->attr.name, "ckpt_thread_ioprio");
 
-	if (gc_entry) {
+	if (gc_entry || thread_entry) {
 		if (!down_read_trylock(&sbi->sb->s_umount))
 			return -EAGAIN;
 	}
 	ret = __sbi_store(a, sbi, buf, count);
-	if (gc_entry)
+	if (gc_entry || thread_entry)
 		up_read(&sbi->sb->s_umount);
 
 	return ret;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 461/556] f2fs: fix to migrate all curseg types during free_segment_range
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (459 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 460/556] f2fs: avoid NULL checkpoint thread access in sysfs Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 462/556] f2fs: fix to avoid potential deadloop in f2fs_fsync_node_pages() Greg Kroah-Hartman
                   ` (107 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Daeho Jeong, Sunmin Jeong, Chao Yu,
	Jaegeuk Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Daeho Jeong <daehojeong@google.com>

commit 8ec06f50ddd8d201bd7e55b896ae28ed9d4cb7d1 upstream.

In free_segment_range(), the curseg evacuation loop only iterates up to
NR_CURSEG_PERSIST_TYPE (0..5), missing non-persistent in-memory curseg
types such as CURSEG_COLD_DATA_PINNED and CURSEG_ALL_DATA_ATGC.

Even though these in-memory curseg types are not saved in the on-disk
checkpoint header, they still occupy active physical segments at runtime.
If an active in-memory curseg happens to be allocated within the segment
range being truncated during filesystem shrink, failing to evacuate it
will cause subsequent writes to the curseg attempting out-of-bounds I/O
on the truncated storage range.

Fix this by expanding the curseg evacuation loop upper bound to
NR_CURSEG_TYPE to ensure all active curseg types are safely migrated
out of the target range.

Fixes: d0b9e42ab615 ("f2fs: introduce inmem curseg")
Cc: stable@vger.kernel.org
Signed-off-by: Daeho Jeong <daehojeong@google.com>
Signed-off-by: Sunmin Jeong <s_min.jeong@samsung.com>
Reviewed-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/f2fs/gc.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/fs/f2fs/gc.c
+++ b/fs/f2fs/gc.c
@@ -2216,7 +2216,7 @@ static int free_segment_range(struct f2f
 	mutex_unlock(&DIRTY_I(sbi)->seglist_lock);
 
 	/* Move out cursegs from the target range */
-	for (type = CURSEG_HOT_DATA; type < NR_CURSEG_PERSIST_TYPE; type++) {
+	for (type = CURSEG_HOT_DATA; type < NR_CURSEG_TYPE; type++) {
 		err = f2fs_allocate_segment_for_resize(sbi, type, start, end);
 		if (err)
 			goto out;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 462/556] f2fs: fix to avoid potential deadloop in f2fs_fsync_node_pages()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (460 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 461/556] f2fs: fix to migrate all curseg types during free_segment_range Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 463/556] f2fs: fix i_size when pinned fallocate partially fails Greg Kroah-Hartman
                   ` (106 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Chao Yu, Jaegeuk Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chao Yu <chao@kernel.org>

commit ce366bfa821ec81dd45bde547ee31e659306cc61 upstream.

There is potential deadloop in race condition:

Thread A				Thread B
- fsync
 - f2fs_do_sync_file
  - f2fs_fsync_node_pages
   - last_fsync_dnode
    - folio_get(last_folio)
					- f2fs_setattr
					 - f2fs_truncate
					  - f2fs_truncate_blocks
					   - f2fs_do_truncate_blocks
					    - f2fs_truncate_inode_blocks
					     - truncate_dnode
					      - truncate_node
					       - invalidate_mapping_pages
					        - folio->mapping = NULL
   - is_node_folio alwasy return false
   - atomic && !marked is always true,
     then goto retry

Cc: stable@kernel.org
Fixes: 608514deba38 ("f2fs: set fsync mark only for the last dnode")
Signed-off-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/f2fs/node.c |    5 +++++
 1 file changed, 5 insertions(+)

--- a/fs/f2fs/node.c
+++ b/fs/f2fs/node.c
@@ -2009,6 +2009,11 @@ continue_unlock:
 		f2fs_debug(sbi, "Retry to write fsync mark: ino=%u, idx=%lx",
 			   ino, last_folio->index);
 		folio_lock(last_folio);
+		if (unlikely(!is_node_folio(last_folio))) {
+			f2fs_folio_put(last_folio, true);
+			ret = -EAGAIN;
+			goto out;
+		}
 		f2fs_folio_wait_writeback(last_folio, NODE, true, true);
 		folio_mark_dirty(last_folio);
 		folio_unlock(last_folio);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 463/556] f2fs: fix i_size when pinned fallocate partially fails
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (461 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 462/556] f2fs: fix to avoid potential deadloop in f2fs_fsync_node_pages() Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 464/556] f2fs: fix to return -EFSCORRUPTED in f2fs_get_node_info() correctly Greg Kroah-Hartman
                   ` (105 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Zhan Xusheng, Chao Yu, Jaegeuk Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhan Xusheng <zhanxusheng1024@gmail.com>

commit 0f448bb3767ef6119f5cdeabcae3f10d6e75aed6 upstream.

From: Zhan Xusheng <zhanxusheng@xiaomi.com>

Commit 4275b59673eb ("f2fs: fix to round down start offset of fallocate
for pin file") moved the allocation loop's start down to a section
boundary, but the error path still converts @expanded against @pg_start,
which holds the unrounded start.

@pg_start exists for that conversion: commit 88f2cfc5fa90 ("f2fs: fix to
update last i_size if fallocate partially succeeds") added it as an
immutable base because map.m_lblk moves every round.  Each round now maps
exactly sec_blks blocks starting from rounddown(pg_start, sec_blks), so
pg_start + expanded overshoots the last allocated block by
pg_start % sec_blks, and a partial failure leaves i_size covering a tail
that was never allocated.  Nothing corrects that afterwards either, since
file_dont_truncate() has already cleared FADVISE_TRUNC_BIT.

It needs a start offset that is not section aligned plus a fallocate that
hits ENOSPC partway, so the error path runs with expanded > 0.  On an
80 MiB image with 2 MiB sections:

  truncate -s 80M img
  mkfs.f2fs -s 1 -f img
  mount -o loop img /mnt
  touch /mnt/pinned
  f2fs_io pinfile set /mnt/pinned
  # 2093056 = block 511, so pg_start % sec_blks = 511
  f2fs_io fallocate 0 2093056 536870912 /mnt/pinned
  stat -c %s /mnt/pinned
  filefrag -v /mnt/pinned

The last extent ends at block 10737 either way.  Before, i_size is
46075904, block 11249, so 511 blocks of it were never allocated, and
filefrag does not mark the last extent eof.  After, i_size is 43982848,
block 10738, and eof is back.  A kernel from before that commit also
shows no overshoot.

Keep @pg_start pointing at where allocation actually begins.

Fixes: 4275b59673eb ("f2fs: fix to round down start offset of fallocate for pin file")
Cc: stable@vger.kernel.org
Signed-off-by: Zhan Xusheng <zhanxusheng@xiaomi.com>
Reviewed-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/f2fs/file.c |    5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

--- a/fs/f2fs/file.c
+++ b/fs/f2fs/file.c
@@ -1928,8 +1928,9 @@ static int f2fs_expand_inode_data(struct
 		block_t sec_len;
 
 		if (map.m_lblk % sec_blks) {
-			map.m_lblk = rounddown(map.m_lblk, sec_blks);
-			map.m_len = pg_end - map.m_lblk;
+			pg_start = rounddown(map.m_lblk, sec_blks);
+			map.m_lblk = pg_start;
+			map.m_len = pg_end - pg_start;
 			if (off_end)
 				map.m_len++;
 		}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 464/556] f2fs: fix to return -EFSCORRUPTED in f2fs_get_node_info() correctly
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (462 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 463/556] f2fs: fix i_size when pinned fallocate partially fails Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 465/556] f2fs: fix to off-by-one issue in f2fs_zero_post_eof_page() Greg Kroah-Hartman
                   ` (104 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Chao Yu, Jaegeuk Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chao Yu <chao@kernel.org>

commit 026d7aeadf27291f961893165edb6079a7078f6f upstream.

Otherwise, it will cache wrong nat info in cache.

Cc: stable@kernel.org
Fixes: 3cb396a2c790 ("f2fs: fix to do sanity check on nat entry of quota inode")
Signed-off-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/f2fs/node.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/fs/f2fs/node.c b/fs/f2fs/node.c
index 38917e4a7319..9775fa90636a 100644
--- a/fs/f2fs/node.c
+++ b/fs/f2fs/node.c
@@ -660,6 +660,7 @@ int f2fs_get_node_info(struct f2fs_sb_info *sbi, nid_t nid,
 			__builtin_return_address(0),
 			ni->ino, ni->nid, ni->blk_addr, ni->version, ni->flag);
 		f2fs_handle_error(sbi, ERROR_INCONSISTENT_NAT);
+		return -EFSCORRUPTED;
 	}
 
 	/* cache nat entry */
-- 
2.55.0




^ permalink raw reply related	[flat|nested] 570+ messages in thread

* [PATCH 7.2 465/556] f2fs: fix to off-by-one issue in f2fs_zero_post_eof_page()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (463 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 464/556] f2fs: fix to return -EFSCORRUPTED in f2fs_get_node_info() correctly Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 466/556] f2fs: fix to clear dirty flag on folio in error path Greg Kroah-Hartman
                   ` (103 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Chao Yu, Jaegeuk Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chao Yu <chao@kernel.org>

commit b2205d3cfd6c76fd5c5443ee9fdb498cfb0e1c66 upstream.

Otherwise, it will drop one more page after new_size which is not
necessary.

Cc: stable@kernel.org
Fixes: ba8dac350faf ("f2fs: fix to zero post-eof page")
Signed-off-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/f2fs/file.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/fs/f2fs/file.c
+++ b/fs/f2fs/file.c
@@ -50,7 +50,7 @@ static void f2fs_zero_post_eof_page(stru
 	if (lock)
 		filemap_invalidate_lock(inode->i_mapping);
 	/* zero or drop pages only in range of [old_size, new_size] */
-	truncate_inode_pages_range(inode->i_mapping, old_size, new_size);
+	truncate_inode_pages_range(inode->i_mapping, old_size, new_size - 1);
 	if (lock)
 		filemap_invalidate_unlock(inode->i_mapping);
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 466/556] f2fs: fix to clear dirty flag on folio in error path
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (464 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 465/556] f2fs: fix to off-by-one issue in f2fs_zero_post_eof_page() Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 467/556] f2fs: protect critical_task_priority updates with s_umount Greg Kroah-Hartman
                   ` (102 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Chao Yu, Jaegeuk Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chao Yu <chao@kernel.org>

commit 5b86eab84ac8e9289b5afc52ef88ab18ba5bacab upstream.

If node block is corrupted due to chksum mismatch or inconsistent
footer info, it needs to drop clear flag of node folio, in order
to persist inconsistent node data to storage.

Cc: stable@kernel.org
Fixes: b42b179bda9f ("f2fs: fix to do checksum even if inode page is uptodate")
Signed-off-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/f2fs/node.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/fs/f2fs/node.c
+++ b/fs/f2fs/node.c
@@ -1618,7 +1618,7 @@ page_hit:
 	if (!err)
 		return folio;
 out_err:
-	folio_clear_uptodate(folio);
+	clear_node_folio_dirty(folio);
 out_put_err:
 	/* ENOENT comes from read_node_folio which is not an error. */
 	if (err != -ENOENT)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 467/556] f2fs: protect critical_task_priority updates with s_umount
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (465 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 466/556] f2fs: fix to clear dirty flag on folio in error path Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 468/556] f2fs: fix valid block count leak on data block allocation failure Greg Kroah-Hartman
                   ` (101 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Wenjie Qi, Chao Yu,
	Jaegeuk Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wenjie Qi <qwjhust@gmail.com>

commit 8e4692c6c165e81b2cbb847d8da4b45a53483b33 upstream.

The sysfs store path already takes s_umount for GC thread control
entries, and ckpt_thread_ioprio is covered as well.

critical_task_priority also updates checkpoint or GC kthread scheduling
state, but it is not covered by that serialization. It can race with
remount or teardown paths that are stopping those threads.

Protect critical_task_priority sysfs writes with s_umount too.

Fixes: 52190933c37a ("f2fs: sysfs: introduce critical_task_priority")
Cc: stable@kernel.org
Signed-off-by: Wenjie Qi <qiwenjie@xiaomi.com>
Reviewed-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/f2fs/sysfs.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/fs/f2fs/sysfs.c
+++ b/fs/f2fs/sysfs.c
@@ -1007,7 +1007,8 @@ static ssize_t f2fs_sbi_store(struct f2f
 	ssize_t ret;
 	bool gc_entry = (!strcmp(a->attr.name, "gc_urgent") ||
 					a->struct_type == GC_THREAD);
-	bool thread_entry = !strcmp(a->attr.name, "ckpt_thread_ioprio");
+	bool thread_entry = !strcmp(a->attr.name, "ckpt_thread_ioprio") ||
+			!strcmp(a->attr.name, "critical_task_priority");
 
 	if (gc_entry || thread_entry) {
 		if (!down_read_trylock(&sbi->sb->s_umount))



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 468/556] f2fs: fix valid block count leak on data block allocation failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (466 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 467/556] f2fs: protect critical_task_priority updates with s_umount Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 469/556] f2fs: fix to reclaim space in f2fs_allocate_pinning_section() Greg Kroah-Hartman
                   ` (100 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Chao Yu, Chen Changcheng,
	Jaegeuk Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chen Changcheng <chenchangcheng@kylinos.cn>

commit 0f9af07ecc1ab486038373db6ae0436c5d674b19 upstream.

In __allocate_data_block(), when allocating a new data block
(dn->data_blkaddr == NULL_ADDR), inc_valid_block_count() is
called first to increment total_valid_block_count and i_blocks.
If the subsequent f2fs_allocate_data_block() fails, the function
returns the error directly without rolling back the
already-incremented block counts, causing a permanent leak.

Fix this by calling dec_valid_block_count() to undo the
increment before returning the error. The condition
old_blkaddr == NULL_ADDR precisely identifies the case where
inc_valid_block_count() was called.

Fixes: 7d009e048d7c ("f2fs: fix to handle segment allocation failure correctly")
Cc: <stable@vger.kernel.org>
Reviewed-by: Chao Yu <chao@kernel.org>
Signed-off-by: Chen Changcheng <chenchangcheng@kylinos.cn>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/f2fs/data.c |    5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

--- a/fs/f2fs/data.c
+++ b/fs/f2fs/data.c
@@ -1533,8 +1533,11 @@ static int __allocate_data_block(struct
 	old_blkaddr = dn->data_blkaddr;
 	err = f2fs_allocate_data_block(sbi, NULL, old_blkaddr,
 				&dn->data_blkaddr, &sum, seg_type, NULL);
-	if (err)
+	if (err) {
+		if (old_blkaddr == NULL_ADDR)
+			dec_valid_block_count(sbi, dn->inode, count);
 		return err;
+	}
 
 	if (GET_SEGNO(sbi, old_blkaddr) != NULL_SEGNO)
 		f2fs_invalidate_internal_cache(sbi, old_blkaddr, 1);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 469/556] f2fs: fix to reclaim space in f2fs_allocate_pinning_section()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (467 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 468/556] f2fs: fix valid block count leak on data block allocation failure Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 470/556] f2fs: fix to pass folio->index to f2fs_sanity_check_node_footer() Greg Kroah-Hartman
                   ` (99 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, stable, Daeho Jeong, Chao Yu,
	Jaegeuk Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chao Yu <chao@kernel.org>

commit fa487f56efba6344aef67d871688f0908fe08af3 upstream.

It needs to trigger checkpoint to free space reclaimed by f2fs_gc_range(),
otherwise, fallocate() on pinfile will fail easily even there is slash
space in conventional zone.

[Testcase]
nullblk_create.sh 512 2 1024 1024
mkfs.f2fs /dev/nullb0 -f -m
mount /dev/nullb0 /mnt/f2fs/
touch /mnt/f2fs/pinfile
f2fs_io pinfile set /mnt/f2fs/pinfile
mkdir /mnt/f2fs/dir/
for((i=0;i<3934;i++)) do { dd if=/dev/zero of=/mnt/f2fs/dir/$i bs=1M count=1;} done
sync
for((i=0;i<3934;i+=2)) do { rm /mnt/f2fs/dir/$i;} done
for((i=0;i<1950;i++)) do { rm /mnt/f2fs/dir/$i;} done
sync
f2fs_io fallocate 0 0 $((1024*1024*1024)) /mnt/f2fs/pinfile
sync
stat /mnt/f2fs/pinfile
f2fs_io fiemap 0 $((1024*1024*1024)) /mnt/f2fs/pinfile

[Before]
fallocate failed: Resource temporarily unavailable
  File: /mnt/f2fs/pinfile
  Size: 109051904       Blocks: 213208     IO Block: 4096   regular file
Device: 250,0   Inode: 4           Links: 1
Access: (0644/-rw-r--r--)  Uid: (    0/    root)   Gid: (    0/    root)
Access: 2026-08-12 20:04:02.264000000 +0800
Modify: 2026-08-12 20:04:26.784000000 +0800
Change: 2026-08-12 20:04:26.784000000 +0800
 Birth: -
root@localhost:~#
root@localhost:~#
root@localhost:~#
root@localhost:~# f2fs_io fiemap 0 $((1024*1024*1024)) /mnt/f2fs/pinfile
Fiemap: offset = 0 len = 1073741824
        logical addr.    physical addr.   length           flags
0       0000000000000000 0000000002e00000 0000000000200000 00001000
1       0000000000200000 000000002dc00000 0000000000400000 00001000
2       0000000000600000 000000002e400000 0000000000600000 00001000
3       0000000000c00000 000000007a400000 0000000005c00000 00001001

[After]
  File: /mnt/f2fs/pinfile
  Size: 1073741824      Blocks: 2099216    IO Block: 4096   regular file
Device: 250,0   Inode: 4           Links: 1
Access: (0644/-rw-r--r--)  Uid: (    0/    root)   Gid: (    0/    root)
Access: 2026-08-12 19:47:49.428000000 +0800
Modify: 2026-08-12 19:49:06.808000000 +0800
Change: 2026-08-12 19:49:06.808000000 +0800
 Birth: -
Fiemap: offset = 0 len = 1073741824
        logical addr.    physical addr.   length           flags
0       0000000000000000 0000000002e00000 0000000000200000 00001000
1       0000000000200000 000000003aa00000 0000000000400000 00001000
2       0000000000600000 000000003b400000 0000000000200000 00001000
3       0000000000800000 000000007a200000 0000000005e00000 00001000
4       0000000006600000 0000000002800000 0000000000200000 00001000
5       0000000006800000 0000000003200000 0000000000400000 00001000
6       0000000006c00000 0000000003000000 0000000000200000 00001000
7       0000000006e00000 0000000003600000 0000000037200000 00001000
8       000000003e000000 000000003b200000 0000000000200000 00001000
9       000000003e200000 000000003a800000 0000000000200000 00001000
10      000000003e400000 000000003ae00000 0000000000400000 00001000
11      000000003e800000 000000003b600000 0000000001800000 00001001

Cc: stable@kernel.org
Fixes: 9703d69d9d15 ("f2fs: support file pinning for zoned devices")
Cc: Daeho Jeong <daehojeong@google.com>
Signed-off-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/f2fs/segment.c |    9 ++++++---
 1 file changed, 6 insertions(+), 3 deletions(-)

--- a/fs/f2fs/segment.c
+++ b/fs/f2fs/segment.c
@@ -3361,10 +3361,13 @@ retry:
 		err = f2fs_gc_range(sbi, 0, sbi->first_seq_zone_segno - 1,
 				true, ZONED_PIN_SEC_REQUIRED_COUNT);
 		f2fs_up_write_trace(&sbi->gc_lock, &lc);
-
-		gc_required = false;
-		if (!err)
+		if (err)
+			return err;
+		err = f2fs_sync_fs(sbi->sb, 1);
+		if (!err) {
+			gc_required = false;
 			goto retry;
+		}
 	}
 
 	return err;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 470/556] f2fs: fix to pass folio->index to f2fs_sanity_check_node_footer()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (468 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 469/556] f2fs: fix to reclaim space in f2fs_allocate_pinning_section() Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 471/556] f2fs: fix to zero post-EOF data when extending file size Greg Kroah-Hartman
                   ` (98 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Chao Yu, Jaegeuk Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chao Yu <chao@kernel.org>

commit 7e188e9f9437ab47c3237d609f1b26348d6fea1a upstream.

Otherwise in f2fs_sanity_check_node_footer(), it will check the
same nid incorrectly.

Cc: stable@kernel.org
Fixes: 0a736109c9d2 ("f2fs: fix to do sanity check on node footer in __write_node_folio()")
Signed-off-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/f2fs/node.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/fs/f2fs/node.c
+++ b/fs/f2fs/node.c
@@ -1790,7 +1790,7 @@ static bool __write_node_folio(struct fo
 	/* get old block addr of this node page */
 	nid = nid_of_node(folio);
 
-	if (f2fs_sanity_check_node_footer(sbi, folio, nid,
+	if (f2fs_sanity_check_node_footer(sbi, folio, folio->index,
 					NODE_TYPE_REGULAR, false)) {
 		fserror_report_metadata(sbi->sb, -EFSCORRUPTED, GFP_NOFS);
 		f2fs_stop_checkpoint(sbi, false, STOP_CP_REASON_CORRUPTED_NID);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 471/556] f2fs: fix to zero post-EOF data when extending file size
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (469 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 470/556] f2fs: fix to pass folio->index to f2fs_sanity_check_node_footer() Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 472/556] drm/amdgpu: Fix init ordering in amdgpu_vram_mgr_init() Greg Kroah-Hartman
                   ` (97 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, stable, Chao Yu, Jaegeuk Kim

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chao Yu <chao@kernel.org>

commit 5eced87b7d19dbc76ebdddaf322046f9ac582fcb upstream.

generic/794  4s ... - output mismatch (see /share/git/fstests/results//generic/794.out.bad)
#    --- tests/generic/794.out   2026-06-12 08:46:32.766426241 +0800
#    +++ /share/git/fstests/results//generic/794.out.bad 2026-07-05 18:32:55.000000000 +0800
#    @@ -1,4 +1,16 @@
#     QA output created by 794
#     append_write
#    +FAIL: non-zero data in gap [4080,4096) after shutdown+remount
#    +000000 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a 5a  >ZZZZZZZZZZZZZZZZ<
#    +*
#    +001000
#     truncate_up
#    ...
#    (Run 'diff -u /share/git/fstests/tests/generic/794.out /share/git/fstests/results//generic/794.out.bad'  to see the entire diff)
Ran: generic/794
Failures: generic/794
Failed 1 of 1 tests

Steps of generic/794:
1. write 4096 bytes to file w/ 0x5a
2. use fiemap to get PBA of first block in file
3. truncate file to 4080
4. umount; write 4096 bytes to file w/ 0x5a directly via PBA; mount
5. extend filesize via
   a) append 4096 from offset 4096, or
   b) truncate 8192, or
   c) fallocate 4096 from offset 4096
6. verify the gap is zeroed in memory [4080,4096)
7. sync range 4096 from offset 4096; shutdown -f (flush meta before shutdown)
8. umount; mount; verify [4080,4096) is zeroed or not.

When extending file size (e.g. via truncate, fallocate, or write) across an
unaligned EOF boundary, we need to ensure that post-EOF data in the partial
page is zeroed out in pagecache and marked dirty, then writeback the cache to
persist zeroed data before committing inode w/ updated i_size.

This help to prevent stale disk data beyond the previous EOF from being exposed
after remounting or crash recovery.

Since f2fs is a LFS filesystem, we only support direct write via PBA in pinfile,
and pinfile has section-aligned filesize, so in Android, there should no problem,
but for other usage in different environment, let's fix this w/ fsync_mode=strict
mount option.

Cc: stable@kernel.org
Signed-off-by: Chao Yu <chao@kernel.org>
Signed-off-by: Jaegeuk Kim <jaegeuk@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/f2fs/file.c |  100 +++++++++++++++++++++++++++++++++++++++++++++++----------
 1 file changed, 84 insertions(+), 16 deletions(-)

--- a/fs/f2fs/file.c
+++ b/fs/f2fs/file.c
@@ -36,16 +36,52 @@
 #include <trace/events/f2fs.h>
 #include <uapi/linux/f2fs.h>
 
-static void f2fs_zero_post_eof_page(struct inode *inode,
-					loff_t new_size, bool lock)
+static int fill_zero(struct inode *inode, pgoff_t index,
+					loff_t start, loff_t len);
+
+static int do_zero_post_eof_page(struct inode *inode, loff_t new_size)
+{
+	loff_t old_size = i_size_read(inode);
+	unsigned int offset, len;
+	pgoff_t index;
+	int err;
+
+	offset = old_size & (PAGE_SIZE - 1);
+
+	if (!offset)
+		return 0;
+
+	len = min_t(loff_t, PAGE_SIZE - offset, new_size - old_size);
+	index = old_size >> PAGE_SHIFT;
+
+	if (f2fs_has_inline_data(inode)) {
+		/* data post eof should be always zero */
+		if (new_size <= MAX_INLINE_DATA(inode))
+			return 0;
+		err = f2fs_convert_inline_inode(inode);
+		if (err)
+			return err;
+	}
+
+	err = fill_zero(inode, index, offset, len);
+	if (err)
+		return err;
+	return filemap_write_and_wait_range(inode->i_mapping,
+				old_size, old_size + len - 1);
+}
+
+static int f2fs_zero_post_eof_page(struct inode *inode,
+					loff_t new_size, bool lock, bool writeback)
 {
 	loff_t old_size = i_size_read(inode);
+	bool strict =
+		F2FS_OPTION(F2FS_I_SB(inode)).fsync_mode == FSYNC_MODE_STRICT;
 
 	if (old_size >= new_size)
-		return;
+		return 0;
 
-	if (mapping_empty(inode->i_mapping))
-		return;
+	if (!strict && mapping_empty(inode->i_mapping))
+		return 0;
 
 	if (lock)
 		filemap_invalidate_lock(inode->i_mapping);
@@ -53,6 +89,16 @@ static void f2fs_zero_post_eof_page(stru
 	truncate_inode_pages_range(inode->i_mapping, old_size, new_size - 1);
 	if (lock)
 		filemap_invalidate_unlock(inode->i_mapping);
+
+	if (!writeback || !strict)
+		return 0;
+	/*
+	 * In fsync_mode=strict, when we expand an unaligned EOF size, we
+	 * should zero post EOF data and writeback the data immediately,
+	 * so that it can avoid exposing stale data after metadata flush
+	 * and POR.
+	 */
+	return do_zero_post_eof_page(inode, new_size);
 }
 
 static vm_fault_t f2fs_filemap_fault(struct vm_fault *vmf)
@@ -132,7 +178,10 @@ static vm_fault_t f2fs_vm_page_mkwrite(s
 
 	f2fs_bug_on(sbi, f2fs_has_inline_data(inode));
 
-	f2fs_zero_post_eof_page(inode, (folio->index + 1) << PAGE_SHIFT, true);
+	err = f2fs_zero_post_eof_page(inode,
+		(folio->index + 1) << PAGE_SHIFT, true, false);
+	if (err)
+		goto out_pagefault;
 
 	file_update_time(vmf->vma->vm_file);
 	filemap_invalidate_lock_shared(inode->i_mapping);
@@ -189,7 +238,7 @@ static vm_fault_t f2fs_vm_page_mkwrite(s
 
 out_sem:
 	filemap_invalidate_unlock_shared(inode->i_mapping);
-
+out_pagefault:
 	sb_end_pagefault(inode->i_sb);
 out:
 	ret = vmf_fs_error(err);
@@ -1175,8 +1224,12 @@ int f2fs_setattr(struct mnt_idmap *idmap
 		f2fs_down_write(&fi->i_gc_rwsem[WRITE]);
 		filemap_invalidate_lock(inode->i_mapping);
 
-		if (attr->ia_size > old_size)
-			f2fs_zero_post_eof_page(inode, attr->ia_size, false);
+		if (attr->ia_size > old_size) {
+			err = f2fs_zero_post_eof_page(inode,
+				attr->ia_size, false, true);
+			if (err)
+				goto err_out;
+		}
 		truncate_setsize(inode, attr->ia_size);
 
 		if (attr->ia_size <= old_size)
@@ -1185,6 +1238,7 @@ int f2fs_setattr(struct mnt_idmap *idmap
 		 * do not trim all blocks after i_size if target size is
 		 * larger than i_size.
 		 */
+err_out:
 		filemap_invalidate_unlock(inode->i_mapping);
 		f2fs_up_write(&fi->i_gc_rwsem[WRITE]);
 		if (err)
@@ -1296,7 +1350,9 @@ static int f2fs_punch_hole(struct inode
 	if (ret)
 		return ret;
 
-	f2fs_zero_post_eof_page(inode, offset + len, true);
+	ret = f2fs_zero_post_eof_page(inode, offset + len, true, false);
+	if (ret)
+		return ret;
 
 	pg_start = ((unsigned long long) offset) >> PAGE_SHIFT;
 	pg_end = ((unsigned long long) offset + len) >> PAGE_SHIFT;
@@ -1583,7 +1639,9 @@ static int f2fs_do_collapse(struct inode
 	f2fs_down_write(&F2FS_I(inode)->i_gc_rwsem[WRITE]);
 	filemap_invalidate_lock(inode->i_mapping);
 
-	f2fs_zero_post_eof_page(inode, offset + len, false);
+	ret = f2fs_zero_post_eof_page(inode, offset + len, false, false);
+	if (ret)
+		goto out_unlock;
 
 	f2fs_lock_op(sbi, &lc);
 	f2fs_drop_extent_tree(inode);
@@ -1591,6 +1649,7 @@ static int f2fs_do_collapse(struct inode
 	ret = __exchange_data_block(inode, inode, end, start, nrpages - end, true);
 	f2fs_unlock_op(sbi, &lc);
 
+out_unlock:
 	filemap_invalidate_unlock(inode->i_mapping);
 	f2fs_up_write(&F2FS_I(inode)->i_gc_rwsem[WRITE]);
 	return ret;
@@ -1712,7 +1771,9 @@ static int f2fs_zero_range(struct inode
 	if (ret)
 		return ret;
 
-	f2fs_zero_post_eof_page(inode, offset + len, true);
+	ret = f2fs_zero_post_eof_page(inode, offset + len, true, false);
+	if (ret)
+		return ret;
 
 	pg_start = ((unsigned long long) offset) >> PAGE_SHIFT;
 	pg_end = ((unsigned long long) offset + len) >> PAGE_SHIFT;
@@ -1847,7 +1908,9 @@ static int f2fs_insert_range(struct inod
 	f2fs_down_write(&F2FS_I(inode)->i_gc_rwsem[WRITE]);
 	filemap_invalidate_lock(mapping);
 
-	f2fs_zero_post_eof_page(inode, offset + len, false);
+	ret = f2fs_zero_post_eof_page(inode, offset + len, false, false);
+	if (ret)
+		goto out_unlock;
 	truncate_pagecache(inode, offset);
 
 	while (!ret && idx > pg_start) {
@@ -1865,6 +1928,7 @@ static int f2fs_insert_range(struct inod
 					idx + delta, nr, false);
 		f2fs_unlock_op(sbi, &lc);
 	}
+out_unlock:
 	filemap_invalidate_unlock(mapping);
 	f2fs_up_write(&F2FS_I(inode)->i_gc_rwsem[WRITE]);
 	if (ret)
@@ -1907,7 +1971,9 @@ static int f2fs_expand_inode_data(struct
 	if (err)
 		return err;
 
-	f2fs_zero_post_eof_page(inode, offset + len, true);
+	err = f2fs_zero_post_eof_page(inode, offset + len, true, true);
+	if (err)
+		return err;
 
 	f2fs_balance_fs(sbi, true);
 
@@ -5024,8 +5090,10 @@ static ssize_t f2fs_write_checks(struct
 	if (err)
 		return err;
 
-	f2fs_zero_post_eof_page(inode,
-		iocb->ki_pos + iov_iter_count(from), true);
+	err = f2fs_zero_post_eof_page(inode,
+		iocb->ki_pos + iov_iter_count(from), true, true);
+	if (err)
+		return err;
 	return count;
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 472/556] drm/amdgpu: Fix init ordering in amdgpu_vram_mgr_init()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (470 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 471/556] f2fs: fix to zero post-EOF data when extending file size Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 473/556] drm/amdgpu: avoid force-completing uninitialized UVD rings Greg Kroah-Hartman
                   ` (96 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sashiko-bot, Friedrich Vock,
	Maarten Lankhorst, Tejun Heo, Maxime Ripard, Christian König,
	Alex Deucher, amd-gfx, dri-devel, Thomas Hellström,
	Arunpravin Paneer Selvam, Maarten Lankhorst,
	Thadeu Lima de Souza Cascardo

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Thomas Hellström <thomas.hellstrom@linux.intel.com>

commit e773798e14ac0aea54ca9676083b91f445e5bc59 upstream.

drmm_cgroup_register_region() is called before INIT_LIST_HEAD() and
gpu_buddy_init() in amdgpu_vram_mgr_init(). If it fails, the function
returns early and bypasses those initializations.

Since adev->mman.initialized is set to true before amdgpu_vram_mgr_init()
is called, a failure triggers amdgpu_ttm_fini(), which calls
amdgpu_vram_mgr_fini(), which then:

 - Calls list_for_each_entry_safe() on reservations_pending and
   reserved_pages, whose list_head::next pointers are zero-initialized
   (NULL). The loop does not recognize them as empty and dereferences NULL.

 - Calls gpu_buddy_fini(), which iterates free_trees[] unconditionally
   via for_each_free_tree(). Since mm->free_trees is NULL
   (never allocated), this dereferences NULL.

Both result in a kernel panic on the module load error path.

Fix by moving drmm_cgroup_register_region() to after the list and buddy
allocator are fully initialized, so the teardown path is safe to run.

Reported-by: Sashiko-bot <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260428073116.15687-1-thomas.hellstrom@linux.intel.com?part=4
Fixes: 2b624a2c1865 ("drm/ttm: Handle cgroup based eviction in TTM")
Cc: Friedrich Vock <friedrich.vock@gmx.de>
Cc: Maarten Lankhorst <dev@lankhorst.se>
Cc: Tejun Heo <tj@kernel.org>
Cc: Maxime Ripard <mripard@kernel.org>
Cc: Christian König <christian.koenig@amd.com>
Cc: Alex Deucher <alexander.deucher@amd.com>
Cc: amd-gfx@lists.freedesktop.org
Cc: dri-devel@lists.freedesktop.org
Cc: stable@vger.kernel.org # v6.14+
Assisted-by: GitHub_Copilot:claude-sonnet-4.6
Signed-off-by: Thomas Hellström <thomas.hellstrom@linux.intel.com>
Reviewed-by: Arunpravin Paneer Selvam <Arunpravin.PaneerSelvam@amd.com>
Reviewed-By: Maarten Lankhorst <maarten.lankhorst@linux.intel.com>
Tested-by: Thadeu Lima de Souza Cascardo <cascardo@igalia.com>
Link: https://patch.msgid.link/20260725100036.2372-2-thomas.hellstrom@linux.intel.com
Acked-by: Christian König <christian.koenig@amd.com>
Signed-off-by: Maarten Lankhorst <dev@lankhorst.se>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/amdgpu/amdgpu_vram_mgr.c |    7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)

--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_vram_mgr.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_vram_mgr.c
@@ -918,9 +918,6 @@ int amdgpu_vram_mgr_init(struct amdgpu_d
 	struct ttm_resource_manager *man = &mgr->manager;
 	int err;
 
-	man->cg = drmm_cgroup_register_region(adev_to_drm(adev), "vram", adev->gmc.real_vram_size);
-	if (IS_ERR(man->cg))
-		return PTR_ERR(man->cg);
 	ttm_resource_manager_init(man, &adev->mman.bdev,
 				  adev->gmc.real_vram_size);
 
@@ -935,6 +932,10 @@ int amdgpu_vram_mgr_init(struct amdgpu_d
 	if (err)
 		return err;
 
+	man->cg = drmm_cgroup_register_region(adev_to_drm(adev), "vram", adev->gmc.real_vram_size);
+	if (IS_ERR(man->cg))
+		return PTR_ERR(man->cg);
+
 	ttm_set_driver_manager(&adev->mman.bdev, TTM_PL_VRAM, &mgr->manager);
 	ttm_resource_manager_set_used(man, true);
 	return 0;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 473/556] drm/amdgpu: avoid force-completing uninitialized UVD rings
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (471 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 472/556] drm/amdgpu: Fix init ordering in amdgpu_vram_mgr_init() Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 474/556] drm/xe/vram: report FLAT_CCS base misalignment Greg Kroah-Hartman
                   ` (95 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Bob Zhou, Leo Liu, Frank Min,
	Alex Deucher

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Bob Zhou <bobzhou2@amd.com>

commit 6760f5cb12d2366ddd58a2d8637f7583d73f596b upstream.

uvd_v7_0_sw_init() does not initialize the UVD decode ring for an
SR-IOV VF. However, amdgpu_uvd_resume() unconditionally force-completes
the decode ring when restoring its fence sequence.

Skip fence completion when the fence driver is not initialized.

Fixes: 0a33b11d26c6 ("drm/amdgpu: mark force completed fences with -ECANCELED")
Cc: stable@vger.kernel.org
Signed-off-by: Bob Zhou <bobzhou2@amd.com>
Acked-by: Leo Liu <leo.liu@amd.com>
Acked-by: Frank Min <Frank.Min@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_uvd.c
@@ -517,7 +517,8 @@ int amdgpu_uvd_resume(struct amdgpu_devi
 			}
 			memset_io(ptr, 0, size);
 			/* to restore uvd fence seq */
-			amdgpu_fence_driver_force_completion(&adev->uvd.inst[i].ring, NULL);
+			if (adev->uvd.inst[i].ring.fence_drv.initialized)
+				amdgpu_fence_driver_force_completion(&adev->uvd.inst[i].ring, NULL);
 		}
 	}
 	return 0;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 474/556] drm/xe/vram: report FLAT_CCS base misalignment
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (472 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 473/556] drm/amdgpu: avoid force-completing uninitialized UVD rings Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 475/556] drm/panthor: harden firmware build-info bounds checks Greg Kroah-Hartman
                   ` (94 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Matthew Auld, Thomas Hellström,
	Matthew Brost, Rodrigo Vivi, stable

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Matthew Auld <matthew.auld@intel.com>

commit 0e68c74e44da81a4599c52437ee1f63a2c234470 upstream.

So we can easily check if a machine had the CCS bug, when looking back
over bug reports where we have the same machine with newer kernel.

Example print for a machine with the CCS bug:

  FLAT_CCS base:27bbff800, aligned:no

v2 (Matt B):
  - Unconditionally print the base + alignment

Fixes: 37173392741c ("drm/xe/vram: fix ccs offset calculation")
Signed-off-by: Matthew Auld <matthew.auld@intel.com>
Cc: Thomas Hellström <thomas.hellstrom@linux.intel.com>
Cc: Matthew Brost <matthew.brost@intel.com>
Cc: Rodrigo Vivi <rodrigo.vivi@intel.com>
Cc: stable@kernel.org
Reviewed-by: Matthew Brost <matthew.brost@intel.com>
Link: https://patch.msgid.link/20260902124117.918018-9-matthew.auld@intel.com
(cherry picked from commit d00b7f4f03bbeb2efad872f1686130e18c2b4141)
Signed-off-by: Rodrigo Vivi <rodrigo.vivi@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/xe/xe_vram.c |    3 +++
 1 file changed, 3 insertions(+)

--- a/drivers/gpu/drm/xe/xe_vram.c
+++ b/drivers/gpu/drm/xe/xe_vram.c
@@ -90,6 +90,9 @@ static int get_flat_ccs_offset(struct xe
 		offset |= offset_lo << 6; /* HW view bits 31:6 */
 		offset *= num_enabled; /* convert to SW view */
 
+		drm_info(&xe->drm, "FLAT_CCS base:%llx, aligned:%s\n", offset,
+			 str_yes_no(IS_ALIGNED(offset, SZ_128K)));
+
 		/*
 		 * Everything below this offset is handed to the VRAM
 		 * allocator, so it has to be the *first* address the



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 475/556] drm/panthor: harden firmware build-info bounds checks
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (473 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 474/556] drm/xe/vram: report FLAT_CCS base misalignment Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 476/556] drm/panthor: fix firmware control interface " Greg Kroah-Hartman
                   ` (93 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Osama Abdelkader, Steven Price

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Osama Abdelkader <osama.abdelkader@gmail.com>

commit 8321b093fa6c297b80586460ce6914d9655df170 upstream.

panthor_fw_read_build_info() checks whether the metadata range fits in the
firmware image with hdr.meta_start + hdr.meta_size. Both fields are u32, so
the addition can wrap and let an out-of-bounds range pass validation.

The function also reads the "git_sha: " prefix without first checking that
the metadata is long enough, and meta_size == 0 can underflow the NULL
terminator index.

Use subtraction-based bounds checking and reject metadata that is too short
to contain the expected prefix and trailing NULL byte.

Fixes: 2718d91816ee ("drm/panthor: Add the FW logical block")
Cc: stable@vger.kernel.org
Signed-off-by: Osama Abdelkader <osama.abdelkader@gmail.com>
Reviewed-by: Steven Price <steven.price@arm.com>
Signed-off-by: Steven Price <steven.price@arm.com>
Link: https://patch.msgid.link/20260720113212.11981-1-osama.abdelkader@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/panthor/panthor_fw.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/drivers/gpu/drm/panthor/panthor_fw.c
+++ b/drivers/gpu/drm/panthor/panthor_fw.c
@@ -707,7 +707,8 @@ static int panthor_fw_read_build_info(st
 		return ret;
 
 	if (hdr.meta_start > fw->size ||
-	    hdr.meta_start + hdr.meta_size > fw->size) {
+	    hdr.meta_size > fw->size - hdr.meta_start ||
+	    hdr.meta_size <= header_len) {
 		drm_err(&ptdev->base, "Firmware build info corrupt\n");
 		/* We don't need the build info, so continue */
 		return 0;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 476/556] drm/panthor: fix firmware control interface bounds checks
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (474 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 475/556] drm/panthor: harden firmware build-info bounds checks Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 477/556] drm/bridge: dw-hdmi: fix i2c adapter leak on probe failure Greg Kroah-Hartman
                   ` (92 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Osama Abdelkader, Steven Price,
	Liviu Dudau

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Osama Abdelkader <osama.abdelkader@gmail.com>

commit 6a47f9fd2d970674ed9dedc52fc7ab76fd015785 upstream.

panthor_init_cs_iface() and panthor_init_csg_iface() validate firmware
control interface offsets with 32-bit arithmetic and the size of the host
wrapper structures. The offsets are derived from firmware-provided strides,
so the arithmetic can wrap before the bounds check, and the host wrapper
size is not the size of the firmware control interface being mapped.

Use 64-bit arithmetic for the computed offsets and validate against the
actual firmware control interface structure sizes with subtraction-based
bounds checks. Also validate that the shared section is large enough for
the global control interface before using it.

Fixes: 2718d91816ee ("drm/panthor: Add the FW logical block")
Cc: stable@vger.kernel.org
Signed-off-by: Osama Abdelkader <osama.abdelkader@gmail.com>
Reviewed-by: Steven Price <steven.price@arm.com>
Reviewed-by: Liviu Dudau <liviu.dudau@arm.com>
Link: https://patch.msgid.link/20260720134435.13377-1-osama.abdelkader@gmail.com
Signed-off-by: Steven Price <steven.price@arm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/panthor/panthor_fw.c |   19 +++++++++++++------
 1 file changed, 13 insertions(+), 6 deletions(-)

--- a/drivers/gpu/drm/panthor/panthor_fw.c
+++ b/drivers/gpu/drm/panthor/panthor_fw.c
@@ -895,14 +895,15 @@ static int panthor_init_cs_iface(struct
 	struct panthor_fw_csg_iface *csg_iface = panthor_fw_get_csg_iface(ptdev, csg_idx);
 	struct panthor_fw_cs_iface *cs_iface = &ptdev->fw->iface.streams[csg_idx][cs_idx];
 	u64 shared_section_sz = panthor_kernel_bo_size(ptdev->fw->shared_section->mem);
-	u32 iface_offset = CSF_GROUP_CONTROL_OFFSET +
-			   (csg_idx * glb_iface->control->group_stride) +
+	u64 iface_offset = CSF_GROUP_CONTROL_OFFSET +
+			   ((u64)csg_idx * glb_iface->control->group_stride) +
 			   CSF_STREAM_CONTROL_OFFSET +
-			   (cs_idx * csg_iface->control->stream_stride);
+			   ((u64)cs_idx * csg_iface->control->stream_stride);
 	struct panthor_fw_cs_iface *first_cs_iface =
 		panthor_fw_get_cs_iface(ptdev, 0, 0);
 
-	if (iface_offset + sizeof(*cs_iface) >= shared_section_sz)
+	if (iface_offset > shared_section_sz ||
+	    sizeof(*cs_iface->control) > shared_section_sz - iface_offset)
 		return -EINVAL;
 
 	spin_lock_init(&cs_iface->lock);
@@ -952,10 +953,12 @@ static int panthor_init_csg_iface(struct
 	struct panthor_fw_global_iface *glb_iface = panthor_fw_get_glb_iface(ptdev);
 	struct panthor_fw_csg_iface *csg_iface = &ptdev->fw->iface.groups[csg_idx];
 	u64 shared_section_sz = panthor_kernel_bo_size(ptdev->fw->shared_section->mem);
-	u32 iface_offset = CSF_GROUP_CONTROL_OFFSET + (csg_idx * glb_iface->control->group_stride);
+	u64 iface_offset = CSF_GROUP_CONTROL_OFFSET +
+			   ((u64)csg_idx * glb_iface->control->group_stride);
 	unsigned int i;
 
-	if (iface_offset + sizeof(*csg_iface) >= shared_section_sz)
+	if (iface_offset > shared_section_sz ||
+	    sizeof(*csg_iface->control) > shared_section_sz - iface_offset)
 		return -EINVAL;
 
 	spin_lock_init(&csg_iface->lock);
@@ -1007,11 +1010,15 @@ static u32 panthor_get_instr_features(st
 static int panthor_fw_init_ifaces(struct panthor_device *ptdev)
 {
 	struct panthor_fw_global_iface *glb_iface = &ptdev->fw->iface.global;
+	u64 shared_section_sz = panthor_kernel_bo_size(ptdev->fw->shared_section->mem);
 	unsigned int i;
 
 	if (!ptdev->fw->shared_section->mem->kmap)
 		return -EINVAL;
 
+	if (sizeof(*glb_iface->control) > shared_section_sz)
+		return -EINVAL;
+
 	spin_lock_init(&glb_iface->lock);
 	glb_iface->control = ptdev->fw->shared_section->mem->kmap;
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 477/556] drm/bridge: dw-hdmi: fix i2c adapter leak on probe failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (475 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 476/556] drm/panthor: fix firmware control interface " Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 478/556] drm/panel-edp: " Greg Kroah-Hartman
                   ` (91 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Neil Armstrong, Johan Hovold,
	Luca Ceresoli, Laurent Pinchart

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit 09b195a7bb23df56269cd2a95d01ba3a5533af13 upstream.

Make sure to drop the i2c adapter device and module references before
returning when detecting a malformed devicetree during probe.

Fixes: 80e2f97968b5 ("drm: bridge: dw-hdmi: Switch to regmap for register access")
Cc: stable@vger.kernel.org	# 4.12
Cc: Neil Armstrong <neil.armstrong@linaro.org>
Signed-off-by: Johan Hovold <johan@kernel.org>
Reviewed-by: Luca Ceresoli <luca.ceresoli@bootlin.com>
Reviewed-by: Laurent Pinchart <laurent.pinchart+renesas@ideasonboard.com>
Link: https://patch.msgid.link/20260717090819.1630965-1-johan@kernel.org
Signed-off-by: Luca Ceresoli <luca.ceresoli@bootlin.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/bridge/synopsys/dw-hdmi.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/drivers/gpu/drm/bridge/synopsys/dw-hdmi.c
+++ b/drivers/gpu/drm/bridge/synopsys/dw-hdmi.c
@@ -3389,7 +3389,8 @@ struct dw_hdmi *dw_hdmi_probe(struct pla
 			break;
 		default:
 			dev_err(dev, "reg-io-width must be 1 or 4\n");
-			return ERR_PTR(-EINVAL);
+			ret = -EINVAL;
+			goto err_res;
 		}
 
 		iores = platform_get_resource(pdev, IORESOURCE_MEM, 0);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 478/556] drm/panel-edp: fix i2c adapter leak on probe failure
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (476 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 477/556] drm/bridge: dw-hdmi: fix i2c adapter leak on probe failure Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 479/556] drm: fix race between partial drm_dev_register() failure and ioctl Greg Kroah-Hartman
                   ` (90 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Douglas Anderson, Johan Hovold

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Johan Hovold <johan@kernel.org>

commit e2a9e291275a74e309a21cbb1def6296a72d6aed upstream.

Make sure to drop the i2c adapter reference on probe failure (e.g.
probe deferral) and on driver unbind also if a devicetree redundantly
uses the 'ddc-i2c-bus' property to point to the aux ddc bus.

Fixes: cc5a3fc041f0 ("drm/panel: panel-simple: Stash DP AUX bus; allow using it for DDC")
Cc: stable@vger.kernel.org	# 5.15
Reported-by: Douglas Anderson <dianders@chromium.org>
Link: https://lore.kernel.org/r/CAD=FV=VZPhzHU+Pet2m3L+Pqc7mOPfZC-f5p0OuNL79wNZPxRg@mail.gmail.com
Signed-off-by: Johan Hovold <johan@kernel.org>
Reviewed-by: Douglas Anderson <dianders@chromium.org>
Signed-off-by: Douglas Anderson <dianders@chromium.org>
Link: https://patch.msgid.link/20260717143119.1815106-2-johan@kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/panel/panel-edp.c |   19 +++++++++++++------
 1 file changed, 13 insertions(+), 6 deletions(-)

--- a/drivers/gpu/drm/panel/panel-edp.c
+++ b/drivers/gpu/drm/panel/panel-edp.c
@@ -831,6 +831,13 @@ exit:
 	return 0;
 }
 
+static void panel_edp_put_adapter(void *_adap)
+{
+	struct i2c_adapter *adap = _adap;
+
+	put_device(&adap->dev);
+}
+
 static int panel_edp_probe(struct device *dev, const struct panel_desc *desc,
 			   struct drm_dp_aux *aux)
 {
@@ -878,6 +885,11 @@ static int panel_edp_probe(struct device
 
 		if (!panel->ddc)
 			return -EPROBE_DEFER;
+
+		err = devm_add_action_or_reset(dev, panel_edp_put_adapter,
+					       panel->ddc);
+		if (err)
+			return err;
 	} else if (aux) {
 		panel->ddc = &aux->ddc;
 	}
@@ -889,7 +901,7 @@ static int panel_edp_probe(struct device
 
 	err = drm_panel_of_backlight(&panel->base);
 	if (err)
-		goto err_finished_ddc_init;
+		return err;
 
 	/*
 	 * We use runtime PM for prepare / unprepare since those power the panel
@@ -936,9 +948,6 @@ static int panel_edp_probe(struct device
 err_finished_pm_runtime:
 	pm_runtime_dont_use_autosuspend(dev);
 	pm_runtime_disable(dev);
-err_finished_ddc_init:
-	if (panel->ddc && (!panel->aux || panel->ddc != &panel->aux->ddc))
-		put_device(&panel->ddc->dev);
 
 	return err;
 }
@@ -982,8 +991,6 @@ static void panel_edp_remove(struct devi
 
 	pm_runtime_dont_use_autosuspend(dev);
 	pm_runtime_disable(dev);
-	if (panel->ddc && (!panel->aux || panel->ddc != &panel->aux->ddc))
-		put_device(&panel->ddc->dev);
 
 	drm_edid_free(panel->drm_edid);
 	panel->drm_edid = NULL;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 479/556] drm: fix race between partial drm_dev_register() failure and ioctl
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (477 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 478/556] drm/panel-edp: " Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 480/556] drm/i915/display: Clear SEL_FETCH_PLANE_CTL on plane disable Greg Kroah-Hartman
                   ` (89 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, sashiko-bot, Alexandre Courbot,
	Lyude Paul, Deborah Brouwer, Danilo Krummrich

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Danilo Krummrich <dakr@kernel.org>

commit eb197f7d60f00d0f5b1b3505dfc86a7e36045a3e upstream.

