* [PATCH 6.18 0000/1518] 6.18.52-rc1 review
@ 2026-09-12 6:36 Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0001/1518] net/mlx5e: xsk: Fix unlocked writing to ICOSQ Greg Kroah-Hartman
` (998 more replies)
0 siblings, 999 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, linux-kernel, torvalds, akpm, linux,
shuah, patches, lkft-triage, pavel, jonathanh, f.fainelli,
sudipm.mukherjee, rwarsow, conor, hargar, broonie, achill, sr
This is the start of the stable review cycle for the 6.18.52 release.
There are 1518 patches in this series, all will be posted as a response
to this one. If anyone has any issues with these being applied, please
let me know.
Responses should be made by Mon, 14 Sep 2026 06:54:17 +0000.
Anything received after that time might be too late.
The whole patch series can be found in one patch at:
https://www.kernel.org/pub/linux/kernel/v6.x/stable-review/patch-6.18.52-rc1.gz
or in the git tree and branch at:
git://git.kernel.org/pub/scm/linux/kernel/git/stable/linux-stable-rc.git linux-6.18.y
and the diffstat can be found below.
thanks,
greg k-h
-------------
Pseudo-Shortlog of commits:
Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Linux 6.18.52-rc1
Arnd Bergmann <arnd@arndb.de>
wifi: mt76: fix airoha_npu dependency tracking
Salman Alghamdi <me@cipherat.com>
staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction
Shyam Sunder Reddy Padira <shyamsunderreddypadira@gmail.com>
staging: rtl8723bs: os_dep: avoid NULL pointer dereference in rtw_cbuf_alloc
Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
pinctrl: airoha: an7583: add missed gpio22 pin group
Tony W Wang-oc <TonyWWang-oc@zhaoxin.com>
ACPI: processor: Add cpuidle driver check in acpi_processor_register_idle_driver()
Huisong Li <lihuisong@huawei.com>
ACPI: processor: idle: Remove redundant static variable and rename cstate check function
Huisong Li <lihuisong@huawei.com>
ACPI: processor: idle: Move max_cstate update out of the loop
Huisong Li <lihuisong@huawei.com>
ACPI: processor: idle: Remove redundant cstate check in acpi_processor_power_init
K Prateek Nayak <kprateek.nayak@amd.com>
cpufreq/amd-pstate: Allow writes to dynamic_epp when state isn't modified
K Prateek Nayak <kprateek.nayak@amd.com>
cpufreq/amd-pstate: Use "epp_default_dc" as default when dynamic_epp is disabled
Mario Limonciello (AMD) <superm1@kernel.org>
cpufreq/amd-pstate: Add support for raw EPP writes
Mario Limonciello (AMD) <superm1@kernel.org>
cpufreq/amd-pstate: Add static asserts for EPP indices
Mario Limonciello (AMD) <superm1@kernel.org>
cpufreq/amd-pstate: Fix some whitespace issues
Jens Axboe <axboe@kernel.dk>
io_uring/waitid: fix KCSAN warning on io_waitid->head
Jens Axboe <axboe@kernel.dk>
io_uring/waitid: use io_waitid_remove_wq() consistently
Jamal Hadi Salim <jhs@mojatatu.com>
net/sched: fq: clamp quantum and initial_quantum in change path
Arnd Bergmann <arnd@arndb.de>
Bluetooth: btmtk: hide unused btmtk_mt6639_devs[] array
Pavel Begunkov <asml.silence@gmail.com>
tcp: reject non zerocopy devmem tx
Kuniyuki Iwashima <kuniyu@google.com>
ipmr: Add __rcu to netns_ipv4.mrt.
Kuniyuki Iwashima <kuniyu@google.com>
ipmr: Call ipmr_fib_lookup() under RCU.
Zhan Xusheng <zhanxusheng@xiaomi.com>
erofs: fix EFSCORRUPTED on multi-algorithm images in z_erofs_map_sanity_check()
Gao Xiang <xiang@kernel.org>
erofs: relax sanity check for tail pclusters due to ztailpacking
Keith Busch <kbusch@kernel.org>
block: fix merging data-less bios
Keith Busch <kbusch@kernel.org>
blk-mq-dma: always initialize dma state
Keith Busch <kbusch@kernel.org>
block: save page offset gaps in cloned bio
Nathan Chancellor <nathan@kernel.org>
integrity: Eliminate weak definition of arch_get_secureboot()
John Johansen <john.johansen@canonical.com>
apparmor: fix kernel-doc comments for inview
Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
pinctrl: airoha: an7581: fix incorrect led mapping in phy4_led1 pin function
Nathan Chancellor <nathan@kernel.org>
pinctrl: airoha: Fix AIROHA_PINCTRL_CONFS_DRIVE_E2 in an7583_pinctrl_match_data
Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
pinctrl: airoha: an7583: add missed gpio32 pin group
Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
pinctrl: airoha: an7583: fix misprint in gpio19 pinconf
Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
pinctrl: airoha: an7583: fix incorrect led mapping in phy4_led1 pin function
Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
pinctrl: airoha: an7583: fix gpio21 pin group
Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
pinctrl: airoha: an7583: fix phy1_led1 pin function
Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
pinctrl: airoha: an7583: remove undefined groups from pcm_spi pin function
Yang Xiuwei <yangxiuwei@kylinos.cn>
scsi: sd: Fix error handling in sd_probe() after large pool creation failure
Arnd Bergmann <arnd@arndb.de>
phy: renesas: rcar-gen3-usb2: add regulator dependency
Namhyung Kim <namhyung@kernel.org>
perf annotate: Fix build with NO_SLANG=1
Johannes Berg <johannes.berg@intel.com>
wifi: nl80211: fix UHR capability validation
Lorenzo Bianconi <lorenzo@kernel.org>
wifi: mt76: npu: Add missing rx_token_size initialization
Devin Wittmayer <lucid_duck@justthetip.ca>
wifi: mt76: restrict NPU/PPE active checks to MMIO devices
Heiko Carstens <hca@linux.ibm.com>
s390/entry: Use lay instead of aghik
Vasily Gorbik <gor@linux.ibm.com>
s390/kexec: Disable stack protector in s390_reset_system()
Thomas Weißschuh <thomas.weissschuh@linutronix.de>
selftests: vDSO: getrandom: Fix path to s390 chacha implementation
Mario Limonciello (AMD) <superm1@kernel.org>
cpufreq/amd-pstate: Fix setting EPP in performance mode
Mario Limonciello <mario.limonciello@amd.com>
cpufreq/amd-pstate: Add POWER_SUPPLY select for dynamic EPP
K Prateek Nayak <kprateek.nayak@amd.com>
cpufreq/amd-pstate: Grab "amd_pstate_driver_lock" when toggling dynamic_epp
K Prateek Nayak <kprateek.nayak@amd.com>
cpufreq/amd-pstate: Return -ENOMEM on failure to allocate profile_name
K Prateek Nayak <kprateek.nayak@amd.com>
cpufreq/amd-pstate: Reorder notifier unregistration and floor perf reset
EDAMAMEX <edame8080@gmail.com>
cpufreq/amd-pstate: handle missing policy in dynamic EPP callbacks
Arnd Bergmann <arnd@arndb.de>
usb: ucsi: huawei_gaokun: move typec_altmode off stack
John Ogness <john.ogness@linutronix.de>
serial: 8250: Ignore flow control on suspend/resume with no_console_suspend
Rafael J. Wysocki <rafael.j.wysocki@intel.com>
platform/x86: lg-laptop: Check ACPI_COMPANION() against NULL
Ian Rogers <irogers@google.com>
perf tests kvm: Avoid leaving perf.data.guest file around
Steven Rostedt <rostedt@goodmis.org>
tracing: Move d_max_latency out of CONFIG_FSNOTIFY protection
Miquel Raynal (DAVE) <miquel.raynal@bootlin.com>
mtd: rawnand: pl353: Fix debug prints
Ben Cressey <ben@cressey.dev>
dm-integrity: fix buffer overflow with keyed discard
Jamal Hadi Salim <jhs@mojatatu.com>
net/sched: sch_htb: limit htb_classify inner-class filter hops
Jiayuan Chen <jiayuan.chen@linux.dev>
tcp: fix corruption of urgent data on multi-segment retransmit
Deepanshu Kartikey <kartikey406@gmail.com>
usb: atm: usbatm: fix invalid ci_range initialization
bui duc phuc <phucduc.bui@gmail.com>
net: fec: only stop PTP if it was initialized
Eric Dumazet <edumazet@google.com>
slip: remove slip_hangup() to fix use-after-free in slip_receive_buf()
Jamal Hadi Salim <jhs@mojatatu.com>
net/sched: bound qdisc_pkt_len to prevent qdisc soft lockup
Pascal Kneuper <PKneuper@dspace.de>
net: stmmac: restore NET_IP_ALIGN in the RX DMA offset
Maxime Chevallier <maxime.chevallier@bootlin.com>
net: stmmac: selftests: Account for the UC filter list for filtering tests
Maxime Chevallier <maxime.chevallier@bootlin.com>
net: stmmac: dwxgmac: Account for the primary MAC address for UC filtering
Maxime Chevallier <maxime.chevallier@bootlin.com>
net: stmmac: dwmac4: Account for the primary MAC address for UC filtering
Maxime Chevallier <maxime.chevallier@bootlin.com>
net: stmmac: dwmac1000: Account for the primary MAC address for UC filtering
Maxime Chevallier <maxime.chevallier@bootlin.com>
net: stmmac: selftests: Check multiple MMC counters
Daniel Pawlik <pawlik.dan@gmail.com>
net: airoha: npu: fix missing streaming DMA mask
Muhammad Usama Anjum <usama.anjum@arm.com>
selftests/arm64: Fix MTE prctl TAP plan
Muhammad Usama Anjum <usama.anjum@arm.com>
selftests/arm64: Treat KSM merge_across_nodes as optional
Muhammad Usama Anjum <usama.anjum@arm.com>
selftests/arm64: Print missing MTE TAP headers
Takashi Iwai <tiwai@suse.de>
ALSA: control: Don't add invalid kcontrols to LED layer
Pablo Neira Ayuso <pablo@netfilter.org>
netfilter: x_tables: replace pr_{info,err}() by pr_info_ratelimited()
Marino Dzalto <marino.dzalto@gmail.com>
netfilter: xt_HL: add pr_fmt and checkentry validation
Pablo Neira Ayuso <pablo@netfilter.org>
netfilter: nf_tables: move hardware offload step after building the chain blob
Alice Mikityanska <alice@isovalent.com>
virtio-net: Ensure that TCP packets don't overflow gso_segs
Balasubramani Vivekanandan <balasubramani.vivekanandan@intel.com>
drm/xe/xe_gt_idle: Add CCS to the powergating info print
Maxime Chevallier <maxime.chevallier@bootlin.com>
net: stmmac: selftests: Pass the IP proto mask in the TC selftest
Jiawen Wu <jiawenwu@trustnetic.com>
net: wangxun: use BIT_ULL() to prevent shift overflow on 32-bit archs
Yifei Chu <Chuyf26@linux.alibaba.com>
net/smc: release the internal TCP sock on IPPROTO_SMC socket creation failure
bui duc phuc <phucduc.bui@gmail.com>
net: ethernet: sun4i-emac: Fix IRQ error handling
Haotian Zhang <vulab@iscas.ac.cn>
samples/ftrace: Fix kthread_stop() on ERR_PTR in ftrace-direct-multi-modify
Haotian Zhang <vulab@iscas.ac.cn>
samples/ftrace: Fix kthread_stop() on ERR_PTR in ftrace-direct-modify
Aleksandr Nogikh <nogikh@google.com>
libceph: validate banner payload length
Xiubo Li <xiubo.li@clyso.com>
ceph: revalidate ki_pos for O_APPEND writes after cap acquisition
Hongling Zeng <zenghongling@kylinos.cn>
ceph: Fix ERR_PTR(0) in ceph_mkdir()
HyeongJun An <sammiee5311@gmail.com>
ASoC: dapm: Fix off-by-one check on the second enum channel
John Johansen <john.johansen@canonical.com>
apparmor: policy_int make sure list heads are initialized before fail path
Thorsten Blum <thorsten.blum@linux.dev>
apparmor: Replace sprintf/strcpy with scnprintf/strscpy in aa_policy_init
Jérémy Jean <Jeremy.Jean@oss.cyber.gouv.fr>
crypto: acomp - allocate async request context when cloning
Ruoyu Wang <ruoyuw560@gmail.com>
tpm: st33zp24: Validate locality read result
Ruoyu Wang <ruoyuw560@gmail.com>
tpm: st33zp24: Return zero on status read failure
Victor Nogueira <victor@mojatatu.com>
net/sched: sch_teql: restore skb->dev on the slave failure path
Jamal Hadi Salim <jhs@mojatatu.com>
net/sched: sfq: clamp quantum to avoid signed overflow soft lockup
Jamal Hadi Salim <jhs@mojatatu.com>
net/sched: hhf: clamp quantum before hhf_change() to avoid overflow
Jamal Hadi Salim <jhs@mojatatu.com>
net/sched: fq_pie: clamp default quantum to avoid signed overflow
Jamal Hadi Salim <jhs@mojatatu.com>
net/sched: sch_codel: clamp default mtu to avoid disabling CoDel
Jamal Hadi Salim <jhs@mojatatu.com>
net/sched: fq_codel: clamp default quantum and mtu
Jamal Hadi Salim <jhs@mojatatu.com>
net/sched: fq: add overflow bounds to quantum and initial quantum
Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
net: fix a resource leak in copy_net_ns() error handling path
Mina Almasry <almasrymina@google.com>
net: core: check skb_frags_readable before uncloning in skb_copy_ubufs
Eric Dumazet <edumazet@google.com>
net/sched: act_skbmod: fix length calculations and avoid invalid header warnings
Karl Mehltretter <kmehltretter@gmail.com>
selftests/proc: make proc-maps-race work with READ_IMPLIES_EXEC
Liam R. Howlett (Oracle) <liam@infradead.org>
maple_tree: fix argument name in header
Liam R. Howlett (Oracle) <liam@infradead.org>
maple_tree: catch race in mas_alloc_cyclic()
Muhammad Usama Anjum <usama.anjum@arm.com>
selftests/mm: skip COW tmpfile cases when fallocate() is unsupported
Frank Sorenson <sorenson@redhat.com>
cifs: fix clearing stats for fastest execution of each smb2 command
Suman Ghosh <sumang@marvell.com>
octeontx2-pf: fix NULL deref of af_xdp_zc_qidx on rep setup
Allison Henderson <achender@kernel.org>
net/rds: use wq_has_sleeper() in rds_cong_map_updated()
Victor Nogueira <victor@mojatatu.com>
net/sched: act_ife: Only operate on Ethernet frames
Eric Dumazet <edumazet@google.com>
net/sched: add qstats_cpu_drop_inc() helper
Wei Fang <wei.fang@nxp.com>
net: enetc: restore RX ring congestion mode after ring reconfiguration
Naveen Mamindlapalli <naveenm@marvell.com>
octeontx2-af: Fix TL3/TL2 link config ENA clearing
Xiang Mei <xmei5@asu.edu>
net: qualcomm: rmnet: restore skb->dev on deaggregated frames
Anshumali Gaur <agaur@marvell.com>
octeontx2-vf: fix workqueue and netdev race in probe/remove
Anshumali Gaur <agaur@marvell.com>
octeontx2-af: fix NULL deref in NIX TM tree debugfs read path
Cen Zhang (Microsoft) <blbllhy@gmail.com>
gtp: add synchronize_net() in gtp_newlink() error path to prevent use-after-free
Stanislav Fomichev <sdf.kernel@gmail.com>
xsk: honor XDP_TX_METADATA in zero-copy path
Stanislav Fomichev <sdf.kernel@gmail.com>
xsk: align TX metadata layout across ABIs
Hyunwoo Kim <imv4bel@gmail.com>
Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop
Ali Ahmet Memis <ali@iusegentoo.com>
Bluetooth: btnxpuart: Validate the FW dump header length
Chris Lu <chris.lu@mediatek.com>
Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path
Chris Lu <chris.lu@mediatek.com>
Bluetooth: btmtksdio: Take exclusive ownership of the SKB before TX
Ismail Tarim <ismailtarim7@gmail.com>
Bluetooth: btmtk: Do not discard the subsystem reset timeout
Ismail Tarim <ismailtarim7@gmail.com>
Bluetooth: btmtk: Do not report success when subsys reset fails
Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Bluetooth: btmtk: Fix short read errors in btmtk_usb_reg_read()
Javier Tia <floss@jetm.me>
Bluetooth: btmtk: Add MT6639 (MT7927) Bluetooth support
Pauli Virtanen <pav@iki.fi>
Bluetooth: L2CAP: fix race l2cap_sock_cleanup_listen() vs. put_chan
Pavel Shpakovskiy <pashpakovskii@salutedevices.com>
Bluetooth: mgmt: fix 'hdev->discovery.uuids' NULL dereference
Pauli Virtanen <pav@iki.fi>
Bluetooth: L2CAP: reject accept queue add unless BT_LISTEN
Vladimir Murzin <vladimir.murzin@arm.com>
arm64: process: Fix context switching MTE store-only tag check
Wei-Lin Chang <weilin.chang@arm.com>
arm64: ptdump: Make note_page_flush() range aware
Geert Uytterhoeven <geert+renesas@glider.be>
erofs: Fix EROFS_FS_ZIP_LZMA_DEFAULT_MAX_STREAMS default logic
Dan Carpenter <error27@gmail.com>
scsi: qla2xxx: Fix an loop timeout test
Michael Kelley <mhkelley58@gmail.com>
Drivers: hv: vmbus: Skip VMBus module cleanup for non-nested root partition
Thierry Reding <treding@nvidia.com>
syscore: Pass context data to callbacks
Eric Dumazet <edumazet@google.com>
net_sched: sch_fq: fix pacing delay underflow with pacing offload
Rong Zhang <i@rong.moe>
net: page_pool: Remove zone/policy GFP flags when allocating XArray entries
Jiawen Wu <jiawenwu@trustnetic.com>
net: libwx: fix concurrent bitmap overwrite in PTP setup
Jiawen Wu <jiawenwu@trustnetic.com>
net: txgbe: fix MISC interrupt unmasking in non-MSI-X mode and device shutdown
Jiawen Wu <jiawenwu@trustnetic.com>
net: wangxun: introduce WX_STATE_DOWN to serialize device shutdown state
Jiawen Wu <jiawenwu@trustnetic.com>
net: wangxun: schedule hardware stats update in watchdog
Jiawen Wu <jiawenwu@trustnetic.com>
net: wangxun: replace busy-wait reset flag with kernel mutex
Jiawen Wu <jiawenwu@trustnetic.com>
net: txgbe: support RSC offload
Jiawen Wu <jiawenwu@trustnetic.com>
net: txgbe: support RX desc merge mode
Wei Fang <wei.fang@nxp.com>
ptp: netc: fix period truncation and potential divide-by-zero in PEROUT
Thomas Walsh <thwalsh@redhat.com>
bnxt_en: Gate TPH enablement behind BNXT_SUPPORTS_QUEUE_API check
Guenter Roeck <linux@roeck-us.net>
bnxt_en: Fix call to hardware monitoring event handler
Cosmo Chou <chou.cosmo@gmail.com>
rtc: pcf85363: Add error checking to regmap calls in probe()
Junrui Luo <moonafterrain@outlook.com>
NFSv4/pnfs: key the data server cache on the NFS version
Junrui Luo <moonafterrain@outlook.com>
NFSv4.2: fix LAYOUTSTATS send buffer exhaustion
Mahanta Jambigi <mjambigi@linux.ibm.com>
net/smc: free pending qentry in smc_llc_flow_stop() before memset
Mahanta Jambigi <mjambigi@linux.ibm.com>
net/smc: free stashed qentry before overwrite in REQ_ADD_LINK to ADD_LINK transition
Jamal Hadi Salim <jhs@mojatatu.com>
net: sched: fix 32-bit backlog wrap in gred, bfifo and plug enqueue
Mina Almasry <almasrymina@google.com>
net: tcp: block mixing readable and unreadable frags
Eric Dumazet <edumazet@google.com>
inetpeer: randomize RB-tree node comparison using SipHash
Eric Dumazet <edumazet@google.com>
ip6mr: plug drop_reason to ip6mr_cache_report()
Kuniyuki Iwashima <kuniyu@google.com>
ipmr: Free mr_table after RCU grace period.
Eric Dumazet <edumazet@google.com>
net: change sock_queue_rcv_skb_reason() to return a drop_reason
Kuniyuki Iwashima <kuniyu@google.com>
ipmr: Remove RTNL in ipmr_rules_init() and ipmr_net_init().
Kuniyuki Iwashima <kuniyu@google.com>
ipmr: Convert ipmr_net_exit_batch() to ->exit_rtnl().
Kuniyuki Iwashima <kuniyu@google.com>
ipmr: Move unregister_netdevice_many() out of ipmr_free_table().
Kuniyuki Iwashima <kuniyu@google.com>
ipmr: Move unregister_netdevice_many() out of mroute_clean_tables().
Pengpeng Hou <pengpeng@iscas.ac.cn>
net: qlcnic: validate unified ROM sections before loading
Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
net: add missing ref_tracker_dir_exit() to net_passive_dec()
Cen Zhang (Microsoft) <blbllhy@gmail.com>
ipv6: avoid divide by zero in rt6_multipath_rebalance
Eric Dumazet <edumazet@google.com>
netdevsim: update queue NAPI association on queue reset
Ruoyu Wang <ruoyuw560@gmail.com>
net: ipa: balance runtime PM reference on remove error
Marek Czernohous <marek@czernohous.de>
forcedeth: stop the tx_timeout register dump past the requested window
Or Har-Toov <ohartoov@nvidia.com>
net/mlx5: E-Switch, preserve max tx speed on vport state modification
Or Har-Toov <ohartoov@nvidia.com>
net/mlx5: Move vport DOWN state check out of mlx5_query_vport_max_tx_speed()
Or Har-Toov <ohartoov@nvidia.com>
net/mlx5: Skip disabled vports when setting max TX speed
Or Har-Toov <ohartoov@nvidia.com>
RDMA/mlx5: Implement query_port_speed callback
Or Har-Toov <ohartoov@nvidia.com>
IB/core: Add query_port_speed verb
Or Har-Toov <ohartoov@nvidia.com>
IB/core: Add helper to convert port attributes to data rate
Or Har-Toov <ohartoov@nvidia.com>
net/mlx5: Add support for querying bond speed
Or Har-Toov <ohartoov@nvidia.com>
net/mlx5: Handle port and vport speed change events in MPESW
Mark Bloch <mbloch@nvidia.com>
net/mlx5: E-Switch, use state lock for vport state changes
Or Har-Toov <ohartoov@nvidia.com>
net/mlx5: Propagate LAG effective max_tx_speed to vports
Or Har-Toov <ohartoov@nvidia.com>
net/mlx5: Add max_tx_speed and its CAP bit to IFC
Saeed Mahameed <saeedm@nvidia.com>
net/mlx5: E-Switch, support eswitch inactive mode
Saeed Mahameed <saeedm@nvidia.com>
net/mlx5: MPFS, add support for dynamic enable/disable
Saeed Mahameed <saeedm@nvidia.com>
devlink: Introduce switchdev_inactive eswitch mode
Fan Ye <fy15309206903@gmail.com>
net: thunderbolt: Count delivered packets in rx_packets and rx_bytes
Victor Nogueira <victor@mojatatu.com>
net/sched: add get_fill_size callbacks for actions missing them
Ruoyu Wang <ruoyuw560@gmail.com>
net: bridge: Reject descending VLAN tunnel ranges
Cen Zhang (Microsoft) <blbllhy@gmail.com>
xsk: fix NULL pointer dereference in __xsk_rcv()
Maciej Fijalkowski <maciej.fijalkowski@intel.com>
xsk: avoid double checking against rx queue being full
Rustam Adilov <adilov@disroot.org>
irqchip/irq-realtek-rtl: Use readl_be()/writel_be() instead of readl()/writel()
Markus Stockhausen <markus.stockhausen@gmx.de>
irqchip/irq-realtek-rtl: Add mask for interrupt handling
Markus Stockhausen <markus.stockhausen@gmx.de>
irqchip/irq-realtek-rtl: Add interrupt data structure
Markus Stockhausen <markus.stockhausen@gmx.de>
irqchip/irq-realtek-rtl: Split out parent setup code
Markus Stockhausen <markus.stockhausen@gmx.de>
irqchip/irq-realtek-rtl: Add multicore support
Markus Stockhausen <markus.stockhausen@gmx.de>
irqchip/irq-realtek-rtl: Add/simplify register helpers
Namjae Jeon <linkinjeon@kernel.org>
smb: server: remove unused DES crypto header
Thomas Huth <thuth@redhat.com>
smb: server: Remove obsolete "select CRYPTO_LIB_DES" from Kconfig file
Runyu Xiao <runyu.xiao@seu.edu.cn>
ALSA: mtpav: shut down output timer before card teardown
Geert Uytterhoeven <geert+renesas@glider.be>
spi: amlogic-spisg: Make sure clk_init_data is fully initialized
Serhat Kumral <serhatkumral1@gmail.com>
RDMA/ucma: Allow path records to exactly fit the output buffer
Haotian Zhang <vulab@iscas.ac.cn>
ALSA: ice1712: Fix the card leak at probe error with the auto-cleanup
Cássio Gabriel <cassiogabrielcontato@gmail.com>
ALSA: core: Add scoped cleanup helper for card references
Lorenzo Pieralisi <lpieralisi@kernel.org>
irqchip/gic-v5: Use logical cpu 0 irs_data for dynamic IST allocation
Lorenzo Pieralisi <lpieralisi@kernel.org>
irqchip/gic-v5: Fix gicv5_init_common() error paths
Lorenzo Pieralisi <lpieralisi@kernel.org>
irqchip/gic-v5: Check for NULL LPI domain on domain teardown
Sascha Bischoff <Sascha.Bischoff@arm.com>
irqchip/gic-v5: Synchronize CPU interface disable
Geert Uytterhoeven <geert+renesas@glider.be>
clk: visconti: Make sure clk_init_data is fully initialized
Geert Uytterhoeven <geert+renesas@glider.be>
clk: ti: Make sure clk_init_data is fully initialized
Bradley Morgan <include@grrlz.net>
prctl: fix PR_SET_MM_AUXV losing the forced AT_NULL terminator
Karl Mehltretter <kmehltretter@gmail.com>
lib/interval_tree: fix allocation warning messages
Linkai Gong <gonglinkai@kylinos.cn>
rtc: gamecube: check return value of devm_rtc_register_device()
Ruoyu Wang <ruoyuw560@gmail.com>
i2c: ocores: Disable clock on failed resume
Biju Das <biju.das.jz@bp.renesas.com>
irqchip/renesas-rzg2l: Fix loss of interrupt
Pengpeng Hou <pengpeng@iscas.ac.cn>
rtc: zynqmp: Return optional clock lookup errors
Frank Sorenson <sorenson@redhat.com>
cifs: remove dead size-update blocks in cifs_setattr_unix/nounix
Christopher Lusk <clusk@northecho.dev>
smb: client: fix request buffer leak in smb2_new_read_req()
Surendra Singh Chouhan <kr494167@gmail.com>
rtc: spacemit: handle regmap_test_bits() error return
Yi Ding <yi.s.ding@gmail.com>
rtc: pcf8563: fix clock provider leak on unbind
GuoHan Zhao <zhaoguohan@kylinos.cn>
virtio: rtc: time out alarm requests
Li RongQing <lirongqing@baidu.com>
vdpa/mlx5: fix wrong list iterated in add_direct_chain error path
Li RongQing <lirongqing@baidu.com>
virtio_pci: fix wrong queue index for admin vq in intx path
Yufeng Wang <wangyufeng@kylinos.cn>
vhost/net: fix clear_user start address in VHOST_GET_FEATURES_ARRAY
Denis V. Lunev <den@openvz.org>
virtio_balloon: quiesce balloon work before device shutdown
Denis V. Lunev <den@openvz.org>
virtio_balloon: factor out virtballoon_quiesce()
Denis V. Lunev <den@openvz.org>
virtio: add virtio_device_shutdown() helper
Linfeng Sun <linfeng.sun.dev@gamil.com>
vdpa_sim: fix cleanup after worker creation failure
Michael S. Tsirkin <mst@redhat.com>
virtio_balloon: disable indirect descriptors
Tetsuo Handa <penguin-kernel@I-love.SAKURA.ne.jp>
net: add missing ref_tracker_dir_exit() to alloc_netdev_mqs()
Ruoyu Wang <ruoyuw560@gmail.com>
bonding: initialize err for empty target lists
Nikolay Kulikov <nikolayof23@gmail.com>
mlxbf-bootctl: fix the build error with FIELD_PREP()
Hemanth Selam <hemanth.selam@gmail.com>
platform/x86/amd/hsmp: Reject negative power cap writes in hwmon
Guangshuo Li <lgs201920130244@gmail.com>
platform/x86: hp-bioscfg: fix password encoding bounds check
Nguyen Dinh Phi <phind.uet@gmail.com>
vsock: use sock_error() to consume sk_err after a failed connect
Nguyen Dinh Phi <phind.uet@gmail.com>
vsock: don't check the listener's sk_err in vsock_accept()
Laurence Rowe <laurencerowe@gmail.com>
vsock: avoid timeout for non-blocking accept() with empty backlog
HyeongJun An <sammiee5311@gmail.com>
platform/x86: dell-wmi-sysman: Fix instance ID bounds
Mahanta Jambigi <mjambigi@linux.ibm.com>
net/smc: hash socket only after full initialisation in smc_sk_init()
Karl Mehltretter <kmehltretter@gmail.com>
8139cp: fix Rx and Tx not being disabled in cp_suspend
Baul Lee <baul.lee@xbow.com>
vxlan: mdb: Fix use-after-free in vxlan_mdb_flush()
Xu Rao <raoxu@uniontech.com>
ALSA: hda: Fix connection list comparison in proc output
Baokun Li <libaokun@linux.alibaba.com>
fuse: check for NULL root inode in fuse_fill_super_submount
Daniel Baluta <daniel.baluta@nxp.com>
soc: qcom: ubwc: Fix missing include
Weiming Shi <bestswngs@gmail.com>
fs/ntfs3: validate ef->size covers the record's name and value
Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
fs/ntfs3: fix out-of-bounds read in read_log_rec_buf()
Baokun Li <libaokun@linux.alibaba.com>
cuse: wait for pending RCU callbacks on module exit
Nikolay Aleksandrov <razor@blackwall.org>
net: bridge: vlan: fix inverted default vlan notification
Maximilian Immanuel Brandtner <maxbr@linux.ibm.com>
tls: fix RX desync on overlapping skbs
Ruoyu Wang <ruoyuw560@gmail.com>
net: dsa: mv88e6xxx: Fix PCS link check on CMODE read error
Xiang Mei <xmei5@asu.edu>
vxlan: vnifilter: enforce exact length of GROUP/GROUP6 attributes
Joas Antonio dos Santos <joasantonio108@gmail.com>
ipvs: fix integer overflow in ftp helper port/address parsing
Chao Yu <chao@kernel.org>
f2fs: fix to avoid pinfile fragment on fragment:{block, segment} mode
Chao Yu <chao@kernel.org>
f2fs: cleanup w/ f2fs_need_rand_{blk, seg, seg_blk}
liujinbao1 <liujinbao1@xiaomi.com>
f2fs:Fix incomplete search range in f2fs_get_victim when f2fs_need_rand_seg is enabled
Xin Xie <xiexinet@gmail.com>
net: hsr: free learned nodes on device setup failure
Qingfang Deng <qingfang.deng@linux.dev>
pppox: drain queued packets on channel handoff
Vladimir Oltean <vladimir.oltean@nxp.com>
net: dsa: b53: fix error propagation from b53_fdb_dump()
Junseo Lim <zirajs7@gmail.com>
net: kcm: Hold RCU read lock while running BPF parser
Prabu Thayalan <prabu.ponrajthayalan@amd.com>
ionic: fix completion descriptor access with 2x desc size
Wei Fang <wei.fang@nxp.com>
ptp: netc: skip PEROUT disable if channel is not enabled
Dan Carpenter <error27@gmail.com>
drm/xe: tests: fix error message in xe_migrate_sanity_test()
Fan Gong <gongfan1@huawei.com>
hinic3: Fix skb linearization mismatch and drop skb when skb_checksum_help() failed
Karl Mehltretter <kmehltretter@gmail.com>
octeontx2-af: initialize lmac_bmap in rvu_mcs_set_lmac_bmap()
Jiayuan Chen <jiayuan.chen@linux.dev>
bpf, xdp: move offload check into dev_xdp_install()
Mathieu Dubois-Briand <mathieu.dubois-briand@bootlin.com>
clk: ti: mux: resolve parent clocks by DT index, not by name
Onur Özkan <work@onurozkan.dev>
clk: devres: fix cleanup in devm_clk_get_optional_enabled_with_rate()
Michael Nemanov <michael.nemanov@vastdata.com>
nfs: fix ENXIO on O_CREAT open of existing symlink over NFSv3
Zhansong Gao <zhsgao@hotmail.com>
NFSv4: Fix incorrect argument passed to nfs4_delete_lease() in nfs4_add_lease()
Jeuk Kim <jeuk20.kim@gmail.com>
NFSv4/flexfiles: fix NULL dereference for NFSv4.0 data servers
ZhangGuoDong <zhangguodong@kylinos.cn>
pnfs/blocklayout: Fix device leaks on parse failure
Ruoyu Wang <ruoyuw560@gmail.com>
NFSv4: remove callback IDR entry on client allocation failure
Arnaud Bonnet <abo@medichon.fr>
nfs: refactor pNFS functions using clear_and_wake_up_bit
Arnaud Bonnet <abo@medichon.fr>
nfs: replace atomic bitops sequence with clear_and_wake_up_bit helper
Ze Tan <tanze@kylinos.cn>
smb/server: fix session leak in ksmbd_session_register()
Hang Nan <2122295973@qq.com>
ksmbd: bound smb_check_perm_dacl() ACE walks by DACL size
Namjae Jeon <linkinjeon@kernel.org>
ksmbd: disconnect on SMB3 decryption failure
Junseo Lim <zirajs7@gmail.com>
bpf: Reject negative optlen in cgroup getsockopt hook
Andreas Schwab <schwab@linux-m68k.org>
m68k: nfcon: Do not call console_is_registered() in nfcon_device()
Junseo Lim <zirajs7@gmail.com>
bpf: Disallow bpf_{g,s}etsockopt() in cgroup UNIX getname hooks
Ojaswin Mujoo <ojaswin@linux.ibm.com>
erofs: fix unused pcluster_pools for higher page sizes
Junseo Lim <zirajs7@gmail.com>
lwt_bpf: Restore reserved headroom after xmit program
Gao Xiang <xiang@kernel.org>
erofs: guard on-disk algorithm IDs against Z_EROFS_COMPRESSION_MAX
Gao Xiang <xiang@kernel.org>
erofs: fix interlaced ztailpacking pclusters
Gao Xiang <xiang@kernel.org>
erofs: error out obviously illegal extents in advance
Gao Xiang <xiang@kernel.org>
erofs: clean up encoded map flags
ZhangGuoDong <zhangguodong@kylinos.cn>
smb/server: preserve error status in smb2_handle_negotiate()
ZhangGuoDong <zhangguodong@kylinos.cn>
smb/server: fix invalid pointer dereference in ksmbd_stop_durable_scavenger()
ZhangGuoDong <zhangguodong@kylinos.cn>
smb/server: fix null-ptr-deref in ksmbd_ipc_tree_connect_request()
Namjae Jeon <linkinjeon@kernel.org>
ksmbd: free preauth sessions on connection teardown
Namjae Jeon <linkinjeon@kernel.org>
ksmbd: do not advertise unimplemented CA support
Yunseong Kim <yunseong.kim@est.tech>
ksmbd: validate ipc response length before dereferencing its fields
Enzo Matsumiya <ematsumiya@suse.de>
smb: server: fix leak of ksmbd_ipc_login_request_ext() returned buffer
Guangshuo Li <lgs201920130244@gmail.com>
ksmbd: Do not skip lock checks for single-byte ranges
Marius Cristea <marius.cristea@microchip.com>
hwmon: (emc1403) Drop hysteresis for low limit temperature
Guenter Roeck <linux@roeck-us.net>
hwmon: (emc1403) Rely on subsystem locking
Szymon Wilczek <swilczek.lx@gmail.com>
hwmon: (coretemp) Fix core_data leak on CPUs without PTS
John Johansen <john.johansen@canonical.com>
apparmor: fix deadlock in complain-mode change_hat
Hongyan Xu <getshell@seu.edu.cn>
block: mtip32xx: synchronize ioctls with device removal
Yao Sang <sangyao@kylinos.cn>
ublk: reject non-power-of-2 zone sizes in SET_PARAMS
Niklas Cassel <cassel@kernel.org>
null_blk: serialize configfs attribute updates with device setup
Zizhi Wo <wozizhi@huawei.com>
null_blk: serialize configfs attribute stores with the lock
Zizhi Wo <wozizhi@huawei.com>
null_blk: reject per-device queue resize for shared tag set
Zizhi Wo <wozizhi@huawei.com>
null_blk: free zones array on device power-off
Zizhi Wo <wozizhi@huawei.com>
null_blk: free global tag_set on init error path
Zizhi Wo <wozizhi@huawei.com>
null_blk: register configfs subsystem after creating default devices
Zizhi Wo <wozizhi@huawei.com>
null_blk: use DEFINE_MUTEX for the file-scope mutex
Pengpeng Hou <pengpeng@iscas.ac.cn>
mailbox: riscv-sbi-mpxy: validate RPMI notification lengths
Huisong Li <lihuisong@huawei.com>
mailbox: pcc: Fix command timeout due to missed interrupt
Linmao Li <lilinmao@kylinos.cn>
mailbox: rockchip: disable pclk on probe failure and unbind
Jia Yang <jia.yang@oss.qualcomm.com>
mailbox: qcom-cpucp: handle NULL data in send_data callback
Jia Yang <jia.yang@oss.qualcomm.com>
mailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock in IRQ handler
Arnaldo Carvalho de Melo <acme@redhat.com>
perf dso: Replace assert with runtime check in dso__read_symbol()
Arnaldo Carvalho de Melo <acme@redhat.com>
perf dso: Guard against cache underflow on short reads in dso_cache__memcpy()
Arnaldo Carvalho de Melo <acme@redhat.com>
perf dso: Use stored fd error instead of stale errno in file_read() and file_size()
Arnaldo Carvalho de Melo <acme@redhat.com>
perf dso: Guard close() against invalid fd in dso__decompress_kmodule_path()
Arnaldo Carvalho de Melo <acme@redhat.com>
perf dso: Guard against errno==0 when dso__get_filename() returns NULL
Tao Cui <cuitao@kylinos.cn>
sched_ext/scx_flatcg: Fix cvtime true-up on slice expiry
Karl Mehltretter <kmehltretter@gmail.com>
crypto: lskcipher - propagate errors from unaligned crypt
Zhushuai Yin <yinzhushuai@huawei.com>
crypto: hisilicon/sec2 - fix CCM algorithm long packet failure
Michal Blaszczyk <michalblk@google.com>
selftests/sched_ext: Fix flaky ddsp failure tests on busy systems
Israel Téllez García <i.tellez@btesa.com>
bpf: Fix pending_pos walk on 32-bit ring position wrap
Hongyan Xu <getshell@seu.edu.cn>
ACPI: scan: fix bus ID cleanup on device_add() failures
Vincent Donnefort <vdonnefort@google.com>
ring-buffer: Remove trace_buffer::cpus
Pu Lehui <pulehui@huawei.com>
riscv, bpf: Fix missing sign-ext for signed 1-byte and 2-byte kfunc args
Andrii Nakryiko <andrii@kernel.org>
selftests/bpf: Use ping_command() for IPv6 pings in lwt_ip_encap
Leon Hwang <leon.hwang@linux.dev>
selftests/bpf: Add tests to verify the fix of encapsulating VxLAN in lwt
Xianglin Lin <1021538027@qq.com>
HID: multitouch: reclassify HTIX5288 to WIN_8_FORCE_MULTI_INPUT_NSMU
Pengpeng Hou <pengpeng@iscas.ac.cn>
ASoC: SOF: validate topology volume range before allocation
Steven Rostedt <rostedt@goodmis.org>
tracing: Have trace_event_update_all() only handle module that is loading
Karl Mehltretter <kmehltretter@gmail.com>
HID: haptic: don't write an uninitialized value to unhandled usages
Aleksandr Nogikh <nogikh@google.com>
ALSA: core: Fix use-after-free in snd_card_do_free()
Zhan Xusheng <zhanxusheng1024@gmail.com>
fs/ntfs3: reject out-of-range evcn in mi_enum_attr()
Zhan Xusheng <zhanxusheng1024@gmail.com>
fs/ntfs3: fix integer overflow in MFT cluster validation
Puranjay Mohan <puranjay@kernel.org>
bpf, arm64: Fix stack-passed arguments for indirect trampolines
Jijie Shao <shaojijie@huawei.com>
net: page_pool: fix UAF in __page_pool_release_netmem_dma on xa_cmpxchg race
Bart Van Assche <bvanassche@acm.org>
scsi: ufs: core: Set task state before io_schedule_timeout()
Chandrakanth Patil <chandrakanth.patil@broadcom.com>
scsi: mpt3sas: Avoid freeing unallocated PCIe SGL buffers
Eduard Zingerman <eddyz87@gmail.com>
selftests/bpf: Fix for veristat file/prog filters processing
Phillip Lougher <phillip@squashfs.org.uk>
Squashfs: check block offset is not negative
Krystian Kaniewski <krystianmkaniewski@gmail.com>
ocfs2: fix circular locking dependency in ocfs2_init_acl()
ZhengYuan Huang <gality369@gmail.com>
ocfs2: validate DIO orphan slot during inode read
ZhengYuan Huang <gality369@gmail.com>
ocfs2: validate orphan slot during inode read
Yuan Chen <chenyuan@kylinos.cn>
bpftool: Fix double close in map dump
Bijan Tabatabai <btabatabai@wisc.edu>
x86/pkeys: Fix pkey_alloc() return value when pkeys are not supported
Rui Qi <qirui.001@bytedance.com>
selftests/cgroup: Preserve CPU hotplug write errors
John Keeping <jkeeping@inmusicbrands.com>
ALSA: seq: midi: Serialize input teardown with event_input
Takashi Iwai <tiwai@suse.de>
ALSA: seq: midi: Optimize event_input locking with RCU
Yuho Choi <dbgh9129@gmail.com>
clocksource/drivers/armada: Unwind timer clock on init failure
Guangshuo Li <lgs201920130244@gmail.com>
clocksource/drivers/clps711x: Do not unmap clocksource MMIO
Peter Oberparleiter <oberpar@linux.ibm.com>
s390/debug: Fix deadlock during unregister
Yuho Choi <dbgh9129@gmail.com>
xenbus: Unregister reboot notifier on init failure
Henrik Grimler <henrik.grimler@axis.com>
power: supply: bq27xxx: bq27z561: fix invalid AverageEnergy address
Henrik Grimler <henrik.grimler@axis.com>
power: supply: bq27xxx: bq28z610: fix invalid AverageEnergy address
Henrik Grimler <henrik.grimler@axis.com>
power: supply: bq27xxx: bq27520g4: fix REG_TTES address
Matti Vaittinen <mazziesaccount@gmail.com>
power: supply: bd99954: Drop bad register fields
Krishna Chaitanya Chundru <krishna.chundru@oss.qualcomm.com>
PCI/ASPM: Disable/restore ASPM on every function for multi-function devices
Felix Gu <ustc.gu@gmail.com>
spi: img-spfi: don't disable runtime PM on DMA deferred probe
Vineet Gupta <vineet.gupta@linux.dev>
selftests/bpf: vmtest.sh: Preserve command quoting when running in the VM
David Matlack <dmatlack@google.com>
selftests: harness: Mark test fixture objects __maybe_unused
Thomas Weißschuh <thomas.weissschuh@linutronix.de>
selftests: harness: Restore order of test functions
Mohammad Abu-Khader <mohammad.abukhader@hotmail.com>
kunit: tool: fix _list_tests filtering wrong variable when list has TAP prefix
Arnaldo Carvalho de Melo <acme@redhat.com>
perf build: Remove leftover feature tests for removed cxx and clang support
Karl Mehltretter <kmehltretter@gmail.com>
super: fix dying superblock warning messages
Krishna Chaitanya Chundru <krishna.chundru@oss.qualcomm.com>
PCI/ASPM: Use pcie_capability_clear_and_set_word() for ASPM disable/restore
Takashi Sakamoto <o-takashi@sakamocchi.jp>
firewire: core: fix memory leak in error path of build_tree()
Takashi Sakamoto <o-takashi@sakamocchi.jp>
firewire: core: validate parent port count before allocating nodes in build_tree()
Takashi Sakamoto <o-takashi@sakamocchi.jp>
firewire: core: consolidate port counting in build_tree()
Takashi Sakamoto <o-takashi@sakamocchi.jp>
firewire: core: add KUnit tests for failure of tree building
Takashi Sakamoto <o-takashi@sakamocchi.jp>
firewire: core: add KUnit tests for successful tree building
Takashi Sakamoto <o-takashi@sakamocchi.jp>
firewire: core: add KUnit test skeleton for node tree
Ran Hongyun <ranhongyun1@huawei.com>
UBI: fix two issues in the ubi.mtd MODULE_PARM_DESC
Rosen Penev <rosenp@gmail.com>
ASoC: xilinx: formatter_pcm: fix stream_data leak on open error
Yuho Choi <dbgh9129@gmail.com>
mtd: ubi: Release device reference on busy detach
Yuho Choi <dbgh9129@gmail.com>
ubi: Fix rollback for explicit UBI device numbers
Zhihao Cheng <chengzhihao1@huawei.com>
UBI: fastmap: Pass to_be_tortured when reusing old fastmap PEBs
Zhihao Cheng <chengzhihao1@huawei.com>
UBI: Preserve torture flag when rescheduling failed erasures
LiangCheng Wang <zaq14760@gmail.com>
ASoC: fsl-asoc-card: defer probe when the CPU DAI device is not ready
bui duc phuc <phucduc.bui@gmail.com>
ASoC: pxa: Use devm_clk_get_optional() for extclk clock
Willem de Bruijn <willemb@google.com>
idpf: add missing cpu_to_le32 in idpf_tx_splitq_build_flow_desc
Robert Malz <robert.malz@canonical.com>
ice: acquire NVM lock around each flash read
Jesse Brandeburg <jesse.brandeburg@intel.com>
ice: refactor to use helpers
Petr Oros <poros@redhat.com>
ice: clear the default forwarding VSI rule when releasing a VSI
Przemyslaw Korba <przemyslaw.korba@intel.com>
ice: fall back to SBQ when LL PHY timer interface times out
Zhu Yanjun <yanjun.zhu@linux.dev>
RDMA/cma: Fix WARNING in res_to_rt
Fan Wu <fanwu01@zju.edu.cn>
RDMA/cxgb4: Free debugfs on registration failure
Guangshuo Li <lgs201920130244@gmail.com>
dmaengine: qcom-bam-dma: fix autosuspend cleanup during removal
HyeongJun An <sammiee5311@gmail.com>
ALSA: seq: Don't leak the extension cell pointer in the bounce payload
Yun Zhou <yun.zhou@windriver.com>
nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing
Linmao Li <lilinmao@kylinos.cn>
nfc: digital: Do not dump a NULL response in command completion
Yinhao Hu <dddddd@hust.edu.cn>
nfc: pn533: hold a reference to the request skb during send_frame
Doruk Tan Ozturk <doruk@0sec.ai>
nfc: llcp: bound SNL TLV parsing to the skb and add length checks
Zhenghang Xiao <kipreyyy@gmail.com>
nfc: nci: fix double completion race in nci_data_exchange_complete
Breno Leitao <leitao@debian.org>
nfc: llcp: read llcp_sock->local under the socket lock in getsockopt
Breno Leitao <leitao@debian.org>
nfc: llcp: avoid userspace overflow on invalid optlen
Chao Shi <coshi036@gmail.com>
nvme: reject passthrough of driver-managed Set Features
Yang Xiuwei <yangxiuwei@kylinos.cn>
nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed()
Guixin Liu <kanie@linux.alibaba.com>
nvmet: fix NULL pointer dereference in nvmet_execute_identify_ns_zns()
Sven Peter <sven@kernel.org>
nvme-apple: Drop the PRP null check chicken bit
Sven Peter <sven@kernel.org>
nvme-apple: Require page aligned buffers on the admin queue
Sven Peter <sven@kernel.org>
nvme: Add a quirk for page aligned admin queue buffers
Maurizio Lombardi <mlombard@redhat.com>
nvme: expose active quirks in sysfs
Keith Busch <kbusch@kernel.org>
nvme: remove virtual boundary for sgl capable devices
Keith Busch <kbusch@kernel.org>
block: accumulate memory segment gaps per bio
Sven Peter <sven@kernel.org>
nvme-apple: Never set the opcode in the NVMMU TCB
Sven Peter <sven@kernel.org>
nvme-apple: Don't set a DMA direction for commands without a data transfer
Sven Peter <sven@kernel.org>
nvme-apple: Destroy the admin queue on removal
Guixin Liu <kanie@linux.alibaba.com>
nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()
Alistair Francis <alistair.francis@wdc.com>
nvme: Add the DHCHAP maximum HD IDs
Ilya Leoshkevich <iii@linux.ibm.com>
s390/irqflags: Add out-of-line definitions of arch_local_irq_*() for KMSAN
Coiby Xu <coxu@redhat.com>
s390: Drop unnecessary CONFIG_IMA_SECURE_AND_OR_TRUSTED_BOOT
Coiby Xu <coxu@redhat.com>
integrity: Make arch_ima_get_secureboot integrity-wide
Josh Poimboeuf <jpoimboe@kernel.org>
arm64: bti: Disable in-kernel BTI with recent versions of Clang
Jorijn van der Graaf <jorijnvdgraaf@catcrafts.net>
ASoC: qcom: q6apm: keep the graph start count in sync with the DSP
Babanpreet Singh <bbnpreetsingh@gmail.com>
spi: sprd-adi: Fix probe succeeding without registering the controller
Esteban Urrutia <esteuwu@proton.me>
phy: qcom: qmp-combo: Drop qmp_v4_calibrate_dp_phy
Abel Vesa <abelvesa@kernel.org>
phy: qualcomm: qmp-combo: Add DP offsets and settings for Glymur platforms
Wesley Cheng <wesley.cheng@oss.qualcomm.com>
phy: qualcomm: qmp-combo: Update QMP PHY with Glymur settings
Wesley Cheng <wesley.cheng@oss.qualcomm.com>
phy: qualcomm: Update the QMP clamp register for V6
Faisal Hassan <faisal.hassan@oss.qualcomm.com>
phy: qcom-qmp-combo: Use regulator_bulk_data with init_load_uA for regulator setup
Esteban Urrutia <esteuwu@proton.me>
phy: qcom: qmp-combo: Correct pre-emphasis table for QMP v4 DP PHYs
Lad Prabhakar <prabhakar.mahadev-lad.rj@bp.renesas.com>
phy: renesas: rcar-gen3-usb2: Ignore missing VBUS regulator
Mukesh Kumar Chaurasiya (IBM) <mkchauras@gmail.com>
rust: uapi: replace direct asm-generic/ioctl.h include with linux/ioctl.h
Vasant Hegde <vasant.hegde@amd.com>
iommu/amd: Fix incorrect device ID in invalid PASID error message
John Johansen <john.johansen@canonical.com>
apparmor: fix unconfined user namespace restriction forced stack
John Johansen <john.johansen@canonical.com>
apparmor: change fn_label_build() call to not return NULL
John Johansen <john.johansen@canonical.com>
apparmor: split xxx_in_ns into its two separate semantic use cases
Michael Walle <mwalle@kernel.org>
powerpc/configs: enable CONFIG_RAS to fix EDAC support
Kuniyuki Iwashima <kuniyu@google.com>
amt: Don't support cross-netns setup.
Liang Luo <luoliang@kylinos.cn>
selftests/sched_ext: Check skeleton open failure in exit test
Guopeng Zhang <zhangguopeng@kylinos.cn>
cgroup/cpuset: Use WRITE_ONCE() for shared prs_err updates
Waiman Long <longman@redhat.com>
cgroup/cpuset: Fail if isolated and nohz_full don't leave any housekeeping
Gabriele Monaco <gmonaco@redhat.com>
cgroup/cpuset: Rename update_unbound_workqueue_cpumask() to update_isolation_cpumasks()
Guixin Liu <kanie@linux.alibaba.com>
nvme-pci: release descriptor pools on probe failure
Guixin Liu <kanie@linux.alibaba.com>
nvmet: propagate percpu_ref_init() failure in nvmet_ns_enable()
Zhengrong Li <zhengrong_li@linux.alibaba.com>
nvmet: fix Reservation Register Replace for unregistered host with IEKEY
Runyu Xiao <runyu.xiao@seu.edu.cn>
sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE
Weiming Shi <bestswngs@gmail.com>
SUNRPC: check rpc_sockaddr2uaddr() return value in rpcb_register_inet4/6
Thomas Weißschuh <linux@weissschuh.net>
hwmon: (cros_ec) Synchronize EC access from the thermal device callbacks
Thomas Weißschuh <linux@weissschuh.net>
hwmon: (cros_ec) Store the hwmon device in cros_ec_hwmon_priv
Thomas Weißschuh <linux@weissschuh.net>
hwmon: (cros_ec) Register the thermal devices after the hwmon ones
Guenter Roeck <linux@roeck-us.net>
hwmon: Support guard() and scoped_guard for subsystem locks
Thomas Weißschuh <linux@weissschuh.net>
hwmon: (cros_ec) Add support for temperature thresholds
Thomas Weißschuh <linux@weissschuh.net>
hwmon: (cros_ec) Move temperature channel params to a macro
Thomas Weißschuh <linux@weissschuh.net>
hwmon: (cros_ec) Split up supported features in the documentation
Marco Elver <elver@google.com>
arm64: Disable KCSAN instrumentation in delay.o
Chuck Lever <chuck.lever@oracle.com>
xdrgen: Fix opaque and string encoders for unbounded members
Chuck Lever <chuck.lever@oracle.com>
xdrgen: Do not declare union XDR functions in the definitions header
Chuck Lever <chuck.lever@oracle.com>
xdrgen: Address some checkpatch whitespace complaints
Karl Mehltretter <kmehltretter@gmail.com>
m68k: Fix backtraces for non-running tasks
Yuho Choi <dbgh9129@gmail.com>
hwrng: imx-rngc - Disable clock on registration failure
Ahsan Atta <ahsan.atta@intel.com>
crypto: qat - remove dead ADF_HEX code
Thorsten Blum <thorsten.blum@linux.dev>
crypto: qat - use 2-arg strscpy where destination size is known
Lu Baolu <baolu.lu@linux.intel.com>
iommu/vt-d: Flush context cache with correct SID when tearing down aliases
Lu Baolu <baolu.lu@linux.intel.com>
iommu/vt-d: Tear down scalable-mode context on probe failure
Lu Baolu <baolu.lu@linux.intel.com>
iommu/vt-d: Clear Present bit before tearing down copied context entry
Desnes Nunes <desnesn@redhat.com>
iommu/vt-d: Fix UCTP context table slot when copying root entries
Andrew Jones <andrew.jones@oss.qualcomm.com>
iommu/dma: Restore locking around msi_page_list
Karl Mehltretter <kmehltretter@gmail.com>
fbdev: clps711x-fb: Remove unreachable unregister_framebuffer() call
Danila Chernetsov <listdansp@mail.ru>
fbdev: kyro: Validate overlay viewport coordinates
Myeonghun Pak <mhun512@gmail.com>
fbdev: tdfxfb: fix PCI enable cleanup with pcim_enable_device()
Ian Rogers <irogers@google.com>
perf synthetic-events: Fix divide by zero in perf_event__synthesize_threads
Ian Rogers <irogers@google.com>
perf python: Fix memory leak in pyrf__metrics_cb
Ian Rogers <irogers@google.com>
perf python: Validate CPU and thread maps in pyrf_evsel__open
Ian Rogers <irogers@google.com>
perf python: Handle Py_None for thread and cpu maps
Ian Rogers <irogers@google.com>
perf python: Check counts_values size in set_values
Ian Rogers <irogers@google.com>
perf test: Fix skiplist leak in cmd_test
Ian Rogers <irogers@google.com>
perf test: Support dynamic test suites with setup callback and private data
Ian Rogers <irogers@google.com>
perf synthetic-events: Fix uninitialized pthread_join
Ian Rogers <irogers@google.com>
perf stat: Fix evsel_list leak in cmd_stat
Rosen Penev <rosenp@gmail.com>
ARM: dts: helios4: add SATA regulator supplies
Rosen Penev <rosenp@gmail.com>
ARM: dts: helios4: add vcc-supply to GPIO expander
Rosen Penev <rosenp@gmail.com>
ARM: dts: helios4: add vcc-supply to EEPROM
Tomáš Macholda <tomas.macholda@nic.cz>
arm64: dts: turris-mox: fix usb3 phys
Tommaso Merciai <tommaso.merciai.xr@bp.renesas.com>
i3c: renesas: Don't register devices when ENTDAA times out
Claudiu Beznea <claudiu.beznea.uj@bp.renesas.com>
i3c: renesas: Follow a unified pattern for transfer and command initialization
Claudiu Beznea <claudiu.beznea.uj@bp.renesas.com>
i3c: renesas: Return immediately if there is no transfer
Sanghyun Park <sanghyun.park.cnu@gmail.com>
bpf: Fix mmap_lock leak in irq_work path
Ihor Solodrai <ihor.solodrai@linux.dev>
bpf: Avoid faultable build ID reads under mm locks
Ihor Solodrai <ihor.solodrai@linux.dev>
bpf: Factor out stack_map build ID helpers
Guodong Xu <guodong@riscstar.com>
riscv: cpufeature: Clarify ISA spec version for canonical order
Victor Nogueira <victor@mojatatu.com>
net/sched: cls_api: fix teardown of an adopted proto on insert-race loss
Nikhil Gautam <nikhilgtr@gmail.com>
iio: light: gp2ap002: re-enable irq if runtime suspend fails
Nikhil Gautam <nikhilgtr@gmail.com>
iio: light: gp2ap002: Fix unbalanced runtime PM on repeated event writes
Vidhu Sarwal <vidhu.linux@gmail.com>
iio: light: opt4060: Fix pointer type passed to div_u64_rem()
Pu Lehui <pulehui@huawei.com>
bpf, cgroup: Fix storage null-ptr-deref after replacing prog
Ali Ahmet Memis <ali@iusegentoo.com>
Bluetooth: MSFT: validate evt_prefix_len against the response length
Guangshuo Li <lgs201920130244@gmail.com>
Bluetooth: btmtksdio: fix usage_count leak when autosuspend_delay is negative
Sean Wang <sean.wang@mediatek.com>
Bluetooth: btmtk: add MT7902 SDIO support
Sean Wang <sean.wang@mediatek.com>
Bluetooth: btmtk: add MT7902 MCU support
Sean Wang <sean.wang@mediatek.com>
mmc: sdio: add MediaTek MT7902 SDIO device ID
Linmao Li <lilinmao@kylinos.cn>
Bluetooth: MGMT: free the HCI command when it is cancelled
Linmao Li <lilinmao@kylinos.cn>
Bluetooth: MGMT: free the mesh send cancel command when it is cancelled
Linmao Li <lilinmao@kylinos.cn>
Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths
Linmao Li <lilinmao@kylinos.cn>
Bluetooth: hci_conn: fix the SCO setup context lifetime
Zijun Hu <zijun.hu@oss.qualcomm.com>
Bluetooth: btintel: Fix diagnostics event detection
HyeongJun An <sammiee5311@gmail.com>
Bluetooth: virtio_bt: avoid OOB read of build info string
Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
pinctrl: airoha: fix edge-triggered interrupts handling
Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
pinctrl: airoha: fix IRQ mask/unmask code
Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
pinctrl: airoha: add missed IRQ resource helpers
Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
pinctrl: airoha: fix getting gpiochip/pinctrl pointers in the IRQ handling code
Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
pinctrl: airoha: add missed get_direction() function for gpio_chip
Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
pinctrl: airoha: an7583: fix spi group pins
Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
pinctrl: airoha: an7583: fix muxing of non-gpio default pins
Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
pinctrl: airoha: an7581: fix mux/conf of pcie_reset pins
Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
pinctrl: airoha: fix pwm pin function for an7581 and an7583
Christian Marangi <ansuelsmth@gmail.com>
pinctrl: airoha: convert PWM GPIO to macro
Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
pinctrl: airoha: an7583: fix I2C0_SDA_PD register bit order
Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
pinctrl: airoha: an7581: fix pinconf of i2c_scl/i2c_sda pins
Mikhail Kshevetskiy <mikhail.kshevetskiy@iopsys.eu>
pinctrl: airoha: fix mdio bitfield names
Christian Marangi <ansuelsmth@gmail.com>
pinctrl: airoha: add support for Airoha AN7583 PINs
Christian Marangi <ansuelsmth@gmail.com>
pinctrl: airoha: convert PHY LED GPIO to macro
Qu Wenruo <wqu@suse.com>
btrfs: qgroup: fix a wrong length calculation in qgroup_free_reserved_data()
Leo Martins <loemra.dev@gmail.com>
btrfs: avoid GFP_ATOMIC allocations in qgroup free paths
Qu Wenruo <wqu@suse.com>
btrfs: use aligned range for locking in extent_fiemap()
Johannes Thumshirn <johannes.thumshirn@wdc.com>
btrfs: zoned: don't clobber the extent buffer when zeroing it out
Yichong Chen <chenyichong@uniontech.com>
btrfs: retry verity reads for not-uptodate Merkle folios
Qu Wenruo <wqu@suse.com>
btrfs: always wait for ordered extents to avoid OE races
David Sterba <dsterba@suse.com>
btrfs: merge setting ret and return ret
Qu Wenruo <wqu@suse.com>
btrfs: make btrfs_repair_io_failure() handle bs > ps cases without large folios
Filipe Manana <fdmanana@suse.com>
btrfs: defrag: fix deadlock between defrag and delalloc space reservation
Yang Xiuwei <yangxiuwei@kylinos.cn>
scsi: sd: Fix sd_done() sense handling condition
Yang Xiuwei <yangxiuwei@kylinos.cn>
scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails
Swarna Prabhu <sw.prabhu6@gmail.com>
scsi: sd: Enable sector size > PAGE_SIZE in SCSI sd driver
Bart Van Assche <bvanassche@acm.org>
scsi: sd: Move the sd_config_discard() function definition
Bart Van Assche <bvanassche@acm.org>
scsi: sd: Move the sd_remove() function definition
Uwe Kleine-König <u.kleine-koenig@baylibre.com>
scsi: sd: Convert to SCSI bus methods
Uwe Kleine-König <u.kleine-koenig@baylibre.com>
scsi: core: sysfs: Make use of bus callbacks
Uwe Kleine-König <u.kleine-koenig@baylibre.com>
scsi: core: Pass a struct scsi_driver to scsi_{,un}register_driver()
Tanushree Shah <tshah@linux.ibm.com>
perf trace-event: Fix integer truncation in do_read() and skip()
Zijun Hu <zijun.hu@oss.qualcomm.com>
Bluetooth: btusb: QCA: Fix populating devcoredump fields on unenabled devices
Zijun Hu <zijun.hu@oss.qualcomm.com>
Bluetooth: btusb: Record matched usb_device_id into btusb_data
Johan Hovold <johan@kernel.org>
Bluetooth: btusb: refactor endpoint lookup
Zijun Hu <zijun.hu@oss.qualcomm.com>
Bluetooth: btusb: Fix BD_ADDR byte order in btusb_set_bdaddr_wcn6855()
Zijun Hu <zijun.hu@oss.qualcomm.com>
Bluetooth: btqca: Fix qca_set_bdaddr() waiting for wrong HCI event
Ricardo Neri <ricardo.neri-calderon@linux.intel.com>
sched/fair: Check CPU capacity before comparing group types during load balance
Ricardo Neri <ricardo.neri-calderon@linux.intel.com>
sched/fair: Also gate overloaded status update for SD_ASYM_CPUCAPACITY
Adrian Hunter <adrian.hunter@intel.com>
perf/x86/intel/pt: Fix stop/start with no update
Adrian Hunter <adrian.hunter@intel.com>
perf/x86/intel/pt: Use bitwise access for PERF_HES_STOPPED
Adrian Hunter <adrian.hunter@intel.com>
perf/x86/intel/pt: Factor out pt_config_enable()
Yuho Choi <dbgh9129@gmail.com>
ACPI: video: Release PCI device reference after lookup
Kamal Wadhwa <kamal.wadhwa@oss.qualcomm.com>
regulator: qcom-rpmh: Fix PMIC5 BOB bypass mode handling
Daniel Borkmann <daniel@iogearbox.net>
bpf, arm64: Fix exception table metadata for arena load-acquire
Daniel Borkmann <daniel@iogearbox.net>
bpf, x86: Fix exception table metadata for arena load-acquire
Daniel Borkmann <daniel@iogearbox.net>
bpf, riscv: Add and use bpf_atomic_is_load_acq() helper
Daniel Borkmann <daniel@iogearbox.net>
bpf: Reject load-acquire from pointers requiring fault protection
James Clark <james.clark@linaro.org>
perf: arm_pmuv3: Zero initialize hw_id branch stack field
James Clark <james.clark@linaro.org>
coresight: Refactor etm4_config_timestamp_event()
Yeoreum Yun <yeoreum.yun@arm.com>
coresight: etm4x: fix leaked trace id
Yeoreum Yun <yeoreum.yun@arm.com>
coresight: etm4x: fix underflow for usage of (nrseqstate - 1)
James Clark <james.clark@linaro.org>
coresight: Change syncfreq to be a u8
Yeoreum Yun <yeoreum.yun@arm.com>
coresight: etm4x: fix wrong check of etm4x_sspcicrn_present()
Bruce Johnston <bjohnsto@redhat.com>
md/raid1: don't set array_frozen in raid1_takeover()
Yu Kuai <yukuai@fygo.io>
md/md-llbitmap: stop daemon timer rearm on destroy
Yu Kuai <yukuai@fygo.io>
md/md-llbitmap: prevent create failure bitmap UAF
Yu Kuai <yukuai@fygo.io>
md: avoid stale clone I/O accounting timestamps
Yu Kuai <yukuai@fygo.io>
md: wait for behind writes before destroying bitmap
Yu Kuai <yukuai@fygo.io>
md/raid5: round bitmap stripes with sector division
Esteban Urrutia <esteuwu@proton.me>
phy: qcom: qmp-pcie: Add pcs_lane1 offset to V5 offsets
Loic Poulain <loic.poulain@oss.qualcomm.com>
phy: qcom: qmp-usb: Fix possible NULL-deref on early runtime suspend
Loic Poulain <loic.poulain@oss.qualcomm.com>
phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend
Loic Poulain <loic.poulain@oss.qualcomm.com>
phy: qcom: qmp-usb-legacy: Fix possible NULL-deref on early runtime suspend
Mohd Ayaan Anwar <mohd.anwar@oss.qualcomm.com>
phy: qcom: sgmii-eth: vote for both voltage rails with correct current loads
Russell King (Oracle) <rmk+kernel@armlinux.org.uk>
phy: qcom-sgmii-eth: relax order of .power_on() vs .set_mode*()
Linkai Gong <gonglinkai@kylinos.cn>
soc: fsl: qe: check platform_driver_register() in qe_ic_of_init()
Yichong Chen <chenyichong@uniontech.com>
hugetlbfs: release subpool on fill_super failure
Simon Glass <sjg@chromium.org>
pinctrl: rockchip: Reset the pin count when recalculating SoC data
Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
firmware_loader: do not queue completed sysfs fallback requests
Manish Rangankar <mrangankar@marvell.com>
scsi: qla2xxx: Remove redundant VPD flash read in sysfs read path
Timur Kristóf <timur.kristof@gmail.com>
drm/amdgpu/gfx6: Use PFP on the compute queues too
Timur Kristóf <timur.kristof@gmail.com>
drm/amdgpu/gfx6: Fixup emitting SWITCH_BUFFER packets
Tanushree Shah <tshah@linux.ibm.com>
perf trace-event: Fix buffer overflow in read_string()
Gerald Loacker <gerald.loacker@wolfvision.net>
phy: rockchip: phy-rockchip-inno-csidphy: fix rk1808 hsfreq table
Felix Gu <ustc.gu@gmail.com>
phy: sunplus: fix error handling in sp_uphy_init()
Biju Das <biju.das.jz@bp.renesas.com>
phy: renesas: phy-rcar-gen3-usb2: Fix devm action registration for disabled VBUS regulator
Tommaso Merciai <tommaso.merciai.xr@bp.renesas.com>
phy: renesas: rcar-gen3-usb2: Add regulator for OTG VBUS control
Tommaso Merciai <tommaso.merciai.xr@bp.renesas.com>
phy: renesas: rcar-gen3-usb2: Factor out VBUS control logic
Meghana Malladi <m-malladi@ti.com>
arm64: dts: ti: k3-am64: Fix MDIO clock reference for ICSSG0 node
Jan Kara <jack@suse.cz>
ext4: fix spurious message about orphan cleanup on RO fs
Timur Kristóf <timur.kristof@gmail.com>
drm/amdgpu/gfx6: Fixup emit_cntxcntl()
Steve Dunnagan <sdunnaga@redhat.com>
leds: gpio: Clear error pointers for skipped LEDs
Arnd Bergmann <arnd@arndb.de>
leds: gpio: Make legacy gpiolib interface optional
Arnd Bergmann <arnd@arndb.de>
gpiolib: move legacy interface into linux/gpio/legacy.h
Sven Peter <sven@kernel.org>
mfd: macsmc: Fix key count endianness annotation
Pengpeng Hou <pengpeng@iscas.ac.cn>
mfd: iqs62x: Reject zero-length firmware records
Pengpeng Hou <pengpeng@iscas.ac.cn>
mfd: rave-sp: validate received frame payload lengths
Vladimir Murzin <vladimir.murzin@arm.com>
arm64: hibernate: Restore DAIF state on error
Ada Couprie Diaz <ada.coupriediaz@arm.com>
arm64: hibernate: mask DAIF before restoring hibernated kernel
Felix Fietkau <nbd@nbd.name>
wifi: mac80211: skip default WMM setup for AP_VLAN links
Leon Romanovsky <leon@kernel.org>
RDMA/erdma: restrict the driver to little-endian systems
Petr Pavlu <petr.pavlu@suse.com>
module/dups: Fix use-after-free in kmod_dup_req lifetime handling
Petr Pavlu <petr.pavlu@suse.com>
module/dups: Inform duplicate requests about the result directly
Naveen Kumar Chaudhary <naveen.osdev@gmail.com>
module: use strscpy() to copy module names in stats and dup tracking
Marco Crivellari <marco.crivellari@suse.com>
module: replace use of system_wq with system_dfl_wq
Shuangpeng Bai <shuangpeng.kernel@gmail.com>
RDMA/siw: Fix use-after-free in siw_accept()
Yehyeong Lee <yhlee@isslab.korea.ac.kr>
IB/isert: post the full-feature receive buffers after session registration
Yehyeong Lee <yhlee@isslab.korea.ac.kr>
IB/isert: delay the final Login Response until the session is registered
Karl Mehltretter <kmehltretter@gmail.com>
cpufreq: imx6q: fix out-of-bounds write when probed more than once
Karl Mehltretter <kmehltretter@gmail.com>
cpufreq: imx6q: fix devres accumulation across driver rebind
Priya Bala Govindasamy <pgovind2@uci.edu>
rust: cpufreq: Fix temporary write in Registration::bios_limit_callback
Priya Bala Govindasamy <pgovind2@uci.edu>
rust: cpufreq: Add CPUFREQ_TABLE_END as last table entry in TableBuilder::to_table
Jernej Skrabec <jernej.skrabec@gmail.com>
drm/sun4i: hdmi-phy: Fix H6 8-bit MPLL config at 594 MHz
Jernej Skrabec <jernej.skrabec@gmail.com>
drm/sun4i: dw-hdmi: Drop TCON TOP port reference
Jernej Skrabec <jernej.skrabec@gmail.com>
drm/sun4i: tcon: Drop remote endpoint reference
Jernej Skrabec <jernej.skrabec@gmail.com>
drm/sun4i: crtc: Propagate layer initialization error
Jernej Skrabec <jernej.skrabec@gmail.com>
drm/sun4i: hdmi: Don't leak sync polarity bits into packet control
Jernej Skrabec <jernej.skrabec@gmail.com>
drm/sun4i: tcon: Drop TCON TOP device reference
Jernej Skrabec <jernej.skrabec@gmail.com>
drm/sun4i: tcon: Set output mux for DSI and LVDS
Jernej Skrabec <jernej.skrabec@gmail.com>
drm/sun4i: vi scaler: Fix coefficient selection
Arnaldo Carvalho de Melo <acme@redhat.com>
perf c2c: Clean up registered formats on c2c_hists__init() and c2c_hists__reinit() failure
Arnaldo Carvalho de Melo <acme@redhat.com>
perf c2c: Fix error masking, OOM, and unchecked caller errors in hpp_list__parse()
Ian Rogers <irogers@google.com>
perf c2c: Use perf_env e_machine rather than arch
Namhyung Kim <namhyung@kernel.org>
perf report: Update sort key state from -F option
Namhyung Kim <namhyung@kernel.org>
perf report: Fix histogram entry collapsing for -F option
Tianyou Li <tianyou.li@intel.com>
perf c2c: Add annotation support to perf c2c report
Alexey Charkov <alchark@flipper.net>
clk: rockchip: rk3576: fix source muxes for SPI0..SPI4
Cen Zhang <zzzccc427@gmail.com>
ocfs2: synchronize heartbeat callbacks with o2net teardown
Arnaldo Carvalho de Melo <acme@redhat.com>
perf libbfd: Fix memory leaks and NULL fclose in BPF disassembly
Arnaldo Carvalho de Melo <acme@redhat.com>
perf bpf: Add PROG_TAGS to required arrays in __bpf_event__print_bpf_prog_info()
Arnaldo Carvalho de Melo <acme@redhat.com>
perf libbfd: Validate BPF prog info arrays before pointer cast
Xie Yuanbin <xieyuanbin1@huawei.com>
ARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults
Linus Walleij <linusw@kernel.org>
ARM: 9481/2: breakpoint: CFI breakpoints only on demand
Yehyeong Lee <yhlee@isslab.korea.ac.kr>
RDMA/srp: fix heap information leak on a truncated SRP_CRED_REQ
Cheng Xu <chengyou@linux.alibaba.com>
RDMA/erdma: Hold QP references for AE and CM processing
Cheng Xu <chengyou@linux.alibaba.com>
RDMA/erdma: Hold CQ references when processing EQ events
Yuntao Wang <yuntao.wang@linux.dev>
kbuild: fix modules.builtin(.modinfo) targets in the top-level Makefile
Robertus Diawan Chris <robertusdchris@gmail.com>
modpost: prevent leak when early return no suffix .o in read_symbols()
Sergei Litvin <litvindev@gmail.com>
scripts/tags.sh: Prevent binary files appearing in cscope.files
Rafael J. Wysocki <rafael.j.wysocki@intel.com>
intel_idle: Avoid using deep idle states during initialization
Artem Bityutskiy <artem.bityutskiy@linux.intel.com>
intel_idle: Add cmdline option to adjust C-states table
Artem Bityutskiy <artem.bityutskiy@linux.intel.com>
intel_idle: Initialize sysfs after cpuidle driver initialization
Daniel Borkmann <daniel@iogearbox.net>
bpf: Check load-acquire src ptr type before the load
Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
arm64: dts: qcom: sar2130p: Fix swapped USB QMP PHY vdda-phy/vdda-pll supplies
Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
arm64: dts: qcom: sm7225-fairphone-fp4: Fix swapped USB QMP PHY vdda-phy/vdda-pll supplies
Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
arm64: dts: qcom: qcs8550-aim300: Fix swapped USB QMP PHY vdda-phy/vdda-pll supplies
Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
arm64: dts: qcom: sc8280xp-blackrock: Fix swapped USB QMP PHY vdda-phy/vdda-pll supplies
Sayali Patil <sayalip@linux.ibm.com>
selftests/mm: fix ternary operator precedence in ksm_tests
Sayali Patil <sayalip@linux.ibm.com>
selftests/mm: fix ksm NUMA merge test for systems with memoryless NUMA nodes
Mike Rapoport (Microsoft) <rppt@kernel.org>
selftests/mm: ksm_tests: use kselftest framework
Pu Lehui <pulehui@huawei.com>
bpf, cgroup: Fix invalid storage access after __cgroup_bpf_attach failed
Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
remoteproc: fix OOB read via signed offset in rsc_table_for_each_entry()
Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
remoteproc: use rsc_table_for_each_entry() in rproc_handle_resources()
Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
remoteproc: Move resource table data structure to its own header
Imran Shaik <imran.shaik@oss.qualcomm.com>
arm64: dts: qcom: agatti: Add missing CX power domain to DISPCC
Andreas Kemnade <andreas@kemnade.info>
drm/omap: dsi: Do not copy isr table
Inochi Amaoto <inochiama@gmail.com>
riscv: dts: sophgo: cv180x: Allow the DMA multiplexer to set channel number for DMA controller
Yichong Chen <chenyichong@uniontech.com>
fat: release buffer head after rebuilding parent
Guangshuo Li <lgs201920130244@gmail.com>
rapidio: clear mport->net when rio_add_net() fails
Calvin Owens <calvin@wbinvd.org>
pps-gpio: remove dead capture_clear code
Michael Byczkowski <by@by-online.de>
pps: pps-gpio: split IRQ handler into hardirq timestamper + threaded handler
Calvin Owens <calvin@wbinvd.org>
pps: don't try to wait for negative timeouts in PPS_FETCH
Bradley Morgan <include@grrlz.net>
lib/string: fix memchr_inv() for large ranges
Cen Zhang <zzzccc427@gmail.com>
ocfs2/cluster: keep heartbeat local node stable
Caleb Sander Mateos <csander@purestorage.com>
ublk: check for ublk_unmap_io() returning 0
Caleb Sander Mateos <csander@purestorage.com>
ublk: check import_ubuf() return value
Tao Cui <cuitao@kylinos.cn>
block/kyber-iosched: flush per-cpu latency buckets over possible CPUs
Tao Cui <cuitao@kylinos.cn>
block/blk-iocost: collect per-cpu latency stats over possible CPUs
Tao Cui <cuitao@kylinos.cn>
block/blk-stat: drain per-cpu callback stats over possible CPUs
Zheng Qixing <zhengqixing@huawei.com>
blk-cgroup: skip dying blkg in blkcg_activate_policy()
Zheng Qixing <zhengqixing@huawei.com>
blk-cgroup: fix race between policy activation and blkg destruction
Breno Leitao <leitao@debian.org>
phonet: pep: do not write beyond optlen in getsockopt
Zxyan Zhu <zxyan0222@gmail.com>
net: stmmac: Skip PHY attach if custom PCS is in use
Sang-Heon Jeon <ekffu200098@gmail.com>
iio: light: tsl2583: return zero in write_raw() on success
Sang-Heon Jeon <ekffu200098@gmail.com>
iio: light: isl29028: return zero in write_raw() on success
Yuanshen Cao <alex.caoys@gmail.com>
iio: light: tsl2772: fix ALS calibscale readback
Arnaldo Carvalho de Melo <acme@redhat.com>
perf arm-spe: Reject zero nr_cpu in metadata to prevent division by zero
Arnaldo Carvalho de Melo <acme@redhat.com>
perf intel-bts: Fix off-by-one in auxtrace_info minimum size check
Arnaldo Carvalho de Melo <acme@redhat.com>
perf intel-pt: Fix off-by-one in auxtrace_info minimum size check
Arnaldo Carvalho de Melo <acme@redhat.com>
perf auxtrace: Fix queue grow overflow and old array leak
Arnaldo Carvalho de Melo <acme@redhat.com>
perf thread-stack: Fix heap buffer overflow on branch stack wrap copy
Jiancheng Huang <jchuang@seu.edu.cn>
HID: lg4ff: validate report length before fixed offsets
Chao Huang <huangchao@kylinos.cn>
HID: i2c-hid: goodix: Disable VDD on VDDIO enable failure
Vicki Pfau <vi@endrift.com>
HID: steam: Reject short reads
Vicki Pfau <vi@endrift.com>
HID: steam: Improve logging and other cleanup
Vicki Pfau <vi@endrift.com>
HID: steam: Add support for sensor events on the Steam Controller (2015)
Vicki Pfau <vi@endrift.com>
HID: steam: Rename some constants that got renamed upstream
Vicki Pfau <vi@endrift.com>
HID: steam: Refactor and clean up report parsing
Ai Chao <aichao@kylinos.cn>
HID: i2c-hid: Fix "(null)" output when reading report descriptor fails
Yousef Alhouseen <alhouseenyousef@gmail.com>
HID: synchronize input before cleaning up a failed probe
谢致邦 (XIE Zhibang) <Yeking@Red54.com>
HID: i2c-hid: Refactor _DSM helper and add i2c-hid-acpi-prp0001 driver
Niklas Cassel <cassel@kernel.org>
misc: pci_endpoint_test: Check SUCCESS bit for doorbell status
Shukai Ni <shukai.ni@kuleuven.be>
dm-integrity: replace forgeable discard filler with a keyed sector marker
Karl Mehltretter <kmehltretter@gmail.com>
tty: clear cdev pointer after cdev_add() failure
Karl Mehltretter <kmehltretter@gmail.com>
serial: amba-pl011: keep console clock enabled for atomic writes
Karl Mehltretter <kmehltretter@gmail.com>
serial: amba-pl011: unprepare console clock on unregister
Thomas Bogendoerfer <tsbogend@alpha.franken.de>
MIPS: ptrace: Fix syscall skipping via PTRACE_SYSCALL
Christophe Leroy (CS GROUP) <chleroy@kernel.org>
soc: fsl: qe: implement get_direction()
Christophe Leroy (CS GROUP) <chleroy@kernel.org>
soc: fsl: qe: properly scan GPIO nodes at startup
Saket Kumar Bhaskar <skb99@linux.ibm.com>
powerpc/irq: Fix missing r2 clobber in PCREL inline assembly
Gou Hao <gouhao@uniontech.com>
powerpc/smp: add NULL guard for cause_ipi in smp_muxed_ipi_message_pass
Troy Mitchell <troy.mitchell@linux.spacemit.com>
pinctrl: spacemit: validate pins in pinconf callbacks
Yulin Lu <luyulin@eswincomputing.com>
pinctrl: eswin: Fix Handling of PIN_CONFIG_PERSIST_STATE
Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
firmware: coreboot: Validate table bounds
Titouan Ameline de Cadeville <titouan.ameline@gmail.com>
firmware: google: Add bounds checks in coreboot_table_populate()
Zhao Li <enderaoelyther@gmail.com>
wifi: cfg80211: stop PMSR before P2P and NAN teardown
Miri Korenblit <miriam.rachel.korenblit@intel.com>
wifi: cfg80211: Add an API to configure local NAN schedule
Johannes Berg <johannes.berg@intel.com>
wifi: nl80211: split out UHR operation information
Miri Korenblit <miriam.rachel.korenblit@intel.com>
wifi: nl80211: refactor nl80211_parse_chandef
Hari Chandrakanthan <quic_haric@quicinc.com>
wifi: cfg80211: add support to handle incumbent signal detected event from mac80211/driver
Johannes Berg <johannes.berg@intel.com>
wifi: cfg80211: add initial UHR support
Johannes Berg <johannes.berg@intel.com>
wifi: ieee80211: add some initial UHR definitions
Sai Pratyusha Magam <sai.magam@oss.qualcomm.com>
wifi: nl80211: Add support for EPP peer indication
Lachlan Hodges <lachlan.hodges@morsemicro.com>
wifi: cfg80211: include S1G_NO_PRIMARY flag when sending channel
Johannes Berg <johannes.berg@intel.com>
wifi: mac80211: disconnect on CSA to channel 0
Zhao Li <enderaoelyther@gmail.com>
wifi: mac80211: skip unused probe response countdown offsets
Slawomir Stepien <sst@poczta.fm>
wifi: zd1211rw: reject secondary interfaces to prevent conflicts
Zhao Li <enderaoelyther@gmail.com>
wifi: mac80211: send TWT teardown to peer after setup TX failure
Davidlohr Bueso <dave@stgolabs.net>
perf/cxlpmu: Fix 64-bit write to 32-bit HDM filter register
Pranjal Shrivastava <praan@google.com>
iommu/arm-smmu-v3: Convert to use atomic poll timeout
Mark Brown <broonie@kernel.org>
kselftest/arm64: Don't write to P0 in irritator on SME only systems
Karl Mehltretter <kmehltretter@gmail.com>
kselftest/arm64: fp-ptrace: Fix checks for inactive SVE and SSVE regsets
Karl Mehltretter <kmehltretter@gmail.com>
arm64/fpsimd: ptrace: Fix inactive SVE and SSVE regsets
Vladimir Murzin <vladimir.murzin@arm.com>
arm64: smp: Fix IPI teardown for GICv5 flow
Jose Ignacio Tornos Martinez <jtornosm@redhat.com>
wifi: mt76: mt7996: remove beacon_int_min_gcd from ADHOC interface combinations
Linghui Wu <linghui.wu@oss.qualcomm.com>
wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump
Felix Fietkau <nbd@nbd.name>
wifi: mt76: mt7996: fix out-of-bounds link array access in mt7996_tx()
Felix Fietkau <nbd@nbd.name>
wifi: mt76: reject out-of-range link ids in mt76_vif_link()
shengwei.lu <shengwei.lu@mediatek.com>
wifi: mt76: mt7925: Fix EHT Beamformee SS subfields to meet 802.11be minimum
Javier Tia <floss@jetm.me>
wifi: mt76: mt7925: advertise EHT 320MHz capabilities for 6GHz band
Peter Chiu <chui-hao.chiu@mediatek.com>
wifi: mt76: fix queue assignment for disassoc packets
Felix Fietkau <nbd@nbd.name>
wifi: mt76: mt7915: report RX chain signal for all RX paths
Felix Fietkau <nbd@nbd.name>
wifi: mt76: mt7915: fix chainmask handling for non-dbdc phys on band 1
Felix Fietkau <nbd@nbd.name>
wifi: mt76: mt7996: do not attach hif2 WED when the main WED attach failed
StanleyYP Wang <StanleyYP.Wang@mediatek.com>
wifi: mt76: mt7996: fix reg addr remap when addr is 0
Felix Fietkau <nbd@nbd.name>
wifi: mt76: mt7915: release hif2 reference on probe IRQ failure
Felix Fietkau <nbd@nbd.name>
wifi: mt76: mt7915: fix ext PHY use-after-free on register error path
Felix Fietkau <nbd@nbd.name>
wifi: mt76: mt7915: fix double hif2 init on the non-WED path
Felix Fietkau <nbd@nbd.name>
wifi: mt76: mt7996: fix MIB TX aggregation counter registers for mt7990
Felix Fietkau <nbd@nbd.name>
wifi: mt76: mt7996: free vif links after clearing wcid entries on full reset
Felix Fietkau <nbd@nbd.name>
wifi: mt76: mt7996: wake MCU waiters before aborting scan in L1 SER
Felix Fietkau <nbd@nbd.name>
wifi: mt76: mt7996: skip key upload when adding an offchannel link
Felix Fietkau <nbd@nbd.name>
wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement
Yonghong Song <yonghong.song@linux.dev>
bpf, x86: Fix trampoline stack size for 128-bit arguments
Arnaldo Carvalho de Melo <acme@redhat.com>
perf machine: Check snprintf truncation for guest kallsyms path
Arnaldo Carvalho de Melo <acme@redhat.com>
perf machine: Free scandir entries in guest kernel map creation
Arnaldo Carvalho de Melo <acme@redhat.com>
perf machine: Reset errno before strtol in guest kernel map creation
Arnaldo Carvalho de Melo <acme@redhat.com>
perf machine: Don't abort guest map creation on first inaccessible dir
Arnaldo Carvalho de Melo <acme@redhat.com>
perf machine: Check snprintf truncation in machines__findnew()
Arnaldo Carvalho de Melo <acme@redhat.com>
perf machine: Guard against NULL strlist in machines__findnew()
Arnaldo Carvalho de Melo <acme@redhat.com>
perf machine: Fix NULL parent dereference in fork event processing
Arnaldo Carvalho de Melo <acme@redhat.com>
perf machine: Fix fd leak on bounds check in maps__set_modules_path_dir()
Joy Zou <joy.zou@oss.nxp.com>
regulator: core: use system_freezable_wq for init complete work
Andrey Golovko <andrey.golovko@gmail.com>
ASoC: tas2783-sdw: drop stale regcache on uninitialized re-attach
Pengpeng Hou <pengpeng@iscas.ac.cn>
ASoC: codecs: tas2783-sdw: Propagate regcache_sync() errors
Charles Keepax <ckeepax@opensource.cirrus.com>
ASoC: tas2783: Use new SoundWire enumeration helper
Charles Keepax <ckeepax@opensource.cirrus.com>
soundwire: Add a helper function to wait for device initialisation
Jeff Johnson <jeff.johnson@oss.qualcomm.com>
wifi: ath11k: fix leak in ath11k_service_ready_ext_event()
Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
drm/msm/dsi: Drop dev_pm_opp_set_rate(0)
Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
drm/msm/dp: Drop dev_pm_opp_set_rate(0)
Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
drm/msm/dpu: Drop sneaky dev_pm_opp_set_rate(0)
Leo Yan <leo.yan@arm.com>
perf: arm_spe: Make wakeup range check overflow safe
Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
drm/msm/dp: do not reject wide-bus modes while a YUV420 mode is active
Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
drm/msm/dp: reject YUV420-only modes without VSC SDP support
Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
drm/msm: don't tear down KMS twice when KMS init fails
Can Peng <pengcan@kylinos.cn>
ACPI: processor: Unregister cpufreq notifier on init failure
Huisong Li <lihuisong@huawei.com>
ACPI: processor: idle: Optimize ACPI idle driver registration
Felix Fietkau <nbd@nbd.name>
wifi: mt76: only consume the WO drop bit on WED v2 devices
StanleyYP Wang <StanleyYP.Wang@mediatek.com>
wifi: mt76: mt7996: add missing rdd_idx check when enabling background radar
Felix Fietkau <nbd@nbd.name>
wifi: mt76: mt7915: use little-endian for bss_info_ra wire fields
Felix Fietkau <nbd@nbd.name>
wifi: mt76: mt7996: don't leak MLD group index on remap alloc failure
Felix Fietkau <nbd@nbd.name>
wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV
Felix Fietkau <nbd@nbd.name>
wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER
Felix Fietkau <nbd@nbd.name>
wifi: mt76: mt7915: unwind state on add_interface failure
Felix Fietkau <nbd@nbd.name>
wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config
Rex Lu <rex.lu@mediatek.com>
wifi: mt76: check txfree done event on the WED hw path
Felix Fietkau <nbd@nbd.name>
wifi: mt76: mt7915: poll the correct SLP CTRL register for the second adie
Felix Fietkau <nbd@nbd.name>
wifi: mt76: fix RXDMAD_C buffer recycling race
Felix Fietkau <nbd@nbd.name>
wifi: mt76: fix uninitialised RXDMAD_C descriptor info
Felix Fietkau <nbd@nbd.name>
wifi: mt76: fix stranded frames in mt76_txq_schedule_pending
Felix Fietkau <nbd@nbd.name>
wifi: mt76: mt7915: write RX header translation bit to the correct register
Felix Fietkau <nbd@nbd.name>
wifi: mt76: mt7996: don't report a zero TX bitrate
Felix Fietkau <nbd@nbd.name>
wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss
Felix Fietkau <nbd@nbd.name>
wifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear
Felix Fietkau <nbd@nbd.name>
wifi: mt76: mt7996: set MT76_MCU_RESET before waking MCU waiters on full reset
Felix Fietkau <nbd@nbd.name>
wifi: mt76: mt7996: validate RX band_idx before dereferencing phys[]
Michael-CY Lee <michael-cy.lee@mediatek.com>
wifi: mt76: assign link_id when sending probe request during scan
Michael-CY Lee <michael-cy.lee@mediatek.com>
wifi: mt76: fix non-AQL packet accounting for MLO stations
Peter Chiu <chui-hao.chiu@mediatek.com>
wifi: mt76: mt7996: fix MLD ID in MAC TXD and HIF TXP
Felix Fietkau <nbd@nbd.name>
wifi: mt76: mt7996: fix out-of-bounds array access during hardware restart
StanleyYP Wang <StanleyYP.Wang@mediatek.com>
wifi: mt76: mt7996: set specific BSSINFO and STAREC commands after channel switch
Shayne Chen <shayne.chen@mediatek.com>
wifi: mt76: mt7996: support fixed rate for link station
Rex Lu <rex.lu@mediatek.com>
wifi: mt76: fix RX data queuing of RRO 3.0
Shayne Chen <shayne.chen@mediatek.com>
wifi: mt76: mt7996: fix capability of EHT-MCS 15 in MRU
Chad Monroe <chad@monroe.io>
wifi: mt76: mt7996: fix EAPOL source BSS for non-MLD stations
Eason Lai <Eason.Lai@mediatek.com>
wifi: mt76: mt792x: Fix memory leak in SDIO TX path
Jared.Huang <jared.huang@mediatek.com>
wifi: mt76: mt7925: fix msg len mismatch between driver and firmware
Jared.Huang <jared.huang@mediatek.com>
wifi: mt76: mt7925: update clc before setting sar power table
Eason Lai <Eason.Lai@mediatek.com>
wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash
Lorenzo Bianconi <lorenzo@kernel.org>
wifi: mt76: always enable RRO queues for non-MT7992 chipset
Lorenzo Bianconi <lorenzo@kernel.org>
wifi: mt76: Introduce the NPU generic layer
Lorenzo Bianconi <lorenzo@kernel.org>
wifi: mt76: Move Q_READ/Q_WRITE definitions in dma.h
Zhi-Jun You <hujy652@gmail.com>
wifi: mt76: mt7915: fix net_fill_forward_path for non-DBDC mt7986
Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
wifi: mt76: mt7921: validate CLC firmware records
Devin Wittmayer <lucid_duck@justthetip.ca>
wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length
Dmitry Gomzyakov <nicerok11@gmail.com>
wifi: mt76: connac: add MT7991A (0x7991) to is_mt7996()
Yichong Chen <chenyichong@uniontech.com>
fanotify: report full event length for FIONREAD
Muhammad Usama Anjum <usama.anjum@arm.com>
misc: sgi-gru: remove interrupt-context page-table walks
Abdun Nihaal <nihaal@cse.iitm.ac.in>
misc: vmc_vmci: Fix potential memory leak in vmci_event_subscribe()
Jinjie Ruan <ruanjinjie@huawei.com>
powerpc/crash: Fix possible memory leak in update_crash_elfcorehdr()
Rosen Penev <rosenp@gmail.com>
powerpc/44x: Set GPIO chip parent
Christophe Leroy (CS GROUP) <chleroy@kernel.org>
powerpc: implement get_direction() in cpm2
Naveen Kumar Chaudhary <naveen.osdev@gmail.com>
locking/lockdep: Fix NULL pointer dereference in __lock_set_class()
Martin Wilck <mwilck@suse.com>
md/raid1: create serial pool adding rdev to array with serialize_policy=1
Yu Peng <pengyu@kylinos.cn>
fs: annotate inode timestamp accessors
Can Peng <pengcan@kylinos.cn>
i3c: master: adi: add OF module alias for autoloading
Jakub Kicinski <kuba@kernel.org>
i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices
Aneesh Kumar K.V (Arm) <aneesh.kumar@kernel.org>
swiotlb: Preserve allocation virtual address for dynamic pools
Aneesh Kumar K.V (Arm) <aneesh.kumar@kernel.org>
iommu/dma: Check atomic pool allocation result directly
Chen Cheng <chencheng@fnnas.com>
md: scope memalloc_noio to allocation critical sections
Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com>
md: skip redundant raid_disks update when value is unchanged
Chen Cheng <chencheng@fnnas.com>
md: remove unused mddev argument from export_rdev
Chen Cheng <chencheng@fnnas.com>
md/bitmap: resume array on backlog_store() error path
Vladimir Zapolskiy <vz@kernel.org>
clk: qcom: Return expected ENOMEM error on dynamic allocation failure
Imran Shaik <imran.shaik@oss.qualcomm.com>
clk: qcom: gpucc-qcm2290: Park RCG's clk source at XO during disable
Stanislav Kinsburskii <skinsburskii@linux.microsoft.com>
lib/test_hmm: fail dmirror_fault() when the mirrored mm is gone
Pu Lehui <pulehui@huawei.com>
bpf: Fix potential UAF when reading bpf link info
Pu Lehui <pulehui@huawei.com>
bpf: Fix potential UAF in bpf_netns_link_update_prog
Hongyan Xu <getshell@seu.edu.cn>
power: supply: sc2731_charger: cancel work on remove
Hongyan Xu <getshell@seu.edu.cn>
power: supply: isp1704_charger: cancel work on remove
Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
arm64: dts: qcom: qcs6490-rb3gen2: Fix the PCIe iommu-map entries
Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
arm64: dts: qcom: lemans: Fix the PCIe iommu-map entries
Shawn Guo <shengchao.guo@oss.qualcomm.com>
arm64: dts: qcom: lemans: Move PCIe devices into soc node
Odelu Kukatla <odelu.kukatla@oss.qualcomm.com>
arm64: dts: qcom: sa8775p: Add reg and clocks for QoS configuration
Abhinaba Rakshit <abhinaba.rakshit@oss.qualcomm.com>
arm64: dts: qcom: lemans: add QCrypto node
Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
arm64: dts: qcom: lemans: add refgen regulator and use it for DSI
Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
arm64: dts: qcom: lemans: move USB PHYs to a proper place
Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
arm64: dts: qcom: talos: Fix the PCIe iommu-map entries
Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
arm64: dts: qcom: sm8750: Fix the PCIe iommu-map entries
Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
arm64: dts: qcom: sm8650: Fix the PCIe iommu-map entries
Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
arm64: dts: qcom: sm8550: Fix the PCIe iommu-map entries
Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
arm64: dts: qcom: sm8450: Fix the PCIe iommu-map entries
Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
arm64: dts: qcom: sm8350: Fix the PCIe iommu-map entries
Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
arm64: dts: qcom: sm8250: Fix the PCIe iommu-map entries
Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
arm64: dts: qcom: sm8150: Fix the PCIe iommu-map entries
Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
arm64: dts: qcom: sdm845: Fix the PCIe iommu-map entries
Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
arm64: dts: qcom: sc8180x: Fix the PCIe iommu-map entries
Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
arm64: dts: qcom: sar2130p: Fix the PCIe iommu-map entries
Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
arm64: dts: qcom: kodiak: Fix the PCIe iommu-map entries
Dawid Wróbel <me@dawidwrobel.com>
arm64: dts: qcom: sm8250-xiaomi-elish: correct the board ID
Keith Busch <kbusch@kernel.org>
block: fix dio leak on metadata mapping error
Christoph Hellwig <hch@lst.de>
block: add a bio_endio_status helper
Christoph Hellwig <hch@lst.de>
block: don't set BIO_QUIET for BLK_STS_AGAIN
Christoph Hellwig <hch@lst.de>
blk-crypto: use on-stack skcipher requests for fallback en/decryption
Christoph Hellwig <hch@lst.de>
blk-crypto: optimize bio splitting in blk_crypto_fallback_encrypt_bio
Christoph Hellwig <hch@lst.de>
blk-crypto: submit the encrypted bio in blk_crypto_fallback_bio_prep
Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
firmware: qcom: scm: Fix tzmem state on probe retry
Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
firmware: qcom: scm: Fix reserved memory cleanup on probe failure
Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
firmware: qcom: scm: Fix NULL dereference in IRQ handler before __scm is published
Yuvaraj Ranganathan <yuvaraj.ranganathan@oss.qualcomm.com>
firmware: qcom: scm: instrument SMC call path with tracepoints
Yuvaraj Ranganathan <yuvaraj.ranganathan@oss.qualcomm.com>
firmware: qcom: scm: add trace events for the SMC call interface
Unnathi Chalicheemala <unnathi.chalicheemala@oss.qualcomm.com>
firmware: qcom_scm: Support multiple waitq contexts
Unnathi Chalicheemala <unnathi.chalicheemala@oss.qualcomm.com>
firmware: qcom_scm: Add API to get waitqueue IRQ info
Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
arm64: dts: qcom: sc8280xp-crd: Fix the pin index for misc_3p3_reg_en
Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
clk: qcom: gcc-qcm2290: don't park QUP RCGs upon registration
Krishna Kurapati <krishna.kurapati@oss.qualcomm.com>
arm64: dts: qcom: qcs404: Fix DTBS Check errors in usb controller nodes
Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
arm64: dts: qcom: sdm632-motorola-ocean: Fix LED default trigger property
Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
arm64: dts: qcom: msm8976-longcheer-l9360: Fix accidental node override
Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
arm64: dts: qcom: msm8998: Don't pull-up I2C pins by default in sleep
Itai Handler <itai.handler@gmail.com>
rcu: Mark accesses to ->rcu_urgent_qs and ->rcu_need_heavy_qs
Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com>
md/raid10: consistently fail atomic writes that require splitting
Jeff Johnson <jeff.johnson@oss.qualcomm.com>
wifi: ath11k: fix stride mismatch in mac_phy_caps_parse()
Jeff Johnson <jeff.johnson@oss.qualcomm.com>
wifi: ath12k: fix stride mismatch in mac_phy_caps_parse()
Fushuai Wang <wangfushuai@baidu.com>
Revert "serial: 8250: Clear CON_PRINTBUFFER on port re-registration"
Cheng-Han Wu <hank20010209@gmail.com>
selftests/zram: fix kernel_gte() for POSIX sh
Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com>
md: recheck spare changes before starting sync
Thomas Weißschuh <thomas.weissschuh@linutronix.de>
tools/nolibc/powerpc: mark ctr and xer as clobbered by system call
Yichong Chen <chenyichong@uniontech.com>
fanotify: stop permission watchdog when timeout is zero
Chen Cheng <chencheng@fnnas.com>
md/raid5: protect lockless recovery_offset accesses during reshape
Sajal Gupta <sajal2005gupta@gmail.com>
md/raid5-ppl: fix use-after-free in ppl_do_flush()
Chen Cheng <chencheng@fnnas.com>
md/raid5: protect bitmap batch counters aka seq_flush/seq_write consistency
Yuho Choi <dbgh9129@gmail.com>
bus: mhi: host: Fix controller cleanup on EDL sysfs failure
Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
bus: mhi: host: Flush the posted write after writing to MHI_SOC_RESET_REQ_OFFSET
Abdun Nihaal <nihaal@cse.iitm.ac.in>
wifi: rtlwifi: pci: fix error path in rtl_pci_probe()
Hongyan Xu <getshell@seu.edu.cn>
platform/chrome: cros_ec_debugfs: Unregister panic notifier
Hongyan Xu <getshell@seu.edu.cn>
platform/chrome: cros_ec_debugfs: Clean up console log on probe failure
Jens Remus <jremus@linux.ibm.com>
s390/vdso: Pass --eh-frame-hdr to the linker
Heiko Carstens <hca@linux.ibm.com>
s390/vdso: Rename vdso64 to vdso
Heiko Carstens <hca@linux.ibm.com>
s390: Add stackprotector support
Heiko Carstens <hca@linux.ibm.com>
s390: Remove compat support
Heiko Carstens <hca@linux.ibm.com>
s390/syscalls: Add pt_regs parameter to SYSCALL_DEFINE0() syscall wrapper
Heiko Carstens <hca@linux.ibm.com>
s390/ptrace: Rename psw_t32 to psw32_t
Hungyu Lin <dennylin0707@gmail.com>
media: qcom: iris: handle runtime PM resume failure in core deinit
Dikshita Agarwal <dikshita.agarwal@oss.qualcomm.com>
media: qcom: iris: Fix bitmask test in iris_allow_cmd()
Anna Maniscalco <anna.maniscalco2000@gmail.com>
drm/msm: remove objects from evit list after pinning them
Ali Tariq <alitariq45892@gmail.com>
PCI: starfive: Fix unchecked pm_runtime_get_sync() in probe
Ali Tariq <alitariq45892@gmail.com>
PCI: starfive: Fix Runtime PM handling and teardown ordering
Jeff Johnson <jeff.johnson@oss.qualcomm.com>
wifi: ath12k: validate TLV length in process_tpc_stats()
Jeff Johnson <jeff.johnson@oss.qualcomm.com>
wifi: ath11k: fix overreads in ath11k_wmi_process_csa_switch_count_event()
Fan Wu <fanwu01@zju.edu.cn>
spi: davinci: switch to managed controller allocation
Guixin Liu <kanie@linux.alibaba.com>
nvme-fc: unmap cmd_iu DMA on rsp_iu mapping failure in init_request
Yehyeong Lee <yhlee@isslab.korea.ac.kr>
IB/isert: reject login PDUs declaring more data than was received
Yehyeong Lee <yhlee@isslab.korea.ac.kr>
IB/isert: reject PDUs declaring more data than was received
Cong Nguyen <congnt264@gmail.com>
media: staging/ipu7: fix async notifier leak on init error
Leon Romanovsky <leon@kernel.org>
RDMA/cxgb4: free STAG index when TPT entry write fails
Leon Romanovsky <leon@kernel.org>
RDMA/mlx5: Send cong param changes to the resolved port mdev
Leon Romanovsky <leon@kernel.org>
RDMA/mlx5: Fix stack out-of-bounds read in cc_params debugfs
David Strahan <David.Strahan@microchip.com>
scsi: smartpqi: Fix AIO retry marker cleared by SCSI core between dispatches.
Ryusuke Konishi <konishi.ryusuke@gmail.com>
nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state mismatch
David Lee <david.lee@trailofbits.com>
nilfs2: prevent out-of-bounds read in super root block parsing
Joshua Crofts <joshua.crofts1@gmail.com>
nilfs2: fix infinite loop in nilfs_clean_segments()
Alexey Charkov <alchark@flipper.net>
clk: rockchip: Fix the fractional part denominator on RK3588/RK3576 PLLs
Akari Tsuyukusa <akkun11.open@gmail.com>
clk: mediatek: mt8135: Fix inverted gate control for devapc_ck
longlong yan <yanlonglong@kylinos.cn>
clk/x86: pmc_atom: add kasprintf return value check
Myeonghun Pak <mhun512@gmail.com>
clk: palmas: Manage external-control prepare with devm
Louis-Alexis Eyraud <louisalexis.eyraud@collabora.com>
clk: mediatek: pllfh: Fix IO remapping leak in register_pllfhs error path
Nicolas Frattaroli <nicolas.frattaroli@collabora.com>
clk: mediatek: Refactor pllfh registration to pass device
Nicolas Frattaroli <nicolas.frattaroli@collabora.com>
clk: mediatek: Pass device to clk_hw_register for PLLs
Nicolas Frattaroli <nicolas.frattaroli@collabora.com>
clk: mediatek: Refactor pll registration to pass device
Guangshuo Li <lgs201920130244@gmail.com>
clk: tegra: tegra124-emc: put EMC node on register failure
Ondrej Jirman <megi@xff.cz>
arm64: dts: allwinner: sun50i-a64-pinephone: Fix mpu6050 mount matrix
Zhao Li <enderaoelyther@gmail.com>
wifi: mac80211: fix per-STA profile length in cross-link CSA parsing
Yonatan Nachum <ynachum@amazon.com>
RDMA/efa: Fix PBL chunk length computation
Peiyang He <peiyang_he@smail.nju.edu.cn>
RDMA/rxe: Fix UAF in ODP init error-handling path
Nicolin Chen <nicolinc@nvidia.com>
iommu/tegra241-cmdqv: Fix VINTF0 leak on the init-failure path
Nicolin Chen <nicolinc@nvidia.com>
iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID
Nicolin Chen <nicolinc@nvidia.com>
iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs
Nicolin Chen <nicolinc@nvidia.com>
iommu/tegra241-cmdqv: Don't run the error ISR before probe sets up vintfs
Nicolin Chen <nicolinc@nvidia.com>
iommu/tegra241-cmdqv: Synchronize the error ISR against VINTF (de)init
Nicolin Chen <nicolinc@nvidia.com>
iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized
Weiming Shi <bestswngs@gmail.com>
fs/ntfs3: reject restart table growth beyond U16_MAX entries
Ivy Lopez <skunkolee@gmail.com>
staging: rtl8723bs: use kfree_sensitive() for key material
Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
firmware: qcom_scm: Introduce PAS context allocator helper function
Bjorn Andersson <bjorn.andersson@oss.qualcomm.com>
remoteproc: Prevent crash handling to race with rproc_del()
Jingyi Wang <jingyi.wang@oss.qualcomm.com>
remoteproc: core: Attach rproc asynchronously in rproc_add() path via schedule_work()
Bjorn Andersson <bjorn.andersson@oss.qualcomm.com>
remoteproc: Allow shutdown of crashed processors
Peng Fan <peng.fan@nxp.com>
remoteproc: core: Drop redundant initialization of 'ret' in rproc_shutdown()
K Prateek Nayak <kprateek.nayak@amd.com>
cpufreq/amd-pstate: Set min_limit_freq based on bios_min_perf
Juan Martinez <juan.martinez@amd.com>
cpufreq/amd-pstate: Add comment explaining nominal_perf usage for performance policy
Babanpreet Singh <bbnpreetsingh@gmail.com>
w1: ds2482: Fix signedness bug in ds2482_w1_triplet()
Fan Wu <fanwu01@zju.edu.cn>
spi: oc-tiny: switch to managed controller allocation
Myeonghun Pak <mhun512@gmail.com>
clk: mediatek: mt6735: Unregister PLLs on probe failure
Yichong Chen <chenyichong@uniontech.com>
isofs: release zisofs block pointer buffer head
Sumeet Pawnikar <sumeet4linux@gmail.com>
powercap: intel_rapl_tpmi: Handle PMU registration failure during probe
Rakesh Kota <rakesh.kota@oss.qualcomm.com>
thermal/drivers/qcom-spmi-adc-tm5: Drop IIO_VAL_INT check in adc_tm5_get_temp
Christian Marangi <ansuelsmth@gmail.com>
thermal/drivers/airoha: Fix copy paste error for sen internal
Christian Marangi <ansuelsmth@gmail.com>
thermal/drivers/airoha: Fix copy paste error on clamp_t low temp
Maher Sanalla <msanalla@nvidia.com>
RDMA/mlx5: Fix integer overflow of user QP buffer size
Can Peng <pengcan@kylinos.cn>
crypto: keembay - publish OF module alias for OCS AES/SM4
Linmao Li <lilinmao@kylinos.cn>
crypto: keembay - Initialize completion before requesting IRQ
Li Qiang <liqiang01@kylinos.cn>
scsi: ufs: debugfs: Reserve space for a string terminator
Babanpreet Singh <bbnpreetsingh@gmail.com>
power: supply: sbs-battery: Use a per-device serial number buffer
Kohei Enju <enju.kohei@fujitsu.com>
arm64: RSI: fix field-spanning write warning in attestation token init
James Clark <james.clark@linaro.org>
tools/build: Allow versioning of all LLVM tools defined in Makefile.include
Justin Yeh <justin.yeh@mediatek.com>
pinctrl: mediatek: free EINT resources on unbind
Alison Schofield <alison.schofield@intel.com>
cxl/region: Fix use-after-free in find_pos_and_ways() error path
Feng Yang <yangfeng@kylinos.cn>
selftests/bpf: Fix memory leak on subtest_states reallocation
Feng Yang <yangfeng@kylinos.cn>
selftests/bpf: Fix incorrect error checking for pthread_create
Karl Mehltretter <kmehltretter@gmail.com>
ARM: lpc32xx: only run SoC init on LPC32xx hardware
Mykyta Yatsenko <yatsenko@meta.com>
bpf: Fix CFI mismatch in task work callback
Fabio Estevam <festevam@gmail.com>
arm64: dts: rockchip: Fix rk3566-bigtreetech-cb2 touchscreen property
Fabio Estevam <festevam@gmail.com>
arm64: dts: rockchip: Fix Gru WLAN sideband interrupt
Damon Ding <damon.ding@rock-chips.com>
arm64: dts: rockchip: Add missing hclk for RK3588 eDP1
Damon Ding <damon.ding@rock-chips.com>
arm64: dts: rockchip: Add missing hclk for RK3588 eDP0
Osama Abdelkader <osama.abdelkader@gmail.com>
drm/panthor: return PTR_ERR() from devm_drm_dev_alloc()
Weiming Wu <weiming3@asu.edu>
fs/ntfs3: fix out-of-bounds read of INDEX_ROOT in reparse/objid init
Florian Westphal <fw@strlen.de>
netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet
Can Peng <pengcan@kylinos.cn>
drm/tve200: add OF module alias for autoloading
Ian Rogers <irogers@google.com>
perf cap: Remove used_root parameter and simplify capability checks
Cosmo Chou <chou.cosmo@gmail.com>
leds: pca9532: Fix phantom device registration on missing hardware
Malaya Kumar Rout <malayarout91@gmail.com>
PM: hibernate: Fix memory leak in snapshot_write_next() error path
Leon Romanovsky <leon@kernel.org>
RDMA/erdma: complete object teardown when the destroy command fails
Sanghyun Park <sanghyun.park.cnu@gmail.com>
xfrm: Fix skb double-free in xfrm_dev_direct_output()
Leo Yan <leo.yan@arm.com>
perf cs-etm: Avoid truncating AUX buffer sizes to int
Leo Yan <leo.yan@arm.com>
perf cs-etm: Flush thread stacks after decoder reset
Junhui Liu <junhui.liu@pigmoral.tech>
riscv: dts: spacemit: k1: Split gmac_clk_ref into independent pinctrl groups
Michael Opdenacker <michael.opdenacker@rootcommit.com>
riscv: dts: spacemit: Add OrangePi R2S board device tree
Troy Mitchell <troy.mitchell@linux.spacemit.com>
riscv: dts: spacemit: add MusePi Pro board device tree
Sudeep Holla <sudeep.holla@kernel.org>
firmware: arm_scmi: Unrequest devices if driver registration fails
Sudeep Holla <sudeep.holla@kernel.org>
firmware: arm_scmi: Roll back partial protocol table registration
Marco Scardovi <scardracs@disroot.org>
cpufreq/amd-pstate: Toggle auto_sel in active mode on shared memory systems
Marco Scardovi <scardracs@disroot.org>
cpufreq/amd-pstate: Fix EPP return type and handle errors during initialization
Mario Limonciello (AMD) <superm1@kernel.org>
cpufreq/amd-pstate: Add support for platform profile class
Mario Limonciello (AMD) <superm1@kernel.org>
cpufreq/amd-pstate: Add dynamic energy performance preference
Gautham R. Shenoy <gautham.shenoy@amd.com>
amd-pstate: Make certain freq_attrs conditionally visible
Mario Limonciello (AMD) <superm1@kernel.org>
cpufreq/amd-pstate: Use sysfs_match_string() for epp
Qianheng Peng <pengqh1@chinatelecom.cn>
cpufreq: amd-pstate-ut: Skip tests when amd-pstate driver is not active
Andre Przywara <andre.przywara@arm.com>
ARM: dts: allwinner: a10: Fix PMU interrupt
Xiang Mei <xmei5@asu.edu>
ext4: check dir entry fits before reading the hash trailer in ext4_search_dir()
Guanghui Yang <3497809730@qq.com>
ext4: fix buffer_head leak in ext4_init_orphan_info
Selvin Xavier <selvin.xavier@broadcom.com>
RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap
Jeff Johnson <jeff.johnson@oss.qualcomm.com>
wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx()
Jeff Johnson <jeff.johnson@oss.qualcomm.com>
wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx()
Jeff Johnson <jeff.johnson@oss.qualcomm.com>
wifi: ath11k: Correctly copy the hint BSSID in WMI scan request
Jeff Johnson <jeff.johnson@oss.qualcomm.com>
wifi: ath12k: Correctly copy the hint BSSID in WMI scan request
Aaradhana Sahu <aaradhana.sahu@oss.qualcomm.com>
wifi: ath12k: allocate HOST_DDR and BDF regions after Q6 RO region
Aaradhana Sahu <aaradhana.sahu@oss.qualcomm.com>
wifi: ath12k: refactor QMI memory assignment
Aaradhana Sahu <aaradhana.sahu@oss.qualcomm.com>
wifi: ath12k: switch to name-based reserved memory lookup
Jeff Johnson <jeff.johnson@oss.qualcomm.com>
wifi: ath6kl: avoid buffer overreads in WMI event handlers
Yao Kai <yaokai34@huawei.com>
ext4: validate readdir offset before accessing dirent
Aditya Prakash Srivastava <aditya.ansh182@gmail.com>
ext4: use fsdata to track inline data write state and fix race
Baokun Li <libaokun@linux.alibaba.com>
ext4: drain in-flight DIO before buffered write fallback
Gerald Yang <gerald.yang@canonical.com>
ext4: clear stale xarray tags on folios skipped during writeback
Pengpeng Hou <pengpeng@iscas.ac.cn>
thermal: intel: int3400: clean up ODVP on probe failures
Nicolin Chen <nicolinc@nvidia.com>
iommu/arm-smmu-v3: Declare eats_s1chk and eats_trans as host-endian u64
Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
iommu/qcom: Fix inverted fault report check in qcom_iommu_fault()
Haoxiang Li <haoxiang_li2024@163.com>
iommu/qcom: Remove sysfs device on probe failure path
Li RongQing <lirongqing@baidu.com>
iommu/amd: Fix undefined behavior in devid_write debugfs function
Sudeep Holla <sudeep.holla@kernel.org>
firmware: arm_scmi: Fix requested device removal race
Patrisious Haddad <phaddad@nvidia.com>
RDMA/core: Fix potential use after free in ib_dealloc_pd_user()
Patrisious Haddad <phaddad@nvidia.com>
RDMA/core: Fix potential use after free in uverbs_free_dmah()
Patrisious Haddad <phaddad@nvidia.com>
RDMA/core: Fix potential use after free in ib_free_cq()
Patrisious Haddad <phaddad@nvidia.com>
RDMA/core: Fix potential use after free in counter_release()
Patrisious Haddad <phaddad@nvidia.com>
RDMA/core: Fix potential use after free in ib_destroy_srq_user()
Patrisious Haddad <phaddad@nvidia.com>
RDMA/core: Fix potential use after free in ib_destroy_cq_user()
Patrisious Haddad <phaddad@nvidia.com>
RDMA/core: Fix use after free in ib_query_qp()
Patrisious Haddad <phaddad@nvidia.com>
RDMA/core: Add rdma_restrack_begin/abort/commit_del() operations
Jason Gunthorpe <jgg@ziepe.ca>
RDMA/nldev: Fix locking when accessing mr->pd
Kalesh AP <kalesh-anakkur.purayil@broadcom.com>
RDMA/restrack: Fix typos in the comments
Leon Romanovsky <leon@kernel.org>
RDMA/mana_ib: drain QP references after partial table insertion
Myeonghun Pak <mhun512@gmail.com>
RDMA/erdma: Fix CEQ tasklet use-after-free on removal
Takuma Fujiwara <t-fujiwara1@ti.com>
PCI: j721e: Fix incorrect max_lanes for J7200
Leon Romanovsky <leon@kernel.org>
RDMA/srpt: Pass the mapped task attribute to target_init_cmd()
Kumar Kartikeya Dwivedi <memxor@gmail.com>
bpf: Mark bpf_refcount field as unique
Kumar Kartikeya Dwivedi <memxor@gmail.com>
bpf: Preserve unique-field state across nested structs
Kumar Kartikeya Dwivedi <memxor@gmail.com>
bpf: Fix offset warn check for bpf_res_spin_lock
Kohei Enju <enju.kohei@fujitsu.com>
virt: arm-cca-guest: use migrate_disable() for attestation token requests
Rafael J. Wysocki <rafael.j.wysocki@intel.com>
ACPI: battery: Adjust charging status validation check
Feng Jiang <jiangfeng@kylinos.cn>
bpf, riscv: Fix extable handling for arena load_acquire
Pu Lehui <pulehui@huawei.com>
riscv, bpf: Fix kernel stack corruption in tailcall with CFI
Pu Lehui <pulehui@huawei.com>
riscv, bpf: Fix memory leak in bpf_jit_free
Ricardo B. Marlière <rbm@suse.com>
libbpf: Search /lib64 and /lib in resolve_full_path()
Kumar Kartikeya Dwivedi <memxor@gmail.com>
bpf: Zero queue and stack outputs on lock failure
Yousef Alhouseen <alhouseenyousef@gmail.com>
platform/x86: acer-wmi: reject missing gaming WMI results
Yun Zhou <yun.zhou@windriver.com>
ext4: skip extra isize expansion during mount to prevent deadlock
Xiang Mei <xmei5@asu.edu>
ext4: fix out-of-bounds read in ext4_read_inline_dir()
Yun Zhou <yun.zhou@windriver.com>
ext4: fix circular lock dependency in ext4_ext_migrate
Chen Pei <cp0613@linux.alibaba.com>
ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root
Pengpeng Hou <pengpeng@iscas.ac.cn>
ACPI: processor: validate MADT IOAPIC entry bounds
Zhu Ling <zhuling2709@phytium.com.cn>
ACPI: EC: Avoid _REG disconnect on GPIO IRQ defer
Pengpeng Hou <pengpeng@iscas.ac.cn>
RDMA/nldev: validate dynamic counter attribute length
Kemeng Shi <shikemeng@huaweicloud.com>
irqchip/gic-v3-its: Prevent leak in its_vpe_irq_domain_alloc()
Viktor Malik <vmalik@redhat.com>
selftests/bpf: Silence array bounds warning in global_map_resize
Viktor Malik <vmalik@redhat.com>
selftests/bpf: Check malloc result with ASSERT_NEQ in test_sha256
Pawan Gupta <pawan.kumar.gupta@linux.intel.com>
x86/bugs: Don't use cpu-type matching in cpu_vuln_blacklist
Frank Li <Frank.Li@nxp.com>
arm64: dts: imx8-ss-audio: Fix LPCG clock indices for ASRC0
Marco Elver <elver@google.com>
kcsan: avoid unintended access checking in NMIs
TanZheng <tanzheng@kylinos.cn>
RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters
Ibrahim Hashimov <security@auditcode.ai>
RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[]
Danila Chernetsov <listdansp@mail.ru>
RDMA/hfi1: Propagate sdma_txinit_ahg() errors
Jun Yan <jerrysteve1101@gmail.com>
arm64: dts: amlogic: meson-axg-s400: enable mipi_pcie_analog_dphy for PCIe
Jun Yan <jerrysteve1101@gmail.com>
arm64: dts: amlogic: meson-axg: Add missing nand_rb0 pin to nand_all_pins
Can Peng <pengcan@kylinos.cn>
phy: starfive: Fix runtime PM cleanup in JH7110 DPHY RX probe
Can Peng <pengcan@kylinos.cn>
phy: starfive: Fix runtime PM cleanup in JH7110 DPHY TX probe
Linmao Li <lilinmao@kylinos.cn>
ASoC: meson: Keep link pointers valid on realloc failure
Koichiro Den <den@valinux.co.jp>
dmaengine: dw-edma: Clear stale requests on termination
Koichiro Den <den@valinux.co.jp>
dmaengine: dw-edma: Serialize channel state checks
Koichiro Den <den@valinux.co.jp>
dmaengine: dw-edma: Serialize abort state updates
Koichiro Den <den@valinux.co.jp>
dmaengine: dw-edma: Terminate all descriptors without callbacks
Yiyang Chen <chenyy23@mails.tsinghua.edu.cn>
bpf: Reject arena frees below the arena base
Puranam V G Tejaswi <puranam.tejaswi@oss.qualcomm.com>
drm/msm/a6xx: Fix RBBM_CLOCK_CNTL3_TP0 value in a730_hwcg
Yuho Choi <dbgh9129@gmail.com>
driver core: soc: Unregister bus on early device registration failure
Alban Bedel <alban.bedel@lht.dlh.de>
software node: Fix software_node_get_reference_args() with index -1
Ian Rogers <irogers@google.com>
perf ui hists: Fix uninitialized stack memory free on pstack allocation failure
zhouminqiang <zhouminqiang2@huawei.com>
mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition()
Ruoyu Wang <ruoyuw560@gmail.com>
mtd: mtdswap: Avoid freeing registered blktrans device twice
Guangshuo Li <lgs201920130244@gmail.com>
mtd: intel-dg: Fix runtime PM error path in probe
Alexander Usyskin <alexander.usyskin@intel.com>
mtd: intel-dg: wake card on operations
Pengpeng Hou <pengpeng@iscas.ac.cn>
soc: ti: knav_qmss: Remove debugfs file on teardown
Md Shofiqul Islam <shofiqtest@gmail.com>
soc: ti: knav_qmss_queue: Implement resource cleanup in remove()
Xiang Mei <xmei5@asu.edu>
vfio/pci: clear vdev->msi_perm after freeing it on init failure
Myeonghun Pak <mhun512@gmail.com>
char: xilinx_hwicap: unregister class on init errors
Pei Xiao <xiaopei01@kylinos.cn>
ipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on remove
Linmao Li <lilinmao@kylinos.cn>
ppdev: prevent overflow when setting port timeout
Breno Leitao <leitao@debian.org>
cacheinfo: don't propagate DT/ACPI error when arch supplies info (arm64)
Pengpeng Hou <pengpeng@iscas.ac.cn>
misc: lan966x_pci: depopulate children on populate failure
Pengpeng Hou <pengpeng@iscas.ac.cn>
misc: ad525x_dpot: use driver core groups for sysfs files
Gleb Markov <markov.gi@npc-ksb.ru>
misc: rtsx: add missing write register handling
Gui-Dong Han <hanguidong02@gmail.com>
misc: bcm-vk: Use acquire/release for msgq_inited
Pavel Zhigulin <Pavel.Zhigulin@kaspersky.com>
speakup: keyhelp: guard letter_offsets possible out-of-range indexing
Christophe JAILLET <christophe.jaillet@wanadoo.fr>
accessibility: speakup: Fix incorrect string length computation in report_char_chartab_status()
Yuho Choi <dbgh9129@gmail.com>
uio: Fix stale info pointer in failed registration path
Gui-Dong Han <hanguidong02@gmail.com>
gpib: Move stuck SRQ update under lock
Cong Nguyen <congnt264@gmail.com>
staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths
Mohammed Rizwan Kaniyate <mrizwank004@gmail.com>
staging: rtl8723bs: remove multiple blank lines in core/
Minu Jin <s9430939@naver.com>
staging: rtl8723bs: replace rtw_zmalloc() with kzalloc()
Nayana Mariyappa <nayana.mariyappa@gmail.com>
staging: rtl8723bs: expand multiple assignment into separate statements
Khushal Chitturi <khushalchitturi@gmail.com>
staging: rtl8723bs: fix operator and type cast spacing
Navaneeth K <knavaneeth786@gmail.com>
staging: rtl8723bs: use standard offsetof in cfg80211 operations
Sameeksha Sankpal <sameekshasankpal@gmail.com>
staging: rtl8723bs: Fix operator spacing in rtw_security.c
David Lee <david.lee@trailofbits.com>
UDF symlink pathComponent header OOB read
Karl Mehltretter <kmehltretter@gmail.com>
tty: hvc: restrict HVC_DCC to ARMv6+ and ARM64
Xu Yang <xu.yang_2@nxp.com>
usb: gadget: f_uac1_legacy: remove broken string configfs attributes
Rafael J. Wysocki <rafael.j.wysocki@intel.com>
ACPI: processor: idle: Expand _LPI package sanity checks
Thorsten Blum <thorsten.blum@linux.dev>
crypto: sl3516 - drop invalid sg_dma_len checks before DMA mapping
Pu Lehui <pulehui@huawei.com>
bpf: Sync tail_call_reachable with callee state on entry
Ruoyu Wang <ruoyuw560@gmail.com>
drm/msm: Only fini scheduler after successful init
Jie Zhang <jie.zhang@oss.qualcomm.com>
drm/msm: Fix task_struct reference leak in recover_worker
Jie Zhang <jie.zhang@oss.qualcomm.com>
drm/msm/a6xx: Fix A621 GPUCC register list for state capture
Akhil P Oommen <akhilpo@oss.qualcomm.com>
drm/msm/a6xx: Rebase GMU register offsets
Jie Zhang <jie.zhang@oss.qualcomm.com>
drm/msm/a6xx: Fix A663 GPUCC register list for state capture
Jie Zhang <jie.zhang@oss.qualcomm.com>
drm/msm: Recover HW before retire hung submit
Shivam Rawat <shivrawa@qti.qualcomm.com>
drm/msm/a6xx: Fix stale rpmh votes after suspend
Mikko Perttunen <mperttunen@nvidia.com>
gpu: host1x: Avoid stack over-read in debug output helpers
Mikko Perttunen <mperttunen@nvidia.com>
gpu: host1x: Fix offset calculation in trace_write_gather
Avraham Stern <avraham.stern@intel.com>
wifi: iwlwifi: mei: pass correct argument to function
Emmanuel Grumbach <emmanuel.grumbach@intel.com>
wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments
Avraham Stern <avraham.stern@intel.com>
wifi: iwlwifi: mei: check SAP message length before reading it
Emmanuel Grumbach <emmanuel.grumbach@intel.com>
wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser
Emmanuel Grumbach <emmanuel.grumbach@intel.com>
wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs
Praveen Talari <praveen.talari@oss.qualcomm.com>
spi: geni-qcom: Fix sticky ret causing wrong return value on invalid proto
Geert Uytterhoeven <geert+renesas@glider.be>
soc: renesas: r8a78000: Drop duplicate "default ARCH_RENESAS"
Abel Vesa <abel.vesa@oss.qualcomm.com>
clk: qcom: gcc-glymur: Enable runtime PM
Ian Rogers <irogers@google.com>
perf jevents: Add more components to the metric sorting order
Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
arm64: dts: qcom: sm8250: correct frequencies in the Iris OPP table
Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
arm64: dts: qcom: sm8250: sort out Iris power domains
George Moussalem <george.moussalem@outlook.com>
arm64: qcom: ipq5018: Add GEPHY RX and TX clocks
George Moussalem <george.moussalem@outlook.com>
arm64: dts: qcom: ipq5018: Correct CMN PLL reference clock rate
Pengyu Luo <mitltlatltl@gmail.com>
arm64: dts: qcom: sc8280xp-x13s: Fix the drive-strength of mclk pin
Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
arm64: dts: qcom: msm8996-xiaomi-gemini: Fix up ti,drv2604 enable GPIO
Denis V. Lunev <den@openvz.org>
x86/mm/pat: Take cpa_lock around large-page collapse
Maoyi Xie <maoyixie.tju@gmail.com>
drm/bridge: tc358767: clamp the reported AUX read size to the request
Hongling Zeng <zenghongling@kylinos.cn>
perf: evsel: Fix error handling in tp_format lookup
Uday Khare <udaykhare77@gmail.com>
remoteproc: qcom: Fix glink->node reference leak in qcom_add_glink_subdev
Zhongqiu Han <zhongqiu.han@oss.qualcomm.com>
cpufreq: schedutil: Fix self-contradictory comment in sugov_iowait_apply()
Rafael J. Wysocki <rafael.j.wysocki@intel.com>
cpufreq: intel_pstate: Fix setting minimum P-state at init time
Gleb Markov <markov.gi@npc-ksb.ru>
drm/amd/display: Remove unused-but-set variable hubp from
Geoffrey McRae <geoffrey.mcrae@amd.com>
drm/amd/display: Fix DM I2C teardown race
Ruoyu Wang <ruoyuw560@gmail.com>
media: ipu6: Do not free aux device pdata after init
Eugen Hristev <ehristev@kernel.org>
media: bcm2835-unicam: Fix asc leaked in error/remove path
Biren Pandya <birenpandya@gmail.com>
media: i2c: rdacm21: Fix missing media_entity_cleanup()
Qingshuang Fu <fuqingshuang@kylinos.cn>
irqchip/renesas-irqc: Fix generic interrupt chip leak on remove
Yuho Choi <dbgh9129@gmail.com>
PCI: xgene: Drop unnecessary OF node reference
Dan Carpenter <error27@gmail.com>
cpufreq: spear: Fix an IS_ERR() vs NULL bug in spear1340_set_cpu_rate()
John Groves <John@Groves.net>
dax: read holder_ops once in dax_holder_notify_failure()
Bryam Vargas <hexlabsecurity@proton.me>
libnvdimm/labels: Bound the on-media label size before the shift
Liang Luo <luoliang@kylinos.cn>
tools/sched_ext: scx_qmap: Fix stale API name in comment
Dan Carpenter <error27@gmail.com>
regulator: adp5055: Fix error code in adp5055_of_parse_cb()
Richard Cheng <icheng@nvidia.com>
cxl/features: Clamp Get Feature output size to the remaining buffer
Richard Cheng <icheng@nvidia.com>
cxl/features: Reject Set Features output buffer smaller than the header
Richard Cheng <icheng@nvidia.com>
cxl/features: Reject Get Feature count larger than the output buffer
Sudeep Holla <sudeep.holla@kernel.org>
firmware: arm_scmi: Fix transport device teardown lookup
Sudeep Holla <sudeep.holla@kernel.org>
firmware: arm_scmi: Unwind P2A receiver mailbox setup failure
Sudeep Holla <sudeep.holla@kernel.org>
firmware: arm_scmi: Unwind TX receiver mailbox setup failure
Sudeep Holla <sudeep.holla@kernel.org>
firmware: arm_scmi: Drop handle on protocol bind failures
Sudeep Holla <sudeep.holla@kernel.org>
firmware: arm_scmi: Protect device request lookup with RCU
Sudeep Holla <sudeep.holla@kernel.org>
firmware: arm_scmi: Use channel ID for transport teardown
Sudeep Holla <sudeep.holla@kernel.org>
firmware: arm_scmi: Reject out of range DT protocol IDs
Sudeep Holla <sudeep.holla@kernel.org>
firmware: arm_scmi: Avoid IDR updates while cleaning channels
Sudeep Holla <sudeep.holla@kernel.org>
firmware: arm_scmi: Free transport channel on IDR failure
Sudeep Holla <sudeep.holla@kernel.org>
firmware: arm_scmi: Clean up channels on setup failure
Sudeep Holla <sudeep.holla@kernel.org>
firmware: arm_scmi: Quiesce notifications before teardown
Sudeep Holla <sudeep.holla@kernel.org>
firmware: arm_scmi: Unregister device notifier before IDR teardown
Sudeep Holla <sudeep.holla@kernel.org>
firmware: arm_scmi: Publish channel state before callbacks
David Stevens <stevensd@google.com>
x86/entry/fred: Encode frame pointer on entry
Baochen Qiang <baochen.qiang@oss.qualcomm.com>
wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate
Kyle Zeng <kylebot@openai.com>
hfsplus: validate thread record before delete key rebuild
Alison Schofield <alison.schofield@intel.com>
cxl/port: Restart port enumeration when a sibling adds the dport first
Dave Jiang <dave.jiang@intel.com>
cxl/pci: Honor -EPROBE_DEFER from component register setup
Dave Jiang <dave.jiang@intel.com>
cxl/mbox: Break poison list loop on an empty payload
Guzebing <Guzebing1612@gmail.com>
cxl/memdev: Fix firmware upload exact-fit handling
Jason Gunthorpe <jgg@ziepe.ca>
iommufd: Simplify iommufd_device_remove_vdev()
Vishnu Santhosh <vishnu.santhosh@oss.qualcomm.com>
rpmsg: glink: fix deadlock in endpoint destroy during driver detach
Srinivas Kandagatla <srinivas.kandagatla@oss.qualcomm.com>
rpmsg: glink: remove duplicate code for rpmsg device remove
Dmitry Ilvokhin <d@ilvokhin.com>
perf record: Fix multiple PERF_RECORD_COMPRESSED2 records per push
Dmitry Ilvokhin <d@ilvokhin.com>
perf record: Return the written size from process_comp_header()
Arnaldo Carvalho de Melo <acme@redhat.com>
perf zstd: Fix compression error path in zstd_compress_stream_to_records()
Reinette Chatre <reinette.chatre@intel.com>
fs/resctrl: Prevent use-after-free in rdtgroup_kn_put()
Hans Verkuil <hverkuil+cisco@kernel.org>
media: v4l2-async: Unregister sub-device if asc_list is empty
Samuel Moelius <sam.moelius@trailofbits.com>
iommufd/selftest: Avoid selftest dirty bitmap size wrap
Xiang Mei <xmei5@asu.edu>
isofs: fix out-of-bounds page array access on empty zisofs block
James Calligeros <jcalligeros99@gmail.com>
ASoC: apple: mca: increase SERDES reset delay
Leon Romanovsky <leon@kernel.org>
RDMA/hfi1: Initialize debugfs after probe completes
Leon Romanovsky <leon@kernel.org>
RDMA/hfi1: Stop flushing the global IB workqueue
Leon Romanovsky <leon@kernel.org>
RDMA/hfi1: Create workqueues before device initialization
Leon Romanovsky <leon@kernel.org>
RDMA/hfi1: Remove redundant PCI device ID validation
Leon Romanovsky <leon@kernel.org>
RDMA/hfi1: Free RX data on late probe failure
Leon Romanovsky <leon@kernel.org>
RDMA/hfi1: Preserve unit 0 on allocation failure
Sean Rhodes <sean@starlabs.systems>
misc: rtsx_usb: avoid USB I/O in runtime autosuspend
Pengpeng Hou <pengpeng@iscas.ac.cn>
pmdomain: bcm: bcm2835: handle genpd provider registration errors
Evgenii Burenchev <evg28bur@yandex.ru>
ALSA: hpi: Check transport errors during HPI6000 adapter initialization
Xiang Mei <xmei5@asu.edu>
xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full
Guangshuo Li <lgs201920130244@gmail.com>
crash_dump: release keyring reference at the correct time
Yuho Choi <dbgh9129@gmail.com>
hwrng: ks-sa - Fix runtime PM cleanup on registration failure
Atish Patra <atishp@meta.com>
crypto: ccp - Fix memory leak in SEV INIT_EX path
Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Revert "drm/msm: dsi: fix PLL init in bonded mode"
Jens Glathe <jens.glathe@oldschoolsolutions.biz>
drm/msm/dp: add missing drm_edid_connector_update() before add_modes on cached EDID
Allison Henderson <achender@kernel.org>
RDMA/rxe: Avoid reprocessing the current packet after the QP enters the error state
Leon Romanovsky <leon@kernel.org>
RDMA/ipoib: Drain RCU callbacks during module teardown
Leon Romanovsky <leon@kernel.org>
RDMA/mlx5: Drain RCU callbacks during module teardown
Leon Romanovsky <leon@kernel.org>
RDMA/core: Wait for RCU callbacks before unloading ib_core
Mert Seftali <mertsftl@gmail.com>
iio: accel: dmard09: Implement IIO_CHAN_INFO_SCALE
Chih-Kang Chang <gary.chang@realtek.com>
wifi: rtw89: 8852a: fix RSSI report when average beacon RSSI is not ready
Kuan-Chung Chen <damon.chen@realtek.com>
wifi: rtw89: phy: support per PHY RX statistics
Kuan-Chung Chen <damon.chen@realtek.com>
wifi: rtw89: mlo: rearrange MLSR link decision flow
Ping-Ke Shih <pkshih@realtek.com>
wifi: rtw89: debug: add parser to diagnose along DIAG_MAC fw element
Ping-Ke Shih <pkshih@realtek.com>
wifi: rtw89: fw: parse firmware element of DIAG_MAC
Ping-Ke Shih <pkshih@realtek.com>
wifi: rtw89: pci: add to read PCI configuration space from common code
Nicholas Dudar <main.kalliope@gmail.com>
bpf: Require a BPF cpumask for bpf_cpumask_populate()
Tejun Heo <tj@kernel.org>
tools/sched_ext: Strip compatibility macros for cgroup and dispatch APIs
Brian Masney <bmasney@redhat.com>
clk: qcom: camcc-sc8280xp: unregister CAMCC_GDSC_CLK
Pengpeng Hou <pengpeng@iscas.ac.cn>
bus: qcom-ebi2: use managed resources for clocks and children
Pengpeng Hou <pengpeng@iscas.ac.cn>
soc: qcom: rpmh-rsc: manage PM notifiers with devres
Yu Peng <pengyu@kylinos.cn>
perf metricgroup: Fix metric expression copy leaks
Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
drm/panel: samsung-s6d16d0: Power off on prepare failure
Pengpeng Hou <pengpeng@iscas.ac.cn>
usb: typec: ucsi: gaokun: unwind notifier on UCSI register failure
Pengyu Luo <mitltlatltl@gmail.com>
usb: ucsi: huawei_gaokun: support mode switching
Biju Das <biju.das.jz@bp.renesas.com>
usb: renesas_usbhs: Fix power-off ordering on unbind
Fei Shao <fshao@chromium.org>
usb: mtu3: allow system suspend during active gadget connection
Linmao Li <lilinmao@kylinos.cn>
platform/surface: acpi-notify: Check ACPI companion before use
Linmao Li <lilinmao@kylinos.cn>
platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL
Gary Guo <gary@garyguo.net>
usb: fix UAF when probe runs concurrent to dyn ID removal
Ruoyu Wang <ruoyuw560@gmail.com>
usb: gadget: aspeed_udc: check endpoint DMA allocation
Maoyi Xie <maoyixie.tju@gmail.com>
usb: ljca: bound bank_num in ljca_enumerate_gpio()
Michael Bommarito <michael.bommarito@gmail.com>
usb: gadget: configfs: fix out-of-bounds read of qw_sign
Nuno Sá <nuno.sa@analog.com>
usb: gadget: f_fs: Fix fence cleanup in ffs_dmabuf_transfer() error paths
Guangshuo Li <lgs201920130244@gmail.com>
serial: qcom-geni: do not advance stale DMA completions
Yuho Choi <dbgh9129@gmail.com>
serial: ma35d1: Fix OF node reference leaks in console init
Fushuai Wang <wangfushuai@baidu.com>
serial: 8250: Clear CON_PRINTBUFFER on port re-registration
John Ogness <john.ogness@linutronix.de>
serial: 8250: Add support for console flow control
John Ogness <john.ogness@linutronix.de>
serial: 8250: Set cons_flow on port registration
John Ogness <john.ogness@linutronix.de>
serial: Replace driver usage of UPF_CONS_FLOW
John Ogness <john.ogness@linutronix.de>
serial: core: Add dedicated uart_port field for console flow
Praveen Talari <praveen.talari@oss.qualcomm.com>
spi: qcom-geni: Fix missing error check on pm_runtime_get_sync()
Tengda Wu <wutengda@huaweicloud.com>
perf capstone: Fix kernel map reference count leak
Liang Luo <luoliang@kylinos.cn>
selftests/sched_ext: Fix bpf_link leak on early return in prog_run
Wolfram Sang <wsa+renesas@sang-engineering.com>
hwspinlock: propagate errno when registering single lock
Felix Gu <gu_0233@qq.com>
remoteproc: qcom_q6v5_adsp: Fix reference leak for device node
Armin Wolf <W_Armin@gmx.de>
platform/x86: lg-laptop: Fix LED resource handling
Rafael J. Wysocki <rafael.j.wysocki@intel.com>
platform/x86: lg-laptop: Convert ACPI driver to a platform one
Rafael J. Wysocki <rafael.j.wysocki@intel.com>
platform/x86: lg-laptop: Drop debug-only ACPI notify handler
Armin Wolf <W_Armin@gmx.de>
platform/x86: dell-wmi-base: Fix resource leak on module load failure
Armin Wolf <W_Armin@gmx.de>
platform/x86: dell-privacy: Fix race condition
Lorenzo Pieralisi <lpieralisi@kernel.org>
ACPI: RISC-V: Fix riscv_acpi_add_prt_dep() loop handling
Lorenzo Pieralisi <lpieralisi@kernel.org>
ACPI: RISC-V: Check acpi_get_handle() status in riscv_acpi_add_prt_dep()
Lorenzo Pieralisi <lpieralisi@kernel.org>
ACPI: RISC-V: Fix riscv_acpi_irq_get_dep() loop termination
John Ogness <john.ogness@linutronix.de>
printk: Fix possible console use-after-free
Andrew Murray <amurray@thegoodpenguin.co.uk>
printk: Introduce console_flush_one_record
Manuel Fombuena <fombuena@outlook.com>
leds: st1202: Validate LED reg property against channel count
Manuel Fombuena <fombuena@outlook.com>
leds: st1202: Disable channel when brightness is set to zero
Manuel Fombuena <fombuena@outlook.com>
leds: st1202: Fix brightness having no effect while pattern mode is active
Manuel Fombuena <fombuena@outlook.com>
leds: st1202: Set all pattern PWM slots to full after clearing pattern
Manuel Fombuena <fombuena@outlook.com>
leds: st1202: Fix spurious pattern sequence start in setup
Manuel Fombuena <fombuena@outlook.com>
leds: st1202: Fix pattern duration prescaler and pattern_clear skip marker
Manuel Fombuena <fombuena@outlook.com>
leds: st1202: Stop pattern sequence before reprogramming
Cosmo Chou <chou.cosmo@gmail.com>
leds: pca9532: Fix inverted GPIO output polarity
Wei Wang <wei.w.wang@hotmail.com>
iommu/amd: Fix false positive in SB IOAPIC IVRS validation
Fu Hao <fuhao@open-hieco.net>
iommu/amd: Add support for Hygon family 18h model 4h IOAPIC
Wei Wang <wei.w.wang@hotmail.com>
iommu/amd: Prevent SB IOAPIC from overriding IVRS validation errors
Vladimir Zapolskiy <vz@kernel.org>
iommu/msm: Return -ENOMEM on memory allocation failure in probe
Daniel Borkmann <daniel@iogearbox.net>
bpf: Fix security_bpf_map_create error handling
Akari Tsuyukusa <akkun11.open@gmail.com>
iommu/mediatek-v1: Fix off-by-one in MT2701_LARB_NR_MAX
Yuho Choi <dbgh9129@gmail.com>
bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation
Sanghyun Park <sanghyun.park.cnu@gmail.com>
bpf: Fix use-after-free on mm_struct in bpf_find_vma()
Breno Leitao <leitao@debian.org>
efi: fix stale reference to efi_recover_from_page_fault()
Daniel Borkmann <daniel@iogearbox.net>
bpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlinux
Tanushree Shah <tshah@linux.ibm.com>
perf dso: Fix kallsyms DSO detection with fallback logic
Sandipan Das <sandipan.das@amd.com>
perf vendor events amd: Reintroduce deprecated Zen 5 core events
Daniel Borkmann <daniel@iogearbox.net>
bpftool: Check EVP_Digest when computing excl_prog_hash
Aleksandr Nogikh <nogikh@google.com>
udf: Mark LVID buffer as uptodate before marking it dirty
Hongyan Xu <getshell@seu.edu.cn>
usb: gadget: r8a66597: avoid double free of ep0_req in probe error path
Bjorn Andersson <bjorn.andersson@oss.qualcomm.com>
usb: typec: ucsi: unregister debugfs entries on teardown
Dan Carpenter <error27@gmail.com>
thermal/drivers/rcar: Fix error checking in probe()
Vidhu Sarwal <vidhu.linux@gmail.com>
staging: media: ipu7: fix pm_runtime refcount leak in ipu7_resume()
Vidhu Sarwal <vidhu.linux@gmail.com>
staging: media: ipu7: fix pm_runtime refcount leak in ipu7_init_fw_code_region_by_sys()
Tanushree Shah <tshah@linux.ibm.com>
perf data convert json: Fix trace_seq memory leak in process_sample_event()
Loic Poulain <loic.poulain@oss.qualcomm.com>
clk: qcom: gcc-qcs8300: Use retention for USB power domains
Loic Poulain <loic.poulain@oss.qualcomm.com>
clk: qcom: gcc-qcs8300: Use retention for PCIe power domains
Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
arm64: dts: qcom: sc8180x-lenovo-flex-5g: Describe the display power net
Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
arm64: dts: qcom: sc8180x-lenovo-flex-5g: Rename regulator nodes
Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
arm64: dts: qcom: sc8180x-primus: Describe the display power net
Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
arm64: dts: qcom: sc8180x-primus: Rename regulator nodes
Jérôme de Bretagne <jerome.debretagne@gmail.com>
arm64: dts: qcom: sc8280xp-arcata: Fix top USB-C DP alt mode
Herman van Hazendonk <github.com@herrie.org>
clk: qcom: gdsc: tear down per-domain genpds in gdsc_unregister()
Herman van Hazendonk <github.com@herrie.org>
clk: qcom: gdsc: propagate gdsc_enable() failure for ALWAYS_ON domains
Herman van Hazendonk <github.com@herrie.org>
clk: qcom: gdsc: propagate gdsc_check_status() errors from gdsc_poll_status
Brian Norris <briannorris@chromium.org>
arm64: dts: qcom: Add #{address,size}-cells to Chromium-based /firmware
David Woodhouse <dwmw@amazon.co.uk>
timekeeping: Account for monotonicity adjustment in ntp_error
Thomas Weißschuh <thomas.weissschuh@linutronix.de>
y2038: uapi: Use 64-bit __kernel_old_timespec::tv_nsec on x32
Malaya Kumar Rout <malayarout91@gmail.com>
time/namespace: Validate nanosecond field in proc_timens_set_offset()
Thomas Weißschuh <thomas.weissschuh@linutronix.de>
timens: Simplify some calls to put_time_ns()
Thomas Weißschuh <thomas.weissschuh@linutronix.de>
timens: Add a __free() wrapper for put_time_ns()
Thomas Weißschuh <thomas.weissschuh@linutronix.de>
timens: Remove dependency on the vDSO
Thomas Weißschuh <thomas.weissschuh@linutronix.de>
vdso/timens: Move functions to new file
Petr Tesarik <ptesarik@suse.com>
x86/tsx: Make tsx_ctrl_state static
Malaya Kumar Rout <malayarout91@gmail.com>
timers/migration: Fix memory leak in tmigr_setup_groups() error path
Yuho Choi <dbgh9129@gmail.com>
timekeeping: Unwind aux clock sysfs children on failure
Yuho Choi <dbgh9129@gmail.com>
clocksource: Unregister subsystem on device registration failure
Jiangshan Yi <yijiangshan@kylinos.cn>
selftests: timers: leap-a-day: Fix -w option and update usage comment
Kemeng Shi <shikemeng@huaweicloud.com>
irqchip/gic-v3-its: Fix its node leak in gic_acpi_parse_madt_its()
Kemeng Shi <shikemeng@huaweicloud.com>
irqchip/gic-v3-its: Fix memleak in its_probe_one()
Wang Yan <wangyan01@kylinos.cn>
selftests/lsm: Fix memory leak in attr_lsm_count
Feng Yang <yangfeng@kylinos.cn>
selftests/bpf: Fix memory leak in msg_alloc_iov
Malaya Kumar Rout <malayarout91@gmail.com>
selftests/bpf: Fix memory leak in msg_alloc_iov error path
Evgenii Burenchev <evg28bur@yandex.ru>
ALSA: via82xx: Remove unreachable branch in snd_via686_pcm_pointer()
Dawei Feng <dawei.feng@seu.edu.cn>
staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init()
Ayush Mukkanwar <ayushmukkanwar@gmail.com>
staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown
Ayush Mukkanwar <ayushmukkanwar@gmail.com>
staging: octeon: replace pr_warn with dev_warn in fill and rx paths
Ayush Mukkanwar <ayushmukkanwar@gmail.com>
staging: octeon: ethernet-mem: replace pr_warn with dev_warn in free functions
Yuvraj Singh Chauhan <ysinghcin@gmail.com>
staging: octeon: fix free_irq dev_id mismatch in cvm_oct_rx_shutdown
Ayush Mukkanwar <ayushmukkanwar@gmail.com>
staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown
Dan Carpenter <error27@gmail.com>
staging: fbtft: Use sysfs_emit_at() to print to sysfs file
Bryam Vargas <hexlabsecurity@proton.me>
greybus: audio: bound the topology section sizes against the fetched size
Rong Zhang <i@rong.moe>
staging: sm750fb: Add missing Kconfig dependency
Ahmet Sezgin Duran <ahmet@sezginduran.net>
staging: sm750fb: gate dualview dataflow using g_dualview
Alexander A. Klimov <grandmaster@al2klimov.de>
staging: greybus: audio: correct sscanf() return value check
Cen Zhang <zzzccc427@gmail.com>
wifi: mac80211_hwsim: avoid NULL skb in stop queue drain
Ruoyu Wang <ruoyuw560@gmail.com>
bus: qcom-ebi2: Fix clock leak on probe failure
Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
bus: qcom-ebi2: Simplify with scoped for each OF child loop
Taniya Das <taniya.das@oss.qualcomm.com>
clk: qcom: gcc-glymur: Move EVA clocks to critical clock list
Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
arm64: dts: qcom: hamoa: Fix clocks for HSPHYs
Luca Weiss <luca.weiss@fairphone.com>
arm64: dts: qcom: sm7225-fairphone-fp4: Fix address in fb node name
Jens Glathe <jens.glathe@oldschoolsolutions.biz>
arm64: dts: qcom: sc8280xp-blackrock: switch to uefi rtc offset
Waiman Long <longman@redhat.com>
cgroup/cpuset: Make nr_deadline_tasks an atomic_t
Haowen Tu <tuhaowen@uniontech.com>
PM: sleep: Fix off-by-one in wakelocks number limit check
Yuho Choi <dbgh9129@gmail.com>
bus: ti-sysc: Fix /chosen node reference leak
Shin'ichiro Kawasaki <shinichiro.kawasaki@wdc.com>
nvmet-rdma: fix response resource leak on queue teardown
Shin'ichiro Kawasaki <shinichiro.kawasaki@wdc.com>
nvmet-rdma: factor out response resource cleanup
Gui-Dong Han <hanguidong02@gmail.com>
nvme-apple: Use acquire/release for queue enabled state
Kuldeep Singh <kuldeep.singh@oss.qualcomm.com>
arm64: dts: qcom: sm8750: wire UFS to ice instance
Jacob Moroni <jmoroni@google.com>
RDMA/irdma: Add refcounting to user ring MRs
Jacob Moroni <jmoroni@google.com>
RDMA/irdma: Add irdma_cq fields to track pbl allocations
Jacob Moroni <jmoroni@google.com>
RDMA/irdma: Add a refcount to track user ring MR associations
Jacob Moroni <jmoroni@google.com>
RDMA/irdma: Deduplicate the irdma_del_memlist logic
Myeonghun Pak <mhun512@gmail.com>
crypto: keembay - Fix AEAD unregister count in error path
Pengpeng Hou <pengpeng@iscas.ac.cn>
crypto: rk3288 - fail ahash requests on HASH idle timeout
Pengpeng Hou <pengpeng@iscas.ac.cn>
hwrng: xilinx-trng - propagate timeout before any data is read
Pengpeng Hou <pengpeng@iscas.ac.cn>
crypto: sa2ul - stop probe if context pool creation fails
Lothar Rubusch <l.rubusch@gmail.com>
crypto: atmel-sha204a - fix heap info leak on I2C transfer failure
Thorsten Blum <thorsten.blum@linux.dev>
crypto: atmel-ecc - reject hardware ECDH without a public key
Giovanni Cabiddu <giovanni.cabiddu@intel.com>
crypto: qat - clear AES key schedule from stack
Giovanni Cabiddu <giovanni.cabiddu@intel.com>
crypto: qat - cancel work on re-enable SR-IOV timeout
Manos Pitsidianakis <manos@pitsidianak.is>
hwrng: core - fix rng list on registration error
Sandipan Das <sandipan.das@amd.com>
perf vendor events amd: Update Zen 5 core events
Sandipan Das <sandipan.das@amd.com>
perf/x86/amd/uncore: Add group validation
Leo Yan <leo.yan@arm.com>
perf cs-etm: Fix thread leaks on trace queue init failure
Thomas Weißschuh <linux@weissschuh.net>
tools/nolibc: mark arg1 operand in __nolibc_syscall0() as write-only
Xuanqiang Luo <luoxuanqiang@kylinos.cn>
fanotify: initialize permission event watchdog state
Pengpeng Hou <pengpeng@iscas.ac.cn>
wifi: rtw89: fix HE extended capability length check
Dmitry Morgun <d.morgun@ispras.ru>
wifi: rtw89: check return values in rtw89_ops_start_ap()
Chih-Kang Chang <gary.chang@realtek.com>
wifi: rtw89: update format of addr cam H2C command
Ping-Ke Shih <pkshih@realtek.com>
wifi: rtw89: fill addr cam H2C command by struct
Tzung-Bi Shih <tzungbi@kernel.org>
platform/chrome: sensorhub: Fix memory overread in ring handler
Hisam Mehboob <hisamshar@gmail.com>
selftests/rseq: Replace glibc-specific __GNUC_PREREQ with portable check
Hanlin Song <pgeorge8929@gmail.com>
csky: Fix a4/a5 restoration in syscall trace path
Sanjay Chitroda <sanjayembeddedse@gmail.com>
iio: orientation: hid-sensor-rotation: Avoid race between callback setup and device exposure
Srinivas Kandagatla <srinivas.kandagatla@oss.qualcomm.com>
soundwire: qcom: Fix port exhaustion check in stream_alloc_ports
Vladimir Zapolskiy <vz@kernel.org>
dmaengine: hisilicon: Return -ENOMEM on dynamic memory allocation in probe
Golla Nagendra <nagendra.golla@amd.com>
dmaengine: zynqmp_dma: fix race between runtime PM and device removal
Suraj Gupta <suraj.gupta2@amd.com>
dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers
Vladimir Zapolskiy <vz@kernel.org>
dmaengine: mediatek: mtk-uart-apdma: Return -ENOMEM on memory allocation failure
Gregory Price <gourry@gourry.net>
mm/mm_init: handle alloc_percpu failure in free_area_init_core_hotplug
Gregory Price <gourry@gourry.net>
mm: name the anonymous MMOP enum as enum mmop
Israel Batista <linux@israelbatista.dev.br>
mm: change type of state in struct memory_block
Israel Batista <linux@israelbatista.dev.br>
mm: convert memory block states (MEM_*) macros to enum
Sechang Lim <rhkrqnwk98@gmail.com>
bpf,lsm: Drop bpf_prog_free from sleepable_lsm_hooks
Guillaume Maudoux <layus.on@gmail.com>
selftests/bpf: Mask socket type flags in mptcpify prog
Alexis Lothoré (eBPF Foundation) <alexis.lothore@bootlin.com>
selftests/bpf: Systematically add SO_REUSEADDR in start_server_addr
Leon Hwang <leon.hwang@linux.dev>
bpf: Copy per-CPU map value padding in copy_map_value_long()
Yichong Chen <chenyichong@uniontech.com>
tools/bpf/bpftool: Reset vmlinux BTF after struct_ops commands
Yichong Chen <chenyichong@uniontech.com>
tools/bpf/bpftool: Reset vmlinux BTF after map commands
Asad Kamal <asad.kamal@amd.com>
drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup
Asad Kamal <asad.kamal@amd.com>
drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup
Uday Khare <udaykhare77@gmail.com>
regulator: tps6594: Fix device node reference leaks in multiphase loop
Ian Rogers <irogers@google.com>
perf tests: Fix flakiness in branch stack sampling tests
Ian Rogers <irogers@google.com>
perf test: Fixes for check branch stack sampling
Ian Rogers <irogers@google.com>
perf tests: Fix flakiness in BPF counters test on hybrid systems
Namhyung Kim <namhyung@kernel.org>
perf test: Fix perf stat --bpf-counters on hybrid machines
Ian Rogers <irogers@google.com>
perf tests: Fix flakiness in trace record and replay test
Ian Rogers <irogers@google.com>
perf tests: Add robust record retry helper and use subsecond workloads
Ian Rogers <irogers@google.com>
perf test kvm: Add some basic perf kvm test coverage
Ian Rogers <irogers@google.com>
perf tests: Skip metrics validation if system-wide recording lacks permission
Namhyung Kim <namhyung@kernel.org>
perf test: Do not skip when some metrics tests succeeded
Ian Rogers <irogers@google.com>
perf test all metrics: Fully ignore Default metric failures
Ian Rogers <irogers@google.com>
perf test metrics: Update all metrics for possibly failing default metrics
Ian Rogers <irogers@google.com>
perf test: Truncate test description to fit terminal width
Ian Rogers <irogers@google.com>
perf test: Truncate printed test descriptions dynamically to avoid terminal wrapping
Ian Rogers <irogers@google.com>
perf test: Add -j/--junit option for JUnit XML test reports
Ian Rogers <irogers@google.com>
perf test: Fix subtest status alignment for multi-digit indexes
Ian Rogers <irogers@google.com>
perf test: Add summary reporting
Ian Rogers <irogers@google.com>
perf test: Show snippet failure output for verbose=1
Ian Rogers <irogers@google.com>
perf test: Refactor parallel poll loop to drain all pipes simultaneously
Ian Rogers <irogers@google.com>
perf test: Drain pipe after child finishes to avoid losing output
Aaradhana Sahu <aaradhana.sahu@oss.qualcomm.com>
wifi: ath12k: correct monitor destination ring size
Sean Young <sean@mess.org>
media: keymaps: Remove obsolete RC_MAP_HAUPPAUGE_NEW keymap define
Sean Young <sean@mess.org>
media: keymaps: Remove obsolete RC_MAP_RC5_TV keymap define
Jinjie Ruan <ruanjinjie@huawei.com>
riscv: kexec_file: Fix crashk_low_res not exclude bug
Daniel McCarthy <daniel@dragonzap.com>
pinctrl: bcm2835: Don't remove an unregistered GPIO chip
Zide Chen <zide.chen@intel.com>
perf/x86/intel/uncore: Keep PCI PMUs working when MMIO/MSR setup fails
Chen, Yu C <yu.c.chen@intel.com>
sched/fair: Fix overflow in update_tg_cfs_runnable()
Wei Yang <richard.weiyang@gmail.com>
mm/mm_init: fix incorrect node_spanned_pages
Henrik Grimler <henrik.grimler@axis.com>
drm/lima: call drm_mm_init() with a valid allocation range
Brian Masney <bmasney@redhat.com>
clk: imx: scu: drop redundant init.ops variable assignment
Frieder Schrempf <frieder.schrempf@kontron.de>
arm64: dts: imx93-kontron: set memory node to 0x80000000/1GiB
Weigang He <geoffreyhe2@gmail.com>
ARM: imx: fix device_node refcount leaks in imx7_src_init()
Weigang He <geoffreyhe2@gmail.com>
ARM: imx: fix device_node refcount leak in imx_src_init()
Min zhang <zhangmin2026@yeah.net>
clk: hisilicon: reset: Use devm_kzalloc to initialize hisi_reset_controller
Shengjiu Wang <shengjiu.wang@nxp.com>
ASoC: fsl_audmix: rework runtime PM handling in probe
Runyu Xiao <runyu.xiao@seu.edu.cn>
ASoC: rt700-sdw: always drain jack work on remove
Rosen Penev <rosenp@gmail.com>
clk: stm32: add missing bitfield.h header
Joey Lu <a0987203069@gmail.com>
clk: nuvoton: ma35d1: fix ma35d1_clk_pll_determine_rate logic
Joey Lu <a0987203069@gmail.com>
clk: nuvoton: ma35d1: fix PLL_CTL1_FRAC bit field width and fractional calc
Joey Lu <a0987203069@gmail.com>
clk: nuvoton: ma35d1: fix ignored div_u64 return values in PLL freq calculation
Alexander A. Klimov <grandmaster@al2klimov.de>
clk: moxart: remove unused variables, fix refcount leak
Myeonghun Pak <mhun512@gmail.com>
clk: versaclock7: Fix APLL clock leak on probe failure
Wei Hou <wei.hou@scaleflux.com>
cxl/pci: Remove incorrect mbox.valid check in cxl_pci_type3_init_mailbox()
Richard Cheng <icheng@nvidia.com>
cxl/mbox: Clamp mailbox output allocation to the payload size
Gui-Dong Han <hanguidong02@gmail.com>
media: cec-pin: Fix event FIFO ordering
Weigang He <geoffreyhe2@gmail.com>
soc: samsung: exynos-pmu: fix of_node refcount leak in exynos_get_pmu_regmap()
Michael Bommarito <michael.bommarito@gmail.com>
HID: roccat: bound device-supplied profile index
Christos Maragkos <whitetowersoftware@gmail.com>
HID: nintendo: Fix imu_timestamp_us double increment per report
Philipp Weber <kernel@phwe.de>
HID: core: quiesce input in hid_hw_stop() to prevent use-after-free
Amin Vakil <info@aminvakil.com>
selftests: proc: include fcntl.h in proc-pidns
Maoyi Xie <maoyixie.tju@gmail.com>
platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count
Jens Remus <jremus@linux.ibm.com>
x86/cfi: Use symmetric SYM_START and SYM_END in __CFI_TYPE()
Wanwu Li <liwanwu@kylinos.cn>
sched_ext/scx_flatcg: Fix cvtime_delta race and add hweight scaling to bypass charging
Konstantin Andreev <andreev@swemel.ru>
smack: restrict smackfs/{direct,mapped} values to 0-255
Konstantin Andreev <andreev@swemel.ru>
smack: deduplicate smackfs/{direct,mapped} file_operations
Dmitry Antipov <dmantipov@yandex.ru>
smack: simplify write handlers of sysfs entries
Konstantin Andreev <andreev@swemel.ru>
smack: fix incorrect task context in smack_msg_queue_msgrcv
Maxime Ripard <mripard@kernel.org>
drm/bridge: cdns-mhdp8546: Return an error pointer on allocation failure
Maxime Ripard <mripard@kernel.org>
drm/bridge: cdns-dsi: Return an error pointer on allocation failure
Nicolas Frattaroli <nicolas.frattaroli@collabora.com>
drm/rockchip: vop2: Recognise 10-bit YUV422 as YUV format
Nicolas Frattaroli <nicolas.frattaroli@collabora.com>
drm/rockchip: vop2: Add RK3576 to the RG swap special case
Maíra Canal <mcanal@igalia.com>
drm/v3d: Clear queue->active_job when v3d_fence_create() fails
Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
drm/bridge: display-connector: trigger initial HPD event for DP
Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
drm/bridge: display-connector: don't autoenable HPD IRQ
Damon Ding <damon.ding@rock-chips.com>
drm/rockchip: analogix_dp: Fix OF node reference leak via auto cleanup
Damon Ding <damon.ding@rock-chips.com>
drm/rockchip: analogix_dp: Enable hclk for RK3588
Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
drm/rockchip: vop2: Wait for layer cfg done before switching LAYERSEL_REGDONE_SEL
Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
drm/rockchip: vop2: Fix wrong wait target in layer cfg done check
Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
drm/rockchip: dw_dp: Release core resources
Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
drm/rockchip: dw_dp: Add missing newline in dev_err_probe() message
Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
drm/rockchip: dw_dp: Simplify error handling
Andy Yan <andy.yan@rock-chips.com>
drm/bridge: synopsys: dw-dp: Set pixel mode by platform data
Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
drm/bridge: synopsys: dw-dp: Support unregistering the AUX channel
Paul Kocialkowski <paulk@sys-base.io>
drm: lcdif: Wait for vblank before disabling DMA
Yicong Hui <yiconghui@gmail.com>
drm: Remove unused header in drm_dumb_buffers.c
Casey Schaufler <casey@schaufler-ca.com>
Smack: Fix error in capability bypass
Yosry Ahmed <yosry@kernel.org>
KVM: x86: Check EFER validity on KVM_SET_SREGS*
Sean Christopherson <seanjc@google.com>
KVM: x86: Move the bulk of register specific code from x86.c to regs.c
Sean Christopherson <seanjc@google.com>
KVM: x86: Rename __{g,s}et_sregs2() => kvm_vcpu_ioctl_x86_{g,s}et_sregs2()
Sean Christopherson <seanjc@google.com>
KVM: x86: Extract REGS and SREGS runtime sync code to helpers
Christian Borntraeger <borntraeger@linux.ibm.com>
KVM: s390: Zero initialize data structures for inject_pfault_token
Yosry Ahmed <yosry@kernel.org>
KVM: x86: Disallow EFER.LME and EFER.LMA if long mode is not supported
Marc Zyngier <maz@kernel.org>
KVM: arm64: Remove VM-wide VNCR mapping counter
Guoniu Zhou <guoniu.zhou@oss.nxp.com>
media: dt-bindings: nxp,imx8-isi: Drop fsl,blk-ctrl requirement for i.MX8ULP
Marc Zyngier <maz@kernel.org>
KVM: arm64: Handle VNCR TLB invalidation race with vcpu_put() VNCR unmapping
Oliver Upton <oupton@kernel.org>
KVM: arm64: nv: Fully update VNCR fixmap state in kvm_translate_vncr()
Bryam Vargas <hexlabsecurity@proton.me>
dm-pcache: validate the persisted dirty_tail chain at load
Bryam Vargas <hexlabsecurity@proton.me>
dm-pcache: bound the logical key offset from persistent memory
Bryam Vargas <hexlabsecurity@proton.me>
dm-pcache: reject a kset that overruns its segment
Yuhang.chen <yhchen312@gmail.com>
wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot
Jeffin Philip <jeffinphilip14@gmail.com>
usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers()
Pawel Laszczak <pawell@cadence.com>
usb: cdnsp: fix wakeup from S3 after controller context loss
Masami Hiramatsu (Google) <mhiramat@kernel.org>
tracing/probes: Fix anon_stack check for unnamed bitfields in btf_find_struct_member
Muhammad Bilal <meatuni001@gmail.com>
staging: sm750fb: fix mono image source stride mismatch in lynxfb_ops_imageblit()
Krishna Chomal <krishna.chomal108@gmail.com>
platform/x86: hp-wmi: Add support for OMEN MAX 16-ak0xxx (8DD6)
Mario Limonciello <mario.limonciello@amd.com>
platform/x86/amd/pmc: Fix msg_port restoration in amd_stb_debugfs_open_v2()
Dapeng Mi <dapeng1.mi@linux.intel.com>
perf/x86/intel: Remove anythread_deprecated bit from perf_capabilities
Baolin Wang <baolin.wang@linux.alibaba.com>
mm: fix incorrect vm_flags usage when checking allowable orders for tmpfs
Lorenzo Stoakes (ARM) <ljs@kernel.org>
mm/secretmem: properly account locked pages
Lorenzo Stoakes (ARM) <ljs@kernel.org>
mm/mremap: reset unfaulted VMA page offset for MREMAP_DONTUNMAP
Usama Arif <usama.arif@linux.dev>
mm/huge_memory: transfer the pmd dirty bit to the folio on zap
Adrian Hunter <adrian.hunter@intel.com>
i3c: master: Fix use-after-free of master->this
Adrian Hunter <adrian.hunter@intel.com>
i3c: master: Do not treat master device as a duplicate target
Steven Rostedt <rostedt@goodmis.org>
ftrace: Take trace_array reference before accessing its ftrace_ops
Imran Shaik <imran.shaik@oss.qualcomm.com>
clk: qcom: Fix test_ctl_hi field for DEFAULT_EVO PLLs
Taimuraz Kaitmazov <taimuraz@kaitmazov.com>
accel/amdxdna: return early from a zero-length flush
Li Chen <me@linux.beauty>
nvdimm: virtio_pmem: refcount requests for token lifetime
Hui Su <sh_def@163.com>
io_uring/waitid: avoid siginfo copy during ring teardown
Li Chen <me@linux.beauty>
nvdimm: virtio_pmem: use READ_ONCE()/WRITE_ONCE() for wait flags
Hui Su <sh_def@163.com>
io_uring/waitid: honor task_work cancellation
Li Chen <me@linux.beauty>
nvdimm: virtio_pmem: always wake -ENOSPC waiters
Caleb Sander Mateos <csander@purestorage.com>
io_uring: add wrapper type for io_req_tw_func_t arg
Li Chen <me@linux.beauty>
nvdimm: virtio_pmem: stop allocating child flush bio
Caleb Sander Mateos <csander@purestorage.com>
io_uring: only call io_should_terminate_tw() once for ctx
Steven Rostedt <rostedt@goodmis.org>
tracing: Take trace_array reference when opening options file
Guangshuo Li <lgs201920130244@gmail.com>
i2c: qcom-cci: fix autosuspend cleanup
Sebastian Andrzej Siewior <bigeasy@linutronix.de>
futex: Provide rt_mutex_.*_schedule() equivalents for futex scheduling
Li Chen <me@linux.beauty>
nvdimm: pmem: keep PREFLUSH before data writes
Jens Axboe <axboe@kernel.dk>
io_uring/waitid: have io_waitid_complete() remove wait queue entry
Steven Rostedt <rostedt@goodmis.org>
tracing: Make printk_trace global for tracing system
Vladimir Zapolskiy <vladimir.zapolskiy@linaro.org>
i2c: qcom-cci: Remove overcautious disable_irq() calls
Peter Zijlstra <peterz@infradead.org>
futex: Optimize futex hash bucket access patterns
Jan Kara <jack@suse.cz>
udf: Fix data loss when converting inline inodes to out of line
Masami Hiramatsu (Google) <mhiramat@kernel.org>
tracing/probes: Fix BTF kflag check for anonymous struct member access
Muhammad Bilal <meatuni001@gmail.com>
staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie()
Vincent Donnefort <vdonnefort@google.com>
ring-buffer: Allow splice reads on static buffers
Srinivas Pandruvada <srinivas.pandruvada@linux.intel.com>
platform/x86: ISST: Validate max level for set feature
Abdun Nihaal <nihaal@cse.iitm.ac.in>
platform/x86: int1092: Fix potential memory leak in sar_probe()
Yilin Zhang <yilinzhang@moonshot.ai>
perf: Fix use-after-free when perf mmap() revival races with the last munmap()
Farhan Ali <alifm@linux.ibm.com>
PCI: Allow per function PCI slots to fix slot reset on s390
Chao Shi <coshi036@gmail.com>
nvme: skip the zoned limits update if the zone info query failed
Glenn Judd <gmj@meta.com>
net/mlx5e: do not HW-GRO coalesce small frames
Miquel Raynal (DAVE) <miquel.raynal@bootlin.com>
mtd: rawnand: pl353: Make sure we use the monolithic helpers for raw accesses
Baineng Shou <shoubaineng@gmail.com>
misc: fastrpc: don't publish fd before copy_to_user() succeeds
Moksh Panicker <mokshpanicker.7@gmail.com>
iio: light: apds9306: fix PM reference leak in apds9306_read_data()
Adrian Hunter <adrian.hunter@intel.com>
i3c: master: Fix recursive locking during device registration
Jon Hunter <jonathanh@nvidia.com>
ASoC: tegra: Fix the MIXER enable default value
Baul Lee <baul.lee@xbow.com>
ALSA: FCP: do not copy out an uninitialised init response
Li Chen <me@linux.beauty>
nvdimm: preserve flush callback -ENOMEM
Jens Axboe <axboe@kernel.dk>
io_uring: unify task_work cancelation checks
Steven Rostedt <rostedt@goodmis.org>
tracing: Clean up use of trace_create_maxlat_file()
Vladimir Zapolskiy <vladimir.zapolskiy@linaro.org>
i2c: qcom-cci: Do not check return value of cci_init()
Marco Elver <elver@google.com>
compiler_types: Move lock checking attributes to compiler-context-analysis.h
Bryam Vargas <hexlabsecurity@proton.me>
wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy
Jan Kara <jack@suse.cz>
udf: Move udf_map_block() up
Martin Kaiser <martin@kaiser.cx>
tracing/probes: ignore id update from btf_type_skip_modifiers
Vivek BalachandharTN <vivek.balachandhar@gmail.com>
staging: rtl8723bs: fix spacing around operators
Steven Rostedt <rostedt@goodmis.org>
ring-buffer: Show persistent buffer dropped events in trace_pipe file
Rafael J. Wysocki <rafael.j.wysocki@intel.com>
PM: runtime: Wrapper macros for ACQUIRE()/ACQUIRE_ERR()
Srinivas Pandruvada <srinivas.pandruvada@linux.intel.com>
platform/x86: ISST: Check for admin capability for write commands
Rafael J. Wysocki <rafael.j.wysocki@intel.com>
platform/x86: intel_sar: Check ACPI_HANDLE() against NULL
Peter Zijlstra <peterz@infradead.org>
perf/core: Fix deadlock in perf_mmap() failure path
Farhan Ali <alifm@linux.ibm.com>
PCI: Introduce PCI_SLOT_PLACEHOLDER constant for slot_nr placeholder value
Caleb Sander Mateos <csander@purestorage.com>
nvme: fold nvme_config_discard() into nvme_update_disk_info()
Dragos Tatulea <dtatulea@nvidia.com>
net/mlx5e: SHAMPO, Always calculate page size
Andrea Scian <andrea.scian@dave.eu>
mtd: rawnand: pl353: Add message about ECC mode
Adrian Hunter <adrian.hunter@intel.com>
i3c: master: Fix device_register() error path
Baineng Shou <shoubaineng@gmail.com>
dma-buf: dma-heap: don't publish fd before copy_to_user() succeeds
Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
ASoC: tegra210_mixer: sort the register default table
Takashi Iwai <tiwai@suse.de>
ALSA: usb-audio: Relax __free() variable declarations
Sven Eckelmann <sven@narfation.org>
batman-adv: fix TX priority extraction for BATADV_FORW_MCAST
SJ Park <sj@kernel.org>
mm/damon/sysfs: read ops_id only once in damon_sysfs_apply_inputs()
Sven Eckelmann <sven@narfation.org>
batman-adv: bla: avoid CRC corruption due to parallel claim add
Sven Eckelmann <sven@narfation.org>
batman-adv: dat: atomically update mac addresses
Akhmed Zhitaev <zhitaevakh@gmail.com>
drm/amd/display: Scale custom brightness curve from full range
Mario Limonciello <mario.limonciello@amd.com>
drm/amd/display: Fix backlight max_brightness to match exported range
Dragos Tatulea <dtatulea@nvidia.com>
net/mlx5e: xsk: Fix unlocked writing to ICOSQ
-------------
Diffstat:
.../ABI/testing/configfs-usb-gadget-uac1_legacy | 3 -
Documentation/admin-guide/device-mapper/dm-ima.rst | 7 +-
.../admin-guide/device-mapper/dm-integrity.rst | 13 +
Documentation/admin-guide/pm/amd-pstate.rst | 34 +-
.../devicetree/bindings/media/nxp,imx8-isi.yaml | 11 +-
Documentation/hwmon/cros_ec_hwmon.rst | 26 +-
Documentation/hwmon/emc1403.rst | 8 +-
Documentation/hwmon/hwmon-kernel-api.rst | 7 +-
Documentation/leds/leds-st1202.rst | 2 +-
Documentation/netlink/specs/devlink.yaml | 2 +
.../networking/devlink/devlink-eswitch-attr.rst | 13 +
Documentation/usb/gadget-testing.rst | 3 -
MAINTAINERS | 3 +
Makefile | 6 +-
arch/Kconfig | 3 +
arch/arm/boot/dts/allwinner/sun4i-a10.dtsi | 2 +-
arch/arm/boot/dts/marvell/armada-388-helios4.dts | 13 +
arch/arm/kernel/hw_breakpoint.c | 11 +-
arch/arm/mach-exynos/mcpm-exynos.c | 12 +-
arch/arm/mach-exynos/suspend.c | 48 +-
arch/arm/mach-imx/src.c | 3 +
arch/arm/mach-lpc32xx/common.c | 5 +-
arch/arm/mach-lpc32xx/common.h | 2 +
arch/arm/mach-lpc32xx/phy3250.c | 2 +
arch/arm/mach-lpc32xx/pm.c | 5 +-
arch/arm/mach-pxa/generic.h | 6 +-
arch/arm/mach-pxa/irq.c | 10 +-
arch/arm/mach-pxa/mfp-pxa2xx.c | 10 +-
arch/arm/mach-pxa/mfp-pxa3xx.c | 10 +-
arch/arm/mach-pxa/pxa25x.c | 4 +-
arch/arm/mach-pxa/pxa27x.c | 4 +-
arch/arm/mach-pxa/pxa3xx.c | 4 +-
arch/arm/mach-pxa/smemc.c | 12 +-
arch/arm/mach-s3c/irq-pm-s3c64xx.c | 12 +-
arch/arm/mach-s5pv210/pm.c | 10 +-
arch/arm/mach-versatile/integrator_ap.c | 12 +-
arch/arm/mm/cache-b15-rac.c | 12 +-
arch/arm/mm/fault.c | 16 +-
arch/arm64/Kconfig | 2 +
.../boot/dts/allwinner/sun50i-a64-pinephone.dtsi | 4 +-
arch/arm64/boot/dts/amlogic/meson-axg-s400.dts | 4 +
arch/arm64/boot/dts/amlogic/meson-axg.dtsi | 3 +-
arch/arm64/boot/dts/freescale/imx8-ss-audio.dtsi | 8 +-
.../boot/dts/freescale/imx93-kontron-osm-s.dtsi | 4 +-
.../boot/dts/marvell/armada-3720-turris-mox.dts | 3 +-
arch/arm64/boot/dts/qcom/hamoa.dtsi | 4 +-
arch/arm64/boot/dts/qcom/ipq5018.dtsi | 5 +-
arch/arm64/boot/dts/qcom/lemans.dtsi | 977 ++++-----
.../boot/dts/qcom/msm8976-longcheer-l9360.dts | 4 +-
arch/arm64/boot/dts/qcom/msm8996-xiaomi-gemini.dts | 2 +-
.../boot/dts/qcom/msm8998-sony-xperia-yoshino.dtsi | 4 -
arch/arm64/boot/dts/qcom/msm8998-xiaomi-sagit.dts | 5 -
arch/arm64/boot/dts/qcom/msm8998.dtsi | 24 +-
arch/arm64/boot/dts/qcom/qcm2290.dtsi | 1 +
arch/arm64/boot/dts/qcom/qcs404.dtsi | 16 +-
arch/arm64/boot/dts/qcom/qcs6490-rb3gen2.dts | 18 +-
arch/arm64/boot/dts/qcom/qcs8550-aim300.dtsi | 4 +-
arch/arm64/boot/dts/qcom/sar2130p-qar2130p.dts | 4 +-
arch/arm64/boot/dts/qcom/sar2130p.dtsi | 8 +-
arch/arm64/boot/dts/qcom/sc7180-trogdor.dtsi | 5 +
arch/arm64/boot/dts/qcom/sc7280-herobrine.dtsi | 5 +
arch/arm64/boot/dts/qcom/sc7280.dtsi | 8 +-
.../arm64/boot/dts/qcom/sc8180x-lenovo-flex-5g.dts | 57 +-
arch/arm64/boot/dts/qcom/sc8180x-primus.dts | 56 +-
arch/arm64/boot/dts/qcom/sc8180x.dtsi | 16 +-
arch/arm64/boot/dts/qcom/sc8280xp-crd.dts | 4 +-
.../dts/qcom/sc8280xp-lenovo-thinkpad-x13s.dts | 2 +-
.../boot/dts/qcom/sc8280xp-microsoft-arcata.dts | 4 +-
.../boot/dts/qcom/sc8280xp-microsoft-blackrock.dts | 19 +-
arch/arm64/boot/dts/qcom/sdm632-motorola-ocean.dts | 2 +-
arch/arm64/boot/dts/qcom/sdm845.dtsi | 64 +-
arch/arm64/boot/dts/qcom/sm6150.dtsi | 4 +-
arch/arm64/boot/dts/qcom/sm7225-fairphone-fp4.dts | 6 +-
arch/arm64/boot/dts/qcom/sm8150.dtsi | 8 +-
.../boot/dts/qcom/sm8250-xiaomi-elish-common.dtsi | 2 +-
arch/arm64/boot/dts/qcom/sm8250.dtsi | 48 +-
arch/arm64/boot/dts/qcom/sm8350.dtsi | 8 +-
arch/arm64/boot/dts/qcom/sm8450.dtsi | 8 +-
arch/arm64/boot/dts/qcom/sm8550.dtsi | 8 +-
arch/arm64/boot/dts/qcom/sm8650.dtsi | 8 +-
arch/arm64/boot/dts/qcom/sm8750.dtsi | 5 +-
.../boot/dts/rockchip/rk3399-gru-chromebook.dtsi | 3 +-
.../boot/dts/rockchip/rk3566-bigtreetech-cb2.dtsi | 2 +-
arch/arm64/boot/dts/rockchip/rk3588-base.dtsi | 4 +-
arch/arm64/boot/dts/rockchip/rk3588-extra.dtsi | 4 +-
arch/arm64/boot/dts/ti/k3-am64-main.dtsi | 2 +-
arch/arm64/include/asm/kvm_host.h | 3 -
arch/arm64/include/asm/processor.h | 2 +-
arch/arm64/include/asm/ptdump.h | 2 +
arch/arm64/include/asm/rsi_cmds.h | 27 +-
arch/arm64/kernel/hibernate.c | 16 +-
arch/arm64/kernel/ptrace.c | 4 +-
arch/arm64/kernel/smp.c | 2 +-
arch/arm64/kvm/hyp/vhe/switch.c | 3 +-
arch/arm64/kvm/nested.c | 64 +-
arch/arm64/lib/Makefile | 4 +
arch/arm64/mm/ptdump.c | 14 +-
arch/arm64/net/bpf_jit_comp.c | 28 +-
arch/csky/kernel/entry.S | 6 +-
arch/loongarch/kernel/smp.c | 12 +-
arch/m68k/emu/nfcon.c | 2 +-
arch/m68k/kernel/traps.c | 4 +-
arch/mips/alchemy/common/dbdma.c | 12 +-
arch/mips/alchemy/common/irq.c | 24 +-
arch/mips/alchemy/common/usb.c | 12 +-
arch/mips/kernel/ptrace.c | 6 +-
arch/mips/pci/pci-alchemy.c | 16 +-
arch/powerpc/Kconfig | 1 +
arch/powerpc/configs/85xx-hw.config | 1 +
arch/powerpc/kernel/ima_arch.c | 5 -
arch/powerpc/kernel/irq.c | 16 +-
arch/powerpc/kernel/secure_boot.c | 6 +
arch/powerpc/kernel/smp.c | 3 +
arch/powerpc/kexec/crash.c | 2 +-
arch/powerpc/platforms/44x/gpio.c | 1 +
arch/powerpc/platforms/cell/spu_base.c | 10 +-
arch/powerpc/platforms/powermac/pic.c | 12 +-
arch/powerpc/sysdev/cpm_common.c | 13 +
arch/powerpc/sysdev/fsl_lbc.c | 12 +-
arch/powerpc/sysdev/fsl_pci.c | 12 +-
arch/powerpc/sysdev/ipic.c | 12 +-
arch/powerpc/sysdev/mpic.c | 14 +-
arch/powerpc/sysdev/mpic_timer.c | 10 +-
arch/riscv/boot/dts/sophgo/cv180x.dtsi | 2 +-
arch/riscv/boot/dts/spacemit/Makefile | 2 +
arch/riscv/boot/dts/spacemit/k1-bananapi-f3.dts | 4 +-
arch/riscv/boot/dts/spacemit/k1-milkv-jupiter.dts | 4 +-
arch/riscv/boot/dts/spacemit/k1-musepi-pro.dts | 79 +
arch/riscv/boot/dts/spacemit/k1-orangepi-r2s.dts | 90 +
arch/riscv/boot/dts/spacemit/k1-pinctrl.dtsi | 24 +-
arch/riscv/kernel/cpufeature.c | 3 +-
arch/riscv/kernel/machine_kexec_file.c | 14 +-
arch/riscv/net/bpf_jit_comp64.c | 19 +-
arch/riscv/net/bpf_jit_core.c | 1 +
arch/s390/Kconfig | 22 +-
arch/s390/Makefile | 11 +-
arch/s390/boot/Makefile | 1 +
arch/s390/boot/boot.h | 4 +
arch/s390/boot/ipl_data.c | 3 +-
arch/s390/boot/ipl_parm.c | 6 +
arch/s390/boot/stackprotector.c | 6 +
arch/s390/boot/startup.c | 8 +
arch/s390/configs/compat.config | 3 -
arch/s390/hypfs/hypfs_sprp.c | 6 +-
arch/s390/include/asm/arch-stackprotector.h | 25 +
arch/s390/include/asm/compat.h | 140 --
arch/s390/include/asm/elf.h | 46 +-
arch/s390/include/asm/ftrace.h | 19 +-
arch/s390/include/asm/irqflags.h | 20 +-
arch/s390/include/asm/lowcore.h | 3 +-
arch/s390/include/asm/processor.h | 12 +-
arch/s390/include/asm/ptrace.h | 2 +-
arch/s390/include/asm/seccomp.h | 5 -
arch/s390/include/asm/stackprotector.h | 16 +
arch/s390/include/asm/syscall.h | 19 +-
arch/s390/include/asm/syscall_wrapper.h | 95 +-
arch/s390/include/asm/thread_info.h | 2 -
arch/s390/include/asm/unistd.h | 5 -
arch/s390/include/asm/vdso-symbols.h | 12 +-
arch/s390/kernel/Makefile | 10 +-
arch/s390/kernel/asm-offsets.c | 4 +
arch/s390/kernel/audit.c | 16 -
arch/s390/kernel/audit.h | 16 -
arch/s390/kernel/compat_audit.c | 48 -
arch/s390/kernel/compat_linux.c | 289 ---
arch/s390/kernel/compat_linux.h | 101 -
arch/s390/kernel/compat_ptrace.h | 64 -
arch/s390/kernel/compat_signal.c | 420 ----
arch/s390/kernel/debug.c | 10 +-
arch/s390/kernel/entry.S | 17 +-
arch/s390/kernel/ima_arch.c | 14 -
arch/s390/kernel/ipl.c | 8 +-
arch/s390/kernel/irqflags.c | 28 +
arch/s390/kernel/module.c | 9 +
arch/s390/kernel/perf_cpum_cf.c | 1 -
arch/s390/kernel/perf_event.c | 1 -
arch/s390/kernel/perf_regs.c | 3 -
arch/s390/kernel/process.c | 9 +-
arch/s390/kernel/ptrace.c | 524 -----
arch/s390/kernel/setup.c | 1 -
arch/s390/kernel/signal.c | 27 +-
arch/s390/kernel/smp.c | 3 +
arch/s390/kernel/stackprotector.c | 156 ++
arch/s390/kernel/stacktrace.c | 3 -
arch/s390/kernel/uprobes.c | 6 +-
arch/s390/kernel/vdso.c | 36 +-
arch/s390/kernel/{vdso32 => vdso}/.gitignore | 2 +-
arch/s390/kernel/vdso/Makefile | 81 +
.../kernel/{vdso64 => vdso}/gen_vdso_offsets.sh | 2 +-
arch/s390/kernel/{vdso64 => vdso}/getcpu.c | 0
arch/s390/kernel/{vdso32 => vdso}/note.S | 0
arch/s390/kernel/{vdso64 => vdso}/vdso.h | 6 +-
.../{vdso64/vdso64.lds.S => vdso/vdso.lds.S} | 0
.../vdso64_generic.c => vdso/vdso_generic.c} | 0
.../kernel/{vdso64 => vdso}/vdso_user_wrapper.S | 0
.../vdso64_wrapper.S => vdso/vdso_wrapper.S} | 8 +-
.../kernel/{vdso64 => vdso}/vgetrandom-chacha.S | 0
arch/s390/kernel/{vdso64 => vdso}/vgetrandom.c | 0
arch/s390/kernel/vdso32/Makefile | 64 -
arch/s390/kernel/vdso32/gen_vdso_offsets.sh | 15 -
arch/s390/kernel/vdso32/vdso32.lds.S | 140 --
arch/s390/kernel/vdso32/vdso32_wrapper.S | 15 -
arch/s390/kernel/vdso32/vdso_user_wrapper.S | 22 -
arch/s390/kernel/vdso64/.gitignore | 2 -
arch/s390/kernel/vdso64/Makefile | 79 -
arch/s390/kernel/vdso64/note.S | 13 -
arch/s390/kernel/vmlinux.lds.S | 13 +
arch/s390/kvm/kvm-s390.c | 4 +-
arch/s390/mm/fault.c | 1 -
arch/s390/mm/mmap.c | 1 -
arch/s390/pci/pci_clp.c | 4 +-
arch/sh/mm/pmb.c | 10 +-
arch/x86/entry/entry_64_fred.S | 2 +
arch/x86/events/amd/ibs.c | 12 +-
arch/x86/events/amd/uncore.c | 31 +
arch/x86/events/intel/core.c | 10 +-
arch/x86/events/intel/pt.c | 96 +-
arch/x86/events/intel/uncore.c | 2 -
arch/x86/events/perf_event.h | 2 +-
arch/x86/hyperv/hv_init.c | 12 +-
arch/x86/include/asm/efi.h | 4 +-
arch/x86/include/asm/linkage.h | 2 +-
arch/x86/include/asm/pkeys.h | 3 +
arch/x86/kernel/amd_gart_64.c | 10 +-
arch/x86/kernel/apic/apic.c | 12 +-
arch/x86/kernel/apic/io_apic.c | 17 +-
arch/x86/kernel/cpu/aperfmperf.c | 20 +-
arch/x86/kernel/cpu/common.c | 25 +-
arch/x86/kernel/cpu/cpu.h | 9 -
arch/x86/kernel/cpu/intel_epb.c | 16 +-
arch/x86/kernel/cpu/mce/core.c | 14 +-
arch/x86/kernel/cpu/microcode/core.c | 15 +-
arch/x86/kernel/cpu/mtrr/legacy.c | 12 +-
arch/x86/kernel/cpu/tsx.c | 9 +-
arch/x86/kernel/cpu/umwait.c | 10 +-
arch/x86/kernel/i8237.c | 10 +-
arch/x86/kernel/i8259.c | 14 +-
arch/x86/kernel/kvm.c | 12 +-
arch/x86/kvm/Makefile | 4 +-
arch/x86/kvm/regs.c | 787 +++++++
arch/x86/kvm/x86.c | 793 +------
arch/x86/kvm/x86.h | 16 +
arch/x86/mm/pat/set_memory.c | 8 +-
arch/x86/net/bpf_jit_comp.c | 14 +-
arch/x86/platform/efi/efi.c | 2 +-
block/bio.c | 10 +
block/blk-cgroup.c | 5 +
block/blk-core.c | 13 +-
block/blk-crypto-fallback.c | 407 ++--
block/blk-crypto-internal.h | 19 +-
block/blk-crypto.c | 52 +-
block/blk-iocost.c | 2 +-
block/blk-map.c | 3 +
block/blk-merge.c | 48 +-
block/blk-mq-dma.c | 4 +-
block/blk-mq.c | 12 +-
block/blk-stat.c | 2 +-
block/fops.c | 9 +-
block/kyber-iosched.c | 2 +-
crypto/acompress.c | 16 +-
crypto/lskcipher.c | 1 -
drivers/accel/amdxdna/amdxdna_gem.c | 4 +
drivers/accessibility/speakup/keyhelp.c | 17 +-
drivers/accessibility/speakup/kobjects.c | 6 +-
drivers/acpi/battery.c | 44 +-
drivers/acpi/ec.c | 40 +-
drivers/acpi/pci_link.c | 10 +-
drivers/acpi/pci_root.c | 3 +-
drivers/acpi/processor_core.c | 31 +-
drivers/acpi/processor_driver.c | 16 +-
drivers/acpi/processor_idle.c | 116 +-
drivers/acpi/riscv/irq.c | 33 +-
drivers/acpi/scan.c | 13 +-
drivers/acpi/sleep.c | 12 +-
drivers/acpi/video_detect.c | 4 +-
drivers/base/cacheinfo.c | 9 +-
drivers/base/firmware_loader/fallback.c | 10 +
drivers/base/firmware_loader/main.c | 12 +-
drivers/base/memory.c | 4 +-
drivers/base/soc.c | 15 +-
drivers/base/swnode.c | 2 +-
drivers/base/syscore.c | 82 +-
drivers/block/mtip32xx/mtip32xx.c | 7 +
drivers/block/mtip32xx/mtip32xx.h | 2 +
drivers/block/null_blk/main.c | 78 +-
drivers/block/ublk_drv.c | 20 +-
drivers/bluetooth/btintel.c | 2 +-
drivers/bluetooth/btmtk.c | 104 +-
drivers/bluetooth/btmtk.h | 8 +-
drivers/bluetooth/btmtksdio.c | 84 +-
drivers/bluetooth/btnxpuart.c | 15 +-
drivers/bluetooth/btqca.c | 3 +-
drivers/bluetooth/btusb.c | 68 +-
drivers/bluetooth/virtio_bt.c | 8 +-
drivers/bus/mhi/ep/main.c | 15 +-
drivers/bus/mhi/host/init.c | 4 +-
drivers/bus/mhi/host/main.c | 6 +
drivers/bus/mvebu-mbus.c | 16 +-
drivers/bus/qcom-ebi2.c | 51 +-
drivers/bus/ti-sysc.c | 12 +-
drivers/char/hw_random/core.c | 4 +-
drivers/char/hw_random/imx-rngc.c | 4 +-
drivers/char/hw_random/ks-sa-rng.c | 9 +-
drivers/char/ppdev.c | 10 +-
drivers/char/tpm/st33zp24/st33zp24.c | 8 +-
drivers/char/xilinx_hwicap/xilinx_hwicap.c | 5 +-
drivers/clk/at91/pmc.c | 12 +-
drivers/clk/clk-devres.c | 12 +-
drivers/clk/clk-moxart.c | 14 -
drivers/clk/clk-palmas.c | 14 +-
drivers/clk/clk-versaclock7.c | 2 +-
drivers/clk/hisilicon/reset.c | 2 +-
drivers/clk/imx/clk-scu.c | 1 -
drivers/clk/imx/clk-vf610.c | 12 +-
drivers/clk/ingenic/jz4725b-cgu.c | 2 +-
drivers/clk/ingenic/jz4740-cgu.c | 2 +-
drivers/clk/ingenic/jz4755-cgu.c | 2 +-
drivers/clk/ingenic/jz4760-cgu.c | 2 +-
drivers/clk/ingenic/jz4770-cgu.c | 2 +-
drivers/clk/ingenic/jz4780-cgu.c | 2 +-
drivers/clk/ingenic/pm.c | 14 +-
drivers/clk/ingenic/pm.h | 2 +-
drivers/clk/ingenic/tcu.c | 12 +-
drivers/clk/ingenic/x1000-cgu.c | 2 +-
drivers/clk/ingenic/x1830-cgu.c | 2 +-
drivers/clk/mediatek/clk-mt2701.c | 2 +-
drivers/clk/mediatek/clk-mt2712-apmixedsys.c | 2 +-
drivers/clk/mediatek/clk-mt6735-apmixedsys.c | 9 +-
drivers/clk/mediatek/clk-mt6765.c | 2 +-
drivers/clk/mediatek/clk-mt6779.c | 2 +-
drivers/clk/mediatek/clk-mt6795-apmixedsys.c | 2 +-
drivers/clk/mediatek/clk-mt6797.c | 2 +-
drivers/clk/mediatek/clk-mt7622-apmixedsys.c | 2 +-
drivers/clk/mediatek/clk-mt7629.c | 2 +-
drivers/clk/mediatek/clk-mt7981-apmixed.c | 2 +-
drivers/clk/mediatek/clk-mt7986-apmixed.c | 2 +-
drivers/clk/mediatek/clk-mt7988-apmixed.c | 2 +-
drivers/clk/mediatek/clk-mt8135-apmixedsys.c | 3 +-
drivers/clk/mediatek/clk-mt8135.c | 5 +-
drivers/clk/mediatek/clk-mt8167-apmixedsys.c | 2 +-
drivers/clk/mediatek/clk-mt8173-apmixedsys.c | 14 +-
drivers/clk/mediatek/clk-mt8183-apmixedsys.c | 2 +-
drivers/clk/mediatek/clk-mt8186-apmixedsys.c | 2 +-
drivers/clk/mediatek/clk-mt8188-apmixedsys.c | 2 +-
drivers/clk/mediatek/clk-mt8192-apmixedsys.c | 2 +-
drivers/clk/mediatek/clk-mt8195-apmixedsys.c | 2 +-
drivers/clk/mediatek/clk-mt8195-apusys_pll.c | 3 +-
drivers/clk/mediatek/clk-mt8196-apmixedsys.c | 3 +-
drivers/clk/mediatek/clk-mt8196-mcu.c | 2 +-
drivers/clk/mediatek/clk-mt8196-mfg.c | 2 +-
drivers/clk/mediatek/clk-mt8196-vlpckgen.c | 2 +-
drivers/clk/mediatek/clk-mt8365-apmixedsys.c | 2 +-
drivers/clk/mediatek/clk-mt8516-apmixedsys.c | 2 +-
drivers/clk/mediatek/clk-pll.c | 16 +-
drivers/clk/mediatek/clk-pll.h | 14 +-
drivers/clk/mediatek/clk-pllfh.c | 111 +-
drivers/clk/mediatek/clk-pllfh.h | 2 +-
drivers/clk/mvebu/common.c | 12 +-
drivers/clk/nuvoton/clk-ma35d1-pll.c | 42 +-
drivers/clk/qcom/camcc-sc8280xp.c | 19 -
drivers/clk/qcom/common.c | 4 +-
drivers/clk/qcom/gcc-glymur.c | 33 +-
drivers/clk/qcom/gcc-qcm2290.c | 18 +-
drivers/clk/qcom/gcc-qcs8300.c | 8 +-
drivers/clk/qcom/gcc-sm6115.c | 6 +-
drivers/clk/qcom/gdsc.c | 25 +-
drivers/clk/qcom/gpucc-qcm2290.c | 2 +-
drivers/clk/rockchip/clk-pll.c | 9 +-
drivers/clk/rockchip/clk-rk3288.c | 12 +-
drivers/clk/rockchip/clk-rk3576.c | 11 +-
drivers/clk/samsung/clk-s5pv210-audss.c | 12 +-
drivers/clk/samsung/clk.c | 12 +-
drivers/clk/stm32/clk-stm32mp21.c | 1 +
drivers/clk/stm32/clk-stm32mp25.c | 1 +
drivers/clk/tegra/clk-tegra124-emc.c | 1 +
drivers/clk/tegra/clk-tegra210.c | 12 +-
drivers/clk/ti/adpll.c | 4 +-
drivers/clk/ti/divider.c | 2 +-
drivers/clk/ti/mux.c | 22 +-
drivers/clk/visconti/clkc.c | 2 +-
drivers/clk/x86/clk-pmc-atom.c | 3 +
drivers/clocksource/clps711x-timer.c | 2 +-
drivers/clocksource/timer-armada-370-xp.c | 30 +-
drivers/cpufreq/Kconfig.x86 | 14 +
drivers/cpufreq/amd-pstate-ut.c | 5 +
drivers/cpufreq/amd-pstate.c | 463 ++++-
drivers/cpufreq/amd-pstate.h | 17 +-
drivers/cpufreq/imx6q-cpufreq.c | 6 +-
drivers/cpufreq/intel_pstate.c | 19 +-
drivers/cpufreq/spear-cpufreq.c | 4 +-
drivers/cpuidle/cpuidle-psci.c | 12 +-
drivers/crypto/atmel-ecc.c | 3 +
drivers/crypto/atmel-sha204a.c | 6 +-
drivers/crypto/ccp/sev-dev.c | 17 +-
drivers/crypto/gemini/sl3516-ce-cipher.c | 8 -
drivers/crypto/hisilicon/sec2/sec_crypto.c | 12 +-
.../crypto/intel/keembay/keembay-ocs-aes-core.c | 9 +-
drivers/crypto/intel/qat/qat_common/adf_aer.c | 2 +
drivers/crypto/intel/qat/qat_common/adf_cfg.c | 10 +-
.../crypto/intel/qat/qat_common/adf_cfg_common.h | 1 -
.../crypto/intel/qat/qat_common/adf_cfg_services.c | 2 +-
.../crypto/intel/qat/qat_common/adf_mstate_mgr.c | 3 +-
.../intel/qat/qat_common/adf_transport_debug.c | 3 +-
drivers/crypto/intel/qat/qat_common/qat_algs.c | 1 +
.../crypto/intel/qat/qat_common/qat_compression.c | 3 +-
drivers/crypto/rockchip/rk3288_crypto_ahash.c | 7 +-
drivers/crypto/sa2ul.c | 6 +-
drivers/crypto/xilinx/xilinx-trng.c | 32 +-
drivers/cxl/core/features.c | 12 +-
drivers/cxl/core/mbox.c | 11 +-
drivers/cxl/core/memdev.c | 2 +-
drivers/cxl/core/port.c | 4 +-
drivers/cxl/core/region.c | 7 +-
drivers/cxl/pci.c | 13 +-
drivers/dax/super.c | 12 +-
drivers/dma-buf/dma-heap.c | 80 +-
drivers/dma/dw-edma/dw-edma-core.c | 104 +-
drivers/dma/hisi_dma.c | 2 +-
drivers/dma/mediatek/mtk-uart-apdma.c | 2 +-
drivers/dma/qcom/bam_dma.c | 1 +
drivers/dma/xilinx/xilinx_dma.c | 12 +-
drivers/dma/xilinx/zynqmp_dma.c | 4 +-
drivers/firewire/.kunitconfig | 1 +
drivers/firewire/Kconfig | 15 +
drivers/firewire/core-topology.c | 62 +-
drivers/firewire/node-tree-test.c | 607 ++++++
drivers/firmware/arm_scmi/bus.c | 89 +-
drivers/firmware/arm_scmi/common.h | 2 +
drivers/firmware/arm_scmi/driver.c | 77 +-
drivers/firmware/arm_scmi/notify.c | 21 +
drivers/firmware/arm_scmi/notify.h | 1 +
drivers/firmware/arm_scmi/transports/mailbox.c | 26 +-
drivers/firmware/arm_scmi/transports/smc.c | 15 +-
drivers/firmware/google/coreboot_table.c | 26 +-
drivers/firmware/qcom/Makefile | 1 +
drivers/firmware/qcom/qcom_scm-smc.c | 12 +-
drivers/firmware/qcom/qcom_scm.c | 194 +-
drivers/firmware/qcom/qcom_scm.h | 3 +-
drivers/firmware/qcom/qcom_scm_trace.h | 143 ++
drivers/firmware/qcom/qcom_tzmem.c | 13 +-
drivers/gpio/gpio-mxc.c | 12 +-
drivers/gpio/gpio-pxa.c | 12 +-
drivers/gpio/gpio-sa1100.c | 12 +-
drivers/gpu/drm/amd/amdgpu/gfx_v6_0.c | 74 +-
drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c | 28 +-
drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.h | 7 +
.../gpu/drm/amd/display/dc/hubp/dcn10/dcn10_hubp.c | 3 +-
.../gpu/drm/amd/pm/powerplay/hwmgr/smu7_hwmgr.c | 24 +
.../gpu/drm/amd/pm/powerplay/hwmgr/vega10_hwmgr.c | 35 +-
drivers/gpu/drm/bridge/cadence/cdns-dsi-core.c | 2 +-
.../gpu/drm/bridge/cadence/cdns-mhdp8546-core.c | 2 +-
drivers/gpu/drm/bridge/display-connector.c | 36 +
drivers/gpu/drm/bridge/synopsys/dw-dp.c | 14 +-
drivers/gpu/drm/bridge/tc358767.c | 2 +-
drivers/gpu/drm/drm_dumb_buffers.c | 1 -
drivers/gpu/drm/lima/lima_device.c | 12 +-
drivers/gpu/drm/msm/adreno/a6xx_catalog.c | 2 +-
drivers/gpu/drm/msm/adreno/a6xx_gmu.c | 107 +-
drivers/gpu/drm/msm/adreno/a6xx_gmu.h | 20 +-
drivers/gpu/drm/msm/adreno/a6xx_gpu_state.c | 5 +-
drivers/gpu/drm/msm/adreno/a6xx_gpu_state.h | 68 +-
drivers/gpu/drm/msm/disp/dpu1/dpu_core_perf.c | 4 +
drivers/gpu/drm/msm/disp/dpu1/dpu_encoder.c | 3 +-
drivers/gpu/drm/msm/disp/mdp4/mdp4_kms.c | 22 +-
drivers/gpu/drm/msm/disp/mdp5/mdp5_kms.c | 11 +-
drivers/gpu/drm/msm/dp/dp_ctrl.c | 5 +-
drivers/gpu/drm/msm/dp/dp_display.c | 28 +-
drivers/gpu/drm/msm/dp/dp_panel.c | 4 +-
drivers/gpu/drm/msm/dsi/dsi_host.c | 2 -
drivers/gpu/drm/msm/dsi/phy/dsi_phy.h | 1 +
drivers/gpu/drm/msm/dsi/phy/dsi_phy_7nm.c | 18 +-
drivers/gpu/drm/msm/msm_drv.h | 8 -
drivers/gpu/drm/msm/msm_gem_vma.c | 2 +
drivers/gpu/drm/msm/msm_gpu.c | 6 +-
drivers/gpu/drm/msm/msm_ringbuffer.c | 7 +-
drivers/gpu/drm/msm/msm_ringbuffer.h | 1 +
drivers/gpu/drm/msm/registers/adreno/a6xx_gmu.xml | 248 +--
drivers/gpu/drm/mxsfb/lcdif_kms.c | 15 +-
drivers/gpu/drm/omapdrm/dss/dsi.c | 7 +-
drivers/gpu/drm/omapdrm/dss/dsi.h | 2 -
drivers/gpu/drm/panel/panel-samsung-s6d16d0.c | 10 +-
drivers/gpu/drm/panthor/panthor_drv.c | 2 +-
drivers/gpu/drm/rockchip/analogix_dp-rockchip.c | 22 +-
drivers/gpu/drm/rockchip/dw_dp-rockchip.c | 45 +-
drivers/gpu/drm/rockchip/rockchip_drm_vop2.c | 5 +-
drivers/gpu/drm/rockchip/rockchip_vop2_reg.c | 21 +-
drivers/gpu/drm/sun4i/sun4i_crtc.c | 2 +-
drivers/gpu/drm/sun4i/sun4i_hdmi_enc.c | 2 +-
drivers/gpu/drm/sun4i/sun4i_tcon.c | 22 +-
drivers/gpu/drm/sun4i/sun8i_dw_hdmi.c | 2 +
drivers/gpu/drm/sun4i/sun8i_hdmi_phy.c | 2 +-
drivers/gpu/drm/sun4i/sun8i_vi_scaler.c | 18 +-
drivers/gpu/drm/tve200/tve200_drv.c | 1 +
drivers/gpu/drm/v3d/v3d_sched.c | 60 +-
drivers/gpu/drm/xe/tests/xe_migrate.c | 3 +-
drivers/gpu/drm/xe/xe_gt_idle.c | 3 +-
drivers/gpu/host1x/debug.c | 4 +-
drivers/gpu/host1x/hw/channel_hw.c | 5 +-
drivers/hid/hid-core.c | 9 +
drivers/hid/hid-haptic.c | 2 +-
drivers/hid/hid-lg4ff.c | 8 +
drivers/hid/hid-multitouch.c | 2 +-
drivers/hid/hid-nintendo.c | 1 -
drivers/hid/hid-roccat-kone.c | 8 +-
drivers/hid/hid-steam.c | 516 +++--
drivers/hid/i2c-hid/Makefile | 2 +-
drivers/hid/i2c-hid/i2c-hid-acpi-prp0001.c | 104 +
drivers/hid/i2c-hid/i2c-hid-acpi.c | 54 +-
drivers/hid/i2c-hid/i2c-hid-acpi.h | 33 +
drivers/hid/i2c-hid/i2c-hid-core.c | 2 +-
drivers/hid/i2c-hid/i2c-hid-of-goodix.c | 4 +-
drivers/hv/vmbus_drv.c | 29 +-
drivers/hwmon/coretemp.c | 1 +
drivers/hwmon/cros_ec_hwmon.c | 121 +-
drivers/hwmon/emc1403.c | 73 +-
drivers/hwspinlock/hwspinlock_core.c | 2 +-
drivers/hwtracing/coresight/coresight-etm4x-cfg.c | 2 +-
drivers/hwtracing/coresight/coresight-etm4x-core.c | 111 +-
.../hwtracing/coresight/coresight-etm4x-sysfs.c | 6 +-
drivers/hwtracing/coresight/coresight-etm4x.h | 63 +-
drivers/i2c/busses/i2c-ocores.c | 6 +-
drivers/i2c/busses/i2c-qcom-cci.c | 24 +-
drivers/i3c/master.c | 63 +-
drivers/i3c/master/adi-i3c-master.c | 1 +
drivers/i3c/master/dw-i3c-master.c | 10 +-
drivers/i3c/master/renesas-i3c.c | 28 +-
drivers/idle/intel_idle.c | 194 +-
drivers/iio/accel/dmard09.c | 7 +
drivers/iio/light/apds9306.c | 8 +-
drivers/iio/light/gp2ap002.c | 14 +-
drivers/iio/light/isl29028.c | 2 +-
drivers/iio/light/opt4060.c | 4 +-
drivers/iio/light/tsl2583.c | 2 +-
drivers/iio/light/tsl2772.c | 2 +-
drivers/iio/orientation/hid-sensor-rotation.c | 20 +-
drivers/infiniband/core/cma.c | 6 +-
drivers/infiniband/core/counters.c | 5 +-
drivers/infiniband/core/cq.c | 2 +-
drivers/infiniband/core/device.c | 2 +
drivers/infiniband/core/nldev.c | 20 +-
drivers/infiniband/core/restrack.c | 174 +-
drivers/infiniband/core/restrack.h | 4 +
drivers/infiniband/core/ucma.c | 2 +-
drivers/infiniband/core/uverbs_cmd.c | 10 +-
drivers/infiniband/core/uverbs_std_types_device.c | 42 +
drivers/infiniband/core/uverbs_std_types_dmah.c | 7 +-
drivers/infiniband/core/verbs.c | 83 +-
drivers/infiniband/hw/bnxt_re/ib_verbs.c | 6 +-
drivers/infiniband/hw/cxgb4/device.c | 2 +-
drivers/infiniband/hw/cxgb4/mem.c | 4 +-
drivers/infiniband/hw/efa/efa_verbs.c | 15 +-
drivers/infiniband/hw/erdma/Kconfig | 2 +-
drivers/infiniband/hw/erdma/erdma_cm.c | 6 +-
drivers/infiniband/hw/erdma/erdma_eq.c | 10 +-
drivers/infiniband/hw/erdma/erdma_verbs.c | 39 +-
drivers/infiniband/hw/erdma/erdma_verbs.h | 40 +-
drivers/infiniband/hw/hfi1/chip.c | 4 +-
drivers/infiniband/hw/hfi1/hfi.h | 2 -
drivers/infiniband/hw/hfi1/init.c | 44 +-
drivers/infiniband/hw/hfi1/user_sdma.c | 13 +-
drivers/infiniband/hw/irdma/utils.c | 6 +
drivers/infiniband/hw/irdma/verbs.c | 116 +-
drivers/infiniband/hw/irdma/verbs.h | 3 +
drivers/infiniband/hw/mana/qp.c | 10 +-
drivers/infiniband/hw/mlx5/cong.c | 8 +-
drivers/infiniband/hw/mlx5/main.c | 127 ++
drivers/infiniband/hw/mlx5/mlx5_ib.h | 2 +
drivers/infiniband/hw/mlx5/qp.c | 25 +-
drivers/infiniband/sw/rxe/rxe_odp.c | 1 +
drivers/infiniband/sw/rxe/rxe_req.c | 15 +
drivers/infiniband/sw/rxe/rxe_resp.c | 9 +-
drivers/infiniband/sw/siw/siw_cm.c | 2 +-
drivers/infiniband/ulp/ipoib/ipoib_main.c | 2 +
drivers/infiniband/ulp/isert/ib_isert.c | 85 +-
drivers/infiniband/ulp/isert/ib_isert.h | 1 +
drivers/infiniband/ulp/srp/ib_srp.c | 45 +-
drivers/infiniband/ulp/srpt/ib_srpt.c | 9 +-
drivers/iommu/amd/debugfs.c | 12 +-
drivers/iommu/amd/init.c | 58 +-
drivers/iommu/amd/ppr.c | 2 +-
drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c | 9 +-
drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c | 119 +-
drivers/iommu/arm/arm-smmu/qcom_iommu.c | 6 +-
drivers/iommu/dma-iommu.c | 26 +-
drivers/iommu/intel/iommu.c | 31 +-
drivers/iommu/intel/iommu.h | 2 +-
drivers/iommu/intel/pasid.c | 9 +-
drivers/iommu/iommufd/device.c | 13 +-
drivers/iommu/iommufd/iommufd_private.h | 9 +-
drivers/iommu/iommufd/main.c | 20 +
drivers/iommu/iommufd/selftest.c | 5 +-
drivers/iommu/msm_iommu.c | 2 +-
drivers/iommu/mtk_iommu_v1.c | 2 +-
drivers/ipack/devices/ipoctal.c | 56 +-
drivers/irqchip/exynos-combiner.c | 14 +-
drivers/irqchip/irq-armada-370-xp.c | 12 +-
drivers/irqchip/irq-bcm7038-l1.c | 12 +-
drivers/irqchip/irq-gic-v3-its.c | 35 +-
drivers/irqchip/irq-gic-v5-irs.c | 2 +-
drivers/irqchip/irq-gic-v5.c | 11 +-
drivers/irqchip/irq-i8259.c | 12 +-
drivers/irqchip/irq-imx-gpcv2.c | 16 +-
drivers/irqchip/irq-loongson-eiointc.c | 12 +-
drivers/irqchip/irq-loongson-htpic.c | 10 +-
drivers/irqchip/irq-loongson-htvec.c | 12 +-
drivers/irqchip/irq-loongson-pch-lpc.c | 12 +-
drivers/irqchip/irq-loongson-pch-pic.c | 12 +-
drivers/irqchip/irq-mchp-eic.c | 12 +-
drivers/irqchip/irq-mst-intc.c | 12 +-
drivers/irqchip/irq-mtk-cirq.c | 12 +-
drivers/irqchip/irq-realtek-rtl.c | 189 +-
drivers/irqchip/irq-renesas-irqc.c | 1 +
drivers/irqchip/irq-renesas-rzg2l.c | 16 +-
drivers/irqchip/irq-sa11x0.c | 12 +-
drivers/irqchip/irq-sifive-plic.c | 12 +-
drivers/irqchip/irq-sun6i-r.c | 18 +-
drivers/irqchip/irq-tegra.c | 12 +-
drivers/irqchip/irq-vic.c | 12 +-
drivers/leds/leds-gpio.c | 53 +-
drivers/leds/leds-pca9532.c | 18 +-
drivers/leds/leds-st1202.c | 96 +-
drivers/leds/trigger/ledtrig-cpu.c | 14 +-
drivers/macintosh/via-pmu.c | 12 +-
drivers/mailbox/pcc.c | 41 +-
drivers/mailbox/qcom-cpucp-mbox.c | 25 +-
drivers/mailbox/riscv-sbi-mpxy-mbox.c | 12 +-
drivers/mailbox/rockchip-mailbox.c | 17 +-
drivers/md/dm-integrity.c | 139 +-
drivers/md/dm-pcache/cache.c | 7 +
drivers/md/dm-pcache/cache.h | 3 +
drivers/md/dm-pcache/cache_gc.c | 5 +
drivers/md/dm-pcache/cache_key.c | 83 +
drivers/md/dm-pcache/cache_writeback.c | 8 +
drivers/md/md-bitmap.c | 5 +-
drivers/md/md-bitmap.h | 1 +
drivers/md/md-llbitmap.c | 20 +-
drivers/md/md.c | 109 +-
drivers/md/md.h | 1 -
drivers/md/raid1.c | 2 -
drivers/md/raid10.c | 14 +-
drivers/md/raid5-ppl.c | 4 +-
drivers/md/raid5.c | 87 +-
drivers/media/cec/core/cec-pin.c | 8 +-
drivers/media/i2c/rdacm21.c | 5 +-
drivers/media/pci/intel/ipu6/ipu6.c | 10 +-
drivers/media/platform/broadcom/bcm2835-unicam.c | 2 +
drivers/media/platform/qcom/iris/iris_core.c | 12 +-
drivers/media/platform/qcom/iris/iris_state.c | 2 +-
drivers/media/v4l2-core/v4l2-async.c | 15 +-
drivers/mfd/iqs62x.c | 2 +-
drivers/mfd/macsmc.c | 8 +-
drivers/mfd/rave-sp.c | 64 +-
drivers/misc/ad525x_dpot-i2c.c | 1 +
drivers/misc/ad525x_dpot-spi.c | 1 +
drivers/misc/ad525x_dpot.c | 177 +-
drivers/misc/ad525x_dpot.h | 3 +
drivers/misc/bcm-vk/bcm_vk_msg.c | 6 +-
drivers/misc/cardreader/rtsx_pcr.c | 2 +
drivers/misc/cardreader/rtsx_usb.c | 26 +-
drivers/misc/fastrpc.c | 16 +-
drivers/misc/lan966x_pci.c | 1 +
drivers/misc/pci_endpoint_test.c | 11 +-
drivers/misc/sgi-gru/grufault.c | 101 +-
drivers/misc/sgi-gru/gruprocfs.c | 1 -
drivers/misc/sgi-gru/grutables.h | 1 -
drivers/misc/vmw_vmci/vmci_event.c | 4 +-
drivers/mtd/devices/mtd_intel_dg.c | 76 +-
drivers/mtd/mtdpart.c | 3 +-
drivers/mtd/mtdswap.c | 1 +
drivers/mtd/nand/raw/pl35x-nand-controller.c | 10 +-
drivers/mtd/ubi/attach.c | 4 +-
drivers/mtd/ubi/build.c | 11 +-
drivers/mtd/ubi/fastmap.c | 6 +-
drivers/mtd/ubi/io.c | 11 +-
drivers/mtd/ubi/ubi.h | 4 +-
drivers/mtd/ubi/wl.c | 15 +-
drivers/net/amt.c | 3 +
drivers/net/bonding/bond_netlink.c | 2 +-
drivers/net/dsa/b53/b53_common.c | 2 +-
drivers/net/dsa/mv88e6xxx/pcs-6352.c | 5 +-
drivers/net/ethernet/airoha/airoha_npu.c | 2 +-
drivers/net/ethernet/allwinner/sun4i-emac.c | 4 +-
drivers/net/ethernet/broadcom/bnxt/bnxt.c | 8 +-
drivers/net/ethernet/broadcom/bnxt/bnxt_hwmon.c | 2 +-
drivers/net/ethernet/freescale/enetc/enetc.c | 72 +-
drivers/net/ethernet/freescale/enetc/enetc.h | 9 +
drivers/net/ethernet/freescale/enetc/enetc_pf.c | 14 +-
drivers/net/ethernet/freescale/fec_main.c | 6 +-
drivers/net/ethernet/huawei/hinic3/hinic3_tx.c | 9 +-
drivers/net/ethernet/intel/ice/devlink/devlink.c | 32 +-
drivers/net/ethernet/intel/ice/ice_ethtool.c | 66 +-
drivers/net/ethernet/intel/ice/ice_flex_pipe.c | 8 +-
drivers/net/ethernet/intel/ice/ice_lag.c | 3 +-
drivers/net/ethernet/intel/ice/ice_lib.c | 3 +
drivers/net/ethernet/intel/ice/ice_main.c | 10 +-
drivers/net/ethernet/intel/ice/ice_nvm.c | 90 +-
drivers/net/ethernet/intel/ice/ice_nvm.h | 2 +-
drivers/net/ethernet/intel/ice/ice_ptp.c | 6 +-
drivers/net/ethernet/intel/ice/ice_ptp_hw.c | 38 +-
drivers/net/ethernet/intel/ice/ice_sriov.c | 3 +-
drivers/net/ethernet/intel/idpf/idpf_txrx.c | 2 +-
drivers/net/ethernet/intel/igc/igc_main.c | 3 +-
.../net/ethernet/marvell/octeontx2/af/mcs_rvu_if.c | 2 +-
.../ethernet/marvell/octeontx2/af/rvu_debugfs.c | 6 +
.../net/ethernet/marvell/octeontx2/af/rvu_nix.c | 11 +-
.../ethernet/marvell/octeontx2/nic/otx2_common.c | 6 +-
.../ethernet/marvell/octeontx2/nic/otx2_ethtool.c | 3 +-
.../net/ethernet/marvell/octeontx2/nic/otx2_vf.c | 20 +-
.../net/ethernet/marvell/octeontx2/nic/otx2_xsk.c | 3 +-
.../net/ethernet/mellanox/mlx5/core/en/xsk/tx.c | 2 +-
drivers/net/ethernet/mellanox/mlx5/core/en_rep.c | 20 +-
drivers/net/ethernet/mellanox/mlx5/core/en_rx.c | 39 +-
drivers/net/ethernet/mellanox/mlx5/core/en_txrx.c | 2 +-
.../ethernet/mellanox/mlx5/core/esw/adj_vport.c | 37 +-
drivers/net/ethernet/mellanox/mlx5/core/eswitch.c | 21 +
drivers/net/ethernet/mellanox/mlx5/core/eswitch.h | 7 +
.../ethernet/mellanox/mlx5/core/eswitch_offloads.c | 211 +-
drivers/net/ethernet/mellanox/mlx5/core/fs_core.c | 5 +
drivers/net/ethernet/mellanox/mlx5/core/lag/lag.c | 222 ++
drivers/net/ethernet/mellanox/mlx5/core/lag/lag.h | 11 +
.../net/ethernet/mellanox/mlx5/core/lag/mpesw.c | 39 +
.../net/ethernet/mellanox/mlx5/core/lag/mpesw.h | 14 +
drivers/net/ethernet/mellanox/mlx5/core/lib/mpfs.c | 116 +-
drivers/net/ethernet/mellanox/mlx5/core/lib/mpfs.h | 9 +
.../net/ethernet/mellanox/mlx5/core/mlx5_core.h | 1 +
drivers/net/ethernet/mellanox/mlx5/core/port.c | 24 +
drivers/net/ethernet/mellanox/mlx5/core/vport.c | 102 +
drivers/net/ethernet/nvidia/forcedeth.c | 2 +-
drivers/net/ethernet/pensando/ionic/ionic_txrx.c | 27 +-
drivers/net/ethernet/qlogic/qlcnic/qlcnic_init.c | 467 +++--
.../net/ethernet/qualcomm/rmnet/rmnet_map_data.c | 1 +
drivers/net/ethernet/realtek/8139cp.c | 2 +-
.../net/ethernet/stmicro/stmmac/dwmac1000_core.c | 2 +-
drivers/net/ethernet/stmicro/stmmac/dwmac4_core.c | 2 +-
.../net/ethernet/stmicro/stmmac/dwxgmac2_core.c | 2 +-
drivers/net/ethernet/stmicro/stmmac/stmmac_main.c | 11 +-
.../net/ethernet/stmicro/stmmac/stmmac_selftests.c | 41 +-
drivers/net/ethernet/wangxun/libwx/wx_ethtool.c | 61 +-
drivers/net/ethernet/wangxun/libwx/wx_hw.c | 71 +-
drivers/net/ethernet/wangxun/libwx/wx_lib.c | 99 +-
drivers/net/ethernet/wangxun/libwx/wx_ptp.c | 18 +-
drivers/net/ethernet/wangxun/libwx/wx_sriov.c | 6 +-
drivers/net/ethernet/wangxun/libwx/wx_type.h | 52 +-
drivers/net/ethernet/wangxun/libwx/wx_vf.h | 1 +
drivers/net/ethernet/wangxun/libwx/wx_vf_common.c | 14 +-
drivers/net/ethernet/wangxun/libwx/wx_vf_lib.c | 3 +
drivers/net/ethernet/wangxun/ngbe/ngbe_ethtool.c | 6 +-
drivers/net/ethernet/wangxun/ngbe/ngbe_main.c | 48 +-
drivers/net/ethernet/wangxun/txgbe/txgbe_ethtool.c | 6 +-
drivers/net/ethernet/wangxun/txgbe/txgbe_irq.c | 7 +-
drivers/net/ethernet/wangxun/txgbe/txgbe_main.c | 19 +-
drivers/net/ethernet/wangxun/txgbe/txgbe_type.h | 2 +-
.../net/ethernet/wangxun/txgbevf/txgbevf_main.c | 11 +
drivers/net/gtp.c | 2 +
drivers/net/ipa/ipa_main.c | 6 +-
drivers/net/netdevsim/netdev.c | 2 +
drivers/net/ppp/pppox.c | 17 +
drivers/net/slip/slip.c | 8 -
drivers/net/thunderbolt/main.c | 6 +-
drivers/net/vxlan/vxlan_mdb.c | 9 +-
drivers/net/vxlan/vxlan_vnifilter.c | 6 +-
drivers/net/wireless/ath/ath10k/snoc.c | 9 +-
drivers/net/wireless/ath/ath11k/dp_rx.c | 32 +-
drivers/net/wireless/ath/ath11k/wmi.c | 40 +-
drivers/net/wireless/ath/ath12k/ahb.c | 18 +-
drivers/net/wireless/ath/ath12k/core.c | 27 +-
drivers/net/wireless/ath/ath12k/core.h | 2 -
drivers/net/wireless/ath/ath12k/qmi.c | 168 +-
drivers/net/wireless/ath/ath12k/wmi.c | 28 +-
drivers/net/wireless/ath/ath6kl/wmi.c | 17 +-
drivers/net/wireless/intel/iwlwifi/fw/dump.c | 2 +-
drivers/net/wireless/intel/iwlwifi/iwl-dbg-tlv.c | 8 +-
drivers/net/wireless/intel/iwlwifi/mei/main.c | 8 +-
drivers/net/wireless/intel/iwlwifi/mvm/ops.c | 2 +-
drivers/net/wireless/mediatek/mt76/Kconfig | 4 +
drivers/net/wireless/mediatek/mt76/Makefile | 5 +
drivers/net/wireless/mediatek/mt76/dma.c | 125 +-
drivers/net/wireless/mediatek/mt76/dma.h | 69 +-
drivers/net/wireless/mediatek/mt76/mac80211.c | 14 +-
drivers/net/wireless/mediatek/mt76/mcu.c | 12 +-
drivers/net/wireless/mediatek/mt76/mt76.h | 138 ++
drivers/net/wireless/mediatek/mt76/mt76_connac.h | 13 +-
drivers/net/wireless/mediatek/mt76/mt76x02_mac.c | 2 +-
drivers/net/wireless/mediatek/mt76/mt7915/eeprom.c | 2 +-
drivers/net/wireless/mediatek/mt76/mt7915/init.c | 9 +-
drivers/net/wireless/mediatek/mt76/mt7915/mac.c | 6 +-
drivers/net/wireless/mediatek/mt76/mt7915/main.c | 24 +-
drivers/net/wireless/mediatek/mt76/mt7915/mcu.c | 10 +-
drivers/net/wireless/mediatek/mt76/mt7915/mcu.h | 6 +-
drivers/net/wireless/mediatek/mt76/mt7915/mt7915.h | 18 +
drivers/net/wireless/mediatek/mt76/mt7915/pci.c | 9 +-
drivers/net/wireless/mediatek/mt76/mt7915/soc.c | 2 +-
.../net/wireless/mediatek/mt76/mt7915/testmode.c | 5 +-
drivers/net/wireless/mediatek/mt76/mt7921/mac.c | 3 +
drivers/net/wireless/mediatek/mt76/mt7921/mcu.c | 28 +-
drivers/net/wireless/mediatek/mt76/mt7921/pci.c | 103 +
drivers/net/wireless/mediatek/mt76/mt7925/main.c | 40 +-
drivers/net/wireless/mediatek/mt76/mt7925/mcu.c | 2 +-
.../net/wireless/mediatek/mt76/mt7996/debugfs.c | 74 +-
drivers/net/wireless/mediatek/mt76/mt7996/init.c | 18 +-
drivers/net/wireless/mediatek/mt76/mt7996/mac.c | 55 +-
drivers/net/wireless/mediatek/mt76/mt7996/main.c | 60 +-
drivers/net/wireless/mediatek/mt76/mt7996/mcu.c | 106 +-
drivers/net/wireless/mediatek/mt76/mt7996/mcu.h | 2 +-
drivers/net/wireless/mediatek/mt76/mt7996/mmio.c | 39 +-
drivers/net/wireless/mediatek/mt76/mt7996/mt7996.h | 26 +
drivers/net/wireless/mediatek/mt76/mt7996/regs.h | 24 +-
drivers/net/wireless/mediatek/mt76/npu.c | 502 +++++
drivers/net/wireless/mediatek/mt76/scan.c | 5 +
drivers/net/wireless/mediatek/mt76/sdio.c | 11 +-
drivers/net/wireless/mediatek/mt76/tx.c | 9 +-
drivers/net/wireless/realtek/rtlwifi/pci.c | 6 +-
drivers/net/wireless/realtek/rtw89/cam.c | 152 +-
drivers/net/wireless/realtek/rtw89/cam.h | 439 +---
drivers/net/wireless/realtek/rtw89/core.c | 52 +-
drivers/net/wireless/realtek/rtw89/core.h | 22 +-
drivers/net/wireless/realtek/rtw89/debug.c | 387 +++-
drivers/net/wireless/realtek/rtw89/fw.c | 58 +-
drivers/net/wireless/realtek/rtw89/fw.h | 9 +-
drivers/net/wireless/realtek/rtw89/mac.c | 6 +-
drivers/net/wireless/realtek/rtw89/mac.h | 2 -
drivers/net/wireless/realtek/rtw89/mac80211.c | 40 +-
drivers/net/wireless/realtek/rtw89/pci.c | 29 +
drivers/net/wireless/realtek/rtw89/pci.h | 1 +
drivers/net/wireless/realtek/rtw89/phy.c | 17 +-
drivers/net/wireless/realtek/rtw89/rtw8851be.c | 1 +
drivers/net/wireless/realtek/rtw89/rtw8852a.c | 7 +-
drivers/net/wireless/realtek/rtw89/rtw8852ae.c | 1 +
drivers/net/wireless/realtek/rtw89/rtw8852be.c | 1 +
drivers/net/wireless/realtek/rtw89/rtw8852bte.c | 1 +
drivers/net/wireless/realtek/rtw89/rtw8852ce.c | 1 +
drivers/net/wireless/realtek/rtw89/rtw8922ae.c | 1 +
drivers/net/wireless/realtek/rtw89/wow.c | 6 +-
drivers/net/wireless/virtual/mac80211_hwsim.c | 5 +-
drivers/net/wireless/zydas/zd1211rw/zd_usb.c | 8 +
drivers/nfc/pn533/pn533.c | 21 +-
drivers/nvdimm/label.c | 15 +-
drivers/nvdimm/nd_virtio.c | 121 +-
drivers/nvdimm/pmem.c | 15 +-
drivers/nvdimm/region_devs.c | 5 +-
drivers/nvdimm/virtio_pmem.c | 17 +-
drivers/nvdimm/virtio_pmem.h | 6 +
drivers/nvme/host/apple.c | 63 +-
drivers/nvme/host/core.c | 79 +-
drivers/nvme/host/fabrics.h | 6 +
drivers/nvme/host/fc.c | 7 +
drivers/nvme/host/ioctl.c | 117 +-
drivers/nvme/host/nvme.h | 68 +
drivers/nvme/host/pci.c | 29 +-
drivers/nvme/host/rdma.c | 1 +
drivers/nvme/host/sysfs.c | 23 +
drivers/nvme/host/tcp.c | 1 +
drivers/nvme/target/core.c | 3 +-
drivers/nvme/target/fabrics-cmd-auth.c | 12 +-
drivers/nvme/target/loop.c | 1 +
drivers/nvme/target/pr.c | 27 +-
drivers/nvme/target/rdma.c | 31 +-
drivers/nvme/target/zns.c | 2 +-
drivers/pci/controller/cadence/pci-j721e.c | 4 +-
drivers/pci/controller/pci-xgene.c | 5 +-
drivers/pci/controller/plda/pcie-starfive.c | 10 +-
drivers/pci/hotplug/pnv_php.c | 2 +-
drivers/pci/hotplug/rpaphp_slot.c | 2 +-
drivers/pci/pci.c | 5 +-
drivers/pci/pcie/aspm.c | 19 +-
drivers/pci/slot.c | 67 +-
drivers/perf/arm_pmuv3.c | 2 +-
drivers/perf/arm_spe_pmu.c | 2 +-
drivers/perf/cxl_pmu.c | 2 +-
drivers/phy/qualcomm/phy-qcom-qmp-combo.c | 736 ++++++-
drivers/phy/qualcomm/phy-qcom-qmp-dp-phy-v8.h | 25 +
.../phy/qualcomm/phy-qcom-qmp-dp-qserdes-com-v8.h | 52 +
drivers/phy/qualcomm/phy-qcom-qmp-pcie.c | 1 +
drivers/phy/qualcomm/phy-qcom-qmp-pcs-aon-v6.h | 12 +
drivers/phy/qualcomm/phy-qcom-qmp-pcs-aon-v8.h | 17 +
drivers/phy/qualcomm/phy-qcom-qmp-pcs-misc-v5.h | 12 +
drivers/phy/qualcomm/phy-qcom-qmp-pcs-misc-v8.h | 12 +
.../phy/qualcomm/phy-qcom-qmp-qserdes-lalb-v8.h | 639 ++++++
drivers/phy/qualcomm/phy-qcom-qmp-usb-legacy.c | 12 +-
drivers/phy/qualcomm/phy-qcom-qmp-usb.c | 12 +-
drivers/phy/qualcomm/phy-qcom-qmp-usb43-pcs-v8.h | 33 +
.../qualcomm/phy-qcom-qmp-usb43-qserdes-com-v8.h | 224 ++
drivers/phy/qualcomm/phy-qcom-qmp.h | 2 +
drivers/phy/qualcomm/phy-qcom-sgmii-eth.c | 43 +-
drivers/phy/qualcomm/phy-qcom-snps-femto-v2.c | 26 +-
drivers/phy/renesas/Kconfig | 1 +
drivers/phy/renesas/phy-rcar-gen3-usb2.c | 187 +-
drivers/phy/rockchip/phy-rockchip-inno-csidphy.c | 2 +-
drivers/phy/starfive/phy-jh7110-dphy-rx.c | 5 +-
drivers/phy/starfive/phy-jh7110-dphy-tx.c | 5 +-
drivers/phy/sunplus/phy-sunplus-usb2.c | 6 +-
drivers/pinctrl/bcm/pinctrl-bcm2835.c | 1 -
drivers/pinctrl/mediatek/mtk-eint.c | 25 +-
drivers/pinctrl/mediatek/pinctrl-airoha.c | 2198 +++++++++++---------
drivers/pinctrl/pinctrl-eic7700.c | 3 +
drivers/pinctrl/pinctrl-rockchip.c | 10 +
drivers/pinctrl/spacemit/pinctrl-k1.c | 10 +-
drivers/platform/chrome/cros_ec_debugfs.c | 6 +-
drivers/platform/chrome/cros_ec_sensorhub_ring.c | 9 +-
drivers/platform/chrome/cros_ec_typec.c | 6 +
drivers/platform/mellanox/mlxbf-bootctl.c | 1 +
drivers/platform/mellanox/mlxbf-pmc.c | 10 +-
drivers/platform/surface/surface_acpi_notify.c | 6 +-
drivers/platform/x86/acer-wmi.c | 4 +-
drivers/platform/x86/amd/hsmp/hwmon.c | 3 +
drivers/platform/x86/amd/pmc/mp1_stb.c | 23 +-
drivers/platform/x86/dell/dell-wmi-base.c | 17 +-
drivers/platform/x86/dell/dell-wmi-privacy.c | 4 +-
.../x86/dell/dell-wmi-sysman/dell-wmi-sysman.h | 2 +-
.../x86/hp/hp-bioscfg/passwdobj-attributes.c | 5 +
drivers/platform/x86/hp/hp-wmi.c | 4 +
drivers/platform/x86/intel/int1092/intel_sar.c | 39 +-
.../x86/intel/speed_select_if/isst_tpmi_core.c | 14 +-
drivers/platform/x86/lg-laptop.c | 79 +-
drivers/pmdomain/bcm/bcm2835-power.c | 7 +-
drivers/power/reset/sc27xx-poweroff.c | 10 +-
drivers/power/supply/bd99954-charger.h | 23 +-
drivers/power/supply/bq27xxx_battery.c | 6 +-
drivers/power/supply/isp1704_charger.c | 1 +
drivers/power/supply/sbs-battery.c | 7 +-
drivers/power/supply/sc2731_charger.c | 2 +
drivers/powercap/intel_rapl_tpmi.c | 5 +-
drivers/pps/clients/pps-gpio.c | 66 +-
drivers/pps/pps.c | 10 +-
drivers/ptp/ptp_netc.c | 13 +-
drivers/rapidio/rio-scan.c | 1 +
drivers/regulator/adp5055-regulator.c | 2 +-
drivers/regulator/core.c | 6 +-
drivers/regulator/qcom-rpmh-regulator.c | 6 +-
drivers/regulator/tps6594-regulator.c | 19 +-
drivers/remoteproc/qcom_common.c | 4 +-
drivers/remoteproc/qcom_q6v5_adsp.c | 1 +
drivers/remoteproc/remoteproc_core.c | 156 +-
drivers/remoteproc/remoteproc_sysfs.c | 1 -
drivers/rpmsg/qcom_glink_native.c | 44 +-
drivers/rtc/rtc-gamecube.c | 4 +-
drivers/rtc/rtc-pcf85363.c | 17 +-
drivers/rtc/rtc-pcf8563.c | 4 +-
drivers/rtc/rtc-spacemit-p1.c | 5 +-
drivers/rtc/rtc-zynqmp.c | 7 +-
drivers/s390/block/dasd.c | 1 -
drivers/s390/block/dasd_eckd.c | 11 -
drivers/s390/block/dasd_ioctl.c | 6 +-
drivers/s390/char/con3270.c | 19 -
drivers/s390/char/fs3270.c | 7 +-
drivers/s390/char/sclp_ctl.c | 12 +-
drivers/s390/char/tape_char.c | 26 -
drivers/s390/char/vmcp.c | 7 +-
drivers/s390/cio/chsc_sch.c | 7 +-
drivers/s390/crypto/zcrypt_api.c | 195 --
drivers/s390/crypto/zcrypt_card.c | 1 -
drivers/s390/crypto/zcrypt_queue.c | 1 -
drivers/s390/net/qeth_core_main.c | 4 +-
drivers/scsi/ch.c | 4 +-
drivers/scsi/mpt3sas/mpt3sas_base.c | 2 +
drivers/scsi/qla2xxx/qla_attr.c | 1 -
drivers/scsi/qla2xxx/qla_nx2.c | 2 +-
drivers/scsi/scsi_sysfs.c | 77 +-
drivers/scsi/sd.c | 297 ++-
drivers/scsi/ses.c | 4 +-
drivers/scsi/smartpqi/smartpqi_init.c | 18 +
drivers/scsi/sr.c | 4 +-
drivers/scsi/st.c | 4 +-
drivers/sh/clk/core.c | 10 +-
drivers/sh/intc/core.c | 12 +-
drivers/soc/bcm/brcmstb/biuctrl.c | 12 +-
drivers/soc/fsl/qe/gpio.c | 25 +
drivers/soc/fsl/qe/qe_ic.c | 3 +-
drivers/soc/fsl/qe/qe_io.c | 15 +
drivers/soc/qcom/rpmh-rsc.c | 37 +-
drivers/soc/renesas/Kconfig | 1 -
drivers/soc/samsung/exynos-pmu.c | 4 +-
drivers/soc/tegra/pmc.c | 17 +-
drivers/soc/ti/knav_qmss.h | 1 +
drivers/soc/ti/knav_qmss_queue.c | 14 +-
drivers/soundwire/bus.c | 31 +
drivers/soundwire/qcom.c | 2 +-
drivers/spi/spi-amlogic-spisg.c | 2 +-
drivers/spi/spi-davinci.c | 7 +-
drivers/spi/spi-geni-qcom.c | 17 +-
drivers/spi/spi-img-spfi.c | 5 +-
drivers/spi/spi-oc-tiny.c | 24 +-
drivers/spi/spi-sprd-adi.c | 6 +
drivers/staging/fbtft/fbtft-sysfs.c | 2 +-
drivers/staging/gpib/common/gpib_os.c | 21 +-
drivers/staging/gpib/common/iblib.c | 3 -
drivers/staging/greybus/audio_gb.c | 13 +
drivers/staging/greybus/audio_manager_sysfs.c | 2 +-
drivers/staging/media/ipu7/ipu7-isys.c | 1 +
drivers/staging/media/ipu7/ipu7.c | 4 +-
drivers/staging/octeon/ethernet-mem.c | 43 +-
drivers/staging/octeon/ethernet-mem.h | 8 +-
drivers/staging/octeon/ethernet-rx.c | 53 +-
drivers/staging/octeon/ethernet-rx.h | 13 +-
drivers/staging/octeon/ethernet-tx.c | 2 +
drivers/staging/octeon/ethernet.c | 43 +-
drivers/staging/octeon/octeon-ethernet.h | 14 +
drivers/staging/rtl8723bs/core/rtw_ap.c | 8 +-
drivers/staging/rtl8723bs/core/rtw_cmd.c | 89 +-
drivers/staging/rtl8723bs/core/rtw_efuse.c | 1 -
drivers/staging/rtl8723bs/core/rtw_ioctl_set.c | 1 -
drivers/staging/rtl8723bs/core/rtw_mlme.c | 29 +-
drivers/staging/rtl8723bs/core/rtw_mlme_ext.c | 106 +-
drivers/staging/rtl8723bs/core/rtw_recv.c | 27 +-
drivers/staging/rtl8723bs/core/rtw_security.c | 159 +-
drivers/staging/rtl8723bs/core/rtw_wlan_util.c | 3 +-
drivers/staging/rtl8723bs/core/rtw_xmit.c | 97 +-
drivers/staging/rtl8723bs/hal/rtl8723bs_recv.c | 2 +-
drivers/staging/rtl8723bs/hal/sdio_ops.c | 2 +-
drivers/staging/rtl8723bs/include/basic_types.h | 1 +
drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c | 29 +-
drivers/staging/rtl8723bs/os_dep/os_intfs.c | 2 +-
drivers/staging/rtl8723bs/os_dep/osdep_service.c | 7 +-
drivers/staging/rtl8723bs/os_dep/sdio_intf.c | 4 +-
drivers/staging/rtl8723bs/os_dep/xmit_linux.c | 2 +-
drivers/staging/sm750fb/Kconfig | 1 +
drivers/staging/sm750fb/sm750.c | 6 +-
drivers/staging/sm750fb/sm750.h | 2 +-
drivers/staging/sm750fb/sm750_accel.c | 6 +-
drivers/staging/sm750fb/sm750_accel.h | 4 +-
drivers/thermal/airoha_thermal.c | 4 +-
.../intel/int340x_thermal/int3400_thermal.c | 4 +-
drivers/thermal/intel/intel_hfi.c | 12 +-
drivers/thermal/qcom/qcom-spmi-adc-tm5.c | 3 -
drivers/thermal/renesas/rcar_thermal.c | 15 +-
drivers/tty/hvc/Kconfig | 2 +-
drivers/tty/serial/8250/8250_core.c | 6 +
drivers/tty/serial/8250/8250_port.c | 21 +-
drivers/tty/serial/amba-pl011.c | 48 +-
drivers/tty/serial/bcm63xx_uart.c | 2 +-
drivers/tty/serial/ma35d1_serial.c | 12 +-
drivers/tty/serial/omap-serial.c | 2 +-
drivers/tty/serial/pch_uart.c | 2 +-
drivers/tty/serial/pxa.c | 2 +-
drivers/tty/serial/qcom_geni_serial.c | 10 +-
drivers/tty/serial/samsung_tty.c | 8 +-
drivers/tty/serial/serial_core.c | 21 +-
drivers/tty/serial/serial_txx9.c | 4 +-
drivers/tty/serial/sunsu.c | 2 +-
drivers/tty/tty_io.c | 4 +-
drivers/ufs/core/ufs-debugfs.c | 2 +-
drivers/ufs/core/ufshcd.c | 5 +-
drivers/uio/uio.c | 5 +
drivers/usb/atm/usbatm.c | 4 +-
drivers/usb/cdns3/cdnsp-gadget.c | 110 +-
drivers/usb/cdns3/cdnsp-gadget.h | 1 +
drivers/usb/cdns3/cdnsp-mem.c | 98 +-
drivers/usb/core/driver.c | 12 +-
drivers/usb/gadget/configfs.c | 4 +-
drivers/usb/gadget/function/f_fs.c | 8 +-
drivers/usb/gadget/function/f_mass_storage.c | 3 +
drivers/usb/gadget/function/f_uac1_legacy.c | 56 -
drivers/usb/gadget/function/u_uac1_legacy.h | 3 -
drivers/usb/gadget/udc/aspeed_udc.c | 50 +-
drivers/usb/gadget/udc/r8a66597-udc.c | 1 -
drivers/usb/misc/usb-ljca.c | 3 +
drivers/usb/mtu3/mtu3_core.c | 11 +-
drivers/usb/renesas_usbhs/common.c | 6 +-
drivers/usb/typec/ucsi/debugfs.c | 1 +
drivers/usb/typec/ucsi/ucsi.c | 2 +
drivers/usb/typec/ucsi/ucsi_huawei_gaokun.c | 68 +-
drivers/vdpa/mlx5/core/mr.c | 2 +-
drivers/vdpa/vdpa_sim/vdpa_sim.c | 25 +-
drivers/vfio/pci/vfio_pci_config.c | 1 +
drivers/vhost/net.c | 3 +-
drivers/video/fbdev/clps711x-fb.c | 2 -
drivers/video/fbdev/kyro/fbdev.c | 24 +-
drivers/video/fbdev/tdfxfb.c | 2 +-
drivers/virt/coco/arm-cca-guest/arm-cca-guest.c | 97 +-
drivers/virtio/virtio.c | 41 +-
drivers/virtio/virtio_balloon.c | 40 +-
drivers/virtio/virtio_pci_common.c | 2 +-
drivers/virtio/virtio_rtc_driver.c | 14 +-
drivers/w1/masters/ds2482.c | 4 +
drivers/xen/xen-acpi-processor.c | 12 +-
drivers/xen/xenbus/xenbus_xs.c | 16 +-
fs/btrfs/bio.c | 68 +-
fs/btrfs/bio.h | 5 +-
fs/btrfs/block-group.c | 3 +-
fs/btrfs/ctree.c | 3 +-
fs/btrfs/defrag.c | 50 +-
fs/btrfs/delayed-inode.c | 4 +-
fs/btrfs/disk-io.c | 51 +-
fs/btrfs/extent-io-tree.c | 10 +-
fs/btrfs/extent-tree.c | 10 +-
fs/btrfs/extent_io.c | 31 +-
fs/btrfs/extent_io.h | 23 +-
fs/btrfs/fiemap.c | 4 +-
fs/btrfs/file.c | 103 +-
fs/btrfs/free-space-tree.c | 4 +-
fs/btrfs/inode-item.c | 7 +-
fs/btrfs/inode.c | 13 +-
fs/btrfs/qgroup.c | 37 +-
fs/btrfs/relocation.c | 5 +-
fs/btrfs/verity.c | 16 +-
fs/btrfs/volumes.c | 9 +-
fs/ceph/dir.c | 2 +-
fs/ceph/file.c | 48 +
fs/erofs/Kconfig | 8 +-
fs/erofs/decompressor.c | 2 +-
fs/erofs/internal.h | 25 +-
fs/erofs/zdata.c | 31 +-
fs/erofs/zmap.c | 82 +-
fs/ext4/dir.c | 20 +-
fs/ext4/ext4.h | 1 +
fs/ext4/file.c | 7 +
fs/ext4/inline.c | 25 +-
fs/ext4/inode.c | 52 +-
fs/ext4/migrate.c | 3 +-
fs/ext4/namei.c | 2 +
fs/ext4/orphan.c | 10 +-
fs/f2fs/f2fs.h | 22 +-
fs/f2fs/gc.c | 5 +-
fs/f2fs/segment.c | 8 +-
fs/f2fs/super.c | 4 +-
fs/fat/nfs.c | 4 +-
fs/fuse/cuse.c | 5 +
fs/fuse/inode.c | 2 +
fs/hfsplus/catalog.c | 25 +-
fs/hfsplus/hfsplus_fs.h | 6 +
fs/hugetlbfs/inode.c | 3 +-
fs/inode.c | 18 +-
fs/isofs/compress.c | 7 +-
fs/nfs/blocklayout/dev.c | 21 +-
fs/nfs/client.c | 14 +-
fs/nfs/dir.c | 7 +
fs/nfs/filelayout/filelayoutdev.c | 3 +-
fs/nfs/flexfilelayout/flexfilelayout.c | 3 +-
fs/nfs/flexfilelayout/flexfilelayoutdev.c | 3 +-
fs/nfs/inode.c | 4 +-
fs/nfs/internal.h | 1 +
fs/nfs/nfs4client.c | 1 +
fs/nfs/nfs4proc.c | 4 +-
fs/nfs/nfs4session.c | 16 +-
fs/nfs/pnfs.c | 35 +-
fs/nfs/pnfs.h | 3 +-
fs/nfs/pnfs_nfs.c | 14 +-
fs/nilfs2/page.c | 17 +-
fs/nilfs2/segment.c | 4 +
fs/nilfs2/the_nilfs.c | 6 +
fs/notify/fanotify/fanotify.c | 1 +
fs/notify/fanotify/fanotify_user.c | 12 +-
fs/ntfs3/fslog.c | 13 +-
fs/ntfs3/fsntfs.c | 8 +-
fs/ntfs3/record.c | 34 +-
fs/ntfs3/super.c | 13 +-
fs/ntfs3/xattr.c | 25 +-
fs/ocfs2/acl.c | 141 +-
fs/ocfs2/acl.h | 19 +-
fs/ocfs2/cluster/heartbeat.c | 86 +-
fs/ocfs2/cluster/heartbeat.h | 5 +
fs/ocfs2/cluster/nodemanager.c | 23 +-
fs/ocfs2/cluster/nodemanager.h | 2 +
fs/ocfs2/cluster/tcp.c | 83 +-
fs/ocfs2/cluster/tcp.h | 1 +
fs/ocfs2/inode.c | 16 +
fs/ocfs2/namei.c | 17 +-
fs/ocfs2/xattr.c | 86 +-
fs/ocfs2/xattr.h | 9 +-
fs/resctrl/rdtgroup.c | 19 +-
fs/smb/client/cifs_debug.c | 2 +-
fs/smb/client/inode.c | 14 -
fs/smb/client/smb2pdu.c | 16 +-
fs/smb/server/Kconfig | 1 -
fs/smb/server/auth.c | 2 +-
fs/smb/server/connection.c | 19 +
fs/smb/server/connection.h | 1 +
fs/smb/server/mgmt/share_config.c | 7 +-
fs/smb/server/mgmt/user_config.c | 1 +
fs/smb/server/mgmt/user_session.c | 24 +-
fs/smb/server/mgmt/user_session.h | 1 +
fs/smb/server/server.c | 4 +-
fs/smb/server/smb2ops.c | 11 +-
fs/smb/server/smb2pdu.c | 15 +-
fs/smb/server/smbacl.c | 4 +-
fs/smb/server/transport_ipc.c | 12 +
fs/smb/server/transport_tcp.c | 6 +
fs/smb/server/vfs.c | 3 -
fs/smb/server/vfs_cache.c | 5 +-
fs/squashfs/cache.c | 2 +-
fs/stat.c | 2 +-
fs/super.c | 4 +-
fs/udf/inode.c | 129 +-
fs/udf/super.c | 23 +-
fs/udf/symlink.c | 2 +
include/acpi/processor.h | 2 +
include/drm/bridge/dw_dp.h | 8 +
include/linux/bio.h | 22 +-
include/linux/blk-mq.h | 16 +
include/linux/blk_types.h | 12 +
include/linux/bpf.h | 19 +-
include/linux/compiler-context-analysis.h | 32 +
include/linux/compiler_types.h | 18 +-
include/linux/dma-buf.h | 5 +
include/linux/efi.h | 4 +-
include/linux/filter.h | 31 +
include/linux/firmware/qcom/qcom_scm.h | 14 +
include/linux/fs.h | 20 +-
include/linux/ftrace.h | 5 +-
include/linux/gpio.h | 162 +-
include/linux/gpio/legacy.h | 173 ++
include/linux/hwmon.h | 3 +
include/linux/i3c/master.h | 3 +
include/linux/ieee80211-uhr.h | 220 ++
include/linux/ieee80211.h | 33 +-
include/linux/ima.h | 7 +-
include/linux/io_uring_types.h | 7 +-
include/linux/leds.h | 2 +
include/linux/libnvdimm.h | 9 +
include/linux/maple_tree.h | 2 +-
include/linux/memory.h | 27 +-
include/linux/memory_hotplug.h | 18 +-
include/linux/mlx5/driver.h | 1 +
include/linux/mlx5/fs.h | 1 +
include/linux/mlx5/mlx5_ifc.h | 9 +-
include/linux/mlx5/vport.h | 7 +
include/linux/mmc/sdio_ids.h | 1 +
include/linux/mroute_base.h | 3 +
include/linux/nfs_xdr.h | 2 +-
include/linux/nvme.h | 4 +
include/linux/pci.h | 14 +-
include/linux/pm_runtime.h | 24 +
include/linux/remoteproc.h | 284 +--
include/linux/rsc_table.h | 364 ++++
include/linux/rtsx_usb.h | 3 +
include/linux/sched/rt.h | 2 +
include/linux/sched/user.h | 3 +-
include/linux/secure_boot.h | 23 +
include/linux/serial_core.h | 20 +
include/linux/soc/airoha/airoha_offload.h | 1 +
include/linux/soc/qcom/ubwc.h | 1 +
include/linux/soundwire/sdw.h | 8 +
include/linux/syscore_ops.h | 17 +-
include/linux/time_namespace.h | 39 +-
include/linux/usb.h | 3 +-
include/linux/virtio.h | 1 +
include/linux/virtio_net.h | 4 +
include/media/rc-map.h | 2 -
include/net/act_api.h | 2 +-
include/net/bluetooth/hci_core.h | 2 +-
include/net/bluetooth/l2cap.h | 5 +
include/net/cfg80211.h | 156 +-
include/net/inetpeer.h | 4 +
include/net/libeth/xsk.h | 2 +-
include/net/netns/ipv4.h | 2 +-
include/net/pkt_sched.h | 1 +
include/net/sch_generic.h | 9 +-
include/net/sock.h | 17 +-
include/net/xdp_sock_drv.h | 22 +-
include/net/xsk_buff_pool.h | 3 +-
include/rdma/ib_verbs.h | 21 +
include/scsi/scsi_driver.h | 7 +-
include/sound/core.h | 2 +
include/trace/events/erofs.h | 7 +-
include/uapi/linux/devlink.h | 1 +
include/uapi/linux/if_xdp.h | 1 +
include/uapi/linux/nl80211.h | 140 ++
include/uapi/linux/time_types.h | 2 +-
include/uapi/rdma/ib_user_ioctl_cmds.h | 6 +
init/Kconfig | 4 +-
io_uring/futex.c | 16 +-
io_uring/io_uring.c | 45 +-
io_uring/io_uring.h | 17 +-
io_uring/msg_ring.c | 3 +-
io_uring/notif.c | 5 +-
io_uring/poll.c | 13 +-
io_uring/poll.h | 2 +-
io_uring/rw.c | 5 +-
io_uring/rw.h | 2 +-
io_uring/timeout.c | 20 +-
io_uring/uring_cmd.c | 5 +-
io_uring/waitid.c | 81 +-
kernel/bpf/arena.c | 2 +
kernel/bpf/bpf_lsm.c | 1 -
kernel/bpf/btf.c | 30 +-
kernel/bpf/cgroup.c | 27 +-
kernel/bpf/cpumask.c | 6 +-
kernel/bpf/helpers.c | 9 +-
kernel/bpf/mmap_unlock_work.h | 51 +-
kernel/bpf/net_namespace.c | 17 +-
kernel/bpf/queue_stack_maps.c | 8 +-
kernel/bpf/ringbuf.c | 2 +-
kernel/bpf/stackmap.c | 192 +-
kernel/bpf/syscall.c | 23 +-
kernel/bpf/task_iter.c | 48 +-
kernel/bpf/verifier.c | 55 +-
kernel/cgroup/cpuset-internal.h | 2 +-
kernel/cgroup/cpuset.c | 118 +-
kernel/cpu_pm.c | 12 +-
kernel/crash_dump_dm_crypt.c | 15 +-
kernel/dma/swiotlb.c | 31 +-
kernel/events/core.c | 90 +-
kernel/events/internal.h | 1 +
kernel/events/ring_buffer.c | 2 +
kernel/futex/core.c | 105 +-
kernel/futex/futex.h | 28 +-
kernel/futex/pi.c | 37 +-
kernel/futex/requeue.c | 20 +-
kernel/futex/waitwake.c | 17 +-
kernel/irq/generic-chip.c | 14 +-
kernel/irq/pm.c | 11 +-
kernel/kcsan/core.c | 12 +-
kernel/locking/lockdep.c | 2 +
kernel/locking/rtmutex_api.c | 2 +
kernel/module/dups.c | 99 +-
kernel/module/stats.c | 2 +-
kernel/power/snapshot.c | 5 +-
kernel/power/wakelock.c | 2 +-
kernel/printk/printk.c | 176 +-
kernel/rcu/tree_plugin.h | 10 +-
kernel/sched/core.c | 16 +
kernel/sched/cpufreq_schedutil.c | 2 +-
kernel/sched/fair.c | 31 +-
kernel/sys.c | 2 +-
kernel/time/Makefile | 1 +
kernel/time/clocksource.c | 8 +-
kernel/time/namespace.c | 165 +-
kernel/time/namespace_internal.h | 28 +
kernel/time/namespace_vdso.c | 160 ++
kernel/time/sched_clock.c | 22 +-
kernel/time/timekeeping.c | 49 +-
kernel/time/timer_migration.c | 4 +-
kernel/trace/ftrace.c | 57 +-
kernel/trace/ring_buffer.c | 67 +-
kernel/trace/trace.c | 111 +-
kernel/trace/trace.h | 12 +-
kernel/trace/trace_btf.c | 31 +-
kernel/trace/trace_btf.h | 3 +-
kernel/trace/trace_events.c | 6 +-
kernel/trace/trace_functions.c | 2 +-
kernel/trace/trace_probe.c | 18 +-
kernel/trace/trace_stack.c | 2 +-
lib/interval_tree_test.c | 4 +-
lib/maple_tree.c | 43 +-
lib/string.c | 3 +-
lib/test_hmm.c | 2 +-
lib/vdso/datastore.c | 25 -
mm/damon/sysfs.c | 6 +-
mm/huge_memory.c | 2 +
mm/khugepaged.c | 6 -
mm/madvise.c | 8 +
mm/memory_hotplug.c | 13 +-
mm/mm_init.c | 19 +-
mm/mremap.c | 21 +-
mm/secretmem.c | 117 +-
net/batman-adv/bridge_loop_avoidance.c | 65 +-
net/batman-adv/distributed-arp-table.c | 58 +-
net/batman-adv/mesh-interface.c | 7 +-
net/batman-adv/types.h | 2 +-
net/bluetooth/hci_conn.c | 20 +-
net/bluetooth/hci_sync.c | 12 +-
net/bluetooth/l2cap_sock.c | 36 +-
net/bluetooth/mgmt.c | 40 +-
net/bluetooth/msft.c | 5 +
net/bluetooth/rfcomm/core.c | 4 +
net/bridge/br_netlink_tunnel.c | 3 +-
net/bridge/br_vlan.c | 4 +-
net/can/bcm.c | 5 +-
net/can/isotp.c | 3 +-
net/can/j1939/socket.c | 3 +-
net/can/raw.c | 3 +-
net/ceph/messenger_v2.c | 5 +
net/core/dev.c | 60 +-
net/core/filter.c | 4 -
net/core/lwt_bpf.c | 15 +-
net/core/net_namespace.c | 25 +-
net/core/page_pool.c | 71 +-
net/core/skbuff.c | 6 +-
net/core/sock.c | 20 +-
net/devlink/netlink_gen.c | 2 +-
net/hsr/hsr_device.c | 2 +
net/ife/ife.c | 14 +-
net/ipv4/inetpeer.c | 38 +-
net/ipv4/ipmr.c | 186 +-
net/ipv4/ipmr_base.c | 16 +
net/ipv4/ping.c | 3 +-
net/ipv4/raw.c | 3 +-
net/ipv4/tcp.c | 6 +-
net/ipv4/tcp_output.c | 2 +-
net/ipv6/ip6mr.c | 22 +-
net/ipv6/raw.c | 3 +-
net/ipv6/route.c | 2 +-
net/ipv6/xfrm6_input.c | 2 +-
net/kcm/kcmsock.c | 3 +
net/mac80211/link.c | 3 +-
net/mac80211/mlme.c | 2 +-
net/mac80211/s1g.c | 2 +-
net/mac80211/spectmgmt.c | 11 +-
net/mac80211/tx.c | 3 +-
net/netfilter/ipvs/ip_vs_ftp.c | 10 +-
net/netfilter/nf_nat_sip.c | 5 +
net/netfilter/nf_tables_api.c | 14 +-
net/netfilter/xt_cgroup.c | 12 +-
net/netfilter/xt_hl.c | 27 +
net/nfc/digital_core.c | 2 +-
net/nfc/llcp_core.c | 29 +-
net/nfc/llcp_sock.c | 14 +-
net/nfc/nci/data.c | 10 +-
net/nfc/nci/rsp.c | 41 +-
net/phonet/pep.c | 2 +-
net/rds/cong.c | 4 +-
net/sched/act_api.c | 7 +-
net/sched/act_bpf.c | 28 +-
net/sched/act_ct.c | 46 +
net/sched/act_ctinfo.c | 11 +
net/sched/act_ife.c | 63 +-
net/sched/act_mpls.c | 2 +-
net/sched/act_pedit.c | 24 +
net/sched/act_police.c | 14 +-
net/sched/act_sample.c | 9 +
net/sched/act_skbedit.c | 2 +-
net/sched/act_skbmod.c | 12 +-
net/sched/act_tunnel_key.c | 80 +
net/sched/cls_api.c | 18 +-
net/sched/sch_api.c | 7 +-
net/sched/sch_cake.c | 2 +-
net/sched/sch_codel.c | 2 +-
net/sched/sch_fifo.c | 2 +-
net/sched/sch_fq.c | 26 +-
net/sched/sch_fq_codel.c | 8 +-
net/sched/sch_fq_pie.c | 3 +-
net/sched/sch_gred.c | 6 +-
net/sched/sch_hhf.c | 4 +
net/sched/sch_htb.c | 7 +-
net/sched/sch_plug.c | 2 +-
net/sched/sch_sfq.c | 3 +-
net/sched/sch_teql.c | 1 +
net/smc/af_smc.c | 2 +-
net/smc/smc_inet.c | 16 +
net/smc/smc_llc.c | 3 +
net/sunrpc/rpcb_clnt.c | 4 +
net/sunrpc/xprtsock.c | 20 +-
net/tls/tls_strp.c | 16 +-
net/vmw_vsock/af_vsock.c | 23 +-
net/wireless/core.c | 57 +-
net/wireless/core.h | 4 +
net/wireless/nl80211.c | 491 ++++-
net/wireless/nl80211.h | 5 +-
net/wireless/pmsr.c | 5 +-
net/wireless/rdev-ops.h | 16 +
net/wireless/reg.c | 4 +-
net/wireless/trace.h | 57 +
net/wireless/util.c | 101 +-
net/xdp/xsk.c | 44 +-
net/xdp/xsk_buff_pool.c | 7 +-
net/xdp/xsk_queue.h | 16 +-
net/xfrm/xfrm_output.c | 4 +-
rust/kernel/cpufreq.rs | 24 +-
rust/uapi/uapi_helper.h | 2 +-
samples/ftrace/ftrace-direct-modify.c | 12 +-
samples/ftrace/ftrace-direct-multi-modify.c | 12 +-
scripts/mod/modpost.c | 6 +-
scripts/tags.sh | 2 +-
security/apparmor/af_unix.c | 2 +-
security/apparmor/apparmorfs.c | 2 +-
security/apparmor/domain.c | 201 +-
security/apparmor/include/lib.h | 31 +-
security/apparmor/include/policy.h | 3 +
security/apparmor/label.c | 26 +-
security/apparmor/lib.c | 20 +-
security/apparmor/mount.c | 17 +-
security/apparmor/policy.c | 22 +-
security/integrity/Makefile | 1 +
security/integrity/efi_secureboot.c | 56 +
security/integrity/ima/ima_appraise.c | 2 +-
security/integrity/ima/ima_efi.c | 47 +-
security/integrity/ima/ima_main.c | 3 +-
security/integrity/integrity.h | 1 +
security/integrity/platform_certs/load_uefi.c | 2 +-
security/smack/smack.h | 5 +-
security/smack/smack_lsm.c | 67 +-
security/smack/smackfs.c | 222 +-
sound/core/control.c | 6 +-
sound/core/control_led.c | 13 +-
sound/core/init.c | 4 +-
sound/core/seq/seq_clientmgr.c | 16 +-
sound/core/seq/seq_midi.c | 61 +-
sound/drivers/mtpav.c | 4 +-
sound/hda/common/proc.c | 2 +-
sound/pci/asihpi/hpi6000.c | 5 +
sound/pci/ice1712/ice1712.c | 7 +-
sound/pci/via82xx_modem.c | 26 +-
sound/soc/apple/mca.c | 6 +-
sound/soc/codecs/rt700-sdw.c | 6 +-
sound/soc/codecs/tas2783-sdw.c | 42 +-
sound/soc/fsl/fsl-asoc-card.c | 4 +-
sound/soc/fsl/fsl_audmix.c | 24 +-
sound/soc/meson/meson-card-utils.c | 17 +-
sound/soc/pxa/pxa-ssp.c | 7 +-
sound/soc/qcom/qdsp6/q6apm.c | 12 +-
sound/soc/soc-dapm.c | 2 +-
sound/soc/sof/topology.c | 18 +-
sound/soc/tegra/tegra210_mixer.c | 10 +-
sound/soc/xilinx/xlnx_formatter_pcm.c | 14 +-
sound/usb/fcp.c | 38 +-
sound/usb/mixer_scarlett2.c | 21 +-
sound/usb/quirks.c | 13 +-
tools/bpf/bpftool/map.c | 16 +-
tools/bpf/bpftool/sign.c | 7 +-
tools/bpf/bpftool/struct_ops.c | 4 +
tools/build/Makefile.feature | 2 -
tools/build/feature/Makefile | 14 -
tools/include/nolibc/arch-powerpc.h | 2 +-
tools/include/nolibc/arch-sparc.h | 2 +-
tools/include/uapi/linux/if_xdp.h | 1 +
tools/lib/bpf/libbpf.c | 3 +-
.../xdrgen/templates/C/enum/declaration/enum.j2 | 1 -
.../xdrgen/templates/C/enum/definition/close.j2 | 1 +
.../xdrgen/templates/C/enum/definition/close_be.j2 | 1 +
.../xdrgen/templates/C/pointer/encoder/string.j2 | 2 +
.../C/pointer/encoder/variable_length_opaque.j2 | 2 +
.../xdrgen/templates/C/struct/encoder/string.j2 | 2 +
.../C/struct/encoder/variable_length_opaque.j2 | 2 +
.../xdrgen/templates/C/union/definition/close.j2 | 5 -
tools/perf/Documentation/perf-c2c.txt | 7 +
tools/perf/builtin-c2c.c | 296 ++-
tools/perf/builtin-ftrace.c | 13 +-
tools/perf/builtin-record.c | 55 +-
tools/perf/builtin-stat.c | 9 +-
.../arch/x86/amdzen5/floating-point.json | 160 +-
.../pmu-events/arch/x86/amdzen5/load-store.json | 8 +-
tools/perf/pmu-events/jevents.py | 5 +-
tools/perf/pmu-events/metric.py | 6 +-
tools/perf/tests/builtin-test.c | 864 +++++++-
tools/perf/tests/shell/kvm.sh | 169 ++
.../perf/tests/shell/lib/perf_metric_validation.py | 11 +-
tools/perf/tests/shell/lib/perf_record.sh | 58 +
tools/perf/tests/shell/pipe_test.sh | 4 +-
.../shell/record+zstd_comp_decomp_multi_record.sh | 63 +
tools/perf/tests/shell/record.sh | 173 +-
tools/perf/tests/shell/record_lbr.sh | 50 +-
tools/perf/tests/shell/stat_all_metrics.sh | 112 +-
tools/perf/tests/shell/stat_bpf_counters.sh | 44 +-
tools/perf/tests/shell/stat_metrics_values.sh | 7 +
tools/perf/tests/shell/test_brstack.sh | 131 +-
tools/perf/tests/shell/trace_record_replay.sh | 38 +-
tools/perf/tests/tests.h | 2 +
tools/perf/ui/browsers/hists.c | 6 +-
tools/perf/util/arm-spe.c | 4 +
tools/perf/util/auxtrace.c | 15 +-
tools/perf/util/bpf-event.c | 3 +-
tools/perf/util/bpf-filter.c | 22 +-
tools/perf/util/cap.c | 4 +-
tools/perf/util/cap.h | 3 +-
tools/perf/util/capstone.c | 13 +-
tools/perf/util/compress.h | 6 +-
tools/perf/util/cs-etm.c | 85 +-
tools/perf/util/data-convert-json.c | 1 +
tools/perf/util/dso.c | 48 +-
tools/perf/util/dso.h | 57 +-
tools/perf/util/evsel.c | 2 +-
tools/perf/util/hist.h | 8 +-
tools/perf/util/intel-bts.c | 2 +-
tools/perf/util/intel-pt.c | 2 +-
tools/perf/util/libbfd.c | 23 +-
tools/perf/util/machine.c | 43 +-
tools/perf/util/metricgroup.c | 7 +-
tools/perf/util/python.c | 66 +-
tools/perf/util/sort.c | 167 +-
tools/perf/util/symbol.c | 3 +-
tools/perf/util/synthetic-events.c | 6 +-
tools/perf/util/thread-stack.c | 2 +-
tools/perf/util/trace-event-read.c | 33 +-
tools/perf/util/util.c | 12 +-
tools/perf/util/zstd.c | 40 +-
tools/sched_ext/include/scx/compat.bpf.h | 110 +-
tools/sched_ext/scx_flatcg.bpf.c | 29 +-
tools/sched_ext/scx_qmap.bpf.c | 16 +-
tools/scripts/Makefile.include | 37 +-
tools/testing/kunit/kunit.py | 2 +-
tools/testing/kunit/kunit_tool_test.py | 12 +
tools/testing/selftests/arm64/fp/fp-ptrace.c | 47 +-
tools/testing/selftests/arm64/fp/sve-test.S | 7 +-
.../selftests/arm64/mte/check_buffer_fill.c | 2 +
.../selftests/arm64/mte/check_child_memory.c | 2 +
.../selftests/arm64/mte/check_gcr_el1_cswitch.c | 1 +
.../selftests/arm64/mte/check_hugetlb_options.c | 2 +
.../selftests/arm64/mte/check_ksm_options.c | 31 +-
.../selftests/arm64/mte/check_mmap_options.c | 2 +
tools/testing/selftests/arm64/mte/check_prctl.c | 2 +-
.../selftests/arm64/mte/check_tags_inclusion.c | 2 +
tools/testing/selftests/arm64/mte/check_user_mem.c | 2 +
tools/testing/selftests/bpf/README.rst | 4 +-
tools/testing/selftests/bpf/network_helpers.c | 10 +-
tools/testing/selftests/bpf/network_helpers.h | 5 +
.../selftests/bpf/prog_tests/global_map_resize.c | 8 +-
.../selftests/bpf/prog_tests/lwt_ip_encap.c | 152 +-
tools/testing/selftests/bpf/prog_tests/mptcp.c | 13 +-
tools/testing/selftests/bpf/prog_tests/sha256.c | 4 +-
.../testing/selftests/bpf/progs/bpf_tracing_net.h | 3 +
tools/testing/selftests/bpf/progs/mptcpify.c | 2 +-
.../selftests/bpf/progs/test_lwt_ip_encap.c | 155 +-
tools/testing/selftests/bpf/test_progs.c | 11 +-
tools/testing/selftests/bpf/test_sockmap.c | 3 +-
tools/testing/selftests/bpf/veristat.c | 76 +-
tools/testing/selftests/bpf/vmtest.sh | 13 +-
tools/testing/selftests/cgroup/test_cpuset_prs.sh | 5 +-
tools/testing/selftests/kselftest_harness.h | 14 +-
tools/testing/selftests/lsm/common.c | 4 +-
tools/testing/selftests/mm/cow.c | 9 +-
tools/testing/selftests/mm/ksm_tests.c | 206 +-
tools/testing/selftests/mm/memfd_secret.c | 30 +-
tools/testing/selftests/proc/proc-maps-race.c | 3 +-
tools/testing/selftests/proc/proc-pidns.c | 1 +
.../selftests/rseq/rseq-x86-thread-pointer.h | 4 +-
.../selftests/sched_ext/ddsp_bogus_dsq_fail.bpf.c | 20 +-
.../selftests/sched_ext/ddsp_vtimelocal_fail.bpf.c | 13 +-
tools/testing/selftests/sched_ext/exit.c | 1 +
tools/testing/selftests/sched_ext/prog_run.c | 36 +-
tools/testing/selftests/timers/leap-a-day.c | 19 +-
tools/testing/selftests/vDSO/vgetrandom-chacha.S | 2 +-
tools/testing/selftests/zram/zram_lib.sh | 2 +-
virt/kvm/kvm_main.c | 18 +-
1613 files changed, 30327 insertions(+), 15639 deletions(-)
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0001/1518] net/mlx5e: xsk: Fix unlocked writing to ICOSQ
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0002/1518] drm/amd/display: Fix backlight max_brightness to match exported range Greg Kroah-Hartman
` (997 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Paul Saab, Dragos Tatulea,
Tariq Toukan, Simon Horman, Jakub Kicinski, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dragos Tatulea <dtatulea@nvidia.com>
commit c326f9c68921e2f14dfcecb2f6b4216313d50248 upstream.