If drm_dev_register() fails after registering a minor (e.g. render minor
registered, primary minor fails), userspace could have opened the first
minor and entered a drm_dev_enter() critical section. Since the
unplugged flag was never set, the ioctl proceeds while the error path
tears down device resources.

Fix this by introducing drm_dev_synchronize_unplug(), which sets the
unplugged flag and waits for the SRCU barrier, ensuring all in-flight
drm_dev_enter() critical sections complete before cleanup proceeds; call
it on the error path of drm_dev_register().

Fixes: bee330f3d672 ("drm: Use srcu to protect drm_device.unplugged")
Cc: stable@vger.kernel.org
Reported-by: sashiko-bot@kernel.org
Closes: https://lore.kernel.org/all/20260620190648.2E9F61F000E9@smtp.kernel.org/
Reviewed-by: Alexandre Courbot <acourbot@nvidia.com>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Tested-by: Deborah Brouwer <deborah.brouwer@collabora.com>
Link: https://patch.msgid.link/20260628145406.2107056-17-dakr@kernel.org
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/drm_drv.c |   34 +++++++++++++++++++++++++---------
 1 file changed, 25 insertions(+), 9 deletions(-)

--- a/drivers/gpu/drm/drm_drv.c
+++ b/drivers/gpu/drm/drm_drv.c
@@ -473,6 +473,22 @@ void drm_dev_exit(int idx)
 }
 EXPORT_SYMBOL(drm_dev_exit);
 
+/*
+ * Mark the device as unplugged and wait for any in-flight drm_dev_enter()
+ * critical sections to complete.
+ */
+static void drm_dev_synchronize_unplug(struct drm_device *dev)
+{
+	/*
+	 * After synchronizing any critical read section is guaranteed to see
+	 * the new value of ->unplugged, and any critical section which might
+	 * still have seen the old value of ->unplugged is guaranteed to have
+	 * finished.
+	 */
+	dev->unplugged = true;
+	synchronize_srcu(&drm_unplug_srcu);
+}
+
 /**
  * drm_dev_unplug - unplug a DRM device
  * @dev: DRM device
@@ -485,15 +501,7 @@ EXPORT_SYMBOL(drm_dev_exit);
  */
 void drm_dev_unplug(struct drm_device *dev)
 {
-	/*
-	 * After synchronizing any critical read section is guaranteed to see
-	 * the new value of ->unplugged, and any critical section which might
-	 * still have seen the old value of ->unplugged is guaranteed to have
-	 * finished.
-	 */
-	dev->unplugged = true;
-	synchronize_srcu(&drm_unplug_srcu);
-
+	drm_dev_synchronize_unplug(dev);
 	drm_dev_unregister(dev);
 
 	/* Clear all CPU mappings pointing to this device */
@@ -1091,6 +1099,7 @@ int drm_dev_register(struct drm_device *
 		goto err_minors;
 
 	dev->registered = true;
+	dev->unplugged = false;
 
 	if (driver->load) {
 		ret = driver->load(dev, flags);
@@ -1118,6 +1127,13 @@ err_unload:
 	if (dev->driver->unload)
 		dev->driver->unload(dev);
 err_minors:
+	/*
+	 * If a minor was registered before the failure, userspace could have
+	 * opened it and entered a drm_dev_enter() critical section. Ensure all
+	 * such sections complete before we clean up.
+	 */
+	drm_dev_synchronize_unplug(dev);
+
 	remove_compat_control_link(dev);
 	drm_minor_unregister(dev, DRM_MINOR_ACCEL);
 	drm_minor_unregister(dev, DRM_MINOR_PRIMARY);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 480/556] drm/i915/display: Clear SEL_FETCH_PLANE_CTL on plane disable
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (478 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 479/556] drm: fix race between partial drm_dev_register() failure and ioctl Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 481/556] drm/i915: Guard against NULL driver_data in i915_pci_probe() Greg Kroah-Hartman
                   ` (88 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Nemesa Garg, Jouni Högander,
	Animesh Manna, Jani Nikula

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Nemesa Garg <nemesa.garg@intel.com>

commit 7f1172a2ac0d7e50850785e2e65789c8aac8411a upstream.

icl_plane_disable_sel_fetch_arm() wrote SEL_FETCH_PLANE_CTL = 0 only when
crtc_state->enable_psr2_sel_fetch was set. If a plane was disabled after
selective fetch had been turned off, the guard fired early and left the
register's enable bit set in hardware.

The bit is harmless until selective fetch is re-enabled.  When it is, the
hardware resumes fetching for the now-disabled plane and keeps its old DDB
range reserved.

i9xx_cursor_disable_sel_fetch_arm() has the same guard on SEL_FETCH_CUR_CTL
and is fixed the same way.

v2: Add same check for cursor also. [sashiko]

Cc: stable@vger.kernel.org
Fixes: b1f5279b5981 ("drm/i915/psr: Move plane sel fetch configuration into plane source files")
Closes: https://gitlab.freedesktop.org/drm/xe/kernel/-/work_items/8739
Assisted-by: GitHub-Copilot:claude-opus-4.6
Signed-off-by: Nemesa Garg <nemesa.garg@intel.com>
Reviewed-by: Jouni Högander <jouni.hogander@intel.com>
Signed-off-by: Animesh Manna <animesh.manna@intel.com>
Link: https://patch.msgid.link/20260818095149.2172935-1-nemesa.garg@intel.com
(cherry picked from commit 600a7c9d40e5e0c5544f42d1c9592c8d15224dc0)
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/i915/display/intel_cursor.c        |   15 ++++++++++-----
 drivers/gpu/drm/i915/display/skl_universal_plane.c |   15 ++++++++++-----
 2 files changed, 20 insertions(+), 10 deletions(-)

--- a/drivers/gpu/drm/i915/display/intel_cursor.c
+++ b/drivers/gpu/drm/i915/display/intel_cursor.c
@@ -530,13 +530,18 @@ static int i9xx_check_cursor(struct inte
 }
 
 static void i9xx_cursor_disable_sel_fetch_arm(struct intel_dsb *dsb,
-					      struct intel_plane *plane,
-					      const struct intel_crtc_state *crtc_state)
+					      struct intel_plane *plane)
 {
 	struct intel_display *display = to_intel_display(plane);
 	enum pipe pipe = plane->pipe;
 
-	if (!crtc_state->enable_psr2_sel_fetch)
+	/*
+	 * Clear this whenever the hardware has selective fetch, not just when
+	 * the current state uses it. The cursor may have been enabled with
+	 * selective fetch earlier and had its enable bit orphaned when the
+	 * feature was switched off.
+	 */
+	if (!HAS_PSR2_SEL_FETCH(display))
 		return;
 
 	intel_de_write_dsb(display, dsb, SEL_FETCH_CUR_CTL(pipe), 0);
@@ -586,7 +591,7 @@ static void i9xx_cursor_update_sel_fetch
 		if (crtc_state->enable_psr2_su_region_et)
 			wa_16021440873(dsb, plane, crtc_state, plane_state);
 		else
-			i9xx_cursor_disable_sel_fetch_arm(dsb, plane, crtc_state);
+			i9xx_cursor_disable_sel_fetch_arm(dsb, plane);
 	}
 }
 
@@ -695,7 +700,7 @@ static void i9xx_cursor_update_arm(struc
 	if (plane_state)
 		i9xx_cursor_update_sel_fetch_arm(dsb, plane, crtc_state, plane_state);
 	else
-		i9xx_cursor_disable_sel_fetch_arm(dsb, plane, crtc_state);
+		i9xx_cursor_disable_sel_fetch_arm(dsb, plane);
 
 	if (plane->cursor.base != base ||
 	    plane->cursor.size != fbc_ctl ||
--- a/drivers/gpu/drm/i915/display/skl_universal_plane.c
+++ b/drivers/gpu/drm/i915/display/skl_universal_plane.c
@@ -879,13 +879,18 @@ skl_plane_disable_arm(struct intel_dsb *
 }
 
 static void icl_plane_disable_sel_fetch_arm(struct intel_dsb *dsb,
-					    struct intel_plane *plane,
-					    const struct intel_crtc_state *crtc_state)
+					    struct intel_plane *plane)
 {
 	struct intel_display *display = to_intel_display(plane);
 	enum pipe pipe = plane->pipe;
 
-	if (!crtc_state->enable_psr2_sel_fetch)
+	/*
+	 * Clear this whenever the hardware has selective fetch, not just when
+	 * the current state uses it. The plane may have been enabled with
+	 * selective fetch earlier and had its enable bit orphaned when the
+	 * feature was switched off.
+	 */
+	if (!HAS_PSR2_SEL_FETCH(display))
 		return;
 
 	intel_de_write_dsb(display, dsb, SEL_FETCH_PLANE_CTL(pipe, plane->id), 0);
@@ -921,7 +926,7 @@ icl_plane_disable_arm(struct intel_dsb *
 
 	skl_write_plane_wm(dsb, plane, crtc_state);
 
-	icl_plane_disable_sel_fetch_arm(dsb, plane, crtc_state);
+	icl_plane_disable_sel_fetch_arm(dsb, plane);
 
 	if (plane_has_normalizer(plane))
 		intel_de_write_dsb(display, dsb,
@@ -1641,7 +1646,7 @@ static void icl_plane_update_sel_fetch_a
 		intel_de_write_dsb(display, dsb, SEL_FETCH_PLANE_CTL(pipe, plane->id),
 				   SEL_FETCH_PLANE_CTL_ENABLE);
 	else
-		icl_plane_disable_sel_fetch_arm(dsb, plane, crtc_state);
+		icl_plane_disable_sel_fetch_arm(dsb, plane);
 }
 
 static void



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 481/556] drm/i915: Guard against NULL driver_data in i915_pci_probe()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (479 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 480/556] drm/i915/display: Clear SEL_FETCH_PLANE_CTL on plane disable Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 482/556] drm/ssd130x: fix column and row end address in partial updates for ssd132x Greg Kroah-Hartman
                   ` (87 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+db96c5ff032f4292a8dc,
	Deepanshu Kartikey, Jani Nikula

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Deepanshu Kartikey <kartikey406@gmail.com>

commit 3785d40831ba5601296283e0197e10e089392757 upstream.

pci_match_device() can return the dummy pci_device_id_any entry
when a device is force-bound via sysfs driver_override, in which
case ->driver_data is unset (NULL). i915_pci_probe() casts it to
struct intel_device_info * unconditionally and dereferences
intel_info->require_force_probe, causing a NULL-ptr-deref.

Reported-by: syzbot+db96c5ff032f4292a8dc@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=db96c5ff032f4292a8dc
Tested-by: syzbot+db96c5ff032f4292a8dc@syzkaller.appspotmail.com
Cc: stable@vger.kernel.org
Signed-off-by: Deepanshu Kartikey <kartikey406@gmail.com>
Link: https://patch.msgid.link/20260813064902.367504-1-kartikey406@gmail.com
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
(cherry picked from commit 2727922084672cc274ecea726ea00363c2893731)
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/i915/i915_pci.c |    3 +++
 1 file changed, 3 insertions(+)

--- a/drivers/gpu/drm/i915/i915_pci.c
+++ b/drivers/gpu/drm/i915/i915_pci.c
@@ -958,6 +958,9 @@ static int i915_pci_probe(struct pci_dev
 		(struct intel_device_info *) ent->driver_data;
 	int err;
 
+	if (!intel_info)
+		return -ENODEV;
+
 	if (intel_info->require_force_probe && !id_forced(pdev->device)) {
 		dev_info(&pdev->dev,
 			 "Your graphics device %04x is not properly supported by i915 in this\n"



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 482/556] drm/ssd130x: fix column and row end address in partial updates for ssd132x
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (480 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 481/556] drm/i915: Guard against NULL driver_data in i915_pci_probe() Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 483/556] drm/sun4i: fix refcount leak in sun4i_backend_init_sat() Greg Kroah-Hartman
                   ` (86 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Amit Barzilai,
	Javier Martinez Canillas

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Amit Barzilai <amit.barzilai22@gmail.com>

commit 99e9c09358195454ecd200b9c6aba6b7d209fad4 upstream.

On partial screen updates, SSD132X controllers expect to get the
rectangle addresses as arguments of the "Set Column Address" and "Set
Row Address" commands. Each command expects the start address and end
address of the row/column in absolute format, however the end
addresses were being sent in a relative format (relative to the start
address).

The relative end addresses work only when the start address is 0. In
those situations, there is no value difference between relative and
absolute addresses.

Fixes: fdd591e00a9c9 ("drm/ssd130x: Add support for the SSD132x OLED controller family")
Cc: stable@vger.kernel.org
Signed-off-by: Amit Barzilai <amit.barzilai22@gmail.com>
Reviewed-by: Javier Martinez Canillas <javierm@redhat.com>
Link: https://patch.msgid.link/20260622122604.32500-2-amit.barzilai22@gmail.com
Signed-off-by: Javier Martinez Canillas <javierm@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/solomon/ssd130x.c |    5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

--- a/drivers/gpu/drm/solomon/ssd130x.c
+++ b/drivers/gpu/drm/solomon/ssd130x.c
@@ -864,12 +864,13 @@ static int ssd132x_update_rect(struct ss
 	 */
 
 	/* Set column start and end */
-	ret = ssd130x_write_cmd(ssd130x, 3, SSD132X_SET_COL_RANGE, x / segment_width, columns - 1);
+	ret = ssd130x_write_cmd(ssd130x, 3, SSD132X_SET_COL_RANGE, x / segment_width,
+				x / segment_width + columns - 1);
 	if (ret < 0)
 		return ret;
 
 	/* Set row start and end */
-	ret = ssd130x_write_cmd(ssd130x, 3, SSD132X_SET_ROW_RANGE, y, rows - 1);
+	ret = ssd130x_write_cmd(ssd130x, 3, SSD132X_SET_ROW_RANGE, y, y + rows - 1);
 	if (ret < 0)
 		return ret;
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 483/556] drm/sun4i: fix refcount leak in sun4i_backend_init_sat()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (481 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 482/556] drm/ssd130x: fix column and row end address in partial updates for ssd132x Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 484/556] drm/ssd130x: fix column and row end address in partial updates in ssd133x Greg Kroah-Hartman
                   ` (85 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Wentao Liang, Jernej Skrabec,
	Chen-Yu Tsai

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Wentao Liang <vulab@iscas.ac.cn>

commit f7a56ff6240e6fd0cb36a3c0a911a1cd54789ce2 upstream.

When sun4i_backend_init_sat() calls reset_control_deassert() it
increments the deassert_count of the reset controller, and must
pair that with a reset_control_assert() call to decrement it.
In the error path where clk_prepare_enable() fails, the function
returns immediately without calling reset_control_assert(), leaking
the reference count.  Other error paths, like the devm_clk_get()
failure, correctly jump to the err_assert_reset label which performs
the missing assert.

Fix the leak by using the existing err_assert_reset label in the
clk_prepare_enable error path instead of returning directly.

Cc: stable@vger.kernel.org
Fixes: 440d2c7b127a ("drm/sun4i: backend: Handle the SAT")
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Reviewed-by: Jernej Skrabec <jernej.skrabec@gmail.com>
Link: https://patch.msgid.link/20260607030950.83636-1-vulab@iscas.ac.cn
Signed-off-by: Chen-Yu Tsai <wens@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/sun4i/sun4i_backend.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/gpu/drm/sun4i/sun4i_backend.c
+++ b/drivers/gpu/drm/sun4i/sun4i_backend.c
@@ -686,7 +686,7 @@ static int sun4i_backend_init_sat(struct
 	ret = clk_prepare_enable(backend->sat_clk);
 	if (ret) {
 		dev_err(dev, "Couldn't enable the SAT clock\n");
-		return ret;
+		goto err_assert_reset;
 	}
 
 	return 0;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 484/556] drm/ssd130x: fix column and row end address in partial updates in ssd133x
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (482 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 483/556] drm/sun4i: fix refcount leak in sun4i_backend_init_sat() Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 485/556] drm/nouveau/disp/r535: Add scanline position support + head state support Greg Kroah-Hartman
                   ` (84 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Amit Barzilai,
	Javier Martinez Canillas

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Amit Barzilai <amit.barzilai22@gmail.com>

commit b7fcb70162acd7f15ed20bc64a14c150db34256f upstream.

On partial screen updates, SSD133X controllers expect to get the
rectangle addresses as arguments of the "Set Column Address" and "Set
Row Address" commands. Each command expects the start address and end
address of the row/column in absolute format, however the end
addresses were being sent in a relative format (relative to the start
address).

The relative end addresses work only when the start address is 0. In
those situations, there is no value difference between relative and
absolute addresses.

Fixes: b4299c936d8fd ("drm/ssd130x: Add support for the SSD133x OLED controller family")
Cc: stable@vger.kernel.org
Signed-off-by: Amit Barzilai <amit.barzilai22@gmail.com>
Reviewed-by: Javier Martinez Canillas <javierm@redhat.com>
Link: https://patch.msgid.link/20260622122604.32500-4-amit.barzilai22@gmail.com
Signed-off-by: Javier Martinez Canillas <javierm@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/solomon/ssd130x.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/drivers/gpu/drm/solomon/ssd130x.c
+++ b/drivers/gpu/drm/solomon/ssd130x.c
@@ -916,12 +916,12 @@ static int ssd133x_update_rect(struct ss
 	 */
 
 	/* Set column start and end */
-	ret = ssd130x_write_cmd(ssd130x, 3, SSD133X_SET_COL_RANGE, x, columns - 1);
+	ret = ssd130x_write_cmd(ssd130x, 3, SSD133X_SET_COL_RANGE, x, x + columns - 1);
 	if (ret < 0)
 		return ret;
 
 	/* Set row start and end */
-	ret = ssd130x_write_cmd(ssd130x, 3, SSD133X_SET_ROW_RANGE, y, rows - 1);
+	ret = ssd130x_write_cmd(ssd130x, 3, SSD133X_SET_ROW_RANGE, y, y + rows - 1);
 	if (ret < 0)
 		return ret;
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 485/556] drm/nouveau/disp/r535: Add scanline position support + head state support
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (483 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 484/556] drm/ssd130x: fix column and row end address in partial updates in ssd133x Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 486/556] drm/hibmc: Fix list of formats on the primary plane Greg Kroah-Hartman
                   ` (83 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Ben Skeggs, Dave Airlie, Timur Tabi,
	Ben Skeggs, James Jones, Faith Ekstrand, Suraj Kandpal,
	Lyude Paul, Aaron Kling, Danilo Krummrich, Zhang Enpei

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Lyude Paul <lyude@redhat.com>

commit 804cb093b245c752f15d17186e0d404f10303593 upstream.

That's right! It looks like this never actually got finished, something
which I just noticed today when I saw this fun message spamming one of my
test machine's kernel logs when enabling display debug output for nouveau:

  [drm:drm_crtc_vblank_helper_get_vblank_timestamp_internal] crtc 0 : scanoutpos query failed.

So it looks like we've been falling back to DRM's core fallback for a while
now, whoops.

So, while it seems that we do have the option of doing this through GSP -
that doesn't seem like a great idea. Mainly because reading this from GSP
would involve a lot more latency then we should have for vblank handling
due to the RPC communication. So instead of implementing that, just use
gv100_head_state and gv100_head_rgpos for implementing .state and .rgpos.
It seems to work perfectly fine!

Fixes: 9e9944449023 ("drm/nouveau/disp/r535: initial support")
Cc: Ben Skeggs <bskeggs@redhat.com>
Cc: Dave Airlie <airlied@redhat.com>
Cc: Timur Tabi <ttabi@nvidia.com>
Cc: Ben Skeggs <bskeggs@nvidia.com>
Cc: James Jones <jajones@nvidia.com>
Cc: Faith Ekstrand <faith.ekstrand@collabora.com>
Cc: Suraj Kandpal <suraj.kandpal@intel.com>
Cc: Lyude Paul <lyude@redhat.com>
Cc: Aaron Kling <webgeek1234@gmail.com>
Cc: Danilo Krummrich <dakr@kernel.org>
Cc: Zhang Enpei <zhang.enpei@zte.com.cn>
Cc: <stable@vger.kernel.org> # v6.7+
Signed-off-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Dave Airlie <airlied@redhat.com>
Link: https://patch.msgid.link/20260429030348.3930866-1-lyude@redhat.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/nouveau/nvkm/engine/disp/gv100.c       |    4 ++--
 drivers/gpu/drm/nouveau/nvkm/engine/disp/head.h        |    2 ++
 drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/disp.c |    8 ++------
 3 files changed, 6 insertions(+), 8 deletions(-)

--- a/drivers/gpu/drm/nouveau/nvkm/engine/disp/gv100.c
+++ b/drivers/gpu/drm/nouveau/nvkm/engine/disp/gv100.c
@@ -253,7 +253,7 @@ gv100_head_vblank_get(struct nvkm_head *
 	nvkm_mask(device, 0x611d80 + (head->id * 4), 0x00000004, 0x00000004);
 }
 
-static void
+void
 gv100_head_rgpos(struct nvkm_head *head, u16 *hline, u16 *vline)
 {
 	struct nvkm_device *device = head->disp->engine.subdev.device;
@@ -263,7 +263,7 @@ gv100_head_rgpos(struct nvkm_head *head,
 	*hline = nvkm_rd32(device, 0x616334 + hoff) & 0x0000ffff;
 }
 
-static void
+void
 gv100_head_state(struct nvkm_head *head, struct nvkm_head_state *state)
 {
 	struct nvkm_device *device = head->disp->engine.subdev.device;
--- a/drivers/gpu/drm/nouveau/nvkm/engine/disp/head.h
+++ b/drivers/gpu/drm/nouveau/nvkm/engine/disp/head.h
@@ -53,6 +53,8 @@ void gf119_head_rgclk(struct nvkm_head *
 
 int gv100_head_cnt(struct nvkm_disp *, unsigned long *);
 int gv100_head_new(struct nvkm_disp *, int id);
+void gv100_head_state(struct nvkm_head *head, struct nvkm_head_state *state);
+void gv100_head_rgpos(struct nvkm_head *head, u16 *hline, u16 *vline);
 
 #define HEAD_MSG(h,l,f,a...) do {                                              \
 	struct nvkm_head *_h = (h);                                            \
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/disp.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/disp.c
@@ -625,14 +625,10 @@ r535_head_vblank_get(struct nvkm_head *h
 	nvkm_mask(device, 0x611d80 + (head->id * 4), 0x00000002, 0x00000002);
 }
 
-static void
-r535_head_state(struct nvkm_head *head, struct nvkm_head_state *state)
-{
-}
-
 static const struct nvkm_head_func
 r535_head = {
-	.state = r535_head_state,
+	.state = gv100_head_state,
+	.rgpos = gv100_head_rgpos,
 	.vblank_get = r535_head_vblank_get,
 	.vblank_put = r535_head_vblank_put,
 };



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 486/556] drm/hibmc: Fix list of formats on the primary plane
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (484 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 485/556] drm/nouveau/disp/r535: Add scanline position support + head state support Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 487/556] drm/hibmc: Use drm_atomic_helper_check_plane_state() Greg Kroah-Hartman
                   ` (82 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Thomas Zimmermann, Yongbang Shi,
	Rongrong Zou, Sean Paul, Xinliang Liu, Dmitry Baryshkov,
	Baihan Li

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Thomas Zimmermann <tzimmermann@suse.de>

commit 0e682e136c466ae37c62f18099f591c096260ee0 upstream.

Remove all formats from the primary plane that are unsupported for
various reasons.

* Formats with alpha channel: planes should not announce alpha channels
unless they support transparency. There's no transparency support in
the primary plane's implementation.

* Formats with BGR order. The common format is in RGB channel order.
There's no BGR support in the primary plane's implementation.

* RGB888: atomic_update programs the format from cpp[0] * 8 / 16. For
RGB888's cpp value of 3 this returns 1.5; rounded to 1. Programming
the value of 1 to HIBMC_CRT_DISP_CTL_FORMAT sets up RGB565. Hence, the
output is distorted. This can be tested by booting with video=1024x768-24.

Removing all unsupported formats leaves XRGB8888 and RGB565. Both of
which are supported and work correctly.

Signed-off-by: Thomas Zimmermann <tzimmermann@suse.de>
Fixes: da52605eea8f ("drm/hisilicon/hibmc: Add support for display engine")
Reviewed-by: Yongbang Shi <shiyongbang@huawei.com>
Cc: Rongrong Zou <zourongrong@gmail.com>
Cc: Sean Paul <seanpaul@chromium.org>
Cc: Xinliang Liu <xinliang.liu@linaro.org>
Cc: Dmitry Baryshkov <lumag@kernel.org>
Cc: Yongbang Shi <shiyongbang@huawei.com>
Cc: Baihan Li <libaihan@huawei.com>
Cc: <stable@vger.kernel.org> # v4.10+
Link: https://patch.msgid.link/20260618123142.92298-3-tzimmermann@suse.de
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_de.c |    6 ++----
 1 file changed, 2 insertions(+), 4 deletions(-)

--- a/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_de.c
+++ b/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_de.c
@@ -153,10 +153,8 @@ static void hibmc_plane_atomic_update(st
 }
 
 static const u32 channel_formats1[] = {
-	DRM_FORMAT_RGB565, DRM_FORMAT_BGR565, DRM_FORMAT_RGB888,
-	DRM_FORMAT_BGR888, DRM_FORMAT_XRGB8888, DRM_FORMAT_XBGR8888,
-	DRM_FORMAT_RGBA8888, DRM_FORMAT_BGRA8888, DRM_FORMAT_ARGB8888,
-	DRM_FORMAT_ABGR8888
+	DRM_FORMAT_XRGB8888,
+	DRM_FORMAT_RGB565,
 };
 
 static const struct drm_plane_funcs hibmc_plane_funcs = {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 487/556] drm/hibmc: Use drm_atomic_helper_check_plane_state()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (485 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 486/556] drm/hibmc: Fix list of formats on the primary plane Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 488/556] drm/amd/display: avoid divide-by-zero in __is_lut_linear() Greg Kroah-Hartman
                   ` (81 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Thomas Zimmermann, Yongbang Shi,
	Rongrong Zou, Sean Paul, Xinliang Liu, Dmitry Baryshkov,
	Baihan Li

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Thomas Zimmermann <tzimmermann@suse.de>

commit 715c5db68bdbd4a524b79ebf20fb61e880fffea0 upstream.

Call drm_atomic_helper_check_plane_state() from the primary plane's
atomic-check helper and replace the custom implementation.

All plane's implementations of atomic_check should call the shared
_check_plane_state() helper first. It adjusts the plane state for
correct positioning, rotation and scaling of the plane. Do this
even if the plane's CRTC has been disabled by setting the parameter
can_update_disabled. The original code returned early in this case,
but it's safe to so and cleaner to have all plane state initialized.

As we don't set can_position, drm_atomic_helper_check_plane_state()'s
visibility check tests if the plane covers all of the CRTC. This is
a small change from the original code, which tested if the plane is
exactly the size of the CRTC. With the new test, the plane still has
to cover all of the CRTC, but can be larger than the CRTC's size. A
later patch can fully implement this feature in hibmc.

If the plane is disabled, the helper clears the visibility flag in the
plane state. On errors or if the plane is not visible, the atomic-check
helper can return early. Implement all this in hibmc and drop the custom
code that does some of it.

v2:
- extend the commit description (Yongbang)

Signed-off-by: Thomas Zimmermann <tzimmermann@suse.de>
Fixes: da52605eea8f ("drm/hisilicon/hibmc: Add support for display engine")
Reviewed-by: Yongbang Shi <shiyongbang@huawei.com>
Cc: Rongrong Zou <zourongrong@gmail.com>
Cc: Sean Paul <seanpaul@chromium.org>
Cc: Xinliang Liu <xinliang.liu@linaro.org>
Cc: Dmitry Baryshkov <lumag@kernel.org>
Cc: Baihan Li <libaihan@huawei.com>
Cc: Yongbang Shi <shiyongbang@huawei.com>
Cc: <stable@vger.kernel.org> # v4.10+
Link: https://patch.msgid.link/20260618123142.92298-2-tzimmermann@suse.de
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_de.c |   50 ++++++++-----------------
 1 file changed, 16 insertions(+), 34 deletions(-)

--- a/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_de.c
+++ b/drivers/gpu/drm/hisilicon/hibmc/hibmc_drm_de.c
@@ -72,46 +72,28 @@ static int hibmc_get_best_clock_idx(cons
 static int hibmc_plane_atomic_check(struct drm_plane *plane,
 				    struct drm_atomic_commit *state)
 {
-	struct drm_plane_state *new_plane_state = drm_atomic_get_new_plane_state(state,
-										 plane);
-	struct drm_framebuffer *fb = new_plane_state->fb;
-	struct drm_crtc *crtc = new_plane_state->crtc;
-	struct drm_crtc_state *crtc_state;
-	u32 src_w = new_plane_state->src_w >> 16;
-	u32 src_h = new_plane_state->src_h >> 16;
-
-	if (!crtc || !fb)
-		return 0;
-
-	crtc_state = drm_atomic_get_crtc_state(state, crtc);
-	if (IS_ERR(crtc_state))
-		return PTR_ERR(crtc_state);
-
-	if (src_w != new_plane_state->crtc_w || src_h != new_plane_state->crtc_h) {
-		drm_dbg_atomic(plane->dev, "scale not support\n");
-		return -EINVAL;
-	}
-
-	if (new_plane_state->crtc_x < 0 || new_plane_state->crtc_y < 0) {
-		drm_dbg_atomic(plane->dev, "crtc_x/y of drm_plane state is invalid\n");
-		return -EINVAL;
-	}
-
-	if (!crtc_state->enable)
+	struct drm_plane_state *new_plane_state =
+		drm_atomic_get_new_plane_state(state, plane);
+	struct drm_crtc_state *new_crtc_state = NULL;
+	int ret;
+
+	if (new_plane_state->crtc)
+		new_crtc_state = drm_atomic_get_new_crtc_state(state, new_plane_state->crtc);
+
+	ret = drm_atomic_helper_check_plane_state(new_plane_state, new_crtc_state,
+						  DRM_PLANE_NO_SCALING,
+						  DRM_PLANE_NO_SCALING,
+						  false, true);
+	if (ret)
+		return ret;
+	else if (!new_plane_state->visible)
 		return 0;
 
-	if (new_plane_state->crtc_x + new_plane_state->crtc_w >
-	    crtc_state->adjusted_mode.hdisplay ||
-	    new_plane_state->crtc_y + new_plane_state->crtc_h >
-	    crtc_state->adjusted_mode.vdisplay) {
-		drm_dbg_atomic(plane->dev, "visible portion of plane is invalid\n");
-		return -EINVAL;
-	}
-
 	if (new_plane_state->fb->pitches[0] % 128 != 0) {
 		drm_dbg_atomic(plane->dev, "wrong stride with 128-byte aligned\n");
 		return -EINVAL;
 	}
+
 	return 0;
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 488/556] drm/amd/display: avoid divide-by-zero in __is_lut_linear()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (486 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 487/556] drm/hibmc: Use drm_atomic_helper_check_plane_state() Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 489/556] drm/amd/display: fix dc_lock leak on GPU reset error paths Greg Kroah-Hartman
                   ` (80 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Harry Wentland, Melissa Wen,
	Daniel Wheeler, Alex Deucher

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Harry Wentland <harry.wentland@amd.com>

commit 4f40873f8a4107df2b9c8e68c947c4fd0cd519d2 upstream.

__is_lut_linear() computes the expected value of each entry with

	expected = i * MAX_DRM_LUT_VALUE / (size - 1);

If it is ever called with a single-entry LUT, size - 1 is zero and the
kernel takes a divide error (#DE). A LUT with fewer than two entries
cannot describe a linear mapping anyway, so return false early instead
of dividing by zero.

Fixes: 086247a4b2fb ("drm/amd/display: Use 4096 lut entries")
Cc: stable@vger.kernel.org
Signed-off-by: Harry Wentland <harry.wentland@amd.com>
Reviewed-by: Melissa Wen <mwen@igalia.com>
Tested-by: Daniel Wheeler <daniel.wheeler@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_color.c |    6 ++++++
 1 file changed, 6 insertions(+)

--- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_color.c
+++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_color.c
@@ -470,6 +470,12 @@ bool __is_lut_linear(const struct drm_co
 	uint32_t expected;
 	int delta;
 
+	/* A LUT with fewer than two entries can't be interpolated and would
+	 * divide by zero below (size - 1); it can't be treated as linear.
+	 */
+	if (size < 2)
+		return false;
+
 	for (i = 0; i < size; i++) {
 		/* All color values should equal */
 		if ((lut[i].red != lut[i].green) || (lut[i].green != lut[i].blue))



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 489/556] drm/amd/display: fix dc_lock leak on GPU reset error paths
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (487 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 488/556] drm/amd/display: avoid divide-by-zero in __is_lut_linear() Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 490/556] drm/amd/display: Fix HPD consideration for VGA/LVDS connectors on DCE Greg Kroah-Hartman
                   ` (79 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Linkai Gong, Mario Limonciello,
	Alex Deucher

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Linkai Gong <gonglinkai@kylinos.cn>

commit 92a9eebd2a1f892fe482154d83f9f1626bc73d3b upstream.

On GPU reset, dm_suspend() takes dc_lock and leaves it for dm_resume()
to drop. If amdgpu_dm_commit_zero_streams() or dm_dmub_hw_init() fails,
the function returns with the lock still held. The matching resume path
is then skipped, so every later dc_lock take hangs.

Release the cached DC state and unlock before returning the error.

Fixes: 3cf7a0bc87f0 ("drm/amd/display: Catch failures for amdgpu_dm_commit_zero_streams()")
Fixes: 2b6943df5413 ("drm/amd/display: Pass up errors for reset GPU that fails to init HW")
Cc: stable@vger.kernel.org
Signed-off-by: Linkai Gong <gonglinkai@kylinos.cn>
Reviewed-by: Mario Limonciello <mario.limonciello@amd.com>
Signed-off-by: Mario Limonciello <mario.limonciello@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c |    6 ++++++
 1 file changed, 6 insertions(+)

--- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
+++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
@@ -3511,6 +3511,9 @@ static int dm_suspend(struct amdgpu_ip_b
 		res = amdgpu_dm_commit_zero_streams(dm->dc);
 		if (res != DC_OK) {
 			drm_err(adev_to_drm(adev), "Failed to commit zero streams: %d\n", res);
+			dc_state_release(dm->cached_dc_state);
+			dm->cached_dc_state = NULL;
+			mutex_unlock(&dm->dc_lock);
 			return -EINVAL;
 		}
 
@@ -3824,6 +3827,9 @@ static int dm_resume(struct amdgpu_ip_bl
 		r = dm_dmub_hw_init(adev);
 		if (r) {
 			drm_err(adev_to_drm(adev), "DMUB interface failed to initialize: status=%d\n", r);
+			dc_state_release(dm->cached_dc_state);
+			dm->cached_dc_state = NULL;
+			mutex_unlock(&dm->dc_lock);
 			return r;
 		}
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 490/556] drm/amd/display: Fix HPD consideration for VGA/LVDS connectors on DCE
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (488 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 489/556] drm/amd/display: fix dc_lock leak on GPU reset error paths Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 491/556] drm/amd/display: validate plane degamma LUT size for private color prop Greg Kroah-Hartman
                   ` (78 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dmytro Laktyushkin, Roman Li,
	Timur Kristóf, Mario Limonciello (AMD), Mario Limonciello,
	Alex Deucher

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Timur Kristóf <timur.kristof@gmail.com>

commit 52536ce677a3470c0e5323b940791efb33975450 upstream.

After a refactor that landed in Linux 7.0,
DC now crashes when it is initialized on GPUs
that have a VGA or LVDS connector. This is because
these connectors have no HPD so the hpd_gpio is NULL
and therefore DC takes the code path meant for
DCN 4.2+ which sets irq_source_hpd = 255 that
causes the subsequent code to try to register
the HPD interrupt, which fails, and causes
a crash.

This commit should be backported to Linux 7.0 and newer.

Cc: stable@vger.kernel.org
Cc: Dmytro Laktyushkin <dmytro.laktyushkin@amd.com>
Cc: Roman Li <roman.li@amd.com>
Closes: https://gitlab.freedesktop.org/drm/amd/-/work_items/5490
Fixes: def3488eb0fd ("drm/amd/display: refactor HPD to increase flexibility")
Signed-off-by: Timur Kristóf <timur.kristof@gmail.com>
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Link: https://patch.msgid.link/20260821215059.312868-1-timur.kristof@gmail.com
Signed-off-by: Mario Limonciello <mario.limonciello@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/display/dc/link/link_factory.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/gpu/drm/amd/display/dc/link/link_factory.c
+++ b/drivers/gpu/drm/amd/display/dc/link/link_factory.c
@@ -632,7 +632,7 @@ static bool construct_phy(struct dc_link
 
 		DC_LOG_DC("BIOS object table - hpd_gpio id: %d", enc_init_data.hpd_gpio->id);
 		DC_LOG_DC("BIOS object table - hpd_gpio en: %d", enc_init_data.hpd_gpio->en);
-	} else {
+	} else if (link->ctx->dce_version > DCN_VERSION_4_01) {
 		struct graphics_object_hpd_info hpd_info;
 
 		if (link->ctx->dc_bios->funcs->get_hpd_info(link->ctx->dc_bios, link->link_id, &hpd_info) == BP_RESULT_OK) {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 491/556] drm/amd/display: validate plane degamma LUT size for private color prop
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (489 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 490/556] drm/amd/display: Fix HPD consideration for VGA/LVDS connectors on DCE Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 492/556] drm/amd/display: Remove const Qualifier From Non-Pointer Fields Greg Kroah-Hartman
                   ` (77 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Harry Wentland, Melissa Wen,
	Daniel Wheeler, Alex Deucher

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Harry Wentland <harry.wentland@amd.com>

commit e4c3ab59021e7c146a84b6671f0d530972bd58b4 upstream.

Unlike the CRTC degamma path, which is guarded by
amdgpu_dm_verify_lut_sizes(), the per-plane degamma LUT size was never
validated before use. __set_dm_plane_degamma() passed the user-supplied
size straight into __is_lut_linear() and, for a non-linear LUT, into
__set_input_tf() -> __drm_lut_to_dc_gamma(), the latter always iterating
MAX_COLOR_LUT_ENTRIES entries regardless of the actual LUT size.

A malformed AMD_PLANE_DEGAMMA_LUT blob (e.g. a single entry) could thus
trigger a divide-by-zero in __is_lut_linear() or an out-of-bounds read in
__drm_lut_to_dc_gamma(). Reject any plane degamma LUT whose size does not
match MAX_COLOR_LUT_ENTRIES, mirroring the invariant the code already
asserts a few lines below (and which the CRTC path enforces).

The AMD_PLANE_DEGAMMA_LUT property is only exposed on builds with
AMD_PRIVATE_COLOR defined.

Fixes: 980f8710075a ("drm/amd/display: add plane degamma TF and LUT support")
Cc: stable@vger.kernel.org
Signed-off-by: Harry Wentland <harry.wentland@amd.com>
Reviewed-by: Melissa Wen <mwen@igalia.com>
Tested-by: Daniel Wheeler <daniel.wheeler@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_color.c |    7 +++++++
 1 file changed, 7 insertions(+)

--- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_color.c
+++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_color.c
@@ -1473,6 +1473,13 @@ __set_dm_plane_degamma(struct drm_plane_
 	degamma_lut = __extract_blob_lut(dm_plane_state->degamma_lut,
 					 &degamma_size);
 
+	if (degamma_lut && degamma_size != MAX_COLOR_LUT_ENTRIES) {
+		drm_dbg(plane_state->state->dev,
+			"Invalid Plane Degamma LUT size. Should be %u but got %u.\n",
+			MAX_COLOR_LUT_ENTRIES, degamma_size);
+		return -EINVAL;
+	}
+
 	has_degamma_lut = degamma_lut &&
 			  !__is_lut_linear(degamma_lut, degamma_size);
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 492/556] drm/amd/display: Remove const Qualifier From Non-Pointer Fields
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (490 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 491/556] drm/amd/display: validate plane degamma LUT size for private color prop Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 493/556] drm/amd/display: Set gpuvm min page size to 4K on dcn35/36 Greg Kroah-Hartman
                   ` (76 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Dillon Varone, Austin Zheng,
	Alex Hung, Dan Wheeler, Alex Deucher

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Austin Zheng <Austin.Zheng@amd.com>

commit 93a77d353cb26772ae2fba50ae7321ae996b7f00 upstream.

[WHY/HOW]
Integer values for
dml2_core_calcs_CalculateWatermarksMALLUseAndDRAMSpeedChangeSupport_params
should not have the const qualifier.
This prevents using different values of the inputs when the
function is called again.

Reviewed-by: Dillon Varone <dillon.varone@amd.com>
Signed-off-by: Austin Zheng <Austin.Zheng@amd.com>
Signed-off-by: Alex Hung <alex.hung@amd.com>
Tested-by: Dan Wheeler <daniel.wheeler@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 342280aae4f33816e8d07c15cb538a3b375a7f8f)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/display/dc/dml2_0/dml21/src/dml2_core/dml2_core_shared_types.h |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/drivers/gpu/drm/amd/display/dc/dml2_0/dml21/src/dml2_core/dml2_core_shared_types.h
+++ b/drivers/gpu/drm/amd/display/dc/dml2_0/dml21/src/dml2_core/dml2_core_shared_types.h
@@ -1748,8 +1748,8 @@ struct dml2_core_calcs_CalculateWatermar
 	bool UnboundedRequestEnabled;
 	unsigned int CompressedBufferSizeInkByte;
 	bool max_outstanding_when_urgent_expected;
-	const unsigned int max_outstanding_requests;
-	const unsigned int max_request_size_bytes;
+	unsigned int max_outstanding_requests;
+	unsigned int max_request_size_bytes;
 	const unsigned int *meta_row_height_l;
 	const unsigned int *meta_row_height_c;
 	const enum dml2_pstate_method *uclk_pstate_switch_modes;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 493/556] drm/amd/display: Set gpuvm min page size to 4K on dcn35/36
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (491 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 492/556] drm/amd/display: Remove const Qualifier From Non-Pointer Fields Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 494/556] drm/amdgpu/gfx8: only apply compute quantums to KCQs Greg Kroah-Hartman
                   ` (75 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Mario Limonciello, Alex Deucher,
	Alex Hung, Roman Li, Dan Wheeler

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Roman Li <Roman.Li@amd.com>

commit 9ce3169430f1db035d491481086e2fae2552569c upstream.

[WHY]
Splash screen corruption on some 8K monitors.

[HOW]
Set GPUVM min page size to 4K for DCN35/36 to use the correct DML2
calculations, avoiding the corruption path observed during splash.

Fixes: 115009d11ccf ("drm/amd/display: Add DCN35 DML2 support")
Cc: Mario Limonciello <mario.limonciello@amd.com>
Cc: Alex Deucher <alexander.deucher@amd.com>
Reviewed-by: Alex Hung <alex.hung@amd.com>
Signed-off-by: Roman Li <Roman.Li@amd.com>
Signed-off-by: Alex Hung <alex.hung@amd.com>
Tested-by: Dan Wheeler <daniel.wheeler@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 2cbfb03dead5088a7bdfe2ce392a5caa3d1b3719)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/display/dc/dml2_0/dml2_translation_helper.c |    1 +
 1 file changed, 1 insertion(+)

--- a/drivers/gpu/drm/amd/display/dc/dml2_0/dml2_translation_helper.c
+++ b/drivers/gpu/drm/amd/display/dc/dml2_0/dml2_translation_helper.c
@@ -301,6 +301,7 @@ void dml2_init_socbb_params(struct dml2_
 		out->smn_latency_us = 2;
 		out->dispclk_dppclk_vco_speed_mhz = 3600;
 		out->pct_ideal_dram_bw_after_urgent_pixel_only = 65.0;
+		out->gpuvm_min_page_size_kbytes = 4;
 		break;
 
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 494/556] drm/amdgpu/gfx8: only apply compute quantums to KCQs
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (492 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 493/556] drm/amd/display: Set gpuvm min page size to 4K on dcn35/36 Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 495/556] drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check Greg Kroah-Hartman
                   ` (74 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jesse Zhang, Kent Russell,
	Alex Deucher

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Alex Deucher <alexander.deucher@amd.com>

commit 7346a046c6a9b9f30cb1f7d301449300a9174c71 upstream.

Don't apply to KIQ.  Seems to cause problems on KIQ
on some ARM platforms.

Closes: https://gitlab.freedesktop.org/drm/amd/-/work_items/5658
Fixes: 91cf34bc5a55 ("drm/amdgpu/gfx8: align mqd settings with KFD")
Reviewed-by: Jesse Zhang <jesse.zhang@amd.com>
Reviewed-by: Kent Russell <kent.russell@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 6aae7bab029cdccae9a7157facfe36bfc35fc940)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/amdgpu/gfx_v8_0.c |    8 +++++---
 1 file changed, 5 insertions(+), 3 deletions(-)

--- a/drivers/gpu/drm/amd/amdgpu/gfx_v8_0.c
+++ b/drivers/gpu/drm/amd/amdgpu/gfx_v8_0.c
@@ -4533,9 +4533,11 @@ static int gfx_v8_0_mqd_init(struct amdg
 	/* set static priority for a queue/ring */
 	gfx_v8_0_mqd_set_priority(ring, mqd);
 	tmp = RREG32(mmCP_HQD_QUANTUM);
-	tmp = REG_SET_FIELD(tmp, CP_HQD_QUANTUM, QUANTUM_EN, 1);
-	tmp = REG_SET_FIELD(tmp, CP_HQD_QUANTUM, QUANTUM_SCALE, 1);
-	tmp = REG_SET_FIELD(tmp, CP_HQD_QUANTUM, QUANTUM_DURATION, 10);
+	if (ring != &adev->gfx.kiq[0].ring) {
+		tmp = REG_SET_FIELD(tmp, CP_HQD_QUANTUM, QUANTUM_EN, 1);
+		tmp = REG_SET_FIELD(tmp, CP_HQD_QUANTUM, QUANTUM_SCALE, 1);
+		tmp = REG_SET_FIELD(tmp, CP_HQD_QUANTUM, QUANTUM_DURATION, 10);
+	}
 	mqd->cp_hqd_quantum = tmp;
 
 	/* map_queues packet doesn't need activate the queue,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 495/556] drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (493 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 494/556] drm/amdgpu/gfx8: only apply compute quantums to KCQs Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 496/556] drm/gud: NUL-terminate TV mode names read from the device Greg Kroah-Hartman
                   ` (73 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, David (Ming Qiang) Wu, Leo Liu,
	Alex Deucher

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: David (Ming Qiang) Wu <David.Wu3@amd.com>

commit 4d7390530853eb7befda9cc786e4c86e8ad7ac9e upstream.

If the supplied msg[2] (num_buffers) is 0x3FFFFFFF, the expression
6 + num_buffers * 4 wraps to 2 and the bounds check passes, letting
the parser loop far past the end of the message BO. Triggering it
additionally requires a ~4GiB mapping so that msg[1] survives the
earlier "header does not fit in BO" check.

Rewrite the test in division form, which is overflow-free by
construction. Also update the message to reflect that msg is invalid.

Fixes: b193019860d6 ("drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg")
Fixes: 0a78f2bac142 ("drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg")
Cc: stable@vger.kernel.org
Signed-off-by: David (Ming Qiang) Wu <David.Wu3@amd.com>
Reviewed-by: Leo Liu <leo.liu@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/amdgpu/vcn_v3_0.c |   10 +++++++---
 drivers/gpu/drm/amd/amdgpu/vcn_v4_0.c |   10 +++++++---
 2 files changed, 14 insertions(+), 6 deletions(-)

--- a/drivers/gpu/drm/amd/amdgpu/vcn_v3_0.c
+++ b/drivers/gpu/drm/amd/amdgpu/vcn_v3_0.c
@@ -1964,9 +1964,13 @@ static int vcn_v3_0_dec_msg(struct amdgp
 	len_dw = msg[1] / 4;
 	num_buffers = msg[2];
 
-	/* Verify that all indices fit within the claimed length. Each index is 4 DWORDs */
-	if (num_buffers > len_dw || 6 + num_buffers * 4 > len_dw) {
-		DRM_ERROR("VCN message has too many buffers!\n");
+	/* Verify that all indices fit within the claimed length.
+	 * There are 6 dwords in the header before the first buffer.
+	 * Each buffer has 4 dwords. Any trailing dwords after the
+	 * last buffer are ignored.
+	 */
+	if (len_dw < 6 || num_buffers > (len_dw - 6) / 4) {
+		DRM_ERROR("Invalid VCN message!\n");
 		r = -EINVAL;
 		goto out;
 	}
--- a/drivers/gpu/drm/amd/amdgpu/vcn_v4_0.c
+++ b/drivers/gpu/drm/amd/amdgpu/vcn_v4_0.c
@@ -1880,9 +1880,13 @@ static int vcn_v4_0_dec_msg(struct amdgp
 	len_dw = msg[1] / 4;
 	num_buffers = msg[2];
 
-	/* Verify that all indices fit within the claimed length. Each index is 4 DWORDs */
-	if (num_buffers > len_dw || 6 + num_buffers * 4 > len_dw) {
-		DRM_ERROR("VCN message has too many buffers!\n");
+	/* Verify that all indices fit within the claimed length.
+	 * There are 6 dwords in the header before the first buffer.
+	 * Each buffer has 4 dwords. Any trailing dwords after the
+	 * last buffer are ignored.
+	 */
+	if (len_dw < 6 || num_buffers > (len_dw - 6) / 4) {
+		DRM_ERROR("Invalid VCN message!\n");
 		r = -EINVAL;
 		goto out;
 	}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 496/556] drm/gud: NUL-terminate TV mode names read from the device
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (494 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 495/556] drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 497/556] drm/gud: validate TV mode names before creating enum property Greg Kroah-Hartman
                   ` (72 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+916c888ba5f1a54c9526,
	Deepanshu Kartikey, Ruben Wauters

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Deepanshu Kartikey <kartikey406@gmail.com>

commit 500cb24cd61bad8a2747ddfc49b7034899c82d94 upstream.

gud_connector_add_tv_mode() reads a buffer of fixed-size mode names from
the USB device and passes pointers into it to
drm_mode_create_tv_properties_legacy(), which calls strlen() on each one.
Nothing guarantees the device NUL-terminates a name, so strlen() can run
past the end of a slot and, for the last mode, past the end of the
allocation.

Terminate each name at the end of its slot before use.

Fixes: 40e1a70b4aed ("drm: Add GUD USB Display driver")
Reported-by: syzbot+916c888ba5f1a54c9526@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=916c888ba5f1a54c9526
Tested-by: syzbot+916c888ba5f1a54c9526@syzkaller.appspotmail.com
Signed-off-by: Deepanshu Kartikey <kartikey406@gmail.com>
Acked-by: Ruben Wauters <rubenru09@aol.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Ruben Wauters <rubenru09@aol.com>
Link: https://patch.msgid.link/20260816085234.22053-1-kartikey406@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/gud/gud_connector.c |    9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

--- a/drivers/gpu/drm/gud/gud_connector.c
+++ b/drivers/gpu/drm/gud/gud_connector.c
@@ -396,8 +396,13 @@ static int gud_connector_add_tv_mode(str
 	}
 
 	num_modes = ret / GUD_CONNECTOR_TV_MODE_NAME_LEN;
-	for (i = 0; i < num_modes; i++)
-		modes[i] = &buf[i * GUD_CONNECTOR_TV_MODE_NAME_LEN];
+	for (i = 0; i < num_modes; i++) {
+		char *mode = &buf[i * GUD_CONNECTOR_TV_MODE_NAME_LEN];
+
+		/* The device is not trusted to NUL-terminate the name */
+		mode[GUD_CONNECTOR_TV_MODE_NAME_LEN - 1] = '\0';
+		modes[i] = mode;
+	}
 
 	ret = drm_mode_create_tv_properties_legacy(connector->dev, num_modes, modes);
 free:



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 497/556] drm/gud: validate TV mode names before creating enum property
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (495 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 496/556] drm/gud: NUL-terminate TV mode names read from the device Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 498/556] drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value Greg Kroah-Hartman
                   ` (71 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, syzbot+9ae8e7884e451eaed5b4, Tao Yu,
	Ruben Wauters

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Tao Yu <tao1.yu@intel.com>

commit da1ea35fea67ad841f4ada28dd61b41be65e5437 upstream.

The GUD protocol returns TV mode names as fixed-size
GUD_CONNECTOR_TV_MODE_NAME_LEN entries and requires each name to be
NUL-terminated.

gud_connector_add_tv_mode() currently passes each fixed-size entry
directly to drm_mode_create_tv_properties_legacy(), which eventually
reaches drm_property_add_enum() and strlen(). If a device returns an
entry without a terminating NUL byte, strlen() reads past the end of
the slot and can run beyond the allocated buffer, triggering an
out-of-bounds read.

Validate that each returned TV mode name contains a NUL terminator
within its fixed-size slot before passing it to the DRM property code.
If a malformed entry is found, reject the device response with -EIO.

This fixes the out-of-bounds read without changing the handling of
valid devices, and avoids silently truncating malformed protocol data.

Reported-by: syzbot+9ae8e7884e451eaed5b4@syzkaller.appspotmail.com
Fixes: 40e1a70b4aed ("drm: Add GUD USB Display driver")
Signed-off-by: Tao Yu <tao1.yu@intel.com>
Reviewed-by: Ruben Wauters <rubenru09@aol.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Ruben Wauters <rubenru09@aol.com>
Link: https://patch.msgid.link/20260819072835.4074130-1-tao1.yu@intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/gud/gud_connector.c |    7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)

--- a/drivers/gpu/drm/gud/gud_connector.c
+++ b/drivers/gpu/drm/gud/gud_connector.c
@@ -399,8 +399,11 @@ static int gud_connector_add_tv_mode(str
 	for (i = 0; i < num_modes; i++) {
 		char *mode = &buf[i * GUD_CONNECTOR_TV_MODE_NAME_LEN];
 
-		/* The device is not trusted to NUL-terminate the name */
-		mode[GUD_CONNECTOR_TV_MODE_NAME_LEN - 1] = '\0';
+		if (!memchr(mode, '\0', GUD_CONNECTOR_TV_MODE_NAME_LEN)) {
+			ret = -EIO;
+			goto free;
+		}
+
 		modes[i] = mode;
 	}
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 498/556] drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (496 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 497/556] drm/gud: validate TV mode names before creating enum property Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:42 ` [PATCH 7.2 499/556] drm: Fix drm_crtc_commit leak if signaled when PAGE_FLIP_EVENT is used Greg Kroah-Hartman
                   ` (70 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Daniel Mack, Kavan Smith,
	Dmitry Baryshkov

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Kavan Smith <kavansmith82@gmail.com>

commit 6cd33b6f4155efc20485929fd0b56bb704641db9 upstream.

MSM8916 runtime DSI commands still go through
msm_dsi_host_xfer_prepare(), which re-applies the link clock rate before
enabling the link clocks. That is fine in principle, but on DSI 6G the
requested byte clock rate often does not exactly match the DSI PHY PLL's
realizable rate. For example, the driver can request 56250000 Hz while the
PLL actually runs at 56246337 Hz.

Because the requested and actual rates differ slightly, every later
link_clk_set_rate() call is treated as a real clock change and re-locks
the PLL. On a video-mode panel without an internal timing generator, such
as samsung,s6d7aa0 / lsl080al03 on MSM8916, that live-clock glitch makes
the panel lose pixel lock and visibly corrupts scanout on each runtime DCS
command, including backlight writes.

Fix this by rounding the computed 6G byte clock rate up front, before it is
stored in msm_host->byte_clk_rate and reused by later transfers. Once the
host carries the PLL-achievable rate instead of the idealized one,
repeated link_clk_set_rate() calls become no-ops in the common clock
framework and no longer re-lock the PLL.

This keeps the normal transfer callback sequencing intact, preserves the
OPP vote path in link_clk_set_rate(), and matches the fix direction
suggested in the original 2018 discussion.

Reported-by: Daniel Mack <daniel@zonque.org>
Closes: https://lore.kernel.org/all/1a682c5b-7fc9-3aaa-120b-64b239a355a3@zonque.org/
Fixes: 6b16f05aa39f ("drm/msm/dsi: Split clk rate setting and enable")
Cc: stable@vger.kernel.org
Signed-off-by: Kavan Smith <kavansmith82@gmail.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/738234/
Link: https://lore.kernel.org/r/20260707013240.681012-1-kavansmith82@gmail.com
[DB: dropped extra chunk from the patch]
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/msm/dsi/dsi_host.c |   12 ++++++++++++
 1 file changed, 12 insertions(+)

--- a/drivers/gpu/drm/msm/dsi/dsi_host.c
+++ b/drivers/gpu/drm/msm/dsi/dsi_host.c
@@ -670,12 +670,24 @@ static void dsi_calc_pclk(struct msm_dsi
 
 int dsi_calc_clk_rate_6g(struct msm_dsi_host *msm_host, bool is_bonded_dsi)
 {
+	long rounded_byte_clk_rate;
+
 	if (!msm_host->mode) {
 		pr_err("%s: mode not set\n", __func__);
 		return -EINVAL;
 	}
 
 	dsi_calc_pclk(msm_host, is_bonded_dsi);
+
+	rounded_byte_clk_rate = clk_round_rate(msm_host->byte_clk,
+					       msm_host->byte_clk_rate);
+	if (rounded_byte_clk_rate < 0) {
+		pr_err("%s: failed to round byte clock rate, %ld\n",
+		       __func__, rounded_byte_clk_rate);
+		return rounded_byte_clk_rate;
+	}
+
+	msm_host->byte_clk_rate = rounded_byte_clk_rate;
 	msm_host->esc_clk_rate = clk_get_rate(msm_host->esc_clk);
 	return 0;
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 499/556] drm: Fix drm_crtc_commit leak if signaled when PAGE_FLIP_EVENT is used
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (497 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 498/556] drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value Greg Kroah-Hartman
@ 2026-09-09 13:42 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 500/556] drm/ttm: Drop tt->restore after successful restore Greg Kroah-Hartman
                   ` (69 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:42 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Thadeu Lima de Souza Cascardo,
	Melissa Wen

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Thadeu Lima de Souza Cascardo <cascardo@igalia.com>

commit 4d4be202165e832d74849b4a68e289a2a377039c upstream.

Commit 1c6ceeee6ebb ("drm/atomic: Fix memleak on ERESTARTSYS during
non-blocking commits") fixed a very similar issue when the event was
allocated by drm_atomic_helper_setup_commit() itself.

However, if the event is allocated in prepare_signaling(), it will also be
set to NULL in complete_signaling(), which prevents drm_crtc_commit from
being put in __drm_atomic_helper_crtc_destroy_state().

Dropping the reference when the event is set to NULL at
complete_signaling() fixes the leak.

The leak can be reproduced by sending a signal to the thread using
DRM_MODE_PAGE_FLIP_EVENT and using a sw_sync fence to cause the atomic
ioctl to block at drm_atomic_helper_wait_for_fences(). It happened both
with amdgpu and vkms.

Fixes: 24835e442f28 ("drm: reference count event->completion")
Cc: stable@vger.kernel.org
Signed-off-by: Thadeu Lima de Souza Cascardo <cascardo@igalia.com>
Reviewed-by: Melissa Wen <mwen@igalia.com>
Signed-off-by: Melissa Wen <mwen@igalia.com>
Link: https://patch.msgid.link/20260727-drm_crtc_atomic_commit_leak-v1-1-23d9948a9d7c@igalia.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/drm_atomic_uapi.c |    2 ++
 1 file changed, 2 insertions(+)

--- a/drivers/gpu/drm/drm_atomic_uapi.c
+++ b/drivers/gpu/drm/drm_atomic_uapi.c
@@ -1563,6 +1563,8 @@ static void complete_signaling(struct dr
 		 * to prevent a double free in drm_atomic_commit_clear.
 		 */
 		if (event && (event->base.fence || event->base.file_priv)) {
+			if (crtc_state->commit && crtc_state->commit->abort_completion)
+				drm_crtc_commit_put(crtc_state->commit);
 			drm_event_cancel_free(dev, &event->base);
 			crtc_state->event = NULL;
 		}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 500/556] drm/ttm: Drop tt->restore after successful restore
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (498 preceding siblings ...)
  2026-09-09 13:42 ` [PATCH 7.2 499/556] drm: Fix drm_crtc_commit leak if signaled when PAGE_FLIP_EVENT is used Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 501/556] drm/amdgpu: check thunderbolt before switcheroo registration Greg Kroah-Hartman
                   ` (68 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Thomas Hellström,
	Christian Koenig, Huang Rui, Matthew Auld, Maarten Lankhorst,
	Maxime Ripard, Thomas Zimmermann, David Airlie, Simona Vetter,
	dri-devel, linux-kernel, Matthew Brost

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Matthew Brost <matthew.brost@intel.com>

commit 941ac10529b3be5965a88d432a161ab459672ba8 upstream.

ttm_pool_restore_and_alloc() can successfully complete the restore
process via ttm_pool_restore_commit(), but tt->restore is not dropped
afterward. As a result, subsequent backup/restore flows observe what
appears to be a completed restore, while in reality shmem handles are
still installed in tt->pages, leading to the stack trace below.

Fix this by freeing and dropping tt->restore in
ttm_pool_restore_and_alloc() upon successful completion of the restore.

20545 [  309.784531] RIP: 0010:sg_alloc_append_table_from_pages+0x38c/0x490
20547 [  309.809570] RSP: 0018:ffffc9000623b838 EFLAGS: 00010206
20548 [  309.814827] RAX: 0000000000001000 RBX: ffff88816e42a160 RCX: 0000000000000000
20549 [  309.821986] RDX: 0000000000002000 RSI: 0000000000000003 RDI: 0000000000001000
20550 [  309.829147] RBP: ffff88816e42a168 R08: 0000000000000002 R09: 000000007ffff000
20551 [  309.836310] R10: ffffc9000623b928 R11: 0000000000000000 R12: 000000007ffff000
20552 [  309.843471] R13: ffff88815ba5a100 R14: 0000000000000000 R15: 0000000000000001
20553 [  309.850634] FS:  00007f9ff305e700(0000) GS:ffff888276c94000(0000) knlGS:0000000000000000
20554 [  309.858749] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
20555 [  309.864519] CR2: 00007f9fca701000 CR3: 00000001565e2005 CR4: 0000000008f70ef0
20556 [  309.871678] PKRU: 55555558
20557 [  309.874403] Call Trace:
20558 [  309.876866]  <TASK>
20559 [  309.878988]  sg_alloc_table_from_pages_segment+0x60/0x100
20560 [  309.884415]  ? ttm_resource_manager_usage+0x36/0x60 [ttm]
20561 [  309.889845]  ? xe_tt_map_sg+0x7d/0xd0 [xe]
20562 [  309.894045]  xe_tt_map_sg+0x7d/0xd0 [xe]
20563 [  309.898037]  xe_bo_move+0x927/0xaa0 [xe]
20564 [  309.902029]  ttm_bo_handle_move_mem+0xba/0x170 [ttm]
20565 [  309.907022]  ttm_bo_validate+0xbe/0x190 [ttm]
20566 [  309.911405]  xe_bo_validate+0x9a/0x120 [xe]
20567 [  309.915663]  xe_gpuvm_validate+0xd9/0x140 [xe]
20568 [  309.920206]  drm_gpuvm_validate+0x2f0/0x5b0 [drm_gpuvm]
20569 [  309.925459]  ? drm_exec_lock_obj+0x63/0x210 [drm_exec]
20570 [  309.930627]  xe_vm_validate_rebind+0x46/0xb0 [xe]
20571 [  309.935428]  xe_exec_fn+0x20/0x40 [xe]
20572 [  309.939249]  drm_gpuvm_exec_lock+0x78/0xc0 [drm_gpuvm]
20573 [  309.944410]  xe_validation_exec_lock+0x5a/0xa0 [xe]
20574 [  309.949385]  xe_exec_ioctl+0x806/0xc30 [xe]
20575 [  309.953639]  ? ttwu_queue_wakelist+0xd9/0xf0
20576 [  309.957935]  ? __pfx_xe_exec_fn+0x10/0x10 [xe]
20577 [  309.962449]  ? __wake_up_common+0x73/0xa0
20578 [  309.966482]  ? __pfx_xe_exec_ioctl+0x10/0x10 [xe]
20579 [  309.971263]  drm_ioctl_kernel+0xa3/0x100
20580 [  309.975209]  drm_ioctl+0x213/0x440
20581 [  309.978637]  ? __pfx_xe_exec_ioctl+0x10/0x10 [xe]
20582 [  309.983415]  xe_drm_ioctl+0x67/0xd0 [xe]
20583 [  309.987408]  __x64_sys_ioctl+0x7f/0xd0

Cc: Thomas Hellström <thomas.hellstrom@linux.intel.com>
Cc: Christian Koenig <christian.koenig@amd.com>
Cc: Huang Rui <ray.huang@amd.com>
Cc: Matthew Auld <matthew.auld@intel.com>
Cc: Maarten Lankhorst <maarten.lankhorst@linux.intel.com>
Cc: Maxime Ripard <mripard@kernel.org>
Cc: Thomas Zimmermann <tzimmermann@suse.de>
Cc: David Airlie <airlied@gmail.com>
Cc: Simona Vetter <simona@ffwll.ch>
Cc: dri-devel@lists.freedesktop.org
Cc: linux-kernel@vger.kernel.org
Cc: stable@vger.kernel.org
Fixes: b63d715b8090 ("drm/ttm/pool, drm/ttm/tt: Provide a helper to shrink pages")
Signed-off-by: Matthew Brost <matthew.brost@intel.com>
Reviewed-by: Thomas Hellström <thomas.hellstrom@linux.intel.com>
Link: https://patch.msgid.link/20260617015531.1164189-1-matthew.brost@intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/ttm/ttm_pool.c |   15 ++++++++++++---
 1 file changed, 12 insertions(+), 3 deletions(-)

--- a/drivers/gpu/drm/ttm/ttm_pool.c
+++ b/drivers/gpu/drm/ttm/ttm_pool.c
@@ -917,6 +917,7 @@ int ttm_pool_restore_and_alloc(struct tt
 {
 	struct ttm_pool_tt_restore *restore = tt->restore;
 	struct ttm_pool_alloc_state alloc;
+	int ret;
 
 	if (WARN_ON(!ttm_tt_is_backed_up(tt)))
 		return -EINVAL;
@@ -940,14 +941,22 @@ int ttm_pool_restore_and_alloc(struct tt
 	} else {
 		alloc = restore->snapshot_alloc;
 		if (ttm_pool_restore_valid(restore)) {
-			int ret = ttm_pool_restore_commit(restore, tt->backup,
-							  ctx, &alloc);
+			ret = ttm_pool_restore_commit(restore, tt->backup,
+						      ctx, &alloc);
 
 			if (ret)
 				return ret;
 		}
-		if (!alloc.remaining_pages)
+		if (!alloc.remaining_pages) {
+			ret = ttm_pool_apply_caching(&alloc);
+			if (ret)
+				return ret;
+
+			kfree(tt->restore);
+			tt->restore = NULL;
+
 			return 0;
+		}
 	}
 
 	return __ttm_pool_alloc(pool, tt, ctx, &alloc, restore);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 501/556] drm/amdgpu: check thunderbolt before switcheroo registration
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (499 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 500/556] drm/ttm: Drop tt->restore after successful restore Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 502/556] drm/amdgpu: delay ttm buffer func enablement on xgmi Greg Kroah-Hartman
                   ` (67 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Yang Wang, Kenneth Feng,
	Alex Deucher

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yang Wang <kevinyang.wang@amd.com>

commit 8587d48d694da5aca580f92461658ec14470592b upstream.

Introduce a helper to consolidate the vga_switcheroo registration condition
used by the init and fini paths.

Keep the explicit pci_is_thunderbolt_attached() check, as dev_is_removable()
does not provide equivalent coverage for Thunderbolt-attached GPUs.
This ensures such devices remain excluded from switcheroo registration while
preserving the existing PX and Apple gmux handling.

Cc: stable@vger.kernel.org
Signed-off-by: Yang Wang <kevinyang.wang@amd.com>
Reviewed-by: Kenneth Feng <kenneth.feng@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/amdgpu/amdgpu_device.c |   14 ++++++++++----
 1 file changed, 10 insertions(+), 4 deletions(-)

--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_device.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_device.c
@@ -3745,6 +3745,14 @@ static void amdgpu_device_sys_interface_
 	amdgpu_ptl_sysfs_fini(adev);
 }
 
+static bool
+amdgpu_device_should_register_switcheroo(struct amdgpu_device *adev, bool px)
+{
+	return !pci_is_thunderbolt_attached(adev->pdev) &&
+	       (px || (!dev_is_removable(&adev->pdev->dev) &&
+		       apple_gmux_detect(NULL, NULL)));
+}
+
 /**
  * amdgpu_device_init - initialize the driver
  *
@@ -4194,8 +4202,7 @@ fence_driver_init:
 
 	px = amdgpu_device_supports_px(adev);
 
-	if (px || (!dev_is_removable(&adev->pdev->dev) &&
-				apple_gmux_detect(NULL, NULL)))
+	if (amdgpu_device_should_register_switcheroo(adev, px))
 		vga_switcheroo_register_client(adev->pdev,
 					       &amdgpu_switcheroo_ops, px);
 
@@ -4359,8 +4366,7 @@ void amdgpu_device_fini_sw(struct amdgpu
 
 	px = amdgpu_device_supports_px(adev);
 
-	if (px || (!dev_is_removable(&adev->pdev->dev) &&
-				apple_gmux_detect(NULL, NULL)))
+	if (amdgpu_device_should_register_switcheroo(adev, px))
 		vga_switcheroo_unregister_client(adev->pdev);
 
 	if (px)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 502/556] drm/amdgpu: delay ttm buffer func enablement on xgmi
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (500 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 501/556] drm/amdgpu: check thunderbolt before switcheroo registration Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 503/556] drm/amdgpu: clamp the isolation index for rings outside a partition Greg Kroah-Hartman
                   ` (66 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Pierre-Eric Pelloux-Prayer,
	Alex Deucher

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pierre-Eric Pelloux-Prayer <pierre-eric.pelloux-prayer@amd.com>

commit c675dea86a000e9550077c5bca97c6431786d1b7 upstream.

When amdgpu_init_minimal_xgmi is used, SDMA engines init
is delayed so amdgpu_ttm_enable_buffer_funcs must be
called later.

Without this, the check for num_buffer_funcs_scheds will
fail and using ttm buffer funcs later will fail.

Given that amdgpu_ttm_enable_buffer_funcs is a no-op if
amdgpu_in_reset() returns true, the call has to occur
after the reset lock is dropped.

Cc: stable@vger.kernel.org
Fixes: e4029f7a9474 ("drm/amdgpu: only use working sdma schedulers for ttm")
Signed-off-by: Pierre-Eric Pelloux-Prayer <pierre-eric.pelloux-prayer@amd.com>
Reviewed-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/amdgpu/amdgpu_device.c |    8 +++++---
 drivers/gpu/drm/amd/amdgpu/amdgpu_xgmi.c   |    3 +++
 2 files changed, 8 insertions(+), 3 deletions(-)

--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_device.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_device.c
@@ -2537,7 +2537,11 @@ static int amdgpu_device_ip_init(struct
 	if (r)
 		goto init_failed;
 
-	amdgpu_ttm_enable_buffer_funcs(adev);
+	/* If SDMA is not brought up during hwini, the ttm buffer funcs enablement
+	 * is delayed after reset-on-init completes.
+	 */
+	if (amdgpu_ip_member_of_hwini(adev, AMD_IP_BLOCK_TYPE_SDMA))
+		amdgpu_ttm_enable_buffer_funcs(adev);
 
 	/* Don't init kfd if whole hive need to be reset during init */
 	if (adev->init_lvl->level != AMDGPU_INIT_LEVEL_MINIMAL_XGMI) {
@@ -5321,8 +5325,6 @@ int amdgpu_device_reinit_after_reset(str
 				if (r)
 					goto out;
 
-				amdgpu_ttm_enable_buffer_funcs(tmp_adev);
-
 				r = amdgpu_device_ip_resume_phase3(tmp_adev);
 				if (r)
 					goto out;
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_xgmi.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_xgmi.c
@@ -1659,6 +1659,9 @@ static void amdgpu_xgmi_reset_on_init_wo
 	amdgpu_device_unlock_reset_domain(tmp_adev->reset_domain);
 
 	list_for_each_entry(tmp_adev, &hive->device_list, gmc.xgmi.head) {
+		/* Enable ttm buffers funcs after the reset lock has been dropped. */
+		amdgpu_ttm_enable_buffer_funcs(tmp_adev);
+
 		r = amdgpu_ras_init_badpage_info(tmp_adev);
 		if (r && r != -EHWPOISON)
 			dev_err(tmp_adev->dev,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 503/556] drm/amdgpu: clamp the isolation index for rings outside a partition
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (501 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 502/556] drm/amdgpu: delay ttm buffer func enablement on xgmi Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 504/556] drm/amdgpu: Disable runtime PM for externally attached dGPUs Greg Kroah-Hartman
                   ` (65 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Xiang Liu, Hawking Zhang,
	Alex Deucher

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Xiang Liu <xiang.liu@amd.com>

commit b30900566642ceb2c9e12b56c2afec28d0fd91a0 upstream.

adev->isolation[] has one slot per partition, but a ring that is not
assigned to one keeps AMDGPU_XCP_NO_PARTITION, which is ~0, so indexing
the array with it is out of bounds. SDMA submissions hit this on both
the isolation enforcement and the VM flush path and trip UBSAN.

Fall back to the first slot the way the cleaner shader path already
does, and stop taking the address before the ring type check that makes
it relevant.

Cc: stable@vger.kernel.org
Signed-off-by: Xiang Liu <xiang.liu@amd.com>
Reviewed-by: Hawking Zhang <Hawking.Zhang@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/amdgpu/amdgpu_device.c |    5 ++++-
 drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c     |    4 +++-
 2 files changed, 7 insertions(+), 2 deletions(-)

--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_device.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_device.c
@@ -6834,8 +6834,8 @@ struct dma_fence *amdgpu_device_enforce_
 						  struct amdgpu_ring *ring,
 						  struct amdgpu_job *job)
 {
-	struct amdgpu_isolation *isolation = &adev->isolation[ring->xcp_id];
 	struct drm_sched_fence *f = job->base.s_fence;
+	struct amdgpu_isolation *isolation;
 	struct dma_fence *dep;
 	void *owner;
 	int r;
@@ -6848,6 +6848,9 @@ struct dma_fence *amdgpu_device_enforce_
 	    ring->funcs->type != AMDGPU_RING_TYPE_COMPUTE)
 		return NULL;
 
+	isolation = &adev->isolation[ring->xcp_id == AMDGPU_XCP_NO_PARTITION ?
+				     0 : ring->xcp_id];
+
 	/*
 	 * All submissions where enforce isolation is false are handled as if
 	 * they come from a single client. Use ~0l as the owner to distinct it
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c
@@ -773,7 +773,9 @@ void amdgpu_vm_flush(struct amdgpu_ring
 		     bool need_pipe_sync)
 {
 	struct amdgpu_device *adev = ring->adev;
-	struct amdgpu_isolation *isolation = &adev->isolation[ring->xcp_id];
+	struct amdgpu_isolation *isolation =
+		&adev->isolation[ring->xcp_id == AMDGPU_XCP_NO_PARTITION ?
+				 0 : ring->xcp_id];
 	unsigned vmhub = ring->vm_hub;
 	struct amdgpu_vmid_mgr *id_mgr = &adev->vm_manager.id_mgr[vmhub];
 	struct amdgpu_vmid *id = &id_mgr->ids[job->vmid];



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 504/556] drm/amdgpu: Disable runtime PM for externally attached dGPUs
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (502 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 503/556] drm/amdgpu: clamp the isolation index for rings outside a partition Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 505/556] drm/amdgpu: fix autosuspend cleanup during removal Greg Kroah-Hartman
                   ` (64 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yang Wang, Candice Li, Kenneth Feng,
	Alex Deucher

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Yang Wang <kevinyang.wang@amd.com>

commit c52feb4365396b6a881b5e8a95540517ffabb3b7 upstream.

pci_is_thunderbolt_attached() requires an upstream PCI bridge with
is_thunderbolt set from an Intel Thunderbolt VSEC. This does not cover
the affected ASM4242 USB4 PCI hierarchy:

  00:02.2
    \- 0f:00.0 [1b21:2421]
       +- 10:01.0 [1b21:2423] -> 45:00.0 -> 46:00.0
       |  -> 47:00.0 -> 48:00.0 -> 49:00.0 [1002:7590]
       \- 10:03.0 -> 76:00.0 [1b21:2425] USB4 Host Router

The host router is outside the GPU upstream bridge chain, leaving no
ancestor with is_thunderbolt set. PCI core propagates DEVICE_REMOVABLE
below the external-facing PCIe tunnel. Disable Runtime PM when either
pci_is_thunderbolt_attached() or dev_is_removable() is true.

Cc: stable@vger.kernel.org
Signed-off-by: Yang Wang <kevinyang.wang@amd.com>
Reviewed-by: Candice Li <candice.li@amd.com>
Reviewed-by: Kenneth Feng <kenneth.feng@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/amdgpu/amdgpu_device.c |    7 +++++++
 1 file changed, 7 insertions(+)

--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_device.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_device.c
@@ -607,6 +607,13 @@ void amdgpu_device_detect_runtime_pm_mod
 	int bamaco_support;
 
 	adev->pm.rpm_mode = AMDGPU_RUNPM_NONE;
+	if (pci_is_thunderbolt_attached(adev->pdev) ||
+	    dev_is_removable(&adev->pdev->dev)) {
+		dev_info(adev->dev,
+			 "Runtime PM disabled for externally attached device\n");
+		return;
+	}
+
 	bamaco_support = amdgpu_device_supports_baco(adev);
 
 	switch (amdgpu_runtime_pm) {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 505/556] drm/amdgpu: fix autosuspend cleanup during removal
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (503 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 504/556] drm/amdgpu: Disable runtime PM for externally attached dGPUs Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 506/556] drm/amdgpu: fix byte/dword unit mismatch in coredump IB dump Greg Kroah-Hartman
                   ` (63 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Guangshuo Li,
	Mario Limonciello (AMD), Mario Limonciello, Alex Deucher

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Guangshuo Li <lgs201920130244@gmail.com>

commit ef5fcf2a6c320676bf8be2dadac93d9023b468b7 upstream.

amdgpu_pci_probe() calls pm_runtime_use_autosuspend(), but
amdgpu_pci_remove() does not call the matching
pm_runtime_dont_use_autosuspend().

If the autosuspend delay is set to a negative value while autosuspend
is enabled, the runtime PM core increments usage_count to prevent
runtime suspend. Without calling pm_runtime_dont_use_autosuspend()
during teardown, this reference is not dropped and usage_count remains
unbalanced.

The documentation for pm_runtime_use_autosuspend() also notes that it
is important to undo it with pm_runtime_dont_use_autosuspend() at
driver exit time, unless runtime PM was initially enabled with
devm_pm_runtime_enable().

Add the missing pm_runtime_dont_use_autosuspend() call to the remove
path.

This issue was found by manual code inspection.

Fixes: d38ceaf99ed0 ("drm/amdgpu: add core driver (v4)")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Link: https://patch.msgid.link/20260808120934.2813010-1-lgs201920130244@gmail.com
Signed-off-by: Mario Limonciello <mario.limonciello@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/amdgpu/amdgpu_drv.c |    1 +
 1 file changed, 1 insertion(+)

--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_drv.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_drv.c
@@ -2548,6 +2548,7 @@ amdgpu_pci_remove(struct pci_dev *pdev)
 	if (adev->pm.rpm_mode != AMDGPU_RUNPM_NONE) {
 		pm_runtime_get_sync(dev->dev);
 		pm_runtime_forbid(dev->dev);
+		pm_runtime_dont_use_autosuspend(dev->dev);
 	}
 
 	amdgpu_driver_unload_kms(dev);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 506/556] drm/amdgpu: fix byte/dword unit mismatch in coredump IB dump
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (504 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 505/556] drm/amdgpu: fix autosuspend cleanup during removal Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 507/556] drm/amdgpu: fix Idle BOs list in VM debugfs status info Greg Kroah-Hartman
                   ` (62 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sunil Khatri, Vitaly Prosyak,
	Christian König, Alex Deucher

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sunil Khatri <sunil.khatri@amd.com>

commit 3b5c4f4a479d0e58a7500cbd2b09d62f719f48b8 upstream.

In amdgpu_devcoredump_print_ibs(), the NO_CPU_ACCESS VRAM path passed
cursor.start/4 and cursor.size/4 to amdgpu_device_mm_access(), but that
function's pos/size parameters are byte offsets/lengths (confirmed by
amdgpu_ttm_vram_mm_access() and leading to wrong size calculation.

Similarly with that change the off index needs to be calculated
based on dword since that is a u32 type.

Fixes: 7b15fc2d1f1a ("drm/amdgpu: dump job ibs in the devcoredump")
Signed-off-by: Sunil Khatri <sunil.khatri@amd.com>
Reviewed-by: Vitaly Prosyak <vitaly.prosyak@amd.com>
Acked-by: Christian König <christian.koenig@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 1bd613b0ed98a23575b18674c94b8b3392614681)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/amdgpu/amdgpu_dev_coredump.c |    6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_dev_coredump.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_dev_coredump.c
@@ -298,10 +298,10 @@ amdgpu_devcoredump_print_ibs(struct drm_
 			amdgpu_res_first(abo->tbo.resource, offset,
 					 coredump->ibs[i].ib_size_dw * 4, &cursor);
 			while (cursor.remaining) {
-				amdgpu_device_mm_access(adev, cursor.start / 4,
-							&ib_content[off], cursor.size / 4,
+				amdgpu_device_mm_access(adev, cursor.start,
+							&ib_content[off], cursor.size,
 							false);
-				off += cursor.size;
+				off += cursor.size / 4;
 				amdgpu_res_next(&cursor, cursor.size);
 			}
 			emit_content = true;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 507/556] drm/amdgpu: fix Idle BOs list in VM debugfs status info
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (505 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 506/556] drm/amdgpu: fix byte/dword unit mismatch in coredump IB dump Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 508/556] drm/amdgpu: force complete the KIQ ring fences on reset Greg Kroah-Hartman
                   ` (61 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Sunil Khatri, Alex Deucher

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sunil Khatri <sunil.khatri@amd.com>

commit 90ce19bd11b2864e26e4b43e7acbffabf037b69b upstream.

amdgpu_debugfs_vm_bo_status_info() prints the "Idle BOs" section by
iterating lists->needs_update, the same list already printed just
above under "Moved BOs". struct amdgpu_vm_bo_status has a dedicated
idle list, populated whenever a BO's state machine settles, but it
was never read here, so genuinely idle BOs never show up in the
debugfs output and the "Idle BOs" section duplicates "Moved BOs"
instead.

Iterate lists->idle for the "Idle BOs" section.

Fixes: 4cdbba5a16aa ("drm/amdgpu: restructure VM state machine v4")
Signed-off-by: Sunil Khatri <sunil.khatri@amd.com>
Reviewed-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 451bfc778a8c364841837def00ba15936f72762b)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c
@@ -3111,7 +3111,7 @@ static void amdgpu_debugfs_vm_bo_status_
 
 	id = 0;
 	seq_puts(m, "\tIdle BOs:\n");
-	list_for_each_entry(base, &lists->needs_update, vm_status) {
+	list_for_each_entry(base, &lists->idle, vm_status) {
 		if (!base->bo)
 			continue;
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 508/556] drm/amdgpu: force complete the KIQ ring fences on reset
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (506 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 507/556] drm/amdgpu: fix Idle BOs list in VM debugfs status info Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 509/556] drm/amdgpu: force complete the MES " Greg Kroah-Hartman
                   ` (60 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Alex Deucher, Jesse Zhang

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jesse Zhang <Jesse.Zhang@amd.com>

commit fd65d1742992361fc2201ecb4e43411e6e417fcb upstream.

Like the MES scheduler ring, the KIQ ring sets no_scheduler = true and uses a
polling fence, so it is skipped by the force-completion loop in
amdgpu_device_pre_asic_reset(). Its hw fence value lives in wb (GTT) memory and
survives a MODE1 reset while fence_drv.sync_seq keeps advancing, so after a
reset the first KIQ submission can poll forever on a seq that is never written
back.

Force complete the KIQ ring fences too so their hw fence is realigned to
sync_seq.

Cc: stable@vger.kernel.org
Reviewed-by: Alex Deucher <alexander.deucher@amd.com>
Suggested-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Jesse Zhang <Jesse.Zhang@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/amdgpu/amdgpu_device.c |   12 ++++++++++++
 1 file changed, 12 insertions(+)

--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_device.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_device.c
@@ -5219,6 +5219,18 @@ int amdgpu_device_pre_asic_reset(struct
 		amdgpu_fence_driver_force_completion(ring, fence);
 	}
 
+	/*
+	 * KIQ rings are polling-fence/no_scheduler like MES, so realign their
+	 * fence too (one ring per XCC), otherwise the first post-reset KIQ
+	 * submission polls forever on a stale seq.
+	 */
+	for (i = 0; i < AMDGPU_MAX_GC_INSTANCES; i++) {
+		struct amdgpu_ring *kiq_ring = &adev->gfx.kiq[i].ring;
+
+		if (kiq_ring->fence_drv.initialized && kiq_ring->sched.ready)
+			amdgpu_fence_driver_force_completion(kiq_ring, fence);
+	}
+
 	amdgpu_fence_driver_isr_toggle(adev, false);
 
 	r = amdgpu_reset_prepare_hwcontext(adev, reset_context);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 509/556] drm/amdgpu: force complete the MES ring fences on reset
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (507 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 508/556] drm/amdgpu: force complete the KIQ ring fences on reset Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 510/556] drm/amdgpu: Skip accessing psp rum time db for APUs Greg Kroah-Hartman
                   ` (59 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jesse Zhang, Alex Deucher

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jesse Zhang <Jesse.Zhang@amd.com>

commit 48dc279c3010ac8f91b1845b2abb3a1e9943a0f5 upstream.

The MES scheduler ring has no drm scheduler (no_scheduler = true), so it is
skipped by the force-completion loop in amdgpu_device_pre_asic_reset(). It uses
a polling fence whose hw value lives in wb (GTT) memory and survives a MODE1
reset, while fence_drv.sync_seq keeps advancing for every packet.

When the reset is triggered because MES itself stopped responding, the
timed-out packets advance sync_seq past the last hw fence value MES wrote.
After resume the first MES submission polls forever on a seq that is never
written back, failing the resume and wedging the box on a second reset:

  amdgpu: MES ring buffer is full.
  amdgpu: *ERROR* ring gfx_0.0.0 test failed (-110)
  amdgpu: resume of IP block <gfx_v11_0> failed -110
  amdgpu: GPU reset end with ret = -110

Force complete the MES scheduler ring fences together with the scheduler rings
so their hw fence is realigned to sync_seq.

v2: cover all XCCs (one scheduler ring each), not just mes.ring[0].

Cc: stable@vger.kernel.org
Signed-off-by: Jesse Zhang <Jesse.Zhang@amd.com>
Reviewed-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/amdgpu/amdgpu_device.c |   13 +++++++++++++
 1 file changed, 13 insertions(+)

--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_device.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_device.c
@@ -5231,6 +5231,19 @@ int amdgpu_device_pre_asic_reset(struct
 			amdgpu_fence_driver_force_completion(kiq_ring, fence);
 	}
 
+	/*
+	 * MES scheduler rings have no drm scheduler, so they are missed by the
+	 * loop above. Realign their polling fence too (one per XCC), otherwise the
+	 * first post-reset submission polls forever on a stale seq. sched.ready is
+	 * only set while the driver owns the ring.
+	 */
+	for (i = 0; i < AMDGPU_MAX_MES_INST_PIPES; i++) {
+		struct amdgpu_ring *mes_ring = &adev->mes.ring[i];
+
+		if (mes_ring->fence_drv.initialized && mes_ring->sched.ready)
+			amdgpu_fence_driver_force_completion(mes_ring, fence);
+	}
+
 	amdgpu_fence_driver_isr_toggle(adev, false);
 
 	r = amdgpu_reset_prepare_hwcontext(adev, reset_context);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 510/556] drm/amdgpu: Skip accessing psp rum time db for APUs
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (508 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 509/556] drm/amdgpu: force complete the MES " Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 511/556] drm/amdgpu: update the fw version for gfx11 userqueues Greg Kroah-Hartman
                   ` (58 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Kanala Ramalingeswara Reddy,
	Alex Deucher

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Kanala Ramalingeswara Reddy <Kanala.RamalingeswaraReddy@amd.com>

commit a26301203a196a991527f7b1ab884d4dd0e7c95e upstream.

Psp runtime DB is for dGPUs only.

Signed-off-by: Kanala Ramalingeswara Reddy <Kanala.RamalingeswaraReddy@amd.com>
Acked-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit dce8195027f146467c9378efb2bb1b0859cb735e)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/amdgpu/amdgpu_psp.c |    6 ++++++
 1 file changed, 6 insertions(+)

--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_psp.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_psp.c
@@ -396,6 +396,12 @@ static bool psp_get_runtime_db_entry(str
 	bool ret = false;
 	int i;
 
+	/*
+	 * Runtime DB is for dGPUs only.
+	 */
+	if (adev->flags & AMD_IS_APU)
+		return false;
+
 	if (amdgpu_ip_version(adev, MP0_HWIP, 0) == IP_VERSION(13, 0, 6) ||
 	    amdgpu_ip_version(adev, MP0_HWIP, 0) == IP_VERSION(13, 0, 12) ||
 	    amdgpu_ip_version(adev, MP0_HWIP, 0) == IP_VERSION(13, 0, 14) ||



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 511/556] drm/amdgpu: update the fw version for gfx11 userqueues
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (509 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 510/556] drm/amdgpu: Skip accessing psp rum time db for APUs Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 512/556] drm/amdgpu: update the fw version for gfx12 userqueues Greg Kroah-Hartman
                   ` (57 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Sunil Khatri, Alex Deucher

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sunil Khatri <sunil.khatri@amd.com>

commit c748dd03df33360549ad60cdccee13570e9c0f90 upstream.

Update to the latest stable fw versions where userqueues
is working as it is expected with major fixes.

Signed-off-by: Sunil Khatri <sunil.khatri@amd.com>
Acked-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit d50201b891604ab97f305d4a20d888ba93305b48)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/amdgpu/gfx_v11_0.c |    8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

--- a/drivers/gpu/drm/amd/amdgpu/gfx_v11_0.c
+++ b/drivers/gpu/drm/amd/amdgpu/gfx_v11_0.c
@@ -1646,10 +1646,10 @@ static int gfx_v11_0_sw_init(struct amdg
 	case IP_VERSION(11, 0, 2):
 	case IP_VERSION(11, 0, 3):
 		if (!adev->gfx.disable_uq &&
-		    adev->gfx.me_fw_version  >= 2420 &&
-		    adev->gfx.pfp_fw_version >= 2580 &&
-		    adev->gfx.mec_fw_version >= 2650 &&
-		    adev->mes.fw_version[0] >= 120) {
+		    adev->gfx.me_fw_version  >= 3090 &&
+		    adev->gfx.pfp_fw_version >= 3190 &&
+		    adev->gfx.mec_fw_version >= 3450 &&
+		    adev->mes.fw_version[0] >= 147) {
 			adev->userq_funcs[AMDGPU_HW_IP_GFX] = &userq_mes_funcs;
 			adev->userq_funcs[AMDGPU_HW_IP_COMPUTE] = &userq_mes_funcs;
 		}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 512/556] drm/amdgpu: update the fw version for gfx12 userqueues
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (510 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 511/556] drm/amdgpu: update the fw version for gfx11 userqueues Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 513/556] drm/amdgpu: use AMDGPU_GPU_PAGE_SHIFT instead of PAGE_SHIFT Greg Kroah-Hartman
                   ` (56 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Sunil Khatri, Alex Deucher

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sunil Khatri <sunil.khatri@amd.com>

commit 49a74a2388528c1a2e96f01114c4513e635605fe upstream.

Update to the latest stable fw versions where userqueues
is working as it is expected with major fixes.

Signed-off-by: Sunil Khatri <sunil.khatri@amd.com>
Acked-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 69fa36e3ac92f2544ee7a1b719ec212b8247a2da)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/amdgpu/gfx_v12_0.c |    8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

--- a/drivers/gpu/drm/amd/amdgpu/gfx_v12_0.c
+++ b/drivers/gpu/drm/amd/amdgpu/gfx_v12_0.c
@@ -1434,10 +1434,10 @@ static int gfx_v12_0_sw_init(struct amdg
 	case IP_VERSION(12, 0, 0):
 	case IP_VERSION(12, 0, 1):
 		if (!adev->gfx.disable_uq &&
-		    adev->gfx.me_fw_version  >= 2780 &&
-		    adev->gfx.pfp_fw_version >= 2840 &&
-		    adev->gfx.mec_fw_version >= 3050 &&
-		    adev->mes.fw_version[0] >= 123) {
+		    adev->gfx.me_fw_version  >= 3090 &&
+		    adev->gfx.pfp_fw_version >= 3190 &&
+		    adev->gfx.mec_fw_version >= 3450 &&
+		    adev->mes.fw_version[0] >= 147) {
 			adev->userq_funcs[AMDGPU_HW_IP_GFX] = &userq_mes_funcs;
 			adev->userq_funcs[AMDGPU_HW_IP_COMPUTE] = &userq_mes_funcs;
 		}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 513/556] drm/amdgpu: use AMDGPU_GPU_PAGE_SHIFT instead of PAGE_SHIFT
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (511 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 512/556] drm/amdgpu: update the fw version for gfx12 userqueues Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 514/556] drm/amdkfd: Add TLB flush after MES queue eviction/suspension Greg Kroah-Hartman
                   ` (55 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Sunil Khatri, Alex Deucher

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sunil Khatri <sunil.khatri@amd.com>

commit d6e16df7df4d2c39e2b04b355d0434fb90e2d62c upstream.

For different address types the variable PAGE_SHIFT might
not work well and it's better to use the GPU specific one

Signed-off-by: Sunil Khatri <sunil.khatri@amd.com>
Reviewed-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 3494b77d10375e0f9ab784e9b20763339844b55b)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c
@@ -2064,7 +2064,7 @@ int amdgpu_vm_bo_clear_mappings(struct a
 			after->start = eaddr + 1;
 			after->last = tmp->last;
 			after->offset = tmp->offset;
-			after->offset += (after->start - tmp->start) << PAGE_SHIFT;
+			after->offset += (after->start - tmp->start) << AMDGPU_GPU_PAGE_SHIFT;
 			after->flags = tmp->flags;
 			after->bo_va = tmp->bo_va;
 			list_add(&after->list, &tmp->bo_va->invalids);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 514/556] drm/amdkfd: Add TLB flush after MES queue eviction/suspension
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (512 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 513/556] drm/amdgpu: use AMDGPU_GPU_PAGE_SHIFT instead of PAGE_SHIFT Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 515/556] drm/amdkfd: Fix error path at svm_migrate_copy_to_ram Greg Kroah-Hartman
                   ` (54 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Priya Hosur, Felix Kuehling,
	Alex Deucher

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Priya Hosur <Priya.Hosur@amd.com>

commit 94e25cb6ab7f4f025bcdcd8ea79fda30f12843a4 upstream.

MES (Micro Engine Scheduler) does not perform heavy-weight TLB
invalidation after unmapping queues, unlike HWS which does this
automatically. This causes a race condition where in-flight DMA
descriptors can access memory that has been unmapped, leading to page
faults and GPU queue hangs during SVM page migration.

The issue manifests as KFDSVMRangeTest.MultiThreadMigrationTest
failures on gfx1151 (Strix Point) with XNACK mode 1 enabled - the GPU
compute queue hangs with packets submitted but never consumed.

Add kfd_flush_tlb() calls after MES queue removal in two locations:
- evict_process_queues_cpsch(): after all queues removed during eviction
- suspend_queues(): after debug/criu queue suspension (with mem_fence barrier)

This ensures all in-flight memory accesses from unmapped queues are
flushed before memory is freed or migrated.

Signed-off-by: Priya Hosur <Priya.Hosur@amd.com>
Reviewed-by: Felix Kuehling <felix.kuehling@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit f5c4f88e0f9c45a8fb9dfac0c1df726c95e41b77)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c |   13 ++++++++++++-
 1 file changed, 12 insertions(+), 1 deletion(-)

--- a/drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c
@@ -1375,6 +1375,14 @@ static int evict_process_queues_cpsch(st
 		}
 	}
 
+	/*
+	 * Heavy-weight TLB flush after MES removes queues to ensure
+	 * in-flight memory accesses complete before memory is freed/migrated.
+	 * HWS does this automatically, MES does not.
+	 */
+	if (dqm->dev->kfd->shared_resources.enable_mes)
+		kfd_flush_tlb(pdd);
+
 	if (!dqm->dev->kfd->shared_resources.enable_mes) {
 		pdd->last_evict_timestamp = get_jiffies_64();
 		retval = execute_queues_cpsch(dqm,
@@ -3651,8 +3659,11 @@ int suspend_queues(struct kfd_process *p
 		if (!per_device_suspended) {
 			dqm_unlock(dqm);
 			mutex_unlock(&p->event_mutex);
-			if (total_suspended)
+			if (total_suspended) {
 				amdgpu_amdkfd_debug_mem_fence(dqm->dev->adev);
+				/* Heavy-weight TLB flush after MES suspends queues */
+				kfd_flush_tlb(pdd);
+			}
 			continue;
 		}
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 515/556] drm/amdkfd: Fix error path at svm_migrate_copy_to_ram
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (513 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 514/556] drm/amdkfd: Add TLB flush after MES queue eviction/suspension Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 516/556] drm/amdkfd: fix scope of mqd_mgr dereference in pqm_debugfs_mqds Greg Kroah-Hartman
                   ` (53 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Xiaogang Chen, Felix Kuehling,
	Alex Deucher

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Xiaogang Chen <xiaogang.chen@amd.com>

commit 960c4a8069bfd352c48cc88592618f1ebe24c69e upstream.

If page migration from device to sys ram fails for some reasons driver needs
release and unlock allocated system pages. To do that driver should use page
physical address, or pfn, then get struct page*. Current driver uses dma
address(for adev) that is not correct with IOMMU enabled, or even in general.

The patch releases and unlocks allocated system pages based on where migration
failed by struct page* of sys ram pages. Also dma_unmap correspodent system
ram pages at error path.

Cc: stable@vger.kernel.org
Signed-off-by: Xiaogang Chen <xiaogang.chen@amd.com>
Reviewed-by: Felix Kuehling <felix.kuehling@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/amdkfd/kfd_migrate.c |   45 ++++++++++++++++++++-----------
 1 file changed, 30 insertions(+), 15 deletions(-)

--- a/drivers/gpu/drm/amd/amdkfd/kfd_migrate.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_migrate.c
@@ -258,15 +258,6 @@ svm_migrate_get_sys_page(struct vm_area_
 	return page;
 }
 
-static void svm_migrate_put_sys_page(unsigned long addr)
-{
-	struct page *page;
-
-	page = pfn_to_page(addr >> PAGE_SHIFT);
-	unlock_page(page);
-	put_page(page);
-}
-
 static unsigned long svm_migrate_successful_pages(struct migrate_vma *migrate)
 {
 	unsigned long mpages = 0;
@@ -591,9 +582,10 @@ svm_migrate_copy_to_ram(struct amdgpu_de
 			dma_addr_t *scratch, u64 npages)
 {
 	struct device *dev = adev->dev;
-	u64 *src;
+	struct page *dpage = NULL;
 	dma_addr_t *dst;
-	struct page *dpage;
+	u64 *src;
+
 	u64 i = 0, j;
 	u64 addr;
 	int r = 0;
@@ -647,6 +639,7 @@ svm_migrate_copy_to_ram(struct amdgpu_de
 		r = dma_mapping_error(dev, dst[i]);
 		if (r) {
 			dev_err(adev->dev, "%s: fail %d dma_map_page\n", __func__, r);
+			dst[i] = 0;
 			goto out_oom;
 		}
 
@@ -654,17 +647,39 @@ svm_migrate_copy_to_ram(struct amdgpu_de
 				     dst[i] >> PAGE_SHIFT, page_to_pfn(dpage));
 
 		migrate->dst[i] = migrate_pfn(page_to_pfn(dpage));
+
+		dpage = NULL;
 		j++;
 	}
 
-	r = svm_migrate_copy_memory_gart(adev, dst + i - j, src + i - j, j,
-					 FROM_VRAM_TO_RAM, mfence);
-
+	if (j > 0)
+		r = svm_migrate_copy_memory_gart(adev, dst + i - j, src + i - j, j,
+						 FROM_VRAM_TO_RAM, mfence);
 out_oom:
 	if (r) {
 		pr_debug("failed %d copy to ram\n", r);
+
+		/* first release current dpage when dma_map_page fail */
+		if (dpage) {
+			unlock_page(dpage);
+			put_page(dpage);
+		}
+
+		/* release previous allocated sys pages and unmap dma address */
 		while (i--) {
-			svm_migrate_put_sys_page(dst[i]);
+
+			if (dst[i]) {
+				dma_unmap_page(dev, dst[i], PAGE_SIZE,
+					       DMA_BIDIRECTIONAL);
+				dst[i] = 0;
+			}
+
+			dpage = migrate_pfn_to_page(migrate->dst[i]);
+			if (!dpage)
+				continue;
+
+			unlock_page(dpage);
+			put_page(dpage);
 			migrate->dst[i] = 0;
 		}
 	}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 516/556] drm/amdkfd: fix scope of mqd_mgr dereference in pqm_debugfs_mqds
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (514 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 515/556] drm/amdkfd: Fix error path at svm_migrate_copy_to_ram Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 517/556] drm/amdkfd: Fix the case that vm range is hole at svm_migrate_copy_to_vram Greg Kroah-Hartman
                   ` (52 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Alex Deucher, Mario Limonciello

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mario Limonciello <mario.limonciello@amd.com>

commit 012a026bae0212952b423a842b7e2c0bf21f8e7a upstream.