During napi poll, when the affinity changes and there's still XSK work
to be done, we trigger an ICOSQ interrupt on the new CPU. However, this
triggering on the ICOSQ is done unprotected.
There are 2 such races:
A) mlx5e_trigger_irq() is called while mlx5e_xsk_alloc_rx_mpwqe() is
running from a different CPU due to affinity change. This can happen
because IRQ triggering is done after napi_complete_done(). At this point
the NAPI can be scheduled on a different CPU. Like this:
CPU A (old affinity, NAPI tail) CPU B (new affinity, fresh NAPI)
------------------------------- --------------------------------
napi_complete_done() clears SCHED
mlx5e_cq_arm(...)
napi_schedule_prep() sets SCHED
mlx5e_napi_poll()
mlx5e_xsk_alloc_rx_mpwqe()
mlx5e_icosq_sync_lock() // noop
memcpy 640 B UMR body
advance sq->pc by 10
mlx5e_trigger_irq(&c->icosq)
wqe_info[pi] = {NOP, 1}
mlx5e_post_nop() advances sq->pc
B) mlx5e_trigger_irq() is called on the ICOSQ when
mlx5e_trigger_napi_icosq() is running.
The obvious fix would be to lock the ICOSQ. But ICOSQ has an optimized
locking scheme that doesn't work for this scenario. Kick the async ICOSQ
instead which is always locked.
This issue was noticed in the wild with the following splat:
netdevice: ge-0-0-1: Bad OP in ICOSQ CQE: 0xd
WARNING: drivers/net/ethernet/mellanox/mlx5/core/en_rx.c:826 [...]
[...]
Call Trace:
<IRQ>
mlx5e_napi_poll+0x11d/0x7f0 [mlx5_core]
__napi_poll+0x30/0x200
? skb_defer_free_flush+0x9c/0xc0
net_rx_action+0x2fe/0x3f0
handle_softirqs+0xd8/0x340
__irq_exit_rcu+0xbc/0xe0
common_interrupt+0x85/0xa0
</IRQ>
<TASK>
asm_common_interrupt+0x26/0x40
[...]
---[ end trace 0000000000000000 ]---
mlx5_core 0000:08:00.0 ge-0-0-1: Error cqe on cqn 0x548, ci 0x2022, qn 0x8f4,
opcode 0xd, syndrome 0x2, vendor syndrome 0x68
00000000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00000010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00000020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00000030: 00 00 00 00 01 00 68 02 01 00 08 f4 de 14 59 d2
WQE DUMP: WQ size 16384 WQ cur size 0, WQE index 0x1e14, len: 64
00000000: 00 00 00 01 d9 ed 80 02 00 00 00 01 d9 ed 90 02
00000010: 00 00 00 01 d9 ed a0 02 00 00 00 01 d9 ed b0 02
00000020: 00 00 00 01 d9 ed c0 02 00 00 00 01 d9 ed d0 02
00000030: 00 00 00 01 d9 ed e0 02 00 00 00 01 d9 ed f0 02
mlx5_core 0000:08:00.0 ge-0-0-1: Error cqe on cqn 0x548, ci 0x2023, qn 0x8f4,
opcode 0xd, syndrome 0x5, vendor syndrome 0xf9
00000000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00000010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00000020: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
00000030: 00 00 00 00 01 00 f9 05 01 00 08 f4 de 15 cf d2
[ Backport to 6.18.y and older: upstream commit calls
mlx5e_trigger_napi_async_icosq(), which was introduced by commit
0da1dba72616 ("net/mlx5e: XSK, Fix unintended ICOSQ change") and is not
present here. In these trees mlx5e_trigger_napi_icosq() is the
equivalent helper: it takes c->async_icosq_lock and triggers
c->async_icosq, which is unconditionally opened, activated, polled and
armed for every channel. Race B does not apply, as it concerns the
sync-ICOSQ variant of mlx5e_trigger_napi_icosq() that only exists
upstream, and mlx5e_icosq_sync_lock() in the race A diagram has no
equivalent here. ]
Fixes: db05815b36cb ("net/mlx5e: Add XSK zero-copy support")
Reported-by: Paul Saab <ps@mu.org>
Signed-off-by: Dragos Tatulea <dtatulea@nvidia.com>
Signed-off-by: Tariq Toukan <tariqt@nvidia.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Link: https://patch.msgid.link/20260513064613.334602-1-tariqt@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/mellanox/mlx5/core/en_txrx.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/mellanox/mlx5/core/en_txrx.c b/drivers/net/ethernet/mellanox/mlx5/core/en_txrx.c
index 76108299ea57d..65758e7211747 100644
--- a/drivers/net/ethernet/mellanox/mlx5/core/en_txrx.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/en_txrx.c
@@ -247,7 +247,7 @@ int mlx5e_napi_poll(struct napi_struct *napi, int budget)
}
if (unlikely(aff_change && busy_xsk)) {
- mlx5e_trigger_irq(&c->icosq);
+ mlx5e_trigger_napi_icosq(c);
ch_stats->force_irq++;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0002/1518] drm/amd/display: Fix backlight max_brightness to match exported range
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0001/1518] net/mlx5e: xsk: Fix unlocked writing to ICOSQ Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0003/1518] drm/amd/display: Scale custom brightness curve from full range Greg Kroah-Hartman
` (996 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alex Hung, Mario Limonciello,
George Zhang, Alex Deucher, Akhmed Zhitaev, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mario Limonciello <mario.limonciello@amd.com>
[ Upstream commit bd9e2b5b0473c75abc0f4134dfe79ecbfb16610d ]
[Why]
FWTS autobrightness fails on eDP panels because actual_brightness can
read higher than the advertised max_brightness (e.g. 63576 vs 62451).
The conversion helpers expose the firmware PWM range to userspace as
[0..max]. But max_brightness is advertised as (max - min), which is
smaller. So reading the level can return a value above max_brightness.
This regressed in commit 4b61b8a39051 ("drm/amd/display: Add debugging
message for brightness caps"), which changed max_brightness to
(max - min) and undid commit 8dbd72cb7900 ("drm/amd/display: Export full
brightness range to userspace").
[How]
Advertise max_brightness as max, and scale the initial AC/DC brightness
against max too. Update the KUnit expectations to match.
[ Backport note: In 6.18.y the backlight property setup still lives in
amdgpu_dm.c, so apply the same property changes there. The upstream
KUnit file was introduced by a later refactoring and is not present. ]
Fixes: 4b61b8a39051 ("drm/amd/display: Add debugging message for brightness caps")
Reviewed-by: Alex Hung <alex.hung@amd.com>
Signed-off-by: Mario Limonciello <mario.limonciello@amd.com>
Signed-off-by: George Zhang <george.zhang@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Akhmed Zhitaev <zhitaevakh@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
index 6eb2514c7c305..c71d34186dfed 100644
--- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
+++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
@@ -5228,11 +5228,11 @@ amdgpu_dm_register_backlight_device(struct amdgpu_dm_connector *aconnector)
caps = &dm->backlight_caps[aconnector->bl_idx];
if (get_brightness_range(caps, &min, &max)) {
if (power_supply_is_system_supplied() > 0)
- props.brightness = DIV_ROUND_CLOSEST((max - min) * caps->ac_level, 100);
+ props.brightness = DIV_ROUND_CLOSEST(max * caps->ac_level, 100);
else
- props.brightness = DIV_ROUND_CLOSEST((max - min) * caps->dc_level, 100);
+ props.brightness = DIV_ROUND_CLOSEST(max * caps->dc_level, 100);
/* min is zero, so max needs to be adjusted */
- props.max_brightness = max - min;
+ props.max_brightness = max;
drm_dbg(drm, "Backlight caps: min: %d, max: %d, ac %d, dc %d\n", min, max,
caps->ac_level, caps->dc_level);
} else
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0003/1518] drm/amd/display: Scale custom brightness curve from full range
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0001/1518] net/mlx5e: xsk: Fix unlocked writing to ICOSQ Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0002/1518] drm/amd/display: Fix backlight max_brightness to match exported range Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0004/1518] batman-adv: dat: atomically update mac addresses Greg Kroah-Hartman
` (995 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Akhmed Zhitaev,
Mario Limonciello (AMD), Mario Limonciello, Alex Deucher,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Akhmed Zhitaev <zhitaevakh@gmail.com>
[ Upstream commit 6fd83a1c2cdea48c396f600795217fbdfb8124f6 ]
Custom brightness curves use an 8-bit input signal. After exporting the
full PWM range to userspace, the curve normalizer still divides requests
by the physical PWM span. On panels with a nonzero minimum PWM level,
this can produce a curve input greater than 255 and send an invalid
backlight level to DC.
Scale the userspace [0..max] range to the curve's [0..255] range
instead. This retains the full advertised range and keeps the reverse
readback conversion unchanged.
[ Backport note: In 6.18.y the brightness helpers still live in
amdgpu_dm.c, while upstream changes the later amdgpu_dm_backlight.c.
Apply the same semantic change at the old location; the logic is
otherwise unchanged. ]
Fixes: 8dbd72cb7900 ("drm/amd/display: Export full brightness range to userspace")
Cc: stable@vger.kernel.org
Signed-off-by: Akhmed Zhitaev <zhitaevakh@gmail.com>
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
(Move to amdgpu_dm_backlight.c)
Link: https://patch.msgid.link/20260813170959.22073-1-zhitaevakh@gmail.com
Signed-off-by: Mario Limonciello <mario.limonciello@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
index c71d34186dfed..9bce65ca29b02 100644
--- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
+++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
@@ -4958,10 +4958,10 @@ static int get_brightness_range(const struct amdgpu_dm_backlight_caps *caps,
return 1;
}
-/* Rescale from [min..max] to [0..AMDGPU_MAX_BL_LEVEL] */
-static inline u32 scale_input_to_fw(int min, int max, u64 input)
+/* Rescale userspace [0..max] to the firmware curve's [0..255]. */
+static inline u32 scale_input_to_fw(int max, u64 input)
{
- return DIV_ROUND_CLOSEST_ULL(input * AMDGPU_MAX_BL_LEVEL, max - min);
+ return DIV_ROUND_CLOSEST_ULL(input * AMDGPU_MAX_BL_LEVEL, max);
}
/* Rescale from [0..AMDGPU_MAX_BL_LEVEL] to [min..max] */
@@ -4974,7 +4974,7 @@ static void convert_custom_brightness(const struct amdgpu_dm_backlight_caps *cap
unsigned int min, unsigned int max,
uint32_t *user_brightness)
{
- u32 brightness = scale_input_to_fw(min, max, *user_brightness);
+ u32 brightness = scale_input_to_fw(max, *user_brightness);
u8 lower_signal, upper_signal, upper_lum, lower_lum, lum;
int left, right;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0004/1518] batman-adv: dat: atomically update mac addresses
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (2 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0003/1518] drm/amd/display: Scale custom brightness curve from full range Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0005/1518] batman-adv: bla: avoid CRC corruption due to parallel claim add Greg Kroah-Hartman
` (994 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Sven Eckelmann, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sven Eckelmann <sven@narfation.org>
commit e6de568d3eda3e3c01c868fabd7a9535d5ee4a73 upstream.
When a MAC address is updated in batadv_dat_entry_add(), it is done using a
simple copy function. A parallel reader might only see parts of this
update. In worst case, the reader is transporting the half updated MAC
address over the network or is creating an ARP response using it -
poisoning the ARP cache.
atomic64_t can be used to store the 48 bit of a mac address. A reader will
then either see the old mac address or the new one - never a mixture of
both.
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-bot@kernel.org>
Fixes: 2f1dfbe18507 ("batman-adv: Distributed ARP Table - implement local storage")
[ Context ]
Signed-off-by: Sven Eckelmann <sven@narfation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/batman-adv/distributed-arp-table.c | 58 +++++++++++++++++---------
net/batman-adv/types.h | 2 +-
2 files changed, 40 insertions(+), 20 deletions(-)
diff --git a/net/batman-adv/distributed-arp-table.c b/net/batman-adv/distributed-arp-table.c
index 4bae8df85516c..72717e2952ab9 100644
--- a/net/batman-adv/distributed-arp-table.c
+++ b/net/batman-adv/distributed-arp-table.c
@@ -375,18 +375,19 @@ batadv_dat_entry_hash_find(struct batadv_priv *bat_priv, __be32 ip,
static void batadv_dat_entry_add(struct batadv_priv *bat_priv, __be32 ip,
u8 *mac_addr, unsigned short vid)
{
+ u64 u64_mac = ether_addr_to_u64(mac_addr);
struct batadv_dat_entry *dat_entry;
int hash_added;
dat_entry = batadv_dat_entry_hash_find(bat_priv, ip, vid);
/* if this entry is already known, just update it */
if (dat_entry) {
- if (!batadv_compare_eth(dat_entry->mac_addr, mac_addr))
- ether_addr_copy(dat_entry->mac_addr, mac_addr);
+ atomic64_set(&dat_entry->mac_addr, u64_mac);
+
dat_entry->last_update = jiffies;
batadv_dbg(BATADV_DBG_DAT, bat_priv,
"Entry updated: %pI4 %pM (vid: %d)\n",
- &dat_entry->ip, dat_entry->mac_addr,
+ &dat_entry->ip, mac_addr,
batadv_print_vid(vid));
goto out;
}
@@ -397,7 +398,7 @@ static void batadv_dat_entry_add(struct batadv_priv *bat_priv, __be32 ip,
dat_entry->ip = ip;
dat_entry->vid = vid;
- ether_addr_copy(dat_entry->mac_addr, mac_addr);
+ atomic64_set(&dat_entry->mac_addr, u64_mac);
dat_entry->last_update = jiffies;
kref_init(&dat_entry->refcount);
@@ -413,7 +414,7 @@ static void batadv_dat_entry_add(struct batadv_priv *bat_priv, __be32 ip,
}
batadv_dbg(BATADV_DBG_DAT, bat_priv, "New entry added: %pI4 %pM (vid: %d)\n",
- &dat_entry->ip, dat_entry->mac_addr, batadv_print_vid(vid));
+ &dat_entry->ip, mac_addr, batadv_print_vid(vid));
out:
batadv_dat_entry_put(dat_entry);
@@ -868,6 +869,8 @@ batadv_dat_cache_dump_entry(struct sk_buff *msg, u32 portid,
struct netlink_callback *cb,
struct batadv_dat_entry *dat_entry)
{
+ u8 mac[ETH_ALEN];
+ u64 u64_mac;
int msecs;
void *hdr;
@@ -880,11 +883,12 @@ batadv_dat_cache_dump_entry(struct sk_buff *msg, u32 portid,
genl_dump_check_consistent(cb, hdr);
msecs = jiffies_to_msecs(jiffies - dat_entry->last_update);
+ u64_mac = atomic64_read(&dat_entry->mac_addr);
+ u64_to_ether_addr(u64_mac, mac);
if (nla_put_in_addr(msg, BATADV_ATTR_DAT_CACHE_IP4ADDRESS,
dat_entry->ip) ||
- nla_put(msg, BATADV_ATTR_DAT_CACHE_HWADDRESS, ETH_ALEN,
- dat_entry->mac_addr) ||
+ nla_put(msg, BATADV_ATTR_DAT_CACHE_HWADDRESS, ETH_ALEN, mac) ||
nla_put_u16(msg, BATADV_ATTR_DAT_CACHE_VID, dat_entry->vid) ||
nla_put_u32(msg, BATADV_ATTR_LAST_SEEN_MSECS, msecs)) {
genlmsg_cancel(msg, hdr);
@@ -1151,6 +1155,8 @@ bool batadv_dat_snoop_outgoing_arp_request(struct batadv_priv *bat_priv,
struct net_device *mesh_iface = bat_priv->mesh_iface;
int hdr_size = 0;
unsigned short vid;
+ u8 mac[ETH_ALEN];
+ u64 u64_mac;
if (!atomic_read(&bat_priv->distributed_arp_table))
goto out;
@@ -1178,6 +1184,9 @@ bool batadv_dat_snoop_outgoing_arp_request(struct batadv_priv *bat_priv,
dat_entry = batadv_dat_entry_hash_find(bat_priv, ip_dst, vid);
if (dat_entry) {
+ u64_mac = atomic64_read(&dat_entry->mac_addr);
+ u64_to_ether_addr(u64_mac, mac);
+
/* If the ARP request is destined for a local client the local
* client will answer itself. DAT would only generate a
* duplicate packet.
@@ -1186,7 +1195,7 @@ bool batadv_dat_snoop_outgoing_arp_request(struct batadv_priv *bat_priv,
* additional DAT answer may trigger kernel warnings about
* a packet coming from the wrong port.
*/
- if (batadv_is_my_client(bat_priv, dat_entry->mac_addr, vid)) {
+ if (batadv_is_my_client(bat_priv, mac, vid)) {
ret = true;
goto out;
}
@@ -1196,18 +1205,16 @@ bool batadv_dat_snoop_outgoing_arp_request(struct batadv_priv *bat_priv,
* the backbone gws belonging to our backbone has claimed the
* destination.
*/
- if (!batadv_bla_check_claim(bat_priv,
- dat_entry->mac_addr, vid)) {
+ if (!batadv_bla_check_claim(bat_priv, mac, vid)) {
batadv_dbg(BATADV_DBG_DAT, bat_priv,
"Device %pM claimed by another backbone gw. Don't send ARP reply!",
- dat_entry->mac_addr);
+ mac);
ret = true;
goto out;
}
skb_new = batadv_dat_arp_create_reply(bat_priv, ip_dst, ip_src,
- dat_entry->mac_addr,
- hw_src, vid);
+ mac, hw_src, vid);
if (!skb_new)
goto out;
@@ -1249,6 +1256,8 @@ bool batadv_dat_snoop_incoming_arp_request(struct batadv_priv *bat_priv,
struct batadv_dat_entry *dat_entry = NULL;
bool ret = false;
unsigned short vid;
+ u8 mac[ETH_ALEN];
+ u64 u64_mac;
int err;
if (!atomic_read(&bat_priv->distributed_arp_table))
@@ -1276,8 +1285,11 @@ bool batadv_dat_snoop_incoming_arp_request(struct batadv_priv *bat_priv,
if (!dat_entry)
goto out;
+ u64_mac = atomic64_read(&dat_entry->mac_addr);
+ u64_to_ether_addr(u64_mac, mac);
+
skb_new = batadv_dat_arp_create_reply(bat_priv, ip_dst, ip_src,
- dat_entry->mac_addr, hw_src, vid);
+ mac, hw_src, vid);
if (!skb_new)
goto out;
@@ -1368,6 +1380,8 @@ bool batadv_dat_snoop_incoming_arp_reply(struct batadv_priv *bat_priv,
u8 *hw_src, *hw_dst;
bool dropped = false;
unsigned short vid;
+ u8 mac[ETH_ALEN];
+ u64 u64_mac;
if (!atomic_read(&bat_priv->distributed_arp_table))
goto out;
@@ -1396,11 +1410,17 @@ bool batadv_dat_snoop_incoming_arp_reply(struct batadv_priv *bat_priv,
* this frame would lead to doubled receive of an ARP reply.
*/
dat_entry = batadv_dat_entry_hash_find(bat_priv, ip_src, vid);
- if (dat_entry && batadv_compare_eth(hw_src, dat_entry->mac_addr)) {
- batadv_dbg(BATADV_DBG_DAT, bat_priv, "Doubled ARP reply removed: ARP MSG = [src: %pM-%pI4 dst: %pM-%pI4]; dat_entry: %pM-%pI4\n",
- hw_src, &ip_src, hw_dst, &ip_dst,
- dat_entry->mac_addr, &dat_entry->ip);
- dropped = true;
+ if (dat_entry) {
+ u64_mac = atomic64_read(&dat_entry->mac_addr);
+ u64_to_ether_addr(u64_mac, mac);
+
+ if (batadv_compare_eth(hw_src, mac)) {
+ batadv_dbg(BATADV_DBG_DAT, bat_priv,
+ "Doubled ARP reply removed: ARP MSG = [src: %pM-%pI4 dst: %pM-%pI4]; dat_entry: %pM-%pI4\n",
+ hw_src, &ip_src, hw_dst, &ip_dst,
+ mac, &dat_entry->ip);
+ dropped = true;
+ }
}
/* Update our internal cache with both the IP addresses the node got
diff --git a/net/batman-adv/types.h b/net/batman-adv/types.h
index ac4494f1b8e2a..51d04f351fdd4 100644
--- a/net/batman-adv/types.h
+++ b/net/batman-adv/types.h
@@ -2127,7 +2127,7 @@ struct batadv_dat_entry {
__be32 ip;
/** @mac_addr: the MAC address associated to the stored IPv4 */
- u8 mac_addr[ETH_ALEN];
+ atomic64_t mac_addr;
/** @vid: the vlan ID associated to this entry */
unsigned short vid;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0005/1518] batman-adv: bla: avoid CRC corruption due to parallel claim add
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (3 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0004/1518] batman-adv: dat: atomically update mac addresses Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0006/1518] mm/damon/sysfs: read ops_id only once in damon_sysfs_apply_inputs() Greg Kroah-Hartman
` (993 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Sven Eckelmann, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sven Eckelmann <sven@narfation.org>
commit 08645ab95768b88e2ff85a89211994651710465b upstream.
batadv_bla_add_claim() is used to add claims and modify the backbone of
claims for CLAIM frames from remote backbones and local packets. When it
handles a claim, it needs to either
* add the new claim's CRC to the backbone CRC
* remove the already existing claim's CRC from the old backbone and add it
to the new backbone
But when the "new" claim code was running in parallel to the "change
backbone" code, it can happen that the CRC was invalid because the
backbone_gw of the claim was changed twice in the "new" claim code path:
* CPU0 creates the claim for gateway A and publishes it in the claim
hash. The crc16 of the address has not yet been added to A's crc at
this point.
* CPU1 processes a claim frame of gateway B for the same client, finds
the just published claim, and performs the ownership change: it
switches the pointer to B, removes the crc16 from A's crc - which
never contained it - and adds it to B's crc.
* CPU0 continues behind the creation branch, unconditionally switches
the pointer back to A without compensating B's crc (its remove_crc
is false for the creation path), and finally adds the crc16 to A's
crc
The CRC is then wrong for both:
* claim belongs to A: but CRC is not part of backbone A's CRC
* claim doesn't belong to B: CRC is still part of backbone B's CRC
This wrong CRC is never recomputated from the stored claims. For local
backbone claims, this can also not recovered using syncs.
To avoid this, split the functionality in clear separate parts:
* new claim which always adds claim CRC to the backbone CRC (but never
changes the already set backbone_gw of the claim back)
* update of existing claim which automatically changes the backbone_gw
entry and only updates both backbone CRCs when there was an actual change
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-bot@kernel.org>
Fixes: 23721387c409 ("batman-adv: add basic bridge loop avoidance code")
[ Context ]
Signed-off-by: Sven Eckelmann <sven@narfation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/batman-adv/bridge_loop_avoidance.c | 63 ++++++++++++++++----------
1 file changed, 39 insertions(+), 24 deletions(-)
diff --git a/net/batman-adv/bridge_loop_avoidance.c b/net/batman-adv/bridge_loop_avoidance.c
index 1591911bceb48..5f2bb9eba3e1d 100644
--- a/net/batman-adv/bridge_loop_avoidance.c
+++ b/net/batman-adv/bridge_loop_avoidance.c
@@ -694,12 +694,14 @@ static void batadv_bla_add_claim(struct batadv_priv *bat_priv,
struct batadv_bla_backbone_gw *old_backbone_gw;
struct batadv_bla_claim *claim;
struct batadv_bla_claim search_claim;
- bool remove_crc = false;
int hash_added;
+ u16 claim_crc;
+ bool changed;
ether_addr_copy(search_claim.addr, mac);
search_claim.vid = vid;
claim = batadv_claim_hash_find(bat_priv, &search_claim);
+ claim_crc = crc16(0, mac, ETH_ALEN);
/* create a new claim entry if it does not exist yet. */
if (!claim) {
@@ -731,43 +733,56 @@ static void batadv_bla_add_claim(struct batadv_priv *bat_priv,
kfree(claim);
return;
}
+
+ spin_lock_bh(&backbone_gw->crc_lock);
+ backbone_gw->crc ^= claim_crc;
+ spin_unlock_bh(&backbone_gw->crc_lock);
+
+ WRITE_ONCE(backbone_gw->lasttime, jiffies);
+
+ batadv_claim_put(claim);
+ return;
+ }
+
+ WRITE_ONCE(claim->lasttime, jiffies);
+
+ /* replace backbone_gw atomically and adjust reference counters */
+ spin_lock_bh(&claim->backbone_lock);
+ if (claim->backbone_gw != backbone_gw) {
+ changed = true;
+
+ old_backbone_gw = claim->backbone_gw;
+ kref_get(&backbone_gw->refcount);
+ claim->backbone_gw = backbone_gw;
} else {
- WRITE_ONCE(claim->lasttime, jiffies);
- if (claim->backbone_gw == backbone_gw)
- /* no need to register a new backbone */
- goto claim_free_ref;
+ old_backbone_gw = NULL;
+ changed = false;
+ }
+ spin_unlock_bh(&claim->backbone_lock);
+ if (changed) {
batadv_dbg(BATADV_DBG_BLA, bat_priv,
"%s(): changing ownership for %pM, vid %d to gw %pM\n",
__func__, mac, batadv_print_vid(vid),
backbone_gw->orig);
- remove_crc = true;
- }
+ /* add claim address to new backbone_gw */
+ spin_lock_bh(&backbone_gw->crc_lock);
+ backbone_gw->crc ^= claim_crc;
+ spin_unlock_bh(&backbone_gw->crc_lock);
- /* replace backbone_gw atomically and adjust reference counters */
- spin_lock_bh(&claim->backbone_lock);
- old_backbone_gw = claim->backbone_gw;
- kref_get(&backbone_gw->refcount);
- claim->backbone_gw = backbone_gw;
- spin_unlock_bh(&claim->backbone_lock);
+ WRITE_ONCE(backbone_gw->lasttime, jiffies);
+ }
- if (remove_crc) {
+ if (old_backbone_gw) {
/* remove claim address from old backbone_gw */
spin_lock_bh(&old_backbone_gw->crc_lock);
- old_backbone_gw->crc ^= crc16(0, claim->addr, ETH_ALEN);
+ old_backbone_gw->crc ^= claim_crc;
spin_unlock_bh(&old_backbone_gw->crc_lock);
- }
-
- batadv_backbone_gw_put(old_backbone_gw);
- /* add claim address to new backbone_gw */
- spin_lock_bh(&backbone_gw->crc_lock);
- backbone_gw->crc ^= crc16(0, claim->addr, ETH_ALEN);
- spin_unlock_bh(&backbone_gw->crc_lock);
- WRITE_ONCE(backbone_gw->lasttime, jiffies);
+ batadv_backbone_gw_put(old_backbone_gw);
+ }
-claim_free_ref:
batadv_claim_put(claim);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0006/1518] mm/damon/sysfs: read ops_id only once in damon_sysfs_apply_inputs()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (4 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0005/1518] batman-adv: bla: avoid CRC corruption due to parallel claim add Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0007/1518] batman-adv: fix TX priority extraction for BATADV_FORW_MCAST Greg Kroah-Hartman
` (992 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, SJ Park, Andrew Morton, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: SJ Park <sj@kernel.org>
[ Upstream commit 5adaaa28be8a79ddd7e103b171f9d6e14e7fc26e ]
damon_sysfs_apply_inputs() reads ops_id twice. It could race with
ops_id_store(). As a result, the min_region_sz could wrongly be set up.
Read it once.
The user impact is trivial. Sane users ain't update the parameter in
parallel. Even if it happens, the DAMON core layer handles the wrong
min_region_sz (!is_power_of_2()). Even if somehow the race ended up
making a min_region_sz that is different from the user's intention but
still valid, only monitoring itself runs differently than expected. No
critical consequences like kernel panic or memory corruption happen
The issue was discovered [1] by Sashiko.
Link: https://lore.kernel.org/20260715031002.108504-7-sj@kernel.org
Link: https://lore.kernel.org/20260703172417.95426-1-sj@kernel.org [1]
Fixes: 8d009da32f13 ("mm/damon/sysfs: set damon_ctx->min_sz_region only for paddr use case")
Signed-off-by: SJ Park <sj@kernel.org>
Cc: <stable@vger.kernel.org> # 6.18.x
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
mm/damon/sysfs.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/mm/damon/sysfs.c b/mm/damon/sysfs.c
index 53f99f05eb38e..7f52470be36e3 100644
--- a/mm/damon/sysfs.c
+++ b/mm/damon/sysfs.c
@@ -1440,14 +1440,16 @@ static inline bool damon_sysfs_kdamond_running(
static int damon_sysfs_apply_inputs(struct damon_ctx *ctx,
struct damon_sysfs_context *sys_ctx)
{
+ enum damon_ops_id ops_id;
int err;
- err = damon_select_ops(ctx, sys_ctx->ops_id);
+ ops_id = READ_ONCE(sys_ctx->ops_id);
+ err = damon_select_ops(ctx, ops_id);
if (err)
return err;
ctx->addr_unit = READ_ONCE(sys_ctx->addr_unit);
/* addr_unit is respected by only DAMON_OPS_PADDR */
- if (sys_ctx->ops_id == DAMON_OPS_PADDR)
+ if (ops_id == DAMON_OPS_PADDR)
ctx->min_sz_region = max(
DAMON_MIN_REGION / ctx->addr_unit, 1);
err = damon_sysfs_set_attrs(ctx, sys_ctx->attrs);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0007/1518] batman-adv: fix TX priority extraction for BATADV_FORW_MCAST
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (5 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0006/1518] mm/damon/sysfs: read ops_id only once in damon_sysfs_apply_inputs() Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0008/1518] ALSA: usb-audio: Relax __free() variable declarations Greg Kroah-Hartman
` (991 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sven Eckelmann, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sven Eckelmann <sven@narfation.org>
commit 7aedb59b80993c912ab45ce24386a2775150962b upstream.
batadv_mcast_forw_mode_by_count() pushs the skb->data for BATADV_FORW_MCAST
forwarding via batadv_mcast_forw_mcsend(). But the
batadv_skb_set_priority() expects the ethernet header directly before
(skb->data + offset). With the moved skb->data, just some random data would
be accessed to get the priority data.
Move the batadv_skb_set_priority() before the decision about the handling
multicast packets and potential header modifications.
Cc: stable@vger.kernel.org
Fixes: 90039133221e ("batman-adv: mcast: implement multicast packet generation")
[ Context ]
Signed-off-by: Sven Eckelmann <sven@narfation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/batman-adv/mesh-interface.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/net/batman-adv/mesh-interface.c b/net/batman-adv/mesh-interface.c
index 0d598bf39bfc2..3d49fd7ef3e62 100644
--- a/net/batman-adv/mesh-interface.c
+++ b/net/batman-adv/mesh-interface.c
@@ -258,6 +258,8 @@ static netdev_tx_t batadv_interface_tx(struct sk_buff *skb,
if (batadv_compare_eth(ethhdr->h_dest, ectp_addr))
goto dropped;
+ batadv_skb_set_priority(skb, 0);
+
gw_mode = atomic_read(&bat_priv->gw.mode);
if (is_multicast_ether_addr(ethhdr->h_dest)) {
/* if gw mode is off, broadcast every packet */
@@ -291,6 +293,9 @@ static netdev_tx_t batadv_interface_tx(struct sk_buff *skb,
send:
if (do_bcast && !is_broadcast_ether_addr(ethhdr->h_dest)) {
+ /* WARNING batadv_mcast_forw_mode might add more headers
+ * in front of the skb. and might even reallocate the skb
+ */
forw_mode = batadv_mcast_forw_mode(bat_priv, skb, vid,
&mcast_is_routable);
switch (forw_mode) {
@@ -308,8 +313,6 @@ static netdev_tx_t batadv_interface_tx(struct sk_buff *skb,
}
}
- batadv_skb_set_priority(skb, 0);
-
/* ethernet packet should be broadcasted */
if (do_bcast) {
primary_if = batadv_primary_if_get_selected(bat_priv);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0008/1518] ALSA: usb-audio: Relax __free() variable declarations
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (6 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0007/1518] batman-adv: fix TX priority extraction for BATADV_FORW_MCAST Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0009/1518] ASoC: tegra210_mixer: sort the register default table Greg Kroah-Hartman
` (990 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Takashi Iwai, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Takashi Iwai <tiwai@suse.de>
[ Upstream commit 03f705b9ca58b91c6dffe64875ea3d9a38cad9b5 ]
We used to have a variable declaration with __free() initialized with
NULL. This was to keep the old coding style rule, but recently it's
relaxed and rather recommends to follow the new rule to declare in
place of use for __free() -- which avoids potential deadlocks or UAFs
with nested cleanups.
Although the current code has no bug, per se, let's follow the new
standard and move the declaration to the place of assignment (or
directly assign the allocated result) instead of NULL initializations.
Note that there are still a few remaining __free(kfree) with NULL
initializations; they are because of the code complexity (the data
size calculation).
Fixes: 43d4940c944c ("ALSA: usb: scarlett2: Clean ups with guard() and __free()")
Fixes: 46757a3e7d50 ("ALSA: FCP: Add Focusrite Control Protocol driver")
Fixes: f7d306b47a24 ("ALSA: usb-audio: Fix a DMA to stack memory bug")
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Link: https://patch.msgid.link/20251216140634.171890-12-tiwai@suse.de
Stable-dep-of: 4335e3877864 ("ALSA: FCP: do not copy out an uninitialised init response")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/usb/fcp.c | 36 ++++++++++++++++++------------------
sound/usb/mixer_scarlett2.c | 21 ++++++++++-----------
sound/usb/quirks.c | 13 ++++++-------
3 files changed, 34 insertions(+), 36 deletions(-)
--- a/sound/usb/fcp.c
+++ b/sound/usb/fcp.c
@@ -187,10 +187,6 @@ static int fcp_usb(struct usb_mixer_inte
{
struct fcp_data *private = mixer->private_data;
struct usb_device *dev = mixer->chip->dev;
- struct fcp_usb_packet *req __free(kfree) = NULL;
- struct fcp_usb_packet *resp __free(kfree) = NULL;
- size_t req_buf_size = struct_size(req, data, req_size);
- size_t resp_buf_size = struct_size(resp, data, resp_size);
int retries = 0;
const int max_retries = 5;
int err;
@@ -198,10 +194,14 @@ static int fcp_usb(struct usb_mixer_inte
if (!private->urb)
return -ENODEV;
+ struct fcp_usb_packet *req __free(kfree) = NULL;
+ size_t req_buf_size = struct_size(req, data, req_size);
req = kmalloc(req_buf_size, GFP_KERNEL);
if (!req)
return -ENOMEM;
+ struct fcp_usb_packet *resp __free(kfree) = NULL;
+ size_t resp_buf_size = struct_size(resp, data, resp_size);
resp = kmalloc(resp_buf_size, GFP_KERNEL);
if (!resp)
return -ENOMEM;
@@ -305,16 +305,17 @@ retry:
static int fcp_reinit(struct usb_mixer_interface *mixer)
{
struct fcp_data *private = mixer->private_data;
- void *step0_resp __free(kfree) = NULL;
- void *step2_resp __free(kfree) = NULL;
if (private->urb)
return 0;
- step0_resp = kmalloc(private->step0_resp_size, GFP_KERNEL);
+ void *step0_resp __free(kfree) =
+ kmalloc(private->step0_resp_size, GFP_KERNEL);
if (!step0_resp)
return -ENOMEM;
- step2_resp = kmalloc(private->step2_resp_size, GFP_KERNEL);
+
+ void *step2_resp __free(kfree) =
+ kmalloc(private->step2_resp_size, GFP_KERNEL);
if (!step2_resp)
return -ENOMEM;
@@ -472,7 +473,6 @@ static int fcp_ioctl_init(struct usb_mix
struct fcp_init init;
struct usb_device *dev = mixer->chip->dev;
struct fcp_data *private = mixer->private_data;
- void *resp __free(kfree) = NULL;
void *step2_resp;
int err, buf_size;
@@ -493,7 +493,8 @@ static int fcp_ioctl_init(struct usb_mix
/* Allocate response buffer */
buf_size = init.step0_resp_size + init.step2_resp_size;
- resp = kmalloc(buf_size, GFP_KERNEL);
+ void *resp __free(kfree) =
+ kmalloc(buf_size, GFP_KERNEL);
if (!resp)
return -ENOMEM;
@@ -627,7 +628,6 @@ static int fcp_ioctl_set_meter_map(struc
{
struct fcp_meter_map map;
struct fcp_data *private = mixer->private_data;
- s16 *tmp_map __free(kfree) = NULL;
int err;
if (copy_from_user(&map, arg, sizeof(map)))
@@ -650,7 +650,8 @@ static int fcp_ioctl_set_meter_map(struc
return -EINVAL;
/* Allocate and copy the map data */
- tmp_map = memdup_array_user(arg->map, map.map_size, sizeof(s16));
+ s16 *tmp_map __free(kfree) =
+ memdup_array_user(arg->map, map.map_size, sizeof(s16));
if (IS_ERR(tmp_map))
return PTR_ERR(tmp_map);
@@ -660,17 +661,16 @@ static int fcp_ioctl_set_meter_map(struc
/* If the control doesn't exist, create it */
if (!private->meter_ctl) {
- s16 *new_map __free(kfree) = NULL;
- __le32 *meter_levels __free(kfree) = NULL;
-
/* Allocate buffer for the map */
- new_map = kmalloc_array(map.map_size, sizeof(s16), GFP_KERNEL);
+ s16 *new_map __free(kfree) =
+ kmalloc_array(map.map_size, sizeof(s16), GFP_KERNEL);
if (!new_map)
return -ENOMEM;
/* Allocate buffer for reading meter levels */
- meter_levels = kmalloc_array(map.meter_slots, sizeof(__le32),
- GFP_KERNEL);
+ __le32 *meter_levels __free(kfree) =
+ kmalloc_array(map.meter_slots, sizeof(__le32),
+ GFP_KERNEL);
if (!meter_levels)
return -ENOMEM;
--- a/sound/usb/mixer_scarlett2.c
+++ b/sound/usb/mixer_scarlett2.c
@@ -2499,18 +2499,18 @@ static int scarlett2_usb(
{
struct scarlett2_data *private = mixer->private_data;
struct usb_device *dev = mixer->chip->dev;
- struct scarlett2_usb_packet *req __free(kfree) = NULL;
- struct scarlett2_usb_packet *resp __free(kfree) = NULL;
- size_t req_buf_size = struct_size(req, data, req_size);
- size_t resp_buf_size = struct_size(resp, data, resp_size);
int retries = 0;
const int max_retries = 5;
int err;
+ struct scarlett2_usb_packet *req __free(kfree) = NULL;
+ size_t req_buf_size = struct_size(req, data, req_size);
req = kmalloc(req_buf_size, GFP_KERNEL);
if (!req)
return -ENOMEM;
+ struct scarlett2_usb_packet *resp __free(kfree) = NULL;
+ size_t resp_buf_size = struct_size(resp, data, resp_size);
resp = kmalloc(resp_buf_size, GFP_KERNEL);
if (!resp)
return -ENOMEM;
@@ -4065,9 +4065,9 @@ static int scarlett2_input_select_ctl_in
struct scarlett2_data *private = mixer->private_data;
int inputs = private->info->gain_input_count;
int i, err;
- char **values __free(kfree) = NULL;
+ char **values __free(kfree) =
+ kcalloc(inputs, sizeof(char *), GFP_KERNEL);
- values = kcalloc(inputs, sizeof(char *), GFP_KERNEL);
if (!values)
return -ENOMEM;
@@ -9293,8 +9293,6 @@ static long scarlett2_hwdep_read(struct
__le32 len;
} __packed req;
- u8 *resp __free(kfree) = NULL;
-
/* Flash segment must first be selected */
if (private->flash_write_state != SCARLETT2_FLASH_WRITE_STATE_SELECTED)
return -EINVAL;
@@ -9332,7 +9330,8 @@ static long scarlett2_hwdep_read(struct
req.offset = cpu_to_le32(*offset);
req.len = cpu_to_le32(count);
- resp = kzalloc(count, GFP_KERNEL);
+ u8 *resp __free(kfree) =
+ kzalloc(count, GFP_KERNEL);
if (!resp)
return -ENOMEM;
@@ -9480,7 +9479,6 @@ static ssize_t scarlett2_devmap_read(
loff_t pos)
{
struct usb_mixer_interface *mixer = entry->private_data;
- u8 *resp_buf __free(kfree) = NULL;
const size_t block_size = SCARLETT2_DEVMAP_BLOCK_SIZE;
size_t copied = 0;
@@ -9490,7 +9488,8 @@ static ssize_t scarlett2_devmap_read(
if (pos + count > entry->size)
count = entry->size - pos;
- resp_buf = kmalloc(block_size, GFP_KERNEL);
+ u8 *resp_buf __free(kfree) =
+ kmalloc(block_size, GFP_KERNEL);
if (!resp_buf)
return -ENOMEM;
--- a/sound/usb/quirks.c
+++ b/sound/usb/quirks.c
@@ -555,7 +555,6 @@ int snd_usb_create_quirk(struct snd_usb_
static int snd_usb_extigy_boot_quirk(struct usb_device *dev, struct usb_interface *intf)
{
struct usb_host_config *config = dev->actconfig;
- struct usb_device_descriptor *new_device_descriptor __free(kfree) = NULL;
int err;
if (le16_to_cpu(get_cfg_desc(config)->wTotalLength) == EXTIGY_FIRMWARE_SIZE_OLD ||
@@ -566,8 +565,8 @@ static int snd_usb_extigy_boot_quirk(str
0x10, 0x43, 0x0001, 0x000a, NULL, 0);
if (err < 0)
dev_dbg(&dev->dev, "error sending boot message: %d\n", err);
-
- new_device_descriptor = kmalloc(sizeof(*new_device_descriptor), GFP_KERNEL);
+ struct usb_device_descriptor *new_device_descriptor __free(kfree) =
+ kmalloc(sizeof(*new_device_descriptor), GFP_KERNEL);
if (!new_device_descriptor)
return -ENOMEM;
err = usb_get_descriptor(dev, USB_DT_DEVICE, 0,
@@ -910,7 +909,6 @@ static void mbox2_setup_48_24_magic(stru
static int snd_usb_mbox2_boot_quirk(struct usb_device *dev)
{
struct usb_host_config *config = dev->actconfig;
- struct usb_device_descriptor *new_device_descriptor __free(kfree) = NULL;
int err;
u8 bootresponse[0x12];
int fwsize;
@@ -945,7 +943,8 @@ static int snd_usb_mbox2_boot_quirk(stru
dev_dbg(&dev->dev, "device initialised!\n");
- new_device_descriptor = kmalloc(sizeof(*new_device_descriptor), GFP_KERNEL);
+ struct usb_device_descriptor *new_device_descriptor __free(kfree) =
+ kmalloc(sizeof(*new_device_descriptor), GFP_KERNEL);
if (!new_device_descriptor)
return -ENOMEM;
@@ -1267,7 +1266,6 @@ static void mbox3_setup_defaults(struct
static int snd_usb_mbox3_boot_quirk(struct usb_device *dev)
{
struct usb_host_config *config = dev->actconfig;
- struct usb_device_descriptor *new_device_descriptor __free(kfree) = NULL;
int err;
int descriptor_size;
@@ -1280,7 +1278,8 @@ static int snd_usb_mbox3_boot_quirk(stru
dev_dbg(&dev->dev, "MBOX3: device initialised!\n");
- new_device_descriptor = kmalloc(sizeof(*new_device_descriptor), GFP_KERNEL);
+ struct usb_device_descriptor *new_device_descriptor __free(kfree) =
+ kmalloc(sizeof(*new_device_descriptor), GFP_KERNEL);
if (!new_device_descriptor)
return -ENOMEM;
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0009/1518] ASoC: tegra210_mixer: sort the register default table
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (7 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0008/1518] ALSA: usb-audio: Relax __free() variable declarations Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0010/1518] dma-buf: dma-heap: dont publish fd before copy_to_user() succeeds Greg Kroah-Hartman
` (989 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Ujfalusi, Mark Brown,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
[ Upstream commit f70bc276fc7f712ff5c8e995d5050558a3198df2 ]
reg_defaults must be sorted by ascending register address, as
regcache_lookup_reg() locates entries in it with bsearch(). See commit
fd80df352ba1 ("regcache: Add support for sorting defaults arrays").
TEGRA210_MIXER_ENABLE (0x400) is the last entry of the table, after
TEGRA210_MIXER_PEAKM_RAM_CTRL (0x434), which makes it unreachable.
regcache_reg_needs_sync() then cannot compare it against its default and
reports that a sync is needed, so it is written to the device on every
regcache_sync() even when it was never touched.
Sort the table by register address.
Fixes: 05bb3d5ec64a ("ASoC: tegra: Add Tegra210 based Mixer driver")
Cc: stable@vger.kernel.org
Signed-off-by: Peter Ujfalusi <peter.ujfalusi@linux.intel.com>
Link: https://patch.msgid.link/20260805122748.13090-4-peter.ujfalusi@linux.intel.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Stable-dep-of: 5442b8093a2f ("ASoC: tegra: Fix the MIXER enable default value")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/soc/tegra/tegra210_mixer.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/sound/soc/tegra/tegra210_mixer.c
+++ b/sound/soc/tegra/tegra210_mixer.c
@@ -57,10 +57,10 @@ static const struct reg_default tegra210
MIXER_TX_REG_DEFAULTS(3),
MIXER_TX_REG_DEFAULTS(4),
+ { TEGRA210_MIXER_ENABLE, 0x1 },
{ TEGRA210_MIXER_CG, 0x00000001},
{ TEGRA210_MIXER_GAIN_CFG_RAM_CTRL, 0x00004000},
{ TEGRA210_MIXER_PEAKM_RAM_CTRL, 0x00004000},
- { TEGRA210_MIXER_ENABLE, 0x1 },
};
/* Default gain parameters */
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0010/1518] dma-buf: dma-heap: dont publish fd before copy_to_user() succeeds
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (8 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0009/1518] ASoC: tegra210_mixer: sort the register default table Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0011/1518] i3c: master: Fix device_register() error path Greg Kroah-Hartman
` (988 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, T.J. Mercier, Christian König,
Sumit Semwal, Baineng Shou, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Baineng Shou <shoubaineng@gmail.com>
[ Upstream commit 30d0aff2c65a277135cfd8ea28fa1ee75e0ea4e0 ]
DMA_HEAP_IOCTL_ALLOC allocates a dma-buf and installs an fd into the
caller's fd table via dma_buf_fd() -> fd_install() before
dma_heap_ioctl() copies the result back to userspace. If the trailing
copy_to_user() fails, userspace never learns the fd number, but the
fd (and the underlying dma-buf reference) are already visible to
other threads in the same process and are leaked for the lifetime of
the process.
The obvious "close it on the failure path" fix is unsafe: once
fd_install() has run, another thread can already dup() the fd, send
it via SCM_RIGHTS, or close() it and let its number be reused, so a
subsequent close_fd() from the ioctl path can operate on an unrelated
file. This was pointed out by Christian König on v1 [1].
Restructure the allocation path so that fd_install() is the last,
unfailable step of a successful ioctl:
1. heap->ops->allocate() creates the dma_buf.
2. get_unused_fd_flags() reserves an fd number in the caller's
fd table without publishing it, so
no other thread can observe it.
3. copy_to_user() delivers the fd number to userspace;
on failure the fd is returned with
put_unused_fd() and the dma_buf
reference is dropped with
dma_buf_put(), leaving no user-
visible state behind.
4. dma_buf_fd_install() publishes the fd and emits the
trace_dma_buf_fd tracepoint -- from
here on the ioctl cannot fail.
A new dma_buf_fd_install() helper is introduced in dma-buf.c to wrap
fd_install() together with the DMA_BUF_TRACE() call, preserving the
export tracing that dma_buf_fd() provides. dma_heap_ioctl_allocate()
is refactored to return the struct dma_buf * directly (returning
ERR_PTR on failure) so the caller holds the dmabuf reference across
steps 3 and 4.
The failure at step 3 is easily reachable from userspace: pass a
struct dma_heap_allocation_data that lives in a page whose protection
is flipped to PROT_READ between copy_from_user() and copy_to_user()
(e.g. via mprotect()). Before this change each such ioctl leaks one
dmabuf fd; after it, the fd table is unchanged on failure and only
/dev/dma_heap/<name> remains open.
No UAPI or heap-driver interface change.
[1] https://lore.kernel.org/dri-devel/175e98de-f414-47d7-81c1-c0fe0a8f7f62@amd.com/
Fixes: c02a81fba74f ("dma-buf: Add dma-buf heaps framework")
Cc: stable@vger.kernel.org
Reviewed-by: T.J. Mercier <tjmercier@google.com>
Acked-by: Christian König <christian.koenig@amd.com>
Acked-by: Sumit Semwal <sumit.semwal@linaro.org>
Signed-off-by: Baineng Shou <shoubaineng@gmail.com>
Link: https://lore.kernel.org/r/20260817050457.1005285-2-shoubaineng@gmail.com
Signed-off-by: Christian König <christian.koenig@amd.com>
Stable adaptation for 6.18:
- Resolve the dma-heap conflict without importing the absent mem_accounting
module parameter; retain the existing kzalloc() form.
- This tree has neither DMA_BUF_TRACE nor trace_dma_buf_fd. Omit the new
dma-buf.c function and export, and provide dma_buf_fd_install as a
single-evaluation macro around the existing fd_install() in dma-buf.h.
This preserves the reserved-fd publication semantics without adding
functions or importing the unrelated tracing infrastructure.
- Retain the heap allocation and usercopy cleanup changes, and expose the
interface needed for the target FastRPC fix to apply unchanged.
[ sashal: Reduced backport -- upstream 30d0aff2c65a2 touches 3 file(s), this
backport carries 2. Not backported here:
drivers/dma-buf/dma-buf.c
This note is generated from the file lists only; see the resolution record
for the reasoning. ]
Stable-dep-of: a4a1a2bfcb29 ("misc: fastrpc: don't publish fd before copy_to_user() succeeds")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/dma-buf/dma-heap.c | 80 ++++++++++++++++++++++-----------------------
include/linux/dma-buf.h | 5 ++
2 files changed, 45 insertions(+), 40 deletions(-)
--- a/drivers/dma-buf/dma-heap.c
+++ b/drivers/dma-buf/dma-heap.c
@@ -49,33 +49,6 @@ static dev_t dma_heap_devt;
static struct class *dma_heap_class;
static DEFINE_XARRAY_ALLOC(dma_heap_minors);
-static int dma_heap_buffer_alloc(struct dma_heap *heap, size_t len,
- u32 fd_flags,
- u64 heap_flags)
-{
- struct dma_buf *dmabuf;
- int fd;
-
- /*
- * Allocations from all heaps have to begin
- * and end on page boundaries.
- */
- len = PAGE_ALIGN(len);
- if (!len)
- return -EINVAL;
-
- dmabuf = heap->ops->allocate(heap, len, fd_flags, heap_flags);
- if (IS_ERR(dmabuf))
- return PTR_ERR(dmabuf);
-
- fd = dma_buf_fd(dmabuf, fd_flags);
- if (fd < 0) {
- dma_buf_put(dmabuf);
- /* just return, as put will call release and that will free */
- }
- return fd;
-}
-
static int dma_heap_open(struct inode *inode, struct file *file)
{
struct dma_heap *heap;
@@ -93,30 +66,42 @@ static int dma_heap_open(struct inode *i
return 0;
}
-static long dma_heap_ioctl_allocate(struct file *file, void *data)
+static struct dma_buf *dma_heap_ioctl_allocate(struct file *file, void *data)
{
struct dma_heap_allocation_data *heap_allocation = data;
struct dma_heap *heap = file->private_data;
+ struct dma_buf *dmabuf;
int fd;
+ size_t len;
if (heap_allocation->fd)
- return -EINVAL;
+ return ERR_PTR(-EINVAL);
if (heap_allocation->fd_flags & ~DMA_HEAP_VALID_FD_FLAGS)
- return -EINVAL;
+ return ERR_PTR(-EINVAL);
if (heap_allocation->heap_flags & ~DMA_HEAP_VALID_HEAP_FLAGS)
- return -EINVAL;
+ return ERR_PTR(-EINVAL);
+
+ len = PAGE_ALIGN(heap_allocation->len);
+ if (!len)
+ return ERR_PTR(-EINVAL);
- fd = dma_heap_buffer_alloc(heap, heap_allocation->len,
- heap_allocation->fd_flags,
- heap_allocation->heap_flags);
- if (fd < 0)
- return fd;
+ dmabuf = heap->ops->allocate(heap, len, heap_allocation->fd_flags,
+ heap_allocation->heap_flags);
+
+ if (IS_ERR(dmabuf))
+ return dmabuf;
+
+ fd = get_unused_fd_flags(heap_allocation->fd_flags);
+ if (fd < 0) {
+ dma_buf_put(dmabuf);
+ return ERR_PTR(fd);
+ }
heap_allocation->fd = fd;
- return 0;
+ return dmabuf;
}
static unsigned int dma_heap_ioctl_cmds[] = {
@@ -132,6 +117,8 @@ static long dma_heap_ioctl(struct file *
unsigned int in_size, out_size, drv_size, ksize;
int nr = _IOC_NR(ucmd);
int ret = 0;
+ int fd;
+ struct dma_buf *dmabuf;
if (nr >= ARRAY_SIZE(dma_heap_ioctl_cmds))
return -EINVAL;
@@ -168,15 +155,28 @@ static long dma_heap_ioctl(struct file *
switch (kcmd) {
case DMA_HEAP_IOCTL_ALLOC:
- ret = dma_heap_ioctl_allocate(file, kdata);
+ dmabuf = dma_heap_ioctl_allocate(file, kdata);
+
+ if (IS_ERR(dmabuf)) {
+ ret = PTR_ERR(dmabuf);
+ break;
+ }
+
+ fd = ((struct dma_heap_allocation_data *)kdata)->fd;
+ if (copy_to_user((void __user *)arg, kdata, out_size) != 0) {
+ put_unused_fd(fd);
+ dma_buf_put(dmabuf);
+ ret = -EFAULT;
+ } else {
+ dma_buf_fd_install(dmabuf, fd);
+ }
+
break;
default:
ret = -ENOTTY;
goto err;
}
- if (copy_to_user((void __user *)arg, kdata, out_size) != 0)
- ret = -EFAULT;
err:
if (kdata != stack_kdata)
kfree(kdata);
--- a/include/linux/dma-buf.h
+++ b/include/linux/dma-buf.h
@@ -582,6 +582,11 @@ void dma_buf_unpin(struct dma_buf_attach
struct dma_buf *dma_buf_export(const struct dma_buf_export_info *exp_info);
int dma_buf_fd(struct dma_buf *dmabuf, int flags);
+/*
+ * This tree has no DMA-BUF fd tracepoint, so publishing a reserved fd only
+ * requires fd_install(). Call this after all fallible work has succeeded.
+ */
+#define dma_buf_fd_install(dmabuf, fd) fd_install((fd), (dmabuf)->file)
struct dma_buf *dma_buf_get(int fd);
void dma_buf_put(struct dma_buf *dmabuf);
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0011/1518] i3c: master: Fix device_register() error path
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (9 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0010/1518] dma-buf: dma-heap: dont publish fd before copy_to_user() succeeds Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0012/1518] mtd: rawnand: pl353: Add message about ECC mode Greg Kroah-Hartman
` (987 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot, Adrian Hunter, Frank Li,
Alexandre Belloni, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Adrian Hunter <adrian.hunter@intel.com>
[ Upstream commit 74be657d98a8d684c0475f3cbd450ef2a30ffc73 ]
When device_register() fails in i3c_master_register_new_i3c_devs(),
put_device() is called to drop the reference taken by
device_register(). That drops the last reference, so the device's
release callback i3c_device_release() runs and frees the i3c_device.
Two problems follow from that:
i3c_device_release() does WARN_ON(i3cdev->desc), so it warns because
desc->dev->desc still points back at the descriptor. Clear it before
calling put_device().
After put_device() frees the i3c_device, desc->dev is left pointing at
freed memory, so clear desc->dev as well. That prevents, for example,
i3c_master_unregister_i3c_devs() seeing desc->dev as non-NULL and
dereferencing it.
Reported-by: sashiko-bot@kernel.org
Link: https://lore.kernel.org/linux-i3c/20260701203053.8F3971F000E9@smtp.kernel.org/
Fixes: cab63f6488761 ("i3c: Fix potential refcount leak in i3c_master_register_new_i3c_devs")
Signed-off-by: Adrian Hunter <adrian.hunter@intel.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260702183644.60827-1-adrian.hunter@intel.com
Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
Stable-dep-of: 456f832e5fc2 ("i3c: master: Fix recursive locking during device registration")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i3c/master.c | 2 ++
1 file changed, 2 insertions(+)
--- a/drivers/i3c/master.c
+++ b/drivers/i3c/master.c
@@ -1817,7 +1817,9 @@ i3c_master_register_new_i3c_devs(struct
if (ret) {
dev_err(&master->dev,
"Failed to add I3C device (err = %d)\n", ret);
+ desc->dev->desc = NULL;
put_device(&desc->dev->dev);
+ desc->dev = NULL;
}
}
}
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0012/1518] mtd: rawnand: pl353: Add message about ECC mode
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (10 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0011/1518] i3c: master: Fix device_register() error path Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0013/1518] net/mlx5e: SHAMPO, Always calculate page size Greg Kroah-Hartman
` (986 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Andrea Scian, Miquel Raynal,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Andrea Scian <andrea.scian@dave.eu>
[ Upstream commit 1e06dbfdfb851170b243d6498e442b449324c664 ]
This just add some information on kernel log about the selected ECC
Signed-off-by: Andrea Scian <andrea.scian@dave.eu>
Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com>
Stable-dep-of: 80ecacd054ff ("mtd: rawnand: pl353: Make sure we use the monolithic helpers for raw accesses")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mtd/nand/raw/pl35x-nand-controller.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/mtd/nand/raw/pl35x-nand-controller.c
+++ b/drivers/mtd/nand/raw/pl35x-nand-controller.c
@@ -973,15 +973,18 @@ static int pl35x_nand_attach_chip(struct
switch (chip->ecc.engine_type) {
case NAND_ECC_ENGINE_TYPE_ON_DIE:
+ dev_dbg(nfc->dev, "Using on-die ECC\n");
/* Keep these legacy BBT descriptors for ON_DIE situations */
chip->bbt_td = &bbt_main_descr;
chip->bbt_md = &bbt_mirror_descr;
fallthrough;
case NAND_ECC_ENGINE_TYPE_NONE:
case NAND_ECC_ENGINE_TYPE_SOFT:
+ dev_dbg(nfc->dev, "Using software ECC (Hamming 1-bit/512B)\n");
chip->ecc.write_page_raw = nand_monolithic_write_page_raw;
break;
case NAND_ECC_ENGINE_TYPE_ON_HOST:
+ dev_dbg(nfc->dev, "Using hardware ECC\n");
ret = pl35x_nand_init_hw_ecc_controller(nfc, chip);
if (ret)
return ret;
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0013/1518] net/mlx5e: SHAMPO, Always calculate page size
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (11 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0012/1518] mtd: rawnand: pl353: Add message about ECC mode Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0014/1518] nvme: fold nvme_config_discard() into nvme_update_disk_info() Greg Kroah-Hartman
` (985 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dragos Tatulea, Cosmin Ratiu,
Tariq Toukan, Paolo Abeni, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dragos Tatulea <dtatulea@nvidia.com>
[ Upstream commit dff1c3164a69284ac9fedb1c25d4c008139e9fb8 ]
Adapt the rx path in SHAMPO mode to calculate page size based on
configured page_shift when dealing with payload data.
This is necessary as an upcoming patch will add support for using
different page sizes.
This change has no functional changes.
Signed-off-by: Dragos Tatulea <dtatulea@nvidia.com>
Reviewed-by: Cosmin Ratiu <cratiu@nvidia.com>
Signed-off-by: Tariq Toukan <tariqt@nvidia.com>
Link: https://patch.msgid.link/20260223204155.1783580-9-tariqt@nvidia.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Backport to 6.18: preserve the XDP fragment accounting fix from
7d7342a18fadc ("net/mlx5e: RX, Fix XDP multi-buf frag counting for
striding RQ"). Keep new_nr_frags and the original frag_page endpoint;
only replace PAGE_SIZE with page_size in the truesize adjustment.
Reintroducing the old frag_page rewind would break page reference
accounting for fragments consumed by XDP.
Retain the page-size calculations and SHAMPO space-check changes so
e2466392a0b8496000e12181cb1ee1535eb0da25 ("net/mlx5e: do not HW-GRO
coalesce small frames") applies without modification. No functions
are added.
Stable-dep-of: e2466392a0b8 ("net/mlx5e: do not HW-GRO coalesce small frames")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/mellanox/mlx5/core/en_rx.c | 34 +++++++++++++++---------
1 file changed, 22 insertions(+), 12 deletions(-)
--- a/drivers/net/ethernet/mellanox/mlx5/core/en_rx.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/en_rx.c
@@ -2014,11 +2014,14 @@ mlx5e_shampo_fill_skb_data(struct sk_buf
struct mlx5e_frag_page *frag_page,
u32 data_bcnt, u32 data_offset)
{
+ u32 page_size = BIT(rq->mpwqe.page_shift);
+
net_prefetchw(skb->data);
do {
/* Non-linear mode, hence non-XSK, which always uses PAGE_SIZE. */
- u32 pg_consumed_bytes = min_t(u32, PAGE_SIZE - data_offset, data_bcnt);
+ u32 pg_consumed_bytes = min_t(u32, page_size - data_offset,
+ data_bcnt);
unsigned int truesize = pg_consumed_bytes;
mlx5e_add_skb_frag(rq, skb, frag_page, data_offset,
@@ -2039,6 +2042,7 @@ mlx5e_skb_from_cqe_mpwrq_nonlinear(struc
u16 headlen = min_t(u16, MLX5E_RX_MAX_HEAD, cqe_bcnt);
struct mlx5e_frag_page *head_page = frag_page;
struct mlx5e_xdp_buff *mxbuf = &rq->mxbuf;
+ u32 page_size = BIT(rq->mpwqe.page_shift);
u32 frag_offset = head_offset;
u32 byte_cnt = cqe_bcnt;
struct skb_shared_info *sinfo;
@@ -2084,9 +2088,9 @@ mlx5e_skb_from_cqe_mpwrq_nonlinear(struc
linear_hr = skb_headroom(skb);
linear_data_len = headlen;
linear_frame_sz = MLX5_SKB_FRAG_SZ(skb_end_offset(skb));
- if (unlikely(frag_offset >= PAGE_SIZE)) {
+ if (unlikely(frag_offset >= page_size)) {
frag_page++;
- frag_offset -= PAGE_SIZE;
+ frag_offset -= page_size;
}
}
@@ -2098,7 +2102,7 @@ mlx5e_skb_from_cqe_mpwrq_nonlinear(struc
while (byte_cnt) {
/* Non-linear mode, hence non-XSK, which always uses PAGE_SIZE. */
pg_consumed_bytes =
- min_t(u32, PAGE_SIZE - frag_offset, byte_cnt);
+ min_t(u32, page_size - frag_offset, byte_cnt);
if (test_bit(MLX5E_RQ_STATE_SHAMPO, &rq->state))
truesize += pg_consumed_bytes;
@@ -2135,7 +2139,7 @@ mlx5e_skb_from_cqe_mpwrq_nonlinear(struc
new_nr_frags = sinfo->nr_frags;
nr_frags_free = old_nr_frags - new_nr_frags;
if (unlikely(nr_frags_free))
- truesize -= (nr_frags_free - 1) * PAGE_SIZE +
+ truesize -= (nr_frags_free - 1) * page_size +
ALIGN(pg_consumed_bytes,
BIT(rq->mpwqe.log_stride_sz));
@@ -2349,15 +2353,16 @@ mlx5e_shampo_flush_skb(struct mlx5e_rq *
rq->hw_gro_data->skb = NULL;
}
-static bool
-mlx5e_hw_gro_skb_has_enough_space(struct sk_buff *skb, u16 data_bcnt)
+static bool mlx5e_hw_gro_skb_has_enough_space(struct sk_buff *skb,
+ u16 data_bcnt,
+ u32 page_size)
{
int nr_frags = skb_shinfo(skb)->nr_frags;
- if (PAGE_SIZE >= GRO_LEGACY_MAX_SIZE)
+ if (page_size >= GRO_LEGACY_MAX_SIZE)
return skb->len + data_bcnt <= GRO_LEGACY_MAX_SIZE;
else
- return PAGE_SIZE * nr_frags + data_bcnt <= GRO_LEGACY_MAX_SIZE;
+ return page_size * nr_frags + data_bcnt <= GRO_LEGACY_MAX_SIZE;
}
static void mlx5e_handle_rx_cqe_mpwrq_shampo(struct mlx5e_rq *rq, struct mlx5_cqe64 *cqe)
@@ -2366,18 +2371,19 @@ static void mlx5e_handle_rx_cqe_mpwrq_sh
u16 header_index = mlx5e_shampo_get_cqe_header_index(rq, cqe);
u32 wqe_offset = be32_to_cpu(cqe->shampo.data_offset);
u16 cstrides = mpwrq_get_cqe_consumed_strides(cqe);
- u32 data_offset = wqe_offset & (PAGE_SIZE - 1);
u32 cqe_bcnt = mpwrq_get_cqe_byte_cnt(cqe);
u16 wqe_id = be16_to_cpu(cqe->wqe_id);
- u32 page_idx = wqe_offset >> PAGE_SHIFT;
u16 head_size = cqe->shampo.header_size;
struct sk_buff **skb = &rq->hw_gro_data->skb;
bool flush = cqe->shampo.flush;
bool match = cqe->shampo.match;
+ u32 page_size = BIT(rq->mpwqe.page_shift);
struct mlx5e_rq_stats *stats = rq->stats;
struct mlx5e_rx_wqe_ll *wqe;
struct mlx5e_mpw_info *wi;
struct mlx5_wq_ll *wq;
+ u32 data_offset;
+ u32 page_idx;
wi = mlx5e_get_mpw_info(rq, wqe_id);
wi->consumed_strides += cstrides;
@@ -2393,7 +2399,11 @@ static void mlx5e_handle_rx_cqe_mpwrq_sh
goto mpwrq_cqe_out;
}
- if (*skb && (!match || !(mlx5e_hw_gro_skb_has_enough_space(*skb, data_bcnt)))) {
+ data_offset = wqe_offset & (page_size - 1);
+ page_idx = wqe_offset >> rq->mpwqe.page_shift;
+ if (*skb &&
+ !(match && mlx5e_hw_gro_skb_has_enough_space(*skb, data_bcnt,
+ page_size))) {
match = false;
mlx5e_shampo_flush_skb(rq, cqe, match);
}
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0014/1518] nvme: fold nvme_config_discard() into nvme_update_disk_info()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (12 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0013/1518] net/mlx5e: SHAMPO, Always calculate page size Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0015/1518] PCI: Introduce PCI_SLOT_PLACEHOLDER constant for slot_nr placeholder value Greg Kroah-Hartman
` (984 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Caleb Sander Mateos,
Christoph Hellwig, Keith Busch, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Caleb Sander Mateos <csander@purestorage.com>
[ Upstream commit 9110b85244f142ca4bcaea27be408c778d3c48d0 ]
The choice of what queue limits are set in nvme_update_disk_info() vs.
nvme_config_discard() seems a bit arbitrary. A subsequent commit will
compute the discard_granularity limit using struct nvme_id_ns, which is
only passed to nvme_update_disk_info() currently. So move the logic in
nvme_config_discard() to nvme_update_disk_info(). Replace several
instances of ns->ctrl in nvme_update_disk_info() with the ctrl variable
brought from nvme_config_discard().
Signed-off-by: Caleb Sander Mateos <csander@purestorage.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Keith Busch <kbusch@kernel.org>
Stable-dep-of: 3838e80fcfb3 ("nvme: skip the zoned limits update if the zone info query failed")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/nvme/host/core.c | 43 +++++++++++++++++++------------------------
1 file changed, 19 insertions(+), 24 deletions(-)
--- a/drivers/nvme/host/core.c
+++ b/drivers/nvme/host/core.c
@@ -1882,26 +1882,6 @@ static bool nvme_init_integrity(struct n
return true;
}
-static void nvme_config_discard(struct nvme_ns *ns, struct queue_limits *lim)
-{
- struct nvme_ctrl *ctrl = ns->ctrl;
-
- if (ctrl->dmrsl && ctrl->dmrsl <= nvme_sect_to_lba(ns->head, UINT_MAX))
- lim->max_hw_discard_sectors =
- nvme_lba_to_sect(ns->head, ctrl->dmrsl);
- else if (ctrl->oncs & NVME_CTRL_ONCS_DSM)
- lim->max_hw_discard_sectors = UINT_MAX;
- else
- lim->max_hw_discard_sectors = 0;
-
- lim->discard_granularity = lim->logical_block_size;
-
- if (ctrl->dmrl)
- lim->max_discard_segments = ctrl->dmrl;
- else
- lim->max_discard_segments = NVME_DSM_MAX_RANGES;
-}
-
static bool nvme_ns_ids_equal(struct nvme_ns_ids *a, struct nvme_ns_ids *b)
{
return uuid_equal(&a->uuid, &b->uuid) &&
@@ -2084,6 +2064,7 @@ static bool nvme_update_disk_info(struct
struct queue_limits *lim)
{
struct nvme_ns_head *head = ns->head;
+ struct nvme_ctrl *ctrl = ns->ctrl;
u32 bs = 1U << head->lba_shift;
u32 atomic_bs, phys_bs, io_opt = 0;
bool valid = true;
@@ -2118,11 +2099,26 @@ static bool nvme_update_disk_info(struct
lim->physical_block_size = min(phys_bs, atomic_bs);
lim->io_min = phys_bs;
lim->io_opt = io_opt;
- if ((ns->ctrl->quirks & NVME_QUIRK_DEALLOCATE_ZEROES) &&
- (ns->ctrl->oncs & NVME_CTRL_ONCS_DSM))
+ if ((ctrl->quirks & NVME_QUIRK_DEALLOCATE_ZEROES) &&
+ (ctrl->oncs & NVME_CTRL_ONCS_DSM))
lim->max_write_zeroes_sectors = UINT_MAX;
else
- lim->max_write_zeroes_sectors = ns->ctrl->max_zeroes_sectors;
+ lim->max_write_zeroes_sectors = ctrl->max_zeroes_sectors;
+
+ if (ctrl->dmrsl && ctrl->dmrsl <= nvme_sect_to_lba(ns->head, UINT_MAX))
+ lim->max_hw_discard_sectors =
+ nvme_lba_to_sect(ns->head, ctrl->dmrsl);
+ else if (ctrl->oncs & NVME_CTRL_ONCS_DSM)
+ lim->max_hw_discard_sectors = UINT_MAX;
+ else
+ lim->max_hw_discard_sectors = 0;
+
+ lim->discard_granularity = lim->logical_block_size;
+
+ if (ctrl->dmrl)
+ lim->max_discard_segments = ctrl->dmrl;
+ else
+ lim->max_discard_segments = NVME_DSM_MAX_RANGES;
return valid;
}
@@ -2387,7 +2383,6 @@ static int nvme_update_ns_info_block(str
if (!nvme_update_disk_info(ns, id, &lim))
capacity = 0;
- nvme_config_discard(ns, &lim);
if (IS_ENABLED(CONFIG_BLK_DEV_ZONED) &&
ns->head->ids.csi == NVME_CSI_ZNS)
nvme_update_zone_info(ns, &lim, &zi);
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0015/1518] PCI: Introduce PCI_SLOT_PLACEHOLDER constant for slot_nr placeholder value
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (13 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0014/1518] nvme: fold nvme_config_discard() into nvme_update_disk_info() Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0016/1518] perf/core: Fix deadlock in perf_mmap() failure path Greg Kroah-Hartman
` (983 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bjorn Helgaas, Farhan Ali,
Madhavan Srinivasan, Tyrel Datwyler, linuxppc-dev, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Farhan Ali <alifm@linux.ibm.com>
[ Upstream commit c243e6c470c4695965cc8287767925bc1d9a7867 ]
Introduce a constant for placeholder value and update the kerneldoc for
pci_create_slot() to reference PCI_SLOT_PLACEHOLDER instead of -1
throughout. No functional change.
Suggested-by: Bjorn Helgaas <bhelgaas@google.com>
Signed-off-by: Farhan Ali <alifm@linux.ibm.com>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Cc: Madhavan Srinivasan <maddy@linux.ibm.com>
Cc: Tyrel Datwyler <tyreld@linux.ibm.com>
Cc: linuxppc-dev@lists.ozlabs.org
Link: https://patch.msgid.link/20260805165518.794-2-alifm@linux.ibm.com
Stable backport: this tree predates 102c8b26b54e ("PCI: Allow all bus
devices to use the same slot"). Include its PCI_SLOT_ALL_DEVICES definition,
slot-number documentation, and core matching/address handling so that
subsequent commit dcc5bec09e23 ("PCI: Allow per function PCI slots to fix
slot reset on s390") applies without conflicts. Keep the PCIe hotplug
callers unchanged; enabling bus-wide slots there is outside this dependency.
Retain the stable tree's kzalloc() and ATTRIBUTE_GROUPS() implementations.
The placeholder conversion covers both PowerPC hotplug callers and the
PCI core. All code changes stay within existing functions.
Stable-dep-of: dcc5bec09e23 ("PCI: Allow per function PCI slots to fix slot reset on s390")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/pci/hotplug/pnv_php.c | 2 -
drivers/pci/hotplug/rpaphp_slot.c | 2 -
drivers/pci/slot.c | 50 ++++++++++++++++++++++++++++----------
include/linux/pci.h | 13 +++++++++
4 files changed, 51 insertions(+), 16 deletions(-)
--- a/drivers/pci/hotplug/pnv_php.c
+++ b/drivers/pci/hotplug/pnv_php.c
@@ -813,7 +813,7 @@ static struct pnv_php_slot *pnv_php_allo
if (dn->child && PCI_DN(dn->child))
php_slot->slot_no = PCI_SLOT(PCI_DN(dn->child)->devfn);
else
- php_slot->slot_no = -1; /* Placeholder slot */
+ php_slot->slot_no = PCI_SLOT_PLACEHOLDER; /* Placeholder slot */
kref_init(&php_slot->kref);
php_slot->state = PNV_PHP_STATE_INITIALIZED;
--- a/drivers/pci/hotplug/rpaphp_slot.c
+++ b/drivers/pci/hotplug/rpaphp_slot.c
@@ -85,7 +85,7 @@ int rpaphp_register_slot(struct slot *sl
struct device_node *child;
u32 my_index;
int retval;
- int slotno = -1;
+ int slotno = PCI_SLOT_PLACEHOLDER;
dbg("%s registering slot:path[%pOF] index[%x], name[%s] pdomain[%x] type[%d]\n",
__func__, slot->dn, slot->index, slot->name,
--- a/drivers/pci/slot.c
+++ b/drivers/pci/slot.c
@@ -37,11 +37,20 @@ static const struct sysfs_ops pci_slot_s
static ssize_t address_read_file(struct pci_slot *slot, char *buf)
{
- if (slot->number == 0xff)
+ if (slot->number == PCI_SLOT_PLACEHOLDER)
return sysfs_emit(buf, "%04x:%02x\n",
pci_domain_nr(slot->bus),
slot->bus->number);
+ /*
+ * Preserve legacy ABI expectations that hotplug drivers that manage
+ * multiple devices per slot emit 0 for the device number.
+ */
+ if (slot->number == PCI_SLOT_ALL_DEVICES)
+ return sysfs_emit(buf, "%04x:%02x:00\n",
+ pci_domain_nr(slot->bus),
+ slot->bus->number);
+
return sysfs_emit(buf, "%04x:%02x:%02x\n",
pci_domain_nr(slot->bus),
slot->bus->number,
@@ -73,7 +82,8 @@ static void pci_slot_release(struct kobj
down_read(&pci_bus_sem);
list_for_each_entry(dev, &slot->bus->devices, bus_list)
- if (PCI_SLOT(dev->devfn) == slot->number)
+ if (slot->number == PCI_SLOT_ALL_DEVICES ||
+ PCI_SLOT(dev->devfn) == slot->number)
dev->slot = NULL;
up_read(&pci_bus_sem);
@@ -166,7 +176,8 @@ void pci_dev_assign_slot(struct pci_dev
mutex_lock(&pci_slot_mutex);
list_for_each_entry(slot, &dev->bus->slots, list)
- if (PCI_SLOT(dev->devfn) == slot->number)
+ if (slot->number == PCI_SLOT_ALL_DEVICES ||
+ PCI_SLOT(dev->devfn) == slot->number)
dev->slot = slot;
mutex_unlock(&pci_slot_mutex);
}
@@ -188,7 +199,8 @@ static struct pci_slot *get_slot(struct
/**
* pci_create_slot - create or increment refcount for physical PCI slot
* @parent: struct pci_bus of parent bridge
- * @slot_nr: PCI_SLOT(pci_dev->devfn) or -1 for placeholder
+ * @slot_nr: PCI_SLOT(pci_dev->devfn), PCI_SLOT_PLACEHOLDER for placeholder, or
+ * PCI_SLOT_ALL_DEVICES
* @name: user visible string presented in /sys/bus/pci/slots/<name>
* @hotplug: set if caller is hotplug driver, NULL otherwise
*
@@ -213,15 +225,26 @@ static struct pci_slot *get_slot(struct
* In most cases, @pci_bus, @slot_nr will be sufficient to uniquely identify
* a slot. There is one notable exception - pSeries (rpaphp), where the
* @slot_nr cannot be determined until a device is actually inserted into
- * the slot. In this scenario, the caller may pass -1 for @slot_nr.
+ * the slot. In this scenario, the caller may pass PCI_SLOT_PLACEHOLDER for @slot_nr.
*
* The following semantics are imposed when the caller passes @slot_nr ==
- * -1. First, we no longer check for an existing %struct pci_slot, as there
- * may be many slots with @slot_nr of -1. The other change in semantics is
- * user-visible, which is the 'address' parameter presented in sysfs will
- * consist solely of a dddd:bb tuple, where dddd is the PCI domain of the
- * %struct pci_bus and bb is the bus number. In other words, the devfn of
- * the 'placeholder' slot will not be displayed.
+ * PCI_SLOT_PLACEHOLDER. First, we no longer check for an existing %struct
+ * pci_slot, as there may be many slots with @slot_nr of
+ * PCI_SLOT_PLACEHOLDER. The other change in semantics is user-visible,
+ * which is the 'address' parameter presented in sysfs will consist solely
+ * of a dddd:bb tuple, where dddd is the PCI domain of the %struct pci_bus
+ * and bb is the bus number. In other words, the devfn of the 'placeholder'
+ * slot will not be displayed.
+ *
+ * Bus-wide slots:
+ * For PCIe hotplug, the physical slot encompasses the entire secondary
+ * bus, not just a single device number. If the device supports ARI and ARI
+ * Forwarding is enabled in the upstream bridge, a multi-function device
+ * may include functions that appear to have several different device
+ * numbers, i.e., PCI_SLOT() values. Pass @slot_nr == PCI_SLOT_ALL_DEVICES
+ * to create a slot that matches all devices on the bus. Unlike placeholder
+ * slots, bus-wide slots go through normal slot lookup and reuse existing
+ * slots if present.
*/
struct pci_slot *pci_create_slot(struct pci_bus *parent, int slot_nr,
const char *name,
@@ -234,7 +257,7 @@ struct pci_slot *pci_create_slot(struct
mutex_lock(&pci_slot_mutex);
- if (slot_nr == -1)
+ if (slot_nr == PCI_SLOT_PLACEHOLDER)
goto placeholder;
/*
@@ -285,7 +308,8 @@ placeholder:
down_read(&pci_bus_sem);
list_for_each_entry(dev, &parent->devices, bus_list)
- if (PCI_SLOT(dev->devfn) == slot_nr)
+ if (slot_nr == PCI_SLOT_ALL_DEVICES ||
+ PCI_SLOT(dev->devfn) == slot_nr)
dev->slot = slot;
up_read(&pci_bus_sem);
--- a/include/linux/pci.h
+++ b/include/linux/pci.h
@@ -72,12 +72,23 @@
/* return bus from PCI devid = ((u16)bus_number) << 8) | devfn */
#define PCI_BUS_NUM(x) (((x) >> 8) & 0xff)
+/*
+ * PCI_SLOT_ALL_DEVICES indicates a slot that covers all devices on the bus.
+ * Used for PCIe hotplug where the physical slot is the entire secondary bus,
+ * and, if ARI Forwarding is enabled, functions may appear to be on multiple
+ * devices.
+ */
+#define PCI_SLOT_ALL_DEVICES 0xfe
+
+/* Used to identify a slot as a placeholder */
+#define PCI_SLOT_PLACEHOLDER 0xff
+
/* pci_slot represents a physical slot */
struct pci_slot {
struct pci_bus *bus; /* Bus this slot is on */
struct list_head list; /* Node in list of slots */
struct hotplug_slot *hotplug; /* Hotplug info (move here) */
- unsigned char number; /* PCI_SLOT(pci_dev->devfn) */
+ unsigned char number; /* Device nr, or PCI_SLOT_ALL_DEVICES */
struct kobject kobj;
};
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0016/1518] perf/core: Fix deadlock in perf_mmap() failure path
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (14 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0015/1518] PCI: Introduce PCI_SLOT_PLACEHOLDER constant for slot_nr placeholder value Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0017/1518] platform/x86: intel_sar: Check ACPI_HANDLE() against NULL Greg Kroah-Hartman
` (982 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ian Rogers, Peter Zijlstra (Intel),
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Peter Zijlstra <peterz@infradead.org>
[ Upstream commit c69df06e4e26e50611190ce04eab92c5cc261b61 ]
Ian noted that commit 77de62ad3de3 ("perf/core: Fix refcount bug and
potential UAF in perf_mmap") would cause a deadlock due to
event->mmap_mutex recursion.
This happens because we're now calling perf_mmap_close() under
mmap_mutex, while that function itself can also take mmap_mutex.
Solve this by noting that perf_mmap_close() is far more complicated
than we need at this particular point, since it deals with scenarios
that cannot happen in this particular case.
Replace the call to perf_mmap_close() with a very narrow undo for the
case of first-exposure. If this is not the first mmap(), there is no
race and it is fine to drop the lock and call perf_mmap_close() to
handle to more complicated scenarios.
Note: move the rb->mmap_user (namespace) handling into the rb
init/free code such that it does not complicate the mmap handling.
Fixes: 77de62ad3de3 ("perf/core: Fix refcount bug and potential UAF in perf_mmap")
Reported-by: Ian Rogers <irogers@google.com>
Closes: https://patch.msgid.link/CAP-5%3DfVJyVMZw%3DDqP53Kxg58nUmJ_0bxoaeOKAbC03BVc11HaA%40mail.gmail.com
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Link: https://patch.msgid.link/20260326112821.GK3738786@noisy.programming.kicks-ass.net
Stable-dep-of: 58a8108bc73d ("perf: Fix use-after-free when perf mmap() revival races with the last munmap()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/events/core.c | 70 ++++++++++++++++++++++++++++++++++----------
kernel/events/internal.h | 1
kernel/events/ring_buffer.c | 2 +
3 files changed, 58 insertions(+), 15 deletions(-)
--- a/kernel/events/core.c
+++ b/kernel/events/core.c
@@ -6737,6 +6737,7 @@ static void perf_mmap_open(struct vm_are
}
static void perf_pmu_output_stop(struct perf_event *event);
+static void perf_mmap_unaccount(struct vm_area_struct *vma, struct perf_buffer *rb);
/*
* A buffer can be mmap()ed multiple times; either directly through the same
@@ -6752,8 +6753,6 @@ static void perf_mmap_close(struct vm_ar
mapped_f unmapped = get_mapped(event, event_unmapped);
struct perf_buffer *rb = ring_buffer_get(event);
struct user_struct *mmap_user = rb->mmap_user;
- int mmap_locked = rb->mmap_locked;
- unsigned long size = perf_data_size(rb);
bool detach_rest = false;
/* FIXIES vs perf_pmu_unregister() */
@@ -6848,11 +6847,7 @@ again:
* Aside from that, this buffer is 'fully' detached and unmapped,
* undo the VM accounting.
*/
-
- atomic_long_sub((size >> PAGE_SHIFT) + 1 - mmap_locked,
- &mmap_user->locked_vm);
- atomic64_sub(mmap_locked, &vma->vm_mm->pinned_vm);
- free_uid(mmap_user);
+ perf_mmap_unaccount(vma, rb);
out_put:
ring_buffer_put(rb); /* could be last */
@@ -6994,6 +6989,15 @@ static void perf_mmap_account(struct vm_
atomic64_add(extra, &vma->vm_mm->pinned_vm);
}
+static void perf_mmap_unaccount(struct vm_area_struct *vma, struct perf_buffer *rb)
+{
+ struct user_struct *user = rb->mmap_user;
+
+ atomic_long_sub((perf_data_size(rb) >> PAGE_SHIFT) + 1 - rb->mmap_locked,
+ &user->locked_vm);
+ atomic64_sub(rb->mmap_locked, &vma->vm_mm->pinned_vm);
+}
+
static int perf_mmap_rb(struct vm_area_struct *vma, struct perf_event *event,
unsigned long nr_pages)
{
@@ -7056,8 +7060,6 @@ static int perf_mmap_rb(struct vm_area_s
if (!rb)
return -ENOMEM;
- refcount_set(&rb->mmap_count, 1);
- rb->mmap_user = get_current_user();
rb->mmap_locked = extra;
ring_buffer_attach(event, rb);
@@ -7207,16 +7209,54 @@ static int perf_mmap(struct file *file,
mapped(event, vma->vm_mm);
/*
- * Try to map it into the page table. On fail, invoke
- * perf_mmap_close() to undo the above, as the callsite expects
- * full cleanup in this case and therefore does not invoke
- * vmops::close().
+ * Try to map it into the page table. On fail undo the above,
+ * as the callsite expects full cleanup in this case and
+ * therefore does not invoke vmops::close().
*/
ret = map_range(event->rb, vma);
- if (ret)
- perf_mmap_close(vma);
+ if (likely(!ret))
+ return 0;
+
+ /* Error path */
+
+ /*
+ * If this is the first mmap(), then event->mmap_count should
+ * be stable at 1. It is only modified by:
+ * perf_mmap_{open,close}() and perf_mmap().
+ *
+ * The former are not possible because this mmap() hasn't been
+ * successful yet, and the latter is serialized by
+ * event->mmap_mutex which we still hold (note that mmap_lock
+ * is not strictly sufficient here, because the event fd can
+ * be passed to another process through trivial means like
+ * fork(), leading to concurrent mmap() from different mm).
+ *
+ * Make sure to remove event->rb before releasing
+ * event->mmap_mutex, such that any concurrent mmap() will not
+ * attempt use this failed buffer.
+ */
+ if (refcount_read(&event->mmap_count) == 1) {
+ /*
+ * Minimal perf_mmap_close(); there can't be AUX or
+ * other events on account of this being the first.
+ */
+ mapped = get_mapped(event, event_unmapped);
+ if (mapped)
+ mapped(event, vma->vm_mm);
+ perf_mmap_unaccount(vma, event->rb);
+ ring_buffer_attach(event, NULL); /* drops last rb->refcount */
+ refcount_set(&event->mmap_count, 0);
+ return ret;
+ }
+
+ /*
+ * Otherwise this is an already existing buffer, and there is
+ * no race vs first exposure, so fall-through and call
+ * perf_mmap_close().
+ */
}
+ perf_mmap_close(vma);
return ret;
}
--- a/kernel/events/internal.h
+++ b/kernel/events/internal.h
@@ -67,6 +67,7 @@ static inline void rb_free_rcu(struct rc
struct perf_buffer *rb;
rb = container_of(rcu_head, struct perf_buffer, rcu_head);
+ free_uid(rb->mmap_user);
rb_free(rb);
}
--- a/kernel/events/ring_buffer.c
+++ b/kernel/events/ring_buffer.c
@@ -340,6 +340,8 @@ ring_buffer_init(struct perf_buffer *rb,
rb->paused = 1;
mutex_init(&rb->aux_mutex);
+ rb->mmap_user = get_current_user();
+ refcount_set(&rb->mmap_count, 1);
}
void perf_aux_output_flag(struct perf_output_handle *handle, u64 flags)
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0017/1518] platform/x86: intel_sar: Check ACPI_HANDLE() against NULL
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (15 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0016/1518] perf/core: Fix deadlock in perf_mmap() failure path Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0018/1518] platform/x86: ISST: Check for admin capability for write commands Greg Kroah-Hartman
` (981 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rafael J. Wysocki, Andy Shevchenko,
Ilpo Järvinen, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: "Rafael J. Wysocki" <rafael.j.wysocki@intel.com>
[ Upstream commit 2765f16c12af7c2533763e46b8113b727354012d ]
Every platform driver can be forced to match a device that doesn't match
its list of device IDs because of device_match_driver_override(), so
platform drivers that rely on the existence of a device's ACPI companion
object need to verify its presence.
Accordingly, add a requisite ACPI_HANDLE() check against NULL to the
platform/x86 intel_sar driver.
Fixes: dcfbd31ef4bc ("platform/x86: BIOS SAR driver for Intel M.2 Modem")
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Reviewed-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
Link: https://patch.msgid.link/14023870.uLZWGnKmhe@rafael.j.wysocki
Reviewed-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
For this stable dependency, also convert the existing allocations in
parse_package() and sar_probe() to kmalloc_objs() and kzalloc_obj().
Both helpers are already available in this tree and retain the same
allocation sizes and GFP_KERNEL flags. This makes intel_sar.c match
the parent of 30c906cff490 ("platform/x86: int1092: Fix potential
memory leak in sar_probe()"), allowing that target to apply unchanged.
No new functions or allocation helpers are introduced.
Stable-dep-of: 30c906cff490 ("platform/x86: int1092: Fix potential memory leak in sar_probe()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/platform/x86/intel/int1092/intel_sar.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
--- a/drivers/platform/x86/intel/int1092/intel_sar.c
+++ b/drivers/platform/x86/intel/int1092/intel_sar.c
@@ -91,8 +91,8 @@ static acpi_status parse_package(struct
item->package.count <= data->total_dev_mode)
return AE_ERROR;
- data->device_mode_info = kmalloc_array(data->total_dev_mode,
- sizeof(struct wwan_device_mode_info), GFP_KERNEL);
+ data->device_mode_info = kmalloc_objs(struct wwan_device_mode_info,
+ data->total_dev_mode);
if (!data->device_mode_info)
return AE_ERROR;
@@ -245,15 +245,20 @@ static void sar_get_data(int reg, struct
static int sar_probe(struct platform_device *device)
{
struct wwan_sar_context *context;
+ acpi_handle handle;
int reg;
int result;
- context = kzalloc(sizeof(*context), GFP_KERNEL);
+ handle = ACPI_HANDLE(&device->dev);
+ if (!handle)
+ return -ENODEV;
+
+ context = kzalloc_obj(*context);
if (!context)
return -ENOMEM;
context->sar_device = device;
- context->handle = ACPI_HANDLE(&device->dev);
+ context->handle = handle;
dev_set_drvdata(&device->dev, context);
result = guid_parse(SAR_DSM_UUID, &context->guid);
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0018/1518] platform/x86: ISST: Check for admin capability for write commands
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (16 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0017/1518] platform/x86: intel_sar: Check ACPI_HANDLE() against NULL Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0019/1518] PM: runtime: Wrapper macros for ACQUIRE()/ACQUIRE_ERR() Greg Kroah-Hartman
` (980 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Srinivas Pandruvada,
Ilpo Järvinen, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Srinivas Pandruvada <srinivas.pandruvada@linux.intel.com>
[ Upstream commit 69cd1ca440a96c85dcedcddfa5e0af6012f60b8b ]
In some SST deployments, administrators want to allow reading SST
capabilities for non-root users. This can be achieved by changing file
permissions for "/dev/isst_interface", but they still want to prevent
any changes to the SST configuration by non-root users.
This capability was available before for non-TPMI SST. Extend the same
capability for TPMI SST by adding a check for CAP_SYS_ADMIN for all
write commands.
Signed-off-by: Srinivas Pandruvada <srinivas.pandruvada@linux.intel.com>
Link: https://patch.msgid.link/20260107060729.1634420-1-srinivas.pandruvada@linux.intel.com
Reviewed-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Stable-dep-of: e45d6b847286 ("platform/x86: ISST: Validate max level for set feature")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/platform/x86/intel/speed_select_if/isst_tpmi_core.c | 11 ++++++-----
1 file changed, 6 insertions(+), 5 deletions(-)
--- a/drivers/platform/x86/intel/speed_select_if/isst_tpmi_core.c
+++ b/drivers/platform/x86/intel/speed_select_if/isst_tpmi_core.c
@@ -625,7 +625,7 @@ static long isst_if_core_power_state(voi
return -EINVAL;
if (core_power.get_set) {
- if (power_domain_info->write_blocked)
+ if (power_domain_info->write_blocked || !capable(CAP_SYS_ADMIN))
return -EPERM;
if (core_power.enable > SST_CP_MAX_ENABLE ||
@@ -684,7 +684,7 @@ static long isst_if_clos_param(void __us
return -EINVAL;
if (clos_param.get_set) {
- if (power_domain_info->write_blocked)
+ if (power_domain_info->write_blocked || !capable(CAP_SYS_ADMIN))
return -EPERM;
if (!in_range(clos_param.min_freq_mhz / SST_MUL_FACTOR_FREQ, 0, SST_MAX_FREQ + 1))
@@ -795,7 +795,8 @@ static long isst_if_clos_assoc(void __us
power_domain_info = &sst_inst->power_domain_info[part][punit_id];
- if (assoc_cmds.get_set && power_domain_info->write_blocked)
+ if (assoc_cmds.get_set && (power_domain_info->write_blocked ||
+ !capable(CAP_SYS_ADMIN)))
return -EPERM;
offset = SST_CLOS_ASSOC_0_OFFSET +
@@ -973,7 +974,7 @@ static int isst_if_set_perf_level(void _
if (!power_domain_info)
return -EINVAL;
- if (power_domain_info->write_blocked)
+ if (power_domain_info->write_blocked || !capable(CAP_SYS_ADMIN))
return -EPERM;
if (!(power_domain_info->pp_header.allowed_level_mask & BIT(perf_level.level)))
@@ -1033,7 +1034,7 @@ static int isst_if_set_perf_feature(void
if (!power_domain_info)
return -EINVAL;
- if (power_domain_info->write_blocked)
+ if (power_domain_info->write_blocked || !capable(CAP_SYS_ADMIN))
return -EPERM;
if (perf_feature.feature & ~SST_PP_FEATURE_STATE_VALID_MASK)
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0019/1518] PM: runtime: Wrapper macros for ACQUIRE()/ACQUIRE_ERR()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (17 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0018/1518] platform/x86: ISST: Check for admin capability for write commands Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0020/1518] ring-buffer: Show persistent buffer dropped events in trace_pipe file Greg Kroah-Hartman
` (979 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rafael J. Wysocki, Dan Williams,
Dhruva Gole, Jonathan Cameron, Frank Li, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: "Rafael J. Wysocki" <rafael.j.wysocki@intel.com>
[ Upstream commit ef8057b07c72a817537856b98d6e7493b9404eaf ]
Add wrapper macros for ACQUIRE()/ACQUIRE_ERR() and runtime PM
usage counter guards introduced recently: pm_runtime_active_try,
pm_runtime_active_auto_try, pm_runtime_active_try_enabled, and
pm_runtime_active_auto_try_enabled.
The new macros should be more straightforward to use.
For example, they can be used for rewriting a piece of code like below:
ACQUIRE(pm_runtime_active_try, pm)(dev);
if ((ret = ACQUIRE_ERR(pm_runtime_active_try, &pm)))
return ret;
in the following way:
PM_RUNTIME_ACQUIRE(dev, pm);
if ((ret = PM_RUNTIME_ACQUIRE_ERR(&pm)))
return ret;
If the original code does not care about the specific error code
returned when attepmting to resume the device:
ACQUIRE(pm_runtime_active_try, pm)(dev);
if (ACQUIRE_ERR(pm_runtime_active_try, &pm))
return -ENXIO;
it may be changed like this:
PM_RUNTIME_ACQUIRE(dev, pm);
if (PM_RUNTIME_ACQUIRE_ERR(&pm))
return -ENXIO;
Link: https://lore.kernel.org/linux-pm/5068916.31r3eYUQgx@rafael.j.wysocki/
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Reviewed-by: Dan Williams <dan.j.williams@intel.com>
Reviewed-by: Dhruva Gole <d-gole@ti.com>
Reviewed-by: Jonathan Cameron <jonathan.cameron@huawei.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/3400866.aeNJFYEL58@rafael.j.wysocki
Stable-dep-of: d378fceaafd7 ("iio: light: apds9306: fix PM reference leak in apds9306_read_data()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
include/linux/pm_runtime.h | 24 ++++++++++++++++++++++++
1 file changed, 24 insertions(+)
--- a/include/linux/pm_runtime.h
+++ b/include/linux/pm_runtime.h
@@ -637,6 +637,30 @@ DEFINE_GUARD_COND(pm_runtime_active_auto
DEFINE_GUARD_COND(pm_runtime_active_auto, _try_enabled,
pm_runtime_resume_and_get(_T), _RET == 0)
+/* ACQUIRE() wrapper macros for the guards defined above. */
+
+#define PM_RUNTIME_ACQUIRE(_dev, _var) \
+ ACQUIRE(pm_runtime_active_try, _var)(_dev)
+
+#define PM_RUNTIME_ACQUIRE_AUTOSUSPEND(_dev, _var) \
+ ACQUIRE(pm_runtime_active_auto_try, _var)(_dev)
+
+#define PM_RUNTIME_ACQUIRE_IF_ENABLED(_dev, _var) \
+ ACQUIRE(pm_runtime_active_try_enabled, _var)(_dev)
+
+#define PM_RUNTIME_ACQUIRE_IF_ENABLED_AUTOSUSPEND(_dev, _var) \
+ ACQUIRE(pm_runtime_active_auto_try_enabled, _var)(_dev)
+
+/*
+ * ACQUIRE_ERR() wrapper macro for guard pm_runtime_active.
+ *
+ * Always check PM_RUNTIME_ACQUIRE_ERR() after using one of the
+ * PM_RUNTIME_ACQUIRE*() macros defined above (yes, it can be used with
+ * any of them) and if it is nonzero, avoid accessing the given device.
+ */
+#define PM_RUNTIME_ACQUIRE_ERR(_var_ptr) \
+ ACQUIRE_ERR(pm_runtime_active, _var_ptr)
+
/**
* pm_runtime_put_sync - Drop device usage counter and run "idle check" if 0.
* @dev: Target device.
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0020/1518] ring-buffer: Show persistent buffer dropped events in trace_pipe file
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (18 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0019/1518] PM: runtime: Wrapper macros for ACQUIRE()/ACQUIRE_ERR() Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0021/1518] staging: rtl8723bs: fix spacing around operators Greg Kroah-Hartman
` (978 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Masami Hiramatsu (Google),
Steven Rostedt, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Steven Rostedt <rostedt@goodmis.org>
[ Upstream commit 8928e4a3be34bf053f9ef1cad67263604bf4f05e ]
When the persistent ring buffer is validated on boot up, if a subbuffer is
deemed invalid, it resets the buffer and continues. Have the code preserve
the RB_MISSED_EVENTS flag in the commit portion of the subbuffer header
and pass that back so that the trace_pipe file can show the missed events
like the trace file does.
For example:
<...>-1242 [005] d.... 4429.120116: page_fault_user: address=0x7ffaebb6e728 ip=0x7ffaeb9d4960 error_code=0x7
<...>-1242 [005] ..... 4429.120124: mm_page_alloc: page=00000000055254f3 pfn=0x1373bd order=0 migratetype=1 gfp_flags=GFP_HIGHUSER_MOVABLE|__GFP_COMP
<...>-1242 [005] d..2. 4429.120132: tlb_flush: pages:1 reason:local MM shootdown (3)
CPU:5 [LOST EVENTS]
<...>-1242 [005] d.... 4429.120661: page_fault_user: address=0x55ba7c2d0944 ip=0x55ba7c20cd02 error_code=0x7
<...>-1242 [005] ..... 4429.120669: mm_page_alloc: page=0000000005a02500 pfn=0x12b6e4 order=0 migratetype=1 gfp_flags=GFP_HIGHUSER_MOVABLE|__GFP_COMP
<...>-1242 [005] d..2. 4429.120680: tlb_flush: pages:1 reason:local MM shootdown (3)
Link: https://patch.msgid.link/20260522171052.156419479@kernel.org
Reviewed-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Backport notes for 6.18:
Keep the ring_buffer_read_page() changes needed as context for
6365c44a824f ("ring-buffer: Allow splice reads on static buffers").
Separate the raw commit flags from the page byte count and preserve the
lost-events flag when copying page contents. Keep the existing bpage name,
rb_page_capacity(reader) bounds and unsigned lost-event count. Read and
mask bpage->commit directly instead of adding the newer data-page helpers.
Drop the reader-page unknown-loss propagation: this tree lacks the
persistent invalid-subbuffer recovery and signed-loss reporting changes
that make that path meaningful.
Keep the copy loop bounded by the page size, not event_size, avoiding the
one-event-per-read regression subsequently fixed by af05b4e06279. Preserve
the loss flag when trimming a swapped page to real_end, and combine output
flags with bitwise OR so an already-set flag is not added a second time.
Stable-dep-of: 6365c44a824f ("ring-buffer: Allow splice reads on static buffers")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/trace/ring_buffer.c | 56 +++++++++++++++++++++++++--------------------
1 file changed, 32 insertions(+), 24 deletions(-)
--- a/kernel/trace/ring_buffer.c
+++ b/kernel/trace/ring_buffer.c
@@ -6682,6 +6682,7 @@ int ring_buffer_read_page(struct trace_b
struct buffer_page *reader;
unsigned long missed_events;
unsigned int commit;
+ unsigned int size;
unsigned int read;
u64 save_timestamp;
@@ -6716,7 +6717,8 @@ int ring_buffer_read_page(struct trace_b
event = rb_reader_event(cpu_buffer);
read = reader->read;
- commit = rb_page_size(reader);
+ commit = rb_page_commit(reader);
+ size = rb_page_size(reader);
/* Check if any events were dropped */
missed_events = cpu_buffer->lost_events;
@@ -6728,13 +6730,14 @@ int ring_buffer_read_page(struct trace_b
* we must copy the data from the page to the buffer.
* Otherwise, we can simply swap the page with the one passed in.
*/
- if (read || (len < (commit - read)) ||
+ if (read || (len < (size - read)) ||
cpu_buffer->reader_page == cpu_buffer->commit_page ||
cpu_buffer->mapped) {
struct buffer_data_page *rpage = cpu_buffer->reader_page->page;
unsigned int rpos = read;
unsigned int pos = 0;
- unsigned int size;
+ unsigned int event_size;
+ unsigned int flags = 0;
/*
* If a full page is expected, this can still be returned
@@ -6743,19 +6746,22 @@ int ring_buffer_read_page(struct trace_b
* the reader page.
*/
if (full &&
- (!read || (len < (commit - read)) ||
+ (!read || (len < (size - read)) ||
cpu_buffer->reader_page == cpu_buffer->commit_page))
return -1;
- if (len > (commit - read))
- len = (commit - read);
+ if (len > (size - read))
+ len = (size - read);
/* Always keep the time extend and data together */
- size = rb_event_ts_length(event);
+ event_size = rb_event_ts_length(event);
- if (len < size)
+ if (len < event_size)
return -1;
+ if (commit & RB_MISSED_EVENTS)
+ flags = RB_MISSED_EVENTS;
+
/* save the current timestamp, since the user will need it */
save_timestamp = cpu_buffer->read_stamp;
@@ -6767,25 +6773,25 @@ int ring_buffer_read_page(struct trace_b
* one or two events.
* We have already ensured there's enough space if this
* is a time extend. */
- size = rb_event_length(event);
- memcpy(bpage->data + pos, rpage->data + rpos, size);
+ event_size = rb_event_length(event);
+ memcpy(bpage->data + pos, rpage->data + rpos, event_size);
- len -= size;
+ len -= event_size;
rb_advance_reader(cpu_buffer);
rpos = reader->read;
- pos += size;
+ pos += event_size;
- if (rpos >= commit)
+ if (rpos >= size)
break;
event = rb_reader_event(cpu_buffer);
/* Always keep the time extend and data together */
- size = rb_event_ts_length(event);
- } while (len >= size);
+ event_size = rb_event_ts_length(event);
+ } while (len >= event_size);
/* update bpage */
- local_set(&bpage->commit, pos);
+ local_set(&bpage->commit, pos | flags);
bpage->time_stamp = save_timestamp;
/* we copied everything to the beginning */
@@ -6810,12 +6816,14 @@ int ring_buffer_read_page(struct trace_b
* on the page.
*/
if (reader->real_end)
- local_set(&bpage->commit, reader->real_end);
+ local_set(&bpage->commit, reader->real_end |
+ (commit & RB_MISSED_EVENTS));
}
cpu_buffer->lost_events = 0;
commit = local_read(&bpage->commit);
+ size = commit & ~RB_MISSED_MASK;
/*
* Set a flag in the commit field if we lost events
*/
@@ -6823,20 +6831,20 @@ int ring_buffer_read_page(struct trace_b
/* If there is room at the end of the page to save the
* missed events, then record it there.
*/
- if (rb_page_capacity(reader) - commit >= sizeof(missed_events)) {
- memcpy(&bpage->data[commit], &missed_events,
+ if (rb_page_capacity(reader) - size >= sizeof(missed_events)) {
+ memcpy(&bpage->data[size], &missed_events,
sizeof(missed_events));
- local_add(RB_MISSED_STORED, &bpage->commit);
- commit += sizeof(missed_events);
+ commit |= RB_MISSED_STORED;
+ size += sizeof(missed_events);
}
- local_add(RB_MISSED_EVENTS, &bpage->commit);
+ local_set(&bpage->commit, commit | RB_MISSED_EVENTS);
}
/*
* This page may be off to user land. Zero it out here.
*/
- if (commit < rb_page_capacity(reader))
- memset(&bpage->data[commit], 0, rb_page_capacity(reader) - commit);
+ if (size < rb_page_capacity(reader))
+ memset(&bpage->data[size], 0, rb_page_capacity(reader) - size);
return read;
}
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0021/1518] staging: rtl8723bs: fix spacing around operators
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (19 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0020/1518] ring-buffer: Show persistent buffer dropped events in trace_pipe file Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0022/1518] tracing/probes: ignore id update from btf_type_skip_modifiers Greg Kroah-Hartman
` (977 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Vivek BalachandharTN, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vivek BalachandharTN <vivek.balachandhar@gmail.com>
[ Upstream commit 2038fe84b8bdf894b634f777096685e78e8f3774 ]
Fix several instances where operators lacked spaces around them.
This improves readability and brings the driver closer to kernel
coding-style guidelines. No functional change.
Signed-off-by: Vivek BalachandharTN <vivek.balachandhar@gmail.com>
Link: https://patch.msgid.link/20251205021417.2705864-3-vivek.balachandhar@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
For this stable dependency, retain only the spacing change to the IE
advance in rtw_restruct_wmm_ie(). This supplies the exact context needed
by target commit 28a289beaf226 ("staging: rtl8723bs: fix OOB read in
rtw_restruct_wmm_ie()"). Drop the unrelated operator-spacing hunks.
Keep the existing bounds-first WMM match condition from stable commit
4dd2d9cf563c5 (upstream a75281626fc8f); applying the older condition
would undo its out-of-bounds-read fix. No functional change.
Stable-dep-of: 28a289beaf22 ("staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/staging/rtl8723bs/core/rtw_mlme.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
--- a/drivers/staging/rtl8723bs/core/rtw_mlme.c
+++ b/drivers/staging/rtl8723bs/core/rtw_mlme.c
@@ -2029,7 +2029,7 @@ int rtw_restruct_wmm_ie(struct adapter *
break;
}
- i += (in_ie[i+1]+2); /* to the next IE element */
+ i += (in_ie[i + 1] + 2); /* to the next IE element */
}
return ielength;
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0022/1518] tracing/probes: ignore id update from btf_type_skip_modifiers
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (20 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0021/1518] staging: rtl8723bs: fix spacing around operators Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0023/1518] udf: Move udf_map_block() up Greg Kroah-Hartman
` (976 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Martin Kaiser,
Masami Hiramatsu (Google), Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Martin Kaiser <martin@kaiser.cx>
[ Upstream commit 823b37855829bc328d46102a56e4d0b2f7a3d0d1 ]
We can pass NULL as id pointer to btf_type_skip_modifiers if we do not
need the id of the returned btf_type.
Link: https://lore.kernel.org/all/20260623132937.3494895-1-martin@kaiser.cx/
Signed-off-by: Martin Kaiser <martin@kaiser.cx>
Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Stable-dep-of: 47e93045a2db ("tracing/probes: Fix BTF kflag check for anonymous struct member access")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/trace/trace_probe.c | 13 +++++--------
1 file changed, 5 insertions(+), 8 deletions(-)
--- a/kernel/trace/trace_probe.c
+++ b/kernel/trace/trace_probe.c
@@ -355,9 +355,8 @@ static bool btf_type_is_char_ptr(struct
{
const struct btf_type *real_type;
u32 intdata;
- s32 tid;
- real_type = btf_type_skip_modifiers(btf, type->type, &tid);
+ real_type = btf_type_skip_modifiers(btf, type->type, NULL);
if (!real_type)
return false;
@@ -374,14 +373,13 @@ static bool btf_type_is_char_array(struc
const struct btf_type *real_type;
const struct btf_array *array;
u32 intdata;
- s32 tid;
if (BTF_INFO_KIND(type->info) != BTF_KIND_ARRAY)
return false;
array = (const struct btf_array *)(type + 1);
- real_type = btf_type_skip_modifiers(btf, array->type, &tid);
+ real_type = btf_type_skip_modifiers(btf, array->type, NULL);
intdata = btf_type_int(real_type);
return !(BTF_INT_ENCODING(intdata) & BTF_INT_SIGNED)
@@ -584,7 +582,6 @@ static int parse_btf_field(char *fieldna
struct btf *btf = ctx_btf(ctx);
char *next;
int is_ptr;
- s32 tid;
do {
if (!is_struct) {
@@ -595,7 +592,7 @@ static int parse_btf_field(char *fieldna
}
/* Convert a struct pointer type to a struct type */
- type = btf_type_skip_modifiers(btf, type->type, &tid);
+ type = btf_type_skip_modifiers(btf, type->type, NULL);
if (!type) {
trace_probe_log_err(ctx->offset, BAD_BTF_TID);
return -EINVAL;
@@ -635,7 +632,7 @@ static int parse_btf_field(char *fieldna
ctx->last_bitsize = 0;
}
- type = btf_type_skip_modifiers(btf, field->type, &tid);
+ type = btf_type_skip_modifiers(btf, field->type, NULL);
if (!type) {
trace_probe_log_err(ctx->offset, BAD_BTF_TID);
return -EINVAL;
@@ -754,7 +751,7 @@ static int parse_btf_arg(char *varname,
return -ENOENT;
found:
- type = btf_type_skip_modifiers(ctx->btf, tid, &tid);
+ type = btf_type_skip_modifiers(ctx->btf, tid, NULL);
found_type:
if (!type) {
trace_probe_log_err(ctx->offset, BAD_BTF_TID);
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0023/1518] udf: Move udf_map_block() up
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (21 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0022/1518] tracing/probes: ignore id update from btf_type_skip_modifiers Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0024/1518] wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy Greg Kroah-Hartman
` (975 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jan Kara, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jan Kara <jack@suse.cz>
[ Upstream commit 97e9d759a4193eabe4d8b6ecac093aac664c16e3 ]
Move udf_map_block() in the file to avoid forward declarations.
Link: https://patch.msgid.link/20260730104232.4086759-3-jack@suse.cz
Signed-off-by: Jan Kara <jack@suse.cz>
Stable-dep-of: 62333e480d12 ("udf: Fix data loss when converting inline inodes to out of line")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/udf/inode.c | 118 ++++++++++++++++++++++++++++-----------------------------
1 file changed, 59 insertions(+), 59 deletions(-)
--- a/fs/udf/inode.c
+++ b/fs/udf/inode.c
@@ -337,65 +337,6 @@ const struct address_space_operations ud
.migrate_folio = buffer_migrate_folio,
};
-/*
- * Expand file stored in ICB to a normal one-block-file
- *
- * This function requires i_mutex held
- */
-int udf_expand_file_adinicb(struct inode *inode)
-{
- struct folio *folio;
- struct udf_inode_info *iinfo = UDF_I(inode);
- int err;
-
- WARN_ON_ONCE(!inode_is_locked(inode));
- if (!iinfo->i_lenAlloc) {
- down_write(&iinfo->i_data_sem);
- if (UDF_QUERY_FLAG(inode->i_sb, UDF_FLAG_USE_SHORT_AD))
- iinfo->i_alloc_type = ICBTAG_FLAG_AD_SHORT;
- else
- iinfo->i_alloc_type = ICBTAG_FLAG_AD_LONG;
- up_write(&iinfo->i_data_sem);
- mark_inode_dirty(inode);
- return 0;
- }
-
- folio = __filemap_get_folio(inode->i_mapping, 0,
- FGP_LOCK | FGP_ACCESSED | FGP_CREAT, GFP_KERNEL);
- if (IS_ERR(folio))
- return PTR_ERR(folio);
-
- if (!folio_test_uptodate(folio))
- udf_adinicb_read_folio(folio);
- down_write(&iinfo->i_data_sem);
- memset(iinfo->i_data + iinfo->i_lenEAttr, 0x00,
- iinfo->i_lenAlloc);
- iinfo->i_lenAlloc = 0;
- if (UDF_QUERY_FLAG(inode->i_sb, UDF_FLAG_USE_SHORT_AD))
- iinfo->i_alloc_type = ICBTAG_FLAG_AD_SHORT;
- else
- iinfo->i_alloc_type = ICBTAG_FLAG_AD_LONG;
- folio_mark_dirty(folio);
- folio_unlock(folio);
- up_write(&iinfo->i_data_sem);
- err = filemap_fdatawrite(inode->i_mapping);
- if (err) {
- /* Restore everything back so that we don't lose data... */
- folio_lock(folio);
- down_write(&iinfo->i_data_sem);
- memcpy_from_folio(iinfo->i_data + iinfo->i_lenEAttr,
- folio, 0, inode->i_size);
- folio_unlock(folio);
- iinfo->i_alloc_type = ICBTAG_FLAG_AD_IN_ICB;
- iinfo->i_lenAlloc = inode->i_size;
- up_write(&iinfo->i_data_sem);
- }
- folio_put(folio);
- mark_inode_dirty(inode);
-
- return err;
-}
-
#define UDF_MAP_CREATE 0x01 /* Mapping can allocate new blocks */
#define UDF_MAP_NOPREALLOC 0x02 /* Do not preallocate blocks */
@@ -456,6 +397,65 @@ out_read:
return ret;
}
+/*
+ * Expand file stored in ICB to a normal one-block-file
+ *
+ * This function requires i_mutex held
+ */
+int udf_expand_file_adinicb(struct inode *inode)
+{
+ struct folio *folio;
+ struct udf_inode_info *iinfo = UDF_I(inode);
+ int err;
+
+ WARN_ON_ONCE(!inode_is_locked(inode));
+ if (!iinfo->i_lenAlloc) {
+ down_write(&iinfo->i_data_sem);
+ if (UDF_QUERY_FLAG(inode->i_sb, UDF_FLAG_USE_SHORT_AD))
+ iinfo->i_alloc_type = ICBTAG_FLAG_AD_SHORT;
+ else
+ iinfo->i_alloc_type = ICBTAG_FLAG_AD_LONG;
+ up_write(&iinfo->i_data_sem);
+ mark_inode_dirty(inode);
+ return 0;
+ }
+
+ folio = __filemap_get_folio(inode->i_mapping, 0,
+ FGP_LOCK | FGP_ACCESSED | FGP_CREAT, GFP_KERNEL);
+ if (IS_ERR(folio))
+ return PTR_ERR(folio);
+
+ if (!folio_test_uptodate(folio))
+ udf_adinicb_read_folio(folio);
+ down_write(&iinfo->i_data_sem);
+ memset(iinfo->i_data + iinfo->i_lenEAttr, 0x00,
+ iinfo->i_lenAlloc);
+ iinfo->i_lenAlloc = 0;
+ if (UDF_QUERY_FLAG(inode->i_sb, UDF_FLAG_USE_SHORT_AD))
+ iinfo->i_alloc_type = ICBTAG_FLAG_AD_SHORT;
+ else
+ iinfo->i_alloc_type = ICBTAG_FLAG_AD_LONG;
+ folio_mark_dirty(folio);
+ folio_unlock(folio);
+ up_write(&iinfo->i_data_sem);
+ err = filemap_fdatawrite(inode->i_mapping);
+ if (err) {
+ /* Restore everything back so that we don't lose data... */
+ folio_lock(folio);
+ down_write(&iinfo->i_data_sem);
+ memcpy_from_folio(iinfo->i_data + iinfo->i_lenEAttr,
+ folio, 0, inode->i_size);
+ folio_unlock(folio);
+ iinfo->i_alloc_type = ICBTAG_FLAG_AD_IN_ICB;
+ iinfo->i_lenAlloc = inode->i_size;
+ up_write(&iinfo->i_data_sem);
+ }
+ folio_put(folio);
+ mark_inode_dirty(inode);
+
+ return err;
+}
+
static int __udf_get_block(struct inode *inode, sector_t block,
struct buffer_head *bh_result, int flags)
{
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0024/1518] wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (22 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0023/1518] udf: Move udf_map_block() up Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0025/1518] compiler_types: Move lock checking attributes to compiler-context-analysis.h Greg Kroah-Hartman
` (974 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bryam Vargas, Felix Fietkau,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bryam Vargas <hexlabsecurity@proton.me>
[ Upstream commit 13b3c29a782033ce4a230be9e5618032813dbcd4 ]
mt7996_mcu_get_eeprom() derives the destination of the EFUSE/EXT block
copy from the address reported by the MCU response (event->addr, a
device-controlled __le32) and clamps only the copy length, never the
destination offset into dev->mt76.eeprom.data. A malicious or
malfunctioning device can report an arbitrary address and drive an
out-of-bounds write of up to MT7996_EXT_EEPROM_BLOCK_SIZE bytes past
eeprom.data.
Reject a response whose address would place the copy outside eeprom.data
before deriving the destination pointer. Devices that echo the requested
in-bounds offset are unaffected.
Fixes: 98686cd21624 ("wifi: mt76: mt7996: add driver for MediaTek Wi-Fi 7 (802.11be) devices")
Cc: stable@vger.kernel.org
Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me>
Link: https://patch.msgid.link/20260625-b4-disp-16f99062-v1-2-aee52ecf61b9@proton.me
Signed-off-by: Felix Fietkau <nbd@nbd.name>
[ Replaced the mode-dependent block size with MT7996_EEPROM_BLOCK_SIZE for the older EFUSE-only implementation. ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/mediatek/mt76/mt7996/mcu.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mcu.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mcu.c
@@ -3866,8 +3866,14 @@ int mt7996_mcu_get_eeprom(struct mt7996_
if (valid) {
u32 addr = le32_to_cpu(*(__le32 *)(skb->data + 12));
- if (!buf)
+ if (!buf) {
+ if (addr > dev->mt76.eeprom.size -
+ MT7996_EEPROM_BLOCK_SIZE) {
+ dev_kfree_skb(skb);
+ return -EINVAL;
+ }
buf = (u8 *)dev->mt76.eeprom.data + addr;
+ }
if (!buf_len || buf_len > MT7996_EEPROM_BLOCK_SIZE)
buf_len = MT7996_EEPROM_BLOCK_SIZE;
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0025/1518] compiler_types: Move lock checking attributes to compiler-context-analysis.h
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (23 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0024/1518] wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0026/1518] i2c: qcom-cci: Do not check return value of cci_init() Greg Kroah-Hartman
` (973 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Marco Elver, Peter Zijlstra (Intel),
Bart Van Assche, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Marco Elver <elver@google.com>
[ Upstream commit de15fecae44df8254fa597bad7eb3680a8b1c10c ]
The conditional definition of lock checking macros and attributes is
about to become more complex. Factor them out into their own header for
better readability, and to make it obvious which features are supported
by which mode (currently only Sparse). This is the first step towards
generalizing towards "context analysis".
No functional change intended.
Signed-off-by: Marco Elver <elver@google.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/20251219154418.3592607-2-elver@google.com
Stable-dep-of: 912edebe8501 ("futex: Provide rt_mutex_.*_schedule() equivalents for futex scheduling")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
include/linux/compiler-context-analysis.h | 32 ++++++++++++++++++++++++++++++
include/linux/compiler_types.h | 18 +---------------
2 files changed, 34 insertions(+), 16 deletions(-)
create mode 100644 include/linux/compiler-context-analysis.h
--- /dev/null
+++ b/include/linux/compiler-context-analysis.h
@@ -0,0 +1,32 @@
+/* SPDX-License-Identifier: GPL-2.0 */
+/*
+ * Macros and attributes for compiler-based static context analysis.
+ */
+
+#ifndef _LINUX_COMPILER_CONTEXT_ANALYSIS_H
+#define _LINUX_COMPILER_CONTEXT_ANALYSIS_H
+
+#ifdef __CHECKER__
+
+/* Sparse context/lock checking support. */
+# define __must_hold(x) __attribute__((context(x,1,1)))
+# define __acquires(x) __attribute__((context(x,0,1)))
+# define __cond_acquires(x) __attribute__((context(x,0,-1)))
+# define __releases(x) __attribute__((context(x,1,0)))
+# define __acquire(x) __context__(x,1)
+# define __release(x) __context__(x,-1)
+# define __cond_lock(x, c) ((c) ? ({ __acquire(x); 1; }) : 0)
+
+#else /* !__CHECKER__ */
+
+# define __must_hold(x)
+# define __acquires(x)
+# define __cond_acquires(x)
+# define __releases(x)
+# define __acquire(x) (void)0
+# define __release(x) (void)0
+# define __cond_lock(x, c) (c)
+
+#endif /* __CHECKER__ */
+
+#endif /* _LINUX_COMPILER_CONTEXT_ANALYSIS_H */
--- a/include/linux/compiler_types.h
+++ b/include/linux/compiler_types.h
@@ -37,6 +37,8 @@
# define BTF_TYPE_TAG(value) /* nothing */
#endif
+#include <linux/compiler-context-analysis.h>
+
/* sparse defines __CHECKER__; see Documentation/dev-tools/sparse.rst */
#ifdef __CHECKER__
/* address spaces */
@@ -47,14 +49,6 @@
# define __rcu __attribute__((noderef, address_space(__rcu)))
static inline void __chk_user_ptr(const volatile void __user *ptr) { }
static inline void __chk_io_ptr(const volatile void __iomem *ptr) { }
-/* context/locking */
-# define __must_hold(x) __attribute__((context(x,1,1)))
-# define __acquires(x) __attribute__((context(x,0,1)))
-# define __cond_acquires(x) __attribute__((context(x,0,-1)))
-# define __releases(x) __attribute__((context(x,1,0)))
-# define __acquire(x) __context__(x,1)
-# define __release(x) __context__(x,-1)
-# define __cond_lock(x,c) ((c) ? ({ __acquire(x); 1; }) : 0)
/* other */
# define __force __attribute__((force))
# define __nocast __attribute__((nocast))
@@ -75,14 +69,6 @@ static inline void __chk_io_ptr(const vo
# define __chk_user_ptr(x) (void)0
# define __chk_io_ptr(x) (void)0
-/* context/locking */
-# define __must_hold(x)
-# define __acquires(x)
-# define __cond_acquires(x)
-# define __releases(x)
-# define __acquire(x) (void)0
-# define __release(x) (void)0
-# define __cond_lock(x,c) (c)
/* other */
# define __force
# define __nocast
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0026/1518] i2c: qcom-cci: Do not check return value of cci_init()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (24 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0025/1518] compiler_types: Move lock checking attributes to compiler-context-analysis.h Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0027/1518] tracing: Clean up use of trace_create_maxlat_file() Greg Kroah-Hartman
` (972 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vladimir Zapolskiy, Loic Poulain,
Konrad Dybcio, Andi Shyti, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vladimir Zapolskiy <vladimir.zapolskiy@linaro.org>
[ Upstream commit 17c5d247e3e4708cac05ff087c8013c0dda383a2 ]
The cci_init() function is not supposed to fail, and it never returns
a non-zero, so it'd make sense to convert its signature to void.
Signed-off-by: Vladimir Zapolskiy <vladimir.zapolskiy@linaro.org>
Reviewed-by: Loic Poulain <loic.poulain@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://lore.kernel.org/r/20260515234121.1607425-3-vladimir.zapolskiy@linaro.org
Stable-dep-of: f98d49864821 ("i2c: qcom-cci: fix autosuspend cleanup")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-qcom-cci.c | 8 ++------
1 file changed, 2 insertions(+), 6 deletions(-)
--- a/drivers/i2c/busses/i2c-qcom-cci.c
+++ b/drivers/i2c/busses/i2c-qcom-cci.c
@@ -246,7 +246,7 @@ static int cci_reset(struct cci *cci)
return 0;
}
-static int cci_init(struct cci *cci)
+static void cci_init(struct cci *cci)
{
u32 val = CCI_IRQ_MASK_0_I2C_M0_RD_DONE |
CCI_IRQ_MASK_0_I2C_M0_Q0_REPORT |
@@ -287,8 +287,6 @@ static int cci_init(struct cci *cci)
val = hw->scl_stretch_en << 8 | hw->trdhld << 4 | hw->tsp;
writel(val, cci->base + CCI_I2C_Mm_MISC_CTL(i));
}
-
- return 0;
}
static int cci_run_queue(struct cci *cci, u8 master, u8 queue)
@@ -598,9 +596,7 @@ static int cci_probe(struct platform_dev
if (ret < 0)
goto error;
- ret = cci_init(cci);
- if (ret < 0)
- goto error;
+ cci_init(cci);
pm_runtime_set_autosuspend_delay(dev, MSEC_PER_SEC);
pm_runtime_use_autosuspend(dev);
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0027/1518] tracing: Clean up use of trace_create_maxlat_file()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (25 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0026/1518] i2c: qcom-cci: Do not check return value of cci_init() Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0028/1518] io_uring: unify task_work cancelation checks Greg Kroah-Hartman
` (971 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mathieu Desnoyers,
Masami Hiramatsu (Google), Steven Rostedt (Google), Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Steven Rostedt <rostedt@goodmis.org>
[ Upstream commit ba73713da50e5c24499ca8941171593466ea34f7 ]
In trace.c, the function trace_create_maxlat_file() is defined behind the
#ifdef CONFIG_TRACER_MAX_TRACE block. The #else part defines it as:
#define trace_create_maxlat_file(tr, d_tracer) \
trace_create_file("tracing_max_latency", TRACE_MODE_WRITE, \
d_tracer, tr, &tracing_max_lat_fops)
But the one place that it it used has:
#ifdef CONFIG_TRACER_MAX_TRACE
trace_create_maxlat_file(tr, d_tracer);
#endif
Which is pointless and also wrong!
It only gets created when both CONFIG_TRACE_MAX_TRACE and CONFIG_FS_NOTIFY
is defined, but the file itself should not be dependent on
CONFIG_FS_NOTIFY. Always create that file when TRACE_MAX_TRACE is defined
regardless if FS_NOTIFY is or is not.
Cc: Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
Acked-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Link: https://patch.msgid.link/20260207191101.0e014abd@robin
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
Stable-dep-of: f2951ebd15c3 ("tracing: Take trace_array reference when opening options file")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/trace/trace.c | 38 ++++++++++++++++----------------------
1 file changed, 16 insertions(+), 22 deletions(-)
--- a/kernel/trace/trace.c
+++ b/kernel/trace/trace.c
@@ -1904,10 +1904,7 @@ static ssize_t trace_seq_to_buffer(struc
unsigned long __read_mostly tracing_thresh;
#ifdef CONFIG_TRACER_MAX_TRACE
-static const struct file_operations tracing_max_lat_fops;
-
#ifdef LATENCY_FS_NOTIFY
-
static struct workqueue_struct *fsnotify_wq;
static void latency_fsnotify_workfn(struct work_struct *work)
@@ -1924,17 +1921,6 @@ static void latency_fsnotify_workfn_irq(
queue_work(fsnotify_wq, &tr->fsnotify_work);
}
-static void trace_create_maxlat_file(struct trace_array *tr,
- struct dentry *d_tracer)
-{
- INIT_WORK(&tr->fsnotify_work, latency_fsnotify_workfn);
- init_irq_work(&tr->fsnotify_irqwork, latency_fsnotify_workfn_irq);
- tr->d_max_latency = trace_create_file("tracing_max_latency",
- TRACE_MODE_WRITE,
- d_tracer, tr,
- &tracing_max_lat_fops);
-}
-
__init static int latency_fsnotify_init(void)
{
fsnotify_wq = alloc_workqueue("tr_max_lat_wq",
@@ -1959,14 +1945,22 @@ void latency_fsnotify(struct trace_array
*/
irq_work_queue(&tr->fsnotify_irqwork);
}
+#endif /* !LATENCY_FS_NOTIFY */
-#else /* !LATENCY_FS_NOTIFY */
-
-#define trace_create_maxlat_file(tr, d_tracer) \
- trace_create_file("tracing_max_latency", TRACE_MODE_WRITE, \
- d_tracer, tr, &tracing_max_lat_fops)
+static const struct file_operations tracing_max_lat_fops;
+static void trace_create_maxlat_file(struct trace_array *tr,
+ struct dentry *d_tracer)
+{
+#ifdef LATENCY_FS_NOTIFY
+ INIT_WORK(&tr->fsnotify_work, latency_fsnotify_workfn);
+ init_irq_work(&tr->fsnotify_irqwork, latency_fsnotify_workfn_irq);
#endif
+ tr->d_max_latency = trace_create_file("tracing_max_latency",
+ TRACE_MODE_WRITE,
+ d_tracer, tr,
+ &tracing_max_lat_fops);
+}
/*
* Copy the new maximum trace into the separate maximum-trace
@@ -2101,7 +2095,9 @@ update_max_tr_single(struct trace_array
__update_max_tr(tr, tsk, cpu);
arch_spin_unlock(&tr->max_lock);
}
-
+#else /* !CONFIG_TRACER_MAX_TRACE */
+static inline void trace_create_maxlat_file(struct trace_array *tr,
+ struct dentry *d_tracer) { }
#endif /* CONFIG_TRACER_MAX_TRACE */
struct pipe_wait {
@@ -10392,9 +10388,7 @@ init_tracer_tracefs(struct trace_array *
create_trace_options_dir(tr);
-#ifdef CONFIG_TRACER_MAX_TRACE
trace_create_maxlat_file(tr, d_tracer);
-#endif
if (ftrace_create_function_files(tr, d_tracer))
MEM_FAIL(1, "Could not allocate function filter files");
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0028/1518] io_uring: unify task_work cancelation checks
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (26 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0027/1518] tracing: Clean up use of trace_create_maxlat_file() Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0029/1518] nvdimm: preserve flush callback -ENOMEM Greg Kroah-Hartman
` (970 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jens Axboe, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jens Axboe <axboe@kernel.dk>
[ Upstream commit 7be20254a743be4f02414b9d56cc3fe5f84e6500 ]
Rather than do per-tw checking, which needs to dip into the task_struct
for checking flags, do it upfront before running task_work. This places
a 'cancel' member in io_tw_token_t, which is assigned before running
task_work for that given ctx.
This is both more efficient in doing it upfront rather than for every
task_work, and it means that io_should_terminate_tw() can be made
private in io_uring.c rather than need to be called by various
callbacks of task_work.
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Stable-dep-of: 14572de82e50 ("io_uring/waitid: honor task_work cancellation")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
include/linux/io_uring_types.h | 1 +
io_uring/io_uring.c | 27 ++++++++++++++++++++-------
io_uring/io_uring.h | 13 -------------
io_uring/poll.c | 2 +-
io_uring/timeout.c | 2 +-
io_uring/uring_cmd.c | 2 +-
6 files changed, 24 insertions(+), 23 deletions(-)
--- a/include/linux/io_uring_types.h
+++ b/include/linux/io_uring_types.h
@@ -482,6 +482,7 @@ struct io_ring_ctx {
* ONLY core io_uring.c should instantiate this struct.
*/
struct io_tw_state {
+ bool cancel;
};
/* Alias to use in code that doesn't instantiate struct io_tw_state */
typedef struct io_tw_state io_tw_token_t;
--- a/io_uring/io_uring.c
+++ b/io_uring/io_uring.c
@@ -268,6 +268,20 @@ static __cold void io_ring_ctx_ref_free(
complete(&ctx->ref_comp);
}
+/*
+ * Terminate the request if either of these conditions are true:
+ *
+ * 1) It's being executed by the original task, but that task is marked
+ * with PF_EXITING as it's exiting.
+ * 2) PF_KTHREAD is set, in which case the invoker of the task_work is
+ * our fallback task_work.
+ * 3) The ring has been closed and is going away.
+ */
+static inline bool io_should_terminate_tw(struct io_ring_ctx *ctx)
+{
+ return (current->flags & (PF_EXITING | PF_KTHREAD)) || percpu_ref_is_dying(&ctx->refs);
+}
+
static __cold void io_fallback_req_func(struct work_struct *work)
{
struct io_ring_ctx *ctx = container_of(work, struct io_ring_ctx,
@@ -278,8 +292,10 @@ static __cold void io_fallback_req_func(
percpu_ref_get(&ctx->refs);
mutex_lock(&ctx->uring_lock);
- llist_for_each_entry_safe(req, tmp, node, io_task_work.node)
+ llist_for_each_entry_safe(req, tmp, node, io_task_work.node) {
+ ts.cancel = io_should_terminate_tw(req->ctx);
req->io_task_work.func(req, ts);
+ }
io_submit_flush_completions(ctx);
mutex_unlock(&ctx->uring_lock);
percpu_ref_put(&ctx->refs);
@@ -1152,6 +1168,7 @@ struct llist_node *io_handle_tw_list(str
ctx = req->ctx;
mutex_lock(&ctx->uring_lock);
percpu_ref_get(&ctx->refs);
+ ts.cancel = io_should_terminate_tw(ctx);
}
INDIRECT_CALL_2(req->io_task_work.func,
io_poll_task_func, io_req_rw_complete,
@@ -1210,11 +1227,6 @@ struct llist_node *tctx_task_work_run(st
{
struct llist_node *node;
- if (unlikely(current->flags & PF_EXITING)) {
- io_fallback_tw(tctx, true);
- return NULL;
- }
-
node = llist_del_all(&tctx->task_list);
if (node) {
node = llist_reverse_order(node);
@@ -1432,6 +1444,7 @@ static int __io_run_local_work(struct io
if (ctx->flags & IORING_SETUP_TASKRUN_FLAG)
atomic_andnot(IORING_SQ_TASKRUN, &ctx->rings->sq_flags);
again:
+ tw.cancel = io_should_terminate_tw(ctx);
min_events -= ret;
ret = __io_run_local_work_loop(&ctx->retry_llist.first, tw, max_events);
if (ctx->retry_llist.first)
@@ -1491,7 +1504,7 @@ void io_req_task_submit(struct io_kiocb
struct io_ring_ctx *ctx = req->ctx;
io_tw_lock(ctx, tw);
- if (unlikely(io_should_terminate_tw(ctx)))
+ if (unlikely(tw.cancel))
io_req_defer_failed(req, -EFAULT);
else if (req->flags & REQ_F_FORCE_ASYNC)
io_queue_iowq(req);
--- a/io_uring/io_uring.h
+++ b/io_uring/io_uring.h
@@ -582,19 +582,6 @@ static inline bool io_allowed_run_tw(str
ctx->submitter_task == current);
}
-/*
- * Terminate the request if either of these conditions are true:
- *
- * 1) It's being executed by the original task, but that task is marked
- * with PF_EXITING as it's exiting.
- * 2) PF_KTHREAD is set, in which case the invoker of the task_work is
- * our fallback task_work.
- */
-static inline bool io_should_terminate_tw(struct io_ring_ctx *ctx)
-{
- return (current->flags & (PF_KTHREAD | PF_EXITING)) || percpu_ref_is_dying(&ctx->refs);
-}
-
static inline void io_req_queue_tw_complete(struct io_kiocb *req, s32 res)
{
io_req_set_res(req, res, 0);
--- a/io_uring/poll.c
+++ b/io_uring/poll.c
@@ -225,7 +225,7 @@ static int io_poll_check_events(struct i
{
int v;
- if (unlikely(io_should_terminate_tw(req->ctx)))
+ if (unlikely(tw.cancel))
return -ECANCELED;
do {
--- a/io_uring/timeout.c
+++ b/io_uring/timeout.c
@@ -324,7 +324,7 @@ static void io_req_task_link_timeout(str
int ret;
if (prev) {
- if (!io_should_terminate_tw(req->ctx)) {
+ if (!tw.cancel) {
struct io_cancel_data cd = {
.ctx = req->ctx,
.data = prev->cqe.user_data,
--- a/io_uring/uring_cmd.c
+++ b/io_uring/uring_cmd.c
@@ -120,7 +120,7 @@ static void io_uring_cmd_work(struct io_
struct io_uring_cmd *ioucmd = io_kiocb_to_cmd(req, struct io_uring_cmd);
unsigned int flags = IO_URING_F_COMPLETE_DEFER;
- if (io_should_terminate_tw(req->ctx))
+ if (unlikely(tw.cancel))
flags |= IO_URING_F_TASK_DEAD;
/* task_work executor checks the deffered list completion */
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0029/1518] nvdimm: preserve flush callback -ENOMEM
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (27 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0028/1518] io_uring: unify task_work cancelation checks Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0030/1518] ALSA: FCP: do not copy out an uninitialised init response Greg Kroah-Hartman
` (969 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pankaj Gupta, Li Chen,
Michael S. Tsirkin, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Li Chen <me@linux.beauty>
[ Upstream commit 6b7108712a4b1c37cac69815aede1dde202b3187 ]
nvdimm_flush() maps provider flush failures to -EIO. Keep that default
because provider callbacks can report host-side or backend failures that
should remain generic I/O errors to the guest.
Guest-side allocation failures should not be reported as I/O errors. In the
virtio-pmem path, the flush request allocation can fail with -ENOMEM before
any request is submitted to the host. Mapping that to -EIO makes resource
pressure look like media failure.
Preserve -ENOMEM from provider callbacks and continue to map other non-zero
provider failures to -EIO. The generic flush path still returns 0, and
pmem_submit_bio() already converts errno values to block status for bio
completion.
Suggested-by: Pankaj Gupta <pankaj.gupta.linux@gmail.com>
Signed-off-by: Li Chen <me@linux.beauty>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260630092338.2094628-2-me@linux.beauty>
Stable-dep-of: e57140944b5a ("nvdimm: virtio_pmem: refcount requests for token lifetime")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/nvdimm/region_devs.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/drivers/nvdimm/region_devs.c
+++ b/drivers/nvdimm/region_devs.c
@@ -1094,7 +1094,8 @@ int nvdimm_flush(struct nd_region *nd_re
if (!nd_region->flush)
rc = generic_nvdimm_flush(nd_region);
else {
- if (nd_region->flush(nd_region, bio))
+ rc = nd_region->flush(nd_region, bio);
+ if (rc && rc != -ENOMEM)
rc = -EIO;
}
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0030/1518] ALSA: FCP: do not copy out an uninitialised init response
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (28 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0029/1518] nvdimm: preserve flush callback -ENOMEM Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0031/1518] ASoC: tegra: Fix the MIXER enable default value Greg Kroah-Hartman
` (968 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Federico Kirschbaum, Baul Lee,
Takashi Iwai, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Baul Lee <baul.lee@xbow.com>
[ Upstream commit 4335e387786479889e6db691fe06d345e52ea536 ]
fcp_ioctl_init() allocates its response buffer with kmalloc() and copies
the whole buffer back to userspace:
buf_size = init.step0_resp_size + init.step2_resp_size;
void *resp __free(kfree) =
kmalloc(buf_size, GFP_KERNEL);
...
if (copy_to_user(arg->resp, resp, buf_size))
return -EFAULT;
Nothing clears the buffer, and the only writer of its leading
step0_resp_size bytes is the step-0 control transfer:
err = snd_usb_ctl_msg(dev, usb_rcvctrlpipe(dev, 0),
FCP_USB_REQ_STEP0,
USB_RECIP_INTERFACE | USB_TYPE_CLASS | USB_DIR_IN,
0, private->bInterfaceNumber,
step0_resp, private->step0_resp_size);
if (err < 0)
return err;
usb_fill_control_urb() does not set URB_SHORT_NOT_OK, so a short or
zero-length data stage completes with status 0 and snd_usb_ctl_msg()
returns a small actual_length. The only check is err < 0, so a short
transfer is accepted as success.
snd_usb_ctl_msg() copies the full size back unconditionally:
buf = kmemdup(data, size, GFP_KERNEL);
...
memcpy(data, buf, size);
Bytes the device never wrote are therefore restored into resp unchanged
and copied to userspace. step0_resp_size and step2_resp_size are each
validated only to 1..255, so the caller also picks the slab cache, from
kmalloc-8 up to kmalloc-512.
On 7.2.0-rc5 (arm64), device answering step 0 with a zero-length data
stage, s0 = s2 = 255:
# init_on_alloc off, no spray
step0 window [0,255): nonzero=94/255
000: 00 80 60 06 00 00 ff ff 18 00 00 00 57 01 ea 01
010: 08 78 22 13 00 00 ff ff a8 c4 5f 80 00 80 ff ff
# same kernel, kmalloc-512 pre-seeded with an 8-byte tag
step0 window [0,255): nonzero=219/255 tagbytes=232
# identical run, init_on_alloc=1
step0 window [0,255): nonzero=0/255 tagbytes=0
# all three runs
step2 window [255,510): device words matched=62/62
a8 c4 5f 80 00 80 ff ff is the little-endian kernel text address
ffff8000805fc4a8. The step-2 window is unaffected, so the disclosure is
exactly the step-0 region.
Zero the buffer, and require the step-0 transfer to deliver the full
step0_resp_size bytes so a short data stage is reported as an error.
Discovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>
Fixes: 46757a3e7d50 ("ALSA: FCP: Add Focusrite Control Protocol driver")
Reported-by: Federico Kirschbaum <federico.kirschbaum@xbow.com>
Reported-by: Baul Lee <baul.lee@xbow.com>
Cc: stable@vger.kernel.org
Signed-off-by: Baul Lee <baul.lee@xbow.com>
Link: https://patch.msgid.link/20260805013804.38839-1-baul.lee@xbow.com
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/usb/fcp.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
--- a/sound/usb/fcp.c
+++ b/sound/usb/fcp.c
@@ -494,7 +494,7 @@ static int fcp_ioctl_init(struct usb_mix
buf_size = init.step0_resp_size + init.step2_resp_size;
void *resp __free(kfree) =
- kmalloc(buf_size, GFP_KERNEL);
+ kzalloc(buf_size, GFP_KERNEL);
if (!resp)
return -ENOMEM;
@@ -1033,6 +1033,8 @@ static int fcp_init(struct usb_mixer_int
step0_resp, private->step0_resp_size);
if (err < 0)
return err;
+ if (err != private->step0_resp_size)
+ return -EIO;
err = fcp_init_notify(mixer);
if (err < 0)
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0031/1518] ASoC: tegra: Fix the MIXER enable default value
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (29 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0030/1518] ALSA: FCP: do not copy out an uninitialised init response Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0032/1518] i3c: master: Fix recursive locking during device registration Greg Kroah-Hartman
` (967 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jon Hunter, Mark Brown, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jon Hunter <jonathanh@nvidia.com>
[ Upstream commit 5442b8093a2f94ecd4696b3875194be09e2676c5 ]
Commit 4b05ccb17f92 ("regcache: Sort the local copy of an unsorted
reg_defaults array") exposed an issue in the Tegra MIXER driver where
the register default for the TEGRA210_MIXER_ENABLE is specified as 1,
but the hardware default is actually 0. After this commit was added the
MIXER driver is no longer working and so fix this by correcting the
default value for this register and explicitly configuring the
MIXER_ENABLE register when runtime resuming the MIXER device.
Fixes: 05bb3d5ec64a ("ASoC: tegra: Add Tegra210 based Mixer driver")
Cc: stable@vger.kernel.org
Signed-off-by: Jon Hunter <jonathanh@nvidia.com>
Link: https://patch.msgid.link/20260821153734.158426-3-jonathanh@nvidia.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
sound/soc/tegra/tegra210_mixer.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
--- a/sound/soc/tegra/tegra210_mixer.c
+++ b/sound/soc/tegra/tegra210_mixer.c
@@ -57,7 +57,7 @@ static const struct reg_default tegra210
MIXER_TX_REG_DEFAULTS(3),
MIXER_TX_REG_DEFAULTS(4),
- { TEGRA210_MIXER_ENABLE, 0x1 },
+ { TEGRA210_MIXER_ENABLE, 0x0 },
{ TEGRA210_MIXER_CG, 0x00000001},
{ TEGRA210_MIXER_GAIN_CFG_RAM_CTRL, 0x00004000},
{ TEGRA210_MIXER_PEAKM_RAM_CTRL, 0x00004000},
@@ -86,11 +86,15 @@ static int tegra210_mixer_runtime_suspen
static int tegra210_mixer_runtime_resume(struct device *dev)
{
struct tegra210_mixer *mixer = dev_get_drvdata(dev);
+ int err;
regcache_cache_only(mixer->regmap, false);
- regcache_sync(mixer->regmap);
+ err = regcache_sync(mixer->regmap);
+ if (err)
+ return err;
- return 0;
+ return regmap_write(mixer->regmap, TEGRA210_MIXER_ENABLE,
+ TEGRA210_MIXER_EN);
}
static int tegra210_mixer_write_ram(struct tegra210_mixer *mixer,
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0032/1518] i3c: master: Fix recursive locking during device registration
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (30 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0031/1518] ASoC: tegra: Fix the MIXER enable default value Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0033/1518] iio: light: apds9306: fix PM reference leak in apds9306_read_data() Greg Kroah-Hartman
` (966 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Adrian Hunter, Frank Li,
Alexandre Belloni, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Adrian Hunter <adrian.hunter@intel.com>
[ Upstream commit 456f832e5fc26fbfd3b8200fd4553eee520cc377 ]
i3c_master_register_new_i3c_devs() registers newly discovered devices
while holding i3c_bus_normaluse_lock(), a down_read(). device_register()
can immediately probe the device, and probe callbacks typically invoke
I3C helpers that take i3c_bus_normaluse_lock() again, leading to a
recursive acquisition of the same rwsem. rwsems do not support recursive
read locking and can deadlock when a writer is waiting. See the
"Recursive read locks" section of Documentation/locking/lockdep-design.rst.
For example, with Intel LPSS I3C, LOCKDEP generates a WARNING like:
# echo intel-lpss-i3c.0 > /sys/bus/platform/drivers/mipi-i3c-hci/unbind
# echo intel-lpss-i3c.0 > /sys/bus/platform/drivers/mipi-i3c-hci/bind
WARNING: possible recursive locking detected
kworker/5:1/94 is trying to acquire lock:
ffff88811c810d78 (&i3cbus->lock){++++}-{4:4}, at: i3c_device_match_id+0x45/0x370
but task is already holding lock:
ffff88811c810d78 (&i3cbus->lock){++++}-{4:4}, at: i3c_master_reg_work_fn+0x21/0x5f0
Fix this by separating device creation from device registration.
Populate desc->dev under the maintenance lock, collect the devices that
still need registration into a local list, then release the lock before
calling device_register(). Finally retake the lock and clean up any
devices that failed to register.
Use the maintenance lock rather than the normal-use lock while adding
device objects. A write-side maintenance lock prevents readers from
observing a partially initialized desc->dev during initial device
population, or desc->dev disappearing if registration fails.
The local list requires a list node, so add a list node member to struct
i3c_device.
Fixes: 3a379bbcea0a ("i3c: Add core I3C infrastructure")
Cc: stable@vger.kernel.org
Signed-off-by: Adrian Hunter <adrian.hunter@intel.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260807145638.168865-2-adrian.hunter@intel.com
Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i3c/master.c | 45 +++++++++++++++++++++++++++++++++------------
include/linux/i3c/master.h | 3 +++
2 files changed, 36 insertions(+), 12 deletions(-)
--- a/drivers/i3c/master.c
+++ b/drivers/i3c/master.c
@@ -1787,12 +1787,21 @@ err_free_dev:
static void
i3c_master_register_new_i3c_devs(struct i3c_master_controller *master)
{
+ struct i3c_device *i3cdev, *tmp;
struct i3c_dev_desc *desc;
+ LIST_HEAD(i3c_unreg_devs);
int ret;
if (!master->init_done)
return;
+ i3c_bus_maintenance_lock(&master->bus);
+
+ if (master->shutting_down) {
+ i3c_bus_maintenance_unlock(&master->bus);
+ return;
+ }
+
i3c_bus_for_each_i3cdev(&master->bus, desc) {
if (desc->dev || !desc->info.dyn_addr || desc == master->this)
continue;
@@ -1813,25 +1822,37 @@ i3c_master_register_new_i3c_devs(struct
if (desc->boardinfo)
desc->dev->dev.of_node = desc->boardinfo->of_node;
- ret = device_register(&desc->dev->dev);
- if (ret) {
- dev_err(&master->dev,
- "Failed to add I3C device (err = %d)\n", ret);
- desc->dev->desc = NULL;
- put_device(&desc->dev->dev);
- desc->dev = NULL;
- }
+ list_add_tail(&desc->dev->node, &i3c_unreg_devs);
}
+
+ i3c_bus_maintenance_unlock(&master->bus);
+
+ list_for_each_entry_safe(i3cdev, tmp, &i3c_unreg_devs, node) {
+ ret = device_register(&i3cdev->dev);
+ if (ret)
+ dev_err(&master->dev, "Failed to add I3C device (err = %d)\n", ret);
+ else
+ list_del_init(&i3cdev->node);
+ }
+
+ i3c_bus_maintenance_lock(&master->bus);
+
+ list_for_each_entry_safe(i3cdev, tmp, &i3c_unreg_devs, node) {
+ list_del(&i3cdev->node);
+ desc = i3cdev->desc;
+ i3cdev->desc = NULL;
+ put_device(&i3cdev->dev);
+ desc->dev = NULL;
+ }
+
+ i3c_bus_maintenance_unlock(&master->bus);
}
static void i3c_master_reg_work_fn(struct work_struct *work)
{
struct i3c_master_controller *master = container_of(work, typeof(*master), reg_work);
- i3c_bus_normaluse_lock(&master->bus);
- if (!master->shutting_down)
- i3c_master_register_new_i3c_devs(master);
- i3c_bus_normaluse_unlock(&master->bus);
+ i3c_master_register_new_i3c_devs(master);
}
/**
--- a/include/linux/i3c/master.h
+++ b/include/linux/i3c/master.h
@@ -228,6 +228,8 @@ struct i3c_dev_desc {
* every time the I3C device is rediscovered with a different dynamic
* address assigned
* @bus: I3C bus this device is attached to
+ * @node: unregistered device list node, only for use by
+ * i3c_master_register_new_i3c_devs(), it is not protected by a lock
*
* I3C device object exposed to I3C device drivers. The takes care of linking
* this object to the relevant &struct_i3c_dev_desc one.
@@ -238,6 +240,7 @@ struct i3c_device {
struct device dev;
struct i3c_dev_desc *desc;
struct i3c_bus *bus;
+ struct list_head node;
};
/*
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0033/1518] iio: light: apds9306: fix PM reference leak in apds9306_read_data()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (31 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0032/1518] i3c: master: Fix recursive locking during device registration Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0034/1518] misc: fastrpc: dont publish fd before copy_to_user() succeeds Greg Kroah-Hartman
` (965 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Moksh Panicker, Jonathan Cameron,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Moksh Panicker <mokshpanicker.7@gmail.com>
[ Upstream commit d378fceaafd79e0dc59d3546bda251a3058062c0 ]
apds9306_read_data() calls pm_runtime_resume_and_get() but several
error paths return directly without calling pm_runtime_put_autosuspend(),
leaking the runtime PM reference and preventing the device from
autosuspending.
Use PM_RUNTIME_ACQUIRE_AUTOSUSPEND() and PM_RUNTIME_ACQUIRE_ERR() to
automatically handle runtime PM reference release on all return paths.
Fixes: 620d1e6c7a3f ("iio: light: Add support for APDS9306 Light Sensor")
Signed-off-by: Moksh Panicker <mokshpanicker.7@gmail.com>
Cc: stable@vger.kernel.org
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/iio/light/apds9306.c | 8 +++-----
1 file changed, 3 insertions(+), 5 deletions(-)
--- a/drivers/iio/light/apds9306.c
+++ b/drivers/iio/light/apds9306.c
@@ -471,9 +471,9 @@ static int apds9306_read_data(struct apd
int status = 0;
u8 buff[3];
- ret = pm_runtime_resume_and_get(data->dev);
- if (ret)
- return ret;
+ PM_RUNTIME_ACQUIRE_AUTOSUSPEND(data->dev, pm);
+ if (PM_RUNTIME_ACQUIRE_ERR(&pm))
+ return PM_RUNTIME_ACQUIRE_ERR(&pm);
ret = regmap_field_read(rf->intg_time, &intg_time_idx);
if (ret)
@@ -537,8 +537,6 @@ static int apds9306_read_data(struct apd
*val = get_unaligned_le24(&buff);
- pm_runtime_put_autosuspend(data->dev);
-
return 0;
}
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0034/1518] misc: fastrpc: dont publish fd before copy_to_user() succeeds
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (32 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0033/1518] iio: light: apds9306: fix PM reference leak in apds9306_read_data() Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0035/1518] mtd: rawnand: pl353: Make sure we use the monolithic helpers for raw accesses Greg Kroah-Hartman
` (964 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian König, Sumit Semwal,
Baineng Shou, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Baineng Shou <shoubaineng@gmail.com>
[ Upstream commit a4a1a2bfcb29785292d634d7787edc6fb550714d ]
fastrpc_ioctl_alloc_dmabuf() calls dma_buf_fd() which installs the fd
into the caller's fd table before copy_to_user() copies the fd number
back to userspace. If copy_to_user() fails, the fd is already visible
to other threads in the same process but the ioctl returns -EFAULT.
The existing comment in the code even acknowledges the problem:
"The usercopy failed, but we can't do much about it, as dma_buf_fd()
already called fd_install()..."
Now that dma_buf_fd_install() is available (introduced to fix the same
issue in dma-heap), apply the same pattern here: reserve the fd with
get_unused_fd_flags(), attempt copy_to_user(), and only on success call
dma_buf_fd_install() to publish it atomically with the tracepoint. On
copy_to_user() failure, put_unused_fd() and dma_buf_put() cleanly
unwind without any user-visible side effects.
Fixes: 6cffd79504ce ("misc: fastrpc: Add support for dmabuf exporter")
Cc: stable@vger.kernel.org
Acked-by: Christian König <christian.koenig@amd.com>
Acked-by: Sumit Semwal <sumit.semwal@linaro.org>
Signed-off-by: Baineng Shou <shoubaineng@gmail.com>
Link: https://lore.kernel.org/r/20260817050457.1005285-3-shoubaineng@gmail.com
Signed-off-by: Christian König <christian.koenig@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/misc/fastrpc.c | 16 ++++++----------
1 file changed, 6 insertions(+), 10 deletions(-)
--- a/drivers/misc/fastrpc.c
+++ b/drivers/misc/fastrpc.c
@@ -1681,24 +1681,20 @@ static int fastrpc_dmabuf_alloc(struct f
return err;
}
- bp.fd = dma_buf_fd(buf->dmabuf, O_ACCMODE);
+ bp.fd = get_unused_fd_flags(O_ACCMODE);
if (bp.fd < 0) {
dma_buf_put(buf->dmabuf);
- return -EINVAL;
+ return bp.fd;
}
if (copy_to_user(argp, &bp, sizeof(bp))) {
- /*
- * The usercopy failed, but we can't do much about it, as
- * dma_buf_fd() already called fd_install() and made the
- * file descriptor accessible for the current process. It
- * might already be closed and dmabuf no longer valid when
- * we reach this point. Therefore "leak" the fd and rely on
- * the process exit path to do any required cleanup.
- */
+ put_unused_fd(bp.fd);
+ dma_buf_put(buf->dmabuf);
return -EFAULT;
}
+ dma_buf_fd_install(buf->dmabuf, bp.fd);
+
return 0;
}
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0035/1518] mtd: rawnand: pl353: Make sure we use the monolithic helpers for raw accesses
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (33 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0034/1518] misc: fastrpc: dont publish fd before copy_to_user() succeeds Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0036/1518] net/mlx5e: do not HW-GRO coalesce small frames Greg Kroah-Hartman
` (963 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Andrea Scian, Miquel Raynal (DAVE),
Michal Simek, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: "Miquel Raynal (DAVE)" <miquel.raynal@bootlin.com>
[ Upstream commit 80ecacd054ffeb60cd28e46ed5cd6bd0d2de318b ]
Any access not using the hardware ECC engine should be monolithic
because the controller has its very own way of handling the end of a
transaction during operation configuration, so we cannot easily make
repeated reads.
This has the side effect of fixing support for software ECC engines.
Suggested-by: Andrea Scian <andrea.scian@dave.eu>
Cc: stable@vger.kernel.org
Fixes: 08d8c62164a3 ("mtd: rawnand: pl353: Add support for the ARM PL353 SMC NAND controller")
Signed-off-by: Miquel Raynal (DAVE) <miquel.raynal@bootlin.com>
Acked-by: Michal Simek <michal.simek@amd.com>
Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/mtd/nand/raw/pl35x-nand-controller.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
--- a/drivers/mtd/nand/raw/pl35x-nand-controller.c
+++ b/drivers/mtd/nand/raw/pl35x-nand-controller.c
@@ -914,7 +914,6 @@ static int pl35x_nand_init_hw_ecc_contro
chip->ecc.steps = mtd->writesize / chip->ecc.size;
chip->ecc.read_page = pl35x_nand_read_page_hwecc;
chip->ecc.write_page = pl35x_nand_write_page_hwecc;
- chip->ecc.write_page_raw = nand_monolithic_write_page_raw;
pl35x_smc_set_ecc_pg_size(nfc, chip, mtd->writesize);
nfc->ecc_buf = devm_kmalloc(nfc->dev, chip->ecc.bytes * chip->ecc.steps,
@@ -981,7 +980,6 @@ static int pl35x_nand_attach_chip(struct
case NAND_ECC_ENGINE_TYPE_NONE:
case NAND_ECC_ENGINE_TYPE_SOFT:
dev_dbg(nfc->dev, "Using software ECC (Hamming 1-bit/512B)\n");
- chip->ecc.write_page_raw = nand_monolithic_write_page_raw;
break;
case NAND_ECC_ENGINE_TYPE_ON_HOST:
dev_dbg(nfc->dev, "Using hardware ECC\n");
@@ -995,6 +993,9 @@ static int pl35x_nand_attach_chip(struct
return -EINVAL;
}
+ chip->ecc.read_page_raw = nand_monolithic_read_page_raw;
+ chip->ecc.write_page_raw = nand_monolithic_write_page_raw;
+
return 0;
}
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0036/1518] net/mlx5e: do not HW-GRO coalesce small frames
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (34 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0035/1518] mtd: rawnand: pl353: Make sure we use the monolithic helpers for raw accesses Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0037/1518] nvme: skip the zoned limits update if the zone info query failed Greg Kroah-Hartman
` (962 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Glenn Judd, Tariq Toukan,
Jakub Kicinski, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Glenn Judd <gmj@meta.com>
[ Upstream commit e2466392a0b8496000e12181cb1ee1535eb0da25 ]
When hardware GRO (SHAMPO) coalesces a small IPv4/TCP segment that was
padded up to the 60-byte minimum Ethernet frame, the trailing padding is
folded into the merged payload causing padding to be delivered
to the user as payload.
Detecting and reproducing the issue: the selftest
tools/testing/selftests/drivers/net/gro.py subtest
hw_ipv4_data_lrg_1byte sends {100, 1} expecting to receive {101}.
In current code, it receives {106} (100 + 1 payload + 5 pad) instead.
This patch avoids giving the user padding as payload by simply not
coalescing small packets (which fails the subtest; the same approach
and behavior as sw gro). This gains code simplicity at the cost of
more computation (passing an extra skb up the stack) for small packets
that could be coalesced.
The threshold is chosen as ETH_ZLEN + 2 * VLAN_HLEN. This is the largest
frame that may still contain minimum-frame padding (+ 2 VLAN tags), so
anything larger is safe to consider for coalesce. (We do not include
ETH_FCS_LEN in that threshold computation as netdev_fix_features()
drops NETIF_F_GRO_HW whenever NETIF_F_RXFCS is set, so retained FCS
can't reach this path.)
Fixes: 92552d3abd32 ("net/mlx5e: HW_GRO cqe handler implementation")
Cc: stable@vger.kernel.org
Signed-off-by: Glenn Judd <gmj@meta.com>
Signed-off-by: Tariq Toukan <tariqt@nvidia.com>
Link: https://patch.msgid.link/20260816064259.3279548-1-tariqt@nvidia.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/ethernet/mellanox/mlx5/core/en_rx.c | 5 +++++
1 file changed, 5 insertions(+)
--- a/drivers/net/ethernet/mellanox/mlx5/core/en_rx.c
+++ b/drivers/net/ethernet/mellanox/mlx5/core/en_rx.c
@@ -2401,6 +2401,11 @@ static void mlx5e_handle_rx_cqe_mpwrq_sh
data_offset = wqe_offset & (page_size - 1);
page_idx = wqe_offset >> rq->mpwqe.page_shift;
+ if (unlikely(cqe_bcnt <= ETH_ZLEN + 2 * VLAN_HLEN)) {
+ match = false;
+ flush = true;
+ }
+
if (*skb &&
!(match && mlx5e_hw_gro_skb_has_enough_space(*skb, data_bcnt,
page_size))) {
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0037/1518] nvme: skip the zoned limits update if the zone info query failed
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (35 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0036/1518] net/mlx5e: do not HW-GRO coalesce small frames Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0038/1518] PCI: Allow per function PCI slots to fix slot reset on s390 Greg Kroah-Hartman
` (961 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Weidong Zhu, Keith Busch,
Christoph Hellwig, Chao Shi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chao Shi <coshi036@gmail.com>
[ Upstream commit 3838e80fcfb32e62baffb63c6dc0a60153665a4d ]
nvme_query_zone_info() returns either a negative errno or a positive
NVMe status code, but nvme_update_ns_info_block() only tests for the
negative case:
ret = nvme_query_zone_info(ns, lbaf, &zi);
if (ret < 0)
goto out;
If the device fails the Identify Namespace (I/O Command Set specific)
command, or the Identify Controller command issued by
nvme_set_max_append(), the positive status falls through and setup
continues with the zero-initialized zone info. nvme_update_zone_info()
then marks the queue zoned with chunk_sectors and ns->head->zsze set to
zero.
blk_validate_zoned_limits() does not check chunk_sectors, so the limits
commit succeeds. blk_revalidate_disk_zones() does reject the zero zone
size, but by then the limits are live and nothing rolls them back, so
I/O keeps being submitted to a zoned queue with a zero zone size and
disk_zone_no() shifts by ilog2(0):
nvme0n1: Invalid non power of two zone size (0)
UBSAN: shift-out-of-bounds in include/linux/blkdev.h:747:16
shift exponent -1 is negative
disk_zone_no include/linux/blkdev.h:747 [inline]
bio_straddles_zones include/linux/blkdev.h:1058 [inline]
blk_zone_wplug_handle_write block/blk-zoned.c:1423 [inline]
blk_zone_plug_bio.cold+0x25/0x1c8 block/blk-zoned.c:1605
blk_mq_submit_bio+0x18fb/0x2870 block/blk-mq.c:3196
submit_bh_wbc+0x575/0x740 fs/buffer.c:2824
__block_write_full_folio+0x728/0xdd0 fs/buffer.c:1933
Any device, firmware or NVMe-oF target that fails this one command
reaches this.
Skip the zoned limits update in that case, and log which of the two
things happened: during a revalidation the queue keeps the zone
geometry it was last validated with, and on a first scan the namespace
is registered without zoned limits, so that it is still available as a
handle for admin commands. Neither of the paths in
nvme_query_zone_info() that return a positive status logs anything, so
the failure would otherwise be silent.
zi.zone_size is an exact indicator: every path that returns a positive
status returns before it is assigned, and after that the only failure
left is -ENODEV, which the caller already handles.
Found by FuzzNvme.
Fixes: c85c9ab926a5 ("nvme: split nvme_update_zone_info")
Cc: stable@vger.kernel.org
Cc: Weidong Zhu <weizhu@fiu.edu>
Suggested-by: Keith Busch <kbusch@kernel.org>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Chao Shi <coshi036@gmail.com>
Signed-off-by: Keith Busch <kbusch@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/nvme/host/core.c | 21 +++++++++++++++++++--
1 file changed, 19 insertions(+), 2 deletions(-)
--- a/drivers/nvme/host/core.c
+++ b/drivers/nvme/host/core.c
@@ -2383,9 +2383,26 @@ static int nvme_update_ns_info_block(str
if (!nvme_update_disk_info(ns, id, &lim))
capacity = 0;
+ /*
+ * A failed zone info query leaves zi zero-initialized, so skip the
+ * zoned limits update instead of configuring the queue from it.
+ * During a revalidation that keeps the zone geometry the queue was
+ * last validated with; on a first scan the namespace is registered
+ * without zoned limits, so that it is still available as a handle
+ * for admin commands.
+ */
if (IS_ENABLED(CONFIG_BLK_DEV_ZONED) &&
- ns->head->ids.csi == NVME_CSI_ZNS)
- nvme_update_zone_info(ns, &lim, &zi);
+ ns->head->ids.csi == NVME_CSI_ZNS) {
+ if (zi.zone_size)
+ nvme_update_zone_info(ns, &lim, &zi);
+ else
+ dev_warn(ns->ctrl->device,
+ "zone info query failed for nsid %u, %s\n",
+ ns->head->ns_id,
+ blk_queue_is_zoned(ns->disk->queue) ?
+ "keeping the previous zone limits" :
+ "not enabling zoned mode");
+ }
if ((ns->ctrl->vwc & NVME_CTRL_VWC_PRESENT) && !info->no_vwc)
lim.features |= BLK_FEAT_WRITE_CACHE | BLK_FEAT_FUA;
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0038/1518] PCI: Allow per function PCI slots to fix slot reset on s390
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (36 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0037/1518] nvme: skip the zoned limits update if the zone info query failed Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0039/1518] perf: Fix use-after-free when perf mmap() revival races with the last munmap() Greg Kroah-Hartman
` (960 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Niklas Schnelle, Farhan Ali,
Bjorn Helgaas, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Farhan Ali <alifm@linux.ibm.com>
[ Upstream commit dcc5bec09e23bbc4f9de055a11fce9937244f2c8 ]
On s390 systems, which use a machine level hypervisor, PCI devices are
always accessed through a form of PCI pass-through which fundamentally
operates on a per PCI function granularity. This is also reflected in the
s390 PCI hotplug driver which creates hotplug slots for individual PCI
functions. Its reset_slot() function, which is a wrapper for
zpci_hot_reset_device(), thus also resets individual functions.
Currently, the pci_create_slot() assigns the same pci_slot object to
multifunction devices. This approach worked fine on s390 systems that only
exposed virtual functions as individual PCI domains to the operating
system. Since commit 44510d6fa0c0 ("s390/pci: Handling multifunctions")
s390 supports exposing the topology of multifunction PCI devices by
grouping them in a shared PCI domain. This creates a problem when resetting
a function through the hotplug driver's slot_reset() interface.
When attempting to reset a function through the hotplug driver, the shared
slot assignment causes the wrong function to be reset instead of the
intended one. It also leaks memory as we do create a pci_slot object for
the function, but don't correctly free it in pci_slot_release().
Add a flag for struct pci_slot to allow per function PCI slots for
functions managed through a hypervisor, which exposes individual PCI
functions while retaining the topology. Since we can use all 8 bits for
slot 'number' (for ARI devices), change slot 'number' u16 to account for
special values PCI_SLOT_PLACEHOLDER and PCI_SLOT_ALL_DEVICES.
Fixes: 44510d6fa0c0 ("s390/pci: Handling multifunctions")
Suggested-by: Niklas Schnelle <schnelle@linux.ibm.com>
Signed-off-by: Farhan Ali <alifm@linux.ibm.com>
Signed-off-by: Bjorn Helgaas <bhelgaas@google.com>
Reviewed-by: Niklas Schnelle <schnelle@linux.ibm.com>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260805165518.794-3-alifm@linux.ibm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/pci/pci.c | 5 +++--
drivers/pci/slot.c | 29 +++++++++++++++++++++++------
include/linux/pci.h | 7 ++++---
3 files changed, 30 insertions(+), 11 deletions(-)
--- a/drivers/pci/pci.c
+++ b/drivers/pci/pci.c
@@ -4828,8 +4828,9 @@ static int pci_reset_hotplug_slot(struct
static int pci_dev_reset_slot_function(struct pci_dev *dev, bool probe)
{
- if (dev->multifunction || dev->subordinate || !dev->slot ||
- dev->dev_flags & PCI_DEV_FLAGS_NO_BUS_RESET)
+ if (dev->subordinate || !dev->slot ||
+ dev->dev_flags & PCI_DEV_FLAGS_NO_BUS_RESET ||
+ (dev->multifunction && !dev->slot->per_func_slot))
return -ENOTTY;
return pci_reset_hotplug_slot(dev->slot->hotplug, probe);
--- a/drivers/pci/slot.c
+++ b/drivers/pci/slot.c
@@ -72,6 +72,23 @@ static ssize_t cur_speed_read_file(struc
return bus_speed_read(slot->bus->cur_bus_speed, buf);
}
+static bool pci_dev_matches_slot(struct pci_dev *dev, struct pci_slot *slot)
+{
+ if (slot->per_func_slot)
+ return dev->devfn == slot->number;
+
+ return slot->number == PCI_SLOT_ALL_DEVICES ||
+ PCI_SLOT(dev->devfn) == slot->number;
+}
+
+static bool pci_slot_enabled_per_func(void)
+{
+ if (IS_ENABLED(CONFIG_S390))
+ return true;
+
+ return false;
+}
+
static void pci_slot_release(struct kobject *kobj)
{
struct pci_dev *dev;
@@ -82,8 +99,7 @@ static void pci_slot_release(struct kobj
down_read(&pci_bus_sem);
list_for_each_entry(dev, &slot->bus->devices, bus_list)
- if (slot->number == PCI_SLOT_ALL_DEVICES ||
- PCI_SLOT(dev->devfn) == slot->number)
+ if (pci_dev_matches_slot(dev, slot))
dev->slot = NULL;
up_read(&pci_bus_sem);
@@ -176,8 +192,7 @@ void pci_dev_assign_slot(struct pci_dev
mutex_lock(&pci_slot_mutex);
list_for_each_entry(slot, &dev->bus->slots, list)
- if (slot->number == PCI_SLOT_ALL_DEVICES ||
- PCI_SLOT(dev->devfn) == slot->number)
+ if (pci_dev_matches_slot(dev, slot))
dev->slot = slot;
mutex_unlock(&pci_slot_mutex);
}
@@ -288,6 +303,9 @@ placeholder:
slot->bus = pci_bus_get(parent);
slot->number = slot_nr;
+ if (pci_slot_enabled_per_func())
+ slot->per_func_slot = 1;
+
slot->kobj.kset = pci_slots_kset;
slot_name = make_slot_name(name);
@@ -308,8 +326,7 @@ placeholder:
down_read(&pci_bus_sem);
list_for_each_entry(dev, &parent->devices, bus_list)
- if (slot_nr == PCI_SLOT_ALL_DEVICES ||
- PCI_SLOT(dev->devfn) == slot_nr)
+ if (pci_dev_matches_slot(dev, slot))
dev->slot = slot;
up_read(&pci_bus_sem);
--- a/include/linux/pci.h
+++ b/include/linux/pci.h
@@ -78,17 +78,18 @@
* and, if ARI Forwarding is enabled, functions may appear to be on multiple
* devices.
*/
-#define PCI_SLOT_ALL_DEVICES 0xfe
+#define PCI_SLOT_ALL_DEVICES 0xfeff
/* Used to identify a slot as a placeholder */
-#define PCI_SLOT_PLACEHOLDER 0xff
+#define PCI_SLOT_PLACEHOLDER 0xffff
/* pci_slot represents a physical slot */
struct pci_slot {
struct pci_bus *bus; /* Bus this slot is on */
struct list_head list; /* Node in list of slots */
struct hotplug_slot *hotplug; /* Hotplug info (move here) */
- unsigned char number; /* Device nr, or PCI_SLOT_ALL_DEVICES */
+ u16 number; /* Device nr, or PCI_SLOT_ALL_DEVICES */
+ unsigned int per_func_slot:1; /* Allow per function slot */
struct kobject kobj;
};
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0039/1518] perf: Fix use-after-free when perf mmap() revival races with the last munmap()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (37 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0038/1518] PCI: Allow per function PCI slots to fix slot reset on s390 Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0040/1518] platform/x86: int1092: Fix potential memory leak in sar_probe() Greg Kroah-Hartman
` (959 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kimi Security Team, Peter Zijlstra,
Weiming Shi, Yilin Zhang, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yilin Zhang <yilinzhang@moonshot.ai>
[ Upstream commit 58a8108bc73de0740d5b88150465d6690ea5f85f ]
perf_mmap_close() drops rb->mmap_count *without* holding
event->mmap_mutex (the refcount_dec_and_test() right before the
refcount_dec_and_mutex_lock() of event->mmap_count). A concurrent
perf_mmap_rb() can slot its entire "revival" path into that window
(perf_mmap holds event->mmap_mutex for its whole duration, including
rb_alloc):
munmap side (perf_mmap_close) mmap side (perf_mmap_rb)
----------------------------------- --------------------------------
rb->mmap_count 1 -> 0 (no lock) (holds event->mmap_mutex)
inc_not_zero(rb->mmap_count) fails
ring_buffer_attach(event, NULL)
rb_alloc() + attach new rb
refcount_set(&event->mmap_count, 1)
lock; event->mmap_count 1 -> 0
ring_buffer_attach(event, NULL)
ring_buffer_put() -> frees the *new* rb
The revival's refcount_set(&event->mmap_count, 1) is an invisible
1 -> 1 write: the close frees the just-revived buffer although the
other process still has it mapped -- a page-level use-after-free
allowing local privilege escalation to root by any unprivileged user
(default kernel.perf_event_paranoid=2).
Swap the order of the two counter updates: event->mmap_count is
dropped first via refcount_dec_and_mutex_lock(), so its 1 -> 0
transition and the ring_buffer_attach() stay serialized with
perf_mmap(). rb->mmap_count == 0 then implies every event using the
buffer is detached already, so the result of the rb->mmap_count drop
can gate the remaining teardown directly and detach_rest is no longer
needed.
An earlier fix for this race from Kyle Zeng and David Lee takes
event->mmap_mutex around both counter updates [0]; here the not-last
close stays lockless.
Fixes: 59741451b49c ("perf: Identify the 0->1 transition for event::mmap_count")
Reported-by: Kimi Security Team <bug-report@moonshot.ai>
Suggested-by: Peter Zijlstra <peterz@infradead.org>
Co-developed-by: Weiming Shi <shiweiming@moonshot.ai>
Signed-off-by: Weiming Shi <shiweiming@moonshot.ai>
Signed-off-by: Yilin Zhang <yilinzhang@moonshot.ai>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Link: https://lore.kernel.org/linux-perf-users/20260804060931.711308-1-david.lee@trailofbits.com/ [0]
Cc: <stable@vger.kernel.org>
Cc: stable@vger.kernel.org # 6.18+
Link: https://patch.msgid.link/20260831162155.1437652-1-yilinzhang@moonshot.ai
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/events/core.c | 20 ++++++++++----------
1 file changed, 10 insertions(+), 10 deletions(-)
--- a/kernel/events/core.c
+++ b/kernel/events/core.c
@@ -6753,7 +6753,6 @@ static void perf_mmap_close(struct vm_ar
mapped_f unmapped = get_mapped(event, event_unmapped);
struct perf_buffer *rb = ring_buffer_get(event);
struct user_struct *mmap_user = rb->mmap_user;
- bool detach_rest = false;
/* FIXIES vs perf_pmu_unregister() */
if (unmapped)
@@ -6784,17 +6783,18 @@ static void perf_mmap_close(struct vm_ar
mutex_unlock(&rb->aux_mutex);
}
- if (refcount_dec_and_test(&rb->mmap_count))
- detach_rest = true;
-
- if (!refcount_dec_and_mutex_lock(&event->mmap_count, &event->mmap_mutex))
- goto out_put;
-
- ring_buffer_attach(event, NULL);
- mutex_unlock(&event->mmap_mutex);
+ /*
+ * Drop references in reverse order of perf_mmap() to prevent
+ * rb revival after rb->mmap_count reaches zero.
+ */
+ if (refcount_dec_and_mutex_lock(&event->mmap_count,
+ &event->mmap_mutex)) {
+ ring_buffer_attach(event, NULL);
+ mutex_unlock(&event->mmap_mutex);
+ }
/* If there's still other mmap()s of this buffer, we're done. */
- if (!detach_rest)
+ if (!refcount_dec_and_test(&rb->mmap_count))
goto out_put;
/*
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0040/1518] platform/x86: int1092: Fix potential memory leak in sar_probe()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (38 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0039/1518] perf: Fix use-after-free when perf mmap() revival races with the last munmap() Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0041/1518] platform/x86: ISST: Validate max level for set feature Greg Kroah-Hartman
` (958 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Abdun Nihaal, Ilpo Järvinen,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Abdun Nihaal <nihaal@cse.iitm.ac.in>
[ Upstream commit 30c906cff490c3601ee9ff110fe8115fabe75fd4 ]
The memory allocated for device_mode_info in parse_package() called by
sar_get_data() is not freed in some of the error paths in sar_probe().
Fix that by converting to use device managed allocations.
Fixes: dcfbd31ef4bc ("platform/x86: BIOS SAR driver for Intel M.2 Modem")
Cc: stable@vger.kernel.org
Signed-off-by: Abdun Nihaal <nihaal@cse.iitm.ac.in>
Link: https://patch.msgid.link/20260723-platx86-v4-1-93b4a178b595@cse.iitm.ac.in
Reviewed-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/platform/x86/intel/int1092/intel_sar.c | 32 +++++++------------------
1 file changed, 10 insertions(+), 22 deletions(-)
--- a/drivers/platform/x86/intel/int1092/intel_sar.c
+++ b/drivers/platform/x86/intel/int1092/intel_sar.c
@@ -91,8 +91,10 @@ static acpi_status parse_package(struct
item->package.count <= data->total_dev_mode)
return AE_ERROR;
- data->device_mode_info = kmalloc_objs(struct wwan_device_mode_info,
- data->total_dev_mode);
+ data->device_mode_info = devm_kmalloc_array(&context->sar_device->dev,
+ data->total_dev_mode,
+ sizeof(*data->device_mode_info),
+ GFP_KERNEL);
if (!data->device_mode_info)
return AE_ERROR;
@@ -253,7 +255,7 @@ static int sar_probe(struct platform_dev
if (!handle)
return -ENODEV;
- context = kzalloc_obj(*context);
+ context = devm_kzalloc(&device->dev, sizeof(*context), GFP_KERNEL);
if (!context)
return -ENOMEM;
@@ -264,7 +266,7 @@ static int sar_probe(struct platform_dev
result = guid_parse(SAR_DSM_UUID, &context->guid);
if (result) {
dev_err(&device->dev, "SAR UUID parse error: %d\n", result);
- goto r_free;
+ return result;
}
for (reg = 0; reg < MAX_REGULATORY; reg++)
@@ -272,43 +274,29 @@ static int sar_probe(struct platform_dev
if (sar_get_device_mode(device) != AE_OK) {
dev_err(&device->dev, "Failed to get device mode\n");
- result = -EIO;
- goto r_free;
+ return -EIO;
}
result = sysfs_create_group(&device->dev.kobj, &intcsar_group);
if (result) {
dev_err(&device->dev, "sysfs creation failed\n");
- goto r_free;
+ return result;
}
if (acpi_install_notify_handler(ACPI_HANDLE(&device->dev), ACPI_DEVICE_NOTIFY,
sar_notify, (void *)device) != AE_OK) {
dev_err(&device->dev, "Failed acpi_install_notify_handler\n");
- result = -EIO;
- goto r_sys;
+ sysfs_remove_group(&device->dev.kobj, &intcsar_group);
+ return -EIO;
}
return 0;
-
-r_sys:
- sysfs_remove_group(&device->dev.kobj, &intcsar_group);
-r_free:
- kfree(context);
- return result;
}
static void sar_remove(struct platform_device *device)
{
- struct wwan_sar_context *context = dev_get_drvdata(&device->dev);
- int reg;
-
acpi_remove_notify_handler(ACPI_HANDLE(&device->dev),
ACPI_DEVICE_NOTIFY, sar_notify);
sysfs_remove_group(&device->dev.kobj, &intcsar_group);
- for (reg = 0; reg < MAX_REGULATORY; reg++)
- kfree(context->config_data[reg].device_mode_info);
-
- kfree(context);
}
static struct platform_driver sar_driver = {
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0041/1518] platform/x86: ISST: Validate max level for set feature
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (39 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0040/1518] platform/x86: int1092: Fix potential memory leak in sar_probe() Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0042/1518] ring-buffer: Allow splice reads on static buffers Greg Kroah-Hartman
` (957 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Srinivas Pandruvada,
Ilpo Järvinen, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Srinivas Pandruvada <srinivas.pandruvada@linux.intel.com>
[ Upstream commit e45d6b8472861d3bac86bb37f8556a7c5aca3266 ]
Validate the level before setting, so that it fails early instead of
failing later when checking the bit mask for allowed levels.
Fixes: ea009e4769fa3 ("platform/x86: ISST: Add SST-PP support via TPMI")
Cc: stable@vger.kernel.org
Signed-off-by: Srinivas Pandruvada <srinivas.pandruvada@linux.intel.com>
Link: https://patch.msgid.link/20260811221514.3905817-3-srinivas.pandruvada@linux.intel.com
Reviewed-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/platform/x86/intel/speed_select_if/isst_tpmi_core.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/platform/x86/intel/speed_select_if/isst_tpmi_core.c
+++ b/drivers/platform/x86/intel/speed_select_if/isst_tpmi_core.c
@@ -974,6 +974,9 @@ static int isst_if_set_perf_level(void _
if (!power_domain_info)
return -EINVAL;
+ if (perf_level.level > power_domain_info->max_level)
+ return -EINVAL;
+
if (power_domain_info->write_blocked || !capable(CAP_SYS_ADMIN))
return -EPERM;
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0042/1518] ring-buffer: Allow splice reads on static buffers
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (40 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0041/1518] platform/x86: ISST: Validate max level for set feature Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0043/1518] staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie() Greg Kroah-Hartman
` (956 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vincent Donnefort, Steven Rostedt,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vincent Donnefort <vdonnefort@google.com>
[ Upstream commit 6365c44a824ff138e7926413932bb5c2e28a4c8c ]
ring_buffer_read_page() rejects splice (full=1) reads on static buffers
(that is user-mapped, persistent or remote) because !read check assumes
unread pages must be swapped. However for those buffers we have no other
choice than memcpy the data.
For the memcpy case, only return an error when the writer is still on
the reader page for the splice interface to wait.
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260901155445.1475405-2-vdonnefort@google.com
Fixes: 117c39200d9d ("ring-buffer: Introducing ring-buffer mapping functions")
Signed-off-by: Vincent Donnefort <vdonnefort@google.com>
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/trace/ring_buffer.c | 11 ++---------
1 file changed, 2 insertions(+), 9 deletions(-)
--- a/kernel/trace/ring_buffer.c
+++ b/kernel/trace/ring_buffer.c
@@ -6739,15 +6739,8 @@ int ring_buffer_read_page(struct trace_b
unsigned int event_size;
unsigned int flags = 0;
- /*
- * If a full page is expected, this can still be returned
- * if there's been a previous partial read and the
- * rest of the page can be read and the commit page is off
- * the reader page.
- */
- if (full &&
- (!read || (len < (size - read)) ||
- cpu_buffer->reader_page == cpu_buffer->commit_page))
+ /* If a full page is requested, it cannot be the commit page */
+ if (full && cpu_buffer->reader_page == cpu_buffer->commit_page)
return -1;
if (len > (size - read))
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0043/1518] staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (41 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0042/1518] ring-buffer: Allow splice reads on static buffers Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0044/1518] tracing/probes: Fix BTF kflag check for anonymous struct member access Greg Kroah-Hartman
` (955 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Muhammad Bilal, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Muhammad Bilal <meatuni001@gmail.com>
[ Upstream commit 28a289beaf226b30b1e6e7d7b1a2946fe2d6e852 ]
rtw_restruct_wmm_ie() scans in_ie for a WMM IE with:
while (i < in_len) {
...
if (i + 5 < in_len && in_ie[i] == 0xDD && ...) {
...
break;
}
i += (in_ie[i + 1] + 2); /* to the next IE element */
}
When the "i + 5 < in_len" match check fails simply because i is
within 5 bytes of the end of the buffer (i.e. no WMM IE was found
near the tail of in_ie), execution falls through to
"i += (in_ie[i + 1] + 2)", which reads in_ie[i + 1]. If i == in_len
- 1 at that point, this is a 1-byte out-of-bounds read of an
attacker-influenced IE buffer built from association/scan data.
Commit a75281626fc8f ("staging: rtl8723bs: fix potential
out-of-bounds read in rtw_restruct_wmm_ie") added the "i + 5 <
in_len" guard to the match condition itself, but did not add an
equivalent guard before the fallthrough advance, so the same class
of OOB read remained reachable through the non-matching path.
Add an explicit bounds check before advancing to the next IE.
Fixes: 554c0a3abf216 ("staging: Add rtl8723bs sdio wifi driver")
Cc: stable@vger.kernel.org
Signed-off-by: Muhammad Bilal <meatuni001@gmail.com>
Link: https://patch.msgid.link/20260728125456.32359-4-meatuni001@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/staging/rtl8723bs/core/rtw_mlme.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/staging/rtl8723bs/core/rtw_mlme.c
+++ b/drivers/staging/rtl8723bs/core/rtw_mlme.c
@@ -2029,6 +2029,9 @@ int rtw_restruct_wmm_ie(struct adapter *
break;
}
+ if (i + 1 >= in_len)
+ break;
+
i += (in_ie[i + 1] + 2); /* to the next IE element */
}
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0044/1518] tracing/probes: Fix BTF kflag check for anonymous struct member access
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (42 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0043/1518] staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie() Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0045/1518] udf: Fix data loss when converting inline inodes to out of line Greg Kroah-Hartman
` (954 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Masami Hiramatsu (Google),
Steven Rostedt, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: "Masami Hiramatsu (Google)" <mhiramat@kernel.org>
[ Upstream commit 47e93045a2db80d24f5fef65adecc6b2b32efa23 ]
btf_find_struct_member() traverses into nested anonymous structures and
unions to find a struct member. However, get_bitoffset_of_field() in
trace_probe.c checked btf_type_kflag(type) using the outer parent type
instead of the actual anonymous structure/union that directly contains
the found member.
If the parent structure and anonymous structure have mismatched kflags
(e.g., the parent has kflag=0 while the anonymous structure has kflag=1
because it contains bitfields), the bitfield size encoded in the upper
8 bits of member->offset is erroneously treated as part of the byte/bit
offset, corrupting the resolved offset and failing to set last_bitsize.
Similarly, btf_find_struct_member() pushed anonymous member offsets
onto anon_stack without masking BTF_MEMBER_BIT_OFFSET() when kflag is set.
To fix this problem, update btf_find_struct_member() to return actual
containing structure/union type via member_type, use appropriate
__btf_member_bit_offset() to get bit offset, and use member_type for
btf_type_kflag() in get_bitoffset_of_field().
Link: https://lore.kernel.org/all/178827250904.123716.17452648791331881284.stgit@devnote2/
Fixes: c440adfbe302 ("tracing/probes: Support BTF based data structure field access")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/all/20260822095110.0772E1F000E9@smtp.kernel.org/
Assisted-by: Antigravity:gemini-3.7-flash
Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Reviewed-by: Steven Rostedt <rostedt@goodmis.org>
[ applied changes to parse_btf_field() because get_bitoffset_of_field() is absent. ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/trace/trace_btf.c | 19 +++++++++++--------
kernel/trace/trace_btf.h | 3 ++-
kernel/trace/trace_probe.c | 5 +++--
3 files changed, 16 insertions(+), 11 deletions(-)
--- a/kernel/trace/trace_btf.c
+++ b/kernel/trace/trace_btf.c
@@ -61,16 +61,17 @@ struct btf_anon_stack {
/*
* Find a member of data structure/union by name and return it.
- * Return NULL if not found, or -EINVAL if parameter is invalid.
- * If the member is an member of anonymous union/structure, the offset
- * of that anonymous union/structure is stored into @anon_offset. Caller
- * can calculate the correct offset from the root data structure by
- * adding anon_offset to the member's offset.
+ * Return NULL if not found, or ERR_PTR(-EINVAL) if parameter is invalid.
+ * If the member is a member of an anonymous union/structure, the bit offset
+ * of that anonymous union/structure is stored into @anon_offset.
+ * If @member_type is non-NULL, the actual containing structure/union type
+ * of the found member is stored into @member_type.
*/
const struct btf_member *btf_find_struct_member(struct btf *btf,
const struct btf_type *type,
const char *member_name,
- u32 *anon_offset)
+ u32 *anon_offset,
+ const struct btf_type **member_type)
{
struct btf_anon_stack *anon_stack;
const struct btf_member *member;
@@ -94,14 +95,16 @@ retry:
if (btf_type_skip_modifiers(btf, member->type, &tid) &&
top < BTF_ANON_STACK_MAX) {
anon_stack[top].tid = tid;
- anon_stack[top++].offset =
- cur_offset + member->offset;
+ anon_stack[top++].offset = cur_offset +
+ __btf_member_bit_offset(type, member);
}
} else {
name = btf_name_by_offset(btf, member->name_off);
if (name && !strcmp(member_name, name)) {
if (anon_offset)
*anon_offset = cur_offset;
+ if (member_type)
+ *member_type = type;
goto out;
}
}
--- a/kernel/trace/trace_btf.h
+++ b/kernel/trace/trace_btf.h
@@ -8,4 +8,5 @@ const struct btf_param *btf_get_func_par
const struct btf_member *btf_find_struct_member(struct btf *btf,
const struct btf_type *type,
const char *member_name,
- u32 *anon_offset);
+ u32 *anon_offset,
+ const struct btf_type **member_type);
--- a/kernel/trace/trace_probe.c
+++ b/kernel/trace/trace_probe.c
@@ -577,6 +577,7 @@ static int parse_btf_field(char *fieldna
{
struct fetch_insn *code = *pcode;
const struct btf_member *field;
+ const struct btf_type *mtype;
u32 bitoffs, anon_offs;
bool is_struct = ctx->struct_btf != NULL;
struct btf *btf = ctx_btf(ctx);
@@ -611,7 +612,7 @@ static int parse_btf_field(char *fieldna
anon_offs = 0;
field = btf_find_struct_member(btf, type, fieldname,
- &anon_offs);
+ &anon_offs, &mtype);
if (IS_ERR(field)) {
trace_probe_log_err(ctx->offset, BAD_BTF_TID);
return PTR_ERR(field);
@@ -624,7 +625,7 @@ static int parse_btf_field(char *fieldna
bitoffs += anon_offs;
/* Accumulate the bit-offsets of the dot-connected fields */
- if (btf_type_kflag(type)) {
+ if (btf_type_kflag(mtype)) {
bitoffs += BTF_MEMBER_BIT_OFFSET(field->offset);
ctx->last_bitsize = BTF_MEMBER_BITFIELD_SIZE(field->offset);
} else {
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0045/1518] udf: Fix data loss when converting inline inodes to out of line
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (43 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0044/1518] tracing/probes: Fix BTF kflag check for anonymous struct member access Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0046/1518] futex: Optimize futex hash bucket access patterns Greg Kroah-Hartman
` (953 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jan Kara, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jan Kara <jack@suse.cz>
[ Upstream commit 62333e480d12ab186f89fe2725b372d12f72d5eb ]
When udf_expand_file_adinicb() converts file from inline format to out
of line, we use filemap_fdatawrite() to writeout the data to the new
blocks. However since 36580ed08776 ("udf: Do not allocate blocks on page
writeback") the writeback actually doesn't allocate the new block and
the folio dirty bit is just silently cleared. Thus unless the file is
written to after the conversion (as it can easily happen in case of
truncate up), the data is just lost. Fix the problem by explicitely
allocating the block underlying the data before starting writeback.
Fixes: 36580ed08776 ("udf: Do not allocate blocks on page writeback")
CC: stable@vger.kernel.org
Link: https://patch.msgid.link/20260730104232.4086759-4-jack@suse.cz
Signed-off-by: Jan Kara <jack@suse.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
fs/udf/inode.c | 15 +++++++++++++--
1 file changed, 13 insertions(+), 2 deletions(-)
--- a/fs/udf/inode.c
+++ b/fs/udf/inode.c
@@ -406,6 +406,10 @@ int udf_expand_file_adinicb(struct inode
{
struct folio *folio;
struct udf_inode_info *iinfo = UDF_I(inode);
+ struct udf_map_rq map = {
+ .lblk = 0,
+ .iflags = UDF_MAP_CREATE,
+ };
int err;
WARN_ON_ONCE(!inode_is_locked(inode));
@@ -435,20 +439,27 @@ int udf_expand_file_adinicb(struct inode
iinfo->i_alloc_type = ICBTAG_FLAG_AD_SHORT;
else
iinfo->i_alloc_type = ICBTAG_FLAG_AD_LONG;
+ up_write(&iinfo->i_data_sem);
+
+ /* Allocate the block underlying the data */
+ err = udf_map_block(inode, &map);
+ if (err < 0)
+ goto restore;
+
folio_mark_dirty(folio);
folio_unlock(folio);
- up_write(&iinfo->i_data_sem);
err = filemap_fdatawrite(inode->i_mapping);
if (err) {
/* Restore everything back so that we don't lose data... */
folio_lock(folio);
+restore:
down_write(&iinfo->i_data_sem);
memcpy_from_folio(iinfo->i_data + iinfo->i_lenEAttr,
folio, 0, inode->i_size);
- folio_unlock(folio);
iinfo->i_alloc_type = ICBTAG_FLAG_AD_IN_ICB;
iinfo->i_lenAlloc = inode->i_size;
up_write(&iinfo->i_data_sem);
+ folio_unlock(folio);
}
folio_put(folio);
mark_inode_dirty(inode);
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0046/1518] futex: Optimize futex hash bucket access patterns
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (44 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0045/1518] udf: Fix data loss when converting inline inodes to out of line Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0047/1518] i2c: qcom-cci: Remove overcautious disable_irq() calls Greg Kroah-Hartman
` (952 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Breno Leitao, Peter Zijlstra (Intel),
Thomas Gleixner, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Peter Zijlstra <peterz@infradead.org>
[ Upstream commit a734d9fca84e1d4fa0cb442ef5f84c88f8212d32 ]
Breno reported significant c2c HITM in a futex hash heavy workload.
It turns out that the hash bucket to private hash table reverse pointer
(futex_hash_bucket::priv) was to blame. Notably when the hash buckets are
heavily contended, the: 'fph = bh->priv;' load in futex_hash() will typically
miss and consequently become quite expensive.
Since this load in particular is quite superfluous, removing it is fairly
straight forward. However, removing it does not in fact achieve anything much.
The pain moves to the next user, notably: futex_hash_put().
Therefore rework the whole private hash refcounting to avoid needing this back
pointer (and removing it). Instead of passing around 'struct futex_hash_bucket
*hb', pass around a new structure that contains it and the related 'struct
futex_private_hash *fph' pointer in tandem.
Funnily this turns out to remove more code than it adds and significantly
improves futex hash performance (as measured by 'perf bench futex hash'):
SKL dual socket 112 threads:
Baseline Patched
shared (16k) 1571857 1641435 + 4.4%
autosize (512) 646390 903371 +39.7%
-b 256 464395 587014 +26.4%
-b 512 715687 995943 +39.2%
-b 1024 995085 1396328 +40.3%
-b 2048 1293114 1668395 +29.0%
-b 4096 2124438 2240228 + 5.5%
Zen3 dual socket 256 threads:
Baseline Patched
shared (16k) 1275840 1381279 + 8.2%
autosize (512) 1252745 1482179 +18.3%
-b 256 856274 955455 +11.5%
-b 512 1267490 1544010 +21.8%
-b 1024 1424013 1625424 +14.1%
-b 2048 1505181 1669342 +10.9%
-b 4096 1465993 1688932 +15.2%
AMD EPYC 9D64 (Zen4, single socket) 176 threads:
Baseline Patched Delta
shared (16k) 1,230,599 1,368,655 +11.2%
autosize (1024) 1,285,440 1,556,946 +21.1%
-b 256 1,341,471 1,520,303 +13.3%
-b 512 1,438,330 1,599,319 +11.2%
-b 1024 1,443,772 1,622,493 +12.4%
-b 2048 1,472,108 1,643,975 +11.7%
-b 4096 1,333,098 1,570,897 +17.8%
Reported-by: Breno Leitao <leitao@debian.org>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Tested-by: Breno Leitao <leitao@debian.org>
Tested-by: Thomas Gleixner <tglx@kernel.org>
Link: https://patch.msgid.link/20260610135510.GB1430057@noisy.programming.kicks-ass.net
[ Stable adaptation: use mm->futex_phash in __futex_hash(), since this
branch does not contain the mm_struct futex field consolidation.
Preserve the final-put use-after-free fix by saving fph->mm before
futex_ref_put(), and restore the NULL guard needed by the direct
private-hash put callers. futex_key_is_private() is already in futex.h;
no new functions are introduced. Keep the bucket-reference conversion
so 912edebe8501 applies without changes. ]
Stable-dep-of: 912edebe8501 ("futex: Provide rt_mutex_.*_schedule() equivalents for futex scheduling")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/futex/core.c | 103 +++++++++++++++---------------------------------
kernel/futex/futex.h | 28 ++++++-------
kernel/futex/pi.c | 21 +++++----
kernel/futex/requeue.c | 20 ++++-----
kernel/futex/waitwake.c | 17 +++++--
5 files changed, 80 insertions(+), 109 deletions(-)
--- a/kernel/futex/core.c
+++ b/kernel/futex/core.c
@@ -125,7 +125,7 @@ late_initcall(fail_futex_debugfs);
#endif /* CONFIG_FAIL_FUTEX */
static struct futex_hash_bucket *
-__futex_hash(union futex_key *key, struct futex_private_hash *fph);
+__futex_hash(union futex_key *key, struct futex_private_hash *fph, struct futex_private_hash **fph_p);
#ifdef CONFIG_FUTEX_PRIVATE_HASH
static bool futex_ref_get(struct futex_private_hash *fph);
@@ -141,35 +141,14 @@ static bool futex_private_hash_get(struc
void futex_private_hash_put(struct futex_private_hash *fph)
{
- struct mm_struct *mm = fph->mm;
-
- if (futex_ref_put(fph))
- wake_up_var(mm);
-}
-
-/**
- * futex_hash_get - Get an additional reference for the local hash.
- * @hb: ptr to the private local hash.
- *
- * Obtain an additional reference for the already obtained hash bucket. The
- * caller must already own an reference.
- */
-void futex_hash_get(struct futex_hash_bucket *hb)
-{
- struct futex_private_hash *fph = hb->priv;
+ struct mm_struct *mm;
if (!fph)
return;
- WARN_ON_ONCE(!futex_private_hash_get(fph));
-}
-void futex_hash_put(struct futex_hash_bucket *hb)
-{
- struct futex_private_hash *fph = hb->priv;
-
- if (!fph)
- return;
- futex_private_hash_put(fph);
+ mm = fph->mm;
+ if (futex_ref_put(fph))
+ wake_up_var(mm);
}
static struct futex_hash_bucket *
@@ -177,14 +156,6 @@ __futex_hash_private(union futex_key *ke
{
u32 hash;
- if (!futex_key_is_private(key))
- return NULL;
-
- if (!fph)
- fph = rcu_dereference(key->private.mm->futex_phash);
- if (!fph || !fph->hash_mask)
- return NULL;
-
hash = jhash2((void *)&key->private.address,
sizeof(key->private.address) / 4,
key->both.offset);
@@ -205,13 +176,12 @@ static void futex_rehash_private(struct
spin_lock(&hb_old->lock);
plist_for_each_entry_safe(this, tmp, &hb_old->chain, list) {
-
plist_del(&this->list, &hb_old->chain);
futex_hb_waiters_dec(hb_old);
WARN_ON_ONCE(this->lock_ptr != &hb_old->lock);
- hb_new = __futex_hash(&this->key, new);
+ hb_new = __futex_hash(&this->key, new, NULL);
futex_hb_waiters_inc(hb_new);
/*
* The new pointer isn't published yet but an already
@@ -265,9 +235,8 @@ static void futex_pivot_hash(struct mm_s
}
}
-struct futex_private_hash *futex_private_hash(void)
+struct futex_private_hash *futex_private_hash(struct mm_struct *mm)
{
- struct mm_struct *mm = current->mm;
/*
* Ideally we don't loop. If there is a replacement in progress
* then a new private hash is already prepared and a reference can't be
@@ -293,18 +262,17 @@ again:
goto again;
}
-struct futex_hash_bucket *futex_hash(union futex_key *key)
+struct futex_bucket_ref futex_hash(union futex_key *key)
{
- struct futex_private_hash *fph;
- struct futex_hash_bucket *hb;
-
again:
scoped_guard(rcu) {
- hb = __futex_hash(key, NULL);
- fph = hb->priv;
+ struct futex_private_hash *fph = NULL;
+ struct futex_hash_bucket *hb;
+
+ hb = __futex_hash(key, NULL, &fph);
if (!fph || futex_private_hash_get(fph))
- return hb;
+ return (struct futex_bucket_ref){ .hb = hb, .fph = fph };
}
futex_pivot_hash(key->private.mm);
goto again;
@@ -312,15 +280,9 @@ again:
#else /* !CONFIG_FUTEX_PRIVATE_HASH */
-static struct futex_hash_bucket *
-__futex_hash_private(union futex_key *key, struct futex_private_hash *fph)
-{
- return NULL;
-}
-
-struct futex_hash_bucket *futex_hash(union futex_key *key)
+struct futex_bucket_ref futex_hash(union futex_key *key)
{
- return __futex_hash(key, NULL);
+ return (struct futex_bucket_ref){ .hb = __futex_hash(key, NULL, NULL), .fph = NULL };
}
#endif /* CONFIG_FUTEX_PRIVATE_HASH */
@@ -398,6 +360,8 @@ static int futex_mpol(struct mm_struct *
* __futex_hash - Return the hash bucket
* @key: Pointer to the futex key for which the hash is calculated
* @fph: Pointer to private hash if known
+ * @fph_p: Pointer to a private hash pointer; output for the private hash
+ * used when set.
*
* We hash on the keys returned from get_futex_key (see below) and return the
* corresponding hash bucket.
@@ -406,18 +370,22 @@ static int futex_mpol(struct mm_struct *
* global hash is returned.
*/
static struct futex_hash_bucket *
-__futex_hash(union futex_key *key, struct futex_private_hash *fph)
+__futex_hash(union futex_key *key, struct futex_private_hash *fph, struct futex_private_hash **fph_p)
{
int node = key->both.node;
u32 hash;
- if (node == FUTEX_NO_NODE) {
- struct futex_hash_bucket *hb;
-
- hb = __futex_hash_private(key, fph);
- if (hb)
- return hb;
+#ifdef CONFIG_FUTEX_PRIVATE_HASH
+ if (node == FUTEX_NO_NODE && futex_key_is_private(key)) {
+ if (!fph)
+ fph = rcu_dereference(key->private.mm->futex_phash);
+ if (fph && fph->hash_mask) {
+ if (fph_p)
+ *fph_p = fph;
+ return __futex_hash_private(key, fph);
+ }
}
+#endif
hash = jhash2((u32 *)key,
offsetof(typeof(*key), both.offset) / sizeof(u32),
@@ -1362,7 +1330,7 @@ static void exit_pi_state_list(struct ta
* on the mutex.
*/
WARN_ON(curr != current);
- guard(private_hash)();
+ guard(private_hash)(current->mm);
/*
* We are a ZOMBIE and nobody can enqueue itself on
* pi_state_list anymore, but we have to be careful
@@ -1374,7 +1342,8 @@ static void exit_pi_state_list(struct ta
pi_state = list_entry(next, struct futex_pi_state, list);
key = pi_state->key;
if (1) {
- CLASS(hb, hb)(&key);
+ CLASS(hbr, hbr)(&key);
+ auto hb = hbr.hb;
/*
* We can race against put_pi_state() removing itself from the
@@ -1556,12 +1525,8 @@ void futex_exec_done(struct task_struct
tsk->futex_state = FUTEX_STATE_OK;
}
-static void futex_hash_bucket_init(struct futex_hash_bucket *fhb,
- struct futex_private_hash *fph)
+static void futex_hash_bucket_init(struct futex_hash_bucket *fhb)
{
-#ifdef CONFIG_FUTEX_PRIVATE_HASH
- fhb->priv = fph;
-#endif
atomic_set(&fhb->waiters, 0);
plist_head_init(&fhb->chain);
spin_lock_init(&fhb->lock);
@@ -1866,7 +1831,7 @@ static int futex_hash_allocate(unsigned
fph->mm = mm;
for (i = 0; i < hash_slots; i++)
- futex_hash_bucket_init(&fph->queues[i], fph);
+ futex_hash_bucket_init(&fph->queues[i]);
if (custom) {
struct wait_bit_queue_entry __wbq_entry;
@@ -2069,7 +2034,7 @@ static int __init futex_init(void)
BUG_ON(!table);
for (i = 0; i < hashsize; i++)
- futex_hash_bucket_init(&table[i], NULL);
+ futex_hash_bucket_init(&table[i]);
futex_queues[n] = table;
}
--- a/kernel/futex/futex.h
+++ b/kernel/futex/futex.h
@@ -144,7 +144,6 @@ struct futex_hash_bucket {
atomic_t waiters;
spinlock_t lock;
struct plist_head chain;
- struct futex_private_hash *priv;
} ____cacheline_aligned_in_smp;
/*
@@ -184,7 +183,7 @@ typedef void (futex_wake_fn)(struct wake
* @requeue_pi_key: the requeue_pi target futex key
* @bitset: bitset for the optional bitmasked wakeup
* @requeue_state: State field for futex_requeue_pi()
- * @drop_hb_ref: Waiter should drop the extra hash bucket reference if true
+ * @drop_fph: Waiter should drop the extra private hash reference when set
* @requeue_wait: RCU wait for futex_requeue_pi() (RT only)
*
* We use this hashed waitqueue, instead of a normal wait_queue_entry_t, so
@@ -211,7 +210,7 @@ struct futex_q {
union futex_key *requeue_pi_key;
u32 bitset;
atomic_t requeue_state;
- bool drop_hb_ref;
+ struct futex_private_hash *drop_fph;
#ifdef CONFIG_PREEMPT_RT
struct rcuwait requeue_wait;
#endif
@@ -231,28 +230,29 @@ extern struct hrtimer_sleeper *
futex_setup_timer(ktime_t *time, struct hrtimer_sleeper *timeout,
int flags, u64 range_ns);
-extern struct futex_hash_bucket *futex_hash(union futex_key *key);
-#ifdef CONFIG_FUTEX_PRIVATE_HASH
-extern void futex_hash_get(struct futex_hash_bucket *hb);
-extern void futex_hash_put(struct futex_hash_bucket *hb);
+struct futex_bucket_ref {
+ struct futex_hash_bucket *hb;
+ struct futex_private_hash *fph;
+};
-extern struct futex_private_hash *futex_private_hash(void);
+#ifdef CONFIG_FUTEX_PRIVATE_HASH
+extern struct futex_private_hash *futex_private_hash(struct mm_struct *mm);
extern void futex_private_hash_put(struct futex_private_hash *fph);
#else /* !CONFIG_FUTEX_PRIVATE_HASH */
-static inline void futex_hash_get(struct futex_hash_bucket *hb) { }
-static inline void futex_hash_put(struct futex_hash_bucket *hb) { }
-static inline struct futex_private_hash *futex_private_hash(void) { return NULL; }
+static inline struct futex_private_hash *futex_private_hash(struct mm_struct *mm) { return NULL; }
static inline void futex_private_hash_put(struct futex_private_hash *fph) { }
#endif
-DEFINE_CLASS(hb, struct futex_hash_bucket *,
- if (_T) futex_hash_put(_T),
+extern struct futex_bucket_ref futex_hash(union futex_key *key);
+
+DEFINE_CLASS(hbr, struct futex_bucket_ref,
+ if (_T.fph) futex_private_hash_put(_T.fph),
futex_hash(key), union futex_key *key);
DEFINE_CLASS(private_hash, struct futex_private_hash *,
if (_T) futex_private_hash_put(_T),
- futex_private_hash(), void);
+ futex_private_hash(mm), struct mm_struct *mm);
/**
* futex_match - Check whether two futex keys are equal
--- a/kernel/futex/pi.c
+++ b/kernel/futex/pi.c
@@ -1005,7 +1005,8 @@ retry:
retry_private:
if (1) {
- CLASS(hb, hb)(&q.key);
+ CLASS(hbr, hbr)(&q.key);
+ auto hb = hbr.hb;
futex_q_lock(&q, hb);
@@ -1068,7 +1069,7 @@ retry_private:
* the thread, performing resize, will block on hb->lock during
* the requeue.
*/
- futex_hash_put(no_free_ptr(hb));
+ futex_private_hash_put(no_free_ptr(hbr.fph));
/*
* Must be done before we enqueue the waiter, here is unfortunately
* under the hb lock, but that *should* work because it does nothing.
@@ -1158,11 +1159,9 @@ no_block:
futex_unqueue_pi(&q);
spin_unlock(q.lock_ptr);
- if (q.drop_hb_ref) {
- CLASS(hb, hb)(&q.key);
- /* Additional reference from futex_unlock_pi() */
- futex_hash_put(hb);
- }
+
+ /* Additional reference from futex_unlock_pi() */
+ futex_private_hash_put(q.drop_fph);
goto out;
out_unlock_put_key:
@@ -1218,7 +1217,8 @@ retry:
if (ret)
return ret;
- CLASS(hb, hb)(&key);
+ CLASS(hbr, hbr)(&key);
+ auto hb = hbr.hb;
spin_lock(&hb->lock);
retry_hb:
@@ -1275,8 +1275,9 @@ retry_hb:
* Acquire a reference for the leaving waiter to ensure
* valid futex_q::lock_ptr.
*/
- futex_hash_get(hb);
- top_waiter->drop_hb_ref = true;
+ if (futex_key_is_private(&key))
+ top_waiter->drop_fph = futex_private_hash(key.private.mm);
+
__futex_unqueue(top_waiter);
raw_spin_unlock_irq(&pi_state->pi_mutex.wait_lock);
goto retry_hb;
--- a/kernel/futex/requeue.c
+++ b/kernel/futex/requeue.c
@@ -249,8 +249,8 @@ void requeue_pi_wake_futex(struct futex_
* Acquire a reference for the waiter to ensure valid
* futex_q::lock_ptr.
*/
- futex_hash_get(hb);
- q->drop_hb_ref = true;
+ if (futex_key_is_private(key))
+ q->drop_fph = futex_private_hash(key->private.mm);
q->lock_ptr = &hb->lock;
task = READ_ONCE(q->task);
@@ -467,8 +467,10 @@ retry:
retry_private:
if (1) {
- CLASS(hb, hb1)(&key1);
- CLASS(hb, hb2)(&key2);
+ CLASS(hbr, hbr1)(&key1);
+ CLASS(hbr, hbr2)(&key2);
+ auto hb1 = hbr1.hb;
+ auto hb2 = hbr2.hb;
futex_hb_waiters_inc(hb2);
double_lock_hb(hb1, hb2);
@@ -840,7 +842,8 @@ int futex_wait_requeue_pi(u32 __user *ua
switch (futex_requeue_pi_wakeup_sync(&q)) {
case Q_REQUEUE_PI_IGNORE:
{
- CLASS(hb, hb)(&q.key);
+ CLASS(hbr, hbr)(&q.key);
+ auto hb = hbr.hb;
/* The waiter is still on uaddr1 */
spin_lock(&hb->lock);
ret = handle_early_requeue_pi_wakeup(hb, &q, to);
@@ -910,11 +913,8 @@ int futex_wait_requeue_pi(u32 __user *ua
default:
BUG();
}
- if (q.drop_hb_ref) {
- CLASS(hb, hb)(&q.key);
- /* Additional reference from requeue_pi_wake_futex() */
- futex_hash_put(hb);
- }
+ /* Additional reference from requeue_pi_wake_futex() */
+ futex_private_hash_put(q.drop_fph);
out:
if (to) {
--- a/kernel/futex/waitwake.c
+++ b/kernel/futex/waitwake.c
@@ -169,7 +169,8 @@ int futex_wake(u32 __user *uaddr, unsign
if ((flags & FLAGS_STRICT) && !nr_wake)
return 0;
- CLASS(hb, hb)(&key);
+ CLASS(hbr, hbr)(&key);
+ auto hb = hbr.hb;
/* Make sure we really have tasks to wakeup */
if (!futex_hb_waiters_pending(hb))
@@ -266,8 +267,10 @@ retry:
retry_private:
if (1) {
- CLASS(hb, hb1)(&key1);
- CLASS(hb, hb2)(&key2);
+ CLASS(hbr, hbr1)(&key1);
+ CLASS(hbr, hbr2)(&key2);
+ auto hb1 = hbr1.hb;
+ auto hb2 = hbr2.hb;
double_lock_hb(hb1, hb2);
op_ret = futex_atomic_op_inuser(op, uaddr2);
@@ -409,7 +412,7 @@ int futex_wait_multiple_setup(struct fut
* Make sure to have a reference on the private_hash such that we
* don't block on rehash after changing the task state below.
*/
- guard(private_hash)();
+ guard(private_hash)(current->mm);
/*
* Enqueuing multiple futexes is tricky, because we need to enqueue
@@ -446,7 +449,8 @@ retry:
u32 val = vs[i].w.val;
if (1) {
- CLASS(hb, hb)(&q->key);
+ CLASS(hbr, hbr)(&q->key);
+ auto hb = hbr.hb;
futex_q_lock(q, hb);
ret = futex_get_value_locked(&uval, uaddr);
@@ -620,7 +624,8 @@ retry:
retry_private:
if (1) {
- CLASS(hb, hb)(&q->key);
+ CLASS(hbr, hbr)(&q->key);
+ auto hb = hbr.hb;
futex_q_lock(q, hb);
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0047/1518] i2c: qcom-cci: Remove overcautious disable_irq() calls
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (45 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0046/1518] futex: Optimize futex hash bucket access patterns Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0048/1518] tracing: Make printk_trace global for tracing system Greg Kroah-Hartman
` (951 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vladimir Zapolskiy, Loic Poulain,
Konrad Dybcio, Andi Shyti, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vladimir Zapolskiy <vladimir.zapolskiy@linaro.org>
[ Upstream commit f0285c286bca5a1e018ba25040cef6c7806c31ef ]
In cci_probe() the controller's interrupt is requested using a devres
managed API, and in cci_probe() error path and cci_remove() it'd be
safe to rely on devres mechanism to free and shutdown the interrupt,
thus explicit disable_irq() calls can be removed as unnecessary ones.
Signed-off-by: Vladimir Zapolskiy <vladimir.zapolskiy@linaro.org>
Reviewed-by: Loic Poulain <loic.poulain@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://lore.kernel.org/r/20260515234121.1607425-5-vladimir.zapolskiy@linaro.org
Stable-dep-of: f98d49864821 ("i2c: qcom-cci: fix autosuspend cleanup")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-qcom-cci.c | 5 +----
1 file changed, 1 insertion(+), 4 deletions(-)
--- a/drivers/i2c/busses/i2c-qcom-cci.c
+++ b/drivers/i2c/busses/i2c-qcom-cci.c
@@ -594,7 +594,7 @@ static int cci_probe(struct platform_dev
ret = cci_reset(cci);
if (ret < 0)
- goto error;
+ goto disable_clocks;
cci_init(cci);
@@ -626,8 +626,6 @@ error_i2c:
of_node_put(cci->master[i].adap.dev.of_node);
}
}
-error:
- disable_irq(cci->irq);
disable_clocks:
cci_disable_clocks(cci);
@@ -647,7 +645,6 @@ static void cci_remove(struct platform_d
}
}
- disable_irq(cci->irq);
pm_runtime_disable(&pdev->dev);
pm_runtime_set_suspended(&pdev->dev);
}
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0048/1518] tracing: Make printk_trace global for tracing system
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (46 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0047/1518] i2c: qcom-cci: Remove overcautious disable_irq() calls Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0049/1518] io_uring/waitid: have io_waitid_complete() remove wait queue entry Greg Kroah-Hartman
` (950 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Masami Hiramatsu, Mark Rutland,
Mathieu Desnoyers, Andrew Morton, Steven Rostedt (Google),
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Steven Rostedt <rostedt@goodmis.org>
[ Upstream commit 1c53d781d42541adc5ba76b4f843a3ff382e01fb ]
The printk_trace is used to determine which trace_array trace_printk()
writes to. By making it a global variable among the tracing subsystem it
will allow the trace_printk functions to be moved out of trace.c and still
have direct access to that variable.
Cc: Masami Hiramatsu <mhiramat@kernel.org>
Cc: Mark Rutland <mark.rutland@arm.com>
Cc: Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
Cc: Andrew Morton <akpm@linux-foundation.org>
Link: https://patch.msgid.link/20260208032450.144525891@kernel.org
Signed-off-by: Steven Rostedt (Google) <rostedt@goodmis.org>
Stable-dep-of: f2951ebd15c3 ("tracing: Take trace_array reference when opening options file")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/trace/trace.c | 2 +-
kernel/trace/trace.h | 2 ++
2 files changed, 3 insertions(+), 1 deletion(-)
--- a/kernel/trace/trace.c
+++ b/kernel/trace/trace.c
@@ -537,7 +537,7 @@ static struct trace_array global_trace =
.trace_flags = TRACE_DEFAULT_FLAGS,
};
-static struct trace_array *printk_trace = &global_trace;
+struct trace_array *printk_trace = &global_trace;
/* List of trace_arrays interested in the top level trace_marker */
static LIST_HEAD(marker_copies);
--- a/kernel/trace/trace.h
+++ b/kernel/trace/trace.h
@@ -479,6 +479,8 @@ extern bool trace_clock_in_ns(struct tra
extern unsigned long trace_adjust_address(struct trace_array *tr, unsigned long addr);
+extern struct trace_array *printk_trace;
+
/*
* The global tracer (top) should be the first trace array added,
* but we check the flag anyway.
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0049/1518] io_uring/waitid: have io_waitid_complete() remove wait queue entry
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (47 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0048/1518] tracing: Make printk_trace global for tracing system Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0050/1518] nvdimm: pmem: keep PREFLUSH before data writes Greg Kroah-Hartman
` (949 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jens Axboe, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jens Axboe <axboe@kernel.dk>
[ Upstream commit a48c0cbf28c03f6c590a14ceb31bf6e619c2f6da ]
Both callers of this need the entry potentially removed, so shift the
removal into the completion side and kill it from the two callers.
While at it, add a helper for removing the wait_queue_entry based
on the passed in io_kiocb.
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Stable-dep-of: 14572de82e50 ("io_uring/waitid: honor task_work cancellation")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
io_uring/waitid.c | 26 ++++++++++++++++++++------
1 file changed, 20 insertions(+), 6 deletions(-)
--- a/io_uring/waitid.c
+++ b/io_uring/waitid.c
@@ -109,6 +109,22 @@ static int io_waitid_finish(struct io_ki
return ret;
}
+static void io_waitid_remove_wq(struct io_kiocb *req)
+{
+ struct io_waitid *iw = io_kiocb_to_cmd(req, struct io_waitid);
+ struct wait_queue_head *head;
+
+ head = READ_ONCE(iw->head);
+ if (head) {
+ struct io_waitid_async *iwa = req->async_data;
+
+ iw->head = NULL;
+ spin_lock_irq(&head->lock);
+ list_del_init(&iwa->wo.child_wait.entry);
+ spin_unlock_irq(&head->lock);
+ }
+}
+
static void io_waitid_complete(struct io_kiocb *req, int ret)
{
struct io_waitid *iw = io_kiocb_to_cmd(req, struct io_waitid);
@@ -119,6 +135,7 @@ static void io_waitid_complete(struct io
lockdep_assert_held(&req->ctx->uring_lock);
hlist_del_init(&req->hash_node);
+ io_waitid_remove_wq(req);
ret = io_waitid_finish(req, ret);
if (ret < 0)
@@ -129,7 +146,8 @@ static void io_waitid_complete(struct io
static bool __io_waitid_cancel(struct io_kiocb *req)
{
struct io_waitid *iw = io_kiocb_to_cmd(req, struct io_waitid);
- struct io_waitid_async *iwa = req->async_data;
+
+ lockdep_assert_held(&req->ctx->uring_lock);
/*
* Mark us canceled regardless of ownership. This will prevent a
@@ -141,9 +159,6 @@ static bool __io_waitid_cancel(struct io
if (atomic_fetch_inc(&iw->refs) & IO_WAITID_REF_MASK)
return false;
- spin_lock_irq(&iw->head->lock);
- list_del_init(&iwa->wo.child_wait.entry);
- spin_unlock_irq(&iw->head->lock);
io_waitid_complete(req, -ECANCELED);
io_req_queue_tw_complete(req, -ECANCELED);
return true;
@@ -209,8 +224,7 @@ static void io_waitid_cb(struct io_kiocb
io_waitid_drop_issue_ref(req);
return;
}
-
- remove_wait_queue(iw->head, &iwa->wo.child_wait);
+ /* fall through to complete, will kill waitqueue */
}
}
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0050/1518] nvdimm: pmem: keep PREFLUSH before data writes
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (48 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0049/1518] io_uring/waitid: have io_waitid_complete() remove wait queue entry Greg Kroah-Hartman
@ 2026-09-12 6:36 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0051/1518] futex: Provide rt_mutex_.*_schedule() equivalents for futex scheduling Greg Kroah-Hartman
` (948 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:36 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Li Chen, Michael S. Tsirkin,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Li Chen <me@linux.beauty>
[ Upstream commit c644a2f8fef5618fcf453c591177700fd07dd024 ]
pmem_submit_bio() records a REQ_PREFLUSH error, but continues to copy the
bio data and can later overwrite the error with a successful REQ_FUA flush.
That lets data writes run after a failed preflush and can complete the bio
successfully despite the failed ordering barrier.
Run the REQ_PREFLUSH flush synchronously before touching the bio data and
complete the bio with the flush error if it fails. Keep asynchronous flush
chaining for REQ_FUA. At that point, data copy has completed and the parent
bio can wait for the chained flush bio.
Signed-off-by: Li Chen <me@linux.beauty>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260630092338.2094628-3-me@linux.beauty>
Stable-dep-of: e57140944b5a ("nvdimm: virtio_pmem: refcount requests for token lifetime")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/nvdimm/pmem.c | 12 +++++++++---
1 file changed, 9 insertions(+), 3 deletions(-)
--- a/drivers/nvdimm/pmem.c
+++ b/drivers/nvdimm/pmem.c
@@ -208,8 +208,14 @@ static void pmem_submit_bio(struct bio *
struct pmem_device *pmem = bio->bi_bdev->bd_disk->private_data;
struct nd_region *nd_region = to_region(pmem);
- if (bio->bi_opf & REQ_PREFLUSH)
- ret = nvdimm_flush(nd_region, bio);
+ if (bio->bi_opf & REQ_PREFLUSH) {
+ ret = nvdimm_flush(nd_region, NULL);
+ if (ret) {
+ bio->bi_status = errno_to_blk_status(ret);
+ bio_endio(bio);
+ return;
+ }
+ }
do_acct = blk_queue_io_stat(bio->bi_bdev->bd_disk->queue);
if (do_acct)
@@ -229,7 +235,7 @@ static void pmem_submit_bio(struct bio *
if (do_acct)
bio_end_io_acct(bio, start);
- if (bio->bi_opf & REQ_FUA)
+ if ((bio->bi_opf & REQ_FUA) && !bio->bi_status)
ret = nvdimm_flush(nd_region, bio);
if (ret)
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0051/1518] futex: Provide rt_mutex_.*_schedule() equivalents for futex scheduling
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (49 preceding siblings ...)
2026-09-12 6:36 ` [PATCH 6.18 0050/1518] nvdimm: pmem: keep PREFLUSH before data writes Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0052/1518] i2c: qcom-cci: fix autosuspend cleanup Greg Kroah-Hartman
` (947 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yao Kai, Sebastian Andrzej Siewior,
Thomas Gleixner, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
[ Upstream commit 912edebe8501a36c6bedcef03bd238ab90a7e060 ]
There is rt_mutex_{pre|post}_schedule() around
rt_mutex_wait_proxy_lock() to ensure that sched_submit_work()/
sched_update_worker() is invoked before we schedule out and block on
rt_mutex while waiting for it become available.
The reason is that blocking on rt_mutex assigns a pi_waiter for the PI
chain and sched_submit_work() will also assign a pi_waiter if it blocks
on lock but a this point we already have a waiter assigned.
We can't skip sched_submit_work() entirely because I/O relies on the
fact that I/O queue is flushed while it blocks on a sleeping lock.
Therefore sched_submit_work() is moved before we block on the lock.
Sleeping lock in this context means mutex or rw_semaphore not spinlock_t
on PREEMPT_RT. Because the mutex abstraction on PREEMPT_RT uses the same
abstraction as the futex proxy lock, the futex code ended up using
rt_mutex_{pre|post}_schedule(), too.
Using it is/ was just to keep the task_struct::sched_rt_mutex assertion
happy. Futex proxy lock is used only in the syscall context of a task.
At this point it never got any I/O that needs to be flushed and it can't
be a workqueue that needs to notify that it will be scheduled out.
Therefore sched_submit_work() does nothing here.
By mistake futex_wait_requeue_pi() -> rt_mutex_wait_proxy_lock() did not
get the rt_mutex_{pre|post}_schedule() annotation. This was not noticed
because in this callchain the lock is (usually) not contended and so
rt_mutex_slowlock_block() does not schedule, triggering the assert.
Adding rt_mutex_pre_schedule() here looks wrong (as noted by PeterZ)
because at this point there is a pi_waiter recorded and invoking
sched_submit_work() with a possible lock contention would be wrong.
Add rt_mutex_futex_{pre|post}_schedule() which toggles the
sched_rt_mutex assert and does not involve sched_submit_work(). Add
asserts here to ensure that sched_submit_work() would do nothing. Use it
only in futex proxy lock case which is rt_mutex_wait_proxy_lock().
Remove it from futex_lock_pi().
Fixes: d14f9e930b90 ("locking/rtmutex: Use rt_mutex specific scheduler helpers")
Reported-by: Yao Kai <yaokai34@huawei.com>
Signed-off-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260901135453.3121948-2-bigeasy@linutronix.de
Closes: https://lore.kernel.org/all/20260717084922.4153317-2-yaokai34@huawei.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
include/linux/sched/rt.h | 2 ++
kernel/futex/pi.c | 16 +++-------------
kernel/locking/rtmutex_api.c | 2 ++
kernel/sched/core.c | 16 ++++++++++++++++
4 files changed, 23 insertions(+), 13 deletions(-)
--- a/include/linux/sched/rt.h
+++ b/include/linux/sched/rt.h
@@ -52,8 +52,10 @@ static inline bool rt_or_dl_task_policy(
#ifdef CONFIG_RT_MUTEXES
extern void rt_mutex_pre_schedule(void);
+extern void rt_mutex_futex_pre_schedule(void);
extern void rt_mutex_schedule(void);
extern void rt_mutex_post_schedule(void);
+extern void rt_mutex_futex_post_schedule(void);
/*
* Must hold either p->pi_lock or task_rq(p)->lock.
--- a/kernel/futex/pi.c
+++ b/kernel/futex/pi.c
@@ -1064,17 +1064,11 @@ retry_private:
* Caution; releasing @hb in-scope. The hb->lock is still locked
* while the reference is dropped. The reference can not be dropped
* after the unlock because if a user initiated resize is in progress
- * then we might need to wake him. This can not be done after the
- * rt_mutex_pre_schedule() invocation. The hb will remain valid because
- * the thread, performing resize, will block on hb->lock during
- * the requeue.
+ * then we might need to wake him. The hb will remain valid
+ * because the thread, performing resize, will block on
+ * hb->lock during the requeue.
*/
futex_private_hash_put(no_free_ptr(hbr.fph));
- /*
- * Must be done before we enqueue the waiter, here is unfortunately
- * under the hb lock, but that *should* work because it does nothing.
- */
- rt_mutex_pre_schedule();
rt_mutex_init_waiter(&rt_waiter);
@@ -1140,10 +1134,6 @@ cleanup:
* the
*/
futex_q_lockptr_lock(&q);
- /*
- * Waiter is unqueued.
- */
- rt_mutex_post_schedule();
no_block:
/*
* Fixup the pi_state owner and possibly acquire the lock if we
--- a/kernel/locking/rtmutex_api.c
+++ b/kernel/locking/rtmutex_api.c
@@ -398,6 +398,7 @@ int __sched rt_mutex_wait_proxy_lock(str
{
int ret;
+ rt_mutex_futex_pre_schedule();
raw_spin_lock_irq(&lock->wait_lock);
/* sleep on the mutex */
set_current_state(TASK_INTERRUPTIBLE);
@@ -408,6 +409,7 @@ int __sched rt_mutex_wait_proxy_lock(str
*/
fixup_rt_mutex_waiters(lock, true);
raw_spin_unlock_irq(&lock->wait_lock);
+ rt_mutex_futex_post_schedule();
return ret;
}
--- a/kernel/sched/core.c
+++ b/kernel/sched/core.c
@@ -7333,6 +7333,17 @@ void rt_mutex_pre_schedule(void)
sched_submit_work(current);
}
+/*
+ * Used within the futex syscall context, skips sched_submit_work() because none
+ * its work will be done. Asserts ensure that it is indeed the case.
+ */
+void rt_mutex_futex_pre_schedule(void)
+{
+ lockdep_assert(!(current->flags & (PF_WQ_WORKER | PF_IO_WORKER)));
+ lockdep_assert(!current->plug);
+ lockdep_assert(!fetch_and_set(current->sched_rt_mutex, 1));
+}
+
void rt_mutex_schedule(void)
{
lockdep_assert(current->sched_rt_mutex);
@@ -7345,6 +7356,11 @@ void rt_mutex_post_schedule(void)
lockdep_assert(fetch_and_set(current->sched_rt_mutex, 0));
}
+void rt_mutex_futex_post_schedule(void)
+{
+ lockdep_assert(fetch_and_set(current->sched_rt_mutex, 0));
+}
+
/*
* rt_mutex_setprio - set the current priority of a task
* @p: task to boost
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0052/1518] i2c: qcom-cci: fix autosuspend cleanup
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (50 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0051/1518] futex: Provide rt_mutex_.*_schedule() equivalents for futex scheduling Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0053/1518] tracing: Take trace_array reference when opening options file Greg Kroah-Hartman
` (946 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Vladimir Zapolskiy,
Loic Poulain, Andi Shyti, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
[ Upstream commit f98d4986482151a835b521a734722fe8dc5ca37d ]
cci_probe() calls pm_runtime_use_autosuspend(), but the remove path
does not call the matching pm_runtime_dont_use_autosuspend() before
disabling runtime PM.
If the autosuspend delay is set to a negative value while autosuspend
is enabled, the runtime PM core increments usage_count to prevent
runtime suspend. Without undoing the autosuspend setting during
teardown, this reference is not dropped and usage_count remains
unbalanced.
Use devm_pm_runtime_set_active_enabled() to manage the runtime PM
state. Its managed cleanup disables autosuspend and runtime PM and
restores the suspended state on probe failure and driver removal.
Remove the now redundant manual runtime PM cleanup.
This issue was found by manual code inspection.
Fixes: e517526195de ("i2c: Add Qualcomm CCI I2C driver")
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Cc: <stable@vger.kernel.org> # v5.8+
Reviewed-by: Vladimir Zapolskiy <vladimir.zapolskiy@linaro.org>
Reviewed-by: Loic Poulain <loic.poulain@oss.qualcomm.com>
Signed-off-by: Andi Shyti <andi.shyti@kernel.org>
Link: https://patch.msgid.link/20260812094425.3515179-1-lgs201920130244@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i2c/busses/i2c-qcom-cci.c | 11 ++++-------
1 file changed, 4 insertions(+), 7 deletions(-)
--- a/drivers/i2c/busses/i2c-qcom-cci.c
+++ b/drivers/i2c/busses/i2c-qcom-cci.c
@@ -599,9 +599,11 @@ static int cci_probe(struct platform_dev
cci_init(cci);
pm_runtime_set_autosuspend_delay(dev, MSEC_PER_SEC);
+ ret = devm_pm_runtime_set_active_enabled(dev);
+ if (ret)
+ goto disable_clocks;
+
pm_runtime_use_autosuspend(dev);
- pm_runtime_set_active(dev);
- pm_runtime_enable(dev);
for (i = 0; i < cci->data->num_masters; i++) {
if (!cci->master[i].cci)
@@ -617,8 +619,6 @@ static int cci_probe(struct platform_dev
return 0;
error_i2c:
- pm_runtime_disable(dev);
- pm_runtime_dont_use_autosuspend(dev);
for (--i ; i >= 0; i--) {
if (cci->master[i].cci) {
@@ -644,9 +644,6 @@ static void cci_remove(struct platform_d
cci_halt(cci, i);
}
}
-
- pm_runtime_disable(&pdev->dev);
- pm_runtime_set_suspended(&pdev->dev);
}
static const struct cci_data cci_v1_data = {
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0053/1518] tracing: Take trace_array reference when opening options file
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (51 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0052/1518] i2c: qcom-cci: fix autosuspend cleanup Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0054/1518] io_uring: only call io_should_terminate_tw() once for ctx Greg Kroah-Hartman
` (945 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot, Steven Rostedt,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Steven Rostedt <rostedt@goodmis.org>
[ Upstream commit f2951ebd15c36a1ea4820a7f0cbb0b5f1c028b73 ]
The options files do not take the trace_array reference for the options
they represent. This could cause a use-after-free kernel crash if one of
these files is opened by one task and another task removes the instance
that the option is for. Because it doesn't take a reference upon opening,
it will not stop the removal which will free the options descriptor that
is being used.
As the options are somewhat dynamic in their creation at boot up, each
file represents a flag in the trace_array. The trace_array has an array of
indexes to represent each of these flags that is stored in the
trace_flags_index array. The address of the index array element is used to
pass to the inode->i_private pointer. Then that element is read which
holds the index (which represents the flag) and then the index is used to
calculate the trace_array descriptor from its trace_flags_index array.
One issue is that the index element can not be referenced until the
trace_array's reference is taken. To handle this, create a new helper
function called: trace_array_options_get() that will iterate all the
existing trace_arrays in the ftrace_trace_arrays list (under the
trace_types_lock), and compare the passed in address of the index element
with the entire array of the trace_array's trace_flags_index array.
If it matches, then up the corresponding trace_array's reference and
return.
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260902121918.5a9e9d1b@gandalf.local.home
Fixes: 577b785f55168 ("tracing: add tracer dependent options to options directory")
Reported-by: sashiko-bot@kernel.org
Closes: https://lore.kernel.org/linux-trace-kernel/20260828135858.2AC501F000E9@smtp.kernel.org/
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
[ replaced the unavailable __trace_array_get(tr) call with tr->ref++ and return 0. ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/trace/trace.c | 69 ++++++++++++++++++++++++++++++++++++++++++++++++---
1 file changed, 65 insertions(+), 4 deletions(-)
--- a/kernel/trace/trace.c
+++ b/kernel/trace/trace.c
@@ -9393,11 +9393,72 @@ trace_options_core_write(struct file *fi
return cnt;
}
+/*
+ * The tr_index is the address of a trace_array->trace_flags_index[]
+ * element that holds the index of the trace flag. But since the
+ * trace_array reference has not been taken yet, it cannot be referenced
+ * as it could have been freed by a rmdir of the instance the trace_array
+ * represents.
+ *
+ * Search the list of trace_arrays and compare the tr_index to the
+ * address of the entire trace_array trace_flags_index array for each
+ * trace_array in the list. If one is matched, then take the reference
+ * and return it. If not, the trace_array no longer exits.
+ */
+static int trace_array_options_get(void *tr_index)
+{
+ struct trace_array *tr;
+ int ret;
+
+ ret = security_locked_down(LOCKDOWN_TRACEFS);
+ if (ret)
+ return ret;
+
+ if (tracing_disabled)
+ return -ENODEV;
+
+ guard(mutex)(&trace_types_lock);
+ list_for_each_entry(tr, &ftrace_trace_arrays, list) {
+ if (tr_index >= (void *)&tr->trace_flags_index[0] &&
+ tr_index < (void *)&tr->trace_flags_index[TRACE_FLAGS_MAX_SIZE]) {
+ tr->ref++;
+ return 0;
+ }
+ }
+ return -ENODEV;
+}
+
+static int trace_options_open(struct inode *inode, struct file *filp)
+{
+ void *tr_index = inode->i_private;
+
+ if (trace_array_options_get(tr_index) < 0)
+ return -ENODEV;
+
+ filp->private_data = tr_index;
+
+ return 0;
+}
+
+static int trace_options_release(struct inode *inode, struct file *filp)
+{
+ void *tr_index = filp->private_data;
+ struct trace_array *tr;
+ unsigned int index;
+
+ get_tr_index(tr_index, &tr, &index);
+
+ trace_array_put(tr);
+
+ return 0;
+}
+
static const struct file_operations trace_options_core_fops = {
- .open = tracing_open_generic,
- .read = trace_options_core_read,
- .write = trace_options_core_write,
- .llseek = generic_file_llseek,
+ .open = trace_options_open,
+ .read = trace_options_core_read,
+ .write = trace_options_core_write,
+ .llseek = generic_file_llseek,
+ .release = trace_options_release,
};
struct dentry *trace_create_file(const char *name,
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0054/1518] io_uring: only call io_should_terminate_tw() once for ctx
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (52 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0053/1518] tracing: Take trace_array reference when opening options file Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0055/1518] nvdimm: virtio_pmem: stop allocating child flush bio Greg Kroah-Hartman
` (944 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Caleb Sander Mateos, Jens Axboe,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Caleb Sander Mateos <csander@purestorage.com>
[ Upstream commit 4531d165ee39edb315b42a4a43e29339fa068e51 ]
io_fallback_req_func() calls io_should_terminate_tw() on each req's ctx.
But since the reqs all come from the ctx's fallback_llist, req->ctx will
be ctx for all of the reqs. Therefore, compute ts.cancel as
io_should_terminate_tw(ctx) just once, outside the loop.
Signed-off-by: Caleb Sander Mateos <csander@purestorage.com>
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Stable-dep-of: 14572de82e50 ("io_uring/waitid: honor task_work cancellation")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
io_uring/io_uring.c | 5 ++---
1 file changed, 2 insertions(+), 3 deletions(-)
--- a/io_uring/io_uring.c
+++ b/io_uring/io_uring.c
@@ -292,10 +292,9 @@ static __cold void io_fallback_req_func(
percpu_ref_get(&ctx->refs);
mutex_lock(&ctx->uring_lock);
- llist_for_each_entry_safe(req, tmp, node, io_task_work.node) {
- ts.cancel = io_should_terminate_tw(req->ctx);
+ ts.cancel = io_should_terminate_tw(ctx);
+ llist_for_each_entry_safe(req, tmp, node, io_task_work.node)
req->io_task_work.func(req, ts);
- }
io_submit_flush_completions(ctx);
mutex_unlock(&ctx->uring_lock);
percpu_ref_put(&ctx->refs);
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0055/1518] nvdimm: virtio_pmem: stop allocating child flush bio
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (53 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0054/1518] io_uring: only call io_should_terminate_tw() once for ctx Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0056/1518] io_uring: add wrapper type for io_req_tw_func_t arg Greg Kroah-Hartman
` (943 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Li Chen, Michael S. Tsirkin,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Li Chen <me@linux.beauty>
[ Upstream commit 40f356e610df95728074b1fc2e2ccb54ca1b5659 ]
pmem_submit_bio() passes the parent bio to nvdimm_flush() for
REQ_FUA. For virtio-pmem this makes async_pmem_flush() allocate
and submit a child PREFLUSH bio chained to the parent.
That child allocation is in the block submit path. Making it
blocking with GFP_NOIO can consume the same global bio mempool that
submit_bio() uses, while making it GFP_ATOMIC can fail under
pressure. A forced failure of the child allocation produced:
virtio_pmem: forcing child bio allocation failure for test
Buffer I/O error on dev pmem0, logical block 0, lost sync page write
EXT4-fs (pmem0): I/O error while writing superblock
EXT4-fs (pmem0): mount failed
Avoid the child bio without turning REQ_FUA into a synchronous
submit-path wait. Let provider flush callbacks return
NVDIMM_FLUSH_ASYNC after taking ownership of parent bio completion.
pmem_submit_bio() returns in that case, and virtio-pmem queues an
ordered WQ_MEM_RECLAIM work item that runs the existing host flush
path and completes the parent bio.
This keeps the asynchronous completion model of the child-bio path
while removing the child bio allocation from the submit path.
Signed-off-by: Li Chen <me@linux.beauty>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260630092338.2094628-5-me@linux.beauty>
Stable-dep-of: e57140944b5a ("nvdimm: virtio_pmem: refcount requests for token lifetime")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/nvdimm/nd_virtio.c | 54 ++++++++++++++++++++++++++++++-------------
drivers/nvdimm/pmem.c | 5 +++
drivers/nvdimm/region_devs.c | 2 +
drivers/nvdimm/virtio_pmem.c | 17 ++++++++++++-
drivers/nvdimm/virtio_pmem.h | 4 +++
include/linux/libnvdimm.h | 9 +++++++
6 files changed, 73 insertions(+), 18 deletions(-)
--- a/drivers/nvdimm/nd_virtio.c
+++ b/drivers/nvdimm/nd_virtio.c
@@ -9,6 +9,12 @@
#include "virtio_pmem.h"
#include "nd.h"
+struct virtio_pmem_flush_work {
+ struct work_struct work;
+ struct nd_region *nd_region;
+ struct bio *bio;
+};
+
/* The interrupt handler */
void virtio_pmem_host_ack(struct virtqueue *vq)
{
@@ -107,30 +113,46 @@ static int virtio_pmem_flush(struct nd_r
return err;
};
+static void virtio_pmem_flush_work(struct work_struct *work)
+{
+ struct virtio_pmem_flush_work *flush;
+ int err;
+
+ flush = container_of(work, struct virtio_pmem_flush_work, work);
+ err = virtio_pmem_flush(flush->nd_region);
+ if (err > 0)
+ err = -EIO;
+ if (err)
+ flush->bio->bi_status = errno_to_blk_status(err);
+ bio_endio(flush->bio);
+ kfree(flush);
+}
+
/* The asynchronous flush callback function */
int async_pmem_flush(struct nd_region *nd_region, struct bio *bio)
{
- /*
- * Create child bio for asynchronous flush and chain with
- * parent bio. Otherwise directly call nd_region flush.
- */
- if (bio && bio->bi_iter.bi_sector != -1) {
- struct bio *child = bio_alloc(bio->bi_bdev, 0,
- REQ_OP_WRITE | REQ_PREFLUSH,
- GFP_ATOMIC);
+ struct virtio_device *vdev = nd_region->provider_data;
+ struct virtio_pmem *vpmem = vdev->priv;
+ struct virtio_pmem_flush_work *flush;
+ int err;
- if (!child)
+ if (bio && bio->bi_iter.bi_sector != -1) {
+ flush = kmalloc_obj(*flush, GFP_NOIO);
+ if (!flush)
return -ENOMEM;
- bio_clone_blkg_association(child, bio);
- child->bi_iter.bi_sector = -1;
- bio_chain(child, bio);
- submit_bio(child);
- return 0;
+
+ INIT_WORK(&flush->work, virtio_pmem_flush_work);
+ flush->nd_region = nd_region;
+ flush->bio = bio;
+ queue_work(vpmem->flush_wq, &flush->work);
+ return NVDIMM_FLUSH_ASYNC;
}
- if (virtio_pmem_flush(nd_region))
+
+ err = virtio_pmem_flush(nd_region);
+ if (err > 0)
return -EIO;
- return 0;
+ return err;
};
EXPORT_SYMBOL_GPL(async_pmem_flush);
MODULE_DESCRIPTION("Virtio Persistent Memory Driver");
--- a/drivers/nvdimm/pmem.c
+++ b/drivers/nvdimm/pmem.c
@@ -235,8 +235,11 @@ static void pmem_submit_bio(struct bio *
if (do_acct)
bio_end_io_acct(bio, start);
- if ((bio->bi_opf & REQ_FUA) && !bio->bi_status)
+ if ((bio->bi_opf & REQ_FUA) && !bio->bi_status) {
ret = nvdimm_flush(nd_region, bio);
+ if (ret == NVDIMM_FLUSH_ASYNC)
+ return;
+ }
if (ret)
bio->bi_status = errno_to_blk_status(ret);
--- a/drivers/nvdimm/region_devs.c
+++ b/drivers/nvdimm/region_devs.c
@@ -1095,6 +1095,8 @@ int nvdimm_flush(struct nd_region *nd_re
rc = generic_nvdimm_flush(nd_region);
else {
rc = nd_region->flush(nd_region, bio);
+ if (rc > 0)
+ return rc;
if (rc && rc != -ENOMEM)
rc = -EIO;
}
--- a/drivers/nvdimm/virtio_pmem.c
+++ b/drivers/nvdimm/virtio_pmem.c
@@ -67,10 +67,17 @@ static int virtio_pmem_probe(struct virt
mutex_init(&vpmem->flush_lock);
vpmem->vdev = vdev;
vdev->priv = vpmem;
+ vpmem->flush_wq = alloc_ordered_workqueue("virtio-pmem-flush",
+ WQ_MEM_RECLAIM);
+ if (!vpmem->flush_wq) {
+ err = -ENOMEM;
+ goto out_err;
+ }
+
err = init_vq(vpmem);
if (err) {
dev_err(&vdev->dev, "failed to initialize virtio pmem vq's\n");
- goto out_err;
+ goto out_wq;
}
if (virtio_has_feature(vdev, VIRTIO_PMEM_F_SHMEM_REGION)) {
@@ -131,6 +138,8 @@ out_nd:
nvdimm_bus_unregister(vpmem->nvdimm_bus);
out_vq:
vdev->config->del_vqs(vdev);
+out_wq:
+ destroy_workqueue(vpmem->flush_wq);
out_err:
return err;
}
@@ -138,14 +147,20 @@ out_err:
static void virtio_pmem_remove(struct virtio_device *vdev)
{
struct nvdimm_bus *nvdimm_bus = dev_get_drvdata(&vdev->dev);
+ struct virtio_pmem *vpmem = vdev->priv;
nvdimm_bus_unregister(nvdimm_bus);
+ drain_workqueue(vpmem->flush_wq);
vdev->config->del_vqs(vdev);
virtio_reset_device(vdev);
+ destroy_workqueue(vpmem->flush_wq);
}
static int virtio_pmem_freeze(struct virtio_device *vdev)
{
+ struct virtio_pmem *vpmem = vdev->priv;
+
+ drain_workqueue(vpmem->flush_wq);
vdev->config->del_vqs(vdev);
virtio_reset_device(vdev);
--- a/drivers/nvdimm/virtio_pmem.h
+++ b/drivers/nvdimm/virtio_pmem.h
@@ -15,6 +15,7 @@
#include <linux/libnvdimm.h>
#include <linux/mutex.h>
#include <linux/spinlock.h>
+#include <linux/workqueue.h>
struct virtio_pmem_request {
struct virtio_pmem_req req;
@@ -39,6 +40,9 @@ struct virtio_pmem {
/* Serialize flush requests to the device. */
struct mutex flush_lock;
+ /* Complete asynchronous FUA flushes outside the submit path. */
+ struct workqueue_struct *flush_wq;
+
/* nvdimm bus registers virtio pmem device */
struct nvdimm_bus *nvdimm_bus;
struct nvdimm_bus_descriptor nd_desc;
--- a/include/linux/libnvdimm.h
+++ b/include/linux/libnvdimm.h
@@ -126,6 +126,15 @@ struct nd_mapping_desc {
struct bio;
struct resource;
struct nd_region;
+
+/*
+ * Provider flush callback return values:
+ * 0: flush completed synchronously
+ * <0: flush failed
+ * >0: flush completion was queued and @bio will be completed later
+ */
+#define NVDIMM_FLUSH_ASYNC 1
+
struct nd_region_desc {
struct resource *res;
struct nd_mapping_desc *mapping;
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0056/1518] io_uring: add wrapper type for io_req_tw_func_t arg
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (54 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0055/1518] nvdimm: virtio_pmem: stop allocating child flush bio Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0057/1518] nvdimm: virtio_pmem: always wake -ENOSPC waiters Greg Kroah-Hartman
` (942 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Caleb Sander Mateos, Jens Axboe,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Caleb Sander Mateos <csander@purestorage.com>
[ Upstream commit c33e779aba6804778c1440192a8033a145ba588d ]
In preparation for uring_cmd implementations to implement functions
with the io_req_tw_func_t signature, introduce a wrapper struct
io_tw_req to hide the struct io_kiocb * argument. The intention is for
only the io_uring core to access the inner struct io_kiocb *. uring_cmd
implementations should instead call a helper from io_uring/cmd.h to
convert struct io_tw_req to struct io_uring_cmd *.
Signed-off-by: Caleb Sander Mateos <csander@purestorage.com>
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Stable-dep-of: 14572de82e50 ("io_uring/waitid: honor task_work cancellation")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
include/linux/io_uring_types.h | 6 +++++-
io_uring/futex.c | 16 +++++++++-------
io_uring/io_uring.c | 21 ++++++++++++---------
io_uring/io_uring.h | 4 ++--
io_uring/msg_ring.c | 3 ++-
io_uring/notif.c | 5 +++--
io_uring/poll.c | 11 ++++++-----
io_uring/poll.h | 2 +-
io_uring/rw.c | 5 +++--
io_uring/rw.h | 2 +-
io_uring/timeout.c | 18 +++++++++++-------
io_uring/uring_cmd.c | 3 ++-
io_uring/waitid.c | 7 ++++---
13 files changed, 61 insertions(+), 42 deletions(-)
--- a/include/linux/io_uring_types.h
+++ b/include/linux/io_uring_types.h
@@ -626,7 +626,11 @@ enum {
REQ_F_SQE_COPIED = IO_REQ_FLAG(REQ_F_SQE_COPIED_BIT),
};
-typedef void (*io_req_tw_func_t)(struct io_kiocb *req, io_tw_token_t tw);
+struct io_tw_req {
+ struct io_kiocb *req;
+};
+
+typedef void (*io_req_tw_func_t)(struct io_tw_req tw_req, io_tw_token_t tw);
struct io_task_work {
struct llist_node node;
--- a/io_uring/futex.c
+++ b/io_uring/futex.c
@@ -41,24 +41,26 @@ void io_futex_cache_free(struct io_ring_
io_alloc_cache_free(&ctx->futex_cache, kfree);
}
-static void __io_futex_complete(struct io_kiocb *req, io_tw_token_t tw)
+static void __io_futex_complete(struct io_tw_req tw_req, io_tw_token_t tw)
{
- hlist_del_init(&req->hash_node);
- io_req_task_complete(req, tw);
+ hlist_del_init(&tw_req.req->hash_node);
+ io_req_task_complete(tw_req, tw);
}
-static void io_futex_complete(struct io_kiocb *req, io_tw_token_t tw)
+static void io_futex_complete(struct io_tw_req tw_req, io_tw_token_t tw)
{
+ struct io_kiocb *req = tw_req.req;
struct io_ring_ctx *ctx = req->ctx;
io_tw_lock(ctx, tw);
io_cache_free(&ctx->futex_cache, req->async_data);
io_req_async_data_clear(req, 0);
- __io_futex_complete(req, tw);
+ __io_futex_complete(tw_req, tw);
}
-static void io_futexv_complete(struct io_kiocb *req, io_tw_token_t tw)
+static void io_futexv_complete(struct io_tw_req tw_req, io_tw_token_t tw)
{
+ struct io_kiocb *req = tw_req.req;
struct io_futex *iof = io_kiocb_to_cmd(req, struct io_futex);
struct futex_vector *futexv = req->async_data;
@@ -73,7 +75,7 @@ static void io_futexv_complete(struct io
}
io_req_async_data_free(req);
- __io_futex_complete(req, tw);
+ __io_futex_complete(tw_req, tw);
}
static bool io_futexv_claim(struct io_futex *iof)
--- a/io_uring/io_uring.c
+++ b/io_uring/io_uring.c
@@ -294,7 +294,7 @@ static __cold void io_fallback_req_func(
mutex_lock(&ctx->uring_lock);
ts.cancel = io_should_terminate_tw(ctx);
llist_for_each_entry_safe(req, tmp, node, io_task_work.node)
- req->io_task_work.func(req, ts);
+ req->io_task_work.func((struct io_tw_req){req}, ts);
io_submit_flush_completions(ctx);
mutex_unlock(&ctx->uring_lock);
percpu_ref_put(&ctx->refs);
@@ -542,9 +542,9 @@ static void io_queue_iowq(struct io_kioc
io_wq_enqueue(tctx->io_wq, &req->work);
}
-static void io_req_queue_iowq_tw(struct io_kiocb *req, io_tw_token_t tw)
+static void io_req_queue_iowq_tw(struct io_tw_req tw_req, io_tw_token_t tw)
{
- io_queue_iowq(req);
+ io_queue_iowq(tw_req.req);
}
void io_req_queue_iowq(struct io_kiocb *req)
@@ -1171,7 +1171,7 @@ struct llist_node *io_handle_tw_list(str
}
INDIRECT_CALL_2(req->io_task_work.func,
io_poll_task_func, io_req_rw_complete,
- req, ts);
+ (struct io_tw_req){req}, ts);
node = next;
(*count)++;
if (unlikely(need_resched())) {
@@ -1422,7 +1422,7 @@ static int __io_run_local_work_loop(stru
io_task_work.node);
INDIRECT_CALL_2(req->io_task_work.func,
io_poll_task_func, io_req_rw_complete,
- req, tw);
+ (struct io_tw_req){req}, tw);
*node = next;
if (++ret >= events)
break;
@@ -1492,14 +1492,17 @@ static int io_run_local_work(struct io_r
return ret;
}
-static void io_req_task_cancel(struct io_kiocb *req, io_tw_token_t tw)
+static void io_req_task_cancel(struct io_tw_req tw_req, io_tw_token_t tw)
{
+ struct io_kiocb *req = tw_req.req;
+
io_tw_lock(req->ctx, tw);
io_req_defer_failed(req, req->cqe.res);
}
-void io_req_task_submit(struct io_kiocb *req, io_tw_token_t tw)
+void io_req_task_submit(struct io_tw_req tw_req, io_tw_token_t tw)
{
+ struct io_kiocb *req = tw_req.req;
struct io_ring_ctx *ctx = req->ctx;
io_tw_lock(ctx, tw);
@@ -1735,9 +1738,9 @@ static int io_iopoll_check(struct io_rin
return 0;
}
-void io_req_task_complete(struct io_kiocb *req, io_tw_token_t tw)
+void io_req_task_complete(struct io_tw_req tw_req, io_tw_token_t tw)
{
- io_req_complete_defer(req);
+ io_req_complete_defer(tw_req.req);
}
/*
--- a/io_uring/io_uring.h
+++ b/io_uring/io_uring.h
@@ -160,9 +160,9 @@ struct file *io_file_get_fixed(struct io
void __io_req_task_work_add(struct io_kiocb *req, unsigned flags);
void io_req_task_work_add_remote(struct io_kiocb *req, unsigned flags);
void io_req_task_queue(struct io_kiocb *req);
-void io_req_task_complete(struct io_kiocb *req, io_tw_token_t tw);
+void io_req_task_complete(struct io_tw_req tw_req, io_tw_token_t tw);
void io_req_task_queue_fail(struct io_kiocb *req, int ret);
-void io_req_task_submit(struct io_kiocb *req, io_tw_token_t tw);
+void io_req_task_submit(struct io_tw_req tw_req, io_tw_token_t tw);
struct llist_node *io_handle_tw_list(struct llist_node *node, unsigned int *count, unsigned int max_entries);
struct llist_node *tctx_task_work_run(struct io_uring_task *tctx, unsigned int max_entries, unsigned int *count);
void tctx_task_work(struct callback_head *cb);
--- a/io_uring/msg_ring.c
+++ b/io_uring/msg_ring.c
@@ -70,8 +70,9 @@ static inline bool io_msg_need_remote(st
return target_ctx->task_complete;
}
-static void io_msg_tw_complete(struct io_kiocb *req, io_tw_token_t tw)
+static void io_msg_tw_complete(struct io_tw_req tw_req, io_tw_token_t tw)
{
+ struct io_kiocb *req = tw_req.req;
struct io_ring_ctx *ctx = req->ctx;
io_add_aux_cqe(ctx, req->cqe.user_data, req->cqe.res, req->cqe.flags);
--- a/io_uring/notif.c
+++ b/io_uring/notif.c
@@ -11,8 +11,9 @@
static const struct ubuf_info_ops io_ubuf_ops;
-static void io_notif_tw_complete(struct io_kiocb *notif, io_tw_token_t tw)
+static void io_notif_tw_complete(struct io_tw_req tw_req, io_tw_token_t tw)
{
+ struct io_kiocb *notif = tw_req.req;
struct io_notif_data *nd = io_notif_to_data(notif);
struct io_ring_ctx *ctx = notif->ctx;
@@ -34,7 +35,7 @@ static void io_notif_tw_complete(struct
}
nd = nd->next;
- io_req_task_complete(notif, tw);
+ io_req_task_complete((struct io_tw_req){notif}, tw);
} while (nd);
}
--- a/io_uring/poll.c
+++ b/io_uring/poll.c
@@ -316,8 +316,9 @@ static int io_poll_check_events(struct i
return IOU_POLL_NO_ACTION;
}
-void io_poll_task_func(struct io_kiocb *req, io_tw_token_t tw)
+void io_poll_task_func(struct io_tw_req tw_req, io_tw_token_t tw)
{
+ struct io_kiocb *req = tw_req.req;
int ret;
ret = io_poll_check_events(req, tw);
@@ -338,7 +339,7 @@ void io_poll_task_func(struct io_kiocb *
poll = io_kiocb_to_cmd(req, struct io_poll);
req->cqe.res = mangle_poll(req->cqe.res & poll->events);
} else if (ret == IOU_POLL_REISSUE) {
- io_req_task_submit(req, tw);
+ io_req_task_submit(tw_req, tw);
return;
} else if (ret != IOU_POLL_REMOVE_POLL_USE_RES) {
req->cqe.res = ret;
@@ -346,14 +347,14 @@ void io_poll_task_func(struct io_kiocb *
}
io_req_set_res(req, req->cqe.res, 0);
- io_req_task_complete(req, tw);
+ io_req_task_complete(tw_req, tw);
} else {
io_tw_lock(req->ctx, tw);
if (ret == IOU_POLL_REMOVE_POLL_USE_RES)
- io_req_task_complete(req, tw);
+ io_req_task_complete(tw_req, tw);
else if (ret == IOU_POLL_DONE || ret == IOU_POLL_REISSUE)
- io_req_task_submit(req, tw);
+ io_req_task_submit(tw_req, tw);
else
io_req_defer_failed(req, ret);
}
--- a/io_uring/poll.h
+++ b/io_uring/poll.h
@@ -46,4 +46,4 @@ int io_arm_poll_handler(struct io_kiocb
bool io_poll_remove_all(struct io_ring_ctx *ctx, struct io_uring_task *tctx,
bool cancel_all);
-void io_poll_task_func(struct io_kiocb *req, io_tw_token_t tw);
+void io_poll_task_func(struct io_tw_req tw_req, io_tw_token_t tw);
--- a/io_uring/rw.c
+++ b/io_uring/rw.c
@@ -574,8 +574,9 @@ static inline int io_fixup_rw_res(struct
return res;
}
-void io_req_rw_complete(struct io_kiocb *req, io_tw_token_t tw)
+void io_req_rw_complete(struct io_tw_req tw_req, io_tw_token_t tw)
{
+ struct io_kiocb *req = tw_req.req;
struct io_rw *rw = io_kiocb_to_cmd(req, struct io_rw);
struct kiocb *kiocb = &rw->kiocb;
@@ -591,7 +592,7 @@ void io_req_rw_complete(struct io_kiocb
req->cqe.flags |= io_put_kbuf(req, req->cqe.res, NULL);
io_req_rw_cleanup(req, 0);
- io_req_task_complete(req, tw);
+ io_req_task_complete(tw_req, tw);
}
static void io_complete_rw(struct kiocb *kiocb, long res)
--- a/io_uring/rw.h
+++ b/io_uring/rw.h
@@ -46,7 +46,7 @@ int io_read_fixed(struct io_kiocb *req,
int io_write_fixed(struct io_kiocb *req, unsigned int issue_flags);
void io_readv_writev_cleanup(struct io_kiocb *req);
void io_rw_fail(struct io_kiocb *req);
-void io_req_rw_complete(struct io_kiocb *req, io_tw_token_t tw);
+void io_req_rw_complete(struct io_tw_req tw_req, io_tw_token_t tw);
int io_read_mshot_prep(struct io_kiocb *req, const struct io_uring_sqe *sqe);
int io_read_mshot(struct io_kiocb *req, unsigned int issue_flags);
void io_rw_cache_free(const void *entry);
--- a/io_uring/timeout.c
+++ b/io_uring/timeout.c
@@ -68,8 +68,9 @@ static inline bool io_timeout_finish(str
static enum hrtimer_restart io_timeout_fn(struct hrtimer *timer);
-static void io_timeout_complete(struct io_kiocb *req, io_tw_token_t tw)
+static void io_timeout_complete(struct io_tw_req tw_req, io_tw_token_t tw)
{
+ struct io_kiocb *req = tw_req.req;
struct io_timeout *timeout = io_kiocb_to_cmd(req, struct io_timeout);
struct io_timeout_data *data = req->async_data;
struct io_ring_ctx *ctx = req->ctx;
@@ -85,7 +86,7 @@ static void io_timeout_complete(struct i
}
}
- io_req_task_complete(req, tw);
+ io_req_task_complete(tw_req, tw);
}
static __cold bool io_flush_killed_timeouts(struct list_head *list, int err)
@@ -157,8 +158,10 @@ __cold void io_flush_timeouts(struct io_
io_flush_killed_timeouts(&list, 0);
}
-static void io_req_tw_fail_links(struct io_kiocb *link, io_tw_token_t tw)
+static void io_req_tw_fail_links(struct io_tw_req tw_req, io_tw_token_t tw)
{
+ struct io_kiocb *link = tw_req.req;
+
io_tw_lock(link->ctx, tw);
while (link) {
struct io_kiocb *nxt = link->link;
@@ -168,7 +171,7 @@ static void io_req_tw_fail_links(struct
res = link->cqe.res;
link->link = NULL;
io_req_set_res(link, res, 0);
- io_req_task_complete(link, tw);
+ io_req_task_complete((struct io_tw_req){link}, tw);
link = nxt;
}
}
@@ -317,8 +320,9 @@ int io_timeout_cancel(struct io_ring_ctx
return 0;
}
-static void io_req_task_link_timeout(struct io_kiocb *req, io_tw_token_t tw)
+static void io_req_task_link_timeout(struct io_tw_req tw_req, io_tw_token_t tw)
{
+ struct io_kiocb *req = tw_req.req;
struct io_timeout *timeout = io_kiocb_to_cmd(req, struct io_timeout);
struct io_kiocb *prev = timeout->prev;
int ret;
@@ -335,11 +339,11 @@ static void io_req_task_link_timeout(str
ret = -ECANCELED;
}
io_req_set_res(req, ret ?: -ETIME, 0);
- io_req_task_complete(req, tw);
+ io_req_task_complete(tw_req, tw);
io_put_req(prev);
} else {
io_req_set_res(req, -ETIME, 0);
- io_req_task_complete(req, tw);
+ io_req_task_complete(tw_req, tw);
}
}
--- a/io_uring/uring_cmd.c
+++ b/io_uring/uring_cmd.c
@@ -115,8 +115,9 @@ void io_uring_cmd_mark_cancelable(struct
}
EXPORT_SYMBOL_GPL(io_uring_cmd_mark_cancelable);
-static void io_uring_cmd_work(struct io_kiocb *req, io_tw_token_t tw)
+static void io_uring_cmd_work(struct io_tw_req tw_req, io_tw_token_t tw)
{
+ struct io_kiocb *req = tw_req.req;
struct io_uring_cmd *ioucmd = io_kiocb_to_cmd(req, struct io_uring_cmd);
unsigned int flags = IO_URING_F_COMPLETE_DEFER;
--- a/io_uring/waitid.c
+++ b/io_uring/waitid.c
@@ -16,7 +16,7 @@
#include "waitid.h"
#include "../kernel/exit.h"
-static void io_waitid_cb(struct io_kiocb *req, io_tw_token_t tw);
+static void io_waitid_cb(struct io_tw_req tw_req, io_tw_token_t tw);
#define IO_WAITID_CANCEL_FLAG BIT(31)
#define IO_WAITID_REF_MASK GENMASK(30, 0)
@@ -194,8 +194,9 @@ static inline bool io_waitid_drop_issue_
return true;
}
-static void io_waitid_cb(struct io_kiocb *req, io_tw_token_t tw)
+static void io_waitid_cb(struct io_tw_req tw_req, io_tw_token_t tw)
{
+ struct io_kiocb *req = tw_req.req;
struct io_waitid_async *iwa = req->async_data;
struct io_ring_ctx *ctx = req->ctx;
int ret;
@@ -229,7 +230,7 @@ static void io_waitid_cb(struct io_kiocb
}
io_waitid_complete(req, ret);
- io_req_task_complete(req, tw);
+ io_req_task_complete(tw_req, tw);
}
static int io_waitid_wait(struct wait_queue_entry *wait, unsigned mode,
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0057/1518] nvdimm: virtio_pmem: always wake -ENOSPC waiters
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (55 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0056/1518] io_uring: add wrapper type for io_req_tw_func_t arg Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0058/1518] io_uring/waitid: honor task_work cancellation Greg Kroah-Hartman
` (941 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Li Chen, Michael S. Tsirkin,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Li Chen <me@linux.beauty>
[ Upstream commit 811808761e19fdea1c25b7c76734b8945f758f27 ]
virtio_pmem_host_ack() reclaims virtqueue descriptors with
virtqueue_get_buf(). The -ENOSPC waiter wakeup is tied to completing the
returned token. If token completion is skipped for any reason, reclaimed
descriptors may not wake a waiter and the submitter may sleep forever
waiting for a free slot. Always wake one -ENOSPC waiter for each virtqueue
completion before touching the returned token.
Signed-off-by: Li Chen <me@linux.beauty>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260630092338.2094628-7-me@linux.beauty>
Stable-dep-of: e57140944b5a ("nvdimm: virtio_pmem: refcount requests for token lifetime")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/nvdimm/nd_virtio.c | 25 ++++++++++++++++---------
1 file changed, 16 insertions(+), 9 deletions(-)
--- a/drivers/nvdimm/nd_virtio.c
+++ b/drivers/nvdimm/nd_virtio.c
@@ -15,26 +15,33 @@ struct virtio_pmem_flush_work {
struct bio *bio;
};
+static void virtio_pmem_wake_one_waiter(struct virtio_pmem *vpmem)
+{
+ struct virtio_pmem_request *req_buf;
+
+ if (list_empty(&vpmem->req_list))
+ return;
+
+ req_buf = list_first_entry(&vpmem->req_list,
+ struct virtio_pmem_request, list);
+ req_buf->wq_buf_avail = true;
+ wake_up(&req_buf->wq_buf);
+ list_del(&req_buf->list);
+}
+
/* The interrupt handler */
void virtio_pmem_host_ack(struct virtqueue *vq)
{
struct virtio_pmem *vpmem = vq->vdev->priv;
- struct virtio_pmem_request *req_data, *req_buf;
+ struct virtio_pmem_request *req_data;
unsigned long flags;
unsigned int len;
spin_lock_irqsave(&vpmem->pmem_lock, flags);
while ((req_data = virtqueue_get_buf(vq, &len)) != NULL) {
+ virtio_pmem_wake_one_waiter(vpmem);
req_data->done = true;
wake_up(&req_data->host_acked);
-
- if (!list_empty(&vpmem->req_list)) {
- req_buf = list_first_entry(&vpmem->req_list,
- struct virtio_pmem_request, list);
- req_buf->wq_buf_avail = true;
- wake_up(&req_buf->wq_buf);
- list_del(&req_buf->list);
- }
}
spin_unlock_irqrestore(&vpmem->pmem_lock, flags);
}
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0058/1518] io_uring/waitid: honor task_work cancellation
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (56 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0057/1518] nvdimm: virtio_pmem: always wake -ENOSPC waiters Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0059/1518] nvdimm: virtio_pmem: use READ_ONCE()/WRITE_ONCE() for wait flags Greg Kroah-Hartman
` (940 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Hui Su, Jens Axboe, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hui Su <sh_def@163.com>
[ Upstream commit 14572de82e5022899e5856008bc9cac97004a88c ]
io_waitid_cb() may run through the fallback task_work path when
task_work_add() can no longer queue work to the originating task. The
fallback runs from a kworker and io_uring marks such task work as
canceled through tw.cancel.
io_waitid_cb() currently ignores tw.cancel and calls __do_wait().
waitid is task-context dependent: __do_wait() performs child lookup
relative to current, and the retry path also uses
current->signal->wait_chldexit. If the callback runs from the fallback
kworker, current is therefore not the task that submitted the request.
Honor tw.cancel before entering __do_wait(). Complete the request with
-ECANCELED and skip the siginfo copy, since canceled task work may run
without the submitting task's userspace execution context.
Keep the existing siginfo handling for normal waitid completion and
explicit cancellation.
Fixes: f31ecf671ddc ("io_uring: add IORING_OP_WAITID support")
Cc: stable@vger.kernel.org
Signed-off-by: Hui Su <sh_def@163.com>
Link: https://patch.msgid.link/20260818103336.1922818-2-sh_def@163.com
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
io_uring/waitid.c | 16 ++++++++++++----
1 file changed, 12 insertions(+), 4 deletions(-)
--- a/io_uring/waitid.c
+++ b/io_uring/waitid.c
@@ -125,7 +125,7 @@ static void io_waitid_remove_wq(struct i
}
}
-static void io_waitid_complete(struct io_kiocb *req, int ret)
+static void io_waitid_complete(struct io_kiocb *req, int ret, bool copy_si)
{
struct io_waitid *iw = io_kiocb_to_cmd(req, struct io_waitid);
@@ -137,7 +137,10 @@ static void io_waitid_complete(struct io
hlist_del_init(&req->hash_node);
io_waitid_remove_wq(req);
- ret = io_waitid_finish(req, ret);
+ if (copy_si)
+ ret = io_waitid_finish(req, ret);
+ else
+ io_waitid_free(req);
if (ret < 0)
req_set_fail(req);
io_req_set_res(req, ret, 0);
@@ -159,7 +162,7 @@ static bool __io_waitid_cancel(struct io
if (atomic_fetch_inc(&iw->refs) & IO_WAITID_REF_MASK)
return false;
- io_waitid_complete(req, -ECANCELED);
+ io_waitid_complete(req, -ECANCELED, true);
io_req_queue_tw_complete(req, -ECANCELED);
return true;
}
@@ -202,6 +205,11 @@ static void io_waitid_cb(struct io_tw_re
int ret;
io_tw_lock(ctx, tw);
+ if (unlikely(tw.cancel)) {
+ io_waitid_complete(req, -ECANCELED, false);
+ io_req_task_complete(tw_req, tw);
+ return;
+ }
ret = __do_wait(&iwa->wo);
@@ -229,7 +237,7 @@ static void io_waitid_cb(struct io_tw_re
}
}
- io_waitid_complete(req, ret);
+ io_waitid_complete(req, ret, true);
io_req_task_complete(tw_req, tw);
}
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0059/1518] nvdimm: virtio_pmem: use READ_ONCE()/WRITE_ONCE() for wait flags
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (57 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0058/1518] io_uring/waitid: honor task_work cancellation Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0060/1518] io_uring/waitid: avoid siginfo copy during ring teardown Greg Kroah-Hartman
` (939 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pankaj Gupta, Li Chen,
Michael S. Tsirkin, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Li Chen <me@linux.beauty>
[ Upstream commit 08e72a5ba1ab9dc0adf993ff0f4d606a1e3445a8 ]
Use READ_ONCE()/WRITE_ONCE() for the wait_event() flags (done and
wq_buf_avail). They are observed by waiters without pmem_lock, so make
the accesses explicit single loads/stores and avoid compiler
reordering/caching across the wait/wake paths.
Acked-by: Pankaj Gupta <pankaj.gupta.linux@gmail.com>
Signed-off-by: Li Chen <me@linux.beauty>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260630092338.2094628-8-me@linux.beauty>
Stable-dep-of: e57140944b5a ("nvdimm: virtio_pmem: refcount requests for token lifetime")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/nvdimm/nd_virtio.c | 14 +++++++-------
1 file changed, 7 insertions(+), 7 deletions(-)
--- a/drivers/nvdimm/nd_virtio.c
+++ b/drivers/nvdimm/nd_virtio.c
@@ -24,9 +24,9 @@ static void virtio_pmem_wake_one_waiter(
req_buf = list_first_entry(&vpmem->req_list,
struct virtio_pmem_request, list);
- req_buf->wq_buf_avail = true;
+ list_del_init(&req_buf->list);
+ WRITE_ONCE(req_buf->wq_buf_avail, true);
wake_up(&req_buf->wq_buf);
- list_del(&req_buf->list);
}
/* The interrupt handler */
@@ -40,7 +40,7 @@ void virtio_pmem_host_ack(struct virtque
spin_lock_irqsave(&vpmem->pmem_lock, flags);
while ((req_data = virtqueue_get_buf(vq, &len)) != NULL) {
virtio_pmem_wake_one_waiter(vpmem);
- req_data->done = true;
+ WRITE_ONCE(req_data->done, true);
wake_up(&req_data->host_acked);
}
spin_unlock_irqrestore(&vpmem->pmem_lock, flags);
@@ -72,7 +72,7 @@ static int virtio_pmem_flush(struct nd_r
if (!req_data)
return -ENOMEM;
- req_data->done = false;
+ WRITE_ONCE(req_data->done, false);
init_waitqueue_head(&req_data->host_acked);
init_waitqueue_head(&req_data->wq_buf);
INIT_LIST_HEAD(&req_data->list);
@@ -93,12 +93,12 @@ static int virtio_pmem_flush(struct nd_r
GFP_ATOMIC)) == -ENOSPC) {
dev_info(&vdev->dev, "failed to send command to virtio pmem device, no free slots in the virtqueue\n");
- req_data->wq_buf_avail = false;
+ WRITE_ONCE(req_data->wq_buf_avail, false);
list_add_tail(&req_data->list, &vpmem->req_list);
spin_unlock_irqrestore(&vpmem->pmem_lock, flags);
/* A host response results in "host_ack" getting called */
- wait_event(req_data->wq_buf, req_data->wq_buf_avail);
+ wait_event(req_data->wq_buf, READ_ONCE(req_data->wq_buf_avail));
spin_lock_irqsave(&vpmem->pmem_lock, flags);
}
err1 = virtqueue_kick(vpmem->req_vq);
@@ -112,7 +112,7 @@ static int virtio_pmem_flush(struct nd_r
err = -EIO;
} else {
/* A host response results in "host_ack" getting called */
- wait_event(req_data->host_acked, req_data->done);
+ wait_event(req_data->host_acked, READ_ONCE(req_data->done));
err = le32_to_cpu(req_data->resp.ret);
}
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0060/1518] io_uring/waitid: avoid siginfo copy during ring teardown
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (58 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0059/1518] nvdimm: virtio_pmem: use READ_ONCE()/WRITE_ONCE() for wait flags Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0061/1518] nvdimm: virtio_pmem: refcount requests for token lifetime Greg Kroah-Hartman
` (938 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Hui Su, Jens Axboe, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hui Su <sh_def@163.com>
[ Upstream commit 2cf20c4e0f72d523b8673053e7120d092ff1f074 ]
During ring teardown, io_ring_exit_work() cancels outstanding requests
from a kworker with a NULL tctx. The waitid cancellation path eventually
reaches io_waitid_finish(), which copies the stored siginfo to the
userspace pointer supplied with the request.
Ring-wide teardown does not run in the task context that submitted the
request, so it must not access that task's userspace pointer. Depending
on the address and mm state, the copy may fail with -EFAULT, but the
uaccess itself is inappropriate from the teardown kworker.
Use a no-copy cancellation callback when io_waitid_remove_all() is
called without an owning task context. Complete the request with
-ECANCELED while releasing the waitid state without touching siginfo.
Keep the existing siginfo handling for explicit async cancellation and
task-scoped cancellation.
Fixes: f31ecf671ddc ("io_uring: add IORING_OP_WAITID support")
Cc: stable@vger.kernel.org
Signed-off-by: Hui Su <sh_def@163.com>
Link: https://patch.msgid.link/20260818103336.1922818-3-sh_def@163.com
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
io_uring/waitid.c | 19 +++++++++++++++----
1 file changed, 15 insertions(+), 4 deletions(-)
--- a/io_uring/waitid.c
+++ b/io_uring/waitid.c
@@ -146,7 +146,7 @@ static void io_waitid_complete(struct io
io_req_set_res(req, ret, 0);
}
-static bool __io_waitid_cancel(struct io_kiocb *req)
+static bool __io_waitid_cancel(struct io_kiocb *req, bool copy_si)
{
struct io_waitid *iw = io_kiocb_to_cmd(req, struct io_waitid);
@@ -162,21 +162,32 @@ static bool __io_waitid_cancel(struct io
if (atomic_fetch_inc(&iw->refs) & IO_WAITID_REF_MASK)
return false;
- io_waitid_complete(req, -ECANCELED, true);
+ io_waitid_complete(req, -ECANCELED, copy_si);
io_req_queue_tw_complete(req, -ECANCELED);
return true;
}
+static bool io_waitid_cancel_cb(struct io_kiocb *req)
+{
+ return __io_waitid_cancel(req, true);
+}
+
+static bool io_waitid_cancel_nocopy_cb(struct io_kiocb *req)
+{
+ return __io_waitid_cancel(req, false);
+}
+
int io_waitid_cancel(struct io_ring_ctx *ctx, struct io_cancel_data *cd,
unsigned int issue_flags)
{
- return io_cancel_remove(ctx, cd, issue_flags, &ctx->waitid_list, __io_waitid_cancel);
+ return io_cancel_remove(ctx, cd, issue_flags, &ctx->waitid_list, io_waitid_cancel_cb);
}
bool io_waitid_remove_all(struct io_ring_ctx *ctx, struct io_uring_task *tctx,
bool cancel_all)
{
- return io_cancel_remove_all(ctx, tctx, &ctx->waitid_list, cancel_all, __io_waitid_cancel);
+ return io_cancel_remove_all(ctx, tctx, &ctx->waitid_list, cancel_all,
+ tctx ? io_waitid_cancel_cb : io_waitid_cancel_nocopy_cb);
}
static inline bool io_waitid_drop_issue_ref(struct io_kiocb *req)
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0061/1518] nvdimm: virtio_pmem: refcount requests for token lifetime
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (59 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0060/1518] io_uring/waitid: avoid siginfo copy during ring teardown Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0062/1518] accel/amdxdna: return early from a zero-length flush Greg Kroah-Hartman
` (937 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Li Chen, Michael S. Tsirkin,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Li Chen <me@linux.beauty>
[ Upstream commit e57140944b5a47a7fd5a142faab29a02af040bc8 ]
KASAN reports slab-use-after-free in __wake_up_common():
BUG: KASAN: slab-use-after-free in __wake_up_common+0x114/0x160
Read of size 8 at addr ffff88810fdcb710 by task swapper/0/0
CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted
6.19.0-next-20260220-00006-g1eae5f204ec3 #4 PREEMPT(full)
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux
1.17.0-2-2 04/01/2014
Call Trace:
<IRQ>
dump_stack_lvl+0x6d/0xb0
print_report+0x170/0x4e2
? __pfx__raw_spin_lock_irqsave+0x10/0x10
? __virt_addr_valid+0x1dc/0x380
kasan_report+0xbc/0xf0
? __wake_up_common+0x114/0x160
? __wake_up_common+0x114/0x160
__wake_up_common+0x114/0x160
? __pfx__raw_spin_lock_irqsave+0x10/0x10
__wake_up+0x36/0x60
virtio_pmem_host_ack+0x11d/0x3b0
? sched_balance_domains+0x29f/0xb00
? __pfx_virtio_pmem_host_ack+0x10/0x10
? _raw_spin_lock_irqsave+0x98/0x100
? __pfx__raw_spin_lock_irqsave+0x10/0x10
vring_interrupt+0x1c9/0x5e0
? __pfx_vp_interrupt+0x10/0x10
vp_vring_interrupt+0x87/0x100
? __pfx_vp_interrupt+0x10/0x10
__handle_irq_event_percpu+0x17f/0x550
? __pfx__raw_spin_lock+0x10/0x10
handle_irq_event+0xab/0x1c0
handle_fasteoi_irq+0x276/0xae0
__common_interrupt+0x65/0x130
common_interrupt+0x78/0xa0
</IRQ>
virtio_pmem_host_ack() wakes a request that has already been freed by the
submitter.
This happens when the request token is still reachable via the virtqueue,
but virtio_pmem_flush() returns and frees it.
Fix the token lifetime by refcounting struct virtio_pmem_request.
virtio_pmem_flush() holds a submitter reference, and the virtqueue holds an
extra reference once the request is queued. The completion path drops the
virtqueue reference, and the submitter drops its reference before
returning.
Fixes: 6e84200c0a29 ("virtio-pmem: Add virtio pmem driver")
Cc: stable@vger.kernel.org
Signed-off-by: Li Chen <me@linux.beauty>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260630092338.2094628-9-me@linux.beauty>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/nvdimm/nd_virtio.c | 32 ++++++++++++++++++++++++++++----
drivers/nvdimm/virtio_pmem.h | 2 ++
2 files changed, 30 insertions(+), 4 deletions(-)
--- a/drivers/nvdimm/nd_virtio.c
+++ b/drivers/nvdimm/nd_virtio.c
@@ -15,6 +15,14 @@ struct virtio_pmem_flush_work {
struct bio *bio;
};
+static void virtio_pmem_req_release(struct kref *kref)
+{
+ struct virtio_pmem_request *req;
+
+ req = container_of(kref, struct virtio_pmem_request, kref);
+ kfree(req);
+}
+
static void virtio_pmem_wake_one_waiter(struct virtio_pmem *vpmem)
{
struct virtio_pmem_request *req_buf;
@@ -42,6 +50,7 @@ void virtio_pmem_host_ack(struct virtque
virtio_pmem_wake_one_waiter(vpmem);
WRITE_ONCE(req_data->done, true);
wake_up(&req_data->host_acked);
+ kref_put(&req_data->kref, virtio_pmem_req_release);
}
spin_unlock_irqrestore(&vpmem->pmem_lock, flags);
}
@@ -72,6 +81,7 @@ static int virtio_pmem_flush(struct nd_r
if (!req_data)
return -ENOMEM;
+ kref_init(&req_data->kref);
WRITE_ONCE(req_data->done, false);
init_waitqueue_head(&req_data->host_acked);
init_waitqueue_head(&req_data->wq_buf);
@@ -89,10 +99,23 @@ static int virtio_pmem_flush(struct nd_r
* to req_list and wait for host_ack to wake us up when free
* slots are available.
*/
- while ((err = virtqueue_add_sgs(vpmem->req_vq, sgs, 1, 1, req_data,
- GFP_ATOMIC)) == -ENOSPC) {
+ for (;;) {
+ err = virtqueue_add_sgs(vpmem->req_vq, sgs, 1, 1, req_data,
+ GFP_ATOMIC);
+ if (!err) {
+ /*
+ * Take the virtqueue reference while @pmem_lock is
+ * held so completion cannot run concurrently.
+ */
+ kref_get(&req_data->kref);
+ break;
+ }
+
+ if (err != -ENOSPC)
+ break;
- dev_info(&vdev->dev, "failed to send command to virtio pmem device, no free slots in the virtqueue\n");
+ dev_info_ratelimited(&vdev->dev,
+ "failed to send command to virtio pmem device, no free slots in the virtqueue\n");
WRITE_ONCE(req_data->wq_buf_avail, false);
list_add_tail(&req_data->list, &vpmem->req_list);
spin_unlock_irqrestore(&vpmem->pmem_lock, flags);
@@ -101,6 +124,7 @@ static int virtio_pmem_flush(struct nd_r
wait_event(req_data->wq_buf, READ_ONCE(req_data->wq_buf_avail));
spin_lock_irqsave(&vpmem->pmem_lock, flags);
}
+
err1 = virtqueue_kick(vpmem->req_vq);
spin_unlock_irqrestore(&vpmem->pmem_lock, flags);
/*
@@ -116,7 +140,7 @@ static int virtio_pmem_flush(struct nd_r
err = le32_to_cpu(req_data->resp.ret);
}
- kfree(req_data);
+ kref_put(&req_data->kref, virtio_pmem_req_release);
return err;
};
--- a/drivers/nvdimm/virtio_pmem.h
+++ b/drivers/nvdimm/virtio_pmem.h
@@ -12,12 +12,14 @@
#include <linux/module.h>
#include <uapi/linux/virtio_pmem.h>
+#include <linux/kref.h>
#include <linux/libnvdimm.h>
#include <linux/mutex.h>
#include <linux/spinlock.h>
#include <linux/workqueue.h>
struct virtio_pmem_request {
+ struct kref kref;
struct virtio_pmem_req req;
struct virtio_pmem_resp resp;
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0062/1518] accel/amdxdna: return early from a zero-length flush
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (60 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0061/1518] nvdimm: virtio_pmem: refcount requests for token lifetime Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0063/1518] clk: qcom: Fix test_ctl_hi field for DEFAULT_EVO PLLs Greg Kroah-Hartman
` (936 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Taimuraz Kaitmazov, Lizhi Hou,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Taimuraz Kaitmazov <taimuraz@kaitmazov.com>
[ Upstream commit dc14753664240cedf669623b27ae9922b0618b25 ]
SYNC_BO does not constrain its size, so a request for zero bytes reaches
drm_clflush_virt_range(), which ends with an unconditional
clflushopt(end - 1). For an empty range that is the byte before the
mapping, and abo->mem.kva comes from vmap(), so the access lands in the
guard page below the vmalloc area and faults:
BUG: unable to handle page fault for address: ffffd16fbbc70fff
#PF: supervisor read access in kernel mode
Oops: Oops: 0000 [#1] SMP NOPTI
CPU: 7 UID: 1000 Comm: sync_bo_probe
RIP: 0010:drm_clflush_virt_range+0x3c/0x70
Call Trace:
amdxdna_drm_sync_bo_ioctl+0x124/0x430 [amdxdna]
drm_ioctl+0x301/0x4c0
__x64_sys_ioctl+0x115/0x2f0
do_syscall_64+0xa6/0x3d0
Any process that can open the render node can do this. Reproduced 3 of 3
times on a Strix Point NPU (1022:17f0), by calling SYNC_BO with size 0 on
an AMDXDNA_BO_SHARE object. The import arm takes the same request but
flushes the whole scatterlist, so it survives it.
Nothing needs flushing for an empty range, so answer before choosing a
path.
Fixes: e252e3f3488a ("accel/amdxdna: Revise device bo creation and free")
Cc: stable@vger.kernel.org
Signed-off-by: Taimuraz Kaitmazov <taimuraz@kaitmazov.com>
Reviewed-by: Lizhi Hou <lizhi.hou@amd.com>
Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
Link: https://patch.msgid.link/20260817230655.356785-1-taimuraz@kaitmazov.com
[ moved the guard into amdxdna_drm_sync_bo_ioctl() because amdxdna_flush_bo() is absent. ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/accel/amdxdna/amdxdna_gem.c | 4 ++++
1 file changed, 4 insertions(+)
--- a/drivers/accel/amdxdna/amdxdna_gem.c
+++ b/drivers/accel/amdxdna/amdxdna_gem.c
@@ -949,6 +949,9 @@ int amdxdna_drm_sync_bo_ioctl(struct drm
goto put_obj;
}
+ if (!args->size)
+ goto unpin;
+
if (is_import_bo(abo))
drm_clflush_sg(abo->base.sgt);
else if (abo->mem.kva)
@@ -958,6 +961,7 @@ int amdxdna_drm_sync_bo_ioctl(struct drm
else
drm_WARN(&xdna->ddev, 1, "Can not get flush memory");
+unpin:
amdxdna_gem_unpin(abo);
XDNA_DBG(xdna, "Sync bo %d offset 0x%llx, size 0x%llx\n",
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0063/1518] clk: qcom: Fix test_ctl_hi field for DEFAULT_EVO PLLs
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (61 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0062/1518] accel/amdxdna: return early from a zero-length flush Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0064/1518] ftrace: Take trace_array reference before accessing its ftrace_ops Greg Kroah-Hartman
` (935 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Imran Shaik, Konrad Dybcio,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Imran Shaik <imran.shaik@oss.qualcomm.com>
[ Upstream commit 830ead322c39c99bf972425b3c35323ec56c29de ]
CLK_ALPHA_PLL_TYPE_DEFAULT_EVO type PLLs do not have the PLL_TEST_CTL_U1
register, so clk_alpha_pll_configure() does not program test_ctl_hi1_val
for this PLL type.
The GCC PLL configurations for QCM2290, Shikra and SM6115 wrongly use
test_ctl_hi1_val instead of test_ctl_hi_val, deviating from the hardware
recommended settings. Fix them to use test_ctl_hi_val.
Fixes: 496d1a13d405 ("clk: qcom: Add Global Clock Controller driver for QCM2290")
Fixes: 01cf3e27824d ("clk: qcom: Add Global clock controller support on Qualcomm Shikra SoC")
Fixes: e88c533d8a2a ("clk: qcom: gcc-sm6115: Add missing PLL config properties")
Cc: stable@vger.kernel.org
Signed-off-by: Imran Shaik <imran.shaik@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260729-pll-test-ctrl-fixup-v1-1-246d79589380@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
[ Omitted gcc-shikra.c changes because the driver is absent from the target branch. ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/clk/qcom/gcc-qcm2290.c | 6 +++---
drivers/clk/qcom/gcc-sm6115.c | 6 +++---
2 files changed, 6 insertions(+), 6 deletions(-)
--- a/drivers/clk/qcom/gcc-qcm2290.c
+++ b/drivers/clk/qcom/gcc-qcm2290.c
@@ -116,7 +116,7 @@ static const struct alpha_pll_config gpl
.vco_mask = GENMASK(21, 20),
.main_output_mask = BIT(0),
.config_ctl_val = 0x4001055B,
- .test_ctl_hi1_val = 0x1,
+ .test_ctl_hi_val = 0x1,
};
static struct clk_alpha_pll gpll10 = {
@@ -148,7 +148,7 @@ static const struct alpha_pll_config gpl
.vco_mask = GENMASK(21, 20),
.main_output_mask = BIT(0),
.config_ctl_val = 0x4001055B,
- .test_ctl_hi1_val = 0x1,
+ .test_ctl_hi_val = 0x1,
};
static struct clk_alpha_pll gpll11 = {
@@ -309,7 +309,7 @@ static const struct alpha_pll_config gpl
.post_div_val = 0x1 << 8,
.post_div_mask = GENMASK(11, 8),
.config_ctl_val = 0x4001055B,
- .test_ctl_hi1_val = 0x1,
+ .test_ctl_hi_val = 0x1,
};
static struct clk_alpha_pll gpll8 = {
--- a/drivers/clk/qcom/gcc-sm6115.c
+++ b/drivers/clk/qcom/gcc-sm6115.c
@@ -120,7 +120,7 @@ static const struct alpha_pll_config gpl
.vco_mask = GENMASK(21, 20),
.main_output_mask = BIT(0),
.config_ctl_val = 0x4001055b,
- .test_ctl_hi1_val = 0x1,
+ .test_ctl_hi_val = 0x1,
.test_ctl_hi_mask = 0x1,
};
@@ -173,7 +173,7 @@ static const struct alpha_pll_config gpl
.vco_val = 0x2 << 20,
.vco_mask = GENMASK(21, 20),
.config_ctl_val = 0x4001055b,
- .test_ctl_hi1_val = 0x1,
+ .test_ctl_hi_val = 0x1,
.test_ctl_hi_mask = 0x1,
};
@@ -367,7 +367,7 @@ static const struct alpha_pll_config gpl
.post_div_val = 0x1 << 8,
.post_div_mask = GENMASK(11, 8),
.config_ctl_val = 0x4001055b,
- .test_ctl_hi1_val = 0x1,
+ .test_ctl_hi_val = 0x1,
.test_ctl_hi_mask = 0x1,
};
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0064/1518] ftrace: Take trace_array reference before accessing its ftrace_ops
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (62 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0063/1518] clk: qcom: Fix test_ctl_hi field for DEFAULT_EVO PLLs Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0065/1518] i3c: master: Do not treat master device as a duplicate target Greg Kroah-Hartman
` (934 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Breno Leitao, Steven Rostedt,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Steven Rostedt <rostedt@goodmis.org>
[ Upstream commit 9100191e5acb2e5ea2313f436667bb5fce129f47 ]
The trace instance files set_ftrace_filter and set_ftrace_notrace was
updated to work with specific trace instances (trace_arrays). The issue is
that when these files are opened, there is a small race window where it
will use the ftrace_ops from the inode->private pointer to get a reference
to the trace_array and then take its reference. The problem is that the
ftrace_ops itself could be freed. If the rmdir on the instance happens at
the same time the set_ftrace_filter file is opened, the rmdir could have
also freed the ftrace_ops and referencing it will cause a use-after-free
bug and crash the kernel.
Instead, pass in the trace_array as the file private data (NULL for the
top level instance), and then pass both the trace_array and the ftrace_ops
to the ftrace_regex_open() function. If the trace_array is NULL, then it
just uses the ftrace_ops without the need to take its reference (like
normal). If the ftrace_ops is NULL, that is only the case for the top
level instance and the global_ops can be used.
This allows the trace_array to have its reference incremented before
touching the ftrace_ops that could also be freed when the instance is.
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260828223901.29e26edb@robin
Fixes: 591dffdade9f0 ("ftrace: Allow for function tracing instance to filter functions")
Reported-by: Breno Leitao <leitao@debian.org>
Tested-by: Breno Leitao <leitao@debian.org>
Closes: https://lore.kernel.org/all/apGORjltZgAiAYHT@gmail.com/
Signed-off-by: Steven Rostedt <rostedt@goodmis.org>
[ retained kzalloc(sizeof(*iter), GFP_KERNEL) instead of kzalloc_obj(*iter). ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
include/linux/ftrace.h | 5 ++-
kernel/trace/ftrace.c | 57 ++++++++++++++++++++++++++---------------
kernel/trace/trace.h | 4 +-
kernel/trace/trace_functions.c | 2 -
kernel/trace/trace_stack.c | 2 -
5 files changed, 44 insertions(+), 26 deletions(-)
--- a/include/linux/ftrace.h
+++ b/include/linux/ftrace.h
@@ -797,8 +797,9 @@ unsigned long ftrace_get_addr_new(struct
unsigned long ftrace_get_addr_curr(struct dyn_ftrace *rec);
extern ftrace_func_t ftrace_trace_function;
+struct trace_array;
-int ftrace_regex_open(struct ftrace_ops *ops, int flag,
+int ftrace_regex_open(struct trace_array *tr, struct ftrace_ops *ops, int flag,
struct inode *inode, struct file *file);
ssize_t ftrace_filter_write(struct file *file, const char __user *ubuf,
size_t cnt, loff_t *ppos);
@@ -1008,7 +1009,7 @@ static inline unsigned long ftrace_locat
* have them defined when ftrace is not enabled, but these
* functions may still be called. Use a macro instead of inline.
*/
-#define ftrace_regex_open(ops, flag, inod, file) ({ -ENODEV; })
+#define ftrace_regex_open(tr, ops, flag, inode, file) ({ -ENODEV; })
#define ftrace_set_early_filter(ops, buf, enable) do { } while (0)
#define ftrace_set_filter_ip(ops, ip, remove, reset) ({ -ENODEV; })
#define ftrace_set_filter_ips(ops, ips, cnt, remove, reset) ({ -ENODEV; })
--- a/kernel/trace/ftrace.c
+++ b/kernel/trace/ftrace.c
@@ -4627,7 +4627,8 @@ ftrace_avail_addrs_open(struct inode *in
/**
* ftrace_regex_open - initialize function tracer filter files
- * @ops: The ftrace_ops that hold the hash filters
+ * @tr: The trace_array that holds the ftrace_ops [optional]
+ * @ops: The ftrace_ops that hold the hash filters [optional]
* @flag: The type of filter to process
* @inode: The inode, usually passed in to your open routine
* @file: The file, usually passed in to your open routine
@@ -4641,26 +4642,45 @@ ftrace_avail_addrs_open(struct inode *in
* tracing_lseek() should be used as the lseek routine, and
* release must call ftrace_regex_release().
*
+ * Note, If @tr is not NULL, its reference has to be taken before
+ * @ops may be referenced.
+ * If @ops is NULL and @tr is not, then @tr->ops is used.
+ * If @tr is NULL and @ops is not then @ops->private is uesd for @tr.
+ * If both @tr and @ops are NULL, then the &global_ops is
+ * to be used, and @tr will be the global_ops.private pointer.
+ *
* Returns: 0 on success or a negative errno value on failure
*/
int
-ftrace_regex_open(struct ftrace_ops *ops, int flag,
+ftrace_regex_open(struct trace_array *tr, struct ftrace_ops *ops, int flag,
struct inode *inode, struct file *file)
{
- struct ftrace_iterator *iter;
+ struct ftrace_iterator *iter = NULL;
struct ftrace_hash *hash;
struct list_head *mod_head;
- struct trace_array *tr = ops->private;
- int ret = -ENOMEM;
-
- ftrace_ops_init(ops);
+ int ret = -ENODEV;
if (unlikely(ftrace_disabled))
return -ENODEV;
+ if (!tr) {
+ if (!ops)
+ ops = &global_ops;
+ tr = ops->private;
+ }
+
if (tracing_check_open_get_tr(tr))
return -ENODEV;
+ if (!ops)
+ ops = tr->ops;
+
+ if (WARN_ON_ONCE(!ops))
+ goto out;
+
+ ftrace_ops_init(ops);
+
+ ret = -ENOMEM;
iter = kzalloc(sizeof(*iter), GFP_KERNEL);
if (!iter)
goto out;
@@ -4738,21 +4758,19 @@ ftrace_regex_open(struct ftrace_ops *ops
static int
ftrace_filter_open(struct inode *inode, struct file *file)
{
- struct ftrace_ops *ops = inode->i_private;
+ struct trace_array *tr = inode->i_private;
- /* Checks for tracefs lockdown */
- return ftrace_regex_open(ops,
- FTRACE_ITER_FILTER | FTRACE_ITER_DO_PROBES,
- inode, file);
+ return ftrace_regex_open(tr, NULL,
+ FTRACE_ITER_FILTER | FTRACE_ITER_DO_PROBES,
+ inode, file);
}
static int
ftrace_notrace_open(struct inode *inode, struct file *file)
{
- struct ftrace_ops *ops = inode->i_private;
+ struct trace_array *tr = inode->i_private;
- /* Checks for tracefs lockdown */
- return ftrace_regex_open(ops, FTRACE_ITER_NOTRACE,
+ return ftrace_regex_open(tr, NULL, FTRACE_ITER_NOTRACE,
inode, file);
}
@@ -7060,15 +7078,15 @@ static const struct file_operations ftra
};
#endif /* CONFIG_FUNCTION_GRAPH_TRACER */
-void ftrace_create_filter_files(struct ftrace_ops *ops,
+void ftrace_create_filter_files(struct trace_array *tr,
struct dentry *parent)
{
trace_create_file("set_ftrace_filter", TRACE_MODE_WRITE, parent,
- ops, &ftrace_filter_fops);
+ tr, &ftrace_filter_fops);
trace_create_file("set_ftrace_notrace", TRACE_MODE_WRITE, parent,
- ops, &ftrace_notrace_fops);
+ tr, &ftrace_notrace_fops);
}
/*
@@ -7093,7 +7111,6 @@ void ftrace_destroy_filter_files(struct
static __init int ftrace_init_dyn_tracefs(struct dentry *d_tracer)
{
-
trace_create_file("available_filter_functions", TRACE_MODE_READ,
d_tracer, NULL, &ftrace_avail_fops);
@@ -7106,7 +7123,7 @@ static __init int ftrace_init_dyn_tracef
trace_create_file("touched_functions", TRACE_MODE_READ,
d_tracer, NULL, &ftrace_touched_fops);
- ftrace_create_filter_files(&global_ops, d_tracer);
+ ftrace_create_filter_files(NULL, d_tracer);
#ifdef CONFIG_FUNCTION_GRAPH_TRACER
trace_create_file("set_graph_function", TRACE_MODE_WRITE, d_tracer,
--- a/kernel/trace/trace.h
+++ b/kernel/trace/trace.h
@@ -1255,7 +1255,7 @@ extern void clear_ftrace_function_probes
int register_ftrace_command(struct ftrace_func_command *cmd);
int unregister_ftrace_command(struct ftrace_func_command *cmd);
-void ftrace_create_filter_files(struct ftrace_ops *ops,
+void ftrace_create_filter_files(struct trace_array *tr,
struct dentry *parent);
void ftrace_destroy_filter_files(struct ftrace_ops *ops);
@@ -1278,11 +1278,11 @@ static inline void clear_ftrace_function
{
}
+#define ftrace_create_filter_files(tr, parent) do { } while (0)
/*
* The ops parameter passed in is usually undefined.
* This must be a macro.
*/
-#define ftrace_create_filter_files(ops, parent) do { } while (0)
#define ftrace_destroy_filter_files(ops) do { } while (0)
#endif /* CONFIG_FUNCTION_TRACER && CONFIG_DYNAMIC_FTRACE */
--- a/kernel/trace/trace_functions.c
+++ b/kernel/trace/trace_functions.c
@@ -101,7 +101,7 @@ int ftrace_create_function_files(struct
return ret;
}
- ftrace_create_filter_files(tr->ops, parent);
+ ftrace_create_filter_files(tr, parent);
return 0;
}
--- a/kernel/trace/trace_stack.c
+++ b/kernel/trace/trace_stack.c
@@ -499,7 +499,7 @@ stack_trace_filter_open(struct inode *in
struct ftrace_ops *ops = inode->i_private;
/* Checks for tracefs lockdown */
- return ftrace_regex_open(ops, FTRACE_ITER_FILTER,
+ return ftrace_regex_open(NULL, ops, FTRACE_ITER_FILTER,
inode, file);
}
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0065/1518] i3c: master: Do not treat master device as a duplicate target
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (63 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0064/1518] ftrace: Take trace_array reference before accessing its ftrace_ops Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0066/1518] i3c: master: Fix use-after-free of master->this Greg Kroah-Hartman
` (933 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Adrian Hunter, Frank Li,
Mukesh Savaliya, Alexandre Belloni, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Adrian Hunter <adrian.hunter@intel.com>
[ Upstream commit 4dc1b3eeba7991905a5b5b8129ebea51be7d87b7 ]
i3c_master_search_i3c_dev_duplicate() searches the bus for another I3C
device with the same PID as the reference device. The search can match
master->this, causing the controller itself to be returned as a
duplicate.
Since the controller is not a target device, it cannot be a duplicate of
one. Exclude master->this from matching so that the function only
returns real duplicate target devices.
Fixes: 3a379bbcea0a ("i3c: Add core I3C infrastructure")
Cc: stable@vger.kernel.org
Signed-off-by: Adrian Hunter <adrian.hunter@intel.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Acked-by: Mukesh Savaliya <mukesh.savaliya@oss.qualcomm.com>
Link: https://patch.msgid.link/20260807145638.168865-4-adrian.hunter@intel.com
Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
[ adjusted the duplicate-device comparison to match the older branch’s PID handling without nonzero-PID checks. ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i3c/master.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/drivers/i3c/master.c
+++ b/drivers/i3c/master.c
@@ -2295,7 +2295,8 @@ i3c_master_search_i3c_dev_duplicate(stru
struct i3c_dev_desc *i3cdev;
i3c_bus_for_each_i3cdev(&master->bus, i3cdev) {
- if (i3cdev != refdev && i3cdev->info.pid == refdev->info.pid)
+ if (i3cdev != refdev && i3cdev->info.pid == refdev->info.pid &&
+ i3cdev != master->this)
return i3cdev;
}
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0066/1518] i3c: master: Fix use-after-free of master->this
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (64 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0065/1518] i3c: master: Do not treat master device as a duplicate target Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0067/1518] mm/huge_memory: transfer the pmd dirty bit to the folio on zap Greg Kroah-Hartman
` (932 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Adrian Hunter, Frank Li,
Alexandre Belloni, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Adrian Hunter <adrian.hunter@intel.com>
[ Upstream commit feb0ed76601f3c2f91f08688c5a7d8b9d382f720 ]
sysfs attribute callbacks for the master controller device dereference
master->this. However, master->this is freed in
i3c_master_detach_free_devs() before the master device itself is
released.
As a result, sysfs accesses can dereference a freed master->this
pointer, leading to a use-after-free.
Keep master->this alive until i3c_masterdev_release(), which is called
after the master device and its sysfs state are being torn down. Do not
free master->this as part of the normal device detach path.
On the error path in i3c_master_set_info(), reset master->this and
bus.cur_master to NULL before freeing the allocated device.
Fixes: 3a379bbcea0a ("i3c: Add core I3C infrastructure")
Cc: stable@vger.kernel.org
Signed-off-by: Adrian Hunter <adrian.hunter@intel.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260807145638.168865-5-adrian.hunter@intel.com
Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
[ retained of_node_put(dev->of_node) instead of upstream’s fwnode_handle_put(dev->fwnode). ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/i3c/master.c | 17 +++++++++++------
1 file changed, 11 insertions(+), 6 deletions(-)
--- a/drivers/i3c/master.c
+++ b/drivers/i3c/master.c
@@ -799,6 +799,11 @@ static struct attribute *i3c_masterdev_a
};
ATTRIBUTE_GROUPS(i3c_masterdev);
+static void i3c_master_free_i3c_dev(struct i3c_dev_desc *dev)
+{
+ kfree(dev);
+}
+
static void i3c_masterdev_release(struct device *dev)
{
struct i3c_master_controller *master = dev_to_i3cmaster(dev);
@@ -811,6 +816,8 @@ static void i3c_masterdev_release(struct
i3c_bus_cleanup(bus);
of_node_put(dev->of_node);
+
+ i3c_master_free_i3c_dev(master->this);
}
static const struct device_type i3c_masterdev_type = {
@@ -1023,11 +1030,6 @@ static void i3c_device_release(struct de
kfree(i3cdev);
}
-static void i3c_master_free_i3c_dev(struct i3c_dev_desc *dev)
-{
- kfree(dev);
-}
-
static struct i3c_dev_desc *
i3c_master_alloc_i3c_dev(struct i3c_master_controller *master,
const struct i3c_device_info *info)
@@ -2046,6 +2048,8 @@ int i3c_master_set_info(struct i3c_maste
return 0;
err_free_dev:
+ master->bus.cur_master = NULL;
+ master->this = NULL;
i3c_master_free_i3c_dev(i3cdev);
return ret;
@@ -2066,7 +2070,8 @@ static void i3c_master_detach_free_devs(
i3cdev->boardinfo->init_dyn_addr,
I3C_ADDR_SLOT_FREE);
- i3c_master_free_i3c_dev(i3cdev);
+ if (i3cdev != master->this)
+ i3c_master_free_i3c_dev(i3cdev);
}
list_for_each_entry_safe(i2cdev, i2ctmp, &master->bus.devs.i2c,
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0067/1518] mm/huge_memory: transfer the pmd dirty bit to the folio on zap
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (65 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0066/1518] i3c: master: Fix use-after-free of master->this Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0068/1518] mm/mremap: reset unfaulted VMA page offset for MREMAP_DONTUNMAP Greg Kroah-Hartman
` (931 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Usama Arif, David Hildenbrand (Arm),
Kiryl Shutsemau, Hugh Dickins, Lance Yang, Zi Yan,
Lorenzo Stoakes (ARM), Baolin Wang, Barry Song, Dev Jain,
Johannes Weiner, Liam R. Howlett, Nhat Pham, Rik van Riel,
Ryan Roberts, Shakeel Butt, Andrew Morton, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Usama Arif <usama.arif@linux.dev>
[ Upstream commit fe6cf984939d8e12cb33a99673c8d026c5135e68 ]
zap_huge_pmd_folio() propagates the pmd young bit to the folio for the
file case, but not the dirty bit. The pte path does propagate it, in
zap_present_folio_ptes() and so does the pmd split path, in
__split_huge_pmd_locked().
For most file mappings the omission is harmless, because writing to a
shared file mapping goes through page_mkwrite(), which dirties the folio.
tmpfs is different: it has no page_mkwrite(), and vma_wants_writenotify()
is false for it, so a *read* fault on a MAP_SHARED tmpfs mapping installs
a writable pmd via do_read_fault(). do_read_fault() does not call
fault_dirty_shared_page(), so subsequent stores through that mapping set
only the hardware dirty bit in the pmd and never call folio_mark_dirty().
A shmem folio allocated by a fault is marked uptodate but not dirty (see
the clear: block in shmem_get_folio_gfp()), so PG_dirty is never set at
all.
Unmapping such a folio - munmap(), or exit_mmap() when the process dies -
then loses the only record that it was written, because zap_huge_pmd()
drops the pmd without transferring the dirty bit. Reclaim afterwards sees
a clean shmem folio: the whole swap-out block in shrink_folio_list() is
inside "if (folio_test_dirty(folio))", so pageout() is skipped and the
folio falls into __remove_mapping(). There, folio_is_file_lru() is false
for a swapbacked folio, so no shadow entry is created and
__filemap_remove_folio(folio, NULL) simply empties the i_pages slot. The
data is freed without ever being written to swap, and the next fault on
that index returns a freshly zeroed folio.
This is silent data loss for any process that keeps state in a MAP_SHARED
tmpfs segment across an unmap - for example a cache handed from one
process generation to the next through /dev/shm. It requires the folio to
be PMD-mapped, so it only shows up once shmem THP is enabled (which is
what we did in Meta fleet and started noticing crashes); with THP off the
pte path transfers the dirty bit correctly. It also only becomes visible
when swap is enabled, because with no swap device shmem folios (which are
on the anon LRU) are not scanned by reclaim at all, so the clean folio is
never dropped.
Reproduced on x86_64 with a tmpfs mounted huge=within_size: read-fault a
2MB-backed region, write a known pattern through the resulting mapping,
munmap, force reclaim of the cgroup, then re-map and read back. Without
this patch the region reads back as zeros and vmstat shows zswpout 0 - the
data was discarded rather than swapped. With this patch the region reads
back correctly and the pages are swapped out as expected. With
huge=never, or when the first touch is a write, the test passes either
way.
Link: https://lore.kernel.org/20260819101222.3732660-1-usama.arif@linux.dev
Fixes: b5072380eb61 ("thp: support file pages in zap_huge_pmd()")
Signed-off-by: Usama Arif <usama.arif@linux.dev>
Acked-by: David Hildenbrand (Arm) <david@kernel.org>
Reviewed-by: Kiryl Shutsemau <kas@kernel.org>
Acked-by: Hugh Dickins <hughd@google.com>
Tested-by: Lance Yang <lance.yang@linux.dev>
Reviewed-by: Zi Yan <ziy@nvidia.com>
Reviewed-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Reviewed-by: Baolin Wang <baolin.wang@linux.alibaba.com>
Cc: Barry Song <baohua@kernel.org>
Cc: Dev Jain <dev.jain@arm.com>
Cc: Johannes Weiner <hannes@cmpxchg.org>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Nhat Pham <nphamcs@gmail.com>
Cc: Rik van Riel <riel@surriel.com>
Cc: Ryan Roberts <ryan.roberts@arm.com>
Cc: Shakeel Butt <shakeel.butt@linux.dev>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/huge_memory.c | 2 ++
1 file changed, 2 insertions(+)
--- a/mm/huge_memory.c
+++ b/mm/huge_memory.c
@@ -2311,6 +2311,8 @@ int zap_huge_pmd(struct mmu_gather *tlb,
* Use flush_needed to indicate whether the PMD entry
* is present, instead of checking pmd_present() again.
*/
+ if (flush_needed && pmd_dirty(orig_pmd))
+ folio_mark_dirty(folio);
if (flush_needed && pmd_young(orig_pmd) &&
likely(vma_has_recency(vma)))
folio_mark_accessed(folio);
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0068/1518] mm/mremap: reset unfaulted VMA page offset for MREMAP_DONTUNMAP
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (66 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0067/1518] mm/huge_memory: transfer the pmd dirty bit to the folio on zap Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0069/1518] mm/secretmem: properly account locked pages Greg Kroah-Hartman
` (930 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Stoakes (ARM),
syzbot+f12658786a4153df5113, Vlastimil Babka (SUSE), Kunwu Chan,
Pedro Falcato, Jann Horn, Liam R. Howlett, Li Xinhai,
Andrew Morton, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: "Lorenzo Stoakes (ARM)" <ljs@kernel.org>
[ Upstream commit 35b0fb391b0df57383bc15985bb769f4555c97ba ]
Uniquely an mremap() invocation using the MREMAP_DONTUNMAP flag can reset
a faulted VMA into an unfaulted one.
It does so after the page tables have been moved to the copied VMA with
MREMAP_DONTUNMAP leaving the old VMA in place which is naturally unfaulted
as the page tables it had are no longer present.
However, in doing so, it violates the invariant that the anonymous page
offset of an unfaulted VMA is vma->vm_start >> PAGE_SHIFT.
This is because a VMA may have been faulted in, mremap()'d (causing a
delta between its page offset and vma->vm_start >> PAGE_SHIFT), and then
mremap()'d again with MREMAP_DONTUNMAP resulting in the unfaulting.
This condition is a violation of a fundamental assumption in mm, but now
also triggers an assert in assert_sane_pgoff() which explicitly checks for
this condition.
Correct it by resetting the VMA's page offset at the point of completing
the MREMAP_DONTUNMAP operation.
Link: https://lore.kernel.org/20260825-fix-mremap-dontunmap-pgoff-v1-1-39a40b2c98b3@kernel.org
Fixes: 1583aa278f5f ("mm: mremap: unlink anon_vmas when mremap with MREMAP_DONTUNMAP success")
Signed-off-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Reported-by: syzbot+f12658786a4153df5113@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/all/6a87853b.ae6ddae5.3da009.0023.GAE@google.com/
Tested-by: syzbot+f12658786a4153df5113@syzkaller.appspotmail.com
Acked-by: Vlastimil Babka (SUSE) <vbabka@kernel.org>
Reviewed-by: Kunwu Chan <kunwu.chan@gmail.com>
Reviewed-by: Pedro Falcato <pfalcato@suse.de>
Cc: Jann Horn <jannh@google.com>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Li Xinhai <lixinhai.lxh@gmail.com>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
[ adapted VMA page-offset helpers to use the branch’s single vm_pgoff field. ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/mremap.c | 21 ++++++++++++++++-----
1 file changed, 16 insertions(+), 5 deletions(-)
--- a/mm/mremap.c
+++ b/mm/mremap.c
@@ -1247,18 +1247,29 @@ static void dontunmap_complete(struct vm
{
unsigned long start = vrm->addr;
unsigned long end = vrm->addr + vrm->old_len;
- unsigned long old_start = vrm->vma->vm_start;
- unsigned long old_end = vrm->vma->vm_end;
+ struct vm_area_struct *vma = vrm->vma;
+ unsigned long old_start = vma->vm_start;
+ unsigned long old_end = vma->vm_end;
/* We always clear VM_LOCKED[ONFAULT] on the old VMA. */
- vm_flags_clear(vrm->vma, VM_LOCKED_MASK);
+ vm_flags_clear(vma, VM_LOCKED_MASK);
/*
* anon_vma links of the old vma is no longer needed after its page
* table has been moved.
*/
- if (new_vma != vrm->vma && start == old_start && end == old_end)
- unlink_anon_vmas(vrm->vma);
+ if (new_vma != vma && start == old_start && end == old_end) {
+ const pgoff_t pgoff_unfaulted = vma->vm_start >> PAGE_SHIFT;
+
+ unlink_anon_vmas(vma);
+ /*
+ * The VMA is now unfaulted and it is an invariant that
+ * unfaulted anonymous VMAs have page offset equal to
+ * vma->vm_start >> PAGE_SHIFT.
+ */
+ if (vma_is_anonymous(vma) && !vma->vm_file)
+ vma->vm_pgoff = pgoff_unfaulted;
+ }
/* Because we won't unmap we don't need to touch locked_vm. */
}
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0069/1518] mm/secretmem: properly account locked pages
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (67 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0068/1518] mm/mremap: reset unfaulted VMA page offset for MREMAP_DONTUNMAP Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0070/1518] mm: fix incorrect vm_flags usage when checking allowable orders for tmpfs Greg Kroah-Hartman
` (929 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Stoakes (ARM), Daehyeon Ko,
Mike Rapoport (Microsoft), David Hildenbrand (Arm),
Alexei Starovoitov, David S. Miller, Hagen Paul Pfeifer,
Jakub Kacinski, James Bottomley, Jesper Dangaard Brouer,
John Fastabend, Liam R. Howlett, Michal Hocko, Stanislav Fomichev,
Suren Baghdasaryan, Vlastimil Babka, Andrew Morton, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: "Lorenzo Stoakes (ARM)" <ljs@kernel.org>
[ Upstream commit 97d34aa65c29cca85e3e9050f4c936389b38a054 ]
secretmem accounts folios by treating memory as if it were mlock()'d and
thus limited by the RLIMIT_MEMLOCK limit.
However the folios are unevictable and remain so until the inode is
evicted, eliminating usual mlock() semantics - mapping folios then
unmapping them does not clear their unevictable state, since it depends on
AS_UNEVICTABLE, not PG_mlocked.
A user can therefore easily work around the RLIMIT_MEMLOCK limit - simply
map then unmap and VmLck no longer counts the secretmem range. Worse,
folios are not accounted in the process's RSS, meaning the OOM killer
won't know to kill the process.
Repeatedly mapping/unmapping (or forking) can then result in the
consumption of all available system memory with unevictable folios and
cause system instability.
A secretmem fd can be passed between processes and over fork so a
per-process limit simply does not make sense, so follow the precedent set
by io_uring, perf, skbuff, iommufd and xdp by tracking the number of
locked pages in user_struct->locked_vm.
Since the scope tracked is actually inode lifetime, the RLIMIT_MEMLOCK
applies per-user not per-process, so it doesn't make sense to bypass for
users with CAP_IPC_LOCK, therefore remove this bypass.
There is simply no reason to carry on marking the mapping as mlock()'d
since it's misleading and the lifecycle is now correctly handled, so
remove this too.
Note that secretmem does not support any form of truncation (including
hole punching) and the folios are unreclaimable, so the folios need only
be accounted on fault and unaccounted on inode destruction.
__secretmem_account_pages() is more or less a duplicate of the code that
io_uring etc. use, but since this is a bug fix that needs backporting,
defer any de-duplication efforts to a follow-up.
test_mlock_limit() asserts mlock_future_ok() on mmap(), however this has
been removed, so remove the test altogether for the fix. A new test will
be sent separately for upstream.
Link: https://lore.kernel.org/20260826-secretmem-accounting-v3-1-94cb04399510@kernel.org
Fixes: 1507f51255c9 ("mm: introduce memfd_secret system call to create "secret" memory areas")
Signed-off-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Reported-by: Daehyeon Ko <4ncienth@gmail.com>
Closes: https://lore.kernel.org/linux-mm/20260813225328.2010303-1-4ncienth@gmail.com/
Reviewed-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Acked-by: David Hildenbrand (Arm) <david@kernel.org>
Tested-by: Daehyeon Ko <4ncienth@gmail.com>
Cc: Alexei Starovoitov <ast@kernel.org>
Cc: David Hildenbrand <david@kernel.org>
Cc: David S. Miller <davem@davemloft.net>
Cc: Hagen Paul Pfeifer <hagen@jauu.net>
Cc: Jakub Kacinski <kuba@kernel.org>
Cc: James Bottomley <james.bottomley@HansenPartnership.com>
Cc: Jesper Dangaard Brouer <hawk@kernel.org>
Cc: John Fastabend <john.fastabend@gmail.com>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Michal Hocko <mhocko@suse.com>
Cc: Stanislav Fomichev <sdf@fomichev.me>
Cc: Suren Baghdasaryan <surenb@google.com>
Cc: Vlastimil Babka <vbabka@kernel.org>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
[ replaced newer VMA flag helpers with direct desc->vm_flags operations ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
include/linux/sched/user.h | 3
mm/secretmem.c | 117 +++++++++++++++++++++++++++---
tools/testing/selftests/mm/memfd_secret.c | 30 -------
3 files changed, 110 insertions(+), 40 deletions(-)
--- a/include/linux/sched/user.h
+++ b/include/linux/sched/user.h
@@ -25,7 +25,8 @@ struct user_struct {
#if defined(CONFIG_PERF_EVENTS) || defined(CONFIG_BPF_SYSCALL) || \
defined(CONFIG_NET) || defined(CONFIG_IO_URING) || \
- defined(CONFIG_VFIO_PCI_ZDEV_KVM) || IS_ENABLED(CONFIG_IOMMUFD)
+ defined(CONFIG_VFIO_PCI_ZDEV_KVM) || IS_ENABLED(CONFIG_IOMMUFD) || \
+ defined(CONFIG_SECRETMEM)
atomic_long_t locked_vm;
#endif
#ifdef CONFIG_WATCH_QUEUE
--- a/mm/secretmem.c
+++ b/mm/secretmem.c
@@ -18,6 +18,8 @@
#include <linux/secretmem.h>
#include <linux/set_memory.h>
#include <linux/sched/signal.h>
+#include <linux/sched/user.h>
+#include <linux/cred.h>
#include <uapi/linux/magic.h>
@@ -47,10 +49,69 @@ bool secretmem_active(void)
return !!atomic_read(&secretmem_users);
}
+struct secretmem_inode_state {
+ struct user_struct *user;
+ atomic_long_t nr_pages_accounted;
+};
+
+static bool __secretmem_account_pages(struct user_struct *user,
+ unsigned long nr_pages)
+{
+ unsigned long page_limit, cur_pages, new_pages;
+
+ if (!nr_pages)
+ return true;
+
+ page_limit = rlimit(RLIMIT_MEMLOCK) >> PAGE_SHIFT;
+
+ cur_pages = atomic_long_read(&user->locked_vm);
+ do {
+ new_pages = cur_pages + nr_pages;
+ if (new_pages > page_limit)
+ return false;
+ } while (!atomic_long_try_cmpxchg(&user->locked_vm,
+ &cur_pages, new_pages));
+ return true;
+}
+
+static bool secretmem_account_folio(struct secretmem_inode_state *state,
+ const struct folio *folio)
+{
+ const unsigned long nr_pages = folio_nr_pages(folio);
+
+ if (!__secretmem_account_pages(state->user, nr_pages))
+ return false;
+
+ atomic_long_add(nr_pages, &state->nr_pages_accounted);
+ return true;
+}
+
+static void __secretmem_unaccount_pages(struct secretmem_inode_state *state,
+ unsigned long nr_pages)
+{
+ atomic_long_sub(nr_pages, &state->user->locked_vm);
+ atomic_long_sub(nr_pages, &state->nr_pages_accounted);
+}
+
+static void secretmem_unaccount_folio(struct secretmem_inode_state *state,
+ struct folio *folio)
+{
+ __secretmem_unaccount_pages(state, folio_nr_pages(folio));
+}
+
+static void secretmem_unaccount_all_folios(struct secretmem_inode_state *state)
+{
+ const unsigned long nr_pages_accounted =
+ atomic_long_read(&state->nr_pages_accounted);
+
+ __secretmem_unaccount_pages(state, nr_pages_accounted);
+}
+
static vm_fault_t secretmem_fault(struct vm_fault *vmf)
{
struct address_space *mapping = vmf->vma->vm_file->f_mapping;
struct inode *inode = file_inode(vmf->vma->vm_file);
+ struct secretmem_inode_state *state = inode->i_private;
pgoff_t offset = vmf->pgoff;
gfp_t gfp = vmf->gfp_mask;
unsigned long addr;
@@ -72,8 +133,15 @@ retry:
goto out;
}
+ if (!secretmem_account_folio(state, folio)) {
+ folio_put(folio);
+ ret = VM_FAULT_SIGBUS;
+ goto out;
+ }
+
err = set_direct_map_invalid_noflush(folio_page(folio, 0));
if (err) {
+ secretmem_unaccount_folio(state, folio);
folio_put(folio);
ret = vmf_error(err);
goto out;
@@ -82,6 +150,7 @@ retry:
__folio_mark_uptodate(folio);
err = filemap_add_folio(mapping, folio, offset, gfp);
if (unlikely(err)) {
+ secretmem_unaccount_folio(state, folio);
/*
* If a split of large page was required, it
* already happened when we marked the page invalid
@@ -112,23 +181,30 @@ static const struct vm_operations_struct
.fault = secretmem_fault,
};
+static void secretmem_destroy_inode_priv(struct inode *inode)
+{
+ struct secretmem_inode_state *state = inode->i_private;
+
+ secretmem_unaccount_all_folios(state);
+ free_uid(state->user);
+ kfree(state);
+ inode->i_private = NULL;
+}
+
static int secretmem_release(struct inode *inode, struct file *file)
{
atomic_dec(&secretmem_users);
+ secretmem_destroy_inode_priv(inode);
+
return 0;
}
static int secretmem_mmap_prepare(struct vm_area_desc *desc)
{
- const unsigned long len = desc->end - desc->start;
-
if ((desc->vm_flags & (VM_SHARED | VM_MAYSHARE)) == 0)
return -EINVAL;
- if (!mlock_future_ok(desc->mm, desc->vm_flags | VM_LOCKED, len))
- return -EAGAIN;
-
- desc->vm_flags |= VM_LOCKED | VM_DONTDUMP;
+ desc->vm_flags |= VM_DONTDUMP;
desc->vm_ops = &secretmem_vm_ops;
return 0;
@@ -188,20 +264,40 @@ static const struct inode_operations sec
static struct vfsmount *secretmem_mnt;
+static int secretmem_init_inode_priv(struct inode *inode)
+{
+ struct secretmem_inode_state *state;
+
+ state = kzalloc_obj(*state);
+ if (!state)
+ return -ENOMEM;
+
+ state->user = get_uid(current_user());
+ inode->i_private = state;
+ return 0;
+}
+
static struct file *secretmem_file_create(unsigned long flags)
{
struct file *file;
struct inode *inode;
const char *anon_name = "[secretmem]";
+ int err;
inode = anon_inode_make_secure_inode(secretmem_mnt->mnt_sb, anon_name, NULL);
if (IS_ERR(inode))
return ERR_CAST(inode);
+ err = secretmem_init_inode_priv(inode);
+ if (err)
+ goto err_free_inode;
+
file = alloc_file_pseudo(inode, secretmem_mnt, "secretmem",
O_RDWR | O_LARGEFILE, &secretmem_fops);
- if (IS_ERR(file))
- goto err_free_inode;
+ if (IS_ERR(file)) {
+ err = PTR_ERR(file);
+ goto err_free_priv;
+ }
mapping_set_gfp_mask(inode->i_mapping, GFP_HIGHUSER);
mapping_set_unevictable(inode->i_mapping);
@@ -216,10 +312,11 @@ static struct file *secretmem_file_creat
atomic_inc(&secretmem_users);
return file;
-
+err_free_priv:
+ secretmem_destroy_inode_priv(inode);
err_free_inode:
iput(inode);
- return file;
+ return ERR_PTR(err);
}
SYSCALL_DEFINE1(memfd_secret, unsigned int, flags)
--- a/tools/testing/selftests/mm/memfd_secret.c
+++ b/tools/testing/selftests/mm/memfd_secret.c
@@ -57,33 +57,6 @@ static void test_file_apis(int fd)
pass("file IO is blocked as expected\n");
}
-static void test_mlock_limit(int fd)
-{
- size_t len;
- char *mem;
-
- len = mlock_limit_cur;
- if (len % page_size != 0)
- len = (len/page_size) * page_size;
-
- mem = mmap(NULL, len, prot, mode, fd, 0);
- if (mem == MAP_FAILED) {
- fail("unable to mmap secret memory\n");
- return;
- }
- munmap(mem, len);
-
- len = mlock_limit_max * 2;
- mem = mmap(NULL, len, prot, mode, fd, 0);
- if (mem != MAP_FAILED) {
- fail("unexpected mlock limit violation\n");
- munmap(mem, len);
- return;
- }
-
- pass("mlock limit is respected\n");
-}
-
static void test_vmsplice(int fd, const char *desc)
{
ssize_t transferred;
@@ -297,7 +270,7 @@ static void prepare(void)
strerror(errno));
}
-#define NUM_TESTS 6
+#define NUM_TESTS 5
int main(int argc, char *argv[])
{
@@ -319,7 +292,6 @@ int main(int argc, char *argv[])
if (ftruncate(fd, page_size))
ksft_exit_fail_msg("ftruncate failed: %s\n", strerror(errno));
- test_mlock_limit(fd);
test_file_apis(fd);
/*
* We have to run the first vmsplice test before any secretmem page was
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0070/1518] mm: fix incorrect vm_flags usage when checking allowable orders for tmpfs
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (68 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0069/1518] mm/secretmem: properly account locked pages Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0071/1518] perf/x86/intel: Remove anythread_deprecated bit from perf_capabilities Greg Kroah-Hartman
` (928 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Baolin Wang, Lance Yang,
Lorenzo Stoakes (ARM), Zi Yan, Barry Song, David Hildenbrand,
Dev Jain, Hugh Dickins, Liam R. Howlett, Ryan Roberts,
Vlastimil Babka, Andrew Morton, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Baolin Wang <baolin.wang@linux.alibaba.com>
[ Upstream commit 2fd4e7693674b17807a6d082feb01a3fbf86f5f8 ]
Lance reported that when nothing else causes the mm to be considered for
khugepaged collapse, an MADV_HUGEPAGE-advised tmpfs VMA alone does not
trigger scanning.
After commit 6beeab870e70 ("mm: shmem: move shmem_huge_global_enabled()
into shmem_allowable_huge_orders()"), the shmem/tmpfs allowable order
check reads vma->flags directly. However, when MADV_HUGEPAGE is handled,
khugepaged_enter_vma() is called before the VMA's flags have been updated,
so the check uses stale flags and incorrectly rejects the VMA for
collapse. As a result, khugepaged does not collapse the tmpfs file into
PMD order in time.
Fix this by calling khugepaged_enter_vma() with the new VMA flags in
madvise_update_vma(). Meanwhile we can remove the khugepaged_enter_vma()
in hugepage_madvise().
Link: https://lore.kernel.org/7d5b5eb27be798f89d563b06254c947ff53db0b2.1787020910.git.baolin.wang@linux.alibaba.com
Fixes: 6beeab870e70 ("mm: shmem: move shmem_huge_global_enabled() into shmem_allowable_huge_orders()")
Signed-off-by: Baolin Wang <baolin.wang@linux.alibaba.com>
Reported-by: Lance Yang <lance.yang@linux.dev>
Closes: https://lore.kernel.org/all/20260815181632.21453-1-lance.yang@linux.dev/
Suggested-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Reviewed-by: Zi Yan <ziy@nvidia.com>
Reviewed-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Cc: Barry Song <baohua@kernel.org>
Cc: David Hildenbrand <david@kernel.org>
Cc: Dev Jain <dev.jain@arm.com>
Cc: Hugh Dickins <hughd@google.com>
Cc: Lance Yang <lance.yang@linux.dev>
Cc: Liam R. Howlett <liam@infradead.org>
Cc: Ryan Roberts <ryan.roberts@arm.com>
Cc: Vlastimil Babka <vbabka@kernel.org>
Cc: <stable@vger.kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
[ adapted newer VMA flag APIs to the older scalar vm_flags_t interface. ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
mm/khugepaged.c | 6 ------
mm/madvise.c | 8 ++++++++
2 files changed, 8 insertions(+), 6 deletions(-)
--- a/mm/khugepaged.c
+++ b/mm/khugepaged.c
@@ -353,12 +353,6 @@ int hugepage_madvise(struct vm_area_stru
#endif
*vm_flags &= ~VM_NOHUGEPAGE;
*vm_flags |= VM_HUGEPAGE;
- /*
- * If the vma become good for khugepaged to scan,
- * register it here without waiting a page fault that
- * may not happen any time soon.
- */
- khugepaged_enter_vma(vma, *vm_flags);
break;
case MADV_NOHUGEPAGE:
*vm_flags &= ~VM_HUGEPAGE;
--- a/mm/madvise.c
+++ b/mm/madvise.c
@@ -177,6 +177,14 @@ static int madvise_update_vma(vm_flags_t
/* vm_flags is protected by the mmap_lock held in write mode. */
vma_start_write(vma);
vm_flags_reset(vma, new_flags);
+ /*
+ * If the vma become good for khugepaged to scan,
+ * register it here without waiting a page fault that
+ * may not happen any time soon.
+ */
+ if (new_flags & VM_HUGEPAGE)
+ khugepaged_enter_vma(vma, new_flags);
+
if (set_new_anon_name)
return replace_anon_vma_name(vma, anon_name);
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0071/1518] perf/x86/intel: Remove anythread_deprecated bit from perf_capabilities
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (69 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0070/1518] mm: fix incorrect vm_flags usage when checking allowable orders for tmpfs Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0072/1518] platform/x86/amd/pmc: Fix msg_port restoration in amd_stb_debugfs_open_v2() Greg Kroah-Hartman
` (927 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Namhyung Kim, Dapeng Mi,
Peter Zijlstra (Intel), Zide Chen, Thomas Falcon, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dapeng Mi <dapeng1.mi@linux.intel.com>
[ Upstream commit 8767b4d73018bd3143f4c55b672064fad292f11b ]
AnyThread mode deprecation is enumerated by CPUID.0AH:EDX[15] instead of
PERF_CAPABILITIES MSR. It's not a good practice to define a bit to
represent "anythread deprecation" in perf_capabilities. It leads to the
anythread_deprecated bit could be overwritten by the real value of
PERF_CAPABILITIES MSR, just like the below code in update_pmu_cap() does.
if (!intel_pmu_broken_perf_cap()) {
/* Perf Metric (Bit 15) and PEBS via PT (Bit 16) are hybrid enumeration */
rdmsrq(MSR_IA32_PERF_CAPABILITIES, hybrid(pmu, intel_cap).capabilities);
}
It leads to the anythread_deprecated bit is cleared to 0 and the "any"
attribute is incorrectly shown in the /sys/devices/cpu/format/ folder on
these support Perfmon v6 platforms, like Clearwater Forest.
$ grep . /sys/devices/cpu/format/*
/sys/devices/cpu/format/acr_mask:config2:0-63
/sys/devices/cpu/format/any:config:21
/sys/devices/cpu/format/cmask:config:24-31
So remove the anythread_deprecated bit from perf_capabilities structure
and directly depends on CPUID.0AH:EDX[15] to judge if anythread is
deprecated.
Fixes: cadbaa039b99 ("perf/x86/intel: Make anythread filter support conditional")
Reported-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Reviewed-by: Zide Chen <zide.chen@intel.com>
Reviewed-by: Thomas Falcon <thomas.falcon@intel.com>
Acked-by: Namhyung Kim <namhyung@kernel.org>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260616044654.3468742-2-dapeng1.mi@linux.intel.com
[ Adjusted hunk context for missing mediated-vPMU initialization code. ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/events/intel/core.c | 10 +++-------
arch/x86/events/perf_event.h | 2 +-
2 files changed, 4 insertions(+), 8 deletions(-)
--- a/arch/x86/events/intel/core.c
+++ b/arch/x86/events/intel/core.c
@@ -6975,12 +6975,6 @@ __init int intel_pmu_init(void)
x86_add_quirk(intel_arch_events_quirk); /* Install first, so it runs last */
- if (version >= 5) {
- x86_pmu.intel_cap.anythread_deprecated = edx.split.anythread_deprecated;
- if (x86_pmu.intel_cap.anythread_deprecated)
- pr_cont(" AnyThread deprecated, ");
- }
-
/*
* Many features on and after V6 require dynamic constraint,
* e.g., Arch PEBS, ACR.
@@ -7778,8 +7772,10 @@ __init int intel_pmu_init(void)
&x86_pmu.intel_ctrl);
/* AnyThread may be deprecated on arch perfmon v5 or later */
- if (x86_pmu.intel_cap.anythread_deprecated)
+ if (version >= 5 && edx.split.anythread_deprecated) {
x86_pmu.format_attrs = intel_arch_formats_attr;
+ pr_cont("AnyThread deprecated, ");
+ }
intel_pmu_check_event_constraints(x86_pmu.event_constraints,
x86_pmu.cntr_mask64,
--- a/arch/x86/events/perf_event.h
+++ b/arch/x86/events/perf_event.h
@@ -656,7 +656,7 @@ union perf_capabilities {
u64 perf_metrics:1;
u64 pebs_output_pt_available:1;
u64 pebs_timing_info:1;
- u64 anythread_deprecated:1;
+ u64 __reserved:1;
u64 rdpmc_metrics_clear:1;
};
u64 capabilities;
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0072/1518] platform/x86/amd/pmc: Fix msg_port restoration in amd_stb_debugfs_open_v2()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (70 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0071/1518] perf/x86/intel: Remove anythread_deprecated bit from perf_capabilities Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0073/1518] platform/x86: hp-wmi: Add support for OMEN MAX 16-ak0xxx (8DD6) Greg Kroah-Hartman
` (926 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mario Limonciello,
Ilpo Järvinen, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mario Limonciello <mario.limonciello@amd.com>
[ Upstream commit cbb32ff92f8a62212e0f7384b1de986ced92082b ]
amd_stb_debugfs_open_v2() switches dev->msg_port to MSG_PORT_S2D to query
S2D telemetry but only restores it to MSG_PORT_PMC on one path. The early
return on the dump_custom_stb path (and the error/allocation returns) leave
the port stuck on MSG_PORT_S2D, so subsequent SMU communication - including
the s2idle prepare/restore handlers - is directed at the wrong mailbox.
Consolidate the exit path through a single label so the message port is
always restored, mirroring the fix in amd_stb_s2d_init().
Reported-by: sashiko.dev
Link: https://sashiko.dev/#/patchset/20260717162023.956346-1-mario.limonciello%40amd.com
Fixes: 2851f4f8ed4e ("platform/x86/amd/pmc: Define enum for S2D/PMC msg_port and add helper function")
Cc: stable@vger.kernel.org
Signed-off-by: Mario Limonciello <mario.limonciello@amd.com>
Link: https://patch.msgid.link/20260721181756.143084-3-mario.limonciello@amd.com
Reviewed-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
[ adjusted allocation context to retain kmalloc(struct_size(...), GFP_KERNEL) instead of kmalloc_flex() ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/platform/x86/amd/pmc/mp1_stb.c | 23 ++++++++++++++---------
1 file changed, 14 insertions(+), 9 deletions(-)
--- a/drivers/platform/x86/amd/pmc/mp1_stb.c
+++ b/drivers/platform/x86/amd/pmc/mp1_stb.c
@@ -157,7 +157,7 @@ static int amd_stb_debugfs_open_v2(struc
struct amd_pmc_dev *dev = filp->f_inode->i_private;
u32 fsize, num_samples, val, stb_rdptr_offset = 0;
struct amd_stb_v2_data *stb_data_arr;
- int ret;
+ int ret = 0;
/* Write dummy postcode while reading the STB buffer */
ret = amd_stb_write(dev, AMD_PMC_STB_DUMMY_PC);
@@ -176,22 +176,24 @@ static int amd_stb_debugfs_open_v2(struc
* the enhanced dram size. Note that we land here only for the
* platforms that support enhanced dram size reporting.
*/
- if (dump_custom_stb)
- return amd_stb_handle_efr(filp);
+ if (dump_custom_stb) {
+ ret = amd_stb_handle_efr(filp);
+ goto out;
+ }
/* Get the num_samples to calculate the last push location */
ret = amd_pmc_send_cmd(dev, S2D_NUM_SAMPLES, &num_samples, dev->stb_arg.s2d_msg_id, true);
- /* Clear msg_port for other SMU operation */
- dev->msg_port = MSG_PORT_PMC;
if (ret) {
dev_err(dev->dev, "error: S2D_NUM_SAMPLES not supported : %d\n", ret);
- return ret;
+ goto out;
}
fsize = min(num_samples, S2D_TELEMETRY_BYTES_MAX);
stb_data_arr = kmalloc(struct_size(stb_data_arr, data, fsize), GFP_KERNEL);
- if (!stb_data_arr)
- return -ENOMEM;
+ if (!stb_data_arr) {
+ ret = -ENOMEM;
+ goto out;
+ }
stb_data_arr->size = fsize;
@@ -214,7 +216,10 @@ static int amd_stb_debugfs_open_v2(struc
filp->private_data = stb_data_arr;
- return 0;
+out:
+ /* Restore the default message port for subsequent SMU operations */
+ dev->msg_port = MSG_PORT_PMC;
+ return ret;
}
static ssize_t amd_stb_debugfs_read_v2(struct file *filp, char __user *buf, size_t size,
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0073/1518] platform/x86: hp-wmi: Add support for OMEN MAX 16-ak0xxx (8DD6)
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (71 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0072/1518] platform/x86/amd/pmc: Fix msg_port restoration in amd_stb_debugfs_open_v2() Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0074/1518] staging: sm750fb: fix mono image source stride mismatch in lynxfb_ops_imageblit() Greg Kroah-Hartman
` (925 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yahia Ahmed, Krishna Chomal,
Ilpo Järvinen, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Krishna Chomal <krishna.chomal108@gmail.com>
[ Upstream commit a7320d6eb9c4240c948cd9c64582b3bd04cbaf4b ]
The HP OMEN MAX 16-ak0xxx (board ID: 8DD6) has the same WMI interface
as other Victus S boards, but requires quirks for correctly switching
thermal profile.
After testing we know that (similar to another HP Omen Max 16 device,
board ID 8D87), the embedded controller on this board does not expose
thermal profile which means we have to intentionally disable EC readback.
Add the DMI board name to victus_s_thermal_profile_boards[] table and
map it to omen_v1_no_ec_thermal_params.
Testing on board 8DD6 confirmed that platform profile is registered
successfully and fan RPMs are readable and controllable.
Tested-by: Yahia Ahmed <yahmedd043@gmail.com>
Cc: stable@vger.kernel.org # v6.18+
Signed-off-by: Krishna Chomal <krishna.chomal108@gmail.com>
Link: https://patch.msgid.link/20260623141314.33947-1-krishna.chomal108@gmail.com
Reviewed-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
[ adapted the board entry to the older victus_s_thermal_profile_boards table using omen_v1_thermal_params. ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/platform/x86/hp/hp-wmi.c | 4 ++++
1 file changed, 4 insertions(+)
--- a/drivers/platform/x86/hp/hp-wmi.c
+++ b/drivers/platform/x86/hp/hp-wmi.c
@@ -194,6 +194,10 @@ static const struct dmi_system_id victus
.matches = { DMI_MATCH(DMI_BOARD_NAME, "8D41") },
.driver_data = (void *)&victus_s_thermal_params,
},
+ {
+ .matches = { DMI_MATCH(DMI_BOARD_NAME, "8DD6") },
+ .driver_data = (void *)&omen_v1_thermal_params,
+ },
{},
};
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0074/1518] staging: sm750fb: fix mono image source stride mismatch in lynxfb_ops_imageblit()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (72 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0073/1518] platform/x86: hp-wmi: Add support for OMEN MAX 16-ak0xxx (8DD6) Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0075/1518] tracing/probes: Fix anon_stack check for unnamed bitfields in btf_find_struct_member Greg Kroah-Hartman
` (924 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dan Carpenter, Muhammad Bilal,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Muhammad Bilal <meatuni001@gmail.com>
[ Upstream commit cc7cd2a9228175c975f62ad56ed7c767701cb4fa ]
sm750_hw_imageblit() advances its monochrome source pointer by
src_delta per scanline, and computes the correct rounded-up stride
internally as:
bytes_per_scan = (width + start_bit + 7) / 8;
Its only caller, lynxfb_ops_imageblit(), instead passed src_delta as
image->width >> 3. For widths not a multiple of 8 this under-counted
the stride, so the source pointer fell further behind the real
per-scanline layout on every line, corrupting the rendered image.
Rather than just fixing the caller's calculation, remove src_delta
as a parameter entirely and have sm750_hw_imageblit() advance by the
bytes_per_scan it already computes for itself. There has only ever
been one caller, and that caller was passing an out-of-sync
derivative of the same width/start_bit values sm750_hw_imageblit()
already has, so keeping stride as a separate parameter served no
purpose beyond letting the two calculations drift apart, which is
exactly what happened here.
Rounding up, rather than down, is the direction consistent with the
rest of the fbdev core: struct fb_image mono bitmap data (the same
image->data this driver receives) is walked elsewhere with byte
strides derived from a ceiling division of width by 8. The generic
mono bit iterator in drivers/video/fbdev/core/fb_imageblit.h advances
scanlines with "iter->data += BITS_TO_BYTES(iter->width)", and
BITS_TO_BYTES() (include/linux/bitops.h) is a ceiling division.
sm750_hw_imageblit()'s own "(width + start_bit + 7) / 8" is that same
ceiling division with an added start_bit offset, so the caller's
">> 3" (floor) was the one calculation out of step with how this data
layout is handled everywhere else.
Found by code review of sm750_hw_imageblit()'s internal stride
calculation against what its only caller was passing in, and
confirmed with a clean -Werror build. I do not have this hardware,
so this has not been exercised at runtime on real sm750 silicon.
Fixes: 81dee67e215b2 ("staging: sm750fb: add sm750 to staging")
Cc: stable@vger.kernel.org
Reviewed-by: Dan Carpenter <error27@gmail.com>
Signed-off-by: Muhammad Bilal <meatuni001@gmail.com>
Link: https://patch.msgid.link/20260901113031.161610-1-meatuni001@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[ Adapted the patch to the older sm750fb variable names. ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/staging/sm750fb/sm750.c | 2 +-
drivers/staging/sm750fb/sm750.h | 2 +-
drivers/staging/sm750fb/sm750_accel.c | 6 ++----
drivers/staging/sm750fb/sm750_accel.h | 4 +---
4 files changed, 5 insertions(+), 9 deletions(-)
--- a/drivers/staging/sm750fb/sm750.c
+++ b/drivers/staging/sm750fb/sm750.c
@@ -273,7 +273,7 @@ static void lynxfb_ops_imageblit(struct
spin_lock(&sm750_dev->slock);
sm750_dev->accel.de_imageblit(&sm750_dev->accel,
- image->data, image->width >> 3, 0,
+ image->data, 0,
base, pitch, bpp,
image->dx, image->dy,
image->width, image->height,
--- a/drivers/staging/sm750fb/sm750.h
+++ b/drivers/staging/sm750fb/sm750.h
@@ -73,7 +73,7 @@ struct lynx_accel {
u32 rop2);
int (*de_imageblit)(struct lynx_accel *accel, const char *p_srcbuf,
- u32 src_delta, u32 start_bit, u32 d_base, u32 d_pitch,
+ u32 start_bit, u32 d_base, u32 d_pitch,
u32 byte_per_pixel, u32 dx, u32 dy, u32 width,
u32 height, u32 f_color, u32 b_color, u32 rop2);
--- a/drivers/staging/sm750fb/sm750_accel.c
+++ b/drivers/staging/sm750fb/sm750_accel.c
@@ -300,8 +300,6 @@ static unsigned int deGetTransparency(st
* sm750_hw_imageblit
* @accel: Acceleration device data
* @pSrcbuf: pointer to start of source buffer in system memory
- * @srcDelta: Pitch value (in bytes) of the source buffer, +ive means top down
- * and -ive mean button up
* @startBit: Mono data can start at any bit in a byte, this value should be
* 0 to 7
* @dBase: Address of destination: offset in frame buffer
@@ -316,7 +314,7 @@ static unsigned int deGetTransparency(st
* @rop2: ROP value
*/
int sm750_hw_imageblit(struct lynx_accel *accel, const char *pSrcbuf,
- u32 srcDelta, u32 startBit, u32 dBase, u32 dPitch,
+ u32 startBit, u32 dBase, u32 dPitch,
u32 bytePerPixel, u32 dx, u32 dy, u32 width,
u32 height, u32 fColor, u32 bColor, u32 rop2)
{
@@ -405,7 +403,7 @@ int sm750_hw_imageblit(struct lynx_accel
write_dpPort(accel, *(unsigned int *)ajRemain);
}
- pSrcbuf += srcDelta;
+ pSrcbuf += ulBytesPerScan;
}
return 0;
--- a/drivers/staging/sm750fb/sm750_accel.h
+++ b/drivers/staging/sm750fb/sm750_accel.h
@@ -220,8 +220,6 @@ int sm750_hw_copyarea(struct lynx_accel
/**
* sm750_hw_imageblit
* @pSrcbuf: pointer to start of source buffer in system memory
- * @srcDelta: Pitch value (in bytes) of the source buffer, +ive means top down
- *>----- and -ive mean button up
* @startBit: Mono data can start at any bit in a byte, this value should be
*>----- 0 to 7
* @dBase: Address of destination: offset in frame buffer
@@ -236,7 +234,7 @@ int sm750_hw_copyarea(struct lynx_accel
* @rop2: ROP value
*/
int sm750_hw_imageblit(struct lynx_accel *accel, const char *pSrcbuf,
- u32 srcDelta, u32 startBit, u32 dBase, u32 dPitch,
+ u32 startBit, u32 dBase, u32 dPitch,
u32 bytePerPixel, u32 dx, u32 dy, u32 width,
u32 height, u32 fColor, u32 bColor, u32 rop2);
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0075/1518] tracing/probes: Fix anon_stack check for unnamed bitfields in btf_find_struct_member
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (73 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0074/1518] staging: sm750fb: fix mono image source stride mismatch in lynxfb_ops_imageblit() Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0076/1518] usb: cdnsp: fix wakeup from S3 after controller context loss Greg Kroah-Hartman
` (923 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Masami Hiramatsu (Google),
Steven Rostedt, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: "Masami Hiramatsu (Google)" <mhiramat@kernel.org>
[ Upstream commit f36d94a20ca185bcadef3a10b980cd2cfd72d53a ]
btf_find_struct_member() traverses into nested anonymous structures
and unions by pushing members with !member->name_off onto anon_stack.
However, it does not consider the unnamed bitfields (e.g. `int : 5`
or `unsigned int : 0`) which also have member->name_off == 0.
If such an unnamed bitfield is pushed to anon_stack, the
btf_find_struct_member() return an error even if there are other
valid entries in anon_stack.
To fix this, only push unnamed struct/union members to anon_stack.
Also move the btf_type_is_struct() check to the entry of this function
because now it is sure only struct/union are pushed to anon_stack.
Link: https://lore.kernel.org/all/178827249775.123716.7813217688423513612.stgit@devnote2/
Fixes: 302db0f5b3d8 ("tracing/probes: Add a function to search a member of a struct/union")
Cc: stable@vger.kernel.org
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/all/20260830143859.D56991F00A3D@smtp.kernel.org/
Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Reviewed-by: Steven Rostedt <rostedt@goodmis.org>
[ retained the existing kcalloc() allocation instead of upstream’s kzalloc_objs() call. ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
kernel/trace/trace_btf.c | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
--- a/kernel/trace/trace_btf.c
+++ b/kernel/trace/trace_btf.c
@@ -75,24 +75,24 @@ const struct btf_member *btf_find_struct
{
struct btf_anon_stack *anon_stack;
const struct btf_member *member;
+ const struct btf_type *mtype;
u32 tid, cur_offset = 0;
const char *name;
int i, top = 0;
+ if (!btf_type_is_struct(type))
+ return ERR_PTR(-EINVAL);
+
anon_stack = kcalloc(BTF_ANON_STACK_MAX, sizeof(*anon_stack), GFP_KERNEL);
if (!anon_stack)
return ERR_PTR(-ENOMEM);
retry:
- if (!btf_type_is_struct(type)) {
- member = ERR_PTR(-EINVAL);
- goto out;
- }
-
for_each_member(i, type, member) {
if (!member->name_off) {
/* Anonymous union/struct: push it for later use */
- if (btf_type_skip_modifiers(btf, member->type, &tid) &&
+ mtype = btf_type_skip_modifiers(btf, member->type, &tid);
+ if (mtype && btf_type_is_struct(mtype) &&
top < BTF_ANON_STACK_MAX) {
anon_stack[top].tid = tid;
anon_stack[top++].offset = cur_offset +
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0076/1518] usb: cdnsp: fix wakeup from S3 after controller context loss
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (74 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0075/1518] tracing/probes: Fix anon_stack check for unnamed bitfields in btf_find_struct_member Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0077/1518] usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers() Greg Kroah-Hartman
` (922 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, stable, Pawel Laszczak, Peter Chen,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pawel Laszczak <pawell@cadence.com>
[ Upstream commit eae6460f617382044c5afe5ef202f4d8b2c099b5 ]
CDNSP controller may lose its runtime register programming across S3
suspend/resume, depending on SoC power domain configuration. After
resume the operational and interrupter registers may contain reset
values, which prevents the gadget side from recovering correctly and
breaks wakeup from S3.
Fix this by detecting whether the controller lost its register context
after resume and handling both cases:
- If context was lost (CFG_3XPORT_U1_PIPE_CLK_GATE_EN set or power
lost): reset the controller and reprogram the state required for
normal operation, including the command ring, DCBAA pointer, doorbell
base, event ring, ERST base/size and event ring dequeue pointer.
- If context was retained: restart the controller directly without
reprogramming registers. Issue a wakeup if the link was in U3 before
suspend.
Move the basic controller register programming out of the one-time memory
initialization path and make it reusable from the resume path. Also
separate ring allocation from ring initialization so that rings can be
reinitialized without reallocating DMA memory.
Always perform the full suspend sequence regardless of the current link
state. Previously, if the device was already in U3, the suspend callback
returned early without stopping the controller, which could lead to
commands being issued on a disabled slot during resume.
Fixes: 3d82904559f4 ("usb: cdnsp: cdns3 Add main part of Cadence USBSSP DRD Driver")
Cc: stable <stable@kernel.org>
Signed-off-by: Pawel Laszczak <pawell@cadence.com>
Acked-by: Peter Chen <peter.chen@kernel.org>
Link: https://patch.msgid.link/20260820-suspend_resume_fix-v3-1-5a713098b977@cadence.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[ Omitted the blank-line deletion in cdnsp_run() to preserve the existing USB2 register write. ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/usb/cdns3/cdnsp-gadget.c | 110 +++++++++++++++++++++++++++++++++++++--
drivers/usb/cdns3/cdnsp-gadget.h | 1
drivers/usb/cdns3/cdnsp-mem.c | 98 ++++++++++++----------------------
3 files changed, 142 insertions(+), 67 deletions(-)
--- a/drivers/usb/cdns3/cdnsp-gadget.c
+++ b/drivers/usb/cdns3/cdnsp-gadget.c
@@ -1820,6 +1820,82 @@ static void cdnsp_get_rev_cap(struct cdn
readl(&pdev->rev_cap->tx_buff_size));
}
+static void cdnsp_set_event_deq(struct cdnsp_device *pdev)
+{
+ dma_addr_t deq;
+ u64 temp;
+
+ deq = cdnsp_trb_virt_to_dma(pdev->event_ring->deq_seg,
+ pdev->event_ring->dequeue);
+
+ /* Update controller event ring dequeue pointer */
+ temp = cdnsp_read_64(&pdev->ir_set->erst_dequeue);
+ temp &= ERST_PTR_MASK;
+
+ /*
+ * Don't clear the EHB bit (which is RW1C) because
+ * there might be more events to service.
+ */
+ temp &= ~ERST_EHB;
+
+ cdnsp_write_64(((u64)deq & (u64)~ERST_PTR_MASK) | temp,
+ &pdev->ir_set->erst_dequeue);
+}
+
+static void cdnsp_add_interrupter(struct cdnsp_device *pdev)
+{
+ u64 erst_base;
+ u32 erst_size;
+
+ /* Set ERST count with the number of entries in the segment table. */
+ erst_size = readl(&pdev->ir_set->erst_size);
+ erst_size &= ERST_SIZE_MASK;
+ erst_size |= ERST_NUM_SEGS;
+ writel(erst_size, &pdev->ir_set->erst_size);
+
+ /* Set the segment table base address. */
+ erst_base = cdnsp_read_64(&pdev->ir_set->erst_base);
+ erst_base &= ERST_PTR_MASK;
+ erst_base |= (pdev->erst.erst_dma_addr & (u64)~ERST_PTR_MASK);
+ cdnsp_write_64(erst_base, &pdev->ir_set->erst_base);
+
+ /* Set the event ring dequeue address. */
+ cdnsp_set_event_deq(pdev);
+}
+
+/* Set up basic CDNSP registers */
+static void cdnsp_init(struct cdnsp_device *pdev)
+{
+ unsigned int val;
+ u64 val_64;
+
+ val = readl(&pdev->op_regs->config_reg);
+ val |= ((val & ~MAX_DEVS) | CDNSP_DEV_MAX_SLOTS) | CONFIG_U3E;
+ writel(val, &pdev->op_regs->config_reg);
+
+ /* Initialize the Command ring */
+ cdnsp_ring_init(pdev, pdev->cmd_ring);
+
+ /* Set the address in the Command Ring Control register */
+ val_64 = cdnsp_read_64(&pdev->op_regs->cmd_ring);
+ val_64 = (val_64 & (u64)CMD_RING_RSVD_BITS) |
+ (pdev->cmd_ring->first_seg->dma & (u64)~CMD_RING_RSVD_BITS) |
+ pdev->cmd_ring->cycle_state;
+ cdnsp_write_64(val_64, &pdev->op_regs->cmd_ring);
+
+ /* Set Device Context Base Address Array pointer */
+ cdnsp_write_64(pdev->dcbaa->dma, &pdev->op_regs->dcbaa_ptr);
+
+ /* Set Doorbell array pointer */
+ val = readl(&pdev->cap_regs->db_off);
+ val &= DBOFF_MASK;
+ pdev->dba = (void __iomem *)pdev->cap_regs + val;
+
+ /* Initialize the Primary interrupter */
+ cdnsp_ring_init(pdev, pdev->event_ring);
+ cdnsp_add_interrupter(pdev);
+}
+
static int cdnsp_gen_setup(struct cdnsp_device *pdev)
{
int ret;
@@ -1885,6 +1961,8 @@ static int cdnsp_gen_setup(struct cdnsp_
if (ret)
return ret;
+ cdnsp_init(pdev);
+
/*
* Software workaround for U1: after transition
* to U1 the controller starts gating clock, and in some cases,
@@ -2015,9 +2093,6 @@ static int cdnsp_gadget_suspend(struct c
struct cdnsp_device *pdev = cdns->gadget_dev;
unsigned long flags;
- if (pdev->link_state == XDEV_U3)
- return 0;
-
spin_lock_irqsave(&pdev->lock, flags);
cdnsp_disconnect_gadget(pdev);
cdnsp_stop(pdev);
@@ -2031,12 +2106,38 @@ static int cdnsp_gadget_resume(struct cd
struct cdnsp_device *pdev = cdns->gadget_dev;
enum usb_device_speed max_speed;
unsigned long flags;
+ bool context_lost;
+ u32 val;
int ret;
if (!pdev->gadget_driver)
return 0;
spin_lock_irqsave(&pdev->lock, flags);
+ val = readl(&pdev->port3x_regs->mode_2);
+ context_lost = !!(val & CFG_3XPORT_U1_PIPE_CLK_GATE_EN) || lost_power;
+
+ if (context_lost) {
+ cdnsp_halt(pdev);
+ cdnsp_set_apb_timeout_value(pdev);
+
+ /* Reset the internal controller memory state and registers. */
+ ret = cdnsp_reset(pdev);
+ if (ret)
+ goto unlock;
+
+ val = readl(&pdev->port3x_regs->mode_2);
+ val &= ~CFG_3XPORT_U1_PIPE_CLK_GATE_EN;
+ writel(val, &pdev->port3x_regs->mode_2);
+
+ cdnsp_clear_cmd_ring(pdev);
+
+ memset(pdev->event_ring->first_seg->trbs, 0,
+ sizeof(union cdnsp_trb) * (TRBS_PER_SEGMENT));
+
+ cdnsp_init(pdev);
+ }
+
max_speed = pdev->gadget_driver->max_speed;
/* Limit speed if necessary. */
@@ -2044,9 +2145,10 @@ static int cdnsp_gadget_resume(struct cd
ret = cdnsp_run(pdev, max_speed);
- if (pdev->link_state == XDEV_U3)
+ if (!context_lost && pdev->link_state == XDEV_U3)
__cdnsp_gadget_wakeup(pdev);
+unlock:
spin_unlock_irqrestore(&pdev->lock, flags);
return ret;
--- a/drivers/usb/cdns3/cdnsp-gadget.h
+++ b/drivers/usb/cdns3/cdnsp-gadget.h
@@ -1509,6 +1509,7 @@ int cdnsp_endpoint_init(struct cdnsp_dev
int cdnsp_ring_expansion(struct cdnsp_device *pdev,
struct cdnsp_ring *ring,
unsigned int num_trbs, gfp_t flags);
+void cdnsp_ring_init(struct cdnsp_device *pdev, struct cdnsp_ring *ring);
struct cdnsp_ring *cdnsp_dma_to_transfer_ring(struct cdnsp_ep *ep, u64 address);
int cdnsp_alloc_stream_info(struct cdnsp_device *pdev,
struct cdnsp_ep *pep,
--- a/drivers/usb/cdns3/cdnsp-mem.c
+++ b/drivers/usb/cdns3/cdnsp-mem.c
@@ -394,13 +394,6 @@ static struct cdnsp_ring *cdnsp_ring_all
if (ret)
goto fail;
- /* Only event ring does not use link TRB. */
- if (type != TYPE_EVENT)
- ring->last_seg->trbs[TRBS_PER_SEGMENT - 1].link.control |=
- cpu_to_le32(LINK_TOGGLE);
-
- cdnsp_initialize_ring_info(ring);
- trace_cdnsp_ring_alloc(ring);
return ring;
fail:
kfree(ring);
@@ -604,6 +597,7 @@ int cdnsp_alloc_stream_info(struct cdnsp
if (!cur_ring)
goto cleanup_rings;
+ cdnsp_ring_init(pdev, cur_ring);
cur_ring->stream_id = cur_stream;
cur_ring->trb_address_map = &stream_info->trb_address_map;
@@ -699,6 +693,8 @@ static int cdnsp_alloc_priv_device(struc
if (!pdev->eps[0].ring)
goto fail;
+ cdnsp_ring_init(pdev, pdev->eps[0].ring);
+
/* Point to output device context in dcbaa. */
pdev->dcbaa->dev_context_ptrs[1] = cpu_to_le64(pdev->out_ctx.dma);
pdev->cmd.in_ctx = &pdev->in_ctx;
@@ -992,6 +988,8 @@ int cdnsp_endpoint_init(struct cdnsp_dev
if (!pep->ring)
return -ENOMEM;
+ cdnsp_ring_init(pdev, pep->ring);
+
pep->skip = false;
/* Fill the endpoint context */
@@ -1099,28 +1097,6 @@ void cdnsp_mem_cleanup(struct cdnsp_devi
pdev->active_port = NULL;
}
-static void cdnsp_set_event_deq(struct cdnsp_device *pdev)
-{
- dma_addr_t deq;
- u64 temp;
-
- deq = cdnsp_trb_virt_to_dma(pdev->event_ring->deq_seg,
- pdev->event_ring->dequeue);
-
- /* Update controller event ring dequeue pointer */
- temp = cdnsp_read_64(&pdev->ir_set->erst_dequeue);
- temp &= ERST_PTR_MASK;
-
- /*
- * Don't clear the EHB bit (which is RW1C) because
- * there might be more events to service.
- */
- temp &= ~ERST_EHB;
-
- cdnsp_write_64(((u64)deq & (u64)~ERST_PTR_MASK) | temp,
- &pdev->ir_set->erst_dequeue);
-}
-
static void cdnsp_add_in_port(struct cdnsp_device *pdev,
struct cdnsp_port *port,
__le32 __iomem *addr)
@@ -1200,6 +1176,36 @@ static int cdnsp_setup_port_arrays(struc
return 0;
}
+static void cdnsp_initialize_ring_segments(struct cdnsp_device *pdev, struct cdnsp_ring *ring)
+{
+ struct cdnsp_segment *seg;
+
+ /* Only event ring does not use link TRB. */
+ if (ring->type == TYPE_EVENT)
+ return;
+
+ seg = ring->first_seg;
+
+ while (seg) {
+ struct cdnsp_segment *next = seg->next;
+
+ cdnsp_link_segments(pdev, seg, next, ring->type);
+ if (next == ring->first_seg)
+ break;
+
+ seg = next;
+ }
+
+ ring->last_seg->trbs[TRBS_PER_SEGMENT - 1].link.control |= cpu_to_le32(LINK_TOGGLE);
+}
+
+void cdnsp_ring_init(struct cdnsp_device *pdev, struct cdnsp_ring *ring)
+{
+ cdnsp_initialize_ring_segments(pdev, ring);
+ cdnsp_initialize_ring_info(ring);
+ trace_cdnsp_ring_alloc(ring);
+}
+
/*
* Initialize memory for CDNSP (one-time init).
*
@@ -1211,10 +1217,8 @@ int cdnsp_mem_init(struct cdnsp_device *
{
struct device *dev = pdev->dev;
int ret = -ENOMEM;
- unsigned int val;
dma_addr_t dma;
u32 page_size;
- u64 val_64;
/*
* Use 4K pages, since that's common and the minimum the
@@ -1222,10 +1226,6 @@ int cdnsp_mem_init(struct cdnsp_device *
*/
page_size = 1 << 12;
- val = readl(&pdev->op_regs->config_reg);
- val |= ((val & ~MAX_DEVS) | CDNSP_DEV_MAX_SLOTS) | CONFIG_U3E;
- writel(val, &pdev->op_regs->config_reg);
-
/*
* Doorbell array must be physically contiguous
* and 64-byte (cache line) aligned.
@@ -1237,8 +1237,6 @@ int cdnsp_mem_init(struct cdnsp_device *
pdev->dcbaa->dma = dma;
- cdnsp_write_64(dma, &pdev->op_regs->dcbaa_ptr);
-
/*
* Initialize the ring segment pool. The ring must be a contiguous
* structure comprised of TRBs. The TRBs must be 16 byte aligned,
@@ -1264,17 +1262,6 @@ int cdnsp_mem_init(struct cdnsp_device *
if (!pdev->cmd_ring)
goto destroy_device_pool;
- /* Set the address in the Command Ring Control register */
- val_64 = cdnsp_read_64(&pdev->op_regs->cmd_ring);
- val_64 = (val_64 & (u64)CMD_RING_RSVD_BITS) |
- (pdev->cmd_ring->first_seg->dma & (u64)~CMD_RING_RSVD_BITS) |
- pdev->cmd_ring->cycle_state;
- cdnsp_write_64(val_64, &pdev->op_regs->cmd_ring);
-
- val = readl(&pdev->cap_regs->db_off);
- val &= DBOFF_MASK;
- pdev->dba = (void __iomem *)pdev->cap_regs + val;
-
/* Set ir_set to interrupt register set 0 */
pdev->ir_set = &pdev->run_regs->ir_set[0];
@@ -1291,21 +1278,6 @@ int cdnsp_mem_init(struct cdnsp_device *
if (ret)
goto free_event_ring;
- /* Set ERST count with the number of entries in the segment table. */
- val = readl(&pdev->ir_set->erst_size);
- val &= ERST_SIZE_MASK;
- val |= ERST_NUM_SEGS;
- writel(val, &pdev->ir_set->erst_size);
-
- /* Set the segment table base address. */
- val_64 = cdnsp_read_64(&pdev->ir_set->erst_base);
- val_64 &= ERST_PTR_MASK;
- val_64 |= (pdev->erst.erst_dma_addr & (u64)~ERST_PTR_MASK);
- cdnsp_write_64(val_64, &pdev->ir_set->erst_base);
-
- /* Set the event ring dequeue address. */
- cdnsp_set_event_deq(pdev);
-
ret = cdnsp_setup_port_arrays(pdev);
if (ret)
goto free_erst;
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0077/1518] usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (75 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0076/1518] usb: cdnsp: fix wakeup from S3 after controller context loss Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0078/1518] wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot Greg Kroah-Hartman
` (921 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+791be35f1fbcc85d06d7, stable,
Jeffin Philip, Alan Stern, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jeffin Philip <jeffinphilip14@gmail.com>
[ Upstream commit 2c0f5ca48674a5b5f9fa4a9c3325aa48053af0bc ]
Previously fsg_num_buffers_validate() was removed as it was not
necessary due to Kconfig setting the limits for n from 2 to 256 with
default as 2. However, setting the page content in such a way that
kstrtou8() reflects n value as either 0 or 1 bypasses these
restrictions leading to a null pointer dereference if n is 0. Fix
this by adding a check for n < 2 and returning -EINVAL if n is
either 0 or 1 consistent with Kconfig logic.
Reported-by: syzbot+791be35f1fbcc85d06d7@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=791be35f1fbcc85d06d7
Fixes: fe5a6c48fd95 ("usb: gadget: storage: get rid of fsg_num_buffers_validate()")
Cc: stable <stable@kernel.org>
Signed-off-by: Jeffin Philip <jeffinphilip14@gmail.com>
Acked-by: Alan Stern <stern@rowland.harvard.edu>
Link: https://patch.msgid.link/20260818035904.10324-1-jeffinphilip14@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
[ adjusted context to retain the branch’s existing kcalloc() call instead of kzalloc_objs(). ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/usb/gadget/function/f_mass_storage.c | 3 +++
1 file changed, 3 insertions(+)
--- a/drivers/usb/gadget/function/f_mass_storage.c
+++ b/drivers/usb/gadget/function/f_mass_storage.c
@@ -2748,6 +2748,9 @@ int fsg_common_set_num_buffers(struct fs
struct fsg_buffhd *bh, *buffhds;
int i;
+ if (n < 2)
+ return -EINVAL;
+
buffhds = kcalloc(n, sizeof(*buffhds), GFP_KERNEL);
if (!buffhds)
return -ENOMEM;
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0078/1518] wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (76 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0077/1518] usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers() Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0079/1518] dm-pcache: reject a kset that overruns its segment Greg Kroah-Hartman
` (920 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ping-Ke Shih, Yuhang.chen,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: "Yuhang.chen" <yhchen312@gmail.com>
[ Upstream commit 667c12782aaf8dd3cb2213e528fe63a73cb63345 ]
Since the hardware rfkill polling was introduced, arm64 platforms can
panic with an asynchronous SError during warm reboot:
SError Interrupt on CPU8, code 0x00000000be000011 -- SError
Workqueue: events_power_efficient rfkill_poll [rfkill]
rtw89_pci_ops_read8+0x94/0x160 [rtw89_pci]
rtw89_core_rfkill_poll+0x50/0x1e0 [rtw89_core]
rtw89_ops_rfkill_poll+0x40/0x68 [rtw89_core]
ieee80211_rfkill_poll+0x3c/0x70 [mac80211]
cfg80211_rfkill_poll+0x40/0x2a0 [cfg80211]
rfkill_poll+0x30/0x88 [rfkill]
Kernel panic - not syncing: Asynchronous SError Interrupt
On the reboot path the kernel only runs device_shutdown(), which calls
each driver's .shutdown callback; .remove is not invoked. The rtw89 PCI
driver had no .shutdown callback, so nothing stopped the rfkill polling
work while the platform was tearing the PCIe link down. Once the link
is gone, the next MMIO read from the poll handler targets a
non-responding device and is reported as a fatal asynchronous SError on
arm64.
Add rtw89_pci_shutdown(), wired to all rtw89 PCI device drivers, which
sets a new RTW89_FLAG_SHUTDOWN flag (mirroring the USB
RTW89_FLAG_UNPLUGGED pattern). When the flag is set,
rtw89_ops_rfkill_poll() returns early, so no MMIO read is issued to the
chip after shutdown begins and the SError no longer occurs.
This does not call the full .remove path from .shutdown, to keep the
shutdown handler minimal and avoid running the non-idempotent teardown
twice.
Fixes: 0b38e6277aed ("wifi: rtw89: add support for hardware rfkill")
Cc: stable@vger.kernel.org
Suggested-by: Ping-Ke Shih <pkshih@realtek.com>
Signed-off-by: Yuhang.chen <yhchen312@gmail.com>
Acked-by: Ping-Ke Shih <pkshih@realtek.com>
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
Link: https://patch.msgid.link/20260729014142.2746777-1-yhchen312@gmail.com
[ Omitted the .shutdown registration in rtw8922de.c because the driver is absent from the target tree. ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/net/wireless/realtek/rtw89/core.h | 1 +
drivers/net/wireless/realtek/rtw89/mac80211.c | 3 ++-
drivers/net/wireless/realtek/rtw89/pci.c | 13 +++++++++++++
drivers/net/wireless/realtek/rtw89/pci.h | 1 +
drivers/net/wireless/realtek/rtw89/rtw8851be.c | 1 +
drivers/net/wireless/realtek/rtw89/rtw8852ae.c | 1 +
drivers/net/wireless/realtek/rtw89/rtw8852be.c | 1 +
drivers/net/wireless/realtek/rtw89/rtw8852bte.c | 1 +
drivers/net/wireless/realtek/rtw89/rtw8852ce.c | 1 +
drivers/net/wireless/realtek/rtw89/rtw8922ae.c | 1 +
10 files changed, 23 insertions(+), 1 deletion(-)
--- a/drivers/net/wireless/realtek/rtw89/core.h
+++ b/drivers/net/wireless/realtek/rtw89/core.h
@@ -5042,6 +5042,7 @@ enum rtw89_flags {
RTW89_FLAG_CHANGING_INTERFACE,
RTW89_FLAG_HW_RFKILL_STATE,
RTW89_FLAG_UNPLUGGED,
+ RTW89_FLAG_SHUTDOWN,
NUM_OF_RTW89_FLAGS,
};
--- a/drivers/net/wireless/realtek/rtw89/mac80211.c
+++ b/drivers/net/wireless/realtek/rtw89/mac80211.c
@@ -1879,7 +1879,8 @@ static void rtw89_ops_rfkill_poll(struct
lockdep_assert_wiphy(hw->wiphy);
/* wl_disable GPIO get floating when entering LPS */
- if (test_bit(RTW89_FLAG_RUNNING, rtwdev->flags))
+ if (test_bit(RTW89_FLAG_RUNNING, rtwdev->flags) ||
+ test_bit(RTW89_FLAG_SHUTDOWN, rtwdev->flags))
return;
rtw89_core_rfkill_poll(rtwdev, false);
--- a/drivers/net/wireless/realtek/rtw89/pci.c
+++ b/drivers/net/wireless/realtek/rtw89/pci.c
@@ -4829,6 +4829,19 @@ void rtw89_pci_remove(struct pci_dev *pd
}
EXPORT_SYMBOL(rtw89_pci_remove);
+void rtw89_pci_shutdown(struct pci_dev *pdev)
+{
+ struct ieee80211_hw *hw = pci_get_drvdata(pdev);
+ struct rtw89_dev *rtwdev;
+
+ if (!hw)
+ return;
+
+ rtwdev = hw->priv;
+ set_bit(RTW89_FLAG_SHUTDOWN, rtwdev->flags);
+}
+EXPORT_SYMBOL(rtw89_pci_shutdown);
+
MODULE_AUTHOR("Realtek Corporation");
MODULE_DESCRIPTION("Realtek PCI 802.11ax wireless driver");
MODULE_LICENSE("Dual BSD/GPL");
--- a/drivers/net/wireless/realtek/rtw89/pci.h
+++ b/drivers/net/wireless/realtek/rtw89/pci.h
@@ -1737,6 +1737,7 @@ struct pci_device_id;
int rtw89_pci_probe(struct pci_dev *pdev, const struct pci_device_id *id);
void rtw89_pci_remove(struct pci_dev *pdev);
+void rtw89_pci_shutdown(struct pci_dev *pdev);
void rtw89_pci_basic_cfg(struct rtw89_dev *rtwdev, bool resume);
void rtw89_pci_ops_reset(struct rtw89_dev *rtwdev);
int rtw89_pci_ltr_set(struct rtw89_dev *rtwdev, bool en);
--- a/drivers/net/wireless/realtek/rtw89/rtw8851be.c
+++ b/drivers/net/wireless/realtek/rtw89/rtw8851be.c
@@ -92,6 +92,7 @@ static struct pci_driver rtw89_8851be_dr
.id_table = rtw89_8851be_id_table,
.probe = rtw89_pci_probe,
.remove = rtw89_pci_remove,
+ .shutdown = rtw89_pci_shutdown,
.driver.pm = &rtw89_pm_ops,
.err_handler = &rtw89_pci_err_handler,
};
--- a/drivers/net/wireless/realtek/rtw89/rtw8852ae.c
+++ b/drivers/net/wireless/realtek/rtw89/rtw8852ae.c
@@ -94,6 +94,7 @@ static struct pci_driver rtw89_8852ae_dr
.id_table = rtw89_8852ae_id_table,
.probe = rtw89_pci_probe,
.remove = rtw89_pci_remove,
+ .shutdown = rtw89_pci_shutdown,
.driver.pm = &rtw89_pm_ops,
.err_handler = &rtw89_pci_err_handler,
};
--- a/drivers/net/wireless/realtek/rtw89/rtw8852be.c
+++ b/drivers/net/wireless/realtek/rtw89/rtw8852be.c
@@ -96,6 +96,7 @@ static struct pci_driver rtw89_8852be_dr
.id_table = rtw89_8852be_id_table,
.probe = rtw89_pci_probe,
.remove = rtw89_pci_remove,
+ .shutdown = rtw89_pci_shutdown,
.driver.pm = &rtw89_pm_ops,
.err_handler = &rtw89_pci_err_handler,
};
--- a/drivers/net/wireless/realtek/rtw89/rtw8852bte.c
+++ b/drivers/net/wireless/realtek/rtw89/rtw8852bte.c
@@ -98,6 +98,7 @@ static struct pci_driver rtw89_8852bte_d
.id_table = rtw89_8852bte_id_table,
.probe = rtw89_pci_probe,
.remove = rtw89_pci_remove,
+ .shutdown = rtw89_pci_shutdown,
.driver.pm = &rtw89_pm_ops,
.err_handler = &rtw89_pci_err_handler,
};
--- a/drivers/net/wireless/realtek/rtw89/rtw8852ce.c
+++ b/drivers/net/wireless/realtek/rtw89/rtw8852ce.c
@@ -121,6 +121,7 @@ static struct pci_driver rtw89_8852ce_dr
.id_table = rtw89_8852ce_id_table,
.probe = rtw89_pci_probe,
.remove = rtw89_pci_remove,
+ .shutdown = rtw89_pci_shutdown,
.driver.pm = &rtw89_pm_ops,
.err_handler = &rtw89_pci_err_handler,
};
--- a/drivers/net/wireless/realtek/rtw89/rtw8922ae.c
+++ b/drivers/net/wireless/realtek/rtw89/rtw8922ae.c
@@ -109,6 +109,7 @@ static struct pci_driver rtw89_8922ae_dr
.id_table = rtw89_8922ae_id_table,
.probe = rtw89_pci_probe,
.remove = rtw89_pci_remove,
+ .shutdown = rtw89_pci_shutdown,
.driver.pm = &rtw89_pm_ops_be,
.err_handler = &rtw89_pci_err_handler,
};
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0079/1518] dm-pcache: reject a kset that overruns its segment
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (77 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0078/1518] wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0080/1518] dm-pcache: bound the logical key offset from persistent memory Greg Kroah-Hartman
` (919 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bryam Vargas, Mikulas Patocka,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bryam Vargas <hexlabsecurity@proton.me>
[ Upstream commit 7ac1f10f987a2ffae4aecf0e2ceca8f552b665cb ]
cache_replay(), the writeback worker and the GC worker read a kset of
get_kset_onmedia_size() bytes and advance the position by it. A forged
key_num makes that size exceed the segment's remaining space, so the
advance walks past the segment and trips the cache_pos_advance() BUG_ON.