Reading /sys/kernel/debug/kfd/mqds while a process holds an active KFD
queue triggers a NULL pointer dereference because the for loop that
calls mqd_mgr->debugfs_show_mqd() is incorrectly placed outside the
if (pqn->q) block that initializes mqd_mgr.

The queue list can contain entries where pqn->q is NULL (kernel queues
where only pqn->kq is valid). In the original code:

  if (pqn->q) {
      ...
      mqd_mgr = q->device->dqm->mqd_mgrs[mqd_type];
      size = mqd_mgr->mqd_stride(...);
  }

  for (xcc = 0; xcc < num_xccs; xcc++) {  // WRONG: outside if block
      mqd = q->mqd + size * xcc;
      r = mqd_mgr->debugfs_show_mqd(m, mqd);
  }

When iterating over a queue node where pqn->q is NULL:
1. The if (pqn->q) block is skipped
2. mqd_mgr remains uninitialized (NULL from declaration)
3. The for loop executes anyway
4. mqd_mgr->debugfs_show_mqd(m, mqd) dereferences NULL

The crash manifests as:

  BUG: kernel NULL pointer dereference, address: 0000000000000000
  #PF: supervisor instruction fetch in kernel mode
  RIP: 0010:0x0
  Call Trace:
   pqm_debugfs_mqds+0x10c/0x1d0 [amdgpu]
   kfd_debugfs_mqds_by_process+0x9b/0x110 [amdgpu]
   seq_read_iter+0x132/0x4b0
   ...

Fix by moving the for loop inside the if (pqn->q) block, so mqd_mgr
and related variables are only used when properly initialized.

Closes: https://gitlab.freedesktop.org/drm/amd/-/work_items/5689
Reviewed-by: Alex Deucher <alexander.deucher@amd.com>
Link: https://patch.msgid.link/20260831130051.2031435-1-mario.limonciello@amd.com
Signed-off-by: Mario Limonciello <mario.limonciello@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 8bfe29d5c798940f797aa24135d2734c3ffce9de)
Cc: stable@vger.kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/amdkfd/kfd_process_queue_manager.c |   12 ++++++------
 1 file changed, 6 insertions(+), 6 deletions(-)

--- a/drivers/gpu/drm/amd/amdkfd/kfd_process_queue_manager.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_process_queue_manager.c
@@ -1148,13 +1148,13 @@ int pqm_debugfs_mqds(struct seq_file *m,
 			mqd_mgr = q->device->dqm->mqd_mgrs[mqd_type];
 			size = mqd_mgr->mqd_stride(mqd_mgr,
 							&q->properties);
-		}
 
-		for (xcc = 0; xcc < num_xccs; xcc++) {
-			mqd = q->mqd + size * xcc;
-			r = mqd_mgr->debugfs_show_mqd(m, mqd);
-			if (r != 0)
-				break;
+			for (xcc = 0; xcc < num_xccs; xcc++) {
+				mqd = q->mqd + size * xcc;
+				r = mqd_mgr->debugfs_show_mqd(m, mqd);
+				if (r != 0)
+					break;
+			}
 		}
 	}
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 517/556] drm/amdkfd: Fix the case that vm range is hole at svm_migrate_copy_to_vram
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (515 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 516/556] drm/amdkfd: fix scope of mqd_mgr dereference in pqm_debugfs_mqds Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 518/556] drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore Greg Kroah-Hartman
                   ` (51 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Xiaogang Chen, Felix Kuehling,
	Alex Deucher

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Xiaogang Chen <xiaogang.chen@amd.com>

commit 520e345ffe05aabef1db82beda4288afb1757ff2 upstream.

When migration vm range is hole at cpu side(MIGRATE_PFN_MIGRATE set +
MIGRATE_PFN_VALID unset) driver still allocates device pages. There is no
dma map of src pages and migration. j is 0 and svm_migrate_copy_memory_gart()
will return an uninitialized r. That can trigger out_free_vram_pages to drop
all VRAM just set up.

Initialize r and only call the last svm_migrate_copy_memory_gart if j > 0.

Current code postponed the last page to the final copy. This patch flushes on
the last page when reach to the end of current drm_buddy_block; avoids another
svm_migrate_copy_memory_gart.

Cc: stable@vger.kernel.org
Signed-off-by: Xiaogang Chen <xiaogang.chen@amd.com>
Reviewed-by: Felix Kuehling <felix.kuehling@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/amdkfd/kfd_migrate.c |   11 +++++++----
 1 file changed, 7 insertions(+), 4 deletions(-)

--- a/drivers/gpu/drm/amd/amdkfd/kfd_migrate.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_migrate.c
@@ -134,7 +134,7 @@ svm_migrate_copy_memory_gart(struct amdg
 	u64 gart_s, gart_d;
 	struct dma_fence *next;
 	u64 size;
-	int r;
+	int r = 0;
 
 	ring = to_amdgpu_ring(adev->mman.buffer_funcs_scheds[0]);
 	entity = &adev->mman.move_entities[0];
@@ -284,7 +284,7 @@ svm_migrate_copy_to_vram(struct kfd_node
 	dma_addr_t *src;
 	u64 *dst;
 	u64 i, j;
-	int r;
+	int r = 0;
 
 	pr_debug("svms 0x%p [0x%lx 0x%lx 0x%llx]\n", prange->svms, prange->start,
 		 prange->last, ttm_res_offset);
@@ -310,6 +310,7 @@ svm_migrate_copy_to_vram(struct kfd_node
 					      DMA_BIDIRECTIONAL);
 			r = dma_mapping_error(dev, src[i]);
 			if (r) {
+				src[i] = 0;
 				dev_err(dev, "%s: fail %d dma_map_page\n",
 					__func__, r);
 				goto out_free_vram_pages;
@@ -334,7 +335,8 @@ svm_migrate_copy_to_vram(struct kfd_node
 		pr_debug_ratelimited("dma mapping src to 0x%llx, pfn 0x%lx\n",
 				     src[i] >> PAGE_SHIFT, page_to_pfn(spage));
 
-		if (j >= (cursor.size >> PAGE_SHIFT) - 1 && i < npages - 1) {
+		/* accumulated j + 1 pages reach end of current drm_buddy_block */
+		if (j + 1 >= (cursor.size >> PAGE_SHIFT)) {
 			r = svm_migrate_copy_memory_gart(adev, src + i - j,
 							 dst + i - j, j + 1,
 							 FROM_RAM_TO_VRAM,
@@ -348,7 +350,8 @@ svm_migrate_copy_to_vram(struct kfd_node
 		}
 	}
 
-	r = svm_migrate_copy_memory_gart(adev, src + i - j, dst + i - j, j,
+	if (j > 0)
+		r = svm_migrate_copy_memory_gart(adev, src + i - j, dst + i - j, j,
 					 FROM_RAM_TO_VRAM, mfence);
 
 out_free_vram_pages:



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 518/556] drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (516 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 517/556] drm/amdkfd: Fix the case that vm range is hole at svm_migrate_copy_to_vram Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 519/556] drm/amdkfd: Reject zero-sized AQL queue allocations after size halving Greg Kroah-Hartman
                   ` (50 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Vladimir Marioukhine, Alex Deucher

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Vladimir Marioukhine <Vladimir.Marioukhine@amd.com>

commit 6aa530642f95d5c48aa336416f94a35e7949b647 upstream.

Both create_queue_cpsch() and create_queue_nocpsch() unconditionally
call mqd_mgr->restore_mqd() when a CRIU restore is in progress
(qd != NULL), with no NULL guard. On any system where restore_mqd is
not implemented for the given queue type, a user holding
CAP_CHECKPOINT_RESTORE can trigger a kernel NULL pointer dereference
and panic the machine by issuing KFD_IOC_CRIU_OP_RESTORE with a
crafted queue restore object. Note that checkpoint_mqd is likewise
unimplemented on GFX12, so no legitimate CRIU image can reach this
path — only a hand-crafted restore payload.

Add a NULL guard for restore_mqd immediately after mqd_mgr is
resolved, unwinding via the existing error labels and returning
-EOPNOTSUPP if the callback is not implemented. This mirrors the
existing checkpoint_mqd guard in checkpoint_mqd().

Fixes: 48f0bdf4e38e ("drm/amdkfd: Added MQD manager files for GFX12.")
Cc: stable@vger.kernel.org
Signed-off-by: Vladimir Marioukhine <Vladimir.Marioukhine@amd.com>
Reviewed-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c |   10 ++++++++++
 1 file changed, 10 insertions(+)

--- a/drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_device_queue_manager.c
@@ -796,6 +796,11 @@ static int create_queue_nocpsch(struct d
 
 	mqd_mgr = dqm->mqd_mgrs[get_mqd_type_from_queue_type(
 			q->properties.type)];
+	if (qd && !mqd_mgr->restore_mqd) {
+		pr_debug("restore_mqd not implemented for this GPU\n");
+		retval = -EOPNOTSUPP;
+		goto deallocate_vmid;
+	}
 	if (q->properties.type == KFD_QUEUE_TYPE_COMPUTE) {
 		retval = allocate_hqd(dqm, q);
 		if (retval)
@@ -2162,6 +2167,11 @@ static int create_queue_cpsch(struct dev
 
 	mqd_mgr = dqm->mqd_mgrs[get_mqd_type_from_queue_type(
 			q->properties.type)];
+	if (qd && !mqd_mgr->restore_mqd) {
+		pr_debug("restore_mqd not implemented for this GPU\n");
+		retval = -EOPNOTSUPP;
+		goto out_deallocate_doorbell;
+	}
 
 	if (q->properties.type == KFD_QUEUE_TYPE_SDMA ||
 		q->properties.type == KFD_QUEUE_TYPE_SDMA_XGMI)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 519/556] drm/amdkfd: Reject zero-sized AQL queue allocations after size halving
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (517 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 518/556] drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 520/556] drm/sysfb: simpledrm: Improve framebuffer-size validation Greg Kroah-Hartman
                   ` (49 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Sunday Clement, Alex Deucher,
	Alex Deucher

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Sunday Clement <Sunday.Clement@amd.com>

commit 40ba09e11188d1b7f79d51fc28aca5ea45e0c138 upstream.

KFD_IOC_ALLOC_MEMORY_OF_GPU with flag
KFD_IOC_ALLOC_MEM_FLAGS_AQL_QUEUE_MEM and size=1 triggers the AQL
wraparound workaround (size >>= 1), reducing size to 0. The resulting
zero passes through PAGE_ALIGN(0) = 0 without validation, bypassing the
per-process VRAM quota check in reserve_mem_limit()
(vram_used + 0 > vram_available is always false).

The fix adds post-halving zero-size validation in the primary
allocation path (amdgpu_amdkfd_gpuvm.c). The check happens after size
halving but before reserve_mem_limit(), and uses err_alignment_size
error path to properly clean up the allocated kgd_mem structure and
mutex.

Cc: stable@vger.kernel.org
Signed-off-by: Sunday Clement <Sunday.Clement@amd.com>
Reviewed-by: Alex Deucher <Alexander.Deucher@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/amd/amdgpu/amdgpu_amdkfd_gpuvm.c |    7 +++++++
 drivers/gpu/drm/amd/amdkfd/kfd_chardev.c         |    3 ++-
 2 files changed, 9 insertions(+), 1 deletion(-)

--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_amdkfd_gpuvm.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_amdkfd_gpuvm.c
@@ -1795,6 +1795,12 @@ int amdgpu_amdkfd_gpuvm_alloc_memory_of_
 		size >>= 1;
 	aligned_size = PAGE_ALIGN(size);
 
+	/* reject AQL queue with size < 2 */
+	if (!aligned_size) {
+		ret = -EINVAL;
+		goto err_alignment_size;
+	}
+
 	(*mem)->alloc_flags = flags;
 
 	amdgpu_sync_create(&(*mem)->sync);
@@ -1886,6 +1892,7 @@ err_bo_create:
 	amdgpu_amdkfd_unreserve_mem_limit(adev, aligned_size, flags, xcp_id);
 err_reserve_limit:
 	amdgpu_sync_free(&(*mem)->sync);
+err_alignment_size:
 	mutex_destroy(&(*mem)->lock);
 	if (gobj)
 		drm_gem_object_put(gobj);
--- a/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_chardev.c
@@ -1200,7 +1200,8 @@ static int kfd_ioctl_alloc_memory_of_gpu
 
 		if (flags & KFD_IOC_ALLOC_MEM_FLAGS_AQL_QUEUE_MEM)
 			size >>= 1;
-		atomic64_add(PAGE_ALIGN(size), &pdd->vram_usage);
+		size = PAGE_ALIGN(size);
+		atomic64_add(size, &pdd->vram_usage);
 	}
 
 	mutex_unlock(&p->mutex);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 520/556] drm/sysfb: simpledrm: Improve framebuffer-size validation
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (518 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 519/556] drm/amdkfd: Reject zero-sized AQL queue allocations after size halving Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 521/556] drm/sysfb: simpledrm: Improve panel-size validation Greg Kroah-Hartman
                   ` (48 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Thomas Zimmermann, Thierry Reding,
	Maxime Ripard, Javier Martinez Canillas

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Thomas Zimmermann <tzimmermann@suse.de>

commit 03f1a3545b721fa7fdadd00080e237519a286a97 upstream.

Validate the framebuffer size from the firmware against the
limitations of struct drm_display_mode. The type only stores sizes
in 16-bit fields. Fail probing on errors.

v2:
- remove unused function simplefb_get_validated_int0() (Sashiko)

Signed-off-by: Thomas Zimmermann <tzimmermann@suse.de>
Reviewed-by: Thierry Reding <treding@nvidia.com>
Reviewed-by: Maxime Ripard <mripard@kernel.org>
Reviewed-by: Javier Martinez Canillas <javierm@redhat.com>
Fixes: 11e8f5fd223b ("drm: Add simpledrm driver")
Cc: <stable@vger.kernel.org> # v5.14+
Fixes: 11e8f5fd223b ("drm: Add simpledrm driver")
Link: https://patch.msgid.link/20260625094509.157581-2-tzimmermann@suse.de
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/sysfb/simpledrm.c |   15 ++++-----------
 1 file changed, 4 insertions(+), 11 deletions(-)

--- a/drivers/gpu/drm/sysfb/simpledrm.c
+++ b/drivers/gpu/drm/sysfb/simpledrm.c
@@ -48,13 +48,6 @@ simplefb_get_validated_int(struct drm_de
 	return drm_sysfb_get_validated_int(dev, name, value, INT_MAX);
 }
 
-static int
-simplefb_get_validated_int0(struct drm_device *dev, const char *name,
-			    uint32_t value)
-{
-	return drm_sysfb_get_validated_int0(dev, name, value, INT_MAX);
-}
-
 static const struct drm_format_info *
 simplefb_get_validated_format(struct drm_device *dev, const char *format_name)
 {
@@ -88,14 +81,14 @@ static int
 simplefb_get_width_pd(struct drm_device *dev,
 		      const struct simplefb_platform_data *pd)
 {
-	return simplefb_get_validated_int0(dev, "width", pd->width);
+	return drm_sysfb_get_validated_int0(dev, "width", pd->width, U16_MAX);
 }
 
 static int
 simplefb_get_height_pd(struct drm_device *dev,
 		       const struct simplefb_platform_data *pd)
 {
-	return simplefb_get_validated_int0(dev, "height", pd->height);
+	return drm_sysfb_get_validated_int0(dev, "height", pd->height, U16_MAX);
 }
 
 static int
@@ -144,7 +137,7 @@ simplefb_get_width_of(struct drm_device
 
 	if (ret)
 		return ret;
-	return simplefb_get_validated_int0(dev, "width", width);
+	return drm_sysfb_get_validated_int0(dev, "width", width, U16_MAX);
 }
 
 static int
@@ -155,7 +148,7 @@ simplefb_get_height_of(struct drm_device
 
 	if (ret)
 		return ret;
-	return simplefb_get_validated_int0(dev, "height", height);
+	return drm_sysfb_get_validated_int0(dev, "height", height, U16_MAX);
 }
 
 static int



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 521/556] drm/sysfb: simpledrm: Improve panel-size validation
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (519 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 520/556] drm/sysfb: simpledrm: Improve framebuffer-size validation Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 522/556] drm/sysfb: simpledrm: Improve stride validation Greg Kroah-Hartman
                   ` (47 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Thomas Zimmermann, Thierry Reding,
	Maxime Ripard, Javier Martinez Canillas, Rayyan Ansari

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Thomas Zimmermann <tzimmermann@suse.de>

commit 3a75a0761914d01c7362adf1f906cc1d1762c189 upstream.

Validate the panel size from the device-tree node against the
limitations of struct drm_display_mode. The type only stores sizes
in 16-bit fields. Fail transparently on errors; do not warn.

v3:
- move comments to a more prominent place (Thierry)
v2:
- only use initialized values in debugging output (Sashiko)

Signed-off-by: Thomas Zimmermann <tzimmermann@suse.de>
Reviewed-by: Thierry Reding <treding@nvidia.com>
Reviewed-by: Maxime Ripard <mripard@kernel.org>
Reviewed-by: Javier Martinez Canillas <javierm@redhat.com>
Fixes: 2a6d731a8f16 ("drm/simpledrm: Allow physical width and height configuration via panel node")
Cc: Rayyan Ansari <rayyan@ansari.sh>
Cc: <stable@vger.kernel.org> # v6.4+
Link: https://patch.msgid.link/20260625094509.157581-3-tzimmermann@suse.de
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/sysfb/simpledrm.c |   49 +++++++++++++++++++++++++++++++++++---
 1 file changed, 46 insertions(+), 3 deletions(-)

--- a/drivers/gpu/drm/sysfb/simpledrm.c
+++ b/drivers/gpu/drm/sysfb/simpledrm.c
@@ -193,6 +193,39 @@ simplefb_get_memory_of(struct drm_device
 	return res;
 }
 
+static int __simplefb_get_panel_size_mm_of(struct drm_device *dev,
+					   struct device_node *of_panel_node,
+					   const char *name)
+{
+	int ret;
+	u32 value;
+
+	ret = of_property_read_u32(of_panel_node, name, &value);
+	if (ret) {
+		drm_dbg(dev, "simplefb: cannot parse panel %s: error %d\n",
+			name, ret);
+		return ret;
+	} else if (value > U16_MAX) {
+		drm_dbg(dev, "simplefb: panel %s of %u exceeds maximum value\n",
+			name, value);
+		return -EINVAL;
+	}
+
+	return value;
+}
+
+static int simplefb_get_panel_width_mm_of(struct drm_device *dev,
+					  struct device_node *of_panel_node)
+{
+	return __simplefb_get_panel_size_mm_of(dev, of_panel_node, "width-mm");
+}
+
+static int simplefb_get_panel_height_mm_of(struct drm_device *dev,
+					   struct device_node *of_panel_node)
+{
+	return __simplefb_get_panel_size_mm_of(dev, of_panel_node, "height-mm");
+}
+
 /*
  * Simple Framebuffer device
  */
@@ -594,7 +627,7 @@ static struct simpledrm_device *simpledr
 	struct drm_sysfb_device *sysfb;
 	struct drm_device *dev;
 	int width, height, stride;
-	int width_mm = 0, height_mm = 0;
+	u16 width_mm = 0, height_mm = 0;
 	struct device_node *panel_node;
 	const struct drm_format_info *format;
 	struct resource *res, *mem = NULL;
@@ -658,8 +691,18 @@ static struct simpledrm_device *simpledr
 			return ERR_CAST(mem);
 		panel_node = of_parse_phandle(of_node, "panel", 0);
 		if (panel_node) {
-			simplefb_read_u32_of(dev, panel_node, "width-mm", &width_mm);
-			simplefb_read_u32_of(dev, panel_node, "height-mm", &height_mm);
+			/*
+			 * Ignore errors from parsing the physical panel
+			 * size. Using the pre-initialized sizes of 0 will
+			 * make drm_sysfb_mode() calculate a default physical
+			 * size based on a resolution of 96 dpi.
+			 */
+			ret = simplefb_get_panel_width_mm_of(dev, panel_node);
+			if (ret > 0)
+				width_mm = ret;
+			ret = simplefb_get_panel_height_mm_of(dev, panel_node);
+			if (ret > 0)
+				height_mm = ret;
 			of_node_put(panel_node);
 		}
 	} else {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 522/556] drm/sysfb: simpledrm: Improve stride validation
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (520 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 521/556] drm/sysfb: simpledrm: Improve panel-size validation Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 523/556] drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation Greg Kroah-Hartman
                   ` (46 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Thomas Zimmermann, Thierry Reding,
	Maxime Ripard, Javier Martinez Canillas

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Thomas Zimmermann <tzimmermann@suse.de>

commit df6533f11688aa30be3bb883c7637f4ffdbb7cbd upstream.

Validate the computed stride against the maximum value INT_MAX.

Signed-off-by: Thomas Zimmermann <tzimmermann@suse.de>
Reviewed-by: Thierry Reding <treding@nvidia.com>
Reviewed-by: Maxime Ripard <mripard@kernel.org>
Reviewed-by: Javier Martinez Canillas <javierm@redhat.com>
Fixes: 7bfa5c7b28d6 ("drm/simpledrm: Compute linestride with drm_format_info_min_pitch()")
Cc: <stable@vger.kernel.org> # v6.1+
Link: https://patch.msgid.link/20260625094509.157581-5-tzimmermann@suse.de
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/sysfb/simpledrm.c |   10 ++++++++--
 1 file changed, 8 insertions(+), 2 deletions(-)

--- a/drivers/gpu/drm/sysfb/simpledrm.c
+++ b/drivers/gpu/drm/sysfb/simpledrm.c
@@ -710,9 +710,15 @@ static struct simpledrm_device *simpledr
 		return ERR_PTR(-ENODEV);
 	}
 	if (!stride) {
-		stride = drm_format_info_min_pitch(format, 0, width);
-		if (drm_WARN_ON(dev, !stride))
+		u64 pitch = drm_format_info_min_pitch(format, 0, width);
+
+		if (drm_WARN_ON(dev, !pitch)) {
+			return ERR_PTR(-EINVAL); /* driver bug */
+		} else if (pitch > INT_MAX) {
+			drm_warn(dev, "stride of %llu exceeds maximum\n", pitch);
 			return ERR_PTR(-EINVAL);
+		}
+		stride = pitch;
 	}
 
 	sysfb->fb_mode = drm_sysfb_mode(width, height, width_mm, height_mm);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 523/556] drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (521 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 522/556] drm/sysfb: simpledrm: Improve stride validation Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 524/556] drm/sysfb: ofdrm: Fix is_avivo() constant comparison bug Greg Kroah-Hartman
                   ` (45 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Shixiong Ou, Thomas Zimmermann

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Shixiong Ou <oushixiong@kylinos.cn>

commit c6f48e59ece0123f6a11527ad4d89b21c2d65b87 upstream.

The framebuffer size calculation `fb_size = linebytes * height` can
overflow when both values are large (e.g., 46341 * 46341 > INT_MAX).
Since linebytes and height are both int types, the multiplication is
performed as int * int, which results in undefined behavior on overflow.

Use check_mul_overflow() to detect and prevent this overflow, consistent
with the approach used in simpledrm.c and corebootdrm.c.

Signed-off-by: Shixiong Ou <oushixiong@kylinos.cn>
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Signed-off-by: Thomas Zimmermann <tzimmermann@suse.de>
Fixes: c8a17756c425 ("drm/ofdrm: Add ofdrm for Open Firmware framebuffers")
Cc: <stable@vger.kernel.org> # v6.2+
Link: https://patch.msgid.link/20260825104134.669676-1-oushixiong1025@163.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/sysfb/ofdrm.c |    6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

--- a/drivers/gpu/drm/sysfb/ofdrm.c
+++ b/drivers/gpu/drm/sysfb/ofdrm.c
@@ -2,6 +2,7 @@
 
 #include <linux/aperture.h>
 #include <linux/of_address.h>
+#include <linux/overflow.h>
 #include <linux/pci.h>
 #include <linux/platform_device.h>
 #include <linux/pm.h>
@@ -913,7 +914,10 @@ static struct ofdrm_device *ofdrm_device
 			return ERR_PTR(-EINVAL);
 	}
 
-	fb_size = linebytes * height;
+	if (check_mul_overflow(linebytes, height, &fb_size)) {
+		drm_err(dev, "framebuffer size exceeds maximum\n");
+		return ERR_PTR(-EINVAL);
+	}
 
 	/*
 	 * Try to figure out the address of the framebuffer. Unfortunately, Open



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 524/556] drm/sysfb: ofdrm: Fix is_avivo() constant comparison bug
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (522 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 523/556] drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 525/556] drm/pagemap: Fix folio allocation fallback and use-after-put Greg Kroah-Hartman
                   ` (44 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Shixiong Ou, Thomas Zimmermann

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Shixiong Ou <oushixiong@kylinos.cn>

commit 958f35cbb8955ca3fa439cd9f2092cb42414aa8c upstream.

The is_avivo() function has a logic error where it compares a constant
to another constant instead of checking the device parameter:

  (PCI_VENDOR_ID_ATI_R600 >= 0x9400)

Signed-off-by: Shixiong Ou <oushixiong@kylinos.cn>
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Fixes: f496834e1674 ("drm/ofdrm: Add per-model device function")
Signed-off-by: Thomas Zimmermann <tzimmermann@suse.de>
Cc: <stable@vger.kernel.org> # v6.2+
Link: https://patch.msgid.link/20260731111729.703116-1-oushixiong1025@163.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/sysfb/ofdrm.c |    2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

--- a/drivers/gpu/drm/sysfb/ofdrm.c
+++ b/drivers/gpu/drm/sysfb/ofdrm.c
@@ -239,7 +239,7 @@ static bool is_avivo(u32 vendor, u32 dev
 	/* This will match most R5xx */
 	return (vendor == PCI_VENDOR_ID_ATI) &&
 	       ((device >= PCI_VENDOR_ID_ATI_R520 && device < 0x7800) ||
-		(PCI_VENDOR_ID_ATI_R600 >= 0x9400));
+		(device >= PCI_VENDOR_ID_ATI_R600));
 }
 
 static enum ofdrm_model display_get_model_of(struct drm_device *dev, struct device_node *of_node)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 525/556] drm/pagemap: Fix folio allocation fallback and use-after-put
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (523 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 524/556] drm/sysfb: ofdrm: Fix is_avivo() constant comparison bug Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 526/556] drm/nouveau/dmem: fix callocated underflow on large folio split Greg Kroah-Hartman
                   ` (43 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Matthew Brost, Himal Prasad Ghimiray

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Matthew Brost <matthew.brost@intel.com>

commit df72e55e754c8d449321ddddad19a8bd3cb8d032 upstream.

drm_pagemap_migrate_populate_ram_pfn() had two issues when populating
RAM PFNs with higher-order folios:

1. The higher-order vma_alloc_folio()/folio_alloc() calls did not pass
   __GFP_NOWARN, so a THP allocation failure under memory pressure
   would spam the kernel log, and there was no fallback path despite a
   TODO comment stating one was needed. Add __GFP_NOWARN to the
   higher-order allocation and, on failure, fall back to order-0
   allocations for the entire range originally covered by the failed
   higher-order allocation, leaving MIGRATE_PFN_COMPOUND unset for
   those PFNs.

2. In the free_pages error path, order was computed via
   folio_order(page_folio(page)) *after* put_page(page) had already
   dropped the reference, resulting in a use-after-free/put when that
   was the last reference on the page. Compute order before releasing
   the page.

Introducing the fallback in 1. also requires the source page array
handed to ->copy_to_ram() to be built differently. Both callers only
populated the entry at the head of each source folio, relying on the
copy callback to derive the rest of the folio from the order recorded
in the matching drm_pagemap_addr. Once the destination has been demoted
to order-0 folios the drm_pagemap_addr entries are per-page, so a source
page is needed for every one of them; leaving them NULL makes the copy
callback stop after the first page and the remainder of the range is
never copied.

The source folio is only split later, by migrate_vma_pages() /
migrate_device_pages(), so its order cannot be used to detect the
demotion - test the destination for MIGRATE_PFN_COMPOUND instead. Factor
the array population out into drm_pagemap_migrate_populate_src_pages()
and use it from both drm_pagemap_evict_to_ram() and
__drm_pagemap_migrate_to_ram().

Fixes: ddeda6136038 ("drm/pagemap: Allocate folios when possible")
Cc: stable@vger.kernel.org
Assisted-by: GitHub_Copilot:claude-opus-5
Signed-off-by: Matthew Brost <matthew.brost@intel.com>
Reviewed-by: Himal Prasad Ghimiray <himal.prasad.ghimiray@intel.com>
Link: https://patch.msgid.link/20260902063504.3024362-2-matthew.brost@intel.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/drm_pagemap.c |  128 +++++++++++++++++++++++++++++++++---------
 1 file changed, 103 insertions(+), 25 deletions(-)

--- a/drivers/gpu/drm/drm_pagemap.c
+++ b/drivers/gpu/drm/drm_pagemap.c
@@ -384,6 +384,58 @@ next:
 }
 
 /**
+ * drm_pagemap_migrate_populate_src_pages() - Populate the source page array
+ * @pages: Array of source pages to populate
+ * @src_mpfn: Source array of migrate PFNs
+ * @dst_mpfn: Destination array of migrate PFNs
+ * @npages: Number of pages in the arrays
+ *
+ * Populate @pages with the device pages the copy callback is to read from.
+ *
+ * Entries are normally only populated at the head of each source folio, with
+ * the copy callback deriving the rest of the folio from the order recorded in
+ * the corresponding drm_pagemap_addr. That does not work where
+ * drm_pagemap_migrate_populate_ram_pfn() had to demote a higher-order source
+ * folio to order-0 destination folios: the drm_pagemap_addr entries are then
+ * per-page, and the copy callback needs a source page for each of them.
+ * Populate every entry for those ranges.
+ *
+ * Note that the source folio itself is only split later, by
+ * migrate_vma_pages() / migrate_device_pages(), so its order cannot be used to
+ * detect the demotion - the destination has to be inspected instead.
+ */
+static void drm_pagemap_migrate_populate_src_pages(struct page **pages,
+						   unsigned long *src_mpfn,
+						   unsigned long *dst_mpfn,
+						   unsigned long npages)
+{
+	unsigned long i;
+
+	for (i = 0; i < npages;) {
+		struct page *page = migrate_pfn_to_page(src_mpfn[i]);
+		unsigned int order = 0;
+		unsigned long j, nr;
+
+		if (!page) {
+			i++;
+			continue;
+		}
+
+		order = folio_order(page_folio(page));
+		nr = NR_PAGES(order);
+
+		if (order && !(dst_mpfn[i] & MIGRATE_PFN_COMPOUND)) {
+			for (j = 0; j < nr && i + j < npages; j++)
+				pages[i + j] = folio_page(page_folio(page), j);
+		} else {
+			pages[i] = page;
+		}
+
+		i += nr;
+	}
+}
+
+/**
  * drm_pagemap_migrate_unmap_pages() - Unmap pages previously mapped for GPU SVM migration
  * @dev: The device for which the pages were mapped
  * @migrate_pfn: Array of migrate pfns set up for the mapped pages. Used to
@@ -875,6 +927,7 @@ static int drm_pagemap_migrate_populate_
 		struct page *page = NULL, *src_page;
 		struct folio *folio;
 		unsigned int order = 0;
+		gfp_t gfp = GFP_HIGHUSER;
 
 		if (!(src_mpfn[i] & MIGRATE_PFN_MIGRATE))
 			goto next;
@@ -891,11 +944,51 @@ static int drm_pagemap_migrate_populate_
 
 		order = folio_order(page_folio(src_page));
 
-		/* TODO: Support fallback to single pages if THP allocation fails */
+		/*
+		 * A large source folio is always collected whole, at its head
+		 * page, PMD aligned and flagged MIGRATE_PFN_COMPOUND: anything
+		 * else is split before it reaches us, either by
+		 * migrate_vma_collect_pmd() or, for the eviction path, by
+		 * migrate_device_pfns(). Both the order-0 fallback below and
+		 * drm_pagemap_migrate_populate_src_pages() rely on that, as
+		 * they index the folio from @i.
+		 */
+		WARN_ON_ONCE(order &&
+			     (src_page != folio_page(page_folio(src_page), 0) ||
+			      !(src_mpfn[i] & MIGRATE_PFN_COMPOUND)));
+
+		if (order)
+			gfp |= __GFP_NOWARN;
+
 		if (vas)
-			folio = vma_alloc_folio(GFP_HIGHUSER, order, vas, addr);
+			folio = vma_alloc_folio(gfp, order, vas, addr);
 		else
-			folio = folio_alloc(GFP_HIGHUSER, order);
+			folio = folio_alloc(gfp, order);
+
+		if (!folio && order) {
+			/*
+			 * Higher-order allocation failed, fall back to
+			 * order-0 allocations for the entire range covered
+			 * by the original higher-order allocation, without
+			 * setting MIGRATE_PFN_COMPOUND, until we move past
+			 * that range.
+			 */
+			unsigned long nr = NR_PAGES(order);
+			unsigned long j;
+
+			gfp &= ~__GFP_NOWARN;
+			for (j = 0; j < nr && i < npages; j++, i++, addr += PAGE_SIZE) {
+				folio = vas ?
+					vma_alloc_folio(gfp, 0, vas, addr) :
+					folio_alloc(gfp, 0);
+				if (!folio)
+					goto free_pages;
+
+				page = folio_page(folio, 0);
+				mpfn[i] = migrate_pfn(page_to_pfn(page));
+			}
+			continue;
+		}
 
 		if (!folio)
 			goto free_pages;
@@ -940,11 +1033,11 @@ free_pages:
 		if (!page)
 			goto next_put;
 
+		order = folio_order(page_folio(page));
+
 		put_page(page);
 		mpfn[i] = 0;
 
-		order = folio_order(page_folio(page));
-
 next_put:
 		i += NR_PAGES(order);
 	}
@@ -1120,7 +1213,7 @@ int drm_pagemap_evict_to_ram(struct drm_
 	unsigned long *src, *dst;
 	struct drm_pagemap_addr *pagemap_addr;
 	void *buf;
-	int i, err = 0;
+	int err = 0;
 	unsigned int retry_count = 2;
 
 	npages = devmem_allocation->size >> PAGE_SHIFT;
@@ -1160,15 +1253,7 @@ retry:
 	if (err)
 		goto err_finalize;
 
-	for (i = 0; i < npages;) {
-		unsigned int order = 0;
-
-		pages[i] = migrate_pfn_to_page(src[i]);
-		if (pages[i])
-			order = folio_order(page_folio(pages[i]));
-
-		i += NR_PAGES(order);
-	}
+	drm_pagemap_migrate_populate_src_pages(pages, src, dst, npages);
 
 	err = ops->copy_to_ram(pages, pagemap_addr, npages, NULL);
 	if (err)
@@ -1235,7 +1320,7 @@ static int __drm_pagemap_migrate_to_ram(
 	struct drm_pagemap_addr *pagemap_addr;
 	unsigned long start, end;
 	void *buf;
-	int i, err = 0;
+	int err = 0;
 
 	zdd = drm_pagemap_page_zone_device_data(page);
 	if (time_before64(get_jiffies_64(), zdd->devmem_allocation->timeslice_expiration))
@@ -1290,15 +1375,8 @@ static int __drm_pagemap_migrate_to_ram(
 	if (err)
 		goto err_finalize;
 
-	for (i = 0; i < npages;) {
-		unsigned int order = 0;
-
-		pages[i] = migrate_pfn_to_page(migrate.src[i]);
-		if (pages[i])
-			order = folio_order(page_folio(pages[i]));
-
-		i += NR_PAGES(order);
-	}
+	drm_pagemap_migrate_populate_src_pages(pages, migrate.src, migrate.dst,
+					       npages);
 
 	err = ops->copy_to_ram(pages, pagemap_addr, npages, NULL);
 	if (err)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 526/556] drm/nouveau/dmem: fix callocated underflow on large folio split
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (524 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 525/556] drm/pagemap: Fix folio allocation fallback and use-after-put Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 527/556] drm/nouveau/dmem: fix mismatched DMA unmap size for large folios Greg Kroah-Hartman
                   ` (42 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yuhao Jiang, Zhenhao Wan, Lyude Paul,
	Danilo Krummrich

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhenhao Wan <whi4ed0g@gmail.com>

commit c2256c044a1df39c8aad4dd2d6f709b2533e2d7a upstream.

nouveau_dmem_folio_free() drops chunk->callocated once per freed folio,
while a large (compound) device-private folio is only counted once when
it is allocated.  When such a folio is split, the mm core invokes
->folio_split() (nouveau_dmem_folio_split()) once for each new
sub-folio, but the hook only fixes up the sub-folio metadata and leaves
chunk->callocated unchanged.

Each resulting sub-folio is later freed separately, so after a split
the single allocation (+1) is met by N frees (-N), leaving
chunk->callocated short by N-1.  On the first split/free cycle it
underflows: WARN_ON(!chunk->callocated) fires, the unsigned counter
wraps and never returns to zero, so the chunk can no longer be
reclaimed (nouveau_dmem_fini() also warns on the leaked count).

Account for the new sub-folio in the split hook, under the same lock as
nouveau_dmem_folio_free(), so the count stays balanced.

Fixes: c32287471077 ("gpu/drm/nouveau: enable THP support for GPU memory migration")
Reported-by: Yuhao Jiang <danisjiang@gmail.com>
Assisted-by: Claude:claude-opus-5
Cc: stable@vger.kernel.org
Signed-off-by: Zhenhao Wan <whi4ed0g@gmail.com>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260811-b4-nouveau-dmem-thp-fixes-v1-2-2cdf9860af2a@gmail.com
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/nouveau/nouveau_dmem.c |   14 ++++++++++++++
 1 file changed, 14 insertions(+)

--- a/drivers/gpu/drm/nouveau/nouveau_dmem.c
+++ b/drivers/gpu/drm/nouveau/nouveau_dmem.c
@@ -279,11 +279,25 @@ err:
 
 static void nouveau_dmem_folio_split(struct folio *head, struct folio *tail)
 {
+	struct nouveau_dmem_chunk *chunk;
+	struct nouveau_dmem *dmem;
+
 	if (tail == NULL)
 		return;
 	tail->pgmap = head->pgmap;
 	tail->mapping = head->mapping;
 	folio_set_zone_device_data(tail, folio_zone_device_data(head));
+
+	/*
+	 * The split hands out a new independently-freeable folio that will
+	 * later be released via nouveau_dmem_folio_free(); account for it so
+	 * chunk->callocated stays balanced.
+	 */
+	chunk = nouveau_page_to_chunk(&head->page);
+	dmem = chunk->drm->dmem;
+	spin_lock(&dmem->lock);
+	chunk->callocated++;
+	spin_unlock(&dmem->lock);
 }
 
 static const struct dev_pagemap_ops nouveau_dmem_pagemap_ops = {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 527/556] drm/nouveau/dmem: fix mismatched DMA unmap size for large folios
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (525 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 526/556] drm/nouveau/dmem: fix callocated underflow on large folio split Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 528/556] drm/nouveau/gsp: use per-version DP_CONFIG_STREAM params on r570 firmware Greg Kroah-Hartman
                   ` (41 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yuhao Jiang, Zhenhao Wan,
	Danilo Krummrich

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhenhao Wan <whi4ed0g@gmail.com>

commit caa1bc2a0a6ca19dcb90bbf88208b0fe2decd66f upstream.

Device-private THP migration maps migration buffers with page_size()
and records that length in dma_info->size.  For a compound folio
page_size() is PAGE_SIZE << order, but two teardown sites still pass a
literal PAGE_SIZE to dma_unmap_page():

  - nouveau_dmem_migrate_to_ram() on the success path, and
  - nouveau_dmem_migrate_copy_one() on the copy-error path.

For an order > 0 folio this unmaps less than was mapped, leaking the
remainder of the IOMMU/IOVA mapping.  The other unmap sites, in
nouveau_dmem_migrate_chunk() and nouveau_dmem_evict_chunk(), already
use the saved size; use it here too.

Fixes: c32287471077 ("gpu/drm/nouveau: enable THP support for GPU memory migration")
Reported-by: Yuhao Jiang <danisjiang@gmail.com>
Assisted-by: Claude:claude-opus-5
Cc: stable@vger.kernel.org
Signed-off-by: Zhenhao Wan <whi4ed0g@gmail.com>
Link: https://patch.msgid.link/20260811-b4-nouveau-dmem-thp-fixes-v1-1-2cdf9860af2a@gmail.com
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/nouveau/nouveau_dmem.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

--- a/drivers/gpu/drm/nouveau/nouveau_dmem.c
+++ b/drivers/gpu/drm/nouveau/nouveau_dmem.c
@@ -267,7 +267,7 @@ static vm_fault_t nouveau_dmem_migrate_t
 	nouveau_fence_new(&fence, dmem->migrate.chan);
 	migrate_vma_pages(&args);
 	nouveau_dmem_fence_done(&fence);
-	dma_unmap_page(drm->dev->dev, dma_info.dma_addr, PAGE_SIZE,
+	dma_unmap_page(drm->dev->dev, dma_info.dma_addr, dma_info.size,
 				DMA_BIDIRECTIONAL);
 done:
 	migrate_vma_finalize(&args);
@@ -786,7 +786,7 @@ static unsigned long nouveau_dmem_migrat
 	return mpfn;
 
 out_dma_unmap:
-	dma_unmap_page(dev, dma_info->dma_addr, PAGE_SIZE, DMA_BIDIRECTIONAL);
+	dma_unmap_page(dev, dma_info->dma_addr, dma_info->size, DMA_BIDIRECTIONAL);
 out_free_page:
 	nouveau_dmem_page_free_locked(drm, dpage);
 out:



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 528/556] drm/nouveau/gsp: use per-version DP_CONFIG_STREAM params on r570 firmware
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (526 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 527/556] drm/nouveau/dmem: fix mismatched DMA unmap size for large folios Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 529/556] drm/nouveau: unsubscribe the channel-kill event before the fence context Greg Kroah-Hartman
                   ` (40 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Mohamed Ahmed, Lyude Paul

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mohamed Ahmed <mohamedahmedegypt2001@gmail.com>

commit 39fd4b742720c68da8695ee1ffa85c5fea4f8e11 upstream.

NVIDIA removed the deprecated actualPclkHz/linkClkFreqHz fields and the
whole Legacy{activeCnt, activeFrac, activePolarity, mvidWarEnabled,
MvidWarParams} block from the SST sub-struct of
NV0073_CTRL_CMD_DP_CONFIG_STREAM_PARAMS between the 535 and 570 releases
(compared in OpenRM tags 535.113.01 vs 570.144), shrinking the struct.

Everything nouveau writes sits at identical offsets in both layouts
except the trailing SST.bEnableAudioOverRightPanel (written as zero), but
the size is wrong on r570, which means r535_sor_dp_sst() and
r535_sor_dp_vcpi() are sent with an incorrect size.

Route the .sst/.vcpi IOR functions through nvkm_rm_api_disp the same way
bl_ctrl and dp.get_caps/set_indexed_link_rates already are. Keep the
existing implementation for r535 and add an r570 implementation built
against the 570.144 layout, which already exists in r570/nvrm/disp.h but
was unused until now. Also add the NV0073_CTRL_CMD_DP_CONFIG_STREAM
define that was missing from the layout.

Other DP controls sent through shared r535 code did not change layout
between the tags.

Fixes: 6cc6e08d4542 ("drm/nouveau/kms: add support for GB20x")
Cc: stable@vger.kernel.org
Signed-off-by: Mohamed Ahmed <mohamedahmedegypt2001@gmail.com>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260825001408.14219-7-mohamedahmedegypt2001@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/disp.c      |   33 ++++--
 drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/disp.c      |   64 ++++++++++++
 drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/nvrm/disp.h |    2 
 drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/rm.h             |    5 
 4 files changed, 97 insertions(+), 7 deletions(-)

--- a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/disp.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/disp.c
@@ -400,16 +400,16 @@ r535_sor_dp_audio(struct nvkm_ior *sor,
 		r535_sor_dp_audio_mute(sor, false);
 }
 
-static void
-r535_sor_dp_vcpi(struct nvkm_ior *sor, int head, u8 slot, u8 slot_nr, u16 pbn, u16 aligned_pbn)
+static int
+r535_dp_vcpi(struct nvkm_ior *sor, int head, u8 slot, u8 slot_nr, u16 pbn, u16 aligned_pbn)
 {
 	struct nvkm_disp *disp = sor->disp;
 	struct NV0073_CTRL_CMD_DP_CONFIG_STREAM_PARAMS *ctrl;
 
 	ctrl = nvkm_gsp_rm_ctrl_get(&disp->rm.objcom,
 				    NV0073_CTRL_CMD_DP_CONFIG_STREAM, sizeof(*ctrl));
-	if (WARN_ON(IS_ERR(ctrl)))
-		return;
+	if (IS_ERR(ctrl))
+		return PTR_ERR(ctrl);
 
 	ctrl->subDeviceInstance = 0;
 	ctrl->head = head;
@@ -429,12 +429,20 @@ r535_sor_dp_vcpi(struct nvkm_ior *sor, i
 	ctrl->MST.sendACT = 0;
 	ctrl->MST.singleHeadMSTPipeline = 0;
 	ctrl->MST.bEnableAudioOverRightPanel = 0;
-	WARN_ON(nvkm_gsp_rm_ctrl_wr(&disp->rm.objcom, ctrl));
+	return nvkm_gsp_rm_ctrl_wr(&disp->rm.objcom, ctrl);
+}
+
+static void
+r535_sor_dp_vcpi(struct nvkm_ior *sor, int head, u8 slot, u8 slot_nr, u16 pbn, u16 aligned_pbn)
+{
+	const struct nvkm_rm_api *rmapi = sor->disp->engine.subdev.device->gsp->rm->api;
+
+	WARN_ON(rmapi->disp->dp.vcpi(sor, head, slot, slot_nr, pbn, aligned_pbn));
 }
 
 static int
-r535_sor_dp_sst(struct nvkm_ior *sor, int head, bool ef,
-		u32 watermark, u32 hblanksym, u32 vblanksym)
+r535_dp_sst(struct nvkm_ior *sor, int head, bool ef,
+	    u32 watermark, u32 hblanksym, u32 vblanksym)
 {
 	struct nvkm_disp *disp = sor->disp;
 	struct NV0073_CTRL_CMD_DP_CONFIG_STREAM_PARAMS *ctrl;
@@ -461,6 +469,15 @@ r535_sor_dp_sst(struct nvkm_ior *sor, in
 	return nvkm_gsp_rm_ctrl_wr(&disp->rm.objcom, ctrl);
 }
 
+static int
+r535_sor_dp_sst(struct nvkm_ior *sor, int head, bool ef,
+		u32 watermark, u32 hblanksym, u32 vblanksym)
+{
+	const struct nvkm_rm_api *rmapi = sor->disp->engine.subdev.device->gsp->rm->api;
+
+	return rmapi->disp->dp.sst(sor, head, ef, watermark, hblanksym, vblanksym);
+}
+
 static const struct nvkm_ior_func_dp
 r535_sor_dp = {
 	.sst = r535_sor_dp_sst,
@@ -1782,6 +1799,8 @@ r535_disp = {
 	.dp = {
 		.get_caps = r535_dp_get_caps,
 		.set_indexed_link_rates = r535_dp_set_indexed_link_rates,
+		.sst = r535_dp_sst,
+		.vcpi = r535_dp_vcpi,
 	},
 	.chan = {
 		.set_pushbuf = r535_disp_chan_set_pushbuf,
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/disp.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/disp.c
@@ -5,6 +5,7 @@
 #include <rm/rm.h>
 
 #include <engine/disp.h>
+#include <engine/disp/ior.h>
 #include <engine/disp/outp.h>
 
 #include "nvhw/drf.h"
@@ -75,6 +76,67 @@ r570_disp_chan_set_pushbuf(struct nvkm_d
 }
 
 static int
+r570_dp_vcpi(struct nvkm_ior *sor, int head, u8 slot, u8 slot_nr, u16 pbn, u16 aligned_pbn)
+{
+	struct nvkm_disp *disp = sor->disp;
+	NV0073_CTRL_CMD_DP_CONFIG_STREAM_PARAMS *ctrl;
+
+	ctrl = nvkm_gsp_rm_ctrl_get(&disp->rm.objcom,
+				    NV0073_CTRL_CMD_DP_CONFIG_STREAM, sizeof(*ctrl));
+	if (IS_ERR(ctrl))
+		return PTR_ERR(ctrl);
+
+	ctrl->subDeviceInstance = 0;
+	ctrl->head = head;
+	ctrl->sorIndex = sor->id;
+	ctrl->dpLink = sor->asy.link == 2;
+	ctrl->bEnableOverride = 1;
+	ctrl->bMST = 1;
+	ctrl->hBlankSym = 0;
+	ctrl->vBlankSym = 0;
+	ctrl->colorFormat = 0;
+	ctrl->bEnableTwoHeadOneOr = 0;
+	ctrl->singleHeadMultistreamMode = 0;
+	ctrl->MST.slotStart = slot;
+	ctrl->MST.slotEnd = slot + slot_nr - 1;
+	ctrl->MST.PBN = pbn;
+	ctrl->MST.Timeslice = aligned_pbn;
+	ctrl->MST.sendACT = 0;
+	ctrl->MST.singleHeadMSTPipeline = 0;
+	ctrl->MST.bEnableAudioOverRightPanel = 0;
+	return nvkm_gsp_rm_ctrl_wr(&disp->rm.objcom, ctrl);
+}
+
+static int
+r570_dp_sst(struct nvkm_ior *sor, int head, bool ef,
+	    u32 watermark, u32 hblanksym, u32 vblanksym)
+{
+	struct nvkm_disp *disp = sor->disp;
+	NV0073_CTRL_CMD_DP_CONFIG_STREAM_PARAMS *ctrl;
+
+	ctrl = nvkm_gsp_rm_ctrl_get(&disp->rm.objcom,
+				    NV0073_CTRL_CMD_DP_CONFIG_STREAM, sizeof(*ctrl));
+	if (IS_ERR(ctrl))
+		return PTR_ERR(ctrl);
+
+	ctrl->subDeviceInstance = 0;
+	ctrl->head = head;
+	ctrl->sorIndex = sor->id;
+	ctrl->dpLink = sor->asy.link == 2;
+	ctrl->bEnableOverride = 1;
+	ctrl->bMST = 0;
+	ctrl->hBlankSym = hblanksym;
+	ctrl->vBlankSym = vblanksym;
+	ctrl->colorFormat = 0;
+	ctrl->bEnableTwoHeadOneOr = 0;
+	ctrl->SST.bEnhancedFraming = ef;
+	ctrl->SST.tuSize = 64;
+	ctrl->SST.waterMark = watermark;
+	ctrl->SST.bEnableAudioOverRightPanel = 0;
+	return nvkm_gsp_rm_ctrl_wr(&disp->rm.objcom, ctrl);
+}
+
+static int
 r570_dp_set_indexed_link_rates(struct nvkm_outp *outp)
 {
 	NV0073_CTRL_CMD_DP_CONFIG_INDEXED_LINK_RATES_PARAMS *ctrl;
@@ -255,6 +317,8 @@ r570_disp = {
 	.dp = {
 		.get_caps = r570_dp_get_caps,
 		.set_indexed_link_rates = r570_dp_set_indexed_link_rates,
+		.sst = r570_dp_sst,
+		.vcpi = r570_dp_vcpi,
 	},
 	.chan = {
 		.set_pushbuf = r570_disp_chan_set_pushbuf,
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/nvrm/disp.h
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/nvrm/disp.h
@@ -256,6 +256,8 @@ typedef struct NV0073_CTRL_DP_CTRL_PARAM
     NvU32 eightLaneDpcdBaseAddr;
 } NV0073_CTRL_DP_CTRL_PARAMS;
 
+#define NV0073_CTRL_CMD_DP_CONFIG_STREAM                   (0x731362U) /* finn: Evaluated from "(FINN_NV04_DISPLAY_COMMON_DP_INTERFACE_ID << 8) | NV0073_CTRL_CMD_DP_CONFIG_STREAM_PARAMS_MESSAGE_ID" */
+
 typedef struct NV0073_CTRL_CMD_DP_CONFIG_STREAM_PARAMS {
     NvU32  subDeviceInstance;
     NvU32  head;
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/rm.h
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/rm.h
@@ -6,6 +6,7 @@
 #ifndef __NVKM_RM_H__
 #define __NVKM_RM_H__
 #include "handles.h"
+struct nvkm_ior;
 struct nvkm_outp;
 struct r535_gr;
 
@@ -93,6 +94,10 @@ struct nvkm_rm_api {
 		struct {
 			int (*get_caps)(struct nvkm_disp *, int *link_bw, bool *mst, bool *wm);
 			int (*set_indexed_link_rates)(struct nvkm_outp *);
+			int (*sst)(struct nvkm_ior *, int head, bool ef,
+				   u32 watermark, u32 hblanksym, u32 vblanksym);
+			int (*vcpi)(struct nvkm_ior *, int head,
+				    u8 slot, u8 slot_nr, u16 pbn, u16 aligned_pbn);
 		} dp;
 
 		struct {



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 529/556] drm/nouveau: unsubscribe the channel-kill event before the fence context
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (527 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 528/556] drm/nouveau/gsp: use per-version DP_CONFIG_STREAM params on r570 firmware Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 530/556] drm/nouveau: Use write-combined maps for coherent Greg Kroah-Hartman
                   ` (39 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Marek Czernohous, Lyude Paul

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Marek Czernohous <marek@czernohous.de>

commit 511585987d27d8cb668acebd399fc4deda23404c upstream.

nouveau_channel_del() tears the fence context down first and only drops
the channel-kill subscription later, in the middle of the nvif object
teardown:

	if (chan->fence)
		nouveau_fence(chan->cli->drm)->context_del(chan);
	...
	nvif_object_dtor(&chan->vram);
	nvif_event_dtor(&chan->kill);

The subscribed handler is nouveau_channel_killed(), which calls
nouveau_channel_kill() and from there nouveau_fence_context_kill() on
chan->fence. A kill event delivered in that window takes fctx->lock and
walks fctx->pending on a fence context that context_del() has already
freed.