Reject a kset whose on-media size exceeds cache_seg_remain() before use.
Fixes: 1d57628ff95b ("dm-pcache: add persistent cache target in device-mapper")
Cc: stable@vger.kernel.org
Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me>
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
[ backported missing writeback_errors support from the upstream dependency. ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/md/dm-pcache/cache.h | 1 +
drivers/md/dm-pcache/cache_gc.c | 5 +++++
drivers/md/dm-pcache/cache_key.c | 5 +++++
drivers/md/dm-pcache/cache_writeback.c | 8 ++++++++
4 files changed, 19 insertions(+)
--- a/drivers/md/dm-pcache/cache.h
+++ b/drivers/md/dm-pcache/cache.h
@@ -180,6 +180,7 @@ struct pcache_cache {
u32 advance;
int ret;
} writeback_ctx;
+ atomic_t writeback_errors;
char gc_kset_onmedia_buf[PCACHE_KSET_ONMEDIA_SIZE_MAX];
struct delayed_work gc_work;
--- a/drivers/md/dm-pcache/cache_gc.c
+++ b/drivers/md/dm-pcache/cache_gc.c
@@ -134,6 +134,11 @@ void pcache_cache_gc_fn(struct work_stru
continue;
}
+ if (get_kset_onmedia_size(kset_onmedia) > cache_seg_remain(&key_tail)) {
+ atomic_inc(&cache->gc_errors);
+ return;
+ }
+
for (i = 0; i < kset_onmedia->key_num; i++) {
struct pcache_cache_key key_tmp = { 0 };
--- a/drivers/md/dm-pcache/cache_key.c
+++ b/drivers/md/dm-pcache/cache_key.c
@@ -811,6 +811,11 @@ int cache_replay(struct pcache_cache *ca
}
/* Replay the kset and check for errors. */
+ if (get_kset_onmedia_size(kset_onmedia) > cache_seg_remain(pos)) {
+ ret = -EIO;
+ goto out;
+ }
+
ret = kset_replay(cache, kset_onmedia);
if (ret)
goto out;
--- a/drivers/md/dm-pcache/cache_writeback.c
+++ b/drivers/md/dm-pcache/cache_writeback.c
@@ -229,6 +229,9 @@ void cache_writeback_fn(struct work_stru
if (pcache_is_stopping(pcache))
goto unlock;
+ if (atomic_read(&cache->writeback_errors))
+ goto unlock;
+
kset_onmedia = (struct pcache_cache_kset_onmedia *)cache->wb_kset_onmedia_buf;
mutex_lock(&cache->dirty_tail_lock);
@@ -246,6 +249,11 @@ void cache_writeback_fn(struct work_stru
goto queue_work;
}
+ if (get_kset_onmedia_size(kset_onmedia) > cache_seg_remain(&dirty_tail)) {
+ atomic_inc(&cache->writeback_errors);
+ goto unlock;
+ }
+
ret = cache_kset_insert_tree(cache, kset_onmedia);
if (ret) {
delay = PCACHE_CACHE_WRITEBACK_INTERVAL;
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0080/1518] dm-pcache: bound the logical key offset from persistent memory
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (78 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0079/1518] dm-pcache: reject a kset that overruns its segment Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0081/1518] dm-pcache: validate the persisted dirty_tail chain at load Greg Kroah-Hartman
` (918 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bryam Vargas, Mikulas Patocka,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bryam Vargas <hexlabsecurity@proton.me>
[ Upstream commit 97fc4b53dbe4a983fdf093243067fa6a64562307 ]
cache_key_decode() takes a key's logical off from the cache device and
later indexes req_key_tree->subtrees[] by it in get_subtree(). An off
past the device forms a subtree pointer outside the array, which
rb_insert() writes through during replay.
Reject a key of zero length, or whose off+len (computed in 64 bits)
exceeds the device size, before it is used.
Fixes: 1d57628ff95b ("dm-pcache: add persistent cache target in device-mapper")
Cc: stable@vger.kernel.org
Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me>
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
[ adjusted context to account for the missing cache_seg_id_valid() check. ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/md/dm-pcache/cache_key.c | 9 +++++++++
1 file changed, 9 insertions(+)
--- a/drivers/md/dm-pcache/cache_key.c
+++ b/drivers/md/dm-pcache/cache_key.c
@@ -90,10 +90,19 @@ int cache_key_decode(struct pcache_cache
struct pcache_cache_key *key)
{
struct dm_pcache *pcache = CACHE_TO_PCACHE(cache);
+ u64 dev_bytes = (u64)cache->dev_size << SECTOR_SHIFT;
key->off = key_onmedia->off;
key->len = key_onmedia->len;
+ if (key_onmedia->len == 0 ||
+ key_onmedia->len > dev_bytes ||
+ key_onmedia->off > dev_bytes - key_onmedia->len) {
+ pcache_dev_err(pcache, "key off %llu + len %u exceeds device size\n",
+ key_onmedia->off, key_onmedia->len);
+ return -EIO;
+ }
+
key->cache_pos.cache_seg = &cache->segments[key_onmedia->cache_seg_id];
key->cache_pos.seg_off = key_onmedia->cache_seg_off;
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0081/1518] dm-pcache: validate the persisted dirty_tail chain at load
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (79 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0080/1518] dm-pcache: bound the logical key offset from persistent memory Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0082/1518] KVM: arm64: nv: Fully update VNCR fixmap state in kvm_translate_vncr() Greg Kroah-Hartman
` (917 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bryam Vargas, Mikulas Patocka,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bryam Vargas <hexlabsecurity@proton.me>
[ Upstream commit 58d620ee9e01d4bdbceaf2ae1450d307a2a9d58b ]
The writeback worker follows the persisted dirty_tail chain, which is
decoded from the cache device independently of the key_tail chain that
cache_replay() walks and bounds. A crafted image, whose on-media fields are
authenticated only by a crc32c with a fixed seed, can aim dirty_tail at a
chain of last ksets that never terminates, so cache_writeback_fn() re-arms
itself with no delay forever.
Walk the dirty_tail chain once at load with the same hop cap cache_replay()
uses and fail the table load with -EIO if it does not reach an end within
n_segs hops.
Fixes: 1d57628ff95b ("dm-pcache: add persistent cache target in device-mapper")
Cc: stable@vger.kernel.org
Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me>
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
[ replaced the unavailable cache_seg_id_valid() helper with an equivalent bounds check against cache->cache_info.n_segs ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/md/dm-pcache/cache.c | 7 +++
drivers/md/dm-pcache/cache.h | 2 +
drivers/md/dm-pcache/cache_key.c | 69 +++++++++++++++++++++++++++++++++++++++
3 files changed, 78 insertions(+)
--- a/drivers/md/dm-pcache/cache.c
+++ b/drivers/md/dm-pcache/cache.c
@@ -197,6 +197,7 @@ static int cache_tail_init(struct pcache
{
struct dm_pcache *pcache = CACHE_TO_PCACHE(cache);
bool new_cache = !(cache->cache_info.flags & PCACHE_CACHE_FLAGS_INIT_DONE);
+ int ret;
if (new_cache) {
__set_bit(0, cache->seg_map);
@@ -213,6 +214,12 @@ static int cache_tail_init(struct pcache
pcache_dev_err(pcache, "Corrupted key tail or dirty tail.\n");
return -EIO;
}
+
+ ret = cache_verify_dirty_tail(cache);
+ if (ret) {
+ pcache_dev_err(pcache, "dirty tail chain does not terminate (crafted cache image?)\n");
+ return ret;
+ }
}
return 0;
--- a/drivers/md/dm-pcache/cache.h
+++ b/drivers/md/dm-pcache/cache.h
@@ -652,6 +652,8 @@ static inline int cache_decode_dirty_tai
&cache->dirty_tail_index);
}
+int cache_verify_dirty_tail(struct pcache_cache *cache);
+
int pcache_cache_init(void);
void pcache_cache_exit(void);
#endif /* _PCACHE_CACHE_H */
--- a/drivers/md/dm-pcache/cache_key.c
+++ b/drivers/md/dm-pcache/cache_key.c
@@ -846,6 +846,75 @@ out:
return ret;
}
+/*
+ * cache_verify_dirty_tail - reject a persisted dirty_tail whose last-kset
+ * chain does not terminate.
+ *
+ * dirty_tail is decoded independently of the key_tail chain cache_replay()
+ * walks, so replay's hop cap does not cover it. A crafted chain that loops
+ * back on itself makes the writeback worker re-arm forever; walk it once here
+ * with the same cap and fail the load if it does not end within n_segs hops.
+ */
+int cache_verify_dirty_tail(struct pcache_cache *cache)
+{
+ struct pcache_cache_pos pos;
+ struct pcache_cache_kset_onmedia *kset_onmedia;
+ u32 to_copy, last_hops = 0, count = 0;
+ int ret = 0;
+
+ kset_onmedia = kzalloc(PCACHE_KSET_ONMEDIA_SIZE_MAX, GFP_KERNEL);
+ if (!kset_onmedia)
+ return -ENOMEM;
+
+ cache_pos_copy(&pos, &cache->dirty_tail);
+
+ while (true) {
+ to_copy = min(PCACHE_KSET_ONMEDIA_SIZE_MAX, cache_seg_remain(&pos));
+ ret = copy_mc_to_kernel(kset_onmedia, cache_pos_addr(&pos), to_copy);
+ if (ret) {
+ ret = -EIO;
+ goto out;
+ }
+
+ /* A missing, short or corrupt kset is the normal end of the chain. */
+ if (!kset_onmedia_valid(kset_onmedia) ||
+ kset_onmedia->crc != cache_kset_crc(kset_onmedia)) {
+ ret = 0;
+ goto out;
+ }
+
+ if (kset_onmedia->flags & PCACHE_KSET_FLAGS_LAST) {
+ if (kset_onmedia->next_cache_seg_id >= cache->cache_info.n_segs) {
+ ret = -EIO;
+ goto out;
+ }
+
+ if (++last_hops > cache->n_segs) {
+ ret = -EIO;
+ goto out;
+ }
+
+ pos.cache_seg = &cache->segments[kset_onmedia->next_cache_seg_id];
+ pos.seg_off = 0;
+ continue;
+ }
+
+ if (get_kset_onmedia_size(kset_onmedia) > cache_seg_remain(&pos)) {
+ ret = -EIO;
+ goto out;
+ }
+
+ cache_pos_advance(&pos, get_kset_onmedia_size(kset_onmedia));
+ if (++count > 512) {
+ cond_resched();
+ count = 0;
+ }
+ }
+out:
+ kfree(kset_onmedia);
+ return ret;
+}
+
int cache_tree_init(struct pcache_cache *cache, struct pcache_cache_tree *cache_tree, u32 n_subtrees)
{
int ret;
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0082/1518] KVM: arm64: nv: Fully update VNCR fixmap state in kvm_translate_vncr()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (80 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0081/1518] dm-pcache: validate the persisted dirty_tail chain at load Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0083/1518] KVM: arm64: Handle VNCR TLB invalidation race with vcpu_put() VNCR unmapping Greg Kroah-Hartman
` (916 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Oliver Upton, Marc Zyngier,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Oliver Upton <oupton@kernel.org>
[ Upstream commit 5949004d7032767e8fde1e8c986a33f241b2a192 ]
kvm_translate_vncr() first invalidates the pseudo-TLB entry and
corresponding fixmap in anticipation of installing a new translation.
While the fixmap invalidation does clear the mapping from host stage-1,
it does not clear the L1_VNCR_MAPPED flag. Depending on the state of the
VNCR TLB at vcpu_put(), this could potentially precipitate a BUG_ON() if
vt->cpu is reset.
Share a helper with kvm_vcpu_put_hw_mmu(), ensuring that KVM's view of
the VNCR fixmap is in sync with the state of the VNCR TLB. Give it a
slightly verbose name to make it obvious that it is meant to be used
local to a CPU, unlike other VNCR TLB maintenance.
Fixes: 069a05e535496 ("KVM: arm64: nv: Handle VNCR_EL2-triggered faults")
Signed-off-by: Oliver Upton <oupton@kernel.org>
Link: https://patch.msgid.link/20260602235450.103057-3-oupton@kernel.org
Signed-off-by: Marc Zyngier <maz@kernel.org>
Stable-dep-of: 38640bc32be3 ("KVM: arm64: Handle VNCR TLB invalidation race with vcpu_put() VNCR unmapping")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/kvm/nested.c | 27 +++++++++++++++++----------
1 file changed, 17 insertions(+), 10 deletions(-)
--- a/arch/arm64/kvm/nested.c
+++ b/arch/arm64/kvm/nested.c
@@ -771,18 +771,24 @@ void kvm_vcpu_load_hw_mmu(struct kvm_vcp
}
}
+static void this_cpu_reset_vncr_fixmap(struct kvm_vcpu *vcpu)
+{
+ if (!host_data_test_flag(L1_VNCR_MAPPED))
+ return;
+
+ BUG_ON(vcpu->arch.vncr_tlb->cpu != smp_processor_id());
+ BUG_ON(is_hyp_ctxt(vcpu));
+
+ clear_fixmap(vncr_fixmap(vcpu->arch.vncr_tlb->cpu));
+ vcpu->arch.vncr_tlb->cpu = -1;
+ host_data_clear_flag(L1_VNCR_MAPPED);
+ atomic_dec(&vcpu->kvm->arch.vncr_map_count);
+}
+
void kvm_vcpu_put_hw_mmu(struct kvm_vcpu *vcpu)
{
/* Unconditionally drop the VNCR mapping if we have one */
- if (host_data_test_flag(L1_VNCR_MAPPED)) {
- BUG_ON(vcpu->arch.vncr_tlb->cpu != smp_processor_id());
- BUG_ON(is_hyp_ctxt(vcpu));
-
- clear_fixmap(vncr_fixmap(vcpu->arch.vncr_tlb->cpu));
- vcpu->arch.vncr_tlb->cpu = -1;
- host_data_clear_flag(L1_VNCR_MAPPED);
- atomic_dec(&vcpu->kvm->arch.vncr_map_count);
- }
+ this_cpu_reset_vncr_fixmap(vcpu);
/*
* Keep a reference on the associated stage-2 MMU if the vCPU is
@@ -1244,7 +1250,8 @@ static int kvm_translate_vncr(struct kvm
* We also prepare the next walk wilst we're at it.
*/
scoped_guard(write_lock, &vcpu->kvm->mmu_lock) {
- invalidate_vncr(vt);
+ this_cpu_reset_vncr_fixmap(vcpu);
+ vt->valid = false;
vt->wi = (struct s1_walk_info) {
.regime = TR_EL20,
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0083/1518] KVM: arm64: Handle VNCR TLB invalidation race with vcpu_put() VNCR unmapping
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (81 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0082/1518] KVM: arm64: nv: Fully update VNCR fixmap state in kvm_translate_vncr() Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0084/1518] media: dt-bindings: nxp,imx8-isi: Drop fsl,blk-ctrl requirement for i.MX8ULP Greg Kroah-Hartman
` (915 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot, Marc Zyngier, Yuan Yao,
Oliver Upton, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Marc Zyngier <maz@kernel.org>
[ Upstream commit 38640bc32be3fcf9526d477155bc19d3f146231f ]
While VNCR TLB invalidation always occurs under the MMU lock,
vcpu_put() doesn't, while it unmaps the VNCR page.
The problem is that the invalidation evaluates vncr_tlb::cpu to
decide whether an unmapping needs to take place (cpu != -1) before
performing it. On the other hand, this_cpu_reset_vncr_fixmap()
unconditionally unmaps if L1_VNCR_MAPPED is set.
These two obviously can race, with a TOCTOU pattern on the TLBI
path, and a BUG_ON() on the vcpu_put() path. And the two can end-up
calling vncr_fixmap(-1), with extra lethal effects.
Move the reset of vncr_tlb::cpu to -1 to a common function, and make
this update atomic so that only a single thread can reset the field
and perform the corresponding unmap. The vcpu_put() still need to
unconditionally unmap the current VNCR to close another ugly race.
Finally, the assignment of vncr_tlb::cpu is moved to be kept in sync
with the actual mapping, similar to L1_VNCR_MAPPED being set.
Fixes: 7270cc9157f47 ("KVM: arm64: nv: Handle VNCR_EL2 invalidation from MMU notifiers")
Reported-by: sashiko-bot@kernel.org
Link: https://lore.kernel.org/r/20260801130237.0FD8F1F00ACA@smtp.kernel.org
Signed-off-by: Marc Zyngier <maz@kernel.org>
Cc: stable@vger.kernel.org
Reviewed-by: Yuan Yao <yaoyuan@linux.alibaba.com>
Link: https://patch.msgid.link/20260806091026.620700-6-maz@kernel.org
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/kvm/nested.c | 42 ++++++++++++++++++++++++++++++++----------
1 file changed, 32 insertions(+), 10 deletions(-)
--- a/arch/arm64/kvm/nested.c
+++ b/arch/arm64/kvm/nested.c
@@ -27,7 +27,7 @@ struct vncr_tlb {
bool hpa_writable;
/* -1 when not mapped on a CPU */
- int cpu;
+ atomic_t cpu;
/*
* true if the TLB is valid. Can only be changed with the
@@ -771,16 +771,40 @@ void kvm_vcpu_load_hw_mmu(struct kvm_vcp
}
}
+/*
+ * Unmapping an L1 VNCR can happen concurrently without the mmu lock being
+ * effective (vcpu_put() vs TLBI handling). The atomic_xchg below ensures
+ * that only one CPU sets it to -1 while getting a valid CPU number back.
+ */
+static int unmap_l1_vncr(struct vncr_tlb *vt)
+{
+ int cpu = atomic_xchg_relaxed(&vt->cpu, -1);
+
+ if (cpu != -1)
+ clear_fixmap(vncr_fixmap(cpu));
+
+ return cpu;
+}
+
static void this_cpu_reset_vncr_fixmap(struct kvm_vcpu *vcpu)
{
if (!host_data_test_flag(L1_VNCR_MAPPED))
return;
- BUG_ON(vcpu->arch.vncr_tlb->cpu != smp_processor_id());
BUG_ON(is_hyp_ctxt(vcpu));
- clear_fixmap(vncr_fixmap(vcpu->arch.vncr_tlb->cpu));
- vcpu->arch.vncr_tlb->cpu = -1;
+ /*
+ * Unconditionally unmap the local VNCR if we have lost the race
+ * against a concurrent TLBI. Otherwise we could end-up running
+ * another vcpu with VNCR still mapped if the TLBI thread is
+ * preempted between the exchange and the clear_fixmap().
+ *
+ * Note that we do not care about the TLBI nuking the fixmap behind
+ * the back of an running vcpu. This will only generate a fault and
+ * possibly a retranslation.
+ */
+ if (unmap_l1_vncr(vcpu->arch.vncr_tlb) == -1)
+ clear_fixmap(vncr_fixmap(smp_processor_id()));
host_data_clear_flag(L1_VNCR_MAPPED);
atomic_dec(&vcpu->kvm->arch.vncr_map_count);
}
@@ -870,8 +894,7 @@ u16 get_asid_by_regime(struct kvm_vcpu *
static void invalidate_vncr(struct vncr_tlb *vt)
{
vt->valid = false;
- if (vt->cpu != -1)
- clear_fixmap(vncr_fixmap(vt->cpu));
+ unmap_l1_vncr(vt);
}
static bool vncr_tlb_intersects(struct vncr_tlb *vt, u64 addr,
@@ -1321,7 +1344,7 @@ static int kvm_translate_vncr(struct kvm
vt->hpa = pfn << PAGE_SHIFT;
vt->hpa_writable = writable;
vt->valid = true;
- vt->cpu = -1;
+ atomic_set(&vt->cpu, -1);
kvm_make_request(KVM_REQ_MAP_L1_VNCR_EL2, vcpu);
kvm_release_faultin_page(vcpu->kvm, page, false, vt->wr.pw && vt->hpa_writable);
@@ -1452,8 +1475,6 @@ static void kvm_map_l1_vncr(struct kvm_v
if (vt->wr.nG && get_asid_by_regime(vcpu, TR_EL20) != vt->wr.asid)
return;
- vt->cpu = smp_processor_id();
-
if (vt->hpa_writable && vt->wr.pw && vt->wr.pr)
prot = PAGE_KERNEL;
else if (vt->wr.pr)
@@ -1468,7 +1489,8 @@ static void kvm_map_l1_vncr(struct kvm_v
* FIXME: WO doesn't work at all, need POE support in the kernel.
*/
if (pgprot_val(prot) != pgprot_val(PAGE_NONE)) {
- __set_fixmap(vncr_fixmap(vt->cpu), vt->hpa, prot);
+ atomic_set(&vt->cpu, smp_processor_id());
+ __set_fixmap(vncr_fixmap(atomic_read(&vt->cpu)), vt->hpa, prot);
host_data_set_flag(L1_VNCR_MAPPED);
atomic_inc(&vcpu->kvm->arch.vncr_map_count);
}
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0084/1518] media: dt-bindings: nxp,imx8-isi: Drop fsl,blk-ctrl requirement for i.MX8ULP
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (82 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0083/1518] KVM: arm64: Handle VNCR TLB invalidation race with vcpu_put() VNCR unmapping Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0085/1518] KVM: arm64: Remove VM-wide VNCR mapping counter Greg Kroah-Hartman
` (914 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Guoniu Zhou, Laurent Pinchart,
Conor Dooley, Hans Verkuil, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guoniu Zhou <guoniu.zhou@oss.nxp.com>
[ Upstream commit fc312f830d8df6c082bd6f7250aa5c0ff063eea4 ]
The i.MX8ULP variant does not require the fsl,blk-ctrl property. Add
fsl,imx8ulp-isi to the exception list alongside fsl,imx91-isi.
Fixes: 288517a3c6c9 ("dt-bindings: media: nxp,imx8-isi: Add i.MX8ULP ISI compatible string")
Cc: stable@vger.kernel.org
Signed-off-by: Guoniu Zhou <guoniu.zhou@oss.nxp.com>
Reviewed-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Acked-by: Conor Dooley <conor.dooley@microchip.com>
Link: https://patch.msgid.link/20260424-csi2_imx8ulp-v12-1-da148eabc035@oss.nxp.com
Signed-off-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
[ added the missing fsl,blk-ctrl conditional using const instead of enum because this branch lacks i.MX91 support. ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
Documentation/devicetree/bindings/media/nxp,imx8-isi.yaml | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
--- a/Documentation/devicetree/bindings/media/nxp,imx8-isi.yaml
+++ b/Documentation/devicetree/bindings/media/nxp,imx8-isi.yaml
@@ -66,7 +66,6 @@ required:
- interrupts
- clocks
- clock-names
- - fsl,blk-ctrl
- ports
allOf:
@@ -109,6 +108,16 @@ allOf:
- port@0
- port@1
+ - if:
+ properties:
+ compatible:
+ not:
+ contains:
+ const: fsl,imx8ulp-isi
+ then:
+ required:
+ - fsl,blk-ctrl
+
additionalProperties: false
examples:
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0085/1518] KVM: arm64: Remove VM-wide VNCR mapping counter
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (83 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0084/1518] media: dt-bindings: nxp,imx8-isi: Drop fsl,blk-ctrl requirement for i.MX8ULP Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0086/1518] KVM: x86: Disallow EFER.LME and EFER.LMA if long mode is not supported Greg Kroah-Hartman
` (913 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yuan Yao, Marc Zyngier,
Lorenzo Stoakes (ARM), Oliver Upton, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Marc Zyngier <maz@kernel.org>
[ Upstream commit c55bc773b6e814406658fae7dc5c15f639ed816e ]
The global VNCR mapping counter is used to decide whether an L1
provided VNCR page is mapped in L0 on any CPU at the point of
dealing with a TLB invalidation. It is incremented when a mapping
is made in the fixmap, and decremented when unmapped.
As it turns out, this tracking has several flaws:
- we are trying to invalidate TLBs, and the mapping is only an
opportunistic consequence of the TLB. Checking this counter to
decide whether a TLB needs to be invalidated may result in missed
invalidations.
- an L1 vcpu invalidating its own TLB (a very likely case) will not
succeed in invalidating the VNCR pseudo TLB because that page is
not mapped in L0 at this stage.
Given that this tracking fails at delivering the minimum guarantees
that are required and is only a performance optimisation, remove it
completely.
Fixes: 4ffa72ad8f37e ("KVM: arm64: nv: Add S1 TLB invalidation primitive for VNCR_EL2")
Reviewed-by: Yuan Yao <yaoyuan@linux.alibaba.com>
Signed-off-by: Marc Zyngier <maz@kernel.org>
Cc: stable@vger.kernel.org
Acked-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Link: https://patch.msgid.link/20260806091026.620700-2-maz@kernel.org
Signed-off-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/arm64/include/asm/kvm_host.h | 3 ---
arch/arm64/kvm/hyp/vhe/switch.c | 3 +--
arch/arm64/kvm/nested.c | 3 ---
3 files changed, 1 insertion(+), 8 deletions(-)
--- a/arch/arm64/include/asm/kvm_host.h
+++ b/arch/arm64/include/asm/kvm_host.h
@@ -397,9 +397,6 @@ struct kvm_arch {
/* Masks for VNCR-backed and general EL2 sysregs */
struct kvm_sysreg_masks *sysreg_masks;
- /* Count the number of VNCR_EL2 currently mapped */
- atomic_t vncr_map_count;
-
/*
* For an untrusted host VM, 'pkvm.handle' is used to lookup
* the associated pKVM instance in the hypervisor.
--- a/arch/arm64/kvm/hyp/vhe/switch.c
+++ b/arch/arm64/kvm/hyp/vhe/switch.c
@@ -427,8 +427,7 @@ static bool kvm_hyp_handle_tlbi_el2(stru
* If we have to check for any VNCR mapping being invalidated,
* go back to the slow path for further processing.
*/
- if (vcpu_el2_e2h_is_set(vcpu) && vcpu_el2_tge_is_set(vcpu) &&
- atomic_read(&vcpu->kvm->arch.vncr_map_count))
+ if (vcpu_el2_e2h_is_set(vcpu) && vcpu_el2_tge_is_set(vcpu))
return false;
__kvm_skip_instr(vcpu);
--- a/arch/arm64/kvm/nested.c
+++ b/arch/arm64/kvm/nested.c
@@ -48,7 +48,6 @@ void kvm_init_nested(struct kvm *kvm)
{
kvm->arch.nested_mmus = NULL;
kvm->arch.nested_mmus_size = 0;
- atomic_set(&kvm->arch.vncr_map_count, 0);
}
static int init_nested_s2_mmu(struct kvm *kvm, struct kvm_s2_mmu *mmu)
@@ -806,7 +805,6 @@ static void this_cpu_reset_vncr_fixmap(s
if (unmap_l1_vncr(vcpu->arch.vncr_tlb) == -1)
clear_fixmap(vncr_fixmap(smp_processor_id()));
host_data_clear_flag(L1_VNCR_MAPPED);
- atomic_dec(&vcpu->kvm->arch.vncr_map_count);
}
void kvm_vcpu_put_hw_mmu(struct kvm_vcpu *vcpu)
@@ -1492,7 +1490,6 @@ static void kvm_map_l1_vncr(struct kvm_v
atomic_set(&vt->cpu, smp_processor_id());
__set_fixmap(vncr_fixmap(atomic_read(&vt->cpu)), vt->hpa, prot);
host_data_set_flag(L1_VNCR_MAPPED);
- atomic_inc(&vcpu->kvm->arch.vncr_map_count);
}
}
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0086/1518] KVM: x86: Disallow EFER.LME and EFER.LMA if long mode is not supported
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (84 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0085/1518] KVM: arm64: Remove VM-wide VNCR mapping counter Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0087/1518] KVM: s390: Zero initialize data structures for inject_pfault_token Greg Kroah-Hartman
` (912 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yosry Ahmed, Sean Christopherson,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yosry Ahmed <yosry@kernel.org>
[ Upstream commit e62392bf39ebfdf60d1d082799397fe1cbf8dfc5 ]
Remove EFER.LME and EFER.LMA from EFER reserved bits only if long mode
is actually supported. KVM does check long-mode support before allowing
the bits for guest writes and userspace writes through KVM_SET_SREGS*
(in __kvm_valid_efer()), but userspace writes through KVM_SET_MSRS only
check reserved bits.
In practice, this doesn't really matter. The true motiviation is getting
rid of the #ifdeffery when initializing efer_reserved_bits.
Cc: stable@vger.kernel.org
Signed-off-by: Yosry Ahmed <yosry@kernel.org>
Link: https://patch.msgid.link/20260713181020.2735367-3-yosry@kernel.org
Signed-off-by: Sean Christopherson <seanjc@google.com>
[ relocated hunks to x86.c and its kvm_x86_vendor_init() because msrs.c and kvm_setup_efer_caps() are absent. ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/kvm/x86.c | 13 ++++---------
1 file changed, 4 insertions(+), 9 deletions(-)
--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -106,16 +106,8 @@ EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_host)
#define emul_to_vcpu(ctxt) \
((struct kvm_vcpu *)(ctxt)->vcpu)
-/* EFER defaults:
- * - enable syscall per default because its emulated by KVM
- * - enable LME and LMA per default on 64 bit KVM
- */
-#ifdef CONFIG_X86_64
-static
-u64 __read_mostly efer_reserved_bits = ~((u64)(EFER_SCE | EFER_LME | EFER_LMA));
-#else
+/* Enable syscall by default because its emulated by KVM */
static u64 __read_mostly efer_reserved_bits = ~((u64)EFER_SCE);
-#endif
#define KVM_EXIT_HYPERCALL_VALID_MASK (1 << KVM_HC_MAP_GPA_RANGE)
@@ -10157,6 +10149,9 @@ int kvm_x86_vendor_init(struct kvm_x86_i
if (r != 0)
goto out_mmu_exit;
+ if (kvm_cpu_cap_has(X86_FEATURE_LM))
+ kvm_enable_efer_bits(EFER_LME | EFER_LMA);
+
enable_device_posted_irqs &= enable_apicv &&
irq_remapping_cap(IRQ_POSTING_CAP);
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0087/1518] KVM: s390: Zero initialize data structures for inject_pfault_token
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (85 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0086/1518] KVM: x86: Disallow EFER.LME and EFER.LMA if long mode is not supported Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0088/1518] KVM: x86: Extract REGS and SREGS runtime sync code to helpers Greg Kroah-Hartman
` (911 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Borntraeger,
Matthew Rosato, Claudio Imbrenda, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Borntraeger <borntraeger@linux.ibm.com>
[ Upstream commit 4e2c7f7cbc27418f9a290399b986c1b85ff93b90 ]
__kvm_inject_pfault_token() only sets .type and .u.ext.ext_params2 of
the on-stack struct kvm_s390_irq but the full ext substructure is copied
into the cpu local variable on inject. ext_params and pad contain stale
stack values.
Interrupt delivery only uses ext_params2, so nothing leaks to the guest,
but a host user can use the migration ioctls to get to the data.
Fix by zero-initializing the irq struct.
Do the same for the inti data structure.
Fixes: 383d0b050106 ("KVM: s390: handle pending local interrupts via bitmap")
Cc: stable@vger.kernel.org
Signed-off-by: Christian Borntraeger <borntraeger@linux.ibm.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Reviewed-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
Message-ID: <20260805110455.7200-3-borntraeger@linux.ibm.com>
[ Adjusted context for missing inti_mem and ret declarations in __kvm_inject_pfault_token(). ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/s390/kvm/kvm-s390.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--- a/arch/s390/kvm/kvm-s390.c
+++ b/arch/s390/kvm/kvm-s390.c
@@ -4705,8 +4705,8 @@ int kvm_s390_try_set_tod_clock(struct kv
static void __kvm_inject_pfault_token(struct kvm_vcpu *vcpu, bool start_token,
unsigned long token)
{
- struct kvm_s390_interrupt inti;
- struct kvm_s390_irq irq;
+ struct kvm_s390_interrupt inti = {};
+ struct kvm_s390_irq irq = {};
if (start_token) {
irq.u.ext.ext_params2 = token;
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0088/1518] KVM: x86: Extract REGS and SREGS runtime sync code to helpers
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (86 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0087/1518] KVM: s390: Zero initialize data structures for inject_pfault_token Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0089/1518] KVM: x86: Rename __{g,s}et_sregs2() => kvm_vcpu_ioctl_x86_{g,s}et_sregs2() Greg Kroah-Hartman
` (910 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yosry Ahmed, Sean Christopherson,
Kai Huang, Binbin Wu, Paolo Bonzini, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sean Christopherson <seanjc@google.com>
[ Upstream commit 6a8a98aa9c147eb63f5a360f157f207bf46c05ee ]
Extract the REGS and SREGS portions of {store,sync}_regs() into separate
helpers in anticipation of moving the register specific code out of x86.c
and into regs.c.
No functional change intended.
Cc: Yosry Ahmed <yosry@kernel.org>
Signed-off-by: Sean Christopherson <seanjc@google.com>
Reviewed-by: Kai Huang <kai.huang@intel.com>
Reviewed-by: Binbin Wu <binbin.wu@linux.intel.com>
Message-ID: <20260613000329.732085-2-seanjc@google.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Stable-dep-of: 184bd464bdb6 ("KVM: x86: Check EFER validity on KVM_SET_SREGS*")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/kvm/x86.c | 17 +++++++++++++++--
1 file changed, 15 insertions(+), 2 deletions(-)
--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -12627,7 +12627,7 @@ int kvm_arch_vcpu_ioctl_set_fpu(struct k
return 0;
}
-static void store_regs(struct kvm_vcpu *vcpu)
+static void kvm_run_sync_regs_to_user(struct kvm_vcpu *vcpu)
{
BUILD_BUG_ON(sizeof(struct kvm_sync_regs) > SYNC_REGS_SIZE_BYTES);
@@ -12636,13 +12636,18 @@ static void store_regs(struct kvm_vcpu *
if (vcpu->run->kvm_valid_regs & KVM_SYNC_X86_SREGS)
__get_sregs(vcpu, &vcpu->run->s.regs.sregs);
+}
+
+static void store_regs(struct kvm_vcpu *vcpu)
+{
+ kvm_run_sync_regs_to_user(vcpu);
if (vcpu->run->kvm_valid_regs & KVM_SYNC_X86_EVENTS)
kvm_vcpu_ioctl_x86_get_vcpu_events(
vcpu, &vcpu->run->s.regs.events);
}
-static int sync_regs(struct kvm_vcpu *vcpu)
+static int kvm_run_sync_regs_from_user(struct kvm_vcpu *vcpu)
{
if (vcpu->run->kvm_dirty_regs & KVM_SYNC_X86_REGS) {
__set_regs(vcpu, &vcpu->run->s.regs.regs);
@@ -12658,6 +12663,14 @@ static int sync_regs(struct kvm_vcpu *vc
vcpu->run->kvm_dirty_regs &= ~KVM_SYNC_X86_SREGS;
}
+ return 0;
+}
+
+static int sync_regs(struct kvm_vcpu *vcpu)
+{
+ if (kvm_run_sync_regs_from_user(vcpu))
+ return -EINVAL;
+
if (vcpu->run->kvm_dirty_regs & KVM_SYNC_X86_EVENTS) {
struct kvm_vcpu_events events = vcpu->run->s.regs.events;
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0089/1518] KVM: x86: Rename __{g,s}et_sregs2() => kvm_vcpu_ioctl_x86_{g,s}et_sregs2()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (87 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0088/1518] KVM: x86: Extract REGS and SREGS runtime sync code to helpers Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0090/1518] KVM: x86: Move the bulk of register specific code from x86.c to regs.c Greg Kroah-Hartman
` (909 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yosry Ahmed, Sean Christopherson,
Kai Huang, Paolo Bonzini, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sean Christopherson <seanjc@google.com>
[ Upstream commit bd130c8d72a1c7dde5523b3f3fae9867eafaa1dc ]
Rename the KVM_{G,S}ET_SREGS2 helpers in anticipation of moving them out of
x86.c (while leaving the ioctl dispatch behind). Having globally visible
APIs named __{g,s}et_sregs2() would be "fine", but ugly, given that
__{g,s}et_sregs() will NOT be globally visible. As a bonus, this makes it
a bit more obvious that the helpers implement newer versions of
kvm_arch_vcpu_ioctl_set_sregs().
No functional change intended.
Cc: Yosry Ahmed <yosry@kernel.org>
Signed-off-by: Sean Christopherson <seanjc@google.com>
Reviewed-by: Kai Huang <kai.huang@intel.com>
Message-ID: <20260613000329.732085-4-seanjc@google.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Stable-dep-of: 184bd464bdb6 ("KVM: x86: Check EFER validity on KVM_SET_SREGS*")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/kvm/x86.c | 16 ++++++++++------
1 file changed, 10 insertions(+), 6 deletions(-)
--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -124,8 +124,10 @@ static void store_regs(struct kvm_vcpu *
static int sync_regs(struct kvm_vcpu *vcpu);
static int kvm_vcpu_do_singlestep(struct kvm_vcpu *vcpu);
-static int __set_sregs2(struct kvm_vcpu *vcpu, struct kvm_sregs2 *sregs2);
-static void __get_sregs2(struct kvm_vcpu *vcpu, struct kvm_sregs2 *sregs2);
+static int kvm_vcpu_ioctl_x86_set_sregs2(struct kvm_vcpu *vcpu,
+ struct kvm_sregs2 *sregs2);
+static void kvm_vcpu_ioctl_x86_get_sregs2(struct kvm_vcpu *vcpu,
+ struct kvm_sregs2 *sregs2);
static DEFINE_MUTEX(vendor_module_lock);
static void kvm_load_guest_fpu(struct kvm_vcpu *vcpu);
@@ -6653,7 +6655,7 @@ long kvm_arch_vcpu_ioctl(struct file *fi
r = -ENOMEM;
if (!u.sregs2)
goto out;
- __get_sregs2(vcpu, u.sregs2);
+ kvm_vcpu_ioctl_x86_get_sregs2(vcpu, u.sregs2);
r = -EFAULT;
if (copy_to_user(argp, u.sregs2, sizeof(struct kvm_sregs2)))
goto out;
@@ -6672,7 +6674,7 @@ long kvm_arch_vcpu_ioctl(struct file *fi
u.sregs2 = NULL;
goto out;
}
- r = __set_sregs2(vcpu, u.sregs2);
+ r = kvm_vcpu_ioctl_x86_set_sregs2(vcpu, u.sregs2);
break;
}
case KVM_HAS_DEVICE_ATTR:
@@ -12157,7 +12159,8 @@ static void __get_sregs(struct kvm_vcpu
(unsigned long *)sregs->interrupt_bitmap);
}
-static void __get_sregs2(struct kvm_vcpu *vcpu, struct kvm_sregs2 *sregs2)
+static void kvm_vcpu_ioctl_x86_get_sregs2(struct kvm_vcpu *vcpu,
+ struct kvm_sregs2 *sregs2)
{
int i;
@@ -12425,7 +12428,8 @@ static int __set_sregs(struct kvm_vcpu *
return 0;
}
-static int __set_sregs2(struct kvm_vcpu *vcpu, struct kvm_sregs2 *sregs2)
+static int kvm_vcpu_ioctl_x86_set_sregs2(struct kvm_vcpu *vcpu,
+ struct kvm_sregs2 *sregs2)
{
int mmu_reset_needed = 0;
bool valid_pdptrs = sregs2->flags & KVM_SREGS2_FLAGS_PDPTRS_VALID;
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0090/1518] KVM: x86: Move the bulk of register specific code from x86.c to regs.c
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (88 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0089/1518] KVM: x86: Rename __{g,s}et_sregs2() => kvm_vcpu_ioctl_x86_{g,s}et_sregs2() Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0091/1518] KVM: x86: Check EFER validity on KVM_SET_SREGS* Greg Kroah-Hartman
` (908 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kai Huang, Sean Christopherson,
Binbin Wu, Paolo Bonzini, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sean Christopherson <seanjc@google.com>
[ Upstream commit 2f5bb3fe583510cf20f9d64aa73089577be3dc36 ]
Introduce regs.c, and move the vast majority of register specific code out
of x86.c and into regs.c. Deliberately leave behind MSR code, as KVM's MSR
support is complex enough to warrant its own compilation unit, and doesn't
have much in common with the other register code.
Note, "struct kvm_sregs" has fields for EFER and MSR_IA32_APICBASE, and so
the {G,S}ET_REGS flows technically contain a tiny amount of MSR code.
MSR_IA32_APICBASE is already managed by lapic.c, and so doesn't require a
"placement decision". As for EFER, leave all other EFER handling in x86.c
(later to be moved to msrs.c). The primary interface to EFER, set_efer(),
is very much MSR specific, even though EFER is arguably more of a Control
Register than an MSR.
No functional change intended.
Reviewed-by: Kai Huang <kai.huang@intel.com>
Signed-off-by: Sean Christopherson <seanjc@google.com>
Reviewed-by: Binbin Wu <binbin.wu@linux.intel.com>
Message-ID: <20260613000329.732085-5-seanjc@google.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Stable backport notes:
Move the existing 6.18 register implementations, retaining its cached
register accessors, MMU-owned PDPTR array, VCPU_EXREG identifiers, and
kvm_translate_gpa() calling convention. Put cross-file declarations in
x86.h, since this branch still uses kvm_cache_regs.h rather than regs.h.
Keep the RIP/RFLAGS helpers and kvm_post_set_cr0() in x86.c, alongside
their private get_segment_base() and kvm_pv_async_pf_enabled() helpers.
Omit the upstream kvm_get_effective_dr7() header change, which is not
needed by this tree. Preserve all existing function bodies and the
diagnostic prefix; only change linkage where required by the move.
This relocates kvm_is_valid_sregs() to regs.c so that target commit
184bd464bdb66daa9173670904f24c29c7b7f7d4 applies without modification.
[ sashal: Reduced backport -- upstream 2f5bb3fe58351 touches 5 file(s), this
backport carries 4. Not backported here:
arch/x86/kvm/regs.h
This note is generated from the file lists only; see the resolution record
for the reasoning. ]
Stable-dep-of: 184bd464bdb6 ("KVM: x86: Check EFER validity on KVM_SET_SREGS*")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/kvm/Makefile | 4
arch/x86/kvm/regs.c | 786 +++++++++++++++++++++++++++++++++++++++++++++++++
arch/x86/kvm/x86.c | 787 --------------------------------------------------
arch/x86/kvm/x86.h | 16 +
4 files changed, 806 insertions(+), 787 deletions(-)
create mode 100644 arch/x86/kvm/regs.c
--- a/arch/x86/kvm/Makefile
+++ b/arch/x86/kvm/Makefile
@@ -5,8 +5,8 @@ ccflags-$(CONFIG_KVM_WERROR) += -Werror
include $(srctree)/virt/kvm/Makefile.kvm
-kvm-y += x86.o emulate.o irq.o lapic.o cpuid.o pmu.o mtrr.o \
- debugfs.o mmu/mmu.o mmu/page_track.o mmu/spte.o
+kvm-y += x86.o emulate.o irq.o lapic.o cpuid.o pmu.o regs.o \
+ mtrr.o debugfs.o mmu/mmu.o mmu/page_track.o mmu/spte.o
kvm-$(CONFIG_X86_64) += mmu/tdp_iter.o mmu/tdp_mmu.o
kvm-$(CONFIG_KVM_IOAPIC) += i8259.o i8254.o ioapic.o
--- /dev/null
+++ b/arch/x86/kvm/regs.c
@@ -0,0 +1,786 @@
+// SPDX-License-Identifier: GPL-2.0-only
+#define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
+
+#include <linux/kvm_host.h>
+
+#include "lapic.h"
+#include "mmu.h"
+#include "x86.h"
+
+static void __get_regs(struct kvm_vcpu *vcpu, struct kvm_regs *regs)
+{
+ if (vcpu->arch.emulate_regs_need_sync_to_vcpu) {
+ /*
+ * We are here if userspace calls get_regs() in the middle of
+ * instruction emulation. Registers state needs to be copied
+ * back from emulation context to vcpu. Userspace shouldn't do
+ * that usually, but some bad designed PV devices (vmware
+ * backdoor interface) need this to work
+ */
+ emulator_writeback_register_cache(vcpu->arch.emulate_ctxt);
+ vcpu->arch.emulate_regs_need_sync_to_vcpu = false;
+ }
+ regs->rax = kvm_rax_read(vcpu);
+ regs->rbx = kvm_rbx_read(vcpu);
+ regs->rcx = kvm_rcx_read(vcpu);
+ regs->rdx = kvm_rdx_read(vcpu);
+ regs->rsi = kvm_rsi_read(vcpu);
+ regs->rdi = kvm_rdi_read(vcpu);
+ regs->rsp = kvm_rsp_read(vcpu);
+ regs->rbp = kvm_rbp_read(vcpu);
+#ifdef CONFIG_X86_64
+ regs->r8 = kvm_r8_read(vcpu);
+ regs->r9 = kvm_r9_read(vcpu);
+ regs->r10 = kvm_r10_read(vcpu);
+ regs->r11 = kvm_r11_read(vcpu);
+ regs->r12 = kvm_r12_read(vcpu);
+ regs->r13 = kvm_r13_read(vcpu);
+ regs->r14 = kvm_r14_read(vcpu);
+ regs->r15 = kvm_r15_read(vcpu);
+#endif
+
+ regs->rip = kvm_rip_read(vcpu);
+ regs->rflags = kvm_get_rflags(vcpu);
+}
+
+int kvm_arch_vcpu_ioctl_get_regs(struct kvm_vcpu *vcpu, struct kvm_regs *regs)
+{
+ if (vcpu->kvm->arch.has_protected_state &&
+ vcpu->arch.guest_state_protected)
+ return -EINVAL;
+
+ vcpu_load(vcpu);
+ __get_regs(vcpu, regs);
+ vcpu_put(vcpu);
+ return 0;
+}
+
+static void __set_regs(struct kvm_vcpu *vcpu, struct kvm_regs *regs)
+{
+ vcpu->arch.emulate_regs_need_sync_from_vcpu = true;
+ vcpu->arch.emulate_regs_need_sync_to_vcpu = false;
+
+ kvm_rax_write(vcpu, regs->rax);
+ kvm_rbx_write(vcpu, regs->rbx);
+ kvm_rcx_write(vcpu, regs->rcx);
+ kvm_rdx_write(vcpu, regs->rdx);
+ kvm_rsi_write(vcpu, regs->rsi);
+ kvm_rdi_write(vcpu, regs->rdi);
+ kvm_rsp_write(vcpu, regs->rsp);
+ kvm_rbp_write(vcpu, regs->rbp);
+#ifdef CONFIG_X86_64
+ kvm_r8_write(vcpu, regs->r8);
+ kvm_r9_write(vcpu, regs->r9);
+ kvm_r10_write(vcpu, regs->r10);
+ kvm_r11_write(vcpu, regs->r11);
+ kvm_r12_write(vcpu, regs->r12);
+ kvm_r13_write(vcpu, regs->r13);
+ kvm_r14_write(vcpu, regs->r14);
+ kvm_r15_write(vcpu, regs->r15);
+#endif
+
+ kvm_rip_write(vcpu, regs->rip);
+ kvm_set_rflags(vcpu, regs->rflags | X86_EFLAGS_FIXED);
+
+ vcpu->arch.exception.pending = false;
+ vcpu->arch.exception_vmexit.pending = false;
+
+ kvm_make_request(KVM_REQ_EVENT, vcpu);
+}
+
+int kvm_arch_vcpu_ioctl_set_regs(struct kvm_vcpu *vcpu, struct kvm_regs *regs)
+{
+ if (vcpu->kvm->arch.has_protected_state &&
+ vcpu->arch.guest_state_protected)
+ return -EINVAL;
+
+ vcpu_load(vcpu);
+ __set_regs(vcpu, regs);
+ vcpu_put(vcpu);
+ return 0;
+}
+
+static inline u64 pdptr_rsvd_bits(struct kvm_vcpu *vcpu)
+{
+ return vcpu->arch.reserved_gpa_bits | rsvd_bits(5, 8) | rsvd_bits(1, 2);
+}
+
+/*
+ * Load the pae pdptrs. Return 1 if they are all valid, 0 otherwise.
+ */
+int load_pdptrs(struct kvm_vcpu *vcpu, unsigned long cr3)
+{
+ struct kvm_mmu *mmu = vcpu->arch.walk_mmu;
+ gfn_t pdpt_gfn = cr3 >> PAGE_SHIFT;
+ gpa_t real_gpa;
+ int i;
+ int ret;
+ u64 pdpte[ARRAY_SIZE(mmu->pdptrs)];
+
+ /*
+ * If the MMU is nested, CR3 holds an L2 GPA and needs to be translated
+ * to an L1 GPA.
+ */
+ real_gpa = kvm_translate_gpa(vcpu, mmu, gfn_to_gpa(pdpt_gfn),
+ PFERR_USER_MASK | PFERR_WRITE_MASK, NULL);
+ if (real_gpa == INVALID_GPA)
+ return 0;
+
+ /* Note the offset, PDPTRs are 32 byte aligned when using PAE paging. */
+ ret = kvm_vcpu_read_guest_page(vcpu, gpa_to_gfn(real_gpa), pdpte,
+ cr3 & GENMASK(11, 5), sizeof(pdpte));
+ if (ret < 0)
+ return 0;
+
+ for (i = 0; i < ARRAY_SIZE(pdpte); ++i) {
+ if ((pdpte[i] & PT_PRESENT_MASK) &&
+ (pdpte[i] & pdptr_rsvd_bits(vcpu))) {
+ return 0;
+ }
+ }
+
+ /*
+ * Marking VCPU_EXREG_PDPTR dirty doesn't work for !tdp_enabled.
+ * Shadow page roots need to be reconstructed instead.
+ */
+ if (!tdp_enabled && memcmp(mmu->pdptrs, pdpte, sizeof(mmu->pdptrs)))
+ kvm_mmu_free_roots(vcpu->kvm, mmu, KVM_MMU_ROOT_CURRENT);
+
+ memcpy(mmu->pdptrs, pdpte, sizeof(mmu->pdptrs));
+ kvm_register_mark_dirty(vcpu, VCPU_EXREG_PDPTR);
+ kvm_make_request(KVM_REQ_LOAD_MMU_PGD, vcpu);
+ vcpu->arch.pdptrs_from_userspace = false;
+
+ return 1;
+}
+EXPORT_SYMBOL_FOR_KVM_INTERNAL(load_pdptrs);
+
+static bool kvm_is_valid_cr0(struct kvm_vcpu *vcpu, unsigned long cr0)
+{
+#ifdef CONFIG_X86_64
+ if (cr0 & 0xffffffff00000000UL)
+ return false;
+#endif
+
+ if ((cr0 & X86_CR0_NW) && !(cr0 & X86_CR0_CD))
+ return false;
+
+ if ((cr0 & X86_CR0_PG) && !(cr0 & X86_CR0_PE))
+ return false;
+
+ return kvm_x86_call(is_valid_cr0)(vcpu, cr0);
+}
+
+int kvm_set_cr0(struct kvm_vcpu *vcpu, unsigned long cr0)
+{
+ unsigned long old_cr0 = kvm_read_cr0(vcpu);
+
+ if (!kvm_is_valid_cr0(vcpu, cr0))
+ return 1;
+
+ cr0 |= X86_CR0_ET;
+
+ /* Write to CR0 reserved bits are ignored, even on Intel. */
+ cr0 &= ~CR0_RESERVED_BITS;
+
+#ifdef CONFIG_X86_64
+ if ((vcpu->arch.efer & EFER_LME) && !is_paging(vcpu) &&
+ (cr0 & X86_CR0_PG)) {
+ int cs_db, cs_l;
+
+ if (!is_pae(vcpu))
+ return 1;
+ kvm_x86_call(get_cs_db_l_bits)(vcpu, &cs_db, &cs_l);
+ if (cs_l)
+ return 1;
+ }
+#endif
+ if (!(vcpu->arch.efer & EFER_LME) && (cr0 & X86_CR0_PG) &&
+ is_pae(vcpu) && ((cr0 ^ old_cr0) & X86_CR0_PDPTR_BITS) &&
+ !load_pdptrs(vcpu, kvm_read_cr3(vcpu)))
+ return 1;
+
+ if (!(cr0 & X86_CR0_PG) &&
+ (is_64_bit_mode(vcpu) || kvm_is_cr4_bit_set(vcpu, X86_CR4_PCIDE)))
+ return 1;
+
+ if (!(cr0 & X86_CR0_WP) && kvm_is_cr4_bit_set(vcpu, X86_CR4_CET))
+ return 1;
+
+ kvm_x86_call(set_cr0)(vcpu, cr0);
+
+ kvm_post_set_cr0(vcpu, old_cr0, cr0);
+
+ return 0;
+}
+EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_set_cr0);
+
+void kvm_lmsw(struct kvm_vcpu *vcpu, unsigned long msw)
+{
+ (void)kvm_set_cr0(vcpu, kvm_read_cr0_bits(vcpu, ~0x0eul) | (msw & 0x0f));
+}
+EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_lmsw);
+
+int kvm_set_cr3(struct kvm_vcpu *vcpu, unsigned long cr3)
+{
+ bool skip_tlb_flush = false;
+ unsigned long pcid = 0;
+#ifdef CONFIG_X86_64
+ if (kvm_is_cr4_bit_set(vcpu, X86_CR4_PCIDE)) {
+ skip_tlb_flush = cr3 & X86_CR3_PCID_NOFLUSH;
+ cr3 &= ~X86_CR3_PCID_NOFLUSH;
+ pcid = cr3 & X86_CR3_PCID_MASK;
+ }
+#endif
+
+ /* PDPTRs are always reloaded for PAE paging. */
+ if (cr3 == kvm_read_cr3(vcpu) && !is_pae_paging(vcpu))
+ goto handle_tlb_flush;
+
+ /*
+ * Do not condition the GPA check on long mode, this helper is used to
+ * stuff CR3, e.g. for RSM emulation, and there is no guarantee that
+ * the current vCPU mode is accurate.
+ */
+ if (!kvm_vcpu_is_legal_cr3(vcpu, cr3))
+ return 1;
+
+ if (is_pae_paging(vcpu) && !load_pdptrs(vcpu, cr3))
+ return 1;
+
+ if (cr3 != kvm_read_cr3(vcpu))
+ kvm_mmu_new_pgd(vcpu, cr3);
+
+ vcpu->arch.cr3 = cr3;
+ kvm_register_mark_dirty(vcpu, VCPU_EXREG_CR3);
+ /* Do not call post_set_cr3, we do not get here for confidential guests. */
+
+handle_tlb_flush:
+ /*
+ * A load of CR3 that flushes the TLB flushes only the current PCID,
+ * even if PCID is disabled, in which case PCID=0 is flushed. It's a
+ * moot point in the end because _disabling_ PCID will flush all PCIDs,
+ * and it's impossible to use a non-zero PCID when PCID is disabled,
+ * i.e. only PCID=0 can be relevant.
+ */
+ if (!skip_tlb_flush)
+ kvm_invalidate_pcid(vcpu, pcid);
+
+ return 0;
+}
+EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_set_cr3);
+
+static bool kvm_is_valid_cr4(struct kvm_vcpu *vcpu, unsigned long cr4)
+{
+ return __kvm_is_valid_cr4(vcpu, cr4) &&
+ kvm_x86_call(is_valid_cr4)(vcpu, cr4);
+}
+
+void kvm_post_set_cr4(struct kvm_vcpu *vcpu, unsigned long old_cr4, unsigned long cr4)
+{
+ if ((cr4 ^ old_cr4) & KVM_MMU_CR4_ROLE_BITS)
+ kvm_mmu_reset_context(vcpu);
+
+ /*
+ * If CR4.PCIDE is changed 0 -> 1, there is no need to flush the TLB
+ * according to the SDM; however, stale prev_roots could be reused
+ * incorrectly in the future after a MOV to CR3 with NOFLUSH=1, so we
+ * free them all. This is *not* a superset of KVM_REQ_TLB_FLUSH_GUEST
+ * or KVM_REQ_TLB_FLUSH_CURRENT, because the hardware TLB is not flushed,
+ * so fall through.
+ */
+ if (!tdp_enabled &&
+ (cr4 & X86_CR4_PCIDE) && !(old_cr4 & X86_CR4_PCIDE))
+ kvm_mmu_unload(vcpu);
+
+ /*
+ * The TLB has to be flushed for all PCIDs if any of the following
+ * (architecturally required) changes happen:
+ * - CR4.PCIDE is changed from 1 to 0
+ * - CR4.PGE is toggled
+ *
+ * This is a superset of KVM_REQ_TLB_FLUSH_CURRENT.
+ */
+ if (((cr4 ^ old_cr4) & X86_CR4_PGE) ||
+ (!(cr4 & X86_CR4_PCIDE) && (old_cr4 & X86_CR4_PCIDE)))
+ kvm_make_request(KVM_REQ_TLB_FLUSH_GUEST, vcpu);
+
+ /*
+ * The TLB has to be flushed for the current PCID if any of the
+ * following (architecturally required) changes happen:
+ * - CR4.SMEP is changed from 0 to 1
+ * - CR4.PAE is toggled
+ */
+ else if (((cr4 ^ old_cr4) & X86_CR4_PAE) ||
+ ((cr4 & X86_CR4_SMEP) && !(old_cr4 & X86_CR4_SMEP)))
+ kvm_make_request(KVM_REQ_TLB_FLUSH_CURRENT, vcpu);
+
+}
+EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_post_set_cr4);
+
+int kvm_set_cr4(struct kvm_vcpu *vcpu, unsigned long cr4)
+{
+ unsigned long old_cr4 = kvm_read_cr4(vcpu);
+
+ if (!kvm_is_valid_cr4(vcpu, cr4))
+ return 1;
+
+ if (is_long_mode(vcpu)) {
+ if (!(cr4 & X86_CR4_PAE))
+ return 1;
+ if ((cr4 ^ old_cr4) & X86_CR4_LA57)
+ return 1;
+ } else if (is_paging(vcpu) && (cr4 & X86_CR4_PAE)
+ && ((cr4 ^ old_cr4) & X86_CR4_PDPTR_BITS)
+ && !load_pdptrs(vcpu, kvm_read_cr3(vcpu)))
+ return 1;
+
+ if ((cr4 & X86_CR4_PCIDE) && !(old_cr4 & X86_CR4_PCIDE)) {
+ /* PCID can not be enabled when cr3[11:0]!=000H or EFER.LMA=0 */
+ if ((kvm_read_cr3(vcpu) & X86_CR3_PCID_MASK) || !is_long_mode(vcpu))
+ return 1;
+ }
+
+ if ((cr4 & X86_CR4_CET) && !kvm_is_cr0_bit_set(vcpu, X86_CR0_WP))
+ return 1;
+
+ kvm_x86_call(set_cr4)(vcpu, cr4);
+
+ kvm_post_set_cr4(vcpu, old_cr4, cr4);
+
+ return 0;
+}
+EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_set_cr4);
+
+int kvm_set_cr8(struct kvm_vcpu *vcpu, unsigned long cr8)
+{
+ if (cr8 & CR8_RESERVED_BITS)
+ return 1;
+ if (lapic_in_kernel(vcpu))
+ kvm_lapic_set_tpr(vcpu, cr8);
+ else
+ vcpu->arch.cr8 = cr8;
+ return 0;
+}
+EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_set_cr8);
+
+unsigned long kvm_get_cr8(struct kvm_vcpu *vcpu)
+{
+ if (lapic_in_kernel(vcpu))
+ return kvm_lapic_get_cr8(vcpu);
+ else
+ return vcpu->arch.cr8;
+}
+EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_get_cr8);
+
+static void __get_sregs_common(struct kvm_vcpu *vcpu, struct kvm_sregs *sregs)
+{
+ struct desc_ptr dt;
+
+ if (vcpu->arch.guest_state_protected)
+ goto skip_protected_regs;
+
+ kvm_handle_exception_payload_quirk(vcpu);
+
+ kvm_get_segment(vcpu, &sregs->cs, VCPU_SREG_CS);
+ kvm_get_segment(vcpu, &sregs->ds, VCPU_SREG_DS);
+ kvm_get_segment(vcpu, &sregs->es, VCPU_SREG_ES);
+ kvm_get_segment(vcpu, &sregs->fs, VCPU_SREG_FS);
+ kvm_get_segment(vcpu, &sregs->gs, VCPU_SREG_GS);
+ kvm_get_segment(vcpu, &sregs->ss, VCPU_SREG_SS);
+
+ kvm_get_segment(vcpu, &sregs->tr, VCPU_SREG_TR);
+ kvm_get_segment(vcpu, &sregs->ldt, VCPU_SREG_LDTR);
+
+ kvm_x86_call(get_idt)(vcpu, &dt);
+ sregs->idt.limit = dt.size;
+ sregs->idt.base = dt.address;
+ kvm_x86_call(get_gdt)(vcpu, &dt);
+ sregs->gdt.limit = dt.size;
+ sregs->gdt.base = dt.address;
+
+ sregs->cr2 = vcpu->arch.cr2;
+ sregs->cr3 = kvm_read_cr3(vcpu);
+
+skip_protected_regs:
+ sregs->cr0 = kvm_read_cr0(vcpu);
+ sregs->cr4 = kvm_read_cr4(vcpu);
+ sregs->cr8 = kvm_get_cr8(vcpu);
+ sregs->efer = vcpu->arch.efer;
+ sregs->apic_base = vcpu->arch.apic_base;
+}
+
+static void __get_sregs(struct kvm_vcpu *vcpu, struct kvm_sregs *sregs)
+{
+ __get_sregs_common(vcpu, sregs);
+
+ if (vcpu->arch.guest_state_protected)
+ return;
+
+ if (vcpu->arch.interrupt.injected && !vcpu->arch.interrupt.soft)
+ set_bit(vcpu->arch.interrupt.nr,
+ (unsigned long *)sregs->interrupt_bitmap);
+}
+
+int kvm_arch_vcpu_ioctl_get_sregs(struct kvm_vcpu *vcpu,
+ struct kvm_sregs *sregs)
+{
+ if (vcpu->kvm->arch.has_protected_state &&
+ vcpu->arch.guest_state_protected)
+ return -EINVAL;
+
+ vcpu_load(vcpu);
+ __get_sregs(vcpu, sregs);
+ vcpu_put(vcpu);
+ return 0;
+}
+
+void kvm_vcpu_ioctl_x86_get_sregs2(struct kvm_vcpu *vcpu,
+ struct kvm_sregs2 *sregs2)
+{
+ int i;
+
+ __get_sregs_common(vcpu, (struct kvm_sregs *)sregs2);
+
+ if (vcpu->arch.guest_state_protected)
+ return;
+
+ if (is_pae_paging(vcpu)) {
+ kvm_vcpu_srcu_read_lock(vcpu);
+ for (i = 0 ; i < 4 ; i++)
+ sregs2->pdptrs[i] = kvm_pdptr_read(vcpu, i);
+ sregs2->flags |= KVM_SREGS2_FLAGS_PDPTRS_VALID;
+ kvm_vcpu_srcu_read_unlock(vcpu);
+ }
+}
+
+static bool kvm_is_valid_sregs(struct kvm_vcpu *vcpu, struct kvm_sregs *sregs)
+{
+ if ((sregs->efer & EFER_LME) && (sregs->cr0 & X86_CR0_PG)) {
+ /*
+ * When EFER.LME and CR0.PG are set, the processor is in
+ * 64-bit mode (though maybe in a 32-bit code segment).
+ * CR4.PAE and EFER.LMA must be set.
+ */
+ if (!(sregs->cr4 & X86_CR4_PAE) || !(sregs->efer & EFER_LMA))
+ return false;
+ if (!kvm_vcpu_is_legal_cr3(vcpu, sregs->cr3))
+ return false;
+ } else {
+ /*
+ * Not in 64-bit mode: EFER.LMA is clear and the code
+ * segment cannot be 64-bit.
+ */
+ if (sregs->efer & EFER_LMA || sregs->cs.l)
+ return false;
+ }
+
+ return kvm_is_valid_cr4(vcpu, sregs->cr4) &&
+ kvm_is_valid_cr0(vcpu, sregs->cr0);
+}
+
+static int __set_sregs_common(struct kvm_vcpu *vcpu, struct kvm_sregs *sregs,
+ int *mmu_reset_needed, bool update_pdptrs)
+{
+ int idx;
+ struct desc_ptr dt;
+
+ if (!kvm_is_valid_sregs(vcpu, sregs))
+ return -EINVAL;
+
+ if (kvm_apic_set_base(vcpu, sregs->apic_base, true))
+ return -EINVAL;
+
+ if (vcpu->arch.guest_state_protected)
+ return 0;
+
+ dt.size = sregs->idt.limit;
+ dt.address = sregs->idt.base;
+ kvm_x86_call(set_idt)(vcpu, &dt);
+ dt.size = sregs->gdt.limit;
+ dt.address = sregs->gdt.base;
+ kvm_x86_call(set_gdt)(vcpu, &dt);
+
+ vcpu->arch.cr2 = sregs->cr2;
+ *mmu_reset_needed |= kvm_read_cr3(vcpu) != sregs->cr3;
+ vcpu->arch.cr3 = sregs->cr3;
+ kvm_register_mark_dirty(vcpu, VCPU_EXREG_CR3);
+ kvm_x86_call(post_set_cr3)(vcpu, sregs->cr3);
+
+ *mmu_reset_needed |= vcpu->arch.efer != sregs->efer;
+ kvm_x86_call(set_efer)(vcpu, sregs->efer);
+
+ *mmu_reset_needed |= kvm_read_cr0(vcpu) != sregs->cr0;
+ kvm_x86_call(set_cr0)(vcpu, sregs->cr0);
+
+ *mmu_reset_needed |= kvm_read_cr4(vcpu) != sregs->cr4;
+ kvm_x86_call(set_cr4)(vcpu, sregs->cr4);
+
+ if (update_pdptrs) {
+ idx = srcu_read_lock(&vcpu->kvm->srcu);
+ if (is_pae_paging(vcpu)) {
+ load_pdptrs(vcpu, kvm_read_cr3(vcpu));
+ *mmu_reset_needed = 1;
+ }
+ srcu_read_unlock(&vcpu->kvm->srcu, idx);
+ }
+
+ kvm_set_segment(vcpu, &sregs->cs, VCPU_SREG_CS);
+ kvm_set_segment(vcpu, &sregs->ds, VCPU_SREG_DS);
+ kvm_set_segment(vcpu, &sregs->es, VCPU_SREG_ES);
+ kvm_set_segment(vcpu, &sregs->fs, VCPU_SREG_FS);
+ kvm_set_segment(vcpu, &sregs->gs, VCPU_SREG_GS);
+ kvm_set_segment(vcpu, &sregs->ss, VCPU_SREG_SS);
+
+ kvm_set_segment(vcpu, &sregs->tr, VCPU_SREG_TR);
+ kvm_set_segment(vcpu, &sregs->ldt, VCPU_SREG_LDTR);
+
+ kvm_set_cr8(vcpu, sregs->cr8);
+
+ /* Older userspace won't unhalt the vcpu on reset. */
+ if (kvm_vcpu_is_bsp(vcpu) && kvm_rip_read(vcpu) == 0xfff0 &&
+ sregs->cs.selector == 0xf000 && sregs->cs.base == 0xffff0000 &&
+ !is_protmode(vcpu))
+ kvm_set_mp_state(vcpu, KVM_MP_STATE_RUNNABLE);
+
+ return 0;
+}
+
+static int __set_sregs(struct kvm_vcpu *vcpu, struct kvm_sregs *sregs)
+{
+ int pending_vec, max_bits;
+ int mmu_reset_needed = 0;
+ int ret = __set_sregs_common(vcpu, sregs, &mmu_reset_needed, true);
+
+ if (ret)
+ return ret;
+
+ if (mmu_reset_needed) {
+ kvm_mmu_reset_context(vcpu);
+ kvm_make_request(KVM_REQ_TLB_FLUSH_GUEST, vcpu);
+ }
+
+ max_bits = KVM_NR_INTERRUPTS;
+ pending_vec = find_first_bit(
+ (const unsigned long *)sregs->interrupt_bitmap, max_bits);
+
+ if (pending_vec < max_bits) {
+ kvm_queue_interrupt(vcpu, pending_vec, false);
+ pr_debug("Set back pending irq %d\n", pending_vec);
+ kvm_make_request(KVM_REQ_EVENT, vcpu);
+ }
+ return 0;
+}
+
+int kvm_arch_vcpu_ioctl_set_sregs(struct kvm_vcpu *vcpu,
+ struct kvm_sregs *sregs)
+{
+ int ret;
+
+ if (vcpu->kvm->arch.has_protected_state &&
+ vcpu->arch.guest_state_protected)
+ return -EINVAL;
+
+ vcpu_load(vcpu);
+ ret = __set_sregs(vcpu, sregs);
+ vcpu_put(vcpu);
+ return ret;
+}
+
+int kvm_vcpu_ioctl_x86_set_sregs2(struct kvm_vcpu *vcpu,
+ struct kvm_sregs2 *sregs2)
+{
+ int mmu_reset_needed = 0;
+ bool valid_pdptrs = sregs2->flags & KVM_SREGS2_FLAGS_PDPTRS_VALID;
+ bool pae = (sregs2->cr0 & X86_CR0_PG) && (sregs2->cr4 & X86_CR4_PAE) &&
+ !(sregs2->efer & EFER_LMA);
+ int i, ret;
+
+ if (sregs2->flags & ~KVM_SREGS2_FLAGS_PDPTRS_VALID)
+ return -EINVAL;
+
+ if (valid_pdptrs && (!pae || vcpu->arch.guest_state_protected))
+ return -EINVAL;
+
+ ret = __set_sregs_common(vcpu, (struct kvm_sregs *)sregs2,
+ &mmu_reset_needed, !valid_pdptrs);
+ if (ret)
+ return ret;
+
+ if (valid_pdptrs) {
+ for (i = 0; i < 4 ; i++)
+ kvm_pdptr_write(vcpu, i, sregs2->pdptrs[i]);
+
+ kvm_register_mark_dirty(vcpu, VCPU_EXREG_PDPTR);
+ mmu_reset_needed = 1;
+ vcpu->arch.pdptrs_from_userspace = true;
+ }
+ if (mmu_reset_needed) {
+ kvm_mmu_reset_context(vcpu);
+ kvm_make_request(KVM_REQ_TLB_FLUSH_GUEST, vcpu);
+ }
+ return 0;
+}
+
+void kvm_run_sync_regs_to_user(struct kvm_vcpu *vcpu)
+{
+ BUILD_BUG_ON(sizeof(struct kvm_sync_regs) > SYNC_REGS_SIZE_BYTES);
+
+ if (vcpu->run->kvm_valid_regs & KVM_SYNC_X86_REGS)
+ __get_regs(vcpu, &vcpu->run->s.regs.regs);
+
+ if (vcpu->run->kvm_valid_regs & KVM_SYNC_X86_SREGS)
+ __get_sregs(vcpu, &vcpu->run->s.regs.sregs);
+}
+
+int kvm_run_sync_regs_from_user(struct kvm_vcpu *vcpu)
+{
+ if (vcpu->run->kvm_dirty_regs & KVM_SYNC_X86_REGS) {
+ __set_regs(vcpu, &vcpu->run->s.regs.regs);
+ vcpu->run->kvm_dirty_regs &= ~KVM_SYNC_X86_REGS;
+ }
+
+ if (vcpu->run->kvm_dirty_regs & KVM_SYNC_X86_SREGS) {
+ struct kvm_sregs sregs = vcpu->run->s.regs.sregs;
+
+ if (__set_sregs(vcpu, &sregs))
+ return -EINVAL;
+
+ vcpu->run->kvm_dirty_regs &= ~KVM_SYNC_X86_SREGS;
+ }
+
+ return 0;
+}
+
+void kvm_update_dr0123(struct kvm_vcpu *vcpu)
+{
+ int i;
+
+ if (!(vcpu->guest_debug & KVM_GUESTDBG_USE_HW_BP)) {
+ for (i = 0; i < KVM_NR_DB_REGS; i++)
+ vcpu->arch.eff_db[i] = vcpu->arch.db[i];
+ }
+}
+
+void kvm_update_dr7(struct kvm_vcpu *vcpu)
+{
+ unsigned long dr7;
+
+ if (vcpu->guest_debug & KVM_GUESTDBG_USE_HW_BP)
+ dr7 = vcpu->arch.guest_debug_dr7;
+ else
+ dr7 = vcpu->arch.dr7;
+ kvm_x86_call(set_dr7)(vcpu, dr7);
+ vcpu->arch.switch_db_regs &= ~KVM_DEBUGREG_BP_ENABLED;
+ if (dr7 & DR7_BP_EN_MASK)
+ vcpu->arch.switch_db_regs |= KVM_DEBUGREG_BP_ENABLED;
+}
+EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_update_dr7);
+
+static u64 kvm_dr6_fixed(struct kvm_vcpu *vcpu)
+{
+ u64 fixed = DR6_FIXED_1;
+
+ if (!guest_cpu_cap_has(vcpu, X86_FEATURE_RTM))
+ fixed |= DR6_RTM;
+
+ if (!guest_cpu_cap_has(vcpu, X86_FEATURE_BUS_LOCK_DETECT))
+ fixed |= DR6_BUS_LOCK;
+ return fixed;
+}
+
+int kvm_set_dr(struct kvm_vcpu *vcpu, int dr, unsigned long val)
+{
+ size_t size = ARRAY_SIZE(vcpu->arch.db);
+
+ switch (dr) {
+ case 0 ... 3:
+ vcpu->arch.db[array_index_nospec(dr, size)] = val;
+ if (!(vcpu->guest_debug & KVM_GUESTDBG_USE_HW_BP))
+ vcpu->arch.eff_db[dr] = val;
+ break;
+ case 4:
+ case 6:
+ if (!kvm_dr6_valid(val))
+ return 1; /* #GP */
+ vcpu->arch.dr6 = (val & DR6_VOLATILE) | kvm_dr6_fixed(vcpu);
+ break;
+ case 5:
+ default: /* 7 */
+ if (!kvm_dr7_valid(val))
+ return 1; /* #GP */
+ vcpu->arch.dr7 = (val & DR7_VOLATILE) | DR7_FIXED_1;
+ kvm_update_dr7(vcpu);
+ break;
+ }
+
+ return 0;
+}
+EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_set_dr);
+
+unsigned long kvm_get_dr(struct kvm_vcpu *vcpu, int dr)
+{
+ size_t size = ARRAY_SIZE(vcpu->arch.db);
+
+ switch (dr) {
+ case 0 ... 3:
+ return vcpu->arch.db[array_index_nospec(dr, size)];
+ case 4:
+ case 6:
+ return vcpu->arch.dr6;
+ case 5:
+ default: /* 7 */
+ return vcpu->arch.dr7;
+ }
+}
+EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_get_dr);
+
+int kvm_vcpu_ioctl_x86_get_debugregs(struct kvm_vcpu *vcpu,
+ struct kvm_debugregs *dbgregs)
+{
+ unsigned int i;
+
+ if (vcpu->kvm->arch.has_protected_state &&
+ vcpu->arch.guest_state_protected)
+ return -EINVAL;
+
+ kvm_handle_exception_payload_quirk(vcpu);
+
+ memset(dbgregs, 0, sizeof(*dbgregs));
+
+ BUILD_BUG_ON(ARRAY_SIZE(vcpu->arch.db) != ARRAY_SIZE(dbgregs->db));
+ for (i = 0; i < ARRAY_SIZE(vcpu->arch.db); i++)
+ dbgregs->db[i] = vcpu->arch.db[i];
+
+ dbgregs->dr6 = vcpu->arch.dr6;
+ dbgregs->dr7 = vcpu->arch.dr7;
+ return 0;
+}
+
+int kvm_vcpu_ioctl_x86_set_debugregs(struct kvm_vcpu *vcpu,
+ struct kvm_debugregs *dbgregs)
+{
+ unsigned int i;
+
+ if (vcpu->kvm->arch.has_protected_state &&
+ vcpu->arch.guest_state_protected)
+ return -EINVAL;
+
+ if (dbgregs->flags)
+ return -EINVAL;
+
+ if (!kvm_dr6_valid(dbgregs->dr6))
+ return -EINVAL;
+ if (!kvm_dr7_valid(dbgregs->dr7))
+ return -EINVAL;
+
+ for (i = 0; i < ARRAY_SIZE(vcpu->arch.db); i++)
+ vcpu->arch.db[i] = dbgregs->db[i];
+
+ kvm_update_dr0123(vcpu);
+ vcpu->arch.dr6 = dbgregs->dr6;
+ vcpu->arch.dr7 = dbgregs->dr7;
+ kvm_update_dr7(vcpu);
+
+ return 0;
+}
--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -124,11 +124,6 @@ static void store_regs(struct kvm_vcpu *
static int sync_regs(struct kvm_vcpu *vcpu);
static int kvm_vcpu_do_singlestep(struct kvm_vcpu *vcpu);
-static int kvm_vcpu_ioctl_x86_set_sregs2(struct kvm_vcpu *vcpu,
- struct kvm_sregs2 *sregs2);
-static void kvm_vcpu_ioctl_x86_get_sregs2(struct kvm_vcpu *vcpu,
- struct kvm_sregs2 *sregs2);
-
static DEFINE_MUTEX(vendor_module_lock);
static void kvm_load_guest_fpu(struct kvm_vcpu *vcpu);
static void kvm_put_guest_fpu(struct kvm_vcpu *vcpu);
@@ -1038,77 +1033,6 @@ static bool kvm_pv_async_pf_enabled(stru
return (vcpu->arch.apf.msr_en_val & mask) == mask;
}
-static inline u64 pdptr_rsvd_bits(struct kvm_vcpu *vcpu)
-{
- return vcpu->arch.reserved_gpa_bits | rsvd_bits(5, 8) | rsvd_bits(1, 2);
-}
-
-/*
- * Load the pae pdptrs. Return 1 if they are all valid, 0 otherwise.
- */
-int load_pdptrs(struct kvm_vcpu *vcpu, unsigned long cr3)
-{
- struct kvm_mmu *mmu = vcpu->arch.walk_mmu;
- gfn_t pdpt_gfn = cr3 >> PAGE_SHIFT;
- gpa_t real_gpa;
- int i;
- int ret;
- u64 pdpte[ARRAY_SIZE(mmu->pdptrs)];
-
- /*
- * If the MMU is nested, CR3 holds an L2 GPA and needs to be translated
- * to an L1 GPA.
- */
- real_gpa = kvm_translate_gpa(vcpu, mmu, gfn_to_gpa(pdpt_gfn),
- PFERR_USER_MASK | PFERR_WRITE_MASK, NULL);
- if (real_gpa == INVALID_GPA)
- return 0;
-
- /* Note the offset, PDPTRs are 32 byte aligned when using PAE paging. */
- ret = kvm_vcpu_read_guest_page(vcpu, gpa_to_gfn(real_gpa), pdpte,
- cr3 & GENMASK(11, 5), sizeof(pdpte));
- if (ret < 0)
- return 0;
-
- for (i = 0; i < ARRAY_SIZE(pdpte); ++i) {
- if ((pdpte[i] & PT_PRESENT_MASK) &&
- (pdpte[i] & pdptr_rsvd_bits(vcpu))) {
- return 0;
- }
- }
-
- /*
- * Marking VCPU_EXREG_PDPTR dirty doesn't work for !tdp_enabled.
- * Shadow page roots need to be reconstructed instead.
- */
- if (!tdp_enabled && memcmp(mmu->pdptrs, pdpte, sizeof(mmu->pdptrs)))
- kvm_mmu_free_roots(vcpu->kvm, mmu, KVM_MMU_ROOT_CURRENT);
-
- memcpy(mmu->pdptrs, pdpte, sizeof(mmu->pdptrs));
- kvm_register_mark_dirty(vcpu, VCPU_EXREG_PDPTR);
- kvm_make_request(KVM_REQ_LOAD_MMU_PGD, vcpu);
- vcpu->arch.pdptrs_from_userspace = false;
-
- return 1;
-}
-EXPORT_SYMBOL_FOR_KVM_INTERNAL(load_pdptrs);
-
-static bool kvm_is_valid_cr0(struct kvm_vcpu *vcpu, unsigned long cr0)
-{
-#ifdef CONFIG_X86_64
- if (cr0 & 0xffffffff00000000UL)
- return false;
-#endif
-
- if ((cr0 & X86_CR0_NW) && !(cr0 & X86_CR0_CD))
- return false;
-
- if ((cr0 & X86_CR0_PG) && !(cr0 & X86_CR0_PE))
- return false;
-
- return kvm_x86_call(is_valid_cr0)(vcpu, cr0);
-}
-
void kvm_post_set_cr0(struct kvm_vcpu *vcpu, unsigned long old_cr0, unsigned long cr0)
{
/*
@@ -1151,56 +1075,6 @@ void kvm_post_set_cr0(struct kvm_vcpu *v
}
EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_post_set_cr0);
-int kvm_set_cr0(struct kvm_vcpu *vcpu, unsigned long cr0)
-{
- unsigned long old_cr0 = kvm_read_cr0(vcpu);
-
- if (!kvm_is_valid_cr0(vcpu, cr0))
- return 1;
-
- cr0 |= X86_CR0_ET;
-
- /* Write to CR0 reserved bits are ignored, even on Intel. */
- cr0 &= ~CR0_RESERVED_BITS;
-
-#ifdef CONFIG_X86_64
- if ((vcpu->arch.efer & EFER_LME) && !is_paging(vcpu) &&
- (cr0 & X86_CR0_PG)) {
- int cs_db, cs_l;
-
- if (!is_pae(vcpu))
- return 1;
- kvm_x86_call(get_cs_db_l_bits)(vcpu, &cs_db, &cs_l);
- if (cs_l)
- return 1;
- }
-#endif
- if (!(vcpu->arch.efer & EFER_LME) && (cr0 & X86_CR0_PG) &&
- is_pae(vcpu) && ((cr0 ^ old_cr0) & X86_CR0_PDPTR_BITS) &&
- !load_pdptrs(vcpu, kvm_read_cr3(vcpu)))
- return 1;
-
- if (!(cr0 & X86_CR0_PG) &&
- (is_64_bit_mode(vcpu) || kvm_is_cr4_bit_set(vcpu, X86_CR4_PCIDE)))
- return 1;
-
- if (!(cr0 & X86_CR0_WP) && kvm_is_cr4_bit_set(vcpu, X86_CR4_CET))
- return 1;
-
- kvm_x86_call(set_cr0)(vcpu, cr0);
-
- kvm_post_set_cr0(vcpu, old_cr0, cr0);
-
- return 0;
-}
-EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_set_cr0);
-
-void kvm_lmsw(struct kvm_vcpu *vcpu, unsigned long msw)
-{
- (void)kvm_set_cr0(vcpu, kvm_read_cr0_bits(vcpu, ~0x0eul) | (msw & 0x0f));
-}
-EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_lmsw);
-
void kvm_load_guest_xsave_state(struct kvm_vcpu *vcpu)
{
if (vcpu->arch.guest_state_protected)
@@ -1316,89 +1190,7 @@ int kvm_emulate_xsetbv(struct kvm_vcpu *
}
EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_emulate_xsetbv);
-static bool kvm_is_valid_cr4(struct kvm_vcpu *vcpu, unsigned long cr4)
-{
- return __kvm_is_valid_cr4(vcpu, cr4) &&
- kvm_x86_call(is_valid_cr4)(vcpu, cr4);
-}
-
-void kvm_post_set_cr4(struct kvm_vcpu *vcpu, unsigned long old_cr4, unsigned long cr4)
-{
- if ((cr4 ^ old_cr4) & KVM_MMU_CR4_ROLE_BITS)
- kvm_mmu_reset_context(vcpu);
-
- /*
- * If CR4.PCIDE is changed 0 -> 1, there is no need to flush the TLB
- * according to the SDM; however, stale prev_roots could be reused
- * incorrectly in the future after a MOV to CR3 with NOFLUSH=1, so we
- * free them all. This is *not* a superset of KVM_REQ_TLB_FLUSH_GUEST
- * or KVM_REQ_TLB_FLUSH_CURRENT, because the hardware TLB is not flushed,
- * so fall through.
- */
- if (!tdp_enabled &&
- (cr4 & X86_CR4_PCIDE) && !(old_cr4 & X86_CR4_PCIDE))
- kvm_mmu_unload(vcpu);
-
- /*
- * The TLB has to be flushed for all PCIDs if any of the following
- * (architecturally required) changes happen:
- * - CR4.PCIDE is changed from 1 to 0
- * - CR4.PGE is toggled
- *
- * This is a superset of KVM_REQ_TLB_FLUSH_CURRENT.
- */
- if (((cr4 ^ old_cr4) & X86_CR4_PGE) ||
- (!(cr4 & X86_CR4_PCIDE) && (old_cr4 & X86_CR4_PCIDE)))
- kvm_make_request(KVM_REQ_TLB_FLUSH_GUEST, vcpu);
-
- /*
- * The TLB has to be flushed for the current PCID if any of the
- * following (architecturally required) changes happen:
- * - CR4.SMEP is changed from 0 to 1
- * - CR4.PAE is toggled
- */
- else if (((cr4 ^ old_cr4) & X86_CR4_PAE) ||
- ((cr4 & X86_CR4_SMEP) && !(old_cr4 & X86_CR4_SMEP)))
- kvm_make_request(KVM_REQ_TLB_FLUSH_CURRENT, vcpu);
-
-}
-EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_post_set_cr4);
-
-int kvm_set_cr4(struct kvm_vcpu *vcpu, unsigned long cr4)
-{
- unsigned long old_cr4 = kvm_read_cr4(vcpu);
-
- if (!kvm_is_valid_cr4(vcpu, cr4))
- return 1;
-
- if (is_long_mode(vcpu)) {
- if (!(cr4 & X86_CR4_PAE))
- return 1;
- if ((cr4 ^ old_cr4) & X86_CR4_LA57)
- return 1;
- } else if (is_paging(vcpu) && (cr4 & X86_CR4_PAE)
- && ((cr4 ^ old_cr4) & X86_CR4_PDPTR_BITS)
- && !load_pdptrs(vcpu, kvm_read_cr3(vcpu)))
- return 1;
-
- if ((cr4 & X86_CR4_PCIDE) && !(old_cr4 & X86_CR4_PCIDE)) {
- /* PCID can not be enabled when cr3[11:0]!=000H or EFER.LMA=0 */
- if ((kvm_read_cr3(vcpu) & X86_CR3_PCID_MASK) || !is_long_mode(vcpu))
- return 1;
- }
-
- if ((cr4 & X86_CR4_CET) && !kvm_is_cr0_bit_set(vcpu, X86_CR0_WP))
- return 1;
-
- kvm_x86_call(set_cr4)(vcpu, cr4);
-
- kvm_post_set_cr4(vcpu, old_cr4, cr4);
-
- return 0;
-}
-EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_set_cr4);
-
-static void kvm_invalidate_pcid(struct kvm_vcpu *vcpu, unsigned long pcid)
+void kvm_invalidate_pcid(struct kvm_vcpu *vcpu, unsigned long pcid)
{
struct kvm_mmu *mmu = vcpu->arch.mmu;
unsigned long roots_to_free = 0;
@@ -1441,159 +1233,6 @@ static void kvm_invalidate_pcid(struct k
kvm_mmu_free_roots(vcpu->kvm, mmu, roots_to_free);
}
-int kvm_set_cr3(struct kvm_vcpu *vcpu, unsigned long cr3)
-{
- bool skip_tlb_flush = false;
- unsigned long pcid = 0;
-#ifdef CONFIG_X86_64
- if (kvm_is_cr4_bit_set(vcpu, X86_CR4_PCIDE)) {
- skip_tlb_flush = cr3 & X86_CR3_PCID_NOFLUSH;
- cr3 &= ~X86_CR3_PCID_NOFLUSH;
- pcid = cr3 & X86_CR3_PCID_MASK;
- }
-#endif
-
- /* PDPTRs are always reloaded for PAE paging. */
- if (cr3 == kvm_read_cr3(vcpu) && !is_pae_paging(vcpu))
- goto handle_tlb_flush;
-
- /*
- * Do not condition the GPA check on long mode, this helper is used to
- * stuff CR3, e.g. for RSM emulation, and there is no guarantee that
- * the current vCPU mode is accurate.
- */
- if (!kvm_vcpu_is_legal_cr3(vcpu, cr3))
- return 1;
-
- if (is_pae_paging(vcpu) && !load_pdptrs(vcpu, cr3))
- return 1;
-
- if (cr3 != kvm_read_cr3(vcpu))
- kvm_mmu_new_pgd(vcpu, cr3);
-
- vcpu->arch.cr3 = cr3;
- kvm_register_mark_dirty(vcpu, VCPU_EXREG_CR3);
- /* Do not call post_set_cr3, we do not get here for confidential guests. */
-
-handle_tlb_flush:
- /*
- * A load of CR3 that flushes the TLB flushes only the current PCID,
- * even if PCID is disabled, in which case PCID=0 is flushed. It's a
- * moot point in the end because _disabling_ PCID will flush all PCIDs,
- * and it's impossible to use a non-zero PCID when PCID is disabled,
- * i.e. only PCID=0 can be relevant.
- */
- if (!skip_tlb_flush)
- kvm_invalidate_pcid(vcpu, pcid);
-
- return 0;
-}
-EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_set_cr3);
-
-int kvm_set_cr8(struct kvm_vcpu *vcpu, unsigned long cr8)
-{
- if (cr8 & CR8_RESERVED_BITS)
- return 1;
- if (lapic_in_kernel(vcpu))
- kvm_lapic_set_tpr(vcpu, cr8);
- else
- vcpu->arch.cr8 = cr8;
- return 0;
-}
-EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_set_cr8);
-
-unsigned long kvm_get_cr8(struct kvm_vcpu *vcpu)
-{
- if (lapic_in_kernel(vcpu))
- return kvm_lapic_get_cr8(vcpu);
- else
- return vcpu->arch.cr8;
-}
-EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_get_cr8);
-
-static void kvm_update_dr0123(struct kvm_vcpu *vcpu)
-{
- int i;
-
- if (!(vcpu->guest_debug & KVM_GUESTDBG_USE_HW_BP)) {
- for (i = 0; i < KVM_NR_DB_REGS; i++)
- vcpu->arch.eff_db[i] = vcpu->arch.db[i];
- }
-}
-
-void kvm_update_dr7(struct kvm_vcpu *vcpu)
-{
- unsigned long dr7;
-
- if (vcpu->guest_debug & KVM_GUESTDBG_USE_HW_BP)
- dr7 = vcpu->arch.guest_debug_dr7;
- else
- dr7 = vcpu->arch.dr7;
- kvm_x86_call(set_dr7)(vcpu, dr7);
- vcpu->arch.switch_db_regs &= ~KVM_DEBUGREG_BP_ENABLED;
- if (dr7 & DR7_BP_EN_MASK)
- vcpu->arch.switch_db_regs |= KVM_DEBUGREG_BP_ENABLED;
-}
-EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_update_dr7);
-
-static u64 kvm_dr6_fixed(struct kvm_vcpu *vcpu)
-{
- u64 fixed = DR6_FIXED_1;
-
- if (!guest_cpu_cap_has(vcpu, X86_FEATURE_RTM))
- fixed |= DR6_RTM;
-
- if (!guest_cpu_cap_has(vcpu, X86_FEATURE_BUS_LOCK_DETECT))
- fixed |= DR6_BUS_LOCK;
- return fixed;
-}
-
-int kvm_set_dr(struct kvm_vcpu *vcpu, int dr, unsigned long val)
-{
- size_t size = ARRAY_SIZE(vcpu->arch.db);
-
- switch (dr) {
- case 0 ... 3:
- vcpu->arch.db[array_index_nospec(dr, size)] = val;
- if (!(vcpu->guest_debug & KVM_GUESTDBG_USE_HW_BP))
- vcpu->arch.eff_db[dr] = val;
- break;
- case 4:
- case 6:
- if (!kvm_dr6_valid(val))
- return 1; /* #GP */
- vcpu->arch.dr6 = (val & DR6_VOLATILE) | kvm_dr6_fixed(vcpu);
- break;
- case 5:
- default: /* 7 */
- if (!kvm_dr7_valid(val))
- return 1; /* #GP */
- vcpu->arch.dr7 = (val & DR7_VOLATILE) | DR7_FIXED_1;
- kvm_update_dr7(vcpu);
- break;
- }
-
- return 0;
-}
-EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_set_dr);
-
-unsigned long kvm_get_dr(struct kvm_vcpu *vcpu, int dr)
-{
- size_t size = ARRAY_SIZE(vcpu->arch.db);
-
- switch (dr) {
- case 0 ... 3:
- return vcpu->arch.db[array_index_nospec(dr, size)];
- case 4:
- case 6:
- return vcpu->arch.dr6;
- case 5:
- default: /* 7 */
- return vcpu->arch.dr7;
- }
-}
-EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_get_dr);
-
int kvm_emulate_rdpmc(struct kvm_vcpu *vcpu)
{
u32 pmc = kvm_rcx_read(vcpu);
@@ -5564,7 +5203,7 @@ static struct kvm_queued_exception *kvm_
return &vcpu->arch.exception;
}
-static void kvm_handle_exception_payload_quirk(struct kvm_vcpu *vcpu)
+void kvm_handle_exception_payload_quirk(struct kvm_vcpu *vcpu)
{
struct kvm_queued_exception *ex = kvm_get_exception_to_save(vcpu);
@@ -5768,56 +5407,6 @@ static int kvm_vcpu_ioctl_x86_set_vcpu_e
return 0;
}
-static int kvm_vcpu_ioctl_x86_get_debugregs(struct kvm_vcpu *vcpu,
- struct kvm_debugregs *dbgregs)
-{
- unsigned int i;
-
- if (vcpu->kvm->arch.has_protected_state &&
- vcpu->arch.guest_state_protected)
- return -EINVAL;
-
- kvm_handle_exception_payload_quirk(vcpu);
-
- memset(dbgregs, 0, sizeof(*dbgregs));
-
- BUILD_BUG_ON(ARRAY_SIZE(vcpu->arch.db) != ARRAY_SIZE(dbgregs->db));
- for (i = 0; i < ARRAY_SIZE(vcpu->arch.db); i++)
- dbgregs->db[i] = vcpu->arch.db[i];
-
- dbgregs->dr6 = vcpu->arch.dr6;
- dbgregs->dr7 = vcpu->arch.dr7;
- return 0;
-}
-
-static int kvm_vcpu_ioctl_x86_set_debugregs(struct kvm_vcpu *vcpu,
- struct kvm_debugregs *dbgregs)
-{
- unsigned int i;
-
- if (vcpu->kvm->arch.has_protected_state &&
- vcpu->arch.guest_state_protected)
- return -EINVAL;
-
- if (dbgregs->flags)
- return -EINVAL;
-
- if (!kvm_dr6_valid(dbgregs->dr6))
- return -EINVAL;
- if (!kvm_dr7_valid(dbgregs->dr7))
- return -EINVAL;
-
- for (i = 0; i < ARRAY_SIZE(vcpu->arch.db); i++)
- vcpu->arch.db[i] = dbgregs->db[i];
-
- kvm_update_dr0123(vcpu);
- vcpu->arch.dr6 = dbgregs->dr6;
- vcpu->arch.dr7 = dbgregs->dr7;
- kvm_update_dr7(vcpu);
-
- return 0;
-}
-
static int kvm_vcpu_ioctl_x86_get_xsave2(struct kvm_vcpu *vcpu,
u8 *state, unsigned int size)
@@ -12017,180 +11606,6 @@ out:
return r;
}
-static void __get_regs(struct kvm_vcpu *vcpu, struct kvm_regs *regs)
-{
- if (vcpu->arch.emulate_regs_need_sync_to_vcpu) {
- /*
- * We are here if userspace calls get_regs() in the middle of
- * instruction emulation. Registers state needs to be copied
- * back from emulation context to vcpu. Userspace shouldn't do
- * that usually, but some bad designed PV devices (vmware
- * backdoor interface) need this to work
- */
- emulator_writeback_register_cache(vcpu->arch.emulate_ctxt);
- vcpu->arch.emulate_regs_need_sync_to_vcpu = false;
- }
- regs->rax = kvm_rax_read(vcpu);
- regs->rbx = kvm_rbx_read(vcpu);
- regs->rcx = kvm_rcx_read(vcpu);
- regs->rdx = kvm_rdx_read(vcpu);
- regs->rsi = kvm_rsi_read(vcpu);
- regs->rdi = kvm_rdi_read(vcpu);
- regs->rsp = kvm_rsp_read(vcpu);
- regs->rbp = kvm_rbp_read(vcpu);
-#ifdef CONFIG_X86_64
- regs->r8 = kvm_r8_read(vcpu);
- regs->r9 = kvm_r9_read(vcpu);
- regs->r10 = kvm_r10_read(vcpu);
- regs->r11 = kvm_r11_read(vcpu);
- regs->r12 = kvm_r12_read(vcpu);
- regs->r13 = kvm_r13_read(vcpu);
- regs->r14 = kvm_r14_read(vcpu);
- regs->r15 = kvm_r15_read(vcpu);
-#endif
-
- regs->rip = kvm_rip_read(vcpu);
- regs->rflags = kvm_get_rflags(vcpu);
-}
-
-int kvm_arch_vcpu_ioctl_get_regs(struct kvm_vcpu *vcpu, struct kvm_regs *regs)
-{
- if (vcpu->kvm->arch.has_protected_state &&
- vcpu->arch.guest_state_protected)
- return -EINVAL;
-
- vcpu_load(vcpu);
- __get_regs(vcpu, regs);
- vcpu_put(vcpu);
- return 0;
-}
-
-static void __set_regs(struct kvm_vcpu *vcpu, struct kvm_regs *regs)
-{
- vcpu->arch.emulate_regs_need_sync_from_vcpu = true;
- vcpu->arch.emulate_regs_need_sync_to_vcpu = false;
-
- kvm_rax_write(vcpu, regs->rax);
- kvm_rbx_write(vcpu, regs->rbx);
- kvm_rcx_write(vcpu, regs->rcx);
- kvm_rdx_write(vcpu, regs->rdx);
- kvm_rsi_write(vcpu, regs->rsi);
- kvm_rdi_write(vcpu, regs->rdi);
- kvm_rsp_write(vcpu, regs->rsp);
- kvm_rbp_write(vcpu, regs->rbp);
-#ifdef CONFIG_X86_64
- kvm_r8_write(vcpu, regs->r8);
- kvm_r9_write(vcpu, regs->r9);
- kvm_r10_write(vcpu, regs->r10);
- kvm_r11_write(vcpu, regs->r11);
- kvm_r12_write(vcpu, regs->r12);
- kvm_r13_write(vcpu, regs->r13);
- kvm_r14_write(vcpu, regs->r14);
- kvm_r15_write(vcpu, regs->r15);
-#endif
-
- kvm_rip_write(vcpu, regs->rip);
- kvm_set_rflags(vcpu, regs->rflags | X86_EFLAGS_FIXED);
-
- vcpu->arch.exception.pending = false;
- vcpu->arch.exception_vmexit.pending = false;
-
- kvm_make_request(KVM_REQ_EVENT, vcpu);
-}
-
-int kvm_arch_vcpu_ioctl_set_regs(struct kvm_vcpu *vcpu, struct kvm_regs *regs)
-{
- if (vcpu->kvm->arch.has_protected_state &&
- vcpu->arch.guest_state_protected)
- return -EINVAL;
-
- vcpu_load(vcpu);
- __set_regs(vcpu, regs);
- vcpu_put(vcpu);
- return 0;
-}
-
-static void __get_sregs_common(struct kvm_vcpu *vcpu, struct kvm_sregs *sregs)
-{
- struct desc_ptr dt;
-
- if (vcpu->arch.guest_state_protected)
- goto skip_protected_regs;
-
- kvm_handle_exception_payload_quirk(vcpu);
-
- kvm_get_segment(vcpu, &sregs->cs, VCPU_SREG_CS);
- kvm_get_segment(vcpu, &sregs->ds, VCPU_SREG_DS);
- kvm_get_segment(vcpu, &sregs->es, VCPU_SREG_ES);
- kvm_get_segment(vcpu, &sregs->fs, VCPU_SREG_FS);
- kvm_get_segment(vcpu, &sregs->gs, VCPU_SREG_GS);
- kvm_get_segment(vcpu, &sregs->ss, VCPU_SREG_SS);
-
- kvm_get_segment(vcpu, &sregs->tr, VCPU_SREG_TR);
- kvm_get_segment(vcpu, &sregs->ldt, VCPU_SREG_LDTR);
-
- kvm_x86_call(get_idt)(vcpu, &dt);
- sregs->idt.limit = dt.size;
- sregs->idt.base = dt.address;
- kvm_x86_call(get_gdt)(vcpu, &dt);
- sregs->gdt.limit = dt.size;
- sregs->gdt.base = dt.address;
-
- sregs->cr2 = vcpu->arch.cr2;
- sregs->cr3 = kvm_read_cr3(vcpu);
-
-skip_protected_regs:
- sregs->cr0 = kvm_read_cr0(vcpu);
- sregs->cr4 = kvm_read_cr4(vcpu);
- sregs->cr8 = kvm_get_cr8(vcpu);
- sregs->efer = vcpu->arch.efer;
- sregs->apic_base = vcpu->arch.apic_base;
-}
-
-static void __get_sregs(struct kvm_vcpu *vcpu, struct kvm_sregs *sregs)
-{
- __get_sregs_common(vcpu, sregs);
-
- if (vcpu->arch.guest_state_protected)
- return;
-
- if (vcpu->arch.interrupt.injected && !vcpu->arch.interrupt.soft)
- set_bit(vcpu->arch.interrupt.nr,
- (unsigned long *)sregs->interrupt_bitmap);
-}
-
-static void kvm_vcpu_ioctl_x86_get_sregs2(struct kvm_vcpu *vcpu,
- struct kvm_sregs2 *sregs2)
-{
- int i;
-
- __get_sregs_common(vcpu, (struct kvm_sregs *)sregs2);
-
- if (vcpu->arch.guest_state_protected)
- return;
-
- if (is_pae_paging(vcpu)) {
- kvm_vcpu_srcu_read_lock(vcpu);
- for (i = 0 ; i < 4 ; i++)
- sregs2->pdptrs[i] = kvm_pdptr_read(vcpu, i);
- sregs2->flags |= KVM_SREGS2_FLAGS_PDPTRS_VALID;
- kvm_vcpu_srcu_read_unlock(vcpu);
- }
-}
-
-int kvm_arch_vcpu_ioctl_get_sregs(struct kvm_vcpu *vcpu,
- struct kvm_sregs *sregs)
-{
- if (vcpu->kvm->arch.has_protected_state &&
- vcpu->arch.guest_state_protected)
- return -EINVAL;
-
- vcpu_load(vcpu);
- __get_sregs(vcpu, sregs);
- vcpu_put(vcpu);
- return 0;
-}
-
int kvm_arch_vcpu_ioctl_get_mpstate(struct kvm_vcpu *vcpu,
struct kvm_mp_state *mp_state)
{
@@ -12310,174 +11725,6 @@ unhandled_task_switch:
}
EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_task_switch);
-static bool kvm_is_valid_sregs(struct kvm_vcpu *vcpu, struct kvm_sregs *sregs)
-{
- if ((sregs->efer & EFER_LME) && (sregs->cr0 & X86_CR0_PG)) {
- /*
- * When EFER.LME and CR0.PG are set, the processor is in
- * 64-bit mode (though maybe in a 32-bit code segment).
- * CR4.PAE and EFER.LMA must be set.
- */
- if (!(sregs->cr4 & X86_CR4_PAE) || !(sregs->efer & EFER_LMA))
- return false;
- if (!kvm_vcpu_is_legal_cr3(vcpu, sregs->cr3))
- return false;
- } else {
- /*
- * Not in 64-bit mode: EFER.LMA is clear and the code
- * segment cannot be 64-bit.
- */
- if (sregs->efer & EFER_LMA || sregs->cs.l)
- return false;
- }
-
- return kvm_is_valid_cr4(vcpu, sregs->cr4) &&
- kvm_is_valid_cr0(vcpu, sregs->cr0);
-}
-
-static int __set_sregs_common(struct kvm_vcpu *vcpu, struct kvm_sregs *sregs,
- int *mmu_reset_needed, bool update_pdptrs)
-{
- int idx;
- struct desc_ptr dt;
-
- if (!kvm_is_valid_sregs(vcpu, sregs))
- return -EINVAL;
-
- if (kvm_apic_set_base(vcpu, sregs->apic_base, true))
- return -EINVAL;
-
- if (vcpu->arch.guest_state_protected)
- return 0;
-
- dt.size = sregs->idt.limit;
- dt.address = sregs->idt.base;
- kvm_x86_call(set_idt)(vcpu, &dt);
- dt.size = sregs->gdt.limit;
- dt.address = sregs->gdt.base;
- kvm_x86_call(set_gdt)(vcpu, &dt);
-
- vcpu->arch.cr2 = sregs->cr2;
- *mmu_reset_needed |= kvm_read_cr3(vcpu) != sregs->cr3;
- vcpu->arch.cr3 = sregs->cr3;
- kvm_register_mark_dirty(vcpu, VCPU_EXREG_CR3);
- kvm_x86_call(post_set_cr3)(vcpu, sregs->cr3);
-
- *mmu_reset_needed |= vcpu->arch.efer != sregs->efer;
- kvm_x86_call(set_efer)(vcpu, sregs->efer);
-
- *mmu_reset_needed |= kvm_read_cr0(vcpu) != sregs->cr0;
- kvm_x86_call(set_cr0)(vcpu, sregs->cr0);
-
- *mmu_reset_needed |= kvm_read_cr4(vcpu) != sregs->cr4;
- kvm_x86_call(set_cr4)(vcpu, sregs->cr4);
-
- if (update_pdptrs) {
- idx = srcu_read_lock(&vcpu->kvm->srcu);
- if (is_pae_paging(vcpu)) {
- load_pdptrs(vcpu, kvm_read_cr3(vcpu));
- *mmu_reset_needed = 1;
- }
- srcu_read_unlock(&vcpu->kvm->srcu, idx);
- }
-
- kvm_set_segment(vcpu, &sregs->cs, VCPU_SREG_CS);
- kvm_set_segment(vcpu, &sregs->ds, VCPU_SREG_DS);
- kvm_set_segment(vcpu, &sregs->es, VCPU_SREG_ES);
- kvm_set_segment(vcpu, &sregs->fs, VCPU_SREG_FS);
- kvm_set_segment(vcpu, &sregs->gs, VCPU_SREG_GS);
- kvm_set_segment(vcpu, &sregs->ss, VCPU_SREG_SS);
-
- kvm_set_segment(vcpu, &sregs->tr, VCPU_SREG_TR);
- kvm_set_segment(vcpu, &sregs->ldt, VCPU_SREG_LDTR);
-
- kvm_set_cr8(vcpu, sregs->cr8);
-
- /* Older userspace won't unhalt the vcpu on reset. */
- if (kvm_vcpu_is_bsp(vcpu) && kvm_rip_read(vcpu) == 0xfff0 &&
- sregs->cs.selector == 0xf000 && sregs->cs.base == 0xffff0000 &&
- !is_protmode(vcpu))
- kvm_set_mp_state(vcpu, KVM_MP_STATE_RUNNABLE);
-
- return 0;
-}
-
-static int __set_sregs(struct kvm_vcpu *vcpu, struct kvm_sregs *sregs)
-{
- int pending_vec, max_bits;
- int mmu_reset_needed = 0;
- int ret = __set_sregs_common(vcpu, sregs, &mmu_reset_needed, true);
-
- if (ret)
- return ret;
-
- if (mmu_reset_needed) {
- kvm_mmu_reset_context(vcpu);
- kvm_make_request(KVM_REQ_TLB_FLUSH_GUEST, vcpu);
- }
-
- max_bits = KVM_NR_INTERRUPTS;
- pending_vec = find_first_bit(
- (const unsigned long *)sregs->interrupt_bitmap, max_bits);
-
- if (pending_vec < max_bits) {
- kvm_queue_interrupt(vcpu, pending_vec, false);
- pr_debug("Set back pending irq %d\n", pending_vec);
- kvm_make_request(KVM_REQ_EVENT, vcpu);
- }
- return 0;
-}
-
-static int kvm_vcpu_ioctl_x86_set_sregs2(struct kvm_vcpu *vcpu,
- struct kvm_sregs2 *sregs2)
-{
- int mmu_reset_needed = 0;
- bool valid_pdptrs = sregs2->flags & KVM_SREGS2_FLAGS_PDPTRS_VALID;
- bool pae = (sregs2->cr0 & X86_CR0_PG) && (sregs2->cr4 & X86_CR4_PAE) &&
- !(sregs2->efer & EFER_LMA);
- int i, ret;
-
- if (sregs2->flags & ~KVM_SREGS2_FLAGS_PDPTRS_VALID)
- return -EINVAL;
-
- if (valid_pdptrs && (!pae || vcpu->arch.guest_state_protected))
- return -EINVAL;
-
- ret = __set_sregs_common(vcpu, (struct kvm_sregs *)sregs2,
- &mmu_reset_needed, !valid_pdptrs);
- if (ret)
- return ret;
-
- if (valid_pdptrs) {
- for (i = 0; i < 4 ; i++)
- kvm_pdptr_write(vcpu, i, sregs2->pdptrs[i]);
-
- kvm_register_mark_dirty(vcpu, VCPU_EXREG_PDPTR);
- mmu_reset_needed = 1;
- vcpu->arch.pdptrs_from_userspace = true;
- }
- if (mmu_reset_needed) {
- kvm_mmu_reset_context(vcpu);
- kvm_make_request(KVM_REQ_TLB_FLUSH_GUEST, vcpu);
- }
- return 0;
-}
-
-int kvm_arch_vcpu_ioctl_set_sregs(struct kvm_vcpu *vcpu,
- struct kvm_sregs *sregs)
-{
- int ret;
-
- if (vcpu->kvm->arch.has_protected_state &&
- vcpu->arch.guest_state_protected)
- return -EINVAL;
-
- vcpu_load(vcpu);
- ret = __set_sregs(vcpu, sregs);
- vcpu_put(vcpu);
- return ret;
-}
-
static void kvm_arch_vcpu_guestdbg_update_apicv_inhibit(struct kvm *kvm)
{
bool set = false;
@@ -12631,17 +11878,6 @@ int kvm_arch_vcpu_ioctl_set_fpu(struct k
return 0;
}
-static void kvm_run_sync_regs_to_user(struct kvm_vcpu *vcpu)
-{
- BUILD_BUG_ON(sizeof(struct kvm_sync_regs) > SYNC_REGS_SIZE_BYTES);
-
- if (vcpu->run->kvm_valid_regs & KVM_SYNC_X86_REGS)
- __get_regs(vcpu, &vcpu->run->s.regs.regs);
-
- if (vcpu->run->kvm_valid_regs & KVM_SYNC_X86_SREGS)
- __get_sregs(vcpu, &vcpu->run->s.regs.sregs);
-}
-
static void store_regs(struct kvm_vcpu *vcpu)
{
kvm_run_sync_regs_to_user(vcpu);
@@ -12651,25 +11887,6 @@ static void store_regs(struct kvm_vcpu *
vcpu, &vcpu->run->s.regs.events);
}
-static int kvm_run_sync_regs_from_user(struct kvm_vcpu *vcpu)
-{
- if (vcpu->run->kvm_dirty_regs & KVM_SYNC_X86_REGS) {
- __set_regs(vcpu, &vcpu->run->s.regs.regs);
- vcpu->run->kvm_dirty_regs &= ~KVM_SYNC_X86_REGS;
- }
-
- if (vcpu->run->kvm_dirty_regs & KVM_SYNC_X86_SREGS) {
- struct kvm_sregs sregs = vcpu->run->s.regs.sregs;
-
- if (__set_sregs(vcpu, &sregs))
- return -EINVAL;
-
- vcpu->run->kvm_dirty_regs &= ~KVM_SYNC_X86_SREGS;
- }
-
- return 0;
-}
-
static int sync_regs(struct kvm_vcpu *vcpu)
{
if (kvm_run_sync_regs_from_user(vcpu))
--- a/arch/x86/kvm/x86.h
+++ b/arch/x86/kvm/x86.h
@@ -54,6 +54,20 @@ struct kvm_host_values {
u64 arch_capabilities;
};
+void kvm_vcpu_ioctl_x86_get_sregs2(struct kvm_vcpu *vcpu,
+ struct kvm_sregs2 *sregs2);
+int kvm_vcpu_ioctl_x86_set_sregs2(struct kvm_vcpu *vcpu,
+ struct kvm_sregs2 *sregs2);
+
+void kvm_run_sync_regs_to_user(struct kvm_vcpu *vcpu);
+int kvm_run_sync_regs_from_user(struct kvm_vcpu *vcpu);
+
+void kvm_update_dr0123(struct kvm_vcpu *vcpu);
+int kvm_vcpu_ioctl_x86_get_debugregs(struct kvm_vcpu *vcpu,
+ struct kvm_debugregs *dbgregs);
+int kvm_vcpu_ioctl_x86_set_debugregs(struct kvm_vcpu *vcpu,
+ struct kvm_debugregs *dbgregs);
+
void kvm_spurious_fault(void);
#define SIZE_OF_MEMSLOTS_HASHTABLE \
@@ -439,6 +453,7 @@ int handle_ud(struct kvm_vcpu *vcpu);
void kvm_deliver_exception_payload(struct kvm_vcpu *vcpu,
struct kvm_queued_exception *ex);
+void kvm_handle_exception_payload_quirk(struct kvm_vcpu *vcpu);
int kvm_mtrr_set_msr(struct kvm_vcpu *vcpu, u32 msr, u64 data);
int kvm_mtrr_get_msr(struct kvm_vcpu *vcpu, u32 msr, u64 *pdata);
@@ -629,6 +644,7 @@ void kvm_load_host_xsave_state(struct kv
int kvm_spec_ctrl_test_value(u64 value);
int kvm_handle_memory_failure(struct kvm_vcpu *vcpu, int r,
struct x86_exception *e);
+void kvm_invalidate_pcid(struct kvm_vcpu *vcpu, unsigned long pcid);
int kvm_handle_invpcid(struct kvm_vcpu *vcpu, unsigned long type, gva_t gva);
bool kvm_msr_allowed(struct kvm_vcpu *vcpu, u32 index, u32 type);
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0091/1518] KVM: x86: Check EFER validity on KVM_SET_SREGS*
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (89 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0090/1518] KVM: x86: Move the bulk of register specific code from x86.c to regs.c Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0092/1518] Smack: Fix error in capability bypass Greg Kroah-Hartman
` (907 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yosry Ahmed, Sean Christopherson,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yosry Ahmed <yosry@kernel.org>
[ Upstream commit 184bd464bdb66daa9173670904f24c29c7b7f7d4 ]
When handling userspace SREGS writes, check the validity of EFER (i.e.
allowed bits) before writing the new value of EFER through the
per-vendor set_efer callbacks. This prevents userspace from writing
bogus values (e.g. EFER.SVME=1 with nested=0).
Note: on KVM_SET_MSRS, KVM only checks EFER validity in terms of KVM
caps, not guest caps, so it is possible to set EFER bits that are
supported by KVM but not by the guest CPUID. Potentially allowing
userspace to set msrs before CPUID.
However, for KVM_SET_SREGS*, check the validity of the set bits against
both KVM and guest caps. This is consistent with other validity checks
(e.g. for CR4) that check validity against guest caps, which already
imposes the need to set CPUID before SREGS.
Cc: stable@vger.kernel.org
Signed-off-by: Yosry Ahmed <yosry@kernel.org>
Link: https://patch.msgid.link/20260713180153.2728382-2-yosry@kernel.org
Signed-off-by: Sean Christopherson <seanjc@google.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
arch/x86/kvm/regs.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/arch/x86/kvm/regs.c
+++ b/arch/x86/kvm/regs.c
@@ -476,7 +476,8 @@ static bool kvm_is_valid_sregs(struct kv
}
return kvm_is_valid_cr4(vcpu, sregs->cr4) &&
- kvm_is_valid_cr0(vcpu, sregs->cr0);
+ kvm_is_valid_cr0(vcpu, sregs->cr0) &&
+ kvm_valid_efer(vcpu, sregs->efer);
}
static int __set_sregs_common(struct kvm_vcpu *vcpu, struct kvm_sregs *sregs,
^ permalink raw reply [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0092/1518] Smack: Fix error in capability bypass
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (90 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0091/1518] KVM: x86: Check EFER validity on KVM_SET_SREGS* Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0093/1518] drm: Remove unused header in drm_dumb_buffers.c Greg Kroah-Hartman
` (906 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Bumjin Im, Casey Schaufler,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Casey Schaufler <casey@schaufler-ca.com>
[ Upstream commit b2faddc13112489f8f11eb40b9456db8c1b58362 ]
A bug in smack_inode_xattr_skipcap() was introduced in the inode
capability handling. The strncmp guard at the top of the function
is coded backwards, resulting in consistently incorrect results.
Correct the check, and the code functions as it should. The error
manifests as requiring CAP_SYS_ADMIN as well as CAP_MAC_ADMIN to
change an inode's MAC attributes.
Fixes: 61df7b828204 ("lsm: fixup the inode xattr capability handling")
Reported-by: Bumjin Im <imbumjin@gmail.com>
Signed-off-by: Casey Schaufler <casey@schaufler-ca.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
security/smack/smack_lsm.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/security/smack/smack_lsm.c b/security/smack/smack_lsm.c
index 0d984fdf211a6..8a53605546c4a 100644
--- a/security/smack/smack_lsm.c
+++ b/security/smack/smack_lsm.c
@@ -1312,7 +1312,7 @@ static int smack_inode_getattr(const struct path *path)
*/
static int smack_inode_xattr_skipcap(const char *name)
{
- if (strncmp(name, XATTR_SMACK_SUFFIX, strlen(XATTR_SMACK_SUFFIX)))
+ if (strncmp(name, XATTR_SMACK_SUFFIX, strlen(XATTR_SMACK_SUFFIX)) == 0)
return 0;
if (strcmp(name, XATTR_NAME_SMACK) == 0 ||
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0093/1518] drm: Remove unused header in drm_dumb_buffers.c
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (91 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0092/1518] Smack: Fix error in capability bypass Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0094/1518] drm: lcdif: Wait for vblank before disabling DMA Greg Kroah-Hartman
` (905 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yicong Hui, Thomas Zimmermann,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yicong Hui <yiconghui@gmail.com>
[ Upstream commit 38b4ce17ef3421fb0e5e6dbdab1974282bde1165 ]
Remove the header #include "drm_internal.h" from drm_dumb_buffers.c,
which is included but not used.
Header was introduced in commit 47f10854ca89 ("drm: Don't export the
drm_gem_dumb_destroy() function") when moving functions, but was not
removed in commit 96a7b60f6ddb ("drm: remove dumb_destroy callback")
when the drm_gem_dumb_destroy function was removed.
Compiles successfully with DRM enabled, pass kunit tests and
IGT-tests in a vng virtual machine.
Fixes: 96a7b60f6ddb ("drm: remove dumb_destroy callback")
Signed-off-by: Yicong Hui <yiconghui@gmail.com>
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Signed-off-by: Thomas Zimmermann <tzimmermann@suse.de>
Link: https://patch.msgid.link/20260409154826.8955-1-yiconghui@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/drm_dumb_buffers.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/drivers/gpu/drm/drm_dumb_buffers.c b/drivers/gpu/drm/drm_dumb_buffers.c
index 70032bba1c97e..7b4ba9fab299a 100644
--- a/drivers/gpu/drm/drm_dumb_buffers.c
+++ b/drivers/gpu/drm/drm_dumb_buffers.c
@@ -29,7 +29,6 @@
#include <drm/drm_mode.h>
#include "drm_crtc_internal.h"
-#include "drm_internal.h"
/**
* DOC: overview
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0094/1518] drm: lcdif: Wait for vblank before disabling DMA
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (92 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0093/1518] drm: Remove unused header in drm_dumb_buffers.c Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0095/1518] drm/bridge: synopsys: dw-dp: Support unregistering the AUX channel Greg Kroah-Hartman
` (904 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Paul Kocialkowski, Frieder Schrempf,
Liu Ying, Lucas Stach, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Paul Kocialkowski <paulk@sys-base.io>
[ Upstream commit 351af554edd994898db12217c3be39979e168d35 ]
It is necessary to wait for the full frame to finish streaming
through the DMA engine before we can safely disable it by removing
the DISP_PARA_DISP_ON bit. Disabling it in-flight can leave the
hardware confused and unable to resume streaming for the next frame.
This causes the FIFO underrun and empty status bits to be set and
a single solid color to be shown on the display, coming from one of
the pixels of the previous frame. The issue occurs sporadically when
a new mode is set, which triggers the crtc disable and enable paths.
Setting the shadow load bit and waiting for it to be cleared by the
DMA engine allows waiting for completion.
The NXP BSP driver addresses this issue with a hardcoded 25 ms sleep.
Fixes: 9db35bb349a0 ("drm: lcdif: Add support for i.MX8MP LCDIF variant")
Signed-off-by: Paul Kocialkowski <paulk@sys-base.io>
Co-developed-by: Lucas Stach <l.stach@pengutronix.de>
Reviewed-by: Frieder Schrempf <frieder.schrempf@kontron.de>
Tested-by: Frieder Schrempf <frieder.schrempf@kontron.de>
Acked-by: Liu Ying <victor.liu@nxp.com>
Link: https://patch.msgid.link/20260402183351.3281123-3-paulk@sys-base.io
Signed-off-by: Lucas Stach <l.stach@pengutronix.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/mxsfb/lcdif_kms.c | 15 ++++++++++++---
1 file changed, 12 insertions(+), 3 deletions(-)
diff --git a/drivers/gpu/drm/mxsfb/lcdif_kms.c b/drivers/gpu/drm/mxsfb/lcdif_kms.c
index 1c3b33be6c40f..d9499d8c71288 100644
--- a/drivers/gpu/drm/mxsfb/lcdif_kms.c
+++ b/drivers/gpu/drm/mxsfb/lcdif_kms.c
@@ -373,14 +373,23 @@ static void lcdif_disable_controller(struct lcdif_drm_private *lcdif)
int ret;
reg = readl(lcdif->base + LCDC_V8_CTRLDESCL0_5);
+ /* Disable the layer for DMA. */
reg &= ~CTRLDESCL0_5_EN;
+ /*
+ * It is necessary to wait for the full frame to finish streaming
+ * through the DMA engine before we can safely disable it by removing
+ * the DISP_PARA_DISP_ON bit. Disabling it in-flight can leave the
+ * hardware confused and unable to resume streaming for the next frame.
+ */
+ reg |= CTRLDESCL0_5_SHADOW_LOAD_EN;
writel(reg, lcdif->base + LCDC_V8_CTRLDESCL0_5);
+ /* Wait for the frame to finish or timeout after 50 ms. */
ret = readl_poll_timeout(lcdif->base + LCDC_V8_CTRLDESCL0_5,
- reg, !(reg & CTRLDESCL0_5_EN),
- 0, 36000); /* Wait ~2 frame times max */
+ reg, !(reg & CTRLDESCL0_5_SHADOW_LOAD_EN),
+ 200, 50000);
if (ret)
- drm_err(lcdif->drm, "Failed to disable controller!\n");
+ drm_err(lcdif->drm, "Timed out waiting for final vblank!\n");
reg = readl(lcdif->base + LCDC_V8_DISP_PARA);
reg &= ~DISP_PARA_DISP_ON;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0095/1518] drm/bridge: synopsys: dw-dp: Support unregistering the AUX channel
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (93 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0094/1518] drm: lcdif: Wait for vblank before disabling DMA Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0096/1518] drm/bridge: synopsys: dw-dp: Set pixel mode by platform data Greg Kroah-Hartman
` (903 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Andy Yan, Cristian Ciocaltea,
Heiko Stuebner, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
[ Upstream commit ed04e8e2307f35b3d8d49a554faf5e72d3d224e6 ]
The DisplayPort AUX channel gets initialized and registered during
dw_dp_bind(), but it is never unregistered, which may lead to resource
leaks and/or use-after-free.
Add the missing dw_dp_unbind() function to allow the users of the
library to handle the required cleanup, i.e. unregister the AUX adapter.
Fixes: 86eecc3a9c2e ("drm/bridge: synopsys: Add DW DPTX Controller support library")
Reviewed-by: Andy Yan <andy.yan@rock-chips.com>
Signed-off-by: Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Link: https://patch.msgid.link/20260601-drm-rk-fixes-v4-1-c3f3f123e1da@collabora.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/bridge/synopsys/dw-dp.c | 6 ++++++
include/drm/bridge/dw_dp.h | 1 +
2 files changed, 7 insertions(+)
diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
index e82960163018a..70f64eb89998f 100644
--- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
+++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
@@ -2098,6 +2098,12 @@ struct dw_dp *dw_dp_bind(struct device *dev, struct drm_encoder *encoder,
}
EXPORT_SYMBOL_GPL(dw_dp_bind);
+void dw_dp_unbind(struct dw_dp *dp)
+{
+ drm_dp_aux_unregister(&dp->aux);
+}
+EXPORT_SYMBOL_GPL(dw_dp_unbind);
+
MODULE_AUTHOR("Andy Yan <andyshrk@163.com>");
MODULE_DESCRIPTION("DW DP Core Library");
MODULE_LICENSE("GPL");
diff --git a/include/drm/bridge/dw_dp.h b/include/drm/bridge/dw_dp.h
index d05df49fd8846..ab5c0a9b01aeb 100644
--- a/include/drm/bridge/dw_dp.h
+++ b/include/drm/bridge/dw_dp.h
@@ -17,4 +17,5 @@ struct dw_dp_plat_data {
struct dw_dp *dw_dp_bind(struct device *dev, struct drm_encoder *encoder,
const struct dw_dp_plat_data *plat_data);
+void dw_dp_unbind(struct dw_dp *dp);
#endif /* __DW_DP__ */
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0096/1518] drm/bridge: synopsys: dw-dp: Set pixel mode by platform data
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (94 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0095/1518] drm/bridge: synopsys: dw-dp: Support unregistering the AUX channel Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0097/1518] drm/rockchip: dw_dp: Simplify error handling Greg Kroah-Hartman
` (902 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Andy Yan, Sebastian Reichel,
Heiko Stuebner, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Andy Yan <andy.yan@rock-chips.com>
[ Upstream commit 77ae37018a2705f5abe8cc428e3496651258901d ]
In the implementation and integration of the SoC, the DW DisplayPort
hardware block can be configured to work in single, dual, quad pixel
mode on differnt platforms, so make the pixel mode set by plat_data
to support the upcoming rk3576 variant.
Signed-off-by: Andy Yan <andy.yan@rock-chips.com>
Reviewed-by: Sebastian Reichel <sebastian.reichel@collabora.com>
Tested-by: Sebastian Reichel <sebastian.reichel@collabora.com>
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Link: https://patch.msgid.link/20260206010421.443605-3-andyshrk@163.com
Stable-dep-of: cc6d7aca2f37 ("drm/rockchip: dw_dp: Release core resources")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/bridge/synopsys/dw-dp.c | 8 +-------
drivers/gpu/drm/rockchip/dw_dp-rockchip.c | 19 +++++++++++++++----
include/drm/bridge/dw_dp.h | 7 +++++++
3 files changed, 23 insertions(+), 11 deletions(-)
diff --git a/drivers/gpu/drm/bridge/synopsys/dw-dp.c b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
index 70f64eb89998f..901bdec4a76ca 100644
--- a/drivers/gpu/drm/bridge/synopsys/dw-dp.c
+++ b/drivers/gpu/drm/bridge/synopsys/dw-dp.c
@@ -352,12 +352,6 @@ enum {
DW_DP_YCBCR420_16BIT,
};
-enum {
- DW_DP_MP_SINGLE_PIXEL,
- DW_DP_MP_DUAL_PIXEL,
- DW_DP_MP_QUAD_PIXEL,
-};
-
enum {
DW_DP_SDP_VERTICAL_INTERVAL = BIT(0),
DW_DP_SDP_HORIZONTAL_INTERVAL = BIT(1),
@@ -1984,7 +1978,7 @@ struct dw_dp *dw_dp_bind(struct device *dev, struct drm_encoder *encoder,
return ERR_CAST(dp);
dp->dev = dev;
- dp->pixel_mode = DW_DP_MP_QUAD_PIXEL;
+ dp->pixel_mode = plat_data->pixel_mode;
dp->plat_data.max_link_rate = plat_data->max_link_rate;
bridge = &dp->bridge;
diff --git a/drivers/gpu/drm/rockchip/dw_dp-rockchip.c b/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
index 6d57e1c746273..80aa8d11b49cb 100644
--- a/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
+++ b/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
@@ -76,7 +76,7 @@ static const struct drm_encoder_helper_funcs dw_dp_encoder_helper_funcs = {
static int dw_dp_rockchip_bind(struct device *dev, struct device *master, void *data)
{
struct platform_device *pdev = to_platform_device(dev);
- struct dw_dp_plat_data plat_data;
+ const struct dw_dp_plat_data *plat_data;
struct drm_device *drm_dev = data;
struct rockchip_dw_dp *dp;
struct drm_encoder *encoder;
@@ -90,7 +90,10 @@ static int dw_dp_rockchip_bind(struct device *dev, struct device *master, void *
dp->dev = dev;
platform_set_drvdata(pdev, dp);
- plat_data.max_link_rate = 810000;
+ plat_data = of_device_get_match_data(dev);
+ if (!plat_data)
+ return -ENODEV;
+
encoder = &dp->encoder.encoder;
encoder->possible_crtcs = drm_of_find_possible_crtcs(drm_dev, dev->of_node);
rockchip_drm_encoder_set_crtc_endpoint_id(&dp->encoder, dev->of_node, 0, 0);
@@ -100,7 +103,7 @@ static int dw_dp_rockchip_bind(struct device *dev, struct device *master, void *
return ret;
drm_encoder_helper_add(encoder, &dw_dp_encoder_helper_funcs);
- dp->base = dw_dp_bind(dev, encoder, &plat_data);
+ dp->base = dw_dp_bind(dev, encoder, plat_data);
if (IS_ERR(dp->base)) {
ret = PTR_ERR(dp->base);
return ret;
@@ -133,8 +136,16 @@ static void dw_dp_remove(struct platform_device *pdev)
component_del(&pdev->dev, &dw_dp_rockchip_component_ops);
}
+static const struct dw_dp_plat_data rk3588_dp_plat_data = {
+ .max_link_rate = 810000,
+ .pixel_mode = DW_DP_MP_QUAD_PIXEL,
+};
+
static const struct of_device_id dw_dp_of_match[] = {
- { .compatible = "rockchip,rk3588-dp", },
+ {
+ .compatible = "rockchip,rk3588-dp",
+ .data = &rk3588_dp_plat_data,
+ },
{}
};
MODULE_DEVICE_TABLE(of, dw_dp_of_match);
diff --git a/include/drm/bridge/dw_dp.h b/include/drm/bridge/dw_dp.h
index ab5c0a9b01aeb..22105c3e8e4d6 100644
--- a/include/drm/bridge/dw_dp.h
+++ b/include/drm/bridge/dw_dp.h
@@ -11,8 +11,15 @@
struct drm_encoder;
struct dw_dp;
+enum {
+ DW_DP_MP_SINGLE_PIXEL,
+ DW_DP_MP_DUAL_PIXEL,
+ DW_DP_MP_QUAD_PIXEL,
+};
+
struct dw_dp_plat_data {
u32 max_link_rate;
+ u8 pixel_mode;
};
struct dw_dp *dw_dp_bind(struct device *dev, struct drm_encoder *encoder,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0097/1518] drm/rockchip: dw_dp: Simplify error handling
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (95 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0096/1518] drm/bridge: synopsys: dw-dp: Set pixel mode by platform data Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0098/1518] drm/rockchip: dw_dp: Add missing newline in dev_err_probe() message Greg Kroah-Hartman
` (901 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Cristian Ciocaltea, Heiko Stuebner,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
[ Upstream commit 26cb3e26efa7cc84289966cab871889f6ca93616 ]
Make the code a bit more compact by getting rid of the superfluous
assignments around PTR_ERR().
While at it, also drop dev assignment in dw_dp_probe().
Signed-off-by: Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Link: https://patch.msgid.link/20260310-drm-rk-fixes-v2-4-645ecfb43f49@collabora.com
Stable-dep-of: cc6d7aca2f37 ("drm/rockchip: dw_dp: Release core resources")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/rockchip/dw_dp-rockchip.c | 21 +++++++--------------
1 file changed, 7 insertions(+), 14 deletions(-)
diff --git a/drivers/gpu/drm/rockchip/dw_dp-rockchip.c b/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
index 80aa8d11b49cb..0e7a2d46dcb0b 100644
--- a/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
+++ b/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
@@ -104,20 +104,15 @@ static int dw_dp_rockchip_bind(struct device *dev, struct device *master, void *
drm_encoder_helper_add(encoder, &dw_dp_encoder_helper_funcs);
dp->base = dw_dp_bind(dev, encoder, plat_data);
- if (IS_ERR(dp->base)) {
- ret = PTR_ERR(dp->base);
- return ret;
- }
+ if (IS_ERR(dp->base))
+ return PTR_ERR(dp->base);
connector = drm_bridge_connector_init(drm_dev, encoder);
- if (IS_ERR(connector)) {
- ret = PTR_ERR(connector);
- return dev_err_probe(dev, ret, "Failed to init bridge connector");
- }
+ if (IS_ERR(connector))
+ return dev_err_probe(dev, PTR_ERR(connector),
+ "Failed to init bridge connector");
- drm_connector_attach_encoder(connector, encoder);
-
- return 0;
+ return drm_connector_attach_encoder(connector, encoder);
}
static const struct component_ops dw_dp_rockchip_component_ops = {
@@ -126,9 +121,7 @@ static const struct component_ops dw_dp_rockchip_component_ops = {
static int dw_dp_probe(struct platform_device *pdev)
{
- struct device *dev = &pdev->dev;
-
- return component_add(dev, &dw_dp_rockchip_component_ops);
+ return component_add(&pdev->dev, &dw_dp_rockchip_component_ops);
}
static void dw_dp_remove(struct platform_device *pdev)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0098/1518] drm/rockchip: dw_dp: Add missing newline in dev_err_probe() message
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (96 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0097/1518] drm/rockchip: dw_dp: Simplify error handling Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0099/1518] drm/rockchip: dw_dp: Release core resources Greg Kroah-Hartman
` (900 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Cristian Ciocaltea, Heiko Stuebner,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
[ Upstream commit 0a01412178047bf3ff351c7e75d373e411072a87 ]
Add the missing trailing newline to dev_err_probe() call in
dw_dp_rockchip_bind().
Fixes: d68ba7bac955 ("drm/rockchip: Add RK3588 DPTX output support")
Fixes: 26cb3e26efa7 ("drm/rockchip: dw_dp: Simplify error handling")
Signed-off-by: Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Link: https://patch.msgid.link/20260601-drm-rk-fixes-v4-2-c3f3f123e1da@collabora.com
Stable-dep-of: cc6d7aca2f37 ("drm/rockchip: dw_dp: Release core resources")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/rockchip/dw_dp-rockchip.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/rockchip/dw_dp-rockchip.c b/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
index 0e7a2d46dcb0b..b3a635609effa 100644
--- a/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
+++ b/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
@@ -110,7 +110,7 @@ static int dw_dp_rockchip_bind(struct device *dev, struct device *master, void *
connector = drm_bridge_connector_init(drm_dev, encoder);
if (IS_ERR(connector))
return dev_err_probe(dev, PTR_ERR(connector),
- "Failed to init bridge connector");
+ "Failed to init bridge connector\n");
return drm_connector_attach_encoder(connector, encoder);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0099/1518] drm/rockchip: dw_dp: Release core resources
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (97 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0098/1518] drm/rockchip: dw_dp: Add missing newline in dev_err_probe() message Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0100/1518] drm/rockchip: vop2: Fix wrong wait target in layer cfg done check Greg Kroah-Hartman
` (899 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Cristian Ciocaltea, Heiko Stuebner,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
[ Upstream commit cc6d7aca2f37a1525a94ef97eb3ce361732c876c ]
Core resources such as the DisplayPort AUX channel get initialized and
registered during dw_dp_bind(), but are never unregistered, which may
lead to memory leaks and/or use-after-free:
[ 224.661371] BUG: KASAN: slab-use-after-free in device_is_dependent+0xe0/0x2b0
[ 224.662015] Read of size 8 at addr ffff00011aee8550 by task modprobe/658
[ 224.662612]
[ 224.662752] CPU: 7 UID: 0 PID: 658 Comm: modprobe Not tainted 7.0.0-rc2-next-20260305 #14 PREEMPT
[ 224.662759] Hardware name: Radxa ROCK 5B (DT)
[ 224.662762] Call trace:
[ 224.662764] show_stack+0x20/0x38 (C)
[ 224.662772] dump_stack_lvl+0x6c/0x98
[ 224.662777] print_report+0x160/0x4b8
[ 224.662783] kasan_report+0xb4/0xe0
[ 224.662790] __asan_report_load8_noabort+0x20/0x30
[ 224.662796] device_is_dependent+0xe0/0x2b0
[ 224.662802] device_is_dependent+0x108/0x2b0
[ 224.662808] device_link_add+0x1f8/0x10b0
[ 224.662813] devm_of_phy_get_by_index+0x120/0x200
[ 224.662819] dw_dp_bind+0x34c/0xb10 [dw_dp]
[ 224.662830] dw_dp_rockchip_bind+0x194/0x250 [rockchipdrm]
[ 224.662864] component_bind_all+0x3a8/0x720
[ 224.662869] rockchip_drm_bind+0x120/0x390 [rockchipdrm]
[ 224.662899] try_to_bring_up_aggregate_device+0x76c/0x838
[ 224.662904] component_master_add_with_match+0x1f4/0x230
[ 224.662909] rockchip_drm_platform_probe+0x420/0x538 [rockchipdrm]
[ 224.662939] platform_probe+0xe8/0x168
[ 224.662945] really_probe+0x340/0x828
[ 224.662950] __driver_probe_device+0x2e0/0x350
[ 224.662954] driver_probe_device+0x80/0x140
[ 224.662959] __driver_attach+0x398/0x460
[ 224.662964] bus_for_each_dev+0xe0/0x198
[ 224.662968] driver_attach+0x50/0x68
[ 224.662972] bus_add_driver+0x2a0/0x4c0
[ 224.662977] driver_register+0x294/0x360
[ 224.662982] __platform_driver_register+0x7c/0x98
[ 224.662987] rockchip_drm_init+0xc4/0xff8 [rockchipdrm]
Since a previous commit exported dw_dp_unbind() function in DW DP core
library to take care of the necessary cleanup, use this in the
component's unbind() callback, as well as in its bind() error path.
Fixes: d68ba7bac955 ("drm/rockchip: Add RK3588 DPTX output support")
Signed-off-by: Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Link: https://patch.msgid.link/20260601-drm-rk-fixes-v4-3-c3f3f123e1da@collabora.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/rockchip/dw_dp-rockchip.c | 13 ++++++++++++-
1 file changed, 12 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/rockchip/dw_dp-rockchip.c b/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
index b3a635609effa..410e5f4573306 100644
--- a/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
+++ b/drivers/gpu/drm/rockchip/dw_dp-rockchip.c
@@ -108,15 +108,26 @@ static int dw_dp_rockchip_bind(struct device *dev, struct device *master, void *
return PTR_ERR(dp->base);
connector = drm_bridge_connector_init(drm_dev, encoder);
- if (IS_ERR(connector))
+ if (IS_ERR(connector)) {
+ dw_dp_unbind(dp->base);
return dev_err_probe(dev, PTR_ERR(connector),
"Failed to init bridge connector\n");
+ }
return drm_connector_attach_encoder(connector, encoder);
}
+static void dw_dp_rockchip_unbind(struct device *dev, struct device *master,
+ void *data)
+{
+ struct rockchip_dw_dp *dp = dev_get_drvdata(dev);
+
+ dw_dp_unbind(dp->base);
+}
+
static const struct component_ops dw_dp_rockchip_component_ops = {
.bind = dw_dp_rockchip_bind,
+ .unbind = dw_dp_rockchip_unbind,
};
static int dw_dp_probe(struct platform_device *pdev)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0100/1518] drm/rockchip: vop2: Fix wrong wait target in layer cfg done check
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (98 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0099/1518] drm/rockchip: dw_dp: Release core resources Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0101/1518] drm/rockchip: vop2: Wait for layer cfg done before switching LAYERSEL_REGDONE_SEL Greg Kroah-Hartman
` (898 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Cristian Ciocaltea, Andy Yan,
Heiko Stuebner, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
[ Upstream commit 9f5670802df085ad343146561e69bac43e9905d2 ]
rk3568_vop2_setup_layer_mixer() waits for the previous Video Port (VP)
layer configuration to take effect before writing a new one to the
shared RK3568_OVL_LAYER_SEL shadow register. However, it passes
vop2->old_layer_sel to rk3568_vop2_wait_for_layer_cfg_done() as the
expected value, which at that point already contains the new VP layer.
This causes the wait to poll for a value that has not been written to
the shadow register yet, resulting in spurious timeouts when two
non-blocking atomic commits race:
rockchip-drm display-subsystem: [drm] *ERROR* wait layer cfg done timeout [...]
Pass the local old_layer_sel instead, which still holds the value
captured from vop2->old_layer_sel before it was overwritten, i.e. the
previous VP target that the hardware is expected to latch.
Fixes: 3e89a8c68354 ("drm/rockchip: vop2: Fix the update of LAYER/PORT select registers when there are multi display output on rk3588/rk3568")
Signed-off-by: Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
Reviewed-by: Andy Yan <andy.yan@rock-chips.com>
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Link: https://patch.msgid.link/20260504-vop2-layer-cfg-tmout-v1-1-730226a7331e@collabora.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/rockchip/rockchip_vop2_reg.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/rockchip/rockchip_vop2_reg.c b/drivers/gpu/drm/rockchip/rockchip_vop2_reg.c
index f3950e8476a75..3fcb0a2c29942 100644
--- a/drivers/gpu/drm/rockchip/rockchip_vop2_reg.c
+++ b/drivers/gpu/drm/rockchip/rockchip_vop2_reg.c
@@ -2307,7 +2307,7 @@ static void rk3568_vop2_setup_layer_mixer(struct vop2_video_port *vp)
* Changes of other VPs' overlays have not taken effect
*/
if (cfg_done)
- rk3568_vop2_wait_for_layer_cfg_done(vop2, vop2->old_layer_sel);
+ rk3568_vop2_wait_for_layer_cfg_done(vop2, old_layer_sel);
}
vop2_writel(vop2, RK3568_OVL_LAYER_SEL, layer_sel);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0101/1518] drm/rockchip: vop2: Wait for layer cfg done before switching LAYERSEL_REGDONE_SEL
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (99 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0100/1518] drm/rockchip: vop2: Fix wrong wait target in layer cfg done check Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0102/1518] drm/rockchip: analogix_dp: Enable hclk for RK3588 Greg Kroah-Hartman
` (897 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Cristian Ciocaltea, Andy Yan,
Heiko Stuebner, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
[ Upstream commit d1ad644e572c0647ad8428439eafea0aacfccf9e ]
LAYERSEL_REGDONE_SEL mask of RK3568_OVL_CTRL register controls which
Video Port (VP) vsync latches the shared RK3568_OVL_{LAYER|PORT}_SEL
shadow registers into the active configuration.
rk3568_vop2_setup_layer_mixer() overwrites LAYERSEL_REGDONE_SEL to the
current VP ID before waiting for the previous VP layer configuration to
take effect. As a consequence, the previous VP vsync can no longer
trigger the latch, so the wait polls a value that might never appear.
Move the layer cfg done wait before the RK3568_OVL_CTRL write so the
previous VP vsync can still commit the pending configuration.
Fixes: 3e89a8c68354 ("drm/rockchip: vop2: Fix the update of LAYER/PORT select registers when there are multi display output on rk3588/rk3568")
Signed-off-by: Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
Reviewed-by: Andy Yan <andy.yan@rock-chips.com>
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Link: https://patch.msgid.link/20260504-vop2-layer-cfg-tmout-v1-2-730226a7331e@collabora.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/rockchip/rockchip_vop2_reg.c | 19 ++++++++++---------
1 file changed, 10 insertions(+), 9 deletions(-)
diff --git a/drivers/gpu/drm/rockchip/rockchip_vop2_reg.c b/drivers/gpu/drm/rockchip/rockchip_vop2_reg.c
index 3fcb0a2c29942..7cac271704c10 100644
--- a/drivers/gpu/drm/rockchip/rockchip_vop2_reg.c
+++ b/drivers/gpu/drm/rockchip/rockchip_vop2_reg.c
@@ -2289,15 +2289,6 @@ static void rk3568_vop2_setup_layer_mixer(struct vop2_video_port *vp)
* lead to the configuration of the previous VP being take effect along with the VSYNC
* of the new VP.
*/
- if (layer_sel != old_layer_sel || port_sel != old_port_sel)
- ovl_ctrl |= FIELD_PREP(RK3568_OVL_CTRL__LAYERSEL_REGDONE_SEL, vp->id);
- vop2_writel(vop2, RK3568_OVL_CTRL, ovl_ctrl);
-
- if (port_sel != old_port_sel) {
- vop2_writel(vop2, RK3568_OVL_PORT_SEL, port_sel);
- vop2_cfg_done(vp);
- rk3568_vop2_wait_for_port_mux_done(vop2);
- }
if (layer_sel != old_layer_sel && atv_layer_sel != old_layer_sel) {
cfg_done = vop2_readl(vop2, RK3568_REG_CFG_DONE);
@@ -2310,6 +2301,16 @@ static void rk3568_vop2_setup_layer_mixer(struct vop2_video_port *vp)
rk3568_vop2_wait_for_layer_cfg_done(vop2, old_layer_sel);
}
+ if (layer_sel != old_layer_sel || port_sel != old_port_sel)
+ ovl_ctrl |= FIELD_PREP(RK3568_OVL_CTRL__LAYERSEL_REGDONE_SEL, vp->id);
+ vop2_writel(vop2, RK3568_OVL_CTRL, ovl_ctrl);
+
+ if (port_sel != old_port_sel) {
+ vop2_writel(vop2, RK3568_OVL_PORT_SEL, port_sel);
+ vop2_cfg_done(vp);
+ rk3568_vop2_wait_for_port_mux_done(vop2);
+ }
+
vop2_writel(vop2, RK3568_OVL_LAYER_SEL, layer_sel);
mutex_unlock(&vop2->ovl_lock);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0102/1518] drm/rockchip: analogix_dp: Enable hclk for RK3588
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (100 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0101/1518] drm/rockchip: vop2: Wait for layer cfg done before switching LAYERSEL_REGDONE_SEL Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0103/1518] drm/rockchip: analogix_dp: Fix OF node reference leak via auto cleanup Greg Kroah-Hartman
` (896 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Damon Ding, Heiko Stuebner,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Damon Ding <damon.ding@rock-chips.com>
[ Upstream commit 104f20616d72825fdcf56cfdc5f89f4e96fd8dbe ]
Acquire and enable the HCLK_VO1 bus clock explicitly for RK3588
eDP controller to guarantee register and datapath access.
The clock was previously enabled implicitly via rockchip,vo-grf
phandle reference, which relies on side effect and is fragile.
Fetch optional "hclk" clock in driver to align with updated device
tree binding and keep consistent with hardware clock dependency.
Fixes: 729f8eefdcad ("drm/rockchip: analogix_dp: Add support for RK3588")
Signed-off-by: Damon Ding <damon.ding@rock-chips.com>
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Link: https://patch.msgid.link/20260601065100.1103873-6-damon.ding@rock-chips.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/rockchip/analogix_dp-rockchip.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/gpu/drm/rockchip/analogix_dp-rockchip.c b/drivers/gpu/drm/rockchip/analogix_dp-rockchip.c
index b905e28afa074..33e9183837487 100644
--- a/drivers/gpu/drm/rockchip/analogix_dp-rockchip.c
+++ b/drivers/gpu/drm/rockchip/analogix_dp-rockchip.c
@@ -328,6 +328,7 @@ static int rockchip_dp_of_probe(struct rockchip_dp_device *dp)
{
struct device *dev = dp->dev;
struct device_node *np = dev->of_node;
+ struct clk *clk;
dp->grf = syscon_regmap_lookup_by_phandle(np, "rockchip,grf");
if (IS_ERR(dp->grf)) {
@@ -351,6 +352,11 @@ static int rockchip_dp_of_probe(struct rockchip_dp_device *dp)
return PTR_ERR(dp->pclk);
}
+ clk = devm_clk_get_optional_enabled(dev, "hclk");
+ if (IS_ERR(clk))
+ return dev_err_probe(dev, PTR_ERR(clk),
+ "failed to get hclk property\n");
+
dp->rst = devm_reset_control_get(dev, "dp");
if (IS_ERR(dp->rst)) {
DRM_DEV_ERROR(dev, "failed to get dp reset control\n");
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0103/1518] drm/rockchip: analogix_dp: Fix OF node reference leak via auto cleanup
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (101 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0102/1518] drm/rockchip: analogix_dp: Enable hclk for RK3588 Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0104/1518] drm/bridge: display-connector: dont autoenable HPD IRQ Greg Kroah-Hartman
` (895 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Damon Ding, Heiko Stuebner,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Damon Ding <damon.ding@rock-chips.com>
[ Upstream commit 87e060521371257ddbb77964b66e60d80afcc7b2 ]
Sashiko reported a reference leak in rockchip_dp_drm_encoder_enable(),
the of_get_child_by_name() function does not call of_node_put() in a
symmetrical way [1].
Fix the device node reference leak by using __free(device_node) to
automatically manage of_node_put() for all device nodes.
Fixes: 729f8eefdcad ("drm/rockchip: analogix_dp: Add support for RK3588")
Link: https://sashiko.dev/#/patchset/20260527024336.191433-1-damon.ding@rock-chips.com?part=5 #1
Signed-off-by: Damon Ding <damon.ding@rock-chips.com>
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Link: https://patch.msgid.link/20260601065100.1103873-7-damon.ding@rock-chips.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/rockchip/analogix_dp-rockchip.c | 16 ++++++++++------
1 file changed, 10 insertions(+), 6 deletions(-)
diff --git a/drivers/gpu/drm/rockchip/analogix_dp-rockchip.c b/drivers/gpu/drm/rockchip/analogix_dp-rockchip.c
index 33e9183837487..7100fcb1650aa 100644
--- a/drivers/gpu/drm/rockchip/analogix_dp-rockchip.c
+++ b/drivers/gpu/drm/rockchip/analogix_dp-rockchip.c
@@ -8,6 +8,7 @@
* Jeff Chen <jeff.chen@rock-chips.com>
*/
+#include <linux/cleanup.h>
#include <linux/component.h>
#include <linux/mfd/syscon.h>
#include <linux/of.h>
@@ -223,7 +224,6 @@ static void rockchip_dp_drm_encoder_enable(struct drm_encoder *encoder,
struct drm_crtc *crtc;
struct drm_crtc_state *old_crtc_state;
struct of_endpoint endpoint;
- struct device_node *remote_port, *remote_port_parent;
char name[32];
u32 port_id;
int ret;
@@ -247,18 +247,22 @@ static void rockchip_dp_drm_encoder_enable(struct drm_encoder *encoder,
if (ret < 0)
return;
- remote_port_parent = of_graph_get_remote_port_parent(endpoint.local_node);
+ struct device_node *remote_port_parent __free(device_node) =
+ of_graph_get_remote_port_parent(endpoint.local_node);
if (remote_port_parent) {
- if (of_get_child_by_name(remote_port_parent, "ports")) {
- remote_port = of_graph_get_remote_port(endpoint.local_node);
+ struct device_node *ports __free(device_node) =
+ of_get_child_by_name(remote_port_parent, "ports");
+
+ if (ports) {
+ struct device_node *remote_port __free(device_node) =
+ of_graph_get_remote_port(endpoint.local_node);
+
of_property_read_u32(remote_port, "reg", &port_id);
- of_node_put(remote_port);
sprintf(name, "%s vp%d", remote_port_parent->full_name, port_id);
} else {
sprintf(name, "%s %s",
remote_port_parent->full_name, endpoint.id ? "vopl" : "vopb");
}
- of_node_put(remote_port_parent);
DRM_DEV_DEBUG(dp->dev, "vop %s output to dp\n", (ret) ? "LIT" : "BIG");
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0104/1518] drm/bridge: display-connector: dont autoenable HPD IRQ
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (102 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0103/1518] drm/rockchip: analogix_dp: Fix OF node reference leak via auto cleanup Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0105/1518] drm/bridge: display-connector: trigger initial HPD event for DP Greg Kroah-Hartman
` (894 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sebastian Reichel, Neil Armstrong,
Dmitry Baryshkov, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
[ Upstream commit 8e9c475060bff87077cfa3bd42011edcb7fb3b0d ]
If HPD IRQ is enabled in the display_connector's probe, it can be
triggered too early, before the DRM connector is completely setup. Use
the enable_hpd / disable_hpd callbacks to control enablement of the HPD
IRQ.
Fixes: 0c275c30176b ("drm/bridge: Add bridge driver for display connectors")
Reviewed-by: Sebastian Reichel <sebastian.reichel@collabora.com>
Reviewed-by: Neil Armstrong <neil.armstrong@linaro.org>
Link: https://patch.msgid.link/20260528-dp-connector-hpd-v3-2-d656eb1079b7@oss.qualcomm.com
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/bridge/display-connector.c | 17 +++++++++++++++++
1 file changed, 17 insertions(+)
diff --git a/drivers/gpu/drm/bridge/display-connector.c b/drivers/gpu/drm/bridge/display-connector.c
index 9a64fefbc903c..8b7b2036010c8 100644
--- a/drivers/gpu/drm/bridge/display-connector.c
+++ b/drivers/gpu/drm/bridge/display-connector.c
@@ -94,6 +94,20 @@ display_connector_bridge_detect(struct drm_bridge *bridge, struct drm_connector
return display_connector_detect(bridge);
}
+static void display_connector_hpd_enable(struct drm_bridge *bridge)
+{
+ struct display_connector *conn = to_display_connector(bridge);
+
+ enable_irq(conn->hpd_irq);
+}
+
+static void display_connector_hpd_disable(struct drm_bridge *bridge)
+{
+ struct display_connector *conn = to_display_connector(bridge);
+
+ disable_irq(conn->hpd_irq);
+}
+
static const struct drm_edid *display_connector_edid_read(struct drm_bridge *bridge,
struct drm_connector *connector)
{
@@ -186,6 +200,8 @@ static const struct drm_bridge_funcs display_connector_bridge_funcs = {
.attach = display_connector_attach,
.destroy = display_connector_destroy,
.detect = display_connector_bridge_detect,
+ .hpd_enable = display_connector_hpd_enable,
+ .hpd_disable = display_connector_hpd_disable,
.edid_read = display_connector_edid_read,
.atomic_get_output_bus_fmts = display_connector_get_output_bus_fmts,
.atomic_get_input_bus_fmts = display_connector_get_input_bus_fmts,
@@ -315,6 +331,7 @@ static int display_connector_probe(struct platform_device *pdev)
NULL, display_connector_hpd_irq,
IRQF_TRIGGER_RISING |
IRQF_TRIGGER_FALLING |
+ IRQF_NO_AUTOEN |
IRQF_ONESHOT,
"HPD", conn);
if (ret) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0105/1518] drm/bridge: display-connector: trigger initial HPD event for DP
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (103 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0104/1518] drm/bridge: display-connector: dont autoenable HPD IRQ Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0106/1518] drm/v3d: Clear queue->active_job when v3d_fence_create() fails Greg Kroah-Hartman
` (893 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yongxing Mou, Sebastian Reichel,
Dmitry Baryshkov, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
[ Upstream commit 60dc0946bbad3eef8bc66a5a8b09b98dbc6e09c0 ]
If the DisplayPort drivers use display-connector for the HPD detection,
the internal HPD state machine might be not active and thus the hardware
might be not able to handle cable detection correctly. Instead it will
depend on the external HPD notifications to set the cable state,
bypassing the internal HPD state machine (for example this is the case
for the msm DP driver).
However if the cable has been plugged before the HPD IRQ has been
enabled, there will be no HPD event coming. The drivers might fail
detection in such a case. Trigger the HPD notification after enabling
the HPD IRQ, propagating the cable insertion state.
Note, this issue only affects drivers which set OP_HPD but not OP_DETECT
(like dp-connector). Here DP differs from HDMI. For HDMI there is no
additional state or extra "bridge with no sinks plugged" cases. The HPD
pin state is equal to the display plugged state. Nor do we have an AUX
bus with timeouts, etc.
Fixes: 2e2bf3a5584d ("drm/bridge: display-connector: add DP support")
Reported-by: Yongxing Mou <yongxing.mou@oss.qualcomm.com>
Reviewed-by: Sebastian Reichel <sebastian.reichel@collabora.com>
Link: https://patch.msgid.link/20260528-dp-connector-hpd-v3-3-d656eb1079b7@oss.qualcomm.com
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/bridge/display-connector.c | 19 +++++++++++++++++++
1 file changed, 19 insertions(+)
diff --git a/drivers/gpu/drm/bridge/display-connector.c b/drivers/gpu/drm/bridge/display-connector.c
index 8b7b2036010c8..ba1d41816f3ec 100644
--- a/drivers/gpu/drm/bridge/display-connector.c
+++ b/drivers/gpu/drm/bridge/display-connector.c
@@ -12,6 +12,7 @@
#include <linux/of.h>
#include <linux/platform_device.h>
#include <linux/regulator/consumer.h>
+#include <linux/workqueue.h>
#include <drm/drm_atomic_helper.h>
#include <drm/drm_bridge.h>
@@ -25,6 +26,8 @@ struct display_connector {
struct regulator *supply;
struct gpio_desc *ddc_en;
+
+ struct work_struct hpd_work;
};
static inline struct display_connector *
@@ -99,15 +102,29 @@ static void display_connector_hpd_enable(struct drm_bridge *bridge)
struct display_connector *conn = to_display_connector(bridge);
enable_irq(conn->hpd_irq);
+
+ if (conn->bridge.type == DRM_MODE_CONNECTOR_DisplayPort)
+ schedule_work(&conn->hpd_work);
}
static void display_connector_hpd_disable(struct drm_bridge *bridge)
{
struct display_connector *conn = to_display_connector(bridge);
+ if (conn->bridge.type == DRM_MODE_CONNECTOR_DisplayPort)
+ cancel_work_sync(&conn->hpd_work);
+
disable_irq(conn->hpd_irq);
}
+static void display_connector_hpd_work(struct work_struct *work)
+{
+ struct display_connector *conn = container_of(work, struct display_connector, hpd_work);
+ struct drm_bridge *bridge = &conn->bridge;
+
+ drm_bridge_hpd_notify(bridge, display_connector_detect(bridge));
+}
+
static const struct drm_edid *display_connector_edid_read(struct drm_bridge *bridge,
struct drm_connector *connector)
{
@@ -403,6 +420,8 @@ static int display_connector_probe(struct platform_device *pdev)
conn->bridge.ops |= DRM_BRIDGE_OP_DETECT;
if (conn->hpd_irq >= 0)
conn->bridge.ops |= DRM_BRIDGE_OP_HPD;
+ if (conn->hpd_irq >= 0 && type == DRM_MODE_CONNECTOR_DisplayPort)
+ INIT_WORK(&conn->hpd_work, display_connector_hpd_work);
dev_dbg(&pdev->dev,
"Found %s display connector '%s' %s DDC bus and %s HPD GPIO (ops 0x%x)\n",
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0106/1518] drm/v3d: Clear queue->active_job when v3d_fence_create() fails
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (104 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0105/1518] drm/bridge: display-connector: trigger initial HPD event for DP Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0107/1518] drm/rockchip: vop2: Add RK3576 to the RG swap special case Greg Kroah-Hartman
` (892 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tvrtko Ursulin, Maíra Canal,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maíra Canal <mcanal@igalia.com>
[ Upstream commit 25a1669907512e927fab9ad4d4fb74ff57f63cd9 ]
The run_job() callbacks for BIN, RENDER, TFU and CSD assign the incoming
job to queue->active_job before calling v3d_fence_create(). If
v3d_fence_create() fails, the callback returns NULL without clearing
active_job, leaving a dangling pointer.
Create a failure path in all run_job() callbacks that clears the active
job before returning NULL. The BIN path takes queue->queue_lock around the
clear as it races against v3d_overflow_mem_work(); RENDER, TFU and CSD
paths have no concurrent reader, so the clear is lock-free.
Fixes: a783a09ee76d ("drm/v3d: Refactor job management.")
Reviewed-by: Tvrtko Ursulin <tvrtko.ursulin@igalia.com>
Link: https://patch.msgid.link/20260604-v3d-sched-misc-fixes-v4-2-c068f5bf5ccf@igalia.com
Signed-off-by: Maíra Canal <mcanal@igalia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/v3d/v3d_sched.c | 60 +++++++++++++++++++--------------
1 file changed, 34 insertions(+), 26 deletions(-)
diff --git a/drivers/gpu/drm/v3d/v3d_sched.c b/drivers/gpu/drm/v3d/v3d_sched.c
index 5bbf1b3e60ec3..9b98386965796 100644
--- a/drivers/gpu/drm/v3d/v3d_sched.c
+++ b/drivers/gpu/drm/v3d/v3d_sched.c
@@ -214,15 +214,11 @@ static struct dma_fence *v3d_bin_job_run(struct drm_sched_job *sched_job)
struct v3d_dev *v3d = job->base.v3d;
struct v3d_queue_state *queue = &v3d->queue[V3D_BIN];
struct drm_device *dev = &v3d->drm;
- struct dma_fence *fence;
+ struct dma_fence *fence = NULL;
unsigned long irqflags;
- if (unlikely(job->base.base.s_fence->finished.error)) {
- spin_lock_irqsave(&queue->queue_lock, irqflags);
- queue->active_job = NULL;
- spin_unlock_irqrestore(&queue->queue_lock, irqflags);
- return NULL;
- }
+ if (unlikely(job->base.base.s_fence->finished.error))
+ goto out_clean_job;
/* Lock required around bin_job update vs
* v3d_overflow_mem_work().
@@ -239,7 +235,7 @@ static struct dma_fence *v3d_bin_job_run(struct drm_sched_job *sched_job)
fence = v3d_fence_create(v3d, V3D_BIN);
if (IS_ERR(fence))
- return NULL;
+ goto out_clean_job;
if (job->base.irq_fence)
dma_fence_put(job->base.irq_fence);
@@ -267,6 +263,12 @@ static struct dma_fence *v3d_bin_job_run(struct drm_sched_job *sched_job)
V3D_CORE_WRITE(0, V3D_CLE_CT0QEA, job->end);
return fence;
+
+out_clean_job:
+ spin_lock_irqsave(&queue->queue_lock, irqflags);
+ queue->active_job = NULL;
+ spin_unlock_irqrestore(&queue->queue_lock, irqflags);
+ return fence;
}
static struct dma_fence *v3d_render_job_run(struct drm_sched_job *sched_job)
@@ -274,12 +276,10 @@ static struct dma_fence *v3d_render_job_run(struct drm_sched_job *sched_job)
struct v3d_render_job *job = to_render_job(sched_job);
struct v3d_dev *v3d = job->base.v3d;
struct drm_device *dev = &v3d->drm;
- struct dma_fence *fence;
+ struct dma_fence *fence = NULL;
- if (unlikely(job->base.base.s_fence->finished.error)) {
- v3d->queue[V3D_RENDER].active_job = NULL;
- return NULL;
- }
+ if (unlikely(job->base.base.s_fence->finished.error))
+ goto out_clean_job;
v3d->queue[V3D_RENDER].active_job = &job->base;
@@ -293,7 +293,7 @@ static struct dma_fence *v3d_render_job_run(struct drm_sched_job *sched_job)
fence = v3d_fence_create(v3d, V3D_RENDER);
if (IS_ERR(fence))
- return NULL;
+ goto out_clean_job;
if (job->base.irq_fence)
dma_fence_put(job->base.irq_fence);
@@ -314,6 +314,10 @@ static struct dma_fence *v3d_render_job_run(struct drm_sched_job *sched_job)
V3D_CORE_WRITE(0, V3D_CLE_CT1QEA, job->end);
return fence;
+
+out_clean_job:
+ v3d->queue[V3D_RENDER].active_job = NULL;
+ return fence;
}
static struct dma_fence *
@@ -322,18 +326,16 @@ v3d_tfu_job_run(struct drm_sched_job *sched_job)
struct v3d_tfu_job *job = to_tfu_job(sched_job);
struct v3d_dev *v3d = job->base.v3d;
struct drm_device *dev = &v3d->drm;
- struct dma_fence *fence;
+ struct dma_fence *fence = NULL;
- if (unlikely(job->base.base.s_fence->finished.error)) {
- v3d->queue[V3D_TFU].active_job = NULL;
- return NULL;
- }
+ if (unlikely(job->base.base.s_fence->finished.error))
+ goto out_clean_job;
v3d->queue[V3D_TFU].active_job = &job->base;
fence = v3d_fence_create(v3d, V3D_TFU);
if (IS_ERR(fence))
- return NULL;
+ goto out_clean_job;
if (job->base.irq_fence)
dma_fence_put(job->base.irq_fence);
@@ -361,6 +363,10 @@ v3d_tfu_job_run(struct drm_sched_job *sched_job)
V3D_WRITE(V3D_TFU_ICFG(v3d->ver), job->args.icfg | V3D_TFU_ICFG_IOC);
return fence;
+
+out_clean_job:
+ v3d->queue[V3D_TFU].active_job = NULL;
+ return fence;
}
static struct dma_fence *
@@ -369,13 +375,11 @@ v3d_csd_job_run(struct drm_sched_job *sched_job)
struct v3d_csd_job *job = to_csd_job(sched_job);
struct v3d_dev *v3d = job->base.v3d;
struct drm_device *dev = &v3d->drm;
- struct dma_fence *fence;
+ struct dma_fence *fence = NULL;
int i, csd_cfg0_reg;
- if (unlikely(job->base.base.s_fence->finished.error)) {
- v3d->queue[V3D_CSD].active_job = NULL;
- return NULL;
- }
+ if (unlikely(job->base.base.s_fence->finished.error))
+ goto out_clean_job;
/* The HW interprets a workgroup size of 0 as 65536; however, the
* user-space driver exposes a maximum of 65535. Therefore, a 0 in
@@ -393,7 +397,7 @@ v3d_csd_job_run(struct drm_sched_job *sched_job)
fence = v3d_fence_create(v3d, V3D_CSD);
if (IS_ERR(fence))
- return NULL;
+ goto out_clean_job;
if (job->base.irq_fence)
dma_fence_put(job->base.irq_fence);
@@ -420,6 +424,10 @@ v3d_csd_job_run(struct drm_sched_job *sched_job)
V3D_CORE_WRITE(0, csd_cfg0_reg, job->args.cfg[0]);
return fence;
+
+out_clean_job:
+ v3d->queue[V3D_CSD].active_job = NULL;
+ return fence;
}
static void
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0107/1518] drm/rockchip: vop2: Add RK3576 to the RG swap special case
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (105 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0106/1518] drm/v3d: Clear queue->active_job when v3d_fence_create() fails Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0108/1518] drm/rockchip: vop2: Recognise 10-bit YUV422 as YUV format Greg Kroah-Hartman
` (891 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Andy Yan, Daniel Stone,
Nicolas Frattaroli, Daniel Stone, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolas Frattaroli <nicolas.frattaroli@collabora.com>
[ Upstream commit ae4a4e69389d576941522c3c2e01a2254fd00d10 ]
Much like RK3588, RK3576 requires an RG swap to be performed for YUV444
8-bit and YUV444 10-bit bus formats.
Add its version to the already existing check for RK3588, so that YUV444
output is correct on this platform.
Fixes: 944757a4cba6 ("drm/rockchip: vop2: Add support for rk3576")
Reviewed-by: Andy Yan <andyshrk@163.com>
Reviewed-by: Daniel Stone <daniel@fooishbar.org>
Signed-off-by: Nicolas Frattaroli <nicolas.frattaroli@collabora.com>
Link: https://patch.msgid.link/20260609-color-format-v17-12-35739b5782cc@collabora.com
Signed-off-by: Daniel Stone <daniels@collabora.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/rockchip/rockchip_drm_vop2.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/rockchip/rockchip_drm_vop2.c b/drivers/gpu/drm/rockchip/rockchip_drm_vop2.c
index 7ec7bea5e38e6..a9ae9e472f56b 100644
--- a/drivers/gpu/drm/rockchip/rockchip_drm_vop2.c
+++ b/drivers/gpu/drm/rockchip/rockchip_drm_vop2.c
@@ -336,7 +336,8 @@ static bool vop2_output_uv_swap(u32 bus_format, u32 output_mode)
static bool vop2_output_rg_swap(struct vop2 *vop2, u32 bus_format)
{
- if (vop2->version == VOP_VERSION_RK3588) {
+ if (vop2->version == VOP_VERSION_RK3588 ||
+ vop2->version == VOP_VERSION_RK3576) {
if (bus_format == MEDIA_BUS_FMT_YUV8_1X24 ||
bus_format == MEDIA_BUS_FMT_YUV10_1X30)
return true;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0108/1518] drm/rockchip: vop2: Recognise 10-bit YUV422 as YUV format
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (106 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0107/1518] drm/rockchip: vop2: Add RK3576 to the RG swap special case Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0109/1518] drm/bridge: cdns-dsi: Return an error pointer on allocation failure Greg Kroah-Hartman
` (890 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Cristian Ciocaltea, Daniel Stone,
Nicolas Frattaroli, Daniel Stone, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolas Frattaroli <nicolas.frattaroli@collabora.com>
[ Upstream commit c1bfe8dac0a79d47eed313b9bcaa2658898684ec ]
The Rockchip VOP2 video output driver has a "is_yuv_output" function,
which returns true when a given bus format is a YUV format, and false
otherwise.
This switch statement is lacking the bus format used for YUV422 10-bit.
Add the two component orderings of the YUV422 10-bit bus formats to the
switch statement.
Fixes: 604be85547ce ("drm/rockchip: Add VOP2 driver")
Reviewed-by: Cristian Ciocaltea <cristian.ciocaltea@collabora.com>
Reviewed-by: Daniel Stone <daniel@fooishbar.org>
Signed-off-by: Nicolas Frattaroli <nicolas.frattaroli@collabora.com>
Link: https://patch.msgid.link/20260609-color-format-v17-13-35739b5782cc@collabora.com
Signed-off-by: Daniel Stone <daniels@collabora.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/rockchip/rockchip_drm_vop2.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/gpu/drm/rockchip/rockchip_drm_vop2.c b/drivers/gpu/drm/rockchip/rockchip_drm_vop2.c
index a9ae9e472f56b..3c48984d62448 100644
--- a/drivers/gpu/drm/rockchip/rockchip_drm_vop2.c
+++ b/drivers/gpu/drm/rockchip/rockchip_drm_vop2.c
@@ -351,6 +351,8 @@ static bool is_yuv_output(u32 bus_format)
switch (bus_format) {
case MEDIA_BUS_FMT_YUV8_1X24:
case MEDIA_BUS_FMT_YUV10_1X30:
+ case MEDIA_BUS_FMT_YUYV10_1X20:
+ case MEDIA_BUS_FMT_UYVY10_1X20:
case MEDIA_BUS_FMT_UYYVYY8_0_5X24:
case MEDIA_BUS_FMT_UYYVYY10_0_5X30:
case MEDIA_BUS_FMT_YUYV8_2X8:
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0109/1518] drm/bridge: cdns-dsi: Return an error pointer on allocation failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (107 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0108/1518] drm/rockchip: vop2: Recognise 10-bit YUV422 as YUV format Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0110/1518] drm/bridge: cdns-mhdp8546: " Greg Kroah-Hartman
` (889 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Luca Ceresoli, Thomas Zimmermann,
Maxime Ripard, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maxime Ripard <mripard@kernel.org>
[ Upstream commit 79ac5c68f1a49a9fdec596ee47577d5a1d52738f ]
The drm_bridge_funcs.atomic_reset documentation states that the hook
must return either a valid drm_bridge_state object or an ERR_PTR().
The cdns_dsi_bridge_atomic_reset() callback returns NULL when the
allocation of its state fails, violating this contract.
Return ERR_PTR(-ENOMEM) instead.
Fixes: a53d987756ea ("drm/bridge: cdns-dsi: Move DSI mode check to _atomic_check()")
Reviewed-by: Luca Ceresoli <luca.ceresoli@bootlin.com>
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Tested-by: Luca Ceresoli <luca.ceresoli@bootlin.com> # imx8mp + sn65dsi84 + bridge hotplug
Link: https://patch.msgid.link/20260619-drm-no-more-bridge-reset-v3-1-ff399263111b@kernel.org
Signed-off-by: Maxime Ripard <mripard@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/bridge/cadence/cdns-dsi-core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/bridge/cadence/cdns-dsi-core.c b/drivers/gpu/drm/bridge/cadence/cdns-dsi-core.c
index de2a32112913e..16b7e56142006 100644
--- a/drivers/gpu/drm/bridge/cadence/cdns-dsi-core.c
+++ b/drivers/gpu/drm/bridge/cadence/cdns-dsi-core.c
@@ -1015,7 +1015,7 @@ cdns_dsi_bridge_atomic_reset(struct drm_bridge *bridge)
dsi_state = kzalloc(sizeof(*dsi_state), GFP_KERNEL);
if (!dsi_state)
- return NULL;
+ return ERR_PTR(-ENOMEM);
memset(dsi_state, 0, sizeof(*dsi_state));
dsi_state->base.bridge = bridge;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0110/1518] drm/bridge: cdns-mhdp8546: Return an error pointer on allocation failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (108 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0109/1518] drm/bridge: cdns-dsi: Return an error pointer on allocation failure Greg Kroah-Hartman
@ 2026-09-12 6:37 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0111/1518] smack: fix incorrect task context in smack_msg_queue_msgrcv Greg Kroah-Hartman
` (888 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:37 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Thomas Zimmermann, Luca Ceresoli,
Maxime Ripard, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maxime Ripard <mripard@kernel.org>
[ Upstream commit 30ac1d403438a6c6039f0af5bb2df3d021f96036 ]
The drm_bridge_funcs.atomic_reset documentation states that the hook
must return either a valid drm_bridge_state object or an ERR_PTR().
The cdns_mhdp_bridge_atomic_reset() callback returns NULL when the
allocation of its state fails, violating this contract.
Return ERR_PTR(-ENOMEM) instead.
Fixes: fb43aa0acdfd ("drm: bridge: Add support for Cadence MHDP8546 DPI/DP bridge")
Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de>
Reviewed-by: Luca Ceresoli <luca.ceresoli@bootlin.com>
Tested-by: Luca Ceresoli <luca.ceresoli@bootlin.com> # imx8mp + sn65dsi84 + bridge hotplug
Link: https://patch.msgid.link/20260619-drm-no-more-bridge-reset-v3-2-ff399263111b@kernel.org
Signed-off-by: Maxime Ripard <mripard@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/bridge/cadence/cdns-mhdp8546-core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/bridge/cadence/cdns-mhdp8546-core.c b/drivers/gpu/drm/bridge/cadence/cdns-mhdp8546-core.c
index 7ee19b7cc92fc..f81db7da711d2 100644
--- a/drivers/gpu/drm/bridge/cadence/cdns-mhdp8546-core.c
+++ b/drivers/gpu/drm/bridge/cadence/cdns-mhdp8546-core.c
@@ -2088,7 +2088,7 @@ cdns_mhdp_bridge_atomic_reset(struct drm_bridge *bridge)
cdns_mhdp_state = kzalloc(sizeof(*cdns_mhdp_state), GFP_KERNEL);
if (!cdns_mhdp_state)
- return NULL;
+ return ERR_PTR(-ENOMEM);
__drm_atomic_helper_bridge_reset(bridge, &cdns_mhdp_state->base);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0111/1518] smack: fix incorrect task context in smack_msg_queue_msgrcv
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (109 preceding siblings ...)
2026-09-12 6:37 ` [PATCH 6.18 0110/1518] drm/bridge: cdns-mhdp8546: " Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0112/1518] smack: simplify write handlers of sysfs entries Greg Kroah-Hartman
` (887 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Konstantin Andreev, Casey Schaufler,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Konstantin Andreev <andreev@swemel.ru>
[ Upstream commit fba3d32825f4bbc8e20f0cdc3b14df57965b8fe5 ]
The smack_msg_queue_msgrcv() function incorrectly checks
the permissions of the 'current' task instead of the
'target' task.
In the msgsnd() syscall path, if a receiver is already waiting,
the pipelined_send() optimization is used to push the message
directly to the receiver task:
ipc/msg.c`pipelined_send():
` smp_store_release(&msr->r_msg, msg)
In this case, the 'sender' (current) task performs the check
on behalf of the 'receiver' task (msr->r_tsk, passed as the
'target' parameter):
ipc/msg.c`pipelined_send():
` security_msg_queue_msgrcv(,, target := msr->r_tsk,,)
However, smack_msg_queue_msgrcv() ignores the 'target' and
checks 'current':
smack_msg_queue_msgrcv(…)
` smk_curacc_msq(isp, MAY_READWRITE); // current task
'current' MAY satisfy smack_msg_queue_msgrcv r/w requirement,
but 'target' (the receiver task) might NOT;
as a result, an unauthorized receiver gets the message,
violating MAC policy.
Test:
1) create a sysv message queue with label “foo”
2) echo "bar foo r" >/smack/load2
3) msgrcv(,,,0,MSG_NOERROR) in "bar"-labeled task.
The task is waiting for the messages ...
4) msgsnd() from a "foo"-labeled task:
"bar"-labeled task gets the message.
This patch fixes the issue by checking permission on the
'target' task instead of 'current'.
(2008-02-04, Casey Schaufler)
Fixes: e114e473771c ("Smack: Simplified Mandatory Access Control Kernel")
Signed-off-by: Konstantin Andreev <andreev@swemel.ru>
Signed-off-by: Casey Schaufler <casey@schaufler-ca.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
security/smack/smack_lsm.c | 65 +++++++++++++++++++++++++++-----------
1 file changed, 47 insertions(+), 18 deletions(-)
diff --git a/security/smack/smack_lsm.c b/security/smack/smack_lsm.c
index 8a53605546c4a..217304cd20c3b 100644
--- a/security/smack/smack_lsm.c
+++ b/security/smack/smack_lsm.c
@@ -130,12 +130,13 @@ static int smk_bu_note(char *note, struct smack_known *sskp,
#define smk_bu_note(note, sskp, oskp, mode, RC) (RC)
#endif
-#ifdef CONFIG_SECURITY_SMACK_BRINGUP
-static int smk_bu_current(char *note, struct smack_known *oskp,
- int mode, int rc)
+static int
+smk_bu_tsk_to_obj(struct task_struct *tsk, const struct task_smack *tsp,
+ char *note, struct smack_known *oskp, int mode, int rc)
{
- struct task_smack *tsp = smack_cred(current_cred());
+#ifdef CONFIG_SECURITY_SMACK_BRINGUP
char acc[SMK_NUM_ACCESS_TYPE + 1];
+ char comm[TASK_COMM_LEN];
if (rc <= 0)
return rc;
@@ -143,14 +144,22 @@ static int smk_bu_current(char *note, struct smack_known *oskp,
rc = 0;
smk_bu_mode(mode, acc);
+
pr_info("Smack %s: (%s %s %s) %s %s\n", smk_bu_mess[rc],
- tsp->smk_task->smk_known, oskp->smk_known,
- acc, current->comm, note);
+ smk_of_task(tsp)->smk_known, oskp->smk_known,
+ acc, get_task_comm(comm, tsk), note);
return 0;
-}
#else
-#define smk_bu_current(note, oskp, mode, RC) (RC)
+ return rc;
#endif
+}
+
+static int smk_bu_current(char *note, struct smack_known *oskp,
+ int mode, int rc)
+{
+ return smk_bu_tsk_to_obj(current, smack_cred(current_cred()),
+ note, oskp, mode, rc);
+}
#ifdef CONFIG_SECURITY_SMACK_BRINGUP
static int smk_bu_task(struct task_struct *otp, int mode, int rc)
@@ -3353,14 +3362,20 @@ static int smack_sem_semop(struct kern_ipc_perm *isp, struct sembuf *sops,
}
/**
- * smk_curacc_msq : helper to check if current has access on msq
- * @isp : the msq
+ * smk_tskacc_msq : helper to check if tsk has access on msq
+ * @tsk: the task that requests access
+ * @isp : the sysv msg queue permissions
* @access : access requested
*
- * return 0 if current has access, error otherwise
+ * return 0 if tsk has access, error otherwise
*/
-static int smk_curacc_msq(struct kern_ipc_perm *isp, int access)
+static int
+smk_tskacc_msq(struct task_struct *tsk, struct kern_ipc_perm *isp, int access)
{
+ const bool tsk_is_current = (tsk == current);
+ const struct cred * const tsk_cred =
+ (tsk_is_current ? current_cred() : get_task_cred(tsk));
+ struct task_smack * const tsp = smack_cred(tsk_cred);
struct smack_known *msp = smack_of_ipc(isp);
struct smk_audit_info ad;
int rc;
@@ -3369,11 +3384,25 @@ static int smk_curacc_msq(struct kern_ipc_perm *isp, int access)
smk_ad_init(&ad, __func__, LSM_AUDIT_DATA_IPC);
ad.a.u.ipc_id = isp->id;
#endif
- rc = smk_curacc(msp, access, &ad);
- rc = smk_bu_current("msq", msp, access, rc);
+ rc = smk_tskacc(tsp, msp, access, &ad);
+ rc = smk_bu_tsk_to_obj(tsk, tsp, "msq", msp, access, rc);
+ if (!tsk_is_current)
+ put_cred(tsk_cred);
return rc;
}
+/**
+ * smk_curacc_msq : helper to check if current has access on msq
+ * @isp : the sysv msg queue permissions
+ * @access : access requested
+ *
+ * return 0 if current has access, error otherwise
+ */
+static int smk_curacc_msq(struct kern_ipc_perm *isp, int access)
+{
+ return smk_tskacc_msq(current, isp, access);
+}
+
/**
* smack_msg_queue_associate - Smack access check for msg_queue
* @isp: the object
@@ -3441,21 +3470,21 @@ static int smack_msg_queue_msgsnd(struct kern_ipc_perm *isp, struct msg_msg *msg
}
/**
- * smack_msg_queue_msgrcv - Smack access check for msg_queue
+ * smack_msg_queue_msgrcv - check it target has r/w access to msg_queue
* @isp: the object
* @msg: unused
- * @target: unused
+ * @target: the task that msgrcv() from the queue
* @type: unused
* @mode: unused
*
- * Returns 0 if current has read and write access, error code otherwise
+ * Returns 0 if target has read and write access, error code otherwise
*/
static int smack_msg_queue_msgrcv(struct kern_ipc_perm *isp,
struct msg_msg *msg,
struct task_struct *target, long type,
int mode)
{
- return smk_curacc_msq(isp, MAY_READWRITE);
+ return smk_tskacc_msq(target, isp, MAY_READWRITE);
}
/**
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0112/1518] smack: simplify write handlers of sysfs entries
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (110 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0111/1518] smack: fix incorrect task context in smack_msg_queue_msgrcv Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0113/1518] smack: deduplicate smackfs/{direct,mapped} file_operations Greg Kroah-Hartman
` (886 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dmitry Antipov, Casey Schaufler,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Antipov <dmantipov@yandex.ru>
[ Upstream commit b78fede1c69a090d377bf80417ce1f7f7f314534 ]
Use the convenient 'kstrto{u,s}32_from_user()' to simplify write
handlers of /smack/{doi,direct,mapped,logging,ptrace} sysfs entries.
Signed-off-by: Dmitry Antipov <dmantipov@yandex.ru>
Signed-off-by: Casey Schaufler <casey@schaufler-ca.com>
Stable-dep-of: 577dc3b6a8cf ("smack: deduplicate smackfs/{direct,mapped} file_operations")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
security/smack/smackfs.c | 81 +++++++++++-----------------------------
1 file changed, 22 insertions(+), 59 deletions(-)
diff --git a/security/smack/smackfs.c b/security/smack/smackfs.c
index d27d9140dda2f..6b04c144b53b2 100644
--- a/security/smack/smackfs.c
+++ b/security/smack/smackfs.c
@@ -1598,24 +1598,17 @@ static ssize_t smk_read_doi(struct file *filp, char __user *buf,
static ssize_t smk_write_doi(struct file *file, const char __user *buf,
size_t count, loff_t *ppos)
{
- char temp[80];
- unsigned long u;
+ int ret;
+ u32 u;
if (!smack_privileged(CAP_MAC_ADMIN))
return -EPERM;
- if (count >= sizeof(temp) || count == 0)
- return -EINVAL;
-
- if (copy_from_user(temp, buf, count) != 0)
- return -EFAULT;
-
- temp[count] = '\0';
+ ret = kstrtou32_from_user(buf, count, 10, &u);
+ if (unlikely(ret))
+ return ret;
- if (kstrtoul(temp, 10, &u))
- return -EINVAL;
-
- if (u == CIPSO_V4_DOI_UNKNOWN || u > U32_MAX)
+ if (u == CIPSO_V4_DOI_UNKNOWN)
return -EINVAL;
return smk_cipso_doi(u, GFP_KERNEL) ? : count;
@@ -1664,22 +1657,14 @@ static ssize_t smk_write_direct(struct file *file, const char __user *buf,
size_t count, loff_t *ppos)
{
struct smack_known *skp;
- char temp[80];
- int i;
+ int i, ret;
if (!smack_privileged(CAP_MAC_ADMIN))
return -EPERM;
- if (count >= sizeof(temp) || count == 0)
- return -EINVAL;
-
- if (copy_from_user(temp, buf, count) != 0)
- return -EFAULT;
-
- temp[count] = '\0';
-
- if (sscanf(temp, "%d", &i) != 1)
- return -EINVAL;
+ ret = kstrtos32_from_user(buf, count, 10, &i);
+ if (unlikely(ret))
+ return ret;
/*
* Don't do anything if the value hasn't actually changed.
@@ -1742,22 +1727,14 @@ static ssize_t smk_write_mapped(struct file *file, const char __user *buf,
size_t count, loff_t *ppos)
{
struct smack_known *skp;
- char temp[80];
- int i;
+ int i, ret;
if (!smack_privileged(CAP_MAC_ADMIN))
return -EPERM;
- if (count >= sizeof(temp) || count == 0)
- return -EINVAL;
-
- if (copy_from_user(temp, buf, count) != 0)
- return -EFAULT;
-
- temp[count] = '\0';
-
- if (sscanf(temp, "%d", &i) != 1)
- return -EINVAL;
+ ret = kstrtos32_from_user(buf, count, 10, &i);
+ if (unlikely(ret))
+ return ret;
/*
* Don't do anything if the value hasn't actually changed.
@@ -2179,22 +2156,15 @@ static ssize_t smk_read_logging(struct file *filp, char __user *buf,
static ssize_t smk_write_logging(struct file *file, const char __user *buf,
size_t count, loff_t *ppos)
{
- char temp[32];
- int i;
+ int i, ret;
if (!smack_privileged(CAP_MAC_ADMIN))
return -EPERM;
- if (count >= sizeof(temp) || count == 0)
- return -EINVAL;
-
- if (copy_from_user(temp, buf, count) != 0)
- return -EFAULT;
+ ret = kstrtos32_from_user(buf, count, 10, &i);
+ if (unlikely(ret))
+ return ret;
- temp[count] = '\0';
-
- if (sscanf(temp, "%d", &i) != 1)
- return -EINVAL;
if (i < 0 || i > 3)
return -EINVAL;
log_policy = i;
@@ -2838,22 +2808,15 @@ static ssize_t smk_read_ptrace(struct file *filp, char __user *buf,
static ssize_t smk_write_ptrace(struct file *file, const char __user *buf,
size_t count, loff_t *ppos)
{
- char temp[32];
- int i;
+ int i, ret;
if (!smack_privileged(CAP_MAC_ADMIN))
return -EPERM;
- if (*ppos != 0 || count >= sizeof(temp) || count == 0)
- return -EINVAL;
-
- if (copy_from_user(temp, buf, count) != 0)
- return -EFAULT;
+ ret = kstrtos32_from_user(buf, count, 10, &i);
+ if (unlikely(ret))
+ return ret;
- temp[count] = '\0';
-
- if (sscanf(temp, "%d", &i) != 1)
- return -EINVAL;
if (i < SMACK_PTRACE_DEFAULT || i > SMACK_PTRACE_MAX)
return -EINVAL;
smack_ptrace_rule = i;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0113/1518] smack: deduplicate smackfs/{direct,mapped} file_operations
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (111 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0112/1518] smack: simplify write handlers of sysfs entries Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0114/1518] smack: restrict smackfs/{direct,mapped} values to 0-255 Greg Kroah-Hartman
` (885 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Konstantin Andreev, Casey Schaufler,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Konstantin Andreev <andreev@swemel.ru>
[ Upstream commit 577dc3b6a8cf200e6e27b2d9967cac14a1fed2f3 ]
The file_operations for smackfs/direct and smackfs/mapped are
identical up to a textual replacement of "direct" with "mapped"
This patch combines two instances of file_operations into one,
handling both files.
Fixes: f7112e6c9abf ("Smack: allow for significantly longer Smack labels v4")
Signed-off-by: Konstantin Andreev <andreev@swemel.ru>
Signed-off-by: Casey Schaufler <casey@schaufler-ca.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
security/smack/smack.h | 5 +-
security/smack/smackfs.c | 133 ++++++++++++---------------------------
2 files changed, 42 insertions(+), 96 deletions(-)
diff --git a/security/smack/smack.h b/security/smack/smack.h
index 759343a6bbaeb..d3c3198ab85e4 100644
--- a/security/smack/smack.h
+++ b/security/smack/smack.h
@@ -303,8 +303,9 @@ int smack_populate_secattr(struct smack_known *skp);
* Shared data.
*/
extern int smack_enabled __initdata;
-extern int smack_cipso_direct;
-extern int smack_cipso_mapped;
+extern int smack_cipso_auto_level[2];
+#define smack_cipso_direct (+smack_cipso_auto_level[0])
+#define smack_cipso_mapped (+smack_cipso_auto_level[1])
extern struct smack_known *smack_net_ambient;
extern struct smack_known *smack_syslog_label;
#ifdef CONFIG_SECURITY_SMACK_BRINGUP
diff --git a/security/smack/smackfs.c b/security/smack/smackfs.c
index 6b04c144b53b2..f86597b084c1e 100644
--- a/security/smack/smackfs.c
+++ b/security/smack/smackfs.c
@@ -83,18 +83,27 @@ static DEFINE_MUTEX(smk_net6addr_lock);
struct smack_known *smack_net_ambient;
/*
- * This is the level in a CIPSO header that indicates a
+ * Sensitivity levels for automatically created CIPSO labels.
+ * See smack_access.c`smack_populate_secattr()
+ *
+ * [0] "direct" labeling, label length < SMK_CIPSOLEN(24):
* smack label is contained directly in the category set.
* It can be reset via smackfs/direct
- */
-int smack_cipso_direct = SMACK_CIPSO_DIRECT_DEFAULT;
-
-/*
- * This is the level in a CIPSO header that indicates a
+ *
+ * [1] "mapped" labeling, label length >= SMK_CIPSOLEN(24):
* secid is contained directly in the category set.
* It can be reset via smackfs/mapped
*/
-int smack_cipso_mapped = SMACK_CIPSO_MAPPED_DEFAULT;
+int smack_cipso_auto_level[2] = {
+ SMACK_CIPSO_DIRECT_DEFAULT,
+ SMACK_CIPSO_MAPPED_DEFAULT,
+};
+
+static int
+smk_cipso_auto_level_idx(const struct file *file)
+{
+ return (file_inode(file)->i_ino != SMK_DIRECT);
+}
#ifdef CONFIG_SECURITY_SMACK_BRINGUP
/*
@@ -1621,15 +1630,15 @@ static const struct file_operations smk_doi_ops = {
};
/**
- * smk_read_direct - read() for /smack/direct
- * @filp: file pointer, not actually used
+ * smk_read_cipso_auto_level - read() for smackfs/direct and smackfs/mapped
+ * @filp: file pointer
* @buf: where to put the result
* @count: maximum to send along
* @ppos: where to start
*
* Returns number of bytes read or error code, as appropriate
*/
-static ssize_t smk_read_direct(struct file *filp, char __user *buf,
+static ssize_t smk_read_cipso_auto_level(struct file *filp, char __user *buf,
size_t count, loff_t *ppos)
{
char temp[80];
@@ -1638,26 +1647,28 @@ static ssize_t smk_read_direct(struct file *filp, char __user *buf,
if (*ppos != 0)
return 0;
- sprintf(temp, "%d", smack_cipso_direct);
+ sprintf(temp, "%d", smack_cipso_auto_level[
+ smk_cipso_auto_level_idx(filp)]);
rc = simple_read_from_buffer(buf, count, ppos, temp, strlen(temp));
return rc;
}
/**
- * smk_write_direct - write() for /smack/direct
- * @file: file pointer, not actually used
+ * smk_write_cipso_auto_level - write() for smackfs/direct and smackfs/mapped
+ * @filp: file pointer
* @buf: where to get the data from
* @count: bytes sent
* @ppos: where to start
*
* Returns number of bytes written or error code, as appropriate
*/
-static ssize_t smk_write_direct(struct file *file, const char __user *buf,
- size_t count, loff_t *ppos)
+static ssize_t
+smk_write_cipso_auto_level(struct file *filp, const char __user *buf,
+ size_t count, loff_t *ppos)
{
struct smack_known *skp;
- int i, ret;
+ int i, ret, idx, old_lvl;
if (!smack_privileged(CAP_MAC_ADMIN))
return -EPERM;
@@ -1669,94 +1680,28 @@ static ssize_t smk_write_direct(struct file *file, const char __user *buf,
/*
* Don't do anything if the value hasn't actually changed.
* If it is changing reset the level on entries that were
- * set up to be direct when they were created.
+ * set up to be "auto" level when they were created.
*/
- if (smack_cipso_direct != i) {
- mutex_lock(&smack_known_lock);
- list_for_each_entry_rcu(skp, &smack_known_list, list)
- if (skp->smk_netlabel.attr.mls.lvl ==
- smack_cipso_direct)
- skp->smk_netlabel.attr.mls.lvl = i;
- smack_cipso_direct = i;
- mutex_unlock(&smack_known_lock);
- }
-
- return count;
-}
+ idx = smk_cipso_auto_level_idx(filp);
+ old_lvl = smack_cipso_auto_level[idx];
-static const struct file_operations smk_direct_ops = {
- .read = smk_read_direct,
- .write = smk_write_direct,
- .llseek = default_llseek,
-};
-
-/**
- * smk_read_mapped - read() for /smack/mapped
- * @filp: file pointer, not actually used
- * @buf: where to put the result
- * @count: maximum to send along
- * @ppos: where to start
- *
- * Returns number of bytes read or error code, as appropriate
- */
-static ssize_t smk_read_mapped(struct file *filp, char __user *buf,
- size_t count, loff_t *ppos)
-{
- char temp[80];
- ssize_t rc;
-
- if (*ppos != 0)
- return 0;
-
- sprintf(temp, "%d", smack_cipso_mapped);
- rc = simple_read_from_buffer(buf, count, ppos, temp, strlen(temp));
-
- return rc;
-}
-
-/**
- * smk_write_mapped - write() for /smack/mapped
- * @file: file pointer, not actually used
- * @buf: where to get the data from
- * @count: bytes sent
- * @ppos: where to start
- *
- * Returns number of bytes written or error code, as appropriate
- */
-static ssize_t smk_write_mapped(struct file *file, const char __user *buf,
- size_t count, loff_t *ppos)
-{
- struct smack_known *skp;
- int i, ret;
-
- if (!smack_privileged(CAP_MAC_ADMIN))
- return -EPERM;
-
- ret = kstrtos32_from_user(buf, count, 10, &i);
- if (unlikely(ret))
- return ret;
-
- /*
- * Don't do anything if the value hasn't actually changed.
- * If it is changing reset the level on entries that were
- * set up to be mapped when they were created.
- */
- if (smack_cipso_mapped != i) {
+ if (old_lvl != i) {
mutex_lock(&smack_known_lock);
list_for_each_entry_rcu(skp, &smack_known_list, list)
if (skp->smk_netlabel.attr.mls.lvl ==
- smack_cipso_mapped)
+ old_lvl)
skp->smk_netlabel.attr.mls.lvl = i;
- smack_cipso_mapped = i;
+ smack_cipso_auto_level[idx] = i;
mutex_unlock(&smack_known_lock);
}
return count;
}
-static const struct file_operations smk_mapped_ops = {
- .read = smk_read_mapped,
- .write = smk_write_mapped,
+static const struct file_operations
+smk_cipso_auto_level_ops = {
+ .read = smk_read_cipso_auto_level,
+ .write = smk_write_cipso_auto_level,
.llseek = default_llseek,
};
@@ -2851,7 +2796,7 @@ static int smk_fill_super(struct super_block *sb, struct fs_context *fc)
[SMK_DOI] = {
"doi", &smk_doi_ops, S_IRUGO|S_IWUSR},
[SMK_DIRECT] = {
- "direct", &smk_direct_ops, S_IRUGO|S_IWUSR},
+ "direct", &smk_cipso_auto_level_ops, 0644},
[SMK_AMBIENT] = {
"ambient", &smk_ambient_ops, S_IRUGO|S_IWUSR},
[SMK_NET4ADDR] = {
@@ -2867,7 +2812,7 @@ static int smk_fill_super(struct super_block *sb, struct fs_context *fc)
[SMK_ACCESSES] = {
"access", &smk_access_ops, S_IRUGO|S_IWUGO},
[SMK_MAPPED] = {
- "mapped", &smk_mapped_ops, S_IRUGO|S_IWUSR},
+ "mapped", &smk_cipso_auto_level_ops, 0644},
[SMK_LOAD2] = {
"load2", &smk_load2_ops, S_IRUGO|S_IWUSR},
[SMK_LOAD_SELF2] = {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0114/1518] smack: restrict smackfs/{direct,mapped} values to 0-255
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (112 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0113/1518] smack: deduplicate smackfs/{direct,mapped} file_operations Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0115/1518] sched_ext/scx_flatcg: Fix cvtime_delta race and add hweight scaling to bypass charging Greg Kroah-Hartman
` (884 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Konstantin Andreev, Casey Schaufler,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Konstantin Andreev <andreev@swemel.ru>
[ Upstream commit a7c44fd9f80e37763acf9cd3c87a58058d206427 ]
Both smackfs/direct and smackfs/mapped incorrectly accept
the full range of integer values. For example:
# cd /sys/fs/smackfs/
# cat direct ; echo
250
# cat cipso2
@ 250/2
_ 250/2,4,5,6,7,8
* 250/3,5,7
^ 250/2,4,5,6,7
? 250/3,4,5,6,7,8
# echo -1234 >direct ; cat direct ; echo
-1234
# cat cipso2
@ -1234/2
_ -1234/2,4,5,6,7,8
* -1234/3,5,7
^ -1234/2,4,5,6,7
? -1234/3,4,5,6,7,8
#
I noticed two things regarding this:
1) sensitivity levels are truncated to 8 bits when labeling
outgoing packets (0x2e = 46 for the -1234 example above)
2) the reverse process fails: incoming packets with sensitivity
level 46 do not match these smackfs/cipso2 entries.
Even observation (1) on its own warrants a fix.
This patch restricts smackfs/direct and smackfs/mapped
accepted values to the 0-255 range.
Fixes: e114e473771c ("Smack: Simplified Mandatory Access Control Kernel")
Signed-off-by: Konstantin Andreev <andreev@swemel.ru>
Signed-off-by: Casey Schaufler <casey@schaufler-ca.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
security/smack/smack.h | 2 +-
security/smack/smackfs.c | 26 ++++++++++++++------------
2 files changed, 15 insertions(+), 13 deletions(-)
diff --git a/security/smack/smack.h b/security/smack/smack.h
index d3c3198ab85e4..4f7f4760e432a 100644
--- a/security/smack/smack.h
+++ b/security/smack/smack.h
@@ -303,7 +303,7 @@ int smack_populate_secattr(struct smack_known *skp);
* Shared data.
*/
extern int smack_enabled __initdata;
-extern int smack_cipso_auto_level[2];
+extern u8 smack_cipso_auto_level[2];
#define smack_cipso_direct (+smack_cipso_auto_level[0])
#define smack_cipso_mapped (+smack_cipso_auto_level[1])
extern struct smack_known *smack_net_ambient;
diff --git a/security/smack/smackfs.c b/security/smack/smackfs.c
index f86597b084c1e..32db00102d1d1 100644
--- a/security/smack/smackfs.c
+++ b/security/smack/smackfs.c
@@ -94,7 +94,7 @@ struct smack_known *smack_net_ambient;
* secid is contained directly in the category set.
* It can be reset via smackfs/mapped
*/
-int smack_cipso_auto_level[2] = {
+u8 smack_cipso_auto_level[2] = {
SMACK_CIPSO_DIRECT_DEFAULT,
SMACK_CIPSO_MAPPED_DEFAULT,
};
@@ -1641,17 +1641,15 @@ static const struct file_operations smk_doi_ops = {
static ssize_t smk_read_cipso_auto_level(struct file *filp, char __user *buf,
size_t count, loff_t *ppos)
{
- char temp[80];
- ssize_t rc;
+ char temp[sizeof "255"];
+ int n;
if (*ppos != 0)
return 0;
- sprintf(temp, "%d", smack_cipso_auto_level[
- smk_cipso_auto_level_idx(filp)]);
- rc = simple_read_from_buffer(buf, count, ppos, temp, strlen(temp));
-
- return rc;
+ n = sprintf(temp, "%u", (unsigned int)smack_cipso_auto_level[
+ smk_cipso_auto_level_idx(filp)]);
+ return simple_read_from_buffer(buf, count, ppos, temp, n);
}
/**
@@ -1667,13 +1665,16 @@ static ssize_t
smk_write_cipso_auto_level(struct file *filp, const char __user *buf,
size_t count, loff_t *ppos)
{
- struct smack_known *skp;
- int i, ret, idx, old_lvl;
+ int ret, idx;
+ u8 i, old_lvl;
if (!smack_privileged(CAP_MAC_ADMIN))
return -EPERM;
-
- ret = kstrtos32_from_user(buf, count, 10, &i);
+ /*
+ * draft-ietf-cipso-ipsecurity-01 (CIPSO 2.2), 3.4.2.4:
+ * "Sensitivity Level is 1 octet in length. Its value is from 0 to 255"
+ */
+ ret = kstrtou8_from_user(buf, count, 10, &i);
if (unlikely(ret))
return ret;
@@ -1686,6 +1687,7 @@ smk_write_cipso_auto_level(struct file *filp, const char __user *buf,
old_lvl = smack_cipso_auto_level[idx];
if (old_lvl != i) {
+ struct smack_known *skp;
mutex_lock(&smack_known_lock);
list_for_each_entry_rcu(skp, &smack_known_list, list)
if (skp->smk_netlabel.attr.mls.lvl ==
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0115/1518] sched_ext/scx_flatcg: Fix cvtime_delta race and add hweight scaling to bypass charging
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (113 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0114/1518] smack: restrict smackfs/{direct,mapped} values to 0-255 Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0116/1518] x86/cfi: Use symmetric SYM_START and SYM_END in __CFI_TYPE() Greg Kroah-Hartman
` (883 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Wanwu Li, Andrea Righi, Tejun Heo,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wanwu Li <liwanwu@kylinos.cn>
[ Upstream commit a5cc43414b38decd50bdd447e558358a6fbd5864 ]
1. cgrp_cap_budget() used __sync_fetch_and_sub(&cgc->cvtime_delta,
cgc->cvtime_delta) to atomically read and clear cvtime_delta. However,
this is not a true atomic read-clear operation: the second argument
(cgc->cvtime_delta) is evaluated as a normal read before the atomic
fetch_and_sub executes. If a concurrent __sync_fetch_and_add() happens
between the read and the sub, the added value gets included in the
returned delta AND remains in cvtime_delta, causing double charging.
Example:
CPU 0 runs cgrp_cap_budget(), CPU 1 runs fcg_stopping().
Assume cvtime_delta = 100 initially.
T1 CPU 0: sub_val = cvtime_delta = 100 cvtime_delta = 100
T2 CPU 1: __sync_fetch_and_add(&cvtime_delta, 10) cvtime_delta = 110
T3 CPU 0: __sync_fetch_and_sub(&cvtime_delta, sub_val) cvtime_delta = 10
returns old=110
delta = 110 (includes the 10 from CPU 1), but cvtime_delta = 10
(the 10 also remains). The 10 is charged twice: once in delta
(applied to cgv_node->cvtime) and once in the residual cvtime_delta
(fetched again next time).
Fix by using __sync_fetch_and_and(&cgc->cvtime_delta, 0).
Disassembly comparison:
(1) delta = __sync_fetch_and_sub(&cgc->cvtime_delta, cgc->cvtime_delta);
228: (79) r7 = *(u64 *)(r9 +40)
229: (87) r7 = -r7
230: (db) r7 = atomic64_fetch_add((u64 *)(r9 +40), r7) //r9 may be changed
(2) delta = __sync_fetch_and_and(&cgc->cvtime_delta, 0);
228: (b7) r8 = 0
229: (db) r8 = atomic64_xchg((u64 *)(r9 +40), r8)
2. The bypass charging path in fcg_stopping() charges raw execution time
to cvtime_delta without scaling by the inverse of the cgroup hweight.
Since cvtime_delta is eventually applied to cgv_node->cvtime which is
in vtime space (weight-scaled), the bypass path should also scale by
FCG_HWEIGHT_ONE / hweight to match the units used by the dispatch path.
Fixes: a4103eacc2ab ("sched_ext: Add a cgroup scheduler which uses flattened hierarchy")
Signed-off-by: Wanwu Li <liwanwu@kylinos.cn>
Reviewed-by: Andrea Righi <arighi@nvidia.com>
Signed-off-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/sched_ext/scx_flatcg.bpf.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/tools/sched_ext/scx_flatcg.bpf.c b/tools/sched_ext/scx_flatcg.bpf.c
index 2c720e3ecad59..eab9dafc8cb31 100644
--- a/tools/sched_ext/scx_flatcg.bpf.c
+++ b/tools/sched_ext/scx_flatcg.bpf.c
@@ -256,7 +256,7 @@ static void cgrp_cap_budget(struct cgv_node *cgv_node, struct fcg_cgrp_ctx *cgc)
* and thus can't be updated and repositioned. Instead, we collect the
* vtime deltas separately and apply it asynchronously here.
*/
- delta = __sync_fetch_and_sub(&cgc->cvtime_delta, cgc->cvtime_delta);
+ delta = __sync_fetch_and_and(&cgc->cvtime_delta, 0);
cvtime = cgv_node->cvtime + delta;
/*
@@ -568,7 +568,8 @@ void BPF_STRUCT_OPS(fcg_stopping, struct task_struct *p, bool runnable)
cgc = find_cgrp_ctx(cgrp);
if (cgc) {
__sync_fetch_and_add(&cgc->cvtime_delta,
- p->se.sum_exec_runtime - taskc->bypassed_at);
+ (p->se.sum_exec_runtime - taskc->bypassed_at) *
+ FCG_HWEIGHT_ONE / (cgc->hweight ?: 1));
taskc->bypassed_at = 0;
}
bpf_cgroup_release(cgrp);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0116/1518] x86/cfi: Use symmetric SYM_START and SYM_END in __CFI_TYPE()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (114 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0115/1518] sched_ext/scx_flatcg: Fix cvtime_delta race and add hweight scaling to bypass charging Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0117/1518] platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count Greg Kroah-Hartman
` (882 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Jens Remus,
Borislav Petkov (AMD), Nathan Chancellor, Peter Zijlstra (Intel),
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jens Remus <jremus@linux.ibm.com>
[ Upstream commit 0cfdf974f133e0ff17ed80e7895adbe7889d9522 ]
Commit
ccace936eec7 ("x86: Add types to indirectly called assembly functions")
introduced a x86-specific implementation of __CFI_TYPE() using an asymmetric
combination of SYM_START() and SYM_FUNC_END() to add a symbol to the KCFI type
identifier that precedes a function.
This asymmetric combination is an issue if SYM_FUNC_END() ever gets extended
in a way that requires it to be used symmetrically with SYM_FUNC_START*().
For instance to emit DWARF CFI directives that denote the start/end of
a function. [1]
Use SYM_END() with SYM_T_FUNC instead. No functional change, as the generic
implementation of SYM_FUNC_END(name) expands into SYM_END(name, SYM_T_FUNC).
Fixes: ccace936eec7 ("x86: Add types to indirectly called assembly functions")
Closes: https://sashiko.dev/#/patchset/20260522110427.2816637-1-jremus@linux.ibm.com?part=3 [1]
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Jens Remus <jremus@linux.ibm.com>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Reviewed-by: Nathan Chancellor <nathan@kernel.org>
Acked-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Link: https://patch.msgid.link/20260611155716.830563-1-jremus@linux.ibm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/include/asm/linkage.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/x86/include/asm/linkage.h b/arch/x86/include/asm/linkage.h
index a7294656ad908..c9769a7b6e66c 100644
--- a/arch/x86/include/asm/linkage.h
+++ b/arch/x86/include/asm/linkage.h
@@ -103,7 +103,7 @@
.byte 0xb8 ASM_NL \
.long __kcfi_typeid_##name ASM_NL \
CFI_POST_PADDING \
- SYM_FUNC_END(__cfi_##name)
+ SYM_END(__cfi_##name, SYM_T_FUNC)
/* UML needs to be able to override memcpy() and friends for KASAN. */
#ifdef CONFIG_UML
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0117/1518] platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (115 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0116/1518] x86/cfi: Use symmetric SYM_START and SYM_END in __CFI_TYPE() Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0118/1518] selftests: proc: include fcntl.h in proc-pidns Greg Kroah-Hartman
` (881 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Andrei Kuchynski, Kaixuan Li,
Maoyi Xie, Benson Leung, Tzung-Bi Shih, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maoyi Xie <maoyixie.tju@gmail.com>
[ Upstream commit a0a8cd9fc9c48b95095bcec4b146f7a99486f58e ]
cros_typec_register_partner_pdos() copies the partner PDOs from the EC
TYPEC_STATUS response into the fixed caps_desc.pdo[PDO_MAX_OBJECTS] array.
memcpy(caps_desc.pdo, resp->source_cap_pdos,
sizeof(u32) * resp->source_cap_count);
...
memcpy(caps_desc.pdo, resp->sink_cap_pdos,
sizeof(u32) * resp->sink_cap_count);
PDO_MAX_OBJECTS is 7. source_cap_count and sink_cap_count are u8 fields
from the EC. The only check is that they are not both zero. If either is
larger than 7, the memcpy writes past the end of the array on the stack.
A count of 255 overflows it by about 1 KB. The EC source arrays are only
seven entries wide. A larger count reads past them too.
The ChromeOS EC firmware caps these counts today, so a compliant setup
does not hit this. The kernel should still validate these values rather
than trust them.
Validate the counts in cros_typec_register_partner_pdos() next to the
memcpy. Skip the PDO registration if either count is above PDO_MAX_OBJECTS.
The rest of cros_typec_handle_status() still runs so events are handled
and cleared.
Fixes: 348a2e8c93d3 ("platform/chrome: cros_ec_typec: Register partner PDOs")
Suggested-by: Andrei Kuchynski <akuchynski@chromium.org>
Co-developed-by: Kaixuan Li <kaixuan.li@ntu.edu.sg>
Signed-off-by: Kaixuan Li <kaixuan.li@ntu.edu.sg>
Signed-off-by: Maoyi Xie <maoyixie.tju@gmail.com>
Reviewed-by: Benson Leung <bleung@chromium.org>
Reviewed-by: Andrei Kuchynski <akuchynski@chromium.org>
Link: https://lore.kernel.org/r/20260625130056.3378097-1-maoyixie.tju@gmail.com
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/platform/chrome/cros_ec_typec.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/platform/chrome/cros_ec_typec.c b/drivers/platform/chrome/cros_ec_typec.c
index b712bcff6fb26..03ca776a837fb 100644
--- a/drivers/platform/chrome/cros_ec_typec.c
+++ b/drivers/platform/chrome/cros_ec_typec.c
@@ -1118,6 +1118,12 @@ static void cros_typec_register_partner_pdos(struct cros_typec_data *typec,
if (!resp->source_cap_count && !resp->sink_cap_count)
return;
+ if (resp->source_cap_count > PDO_MAX_OBJECTS ||
+ resp->sink_cap_count > PDO_MAX_OBJECTS) {
+ dev_warn(typec->dev, "Invalid PDO count from EC, port: %d\n", port_num);
+ return;
+ }
+
port->partner_pd = typec_partner_usb_power_delivery_register(port->partner, &desc);
if (IS_ERR(port->partner_pd)) {
dev_warn(typec->dev, "Failed to register partner PD device, port: %d\n", port_num);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0118/1518] selftests: proc: include fcntl.h in proc-pidns
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (116 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0117/1518] platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0119/1518] HID: core: quiesce input in hid_hw_stop() to prevent use-after-free Greg Kroah-Hartman
` (880 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Amin Vakil,
Christian Brauner (Amutable), Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Amin Vakil <info@aminvakil.com>
[ Upstream commit 879b3353d04d043a9e01525c520d9b81339421b2 ]
proc-pidns.c uses open() and O_* flags, but does not include
<fcntl.h>. This breaks the proc selftests build with errors such as:
error: implicit declaration of function 'open'
error: 'O_WRONLY' undeclared
error: 'O_CREAT' undeclared
error: 'O_RDONLY' undeclared
Include <fcntl.h> to provide the declaration and flag definitions.
Fixes: 5554d820f71c ("selftests/proc: add tests for new pidns APIs")
Tested with:
make -C tools/testing/selftests TARGETS=proc
Signed-off-by: Amin Vakil <info@aminvakil.com>
Link: https://patch.msgid.link/20260618151444.124739-1-info@aminvakil.com
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/proc/proc-pidns.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/tools/testing/selftests/proc/proc-pidns.c b/tools/testing/selftests/proc/proc-pidns.c
index 52500597f9514..f0fff6991d461 100644
--- a/tools/testing/selftests/proc/proc-pidns.c
+++ b/tools/testing/selftests/proc/proc-pidns.c
@@ -6,6 +6,7 @@
#include <assert.h>
#include <errno.h>
+#include <fcntl.h>
#include <sched.h>
#include <stdbool.h>
#include <stdlib.h>
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0119/1518] HID: core: quiesce input in hid_hw_stop() to prevent use-after-free
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (117 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0118/1518] selftests: proc: include fcntl.h in proc-pidns Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0120/1518] HID: nintendo: Fix imu_timestamp_us double increment per report Greg Kroah-Hartman
` (879 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+9eebf5f6544c5e873858,
Philipp Weber, Jiri Kosina, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Philipp Weber <kernel@phwe.de>
[ Upstream commit a4bc41504690b7d7064931909874f5b98cd148b6 ]
A driver's probe calls hid_device_io_start() to enable input delivery,
then fails at a later initialization step and unwinds via hid_hw_stop().
The unwind frees struct hidraw via hidraw_disconnect() while in-flight
HID reports may still be running on another CPU, dereferencing the
freed object through hidraw_report_event(). syzbot reports the
resulting use-after-free for the corsair-psu HID driver.
Edward Adam Davis posted a per-driver fix for corsair-psu that adds
an explicit hid_device_io_stop() before hid_hw_stop() in the probe
error path ("hwmon: prevent packets from going to driver for probe",
2026-04-28). Auditing the tree shows 15 drivers call
hid_device_io_start(); 7 also call hid_device_io_stop() and 8 do not:
drivers calling hid_device_io_start() without a matching
hid_device_io_stop() before hid_hw_stop():
drivers/hwmon/corsair-psu.c (fix posted by Edward)
drivers/hwmon/corsair-cpro.c
drivers/hwmon/nzxt-kraken3.c
drivers/hwmon/nzxt-smart2.c
drivers/hwmon/gigabyte_waterforce.c
drivers/hid/hid-logitech-dj.c
drivers/hid/hid-nintendo.c
drivers/hid/hid-mcp2221.c
Roughly half of all callers of the API are exposed. Centralize the
quiesce in hid_hw_stop() so callers do not have to remember the
matching stop: if a driver has left hdev->io_started true on entry,
call hid_device_io_stop() before hid_disconnect().
For the 7 drivers that already call hid_device_io_stop() correctly,
hdev->io_started is false on entry, the guard short-circuits, and
behavior is unchanged.
No Fixes: tag because the affected drivers gained their
hid_device_io_start() calls independently over years; the bug is a
class-wide API misuse rather than a regression from one commit.
Reported-by: syzbot+9eebf5f6544c5e873858@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=9eebf5f6544c5e873858
Signed-off-by: Philipp Weber <kernel@phwe.de>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hid/hid-core.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/drivers/hid/hid-core.c b/drivers/hid/hid-core.c
index 7f442a2798d8f..55990d17c5669 100644
--- a/drivers/hid/hid-core.c
+++ b/drivers/hid/hid-core.c
@@ -2450,9 +2450,16 @@ EXPORT_SYMBOL_GPL(hid_hw_start);
*
* This is usually called from remove function or from probe when something
* failed and hid_hw_start was called already.
+ *
+ * If the caller enabled HID input via hid_device_io_start() and is unwinding
+ * without an explicit hid_device_io_stop(), quiesce input first so that
+ * in-flight reports cannot reach handlers (e.g. hidraw_report_event) whose
+ * backing objects hid_disconnect() is about to free.
*/
void hid_hw_stop(struct hid_device *hdev)
{
+ if (hdev->io_started)
+ hid_device_io_stop(hdev);
hid_disconnect(hdev);
hdev->ll_driver->stop(hdev);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0120/1518] HID: nintendo: Fix imu_timestamp_us double increment per report
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (118 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0119/1518] HID: core: quiesce input in hid_hw_stop() to prevent use-after-free Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0121/1518] HID: roccat: bound device-supplied profile index Greg Kroah-Hartman
` (878 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christos Maragkos, Jiri Kosina,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christos Maragkos <whitetowersoftware@gmail.com>
[ Upstream commit 1f9b25d3fb65b9384dec16d9db13a3e71abd9145 ]
Previously, the imu_timestamp_us variable was incremented twice per
report, causing it to advance by two times the desired amount.
This resulted in incorrect jumps in IMU timestamps reported using
MSC_TIMESTAMP, so userspace applications saw corrupted timing on
functions such as gyroscope-based aim and motion controls.
This is fixed by removing the redundant increment at the start of the
report handling so the remaining can account for the full report
interval.
Fixes: 4ff5b10840a88 ("HID: nintendo: add IMU support")
Signed-off-by: Christos Maragkos <whitetowersoftware@gmail.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hid/hid-nintendo.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/drivers/hid/hid-nintendo.c b/drivers/hid/hid-nintendo.c
index d5f049424f080..34642352b439d 100644
--- a/drivers/hid/hid-nintendo.c
+++ b/drivers/hid/hid-nintendo.c
@@ -1453,7 +1453,6 @@ static void joycon_parse_imu_report(struct joycon_ctlr *ctlr,
dropped_threshold = ctlr->imu_avg_delta_ms * 3 / 2;
dropped_pkts = (delta - min(delta, dropped_threshold)) /
ctlr->imu_avg_delta_ms;
- ctlr->imu_timestamp_us += 1000 * ctlr->imu_avg_delta_ms;
if (dropped_pkts > JC_IMU_DROPPED_PKT_WARNING) {
hid_warn_ratelimited(ctlr->hdev,
"compensating for %u dropped IMU reports\n",
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0121/1518] HID: roccat: bound device-supplied profile index
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (119 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0120/1518] HID: nintendo: Fix imu_timestamp_us double increment per report Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0122/1518] soc: samsung: exynos-pmu: fix of_node refcount leak in exynos_get_pmu_regmap() Greg Kroah-Hartman
` (877 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Bommarito, Jiri Kosina,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michael Bommarito <michael.bommarito@gmail.com>
[ Upstream commit 43fae42628a8c10fa8981773d7ec9f1a367821a7 ]
kone_keep_values_up_to_date() and kone_profile_activated() use an
8-bit, device-supplied profile value as an index into the 5-element
kone->profiles[] array without a range check. A malicious USB device
claiming the Roccat Kone id can send a switch-profile event (or a
startup_profile read at probe) with an out-of-range value and make the
driver read out of bounds; the result is exposed via the actual_dpi
sysfs attribute.
Reject out-of-range indices in both paths.
This was found with static analysis and confirmed with the KUnit test
added in the following patch (KASAN: slab-out-of-bounds).
Fixes: 14bf62cde7942 ("HID: add driver for Roccat Kone gaming mouse")
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hid/hid-roccat-kone.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
diff --git a/drivers/hid/hid-roccat-kone.c b/drivers/hid/hid-roccat-kone.c
index fabc08efcfd8c..2510001fead94 100644
--- a/drivers/hid/hid-roccat-kone.c
+++ b/drivers/hid/hid-roccat-kone.c
@@ -36,6 +36,8 @@ static uint profile_numbers[5] = {0, 1, 2, 3, 4};
static void kone_profile_activated(struct kone_device *kone, uint new_profile)
{
+ if (new_profile < 1 || new_profile > ARRAY_SIZE(kone->profiles))
+ new_profile = 1;
kone->actual_profile = new_profile;
kone->actual_dpi = kone->profiles[new_profile - 1].startup_dpi;
}
@@ -793,8 +795,10 @@ static void kone_keep_values_up_to_date(struct kone_device *kone,
{
switch (event->event) {
case kone_mouse_event_switch_profile:
- kone->actual_dpi = kone->profiles[event->value - 1].
- startup_dpi;
+ if (event->value >= 1 &&
+ event->value <= ARRAY_SIZE(kone->profiles))
+ kone->actual_dpi =
+ kone->profiles[event->value - 1].startup_dpi;
fallthrough;
case kone_mouse_event_osd_profile:
kone->actual_profile = event->value;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0122/1518] soc: samsung: exynos-pmu: fix of_node refcount leak in exynos_get_pmu_regmap()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (120 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0121/1518] HID: roccat: bound device-supplied profile index Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0123/1518] media: cec-pin: Fix event FIFO ordering Greg Kroah-Hartman
` (876 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Weigang He, Krzysztof Kozlowski,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Weigang He <geoffreyhe2@gmail.com>
[ Upstream commit fa476d53edd24e8105faace04e881b9c4179738f ]
exynos_get_pmu_regmap() obtains a device_node via of_find_matching_node()
and passes it to exynos_get_pmu_regmap_by_phandle(np, NULL). With
propname == NULL the callee uses np directly and does not drop a
reference, so the reference taken by of_find_matching_node() is leaked on
every call -- including on each -EPROBE_DEFER retry of the only in-tree
caller, exynos_retention_init() in the Exynos pinctrl driver.
Annotate np with the __free(device_node) cleanup attribute so the
reference is released when the function returns.
Found by static analysis tool CodeQL.
Fixes: 76640b84bd7a ("soc: samsung: pmu: Provide global function to get PMU regmap")
Signed-off-by: Weigang He <geoffreyhe2@gmail.com>
Link: https://patch.msgid.link/20260609143852.1783558-1-geoffreyhe2@gmail.com
Signed-off-by: Krzysztof Kozlowski <krzk@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/soc/samsung/exynos-pmu.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/soc/samsung/exynos-pmu.c b/drivers/soc/samsung/exynos-pmu.c
index f8fe1a5965ab4..d910499731131 100644
--- a/drivers/soc/samsung/exynos-pmu.c
+++ b/drivers/soc/samsung/exynos-pmu.c
@@ -300,8 +300,8 @@ static const struct mfd_cell exynos_pmu_devs[] = {
*/
struct regmap *exynos_get_pmu_regmap(void)
{
- struct device_node *np = of_find_matching_node(NULL,
- exynos_pmu_of_device_ids);
+ struct device_node *np __free(device_node) =
+ of_find_matching_node(NULL, exynos_pmu_of_device_ids);
if (np)
return exynos_get_pmu_regmap_by_phandle(np, NULL);
return ERR_PTR(-ENODEV);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0123/1518] media: cec-pin: Fix event FIFO ordering
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (121 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0122/1518] soc: samsung: exynos-pmu: fix of_node refcount leak in exynos_get_pmu_regmap() Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0124/1518] cxl/mbox: Clamp mailbox output allocation to the payload size Greg Kroah-Hartman
` (875 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Gui-Dong Han, Hans Verkuil,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gui-Dong Han <hanguidong02@gmail.com>
[ Upstream commit a1d83d1b810665bd53ce8a7b7867e054d68676c7 ]
cec_pin_update() fills work_pin_events[] and work_pin_ts[], then
increments work_pin_num_events. cec_pin_thread_func() uses that counter
to decide when to read the FIFO entries.
Do not let the counter update be observed without the event update. Also
do not let a freed slot be reused before the thread has finished reading
it. Use release operations when publishing an entry and releasing a slot,
and acquire operations when consuming those counter updates.
Leave the other work_pin_num_events users as they do not participate in
this FIFO publication path.
Fixes: ea5c8ef29668 ("media: cec-pin: add low-level pin hardware support")
Signed-off-by: Gui-Dong Han <hanguidong02@gmail.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/media/cec/core/cec-pin.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/drivers/media/cec/core/cec-pin.c b/drivers/media/cec/core/cec-pin.c
index 4d7155281daae..754a4bfcc87c7 100644
--- a/drivers/media/cec/core/cec-pin.c
+++ b/drivers/media/cec/core/cec-pin.c
@@ -115,7 +115,7 @@ static void cec_pin_update(struct cec_pin *pin, bool v, bool force)
return;
pin->adap->cec_pin_is_high = v;
- if (atomic_read(&pin->work_pin_num_events) < CEC_NUM_PIN_EVENTS) {
+ if (atomic_read_acquire(&pin->work_pin_num_events) < CEC_NUM_PIN_EVENTS) {
u8 ev = v;
if (pin->work_pin_events_dropped) {
@@ -126,7 +126,7 @@ static void cec_pin_update(struct cec_pin *pin, bool v, bool force)
pin->work_pin_ts[pin->work_pin_events_wr] = ktime_get();
pin->work_pin_events_wr =
(pin->work_pin_events_wr + 1) % CEC_NUM_PIN_EVENTS;
- atomic_inc(&pin->work_pin_num_events);
+ atomic_inc_return_release(&pin->work_pin_num_events);
} else {
pin->work_pin_events_dropped = true;
pin->work_pin_events_dropped_cnt++;
@@ -1101,7 +1101,7 @@ static int cec_pin_thread_func(void *_adap)
pin->work_tx_ts);
}
- while (atomic_read(&pin->work_pin_num_events)) {
+ while (atomic_read_acquire(&pin->work_pin_num_events)) {
unsigned int idx = pin->work_pin_events_rd;
u8 v = pin->work_pin_events[idx];
@@ -1110,7 +1110,7 @@ static int cec_pin_thread_func(void *_adap)
v & CEC_PIN_EVENT_FL_DROPPED,
pin->work_pin_ts[idx]);
pin->work_pin_events_rd = (idx + 1) % CEC_NUM_PIN_EVENTS;
- atomic_dec(&pin->work_pin_num_events);
+ atomic_dec_return_release(&pin->work_pin_num_events);
}
switch (atomic_xchg(&pin->work_irq_change,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0124/1518] cxl/mbox: Clamp mailbox output allocation to the payload size
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (122 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0123/1518] media: cec-pin: Fix event FIFO ordering Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0125/1518] cxl/pci: Remove incorrect mbox.valid check in cxl_pci_type3_init_mailbox() Greg Kroah-Hartman
` (874 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kai-Heng Feng, Koba Ko, Dave Jiang,
Davidlohr Bueso, Richard Cheng, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Richard Cheng <icheng@nvidia.com>
[ Upstream commit 8a13db9f899d149c3aab24abcb668121cfda5a4f ]
CXL_MEM_SEND_COMMAND bounds the user's in.size to the mailbox payload
size but leaves out.size unbounded, then cxl_mbox_cmd_ctor() calls
kvzalloc(out.size). A large out.size drives a huge allocation, above
INT_MAX it WARNs and taints, and with panic_on_warn=1 it panics.
The transport __cxl_pci_mbox_send_cmd() already clamps the response copy
to min(out.size, payload_size, device len), so the output buffer is
never written beyond payload_size. Clamp the allocation to payload_size
too, matching the RAW path.
Fixes: 583fa5e71cae ("cxl/mem: Add basic IOCTL interface")
Reviewed-by: Kai-Heng Feng <kaihengf@nvidia.com>
Reviewed-by: Koba Ko <kobak@nvidia.com>
Reviewed-by: Dave Jiang <dave.jiang@intel.com>
Reviewed-by: Davidlohr Bueso <dave@stgolabs.net>
Signed-off-by: Richard Cheng <icheng@nvidia.com>
Link: https://patch.msgid.link/20260624144147.53997-1-icheng@nvidia.com
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/cxl/core/mbox.c | 6 +-----
1 file changed, 1 insertion(+), 5 deletions(-)
diff --git a/drivers/cxl/core/mbox.c b/drivers/cxl/core/mbox.c
index daee364619f92..fa775f50fe75e 100644
--- a/drivers/cxl/core/mbox.c
+++ b/drivers/cxl/core/mbox.c
@@ -379,11 +379,7 @@ static int cxl_mbox_cmd_ctor(struct cxl_mbox_cmd *mbox_cmd,
}
}
- /* Prepare to handle a full payload for variable sized output */
- if (out_size == CXL_VARIABLE_PAYLOAD)
- mbox_cmd->size_out = cxl_mbox->payload_size;
- else
- mbox_cmd->size_out = out_size;
+ mbox_cmd->size_out = min_t(size_t, out_size, cxl_mbox->payload_size);
if (mbox_cmd->size_out) {
mbox_cmd->payload_out = kvzalloc(mbox_cmd->size_out, GFP_KERNEL);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0125/1518] cxl/pci: Remove incorrect mbox.valid check in cxl_pci_type3_init_mailbox()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (123 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0124/1518] cxl/mbox: Clamp mailbox output allocation to the payload size Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0126/1518] clk: versaclock7: Fix APLL clock leak on probe failure Greg Kroah-Hartman
` (873 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Richard Cheng, Wei Hou, Li Ming,
Dave Jiang, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wei Hou <wei.hou@scaleflux.com>
[ Upstream commit d79b81893d0cc93737e811a465b9ef9a00156fd5 ]
The driver's design intent is that missing or malformed component
registers should not prevent mailbox initialization. cxl_pci_probe()
already reflects this: the CXL_REGLOC_RBI_COMPONENT setup path only
emits a dev_warn() and continues when component registers are absent,
rather than returning an error.
The check 'if (!cxlds->reg_map.device_map.mbox.valid)' violates this
intent and is also technically incorrect for two reasons:
1. Wrong struct: the MEMDEV register block is enumerated into a local
variable 'map', not into 'cxlds->reg_map'. The device_map.mbox.valid
field inside cxlds->reg_map is never written by the MEMDEV probe and
will always read as zero regardless of actual hardware capability.
2. Already validated: cxl_pci_setup_regs(CXL_REGLOC_RBI_MEMDEV) calls
cxl_probe_regs() which explicitly checks mbox.valid and returns
-ENXIO if the mailbox is absent. If that check passes, the mailbox is
guaranteed to be present by the time cxl_pci_type3_init_mailbox() is
called.
The value that the check actually reads is component_map.ras.valid,
which aliases device_map.mbox.valid in the union. This is populated by
the COMPONENT probe, not the MEMDEV probe. On devices where the
component register BAR does not implement a CXL Component Capability
Array (e.g. certain DCD devices), cxl_probe_component_regs() returns
early leaving ras.valid=false. Through the union, this makes mbox.valid
read as false, causing cxl_pci_type3_init_mailbox() to return -ENODEV
(-19) even though the mailbox hardware is fully functional.
Remove the check. Mailbox presence has already been validated by
cxl_pci_setup_regs(CXL_REGLOC_RBI_MEMDEV). The presence or absence of
component registers is irrelevant to mailbox initialization.
Fixes: 8d8081cecfb9 ("cxl: Move mailbox related bits to the same context")
Reviewed-by: Richard Cheng <icheng@nvidia.com>
Signed-off-by: Wei Hou <wei.hou@scaleflux.com>
Reviewed-by: Li Ming <ming.li@zohomail.com>
Link: https://patch.msgid.link/20260628155857.239866-1-wei.hou@scaleflux.com
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/cxl/pci.c | 6 ------
1 file changed, 6 deletions(-)
diff --git a/drivers/cxl/pci.c b/drivers/cxl/pci.c
index 2c42ab75e56a8..24fb1b230ca02 100644
--- a/drivers/cxl/pci.c
+++ b/drivers/cxl/pci.c
@@ -807,12 +807,6 @@ static int cxl_pci_type3_init_mailbox(struct cxl_dev_state *cxlds)
{
int rc;
- /*
- * Fail the init if there's no mailbox. For a type3 this is out of spec.
- */
- if (!cxlds->reg_map.device_map.mbox.valid)
- return -ENODEV;
-
rc = cxl_mailbox_init(&cxlds->cxl_mbox, cxlds->dev);
if (rc)
return rc;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0126/1518] clk: versaclock7: Fix APLL clock leak on probe failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (124 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0125/1518] cxl/pci: Remove incorrect mbox.valid check in cxl_pci_type3_init_mailbox() Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0127/1518] clk: moxart: remove unused variables, fix refcount leak Greg Kroah-Hartman
` (872 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ijae Kim, Myeonghun Pak,
Brian Masney, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Myeonghun Pak <mhun512@gmail.com>
[ Upstream commit e25d8d35e8cbc1a4c04a8b86eed6aa7229f6449e ]
vc7_probe() registers the APLL with clk_register_fixed_rate(), which is
not devm-managed and must be explicitly unregistered on probe failure.
Most later errors already unwind through err_clk, but a failure from
vc7_get_bank_clk() in the output registration loop returned directly.
That skipped clk_unregister_fixed_rate() and leaked the APLL clock.
Route that error through the existing err_clk label so the fixed-rate
clock is released consistently with the other probe failure paths.
This issue was identified during our ongoing static-analysis research while
reviewing kernel code.
Fixes: 48c5e98fedd9 ("clk: Renesas versaclock7 ccf device driver")
Co-developed-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
Reviewed-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/clk-versaclock7.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/clk/clk-versaclock7.c b/drivers/clk/clk-versaclock7.c
index adcc603e32593..e3a36dcd98b80 100644
--- a/drivers/clk/clk-versaclock7.c
+++ b/drivers/clk/clk-versaclock7.c
@@ -1197,7 +1197,7 @@ static int vc7_probe(struct i2c_client *client)
if (ret) {
dev_err_probe(&client->dev, ret,
"unable to register output %d\n", i);
- return ret;
+ goto err_clk;
}
switch (bank_src_map.type) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0127/1518] clk: moxart: remove unused variables, fix refcount leak
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (125 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0126/1518] clk: versaclock7: Fix APLL clock leak on probe failure Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0128/1518] clk: nuvoton: ma35d1: fix ignored div_u64 return values in PLL freq calculation Greg Kroah-Hartman
` (871 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alexander A. Klimov, Brian Masney,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexander A. Klimov <grandmaster@al2klimov.de>
[ Upstream commit 9f275f2ee9ca60ea4c092bdc0195987945ad8ad8 ]
Not only these error checks are redundand,
those of_clk_get() return values weren't cleaned up via clk_put().
Fixes: c7bb4fc16ead ("clk: add MOXA ART SoCs clock driver")
Signed-off-by: Alexander A. Klimov <grandmaster@al2klimov.de>
Reviewed-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/clk-moxart.c | 14 --------------
1 file changed, 14 deletions(-)
diff --git a/drivers/clk/clk-moxart.c b/drivers/clk/clk-moxart.c
index 3786a0153ad17..40663ef3ef0ae 100644
--- a/drivers/clk/clk-moxart.c
+++ b/drivers/clk/clk-moxart.c
@@ -17,7 +17,6 @@ static void __init moxart_of_pll_clk_init(struct device_node *node)
{
void __iomem *base;
struct clk_hw *hw;
- struct clk *ref_clk;
unsigned int mul;
const char *name = node->name;
const char *parent_name;
@@ -34,12 +33,6 @@ static void __init moxart_of_pll_clk_init(struct device_node *node)
mul = readl(base + 0x30) >> 3 & 0x3f;
iounmap(base);
- ref_clk = of_clk_get(node, 0);
- if (IS_ERR(ref_clk)) {
- pr_err("%pOF: of_clk_get failed\n", node);
- return;
- }
-
hw = clk_hw_register_fixed_factor(NULL, name, parent_name, 0, mul, 1);
if (IS_ERR(hw)) {
pr_err("%pOF: failed to register clock\n", node);
@@ -56,7 +49,6 @@ static void __init moxart_of_apb_clk_init(struct device_node *node)
{
void __iomem *base;
struct clk_hw *hw;
- struct clk *pll_clk;
unsigned int div, val;
unsigned int div_idx[] = { 2, 3, 4, 6, 8};
const char *name = node->name;
@@ -78,12 +70,6 @@ static void __init moxart_of_apb_clk_init(struct device_node *node)
val = 0;
div = div_idx[val] * 2;
- pll_clk = of_clk_get(node, 0);
- if (IS_ERR(pll_clk)) {
- pr_err("%pOF: of_clk_get failed\n", node);
- return;
- }
-
hw = clk_hw_register_fixed_factor(NULL, name, parent_name, 0, 1, div);
if (IS_ERR(hw)) {
pr_err("%pOF: failed to register clock\n", node);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0128/1518] clk: nuvoton: ma35d1: fix ignored div_u64 return values in PLL freq calculation
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (126 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0127/1518] clk: moxart: remove unused variables, fix refcount leak Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0129/1518] clk: nuvoton: ma35d1: fix PLL_CTL1_FRAC bit field width and fractional calc Greg Kroah-Hartman
` (870 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Brian Masney, Joey Lu, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Joey Lu <a0987203069@gmail.com>
[ Upstream commit b3a2223a7805c7e6759a32a5d6ca574ad07e2710 ]
div_u64() does not modify its argument in place; the return value must
be assigned. Both ma35d1_calc_smic_pll_freq() and ma35d1_calc_pll_freq()
called div_u64() and discarded the result, leaving pll_freq holding the
undivided product and thus returning a frequency orders of magnitude too
high.
Fixes: 691521a367cf ("clk: nuvoton: Add clock driver for ma35d1 clock controller")
Reviewed-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Joey Lu <a0987203069@gmail.com>
Signed-off-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/nuvoton/clk-ma35d1-pll.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/clk/nuvoton/clk-ma35d1-pll.c b/drivers/clk/nuvoton/clk-ma35d1-pll.c
index 4620acfe47e85..bfedd45bd04b7 100644
--- a/drivers/clk/nuvoton/clk-ma35d1-pll.c
+++ b/drivers/clk/nuvoton/clk-ma35d1-pll.c
@@ -92,7 +92,7 @@ static unsigned long ma35d1_calc_smic_pll_freq(u32 pll0_ctl0,
p = FIELD_GET(SPLL0_CTL0_OUTDIV, pll0_ctl0);
outdiv = 1 << p;
pll_freq = (u64)parent_rate * n;
- div_u64(pll_freq, m * outdiv);
+ pll_freq = div_u64(pll_freq, m * outdiv);
return pll_freq;
}
@@ -110,7 +110,7 @@ static unsigned long ma35d1_calc_pll_freq(u8 mode, u32 *reg_ctl, unsigned long p
if (mode == PLL_MODE_INT) {
pll_freq = (u64)parent_rate * n;
- div_u64(pll_freq, m * p);
+ pll_freq = div_u64(pll_freq, m * p);
} else {
x = FIELD_GET(PLL_CTL1_FRAC, reg_ctl[1]);
/* 2 decimal places floating to integer (ex. 1.23 to 123) */
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0129/1518] clk: nuvoton: ma35d1: fix PLL_CTL1_FRAC bit field width and fractional calc
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (127 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0128/1518] clk: nuvoton: ma35d1: fix ignored div_u64 return values in PLL freq calculation Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0130/1518] clk: nuvoton: ma35d1: fix ma35d1_clk_pll_determine_rate logic Greg Kroah-Hartman
` (869 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Joey Lu, Brian Masney, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Joey Lu <a0987203069@gmail.com>
[ Upstream commit 26de5aed72d80bd8aec2583134aca3597c64fda9 ]
PLL_CTL1_FRAC was defined as GENMASK(31, 24), covering only 8 bits.
The hardware fractional field occupies bits [31:8] (24 bits), so the
mask must be GENMASK(31, 8).
The previous fractional-mode calculation used FIELD_MAX(PLL_CTL1_FRAC)
as the denominator to obtain 2 decimal places. With the corrected 24-bit
mask the old divisor is wrong; replace the arithmetic with a proper
24-bit fixed-point rounding to 3 decimal places using the kernel's
DIV_ROUND_CLOSEST_ULL helper:
n_frac = n * 1000 + DIV_ROUND_CLOSEST_ULL(x * 1000, 1 << 24)
Fixes: 691521a367cf ("clk: nuvoton: Add clock driver for ma35d1 clock controller")
Signed-off-by: Joey Lu <a0987203069@gmail.com>
Reviewed-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/nuvoton/clk-ma35d1-pll.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/drivers/clk/nuvoton/clk-ma35d1-pll.c b/drivers/clk/nuvoton/clk-ma35d1-pll.c
index bfedd45bd04b7..eb9d69d2077b1 100644
--- a/drivers/clk/nuvoton/clk-ma35d1-pll.c
+++ b/drivers/clk/nuvoton/clk-ma35d1-pll.c
@@ -48,7 +48,7 @@
#define PLL_CTL1_PD BIT(0)
#define PLL_CTL1_BP BIT(1)
#define PLL_CTL1_OUTDIV GENMASK(6, 4)
-#define PLL_CTL1_FRAC GENMASK(31, 24)
+#define PLL_CTL1_FRAC GENMASK(31, 8)
#define PLL_CTL2_SLOPE GENMASK(23, 0)
#define INDIV_MIN 1
@@ -113,9 +113,9 @@ static unsigned long ma35d1_calc_pll_freq(u8 mode, u32 *reg_ctl, unsigned long p
pll_freq = div_u64(pll_freq, m * p);
} else {
x = FIELD_GET(PLL_CTL1_FRAC, reg_ctl[1]);
- /* 2 decimal places floating to integer (ex. 1.23 to 123) */
- n = n * 100 + ((x * 100) / FIELD_MAX(PLL_CTL1_FRAC));
- pll_freq = div_u64(parent_rate * n, 100 * m * p);
+ /* convert 24-bit fraction to 3 decimal digits, rounding to closest */
+ n = n * 1000 + DIV_ROUND_CLOSEST_ULL((u64)x * 1000, 1ULL << 24);
+ pll_freq = div_u64((u64)parent_rate * n, 1000 * m * p);
}
return pll_freq;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0130/1518] clk: nuvoton: ma35d1: fix ma35d1_clk_pll_determine_rate logic
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (128 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0129/1518] clk: nuvoton: ma35d1: fix PLL_CTL1_FRAC bit field width and fractional calc Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0131/1518] clk: stm32: add missing bitfield.h header Greg Kroah-Hartman
` (868 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Joey Lu, Brian Masney, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Joey Lu <a0987203069@gmail.com>
[ Upstream commit e1311954cb600d5f95cd9e2fe9a7376edc2ac3c5 ]
ma35d1_clk_pll_determine_rate() called ma35d1_pll_find_closest()
unconditionally before the switch statement, and then every case
branch overwrote pll_freq by reading the current hardware registers.
For CAPLL and DDRPLL this means find_closest() ran unnecessarily
(and incorrectly, since those PLLs are read-only) and its result
was silently discarded.
Fix by moving the find_closest() call inside the APLL/EPLL/VPLL
branch where it belongs. Group CAPLL and DDRPLL together as
read-only PLLs that simply report their current rate; handle them
with an explicit if/else to keep the CAPLL (SMIC design) and DDRPLL
(standard design) paths distinct.
Fixes: 691521a367cf ("clk: nuvoton: Add clock driver for ma35d1 clock controller")
Signed-off-by: Joey Lu <a0987203069@gmail.com>
Signed-off-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/nuvoton/clk-ma35d1-pll.c | 26 +++++++++++++-------------
1 file changed, 13 insertions(+), 13 deletions(-)
diff --git a/drivers/clk/nuvoton/clk-ma35d1-pll.c b/drivers/clk/nuvoton/clk-ma35d1-pll.c
index eb9d69d2077b1..c7c0dc91a012c 100644
--- a/drivers/clk/nuvoton/clk-ma35d1-pll.c
+++ b/drivers/clk/nuvoton/clk-ma35d1-pll.c
@@ -255,32 +255,32 @@ static int ma35d1_clk_pll_determine_rate(struct clk_hw *hw,
if (req->best_parent_rate < PLL_FREF_MIN_FREQ || req->best_parent_rate > PLL_FREF_MAX_FREQ)
return -EINVAL;
- ret = ma35d1_pll_find_closest(pll, req->rate, req->best_parent_rate,
- reg_ctl, &pll_freq);
- if (ret < 0)
- return ret;
-
switch (pll->id) {
case CAPLL:
+ case DDRPLL:
+ /* Read-only PLLs: return current rate */
reg_ctl[0] = readl_relaxed(pll->ctl0_base);
- pll_freq = ma35d1_calc_smic_pll_freq(reg_ctl[0], req->best_parent_rate);
+ if (pll->id == CAPLL) {
+ pll_freq = ma35d1_calc_smic_pll_freq(reg_ctl[0], req->best_parent_rate);
+ } else {
+ reg_ctl[1] = readl_relaxed(pll->ctl1_base);
+ pll_freq = ma35d1_calc_pll_freq(pll->mode, reg_ctl, req->best_parent_rate);
+ }
req->rate = pll_freq;
-
return 0;
- case DDRPLL:
case APLL:
case EPLL:
case VPLL:
- reg_ctl[0] = readl_relaxed(pll->ctl0_base);
- reg_ctl[1] = readl_relaxed(pll->ctl1_base);
- pll_freq = ma35d1_calc_pll_freq(pll->mode, reg_ctl, req->best_parent_rate);
+ /* Configurable PLLs: find closest achievable rate */
+ ret = ma35d1_pll_find_closest(pll, req->rate, req->best_parent_rate,
+ reg_ctl, &pll_freq);
+ if (ret < 0)
+ return ret;
req->rate = pll_freq;
-
return 0;
}
req->rate = 0;
-
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0131/1518] clk: stm32: add missing bitfield.h header
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (129 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0130/1518] clk: nuvoton: ma35d1: fix ma35d1_clk_pll_determine_rate logic Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0132/1518] ASoC: rt700-sdw: always drain jack work on remove Greg Kroah-Hartman
` (867 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Rosen Penev, Brian Masney,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rosen Penev <rosenp@gmail.com>
[ Upstream commit 0bf68e8dcb843f094ed73c2c54e9fe58a7a4f774 ]
It seems some ARM header includes this and the build passes there, but
nowhere else. Note that the driver has COMPILE_TEST in depends.
Fixes: 37ae8501cdb0 ("clk: stm32: introduce clocks for STM32MP21 platfor")
Signed-off-by: Rosen Penev <rosenp@gmail.com>
Reviewed-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/stm32/clk-stm32mp21.c | 1 +
drivers/clk/stm32/clk-stm32mp25.c | 1 +
2 files changed, 2 insertions(+)
diff --git a/drivers/clk/stm32/clk-stm32mp21.c b/drivers/clk/stm32/clk-stm32mp21.c
index c8a37b716bd55..bdb17419908c8 100644
--- a/drivers/clk/stm32/clk-stm32mp21.c
+++ b/drivers/clk/stm32/clk-stm32mp21.c
@@ -4,6 +4,7 @@
* Author: Gabriel Fernandez <gabriel.fernandez@foss.st.com> for STMicroelectronics.
*/
+#include <linux/bitfield.h>
#include <linux/bus/stm32_firewall_device.h>
#include <linux/clk-provider.h>
#include <linux/io.h>
diff --git a/drivers/clk/stm32/clk-stm32mp25.c b/drivers/clk/stm32/clk-stm32mp25.c
index 52f0e8a129262..eb0bc918ecee0 100644
--- a/drivers/clk/stm32/clk-stm32mp25.c
+++ b/drivers/clk/stm32/clk-stm32mp25.c
@@ -4,6 +4,7 @@
* Author: Gabriel Fernandez <gabriel.fernandez@foss.st.com> for STMicroelectronics.
*/
+#include <linux/bitfield.h>
#include <linux/bus/stm32_firewall_device.h>
#include <linux/clk-provider.h>
#include <linux/io.h>
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0132/1518] ASoC: rt700-sdw: always drain jack work on remove
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (130 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0131/1518] clk: stm32: add missing bitfield.h header Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0133/1518] ASoC: fsl_audmix: rework runtime PM handling in probe Greg Kroah-Hartman
` (866 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Runyu Xiao, Mark Brown, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Runyu Xiao <runyu.xiao@seu.edu.cn>
[ Upstream commit 612ccf42acd14bb2685fa60c3495ca13e63e8989 ]
rt700_sdw_remove() drains jack_detect_work and jack_btn_check_work only
when rt700->hw_init is true. That state bit is cleared by
rt700_update_status() when the SoundWire slave becomes UNATTACHED, but a
jack work item can already have been queued by rt700_interrupt_callback()
or rt700_jack_init() while the device was initialized.
Do not use hw_init as the remove-time guard for draining these work
objects. The delayed works are initialized during rt700_init(), so remove
can cancel them unconditionally and pair the object lifetime with the
codec-private data lifetime instead of a mutable hardware state bit.
This issue was found by our static analysis tool and then confirmed by
manual review of the SoundWire status, interrupt and remove paths. The
remove path should drain work based on whether the work object exists, not
on a runtime hardware state bit that can change after the work was queued.
A QEMU PoC queued jack_detect_work, simulated SDW_SLAVE_UNATTACHED, and
then entered remove. DEBUG_OBJECTS reported an active timer/work object
associated with the rt700 jack work path after remove skipped the cancel.
This is sent as an RFC because the practical trigger depends on SoundWire
core remove ordering after an UNATTACHED status update. If remove cannot
run after hw_init has been cleared while jack work is still pending, this
is a defensive lifecycle cleanup rather than a reachable race on current
systems.
Fixes: 737ee8bdf682 ("ASoC: rt700-sdw: use cancel_work_sync() in .remove as well as .suspend")
Signed-off-by: Runyu Xiao <runyu.xiao@seu.edu.cn>
Link: https://patch.msgid.link/20260619122325.2504287-1-runyu.xiao@seu.edu.cn
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/codecs/rt700-sdw.c | 6 ++----
1 file changed, 2 insertions(+), 4 deletions(-)
diff --git a/sound/soc/codecs/rt700-sdw.c b/sound/soc/codecs/rt700-sdw.c
index 44543c0da1772..f7bd793e3e672 100644
--- a/sound/soc/codecs/rt700-sdw.c
+++ b/sound/soc/codecs/rt700-sdw.c
@@ -459,10 +459,8 @@ static int rt700_sdw_remove(struct sdw_slave *slave)
{
struct rt700_priv *rt700 = dev_get_drvdata(&slave->dev);
- if (rt700->hw_init) {
- cancel_delayed_work_sync(&rt700->jack_detect_work);
- cancel_delayed_work_sync(&rt700->jack_btn_check_work);
- }
+ cancel_delayed_work_sync(&rt700->jack_detect_work);
+ cancel_delayed_work_sync(&rt700->jack_btn_check_work);
pm_runtime_disable(&slave->dev);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0133/1518] ASoC: fsl_audmix: rework runtime PM handling in probe
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (131 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0132/1518] ASoC: rt700-sdw: always drain jack work on remove Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0134/1518] clk: hisilicon: reset: Use devm_kzalloc to initialize hisi_reset_controller Greg Kroah-Hartman
` (865 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Shengjiu Wang, Mark Brown,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shengjiu Wang <shengjiu.wang@nxp.com>
[ Upstream commit 3359ba93d01a23b2e4249e9e44ccfe48eb9c5d71 ]
After pm_runtime_enable() the AUDMIX block is powered off and stays
suspended until the first runtime resume. Register writes issued between
probe() and the first resume (e.g. from DAPM or ALSA control paths)
target unpowered hardware and cause a system hang.
Fix this by calling pm_runtime_resume_and_get() immediately after
pm_runtime_enable() to power the hardware up and enable its clocks.
Release the reference afterwards with pm_runtime_put() to allow the
runtime PM framework to suspend the device and switch the regmap to
cache-only mode when idle.
When CONFIG_PM is disabled or runtime PM is not enabled, pm_runtime_*
calls are stubs that do not power up the hardware. Handle this case
explicitly by calling fsl_audmix_runtime_resume() directly so the
hardware is always initialised and its clocks are enabled, ensuring
register accesses succeed regardless of PM configuration.
Fixes: be1df61cf06ef ("ASoC: fsl: Add Audio Mixer CPU DAI driver")
Signed-off-by: Shengjiu Wang <shengjiu.wang@nxp.com>
Link: https://patch.msgid.link/20260618023818.31618-1-shengjiu.wang@oss.nxp.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/fsl/fsl_audmix.c | 24 ++++++++++++++++++++++--
1 file changed, 22 insertions(+), 2 deletions(-)
diff --git a/sound/soc/fsl/fsl_audmix.c b/sound/soc/fsl/fsl_audmix.c
index d9b0bd61755d5..c9a7a41ef388c 100644
--- a/sound/soc/fsl/fsl_audmix.c
+++ b/sound/soc/fsl/fsl_audmix.c
@@ -454,6 +454,9 @@ static const struct of_device_id fsl_audmix_ids[] = {
};
MODULE_DEVICE_TABLE(of, fsl_audmix_ids);
+static int fsl_audmix_runtime_resume(struct device *dev);
+static int fsl_audmix_runtime_suspend(struct device *dev);
+
static int fsl_audmix_probe(struct platform_device *pdev)
{
struct device *dev = &pdev->dev;
@@ -485,13 +488,25 @@ static int fsl_audmix_probe(struct platform_device *pdev)
spin_lock_init(&priv->lock);
platform_set_drvdata(pdev, priv);
pm_runtime_enable(dev);
+ if (!pm_runtime_enabled(dev)) {
+ ret = fsl_audmix_runtime_resume(dev);
+ if (ret)
+ goto err_disable_pm;
+ }
+
+ ret = pm_runtime_resume_and_get(dev);
+ if (ret < 0)
+ goto err_pm_get_sync;
+
+ /* To enable regmap cache only when runtime PM enabled */
+ pm_runtime_put(dev);
ret = devm_snd_soc_register_component(dev, &fsl_audmix_component,
fsl_audmix_dai,
ARRAY_SIZE(fsl_audmix_dai));
if (ret) {
dev_err(dev, "failed to register ASoC DAI\n");
- goto err_disable_pm;
+ goto err_pm_get_sync;
}
/*
@@ -503,12 +518,15 @@ static int fsl_audmix_probe(struct platform_device *pdev)
if (IS_ERR(priv->pdev)) {
ret = PTR_ERR(priv->pdev);
dev_err(dev, "failed to register platform: %d\n", ret);
- goto err_disable_pm;
+ goto err_pm_get_sync;
}
}
return 0;
+err_pm_get_sync:
+ if (!pm_runtime_status_suspended(dev))
+ fsl_audmix_runtime_suspend(dev);
err_disable_pm:
pm_runtime_disable(dev);
return ret;
@@ -519,6 +537,8 @@ static void fsl_audmix_remove(struct platform_device *pdev)
struct fsl_audmix *priv = dev_get_drvdata(&pdev->dev);
pm_runtime_disable(&pdev->dev);
+ if (!pm_runtime_status_suspended(&pdev->dev))
+ fsl_audmix_runtime_suspend(&pdev->dev);
if (priv->pdev)
platform_device_unregister(priv->pdev);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0134/1518] clk: hisilicon: reset: Use devm_kzalloc to initialize hisi_reset_controller
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (132 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0133/1518] ASoC: fsl_audmix: rework runtime PM handling in probe Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0135/1518] ARM: imx: fix device_node refcount leak in imx_src_init() Greg Kroah-Hartman
` (864 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Brian Masney, Min zhang, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Min zhang <zhangmin2026@yeah.net>
[ Upstream commit a8036f4591542de4b38ec81d3e2ba47bc0b2652b ]
Using devm_kmalloc() does not zero-initialize the allocated structure.
Uninitialized members in struct hisi_reset_controller may contain garbage
data, which can cause reset_controller_register() to fail unexpectedly.
Replace devm_kmalloc() with devm_kzalloc() to ensure all structure fields
are properly zero-initialized.
Fixes: 97b7129cd2afb ("reset: hisilicon: change the definition of hisi_reset_init")
Reviewed-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Min zhang <zhangmin2026@yeah.net>
Signed-off-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/hisilicon/reset.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/clk/hisilicon/reset.c b/drivers/clk/hisilicon/reset.c
index 93cee17db8b16..c3b7daac93132 100644
--- a/drivers/clk/hisilicon/reset.c
+++ b/drivers/clk/hisilicon/reset.c
@@ -91,7 +91,7 @@ struct hisi_reset_controller *hisi_reset_init(struct platform_device *pdev)
{
struct hisi_reset_controller *rstc;
- rstc = devm_kmalloc(&pdev->dev, sizeof(*rstc), GFP_KERNEL);
+ rstc = devm_kzalloc(&pdev->dev, sizeof(*rstc), GFP_KERNEL);
if (!rstc)
return NULL;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0135/1518] ARM: imx: fix device_node refcount leak in imx_src_init()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (133 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0134/1518] clk: hisilicon: reset: Use devm_kzalloc to initialize hisi_reset_controller Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0136/1518] ARM: imx: fix device_node refcount leaks in imx7_src_init() Greg Kroah-Hartman
` (863 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Weigang He, Frank Li, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Weigang He <geoffreyhe2@gmail.com>
[ Upstream commit 936407c3563ac745cbbb9953c0cf2472128a22f4 ]
imx_src_init() obtains a device_node reference via
of_find_compatible_node() matching "fsl,imx51-src" and uses it only to
call of_iomap(). It never releases that reference: on the success path
the function returns at the end without of_node_put(np), leaking one
device_node refcount on every boot of an i.MX5/6 platform.
Release the reference right after of_iomap(). of_iomap() maps the
node's registers but does not retain a reference to the device_node, so
the node can be put once the mapping is done. The early return on a NULL
np needs no put.
Found by static analysis tool CodeQL.
Fixes: bd3d924d71a4 ("ARM i.MX5: Add System Reset Controller (SRC) support for i.MX51 and i.MX53")
Signed-off-by: Weigang He <geoffreyhe2@gmail.com>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm/mach-imx/src.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/arch/arm/mach-imx/src.c b/arch/arm/mach-imx/src.c
index 59a8e8cc44693..f28bfb653a88f 100644
--- a/arch/arm/mach-imx/src.c
+++ b/arch/arm/mach-imx/src.c
@@ -171,6 +171,7 @@ void __init imx_src_init(void)
if (!np)
return;
src_base = of_iomap(np, 0);
+ of_node_put(np);
WARN_ON(!src_base);
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0136/1518] ARM: imx: fix device_node refcount leaks in imx7_src_init()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (134 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0135/1518] ARM: imx: fix device_node refcount leak in imx_src_init() Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0137/1518] arm64: dts: imx93-kontron: set memory node to 0x80000000/1GiB Greg Kroah-Hartman
` (862 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Weigang He, Frank Li, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Weigang He <geoffreyhe2@gmail.com>
[ Upstream commit 3de939b2ac843d56d88e2ab1e1b1f667cba9e1d4 ]
imx7_src_init() obtains two device_node references via
of_find_compatible_node() - one for "fsl,imx7d-src" and one for
"fsl,imx7d-gpc" - reusing the same np variable, but never calls
of_node_put() on either. On every i.MX7D boot up to two device_node
refcounts are leaked:
- The "fsl,imx7d-src" node is leaked both when of_iomap() fails (the
early return after the mapping) and when it succeeds, because np is
then overwritten by the second of_find_compatible_node() call
without releasing the prior reference.
- The "fsl,imx7d-gpc" node is leaked on every path leaving the
function after it is acquired.
Release each reference immediately after of_iomap() consumes the node.
of_iomap() maps the node's registers but does not retain a reference to
the device_node, so it is safe to put the node once mapped; this also
drops the first reference before np is reused for the second lookup.
Found by static analysis tool CodeQL.
Fixes: e34645f45805 ("ARM: imx: add smp support for imx7d")
Signed-off-by: Weigang He <geoffreyhe2@gmail.com>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm/mach-imx/src.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/arch/arm/mach-imx/src.c b/arch/arm/mach-imx/src.c
index f28bfb653a88f..c3c80b4c3d53b 100644
--- a/arch/arm/mach-imx/src.c
+++ b/arch/arm/mach-imx/src.c
@@ -196,6 +196,7 @@ void __init imx7_src_init(void)
return;
src_base = of_iomap(np, 0);
+ of_node_put(np);
if (!src_base)
return;
@@ -204,6 +205,7 @@ void __init imx7_src_init(void)
return;
gpc_base = of_iomap(np, 0);
+ of_node_put(np);
if (!gpc_base)
return;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0137/1518] arm64: dts: imx93-kontron: set memory node to 0x80000000/1GiB
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (135 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0136/1518] ARM: imx: fix device_node refcount leaks in imx7_src_init() Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0138/1518] clk: imx: scu: drop redundant init.ops variable assignment Greg Kroah-Hartman
` (861 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Frieder Schrempf, Frank Li,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frieder Schrempf <frieder.schrempf@kontron.de>
[ Upstream commit 9c269fe7eae8cb60d8d6c326dd8955818722fae9 ]
The start address of the DRAM area is 0x80000000. The minimal size of the
DDR on the SoM is 1 GiB.
Fixes: 2b52fd6035b7 ("arm64: dts: Add support for Kontron i.MX93 OSM-S SoM and BL carrier board")
Signed-off-by: Frieder Schrempf <frieder.schrempf@kontron.de>
Signed-off-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/freescale/imx93-kontron-osm-s.dtsi | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/arm64/boot/dts/freescale/imx93-kontron-osm-s.dtsi b/arch/arm64/boot/dts/freescale/imx93-kontron-osm-s.dtsi
index c79b1df339db1..f881912cde460 100644
--- a/arch/arm64/boot/dts/freescale/imx93-kontron-osm-s.dtsi
+++ b/arch/arm64/boot/dts/freescale/imx93-kontron-osm-s.dtsi
@@ -15,9 +15,9 @@ aliases {
rtc1 = &bbnsm_rtc;
};
- memory@40000000 {
+ memory@80000000 {
device_type = "memory";
- reg = <0x0 0x40000000 0 0x80000000>;
+ reg = <0x0 0x80000000 0 0x40000000>;
};
chosen {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0138/1518] clk: imx: scu: drop redundant init.ops variable assignment
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (136 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0137/1518] arm64: dts: imx93-kontron: set memory node to 0x80000000/1GiB Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0139/1518] drm/lima: call drm_mm_init() with a valid allocation range Greg Kroah-Hartman
` (860 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Peng Fan, Brian Masney, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Brian Masney <bmasney@redhat.com>
[ Upstream commit 5f2db1ce201216e81333ecc2ab51494410b2fe0d ]
The init.ops is assigned a default value, however right below it is an
if, else if, and else where all of them also assign a value to init.ops.
Drop the redundant init.ops assignment at the top.
Fixes: 3b9ea606cda53 ("clk: imx: scu: add cpu frequency scaling support")
Reviewed-by: Peng Fan <peng.fan@nxp.com>
Signed-off-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/imx/clk-scu.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/drivers/clk/imx/clk-scu.c b/drivers/clk/imx/clk-scu.c
index c03f7821824d1..b2b0e5f05b238 100644
--- a/drivers/clk/imx/clk-scu.c
+++ b/drivers/clk/imx/clk-scu.c
@@ -465,7 +465,6 @@ struct clk_hw *__imx_clk_scu(struct device *dev, const char *name,
clk->clk_type = clk_type;
init.name = name;
- init.ops = &clk_scu_ops;
if (rsrc_id == IMX_SC_R_A35 || rsrc_id == IMX_SC_R_A53 || rsrc_id == IMX_SC_R_A72)
init.ops = &clk_scu_cpu_ops;
else if (rsrc_id == IMX_SC_R_PI_0_PLL)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0139/1518] drm/lima: call drm_mm_init() with a valid allocation range
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (137 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0138/1518] clk: imx: scu: drop redundant init.ops variable assignment Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0140/1518] mm/mm_init: fix incorrect node_spanned_pages Greg Kroah-Hartman
` (859 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Henrik Grimler, Qiang Yu,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Henrik Grimler <henrik.grimler@axis.com>
[ Upstream commit 3b3bce4a692ac60d9f4a341e6b597dd1fd0a28f9 ]
lima_vm_create() is currently run before va_start and va_end are set up,
meaning they are both 0. lima_vm_create() runs drm_mm_init() with them
as arguments for the allocator, and if DRM_DEBUG_MM is enabled the
DRM_MM_BUG_ON check in drm_mm_init then fires, as seen here on
exynos4412-odroid-u2:
[ 1.736297] ------------[ cut here ]------------
[ 1.740370] kernel BUG at drivers/gpu/drm/drm_mm.c:931!
[ 1.745574] Internal error: Oops - BUG: 0 [#1] SMP ARM
[ 1.750697] Modules linked in:
[ 1.753734] CPU: 0 UID: 0 PID: 41 Comm: kworker/u16:1 Not tainted 7.0.10-postmarketos-exynos4 #11 PREEMPT
[ 1.763372] Hardware name: Samsung Exynos (Flattened Device Tree)
[ 1.769446] Workqueue: events_unbound deferred_probe_work_func
[ 1.775261] PC is at drm_mm_init+0x9c/0xa4
[ 1.779339] LR is at lima_vm_create+0x144/0x17c
[ ... ]
Fix the issue by moving the lima_vm_create() call after va_start and
va_end are set up.
Fixes: a1d2a6339961 ("drm/lima: driver for ARM Mali4xx GPUs")
Signed-off-by: Henrik Grimler <henrik.grimler@axis.com>
Signed-off-by: Qiang Yu <yuq825@gmail.com>
Link: https://patch.msgid.link/20260601-lima-alloc-fix-v1-1-16d3f3b7b780@axis.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/lima/lima_device.c | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
diff --git a/drivers/gpu/drm/lima/lima_device.c b/drivers/gpu/drm/lima/lima_device.c
index 0bf7105c8748b..7c873e62c16da 100644
--- a/drivers/gpu/drm/lima/lima_device.c
+++ b/drivers/gpu/drm/lima/lima_device.c
@@ -368,12 +368,6 @@ int lima_device_init(struct lima_device *ldev)
if (err)
goto err_out0;
- ldev->empty_vm = lima_vm_create(ldev);
- if (!ldev->empty_vm) {
- err = -ENOMEM;
- goto err_out1;
- }
-
ldev->va_start = 0;
if (ldev->id == lima_gpu_mali450) {
ldev->va_end = LIMA_VA_RESERVE_START;
@@ -387,6 +381,12 @@ int lima_device_init(struct lima_device *ldev)
} else
ldev->va_end = LIMA_VA_RESERVE_END;
+ ldev->empty_vm = lima_vm_create(ldev);
+ if (!ldev->empty_vm) {
+ err = -ENOMEM;
+ goto err_out1;
+ }
+
ldev->iomem = devm_platform_ioremap_resource(pdev, 0);
if (IS_ERR(ldev->iomem)) {
dev_err(ldev->dev, "fail to ioremap iomem\n");
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0140/1518] mm/mm_init: fix incorrect node_spanned_pages
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (138 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0139/1518] drm/lima: call drm_mm_init() with a valid allocation range Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0141/1518] sched/fair: Fix overflow in update_tg_cfs_runnable() Greg Kroah-Hartman
` (858 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Wei Yang, Yuan Liu,
Mike Rapoport (Microsoft), Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wei Yang <richard.weiyang@gmail.com>
[ Upstream commit 7783dcd79ae9c4aa48bc47bd4275772445dc4b2a ]
Current node_spanned_pages is got as a summation of all zone's spanned page
in calculate_node_totalpages(). Generally this is good, but if we use
kernelcore=mirror, it is would be wrong.
Without kernelcore=mirror:
The test machine has below memory layout:
memory[0x0] [0x0000000000001000-0x000000000009efff], 0x000000000009e000 bytes on node 0 flags: 0x0
memory[0x1] [0x0000000000100000-0x00000000bffdefff], 0x00000000bfedf000 bytes on node 0 flags: 0x0
memory[0x2] [0x0000000100000000-0x00000001bfffffff], 0x00000000c0000000 bytes on node 0 flags: 0x0
And the Zone range is:
DMA [mem 0x0000000000001000-0x0000000000ffffff]
DMA32 [mem 0x0000000001000000-0x00000000ffffffff]
Normal [mem 0x0000000100000000-0x00000001bfffffff]
Then we see, with spanned_pages printed:
On node 0 spanned_pages: 1835007 totalpages: 1572733
With kernelcore=mirror:
The test machine has below memory layout:
memory[0x0] [0x0000000000001000-0x000000000009efff], 0x000000000009e000 bytes on node 0 flags: 0x2
memory[0x1] [0x0000000000100000-0x00000000bffdefff], 0x00000000bfedf000 bytes on node 0 flags: 0x2
memory[0x2] [0x0000000100000000-0x000000013fffffff], 0x0000000040000000 bytes on node 0 flags: 0x2
memory[0x3] [0x0000000140000000-0x00000001bfffffff], 0x0000000080000000 bytes on node 0 flags: 0x0
And the Zone range is:
DMA [mem 0x0000000000001000-0x0000000000ffffff]
DMA32 [mem 0x0000000001000000-0x00000000ffffffff]
Normal [mem 0x0000000100000000-0x00000001bfffffff]
Device empty
Movable zone start for each node
Node 0: 0x0000000140000000
Then we see, with spanned_pages printed:
On node 0 spanned_pages: 2359295 totalpages: 1572733
The total range of memory on node 0 doesn't change, but the spanned_pages
becomes much larger.
The reason is when kernelcore=mirror is specified, the range of Zone Normal
and Zone Movable would overlap. So the overlapped range would be calculated
twice.
A wrong node_spanned_pages would effect defer_init(), since each
zone_end_pfn is less than pgdat_end_pfn().
As we already passed in node_start_pfn and node_end_pfn, fix this by get it
from (node_start_pfn - node_end_pfn) directly.
Fixes: 342332e6a925 ("mm/page_alloc.c: introduce kernelcore=mirror option")
Signed-off-by: Wei Yang <richard.weiyang@gmail.com>
Cc: Yuan Liu <yuan1.liu@intel.com>
Link: https://patch.msgid.link/20260622022403.16375-1-richard.weiyang@gmail.com
Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
mm/mm_init.c | 5 ++---
1 file changed, 2 insertions(+), 3 deletions(-)
diff --git a/mm/mm_init.c b/mm/mm_init.c
index 5789ad8ba9b6d..4ed5b09f4eb4f 100644
--- a/mm/mm_init.c
+++ b/mm/mm_init.c
@@ -1351,7 +1351,7 @@ static void __init calculate_node_totalpages(struct pglist_data *pgdat,
unsigned long node_start_pfn,
unsigned long node_end_pfn)
{
- unsigned long realtotalpages = 0, totalpages = 0;
+ unsigned long realtotalpages = 0;
enum zone_type i;
for (i = 0; i < MAX_NR_ZONES; i++) {
@@ -1381,11 +1381,10 @@ static void __init calculate_node_totalpages(struct pglist_data *pgdat,
zone->present_early_pages = real_size;
#endif
- totalpages += spanned;
realtotalpages += real_size;
}
- pgdat->node_spanned_pages = totalpages;
+ pgdat->node_spanned_pages = node_end_pfn - node_start_pfn;
pgdat->node_present_pages = realtotalpages;
pr_debug("On node %d totalpages: %lu\n", pgdat->node_id, realtotalpages);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0141/1518] sched/fair: Fix overflow in update_tg_cfs_runnable()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (139 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0140/1518] mm/mm_init: fix incorrect node_spanned_pages Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0142/1518] perf/x86/intel/uncore: Keep PCI PMUs working when MMIO/MSR setup fails Greg Kroah-Hartman
` (857 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chen Yu, Peter Zijlstra (Intel),
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chen, Yu C <yu.c.chen@intel.com>
[ Upstream commit 4f166adb5cb0525d9e32d45729fd8f28c80acbee ]
A divide-by-zero crash is observed when running hackbench:
[14697.488452] CPU: 112 UID: 0 PID: 124791 Comm: hackbench Not tainted 7.1.0-rc2+
[14697.492627] RIP: 0010:propagate_entity_load_avg+0x35f/0x3e0
[14697.506799] <TASK>
[14697.507411] __dequeue_task+0x2b4/0xc70
[14697.508677] dequeue_task_fair+0x36/0x370
[14697.509047] dequeue_task+0x101/0x2f0
[14697.509426] __schedule+0x1b1/0x1a00
[14697.510868] anon_pipe_read+0x3da/0x450
[14697.511400] vfs_read+0x361/0x390
[14697.512053] __x64_sys_read+0x19/0x30
The divide-by-zero happens here:
if (scale_load_down(gcfs_rq->load.weight)) {
load_sum = div_u64(gcfs_rq->avg.load_sum,
scale_load_down(gcfs_rq->load.weight));
}
gcfs_rq->load.weight is an insane large value and is truncated
to the lower 32 bits by div_u64, which happen to be 0.
Using AI for investigation, the cause is a u32 overflow in
update_tg_cfs_runnable(), and flat pickup became a victim when using
tg_tasks():
u32 new_sum, divider;
...
new_sum = se->avg.runnable_avg * divider; <-- boom
The following sequence shows how this triggers the crash:
propagate_entity_load_avg()
update_tg_cfs_runnable() # u32 overflow corrupts runnable_sum
__update_load_avg_cfs_rq()
___update_load_avg() # computes insane runnable_avg
update_tg_load_avg() # propagates to tg->runnable_avg
update_cfs_group()
calc_concur_shares()
tg_tasks() # long-to-int truncation, negative nr
reweight_entity() # corrupted se->load.weight
update_load_add() # corrupted cfs_rq->load.weight
propagate_entity_load_avg()
update_tg_cfs_load()
div_u64() # divide-by-zero
Fix by widening new_sum from u32 to u64 (no need to force tg_tasks()
to return unsigned long after this fix)
Fixes: 95246d1ec80b ("sched/pelt: Relax the sync of runnable_sum with runnable_avg")
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Chen Yu <yu.c.chen@intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Link: https://patch.msgid.link/a22eea2b-4c4a-4623-9a44-d7b18c0c91c8@intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/sched/fair.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/kernel/sched/fair.c b/kernel/sched/fair.c
index eb4d5e558b6e1..30ebe2823d238 100644
--- a/kernel/sched/fair.c
+++ b/kernel/sched/fair.c
@@ -4463,7 +4463,8 @@ static inline void
update_tg_cfs_runnable(struct cfs_rq *cfs_rq, struct sched_entity *se, struct cfs_rq *gcfs_rq)
{
long delta_sum, delta_avg = gcfs_rq->avg.runnable_avg - se->avg.runnable_avg;
- u32 new_sum, divider;
+ u64 new_sum;
+ u32 divider;
/* Nothing to update */
if (!delta_avg)
@@ -4477,7 +4478,7 @@ update_tg_cfs_runnable(struct cfs_rq *cfs_rq, struct sched_entity *se, struct cf
/* Set new sched_entity's runnable */
se->avg.runnable_avg = gcfs_rq->avg.runnable_avg;
- new_sum = se->avg.runnable_avg * divider;
+ new_sum = (u64)se->avg.runnable_avg * divider;
delta_sum = (long)new_sum - (long)se->avg.runnable_sum;
se->avg.runnable_sum = new_sum;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0142/1518] perf/x86/intel/uncore: Keep PCI PMUs working when MMIO/MSR setup fails
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (140 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0141/1518] sched/fair: Fix overflow in update_tg_cfs_runnable() Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0143/1518] pinctrl: bcm2835: Dont remove an unregistered GPIO chip Greg Kroah-Hartman
` (856 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zide Chen, Peter Zijlstra (Intel),
Ian Rogers, Dapeng Mi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zide Chen <zide.chen@intel.com>
[ Upstream commit 3012af7df3430788eddd30b3c6654d0a0a5f06c6 ]
uncore_event_cpu_online() returns -ENOMEM early when both the MSR and
MMIO box allocations fail. This also aborts PCI uncore setup, even
though PCI PMUs are independent of the MSR/MMIO paths.
Remove the early return so PCI uncore setup always runs regardless
of whether MSR or MMIO box allocation succeeds.
Fixes: 3da04b8a00dd ("perf/x86/intel/uncore: Support MMIO type uncore blocks")
Signed-off-by: Zide Chen <zide.chen@intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Reviewed-by: Ian Rogers <irogers@google.com>
Reviewed-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Link: https://patch.msgid.link/20260611160033.66760-5-zide.chen@intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/events/intel/uncore.c | 2 --
1 file changed, 2 deletions(-)
diff --git a/arch/x86/events/intel/uncore.c b/arch/x86/events/intel/uncore.c
index 8301a589d9a61..a5793847ed5a9 100644
--- a/arch/x86/events/intel/uncore.c
+++ b/arch/x86/events/intel/uncore.c
@@ -1613,8 +1613,6 @@ static int uncore_event_cpu_online(unsigned int cpu)
die = topology_logical_die_id(cpu);
msr_ret = uncore_box_ref(uncore_msr_uncores, die, cpu);
mmio_ret = uncore_box_ref(uncore_mmio_uncores, die, cpu);
- if (msr_ret && mmio_ret)
- return -ENOMEM;
/*
* Check if there is an online cpu in the package
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0143/1518] pinctrl: bcm2835: Dont remove an unregistered GPIO chip
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (141 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0142/1518] perf/x86/intel/uncore: Keep PCI PMUs working when MMIO/MSR setup fails Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0144/1518] riscv: kexec_file: Fix crashk_low_res not exclude bug Greg Kroah-Hartman
` (855 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Daniel McCarthy, Linus Walleij,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel McCarthy <daniel@dragonzap.com>
[ Upstream commit 32711f77db0641e57fd96fdc013bf1286b9f2514 ]
If the devm_pinctrl_register() function fails,
bcm2835_pinctrl_probe() calls gpiochip_remove()
before gpiochip_add_data() has registered the GPIO chip.
This means that upon failure the gpio_chip.gpiodev
is NULL resulting in a null pointer dereference
inside the gpiochip_remove() function.
Remove the unnecessary function call to gpiochip_remove().
No GPIO cleanup is required because the GPIO chip
has not yet been registered. Without this change there
is potential for a kernel panic upon registration failure
Fixes: 266423e60ea1 ("pinctrl: bcm2835: Change init order for gpio hogs")
Signed-off-by: Daniel McCarthy <daniel@dragonzap.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pinctrl/bcm/pinctrl-bcm2835.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/drivers/pinctrl/bcm/pinctrl-bcm2835.c b/drivers/pinctrl/bcm/pinctrl-bcm2835.c
index c165674c5b4db..bda4273138ff3 100644
--- a/drivers/pinctrl/bcm/pinctrl-bcm2835.c
+++ b/drivers/pinctrl/bcm/pinctrl-bcm2835.c
@@ -1351,7 +1351,6 @@ static int bcm2835_pinctrl_probe(struct platform_device *pdev)
pc->pctl_desc = *pdata->pctl_desc;
pc->pctl_dev = devm_pinctrl_register(dev, &pc->pctl_desc, pc);
if (IS_ERR(pc->pctl_dev)) {
- gpiochip_remove(&pc->gpio_chip);
return PTR_ERR(pc->pctl_dev);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0144/1518] riscv: kexec_file: Fix crashk_low_res not exclude bug
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (142 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0143/1518] pinctrl: bcm2835: Dont remove an unregistered GPIO chip Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0145/1518] media: keymaps: Remove obsolete RC_MAP_RC5_TV keymap define Greg Kroah-Hartman
` (854 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Guo Ren, Baoquan He, Jinjie Ruan,
Mike Rapoport (Microsoft), Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jinjie Ruan <ruanjinjie@huawei.com>
[ Upstream commit 5fc6e7d45373571d03cd04fd4c6069c0a97fa75a ]
As done in commit 944a45abfabc ("arm64: kdump: Reimplement crashkernel=X")
and commit 4831be702b95 ("arm64/kexec: Fix missing extra range for
crashkres_low.") for arm64, while implementing crashkernel=X,[high,low],
riscv should have excluded the "crashk_low_res" reserved ranges from
the crash kernel memory to prevent them from being exported through
/proc/vmcore, and the exclusion would need an extra crash_mem range.
Just simply tested on qemu with crashkernel=4G with kexec in [1] mentioned
in [2]. And the second kernel can be started normally.
# dmesg | grep crash
[ 0.000000] crashkernel low memory reserved: 0xf8000000 - 0x100000000 (128 MB)
[ 0.000000] crashkernel reserved: 0x000000017fe00000 - 0x000000027fe00000 (4096 MB)
[1]: https://github.com/chenjh005/kexec-tools/tree/build-test-riscv-v2
[2]: https://lore.kernel.org/all/20230726175000.2536220-1-chenjiahao16@huawei.com/
Cc: Guo Ren <guoren@kernel.org>
Cc: Baoquan He <bhe@redhat.com>
Fixes: 5882e5acf18d ("riscv: kdump: Implement crashkernel=X,[high,low]")
Reviewed-by: Guo Ren <guoren@kernel.org>
Signed-off-by: Jinjie Ruan <ruanjinjie@huawei.com>
Link: https://github.com/chenjh005/kexec-tools/tree/build-test-riscv-v2
Link: https://lore.kernel.org/all/20230726175000.2536220-1-chenjiahao16@huawei.com/
Link: https://patch.msgid.link/20260629094746.191843-2-ruanjinjie@huawei.com
Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/riscv/kernel/machine_kexec_file.c | 14 +++++++++++---
1 file changed, 11 insertions(+), 3 deletions(-)
diff --git a/arch/riscv/kernel/machine_kexec_file.c b/arch/riscv/kernel/machine_kexec_file.c
index dd9d92a965174..6ef5bd34d130a 100644
--- a/arch/riscv/kernel/machine_kexec_file.c
+++ b/arch/riscv/kernel/machine_kexec_file.c
@@ -61,7 +61,7 @@ static int prepare_elf_headers(void **addr, unsigned long *sz)
unsigned int nr_ranges;
int ret;
- nr_ranges = 1; /* For exclusion of crashkernel region */
+ nr_ranges = 2; /* For exclusion of crashkernel region */
walk_system_ram_res(0, -1, &nr_ranges, get_nr_ram_ranges_callback);
cmem = kmalloc(struct_size(cmem, ranges, nr_ranges), GFP_KERNEL);
@@ -76,8 +76,16 @@ static int prepare_elf_headers(void **addr, unsigned long *sz)
/* Exclude crashkernel region */
ret = crash_exclude_mem_range(cmem, crashk_res.start, crashk_res.end);
- if (!ret)
- ret = crash_prepare_elf64_headers(cmem, true, addr, sz);
+ if (ret)
+ goto out;
+
+ if (crashk_low_res.end) {
+ ret = crash_exclude_mem_range(cmem, crashk_low_res.start, crashk_low_res.end);
+ if (ret)
+ goto out;
+ }
+
+ ret = crash_prepare_elf64_headers(cmem, true, addr, sz);
out:
kfree(cmem);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0145/1518] media: keymaps: Remove obsolete RC_MAP_RC5_TV keymap define
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (143 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0144/1518] riscv: kexec_file: Fix crashk_low_res not exclude bug Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0146/1518] media: keymaps: Remove obsolete RC_MAP_HAUPPAUGE_NEW " Greg Kroah-Hartman
` (853 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sean Young, Mauro Carvalho Chehab,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sean Young <sean@mess.org>
[ Upstream commit 5370facb7b4461166a4610d456fefeb92ef50a82 ]
Since commit 206241069ecf ("[media] rc/keymaps: Remove the obsolete
rc-rc5-tv keymap"), the rc-rc5-tv keymap is no longer in the tree.
Fixes: 206241069ecf ("[media] rc/keymaps: Remove the obsolete rc-rc5-tv keymap")
Signed-off-by: Sean Young <sean@mess.org>
Acked-by: Mauro Carvalho Chehab <mchehab+huawei@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/media/rc-map.h | 1 -
1 file changed, 1 deletion(-)
diff --git a/include/media/rc-map.h b/include/media/rc-map.h
index d90e4611b0664..950d702aee3bb 100644
--- a/include/media/rc-map.h
+++ b/include/media/rc-map.h
@@ -309,7 +309,6 @@ struct rc_map *rc_map_get(const char *name);
#define RC_MAP_PROTEUS_2309 "rc-proteus-2309"
#define RC_MAP_PURPLETV "rc-purpletv"
#define RC_MAP_PV951 "rc-pv951"
-#define RC_MAP_RC5_TV "rc-rc5-tv"
#define RC_MAP_RC6_MCE "rc-rc6-mce"
#define RC_MAP_REAL_AUDIO_220_32_KEYS "rc-real-audio-220-32-keys"
#define RC_MAP_REDDO "rc-reddo"
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0146/1518] media: keymaps: Remove obsolete RC_MAP_HAUPPAUGE_NEW keymap define
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (144 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0145/1518] media: keymaps: Remove obsolete RC_MAP_RC5_TV keymap define Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0147/1518] wifi: ath12k: correct monitor destination ring size Greg Kroah-Hartman
` (852 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sean Young, Mauro Carvalho Chehab,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sean Young <sean@mess.org>
[ Upstream commit 6e5deb2923b0d1b73c77a1a77c30b0da43d9e022 ]
Since commit af86ce79f020 ("[media] remove the old RC_MAP_HAUPPAUGE_NEW
RC map"), the RC_MAP_HAUPPAUGE_NEW define is no longer used.
Fixes: af86ce79f020 ("[media] remove the old RC_MAP_HAUPPAUGE_NEW RC map")
Signed-off-by: Sean Young <sean@mess.org>
Acked-by: Mauro Carvalho Chehab <mchehab+huawei@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/media/rc-map.h | 1 -
1 file changed, 1 deletion(-)
diff --git a/include/media/rc-map.h b/include/media/rc-map.h
index 950d702aee3bb..d95ed3e96de28 100644
--- a/include/media/rc-map.h
+++ b/include/media/rc-map.h
@@ -262,7 +262,6 @@ struct rc_map *rc_map_get(const char *name);
#define RC_MAP_GENIUS_TVGO_A11MCE "rc-genius-tvgo-a11mce"
#define RC_MAP_GOTVIEW7135 "rc-gotview7135"
#define RC_MAP_HAUPPAUGE "rc-hauppauge"
-#define RC_MAP_HAUPPAUGE_NEW "rc-hauppauge"
#define RC_MAP_HISI_POPLAR "rc-hisi-poplar"
#define RC_MAP_HISI_TV_DEMO "rc-hisi-tv-demo"
#define RC_MAP_IMON_MCE "rc-imon-mce"
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0147/1518] wifi: ath12k: correct monitor destination ring size
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (145 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0146/1518] media: keymaps: Remove obsolete RC_MAP_HAUPPAUGE_NEW " Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0148/1518] perf test: Drain pipe after child finishes to avoid losing output Greg Kroah-Hartman
` (851 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Aaradhana Sahu, Rameshkumar Sundaram,
Baochen Qiang, Jeff Johnson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aaradhana Sahu <aaradhana.sahu@oss.qualcomm.com>
[ Upstream commit 913998f903fb1432c0046c33003db38a9e8bedb1 ]
The default memory profile configures rxdma_monitor_dst_ring_size as 8092,
which is a typo. The intended value is 8192, consistent with all other ring
sizes in the table being powers of two.
Correct the monitor destination ring size to 8192.
Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.6-01243-QCAHKSWPL_SILICONZ-1
Fixes: defae535dd63 ("wifi: ath12k: Add a table of parameters entries impacting memory consumption")
Signed-off-by: Aaradhana Sahu <aaradhana.sahu@oss.qualcomm.com>
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Link: https://patch.msgid.link/20260616062342.4079796-1-aaradhana.sahu@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/ath/ath12k/core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/ath/ath12k/core.c b/drivers/net/wireless/ath/ath12k/core.c
index cc352eef19399..5fed8d1bcadb3 100644
--- a/drivers/net/wireless/ath/ath12k/core.c
+++ b/drivers/net/wireless/ath/ath12k/core.c
@@ -46,7 +46,7 @@ ath12k_mem_profile_based_param ath12k_mem_profile_based_param[] = {
.dp_params = {
.tx_comp_ring_size = 32768,
.rxdma_monitor_buf_ring_size = 4096,
- .rxdma_monitor_dst_ring_size = 8092,
+ .rxdma_monitor_dst_ring_size = 8192,
.num_pool_tx_desc = 32768,
.rx_desc_count = 12288,
},
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0148/1518] perf test: Drain pipe after child finishes to avoid losing output
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (146 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0147/1518] wifi: ath12k: correct monitor destination ring size Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0149/1518] perf test: Refactor parallel poll loop to drain all pipes simultaneously Greg Kroah-Hartman
` (850 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ian Rogers, Adrian Hunter,
Alexander Shishkin, Ingo Molnar, James Clark, Jiri Olsa,
Namhyung Kim, Peter Zijlstra, Arnaldo Carvalho de Melo,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ian Rogers <irogers@google.com>
[ Upstream commit 744af598719776b2ca8b0f5388b51d2493cc94b7 ]
When running tests in parallel, the parent process reads output from the
child's pipe. However, it might exit the loop as soon as the child is
detected as finished, potentially missing data that arrived in the pipe
just after the last poll or before the loop terminated.
Address this by draining the pipe after the main loop in finish_test.
Assisted-by: Gemini-CLI:Google Gemini 3
Signed-off-by: Ian Rogers <irogers@google.com>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Cc: Alexander Shishkin <alexander.shishkin@linux.intel.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: James Clark <james.clark@linaro.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Stable-dep-of: 32e6312f7e39 ("perf test: Truncate test description to fit terminal width")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/tests/builtin-test.c | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/tools/perf/tests/builtin-test.c b/tools/perf/tests/builtin-test.c
index 0d2fb7a4ae5bd..b02138a855753 100644
--- a/tools/perf/tests/builtin-test.c
+++ b/tools/perf/tests/builtin-test.c
@@ -476,6 +476,16 @@ static void finish_test(struct child_test **child_tests, int running_test, int c
if (err_done)
err_done = check_if_command_finished(&child_test->process);
}
+ /* Drain any remaining data from the pipe. */
+ if (err > 0) {
+ char buf[512];
+ ssize_t len;
+
+ while ((len = read(err, buf, sizeof(buf) - 1)) > 0) {
+ buf[len] = '\0';
+ strbuf_addstr(&err_output, buf);
+ }
+ }
if (perf_use_color_default && last_running != -1) {
/* Erase "Running (.. active)" line printed before poll/sleep. */
fprintf(debug_file(), PERF_COLOR_DELETE_LINE);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0149/1518] perf test: Refactor parallel poll loop to drain all pipes simultaneously
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (147 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0148/1518] perf test: Drain pipe after child finishes to avoid losing output Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0150/1518] perf test: Show snippet failure output for verbose=1 Greg Kroah-Hartman
` (849 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ian Rogers, Adrian Hunter,
Alexander Shishkin, Ingo Molnar, James Clark, Jiri Olsa,
Namhyung Kim, Peter Zijlstra, Arnaldo Carvalho de Melo,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ian Rogers <irogers@google.com>
[ Upstream commit f35450738e789b80b540f41487b9053defd0bb8d ]
When running tests in parallel with verbose output (-v), child processes
write to pipes. If a test produces significant output (e.g. Granite
Rapids metric parsing printing hundreds of lines), it fills the 64KB
pipe buffer and blocks.
Previously, the parent harness (finish_test) only polled the pipe of the
current test waiting to be printed. Other children blocked indefinitely
until the parent reached them, severely sequentializing execution.
Address this by implementing finish_tests_parallel() to poll and drain
output pipes from all running children simultaneously into per-child
buffers, employing safe strbuf_addstr string operations alongside
thorough variable orderings for strict ISO C90 compliance. Reaping
occurs out of order as children finish, while final result printing
remains strictly in order.
This drops parallel verbose execution time for the PMU events suite from
~35 seconds down to ~5.9 seconds.
Assisted-by: Gemini-CLI:Google Gemini 3
Signed-off-by: Ian Rogers <irogers@google.com>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Cc: Alexander Shishkin <alexander.shishkin@linux.intel.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: James Clark <james.clark@linaro.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Stable-dep-of: 32e6312f7e39 ("perf test: Truncate test description to fit terminal width")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/tests/builtin-test.c | 267 +++++++++++++++++++++++++++++++-
1 file changed, 259 insertions(+), 8 deletions(-)
diff --git a/tools/perf/tests/builtin-test.c b/tools/perf/tests/builtin-test.c
index b02138a855753..552aa898fc70d 100644
--- a/tools/perf/tests/builtin-test.c
+++ b/tools/perf/tests/builtin-test.c
@@ -295,6 +295,9 @@ struct child_test {
struct test_suite *test;
int suite_num;
int test_case_num;
+ struct strbuf err_output;
+ int result;
+ bool done;
};
static jmp_buf run_test_jmp_buf;
@@ -349,6 +352,11 @@ static int run_test_child(struct child_process *process)
#define TEST_RUNNING -3
+static struct pollfd *global_pfds;
+static size_t *global_pfd_indices;
+
+static int strbuf_addstr_safe(struct strbuf *sb, const char *s);
+
static int print_test_result(struct test_suite *t, int curr_suite, int curr_test_case,
int result, int width, int running)
{
@@ -415,7 +423,7 @@ static void finish_test(struct child_test **child_tests, int running_test, int c
* Busy loop reading from the child's stdout/stderr that are set to be
* non-blocking until EOF.
*/
- if (err > 0)
+ if (err >= 0)
fcntl(err, F_SETFL, O_NONBLOCK);
if (verbose > 1) {
if (test_suite__num_test_cases(t) > 1)
@@ -469,7 +477,7 @@ static void finish_test(struct child_test **child_tests, int running_test, int c
if (len > 0) {
err_done = false;
buf[len] = '\0';
- strbuf_addstr(&err_output, buf);
+ strbuf_addstr_safe(&err_output, buf);
}
}
}
@@ -477,13 +485,13 @@ static void finish_test(struct child_test **child_tests, int running_test, int c
err_done = check_if_command_finished(&child_test->process);
}
/* Drain any remaining data from the pipe. */
- if (err > 0) {
+ if (err >= 0) {
char buf[512];
ssize_t len;
while ((len = read(err, buf, sizeof(buf) - 1)) > 0) {
buf[len] = '\0';
- strbuf_addstr(&err_output, buf);
+ strbuf_addstr_safe(&err_output, buf);
}
}
if (perf_use_color_default && last_running != -1) {
@@ -492,16 +500,253 @@ static void finish_test(struct child_test **child_tests, int running_test, int c
}
/* Clean up child process. */
ret = finish_command(&child_test->process);
+ child_test->process.pid = 0;
+ if (child_test->err_output.len > 0) {
+ struct strbuf merged = STRBUF_INIT;
+
+ if (child_test->err_output.buf)
+ strbuf_addstr_safe(&merged, child_test->err_output.buf);
+ if (err_output.buf)
+ strbuf_addstr_safe(&merged, err_output.buf);
+ strbuf_release(&err_output);
+ err_output = merged;
+ }
if (verbose > 1 || (verbose == 1 && ret == TEST_FAIL))
fprintf(stderr, "%s", err_output.buf);
strbuf_release(&err_output);
+ strbuf_release(&child_test->err_output);
print_test_result(t, curr_suite, curr_test_case, ret, width, /*running=*/0);
if (err > 0)
close(err);
zfree(&child_tests[running_test]);
}
+static int strbuf_addstr_safe(struct strbuf *sb, const char *s)
+{
+ sigset_t set, oldset;
+ int ret;
+
+ sigemptyset(&set);
+ sigaddset(&set, SIGINT);
+ sigaddset(&set, SIGTERM);
+ pthread_sigmask(SIG_BLOCK, &set, &oldset);
+ ret = strbuf_addstr(sb, s);
+ pthread_sigmask(SIG_SETMASK, &oldset, NULL);
+ return ret;
+}
+
+static void drain_child_process_err(struct child_test *child)
+{
+ char buf[512];
+ ssize_t len;
+
+ while ((len = read(child->process.err, buf, sizeof(buf) - 1)) > 0) {
+ buf[len] = '\0';
+ strbuf_addstr_safe(&child->err_output, buf);
+ }
+}
+
+static void handle_child_pipe_activity(struct child_test *child, short revents)
+{
+ if (!revents)
+ return;
+
+ drain_child_process_err(child);
+ /*
+ * If the child closed its end of the pipe (EOF) or encountered
+ * an error, close the file descriptor immediately and set it
+ * to -1. This removes it from the pfds array for subsequent
+ * iterations, preventing a tight CPU busy-loop while waiting
+ * for the process itself to exit.
+ */
+ if (revents & (POLLHUP | POLLERR | POLLNVAL)) {
+ close(child->process.err);
+ child->process.err = -1;
+ }
+}
+
+static int finish_tests_parallel(struct child_test **child_tests, size_t num_tests, int width)
+{
+ size_t next_to_print = 0;
+ struct pollfd *pfds;
+ size_t *pfd_indices;
+ size_t num_pfds = 0;
+ int last_running = -1;
+ size_t i;
+ int last_suite_printed = -1;
+ sigset_t set, oldset;
+
+ sigemptyset(&set);
+ sigaddset(&set, SIGINT);
+ sigaddset(&set, SIGTERM);
+
+ pthread_sigmask(SIG_BLOCK, &set, &oldset);
+ global_pfds = calloc(num_tests, sizeof(*pfds));
+ global_pfd_indices = calloc(num_tests, sizeof(*pfd_indices));
+ pfds = global_pfds;
+ pfd_indices = global_pfd_indices;
+ if (!pfds || !pfd_indices) {
+ free(pfds);
+ free(pfd_indices);
+ global_pfds = NULL;
+ global_pfd_indices = NULL;
+ pthread_sigmask(SIG_SETMASK, &oldset, NULL);
+ return -ENOMEM;
+ }
+ pthread_sigmask(SIG_SETMASK, &oldset, NULL);
+
+ for (i = 0; i < num_tests; i++) {
+ struct child_test *child = child_tests[i];
+
+ if (!child)
+ continue;
+ strbuf_init(&child->err_output, 0);
+ if (child->process.err >= 0)
+ fcntl(child->process.err, F_SETFL, O_NONBLOCK);
+ }
+
+ while (next_to_print < num_tests) {
+ size_t running_count = 0;
+ size_t p;
+
+ while (next_to_print < num_tests &&
+ (!child_tests[next_to_print] || child_tests[next_to_print]->done))
+ next_to_print++;
+
+ if (next_to_print >= num_tests)
+ break;
+
+ num_pfds = 0;
+
+ for (i = next_to_print; i < num_tests; i++) {
+ struct child_test *child = child_tests[i];
+
+ if (!child || child->done)
+ continue;
+
+ if (!check_if_command_finished(&child->process))
+ running_count++;
+
+ if (child->process.err >= 0) {
+ pfds[num_pfds].fd = child->process.err;
+ pfds[num_pfds].events = POLLIN | POLLERR | POLLHUP | POLLNVAL;
+ pfd_indices[num_pfds] = i;
+ num_pfds++;
+ }
+ }
+
+ if (perf_use_color_default && running_count != (size_t)last_running) {
+ struct child_test *next_child = child_tests[next_to_print];
+
+ if (last_running != -1)
+ fprintf(debug_file(), PERF_COLOR_DELETE_LINE);
+
+ if (next_child) {
+ if (test_suite__num_test_cases(next_child->test) > 1 &&
+ last_suite_printed != next_child->suite_num) {
+ pr_info("%3d: %-*s:\n", next_child->suite_num + 1, width,
+ test_description(next_child->test, -1));
+ last_suite_printed = next_child->suite_num;
+ }
+ print_test_result(next_child->test, next_child->suite_num,
+ next_child->test_case_num, TEST_RUNNING, width,
+ running_count);
+ }
+ last_running = running_count;
+ }
+
+ if (num_pfds == 0) {
+ if (running_count > 0)
+ usleep(10 * 1000);
+ } else {
+ int pret = poll(pfds, num_pfds, 100);
+
+ if (pret > 0) {
+ for (p = 0; p < num_pfds; p++) {
+ size_t idx = pfd_indices[p];
+
+ handle_child_pipe_activity(child_tests[idx],
+ pfds[p].revents);
+ }
+ }
+ }
+
+ for (i = next_to_print; i < num_tests; i++) {
+ struct child_test *child = child_tests[i];
+
+ if (!child || child->done)
+ continue;
+
+ if (check_if_command_finished(&child->process)) {
+ if (child->process.err >= 0) {
+ drain_child_process_err(child);
+ close(child->process.err);
+ child->process.err = -1;
+ }
+ child->result = finish_command(&child->process);
+ child->process.pid = 0;
+ child->done = true;
+ }
+ }
+
+ while (next_to_print < num_tests) {
+ struct child_test *child = child_tests[next_to_print];
+
+ if (!child) {
+ next_to_print++;
+ continue;
+ }
+ if (!child->done)
+ break;
+
+ if (perf_use_color_default && last_running != -1) {
+ fprintf(debug_file(), PERF_COLOR_DELETE_LINE);
+ last_running = -1;
+ }
+
+ if (test_suite__num_test_cases(child->test) > 1 &&
+ last_suite_printed != child->suite_num) {
+ pr_info("%3d: %-*s:\n", child->suite_num + 1, width,
+ test_description(child->test, -1));
+ last_suite_printed = child->suite_num;
+ }
+
+ if (verbose > 1) {
+ if (test_suite__num_test_cases(child->test) > 1) {
+ pr_info("%3d.%1d: %s:\n", child->suite_num + 1,
+ child->test_case_num + 1,
+ test_description(child->test,
+ child->test_case_num));
+ } else {
+ pr_info("%3d: %s:\n", child->suite_num + 1,
+ test_description(child->test, -1));
+ }
+ }
+
+ if (verbose > 1 || (verbose == 1 && child->result == TEST_FAIL))
+ fprintf(stderr, "%s", child->err_output.buf);
+
+ print_test_result(child->test, child->suite_num, child->test_case_num,
+ child->result, width, 0);
+ pthread_sigmask(SIG_BLOCK, &set, &oldset);
+ strbuf_release(&child->err_output);
+ child_tests[next_to_print] = NULL;
+ zfree(&child);
+ pthread_sigmask(SIG_SETMASK, &oldset, NULL);
+ next_to_print++;
+ }
+ }
+
+ pthread_sigmask(SIG_BLOCK, &set, &oldset);
+ free(global_pfds);
+ free(global_pfd_indices);
+ global_pfds = NULL;
+ global_pfd_indices = NULL;
+ pthread_sigmask(SIG_SETMASK, &oldset, NULL);
+ return 0;
+}
+
static int start_test(struct test_suite *test, int curr_suite, int curr_test_case,
struct child_test **child, int width, int pass)
{
@@ -535,13 +780,14 @@ static int start_test(struct test_suite *test, int curr_suite, int curr_test_cas
(*child)->test_case_num = curr_test_case;
(*child)->process.pid = -1;
(*child)->process.no_stdin = 1;
+ (*child)->process.in = -1;
+ (*child)->process.out = -1;
+ (*child)->process.err = -1;
if (verbose <= 0) {
(*child)->process.no_stdout = 1;
(*child)->process.no_stderr = 1;
} else {
(*child)->process.stdout_to_stderr = 1;
- (*child)->process.out = -1;
- (*child)->process.err = -1;
}
(*child)->process.no_exec_cmd = run_test_child;
if (sequential || pass == 2) {
@@ -664,8 +910,9 @@ static int __cmd_test(struct test_suite **suites, int argc, const char *argv[],
}
if (!sequential) {
/* Parallel mode starts tests but doesn't finish them. Do that now. */
- for (size_t x = 0; x < num_tests; x++)
- finish_test(child_tests, x, num_tests, width);
+ err = finish_tests_parallel(child_tests, num_tests, width);
+ if (err)
+ goto err_out;
}
}
err_out:
@@ -676,6 +923,10 @@ static int __cmd_test(struct test_suite **suites, int argc, const char *argv[],
for (size_t x = 0; x < num_tests; x++)
finish_test(child_tests, x, num_tests, width);
}
+ free(global_pfds);
+ free(global_pfd_indices);
+ global_pfds = NULL;
+ global_pfd_indices = NULL;
free(child_tests);
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0150/1518] perf test: Show snippet failure output for verbose=1
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (148 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0149/1518] perf test: Refactor parallel poll loop to drain all pipes simultaneously Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0151/1518] perf test: Add summary reporting Greg Kroah-Hartman
` (848 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ian Rogers, Adrian Hunter,
Alexander Shishkin, Ingo Molnar, James Clark, Jiri Olsa,
Namhyung Kim, Peter Zijlstra, Arnaldo Carvalho de Melo,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ian Rogers <irogers@google.com>
[ Upstream commit b5a4a361f5cfb8f6f6f0a59536fd5fad11ed9f5f ]
Currently, when running tests in verbose mode (-v), if a test case
fails, the entire raw standard error buffer is dumped to stderr via
fprintf(stderr, "%s", child->err_output.buf). For tests that generate
massive amounts of debugging or logging output before dying, this
results in multi-page terminal dumps where highly critical diagnostic
keywords (error, fail, segv) are easily lost.
Implement a smart, bounded snippet string processor to improve
failure triaging:
1. Introduce a configurable quota limit static unsigned int
failure_snippet_lines = 10; accessible via a new command-line option
--failure-snippet-lines <N>.
2. Parse the raw error buffer dynamically into lines and run a
three-pass extraction algorithm:
- Pass 0: Always select the very first line of the log as an initial
outline marker.
- Pass 1: Scan forward from the top of the log to pick up to N lines
that contain case-insensitive failure keywords (error, fail,
segv, abort) to isolate the root cause. Automatically pull in
the immediate subsequent line as highly-prioritized context.
Allow adjacent matching lines to overlap without dropping context
by evaluating keywords for all lines (e.g. when "Failed to
report" is followed by "Error:").
- Pass 2: If quota remains, scan backward from the absolute tail of
the log to capture trailing crash or abort context.
3. Output the selected lines in their original chronological order,
inserting a clear ... separator between non-contiguous line jumps.
4. Wrap matched failure keywords dynamically in bold red
(PERF_COLOR_RED) to immediately draw the eye to failures.
5. Invoke the smart processor purely when verbose == 1 && ret ==
TEST_FAIL in both finish_test and finish_tests_parallel, leaving
raw full-output dumping completely untouched when running highly
verbose (-vv).
Assisted-by: Gemini-CLI:Google Gemini 3
Signed-off-by: Ian Rogers <irogers@google.com>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Cc: Alexander Shishkin <alexander.shishkin@linux.intel.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: James Clark <james.clark@linaro.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Stable-dep-of: 32e6312f7e39 ("perf test: Truncate test description to fit terminal width")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/tests/builtin-test.c | 203 +++++++++++++++++++++++++++++++-
1 file changed, 200 insertions(+), 3 deletions(-)
diff --git a/tools/perf/tests/builtin-test.c b/tools/perf/tests/builtin-test.c
index 552aa898fc70d..626d1b328b2f2 100644
--- a/tools/perf/tests/builtin-test.c
+++ b/tools/perf/tests/builtin-test.c
@@ -48,6 +48,8 @@ static bool dont_fork;
static bool sequential;
/* Number of times each test is run. */
static unsigned int runs_per_test = 1;
+/* Number of lines to include in failure snippet. */
+static unsigned int failure_snippet_lines = 10;
const char *dso_to_test;
const char *test_objdump_path = "objdump";
@@ -337,7 +339,7 @@ static int run_test_child(struct child_process *process)
for (size_t i = 0; i < ARRAY_SIZE(signals); i++)
signal(signals[i], child_test_sig_handler);
- pr_debug("--- start ---\n");
+ pr_debug("---- start ----\n");
pr_debug("test child forked, pid %d\n", getpid());
err = test_function(child->test, child->test_case_num)(child->test, child->test_case_num);
pr_debug("---- end(%d) ----\n", err);
@@ -393,6 +395,195 @@ static int print_test_result(struct test_suite *t, int curr_suite, int curr_test
return 0;
}
+static const char * const fail_keywords[] = {
+ "error", "fail", "segv", "abort",
+ "signal", "fatal", "panic", "corrupt", NULL
+};
+
+static const char *find_next_keyword(const char *str, size_t max_len, size_t *kw_len)
+{
+ const char *best = NULL;
+ size_t best_len = 0;
+ int k;
+
+ for (k = 0; fail_keywords[k]; k++) {
+ const char *s = str;
+ size_t len = strlen(fail_keywords[k]);
+
+ while ((size_t)(s - str) + len <= max_len) {
+ size_t i;
+
+ if (best && s >= best)
+ break;
+
+ for (i = 0; i < len; i++) {
+ if (tolower(s[i]) != fail_keywords[k][i])
+ break;
+ }
+ if (i == len) {
+ if (!best || s < best) {
+ best = s;
+ best_len = len;
+ }
+ break;
+ }
+ s++;
+ }
+ }
+ if (best) {
+ *kw_len = best_len;
+ return best;
+ }
+ return NULL;
+}
+
+static void print_line_highlighted(FILE *fp, const char *line, size_t len)
+{
+ const char *s = line;
+
+ while (len > 0) {
+ size_t kw_len = 0;
+ const char *match = find_next_keyword(s, len, &kw_len);
+
+ if (!match) {
+ fwrite(s, 1, len, fp);
+ break;
+ }
+ if (match > s)
+ fwrite(s, 1, match - s, fp);
+ if (perf_use_color_default)
+ fprintf(fp, "%s", PERF_COLOR_RED);
+ fwrite(match, 1, kw_len, fp);
+ if (perf_use_color_default)
+ fprintf(fp, "%s", PERF_COLOR_RESET);
+
+ len -= (match + kw_len) - s;
+ s = match + kw_len;
+ }
+}
+
+
+static void print_test_failure_snippet(FILE *fp, const char *buf)
+{
+ size_t num_lines = 0;
+ size_t max_lines = 128;
+ const char **lines = calloc(max_lines, sizeof(const char *));
+ size_t *line_lens = calloc(max_lines, sizeof(size_t));
+ const char *s = buf;
+ size_t i;
+ unsigned int picked_count = 0;
+ bool *pick;
+ int last_printed = -1;
+
+ if (!lines || !line_lens) {
+ free(lines); free(line_lens);
+ fprintf(fp, "%s", buf);
+ return;
+ }
+
+ while (*s) {
+ const char *eol = strchr(s, '\n');
+ size_t len;
+
+ if (eol)
+ len = eol - s + 1;
+ else
+ len = strlen(s);
+
+ if (num_lines == max_lines) {
+ const char **new_lines;
+ size_t *new_lens;
+
+ max_lines *= 2;
+ new_lines = realloc(lines, max_lines * sizeof(const char *));
+ if (!new_lines) {
+ free(lines); free(line_lens);
+ fprintf(fp, "%s", buf);
+ return;
+ }
+ lines = new_lines;
+
+ new_lens = realloc(line_lens, max_lines * sizeof(size_t));
+ if (!new_lens) {
+ free(lines); free(line_lens);
+ fprintf(fp, "%s", buf);
+ return;
+ }
+ line_lens = new_lens;
+ }
+ lines[num_lines] = s;
+ line_lens[num_lines] = len;
+ num_lines++;
+ s += len;
+ }
+
+ if (num_lines <= failure_snippet_lines) {
+ for (i = 0; i < num_lines; i++)
+ print_line_highlighted(fp, lines[i], line_lens[i]);
+ free(lines); free(line_lens);
+ return;
+ }
+
+ pick = calloc(num_lines, sizeof(bool));
+ if (!pick) {
+ for (i = 0; i < num_lines; i++)
+ print_line_highlighted(fp, lines[i], line_lens[i]);
+ free(lines); free(line_lens);
+ return;
+ }
+
+ /* Pass 0: Always pick the very first line */
+ if (num_lines > 0 && picked_count < failure_snippet_lines) {
+ pick[0] = true;
+ picked_count++;
+ }
+
+ /* Pass 1: Pick lines with failure keywords from start (Highest Priority) */
+ for (i = 0; i < num_lines && picked_count < failure_snippet_lines; i++) {
+ size_t dummy;
+
+ if (find_next_keyword(lines[i], line_lens[i], &dummy)) {
+ if (!pick[i]) {
+ pick[i] = true;
+ picked_count++;
+ }
+ /* Prioritize getting the immediate next line for context */
+ if (i + 1 < num_lines && !pick[i + 1] &&
+ picked_count < failure_snippet_lines) {
+ pick[i + 1] = true;
+ picked_count++;
+ }
+ }
+ }
+
+ /* Pass 2: Fill remaining quota from the end backwards */
+ i = num_lines;
+ while (i > 0 && picked_count < failure_snippet_lines) {
+ i--;
+ if (!pick[i]) {
+ pick[i] = true;
+ picked_count++;
+ }
+ }
+
+ for (i = 0; i < num_lines; i++) {
+ if (!pick[i])
+ continue;
+ if (last_printed != -1 && (int)i > last_printed + 1) {
+ if (perf_use_color_default)
+ fprintf(fp, "%s...%s\n", PERF_COLOR_BLUE, PERF_COLOR_RESET);
+ else
+ fprintf(fp, "...\n");
+ }
+ print_line_highlighted(fp, lines[i], line_lens[i]);
+ last_printed = i;
+ }
+
+ free(pick);
+ free(lines);
+ free(line_lens);
+}
+
static void finish_test(struct child_test **child_tests, int running_test, int child_test_num,
int width)
{
@@ -511,8 +702,10 @@ static void finish_test(struct child_test **child_tests, int running_test, int c
strbuf_release(&err_output);
err_output = merged;
}
- if (verbose > 1 || (verbose == 1 && ret == TEST_FAIL))
+ if (verbose > 1)
fprintf(stderr, "%s", err_output.buf);
+ else if (verbose == 1 && ret == TEST_FAIL)
+ print_test_failure_snippet(stderr, err_output.buf);
strbuf_release(&err_output);
strbuf_release(&child_test->err_output);
@@ -724,8 +917,10 @@ static int finish_tests_parallel(struct child_test **child_tests, size_t num_tes
}
}
- if (verbose > 1 || (verbose == 1 && child->result == TEST_FAIL))
+ if (verbose > 1)
fprintf(stderr, "%s", child->err_output.buf);
+ else if (verbose == 1 && child->result == TEST_FAIL)
+ print_test_failure_snippet(stderr, child->err_output.buf);
print_test_result(child->test, child->suite_num, child->test_case_num,
child->result, width, 0);
@@ -1057,6 +1252,8 @@ int cmd_test(int argc, const char **argv)
OPT_STRING(0, "dso", &dso_to_test, "dso", "dso to test"),
OPT_STRING(0, "objdump", &test_objdump_path, "path",
"objdump binary to use for disassembly and annotations"),
+ OPT_UINTEGER(0, "failure-snippet-lines", &failure_snippet_lines,
+ "Number of lines to include in failure snippet, default 10"),
OPT_END()
};
const char * const test_subcommands[] = { "list", NULL };
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0151/1518] perf test: Add summary reporting
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (149 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0150/1518] perf test: Show snippet failure output for verbose=1 Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0152/1518] perf test: Fix subtest status alignment for multi-digit indexes Greg Kroah-Hartman
` (847 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ian Rogers, Adrian Hunter,
Alexander Shishkin, Ingo Molnar, James Clark, Jiri Olsa,
Namhyung Kim, Peter Zijlstra, Arnaldo Carvalho de Melo,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ian Rogers <irogers@google.com>
[ Upstream commit 33f20342ba525ef75fd9734db71e9823fe65e769 ]
Currently, when running test suites (perf test), users must scroll
through hundreds of lines of console output to manually tally the number
of passed, skipped, or failed test cases.
Introduce an automated, global execution summary printed at the absolute
tail of the test run:
1. Track counts mid-flight inside the print_test_result() accumulator,
clearly separating pass counts into standalone main tests vs.
individual subtests (where num_test_cases > 1).
2. Accumulate the precise descriptions of all failed test cases
directly into a global string buffer, formatted with their suite
indices (e.g., 3.1: Parse event definition strings) for effortless
cross-referencing.
3. Define a summary printer function print_tests_summary() that
emits a colored outline of the final pass, skip, and fail totals,
followed by the explicit list of failed tests.
4. Invoke the summary printer right before freeing the test array at
the absolute tail of __cmd_test(), guaranteeing that the summary is
successfully printed even if an internal emergency signal cleanup
occurs or if the user interrupts the run early.
Example output:
```
$ sudo perf test -v
1: vmlinux symtab matches kallsyms : Skip
2: Detect openat syscall event : Ok
3: Detect openat syscall event on all cpus : Ok
...
163: perf trace summary : Ok
=== Test Summary ===
Passed main tests : 123
Passed subtests : 145
Skipped tests : 22
Failed tests : 6
List of failed tests:
92: perf kvm tests
95: kernel lock contention analysis test
120: perf metrics value validation
124: Check branch stack sampling
143: perftool-testsuite_probe
158: test Intel TPEBS counting mode
```
Assisted-by: Gemini-CLI:Google Gemini 3
Signed-off-by: Ian Rogers <irogers@google.com>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Cc: Alexander Shishkin <alexander.shishkin@linux.intel.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: James Clark <james.clark@linaro.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Stable-dep-of: 32e6312f7e39 ("perf test: Truncate test description to fit terminal width")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/tests/builtin-test.c | 89 +++++++++++++++++++++++++++++++--
1 file changed, 86 insertions(+), 3 deletions(-)
diff --git a/tools/perf/tests/builtin-test.c b/tools/perf/tests/builtin-test.c
index 626d1b328b2f2..13c4dfa5d512a 100644
--- a/tools/perf/tests/builtin-test.c
+++ b/tools/perf/tests/builtin-test.c
@@ -356,8 +356,14 @@ static int run_test_child(struct child_process *process)
static struct pollfd *global_pfds;
static size_t *global_pfd_indices;
+static unsigned int summary_tests_passed;
+static unsigned int summary_subtests_passed;
+static unsigned int summary_tests_skipped;
+static unsigned int summary_tests_failed;
+static struct strbuf summary_failed_tests_buf = STRBUF_INIT;
static int strbuf_addstr_safe(struct strbuf *sb, const char *s);
+static int __printf(2, 3) strbuf_addf_safe(struct strbuf *sb, const char *fmt, ...);
static int print_test_result(struct test_suite *t, int curr_suite, int curr_test_case,
int result, int width, int running)
@@ -375,11 +381,16 @@ static int print_test_result(struct test_suite *t, int curr_suite, int curr_test
color_fprintf(stderr, PERF_COLOR_YELLOW, " Running (%d active)\n", running);
break;
case TEST_OK:
+ if (test_suite__num_test_cases(t) > 1)
+ summary_subtests_passed++;
+ else
+ summary_tests_passed++;
pr_info(" Ok\n");
break;
case TEST_SKIP: {
const char *reason = skip_reason(t, curr_test_case);
+ summary_tests_skipped++;
if (reason)
color_fprintf(stderr, PERF_COLOR_YELLOW, " Skip (%s)\n", reason);
else
@@ -388,6 +399,15 @@ static int print_test_result(struct test_suite *t, int curr_suite, int curr_test
break;
case TEST_FAIL:
default:
+ summary_tests_failed++;
+ if (test_suite__num_test_cases(t) > 1)
+ strbuf_addf_safe(&summary_failed_tests_buf, " %3d.%1d: %s\n",
+ curr_suite + 1, curr_test_case + 1,
+ test_description(t, curr_test_case));
+ else
+ strbuf_addf_safe(&summary_failed_tests_buf, " %3d: %s\n",
+ curr_suite + 1,
+ test_description(t, curr_test_case));
color_fprintf(stderr, PERF_COLOR_RED, " FAILED!\n");
break;
}
@@ -729,6 +749,47 @@ static int strbuf_addstr_safe(struct strbuf *sb, const char *s)
return ret;
}
+static int __printf(2, 3) strbuf_addf_safe(struct strbuf *sb, const char *fmt, ...)
+{
+ char buf[1024];
+ va_list ap;
+ int len;
+ sigset_t set, oldset;
+ int ret;
+
+ sigemptyset(&set);
+ sigaddset(&set, SIGINT);
+ sigaddset(&set, SIGTERM);
+ sigprocmask(SIG_BLOCK, &set, &oldset);
+
+ va_start(ap, fmt);
+ len = vsnprintf(buf, sizeof(buf), fmt, ap);
+ va_end(ap);
+
+ if (len < 0) {
+ sigprocmask(SIG_SETMASK, &oldset, NULL);
+ return len;
+ }
+ if ((size_t)len >= sizeof(buf)) {
+ char *dynamic_buf = malloc(len + 1);
+
+ if (!dynamic_buf) {
+ sigprocmask(SIG_SETMASK, &oldset, NULL);
+ return -ENOMEM;
+ }
+ va_start(ap, fmt);
+ vsnprintf(dynamic_buf, len + 1, fmt, ap);
+ va_end(ap);
+ ret = strbuf_addstr(sb, dynamic_buf);
+ free(dynamic_buf);
+ } else {
+ ret = strbuf_addstr(sb, buf);
+ }
+
+ sigprocmask(SIG_SETMASK, &oldset, NULL);
+ return ret;
+}
+
static void drain_child_process_err(struct child_test *child)
{
char buf[512];
@@ -1006,6 +1067,23 @@ static void cmd_test_sig_handler(int sig)
siglongjmp(cmd_test_jmp_buf, sig);
}
+static void print_tests_summary(void)
+{
+ pr_info("\n=== Test Summary ===\n");
+ pr_info("Passed main tests : %u\n", summary_tests_passed);
+ pr_info("Passed subtests : %u\n", summary_subtests_passed);
+ pr_info("Skipped tests : %u\n", summary_tests_skipped);
+ if (summary_tests_failed > 0) {
+ color_fprintf(stderr, PERF_COLOR_RED, "Failed tests : %u\n",
+ summary_tests_failed);
+ pr_info("List of failed tests:\n");
+ pr_info("%s", summary_failed_tests_buf.buf);
+ } else {
+ color_fprintf(stderr, PERF_COLOR_GREEN, "Failed tests : 0\n");
+ }
+ strbuf_release(&summary_failed_tests_buf);
+}
+
static int __cmd_test(struct test_suite **suites, int argc, const char *argv[],
struct intlist *skiplist)
{
@@ -1083,9 +1161,13 @@ static int __cmd_test(struct test_suite **suites, int argc, const char *argv[],
}
if (intlist__find(skiplist, curr_suite + 1)) {
- pr_info("%3d: %-*s:", curr_suite + 1, width,
- test_description(*t, -1));
- color_fprintf(stderr, PERF_COLOR_YELLOW, " Skip (user override)\n");
+ if (pass == 1) {
+ pr_info("%3d: %-*s:", curr_suite + 1, width,
+ test_description(*t, -1));
+ color_fprintf(stderr, PERF_COLOR_YELLOW,
+ " Skip (user override)\n");
+ summary_tests_skipped++;
+ }
continue;
}
@@ -1118,6 +1200,7 @@ static int __cmd_test(struct test_suite **suites, int argc, const char *argv[],
for (size_t x = 0; x < num_tests; x++)
finish_test(child_tests, x, num_tests, width);
}
+ print_tests_summary();
free(global_pfds);
free(global_pfd_indices);
global_pfds = NULL;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0152/1518] perf test: Fix subtest status alignment for multi-digit indexes
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (150 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0151/1518] perf test: Add summary reporting Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0153/1518] perf test: Add -j/--junit option for JUnit XML test reports Greg Kroah-Hartman
` (846 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ian Rogers, Arnaldo Carvalho de Melo,
Adrian Hunter, Alexander Shishkin, Ingo Molnar, James Clark,
Jiri Olsa, Namhyung Kim, Peter Zijlstra, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ian Rogers <irogers@google.com>
[ Upstream commit 94ac3ce427c8f80d699909c85a7cb70a589c562d ]
When running perf test, the status column (: Ok) became misaligned when
subtest indexes reached 2 or 3 digits (e.g. 9.100 vs 9.9 vs 10.1). This
occurred because the subtest description field width (subw) was
statically fixed to width - 2, assuming all subtest index prefixes were
exactly 7 characters wide.
Dynamically calculate subw based on the exact character length of the
test suite and subtest index prefix. This ensures the status column is
perfectly aligned vertically across all test outputs regardless of
subtest index digit count.
Assisted-by: Gemini-CLI:Google Gemini 3
Signed-off-by: Ian Rogers <irogers@google.com>
Tested-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Cc: Alexander Shishkin <alexander.shishkin@linux.intel.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: James Clark <james.clark@linaro.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Stable-dep-of: 32e6312f7e39 ("perf test: Truncate test description to fit terminal width")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/tests/builtin-test.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
diff --git a/tools/perf/tests/builtin-test.c b/tools/perf/tests/builtin-test.c
index 13c4dfa5d512a..afd4301aca715 100644
--- a/tools/perf/tests/builtin-test.c
+++ b/tools/perf/tests/builtin-test.c
@@ -369,10 +369,12 @@ static int print_test_result(struct test_suite *t, int curr_suite, int curr_test
int result, int width, int running)
{
if (test_suite__num_test_cases(t) > 1) {
- int subw = width > 2 ? width - 2 : width;
+ char prefix[32];
+ int len = snprintf(prefix, sizeof(prefix), "%3d.%1d:",
+ curr_suite + 1, curr_test_case + 1);
+ int subw = len >= 4 ? width + 4 - len : width;
- pr_info("%3d.%1d: %-*s:", curr_suite + 1, curr_test_case + 1, subw,
- test_description(t, curr_test_case));
+ pr_info("%s %-*s:", prefix, subw, test_description(t, curr_test_case));
} else
pr_info("%3d: %-*s:", curr_suite + 1, width, test_description(t, curr_test_case));
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0153/1518] perf test: Add -j/--junit option for JUnit XML test reports
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (151 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0152/1518] perf test: Fix subtest status alignment for multi-digit indexes Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0154/1518] perf test: Truncate printed test descriptions dynamically to avoid terminal wrapping Greg Kroah-Hartman
` (845 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ian Rogers, Arnaldo Carvalho de Melo,
Adrian Hunter, Alexander Shishkin, Ingo Molnar, James Clark,
Jiri Olsa, Namhyung Kim, Peter Zijlstra, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ian Rogers <irogers@google.com>
[ Upstream commit e2c545737bf4387d1217d3608274823421e1dbf2 ]
Add a -j/--junit command line option to generate standard JUnit XML
format test reports. The generated file defaults to 'test.xml' if no
filename is specified, but allows users to override the path (e.g.
-jmytest.xml).
The XML report captures individual test suite and subtest execution
latency, alongside XML-escaped failure logs and skip reasons, while
preserving the full multi-process concurrency speed of parallel test
execution.
Assisted-by: Gemini-CLI:Google Gemini 3
Signed-off-by: Ian Rogers <irogers@google.com>
Tested-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Cc: Alexander Shishkin <alexander.shishkin@linux.intel.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: James Clark <james.clark@linaro.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Link: https://lore.kernel.org/r/20260602174129.3192312-15-irogers@google.com
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Stable-dep-of: 32e6312f7e39 ("perf test: Truncate test description to fit terminal width")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/tests/builtin-test.c | 148 ++++++++++++++++++++++++++++++--
1 file changed, 142 insertions(+), 6 deletions(-)
diff --git a/tools/perf/tests/builtin-test.c b/tools/perf/tests/builtin-test.c
index afd4301aca715..9f262a4c93a22 100644
--- a/tools/perf/tests/builtin-test.c
+++ b/tools/perf/tests/builtin-test.c
@@ -19,6 +19,7 @@
#include <dirent.h>
#include <sys/wait.h>
#include <sys/stat.h>
+#include <sys/time.h>
#include "builtin.h"
#include "config.h"
#include "hist.h"
@@ -39,6 +40,9 @@
#include "tests-scripts.h"
+static const char *junit_filename;
+static struct strbuf junit_xml_buf = STRBUF_INIT;
+
/*
* Command line option to not fork the test running in the same process and
* making them easier to debug.
@@ -300,6 +304,8 @@ struct child_test {
struct strbuf err_output;
int result;
bool done;
+ struct timespec start_time;
+ struct timespec end_time;
};
static jmp_buf run_test_jmp_buf;
@@ -365,8 +371,34 @@ static struct strbuf summary_failed_tests_buf = STRBUF_INIT;
static int strbuf_addstr_safe(struct strbuf *sb, const char *s);
static int __printf(2, 3) strbuf_addf_safe(struct strbuf *sb, const char *fmt, ...);
+static char *xml_escape(const char *str)
+{
+ struct strbuf buf = STRBUF_INIT;
+ const char *p;
+ char *res;
+
+ if (!str)
+ return strdup("");
+
+ for (p = str; *p; p++) {
+ if (*p == '&')
+ strbuf_addstr(&buf, "&");
+ else if (*p == '<')
+ strbuf_addstr(&buf, "<");
+ else if (*p == '>')
+ strbuf_addstr(&buf, ">");
+ else if (*p == '"')
+ strbuf_addstr(&buf, """);
+ else if ((unsigned char)*p >= 32 || *p == '\n' || *p == '\t')
+ strbuf_addch(&buf, *p);
+ }
+ res = strbuf_detach(&buf, NULL);
+ return res ? res : strdup("");
+}
+
static int print_test_result(struct test_suite *t, int curr_suite, int curr_test_case,
- int result, int width, int running)
+ int result, int width, int running,
+ const char *err_output, double elapsed)
{
if (test_suite__num_test_cases(t) > 1) {
char prefix[32];
@@ -414,6 +446,34 @@ static int print_test_result(struct test_suite *t, int curr_suite, int curr_test
break;
}
+ if (junit_filename && result != TEST_RUNNING) {
+ const char *classname = t->desc;
+ const char *testname = test_description(t, curr_test_case);
+ char *escaped_err = xml_escape(err_output);
+ char *escaped_class = xml_escape(classname);
+ char *escaped_test = xml_escape(testname);
+
+ strbuf_addf(&junit_xml_buf,
+ " <testcase classname=\"%s\" name=\"%s\" time=\"%.2f\">\n",
+ escaped_class, escaped_test, elapsed);
+ if (result != TEST_OK && result != TEST_SKIP) {
+ strbuf_addf(&junit_xml_buf,
+ " <failure message=\"FAILED\">\n%s\n </failure>\n",
+ escaped_err);
+ } else if (result == TEST_SKIP) {
+ const char *reason = skip_reason(t, curr_test_case);
+ char *escaped_reason = xml_escape(reason ? reason : "Skip");
+
+ strbuf_addf(&junit_xml_buf, " <skipped message=\"%s\"/>\n",
+ escaped_reason);
+ free(escaped_reason);
+ }
+ strbuf_addstr(&junit_xml_buf, " </testcase>\n");
+ free(escaped_err);
+ free(escaped_class);
+ free(escaped_test);
+ }
+
return 0;
}
@@ -616,6 +676,8 @@ static void finish_test(struct child_test **child_tests, int running_test, int c
struct strbuf err_output = STRBUF_INIT;
int last_running = -1;
int ret;
+ struct timespec end_time;
+ double elapsed;
if (child_test == NULL) {
/* Test wasn't started. */
@@ -669,7 +731,7 @@ static void finish_test(struct child_test **child_tests, int running_test, int c
fprintf(debug_file(), PERF_COLOR_DELETE_LINE);
}
print_test_result(t, curr_suite, curr_test_case, TEST_RUNNING,
- width, running);
+ width, running, NULL, 0.0);
last_running = running;
}
}
@@ -729,9 +791,14 @@ static void finish_test(struct child_test **child_tests, int running_test, int c
else if (verbose == 1 && ret == TEST_FAIL)
print_test_failure_snippet(stderr, err_output.buf);
+ clock_gettime(CLOCK_MONOTONIC, &end_time);
+ elapsed = (end_time.tv_sec - child_test->start_time.tv_sec) +
+ (end_time.tv_nsec - child_test->start_time.tv_nsec) / 1000000000.0;
+
+ print_test_result(t, curr_suite, curr_test_case, ret, width, /*running=*/0,
+ err_output.buf, elapsed);
strbuf_release(&err_output);
strbuf_release(&child_test->err_output);
- print_test_result(t, curr_suite, curr_test_case, ret, width, /*running=*/0);
if (err > 0)
close(err);
zfree(&child_tests[running_test]);
@@ -907,7 +974,7 @@ static int finish_tests_parallel(struct child_test **child_tests, size_t num_tes
}
print_test_result(next_child->test, next_child->suite_num,
next_child->test_case_num, TEST_RUNNING, width,
- running_count);
+ running_count, NULL, 0.0);
}
last_running = running_count;
}
@@ -942,12 +1009,14 @@ static int finish_tests_parallel(struct child_test **child_tests, size_t num_tes
}
child->result = finish_command(&child->process);
child->process.pid = 0;
+ clock_gettime(CLOCK_MONOTONIC, &child->end_time);
child->done = true;
}
}
while (next_to_print < num_tests) {
struct child_test *child = child_tests[next_to_print];
+ double elapsed;
if (!child) {
next_to_print++;
@@ -985,8 +1054,12 @@ static int finish_tests_parallel(struct child_test **child_tests, size_t num_tes
else if (verbose == 1 && child->result == TEST_FAIL)
print_test_failure_snippet(stderr, child->err_output.buf);
+ elapsed = (child->end_time.tv_sec - child->start_time.tv_sec) +
+ (child->end_time.tv_nsec -
+ child->start_time.tv_nsec) / 1000000000.0;
+
print_test_result(child->test, child->suite_num, child->test_case_num,
- child->result, width, 0);
+ child->result, width, 0, child->err_output.buf, elapsed);
pthread_sigmask(SIG_BLOCK, &set, &oldset);
strbuf_release(&child->err_output);
child_tests[next_to_print] = NULL;
@@ -1013,11 +1086,18 @@ static int start_test(struct test_suite *test, int curr_suite, int curr_test_cas
*child = NULL;
if (dont_fork) {
if (pass == 1) {
+ struct timespec start_time, end_time;
+ double elapsed;
+
+ clock_gettime(CLOCK_MONOTONIC, &start_time);
pr_debug("--- start ---\n");
err = test_function(test, curr_test_case)(test, curr_test_case);
pr_debug("---- end ----\n");
+ clock_gettime(CLOCK_MONOTONIC, &end_time);
+ elapsed = (end_time.tv_sec - start_time.tv_sec) +
+ (end_time.tv_nsec - start_time.tv_nsec) / 1000000000.0;
print_test_result(test, curr_suite, curr_test_case, err, width,
- /*running=*/0);
+ /*running=*/0, NULL, elapsed);
}
return 0;
}
@@ -1083,6 +1163,41 @@ static void print_tests_summary(void)
} else {
color_fprintf(stderr, PERF_COLOR_GREEN, "Failed tests : 0\n");
}
+
+ if (junit_filename) {
+ int fd;
+ FILE *fp;
+
+ fd = open(junit_filename, O_CREAT | O_TRUNC | O_WRONLY | O_NOFOLLOW, 0644);
+ if (fd >= 0) {
+ fp = fdopen(fd, "w");
+ if (fp) {
+ unsigned int total = summary_tests_passed +
+ summary_subtests_passed +
+ summary_tests_skipped +
+ summary_tests_failed;
+ fprintf(fp, "<?xml version=\"1.0\" encoding=\"utf-8\"?>\n");
+ fprintf(fp, "<testsuites>\n");
+ fprintf(fp,
+ " <testsuite name=\"perf-tests\" tests=\"%u\" failures=\"%u\" skipped=\"%u\">\n",
+ total, summary_tests_failed,
+ summary_tests_skipped);
+ fprintf(fp, "%s", junit_xml_buf.buf);
+ fprintf(fp, " </testsuite>\n");
+ fprintf(fp, "</testsuites>\n");
+ fclose(fp);
+ pr_info("Wrote junit XML output to %s\n", junit_filename);
+ } else {
+ close(fd);
+ pr_err("Failed to associate stream with fd for %s: %s\n",
+ junit_filename, strerror(errno));
+ }
+ } else {
+ pr_err("Failed to open %s for writing junit XML output: %s\n",
+ junit_filename, strerror(errno));
+ }
+ }
+ strbuf_release(&junit_xml_buf);
strbuf_release(&summary_failed_tests_buf);
}
@@ -1169,6 +1284,25 @@ static int __cmd_test(struct test_suite **suites, int argc, const char *argv[],
color_fprintf(stderr, PERF_COLOR_YELLOW,
" Skip (user override)\n");
summary_tests_skipped++;
+ if (junit_filename) {
+ char *escaped_class =
+ xml_escape((const char *)
+ test_description(*t, -1));
+ char *escaped_test = xml_escape("override");
+ char *escaped_reason =
+ xml_escape("user override");
+
+ strbuf_addf(&junit_xml_buf,
+ " <testcase classname=\"%s\" name=\"%s\" time=\"0.000\">\n",
+ escaped_class, escaped_test);
+ strbuf_addf(&junit_xml_buf,
+ " <skipped message=\"%s\"/>\n",
+ escaped_reason);
+ strbuf_addstr(&junit_xml_buf, " </testcase>\n");
+ free(escaped_reason);
+ free(escaped_test);
+ free(escaped_class);
+ }
}
continue;
}
@@ -1339,6 +1473,8 @@ int cmd_test(int argc, const char **argv)
"objdump binary to use for disassembly and annotations"),
OPT_UINTEGER(0, "failure-snippet-lines", &failure_snippet_lines,
"Number of lines to include in failure snippet, default 10"),
+ OPT_STRING_OPTARG('j', "junit", &junit_filename, "file",
+ "Generate junit XML output, default test.xml", "test.xml"),
OPT_END()
};
const char * const test_subcommands[] = { "list", NULL };
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0154/1518] perf test: Truncate printed test descriptions dynamically to avoid terminal wrapping
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (152 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0153/1518] perf test: Add -j/--junit option for JUnit XML test reports Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0155/1518] perf test: Truncate test description to fit terminal width Greg Kroah-Hartman
` (844 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ian Rogers, Adrian Hunter,
Alexander Shishkin, Ingo Molnar, James Clark, Jiri Olsa,
Namhyung Kim, Peter Zijlstra, Arnaldo Carvalho de Melo,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ian Rogers <irogers@google.com>
[ Upstream commit 9e3fcab6fbecebbcffeafeb5db612a57688cb7f4 ]
When test descriptions are extremely long (e.g., the truncated perf.data
graceful handling test is 103 characters long), they wrap across terminal
boundaries.
Because the ANSI escape code to delete the line (PERF_COLOR_DELETE_LINE)
only clears a single terminal line, visual wrapping leaves orphan
wrapped lines on the screen, which results in the test description being
printed multiple times.
Resolve this by checking the terminal width (get_term_dimensions) and
dynamically truncating the printed test description to fit within the
available columns, leaving safety space for the prefix index and status
suffix.
Also, remove the width padding from the test suite headers which do not
display inline status messages. This prevents their trailing colons from
wrapping onto new lines on standard width terminals.
Finally, avoid GCC 16's -Wformat-truncation warnings by delegating the
description padding to pr_info's %-*s format specifier instead of padding
within a temporary buffer, and clamp the truncation limit to the temporary
buffer's size.
JUnit XML output and the failure summary report still print the full,
untruncated test descriptions.
Assisted-by: Gemini-CLI:Google Gemini 3.1 Pro
Signed-off-by: Ian Rogers <irogers@google.com>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Cc: Alexander Shishkin <alexander.shishkin@linux.intel.com>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: James Clark <james.clark@linaro.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Stable-dep-of: 32e6312f7e39 ("perf test: Truncate test description to fit terminal width")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/tests/builtin-test.c | 66 +++++++++++++++++++++++++++++----
1 file changed, 59 insertions(+), 7 deletions(-)
diff --git a/tools/perf/tests/builtin-test.c b/tools/perf/tests/builtin-test.c
index 9f262a4c93a22..8b98b352aa3b8 100644
--- a/tools/perf/tests/builtin-test.c
+++ b/tools/perf/tests/builtin-test.c
@@ -20,6 +20,8 @@
#include <sys/wait.h>
#include <sys/stat.h>
#include <sys/time.h>
+#include <sys/ioctl.h>
+#include "util/term.h"
#include "builtin.h"
#include "config.h"
#include "hist.h"
@@ -396,19 +398,69 @@ static char *xml_escape(const char *str)
return res ? res : strdup("");
}
+static const char *format_test_description(const char *desc, int max_desc_width,
+ char *buf, size_t buf_sz)
+{
+ int len = strlen(desc);
+
+ /*
+ * Clamp to buf_sz to prevent GCC format-truncation warnings
+ * when terminal width is very large.
+ */
+ if (max_desc_width >= (int)buf_sz)
+ max_desc_width = buf_sz - 1;
+
+ if (len > max_desc_width) {
+ snprintf(buf, buf_sz, "%.*s...", max_desc_width - 3, desc);
+ return buf;
+ }
+ return desc;
+}
+
static int print_test_result(struct test_suite *t, int curr_suite, int curr_test_case,
int result, int width, int running,
const char *err_output, double elapsed)
{
+ char desc_buf[256];
+ const char *desc = test_description(t, curr_test_case);
+ struct winsize ws;
+ int max_desc_area_width;
+ int target_desc_area_width;
+ int desc_padding;
+
+ get_term_dimensions(&ws);
+ /*
+ * Total terminal columns minus space for status e.g. " Running (12 active)"
+ * which is 20 chars, plus a margin of 3 chars = 23 chars.
+ */
+ max_desc_area_width = ws.ws_col - 23;
+ if (max_desc_area_width < 40)
+ max_desc_area_width = 40;
+
+ /* Standard test has prefix "%3d: " which is 5 chars */
+ target_desc_area_width = width + 5;
+ if (target_desc_area_width > max_desc_area_width)
+ target_desc_area_width = max_desc_area_width;
+
if (test_suite__num_test_cases(t) > 1) {
char prefix[32];
int len = snprintf(prefix, sizeof(prefix), "%3d.%1d:",
curr_suite + 1, curr_test_case + 1);
- int subw = len >= 4 ? width + 4 - len : width;
- pr_info("%s %-*s:", prefix, subw, test_description(t, curr_test_case));
- } else
- pr_info("%3d: %-*s:", curr_suite + 1, width, test_description(t, curr_test_case));
+ desc_padding = target_desc_area_width - (len + 1);
+ if (desc_padding < 20)
+ desc_padding = 20;
+
+ desc = format_test_description(desc, desc_padding, desc_buf, sizeof(desc_buf));
+ pr_info("%s %-*s:", prefix, desc_padding, desc);
+ } else {
+ desc_padding = target_desc_area_width - 5;
+ if (desc_padding < 20)
+ desc_padding = 20;
+
+ desc = format_test_description(desc, desc_padding, desc_buf, sizeof(desc_buf));
+ pr_info("%3d: %-*s:", curr_suite + 1, desc_padding, desc);
+ }
switch (result) {
case TEST_RUNNING:
@@ -692,7 +744,7 @@ static void finish_test(struct child_test **child_tests, int running_test, int c
* sub test names.
*/
if (test_suite__num_test_cases(t) > 1 && curr_test_case == 0)
- pr_info("%3d: %-*s:\n", curr_suite + 1, width, test_description(t, -1));
+ pr_info("%3d: %s:\n", curr_suite + 1, test_description(t, -1));
/*
* Busy loop reading from the child's stdout/stderr that are set to be
@@ -968,7 +1020,7 @@ static int finish_tests_parallel(struct child_test **child_tests, size_t num_tes
if (next_child) {
if (test_suite__num_test_cases(next_child->test) > 1 &&
last_suite_printed != next_child->suite_num) {
- pr_info("%3d: %-*s:\n", next_child->suite_num + 1, width,
+ pr_info("%3d: %s:\n", next_child->suite_num + 1,
test_description(next_child->test, -1));
last_suite_printed = next_child->suite_num;
}
@@ -1032,7 +1084,7 @@ static int finish_tests_parallel(struct child_test **child_tests, size_t num_tes
if (test_suite__num_test_cases(child->test) > 1 &&
last_suite_printed != child->suite_num) {
- pr_info("%3d: %-*s:\n", child->suite_num + 1, width,
+ pr_info("%3d: %s:\n", child->suite_num + 1,
test_description(child->test, -1));
last_suite_printed = child->suite_num;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0155/1518] perf test: Truncate test description to fit terminal width
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (153 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0154/1518] perf test: Truncate printed test descriptions dynamically to avoid terminal wrapping Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0156/1518] perf test metrics: Update all metrics for possibly failing default metrics Greg Kroah-Hartman
` (843 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ian Rogers, Namhyung Kim,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ian Rogers <irogers@google.com>
[ Upstream commit 32e6312f7e397bf0b731b43a6504966398af0788 ]
The parallel test harness uses the carriage return delete escape sequence
`PERF_COLOR_DELETE_LINE` ("\033[A\33[2K\r") to erase and update the
"Running (X active)" progress lines.
However, if a test description is longer than the terminal width, the line
wraps around. When this happens, the cursor up escape sequence `\033[A`
only moves the cursor to the last wrapped row, leaving the top half of the
description printed on the previous line. This leads to name duplication
and output corruption spilling over multiple rows on consoles narrower
than the maximum description length (e.g., 101 columns wide).
Fix this by dynamically querying the terminal width using
`get_term_dimensions` and truncating the printed test descriptions using
the `%-*.*s` printf format. We reserve 35 characters for prefix, status,
and spacing metrics to guarantee the progress line never wraps.
Fixes: 0e036dcad4e6 ("perf test: Display number of active running tests")
Assisted-by: Antigravity:gemini-3.1-pro
Signed-off-by: Ian Rogers <irogers@google.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/tests/builtin-test.c | 163 +++++++++++++++++---------------
1 file changed, 89 insertions(+), 74 deletions(-)
diff --git a/tools/perf/tests/builtin-test.c b/tools/perf/tests/builtin-test.c
index 8b98b352aa3b8..91d45768f0cac 100644
--- a/tools/perf/tests/builtin-test.c
+++ b/tools/perf/tests/builtin-test.c
@@ -10,37 +10,40 @@
#ifdef HAVE_BACKTRACE_SUPPORT
#include <execinfo.h>
#endif
-#include <poll.h>
-#include <unistd.h>
#include <setjmp.h>
-#include <string.h>
#include <stdlib.h>
-#include <sys/types.h>
+#include <string.h>
+
#include <dirent.h>
-#include <sys/wait.h>
+#include "util/term.h"
+#include <linux/kernel.h>
+#include <linux/string.h>
+#include <linux/zalloc.h>
+#include <poll.h>
+#include <sys/ioctl.h>
#include <sys/stat.h>
#include <sys/time.h>
-#include <sys/ioctl.h>
-#include "util/term.h"
+#include <sys/types.h>
+#include <sys/wait.h>
+#include <unistd.h>
+
+#include <subcmd/exec-cmd.h>
+#include <subcmd/parse-options.h>
+#include <subcmd/run-command.h>
+
#include "builtin.h"
+#include "color.h"
#include "config.h"
+#include "debug.h"
#include "hist.h"
#include "intlist.h"
-#include "tests.h"
-#include "debug.h"
-#include "color.h"
-#include <subcmd/parse-options.h>
-#include <subcmd/run-command.h>
#include "string2.h"
#include "symbol.h"
+#include "tests-scripts.h"
+#include "tests.h"
#include "util/rlimit.h"
#include "util/strbuf.h"
-#include <linux/kernel.h>
-#include <linux/string.h>
-#include <subcmd/exec-cmd.h>
-#include <linux/zalloc.h>
-
-#include "tests-scripts.h"
+#include "util/term.h"
static const char *junit_filename;
static struct strbuf junit_xml_buf = STRBUF_INIT;
@@ -398,73 +401,73 @@ static char *xml_escape(const char *str)
return res ? res : strdup("");
}
-static const char *format_test_description(const char *desc, int max_desc_width,
- char *buf, size_t buf_sz)
+static int get_term_width(void)
{
- int len = strlen(desc);
+ struct winsize ws;
+ int cols = 80;
+ int term_width;
/*
- * Clamp to buf_sz to prevent GCC format-truncation warnings
- * when terminal width is very large.
+ * If output is redirected to a file or piped, we don't need to wrap
+ * or truncate at all. Use a massive virtually infinite terminal width
+ * so descriptions are printed in full.
*/
- if (max_desc_width >= (int)buf_sz)
- max_desc_width = buf_sz - 1;
+ if (!isatty(fileno(debug_file())))
+ return 10000;
- if (len > max_desc_width) {
- snprintf(buf, buf_sz, "%.*s...", max_desc_width - 3, desc);
- return buf;
- }
- return desc;
+ get_term_dimensions(&ws);
+ if (ws.ws_col > 0)
+ cols = ws.ws_col;
+
+ /*
+ * Limit description width to fit on a single line. We subtract 35
+ * columns of headroom to allocate space for:
+ * - The suite index prefix: e.g. " 10.100:" (8 characters) plus 1 space separator.
+ * - The trailing colon (1 character) and space before status (1 character).
+ * - The longest status results: e.g. "Skip (some metrics failed)" (26 characters)
+ * or "Running (XX active)" (20 characters).
+ *
+ * A minimum description width of 10 is enforced to ensure names are
+ * legible even on very narrow consoles.
+ */
+ term_width = cols - 35;
+ if (term_width < 10)
+ term_width = 10;
+
+ return term_width;
+}
+
+static int get_max_desc_width(int width)
+{
+ int term_width = get_term_width();
+
+ return width > term_width ? term_width : width;
}
static int print_test_result(struct test_suite *t, int curr_suite, int curr_test_case,
int result, int width, int running,
const char *err_output, double elapsed)
{
- char desc_buf[256];
- const char *desc = test_description(t, curr_test_case);
- struct winsize ws;
- int max_desc_area_width;
- int target_desc_area_width;
- int desc_padding;
-
- get_term_dimensions(&ws);
- /*
- * Total terminal columns minus space for status e.g. " Running (12 active)"
- * which is 20 chars, plus a margin of 3 chars = 23 chars.
- */
- max_desc_area_width = ws.ws_col - 23;
- if (max_desc_area_width < 40)
- max_desc_area_width = 40;
-
- /* Standard test has prefix "%3d: " which is 5 chars */
- target_desc_area_width = width + 5;
- if (target_desc_area_width > max_desc_area_width)
- target_desc_area_width = max_desc_area_width;
+ int pad_width = get_max_desc_width(width);
+ int term_width = get_term_width();
if (test_suite__num_test_cases(t) > 1) {
char prefix[32];
int len = snprintf(prefix, sizeof(prefix), "%3d.%1d:",
curr_suite + 1, curr_test_case + 1);
+ int pad = len >= 4 ? pad_width + 4 - len : pad_width;
+ int trunc = len >= 4 ? term_width + 4 - len : term_width;
- desc_padding = target_desc_area_width - (len + 1);
- if (desc_padding < 20)
- desc_padding = 20;
-
- desc = format_test_description(desc, desc_padding, desc_buf, sizeof(desc_buf));
- pr_info("%s %-*s:", prefix, desc_padding, desc);
+ pr_info("%s %-*.*s:", prefix, pad, trunc,
+ test_description(t, curr_test_case));
} else {
- desc_padding = target_desc_area_width - 5;
- if (desc_padding < 20)
- desc_padding = 20;
-
- desc = format_test_description(desc, desc_padding, desc_buf, sizeof(desc_buf));
- pr_info("%3d: %-*s:", curr_suite + 1, desc_padding, desc);
+ pr_info("%3d: %-*.*s:", curr_suite + 1, pad_width, term_width,
+ test_description(t, curr_test_case));
}
switch (result) {
case TEST_RUNNING:
- color_fprintf(stderr, PERF_COLOR_YELLOW, " Running (%d active)\n", running);
+ color_fprintf(debug_file(), PERF_COLOR_YELLOW, " Running (%d active)\n", running);
break;
case TEST_OK:
if (test_suite__num_test_cases(t) > 1)
@@ -478,9 +481,9 @@ static int print_test_result(struct test_suite *t, int curr_suite, int curr_test
summary_tests_skipped++;
if (reason)
- color_fprintf(stderr, PERF_COLOR_YELLOW, " Skip (%s)\n", reason);
+ color_fprintf(debug_file(), PERF_COLOR_YELLOW, " Skip (%s)\n", reason);
else
- color_fprintf(stderr, PERF_COLOR_YELLOW, " Skip\n");
+ color_fprintf(debug_file(), PERF_COLOR_YELLOW, " Skip\n");
}
break;
case TEST_FAIL:
@@ -494,7 +497,7 @@ static int print_test_result(struct test_suite *t, int curr_suite, int curr_test
strbuf_addf_safe(&summary_failed_tests_buf, " %3d: %s\n",
curr_suite + 1,
test_description(t, curr_test_case));
- color_fprintf(stderr, PERF_COLOR_RED, " FAILED!\n");
+ color_fprintf(debug_file(), PERF_COLOR_RED, " FAILED!\n");
break;
}
@@ -730,6 +733,7 @@ static void finish_test(struct child_test **child_tests, int running_test, int c
int ret;
struct timespec end_time;
double elapsed;
+ width = get_max_desc_width(width);
if (child_test == NULL) {
/* Test wasn't started. */
@@ -744,7 +748,8 @@ static void finish_test(struct child_test **child_tests, int running_test, int c
* sub test names.
*/
if (test_suite__num_test_cases(t) > 1 && curr_test_case == 0)
- pr_info("%3d: %s:\n", curr_suite + 1, test_description(t, -1));
+ pr_info("%3d: %-*.*s:\n", curr_suite + 1, width, width,
+ test_description(t, -1));
/*
* Busy loop reading from the child's stdout/stderr that are set to be
@@ -952,6 +957,8 @@ static int finish_tests_parallel(struct child_test **child_tests, size_t num_tes
int last_suite_printed = -1;
sigset_t set, oldset;
+ width = get_max_desc_width(width);
+
sigemptyset(&set);
sigaddset(&set, SIGINT);
sigaddset(&set, SIGTERM);
@@ -1020,8 +1027,11 @@ static int finish_tests_parallel(struct child_test **child_tests, size_t num_tes
if (next_child) {
if (test_suite__num_test_cases(next_child->test) > 1 &&
last_suite_printed != next_child->suite_num) {
- pr_info("%3d: %s:\n", next_child->suite_num + 1,
- test_description(next_child->test, -1));
+ pr_info("%3d: %-*.*s:\n",
+ next_child->suite_num + 1,
+ width, width,
+ test_description(
+ next_child->test, -1));
last_suite_printed = next_child->suite_num;
}
print_test_result(next_child->test, next_child->suite_num,
@@ -1084,7 +1094,8 @@ static int finish_tests_parallel(struct child_test **child_tests, size_t num_tes
if (test_suite__num_test_cases(child->test) > 1 &&
last_suite_printed != child->suite_num) {
- pr_info("%3d: %s:\n", child->suite_num + 1,
+ pr_info("%3d: %-*.*s:\n", child->suite_num + 1,
+ width, width,
test_description(child->test, -1));
last_suite_printed = child->suite_num;
}
@@ -1208,12 +1219,12 @@ static void print_tests_summary(void)
pr_info("Passed subtests : %u\n", summary_subtests_passed);
pr_info("Skipped tests : %u\n", summary_tests_skipped);
if (summary_tests_failed > 0) {
- color_fprintf(stderr, PERF_COLOR_RED, "Failed tests : %u\n",
+ color_fprintf(debug_file(), PERF_COLOR_RED, "Failed tests : %u\n",
summary_tests_failed);
pr_info("List of failed tests:\n");
pr_info("%s", summary_failed_tests_buf.buf);
} else {
- color_fprintf(stderr, PERF_COLOR_GREEN, "Failed tests : 0\n");
+ color_fprintf(debug_file(), PERF_COLOR_GREEN, "Failed tests : 0\n");
}
if (junit_filename) {
@@ -1331,9 +1342,13 @@ static int __cmd_test(struct test_suite **suites, int argc, const char *argv[],
if (intlist__find(skiplist, curr_suite + 1)) {
if (pass == 1) {
- pr_info("%3d: %-*s:", curr_suite + 1, width,
+ int pad_width = get_max_desc_width(width);
+ int term_width = get_term_width();
+
+ pr_info("%3d: %-*.*s:", curr_suite + 1,
+ pad_width, term_width,
test_description(*t, -1));
- color_fprintf(stderr, PERF_COLOR_YELLOW,
+ color_fprintf(debug_file(), PERF_COLOR_YELLOW,
" Skip (user override)\n");
summary_tests_skipped++;
if (junit_filename) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0156/1518] perf test metrics: Update all metrics for possibly failing default metrics
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (154 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0155/1518] perf test: Truncate test description to fit terminal width Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0157/1518] perf test all metrics: Fully ignore Default metric failures Greg Kroah-Hartman
` (842 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ian Rogers, Namhyung Kim,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ian Rogers <irogers@google.com>
[ Upstream commit 91c1949d768520d9befa7761eb97c3826997da25 ]
Default metrics may use unsupported events and be ignored. These
metrics shouldn't cause metric testing to fail.
Signed-off-by: Ian Rogers <irogers@google.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Stable-dep-of: 8953bfd8820b ("perf tests: Skip metrics validation if system-wide recording lacks permission")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/tests/shell/stat_all_metrics.sh | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/tools/perf/tests/shell/stat_all_metrics.sh b/tools/perf/tests/shell/stat_all_metrics.sh
index 6fa585a1e34c9..a7edf01b39433 100755
--- a/tools/perf/tests/shell/stat_all_metrics.sh
+++ b/tools/perf/tests/shell/stat_all_metrics.sh
@@ -25,8 +25,13 @@ for m in $(perf list --raw-dump metrics); do
# No error result and metric shown.
continue
fi
- if [[ "$result" =~ "Cannot resolve IDs for" ]]
+ if [[ "$result" =~ "Cannot resolve IDs for" || "$result" =~ "No supported events found" ]]
then
+ if [[ "$m" == @(l1_prefetch_miss_rate|stalled_cycles_per_instruction) ]]
+ then
+ # Default metrics that may use unsupported events.
+ continue
+ fi
echo "Metric contains missing events"
echo $result
err=1 # Fail
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0157/1518] perf test all metrics: Fully ignore Default metric failures
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (155 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0156/1518] perf test metrics: Update all metrics for possibly failing default metrics Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0158/1518] perf test: Do not skip when some metrics tests succeeded Greg Kroah-Hartman
` (841 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Thomas Richter, Namhyung Kim,
James Clark, Ian Rogers, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ian Rogers <irogers@google.com>
[ Upstream commit 41b67ab3d2f5be9d0b6e5ba9cbec97c820fc50e8 ]
Determine if a metric is default from `perf list --raw-dump $m` eg:
```
$ perf list --raw-dump l1_prefetch_miss_rate
Default4 l1_prefetch_miss_rate
```
If a metric has "not supported" or "no supported events" then ignore
these failures for default metrics. Tidy up the skip/fail messages in
the output to make them easier to spot/read.
```
$ perf list -vv "all metrics"
...
Testing llc_miss_rate
[Ignored llc_miss_rate] failed but as a Default metric this can be expected
Error: No supported events found. The LLC-loads event is not supported.
...
```
Reported-by: Thomas Richter <tmricht@linux.ibm.com>
Closes: https://lore.kernel.org/linux-perf-users/20251119104751.51960-1-tmricht@linux.ibm.com/
Reported-by: Namhyung Kim <namhyung@kernel.org>
Reported-by: James Clark <james.clark@linaro.org>
Closes: https://lore.kernel.org/lkml/aRi9xnwdLh3Dir9f@google.com/
Signed-off-by: Ian Rogers <irogers@google.com>
Reviewed-by: James Clark <james.clark@linaro.org>
Tested-by: Thomas Richter <tmricht@linux.ibm.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Stable-dep-of: 8953bfd8820b ("perf tests: Skip metrics validation if system-wide recording lacks permission")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/tests/shell/stat_all_metrics.sh | 27 ++++++++++++++--------
1 file changed, 17 insertions(+), 10 deletions(-)
diff --git a/tools/perf/tests/shell/stat_all_metrics.sh b/tools/perf/tests/shell/stat_all_metrics.sh
index a7edf01b39433..3dabb39c7cc8c 100755
--- a/tools/perf/tests/shell/stat_all_metrics.sh
+++ b/tools/perf/tests/shell/stat_all_metrics.sh
@@ -27,19 +27,20 @@ for m in $(perf list --raw-dump metrics); do
fi
if [[ "$result" =~ "Cannot resolve IDs for" || "$result" =~ "No supported events found" ]]
then
- if [[ "$m" == @(l1_prefetch_miss_rate|stalled_cycles_per_instruction) ]]
+ if [[ $(perf list --raw-dump $m) == "Default"* ]]
then
- # Default metrics that may use unsupported events.
+ echo "[Ignored $m] failed but as a Default metric this can be expected"
+ echo $result
continue
fi
- echo "Metric contains missing events"
+ echo "[Failed $m] Metric contains missing events"
echo $result
err=1 # Fail
continue
elif [[ "$result" =~ \
"Access to performance monitoring and observability operations is limited" ]]
then
- echo "Permission failure"
+ echo "[Skipped $m] Permission failure"
echo $result
if [[ $err -eq 0 ]]
then
@@ -48,7 +49,7 @@ for m in $(perf list --raw-dump metrics); do
continue
elif [[ "$result" =~ "in per-thread mode, enable system wide" ]]
then
- echo "Permissions - need system wide mode"
+ echo "[Skipped $m] Permissions - need system wide mode"
echo $result
if [[ $err -eq 0 ]]
then
@@ -57,7 +58,13 @@ for m in $(perf list --raw-dump metrics); do
continue
elif [[ "$result" =~ "<not supported>" ]]
then
- echo "Not supported events"
+ if [[ $(perf list --raw-dump $m) == "Default"* ]]
+ then
+ echo "[Ignored $m] failed but as a Default metric this can be expected"
+ echo $result
+ continue
+ fi
+ echo "[Skipped $m] Not supported events"
echo $result
if [[ $err -eq 0 ]]
then
@@ -66,7 +73,7 @@ for m in $(perf list --raw-dump metrics); do
continue
elif [[ "$result" =~ "<not counted>" ]]
then
- echo "Not counted events"
+ echo "[Skipped $m] Not counted events"
echo $result
if [[ $err -eq 0 ]]
then
@@ -75,7 +82,7 @@ for m in $(perf list --raw-dump metrics); do
continue
elif [[ "$result" =~ "FP_ARITH" || "$result" =~ "AMX" ]]
then
- echo "FP issues"
+ echo "[Skipped $m] FP issues"
echo $result
if [[ $err -eq 0 ]]
then
@@ -84,7 +91,7 @@ for m in $(perf list --raw-dump metrics); do
continue
elif [[ "$result" =~ "PMM" ]]
then
- echo "Optane memory issues"
+ echo "[Skipped $m] Optane memory issues"
echo $result
if [[ $err -eq 0 ]]
then
@@ -101,7 +108,7 @@ for m in $(perf list --raw-dump metrics); do
# No error result and metric shown.
continue
fi
- echo "Metric '$m' has non-zero error '$result_err' or not printed in:"
+ echo "[Failed $m] has non-zero error '$result_err' or not printed in:"
echo "$result"
err=1
done
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0158/1518] perf test: Do not skip when some metrics tests succeeded
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (156 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0157/1518] perf test all metrics: Fully ignore Default metric failures Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0159/1518] perf tests: Skip metrics validation if system-wide recording lacks permission Greg Kroah-Hartman
` (840 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Namhyung Kim,
Arnaldo Carvalho de Melo, Adrian Hunter, Ian Rogers, Ingo Molnar,
James Clark, Jiri Olsa, Peter Zijlstra, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namhyung Kim <namhyung@kernel.org>
[ Upstream commit 1c89bc1b95fa9058f3e7cd37f1142939261417d5 ]
I think the return value of SKIP (2) should be used when it skipped the
entire test suite rather than a few of them. While the FAIL should be
reserved if any of test failed.
$ perf test -vv 110
110: perf all metrics test:
--- start ---
test child forked, pid 2496399
Testing tma_core_bound
Testing tma_info_core_ilp
Testing tma_info_memory_l2mpki
Testing tma_memory_bound
Testing tma_bottleneck_irregular_overhead
Testing tma_bottleneck_mispredictions
Testing tma_info_bad_spec_branch_misprediction_cost
Testing tma_info_bad_spec_ipmisp_cond_ntaken
Testing tma_info_bad_spec_ipmisp_cond_taken
Testing tma_info_bad_spec_ipmisp_indirect
Testing tma_info_bad_spec_ipmisp_ret
Testing tma_info_bad_spec_ipmispredict
Testing tma_info_branches_callret
Testing tma_info_branches_cond_nt
Testing tma_info_branches_cond_tk
Testing tma_info_branches_jump
Testing tma_info_branches_other_branches
Testing tma_branch_mispredicts
Testing tma_clears_resteers
Testing tma_machine_clears
Testing tma_mispredicts_resteers
Testing tma_bottleneck_big_code
Testing tma_icache_misses
Testing tma_itlb_misses
Testing tma_unknown_branches
Testing tma_info_bad_spec_spec_clears_ratio
Testing tma_other_mispredicts
Testing tma_branch_instructions
Testing tma_info_frontend_tbpc
Testing tma_info_inst_mix_bptkbranch
Testing tma_info_inst_mix_ipbranch
Testing tma_info_inst_mix_ipcall
Testing tma_info_inst_mix_iptb
Testing tma_info_system_ipfarbranch
Testing tma_info_thread_uptb
Testing tma_bottleneck_branching_overhead
Testing tma_nop_instructions
Testing tma_bottleneck_compute_bound_est
Testing tma_divider
Testing tma_ports_utilized_3m
Testing tma_bottleneck_instruction_fetch_bw
Testing tma_frontend_bound
Testing tma_assists
Testing tma_other_nukes
Testing tma_serializing_operation
Testing tma_bottleneck_data_cache_memory_bandwidth
Testing tma_fb_full
Testing tma_mem_bandwidth
Testing tma_sq_full
Testing tma_bottleneck_data_cache_memory_latency
Testing tma_l1_latency_dependency
Testing tma_l2_bound
Testing tma_l3_hit_latency
Testing tma_mem_latency
Testing tma_store_latency
Testing tma_bottleneck_memory_synchronization
Testing tma_contested_accesses
Testing tma_data_sharing
Testing tma_false_sharing
Testing tma_bottleneck_memory_data_tlbs
Testing tma_dtlb_load
Testing tma_dtlb_store
Testing tma_backend_bound
Testing tma_bottleneck_other_bottlenecks
Testing tma_bottleneck_useful_work
Testing tma_retiring
Testing tma_info_memory_fb_hpki
Testing tma_info_memory_l1mpki
Testing tma_info_memory_l1mpki_load
Testing tma_info_memory_l2hpki_all
Testing tma_info_memory_l2hpki_load
Testing tma_info_memory_l2mpki_all
Testing tma_info_memory_l2mpki_load
Testing tma_l1_bound
Testing tma_l3_bound
Testing tma_info_memory_l2mpki_rfo
Testing tma_fp_scalar
Testing tma_fp_vector
Testing tma_fp_vector_128b
Testing tma_fp_vector_256b
Testing tma_fp_vector_512b
Testing tma_port_0
Testing tma_x87_use
Testing tma_info_botlnk_l0_core_bound_likely
Testing tma_info_core_fp_arith_utilization
Testing tma_info_pipeline_execute
Testing tma_info_system_gflops
Testing tma_info_thread_execute_per_issue
Testing tma_dsb
Testing tma_info_botlnk_l2_dsb_bandwidth
Testing tma_info_frontend_dsb_coverage
Testing tma_decoder0_alone
Testing tma_dsb_switches
Testing tma_info_botlnk_l2_dsb_misses
Testing tma_info_frontend_dsb_switch_cost
Testing tma_info_frontend_ipdsb_miss_ret
Testing tma_mite
Testing tma_mite_4wide
Testing CPUs_utilized
Testing backend_cycles_idle
[Ignored backend_cycles_idle] failed but as a Default metric this can be expected
Performance counter stats for 'perf test -w noploop': <not counted> cpu-cycles:u <not supported> stalled-cycles-backend:u 1.014051473 seconds time elapsed 1.005718000 seconds user 0.008013000 seconds sys
Testing branch_frequency
Testing branch_miss_rate
Testing cs_per_second
Testing cycles_frequency
Testing frontend_cycles_idle
[Ignored frontend_cycles_idle] failed but as a Default metric this can be expected
Performance counter stats for 'perf test -w noploop': <not counted> cpu-cycles:u <not supported> stalled-cycles-frontend:u 1.012813656 seconds time elapsed 1.004603000 seconds user 0.008004000 seconds sys
Testing insn_per_cycle
Testing migrations_per_second
Testing page_faults_per_second
Testing stalled_cycles_per_instruction
[Ignored stalled_cycles_per_instruction] failed but as a Default metric this can be expected
Error: No supported events found. The stalled-cycles-backend:u event is not supported.
Testing tma_bad_speculation
Testing l1d_miss_rate
Testing llc_miss_rate
Testing dtlb_miss_rate
Testing itlb_miss_rate
[Ignored itlb_miss_rate] failed but as a Default metric this can be expected
Performance counter stats for 'perf test -w noploop': <not supported> iTLB-loads:u 3,097 iTLB-load-misses:u 1.012766732 seconds time elapsed 1.004318000 seconds user 0.008002000 seconds sys
Testing l1i_miss_rate
[Ignored l1i_miss_rate] failed but as a Default metric this can be expected
Performance counter stats for 'perf test -w noploop': <not counted> L1-icache-load-misses:u <not supported> L1-icache-loads:u 1.013606395 seconds time elapsed 1.001371000 seconds user 0.011968000 seconds sys
Testing l1_prefetch_miss_rate
[Ignored l1_prefetch_miss_rate] failed but as a Default metric this can be expected
Error: No supported events found. The L1-dcache-prefetches:u event is not supported.
Testing tma_info_botlnk_l2_ic_misses
Testing tma_info_frontend_fetch_upc
Testing tma_info_frontend_icache_miss_latency
Testing tma_info_frontend_ipunknown_branch
Testing tma_info_frontend_lsd_coverage
Testing tma_info_memory_tlb_code_stlb_mpki
Testing tma_info_pipeline_fetch_dsb
Testing tma_info_pipeline_fetch_lsd
Testing tma_info_pipeline_fetch_mite
Testing tma_info_pipeline_fetch_ms
Testing tma_fetch_bandwidth
Testing tma_lsd
Testing tma_branch_resteers
Testing tma_code_l2_hit
Testing tma_code_l2_miss
Testing tma_code_stlb_hit
Testing tma_code_stlb_miss
Testing tma_code_stlb_miss_2m
Testing tma_code_stlb_miss_4k
Testing tma_lcp
Testing tma_ms_switches
Testing tma_info_core_flopc
Testing tma_info_inst_mix_iparith
Testing tma_info_inst_mix_iparith_avx128
Testing tma_info_inst_mix_iparith_avx256
Testing tma_info_inst_mix_iparith_avx512
Testing tma_info_inst_mix_iparith_scalar_dp
Testing tma_info_inst_mix_iparith_scalar_sp
Testing tma_info_inst_mix_ipflop
Testing tma_info_inst_mix_ippause
Testing tma_fetch_latency
Testing tma_fp_arith
Testing tma_fp_assists
Testing tma_info_system_cpu_utilization
Testing tma_info_system_dram_bw_use
[Skipped tma_info_system_dram_bw_use] Not supported events
Performance counter stats for 'perf test -w noploop': <not supported> UNC_ARB_TRK_REQUESTS.ALL:u <not supported> UNC_ARB_COH_TRK_REQUESTS.ALL:u 1,013,554,749 duration_time 1.013527265 seconds time elapsed 1.005417000 seconds user 0.008011000 seconds sys
Testing tma_info_frontend_l2mpki_code
Testing tma_info_frontend_l2mpki_code_all
Testing tma_info_inst_mix_ipload
Testing tma_info_inst_mix_ipstore
Testing tma_info_memory_latency_load_l2_miss_latency
Testing tma_lock_latency
Testing tma_info_memory_core_l1d_cache_fill_bw_2t
Testing tma_info_memory_core_l2_cache_fill_bw_2t
Testing tma_info_memory_core_l3_cache_access_bw_2t
Testing tma_info_memory_core_l3_cache_fill_bw_2t
Testing tma_info_memory_l1d_cache_fill_bw
Testing tma_info_memory_l2_cache_fill_bw
Testing tma_info_memory_l3_cache_access_bw
Testing tma_info_memory_l3_cache_fill_bw
Testing tma_info_memory_l3mpki
Testing tma_info_memory_load_miss_real_latency
Testing tma_info_memory_mix_bus_lock_pki
Testing tma_info_memory_mix_uc_load_pki
Testing tma_info_memory_mlp
Testing tma_info_memory_tlb_load_stlb_mpki
Testing tma_info_memory_tlb_page_walks_utilization
Testing tma_info_memory_tlb_store_stlb_mpki
Testing tma_info_system_mem_parallel_reads
[Skipped tma_info_system_mem_parallel_reads] Not supported events
Performance counter stats for 'perf test -w noploop': <not supported> UNC_ARB_DAT_OCCUPANCY.RD:u <not counted> UNC_ARB_DAT_OCCUPANCY.RD/cmask=1/ 1.013354884 seconds time elapsed 1.009239000 seconds user 0.004004000 seconds sys
Testing tma_info_system_mem_read_latency
[Skipped tma_info_system_mem_read_latency] Not supported events
Performance counter stats for 'perf test -w noploop': <not supported> UNC_ARB_DAT_OCCUPANCY.RD:u <not counted> UNC_ARB_TRK_OCCUPANCY.RD <not counted> UNC_ARB_TRK_REQUESTS.RD 1.012882143 seconds time elapsed 1.004600000 seconds user 0.008036000 seconds sys
Testing tma_info_thread_cpi
Testing tma_streaming_stores
Testing tma_dram_bound
Testing tma_store_bound
Testing tma_l2_hit_latency
Testing tma_load_stlb_hit
Testing tma_load_stlb_miss
Testing tma_load_stlb_miss_1g
Testing tma_load_stlb_miss_2m
Testing tma_load_stlb_miss_4k
Testing tma_store_stlb_hit
Testing tma_store_stlb_miss
Testing tma_store_stlb_miss_1g
Testing tma_store_stlb_miss_2m
Testing tma_store_stlb_miss_4k
Testing tma_info_memory_latency_data_l2_mlp
Testing tma_info_memory_latency_load_l2_mlp
Testing tma_info_pipeline_ipassist
Testing tma_microcode_sequencer
Testing tma_ms
Testing tma_info_system_kernel_cpi
[Failed tma_info_system_kernel_cpi] Metric contains missing events
Error: No supported events found. Access to performance monitoring and observability operations is limited. Consider adjusting /proc/sys/kernel/perf_event_paranoid setting to open access to performance monitoring and observability operations for processes without CAP_PERFMON, CAP_SYS_PTRACE or CAP_SYS_ADMIN Linux capability. More information can be found at 'Perf events and tool security' document: https://www.kernel.org/doc/html/latest/admin-guide/perf-security.html perf_event_paranoid setting is 2: -1: Allow use of (almost) all events by all users Ignore mlock limit after perf_event_mlock_kb without CAP_IPC_LOCK >= 0: Disallow raw and ftrace function tracepoint access >= 1: Disallow CPU event access >= 2: Disallow kernel profiling To make the adjusted perf_event_paranoid setting permanent preserve it in /etc/sysctl.conf (e.g. kernel.perf_event_paranoid = <setting>)
Testing tma_info_system_kernel_utilization
[Failed tma_info_system_kernel_utilization] Metric contains missing events
Error: No supported events found. Access to performance monitoring and observability operations is limited. Consider adjusting /proc/sys/kernel/perf_event_paranoid setting to open access to performance monitoring and observability operations for processes without CAP_PERFMON, CAP_SYS_PTRACE or CAP_SYS_ADMIN Linux capability. More information can be found at 'Perf events and tool security' document: https://www.kernel.org/doc/html/latest/admin-guide/perf-security.html perf_event_paranoid setting is 2: -1: Allow use of (almost) all events by all users Ignore mlock limit after perf_event_mlock_kb without CAP_IPC_LOCK >= 0: Disallow raw and ftrace function tracepoint access >= 1: Disallow CPU event access >= 2: Disallow kernel profiling To make the adjusted perf_event_paranoid setting permanent preserve it in /etc/sysctl.conf (e.g. kernel.perf_event_paranoid = <setting>)
Testing tma_info_pipeline_retire
Testing tma_info_thread_clks
Testing tma_info_thread_uoppi
Testing tma_memory_operations
Testing tma_other_light_ops
Testing tma_ports_utilization
Testing tma_ports_utilized_0
Testing tma_ports_utilized_1
Testing tma_ports_utilized_2
Testing C10_Pkg_Residency
[Failed C10_Pkg_Residency] Metric contains missing events
WARNING: grouped events cpus do not match. Events with CPUs not matching the leader will be removed from the group. anon group { cstate_pkg/c10-residency/, msr/tsc/ } Error: No supported events found. Invalid event (cstate_pkg/c10-residency/u) in per-thread mode, enable system wide with '-a'.
Testing C2_Pkg_Residency
[Failed C2_Pkg_Residency] Metric contains missing events
WARNING: grouped events cpus do not match. Events with CPUs not matching the leader will be removed from the group. anon group { cstate_pkg/c2-residency/, msr/tsc/ } Error: No supported events found. Invalid event (cstate_pkg/c2-residency/u) in per-thread mode, enable system wide with '-a'.
Testing C3_Pkg_Residency
[Failed C3_Pkg_Residency] Metric contains missing events
WARNING: grouped events cpus do not match. Events with CPUs not matching the leader will be removed from the group. anon group { msr/tsc/, cstate_pkg/c3-residency/ } Error: No supported events found. Invalid event (msr/tsc/u) in per-thread mode, enable system wide with '-a'.
Testing C6_Core_Residency
[Failed C6_Core_Residency] Metric contains missing events
WARNING: grouped events cpus do not match. Events with CPUs not matching the leader will be removed from the group. anon group { cstate_core/c6-residency/, msr/tsc/ } Error: No supported events found. Invalid event (cstate_core/c6-residency/u) in per-thread mode, enable system wide with '-a'.
Testing C6_Pkg_Residency
[Failed C6_Pkg_Residency] Metric contains missing events
WARNING: grouped events cpus do not match. Events with CPUs not matching the leader will be removed from the group. anon group { cstate_pkg/c6-residency/, msr/tsc/ } Error: No supported events found. Invalid event (cstate_pkg/c6-residency/u) in per-thread mode, enable system wide with '-a'.
Testing C7_Core_Residency
[Failed C7_Core_Residency] Metric contains missing events
WARNING: grouped events cpus do not match. Events with CPUs not matching the leader will be removed from the group. anon group { cstate_core/c7-residency/, msr/tsc/ } Error: No supported events found. Invalid event (cstate_core/c7-residency/u) in per-thread mode, enable system wide with '-a'.
Testing C7_Pkg_Residency
[Failed C7_Pkg_Residency] Metric contains missing events
WARNING: grouped events cpus do not match. Events with CPUs not matching the leader will be removed from the group. anon group { cstate_pkg/c7-residency/, msr/tsc/ } Error: No supported events found. Invalid event (cstate_pkg/c7-residency/u) in per-thread mode, enable system wide with '-a'.
Testing C8_Pkg_Residency
[Failed C8_Pkg_Residency] Metric contains missing events
WARNING: grouped events cpus do not match. Events with CPUs not matching the leader will be removed from the group. anon group { cstate_pkg/c8-residency/, msr/tsc/ } Error: No supported events found. Invalid event (cstate_pkg/c8-residency/u) in per-thread mode, enable system wide with '-a'.
Testing C9_Pkg_Residency
[Failed C9_Pkg_Residency] Metric contains missing events
WARNING: grouped events cpus do not match. Events with CPUs not matching the leader will be removed from the group. anon group { cstate_pkg/c9-residency/, msr/tsc/ } Error: No supported events found. Invalid event (cstate_pkg/c9-residency/u) in per-thread mode, enable system wide with '-a'.
Testing tma_info_core_epc
Testing tma_info_system_core_frequency
Testing tma_info_system_power
[Skipped tma_info_system_power] Not supported events
Performance counter stats for 'perf test -w noploop': <not supported> Joules power/energy-pkg/u 1,013,238,256 duration_time 1.013223072 seconds time elapsed 0.995924000 seconds user 0.011903000 seconds sys
Testing tma_info_system_power_license0_utilization
Testing tma_info_system_power_license1_utilization
Testing tma_info_system_power_license2_utilization
Testing tma_info_system_turbo_utilization
Testing tma_info_inst_mix_ipswpf
Testing tma_info_memory_prefetches_useless_hwpf
Testing tma_info_core_coreipc
Testing tma_info_thread_ipc
Testing tma_heavy_operations
Testing tma_light_operations
Testing tma_info_core_core_clks
Testing tma_info_system_smt_2t_utilization
Testing tma_info_thread_slots_utilization
Testing UNCORE_FREQ
[Skipped UNCORE_FREQ] Not supported events
Performance counter stats for 'perf test -w noploop': <not supported> UNC_CLOCK.SOCKET:u 1,015,993,466 duration_time 1.015949387 seconds time elapsed 1.007676000 seconds user 0.008029000 seconds sys
Testing tma_info_system_socket_clks
[Failed tma_info_system_socket_clks] Metric contains missing events
Error: No supported events found. Invalid event (UNC_CLOCK.SOCKET:u) in per-thread mode, enable system wide with '-a'.
Testing tma_info_inst_mix_instructions
Testing tma_info_system_cpus_utilized
Testing tma_info_system_mux
Testing tma_info_system_time
Testing tma_info_thread_slots
Testing tma_few_uops_instructions
Testing tma_4k_aliasing
Testing tma_cisc
Testing tma_fp_divider
Testing tma_int_divider
Testing tma_slow_pause
Testing tma_split_loads
Testing tma_split_stores
Testing tma_store_fwd_blk
Testing tma_alu_op_utilization
Testing tma_load_op_utilization
Testing tma_mixing_vectors
Testing tma_store_op_utilization
Testing tma_port_1
Testing tma_port_5
Testing tma_port_6
Testing smi_cycles
[Skipped smi_cycles] Not supported events
Performance counter stats for 'perf test -w noploop': <not supported> msr/smi/u <not supported> msr/aperf/u 3,965,789,327 cycles:u 1.012779591 seconds time elapsed 1.004579000 seconds user 0.007972000 seconds sys
Testing smi_num
[Failed smi_num] Metric contains missing events
Error: No supported events found. Invalid event (msr/smi/u) in per-thread mode, enable system wide with '-a'.
Testing tsx_aborted_cycles
Testing tsx_cycles_per_elision
Testing tsx_cycles_per_transaction
Testing tsx_transactional_cycles
---- end(-1) ----
110: perf all metrics test : FAILED!
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Tested-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Cc: Ian Rogers <irogers@google.com>
Cc: Ingo Molnar <mingo@kernel.org>
Cc: James Clark <james.clark@linaro.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Stable-dep-of: 8953bfd8820b ("perf tests: Skip metrics validation if system-wide recording lacks permission")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/tests/shell/stat_all_metrics.sh | 29 ++++++++++++++++------
1 file changed, 22 insertions(+), 7 deletions(-)
diff --git a/tools/perf/tests/shell/stat_all_metrics.sh b/tools/perf/tests/shell/stat_all_metrics.sh
index 3dabb39c7cc8c..b582d23f28c9e 100755
--- a/tools/perf/tests/shell/stat_all_metrics.sh
+++ b/tools/perf/tests/shell/stat_all_metrics.sh
@@ -15,7 +15,8 @@ then
test_prog="perf test -w noploop"
fi
-err=0
+skip=0
+err=3
for m in $(perf list --raw-dump metrics); do
echo "Testing $m"
result=$(perf stat -M "$m" $system_wide_flag -- $test_prog 2>&1)
@@ -23,6 +24,10 @@ for m in $(perf list --raw-dump metrics); do
if [[ $result_err -eq 0 && "$result" =~ ${m:0:50} ]]
then
# No error result and metric shown.
+ if [[ "$err" -ne 1 ]]
+ then
+ err=0
+ fi
continue
fi
if [[ "$result" =~ "Cannot resolve IDs for" || "$result" =~ "No supported events found" ]]
@@ -44,7 +49,7 @@ for m in $(perf list --raw-dump metrics); do
echo $result
if [[ $err -eq 0 ]]
then
- err=2 # Skip
+ skip=1
fi
continue
elif [[ "$result" =~ "in per-thread mode, enable system wide" ]]
@@ -53,7 +58,7 @@ for m in $(perf list --raw-dump metrics); do
echo $result
if [[ $err -eq 0 ]]
then
- err=2 # Skip
+ skip=1
fi
continue
elif [[ "$result" =~ "<not supported>" ]]
@@ -68,7 +73,7 @@ for m in $(perf list --raw-dump metrics); do
echo $result
if [[ $err -eq 0 ]]
then
- err=2 # Skip
+ skip=1
fi
continue
elif [[ "$result" =~ "<not counted>" ]]
@@ -77,7 +82,7 @@ for m in $(perf list --raw-dump metrics); do
echo $result
if [[ $err -eq 0 ]]
then
- err=2 # Skip
+ skip=1
fi
continue
elif [[ "$result" =~ "FP_ARITH" || "$result" =~ "AMX" ]]
@@ -86,7 +91,7 @@ for m in $(perf list --raw-dump metrics); do
echo $result
if [[ $err -eq 0 ]]
then
- err=2 # Skip
+ skip=1
fi
continue
elif [[ "$result" =~ "PMM" ]]
@@ -95,7 +100,7 @@ for m in $(perf list --raw-dump metrics); do
echo $result
if [[ $err -eq 0 ]]
then
- err=2 # Skip
+ skip=1
fi
continue
fi
@@ -106,6 +111,10 @@ for m in $(perf list --raw-dump metrics); do
if [[ $result_err -eq 0 && "$result" =~ ${m:0:50} ]]
then
# No error result and metric shown.
+ if [[ "$err" -ne 1 ]]
+ then
+ err=0
+ fi
continue
fi
echo "[Failed $m] has non-zero error '$result_err' or not printed in:"
@@ -113,4 +122,10 @@ for m in $(perf list --raw-dump metrics); do
err=1
done
+# return SKIP only if no success returned
+if [[ "$err" -eq 3 && "$skip" -eq 1 ]]
+then
+ err=2
+fi
+
exit "$err"
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0159/1518] perf tests: Skip metrics validation if system-wide recording lacks permission
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (157 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0158/1518] perf test: Do not skip when some metrics tests succeeded Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0160/1518] perf test kvm: Add some basic perf kvm test coverage Greg Kroah-Hartman
` (839 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ian Rogers, Namhyung Kim,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ian Rogers <irogers@google.com>
[ Upstream commit 8953bfd8820b6525032023fda3a420098c1823ae ]
The metrics value validation test requires system-wide recording (`-a`),
which can fail on systems without root permissions or where paranoid
levels restrict tracing. Add a check to skip the test if `-a` is not
supported.
Also fix false negatives during validation by updating parse error string
patterns and resolving issues in metric list generation.
Fixes: 3ad7092f5145 ("perf test: Add metric value validation test")
Assisted-by: Antigravity:gemini-3.1-pro
Signed-off-by: Ian Rogers <irogers@google.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../tests/shell/lib/perf_metric_validation.py | 11 ++-
tools/perf/tests/shell/stat_all_metrics.sh | 75 ++++++++++++-------
tools/perf/tests/shell/stat_metrics_values.sh | 7 ++
3 files changed, 60 insertions(+), 33 deletions(-)
diff --git a/tools/perf/tests/shell/lib/perf_metric_validation.py b/tools/perf/tests/shell/lib/perf_metric_validation.py
index dea8ef1977bf6..3d52f94f22b91 100644
--- a/tools/perf/tests/shell/lib/perf_metric_validation.py
+++ b/tools/perf/tests/shell/lib/perf_metric_validation.py
@@ -383,10 +383,13 @@ class Validator:
wl = workload.split()
command.extend(wl)
print(" ".join(command))
- cmd = subprocess.run(command, stderr=subprocess.PIPE, encoding='utf-8')
- data = [x+'}' for x in cmd.stderr.split('}\n') if x]
- if data[0][0] != '{':
- data[0] = data[0][data[0].find('{'):]
+ cmd = subprocess.run(command, stdout=subprocess.PIPE, stderr=subprocess.PIPE, encoding='utf-8')
+ lines = cmd.stderr.splitlines() + cmd.stdout.splitlines()
+ data = []
+ for line in lines:
+ line = line.strip()
+ if line.startswith('{') and line.endswith('}'):
+ data.append(line)
return data
def collect_perf(self, workload: str):
diff --git a/tools/perf/tests/shell/stat_all_metrics.sh b/tools/perf/tests/shell/stat_all_metrics.sh
index b582d23f28c9e..feeb34c6fa6df 100755
--- a/tools/perf/tests/shell/stat_all_metrics.sh
+++ b/tools/perf/tests/shell/stat_all_metrics.sh
@@ -12,38 +12,65 @@ system_wide_flag="-a"
if ParanoidAndNotRoot 0
then
system_wide_flag=""
- test_prog="perf test -w noploop"
+ test_prog="perf test -w noploop 0.01"
fi
+check_metric() {
+ local output="$1"
+ local status="$2"
+ local metric="$3"
+
+ if [[ $status -ne 0 || ! "$output" =~ ${metric:0:50} ]]; then
+ return 1
+ fi
+
+ if [[ "$output" =~ "<not counted>" || "$output" =~ "<not supported>" ]]; then
+ return 1
+ fi
+
+ return 0
+}
+
skip=0
err=3
for m in $(perf list --raw-dump metrics); do
echo "Testing $m"
result=$(perf stat -M "$m" $system_wide_flag -- $test_prog 2>&1)
result_err=$?
- if [[ $result_err -eq 0 && "$result" =~ ${m:0:50} ]]
- then
- # No error result and metric shown.
+
+ if check_metric "$result" $result_err "$m"; then
if [[ "$err" -ne 1 ]]
then
err=0
fi
continue
fi
- if [[ "$result" =~ "Cannot resolve IDs for" || "$result" =~ "No supported events found" ]]
+
+ if [[ "$result" =~ "Access to performance monitoring and observability operations is limited" || \
+ "$result" =~ "in per-thread mode, enable system wide" || \
+ "$result" =~ "<not supported>" || \
+ "$result" =~ "Cannot resolve IDs for" || \
+ "$result" =~ "No supported events found" || \
+ "$result" =~ "FP_ARITH" || \
+ "$result" =~ "AMX" || \
+ "$result" =~ "PMM" ]]
then
- if [[ $(perf list --raw-dump $m) == "Default"* ]]
- then
- echo "[Ignored $m] failed but as a Default metric this can be expected"
- echo $result
+ true
+ else
+ result=$(perf stat -M "$m" $system_wide_flag -- perf test -w noploop 0.1 2>&1)
+ result_err=$?
+
+ if check_metric "$result" $result_err "$m"; then
+ if [[ "$err" -ne 1 ]]
+ then
+ err=0
+ fi
continue
fi
- echo "[Failed $m] Metric contains missing events"
- echo $result
- err=1 # Fail
- continue
- elif [[ "$result" =~ \
- "Access to performance monitoring and observability operations is limited" ]]
+ fi
+
+ # If retry also failed, determine if we skip, ignore, or fail
+ if [[ "$result" =~ "Access to performance monitoring and observability operations is limited" ]]
then
echo "[Skipped $m] Permission failure"
echo $result
@@ -61,7 +88,9 @@ for m in $(perf list --raw-dump metrics); do
skip=1
fi
continue
- elif [[ "$result" =~ "<not supported>" ]]
+ elif [[ "$result" =~ "<not supported>" || \
+ "$result" =~ "Cannot resolve IDs for" || \
+ "$result" =~ "No supported events found" ]]
then
if [[ $(perf list --raw-dump $m) == "Default"* ]]
then
@@ -105,19 +134,7 @@ for m in $(perf list --raw-dump metrics); do
continue
fi
- # Failed, possibly the workload was too small so retry with something longer.
- result=$(perf stat -M "$m" $system_wide_flag -- perf bench internals synthesize 2>&1)
- result_err=$?
- if [[ $result_err -eq 0 && "$result" =~ ${m:0:50} ]]
- then
- # No error result and metric shown.
- if [[ "$err" -ne 1 ]]
- then
- err=0
- fi
- continue
- fi
- echo "[Failed $m] has non-zero error '$result_err' or not printed in:"
+ echo "[Failed $m] has non-zero error '$result_err' or not printed/counted in:"
echo "$result"
err=1
done
diff --git a/tools/perf/tests/shell/stat_metrics_values.sh b/tools/perf/tests/shell/stat_metrics_values.sh
index 30566f0b54279..76f1e99d1273f 100755
--- a/tools/perf/tests/shell/stat_metrics_values.sh
+++ b/tools/perf/tests/shell/stat_metrics_values.sh
@@ -8,6 +8,13 @@ shelldir=$(dirname "$0")
grep -q GenuineIntel /proc/cpuinfo || { echo Skipping non-Intel; exit 2; }
+# Skip if no permission to record system-wide events
+if ! perf stat -a -e instructions sleep 0.01 >/dev/null 2>&1; then
+ echo "Skipping: no permission to record system-wide events (-a)"
+ exit 2
+fi
+
+
pythonvalidator=$(dirname $0)/lib/perf_metric_validation.py
rulefile=$(dirname $0)/lib/perf_metric_validation_rules.json
tmpdir=$(mktemp -d /tmp/__perf_test.program.XXXXX)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0160/1518] perf test kvm: Add some basic perf kvm test coverage
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (158 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0159/1518] perf tests: Skip metrics validation if system-wide recording lacks permission Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0161/1518] perf tests: Add robust record retry helper and use subsecond workloads Greg Kroah-Hartman
` (838 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ian Rogers, Namhyung Kim,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ian Rogers <irogers@google.com>
[ Upstream commit b58261584d2f6b5241ac1693026242ef2f2148b4 ]
Setup qemu with KVM then run kvm stat and some host
recording/reporting/build-id tests.
Signed-off-by: Ian Rogers <irogers@google.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Stable-dep-of: 509a2b9a6e14 ("perf tests: Fix flakiness in trace record and replay test")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/tests/shell/kvm.sh | 154 ++++++++++++++++++++++++++++++++++
1 file changed, 154 insertions(+)
create mode 100755 tools/perf/tests/shell/kvm.sh
diff --git a/tools/perf/tests/shell/kvm.sh b/tools/perf/tests/shell/kvm.sh
new file mode 100755
index 0000000000000..2fafde1a29cca
--- /dev/null
+++ b/tools/perf/tests/shell/kvm.sh
@@ -0,0 +1,154 @@
+#!/bin/bash
+# perf kvm tests
+# SPDX-License-Identifier: GPL-2.0
+
+set -e
+
+err=0
+perfdata=$(mktemp /tmp/__perf_kvm_test.perf.data.XXXXX)
+qemu_pid_file=$(mktemp /tmp/__perf_kvm_test.qemu.pid.XXXXX)
+
+cleanup() {
+ rm -f "${perfdata}"
+ if [ -f "${qemu_pid_file}" ]; then
+ if [ -s "${qemu_pid_file}" ]; then
+ qemu_pid=$(cat "${qemu_pid_file}")
+ if [ -n "${qemu_pid}" ]; then
+ kill "${qemu_pid}" 2>/dev/null || true
+ fi
+ fi
+ rm -f "${qemu_pid_file}"
+ fi
+ trap - EXIT TERM INT
+}
+
+trap_cleanup() {
+ echo "Unexpected signal in ${FUNCNAME[1]}"
+ cleanup
+ exit 1
+}
+trap trap_cleanup EXIT TERM INT
+
+skip() {
+ echo "Skip: $1"
+ cleanup
+ exit 2
+}
+
+test_kvm_stat() {
+ echo "Testing perf kvm stat"
+
+ echo "Recording kvm events for pid ${qemu_pid}..."
+ if ! perf kvm stat record -p "${qemu_pid}" -o "${perfdata}" sleep 1; then
+ echo "Failed to record kvm events"
+ err=1
+ return
+ fi
+
+ echo "Reporting kvm events..."
+ if ! perf kvm -i "${perfdata}" stat report 2>&1 | grep -q "VM-EXIT"; then
+ echo "Failed to find VM-EXIT in report"
+ perf kvm -i "${perfdata}" stat report 2>&1
+ err=1
+ return
+ fi
+
+ echo "perf kvm stat test [Success]"
+}
+
+test_kvm_record_report() {
+ echo "Testing perf kvm record/report"
+
+ echo "Recording kvm profile for pid ${qemu_pid}..."
+ # Use --host to avoid needing guest symbols/mounts for this simple test
+ # We just want to verify the command runs and produces data
+ # We run in background and kill it because 'perf kvm record' appends options
+ # after the command, which breaks 'sleep' (e.g. it gets '-e cycles').
+ perf kvm --host record -p "${qemu_pid}" -o "${perfdata}" &
+ rec_pid=$!
+ sleep 1
+ kill -INT "${rec_pid}"
+ wait "${rec_pid}" || true
+
+ echo "Reporting kvm profile..."
+ # Check for some standard output from report
+ if ! perf kvm -i "${perfdata}" report --stdio 2>&1 | grep -q "Event count"; then
+ echo "Failed to report kvm profile"
+ perf kvm -i "${perfdata}" report --stdio 2>&1
+ err=1
+ return
+ fi
+
+ echo "perf kvm record/report test [Success]"
+}
+
+test_kvm_buildid_list() {
+ echo "Testing perf kvm buildid-list"
+
+ # We reuse the perf.data from the previous record test
+ if ! perf kvm --host -i "${perfdata}" buildid-list 2>&1 | grep -q "."; then
+ echo "Failed to list buildids"
+ perf kvm --host -i "${perfdata}" buildid-list 2>&1
+ err=1
+ return
+ fi
+
+ echo "perf kvm buildid-list test [Success]"
+}
+
+setup_qemu() {
+ # Find qemu
+ if [ "$(uname -m)" = "x86_64" ]; then
+ qemu="qemu-system-x86_64"
+ elif [ "$(uname -m)" = "aarch64" ]; then
+ qemu="qemu-system-aarch64"
+ elif [ "$(uname -m)" = "s390x" ]; then
+ qemu="qemu-system-s390x"
+ elif [ "$(uname -m)" = "ppc64le" ]; then
+ qemu="qemu-system-ppc64"
+ else
+ qemu="qemu-system-$(uname -m)"
+ fi
+
+ if ! which -s "$qemu"; then
+ skip "$qemu not found"
+ fi
+
+ if [ ! -r /dev/kvm ] || [ ! -w /dev/kvm ]; then
+ skip "/dev/kvm not accessible"
+ fi
+
+ if ! perf kvm stat record -a sleep 0.01 >/dev/null 2>&1; then
+ skip "No permission to record kvm events"
+ fi
+
+ echo "Starting $qemu..."
+ # Start qemu in background, detached, with pidfile
+ # We use -display none -daemonize and a monitor to keep it alive/controllable if needed
+ # We don't need a real kernel, just KVM active.
+ if ! $qemu -enable-kvm -display none -daemonize -pidfile "${qemu_pid_file}" -monitor none; then
+ echo "Failed to start qemu"
+ err=1
+ return
+ fi
+
+ # Wait a bit for qemu to start
+ sleep 1
+ qemu_pid=$(cat "${qemu_pid_file}")
+
+ if ! kill -0 "${qemu_pid}" 2>/dev/null; then
+ echo "Qemu process failed to stay alive"
+ err=1
+ return
+ fi
+}
+
+setup_qemu
+if [ $err -eq 0 ]; then
+ test_kvm_stat
+ test_kvm_record_report
+ test_kvm_buildid_list
+fi
+
+cleanup
+exit $err
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0161/1518] perf tests: Add robust record retry helper and use subsecond workloads
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (159 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0160/1518] perf test kvm: Add some basic perf kvm test coverage Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0162/1518] perf tests: Fix flakiness in trace record and replay test Greg Kroah-Hartman
` (837 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ian Rogers, Namhyung Kim,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ian Rogers <irogers@google.com>
[ Upstream commit 74dba58222f0d34cf8bd3eba1a6926e9654d4b6b ]
Introduce `perf_record_with_retry` and `perf_record_cleanup` in a shared
library `tests/shell/lib/perf_record.sh` to prevent record test failures
caused by transient recording or workload delays.
Update `record.sh`, `record_lbr.sh`, `pipe_test.sh`, `kvm.sh`, and
`stat_all_pfm.sh` to use this robust record retry logic. These tests now
start with very short durations (e.g. 0.01 seconds) and scale up if the
initial recording failed to capture samples, significantly improving test
execution speed on success while remaining resilient to slow systems.
Assisted-by: Antigravity:gemini-3.1-pro
Signed-off-by: Ian Rogers <irogers@google.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Stable-dep-of: 509a2b9a6e14 ("perf tests: Fix flakiness in trace record and replay test")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/tests/shell/kvm.sh | 61 +++++---
tools/perf/tests/shell/lib/perf_record.sh | 53 +++++++
tools/perf/tests/shell/pipe_test.sh | 4 +-
tools/perf/tests/shell/record.sh | 173 +++++++++++-----------
tools/perf/tests/shell/record_lbr.sh | 50 +++++--
5 files changed, 214 insertions(+), 127 deletions(-)
create mode 100644 tools/perf/tests/shell/lib/perf_record.sh
diff --git a/tools/perf/tests/shell/kvm.sh b/tools/perf/tests/shell/kvm.sh
index 2fafde1a29cca..85089f8c2d48b 100755
--- a/tools/perf/tests/shell/kvm.sh
+++ b/tools/perf/tests/shell/kvm.sh
@@ -38,17 +38,28 @@ skip() {
test_kvm_stat() {
echo "Testing perf kvm stat"
- echo "Recording kvm events for pid ${qemu_pid}..."
- if ! perf kvm stat record -p "${qemu_pid}" -o "${perfdata}" sleep 1; then
- echo "Failed to record kvm events"
- err=1
- return
- fi
+ local duration
+ local success=false
+ for duration in 1 2 4 8; do
+ echo "Recording kvm events for pid ${qemu_pid} (duration ${duration}s)..."
+ rm -f "${perfdata}" "${perfdata}".old
+ if ! perf kvm stat record -p "${qemu_pid}" -o "${perfdata}" \
+ sleep ${duration} >/dev/null 2>&1; then
+ echo "perf kvm stat record failed, retrying..."
+ continue
+ fi
+
+ if [ -e "${perfdata}" ] && \
+ perf kvm -i "${perfdata}" stat report 2>&1 | grep -q "VM-EXIT"; then
+ success=true
+ break
+ fi
+ echo "No VM-EXIT events found, retrying..."
+ done
- echo "Reporting kvm events..."
- if ! perf kvm -i "${perfdata}" stat report 2>&1 | grep -q "VM-EXIT"; then
+ if [ "$success" = false ]; then
echo "Failed to find VM-EXIT in report"
- perf kvm -i "${perfdata}" stat report 2>&1
+ perf kvm -i "${perfdata}" stat report 2>&1 || true
err=1
return
fi
@@ -59,22 +70,26 @@ test_kvm_stat() {
test_kvm_record_report() {
echo "Testing perf kvm record/report"
- echo "Recording kvm profile for pid ${qemu_pid}..."
- # Use --host to avoid needing guest symbols/mounts for this simple test
- # We just want to verify the command runs and produces data
- # We run in background and kill it because 'perf kvm record' appends options
- # after the command, which breaks 'sleep' (e.g. it gets '-e cycles').
- perf kvm --host record -p "${qemu_pid}" -o "${perfdata}" &
- rec_pid=$!
- sleep 1
- kill -INT "${rec_pid}"
- wait "${rec_pid}" || true
+ local duration
+ local success=false
+ for duration in 1 2 4 8; do
+ echo "Recording kvm profile for pid ${qemu_pid} (duration ${duration}s)..."
+ rm -f "${perfdata}" "${perfdata}".old
+
+ perf kvm --host record -p "${qemu_pid}" -o "${perfdata}" \
+ -e cpu-clock sleep ${duration}
+
+ if [ -e "${perfdata}" ] && \
+ perf kvm -i "${perfdata}" report --stdio 2>&1 | grep -q "Event count"; then
+ success=true
+ break
+ fi
+ echo "No samples or report failed, retrying..."
+ done
- echo "Reporting kvm profile..."
- # Check for some standard output from report
- if ! perf kvm -i "${perfdata}" report --stdio 2>&1 | grep -q "Event count"; then
+ if [ "$success" = false ]; then
echo "Failed to report kvm profile"
- perf kvm -i "${perfdata}" report --stdio 2>&1
+ perf kvm -i "${perfdata}" report --stdio 2>&1 || true
err=1
return
fi
diff --git a/tools/perf/tests/shell/lib/perf_record.sh b/tools/perf/tests/shell/lib/perf_record.sh
new file mode 100644
index 0000000000000..e137fa75370de
--- /dev/null
+++ b/tools/perf/tests/shell/lib/perf_record.sh
@@ -0,0 +1,53 @@
+# SPDX-License-Identifier: GPL-2.0
+
+PERF_RECORD_LOGS=()
+
+perf_record_with_retry() {
+ local perfdata="$1"
+ local check_cmd="$2"
+ local testprog_base="$3"
+ shift 3
+
+ local logfile
+ logfile=$(mktemp /tmp/__perf_record_retry.XXXXXX)
+ PERF_RECORD_LOGS+=("$logfile")
+
+ # Save the e flag state and disable it
+ local save_e
+ if [[ $- == *e* ]]; then
+ save_e="set -e"
+ else
+ save_e="set +e"
+ fi
+ set +e
+
+ local duration
+ local first_run=true
+ local ret=1
+ for duration in 0.01 0.1 0.3 1.0 2.0; do
+ rm -f "${perfdata}".old
+ perf record "$@" -o "${perfdata}" ${testprog_base} ${duration} > "$logfile" 2>&1
+ local record_exit=$?
+
+ if [ "$first_run" = true ] && [ $record_exit -ne 0 ]; then
+ ret=2
+ break
+ fi
+ first_run=false
+
+ if [ -e "${perfdata}" ] && eval "${check_cmd}"; then
+ ret=0
+ break
+ fi
+ done
+
+ eval "$save_e"
+ return $ret
+}
+
+perf_record_cleanup() {
+ for logfile in "${PERF_RECORD_LOGS[@]}"; do
+ rm -f "$logfile"
+ done
+ PERF_RECORD_LOGS=()
+}
diff --git a/tools/perf/tests/shell/pipe_test.sh b/tools/perf/tests/shell/pipe_test.sh
index e459aa99a9515..ce68d850c9838 100755
--- a/tools/perf/tests/shell/pipe_test.sh
+++ b/tools/perf/tests/shell/pipe_test.sh
@@ -12,8 +12,8 @@ skip_test_missing_symbol ${sym}
data=$(mktemp /tmp/perf.data.XXXXXX)
data2=$(mktemp /tmp/perf.data2.XXXXXX)
-prog="perf test -w noploop"
-[ "$(uname -m)" = "s390x" ] && prog="$prog 3"
+prog="perf test -w noploop 0.1"
+[ "$(uname -m)" = "s390x" ] && prog="perf test -w noploop 3"
err=0
set -e
diff --git a/tools/perf/tests/shell/record.sh b/tools/perf/tests/shell/record.sh
index 0f5841c479e75..fc78ca52075c4 100755
--- a/tools/perf/tests/shell/record.sh
+++ b/tools/perf/tests/shell/record.sh
@@ -1,10 +1,13 @@
#!/bin/bash
-# perf record tests (exclusive)
# SPDX-License-Identifier: GPL-2.0
+# perf record tests
set -e
shelldir=$(dirname "$0")
+. "${shelldir}"/lib/perf_record.sh
+
+
# shellcheck source=lib/waiting.sh
. "${shelldir}"/lib/waiting.sh
@@ -39,6 +42,7 @@ cleanup() {
rm -f "${perfdata}"
rm -f "${perfdata}".old
rm -f "${script_output}"
+ perf_record_cleanup
trap - EXIT TERM INT
}
@@ -50,22 +54,20 @@ trap_cleanup() {
}
trap trap_cleanup EXIT TERM INT
+check_per_thread() {
+ perf report -i "${perfdata}" -q | grep -q "${testsym}"
+}
+
test_per_thread() {
echo "Basic --per-thread mode test"
- if ! perf record -o /dev/null --quiet ${testprog} 2> /dev/null
- then
+ local ret=0
+ perf_record_with_retry "${perfdata}" "check_per_thread" "perf test -w thloop" \
+ --per-thread || ret=$?
+ if [ $ret -eq 2 ]; then
echo "Per-thread record [Skipped event not supported]"
return
- fi
- if ! perf record --per-thread -o "${perfdata}" ${testprog} 2> /dev/null
- then
- echo "Per-thread record [Failed record]"
- err=1
- return
- fi
- if ! perf report -i "${perfdata}" -q | grep -q "${testsym}"
- then
- echo "Per-thread record [Failed missing output]"
+ elif [ $ret -eq 1 ]; then
+ echo "Per-thread record [Failed record or missing output]"
err=1
return
fi
@@ -96,6 +98,10 @@ test_per_thread() {
echo "Basic --per-thread mode test [Success]"
}
+check_register_capture() {
+ perf script -F ip,sym,iregs -i "${perfdata}" 2>/dev/null | grep -q "DI:"
+}
+
test_register_capture() {
echo "Register capture test"
if ! perf list pmu | grep -q 'br_inst_retired.near_call'
@@ -108,11 +114,12 @@ test_register_capture() {
echo "Register capture test [Skipped missing registers]"
return
fi
- if ! perf record -o - --intr-regs=di,r8,dx,cx -e br_inst_retired.near_call \
- -c 1000 --per-thread ${testprog} 2> /dev/null \
- | perf script -F ip,sym,iregs -i - 2> /dev/null \
- | grep -q "DI:"
- then
+
+ local ret=0
+ perf_record_with_retry "${perfdata}" "check_register_capture" "perf test -w thloop" \
+ --intr-regs=di,r8,dx,cx -e br_inst_retired.near_call -c 1000 --per-thread || ret=$?
+
+ if [ $ret -ne 0 ]; then
echo "Register capture test [Failed missing output]"
err=1
return
@@ -120,65 +127,66 @@ test_register_capture() {
echo "Register capture test [Success]"
}
+check_system_wide() {
+ perf report -i "${perfdata}" -q | grep -q "${testsym}"
+}
+
test_system_wide() {
echo "Basic --system-wide mode test"
- if ! perf record -aB --synth=no -o "${perfdata}" ${testprog} 2> /dev/null
- then
+ local ret=0
+ perf_record_with_retry "${perfdata}" "check_system_wide" "perf test -w thloop" \
+ -aB --synth=no || ret=$?
+ if [ $ret -eq 2 ]; then
echo "System-wide record [Skipped not supported]"
return
- fi
- if ! perf report -i "${perfdata}" -q | grep -q "${testsym}"
- then
+ elif [ $ret -eq 1 ]; then
echo "System-wide record [Failed missing output]"
err=1
return
fi
- if ! perf record -aB --synth=no -e cpu-clock,cs --threads=cpu \
- -o "${perfdata}" ${testprog} 2> /dev/null
- then
- echo "System-wide record [Failed record --threads option]"
- err=1
- return
- fi
- if ! perf report -i "${perfdata}" -q | grep -q "${testsym}"
- then
- echo "System-wide record [Failed --threads missing output]"
+
+ ret=0
+ perf_record_with_retry "${perfdata}" "check_system_wide" "perf test -w thloop" \
+ -aB --synth=no -e cpu-clock,cs --threads=cpu || ret=$?
+ if [ $ret -ne 0 ]; then
+ echo "System-wide record [Failed record --threads option or missing output]"
err=1
return
fi
echo "Basic --system-wide mode test [Success]"
}
+check_workload() {
+ perf report -i "${perfdata}" -q | grep -q "${testsym}"
+}
+
test_workload() {
echo "Basic target workload test"
- if ! perf record -o "${perfdata}" ${testprog} 2> /dev/null
- then
- echo "Workload record [Failed record]"
+ local ret=0
+ perf_record_with_retry "${perfdata}" "check_workload" "perf test -w thloop" || ret=$?
+ if [ $ret -ne 0 ]; then
+ echo "Workload record [Failed record or missing output]"
err=1
return
fi
- if ! perf report -i "${perfdata}" -q | grep -q "${testsym}"
- then
- echo "Workload record [Failed missing output]"
- err=1
- return
- fi
- if ! perf record -e cpu-clock,cs --threads=package \
- -o "${perfdata}" ${testprog} 2> /dev/null
- then
- echo "Workload record [Failed record --threads option]"
- err=1
- return
- fi
- if ! perf report -i "${perfdata}" -q | grep -q "${testsym}"
- then
- echo "Workload record [Failed --threads missing output]"
+
+ ret=0
+ perf_record_with_retry "${perfdata}" "check_workload" "perf test -w thloop" \
+ -e cpu-clock,cs --threads=package || ret=$?
+ if [ $ret -ne 0 ]; then
+ echo "Workload record [Failed record --threads option or missing output]"
err=1
return
fi
echo "Basic target workload test [Success]"
}
+check_branch_counter() {
+ perf report -i "${perfdata}" -D -q 2>/dev/null | grep -q "$br_cntr_output" && \
+ perf script -i "${perfdata}" -F +brstackinsn,+brcntr 2>/dev/null | \
+ grep -q "$br_cntr_script_output"
+}
+
test_branch_counter() {
echo "Branch counter test"
# Check if the branch counter feature is supported
@@ -190,67 +198,60 @@ test_branch_counter() {
return
fi
done
- if ! perf record -o "${perfdata}" -e "{branches:p,instructions}" -j any,counter ${testprog} 2> /dev/null
- then
- echo "Branch counter record test [Failed record]"
- err=1
- return
- fi
- if ! perf report -i "${perfdata}" -D -q | grep -q "$br_cntr_output"
- then
- echo "Branch counter report test [Failed missing output]"
- err=1
- return
- fi
- if ! perf script -i "${perfdata}" -F +brstackinsn,+brcntr | grep -q "$br_cntr_script_output"
- then
- echo " Branch counter script test [Failed missing output]"
+ local ret=0
+ perf_record_with_retry "${perfdata}" "check_branch_counter" "perf test -w thloop" \
+ -e "{branches:p,instructions}" -j any,counter || ret=$?
+ if [ $ret -ne 0 ]; then
+ echo "Branch counter test [Failed record or missing output]"
err=1
return
fi
echo "Branch counter test [Success]"
}
+check_cgroup() {
+ perf report -i "${perfdata}" -D 2>/dev/null | grep -q "CGROUP" && \
+ perf script -i "${perfdata}" -F cgroup 2>/dev/null | grep -q -v "unknown"
+}
+
test_cgroup() {
echo "Cgroup sampling test"
- if ! perf record -aB --synth=cgroup --all-cgroups -o "${perfdata}" ${testprog} 2> /dev/null
- then
+ local ret=0
+ perf_record_with_retry "${perfdata}" "check_cgroup" "perf test -w thloop" \
+ -aB --synth=cgroup --all-cgroups || ret=$?
+ if [ $ret -eq 2 ]; then
echo "Cgroup sampling [Skipped not supported]"
return
- fi
- if ! perf report -i "${perfdata}" -D | grep -q "CGROUP"
- then
+ elif [ $ret -eq 1 ]; then
echo "Cgroup sampling [Failed missing output]"
err=1
return
fi
- if ! perf script -i "${perfdata}" -F cgroup | grep -q -v "unknown"
- then
- echo "Cgroup sampling [Failed cannot resolve cgroup names]"
- err=1
- return
- fi
echo "Cgroup sampling test [Success]"
}
+check_uid() {
+ perf report -i "${perfdata}" -q | grep -q "${testsym}"
+}
+
test_uid() {
echo "Uid sampling test"
- if ! perf record -aB --synth=no --uid "$(id -u)" -o "${perfdata}" ${testprog} \
- > "${script_output}" 2>&1
- then
- if grep -q "libbpf.*EPERM" "${script_output}"
+ local ret=0
+ perf_record_with_retry "${perfdata}" "check_uid" "perf test -w thloop" \
+ -aB --synth=no --uid "$(id -u)" || ret=$?
+ if [ $ret -eq 2 ]; then
+ local logfile="${PERF_RECORD_LOGS[${#PERF_RECORD_LOGS[@]}-1]}"
+ if grep -q -E "libbpf.*EPERM|Access to performance monitoring" "$logfile" || \
+ grep -q -E "Permission denied|Failure to open any events" "$logfile"
then
echo "Uid sampling [Skipped permissions]"
return
else
echo "Uid sampling [Failed to record]"
err=1
- # cat "${script_output}"
return
fi
- fi
- if ! perf report -i "${perfdata}" -q | grep -q "${testsym}"
- then
+ elif [ $ret -eq 1 ]; then
echo "Uid sampling [Failed missing output]"
err=1
return
diff --git a/tools/perf/tests/shell/record_lbr.sh b/tools/perf/tests/shell/record_lbr.sh
index 78a02e90ece1e..8d51afeb437ba 100755
--- a/tools/perf/tests/shell/record_lbr.sh
+++ b/tools/perf/tests/shell/record_lbr.sh
@@ -1,9 +1,12 @@
#!/bin/bash
-# perf record LBR tests (exclusive)
# SPDX-License-Identifier: GPL-2.0
+# perf record LBR tests
set -e
+shelldir=$(dirname "$0")
+. "${shelldir}"/lib/perf_record.sh
+
ParanoidAndNotRoot() {
[ "$(id -u)" != 0 ] && [ "$(cat /proc/sys/kernel/perf_event_paranoid)" -gt $1 ]
}
@@ -22,6 +25,7 @@ cleanup() {
rm -rf "${perfdata}"
rm -rf "${perfdata}".old
rm -rf "${perfdata}".txt
+ perf_record_cleanup
trap - EXIT TERM INT
}
@@ -34,22 +38,28 @@ trap_cleanup() {
trap trap_cleanup EXIT TERM INT
+check_lbr_callgraph() {
+ perf report --stitch-lbr -i "${perfdata}" > "${perfdata}".txt 2>&1
+}
+
lbr_callgraph_test() {
test="LBR callgraph"
echo "$test"
- if ! perf record -e cycles --call-graph lbr -o "${perfdata}" perf test -w thloop
- then
+ set +e
+ perf_record_with_retry "${perfdata}" "check_lbr_callgraph" "perf test -w thloop" \
+ -e cycles --call-graph lbr
+ local ret=$?
+ set -e
+
+ if [ $ret -eq 2 ]; then
echo "$test [Failed support missing]"
if [ $err -eq 0 ]
then
err=2
fi
return
- fi
-
- if ! perf report --stitch-lbr -i "${perfdata}" > "${perfdata}".txt
- then
+ elif [ $ret -eq 1 ]; then
cat "${perfdata}".txt
echo "$test [Failed in perf report]"
err=1
@@ -59,6 +69,12 @@ lbr_callgraph_test() {
echo "$test [Success]"
}
+check_lbr_samples() {
+ local out
+ out=$(perf report -D -i "${perfdata}" 2> /dev/null | grep -A1 'PERF_RECORD_SAMPLE')
+ [ "$(echo "$out" | grep -c 'PERF_RECORD_SAMPLE' || true)" -gt 0 ]
+}
+
lbr_test() {
local branch_flags=$1
local test="LBR $2 test"
@@ -70,25 +86,27 @@ lbr_test() {
local r
echo "$test"
- if ! perf record -e cycles $branch_flags -o "${perfdata}" perf test -w thloop
- then
+ set +e
+ perf_record_with_retry "${perfdata}" "check_lbr_samples" "perf test -w thloop" \
+ -e cycles $branch_flags
+ local ret=$?
+ set -e
+
+ if [ $ret -eq 2 ]; then
echo "$test [Failed support missing]"
- perf record -e cycles $branch_flags -o "${perfdata}" perf test -w thloop || true
if [ $err -eq 0 ]
then
err=2
fi
return
- fi
-
- out=$(perf report -D -i "${perfdata}" 2> /dev/null | grep -A1 'PERF_RECORD_SAMPLE')
- sam_nr=$(echo "$out" | grep -c 'PERF_RECORD_SAMPLE' || true)
- if [ $sam_nr -eq 0 ]
- then
+ elif [ $ret -eq 1 ]; then
echo "$test [Failed no samples captured]"
err=1
return
fi
+
+ out=$(perf report -D -i "${perfdata}" 2> /dev/null | grep -A1 'PERF_RECORD_SAMPLE')
+ sam_nr=$(echo "$out" | grep -c 'PERF_RECORD_SAMPLE' || true)
echo "$test: $sam_nr samples"
bs_nr=$(echo "$out" | grep -c 'branch stack: nr:' || true)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0162/1518] perf tests: Fix flakiness in trace record and replay test
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (160 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0161/1518] perf tests: Add robust record retry helper and use subsecond workloads Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0163/1518] perf test: Fix perf stat --bpf-counters on hybrid machines Greg Kroah-Hartman
` (836 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ian Rogers, Namhyung Kim,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ian Rogers <irogers@google.com>
[ Upstream commit 509a2b9a6e142697dd5f34cdd802e5b86eababa1 ]
The `perf trace record and replay` test fails intermittently on slow or
virtualized hosts because the default recording workload (`sleep 1`)
occasionally completes without scheduling the target `nanosleep` or
`clock_nanosleep` system calls inside the recorded sample window,
resulting in the error: `Failed: cannot find *nanosleep syscall`.
Generalize the `perf_record_with_retry` helper in
`tests/shell/lib/perf_record.sh` to support a custom record command prefix
via the `PERF_RECORD_CMD` environment variable (defaulting to "perf
record").
Update `trace_record_replay.sh` to use this robust retry loop running with
`PERF_RECORD_CMD="perf trace record"` and a base workload of `sleep`. The
test will automatically retry with scaled sleep durations (from 0.01s up
to 2.0s) until the required `nanosleep` event is successfully captured.
Fixes: 15bcfb96d0dd ("perf test: Add trace record and replay test")
Assisted-by: Antigravity:gemini-3.1-pro
Signed-off-by: Ian Rogers <irogers@google.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/tests/shell/lib/perf_record.sh | 7 +++-
tools/perf/tests/shell/trace_record_replay.sh | 38 +++++++++++++++++--
2 files changed, 40 insertions(+), 5 deletions(-)
diff --git a/tools/perf/tests/shell/lib/perf_record.sh b/tools/perf/tests/shell/lib/perf_record.sh
index e137fa75370de..2b9e11b66dc7a 100644
--- a/tools/perf/tests/shell/lib/perf_record.sh
+++ b/tools/perf/tests/shell/lib/perf_record.sh
@@ -24,9 +24,14 @@ perf_record_with_retry() {
local duration
local first_run=true
local ret=1
+ local cmd_prefix="perf record"
+ if [ -n "${PERF_RECORD_CMD}" ]; then
+ cmd_prefix="${PERF_RECORD_CMD}"
+ fi
+
for duration in 0.01 0.1 0.3 1.0 2.0; do
rm -f "${perfdata}".old
- perf record "$@" -o "${perfdata}" ${testprog_base} ${duration} > "$logfile" 2>&1
+ ${cmd_prefix} "$@" -o "${perfdata}" ${testprog_base} ${duration} > "$logfile" 2>&1
local record_exit=$?
if [ "$first_run" = true ] && [ $record_exit -ne 0 ]; then
diff --git a/tools/perf/tests/shell/trace_record_replay.sh b/tools/perf/tests/shell/trace_record_replay.sh
index 88d30a03dcecb..38fcafcdfb91c 100755
--- a/tools/perf/tests/shell/trace_record_replay.sh
+++ b/tools/perf/tests/shell/trace_record_replay.sh
@@ -6,16 +6,46 @@
# shellcheck source=lib/probe.sh
. "$(dirname $0)"/lib/probe.sh
+# shellcheck source=lib/perf_record.sh
+. "$(dirname $0)"/lib/perf_record.sh
skip_if_no_perf_trace || exit 2
[ "$(id -u)" = 0 ] || exit 2
file=$(mktemp /tmp/temporary_file.XXXXX)
+err=0
-perf trace record -o ${file} sleep 1 || exit 1
-if ! perf trace -i ${file} 2>&1 | grep nanosleep; then
- echo "Failed: cannot find *nanosleep syscall"
+cleanup() {
+ rm -f ${file}
+ perf_record_cleanup
+ trap - EXIT INT TERM
+}
+
+trap_cleanup() {
+ echo "Unexpected signal in ${FUNCNAME[1]}"
+ cleanup
+ exit 1
+}
+trap trap_cleanup EXIT INT TERM
+
+check_nanosleep() {
+ perf trace -i "${file}" 2>&1 | grep -q nanosleep
+}
+
+PERF_RECORD_CMD="perf trace record" perf_record_with_retry "${file}" "check_nanosleep" "sleep"
+err=$?
+
+if [ $err -ne 0 ]; then
+ if [ $err -eq 2 ]; then
+ logfile="${PERF_RECORD_LOGS[${#PERF_RECORD_LOGS[@]}-1]}"
+ echo "perf trace record failed. Log output:"
+ cat "$logfile"
+ else
+ echo "Failed: cannot find *nanosleep syscall"
+ fi
+ cleanup
exit 1
fi
-rm -f ${file}
+cleanup
+exit 0
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0163/1518] perf test: Fix perf stat --bpf-counters on hybrid machines
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (161 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0162/1518] perf tests: Fix flakiness in trace record and replay test Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0164/1518] perf tests: Fix flakiness in BPF counters test on hybrid systems Greg Kroah-Hartman
` (835 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ian Rogers, Namhyung Kim,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namhyung Kim <namhyung@kernel.org>
[ Upstream commit d9db9c8db56c3e378aa5c91637664f77ca5a6f72 ]
The test constantly fails on my Intel hybrid machine. The issue was it
has two events in the output even if I only gave it one event.
$ perf stat -e instructions -- perf test -w sqrtloop
Performance counter stats for 'perf test -w sqrtloop':
910,856,421 cpu_atom/instructions/ (28.05%)
14,852,865,997 cpu_core/instructions/ (96.79%)
1.014313341 seconds time elapsed
1.004114000 seconds user
0.008174000 seconds sys
Let's modify the awk script to add the values for each line and print
the total. The variable 'i' has a number of input lines that have valid
output and variable 'c' has the sum of actual counter values. That way
it should work on any platforms.
Reviewed-by: Ian Rogers <irogers@google.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Stable-dep-of: b02027776ac5 ("perf tests: Fix flakiness in BPF counters test on hybrid systems")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/tests/shell/stat_bpf_counters.sh | 20 ++++++++++++++++----
1 file changed, 16 insertions(+), 4 deletions(-)
diff --git a/tools/perf/tests/shell/stat_bpf_counters.sh b/tools/perf/tests/shell/stat_bpf_counters.sh
index f43e28a136d3c..35463358b273c 100755
--- a/tools/perf/tests/shell/stat_bpf_counters.sh
+++ b/tools/perf/tests/shell/stat_bpf_counters.sh
@@ -41,8 +41,14 @@ check_counts()
test_bpf_counters()
{
printf "Testing --bpf-counters "
- base_instructions=$(perf stat --no-big-num -e instructions -- $workload 2>&1 | awk '/instructions/ {print $1}')
- bpf_instructions=$(perf stat --no-big-num --bpf-counters -e instructions -- $workload 2>&1 | awk '/instructions/ {print $1}')
+ base_instructions=$(perf stat --no-big-num -e instructions -- $workload 2>&1 | \
+ awk -v i=0 -v c=0 '/instructions/ { \
+ if ($1 != "<not") { i++; c += $1 } \
+ } END { if (i > 0) printf "%.0f", c; else print "<not" }')
+ bpf_instructions=$(perf stat --no-big-num --bpf-counters -e instructions -- $workload 2>&1 | \
+ awk -v i=0 -v c=0 '/instructions/ { \
+ if ($1 != "<not") { i++; c += $1 } \
+ } END { if (i > 0) printf "%.0f", c; else print "<not" }')
check_counts $base_instructions $bpf_instructions
compare_number $base_instructions $bpf_instructions
echo "[Success]"
@@ -52,8 +58,14 @@ test_bpf_modifier()
{
printf "Testing bpf event modifier "
stat_output=$(perf stat --no-big-num -e instructions/name=base_instructions/,instructions/name=bpf_instructions/b -- $workload 2>&1)
- base_instructions=$(echo "$stat_output"| awk '/base_instructions/ {print $1}')
- bpf_instructions=$(echo "$stat_output"| awk '/bpf_instructions/ {print $1}')
+ base_instructions=$(echo "$stat_output"| \
+ awk -v i=0 -v c=0 '/base_instructions/ { \
+ if ($1 != "<not") { i++; c += $1 } \
+ } END { if (i > 0) printf "%.0f", c; else print "<not" }')
+ bpf_instructions=$(echo "$stat_output"| \
+ awk -v i=0 -v c=0 '/bpf_instructions/ { \
+ if ($1 != "<not") { i++; c += $1 } \
+ } END { if (i > 0) printf "%.0f", c; else print "<not" }')
check_counts $base_instructions $bpf_instructions
compare_number $base_instructions $bpf_instructions
echo "[Success]"
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0164/1518] perf tests: Fix flakiness in BPF counters test on hybrid systems
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (162 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0163/1518] perf test: Fix perf stat --bpf-counters on hybrid machines Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0165/1518] perf test: Fixes for check branch stack sampling Greg Kroah-Hartman
` (834 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ian Rogers, Namhyung Kim,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ian Rogers <irogers@google.com>
[ Upstream commit b02027776ac5bf737f1b76f3759f405e376097e5 ]
The `perf stat --bpf-counters test` fails intermittently on hybrid
architectures or systems with dynamic frequency scaling (DVFS). This
happens because the test workload (`sqrtloop`) runs for a fixed 1-second
duration, and the CPU frequency can scale dynamically between idle and
maximum frequency. As the first run runs on a cold CPU and the second run
runs on a warmed-up CPU (or vice versa), the number of instructions
executed in 1 second differs by up to 2.2x, violating the comparison
tolerance.
Also, when running as root, BPF tracepoints and scheduling programs
trigger frequently. Since standard `perf stat -e instructions` measures
both user and kernel space instructions, it counts BPF helper and program
execution overheads, whereas the BPF counters themselves do not self-
measure. This introduces a large kernel-space instruction count
discrepancy between standard and BPF counters.
Fix these issues by:
1. Switching the workload to a strictly deterministic, iteration-based
workload: `awk 'BEGIN { for (i=0; i<10000000; i++) sum+=i }'`. We pin
the
workload to a single random allowed CPU using `taskset -c $CPU` via a
bash array.
2. Restricting the counted event to user-space only (`instructions:u` or
`/u`).
3. Tightening the comparison tolerance from 20% to 15%.
These modifications isolate the measurements to user-space instructions of
the deterministic loop, which executes a virtually identical number of
instructions on both runs (with less than 0.001% variation), eliminating
Dynamic Frequency Scaling (DVFS), kernel scheduling noise, and BPF helper
self-measurement overheads.
Fixes: 2c0cb9f56020 ("perf test: Add a shell test for 'perf stat --bpf-counters' new option")
Assisted-by: Antigravity:gemini-3.1-pro
Signed-off-by: Ian Rogers <irogers@google.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/tests/shell/stat_bpf_counters.sh | 28 +++++++++++++--------
1 file changed, 18 insertions(+), 10 deletions(-)
diff --git a/tools/perf/tests/shell/stat_bpf_counters.sh b/tools/perf/tests/shell/stat_bpf_counters.sh
index 35463358b273c..11de77ee38ad4 100755
--- a/tools/perf/tests/shell/stat_bpf_counters.sh
+++ b/tools/perf/tests/shell/stat_bpf_counters.sh
@@ -4,21 +4,26 @@
set -e
-workload="perf test -w sqrtloop"
+# Get the first allowed CPU
+CPU=$(taskset -c -p $$ | awk -F': ' '{print $2}' | awk -F'[,-]' '{print $1}')
+if [ -z "$CPU" ]; then
+ CPU=0
+fi
+workload=(taskset -c "$CPU" awk 'BEGIN { for (i=0; i<10000000; i++) sum+=i }')
-# check whether $2 is within +/- 20% of $1
+# check whether $2 is within +/- 15% of $1
compare_number()
{
first_num=$1
second_num=$2
- # upper bound is first_num * 120%
- upper=$(expr $first_num + $first_num / 5 )
- # lower bound is first_num * 80%
- lower=$(expr $first_num - $first_num / 5 )
+ # upper bound is first_num * 115%
+ upper=$(expr $first_num + $first_num / 20 \* 3 )
+ # lower bound is first_num * 85%
+ lower=$(expr $first_num - $first_num / 20 \* 3 )
if [ $second_num -gt $upper ] || [ $second_num -lt $lower ]; then
- echo "The difference between $first_num and $second_num are greater than 20%."
+ echo "The difference between $first_num and $second_num are greater than 15%."
exit 1
fi
}
@@ -41,11 +46,12 @@ check_counts()
test_bpf_counters()
{
printf "Testing --bpf-counters "
- base_instructions=$(perf stat --no-big-num -e instructions -- $workload 2>&1 | \
+ base_instructions=$(perf stat --no-big-num -e instructions:u -- "${workload[@]}" 2>&1 | \
awk -v i=0 -v c=0 '/instructions/ { \
if ($1 != "<not") { i++; c += $1 } \
} END { if (i > 0) printf "%.0f", c; else print "<not" }')
- bpf_instructions=$(perf stat --no-big-num --bpf-counters -e instructions -- $workload 2>&1 | \
+ bpf_instructions=$(perf stat --no-big-num --bpf-counters -e instructions:u \
+ -- "${workload[@]}" 2>&1 | \
awk -v i=0 -v c=0 '/instructions/ { \
if ($1 != "<not") { i++; c += $1 } \
} END { if (i > 0) printf "%.0f", c; else print "<not" }')
@@ -57,7 +63,9 @@ test_bpf_counters()
test_bpf_modifier()
{
printf "Testing bpf event modifier "
- stat_output=$(perf stat --no-big-num -e instructions/name=base_instructions/,instructions/name=bpf_instructions/b -- $workload 2>&1)
+ stat_output=$(perf stat --no-big-num \
+ -e instructions/name=base_instructions/u,instructions/name=bpf_instructions/bu \
+ -- "${workload[@]}" 2>&1)
base_instructions=$(echo "$stat_output"| \
awk -v i=0 -v c=0 '/base_instructions/ { \
if ($1 != "<not") { i++; c += $1 } \
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0165/1518] perf test: Fixes for check branch stack sampling
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (163 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0164/1518] perf tests: Fix flakiness in BPF counters test on hybrid systems Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0166/1518] perf tests: Fix flakiness in branch stack sampling tests Greg Kroah-Hartman
` (833 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ian Rogers, James Clark,
Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ian Rogers <irogers@google.com>
[ Upstream commit 86d1095fdb7017a93e9d7be875775f7e5aa5c2f5 ]
When filtering branch stack samples on user events they sample in user
land but may have come from the kernel. Aarch64 avoids leaking the
kernel address for kaslr reasons but other platforms, for now,
don't. Be more permissive in allowing kernel addresses in the source
of user branch stacks.