Nothing reaches this below Fermi today, because the subscription is
gated on FERMI_CHANNEL_GPFIFO and nothing kills a channel there. On
Fermi and newer the window is real but narrow, since a kill has to land
exactly while the channel is being destroyed. That is reason enough on
its own, which is why this carries a Fixes: tag. The last patch in this
series subscribes Tesla channels as well; nothing kills those today, so
it does not widen the exposure now, but it is the groundwork for a
recovery path that would, and the ordering is better fixed before that
lands than alongside it.

Drop the subscription before anything it depends on is torn down.

Fixes: ea13e5abf807 ("drm/nouveau: signal pending fences when channel has been killed")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-5
Signed-off-by: Marek Czernohous <marek@czernohous.de>
Fixes: ea13e5abf807 ("drm/nouveau: signal pending fences when channel has been killed")
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260812231330.705425-2-mczernohous@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/nouveau/nouveau_chan.c |    9 ++++++++-
 1 file changed, 8 insertions(+), 1 deletion(-)

--- a/drivers/gpu/drm/nouveau/nouveau_chan.c
+++ b/drivers/gpu/drm/nouveau/nouveau_chan.c
@@ -90,6 +90,14 @@ nouveau_channel_del(struct nouveau_chann
 {
 	struct nouveau_channel *chan = *pchan;
 	if (chan) {
+		/*
+		 * Drop the kill-event subscription first.  Its handler
+		 * dereferences chan->fence, which the fence context teardown
+		 * below frees, so leaving it armed across the teardown leaves
+		 * a window for a use-after-free.
+		 */
+		nvif_event_dtor(&chan->kill);
+
 		if (chan->fence)
 			nouveau_fence(chan->cli->drm)->context_del(chan);
 
@@ -100,7 +108,6 @@ nouveau_channel_del(struct nouveau_chann
 		nvif_object_dtor(&chan->nvsw);
 		nvif_object_dtor(&chan->gart);
 		nvif_object_dtor(&chan->vram);
-		nvif_event_dtor(&chan->kill);
 		nvif_object_dtor(&chan->user);
 		nvif_mem_dtor(&chan->mem_userd);
 		nouveau_vma_del(&chan->sema.vma);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 530/556] drm/nouveau: Use write-combined maps for coherent
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (528 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 529/556] drm/nouveau: unsubscribe the channel-kill event before the fence context Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 531/556] drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op Greg Kroah-Hartman
                   ` (38 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Faith Ekstrand, Aaron Kling,
	Danilo Krummrich

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Faith Ekstrand <faith.ekstrand@collabora.com>

commit 774b73428e6eabb4f0382aeeb76e569c7b106a29 upstream.

On Tegra devices, uncached maps translate to device memory, causing
unaligned accesses by userspace resulting in a SIGBUS. Instead, use
write-combined maps to ensure proper access.

This would also affect discrete cards on any Arm device. It was
determined that discrete cards regardless of cpu arch should use
write-combined maps for coherent anyways. Thus this change is made for
all gpu types.

Cc: stable@vger.kernel.org
Signed-off-by: Faith Ekstrand <faith.ekstrand@collabora.com>
Co-developed-by: Aaron Kling <webgeek1234@gmail.com>
Signed-off-by: Aaron Kling <webgeek1234@gmail.com>
Fixes: 1b4ea4c5980f ("drm/ttm: set the tt caching state at creation time")
Link: https://patch.msgid.link/20260821-tegra-coherent-wc-v2-1-2b1ddb67bf18@gmail.com
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/nouveau/nouveau_sgdma.c |    4 +---
 1 file changed, 1 insertion(+), 3 deletions(-)

--- a/drivers/gpu/drm/nouveau/nouveau_sgdma.c
+++ b/drivers/gpu/drm/nouveau/nouveau_sgdma.c
@@ -72,9 +72,7 @@ nouveau_sgdma_create_ttm(struct ttm_buff
 	struct nouveau_sgdma_be *nvbe;
 	enum ttm_caching caching;
 
-	if (nvbo->force_coherent)
-		caching = ttm_uncached;
-	else if (drm->agp.bridge)
+	if (nvbo->force_coherent || drm->agp.bridge)
 		caching = ttm_write_combined;
 	else
 		caching = ttm_cached;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 531/556] drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (529 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 530/556] drm/nouveau: Use write-combined maps for coherent Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 532/556] drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE Greg Kroah-Hartman
                   ` (37 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yuhao Jiang, Zhenhao Wan, Lyude Paul,
	Danilo Krummrich

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhenhao Wan <whi4ed0g@gmail.com>

commit 412a6ceb56d501ef2f8202e26ab4b5d4dfbca566 upstream.

Each bind_job_op is zeroed by kzalloc_obj() in bind_job_op_from_uop(),
and the OP_MAP_SPARSE case in nouveau_uvmm_bind_job_submit() only creates
a region, so op->ops stays NULL for a successfully processed sparse map.

If a later op in the same job fails, the reverse unwind loop revisits that
op and calls drm_gpuva_ops_free(&uvmm->base, op->ops) unconditionally.
drm_gpuva_ops_free() dereferences its argument right away
(list_for_each_entry_safe on &ops->list), so a NULL op->ops oopses. The
path is reachable by any render-node fd holder, since NOUVEAU_VM_BIND is
DRM_RENDER_ALLOW.

Guard the free with IS_ERR_OR_NULL(), as nouveau_uvmm_bind_job_cleanup()
already does for the identical free.

Fixes: b88baab82871 ("drm/nouveau: implement new VM_BIND uAPI")
Reported-by: Yuhao Jiang <danisjiang@gmail.com>
Assisted-by: Claude:claude-opus-5
Cc: stable@vger.kernel.org
Signed-off-by: Zhenhao Wan <whi4ed0g@gmail.com>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260811-nouveau-uvmm-vmbind-fixes-v2-1-aaee4b395d04@gmail.com
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/nouveau/nouveau_uvmm.c |    3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

--- a/drivers/gpu/drm/nouveau/nouveau_uvmm.c
+++ b/drivers/gpu/drm/nouveau/nouveau_uvmm.c
@@ -1489,7 +1489,8 @@ unwind:
 			break;
 		}
 
-		drm_gpuva_ops_free(&uvmm->base, op->ops);
+		if (!IS_ERR_OR_NULL(op->ops))
+			drm_gpuva_ops_free(&uvmm->base, op->ops);
 		op->ops = NULL;
 		op->reg = NULL;
 	}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 532/556] drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (530 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 531/556] drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 533/556] drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE Greg Kroah-Hartman
                   ` (36 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yuhao Jiang, Zhenhao Wan, Lyude Paul,
	Danilo Krummrich

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhenhao Wan <whi4ed0g@gmail.com>

commit ccf930812f23b8259ef64fd3394d53b093e4651a upstream.

In nouveau_uvmm_bind_job_submit()'s OP_UNMAP_SPARSE arm, op->reg is set
from nouveau_uvma_region_find(), which only looks the region up and takes
no reference; a region's sole reference is its membership in
uvmm->region_mt. Two failure paths leave op->reg set: the -ENOENT check
when the region is busy, and the drm_gpuvm_sm_unmap_ops_create() failure.
The sibling nouveau_uvmm_sm_unmap_prepare() failure just below clears
op->reg; these two do not.

unwind_continue steps back one op, so the failing op is skipped by the
unwind loop and its op->reg stays set. nouveau_uvmm_bind_job_cleanup()
then enters its if (op->reg) branch and calls nouveau_uvma_region_remove()
and nouveau_uvma_region_put() on it, dropping the tree's sole reference
and freeing a region this job never created. The comment above the
cleanup loop documents the broken invariant: op->reg must be NULL on
submit failure.

This frees a live region on an unrelated failure, reachable single-job
when drm_gpuvm_sm_unmap_ops_create() returns -ENOMEM; if another job owns
the same region, its cleanup then removes and puts the freed region, a
use-after-free. Clear op->reg on both failure paths.

Fixes: b88baab82871 ("drm/nouveau: implement new VM_BIND uAPI")
Reported-by: Yuhao Jiang <danisjiang@gmail.com>
Assisted-by: Claude:claude-opus-5
Cc: stable@vger.kernel.org
Signed-off-by: Zhenhao Wan <whi4ed0g@gmail.com>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260811-nouveau-uvmm-vmbind-fixes-v2-2-aaee4b395d04@gmail.com
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/nouveau/nouveau_uvmm.c |    2 ++
 1 file changed, 2 insertions(+)

--- a/drivers/gpu/drm/nouveau/nouveau_uvmm.c
+++ b/drivers/gpu/drm/nouveau/nouveau_uvmm.c
@@ -1319,6 +1319,7 @@ nouveau_uvmm_bind_job_submit(struct nouv
 							   op->va.range);
 			if (!op->reg || op->reg->dirty) {
 				ret = -ENOENT;
+				op->reg = NULL;
 				goto unwind_continue;
 			}
 
@@ -1327,6 +1328,7 @@ nouveau_uvmm_bind_job_submit(struct nouv
 								op->va.range);
 			if (IS_ERR(op->ops)) {
 				ret = PTR_ERR(op->ops);
+				op->reg = NULL;
 				goto unwind_continue;
 			}
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 533/556] drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (531 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 532/556] drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 534/556] drm/nouveau/disp: move GSP head-timing ISR and vblank helpers to tu102.c Greg Kroah-Hartman
                   ` (35 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Yuhao Jiang, Zhenhao Wan, Lyude Paul,
	Danilo Krummrich

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Zhenhao Wan <whi4ed0g@gmail.com>

commit 38a62306c4266bcb3cd89e33c7111ee33096ebb3 upstream.

A successful OP_UNMAP_SPARSE marks its region dirty with
nouveau_uvma_region_dirty() and defers the teardown to
nouveau_uvmm_bind_job_cleanup(); it does not remove the region from
uvmm->region_mt.

If a later op in the job fails, the unwind path never clears reg->dirty
(set in one place, cleared nowhere) and sets op->reg = NULL, so cleanup
skips the teardown. The region is left in the tree with dirty set and its
completion never signalled. Later binds over that range then fail
permanently -- -ENOENT or -EINVAL from the dirty checks, or an unkillable
wait_for_completion() in bind_validate_region() -- for the lifetime of
the uvmm.

Clear reg->dirty when the unwind reverts the sparse unmap, restoring the
region to the state it was found in.

Fixes: b88baab82871 ("drm/nouveau: implement new VM_BIND uAPI")
Reported-by: Yuhao Jiang <danisjiang@gmail.com>
Assisted-by: Claude:claude-opus-5
Cc: stable@vger.kernel.org
Signed-off-by: Zhenhao Wan <whi4ed0g@gmail.com>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260811-nouveau-uvmm-vmbind-fixes-v2-3-aaee4b395d04@gmail.com
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/nouveau/nouveau_uvmm.c |    1 +
 1 file changed, 1 insertion(+)

--- a/drivers/gpu/drm/nouveau/nouveau_uvmm.c
+++ b/drivers/gpu/drm/nouveau/nouveau_uvmm.c
@@ -1475,6 +1475,7 @@ unwind:
 						    op->va.range);
 			break;
 		case OP_UNMAP_SPARSE:
+			op->reg->dirty = false;
 			__nouveau_uvma_region_insert(uvmm, op->reg);
 			nouveau_uvmm_sm_unmap_prepare_unwind(uvmm, &op->new,
 							     op->ops);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 534/556] drm/nouveau/disp: move GSP head-timing ISR and vblank helpers to tu102.c
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (532 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 533/556] drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 535/556] drm/nouveau/disp: move the GSP HDMI GCP AVMute write to engine/disp Greg Kroah-Hartman
                   ` (34 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Mohamed Ahmed, Lyude Paul

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mohamed Ahmed <mohamedahmedegypt2001@gmail.com>

commit c6659e0ffc19b4ef0b3273c185cb8409a154eada upstream.

The GSP-RM display code in rm/r535/disp.c owns a handful of direct MMIO
routines: the head-timing (vblank) interrupt handler and the per-head
vblank enable/disable. They program display registers, not RM, so they
belong with the rest of the per-chip register code in engine/disp/.

Move them to tu102.c (Turing is the first GSP-capable generation) as
tu102_disp_intr() and tu102_head_vblank_get()/put(), exported for
rm/r535/disp.c, which keeps calling them by name for now. No functional
change.

Fixes: 6cc6e08d4542 ("drm/nouveau/kms: add support for GB20x")
Cc: stable@vger.kernel.org
Signed-off-by: Mohamed Ahmed <mohamedahmedegypt2001@gmail.com>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260825001408.14219-2-mohamedahmedegypt2001@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/nouveau/nvkm/engine/disp/head.h        |    3 
 drivers/gpu/drm/nouveau/nvkm/engine/disp/priv.h        |    1 
 drivers/gpu/drm/nouveau/nvkm/engine/disp/tu102.c       |   50 ++++++++++++++++
 drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/disp.c |   52 -----------------
 4 files changed, 57 insertions(+), 49 deletions(-)

--- a/drivers/gpu/drm/nouveau/nvkm/engine/disp/head.h
+++ b/drivers/gpu/drm/nouveau/nvkm/engine/disp/head.h
@@ -56,6 +56,9 @@ int gv100_head_new(struct nvkm_disp *, i
 void gv100_head_state(struct nvkm_head *head, struct nvkm_head_state *state);
 void gv100_head_rgpos(struct nvkm_head *head, u16 *hline, u16 *vline);
 
+void tu102_head_vblank_get(struct nvkm_head *);
+void tu102_head_vblank_put(struct nvkm_head *);
+
 #define HEAD_MSG(h,l,f,a...) do {                                              \
 	struct nvkm_head *_h = (h);                                            \
 	nvkm_##l(&_h->disp->engine.subdev, "head-%d: "f"\n", _h->id, ##a);     \
--- a/drivers/gpu/drm/nouveau/nvkm/engine/disp/priv.h
+++ b/drivers/gpu/drm/nouveau/nvkm/engine/disp/priv.h
@@ -72,6 +72,7 @@ int gv100_disp_wndw_cnt(struct nvkm_disp
 int gv100_disp_caps_new(const struct nvkm_oclass *, void *, u32, struct nvkm_object **);
 
 int tu102_disp_init(struct nvkm_disp *);
+irqreturn_t tu102_disp_intr(struct nvkm_inth *);
 
 void nv50_disp_dptmds_war_2(struct nvkm_disp *, struct dcb_output *);
 void nv50_disp_dptmds_war_3(struct nvkm_disp *, struct dcb_output *);
--- a/drivers/gpu/drm/nouveau/nvkm/engine/disp/tu102.c
+++ b/drivers/gpu/drm/nouveau/nvkm/engine/disp/tu102.c
@@ -104,6 +104,56 @@ tu102_sor_new(struct nvkm_disp *disp, in
 	return nvkm_ior_new_(&tu102_sor, disp, SOR, id, hda & BIT(id));
 }
 
+/* The GSP-RM display path leaves head-timing (vblank) interrupts and their
+ * enables to us. These program the RM head-timing line (bit 1 of the
+ * per-head enable, not the bit nvkm's own gv100 path uses).
+ */
+void
+tu102_head_vblank_put(struct nvkm_head *head)
+{
+	struct nvkm_device *device = head->disp->engine.subdev.device;
+
+	nvkm_mask(device, 0x611d80 + (head->id * 4), 0x00000002, 0x00000000);
+}
+
+void
+tu102_head_vblank_get(struct nvkm_head *head)
+{
+	struct nvkm_device *device = head->disp->engine.subdev.device;
+
+	nvkm_wr32(device, 0x611800 + (head->id * 4), 0x00000002);
+	nvkm_mask(device, 0x611d80 + (head->id * 4), 0x00000002, 0x00000002);
+}
+
+static void
+tu102_disp_intr_head_timing(struct nvkm_disp *disp, int head)
+{
+	struct nvkm_subdev *subdev = &disp->engine.subdev;
+	struct nvkm_device *device = subdev->device;
+	u32 stat = nvkm_rd32(device, 0x611c00 + (head * 0x04));
+
+	if (stat & 0x00000002) {
+		nvkm_disp_vblank(disp, head);
+
+		nvkm_wr32(device, 0x611800 + (head * 0x04), 0x00000002);
+	}
+}
+
+irqreturn_t
+tu102_disp_intr(struct nvkm_inth *inth)
+{
+	struct nvkm_disp *disp = container_of(inth, typeof(*disp), engine.subdev.inth);
+	struct nvkm_subdev *subdev = &disp->engine.subdev;
+	struct nvkm_device *device = subdev->device;
+	unsigned long mask = nvkm_rd32(device, 0x611ec0) & 0x000000ff;
+	int head;
+
+	for_each_set_bit(head, &mask, 8)
+		tu102_disp_intr_head_timing(disp, head);
+
+	return IRQ_HANDLED;
+}
+
 int
 tu102_disp_init(struct nvkm_disp *disp)
 {
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/disp.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/disp.c
@@ -625,29 +625,12 @@ r535_sor_cnt(struct nvkm_disp *disp, uns
 	return 4;
 }
 
-static void
-r535_head_vblank_put(struct nvkm_head *head)
-{
-	struct nvkm_device *device = head->disp->engine.subdev.device;
-
-	nvkm_mask(device, 0x611d80 + (head->id * 4), 0x00000002, 0x00000000);
-}
-
-static void
-r535_head_vblank_get(struct nvkm_head *head)
-{
-	struct nvkm_device *device = head->disp->engine.subdev.device;
-
-	nvkm_wr32(device, 0x611800 + (head->id * 4), 0x00000002);
-	nvkm_mask(device, 0x611d80 + (head->id * 4), 0x00000002, 0x00000002);
-}
-
 static const struct nvkm_head_func
 r535_head = {
 	.state = gv100_head_state,
 	.rgpos = gv100_head_rgpos,
-	.vblank_get = r535_head_vblank_get,
-	.vblank_put = r535_head_vblank_put,
+	.vblank_get = tu102_head_vblank_get,
+	.vblank_put = tu102_head_vblank_put,
 };
 
 static struct nvkm_conn *
@@ -1422,35 +1405,6 @@ r535_disp_event = {
 };
 
 static void
-r535_disp_intr_head_timing(struct nvkm_disp *disp, int head)
-{
-	struct nvkm_subdev *subdev = &disp->engine.subdev;
-	struct nvkm_device *device = subdev->device;
-	u32 stat = nvkm_rd32(device, 0x611c00 + (head * 0x04));
-
-	if (stat & 0x00000002) {
-		nvkm_disp_vblank(disp, head);
-
-		nvkm_wr32(device, 0x611800 + (head * 0x04), 0x00000002);
-	}
-}
-
-static irqreturn_t
-r535_disp_intr(struct nvkm_inth *inth)
-{
-	struct nvkm_disp *disp = container_of(inth, typeof(*disp), engine.subdev.inth);
-	struct nvkm_subdev *subdev = &disp->engine.subdev;
-	struct nvkm_device *device = subdev->device;
-	unsigned long mask = nvkm_rd32(device, 0x611ec0) & 0x000000ff;
-	int head;
-
-	for_each_set_bit(head, &mask, 8)
-		r535_disp_intr_head_timing(disp, head);
-
-	return IRQ_HANDLED;
-}
-
-static void
 r535_disp_fini(struct nvkm_disp *disp, bool suspend)
 {
 	if (!disp->engine.subdev.use.enabled)
@@ -1725,7 +1679,7 @@ r535_disp_oneinit(struct nvkm_disp *disp
 		return ret;
 
 	ret = nvkm_inth_add(&device->vfn->intr, ret, NVKM_INTR_PRIO_NORMAL, &disp->engine.subdev,
-			    r535_disp_intr, &disp->engine.subdev.inth);
+			    tu102_disp_intr, &disp->engine.subdev.inth);
 	if (ret)
 		return ret;
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 535/556] drm/nouveau/disp: move the GSP HDMI GCP AVMute write to engine/disp
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (533 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 534/556] drm/nouveau/disp: move GSP head-timing ISR and vblank helpers to tu102.c Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 536/556] drm/nouveau/disp: route GSP-RM display MMIO through nvkm_disp_func hooks Greg Kroah-Hartman
                   ` (33 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Mohamed Ahmed, Lyude Paul

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mohamed Ahmed <mohamedahmedegypt2001@gmail.com>

commit eb1ffc3dc72d379a41e367a44b99fb61a15bf8ba upstream.

r535_sor_hdmi_audio() pairs two RM controls (a SET_OD_PACKET carrying
the same General Control Packet, and the audio mute-stream toggle)
with a direct write of the GCP AVMute bit through the SF GCP unit.
The controls are RM and stay, but the direct write is register
programming and moves next to the other per-chip display code as
tu102_sor_hdmi_gcp(). No functional change.

Fixes: 6cc6e08d4542 ("drm/nouveau/kms: add support for GB20x")
Cc: stable@vger.kernel.org
Signed-off-by: Mohamed Ahmed <mohamedahmedegypt2001@gmail.com>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260825001408.14219-3-mohamedahmedegypt2001@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/nouveau/nvkm/engine/disp/ior.h         |    1 +
 drivers/gpu/drm/nouveau/nvkm/engine/disp/tu102.c       |   15 +++++++++++++++
 drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/disp.c |    9 +--------
 3 files changed, 17 insertions(+), 8 deletions(-)

--- a/drivers/gpu/drm/nouveau/nvkm/engine/disp/ior.h
+++ b/drivers/gpu/drm/nouveau/nvkm/engine/disp/ior.h
@@ -194,6 +194,7 @@ void gv100_sor_dp_audio_sym(struct nvkm_
 void gv100_sor_dp_watermark(struct nvkm_ior *, int, u8);
 extern const struct nvkm_ior_func_hda gv100_sor_hda;
 
+void tu102_sor_hdmi_gcp(struct nvkm_ior *, int, bool);
 void tu102_sor_dp_vcpi(struct nvkm_ior *, int, u8, u8, u16, u16);
 
 int nv50_pior_cnt(struct nvkm_disp *, unsigned long *);
--- a/drivers/gpu/drm/nouveau/nvkm/engine/disp/tu102.c
+++ b/drivers/gpu/drm/nouveau/nvkm/engine/disp/tu102.c
@@ -30,6 +30,21 @@
 
 #include <nvif/class.h>
 
+/* General Control Packet: bracket an audio enable/disable with AVMute
+ * through the legacy GCP SF unit. Used by the GSP-RM path, which sends the
+ * equivalent packet via RM as well but keeps the direct write in sync.
+ */
+void
+tu102_sor_hdmi_gcp(struct nvkm_ior *sor, int head, bool enable)
+{
+	struct nvkm_device *device = sor->disp->engine.subdev.device;
+	const u32 hdmi = head * 0x400;
+
+	nvkm_mask(device, 0x6f00c0 + hdmi, 0x00000001, 0x00000000);
+	nvkm_wr32(device, 0x6f00cc + hdmi, !enable ? 0x00000001 : 0x00000010);
+	nvkm_mask(device, 0x6f00c0 + hdmi, 0x00000001, 0x00000001);
+}
+
 void
 tu102_sor_dp_vcpi(struct nvkm_ior *sor, int head, u8 slot, u8 slot_nr, u16 pbn, u16 aligned)
 {
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/disp.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/disp.c
@@ -562,16 +562,9 @@ r535_sor_hdmi_ctrl_audio(struct nvkm_out
 static void
 r535_sor_hdmi_audio(struct nvkm_ior *sor, int head, bool enable)
 {
-	struct nvkm_device *device = sor->disp->engine.subdev.device;
-	const u32 hdmi = head * 0x400;
-
 	r535_sor_hdmi_ctrl_audio(sor->asy.outp, enable);
 	r535_sor_hdmi_ctrl_audio_mute(sor->asy.outp, !enable);
-
-	/* General Control (GCP). */
-	nvkm_mask(device, 0x6f00c0 + hdmi, 0x00000001, 0x00000000);
-	nvkm_wr32(device, 0x6f00cc + hdmi, !enable ? 0x00000001 : 0x00000010);
-	nvkm_mask(device, 0x6f00c0 + hdmi, 0x00000001, 0x00000001);
+	tu102_sor_hdmi_gcp(sor, head, enable);
 }
 
 static void



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 536/556] drm/nouveau/disp: route GSP-RM display MMIO through nvkm_disp_func hooks
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (534 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 535/556] drm/nouveau/disp: move the GSP HDMI GCP AVMute write to engine/disp Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 537/556] drm/nouveau/disp: fix HDMI vendor infoframes on GB20x Greg Kroah-Hartman
                   ` (32 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Mohamed Ahmed, Lyude Paul

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mohamed Ahmed <mohamedahmedegypt2001@gmail.com>

commit 9886aad51f4b5e7082209a153e404bcd8101356c upstream.

The GSP-RM display code in rm/r535/disp.c borrows a few
register-programming routines from engine/disp (the head-timing
interrupt handler, vblank enables, armed head state and scanout position
readback, the AVI/VSI infoframe writers and the GCP AVMute write) and so
far picked them by name, which means it has to know which chip it runs
on the moment a generation changes any of them.

Give nvkm_disp_func a .gsp table that each chip fills with exactly those
hooks, add tu102_gsp_disp (TU1xx) and ga102_gsp_disp (GA10x onwards)
carrying the current functions, hand them to r535_disp_new() instead of
the full hardware tables, and make rm/r535/disp.c call through the
hooks. The head hooks are a whole nvkm_head_func, so r535_head goes away
and the chip's own table is handed to nvkm_head_new_(). r535_sor_hdmi
gets infoframe forwarders, r535_sor_hdmi_audio() calls the GCP hook, and
the interrupt handler comes from the table. The tables are per chip even
though the two currently coincide, so a generation that changes a hook
only touches its own file.
rm/r535/disp.c no longer contains chip-specific register code, and a new
display generation only has to provide its own table. No functional
change.

Fixes: 6cc6e08d4542 ("drm/nouveau/kms: add support for GB20x")
Cc: stable@vger.kernel.org
Signed-off-by: Mohamed Ahmed <mohamedahmedegypt2001@gmail.com>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260825001408.14219-4-mohamedahmedegypt2001@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/nouveau/nvkm/engine/disp/ga102.c       |   13 ++++++-
 drivers/gpu/drm/nouveau/nvkm/engine/disp/head.h        |    1 
 drivers/gpu/drm/nouveau/nvkm/engine/disp/priv.h        |   14 +++++++
 drivers/gpu/drm/nouveau/nvkm/engine/disp/tu102.c       |   21 ++++++++++-
 drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/disp.c |   31 +++++++++--------
 5 files changed, 65 insertions(+), 15 deletions(-)

--- a/drivers/gpu/drm/nouveau/nvkm/engine/disp/ga102.c
+++ b/drivers/gpu/drm/nouveau/nvkm/engine/disp/ga102.c
@@ -144,12 +144,23 @@ ga102_disp = {
 	},
 };
 
+static const struct nvkm_disp_func
+ga102_gsp_disp = {
+	.uevent = &gv100_disp_chan_uevent,
+	.ramht_size = 0x2000,
+	.gsp.intr = tu102_disp_intr,
+	.gsp.head = &tu102_gsp_head,
+	.gsp.hdmi_gcp = tu102_sor_hdmi_gcp,
+	.gsp.hdmi_infoframe_avi = gv100_sor_hdmi_infoframe_avi,
+	.gsp.hdmi_infoframe_vsi = gv100_sor_hdmi_infoframe_vsi,
+};
+
 int
 ga102_disp_new(struct nvkm_device *device, enum nvkm_subdev_type type, int inst,
 	       struct nvkm_disp **pdisp)
 {
 	if (nvkm_gsp_rm(device->gsp))
-		return r535_disp_new(&ga102_disp, device, type, inst, pdisp);
+		return r535_disp_new(&ga102_gsp_disp, device, type, inst, pdisp);
 
 	return nvkm_disp_new_(&ga102_disp, device, type, inst, pdisp);
 }
--- a/drivers/gpu/drm/nouveau/nvkm/engine/disp/head.h
+++ b/drivers/gpu/drm/nouveau/nvkm/engine/disp/head.h
@@ -58,6 +58,7 @@ void gv100_head_rgpos(struct nvkm_head *
 
 void tu102_head_vblank_get(struct nvkm_head *);
 void tu102_head_vblank_put(struct nvkm_head *);
+extern const struct nvkm_head_func tu102_gsp_head;
 
 #define HEAD_MSG(h,l,f,a...) do {                                              \
 	struct nvkm_head *_h = (h);                                            \
--- a/drivers/gpu/drm/nouveau/nvkm/engine/disp/priv.h
+++ b/drivers/gpu/drm/nouveau/nvkm/engine/disp/priv.h
@@ -5,6 +5,8 @@
 #include <engine/disp.h>
 #include <core/enum.h>
 struct nvkm_head;
+struct nvkm_head_func;
+struct nvkm_ior;
 struct nvkm_outp;
 struct dcb_output;
 
@@ -34,6 +36,18 @@ struct nvkm_disp_func {
 		int (*new)(struct nvkm_disp *, int id);
 	} wndw, head, dac, sor, pior;
 
+	/* Register programming that the GSP-RM display path (rm/r535) needs from
+	 * the chip, everything else on that path goes through RM. The hooks are
+	 * called unconditionally and the head table is handed to nvkm_head_new_().
+	 */
+	struct {
+		irqreturn_t (*intr)(struct nvkm_inth *);
+		const struct nvkm_head_func *head;
+		void (*hdmi_gcp)(struct nvkm_ior *, int head, bool enable);
+		void (*hdmi_infoframe_avi)(struct nvkm_ior *, int head, void *data, u32 size);
+		void (*hdmi_infoframe_vsi)(struct nvkm_ior *, int head, void *data, u32 size);
+	} gsp;
+
 	u16 ramht_size;
 
 	struct nvkm_sclass root;
--- a/drivers/gpu/drm/nouveau/nvkm/engine/disp/tu102.c
+++ b/drivers/gpu/drm/nouveau/nvkm/engine/disp/tu102.c
@@ -140,6 +140,14 @@ tu102_head_vblank_get(struct nvkm_head *
 	nvkm_mask(device, 0x611d80 + (head->id * 4), 0x00000002, 0x00000002);
 }
 
+const struct nvkm_head_func
+tu102_gsp_head = {
+	.state = gv100_head_state,
+	.rgpos = gv100_head_rgpos,
+	.vblank_get = tu102_head_vblank_get,
+	.vblank_put = tu102_head_vblank_put,
+};
+
 static void
 tu102_disp_intr_head_timing(struct nvkm_disp *disp, int head)
 {
@@ -295,12 +303,23 @@ tu102_disp = {
 	},
 };
 
+static const struct nvkm_disp_func
+tu102_gsp_disp = {
+	.uevent = &gv100_disp_chan_uevent,
+	.ramht_size = 0x2000,
+	.gsp.intr = tu102_disp_intr,
+	.gsp.head = &tu102_gsp_head,
+	.gsp.hdmi_gcp = tu102_sor_hdmi_gcp,
+	.gsp.hdmi_infoframe_avi = gv100_sor_hdmi_infoframe_avi,
+	.gsp.hdmi_infoframe_vsi = gv100_sor_hdmi_infoframe_vsi,
+};
+
 int
 tu102_disp_new(struct nvkm_device *device, enum nvkm_subdev_type type, int inst,
 	       struct nvkm_disp **pdisp)
 {
 	if (nvkm_gsp_rm(device->gsp))
-		return r535_disp_new(&tu102_disp, device, type, inst, pdisp);
+		return r535_disp_new(&tu102_gsp_disp, device, type, inst, pdisp);
 
 	return nvkm_disp_new_(&tu102_disp, device, type, inst, pdisp);
 }
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/disp.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/disp.c
@@ -564,7 +564,19 @@ r535_sor_hdmi_audio(struct nvkm_ior *sor
 {
 	r535_sor_hdmi_ctrl_audio(sor->asy.outp, enable);
 	r535_sor_hdmi_ctrl_audio_mute(sor->asy.outp, !enable);
-	tu102_sor_hdmi_gcp(sor, head, enable);
+	sor->disp->func->gsp.hdmi_gcp(sor, head, enable);
+}
+
+static void
+r535_sor_hdmi_infoframe_avi(struct nvkm_ior *sor, int head, void *data, u32 size)
+{
+	sor->disp->func->gsp.hdmi_infoframe_avi(sor, head, data, size);
+}
+
+static void
+r535_sor_hdmi_infoframe_vsi(struct nvkm_ior *sor, int head, void *data, u32 size)
+{
+	sor->disp->func->gsp.hdmi_infoframe_vsi(sor, head, data, size);
 }
 
 static void
@@ -592,8 +604,8 @@ r535_sor_hdmi = {
 	.ctrl = r535_sor_hdmi_ctrl,
 	.scdc = r535_sor_hdmi_scdc,
 	/*TODO: SF_USER -> KMS. */
-	.infoframe_avi = gv100_sor_hdmi_infoframe_avi,
-	.infoframe_vsi = gv100_sor_hdmi_infoframe_vsi,
+	.infoframe_avi = r535_sor_hdmi_infoframe_avi,
+	.infoframe_vsi = r535_sor_hdmi_infoframe_vsi,
 	.audio = r535_sor_hdmi_audio,
 };
 
@@ -618,14 +630,6 @@ r535_sor_cnt(struct nvkm_disp *disp, uns
 	return 4;
 }
 
-static const struct nvkm_head_func
-r535_head = {
-	.state = gv100_head_state,
-	.rgpos = gv100_head_rgpos,
-	.vblank_get = tu102_head_vblank_get,
-	.vblank_put = tu102_head_vblank_put,
-};
-
 static struct nvkm_conn *
 r535_conn_new(struct nvkm_disp *disp, u32 id)
 {
@@ -1623,7 +1627,7 @@ r535_disp_oneinit(struct nvkm_disp *disp
 		nvkm_gsp_rm_ctrl_done(&disp->rm.objcom, ctrl);
 
 		for_each_set_bit(i, &disp->head.mask, disp->head.nr) {
-			ret = nvkm_head_new_(&r535_head, disp, i);
+			ret = nvkm_head_new_(disp->func->gsp.head, disp, i);
 			if (ret)
 				return ret;
 		}
@@ -1672,7 +1676,7 @@ r535_disp_oneinit(struct nvkm_disp *disp
 		return ret;
 
 	ret = nvkm_inth_add(&device->vfn->intr, ret, NVKM_INTR_PRIO_NORMAL, &disp->engine.subdev,
-			    tu102_disp_intr, &disp->engine.subdev.inth);
+			    disp->func->gsp.intr, &disp->engine.subdev.inth);
 	if (ret)
 		return ret;
 
@@ -1705,6 +1709,7 @@ r535_disp_new(const struct nvkm_disp_fun
 	rm->uevent = hw->uevent;
 	rm->sor.cnt = r535_sor_cnt;
 	rm->sor.new = r535_sor_new;
+	rm->gsp = hw->gsp;
 	rm->ramht_size = hw->ramht_size;
 
 	rm->root.oclass = gpu->disp.class.root;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 537/556] drm/nouveau/disp: fix HDMI vendor infoframes on GB20x
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (535 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 536/556] drm/nouveau/disp: route GSP-RM display MMIO through nvkm_disp_func hooks Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 538/556] drm/nouveau/disp: fix HDMI GCP AVMute register offsets " Greg Kroah-Hartman
                   ` (31 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Mohamed Ahmed, Lyude Paul

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mohamed Ahmed <mohamedahmedegypt2001@gmail.com>

commit 92f09dcb4e8473ab25764e950994ab7b6abce6dd upstream.

The GSP path reuses the GV100 direct-MMIO infoframe writers on every
chip. On GB20x that is only half right as while the legacy SF AVI unit is
unchanged, the legacy VSI unit at 0x6f0100 was removed, so
gv100_sor_hdmi_infoframe_vsi() writes into a reserved area and no vendor
infoframe ever reaches the HW. This affects HDMI-VIC signalling which
can impact some 4K modes for legacy HDMI 1.4 sinks.

GB20x (NVDisplay 5.0+) reorganised the SF HDMI packet units. Per NVIDIA's
published C971/CA71 DISP_SF_USER class headers, only three legacy units
remain (AVI at +0x000, GCP at +0x040, ACR at +0x080), and vendor
infoframes must instead be sent through the shared generic infoframe
units at +0x130, whose 9-dword packet slots are loaded through the
shared data port at +0x3f0/+0x3f4.

Add a VSI writer using the same programming sequence OpenRM uses on
these chips (nvhdmipkt_C971.c, programAdvancedInfoframeC971()): disable
the unit and wait for it to idle, clear the SENT status, write the packet
through the data port with a zero inserted in HB3 after the three header
bytes, then enable the unit for every-frame transmission during vblank.
Generic unit 1 is used for the VSI, matching the slot assignment in
NVIDIA's nvkms (NVHDMIPKT_TYPE_SHARED_GENERIC2, unit 0 is reserved
for extended metadata packets and unit 2 for the HDR DRM infoframe,
if those are wired up later).

GB20x so far shared GA10x's display entry point. Give it its own,
gb202_disp_new(), with a gb202_gsp_disp table that supplies the VSI
writer to the GSP path and otherwise carries the same hooks as GA10x.
The following fixes fill in the rest of the GB20x differences there.

Fixes: 6cc6e08d4542 ("drm/nouveau/kms: add support for GB20x")
Cc: stable@vger.kernel.org
Signed-off-by: Mohamed Ahmed <mohamedahmedegypt2001@gmail.com>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260825001408.14219-5-mohamedahmedegypt2001@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/nouveau/include/nvkm/engine/disp.h |    1 
 drivers/gpu/drm/nouveau/nvkm/engine/device/base.c  |   10 +-
 drivers/gpu/drm/nouveau/nvkm/engine/disp/Kbuild    |    1 
 drivers/gpu/drm/nouveau/nvkm/engine/disp/gb202.c   |   88 +++++++++++++++++++++
 4 files changed, 95 insertions(+), 5 deletions(-)
 create mode 100644 drivers/gpu/drm/nouveau/nvkm/engine/disp/gb202.c

--- a/drivers/gpu/drm/nouveau/include/nvkm/engine/disp.h
+++ b/drivers/gpu/drm/nouveau/include/nvkm/engine/disp.h
@@ -87,4 +87,5 @@ int gp102_disp_new(struct nvkm_device *,
 int gv100_disp_new(struct nvkm_device *, enum nvkm_subdev_type, int inst, struct nvkm_disp **);
 int tu102_disp_new(struct nvkm_device *, enum nvkm_subdev_type, int inst, struct nvkm_disp **);
 int ga102_disp_new(struct nvkm_device *, enum nvkm_subdev_type, int inst, struct nvkm_disp **);
+int gb202_disp_new(struct nvkm_device *, enum nvkm_subdev_type, int inst, struct nvkm_disp **);
 #endif
--- a/drivers/gpu/drm/nouveau/nvkm/engine/device/base.c
+++ b/drivers/gpu/drm/nouveau/nvkm/engine/device/base.c
@@ -2846,7 +2846,7 @@ nv1b2_chipset = {
 	.pci      = { 0x00000001, gh100_pci_new },
 	.timer    = { 0x00000001, gk20a_timer_new },
 	.vfn      = { 0x00000001, ga100_vfn_new },
-	.disp     = { 0x00000001, ga102_disp_new },
+	.disp     = { 0x00000001, gb202_disp_new },
 	.fifo     = { 0x00000001, ga102_fifo_new },
 };
 
@@ -2862,7 +2862,7 @@ nv1b3_chipset = {
 	.pci      = { 0x00000001, gh100_pci_new },
 	.timer    = { 0x00000001, gk20a_timer_new },
 	.vfn      = { 0x00000001, ga100_vfn_new },
-	.disp     = { 0x00000001, ga102_disp_new },
+	.disp     = { 0x00000001, gb202_disp_new },
 	.fifo     = { 0x00000001, ga102_fifo_new },
 };
 
@@ -2878,7 +2878,7 @@ nv1b5_chipset = {
 	.pci      = { 0x00000001, gh100_pci_new },
 	.timer    = { 0x00000001, gk20a_timer_new },
 	.vfn      = { 0x00000001, ga100_vfn_new },
-	.disp     = { 0x00000001, ga102_disp_new },
+	.disp     = { 0x00000001, gb202_disp_new },
 	.fifo     = { 0x00000001, ga102_fifo_new },
 };
 
@@ -2894,7 +2894,7 @@ nv1b6_chipset = {
 	.pci      = { 0x00000001, gh100_pci_new },
 	.timer    = { 0x00000001, gk20a_timer_new },
 	.vfn      = { 0x00000001, ga100_vfn_new },
-	.disp     = { 0x00000001, ga102_disp_new },
+	.disp     = { 0x00000001, gb202_disp_new },
 	.fifo     = { 0x00000001, ga102_fifo_new },
 };
 
@@ -2910,7 +2910,7 @@ nv1b7_chipset = {
 	.pci      = { 0x00000001, gh100_pci_new },
 	.timer    = { 0x00000001, gk20a_timer_new },
 	.vfn      = { 0x00000001, ga100_vfn_new },
-	.disp     = { 0x00000001, ga102_disp_new },
+	.disp     = { 0x00000001, gb202_disp_new },
 	.fifo     = { 0x00000001, ga102_fifo_new },
 };
 
--- a/drivers/gpu/drm/nouveau/nvkm/engine/disp/Kbuild
+++ b/drivers/gpu/drm/nouveau/nvkm/engine/disp/Kbuild
@@ -27,6 +27,7 @@ nvkm-y += nvkm/engine/disp/gp102.o
 nvkm-y += nvkm/engine/disp/gv100.o
 nvkm-y += nvkm/engine/disp/tu102.o
 nvkm-y += nvkm/engine/disp/ga102.o
+nvkm-y += nvkm/engine/disp/gb202.o
 
 nvkm-y += nvkm/engine/disp/udisp.o
 nvkm-y += nvkm/engine/disp/uconn.o
--- /dev/null
+++ b/drivers/gpu/drm/nouveau/nvkm/engine/disp/gb202.c
@@ -0,0 +1,88 @@
+// SPDX-License-Identifier: MIT
+/*
+ * Copyright 2026 Valve Corp.
+ */
+#include "priv.h"
+#include "head.h"
+#include "ior.h"
+
+#include <subdev/timer.h>
+
+/* GB20x (NVD5.0) reorganised the SF HDMI packet units. The AVI unit is
+ * unchanged from GV100, but the legacy VSI unit is gone. Vendor infoframes
+ * are sent through the shared generic infoframe units instead. Register
+ * layout per NVIDIA's clc971.h/clca71.h, programming sequence per
+ * nvhdmipkt_C971.c:programAdvancedInfoframeC971().
+ */
+static void
+gb202_sor_hdmi_infoframe_vsi(struct nvkm_ior *ior, int head, void *data, u32 size)
+{
+	struct nvkm_device *device = ior->disp->engine.subdev.device;
+	const u32 hoff = head * 0x400;
+	/* Generic infoframe unit 1, the slot NVIDIA's driver uses for the VSI. */
+	const u32 ctrl = 0x6f0138 + hoff;
+	u8 buf[36] = {};
+	int i;
+
+	/* Disable the unit and wait for it to go idle. */
+	nvkm_mask(device, ctrl, 0x00000001, 0x00000000);
+	if (nvkm_msec(device, 2000,
+		if (!(nvkm_rd32(device, ctrl) & 0x00400000))
+			break;
+	) < 0)
+		return;
+
+	if (!size)
+		return;
+
+	/* Clear SENT status, and point the data port at unit 1's slot. */
+	nvkm_mask(device, ctrl, 0x00800000, 0x00800000);
+	nvkm_wr32(device, 0x6f03f0 + hoff, 0x00000001);
+
+	/* The data port takes the raw packet, except that a zero is inserted
+	 * in HB3 after the three header bytes. A slot is 9 dwords (HB0-3 plus
+	 * up to 32 payload bytes). An HDMI infoframe carries at most PB0-27,
+	 * so the tail stays zero, and we always write the whole slot.
+	 */
+	size = min_t(u32, size, 31);
+	memcpy(buf, data, min_t(u32, size, 3));
+	if (size > 3)
+		memcpy(&buf[4], (u8 *)data + 3, size - 3);
+
+	for (i = 0; i < 36; i += 4) {
+		nvkm_wr32(device, 0x6f03f4 + hoff, buf[i + 0] | buf[i + 1] << 8 |
+						   buf[i + 2] << 16 |
+						   (u32)buf[i + 3] << 24);
+	}
+
+	/* No flip ID or scanline matching. */
+	nvkm_wr32(device, 0x6f013c + hoff, 0x00000000);
+
+	/* ENABLE | RUN_MODE=ALWAYS | LOC=VBLANK | OFFSET=1 | SIZE=0. */
+	nvkm_wr32(device, ctrl, 0x00000041);
+
+	/* Audio priority low (the init value). */
+	nvkm_wr32(device, 0x6f03f8 + hoff, 0x00000002);
+}
+
+/* GB20x is GSP-only. This table supplies the register programming the
+ * GSP-RM display path needs from the chip.
+ */
+static const struct nvkm_disp_func
+gb202_gsp_disp = {
+	.uevent = &gv100_disp_chan_uevent,
+	.ramht_size = 0x2000,
+	.gsp.intr = tu102_disp_intr,
+	.gsp.head = &tu102_gsp_head,
+	.gsp.hdmi_gcp = tu102_sor_hdmi_gcp,
+	/* The legacy AVI unit is unchanged on GB20x. */
+	.gsp.hdmi_infoframe_avi = gv100_sor_hdmi_infoframe_avi,
+	.gsp.hdmi_infoframe_vsi = gb202_sor_hdmi_infoframe_vsi,
+};
+
+int
+gb202_disp_new(struct nvkm_device *device, enum nvkm_subdev_type type, int inst,
+	       struct nvkm_disp **pdisp)
+{
+	return r535_disp_new(&gb202_gsp_disp, device, type, inst, pdisp);
+}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 538/556] drm/nouveau/disp: fix HDMI GCP AVMute register offsets on GB20x
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (536 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 537/556] drm/nouveau/disp: fix HDMI vendor infoframes on GB20x Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 539/556] drm/nouveau/disp: fix head state readback " Greg Kroah-Hartman
                   ` (30 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Mohamed Ahmed, Lyude Paul

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mohamed Ahmed <mohamedahmedegypt2001@gmail.com>

commit 764deff8450c9a83e335c17c32ea258ec25bb71e upstream.

The GSP path brackets audio enablement with a General Control Packet
AVMute toggle. r535_sor_hdmi_audio() calls the gsp.hdmi_gcp hook, which
every chip so far serves with tu102_sor_hdmi_gcp() and the legacy GCP
unit at 0x6f00c0/0x6f00cc. On GB20x the SF packet units were compacted
and the old generic and VSI units are gone (ACR keeps slot 2) and the
GCP unit moved from slot 3 to slot 1 (control 0x6f0040 and subpack
0x6f004c from NVIDIA's published clc971.h. The same offsets are also
used by OpenRM's hdmiWriteGeneralCtrlPacketC871() on these chips). The
old addresses are reserved on GB20x, so the AVMute writes were silent
no-ops and mitigated only by the equivalent GCP r535_sor_hdmi_audio()
already sends through the SET_OD_PACKET RM control.

Add a GB20x GCP writer using the new offsets and hook it into
gb202_gsp_disp, keeping the direct MMIO path in sync with the hardware
as on earlier chips.

Only SB0 (the AVMute bit) is written. On NVD5.0 the subpack register also
carries SB1_CTRL (bit 24), which selects where the deep-color CD/PP
fields are generated (hardware or from the driver, with the default being
HW). hdmiWriteGeneralCtrlPacketC871() likewise writes only SB0-SB2.

Fixes: 6cc6e08d4542 ("drm/nouveau/kms: add support for GB20x")
Cc: stable@vger.kernel.org
Signed-off-by: Mohamed Ahmed <mohamedahmedegypt2001@gmail.com>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260825001408.14219-6-mohamedahmedegypt2001@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/nouveau/nvkm/engine/disp/gb202.c |   20 +++++++++++++++++++-
 1 file changed, 19 insertions(+), 1 deletion(-)

--- a/drivers/gpu/drm/nouveau/nvkm/engine/disp/gb202.c
+++ b/drivers/gpu/drm/nouveau/nvkm/engine/disp/gb202.c
@@ -65,6 +65,24 @@ gb202_sor_hdmi_infoframe_vsi(struct nvkm
 	nvkm_wr32(device, 0x6f03f8 + hoff, 0x00000002);
 }
 
+/* General Control Packet AVMute bracket. The GCP unit moved to slot 1 on
+ * NVD5.0. Only SB0 (the AVMute bit) is ours to write so we must not do a
+ * full write here: SB1 carries the deep-color CD/PP fields, and SB1_CTRL
+ * (bit 24, new with clc871.h) controls where their generation happens (HW
+ * or driver) on these chips, with the default being HW.
+ */
+static void
+gb202_sor_hdmi_gcp(struct nvkm_ior *sor, int head, bool enable)
+{
+	struct nvkm_device *device = sor->disp->engine.subdev.device;
+	const u32 hdmi = head * 0x400;
+
+	nvkm_mask(device, 0x6f0040 + hdmi, 0x00000001, 0x00000000);
+	nvkm_mask(device, 0x6f004c + hdmi, 0x000000ff, !enable ? 0x00000001 :
+								 0x00000010);
+	nvkm_mask(device, 0x6f0040 + hdmi, 0x00000001, 0x00000001);
+}
+
 /* GB20x is GSP-only. This table supplies the register programming the
  * GSP-RM display path needs from the chip.
  */
@@ -74,7 +92,7 @@ gb202_gsp_disp = {
 	.ramht_size = 0x2000,
 	.gsp.intr = tu102_disp_intr,
 	.gsp.head = &tu102_gsp_head,
-	.gsp.hdmi_gcp = tu102_sor_hdmi_gcp,
+	.gsp.hdmi_gcp = gb202_sor_hdmi_gcp,
 	/* The legacy AVI unit is unchanged on GB20x. */
 	.gsp.hdmi_infoframe_avi = gv100_sor_hdmi_infoframe_avi,
 	.gsp.hdmi_infoframe_vsi = gb202_sor_hdmi_infoframe_vsi,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 539/556] drm/nouveau/disp: fix head state readback on GB20x
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (537 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 538/556] drm/nouveau/disp: fix HDMI GCP AVMute register offsets " Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 540/556] drm/nouveau/gsp: fix vblank interrupts " Greg Kroah-Hartman
                   ` (29 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Mohamed Ahmed, Lyude Paul

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mohamed Ahmed <mohamedahmedegypt2001@gmail.com>

commit 9421dfe912e55360e6b9301a110acb00df7e7320 upstream.

The GSP path reads armed head state and the RG scanout position through
gv100_head_state() and gv100_head_rgpos() on every generation.
gv100_head_state() reads the core channel's state mirror at a 0x400
per-head stride, which NVD5.0 (GB20x) doubled. Per NVIDIA's published
CA7D class header every HEAD_SET method sits at 0x2000 + head * 0x800,
while the mirror bases are unchanged (assembly at 0x680000, armed at
+0x8000, per OpenRM's v03_00 channel-user-base HAL which is still used on
DISPv0502).

Add gb202_head_state(), the same readback at the 0x800 stride, and a
gb202_gsp_head table to supply it.
gv100_head_rgpos() is kept. The RG registers keep their per-head 0x800
stride on NVD5.0, and OpenRM's kdispReadRgLineCountAndFrameCount_v03_00
still reads NV_PDISP_RG_DPCA on DISPv0502.

Fixes: 6cc6e08d4542 ("drm/nouveau/kms: add support for GB20x")
Cc: stable@vger.kernel.org
Signed-off-by: Mohamed Ahmed <mohamedahmedegypt2001@gmail.com>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260825001408.14219-8-mohamedahmedegypt2001@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/nouveau/nvkm/engine/disp/gb202.c |   51 ++++++++++++++++++++++-
 1 file changed, 50 insertions(+), 1 deletion(-)

--- a/drivers/gpu/drm/nouveau/nvkm/engine/disp/gb202.c
+++ b/drivers/gpu/drm/nouveau/nvkm/engine/disp/gb202.c
@@ -83,6 +83,55 @@ gb202_sor_hdmi_gcp(struct nvkm_ior *sor,
 	nvkm_mask(device, 0x6f0040 + hdmi, 0x00000001, 0x00000001);
 }
 
+/* Same core-channel state mirror as gv100_head_state() (assembly at 0x680000,
+ * armed at +0x8000, per-head method offsets unchanged), but NVD5.0 spaces
+ * heads 0x800 apart (see NVCA7D_HEAD_SET_*(a) in clca7d.h).
+ */
+static void
+gb202_head_state(struct nvkm_head *head, struct nvkm_head_state *state)
+{
+	struct nvkm_device *device = head->disp->engine.subdev.device;
+	const u32 hoff = (state == &head->arm) * 0x8000 + head->id * 0x800;
+	u32 data;
+
+	data = nvkm_rd32(device, 0x682064 + hoff);
+	state->vtotal = (data & 0xffff0000) >> 16;
+	state->htotal = (data & 0x0000ffff);
+	data = nvkm_rd32(device, 0x682068 + hoff);
+	state->vsynce = (data & 0xffff0000) >> 16;
+	state->hsynce = (data & 0x0000ffff);
+	data = nvkm_rd32(device, 0x68206c + hoff);
+	state->vblanke = (data & 0xffff0000) >> 16;
+	state->hblanke = (data & 0x0000ffff);
+	data = nvkm_rd32(device, 0x682070 + hoff);
+	state->vblanks = (data & 0xffff0000) >> 16;
+	state->hblanks = (data & 0x0000ffff);
+	/* Bit 31 is ADJ1000DIV1001, not a HERTZ bit. We don't have enough bits
+	 * to add the full clock in hz on Blackwell (35 bits), but state->hz
+	 * is unused and obsolete under GSP so this is fine.
+	 */
+	state->hz = nvkm_rd32(device, 0x68200c + hoff) & 0x7fffffff;
+
+	data = nvkm_rd32(device, 0x682004 + hoff);
+	switch ((data & 0x000000f0) >> 4) {
+	case 5: state->or.depth = 30; break;
+	case 4: state->or.depth = 24; break;
+	case 1: state->or.depth = 18; break;
+	default:
+		state->or.depth = 18;
+		WARN_ON(1);
+		break;
+	}
+}
+
+static const struct nvkm_head_func
+gb202_gsp_head = {
+	.state = gb202_head_state,
+	.rgpos = gv100_head_rgpos,
+	.vblank_get = tu102_head_vblank_get,
+	.vblank_put = tu102_head_vblank_put,
+};
+
 /* GB20x is GSP-only. This table supplies the register programming the
  * GSP-RM display path needs from the chip.
  */
@@ -91,7 +140,7 @@ gb202_gsp_disp = {
 	.uevent = &gv100_disp_chan_uevent,
 	.ramht_size = 0x2000,
 	.gsp.intr = tu102_disp_intr,
-	.gsp.head = &tu102_gsp_head,
+	.gsp.head = &gb202_gsp_head,
 	.gsp.hdmi_gcp = gb202_sor_hdmi_gcp,
 	/* The legacy AVI unit is unchanged on GB20x. */
 	.gsp.hdmi_infoframe_avi = gv100_sor_hdmi_infoframe_avi,



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 540/556] drm/nouveau/gsp: fix vblank interrupts on GB20x
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (538 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 539/556] drm/nouveau/disp: fix head state readback " Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 541/556] ksmbd: fix use-after-free in oplock break notification Greg Kroah-Hartman
                   ` (28 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Mohamed Ahmed, Lyude Paul

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mohamed Ahmed <mohamedahmedegypt2001@gmail.com>

commit 5bb489b333237c1bf63a891a4362986253a0060a upstream.

The GSP path programs per-head timing (vblank) interrupts the same way on
every generation. NVD5.0 (GB20x) reworked the FE interrupt frontend
around four message-based kernel vectors (high latency, low latency, PMU,
and GSP) and moved RM head-timing interrupts to the dedicated low-latency
vector:

 - The enable is NV_PDISP_FE_RM_INTR_EN1_HEAD_TIMING, 0x611ef0 +
   head*4 (570.144 kernel_head_0501.c, renamed kernel_head_0502.c from
   575.51.02 on, and v05_01 dev_disp.h).

 - The vector is reported as a separate interrupt table entry,
   MC_ENGINE_IDX_DISP_LOW (intr_gb202.c, intrCacheDispIntrVectors).

 - The vector must be re-armed through NV_PDISP_FE_INTR_RETRIGGER(1)
   at 0x611f34 after servicing (kdispServiceInterrupt ->
   kdispIntrRetrigger_v05_01).

The event latch (0x611800), per-head status (0x611c00), and dispatch
summary (0x611ec0) the interrupt handler uses are unchanged on GB20x
(kheadReadPendingVblank_v03_00 and kheadResetPendingLastData_v03_00
remain for DISPv0502+).

On GB20x the old code enables head timing onto the legacy vector, leaves
its handler there, and never re-arms the message-based vectors. Page
flips still complete (nv50 sends those events from the commit path), so
the desktop looks fine while DRM vblank waits and vblank sequence queries
are affected.

Supply GB20x vblank enables and an interrupt handler that re-arms the
vector after servicing through gb202_gsp_disp, translate the low-latency
interrupt table entry as a second NVKM_ENGINE_DISP instance, and add a
gsp.intr_low_latency flag so r535_disp_oneinit() attaches the handler to
that instance. GB20x was the last cross-file user of the TU1xx vblank
enables, so make those static and drop their head.h prototypes.

Fixes: 6cc6e08d4542 ("drm/nouveau/kms: add support for GB20x")
Cc: stable@vger.kernel.org
Signed-off-by: Mohamed Ahmed <mohamedahmedegypt2001@gmail.com>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260825001408.14219-9-mohamedahmedegypt2001@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/gpu/drm/nouveau/nvkm/engine/disp/gb202.c       |   42 +++++++++++++++--
 drivers/gpu/drm/nouveau/nvkm/engine/disp/head.h        |    2 
 drivers/gpu/drm/nouveau/nvkm/engine/disp/priv.h        |    2 
 drivers/gpu/drm/nouveau/nvkm/engine/disp/tu102.c       |    4 -
 drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/disp.c |   10 +++-
 drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/gsp.c  |    9 +++
 6 files changed, 61 insertions(+), 8 deletions(-)

--- a/drivers/gpu/drm/nouveau/nvkm/engine/disp/gb202.c
+++ b/drivers/gpu/drm/nouveau/nvkm/engine/disp/gb202.c
@@ -124,12 +124,46 @@ gb202_head_state(struct nvkm_head *head,
 	}
 }
 
+/* NVD5.0 (GB20x and later) moved the RM head-timing interrupt enable to
+ * the low-latency vector's EN1 block. The event latch is unchanged.
+ */
+static void
+gb202_head_vblank_put(struct nvkm_head *head)
+{
+	struct nvkm_device *device = head->disp->engine.subdev.device;
+
+	nvkm_mask(device, 0x611ef0 + (head->id * 4), 0x00000002, 0x00000000);
+}
+
+static void
+gb202_head_vblank_get(struct nvkm_head *head)
+{
+	struct nvkm_device *device = head->disp->engine.subdev.device;
+
+	nvkm_wr32(device, 0x611800 + (head->id * 4), 0x00000002);
+	nvkm_mask(device, 0x611ef0 + (head->id * 4), 0x00000002, 0x00000002);
+}
+
+static irqreturn_t
+gb202_disp_intr(struct nvkm_inth *inth)
+{
+	struct nvkm_disp *disp = container_of(inth, typeof(*disp), engine.subdev.inth);
+	irqreturn_t ret = tu102_disp_intr(inth);
+
+	/* The FE interrupt vectors are message-based on NVD5.0. Re-arm the
+	 * low-latency vector so it fires again for any event that latched
+	 * while we were servicing.
+	 */
+	nvkm_wr32(disp->engine.subdev.device, 0x611f34, 0x00000001);
+	return ret;
+}
+
 static const struct nvkm_head_func
 gb202_gsp_head = {
 	.state = gb202_head_state,
 	.rgpos = gv100_head_rgpos,
-	.vblank_get = tu102_head_vblank_get,
-	.vblank_put = tu102_head_vblank_put,
+	.vblank_get = gb202_head_vblank_get,
+	.vblank_put = gb202_head_vblank_put,
 };
 
 /* GB20x is GSP-only. This table supplies the register programming the
@@ -139,7 +173,9 @@ static const struct nvkm_disp_func
 gb202_gsp_disp = {
 	.uevent = &gv100_disp_chan_uevent,
 	.ramht_size = 0x2000,
-	.gsp.intr = tu102_disp_intr,
+	/* Head timing arrives on the dedicated low-latency vector. */
+	.gsp.intr = gb202_disp_intr,
+	.gsp.intr_low_latency = true,
 	.gsp.head = &gb202_gsp_head,
 	.gsp.hdmi_gcp = gb202_sor_hdmi_gcp,
 	/* The legacy AVI unit is unchanged on GB20x. */
--- a/drivers/gpu/drm/nouveau/nvkm/engine/disp/head.h
+++ b/drivers/gpu/drm/nouveau/nvkm/engine/disp/head.h
@@ -56,8 +56,6 @@ int gv100_head_new(struct nvkm_disp *, i
 void gv100_head_state(struct nvkm_head *head, struct nvkm_head_state *state);
 void gv100_head_rgpos(struct nvkm_head *head, u16 *hline, u16 *vline);
 
-void tu102_head_vblank_get(struct nvkm_head *);
-void tu102_head_vblank_put(struct nvkm_head *);
 extern const struct nvkm_head_func tu102_gsp_head;
 
 #define HEAD_MSG(h,l,f,a...) do {                                              \
--- a/drivers/gpu/drm/nouveau/nvkm/engine/disp/priv.h
+++ b/drivers/gpu/drm/nouveau/nvkm/engine/disp/priv.h
@@ -42,6 +42,8 @@ struct nvkm_disp_func {
 	 */
 	struct {
 		irqreturn_t (*intr)(struct nvkm_inth *);
+		/* Head-timing interrupts arrive on a second DISP vector. */
+		bool intr_low_latency;
 		const struct nvkm_head_func *head;
 		void (*hdmi_gcp)(struct nvkm_ior *, int head, bool enable);
 		void (*hdmi_infoframe_avi)(struct nvkm_ior *, int head, void *data, u32 size);
--- a/drivers/gpu/drm/nouveau/nvkm/engine/disp/tu102.c
+++ b/drivers/gpu/drm/nouveau/nvkm/engine/disp/tu102.c
@@ -123,7 +123,7 @@ tu102_sor_new(struct nvkm_disp *disp, in
  * enables to us. These program the RM head-timing line (bit 1 of the
  * per-head enable, not the bit nvkm's own gv100 path uses).
  */
-void
+static void
 tu102_head_vblank_put(struct nvkm_head *head)
 {
 	struct nvkm_device *device = head->disp->engine.subdev.device;
@@ -131,7 +131,7 @@ tu102_head_vblank_put(struct nvkm_head *
 	nvkm_mask(device, 0x611d80 + (head->id * 4), 0x00000002, 0x00000000);
 }
 
-void
+static void
 tu102_head_vblank_get(struct nvkm_head *head)
 {
 	struct nvkm_device *device = head->disp->engine.subdev.device;
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/disp.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r535/disp.c
@@ -1671,7 +1671,15 @@ r535_disp_oneinit(struct nvkm_disp *disp
 	if (ret)
 		return ret;
 
-	ret = nvkm_gsp_intr_stall(gsp, disp->engine.subdev.type, disp->engine.subdev.inst);
+	/* Chips that raise head-timing interrupts on a separate low-latency
+	 * vector report it as a second DISP interrupt table entry, exposed
+	 * as instance 1 by the RM engine-index translation (see
+	 * r570_gsp_xlat_mc_engine_idx()). Their high-latency vector
+	 * (instance 0) is left unhandled as no event nouveau enables is
+	 * routed to it, and without a handler it stays masked.
+	 */
+	ret = nvkm_gsp_intr_stall(gsp, disp->engine.subdev.type,
+				  disp->func->gsp.intr_low_latency ? 1 : disp->engine.subdev.inst);
 	if (ret < 0)
 		return ret;
 
--- a/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/gsp.c
+++ b/drivers/gpu/drm/nouveau/nvkm/subdev/gsp/rm/r570/gsp.c
@@ -44,6 +44,15 @@ r570_gsp_xlat_mc_engine_idx(u32 mc_engin
 		*ptype = NVKM_ENGINE_DISP;
 		*pinst = 0;
 		return true;
+	case MC_ENGINE_IDX_DISP_LOW:
+		/* GB20x+ report a separate low-latency display vector, used
+		 * for head-timing interrupts. Expose it as a second DISP
+		 * interrupt instance. r535_disp_oneinit() attaches the
+		 * handler to it when the chip's gsp.intr_low_latency is set.
+		 */
+		*ptype = NVKM_ENGINE_DISP;
+		*pinst = 1;
+		return true;
 	case MC_ENGINE_IDX_CE0 ... MC_ENGINE_IDX_CE19:
 		*ptype = NVKM_ENGINE_CE;
 		*pinst = mc_engine_idx - MC_ENGINE_IDX_CE0;



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 541/556] ksmbd: fix use-after-free in oplock break notification
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (539 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 540/556] drm/nouveau/gsp: fix vblank interrupts " Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 542/556] bpf: Factor stackid_init function from __bpf_get_stackid Greg Kroah-Hartman
                   ` (27 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Abdifatah Suruur, Namjae Jeon

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Abdifatah Suruur <suruurism@gmail.com>

commit 0e753899627b5e28a9fea8bca98262a6f65a2452 upstream.

smb2_oplock_break_noti() reads opinfo->conn without any lock and
dereferences it after two allocations which may sleep.  When the
durable handle owning the oplock is disconnected, session_fd_check()
clears opinfo->conn and drops its conn reference under ci->m_lock, and
the last ksmbd_conn_put() frees the connection.  A break triggered by
another connection that races with the teardown can then resurrect the
freed connection: ksmbd_conn_get() is a plain atomic_inc, and the
queued break work later dereferences the stale conn via
ksmbd_conn_write(), a use-after-free reachable by any authenticated
client holding a durable batch oplock.

Thread the caller's inode into the notification path instead of taking
a new reference on it.  Every caller of oplock_break() already holds a
live ksmbd_file (or an explicit ksmbd_inode_lookup_lock() reference,
in the parent lease break paths) on the inode that owns the break
target's oplock list, so ci cannot be freed during the call, and its
lock can be taken without dereferencing opinfo->o_fp, which a
concurrent close may free.  Select and pin the connection under
ci->m_lock, the same lock session_fd_check() and
ksmbd_reopen_durable_fd() use to update opinfo->conn, so a concurrent
detach either loses the race to the clear or keeps the connection
alive until the notification work releases it.  Transfer the reference
to the work item and release it on allocation failures.

Fixes: b003086d7696 ("ksmbd: fix NULL-deref of opinfo->conn in oplock/lease break notifiers")
Cc: stable@vger.kernel.org
Signed-off-by: Abdifatah Suruur <suruurism@gmail.com>
Signed-off-by: Namjae Jeon <linkinjeon@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 fs/smb/server/oplock.c |   79 ++++++++++++++++++++++++++++++++++++-------------
 1 file changed, 59 insertions(+), 20 deletions(-)

--- a/fs/smb/server/oplock.c
+++ b/fs/smb/server/oplock.c
@@ -878,31 +878,69 @@ out:
 	ksmbd_conn_put(conn);
 }
 
+/*
+ * Select and pin the connection used for an oplock break before doing any
+ * allocations which may sleep.  The caller of oplock_break() holds a live
+ * reference on ci (a file being opened, a file being operated on, or an
+ * explicit ksmbd_inode_lookup_lock() reference in the parent lease break
+ * paths), so the inode cannot be freed during the call and its lock is
+ * reachable without dereferencing opinfo->o_fp, which is not pinned by
+ * the oplock reference and may be freed by a concurrent close.
+ *
+ * opinfo->conn is cleared under ci->m_lock by session_fd_check() when the
+ * durable handle owning the oplock is disconnected, reassigned by
+ * ksmbd_reopen_durable_fd() under the same lock, and the last
+ * ksmbd_conn_put() of the old connection frees it.  Holding the read lock
+ * excludes both writers, so the connection cannot be freed while it is
+ * selected.
+ */
+static struct ksmbd_conn *smb2_oplock_break_conn_get(struct oplock_info *opinfo,
+						     struct ksmbd_inode *ci)
+{
+	struct ksmbd_conn *conn;
+
+	down_read(&ci->m_lock);
+	conn = READ_ONCE(opinfo->conn);
+	if (conn && !ksmbd_conn_releasing(conn))
+		conn = ksmbd_conn_get(conn);
+	else
+		conn = NULL;
+	up_read(&ci->m_lock);
+
+	return conn;
+}
+
 /**
  * smb2_oplock_break_noti() - send smb2 exclusive/batch to level2 oplock
  *		break command from server to client
  * @opinfo:		oplock info object
+ * @ci:		inode owning the break target's oplock list, pinned by
+ *		the caller
  *
  * Return:      0 on success, otherwise error
  */
-static int smb2_oplock_break_noti(struct oplock_info *opinfo)
+static int smb2_oplock_break_noti(struct oplock_info *opinfo,
+				  struct ksmbd_inode *ci)
 {
 	struct ksmbd_conn *conn;
 	struct oplock_break_info *br_info;
 	int ret = 0;
 	struct ksmbd_work *work;
 
-	conn = READ_ONCE(opinfo->conn);
+	conn = smb2_oplock_break_conn_get(opinfo, ci);
 	if (!conn)
 		return ksmbd_invalidate_durable_fd(opinfo->fid);
 
 	work = ksmbd_alloc_work_struct();
-	if (!work)
+	if (!work) {
+		ksmbd_conn_put(conn);
 		return -ENOMEM;
+	}
 
 	br_info = kmalloc_obj(struct oplock_break_info, KSMBD_DEFAULT_GFP);
 	if (!br_info) {
 		ksmbd_free_work_struct(work);
+		ksmbd_conn_put(conn);
 		return -ENOMEM;
 	}
 
@@ -911,7 +949,8 @@ static int smb2_oplock_break_noti(struct
 	br_info->open_trunc = opinfo->open_trunc;
 
 	work->request_buf = (char *)br_info;
-	work->conn = ksmbd_conn_get(conn);
+	/* Transfer the reference acquired by smb2_oplock_break_conn_get(). */
+	work->conn = conn;
 	work->sess = opinfo->sess;
 
 	ksmbd_conn_r_count_inc(conn);
@@ -1074,9 +1113,9 @@ static void wait_lease_breaking(struct o
 	}
 }
 
-static int oplock_break(struct oplock_info *brk_opinfo, int req_op_level,
-			struct ksmbd_work *in_work, bool share_break)
-{
+static int oplock_break(struct oplock_info *brk_opinfo, struct ksmbd_inode *ci,
+			int req_op_level, struct ksmbd_work *in_work,
+			bool share_break, bool sync_lease_break){
 	int err = 0;
 	bool sent_interim = false;
 
@@ -1196,7 +1235,7 @@ again:
 			brk_opinfo->op_state = OPLOCK_ACK_WAIT;
 	}
 
-	err = smb2_oplock_break_noti(brk_opinfo);
+	err = smb2_oplock_break_noti(brk_opinfo, ci);
 
 	ksmbd_debug(OPLOCK, "oplock granted = %d\n", brk_opinfo->level);
 	if (brk_opinfo->op_state == OPLOCK_CLOSING)
@@ -1224,13 +1263,14 @@ static int oplock_break_add(struct list_
 	return 0;
 }
 
-static void oplock_break_drain_none(struct list_head *head)
+static void oplock_break_drain_none(struct list_head *head,
+				    struct ksmbd_inode *ci)
 {
 	struct oplock_break_entry *ent, *tmp;
 
 	list_for_each_entry_safe(ent, tmp, head, list) {
-		oplock_break(ent->opinfo, SMB2_OPLOCK_LEVEL_NONE, NULL, false);
-		list_del(&ent->list);
+		oplock_break(ent->opinfo, ci, SMB2_OPLOCK_LEVEL_NONE, NULL,
+			     false, false);		list_del(&ent->list);
 		opinfo_put(ent->opinfo);
 		kfree(ent);
 	}
@@ -1377,7 +1417,7 @@ void smb_send_parent_lease_break_noti(st
 	}
 	up_read(&p_ci->m_lock);
 
-	oplock_break_drain_none(&brk_list);
+	oplock_break_drain_none(&brk_list, p_ci);
 
 	ksmbd_inode_put(p_ci);
 }
@@ -1421,7 +1461,7 @@ void smb_lazy_parent_lease_break_close(s
 	}
 	up_read(&p_ci->m_lock);
 
-	oplock_break_drain_none(&brk_list);
+	oplock_break_drain_none(&brk_list, p_ci);
 
 	ksmbd_inode_put(p_ci);
 }
@@ -1541,9 +1581,8 @@ int smb_grant_oplock(struct ksmbd_work *
 	prev_durable_detached = prev_op_snapshot.durable_detached;
 	prev_fid = prev_op_snapshot.fid;
 
-	err = oplock_break(prev_opinfo, break_level, work,
-			   share_ret < 0 && prev_opinfo->is_lease);
-	if (prev_durable_detached || (prev_durable_open && err == -ENOENT))
+	err = oplock_break(prev_opinfo, ci, break_level, work,
+			   share_ret < 0 && prev_opinfo->is_lease, false);	if (prev_durable_detached || (prev_durable_open && err == -ENOENT))
 		ksmbd_invalidate_durable_fd(prev_fid);
 	opinfo_put(prev_opinfo);
 	if (err == -EAGAIN) {
@@ -1640,8 +1679,8 @@ static bool smb_break_all_write_oplock(s
 	}
 
 	brk_opinfo->open_trunc = is_trunc;
-	oplock_break(brk_opinfo, SMB2_OPLOCK_LEVEL_II, work, false);
-	sent_break = true;
+	oplock_break(brk_opinfo, fp->f_ci, SMB2_OPLOCK_LEVEL_II, work, false,
+		     false);	sent_break = true;
 	opinfo_put(brk_opinfo);
 
 	return sent_break;
@@ -1727,11 +1766,11 @@ next:
 			brk_op->level = SMB2_OPLOCK_LEVEL_NONE;
 			brk_op->op_state = OPLOCK_STATE_NONE;
 		} else {
-			oplock_break(brk_op,
+			oplock_break(brk_op, ci,
 				     brk_op->is_lease && !is_trunc ?
 				     SMB2_OPLOCK_LEVEL_II : SMB2_OPLOCK_LEVEL_NONE,
 				     send_interim && !sent_interim ? work : NULL,
-				     false);
+				     false, false);
 		}
 		sent_interim = true;
 		list_del(&ent->list);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 542/556] bpf: Factor stackid_init function from __bpf_get_stackid
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (540 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 541/556] ksmbd: fix use-after-free in oplock break notification Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 543/556] bpf: Factor stackid_fastpath " Greg Kroah-Hartman
                   ` (26 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jiri Olsa, Andrii Nakryiko,
	Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jiri Olsa <jolsa@kernel.org>

[ Upstream commit 15b837759a97237d647962f9943afe0d55af615a ]

The new stackid_init function stores all the necessary bits for stackid
trace and it will be used by other functions in following changes.

Signed-off-by: Jiri Olsa <jolsa@kernel.org>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Link: https://lore.kernel.org/bpf/20260803210149.296496-2-jolsa@kernel.org
Stable-dep-of: 15f1bd857466 ("bpf: Disable preemption in bpf_get_stackid")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 kernel/bpf/stackmap.c |   95 +++++++++++++++++++++++++++++++-------------------
 1 file changed, 59 insertions(+), 36 deletions(-)

--- a/kernel/bpf/stackmap.c
+++ b/kernel/bpf/stackmap.c
@@ -504,33 +504,54 @@ get_callchain_entry_for_task(struct task
 #endif
 }
 
-static long __bpf_get_stackid(struct bpf_map *map,
-			      struct perf_callchain_entry *trace, u64 flags)
+struct stackid {
+	struct stack_map_bucket *bucket;
+	u64 *ips;
+	u32  nr;
+	u32  len;
+	u32  hash;
+	u32  id;
+};
+
+static int stackid_init(struct stackid *stackid, struct bpf_map *map,
+			struct perf_callchain_entry *trace, u64 flags)
 {
 	struct bpf_stack_map *smap = container_of(map, struct bpf_stack_map, map);
-	struct stack_map_bucket *bucket, *new_bucket, *old_bucket;
-	u32 hash, id, trace_nr, trace_len, i, max_depth;
 	u32 skip = flags & BPF_F_SKIP_FIELD_MASK;
-	bool user = flags & BPF_F_USER_STACK;
-	u64 *ips;
-	bool hash_matches;
+	u32 max_depth;
 
 	if (trace->nr <= skip)
 		/* skipping more than usable stack trace */
 		return -EFAULT;
 
 	max_depth = stack_map_calculate_max_depth(map->value_size, stack_map_data_size(map), flags);
-	trace_nr = min_t(u32, trace->nr - skip, max_depth - skip);
-	trace_len = trace_nr * sizeof(u64);
-	ips = trace->ip + skip;
-	hash = jhash2((u32 *)ips, trace_len / sizeof(u32), 0);
-	id = hash & (smap->n_buckets - 1);
-	bucket = READ_ONCE(smap->buckets[id]);
+	stackid->nr = min_t(u32, trace->nr - skip, max_depth - skip);
+	stackid->len = stackid->nr * sizeof(u64);
+	stackid->ips = trace->ip + skip;
+	stackid->hash = jhash2((u32 *)stackid->ips, stackid->len / sizeof(u32), 0);
+	stackid->id = stackid->hash & (smap->n_buckets - 1);
+	stackid->bucket = READ_ONCE(smap->buckets[stackid->id]);
+	return 0;
+}
+
+static long __bpf_get_stackid(struct stackid *stackid, struct bpf_map *map,
+			      struct perf_callchain_entry *trace, u64 flags)
+{
+	struct bpf_stack_map *smap = container_of(map, struct bpf_stack_map, map);
+	struct stack_map_bucket *new_bucket, *old_bucket;
+	bool user = flags & BPF_F_USER_STACK;
+	bool hash_matches;
+	u32 trace_len, i;
+	int err;
+
+	err = stackid_init(stackid, map, trace, flags);
+	if (err)
+		return err;
 
-	hash_matches = bucket && bucket->hash == hash;
+	hash_matches = stackid->bucket && stackid->bucket->hash == stackid->hash;
 	/* fast cmp */
 	if (hash_matches && flags & BPF_F_FAST_STACK_CMP)
-		return id;
+		return stackid->id;
 
 	if (stack_map_use_build_id(map)) {
 		struct bpf_stack_build_id *id_offs;
@@ -540,42 +561,42 @@ static long __bpf_get_stackid(struct bpf
 			pcpu_freelist_pop(&smap->freelist);
 		if (unlikely(!new_bucket))
 			return -ENOMEM;
-		new_bucket->nr = trace_nr;
+		new_bucket->nr = stackid->nr;
 		id_offs = (struct bpf_stack_build_id *)new_bucket->data;
-		for (i = 0; i < trace_nr; i++)
-			id_offs[i].ip = ips[i];
-		stack_map_get_build_id_offset(id_offs, trace_nr, user, false /* !may_fault */);
-		trace_len = trace_nr * sizeof(struct bpf_stack_build_id);
-		if (hash_matches && bucket->nr == trace_nr &&
-		    memcmp(bucket->data, new_bucket->data, trace_len) == 0) {
+		for (i = 0; i < stackid->nr; i++)
+			id_offs[i].ip = stackid->ips[i];
+		stack_map_get_build_id_offset(id_offs, stackid->nr, user, false /* !may_fault */);
+		trace_len = stackid->nr * sizeof(struct bpf_stack_build_id);
+		if (hash_matches && stackid->bucket->nr == stackid->nr &&
+		    memcmp(stackid->bucket->data, new_bucket->data, trace_len) == 0) {
 			pcpu_freelist_push(&smap->freelist, &new_bucket->fnode);
-			return id;
+			return stackid->id;
 		}
-		if (bucket && !(flags & BPF_F_REUSE_STACKID)) {
+		if (stackid->bucket && !(flags & BPF_F_REUSE_STACKID)) {
 			pcpu_freelist_push(&smap->freelist, &new_bucket->fnode);
 			return -EEXIST;
 		}
 	} else {
-		if (hash_matches && bucket->nr == trace_nr &&
-		    memcmp(bucket->data, ips, trace_len) == 0)
-			return id;
-		if (bucket && !(flags & BPF_F_REUSE_STACKID))
+		if (hash_matches && stackid->bucket->nr == stackid->nr &&
+		    memcmp(stackid->bucket->data, stackid->ips, stackid->len) == 0)
+			return stackid->id;
+		if (stackid->bucket && !(flags & BPF_F_REUSE_STACKID))
 			return -EEXIST;
 
 		new_bucket = (struct stack_map_bucket *)
 			pcpu_freelist_pop(&smap->freelist);
 		if (unlikely(!new_bucket))
 			return -ENOMEM;
-		memcpy(new_bucket->data, ips, trace_len);
+		memcpy(new_bucket->data, stackid->ips, stackid->len);
 	}
 
-	new_bucket->hash = hash;
-	new_bucket->nr = trace_nr;
+	new_bucket->hash = stackid->hash;
+	new_bucket->nr = stackid->nr;
 
-	old_bucket = xchg(&smap->buckets[id], new_bucket);
+	old_bucket = xchg(&smap->buckets[stackid->id], new_bucket);
 	if (old_bucket)
 		pcpu_freelist_push(&smap->freelist, &old_bucket->fnode);
-	return id;
+	return stackid->id;
 }
 
 BPF_CALL_3(bpf_get_stackid, struct pt_regs *, regs, struct bpf_map *, map,
@@ -584,6 +605,7 @@ BPF_CALL_3(bpf_get_stackid, struct pt_re
 	u32 elem_size = stack_map_data_size(map);
 	bool user = flags & BPF_F_USER_STACK;
 	struct perf_callchain_entry *trace;
+	struct stackid stackid;
 	bool kernel = !user;
 	u32 max_depth;
 
@@ -599,7 +621,7 @@ BPF_CALL_3(bpf_get_stackid, struct pt_re
 		/* couldn't fetch the stack trace */
 		return -EFAULT;
 
-	return __bpf_get_stackid(map, trace, flags);
+	return __bpf_get_stackid(&stackid, map, trace, flags);
 }
 
 const struct bpf_func_proto bpf_get_stackid_proto = {
@@ -628,6 +650,7 @@ BPF_CALL_3(bpf_get_stackid_pe, struct bp
 {
 	struct perf_event *event = ctx->event;
 	struct perf_callchain_entry *trace;
+	struct stackid stackid;
 	bool kernel, user;
 	__u64 nr_kernel;
 	int ret;
@@ -653,7 +676,7 @@ BPF_CALL_3(bpf_get_stackid_pe, struct bp
 
 	if (kernel) {
 		trace->nr = nr_kernel;
-		ret = __bpf_get_stackid(map, trace, flags);
+		ret = __bpf_get_stackid(&stackid, map, trace, flags);
 	} else { /* user */
 		u64 skip = flags & BPF_F_SKIP_FIELD_MASK;
 
@@ -662,7 +685,7 @@ BPF_CALL_3(bpf_get_stackid_pe, struct bp
 			return -EFAULT;
 
 		flags = (flags & ~BPF_F_SKIP_FIELD_MASK) | skip;
-		ret = __bpf_get_stackid(map, trace, flags);
+		ret = __bpf_get_stackid(&stackid, map, trace, flags);
 	}
 
 	/* restore nr */



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 543/556] bpf: Factor stackid_fastpath function from __bpf_get_stackid
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (541 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 542/556] bpf: Factor stackid_init function from __bpf_get_stackid Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 544/556] bpf: Factor stackid_new_bucket " Greg Kroah-Hartman
                   ` (25 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jiri Olsa, Andrii Nakryiko,
	Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jiri Olsa <jolsa@kernel.org>

[ Upstream commit 0ca56befcffec3a6c9d1842eae06c74e1cf41f11 ]

The new stackid_fastpath does the fast stack hash and trace check, that
does not need new bucket allocation. It covers both just-ip and buildid
code paths.

Signed-off-by: Jiri Olsa <jolsa@kernel.org>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Link: https://lore.kernel.org/bpf/20260803210149.296496-3-jolsa@kernel.org
Stable-dep-of: 15f1bd857466 ("bpf: Disable preemption in bpf_get_stackid")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 kernel/bpf/stackmap.c |   43 ++++++++++++++++++++++++++++---------------
 1 file changed, 28 insertions(+), 15 deletions(-)

--- a/kernel/bpf/stackmap.c
+++ b/kernel/bpf/stackmap.c
@@ -511,6 +511,7 @@ struct stackid {
 	u32  len;
 	u32  hash;
 	u32  id;
+	bool hash_matches;
 };
 
 static int stackid_init(struct stackid *stackid, struct bpf_map *map,
@@ -531,28 +532,46 @@ static int stackid_init(struct stackid *
 	stackid->hash = jhash2((u32 *)stackid->ips, stackid->len / sizeof(u32), 0);
 	stackid->id = stackid->hash & (smap->n_buckets - 1);
 	stackid->bucket = READ_ONCE(smap->buckets[stackid->id]);
+	stackid->hash_matches = stackid->bucket && stackid->bucket->hash == stackid->hash;
 	return 0;
 }
 
+static int stackid_fastpath(struct stackid *stackid, struct bpf_map *map,
+			    struct perf_callchain_entry *trace, u64 flags)
+{
+	int err;
+
+	err = stackid_init(stackid, map, trace, flags);
+	if (err)
+		return err;
+
+	/* fast cmp */
+	if (stackid->hash_matches && flags & BPF_F_FAST_STACK_CMP)
+		return stackid->id;
+
+	if (stack_map_use_build_id(map))
+		return -ENOENT;
+	if (stackid->hash_matches && stackid->bucket->nr == stackid->nr &&
+	    memcmp(stackid->bucket->data, stackid->ips, stackid->len) == 0)
+		return stackid->id;
+	if (stackid->bucket && !(flags & BPF_F_REUSE_STACKID))
+		return -EEXIST;
+	return -ENOENT;
+}
+
 static long __bpf_get_stackid(struct stackid *stackid, struct bpf_map *map,
 			      struct perf_callchain_entry *trace, u64 flags)
 {
 	struct bpf_stack_map *smap = container_of(map, struct bpf_stack_map, map);
 	struct stack_map_bucket *new_bucket, *old_bucket;
 	bool user = flags & BPF_F_USER_STACK;
-	bool hash_matches;
 	u32 trace_len, i;
 	int err;
 
-	err = stackid_init(stackid, map, trace, flags);
-	if (err)
+	err = stackid_fastpath(stackid, map, trace, flags);
+	if (err != -ENOENT)
 		return err;
 
-	hash_matches = stackid->bucket && stackid->bucket->hash == stackid->hash;
-	/* fast cmp */
-	if (hash_matches && flags & BPF_F_FAST_STACK_CMP)
-		return stackid->id;
-
 	if (stack_map_use_build_id(map)) {
 		struct bpf_stack_build_id *id_offs;
 
@@ -567,7 +586,7 @@ static long __bpf_get_stackid(struct sta
 			id_offs[i].ip = stackid->ips[i];
 		stack_map_get_build_id_offset(id_offs, stackid->nr, user, false /* !may_fault */);
 		trace_len = stackid->nr * sizeof(struct bpf_stack_build_id);
-		if (hash_matches && stackid->bucket->nr == stackid->nr &&
+		if (stackid->hash_matches && stackid->bucket->nr == stackid->nr &&
 		    memcmp(stackid->bucket->data, new_bucket->data, trace_len) == 0) {
 			pcpu_freelist_push(&smap->freelist, &new_bucket->fnode);
 			return stackid->id;
@@ -577,12 +596,6 @@ static long __bpf_get_stackid(struct sta
 			return -EEXIST;
 		}
 	} else {
-		if (hash_matches && stackid->bucket->nr == stackid->nr &&
-		    memcmp(stackid->bucket->data, stackid->ips, stackid->len) == 0)
-			return stackid->id;
-		if (stackid->bucket && !(flags & BPF_F_REUSE_STACKID))
-			return -EEXIST;
-
 		new_bucket = (struct stack_map_bucket *)
 			pcpu_freelist_pop(&smap->freelist);
 		if (unlikely(!new_bucket))



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 544/556] bpf: Factor stackid_new_bucket from __bpf_get_stackid
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (542 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 543/556] bpf: Factor stackid_fastpath " Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 545/556] bpf: Use stack id functions instead of __bpf_get_stackid Greg Kroah-Hartman
                   ` (24 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jiri Olsa, Andrii Nakryiko,
	Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jiri Olsa <jolsa@kernel.org>

[ Upstream commit bb4e6f4e1b68fe60c04ca04c564c6624e837dbf4 ]

The new stackid_new_bucket allocates the new bucket and initializes it
with the trace data.

Signed-off-by: Jiri Olsa <jolsa@kernel.org>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Link: https://lore.kernel.org/bpf/20260803210149.296496-4-jolsa@kernel.org
Stable-dep-of: 15f1bd857466 ("bpf: Disable preemption in bpf_get_stackid")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 kernel/bpf/stackmap.c |   48 ++++++++++++++++++++++++++++++------------------
 1 file changed, 30 insertions(+), 18 deletions(-)

--- a/kernel/bpf/stackmap.c
+++ b/kernel/bpf/stackmap.c
@@ -559,31 +559,52 @@ static int stackid_fastpath(struct stack
 	return -ENOENT;
 }
 
+static struct stack_map_bucket *
+stackid_new_bucket(struct stackid *stackid, struct bpf_map *map)
+{
+	struct bpf_stack_map *smap = container_of(map, struct bpf_stack_map, map);
+	struct bpf_stack_build_id *id_offs;
+	struct stack_map_bucket *bucket;
+	u32 i;
+
+	bucket = (struct stack_map_bucket *) pcpu_freelist_pop(&smap->freelist);
+	if (unlikely(!bucket))
+		return NULL;
+
+	if (stack_map_use_build_id(map)) {
+		id_offs = (struct bpf_stack_build_id *)bucket->data;
+		for (i = 0; i < stackid->nr; i++)
+			id_offs[i].ip = stackid->ips[i];
+	} else {
+		memcpy(bucket->data, stackid->ips, stackid->len);
+	}
+
+	bucket->hash = stackid->hash;
+	bucket->nr = stackid->nr;
+	return bucket;
+}
+
 static long __bpf_get_stackid(struct stackid *stackid, struct bpf_map *map,
 			      struct perf_callchain_entry *trace, u64 flags)
 {
 	struct bpf_stack_map *smap = container_of(map, struct bpf_stack_map, map);
 	struct stack_map_bucket *new_bucket, *old_bucket;
 	bool user = flags & BPF_F_USER_STACK;
-	u32 trace_len, i;
+	u32 trace_len;
 	int err;
 
 	err = stackid_fastpath(stackid, map, trace, flags);
 	if (err != -ENOENT)
 		return err;
 
+	new_bucket = stackid_new_bucket(stackid, map);
+	if (!new_bucket)
+		return -ENOMEM;
+
 	if (stack_map_use_build_id(map)) {
 		struct bpf_stack_build_id *id_offs;
 
-		/* for build_id+offset, pop a bucket before slow cmp */
-		new_bucket = (struct stack_map_bucket *)
-			pcpu_freelist_pop(&smap->freelist);
-		if (unlikely(!new_bucket))
-			return -ENOMEM;
-		new_bucket->nr = stackid->nr;
 		id_offs = (struct bpf_stack_build_id *)new_bucket->data;
-		for (i = 0; i < stackid->nr; i++)
-			id_offs[i].ip = stackid->ips[i];
 		stack_map_get_build_id_offset(id_offs, stackid->nr, user, false /* !may_fault */);
 		trace_len = stackid->nr * sizeof(struct bpf_stack_build_id);
 		if (stackid->hash_matches && stackid->bucket->nr == stackid->nr &&
@@ -595,17 +616,8 @@ static long __bpf_get_stackid(struct sta
 			pcpu_freelist_push(&smap->freelist, &new_bucket->fnode);
 			return -EEXIST;
 		}
-	} else {
-		new_bucket = (struct stack_map_bucket *)
-			pcpu_freelist_pop(&smap->freelist);
-		if (unlikely(!new_bucket))
-			return -ENOMEM;
-		memcpy(new_bucket->data, stackid->ips, stackid->len);
 	}
 
-	new_bucket->hash = stackid->hash;
-	new_bucket->nr = stackid->nr;
-
 	old_bucket = xchg(&smap->buckets[stackid->id], new_bucket);
 	if (old_bucket)
 		pcpu_freelist_push(&smap->freelist, &old_bucket->fnode);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 545/556] bpf: Use stack id functions instead of __bpf_get_stackid
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (543 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 544/556] bpf: Factor stackid_new_bucket " Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 546/556] bpf: Disable preemption in bpf_get_stackid Greg Kroah-Hartman
                   ` (23 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Jiri Olsa, Andrii Nakryiko,
	Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jiri Olsa <jolsa@kernel.org>

[ Upstream commit 09b3fd6caa0b57f8a39254ee5db3af30bdd53c18 ]

Replacing __bpf_get_stackid calls with sequence of following functions:

  stackid_fastpath
  stackid_new_bucket
  stackid_install

This makes code more structured and allows us to easily disable
preemption only in bpf_get_stackid in following changes.

Signed-off-by: Jiri Olsa <jolsa@kernel.org>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Link: https://lore.kernel.org/bpf/20260803210149.296496-5-jolsa@kernel.org
Stable-dep-of: 15f1bd857466 ("bpf: Disable preemption in bpf_get_stackid")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 kernel/bpf/stackmap.c |   43 +++++++++++++++++++++++++++----------------
 1 file changed, 27 insertions(+), 16 deletions(-)

--- a/kernel/bpf/stackmap.c
+++ b/kernel/bpf/stackmap.c
@@ -584,22 +584,13 @@ stackid_new_bucket(struct stackid *stack
 	return bucket;
 }
 
-static long __bpf_get_stackid(struct stackid *stackid, struct bpf_map *map,
-			      struct perf_callchain_entry *trace, u64 flags)
+static long stackid_install(struct stackid *stackid, struct bpf_map *map,
+			    struct stack_map_bucket *new_bucket, u64 flags)
 {
 	struct bpf_stack_map *smap = container_of(map, struct bpf_stack_map, map);
-	struct stack_map_bucket *new_bucket, *old_bucket;
 	bool user = flags & BPF_F_USER_STACK;
+	struct stack_map_bucket *old_bucket;
 	u32 trace_len;
-	int err;
-
-	err = stackid_fastpath(stackid, map, trace, flags);
-	if (err != -ENOENT)
-		return err;
-
-	new_bucket = stackid_new_bucket(stackid, map);
-	if (!new_bucket)
-		return -ENOMEM;
 
 	if (stack_map_use_build_id(map)) {
 		struct bpf_stack_build_id *id_offs;
@@ -629,10 +620,12 @@ BPF_CALL_3(bpf_get_stackid, struct pt_re
 {
 	u32 elem_size = stack_map_data_size(map);
 	bool user = flags & BPF_F_USER_STACK;
+	struct stack_map_bucket *new_bucket;
 	struct perf_callchain_entry *trace;
 	struct stackid stackid;
 	bool kernel = !user;
 	u32 max_depth;
+	int err;
 
 	if (unlikely(flags & ~(BPF_F_SKIP_FIELD_MASK | BPF_F_USER_STACK |
 			       BPF_F_FAST_STACK_CMP | BPF_F_REUSE_STACKID)))
@@ -646,7 +639,15 @@ BPF_CALL_3(bpf_get_stackid, struct pt_re
 		/* couldn't fetch the stack trace */
 		return -EFAULT;
 
-	return __bpf_get_stackid(&stackid, map, trace, flags);
+	err = stackid_fastpath(&stackid, map, trace, flags);
+	if (err != -ENOENT)
+		return err;
+
+	new_bucket = stackid_new_bucket(&stackid, map);
+	if (!new_bucket)
+		return -ENOMEM;
+
+	return stackid_install(&stackid, map, new_bucket, flags);
 }
 
 const struct bpf_func_proto bpf_get_stackid_proto = {
@@ -674,6 +675,7 @@ BPF_CALL_3(bpf_get_stackid_pe, struct bp
 	   struct bpf_map *, map, u64, flags)
 {
 	struct perf_event *event = ctx->event;
+	struct stack_map_bucket *new_bucket;
 	struct perf_callchain_entry *trace;
 	struct stackid stackid;
 	bool kernel, user;
@@ -701,7 +703,6 @@ BPF_CALL_3(bpf_get_stackid_pe, struct bp
 
 	if (kernel) {
 		trace->nr = nr_kernel;
-		ret = __bpf_get_stackid(&stackid, map, trace, flags);
 	} else { /* user */
 		u64 skip = flags & BPF_F_SKIP_FIELD_MASK;
 
@@ -710,12 +711,22 @@ BPF_CALL_3(bpf_get_stackid_pe, struct bp
 			return -EFAULT;
 
 		flags = (flags & ~BPF_F_SKIP_FIELD_MASK) | skip;
-		ret = __bpf_get_stackid(&stackid, map, trace, flags);
 	}
 
+	ret = stackid_fastpath(&stackid, map, trace, flags);
+	if (ret != -ENOENT)
+		goto out;
+
+	new_bucket = stackid_new_bucket(&stackid, map);
+	if (new_bucket) {
+		trace->nr = nr;
+		return stackid_install(&stackid, map, new_bucket, flags);
+	}
+	ret = -ENOMEM;
+
+out:
 	/* restore nr */
 	trace->nr = nr;
-
 	return ret;
 }
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 546/556] bpf: Disable preemption in bpf_get_stackid
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (544 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 545/556] bpf: Use stack id functions instead of __bpf_get_stackid Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 547/556] rpcrdma: arm rn_done before publishing the notification Greg Kroah-Hartman
                   ` (22 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Tao Chen, Jiri Olsa, Andrii Nakryiko,
	Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Jiri Olsa <jolsa@kernel.org>

[ Upstream commit 15f1bd8574662f1b7b26aaa2e23ebf4066f0117d ]

The get_perf_callchain call needs disabled preemption plus we need
it disabled as long as we access its returned trace entries buffer.

Note the bpf_get_stackid_pe function is executed already with
preemption disabled.