When filtering branch stack samples on kernel events they sample in
kernel land but may have come from user land. Avoid the target being a
user address but allow the source to be in user land. Aarch64 may not
leak the user land addresses (making them 0) but other platforms
do. As the kernel address sampling implies privelege, just allow this.
Increase the duration of the system call sampling test to make the
likelihood of sampling a system call higher (increased from 1000 to
8000 loops - a number found through experimentation on an Intel
Tigerlake laptop), also make the period of the event a prime number.
Put unneeded perf record output into a temporary file so that the test
output isn't cluttered. More clearly state which test is running and
the pass, fail or skipped result of the test.
These changes make the test on an Intel tigerlake laptop reliably pass
rather than reliably fail.
Signed-off-by: Ian Rogers <irogers@google.com>
Reviewed-by: James Clark <james.clark@linaro.org>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Stable-dep-of: 344d3aec164d ("perf tests: Fix flakiness in branch stack sampling tests")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/tests/shell/test_brstack.sh | 146 ++++++++++++++++---------
1 file changed, 96 insertions(+), 50 deletions(-)
diff --git a/tools/perf/tests/shell/test_brstack.sh b/tools/perf/tests/shell/test_brstack.sh
index 85233d435be63..eb5837f82e390 100755
--- a/tools/perf/tests/shell/test_brstack.sh
+++ b/tools/perf/tests/shell/test_brstack.sh
@@ -38,9 +38,13 @@ is_arm64() {
[ "$(uname -m)" = "aarch64" ];
}
+has_kaslr_bug() {
+ [ "$(uname -m)" != "aarch64" ];
+}
+
check_branches() {
if ! tr -s ' ' '\n' < "$TMPDIR/perf.script" | grep -E -m1 -q "$1"; then
- echo "Branches missing $1"
+ echo "ERROR: Branches missing $1"
err=1
fi
}
@@ -48,6 +52,8 @@ check_branches() {
test_user_branches() {
echo "Testing user branch stack sampling"
+ start_err=$err
+ err=0
perf record -o "$TMPDIR/perf.data" --branch-filter any,save_type,u -- ${TESTPROG} > "$TMPDIR/record.txt" 2>&1
perf script -i "$TMPDIR/perf.data" --fields brstacksym > "$TMPDIR/perf.script"
@@ -73,59 +79,88 @@ test_user_branches() {
perf script -i "$TMPDIR/perf.data" --fields brstack | \
tr ' ' '\n' > "$TMPDIR/perf.script"
- # There should be no kernel addresses with the u option, in either
- # source or target addresses.
- if grep -E -m1 "0x[89a-f][0-9a-f]{15}" $TMPDIR/perf.script; then
- echo "ERROR: Kernel address found in user mode"
+ # There should be no kernel addresses in the target with the u option.
+ local regex="0x[89a-f][0-9a-f]{15}"
+ if has_kaslr_bug; then
+ # If the system has a kaslr bug that may leak kernel addresses
+ # in the source of something like an ERET/SYSRET. Make the regex
+ # more specific and just check the target address is in user
+ # code.
+ regex="^0x[0-9a-f]{0,16}/0x[89a-f][0-9a-f]{15}/"
+ fi
+ if grep -q -E -m1 "$regex" $TMPDIR/perf.script; then
+ echo "Testing user branch stack sampling [Failed kernel address found in user mode]"
err=1
fi
# some branch types are still not being tested:
# IND COND_CALL COND_RET SYSRET SERROR NO_TX
+ if [ $err -eq 0 ]; then
+ echo "Testing user branch stack sampling [Passed]"
+ err=$start_err
+ else
+ echo "Testing user branch stack sampling [Failed]"
+ fi
}
test_trap_eret_branches() {
echo "Testing trap & eret branches"
+
if ! is_arm64; then
- echo "skip: not arm64"
+ echo "Testing trap & eret branches [Skipped not arm64]"
+ return
+ fi
+ start_err=$err
+ err=0
+ perf record -o $TMPDIR/perf.data --branch-filter any,save_type,u,k -- \
+ perf test -w traploop 1000 > "$TMPDIR/record.txt" 2>&1
+ perf script -i $TMPDIR/perf.data --fields brstacksym | \
+ tr ' ' '\n' > $TMPDIR/perf.script
+
+ # BRBINF<n>.TYPE == TRAP are mapped to PERF_BR_IRQ by the BRBE driver
+ check_branches "^trap_bench\+[^ ]+/[^ ]/IRQ/"
+ check_branches "^[^ ]+/trap_bench\+[^ ]+/ERET/"
+ if [ $err -eq 0 ]; then
+ echo "Testing trap & eret branches [Passed]"
+ err=$start_err
else
- perf record -o $TMPDIR/perf.data --branch-filter any,save_type,u,k -- \
- perf test -w traploop 1000
- perf script -i $TMPDIR/perf.data --fields brstacksym | \
- tr ' ' '\n' > $TMPDIR/perf.script
-
- # BRBINF<n>.TYPE == TRAP are mapped to PERF_BR_IRQ by the BRBE driver
- check_branches "^trap_bench\+[^ ]+/[^ ]/IRQ/"
- check_branches "^[^ ]+/trap_bench\+[^ ]+/ERET/"
+ echo "Testing trap & eret branches [Failed]"
fi
}
test_kernel_branches() {
- echo "Testing that k option only includes kernel source addresses"
+ echo "Testing kernel branch sampling"
- if ! perf record --branch-filter any,k -o- -- true > /dev/null; then
- echo "skip: not enough privileges"
+ if ! perf record --branch-filter any,k -o- -- true > "$TMPDIR/record.txt" 2>&1; then
+ echo "Testing that k option [Skipped not enough privileges]"
+ return
+ fi
+ start_err=$err
+ err=0
+ perf record -o $TMPDIR/perf.data --branch-filter any,k -- \
+ perf bench syscall basic --loop 1000 > "$TMPDIR/record.txt" 2>&1
+ perf script -i $TMPDIR/perf.data --fields brstack | \
+ tr ' ' '\n' > $TMPDIR/perf.script
+
+ # Example of branch entries:
+ # "0xffffffff93bda241/0xffffffff93bda20f/M/-/-/..."
+ # Source addresses come first in user or kernel code. Next is the target
+ # address that must be in the kernel.
+
+ # Look for source addresses with top bit set
+ if ! grep -q -E -m1 "^0x[89a-f][0-9a-f]{15}" $TMPDIR/perf.script; then
+ echo "Testing kernel branch sampling [Failed kernel branches missing]"
+ err=1
+ fi
+ # Look for no target addresses without top bit set
+ if grep -q -E -m1 "^0x[0-9a-f]{0,16}/0x[0-7][0-9a-f]{1,15}/" $TMPDIR/perf.script; then
+ echo "Testing kernel branch sampling [Failed user branches found]"
+ err=1
+ fi
+ if [ $err -eq 0 ]; then
+ echo "Testing kernel branch sampling [Passed]"
+ err=$start_err
else
- perf record -o $TMPDIR/perf.data --branch-filter any,k -- \
- perf bench syscall basic --loop 1000
- perf script -i $TMPDIR/perf.data --fields brstack | \
- tr ' ' '\n' > $TMPDIR/perf.script
-
- # Example of branch entries:
- # "0xffffffff93bda241/0xffffffff93bda20f/M/-/-/..."
- # Source addresses come first and target address can be either
- # userspace or kernel even with k option, as long as the source
- # is in kernel.
-
- #Look for source addresses with top bit set
- if ! grep -E -m1 "^0x[89a-f][0-9a-f]{15}" $TMPDIR/perf.script; then
- echo "ERROR: Kernel branches missing"
- err=1
- fi
- # Look for no source addresses without top bit set
- if grep -E -m1 "^0x[0-7][0-9a-f]{0,15}" $TMPDIR/perf.script; then
- echo "ERROR: User branches found with kernel filter"
- err=1
- fi
+ echo "Testing kernel branch sampling [Failed]"
fi
}
@@ -136,14 +171,15 @@ test_filter() {
test_filter_expect=$2
echo "Testing branch stack filtering permutation ($test_filter_filter,$test_filter_expect)"
- perf record -o "$TMPDIR/perf.data" --branch-filter "$test_filter_filter,save_type,u" -- ${TESTPROG} > "$TMPDIR/record.txt" 2>&1
+ perf record -o "$TMPDIR/perf.data" --branch-filter "$test_filter_filter,save_type,u" -- \
+ ${TESTPROG} > "$TMPDIR/record.txt" 2>&1
perf script -i "$TMPDIR/perf.data" --fields brstack > "$TMPDIR/perf.script"
# fail if we find any branch type that doesn't match any of the expected ones
# also consider UNKNOWN branch types (-)
if [ ! -s "$TMPDIR/perf.script" ]
then
- echo "Empty script output"
+ echo "Testing branch stack filtering [Failed empty script output]"
err=1
return
fi
@@ -154,26 +190,36 @@ test_filter() {
> "$TMPDIR/perf.script-filtered" || true
if [ -s "$TMPDIR/perf.script-filtered" ]
then
- echo "Unexpected branch filter in script output"
+ echo "Testing branch stack filtering [Failed unexpected branch filter]"
cat "$TMPDIR/perf.script"
err=1
return
fi
+ echo "Testing branch stack filtering [Passed]"
}
test_syscall() {
echo "Testing syscalls"
# skip if perf doesn't have enough privileges
- if ! perf record --branch-filter any,k -o- -- true > /dev/null; then
- echo "skip: not enough privileges"
+ if ! perf record --branch-filter any,k -o- -- true > "$TMPDIR/record.txt" 2>&1; then
+ echo "Testing syscalls [Skipped: not enough privileges]"
+ return
+ fi
+ start_err=$err
+ err=0
+ perf record -o $TMPDIR/perf.data --branch-filter \
+ any_call,save_type,u,k -c 10007 -- \
+ perf bench syscall basic --loop 8000 > "$TMPDIR/record.txt" 2>&1
+ perf script -i $TMPDIR/perf.data --fields brstacksym | \
+ tr ' ' '\n' > $TMPDIR/perf.script
+
+ check_branches "getppid[^ ]*/SYSCALL/"
+
+ if [ $err -eq 0 ]; then
+ echo "Testing syscalls [Passed]"
+ err=$start_err
else
- perf record -o $TMPDIR/perf.data --branch-filter \
- any_call,save_type,u,k -c 10000 -- \
- perf bench syscall basic --loop 1000
- perf script -i $TMPDIR/perf.data --fields brstacksym | \
- tr ' ' '\n' > $TMPDIR/perf.script
-
- check_branches "getppid[^ ]*/SYSCALL/"
+ echo "Testing syscalls [Failed]"
fi
}
set -e
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0166/1518] perf tests: Fix flakiness in branch stack sampling tests
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (164 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0165/1518] perf test: Fixes for check branch stack sampling Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0167/1518] regulator: tps6594: Fix device node reference leaks in multiphase loop Greg Kroah-Hartman
` (832 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ian Rogers, Namhyung Kim,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ian Rogers <irogers@google.com>
[ Upstream commit 344d3aec164dba83a5520f23a0d46e13e904a205 ]
The branch stack sampling test (test 130) runs short iteration-based
workloads to verify syscall, kernel, and trap branch stack sampling.
Specifically, `test_syscall()` and `test_kernel_branches()` run `perf
bench syscall basic` with loop counts of 8000 and 1000, and
`test_trap_eret_branches()` runs `traploop` with 1000 iterations.
Because these loop limits are extremely small, the total benchmark
runtimes last only a few milliseconds (or less). Under high load,
virtualization, or coarse sampling conditions, PMU cycle sampling fails to
capture enough samples inside the brief benchmark loops. This leads to
false negatives where the script output lacks the expected syscall,
kernel, or trap branch entries (e.g. "ERROR: Branches missing getppid[^
]*/SYSCALL/").
Fix this by increasing the workload loop counts to 100,000 across all
three test sections. Running 100,000 loops still finishes virtually
instantaneously (less than 0.1 seconds), but generates enough iterations
to guarantee robust branch stack capture.
Fixes: b55878c90ab9 ("perf test: Add test for branch stack sampling")
Assisted-by: Antigravity:gemini-3.1-pro
Signed-off-by: Ian Rogers <irogers@google.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/tests/shell/test_brstack.sh | 107 +++++++++++++++----------
1 file changed, 66 insertions(+), 41 deletions(-)
diff --git a/tools/perf/tests/shell/test_brstack.sh b/tools/perf/tests/shell/test_brstack.sh
index eb5837f82e390..71550e0b37baa 100755
--- a/tools/perf/tests/shell/test_brstack.sh
+++ b/tools/perf/tests/shell/test_brstack.sh
@@ -110,20 +110,29 @@ test_trap_eret_branches() {
return
fi
start_err=$err
- err=0
- perf record -o $TMPDIR/perf.data --branch-filter any,save_type,u,k -- \
- perf test -w traploop 1000 > "$TMPDIR/record.txt" 2>&1
- perf script -i $TMPDIR/perf.data --fields brstacksym | \
- tr ' ' '\n' > $TMPDIR/perf.script
-
- # BRBINF<n>.TYPE == TRAP are mapped to PERF_BR_IRQ by the BRBE driver
- check_branches "^trap_bench\+[^ ]+/[^ ]/IRQ/"
- check_branches "^[^ ]+/trap_bench\+[^ ]+/ERET/"
- if [ $err -eq 0 ]; then
+ local ret=1
+ for loops in 1000 10000 100000; do
+ err=0
+ perf record -o $TMPDIR/perf.data --branch-filter any,save_type,u,k -- \
+ perf test -w traploop $loops > "$TMPDIR/record.txt" 2>&1
+ perf script -i $TMPDIR/perf.data --fields brstacksym | \
+ tr ' ' '\n' > $TMPDIR/perf.script
+
+ # BRBINF<n>.TYPE == TRAP are mapped to PERF_BR_IRQ by the BRBE driver
+ check_branches "^trap_bench\+[^ ]+/[^ ]/IRQ/"
+ check_branches "^[^ ]+/trap_bench\+[^ ]+/ERET/"
+ if [ $err -eq 0 ]; then
+ ret=0
+ break
+ fi
+ done
+
+ if [ $ret -eq 0 ]; then
echo "Testing trap & eret branches [Passed]"
err=$start_err
else
echo "Testing trap & eret branches [Failed]"
+ err=1
fi
}
@@ -135,32 +144,40 @@ test_kernel_branches() {
return
fi
start_err=$err
- err=0
- perf record -o $TMPDIR/perf.data --branch-filter any,k -- \
- perf bench syscall basic --loop 1000 > "$TMPDIR/record.txt" 2>&1
- perf script -i $TMPDIR/perf.data --fields brstack | \
- tr ' ' '\n' > $TMPDIR/perf.script
-
- # Example of branch entries:
- # "0xffffffff93bda241/0xffffffff93bda20f/M/-/-/..."
- # Source addresses come first in user or kernel code. Next is the target
- # address that must be in the kernel.
-
- # Look for source addresses with top bit set
- if ! grep -q -E -m1 "^0x[89a-f][0-9a-f]{15}" $TMPDIR/perf.script; then
- echo "Testing kernel branch sampling [Failed kernel branches missing]"
- err=1
- fi
- # Look for no target addresses without top bit set
- if grep -q -E -m1 "^0x[0-9a-f]{0,16}/0x[0-7][0-9a-f]{1,15}/" $TMPDIR/perf.script; then
- echo "Testing kernel branch sampling [Failed user branches found]"
- err=1
- fi
- if [ $err -eq 0 ]; then
+ local ret=1
+ for loops in 1000 10000 100000; do
+ err=0
+ perf record -o $TMPDIR/perf.data --branch-filter any,k -- \
+ perf bench syscall basic --loop $loops > "$TMPDIR/record.txt" 2>&1
+ perf script -i $TMPDIR/perf.data --fields brstack | \
+ tr ' ' '\n' > $TMPDIR/perf.script
+
+ # Example of branch entries:
+ # "0xffffffff93bda241/0xffffffff93bda20f/M/-/-/..."
+ # Source addresses come first in user or kernel code. Next is the target
+ # address that must be in the kernel.
+
+ # Look for source addresses with top bit set
+ if ! grep -q -E -m1 "^0x[89a-f][0-9a-f]{15}" $TMPDIR/perf.script; then
+ err=1
+ fi
+ # Look for no target addresses without top bit set
+ if grep -q -E -m1 "^0x[0-9a-f]{0,16}/0x[0-7][0-9a-f]{1,15}/" \
+ $TMPDIR/perf.script; then
+ err=1
+ fi
+ if [ $err -eq 0 ]; then
+ ret=0
+ break
+ fi
+ done
+
+ if [ $ret -eq 0 ]; then
echo "Testing kernel branch sampling [Passed]"
err=$start_err
else
echo "Testing kernel branch sampling [Failed]"
+ err=1
fi
}
@@ -206,20 +223,28 @@ test_syscall() {
return
fi
start_err=$err
- err=0
- perf record -o $TMPDIR/perf.data --branch-filter \
- any_call,save_type,u,k -c 10007 -- \
- perf bench syscall basic --loop 8000 > "$TMPDIR/record.txt" 2>&1
- perf script -i $TMPDIR/perf.data --fields brstacksym | \
- tr ' ' '\n' > $TMPDIR/perf.script
-
- check_branches "getppid[^ ]*/SYSCALL/"
+ local ret=1
+ for loops in 8000 30000 100000; do
+ err=0
+ perf record -o $TMPDIR/perf.data --branch-filter \
+ any_call,save_type,u,k -c 10007 -- \
+ perf bench syscall basic --loop $loops > "$TMPDIR/record.txt" 2>&1
+ perf script -i $TMPDIR/perf.data --fields brstacksym | \
+ tr ' ' '\n' > $TMPDIR/perf.script
+
+ check_branches "getppid[^ ]*/SYSCALL/"
+ if [ $err -eq 0 ]; then
+ ret=0
+ break
+ fi
+ done
- if [ $err -eq 0 ]; then
+ if [ $ret -eq 0 ]; then
echo "Testing syscalls [Passed]"
err=$start_err
else
echo "Testing syscalls [Failed]"
+ err=1
fi
}
set -e
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0167/1518] regulator: tps6594: Fix device node reference leaks in multiphase loop
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (165 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0166/1518] perf tests: Fix flakiness in branch stack sampling tests Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0168/1518] drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup Greg Kroah-Hartman
` (831 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Uday Khare, Mark Brown, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Uday Khare <udaykhare77@gmail.com>
[ Upstream commit 7fd28093b3effc4f92566466df364622830ec608 ]
In tps6594_regulator_probe(), the multi-phase configuration loop calls
of_find_node_by_name() to find buck nodes by name, and of_get_parent()
twice to navigate to the PMIC parent node. None of the acquired node
references (np, intermediate parent, np_pmic_parent) are ever released
via of_node_put(), causing a reference leak on every loop iteration.
Additionally, of_find_node_by_name() can return NULL, but the result was
immediately passed to of_node_full_name() and of_get_parent() without a
NULL check, which could lead to a NULL pointer dereference.
Fix this by:
- Adding a NULL check for np after of_find_node_by_name()
- Storing the intermediate parent node in a local variable np_parent
- Calling of_node_put() on np, np_parent and np_pmic_parent at the
end of each loop iteration
Fixes: f17ccc5deb4d ("regulator: tps6594-regulator: Add driver for TI TPS6594 regulators")
Signed-off-by: Uday Khare <udaykhare77@gmail.com>
Link: https://patch.msgid.link/20260618132327.11529-1-udaykhare77@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/regulator/tps6594-regulator.c | 19 +++++++++++++++----
1 file changed, 15 insertions(+), 4 deletions(-)
diff --git a/drivers/regulator/tps6594-regulator.c b/drivers/regulator/tps6594-regulator.c
index 645e83462c645..31a5218d55105 100644
--- a/drivers/regulator/tps6594-regulator.c
+++ b/drivers/regulator/tps6594-regulator.c
@@ -669,13 +669,20 @@ static int tps6594_regulator_probe(struct platform_device *pdev)
* buck_configured to avoid creating bucks for every buck in multiphase
*/
for (multi = 0; multi < desc->num_multi_phase_regs; multi++) {
+ struct device_node *np_parent;
+
multi_regs = &desc->multi_phase_regs[multi];
np = of_find_node_by_name(tps->dev->of_node, multi_regs->supply_name);
- npname = of_node_full_name(np);
- np_pmic_parent = of_get_parent(of_get_parent(np));
- if (of_node_cmp(of_node_full_name(np_pmic_parent), tps->dev->of_node->full_name))
+ if (!np)
continue;
- if (strcmp(npname, multi_regs->supply_name) == 0) {
+
+ npname = of_node_full_name(np);
+ np_parent = of_get_parent(np);
+ np_pmic_parent = of_get_parent(np_parent);
+
+ if (np_pmic_parent &&
+ !of_node_cmp(of_node_full_name(np_pmic_parent), tps->dev->of_node->full_name) &&
+ strcmp(npname, multi_regs->supply_name) == 0) {
switch (multi) {
case MULTI_BUCK12:
buck_multi[0] = true;
@@ -706,6 +713,10 @@ static int tps6594_regulator_probe(struct platform_device *pdev)
break;
}
}
+
+ of_node_put(np_pmic_parent);
+ of_node_put(np_parent);
+ of_node_put(np);
}
reg_irq_nb = desc->num_irq_types * (desc->num_buck_regs + desc->num_ldo_regs);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0168/1518] drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (166 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0167/1518] regulator: tps6594: Fix device node reference leaks in multiphase loop Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0169/1518] drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup Greg Kroah-Hartman
` (830 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Asad Kamal, Lijo Lazar,
Hawking Zhang, Alex Deucher, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Asad Kamal <asad.kamal@amd.com>
[ Upstream commit 3a8a05477cda6c8293e2b629495b42981dcaba32 ]
vddInd and vddcInd fields from VBIOS-parsed tables are used to index into
voltage lookup tables without a bounds check. Return -EINVAL when any
index is out of range.
Fixes: c82baa281843 ("drm/amd/powerplay: add Tonga dpm support (v3)")
Signed-off-by: Asad Kamal <asad.kamal@amd.com>
Reviewed-by: Lijo Lazar <lijo.lazar@amd.com>
Reviewed-by: Hawking Zhang <Hawking.Zhang@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../drm/amd/pm/powerplay/hwmgr/smu7_hwmgr.c | 24 +++++++++++++++++++
1 file changed, 24 insertions(+)
diff --git a/drivers/gpu/drm/amd/pm/powerplay/hwmgr/smu7_hwmgr.c b/drivers/gpu/drm/amd/pm/powerplay/hwmgr/smu7_hwmgr.c
index 6529a91a613b6..ba953654a0206 100644
--- a/drivers/gpu/drm/amd/pm/powerplay/hwmgr/smu7_hwmgr.c
+++ b/drivers/gpu/drm/amd/pm/powerplay/hwmgr/smu7_hwmgr.c
@@ -2216,12 +2216,24 @@ static int smu7_patch_voltage_dependency_tables_with_lookup_table(
if (data->vdd_gfx_control == SMU7_VOLTAGE_CONTROL_BY_SVID2) {
for (entry_id = 0; entry_id < sclk_table->count; ++entry_id) {
voltage_id = sclk_table->entries[entry_id].vddInd;
+ if (voltage_id >= table_info->vddgfx_lookup_table->count) {
+ pr_err("amdgpu: sclk[%u] vddgfx index %u out of bounds (%u)\n",
+ entry_id, voltage_id,
+ table_info->vddgfx_lookup_table->count);
+ return -EINVAL;
+ }
sclk_table->entries[entry_id].vddgfx =
table_info->vddgfx_lookup_table->entries[voltage_id].us_vdd;
}
} else {
for (entry_id = 0; entry_id < sclk_table->count; ++entry_id) {
voltage_id = sclk_table->entries[entry_id].vddInd;
+ if (voltage_id >= table_info->vddc_lookup_table->count) {
+ pr_err("amdgpu: sclk[%u] vddc index %u out of bounds (%u)\n",
+ entry_id, voltage_id,
+ table_info->vddc_lookup_table->count);
+ return -EINVAL;
+ }
sclk_table->entries[entry_id].vddc =
table_info->vddc_lookup_table->entries[voltage_id].us_vdd;
}
@@ -2229,12 +2241,24 @@ static int smu7_patch_voltage_dependency_tables_with_lookup_table(
for (entry_id = 0; entry_id < mclk_table->count; ++entry_id) {
voltage_id = mclk_table->entries[entry_id].vddInd;
+ if (voltage_id >= table_info->vddc_lookup_table->count) {
+ pr_err("amdgpu: mclk[%u] vddc index %u out of bounds (%u)\n",
+ entry_id, voltage_id,
+ table_info->vddc_lookup_table->count);
+ return -EINVAL;
+ }
mclk_table->entries[entry_id].vddc =
table_info->vddc_lookup_table->entries[voltage_id].us_vdd;
}
for (entry_id = 0; entry_id < mm_table->count; ++entry_id) {
voltage_id = mm_table->entries[entry_id].vddcInd;
+ if (voltage_id >= table_info->vddc_lookup_table->count) {
+ pr_err("amdgpu: mm[%u] vddc index %u out of bounds (%u)\n",
+ entry_id, voltage_id,
+ table_info->vddc_lookup_table->count);
+ return -EINVAL;
+ }
mm_table->entries[entry_id].vddc =
table_info->vddc_lookup_table->entries[voltage_id].us_vdd;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0169/1518] drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (167 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0168/1518] drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0170/1518] tools/bpf/bpftool: Reset vmlinux BTF after map commands Greg Kroah-Hartman
` (829 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Asad Kamal, Lijo Lazar,
Hawking Zhang, Alex Deucher, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Asad Kamal <asad.kamal@amd.com>
[ Upstream commit 6fa33f594e46e775a94097f71b486d7b006b6917 ]
vddInd, vddciInd and mvddInd from VBIOS-parsed tables index into vddc,
vddci and vddmem lookup tables without bounds checks across nine sites.
Return -EINVAL when any index is out of range.
Fixes: f83a9991648b ("drm/amd/powerplay: add Vega10 powerplay support (v5)")
Signed-off-by: Asad Kamal <asad.kamal@amd.com>
Reviewed-by: Lijo Lazar <lijo.lazar@amd.com>
Reviewed-by: Hawking Zhang <Hawking.Zhang@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../drm/amd/pm/powerplay/hwmgr/vega10_hwmgr.c | 35 ++++++++++++++++++-
1 file changed, 34 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/amd/pm/powerplay/hwmgr/vega10_hwmgr.c b/drivers/gpu/drm/amd/pm/powerplay/hwmgr/vega10_hwmgr.c
index 9ace863792d48..b3fed2a478aab 100644
--- a/drivers/gpu/drm/amd/pm/powerplay/hwmgr/vega10_hwmgr.c
+++ b/drivers/gpu/drm/amd/pm/powerplay/hwmgr/vega10_hwmgr.c
@@ -685,10 +685,18 @@ static int vega10_patch_voltage_dependency_tables_with_lookup_table(
case 3: vdt = table_info->vdd_dep_on_pixclk; break;
case 4: vdt = table_info->vdd_dep_on_dispclk; break;
case 5: vdt = table_info->vdd_dep_on_phyclk; break;
+ default:
+ continue;
}
for (entry_id = 0; entry_id < vdt->count; entry_id++) {
voltage_id = vdt->entries[entry_id].vddInd;
+ if (voltage_id >= table_info->vddc_lookup_table->count) {
+ pr_err("amdgpu: clk_dep[%u][%u] vddc index %u out of bounds (%u)\n",
+ i, entry_id, voltage_id,
+ table_info->vddc_lookup_table->count);
+ return -EINVAL;
+ }
vdt->entries[entry_id].vddc =
table_info->vddc_lookup_table->entries[voltage_id].us_vdd;
}
@@ -696,23 +704,48 @@ static int vega10_patch_voltage_dependency_tables_with_lookup_table(
for (entry_id = 0; entry_id < mm_table->count; ++entry_id) {
voltage_id = mm_table->entries[entry_id].vddcInd;
+ if (voltage_id >= table_info->vddc_lookup_table->count) {
+ pr_err("amdgpu: mm[%u] vddc index %u out of bounds (%u)\n",
+ entry_id, voltage_id,
+ table_info->vddc_lookup_table->count);
+ return -EINVAL;
+ }
mm_table->entries[entry_id].vddc =
table_info->vddc_lookup_table->entries[voltage_id].us_vdd;
}
for (entry_id = 0; entry_id < mclk_table->count; ++entry_id) {
voltage_id = mclk_table->entries[entry_id].vddInd;
+ if (voltage_id >= table_info->vddc_lookup_table->count) {
+ pr_err("amdgpu: mclk[%u] vddc index %u out of bounds (%u)\n",
+ entry_id, voltage_id,
+ table_info->vddc_lookup_table->count);
+ return -EINVAL;
+ }
mclk_table->entries[entry_id].vddc =
table_info->vddc_lookup_table->entries[voltage_id].us_vdd;
+
voltage_id = mclk_table->entries[entry_id].vddciInd;
+ if (voltage_id >= table_info->vddci_lookup_table->count) {
+ pr_err("amdgpu: mclk[%u] vddci index %u out of bounds (%u)\n",
+ entry_id, voltage_id,
+ table_info->vddci_lookup_table->count);
+ return -EINVAL;
+ }
mclk_table->entries[entry_id].vddci =
table_info->vddci_lookup_table->entries[voltage_id].us_vdd;
+
voltage_id = mclk_table->entries[entry_id].mvddInd;
+ if (voltage_id >= table_info->vddmem_lookup_table->count) {
+ pr_err("amdgpu: mclk[%u] vddmem index %u out of bounds (%u)\n",
+ entry_id, voltage_id,
+ table_info->vddmem_lookup_table->count);
+ return -EINVAL;
+ }
mclk_table->entries[entry_id].mvdd =
table_info->vddmem_lookup_table->entries[voltage_id].us_vdd;
}
-
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0170/1518] tools/bpf/bpftool: Reset vmlinux BTF after map commands
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (168 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0169/1518] drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup Greg Kroah-Hartman
@ 2026-09-12 6:38 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0171/1518] tools/bpf/bpftool: Reset vmlinux BTF after struct_ops commands Greg Kroah-Hartman
` (828 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:38 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yichong Chen, Andrii Nakryiko,
Emil Tsalapatis, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yichong Chen <chenyichong@uniontech.com>
[ Upstream commit 66d7e39e49b0dd57610c9b63afc65b4d5690983b ]
get_map_kv_btf() caches the vmlinux BTF object when a map uses
btf_vmlinux_value_type_id. map dump released that object when the
command completed, but left the global pointer stale.
The same cached object can also be returned to print_key_value(), which
freed it directly. That leaves btf_vmlinux dangling before the command
cleanup path runs.
Use free_map_kv_btf() for per-entry cleanup, and reset the cached
btf_vmlinux pointer when the map command releases the object. This keeps
batch mode from reusing a freed BTF object.
Fixes: 4e1ea33292ff ("bpftool: Support dumping a map with btf_vmlinux_value_type_id")
Signed-off-by: Yichong Chen <chenyichong@uniontech.com>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Link: https://lore.kernel.org/bpf/9072F43B3F74DF91+20260624025055.1574875-2-chenyichong@uniontech.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/bpf/bpftool/map.c | 12 +++++++++---
1 file changed, 9 insertions(+), 3 deletions(-)
diff --git a/tools/bpf/bpftool/map.c b/tools/bpf/bpftool/map.c
index c9de44a45778b..f65f774476a70 100644
--- a/tools/bpf/bpftool/map.c
+++ b/tools/bpf/bpftool/map.c
@@ -790,6 +790,12 @@ static int maps_have_btf(int *fds, int nb_fds)
static struct btf *btf_vmlinux;
+static void free_btf_vmlinux(void)
+{
+ btf__free(btf_vmlinux);
+ btf_vmlinux = NULL;
+}
+
static int get_map_kv_btf(const struct bpf_map_info *info, struct btf **btf)
{
int err = 0;
@@ -958,7 +964,7 @@ static int do_dump(int argc, char **argv)
close(fds[i]);
exit_free:
free(fds);
- btf__free(btf_vmlinux);
+ free_btf_vmlinux();
return err;
}
@@ -1049,7 +1055,7 @@ static void print_key_value(struct bpf_map_info *info, void *key,
btf_wtr = get_btf_writer();
if (!btf_wtr) {
p_info("failed to create json writer for btf. falling back to plain output");
- btf__free(btf);
+ free_map_kv_btf(btf);
btf = NULL;
print_entry_plain(info, key, value);
} else {
@@ -1065,7 +1071,7 @@ static void print_key_value(struct bpf_map_info *info, void *key,
} else {
print_entry_plain(info, key, value);
}
- btf__free(btf);
+ free_map_kv_btf(btf);
}
static int do_lookup(int argc, char **argv)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0171/1518] tools/bpf/bpftool: Reset vmlinux BTF after struct_ops commands
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (169 preceding siblings ...)
2026-09-12 6:38 ` [PATCH 6.18 0170/1518] tools/bpf/bpftool: Reset vmlinux BTF after map commands Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0172/1518] bpf: Copy per-CPU map value padding in copy_map_value_long() Greg Kroah-Hartman
` (827 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yichong Chen, Andrii Nakryiko,
Emil Tsalapatis, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yichong Chen <chenyichong@uniontech.com>
[ Upstream commit f7f540e19751face50c68bb9ce58460fcb46c293 ]
struct_ops frees the global btf_vmlinux object.
In batch mode, a later struct_ops command can reuse stale state.
Reset the BTF pointer and cached map info state.
Fixes: 65c93628599d ("bpftool: Add struct_ops support")
Signed-off-by: Yichong Chen <chenyichong@uniontech.com>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Link: https://lore.kernel.org/bpf/9F9017160ABE125F+20260624025055.1574875-3-chenyichong@uniontech.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/bpf/bpftool/struct_ops.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/tools/bpf/bpftool/struct_ops.c b/tools/bpf/bpftool/struct_ops.c
index aa43dead249cb..835e5e561f7fc 100644
--- a/tools/bpf/bpftool/struct_ops.c
+++ b/tools/bpf/bpftool/struct_ops.c
@@ -643,6 +643,10 @@ int do_struct_ops(int argc, char **argv)
err = cmd_select(cmds, argc, argv, do_help);
btf__free(btf_vmlinux);
+ btf_vmlinux = NULL;
+ map_info_type = NULL;
+ map_info_alloc_len = 0;
+ map_info_type_id = 0;
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0172/1518] bpf: Copy per-CPU map value padding in copy_map_value_long()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (170 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0171/1518] tools/bpf/bpftool: Reset vmlinux BTF after struct_ops commands Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0173/1518] selftests/bpf: Systematically add SO_REUSEADDR in start_server_addr Greg Kroah-Hartman
` (826 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Leon Hwang, Andrii Nakryiko,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leon Hwang <leon.hwang@linux.dev>
[ Upstream commit 7cf9cd98cf6f0df3befc167ca6b54c07014d71de ]
In kernel, per-CPU map elements are stored with
round_up(map->value_size, 8) bytes. On UAPI lookup paths, it copies the
rounded size for each CPU into a temporary buffer.
However, copy_map_value_long() passes 'map->value_size' to
bpf_obj_memcpy(). When the map has special fields, bpf_obj_memcpy() copies
around those fields with memcpy(), and does not copy the tail padding
between 'map->value_size' and round_up(map->value_size, 8).
The temporary UAPI lookup buffers are allocated without __GFP_ZERO. As a
result, when the per-CPU map's value size is not equal to
round_up(map->value_size, 8), UAPI LOOKUP_ELEM and its variants can return
stale heap contents from that padding to user space. The same issue
applies to bpf_iter for per-CPU maps.
Pass round_up(map->value_size, 8) to bpf_obj_memcpy() from
copy_map_value_long(), so per-CPU maps both with and without special
fields copy the entire per-CPU slot. Remove the now redundant round_up()
from bpf_obj_memcpy()'s long_memcpy path.
Fixes: 448325199f57 ("bpf: Add copy_map_value_long to copy to remote percpu memory")
Signed-off-by: Leon Hwang <leon.hwang@linux.dev>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Link: https://lore.kernel.org/bpf/20260624155115.85196-2-leon.hwang@linux.dev
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/bpf.h | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/include/linux/bpf.h b/include/linux/bpf.h
index e264c695f31ce..84a8afc6e6df3 100644
--- a/include/linux/bpf.h
+++ b/include/linux/bpf.h
@@ -536,7 +536,7 @@ static inline void bpf_obj_memcpy(struct btf_record *rec,
if (IS_ERR_OR_NULL(rec)) {
if (long_memcpy)
- bpf_long_memcpy(dst, src, round_up(size, 8));
+ bpf_long_memcpy(dst, src, size);
else
memcpy(dst, src, size);
return;
@@ -559,7 +559,7 @@ static inline void copy_map_value(struct bpf_map *map, void *dst, void *src)
static inline void copy_map_value_long(struct bpf_map *map, void *dst, void *src)
{
- bpf_obj_memcpy(map->record, dst, src, map->value_size, true);
+ bpf_obj_memcpy(map->record, dst, src, round_up(map->value_size, 8), true);
}
static inline void bpf_obj_swap_uptrs(const struct btf_record *rec, void *dst, void *src)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0173/1518] selftests/bpf: Systematically add SO_REUSEADDR in start_server_addr
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (171 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0172/1518] bpf: Copy per-CPU map value padding in copy_map_value_long() Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0174/1518] selftests/bpf: Mask socket type flags in mptcpify prog Greg Kroah-Hartman
` (825 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alexis Lothoré ,
Martin KaFai Lau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexis Lothoré (eBPF Foundation) <alexis.lothore@bootlin.com>
[ Upstream commit 38e36514fcb01ff1cce84cd77a93906f233a4cb8 ]
Some tests have to stop/start a server multiple time with the same
listening address. Doing so without SO_REUSADDR leads to failures due to
the socket still being in TIME_WAIT right after the first instance
stop/before the second instance start. Instead of letting each test
manually set SO_REUSEADDR on their servers, it can be done automatically
by start_server_addr for all tests (and without any major downside).
Enforce SO_REUSEADDR in start_server_addr for all tests.
Signed-off-by: Alexis Lothoré (eBPF Foundation) <alexis.lothore@bootlin.com>
Signed-off-by: Martin KaFai Lau <martin.lau@kernel.org>
Link: https://patch.msgid.link/20251105-start-server-soreuseaddr-v1-1-1bbd9c1f8d65@bootlin.com
Stable-dep-of: b4b8b334f6b5 ("selftests/bpf: Mask socket type flags in mptcpify prog")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/bpf/network_helpers.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/tools/testing/selftests/bpf/network_helpers.c b/tools/testing/selftests/bpf/network_helpers.c
index cdf7b66414442..e7ae891669e50 100644
--- a/tools/testing/selftests/bpf/network_helpers.c
+++ b/tools/testing/selftests/bpf/network_helpers.c
@@ -97,7 +97,7 @@ int settimeo(int fd, int timeout_ms)
int start_server_addr(int type, const struct sockaddr_storage *addr, socklen_t addrlen,
const struct network_helper_opts *opts)
{
- int fd;
+ int on = 1, fd;
if (!opts)
opts = &default_opts;
@@ -111,6 +111,12 @@ int start_server_addr(int type, const struct sockaddr_storage *addr, socklen_t a
if (settimeo(fd, opts->timeout_ms))
goto error_close;
+ if (type == SOCK_STREAM &&
+ setsockopt(fd, SOL_SOCKET, SO_REUSEADDR, &on, sizeof(on))) {
+ log_err("Failed to enable SO_REUSEADDR");
+ goto error_close;
+ }
+
if (opts->post_socket_cb &&
opts->post_socket_cb(fd, opts->cb_opts)) {
log_err("Failed to call post_socket_cb");
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0174/1518] selftests/bpf: Mask socket type flags in mptcpify prog
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (172 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0173/1518] selftests/bpf: Systematically add SO_REUSEADDR in start_server_addr Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0175/1518] bpf,lsm: Drop bpf_prog_free from sleepable_lsm_hooks Greg Kroah-Hartman
` (824 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Guillaume Maudoux, Andrii Nakryiko,
Matthieu Baerts (NGI0), Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guillaume Maudoux <layus.on@gmail.com>
[ Upstream commit b4b8b334f6b535a86ab83f18d3d241fe01270bc3 ]
The mptcpify BPF prog upgrades eligible TCP sockets to MPTCP, but only
when the socket type is exactly SOCK_STREAM. Its update_socket_protocol()
hook runs on the raw type from userspace, before the socket core masks
it with SOCK_TYPE_MASK, so the type may still carry SOCK_CLOEXEC or
SOCK_NONBLOCK in its upper bits and the equality check fails.
As a result, a socket(AF_INET, SOCK_STREAM | SOCK_CLOEXEC, 0) -- what
common libraries do by default -- is silently left as plain TCP. This
was hit in practice with curl. Since mptcpify.c is referenced as example
code for enabling MPTCP transparently, the same mistake is likely to be
copied into real deployments where it fails the same way and is hard to
diagnose.
Mask the type before comparing, mirroring the socket core. Extend the
test to also create the server with SOCK_CLOEXEC set; the same masking
is applied to start_server_addr() so a flagged type still listens.
Fixes: ddba122428a7 ("selftests/bpf: Add mptcpify test")
Signed-off-by: Guillaume Maudoux <layus.on@gmail.com>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Reviewed-by: Matthieu Baerts (NGI0) <matttbe@kernel.org>
Link: https://lore.kernel.org/bpf/20260630095723.564392-1-layus.on@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/bpf/network_helpers.c | 4 ++--
tools/testing/selftests/bpf/network_helpers.h | 5 +++++
tools/testing/selftests/bpf/prog_tests/mptcp.c | 13 ++++++++++---
tools/testing/selftests/bpf/progs/bpf_tracing_net.h | 3 +++
tools/testing/selftests/bpf/progs/mptcpify.c | 2 +-
5 files changed, 21 insertions(+), 6 deletions(-)
diff --git a/tools/testing/selftests/bpf/network_helpers.c b/tools/testing/selftests/bpf/network_helpers.c
index e7ae891669e50..2067e12034ba0 100644
--- a/tools/testing/selftests/bpf/network_helpers.c
+++ b/tools/testing/selftests/bpf/network_helpers.c
@@ -111,7 +111,7 @@ int start_server_addr(int type, const struct sockaddr_storage *addr, socklen_t a
if (settimeo(fd, opts->timeout_ms))
goto error_close;
- if (type == SOCK_STREAM &&
+ if ((type & SOCK_TYPE_MASK) == SOCK_STREAM &&
setsockopt(fd, SOL_SOCKET, SO_REUSEADDR, &on, sizeof(on))) {
log_err("Failed to enable SO_REUSEADDR");
goto error_close;
@@ -128,7 +128,7 @@ int start_server_addr(int type, const struct sockaddr_storage *addr, socklen_t a
goto error_close;
}
- if (type == SOCK_STREAM) {
+ if ((type & SOCK_TYPE_MASK) == SOCK_STREAM) {
if (listen(fd, opts->backlog ? MAX(opts->backlog, 0) : 1) < 0) {
log_err("Failed to listed on socket");
goto error_close;
diff --git a/tools/testing/selftests/bpf/network_helpers.h b/tools/testing/selftests/bpf/network_helpers.h
index ef208eefd571a..5ea989bc40098 100644
--- a/tools/testing/selftests/bpf/network_helpers.h
+++ b/tools/testing/selftests/bpf/network_helpers.h
@@ -25,6 +25,11 @@ typedef __u16 __sum16;
#define VIP_NUM 5
#define MAGIC_BYTES 123
+/* include/linux/net.h */
+#ifndef SOCK_TYPE_MASK
+#define SOCK_TYPE_MASK 0xf
+#endif
+
struct network_helper_opts {
int timeout_ms;
int proto;
diff --git a/tools/testing/selftests/bpf/prog_tests/mptcp.c b/tools/testing/selftests/bpf/prog_tests/mptcp.c
index 8fade8bdc4516..32dfc1c511af6 100644
--- a/tools/testing/selftests/bpf/prog_tests/mptcp.c
+++ b/tools/testing/selftests/bpf/prog_tests/mptcp.c
@@ -264,7 +264,7 @@ static int verify_mptcpify(int server_fd, int client_fd)
return err;
}
-static int run_mptcpify(int cgroup_fd)
+static int run_mptcpify(int cgroup_fd, int type)
{
int server_fd, client_fd, err = 0;
struct mptcpify *mptcpify_skel;
@@ -280,7 +280,7 @@ static int run_mptcpify(int cgroup_fd)
goto out;
/* without MPTCP */
- server_fd = start_server(AF_INET, SOCK_STREAM, NULL, 0, 0);
+ server_fd = start_server(AF_INET, type, NULL, 0, 0);
if (!ASSERT_GE(server_fd, 0, "start_server")) {
err = -EIO;
goto out;
@@ -317,7 +317,14 @@ static void test_mptcpify(void)
if (!ASSERT_OK_PTR(netns, "netns_new"))
goto fail;
- ASSERT_OK(run_mptcpify(cgroup_fd), "run_mptcpify");
+ ASSERT_OK(run_mptcpify(cgroup_fd, SOCK_STREAM), "run_mptcpify");
+ /* userspace sets flags such as SOCK_CLOEXEC together with the type;
+ * the BPF prog must still upgrade the socket to MPTCP. See
+ * update_socket_protocol() in net/socket.c, which runs before the
+ * type is masked with SOCK_TYPE_MASK.
+ */
+ ASSERT_OK(run_mptcpify(cgroup_fd, SOCK_STREAM | SOCK_CLOEXEC),
+ "run_mptcpify_cloexec");
fail:
netns_free(netns);
diff --git a/tools/testing/selftests/bpf/progs/bpf_tracing_net.h b/tools/testing/selftests/bpf/progs/bpf_tracing_net.h
index 17db400f0e0d9..a972e174f741b 100644
--- a/tools/testing/selftests/bpf/progs/bpf_tracing_net.h
+++ b/tools/testing/selftests/bpf/progs/bpf_tracing_net.h
@@ -8,6 +8,9 @@
#define AF_INET 2
#define AF_INET6 10
+/* include/linux/net.h */
+#define SOCK_TYPE_MASK 0xf
+
#define SOL_SOCKET 1
#define SO_REUSEADDR 2
#define SO_SNDBUF 7
diff --git a/tools/testing/selftests/bpf/progs/mptcpify.c b/tools/testing/selftests/bpf/progs/mptcpify.c
index cbdc730c3a471..e3f8cb54dbe97 100644
--- a/tools/testing/selftests/bpf/progs/mptcpify.c
+++ b/tools/testing/selftests/bpf/progs/mptcpify.c
@@ -15,7 +15,7 @@ int BPF_PROG(mptcpify, int family, int type, int protocol)
return protocol;
if ((family == AF_INET || family == AF_INET6) &&
- type == SOCK_STREAM &&
+ (type & SOCK_TYPE_MASK) == SOCK_STREAM &&
(!protocol || protocol == IPPROTO_TCP)) {
return IPPROTO_MPTCP;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0175/1518] bpf,lsm: Drop bpf_prog_free from sleepable_lsm_hooks
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (173 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0174/1518] selftests/bpf: Mask socket type flags in mptcpify prog Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0176/1518] mm: convert memory block states (MEM_*) macros to enum Greg Kroah-Hartman
` (823 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sechang Lim, Andrii Nakryiko,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sechang Lim <rhkrqnwk98@gmail.com>
[ Upstream commit 2ce3f548cfc6a1fe4c53479cf8a21931cdfd51d8 ]
__bpf_prog_put_rcu() is the call_rcu() callback for non-sleepable programs.
security_bpf_prog_free() called from there fires bpf_prog_free in softirq;
if a sleepable LSM prog is attached to that hook, might_fault() BUGs:
BUG: sleeping function called from invalid context
in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 5038
preempt_count: 101, expected: 0
Call Trace:
<IRQ>
__bpf_prog_enter_sleepable+0x1cd/0x320 kernel/bpf/trampoline.c:1255
bpf_trampoline_6442549705+0x53/0xd7
security_bpf_prog_free+0xde/0x130 security/security.c:5465
__bpf_prog_put_rcu+0xab/0xd0 kernel/bpf/syscall.c:2365
rcu_do_batch kernel/rcu/tree.c:2617 [inline]
handle_softirqs+0x236/0x800 kernel/softirq.c:622
</IRQ>
The call_rcu/call_rcu_tasks_trace split reflects the freed program's
sleepability, not that of any attached observer.
security_bpf_prog_free() also frees prog->aux->security, which has to stay
after the grace period, so drop bpf_prog_free from sleepable_lsm_hooks
rather than move the call. Non-sleepable observers still run there.
Fixes: 1b67772e4e3f ("bpf,lsm: Refactor bpf_prog_alloc/bpf_prog_free LSM hooks")
Signed-off-by: Sechang Lim <rhkrqnwk98@gmail.com>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Link: https://lore.kernel.org/bpf/20260701080757.1394144-1-rhkrqnwk98@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/bpf_lsm.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/kernel/bpf/bpf_lsm.c b/kernel/bpf/bpf_lsm.c
index 518c933fe944c..48876fe838ab9 100644
--- a/kernel/bpf/bpf_lsm.c
+++ b/kernel/bpf/bpf_lsm.c
@@ -293,7 +293,6 @@ BTF_ID(func, bpf_lsm_bpf_map_create)
BTF_ID(func, bpf_lsm_bpf_map_free)
BTF_ID(func, bpf_lsm_bpf_prog)
BTF_ID(func, bpf_lsm_bpf_prog_load)
-BTF_ID(func, bpf_lsm_bpf_prog_free)
BTF_ID(func, bpf_lsm_bpf_token_create)
BTF_ID(func, bpf_lsm_bpf_token_free)
BTF_ID(func, bpf_lsm_bpf_token_cmd)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0176/1518] mm: convert memory block states (MEM_*) macros to enum
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (174 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0175/1518] bpf,lsm: Drop bpf_prog_free from sleepable_lsm_hooks Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0177/1518] mm: change type of state in struct memory_block Greg Kroah-Hartman
` (822 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Israel Batista, David Hildenbrand,
Mike Rapoport (Microsoft), Lorenzo Stoakes, Omar Sandoval,
Randy Dunlap, Andrew Morton, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Israel Batista <linux@israelbatista.dev.br>
[ Upstream commit 1a4f70f6851a1916c4f0e52731c7ecfe99bf36e6 ]
Patch series "mm: Convert memory block states (MEM_*) macros to enums", v2.
The MEM_* constants indicating the state of a memory block are currently
defined as macros, meaning their definitions will be omitted from the
debuginfo on most kernel builds. This makes it harder for debuggers to
correctly map the block state at runtime, which can be quite useful when
analysing errors related to memory hot plugging and unplugging with tools
such as drgn.
Converting the constants to an enum ensures the correct information is
emitted by the compiler and available for the debugger, without needing to
hard-code them into the debugger and track their changes.
This patch series aims to replace the current macros with a newly created
enum named memory_block_state, while also taking advantage of the compile
time guarantees that we get when using enums.
The first patch does the conversion of the macros to an enum, while the
2nd and 3rd patches use this enum to clean up some type declarations and
make sure that only valid values are used.
This patch (of 3):
Converting the MEM_* constants from macros to an enum ensures that their
values will be correctly emitted in the debug symbols, making it easier to
trace the meaning of each value when debugging with tools such as drgn,
without the need to hard-code the values.
Since the values are mutually exclusive and they are not exposed directly
to userspace, I also dropped the misleading pattern (1<<X) that made it
look like they were combinable flags.
Link: https://lkml.kernel.org/r/20251029195617.2210700-1-linux@israelbatista.dev.br
Link: https://lkml.kernel.org/r/20251029195617.2210700-2-linux@israelbatista.dev.br
Signed-off-by: Israel Batista <linux@israelbatista.dev.br>
Acked-by: David Hildenbrand <david@redhat.com>
Acked-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Reviewed-by: Lorenzo Stoakes <lorenzo.stoakes@oracle.com>
Cc: Omar Sandoval <osandov@osandov.com>
Cc: Randy Dunlap <rdunlap@infradead.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Stable-dep-of: 2ebce860bdd7 ("mm/mm_init: handle alloc_percpu failure in free_area_init_core_hotplug")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/memory.h | 22 ++++++++++++----------
1 file changed, 12 insertions(+), 10 deletions(-)
diff --git a/include/linux/memory.h b/include/linux/memory.h
index 0c214256216f6..f4e358477c6a7 100644
--- a/include/linux/memory.h
+++ b/include/linux/memory.h
@@ -64,6 +64,18 @@ struct memory_group {
};
};
+enum memory_block_state {
+ /* These states are exposed to userspace as text strings in sysfs */
+ MEM_ONLINE, /* exposed to userspace */
+ MEM_GOING_OFFLINE, /* exposed to userspace */
+ MEM_OFFLINE, /* exposed to userspace */
+ MEM_GOING_ONLINE,
+ MEM_CANCEL_ONLINE,
+ MEM_CANCEL_OFFLINE,
+ MEM_PREPARE_ONLINE,
+ MEM_FINISH_OFFLINE,
+};
+
struct memory_block {
unsigned long start_section_nr;
unsigned long state; /* serialized by the dev->lock */
@@ -89,16 +101,6 @@ int arch_get_memory_phys_device(unsigned long start_pfn);
unsigned long memory_block_size_bytes(void);
int set_memory_block_size_order(unsigned int order);
-/* These states are exposed to userspace as text strings in sysfs */
-#define MEM_ONLINE (1<<0) /* exposed to userspace */
-#define MEM_GOING_OFFLINE (1<<1) /* exposed to userspace */
-#define MEM_OFFLINE (1<<2) /* exposed to userspace */
-#define MEM_GOING_ONLINE (1<<3)
-#define MEM_CANCEL_ONLINE (1<<4)
-#define MEM_CANCEL_OFFLINE (1<<5)
-#define MEM_PREPARE_ONLINE (1<<6)
-#define MEM_FINISH_OFFLINE (1<<7)
-
struct memory_notify {
/*
* The altmap_start_pfn and altmap_nr_pages fields are designated for
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0177/1518] mm: change type of state in struct memory_block
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (175 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0176/1518] mm: convert memory block states (MEM_*) macros to enum Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0178/1518] mm: name the anonymous MMOP enum as enum mmop Greg Kroah-Hartman
` (821 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Israel Batista, David Hildenbrand,
Mike Rapoport (Microsoft), Lorenzo Stoakes, Omar Sandoval,
Randy Dunlap, Andrew Morton, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Israel Batista <linux@israelbatista.dev.br>
[ Upstream commit 8bc7ba3d265d6ee698de4b1941b7e8f7d91a0562 ]
The state of a memory block should be restricted to values specified in
the documentation of the memory hotplug API. However, since the state
field in the memory_block struct was defined as an unsigned long, this
restriction was not enforced at compile time.
With the introduction of the enum memory_block_state, it is now possible
to incorporate the desired semantics in the field declaration and enforce
these restrictions at compile time.
[akpm@linux-foundation.org: fix whitespace, per Randy]
Link: https://lkml.kernel.org/r/20251029195617.2210700-3-linux@israelbatista.dev.br
Signed-off-by: Israel Batista <linux@israelbatista.dev.br>
Acked-by: David Hildenbrand <david@redhat.com>
Acked-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Reviewed-by: Lorenzo Stoakes <lorenzo.stoakes@oracle.com>
Cc: Omar Sandoval <osandov@osandov.com>
Cc: Randy Dunlap <rdunlap@infradead.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Stable-dep-of: 2ebce860bdd7 ("mm/mm_init: handle alloc_percpu failure in free_area_init_core_hotplug")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/base/memory.c | 2 +-
include/linux/memory.h | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/base/memory.c b/drivers/base/memory.c
index fdbec49f5f5b2..c7d2323133e70 100644
--- a/drivers/base/memory.c
+++ b/drivers/base/memory.c
@@ -198,7 +198,7 @@ static ssize_t state_show(struct device *dev, struct device_attribute *attr,
break;
default:
WARN_ON(1);
- return sysfs_emit(buf, "ERROR-UNKNOWN-%ld\n", mem->state);
+ return sysfs_emit(buf, "ERROR-UNKNOWN-%d\n", mem->state);
}
return sysfs_emit(buf, "%s\n", output);
diff --git a/include/linux/memory.h b/include/linux/memory.h
index f4e358477c6a7..ca20cbdd71f25 100644
--- a/include/linux/memory.h
+++ b/include/linux/memory.h
@@ -78,7 +78,7 @@ enum memory_block_state {
struct memory_block {
unsigned long start_section_nr;
- unsigned long state; /* serialized by the dev->lock */
+ enum memory_block_state state; /* serialized by the dev->lock */
int online_type; /* for passing data to online routine */
int nid; /* NID for this memory block */
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0178/1518] mm: name the anonymous MMOP enum as enum mmop
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (176 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0177/1518] mm: change type of state in struct memory_block Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0179/1518] mm/mm_init: handle alloc_percpu failure in free_area_init_core_hotplug Greg Kroah-Hartman
` (820 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Gregory Price, Jonathan Cameron,
David Hildenbrand (arm), Ben Cheatham, Dave Jiang,
Davidlohr Bueso, Danilo Krummrich, Liam Howlett, Lorenzo Stoakes,
Michal Hocko, Mike Rapoport, Oscar Salvador, Suren Baghdasaryan,
Vlastimil Babka, Andrew Morton, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gregory Price <gourry@gourry.net>
[ Upstream commit c5c48345135ff04e039377020df23294d59aa59a ]
Give the MMOP enum (MMOP_OFFLINE, MMOP_ONLINE, etc) a proper type name so
the compiler can help catch invalid values being assigned to variables of
this type.
Leave the existing functions returning int alone to allow for
value-or-error pattern to remain unchanged without churn.
mmop_default_online_type is left as int because it uses the -1 sentinal
value to signal it hasn't been initialized yet.
Keep the uint8_t buffer in offline_and_remove_memory() as-is for space
efficiency, with an explicit cast when we consume the value.
Move the enum definition before the CONFIG_MEMORY_HOTPLUG guard so it is
unconditionally available for struct memory_block in memory.h.
No functional change.
Link: https://lore.kernel.org/linux-mm/3424eba7-523b-4351-abd0-3a888a3e5e61@kernel.org/
Link: https://lkml.kernel.org/r/20260211215447.2194189-1-gourry@gourry.net
Signed-off-by: Gregory Price <gourry@gourry.net>
Suggested-by: Jonathan Cameron <jonathan.cameron@huawei.com>
Suggested-by: "David Hildenbrand (arm)" <david@kernel.org>
Reviewed-by: Ben Cheatham <benjamin.cheatham@amd.com>
Acked-by: David Hildenbrand (Arm) <david@kernel.org>
Reviewed-by: Dave Jiang <dave.jiang@intel.com>
Reviewed-by: Davidlohr Bueso <dave@stgolabs.net>
Reviewed-by: Jonathan Cameron <jonathan.cameron@huawei.com>
Cc: Danilo Krummrich <dakr@kernel.org>
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Cc: Liam Howlett <liam.howlett@oracle.com>
Cc: Lorenzo Stoakes <lorenzo.stoakes@oracle.com>
Cc: Michal Hocko <mhocko@suse.com>
Cc: Mike Rapoport <rppt@kernel.org>
Cc: Oscar Salvador <osalvador@suse.de>
Cc: Suren Baghdasaryan <surenb@google.com>
Cc: Vlastimil Babka <vbabka@suse.cz>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Stable-dep-of: 2ebce860bdd7 ("mm/mm_init: handle alloc_percpu failure in free_area_init_core_hotplug")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/base/memory.c | 2 +-
include/linux/memory.h | 3 ++-
include/linux/memory_hotplug.h | 16 ++++++++--------
mm/memory_hotplug.c | 10 +++++-----
4 files changed, 16 insertions(+), 15 deletions(-)
diff --git a/drivers/base/memory.c b/drivers/base/memory.c
index c7d2323133e70..8adee0e8c753d 100644
--- a/drivers/base/memory.c
+++ b/drivers/base/memory.c
@@ -473,7 +473,7 @@ static ssize_t phys_device_show(struct device *dev,
static int print_allowed_zone(char *buf, int len, int nid,
struct memory_group *group,
unsigned long start_pfn, unsigned long nr_pages,
- int online_type, struct zone *default_zone)
+ enum mmop online_type, struct zone *default_zone)
{
struct zone *zone;
diff --git a/include/linux/memory.h b/include/linux/memory.h
index ca20cbdd71f25..1c0c8f3c35fbb 100644
--- a/include/linux/memory.h
+++ b/include/linux/memory.h
@@ -19,6 +19,7 @@
#include <linux/node.h>
#include <linux/compiler.h>
#include <linux/mutex.h>
+#include <linux/memory_hotplug.h>
#define MIN_MEMORY_BLOCK_SIZE (1UL << SECTION_SIZE_BITS)
@@ -79,7 +80,7 @@ enum memory_block_state {
struct memory_block {
unsigned long start_section_nr;
enum memory_block_state state; /* serialized by the dev->lock */
- int online_type; /* for passing data to online routine */
+ enum mmop online_type; /* for passing data to online routine */
int nid; /* NID for this memory block */
/*
* The single zone of this memory block if all PFNs of this memory block
diff --git a/include/linux/memory_hotplug.h b/include/linux/memory_hotplug.h
index 23f038a162319..d4d54070f77a5 100644
--- a/include/linux/memory_hotplug.h
+++ b/include/linux/memory_hotplug.h
@@ -16,11 +16,8 @@ struct resource;
struct vmem_altmap;
struct dev_pagemap;
-#ifdef CONFIG_MEMORY_HOTPLUG
-struct page *pfn_to_online_page(unsigned long pfn);
-
/* Types for control the zone type of onlined and offlined memory */
-enum {
+enum mmop {
/* Offline the memory. */
MMOP_OFFLINE = 0,
/* Online the memory. Zone depends, see default_zone_for_pfn(). */
@@ -31,6 +28,9 @@ enum {
MMOP_ONLINE_MOVABLE,
};
+#ifdef CONFIG_MEMORY_HOTPLUG
+struct page *pfn_to_online_page(unsigned long pfn);
+
/* Flags for add_memory() and friends to specify memory hotplug details. */
typedef int __bitwise mhp_t;
@@ -302,8 +302,8 @@ static inline void __remove_memory(u64 start, u64 size) {}
#ifdef CONFIG_MEMORY_HOTPLUG
/* Default online_type (MMOP_*) when new memory blocks are added. */
-extern int mhp_get_default_online_type(void);
-extern void mhp_set_default_online_type(int online_type);
+extern enum mmop mhp_get_default_online_type(void);
+extern void mhp_set_default_online_type(enum mmop online_type);
extern void __ref free_area_init_core_hotplug(struct pglist_data *pgdat);
extern int __add_memory(int nid, u64 start, u64 size, mhp_t mhp_flags);
extern int add_memory(int nid, u64 start, u64 size, mhp_t mhp_flags);
@@ -326,8 +326,8 @@ extern void sparse_remove_section(unsigned long pfn, unsigned long nr_pages,
struct vmem_altmap *altmap);
extern struct page *sparse_decode_mem_map(unsigned long coded_mem_map,
unsigned long pnum);
-extern struct zone *zone_for_pfn_range(int online_type, int nid,
- struct memory_group *group, unsigned long start_pfn,
+extern struct zone *zone_for_pfn_range(enum mmop online_type,
+ int nid, struct memory_group *group, unsigned long start_pfn,
unsigned long nr_pages);
extern int arch_create_linear_mapping(int nid, u64 start, u64 size,
struct mhp_params *params);
diff --git a/mm/memory_hotplug.c b/mm/memory_hotplug.c
index b7030bcd9b03e..a0e9cfe208da1 100644
--- a/mm/memory_hotplug.c
+++ b/mm/memory_hotplug.c
@@ -221,7 +221,7 @@ void put_online_mems(void)
bool movable_node_enabled = false;
static int mhp_default_online_type = -1;
-int mhp_get_default_online_type(void)
+enum mmop mhp_get_default_online_type(void)
{
if (mhp_default_online_type >= 0)
return mhp_default_online_type;
@@ -240,7 +240,7 @@ int mhp_get_default_online_type(void)
return mhp_default_online_type;
}
-void mhp_set_default_online_type(int online_type)
+void mhp_set_default_online_type(enum mmop online_type)
{
mhp_default_online_type = online_type;
}
@@ -1046,7 +1046,7 @@ static inline struct zone *default_zone_for_pfn(int nid, unsigned long start_pfn
return movable_node_enabled ? movable_zone : kernel_zone;
}
-struct zone *zone_for_pfn_range(int online_type, int nid,
+struct zone *zone_for_pfn_range(enum mmop online_type, int nid,
struct memory_group *group, unsigned long start_pfn,
unsigned long nr_pages)
{
@@ -2338,7 +2338,7 @@ EXPORT_SYMBOL_GPL(remove_memory);
static int try_offline_memory_block(struct memory_block *mem, void *arg)
{
- uint8_t online_type = MMOP_ONLINE_KERNEL;
+ enum mmop online_type = MMOP_ONLINE_KERNEL;
uint8_t **online_types = arg;
struct page *page;
int rc;
@@ -2371,7 +2371,7 @@ static int try_reonline_memory_block(struct memory_block *mem, void *arg)
int rc;
if (**online_types != MMOP_OFFLINE) {
- mem->online_type = **online_types;
+ mem->online_type = (enum mmop)**online_types;
rc = device_online(&mem->dev);
if (rc < 0)
pr_warn("%s: Failed to re-online memory: %d",
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0179/1518] mm/mm_init: handle alloc_percpu failure in free_area_init_core_hotplug
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (177 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0178/1518] mm: name the anonymous MMOP enum as enum mmop Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0180/1518] dmaengine: mediatek: mtk-uart-apdma: Return -ENOMEM on memory allocation failure Greg Kroah-Hartman
` (819 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Gregory Price,
David Hildenbrand (Arm), Mike Rapoport (Microsoft), Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gregory Price <gourry@gourry.net>
[ Upstream commit 2ebce860bdd7ae5e13002811bc9bbbf33fcfc221 ]
We miss a failed allocation check for pgdat->per_cpu_nodestats, which
results in a NULL deref when we offset into the per-cpu area.
Propagate -ENOMEM up the stack and leave per_cpu_nodestats pointing
at boot_nodestats so a later online can retry the allocation.
hotadd_init_pgdat() returns NULL on failure, which __try_online_node()
already maps to -ENOMEM.
On failure nothing needs to be unwound:
- the node is never marked online
- per_cpu_nodestats is left pointing at boot_nodestats
- __add_memory_resource() cleans up pending memblock resources
- later online attempts retry the per_cpu_nodestats allocation
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://sashiko.dev/#/patchset/20260627202243.758289-1-gourry%40gourry.net
Fixes: 75ef71840539 ("mm, vmstat: add infrastructure for per-node vmstats")
Signed-off-by: Gregory Price <gourry@gourry.net>
Acked-by: David Hildenbrand (Arm) <david@kernel.org>
Link: https://patch.msgid.link/20260701221613.2818148-1-gourry@gourry.net
Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/memory_hotplug.h | 2 +-
mm/memory_hotplug.c | 3 ++-
mm/mm_init.c | 14 +++++++++++---
3 files changed, 14 insertions(+), 5 deletions(-)
diff --git a/include/linux/memory_hotplug.h b/include/linux/memory_hotplug.h
index d4d54070f77a5..bb01cd2671312 100644
--- a/include/linux/memory_hotplug.h
+++ b/include/linux/memory_hotplug.h
@@ -304,7 +304,7 @@ static inline void __remove_memory(u64 start, u64 size) {}
/* Default online_type (MMOP_*) when new memory blocks are added. */
extern enum mmop mhp_get_default_online_type(void);
extern void mhp_set_default_online_type(enum mmop online_type);
-extern void __ref free_area_init_core_hotplug(struct pglist_data *pgdat);
+int __ref free_area_init_core_hotplug(struct pglist_data *pgdat);
extern int __add_memory(int nid, u64 start, u64 size, mhp_t mhp_flags);
extern int add_memory(int nid, u64 start, u64 size, mhp_t mhp_flags);
extern int add_memory_resource(int nid, struct resource *resource,
diff --git a/mm/memory_hotplug.c b/mm/memory_hotplug.c
index a0e9cfe208da1..9fdfb2d317654 100644
--- a/mm/memory_hotplug.c
+++ b/mm/memory_hotplug.c
@@ -1279,7 +1279,8 @@ static pg_data_t *hotadd_init_pgdat(int nid)
pgdat = NODE_DATA(nid);
/* init node's zones as empty zones, we don't have any present pages.*/
- free_area_init_core_hotplug(pgdat);
+ if (free_area_init_core_hotplug(pgdat))
+ return NULL;
/*
* The node we allocated has no zone fallback lists. For avoiding
diff --git a/mm/mm_init.c b/mm/mm_init.c
index 4ed5b09f4eb4f..a27ba1c1a7192 100644
--- a/mm/mm_init.c
+++ b/mm/mm_init.c
@@ -1560,7 +1560,7 @@ void __init set_pageblock_order(void)
* NOTE: this function is only called during memory hotplug
*/
#ifdef CONFIG_MEMORY_HOTPLUG
-void __ref free_area_init_core_hotplug(struct pglist_data *pgdat)
+int __ref free_area_init_core_hotplug(struct pglist_data *pgdat)
{
int nid = pgdat->node_id;
enum zone_type z;
@@ -1568,8 +1568,14 @@ void __ref free_area_init_core_hotplug(struct pglist_data *pgdat)
pgdat_init_internals(pgdat);
- if (pgdat->per_cpu_nodestats == &boot_nodestats)
- pgdat->per_cpu_nodestats = alloc_percpu(struct per_cpu_nodestat);
+ if (pgdat->per_cpu_nodestats == &boot_nodestats) {
+ struct per_cpu_nodestat __percpu *p;
+
+ p = alloc_percpu(struct per_cpu_nodestat);
+ if (!p)
+ return -ENOMEM;
+ pgdat->per_cpu_nodestats = p;
+ }
/*
* Reset the nr_zones, order and highest_zoneidx before reuse.
@@ -1607,6 +1613,8 @@ void __ref free_area_init_core_hotplug(struct pglist_data *pgdat)
zone->present_pages = 0;
zone_init_internals(zone, z, nid, 0);
}
+
+ return 0;
}
#endif
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0180/1518] dmaengine: mediatek: mtk-uart-apdma: Return -ENOMEM on memory allocation failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (178 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0179/1518] mm/mm_init: handle alloc_percpu failure in free_area_init_core_hotplug Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0181/1518] dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers Greg Kroah-Hartman
` (818 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vladimir Zapolskiy,
AngeloGioacchino Del Regno, Frank Li, Matthias Brugger,
Vinod Koul, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vladimir Zapolskiy <vz@kernel.org>
[ Upstream commit 467265c750edd7ab43803deeafe7d3120a791d32 ]
If dynamic memory allocation in driver's probe function execution fails, it
should be reported to the driver's framework with -ENOMEM error code.
Fixes: 9135408c3ace ("dmaengine: mediatek: Add MediaTek UART APDMA support")
Signed-off-by: Vladimir Zapolskiy <vz@kernel.org>
Reviewed-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Reviewed-by: Matthias Brugger <matthias.bgg@gmail.com>
Link: https://patch.msgid.link/20260701200703.117929-1-vz@kernel.org
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/mediatek/mtk-uart-apdma.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/dma/mediatek/mtk-uart-apdma.c b/drivers/dma/mediatek/mtk-uart-apdma.c
index 96c18c815f1df..cdba081637975 100644
--- a/drivers/dma/mediatek/mtk-uart-apdma.c
+++ b/drivers/dma/mediatek/mtk-uart-apdma.c
@@ -530,7 +530,7 @@ static int mtk_uart_apdma_probe(struct platform_device *pdev)
for (i = 0; i < mtkd->dma_requests; i++) {
c = devm_kzalloc(mtkd->ddev.dev, sizeof(*c), GFP_KERNEL);
if (!c) {
- rc = -ENODEV;
+ rc = -ENOMEM;
goto err_no_dma;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0181/1518] dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (179 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0180/1518] dmaengine: mediatek: mtk-uart-apdma: Return -ENOMEM on memory allocation failure Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0182/1518] dmaengine: zynqmp_dma: fix race between runtime PM and device removal Greg Kroah-Hartman
` (817 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Folker Schwesinger, Suraj Gupta,
Srinivas Neeli, Radhey Shyam Pandey, Vinod Koul, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Suraj Gupta <suraj.gupta2@amd.com>
[ Upstream commit 0b6d055edb55ecadadf54e930c2b4fab76fa9a5a ]
Fix a race condition in AXIDMA and MCDMA irq handlers where the channel
could be incorrectly marked as idle and attempt spurious transfers when
descriptors are still being processed.
The issue occurs when:
1. Multiple descriptors are queued and active.
2. An interrupt fires after completing some descriptors.
3. xilinx_dma_complete_descriptor() moves completed descriptors to
done_list.
4. Channel is marked idle and start_transfer() is called even though
active_list still contains unprocessed descriptors.
5. This leads to premature transfer attempts and potential descriptor
corruption or missed completions.
Only mark the channel as idle and start new transfers when the active list
is actually empty, ensuring proper channel state management and avoiding
spurious transfer attempts.
Fixes: c0bba3a99f07 ("dmaengine: vdma: Add Support for Xilinx AXI Direct Memory Access Engine")
Tested-by: Folker Schwesinger <dev@folker-schwesinger.de>
Signed-off-by: Suraj Gupta <suraj.gupta2@amd.com>
Co-developed-by: Srinivas Neeli <srinivas.neeli@amd.com>
Signed-off-by: Srinivas Neeli <srinivas.neeli@amd.com>
Reviewed-by: Radhey Shyam Pandey <radhey.shyam.pandey@amd.com>
Link: https://patch.msgid.link/20260626092656.1563871-2-suraj.gupta2@amd.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/xilinx/xilinx_dma.c | 12 ++++++++----
1 file changed, 8 insertions(+), 4 deletions(-)
diff --git a/drivers/dma/xilinx/xilinx_dma.c b/drivers/dma/xilinx/xilinx_dma.c
index 7dec5e6babe14..30e3db94ddf07 100644
--- a/drivers/dma/xilinx/xilinx_dma.c
+++ b/drivers/dma/xilinx/xilinx_dma.c
@@ -1872,8 +1872,10 @@ static irqreturn_t xilinx_mcdma_irq_handler(int irq, void *data)
if (status & XILINX_MCDMA_IRQ_IOC_MASK) {
spin_lock(&chan->lock);
xilinx_dma_complete_descriptor(chan);
- chan->idle = true;
- chan->start_transfer(chan);
+ if (list_empty(&chan->active_list)) {
+ chan->idle = true;
+ chan->start_transfer(chan);
+ }
spin_unlock(&chan->lock);
}
@@ -1929,8 +1931,10 @@ static irqreturn_t xilinx_dma_irq_handler(int irq, void *data)
XILINX_DMA_DMASR_DLY_CNT_IRQ)) {
spin_lock(&chan->lock);
xilinx_dma_complete_descriptor(chan);
- chan->idle = true;
- chan->start_transfer(chan);
+ if (list_empty(&chan->active_list)) {
+ chan->idle = true;
+ chan->start_transfer(chan);
+ }
spin_unlock(&chan->lock);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0182/1518] dmaengine: zynqmp_dma: fix race between runtime PM and device removal
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (180 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0181/1518] dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0183/1518] dmaengine: hisilicon: Return -ENOMEM on dynamic memory allocation in probe Greg Kroah-Hartman
` (816 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Prasanna Kumar T S M, Golla Nagendra,
Radhey Shyam Pandey, Vinod Koul, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Golla Nagendra <nagendra.golla@amd.com>
[ Upstream commit 516ba2d8b7aac4238f9fcbd58579c43c71b9b695 ]
In zynqmp_dma_remove(), runtime PM was disabled only after checking
state and doing a manual suspend. This can race with runtime PM in the
remove/unbind (rmmod) path.
Disable runtime PM first, then suspend only if the device is not already
suspended. To prevent any further runtime PM transitions.
Fixes: 72dd8b2914b5 ("dmaengine: zynqmp_dma: Add shutdown operation support")
Co-developed-by: Prasanna Kumar T S M <ptsm@linux.microsoft.com>
Signed-off-by: Prasanna Kumar T S M <ptsm@linux.microsoft.com>
Signed-off-by: Golla Nagendra <nagendra.golla@amd.com>
Reviewed-by: Radhey Shyam Pandey <radhey.shyam.pandey@amd.com>
Link: https://patch.msgid.link/20260630064844.705173-2-nagendra.golla@amd.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/xilinx/zynqmp_dma.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/dma/xilinx/zynqmp_dma.c b/drivers/dma/xilinx/zynqmp_dma.c
index f7e584de4335e..23e07d72a5225 100644
--- a/drivers/dma/xilinx/zynqmp_dma.c
+++ b/drivers/dma/xilinx/zynqmp_dma.c
@@ -1173,9 +1173,9 @@ static void zynqmp_dma_remove(struct platform_device *pdev)
dma_async_device_unregister(&zdev->common);
zynqmp_dma_chan_remove(zdev->chan);
- if (pm_runtime_active(zdev->dev))
- zynqmp_dma_runtime_suspend(zdev->dev);
pm_runtime_disable(zdev->dev);
+ if (!pm_runtime_status_suspended(zdev->dev))
+ zynqmp_dma_runtime_suspend(zdev->dev);
}
static const struct of_device_id zynqmp_dma_of_match[] = {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0183/1518] dmaengine: hisilicon: Return -ENOMEM on dynamic memory allocation in probe
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (181 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0182/1518] dmaengine: zynqmp_dma: fix race between runtime PM and device removal Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0184/1518] soundwire: qcom: Fix port exhaustion check in stream_alloc_ports Greg Kroah-Hartman
` (815 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vladimir Zapolskiy, Frank Li,
Vinod Koul, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vladimir Zapolskiy <vz@kernel.org>
[ Upstream commit cbabdd6ce1b313b5877c7fbb2f5e2f7936564d2f ]
Out of memory situation on driver's probe is expected to be reported to
the driver's framework with a proper -ENOMEM error code.
Fixes: e9f08b65250d ("dmaengine: hisilicon: Add Kunpeng DMA engine support")
Signed-off-by: Vladimir Zapolskiy <vz@kernel.org>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260630144214.4080302-1-vz@kernel.org
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/hisi_dma.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/dma/hisi_dma.c b/drivers/dma/hisi_dma.c
index 25a4134be36b7..ede094e0d0905 100644
--- a/drivers/dma/hisi_dma.c
+++ b/drivers/dma/hisi_dma.c
@@ -983,7 +983,7 @@ static int hisi_dma_probe(struct pci_dev *pdev, const struct pci_device_id *id)
hdma_dev = devm_kzalloc(dev, struct_size(hdma_dev, chan, chan_num),
GFP_KERNEL);
if (!hdma_dev)
- return -EINVAL;
+ return -ENOMEM;
hdma_dev->base = pcim_iomap_table(pdev)[PCI_BAR_2];
hdma_dev->pdev = pdev;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0184/1518] soundwire: qcom: Fix port exhaustion check in stream_alloc_ports
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (182 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0183/1518] dmaengine: hisilicon: Return -ENOMEM on dynamic memory allocation in probe Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0185/1518] iio: orientation: hid-sensor-rotation: Avoid race between callback setup and device exposure Greg Kroah-Hartman
` (814 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot, Srinivas Kandagatla,
Vinod Koul, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Srinivas Kandagatla <srinivas.kandagatla@oss.qualcomm.com>
[ Upstream commit 6ccec91c3535b07310e12d32fe9c67ff8d31d965 ]
find_first_zero_bit(mask, n) returns n (not n+1) when all bits are set,
so the guard `pn > maxport` is never true on exhaustion. The driver
would silently call set_bit(maxport, port_mask) and assign the
out-of-range port instead of returning -EBUSY. Fix the comparison to
`pn >= maxport`.
Fixes: 02efb49aa805 ("soundwire: qcom: add support for SoundWire controller")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Assisted-by: Claude Sonnet 4.6
Signed-off-by: Srinivas Kandagatla <srinivas.kandagatla@oss.qualcomm.com>
Link: https://patch.msgid.link/20260701193006.4113-2-srinivas.kandagatla@oss.qualcomm.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/soundwire/qcom.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/soundwire/qcom.c b/drivers/soundwire/qcom.c
index 5b3078220189b..a4f108fdffddb 100644
--- a/drivers/soundwire/qcom.c
+++ b/drivers/soundwire/qcom.c
@@ -1201,7 +1201,7 @@ static int qcom_swrm_stream_alloc_ports(struct qcom_swrm_ctrl *ctrl,
else
pn = find_first_zero_bit(port_mask, maxport);
- if (pn > maxport) {
+ if (pn >= maxport) {
dev_err(ctrl->dev, "All ports busy\n");
ret = -EBUSY;
goto out;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0185/1518] iio: orientation: hid-sensor-rotation: Avoid race between callback setup and device exposure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (183 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0184/1518] soundwire: qcom: Fix port exhaustion check in stream_alloc_ports Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0186/1518] csky: Fix a4/a5 restoration in syscall trace path Greg Kroah-Hartman
` (813 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sanjay Chitroda, Andy Shevchenko,
Srinivas Pandruvada, Jonathan Cameron, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sanjay Chitroda <sanjayembeddedse@gmail.com>
[ Upstream commit 0e32649a7cf3cd784862f8dc0c68a5134731bfff ]
The driver currently exposes the IIO device to userspace before
completing sensor hub callback registration, and similarly removes
callbacks while the device can still be accessed during teardown.
This creates a timing window where userspace may enable the buffer
before callbacks are available. In such cases:
- samples can be dropped,
- buffered reads may observe stale or no data.
Reorder probe and remove paths to ensure callbacks are active before
device exposure and are removed after device is no longer accessible.
This avoids a race window leading to data loss.
Signed-off-by: Sanjay Chitroda <sanjayembeddedse@gmail.com>
Fixes: fc18dddc0625 ("iio: hid-sensors: Added device rotation support")
Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com>
Acked-by: Srinivas Pandruvada <srinivas.pandruvada@linux.intel.com>
Signed-off-by: Jonathan Cameron <jic23@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/iio/orientation/hid-sensor-rotation.c | 20 +++++++++----------
1 file changed, 10 insertions(+), 10 deletions(-)
diff --git a/drivers/iio/orientation/hid-sensor-rotation.c b/drivers/iio/orientation/hid-sensor-rotation.c
index 83a0b0283605b..061934f0cb999 100644
--- a/drivers/iio/orientation/hid-sensor-rotation.c
+++ b/drivers/iio/orientation/hid-sensor-rotation.c
@@ -353,12 +353,6 @@ static int hid_dev_rot_probe(struct platform_device *pdev)
return ret;
}
- ret = iio_device_register(indio_dev);
- if (ret) {
- dev_err(&pdev->dev, "device register failed\n");
- goto error_remove_trigger;
- }
-
rot_state->callbacks.send_event = dev_rot_proc_event;
rot_state->callbacks.capture_sample = dev_rot_capture_sample;
rot_state->callbacks.pdev = pdev;
@@ -366,13 +360,19 @@ static int hid_dev_rot_probe(struct platform_device *pdev)
&rot_state->callbacks);
if (ret) {
dev_err(&pdev->dev, "callback reg failed\n");
- goto error_iio_unreg;
+ goto error_remove_trigger;
+ }
+
+ ret = iio_device_register(indio_dev);
+ if (ret) {
+ dev_err(&pdev->dev, "device register failed\n");
+ goto error_remove_callback;
}
return 0;
-error_iio_unreg:
- iio_device_unregister(indio_dev);
+error_remove_callback:
+ sensor_hub_remove_callback(hsdev, hsdev->usage);
error_remove_trigger:
hid_sensor_remove_trigger(indio_dev, &rot_state->common_attributes);
return ret;
@@ -385,8 +385,8 @@ static void hid_dev_rot_remove(struct platform_device *pdev)
struct iio_dev *indio_dev = platform_get_drvdata(pdev);
struct dev_rot_state *rot_state = iio_priv(indio_dev);
- sensor_hub_remove_callback(hsdev, hsdev->usage);
iio_device_unregister(indio_dev);
+ sensor_hub_remove_callback(hsdev, hsdev->usage);
hid_sensor_remove_trigger(indio_dev, &rot_state->common_attributes);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0186/1518] csky: Fix a4/a5 restoration in syscall trace path
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (184 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0185/1518] iio: orientation: hid-sensor-rotation: Avoid race between callback setup and device exposure Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0187/1518] selftests/rseq: Replace glibc-specific __GNUC_PREREQ with portable check Greg Kroah-Hartman
` (812 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Guo Ren, Hanlin Song, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hanlin Song <pgeorge8929@gmail.com>
[ Upstream commit abb81e5ce7d995baa41556b8125fa59e28ba3be8 ]
The syscall trace path reloads syscall arguments from pt_regs before
calling the syscall handler. On C-SKY ABIv2, the 5th and 6th syscall
arguments are prepared as stack arguments before invoking syscallid.
The current code adjusts sp before loading LSAVE_A4 and LSAVE_A5. Since
those offsets are relative to the original pt_regs base, loading them
after changing sp fetches the wrong slots. As a result, traced syscalls
that use the 5th or 6th argument may receive corrupted arguments.
This is visible with mmap2(), which takes six arguments. A small
PTRACE_SYSCALL reproducer opens a file and maps one page with:
mmap(NULL, 4096, PROT_READ | PROT_EXEC, MAP_PRIVATE, fd, 0)
Before the fix, the traced child fails the mmap and exits with 12.
After the fix, the mapping succeeds and the child exits with 0.
Fix the trace path by loading a4/a5 from pt_regs before changing sp.
Tested on: ck860f, linux-4.19.15, C-SKY abiv2
Fixes: e0bbb53843b5 ("csky: Fixup abiv2 syscall_trace break a4 & a5")
Suggested-by: Guo Ren <guoren@kernel.org>
Signed-off-by: Hanlin Song <pgeorge8929@gmail.com>
Signed-off-by: Guo Ren (Alibaba DAMO Academy) <guoren@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/csky/kernel/entry.S | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/arch/csky/kernel/entry.S b/arch/csky/kernel/entry.S
index c68cdcc76d60e..3261f46f22442 100644
--- a/arch/csky/kernel/entry.S
+++ b/arch/csky/kernel/entry.S
@@ -93,11 +93,11 @@ csky_syscall_trace:
ldw a2, (sp, LSAVE_A2)
ldw a3, (sp, LSAVE_A3)
#if defined(__CSKYABIV2__)
- subi sp, 8
ldw r9, (sp, LSAVE_A4)
+ ldw r10, (sp, LSAVE_A5)
+ subi sp, 8
stw r9, (sp, 0x0)
- ldw r9, (sp, LSAVE_A5)
- stw r9, (sp, 0x4)
+ stw r10, (sp, 0x4)
jsr syscallid /* Do system call */
addi sp, 8
#else
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0187/1518] selftests/rseq: Replace glibc-specific __GNUC_PREREQ with portable check
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (185 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0186/1518] csky: Fix a4/a5 restoration in syscall trace path Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0188/1518] platform/chrome: sensorhub: Fix memory overread in ring handler Greg Kroah-Hartman
` (811 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hisam Mehboob, Thomas Gleixner,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hisam Mehboob <hisamshar@gmail.com>
[ Upstream commit d7b2769f8dba3e5f40d2a8a11988812d51160b17 ]
Building the rseq selftests against musl libc fails because musl's
<features.h> does not provide the glibc-specific __GNUC_PREREQ macro:
error: missing binary operator before token '('
Replace __GNUC_PREREQ(11, 1) with an equivalent check using __GNUC__
and __GNUC_MINOR__ directly. This pattern is portable across all C
library implementations and is already used elsewhere in the tools/
tree (e.g., tools/include/linux/string.h).
This also allows removing the #include <features.h>, which was only
needed for __GNUC_PREREQ.
Fixes: 886ddfba933f ("selftests/rseq: Introduce thread pointer getters")
Signed-off-by: Hisam Mehboob <hisamshar@gmail.com>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Link: https://patch.msgid.link/20260618193724.589113-2-hisamshar@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/rseq/rseq-x86-thread-pointer.h | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
diff --git a/tools/testing/selftests/rseq/rseq-x86-thread-pointer.h b/tools/testing/selftests/rseq/rseq-x86-thread-pointer.h
index d3133587d9968..5a29d6bec51f4 100644
--- a/tools/testing/selftests/rseq/rseq-x86-thread-pointer.h
+++ b/tools/testing/selftests/rseq/rseq-x86-thread-pointer.h
@@ -8,13 +8,11 @@
#ifndef _RSEQ_X86_THREAD_POINTER
#define _RSEQ_X86_THREAD_POINTER
-#include <features.h>
-
#ifdef __cplusplus
extern "C" {
#endif
-#if __GNUC_PREREQ (11, 1)
+#if __GNUC__ > 11 || (__GNUC__ == 11 && __GNUC_MINOR__ >= 1)
static inline void *rseq_thread_pointer(void)
{
return __builtin_thread_pointer();
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0188/1518] platform/chrome: sensorhub: Fix memory overread in ring handler
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (186 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0187/1518] selftests/rseq: Replace glibc-specific __GNUC_PREREQ with portable check Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0189/1518] wifi: rtw89: fill addr cam H2C command by struct Greg Kroah-Hartman
` (810 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Tomasz Figa, Tzung-Bi Shih,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tzung-Bi Shih <tzungbi@kernel.org>
[ Upstream commit d1ceb2b2324717fa30b44d56ef0c52813e239569 ]
`max_response` and `sensor_num` are read from different EC commands:
- `max_response` is from cros_ec_get_proto_info().
ec_dev->max_response = info->max_response_packet_size -
sizeof(struct ec_host_response);
- `sensor_num` is from cros_ec_get_sensor_count().
sensor_num = cros_ec_get_sensor_count(ec);
With a malfunctioning EC firmware, it is possible that the `msg->insize`
(i.e., `fifo_info_length` in the context) could be clamped in
cros_ec_cmd_xfer() because `msg->insize` is greater than `max_response`.
int fifo_info_length =
sizeof(struct ec_response_motion_sense_fifo_info) +
sizeof(u16) * sensorhub->sensor_num;
This means the number of read bytes could be less than expected. As a
result, the subsequent memcpy() in cros_ec_sensorhub_ring_handler()
overreads the `resp->fifo_info` buffer.
Check the return value of cros_ec_cmd_xfer_status() and abort if the
number of bytes read does not match the expected length.
Fixes: 145d59baff59 ("platform/chrome: cros_ec_sensorhub: Add FIFO support")
Reviewed-by: Tomasz Figa <tfiga@chromium.org>
Link: https://lore.kernel.org/r/20260702082745.1014968-1-tzungbi@kernel.org
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/platform/chrome/cros_ec_sensorhub_ring.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/drivers/platform/chrome/cros_ec_sensorhub_ring.c b/drivers/platform/chrome/cros_ec_sensorhub_ring.c
index 302d037b90a1f..b5970e8620bf0 100644
--- a/drivers/platform/chrome/cros_ec_sensorhub_ring.c
+++ b/drivers/platform/chrome/cros_ec_sensorhub_ring.c
@@ -825,8 +825,15 @@ static void cros_ec_sensorhub_ring_handler(struct cros_ec_sensorhub *sensorhub)
sensorhub->msg->outsize = 1;
sensorhub->msg->insize = fifo_info_length;
- if (cros_ec_cmd_xfer_status(ec->ec_dev, sensorhub->msg) < 0)
+ ret = cros_ec_cmd_xfer_status(ec->ec_dev, sensorhub->msg);
+ if (ret < 0)
+ goto error;
+ if (ret != fifo_info_length) {
+ dev_warn_ratelimited(sensorhub->dev,
+ "Mismatch read length: size %d - expected %d\n",
+ ret, fifo_info_length);
goto error;
+ }
memcpy(fifo_info, &sensorhub->resp->fifo_info,
fifo_info_length);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0189/1518] wifi: rtw89: fill addr cam H2C command by struct
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (187 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0188/1518] platform/chrome: sensorhub: Fix memory overread in ring handler Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0190/1518] wifi: rtw89: update format of addr cam H2C command Greg Kroah-Hartman
` (809 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ping-Ke Shih, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ping-Ke Shih <pkshih@realtek.com>
[ Upstream commit 239dd70d776cf94f39000740b307c91e4f72d615 ]
The addr cam is used to tell firmware the MAC address and BSSID associated
to connected stations. Use struct instead of macros with pointer arithmetic
to fill the data.
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
Link: https://patch.msgid.link/20251114060128.35363-12-pkshih@realtek.com
Stable-dep-of: a8cddb62c573 ("wifi: rtw89: check return values in rtw89_ops_start_ap()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/realtek/rtw89/cam.c | 150 ++++----
drivers/net/wireless/realtek/rtw89/cam.h | 431 +++++------------------
drivers/net/wireless/realtek/rtw89/fw.c | 17 +-
3 files changed, 173 insertions(+), 425 deletions(-)
diff --git a/drivers/net/wireless/realtek/rtw89/cam.c b/drivers/net/wireless/realtek/rtw89/cam.c
index 385a238fe5cc2..8233d91024e8e 100644
--- a/drivers/net/wireless/realtek/rtw89/cam.c
+++ b/drivers/net/wireless/realtek/rtw89/cam.c
@@ -760,7 +760,8 @@ int rtw89_cam_init(struct rtw89_dev *rtwdev, struct rtw89_vif_link *rtwvif_link)
int rtw89_cam_fill_bssid_cam_info(struct rtw89_dev *rtwdev,
struct rtw89_vif_link *rtwvif_link,
- struct rtw89_sta_link *rtwsta_link, u8 *cmd)
+ struct rtw89_sta_link *rtwsta_link,
+ struct rtw89_h2c_addr_cam *h2c)
{
struct rtw89_bssid_cam_entry *bssid_cam = rtw89_get_bssid_cam_of(rtwvif_link,
rtwsta_link);
@@ -780,20 +781,19 @@ int rtw89_cam_fill_bssid_cam_info(struct rtw89_dev *rtwdev,
rcu_read_unlock();
- FWCMD_SET_ADDR_BSSID_IDX(cmd, bssid_cam->bssid_cam_idx);
- FWCMD_SET_ADDR_BSSID_OFFSET(cmd, bssid_cam->offset);
- FWCMD_SET_ADDR_BSSID_LEN(cmd, bssid_cam->len);
- FWCMD_SET_ADDR_BSSID_VALID(cmd, bssid_cam->valid);
- FWCMD_SET_ADDR_BSSID_MASK(cmd, bss_mask);
- FWCMD_SET_ADDR_BSSID_BB_SEL(cmd, bssid_cam->phy_idx);
- FWCMD_SET_ADDR_BSSID_BSS_COLOR(cmd, bss_color);
-
- FWCMD_SET_ADDR_BSSID_BSSID0(cmd, bssid_cam->bssid[0]);
- FWCMD_SET_ADDR_BSSID_BSSID1(cmd, bssid_cam->bssid[1]);
- FWCMD_SET_ADDR_BSSID_BSSID2(cmd, bssid_cam->bssid[2]);
- FWCMD_SET_ADDR_BSSID_BSSID3(cmd, bssid_cam->bssid[3]);
- FWCMD_SET_ADDR_BSSID_BSSID4(cmd, bssid_cam->bssid[4]);
- FWCMD_SET_ADDR_BSSID_BSSID5(cmd, bssid_cam->bssid[5]);
+ h2c->w12 = le32_encode_bits(bssid_cam->bssid_cam_idx, ADDR_CAM_W12_BSSID_IDX) |
+ le32_encode_bits(bssid_cam->offset, ADDR_CAM_W12_BSSID_OFFSET) |
+ le32_encode_bits(bssid_cam->len, ADDR_CAM_W12_BSSID_LEN);
+ h2c->w13 = le32_encode_bits(bssid_cam->valid, ADDR_CAM_W13_BSSID_VALID) |
+ le32_encode_bits(bss_mask, ADDR_CAM_W13_BSSID_MASK) |
+ le32_encode_bits(bssid_cam->phy_idx, ADDR_CAM_W13_BSSID_BB_SEL) |
+ le32_encode_bits(bss_color, ADDR_CAM_W13_BSSID_BSS_COLOR) |
+ le32_encode_bits(bssid_cam->bssid[0], ADDR_CAM_W13_BSSID_BSSID0) |
+ le32_encode_bits(bssid_cam->bssid[1], ADDR_CAM_W13_BSSID_BSSID1);
+ h2c->w14 = le32_encode_bits(bssid_cam->bssid[2], ADDR_CAM_W14_BSSID_BSSID2) |
+ le32_encode_bits(bssid_cam->bssid[3], ADDR_CAM_W14_BSSID_BSSID3) |
+ le32_encode_bits(bssid_cam->bssid[4], ADDR_CAM_W14_BSSID_BSSID4) |
+ le32_encode_bits(bssid_cam->bssid[5], ADDR_CAM_W14_BSSID_BSSID5);
return 0;
}
@@ -813,7 +813,7 @@ void rtw89_cam_fill_addr_cam_info(struct rtw89_dev *rtwdev,
struct rtw89_vif_link *rtwvif_link,
struct rtw89_sta_link *rtwsta_link,
const u8 *scan_mac_addr,
- u8 *cmd)
+ struct rtw89_h2c_addr_cam *h2c)
{
struct ieee80211_vif *vif = rtwvif_link_to_vif(rtwvif_link);
struct rtw89_addr_cam_entry *addr_cam =
@@ -845,69 +845,65 @@ void rtw89_cam_fill_addr_cam_info(struct rtw89_dev *rtwdev,
sma_hash = rtw89_cam_addr_hash(sma_start, sma);
tma_hash = rtw89_cam_addr_hash(tma_start, tma);
- FWCMD_SET_ADDR_IDX(cmd, addr_cam->addr_cam_idx);
- FWCMD_SET_ADDR_OFFSET(cmd, addr_cam->offset);
- FWCMD_SET_ADDR_LEN(cmd, addr_cam->len);
-
- FWCMD_SET_ADDR_VALID(cmd, addr_cam->valid);
- FWCMD_SET_ADDR_NET_TYPE(cmd, rtwvif_link->net_type);
- FWCMD_SET_ADDR_BCN_HIT_COND(cmd, rtwvif_link->bcn_hit_cond);
- FWCMD_SET_ADDR_HIT_RULE(cmd, rtwvif_link->hit_rule);
- FWCMD_SET_ADDR_BB_SEL(cmd, rtwvif_link->phy_idx);
- FWCMD_SET_ADDR_ADDR_MASK(cmd, addr_cam->addr_mask);
- FWCMD_SET_ADDR_MASK_SEL(cmd, addr_cam->mask_sel);
- FWCMD_SET_ADDR_SMA_HASH(cmd, sma_hash);
- FWCMD_SET_ADDR_TMA_HASH(cmd, tma_hash);
-
- FWCMD_SET_ADDR_BSSID_CAM_IDX(cmd, addr_cam->bssid_cam_idx);
-
- FWCMD_SET_ADDR_SMA0(cmd, sma[0]);
- FWCMD_SET_ADDR_SMA1(cmd, sma[1]);
- FWCMD_SET_ADDR_SMA2(cmd, sma[2]);
- FWCMD_SET_ADDR_SMA3(cmd, sma[3]);
- FWCMD_SET_ADDR_SMA4(cmd, sma[4]);
- FWCMD_SET_ADDR_SMA5(cmd, sma[5]);
-
- FWCMD_SET_ADDR_TMA0(cmd, tma[0]);
- FWCMD_SET_ADDR_TMA1(cmd, tma[1]);
- FWCMD_SET_ADDR_TMA2(cmd, tma[2]);
- FWCMD_SET_ADDR_TMA3(cmd, tma[3]);
- FWCMD_SET_ADDR_TMA4(cmd, tma[4]);
- FWCMD_SET_ADDR_TMA5(cmd, tma[5]);
-
- FWCMD_SET_ADDR_PORT_INT(cmd, rtwvif_link->port);
- FWCMD_SET_ADDR_TSF_SYNC(cmd, rtwvif_link->port);
- FWCMD_SET_ADDR_TF_TRS(cmd, rtwvif_link->trigger);
- FWCMD_SET_ADDR_LSIG_TXOP(cmd, rtwvif_link->lsig_txop);
- FWCMD_SET_ADDR_TGT_IND(cmd, rtwvif_link->tgt_ind);
- FWCMD_SET_ADDR_FRM_TGT_IND(cmd, rtwvif_link->frm_tgt_ind);
- FWCMD_SET_ADDR_MACID(cmd, rtwsta_link ? rtwsta_link->mac_id :
- rtwvif_link->mac_id);
+ h2c->w1 = le32_encode_bits(addr_cam->addr_cam_idx, ADDR_CAM_W1_IDX) |
+ le32_encode_bits(addr_cam->offset, ADDR_CAM_W1_OFFSET) |
+ le32_encode_bits(addr_cam->len, ADDR_CAM_W1_LEN);
+ h2c->w2 = le32_encode_bits(addr_cam->valid, ADDR_CAM_W2_VALID) |
+ le32_encode_bits(rtwvif_link->net_type, ADDR_CAM_W2_NET_TYPE) |
+ le32_encode_bits(rtwvif_link->bcn_hit_cond, ADDR_CAM_W2_BCN_HIT_COND) |
+ le32_encode_bits(rtwvif_link->hit_rule, ADDR_CAM_W2_HIT_RULE) |
+ le32_encode_bits(rtwvif_link->phy_idx, ADDR_CAM_W2_BB_SEL) |
+ le32_encode_bits(addr_cam->addr_mask, ADDR_CAM_W2_ADDR_MASK) |
+ le32_encode_bits(addr_cam->mask_sel, ADDR_CAM_W2_MASK_SEL) |
+ le32_encode_bits(sma_hash, ADDR_CAM_W2_SMA_HASH) |
+ le32_encode_bits(tma_hash, ADDR_CAM_W2_TMA_HASH);
+ h2c->w3 = le32_encode_bits(addr_cam->bssid_cam_idx, ADDR_CAM_W3_BSSID_CAM_IDX);
+ h2c->w4 = le32_encode_bits(sma[0], ADDR_CAM_W4_SMA0) |
+ le32_encode_bits(sma[1], ADDR_CAM_W4_SMA1) |
+ le32_encode_bits(sma[2], ADDR_CAM_W4_SMA2) |
+ le32_encode_bits(sma[3], ADDR_CAM_W4_SMA3);
+ h2c->w5 = le32_encode_bits(sma[4], ADDR_CAM_W5_SMA4) |
+ le32_encode_bits(sma[5], ADDR_CAM_W5_SMA5) |
+ le32_encode_bits(tma[0], ADDR_CAM_W5_TMA0) |
+ le32_encode_bits(tma[1], ADDR_CAM_W5_TMA1);
+ h2c->w6 = le32_encode_bits(tma[2], ADDR_CAM_W6_TMA2) |
+ le32_encode_bits(tma[3], ADDR_CAM_W6_TMA3) |
+ le32_encode_bits(tma[4], ADDR_CAM_W6_TMA4) |
+ le32_encode_bits(tma[5], ADDR_CAM_W6_TMA5);
+ h2c->w8 = le32_encode_bits(rtwvif_link->port, ADDR_CAM_W8_PORT_INT) |
+ le32_encode_bits(rtwvif_link->port, ADDR_CAM_W8_TSF_SYNC) |
+ le32_encode_bits(rtwvif_link->trigger, ADDR_CAM_W8_TF_TRS) |
+ le32_encode_bits(rtwvif_link->lsig_txop, ADDR_CAM_W8_LSIG_TXOP) |
+ le32_encode_bits(rtwvif_link->tgt_ind, ADDR_CAM_W8_TGT_IND) |
+ le32_encode_bits(rtwvif_link->frm_tgt_ind, ADDR_CAM_W8_FRM_TGT_IND) |
+ le32_encode_bits(rtwsta_link ? rtwsta_link->mac_id :
+ rtwvif_link->mac_id, ADDR_CAM_W8_MACID);
+
if (rtwvif_link->net_type == RTW89_NET_TYPE_INFRA)
- FWCMD_SET_ADDR_AID12(cmd, vif->cfg.aid & 0xfff);
+ h2c->w9 = le32_encode_bits(vif->cfg.aid & 0xfff, ADDR_CAM_W9_AID12);
else if (rtwvif_link->net_type == RTW89_NET_TYPE_AP_MODE)
- FWCMD_SET_ADDR_AID12(cmd, sta ? sta->aid & 0xfff : 0);
- FWCMD_SET_ADDR_WOL_PATTERN(cmd, rtwvif_link->wowlan_pattern);
- FWCMD_SET_ADDR_WOL_UC(cmd, rtwvif_link->wowlan_uc);
- FWCMD_SET_ADDR_WOL_MAGIC(cmd, rtwvif_link->wowlan_magic);
- FWCMD_SET_ADDR_WAPI(cmd, addr_cam->wapi);
- FWCMD_SET_ADDR_SEC_ENT_MODE(cmd, addr_cam->sec_ent_mode);
- FWCMD_SET_ADDR_SEC_ENT0_KEYID(cmd, addr_cam->sec_ent_keyid[0]);
- FWCMD_SET_ADDR_SEC_ENT1_KEYID(cmd, addr_cam->sec_ent_keyid[1]);
- FWCMD_SET_ADDR_SEC_ENT2_KEYID(cmd, addr_cam->sec_ent_keyid[2]);
- FWCMD_SET_ADDR_SEC_ENT3_KEYID(cmd, addr_cam->sec_ent_keyid[3]);
- FWCMD_SET_ADDR_SEC_ENT4_KEYID(cmd, addr_cam->sec_ent_keyid[4]);
- FWCMD_SET_ADDR_SEC_ENT5_KEYID(cmd, addr_cam->sec_ent_keyid[5]);
- FWCMD_SET_ADDR_SEC_ENT6_KEYID(cmd, addr_cam->sec_ent_keyid[6]);
-
- FWCMD_SET_ADDR_SEC_ENT_VALID(cmd, addr_cam->sec_cam_map[0] & 0xff);
- FWCMD_SET_ADDR_SEC_ENT0(cmd, addr_cam->sec_ent[0]);
- FWCMD_SET_ADDR_SEC_ENT1(cmd, addr_cam->sec_ent[1]);
- FWCMD_SET_ADDR_SEC_ENT2(cmd, addr_cam->sec_ent[2]);
- FWCMD_SET_ADDR_SEC_ENT3(cmd, addr_cam->sec_ent[3]);
- FWCMD_SET_ADDR_SEC_ENT4(cmd, addr_cam->sec_ent[4]);
- FWCMD_SET_ADDR_SEC_ENT5(cmd, addr_cam->sec_ent[5]);
- FWCMD_SET_ADDR_SEC_ENT6(cmd, addr_cam->sec_ent[6]);
+ h2c->w9 = le32_encode_bits(sta ? sta->aid & 0xfff : 0, ADDR_CAM_W9_AID12);
+
+ h2c->w9 |= le32_encode_bits(rtwvif_link->wowlan_pattern, ADDR_CAM_W9_WOL_PATTERN) |
+ le32_encode_bits(rtwvif_link->wowlan_uc, ADDR_CAM_W9_WOL_UC) |
+ le32_encode_bits(rtwvif_link->wowlan_magic, ADDR_CAM_W9_WOL_MAGIC) |
+ le32_encode_bits(addr_cam->wapi, ADDR_CAM_W9_WAPI) |
+ le32_encode_bits(addr_cam->sec_ent_mode, ADDR_CAM_W9_SEC_ENT_MODE) |
+ le32_encode_bits(addr_cam->sec_ent_keyid[0], ADDR_CAM_W9_SEC_ENT0_KEYID) |
+ le32_encode_bits(addr_cam->sec_ent_keyid[1], ADDR_CAM_W9_SEC_ENT1_KEYID) |
+ le32_encode_bits(addr_cam->sec_ent_keyid[2], ADDR_CAM_W9_SEC_ENT2_KEYID) |
+ le32_encode_bits(addr_cam->sec_ent_keyid[3], ADDR_CAM_W9_SEC_ENT3_KEYID) |
+ le32_encode_bits(addr_cam->sec_ent_keyid[4], ADDR_CAM_W9_SEC_ENT4_KEYID) |
+ le32_encode_bits(addr_cam->sec_ent_keyid[5], ADDR_CAM_W9_SEC_ENT5_KEYID) |
+ le32_encode_bits(addr_cam->sec_ent_keyid[6], ADDR_CAM_W9_SEC_ENT6_KEYID);
+ h2c->w10 = le32_encode_bits(addr_cam->sec_cam_map[0] & 0xff, ADDR_CAM_W10_SEC_ENT_VALID) |
+ le32_encode_bits(addr_cam->sec_ent[0], ADDR_CAM_W10_SEC_ENT0) |
+ le32_encode_bits(addr_cam->sec_ent[1], ADDR_CAM_W10_SEC_ENT1) |
+ le32_encode_bits(addr_cam->sec_ent[2], ADDR_CAM_W10_SEC_ENT2);
+ h2c->w11 = le32_encode_bits(addr_cam->sec_ent[3], ADDR_CAM_W11_SEC_ENT3) |
+ le32_encode_bits(addr_cam->sec_ent[4], ADDR_CAM_W11_SEC_ENT4) |
+ le32_encode_bits(addr_cam->sec_ent[5], ADDR_CAM_W11_SEC_ENT5) |
+ le32_encode_bits(addr_cam->sec_ent[6], ADDR_CAM_W11_SEC_ENT6);
rcu_read_unlock();
}
diff --git a/drivers/net/wireless/realtek/rtw89/cam.h b/drivers/net/wireless/realtek/rtw89/cam.h
index 8fd2d776408ea..2bc8fbf79c0b8 100644
--- a/drivers/net/wireless/realtek/rtw89/cam.h
+++ b/drivers/net/wireless/realtek/rtw89/cam.h
@@ -12,345 +12,92 @@
#define RTW89_BSSID_MATCH_ALL GENMASK(5, 0)
#define RTW89_BSSID_MATCH_5_BYTES GENMASK(4, 0)
-static inline void FWCMD_SET_ADDR_IDX(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 1, value, GENMASK(7, 0));
-}
-
-static inline void FWCMD_SET_ADDR_OFFSET(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 1, value, GENMASK(15, 8));
-}
-
-static inline void FWCMD_SET_ADDR_LEN(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 1, value, GENMASK(23, 16));
-}
-
-static inline void FWCMD_SET_ADDR_VALID(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 2, value, BIT(0));
-}
-
-static inline void FWCMD_SET_ADDR_NET_TYPE(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 2, value, GENMASK(2, 1));
-}
-
-static inline void FWCMD_SET_ADDR_BCN_HIT_COND(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 2, value, GENMASK(4, 3));
-}
-
-static inline void FWCMD_SET_ADDR_HIT_RULE(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 2, value, GENMASK(6, 5));
-}
-
-static inline void FWCMD_SET_ADDR_BB_SEL(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 2, value, BIT(7));
-}
-
-static inline void FWCMD_SET_ADDR_ADDR_MASK(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 2, value, GENMASK(13, 8));
-}
-
-static inline void FWCMD_SET_ADDR_MASK_SEL(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 2, value, GENMASK(15, 14));
-}
-
-static inline void FWCMD_SET_ADDR_SMA_HASH(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 2, value, GENMASK(23, 16));
-}
-
-static inline void FWCMD_SET_ADDR_TMA_HASH(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 2, value, GENMASK(31, 24));
-}
-
-static inline void FWCMD_SET_ADDR_BSSID_CAM_IDX(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 3, value, GENMASK(5, 0));
-}
-
-static inline void FWCMD_SET_ADDR_SMA0(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 4, value, GENMASK(7, 0));
-}
-
-static inline void FWCMD_SET_ADDR_SMA1(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 4, value, GENMASK(15, 8));
-}
-
-static inline void FWCMD_SET_ADDR_SMA2(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 4, value, GENMASK(23, 16));
-}
-
-static inline void FWCMD_SET_ADDR_SMA3(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 4, value, GENMASK(31, 24));
-}
-
-static inline void FWCMD_SET_ADDR_SMA4(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 5, value, GENMASK(7, 0));
-}
-
-static inline void FWCMD_SET_ADDR_SMA5(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 5, value, GENMASK(15, 8));
-}
-
-static inline void FWCMD_SET_ADDR_TMA0(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 5, value, GENMASK(23, 16));
-}
-
-static inline void FWCMD_SET_ADDR_TMA1(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 5, value, GENMASK(31, 24));
-}
-
-static inline void FWCMD_SET_ADDR_TMA2(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 6, value, GENMASK(7, 0));
-}
-
-static inline void FWCMD_SET_ADDR_TMA3(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 6, value, GENMASK(15, 8));
-}
-
-static inline void FWCMD_SET_ADDR_TMA4(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 6, value, GENMASK(23, 16));
-}
-
-static inline void FWCMD_SET_ADDR_TMA5(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 6, value, GENMASK(31, 24));
-}
-
-static inline void FWCMD_SET_ADDR_MACID(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 8, value, GENMASK(7, 0));
-}
-
-static inline void FWCMD_SET_ADDR_PORT_INT(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 8, value, GENMASK(10, 8));
-}
-
-static inline void FWCMD_SET_ADDR_TSF_SYNC(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 8, value, GENMASK(13, 11));
-}
-
-static inline void FWCMD_SET_ADDR_TF_TRS(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 8, value, BIT(14));
-}
-
-static inline void FWCMD_SET_ADDR_LSIG_TXOP(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 8, value, BIT(15));
-}
-
-static inline void FWCMD_SET_ADDR_TGT_IND(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 8, value, GENMASK(26, 24));
-}
-
-static inline void FWCMD_SET_ADDR_FRM_TGT_IND(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 8, value, GENMASK(29, 27));
-}
-
-static inline void FWCMD_SET_ADDR_AID12(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 9, value, GENMASK(11, 0));
-}
-
-static inline void FWCMD_SET_ADDR_AID12_0(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 9, value, GENMASK(7, 0));
-}
-
-static inline void FWCMD_SET_ADDR_AID12_1(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 9, value, GENMASK(11, 8));
-}
-
-static inline void FWCMD_SET_ADDR_WOL_PATTERN(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 9, value, BIT(12));
-}
-
-static inline void FWCMD_SET_ADDR_WOL_UC(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 9, value, BIT(13));
-}
-
-static inline void FWCMD_SET_ADDR_WOL_MAGIC(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 9, value, BIT(14));
-}
-
-static inline void FWCMD_SET_ADDR_WAPI(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 9, value, BIT(15));
-}
-
-static inline void FWCMD_SET_ADDR_SEC_ENT_MODE(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 9, value, GENMASK(17, 16));
-}
-
-static inline void FWCMD_SET_ADDR_SEC_ENT0_KEYID(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 9, value, GENMASK(19, 18));
-}
-
-static inline void FWCMD_SET_ADDR_SEC_ENT1_KEYID(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 9, value, GENMASK(21, 20));
-}
-
-static inline void FWCMD_SET_ADDR_SEC_ENT2_KEYID(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 9, value, GENMASK(23, 22));
-}
-
-static inline void FWCMD_SET_ADDR_SEC_ENT3_KEYID(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 9, value, GENMASK(25, 24));
-}
-
-static inline void FWCMD_SET_ADDR_SEC_ENT4_KEYID(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 9, value, GENMASK(27, 26));
-}
-
-static inline void FWCMD_SET_ADDR_SEC_ENT5_KEYID(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 9, value, GENMASK(29, 28));
-}
-
-static inline void FWCMD_SET_ADDR_SEC_ENT6_KEYID(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 9, value, GENMASK(31, 30));
-}
-
-static inline void FWCMD_SET_ADDR_SEC_ENT_VALID(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 10, value, GENMASK(7, 0));
-}
-
-static inline void FWCMD_SET_ADDR_SEC_ENT0(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 10, value, GENMASK(15, 8));
-}
-
-static inline void FWCMD_SET_ADDR_SEC_ENT1(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 10, value, GENMASK(23, 16));
-}
-
-static inline void FWCMD_SET_ADDR_SEC_ENT2(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 10, value, GENMASK(31, 24));
-}
-
-static inline void FWCMD_SET_ADDR_SEC_ENT3(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 11, value, GENMASK(7, 0));
-}
-
-static inline void FWCMD_SET_ADDR_SEC_ENT4(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 11, value, GENMASK(15, 8));
-}
-
-static inline void FWCMD_SET_ADDR_SEC_ENT5(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 11, value, GENMASK(23, 16));
-}
-
-static inline void FWCMD_SET_ADDR_SEC_ENT6(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 11, value, GENMASK(31, 24));
-}
-
-static inline void FWCMD_SET_ADDR_BSSID_IDX(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 12, value, GENMASK(7, 0));
-}
-
-static inline void FWCMD_SET_ADDR_BSSID_OFFSET(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 12, value, GENMASK(15, 8));
-}
-
-static inline void FWCMD_SET_ADDR_BSSID_LEN(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 12, value, GENMASK(23, 16));
-}
-
-static inline void FWCMD_SET_ADDR_BSSID_VALID(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 13, value, BIT(0));
-}
-
-static inline void FWCMD_SET_ADDR_BSSID_BB_SEL(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 13, value, BIT(1));
-}
-
-static inline void FWCMD_SET_ADDR_BSSID_MASK(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 13, value, GENMASK(7, 2));
-}
-
-static inline void FWCMD_SET_ADDR_BSSID_BSS_COLOR(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 13, value, GENMASK(13, 8));
-}
-
-static inline void FWCMD_SET_ADDR_BSSID_BSSID0(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 13, value, GENMASK(23, 16));
-}
-
-static inline void FWCMD_SET_ADDR_BSSID_BSSID1(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 13, value, GENMASK(31, 24));
-}
-
-static inline void FWCMD_SET_ADDR_BSSID_BSSID2(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 14, value, GENMASK(7, 0));
-}
-
-static inline void FWCMD_SET_ADDR_BSSID_BSSID3(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 14, value, GENMASK(15, 8));
-}
-
-static inline void FWCMD_SET_ADDR_BSSID_BSSID4(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 14, value, GENMASK(23, 16));
-}
+struct rtw89_h2c_addr_cam {
+ __le32 w0;
+ __le32 w1;
+ __le32 w2;
+ __le32 w3;
+ __le32 w4;
+ __le32 w5;
+ __le32 w6;
+ __le32 w7;
+ __le32 w8;
+ __le32 w9;
+ __le32 w10;
+ __le32 w11;
+ __le32 w12;
+ __le32 w13;
+ __le32 w14;
+} __packed;
-static inline void FWCMD_SET_ADDR_BSSID_BSSID5(void *cmd, u32 value)
-{
- le32p_replace_bits((__le32 *)(cmd) + 14, value, GENMASK(31, 24));
-}
+#define ADDR_CAM_W1_IDX GENMASK(7, 0)
+#define ADDR_CAM_W1_OFFSET GENMASK(15, 8)
+#define ADDR_CAM_W1_LEN GENMASK(23, 16)
+#define ADDR_CAM_W2_VALID BIT(0)
+#define ADDR_CAM_W2_NET_TYPE GENMASK(2, 1)
+#define ADDR_CAM_W2_BCN_HIT_COND GENMASK(4, 3)
+#define ADDR_CAM_W2_HIT_RULE GENMASK(6, 5)
+#define ADDR_CAM_W2_BB_SEL BIT(7)
+#define ADDR_CAM_W2_ADDR_MASK GENMASK(13, 8)
+#define ADDR_CAM_W2_MASK_SEL GENMASK(15, 14)
+#define ADDR_CAM_W2_SMA_HASH GENMASK(23, 16)
+#define ADDR_CAM_W2_TMA_HASH GENMASK(31, 24)
+#define ADDR_CAM_W3_BSSID_CAM_IDX GENMASK(5, 0)
+#define ADDR_CAM_W4_SMA0 GENMASK(7, 0)
+#define ADDR_CAM_W4_SMA1 GENMASK(15, 8)
+#define ADDR_CAM_W4_SMA2 GENMASK(23, 16)
+#define ADDR_CAM_W4_SMA3 GENMASK(31, 24)
+#define ADDR_CAM_W5_SMA4 GENMASK(7, 0)
+#define ADDR_CAM_W5_SMA5 GENMASK(15, 8)
+#define ADDR_CAM_W5_TMA0 GENMASK(23, 16)
+#define ADDR_CAM_W5_TMA1 GENMASK(31, 24)
+#define ADDR_CAM_W6_TMA2 GENMASK(7, 0)
+#define ADDR_CAM_W6_TMA3 GENMASK(15, 8)
+#define ADDR_CAM_W6_TMA4 GENMASK(23, 16)
+#define ADDR_CAM_W6_TMA5 GENMASK(31, 24)
+#define ADDR_CAM_W8_MACID GENMASK(7, 0)
+#define ADDR_CAM_W8_PORT_INT GENMASK(10, 8)
+#define ADDR_CAM_W8_TSF_SYNC GENMASK(13, 11)
+#define ADDR_CAM_W8_TF_TRS BIT(14)
+#define ADDR_CAM_W8_LSIG_TXOP BIT(15)
+#define ADDR_CAM_W8_TGT_IND GENMASK(26, 24)
+#define ADDR_CAM_W8_FRM_TGT_IND GENMASK(29, 27)
+#define ADDR_CAM_W9_AID12 GENMASK(11, 0)
+#define ADDR_CAM_W9_AID12_0 GENMASK(7, 0)
+#define ADDR_CAM_W9_AID12_1 GENMASK(11, 8)
+#define ADDR_CAM_W9_WOL_PATTERN BIT(12)
+#define ADDR_CAM_W9_WOL_UC BIT(13)
+#define ADDR_CAM_W9_WOL_MAGIC BIT(14)
+#define ADDR_CAM_W9_WAPI BIT(15)
+#define ADDR_CAM_W9_SEC_ENT_MODE GENMASK(17, 16)
+#define ADDR_CAM_W9_SEC_ENT0_KEYID GENMASK(19, 18)
+#define ADDR_CAM_W9_SEC_ENT1_KEYID GENMASK(21, 20)
+#define ADDR_CAM_W9_SEC_ENT2_KEYID GENMASK(23, 22)
+#define ADDR_CAM_W9_SEC_ENT3_KEYID GENMASK(25, 24)
+#define ADDR_CAM_W9_SEC_ENT4_KEYID GENMASK(27, 26)
+#define ADDR_CAM_W9_SEC_ENT5_KEYID GENMASK(29, 28)
+#define ADDR_CAM_W9_SEC_ENT6_KEYID GENMASK(31, 30)
+#define ADDR_CAM_W10_SEC_ENT_VALID GENMASK(7, 0)
+#define ADDR_CAM_W10_SEC_ENT0 GENMASK(15, 8)
+#define ADDR_CAM_W10_SEC_ENT1 GENMASK(23, 16)
+#define ADDR_CAM_W10_SEC_ENT2 GENMASK(31, 24)
+#define ADDR_CAM_W11_SEC_ENT3 GENMASK(7, 0)
+#define ADDR_CAM_W11_SEC_ENT4 GENMASK(15, 8)
+#define ADDR_CAM_W11_SEC_ENT5 GENMASK(23, 16)
+#define ADDR_CAM_W11_SEC_ENT6 GENMASK(31, 24)
+#define ADDR_CAM_W12_BSSID_IDX GENMASK(7, 0)
+#define ADDR_CAM_W12_BSSID_OFFSET GENMASK(15, 8)
+#define ADDR_CAM_W12_BSSID_LEN GENMASK(23, 16)
+#define ADDR_CAM_W13_BSSID_VALID BIT(0)
+#define ADDR_CAM_W13_BSSID_BB_SEL BIT(1)
+#define ADDR_CAM_W13_BSSID_MASK GENMASK(7, 2)
+#define ADDR_CAM_W13_BSSID_BSS_COLOR GENMASK(13, 8)
+#define ADDR_CAM_W13_BSSID_BSSID0 GENMASK(23, 16)
+#define ADDR_CAM_W13_BSSID_BSSID1 GENMASK(31, 24)
+#define ADDR_CAM_W14_BSSID_BSSID2 GENMASK(7, 0)
+#define ADDR_CAM_W14_BSSID_BSSID3 GENMASK(15, 8)
+#define ADDR_CAM_W14_BSSID_BSSID4 GENMASK(23, 16)
+#define ADDR_CAM_W14_BSSID_BSSID5 GENMASK(31, 24)
struct rtw89_h2c_dctlinfo_ud_v1 {
__le32 c0;
@@ -552,9 +299,10 @@ int rtw89_cam_init_bssid_cam(struct rtw89_dev *rtwdev,
void rtw89_cam_deinit_bssid_cam(struct rtw89_dev *rtwdev,
struct rtw89_bssid_cam_entry *bssid_cam);
void rtw89_cam_fill_addr_cam_info(struct rtw89_dev *rtwdev,
- struct rtw89_vif_link *vif,
+ struct rtw89_vif_link *rtwvif_link,
struct rtw89_sta_link *rtwsta_link,
- const u8 *scan_mac_addr, u8 *cmd);
+ const u8 *scan_mac_addr,
+ struct rtw89_h2c_addr_cam *h2c);
void rtw89_cam_fill_dctl_sec_cam_info_v1(struct rtw89_dev *rtwdev,
struct rtw89_vif_link *rtwvif_link,
struct rtw89_sta_link *rtwsta_link,
@@ -565,7 +313,8 @@ void rtw89_cam_fill_dctl_sec_cam_info_v2(struct rtw89_dev *rtwdev,
struct rtw89_h2c_dctlinfo_ud_v2 *h2c);
int rtw89_cam_fill_bssid_cam_info(struct rtw89_dev *rtwdev,
struct rtw89_vif_link *rtwvif_link,
- struct rtw89_sta_link *rtwsta_link, u8 *cmd);
+ struct rtw89_sta_link *rtwsta_link,
+ struct rtw89_h2c_addr_cam *h2c);
int rtw89_cam_sec_key_add(struct rtw89_dev *rtwdev,
struct ieee80211_vif *vif,
struct ieee80211_sta *sta,
diff --git a/drivers/net/wireless/realtek/rtw89/fw.c b/drivers/net/wireless/realtek/rtw89/fw.c
index 15ac357bbdbac..04040efdf1f1b 100644
--- a/drivers/net/wireless/realtek/rtw89/fw.c
+++ b/drivers/net/wireless/realtek/rtw89/fw.c
@@ -2110,28 +2110,31 @@ void rtw89_fw_log_dump(struct rtw89_dev *rtwdev, u8 *buf, u32 len)
}
-#define H2C_CAM_LEN 60
int rtw89_fw_h2c_cam(struct rtw89_dev *rtwdev, struct rtw89_vif_link *rtwvif_link,
struct rtw89_sta_link *rtwsta_link, const u8 *scan_mac_addr)
{
+ struct rtw89_h2c_addr_cam *h2c;
+ u32 len = sizeof(*h2c);
struct sk_buff *skb;
int ret;
- skb = rtw89_fw_h2c_alloc_skb_with_hdr(rtwdev, H2C_CAM_LEN);
+ skb = rtw89_fw_h2c_alloc_skb_with_hdr(rtwdev, len);
if (!skb) {
rtw89_err(rtwdev, "failed to alloc skb for fw dl\n");
return -ENOMEM;
}
- skb_put(skb, H2C_CAM_LEN);
- rtw89_cam_fill_addr_cam_info(rtwdev, rtwvif_link, rtwsta_link, scan_mac_addr,
- skb->data);
- rtw89_cam_fill_bssid_cam_info(rtwdev, rtwvif_link, rtwsta_link, skb->data);
+ skb_put(skb, len);
+ h2c = (struct rtw89_h2c_addr_cam *)skb->data;
+
+ rtw89_cam_fill_addr_cam_info(rtwdev, rtwvif_link, rtwsta_link,
+ scan_mac_addr, h2c);
+ rtw89_cam_fill_bssid_cam_info(rtwdev, rtwvif_link, rtwsta_link, h2c);
rtw89_h2c_pkt_set_hdr(rtwdev, skb, FWCMD_TYPE_H2C,
H2C_CAT_MAC,
H2C_CL_MAC_ADDR_CAM_UPDATE,
H2C_FUNC_MAC_ADDR_CAM_UPD, 0, 1,
- H2C_CAM_LEN);
+ len);
ret = rtw89_h2c_tx(rtwdev, skb, false);
if (ret) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0190/1518] wifi: rtw89: update format of addr cam H2C command
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (188 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0189/1518] wifi: rtw89: fill addr cam H2C command by struct Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0191/1518] wifi: rtw89: check return values in rtw89_ops_start_ap() Greg Kroah-Hartman
` (808 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chih-Kang Chang, Ping-Ke Shih,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chih-Kang Chang <gary.chang@realtek.com>
[ Upstream commit 9dab26b9fa457ee538be650ca0bddf352c059e79 ]
The addr cam H2C command is to tell firmware the addr related info.
For RTL8922D and RTL8922A after firmware version 0.35.84.0, the addr cam
must be updated with update mode to avoid clearing previously set
fields. Update it accordingly.
Signed-off-by: Chih-Kang Chang <gary.chang@realtek.com>
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
Link: https://patch.msgid.link/20251114060128.35363-14-pkshih@realtek.com
Stable-dep-of: a8cddb62c573 ("wifi: rtw89: check return values in rtw89_ops_start_ap()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/realtek/rtw89/cam.c | 10 ++++---
drivers/net/wireless/realtek/rtw89/cam.h | 12 ++++++---
drivers/net/wireless/realtek/rtw89/core.c | 12 ++++++---
drivers/net/wireless/realtek/rtw89/core.h | 1 +
drivers/net/wireless/realtek/rtw89/fw.c | 26 ++++++++++++++++---
drivers/net/wireless/realtek/rtw89/fw.h | 3 ++-
drivers/net/wireless/realtek/rtw89/mac.c | 4 +--
drivers/net/wireless/realtek/rtw89/mac80211.c | 4 +--
drivers/net/wireless/realtek/rtw89/wow.c | 6 +++--
9 files changed, 56 insertions(+), 22 deletions(-)
diff --git a/drivers/net/wireless/realtek/rtw89/cam.c b/drivers/net/wireless/realtek/rtw89/cam.c
index 8233d91024e8e..93a0294396351 100644
--- a/drivers/net/wireless/realtek/rtw89/cam.c
+++ b/drivers/net/wireless/realtek/rtw89/cam.c
@@ -236,7 +236,8 @@ static int __rtw89_cam_detach_sec_cam(struct rtw89_dev *rtwdev,
if (ret)
rtw89_err(rtwdev,
"failed to update dctl cam del key: %d\n", ret);
- ret = rtw89_fw_h2c_cam(rtwdev, rtwvif_link, rtwsta_link, NULL);
+ ret = rtw89_fw_h2c_cam(rtwdev, rtwvif_link, rtwsta_link, NULL,
+ RTW89_ROLE_INFO_CHANGE);
if (ret)
rtw89_err(rtwdev, "failed to update cam del key: %d\n", ret);
}
@@ -276,7 +277,8 @@ static int __rtw89_cam_attach_sec_cam(struct rtw89_dev *rtwdev,
ret);
return ret;
}
- ret = rtw89_fw_h2c_cam(rtwdev, rtwvif_link, rtwsta_link, NULL);
+ ret = rtw89_fw_h2c_cam(rtwdev, rtwvif_link, rtwsta_link, NULL,
+ RTW89_ROLE_INFO_CHANGE);
if (ret) {
rtw89_err(rtwdev, "failed to update addr cam sec entry: %d\n",
ret);
@@ -761,7 +763,7 @@ int rtw89_cam_init(struct rtw89_dev *rtwdev, struct rtw89_vif_link *rtwvif_link)
int rtw89_cam_fill_bssid_cam_info(struct rtw89_dev *rtwdev,
struct rtw89_vif_link *rtwvif_link,
struct rtw89_sta_link *rtwsta_link,
- struct rtw89_h2c_addr_cam *h2c)
+ struct rtw89_h2c_addr_cam_v0 *h2c)
{
struct rtw89_bssid_cam_entry *bssid_cam = rtw89_get_bssid_cam_of(rtwvif_link,
rtwsta_link);
@@ -813,7 +815,7 @@ void rtw89_cam_fill_addr_cam_info(struct rtw89_dev *rtwdev,
struct rtw89_vif_link *rtwvif_link,
struct rtw89_sta_link *rtwsta_link,
const u8 *scan_mac_addr,
- struct rtw89_h2c_addr_cam *h2c)
+ struct rtw89_h2c_addr_cam_v0 *h2c)
{
struct ieee80211_vif *vif = rtwvif_link_to_vif(rtwvif_link);
struct rtw89_addr_cam_entry *addr_cam =
diff --git a/drivers/net/wireless/realtek/rtw89/cam.h b/drivers/net/wireless/realtek/rtw89/cam.h
index 2bc8fbf79c0b8..4436bacf0348e 100644
--- a/drivers/net/wireless/realtek/rtw89/cam.h
+++ b/drivers/net/wireless/realtek/rtw89/cam.h
@@ -12,7 +12,7 @@
#define RTW89_BSSID_MATCH_ALL GENMASK(5, 0)
#define RTW89_BSSID_MATCH_5_BYTES GENMASK(4, 0)
-struct rtw89_h2c_addr_cam {
+struct rtw89_h2c_addr_cam_v0 {
__le32 w0;
__le32 w1;
__le32 w2;
@@ -30,6 +30,11 @@ struct rtw89_h2c_addr_cam {
__le32 w14;
} __packed;
+struct rtw89_h2c_addr_cam {
+ struct rtw89_h2c_addr_cam_v0 v0;
+ __le32 w15;
+} __packed;
+
#define ADDR_CAM_W1_IDX GENMASK(7, 0)
#define ADDR_CAM_W1_OFFSET GENMASK(15, 8)
#define ADDR_CAM_W1_LEN GENMASK(23, 16)
@@ -98,6 +103,7 @@ struct rtw89_h2c_addr_cam {
#define ADDR_CAM_W14_BSSID_BSSID3 GENMASK(15, 8)
#define ADDR_CAM_W14_BSSID_BSSID4 GENMASK(23, 16)
#define ADDR_CAM_W14_BSSID_BSSID5 GENMASK(31, 24)
+#define ADDR_CAM_W15_UPD_MODE GENMASK(2, 0)
struct rtw89_h2c_dctlinfo_ud_v1 {
__le32 c0;
@@ -302,7 +308,7 @@ void rtw89_cam_fill_addr_cam_info(struct rtw89_dev *rtwdev,
struct rtw89_vif_link *rtwvif_link,
struct rtw89_sta_link *rtwsta_link,
const u8 *scan_mac_addr,
- struct rtw89_h2c_addr_cam *h2c);
+ struct rtw89_h2c_addr_cam_v0 *h2c);
void rtw89_cam_fill_dctl_sec_cam_info_v1(struct rtw89_dev *rtwdev,
struct rtw89_vif_link *rtwvif_link,
struct rtw89_sta_link *rtwsta_link,
@@ -314,7 +320,7 @@ void rtw89_cam_fill_dctl_sec_cam_info_v2(struct rtw89_dev *rtwdev,
int rtw89_cam_fill_bssid_cam_info(struct rtw89_dev *rtwdev,
struct rtw89_vif_link *rtwvif_link,
struct rtw89_sta_link *rtwsta_link,
- struct rtw89_h2c_addr_cam *h2c);
+ struct rtw89_h2c_addr_cam_v0 *h2c);
int rtw89_cam_sec_key_add(struct rtw89_dev *rtwdev,
struct ieee80211_vif *vif,
struct ieee80211_sta *sta,
diff --git a/drivers/net/wireless/realtek/rtw89/core.c b/drivers/net/wireless/realtek/rtw89/core.c
index 018857d3569a8..5fd15fc840d8c 100644
--- a/drivers/net/wireless/realtek/rtw89/core.c
+++ b/drivers/net/wireless/realtek/rtw89/core.c
@@ -4703,7 +4703,8 @@ int rtw89_core_sta_link_disconnect(struct rtw89_dev *rtwdev,
}
/* update cam aid mac_id net_type */
- ret = rtw89_fw_h2c_cam(rtwdev, rtwvif_link, rtwsta_link, NULL);
+ ret = rtw89_fw_h2c_cam(rtwdev, rtwvif_link, rtwsta_link, NULL,
+ RTW89_ROLE_CON_DISCONN);
if (ret) {
rtw89_warn(rtwdev, "failed to send h2c cam\n");
return ret;
@@ -4777,7 +4778,8 @@ int rtw89_core_sta_link_assoc(struct rtw89_dev *rtwdev,
}
/* update cam aid mac_id net_type */
- ret = rtw89_fw_h2c_cam(rtwdev, rtwvif_link, rtwsta_link, NULL);
+ ret = rtw89_fw_h2c_cam(rtwdev, rtwvif_link, rtwsta_link, NULL,
+ RTW89_ROLE_CON_DISCONN);
if (ret) {
rtw89_warn(rtwdev, "failed to send h2c cam\n");
return ret;
@@ -5895,7 +5897,8 @@ void rtw89_core_scan_start(struct rtw89_dev *rtwdev, struct rtw89_vif_link *rtwv
rtw89_phy_config_edcca(rtwdev, bb, true);
rtw89_tas_scan(rtwdev, true);
- rtw89_fw_h2c_cam(rtwdev, rtwvif_link, NULL, mac_addr);
+ rtw89_fw_h2c_cam(rtwdev, rtwvif_link, NULL, mac_addr,
+ RTW89_ROLE_INFO_CHANGE);
}
void rtw89_core_scan_complete(struct rtw89_dev *rtwdev,
@@ -5915,7 +5918,8 @@ void rtw89_core_scan_complete(struct rtw89_dev *rtwdev,
rcu_read_unlock();
- rtw89_fw_h2c_cam(rtwdev, rtwvif_link, NULL, NULL);
+ rtw89_fw_h2c_cam(rtwdev, rtwvif_link, NULL, NULL,
+ RTW89_ROLE_INFO_CHANGE);
rtw89_chip_rfk_scan(rtwdev, rtwvif_link, false);
rtw89_btc_ntfy_scan_finish(rtwdev, rtwvif_link->phy_idx);
diff --git a/drivers/net/wireless/realtek/rtw89/core.h b/drivers/net/wireless/realtek/rtw89/core.h
index 7e35168e8d606..30bc177808352 100644
--- a/drivers/net/wireless/realtek/rtw89/core.h
+++ b/drivers/net/wireless/realtek/rtw89/core.h
@@ -4640,6 +4640,7 @@ enum rtw89_fw_feature {
RTW89_FW_FEATURE_RFK_NTFY_MCC_V0,
RTW89_FW_FEATURE_LPS_DACK_BY_C2H_REG,
RTW89_FW_FEATURE_BEACON_TRACKING,
+ RTW89_FW_FEATURE_ADDR_CAM_V0,
};
struct rtw89_fw_suit {
diff --git a/drivers/net/wireless/realtek/rtw89/fw.c b/drivers/net/wireless/realtek/rtw89/fw.c
index 04040efdf1f1b..81cd3ea2c3b69 100644
--- a/drivers/net/wireless/realtek/rtw89/fw.c
+++ b/drivers/net/wireless/realtek/rtw89/fw.c
@@ -870,6 +870,7 @@ static const struct __fw_feat_cfg fw_feat_tbl[] = {
__CFG_FW_FEAT(RTL8922A, ge, 0, 35, 76, 0, LPS_DACK_BY_C2H_REG),
__CFG_FW_FEAT(RTL8922A, ge, 0, 35, 79, 0, CRASH_TRIGGER_TYPE_1),
__CFG_FW_FEAT(RTL8922A, ge, 0, 35, 80, 0, BEACON_TRACKING),
+ __CFG_FW_FEAT(RTL8922A, lt, 0, 35, 84, 0, ADDR_CAM_V0),
};
static void rtw89_fw_iterate_feature_cfg(struct rtw89_fw_info *fw,
@@ -2111,25 +2112,42 @@ void rtw89_fw_log_dump(struct rtw89_dev *rtwdev, u8 *buf, u32 len)
}
int rtw89_fw_h2c_cam(struct rtw89_dev *rtwdev, struct rtw89_vif_link *rtwvif_link,
- struct rtw89_sta_link *rtwsta_link, const u8 *scan_mac_addr)
+ struct rtw89_sta_link *rtwsta_link, const u8 *scan_mac_addr,
+ enum rtw89_upd_mode upd_mode)
{
+ const struct rtw89_chip_info *chip = rtwdev->chip;
+ struct rtw89_h2c_addr_cam_v0 *h2c_v0;
struct rtw89_h2c_addr_cam *h2c;
u32 len = sizeof(*h2c);
struct sk_buff *skb;
+ u8 ver = U8_MAX;
int ret;
+ if (RTW89_CHK_FW_FEATURE(ADDR_CAM_V0, &rtwdev->fw) ||
+ chip->chip_gen == RTW89_CHIP_AX) {
+ len = sizeof(*h2c_v0);
+ ver = 0;
+ }
+
skb = rtw89_fw_h2c_alloc_skb_with_hdr(rtwdev, len);
if (!skb) {
rtw89_err(rtwdev, "failed to alloc skb for fw dl\n");
return -ENOMEM;
}
skb_put(skb, len);
- h2c = (struct rtw89_h2c_addr_cam *)skb->data;
+ h2c_v0 = (struct rtw89_h2c_addr_cam_v0 *)skb->data;
rtw89_cam_fill_addr_cam_info(rtwdev, rtwvif_link, rtwsta_link,
- scan_mac_addr, h2c);
- rtw89_cam_fill_bssid_cam_info(rtwdev, rtwvif_link, rtwsta_link, h2c);
+ scan_mac_addr, h2c_v0);
+ rtw89_cam_fill_bssid_cam_info(rtwdev, rtwvif_link, rtwsta_link, h2c_v0);
+ if (ver == 0)
+ goto hdr;
+
+ h2c = (struct rtw89_h2c_addr_cam *)skb->data;
+ h2c->w15 = le32_encode_bits(upd_mode, ADDR_CAM_W15_UPD_MODE);
+
+hdr:
rtw89_h2c_pkt_set_hdr(rtwdev, skb, FWCMD_TYPE_H2C,
H2C_CAT_MAC,
H2C_CL_MAC_ADDR_CAM_UPDATE,
diff --git a/drivers/net/wireless/realtek/rtw89/fw.h b/drivers/net/wireless/realtek/rtw89/fw.h
index 47e5cbec306d2..7c3cb6d85ca5d 100644
--- a/drivers/net/wireless/realtek/rtw89/fw.h
+++ b/drivers/net/wireless/realtek/rtw89/fw.h
@@ -4827,7 +4827,8 @@ int rtw89_fw_h2c_tbtt_tuning(struct rtw89_dev *rtwdev,
struct rtw89_vif_link *rtwvif_link, u32 offset);
int rtw89_fw_h2c_pwr_lvl(struct rtw89_dev *rtwdev, struct rtw89_vif_link *rtwvif_link);
int rtw89_fw_h2c_cam(struct rtw89_dev *rtwdev, struct rtw89_vif_link *vif,
- struct rtw89_sta_link *rtwsta_link, const u8 *scan_mac_addr);
+ struct rtw89_sta_link *rtwsta_link, const u8 *scan_mac_addr,
+ enum rtw89_upd_mode upd_mode);
int rtw89_fw_h2c_dctl_sec_cam_v1(struct rtw89_dev *rtwdev,
struct rtw89_vif_link *rtwvif_link,
struct rtw89_sta_link *rtwsta_link);
diff --git a/drivers/net/wireless/realtek/rtw89/mac.c b/drivers/net/wireless/realtek/rtw89/mac.c
index 71194ea68bcee..8194ae570ee94 100644
--- a/drivers/net/wireless/realtek/rtw89/mac.c
+++ b/drivers/net/wireless/realtek/rtw89/mac.c
@@ -4786,7 +4786,7 @@ int rtw89_mac_vif_init(struct rtw89_dev *rtwdev, struct rtw89_vif_link *rtwvif_l
if (ret)
return ret;
- ret = rtw89_fw_h2c_cam(rtwdev, rtwvif_link, NULL, NULL);
+ ret = rtw89_fw_h2c_cam(rtwdev, rtwvif_link, NULL, NULL, RTW89_ROLE_CREATE);
if (ret)
return ret;
@@ -4811,7 +4811,7 @@ int rtw89_mac_vif_deinit(struct rtw89_dev *rtwdev, struct rtw89_vif_link *rtwvif
rtw89_cam_deinit(rtwdev, rtwvif_link);
- ret = rtw89_fw_h2c_cam(rtwdev, rtwvif_link, NULL, NULL);
+ ret = rtw89_fw_h2c_cam(rtwdev, rtwvif_link, NULL, NULL, RTW89_ROLE_REMOVE);
if (ret)
return ret;
diff --git a/drivers/net/wireless/realtek/rtw89/mac80211.c b/drivers/net/wireless/realtek/rtw89/mac80211.c
index 968d0346a87f4..7c8ec4f3c77e9 100644
--- a/drivers/net/wireless/realtek/rtw89/mac80211.c
+++ b/drivers/net/wireless/realtek/rtw89/mac80211.c
@@ -745,7 +745,7 @@ static void rtw89_ops_link_info_changed(struct ieee80211_hw *hw,
if (changed & BSS_CHANGED_BSSID) {
ether_addr_copy(rtwvif_link->bssid, conf->bssid);
rtw89_cam_bssid_changed(rtwdev, rtwvif_link);
- rtw89_fw_h2c_cam(rtwdev, rtwvif_link, NULL, NULL);
+ rtw89_fw_h2c_cam(rtwdev, rtwvif_link, NULL, NULL, RTW89_ROLE_INFO_CHANGE);
WRITE_ONCE(rtwvif_link->sync_bcn_tsf, 0);
}
@@ -804,7 +804,7 @@ static int rtw89_ops_start_ap(struct ieee80211_hw *hw,
rtw89_chip_h2c_assoc_cmac_tbl(rtwdev, rtwvif_link, NULL);
rtw89_fw_h2c_role_maintain(rtwdev, rtwvif_link, NULL, RTW89_ROLE_TYPE_CHANGE);
rtw89_fw_h2c_join_info(rtwdev, rtwvif_link, NULL, true);
- rtw89_fw_h2c_cam(rtwdev, rtwvif_link, NULL, NULL);
+ rtw89_fw_h2c_cam(rtwdev, rtwvif_link, NULL, NULL, RTW89_ROLE_TYPE_CHANGE);
rtw89_chip_rfk_channel(rtwdev, rtwvif_link);
if (RTW89_CHK_FW_FEATURE(NOTIFY_AP_INFO, &rtwdev->fw)) {
diff --git a/drivers/net/wireless/realtek/rtw89/wow.c b/drivers/net/wireless/realtek/rtw89/wow.c
index f34cd863d1009..f6cdbc15dcc4a 100644
--- a/drivers/net/wireless/realtek/rtw89/wow.c
+++ b/drivers/net/wireless/realtek/rtw89/wow.c
@@ -1225,7 +1225,8 @@ static int rtw89_wow_cfg_wake(struct rtw89_dev *rtwdev, bool wow)
}
}
- ret = rtw89_fw_h2c_cam(rtwdev, rtwvif_link, rtwsta_link, NULL);
+ ret = rtw89_fw_h2c_cam(rtwdev, rtwvif_link, rtwsta_link, NULL,
+ RTW89_ROLE_INFO_CHANGE);
if (ret) {
rtw89_warn(rtwdev, "failed to send h2c cam\n");
return ret;
@@ -1322,7 +1323,8 @@ static int rtw89_wow_swap_fw(struct rtw89_dev *rtwdev, bool wow)
return ret;
}
- ret = rtw89_fw_h2c_cam(rtwdev, rtwvif_link, rtwsta_link, NULL);
+ ret = rtw89_fw_h2c_cam(rtwdev, rtwvif_link, rtwsta_link, NULL,
+ RTW89_ROLE_FW_RESTORE);
if (ret) {
rtw89_warn(rtwdev, "failed to send h2c cam\n");
return ret;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0191/1518] wifi: rtw89: check return values in rtw89_ops_start_ap()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (189 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0190/1518] wifi: rtw89: update format of addr cam H2C command Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0192/1518] wifi: rtw89: fix HE extended capability length check Greg Kroah-Hartman
` (807 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dmitry Morgun, Ping-Ke Shih,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Morgun <d.morgun@ispras.ru>
[ Upstream commit a8cddb62c573f28eef5f887a8f3156e8ee22776a ]
Several functions called in rtw89_ops_start_ap() may fail to allocate
skb or fail to send H2C command to firmware, returning -ENOMEM or an
error code. Their return values are ignored, so subsequent commands
are executed with incorrect state.
Check the return values and propagate errors.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Fixes: a52e4f2ce0f5 ("rtw89: implement ieee80211_ops::start_ap and stop_ap")
Signed-off-by: Dmitry Morgun <d.morgun@ispras.ru>
Acked-by: Ping-Ke Shih <pkshih@realtek.com>
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
Link: https://patch.msgid.link/20260629094452.8709-1-d.morgun@ispras.ru
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/realtek/rtw89/mac80211.c | 35 ++++++++++++++++---
1 file changed, 30 insertions(+), 5 deletions(-)
diff --git a/drivers/net/wireless/realtek/rtw89/mac80211.c b/drivers/net/wireless/realtek/rtw89/mac80211.c
index 7c8ec4f3c77e9..fd818d4b35314 100644
--- a/drivers/net/wireless/realtek/rtw89/mac80211.c
+++ b/drivers/net/wireless/realtek/rtw89/mac80211.c
@@ -800,11 +800,36 @@ static int rtw89_ops_start_ap(struct ieee80211_hw *hw,
ether_addr_copy(rtwvif_link->bssid, link_conf->bssid);
rtw89_cam_bssid_changed(rtwdev, rtwvif_link);
- rtw89_mac_port_update(rtwdev, rtwvif_link);
- rtw89_chip_h2c_assoc_cmac_tbl(rtwdev, rtwvif_link, NULL);
- rtw89_fw_h2c_role_maintain(rtwdev, rtwvif_link, NULL, RTW89_ROLE_TYPE_CHANGE);
- rtw89_fw_h2c_join_info(rtwdev, rtwvif_link, NULL, true);
- rtw89_fw_h2c_cam(rtwdev, rtwvif_link, NULL, NULL, RTW89_ROLE_TYPE_CHANGE);
+ ret = rtw89_mac_port_update(rtwdev, rtwvif_link);
+ if (ret) {
+ rtw89_warn(rtwdev, "failed to update mac port\n");
+ return ret;
+ }
+
+ ret = rtw89_chip_h2c_assoc_cmac_tbl(rtwdev, rtwvif_link, NULL);
+ if (ret) {
+ rtw89_warn(rtwdev, "failed to send h2c cmac table\n");
+ return ret;
+ }
+
+ ret = rtw89_fw_h2c_role_maintain(rtwdev, rtwvif_link, NULL, RTW89_ROLE_TYPE_CHANGE);
+ if (ret) {
+ rtw89_warn(rtwdev, "failed to send h2c role info\n");
+ return ret;
+ }
+
+ ret = rtw89_fw_h2c_join_info(rtwdev, rtwvif_link, NULL, true);
+ if (ret) {
+ rtw89_warn(rtwdev, "failed to send h2c join info\n");
+ return ret;
+ }
+
+ ret = rtw89_fw_h2c_cam(rtwdev, rtwvif_link, NULL, NULL, RTW89_ROLE_TYPE_CHANGE);
+ if (ret) {
+ rtw89_warn(rtwdev, "failed to send h2c cam\n");
+ return ret;
+ }
+
rtw89_chip_rfk_channel(rtwdev, rtwvif_link);
if (RTW89_CHK_FW_FEATURE(NOTIFY_AP_INFO, &rtwdev->fw)) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0192/1518] wifi: rtw89: fix HE extended capability length check
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (190 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0191/1518] wifi: rtw89: check return values in rtw89_ops_start_ap() Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0193/1518] fanotify: initialize permission event watchdog state Greg Kroah-Hartman
` (806 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Ping-Ke Shih,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit 2aba608a86e9b099c9af2ea70b620552dee2b628 ]
rtw89_mac_check_he_obss_narrow_bw_ru_iter() reads extended capability
byte 10, but rejects only datalen values below 10. Byte 10 requires at
least 11 bytes.
Require datalen >= 11 before reading data[10].
Fixes: 8d540f9d2916 ("wifi: rtw89: disable 26-tone RU HE TB PPDU transmissions")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Acked-by: Ping-Ke Shih <pkshih@realtek.com>
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
Link: https://patch.msgid.link/2026063009025530.2-ccfa108-0024-wifi-rtw89-fix-HE-extended--pengpeng@iscas.ac.cn
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/realtek/rtw89/mac.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/realtek/rtw89/mac.c b/drivers/net/wireless/realtek/rtw89/mac.c
index 8194ae570ee94..f0773f7c3749a 100644
--- a/drivers/net/wireless/realtek/rtw89/mac.c
+++ b/drivers/net/wireless/realtek/rtw89/mac.c
@@ -4885,7 +4885,7 @@ static void rtw89_mac_check_he_obss_narrow_bw_ru_iter(struct wiphy *wiphy,
elem = cfg80211_find_elem(WLAN_EID_EXT_CAPABILITY, ies->data,
ies->len);
- if (!elem || elem->datalen < 10 ||
+ if (!elem || elem->datalen < 11 ||
!(elem->data[10] & WLAN_EXT_CAPA10_OBSS_NARROW_BW_RU_TOLERANCE_SUPPORT))
*tolerated = false;
rcu_read_unlock();
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0193/1518] fanotify: initialize permission event watchdog state
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (191 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0192/1518] wifi: rtw89: fix HE extended capability length check Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0194/1518] tools/nolibc: mark arg1 operand in __nolibc_syscall0() as write-only Greg Kroah-Hartman
` (805 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xuanqiang Luo, Jan Kara, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
[ Upstream commit a3aa899823dda059ab88a58254f9a605e03ec275 ]
fanotify permission events are allocated with kmem_cache_alloc(), but
fanotify_alloc_perm_event() does not initialize watchdog_cnt.
The watchdog reads watchdog_cnt after the event is moved to access_list.
A stale value can make it warn too early or skip the warning.
Initialize watchdog_cnt when allocating a permission event.
Fixes: b8cf8fda522d ("fanotify: add watchdog for permission events")
Signed-off-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Link: https://patch.msgid.link/20260703031345.9354-1-xuanqiang.luo@linux.dev
Signed-off-by: Jan Kara <jack@suse.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/notify/fanotify/fanotify.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/fs/notify/fanotify/fanotify.c b/fs/notify/fanotify/fanotify.c
index cf57eabfed456..cdb69c23e2e6c 100644
--- a/fs/notify/fanotify/fanotify.c
+++ b/fs/notify/fanotify/fanotify.c
@@ -601,6 +601,7 @@ static struct fanotify_event *fanotify_alloc_perm_event(const void *data,
pevent->hdr.pad = 0;
pevent->hdr.len = 0;
pevent->state = FAN_EVENT_INIT;
+ pevent->watchdog_cnt = 0;
pevent->path = *path;
pevent->pos = range ? range->pos : FANOTIFY_NO_RANGE;
pevent->count = range ? range->count : 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0194/1518] tools/nolibc: mark arg1 operand in __nolibc_syscall0() as write-only
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (192 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0193/1518] fanotify: initialize permission event watchdog state Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0195/1518] perf cs-etm: Fix thread leaks on trace queue init failure Greg Kroah-Hartman
` (804 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Thomas Weißschuh, Willy Tarreau,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Weißschuh <linux@weissschuh.net>
[ Upstream commit a3b2181459a2c74c03ddbad585f884eefc8ff8ff ]
__nolibc_syscall0() does not set the arg1 variable before passing it to
the asm block. This uninitialized variable read is undefined behavior.
Clang can miscompile this.
Mark the asm operand as write-only to fix this.
Fixes: 8e1930296f92 ("tools/nolibc: Add support for SPARC")
Signed-off-by: Thomas Weißschuh <linux@weissschuh.net>
Acked-by: Willy Tarreau <w@1wt.eu>
Link: https://patch.msgid.link/20260703-nolibc-sparc-asm-v1-1-c7fe73e2e777@weissschuh.net
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/include/nolibc/arch-sparc.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/include/nolibc/arch-sparc.h b/tools/include/nolibc/arch-sparc.h
index ca420d843e254..a9386a4808a75 100644
--- a/tools/include/nolibc/arch-sparc.h
+++ b/tools/include/nolibc/arch-sparc.h
@@ -45,7 +45,7 @@
\
__asm__ volatile ( \
_NOLIBC_SYSCALL \
- : "+r"(_arg1) \
+ : "=r"(_arg1) \
: "r"(_num) \
: "memory", "cc" \
); \
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0195/1518] perf cs-etm: Fix thread leaks on trace queue init failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (193 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0194/1518] tools/nolibc: mark arg1 operand in __nolibc_syscall0() as write-only Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0196/1518] perf/x86/amd/uncore: Add group validation Greg Kroah-Hartman
` (803 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, James Clark, Leo Yan, Namhyung Kim,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leo Yan <leo.yan@arm.com>
[ Upstream commit 50cd0d54f1f6dd9b3de7c0ad101bd41d06206ace ]
cs_etm__init_traceid_queue() allocates the frontend and decode threads,
if a later allocation fails, the error path does not drop thread
reference that was already acquired.
Release both thread pointers with thread__zput() on the error path, so
does not leak thread references or leave stale pointers behind.
Fixes: 951ccccdc715 ("perf cs-etm: Only track threads instead of PID and TIDs")
Reviewed-by: James Clark <james.clark@linaro.org>
Signed-off-by: Leo Yan <leo.yan@arm.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/cs-etm.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/tools/perf/util/cs-etm.c b/tools/perf/util/cs-etm.c
index 520670348311e..66dbead2c03bc 100644
--- a/tools/perf/util/cs-etm.c
+++ b/tools/perf/util/cs-etm.c
@@ -645,6 +645,8 @@ static int cs_etm__init_traceid_queue(struct cs_etm_queue *etmq,
queue->tid);
tidq->decode_thread = machine__findnew_thread(&etm->session->machines.host, -1,
queue->tid);
+ if (!tidq->frontend_thread || !tidq->decode_thread)
+ goto out;
tidq->packet = zalloc(sizeof(struct cs_etm_packet));
if (!tidq->packet)
@@ -679,6 +681,8 @@ static int cs_etm__init_traceid_queue(struct cs_etm_queue *etmq,
zfree(&tidq->prev_packet);
zfree(&tidq->packet);
out:
+ thread__zput(tidq->frontend_thread);
+ thread__zput(tidq->decode_thread);
return rc;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0196/1518] perf/x86/amd/uncore: Add group validation
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (194 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0195/1518] perf cs-etm: Fix thread leaks on trace queue init failure Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0197/1518] perf vendor events amd: Update Zen 5 core events Greg Kroah-Hartman
` (802 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sandipan Das, Peter Zijlstra (Intel),
Ingo Molnar, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sandipan Das <sandipan.das@amd.com>
[ Upstream commit edda9051e267b7390c7ce24b1b71434414ad156e ]
The amd_uncore driver currently does not validate event groups and
allows creation of groups with more events than the number of available
hardware counters. Because of this, pmu->event_init() succeeds but
counter assignment fails later in pmu->add() which returns -EBUSY once
all counters are exhausted.
Address this by introducing group validation in the pmu->event_init()
path. Since the uncore PMUs have no per-event constraints and all
counters of a PMU are interchangeable, validation is reduced to just
counting the group members that target a PMU and ensuring that they fit
within the available set of counters.
Fixes: c43ca5091a37 ("perf/x86/amd: Add support for AMD NB and L2I "uncore" counters")
Signed-off-by: Sandipan Das <sandipan.das@amd.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Link: https://patch.msgid.link/750877d66e208603c3047f13eed6399625d43969.1782884387.git.sandipan.das@amd.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/events/amd/uncore.c | 31 +++++++++++++++++++++++++++++++
1 file changed, 31 insertions(+)
diff --git a/arch/x86/events/amd/uncore.c b/arch/x86/events/amd/uncore.c
index 9a13a9f21d2f8..c960481222727 100644
--- a/arch/x86/events/amd/uncore.c
+++ b/arch/x86/events/amd/uncore.c
@@ -264,6 +264,29 @@ static void amd_uncore_del(struct perf_event *event, int flags)
hwc->idx = -1;
}
+static bool amd_uncore_group_valid(struct perf_event *event)
+{
+ struct amd_uncore_pmu *pmu = event_to_amd_uncore_pmu(event);
+ struct perf_event *leader = event->group_leader;
+ struct perf_event *sibling;
+ int counters = 0;
+
+ if (leader->pmu == event->pmu)
+ counters++;
+
+ for_each_sibling_event(sibling, leader) {
+ if (sibling->pmu == event->pmu &&
+ sibling->state > PERF_EVENT_STATE_OFF)
+ counters++;
+ }
+
+ /*
+ * When pmu->event_init() is called, the event is yet to be linked to
+ * its leader's sibling list, so it is counted separately
+ */
+ return (counters + 1) <= pmu->num_counters;
+}
+
static int amd_uncore_event_init(struct perf_event *event)
{
struct amd_uncore_pmu *pmu;
@@ -281,6 +304,14 @@ static int amd_uncore_event_init(struct perf_event *event)
if (!ctx)
return -ENODEV;
+ /*
+ * Ensure that all events in a group can be scheduled together so that
+ * a failure can be reported at perf_event_open() time rather than
+ * silently at pmu->add() time when no free counter is found
+ */
+ if (event->group_leader != event && !amd_uncore_group_valid(event))
+ return -EINVAL;
+
/*
* NB and Last level cache counters (MSRs) are shared across all cores
* that share the same NB / Last level cache. On family 16h and below,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0197/1518] perf vendor events amd: Update Zen 5 core events
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (195 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0196/1518] perf/x86/amd/uncore: Add group validation Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0198/1518] hwrng: core - fix rng list on registration error Greg Kroah-Hartman
` (801 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sandipan Das, Namhyung Kim,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sandipan Das <sandipan.das@amd.com>
[ Upstream commit 047979af3bf6a118066c81099162d518de63abb1 ]
Update definitions for the following events.
* PMCx00A - Add missing unit masks
* PMCx00B - Add missing unit masks and fix descriptions
* PMCx00C - Add missing unit masks
* PMCx00D - Add missing unit masks
* PMCx025 - Add missing unit masks and fix descriptions
Fixes: 45c072f2537a ("perf vendor events amd: Add Zen 5 core events")
Signed-off-by: Sandipan Das <sandipan.das@amd.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../arch/x86/amdzen5/floating-point.json | 130 +++++++++++++++---
.../arch/x86/amdzen5/load-store.json | 8 +-
2 files changed, 120 insertions(+), 18 deletions(-)
diff --git a/tools/perf/pmu-events/arch/x86/amdzen5/floating-point.json b/tools/perf/pmu-events/arch/x86/amdzen5/floating-point.json
index 9204bfb1d69e0..569975b53cc33 100644
--- a/tools/perf/pmu-events/arch/x86/amdzen5/floating-point.json
+++ b/tools/perf/pmu-events/arch/x86/amdzen5/floating-point.json
@@ -179,6 +179,30 @@
"BriefDescription": "Retired scalar floating-point blend ops.",
"UMask": "0x09"
},
+ {
+ "EventName": "fp_ops_retired_by_type.scalar_mov",
+ "EventCode": "0x0a",
+ "BriefDescription": "Retired scalar floating-point MOV ops.",
+ "UMask": "0x0a"
+ },
+ {
+ "EventName": "fp_ops_retired_by_type.scalar_shuffle",
+ "EventCode": "0x0a",
+ "BriefDescription": "Retired scalar floating-point shuffle ops (may include instructions not necessarily thought of as including shuffles e.g. horizontal add, dot product, and certain MOV instructions).",
+ "UMask": "0x0b"
+ },
+ {
+ "EventName": "fp_ops_retired_by_type.scalar_bfloat",
+ "EventCode": "0x0a",
+ "BriefDescription": "Retired scalar floating-point bfloat ops.",
+ "UMask": "0x0c"
+ },
+ {
+ "EventName": "fp_ops_retired_by_type.scalar_logical",
+ "EventCode": "0x0a",
+ "BriefDescription": "Retired scalar floating-point logical ops.",
+ "UMask": "0x0d"
+ },
{
"EventName": "fp_ops_retired_by_type.scalar_other",
"EventCode": "0x0a",
@@ -245,12 +269,24 @@
"BriefDescription": "Retired vector floating-point blend ops.",
"UMask": "0x90"
},
+ {
+ "EventName": "fp_ops_retired_by_type.vector_mov",
+ "EventCode": "0x0a",
+ "BriefDescription": "Retired vector floating-point MOV ops.",
+ "UMask": "0xa0"
+ },
{
"EventName": "fp_ops_retired_by_type.vector_shuffle",
"EventCode": "0x0a",
"BriefDescription": "Retired vector floating-point shuffle ops (may include instructions not necessarily thought of as including shuffles e.g. horizontal add, dot product, and certain MOV instructions).",
"UMask": "0xb0"
},
+ {
+ "EventName": "fp_ops_retired_by_type.vector_bfloat",
+ "EventCode": "0x0a",
+ "BriefDescription": "Retired vector floating-point bfloat ops.",
+ "UMask": "0xc0"
+ },
{
"EventName": "fp_ops_retired_by_type.vector_logical",
"EventCode": "0x0a",
@@ -278,7 +314,7 @@
{
"EventName": "sse_avx_ops_retired.mmx_add",
"EventCode": "0x0b",
- "BriefDescription": "Retired MMX integer add.",
+ "BriefDescription": "Retired MMX integer add ops.",
"UMask": "0x01"
},
{
@@ -299,16 +335,34 @@
"BriefDescription": "Retired MMX integer multiply-accumulate ops.",
"UMask": "0x04"
},
+ {
+ "EventName": "sse_avx_ops_retired.mmx_aes",
+ "EventCode": "0x0b",
+ "BriefDescription": "Retired MMX integer AES ops.",
+ "UMask": "0x05"
+ },
+ {
+ "EventName": "sse_avx_ops_retired.mmx_sha",
+ "EventCode": "0x0b",
+ "BriefDescription": "Retired MMX integer SHA ops.",
+ "UMask": "0x06"
+ },
{
"EventName": "sse_avx_ops_retired.mmx_cmp",
"EventCode": "0x0b",
"BriefDescription": "Retired MMX integer compare ops.",
"UMask": "0x07"
},
+ {
+ "EventName": "sse_avx_ops_retired.mmx_cvt",
+ "EventCode": "0x0b",
+ "BriefDescription": "Retired MMX integer convert or pack ops.",
+ "UMask": "0x08"
+ },
{
"EventName": "sse_avx_ops_retired.mmx_shift",
"EventCode": "0x0b",
- "BriefDescription": "Retired MMX integer shift ops.",
+ "BriefDescription": "Retired MMX integer shift or rotate ops.",
"UMask": "0x09"
},
{
@@ -324,9 +378,9 @@
"UMask": "0x0b"
},
{
- "EventName": "sse_avx_ops_retired.mmx_pack",
+ "EventName": "sse_avx_ops_retired.mmx_vnni",
"EventCode": "0x0b",
- "BriefDescription": "Retired MMX integer pack ops.",
+ "BriefDescription": "Retired MMX integer VNNI ops.",
"UMask": "0x0c"
},
{
@@ -390,15 +444,15 @@
"UMask": "0x70"
},
{
- "EventName": "sse_avx_ops_retired.sse_avx_clm",
+ "EventName": "sse_avx_ops_retired.sse_avx_cvt",
"EventCode": "0x0b",
- "BriefDescription": "Retired SSE and AVX integer CLM ops.",
+ "BriefDescription": "Retired SSE and AVX integer convert or pack ops.",
"UMask": "0x80"
},
{
"EventName": "sse_avx_ops_retired.sse_avx_shift",
"EventCode": "0x0b",
- "BriefDescription": "Retired SSE and AVX integer shift ops.",
+ "BriefDescription": "Retired SSE and AVX integer shift or rotate ops.",
"UMask": "0x90"
},
{
@@ -414,9 +468,9 @@
"UMask": "0xb0"
},
{
- "EventName": "sse_avx_ops_retired.sse_avx_pack",
+ "EventName": "sse_avx_ops_retired.sse_avx_vnni",
"EventCode": "0x0b",
- "BriefDescription": "Retired SSE and AVX integer pack ops.",
+ "BriefDescription": "Retired SSE and AVX integer VNNI ops.",
"UMask": "0xc0"
},
{
@@ -497,12 +551,24 @@
"BriefDescription": "Retired 128-bit packed floating-point blend ops.",
"UMask": "0x09"
},
+ {
+ "EventName": "fp_pack_ops_retired.fp128_mov",
+ "EventCode": "0x0c",
+ "BriefDescription": "Retired 128-bit packed floating-point MOV ops.",
+ "UMask": "0x0a"
+ },
{
"EventName": "fp_pack_ops_retired.fp128_shuffle",
"EventCode": "0x0c",
"BriefDescription": "Retired 128-bit packed floating-point shuffle ops (may include instructions not necessarily thought of as including shuffles e.g. horizontal add, dot product, and certain MOV instructions).",
"UMask": "0x0b"
},
+ {
+ "EventName": "fp_pack_ops_retired.fp128_bfloat",
+ "EventCode": "0x0c",
+ "BriefDescription": "Retired 128-bit packed floating-point bfloat ops.",
+ "UMask": "0x0c"
+ },
{
"EventName": "fp_pack_ops_retired.fp128_logical",
"EventCode": "0x0c",
@@ -575,12 +641,24 @@
"BriefDescription": "Retired 256-bit packed floating-point blend ops.",
"UMask": "0x90"
},
+ {
+ "EventName": "fp_pack_ops_retired.fp256_mov",
+ "EventCode": "0x0c",
+ "BriefDescription": "Retired 256-bit packed floating-point MOV ops.",
+ "UMask": "0xa0"
+ },
{
"EventName": "fp_pack_ops_retired.fp256_shuffle",
"EventCode": "0x0c",
"BriefDescription": "Retired 256-bit packed floating-point shuffle ops (may include instructions not necessarily thought of as including shuffles e.g. horizontal add, dot product, and certain MOV instructions).",
"UMask": "0xb0"
},
+ {
+ "EventName": "fp_pack_ops_retired.fp256_bfloat",
+ "EventCode": "0x0c",
+ "BriefDescription": "Retired 256-bit packed floating-point bfloat ops.",
+ "UMask": "0xc0"
+ },
{
"EventName": "fp_pack_ops_retired.fp256_logical",
"EventCode": "0x0c",
@@ -648,15 +726,15 @@
"UMask": "0x07"
},
{
- "EventName": "packed_int_op_type.int128_clm",
+ "EventName": "packed_int_op_type.int128_cvt",
"EventCode": "0x0d",
- "BriefDescription": "Retired 128-bit packed integer CLM ops.",
+ "BriefDescription": "Retired 128-bit packed integer convert or pack ops.",
"UMask": "0x08"
},
{
"EventName": "packed_int_op_type.int128_shift",
"EventCode": "0x0d",
- "BriefDescription": "Retired 128-bit packed integer shift ops.",
+ "BriefDescription": "Retired 128-bit packed integer shift or rotate ops.",
"UMask": "0x09"
},
{
@@ -672,9 +750,9 @@
"UMask": "0x0b"
},
{
- "EventName": "packed_int_op_type.int128_pack",
+ "EventName": "packed_int_op_type.int128_vnni",
"EventCode": "0x0d",
- "BriefDescription": "Retired 128-bit packed integer pack ops.",
+ "BriefDescription": "Retired 128-bit packed integer VNNI ops.",
"UMask": "0x0c"
},
{
@@ -719,16 +797,34 @@
"BriefDescription": "Retired 256-bit packed integer multiply-accumulate ops.",
"UMask": "0x40"
},
+ {
+ "EventName": "packed_int_op_type.int256_aes",
+ "EventCode": "0x0d",
+ "BriefDescription": "Retired 256-bit packed integer AES ops.",
+ "UMask": "0x50"
+ },
+ {
+ "EventName": "packed_int_op_type.int256_sha",
+ "EventCode": "0x0d",
+ "BriefDescription": "Retired 256-bit packed integer SHA ops.",
+ "UMask": "0x60"
+ },
{
"EventName": "packed_int_op_type.int256_cmp",
"EventCode": "0x0d",
"BriefDescription": "Retired 256-bit packed integer compare ops.",
"UMask": "0x70"
},
+ {
+ "EventName": "packed_int_op_type.int256_cvt",
+ "EventCode": "0x0d",
+ "BriefDescription": "Retired 256-bit packed integer convert or pack ops.",
+ "UMask": "0x80"
+ },
{
"EventName": "packed_int_op_type.int256_shift",
"EventCode": "0x0d",
- "BriefDescription": "Retired 256-bit packed integer shift ops.",
+ "BriefDescription": "Retired 256-bit packed integer shift or rotate ops.",
"UMask": "0x90"
},
{
@@ -744,9 +840,9 @@
"UMask": "0xb0"
},
{
- "EventName": "packed_int_op_type.int256_pack",
+ "EventName": "packed_int_op_type.int256_vnni",
"EventCode": "0x0d",
- "BriefDescription": "Retired 256-bit packed integer pack ops.",
+ "BriefDescription": "Retired 256-bit packed integer VNNI ops.",
"UMask": "0xc0"
},
{
diff --git a/tools/perf/pmu-events/arch/x86/amdzen5/load-store.json b/tools/perf/pmu-events/arch/x86/amdzen5/load-store.json
index 06bbaea159259..b1994539ece82 100644
--- a/tools/perf/pmu-events/arch/x86/amdzen5/load-store.json
+++ b/tools/perf/pmu-events/arch/x86/amdzen5/load-store.json
@@ -8,9 +8,15 @@
{
"EventName": "ls_locks.bus_lock",
"EventCode": "0x25",
- "BriefDescription": "Retired Lock instructions which caused a bus lock.",
+ "BriefDescription": "Retired lock instructions which caused a bus lock.",
"UMask": "0x01"
},
+ {
+ "EventName": "ls_locks.all",
+ "EventCode": "0x25",
+ "BriefDescription": "Retired lock instructions of all types.",
+ "UMask": "0x1f"
+ },
{
"EventName": "ls_ret_cl_flush",
"EventCode": "0x26",
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0198/1518] hwrng: core - fix rng list on registration error
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (196 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0197/1518] perf vendor events amd: Update Zen 5 core events Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0199/1518] crypto: qat - cancel work on re-enable SR-IOV timeout Greg Kroah-Hartman
` (800 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Manos Pitsidianakis, Herbert Xu,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manos Pitsidianakis <manos@pitsidianak.is>
[ Upstream commit 3a5834db2b1ce25649f330e78efe1ccde78967fd ]
hwrng_register(rng) does the following:
1. Checks if rng has name and read methods set
2. Checks if the name already exists
3. Adds rng to global rng_list
4. May try to set rng to current_rng
If step 4 fails, it returns an error. However, it does not remove the
rng from rng_list, causing a dangling reference which can result in
use-after-free if the caller frees rng, since registration failed.
Add a list_del_init() cleanup step.
Fixes: 2bbb6983887f ("hwrng: use rng source with best quality")
Signed-off-by: Manos Pitsidianakis <manos@pitsidianak.is>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/char/hw_random/core.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/char/hw_random/core.c b/drivers/char/hw_random/core.c
index 036de7294bbda..054ffbc9e4220 100644
--- a/drivers/char/hw_random/core.c
+++ b/drivers/char/hw_random/core.c
@@ -604,11 +604,13 @@ int hwrng_register(struct hwrng *rng)
*/
err = set_current_rng(rng);
if (err)
- goto out_unlock;
+ goto out_list_del;
}
}
mutex_unlock(&rng_mutex);
return 0;
+out_list_del:
+ list_del_init(&rng->list);
out_unlock:
mutex_unlock(&rng_mutex);
out:
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0199/1518] crypto: qat - cancel work on re-enable SR-IOV timeout
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (197 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0198/1518] hwrng: core - fix rng list on registration error Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0200/1518] crypto: qat - clear AES key schedule from stack Greg Kroah-Hartman
` (799 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Giovanni Cabiddu, Ahsan Atta,
Herbert Xu, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Giovanni Cabiddu <giovanni.cabiddu@intel.com>
[ Upstream commit 455b0f3ac9e254edab9f5a873d337abe5e6e3604 ]
The QAT reset worker queues SR-IOV reenable work using a work_struct and
completion embedded in an on-stack adf_sriov_dev_data. If the completion
wait times out, the reset worker can return while device_sriov_wq still
holds or executes the stack-backed work item.
Cancel the work on the device_sriov_wq on timeout before the stack frame
unwinds.
Fixes: 4469f9b23468 ("crypto: qat - re-enable sriov after pf reset")
Signed-off-by: Giovanni Cabiddu <giovanni.cabiddu@intel.com>
Reviewed-by: Ahsan Atta <ahsan.atta@intel.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/crypto/intel/qat/qat_common/adf_aer.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/crypto/intel/qat/qat_common/adf_aer.c b/drivers/crypto/intel/qat/qat_common/adf_aer.c
index f26cadc19d6bb..ea826333c45f4 100644
--- a/drivers/crypto/intel/qat/qat_common/adf_aer.c
+++ b/drivers/crypto/intel/qat/qat_common/adf_aer.c
@@ -190,6 +190,8 @@ static void adf_device_reset_worker(struct work_struct *work)
queue_work(device_sriov_wq, &sriov_data.sriov_work);
if (wait_for_completion_timeout(&sriov_data.compl, wait_jiffies))
adf_pf2vf_notify_restarted(accel_dev);
+ else
+ cancel_work_sync(&sriov_data.sriov_work);
adf_dev_restarted_notify(accel_dev);
clear_bit(ADF_STATUS_RESTARTING, &accel_dev->status);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0200/1518] crypto: qat - clear AES key schedule from stack
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (198 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0199/1518] crypto: qat - cancel work on re-enable SR-IOV timeout Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0201/1518] crypto: atmel-ecc - reject hardware ECDH without a public key Greg Kroah-Hartman
` (798 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Giovanni Cabiddu, Ahsan Atta,
Herbert Xu, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Giovanni Cabiddu <giovanni.cabiddu@intel.com>
[ Upstream commit d41a9fcfb7f9ee36e4a4aaf5e7996bca6be1e7a9 ]
qat_alg_xts_reverse_key() expands the forward XTS AES key on the stack.
That schedule contains key material and can remain in the stack frame.
Clear the temporary crypto_aes_ctx with memzero_explicit() after the copy.
Fixes: 5106dfeaeabe ("crypto: qat - add AES-XTS support for QAT GEN4 devices")
Signed-off-by: Giovanni Cabiddu <giovanni.cabiddu@intel.com>
Reviewed-by: Ahsan Atta <ahsan.atta@intel.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/crypto/intel/qat/qat_common/qat_algs.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/crypto/intel/qat/qat_common/qat_algs.c b/drivers/crypto/intel/qat/qat_common/qat_algs.c
index 7f638a62e3ade..91663805d9e60 100644
--- a/drivers/crypto/intel/qat/qat_common/qat_algs.c
+++ b/drivers/crypto/intel/qat/qat_common/qat_algs.c
@@ -405,6 +405,7 @@ static void qat_alg_xts_reverse_key(const u8 *key_forward, unsigned int keylen,
memcpy(key_reverse + AES_BLOCK_SIZE, key - AES_BLOCK_SIZE,
AES_BLOCK_SIZE);
}
+ memzero_explicit(&aes_expanded, sizeof(aes_expanded));
}
static void qat_alg_skcipher_init_dec(struct qat_alg_skcipher_ctx *ctx,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0201/1518] crypto: atmel-ecc - reject hardware ECDH without a public key
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (199 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0200/1518] crypto: qat - clear AES key schedule from stack Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0202/1518] crypto: atmel-sha204a - fix heap info leak on I2C transfer failure Greg Kroah-Hartman
` (797 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Thorsten Blum, Herbert Xu,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thorsten Blum <thorsten.blum@linux.dev>
[ Upstream commit f240f9b588f4e2de89822adebf560a96b5d263ed ]
The hardware ECDH path in atmel_ecdh_compute_shared_secret() uses the
private key stored in the device. However, the public key is cached only
after atmel_ecdh_set_secret() successfully generated that private key
for the current tfm.
atmel_ecdh_generate_public_key() already rejects requests when no public
key is cached. Add the same check to atmel_ecdh_compute_shared_secret()
to prevent the device from using a private key that was not generated
for the current tfm.
Fixes: 11105693fa05 ("crypto: atmel-ecc - introduce Microchip / Atmel ECC driver")
Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/crypto/atmel-ecc.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/crypto/atmel-ecc.c b/drivers/crypto/atmel-ecc.c
index 91edb42aba4af..93e3513541c7d 100644
--- a/drivers/crypto/atmel-ecc.c
+++ b/drivers/crypto/atmel-ecc.c
@@ -165,6 +165,9 @@ static int atmel_ecdh_compute_shared_secret(struct kpp_request *req)
return crypto_kpp_compute_shared_secret(req);
}
+ if (!ctx->public_key)
+ return -EINVAL;
+
/* A P-256 public key must contain two 32-byte coordinates */
if (req->src_len != ATMEL_ECC_PUBKEY_SIZE)
return -EINVAL;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0202/1518] crypto: atmel-sha204a - fix heap info leak on I2C transfer failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (200 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0201/1518] crypto: atmel-ecc - reject hardware ECDH without a public key Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0203/1518] crypto: sa2ul - stop probe if context pool creation fails Greg Kroah-Hartman
` (796 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lothar Rubusch, Thorsten Blum,
Herbert Xu, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lothar Rubusch <l.rubusch@gmail.com>
[ Upstream commit 72bbf11ba14bd7d5fbf31a1ec42fff608b657f74 ]
The nonblocking RNG path allocates a work_data structure to track the
state of an in-flight asynchronous I2C request. This pointer is stored
in rng->priv and later consumed by the read path once the transaction
completes.
If the underlying I2C transfer fails, the completion callback is invoked
with a non-zero status. In this case, the allocated work_data is not
usable for producing RNG output and must not remain associated with the
hwrng state.
Previously, the failure path only logged a warning but left the pointer
state uncleared, which can result in subsequent read attempts observing
stale state and interpreting it as valid completion data.
Fix this by freeing the pending work_data. The I2C transaction reports
an error. This ensures that failed requests do not leave residual state
behind that could be interpreted as valid RNG data on later reads.
Clearing rng->priv is done at the subsequent call to nonblocking read.
Fixes: da001fb651b0 ("crypto: atmel-i2c - add support for SHA204A random number generator")
Signed-off-by: Lothar Rubusch <l.rubusch@gmail.com>
Assisted-by: Gemini:1.5 Pro [google]
Reviewed-by: Thorsten Blum <thorsten.blum@linux.dev>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/crypto/atmel-sha204a.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/drivers/crypto/atmel-sha204a.c b/drivers/crypto/atmel-sha204a.c
index 8a3520c9a0ff5..d2031abbd8efa 100644
--- a/drivers/crypto/atmel-sha204a.c
+++ b/drivers/crypto/atmel-sha204a.c
@@ -31,10 +31,14 @@ static void atmel_sha204a_rng_done(struct atmel_i2c_work_data *work_data,
struct atmel_i2c_client_priv *i2c_priv = work_data->ctx;
struct hwrng *rng = areq;
- if (status)
+ if (status) {
dev_warn_ratelimited(&i2c_priv->client->dev,
"i2c transaction failed (%d)\n",
status);
+ kfree(work_data);
+ atomic_dec(&i2c_priv->tfm_count);
+ return;
+ }
rng->priv = (unsigned long)work_data;
atomic_dec(&i2c_priv->tfm_count);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0203/1518] crypto: sa2ul - stop probe if context pool creation fails
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (201 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0202/1518] crypto: atmel-sha204a - fix heap info leak on I2C transfer failure Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0204/1518] hwrng: xilinx-trng - propagate timeout before any data is read Greg Kroah-Hartman
` (795 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Herbert Xu,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit d03f980a25853f6a380895119a572a3bb1194e8d ]
sa_ul_probe() calls sa_init_mem() to create the DMA pool used for
security context buffers, but ignores its return value. If pool creation
fails, probe still continues with DMA setup, algorithm registration and
child population even though later request setup depends on that pool.
Stop probing when sa_init_mem() fails, and route that failure to the PM
cleanup path without attempting to destroy an uncreated DMA pool.
Fixes: 7694b6ca649f ("crypto: sa2ul - Add crypto driver")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/crypto/sa2ul.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/drivers/crypto/sa2ul.c b/drivers/crypto/sa2ul.c
index 52fe4baeff934..73034aeb63862 100644
--- a/drivers/crypto/sa2ul.c
+++ b/drivers/crypto/sa2ul.c
@@ -2395,7 +2395,10 @@ static int sa_ul_probe(struct platform_device *pdev)
return ret;
}
- sa_init_mem(dev_data);
+ ret = sa_init_mem(dev_data);
+ if (ret)
+ goto disable_pm;
+
ret = sa_dma_init(dev_data);
if (ret)
goto destroy_dma_pool;
@@ -2430,6 +2433,7 @@ static int sa_ul_probe(struct platform_device *pdev)
destroy_dma_pool:
dma_pool_destroy(dev_data->sc_pool);
+disable_pm:
pm_runtime_put_sync(dev);
pm_runtime_disable(dev);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0204/1518] hwrng: xilinx-trng - propagate timeout before any data is read
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (202 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0203/1518] crypto: sa2ul - stop probe if context pool creation fails Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0205/1518] crypto: rk3288 - fail ahash requests on HASH idle timeout Greg Kroah-Hartman
` (794 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Herbert Xu,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit ba088974419326daf46c5dc03e2cf6ab6ab701f7 ]
xtrng_readblock32() polls for 16-byte chunks but returns the number of
bytes read even when the first poll times out. Its caller then treats a
zero return as a short successful read, and partial reads for full
32-byte blocks can make the tail copy use a fixed block offset rather
than the amount already produced.
Return the poll error when no data has been read, preserve partial
positive returns after some data is available, stop the generator on all
collection exits, and append tail bytes at the current output count.
Fixes: 8979744aca80 ("crypto: xilinx - Add TRNG driver for Versal")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/crypto/xilinx/xilinx-trng.c | 32 +++++++++++++++++++++--------
1 file changed, 24 insertions(+), 8 deletions(-)
diff --git a/drivers/crypto/xilinx/xilinx-trng.c b/drivers/crypto/xilinx/xilinx-trng.c
index 3b193471cc94c..7f9762ea042bb 100644
--- a/drivers/crypto/xilinx/xilinx-trng.c
+++ b/drivers/crypto/xilinx/xilinx-trng.c
@@ -91,8 +91,8 @@ static void xtrng_softreset(struct xilinx_rng *rng)
xtrng_readwrite32(rng->rng_base + TRNG_CTRL_OFFSET, TRNG_CTRL_PRNGSRST_MASK, 0);
}
-/* Return no. of bytes read */
-static size_t xtrng_readblock32(void __iomem *rng_base, __be32 *buf, int blocks32, bool wait)
+/* Return no. of bytes read or a negative error before any data is read. */
+static int xtrng_readblock32(void __iomem *rng_base, __be32 *buf, int blocks32, bool wait)
{
int read = 0, ret;
int timeout = 1;
@@ -107,8 +107,11 @@ static size_t xtrng_readblock32(void __iomem *rng_base, __be32 *buf, int blocks3
ret = readl_poll_timeout(rng_base + TRNG_STATUS_OFFSET, val,
(val & TRNG_STATUS_QCNT_MASK) ==
TRNG_STATUS_QCNT_16_BYTES, !!wait, timeout);
- if (ret)
+ if (ret) {
+ if (!read)
+ return ret;
break;
+ }
for (idx = 0; idx < TRNG_READ_4_WORD; idx++) {
*(buf + read) = cpu_to_be32(ioread32(rng_base + TRNG_CORE_OUTPUT_OFFSET));
@@ -123,27 +126,40 @@ static int xtrng_collect_random_data(struct xilinx_rng *rng, u8 *rand_gen_buf,
{
u8 randbuf[TRNG_SEC_STRENGTH_BYTES];
int byteleft, blocks, count = 0;
+ int full_blocks_bytes;
int ret;
byteleft = no_of_random_bytes & (TRNG_SEC_STRENGTH_BYTES - 1);
blocks = no_of_random_bytes >> TRNG_SEC_STRENGTH_SHIFT;
+ full_blocks_bytes = blocks * TRNG_SEC_STRENGTH_BYTES;
xtrng_readwrite32(rng->rng_base + TRNG_CTRL_OFFSET, TRNG_CTRL_PRNGSTART_MASK,
TRNG_CTRL_PRNGSTART_MASK);
if (blocks) {
ret = xtrng_readblock32(rng->rng_base, (__be32 *)rand_gen_buf, blocks, wait);
- if (!ret)
- return 0;
+ if (ret <= 0) {
+ count = ret;
+ goto out_stop;
+ }
count += ret;
+ if (ret < full_blocks_bytes)
+ goto out_stop;
}
if (byteleft) {
ret = xtrng_readblock32(rng->rng_base, (__be32 *)randbuf, 1, wait);
+ if (ret < 0) {
+ if (!count)
+ count = ret;
+ goto out_stop;
+ }
if (!ret)
- return count;
- memcpy(rand_gen_buf + (blocks * TRNG_SEC_STRENGTH_BYTES), randbuf, byteleft);
- count += byteleft;
+ goto out_stop;
+ ret = min(ret, no_of_random_bytes - count);
+ memcpy(rand_gen_buf + count, randbuf, ret);
+ count += ret;
}
+out_stop:
xtrng_readwrite32(rng->rng_base + TRNG_CTRL_OFFSET,
TRNG_CTRL_PRNGMODE_MASK | TRNG_CTRL_PRNGSTART_MASK, 0U);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0205/1518] crypto: rk3288 - fail ahash requests on HASH idle timeout
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (203 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0204/1518] hwrng: xilinx-trng - propagate timeout before any data is read Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0206/1518] crypto: keembay - Fix AEAD unregister count in error path Greg Kroah-Hartman
` (793 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Herbert Xu,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit ae150db7826f21e8d19e54fb6243169628809c4d ]
rk_hash_run() waits for RK_CRYPTO_HASH_STS to become idle after the
final DMA transfer, but ignores the poll result. If the hash engine
never becomes idle, the driver still reads the digest registers and
finalizes the request with the previous success value.
Store the poll result and finalize the request with the timeout error
before reading the digest registers.
Fixes: 37bc22159c45 ("crypto: rockchip - use read_poll_timeout")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/crypto/rockchip/rk3288_crypto_ahash.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/drivers/crypto/rockchip/rk3288_crypto_ahash.c b/drivers/crypto/rockchip/rk3288_crypto_ahash.c
index b9f5a8b42e661..d3482619aa2f1 100644
--- a/drivers/crypto/rockchip/rk3288_crypto_ahash.c
+++ b/drivers/crypto/rockchip/rk3288_crypto_ahash.c
@@ -324,7 +324,12 @@ static int rk_hash_run(struct crypto_engine *engine, void *breq)
* efficiency, and make it response quickly when dma
* complete.
*/
- readl_poll_timeout(rkc->reg + RK_CRYPTO_HASH_STS, v, v == 0, 10, 1000);
+ err = readl_poll_timeout(rkc->reg + RK_CRYPTO_HASH_STS, v,
+ v == 0, 10, 1000);
+ if (err) {
+ dev_err(rkc->dev, "HASH idle timeout\n");
+ goto theend;
+ }
for (i = 0; i < crypto_ahash_digestsize(tfm) / 4; i++) {
v = readl(rkc->reg + RK_CRYPTO_HASH_DOUT_0 + i * 4);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0206/1518] crypto: keembay - Fix AEAD unregister count in error path
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (204 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0205/1518] crypto: rk3288 - fail ahash requests on HASH idle timeout Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0207/1518] RDMA/irdma: Deduplicate the irdma_del_memlist logic Greg Kroah-Hartman
` (792 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ijae Kim, Myeonghun Pak, Herbert Xu,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Myeonghun Pak <mhun512@gmail.com>
[ Upstream commit e264401ce4776a288524e5b87593d4d864147115 ]
register_aes_algs() registers the AEAD algorithms before registering the
skcipher algorithms. If skcipher registration fails, the function unwinds
the earlier AEAD registration with crypto_engine_unregister_aeads(), but it
passes ARRAY_SIZE(algs), which is the skcipher table size.
Use ARRAY_SIZE(algs_aead) for the AEAD unwind path so the unregister helper
iterates over the same table that was registered. Also clarify the nearby
comment: the crypto registration helpers clean up algorithms registered
within the same call, while this function must still unwind earlier
successful registration steps.
Fixes: 885743324513 ("crypto: keembay - Add support for Keem Bay OCS AES/SM4")
Co-developed-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/crypto/intel/keembay/keembay-ocs-aes-core.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/crypto/intel/keembay/keembay-ocs-aes-core.c b/drivers/crypto/intel/keembay/keembay-ocs-aes-core.c
index 8a8f6c81e010c..0e424024224e5 100644
--- a/drivers/crypto/intel/keembay/keembay-ocs-aes-core.c
+++ b/drivers/crypto/intel/keembay/keembay-ocs-aes-core.c
@@ -1541,7 +1541,7 @@ static int register_aes_algs(struct ocs_aes_dev *aes_dev)
/*
* If any algorithm fails to register, all preceding algorithms that
- * were successfully registered will be automatically unregistered.
+ * were registered in the same call are automatically unregistered.
*/
ret = crypto_engine_register_aeads(algs_aead, ARRAY_SIZE(algs_aead));
if (ret)
@@ -1549,7 +1549,7 @@ static int register_aes_algs(struct ocs_aes_dev *aes_dev)
ret = crypto_engine_register_skciphers(algs, ARRAY_SIZE(algs));
if (ret)
- crypto_engine_unregister_aeads(algs_aead, ARRAY_SIZE(algs));
+ crypto_engine_unregister_aeads(algs_aead, ARRAY_SIZE(algs_aead));
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0207/1518] RDMA/irdma: Deduplicate the irdma_del_memlist logic
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (205 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0206/1518] crypto: keembay - Fix AEAD unregister count in error path Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0208/1518] RDMA/irdma: Add a refcount to track user ring MR associations Greg Kroah-Hartman
` (791 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jacob Moroni, Leon Romanovsky,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jacob Moroni <jmoroni@google.com>
[ Upstream commit 097f50384e1877b7cf3ace12ff0d1beed19f2088 ]
Simplify/dedup the irdma_del_memlist logic in preparation for
the QP/CQ/SRQ ring MR refcounting change that will follow in
a subsequent commit.
Signed-off-by: Jacob Moroni <jmoroni@google.com>
Link: https://patch.msgid.link/20260618201458.875740-2-jmoroni@google.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Stable-dep-of: f67d8a08f60c ("RDMA/irdma: Add refcounting to user ring MRs")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/irdma/verbs.c | 31 +++++++++++------------------
1 file changed, 12 insertions(+), 19 deletions(-)
diff --git a/drivers/infiniband/hw/irdma/verbs.c b/drivers/infiniband/hw/irdma/verbs.c
index 4084168d0194f..9f3884f31555c 100644
--- a/drivers/infiniband/hw/irdma/verbs.c
+++ b/drivers/infiniband/hw/irdma/verbs.c
@@ -3868,35 +3868,28 @@ static void irdma_del_memlist(struct irdma_mr *iwmr,
{
struct irdma_pbl *iwpbl = &iwmr->iwpbl;
unsigned long flags;
+ spinlock_t *lock;
switch (iwmr->type) {
case IRDMA_MEMREG_TYPE_CQ:
- spin_lock_irqsave(&ucontext->cq_reg_mem_list_lock, flags);
- if (iwpbl->on_list) {
- iwpbl->on_list = false;
- list_del(&iwpbl->list);
- }
- spin_unlock_irqrestore(&ucontext->cq_reg_mem_list_lock, flags);
+ lock = &ucontext->cq_reg_mem_list_lock;
break;
case IRDMA_MEMREG_TYPE_QP:
- spin_lock_irqsave(&ucontext->qp_reg_mem_list_lock, flags);
- if (iwpbl->on_list) {
- iwpbl->on_list = false;
- list_del(&iwpbl->list);
- }
- spin_unlock_irqrestore(&ucontext->qp_reg_mem_list_lock, flags);
+ lock = &ucontext->qp_reg_mem_list_lock;
break;
case IRDMA_MEMREG_TYPE_SRQ:
- spin_lock_irqsave(&ucontext->srq_reg_mem_list_lock, flags);
- if (iwpbl->on_list) {
- iwpbl->on_list = false;
- list_del(&iwpbl->list);
- }
- spin_unlock_irqrestore(&ucontext->srq_reg_mem_list_lock, flags);
+ lock = &ucontext->srq_reg_mem_list_lock;
break;
default:
- break;
+ return;
+ }
+
+ spin_lock_irqsave(lock, flags);
+ if (iwpbl->on_list) {
+ iwpbl->on_list = false;
+ list_del(&iwpbl->list);
}
+ spin_unlock_irqrestore(lock, flags);
}
/**
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0208/1518] RDMA/irdma: Add a refcount to track user ring MR associations
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (206 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0207/1518] RDMA/irdma: Deduplicate the irdma_del_memlist logic Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0209/1518] RDMA/irdma: Add irdma_cq fields to track pbl allocations Greg Kroah-Hartman
` (790 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jacob Moroni, Leon Romanovsky,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jacob Moroni <jmoroni@google.com>
[ Upstream commit a7d0a6b58256a77566e9088a99e1594bf35821ec ]
User QP/CQ/SRQ rings are registered with the normal reg_mr
mechanism prior to creating the actual QP/CQ/SRQ object. In
order to prevent userspace from deregistering these special MRs
while the child object still exists, a refcount will be used.
This commit adds the refcount and logic to reject a dereg_mr
with active references. Subsequent commits will add logic to
bump this refcount when the user QP/CQ/SRQ objects are created.
Signed-off-by: Jacob Moroni <jmoroni@google.com>
Link: https://patch.msgid.link/20260618201458.875740-3-jmoroni@google.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Stable-dep-of: f67d8a08f60c ("RDMA/irdma: Add refcounting to user ring MRs")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/irdma/verbs.c | 21 +++++++++++++++++----
drivers/infiniband/hw/irdma/verbs.h | 1 +
2 files changed, 18 insertions(+), 4 deletions(-)
diff --git a/drivers/infiniband/hw/irdma/verbs.c b/drivers/infiniband/hw/irdma/verbs.c
index 9f3884f31555c..0bdb0481a7e12 100644
--- a/drivers/infiniband/hw/irdma/verbs.c
+++ b/drivers/infiniband/hw/irdma/verbs.c
@@ -3363,6 +3363,7 @@ static struct irdma_mr *irdma_alloc_iwmr(struct ib_umem *region,
if (!iwmr)
return ERR_PTR(-ENOMEM);
+ refcount_set(&iwmr->user_ring_refs, 1);
iwpbl = &iwmr->iwpbl;
iwpbl->iwmr = iwmr;
iwmr->region = region;
@@ -3862,13 +3863,16 @@ static struct ib_mr *irdma_get_dma_mr(struct ib_pd *pd, int acc)
* irdma_del_memlist - Deleting pbl list entries for CQ/QP
* @iwmr: iwmr for IB's user page addresses
* @ucontext: ptr to user context
+ *
+ * Return: True if the MR is currently in-use by a QP/CQ/SRQ ring.
*/
-static void irdma_del_memlist(struct irdma_mr *iwmr,
+static bool irdma_del_memlist(struct irdma_mr *iwmr,
struct irdma_ucontext *ucontext)
{
struct irdma_pbl *iwpbl = &iwmr->iwpbl;
unsigned long flags;
spinlock_t *lock;
+ bool in_use = false;
switch (iwmr->type) {
case IRDMA_MEMREG_TYPE_CQ:
@@ -3881,15 +3885,19 @@ static void irdma_del_memlist(struct irdma_mr *iwmr,
lock = &ucontext->srq_reg_mem_list_lock;
break;
default:
- return;
+ return false;
}
spin_lock_irqsave(lock, flags);
- if (iwpbl->on_list) {
+ if (!refcount_dec_if_one(&iwmr->user_ring_refs)) {
+ in_use = true;
+ } else if (iwpbl->on_list) {
iwpbl->on_list = false;
list_del(&iwpbl->list);
}
spin_unlock_irqrestore(lock, flags);
+
+ return in_use;
}
/**
@@ -3911,7 +3919,12 @@ static int irdma_dereg_mr(struct ib_mr *ib_mr, struct ib_udata *udata)
ucontext = rdma_udata_to_drv_context(udata,
struct irdma_ucontext,
ibucontext);
- irdma_del_memlist(iwmr, ucontext);
+
+ /* Do not allow the MR to be unpinned if it is still
+ * backing a user ring.
+ */
+ if (irdma_del_memlist(iwmr, ucontext))
+ return -EBUSY;
}
goto done;
}
diff --git a/drivers/infiniband/hw/irdma/verbs.h b/drivers/infiniband/hw/irdma/verbs.h
index 289ebc9b23ca7..fbd487dbebfb9 100644
--- a/drivers/infiniband/hw/irdma/verbs.h
+++ b/drivers/infiniband/hw/irdma/verbs.h
@@ -120,6 +120,7 @@ struct irdma_mr {
u64 len;
u64 pgaddrmem[IRDMA_MAX_SAVED_PHY_PGADDR];
struct irdma_pbl iwpbl;
+ refcount_t user_ring_refs;
};
struct irdma_srq {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0209/1518] RDMA/irdma: Add irdma_cq fields to track pbl allocations
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (207 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0208/1518] RDMA/irdma: Add a refcount to track user ring MR associations Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0210/1518] RDMA/irdma: Add refcounting to user ring MRs Greg Kroah-Hartman
` (789 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jacob Moroni, Leon Romanovsky,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jacob Moroni <jmoroni@google.com>
[ Upstream commit 971e99623ed7a0d75a719021cf4fd64e5f9e44e5 ]
These fields will be used in a subsequent commit which adds
refcounting to user CQ MRs.
Signed-off-by: Jacob Moroni <jmoroni@google.com>
Link: https://patch.msgid.link/20260618201458.875740-4-jmoroni@google.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Stable-dep-of: f67d8a08f60c ("RDMA/irdma: Add refcounting to user ring MRs")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/irdma/verbs.c | 25 +++++++++++++++----------
drivers/infiniband/hw/irdma/verbs.h | 2 ++
2 files changed, 17 insertions(+), 10 deletions(-)
diff --git a/drivers/infiniband/hw/irdma/verbs.c b/drivers/infiniband/hw/irdma/verbs.c
index 0bdb0481a7e12..b06e99c8c7b23 100644
--- a/drivers/infiniband/hw/irdma/verbs.c
+++ b/drivers/infiniband/hw/irdma/verbs.c
@@ -2130,6 +2130,11 @@ static int irdma_resize_cq(struct ib_cq *ibcq, int entries,
goto error;
spin_lock_irqsave(&iwcq->lock, flags);
+ if (udata)
+ /* Only update if the resize was successful. Otherwise, HW is
+ * still pointing to the old PBL.
+ */
+ iwcq->iwpbl = iwpbl_buf;
if (cq_buf) {
cq_buf->kmem_buf = iwcq->kmem;
cq_buf->hw = dev->hw;
@@ -2500,6 +2505,8 @@ static int irdma_create_cq(struct ib_cq *ibcq,
INIT_LIST_HEAD(&iwcq->resize_list);
INIT_LIST_HEAD(&iwcq->cmpl_generated);
iwcq->cq_num = cq_num;
+ iwcq->iwpbl = NULL;
+ iwcq->iwpbl_shadow = NULL;
info.dev = dev;
ukinfo->cq_size = max(entries, 4);
ukinfo->cq_id = cq_num;
@@ -2518,8 +2525,6 @@ static int irdma_create_cq(struct ib_cq *ibcq,
struct irdma_ucontext *ucontext;
struct irdma_create_cq_req req = {};
struct irdma_cq_mr *cqmr;
- struct irdma_pbl *iwpbl;
- struct irdma_pbl *iwpbl_shadow;
struct irdma_cq_mr *cqmr_shadow;
iwcq->user_mode = true;
@@ -2533,34 +2538,34 @@ static int irdma_create_cq(struct ib_cq *ibcq,
}
spin_lock_irqsave(&ucontext->cq_reg_mem_list_lock, flags);
- iwpbl = irdma_get_pbl((unsigned long)req.user_cq_buf,
- &ucontext->cq_reg_mem_list);
+ iwcq->iwpbl = irdma_get_pbl((unsigned long)req.user_cq_buf,
+ &ucontext->cq_reg_mem_list);
spin_unlock_irqrestore(&ucontext->cq_reg_mem_list_lock, flags);
- if (!iwpbl) {
+ if (!iwcq->iwpbl) {
err_code = -EPROTO;
goto cq_free_rsrc;
}
- cqmr = &iwpbl->cq_mr;
+ cqmr = &iwcq->iwpbl->cq_mr;
if (rf->sc_dev.hw_attrs.uk_attrs.feature_flags &
IRDMA_FEATURE_CQ_RESIZE) {
spin_lock_irqsave(&ucontext->cq_reg_mem_list_lock, flags);
- iwpbl_shadow = irdma_get_pbl(
+ iwcq->iwpbl_shadow = irdma_get_pbl(
(unsigned long)req.user_shadow_area,
&ucontext->cq_reg_mem_list);
spin_unlock_irqrestore(&ucontext->cq_reg_mem_list_lock, flags);
- if (!iwpbl_shadow) {
+ if (!iwcq->iwpbl_shadow) {
err_code = -EPROTO;
goto cq_free_rsrc;
}
- cqmr_shadow = &iwpbl_shadow->cq_mr;
+ cqmr_shadow = &iwcq->iwpbl_shadow->cq_mr;
info.shadow_area_pa = cqmr_shadow->cq_pbl.addr;
} else {
info.shadow_area_pa = cqmr->shadow;
}
- if (iwpbl->pbl_allocated) {
+ if (iwcq->iwpbl->pbl_allocated) {
info.virtual_map = true;
info.pbl_chunk_size = 1;
info.first_pm_pbl_idx = cqmr->cq_pbl.idx;
diff --git a/drivers/infiniband/hw/irdma/verbs.h b/drivers/infiniband/hw/irdma/verbs.h
index fbd487dbebfb9..a1651641eb714 100644
--- a/drivers/infiniband/hw/irdma/verbs.h
+++ b/drivers/infiniband/hw/irdma/verbs.h
@@ -153,6 +153,8 @@ struct irdma_cq {
struct list_head resize_list;
struct irdma_cq_poll_info cur_cqe;
struct list_head cmpl_generated;
+ struct irdma_pbl *iwpbl;
+ struct irdma_pbl *iwpbl_shadow;
};
struct irdma_cmpl_gen {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0210/1518] RDMA/irdma: Add refcounting to user ring MRs
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (208 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0209/1518] RDMA/irdma: Add irdma_cq fields to track pbl allocations Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0211/1518] arm64: dts: qcom: sm8750: wire UFS to ice instance Greg Kroah-Hartman
` (788 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jacob Moroni, Leon Romanovsky,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jacob Moroni <jmoroni@google.com>
[ Upstream commit f67d8a08f60c9217df6d40da56422d2049f5e334 ]
Prevent userspace from deregistering the MRs that back QP/CQ/SRQ rings
by bumping the MR's refcount upon association.
Fixes: b48c24c2d710 ("RDMA/irdma: Implement device supported verb APIs")
Signed-off-by: Jacob Moroni <jmoroni@google.com>
Link: https://patch.msgid.link/20260618201458.875740-5-jmoroni@google.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/irdma/utils.c | 6 ++++
drivers/infiniband/hw/irdma/verbs.c | 45 +++++++++++++++++++++++++++--
2 files changed, 49 insertions(+), 2 deletions(-)
diff --git a/drivers/infiniband/hw/irdma/utils.c b/drivers/infiniband/hw/irdma/utils.c
index e5e226b346211..835c11d6cc85c 100644
--- a/drivers/infiniband/hw/irdma/utils.c
+++ b/drivers/infiniband/hw/irdma/utils.c
@@ -1169,6 +1169,12 @@ void irdma_free_qp_rsrc(struct irdma_qp *iwqp)
iwqp->kqp.dma_mem.va = NULL;
kfree(iwqp->kqp.sq_wrid_mem);
kfree(iwqp->kqp.rq_wrid_mem);
+
+ if (iwqp->user_mode && iwqp->iwpbl) {
+ struct irdma_mr *iwmr = iwqp->iwpbl->iwmr;
+
+ refcount_dec(&iwmr->user_ring_refs);
+ }
}
/**
diff --git a/drivers/infiniband/hw/irdma/verbs.c b/drivers/infiniband/hw/irdma/verbs.c
index b06e99c8c7b23..9ada0bc00bd07 100644
--- a/drivers/infiniband/hw/irdma/verbs.c
+++ b/drivers/infiniband/hw/irdma/verbs.c
@@ -462,6 +462,9 @@ static struct irdma_pbl *irdma_get_pbl(unsigned long va,
list_for_each_entry (iwpbl, pbl_list, list) {
if (iwpbl->user_base == va) {
+ struct irdma_mr *iwmr = iwpbl->iwmr;
+
+ refcount_inc(&iwmr->user_ring_refs);
list_del(&iwpbl->list);
iwpbl->on_list = false;
return iwpbl;
@@ -1887,6 +1890,11 @@ static void irdma_srq_free_rsrc(struct irdma_pci_f *rf, struct irdma_srq *iwsrq)
dma_free_coherent(rf->sc_dev.hw->device, iwsrq->kmem.size,
iwsrq->kmem.va, iwsrq->kmem.pa);
iwsrq->kmem.va = NULL;
+ } else {
+ /* Not called in any failure path, so iwpbl is valid. */
+ struct irdma_mr *iwmr = iwsrq->iwpbl->iwmr;
+
+ refcount_dec(&iwmr->user_ring_refs);
}
irdma_free_rsrc(rf, rf->allocated_srqs, srq->srq_uk.srq_id);
@@ -1909,6 +1917,21 @@ static void irdma_cq_free_rsrc(struct irdma_pci_f *rf, struct irdma_cq *iwcq)
iwcq->kmem_shadow.size,
iwcq->kmem_shadow.va, iwcq->kmem_shadow.pa);
iwcq->kmem_shadow.va = NULL;
+ } else {
+ struct irdma_mr *iwmr;
+
+ /* May be called in a failure path before iwpbl is valid. */
+ if (iwcq->iwpbl) {
+ iwmr = iwcq->iwpbl->iwmr;
+
+ refcount_dec(&iwmr->user_ring_refs);
+ }
+
+ if (iwcq->iwpbl_shadow) {
+ iwmr = iwcq->iwpbl_shadow->iwmr;
+
+ refcount_dec(&iwmr->user_ring_refs);
+ }
}
irdma_free_rsrc(rf, rf->allocated_cqs, cq->cq_uk.cq_id);
@@ -2024,7 +2047,7 @@ static int irdma_resize_cq(struct ib_cq *ibcq, int entries,
struct irdma_modify_cq_info info = {};
struct irdma_dma_mem kmem_buf;
struct irdma_cq_mr *cqmr_buf;
- struct irdma_pbl *iwpbl_buf;
+ struct irdma_pbl *iwpbl_buf = NULL;
struct irdma_device *iwdev;
struct irdma_pci_f *rf;
struct irdma_cq_buf *cq_buf = NULL;
@@ -2130,11 +2153,19 @@ static int irdma_resize_cq(struct ib_cq *ibcq, int entries,
goto error;
spin_lock_irqsave(&iwcq->lock, flags);
- if (udata)
+ if (udata) {
+ struct irdma_pbl *old_iwpbl = iwcq->iwpbl;
+
/* Only update if the resize was successful. Otherwise, HW is
* still pointing to the old PBL.
*/
iwcq->iwpbl = iwpbl_buf;
+ if (old_iwpbl) {
+ struct irdma_mr *old_iwmr = old_iwpbl->iwmr;
+
+ refcount_dec(&old_iwmr->user_ring_refs);
+ }
+ }
if (cq_buf) {
cq_buf->kmem_buf = iwcq->kmem;
cq_buf->hw = dev->hw;
@@ -2150,6 +2181,11 @@ static int irdma_resize_cq(struct ib_cq *ibcq, int entries,
return 0;
error:
+ if (iwpbl_buf) {
+ struct irdma_mr *iwmr = iwpbl_buf->iwmr;
+
+ refcount_dec(&iwmr->user_ring_refs);
+ }
if (!udata) {
dma_free_coherent(dev->hw->device, kmem_buf.size, kmem_buf.va,
kmem_buf.pa);
@@ -2427,6 +2463,11 @@ static int irdma_create_srq(struct ib_srq *ibsrq,
dma_free_coherent(rf->hw.device, iwsrq->kmem.size,
iwsrq->kmem.va, iwsrq->kmem.pa);
free_rsrc:
+ if (iwsrq->user_mode && iwsrq->iwpbl) {
+ struct irdma_mr *iwmr = iwsrq->iwpbl->iwmr;
+
+ refcount_dec(&iwmr->user_ring_refs);
+ }
irdma_free_rsrc(rf, rf->allocated_srqs, iwsrq->srq_num);
return err_code;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0211/1518] arm64: dts: qcom: sm8750: wire UFS to ice instance
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (209 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0210/1518] RDMA/irdma: Add refcounting to user ring MRs Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0212/1518] nvme-apple: Use acquire/release for queue enabled state Greg Kroah-Hartman
` (787 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuldeep Singh, Konrad Dybcio,
Bjorn Andersson, Sasha Levin, Wenjia Zhang
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuldeep Singh <kuldeep.singh@oss.qualcomm.com>
[ Upstream commit ac456227d22952b656ad291ebd2d3d3e498e3d95 ]
The Inline Crypto Engine (ICE) exists as a standalone DT node, but the
UFS node lacks the required qcom,ice phandle reference.
Add the qcom,ice property to explicitly associate the UFS controller
with its ICE instance.
Fixes: d288abc3a70e ("arm64: dts: qcom: sm8750: Add UFS nodes for SM8750 SoC")
Signed-off-by: Kuldeep Singh <kuldeep.singh@oss.qualcomm.com>
Tested-by: Wenjia Zhang <wenjia.zhang@oss.qualcomm.com> # on sm8750-mtp
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260429-sm8750_ice_dt_fix-v1-1-2540dc337082@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sm8750.dtsi | 1 +
1 file changed, 1 insertion(+)
diff --git a/arch/arm64/boot/dts/qcom/sm8750.dtsi b/arch/arm64/boot/dts/qcom/sm8750.dtsi
index 2760c4f7e6f35..b714207e4c158 100644
--- a/arch/arm64/boot/dts/qcom/sm8750.dtsi
+++ b/arch/arm64/boot/dts/qcom/sm8750.dtsi
@@ -3558,6 +3558,7 @@ &mc_virt SLAVE_EBI1 QCOM_ICC_TAG_ALWAYS>,
phy-names = "ufsphy";
#reset-cells = <1>;
+ qcom,ice = <&ice>;
status = "disabled";
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0212/1518] nvme-apple: Use acquire/release for queue enabled state
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (210 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0211/1518] arm64: dts: qcom: sm8750: wire UFS to ice instance Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0213/1518] nvmet-rdma: factor out response resource cleanup Greg Kroah-Hartman
` (786 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Gui-Dong Han, Christoph Hellwig,
Keith Busch, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gui-Dong Han <hanguidong02@gmail.com>
[ Upstream commit f61c934aa084b7440fec681be3f4b481eb5a8609 ]
apple_nvme_init_queue() initializes queue state and then marks the queue
enabled. The interrupt and request paths check enabled before using that
queue state.
The old wmb() after WRITE_ONCE(enabled, true) does not publish the
earlier initialization before enabled becomes visible. Use a release store
when enabling the queue and acquire loads when testing it.
Although the shutdown-side enabled accesses are not used for publishing
queue initialization, use helpers for them as well for consistency.
Fixes: 5bd2927aceba ("nvme-apple: Add initial Apple SoC NVMe driver")
Signed-off-by: Gui-Dong Han <hanguidong02@gmail.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Keith Busch <kbusch@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/nvme/host/apple.c | 30 +++++++++++++++++++++++-------
1 file changed, 23 insertions(+), 7 deletions(-)
diff --git a/drivers/nvme/host/apple.c b/drivers/nvme/host/apple.c
index 9cc614227bc70..b0ae46bda4031 100644
--- a/drivers/nvme/host/apple.c
+++ b/drivers/nvme/host/apple.c
@@ -151,6 +151,23 @@ struct apple_nvme_queue {
bool enabled;
};
+static inline bool apple_nvme_queue_enabled(struct apple_nvme_queue *q)
+{
+ /* Pair with apple_nvme_enable_queue(). */
+ return smp_load_acquire(&q->enabled);
+}
+
+static inline void apple_nvme_enable_queue(struct apple_nvme_queue *q)
+{
+ /* Publish queue initialization before setting q->enabled. */
+ smp_store_release(&q->enabled, true);
+}
+
+static inline void apple_nvme_disable_queue(struct apple_nvme_queue *q)
+{
+ WRITE_ONCE(q->enabled, false);
+}
+
/*
* The apple_nvme_iod describes the data in an I/O.
*
@@ -677,7 +694,7 @@ static bool apple_nvme_handle_cq(struct apple_nvme_queue *q, bool force)
bool found;
DEFINE_IO_COMP_BATCH(iob);
- if (!READ_ONCE(q->enabled) && !force)
+ if (!apple_nvme_queue_enabled(q) && !force)
return false;
found = apple_nvme_poll_cq(q, &iob);
@@ -780,7 +797,7 @@ static blk_status_t apple_nvme_queue_rq(struct blk_mq_hw_ctx *hctx,
* We should not need to do this, but we're still using this to
* ensure we can drain requests on a dying queue.