Fixes: d5a3b1f69186 ("bpf: introduce BPF_MAP_TYPE_STACK_TRACE")
Reported-by: Tao Chen <chen.dylane@linux.dev>
Signed-off-by: Jiri Olsa <jolsa@kernel.org>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Cc: stable@vger.kernel.org
Link: https://lore.kernel.org/bpf/20260803210149.296496-6-jolsa@kernel.org

Closes: https://lore.kernel.org/bpf/20260206090653.1336687-2-chen.dylane@linux.dev/
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 kernel/bpf/stackmap.c |   24 +++++++++++++-----------
 1 file changed, 13 insertions(+), 11 deletions(-)

--- a/kernel/bpf/stackmap.c
+++ b/kernel/bpf/stackmap.c
@@ -632,20 +632,22 @@ BPF_CALL_3(bpf_get_stackid, struct pt_re
 		return -EINVAL;
 
 	max_depth = stack_map_calculate_max_depth(map->value_size, elem_size, flags);
-	trace = get_perf_callchain(regs, kernel, user, max_depth,
-				   false, false, 0);
 
-	if (unlikely(!trace))
-		/* couldn't fetch the stack trace */
-		return -EFAULT;
+	scoped_guard(preempt) {
+		trace = get_perf_callchain(regs, kernel, user, max_depth,
+					   false, false, 0);
+		if (unlikely(!trace))
+			/* couldn't fetch the stack trace */
+			return -EFAULT;
 
-	err = stackid_fastpath(&stackid, map, trace, flags);
-	if (err != -ENOENT)
-		return err;
+		err = stackid_fastpath(&stackid, map, trace, flags);
+		if (err != -ENOENT)
+			return err;
 
-	new_bucket = stackid_new_bucket(&stackid, map);
-	if (!new_bucket)
-		return -ENOMEM;
+		new_bucket = stackid_new_bucket(&stackid, map);
+		if (!new_bucket)
+			return -ENOMEM;
+	}
 
 	return stackid_install(&stackid, map, new_bucket, flags);
 }



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 547/556] rpcrdma: arm rn_done before publishing the notification
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (545 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 546/556] bpf: Disable preemption in bpf_get_stackid Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 548/556] remoteproc: qcom: pas: Guard dtb metadata release with dtb_pas_id check Greg Kroah-Hartman
                   ` (21 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, Chuck Lever, Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Chuck Lever <chuck.lever@oracle.com>

[ Upstream commit 5b06f706374c37375bdff9d21cc10e61df925a92 ]

rpcrdma_rn_register() inserts @rn into rd_xa with xa_alloc() before
storing the caller's callback in rn->rn_done. The xarray makes @rn
reachable to rpcrdma_remove_one(), which walks rd_xa and invokes
rn->rn_done(rn) for every registered notification. A device removal
that races a fresh registration can therefore observe @rn with
rn_done still NULL, because the notification objects are zero
allocated by their owners, and call through a NULL function pointer.

Store rn->rn_done before xa_alloc() publishes @rn. The xarray's
store-side and load-side ordering then guarantees that any CPU which
finds @rn in rd_xa also observes the armed callback.

rpcrdma_rn_unregister() treats a non-NULL rn_done as the sentinel
for a completed registration, so the early store must not survive a
failed registration. Clear rn_done again when xa_alloc() fails.
Were it left set, the failed-accept cleanup path would call
rpcrdma_rn_unregister() on an @rn that was never inserted, erasing
an unrelated rd_xa slot and underflowing rd_kref.

Fixes: 7e86845a0346 ("rpcrdma: Implement generic device removal")
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260601201703.46078-1-cel@kernel.org
Signed-off-by: Chuck Lever <chuck.lever@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/sunrpc/xprtrdma/ib_client.c |   24 ++++++++++++++++++------
 1 file changed, 18 insertions(+), 6 deletions(-)

--- a/net/sunrpc/xprtrdma/ib_client.c
+++ b/net/sunrpc/xprtrdma/ib_client.c
@@ -52,8 +52,8 @@ static struct rpcrdma_device *rpcrdma_ge
  * is unregistered first.
  *
  * On failure, a negative errno is returned. rn->rn_done is left
- * NULL on every failure path (it is assigned only after xa_alloc
- * and kref_get have both succeeded), so the @rn may safely be
+ * NULL on every failure path (it is armed before xa_alloc but
+ * cleared again if xa_alloc fails), so the @rn may safely be
  * passed to rpcrdma_rn_unregister() without a separate
  * registered/unregistered flag in the caller.
  */
@@ -66,10 +66,21 @@ int rpcrdma_rn_register(struct ib_device
 	if (!rd || test_bit(RPCRDMA_RD_F_REMOVING, &rd->rd_flags))
 		return -ENETUNREACH;
 
-	if (xa_alloc(&rd->rd_xa, &rn->rn_index, rn, xa_limit_32b, GFP_KERNEL) < 0)
+	/*
+	 * Arm rn_done before xa_alloc() publishes @rn: once @rn is
+	 * visible in rd_xa, a concurrent rpcrdma_remove_one() can
+	 * call rn->rn_done(), so the pointer must already be set.
+	 *
+	 * Restore NULL if xa_alloc() fails. rn_done doubles as the
+	 * registration sentinel for rpcrdma_rn_unregister(); a stale
+	 * value would unregister an @rn that was never inserted.
+	 */
+	rn->rn_done = done;
+	if (xa_alloc(&rd->rd_xa, &rn->rn_index, rn, xa_limit_32b, GFP_KERNEL) < 0) {
+		rn->rn_done = NULL;
 		return -ENOMEM;
+	}
 	kref_get(&rd->rd_kref);
-	rn->rn_done = done;
 	trace_rpcrdma_client_register(device, rn);
 	return 0;
 }
@@ -102,8 +113,9 @@ void rpcrdma_rn_unregister(struct ib_dev
 
 	/*
 	 * rn_done is the registration sentinel: rpcrdma_rn_register
-	 * assigns it last, after xa_alloc and kref_get have both
-	 * succeeded. A NULL rn_done means this notification was
+	 * leaves it NULL on every failure path, clearing it again if
+	 * xa_alloc fails, so a non-NULL rn_done marks a completed
+	 * registration. A NULL rn_done means this notification was
 	 * never registered (or its registration failed) or has
 	 * already been unregistered, and the call is a no-op.
 	 * Without this guard, rn_index == 0 from a kzalloc'd



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 548/556] remoteproc: qcom: pas: Guard dtb metadata release with dtb_pas_id check
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (546 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 547/556] rpcrdma: arm rn_done before publishing the notification Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 549/556] power: supply: ab8500_fg: Remove redundant dev_err()/dev_err_probe() Greg Kroah-Hartman
                   ` (20 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Dmitry Baryshkov,
	Mukesh Ojha, Bjorn Andersson, Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>

[ Upstream commit c06c5ab4945392d2c2aded6d832ab6b58cabe351 ]

All other call sites of qcom_scm_pas_metadata_release() for the DTB
context are guarded by a check on pas->dtb_pas_id, but the call inside
qcom_pas_load() was not. Fix this by moving the call to the guarded
block.

Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Fixes: 29814986b82e ("remoteproc: qcom_q6v5_pas: add support for dtb co-firmware loading")
Cc: stable@vger.kernel.org
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260724182858.1868271-3-mukesh.ojha@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
[ changed qcom_pas_metadata_release() to qcom_scm_pas_metadata_release() for the older branch API. ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/remoteproc/qcom_q6v5_pas.c |   13 +++++--------
 1 file changed, 5 insertions(+), 8 deletions(-)

--- a/drivers/remoteproc/qcom_q6v5_pas.c
+++ b/drivers/remoteproc/qcom_q6v5_pas.c
@@ -240,17 +240,14 @@ static int qcom_pas_load(struct rproc *r
 		ret = qcom_mdt_pas_load(pas->dtb_pas_ctx, pas->dtb_firmware,
 					pas->dtb_firmware_name, pas->dtb_mem_region,
 					&pas->dtb_mem_reloc);
-		if (ret)
-			goto release_dtb_metadata;
+		if (ret) {
+			qcom_scm_pas_metadata_release(pas->dtb_pas_ctx);
+			release_firmware(pas->dtb_firmware);
+			return ret;
+		}
 	}
 
 	return 0;
-
-release_dtb_metadata:
-	qcom_scm_pas_metadata_release(pas->dtb_pas_ctx);
-	release_firmware(pas->dtb_firmware);
-
-	return ret;
 }
 
 static void qcom_pas_unmap_carveout(struct rproc *rproc, phys_addr_t mem_phys, size_t size)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 549/556] power: supply: ab8500_fg: Remove redundant dev_err()/dev_err_probe()
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (547 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 548/556] remoteproc: qcom: pas: Guard dtb metadata release with dtb_pas_id check Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 550/556] power: supply: ab8500_fg: fix use-after-free on remove Greg Kroah-Hartman
                   ` (19 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Pan Chuang, Linus Walleij,
	Sebastian Reichel, Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Pan Chuang <panchuang@vivo.com>

[ Upstream commit aa5f4decedfb4fc5cd0fe49ab256ad4304d192e4 ]

The devm_request_threaded_irq() and devm_request_irq() now automatically
log detailed error messages on failure. This eliminates the need for
driver-specific dev_err() and dev_err_probe() calls that previously
printed generic messages.

Signed-off-by: Pan Chuang <panchuang@vivo.com>
Reviewed-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260709033428.362970-7-panchuang@vivo.com
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
Stable-dep-of: 75b1e88d3425 ("power: supply: ab8500_fg: fix use-after-free on remove")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/power/supply/ab8500_fg.c |    2 --
 1 file changed, 2 deletions(-)

--- a/drivers/power/supply/ab8500_fg.c
+++ b/drivers/power/supply/ab8500_fg.c
@@ -3178,8 +3178,6 @@ static int ab8500_fg_probe(struct platfo
 				  ab8500_fg_irq[i].name, di);
 
 		if (ret != 0) {
-			dev_err(dev, "failed to request %s IRQ %d: %d\n",
-				ab8500_fg_irq[i].name, irq, ret);
 			destroy_workqueue(di->fg_wq);
 			return ret;
 		}



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 550/556] power: supply: ab8500_fg: fix use-after-free on remove
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (548 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 549/556] power: supply: ab8500_fg: Remove redundant dev_err()/dev_err_probe() Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 551/556] mm/damon/core: avoid infinite kdamond_merge_regions() internal loop Greg Kroah-Hartman
                   ` (18 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Fan Wu, Linus Walleij,
	Sebastian Reichel, Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Fan Wu <fanwu01@zju.edu.cn>

[ Upstream commit 75b1e88d34254f4fb7753345e21bfee47abddd7f ]

ab8500_fg_remove() destroys the driver workqueue while the threaded
interrupt handlers are still armed; they are devm-managed and freed
only after ->remove() returns, so a handler that fires in that
window queues work on the freed workqueue.

Tear the workqueue down through devm instead, registering its cleanup
after the power supply and before the interrupt requests.  devm then
frees the interrupts first, so the handlers can no longer queue work,
before disabling the delayed and plain work items and destroying the
workqueue.  Disabling the items, rather than cancelling them, keeps
them disabled so no producer (including the power-supply
external_power_changed callback) can requeue them.

Found by an in-house static analysis tool.

Fixes: 13151631b5bd ("ab8500-fg: A8500 fuel gauge driver")
Cc: stable@vger.kernel.org # v6.10+
Assisted-by: Codex:gpt-5.6
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Reviewed-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260802020316.417757-1-fanwu01@zju.edu.cn
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/power/supply/ab8500_fg.c |   30 +++++++++++++++++++++---------
 1 file changed, 21 insertions(+), 9 deletions(-)

--- a/drivers/power/supply/ab8500_fg.c
+++ b/drivers/power/supply/ab8500_fg.c
@@ -3054,6 +3054,20 @@ static void ab8500_fg_unbind(struct devi
 	flush_workqueue(di->fg_wq);
 }
 
+/* Disable, not cancel: works stay disabled so nothing can re-arm them. */
+static void ab8500_fg_destroy_workqueue(void *data)
+{
+	struct ab8500_fg *di = data;
+
+	disable_work_sync(&di->fg_acc_cur_work);
+	disable_work_sync(&di->fg_work);
+	disable_delayed_work_sync(&di->fg_reinit_work);
+	disable_delayed_work_sync(&di->fg_low_bat_work);
+	disable_delayed_work_sync(&di->fg_check_hw_failure_work);
+	disable_delayed_work_sync(&di->fg_periodic_work);
+	destroy_workqueue(di->fg_wq);
+}
+
 static const struct component_ops ab8500_fg_component_ops = {
 	.bind = ab8500_fg_bind,
 	.unbind = ab8500_fg_unbind,
@@ -3155,6 +3169,11 @@ static int ab8500_fg_probe(struct platfo
 		return PTR_ERR(di->fg_psy);
 	}
 
+	/* Registered after fg_psy, before the IRQs: devm frees IRQ -> workqueue -> fg_psy. */
+	ret = devm_add_action_or_reset(dev, ab8500_fg_destroy_workqueue, di);
+	if (ret)
+		return ret;
+
 	di->fg_samples = SEC_TO_SAMPLE(di->bm->fg_params->init_timer);
 
 	/*
@@ -3167,20 +3186,16 @@ static int ab8500_fg_probe(struct platfo
 	/* Register primary interrupt handlers */
 	for (i = 0; i < ARRAY_SIZE(ab8500_fg_irq); i++) {
 		irq = platform_get_irq_byname(pdev, ab8500_fg_irq[i].name);
-		if (irq < 0) {
-			destroy_workqueue(di->fg_wq);
+		if (irq < 0)
 			return irq;
-		}
 
 		ret = devm_request_threaded_irq(dev, irq, NULL,
 				  ab8500_fg_irq[i].isr,
 				  IRQF_SHARED | IRQF_NO_SUSPEND | IRQF_ONESHOT,
 				  ab8500_fg_irq[i].name, di);
 
-		if (ret != 0) {
-			destroy_workqueue(di->fg_wq);
+		if (ret != 0)
 			return ret;
-		}
 		dev_dbg(dev, "Requested %s IRQ %d: %d\n",
 			ab8500_fg_irq[i].name, irq, ret);
 	}
@@ -3194,7 +3209,6 @@ static int ab8500_fg_probe(struct platfo
 	ret = ab8500_fg_sysfs_init(di);
 	if (ret) {
 		dev_err(dev, "failed to create sysfs entry\n");
-		destroy_workqueue(di->fg_wq);
 		return ret;
 	}
 
@@ -3202,7 +3216,6 @@ static int ab8500_fg_probe(struct platfo
 	if (ret) {
 		dev_err(dev, "failed to create FG psy\n");
 		ab8500_fg_sysfs_exit(di);
-		destroy_workqueue(di->fg_wq);
 		return ret;
 	}
 
@@ -3222,7 +3235,6 @@ static void ab8500_fg_remove(struct plat
 {
 	struct ab8500_fg *di = platform_get_drvdata(pdev);
 
-	destroy_workqueue(di->fg_wq);
 	component_del(&pdev->dev, &ab8500_fg_component_ops);
 	list_del(&di->node);
 	ab8500_fg_sysfs_exit(di);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 551/556] mm/damon/core: avoid infinite kdamond_merge_regions() internal loop
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (549 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 550/556] power: supply: ab8500_fg: fix use-after-free on remove Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 552/556] mm/damon/ops-common: use nr_accesses moving sum for quota score Greg Kroah-Hartman
                   ` (17 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit 123e4619ab6c8ab1c4cb1d7a58311a2af13929cd upstream.

Patch series "mm/damon: unurgent fixes for infinite loop, NULL de-ref and
races", v1.1.

Sashiko found a few issues in DAMON that could cause infinite loop, NULL
dereference and monitoring results degradation.  The first two sounds
scary but the infinite loop happens only under unreasonable user setup.
The NULL dereference is only in a unit test.  Monitoring results
degradation is trivial since it is only best-effort, and those happens
from only unlikely races.  Still those are bugs that better to fix if
possible.  Fix those.


This patch (of 6):

Due to online parameter update like events, the number of DAMON regions
could be higher than the user-set upper limit.  kdamond_merge_regions()
repeats merge regions until the number meets the limit, while doubling the
merge threshold up to the theoretical maximum threshold.  It is tried only
up to the theoretical maximum threshold because even the aggressive
merging can fail from reducing the number of regions under the
user-defined upper limit.  For example, there could be many user-defined
non-contiguous regions that cannot be merged.

The threshold based loop break condition is evaluated by comparing the
threshold for the next merging try against the theoretical maximum
threshold.  If max_thres is larger than UINT_MAX / 2, doubling the
threshold could make it overflow, and bypass the loop break condition.  In
the case, if the number of regions cannot be reduced under the upper limit
like explained above, the loop will run infinitely.

Prevent the case by doing the break condition check before doubling the
threshold.  Also, prevent the threshold exceeding the maximum threshold,
as it could overflow and apply the wrong merge threshold.

This issue is unlikely to occur in real world, since having the max_thres
higher than UINT_MAX / 2 require unrealistically large aggregation
intervals compared to the sampling interval.  Also, it requires an
unrealistically large number of uncontiguous regions setup.  Nonetheless,
the consequence is bad and the fix is simple.

The issue was discovered [1] by Sashiko.

Link: https://lore.kernel.org/20260715031002.108504-1-sj@kernel.org
Link: https://lore.kernel.org/20260715031002.108504-2-sj@kernel.org
Link: https://lore.kernel.org/20260709145425.96247-1-sj@kernel.org [1]
Fixes: 310d6c15e910 ("mm/damon/core: merge regions aggressively when max_nr_regions is unmet")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: <stable@vger.kernel.org> # 6.10.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: SJ Park <sj@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/damon/core.c |   13 +++++++++----
 1 file changed, 9 insertions(+), 4 deletions(-)

--- a/mm/damon/core.c
+++ b/mm/damon/core.c
@@ -3166,15 +3166,20 @@ static void kdamond_merge_regions(struct
 
 	max_thres = c->attrs.aggr_interval /
 		(c->attrs.sample_interval ?  c->attrs.sample_interval : 1);
-	do {
+	while (true) {
 		nr_regions = 0;
 		damon_for_each_target(t, c) {
 			damon_merge_regions_of(t, threshold, sz_limit);
 			nr_regions += damon_nr_regions(t);
 		}
-		threshold = max(1, threshold * 2);
-	} while (nr_regions > c->attrs.max_nr_regions &&
-			threshold / 2 < max_thres);
+		if (nr_regions <= c->attrs.max_nr_regions ||
+				max_thres <= threshold)
+			break;
+		if (threshold < max_thres / 2)
+			threshold = max(1, threshold * 2);
+		else
+			threshold = max_thres;
+	}
 }
 
 #ifdef CONFIG_DAMON_DEBUG_SANITY



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 552/556] mm/damon/ops-common: use nr_accesses moving sum for quota score
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (550 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 551/556] mm/damon/core: avoid infinite kdamond_merge_regions() internal loop Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 553/556] mm/damon/paddr: drop last same folio access check reuse optimization Greg Kroah-Hartman
                   ` (16 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit 6c25083f7ae7e2660d766169e5b4d3e96010503f upstream.

Since commit 42f994b71404 ("mm/damon/core: implement scheme-specific apply
interval"), DAMOS scheme can be applied at any time.  At that time,
nr_accesses may not be fully aggregated.  But the quota prioritization
score is calculated using the not fully aggregated count.  As a result,
the performance of DAMOS could be degraded.  Fix by using
damon_nr_accesses_mvsum() instead.

The user impact of the issue is suboptimum DAMOS performance under certain
setups.  Nonetheless, the bug was there from the beginning of the setup
availability.  In other words, the suboptimum performance is the baseline
of the setup and hence it didn't cause regression.  Also the extent of the
suboptimality was not big enough to be found from users and testers.
Still, this is a clear bug that is better to be fixed, and can be easily
fixed.

Link: https://lore.kernel.org/20260719161136.90191-1-sj@kernel.org
Fixes: 42f994b71404 ("mm/damon/core: implement scheme-specific apply interval")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: <stable@vger.kernel.org> # 6.7.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: SJ Park <sj@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/damon/ops-common.c |    5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

--- a/mm/damon/ops-common.c
+++ b/mm/damon/ops-common.c
@@ -111,8 +111,9 @@ int damon_hot_score(struct damon_ctx *c,
 	unsigned int age_weight = s->quota.weight_age;
 	int hotness;
 
-	freq_subscore = r->nr_accesses * DAMON_MAX_SUBSCORE /
-		damon_max_nr_accesses(&c->attrs);
+	freq_subscore = mult_frac(r->nr_accesses_bp / 10000,
+			DAMON_MAX_SUBSCORE,
+			damon_max_nr_accesses(&c->attrs));
 
 	age_in_sec = (unsigned long)r->age * c->attrs.aggr_interval / 1000000;
 	if (age_in_sec)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 553/556] mm/damon/paddr: drop last same folio access check reuse optimization
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (551 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 552/556] mm/damon/ops-common: use nr_accesses moving sum for quota score Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 554/556] mm/damon/vaddr: drop last same folio access check optimization Greg Kroah-Hartman
                   ` (15 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit f23f0aa62b2f32c2b12f95959fc4603ef81678b2 upstream.

It can race when multiple kdamonds are being used.  The problem from the
race is doubtful, but the gain from the optimization is also doubtful.
Simply drop the optimization in favor of code simplicity.

The user impact is doubtfully trivial.  After all, this kind of
interference can happen only by intentional user setup.  Even if it
happens, it will be rare, and the consequence is degradation of the
best-effort monitoring results.  No critical consequences like kernel
panic or memory corruption happen.

The race was discovered [1] by Sashiko.

Link: https://lore.kernel.org/20260715031002.108504-5-sj@kernel.org
Link: https://lore.kernel.org/20260621204050.10993-1-sj@kernel.org [1]
Fixes: a28397beb55b ("mm/damon: implement primitives for physical address space monitoring")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: <stable@vger.kernel.org> # 5.16.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: SJ Park <sj@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/damon/paddr.c |   20 ++++----------------
 1 file changed, 4 insertions(+), 16 deletions(-)

--- a/mm/damon/paddr.c
+++ b/mm/damon/paddr.c
@@ -65,7 +65,7 @@ static void damon_pa_prepare_access_chec
 	}
 }
 
-static bool damon_pa_young(phys_addr_t paddr, unsigned long *folio_sz)
+static bool damon_pa_young(phys_addr_t paddr)
 {
 	struct folio *folio = damon_get_folio(PHYS_PFN(paddr));
 	bool accessed;
@@ -74,7 +74,6 @@ static bool damon_pa_young(phys_addr_t p
 		return false;
 
 	accessed = damon_folio_young(folio);
-	*folio_sz = folio_size(folio);
 	folio_put(folio);
 	return accessed;
 }
@@ -82,23 +81,12 @@ static bool damon_pa_young(phys_addr_t p
 static void __damon_pa_check_access(struct damon_region *r,
 		struct damon_attrs *attrs, unsigned long addr_unit)
 {
-	static phys_addr_t last_addr;
-	static unsigned long last_folio_sz = PAGE_SIZE;
-	static bool last_accessed;
+	bool accessed;
 	phys_addr_t sampling_addr = damon_pa_phys_addr(
 			r->sampling_addr, addr_unit);
 
-	/* If the region is in the last checked page, reuse the result */
-	if (ALIGN_DOWN(last_addr, last_folio_sz) ==
-				ALIGN_DOWN(sampling_addr, last_folio_sz)) {
-		damon_update_region_access_rate(r, last_accessed, attrs);
-		return;
-	}
-
-	last_accessed = damon_pa_young(sampling_addr, &last_folio_sz);
-	damon_update_region_access_rate(r, last_accessed, attrs);
-
-	last_addr = sampling_addr;
+	accessed = damon_pa_young(sampling_addr);
+	damon_update_region_access_rate(r, accessed, attrs);
 }
 
 static unsigned int damon_pa_check_accesses(struct damon_ctx *ctx)



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 554/556] mm/damon/vaddr: drop last same folio access check optimization
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (552 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 553/556] mm/damon/paddr: drop last same folio access check reuse optimization Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 555/556] PCI: Introduce PCI_SLOT_PLACEHOLDER constant for slot_nr placeholder value Greg Kroah-Hartman
                   ` (14 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Andrew Morton

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: SJ Park <sj@kernel.org>

commit 831846078caa14b7d00b2ccca8b8fe522afe3204 upstream.

The optimization can race when multiple kdamonds are running.  Meanwhile,
the impact of the optimization is quite doubtful.  Just remove it.

The user impact of the issue should be quite trivial.  After all, the race
can happen only when the user intentionally setup DAMON in the way.  Even
if it happens, it would be rare and only degrade the best-effort
monitoring results.  No critical consequences like kernel panic or memory
corruption happen.

The race possibility was discovered [1] by Sashiko.

Link: https://lore.kernel.org/20260715031002.108504-4-sj@kernel.org
Link: https://lore.kernel.org/20260621204050.10993-1-sj@kernel.org [1]
Fixes: 3f49584b262c ("mm/damon: implement primitives for the virtual memory address spaces")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: <stable@vger.kernel.org> # 5.15.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: SJ Park <sj@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 mm/damon/vaddr.c |   34 ++++++----------------------------
 1 file changed, 6 insertions(+), 28 deletions(-)

--- a/mm/damon/vaddr.c
+++ b/mm/damon/vaddr.c
@@ -382,8 +382,6 @@ static void damon_va_prepare_access_chec
 }
 
 struct damon_young_walk_private {
-	/* size of the folio for the access checked virtual memory address */
-	unsigned long *folio_sz;
 	bool young;
 };
 
@@ -410,7 +408,6 @@ static int damon_young_pmd_entry(pmd_t *
 					mmu_notifier_test_young(walk->mm,
 						addr))
 			priv->young = true;
-		*priv->folio_sz = HPAGE_PMD_SIZE;
 huge_out:
 		spin_unlock(ptl);
 		return 0;
@@ -429,7 +426,6 @@ huge_out:
 	if (pte_young(ptent) || !folio_test_idle(folio) ||
 			mmu_notifier_test_young(walk->mm, addr))
 		priv->young = true;
-	*priv->folio_sz = folio_size(folio);
 out:
 	pte_unmap_unlock(pte, ptl);
 	return 0;
@@ -457,7 +453,6 @@ static int damon_young_hugetlb_entry(pte
 	if (pte_young(entry) || !folio_test_idle(folio) ||
 	    mmu_notifier_test_young(walk->mm, addr))
 		priv->young = true;
-	*priv->folio_sz = huge_page_size(h);
 
 	folio_put(folio);
 
@@ -469,11 +464,9 @@ out:
 #define damon_young_hugetlb_entry NULL
 #endif /* CONFIG_HUGETLB_PAGE */
 
-static bool damon_va_young(struct mm_struct *mm, unsigned long addr,
-		unsigned long *folio_sz)
+static bool damon_va_young(struct mm_struct *mm, unsigned long addr)
 {
 	struct damon_young_walk_private arg = {
-		.folio_sz = folio_sz,
 		.young = false,
 	};
 
@@ -493,29 +486,18 @@ static bool damon_va_young(struct mm_str
  * r	the region to be checked
  */
 static void __damon_va_check_access(struct mm_struct *mm,
-				struct damon_region *r, bool same_target,
+				struct damon_region *r,
 				struct damon_attrs *attrs)
 {
-	static unsigned long last_addr;
-	static unsigned long last_folio_sz = PAGE_SIZE;
-	static bool last_accessed;
+	bool accessed;
 
 	if (!mm) {
 		damon_update_region_access_rate(r, false, attrs);
 		return;
 	}
 
-	/* If the region is in the last checked page, reuse the result */
-	if (same_target && (ALIGN_DOWN(last_addr, last_folio_sz) ==
-				ALIGN_DOWN(r->sampling_addr, last_folio_sz))) {
-		damon_update_region_access_rate(r, last_accessed, attrs);
-		return;
-	}
-
-	last_accessed = damon_va_young(mm, r->sampling_addr, &last_folio_sz);
-	damon_update_region_access_rate(r, last_accessed, attrs);
-
-	last_addr = r->sampling_addr;
+	accessed = damon_va_young(mm, r->sampling_addr);
+	damon_update_region_access_rate(r, accessed, attrs);
 }
 
 static unsigned int damon_va_check_accesses(struct damon_ctx *ctx)
@@ -524,16 +506,12 @@ static unsigned int damon_va_check_acces
 	struct mm_struct *mm;
 	struct damon_region *r;
 	unsigned int max_nr_accesses = 0;
-	bool same_target;
 
 	damon_for_each_target(t, ctx) {
 		mm = damon_get_mm(t);
-		same_target = false;
 		damon_for_each_region(r, t) {
-			__damon_va_check_access(mm, r, same_target,
-					&ctx->attrs);
+			__damon_va_check_access(mm, r, &ctx->attrs);
 			max_nr_accesses = max(r->nr_accesses, max_nr_accesses);
-			same_target = true;
 		}
 		if (mm)
 			mmput(mm);



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 555/556] PCI: Introduce PCI_SLOT_PLACEHOLDER constant for slot_nr placeholder value
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (553 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 554/556] mm/damon/vaddr: drop last same folio access check optimization Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 13:43 ` [PATCH 7.2 556/556] PCI: Allow per function PCI slots to fix slot reset on s390 Greg Kroah-Hartman
                   ` (13 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Bjorn Helgaas, Farhan Ali,
	Madhavan Srinivasan, Tyrel Datwyler, linuxppc-dev, Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Farhan Ali <alifm@linux.ibm.com>

[ Upstream commit c243e6c470c4695965cc8287767925bc1d9a7867 ]

Introduce a constant for placeholder value and update the kerneldoc for
pci_create_slot() to reference PCI_SLOT_PLACEHOLDER instead of -1
throughout. No functional change.

Suggested-by: Bjorn Helgaas <bhelgaas@google.com>
Signed-off-by: Farhan Ali <alifm@linux.ibm.com>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Cc: Madhavan Srinivasan <maddy@linux.ibm.com>
Cc: Tyrel Datwyler <tyreld@linux.ibm.com>
Cc: linuxppc-dev@lists.ozlabs.org
Link: https://patch.msgid.link/20260805165518.794-2-alifm@linux.ibm.com
Stable-dep-of: dcc5bec09e23 ("PCI: Allow per function PCI slots to fix slot reset on s390")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/pci/hotplug/pnv_php.c     |    2 +-
 drivers/pci/hotplug/rpaphp_slot.c |    2 +-
 drivers/pci/slot.c                |   21 +++++++++++----------
 include/linux/pci.h               |    3 +++
 4 files changed, 16 insertions(+), 12 deletions(-)

--- a/drivers/pci/hotplug/pnv_php.c
+++ b/drivers/pci/hotplug/pnv_php.c
@@ -808,7 +808,7 @@ static struct pnv_php_slot *pnv_php_allo
 	if (dn->child && PCI_DN(dn->child))
 		php_slot->slot_no = PCI_SLOT(PCI_DN(dn->child)->devfn);
 	else
-		php_slot->slot_no = -1;   /* Placeholder slot */
+		php_slot->slot_no = PCI_SLOT_PLACEHOLDER;   /* Placeholder slot */
 
 	kref_init(&php_slot->kref);
 	php_slot->state	                = PNV_PHP_STATE_INITIALIZED;
--- a/drivers/pci/hotplug/rpaphp_slot.c
+++ b/drivers/pci/hotplug/rpaphp_slot.c
@@ -84,7 +84,7 @@ int rpaphp_register_slot(struct slot *sl
 	struct hotplug_slot *php_slot = &slot->hotplug_slot;
 	u32 my_index;
 	int retval;
-	int slotno = -1;
+	int slotno = PCI_SLOT_PLACEHOLDER;
 
 	dbg("%s registering slot:path[%pOF] index[%x], name[%s] pdomain[%x] type[%d]\n",
 		__func__, slot->dn, slot->index, slot->name,
--- a/drivers/pci/slot.c
+++ b/drivers/pci/slot.c
@@ -37,7 +37,7 @@ static const struct sysfs_ops pci_slot_s
 
 static ssize_t address_read_file(struct pci_slot *slot, char *buf)
 {
-	if (slot->number == 0xff)
+	if (slot->number == PCI_SLOT_PLACEHOLDER)
 		return sysfs_emit(buf, "%04x:%02x\n",
 				  pci_domain_nr(slot->bus),
 				  slot->bus->number);
@@ -210,7 +210,7 @@ static struct pci_slot *get_slot(struct
 /**
  * pci_create_slot - create or increment refcount for physical PCI slot
  * @parent: struct pci_bus of parent bridge
- * @slot_nr: PCI_SLOT(pci_dev->devfn), -1 for placeholder, or
+ * @slot_nr: PCI_SLOT(pci_dev->devfn), PCI_SLOT_PLACEHOLDER for placeholder, or
  *	PCI_SLOT_ALL_DEVICES
  * @name: user visible string presented in /sys/bus/pci/slots/<name>
  * @hotplug: set if caller is hotplug driver, NULL otherwise
@@ -236,15 +236,16 @@ static struct pci_slot *get_slot(struct
  * In most cases, @pci_bus, @slot_nr will be sufficient to uniquely identify
  * a slot. There is one notable exception - pSeries (rpaphp), where the
  * @slot_nr cannot be determined until a device is actually inserted into
- * the slot. In this scenario, the caller may pass -1 for @slot_nr.
+ * the slot. In this scenario, the caller may pass PCI_SLOT_PLACEHOLDER for @slot_nr.
  *
  * The following semantics are imposed when the caller passes @slot_nr ==
- * -1. First, we no longer check for an existing %struct pci_slot, as there
- * may be many slots with @slot_nr of -1.  The other change in semantics is
- * user-visible, which is the 'address' parameter presented in sysfs will
- * consist solely of a dddd:bb tuple, where dddd is the PCI domain of the
- * %struct pci_bus and bb is the bus number. In other words, the devfn of
- * the 'placeholder' slot will not be displayed.
+ * PCI_SLOT_PLACEHOLDER. First, we no longer check for an existing %struct
+ * pci_slot, as there may be many slots with @slot_nr of
+ * PCI_SLOT_PLACEHOLDER. The other change in semantics is user-visible,
+ * which is the 'address' parameter presented in sysfs will consist solely
+ * of a dddd:bb tuple, where dddd is the PCI domain of the %struct pci_bus
+ * and bb is the bus number. In other words, the devfn of the 'placeholder'
+ * slot will not be displayed.
  *
  * Bus-wide slots:
  * For PCIe hotplug, the physical slot encompasses the entire secondary
@@ -267,7 +268,7 @@ struct pci_slot *pci_create_slot(struct
 
 	mutex_lock(&pci_slot_mutex);
 
-	if (slot_nr == -1)
+	if (slot_nr == PCI_SLOT_PLACEHOLDER)
 		goto placeholder;
 
 	/*
--- a/include/linux/pci.h
+++ b/include/linux/pci.h
@@ -81,6 +81,9 @@
  */
 #define PCI_SLOT_ALL_DEVICES	0xfe
 
+/* Used to identify a slot as a placeholder */
+#define PCI_SLOT_PLACEHOLDER	0xff
+
 /* pci_slot represents a physical slot */
 struct pci_slot {
 	struct pci_bus		*bus;		/* Bus this slot is on */



^ permalink raw reply	[flat|nested] 570+ messages in thread

* [PATCH 7.2 556/556] PCI: Allow per function PCI slots to fix slot reset on s390
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (554 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 555/556] PCI: Introduce PCI_SLOT_PLACEHOLDER constant for slot_nr placeholder value Greg Kroah-Hartman
@ 2026-09-09 13:43 ` Greg Kroah-Hartman
  2026-09-09 15:51 ` [PATCH 7.2 000/556] 7.2.5-rc1 review Ronald Warsow
                   ` (12 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-09 13:43 UTC (permalink / raw)
  To: stable
  Cc: Greg Kroah-Hartman, patches, Niklas Schnelle, Farhan Ali,
	Bjorn Helgaas, Sasha Levin

7.2-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Farhan Ali <alifm@linux.ibm.com>

[ Upstream commit dcc5bec09e23bbc4f9de055a11fce9937244f2c8 ]

On s390 systems, which use a machine level hypervisor, PCI devices are
always accessed through a form of PCI pass-through which fundamentally
operates on a per PCI function granularity. This is also reflected in the
s390 PCI hotplug driver which creates hotplug slots for individual PCI
functions. Its reset_slot() function, which is a wrapper for
zpci_hot_reset_device(), thus also resets individual functions.

Currently, the pci_create_slot() assigns the same pci_slot object to
multifunction devices. This approach worked fine on s390 systems that only
exposed virtual functions as individual PCI domains to the operating
system.  Since commit 44510d6fa0c0 ("s390/pci: Handling multifunctions")
s390 supports exposing the topology of multifunction PCI devices by
grouping them in a shared PCI domain. This creates a problem when resetting
a function through the hotplug driver's slot_reset() interface.

When attempting to reset a function through the hotplug driver, the shared
slot assignment causes the wrong function to be reset instead of the
intended one. It also leaks memory as we do create a pci_slot object for
the function, but don't correctly free it in pci_slot_release().

Add a flag for struct pci_slot to allow per function PCI slots for
functions managed through a hypervisor, which exposes individual PCI
functions while retaining the topology. Since we can use all 8 bits for
slot 'number' (for ARI devices), change slot 'number' u16 to account for
special values PCI_SLOT_PLACEHOLDER and PCI_SLOT_ALL_DEVICES.

Fixes: 44510d6fa0c0 ("s390/pci: Handling multifunctions")
Suggested-by: Niklas Schnelle <schnelle@linux.ibm.com>
Signed-off-by: Farhan Ali <alifm@linux.ibm.com>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Reviewed-by: Niklas Schnelle <schnelle@linux.ibm.com>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260805165518.794-3-alifm@linux.ibm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 drivers/pci/pci.c   |    5 +++--
 drivers/pci/slot.c  |   29 +++++++++++++++++++++++------
 include/linux/pci.h |    7 ++++---
 3 files changed, 30 insertions(+), 11 deletions(-)

--- a/drivers/pci/pci.c
+++ b/drivers/pci/pci.c
@@ -4897,8 +4897,9 @@ static int pci_reset_hotplug_slot(struct
 
 static int pci_dev_reset_slot_function(struct pci_dev *dev, bool probe)
 {
-	if (dev->multifunction || dev->subordinate || !dev->slot ||
-	    dev->dev_flags & PCI_DEV_FLAGS_NO_BUS_RESET)
+	if (dev->subordinate || !dev->slot ||
+	    dev->dev_flags & PCI_DEV_FLAGS_NO_BUS_RESET ||
+	    (dev->multifunction && !dev->slot->per_func_slot))
 		return -ENOTTY;
 
 	return pci_reset_hotplug_slot(dev->slot->hotplug, probe);
--- a/drivers/pci/slot.c
+++ b/drivers/pci/slot.c
@@ -72,6 +72,23 @@ static ssize_t cur_speed_read_file(struc
 	return bus_speed_read(slot->bus->cur_bus_speed, buf);
 }
 
+static bool pci_dev_matches_slot(struct pci_dev *dev, struct pci_slot *slot)
+{
+	if (slot->per_func_slot)
+		return dev->devfn == slot->number;
+
+	return slot->number == PCI_SLOT_ALL_DEVICES ||
+		PCI_SLOT(dev->devfn) == slot->number;
+}
+
+static bool pci_slot_enabled_per_func(void)
+{
+	if (IS_ENABLED(CONFIG_S390))
+		return true;
+
+	return false;
+}
+
 static void pci_slot_release(struct kobject *kobj)
 {
 	struct pci_dev *dev;
@@ -82,8 +99,7 @@ static void pci_slot_release(struct kobj
 
 	down_read(&pci_bus_sem);
 	list_for_each_entry(dev, &slot->bus->devices, bus_list)
-		if (slot->number == PCI_SLOT_ALL_DEVICES ||
-		    PCI_SLOT(dev->devfn) == slot->number)
+		if (pci_dev_matches_slot(dev, slot))
 			dev->slot = NULL;
 	up_read(&pci_bus_sem);
 
@@ -187,8 +203,7 @@ void pci_dev_assign_slot(struct pci_dev
 
 	mutex_lock(&pci_slot_mutex);
 	list_for_each_entry(slot, &dev->bus->slots, list)
-		if (slot->number == PCI_SLOT_ALL_DEVICES ||
-		    PCI_SLOT(dev->devfn) == slot->number)
+		if (pci_dev_matches_slot(dev, slot))
 			dev->slot = slot;
 	mutex_unlock(&pci_slot_mutex);
 }
@@ -299,6 +314,9 @@ placeholder:
 	slot->bus = pci_bus_get(parent);
 	slot->number = slot_nr;
 
+	if (pci_slot_enabled_per_func())
+		slot->per_func_slot = 1;
+
 	slot->kobj.kset = pci_slots_kset;
 
 	slot_name = make_slot_name(name);
@@ -319,8 +337,7 @@ placeholder:
 
 	down_read(&pci_bus_sem);
 	list_for_each_entry(dev, &parent->devices, bus_list)
-		if (slot_nr == PCI_SLOT_ALL_DEVICES ||
-		    PCI_SLOT(dev->devfn) == slot_nr)
+		if (pci_dev_matches_slot(dev, slot))
 			dev->slot = slot;
 	up_read(&pci_bus_sem);
 
--- a/include/linux/pci.h
+++ b/include/linux/pci.h
@@ -79,17 +79,18 @@
  * and, if ARI Forwarding is enabled, functions may appear to be on multiple
  * devices.
  */
-#define PCI_SLOT_ALL_DEVICES	0xfe
+#define PCI_SLOT_ALL_DEVICES	0xfeff
 
 /* Used to identify a slot as a placeholder */
-#define PCI_SLOT_PLACEHOLDER	0xff
+#define PCI_SLOT_PLACEHOLDER	0xffff
 
 /* pci_slot represents a physical slot */
 struct pci_slot {
 	struct pci_bus		*bus;		/* Bus this slot is on */
 	struct list_head	list;		/* Node in list of slots */
 	struct hotplug_slot	*hotplug;	/* Hotplug info (move here) */
-	unsigned char		number;		/* Device nr, or PCI_SLOT_ALL_DEVICES */
+	u16			number;		/* Device nr, or PCI_SLOT_ALL_DEVICES */
+	unsigned int		per_func_slot:1; /* Allow per function slot */
 	struct kobject		kobj;
 };
 



^ permalink raw reply	[flat|nested] 570+ messages in thread

* Re: [PATCH 7.2 000/556] 7.2.5-rc1 review
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (555 preceding siblings ...)
  2026-09-09 13:43 ` [PATCH 7.2 556/556] PCI: Allow per function PCI slots to fix slot reset on s390 Greg Kroah-Hartman
@ 2026-09-09 15:51 ` Ronald Warsow
  2026-09-09 16:06 ` Brett A C Sheffield
                   ` (11 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Ronald Warsow @ 2026-09-09 15:51 UTC (permalink / raw)
  To: Greg Kroah-Hartman, stable
  Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
	lkft-triage, pavel, jonathanh, f.fainelli, sudipm.mukherjee,
	conor, hargar, broonie, achill, sr

Hi

kernel build / boot test on x86_64 (Intel).

No regressions here.

Thanks

Tested-by: Ronald Warsow <rwarsow@gmx.de>

^ permalink raw reply	[flat|nested] 570+ messages in thread

* Re: [PATCH 7.2 000/556] 7.2.5-rc1 review
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (556 preceding siblings ...)
  2026-09-09 15:51 ` [PATCH 7.2 000/556] 7.2.5-rc1 review Ronald Warsow
@ 2026-09-09 16:06 ` Brett A C Sheffield
  2026-09-09 18:44 ` Florian Fainelli
                   ` (10 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Brett A C Sheffield @ 2026-09-09 16:06 UTC (permalink / raw)
  To: gregkh
  Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
	patches, lkft-triage, pavel, jonathanh, f.fainelli,
	sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr,
	Brett A C Sheffield

# Librecast Test Results

020/020 [ OK ] liblcrq
010/010 [ OK ] libmld
120/120 [ OK ] liblibrecast

CPU/kernel: Linux auntie 7.2.5-rc1-ge01c81012950 #2 SMP PREEMPT_DYNAMIC Wed Sep  9 15:28:34 -00 2026 x86_64 AMD Ryzen 9 9950X 16-Core Processor AuthenticAMD GNU/Linux

Tested-by: Brett A C Sheffield <bacs@librecast.net>

^ permalink raw reply	[flat|nested] 570+ messages in thread

* Re: [PATCH 7.2 000/556] 7.2.5-rc1 review
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (557 preceding siblings ...)
  2026-09-09 16:06 ` Brett A C Sheffield
@ 2026-09-09 18:44 ` Florian Fainelli
  2026-09-09 22:23 ` Shuah Khan
                   ` (9 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Florian Fainelli @ 2026-09-09 18:44 UTC (permalink / raw)
  To: Greg Kroah-Hartman, stable
  Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
	lkft-triage, pavel, jonathanh, sudipm.mukherjee, rwarsow, conor,
	hargar, broonie, achill, sr

On 9/9/26 06:34, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 7.2.5 release.
> There are 556 patches in this series, all will be posted as a response
> to this one.  If anyone has any issues with these being applied, please
> let me know.
> 
> Responses should be made by Fri, 11 Sep 2026 13:40:31 +0000.
> Anything received after that time might be too late.
> 
> The whole patch series can be found in one patch at:
> 	https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.2.5-rc1.gz
> or in the git tree and branch at:
> 	git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.2.y
> and the diffstat can be found below.
> 
> thanks,
> 
> greg k-h

On ARCH_BRCMSTB using 32-bit and 64-bit ARM kernels, build tested on 
BMIPS_GENERIC:

Tested-by: Florian Fainelli <florian.fainelli@broadcom.com>
-- 
Florian

^ permalink raw reply	[flat|nested] 570+ messages in thread

* Re: [PATCH 7.2 000/556] 7.2.5-rc1 review
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (558 preceding siblings ...)
  2026-09-09 18:44 ` Florian Fainelli
@ 2026-09-09 22:23 ` Shuah Khan
  2026-09-09 22:52 ` Miguel Ojeda
                   ` (8 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Shuah Khan @ 2026-09-09 22:23 UTC (permalink / raw)
  To: Greg Kroah-Hartman, stable
  Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
	lkft-triage, pavel, jonathanh, f.fainelli, sudipm.mukherjee,
	rwarsow, conor, hargar, broonie, achill, sr, Shuah Khan

On 9/9/26 07:34, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 7.2.5 release.
> There are 556 patches in this series, all will be posted as a response
> to this one.  If anyone has any issues with these being applied, please
> let me know.
> 
> Responses should be made by Fri, 11 Sep 2026 13:40:31 +0000.
> Anything received after that time might be too late.
> 
> The whole patch series can be found in one patch at:
> 	https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.2.5-rc1.gz
> or in the git tree and branch at:
> 	git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.2.y
> and the diffstat can be found below.
> 
> thanks,
> 
> greg k-h
> 

Compiled and booted on my test system. No dmesg regressions.

Tested-by: Shuah Khan <skhan@linuxfoundation.org>

thanks,
-- Shuah

^ permalink raw reply	[flat|nested] 570+ messages in thread

* Re: [PATCH 7.2 000/556] 7.2.5-rc1 review
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (559 preceding siblings ...)
  2026-09-09 22:23 ` Shuah Khan
@ 2026-09-09 22:52 ` Miguel Ojeda
  2026-09-09 23:08 ` Takeshi Ogasawara
                   ` (7 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Miguel Ojeda @ 2026-09-09 22:52 UTC (permalink / raw)
  To: gregkh
  Cc: achill, akpm, broonie, conor, f.fainelli, hargar, jonathanh,
	linux-kernel, linux, lkft-triage, patches, patches, pavel,
	rwarsow, shuah, sr, stable, sudipm.mukherjee, torvalds,
	Miguel Ojeda

On Wed, 09 Sep 2026 15:34:40 +0200 Greg Kroah-Hartman <gregkh@linuxfoundation.org> wrote:
>
> This is the start of the stable review cycle for the 7.2.5 release.
> There are 556 patches in this series, all will be posted as a response
> to this one.  If anyone has any issues with these being applied, please
> let me know.
> 
> Responses should be made by Fri, 11 Sep 2026 13:40:31 +0000.
> Anything received after that time might be too late.

Boot-tested under QEMU for Rust x86_64, arm64 and riscv64; built-tested
for loongarch64 and arm32:

Tested-by: Miguel Ojeda <ojeda@kernel.org>

Thanks!

Cheers,
Miguel

^ permalink raw reply	[flat|nested] 570+ messages in thread

* Re: [PATCH 7.2 000/556] 7.2.5-rc1 review
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (560 preceding siblings ...)
  2026-09-09 22:52 ` Miguel Ojeda
@ 2026-09-09 23:08 ` Takeshi Ogasawara
  2026-09-10 12:07 ` Dileep malepu
                   ` (6 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Takeshi Ogasawara @ 2026-09-09 23:08 UTC (permalink / raw)
  To: Greg Kroah-Hartman
  Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
	patches, lkft-triage, pavel, jonathanh, f.fainelli,
	sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr

Hi Greg

On Wed, Sep 9, 2026 at 11:14 PM Greg Kroah-Hartman
<gregkh@linuxfoundation.org> wrote:
>
> This is the start of the stable review cycle for the 7.2.5 release.
> There are 556 patches in this series, all will be posted as a response
> to this one.  If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Fri, 11 Sep 2026 13:40:31 +0000.
> Anything received after that time might be too late.
>
> The whole patch series can be found in one patch at:
>         https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.2.5-rc1.gz
> or in the git tree and branch at:
>         git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.2.y
> and the diffstat can be found below.
>
> thanks,
>
> greg k-h
>

Linux version 7.2.5-rc1 tested.

Build successfully completed.
Boot successfully completed.
No dmesg regressions.
Video output normal.
Sound output normal.

Lenovo ThinkPad X1 Carbon Gen10(Intel i7-1260P(x86_64) arch linux)

[    0.000000] Linux version 7.2.5-rc1rv-ge01c81012950
(takeshi@ThinkPadX1Gen10J0764) (gcc (GCC) 16.2.1 20260810, GNU ld (GNU
Binutils) 2.47) #1 SMP PREEMPT_DYNAMIC Thu Sep 10 07:34:49 JST 2026

Tested-by: Takeshi Ogasawara <takeshi.ogasawara@futuring-girl.com>

^ permalink raw reply	[flat|nested] 570+ messages in thread

* Re: [PATCH 7.2 000/556] 7.2.5-rc1 review
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (561 preceding siblings ...)
  2026-09-09 23:08 ` Takeshi Ogasawara
@ 2026-09-10 12:07 ` Dileep malepu
  2026-09-10 12:23 ` Wentao Guan
                   ` (5 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Dileep malepu @ 2026-09-10 12:07 UTC (permalink / raw)
  To: Greg Kroah-Hartman
  Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
	patches, lkft-triage, pavel, jonathanh, f.fainelli,
	sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr

On Wed, Sep 9, 2026 at 7:48 PM Greg Kroah-Hartman
<gregkh@linuxfoundation.org> wrote:
>
> This is the start of the stable review cycle for the 7.2.5 release.
> There are 556 patches in this series, all will be posted as a response
> to this one.  If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Fri, 11 Sep 2026 13:40:31 +0000.
> Anything received after that time might be too late.
>
> The whole patch series can be found in one patch at:
>         https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.2.5-rc1.gz
> or in the git tree and branch at:
>         git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.2.y
> and the diffstat can be found below.
>
> thanks,
>
> greg k-h
>
> -------------
tested Linux stable-rc 7.2.5-rc1 on both x86_64 and arm64.

The kernel built successfully and booted successfully under QEMU
on both architectures. I also checked the dmesg output after boot
and did not find any regressions.

Kernel version: 7.2.5-rc1
Configurations tested: x86_64_defconfig, defconfig
Architectures tested: x86_64, arm64
Kernel source: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git
Commit: e01c81012950bb7454e595765197025a0fcbc0d5

Tested-by: Dileep Malepu <dileep.debian@gmail.com>

Best regards,
Dileep Malepu.

^ permalink raw reply	[flat|nested] 570+ messages in thread

* Re: [PATCH 7.2 000/556] 7.2.5-rc1 review
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (562 preceding siblings ...)
  2026-09-10 12:07 ` Dileep malepu
@ 2026-09-10 12:23 ` Wentao Guan
  2026-09-10 13:51 ` Justin Forbes
                   ` (4 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Wentao Guan @ 2026-09-10 12:23 UTC (permalink / raw)
  To: gregkh
  Cc: achill, akpm, broonie, conor, f.fainelli, hargar, jonathanh,
	linux-kernel, linux, lkft-triage, patches, patches, pavel,
	rwarsow, shuah, sr, stable, sudipm.mukherjee, torvalds,
	Wentao Guan

Build tested in our x86/arm64/loongarch config successfully without error.

Tested-by: Wentao Guan <guanwentao@uniontech.com>

Best Regards
Wentao Guan

^ permalink raw reply	[flat|nested] 570+ messages in thread

* Re: [PATCH 7.2 000/556] 7.2.5-rc1 review
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (563 preceding siblings ...)
  2026-09-10 12:23 ` Wentao Guan
@ 2026-09-10 13:51 ` Justin Forbes
  2026-09-10 14:57 ` Ron Economos
                   ` (3 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Justin Forbes @ 2026-09-10 13:51 UTC (permalink / raw)
  To: Greg Kroah-Hartman
  Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
	patches, lkft-triage, pavel, jonathanh, f.fainelli,
	sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr

On Wed, Sep 09, 2026 at 03:34:40PM +0200, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 7.2.5 release.
> There are 556 patches in this series, all will be posted as a response
> to this one.  If anyone has any issues with these being applied, please
> let me know.
> 
> Responses should be made by Fri, 11 Sep 2026 13:40:31 +0000.
> Anything received after that time might be too late.
> 
> The whole patch series can be found in one patch at:
> 	https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.2.5-rc1.gz
> or in the git tree and branch at:
> 	git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.2.y
> and the diffstat can be found below.
> 
> thanks,
> 
> greg k-h

Tested rc1 against the Fedora build system (aarch64, ppc64le, s390x,
x86_64), and boot tested x86_64. No regressions noted.

Tested-by: Justin M. Forbes <jforbes@fedoraproject.org>

^ permalink raw reply	[flat|nested] 570+ messages in thread

* Re: [PATCH 7.2 000/556] 7.2.5-rc1 review
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (564 preceding siblings ...)
  2026-09-10 13:51 ` Justin Forbes
@ 2026-09-10 14:57 ` Ron Economos
  2026-09-10 17:36 ` Barry K. Nathan
                   ` (2 subsequent siblings)
  568 siblings, 0 replies; 570+ messages in thread
From: Ron Economos @ 2026-09-10 14:57 UTC (permalink / raw)
  To: Greg Kroah-Hartman, stable
  Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
	lkft-triage, pavel, jonathanh, f.fainelli, sudipm.mukherjee,
	rwarsow, conor, hargar, broonie, achill, sr

On 9/9/26 06:34, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 7.2.5 release.
> There are 556 patches in this series, all will be posted as a response
> to this one.  If anyone has any issues with these being applied, please
> let me know.
>
> Responses should be made by Fri, 11 Sep 2026 13:40:31 +0000.
> Anything received after that time might be too late.
>
> The whole patch series can be found in one patch at:
> 	https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.2.5-rc1.gz
> or in the git tree and branch at:
> 	git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.2.y
> and the diffstat can be found below.
>
> thanks,
>
> greg k-h

Built and booted successfully on RISC-V RV64 (HiFive Unmatched).

Tested-by: Ron Economos <re@w6rz.net>


^ permalink raw reply	[flat|nested] 570+ messages in thread

* Re: [PATCH 7.2 000/556] 7.2.5-rc1 review
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (565 preceding siblings ...)
  2026-09-10 14:57 ` Ron Economos
@ 2026-09-10 17:36 ` Barry K. Nathan
  2026-09-10 21:08 ` Benjamin Boortz
  2026-09-11  8:24 ` Peter Schneider
  568 siblings, 0 replies; 570+ messages in thread
From: Barry K. Nathan @ 2026-09-10 17:36 UTC (permalink / raw)
  To: Greg Kroah-Hartman, stable
  Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
	lkft-triage, pavel, jonathanh, f.fainelli, sudipm.mukherjee,
	rwarsow, conor, hargar, broonie, achill, sr

On 9/9/26 6:34 AM, Greg Kroah-Hartman wrote:
> This is the start of the stable review cycle for the 7.2.5 release.
> There are 556 patches in this series, all will be posted as a response
> to this one.  If anyone has any issues with these being applied, please
> let me know.
> 
> Responses should be made by Fri, 11 Sep 2026 13:40:31 +0000.
> Anything received after that time might be too late.
> 
> The whole patch series can be found in one patch at:
> 	https://www.kernel.org/pub/linux/kernel/v7.x/stable-review/patch-7.2.5-rc1.gz
> or in the git tree and branch at:
> 	git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-7.2.y
> and the diffstat can be found below.
> 
> thanks,
> 
> greg k-h

Tested on 3 amd64 systems (my DIY home NAS, my Lenovo ThinkPad T14 Gen
1, and an Apple MacBook Air 13" 2017). Working well, no regressions
observed.

Tested-by: Barry K. Nathan <barryn@pobox.com>

-- 
-Barry K. Nathan  <barryn@pobox.com>

^ permalink raw reply	[flat|nested] 570+ messages in thread

* Re: [PATCH 7.2 000/556] 7.2.5-rc1 review
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (566 preceding siblings ...)
  2026-09-10 17:36 ` Barry K. Nathan
@ 2026-09-10 21:08 ` Benjamin Boortz
  2026-09-11  8:24 ` Peter Schneider
  568 siblings, 0 replies; 570+ messages in thread
From: Benjamin Boortz @ 2026-09-10 21:08 UTC (permalink / raw)
  To: Greg Kroah-Hartman
  Cc: stable, patches, linux-kernel, torvalds, akpm, linux, shuah,
	patches, lkft-triage, pavel, jonathanh, f.fainelli,
	sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr

On Wed, Sep 09, 2026 at 03:34:40PM +0200, Greg Kroah-Hartman wrote:

>This is the start of the stable review cycle for the 7.2.5 release.
>There are 556 patches in this series, all will be posted as a response
>to this one.  If anyone has any issues with these being applied, please
>let me know.

Build and boot tested with QEMU for x86_64, i386, arm64, and riscv
across multiple configurations, and boots on AMD Ryzen 7 5800H.
No regressions observed.

Tested-by: Benjamin Boortz <bennib@mailbox.org>

^ permalink raw reply	[flat|nested] 570+ messages in thread

* Re: [PATCH 7.2 000/556] 7.2.5-rc1 review
  2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
                   ` (567 preceding siblings ...)
  2026-09-10 21:08 ` Benjamin Boortz
@ 2026-09-11  8:24 ` Peter Schneider
  568 siblings, 0 replies; 570+ messages in thread
From: Peter Schneider @ 2026-09-11  8:24 UTC (permalink / raw)
  To: Greg Kroah-Hartman, stable
  Cc: patches, linux-kernel, torvalds, akpm, linux, shuah, patches,
	lkft-triage, pavel, jonathanh, f.fainelli, sudipm.mukherjee,
	rwarsow, conor, hargar, broonie, achill, sr

Am 09.09.2026 um 15:34 schrieb Greg Kroah-Hartman:
> This is the start of the stable review cycle for the 7.2.5 release.
> There are 556 patches in this series, all will be posted as a response
> to this one.  If anyone has any issues with these being applied, please
> let me know.

Builds, boots and works on my 2-socket Ivy Bridge Xeon E5-2697v2 server. No dmesg oddities or regressions found.

Tested-by: Peter Schneider <pschneider1968@googlemail.com>


Beste Grüße,
Peter Schneider

-- 
Climb the mountain not to plant your flag, but to embrace the challenge,
enjoy the air and behold the view. Climb it so you can see the world,
not so the world can see you.                    -- David McCullough Jr.

OpenPGP:  0xA3828BD796CCE11A8CADE8866E3A92C92C3FF244
Download: https://www.peters-netzplatz.de/download/pschneider1968_pub.asc
https://keys.mailvelope.com/pks/lookup?op=get&search=pschneider1968@googlemail.com
https://keys.mailvelope.com/pks/lookup?op=get&search=pschneider1968@gmail.com

^ permalink raw reply	[flat|nested] 570+ messages in thread

end of thread, other threads:[~2026-09-11  8:24 UTC | newest]

Thread overview: 570+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-09 13:34 [PATCH 7.2 000/556] 7.2.5-rc1 review Greg Kroah-Hartman
2026-09-09 13:34 ` [PATCH 7.2 001/556] net: skbuff: dont skb_tx_error() the source skb in skb_zerocopy() Greg Kroah-Hartman
2026-09-09 13:34 ` [PATCH 7.2 002/556] fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list() Greg Kroah-Hartman
2026-09-09 13:34 ` [PATCH 7.2 003/556] drm/xe: Dont hand out the flat CCS storage as usable VRAM Greg Kroah-Hartman
2026-09-09 13:34 ` [PATCH 7.2 004/556] mm/page_alloc: dont spin_trylock() in NMI on UP Greg Kroah-Hartman
2026-09-09 13:34 ` [PATCH 7.2 005/556] USB: gadget: ffs: fix mm lifetime handling Greg Kroah-Hartman
2026-09-09 13:34 ` [PATCH 7.2 006/556] usb: gadget: f_fs: Fix Use-After-Free in AIO error path Greg Kroah-Hartman
2026-09-09 13:34 ` [PATCH 7.2 007/556] zram: move lockmap to be per-zram instead per table Greg Kroah-Hartman
2026-09-09 13:34 ` [PATCH 7.2 008/556] zram: fix slot lock bit position on big-endian 64-bit Greg Kroah-Hartman
2026-09-09 13:34 ` [PATCH 7.2 009/556] ceph: properly decrypt filenames in vmalloc() buffers Greg Kroah-Hartman
2026-09-09 13:34 ` [PATCH 7.2 010/556] HID: sony: use guard() and scoped_guard() Greg Kroah-Hartman
2026-09-09 13:34 ` [PATCH 7.2 011/556] HID: sony: clean up device list on probe failure Greg Kroah-Hartman
2026-09-09 13:34 ` [PATCH 7.2 012/556] ACPI: battery: Use kstrtoul() over sscanf("%lu\n") Greg Kroah-Hartman
2026-09-09 13:34 ` [PATCH 7.2 013/556] ACPI: battery: Protect all properties with a separated mutex Greg Kroah-Hartman
2026-09-09 13:34 ` [PATCH 7.2 014/556] KVM: x86/mmu: Fold kvm_mmu_zap_memslot() into kvm_arch_flush_shadow_memslot() Greg Kroah-Hartman
2026-09-09 13:34 ` [PATCH 7.2 015/556] KVM: x86/mmu: Split kvm_mmu_zap_all_fast() into "front" and "back" halves Greg Kroah-Hartman
2026-09-09 13:34 ` [PATCH 7.2 016/556] KVM: x86/mmu: Use split "zap all fast" helpers when invalidating memslot Greg Kroah-Hartman
2026-09-09 13:34 ` [PATCH 7.2 017/556] KVM: SEV: Forcefully invalidate SNP VMSA if its backing gmem page is zapped Greg Kroah-Hartman
2026-09-09 13:34 ` [PATCH 7.2 018/556] NFSD: Annotate caller preconditions for the state-table walkers Greg Kroah-Hartman
2026-09-09 13:34 ` [PATCH 7.2 019/556] NFSD: Guard admin state-revocation walks with NFSD_NET_UP Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 020/556] NFSD: Prevent client use-after-free during export state revocation Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 021/556] NFSD: Consolidate the revocation-path client unpin Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 022/556] NFSD: Prevent client use-after-free during close_lru reaping Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 023/556] NFSD: Prevent client use-after-free during blocked-lock reaping Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 024/556] drm/amd/display: fix division by zero in get_estimated_bw() Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 025/556] usb: image: mdc800: change kmalloc() to kzalloc() Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 026/556] ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output() Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 027/556] clk: qcom: gcc-mdm9607: Increase delay for USB PHY reset Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 028/556] media: usbtv: keep device alive while ALSA card exists Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 029/556] usb-storage: ene_ub6250: fix race between scan work and probe Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 030/556] usb: cdnsp: fix wakeup from S3 after controller context loss Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 031/556] usb: f_mass_storage: Bump local buffer size in fsg_common_create_luns() Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 032/556] usb: dwc3: google: Initialise probe properties with DWC3_DEFAULT_PROPERTIES Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 033/556] usb: dwc3: clear forceRM when issuing EndTransfer Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 034/556] usb: storage: realtek_cr: fix use-after-free on disconnect Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 035/556] usb: typec: hd3ss3220: track VBUS enable state per consumer Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 036/556] usb: typec: mux: avoid duplicated mux switches Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 037/556] usb: typec: mux: Fix typec_switch_match() Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 038/556] usb: typec: qcom-pmic-typec: disable cc_debounce_dwork on stop Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 039/556] usb: typec: qcom-pmic-typec: drain cc_debounce_dwork if port_start() fails Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 040/556] usb: typec: qcom-pmic: cancel reset_work on stop Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 041/556] usb: typec: tcpm: constrain TCPM_SOURCING_VBUS event handling Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 042/556] usb: typec: tipd: Fix Thunderbolt altmode VDOs for cd321x Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 043/556] usb: typec: ucsi: displayport: Fix OOB altmode array index Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 044/556] usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 045/556] usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers() Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 046/556] usb: gadget: f_midi2: fix use-after-free in string attribute show path Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 047/556] usb: gadget: f_midi: initialize work in f_midi_alloc() Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 048/556] USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl() Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 049/556] usb: gadget: fix null pointer dereference in usb_put_function_instance() Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 050/556] staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr() Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 051/556] staging: rtl8723bs: fix OOB read in rtw_action_frame_parse() Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 052/556] staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie() Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 053/556] xhci: fix lost bounce buffers on TDs spanning several ring segments Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 054/556] thermal/drivers/imx: Disable clock on runtime resume failure Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 055/556] thermal/drivers/qoriq: Disable clock on " Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 056/556] tracing/probes: Fix anon_stack check for unnamed bitfields in btf_find_struct_member Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 057/556] tracing: Have show_event_filters/triggers files take trace array ref Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 058/556] tracing: Take trace_array reference when opening options file Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 059/556] userfaultfd: reset err to be 0 when move_pages_ptes succeeded Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 060/556] ublk: clear VM_MAYWRITE on read-only ublk char device mmap Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 061/556] soc: fsl: qe: Add chained_irq_{enter,exit}() calls in cascade handler Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 062/556] soc: qcom: geni-se: Use HW PROG_RAM_DEPTH to validate firmware size Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 063/556] spi: bcm63xx-hsspi: disable clocks on resume failure Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 064/556] spi: bcm63xx: disable clock " Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 065/556] spi: bcmbca-hsspi: disable clocks " Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 066/556] spi: Fix DMA mapping ownership on partial map failure Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 067/556] scsi: target: iscsi: Reserve a terminator byte for the login payload Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 068/556] scsi: bsg: Cap io_uring sense copy to max_response_len Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 069/556] scsi: bsg: Fix TOCTOU in io_uring passthrough command setup Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 070/556] scsi: megaraid_sas: Limit NVMe request size to the PRP chain frame Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 071/556] scsi: pm8001: Use rollback index when freeing MSI-X vectors Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 072/556] Docs/ABI/damon: fix typo in intervals_goal sysfs path Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 073/556] mm/damon/sysfs: read addr_unit only once in damon_sysfs_apply_inputs() Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 074/556] mm/damon/sysfs: read ops_id " Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 075/556] mm/damon/tests/core-kunit: catch test failure in test_merge_regions_of() Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 076/556] mm/damon/vaddr-kunit: check region count in three_regions test Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 077/556] samples/damon/mtier: handle damon_start() failure Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 078/556] samples/damon/mtier: handle damon_stop() failure Greg Kroah-Hartman
2026-09-09 13:35 ` [PATCH 7.2 079/556] samples/damon/prcl: handle damon_start() failure Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 080/556] samples/damon/prcl: stop and free damon ctx when damon_call() fails Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 081/556] samples/damon/wsse: handle damon_start() failure Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 082/556] samples/damon/wsse: stop and free damon ctx when damon_call() fails Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 083/556] mm/damon/sysfs-schemes: kobject_del() scheme action destination dirs Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 084/556] mm/damon/sysfs-schemes: kobject_del() scheme dirs Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 085/556] mm/damon/sysfs-schemes: kobject_del() scheme filter dirs Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 086/556] mm/damon/sysfs-schemes: kobject_del() scheme quota goal dirs Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 087/556] mm/damon/sysfs-schemes: kobject_del() scheme region dirs Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 088/556] mm/damon/sysfs: kobject_del() region and target (error) dirs Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 089/556] mm/damon/sysfs: kobject_del() target (normal), context and kdamond dirs Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 090/556] mm/damon/core-kunit: check region count before testing in split_at() Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 091/556] mm/damon/core-kunit: handle region split failure in filter_out() Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 092/556] mm/damon/core-kunit: skip wrong dest walk in commit_dests_for() Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 093/556] mm/damon/core-kunit: skip wrong quota goal walk in commit_quota_goals() Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 094/556] mm/damon/core-kunit: skip wrong region walk in commit_target_regions() Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 095/556] mm/damon/core: handle region split failure in apply_min_nr_regions() Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 096/556] mm/damon/core: initialize damos->last_applied Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 097/556] mm/secretmem: properly account locked pages Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 098/556] futex: Prevent rcuwait use-after-free during requeue PI Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 099/556] futex: Provide rt_mutex_.*_schedule() equivalents for futex scheduling Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 100/556] ftrace: Take trace_array reference before accessing its ftrace_ops Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 101/556] ftrace: Synchronize the initialization of ftrace_ops Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 102/556] HID: bpf: serialize device reference release in struct_ops destroy path Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 103/556] HID: rmi: fix OOB access with undersized RMI reports Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 104/556] HID: wacom: validate report length in wacom_intuos_pro2_bt_irq Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 105/556] dm: fix race when loading and unloading a table Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 106/556] dm: fix resume-vs-remove race Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 107/556] dma-buf: dma-heap: dont publish fd before copy_to_user() succeeds Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 108/556] dma-direct: return struct page from dma_direct_alloc_from_pool() Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 109/556] dmaengine: fsl-edma: tracing: no ptr dereference during log output Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 110/556] dmaengine: dw-edma: Fix HDMA channel status register access Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 111/556] dmaengine: dw-edma: Complete descriptors before pausing Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 112/556] dmaengine: dw-edma: Initialize IRQ data before requesting IRQs Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 113/556] dmaengine: dw-edma: Mark emulated IRQ as level-triggered Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 114/556] cpuidle: dt_idle_genpd: kfree() the original name allocation Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 115/556] cpuidle: psci: Fix support for probe deferral by dropping the faux device Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 116/556] block: flag zoned disks with GENHD_FL_NO_PART Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 117/556] bpf, riscv: Make arena support depend on ZACAS Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 118/556] bpf: Fix infinite loop in pcpu_freelist push with one possible CPU Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 119/556] ceph: lock mutex in ceph_mds_check_access() Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 120/556] ata: ahci: work around lost interrupts on Marvell 88SE61xx Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 121/556] ima: Check for ERR_PTR from dentry_path() in validate_hash_algo() Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 122/556] irqchip/stm32mp-exti: Fix the unit of the hwspinlock timeout Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 123/556] kprobes: Protect kprobe_blacklist with RCU Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 124/556] misc: fastrpc: dont publish fd before copy_to_user() succeeds Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 125/556] mm/huge_memory: transfer the pmd dirty bit to the folio on zap Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 126/556] mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave() Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 127/556] memcg: keep folios objcg same as its node Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 128/556] memcg: bypass the reclaim and oom killer for dying tasks once oom_reaper is done Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 129/556] memcg: make the v1 soft limit knob inert Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 130/556] rtc: rzn1: Handle EPROBE_DEFER for optional pps interrupt Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 131/556] rtc: rzn1: Fix weekday underflow when alarm crosses month boundary Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 132/556] rtc: rzn1: Handle unset alarm weekday in rzn1_rtc_read_alarm Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 133/556] rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 134/556] perf/x86/intel: Fix kernel address leakages in LBR stack Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 135/556] perf/x86/intel: Remove anythread_deprecated bit from perf_capabilities Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 136/556] perf trace: Factor out BPF loop body Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 137/556] perf trace: Refactor augmented_raw_syscalls using bpf_for Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 138/556] perf hisi-ptt: Fix PTT trace TLP header parsing Greg Kroah-Hartman
2026-09-09 13:36 ` [PATCH 7.2 139/556] perf build: Add clang and rust target flags for LoongArch Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 140/556] perf: Fix use-after-free when perf mmap() revival races with the last munmap() Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 141/556] i2c: designware: Enable interrupt mask workaround for HJMC3001 Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 142/556] i2c: qcom-geni: update frequency table to fix timing parameters Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 143/556] i2c: core: fix debugfs UAF on adapter removal Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 144/556] i2c: mux: Fix channel node leak on adapter add failure Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 145/556] i2c: qcom-cci: fix autosuspend cleanup Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 146/556] arm64: mm: Fix the lockless page-table walk in show_pte() Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 147/556] arm64: Dont read GMID_EL1 when MTE is disabled Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 148/556] arm64: errata: pass REVIDR when matching target implementation CPUs Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 149/556] ALSA: rawmidi: Return the error from snd_rawmidi_input_params() Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 150/556] ALSA: harmony: initialize locks before requesting IRQ Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 151/556] ALSA: pcm: Fix race between non-atomic ops and trigger-start Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 152/556] ring-buffer: Allow splice reads on static buffers Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 153/556] accel/amdxdna: return early from a zero-length flush Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 154/556] accel/ethosu: check MMIO mapping errors in probe Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 155/556] accel/ethosu: fix job completion fence cleanup Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 156/556] nvme-fabrics: fix DHCHAP secret leak on parse failure Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 157/556] nvme-fc: fix double free of fabrics options when nvme_add_ctrl() fails Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 158/556] nvme-tcp: check the data direction of a C2HData PDU Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 159/556] nvme: add missing SRCU grace period in error path Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 160/556] nvme: skip the zoned limits update if the zone info query failed Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 161/556] nvmet-auth: Synchronize timeout work during SQ teardown Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 162/556] nvmet-tcp: fix out-of-bounds write when receiving an over-long PDU Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 163/556] nvmet-tcp: reject unsolicited H2CData PDUs Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 164/556] pmdomain: airoha: fix unselectable AIROHA_CPU_PM_DOMAIN kconfig Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 165/556] Revert "irqchip/mbigen: Fix mbigen node address layout" Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 166/556] Revert "once: dont use a work queue to reset sleepable static key" Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 167/556] Revert "pmdomain: qcom: rpmhpd: Add missing MXC and MMCX power domains for Eliza" Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 168/556] mm: fix incorrect vm_flags usage when checking allowable orders for tmpfs Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 169/556] mm/migrate_device: avoid out-of-bounds writes for compound folios Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 170/556] mm/hugetlb: fix missing migratable flag on same-node hugetlb migration Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 171/556] mm/hugetlb_cma: fix null nodemask dereference in hugetlb_cma_alloc_frozen_folio Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 172/556] mm/hugetlb: keep max_huge_pages when dissolving surplus folios Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 173/556] mm/hugetlb_cgroup: call page_counter_set_max() outside VM_BUG_ON() Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 174/556] nvdimm/btt: reject an arena whose nfree is below the lane count Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 175/556] parisc: eisa: Fix infinite loop when parsing invalid IRQ value Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 176/556] parisc: Fix alignment of asm statements in head.S Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 177/556] powerpc/kexec_file: Fix null-ptr-def in extra size calculation Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 178/556] powerpc/kexec_file: Prevent kexec range truncation Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 179/556] powerpc/mm: fix wrong addr_pfn tracking in compound vmemmap population Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 180/556] powerpc/pseries: Handle and log pseries-wdt registration failures Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 181/556] powerpc/pseries: Move H_WATCHDOG definitions to a common header Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 182/556] powerpc/crash: stop watchdogs before booting kdump kernel Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 183/556] s390/vfio-ap: fix stale pqap_hook pointer on error in vfio_ap_mdev_set_kvm() Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 184/556] s390/vfio-ap: Fix stale do_remove flag across iterations in vfio_ap_mdev_cfg_remove Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 185/556] s390/vfio-ap: Fix control domain removal " Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 186/556] s390/vfio-ap: Fix dereference matrix_mdev->kvm without checking for NULL Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 187/556] s390/vfio-ap: Fix hot-unplug skipped when last AP adapter or domain removed Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 188/556] s390/vfio-ap: Fix missing lock required to access list of ap_matrix_mdev objects Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 189/556] s390/vfio-ap: Fix NULL deref in status_show() during queue probe Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 190/556] s390/vfio-ap: fix potential use of uninitialized apm_filtered bitmap Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 191/556] s390/vfio-ap: Fix required lock not held during update of ap_matrix_mdev object Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 192/556] mtd: afs: validate v2 image info bounds Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 193/556] mtd: mtdoops: free page bitmap when the backing MTD is removed Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 194/556] mtd: nand: realtek-ecc: add missing MODULE_DEVICE_TABLE() Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 195/556] mtd: rawnand: pl353: Make sure we use the monolithic helpers for raw accesses Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 196/556] mtd: rawnand: sunxi: group controller delay tables Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 197/556] mtd: rawnand: sunxi: describe tADL and tWHR delays Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 198/556] mtd: rawnand: sunxi: fix H6/H616 controller timings Greg Kroah-Hartman
2026-09-09 13:37 ` [PATCH 7.2 199/556] mtd: rawnand: validate ONFI extended parameter page sections Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 200/556] batman-adv: fix stale receive device on merged fragments Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 201/556] batman-adv: fix TX priority extraction for BATADV_FORW_MCAST Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 202/556] batman-adv: mcast: ensure unshared skb for multicast packets Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 203/556] batman-adv: mcast: linearize skbuff for packet generation Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 204/556] batman-adv: dat: avoid unaligned fault in IP extraction Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 205/556] batman-adv: bla: fix freeing of claims on meshif deletion Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 206/556] batman-adv: bla: prevent CRC corruptions after claim flush Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 207/556] clk: clocking-wizard: fix integer overflow in rate calculation Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 208/556] clk: mediatek: mt8196: Select REGMAP_MMIO for vlpckgen Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 209/556] clk: meson: align gxbb_32k_clk_sel number of parents with actual count Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 210/556] clk: microchip: mpfs: fix regmap_update_bits() mask/val order Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 211/556] clk: qcom: gcc-msm8916: Fix enable_reg for gcc_blsp1_sleep_clk Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 212/556] clk: qcom: gcc-msm8939: " Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 213/556] clk: rockchip: rk3588: Dont change PLL rates when setting dclk_vop2_src Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 214/556] clk: qcom: gcc-mdm9607: Drop incorrect apss_tcu_clk_src Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 215/556] clk: qcom: gcc-mdm9607: Drop incorrect system_noc_bfdcd_clk_src Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 216/556] clk: qcom: gcc-mdm9607: Fix enable_reg for gcc_blsp1_sleep_clk Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 217/556] clk: qcom: gcc-mdm9607: Fix halt_reg for gcc_apss_axi_clk Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 218/556] clk: qcom: gcc-mdm9607: Drop incorrect BIMC PLL and related clocks Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 219/556] i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 220/556] ASoC: adau1761: sort the register default table Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 221/556] ASoC: cs35l33: drain threaded IRQ before runtime suspend Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 222/556] ASoC: cs35l34: " Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 223/556] ASoC: cx2072x: sort the register default table Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 224/556] ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 225/556] ASoC: fsl_easrc: Use div64_u64 for 64-by-64 division Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 226/556] ASoC: fsl_easrc: sort the register default table Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 227/556] ASoC: hdac_hda: Fix hlink refcount leak on component registration failure Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 228/556] AsoC: intel: sst: fix PCI device reference leak on probe failure Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 229/556] ASoC: loongson: Fix error handling in ACPI property parsing Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 230/556] ASoC: max9860: sort the register default table Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 231/556] ASoC: ml26124: " Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 232/556] ASoC: pcm512x: " Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 233/556] ASoC: pm4125-sdw: " Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 234/556] ASoC: rt1017-sdca-sdw: " Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 235/556] ASoC: rt1316-sdw: " Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 236/556] ASoC: rt1318-sdw: " Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 237/556] ASoC: rt1318: " Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 238/556] ASoC: rt274: " Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 239/556] ASoC: rt286: " Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 240/556] ASoC: rt298: " Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 241/556] ASoC: rt700: drop duplicate reg_default entry Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 242/556] ASoC: rt700: sort the register default table Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 243/556] ASoC: rt711-sdca: sort the register default tables Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 244/556] ASoC: rt711: sort the register default table Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 245/556] ASoC: rt712-sdca-dmic: " Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 246/556] ASoC: rt712-sdca-sdw: " Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 247/556] ASoC: rt715-sdca: drop duplicate reg_default entries Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 248/556] ASoC: rt715-sdca: sort the register default tables Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 249/556] ASoC: rt715: sort the register default table Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 250/556] ASoC: rt721-sdca-sdw: " Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 251/556] ASoC: samsung: aries_audio_probe: double of_node_put due to direct assignment without of_node_get Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 252/556] ASoC: sgtl5000: sort the register default table Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 253/556] ASoC: sti-sas: " Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 254/556] ASoC: tas2552: " Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 255/556] ASoC: tas2764: " Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 256/556] ASoC: tas2780: " Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 257/556] ASoC: tas2783-sdw: drop duplicate reg_default entry Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 258/556] ASoC: tas2783-sdw: sort the register default table Greg Kroah-Hartman
2026-09-09 13:38 ` [PATCH 7.2 259/556] iio: adc: ad4080: configure backend data size Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 260/556] iio: adc: adi-axi-adc: add data size support for AD408X backend Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 261/556] iio: adc: max14001: add missing select REGMAP to Kconfig Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 262/556] iio: adc: max34408: add missing select REGMAP_I2C " Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 263/556] iio: adc: pac1921: fix wrong channel used in trigger handler read Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 264/556] iio: buffer: Fix potential use-after-free in anonymous buffer release Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 265/556] iio: buffer: Make IIO DMA fence release RCU-safe Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 266/556] iio: buffer: Tie IIO dma fence lock lifetime to the fence Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 267/556] iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 268/556] iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 269/556] iio: chemical: sgp30: Handle IAQ thread creation failure Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 270/556] iio: dac: ad3552r-hs: fix scnprintf() buffer bound in data source show Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 271/556] iio: dac: ad5446: fix OF module device table Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 272/556] iio: dac: m62332: Fix regulator reference count imbalance Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 273/556] iio: dac: mcp47feb02: add missing select REGMAP_I2C to Kconfig Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 274/556] iio: gyro: mpu3050: fix sign of raw angular velocity readings Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 275/556] iio: imu: st_lsm6dsx: Update enable mask when using sensor fusion Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 276/556] iio: light: apds9306: fix PM reference leak in apds9306_read_data() Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 277/556] iio: light: cm32181: return zero after writing calibscale Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 278/556] iio: light: gp2ap002: Disable regulators on resume failure Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 279/556] iio: light: ltrf216a: fix runtime PM reference leak in error path Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 280/556] iio: pressure: dps310: fix NULL pointer dereference on ACPI probe Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 281/556] iio: pressure: mpl115: Fix runtime PM cleanup Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 282/556] iio: srf04: fix pm_runtime handling on probe error path Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 283/556] iio: temperature: hid-sensor-temperature: switch to non-devm iio_device_register() Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 284/556] iio: ti-ads7138: Disable STATS_EN bit while reading conversion results Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 285/556] iio: light: opt4060: Reject integration times with a non-zero seconds part Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 286/556] iio: light: opt4060: Fix incorrect register name in threshold read error message Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 287/556] iio: light: opt4001: Fix power down clearing bits of the wrong register Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 288/556] iio: light: opt4001: Fix incompatible pointer type passed to div_u64_rem() Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 289/556] iio: light: opt4001: Reject integration times with a non-zero seconds part Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 290/556] iio: light: opt4001: Fix reversed GENMASK() arguments in fault count mask Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 291/556] KVM: PPC: Book3S HV: Validate arch_compat against host compatibility mode Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 292/556] KVM: nVMX: Always flush vpid02 on first use Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 293/556] KVM: nVMX: Decouple INVVPID operand checks from flushing of vpid02 Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 294/556] KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 295/556] KVM: nVMX: Service local TLB flushes on failed nested VM-Enter Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 296/556] KVM: nVM: Ensure INVVPID is emulated on the correct physical CPU Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 297/556] KVM: x86/mmu: Use CMPXCHG when clearing Accessed bit in TDP MMU Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 298/556] KVM: x86/mmu: Consume the locked rmap value in the lockless rmap walk Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 299/556] KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 300/556] KVM: x86: Serialize writes to disabled_quirks using kvm->lock Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 301/556] KVM: x86: Ensure runtime reads of disabled_quirks are resolved once Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 302/556] KVM: x86: Move enabling EFER.SVME and EFER.LMSLE to generic EFER setup Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 303/556] KVM: s390: Fix length check __import_wp_info() Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 304/556] KVM: s390: Fix memory leak in guest debug handling Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 305/556] KVM: s390: Fix old_data leak in guest debug error path Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 306/556] KVM: s390: Free guest debug data on vcpu destroy Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 307/556] KVM: s390: Take srcu when importing watchpoint data Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 308/556] KVM: s390: Zero initialize data structures for inject_pfault_token Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 309/556] KVM: s390: Zero initialize irq in reinject_machine_check Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 310/556] KVM: s390: Fix memory corruption by not reinjecting CK machine checks Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 311/556] KVM: s390: keyop: use mmu_lock to read gmap->asce Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 312/556] KVM: s390: pv: Fix rc/rrc offset for PVM_DUMP Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 313/556] KVM: s390: Restore sigset on error path Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 314/556] KVM: arm64: Consider SCTLR_EL2.M when mapping the L1 VNCR page Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 315/556] KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 316/556] KVM: arm64: Correctly handle end of VA space TLBI invalidation Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 317/556] KVM: arm64: Handle VNCR TLB invalidation race with vcpu_put() VNCR unmapping Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 318/556] KVM: arm64: Make VNCR invalidation participate in MMU invalidation retry Greg Kroah-Hartman
2026-09-09 13:39 ` [PATCH 7.2 319/556] KVM: arm64: Remove VM-wide VNCR mapping counter Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 320/556] KVM: arm64: Sign-extend VA for range-based TLBI invalidation Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 321/556] KVM: arm64: vgic-v3: take an LPI reference in vgic_v3_save_pending_tables Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 322/556] KVM: arm64: vgic: Fix detection of MI on no pending LR Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 323/556] KVM: arm64: vgic: Reset in_kernel on private IRQ allocation failure Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 324/556] KVM: arm64: vgic-its: Dont dereference a NULL collection on ITT save Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 325/556] KVM: arm64: Correctly cap TLBI Range to the architural limit Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 326/556] LoongArch: KVM: Set vcpu->cpu before IN_GUEST_MODE is set Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 327/556] LoongArch: KVM: Fix uninitialized stack variable issue with dmsintc Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 328/556] LoongArch: KVM: Fix PC double advance in kernel MMIO read fast path Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 329/556] LoongArch: KVM: Add unregister helpers for the KVM interrupt devices Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 330/556] LoongArch: KVM: Fix resource leak in kvm_loongarch_env_init() error path Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 331/556] LoongArch: KVM: Fix TOCTOU race on pv_features Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 332/556] LoongArch: KVM: Free init resources if kvm_init() fails Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 333/556] LoongArch: KVM: Preserve memslot arch flags on KVM_MR_FLAGS_ONLY Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 334/556] LoongArch: KVM: Validate MSI data before routing it to EIOINTC Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 335/556] LoongArch: Add DIRECT_MAP_PHYSMEM_END definition Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 336/556] LoongArch: BPF: Optimize redundant TCC loads in epilogue Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 337/556] LoongArch: BPF: Refactor jump offset calculation in tail call Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 338/556] LoongArch: Expand module virtual address space to 2GB Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 339/556] LoongArch: BPF: Move arena register slot below TCC context Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 340/556] LoongArch: BPF: Fix off-by-one error for insn_is_cast_user() Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 341/556] LoongArch: Fix acpi_package_ids[] array overflow Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 342/556] LoongArch: Do not select HAVE_RUST when KASAN is enabled Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 343/556] LoongArch: Do not save/restore percpu base register in rethook trampoline Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 344/556] LoongArch: Avoid preempt count underflow without probe Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 345/556] rust: drm: ioctl: fix unbounded lifetimes in ioctl handler arguments Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 346/556] media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 347/556] media: amphion: Remove obsolete frame_count check in venc_start_session Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 348/556] media: bcm2835-unicam: Fix pipeline wrong validation for unpacked formats Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 349/556] media: cec: core: Fix kmemleak due to missed rc_free_device() call Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 350/556] media: cec: disable delayed work before freeing an interrupted transmit Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 351/556] media: cec: extron-da-hd-4k-plus: add sanity check Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 352/556] media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid debugfs clash Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 353/556] media: cec: Serialize exclusive follower delivery Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 354/556] media: cedrus: fix memory leak in cedrus_init_ctrls() Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 355/556] media: cobalt: Avoid freeing ALSA private data twice Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 356/556] media: cx231xx: reject geometry changes while the VBI queue is busy Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 357/556] media: cx23885: cancel NetUP CI work before teardown Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 358/556] media: dt-bindings: nxp,imx8-isi: Drop fsl,blk-ctrl requirement for i.MX8ULP Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 359/556] media: em28xx: defer audio-only extension registration Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 360/556] media: em28xx: fix use-after-free of dev_next->devlist on disconnect Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 361/556] media: go7007: defer the ALSA v4l2 put until card release Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 362/556] media: i2c: alvium: Fix: Correct name of register in alvium_set_ctrl_auto_exposure Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 363/556] media: i2c: imx415: Release runtime PM reference on VBLANK error Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 364/556] media: i2c: imx415: Return test pattern write errors Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 365/556] media: i2c: ov02a10: fix endpoint parsing use-after-free Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 366/556] media: i2c: ov7740: fix use-after-destroy in remove Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 367/556] media: i2c: ov9282: restore flash duration calculation Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 368/556] media: i2c: vd55g1: Fix manual digital gain on color variant Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 369/556] media: i2c: vd55g1: Fix media bus code initialization Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 370/556] media: imx355: Avoid calling imx355_power_off twice in error path Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 371/556] media: intel/ipu6: fix async notifier cleanup leak on parse error Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 372/556] media: ipu-bridge: check all DMI entries when overriding sensor rotation Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 373/556] media: iris: Enumerate cap->bus_info to differentiate between encoder and decoder Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 374/556] media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 375/556] media: platform: mtk-mdp3: Fix SCP device refcounting Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 376/556] media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 377/556] media: nxp: imx8-isi: Fix stream ID validation bypass in crossbar routing Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 378/556] media: nxp: imx8-isi: Correct color map between V4L2 and ISI Greg Kroah-Hartman
2026-09-09 13:40 ` [PATCH 7.2 379/556] media: nxp: imx8-isi: Use BIT_ULL() for 64-bit stream masks Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 380/556] media: mali-c55: fix dropped last AEC histogram zone weight Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 381/556] media: mali-c55: Fix clock leak on reset deassert failure Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 382/556] media: mali-c55: Fix AEXP IHIST disable bit shift Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 383/556] media: mali-c55: Fix scaler factor overflow for large crop sizes Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 384/556] media: rc: sunxi-cir: Unregister rc device on probe failure Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 385/556] media: rockchip: rga: dont change RGB quantization Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 386/556] media: rkvdec: Propagate platform_get_irq() errors Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 387/556] media: rkvdec: hevc: tighten EXT SPS RPS control dimensions Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 388/556] media: rkvdec: hevc: guard INTER_REF_PIC_SET_PRED index underflow Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 389/556] media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 390/556] media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 391/556] media: rzg2l-cru: Align bytesperline to hardware DMA stride requirement Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 392/556] media: s2255: bound JPEG frame size before copying into the buffer Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 393/556] media: s2255: check firmware size before reading trailing marker Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 394/556] media: saa7164: fix cleanup on resource allocation failure Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 395/556] media: tda18250: fix possible integer overflow Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 396/556] media: ti: vpe: quiesce overflow recovery before freeing streams Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 397/556] media: v4l2-async: avoid deleting unlinked ASC entry on link error Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 398/556] media: v4l2-ctrls: validate HEVC EXT SPS RPS counts Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 399/556] media: v4l2-ctrls: Allow unknown HDR10 white point and luminance Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 400/556] media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 401/556] media: venus: fix payload size returned by parse_caps() and parse_alloc_mode() Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 402/556] media: venus: fix payload size calculation in parse_raw_formats() Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 403/556] media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 404/556] media: vimc: fix pixel format lookup in enum_framesizes Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 405/556] media: zoran: Avoid freeing a registered video_device twice Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 406/556] media: qcom: iris: fix state-change debug log printing stale value Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 407/556] media: qcom: iris: use disable_irq() during power-off Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 408/556] media: qcom: iris: fix missing hfi_id in gen1 GOP_SIZE cap Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 409/556] media: chips-media: wave5: Guard bit depth check with initial_info_obtained Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 410/556] media: chips-media: wave5: Set inst->std during default format initialization Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 411/556] media: chips-media: wave5: avoid skipping device_run while VPU has work Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 412/556] media: chips-media: wave5: Add timeout while stop_streaming Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 413/556] media: chips-media: wave5: Defer job_finish() only when a DEC_PIC was queued Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 414/556] media: chips-media: wave5: Fix pipeline stall when queuing fails Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 415/556] media: chips-media: wave5: Resume device before setting EOS flag Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 416/556] scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 417/556] scsi: qla2xxx: Bound i2c->length in I2C " Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 418/556] scsi: qla2xxx: edif: Fix NULL pointer deref in RX SA delete check Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 419/556] scsi: qla2xxx: Fix Name Server logout detection on FWI2 adapters Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 420/556] scsi: qla2xxx: Fix BSG job leak on validate flash image error path Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 421/556] scsi: qla2xxx: Hold vport reference in qla24xx_report_id_acquisition() Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 422/556] scsi: qla2xxx: Initialize NVMe abort_work once at submission Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 423/556] scsi: qla2xxx: Check entry_status in qla24xx_modify_vp_config() Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 424/556] scsi: qla2xxx: Zero dport diagnostics buffer to avoid info leak Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 425/556] scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions() Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 426/556] scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 427/556] scsi: qla2xxx: Clamp MSI-X derived queue counts to avoid truncation Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 428/556] scsi: qla2xxx: Serialize flash version read in reset handler Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 429/556] scsi: qla2xxx: Fix cs84xx use-after-free on host teardown Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 430/556] scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 431/556] scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state() Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 432/556] scsi: qla2xxx: Fix FCE trace enable parsing in debugfs Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 433/556] scsi: qla2xxx: Dont query firmware state while chip is down Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 434/556] scsi: qla2xxx: Reject non-SCSI SRB on status IOCB fast path Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 435/556] scsi: qla2xxx: Fix response queue over-consumption in __qla_consume_iocb() Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 436/556] scsi: qla2xxx: Quiesce response IRQ before freeing request queue Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 437/556] scsi: qla2xxx: Avoid double completion in async IOCB timeout Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 438/556] scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read Greg Kroah-Hartman
2026-09-09 13:41 ` [PATCH 7.2 439/556] scsi: qla2xxx: Avoid req_q_map double-read in qla2x00_error_entry() Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 440/556] scsi: qla2xxx: Fix NVMe abort reference leak on repeated abort Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 441/556] scsi: qla2xxx: Drop vport reference under lock in report ID acquisition Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 442/556] scsi: qla2xxx: Hold vport_slock for host map update " Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 443/556] scsi: qla2xxx: Use coherent DMA buffer for D_Port diagnostics Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 444/556] scsi: qla2xxx: Zero-init bsg stack buffers to avoid info leak Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 445/556] scsi: qla2xxx: Skip NVMe LS reject IOCB when FW not started Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 446/556] f2fs: return symlink writeback errors Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 447/556] f2fs: reject overlapping move range after len expansion Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 448/556] f2fs: only redirty pinned folios in redirty_blocks Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 449/556] f2fs: fix to avoid move_range and defragment on device_alias file Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 450/556] f2fs: validate MOVE_RANGE destination size Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 451/556] f2fs: dirty directory inodes on mtime/ctime update Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 452/556] f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set() Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 453/556] f2fs: return writeback error from collapse range Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 454/556] f2fs: limit recovery filename logging to stored length Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 455/556] f2fs: dont drop the top folio order in the f2fs_iostat tracepoint Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 456/556] f2fs: fix to avoid potential section-unaligned pinfile Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 457/556] f2fs: embed f2fs_gc_kthread in f2fs_sb_info Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 458/556] f2fs: fix dentry folio leak in find_in_level Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 459/556] f2fs: fix folio_nr_pages() race after put in large folio invalidate Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 460/556] f2fs: avoid NULL checkpoint thread access in sysfs Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 461/556] f2fs: fix to migrate all curseg types during free_segment_range Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 462/556] f2fs: fix to avoid potential deadloop in f2fs_fsync_node_pages() Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 463/556] f2fs: fix i_size when pinned fallocate partially fails Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 464/556] f2fs: fix to return -EFSCORRUPTED in f2fs_get_node_info() correctly Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 465/556] f2fs: fix to off-by-one issue in f2fs_zero_post_eof_page() Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 466/556] f2fs: fix to clear dirty flag on folio in error path Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 467/556] f2fs: protect critical_task_priority updates with s_umount Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 468/556] f2fs: fix valid block count leak on data block allocation failure Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 469/556] f2fs: fix to reclaim space in f2fs_allocate_pinning_section() Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 470/556] f2fs: fix to pass folio->index to f2fs_sanity_check_node_footer() Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 471/556] f2fs: fix to zero post-EOF data when extending file size Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 472/556] drm/amdgpu: Fix init ordering in amdgpu_vram_mgr_init() Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 473/556] drm/amdgpu: avoid force-completing uninitialized UVD rings Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 474/556] drm/xe/vram: report FLAT_CCS base misalignment Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 475/556] drm/panthor: harden firmware build-info bounds checks Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 476/556] drm/panthor: fix firmware control interface " Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 477/556] drm/bridge: dw-hdmi: fix i2c adapter leak on probe failure Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 478/556] drm/panel-edp: " Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 479/556] drm: fix race between partial drm_dev_register() failure and ioctl Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 480/556] drm/i915/display: Clear SEL_FETCH_PLANE_CTL on plane disable Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 481/556] drm/i915: Guard against NULL driver_data in i915_pci_probe() Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 482/556] drm/ssd130x: fix column and row end address in partial updates for ssd132x Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 483/556] drm/sun4i: fix refcount leak in sun4i_backend_init_sat() Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 484/556] drm/ssd130x: fix column and row end address in partial updates in ssd133x Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 485/556] drm/nouveau/disp/r535: Add scanline position support + head state support Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 486/556] drm/hibmc: Fix list of formats on the primary plane Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 487/556] drm/hibmc: Use drm_atomic_helper_check_plane_state() Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 488/556] drm/amd/display: avoid divide-by-zero in __is_lut_linear() Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 489/556] drm/amd/display: fix dc_lock leak on GPU reset error paths Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 490/556] drm/amd/display: Fix HPD consideration for VGA/LVDS connectors on DCE Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 491/556] drm/amd/display: validate plane degamma LUT size for private color prop Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 492/556] drm/amd/display: Remove const Qualifier From Non-Pointer Fields Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 493/556] drm/amd/display: Set gpuvm min page size to 4K on dcn35/36 Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 494/556] drm/amdgpu/gfx8: only apply compute quantums to KCQs Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 495/556] drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 496/556] drm/gud: NUL-terminate TV mode names read from the device Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 497/556] drm/gud: validate TV mode names before creating enum property Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 498/556] drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value Greg Kroah-Hartman
2026-09-09 13:42 ` [PATCH 7.2 499/556] drm: Fix drm_crtc_commit leak if signaled when PAGE_FLIP_EVENT is used Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 500/556] drm/ttm: Drop tt->restore after successful restore Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 501/556] drm/amdgpu: check thunderbolt before switcheroo registration Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 502/556] drm/amdgpu: delay ttm buffer func enablement on xgmi Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 503/556] drm/amdgpu: clamp the isolation index for rings outside a partition Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 504/556] drm/amdgpu: Disable runtime PM for externally attached dGPUs Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 505/556] drm/amdgpu: fix autosuspend cleanup during removal Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 506/556] drm/amdgpu: fix byte/dword unit mismatch in coredump IB dump Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 507/556] drm/amdgpu: fix Idle BOs list in VM debugfs status info Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 508/556] drm/amdgpu: force complete the KIQ ring fences on reset Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 509/556] drm/amdgpu: force complete the MES " Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 510/556] drm/amdgpu: Skip accessing psp rum time db for APUs Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 511/556] drm/amdgpu: update the fw version for gfx11 userqueues Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 512/556] drm/amdgpu: update the fw version for gfx12 userqueues Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 513/556] drm/amdgpu: use AMDGPU_GPU_PAGE_SHIFT instead of PAGE_SHIFT Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 514/556] drm/amdkfd: Add TLB flush after MES queue eviction/suspension Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 515/556] drm/amdkfd: Fix error path at svm_migrate_copy_to_ram Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 516/556] drm/amdkfd: fix scope of mqd_mgr dereference in pqm_debugfs_mqds Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 517/556] drm/amdkfd: Fix the case that vm range is hole at svm_migrate_copy_to_vram Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 518/556] drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 519/556] drm/amdkfd: Reject zero-sized AQL queue allocations after size halving Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 520/556] drm/sysfb: simpledrm: Improve framebuffer-size validation Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 521/556] drm/sysfb: simpledrm: Improve panel-size validation Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 522/556] drm/sysfb: simpledrm: Improve stride validation Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 523/556] drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 524/556] drm/sysfb: ofdrm: Fix is_avivo() constant comparison bug Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 525/556] drm/pagemap: Fix folio allocation fallback and use-after-put Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 526/556] drm/nouveau/dmem: fix callocated underflow on large folio split Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 527/556] drm/nouveau/dmem: fix mismatched DMA unmap size for large folios Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 528/556] drm/nouveau/gsp: use per-version DP_CONFIG_STREAM params on r570 firmware Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 529/556] drm/nouveau: unsubscribe the channel-kill event before the fence context Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 530/556] drm/nouveau: Use write-combined maps for coherent Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 531/556] drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 532/556] drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 533/556] drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 534/556] drm/nouveau/disp: move GSP head-timing ISR and vblank helpers to tu102.c Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 535/556] drm/nouveau/disp: move the GSP HDMI GCP AVMute write to engine/disp Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 536/556] drm/nouveau/disp: route GSP-RM display MMIO through nvkm_disp_func hooks Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 537/556] drm/nouveau/disp: fix HDMI vendor infoframes on GB20x Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 538/556] drm/nouveau/disp: fix HDMI GCP AVMute register offsets " Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 539/556] drm/nouveau/disp: fix head state readback " Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 540/556] drm/nouveau/gsp: fix vblank interrupts " Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 541/556] ksmbd: fix use-after-free in oplock break notification Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 542/556] bpf: Factor stackid_init function from __bpf_get_stackid Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 543/556] bpf: Factor stackid_fastpath " Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 544/556] bpf: Factor stackid_new_bucket " Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 545/556] bpf: Use stack id functions instead of __bpf_get_stackid Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 546/556] bpf: Disable preemption in bpf_get_stackid Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 547/556] rpcrdma: arm rn_done before publishing the notification Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 548/556] remoteproc: qcom: pas: Guard dtb metadata release with dtb_pas_id check Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 549/556] power: supply: ab8500_fg: Remove redundant dev_err()/dev_err_probe() Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 550/556] power: supply: ab8500_fg: fix use-after-free on remove Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 551/556] mm/damon/core: avoid infinite kdamond_merge_regions() internal loop Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 552/556] mm/damon/ops-common: use nr_accesses moving sum for quota score Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 553/556] mm/damon/paddr: drop last same folio access check reuse optimization Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 554/556] mm/damon/vaddr: drop last same folio access check optimization Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 555/556] PCI: Introduce PCI_SLOT_PLACEHOLDER constant for slot_nr placeholder value Greg Kroah-Hartman
2026-09-09 13:43 ` [PATCH 7.2 556/556] PCI: Allow per function PCI slots to fix slot reset on s390 Greg Kroah-Hartman
2026-09-09 15:51 ` [PATCH 7.2 000/556] 7.2.5-rc1 review Ronald Warsow
2026-09-09 16:06 ` Brett A C Sheffield
2026-09-09 18:44 ` Florian Fainelli
2026-09-09 22:23 ` Shuah Khan
2026-09-09 22:52 ` Miguel Ojeda
2026-09-09 23:08 ` Takeshi Ogasawara
2026-09-10 12:07 ` Dileep malepu
2026-09-10 12:23 ` Wentao Guan
2026-09-10 13:51 ` Justin Forbes
2026-09-10 14:57 ` Ron Economos
2026-09-10 17:36 ` Barry K. Nathan
2026-09-10 21:08 ` Benjamin Boortz
2026-09-11  8:24 ` Peter Schneider

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).