*/
- if (unlikely(!READ_ONCE(q->enabled)))
+ if (unlikely(!apple_nvme_queue_enabled(q)))
return BLK_STS_IOERR;
if (!nvme_check_ready(&anv->ctrl, req, true))
@@ -863,7 +880,7 @@ static void apple_nvme_disable(struct apple_nvme *anv, bool shutdown)
nvme_quiesce_io_queues(&anv->ctrl);
if (!dead) {
- if (READ_ONCE(anv->ioq.enabled)) {
+ if (apple_nvme_queue_enabled(&anv->ioq)) {
apple_nvme_remove_sq(anv);
apple_nvme_remove_cq(anv);
}
@@ -887,8 +904,8 @@ static void apple_nvme_disable(struct apple_nvme *anv, bool shutdown)
nvme_disable_ctrl(&anv->ctrl, false);
}
- WRITE_ONCE(anv->ioq.enabled, false);
- WRITE_ONCE(anv->adminq.enabled, false);
+ apple_nvme_disable_queue(&anv->ioq);
+ apple_nvme_disable_queue(&anv->adminq);
mb(); /* ensure that nvme_queue_rq() sees that enabled is cleared */
nvme_quiesce_admin_queue(&anv->ctrl);
@@ -1016,8 +1033,7 @@ static void apple_nvme_init_queue(struct apple_nvme_queue *q)
memset(q->tcbs, 0, anv->hw->max_queue_depth
* sizeof(struct apple_nvmmu_tcb));
memset(q->cqes, 0, depth * sizeof(struct nvme_completion));
- WRITE_ONCE(q->enabled, true);
- wmb(); /* ensure the first interrupt sees the initialization */
+ apple_nvme_enable_queue(q);
}
static void apple_nvme_reset_work(struct work_struct *work)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0213/1518] nvmet-rdma: factor out response resource cleanup
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (211 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0212/1518] nvme-apple: Use acquire/release for queue enabled state Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0214/1518] nvmet-rdma: fix response resource leak on queue teardown Greg Kroah-Hartman
` (785 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shinichiro Kawasaki,
Christoph Hellwig, Keith Busch, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shin'ichiro Kawasaki <shinichiro.kawasaki@wdc.com>
[ Upstream commit 90096175473f7c86e39c3f74f10343f965f5a05d ]
Move the RDMA read/write context teardown and the request SGL freeing
out of nvmet_rdma_release_rsp() into a new helper function
nvmet_rdma_free_rsp_resources().
This is a refactoring with no functional change, in preparation for the
following patch that uses nvmet_rdma_free_rsp_resources().
Signed-off-by: Shin'ichiro Kawasaki <shinichiro.kawasaki@wdc.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Keith Busch <kbusch@kernel.org>
Stable-dep-of: 0114dd303b37 ("nvmet-rdma: fix response resource leak on queue teardown")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/nvme/target/rdma.c | 13 ++++++++++---
1 file changed, 10 insertions(+), 3 deletions(-)
diff --git a/drivers/nvme/target/rdma.c b/drivers/nvme/target/rdma.c
index 4b493226d07c1..a6152326eb861 100644
--- a/drivers/nvme/target/rdma.c
+++ b/drivers/nvme/target/rdma.c
@@ -658,18 +658,25 @@ static void nvmet_rdma_rw_ctx_destroy(struct nvmet_rdma_rsp *rsp)
req->sg, req->sg_cnt, nvmet_data_dir(req));
}
-static void nvmet_rdma_release_rsp(struct nvmet_rdma_rsp *rsp)
+static void nvmet_rdma_free_rsp_resources(struct nvmet_rdma_rsp *rsp)
{
struct nvmet_rdma_queue *queue = rsp->queue;
- atomic_add(1 + rsp->n_rdma, &queue->sq_wr_avail);
-
if (rsp->n_rdma)
nvmet_rdma_rw_ctx_destroy(rsp);
if (rsp->req.sg < rsp->cmd->inline_sg ||
rsp->req.sg >= rsp->cmd->inline_sg + queue->dev->inline_page_count)
nvmet_req_free_sgls(&rsp->req);
+}
+
+static void nvmet_rdma_release_rsp(struct nvmet_rdma_rsp *rsp)
+{
+ struct nvmet_rdma_queue *queue = rsp->queue;
+
+ atomic_add(1 + rsp->n_rdma, &queue->sq_wr_avail);
+
+ nvmet_rdma_free_rsp_resources(rsp);
if (unlikely(!list_empty_careful(&queue->rsp_wr_wait_list)))
nvmet_rdma_process_wr_wait_list(queue);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0214/1518] nvmet-rdma: fix response resource leak on queue teardown
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (212 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0213/1518] nvmet-rdma: factor out response resource cleanup Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0215/1518] bus: ti-sysc: Fix /chosen node reference leak Greg Kroah-Hartman
` (784 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shinichiro Kawasaki,
Christoph Hellwig, Keith Busch, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shin'ichiro Kawasaki <shinichiro.kawasaki@wdc.com>
[ Upstream commit 0114dd303b373522dea06053aabae34bdd33a7c4 ]
When an nvme target with rdma transport is removed while I/Os are in
flight, a response can be posted but its send completion is never
delivered before the connection is torn down. As a result
nvmet_rdma_send_done() and nvmet_rdma_release_rsp() are never called for
the response, and this leaks the allocated RDMA read/write context and
request SGLs.
These leaks are recreated by running blktests nvme/061 with the rdma
transport and the siw driver. Kernel kmemleak feature reports them as
follows:
unreferenced object 0xffff88812bc490c0 (size 32):
comm "kworker/2:1H", pid 409, jiffies 4307744490
backtrace (crc 89afd339):
__kmalloc_noprof+0x5f9/0x890
sgl_alloc_order+0x7b/0x380
nvmet_req_alloc_sgls+0x290/0x4f0 [nvmet]
nvmet_rdma_map_sgl_keyed+0x241/0x12e0 [nvmet_rdma]
nvmet_rdma_handle_command+0x73e/0xb80 [nvmet_rdma]
__ib_process_cq+0x149/0x4c0 [ib_core]
ib_cq_poll_work+0x49/0x160 [ib_core]
process_one_work+0x8b2/0x1640
worker_thread+0x5fd/0xfe0
kthread+0x367/0x460
ret_from_fork+0x655/0x9d0
ret_from_fork_asm+0x1a/0x30
unreferenced object 0xffff88814bd05e80 (size 64):
comm "kworker/3:1H", pid 148, jiffies 4295195428
backtrace (crc e35510cb):
__kmalloc_noprof+0x5f9/0x890
rdma_rw_ctx_init+0x333/0x1fa0 [ib_core]
nvmet_rdma_map_sgl_keyed+0x5c8/0x12e0 [nvmet_rdma]
nvmet_rdma_handle_command+0x73e/0xb80 [nvmet_rdma]
__ib_process_cq+0x149/0x4c0 [ib_core]
ib_cq_poll_work+0x49/0x160 [ib_core]
process_one_work+0x8b2/0x1640
worker_thread+0x5fd/0xfe0
kthread+0x367/0x460
ret_from_fork+0x655/0x9d0
ret_from_fork_asm+0x1a/0x30
To avoid the memory leaks, reclaim the memory of the in-flight responses
when the queue QP is torn down. Call nvmet_rdma_free_rsp_resources()
that frees up the RDMA read/write context and the request SGLs of such
responses.
Fixes: 8f000cac6e7a ("nvmet-rdma: add a NVMe over Fabrics RDMA target driver")
Signed-off-by: Shin'ichiro Kawasaki <shinichiro.kawasaki@wdc.com>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Keith Busch <kbusch@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/nvme/target/rdma.c | 18 ++++++++++++++++++
1 file changed, 18 insertions(+)
diff --git a/drivers/nvme/target/rdma.c b/drivers/nvme/target/rdma.c
index a6152326eb861..97eb0c61baa14 100644
--- a/drivers/nvme/target/rdma.c
+++ b/drivers/nvme/target/rdma.c
@@ -1346,9 +1346,27 @@ static int nvmet_rdma_create_queue_ib(struct nvmet_rdma_queue *queue)
goto out;
}
+static bool nvmet_rdma_reclaim_rsp(struct sbitmap *sb, unsigned int bitnr,
+ void *data)
+{
+ struct nvmet_rdma_queue *queue = data;
+
+ nvmet_rdma_free_rsp_resources(&queue->rsps[bitnr]);
+
+ return true;
+}
+
static void nvmet_rdma_destroy_queue_ib(struct nvmet_rdma_queue *queue)
{
ib_drain_qp(queue->qp);
+
+ /*
+ * Reclaim resources of a response that is still in-flight when the
+ * queue is being torn down. This happens when the connection was
+ * forcefully disconnected while an I/O is in flight.
+ */
+ sbitmap_for_each_set(&queue->rsp_tags, nvmet_rdma_reclaim_rsp, queue);
+
if (queue->cm_id)
rdma_destroy_id(queue->cm_id);
ib_destroy_qp(queue->qp);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0215/1518] bus: ti-sysc: Fix /chosen node reference leak
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (213 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0214/1518] nvmet-rdma: fix response resource leak on queue teardown Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0216/1518] PM: sleep: Fix off-by-one in wakelocks number limit check Greg Kroah-Hartman
` (783 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yuho Choi, Andreas Kemnade,
Kevin Hilman (TI), Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuho Choi <dbgh9129@gmail.com>
[ Upstream commit 6342de0aed216b6df460b492ddb532b3e0ed16f1 ]
sysc_init_stdout_path() gets the /chosen node with
of_find_node_by_path() to read stdout-path. The function then overwrites
the local node pointer with the stdout-path lookup result, or exits on
error, without dropping the /chosen reference.
Keep the /chosen node in a separate variable and put it after the
stdout-path value has been used for the lookup. The successful stdout
node lookup remains referenced by the cached stdout_path pointer.
Fixes: 3bb37c8e6e6a ("bus: ti-sysc: Handle stdout-path for debug console")
Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
Reviewed-by: Andreas Kemnade <andreas@kemnade.info>
Link: https://patch.msgid.link/20260615200540.770205-1-dbgh9129@gmail.com
Signed-off-by: Kevin Hilman (TI) <khilman@baylibre.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bus/ti-sysc.c | 12 ++++++++----
1 file changed, 8 insertions(+), 4 deletions(-)
diff --git a/drivers/bus/ti-sysc.c b/drivers/bus/ti-sysc.c
index 610354ce7f8f0..5c096eb3f4279 100644
--- a/drivers/bus/ti-sysc.c
+++ b/drivers/bus/ti-sysc.c
@@ -682,6 +682,7 @@ static struct device_node *stdout_path;
static void sysc_init_stdout_path(struct sysc *ddata)
{
+ struct device_node *chosen;
struct device_node *np = NULL;
const char *uart;
@@ -691,15 +692,18 @@ static void sysc_init_stdout_path(struct sysc *ddata)
if (stdout_path)
return;
- np = of_find_node_by_path("/chosen");
- if (!np)
+ chosen = of_find_node_by_path("/chosen");
+ if (!chosen)
goto err;
- uart = of_get_property(np, "stdout-path", NULL);
- if (!uart)
+ uart = of_get_property(chosen, "stdout-path", NULL);
+ if (!uart) {
+ of_node_put(chosen);
goto err;
+ }
np = of_find_node_by_path(uart);
+ of_node_put(chosen);
if (!np)
goto err;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0216/1518] PM: sleep: Fix off-by-one in wakelocks number limit check
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (214 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0215/1518] bus: ti-sysc: Fix /chosen node reference leak Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0217/1518] cgroup/cpuset: Make nr_deadline_tasks an atomic_t Greg Kroah-Hartman
` (782 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Haowen Tu, Rafael J. Wysocki,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Haowen Tu <tuhaowen@uniontech.com>
[ Upstream commit 6058646587dded0ce0ba91bd5a6afbf14fe42055 ]
CONFIG_PM_WAKELOCKS_LIMIT is documented as the maximum number of
user-space wakeup sources, but the limit check is performed before
the counter is incremented and only rejects new wakeup sources when the
current number is greater than the limit. This allows one extra wakeup
source to be created.
Reject new wakeup sources once the counter has reached the limit.
Fixes: b86ff9820fd5 ("PM / Sleep: Add user space interface for manipulating wakeup sources, v3")
Signed-off-by: Haowen Tu <tuhaowen@uniontech.com>
[ rjw: Subject edits ]
Link: https://patch.msgid.link/20260624053839.2150567-1-tuhaowen@uniontech.com
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/power/wakelock.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/kernel/power/wakelock.c b/kernel/power/wakelock.c
index 4e941999a53ba..5c2a248cf249a 100644
--- a/kernel/power/wakelock.c
+++ b/kernel/power/wakelock.c
@@ -63,7 +63,7 @@ static unsigned int number_of_wakelocks;
static inline bool wakelocks_limit_exceeded(void)
{
- return number_of_wakelocks > CONFIG_PM_WAKELOCKS_LIMIT;
+ return number_of_wakelocks >= CONFIG_PM_WAKELOCKS_LIMIT;
}
static inline void increment_wakelocks_number(void)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0217/1518] cgroup/cpuset: Make nr_deadline_tasks an atomic_t
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (215 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0216/1518] PM: sleep: Fix off-by-one in wakelocks number limit check Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0218/1518] arm64: dts: qcom: sc8280xp-blackrock: switch to uefi rtc offset Greg Kroah-Hartman
` (781 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ridong Chen, Waiman Long, Tejun Heo,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Waiman Long <longman@redhat.com>
[ Upstream commit 95220e1f18f6321008f021abc7d6f581f64bcb82 ]
The nr_deadline_tasks variable in the cpuset structure was introduced by
commit 6c24849f5515 ("sched/cpuset: Keep track of SCHED_DEADLINE task
in cpusets"). It is reported by sashiko [1] that nr_deadline_tasks
can currently be modified by inc_dl_tasks_cs() under rq->lock and
by cpuset_attach() under cpuset_mutex. So if both updates happen
simultaneously, the nr_deadline_tasks variable can be corrupted leading
to incorrect operations down the road.
Fix that by changing its type to atomic_t so that nr_deadline_tasks
are always atomically updated. This fix patch is a low hanging fruit.
It can handle some of the races between a concurrent sched_setscheduler()
and cpuset_can_attach()/cpuset_attach() calls, but not all of them like
the other issue raised by sashiko [2]. This will be handled hopefully
in a future follow up patch.
[1] https://sashiko.dev/#/patchset/20260626181923.133658-1-longman%40redhat.com
[2] https://sashiko.dev/#/patchset/20260630033344.352702-1-longman%40redhat.com
Fixes: 6c24849f5515 ("sched/cpuset: Keep track of SCHED_DEADLINE task in cpusets")
Reviewed-by: Ridong Chen <ridong.chen@linux.dev>
Signed-off-by: Waiman Long <longman@redhat.com>
Signed-off-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/cgroup/cpuset-internal.h | 2 +-
kernel/cgroup/cpuset.c | 10 +++++-----
2 files changed, 6 insertions(+), 6 deletions(-)
diff --git a/kernel/cgroup/cpuset-internal.h b/kernel/cgroup/cpuset-internal.h
index 337608f408ce0..0eb9ebd4fcb92 100644
--- a/kernel/cgroup/cpuset-internal.h
+++ b/kernel/cgroup/cpuset-internal.h
@@ -165,7 +165,7 @@ struct cpuset {
* number of SCHED_DEADLINE tasks attached to this cpuset, so that we
* know when to rebuild associated root domain bandwidth information.
*/
- int nr_deadline_tasks;
+ atomic_t nr_deadline_tasks;
int nr_migrate_dl_tasks;
u64 sum_migrate_dl_bw;
diff --git a/kernel/cgroup/cpuset.c b/kernel/cgroup/cpuset.c
index 2386090351cd3..23c90b1e219ac 100644
--- a/kernel/cgroup/cpuset.c
+++ b/kernel/cgroup/cpuset.c
@@ -145,14 +145,14 @@ void inc_dl_tasks_cs(struct task_struct *p)
{
struct cpuset *cs = task_cs(p);
- cs->nr_deadline_tasks++;
+ atomic_inc(&cs->nr_deadline_tasks);
}
void dec_dl_tasks_cs(struct task_struct *p)
{
struct cpuset *cs = task_cs(p);
- cs->nr_deadline_tasks--;
+ atomic_dec(&cs->nr_deadline_tasks);
}
static inline bool is_partition_valid(const struct cpuset *cs)
@@ -1033,7 +1033,7 @@ static void dl_update_tasks_root_domain(struct cpuset *cs)
struct css_task_iter it;
struct task_struct *task;
- if (cs->nr_deadline_tasks == 0)
+ if (atomic_read(&cs->nr_deadline_tasks) == 0)
return;
css_task_iter_start(&cs->css, 0, &it);
@@ -3313,8 +3313,8 @@ static void cpuset_attach(struct cgroup_taskset *tset)
cs->old_mems_allowed = cpuset_attach_nodemask_to;
if (cs->nr_migrate_dl_tasks) {
- cs->nr_deadline_tasks += cs->nr_migrate_dl_tasks;
- oldcs->nr_deadline_tasks -= cs->nr_migrate_dl_tasks;
+ atomic_add(cs->nr_migrate_dl_tasks, &cs->nr_deadline_tasks);
+ atomic_sub(cs->nr_migrate_dl_tasks, &oldcs->nr_deadline_tasks);
reset_migrate_dl_data(cs);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0218/1518] arm64: dts: qcom: sc8280xp-blackrock: switch to uefi rtc offset
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (216 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0217/1518] cgroup/cpuset: Make nr_deadline_tasks an atomic_t Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0219/1518] arm64: dts: qcom: sm7225-fairphone-fp4: Fix address in fb node name Greg Kroah-Hartman
` (780 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jens Glathe, Konrad Dybcio,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jens Glathe <jens.glathe@oldschoolsolutions.biz>
[ Upstream commit f52102fc9ccbbb3c4bc01a29f3194fe07f9602f5 ]
On many Qualcomm platforms the PMIC RTC control and time registers are
read-only so that the RTC time can not be updated. Instead an offset
needs be stored in some machine-specific non-volatile memory, which a
driver can take into account.
On platforms where the offset is stored in a Qualcomm specific UEFI
variable the variables are also accessed in a non-standard way, which
means that the OS cannot assume that the variable service is available
by the time the RTC driver probes.
Use the new 'qcom,uefi-rtc-info' property to indicate that the offset is
stored in a UEFI variable so that the OS can determine whether to wait
for it to become available.
[1]: https://lore.kernel.org/r/20250423075143.11157-4-johan+linaro@kernel.org
Fixes: 16a7fed11714 ("arm64: dts: qcom: sc8280xp-blackrock: dt definition for WDK2023")
Signed-off-by: Jens Glathe <jens.glathe@oldschoolsolutions.biz>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260501-blackrock-rtc-v1-1-bddf3e37fa94@oldschoolsolutions.biz
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../boot/dts/qcom/sc8280xp-microsoft-blackrock.dts | 11 +----------
1 file changed, 1 insertion(+), 10 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sc8280xp-microsoft-blackrock.dts b/arch/arm64/boot/dts/qcom/sc8280xp-microsoft-blackrock.dts
index a40dccd70dfda..3c3607929c2f2 100644
--- a/arch/arm64/boot/dts/qcom/sc8280xp-microsoft-blackrock.dts
+++ b/arch/arm64/boot/dts/qcom/sc8280xp-microsoft-blackrock.dts
@@ -769,20 +769,11 @@ &pmk8280_pon_resin {
};
&pmk8280_rtc {
- nvmem-cells = <&rtc_offset>;
- nvmem-cell-names = "offset";
+ qcom,uefi-rtc-info;
status = "okay";
};
-&pmk8280_sdam_6 {
- status = "okay";
-
- rtc_offset: rtc-offset@bc {
- reg = <0xbc 0x4>;
- };
-};
-
&pmk8280_vadc {
channel@144 {
reg = <PM8350_ADC7_AMUX_THM1_100K_PU(1)>;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0219/1518] arm64: dts: qcom: sm7225-fairphone-fp4: Fix address in fb node name
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (217 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0218/1518] arm64: dts: qcom: sc8280xp-blackrock: switch to uefi rtc offset Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0220/1518] arm64: dts: qcom: hamoa: Fix clocks for HSPHYs Greg Kroah-Hartman
` (779 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Luca Weiss, Konrad Dybcio,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Luca Weiss <luca.weiss@fairphone.com>
[ Upstream commit f6e65005fe55c3d09287851523de06367cbf0bc2 ]
'reg' is 0xa0000000 so the node name is missing a zero. Add it, so that
the reg and address in the node name matches.
No functional impact.
Fixes: 4cbea668767d ("arm64: dts: qcom: sm7225: Add device tree for Fairphone 4")
Signed-off-by: Luca Weiss <luca.weiss@fairphone.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260505-sm6350-misc-v1-3-0b9efc22690c@fairphone.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sm7225-fairphone-fp4.dts | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/arm64/boot/dts/qcom/sm7225-fairphone-fp4.dts b/arch/arm64/boot/dts/qcom/sm7225-fairphone-fp4.dts
index 8cbe068645ea9..b353de2bc37ad 100644
--- a/arch/arm64/boot/dts/qcom/sm7225-fairphone-fp4.dts
+++ b/arch/arm64/boot/dts/qcom/sm7225-fairphone-fp4.dts
@@ -48,7 +48,7 @@ chosen {
stdout-path = "serial0:115200n8";
- framebuffer0: framebuffer@a000000 {
+ framebuffer0: framebuffer@a0000000 {
compatible = "simple-framebuffer";
reg = <0 0xa0000000 0 (2340 * 1080 * 4)>;
width = <1080>;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0220/1518] arm64: dts: qcom: hamoa: Fix clocks for HSPHYs
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (218 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0219/1518] arm64: dts: qcom: sm7225-fairphone-fp4: Fix address in fb node name Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0221/1518] clk: qcom: gcc-glymur: Move EVA clocks to critical clock list Greg Kroah-Hartman
` (778 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Abel Vesa,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
[ Upstream commit 115894bc201b0cd1799d239875a1b40924f0ef7b ]
The tertiary controller's HSPHY has its own toggle in TCSR, while the
primary one is wired directly to the XO clock. Fix that.
Fixes: 4af46b7bd66f ("arm64: dts: qcom: x1e80100: Add USB nodes")
Signed-off-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260518-topic-hamoa_hsphy_clk-v1-1-d85203756505@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/hamoa.dtsi | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/hamoa.dtsi b/arch/arm64/boot/dts/qcom/hamoa.dtsi
index adb18c10dbd9f..6a456b3694fc9 100644
--- a/arch/arm64/boot/dts/qcom/hamoa.dtsi
+++ b/arch/arm64/boot/dts/qcom/hamoa.dtsi
@@ -2826,7 +2826,7 @@ usb_1_ss0_hsphy: phy@fd3000 {
reg = <0 0x00fd3000 0 0x154>;
#phy-cells = <0>;
- clocks = <&tcsr TCSR_USB2_1_CLKREF_EN>;
+ clocks = <&rpmhcc RPMH_CXO_CLK>;
clock-names = "ref";
resets = <&gcc GCC_QUSB2PHY_PRIM_BCR>;
@@ -2968,7 +2968,7 @@ usb_1_ss2_hsphy: phy@fde000 {
reg = <0 0x00fde000 0 0x154>;
#phy-cells = <0>;
- clocks = <&tcsr TCSR_USB2_1_CLKREF_EN>;
+ clocks = <&tcsr TCSR_USB2_2_CLKREF_EN>;
clock-names = "ref";
resets = <&gcc GCC_QUSB2PHY_TERT_BCR>;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0221/1518] clk: qcom: gcc-glymur: Move EVA clocks to critical clock list
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (219 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0220/1518] arm64: dts: qcom: hamoa: Fix clocks for HSPHYs Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0222/1518] bus: qcom-ebi2: Simplify with scoped for each OF child loop Greg Kroah-Hartman
` (777 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Taniya Das, Konrad Dybcio,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Taniya Das <taniya.das@oss.qualcomm.com>
[ Upstream commit 7399034fd78615ba826b864fca2e4572f13cf8e3 ]
The gcc_eva_ahb_clk and gcc_eva_xo_clk branch clocks should not be
registered as standalone GCC branch clocks. Drop these clocks from
the GCC clock list and instead add their CBCR registers to the GCC
critical clocks list to ensure they remain enabled during early boot.
If these clocks are registered as normal branch clocks, they may be
gated, which breaks access to the EVA clock controller during clock
controller probe, thus leave them as critical clocks similar to other
subsystem AHB and XO clocks.
Fixes: efe504300a17 ("clk: qcom: gcc: Add support for Global Clock Controller")
Signed-off-by: Taniya Das <taniya.das@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260617-evacc_glymur-v2-1-905108dacaaa@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/qcom/gcc-glymur.c | 32 ++------------------------------
1 file changed, 2 insertions(+), 30 deletions(-)
diff --git a/drivers/clk/qcom/gcc-glymur.c b/drivers/clk/qcom/gcc-glymur.c
index eff3248d483ad..9e84f3e7c6a9b 100644
--- a/drivers/clk/qcom/gcc-glymur.c
+++ b/drivers/clk/qcom/gcc-glymur.c
@@ -3671,21 +3671,6 @@ static struct clk_branch gcc_disp_hf_axi_clk = {
},
};
-static struct clk_branch gcc_eva_ahb_clk = {
- .halt_reg = 0x9b004,
- .halt_check = BRANCH_HALT_VOTED,
- .hwcg_reg = 0x9b004,
- .hwcg_bit = 1,
- .clkr = {
- .enable_reg = 0x9b004,
- .enable_mask = BIT(0),
- .hw.init = &(const struct clk_init_data) {
- .name = "gcc_eva_ahb_clk",
- .ops = &clk_branch2_ops,
- },
- },
-};
-
static struct clk_branch gcc_eva_axi0_clk = {
.halt_reg = 0x9b008,
.halt_check = BRANCH_HALT_SKIP,
@@ -3716,19 +3701,6 @@ static struct clk_branch gcc_eva_axi0c_clk = {
},
};
-static struct clk_branch gcc_eva_xo_clk = {
- .halt_reg = 0x9b024,
- .halt_check = BRANCH_HALT,
- .clkr = {
- .enable_reg = 0x9b024,
- .enable_mask = BIT(0),
- .hw.init = &(const struct clk_init_data) {
- .name = "gcc_eva_xo_clk",
- .ops = &clk_branch2_ops,
- },
- },
-};
-
static struct clk_branch gcc_gp1_clk = {
.halt_reg = 0x64000,
.halt_check = BRANCH_HALT,
@@ -7995,10 +7967,8 @@ static struct clk_regmap *gcc_glymur_clocks[] = {
[GCC_CFG_NOC_USB_ANOC_AHB_CLK] = &gcc_cfg_noc_usb_anoc_ahb_clk.clkr,
[GCC_CFG_NOC_USB_ANOC_SOUTH_AHB_CLK] = &gcc_cfg_noc_usb_anoc_south_ahb_clk.clkr,
[GCC_DISP_HF_AXI_CLK] = &gcc_disp_hf_axi_clk.clkr,
- [GCC_EVA_AHB_CLK] = &gcc_eva_ahb_clk.clkr,
[GCC_EVA_AXI0_CLK] = &gcc_eva_axi0_clk.clkr,
[GCC_EVA_AXI0C_CLK] = &gcc_eva_axi0c_clk.clkr,
- [GCC_EVA_XO_CLK] = &gcc_eva_xo_clk.clkr,
[GCC_GP1_CLK] = &gcc_gp1_clk.clkr,
[GCC_GP1_CLK_SRC] = &gcc_gp1_clk_src.clkr,
[GCC_GP2_CLK] = &gcc_gp2_clk.clkr,
@@ -8547,6 +8517,8 @@ static u32 gcc_glymur_critical_cbcrs[] = {
0x71004, /* GCC_GPU_CFG_AHB_CLK */
0x32004, /* GCC_VIDEO_AHB_CLK */
0x32058, /* GCC_VIDEO_XO_CLK */
+ 0x9b004, /* GCC_EVA_AHB_CLK */
+ 0x9b024, /* GCC_EVA_XO_CLK */
};
static const struct regmap_config gcc_glymur_regmap_config = {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0222/1518] bus: qcom-ebi2: Simplify with scoped for each OF child loop
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (220 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0221/1518] clk: qcom: gcc-glymur: Move EVA clocks to critical clock list Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0223/1518] bus: qcom-ebi2: Fix clock leak on probe failure Greg Kroah-Hartman
` (776 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Krzysztof Kozlowski, Konrad Dybcio,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
[ Upstream commit 9c252f3c8f390fae4ca09de36c9262a35ae88ace ]
Use scoped for-each loop when iterating over device nodes to make code a
bit simpler.
Signed-off-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260102125030.65186-3-krzysztof.kozlowski@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Stable-dep-of: 64774dea5896 ("bus: qcom-ebi2: Fix clock leak on probe failure")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bus/qcom-ebi2.c | 7 ++-----
1 file changed, 2 insertions(+), 5 deletions(-)
diff --git a/drivers/bus/qcom-ebi2.c b/drivers/bus/qcom-ebi2.c
index c1fef1b4bd89b..be8166565e7cc 100644
--- a/drivers/bus/qcom-ebi2.c
+++ b/drivers/bus/qcom-ebi2.c
@@ -292,7 +292,6 @@ static void qcom_ebi2_setup_chipselect(struct device_node *np,
static int qcom_ebi2_probe(struct platform_device *pdev)
{
struct device_node *np = pdev->dev.of_node;
- struct device_node *child;
struct device *dev = &pdev->dev;
struct resource *res;
void __iomem *ebi2_base;
@@ -348,15 +347,13 @@ static int qcom_ebi2_probe(struct platform_device *pdev)
writel(val, ebi2_base);
/* Walk over the child nodes and see what chipselects we use */
- for_each_available_child_of_node(np, child) {
+ for_each_available_child_of_node_scoped(np, child) {
u32 csindex;
/* Figure out the chipselect */
ret = of_property_read_u32(child, "reg", &csindex);
- if (ret) {
- of_node_put(child);
+ if (ret)
return ret;
- }
if (csindex > 5) {
dev_err(dev,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0223/1518] bus: qcom-ebi2: Fix clock leak on probe failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (221 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0222/1518] bus: qcom-ebi2: Simplify with scoped for each OF child loop Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0224/1518] wifi: mac80211_hwsim: avoid NULL skb in stop queue drain Greg Kroah-Hartman
` (775 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ruoyu Wang, Bjorn Andersson,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ruoyu Wang <ruoyuw560@gmail.com>
[ Upstream commit 64774dea58969194ea5c27fa639954e551a87024 ]
qcom_ebi2_probe() enables the EBI2X and EBI2 clocks before it walks
child nodes and populates child devices. If reading a child node's reg
property fails, or if of_platform_default_populate() fails, probe returns
without disabling either clock.
Route those failure paths through the existing clock cleanup labels so a
failed probe does not leave the clocks prepared and enabled.
Fixes: 335a12754808 ("bus: qcom: add EBI2 driver")
Signed-off-by: Ruoyu Wang <ruoyuw560@gmail.com>
Link: https://lore.kernel.org/r/20260620080406.1970447-1-ruoyuw560@gmail.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bus/qcom-ebi2.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
diff --git a/drivers/bus/qcom-ebi2.c b/drivers/bus/qcom-ebi2.c
index be8166565e7cc..ab00c75b9e953 100644
--- a/drivers/bus/qcom-ebi2.c
+++ b/drivers/bus/qcom-ebi2.c
@@ -353,7 +353,7 @@ static int qcom_ebi2_probe(struct platform_device *pdev)
/* Figure out the chipselect */
ret = of_property_read_u32(child, "reg", &csindex);
if (ret)
- return ret;
+ goto err_disable_clk;
if (csindex > 5) {
dev_err(dev,
@@ -372,8 +372,12 @@ static int qcom_ebi2_probe(struct platform_device *pdev)
have_children = true;
}
- if (have_children)
- return of_platform_default_populate(np, NULL, dev);
+ if (have_children) {
+ ret = of_platform_default_populate(np, NULL, dev);
+ if (ret)
+ goto err_disable_clk;
+ }
+
return 0;
err_disable_clk:
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0224/1518] wifi: mac80211_hwsim: avoid NULL skb in stop queue drain
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (222 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0223/1518] bus: qcom-ebi2: Fix clock leak on probe failure Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0225/1518] staging: greybus: audio: correct sscanf() return value check Greg Kroah-Hartman
` (774 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Cen Zhang, Johannes Berg,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cen Zhang <zzzccc427@gmail.com>
[ Upstream commit 158438cd6ad69d6dd7d871582c38baf22169fede ]
mac80211_hwsim_stop() drops any frames left in data->pending. The loop
currently checks skb_queue_empty() and then dequeues separately.
That split is racy with TX status handling, which can remove a pending
frame under the queue lock. If the last entry is removed after the empty
check, skb_dequeue() returns NULL and the stop path passes that NULL skb
to ieee80211_free_txskb().
Use skb_dequeue() as the loop condition instead. The dequeue result is the
object that stop owns and frees, and a concurrent status completion that
empties the queue simply makes the loop terminate.
Fixes: bd18de517923 ("mac80211_hwsim: drop pending frames on stop")
Assisted-by: Codex:gpt-5.5
Signed-off-by: Cen Zhang <zzzccc427@gmail.com>
Link: https://patch.msgid.link/20260706161822.921039-1-zzzccc427@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/virtual/mac80211_hwsim.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/drivers/net/wireless/virtual/mac80211_hwsim.c b/drivers/net/wireless/virtual/mac80211_hwsim.c
index a0724e1c53070..3d66f4aa8393e 100644
--- a/drivers/net/wireless/virtual/mac80211_hwsim.c
+++ b/drivers/net/wireless/virtual/mac80211_hwsim.c
@@ -2159,6 +2159,7 @@ static int mac80211_hwsim_start(struct ieee80211_hw *hw)
static void mac80211_hwsim_stop(struct ieee80211_hw *hw, bool suspend)
{
struct mac80211_hwsim_data *data = hw->priv;
+ struct sk_buff *skb;
int i;
data->started = false;
@@ -2166,8 +2167,8 @@ static void mac80211_hwsim_stop(struct ieee80211_hw *hw, bool suspend)
for (i = 0; i < ARRAY_SIZE(data->link_data); i++)
hrtimer_cancel(&data->link_data[i].beacon_timer);
- while (!skb_queue_empty(&data->pending))
- ieee80211_free_txskb(hw, skb_dequeue(&data->pending));
+ while ((skb = skb_dequeue(&data->pending)))
+ ieee80211_free_txskb(hw, skb);
wiphy_dbg(hw->wiphy, "%s\n", __func__);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0225/1518] staging: greybus: audio: correct sscanf() return value check
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (223 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0224/1518] wifi: mac80211_hwsim: avoid NULL skb in stop queue drain Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0226/1518] staging: sm750fb: gate dualview dataflow using g_dualview Greg Kroah-Hartman
` (773 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Alexander A. Klimov, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexander A. Klimov <grandmaster@al2klimov.de>
[ Upstream commit f883fa1a0a0212f63acb18c50e5f900301f3bb1e ]
manager_sysfs_add_store() passes 6 pointers to sscanf(),
but required latter to return 7 which always failed the operation.
I corrected it to 6.
Fixes: 49b9137a6002 ("staging: greybus: audio: remove redundant slot field")
Signed-off-by: Alexander A. Klimov <grandmaster@al2klimov.de>
Link: https://patch.msgid.link/20260521182331.22685-1-grandmaster@al2klimov.de
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/staging/greybus/audio_manager_sysfs.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/staging/greybus/audio_manager_sysfs.c b/drivers/staging/greybus/audio_manager_sysfs.c
index fcd518f9540cd..ff323ca8154f3 100644
--- a/drivers/staging/greybus/audio_manager_sysfs.c
+++ b/drivers/staging/greybus/audio_manager_sysfs.c
@@ -23,7 +23,7 @@ static ssize_t manager_sysfs_add_store(struct kobject *kobj,
desc.name, &desc.vid, &desc.pid, &desc.intf_id,
&desc.ip_devices, &desc.op_devices);
- if (num != 7)
+ if (num != 6)
return -EINVAL;
num = gb_audio_manager_add(&desc);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0226/1518] staging: sm750fb: gate dualview dataflow using g_dualview
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (224 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0225/1518] staging: greybus: audio: correct sscanf() return value check Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0227/1518] staging: sm750fb: Add missing Kconfig dependency Greg Kroah-Hartman
` (772 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ahmet Sezgin Duran, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ahmet Sezgin Duran <ahmet@sezginduran.net>
[ Upstream commit d352778979d2eed09e266ed0f3a5e3ccd3983940 ]
In sm750fb_setup and sm750fb_set_drv functions, the dualview
related code is guarded by `sm750_dev->fb_count > 1` condition.
That value is updated only after each framebuffer is registered,
while both guards are used before any increment.
Current flow:
lynxfb_pci_probe()
sm750fb_setup() // fb_count is 0
for each fb:
sm750fb_framebuffer_alloc()
lynxfb_set_fbinfo()
sm750fb_set_drv() // fb_count is 0 or 1
register_framebuffer()
sm750_dev->fb_count++; // fb_count is incremented
Thus even if `dualview=1` parameter is passed down to the driver,
fb_count is never > 1 at either check, so dualview dataflows are
not selected and crtc->vidmem_size is never halved.
Use `g_dualview` global variable instead of fb_count > 1 to correctly
enable dualview capabilities.
Fixes: a3f92cc94c61 ("staging: sm750fb: replace dual member of sm750_dev with fb_count")
Signed-off-by: Ahmet Sezgin Duran <ahmet@sezginduran.net>
Link: https://patch.msgid.link/20260521204425.82627-1-ahmet@sezginduran.net
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/staging/sm750fb/sm750.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/staging/sm750fb/sm750.c b/drivers/staging/sm750fb/sm750.c
index 4f78fcfa52e10..676ef44577248 100644
--- a/drivers/staging/sm750fb/sm750.c
+++ b/drivers/staging/sm750fb/sm750.c
@@ -603,7 +603,7 @@ static int sm750fb_set_drv(struct lynxfb_par *par)
crtc = &par->crtc;
crtc->vidmem_size = sm750_dev->vidmem_size;
- if (sm750_dev->fb_count > 1)
+ if (g_dualview)
crtc->vidmem_size >>= 1;
/* setup crtc and output member */
@@ -968,7 +968,7 @@ static void sm750fb_setup(struct sm750_dev *sm750_dev, char *src)
NO_PARAM:
if (sm750_dev->revid != SM750LE_REVISION_ID) {
- if (sm750_dev->fb_count > 1) {
+ if (g_dualview) {
if (swap)
sm750_dev->dataflow = sm750_dual_swap;
else
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0227/1518] staging: sm750fb: Add missing Kconfig dependency
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (225 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0226/1518] staging: sm750fb: gate dualview dataflow using g_dualview Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0228/1518] greybus: audio: bound the topology section sizes against the fetched size Greg Kroah-Hartman
` (771 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Rong Zhang, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rong Zhang <i@rong.moe>
[ Upstream commit da8fd33e7d6af4c069668c2d42234b969f706885 ]
The sm750 frame buffer driver depends on FB_IOMEM_FOPS, but its Kconfig
somehow misses it.
Fix it by making FB_SM750 select FB_IOMEM_FOPS, as other frame buffer
drivers do.
Fixes: dc0ad215e5d8 ("staging/sm750fb: Initialize fb_ops with fbdev macros")
Signed-off-by: Rong Zhang <i@rong.moe>
Link: https://patch.msgid.link/20260603-sm750-fb-iomem-kconfig-v1-1-7f6a3046cce2@rong.moe
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/staging/sm750fb/Kconfig | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/staging/sm750fb/Kconfig b/drivers/staging/sm750fb/Kconfig
index 08bcccdd0f1c4..25fe422f55f2c 100644
--- a/drivers/staging/sm750fb/Kconfig
+++ b/drivers/staging/sm750fb/Kconfig
@@ -6,6 +6,7 @@ config FB_SM750
select FB_CFB_FILLRECT
select FB_CFB_COPYAREA
select FB_CFB_IMAGEBLIT
+ select FB_IOMEM_FOPS
help
Frame buffer driver for the Silicon Motion SM750 chip
with 2D acceleration and dual head support.
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0228/1518] greybus: audio: bound the topology section sizes against the fetched size
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (226 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0227/1518] staging: sm750fb: Add missing Kconfig dependency Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0229/1518] staging: fbtft: Use sysfs_emit_at() to print to sysfs file Greg Kroah-Hartman
` (770 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Bryam Vargas, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bryam Vargas <hexlabsecurity@proton.me>
[ Upstream commit 33d8c7b794d2a30637c9d3fcb478f1d3222bef1e ]
gb_audio_gb_get_topology() fetches a topology blob of a module-supplied
size, and gbaudio_tplg_parse_data() then walks it by adding the
module-supplied size_dais, size_controls and size_widgets fields to
form the control, widget and route section offsets. Those le32 sizes
are never checked against the fetched blob, so a module reporting a
small topology size but large section sizes makes the offsets point
past the allocation, and parsing reads out of bounds.
Reject a topology whose section sizes do not fit within the fetched
size before it is parsed.
Fixes: 184992e305f1 ("greybus: audio: Add Greybus Audio Device Class Protocol helper routines")
Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me>
Link: https://patch.msgid.link/20260616-b4-disp-4352e8b0-v1-1-3e09f62e0ad5@proton.me
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/staging/greybus/audio_gb.c | 13 +++++++++++++
1 file changed, 13 insertions(+)
diff --git a/drivers/staging/greybus/audio_gb.c b/drivers/staging/greybus/audio_gb.c
index 9d8994fdb41a2..144591f1a5128 100644
--- a/drivers/staging/greybus/audio_gb.c
+++ b/drivers/staging/greybus/audio_gb.c
@@ -37,6 +37,19 @@ int gb_audio_gb_get_topology(struct gb_connection *connection,
return ret;
}
+ /*
+ * The size_* fields are supplied by the module and are used by
+ * gbaudio_tplg_parse_data() to compute offsets into the blob; make
+ * sure the sections fit within the fetched topology, so walking it
+ * cannot read out of bounds.
+ */
+ if ((u64)le32_to_cpu(topo->size_dais) + le32_to_cpu(topo->size_controls) +
+ le32_to_cpu(topo->size_widgets) + le32_to_cpu(topo->size_routes) >
+ size - sizeof(*topo)) {
+ kfree(topo);
+ return -EINVAL;
+ }
+
*topology = topo;
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0229/1518] staging: fbtft: Use sysfs_emit_at() to print to sysfs file
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (227 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0228/1518] greybus: audio: bound the topology section sizes against the fetched size Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0230/1518] staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown Greg Kroah-Hartman
` (769 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dan Carpenter, Andy Shevchenko,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dan Carpenter <error27@gmail.com>
[ Upstream commit 221192a784c25e28b489a7e75fabf59be4f63d57 ]
This scnprintf() uses the wrong limit. It should be "PAGE_SIZE - len"
instead of just PAGE_SIZE. We're not going to hit the limit in real
life since we are printing at most FBTFT_GAMMA_MAX_VALUES_TOTAL (128)
u32 values, however, it's still worth fixing.
Use sysfs_emit_at() to fix this since this is a sysfs file.
Fixes: c296d5f9957c ("staging: fbtft: core support")
Signed-off-by: Dan Carpenter <error27@gmail.com>
Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com>
Link: https://patch.msgid.link/ah_Y_Y2RtqeGxchF@stanley.mountain
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/staging/fbtft/fbtft-sysfs.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/staging/fbtft/fbtft-sysfs.c b/drivers/staging/fbtft/fbtft-sysfs.c
index e45c90a03a903..7bd6cbf2f1e56 100644
--- a/drivers/staging/fbtft/fbtft-sysfs.c
+++ b/drivers/staging/fbtft/fbtft-sysfs.c
@@ -98,7 +98,7 @@ sprintf_gamma(struct fbtft_par *par, u32 *curves, char *buf)
mutex_lock(&par->gamma.lock);
for (i = 0; i < par->gamma.num_curves; i++) {
for (j = 0; j < par->gamma.num_values; j++)
- len += scnprintf(&buf[len], PAGE_SIZE,
+ len += sysfs_emit_at(buf, len,
"%04x ", curves[i * par->gamma.num_values + j]);
buf[len - 1] = '\n';
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0230/1518] staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (228 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0229/1518] staging: fbtft: Use sysfs_emit_at() to print to sysfs file Greg Kroah-Hartman
@ 2026-09-12 6:39 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0231/1518] staging: octeon: fix free_irq dev_id mismatch in cvm_oct_rx_shutdown Greg Kroah-Hartman
` (768 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:39 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Ayush Mukkanwar,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ayush Mukkanwar <ayushmukkanwar@gmail.com>
[ Upstream commit b9af44b0d20b2247c4eb0ea5cfca907d643eea50 ]
The TX cleanup tasklet can be scheduled by the watchdog IRQ handler
to execute cvm_oct_tx_do_cleanup. There can be a pending tasklet in
the queue which might run after the cvm_oct_remove() frees net_device
structures, causing a use-after-free in cvm_oct_tx_do_cleanup() as it
iterates cvm_oct_device[] which is an array of netdevice pointers.
Add tasklet_kill() after free_irq() to ensure the tasklet is no longer
scheduled or running before teardown proceeds.
Fixes: 4898c560103f ("Staging: Octeon: Free transmit SKBs in a timely manner")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260511150931.93382-1-ayushmukkanwar%40gmail.com
Signed-off-by: Ayush Mukkanwar <ayushmukkanwar@gmail.com>
Link: https://patch.msgid.link/20260615172734.42038-1-ayushmukkanwar@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/staging/octeon/ethernet-tx.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/staging/octeon/ethernet-tx.c b/drivers/staging/octeon/ethernet-tx.c
index f5bbedac6a653..1b30fe1bcf43b 100644
--- a/drivers/staging/octeon/ethernet-tx.c
+++ b/drivers/staging/octeon/ethernet-tx.c
@@ -670,4 +670,6 @@ void cvm_oct_tx_shutdown(void)
{
/* Free the interrupt handler */
free_irq(OCTEON_IRQ_TIMER1, cvm_oct_device);
+
+ tasklet_kill(&cvm_oct_tx_cleanup_tasklet);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0231/1518] staging: octeon: fix free_irq dev_id mismatch in cvm_oct_rx_shutdown
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (229 preceding siblings ...)
2026-09-12 6:39 ` [PATCH 6.18 0230/1518] staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0232/1518] staging: octeon: ethernet-mem: replace pr_warn with dev_warn in free functions Greg Kroah-Hartman
` (767 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yuvraj Singh Chauhan, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuvraj Singh Chauhan <ysinghcin@gmail.com>
[ Upstream commit 41db5b76eeb4cc11a1097384caba7cfc659f7293 ]
In cvm_oct_rx_initialize(), request_irq() is called with
&oct_rx_group[i].napi as the dev_id:
request_irq(oct_rx_group[i].irq, cvm_oct_do_interrupt, 0, "Ethernet",
&oct_rx_group[i].napi);
However, cvm_oct_rx_shutdown() passes cvm_oct_device (an array of
struct net_device pointers) as the dev_id to free_irq():
free_irq(oct_rx_group[i].irq, cvm_oct_device);
Since __free_irq() matches the action to remove by comparing
dev_id pointers, the mismatched cookie means the IRQ handler is
never found, triggering a WARN and leaving the IRQ line permanently
allocated. This prevents proper driver cleanup on module removal.
Fix the mismatch by passing &oct_rx_group[i].napi as the dev_id
to free_irq(), matching what was used during request_irq().
Signed-off-by: Yuvraj Singh Chauhan <ysinghcin@gmail.com>
Link: https://patch.msgid.link/20260212171903.1417804-1-ysinghcin@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Stable-dep-of: c0a9a8586a63 ("staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/staging/octeon/ethernet-rx.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/staging/octeon/ethernet-rx.c b/drivers/staging/octeon/ethernet-rx.c
index 965330eec80a8..d0b43d50b83ce 100644
--- a/drivers/staging/octeon/ethernet-rx.c
+++ b/drivers/staging/octeon/ethernet-rx.c
@@ -535,7 +535,7 @@ void cvm_oct_rx_shutdown(void)
cvmx_write_csr(CVMX_POW_WQ_INT_THRX(i), 0);
/* Free the interrupt handler */
- free_irq(oct_rx_group[i].irq, cvm_oct_device);
+ free_irq(oct_rx_group[i].irq, &oct_rx_group[i].napi);
netif_napi_del(&oct_rx_group[i].napi);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0232/1518] staging: octeon: ethernet-mem: replace pr_warn with dev_warn in free functions
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (230 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0231/1518] staging: octeon: fix free_irq dev_id mismatch in cvm_oct_rx_shutdown Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0233/1518] staging: octeon: replace pr_warn with dev_warn in fill and rx paths Greg Kroah-Hartman
` (766 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ayush Mukkanwar, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ayush Mukkanwar <ayushmukkanwar@gmail.com>
[ Upstream commit be5e8d5f61b31105e0ed7f51cd591653aea5054f ]
Add struct platform_device parameter to cvm_oct_free_hw_skbuff,
cvm_oct_free_hw_memory and cvm_oct_mem_empty_fpa. Replace pr_warn
calls with dev_warn, using &pdev->dev for device-aware logging.
Signed-off-by: Ayush Mukkanwar <ayushmukkanwar@gmail.com>
Link: https://patch.msgid.link/20260511150931.93382-2-ayushmukkanwar@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Stable-dep-of: c0a9a8586a63 ("staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/staging/octeon/ethernet-mem.c | 31 ++++++++++++++++-----------
drivers/staging/octeon/ethernet-mem.h | 5 ++++-
drivers/staging/octeon/ethernet.c | 6 +++---
3 files changed, 25 insertions(+), 17 deletions(-)
diff --git a/drivers/staging/octeon/ethernet-mem.c b/drivers/staging/octeon/ethernet-mem.c
index 532594957ebcf..af79b2bdac278 100644
--- a/drivers/staging/octeon/ethernet-mem.c
+++ b/drivers/staging/octeon/ethernet-mem.c
@@ -5,6 +5,7 @@
* Copyright (c) 2003-2010 Cavium Networks
*/
+#include <linux/platform_device.h>
#include <linux/kernel.h>
#include <linux/netdevice.h>
#include <linux/slab.h>
@@ -40,11 +41,13 @@ static int cvm_oct_fill_hw_skbuff(int pool, int size, int elements)
/**
* cvm_oct_free_hw_skbuff- free hardware pool skbuffs
+ * @pdev: Platform device for logging
* @pool: Pool to allocate an skbuff for
* @size: Size of the buffer needed for the pool
* @elements: Number of buffers to allocate
*/
-static void cvm_oct_free_hw_skbuff(int pool, int size, int elements)
+static void cvm_oct_free_hw_skbuff(struct platform_device *pdev,
+ int pool, int size, int elements)
{
char *memory;
@@ -59,11 +62,11 @@ static void cvm_oct_free_hw_skbuff(int pool, int size, int elements)
} while (memory);
if (elements < 0)
- pr_warn("Freeing of pool %u had too many skbuffs (%d)\n",
- pool, elements);
+ dev_warn(&pdev->dev, "Freeing of pool %u had too many skbuffs (%d)\n",
+ pool, elements);
else if (elements > 0)
- pr_warn("Freeing of pool %u is missing %d skbuffs\n",
- pool, elements);
+ dev_warn(&pdev->dev, "Freeing of pool %u is missing %d skbuffs\n",
+ pool, elements);
}
/**
@@ -107,11 +110,13 @@ static int cvm_oct_fill_hw_memory(int pool, int size, int elements)
/**
* cvm_oct_free_hw_memory - Free memory allocated by cvm_oct_fill_hw_memory
+ * @pdev: Platform device for logging
* @pool: FPA pool to free
* @size: Size of each buffer in the pool
* @elements: Number of buffers that should be in the pool
*/
-static void cvm_oct_free_hw_memory(int pool, int size, int elements)
+static void cvm_oct_free_hw_memory(struct platform_device *pdev,
+ int pool, int size, int elements)
{
char *memory;
char *fpa;
@@ -127,11 +132,11 @@ static void cvm_oct_free_hw_memory(int pool, int size, int elements)
} while (fpa);
if (elements < 0)
- pr_warn("Freeing of pool %u had too many buffers (%d)\n",
- pool, elements);
+ dev_warn(&pdev->dev, "Freeing of pool %u had too many buffers (%d)\n",
+ pool, elements);
else if (elements > 0)
- pr_warn("Warning: Freeing of pool %u is missing %d buffers\n",
- pool, elements);
+ dev_warn(&pdev->dev, "Freeing of pool %u is missing %d buffers\n",
+ pool, elements);
}
int cvm_oct_mem_fill_fpa(int pool, int size, int elements)
@@ -145,10 +150,10 @@ int cvm_oct_mem_fill_fpa(int pool, int size, int elements)
return freed;
}
-void cvm_oct_mem_empty_fpa(int pool, int size, int elements)
+void cvm_oct_mem_empty_fpa(struct platform_device *pdev, int pool, int size, int elements)
{
if (pool == CVMX_FPA_PACKET_POOL)
- cvm_oct_free_hw_skbuff(pool, size, elements);
+ cvm_oct_free_hw_skbuff(pdev, pool, size, elements);
else
- cvm_oct_free_hw_memory(pool, size, elements);
+ cvm_oct_free_hw_memory(pdev, pool, size, elements);
}
diff --git a/drivers/staging/octeon/ethernet-mem.h b/drivers/staging/octeon/ethernet-mem.h
index 692dcdb7154da..ff10ba4525ee8 100644
--- a/drivers/staging/octeon/ethernet-mem.h
+++ b/drivers/staging/octeon/ethernet-mem.h
@@ -6,4 +6,7 @@
*/
int cvm_oct_mem_fill_fpa(int pool, int size, int elements);
-void cvm_oct_mem_empty_fpa(int pool, int size, int elements);
+struct platform_device;
+
+void cvm_oct_mem_empty_fpa(struct platform_device *pdev, int pool, int size,
+ int elements);
diff --git a/drivers/staging/octeon/ethernet.c b/drivers/staging/octeon/ethernet.c
index eadb74fc14c8d..badf5ceaf5b48 100644
--- a/drivers/staging/octeon/ethernet.c
+++ b/drivers/staging/octeon/ethernet.c
@@ -958,12 +958,12 @@ static void cvm_oct_remove(struct platform_device *pdev)
cvmx_ipd_free_ptr();
/* Free the HW pools */
- cvm_oct_mem_empty_fpa(CVMX_FPA_PACKET_POOL, CVMX_FPA_PACKET_POOL_SIZE,
+ cvm_oct_mem_empty_fpa(pdev, CVMX_FPA_PACKET_POOL, CVMX_FPA_PACKET_POOL_SIZE,
num_packet_buffers);
- cvm_oct_mem_empty_fpa(CVMX_FPA_WQE_POOL, CVMX_FPA_WQE_POOL_SIZE,
+ cvm_oct_mem_empty_fpa(pdev, CVMX_FPA_WQE_POOL, CVMX_FPA_WQE_POOL_SIZE,
num_packet_buffers);
if (CVMX_FPA_OUTPUT_BUFFER_POOL != CVMX_FPA_PACKET_POOL)
- cvm_oct_mem_empty_fpa(CVMX_FPA_OUTPUT_BUFFER_POOL,
+ cvm_oct_mem_empty_fpa(pdev, CVMX_FPA_OUTPUT_BUFFER_POOL,
CVMX_FPA_OUTPUT_BUFFER_POOL_SIZE, 128);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0233/1518] staging: octeon: replace pr_warn with dev_warn in fill and rx paths
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (231 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0232/1518] staging: octeon: ethernet-mem: replace pr_warn with dev_warn in free functions Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0234/1518] staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown Greg Kroah-Hartman
` (765 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ayush Mukkanwar, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ayush Mukkanwar <ayushmukkanwar@gmail.com>
[ Upstream commit 2191a8dfd1f5a3091e9f388899beb137686c6532 ]
Add struct platform_device parameter to cvm_oct_fill_hw_memory,
cvm_oct_mem_fill_fpa, cvm_oct_rx_refill_pool and
cvm_oct_rx_initialize to support device-aware logging. Replace
pr_warn with dev_warn using &pdev->dev.
To avoid passing these parameters through global state, introduce
struct octeon_ethernet_platform to hold per-device state including
the rx_refill_work and the oct_rx_group array. This ensures all
receive group state and workers are correctly associated with the
platform device.
Define struct oct_rx_group and struct octeon_ethernet_platform in
octeon-ethernet.h so they are shared across compilation units.
Signed-off-by: Ayush Mukkanwar <ayushmukkanwar@gmail.com>
Link: https://patch.msgid.link/20260511150931.93382-4-ayushmukkanwar@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Stable-dep-of: c0a9a8586a63 ("staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/staging/octeon/ethernet-mem.c | 12 +++---
drivers/staging/octeon/ethernet-mem.h | 3 +-
drivers/staging/octeon/ethernet-rx.c | 49 ++++++++++++------------
drivers/staging/octeon/ethernet-rx.h | 11 ++++--
drivers/staging/octeon/ethernet.c | 37 +++++++++++-------
drivers/staging/octeon/octeon-ethernet.h | 14 +++++++
6 files changed, 78 insertions(+), 48 deletions(-)
diff --git a/drivers/staging/octeon/ethernet-mem.c b/drivers/staging/octeon/ethernet-mem.c
index af79b2bdac278..68c3ef984e565 100644
--- a/drivers/staging/octeon/ethernet-mem.c
+++ b/drivers/staging/octeon/ethernet-mem.c
@@ -71,13 +71,15 @@ static void cvm_oct_free_hw_skbuff(struct platform_device *pdev,
/**
* cvm_oct_fill_hw_memory - fill a hardware pool with memory.
+ * @pdev: Platform device for logging
* @pool: Pool to populate
* @size: Size of each buffer in the pool
* @elements: Number of buffers to allocate
*
* Returns the actual number of buffers allocated.
*/
-static int cvm_oct_fill_hw_memory(int pool, int size, int elements)
+static int cvm_oct_fill_hw_memory(struct platform_device *pdev, int pool, int size,
+ int elements)
{
char *memory;
char *fpa;
@@ -96,8 +98,8 @@ static int cvm_oct_fill_hw_memory(int pool, int size, int elements)
*/
memory = kmalloc(size + 256, GFP_ATOMIC);
if (unlikely(!memory)) {
- pr_warn("Unable to allocate %u bytes for FPA pool %d\n",
- elements * size, pool);
+ dev_warn(&pdev->dev, "Unable to allocate %u bytes for FPA pool %d\n",
+ elements * size, pool);
break;
}
fpa = (char *)(((unsigned long)memory + 256) & ~0x7fUL);
@@ -139,14 +141,14 @@ static void cvm_oct_free_hw_memory(struct platform_device *pdev,
pool, elements);
}
-int cvm_oct_mem_fill_fpa(int pool, int size, int elements)
+int cvm_oct_mem_fill_fpa(struct platform_device *pdev, int pool, int size, int elements)
{
int freed;
if (pool == CVMX_FPA_PACKET_POOL)
freed = cvm_oct_fill_hw_skbuff(pool, size, elements);
else
- freed = cvm_oct_fill_hw_memory(pool, size, elements);
+ freed = cvm_oct_fill_hw_memory(pdev, pool, size, elements);
return freed;
}
diff --git a/drivers/staging/octeon/ethernet-mem.h b/drivers/staging/octeon/ethernet-mem.h
index ff10ba4525ee8..9279bb0de2db4 100644
--- a/drivers/staging/octeon/ethernet-mem.h
+++ b/drivers/staging/octeon/ethernet-mem.h
@@ -5,8 +5,9 @@
* Copyright (c) 2003-2007 Cavium Networks
*/
-int cvm_oct_mem_fill_fpa(int pool, int size, int elements);
struct platform_device;
+int cvm_oct_mem_fill_fpa(struct platform_device *pdev, int pool, int size,
+ int elements);
void cvm_oct_mem_empty_fpa(struct platform_device *pdev, int pool, int size,
int elements);
diff --git a/drivers/staging/octeon/ethernet-rx.c b/drivers/staging/octeon/ethernet-rx.c
index d0b43d50b83ce..cd36b5ba6f6c2 100644
--- a/drivers/staging/octeon/ethernet-rx.c
+++ b/drivers/staging/octeon/ethernet-rx.c
@@ -5,6 +5,7 @@
* Copyright (c) 2003-2010 Cavium Networks
*/
+#include <linux/platform_device.h>
#include <linux/module.h>
#include <linux/kernel.h>
#include <linux/cache.h>
@@ -31,12 +32,6 @@
static atomic_t oct_rx_ready = ATOMIC_INIT(0);
-static struct oct_rx_group {
- int irq;
- int group;
- struct napi_struct napi;
-} oct_rx_group[16];
-
/**
* cvm_oct_do_interrupt - interrupt handler.
* @irq: Interrupt number.
@@ -397,7 +392,7 @@ static int cvm_oct_poll(struct oct_rx_group *rx_group, int budget)
/* Restore the scratch area */
cvmx_scratch_write64(CVMX_SCR_SCRATCH, old_scratch);
}
- cvm_oct_rx_refill_pool(0);
+ cvm_oct_rx_refill_pool(rx_group->pdev, 0);
return rx_count;
}
@@ -434,24 +429,28 @@ static int cvm_oct_napi_poll(struct napi_struct *napi, int budget)
*/
void cvm_oct_poll_controller(struct net_device *dev)
{
+ struct platform_device *pdev = to_platform_device(dev->dev.parent);
+ struct octeon_ethernet_platform *plat = platform_get_drvdata(pdev);
int i;
if (!atomic_read(&oct_rx_ready))
return;
- for (i = 0; i < ARRAY_SIZE(oct_rx_group); i++) {
+ for (i = 0; i < ARRAY_SIZE(plat->rx_group); i++) {
if (!(pow_receive_groups & BIT(i)))
continue;
- cvm_oct_poll(&oct_rx_group[i], 16);
+ cvm_oct_poll(&plat->rx_group[i], 16);
}
}
#endif
-void cvm_oct_rx_initialize(void)
+void cvm_oct_rx_initialize(struct platform_device *pdev)
{
int i;
struct net_device *dev_for_napi = NULL;
+ struct octeon_ethernet_platform *plat = platform_get_drvdata(pdev);
+ struct oct_rx_group *rx_group = plat->rx_group;
for (i = 0; i < TOTAL_NUMBER_OF_PORTS; i++) {
if (cvm_oct_device[i]) {
@@ -463,27 +462,28 @@ void cvm_oct_rx_initialize(void)
if (!dev_for_napi)
panic("No net_devices were allocated.");
- for (i = 0; i < ARRAY_SIZE(oct_rx_group); i++) {
+ for (i = 0; i < ARRAY_SIZE(plat->rx_group); i++) {
int ret;
if (!(pow_receive_groups & BIT(i)))
continue;
- netif_napi_add_weight(dev_for_napi, &oct_rx_group[i].napi,
+ netif_napi_add_weight(dev_for_napi, &rx_group[i].napi,
cvm_oct_napi_poll, rx_napi_weight);
- napi_enable(&oct_rx_group[i].napi);
+ napi_enable(&rx_group[i].napi);
- oct_rx_group[i].irq = OCTEON_IRQ_WORKQ0 + i;
- oct_rx_group[i].group = i;
+ rx_group[i].irq = OCTEON_IRQ_WORKQ0 + i;
+ rx_group[i].group = i;
+ rx_group[i].pdev = pdev;
/* Register an IRQ handler to receive POW interrupts */
- ret = request_irq(oct_rx_group[i].irq, cvm_oct_do_interrupt, 0,
- "Ethernet", &oct_rx_group[i].napi);
+ ret = request_irq(rx_group[i].irq, cvm_oct_do_interrupt, 0,
+ "Ethernet", &rx_group[i].napi);
if (ret)
panic("Could not acquire Ethernet IRQ %d\n",
- oct_rx_group[i].irq);
+ rx_group[i].irq);
- disable_irq_nosync(oct_rx_group[i].irq);
+ disable_irq_nosync(rx_group[i].irq);
/* Enable POW interrupt when our port has at least one packet */
if (OCTEON_IS_MODEL(OCTEON_CN68XX)) {
@@ -515,16 +515,17 @@ void cvm_oct_rx_initialize(void)
/* Schedule NAPI now. This will indirectly enable the
* interrupt.
*/
- napi_schedule(&oct_rx_group[i].napi);
+ napi_schedule(&rx_group[i].napi);
}
atomic_inc(&oct_rx_ready);
}
-void cvm_oct_rx_shutdown(void)
+void cvm_oct_rx_shutdown(struct platform_device *pdev)
{
+ struct octeon_ethernet_platform *plat = platform_get_drvdata(pdev);
int i;
- for (i = 0; i < ARRAY_SIZE(oct_rx_group); i++) {
+ for (i = 0; i < ARRAY_SIZE(plat->rx_group); i++) {
if (!(pow_receive_groups & BIT(i)))
continue;
@@ -535,8 +536,8 @@ void cvm_oct_rx_shutdown(void)
cvmx_write_csr(CVMX_POW_WQ_INT_THRX(i), 0);
/* Free the interrupt handler */
- free_irq(oct_rx_group[i].irq, &oct_rx_group[i].napi);
+ free_irq(plat->rx_group[i].irq, &plat->rx_group[i].napi);
- netif_napi_del(&oct_rx_group[i].napi);
+ netif_napi_del(&plat->rx_group[i].napi);
}
}
diff --git a/drivers/staging/octeon/ethernet-rx.h b/drivers/staging/octeon/ethernet-rx.h
index ff6482fa20d69..6093694326cb6 100644
--- a/drivers/staging/octeon/ethernet-rx.h
+++ b/drivers/staging/octeon/ethernet-rx.h
@@ -5,11 +5,14 @@
* Copyright (c) 2003-2007 Cavium Networks
*/
+struct platform_device;
+
void cvm_oct_poll_controller(struct net_device *dev);
-void cvm_oct_rx_initialize(void);
-void cvm_oct_rx_shutdown(void);
+void cvm_oct_rx_initialize(struct platform_device *pdev);
+void cvm_oct_rx_shutdown(struct platform_device *pdev);
-static inline void cvm_oct_rx_refill_pool(int fill_threshold)
+static inline void cvm_oct_rx_refill_pool(struct platform_device *pdev,
+ int fill_threshold)
{
int number_to_free;
int num_freed;
@@ -20,7 +23,7 @@ static inline void cvm_oct_rx_refill_pool(int fill_threshold)
if (number_to_free > fill_threshold) {
cvmx_fau_atomic_add32(FAU_NUM_PACKET_BUFFERS_TO_FREE,
-number_to_free);
- num_freed = cvm_oct_mem_fill_fpa(CVMX_FPA_PACKET_POOL,
+ num_freed = cvm_oct_mem_fill_fpa(pdev, CVMX_FPA_PACKET_POOL,
CVMX_FPA_PACKET_POOL_SIZE,
number_to_free);
if (num_freed != number_to_free) {
diff --git a/drivers/staging/octeon/ethernet.c b/drivers/staging/octeon/ethernet.c
index badf5ceaf5b48..0a24c62ae32bf 100644
--- a/drivers/staging/octeon/ethernet.c
+++ b/drivers/staging/octeon/ethernet.c
@@ -104,11 +104,10 @@ struct net_device *cvm_oct_device[TOTAL_NUMBER_OF_PORTS];
u64 cvm_oct_tx_poll_interval;
-static void cvm_oct_rx_refill_worker(struct work_struct *work);
-static DECLARE_DELAYED_WORK(cvm_oct_rx_refill_work, cvm_oct_rx_refill_worker);
-
static void cvm_oct_rx_refill_worker(struct work_struct *work)
{
+ struct octeon_ethernet_platform *plat = container_of(work,
+ struct octeon_ethernet_platform, rx_refill_work.work);
/*
* FPA 0 may have been drained, try to refill it if we need
* more than num_packet_buffers / 2, otherwise normal receive
@@ -116,10 +115,10 @@ static void cvm_oct_rx_refill_worker(struct work_struct *work)
* could be received so cvm_oct_napi_poll would never be
* invoked to do the refill.
*/
- cvm_oct_rx_refill_pool(num_packet_buffers / 2);
+ cvm_oct_rx_refill_pool(plat->pdev, num_packet_buffers / 2);
if (!atomic_read(&cvm_oct_poll_queue_stopping))
- schedule_delayed_work(&cvm_oct_rx_refill_work, HZ);
+ schedule_delayed_work(&plat->rx_refill_work, HZ);
}
static void cvm_oct_periodic_worker(struct work_struct *work)
@@ -138,16 +137,16 @@ static void cvm_oct_periodic_worker(struct work_struct *work)
schedule_delayed_work(&priv->port_periodic_work, HZ);
}
-static void cvm_oct_configure_common_hw(void)
+static void cvm_oct_configure_common_hw(struct platform_device *pdev)
{
/* Setup the FPA */
cvmx_fpa_enable();
- cvm_oct_mem_fill_fpa(CVMX_FPA_PACKET_POOL, CVMX_FPA_PACKET_POOL_SIZE,
+ cvm_oct_mem_fill_fpa(pdev, CVMX_FPA_PACKET_POOL, CVMX_FPA_PACKET_POOL_SIZE,
num_packet_buffers);
- cvm_oct_mem_fill_fpa(CVMX_FPA_WQE_POOL, CVMX_FPA_WQE_POOL_SIZE,
+ cvm_oct_mem_fill_fpa(pdev, CVMX_FPA_WQE_POOL, CVMX_FPA_WQE_POOL_SIZE,
num_packet_buffers);
if (CVMX_FPA_OUTPUT_BUFFER_POOL != CVMX_FPA_PACKET_POOL)
- cvm_oct_mem_fill_fpa(CVMX_FPA_OUTPUT_BUFFER_POOL,
+ cvm_oct_mem_fill_fpa(pdev, CVMX_FPA_OUTPUT_BUFFER_POOL,
CVMX_FPA_OUTPUT_BUFFER_POOL_SIZE, 1024);
#ifdef __LITTLE_ENDIAN
@@ -678,6 +677,15 @@ static int cvm_oct_probe(struct platform_device *pdev)
int qos;
struct device_node *pip;
int mtu_overhead = ETH_HLEN + ETH_FCS_LEN;
+ struct octeon_ethernet_platform *plat;
+
+ plat = devm_kzalloc(&pdev->dev, sizeof(*plat), GFP_KERNEL);
+ if (!plat)
+ return -ENOMEM;
+
+ plat->pdev = pdev;
+ INIT_DELAYED_WORK(&plat->rx_refill_work, cvm_oct_rx_refill_worker);
+ platform_set_drvdata(pdev, plat);
#if IS_ENABLED(CONFIG_VLAN_8021Q)
mtu_overhead += VLAN_HLEN;
@@ -689,7 +697,7 @@ static int cvm_oct_probe(struct platform_device *pdev)
return -EINVAL;
}
- cvm_oct_configure_common_hw();
+ cvm_oct_configure_common_hw(pdev);
cvmx_helper_initialize_packet_io_global();
@@ -912,28 +920,29 @@ static int cvm_oct_probe(struct platform_device *pdev)
}
cvm_oct_tx_initialize();
- cvm_oct_rx_initialize();
+ cvm_oct_rx_initialize(pdev);
/*
* 150 uS: about 10 1500-byte packets at 1GE.
*/
cvm_oct_tx_poll_interval = 150 * (octeon_get_clock_rate() / 1000000);
- schedule_delayed_work(&cvm_oct_rx_refill_work, HZ);
+ schedule_delayed_work(&plat->rx_refill_work, HZ);
return 0;
}
static void cvm_oct_remove(struct platform_device *pdev)
{
+ struct octeon_ethernet_platform *plat = platform_get_drvdata(pdev);
int port;
cvmx_ipd_disable();
atomic_inc_return(&cvm_oct_poll_queue_stopping);
- cancel_delayed_work_sync(&cvm_oct_rx_refill_work);
+ cancel_delayed_work_sync(&plat->rx_refill_work);
- cvm_oct_rx_shutdown();
+ cvm_oct_rx_shutdown(pdev);
cvm_oct_tx_shutdown();
cvmx_pko_disable();
diff --git a/drivers/staging/octeon/octeon-ethernet.h b/drivers/staging/octeon/octeon-ethernet.h
index a6140705706f4..0ac430db1e6eb 100644
--- a/drivers/staging/octeon/octeon-ethernet.h
+++ b/drivers/staging/octeon/octeon-ethernet.h
@@ -11,6 +11,7 @@
#ifndef OCTEON_ETHERNET_H
#define OCTEON_ETHERNET_H
+#include <linux/netdevice.h>
#include <linux/of.h>
#include <linux/phy.h>
@@ -74,6 +75,19 @@ struct octeon_ethernet {
struct device_node *of_node;
};
+struct oct_rx_group {
+ int irq;
+ int group;
+ struct napi_struct napi;
+ struct platform_device *pdev;
+};
+
+struct octeon_ethernet_platform {
+ struct platform_device *pdev;
+ struct delayed_work rx_refill_work;
+ struct oct_rx_group rx_group[16];
+};
+
int cvm_oct_free_work(void *work_queue_entry);
int cvm_oct_rgmii_open(struct net_device *dev);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0234/1518] staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (232 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0233/1518] staging: octeon: replace pr_warn with dev_warn in fill and rx paths Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0235/1518] staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() Greg Kroah-Hartman
` (764 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Ayush Mukkanwar,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ayush Mukkanwar <ayushmukkanwar@gmail.com>
[ Upstream commit c0a9a8586a63fda49e61a6b83360feac2a60d898 ]
cvm_oct_rx_shutdown calls free_irq and netif_napi_del without
disabling the napi instance first. As the free_irq only waits
for completion of hard interrupt handlers, the napi poll
function could still be active. If cvm_oct_remove proceeds to
free the plat structure (which holds the NAPI instances), the
active poll function will access freed memory, resulting in a
use-after-free crash.
Fixes: 3368c784bcf7 ("Staging: Octeon Ethernet: Convert to NAPI.")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260511150931.93382-1-ayushmukkanwar%40gmail.com
Signed-off-by: Ayush Mukkanwar <ayushmukkanwar@gmail.com>
Link: https://patch.msgid.link/20260615172734.42038-2-ayushmukkanwar@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/staging/octeon/ethernet-rx.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/staging/octeon/ethernet-rx.c b/drivers/staging/octeon/ethernet-rx.c
index cd36b5ba6f6c2..3e9d58d321560 100644
--- a/drivers/staging/octeon/ethernet-rx.c
+++ b/drivers/staging/octeon/ethernet-rx.c
@@ -535,6 +535,8 @@ void cvm_oct_rx_shutdown(struct platform_device *pdev)
else
cvmx_write_csr(CVMX_POW_WQ_INT_THRX(i), 0);
+ napi_disable(&plat->rx_group[i].napi);
+
/* Free the interrupt handler */
free_irq(plat->rx_group[i].irq, &plat->rx_group[i].napi);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0235/1518] staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (233 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0234/1518] staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0236/1518] ALSA: via82xx: Remove unreachable branch in snd_via686_pcm_pointer() Greg Kroah-Hartman
` (763 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zilin Guan, Dawei Feng,
Dan Carpenter, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dawei Feng <dawei.feng@seu.edu.cn>
[ Upstream commit 264676418b726baca7be49171e306b6aa05cceb0 ]
padapter->HalData is allocated via vzalloc(), but incorrectly freed
using kfree() in the rtw_sdio_if1_init() error path. Using kfree() to
release this vmalloc-backed buffer can lead to memory corruption.
Use rtw_hal_data_deinit() to pair the free correctly and free
HalData with vfree().
The bug was first flagged by an experimental static analysis tool we
are developing for kernel memory-management bugs. Manual inspection
confirms that the issue is still present in current mainline.
An x86_64 allyesconfig build showed no new warnings. As we do not have
suitable RTL8723BS SDIO hardware to test with, no runtime testing was
able to be performed.
Fixes: 554c0a3abf21 ("staging: Add rtl8723bs sdio wifi driver")
Signed-off-by: Zilin Guan <zilin@seu.edu.cn>
Signed-off-by: Dawei Feng <dawei.feng@seu.edu.cn>
Reviewed-by: Dan Carpenter <error27@gmail.com>
Link: https://patch.msgid.link/20260525091836.812565-1-dawei.feng@seu.edu.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/staging/rtl8723bs/os_dep/sdio_intf.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/staging/rtl8723bs/os_dep/sdio_intf.c b/drivers/staging/rtl8723bs/os_dep/sdio_intf.c
index 139ace51486d2..ae379e99736ad 100644
--- a/drivers/staging/rtl8723bs/os_dep/sdio_intf.c
+++ b/drivers/staging/rtl8723bs/os_dep/sdio_intf.c
@@ -307,8 +307,8 @@ static struct adapter *rtw_sdio_if1_init(struct dvobj_priv *dvobj, const struct
status = _SUCCESS;
free_hal_data:
- if (status != _SUCCESS && padapter->HalData)
- kfree(padapter->HalData);
+ if (status != _SUCCESS)
+ rtw_hal_data_deinit(padapter);
if (status != _SUCCESS) {
rtw_wdev_unregister(padapter->rtw_wdev);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0236/1518] ALSA: via82xx: Remove unreachable branch in snd_via686_pcm_pointer()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (234 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0235/1518] staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0237/1518] selftests/bpf: Fix memory leak in msg_alloc_iov error path Greg Kroah-Hartman
` (762 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Evgenii Burenchev, Takashi Iwai,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Evgenii Burenchev <evg28bur@yandex.ru>
[ Upstream commit cd3447e1b6425efd1704ed07f1f245c842927eb0 ]
The condition
if (count && size < count)
can never evaluate to true.
The VIA DMA count register is masked with 0x00ffffff before use, while
the DMA buffer size is limited to 0x00fffffe bytes. As a result, 'count'
can never exceed 'size', making the condition permanently false.
This branch has therefore been unreachable since the driver was
introduced. Remove the unreachable branch without changing runtime
behavior.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Evgenii Burenchev <evg28bur@yandex.ru>
Link: https://patch.msgid.link/20260706131638.15311-1-evg28bur@yandex.ru
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/pci/via82xx_modem.c | 26 ++++++++++----------------
1 file changed, 10 insertions(+), 16 deletions(-)
diff --git a/sound/pci/via82xx_modem.c b/sound/pci/via82xx_modem.c
index 6ce2cd88cda6c..605a3a0053d92 100644
--- a/sound/pci/via82xx_modem.c
+++ b/sound/pci/via82xx_modem.c
@@ -575,24 +575,18 @@ static inline unsigned int calc_linear_pos(struct via82xx_modem *chip,
viadev->bufsize2, viadev->idx_table[idx].offset,
viadev->idx_table[idx].size, count);
#endif
- if (count && size < count) {
+ if (! count)
+ /* bogus count 0 on the DMA boundary? */
+ res = viadev->idx_table[idx].offset;
+ else
+ /* count register returns full size
+ * when end of buffer is reached
+ */
+ res = viadev->idx_table[idx].offset + size;
+ if (check_invalid_pos(viadev, res)) {
dev_dbg(chip->card->dev,
- "invalid via82xx_cur_ptr, using last valid pointer\n");
+ "invalid via82xx_cur_ptr (2), using last valid pointer\n");
res = viadev->lastpos;
- } else {
- if (! count)
- /* bogus count 0 on the DMA boundary? */
- res = viadev->idx_table[idx].offset;
- else
- /* count register returns full size
- * when end of buffer is reached
- */
- res = viadev->idx_table[idx].offset + size;
- if (check_invalid_pos(viadev, res)) {
- dev_dbg(chip->card->dev,
- "invalid via82xx_cur_ptr (2), using last valid pointer\n");
- res = viadev->lastpos;
- }
}
}
viadev->lastpos = res; /* remember the last position */
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0237/1518] selftests/bpf: Fix memory leak in msg_alloc_iov error path
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (235 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0236/1518] ALSA: via82xx: Remove unreachable branch in snd_via686_pcm_pointer() Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0238/1518] selftests/bpf: Fix memory leak in msg_alloc_iov Greg Kroah-Hartman
` (761 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Malaya Kumar Rout, Emil Tsalapatis,
Kumar Kartikeya Dwivedi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Malaya Kumar Rout <malayarout91@gmail.com>
[ Upstream commit 0bebfaa39deadec21638f6fba553eae12627a26d ]
In msg_alloc_iov(), when calloc() fails for an individual iov_base
allocation, the error path frees all previously allocated iov_base
entries but fails to free the iov array itself that was allocated
with calloc() at the beginning of the function. This results in a
memory leak of the iov array.
Add free(iov) in the unwind_iov error path to ensure proper cleanup
of all allocated memory.
Fixes: 753fb2ee0934 ("bpf: sockmap, add msg_peek tests to test_sockmap")
Signed-off-by: Malaya Kumar Rout <malayarout91@gmail.com>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Link: https://lore.kernel.org/bpf/20260704122936.102394-1-malayarout91@gmail.com
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/bpf/test_sockmap.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/tools/testing/selftests/bpf/test_sockmap.c b/tools/testing/selftests/bpf/test_sockmap.c
index 76568db7a6642..6879918a8cafb 100644
--- a/tools/testing/selftests/bpf/test_sockmap.c
+++ b/tools/testing/selftests/bpf/test_sockmap.c
@@ -515,6 +515,7 @@ static int msg_alloc_iov(struct msghdr *msg,
unwind_iov:
for (i--; i >= 0 ; i--)
free(msg->msg_iov[i].iov_base);
+ free(iov);
return -ENOMEM;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0238/1518] selftests/bpf: Fix memory leak in msg_alloc_iov
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (236 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0237/1518] selftests/bpf: Fix memory leak in msg_alloc_iov error path Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0239/1518] selftests/lsm: Fix memory leak in attr_lsm_count Greg Kroah-Hartman
` (760 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Feng Yang, John Fastabend,
Kumar Kartikeya Dwivedi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Feng Yang <yangfeng@kylinos.cn>
[ Upstream commit 602701718649936eb287bf6c7ecf870ec54c6f71 ]
In the msg_alloc_iov function, the iov pointer is only assigned to
msg->msg_iov after all memory allocations complete successfully.
Therefore, when a calloc failure triggers the unwind_iov cleanup branch,
we should use the local variable iov instead of msg->msg_iov.
Fixes: 753fb2ee0934 ("bpf: sockmap, add msg_peek tests to test_sockmap")
Signed-off-by: Feng Yang <yangfeng@kylinos.cn>
Reviewed-by: John Fastabend <john.fastabend@gmail.com>
Link: https://lore.kernel.org/bpf/20260707081434.539327-1-yangfeng59949@163.com
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/bpf/test_sockmap.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/testing/selftests/bpf/test_sockmap.c b/tools/testing/selftests/bpf/test_sockmap.c
index 6879918a8cafb..f8b57f3c3f236 100644
--- a/tools/testing/selftests/bpf/test_sockmap.c
+++ b/tools/testing/selftests/bpf/test_sockmap.c
@@ -514,7 +514,7 @@ static int msg_alloc_iov(struct msghdr *msg,
return 0;
unwind_iov:
for (i--; i >= 0 ; i--)
- free(msg->msg_iov[i].iov_base);
+ free(iov[i].iov_base);
free(iov);
return -ENOMEM;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0239/1518] selftests/lsm: Fix memory leak in attr_lsm_count
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (237 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0238/1518] selftests/bpf: Fix memory leak in msg_alloc_iov Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0240/1518] irqchip/gic-v3-its: Fix memleak in its_probe_one() Greg Kroah-Hartman
` (759 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Wang Yan, William Roberts,
Paul Moore, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wang Yan <wangyan01@kylinos.cn>
[ Upstream commit 0cee720cfd51402cfcb14d96cb326a36c13b823a ]
The calloc-allocated buffer in attr_lsm_count() is never released on
any exit path, including both the normal return path and the early
return when read_sysfs_lsms fails, resulting in a heap memory leak.
Add free() for the buffer on all return branches to fix the leak.
Fixes: d3d929a8b0cd ("LSM: selftests for Linux Security Module syscalls")
Signed-off-by: Wang Yan <wangyan01@kylinos.cn>
Reviewed-by: William Roberts <bill.c.roberts@gmail.com>
Tested-by: William Roberts <bill.c.roberts@gmail.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/lsm/common.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/tools/testing/selftests/lsm/common.c b/tools/testing/selftests/lsm/common.c
index 9ad258912646c..927dce4f04cb2 100644
--- a/tools/testing/selftests/lsm/common.c
+++ b/tools/testing/selftests/lsm/common.c
@@ -76,7 +76,7 @@ int attr_lsm_count(void)
return 0;
if (read_sysfs_lsms(names, sysconf(_SC_PAGESIZE)))
- return 0;
+ goto out;
if (strstr(names, "selinux"))
count++;
@@ -85,5 +85,7 @@ int attr_lsm_count(void)
if (strstr(names, "apparmor"))
count++;
+out:
+ free(names);
return count;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0240/1518] irqchip/gic-v3-its: Fix memleak in its_probe_one()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (238 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0239/1518] selftests/lsm: Fix memory leak in attr_lsm_count Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0241/1518] irqchip/gic-v3-its: Fix its node leak in gic_acpi_parse_madt_its() Greg Kroah-Hartman
` (758 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kemeng Shi, Thomas Gleixner,
Radu Rendec, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kemeng Shi <shikemeng@huaweicloud.com>
[ Upstream commit 1efffab6fe336a5c4fd3c2886f255cd2f998e65f ]
Fix collection leak when its_init_domain() failed in its_probe_one().
Fixes: 4c21f3c26ecc2 ("irqchip: GICv3: ITS: DT probing and initialization")
Signed-off-by: Kemeng Shi <shikemeng@huaweicloud.com>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Reviewed-by: Radu Rendec <radu@rendec.net>
Link: https://patch.msgid.link/20260702033050.1583-2-shikemeng@huaweicloud.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/irqchip/irq-gic-v3-its.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/irqchip/irq-gic-v3-its.c b/drivers/irqchip/irq-gic-v3-its.c
index a1661657391d6..fb67456e301e4 100644
--- a/drivers/irqchip/irq-gic-v3-its.c
+++ b/drivers/irqchip/irq-gic-v3-its.c
@@ -5322,7 +5322,7 @@ static int __init its_probe_one(struct its_node *its)
err = its_init_domain(its);
if (err)
- goto out_free_tables;
+ goto out_free_collection;
raw_spin_lock(&its_lock);
list_add(&its->entry, &its_nodes);
@@ -5330,6 +5330,8 @@ static int __init its_probe_one(struct its_node *its)
return 0;
+out_free_collection:
+ kfree(its->collections);
out_free_tables:
its_free_tables(its);
out_free_cmd:
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0241/1518] irqchip/gic-v3-its: Fix its node leak in gic_acpi_parse_madt_its()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (239 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0240/1518] irqchip/gic-v3-its: Fix memleak in its_probe_one() Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0242/1518] selftests: timers: leap-a-day: Fix -w option and update usage comment Greg Kroah-Hartman
` (757 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kemeng Shi, Thomas Gleixner,
Radu Rendec, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kemeng Shi <shikemeng@huaweicloud.com>
[ Upstream commit 698a8648ca8051d34722b09b8a8088c741120ac3 ]
Fix its node leak when its_probe_one() failed in
gic_acpi_parse_madt_its().
Fixes: 9585a495ac936 ("irqchip/gic-v3-its: Split allocation from initialisation of its_node")
Signed-off-by: Kemeng Shi <shikemeng@huaweicloud.com>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Reviewed-by: Radu Rendec <radu@rendec.net>
Link: https://patch.msgid.link/20260702033050.1583-3-shikemeng@huaweicloud.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/irqchip/irq-gic-v3-its.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
diff --git a/drivers/irqchip/irq-gic-v3-its.c b/drivers/irqchip/irq-gic-v3-its.c
index fb67456e301e4..627b708c96264 100644
--- a/drivers/irqchip/irq-gic-v3-its.c
+++ b/drivers/irqchip/irq-gic-v3-its.c
@@ -5744,9 +5744,13 @@ static int __init gic_acpi_parse_madt_its(union acpi_subtable_headers *header,
its->flags |= ITS_FLAGS_FORCE_NON_SHAREABLE;
err = its_probe_one(its);
- if (!err)
- return 0;
+ if (err)
+ goto probe_err;
+
+ return 0;
+probe_err:
+ its_node_destroy(its);
node_err:
iort_deregister_domain_token(its_entry->translation_id);
dom_err:
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0242/1518] selftests: timers: leap-a-day: Fix -w option and update usage comment
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (240 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0241/1518] irqchip/gic-v3-its: Fix its node leak in gic_acpi_parse_madt_its() Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0243/1518] clocksource: Unregister subsystem on device registration failure Greg Kroah-Hartman
` (756 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jiangshan Yi, Thomas Gleixner,
John Stultz, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiangshan Yi <yijiangshan@kylinos.cn>
[ Upstream commit b4b66151a71445f3a71574136ddc82968c7b175e ]
Commit 98b74e1f3104 ("kselftests: timers: leap-a-day: Change default
arguments to help test runs") replaced the -s option with -w and made
"wait for the leap second" the non-default behaviour, but it only
updated the switch/case handling. Two things were left inconsistent:
- The getopt() option string still lists 's' instead of 'w', so
passing -w is rejected as an invalid option and the new behaviour
cannot be selected at all.
- The file header comment still documents the removed -s option and
an outdated default for -i.
Fix the getopt() string to accept 'w' (matching the existing case 'w':
handler) and update the header comment to describe -w, -t and the
current -i default.
Fixes: 98b74e1f3104 ("kselftests: timers: leap-a-day: Change default arguments to help test runs")
Signed-off-by: Jiangshan Yi <yijiangshan@kylinos.cn>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Acked-by: John Stultz <jstultz@google.com>
Link: https://patch.msgid.link/20260702093915.2652638-1-yijiangshan@kylinos.cn
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/timers/leap-a-day.c | 19 +++++++++++--------
1 file changed, 11 insertions(+), 8 deletions(-)
diff --git a/tools/testing/selftests/timers/leap-a-day.c b/tools/testing/selftests/timers/leap-a-day.c
index 04004a7c0934f..e677e31a22110 100644
--- a/tools/testing/selftests/timers/leap-a-day.c
+++ b/tools/testing/selftests/timers/leap-a-day.c
@@ -9,16 +9,19 @@
* kernel's leap-second behavior, as well as how well applications
* handle the leap-second discontinuity.
*
- * Usage: leap-a-day [-s] [-i <num>]
+ * Usage: leap-a-day [-w] [-i <num>] [-t]
*
* Options:
- * -s: Each iteration, set the date to 10 seconds before midnight GMT.
- * This speeds up the number of leapsecond transitions tested,
- * but because it calls settimeofday frequently, advancing the
- * time by 24 hours every ~16 seconds, it may cause application
- * disruption.
+ * -w: Only set the leap-second flag and wait for the leap second
+ * each iteration, instead of advancing the time. By default the
+ * date is set to 10 seconds before midnight GMT, which speeds up
+ * the number of leapsecond transitions tested, but because it
+ * calls settimeofday frequently, advancing the time by 24 hours
+ * every ~16 seconds, it may cause application disruption.
*
- * -i: Number of iterations to run (default: infinite)
+ * -i: Number of iterations to run (-1 = infinite, default: 10)
+ *
+ * -t: Print TAI time.
*
* Other notes: Disabling NTP prior to running this is advised, as the two
* may conflict in their commands to the kernel.
@@ -186,7 +189,7 @@ int main(int argc, char **argv)
int opt;
/* Process arguments */
- while ((opt = getopt(argc, argv, "sti:")) != -1) {
+ while ((opt = getopt(argc, argv, "wti:")) != -1) {
switch (opt) {
case 'w':
printf("Only setting leap-flag, not changing time. It could take up to a day for leap to trigger.\n");
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0243/1518] clocksource: Unregister subsystem on device registration failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (241 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0242/1518] selftests: timers: leap-a-day: Fix -w option and update usage comment Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0244/1518] timekeeping: Unwind aux clock sysfs children on failure Greg Kroah-Hartman
` (755 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yuho Choi, Thomas Gleixner,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuho Choi <dbgh9129@gmail.com>
[ Upstream commit 3dee6537e728bd8137fda6eaf859f26e685943f7 ]
init_clocksource_sysfs() registers the clocksource subsystem before
registering the clocksource device. If device_register() fails, the
function returns the error while leaving the subsystem registered.
Unregister the clocksource subsystem on that failure path so the
successful subsystem registration is unwound before returning.
Fixes: d369a5d8fc70 ("clocksource: convert sysdev_class to a regular subsystem")
Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Link: https://patch.msgid.link/20260702215733.84588-1-dbgh9129@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/time/clocksource.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
diff --git a/kernel/time/clocksource.c b/kernel/time/clocksource.c
index df71949616584..c2ce6cea24107 100644
--- a/kernel/time/clocksource.c
+++ b/kernel/time/clocksource.c
@@ -1482,8 +1482,12 @@ static int __init init_clocksource_sysfs(void)
{
int error = subsys_system_register(&clocksource_subsys, NULL);
- if (!error)
- error = device_register(&device_clocksource);
+ if (error)
+ return error;
+
+ error = device_register(&device_clocksource);
+ if (error)
+ bus_unregister(&clocksource_subsys);
return error;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0244/1518] timekeeping: Unwind aux clock sysfs children on failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (242 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0243/1518] clocksource: Unregister subsystem on device registration failure Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0245/1518] timers/migration: Fix memory leak in tmigr_setup_groups() error path Greg Kroah-Hartman
` (754 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yuho Choi, Thomas Gleixner,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuho Choi <dbgh9129@gmail.com>
[ Upstream commit f2eee7e31ccd4bc87d047d8670cc2ec39cf36647 ]
tk_aux_sysfs_init() creates one child kobject per auxiliary clock. If a
later child or sysfs group creation fails, the current error path only
puts the parent kobjects and leaves earlier children and groups behind.
Store the child kobjects during init and remove the successfully created
groups and kobjects on failure.
Fixes: 7b5ab04f035f ("timekeeping: Fix resource leak in tk_aux_sysfs_init() error paths")
Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Link: https://patch.msgid.link/20260703165337.168445-1-dbgh9129@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/time/timekeeping.c | 21 +++++++++++++++------
1 file changed, 15 insertions(+), 6 deletions(-)
diff --git a/kernel/time/timekeeping.c b/kernel/time/timekeeping.c
index 06184f304c6a0..e6060d9392d09 100644
--- a/kernel/time/timekeeping.c
+++ b/kernel/time/timekeeping.c
@@ -3065,7 +3065,9 @@ static const struct attribute_group aux_clock_enable_attr_group = {
static int __init tk_aux_sysfs_init(void)
{
struct kobject *auxo, *tko = kobject_create_and_add("time", kernel_kobj);
+ struct kobject *clks[MAX_AUX_CLOCKS];
int ret = -ENOMEM;
+ int i;
if (!tko)
return ret;
@@ -3074,21 +3076,28 @@ static int __init tk_aux_sysfs_init(void)
if (!auxo)
goto err_clean;
- for (int i = 0; i < MAX_AUX_CLOCKS; i++) {
+ for (i = 0; i < MAX_AUX_CLOCKS; i++) {
char id[2] = { [0] = '0' + i, };
- struct kobject *clk = kobject_create_and_add(id, auxo);
+ clks[i] = kobject_create_and_add(id, auxo);
- if (!clk) {
+ if (!clks[i]) {
ret = -ENOMEM;
- goto err_clean;
+ goto err_clks;
}
- ret = sysfs_create_group(clk, &aux_clock_enable_attr_group);
+ ret = sysfs_create_group(clks[i], &aux_clock_enable_attr_group);
if (ret)
- goto err_clean;
+ goto err_clk;
}
return 0;
+err_clk:
+ kobject_put(clks[i]);
+err_clks:
+ while (--i >= 0) {
+ sysfs_remove_group(clks[i], &aux_clock_enable_attr_group);
+ kobject_put(clks[i]);
+ }
err_clean:
kobject_put(auxo);
kobject_put(tko);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0245/1518] timers/migration: Fix memory leak in tmigr_setup_groups() error path
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (243 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0244/1518] timekeeping: Unwind aux clock sysfs children on failure Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0246/1518] x86/tsx: Make tsx_ctrl_state static Greg Kroah-Hartman
` (753 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Malaya Kumar Rout, Thomas Gleixner,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Malaya Kumar Rout <malayarout91@gmail.com>
[ Upstream commit eddfded4196542deda7cb2da3d7ebef83f7ccfa4 ]
When the WARN_ON_ONCE(i >= tmigr_hierarchy_levels) assertion triggers,
the function returns -EINVAL without freeing the 'stack' memory allocated
via kzalloc_objs() at the beginning of the function.
Add kfree(stack) before returning to prevent the memory leak.
Fixes: 6c181b5667ee ("timers/migration: Convert "while" loops to use "for"")
Signed-off-by: Malaya Kumar Rout <malayarout91@gmail.com>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Link: https://patch.msgid.link/20260704085533.87098-1-malayarout91@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/time/timer_migration.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/kernel/time/timer_migration.c b/kernel/time/timer_migration.c
index 76d896a99d7b0..32f338052bc4f 100644
--- a/kernel/time/timer_migration.c
+++ b/kernel/time/timer_migration.c
@@ -1667,8 +1667,10 @@ static int tmigr_setup_groups(unsigned int cpu, unsigned int node,
}
/* Assert single root without parent */
- if (WARN_ON_ONCE(i >= tmigr_hierarchy_levels))
+ if (WARN_ON_ONCE(i >= tmigr_hierarchy_levels)) {
+ kfree(stack);
return -EINVAL;
+ }
for (; i >= start_lvl; i--) {
group = stack[i];
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0246/1518] x86/tsx: Make tsx_ctrl_state static
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (244 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0245/1518] timers/migration: Fix memory leak in tmigr_setup_groups() error path Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0247/1518] vdso/timens: Move functions to new file Greg Kroah-Hartman
` (752 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Petr Tesarik, Borislav Petkov (AMD),
Nikolay Borisov, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Petr Tesarik <ptesarik@suse.com>
[ Upstream commit f018fca8f90bc383fefd97e3b2db03ea612ac789 ]
Move all definitions related to tsx_ctrl_state to tsx.c. They are
never referenced outside this file.
No functional change.
Signed-off-by: Petr Tesarik <ptesarik@suse.com>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Reviewed-by: Nikolay Borisov <nik.borisov@suse.com>
Link: https://lore.kernel.org/all/cover.1758906115.git.ptesarik@suse.com
Stable-dep-of: 06aba58e5849 ("time/namespace: Validate nanosecond field in proc_timens_set_offset()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/kernel/cpu/cpu.h | 9 ---------
arch/x86/kernel/cpu/tsx.c | 9 ++++++++-
2 files changed, 8 insertions(+), 10 deletions(-)
diff --git a/arch/x86/kernel/cpu/cpu.h b/arch/x86/kernel/cpu/cpu.h
index 92032422a8298..dca2d5845e427 100644
--- a/arch/x86/kernel/cpu/cpu.h
+++ b/arch/x86/kernel/cpu/cpu.h
@@ -42,15 +42,6 @@ extern const struct cpu_dev *const __x86_cpu_dev_start[],
*const __x86_cpu_dev_end[];
#ifdef CONFIG_CPU_SUP_INTEL
-enum tsx_ctrl_states {
- TSX_CTRL_ENABLE,
- TSX_CTRL_DISABLE,
- TSX_CTRL_RTM_ALWAYS_ABORT,
- TSX_CTRL_NOT_SUPPORTED,
-};
-
-extern __ro_after_init enum tsx_ctrl_states tsx_ctrl_state;
-
extern void __init tsx_init(void);
void tsx_ap_init(void);
void intel_unlock_cpuid_leafs(struct cpuinfo_x86 *c);
diff --git a/arch/x86/kernel/cpu/tsx.c b/arch/x86/kernel/cpu/tsx.c
index 49782724a9430..8be08ece22148 100644
--- a/arch/x86/kernel/cpu/tsx.c
+++ b/arch/x86/kernel/cpu/tsx.c
@@ -19,7 +19,14 @@
#undef pr_fmt
#define pr_fmt(fmt) "tsx: " fmt
-enum tsx_ctrl_states tsx_ctrl_state __ro_after_init = TSX_CTRL_NOT_SUPPORTED;
+enum tsx_ctrl_states {
+ TSX_CTRL_ENABLE,
+ TSX_CTRL_DISABLE,
+ TSX_CTRL_RTM_ALWAYS_ABORT,
+ TSX_CTRL_NOT_SUPPORTED,
+};
+
+static enum tsx_ctrl_states tsx_ctrl_state __ro_after_init = TSX_CTRL_NOT_SUPPORTED;
static void tsx_disable(void)
{
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0247/1518] vdso/timens: Move functions to new file
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (245 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0246/1518] x86/tsx: Make tsx_ctrl_state static Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0248/1518] timens: Remove dependency on the vDSO Greg Kroah-Hartman
` (751 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Thomas Weißschuh,
Thomas Gleixner, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Weißschuh <thomas.weissschuh@linutronix.de>
[ Upstream commit 5dc9cf835aba73c882348aa4f99be83b6e45ad9b ]
As a preparation of the untangling of time namespaces and the vDSO, move
the glue functions between those subsystems into a new file.
While at it, switch the mutex lock and mmap_read_lock() in the vDSO
namespace code to guard().
Signed-off-by: Thomas Weißschuh <thomas.weissschuh@linutronix.de>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Link: https://patch.msgid.link/20260326-vdso-timens-decoupling-v2-1-c82693a7775f@linutronix.de
Stable-dep-of: 06aba58e5849 ("time/namespace: Validate nanosecond field in proc_timens_set_offset()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
MAINTAINERS | 2 +
include/linux/time_namespace.h | 8 --
kernel/time/Makefile | 2 +-
kernel/time/namespace.c | 124 +-------------------------
kernel/time/namespace_internal.h | 13 +++
kernel/time/namespace_vdso.c | 146 +++++++++++++++++++++++++++++++
lib/vdso/datastore.c | 25 ------
7 files changed, 166 insertions(+), 154 deletions(-)
create mode 100644 kernel/time/namespace_internal.h
create mode 100644 kernel/time/namespace_vdso.c
diff --git a/MAINTAINERS b/MAINTAINERS
index 8262a885a6994..2a8ccc21183ae 100644
--- a/MAINTAINERS
+++ b/MAINTAINERS
@@ -10533,6 +10533,7 @@ S: Maintained
T: git git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git timers/vdso
F: include/asm-generic/vdso/vsyscall.h
F: include/vdso/
+F: kernel/time/namespace_vdso.c
F: kernel/time/vsyscall.c
F: lib/vdso/
F: tools/testing/selftests/vDSO/
@@ -20502,6 +20503,7 @@ F: include/trace/events/timer*
F: kernel/time/itimer.c
F: kernel/time/posix-*
F: kernel/time/namespace.c
+F: kernel/time/namespace_vdso.c
POWER MANAGEMENT CORE
M: "Rafael J. Wysocki" <rafael@kernel.org>
diff --git a/include/linux/time_namespace.h b/include/linux/time_namespace.h
index c514d0e5a45cb..0421bf1b13d7a 100644
--- a/include/linux/time_namespace.h
+++ b/include/linux/time_namespace.h
@@ -38,8 +38,6 @@ static inline struct time_namespace *to_time_ns(struct ns_common *ns)
return container_of(ns, struct time_namespace, ns);
}
void __init time_ns_init(void);
-extern int vdso_join_timens(struct task_struct *task,
- struct time_namespace *ns);
extern void timens_commit(struct task_struct *tsk, struct time_namespace *ns);
static inline struct time_namespace *get_time_ns(struct time_namespace *ns)
@@ -117,12 +115,6 @@ static inline void __init time_ns_init(void)
{
}
-static inline int vdso_join_timens(struct task_struct *task,
- struct time_namespace *ns)
-{
- return 0;
-}
-
static inline void timens_commit(struct task_struct *tsk,
struct time_namespace *ns)
{
diff --git a/kernel/time/Makefile b/kernel/time/Makefile
index f7d52d9543cc7..662bccb3b7f9a 100644
--- a/kernel/time/Makefile
+++ b/kernel/time/Makefile
@@ -29,6 +29,6 @@ endif
obj-$(CONFIG_GENERIC_GETTIMEOFDAY) += vsyscall.o
obj-$(CONFIG_DEBUG_FS) += timekeeping_debug.o
obj-$(CONFIG_TEST_UDELAY) += test_udelay.o
-obj-$(CONFIG_TIME_NS) += namespace.o
+obj-$(CONFIG_TIME_NS) += namespace.o namespace_vdso.o
obj-$(CONFIG_TEST_CLOCKSOURCE_WATCHDOG) += clocksource-wdtest.o
obj-$(CONFIG_TIME_KUNIT_TEST) += time_test.o
diff --git a/kernel/time/namespace.c b/kernel/time/namespace.c
index 5b6997f4dc3da..0e15a5daa45e7 100644
--- a/kernel/time/namespace.c
+++ b/kernel/time/namespace.c
@@ -19,7 +19,7 @@
#include <linux/err.h>
#include <linux/mm.h>
-#include <vdso/datapage.h>
+#include "namespace_internal.h"
ktime_t do_timens_ktime_to_host(clockid_t clockid, ktime_t tim,
struct timens_offsets *ns_offsets)
@@ -138,117 +138,7 @@ struct time_namespace *copy_time_ns(u64 flags,
return clone_time_ns(user_ns, old_ns);
}
-static struct timens_offset offset_from_ts(struct timespec64 off)
-{
- struct timens_offset ret;
-
- ret.sec = off.tv_sec;
- ret.nsec = off.tv_nsec;
-
- return ret;
-}
-
-/*
- * A time namespace VVAR page has the same layout as the VVAR page which
- * contains the system wide VDSO data.
- *
- * For a normal task the VVAR pages are installed in the normal ordering:
- * VVAR
- * PVCLOCK
- * HVCLOCK
- * TIMENS <- Not really required
- *
- * Now for a timens task the pages are installed in the following order:
- * TIMENS
- * PVCLOCK
- * HVCLOCK
- * VVAR
- *
- * The check for vdso_clock->clock_mode is in the unlikely path of
- * the seq begin magic. So for the non-timens case most of the time
- * 'seq' is even, so the branch is not taken.
- *
- * If 'seq' is odd, i.e. a concurrent update is in progress, the extra check
- * for vdso_clock->clock_mode is a non-issue. The task is spin waiting for the
- * update to finish and for 'seq' to become even anyway.
- *
- * Timens page has vdso_clock->clock_mode set to VDSO_CLOCKMODE_TIMENS which
- * enforces the time namespace handling path.
- */
-static void timens_setup_vdso_clock_data(struct vdso_clock *vc,
- struct time_namespace *ns)
-{
- struct timens_offset *offset = vc->offset;
- struct timens_offset monotonic = offset_from_ts(ns->offsets.monotonic);
- struct timens_offset boottime = offset_from_ts(ns->offsets.boottime);
-
- vc->seq = 1;
- vc->clock_mode = VDSO_CLOCKMODE_TIMENS;
- offset[CLOCK_MONOTONIC] = monotonic;
- offset[CLOCK_MONOTONIC_RAW] = monotonic;
- offset[CLOCK_MONOTONIC_COARSE] = monotonic;
- offset[CLOCK_BOOTTIME] = boottime;
- offset[CLOCK_BOOTTIME_ALARM] = boottime;
-}
-
-struct page *find_timens_vvar_page(struct vm_area_struct *vma)
-{
- if (likely(vma->vm_mm == current->mm))
- return current->nsproxy->time_ns->vvar_page;
-
- /*
- * VM_PFNMAP | VM_IO protect .fault() handler from being called
- * through interfaces like /proc/$pid/mem or
- * process_vm_{readv,writev}() as long as there's no .access()
- * in special_mapping_vmops().
- * For more details check_vma_flags() and __access_remote_vm()
- */
-
- WARN(1, "vvar_page accessed remotely");
-
- return NULL;
-}
-
-/*
- * Protects possibly multiple offsets writers racing each other
- * and tasks entering the namespace.
- */
-static DEFINE_MUTEX(offset_lock);
-
-static void timens_set_vvar_page(struct task_struct *task,
- struct time_namespace *ns)
-{
- struct vdso_time_data *vdata;
- struct vdso_clock *vc;
- unsigned int i;
-
- if (ns == &init_time_ns)
- return;
-
- /* Fast-path, taken by every task in namespace except the first. */
- if (likely(ns->frozen_offsets))
- return;
-
- mutex_lock(&offset_lock);
- /* Nothing to-do: vvar_page has been already initialized. */
- if (ns->frozen_offsets)
- goto out;
-
- ns->frozen_offsets = true;
- vdata = page_address(ns->vvar_page);
- vc = vdata->clock_data;
-
- for (i = 0; i < CS_BASES; i++)
- timens_setup_vdso_clock_data(&vc[i], ns);
-
- if (IS_ENABLED(CONFIG_POSIX_AUX_CLOCKS)) {
- for (i = 0; i < ARRAY_SIZE(vdata->aux_clock_data); i++)
- timens_setup_vdso_clock_data(&vdata->aux_clock_data[i], ns);
- }
-
-out:
- mutex_unlock(&offset_lock);
-}
+DEFINE_MUTEX(timens_offset_lock);
void free_time_ns(struct time_namespace *ns)
{
@@ -298,12 +188,6 @@ static void timens_put(struct ns_common *ns)
put_time_ns(to_time_ns(ns));
}
-void timens_commit(struct task_struct *tsk, struct time_namespace *ns)
-{
- timens_set_vvar_page(tsk, ns);
- vdso_join_timens(tsk, ns);
-}
-
static int timens_install(struct nsset *nsset, struct ns_common *new)
{
struct nsproxy *nsproxy = nsset->nsproxy;
@@ -428,7 +312,7 @@ int proc_timens_set_offset(struct file *file, struct task_struct *p,
goto out;
}
- mutex_lock(&offset_lock);
+ mutex_lock(&timens_offset_lock);
if (time_ns->frozen_offsets) {
err = -EACCES;
goto out_unlock;
@@ -453,7 +337,7 @@ int proc_timens_set_offset(struct file *file, struct task_struct *p,
}
out_unlock:
- mutex_unlock(&offset_lock);
+ mutex_unlock(&timens_offset_lock);
out:
put_time_ns(time_ns);
diff --git a/kernel/time/namespace_internal.h b/kernel/time/namespace_internal.h
new file mode 100644
index 0000000000000..e85da11abb4d9
--- /dev/null
+++ b/kernel/time/namespace_internal.h
@@ -0,0 +1,13 @@
+/* SPDX-License-Identifier: GPL-2.0 */
+#ifndef _TIME_NAMESPACE_INTERNAL_H
+#define _TIME_NAMESPACE_INTERNAL_H
+
+#include <linux/mutex.h>
+
+/*
+ * Protects possibly multiple offsets writers racing each other
+ * and tasks entering the namespace.
+ */
+extern struct mutex timens_offset_lock;
+
+#endif /* _TIME_NAMESPACE_INTERNAL_H */
diff --git a/kernel/time/namespace_vdso.c b/kernel/time/namespace_vdso.c
new file mode 100644
index 0000000000000..0e154f9015012
--- /dev/null
+++ b/kernel/time/namespace_vdso.c
@@ -0,0 +1,146 @@
+// SPDX-License-Identifier: GPL-2.0
+/*
+ * Author: Andrei Vagin <avagin@openvz.org>
+ * Author: Dmitry Safonov <dima@arista.com>
+ */
+
+#include <linux/cleanup.h>
+#include <linux/mm.h>
+#include <linux/time_namespace.h>
+#include <linux/time.h>
+#include <linux/vdso_datastore.h>
+
+#include <vdso/clocksource.h>
+#include <vdso/datapage.h>
+
+#include "namespace_internal.h"
+
+static struct timens_offset offset_from_ts(struct timespec64 off)
+{
+ struct timens_offset ret;
+
+ ret.sec = off.tv_sec;
+ ret.nsec = off.tv_nsec;
+
+ return ret;
+}
+
+/*
+ * A time namespace VVAR page has the same layout as the VVAR page which
+ * contains the system wide VDSO data.
+ *
+ * For a normal task the VVAR pages are installed in the normal ordering:
+ * VVAR
+ * PVCLOCK
+ * HVCLOCK
+ * TIMENS <- Not really required
+ *
+ * Now for a timens task the pages are installed in the following order:
+ * TIMENS
+ * PVCLOCK
+ * HVCLOCK
+ * VVAR
+ *
+ * The check for vdso_clock->clock_mode is in the unlikely path of
+ * the seq begin magic. So for the non-timens case most of the time
+ * 'seq' is even, so the branch is not taken.
+ *
+ * If 'seq' is odd, i.e. a concurrent update is in progress, the extra check
+ * for vdso_clock->clock_mode is a non-issue. The task is spin waiting for the
+ * update to finish and for 'seq' to become even anyway.
+ *
+ * Timens page has vdso_clock->clock_mode set to VDSO_CLOCKMODE_TIMENS which
+ * enforces the time namespace handling path.
+ */
+static void timens_setup_vdso_clock_data(struct vdso_clock *vc,
+ struct time_namespace *ns)
+{
+ struct timens_offset *offset = vc->offset;
+ struct timens_offset monotonic = offset_from_ts(ns->offsets.monotonic);
+ struct timens_offset boottime = offset_from_ts(ns->offsets.boottime);
+
+ vc->seq = 1;
+ vc->clock_mode = VDSO_CLOCKMODE_TIMENS;
+ offset[CLOCK_MONOTONIC] = monotonic;
+ offset[CLOCK_MONOTONIC_RAW] = monotonic;
+ offset[CLOCK_MONOTONIC_COARSE] = monotonic;
+ offset[CLOCK_BOOTTIME] = boottime;
+ offset[CLOCK_BOOTTIME_ALARM] = boottime;
+}
+
+struct page *find_timens_vvar_page(struct vm_area_struct *vma)
+{
+ if (likely(vma->vm_mm == current->mm))
+ return current->nsproxy->time_ns->vvar_page;
+
+ /*
+ * VM_PFNMAP | VM_IO protect .fault() handler from being called
+ * through interfaces like /proc/$pid/mem or
+ * process_vm_{readv,writev}() as long as there's no .access()
+ * in special_mapping_vmops().
+ * For more details check_vma_flags() and __access_remote_vm()
+ */
+
+ WARN(1, "vvar_page accessed remotely");
+
+ return NULL;
+}
+
+static void timens_set_vvar_page(struct task_struct *task,
+ struct time_namespace *ns)
+{
+ struct vdso_time_data *vdata;
+ struct vdso_clock *vc;
+ unsigned int i;
+
+ if (ns == &init_time_ns)
+ return;
+
+ /* Fast-path, taken by every task in namespace except the first. */
+ if (likely(ns->frozen_offsets))
+ return;
+
+ guard(mutex)(&timens_offset_lock);
+ /* Nothing to-do: vvar_page has been already initialized. */
+ if (ns->frozen_offsets)
+ return;
+
+ ns->frozen_offsets = true;
+ vdata = page_address(ns->vvar_page);
+ vc = vdata->clock_data;
+
+ for (i = 0; i < CS_BASES; i++)
+ timens_setup_vdso_clock_data(&vc[i], ns);
+
+ if (IS_ENABLED(CONFIG_POSIX_AUX_CLOCKS)) {
+ for (i = 0; i < ARRAY_SIZE(vdata->aux_clock_data); i++)
+ timens_setup_vdso_clock_data(&vdata->aux_clock_data[i], ns);
+ }
+}
+
+/*
+ * The vvar page layout depends on whether a task belongs to the root or
+ * non-root time namespace. Whenever a task changes its namespace, the VVAR
+ * page tables are cleared and then they will be re-faulted with a
+ * corresponding layout.
+ * See also the comment near timens_setup_vdso_clock_data() for details.
+ */
+static int vdso_join_timens(struct task_struct *task, struct time_namespace *ns)
+{
+ struct mm_struct *mm = task->mm;
+ struct vm_area_struct *vma;
+ VMA_ITERATOR(vmi, mm, 0);
+
+ guard(mmap_read_lock)(mm);
+ for_each_vma(vmi, vma) {
+ if (vma_is_special_mapping(vma, &vdso_vvar_mapping))
+ zap_vma_pages(vma);
+ }
+ return 0;
+}
+
+void timens_commit(struct task_struct *tsk, struct time_namespace *ns)
+{
+ timens_set_vvar_page(tsk, ns);
+ vdso_join_timens(tsk, ns);
+}
diff --git a/lib/vdso/datastore.c b/lib/vdso/datastore.c
index a565c30c71a04..64d868dad8dd1 100644
--- a/lib/vdso/datastore.c
+++ b/lib/vdso/datastore.c
@@ -103,28 +103,3 @@ struct vm_area_struct *vdso_install_vvar_mapping(struct mm_struct *mm, unsigned
VM_PFNMAP | VM_SEALED_SYSMAP,
&vdso_vvar_mapping);
}
-
-#ifdef CONFIG_TIME_NS
-/*
- * The vvar page layout depends on whether a task belongs to the root or
- * non-root time namespace. Whenever a task changes its namespace, the VVAR
- * page tables are cleared and then they will be re-faulted with a
- * corresponding layout.
- * See also the comment near timens_setup_vdso_clock_data() for details.
- */
-int vdso_join_timens(struct task_struct *task, struct time_namespace *ns)
-{
- struct mm_struct *mm = task->mm;
- struct vm_area_struct *vma;
- VMA_ITERATOR(vmi, mm, 0);
-
- mmap_read_lock(mm);
- for_each_vma(vmi, vma) {
- if (vma_is_special_mapping(vma, &vdso_vvar_mapping))
- zap_vma_pages(vma);
- }
- mmap_read_unlock(mm);
-
- return 0;
-}
-#endif
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0248/1518] timens: Remove dependency on the vDSO
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (246 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0247/1518] vdso/timens: Move functions to new file Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0249/1518] timens: Add a __free() wrapper for put_time_ns() Greg Kroah-Hartman
` (750 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Thomas Weißschuh,
Thomas Gleixner, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Weißschuh <thomas.weissschuh@linutronix.de>
[ Upstream commit 1b6c89285d37114d7efe8ab04102a542581cd7da ]
Previously, missing time namespace support in the vDSO meant that time
namespaces needed to be disabled globally. This was expressed in a hard
dependency on the generic vDSO library. This also meant that architectures
without any vDSO or only a stub vDSO could not enable time namespaces.
Now that all architectures using a real vDSO are using the generic library,
that dependency is not necessary anymore.
Remove the dependency and let all architectures enable time namespaces.
Signed-off-by: Thomas Weißschuh <thomas.weissschuh@linutronix.de>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Link: https://patch.msgid.link/20260326-vdso-timens-decoupling-v2-2-c82693a7775f@linutronix.de
Stable-dep-of: 06aba58e5849 ("time/namespace: Validate nanosecond field in proc_timens_set_offset()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/time_namespace.h | 28 ++++++++++++++++------------
init/Kconfig | 4 +++-
kernel/time/Makefile | 3 ++-
kernel/time/namespace.c | 8 ++++----
kernel/time/namespace_internal.h | 15 +++++++++++++++
kernel/time/namespace_vdso.c | 14 ++++++++++++++
6 files changed, 54 insertions(+), 18 deletions(-)
diff --git a/include/linux/time_namespace.h b/include/linux/time_namespace.h
index 0421bf1b13d7a..c1de21a27c340 100644
--- a/include/linux/time_namespace.h
+++ b/include/linux/time_namespace.h
@@ -25,7 +25,9 @@ struct time_namespace {
struct ucounts *ucounts;
struct ns_common ns;
struct timens_offsets offsets;
+#ifdef CONFIG_TIME_NS_VDSO
struct page *vvar_page;
+#endif
/* If set prevents changing offsets after any task joined namespace. */
bool frozen_offsets;
} __randomize_layout;
@@ -38,7 +40,6 @@ static inline struct time_namespace *to_time_ns(struct ns_common *ns)
return container_of(ns, struct time_namespace, ns);
}
void __init time_ns_init(void);
-extern void timens_commit(struct task_struct *tsk, struct time_namespace *ns);
static inline struct time_namespace *get_time_ns(struct time_namespace *ns)
{
@@ -51,7 +52,6 @@ struct time_namespace *copy_time_ns(u64 flags,
struct time_namespace *old_ns);
void free_time_ns(struct time_namespace *ns);
void timens_on_fork(struct nsproxy *nsproxy, struct task_struct *tsk);
-struct page *find_timens_vvar_page(struct vm_area_struct *vma);
static inline void put_time_ns(struct time_namespace *ns)
{
@@ -115,11 +115,6 @@ static inline void __init time_ns_init(void)
{
}
-static inline void timens_commit(struct task_struct *tsk,
- struct time_namespace *ns)
-{
-}
-
static inline struct time_namespace *get_time_ns(struct time_namespace *ns)
{
return NULL;
@@ -146,11 +141,6 @@ static inline void timens_on_fork(struct nsproxy *nsproxy,
return;
}
-static inline struct page *find_timens_vvar_page(struct vm_area_struct *vma)
-{
- return NULL;
-}
-
static inline void timens_add_monotonic(struct timespec64 *ts) { }
static inline void timens_add_boottime(struct timespec64 *ts) { }
@@ -167,4 +157,18 @@ static inline ktime_t timens_ktime_to_host(clockid_t clockid, ktime_t tim)
}
#endif
+#ifdef CONFIG_TIME_NS_VDSO
+extern void timens_commit(struct task_struct *tsk, struct time_namespace *ns);
+struct page *find_timens_vvar_page(struct vm_area_struct *vma);
+#else /* !CONFIG_TIME_NS_VDSO */
+static inline void timens_commit(struct task_struct *tsk, struct time_namespace *ns)
+{
+}
+
+static inline struct page *find_timens_vvar_page(struct vm_area_struct *vma)
+{
+ return NULL;
+}
+#endif /* CONFIG_TIME_NS_VDSO */
+
#endif /* _LINUX_TIMENS_H */
diff --git a/init/Kconfig b/init/Kconfig
index 6ce315af48c15..6e66f327904b8 100644
--- a/init/Kconfig
+++ b/init/Kconfig
@@ -1366,12 +1366,14 @@ config UTS_NS
config TIME_NS
bool "TIME namespace"
- depends on GENERIC_GETTIMEOFDAY
default y
help
In this namespace boottime and monotonic clocks can be set.
The time will keep going with the same pace.
+config TIME_NS_VDSO
+ def_bool TIME_NS && GENERIC_GETTIMEOFDAY
+
config IPC_NS
bool "IPC namespace"
depends on (SYSVIPC || POSIX_MQUEUE)
diff --git a/kernel/time/Makefile b/kernel/time/Makefile
index 662bccb3b7f9a..eaf290c972f95 100644
--- a/kernel/time/Makefile
+++ b/kernel/time/Makefile
@@ -29,6 +29,7 @@ endif
obj-$(CONFIG_GENERIC_GETTIMEOFDAY) += vsyscall.o
obj-$(CONFIG_DEBUG_FS) += timekeeping_debug.o
obj-$(CONFIG_TEST_UDELAY) += test_udelay.o
-obj-$(CONFIG_TIME_NS) += namespace.o namespace_vdso.o
+obj-$(CONFIG_TIME_NS) += namespace.o
+obj-$(CONFIG_TIME_NS_VDSO) += namespace_vdso.o
obj-$(CONFIG_TEST_CLOCKSOURCE_WATCHDOG) += clocksource-wdtest.o
obj-$(CONFIG_TIME_KUNIT_TEST) += time_test.o
diff --git a/kernel/time/namespace.c b/kernel/time/namespace.c
index 0e15a5daa45e7..9191899289fcb 100644
--- a/kernel/time/namespace.c
+++ b/kernel/time/namespace.c
@@ -93,8 +93,8 @@ static struct time_namespace *clone_time_ns(struct user_namespace *user_ns,
if (!ns)
goto fail_dec;
- ns->vvar_page = alloc_page(GFP_KERNEL_ACCOUNT | __GFP_ZERO);
- if (!ns->vvar_page)
+ err = timens_vdso_alloc_vvar_page(ns);
+ if (err)
goto fail_free;
err = ns_common_init(ns);
@@ -109,7 +109,7 @@ static struct time_namespace *clone_time_ns(struct user_namespace *user_ns,
return ns;
fail_free_page:
- __free_page(ns->vvar_page);
+ timens_vdso_free_vvar_page(ns);
fail_free:
kfree(ns);
fail_dec:
@@ -146,7 +146,7 @@ void free_time_ns(struct time_namespace *ns)
dec_time_namespaces(ns->ucounts);
put_user_ns(ns->user_ns);
ns_common_free(ns);
- __free_page(ns->vvar_page);
+ timens_vdso_free_vvar_page(ns);
/* Concurrent nstree traversal depends on a grace period. */
kfree_rcu(ns, ns.ns_rcu);
}
diff --git a/kernel/time/namespace_internal.h b/kernel/time/namespace_internal.h
index e85da11abb4d9..b37ba179f43b2 100644
--- a/kernel/time/namespace_internal.h
+++ b/kernel/time/namespace_internal.h
@@ -4,10 +4,25 @@
#include <linux/mutex.h>
+struct time_namespace;
+
/*
* Protects possibly multiple offsets writers racing each other
* and tasks entering the namespace.
*/
extern struct mutex timens_offset_lock;
+#ifdef CONFIG_TIME_NS_VDSO
+int timens_vdso_alloc_vvar_page(struct time_namespace *ns);
+void timens_vdso_free_vvar_page(struct time_namespace *ns);
+#else /* !CONFIG_TIME_NS_VDSO */
+static inline int timens_vdso_alloc_vvar_page(struct time_namespace *ns)
+{
+ return 0;
+}
+static inline void timens_vdso_free_vvar_page(struct time_namespace *ns)
+{
+}
+#endif /* CONFIG_TIME_NS_VDSO */
+
#endif /* _TIME_NAMESPACE_INTERNAL_H */
diff --git a/kernel/time/namespace_vdso.c b/kernel/time/namespace_vdso.c
index 0e154f9015012..88c075cd16a36 100644
--- a/kernel/time/namespace_vdso.c
+++ b/kernel/time/namespace_vdso.c
@@ -144,3 +144,17 @@ void timens_commit(struct task_struct *tsk, struct time_namespace *ns)
timens_set_vvar_page(tsk, ns);
vdso_join_timens(tsk, ns);
}
+
+int timens_vdso_alloc_vvar_page(struct time_namespace *ns)
+{
+ ns->vvar_page = alloc_page(GFP_KERNEL_ACCOUNT | __GFP_ZERO);
+ if (!ns->vvar_page)
+ return -ENOMEM;
+
+ return 0;
+}
+
+void timens_vdso_free_vvar_page(struct time_namespace *ns)
+{
+ __free_page(ns->vvar_page);
+}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0249/1518] timens: Add a __free() wrapper for put_time_ns()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (247 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0248/1518] timens: Remove dependency on the vDSO Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0250/1518] timens: Simplify some calls to put_time_ns() Greg Kroah-Hartman
` (749 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Thomas Weißschuh,
Thomas Gleixner, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Weißschuh <thomas.weissschuh@linutronix.de>
[ Upstream commit c2de5a5be4d60af5f928a2dd2b0f73e17358e346 ]
The wrapper will be used to simplify cleanups of 'struct time_namespace'.
Signed-off-by: Thomas Weißschuh <thomas.weissschuh@linutronix.de>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Link: https://patch.msgid.link/20260330-timens-cleanup-v1-1-936e91c9dd30@linutronix.de
Stable-dep-of: 06aba58e5849 ("time/namespace: Validate nanosecond field in proc_timens_set_offset()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/time_namespace.h | 3 +++
1 file changed, 3 insertions(+)
diff --git a/include/linux/time_namespace.h b/include/linux/time_namespace.h
index c1de21a27c340..58bd9728df583 100644
--- a/include/linux/time_namespace.h
+++ b/include/linux/time_namespace.h
@@ -8,6 +8,7 @@
#include <linux/ns_common.h>
#include <linux/err.h>
#include <linux/time64.h>
+#include <linux/cleanup.h>
struct user_namespace;
extern struct user_namespace init_user_ns;
@@ -171,4 +172,6 @@ static inline struct page *find_timens_vvar_page(struct vm_area_struct *vma)
}
#endif /* CONFIG_TIME_NS_VDSO */
+DEFINE_FREE(time_ns, struct time_namespace *, if (_T) put_time_ns(_T))
+
#endif /* _LINUX_TIMENS_H */
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0250/1518] timens: Simplify some calls to put_time_ns()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (248 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0249/1518] timens: Add a __free() wrapper for put_time_ns() Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0251/1518] time/namespace: Validate nanosecond field in proc_timens_set_offset() Greg Kroah-Hartman
` (748 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Thomas Weißschuh,
Thomas Gleixner, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Weißschuh <thomas.weissschuh@linutronix.de>
[ Upstream commit 3fa3aeb4a5cb19e372680ef8860a0381cd5409e9 ]
Use the new __free() based cleanup helpers to simplify some functions.
Signed-off-by: Thomas Weißschuh <thomas.weissschuh@linutronix.de>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Link: https://patch.msgid.link/20260330-timens-cleanup-v1-2-936e91c9dd30@linutronix.de
Stable-dep-of: 06aba58e5849 ("time/namespace: Validate nanosecond field in proc_timens_set_offset()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/time/namespace.c | 29 +++++++++++------------------
1 file changed, 11 insertions(+), 18 deletions(-)
diff --git a/kernel/time/namespace.c b/kernel/time/namespace.c
index 9191899289fcb..6feb75b52b5cd 100644
--- a/kernel/time/namespace.c
+++ b/kernel/time/namespace.c
@@ -18,6 +18,7 @@
#include <linux/cred.h>
#include <linux/err.h>
#include <linux/mm.h>
+#include <linux/cleanup.h>
#include "namespace_internal.h"
@@ -251,36 +252,33 @@ static void show_offset(struct seq_file *m, int clockid, struct timespec64 *ts)
void proc_timens_show_offsets(struct task_struct *p, struct seq_file *m)
{
- struct ns_common *ns;
- struct time_namespace *time_ns;
+ struct time_namespace *time_ns __free(time_ns) = NULL;
+ struct ns_common *ns = timens_for_children_get(p);
- ns = timens_for_children_get(p);
if (!ns)
return;
+
time_ns = to_time_ns(ns);
show_offset(m, CLOCK_MONOTONIC, &time_ns->offsets.monotonic);
show_offset(m, CLOCK_BOOTTIME, &time_ns->offsets.boottime);
- put_time_ns(time_ns);
}
int proc_timens_set_offset(struct file *file, struct task_struct *p,
struct proc_timens_offset *offsets, int noffsets)
{
- struct ns_common *ns;
- struct time_namespace *time_ns;
+ struct time_namespace *time_ns __free(time_ns) = NULL;
+ struct ns_common *ns = timens_for_children_get(p);
struct timespec64 tp;
int i, err;
- ns = timens_for_children_get(p);
if (!ns)
return -ESRCH;
+
time_ns = to_time_ns(ns);
- if (!file_ns_capable(file, time_ns->user_ns, CAP_SYS_TIME)) {
- put_time_ns(time_ns);
+ if (!file_ns_capable(file, time_ns->user_ns, CAP_SYS_TIME))
return -EPERM;
- }
for (i = 0; i < noffsets; i++) {
struct proc_timens_offset *off = &offsets[i];
@@ -293,15 +291,12 @@ int proc_timens_set_offset(struct file *file, struct task_struct *p,
ktime_get_boottime_ts64(&tp);
break;
default:
- err = -EINVAL;
- goto out;
+ return -EINVAL;
}
- err = -ERANGE;
-
if (off->val.tv_sec > KTIME_SEC_MAX ||
off->val.tv_sec < -KTIME_SEC_MAX)
- goto out;
+ return -ERANGE;
tp = timespec64_add(tp, off->val);
/*
@@ -309,7 +304,7 @@ int proc_timens_set_offset(struct file *file, struct task_struct *p,
* still unreachable.
*/
if (tp.tv_sec < 0 || tp.tv_sec > KTIME_SEC_MAX / 2)
- goto out;
+ return -ERANGE;
}
mutex_lock(&timens_offset_lock);
@@ -338,8 +333,6 @@ int proc_timens_set_offset(struct file *file, struct task_struct *p,
out_unlock:
mutex_unlock(&timens_offset_lock);
-out:
- put_time_ns(time_ns);
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0251/1518] time/namespace: Validate nanosecond field in proc_timens_set_offset()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (249 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0250/1518] timens: Simplify some calls to put_time_ns() Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0252/1518] y2038: uapi: Use 64-bit __kernel_old_timespec::tv_nsec on x32 Greg Kroah-Hartman
` (747 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Malaya Kumar Rout, Thomas Gleixner,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Malaya Kumar Rout <malayarout91@gmail.com>
[ Upstream commit 06aba58e58492d2b8eae059274caed29025ea96e ]
The function validates tv_sec to be within [-KTIME_SEC_MAX, KTIME_SEC_MAX]
but never validates that tv_nsec is within the valid range of
[0, NSEC_PER_SEC-1] before using it in timespec64_add().
timespec64_add() expects both timespec64 structures to have normalized
values with tv_nsec in the range [0, 999999999]. If off->val.tv_nsec
contains invalid values (negative or >= NSEC_PER_SEC), it could lead to
incorrect calculations or unexpected behavior.
Add validation to ensure tv_nsec is within the valid range before
performing the addition.
Fixes: 04a8682a71be ("fs/proc: Introduce /proc/pid/timens_offsets")
Signed-off-by: Malaya Kumar Rout <malayarout91@gmail.com>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Link: https://patch.msgid.link/20260704093429.89350-1-malayarout91@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/time/namespace.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/kernel/time/namespace.c b/kernel/time/namespace.c
index 6feb75b52b5cd..8c5d997324d9f 100644
--- a/kernel/time/namespace.c
+++ b/kernel/time/namespace.c
@@ -294,10 +294,12 @@ int proc_timens_set_offset(struct file *file, struct task_struct *p,
return -EINVAL;
}
- if (off->val.tv_sec > KTIME_SEC_MAX ||
- off->val.tv_sec < -KTIME_SEC_MAX)
+ if (off->val.tv_sec > KTIME_SEC_MAX || off->val.tv_sec < -KTIME_SEC_MAX)
return -ERANGE;
+ if (off->val.tv_nsec < 0 || off->val.tv_nsec >= NSEC_PER_SEC)
+ return -EINVAL;
+
tp = timespec64_add(tp, off->val);
/*
* KTIME_SEC_MAX is divided by 2 to be sure that KTIME_MAX is
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0252/1518] y2038: uapi: Use 64-bit __kernel_old_timespec::tv_nsec on x32
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (250 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0251/1518] time/namespace: Validate nanosecond field in proc_timens_set_offset() Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0253/1518] timekeeping: Account for monotonicity adjustment in ntp_error Greg Kroah-Hartman
` (746 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Thomas Weißschuh,
Thomas Gleixner, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Weißschuh <thomas.weissschuh@linutronix.de>
[ Upstream commit 79ced850e549e8c86b772a79ea417a1425b5c04b ]
'struct __kernel_old_timespec' represents the 'native' time ABI of the
kernel. On 32-bit systems it uses 32-bit fields and on 64-bit systems
it uses 64-bit fields.
However the x86 x32 ABI uses the 64-bit time ABI natively. This is
correctly handled for the 'tv_sec' fields, through the typedefs of
'__kernel_old_time_t' -> '__kernel_long_t' -> 'long long'. The same
treatment was missed for 'tv_nsec'.
In practice this might not make much of a difference as the value of
'tv_nsec' will always fit into 32 bits and the missing bits fall
into the padding of the structure.
When introspecting the structure however, a difference can be observed.
Switch to 64-bit tv_nsec on x32. No other architectures or ABIs are
affected.
While this could be interpreted as violating the POSIX requirement of
'timespec::tv_nsec' being 'long':
* __kernel_old_timespec is not actually the POSIX timespec type
* the requirement is gone in newer versions of POSIX
* this matches glibc
Fixes: 94c467ddb273 ("y2038: add __kernel_old_timespec and __kernel_old_time_t")
Signed-off-by: Thomas Weißschuh <thomas.weissschuh@linutronix.de>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Link: https://patch.msgid.link/20260504-timespec-x32-v2-1-0739c9047fc4@linutronix.de
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/uapi/linux/time_types.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/include/uapi/linux/time_types.h b/include/uapi/linux/time_types.h
index bcc0002115d39..03a0d8aaadca5 100644
--- a/include/uapi/linux/time_types.h
+++ b/include/uapi/linux/time_types.h
@@ -30,7 +30,7 @@ struct __kernel_old_timeval {
struct __kernel_old_timespec {
__kernel_old_time_t tv_sec; /* seconds */
- long tv_nsec; /* nanoseconds */
+ __kernel_long_t tv_nsec; /* nanoseconds */
};
struct __kernel_old_itimerval {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0253/1518] timekeeping: Account for monotonicity adjustment in ntp_error
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (251 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0252/1518] y2038: uapi: Use 64-bit __kernel_old_timespec::tv_nsec on x32 Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0254/1518] arm64: dts: qcom: Add #{address,size}-cells to Chromium-based /firmware Greg Kroah-Hartman
` (745 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Woodhouse, Thomas Gleixner,
John Stultz, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Woodhouse <dwmw@amazon.co.uk>
[ Upstream commit b7befd6d91207cf3f4cecd68fea0c212093906cf ]
timekeeping_apply_adjustment() modifies xtime_nsec to ensure monotonicity
when mult changes:
xtime_nsec -= offset
This ensures that the time reported to userspace does not jump when the
multiplier is adjusted from one tick to the next. However, the ntp_error
accumulator which tracks the difference between intended and actual
clock position was not being updated to reflect this additional
discrepancy.
An earlier attempt at this compensation existed as:
ntp_error -= (interval - offset) << ntp_error_shift
but was removed in commit c2cda2a5bda9 ("timekeeping/ntp: Don't align
NTP frequency adjustments to ticks") because it was a major source of
NTP error. That's because (interval - offset) was wrong: the subtraction
of "interval" prematurely accounted for the changed xtime_interval of
the next tick, which would be correctly accounted in the next
accumulation anyway — a double subtraction.
What is actually needed is just the "offset" part: ntp_error must be
told that xtime_nsec moved by "offset" without a corresponding change
in the intended position. For the normal ±1 mult dithering this is
negligible (the adjustments cancel over time), but for larger mult
changes — such as when an external reference clock sets a new
frequency — the one-time uncompensated offset is significant.
Fix by adjusting ntp_error by the correct amount:
ntp_error += offset << ntp_error_shift
This keeps ntp_error consistent with the actual xtime_nsec position
after the adjustment, and ensures the discrepancy is correctly smoothed
away over time and the clock returns to where it should have been.
Fixes: c2cda2a5bda9 ("timekeeping/ntp: Don't align NTP frequency adjustments to ticks")
Signed-off-by: David Woodhouse <dwmw@amazon.co.uk>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Assisted-by: Kiro:claude-opus-4.6-1m
Acked-by: John Stultz <jstultz@google.com>
Link: https://patch.msgid.link/20260621220051.1030462-3-dwmw2@infradead.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/time/timekeeping.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/kernel/time/timekeeping.c b/kernel/time/timekeeping.c
index e6060d9392d09..03408b5fcf695 100644
--- a/kernel/time/timekeeping.c
+++ b/kernel/time/timekeeping.c
@@ -2140,6 +2140,11 @@ static __always_inline void timekeeping_apply_adjustment(struct timekeeper *tk,
* xtime_nsec_2 = xtime_nsec_1 - offset
* Which simplifies to:
* xtime_nsec -= offset
+ *
+ * When subtracting offset from xtime_nsec, the same amount
+ * (in appropriate units) has to be added to ntp_error, in
+ * order to correctly track the delta between the time
+ * reported in xtime_nsec, and the intended time.
*/
if ((mult_adj > 0) && (tk->tkr_mono.mult + mult_adj < mult_adj)) {
/* NTP adjustment caused clocksource mult overflow */
@@ -2150,6 +2155,7 @@ static __always_inline void timekeeping_apply_adjustment(struct timekeeper *tk,
tk->tkr_mono.mult += mult_adj;
tk->xtime_interval += interval;
tk->tkr_mono.xtime_nsec -= offset;
+ tk->ntp_error += offset << tk->ntp_error_shift;
}
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0254/1518] arm64: dts: qcom: Add #{address,size}-cells to Chromium-based /firmware
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (252 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0253/1518] timekeeping: Account for monotonicity adjustment in ntp_error Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0255/1518] clk: qcom: gdsc: propagate gdsc_check_status() errors from gdsc_poll_status Greg Kroah-Hartman
` (744 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Brian Norris, Dmitry Baryshkov,
Douglas Anderson, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Brian Norris <briannorris@chromium.org>
[ Upstream commit 2a906f0b4f037b3fe5f790a48f88549a86288fdf ]
Chromium/Depthcharge bootloaders may dynamically add a few device nodes
to a system's DTB under a /firmware node. A typical DT looks something
like the following:
/ {
firmware {
ranges;
coreboot {
compatible = "coreboot";
reg = <...>;
...;
};
};
};
Notably, the /firmware node has an empty 'ranges', but does not have
address/size-cells.
Commit 6e5773d52f4a ("of/address: Fix WARN when attempting translating
non-translatable addresses") started requiring #address-cells for a
device's parent if we want to use the reg resource in a device node.
This leads to errors like the following:
[ 7.763870] coreboot_table firmware:coreboot: probe with driver coreboot_table failed with error -22
Add appropriate #{address,size}-cells to work around the problem.
Note that Google has also patched the Depthcharge bootloader source to
add {address,size}-cells [1], but bootloader updates are typically
delivered only via Google OS updates. Not all users install Google
software updates, and even if they do, Google may not produce updated
binaries for all/older devices.
[1] https://lore.kernel.org/all/20241209092809.GA3246424@google.com/
https://crrev.com/c/6051580 ("coreboot: Insert #address-cells and
#size-cells for firmware node")
Closes: https://lore.kernel.org/all/aeKlYzTiL0OB1y3g@google.com/
Fixes: 6e5773d52f4a ("of/address: Fix WARN when attempting translating non-translatable addresses")
Signed-off-by: Brian Norris <briannorris@chromium.org>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Reviewed-by: Douglas Anderson <dianders@chromium.org>
Link: https://lore.kernel.org/r/20260428200712.2660635-8-briannorris@chromium.org
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sc7180-trogdor.dtsi | 5 +++++
arch/arm64/boot/dts/qcom/sc7280-herobrine.dtsi | 5 +++++
2 files changed, 10 insertions(+)
diff --git a/arch/arm64/boot/dts/qcom/sc7180-trogdor.dtsi b/arch/arm64/boot/dts/qcom/sc7180-trogdor.dtsi
index 74ab321d3333c..d60fad977a284 100644
--- a/arch/arm64/boot/dts/qcom/sc7180-trogdor.dtsi
+++ b/arch/arm64/boot/dts/qcom/sc7180-trogdor.dtsi
@@ -98,6 +98,11 @@ chosen {
stdout-path = "serial0:115200n8";
};
+ firmware {
+ #address-cells = <2>;
+ #size-cells = <2>;
+ };
+
/* FIXED REGULATORS - parents above children */
/* This is the top level supply and variable voltage */
diff --git a/arch/arm64/boot/dts/qcom/sc7280-herobrine.dtsi b/arch/arm64/boot/dts/qcom/sc7280-herobrine.dtsi
index 5c5e4f1dd2217..58ea0532c0fbb 100644
--- a/arch/arm64/boot/dts/qcom/sc7280-herobrine.dtsi
+++ b/arch/arm64/boot/dts/qcom/sc7280-herobrine.dtsi
@@ -25,6 +25,11 @@ chosen {
stdout-path = "serial0:115200n8";
};
+ firmware {
+ #address-cells = <2>;
+ #size-cells = <2>;
+ };
+
/*
* FIXED REGULATORS
*
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0255/1518] clk: qcom: gdsc: propagate gdsc_check_status() errors from gdsc_poll_status
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (253 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0254/1518] arm64: dts: qcom: Add #{address,size}-cells to Chromium-based /firmware Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0256/1518] clk: qcom: gdsc: propagate gdsc_enable() failure for ALWAYS_ON domains Greg Kroah-Hartman
` (743 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Herman van Hazendonk,
Dmitry Baryshkov, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Herman van Hazendonk <github.com@herrie.org>
[ Upstream commit d69f0c2b8d292b4890c9f0fbe184dfc26c4de86c ]
gdsc_check_status() returns negative errno when the underlying
regmap_read() fails -- e.g. when a parent regmap dies during system
suspend, a CSR is removed by an HW debug tool, or the bus controller
goes into protection. gdsc_poll_status() treats the result as a plain
boolean ("is the GDSC in the requested state?"), so any negative error
return is truncated to "true" and the poll exits with success even
though the rail's real state is unknown:
do {
if (gdsc_check_status(sc, status))
return 0;
} while (ktime_us_delta(ktime_get(), start) < STATUS_POLL_TIMEOUT_US);
if (gdsc_check_status(sc, status))
return 0;
return -ETIMEDOUT;
This silently misleads gdsc_toggle_logic() (which writes/un-writes
SW_COLLAPSE on the strength of the poll succeeding) and the gdsc_init()
sync path (which assumes the readback represents real silicon state).
Latch the return value, propagate negative errno immediately, and only
treat a strictly-positive value as "reached the target state". Make the
same change in the post-timeout final check so a regmap that comes back
after the deadline does not silently degrade to -ETIMEDOUT.
Signed-off-by: Herman van Hazendonk <github.com@herrie.org>
Fixes: 77b1067a19b4 ("clk: qcom: gdsc: Add support for gdscs with gds hw controller")
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260602140934.796697-2-github.com@herrie.org
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/qcom/gdsc.c | 11 +++++++++--
1 file changed, 9 insertions(+), 2 deletions(-)
diff --git a/drivers/clk/qcom/gdsc.c b/drivers/clk/qcom/gdsc.c
index 95aa071202455..b9b47f584f6d1 100644
--- a/drivers/clk/qcom/gdsc.c
+++ b/drivers/clk/qcom/gdsc.c
@@ -103,14 +103,21 @@ static int gdsc_hwctrl(struct gdsc *sc, bool en)
static int gdsc_poll_status(struct gdsc *sc, enum gdsc_status status)
{
ktime_t start;
+ int ret;
start = ktime_get();
do {
- if (gdsc_check_status(sc, status))
+ ret = gdsc_check_status(sc, status);
+ if (ret < 0)
+ return ret;
+ if (ret)
return 0;
} while (ktime_us_delta(ktime_get(), start) < STATUS_POLL_TIMEOUT_US);
- if (gdsc_check_status(sc, status))
+ ret = gdsc_check_status(sc, status);
+ if (ret < 0)
+ return ret;
+ if (ret)
return 0;
return -ETIMEDOUT;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0256/1518] clk: qcom: gdsc: propagate gdsc_enable() failure for ALWAYS_ON domains
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (254 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0255/1518] clk: qcom: gdsc: propagate gdsc_check_status() errors from gdsc_poll_status Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0257/1518] clk: qcom: gdsc: tear down per-domain genpds in gdsc_unregister() Greg Kroah-Hartman
` (742 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Herman van Hazendonk,
Dmitry Baryshkov, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Herman van Hazendonk <github.com@herrie.org>
[ Upstream commit eea55fc694e132aacbe2cf4be7f345115e3d1801 ]
GENPD_FLAG_ALWAYS_ON requires the underlying domain to be on at
genpd_init() time -- the framework will refuse to register the domain
otherwise. When the cold readback in gdsc_init() finds an ALWAYS_ON
GDSC powered down, the driver tries to bring it back up:
} else if (sc->flags & ALWAYS_ON) {
/* If ALWAYS_ON GDSCs are not ON, turn them ON */
gdsc_enable(&sc->pd);
on = true;
}
but discards the return value: if gdsc_enable() fails (regmap write
error, the long-form sequence's status poll times out, or the
HW_CTRL hand-off errors) the code still sets on=true and falls
through to pm_genpd_init(..., !on) -- which then registers the
domain in the ON state and sets GENPD_FLAG_ALWAYS_ON, even though
the silicon is actually off. Subsequent consumer probes will see
genpd report "on" while accessing dead registers and hang or read
garbage.
Catch the failure and surface it: returning the error from
gdsc_init() makes the provider probe fail with the underlying errno,
which propagates to consumers as -EPROBE_DEFER (or fatal if the
hardware really is broken) rather than silently lying about the
rail state.
Signed-off-by: Herman van Hazendonk <github.com@herrie.org>
Fixes: fb55bea1fe43 ("clk: qcom: gdsc: Add support for ALWAYS_ON gdscs")
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260602140934.796697-3-github.com@herrie.org
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/qcom/gdsc.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/clk/qcom/gdsc.c b/drivers/clk/qcom/gdsc.c
index b9b47f584f6d1..a80a489763edc 100644
--- a/drivers/clk/qcom/gdsc.c
+++ b/drivers/clk/qcom/gdsc.c
@@ -481,7 +481,9 @@ static int gdsc_init(struct gdsc *sc)
} else if (sc->flags & ALWAYS_ON) {
/* If ALWAYS_ON GDSCs are not ON, turn them ON */
- gdsc_enable(&sc->pd);
+ ret = gdsc_enable(&sc->pd);
+ if (ret)
+ return ret;
on = true;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0257/1518] clk: qcom: gdsc: tear down per-domain genpds in gdsc_unregister()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (255 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0256/1518] clk: qcom: gdsc: propagate gdsc_enable() failure for ALWAYS_ON domains Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0258/1518] arm64: dts: qcom: sc8280xp-arcata: Fix top USB-C DP alt mode Greg Kroah-Hartman
` (741 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Herman van Hazendonk,
Dmitry Baryshkov, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Herman van Hazendonk <github.com@herrie.org>
[ Upstream commit 86b23609d5e17a770d03037e53c6a443e742a6e6 ]
gdsc_unregister() removes the OF provider entry and tears down the
parent/subdomain wiring, but never calls pm_genpd_remove() on the
individual generic_pm_domain structures registered by gdsc_init():
void gdsc_unregister(struct gdsc_desc *desc)
{
struct device *dev = desc->dev;
size_t num = desc->num;
gdsc_pm_subdomain_remove(desc, num);
of_genpd_del_provider(dev->of_node);
}
That leaves dangling entries on the global gpd_list. After a provider
unbind/rebind cycle (deferred-probe replay during early boot, real
module unload of a clk driver that owns GDSCs, or an OF-overlay tear-
down) the next gdsc_init() will end up trying to re-register a name
that is still in the list and pm_genpd_init() returns -EEXIST.
While we are here, flip the order so the consumer-facing OF provider
entry is the first thing removed -- otherwise a fresh
of_genpd_get_from_provider() call racing with the teardown could
attach to a domain that is mid-removal.
Iterate the scs[] array and pm_genpd_remove() each registered domain
after the subdomain links are torn down. The regulators stay devm-
managed (devm_regulator_get_optional() in gdsc_register()), so the
release happens automatically when the underlying device is unbound;
just the genpd accounting needs to be undone explicitly.
Signed-off-by: Herman van Hazendonk <github.com@herrie.org>
Fixes: 45dd0e55317c ("clk: qcom: Add support for GDSCs")
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260602140934.796697-4-github.com@herrie.org
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/qcom/gdsc.c | 10 +++++++++-
1 file changed, 9 insertions(+), 1 deletion(-)
diff --git a/drivers/clk/qcom/gdsc.c b/drivers/clk/qcom/gdsc.c
index a80a489763edc..71826ccbd9bd1 100644
--- a/drivers/clk/qcom/gdsc.c
+++ b/drivers/clk/qcom/gdsc.c
@@ -645,10 +645,18 @@ int gdsc_register(struct gdsc_desc *desc,
void gdsc_unregister(struct gdsc_desc *desc)
{
struct device *dev = desc->dev;
+ struct gdsc **scs = desc->scs;
size_t num = desc->num;
+ int i;
- gdsc_pm_subdomain_remove(desc, num);
of_genpd_del_provider(dev->of_node);
+ gdsc_pm_subdomain_remove(desc, num);
+
+ for (i = 0; i < num; i++) {
+ if (!scs[i])
+ continue;
+ pm_genpd_remove(&scs[i]->pd);
+ }
}
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0258/1518] arm64: dts: qcom: sc8280xp-arcata: Fix top USB-C DP alt mode
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (256 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0257/1518] clk: qcom: gdsc: tear down per-domain genpds in gdsc_unregister() Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0259/1518] arm64: dts: qcom: sc8180x-primus: Rename regulator nodes Greg Kroah-Hartman
` (740 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jens Glathe, Konrad Dybcio,
Jérôme de Bretagne, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jérôme de Bretagne <jerome.debretagne@gmail.com>
[ Upstream commit 16065c4ec1e7ca595f4fa363dc2251c6bdf1f6b3 ]
The top USB-C port (usb0) didn't switch to DP alt mode, as reusing the
same GPIO 101 as on the SC8280XP CRD or Lenovo ThinkPad X13s was not
working on the Surface Pro 9 5G.
Investigation [1] by Jens on the Windows Dev Kit (WDK2023), the other
sc8280xp-based "blackrock" model from Microsoft, found a reference
to GPIO 100 in the DSDT in addition to 101. Switching to GPIO 100
fixed the issue on blackrock, as it does on arcata to enable
external screen when using the left-side top USB-C port.
[1] https://lore.kernel.org/all/20250609-blackrock-usb0-mux-v1-1-7903c3b071e4@oldschoolsolutions.biz/
Cc: Jens Glathe <jens.glathe@oldschoolsolutions.biz>
Fixes: f6231a2eefd4 ("arm64: dts: qcom: sc8280xp: Add Microsoft Surface Pro 9 5G")
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Jérôme de Bretagne <jerome.debretagne@gmail.com>
Link: https://lore.kernel.org/r/20260604-surface-sp9-5g-for-next-v3-4-6aa6f6612c10@gmail.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sc8280xp-microsoft-arcata.dts | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sc8280xp-microsoft-arcata.dts b/arch/arm64/boot/dts/qcom/sc8280xp-microsoft-arcata.dts
index aeed3ef152eba..cdc2b0dcca27b 100644
--- a/arch/arm64/boot/dts/qcom/sc8280xp-microsoft-arcata.dts
+++ b/arch/arm64/boot/dts/qcom/sc8280xp-microsoft-arcata.dts
@@ -248,7 +248,7 @@ map1 {
usb0-sbu-mux {
compatible = "pericom,pi3usb102", "gpio-sbu-mux";
- enable-gpios = <&tlmm 101 GPIO_ACTIVE_LOW>;
+ enable-gpios = <&tlmm 100 GPIO_ACTIVE_LOW>;
select-gpios = <&tlmm 164 GPIO_ACTIVE_HIGH>;
pinctrl-0 = <&usb0_sbu_default>;
@@ -1002,7 +1002,7 @@ tx-pins {
usb0_sbu_default: usb0-sbu-state {
oe-n-pins {
- pins = "gpio101";
+ pins = "gpio100";
function = "gpio";
bias-disable;
drive-strength = <16>;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0259/1518] arm64: dts: qcom: sc8180x-primus: Rename regulator nodes
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (257 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0258/1518] arm64: dts: qcom: sc8280xp-arcata: Fix top USB-C DP alt mode Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0260/1518] arm64: dts: qcom: sc8180x-primus: Describe the display power net Greg Kroah-Hartman
` (739 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dmitry Baryshkov, Konrad Dybcio,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
[ Upstream commit ae51d9396f9318189e91578878409d8ada152edb ]
The nodes would be sorted correctly, if their names started with
"regulator-" (which is the style used in the latest submissions).
Touch that up.
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260616-topic-8180_disp_power-v2-1-167785993231@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Stable-dep-of: 80bf2eb87bfb ("arm64: dts: qcom: sc8180x-primus: Describe the display power net")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sc8180x-primus.dts | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sc8180x-primus.dts b/arch/arm64/boot/dts/qcom/sc8180x-primus.dts
index 93de9fe918ebd..4ff5d659e5b44 100644
--- a/arch/arm64/boot/dts/qcom/sc8180x-primus.dts
+++ b/arch/arm64/boot/dts/qcom/sc8180x-primus.dts
@@ -165,7 +165,7 @@ reserved-region@9a500000 {
};
};
- vreg_nvme_0p9: nvme-0p9-regulator {
+ vreg_nvme_0p9: regulator-nvme-0p9 {
compatible = "regulator-fixed";
regulator-name = "vreg_nvme_0p9";
@@ -175,7 +175,7 @@ vreg_nvme_0p9: nvme-0p9-regulator {
regulator-always-on;
};
- vreg_nvme_3p3: nvme-3p3-regulator {
+ vreg_nvme_3p3: regulator-nvme-3p3 {
compatible = "regulator-fixed";
regulator-name = "vreg_nvme_3p3";
@@ -188,7 +188,7 @@ vreg_nvme_3p3: nvme-3p3-regulator {
regulator-always-on;
};
- vdd_kb_tp_3v3: vdd-kb-tp-3v3-regulator {
+ vdd_kb_tp_3v3: regulator-vdd-kb-tp-3v3 {
compatible = "regulator-fixed";
regulator-name = "vdd_kb_tp_3v3";
regulator-min-microvolt = <3300000>;
@@ -203,7 +203,7 @@ vdd_kb_tp_3v3: vdd-kb-tp-3v3-regulator {
pinctrl-0 = <&kb_tp_3v3_en_active_state>;
};
- vph_pwr: vph-pwr-regulator {
+ vph_pwr: regulator-vph-pwr {
compatible = "regulator-fixed";
regulator-name = "vph_pwr";
regulator-min-microvolt = <3700000>;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0260/1518] arm64: dts: qcom: sc8180x-primus: Describe the display power net
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (258 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0259/1518] arm64: dts: qcom: sc8180x-primus: Rename regulator nodes Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0261/1518] arm64: dts: qcom: sc8180x-lenovo-flex-5g: Rename regulator nodes Greg Kroah-Hartman
` (738 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Bjorn Andersson,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
[ Upstream commit 80bf2eb87bfbf1b7bc7b12228cbcc710b0a26275 ]
Describe and wire up the power supplies for the eDP panel and its
backlight. Previously, this was only working because of settings
inherited from the bootloader.
Fixes: 2ce38cc1e8fe ("arm64: dts: qcom: sc8180x: Introduce Primus")
Signed-off-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260616-topic-8180_disp_power-v2-2-167785993231@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sc8180x-primus.dts | 48 ++++++++++++++++++++-
1 file changed, 47 insertions(+), 1 deletion(-)
diff --git a/arch/arm64/boot/dts/qcom/sc8180x-primus.dts b/arch/arm64/boot/dts/qcom/sc8180x-primus.dts
index 4ff5d659e5b44..76679e311ecf9 100644
--- a/arch/arm64/boot/dts/qcom/sc8180x-primus.dts
+++ b/arch/arm64/boot/dts/qcom/sc8180x-primus.dts
@@ -27,9 +27,10 @@ backlight: backlight {
compatible = "pwm-backlight";
pwms = <&pmc8180c_lpg 4 1000000>;
enable-gpios = <&pmc8180c_gpios 8 GPIO_ACTIVE_HIGH>;
+ power-supply = <&vled_bl_pw>;
- pinctrl-names = "default";
pinctrl-0 = <&bl_pwm_default>;
+ pinctrl-names = "default";
};
chosen {
@@ -165,6 +166,38 @@ reserved-region@9a500000 {
};
};
+ vled_bl_pw: regulator-vled-bl-pw {
+ compatible = "regulator-fixed";
+
+ regulator-name = "VLED_BL_PW";
+ regulator-min-microvolt = <3300000>;
+ regulator-max-microvolt = <3300000>;
+
+ gpio = <&pmc8180_2_gpios 1 GPIO_ACTIVE_HIGH>;
+ enable-active-high;
+
+ pinctrl-0 = <&bl_pwr_en>;
+ pinctrl-names = "default";
+
+ regulator-boot-on;
+ };
+
+ vreg_lcm_3v3: regulator-edp-3p3 {
+ compatible = "regulator-fixed";
+
+ regulator-name = "VREG_LCM_3V3";
+ regulator-min-microvolt = <3300000>;
+ regulator-max-microvolt = <3300000>;
+
+ gpio = <&tlmm 130 GPIO_ACTIVE_HIGH>;
+ enable-active-high;
+
+ pinctrl-0 = <&lcm_3v3_en>;
+ pinctrl-names = "default";
+
+ regulator-boot-on;
+ };
+
vreg_nvme_0p9: regulator-nvme-0p9 {
compatible = "regulator-fixed";
regulator-name = "vreg_nvme_0p9";
@@ -539,6 +572,7 @@ &mdss_edp {
aux-bus {
panel {
compatible = "edp-panel";
+ power-supply = <&vreg_lcm_3v3>;
backlight = <&backlight>;
@@ -768,6 +802,12 @@ &wifi {
};
/* PINCTRL */
+&pmc8180_2_gpios {
+ bl_pwr_en: bl-pwr-en-state {
+ pins = "gpio1";
+ function = "normal";
+ };
+};
&pmc8180c_gpios {
bl_pwm_default: bl-pwm-default-state {
@@ -949,4 +989,10 @@ rx-pins {
bias-pull-up;
};
};
+
+ lcm_3v3_en: lcm-3v3-en-state {
+ pins = "gpio130";
+ function = "gpio";
+ bias-disable;
+ };
};
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0261/1518] arm64: dts: qcom: sc8180x-lenovo-flex-5g: Rename regulator nodes
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (259 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0260/1518] arm64: dts: qcom: sc8180x-primus: Describe the display power net Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0262/1518] arm64: dts: qcom: sc8180x-lenovo-flex-5g: Describe the display power net Greg Kroah-Hartman
` (737 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dmitry Baryshkov, Konrad Dybcio,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
[ Upstream commit 0b1c6d2a65fc41aa0d5f6617dd04043384678d61 ]
Align with the contemporary way of naming regulator nodes (regulator-
prefix) in preparation for adding more of them.
Reorder the renamed entries to match the expectations of the DT coding
style doc.
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260616-topic-8180_disp_power-v2-3-167785993231@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Stable-dep-of: d5f5c089858f ("arm64: dts: qcom: sc8180x-lenovo-flex-5g: Describe the display power net")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../boot/dts/qcom/sc8180x-lenovo-flex-5g.dts | 16 ++++++++--------
1 file changed, 8 insertions(+), 8 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sc8180x-lenovo-flex-5g.dts b/arch/arm64/boot/dts/qcom/sc8180x-lenovo-flex-5g.dts
index 08d0784d0cbb8..ae5f51d8c896a 100644
--- a/arch/arm64/boot/dts/qcom/sc8180x-lenovo-flex-5g.dts
+++ b/arch/arm64/boot/dts/qcom/sc8180x-lenovo-flex-5g.dts
@@ -162,14 +162,7 @@ cdsp_mem: cdsp-region@98900000 {
};
};
- vph_pwr: vph-pwr-regulator {
- compatible = "regulator-fixed";
- regulator-name = "vph_pwr";
- regulator-min-microvolt = <3700000>;
- regulator-max-microvolt = <3700000>;
- };
-
- vreg_s4a_1p8: pm8150-s4-regulator {
+ vreg_s4a_1p8: regulator-pm8150-s4 {
compatible = "regulator-fixed";
regulator-name = "vreg_s4a_1p8";
@@ -182,6 +175,13 @@ vreg_s4a_1p8: pm8150-s4-regulator {
vin-supply = <&vph_pwr>;
};
+ vph_pwr: regulator-vph-pwr {
+ compatible = "regulator-fixed";
+ regulator-name = "vph_pwr";
+ regulator-min-microvolt = <3700000>;
+ regulator-max-microvolt = <3700000>;
+ };
+
usbprim-sbu-mux {
compatible = "pericom,pi3usb102", "gpio-sbu-mux";
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0262/1518] arm64: dts: qcom: sc8180x-lenovo-flex-5g: Describe the display power net
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (260 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0261/1518] arm64: dts: qcom: sc8180x-lenovo-flex-5g: Rename regulator nodes Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0263/1518] clk: qcom: gcc-qcs8300: Use retention for PCIe power domains Greg Kroah-Hartman
` (736 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Bjorn Andersson,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
[ Upstream commit d5f5c089858f7accd1e4574c0c09d811e90eb51f ]
Describe and wire up the power supplies for the eDP panel and its
backlight. Previously, this was only working because of settings
inherited from the bootloader.
Fixes: 20dea72a393c ("arm64: dts: qcom: sc8180x: Introduce Lenovo Flex 5G")
Signed-off-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260616-topic-8180_disp_power-v2-4-167785993231@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../boot/dts/qcom/sc8180x-lenovo-flex-5g.dts | 47 +++++++++++++++++++
1 file changed, 47 insertions(+)
diff --git a/arch/arm64/boot/dts/qcom/sc8180x-lenovo-flex-5g.dts b/arch/arm64/boot/dts/qcom/sc8180x-lenovo-flex-5g.dts
index ae5f51d8c896a..8f8f66a2297e5 100644
--- a/arch/arm64/boot/dts/qcom/sc8180x-lenovo-flex-5g.dts
+++ b/arch/arm64/boot/dts/qcom/sc8180x-lenovo-flex-5g.dts
@@ -26,6 +26,7 @@ backlight: backlight {
compatible = "pwm-backlight";
pwms = <&pmc8180c_lpg 4 1000000>;
enable-gpios = <&pmc8180c_gpios 8 GPIO_ACTIVE_HIGH>;
+ power-supply = <&vled_bl_pw>;
pinctrl-0 = <&bl_pwm_default>;
pinctrl-names = "default";
@@ -162,6 +163,38 @@ cdsp_mem: cdsp-region@98900000 {
};
};
+ vled_bl_pw: regulator-vled-bl-pw {
+ compatible = "regulator-fixed";
+
+ regulator-name = "VLED_BL_PW";
+ regulator-min-microvolt = <3300000>;
+ regulator-max-microvolt = <3300000>;
+
+ gpio = <&pmc8180_2_gpios 1 GPIO_ACTIVE_HIGH>;
+ enable-active-high;
+
+ pinctrl-0 = <&bl_pwr_en>;
+ pinctrl-names = "default";
+
+ regulator-boot-on;
+ };
+
+ vreg_lcm_3v3: regulator-edp-3p3 {
+ compatible = "regulator-fixed";
+
+ regulator-name = "VREG_LCM_3V3";
+ regulator-min-microvolt = <3300000>;
+ regulator-max-microvolt = <3300000>;
+
+ gpio = <&tlmm 130 GPIO_ACTIVE_HIGH>;
+ enable-active-high;
+
+ pinctrl-0 = <&lcm_3v3_en>;
+ pinctrl-names = "default";
+
+ regulator-boot-on;
+ };
+
vreg_s4a_1p8: regulator-pm8150-s4 {
compatible = "regulator-fixed";
regulator-name = "vreg_s4a_1p8";
@@ -444,6 +477,7 @@ &mdss_edp {
aux-bus {
panel {
compatible = "edp-panel";
+ power-supply = <&vreg_lcm_3v3>;
no-hpd;
backlight = <&backlight>;
@@ -478,6 +512,13 @@ &pcie3_phy {
status = "okay";
};
+&pmc8180_2_gpios {
+ bl_pwr_en: bl-pwr-en-state {
+ pins = "gpio1";
+ function = "normal";
+ };
+};
+
&pmc8180_pwrkey {
status = "okay";
};
@@ -771,6 +812,12 @@ ts_int_default: ts-int-default-state {
drive-strength = <2>;
};
+ lcm_3v3_en: lcm-3v3-en-state {
+ pins = "gpio130";
+ function = "gpio";
+ bias-disable;
+ };
+
usbprim_sbu_default: usbprim-sbu-state {
oe-n-pins {
pins = "gpio152";
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0263/1518] clk: qcom: gcc-qcs8300: Use retention for PCIe power domains
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (261 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0262/1518] arm64: dts: qcom: sc8180x-lenovo-flex-5g: Describe the display power net Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0264/1518] clk: qcom: gcc-qcs8300: Use retention for USB " Greg Kroah-Hartman
` (735 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Loic Poulain, Konrad Dybcio,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Loic Poulain <loic.poulain@oss.qualcomm.com>
[ Upstream commit 11b170abe4d324cac0d15a410282d1ec2b6bafa0 ]
As the PCIe host controller driver does not yet support dealing with the
loss of state during suspend, use retention for relevant GDSCs.
Fix the PCIe link not surviving upon resume, and GDSC error:
gcc_pcie_0_gdsc status stuck at 'off'
Fixes: 95eeb2ffce73 ("clk: qcom: Add support for Global Clock Controller on QCS8300")
Signed-off-by: Loic Poulain <loic.poulain@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260629-monza-suspend-v1-1-b601d8a2f2f8@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/qcom/gcc-qcs8300.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/clk/qcom/gcc-qcs8300.c b/drivers/clk/qcom/gcc-qcs8300.c
index 80831c7dea3bc..009672b75fb90 100644
--- a/drivers/clk/qcom/gcc-qcs8300.c
+++ b/drivers/clk/qcom/gcc-qcs8300.c
@@ -3268,7 +3268,7 @@ static struct gdsc gcc_pcie_0_gdsc = {
.pd = {
.name = "gcc_pcie_0_gdsc",
},
- .pwrsts = PWRSTS_OFF_ON,
+ .pwrsts = PWRSTS_RET_ON,
.flags = VOTABLE | RETAIN_FF_ENABLE | POLL_CFG_GDSCR,
};
@@ -3282,7 +3282,7 @@ static struct gdsc gcc_pcie_1_gdsc = {
.pd = {
.name = "gcc_pcie_1_gdsc",
},
- .pwrsts = PWRSTS_OFF_ON,
+ .pwrsts = PWRSTS_RET_ON,
.flags = VOTABLE | RETAIN_FF_ENABLE | POLL_CFG_GDSCR,
};
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0264/1518] clk: qcom: gcc-qcs8300: Use retention for USB power domains
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (262 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0263/1518] clk: qcom: gcc-qcs8300: Use retention for PCIe power domains Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0265/1518] perf data convert json: Fix trace_seq memory leak in process_sample_event() Greg Kroah-Hartman
` (734 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Loic Poulain, Konrad Dybcio,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Loic Poulain <loic.poulain@oss.qualcomm.com>
[ Upstream commit d8638610e0c9ebab2800b7ad6c2c2a3737090da9 ]
The USB subsystem does not expect to lose its state on suspend:
xhci-hcd xhci-hcd.1.auto: xHC error in resume, USBSTS 0x401, Reinit
usb usb1: root hub lost power or was reset
To maintain state during suspend, the relevant GDSCs need to stay in
retention mode, like they do on other similar SoCs. Change the mode to
PWRSTS_RET_ON to fix.
Fixes: 95eeb2ffce73 ("clk: qcom: Add support for Global Clock Controller on QCS8300")
Signed-off-by: Loic Poulain <loic.poulain@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260629-monza-suspend-v1-2-b601d8a2f2f8@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/qcom/gcc-qcs8300.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/clk/qcom/gcc-qcs8300.c b/drivers/clk/qcom/gcc-qcs8300.c
index 009672b75fb90..fe0632687f9f0 100644
--- a/drivers/clk/qcom/gcc-qcs8300.c
+++ b/drivers/clk/qcom/gcc-qcs8300.c
@@ -3306,7 +3306,7 @@ static struct gdsc gcc_usb20_prim_gdsc = {
.pd = {
.name = "gcc_usb20_prim_gdsc",
},
- .pwrsts = PWRSTS_OFF_ON,
+ .pwrsts = PWRSTS_RET_ON,
.flags = RETAIN_FF_ENABLE | POLL_CFG_GDSCR,
};
@@ -3318,7 +3318,7 @@ static struct gdsc gcc_usb30_prim_gdsc = {
.pd = {
.name = "gcc_usb30_prim_gdsc",
},
- .pwrsts = PWRSTS_OFF_ON,
+ .pwrsts = PWRSTS_RET_ON,
.flags = RETAIN_FF_ENABLE | POLL_CFG_GDSCR,
};
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0265/1518] perf data convert json: Fix trace_seq memory leak in process_sample_event()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (263 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0264/1518] clk: qcom: gcc-qcs8300: Use retention for USB " Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0266/1518] staging: media: ipu7: fix pm_runtime refcount leak in ipu7_init_fw_code_region_by_sys() Greg Kroah-Hartman
` (733 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tanushree Shah, Namhyung Kim,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tanushree Shah <tshah@linux.ibm.com>
[ Upstream commit dcb87c88952046ef43cb5ba3a5b95eb29c362a16 ]
Unlike the in-kernel trace_seq which uses a statically allocated buffer,
the userspace traceevent library's trace_seq uses a dynamically allocated
one. Therefore, every trace_seq_init() call must be paired with a
trace_seq_destroy(), otherwise it produces a memory leak.
In process_sample_event(), a trace_seq is initialized for each field when
formatting tracepoint raw_data, but the matching trace_seq_destroy() is
never called, leaking memory for every field of every sample processed.
Add the missing trace_seq_destroy() after using the trace_seq buffer to
properly free the allocated memory.
Detected with Valgrind on a perf.data file with 2,729 tracepoint samples:
Before: definitely lost: 55,537,664 bytes in 13,559 blocks
After: definitely lost: 0 bytes in 0 blocks
Fixes: 9d895e468429 ("perf data: Add tracepoint fields when converting to JSON")
Signed-off-by: Tanushree Shah <tshah@linux.ibm.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/data-convert-json.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/tools/perf/util/data-convert-json.c b/tools/perf/util/data-convert-json.c
index 9dc1e184cf3c9..9c96d84df900a 100644
--- a/tools/perf/util/data-convert-json.c
+++ b/tools/perf/util/data-convert-json.c
@@ -242,6 +242,7 @@ static int process_sample_event(const struct perf_tool *tool,
trace_seq_init(&s);
tep_print_field(&s, sample->raw_data, fields[i]);
output_json_key_string(out, true, 3, fields[i]->name, s.buffer);
+ trace_seq_destroy(&s);
i++;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0266/1518] staging: media: ipu7: fix pm_runtime refcount leak in ipu7_init_fw_code_region_by_sys()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (264 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0265/1518] perf data convert json: Fix trace_seq memory leak in process_sample_event() Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0267/1518] staging: media: ipu7: fix pm_runtime refcount leak in ipu7_resume() Greg Kroah-Hartman
` (732 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Vidhu Sarwal, Sakari Ailus,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vidhu Sarwal <vidhu.linux@gmail.com>
[ Upstream commit 843644e1c3347670498d247d7cd20dff1569181c ]
ipu7_init_fw_code_region_by_sys() calls pm_runtime_get_sync() before
accessing the firmware code region. If resuming the device fails,
pm_runtime_get_sync() leaves the runtime PM usage count incremented,
but the error path returns without dropping the reference.
Use pm_runtime_resume_and_get() instead, which balances the usage count
automatically on failure and avoids the leak.
The ipu6 driver uses pm_runtime_resume_and_get() in the equivalent
location.
Fixes: b7fe4c0019b1 ("media: staging/ipu7: add Intel IPU7 PCI device driver")
Signed-off-by: Vidhu Sarwal <vidhu.linux@gmail.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/staging/media/ipu7/ipu7.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/staging/media/ipu7/ipu7.c b/drivers/staging/media/ipu7/ipu7.c
index 8ec571c6bd07f..83e73fac3a7e0 100644
--- a/drivers/staging/media/ipu7/ipu7.c
+++ b/drivers/staging/media/ipu7/ipu7.c
@@ -2343,7 +2343,7 @@ static int ipu7_init_fw_code_region_by_sys(struct ipu7_bus_device *sys,
return ret;
}
- ret = pm_runtime_get_sync(dev);
+ ret = pm_runtime_resume_and_get(dev);
if (ret < 0) {
dev_err(dev, "Failed to get runtime PM\n");
return ret;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0267/1518] staging: media: ipu7: fix pm_runtime refcount leak in ipu7_resume()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (265 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0266/1518] staging: media: ipu7: fix pm_runtime refcount leak in ipu7_init_fw_code_region_by_sys() Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0268/1518] thermal/drivers/rcar: Fix error checking in probe() Greg Kroah-Hartman
` (731 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Vidhu Sarwal, Sakari Ailus,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vidhu Sarwal <vidhu.linux@gmail.com>
[ Upstream commit b298b80814dd0fc3cb1c8c0e0082fc14fdb5fecf ]
ipu7_resume() calls pm_runtime_get_sync() before resuming the device.
If the runtime PM resume fails, the usage count remains incremented, but
the error path returns without dropping the reference.
Use pm_runtime_resume_and_get() instead, which balances the usage count
on failure and avoids the leak. Keep returning 0 on error, as resume
callbacks should not propagate failures to the PM core, matching the
behaviour of the ipu6 driver.
Fixes: b7fe4c0019b1 ("media: staging/ipu7: add Intel IPU7 PCI device driver")
Signed-off-by: Vidhu Sarwal <vidhu.linux@gmail.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/staging/media/ipu7/ipu7.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/staging/media/ipu7/ipu7.c b/drivers/staging/media/ipu7/ipu7.c
index 83e73fac3a7e0..34fe95145c826 100644
--- a/drivers/staging/media/ipu7/ipu7.c
+++ b/drivers/staging/media/ipu7/ipu7.c
@@ -2702,7 +2702,7 @@ static int ipu7_resume(struct device *dev)
if (ret)
dev_err(dev, "IPC reset protocol failed!\n");
- ret = pm_runtime_get_sync(&isp->psys->auxdev.dev);
+ ret = pm_runtime_resume_and_get(&isp->psys->auxdev.dev);
if (ret < 0) {
dev_err(dev, "Failed to get runtime PM\n");
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0268/1518] thermal/drivers/rcar: Fix error checking in probe()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (266 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0267/1518] staging: media: ipu7: fix pm_runtime refcount leak in ipu7_resume() Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0269/1518] usb: typec: ucsi: unregister debugfs entries on teardown Greg Kroah-Hartman
` (730 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Geert Uytterhoeven,
Niklas Söderlund, Dan Carpenter, Daniel Lezcano, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dan Carpenter <error27@gmail.com>
[ Upstream commit dd04ad1cdabcad51e34b74b4e91b9aeb7180d05d ]
This code accidentally calls thermal_zone_device_enable() before checking
whether thermal_zone_device_register_with_trips() failed. Move the call
until later to avoid an error pointer dereference of "priv->zone".
The driver works differently depending on if we are using OF thermal or
not. We use thermal_add_hwmon_sysfs() if we are using OF thermal and
call thermal_zone_device_enable() if not. We can share same error check
for if either of these fail.
Moving the thermal_zone_device_enable() call is a bit cleaner as well.
The original code used a three step process to cleanup:
1. Call thermal_zone_device_unregister() to cleanup.
2. Set priv->zone to an error pointer to preserve the error code.
3. Set priv->zone to NULL to avoid a second call to
thermal_zone_device_unregister() in the rcar_thermal_remove()
function.
Now we can just do a direct goto error_unregister and rcar_thermal_remove()
handles the cleanup properly.
Fixes: bbcf90c0646a ("thermal: Explicitly enable non-changing thermal zone devices")
Reviewed-by: Geert Uytterhoeven <geert+renesas@glider.be>
Reviewed-by: Niklas Söderlund <niklas.soderlund+renesas@ragnatech.se>
Signed-off-by: Dan Carpenter <error27@gmail.com>
Signed-off-by: Daniel Lezcano <daniel.lezcano@kernel.org>
Link: https://patch.msgid.link/aj5WnseULiwgmlWv@stanley.mountain
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/thermal/renesas/rcar_thermal.c | 15 +++++----------
1 file changed, 5 insertions(+), 10 deletions(-)
diff --git a/drivers/thermal/renesas/rcar_thermal.c b/drivers/thermal/renesas/rcar_thermal.c
index fdd7afdc4ff69..27adc64757f55 100644
--- a/drivers/thermal/renesas/rcar_thermal.c
+++ b/drivers/thermal/renesas/rcar_thermal.c
@@ -492,12 +492,6 @@ static int rcar_thermal_probe(struct platform_device *pdev)
"rcar_thermal", trips, ARRAY_SIZE(trips), priv,
&rcar_thermal_zone_ops, NULL, 0,
idle);
-
- ret = thermal_zone_device_enable(priv->zone);
- if (ret) {
- thermal_zone_device_unregister(priv->zone);
- priv->zone = ERR_PTR(ret);
- }
}
if (IS_ERR(priv->zone)) {
dev_err(dev, "can't register thermal zone\n");
@@ -506,11 +500,12 @@ static int rcar_thermal_probe(struct platform_device *pdev)
goto error_unregister;
}
- if (chip->use_of_thermal) {
+ if (chip->use_of_thermal)
ret = thermal_add_hwmon_sysfs(priv->zone);
- if (ret)
- goto error_unregister;
- }
+ else
+ ret = thermal_zone_device_enable(priv->zone);
+ if (ret)
+ goto error_unregister;
rcar_thermal_irq_enable(priv);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0269/1518] usb: typec: ucsi: unregister debugfs entries on teardown
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (267 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0268/1518] thermal/drivers/rcar: Fix error checking in probe() Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0270/1518] usb: gadget: r8a66597: avoid double free of ep0_req in probe error path Greg Kroah-Hartman
` (729 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bjorn Andersson, Konrad Dybcio,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bjorn Andersson <bjorn.andersson@oss.qualcomm.com>
[ Upstream commit eed73a65ab609b79d53de88cccc34b36dfe753c4 ]
ucsi_register() creates per-instance debugfs entries, but
ucsi_unregister() keeps them around until ucsi_destroy().
Drivers like ucsi_glink that unregister/register the same UCSI
instance across remoteproc restart then try to create an already
existing debugfs directory and log:
debugfs: 'pmic_glink.ucsi.0' already exists in 'ucsi'
Unregister debugfs entries as part of ucsi_unregister(), and
clear ucsi->debugfs after freeing it so repeated unregister
paths remain safe.
Assisted-by: Codex:GPT-5.5
Signed-off-by: Bjorn Andersson <bjorn.andersson@oss.qualcomm.com>
Fixes: df0383ffad64 ("usb: typec: ucsi: Add debugfs for ucsi commands")
Tested-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com> # X1E80100 CRD
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://patch.msgid.link/20260611-usci-unregister-debugfs-v1-1-f4a518a94f27@oss.qualcomm.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/usb/typec/ucsi/debugfs.c | 1 +
drivers/usb/typec/ucsi/ucsi.c | 2 ++
2 files changed, 3 insertions(+)
diff --git a/drivers/usb/typec/ucsi/debugfs.c b/drivers/usb/typec/ucsi/debugfs.c
index f73f2b54554e2..414ffe1d23780 100644
--- a/drivers/usb/typec/ucsi/debugfs.c
+++ b/drivers/usb/typec/ucsi/debugfs.c
@@ -129,6 +129,7 @@ void ucsi_debugfs_unregister(struct ucsi *ucsi)
debugfs_remove_recursive(ucsi->debugfs->dentry);
kfree(ucsi->debugfs);
+ ucsi->debugfs = NULL;
}
void ucsi_debugfs_init(void)
diff --git a/drivers/usb/typec/ucsi/ucsi.c b/drivers/usb/typec/ucsi/ucsi.c
index 85e2e7fcd02cd..2acd48a0a6a2b 100644
--- a/drivers/usb/typec/ucsi/ucsi.c
+++ b/drivers/usb/typec/ucsi/ucsi.c
@@ -2275,6 +2275,8 @@ void ucsi_unregister(struct ucsi *ucsi)
cancel_delayed_work_sync(&ucsi->work);
cancel_work_sync(&ucsi->resume_work);
+ ucsi_debugfs_unregister(ucsi);
+
/* Disable notifications */
ucsi->ops->async_control(ucsi, cmd);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0270/1518] usb: gadget: r8a66597: avoid double free of ep0_req in probe error path
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (268 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0269/1518] usb: typec: ucsi: unregister debugfs entries on teardown Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0271/1518] udf: Mark LVID buffer as uptodate before marking it dirty Greg Kroah-Hartman
` (728 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Hongyan Xu, Slavin Liu, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hongyan Xu <getshell@seu.edu.cn>
[ Upstream commit 41d541e3718db01668a4cd29815ee4b3b55f76d2 ]
If usb_add_gadget_udc() fails, r8a66597_probe() jumps to err_add_udc
and frees ep0_req, then falls through to clean_up2 where ep0_req is
freed again when it is non-NULL.
Remove the redundant free from err_add_udc and keep the cleanup in
clean_up2 so the request is released exactly once.
Fixes: 776976a67ae2 ("usb: gadget: r8a66597-udc: cleanup error path")
Issue found using a prototype static analysis tool
and confirmed by code review.
Signed-off-by: Hongyan Xu <getshell@seu.edu.cn>
Signed-off-by: Slavin Liu <220245772@seu.edu.cn>
Link: https://patch.msgid.link/20260624140908.1282-1-getshell@seu.edu.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/usb/gadget/udc/r8a66597-udc.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/drivers/usb/gadget/udc/r8a66597-udc.c b/drivers/usb/gadget/udc/r8a66597-udc.c
index e5c2630e37114..29ae81c95d0a6 100644
--- a/drivers/usb/gadget/udc/r8a66597-udc.c
+++ b/drivers/usb/gadget/udc/r8a66597-udc.c
@@ -1951,7 +1951,6 @@ static int r8a66597_probe(struct platform_device *pdev)
return 0;
err_add_udc:
- r8a66597_free_request(&r8a66597->ep[0].ep, r8a66597->ep0_req);
clean_up2:
if (r8a66597->pdata->on_chip)
clk_disable_unprepare(r8a66597->clk);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0271/1518] udf: Mark LVID buffer as uptodate before marking it dirty
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (269 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0270/1518] usb: gadget: r8a66597: avoid double free of ep0_req in probe error path Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0272/1518] bpftool: Check EVP_Digest when computing excl_prog_hash Greg Kroah-Hartman
` (727 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+0306b38d9ed6ef71467d,
Aleksandr Nogikh, Jan Kara, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aleksandr Nogikh <nogikh@google.com>
[ Upstream commit fb0601134c7e51728bd098abc6909315de1e5d86 ]
When an I/O error occurs while writing the Logical Volume Integrity
Descriptor (LVID) buffer to the block device, the block layer's completion
handler (`end_buffer_write_sync()`) clears the `BH_Uptodate` flag on the
buffer. However, the buffer still contains valid LVID data in memory. If
the filesystem is subsequently remounted read-write or synced,
`udf_open_lvid()` or `udf_sync_fs()` will modify the LVID buffer and call
`mark_buffer_dirty()`. This triggers a spurious
`WARN_ON_ONCE(!buffer_uptodate(bh))` warning in `mark_buffer_dirty()`
because the buffer is not marked uptodate, even though its in-memory
contents are valid and are about to be overwritten.
To prevent this spurious warning, unconditionally set the `BH_Uptodate`
flag before calling `mark_buffer_dirty()` in `udf_open_lvid()` and
`udf_sync_fs()`. This acknowledges that the in-memory buffer is valid and
matches the workaround previously applied to `udf_close_lvid()` in commit
853a0c25baf9 ("udf: Mark LVID buffer as uptodate before marking it dirty").
Extending this workaround ensures consistent behavior across all LVID
updates.
Buffer I/O error on dev loop0, logical block 128, lost sync page write
------------[ cut here ]------------
!buffer_uptodate(bh)
WARNING: fs/buffer.c:1087 at mark_buffer_dirty+0x299/0x410 fs/buffer.c:1087
...
Call Trace:
<TASK>
udf_open_lvid+0x369/0x5b0 fs/udf/super.c:2078
udf_reconfigure+0x336/0x540 fs/udf/super.c:679
reconfigure_super+0x232/0x8f0 fs/super.c:1080
vfs_cmd_reconfigure fs/fsopen.c:268 [inline]
vfs_fsconfig_locked+0x171/0x320 fs/fsopen.c:297
__do_sys_fsconfig fs/fsopen.c:463 [inline]
__se_sys_fsconfig+0x6b9/0x810 fs/fsopen.c:350
do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94
</TASK>
Fixes: 853a0c25baf9 ("udf: Mark LVID buffer as uptodate before marking it dirty")
Assisted-by: Gemini:gemini-3.1-pro-preview Gemini:gemini-3-flash-preview syzbot
Reported-by: syzbot+0306b38d9ed6ef71467d@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=0306b38d9ed6ef71467d
Link: https://syzkaller.appspot.com/ai_job?id=05f8e20f-f080-4c7f-a206-08dbc15cb4a1
Signed-off-by: Aleksandr Nogikh <nogikh@google.com>
Link: https://patch.msgid.link/6ffb2ca8-e22f-4fd6-9f37-7202ec0878bd@mail.kernel.org
Signed-off-by: Jan Kara <jack@suse.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/udf/super.c | 23 ++++++++++++++---------
1 file changed, 14 insertions(+), 9 deletions(-)
diff --git a/fs/udf/super.c b/fs/udf/super.c
index 5a82ae2af93ec..ff170bc0962b5 100644
--- a/fs/udf/super.c
+++ b/fs/udf/super.c
@@ -2048,6 +2048,17 @@ static int udf_load_vrs(struct super_block *sb, struct udf_options *uopt,
return 0;
}
+static void udf_mark_buffer_dirty(struct buffer_head *bh)
+{
+ /*
+ * We set buffer uptodate unconditionally here to avoid spurious
+ * warnings from mark_buffer_dirty() when previous EIO has marked
+ * the buffer as !uptodate
+ */
+ set_buffer_uptodate(bh);
+ mark_buffer_dirty(bh);
+}
+
static void udf_finalize_lvid(struct logicalVolIntegrityDesc *lvid)
{
struct timespec64 ts;
@@ -2083,7 +2094,7 @@ static void udf_open_lvid(struct super_block *sb)
UDF_SET_FLAG(sb, UDF_FLAG_INCONSISTENT);
udf_finalize_lvid(lvid);
- mark_buffer_dirty(bh);
+ udf_mark_buffer_dirty(bh);
sbi->s_lvid_dirty = 0;
mutex_unlock(&sbi->s_alloc_mutex);
/* Make opening of filesystem visible on the media immediately */
@@ -2116,14 +2127,8 @@ static void udf_close_lvid(struct super_block *sb)
if (!UDF_QUERY_FLAG(sb, UDF_FLAG_INCONSISTENT))
lvid->integrityType = cpu_to_le32(LVID_INTEGRITY_TYPE_CLOSE);
- /*
- * We set buffer uptodate unconditionally here to avoid spurious
- * warnings from mark_buffer_dirty() when previous EIO has marked
- * the buffer as !uptodate
- */
- set_buffer_uptodate(bh);
udf_finalize_lvid(lvid);
- mark_buffer_dirty(bh);
+ udf_mark_buffer_dirty(bh);
sbi->s_lvid_dirty = 0;
mutex_unlock(&sbi->s_alloc_mutex);
/* Make closing of filesystem visible on the media immediately */
@@ -2405,7 +2410,7 @@ static int udf_sync_fs(struct super_block *sb, int wait)
* Blockdevice will be synced later so we don't have to submit
* the buffer for IO
*/
- mark_buffer_dirty(bh);
+ udf_mark_buffer_dirty(bh);
sbi->s_lvid_dirty = 0;
}
mutex_unlock(&sbi->s_alloc_mutex);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0272/1518] bpftool: Check EVP_Digest when computing excl_prog_hash
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (270 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0271/1518] udf: Mark LVID buffer as uptodate before marking it dirty Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0273/1518] perf vendor events amd: Reintroduce deprecated Zen 5 core events Greg Kroah-Hartman
` (726 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Daniel Borkmann, Quentin Monnet,
Kumar Kartikeya Dwivedi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel Borkmann <daniel@iogearbox.net>
[ Upstream commit 576bcaa1f5c208af0f590c9622247da87b49c05f ]
bpftool_prog_sign() ignores the return value of EVP_Digest(). If the
digest computation fails (context allocation failure, or a digest
fetch failure under OpenSSL), EVP_Digest() returns 0 and leaves the
output buffer untouched, but the function still reports success.
Fixes: 40863f4d6ef2 ("bpftool: Add support for signing BPF programs")
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Reviewed-by: Quentin Monnet <qmo@kernel.org>
Link: https://lore.kernel.org/bpf/20260708075343.358712-5-daniel@iogearbox.net
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/bpf/bpftool/sign.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/tools/bpf/bpftool/sign.c b/tools/bpf/bpftool/sign.c
index f9b742f4bb104..1257dba8ef2fd 100644
--- a/tools/bpf/bpftool/sign.c
+++ b/tools/bpf/bpftool/sign.c
@@ -175,8 +175,11 @@ int bpftool_prog_sign(struct bpf_load_and_run_opts *opts)
goto cleanup;
}
- EVP_Digest(opts->insns, opts->insns_sz, opts->excl_prog_hash,
- &opts->excl_prog_hash_sz, EVP_sha256(), NULL);
+ if (EVP_Digest(opts->insns, opts->insns_sz, opts->excl_prog_hash,
+ &opts->excl_prog_hash_sz, EVP_sha256(), NULL) != 1) {
+ err = -EIO;
+ goto cleanup;
+ }
bd_out = BIO_new(BIO_s_mem());
if (!bd_out) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0273/1518] perf vendor events amd: Reintroduce deprecated Zen 5 core events
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (271 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0272/1518] bpftool: Check EVP_Digest when computing excl_prog_hash Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0274/1518] perf dso: Fix kallsyms DSO detection with fallback logic Greg Kroah-Hartman
` (725 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ian Rogers, Sandipan Das,
Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sandipan Das <sandipan.das@amd.com>
[ Upstream commit eda39f98bbc5ce8b7b0be10193d2de38ed59da6c ]
Maintain backward compatibility by reintroducing the events that were
previously removed by commit 047979af3bf6 ("perf vendor events amd:
Update Zen 5 core events"). Also set the deprecated flag and update
the descriptions to point users to the correct alternative.
Reported-by: Ian Rogers <irogers@google.com>
Closes: https://lore.kernel.org/all/CAP-5=fV_czvd-z4N7K+_SabxuOm9UUHRyBxNuchrtAgJL3OqOw@mail.gmail.com/
Fixes: 047979af3bf6 ("perf vendor events amd: Update Zen 5 core events")
Signed-off-by: Sandipan Das <sandipan.das@amd.com>
Reviewed-by: Ian Rogers <irogers@google.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../arch/x86/amdzen5/floating-point.json | 42 +++++++++++++++++++
1 file changed, 42 insertions(+)
diff --git a/tools/perf/pmu-events/arch/x86/amdzen5/floating-point.json b/tools/perf/pmu-events/arch/x86/amdzen5/floating-point.json
index 569975b53cc33..50d38434f8d3d 100644
--- a/tools/perf/pmu-events/arch/x86/amdzen5/floating-point.json
+++ b/tools/perf/pmu-events/arch/x86/amdzen5/floating-point.json
@@ -383,6 +383,13 @@
"BriefDescription": "Retired MMX integer VNNI ops.",
"UMask": "0x0c"
},
+ {
+ "EventName": "sse_avx_ops_retired.mmx_pack",
+ "EventCode": "0x0b",
+ "BriefDescription": "This event is deprecated. Refer to new event sse_avx_ops_retired.mmx_vnni",
+ "Deprecated": "1",
+ "UMask": "0x0c"
+ },
{
"EventName": "sse_avx_ops_retired.mmx_logical",
"EventCode": "0x0b",
@@ -449,6 +456,13 @@
"BriefDescription": "Retired SSE and AVX integer convert or pack ops.",
"UMask": "0x80"
},
+ {
+ "EventName": "sse_avx_ops_retired.sse_avx_clm",
+ "EventCode": "0x0b",
+ "BriefDescription": "This event is deprecated. Refer to new event sse_avx_ops_retired.sse_avx_cvt",
+ "Deprecated": "1",
+ "UMask": "0x80"
+ },
{
"EventName": "sse_avx_ops_retired.sse_avx_shift",
"EventCode": "0x0b",
@@ -473,6 +487,13 @@
"BriefDescription": "Retired SSE and AVX integer VNNI ops.",
"UMask": "0xc0"
},
+ {
+ "EventName": "sse_avx_ops_retired.sse_avx_pack",
+ "EventCode": "0x0b",
+ "BriefDescription": "This event is deprecated. Refer to new event sse_avx_ops_retired.sse_avx_vnni",
+ "Deprecated": "1",
+ "UMask": "0xc0"
+ },
{
"EventName": "sse_avx_ops_retired.sse_avx_logical",
"EventCode": "0x0b",
@@ -731,6 +752,13 @@
"BriefDescription": "Retired 128-bit packed integer convert or pack ops.",
"UMask": "0x08"
},
+ {
+ "EventName": "packed_int_op_type.int128_clm",
+ "EventCode": "0x0d",
+ "BriefDescription": "This event is deprecated. Refer to new event packed_int_op_type.int128_cvt",
+ "Deprecated": "1",
+ "UMask": "0x08"
+ },
{
"EventName": "packed_int_op_type.int128_shift",
"EventCode": "0x0d",
@@ -755,6 +783,13 @@
"BriefDescription": "Retired 128-bit packed integer VNNI ops.",
"UMask": "0x0c"
},
+ {
+ "EventName": "packed_int_op_type.int128_pack",
+ "EventCode": "0x0d",
+ "BriefDescription": "This event is deprecated. Refer to new event packed_int_op_type.int128_vnni",
+ "Deprecated": "1",
+ "UMask": "0x0c"
+ },
{
"EventName": "packed_int_op_type.int128_logical",
"EventCode": "0x0d",
@@ -845,6 +880,13 @@
"BriefDescription": "Retired 256-bit packed integer VNNI ops.",
"UMask": "0xc0"
},
+ {
+ "EventName": "packed_int_op_type.int256_pack",
+ "EventCode": "0x0d",
+ "BriefDescription": "This event is deprecated. Refer to new event packed_int_op_type.int256_vnni",
+ "Deprecated": "1",
+ "UMask": "0xc0"
+ },
{
"EventName": "packed_int_op_type.int256_logical",
"EventCode": "0x0d",
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0274/1518] perf dso: Fix kallsyms DSO detection with fallback logic
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (272 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0273/1518] perf vendor events amd: Reintroduce deprecated Zen 5 core events Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0275/1518] bpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlinux Greg Kroah-Hartman
` (724 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tanushree Shah, Namhyung Kim,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tanushree Shah <tshah@linux.ibm.com>
[ Upstream commit 8c5f60344b07f839267c0c835962e2206143be85 ]
The current kallsyms detection in dso__is_kallsyms() uses the
dso_binary_type enum which fixes the issue of kallsyms being cached in
the build-id cache for out-of-tree modules.
However, during build-id injection in perf record/inject, dso_binary_type
has not been explicitly set yet,so dso__binary_type() returns
DSO_BINARY_TYPE__NOT_FOUND instead of DSO_BINARY_TYPE__KALLSYMS for the
kernel DSO. The current check then fails to identify it as kallsyms,
causing build-id symlinks to not be created in ~/.debug/.build-id/ and
perf archive to fail with "Cannot stat" errors.
Steps to reproduce the issue:
1. rm -rf ~/.debug/.build-id
2. perf record sleep 1
3. perf archive
Fix by falling back to matching long_name against the known kallsyms
strings explicitly when binary_type is not yet set
(== DSO_BINARY_TYPE__NOT_FOUND). Use strcmp() for exact matching of
fixed names and strict validation for guest kallsyms with embedded PID
to prevent path traversal attacks.
Fixes: ebf0b332732d ("perf dso: fix dso__is_kallsyms() check")
Signed-off-by: Tanushree Shah <tshah@linux.ibm.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/dso.h | 57 ++++++++++++++++++++++++++++++++++++++++++-
1 file changed, 56 insertions(+), 1 deletion(-)
diff --git a/tools/perf/util/dso.h b/tools/perf/util/dso.h
index 54e470dd07305..b374dfabf49cc 100644
--- a/tools/perf/util/dso.h
+++ b/tools/perf/util/dso.h
@@ -9,6 +9,7 @@
#include <stdbool.h>
#include <stdio.h>
#include <linux/bitops.h>
+#include <string.h>
#include "build-id.h"
#include "debuginfo.h"
#include "mutex.h"
@@ -20,6 +21,40 @@ struct perf_env;
#define DSO__NAME_KALLSYMS "[kernel.kallsyms]"
#define DSO__NAME_KCORE "[kernel.kcore]"
+#define DSO__NAME_GUEST_KALLSYMS "[guest.kernel.kallsyms]"
+#define DSO__NAME_GUEST_KALLSYMS_PID_PREFIX "[guest.kernel.kallsyms."
+
+/*
+ * Validate names of the form "[guest.kernel.kallsyms.<pid>]", where
+ * <pid> is the PID of the guest VM and varies per guest, so it
+ * cannot be matched with strcmp() against a fixed string.
+ *
+ * Every character after the fixed prefix must be a decimal digit,
+ * with ']' immediately terminating the digit run and nothing
+ * following it. This rules out '/', "..", or any other character
+ * being smuggled into the name.
+ */
+static inline bool is_guest_kallsyms_pid_name(const char *name)
+{
+ const size_t prefix_len = sizeof(DSO__NAME_GUEST_KALLSYMS_PID_PREFIX) - 1;
+ size_t digits;
+
+ if (strncmp(name, DSO__NAME_GUEST_KALLSYMS_PID_PREFIX, prefix_len) != 0)
+ return false;
+
+ digits = strspn(name + prefix_len, "0123456789");
+ if (digits == 0)
+ return false;
+
+ /* ']' must terminate the digit run, with nothing trailing it */
+ if (name[prefix_len + digits] != ']')
+ return false;
+
+ if (name[prefix_len + digits + 1] != '\0')
+ return false;
+
+ return true;
+}
/**
* enum dso_binary_type - The kind of DSO generally associated with a memory
@@ -894,8 +929,28 @@ static inline bool dso__is_kcore(const struct dso *dso)
static inline bool dso__is_kallsyms(const struct dso *dso)
{
enum dso_binary_type bt = dso__binary_type(dso);
+ const char *name;
+
+ if (bt == DSO_BINARY_TYPE__KALLSYMS || bt == DSO_BINARY_TYPE__GUEST_KALLSYMS)
+ return true;
+
+ if (bt != DSO_BINARY_TYPE__NOT_FOUND)
+ return false;
+
+ if (!dso__kernel(dso))
+ return false;
+
+ name = dso__long_name(dso);
+ if (!name)
+ return false;
+
+ if (!strcmp(name, DSO__NAME_KALLSYMS))
+ return true;
+
+ if (!strcmp(name, DSO__NAME_GUEST_KALLSYMS))
+ return true;
- return bt == DSO_BINARY_TYPE__KALLSYMS || bt == DSO_BINARY_TYPE__GUEST_KALLSYMS;
+ return is_guest_kallsyms_pid_name(name);
}
bool dso__is_object_file(const struct dso *dso);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0275/1518] bpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlinux
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (273 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0274/1518] perf dso: Fix kallsyms DSO detection with fallback logic Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0276/1518] efi: fix stale reference to efi_recover_from_page_fault() Greg Kroah-Hartman
` (723 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Daniel Borkmann,
Kumar Kartikeya Dwivedi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel Borkmann <daniel@iogearbox.net>
[ Upstream commit 92863e678070f57c17c868e4bfa2441a5c61ad2b ]
bpf_get_btf_vmlinux() lazily parses the vmlinux BTF under the
bpf_verifier_lock, but publishes the result through a plain store
and re-checks it through a plain lockless load. Nothing orders
the stores initializing the struct btf inside btf_parse_vmlinux()
against the store publishing the pointer: On a weakly ordered
arch, a concurrent first-time caller taking the lockless fast
path could in principle observe the pointer before the parsed
contents are visible. The mutex_unlock() does not help such a
reader given it only synchronizes with a later acquisition of the
same lock. Thus, publish the pointer with smp_store_release()
and read it on the fast path with smp_load_acquire().
Acquire semantics are needed rather than a dependency-ordered
READ_ONCE(): btf_parse_vmlinux() also populates globals outside
the returned object (e.g. bpf_ctx_convert.t). An address
dependency would only order accesses performed through the
pointer and not cover other globals.
Fixes: 8580ac9404f6 ("bpf: Process in-kernel BTF")
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/bpf/20260708211537.371874-2-daniel@iogearbox.net
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/verifier.c | 20 ++++++++++++++++----
1 file changed, 16 insertions(+), 4 deletions(-)
diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index 140be10eeb7bf..3be56a023a1bc 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -24406,13 +24406,25 @@ static int check_attach_btf_id(struct bpf_verifier_env *env)
struct btf *bpf_get_btf_vmlinux(void)
{
- if (!btf_vmlinux && IS_ENABLED(CONFIG_DEBUG_INFO_BTF)) {
+ /* Pairs with the smp_store_release() on the parse path below. */
+ struct btf *btf = smp_load_acquire(&btf_vmlinux);
+
+ if (!btf && IS_ENABLED(CONFIG_DEBUG_INFO_BTF)) {
mutex_lock(&bpf_verifier_lock);
- if (!btf_vmlinux)
- btf_vmlinux = btf_parse_vmlinux();
+ btf = btf_vmlinux;
+ if (!btf) {
+ btf = btf_parse_vmlinux();
+ /*
+ * Order the parsed BTF contents and the globals the
+ * parse populated (e.g. bpf_ctx_convert.t) before
+ * the pointer publication. Pairs with the acquire
+ * on the lockless fast path above.
+ */
+ smp_store_release(&btf_vmlinux, btf);
+ }
mutex_unlock(&bpf_verifier_lock);
}
- return btf_vmlinux;
+ return btf;
}
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0276/1518] efi: fix stale reference to efi_recover_from_page_fault()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (274 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0275/1518] bpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlinux Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0277/1518] bpf: Fix use-after-free on mm_struct in bpf_find_vma() Greg Kroah-Hartman
` (722 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Breno Leitao, Ard Biesheuvel,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Breno Leitao <leitao@debian.org>
[ Upstream commit 718ee46ba4d95d28d50d3f6437afbbe2be531175 ]
efi_recover_from_page_fault() was renamed to
efi_crash_gracefully_on_page_fault(), but the comment above enum
efi_rts_ids was not updated. Use the current name.
Fixes: c46f52231e79 ("x86/{fault,efi}: Fix and rename efi_recover_from_page_fault()")
Signed-off-by: Breno Leitao <leitao@debian.org>
Signed-off-by: Ard Biesheuvel <ardb@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/efi.h | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/include/linux/efi.h b/include/linux/efi.h
index a98cc39e7aaa8..0ec9f3dc596d4 100644
--- a/include/linux/efi.h
+++ b/include/linux/efi.h
@@ -1228,8 +1228,8 @@ efi_call_acpi_prm_handler(efi_status_t (__efiapi *handler_addr)(u64, void *),
/*
* efi_runtime_service() function identifiers.
- * "NONE" is used by efi_recover_from_page_fault() to check if the page
- * fault happened while executing an efi runtime service.
+ * "NONE" is used by efi_crash_gracefully_on_page_fault() to check if the
+ * page fault happened while executing an efi runtime service.
*/
enum efi_rts_ids {
EFI_NONE,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0277/1518] bpf: Fix use-after-free on mm_struct in bpf_find_vma()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (275 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0276/1518] efi: fix stale reference to efi_recover_from_page_fault() Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0278/1518] bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation Greg Kroah-Hartman
` (721 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sanghyun Park, Puranjay Mohan,
Yonghong Song, Kumar Kartikeya Dwivedi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sanghyun Park <sanghyun.park.cnu@gmail.com>
[ Upstream commit 47b079e2117a2ee52e21f8b72935900c702fc0b5 ]
bpf_find_vma() reads task->mm and calls mmap_read_trylock(mm) without
holding a reference on the mm. On a foreign task, a concurrent exit_mm()
can free the mm_struct between the lockless read and the trylock,
resulting in a use-after-free. mm_struct is not SLAB_TYPESAFE_BY_RCU.
For the current task, task->mm is stable. For a foreign task, pin the mm
under task->alloc_lock and release it with mmput_async(), mirroring commit
d8e27d2d22b6 ("bpf: fix mm lifecycle in open-coded task_vma iterator").
Use spin_trylock() instead of get_task_mm() so BPF context does not block
on alloc_lock. Reject irqs-disabled contexts and !CONFIG_MMU on the
foreign-task path because dropping the mm reference is not safe there.
Race:
CPU0 (BPF program) CPU1 (exiting task)
============================ ==========================
bpf_find_vma(foreign_task):
mm = task->mm
exit_mm():
task->mm = NULL
mmput(mm) -> frees mm_struct
mmap_read_trylock(mm)
// UAF on mm
Fixes: 7c7e3d31e785 ("bpf: Introduce helper bpf_find_vma")
Signed-off-by: Sanghyun Park <sanghyun.park.cnu@gmail.com>
Reviewed-by: Puranjay Mohan <puranjay@kernel.org>
Acked-by: Yonghong Song <yonghong.song@linux.dev>
Link: https://lore.kernel.org/bpf/20260708072106.199637-2-sanghyun.park.cnu@gmail.com
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/task_iter.c | 36 +++++++++++++++++++++++++++++++++---
1 file changed, 33 insertions(+), 3 deletions(-)
diff --git a/kernel/bpf/task_iter.c b/kernel/bpf/task_iter.c
index e791ae065c39b..b256fb9c1214e 100644
--- a/kernel/bpf/task_iter.c
+++ b/kernel/bpf/task_iter.c
@@ -756,6 +756,7 @@ BPF_CALL_5(bpf_find_vma, struct task_struct *, task, u64, start,
struct mmap_unlock_irq_work *work = NULL;
struct vm_area_struct *vma;
bool irq_work_busy = false;
+ bool __maybe_unused mmput_needed = false;
struct mm_struct *mm;
int ret = -ENOENT;
@@ -765,14 +766,38 @@ BPF_CALL_5(bpf_find_vma, struct task_struct *, task, u64, start,
if (!task)
return -ENOENT;
- mm = task->mm;
+ if (task == current) {
+ mm = task->mm;
+ } else {
+ /*
+ * Foreign task: pin task->mm against a concurrent exit_mm().
+ * Use trylock on alloc_lock instead of get_task_mm()'s
+ * blocking task_lock() to avoid deadlocking the target task.
+ */
+ if (!IS_ENABLED(CONFIG_MMU))
+ return -EOPNOTSUPP;
+ if (irqs_disabled())
+ return -EBUSY;
+ if (!spin_trylock(&task->alloc_lock))
+ return -EBUSY;
+ mm = task->mm;
+ if (mm && !(task->flags & PF_KTHREAD)) {
+ mmget(mm);
+ mmput_needed = true;
+ } else {
+ mm = NULL;
+ }
+ spin_unlock(&task->alloc_lock);
+ }
if (!mm)
return -ENOENT;
irq_work_busy = bpf_mmap_unlock_get_irq_work(&work);
- if (irq_work_busy || !mmap_read_trylock(mm))
- return -EBUSY;
+ if (irq_work_busy || !mmap_read_trylock(mm)) {
+ ret = -EBUSY;
+ goto out;
+ }
vma = find_vma(mm, start);
@@ -782,6 +807,11 @@ BPF_CALL_5(bpf_find_vma, struct task_struct *, task, u64, start,
ret = 0;
}
bpf_mmap_unlock_mm(work, mm);
+out:
+#ifdef CONFIG_MMU
+ if (mmput_needed)
+ mmput_async(mm);
+#endif
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0278/1518] bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (276 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0277/1518] bpf: Fix use-after-free on mm_struct in bpf_find_vma() Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0279/1518] iommu/mediatek-v1: Fix off-by-one in MT2701_LARB_NR_MAX Greg Kroah-Hartman
` (720 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yuho Choi, Manivannan Sadhasivam,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuho Choi <dbgh9129@gmail.com>
[ Upstream commit 6f12862600bb70e599a614d706a095ea5f8f9858 ]
mhi_ep_create_device() takes one device reference for the UL channel and
another for the DL channel after allocating the transfer device. These
references are normally released by mhi_ep_destroy_device() before the
device itself is removed.
If dev_set_name() or device_add() fails, the error path currently drops
only one reference. The remaining channel references keep the device
from being released and leave the channels associated with a device that
was never registered.
Route both failures through a common unwind path that drops the DL
channel reference, the UL channel reference, and the initial reference
from device_initialize().
Fixes: 297c77a0f273 ("bus: mhi: ep: Add support for creating and destroying MHI EP devices")
Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
Signed-off-by: Manivannan Sadhasivam <mani@kernel.org>
Link: https://patch.msgid.link/20260603195142.2189386-1-dbgh9129@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bus/mhi/ep/main.c | 15 ++++++++++-----
1 file changed, 10 insertions(+), 5 deletions(-)
diff --git a/drivers/bus/mhi/ep/main.c b/drivers/bus/mhi/ep/main.c
index 2f58ad0f14b65..fd1d7c84fb1c5 100644
--- a/drivers/bus/mhi/ep/main.c
+++ b/drivers/bus/mhi/ep/main.c
@@ -1340,14 +1340,19 @@ static int mhi_ep_create_device(struct mhi_ep_cntrl *mhi_cntrl, u32 ch_id)
ret = dev_set_name(&mhi_dev->dev, "%s_%s",
dev_name(&mhi_cntrl->mhi_dev->dev),
mhi_dev->name);
- if (ret) {
- put_device(&mhi_dev->dev);
- return ret;
- }
+ if (ret)
+ goto err_put_channels;
ret = device_add(&mhi_dev->dev);
if (ret)
- put_device(&mhi_dev->dev);
+ goto err_put_channels;
+
+ return 0;
+
+err_put_channels:
+ put_device(&mhi_dev->dev); /* DL channel reference */
+ put_device(&mhi_dev->dev); /* UL channel reference */
+ put_device(&mhi_dev->dev); /* device_initialize() reference */
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0279/1518] iommu/mediatek-v1: Fix off-by-one in MT2701_LARB_NR_MAX
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (277 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0278/1518] bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0280/1518] bpf: Fix security_bpf_map_create error handling Greg Kroah-Hartman
` (719 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Akari Tsuyukusa, Joerg Roedel,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Akari Tsuyukusa <akkun11.open@gmail.com>
[ Upstream commit aebaa93f3da1572877579c2e15ebf27be2dcc7fb ]
The mt2701_m4u_in_larb[] array contains 4 (for LARB0 to LARB3)
elements, meaning mt2701_m4u_to_larb() can legitimately return 3.
The current check `if (larbid >= MT2701_LARB_NR_MAX)` incorrectly
rejects valid LARB3 with -EINVAL.
Fix this off-by-one error by updating MT2701_LARB_NR_MAX to 4.
Note that this does not cause immediate issues with the current
mt2701.dtsi and mt7623n.dtsi because it only defines 3 LARBs:
mediatek,larbs = <&larb0 &larb1 &larb2>;
Thus, larbid never reaches 3 in the existing upstream device tree.
Fixes: de78657e16f4 ("iommu/mediatek: Fix NULL pointer dereference when printing dev_name")
Signed-off-by: Akari Tsuyukusa <akkun11.open@gmail.com>
Signed-off-by: Joerg Roedel <joerg.roedel@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/iommu/mtk_iommu_v1.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/iommu/mtk_iommu_v1.c b/drivers/iommu/mtk_iommu_v1.c
index 44b965a2db923..ad2dbd29fef8d 100644
--- a/drivers/iommu/mtk_iommu_v1.c
+++ b/drivers/iommu/mtk_iommu_v1.c
@@ -88,7 +88,7 @@ struct dma_iommu_mapping {
/* MTK generation one iommu HW only support 4K size mapping */
#define MT2701_IOMMU_PAGE_SHIFT 12
#define MT2701_IOMMU_PAGE_SIZE (1UL << MT2701_IOMMU_PAGE_SHIFT)
-#define MT2701_LARB_NR_MAX 3
+#define MT2701_LARB_NR_MAX 4
/*
* MTK m4u support 4GB iova address space, and only support 4K page
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0280/1518] bpf: Fix security_bpf_map_create error handling
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (278 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0279/1518] iommu/mediatek-v1: Fix off-by-one in MT2701_LARB_NR_MAX Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0281/1518] iommu/msm: Return -ENOMEM on memory allocation failure in probe Greg Kroah-Hartman
` (718 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Daniel Borkmann,
Kumar Kartikeya Dwivedi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel Borkmann <daniel@iogearbox.net>
[ Upstream commit 36ffa86c42f91c8a57071e024afc4ffb51a8958f ]
Commit 5816bf4273ed ("lsm,selinux: Add LSM blob support for BPF objects")
made the LSM hook wrappers for BPF object creation clean up the LSM
state internally upon denial, e.g. security_bpf_map_create() internally
calls security_bpf_map_free() when the bpf_map_create hook returns an
error. map_create() however still routes a denial to its free_map_sec
label, which invokes security_bpf_map_free() a second time, so the
bpf_map_free hook fires twice for a single denied map.
In-tree LSMs are unaffected in practice since the blob kfree() inside
security_bpf_map_free() is NULL-safe and idempotent and none of them
implement bpf_map_free, but a BPF LSM program attached to that hook
observes double invocations. Route the denial to free_map instead.
Fixes: 5816bf4273ed ("lsm,selinux: Add LSM blob support for BPF objects")
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/bpf/20260709073422.379247-1-daniel@iogearbox.net
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/syscall.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/kernel/bpf/syscall.c b/kernel/bpf/syscall.c
index e92fd2bec98c7..b8937bebf5b81 100644
--- a/kernel/bpf/syscall.c
+++ b/kernel/bpf/syscall.c
@@ -1593,7 +1593,7 @@ static int map_create(union bpf_attr *attr, bpfptr_t uattr)
err = security_bpf_map_create(map, attr, token, uattr.is_kernel);
if (err)
- goto free_map_sec;
+ goto free_map;
err = bpf_map_alloc_id(map);
if (err)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0281/1518] iommu/msm: Return -ENOMEM on memory allocation failure in probe
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (279 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0280/1518] bpf: Fix security_bpf_map_create error handling Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0282/1518] iommu/amd: Prevent SB IOAPIC from overriding IVRS validation errors Greg Kroah-Hartman
` (717 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vladimir Zapolskiy, Dmitry Baryshkov,
Konrad Dybcio, Joerg Roedel, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vladimir Zapolskiy <vz@kernel.org>
[ Upstream commit b0d50c9016c4c2959dfa61bf9549cf98f9aa19cd ]
If dynamic memory allocation in driver's probe function execution fails,
it should be reported to the driver's framework with -ENOMEM error code.
Fixes: 109bd48ea2e1 ("iommu/msm: Add DT adaptation")
Signed-off-by: Vladimir Zapolskiy <vz@kernel.org>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Joerg Roedel <joerg.roedel@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/iommu/msm_iommu.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/iommu/msm_iommu.c b/drivers/iommu/msm_iommu.c
index d5e2fc9b01116..1dfa6f69c28f2 100644
--- a/drivers/iommu/msm_iommu.c
+++ b/drivers/iommu/msm_iommu.c
@@ -719,7 +719,7 @@ static int msm_iommu_probe(struct platform_device *pdev)
iommu = devm_kzalloc(&pdev->dev, sizeof(*iommu), GFP_KERNEL);
if (!iommu)
- return -ENODEV;
+ return -ENOMEM;
iommu->dev = &pdev->dev;
INIT_LIST_HEAD(&iommu->ctx_list);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0282/1518] iommu/amd: Prevent SB IOAPIC from overriding IVRS validation errors
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (280 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0281/1518] iommu/msm: Return -ENOMEM on memory allocation failure in probe Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0283/1518] iommu/amd: Add support for Hygon family 18h model 4h IOAPIC Greg Kroah-Hartman
` (716 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Wei Wang, Yongwei Xu, Vasant Hegde,
Joerg Roedel, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wei Wang <wei.w.wang@hotmail.com>
[ Upstream commit 854056480f9217568e3ab5edd81a9347a173ea79 ]
The check_ioapic_information() function validates IOAPICs against the
IVRS table to safely disable Interrupt Remapping (IR) if the BIOS provides
a broken topology.
Currently, the validation loop contains a bug: If an unmapped secondary
IOAPIC is encountered, 'ret' is set to false. But if the Southbridge (SB)
IOAPIC is enumerated after it in the MADT, the loop overwrites 'ret' to
true.
This bypasses the validation failure and leaves IR enabled. When devices
attached to the unmapped secondary IOAPIC fire interrupts, the IOMMU drops
them due to the missing Requestor ID, leading to localized device hangs.
Fix this by initializing 'ret' to true and only toggling it to false
upon encountering a validation error, ensuring failures are never erased.
Fixes: c2ff5cf5294b ("iommu/amd: Work around wrong IOAPIC device-id in IVRS table")
Signed-off-by: Wei Wang <wei.w.wang@hotmail.com>
Tested-by: Yongwei Xu <xuyongwei@open-hieco.net>
Reviewed-by: Vasant Hegde <vasant.hegde@amd.com>
Signed-off-by: Joerg Roedel <joerg.roedel@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/iommu/amd/init.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/iommu/amd/init.c b/drivers/iommu/amd/init.c
index 69170146d4421..20b1cc2159332 100644
--- a/drivers/iommu/amd/init.c
+++ b/drivers/iommu/amd/init.c
@@ -3103,7 +3103,7 @@ static bool __init check_ioapic_information(void)
int idx;
has_sb_ioapic = false;
- ret = false;
+ ret = true;
/*
* If we have map overrides on the kernel command line the
@@ -3123,7 +3123,6 @@ static bool __init check_ioapic_information(void)
ret = false;
} else if (devid == IOAPIC_SB_DEVID) {
has_sb_ioapic = true;
- ret = true;
}
}
@@ -3137,6 +3136,7 @@ static bool __init check_ioapic_information(void)
* device id for the IOAPIC in the system.
*/
pr_err("%s: No southbridge IOAPIC found\n", fw_bug);
+ ret = false;
}
if (!ret)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0283/1518] iommu/amd: Add support for Hygon family 18h model 4h IOAPIC
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (281 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0282/1518] iommu/amd: Prevent SB IOAPIC from overriding IVRS validation errors Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0284/1518] iommu/amd: Fix false positive in SB IOAPIC IVRS validation Greg Kroah-Hartman
` (715 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Fu Hao, Tingyin Duan, Joerg Roedel,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fu Hao <fuhao@open-hieco.net>
[ Upstream commit 5beda8cadb1f072140e58b1edb7604444a42d955 ]
The SB IOAPIC is on the device 0xb from Hygon family 18h model 4h.
Signed-off-by: Fu Hao <fuhao@open-hieco.net>
Tested-by: Tingyin Duan <tingyin.duan@gmail.com>
Signed-off-by: Joerg Roedel <joerg.roedel@amd.com>
Stable-dep-of: 04fee302fac7 ("iommu/amd: Fix false positive in SB IOAPIC IVRS validation")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/iommu/amd/init.c | 10 +++++++++-
1 file changed, 9 insertions(+), 1 deletion(-)
diff --git a/drivers/iommu/amd/init.c b/drivers/iommu/amd/init.c
index 20b1cc2159332..bf8b114386884 100644
--- a/drivers/iommu/amd/init.c
+++ b/drivers/iommu/amd/init.c
@@ -3096,6 +3096,9 @@ static void __init free_iommu_resources(void)
/* SB IOAPIC is always on this device in AMD systems */
#define IOAPIC_SB_DEVID ((0x00 << 8) | PCI_DEVFN(0x14, 0))
+/* SB IOAPIC for Hygon family 18h model 4h is on the device 0xb */
+#define IOAPIC_SB_DEVID_FAM18H_M4H ((0x00 << 8) | PCI_DEVFN(0xb, 0))
+
static bool __init check_ioapic_information(void)
{
const char *fw_bug = FW_BUG;
@@ -3121,7 +3124,12 @@ static bool __init check_ioapic_information(void)
pr_err("%s: IOAPIC[%d] not in IVRS table\n",
fw_bug, id);
ret = false;
- } else if (devid == IOAPIC_SB_DEVID) {
+ } else if (devid == IOAPIC_SB_DEVID ||
+ (boot_cpu_data.x86_vendor == X86_VENDOR_HYGON &&
+ boot_cpu_data.x86 == 0x18 &&
+ boot_cpu_data.x86_model >= 0x4 &&
+ boot_cpu_data.x86_model <= 0xf &&
+ devid == IOAPIC_SB_DEVID_FAM18H_M4H)) {
has_sb_ioapic = true;
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0284/1518] iommu/amd: Fix false positive in SB IOAPIC IVRS validation
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (282 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0283/1518] iommu/amd: Add support for Hygon family 18h model 4h IOAPIC Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0285/1518] leds: pca9532: Fix inverted GPIO output polarity Greg Kroah-Hartman
` (714 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Wei Wang, Yongwei Xu, Vasant Hegde,
Joerg Roedel, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wei Wang <wei.w.wang@hotmail.com>
[ Upstream commit 04fee302fac762a242ff1ad6810cff90c2a350ba ]
The check_ioapic_information() function is designed to prevent boot hangs
by ensuring the Southbridge (SB) IOAPIC is properly mapped in the IVRS
table before enabling Interrupt Remapping.
Currently, this check passes if *any* enumerated IOAPIC matches the
expected SB IOAPIC device ID. If a buggy BIOS incorrectly assigns the
SB IOAPIC's device ID to a secondary IOAPIC in the IVRS, while scrambling
the true SB IOAPIC's mapping, the check hits a false positive and
succeeds.
This erroneously enables Interrupt Remapping. Consequently, the IOMMU
blocks unmapped interrupts from the actual SB IOAPIC, dropping the system
timer and leading to a silent kernel boot hang.
Tighten the validation to verify the device ID specifically against the SB
IOAPIC by matching their APIC IDs first. This prevents the validation
check from being bypassed via device ID aliasing.
Fixes: c2ff5cf5294b ("iommu/amd: Work around wrong IOAPIC device-id in IVRS table")
Signed-off-by: Wei Wang <wei.w.wang@hotmail.com>
Tested-by: Yongwei Xu <xuyongwei@open-hieco.net>
Reviewed-by: Vasant Hegde <vasant.hegde@amd.com>
Signed-off-by: Joerg Roedel <joerg.roedel@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/iommu/amd/init.c | 32 ++++++++++++++++++++++++++++----
1 file changed, 28 insertions(+), 4 deletions(-)
diff --git a/drivers/iommu/amd/init.c b/drivers/iommu/amd/init.c
index bf8b114386884..2437f416d0c10 100644
--- a/drivers/iommu/amd/init.c
+++ b/drivers/iommu/amd/init.c
@@ -3099,11 +3099,25 @@ static void __init free_iommu_resources(void)
/* SB IOAPIC for Hygon family 18h model 4h is on the device 0xb */
#define IOAPIC_SB_DEVID_FAM18H_M4H ((0x00 << 8) | PCI_DEVFN(0xb, 0))
+/*
+ * The Southbridge IOAPIC is assigned a GSI Base of 0 (handling interrupts
+ * 0 through 23).
+ */
+static int __init get_sb_ioapic_id(void)
+{
+ int idx = mp_find_ioapic(0);
+
+ if (idx < 0)
+ return -ENODEV;
+
+ return mpc_ioapic_id(idx);
+}
+
static bool __init check_ioapic_information(void)
{
const char *fw_bug = FW_BUG;
bool ret, has_sb_ioapic;
- int idx;
+ int idx, sb_apicid;
has_sb_ioapic = false;
ret = true;
@@ -3116,6 +3130,16 @@ static bool __init check_ioapic_information(void)
if (cmdline_maps)
fw_bug = "";
+ sb_apicid = get_sb_ioapic_id();
+ if (sb_apicid < 0) {
+ /*
+ * Lack of SB IOAPIC registration is not a firmware bug,
+ * e.g. kernel booted with noapic or noacpi.
+ */
+ fw_bug = "";
+ goto out;
+ }
+
for (idx = 0; idx < nr_ioapics; idx++) {
int devid, id = mpc_ioapic_id(idx);
@@ -3124,16 +3148,16 @@ static bool __init check_ioapic_information(void)
pr_err("%s: IOAPIC[%d] not in IVRS table\n",
fw_bug, id);
ret = false;
- } else if (devid == IOAPIC_SB_DEVID ||
+ } else if (id == sb_apicid && (devid == IOAPIC_SB_DEVID ||
(boot_cpu_data.x86_vendor == X86_VENDOR_HYGON &&
boot_cpu_data.x86 == 0x18 &&
boot_cpu_data.x86_model >= 0x4 &&
boot_cpu_data.x86_model <= 0xf &&
- devid == IOAPIC_SB_DEVID_FAM18H_M4H)) {
+ devid == IOAPIC_SB_DEVID_FAM18H_M4H))) {
has_sb_ioapic = true;
}
}
-
+out:
if (!has_sb_ioapic) {
/*
* We expect the SB IOAPIC to be listed in the IVRS
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0285/1518] leds: pca9532: Fix inverted GPIO output polarity
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (283 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0284/1518] iommu/amd: Fix false positive in SB IOAPIC IVRS validation Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0286/1518] leds: st1202: Stop pattern sequence before reprogramming Greg Kroah-Hartman
` (713 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Cosmo Chou, Bartosz Golaszewski,
Lee Jones, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cosmo Chou <chou.cosmo@gmail.com>
[ Upstream commit 65a38a28a0b04af19a5e1fbf3869051412eeac96 ]
The pca9532_gpio_set_value() function incorrectly mapped the requested
value to PCA9532_ON and PCA9532_OFF, inverting the GPIO output polarity.
A requested logical high (val=1) incorrectly enabled the LED output
driver, which on this open-drain device pulls the pin low, while a
requested logical low (val=0) released the pin.
Correct the mapping so that val=1 yields PCA9532_OFF (pin released /
high-impedance) and val=0 yields PCA9532_ON (pin driven low).
pca9532_gpio_direction_input() is also updated to pass val=1 to
pca9532_gpio_set_value() to align with the corrected polarity mapping,
ensuring the pin remains not driven when configured as an input.
Fixes: 3c1ab50d0a31 ("drivers/leds/leds-pca9532.c: add gpio capability")
Signed-off-by: Cosmo Chou <chou.cosmo@gmail.com>
Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Link: https://patch.msgid.link/20260703014201.69829-1-chou.cosmo@gmail.com
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/leds/leds-pca9532.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/leds/leds-pca9532.c b/drivers/leds/leds-pca9532.c
index 0344189bb991c..80bf94e699d41 100644
--- a/drivers/leds/leds-pca9532.c
+++ b/drivers/leds/leds-pca9532.c
@@ -325,9 +325,9 @@ static int pca9532_gpio_set_value(struct gpio_chip *gc, unsigned int offset,
struct pca9532_led *led = &data->leds[offset];
if (val)
- led->state = PCA9532_ON;
- else
led->state = PCA9532_OFF;
+ else
+ led->state = PCA9532_ON;
pca9532_setled(led);
@@ -347,7 +347,7 @@ static int pca9532_gpio_get_value(struct gpio_chip *gc, unsigned offset)
static int pca9532_gpio_direction_input(struct gpio_chip *gc, unsigned offset)
{
/* To use as input ensure pin is not driven */
- pca9532_gpio_set_value(gc, offset, 0);
+ pca9532_gpio_set_value(gc, offset, 1);
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0286/1518] leds: st1202: Stop pattern sequence before reprogramming
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (284 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0285/1518] leds: pca9532: Fix inverted GPIO output polarity Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0287/1518] leds: st1202: Fix pattern duration prescaler and pattern_clear skip marker Greg Kroah-Hartman
` (712 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Manuel Fombuena, Lee Jones,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manuel Fombuena <fombuena@outlook.com>
[ Upstream commit 9c019a8cb95d820e0bd03e75cfbad2c5b13941b7 ]
The LED1202 datasheet (section 4.8) states that modifications to the
Pattern Sequence Repetition register (PAT_REP) and pattern duration
registers are only applied after the sequence has completed or been
stopped. When the device is running in infinite loop mode (PAT_REP =
0xFF) the sequence never completes on its own, so these writes are
silently ignored by the hardware.
Neither pattern_clear() nor pattern_set() stop the running sequence
before modifying pattern registers, causing any subsequent pattern
reprogramming to have no effect when the previous pattern was set to
infinite repeat.
Fix this by clearing PATS in the Configuration register before touching
any pattern registers in both functions, ensuring the hardware accepts
the new values immediately.
Note that the LED1202 has a single global pattern sequencer shared by
all channels: PATS, PATSR, the duration registers, and PAT_REP are
chip-wide. Stopping the sequencer in pattern_clear() therefore halts
any pattern running on other channels. This is an inherent hardware
constraint; pattern_set() restarts the sequencer when a new pattern is
programmed.
Fixes: 259230378c65 ("leds: Add LED1202 I2C driver")
Signed-off-by: Manuel Fombuena <fombuena@outlook.com>
Assisted-by: Claude:claude-sonnet-4-6
Link: https://patch.msgid.link/GV1PR08MB84978D0F499774773C7DA1FCC5F52@GV1PR08MB8497.eurprd08.prod.outlook.com
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/leds/leds-st1202.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/drivers/leds/leds-st1202.c b/drivers/leds/leds-st1202.c
index 4e5dd76d714d8..1dbf2251f6bc9 100644
--- a/drivers/leds/leds-st1202.c
+++ b/drivers/leds/leds-st1202.c
@@ -201,6 +201,10 @@ static int st1202_led_pattern_clear(struct led_classdev *ldev)
guard(mutex)(&chip->lock);
+ ret = st1202_write_reg(chip, ST1202_CONFIG_REG, ST1202_CONFIG_REG_SHFT);
+ if (ret != 0)
+ return ret;
+
for (int patt = 0; patt < ST1202_MAX_PATTERNS; patt++) {
ret = st1202_pwm_pattern_write(chip, led->led_num, patt, LED_OFF);
if (ret != 0)
@@ -227,6 +231,10 @@ static int st1202_led_pattern_set(struct led_classdev *ldev,
guard(mutex)(&chip->lock);
+ ret = st1202_write_reg(chip, ST1202_CONFIG_REG, ST1202_CONFIG_REG_SHFT);
+ if (ret != 0)
+ return ret;
+
for (int patt = 0; patt < len; patt++) {
if (pattern[patt].delta_t < ST1202_MILLIS_PATTERN_DUR_MIN ||
pattern[patt].delta_t > ST1202_MILLIS_PATTERN_DUR_MAX)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0287/1518] leds: st1202: Fix pattern duration prescaler and pattern_clear skip marker
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (285 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0286/1518] leds: st1202: Stop pattern sequence before reprogramming Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0288/1518] leds: st1202: Fix spurious pattern sequence start in setup Greg Kroah-Hartman
` (711 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Manuel Fombuena, Lee Jones,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manuel Fombuena <fombuena@outlook.com>
[ Upstream commit d32f8bdc2b417a3013e1316a54a0b314f973bbc1 ]
The PATy_DUR register encodes duration as N × 22.2 ms, with register
value 0 reserved as a pattern skip indicator (§7.10). The driver
incorrectly subtracted 1 from the register value:
value / ST1202_MILLIS_PATTERN_DUR_MIN - 1
This caused two problems:
- All programmed durations were off by one step (~22 ms too short).
- Writing the minimum duration (22 ms) produced register value 0,
silently skipping the pattern step instead of setting a 22 ms
duration.
The maximum duration constant was also wrong at 5660 ms. The 8-bit
register saturates at 255, giving a maximum of 5610 ms (22 ms × 255).
Values above 5653 ms were already producing a uint8_t overflow and
writing 0 to the hardware.
Fix the formula by removing the erroneous subtraction, and derive the
maximum from the register width so the relationship is explicit. Update
the documentation to reflect the correct maximum.
This exposes a secondary issue: pattern_clear() was calling
st1202_duration_pattern_write() with ST1202_MILLIS_PATTERN_DUR_MIN to
reset unused slots, accidentally relying on the broken formula to
produce register value 0. With the corrected formula, the same call
writes 0x01 (22 ms), leaving unused slots as valid 22 ms zero-PWM
steps and making the LED appear off for 7 × 22 ms out of every cycle.
Write 0 directly to the duration registers in pattern_clear() so unused
slots are always explicitly marked as skip, independently of the
conversion formula.
Fixes: 259230378c65 ("leds: Add LED1202 I2C driver")
Signed-off-by: Manuel Fombuena <fombuena@outlook.com>
Assisted-by: Claude:claude-sonnet-4-6
Link: https://patch.msgid.link/GV1PR08MB84971D3AF982F4F707A378F0C5F52@GV1PR08MB8497.eurprd08.prod.outlook.com
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
Documentation/leds/leds-st1202.rst | 2 +-
drivers/leds/leds-st1202.c | 6 +++---
2 files changed, 4 insertions(+), 4 deletions(-)
diff --git a/Documentation/leds/leds-st1202.rst b/Documentation/leds/leds-st1202.rst
index 1a09fbfcedcff..a2353549469ee 100644
--- a/Documentation/leds/leds-st1202.rst
+++ b/Documentation/leds/leds-st1202.rst
@@ -17,7 +17,7 @@ To be compatible with the hardware pattern format, maximum 8 tuples of
brightness (PWM) and duration must be written to hw_pattern.
- Min pattern duration: 22 ms
-- Max pattern duration: 5660 ms
+- Max pattern duration: 5610 ms
The format of the hardware pattern values should be:
"brightness duration brightness duration ..."
diff --git a/drivers/leds/leds-st1202.c b/drivers/leds/leds-st1202.c
index 1dbf2251f6bc9..6bc726f9ef467 100644
--- a/drivers/leds/leds-st1202.c
+++ b/drivers/leds/leds-st1202.c
@@ -32,7 +32,7 @@
#define ST1202_ILED_REG0 0x09
#define ST1202_MAX_LEDS 12
#define ST1202_MAX_PATTERNS 8
-#define ST1202_MILLIS_PATTERN_DUR_MAX 5660
+#define ST1202_MILLIS_PATTERN_DUR_MAX (ST1202_MILLIS_PATTERN_DUR_MIN * U8_MAX)
#define ST1202_MILLIS_PATTERN_DUR_MIN 22
#define ST1202_PATTERN_DUR 0x16
#define ST1202_PATTERN_PWM 0x1E
@@ -86,7 +86,7 @@ static int st1202_write_reg(struct st1202_chip *chip, int reg, uint8_t val)
static uint8_t st1202_prescalar_to_miliseconds(unsigned int value)
{
- return value / ST1202_MILLIS_PATTERN_DUR_MIN - 1;
+ return value / ST1202_MILLIS_PATTERN_DUR_MIN;
}
static int st1202_pwm_pattern_write(struct st1202_chip *chip, int led_num,
@@ -210,7 +210,7 @@ static int st1202_led_pattern_clear(struct led_classdev *ldev)
if (ret != 0)
return ret;
- ret = st1202_duration_pattern_write(chip, patt, ST1202_MILLIS_PATTERN_DUR_MIN);
+ ret = st1202_write_reg(chip, ST1202_PATTERN_DUR + patt, 0);
if (ret != 0)
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0288/1518] leds: st1202: Fix spurious pattern sequence start in setup
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (286 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0287/1518] leds: st1202: Fix pattern duration prescaler and pattern_clear skip marker Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0289/1518] leds: st1202: Set all pattern PWM slots to full after clearing pattern Greg Kroah-Hartman
` (710 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Manuel Fombuena, Lee Jones,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manuel Fombuena <fombuena@outlook.com>
[ Upstream commit dcc31246aaf0d330a3ba9a725f56c33e6d634caa ]
st1202_setup() writes PATS and PATSR to the Configuration register as
its final step, which starts the hardware pattern sequencer during
device probe before any patterns have been programmed. This causes the
device to run a sequence with whatever values happen to be in the
pattern registers at the time.
Remove the write. The device reset at the start of setup restores all
registers to their power-on defaults, leaving PATS and PATSR cleared.
Fixes: 259230378c65 ("leds: Add LED1202 I2C driver")
Signed-off-by: Manuel Fombuena <fombuena@outlook.com>
Assisted-by: Claude:claude-sonnet-4-6
Link: https://patch.msgid.link/GV1PR08MB849724B0FF00255F4760FAE0C5F52@GV1PR08MB8497.eurprd08.prod.outlook.com
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/leds/leds-st1202.c | 5 -----
1 file changed, 5 deletions(-)
diff --git a/drivers/leds/leds-st1202.c b/drivers/leds/leds-st1202.c
index 6bc726f9ef467..413c2bd68dab5 100644
--- a/drivers/leds/leds-st1202.c
+++ b/drivers/leds/leds-st1202.c
@@ -331,11 +331,6 @@ static int st1202_setup(struct st1202_chip *chip)
if (ret < 0)
return ret;
- ret = st1202_write_reg(chip, ST1202_CONFIG_REG,
- ST1202_CONFIG_REG_PATS | ST1202_CONFIG_REG_PATSR);
- if (ret < 0)
- return ret;
-
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0289/1518] leds: st1202: Set all pattern PWM slots to full after clearing pattern
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (287 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0288/1518] leds: st1202: Fix spurious pattern sequence start in setup Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0290/1518] leds: st1202: Fix brightness having no effect while pattern mode is active Greg Kroah-Hartman
` (709 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Manuel Fombuena, Lee Jones,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manuel Fombuena <fombuena@outlook.com>
[ Upstream commit d2ca0e2b6d6430f9c60bb2e0ee0b2b3dc4e5d86a ]
pattern_clear() sets all PWM registers for the channel to LED_OFF (0).
In static mode (PATS=0), the LED output is ILED x Pattern0_PWM / 4095;
with Pattern0 at zero the LED remains dark regardless of the ILED value.
The LED1202 has a single global sequencer shared across all channels.
If another channel starts the sequencer after this one has been cleared,
the cleared channel runs through all 8 steps at zero duty cycle and
stays dark regardless of ILED.
Set all 8 PWM slots to ST1202_PATTERN_PWM_FULL so that ILED alone
controls the channel brightness in both static and sequencer modes.
Signed-off-by: Manuel Fombuena <fombuena@outlook.com>
Assisted-by: Claude:claude-sonnet-4-6
Link: https://patch.msgid.link/GV1PR08MB849732C162CFE9E2C525AC16C5F52@GV1PR08MB8497.eurprd08.prod.outlook.com
Signed-off-by: Lee Jones <lee@kernel.org>
Stable-dep-of: 7cbe470366bd ("leds: st1202: Fix brightness having no effect while pattern mode is active")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/leds/leds-st1202.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/leds/leds-st1202.c b/drivers/leds/leds-st1202.c
index 413c2bd68dab5..4627b244c12fe 100644
--- a/drivers/leds/leds-st1202.c
+++ b/drivers/leds/leds-st1202.c
@@ -36,6 +36,7 @@
#define ST1202_MILLIS_PATTERN_DUR_MIN 22
#define ST1202_PATTERN_DUR 0x16
#define ST1202_PATTERN_PWM 0x1E
+#define ST1202_PATTERN_PWM_FULL 0x0FFF
#define ST1202_PATTERN_REP 0x15
struct st1202_led {
@@ -206,7 +207,7 @@ static int st1202_led_pattern_clear(struct led_classdev *ldev)
return ret;
for (int patt = 0; patt < ST1202_MAX_PATTERNS; patt++) {
- ret = st1202_pwm_pattern_write(chip, led->led_num, patt, LED_OFF);
+ ret = st1202_pwm_pattern_write(chip, led->led_num, patt, ST1202_PATTERN_PWM_FULL);
if (ret != 0)
return ret;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0290/1518] leds: st1202: Fix brightness having no effect while pattern mode is active
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (288 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0289/1518] leds: st1202: Set all pattern PWM slots to full after clearing pattern Greg Kroah-Hartman
@ 2026-09-12 6:40 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0291/1518] leds: st1202: Disable channel when brightness is set to zero Greg Kroah-Hartman
` (708 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:40 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Manuel Fombuena, Lee Jones,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manuel Fombuena <fombuena@outlook.com>
[ Upstream commit 7cbe470366bdd43c7e8114fb2c4d74fa69093121 ]
Once a hardware pattern is running (PATS=1), writing to the brightness
sysfs attribute only updates the ILED register. The visible output is
ILED x Pattern_PWM / 4095, so the change has little effect and the LED
never returns to steady static operation as the user expects.
The LED1202 has a single global sequencer shared across all channels.
Stopping it in brightness_set() to force static mode would halt running
patterns on all other active LEDs.
Instead, set all 8 PWM slots for the channel to ST1202_PATTERN_PWM_FULL
before writing ILED. With every step at full duty cycle, the output is
ILED x FULL / 4095 = ILED regardless of the sequencer state, without
disturbing other channels.
This also enables basic LED operation without the pattern trigger: with
the trigger set to none, the brightness sysfs attribute fully controls
the LED as a simple on/off device.
Fixes: 259230378c65 ("leds: Add LED1202 I2C driver")
Signed-off-by: Manuel Fombuena <fombuena@outlook.com>
Assisted-by: Claude:claude-sonnet-4-6
Link: https://patch.msgid.link/GV1PR08MB8497570FD162D0D42A9864E3C5F52@GV1PR08MB8497.eurprd08.prod.outlook.com
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/leds/leds-st1202.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/leds/leds-st1202.c b/drivers/leds/leds-st1202.c
index 4627b244c12fe..680ccb4395773 100644
--- a/drivers/leds/leds-st1202.c
+++ b/drivers/leds/leds-st1202.c
@@ -137,6 +137,8 @@ static void st1202_brightness_set(struct led_classdev *led_cdev,
guard(mutex)(&chip->lock);
+ for (int patt = 0; patt < ST1202_MAX_PATTERNS; patt++)
+ st1202_pwm_pattern_write(chip, led->led_num, patt, ST1202_PATTERN_PWM_FULL);
st1202_write_reg(chip, ST1202_ILED_REG0 + led->led_num, value);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0291/1518] leds: st1202: Disable channel when brightness is set to zero
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (289 preceding siblings ...)
2026-09-12 6:40 ` [PATCH 6.18 0290/1518] leds: st1202: Fix brightness having no effect while pattern mode is active Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0292/1518] leds: st1202: Validate LED reg property against channel count Greg Kroah-Hartman
` (707 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Manuel Fombuena, Lee Jones,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manuel Fombuena <fombuena@outlook.com>
[ Upstream commit 0767335233a8cbab00bbe260a4e4bd380c7677fd ]
When brightness_set() is called with LED_OFF, only the ILED register is
zeroed; the channel enable bit is left set from probe time. A hardware
channel enabled with ILED=0 still draws a small residual current, causing
a dim glow even when the LED is supposed to be off.
Fix this by splitting st1202_channel_set() into a lockless inner function
__st1202_channel_set() and a locking wrapper, then calling the inner
function from brightness_set() while it already holds the mutex. The
channel is now disabled when value is zero and re-enabled when non-zero,
in the same lock region as the ILED write.
Fixes: 259230378c65 ("leds: Add LED1202 I2C driver")
Signed-off-by: Manuel Fombuena <fombuena@outlook.com>
Assisted-by: Claude:claude-sonnet-4-6
Link: https://patch.msgid.link/GV1PR08MB8497F11B30FE7D74CAA25135C5F52@GV1PR08MB8497.eurprd08.prod.outlook.com
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/leds/leds-st1202.c | 68 ++++++++++++++++++++++----------------
1 file changed, 39 insertions(+), 29 deletions(-)
diff --git a/drivers/leds/leds-st1202.c b/drivers/leds/leds-st1202.c
index 680ccb4395773..61b7fe715b880 100644
--- a/drivers/leds/leds-st1202.c
+++ b/drivers/leds/leds-st1202.c
@@ -129,39 +129,11 @@ static int st1202_duration_pattern_write(struct st1202_chip *chip, int pattern,
st1202_prescalar_to_miliseconds(value));
}
-static void st1202_brightness_set(struct led_classdev *led_cdev,
- enum led_brightness value)
-{
- struct st1202_led *led = cdev_to_st1202_led(led_cdev);
- struct st1202_chip *chip = led->chip;
-
- guard(mutex)(&chip->lock);
-
- for (int patt = 0; patt < ST1202_MAX_PATTERNS; patt++)
- st1202_pwm_pattern_write(chip, led->led_num, patt, ST1202_PATTERN_PWM_FULL);
- st1202_write_reg(chip, ST1202_ILED_REG0 + led->led_num, value);
-}
-
-static enum led_brightness st1202_brightness_get(struct led_classdev *led_cdev)
-{
- struct st1202_led *led = cdev_to_st1202_led(led_cdev);
- struct st1202_chip *chip = led->chip;
- u8 value = 0;
-
- guard(mutex)(&chip->lock);
-
- st1202_read_reg(chip, ST1202_ILED_REG0 + led->led_num, &value);
-
- return value;
-}
-
-static int st1202_channel_set(struct st1202_chip *chip, int led_num, bool active)
+static int __st1202_channel_set(struct st1202_chip *chip, int led_num, bool active)
{
u8 chan_low, chan_high;
int ret;
- guard(mutex)(&chip->lock);
-
if (led_num <= 7) {
ret = st1202_read_reg(chip, ST1202_CHAN_ENABLE_LOW, &chan_low);
if (ret < 0)
@@ -189,6 +161,40 @@ static int st1202_channel_set(struct st1202_chip *chip, int led_num, bool active
return 0;
}
+static int st1202_channel_set(struct st1202_chip *chip, int led_num, bool active)
+{
+ guard(mutex)(&chip->lock);
+
+ return __st1202_channel_set(chip, led_num, active);
+}
+
+static void st1202_brightness_set(struct led_classdev *led_cdev,
+ enum led_brightness value)
+{
+ struct st1202_led *led = cdev_to_st1202_led(led_cdev);
+ struct st1202_chip *chip = led->chip;
+
+ guard(mutex)(&chip->lock);
+
+ for (int patt = 0; patt < ST1202_MAX_PATTERNS; patt++)
+ st1202_pwm_pattern_write(chip, led->led_num, patt, ST1202_PATTERN_PWM_FULL);
+ st1202_write_reg(chip, ST1202_ILED_REG0 + led->led_num, value);
+ __st1202_channel_set(chip, led->led_num, !!value);
+}
+
+static enum led_brightness st1202_brightness_get(struct led_classdev *led_cdev)
+{
+ struct st1202_led *led = cdev_to_st1202_led(led_cdev);
+ struct st1202_chip *chip = led->chip;
+ u8 value = 0;
+
+ guard(mutex)(&chip->lock);
+
+ st1202_read_reg(chip, ST1202_ILED_REG0 + led->led_num, &value);
+
+ return value;
+}
+
static int st1202_led_set(struct led_classdev *ldev, enum led_brightness value)
{
struct st1202_led *led = cdev_to_st1202_led(ldev);
@@ -256,6 +262,10 @@ static int st1202_led_pattern_set(struct led_classdev *ldev,
if (ret != 0)
return ret;
+ ret = __st1202_channel_set(chip, led->led_num, true);
+ if (ret != 0)
+ return ret;
+
ret = st1202_write_reg(chip, ST1202_CONFIG_REG, (ST1202_CONFIG_REG_PATSR |
ST1202_CONFIG_REG_PATS | ST1202_CONFIG_REG_SHFT));
if (ret != 0)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0292/1518] leds: st1202: Validate LED reg property against channel count
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (290 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0291/1518] leds: st1202: Disable channel when brightness is set to zero Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0293/1518] printk: Introduce console_flush_one_record Greg Kroah-Hartman
` (706 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Manuel Fombuena, Lee Jones,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manuel Fombuena <fombuena@outlook.com>
[ Upstream commit cf197514bdfd3877f42b5dce1efd40b7b686547e ]
The reg property from the device tree is used directly as an array index
into chip->leds[] without bounds checking. A value >= ST1202_MAX_LEDS
would cause an out-of-bounds write during probe.
Fixes: 259230378c65 ("leds: Add LED1202 I2C driver")
Signed-off-by: Manuel Fombuena <fombuena@outlook.com>
Assisted-by: Claude:claude-sonnet-4-6
Link: https://patch.msgid.link/GV1PR08MB849718B43321DB7E5A05D17BC5F52@GV1PR08MB8497.eurprd08.prod.outlook.com
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/leds/leds-st1202.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/drivers/leds/leds-st1202.c b/drivers/leds/leds-st1202.c
index 61b7fe715b880..f5b53a9ed59c6 100644
--- a/drivers/leds/leds-st1202.c
+++ b/drivers/leds/leds-st1202.c
@@ -278,13 +278,19 @@ static int st1202_dt_init(struct st1202_chip *chip)
{
struct device *dev = &chip->client->dev;
struct st1202_led *led;
- int err, reg;
+ int err;
+ u32 reg;
for_each_available_child_of_node_scoped(dev_of_node(dev), child) {
err = of_property_read_u32(child, "reg", ®);
if (err)
return dev_err_probe(dev, err, "Invalid register\n");
+ if (reg >= ST1202_MAX_LEDS)
+ return dev_err_probe(dev, -EINVAL,
+ "LED reg %u out of range [0, %d]\n",
+ reg, ST1202_MAX_LEDS - 1);
+
led = &chip->leds[reg];
led->is_active = true;
led->fwnode = of_fwnode_handle(child);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0293/1518] printk: Introduce console_flush_one_record
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (291 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0292/1518] leds: st1202: Validate LED reg property against channel count Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0294/1518] printk: Fix possible console use-after-free Greg Kroah-Hartman
` (705 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Petr Mladek, Andrew Murray,
John Ogness, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Andrew Murray <amurray@thegoodpenguin.co.uk>
[ Upstream commit 741ea7aa95dd9ac77f861e7d0961d8d231ac8448 ]
console_flush_all prints all remaining records to all usable consoles
whilst its caller holds console_lock. This can result in large waiting
times for those waiting for console_lock especially where there is a
large volume of records or where the console is slow (e.g. serial).
Let's extract the parts of this function which print a single record
into a new function named console_flush_one_record. This can later
be used for functions that will release and reacquire console_lock
between records.
This commit should not change existing functionality.
Reviewed-by: Petr Mladek <pmladek@suse.com>
Signed-off-by: Andrew Murray <amurray@thegoodpenguin.co.uk>
Reviewed-by: John Ogness <john.ogness@linutronix.de>
Link: https://patch.msgid.link/20251020-printk_legacy_thread_console_lock-v3-1-00f1f0ac055a@thegoodpenguin.co.uk
Signed-off-by: Petr Mladek <pmladek@suse.com>
Stable-dep-of: 36630cafbeed ("printk: Fix possible console use-after-free")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/printk/printk.c | 158 ++++++++++++++++++++++++++---------------
1 file changed, 99 insertions(+), 59 deletions(-)
diff --git a/kernel/printk/printk.c b/kernel/printk/printk.c
index c27fc7fc64eb5..8f3097664622d 100644
--- a/kernel/printk/printk.c
+++ b/kernel/printk/printk.c
@@ -3155,6 +3155,99 @@ static inline void printk_kthreads_check_locked(void) { }
#endif /* CONFIG_PRINTK */
+
+/*
+ * Print out one record for each console.
+ *
+ * @do_cond_resched is set by the caller. It can be true only in schedulable
+ * context.
+ *
+ * @next_seq is set to the sequence number after the last available record.
+ * The value is valid only when there is at least one usable console and all
+ * usable consoles were flushed.
+ *
+ * @handover will be set to true if a printk waiter has taken over the
+ * console_lock, in which case the caller is no longer holding the
+ * console_lock. Otherwise it is set to false.
+ *
+ * @any_usable will be set to true if there are any usable consoles.
+ *
+ * Returns true when there was at least one usable console and a record was
+ * flushed. A returned false indicates there were no records to flush for any
+ * of the consoles. It may also indicate that there were no usable consoles,
+ * the context has been lost or there is a panic suitation. Regardless the
+ * reason, the caller should assume it is not useful to immediately try again.
+ *
+ * Requires the console_lock.
+ */
+static bool console_flush_one_record(bool do_cond_resched, u64 *next_seq, bool *handover,
+ bool *any_usable)
+{
+ struct console_flush_type ft;
+ bool any_progress = false;
+ struct console *con;
+ int cookie;
+
+ printk_get_console_flush_type(&ft);
+
+ cookie = console_srcu_read_lock();
+ for_each_console_srcu(con) {
+ short flags = console_srcu_read_flags(con);
+ u64 printk_seq;
+ bool progress;
+
+ /*
+ * console_flush_one_record() is only responsible for
+ * nbcon consoles when the nbcon consoles cannot print via
+ * their atomic or threaded flushing.
+ */
+ if ((flags & CON_NBCON) && (ft.nbcon_atomic || ft.nbcon_offload))
+ continue;
+
+ if (!console_is_usable(con, flags, !do_cond_resched))
+ continue;
+ *any_usable = true;
+
+ if (flags & CON_NBCON) {
+ progress = nbcon_legacy_emit_next_record(con, handover, cookie,
+ !do_cond_resched);
+ printk_seq = nbcon_seq_read(con);
+ } else {
+ progress = console_emit_next_record(con, handover, cookie);
+ printk_seq = con->seq;
+ }
+
+ /*
+ * If a handover has occurred, the SRCU read lock
+ * is already released.
+ */
+ if (*handover)
+ return false;
+
+ /* Track the next of the highest seq flushed. */
+ if (printk_seq > *next_seq)
+ *next_seq = printk_seq;
+
+ if (!progress)
+ continue;
+ any_progress = true;
+
+ /* Allow panic_cpu to take over the consoles safely. */
+ if (panic_on_other_cpu())
+ goto abandon;
+
+ if (do_cond_resched)
+ cond_resched();
+ }
+ console_srcu_read_unlock(cookie);
+
+ return any_progress;
+
+abandon:
+ console_srcu_read_unlock(cookie);
+ return false;
+}
+
/*
* Print out all remaining records to all consoles.
*
@@ -3180,77 +3273,24 @@ static inline void printk_kthreads_check_locked(void) { }
*/
static bool console_flush_all(bool do_cond_resched, u64 *next_seq, bool *handover)
{
- struct console_flush_type ft;
bool any_usable = false;
- struct console *con;
bool any_progress;
- int cookie;
*next_seq = 0;
*handover = false;
do {
- any_progress = false;
+ any_progress = console_flush_one_record(do_cond_resched, next_seq, handover,
+ &any_usable);
- printk_get_console_flush_type(&ft);
-
- cookie = console_srcu_read_lock();
- for_each_console_srcu(con) {
- short flags = console_srcu_read_flags(con);
- u64 printk_seq;
- bool progress;
+ if (*handover)
+ return false;
- /*
- * console_flush_all() is only responsible for nbcon
- * consoles when the nbcon consoles cannot print via
- * their atomic or threaded flushing.
- */
- if ((flags & CON_NBCON) && (ft.nbcon_atomic || ft.nbcon_offload))
- continue;
-
- if (!console_is_usable(con, flags, !do_cond_resched))
- continue;
- any_usable = true;
-
- if (flags & CON_NBCON) {
- progress = nbcon_legacy_emit_next_record(con, handover, cookie,
- !do_cond_resched);
- printk_seq = nbcon_seq_read(con);
- } else {
- progress = console_emit_next_record(con, handover, cookie);
- printk_seq = con->seq;
- }
-
- /*
- * If a handover has occurred, the SRCU read lock
- * is already released.
- */
- if (*handover)
- return false;
-
- /* Track the next of the highest seq flushed. */
- if (printk_seq > *next_seq)
- *next_seq = printk_seq;
-
- if (!progress)
- continue;
- any_progress = true;
-
- /* Allow panic_cpu to take over the consoles safely. */
- if (panic_on_other_cpu())
- goto abandon;
-
- if (do_cond_resched)
- cond_resched();
- }
- console_srcu_read_unlock(cookie);
+ if (panic_on_other_cpu())
+ return false;
} while (any_progress);
return any_usable;
-
-abandon:
- console_srcu_read_unlock(cookie);
- return false;
}
static void __console_flush_and_unlock(void)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0294/1518] printk: Fix possible console use-after-free
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (292 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0293/1518] printk: Introduce console_flush_one_record Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0295/1518] ACPI: RISC-V: Fix riscv_acpi_irq_get_dep() loop termination Greg Kroah-Hartman
` (704 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, John Ogness, Petr Mladek,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: John Ogness <john.ogness@linutronix.de>
[ Upstream commit 36630cafbeede0b64c370edb2f7b4094327ee1e0 ]
When emitting a record via legacy printing, it is possible that a handover
to another legacy printing context occurs. When a context has performed a
handover, the console SRCU read lock is released and the pointer to the
console struct might now be invalid. Therefore, after calling
nbcon_legacy_emit_next_record() or console_emit_next_record(), it is
necessary to check if a handover occurred _before_ further @con usage.
Sashiko pointed out that console_flush_one_record() was not doing this.
In console_flush_one_record(), after emitting a record, move the further
usage of @con after the handover check.
Fixes: c158834b223f ("printk: nbcon: Use nbcon consoles in console_flush_all()")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/lkml/20260630170903.099D61F000E9@smtp.kernel.org
Signed-off-by: John Ogness <john.ogness@linutronix.de>
Reviewed-by: Petr Mladek <pmladek@suse.com>
Link: https://patch.msgid.link/20260703141521.202813-1-john.ogness@linutronix.de
Signed-off-by: Petr Mladek <pmladek@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/printk/printk.c | 11 +++++++++--
1 file changed, 9 insertions(+), 2 deletions(-)
diff --git a/kernel/printk/printk.c b/kernel/printk/printk.c
index 8f3097664622d..ea9fff8f0da87 100644
--- a/kernel/printk/printk.c
+++ b/kernel/printk/printk.c
@@ -3211,10 +3211,8 @@ static bool console_flush_one_record(bool do_cond_resched, u64 *next_seq, bool *
if (flags & CON_NBCON) {
progress = nbcon_legacy_emit_next_record(con, handover, cookie,
!do_cond_resched);
- printk_seq = nbcon_seq_read(con);
} else {
progress = console_emit_next_record(con, handover, cookie);
- printk_seq = con->seq;
}
/*
@@ -3224,6 +3222,15 @@ static bool console_flush_one_record(bool do_cond_resched, u64 *next_seq, bool *
if (*handover)
return false;
+ /*
+ * @con can be used here now that it is certain that this
+ * context is still holding the SRCU read lock.
+ */
+ if (flags & CON_NBCON)
+ printk_seq = nbcon_seq_read(con);
+ else
+ printk_seq = con->seq;
+
/* Track the next of the highest seq flushed. */
if (printk_seq > *next_seq)
*next_seq = printk_seq;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0295/1518] ACPI: RISC-V: Fix riscv_acpi_irq_get_dep() loop termination
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (293 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0294/1518] printk: Fix possible console use-after-free Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0296/1518] ACPI: RISC-V: Check acpi_get_handle() status in riscv_acpi_add_prt_dep() Greg Kroah-Hartman
` (703 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Pieralisi, Sunil V L,
Rafael J. Wysocki, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lorenzo Pieralisi <lpieralisi@kernel.org>
[ Upstream commit 64ae310bffa477cd11029c818bec489f4b8a845e ]
In riscv_acpi_add_irq_dep() the main loop condition would currently stop
the loop if an interrupt descriptor contains an interrupt for which the
respective GSI handle is NULL, which is not correct because subsequent
interrupts in the interrupt descriptor might still have a GSI dependency
that must not be skipped.
Rework riscv_acpi_add_irq_dep() and the riscv_acpi_irq_get_dep() call chain
to fix it - by not forcing the loop to stop in order to guarantee
dependency detection for all the interrupt entries in the CRS descriptor.
Fixes: 1b173cc4bfcd ("ACPI: RISC-V: Implement function to add implicit dependencies")
Signed-off-by: Lorenzo Pieralisi <lpieralisi@kernel.org>
Tested-by: Sunil V L <sunilvl@oss.qualcomm.com>
Reviewed-by: Sunil V L <sunilvl@oss.qualcomm.com>
Link: https://patch.msgid.link/20260709-gic-v5-acpi-iwb-probe-deferral-v4-2-48dae790f871@kernel.org
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/riscv/irq.c | 10 ++++++----
1 file changed, 6 insertions(+), 4 deletions(-)
diff --git a/drivers/acpi/riscv/irq.c b/drivers/acpi/riscv/irq.c
index d9a2154d6c6ab..52bb2738fa61b 100644
--- a/drivers/acpi/riscv/irq.c
+++ b/drivers/acpi/riscv/irq.c
@@ -299,6 +299,7 @@ static acpi_status riscv_acpi_irq_get_parent(struct acpi_resource *ares, void *c
return AE_OK;
ctx->handle = riscv_acpi_get_gsi_handle(eirq->interrupts[ctx->index]);
+ ctx->rc = 0;
return AE_CTRL_TERMINATE;
}
@@ -314,10 +315,8 @@ static int riscv_acpi_irq_get_dep(acpi_handle handle, unsigned int index, acpi_h
acpi_walk_resources(handle, METHOD_NAME__CRS, riscv_acpi_irq_get_parent, &ctx);
*gsi_handle = ctx.handle;
- if (*gsi_handle)
- return 1;
- return 0;
+ return ctx.rc;
}
static u32 riscv_acpi_add_prt_dep(acpi_handle handle)
@@ -379,8 +378,11 @@ static u32 riscv_acpi_add_irq_dep(acpi_handle handle)
int i;
for (i = 0;
- riscv_acpi_irq_get_dep(handle, i, &gsi_handle);
+ !riscv_acpi_irq_get_dep(handle, i, &gsi_handle);
i++) {
+ if (!gsi_handle)
+ continue;
+
dep_devices.count = 1;
dep_devices.handles = kcalloc(1, sizeof(*dep_devices.handles), GFP_KERNEL);
if (!dep_devices.handles) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0296/1518] ACPI: RISC-V: Check acpi_get_handle() status in riscv_acpi_add_prt_dep()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (294 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0295/1518] ACPI: RISC-V: Fix riscv_acpi_irq_get_dep() loop termination Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0297/1518] ACPI: RISC-V: Fix riscv_acpi_add_prt_dep() loop handling Greg Kroah-Hartman
` (702 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Pieralisi, Sunil V L,
Rafael J. Wysocki, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lorenzo Pieralisi <lpieralisi@kernel.org>
[ Upstream commit 20435bda13f1219891ed0ce41207e320a916ff9c ]
In riscv_acpi_add_prt_dep(), the acpi_get_handle() call can fail which
would leave link_handle uninitialized.
Fix it by checking the acpi_get_handle() return status and skip the entry
if it fails.
Fixes: 1b173cc4bfcd ("ACPI: RISC-V: Implement function to add implicit dependencies")
Signed-off-by: Lorenzo Pieralisi <lpieralisi@kernel.org>
Tested-by: Sunil V L <sunilvl@oss.qualcomm.com>
Reviewed-by: Sunil V L <sunilvl@oss.qualcomm.com>
Link: https://patch.msgid.link/20260709-gic-v5-acpi-iwb-probe-deferral-v4-3-48dae790f871@kernel.org
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/riscv/irq.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/acpi/riscv/irq.c b/drivers/acpi/riscv/irq.c
index 52bb2738fa61b..46af9085dbce7 100644
--- a/drivers/acpi/riscv/irq.c
+++ b/drivers/acpi/riscv/irq.c
@@ -339,7 +339,9 @@ static u32 riscv_acpi_add_prt_dep(acpi_handle handle)
entry = buffer.pointer;
while (entry && (entry->length > 0)) {
if (entry->source[0]) {
- acpi_get_handle(handle, entry->source, &link_handle);
+ status = acpi_get_handle(handle, entry->source, &link_handle);
+ if (ACPI_FAILURE(status))
+ continue;
dep_devices.count = 1;
dep_devices.handles = kcalloc(1, sizeof(*dep_devices.handles), GFP_KERNEL);
if (!dep_devices.handles) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0297/1518] ACPI: RISC-V: Fix riscv_acpi_add_prt_dep() loop handling
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (295 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0296/1518] ACPI: RISC-V: Check acpi_get_handle() status in riscv_acpi_add_prt_dep() Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0298/1518] platform/x86: dell-privacy: Fix race condition Greg Kroah-Hartman
` (701 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Pieralisi, Sunil V L,
Rafael J. Wysocki, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lorenzo Pieralisi <lpieralisi@kernel.org>
[ Upstream commit 3a56321d0aceee2a0bd80d23366401c131ff8350 ]
The loop in riscv_acpi_add_prt_dep() includes error conditions that are
handled in a dubious - if not outright wrong - way, by continuining the
loop (which skips and misses the entry pointer update to point to the next
entry).
Rewrite the loop as a for loop (that handles the continuation correctly)
and wrap the condition and update statements using helper functions to make
it cleaner.
Fixes: 1b173cc4bfcd ("ACPI: RISC-V: Implement function to add implicit dependencies")
Signed-off-by: Lorenzo Pieralisi <lpieralisi@kernel.org>
Tested-by: Sunil V L <sunilvl@oss.qualcomm.com>
Reviewed-by: Sunil V L <sunilvl@oss.qualcomm.com>
Link: https://patch.msgid.link/20260709-gic-v5-acpi-iwb-probe-deferral-v4-4-48dae790f871@kernel.org
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/riscv/irq.c | 19 +++++++++++++++----
1 file changed, 15 insertions(+), 4 deletions(-)
diff --git a/drivers/acpi/riscv/irq.c b/drivers/acpi/riscv/irq.c
index 46af9085dbce7..f41ab67040374 100644
--- a/drivers/acpi/riscv/irq.c
+++ b/drivers/acpi/riscv/irq.c
@@ -319,6 +319,20 @@ static int riscv_acpi_irq_get_dep(acpi_handle handle, unsigned int index, acpi_h
return ctx.rc;
}
+static bool acpi_prt_entry_valid(void *prt_entry)
+{
+ struct acpi_pci_routing_table *entry = prt_entry;
+
+ return entry && entry->length > 0;
+}
+
+static void *acpi_prt_next_entry(void *prt_entry)
+{
+ struct acpi_pci_routing_table *entry = prt_entry;
+
+ return prt_entry + entry->length;
+}
+
static u32 riscv_acpi_add_prt_dep(acpi_handle handle)
{
struct acpi_buffer buffer = { ACPI_ALLOCATE_BUFFER, NULL };
@@ -337,7 +351,7 @@ static u32 riscv_acpi_add_prt_dep(acpi_handle handle)
}
entry = buffer.pointer;
- while (entry && (entry->length > 0)) {
+ for (; acpi_prt_entry_valid(entry); entry = acpi_prt_next_entry(entry)) {
if (entry->source[0]) {
status = acpi_get_handle(handle, entry->source, &link_handle);
if (ACPI_FAILURE(status))
@@ -363,9 +377,6 @@ static u32 riscv_acpi_add_prt_dep(acpi_handle handle)
dep_devices.handles[0] = gsi_handle;
count += acpi_scan_add_dep(handle, &dep_devices);
}
-
- entry = (struct acpi_pci_routing_table *)
- ((unsigned long)entry + entry->length);
}
kfree(buffer.pointer);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0298/1518] platform/x86: dell-privacy: Fix race condition
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (296 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0297/1518] ACPI: RISC-V: Fix riscv_acpi_add_prt_dep() loop handling Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0299/1518] platform/x86: dell-wmi-base: Fix resource leak on module load failure Greg Kroah-Hartman
` (700 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Armin Wolf, Ilpo Järvinen,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Armin Wolf <W_Armin@gmx.de>
[ Upstream commit ca9338dbc64759b30741b12017c050b33c94dfa2 ]
Accessing priv->features_present needs to happen with the list mutex
being held, otherwise priv can be freed at any moment.
Fixes: 8af9fa37b8a3 ("platform/x86: dell-privacy: Add support for Dell hardware privacy")
Signed-off-by: Armin Wolf <W_Armin@gmx.de>
Link: https://patch.msgid.link/20260612173451.467629-2-W_Armin@gmx.de
Reviewed-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/platform/x86/dell/dell-wmi-privacy.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/platform/x86/dell/dell-wmi-privacy.c b/drivers/platform/x86/dell/dell-wmi-privacy.c
index 4b65e1655d42a..7c2b6fae96c52 100644
--- a/drivers/platform/x86/dell/dell-wmi-privacy.c
+++ b/drivers/platform/x86/dell/dell-wmi-privacy.c
@@ -69,11 +69,11 @@ bool dell_privacy_has_mic_mute(void)
{
struct privacy_wmi_data *priv;
- mutex_lock(&list_mutex);
+ guard(mutex)(&list_mutex);
+
priv = list_first_entry_or_null(&wmi_list,
struct privacy_wmi_data,
list);
- mutex_unlock(&list_mutex);
return priv && (priv->features_present & BIT(DELL_PRIVACY_TYPE_AUDIO));
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0299/1518] platform/x86: dell-wmi-base: Fix resource leak on module load failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (297 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0298/1518] platform/x86: dell-privacy: Fix race condition Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0300/1518] platform/x86: lg-laptop: Drop debug-only ACPI notify handler Greg Kroah-Hartman
` (699 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Armin Wolf, Ilpo Järvinen,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Armin Wolf <W_Armin@gmx.de>
[ Upstream commit 072841e02cf9c00a7e8a9c567a14239e02ca47ad ]
We need to properly clean up the SMBIOS request and the privacy driver
when the module load fails.
Fixes: 8af9fa37b8a3 ("platform/x86: dell-privacy: Add support for Dell hardware privacy")
Signed-off-by: Armin Wolf <W_Armin@gmx.de>
Link: https://patch.msgid.link/20260612173451.467629-3-W_Armin@gmx.de
Reviewed-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/platform/x86/dell/dell-wmi-base.c | 17 +++++++++++++++--
1 file changed, 15 insertions(+), 2 deletions(-)
diff --git a/drivers/platform/x86/dell/dell-wmi-base.c b/drivers/platform/x86/dell/dell-wmi-base.c
index 907f1da01c8db..ba6c88e2a5ec0 100644
--- a/drivers/platform/x86/dell/dell-wmi-base.c
+++ b/drivers/platform/x86/dell/dell-wmi-base.c
@@ -851,9 +851,22 @@ static int __init dell_wmi_init(void)
err = dell_privacy_register_driver();
if (err)
- return err;
+ goto out_smbios;
- return wmi_driver_register(&dell_wmi_driver);
+ err = wmi_driver_register(&dell_wmi_driver);
+ if (err)
+ goto out_privacy;
+
+ return 0;
+
+out_privacy:
+ dell_privacy_unregister_driver();
+
+out_smbios:
+ if (wmi_requires_smbios_request)
+ dell_wmi_events_set_enabled(false);
+
+ return err;
}
late_initcall(dell_wmi_init);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0300/1518] platform/x86: lg-laptop: Drop debug-only ACPI notify handler
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (298 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0299/1518] platform/x86: dell-wmi-base: Fix resource leak on module load failure Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0301/1518] platform/x86: lg-laptop: Convert ACPI driver to a platform one Greg Kroah-Hartman
` (698 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rafael J. Wysocki,
Ilpo Järvinen, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
[ Upstream commit c12fe0b2c12195e0d1c56e0f670a6bd792b0567e ]
To facilitate subsequent conversion of the driver to using struct
platform_driver instead of struct acpi_driver, drop the debug-only
notify handler method from the driver.
No intentional functional impact beyond debug.
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/3346280.5fSG56mABF@rafael.j.wysocki
Reviewed-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Stable-dep-of: 3e91964aa74a ("platform/x86: lg-laptop: Fix LED resource handling")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/platform/x86/lg-laptop.c | 6 ------
1 file changed, 6 deletions(-)
diff --git a/drivers/platform/x86/lg-laptop.c b/drivers/platform/x86/lg-laptop.c
index 6af6cf477c5b5..6a45e6270941a 100644
--- a/drivers/platform/x86/lg-laptop.c
+++ b/drivers/platform/x86/lg-laptop.c
@@ -269,11 +269,6 @@ static void wmi_input_setup(void)
}
}
-static void acpi_notify(struct acpi_device *device, u32 event)
-{
- acpi_handle_debug(device->handle, "notify: %d\n", event);
-}
-
static ssize_t fan_mode_store(struct device *dev,
struct device_attribute *attr,
const char *buffer, size_t count)
@@ -886,7 +881,6 @@ static struct acpi_driver acpi_driver = {
.ops = {
.add = acpi_add,
.remove = acpi_remove,
- .notify = acpi_notify,
},
};
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0301/1518] platform/x86: lg-laptop: Convert ACPI driver to a platform one
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (299 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0300/1518] platform/x86: lg-laptop: Drop debug-only ACPI notify handler Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0302/1518] platform/x86: lg-laptop: Fix LED resource handling Greg Kroah-Hartman
` (697 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rafael J. Wysocki,
Ilpo Järvinen, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
[ Upstream commit 2d9cb20610f75ca48c1cac064aede90196787507 ]
In all cases in which a struct acpi_driver is used for binding a driver
to an ACPI device object, a corresponding platform device is created by
the ACPI core and that device is regarded as a proper representation of
underlying hardware. Accordingly, a struct platform_driver should be
used by driver code to bind to that device. There are multiple reasons
why drivers should not bind directly to ACPI device objects [1].
Overall, it is better to bind drivers to platform devices than to their
ACPI companions, so convert the LG Gram ACPI features and hotkeys driver
from an ACPI driver to a platform one.
While this is not expected to alter functionality, it changes sysfs
layout and so it will be visible to user space.
Link: https://lore.kernel.org/all/2396510.ElGaqSPkdT@rafael.j.wysocki/ [1]
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/1868365.VLH7GnMWUR@rafael.j.wysocki
Reviewed-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Stable-dep-of: 3e91964aa74a ("platform/x86: lg-laptop: Fix LED resource handling")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/platform/x86/lg-laptop.c | 45 +++++++++-----------------------
1 file changed, 13 insertions(+), 32 deletions(-)
diff --git a/drivers/platform/x86/lg-laptop.c b/drivers/platform/x86/lg-laptop.c
index 6a45e6270941a..a68c4867e696b 100644
--- a/drivers/platform/x86/lg-laptop.c
+++ b/drivers/platform/x86/lg-laptop.c
@@ -748,8 +748,9 @@ static void lg_laptop_remove_address_space_handler(void *data)
&lg_laptop_address_space_handler);
}
-static int acpi_add(struct acpi_device *device)
+static int acpi_probe(struct platform_device *pdev)
{
+ struct acpi_device *device = ACPI_COMPANION(&pdev->dev);
struct platform_device_info pdev_info = {
.fwnode = acpi_fwnode_handle(device),
.name = PLATFORM_NAME,
@@ -765,11 +766,11 @@ static int acpi_add(struct acpi_device *device)
status = acpi_install_address_space_handler(device->handle, LG_ADDRESS_SPACE_ID,
&lg_laptop_address_space_handler,
- NULL, &device->dev);
+ NULL, &pdev->dev);
if (ACPI_FAILURE(status))
return -ENODEV;
- ret = devm_add_action_or_reset(&device->dev, lg_laptop_remove_address_space_handler,
+ ret = devm_add_action_or_reset(&pdev->dev, lg_laptop_remove_address_space_handler,
device);
if (ret < 0)
return ret;
@@ -854,7 +855,7 @@ static int acpi_add(struct acpi_device *device)
return ret;
}
-static void acpi_remove(struct acpi_device *device)
+static void acpi_remove(struct platform_device *pdev)
{
sysfs_remove_group(&pf_device->dev.kobj, &dev_attribute_group);
@@ -874,33 +875,13 @@ static const struct acpi_device_id device_ids[] = {
};
MODULE_DEVICE_TABLE(acpi, device_ids);
-static struct acpi_driver acpi_driver = {
- .name = "LG Gram Laptop Support",
- .class = "lg-laptop",
- .ids = device_ids,
- .ops = {
- .add = acpi_add,
- .remove = acpi_remove,
- },
+static struct platform_driver acpi_driver = {
+ .probe = acpi_probe,
+ .remove = acpi_remove,
+ .driver = {
+ .name = "LG Gram Laptop Support",
+ .acpi_match_table = device_ids,
+ },
};
-static int __init acpi_init(void)
-{
- int result;
-
- result = acpi_bus_register_driver(&acpi_driver);
- if (result < 0) {
- pr_debug("Error registering driver\n");
- return -ENODEV;
- }
-
- return 0;
-}
-
-static void __exit acpi_exit(void)
-{
- acpi_bus_unregister_driver(&acpi_driver);
-}
-
-module_init(acpi_init);
-module_exit(acpi_exit);
+module_platform_driver(acpi_driver);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0302/1518] platform/x86: lg-laptop: Fix LED resource handling
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (300 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0301/1518] platform/x86: lg-laptop: Convert ACPI driver to a platform one Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0303/1518] remoteproc: qcom_q6v5_adsp: Fix reference leak for device node Greg Kroah-Hartman
` (696 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Armin Wolf, Ilpo Järvinen,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Armin Wolf <W_Armin@gmx.de>
[ Upstream commit 3e91964aa74ab261aa15d9d96318eded2fd9d22a ]
The event notification callback might access kbd_backlight even
when it was not successfully registered with the LED subsystem.
The same happens inside acpi_remove(), where the LED devices are
unregistered unconditionally.
Fix this by tracking the availability of the kbd_backlight LED
device and use devm_led_classdev_register() to let devres take
care of unregistering the LED devices during removal. For this
the parent device of the LED devices is changed to the native
platform device.
Fixes: ae26278829a8 ("platform/x86: lg-laptop: Use correct event for keyboard backlight FN-key")
Signed-off-by: Armin Wolf <W_Armin@gmx.de>
Link: https://patch.msgid.link/20260708195553.7762-2-W_Armin@gmx.de
Reviewed-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/platform/x86/lg-laptop.c | 21 ++++++++++++++-------
1 file changed, 14 insertions(+), 7 deletions(-)
diff --git a/drivers/platform/x86/lg-laptop.c b/drivers/platform/x86/lg-laptop.c
index a68c4867e696b..0a5c8f0471823 100644
--- a/drivers/platform/x86/lg-laptop.c
+++ b/drivers/platform/x86/lg-laptop.c
@@ -98,6 +98,7 @@ static u32 inited;
#define INIT_SPARSE_KEYMAP 0x80
static int battery_limit_use_wmbb;
+static bool kbd_backlight_available;
static struct led_classdev kbd_backlight;
static enum led_brightness get_kbd_backlight_level(struct device *dev);
@@ -212,6 +213,7 @@ static union acpi_object *lg_wmbb(struct device *dev, u32 method_id, u32 arg1, u
static void wmi_notify(union acpi_object *obj, void *context)
{
long data = (long)context;
+ unsigned int brightness;
pr_debug("event guid %li\n", data);
if (!obj)
@@ -222,8 +224,11 @@ static void wmi_notify(union acpi_object *obj, void *context)
struct key_entry *key;
if (eventcode == 0x10000000) {
- led_classdev_notify_brightness_hw_changed(
- &kbd_backlight, get_kbd_backlight_level(kbd_backlight.dev->parent));
+ if (kbd_backlight_available) {
+ brightness = get_kbd_backlight_level(kbd_backlight.dev->parent);
+ led_classdev_notify_brightness_hw_changed(&kbd_backlight,
+ brightness);
+ }
} else {
key = sparse_keymap_entry_from_scancode(
wmi_input_dev, eventcode);
@@ -840,8 +845,13 @@ static int acpi_probe(struct platform_device *pdev)
goto out_platform_device;
/* LEDs are optional */
- led_classdev_register(&pf_device->dev, &kbd_backlight);
- led_classdev_register(&pf_device->dev, &tpad_led);
+ ret = devm_led_classdev_register(&pdev->dev, &kbd_backlight);
+ if (ret < 0)
+ kbd_backlight_available = false;
+ else
+ kbd_backlight_available = true;
+
+ devm_led_classdev_register(&pdev->dev, &tpad_led);
wmi_input_setup();
battery_hook_register(&battery_hook);
@@ -859,9 +869,6 @@ static void acpi_remove(struct platform_device *pdev)
{
sysfs_remove_group(&pf_device->dev.kobj, &dev_attribute_group);
- led_classdev_unregister(&tpad_led);
- led_classdev_unregister(&kbd_backlight);
-
battery_hook_unregister(&battery_hook);
wmi_input_destroy();
platform_device_unregister(pf_device);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0303/1518] remoteproc: qcom_q6v5_adsp: Fix reference leak for device node
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (301 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0302/1518] platform/x86: lg-laptop: Fix LED resource handling Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0304/1518] hwspinlock: propagate errno when registering single lock Greg Kroah-Hartman
` (695 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Gu, Bjorn Andersson,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Gu <gu_0233@qq.com>
[ Upstream commit 8c952807c2cebd5e9e9b37146c9383229794c129 ]
When calling of_parse_phandle_with_args(), the caller is responsible
to call of_node_put() to release the reference of device node.
In adsp_map_carveout, it does not release the reference.
Fixes: f22eedff28af ("remoteproc: qcom: Add support for memory sandbox")
Signed-off-by: Felix Gu <gu_0233@qq.com>
Link: https://lore.kernel.org/r/tencent_EDC2253D3B1C22217E1259E07765D269100A@qq.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/remoteproc/qcom_q6v5_adsp.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/remoteproc/qcom_q6v5_adsp.c b/drivers/remoteproc/qcom_q6v5_adsp.c
index e98b7e03162c7..b7d472afd5a9b 100644
--- a/drivers/remoteproc/qcom_q6v5_adsp.c
+++ b/drivers/remoteproc/qcom_q6v5_adsp.c
@@ -355,6 +355,7 @@ static int adsp_map_carveout(struct rproc *rproc)
return ret;
sid = args.args[0] & SID_MASK_DEFAULT;
+ of_node_put(args.np);
/* Add SID configuration for ADSP Firmware to SMMU */
iova = adsp->mem_phys | (sid << 32);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0304/1518] hwspinlock: propagate errno when registering single lock
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (302 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0303/1518] remoteproc: qcom_q6v5_adsp: Fix reference leak for device node Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0305/1518] selftests/sched_ext: Fix bpf_link leak on early return in prog_run Greg Kroah-Hartman
` (694 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Wolfram Sang, Bjorn Andersson,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Wolfram Sang <wsa+renesas@sang-engineering.com>
[ Upstream commit e088ffa9a00eaaaf90da74763e774ca160969c26 ]
hwspin_lock_register_single() always returns 0 despite checking the
result from radix_tree_insert(). Propagate the errno to make sanity
checks in callers of this function actually meaningful.
Fixes: 300bab9770e2 ("hwspinlock/core: register a bank of hwspinlocks in a single API call")
Link: https://sashiko.dev/#/patchset/20260319105947.6237-1-wsa%2Brenesas%40sang-engineering.com # review of patch 14
Signed-off-by: Wolfram Sang <wsa+renesas@sang-engineering.com>
Link: https://lore.kernel.org/r/20260512084856.30497-2-wsa+renesas@sang-engineering.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwspinlock/hwspinlock_core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/hwspinlock/hwspinlock_core.c b/drivers/hwspinlock/hwspinlock_core.c
index cc8e952a67727..a509b73da190d 100644
--- a/drivers/hwspinlock/hwspinlock_core.c
+++ b/drivers/hwspinlock/hwspinlock_core.c
@@ -472,7 +472,7 @@ static int hwspin_lock_register_single(struct hwspinlock *hwlock, int id)
out:
mutex_unlock(&hwspinlock_tree_lock);
- return 0;
+ return ret;
}
static struct hwspinlock *hwspin_lock_unregister_single(unsigned int id)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0305/1518] selftests/sched_ext: Fix bpf_link leak on early return in prog_run
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (303 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0304/1518] hwspinlock: propagate errno when registering single lock Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0306/1518] perf capstone: Fix kernel map reference count leak Greg Kroah-Hartman
` (693 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Liang Luo, Andrea Righi, Tejun Heo,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Liang Luo <luoliang@kylinos.cn>
[ Upstream commit e655c1f1bd14804f398df7da029c4a7e3f9ccd7f ]
In prog_run's run(), the bpf_link is attached early but only destroyed
on the success path. The three SCX_EQ assertions between attach and
destroy expand to a direct 'return SCX_TEST_FAIL', so if any of them
triggers, bpf_link__destroy() is never reached and the BPF scheduler
stays loaded. All subsequent tests then fail to attach because SCX is
not in the DISABLED state.
Convert those assertions to explicit checks that jump to a unified
'out' label which always runs the cleanup, matching the pattern used
in cyclic_kick_wait.c.
Fixes: a5db7817af78 ("sched_ext: Add selftests")
Signed-off-by: Liang Luo <luoliang@kylinos.cn>
Reviewed-by: Andrea Righi <arighi@nvidia.com>
Signed-off-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/sched_ext/prog_run.c | 34 +++++++++++++++-----
1 file changed, 26 insertions(+), 8 deletions(-)
diff --git a/tools/testing/selftests/sched_ext/prog_run.c b/tools/testing/selftests/sched_ext/prog_run.c
index 05974820ca69d..1129ec2aaddc7 100644
--- a/tools/testing/selftests/sched_ext/prog_run.c
+++ b/tools/testing/selftests/sched_ext/prog_run.c
@@ -28,7 +28,8 @@ static enum scx_test_status setup(void **ctx)
static enum scx_test_status run(void *ctx)
{
struct prog_run *skel = ctx;
- struct bpf_link *link;
+ struct bpf_link *link = NULL;
+ enum scx_test_status status = SCX_TEST_PASS;
int prog_fd, err = 0;
prog_fd = bpf_program__fd(skel->progs.prog_run_syscall);
@@ -42,23 +43,40 @@ static enum scx_test_status run(void *ctx)
link = bpf_map__attach_struct_ops(skel->maps.prog_run_ops);
if (!link) {
SCX_ERR("Failed to attach scheduler");
- close(prog_fd);
- return SCX_TEST_FAIL;
+ status = SCX_TEST_FAIL;
+ goto out;
}
err = bpf_prog_test_run_opts(prog_fd, &topts);
- SCX_EQ(err, 0);
+ if (err) {
+ SCX_ERR("BPF_PROG_RUN failed (%d)", err);
+ status = SCX_TEST_FAIL;
+ goto out;
+ }
/* Assumes uei.kind is written last */
while (skel->data->uei.kind == EXIT_KIND(SCX_EXIT_NONE))
sched_yield();
- SCX_EQ(skel->data->uei.kind, EXIT_KIND(SCX_EXIT_UNREG_BPF));
- SCX_EQ(skel->data->uei.exit_code, 0xdeadbeef);
+ if (skel->data->uei.kind != EXIT_KIND(SCX_EXIT_UNREG_BPF)) {
+ SCX_ERR("Unexpected exit kind: %llu",
+ (unsigned long long)skel->data->uei.kind);
+ status = SCX_TEST_FAIL;
+ goto out;
+ }
+ if (skel->data->uei.exit_code != 0xdeadbeef) {
+ SCX_ERR("Unexpected exit code: %lld",
+ (long long)skel->data->uei.exit_code);
+ status = SCX_TEST_FAIL;
+ goto out;
+ }
+
+out:
close(prog_fd);
- bpf_link__destroy(link);
+ if (link)
+ bpf_link__destroy(link);
- return SCX_TEST_PASS;
+ return status;
}
static void cleanup(void *ctx)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0306/1518] perf capstone: Fix kernel map reference count leak
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (304 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0305/1518] selftests/sched_ext: Fix bpf_link leak on early return in prog_run Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0307/1518] spi: qcom-geni: Fix missing error check on pm_runtime_get_sync() Greg Kroah-Hartman
` (692 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Tengda Wu, Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tengda Wu <wutengda@huaweicloud.com>
[ Upstream commit d3c9fca531e2465f3a8f585965f3d10e1a6595ff ]
In print_capstone_detail(), maps__find() is used to locate the kernel
map. This function increments the reference count of the found map
object. However, the current implementation fails to call map__put()
after the map is no longer needed, leading to a reference count leak.
Fix this by adding a map__put(map) call to properly release the
reference after use.
Fixes: 92dfc59463d5 ("perf annotate: Add symbol name when using capstone")
Signed-off-by: Tengda Wu <wutengda@huaweicloud.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/capstone.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
diff --git a/tools/perf/util/capstone.c b/tools/perf/util/capstone.c
index 2c7feab61b7bf..1e2b697c86fc5 100644
--- a/tools/perf/util/capstone.c
+++ b/tools/perf/util/capstone.c
@@ -156,6 +156,7 @@ static void print_capstone_detail(cs_insn *insn, char *buf, size_t len,
for (i = 0; i < insn->detail->x86.op_count; i++) {
cs_x86_op *op = &insn->detail->x86.operands[i];
u64 orig_addr;
+ struct map *found_map = NULL;
if (op->type != X86_OP_MEM)
continue;
@@ -171,19 +172,22 @@ static void print_capstone_detail(cs_insn *insn, char *buf, size_t len,
if (dso__kernel(map__dso(map))) {
/*
* The kernel maps can be split into sections, let's
- * find the map first and the search the symbol.
+ * find the map first and then search the symbol.
*/
- map = maps__find(map__kmaps(map), addr);
- if (map == NULL)
+ found_map = maps__find(map__kmaps(map), addr);
+ if (found_map == NULL)
continue;
+ map = found_map;
}
/* convert it to map-relative address for search */
addr = map__map_ip(map, addr);
sym = map__find_symbol(map, addr);
- if (sym == NULL)
+ if (sym == NULL) {
+ map__put(found_map);
continue;
+ }
if (addr == sym->start) {
scnprintf(buf, len, "\t# %"PRIx64" <%s>",
@@ -192,6 +196,7 @@ static void print_capstone_detail(cs_insn *insn, char *buf, size_t len,
scnprintf(buf, len, "\t# %"PRIx64" <%s+%#"PRIx64">",
orig_addr, sym->name, addr - sym->start);
}
+ map__put(found_map);
break;
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0307/1518] spi: qcom-geni: Fix missing error check on pm_runtime_get_sync()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (305 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0306/1518] perf capstone: Fix kernel map reference count leak Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0308/1518] serial: core: Add dedicated uart_port field for console flow Greg Kroah-Hartman
` (691 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rafael J. Wysocki (Intel),
Konrad Dybcio, Praveen Talari, Mark Brown, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Praveen Talari <praveen.talari@oss.qualcomm.com>
[ Upstream commit d8e9ea989acb54508477e4a8c9d9eaf8217e0081 ]
spi_geni_init() calls pm_runtime_get_sync() to power up the device
before accessing hardware registers, but never checks the return value.
If the runtime resume fails, the function silently proceeds to read and
write hardware registers on a device that may not be powered up, leading
to register access faults.
Fix this by replacing pm_runtime_get_sync() with the
PM_RUNTIME_ACQUIRE_IF_ENABLED() macro and checking the result via
PM_RUNTIME_ACQUIRE_ERR(), propagating any error back to the caller
immediately before any hardware access occurs.
Since the macro handles its own cleanup on failure, the out_pm label and
the corresponding pm_runtime_put() call are no longer needed. Replace
all goto out_pm paths with direct return ret statements and remove the
label entirely.
Fixes: 561de45f72bd ("spi: spi-geni-qcom: Add SPI driver support for GENI based QUP")
Reviewed-by: Rafael J. Wysocki (Intel) <rafael@kernel.org>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Praveen Talari <praveen.talari@oss.qualcomm.com>
Link: https://patch.msgid.link/20260710-fix_sticky_-einval_after_pm_runtime_api_failure-v4-2-be81d6c15043@oss.qualcomm.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/spi/spi-geni-qcom.c | 17 ++++++++++-------
1 file changed, 10 insertions(+), 7 deletions(-)
diff --git a/drivers/spi/spi-geni-qcom.c b/drivers/spi/spi-geni-qcom.c
index 736120107184f..117ff94df9430 100644
--- a/drivers/spi/spi-geni-qcom.c
+++ b/drivers/spi/spi-geni-qcom.c
@@ -657,25 +657,30 @@ static int spi_geni_init(struct spi_geni_master *mas)
u32 spi_tx_cfg, fifo_disable;
int ret = -ENXIO;
- pm_runtime_get_sync(mas->dev);
+ PM_RUNTIME_ACQUIRE_IF_ENABLED(mas->dev, pm);
+ ret = PM_RUNTIME_ACQUIRE_ERR(&pm);
+ if (ret < 0) {
+ dev_err(mas->dev, "Failed to resume and get %d\n", ret);
+ return ret;
+ }
proto = geni_se_read_proto(se);
if (spi->target) {
if (proto != GENI_SE_SPI_SLAVE) {
dev_err(mas->dev, "Invalid proto %d\n", proto);
- goto out_pm;
+ return ret;
}
spi_slv_setup(mas);
} else if (proto == GENI_SE_INVALID_PROTO) {
ret = geni_load_se_firmware(se, GENI_SE_SPI);
if (ret) {
dev_err(mas->dev, "spi master firmware load failed ret: %d\n", ret);
- goto out_pm;
+ return ret;
}
} else if (proto != GENI_SE_SPI) {
dev_err(mas->dev, "Invalid proto %d\n", proto);
- goto out_pm;
+ return ret;
}
mas->tx_fifo_depth = geni_se_get_tx_fifo_depth(se);
@@ -708,7 +713,7 @@ static int spi_geni_init(struct spi_geni_master *mas)
dev_dbg(mas->dev, "Using GPI DMA mode for SPI\n");
break;
} else if (ret == -EPROBE_DEFER) {
- goto out_pm;
+ return ret;
}
/*
* in case of failure to get gpi dma channel, we can still do the
@@ -737,8 +742,6 @@ static int spi_geni_init(struct spi_geni_master *mas)
writel(spi_tx_cfg, se->base + SE_SPI_TRANS_CFG);
}
-out_pm:
- pm_runtime_put(mas->dev);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0308/1518] serial: core: Add dedicated uart_port field for console flow
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (306 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0307/1518] spi: qcom-geni: Fix missing error check on pm_runtime_get_sync() Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0309/1518] serial: Replace driver usage of UPF_CONS_FLOW Greg Kroah-Hartman
` (690 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, John Ogness, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: John Ogness <john.ogness@linutronix.de>
[ Upstream commit 9c7eb1c9c3e3bfecb556fc8fa1b68939385444de ]
Currently the UPF_CONS_FLOW bit in the uart_port.flags field is used
by serial console drivers to identify if a user has configured flow
control on the console. Usually this policy is setup during early
boot, but can be changed at runtime.
The bits in uart_port.flags are either hardware and driver
properties that are initialized before usage or are properties that
can be changed via the tty layer.
The UPF_CONS_FLOW bit is an exception because it is a console-only
policy that can change at runtime and its setting and usage have
nothing to do with the tty layer. This actually causes a problem
for its usage because uart_port.flags is synchronized by a related
tty_port.mutex, but a console has no relation to a tty (other than
sharing the port).
This is probably why console flow control is not properly available
for most serial drivers. And it is hindering being able to provide a
proper implementation. Commit d01f4d181c92 ("serial: core: Privatize
tty->hw_stopped") addressed a similar issue to deal with software
assisted CTS flow state tracking.
Add a new uart_port boolean field "cons_flow" to store the user
configuration for console flow control. Add getter/setter wrappers
to allow for adding more policies later and/or locking constraint
validation.
Mark UPF_CONS_FLOW as deprecated.
Signed-off-by: John Ogness <john.ogness@linutronix.de>
Link: https://patch.msgid.link/20260506121606.5805-2-john.ogness@linutronix.de
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Stable-dep-of: d338ab1d9060 ("serial: 8250: Clear CON_PRINTBUFFER on port re-registration")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/serial_core.h | 12 ++++++++++++
1 file changed, 12 insertions(+)
diff --git a/include/linux/serial_core.h b/include/linux/serial_core.h
index 110ad4e2aef99..d1404c97dc524 100644
--- a/include/linux/serial_core.h
+++ b/include/linux/serial_core.h
@@ -533,6 +533,7 @@ struct uart_port {
#define UPF_HARD_FLOW ((__force upf_t) (UPF_AUTO_CTS | UPF_AUTO_RTS))
/* Port has hardware-assisted s/w flow control */
#define UPF_SOFT_FLOW ((__force upf_t) BIT_ULL(22))
+/* Deprecated: use uart_set_cons_flow_enabled()/uart_cons_flow_enabled() instead. */
#define UPF_CONS_FLOW ((__force upf_t) BIT_ULL(23))
#define UPF_SHARE_IRQ ((__force upf_t) BIT_ULL(24))
#define UPF_EXAR_EFR ((__force upf_t) BIT_ULL(25))
@@ -567,6 +568,7 @@ struct uart_port {
#define UPSTAT_SYNC_FIFO ((__force upstat_t) (1 << 5))
bool hw_stopped; /* sw-assisted CTS flow state */
+ bool cons_flow; /* user specified console flow control */
unsigned int mctrl; /* current modem ctrl settings */
unsigned int frame_time; /* frame timing in ns */
unsigned int type; /* port type */
@@ -1163,6 +1165,16 @@ static inline bool uart_softcts_mode(struct uart_port *uport)
return ((uport->status & mask) == UPSTAT_CTS_ENABLE);
}
+static inline void uart_set_cons_flow_enabled(struct uart_port *uport, bool enabled)
+{
+ uport->cons_flow = enabled;
+}
+
+static inline bool uart_cons_flow_enabled(const struct uart_port *uport)
+{
+ return uport->cons_flow;
+}
+
/*
* The following are helper functions for the low level drivers.
*/
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0309/1518] serial: Replace driver usage of UPF_CONS_FLOW
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (307 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0308/1518] serial: core: Add dedicated uart_port field for console flow Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0310/1518] serial: 8250: Set cons_flow on port registration Greg Kroah-Hartman
` (689 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, John Ogness, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: John Ogness <john.ogness@linutronix.de>
[ Upstream commit bf558715d91cfa28f283de7105a879a92da31fb7 ]
Rather than using the UPF_CONS_FLOW bit of uart_port.flags to track
the user configuration of console flow control, use the newly added
uart_port.cons_flow (via its getter/setter functions).
A coccinelle script was used to perform the search/replace.
Note1: The sh-sci driver is blindly copying platform data configuration
flags to uart_port.flags. Thus UPF_CONS_FLOW could get set for
uart_port.flags. A follow-up commit will address this.
Note2: The samsung_tty driver is using UPF_CONS_FLOW as a platform data
configuration flag. However, the driver explicitly checks for
this configuration flag and thus setting UPF_CONS_FLOW in
uart_port.flags is avoided.
Signed-off-by: John Ogness <john.ogness@linutronix.de>
Link: https://patch.msgid.link/20260506121606.5805-3-john.ogness@linutronix.de
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Stable-dep-of: d338ab1d9060 ("serial: 8250: Clear CON_PRINTBUFFER on port re-registration")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/tty/serial/8250/8250_port.c | 4 ++--
drivers/tty/serial/bcm63xx_uart.c | 2 +-
drivers/tty/serial/omap-serial.c | 2 +-
drivers/tty/serial/pch_uart.c | 2 +-
drivers/tty/serial/pxa.c | 2 +-
drivers/tty/serial/samsung_tty.c | 8 ++++----
drivers/tty/serial/serial_txx9.c | 4 ++--
drivers/tty/serial/sunsu.c | 2 +-
8 files changed, 13 insertions(+), 13 deletions(-)
diff --git a/drivers/tty/serial/8250/8250_port.c b/drivers/tty/serial/8250/8250_port.c
index 0c633639f7657..9d560ddc81d1d 100644
--- a/drivers/tty/serial/8250/8250_port.c
+++ b/drivers/tty/serial/8250/8250_port.c
@@ -1991,7 +1991,7 @@ static void wait_for_xmitr(struct uart_8250_port *up, int bits)
wait_for_lsr(up, bits);
/* Wait up to 1s for flow control if necessary */
- if (up->port.flags & UPF_CONS_FLOW) {
+ if (uart_cons_flow_enabled(&up->port)) {
for (tmout = 1000000; tmout; tmout--) {
unsigned int msr = serial_in(up, UART_MSR);
up->msr_saved_flags |= msr & MSR_SAVE_FLAGS;
@@ -3354,7 +3354,7 @@ void serial8250_console_write(struct uart_8250_port *up, const char *s,
* it regardless of the CTS state. Therefore, only use fifo
* if we don't use control flow.
*/
- !(up->port.flags & UPF_CONS_FLOW);
+ !uart_cons_flow_enabled(&up->port);
if (likely(use_fifo))
serial8250_console_fifo_write(up, s, count);
diff --git a/drivers/tty/serial/bcm63xx_uart.c b/drivers/tty/serial/bcm63xx_uart.c
index 51df9d2d8bfc5..544695cb184c3 100644
--- a/drivers/tty/serial/bcm63xx_uart.c
+++ b/drivers/tty/serial/bcm63xx_uart.c
@@ -675,7 +675,7 @@ static void wait_for_xmitr(struct uart_port *port)
}
/* Wait up to 1s for flow control if necessary */
- if (port->flags & UPF_CONS_FLOW) {
+ if (uart_cons_flow_enabled(port)) {
tmout = 1000000;
while (--tmout) {
unsigned int val;
diff --git a/drivers/tty/serial/omap-serial.c b/drivers/tty/serial/omap-serial.c
index 0b85f47ff19e0..a689d190940cf 100644
--- a/drivers/tty/serial/omap-serial.c
+++ b/drivers/tty/serial/omap-serial.c
@@ -1092,7 +1092,7 @@ static void __maybe_unused wait_for_xmitr(struct uart_omap_port *up)
} while (!uart_lsr_tx_empty(status));
/* Wait up to 1s for flow control if necessary */
- if (up->port.flags & UPF_CONS_FLOW) {
+ if (uart_cons_flow_enabled(&up->port)) {
for (tmout = 1000000; tmout; tmout--) {
unsigned int msr = serial_in(up, UART_MSR);
diff --git a/drivers/tty/serial/pch_uart.c b/drivers/tty/serial/pch_uart.c
index 9992fa231e4e8..c3f32e0590b7f 100644
--- a/drivers/tty/serial/pch_uart.c
+++ b/drivers/tty/serial/pch_uart.c
@@ -1451,7 +1451,7 @@ static void wait_for_xmitr(struct eg20t_port *up, int bits)
}
/* Wait up to 1s for flow control if necessary */
- if (up->port.flags & UPF_CONS_FLOW) {
+ if (uart_cons_flow_enabled(&up->port)) {
unsigned int tmout;
for (tmout = 1000000; tmout; tmout--) {
unsigned int msr = ioread8(up->membase + UART_MSR);
diff --git a/drivers/tty/serial/pxa.c b/drivers/tty/serial/pxa.c
index e395ff29c1a2c..027d936b50239 100644
--- a/drivers/tty/serial/pxa.c
+++ b/drivers/tty/serial/pxa.c
@@ -573,7 +573,7 @@ static void wait_for_xmitr(struct uart_pxa_port *up)
} while (!uart_lsr_tx_empty(status));
/* Wait up to 1s for flow control if necessary */
- if (up->port.flags & UPF_CONS_FLOW) {
+ if (uart_cons_flow_enabled(&up->port)) {
tmout = 1000000;
while (--tmout &&
((serial_in(up, UART_MSR) & UART_MSR_CTS) == 0))
diff --git a/drivers/tty/serial/samsung_tty.c b/drivers/tty/serial/samsung_tty.c
index 7a0b89d856c2d..59d58fb743a31 100644
--- a/drivers/tty/serial/samsung_tty.c
+++ b/drivers/tty/serial/samsung_tty.c
@@ -311,7 +311,7 @@ static void s3c24xx_serial_stop_tx(struct uart_port *port)
ourport->tx_enabled = 0;
ourport->tx_in_progress = 0;
- if (port->flags & UPF_CONS_FLOW)
+ if (uart_cons_flow_enabled(port))
s3c24xx_serial_rx_enable(port);
ourport->tx_mode = 0;
@@ -485,7 +485,7 @@ static void s3c24xx_serial_start_tx(struct uart_port *port)
struct tty_port *tport = &port->state->port;
if (!ourport->tx_enabled) {
- if (port->flags & UPF_CONS_FLOW)
+ if (uart_cons_flow_enabled(port))
s3c24xx_serial_rx_disable(port);
ourport->tx_enabled = 1;
@@ -773,7 +773,7 @@ static void s3c24xx_serial_rx_drain_fifo(struct s3c24xx_uart_port *ourport)
uerstat = rd_regl(port, S3C2410_UERSTAT);
ch = rd_reg(port, S3C2410_URXH);
- if (port->flags & UPF_CONS_FLOW) {
+ if (uart_cons_flow_enabled(port)) {
bool txe = s3c24xx_serial_txempty_nofifo(port);
if (ourport->rx_enabled) {
@@ -1828,7 +1828,7 @@ static int s3c24xx_serial_init_port(struct s3c24xx_uart_port *ourport,
if (cfg->uart_flags & UPF_CONS_FLOW) {
dev_dbg(port->dev, "enabling flow control\n");
- port->flags |= UPF_CONS_FLOW;
+ uart_set_cons_flow_enabled(port, true);
}
/* sort our the physical and virtual addresses for each UART */
diff --git a/drivers/tty/serial/serial_txx9.c b/drivers/tty/serial/serial_txx9.c
index 436a559234dfe..4ae9a45c8e3a3 100644
--- a/drivers/tty/serial/serial_txx9.c
+++ b/drivers/tty/serial/serial_txx9.c
@@ -422,7 +422,7 @@ static void wait_for_xmitr(struct uart_port *up)
udelay(1);
/* Wait up to 1s for flow control if necessary */
- if (up->flags & UPF_CONS_FLOW) {
+ if (uart_cons_flow_enabled(up)) {
tmout = 1000000;
while (--tmout &&
(sio_in(up, TXX9_SICISR) & TXX9_SICISR_CTSS))
@@ -857,7 +857,7 @@ serial_txx9_console_write(struct console *co, const char *s, unsigned int count)
* Disable flow-control if enabled (and unnecessary)
*/
flcr = sio_in(up, TXX9_SIFLCR);
- if (!(up->flags & UPF_CONS_FLOW) && (flcr & TXX9_SIFLCR_TES))
+ if (!uart_cons_flow_enabled(up) && (flcr & TXX9_SIFLCR_TES))
sio_out(up, TXX9_SIFLCR, flcr & ~TXX9_SIFLCR_TES);
uart_console_write(up, s, count, serial_txx9_console_putchar);
diff --git a/drivers/tty/serial/sunsu.c b/drivers/tty/serial/sunsu.c
index 383141fe7ba0d..f71937fbe8aa9 100644
--- a/drivers/tty/serial/sunsu.c
+++ b/drivers/tty/serial/sunsu.c
@@ -1245,7 +1245,7 @@ static void wait_for_xmitr(struct uart_sunsu_port *up)
} while (!uart_lsr_tx_empty(status));
/* Wait up to 1s for flow control if necessary */
- if (up->port.flags & UPF_CONS_FLOW) {
+ if (uart_cons_flow_enabled(&up->port)) {
tmout = 1000000;
while (--tmout &&
((serial_in(up, UART_MSR) & UART_MSR_CTS) == 0))
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0310/1518] serial: 8250: Set cons_flow on port registration
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (308 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0309/1518] serial: Replace driver usage of UPF_CONS_FLOW Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0311/1518] serial: 8250: Add support for console flow control Greg Kroah-Hartman
` (688 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, John Ogness, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: John Ogness <john.ogness@linutronix.de>
[ Upstream commit f69ec492244d54068f08c20f90979274d8ac3655 ]
Since console flow control policy is no longer part of uart_port.flags,
explicitly set the policy for the port.
Signed-off-by: John Ogness <john.ogness@linutronix.de>
Link: https://patch.msgid.link/20260511152706.151498-2-john.ogness@linutronix.de
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Stable-dep-of: d338ab1d9060 ("serial: 8250: Clear CON_PRINTBUFFER on port re-registration")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/tty/serial/8250/8250_core.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/tty/serial/8250/8250_core.c b/drivers/tty/serial/8250/8250_core.c
index bfa421ab32536..d8baeee9cca52 100644
--- a/drivers/tty/serial/8250/8250_core.c
+++ b/drivers/tty/serial/8250/8250_core.c
@@ -742,6 +742,8 @@ int serial8250_register_8250_port(const struct uart_8250_port *up)
uart->lsr_save_mask = up->lsr_save_mask;
uart->dma = up->dma;
+ uart_set_cons_flow_enabled(&uart->port, uart_cons_flow_enabled(&up->port));
+
/* Take tx_loadsz from fifosize if it wasn't set separately */
if (uart->port.fifosize && !uart->tx_loadsz)
uart->tx_loadsz = uart->port.fifosize;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0311/1518] serial: 8250: Add support for console flow control
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (309 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0310/1518] serial: 8250: Set cons_flow on port registration Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0312/1518] serial: 8250: Clear CON_PRINTBUFFER on port re-registration Greg Kroah-Hartman
` (687 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, John Ogness, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: John Ogness <john.ogness@linutronix.de>
[ Upstream commit 5e6dfb87b191f34b1bb7cfb4d668665e5b70687b ]
The kernel documentation specifies that the console option 'r' can
be used to enable hardware flow control for console writes. The 8250
driver does include code for hardware flow control on the console if
cons_flow is set, but there is no code path that actually sets this.
However, that is not the only issue. The problems are:
1. Specifying the console option 'r' does not lead to cons_flow being
set.
2. Even if cons_flow would be set, serial8250_register_8250_port()
clears it.
3. When the console option 'r' is specified, uart_set_options()
attempts to initialize the port for CRTSCTS. However, afterwards
it does not set the UPSTAT_CTS_ENABLE status bit and therefore on
boot, uart_cts_enabled() is always false. This policy bit is
important for console drivers as a criteria if they may poll CTS.
4. Even though uart_set_options() attempts to initialize the port
for CRTSCTS, the 8250 set_termios() callback does not enable the
RTS signal (TIOCM_RTS) and thus the hardware is not properly
initialized for CTS polling.
5. Even if modem control was properly setup for CTS polling
(TIOCM_RTS), uart_configure_port() clears TIOCM_RTS, thus
breaking CTS polling.
6. wait_for_xmitr() and serial8250_console_write() use cons_flow
to decide if CTS polling should occur. However, the condition
should also include a check that it is not in RS485 mode and
CRTSCTS is actually enabled in the hardware.
Address all these issues as conservatively as possible by gating them
behind checks focussed on the user specifying console hardware flow
control support and the hardware being configured for CTS polling
at the time of the write to the UART.
Since checking the UPSTAT_CTS_ENABLE status bit is a part of the new
condition gate, these changes also support runtime termios updates to
disable/enable CRTSCTS.
Signed-off-by: John Ogness <john.ogness@linutronix.de>
Link: https://patch.msgid.link/20260511152706.151498-4-john.ogness@linutronix.de
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Stable-dep-of: d338ab1d9060 ("serial: 8250: Clear CON_PRINTBUFFER on port re-registration")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/tty/serial/8250/8250_core.c | 6 +++++-
drivers/tty/serial/8250/8250_port.c | 13 +++++++++++--
drivers/tty/serial/serial_core.c | 21 ++++++++++++++++++++-
include/linux/serial_core.h | 8 ++++++++
4 files changed, 44 insertions(+), 4 deletions(-)
diff --git a/drivers/tty/serial/8250/8250_core.c b/drivers/tty/serial/8250/8250_core.c
index d8baeee9cca52..ccd5a18f53356 100644
--- a/drivers/tty/serial/8250/8250_core.c
+++ b/drivers/tty/serial/8250/8250_core.c
@@ -689,6 +689,7 @@ static void serial_8250_overrun_backoff_work(struct work_struct *work)
int serial8250_register_8250_port(const struct uart_8250_port *up)
{
struct uart_8250_port *uart;
+ bool cons_flow;
int ret;
if (up->port.uartclk == 0)
@@ -712,6 +713,9 @@ int serial8250_register_8250_port(const struct uart_8250_port *up)
if (uart->port.type == PORT_8250_CIR)
return -ENODEV;
+ /* Preserve specified console flow control. */
+ cons_flow = uart_cons_flow_enabled(&uart->port);
+
if (uart->port.dev)
uart_remove_one_port(&serial8250_reg, &uart->port);
@@ -742,7 +746,7 @@ int serial8250_register_8250_port(const struct uart_8250_port *up)
uart->lsr_save_mask = up->lsr_save_mask;
uart->dma = up->dma;
- uart_set_cons_flow_enabled(&uart->port, uart_cons_flow_enabled(&up->port));
+ uart_set_cons_flow_enabled(&uart->port, uart_cons_flow_enabled(&up->port) | cons_flow);
/* Take tx_loadsz from fifosize if it wasn't set separately */
if (uart->port.fifosize && !uart->tx_loadsz)
diff --git a/drivers/tty/serial/8250/8250_port.c b/drivers/tty/serial/8250/8250_port.c
index 9d560ddc81d1d..19b5b754a132d 100644
--- a/drivers/tty/serial/8250/8250_port.c
+++ b/drivers/tty/serial/8250/8250_port.c
@@ -1991,7 +1991,7 @@ static void wait_for_xmitr(struct uart_8250_port *up, int bits)
wait_for_lsr(up, bits);
/* Wait up to 1s for flow control if necessary */
- if (uart_cons_flow_enabled(&up->port)) {
+ if (uart_console_hwflow_active(&up->port)) {
for (tmout = 1000000; tmout; tmout--) {
unsigned int msr = serial_in(up, UART_MSR);
up->msr_saved_flags |= msr & MSR_SAVE_FLAGS;
@@ -2785,6 +2785,12 @@ serial8250_do_set_termios(struct uart_port *port, struct ktermios *termios,
serial8250_set_efr(port, termios);
serial8250_set_divisor(port, baud, quot, frac);
serial8250_set_fcr(port, termios);
+ /* Consoles manually poll CTS for hardware flow control. */
+ if (uart_console(port) &&
+ !(port->rs485.flags & SER_RS485_ENABLED)
+ && termios->c_cflag & CRTSCTS) {
+ port->mctrl |= TIOCM_RTS;
+ }
serial8250_set_mctrl(port, port->mctrl);
}
@@ -3354,7 +3360,7 @@ void serial8250_console_write(struct uart_8250_port *up, const char *s,
* it regardless of the CTS state. Therefore, only use fifo
* if we don't use control flow.
*/
- !uart_cons_flow_enabled(&up->port);
+ !uart_console_hwflow_active(&up->port);
if (likely(use_fifo))
serial8250_console_fifo_write(up, s, count);
@@ -3424,6 +3430,9 @@ int serial8250_console_setup(struct uart_port *port, char *options, bool probe)
if (ret)
return ret;
+ /* Track user-specified console flow control. */
+ uart_set_cons_flow_enabled(port, flow == 'r');
+
if (port->dev)
pm_runtime_get_sync(port->dev);
diff --git a/drivers/tty/serial/serial_core.c b/drivers/tty/serial/serial_core.c
index ca72454b3eb09..96599dee967bf 100644
--- a/drivers/tty/serial/serial_core.c
+++ b/drivers/tty/serial/serial_core.c
@@ -2263,6 +2263,18 @@ uart_set_options(struct uart_port *port, struct console *co,
port->mctrl |= TIOCM_DTR;
port->ops->set_termios(port, &termios, &dummy);
+
+ /*
+ * If console hardware flow control was specified and is supported,
+ * the related policy UPSTAT_CTS_ENABLE must be set to allow console
+ * drivers to identify if CTS should be used for polling.
+ */
+ if (flow == 'r' && (termios.c_cflag & CRTSCTS)) {
+ /* Synchronize @status RMW update against the console. */
+ guard(uart_port_lock_irqsave)(port);
+ port->status |= UPSTAT_CTS_ENABLE;
+ }
+
/*
* Allow the setting of the UART parameters with a NULL console
* too:
@@ -2569,7 +2581,14 @@ uart_configure_port(struct uart_driver *drv, struct uart_state *state,
* We probably don't need a spinlock around this, but
*/
scoped_guard(uart_port_lock_irqsave, port) {
- port->mctrl &= TIOCM_DTR;
+ unsigned int mask = TIOCM_DTR;
+
+ /* Console hardware flow control polls CTS. */
+ if (uart_console_hwflow_active(port))
+ mask |= TIOCM_RTS;
+
+ port->mctrl &= mask;
+
if (!(port->rs485.flags & SER_RS485_ENABLED))
port->ops->set_mctrl(port, port->mctrl);
}
diff --git a/include/linux/serial_core.h b/include/linux/serial_core.h
index d1404c97dc524..bdc214386e4a5 100644
--- a/include/linux/serial_core.h
+++ b/include/linux/serial_core.h
@@ -1175,6 +1175,14 @@ static inline bool uart_cons_flow_enabled(const struct uart_port *uport)
return uport->cons_flow;
}
+static inline bool uart_console_hwflow_active(struct uart_port *uport)
+{
+ return uart_console(uport) &&
+ !(uport->rs485.flags & SER_RS485_ENABLED) &&
+ uart_cons_flow_enabled(uport) &&
+ uart_cts_enabled(uport);
+}
+
/*
* The following are helper functions for the low level drivers.
*/
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0312/1518] serial: 8250: Clear CON_PRINTBUFFER on port re-registration
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (310 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0311/1518] serial: 8250: Add support for console flow control Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0313/1518] serial: ma35d1: Fix OF node reference leaks in console init Greg Kroah-Hartman
` (686 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Fushuai Wang, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fushuai Wang <wangfushuai@baidu.com>
[ Upstream commit d338ab1d90603f875c4f7ed223406535378173a5 ]
When two PnP devices map to the same physical port, the serial8250 driver
removes and re-registers the console structure for the same port.
During re-registration, the console structure still has CON_PRINTBUFFER set
from the initial registration, which causes console_init_seq() to set
console->seq to syslog_seq. This results in re-printing the entire
system log buffer, which may lead to RCU stall on slow serial consoles.
Clear CON_PRINTBUFFER when re-registering a port to prevent duplicate
log printing.
Fixes: 835d844d1a28 ("8250_pnp: do pnp probe before legacy probe")
Suggested-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Fushuai Wang <wangfushuai@baidu.com>
Link: https://patch.msgid.link/20260522101042.21976-1-fushuai.wang@linux.dev
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/tty/serial/8250/8250_core.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/drivers/tty/serial/8250/8250_core.c b/drivers/tty/serial/8250/8250_core.c
index ccd5a18f53356..b6568880f750d 100644
--- a/drivers/tty/serial/8250/8250_core.c
+++ b/drivers/tty/serial/8250/8250_core.c
@@ -716,8 +716,12 @@ int serial8250_register_8250_port(const struct uart_8250_port *up)
/* Preserve specified console flow control. */
cons_flow = uart_cons_flow_enabled(&uart->port);
- if (uart->port.dev)
+ if (uart->port.dev) {
+ if (uart_console(&uart->port))
+ uart->port.cons->flags &= ~CON_PRINTBUFFER;
+
uart_remove_one_port(&serial8250_reg, &uart->port);
+ }
uart->port.ctrl_id = up->port.ctrl_id;
uart->port.port_id = up->port.port_id;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0313/1518] serial: ma35d1: Fix OF node reference leaks in console init
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (311 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0312/1518] serial: 8250: Clear CON_PRINTBUFFER on port re-registration Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0314/1518] serial: qcom-geni: do not advance stale DMA completions Greg Kroah-Hartman
` (685 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yuho Choi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuho Choi <dbgh9129@gmail.com>
[ Upstream commit 8dfea56f350b3dc826f35711802ad6ae8fae0748 ]
ma35d1serial_console_init_port() stores matching UART device nodes in
ma35d1serial_uart_nodes[] with an extra of_node_get() so that console
setup can later read the "reg" property. However, the stored references
are never released after console setup has finished using them.
Drop the stored node reference after ma35d1serial_console_setup() reads
the "reg" property, and clear the array slot to avoid leaving a stale
pointer behind. Also release the iterator reference before breaking out
of for_each_matching_node(), since the normal iterator advance will not
run in that path.
Fixes: 930cbf92db01 ("tty: serial: Add Nuvoton ma35d1 serial driver support")
Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
Link: https://patch.msgid.link/20260630214043.1887351-1-dbgh9129@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/tty/serial/ma35d1_serial.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
diff --git a/drivers/tty/serial/ma35d1_serial.c b/drivers/tty/serial/ma35d1_serial.c
index 285b0fe41a86a..920fe7ff5083b 100644
--- a/drivers/tty/serial/ma35d1_serial.c
+++ b/drivers/tty/serial/ma35d1_serial.c
@@ -608,8 +608,14 @@ static int __init ma35d1serial_console_setup(struct console *co, char *options)
if (!np || !p)
return -ENODEV;
- if (of_property_read_u32_array(np, "reg", val32, ARRAY_SIZE(val32)) != 0)
+ if (of_property_read_u32_array(np, "reg", val32, ARRAY_SIZE(val32)) != 0) {
+ of_node_put(np);
+ ma35d1serial_uart_nodes[co->index] = NULL;
return -EINVAL;
+ }
+
+ of_node_put(np);
+ ma35d1serial_uart_nodes[co->index] = NULL;
p->port.iobase = val32[1];
p->port.membase = ioremap(p->port.iobase, MA35_UART_REG_SIZE);
@@ -648,8 +654,10 @@ static void ma35d1serial_console_init_port(void)
of_node_get(np);
ma35d1serial_uart_nodes[i] = np;
i++;
- if (i == MA35_UART_NR)
+ if (i == MA35_UART_NR) {
+ of_node_put(np);
break;
+ }
}
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0314/1518] serial: qcom-geni: do not advance stale DMA completions
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (312 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0313/1518] serial: ma35d1: Fix OF node reference leaks in console init Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0315/1518] usb: gadget: f_fs: Fix fence cleanup in ffs_dmabuf_transfer() error paths Greg Kroah-Hartman
` (684 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
[ Upstream commit 7ea38c49e7178960926657863299face6dc0e1b0 ]
The qcom GENI serial DMA TX completion path advances the transmit fifo by
the number of bytes recorded in port->tx_remaining.
If uart_flush_buffer() runs after the hardware has completed a DMA
transfer but before the DMA completion interrupt has been handled, the
serial core resets the transmit fifo while port->tx_remaining still
describes the old DMA transfer.
A previous fix avoided advancing an empty fifo by checking that the fifo
length is at least tx_remaining. That still does not distinguish the old
DMA payload from new bytes written after the flush. If userspace writes
new data before the stale DMA completion interrupt is handled, the fifo
can again contain at least tx_remaining bytes and the stale completion
can advance and discard those new bytes.
Mark an in-flight DMA transfer stale when the transmit fifo is flushed.
The later completion still unprepares the original DMA mapping using the
saved length, but it no longer advances the transmit fifo.
Fixes: 2aaa43c70778 ("tty: serial: qcom-geni-serial: add support for serial engine DMA")
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Link: https://patch.msgid.link/20260708131726.768692-1-lgs201920130244@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/tty/serial/qcom_geni_serial.c | 10 +++++++++-
1 file changed, 9 insertions(+), 1 deletion(-)
diff --git a/drivers/tty/serial/qcom_geni_serial.c b/drivers/tty/serial/qcom_geni_serial.c
index 1d561a00cbbd9..953b737357103 100644
--- a/drivers/tty/serial/qcom_geni_serial.c
+++ b/drivers/tty/serial/qcom_geni_serial.c
@@ -136,6 +136,7 @@ struct qcom_geni_serial_port {
unsigned int tx_remaining;
unsigned int tx_queued;
+ bool tx_dma_stale;
int wakeup_irq;
bool rx_tx_swap;
bool cts_rts_swap;
@@ -688,6 +689,7 @@ static void qcom_geni_serial_start_tx_dma(struct uart_port *uport)
}
port->tx_remaining = xmit_size;
+ port->tx_dma_stale = false;
}
static void qcom_geni_serial_start_tx_fifo(struct uart_port *uport)
@@ -1020,6 +1022,7 @@ static void qcom_geni_serial_handle_tx_dma(struct uart_port *uport)
struct qcom_geni_serial_port *port = to_dev_port(uport);
struct tty_port *tport = &uport->state->port;
unsigned int fifo_len = kfifo_len(&tport->xmit_fifo);
+ bool tx_dma_stale = port->tx_dma_stale;
/*
* Only advance the kfifo if it still contains the bytes that were
@@ -1030,12 +1033,13 @@ static void qcom_geni_serial_handle_tx_dma(struct uart_port *uport)
* kfifo->in, making kfifo_len() wrap to UART_XMIT_SIZE - tx_remaining
* and triggering a spurious large DMA transfer of stale data.
*/
- if (fifo_len >= port->tx_remaining)
+ if (!tx_dma_stale && fifo_len >= port->tx_remaining)
uart_xmit_advance(uport, port->tx_remaining);
geni_se_tx_dma_unprep(&port->se, port->tx_dma_addr, port->tx_remaining);
port->tx_dma_addr = 0;
port->tx_remaining = 0;
+ port->tx_dma_stale = false;
if (!kfifo_is_empty(&tport->xmit_fifo))
qcom_geni_serial_start_tx_dma(uport);
@@ -1173,6 +1177,10 @@ static void qcom_geni_serial_shutdown(struct uart_port *uport)
static void qcom_geni_serial_flush_buffer_fifo(struct uart_port *uport)
{
+ struct qcom_geni_serial_port *port = to_dev_port(uport);
+
+ if (port->tx_dma_addr)
+ port->tx_dma_stale = true;
qcom_geni_serial_cancel_tx_cmd(uport);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0315/1518] usb: gadget: f_fs: Fix fence cleanup in ffs_dmabuf_transfer() error paths
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (313 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0314/1518] serial: qcom-geni: do not advance stale DMA completions Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0316/1518] usb: gadget: configfs: fix out-of-bounds read of qw_sign Greg Kroah-Hartman
` (683 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nuno Sá, Paul Cercueil,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nuno Sá <nuno.sa@analog.com>
[ Upstream commit 621707dc67c9846fd876d7579ec951d92aa033f1 ]
The error paths for endpoint-disabled (ESHUTDOWN) and request-allocation
failure (ENOMEM) in ffs_dmabuf_transfer() jump to err_fence_put which
calls dma_fence_put() on the fence. However, at that point the fence has
only been kmalloc'd — dma_fence_init() has not been called yet, so the
refcount and the fence ops are uninitialized. Calling dma_fence_put() on
such an object leads to undefined behavior.
Use kfree() instead, since the fence is just a plain allocation at this
stage, and rename the label to err_fence_free to reflect the actual
cleanup action.
Fixes: 7b07a2a7ca02 ("usb: gadget: functionfs: Add DMABUF import interface")
Signed-off-by: Nuno Sá <nuno.sa@analog.com>
Reviewed-by: Paul Cercueil <paul@crapouillou.net>
Link: https://patch.msgid.link/20260612-fix-f_fs-fence-cleanup-v1-1-79f489b0efe9@analog.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/usb/gadget/function/f_fs.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/drivers/usb/gadget/function/f_fs.c b/drivers/usb/gadget/function/f_fs.c
index 09d6872ad38b7..d73b082d5d835 100644
--- a/drivers/usb/gadget/function/f_fs.c
+++ b/drivers/usb/gadget/function/f_fs.c
@@ -1683,13 +1683,13 @@ static int ffs_dmabuf_transfer(struct file *file,
/* In the meantime, endpoint got disabled or changed. */
if (epfile->ep != ep) {
ret = -ESHUTDOWN;
- goto err_fence_put;
+ goto err_fence_free;
}
usb_req = usb_ep_alloc_request(ep->ep, GFP_ATOMIC);
if (!usb_req) {
ret = -ENOMEM;
- goto err_fence_put;
+ goto err_fence_free;
}
/*
@@ -1738,9 +1738,9 @@ static int ffs_dmabuf_transfer(struct file *file,
return ret;
-err_fence_put:
+err_fence_free:
spin_unlock_irq(&epfile->ffs->eps_lock);
- dma_fence_put(&fence->base);
+ kfree(fence);
err_resv_unlock:
dma_resv_unlock(dmabuf->resv);
err_attachment_put:
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0316/1518] usb: gadget: configfs: fix out-of-bounds read of qw_sign
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (314 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0315/1518] usb: gadget: f_fs: Fix fence cleanup in ffs_dmabuf_transfer() error paths Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0317/1518] usb: ljca: bound bank_num in ljca_enumerate_gpio() Greg Kroah-Hartman
` (682 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Michael Bommarito, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michael Bommarito <michael.bommarito@gmail.com>
[ Upstream commit f63edb54d8f738f9c21e2068c777ae1c097df6b7 ]
os_desc_qw_sign_show() passes OS_STRING_QW_SIGN_LEN as the input
length to utf16s_to_utf8s(), but that argument counts UTF-16 code
units while OS_STRING_QW_SIGN_LEN (14) is the byte size of qw_sign[].
The array holds only OS_STRING_QW_SIGN_LEN / 2 (7) code units, so the
conversion reads up to 7 units (14 bytes) past the end of qw_sign[]
into the following members of struct gadget_info when the stored
signature fills the array without a NUL terminator, exposing those
bytes through the configfs attribute.
The store path halves the count for its input bound but passes the
full byte count as the utf8s_to_utf16s() output limit; use the
destination code-unit count in both directions.
Fixes: 76180d716f91 ("usb: gadget: configfs: make qw_sign attribute symmetric")
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Link: https://patch.msgid.link/20260618005043.1581707-1-michael.bommarito@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/usb/gadget/configfs.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/usb/gadget/configfs.c b/drivers/usb/gadget/configfs.c
index 6bcac85c55501..aa0a25efb6aa0 100644
--- a/drivers/usb/gadget/configfs.c
+++ b/drivers/usb/gadget/configfs.c
@@ -1177,7 +1177,7 @@ static ssize_t os_desc_qw_sign_show(struct config_item *item, char *page)
struct gadget_info *gi = os_desc_item_to_gadget_info(item);
int res;
- res = utf16s_to_utf8s((wchar_t *) gi->qw_sign, OS_STRING_QW_SIGN_LEN,
+ res = utf16s_to_utf8s((wchar_t *) gi->qw_sign, OS_STRING_QW_SIGN_LEN / 2,
UTF16_LITTLE_ENDIAN, page, PAGE_SIZE - 1);
page[res++] = '\n';
@@ -1199,7 +1199,7 @@ static ssize_t os_desc_qw_sign_store(struct config_item *item, const char *page,
mutex_lock(&gi->lock);
res = utf8s_to_utf16s(page, l,
UTF16_LITTLE_ENDIAN, (wchar_t *) gi->qw_sign,
- OS_STRING_QW_SIGN_LEN);
+ OS_STRING_QW_SIGN_LEN / 2);
if (res > 0)
res = len;
mutex_unlock(&gi->lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0317/1518] usb: ljca: bound bank_num in ljca_enumerate_gpio()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (315 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0316/1518] usb: gadget: configfs: fix out-of-bounds read of qw_sign Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0318/1518] usb: gadget: aspeed_udc: check endpoint DMA allocation Greg Kroah-Hartman
` (681 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Maoyi Xie, Sakari Ailus, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maoyi Xie <maoyixie.tju@gmail.com>
[ Upstream commit dd9483726d0f16c1a56879c3edb65128259a4e2b ]
ljca_enumerate_gpio() reads desc->bank_num from the device and loops
valid_pin[i] = get_unaligned_le32(...) for i < bank_num. valid_pin[]
holds only LJCA_MAX_GPIO_NUM / 32 = 2 entries.
Two checks run before the loop. The reply length must match
struct_size(desc, bank_desc, bank_num). The product
pins_per_bank * bank_num must not exceed LJCA_MAX_GPIO_NUM. Neither one
bounds bank_num against the size of valid_pin[]. The reply is capped at
LJCA_MAX_PAYLOAD_SIZE (60) bytes, so the struct_size check limits
bank_num to 9. A device that reports bank_num 9 with pins_per_bank 7
still passes both checks. gpio_num is 63 and the reply is 56 bytes. The
loop then writes nine u32 into the two entry array and overruns
valid_pin[] on the stack.
A broken or malicious LJCA device can therefore overflow the stack.
Reject a bank_num that does not fit valid_pin[].
Fixes: acd6199f195d ("usb: Add support for Intel LJCA device")
Signed-off-by: Maoyi Xie <maoyixie.tju@gmail.com>
Acked-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Link: https://patch.msgid.link/178176358875.3352358.6059116660356914900@maoyixie.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/usb/misc/usb-ljca.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/usb/misc/usb-ljca.c b/drivers/usb/misc/usb-ljca.c
index c562630d862c7..b19cc99edfeb6 100644
--- a/drivers/usb/misc/usb-ljca.c
+++ b/drivers/usb/misc/usb-ljca.c
@@ -585,6 +585,9 @@ static int ljca_enumerate_gpio(struct ljca_adapter *adap)
if (gpio_num > LJCA_MAX_GPIO_NUM)
return -EINVAL;
+ if (desc->bank_num > ARRAY_SIZE(valid_pin))
+ return -EINVAL;
+
/* construct platform data */
gpio_info = kzalloc(sizeof *gpio_info, GFP_KERNEL);
if (!gpio_info)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0318/1518] usb: gadget: aspeed_udc: check endpoint DMA allocation
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (316 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0317/1518] usb: ljca: bound bank_num in ljca_enumerate_gpio() Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0319/1518] usb: fix UAF when probe runs concurrent to dyn ID removal Greg Kroah-Hartman
` (680 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ruoyu Wang, Andrew Jeffery,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ruoyu Wang <ruoyuw560@gmail.com>
[ Upstream commit 97cee53a94be3bd4fd8fbed6071bd2f32dad1ab1 ]
ast_udc_probe() allocates a coherent DMA buffer used as the backing store
for endpoint buffers. ast_udc_init_ep() derives per-endpoint buffer
pointers from udc->ep0_buf, so a failed allocation is dereferenced during
probe.
Check the allocation before endpoint setup. The existing probe error path
called ast_udc_remove(), which unregisters the gadget unconditionally and
is not safe before usb_add_gadget_udc() succeeds. Add a local cleanup
helper for probe failures so pre-registration failures only unwind the
resources that were actually initialized.
This was found by a local static analysis checker for unchecked allocator
returns while scanning Linux 6.16. The change was checked by applying it
to current mainline and by running checkpatch. I do not have access to
Aspeed UDC hardware, so no runtime testing was performed.
Fixes: 055276c13205 ("usb: gadget: add Aspeed ast2600 udc driver")
Signed-off-by: Ruoyu Wang <ruoyuw560@gmail.com>
Reviewed-by: Andrew Jeffery <andrew@codeconstruct.com.au>
Link: https://patch.msgid.link/20260610121022.3-1-ruoyuw560@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/usb/gadget/udc/aspeed_udc.c | 50 ++++++++++++++++++-----------
1 file changed, 32 insertions(+), 18 deletions(-)
diff --git a/drivers/usb/gadget/udc/aspeed_udc.c b/drivers/usb/gadget/udc/aspeed_udc.c
index 353bfb1ff0a12..1757570f7b3a3 100644
--- a/drivers/usb/gadget/udc/aspeed_udc.c
+++ b/drivers/usb/gadget/udc/aspeed_udc.c
@@ -1434,25 +1434,12 @@ static void ast_udc_init_hw(struct ast_udc_dev *udc)
ast_udc_write(udc, 0, AST_UDC_EP0_CTRL);
}
-static void ast_udc_remove(struct platform_device *pdev)
+static void ast_udc_cleanup(struct platform_device *pdev)
{
struct ast_udc_dev *udc = platform_get_drvdata(pdev);
unsigned long flags;
u32 ctrl;
- usb_del_gadget_udc(&udc->gadget);
- if (udc->driver) {
- /*
- * This is broken as only some cleanup is skipped, *udev is
- * freed and the register mapping goes away. Any further usage
- * probably crashes. Also the device is unbound, so the skipped
- * cleanup is never catched up later.
- */
- dev_alert(&pdev->dev,
- "Driver is busy and still going away. Fasten your seat belts!\n");
- return;
- }
-
spin_lock_irqsave(&udc->lock, flags);
/* Disable upstream port connection */
@@ -1472,6 +1459,26 @@ static void ast_udc_remove(struct platform_device *pdev)
udc->ep0_buf = NULL;
}
+static void ast_udc_remove(struct platform_device *pdev)
+{
+ struct ast_udc_dev *udc = platform_get_drvdata(pdev);
+
+ usb_del_gadget_udc(&udc->gadget);
+ if (udc->driver) {
+ /*
+ * This is broken as only some cleanup is skipped, *udev is
+ * freed and the register mapping goes away. Any further usage
+ * probably crashes. Also the device is unbound, so the skipped
+ * cleanup is never catched up later.
+ */
+ dev_alert(&pdev->dev,
+ "Driver is busy and still going away. Fasten your seat belts!\n");
+ return;
+ }
+
+ ast_udc_cleanup(pdev);
+}
+
static int ast_udc_probe(struct platform_device *pdev)
{
enum usb_device_speed max_speed;
@@ -1524,6 +1531,12 @@ static int ast_udc_probe(struct platform_device *pdev)
AST_UDC_NUM_ENDPOINTS,
&udc->ep0_buf_dma, GFP_KERNEL);
+ if (!udc->ep0_buf) {
+ clk_disable_unprepare(udc->clk);
+ rc = -ENOMEM;
+ goto err;
+ }
+
udc->gadget.speed = USB_SPEED_UNKNOWN;
udc->gadget.max_speed = USB_SPEED_HIGH;
udc->creq = udc->reg + AST_UDC_SETUP0;
@@ -1553,20 +1566,20 @@ static int ast_udc_probe(struct platform_device *pdev)
udc->irq = platform_get_irq(pdev, 0);
if (udc->irq < 0) {
rc = udc->irq;
- goto err;
+ goto err_cleanup;
}
rc = devm_request_irq(&pdev->dev, udc->irq, ast_udc_isr, 0,
KBUILD_MODNAME, udc);
if (rc) {
dev_err(&pdev->dev, "Failed to request interrupt\n");
- goto err;
+ goto err_cleanup;
}
rc = usb_add_gadget_udc(&pdev->dev, &udc->gadget);
if (rc) {
dev_err(&pdev->dev, "Failed to add gadget udc\n");
- goto err;
+ goto err_cleanup;
}
dev_info(&pdev->dev, "Initialized udc in USB%s mode\n",
@@ -1574,9 +1587,10 @@ static int ast_udc_probe(struct platform_device *pdev)
return 0;
+err_cleanup:
+ ast_udc_cleanup(pdev);
err:
dev_err(&pdev->dev, "Failed to udc probe, rc:0x%x\n", rc);
- ast_udc_remove(pdev);
return rc;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0319/1518] usb: fix UAF when probe runs concurrent to dyn ID removal
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (317 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0318/1518] usb: gadget: aspeed_udc: check endpoint DMA allocation Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0320/1518] platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL Greg Kroah-Hartman
` (679 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Gary Guo, Danilo Krummrich,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gary Guo <gary@garyguo.net>
[ Upstream commit ef8154d8b52d60338c1fd8d793cd8e891c604c14 ]
Dynamic IDs are only guaranteed to be valid when usb_dynids_lock is held,
as remove_id_store can free the node. Thus, make a copy in
usb_probe_interface. Clarify the documentation that the id parameter is
only valid during the probe.
USB serial has the same pattern, but it does not need fixing as the IDs
cannot be removed via sysfs.
Fixes: 0c7a2b72746a ("USB: add remove_id sysfs attr for usb drivers")
Signed-off-by: Gary Guo <gary@garyguo.net>
Reviewed-by: Danilo Krummrich <dakr@kernel.org>
Link: https://patch.msgid.link/20260707-usb_dyn_id_uaf-v2-7-632dcf3adfba@garyguo.net
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/usb/core/driver.c | 12 ++++++++----
include/linux/usb.h | 3 ++-
2 files changed, 10 insertions(+), 5 deletions(-)
diff --git a/drivers/usb/core/driver.c b/drivers/usb/core/driver.c
index 74b8bdc27dbf5..acd05f87b8e14 100644
--- a/drivers/usb/core/driver.c
+++ b/drivers/usb/core/driver.c
@@ -228,14 +228,16 @@ static void usb_free_dynids(struct usb_driver *usb_drv)
}
static const struct usb_device_id *usb_match_dynamic_id(struct usb_interface *intf,
- const struct usb_driver *drv)
+ const struct usb_driver *drv,
+ struct usb_device_id *id_copy)
{
struct usb_dynid *dynid;
guard(mutex)(&usb_dynids_lock);
list_for_each_entry(dynid, &drv->dynids.list, node) {
if (usb_match_one_id(intf, &dynid->id)) {
- return &dynid->id;
+ *id_copy = dynid->id;
+ return id_copy;
}
}
return NULL;
@@ -321,6 +323,7 @@ static int usb_probe_interface(struct device *dev)
struct usb_interface *intf = to_usb_interface(dev);
struct usb_device *udev = interface_to_usbdev(intf);
const struct usb_device_id *id;
+ struct usb_device_id id_copy;
int error = -ENODEV;
int lpm_disable_error = -ENODEV;
@@ -340,7 +343,7 @@ static int usb_probe_interface(struct device *dev)
return error;
}
- id = usb_match_dynamic_id(intf, driver);
+ id = usb_match_dynamic_id(intf, driver, &id_copy);
if (!id)
id = usb_match_id(intf, driver->id_table);
if (!id)
@@ -892,6 +895,7 @@ static int usb_device_match(struct device *dev, const struct device_driver *drv)
struct usb_interface *intf;
const struct usb_driver *usb_drv;
const struct usb_device_id *id;
+ struct usb_device_id id_copy;
/* device drivers never match interfaces */
if (is_usb_device_driver(drv))
@@ -904,7 +908,7 @@ static int usb_device_match(struct device *dev, const struct device_driver *drv)
if (id)
return 1;
- id = usb_match_dynamic_id(intf, usb_drv);
+ id = usb_match_dynamic_id(intf, usb_drv, &id_copy);
if (id)
return 1;
}
diff --git a/include/linux/usb.h b/include/linux/usb.h
index 375ee6e202dbe..f2adf76340953 100644
--- a/include/linux/usb.h
+++ b/include/linux/usb.h
@@ -1185,7 +1185,8 @@ extern ssize_t usb_show_dynids(struct usb_dynids *dynids, char *buf);
* interface. It may also use usb_set_interface() to specify the
* appropriate altsetting. If unwilling to manage the interface,
* return -ENODEV, if genuine IO errors occurred, an appropriate
- * negative errno value.
+ * negative errno value. The usb_device_id parameter is only valid during
+ * probe.
* @disconnect: Called when the interface is no longer accessible, usually
* because its device has been (or is being) disconnected or the
* driver module is being unloaded.
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0320/1518] platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (318 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0319/1518] usb: fix UAF when probe runs concurrent to dyn ID removal Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0321/1518] platform/surface: acpi-notify: Check ACPI companion before use Greg Kroah-Hartman
` (678 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Linmao Li, Ilpo Järvinen,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linmao Li <lilinmao@kylinos.cn>
[ Upstream commit c38cce70adef874c2a7b5132c14d6c221401deff ]
Every platform driver can be forced to match a device that doesn't match
its list of device IDs because of device_match_driver_override(), so
platform drivers that rely on the existence of a device's ACPI companion
object need to verify its presence.
mlxbf_pmc_probe() passes the result of ACPI_COMPANION() to
acpi_device_hid(), which dereferences it, so force-binding the driver to
a device without an ACPI companion leads to a NULL pointer dereference.
Accordingly, add a requisite ACPI_COMPANION() check against NULL to the
mlxbf-pmc driver and return -ENODEV when the companion is missing.
Fixes: 1a218d312e65 ("platform/mellanox: mlxbf-pmc: Add Mellanox BlueField PMC driver")
Signed-off-by: Linmao Li <lilinmao@kylinos.cn>
Link: https://patch.msgid.link/20260706012056.524096-1-lilinmao@kylinos.cn
Reviewed-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/platform/mellanox/mlxbf-pmc.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/drivers/platform/mellanox/mlxbf-pmc.c b/drivers/platform/mellanox/mlxbf-pmc.c
index 5ec1ad4716967..2ad9e2b0493c4 100644
--- a/drivers/platform/mellanox/mlxbf-pmc.c
+++ b/drivers/platform/mellanox/mlxbf-pmc.c
@@ -2262,13 +2262,19 @@ static int mlxbf_pmc_map_counters(struct device *dev)
static int mlxbf_pmc_probe(struct platform_device *pdev)
{
- struct acpi_device *acpi_dev = ACPI_COMPANION(&pdev->dev);
- const char *hid = acpi_device_hid(acpi_dev);
struct device *dev = &pdev->dev;
+ struct acpi_device *acpi_dev;
struct arm_smccc_res res;
+ const char *hid;
guid_t guid;
int ret;
+ acpi_dev = ACPI_COMPANION(&pdev->dev);
+ if (!acpi_dev)
+ return -ENODEV;
+
+ hid = acpi_device_hid(acpi_dev);
+
/* Ensure we have the UUID we expect for this service. */
arm_smccc_smc(MLXBF_PMC_SIP_SVC_UID, 0, 0, 0, 0, 0, 0, 0, &res);
guid_parse(mlxbf_pmc_svc_uuid_str, &guid);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0321/1518] platform/surface: acpi-notify: Check ACPI companion before use
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (319 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0320/1518] platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0322/1518] usb: mtu3: allow system suspend during active gadget connection Greg Kroah-Hartman
` (677 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Linmao Li, Ilpo Järvinen,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linmao Li <lilinmao@kylinos.cn>
[ Upstream commit 2b3a5dabe89e330413af403246b648c1890f368f ]
Since every platform driver can be forced to match a device that doesn't
match its list of device IDs because of device_match_driver_override(),
platform drivers that rely on the existence of a device's ACPI companion
object should verify its presence.
san_probe() dereferences the result of ACPI_COMPANION() when installing
the GSBUS address space handler, so force-binding the driver to a device
without an ACPI companion leads to a NULL pointer dereference. The
dereference was introduced when the probe function was switched from
ACPI_HANDLE() to ACPI_COMPANION().
Check the ACPI companion against NULL and return -ENODEV when it is
missing, like commit e4865a56d013 ("ACPI: driver: Check ACPI_COMPANION()
against NULL during probe") does for the core ACPI platform drivers.
Fixes: a9e10e587304 ("ACPI: scan: Extend acpi_walk_dep_device_list()")
Signed-off-by: Linmao Li <lilinmao@kylinos.cn>
Link: https://patch.msgid.link/20260706012512.524359-2-lilinmao@kylinos.cn
Reviewed-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/platform/surface/surface_acpi_notify.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/drivers/platform/surface/surface_acpi_notify.c b/drivers/platform/surface/surface_acpi_notify.c
index 3b30cfe3466b8..3bad4e689f5ce 100644
--- a/drivers/platform/surface/surface_acpi_notify.c
+++ b/drivers/platform/surface/surface_acpi_notify.c
@@ -777,12 +777,16 @@ static int san_consumer_links_setup(struct platform_device *pdev)
static int san_probe(struct platform_device *pdev)
{
- struct acpi_device *san = ACPI_COMPANION(&pdev->dev);
struct ssam_controller *ctrl;
+ struct acpi_device *san;
struct san_data *data;
acpi_status astatus;
int status;
+ san = ACPI_COMPANION(&pdev->dev);
+ if (!san)
+ return -ENODEV;
+
ctrl = ssam_client_bind(&pdev->dev);
if (IS_ERR(ctrl))
return PTR_ERR(ctrl) == -ENODEV ? -EPROBE_DEFER : PTR_ERR(ctrl);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0322/1518] usb: mtu3: allow system suspend during active gadget connection
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (320 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0321/1518] platform/surface: acpi-notify: Check ACPI companion before use Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0323/1518] usb: renesas_usbhs: Fix power-off ordering on unbind Greg Kroah-Hartman
` (676 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Fei Shao, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fei Shao <fshao@chromium.org>
[ Upstream commit e69027c25361b6044c7928715667586cc5469063 ]
When operating in gadget mode connected to a USB host, system suspend
fails with -EBUSY because active peripheral connections block suspend
entry.
Fix this by restricting the -EBUSY check to runtime autosuspend
(PMSG_IS_AUTO). For system suspend (!PMSG_IS_AUTO), perform soft
disconnect to disconnect from the bus and allow MAC sleep.
Fixes: 427c66422e14 ("usb: mtu3: support suspend/resume for device mode")
Signed-off-by: Fei Shao <fshao@chromium.org>
Link: https://patch.msgid.link/20260626082218.2750459-2-fshao@chromium.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/usb/mtu3/mtu3_core.c | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
diff --git a/drivers/usb/mtu3/mtu3_core.c b/drivers/usb/mtu3/mtu3_core.c
index a3a6282893d09..ca8cb6c3a01bf 100644
--- a/drivers/usb/mtu3/mtu3_core.c
+++ b/drivers/usb/mtu3/mtu3_core.c
@@ -1037,9 +1037,14 @@ int ssusb_gadget_suspend(struct ssusb_mtk *ssusb, pm_message_t msg)
if (!mtu->gadget_driver)
return 0;
- if (mtu->connected)
+ /* Prevent runtime suspend when active connection exists */
+ if (mtu->connected && PMSG_IS_AUTO(msg))
return -EBUSY;
+ /* Perform soft disconnect for system suspend */
+ if (mtu->softconnect && !PMSG_IS_AUTO(msg))
+ mtu3_dev_on_off(mtu, 0);
+
mtu3_dev_suspend(mtu);
synchronize_irq(mtu->irq);
@@ -1055,5 +1060,9 @@ int ssusb_gadget_resume(struct ssusb_mtk *ssusb, pm_message_t msg)
mtu3_dev_resume(mtu);
+ /* Restore soft connect for system resume */
+ if (mtu->softconnect && !PMSG_IS_AUTO(msg))
+ mtu3_dev_on_off(mtu, 1);
+
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0323/1518] usb: renesas_usbhs: Fix power-off ordering on unbind
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (321 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0322/1518] usb: mtu3: allow system suspend during active gadget connection Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0324/1518] usb: ucsi: huawei_gaokun: support mode switching Greg Kroah-Hartman
` (675 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Biju Das, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Biju Das <biju.das.jz@bp.renesas.com>
[ Upstream commit 589b9e6f96be6bd8dd0d45fda8e948c31dc2fe94 ]
Move the usbhsc_power_ctrl() call to before hardware_exit() and
reset_control_assert() in usbhs_remove(), so the PHY is powered off
while priv->phy is still valid, rather than after hardware_exit()
has already cleared it.
Fixes: eb9ac779830b ("usb: renesas_usbhs: Fix synchronous external abort on unbind")
Signed-off-by: Biju Das <biju.das.jz@bp.renesas.com>
Link: https://patch.msgid.link/20260702073832.175047-1-biju.das.jz@bp.renesas.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/usb/renesas_usbhs/common.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/usb/renesas_usbhs/common.c b/drivers/usb/renesas_usbhs/common.c
index 8a79548e1569b..fddb57b8d8472 100644
--- a/drivers/usb/renesas_usbhs/common.c
+++ b/drivers/usb/renesas_usbhs/common.c
@@ -813,9 +813,6 @@ static void usbhs_remove(struct platform_device *pdev)
flush_delayed_work(&priv->notify_hotplug_work);
- usbhs_platform_call(priv, hardware_exit, pdev);
- reset_control_assert(priv->rsts);
-
/*
* Explicitly free the IRQ to ensure the interrupt handler is
* disabled and synchronized before freeing resources.
@@ -832,6 +829,9 @@ static void usbhs_remove(struct platform_device *pdev)
if (!usbhs_get_dparam(priv, runtime_pwctrl))
usbhsc_power_ctrl(priv, 0);
+ usbhs_platform_call(priv, hardware_exit, pdev);
+ reset_control_assert(priv->rsts);
+
usbhsc_clk_put(priv);
pm_runtime_disable(&pdev->dev);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0324/1518] usb: ucsi: huawei_gaokun: support mode switching
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (322 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0323/1518] usb: renesas_usbhs: Fix power-off ordering on unbind Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0325/1518] usb: typec: ucsi: gaokun: unwind notifier on UCSI register failure Greg Kroah-Hartman
` (674 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pengyu Luo, Heikki Krogerus,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengyu Luo <mitltlatltl@gmail.com>
[ Upstream commit 1c2b66a7d7257d2652aa41f9a860ecb96dde27dd ]
The USB PHY (QMP Combo PHY) is always initialized in USB3+DP mode. In
the past, there was no MUX, and it was unnecessary to set it, since
MSM only supported 2-lane DP. But now, MST and 4-lane DP support has
been added to MSM, and a MUX has been added to the PHY. To support
4-lane DP and mode switching for gaokun, get the MUX and set it.
Signed-off-by: Pengyu Luo <mitltlatltl@gmail.com>
Acked-by: Heikki Krogerus <heikki.krogerus@linux.intel.com>
Link: https://patch.msgid.link/20260607101844.820064-1-mitltlatltl@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Stable-dep-of: 2c5659a7064e ("usb: typec: ucsi: gaokun: unwind notifier on UCSI register failure")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/usb/typec/ucsi/ucsi_huawei_gaokun.c | 55 +++++++++++++++------
1 file changed, 41 insertions(+), 14 deletions(-)
diff --git a/drivers/usb/typec/ucsi/ucsi_huawei_gaokun.c b/drivers/usb/typec/ucsi/ucsi_huawei_gaokun.c
index c5965656babad..95b7b77b726d7 100644
--- a/drivers/usb/typec/ucsi/ucsi_huawei_gaokun.c
+++ b/drivers/usb/typec/ucsi/ucsi_huawei_gaokun.c
@@ -18,6 +18,7 @@
#include <linux/usb/pd_vdo.h>
#include <linux/usb/typec_altmode.h>
#include <linux/usb/typec_dp.h>
+#include <linux/usb/typec_mux.h>
#include <linux/workqueue_types.h>
#include "ucsi.h"
@@ -82,6 +83,8 @@ struct gaokun_ucsi_port {
struct gaokun_ucsi *ucsi;
struct auxiliary_device *bridge;
+ struct typec_mux *typec_mux;
+
int idx;
enum gaokun_ucsi_ccx ccx;
enum gaokun_ucsi_mux mux;
@@ -226,19 +229,18 @@ static void gaokun_ucsi_port_update(struct gaokun_ucsi_port *port,
port->hpd_state = FIELD_GET(GAOKUN_HPD_STATE_MASK, ddi);
port->hpd_irq = FIELD_GET(GAOKUN_HPD_IRQ_MASK, ddi);
- /* Mode and SVID are unused; keeping them to make things clearer */
switch (port->mode) {
case USBC_DPAM_PAN_C:
case USBC_DPAM_PAN_C_REVERSE:
- port->mode = DP_PIN_ASSIGN_C; /* correct it for usb later */
+ port->mode = TYPEC_DP_STATE_C; /* correct it for usb later */
break;
case USBC_DPAM_PAN_D:
case USBC_DPAM_PAN_D_REVERSE:
- port->mode = DP_PIN_ASSIGN_D;
+ port->mode = TYPEC_DP_STATE_D;
break;
case USBC_DPAM_PAN_E:
case USBC_DPAM_PAN_E_REVERSE:
- port->mode = DP_PIN_ASSIGN_E;
+ port->mode = TYPEC_DP_STATE_E;
break;
case USBC_DPAM_PAN_NONE:
port->mode = TYPEC_STATE_SAFE;
@@ -287,18 +289,32 @@ static int gaokun_ucsi_refresh(struct gaokun_ucsi *uec)
return idx;
}
-static void gaokun_ucsi_handle_altmode(struct gaokun_ucsi_port *port)
+static void gaokun_ucsi_handle_usb_mode(struct gaokun_ucsi_port *port)
{
struct gaokun_ucsi *uec = port->ucsi;
- int idx = port->idx;
-
- if (idx >= uec->ucsi->cap.num_connectors) {
+ struct typec_mux_state state = {};
+ struct typec_altmode dp_alt = {};
+ int idx = port->idx, ret;
+
+ /*
+ * For every typec port on this platform, the only mode-switch is
+ * controlled by its qmp combo phy which consumes svid and mode only.
+ */
+ dp_alt.svid = port->svid;
+ state.mode = port->mode;
+ state.alt = &dp_alt;
+
+ if (idx >= uec->num_ports) {
dev_warn(uec->dev, "altmode port out of range: %d\n", idx);
return;
}
+ ret = typec_mux_set(port->typec_mux, &state);
+ if (ret)
+ dev_err(uec->dev, "failed to set mux %d\n", ret);
+
/* UCSI callback .connector_status() have set orientation */
- if (port->bridge)
+ if (port->bridge && port->svid == USB_TYPEC_DP_SID)
drm_aux_hpd_bridge_notify(&port->bridge->dev,
port->hpd_state ?
connector_status_connected :
@@ -307,7 +323,7 @@ static void gaokun_ucsi_handle_altmode(struct gaokun_ucsi_port *port)
gaokun_ec_ucsi_pan_ack(uec->ec, port->idx);
}
-static void gaokun_ucsi_altmode_notify_ind(struct gaokun_ucsi *uec)
+static void gaokun_ucsi_usb_notify_ind(struct gaokun_ucsi *uec)
{
int idx;
@@ -320,7 +336,7 @@ static void gaokun_ucsi_altmode_notify_ind(struct gaokun_ucsi *uec)
if (idx == GAOKUN_UCSI_NO_PORT_UPDATE)
gaokun_ec_ucsi_pan_ack(uec->ec, idx); /* ack directly if no update */
else
- gaokun_ucsi_handle_altmode(&uec->ports[idx]);
+ gaokun_ucsi_handle_usb_mode(&uec->ports[idx]);
}
/*
@@ -352,7 +368,7 @@ static void gaokun_ucsi_handle_no_usb_event(struct gaokun_ucsi *uec, int idx)
port = &uec->ports[idx];
if (!wait_for_completion_timeout(&port->usb_ack, 2 * HZ)) {
dev_warn(uec->dev, "No USB EVENT, triggered by UCSI EVENT");
- gaokun_ucsi_altmode_notify_ind(uec);
+ gaokun_ucsi_usb_notify_ind(uec);
}
}
@@ -366,7 +382,7 @@ static int gaokun_ucsi_notify(struct notifier_block *nb,
switch (action) {
case EC_EVENT_USB:
gaokun_ucsi_complete_usb_ack(uec);
- gaokun_ucsi_altmode_notify_ind(uec);
+ gaokun_ucsi_usb_notify_ind(uec);
return NOTIFY_OK;
case EC_EVENT_UCSI:
@@ -429,8 +445,15 @@ static int gaokun_ucsi_ports_init(struct gaokun_ucsi *uec)
fwnode_handle_put(fwnode);
return PTR_ERR(ucsi_port->bridge);
}
- }
+ ucsi_port->typec_mux = fwnode_typec_mux_get(fwnode);
+ if (IS_ERR(ucsi_port->typec_mux)) {
+ fwnode_handle_put(fwnode);
+ return dev_err_probe(dev, PTR_ERR(ucsi_port->typec_mux),
+ "failed to acquire mode-switch for port: %d\n",
+ port);
+ }
+ }
for (i = 0; i < num_ports; i++) {
if (!uec->ports[i].bridge)
continue;
@@ -502,10 +525,14 @@ static int gaokun_ucsi_probe(struct auxiliary_device *adev,
static void gaokun_ucsi_remove(struct auxiliary_device *adev)
{
struct gaokun_ucsi *uec = auxiliary_get_drvdata(adev);
+ int i;
disable_delayed_work_sync(&uec->work);
gaokun_ec_unregister_notify(uec->ec, &uec->nb);
ucsi_unregister(uec->ucsi);
+ for (i = 0; i < uec->num_ports; ++i)
+ typec_mux_put(uec->ports[i].typec_mux);
+
ucsi_destroy(uec->ucsi);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0325/1518] usb: typec: ucsi: gaokun: unwind notifier on UCSI register failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (323 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0324/1518] usb: ucsi: huawei_gaokun: support mode switching Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0326/1518] drm/panel: samsung-s6d16d0: Power off on prepare failure Greg Kroah-Hartman
` (673 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Heikki Krogerus, Pengyu Luo,
Pengpeng Hou, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit 2c5659a7064e7c4c0c51eb9356bcf6726a85773b ]
gaokun_ucsi_register_worker() registers the EC notifier before calling
ucsi_register(). If ucsi_register() fails, the worker currently only logs
the error and leaves the notifier registered. Later EC events can then
call into an unpublished UCSI instance.
The remove path also unconditionally unregisters both the EC notifier and
the UCSI device even if the delayed worker failed before both publication
steps completed.
Unregister the notifier immediately when ucsi_register() fails, and track
only the fully published state. The remove path then tears down the pair
only if both publication steps completed.
Fixes: 00327d7f2c8c ("usb: typec: ucsi: add Huawei Matebook E Go ucsi driver")
Reviewed-by: Heikki Krogerus <heikki.krogerus@linux.intel.com>
Reviewed-by: Pengyu Luo <mitltlatltl@gmail.com>
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260709123239.62930-1-pengpeng@iscas.ac.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/usb/typec/ucsi/ucsi_huawei_gaokun.c | 15 ++++++++++++---
1 file changed, 12 insertions(+), 3 deletions(-)
diff --git a/drivers/usb/typec/ucsi/ucsi_huawei_gaokun.c b/drivers/usb/typec/ucsi/ucsi_huawei_gaokun.c
index 95b7b77b726d7..b40718f402370 100644
--- a/drivers/usb/typec/ucsi/ucsi_huawei_gaokun.c
+++ b/drivers/usb/typec/ucsi/ucsi_huawei_gaokun.c
@@ -103,6 +103,7 @@ struct gaokun_ucsi {
struct notifier_block nb;
u16 version;
u8 num_ports;
+ bool registered;
};
/* -------------------------------------------------------------------------- */
@@ -482,8 +483,13 @@ static void gaokun_ucsi_register_worker(struct work_struct *work)
}
ret = ucsi_register(ucsi);
- if (ret)
+ if (ret) {
dev_err_probe(ucsi->dev, ret, "ucsi register failed\n");
+ gaokun_ec_unregister_notify(uec->ec, &uec->nb);
+ return;
+ }
+
+ uec->registered = true;
}
static int gaokun_ucsi_probe(struct auxiliary_device *adev,
@@ -528,8 +534,11 @@ static void gaokun_ucsi_remove(struct auxiliary_device *adev)
int i;
disable_delayed_work_sync(&uec->work);
- gaokun_ec_unregister_notify(uec->ec, &uec->nb);
- ucsi_unregister(uec->ucsi);
+ if (uec->registered) {
+ gaokun_ec_unregister_notify(uec->ec, &uec->nb);
+ ucsi_unregister(uec->ucsi);
+ }
+
for (i = 0; i < uec->num_ports; ++i)
typec_mux_put(uec->ports[i].typec_mux);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0326/1518] drm/panel: samsung-s6d16d0: Power off on prepare failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (324 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0325/1518] usb: typec: ucsi: gaokun: unwind notifier on UCSI register failure Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0327/1518] perf metricgroup: Fix metric expression copy leaks Greg Kroah-Hartman
` (672 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Laxman Acharya Padhya, Linus Walleij,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
[ Upstream commit a9f950adfe2147318d75e7a6eab5e814851802ac ]
If enabling tearing mode or exiting sleep mode fails after the
regulator is enabled, s6d16d0_prepare() returns without asserting
reset or disabling the supply. Since the DRM panel core leaves the
panel unprepared, a later unprepare call skips the driver callback
and the supply remains enabled.
Assert reset and disable the supply before returning the DSI command error.
Fixes: ac1d6d74884e ("drm/panel: Add driver for Samsung S6D16D0 panel")
Assisted-by: Codex:gpt-5
Signed-off-by: Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260704070648.35249-1-acharyalaxman8848@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/panel/panel-samsung-s6d16d0.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/drivers/gpu/drm/panel/panel-samsung-s6d16d0.c b/drivers/gpu/drm/panel/panel-samsung-s6d16d0.c
index ba1a02000bb9d..04e19b5f22f8b 100644
--- a/drivers/gpu/drm/panel/panel-samsung-s6d16d0.c
+++ b/drivers/gpu/drm/panel/panel-samsung-s6d16d0.c
@@ -89,16 +89,22 @@ static int s6d16d0_prepare(struct drm_panel *panel)
MIPI_DSI_DCS_TEAR_MODE_VBLANK);
if (ret) {
dev_err(s6->dev, "failed to enable vblank TE (%d)\n", ret);
- return ret;
+ goto err_power_off;
}
/* Exit sleep mode and power on */
ret = mipi_dsi_dcs_exit_sleep_mode(dsi);
if (ret) {
dev_err(s6->dev, "failed to exit sleep mode (%d)\n", ret);
- return ret;
+ goto err_power_off;
}
return 0;
+
+err_power_off:
+ gpiod_set_value_cansleep(s6->reset_gpio, 1);
+ regulator_disable(s6->supply);
+
+ return ret;
}
static int s6d16d0_enable(struct drm_panel *panel)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0327/1518] perf metricgroup: Fix metric expression copy leaks
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (325 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0326/1518] drm/panel: samsung-s6d16d0: Power off on prepare failure Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0328/1518] soc: qcom: rpmh-rsc: manage PM notifiers with devres Greg Kroah-Hartman
` (671 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yu Peng, Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yu Peng <pengyu@kylinos.cn>
[ Upstream commit ef3af1df4f3372bd8ad47619452a283048b3bc8d ]
metricgroup__copy_metric_events() allocates a new metric expression and
duplicates metric_name before linking the expression into the destination
metric event.
Free new_expr when strdup() fails, and free the duplicated metric_name on
the later error paths.
Fixes: b85a4d61d302 ("perf metric: Allow modifiers on metrics")
Signed-off-by: Yu Peng <pengyu@kylinos.cn>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/metricgroup.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/tools/perf/util/metricgroup.c b/tools/perf/util/metricgroup.c
index 238c3e605bfe1..bf98a01c4222d 100644
--- a/tools/perf/util/metricgroup.c
+++ b/tools/perf/util/metricgroup.c
@@ -1614,8 +1614,10 @@ int metricgroup__copy_metric_events(struct evlist *evlist, struct cgroup *cgrp,
new_expr->metric_expr = old_expr->metric_expr;
new_expr->metric_threshold = old_expr->metric_threshold;
new_expr->metric_name = strdup(old_expr->metric_name);
- if (!new_expr->metric_name)
+ if (!new_expr->metric_name) {
+ free(new_expr);
return -ENOMEM;
+ }
new_expr->metric_unit = old_expr->metric_unit;
new_expr->runtime = old_expr->runtime;
@@ -1627,6 +1629,7 @@ int metricgroup__copy_metric_events(struct evlist *evlist, struct cgroup *cgrp,
alloc_size = sizeof(*new_expr->metric_refs);
new_expr->metric_refs = calloc(nr + 1, alloc_size);
if (!new_expr->metric_refs) {
+ zfree(&new_expr->metric_name);
free(new_expr);
return -ENOMEM;
}
@@ -1643,6 +1646,7 @@ int metricgroup__copy_metric_events(struct evlist *evlist, struct cgroup *cgrp,
alloc_size = sizeof(*new_expr->metric_events);
new_expr->metric_events = calloc(nr + 1, alloc_size);
if (!new_expr->metric_events) {
+ zfree(&new_expr->metric_name);
zfree(&new_expr->metric_refs);
free(new_expr);
return -ENOMEM;
@@ -1653,6 +1657,7 @@ int metricgroup__copy_metric_events(struct evlist *evlist, struct cgroup *cgrp,
evsel = old_expr->metric_events[idx];
evsel = evlist__find_evsel(evlist, evsel->core.idx);
if (evsel == NULL) {
+ zfree(&new_expr->metric_name);
zfree(&new_expr->metric_events);
zfree(&new_expr->metric_refs);
free(new_expr);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0328/1518] soc: qcom: rpmh-rsc: manage PM notifiers with devres
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (326 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0327/1518] perf metricgroup: Fix metric expression copy leaks Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0329/1518] bus: qcom-ebi2: use managed resources for clocks and children Greg Kroah-Hartman
` (670 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Konrad Dybcio,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit 75e918aa876440d8ad559a11d6ab87bddb1ed79a ]
rpmh_rsc_probe() registers CPU PM or genpd notifiers before populating
child devices. If child population fails, the CPU PM notifier path is not
unwound and the genpd path needs open-coded cleanup.
Use devm_pm_runtime_enable() for the genpd path and
devm_add_action_or_reset() for both notifier registrations. This makes
probe failure and driver detach use the same cleanup model while keeping
devm_of_platform_populate() responsible for child devices.
Fixes: 25092e6100ac ("soc: qcom: rpmh-rsc: Attach RSC to cluster PM domain")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260623015501.31129-1-pengpeng@iscas.ac.cn
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/soc/qcom/rpmh-rsc.c | 37 ++++++++++++++++++++++++++-----------
1 file changed, 26 insertions(+), 11 deletions(-)
diff --git a/drivers/soc/qcom/rpmh-rsc.c b/drivers/soc/qcom/rpmh-rsc.c
index c6f7d5c9c493d..66928ca40b9aa 100644
--- a/drivers/soc/qcom/rpmh-rsc.c
+++ b/drivers/soc/qcom/rpmh-rsc.c
@@ -944,17 +944,30 @@ static int rpmh_rsc_pd_callback(struct notifier_block *nfb,
return NOTIFY_OK;
}
+static void rpmh_rsc_pd_detach(void *data)
+{
+ dev_pm_genpd_remove_notifier(data);
+}
+
static int rpmh_rsc_pd_attach(struct rsc_drv *drv, struct device *dev)
{
int ret;
- pm_runtime_enable(dev);
+ ret = devm_pm_runtime_enable(dev);
+ if (ret)
+ return ret;
+
drv->genpd_nb.notifier_call = rpmh_rsc_pd_callback;
ret = dev_pm_genpd_add_notifier(dev, &drv->genpd_nb);
if (ret)
- pm_runtime_disable(dev);
+ return ret;
- return ret;
+ return devm_add_action_or_reset(dev, rpmh_rsc_pd_detach, dev);
+}
+
+static void rpmh_rsc_cpu_pm_unregister(void *data)
+{
+ cpu_pm_unregister_notifier(data);
}
static int rpmh_probe_tcs_config(struct platform_device *pdev, struct rsc_drv *drv)
@@ -1107,7 +1120,15 @@ static int rpmh_rsc_probe(struct platform_device *pdev)
return ret;
} else {
drv->rsc_pm.notifier_call = rpmh_rsc_cpu_pm_callback;
- cpu_pm_register_notifier(&drv->rsc_pm);
+ ret = cpu_pm_register_notifier(&drv->rsc_pm);
+ if (ret)
+ return ret;
+
+ ret = devm_add_action_or_reset(&pdev->dev,
+ rpmh_rsc_cpu_pm_unregister,
+ &drv->rsc_pm);
+ if (ret)
+ return ret;
}
}
@@ -1122,13 +1143,7 @@ static int rpmh_rsc_probe(struct platform_device *pdev)
dev_set_drvdata(&pdev->dev, drv);
drv->dev = &pdev->dev;
- ret = devm_of_platform_populate(&pdev->dev);
- if (ret && pdev->dev.pm_domain) {
- dev_pm_genpd_remove_notifier(&pdev->dev);
- pm_runtime_disable(&pdev->dev);
- }
-
- return ret;
+ return devm_of_platform_populate(&pdev->dev);
}
static const struct of_device_id rpmh_drv_match[] = {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0329/1518] bus: qcom-ebi2: use managed resources for clocks and children
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (327 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0328/1518] soc: qcom: rpmh-rsc: manage PM notifiers with devres Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0330/1518] clk: qcom: camcc-sc8280xp: unregister CAMCC_GDSC_CLK Greg Kroah-Hartman
` (669 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Konrad Dybcio,
Linus Walleij, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit d19a46f7ed8eb54fea61e0eaf7db53ff7babb03c ]
qcom_ebi2_probe() enables the EBI2 clocks manually and populates child
devices manually. Several later failure paths can then return without
disabling the clocks or without relying on the driver core to undo child
population.
Use devm_clk_get_enabled() for both clocks and
devm_of_platform_populate() for children. This lets the driver core
unwind the resources automatically and removes the hand-written error
labels.
Fixes: 335a12754808 ("bus: qcom: add EBI2 driver")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Linus Walleij <linusw@kernel.org>
Link: https://lore.kernel.org/r/20260623015415.26975-1-pengpeng@iscas.ac.cn
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bus/qcom-ebi2.c | 50 +++++++++--------------------------------
1 file changed, 11 insertions(+), 39 deletions(-)
diff --git a/drivers/bus/qcom-ebi2.c b/drivers/bus/qcom-ebi2.c
index ab00c75b9e953..8d2eb955dc921 100644
--- a/drivers/bus/qcom-ebi2.c
+++ b/drivers/bus/qcom-ebi2.c
@@ -302,41 +302,23 @@ static int qcom_ebi2_probe(struct platform_device *pdev)
u32 val;
int ret;
- ebi2xclk = devm_clk_get(dev, "ebi2x");
+ ebi2xclk = devm_clk_get_enabled(dev, "ebi2x");
if (IS_ERR(ebi2xclk))
return PTR_ERR(ebi2xclk);
- ret = clk_prepare_enable(ebi2xclk);
- if (ret) {
- dev_err(dev, "could not enable EBI2X clk (%d)\n", ret);
- return ret;
- }
-
- ebi2clk = devm_clk_get(dev, "ebi2");
- if (IS_ERR(ebi2clk)) {
- ret = PTR_ERR(ebi2clk);
- goto err_disable_2x_clk;
- }
-
- ret = clk_prepare_enable(ebi2clk);
- if (ret) {
- dev_err(dev, "could not enable EBI2 clk\n");
- goto err_disable_2x_clk;
- }
+ ebi2clk = devm_clk_get_enabled(dev, "ebi2");
+ if (IS_ERR(ebi2clk))
+ return PTR_ERR(ebi2clk);
res = platform_get_resource(pdev, IORESOURCE_MEM, 0);
ebi2_base = devm_ioremap_resource(dev, res);
- if (IS_ERR(ebi2_base)) {
- ret = PTR_ERR(ebi2_base);
- goto err_disable_clk;
- }
+ if (IS_ERR(ebi2_base))
+ return PTR_ERR(ebi2_base);
res = platform_get_resource(pdev, IORESOURCE_MEM, 1);
ebi2_xmem = devm_ioremap_resource(dev, res);
- if (IS_ERR(ebi2_xmem)) {
- ret = PTR_ERR(ebi2_xmem);
- goto err_disable_clk;
- }
+ if (IS_ERR(ebi2_xmem))
+ return PTR_ERR(ebi2_xmem);
/* Allegedly this turns the power save mode off */
writel(0UL, ebi2_xmem + EBI2_XMEM_CFG);
@@ -353,7 +335,7 @@ static int qcom_ebi2_probe(struct platform_device *pdev)
/* Figure out the chipselect */
ret = of_property_read_u32(child, "reg", &csindex);
if (ret)
- goto err_disable_clk;
+ return ret;
if (csindex > 5) {
dev_err(dev,
@@ -372,20 +354,10 @@ static int qcom_ebi2_probe(struct platform_device *pdev)
have_children = true;
}
- if (have_children) {
- ret = of_platform_default_populate(np, NULL, dev);
- if (ret)
- goto err_disable_clk;
- }
+ if (have_children)
+ return devm_of_platform_populate(dev);
return 0;
-
-err_disable_clk:
- clk_disable_unprepare(ebi2clk);
-err_disable_2x_clk:
- clk_disable_unprepare(ebi2xclk);
-
- return ret;
}
static const struct of_device_id qcom_ebi2_of_match[] = {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0330/1518] clk: qcom: camcc-sc8280xp: unregister CAMCC_GDSC_CLK
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (328 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0329/1518] bus: qcom-ebi2: use managed resources for clocks and children Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0331/1518] tools/sched_ext: Strip compatibility macros for cgroup and dispatch APIs Greg Kroah-Hartman
` (668 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jagadeesh Kona, Brian Masney,
Konrad Dybcio, Dmitry Baryshkov, Bryan ODonoghue, Bjorn Andersson,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Brian Masney <bmasney@redhat.com>
[ Upstream commit 499b4cb6710f9a351d8b57a2132f9b4389d8464a ]
With the introduction of sync_state support in the clk and pmdomain
subsystems, the following warning happens when the unused clocks are
shutdown in camcc-sc8280xp:
[ 15.408367] titan_top_gdsc status stuck at 'on'
[ 15.408429] WARNING: drivers/clk/qcom/gdsc.c:178 at gdsc_toggle_logic+0x14c/0x160, CPU#2: kworker/u32:1/14
[ 15.408462] Modules linked in: bnep vfat fat ath11k_pci(+) ath11k mac80211 cfg80211 mhi libarc4 snd_soc_wcd938x snd_soc_wcd938x_sdw snd_soc_wcd_classh hci_uart snd_soc_wcd_common
snd_soc_sc8280xp soundwire_qcom snd_soc_wcd_mbhc snd_soc_qcom_sdw slimbus snd_soc_qcom_common regmap_sdw btqca btrtl qcom_camss soundwire_bus btbcm btintel snd_soc_sdca snd_soc_lpass_wsa_macro
bluetooth snd_soc_lpass_tx_macro snd_soc_lpass_va_macro snd_soc_lpass_rx_macro snd_soc_hdmi_codec snd_soc_lpass_macro_common videobuf2_dma_sg ov5675 v4l2_fwnode videobuf2_memops
qcom_spmi_adc5 snd_soc_core qcom_spmi_adc_tm5 videobuf2_v4l2 snd_seq snd_seq_device videobuf2_common v4l2_async qcom_vadc_common qcom_spmi_temp_alarm pm8941_pwrkey industrialio videodev
snd_compress rfkill ac97_bus snd_pcm_dmaengine qcom_tsens mc qcom_edac snd_pcm pci_pwrctrl_pwrseq qcom_cpufreq_hw snd_timer snd qcomtee soundcore tee leds_gpio joydev binfmt_misc zram
lz4hc_compress governor_simpleondemand panel_edp msm xhci_plat_hcd nvme nvme_core dwc3 qcom_pm8008_regulator
[ 15.408688] ucsi_glink nvme_keyring nvme_auth pmic_glink_altmode udc_core typec_ucsi aux_hpd_bridge qcom_battmgr ulpi ubwc_config socinfo ocmem drm_gpuvm qcom_q6v5_pas drm_exec
qcom_pil_info leds_qcom_lpg gpu_sched led_class_multicolor rtc_pm8xxx qcom_pbs qcom_common drm_display_helper qcom_pon qcom_glink_smem qcom_glink ghash_ce pwrseq_qcom_wcn gpio_sbu_mux
qcom_stats phy_qcom_qmp_combo qcom_q6v5 gf128mul cec dispcc_sc8280xp phy_qcom_edp camcc_sc8280xp i2c_qcom_cci qcom_sysmon drm_dp_aux_bus mdt_loader aux_bridge qcom_pm8008 i2c_hid_of_elan
dwc3_qcom_legacy llcc_qcom icc_bwmon gpi typec qcom_refgen_regulator phy_qcom_qmp_usb nvmem_qfprom qcom_ipcc phy_qcom_snps_femto_v2 gpucc_sc8280xp pinctrl_sc8280xp_lpass_lpi qcom_hwspinlock
pinctrl_lpass_lpi lpasscc_sc8280xp qrtr qcom_aoss pmic_glink pdr_interface phy_qcom_qmp_pcie qcom_smd qcom_pdr_msg icc_osm_l3 qcom_wdt qmi_helpers qcom_rng smp2p rpmsg_core gpio_keys pwm_bl
smem hid_multitouch fuse i2c_dev
[ 15.408928] CPU: 2 UID: 0 PID: 14 Comm: kworker/u32:1 Not tainted 7.1.0+ #2 PREEMPT(lazy)
[ 15.408937] Hardware name: LENOVO 21BX0016US/21BX0016US, BIOS N3HET88W (1.60 ) 03/14/2024
[ 15.408942] Workqueue: pm pm_runtime_work
[ 15.408959] pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
[ 15.408967] pc : gdsc_toggle_logic+0x14c/0x160
[ 15.408978] lr : gdsc_toggle_logic+0x14c/0x160
[ 15.408987] sp : ffff8000800f3b40
[ 15.408991] x29: ffff8000800f3b40 x28: 0000000000000000 x27: 0000000000000000
[ 15.409003] x26: 0000000000000000 x25: 0000000000000000 x24: 0000000000000000
[ 15.409014] x23: 0000000000000000 x22: 0000000000000001 x21: ffffa33f298fca88
[ 15.409024] x20: 0000000000000000 x19: ffffa33f298fc5b0 x18: 00cd15db75dacefd
[ 15.409035] x17: 000000040044ffff x16: ffffa33f3b1a3d88 x15: 726f776b80000002
[ 15.409045] x14: ffffffffffffffff x13: 0000000000000028 x12: 0101010101010101
[ 15.409056] x11: 7f7f7f7f7f7f7f7f x10: fefeff3039313274 x9 : ffffa33f3a5edafc
[ 15.409067] x8 : ffff8000800f3780 x7 : 0000000000000001 x6 : 0000000000000001
[ 15.409078] x5 : ffff000bf3ca1288 x4 : 0000000000000000 x3 : ffff5cccb6a3f000
[ 15.409088] x2 : 0000000000000000 x1 : 0000000000000000 x0 : ffff000080ae0000
[ 15.409098] Call trace:
[ 15.409103] gdsc_toggle_logic+0x14c/0x160 (P)
[ 15.409115] gdsc_disable+0x4c/0x190
[ 15.409126] _genpd_power_off+0xa0/0x1a8
[ 15.409137] genpd_power_off.part.0+0x180/0x2a0
[ 15.409149] genpd_runtime_suspend+0x218/0x310
[ 15.409155] __rpm_callback+0x50/0x1f8
[ 15.409166] rpm_callback+0x7c/0x90
[ 15.409175] rpm_suspend+0xe8/0x690
[ 15.409185] pm_runtime_work+0xd0/0xe0
[ 15.409195] process_one_work+0x18c/0x518
[ 15.409208] worker_thread+0x190/0x320
[ 15.409218] kthread+0x110/0x130
[ 15.409227] ret_from_fork+0x10/0x20
This clock is force enabled to be on in the probe, and registered with
the Common Clk Framework, resulting in them being toggled off after
unused clocks are shutdown. This clock is required for the GDSC
transitions.
Similar to the fix in commit b60521eff227 ("clk: qcom: gcc-x1e80100:
Unregister GCC_GPU_CFG_AHB_CLK/GCC_DISP_XO_CLK"), let's just unregister
this clock.
Link: https://lore.kernel.org/linux-clk/20260626-camcc-sc8280xp-titan-top-v1-1-2ca246886493@redhat.com/
Fixes: ff93872a9c616 ("clk: qcom: camcc-sc8280xp: Add sc8280xp CAMCC")
Suggested-by: Jagadeesh Kona <jagadeesh.kona@oss.qualcomm.com>
Signed-off-by: Brian Masney <bmasney@redhat.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Reviewed-by: Bryan O'Donoghue <bryan.odonoghue@linaro.org>
Link: https://lore.kernel.org/r/20260708-camcc-sc8280xp-remove-gdsc-v1-1-dfaab98a3bf5@redhat.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/qcom/camcc-sc8280xp.c | 19 -------------------
1 file changed, 19 deletions(-)
diff --git a/drivers/clk/qcom/camcc-sc8280xp.c b/drivers/clk/qcom/camcc-sc8280xp.c
index 18f5a3eb313e1..1de238a85ab9f 100644
--- a/drivers/clk/qcom/camcc-sc8280xp.c
+++ b/drivers/clk/qcom/camcc-sc8280xp.c
@@ -1754,24 +1754,6 @@ static struct clk_branch camcc_csiphy3_clk = {
},
};
-static struct clk_branch camcc_gdsc_clk = {
- .halt_reg = 0xc1e4,
- .halt_check = BRANCH_HALT,
- .clkr = {
- .enable_reg = 0xc1e4,
- .enable_mask = BIT(0),
- .hw.init = &(struct clk_init_data){
- .name = "camcc_gdsc_clk",
- .parent_hws = (const struct clk_hw*[]){
- &camcc_xo_clk_src.clkr.hw,
- },
- .num_parents = 1,
- .flags = CLK_SET_RATE_PARENT,
- .ops = &clk_branch2_ops,
- },
- },
-};
-
static struct clk_branch camcc_icp_ahb_clk = {
.halt_reg = 0xc0d8,
.halt_check = BRANCH_HALT,
@@ -2840,7 +2822,6 @@ static struct clk_regmap *camcc_sc8280xp_clocks[] = {
[CAMCC_CSIPHY2_CLK] = &camcc_csiphy2_clk.clkr,
[CAMCC_CSIPHY3_CLK] = &camcc_csiphy3_clk.clkr,
[CAMCC_FAST_AHB_CLK_SRC] = &camcc_fast_ahb_clk_src.clkr,
- [CAMCC_GDSC_CLK] = &camcc_gdsc_clk.clkr,
[CAMCC_ICP_AHB_CLK] = &camcc_icp_ahb_clk.clkr,
[CAMCC_ICP_CLK] = &camcc_icp_clk.clkr,
[CAMCC_ICP_CLK_SRC] = &camcc_icp_clk_src.clkr,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0331/1518] tools/sched_ext: Strip compatibility macros for cgroup and dispatch APIs
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (329 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0330/1518] clk: qcom: camcc-sc8280xp: unregister CAMCC_GDSC_CLK Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0332/1518] bpf: Require a BPF cpumask for bpf_cpumask_populate() Greg Kroah-Hartman
` (667 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Changwoo Min, Andrea Righi,
Emil Tsalapatis, Tejun Heo, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tejun Heo <tj@kernel.org>
[ Upstream commit 111a79800aeda615797f20b3a00ef116edce9e03 ]
Enough time has passed since the introduction of scx_bpf_task_cgroup() and
the scx_bpf_dispatch* -> scx_bpf_dsq* kfunc renaming. Strip the compatibility
macros.
Acked-by: Changwoo Min <changwoo@igalia.com>
Acked-by: Andrea Righi <arighi@nvidia.com>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Signed-off-by: Tejun Heo <tj@kernel.org>
Stable-dep-of: 8740156ad33b ("bpf: Require a BPF cpumask for bpf_cpumask_populate()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/sched_ext/include/scx/compat.bpf.h | 108 +----------------------
tools/sched_ext/scx_flatcg.bpf.c | 10 +--
tools/sched_ext/scx_qmap.bpf.c | 14 ++-
3 files changed, 12 insertions(+), 120 deletions(-)
diff --git a/tools/sched_ext/include/scx/compat.bpf.h b/tools/sched_ext/include/scx/compat.bpf.h
index dd9144624dc99..d979f16a3ae2b 100644
--- a/tools/sched_ext/include/scx/compat.bpf.h
+++ b/tools/sched_ext/include/scx/compat.bpf.h
@@ -15,121 +15,17 @@
__ret; \
})
-/* v6.12: 819513666966 ("sched_ext: Add cgroup support") */
-#define __COMPAT_scx_bpf_task_cgroup(p) \
- (bpf_ksym_exists(scx_bpf_task_cgroup) ? \
- scx_bpf_task_cgroup((p)) : NULL)
-
/*
- * v6.13: The verb `dispatch` was too overloaded and confusing. kfuncs are
- * renamed to unload the verb.
- *
- * Build error is triggered if old names are used. New binaries work with both
- * new and old names. The compat macros will be removed on v6.15 release.
+ * v6.15: 950ad93df2fc ("bpf: add kfunc for populating cpumask bits")
*
- * scx_bpf_dispatch_from_dsq() and friends were added during v6.12 by
- * 4c30f5ce4f7a ("sched_ext: Implement scx_bpf_dispatch[_vtime]_from_dsq()").
- * Preserve __COMPAT macros until v6.15.
+ * Compat macro will be dropped on v6.19 release.
*/
-void scx_bpf_dispatch___compat(struct task_struct *p, u64 dsq_id, u64 slice, u64 enq_flags) __ksym __weak;
-void scx_bpf_dispatch_vtime___compat(struct task_struct *p, u64 dsq_id, u64 slice, u64 vtime, u64 enq_flags) __ksym __weak;
-bool scx_bpf_consume___compat(u64 dsq_id) __ksym __weak;
-void scx_bpf_dispatch_from_dsq_set_slice___compat(struct bpf_iter_scx_dsq *it__iter, u64 slice) __ksym __weak;
-void scx_bpf_dispatch_from_dsq_set_vtime___compat(struct bpf_iter_scx_dsq *it__iter, u64 vtime) __ksym __weak;
-bool scx_bpf_dispatch_from_dsq___compat(struct bpf_iter_scx_dsq *it__iter, struct task_struct *p, u64 dsq_id, u64 enq_flags) __ksym __weak;
-bool scx_bpf_dispatch_vtime_from_dsq___compat(struct bpf_iter_scx_dsq *it__iter, struct task_struct *p, u64 dsq_id, u64 enq_flags) __ksym __weak;
int bpf_cpumask_populate(struct cpumask *dst, void *src, size_t src__sz) __ksym __weak;
-#define scx_bpf_dsq_insert(p, dsq_id, slice, enq_flags) \
- (bpf_ksym_exists(scx_bpf_dsq_insert) ? \
- scx_bpf_dsq_insert((p), (dsq_id), (slice), (enq_flags)) : \
- scx_bpf_dispatch___compat((p), (dsq_id), (slice), (enq_flags)))
-
-#define scx_bpf_dsq_insert_vtime(p, dsq_id, slice, vtime, enq_flags) \
- (bpf_ksym_exists(scx_bpf_dsq_insert_vtime) ? \
- scx_bpf_dsq_insert_vtime((p), (dsq_id), (slice), (vtime), (enq_flags)) : \
- scx_bpf_dispatch_vtime___compat((p), (dsq_id), (slice), (vtime), (enq_flags)))
-
-#define scx_bpf_dsq_move_to_local(dsq_id) \
- (bpf_ksym_exists(scx_bpf_dsq_move_to_local) ? \
- scx_bpf_dsq_move_to_local((dsq_id)) : \
- scx_bpf_consume___compat((dsq_id)))
-
-#define __COMPAT_scx_bpf_dsq_move_set_slice(it__iter, slice) \
- (bpf_ksym_exists(scx_bpf_dsq_move_set_slice) ? \
- scx_bpf_dsq_move_set_slice((it__iter), (slice)) : \
- (bpf_ksym_exists(scx_bpf_dispatch_from_dsq_set_slice___compat) ? \
- scx_bpf_dispatch_from_dsq_set_slice___compat((it__iter), (slice)) : \
- (void)0))
-
-#define __COMPAT_scx_bpf_dsq_move_set_vtime(it__iter, vtime) \
- (bpf_ksym_exists(scx_bpf_dsq_move_set_vtime) ? \
- scx_bpf_dsq_move_set_vtime((it__iter), (vtime)) : \
- (bpf_ksym_exists(scx_bpf_dispatch_from_dsq_set_vtime___compat) ? \
- scx_bpf_dispatch_from_dsq_set_vtime___compat((it__iter), (vtime)) : \
- (void) 0))
-
-#define __COMPAT_scx_bpf_dsq_move(it__iter, p, dsq_id, enq_flags) \
- (bpf_ksym_exists(scx_bpf_dsq_move) ? \
- scx_bpf_dsq_move((it__iter), (p), (dsq_id), (enq_flags)) : \
- (bpf_ksym_exists(scx_bpf_dispatch_from_dsq___compat) ? \
- scx_bpf_dispatch_from_dsq___compat((it__iter), (p), (dsq_id), (enq_flags)) : \
- false))
-
-#define __COMPAT_scx_bpf_dsq_move_vtime(it__iter, p, dsq_id, enq_flags) \
- (bpf_ksym_exists(scx_bpf_dsq_move_vtime) ? \
- scx_bpf_dsq_move_vtime((it__iter), (p), (dsq_id), (enq_flags)) : \
- (bpf_ksym_exists(scx_bpf_dispatch_vtime_from_dsq___compat) ? \
- scx_bpf_dispatch_vtime_from_dsq___compat((it__iter), (p), (dsq_id), (enq_flags)) : \
- false))
-
#define __COMPAT_bpf_cpumask_populate(cpumask, src, size__sz) \
(bpf_ksym_exists(bpf_cpumask_populate) ? \
(bpf_cpumask_populate(cpumask, src, size__sz)) : -EOPNOTSUPP)
-#define scx_bpf_dispatch(p, dsq_id, slice, enq_flags) \
- _Static_assert(false, "scx_bpf_dispatch() renamed to scx_bpf_dsq_insert()")
-
-#define scx_bpf_dispatch_vtime(p, dsq_id, slice, vtime, enq_flags) \
- _Static_assert(false, "scx_bpf_dispatch_vtime() renamed to scx_bpf_dsq_insert_vtime()")
-
-#define scx_bpf_consume(dsq_id) ({ \
- _Static_assert(false, "scx_bpf_consume() renamed to scx_bpf_dsq_move_to_local()"); \
- false; \
-})
-
-#define scx_bpf_dispatch_from_dsq_set_slice(it__iter, slice) \
- _Static_assert(false, "scx_bpf_dispatch_from_dsq_set_slice() renamed to scx_bpf_dsq_move_set_slice()")
-
-#define scx_bpf_dispatch_from_dsq_set_vtime(it__iter, vtime) \
- _Static_assert(false, "scx_bpf_dispatch_from_dsq_set_vtime() renamed to scx_bpf_dsq_move_set_vtime()")
-
-#define scx_bpf_dispatch_from_dsq(it__iter, p, dsq_id, enq_flags) ({ \
- _Static_assert(false, "scx_bpf_dispatch_from_dsq() renamed to scx_bpf_dsq_move()"); \
- false; \
-})
-
-#define scx_bpf_dispatch_vtime_from_dsq(it__iter, p, dsq_id, enq_flags) ({ \
- _Static_assert(false, "scx_bpf_dispatch_vtime_from_dsq() renamed to scx_bpf_dsq_move_vtime()"); \
- false; \
-})
-
-#define __COMPAT_scx_bpf_dispatch_from_dsq_set_slice(it__iter, slice) \
- _Static_assert(false, "__COMPAT_scx_bpf_dispatch_from_dsq_set_slice() renamed to __COMPAT_scx_bpf_dsq_move_set_slice()")
-
-#define __COMPAT_scx_bpf_dispatch_from_dsq_set_vtime(it__iter, vtime) \
- _Static_assert(false, "__COMPAT_scx_bpf_dispatch_from_dsq_set_vtime() renamed to __COMPAT_scx_bpf_dsq_move_set_vtime()")
-
-#define __COMPAT_scx_bpf_dispatch_from_dsq(it__iter, p, dsq_id, enq_flags) ({ \
- _Static_assert(false, "__COMPAT_scx_bpf_dispatch_from_dsq() renamed to __COMPAT_scx_bpf_dsq_move()"); \
- false; \
-})
-
-#define __COMPAT_scx_bpf_dispatch_vtime_from_dsq(it__iter, p, dsq_id, enq_flags) ({ \
- _Static_assert(false, "__COMPAT_scx_bpf_dispatch_vtime_from_dsq() renamed to __COMPAT_scx_bpf_dsq_move_vtime()"); \
- false; \
-})
-
/**
* __COMPAT_is_enq_cpu_selected - Test if SCX_ENQ_CPU_SELECTED is on
* in a compatible way. We will preserve this __COMPAT helper until v6.16.
diff --git a/tools/sched_ext/scx_flatcg.bpf.c b/tools/sched_ext/scx_flatcg.bpf.c
index eab9dafc8cb31..cd9bf93d70b1f 100644
--- a/tools/sched_ext/scx_flatcg.bpf.c
+++ b/tools/sched_ext/scx_flatcg.bpf.c
@@ -382,7 +382,7 @@ void BPF_STRUCT_OPS(fcg_enqueue, struct task_struct *p, u64 enq_flags)
return;
}
- cgrp = __COMPAT_scx_bpf_task_cgroup(p);
+ cgrp = scx_bpf_task_cgroup(p);
cgc = find_cgrp_ctx(cgrp);
if (!cgc)
goto out_release;
@@ -508,7 +508,7 @@ void BPF_STRUCT_OPS(fcg_runnable, struct task_struct *p, u64 enq_flags)
{
struct cgroup *cgrp;
- cgrp = __COMPAT_scx_bpf_task_cgroup(p);
+ cgrp = scx_bpf_task_cgroup(p);
update_active_weight_sums(cgrp, true);
bpf_cgroup_release(cgrp);
}
@@ -521,7 +521,7 @@ void BPF_STRUCT_OPS(fcg_running, struct task_struct *p)
if (fifo_sched)
return;
- cgrp = __COMPAT_scx_bpf_task_cgroup(p);
+ cgrp = scx_bpf_task_cgroup(p);
cgc = find_cgrp_ctx(cgrp);
if (cgc) {
/*
@@ -564,7 +564,7 @@ void BPF_STRUCT_OPS(fcg_stopping, struct task_struct *p, bool runnable)
if (!taskc->bypassed_at)
return;
- cgrp = __COMPAT_scx_bpf_task_cgroup(p);
+ cgrp = scx_bpf_task_cgroup(p);
cgc = find_cgrp_ctx(cgrp);
if (cgc) {
__sync_fetch_and_add(&cgc->cvtime_delta,
@@ -579,7 +579,7 @@ void BPF_STRUCT_OPS(fcg_quiescent, struct task_struct *p, u64 deq_flags)
{
struct cgroup *cgrp;
- cgrp = __COMPAT_scx_bpf_task_cgroup(p);
+ cgrp = scx_bpf_task_cgroup(p);
update_active_weight_sums(cgrp, false);
bpf_cgroup_release(cgrp);
}
diff --git a/tools/sched_ext/scx_qmap.bpf.c b/tools/sched_ext/scx_qmap.bpf.c
index 4f65a7550fb2d..b76702bbf1ee8 100644
--- a/tools/sched_ext/scx_qmap.bpf.c
+++ b/tools/sched_ext/scx_qmap.bpf.c
@@ -320,12 +320,9 @@ static bool dispatch_highpri(bool from_timer)
if (tctx->highpri) {
/* exercise the set_*() and vtime interface too */
- __COMPAT_scx_bpf_dsq_move_set_slice(
- BPF_FOR_EACH_ITER, slice_ns * 2);
- __COMPAT_scx_bpf_dsq_move_set_vtime(
- BPF_FOR_EACH_ITER, highpri_seq++);
- __COMPAT_scx_bpf_dsq_move_vtime(
- BPF_FOR_EACH_ITER, p, HIGHPRI_DSQ, 0);
+ scx_bpf_dsq_move_set_slice(BPF_FOR_EACH_ITER, slice_ns * 2);
+ scx_bpf_dsq_move_set_vtime(BPF_FOR_EACH_ITER, highpri_seq++);
+ scx_bpf_dsq_move_vtime(BPF_FOR_EACH_ITER, p, HIGHPRI_DSQ, 0);
}
}
@@ -342,9 +339,8 @@ static bool dispatch_highpri(bool from_timer)
else
cpu = scx_bpf_pick_any_cpu(p->cpus_ptr, 0);
- if (__COMPAT_scx_bpf_dsq_move(BPF_FOR_EACH_ITER, p,
- SCX_DSQ_LOCAL_ON | cpu,
- SCX_ENQ_PREEMPT)) {
+ if (scx_bpf_dsq_move(BPF_FOR_EACH_ITER, p, SCX_DSQ_LOCAL_ON | cpu,
+ SCX_ENQ_PREEMPT)) {
if (cpu == this_cpu) {
dispatched = true;
__sync_fetch_and_add(&nr_expedited_local, 1);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0332/1518] bpf: Require a BPF cpumask for bpf_cpumask_populate()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (330 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0331/1518] tools/sched_ext: Strip compatibility macros for cgroup and dispatch APIs Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0333/1518] wifi: rtw89: pci: add to read PCI configuration space from common code Greg Kroah-Hartman
` (666 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nicholas Dudar, Tejun Heo,
Emil Tsalapatis, Kumar Kartikeya Dwivedi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicholas Dudar <main.kalliope@gmail.com>
[ Upstream commit 8740156ad33be5071b588b594c55f279457f667c ]
bpf_cpumask_populate() writes to its destination with bitmap_copy(), but
the destination is typed as struct cpumask *. That allows the verifier to
accept borrowed cpumask pointers returned by read-only kfuncs, such as
scx_bpf_get_online_cpumask(), as a writable destination.
Make the destination a struct bpf_cpumask * so populate follows the same
ownership rule as the other mutating cpumask kfuncs. Query kfuncs continue
to accept const struct cpumask * inputs.
Fixes: 950ad93df2fc ("bpf: add kfunc for populating cpumask bits")
Signed-off-by: Nicholas Dudar <main.kalliope@gmail.com>
Acked-by: Tejun Heo <tj@kernel.org>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Link: https://lore.kernel.org/bpf/20260709182800.2037938-2-main.kalliope@gmail.com
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/cpumask.c | 6 +++---
tools/sched_ext/include/scx/compat.bpf.h | 2 +-
2 files changed, 4 insertions(+), 4 deletions(-)
diff --git a/kernel/bpf/cpumask.c b/kernel/bpf/cpumask.c
index 9876c5fe6c2a2..341f80bb72ff2 100644
--- a/kernel/bpf/cpumask.c
+++ b/kernel/bpf/cpumask.c
@@ -449,12 +449,12 @@ __bpf_kfunc u32 bpf_cpumask_weight(const struct cpumask *cpumask)
* @src__sz: Length of the BPF memory region in bytes.
*
* Return:
- * * 0 if the struct cpumask * instance was populated successfully.
+ * * 0 if the struct bpf_cpumask * instance was populated successfully.
* * -EACCES if the memory region is too small to populate the cpumask.
* * -EINVAL if the memory region is not aligned to the size of a long
* and the architecture does not support efficient unaligned accesses.
*/
-__bpf_kfunc int bpf_cpumask_populate(struct cpumask *cpumask, void *src, size_t src__sz)
+__bpf_kfunc int bpf_cpumask_populate(struct bpf_cpumask *cpumask, void *src, size_t src__sz)
{
unsigned long source = (unsigned long)src;
@@ -467,7 +467,7 @@ __bpf_kfunc int bpf_cpumask_populate(struct cpumask *cpumask, void *src, size_t
!IS_ALIGNED(source, sizeof(long)))
return -EINVAL;
- bitmap_copy(cpumask_bits(cpumask), src, nr_cpu_ids);
+ bitmap_copy(cpumask_bits(&cpumask->cpumask), src, nr_cpu_ids);
return 0;
}
diff --git a/tools/sched_ext/include/scx/compat.bpf.h b/tools/sched_ext/include/scx/compat.bpf.h
index d979f16a3ae2b..3ffd14e9c948f 100644
--- a/tools/sched_ext/include/scx/compat.bpf.h
+++ b/tools/sched_ext/include/scx/compat.bpf.h
@@ -20,7 +20,7 @@
*
* Compat macro will be dropped on v6.19 release.
*/
-int bpf_cpumask_populate(struct cpumask *dst, void *src, size_t src__sz) __ksym __weak;
+int bpf_cpumask_populate(struct bpf_cpumask *dst, void *src, size_t src__sz) __ksym __weak;
#define __COMPAT_bpf_cpumask_populate(cpumask, src, size__sz) \
(bpf_ksym_exists(bpf_cpumask_populate) ? \
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0333/1518] wifi: rtw89: pci: add to read PCI configuration space from common code
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (331 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0332/1518] bpf: Require a BPF cpumask for bpf_cpumask_populate() Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0334/1518] wifi: rtw89: fw: parse firmware element of DIAG_MAC Greg Kroah-Hartman
` (665 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ping-Ke Shih, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ping-Ke Shih <pkshih@realtek.com>
[ Upstream commit dae8d7d63b740d8f5972b8438b139a6488e0f9fa ]
Normally only access PCI device in pci.c. However for debug purpose,
a set of registers predefined in firmware element including PCI
configuration space should be read for diagnosis.
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
Link: https://patch.msgid.link/20251111022452.28093-2-pkshih@realtek.com
Stable-dep-of: 9bf6bd6ed5ac ("wifi: rtw89: 8852a: fix RSSI report when average beacon RSSI is not ready")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/realtek/rtw89/core.h | 13 +++++++++++++
drivers/net/wireless/realtek/rtw89/mac.h | 2 --
drivers/net/wireless/realtek/rtw89/pci.c | 16 ++++++++++++++++
3 files changed, 29 insertions(+), 2 deletions(-)
diff --git a/drivers/net/wireless/realtek/rtw89/core.h b/drivers/net/wireless/realtek/rtw89/core.h
index 30bc177808352..d3531630a7023 100644
--- a/drivers/net/wireless/realtek/rtw89/core.h
+++ b/drivers/net/wireless/realtek/rtw89/core.h
@@ -38,6 +38,8 @@ extern const struct ieee80211_ops rtw89_ops;
#define RFREG_MASK 0xfffff
#define INV_RF_DATA 0xffffffff
#define BYPASS_CR_DATA 0xbabecafe
+#define RTW89_R32_EA 0xEAEAEAEA
+#define RTW89_R32_DEAD 0xDEADBEEF
#define RTW89_TRACK_WORK_PERIOD round_jiffies_relative(HZ * 2)
#define RTW89_TRACK_PS_WORK_PERIOD msecs_to_jiffies(100)
@@ -3652,6 +3654,8 @@ struct rtw89_hci_ops {
void (*write16)(struct rtw89_dev *rtwdev, u32 addr, u16 data);
void (*write32)(struct rtw89_dev *rtwdev, u32 addr, u32 data);
+ u32 (*read32_pci_cfg)(struct rtw89_dev *rtwdev, u32 addr);
+
int (*mac_pre_init)(struct rtw89_dev *rtwdev);
int (*mac_pre_deinit)(struct rtw89_dev *rtwdev);
int (*mac_post_init)(struct rtw89_dev *rtwdev);
@@ -6626,6 +6630,15 @@ rtw89_write_rf(struct rtw89_dev *rtwdev, enum rtw89_rf_path rf_path,
mutex_unlock(&rtwdev->rf_mutex);
}
+static inline u32 rtw89_read32_pci_cfg(struct rtw89_dev *rtwdev, u32 addr)
+{
+ if (rtwdev->hci.type != RTW89_HCI_TYPE_PCIE ||
+ !rtwdev->hci.ops->read32_pci_cfg)
+ return RTW89_R32_EA;
+
+ return rtwdev->hci.ops->read32_pci_cfg(rtwdev, addr);
+}
+
static inline struct ieee80211_txq *rtw89_txq_to_txq(struct rtw89_txq *rtwtxq)
{
void *p = rtwtxq;
diff --git a/drivers/net/wireless/realtek/rtw89/mac.h b/drivers/net/wireless/realtek/rtw89/mac.h
index 51e37c183a35e..1ac1d0cd79594 100644
--- a/drivers/net/wireless/realtek/rtw89/mac.h
+++ b/drivers/net/wireless/realtek/rtw89/mac.h
@@ -574,8 +574,6 @@ enum rtw89_mac_bf_rrsc_rate {
RTW89_MAC_BF_RRSC_MAX = 32
};
-#define RTW89_R32_EA 0xEAEAEAEA
-#define RTW89_R32_DEAD 0xDEADBEEF
#define MAC_REG_POOL_COUNT 10
#define ACCESS_CMAC(_addr) \
({typeof(_addr) __addr = (_addr); \
diff --git a/drivers/net/wireless/realtek/rtw89/pci.c b/drivers/net/wireless/realtek/rtw89/pci.c
index 6c1f66e65497f..b24237c1e7df7 100644
--- a/drivers/net/wireless/realtek/rtw89/pci.c
+++ b/drivers/net/wireless/realtek/rtw89/pci.c
@@ -2071,6 +2071,20 @@ static void rtw89_pci_ops_write32(struct rtw89_dev *rtwdev, u32 addr, u32 data)
writel(data, rtwpci->mmap + addr);
}
+static u32 rtw89_pci_ops_read32_pci_cfg(struct rtw89_dev *rtwdev, u32 addr)
+{
+ struct rtw89_pci *rtwpci = (struct rtw89_pci *)rtwdev->priv;
+ struct pci_dev *pdev = rtwpci->pdev;
+ u32 value;
+ int ret;
+
+ ret = pci_read_config_dword(pdev, addr, &value);
+ if (ret)
+ return RTW89_R32_EA;
+
+ return value;
+}
+
static void rtw89_pci_ctrl_dma_trx(struct rtw89_dev *rtwdev, bool enable)
{
const struct rtw89_pci_info *info = rtwdev->pci_info;
@@ -4691,6 +4705,8 @@ static const struct rtw89_hci_ops rtw89_pci_ops = {
.write16 = rtw89_pci_ops_write16,
.write32 = rtw89_pci_ops_write32,
+ .read32_pci_cfg = rtw89_pci_ops_read32_pci_cfg,
+
.mac_pre_init = rtw89_pci_ops_mac_pre_init,
.mac_pre_deinit = rtw89_pci_ops_mac_pre_deinit,
.mac_post_init = rtw89_pci_ops_mac_post_init,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0334/1518] wifi: rtw89: fw: parse firmware element of DIAG_MAC
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (332 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0333/1518] wifi: rtw89: pci: add to read PCI configuration space from common code Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0335/1518] wifi: rtw89: debug: add parser to diagnose along DIAG_MAC fw element Greg Kroah-Hartman
` (664 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ping-Ke Shih, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ping-Ke Shih <pkshih@realtek.com>
[ Upstream commit de19cc7def5a9c646264a1e7a2a183a3baad112f ]
The firmware element ID 28 is a set of rules to diagnose if MAC get
abnormal. The latter patch will use these rules via debugfs to know
the status.
The element contains rules with their textual messages shown as below:
+------------------------------------+
| |
| +-----------+ |
| | rule_size |-------|----------+
+----------------+-----------+-------+ -- |
| rule[0] | \ |
| rule[1] | | <---+
| : | /
+------------------------------------+ --
| msg[0] msg[1] | each msg has variable length
| msg[2] msg[3] ... | (with address align 2)
| ... |
+------------------------------------+
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
Link: https://patch.msgid.link/20251111022452.28093-3-pkshih@realtek.com
Stable-dep-of: 9bf6bd6ed5ac ("wifi: rtw89: 8852a: fix RSSI report when average beacon RSSI is not ready")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/realtek/rtw89/core.h | 1 +
drivers/net/wireless/realtek/rtw89/fw.c | 15 +++++++++++++++
drivers/net/wireless/realtek/rtw89/fw.h | 6 ++++++
3 files changed, 22 insertions(+)
diff --git a/drivers/net/wireless/realtek/rtw89/core.h b/drivers/net/wireless/realtek/rtw89/core.h
index d3531630a7023..3998a53b4ee90 100644
--- a/drivers/net/wireless/realtek/rtw89/core.h
+++ b/drivers/net/wireless/realtek/rtw89/core.h
@@ -4705,6 +4705,7 @@ struct rtw89_fw_elm_info {
struct rtw89_phy_rfk_log_fmt *rfk_log_fmt;
const struct rtw89_regd_data *regd;
const struct rtw89_fw_element_hdr *afe;
+ const struct rtw89_fw_element_hdr *diag_mac;
};
enum rtw89_fw_mss_dev_type {
diff --git a/drivers/net/wireless/realtek/rtw89/fw.c b/drivers/net/wireless/realtek/rtw89/fw.c
index 81cd3ea2c3b69..4191fbbc2161c 100644
--- a/drivers/net/wireless/realtek/rtw89/fw.c
+++ b/drivers/net/wireless/realtek/rtw89/fw.c
@@ -1299,6 +1299,18 @@ int rtw89_build_afe_pwr_seq_from_elm(struct rtw89_dev *rtwdev,
return 0;
}
+static
+int rtw89_recognize_diag_mac_from_elm(struct rtw89_dev *rtwdev,
+ const struct rtw89_fw_element_hdr *elm,
+ const union rtw89_fw_element_arg arg)
+{
+ struct rtw89_fw_elm_info *elm_info = &rtwdev->fw.elm_info;
+
+ elm_info->diag_mac = elm;
+
+ return 0;
+}
+
static const struct rtw89_fw_element_handler __fw_element_handlers[] = {
[RTW89_FW_ELEMENT_ID_BBMCU0] = {__rtw89_fw_recognize_from_elm,
{ .fw_type = RTW89_FW_BBMCU0 }, NULL},
@@ -1387,6 +1399,9 @@ static const struct rtw89_fw_element_handler __fw_element_handlers[] = {
[RTW89_FW_ELEMENT_ID_AFE_PWR_SEQ] = {
rtw89_build_afe_pwr_seq_from_elm, {}, "AFE",
},
+ [RTW89_FW_ELEMENT_ID_DIAG_MAC] = {
+ rtw89_recognize_diag_mac_from_elm, {}, NULL,
+ },
};
int rtw89_fw_recognize_elements(struct rtw89_dev *rtwdev)
diff --git a/drivers/net/wireless/realtek/rtw89/fw.h b/drivers/net/wireless/realtek/rtw89/fw.h
index 7c3cb6d85ca5d..98078a3ef89e6 100644
--- a/drivers/net/wireless/realtek/rtw89/fw.h
+++ b/drivers/net/wireless/realtek/rtw89/fw.h
@@ -3989,6 +3989,7 @@ enum rtw89_fw_element_id {
RTW89_FW_ELEMENT_ID_TXPWR_DA_LMT_RU_5GHZ = 25,
RTW89_FW_ELEMENT_ID_TXPWR_DA_LMT_RU_6GHZ = 26,
RTW89_FW_ELEMENT_ID_AFE_PWR_SEQ = 27,
+ RTW89_FW_ELEMENT_ID_DIAG_MAC = 28,
RTW89_FW_ELEMENT_ID_NUM,
};
@@ -4166,6 +4167,11 @@ struct rtw89_fw_element_hdr {
__le32 val;
} __packed infos[];
} __packed afe;
+ struct {
+ __le32 rule_size;
+ u8 rsvd[4];
+ u8 rules_and_msgs[];
+ } __packed diag_mac;
struct __rtw89_fw_txpwr_element txpwr;
struct __rtw89_fw_regd_element regd;
} __packed u;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0335/1518] wifi: rtw89: debug: add parser to diagnose along DIAG_MAC fw element
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (333 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0334/1518] wifi: rtw89: fw: parse firmware element of DIAG_MAC Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0336/1518] wifi: rtw89: mlo: rearrange MLSR link decision flow Greg Kroah-Hartman
` (663 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ping-Ke Shih, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ping-Ke Shih <pkshih@realtek.com>
[ Upstream commit 7bf433c6767ffe2ad5b7ac8680c6e93e7d0be3e4 ]
The rules to diagnose MAC have a common header, and a cmd field is used
to know the exact command and its format. The rules with the same tuple of
fields {sheet, seq} can be seen as a set of compound rules, which treat
it as positive rule if just one of the rules is positive.
Take EQUALV rules as example, if value of {addr, mask} is equal to
predefined value as field val, a rule is positive. Fields addr_name_offset
and msg_offset are offsets related to textual messages for human readable.
Format of common rule header (8 bytes)
+-------+-----+--------+-----------+-----+---------+
| sheet | cmd | seq[2] | io / band | len | rsvd[2] |
+-------+-----+--------+-----------+-----+---------+
Format of rule command is EQUALV (equal value) (24 bytes):
+------+------------------+------+-----+------------+---------+
| addr | addr_name_offset | mask | val | msg_offset | rsvd[4] |
+------+------------------+------+-----+------------+---------+
Format of message:
+-----+----------+
| len | string[] |
+-----+----------+
An example of output:
Plain(Ignore)/Rules/Positive: 115(4)/86/81
Where, Plain is total rules written in firmware element.
Ignore is the ignored rules, such as USB IO, but current is PCIE.
Rules is number of set of compound rules.
Positive is number of positive Rules.
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
Link: https://patch.msgid.link/20251111022452.28093-4-pkshih@realtek.com
Stable-dep-of: 9bf6bd6ed5ac ("wifi: rtw89: 8852a: fix RSSI report when average beacon RSSI is not ready")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/realtek/rtw89/debug.c | 299 +++++++++++++++++++++
1 file changed, 299 insertions(+)
diff --git a/drivers/net/wireless/realtek/rtw89/debug.c b/drivers/net/wireless/realtek/rtw89/debug.c
index a82df3814069c..987eef8170f2b 100644
--- a/drivers/net/wireless/realtek/rtw89/debug.c
+++ b/drivers/net/wireless/realtek/rtw89/debug.c
@@ -87,6 +87,7 @@ struct rtw89_debugfs {
struct rtw89_debugfs_priv disable_dm;
struct rtw89_debugfs_priv mlo_mode;
struct rtw89_debugfs_priv beacon_info;
+ struct rtw89_debugfs_priv diag_mac;
};
struct rtw89_debugfs_iter_data {
@@ -4361,6 +4362,302 @@ rtw89_debug_priv_mlo_mode_set(struct rtw89_dev *rtwdev,
return count;
}
+enum __diag_mac_cmd {
+ __CMD_EQUALV,
+ __CMD_EQUALO,
+ __CMD_NEQUALV,
+ __CMD_NEQUALO,
+ __CMD_SETEQUALV,
+ __CMD_SETEQUALO,
+ __CMD_CMPWCR,
+ __CMD_CMPWWD,
+ __CMD_NEQ_CMPWCR,
+ __CMD_NEQ_CMPWWD,
+ __CMD_INCREMENT,
+ __CMD_MESSAGE,
+};
+
+enum __diag_mac_io {
+ __IO_NORMAL,
+ __IO_NORMAL_PCIE,
+ __IO_NORMAL_USB,
+ __IO_NORMAL_SDIO,
+ __IO_PCIE_CFG,
+ __IO_SDIO_CCCR,
+};
+
+struct __diag_mac_rule_header {
+ u8 sheet;
+ u8 cmd;
+ u8 seq_major;
+ u8 seq_minor;
+ u8 io_band;
+ #define __DIAG_MAC_IO GENMASK(3, 0)
+ #define __DIAG_MAC_N_BAND BIT(4)
+ #define __DIAG_MAC_HAS_BAND BIT(5)
+ u8 len; /* include header. Unit: 4 bytes */
+ u8 rsvd[2];
+} __packed;
+
+struct __diag_mac_rule_equal {
+ struct __diag_mac_rule_header header;
+ __le32 addr;
+ __le32 addr_name_offset;
+ __le32 mask;
+ __le32 val;
+ __le32 msg_offset;
+ u8 rsvd[4];
+} __packed;
+
+struct __diag_mac_rule_increment {
+ struct __diag_mac_rule_header header;
+ __le32 addr;
+ __le32 addr_name_offset;
+ __le32 mask;
+ __le16 sel;
+ __le16 delay;
+ __le32 msg_offset;
+ u8 rsvd[4];
+} __packed;
+
+struct __diag_mac_msg_buf {
+ __le16 len;
+ char string[];
+} __packed;
+
+static ssize_t rtw89_mac_diag_do_equalv(struct rtw89_dev *rtwdev,
+ char *buf, size_t bufsz,
+ const struct __diag_mac_rule_equal *r,
+ const void *msg_start,
+ u64 *positive_bmp)
+{
+ const struct __diag_mac_msg_buf *name = msg_start +
+ le32_to_cpu(r->addr_name_offset);
+ const struct __diag_mac_msg_buf *msg = msg_start +
+ le32_to_cpu(r->msg_offset);
+ bool want_eq = r->header.cmd == __CMD_EQUALV;
+ char *p = buf, *end = buf + bufsz;
+ bool equal = false;
+ u32 val;
+
+ *positive_bmp <<= 1;
+
+ if (u8_get_bits(r->header.io_band, __DIAG_MAC_IO) == __IO_PCIE_CFG)
+ val = rtw89_read32_pci_cfg(rtwdev, le32_to_cpu(r->addr));
+ else
+ val = rtw89_read32(rtwdev, le32_to_cpu(r->addr));
+
+ if ((val & le32_to_cpu(r->mask)) == le32_to_cpu(r->val))
+ equal = true;
+
+ if (want_eq == equal) {
+ *positive_bmp |= BIT(0);
+ return p - buf;
+ }
+
+ p += scnprintf(p, end - p, "sheet: %d, cmd: %d, Reg: %.*s => %x, %.*s\n",
+ r->header.sheet, r->header.cmd, le16_to_cpu(name->len),
+ name->string, val, le16_to_cpu(msg->len), msg->string);
+
+ return p - buf;
+}
+
+static ssize_t rtw89_mac_diag_do_increment(struct rtw89_dev *rtwdev,
+ char *buf, size_t bufsz,
+ const struct __diag_mac_rule_increment *r,
+ const void *msg_start,
+ u64 *positive_bmp)
+{
+ const struct __diag_mac_msg_buf *name = msg_start +
+ le32_to_cpu(r->addr_name_offset);
+ const struct __diag_mac_msg_buf *msg = msg_start +
+ le32_to_cpu(r->msg_offset);
+ char *p = buf, *end = buf + bufsz;
+ u32 addr = le32_to_cpu(r->addr);
+ u32 mask = le32_to_cpu(r->mask);
+ u16 sel = le16_to_cpu(r->sel);
+ u32 val1, val2;
+
+ *positive_bmp <<= 1;
+
+ rtw89_write32(rtwdev, addr, sel);
+
+ if (u8_get_bits(r->header.io_band, __DIAG_MAC_IO) == __IO_PCIE_CFG)
+ val1 = rtw89_read32_pci_cfg(rtwdev, addr);
+ else
+ val1 = rtw89_read32(rtwdev, addr);
+
+ mdelay(le16_to_cpu(r->delay));
+
+ if (u8_get_bits(r->header.io_band, __DIAG_MAC_IO) == __IO_PCIE_CFG)
+ val2 = rtw89_read32_pci_cfg(rtwdev, addr);
+ else
+ val2 = rtw89_read32(rtwdev, addr);
+
+ if ((val2 & mask) > (val1 & mask)) {
+ *positive_bmp |= BIT(0);
+ return p - buf;
+ }
+
+ p += scnprintf(p, end - p, "sheet: %d, cmd: %d, Reg: %.*s [%d]=> %x, %.*s\n",
+ r->header.sheet, r->header.cmd, le16_to_cpu(name->len),
+ name->string, le16_to_cpu(r->sel), val1,
+ le16_to_cpu(msg->len), msg->string);
+
+ return p - buf;
+}
+
+static bool rtw89_mac_diag_match_hci(struct rtw89_dev *rtwdev,
+ const struct __diag_mac_rule_header *rh)
+{
+ switch (u8_get_bits(rh->io_band, __DIAG_MAC_IO)) {
+ case __IO_NORMAL:
+ default:
+ return true;
+ case __IO_NORMAL_PCIE:
+ case __IO_PCIE_CFG:
+ if (rtwdev->hci.type == RTW89_HCI_TYPE_PCIE)
+ return true;
+ break;
+ case __IO_NORMAL_USB:
+ if (rtwdev->hci.type == RTW89_HCI_TYPE_USB)
+ return true;
+ break;
+ case __IO_NORMAL_SDIO:
+ case __IO_SDIO_CCCR:
+ if (rtwdev->hci.type == RTW89_HCI_TYPE_SDIO)
+ return true;
+ break;
+ }
+
+ return false;
+}
+
+static bool rtw89_mac_diag_match_band(struct rtw89_dev *rtwdev,
+ const struct __diag_mac_rule_header *rh)
+{
+ u8 active_bands;
+ bool has_band;
+ u8 band;
+
+ has_band = u8_get_bits(rh->io_band, __DIAG_MAC_HAS_BAND);
+ if (!has_band)
+ return true;
+
+ band = u8_get_bits(rh->io_band, __DIAG_MAC_N_BAND);
+ active_bands = rtw89_get_active_phy_bitmap(rtwdev);
+
+ if (active_bands & BIT(band))
+ return true;
+
+ return false;
+}
+
+static ssize_t rtw89_mac_diag_iter_all(struct rtw89_dev *rtwdev,
+ char *buf, size_t bufsz)
+{
+ const struct rtw89_fw_element_hdr *elm = rtwdev->fw.elm_info.diag_mac;
+ u32 n_plains = 0, n_rules = 0, n_positive = 0, n_ignore = 0;
+ char *p = buf, *end = buf + bufsz, *p_rewind;
+ const void *rule, *rule_end;
+ u32 elm_size, rule_size;
+ const void *msg_start;
+ u64 positive_bmp = 0;
+ u8 prev_sheet = 0;
+ u8 prev_seq = 0;
+ int limit;
+
+ if (!elm) {
+ p += scnprintf(p, end - p, "No diag_mac entry\n");
+ goto out;
+ }
+
+ rule_size = le32_to_cpu(elm->u.diag_mac.rule_size);
+ elm_size = le32_to_cpu(elm->size);
+
+ if (ALIGN(rule_size, 16) > elm_size) {
+ p += scnprintf(p, end - p, "rule size (%u) exceed elm_size (%u)\n",
+ ALIGN(rule_size, 16), elm_size);
+ goto out;
+ }
+
+ rule = &elm->u.diag_mac.rules_and_msgs[0];
+ rule_end = &elm->u.diag_mac.rules_and_msgs[rule_size];
+ msg_start = &elm->u.diag_mac.rules_and_msgs[ALIGN(rule_size, 16)];
+
+ for (limit = 0; limit < 5000 && rule < rule_end; limit++) {
+ const struct __diag_mac_rule_header *rh = rule;
+ u8 sheet = rh->sheet;
+ u8 seq = rh->seq_major;
+
+ if (!rtw89_mac_diag_match_hci(rtwdev, rh) ||
+ !rtw89_mac_diag_match_band(rtwdev, rh)) {
+ n_ignore++;
+ goto next;
+ }
+
+ if (!seq || prev_sheet != sheet || prev_seq != seq) {
+ if (positive_bmp) {
+ n_positive++;
+ /*
+ * discard output for negative results if one in
+ * a sequence set is positive.
+ */
+ if (p_rewind)
+ p = p_rewind;
+ }
+ p_rewind = seq ? p : NULL;
+ positive_bmp = 0;
+ n_rules++;
+ }
+
+ switch (rh->cmd) {
+ case __CMD_EQUALV:
+ case __CMD_NEQUALV:
+ p += rtw89_mac_diag_do_equalv(rtwdev, p, end - p, rule,
+ msg_start, &positive_bmp);
+ break;
+ case __CMD_INCREMENT:
+ p += rtw89_mac_diag_do_increment(rtwdev, p, end - p, rule,
+ msg_start, &positive_bmp);
+ break;
+ default:
+ p += scnprintf(p, end - p, "unknown rule cmd %u\n", rh->cmd);
+ break;
+ }
+
+next:
+ n_plains++;
+ rule += rh->len * 4;
+ prev_seq = seq;
+ prev_sheet = sheet;
+ }
+
+ if (positive_bmp) {
+ n_positive++;
+ if (p_rewind)
+ p = p_rewind;
+ }
+
+ p += scnprintf(p, end - p, "\nPlain(Ignore)/Rules/Positive: %u(%u)/%u/%u\n",
+ n_plains, n_ignore, n_rules, n_positive);
+
+out:
+ return p - buf;
+}
+
+static ssize_t
+rtw89_debug_priv_diag_mac_get(struct rtw89_dev *rtwdev,
+ struct rtw89_debugfs_priv *debugfs_priv,
+ char *buf, size_t bufsz)
+{
+ lockdep_assert_wiphy(rtwdev->hw->wiphy);
+
+ rtw89_leave_lps(rtwdev);
+
+ return rtw89_mac_diag_iter_all(rtwdev, buf, bufsz);
+}
+
static ssize_t
rtw89_debug_priv_beacon_info_get(struct rtw89_dev *rtwdev,
struct rtw89_debugfs_priv *debugfs_priv,
@@ -4478,6 +4775,7 @@ static const struct rtw89_debugfs rtw89_debugfs_templ = {
.disable_dm = rtw89_debug_priv_set_and_get(disable_dm, RWLOCK),
.mlo_mode = rtw89_debug_priv_set_and_get(mlo_mode, RWLOCK),
.beacon_info = rtw89_debug_priv_get(beacon_info),
+ .diag_mac = rtw89_debug_priv_get(diag_mac, RSIZE_16K, RLOCK),
};
#define rtw89_debugfs_add(name, mode, fopname, parent) \
@@ -4524,6 +4822,7 @@ void rtw89_debugfs_add_sec1(struct rtw89_dev *rtwdev, struct dentry *debugfs_top
rtw89_debugfs_add_rw(disable_dm);
rtw89_debugfs_add_rw(mlo_mode);
rtw89_debugfs_add_r(beacon_info);
+ rtw89_debugfs_add_r(diag_mac);
}
void rtw89_debugfs_init(struct rtw89_dev *rtwdev)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0336/1518] wifi: rtw89: mlo: rearrange MLSR link decision flow
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (334 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0335/1518] wifi: rtw89: debug: add parser to diagnose along DIAG_MAC fw element Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0337/1518] wifi: rtw89: phy: support per PHY RX statistics Greg Kroah-Hartman
` (662 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuan-Chung Chen, Ping-Ke Shih,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuan-Chung Chen <damon.chen@realtek.com>
[ Upstream commit 7284f5be5d298c901be1fc9fda6a2476f5ffdbaf ]
The original MLSR link decision refers to RSSI, but it should be
based on the premise of an existing link. Otherwise, make a link
decision to select a new link from any available band.
Signed-off-by: Kuan-Chung Chen <damon.chen@realtek.com>
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
Link: https://patch.msgid.link/20260429132625.1659182-2-pkshih@realtek.com
Stable-dep-of: 9bf6bd6ed5ac ("wifi: rtw89: 8852a: fix RSSI report when average beacon RSSI is not ready")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/realtek/rtw89/core.c | 14 +++++++-------
1 file changed, 7 insertions(+), 7 deletions(-)
diff --git a/drivers/net/wireless/realtek/rtw89/core.c b/drivers/net/wireless/realtek/rtw89/core.c
index 5fd15fc840d8c..2c37b94256f91 100644
--- a/drivers/net/wireless/realtek/rtw89/core.c
+++ b/drivers/net/wireless/realtek/rtw89/core.c
@@ -4270,13 +4270,19 @@ static void rtw89_core_mlsr_link_decision(struct rtw89_dev *rtwdev,
{
unsigned int sel_link_id = IEEE80211_MLD_MAX_NUM_LINKS;
struct ieee80211_vif *vif = rtwvif_to_vif(rtwvif);
+ u8 decided_bands = BIT(RTW89_BAND_NUM) - 1;
struct rtw89_vif_link *rtwvif_link;
const struct rtw89_chan *chan;
unsigned long usable_links;
unsigned int link_id;
- u8 decided_bands;
u8 rssi;
+ usable_links = ieee80211_vif_usable_links(vif);
+
+ rtwvif_link = rtw89_get_designated_link(rtwvif);
+ if (unlikely(!rtwvif_link))
+ goto select;
+
rssi = ewma_rssi_read(&rtwdev->phystat.bcn_rssi);
if (unlikely(!rssi))
return;
@@ -4288,12 +4294,6 @@ static void rtw89_core_mlsr_link_decision(struct rtw89_dev *rtwdev,
else
return;
- usable_links = ieee80211_vif_usable_links(vif);
-
- rtwvif_link = rtw89_get_designated_link(rtwvif);
- if (unlikely(!rtwvif_link))
- goto select;
-
chan = rtw89_chan_get(rtwdev, rtwvif_link->chanctx_idx);
if (decided_bands & BIT(chan->band_type))
return;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0337/1518] wifi: rtw89: phy: support per PHY RX statistics
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (335 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0336/1518] wifi: rtw89: mlo: rearrange MLSR link decision flow Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0338/1518] wifi: rtw89: 8852a: fix RSSI report when average beacon RSSI is not ready Greg Kroah-Hartman
` (661 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kuan-Chung Chen, Ping-Ke Shih,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kuan-Chung Chen <damon.chen@realtek.com>
[ Upstream commit 09d369c66373de8708e442a30460ced17f254915 ]
Previously, RX statistics such as beacon RSSI and packet
counters were shared across all PHYs. To support MLO,
extend the statistics to be maintained per PHY.
Update the debugfs output for phy_info and beacon_info
to include a "[PHY X]" label for better clarity.
The output of phy_info:
TP TX: 0 [0] Mbps (lv: 0), RX: 0 [0] Mbps (lv: 0)
Avg packet length: TX=0, RX=120
TF: 0
[PHY 0]
Beacon: 19 (-45 dBm)
RX count:
Legacy: [0, 0, 0, 0]
...
EHT 2SS: [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0]
The output of beacon_info:
[PHY 0]
Beacon: 20
raw rssi: 131
hw rate: 4
length: 437
[Beacon info]
interval: 100
dtim: 1
Signed-off-by: Kuan-Chung Chen <damon.chen@realtek.com>
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
Link: https://patch.msgid.link/20260429132625.1659182-3-pkshih@realtek.com
Stable-dep-of: 9bf6bd6ed5ac ("wifi: rtw89: 8852a: fix RSSI report when average beacon RSSI is not ready")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/realtek/rtw89/core.c | 26 ++++--
drivers/net/wireless/realtek/rtw89/core.h | 6 +-
drivers/net/wireless/realtek/rtw89/debug.c | 88 ++++++++++++-------
drivers/net/wireless/realtek/rtw89/fw.c | 6 +-
drivers/net/wireless/realtek/rtw89/phy.c | 17 ++--
drivers/net/wireless/realtek/rtw89/rtw8852a.c | 5 +-
6 files changed, 97 insertions(+), 51 deletions(-)
diff --git a/drivers/net/wireless/realtek/rtw89/core.c b/drivers/net/wireless/realtek/rtw89/core.c
index 2c37b94256f91..46c5de687dfc0 100644
--- a/drivers/net/wireless/realtek/rtw89/core.c
+++ b/drivers/net/wireless/realtek/rtw89/core.c
@@ -2499,12 +2499,14 @@ static u16 rtw89_bcn_get_histogram_bound(struct rtw89_dev *rtwdev, u8 target)
}
static u16 rtw89_bcn_get_rx_time(struct rtw89_dev *rtwdev,
- const struct rtw89_chan *chan)
+ struct rtw89_vif_link *rtwvif_link)
{
#define RTW89_SYMBOL_TIME_2GHZ 192
#define RTW89_SYMBOL_TIME_5GHZ 20
#define RTW89_SYMBOL_TIME_6GHZ 20
- struct rtw89_pkt_stat *pkt_stat = &rtwdev->phystat.cur_pkt_stat;
+ const struct rtw89_chan *chan = rtw89_chan_get(rtwdev, rtwvif_link->chanctx_idx);
+ struct rtw89_bb_ctx *bb = rtw89_get_bb_ctx(rtwdev, rtwvif_link->phy_idx);
+ struct rtw89_pkt_stat *pkt_stat = &bb->cur_pkt_stat;
u16 bitrate, val;
if (!rtw89_legacy_rate_to_bitrate(rtwdev, pkt_stat->beacon_rate, &bitrate))
@@ -2535,15 +2537,15 @@ static void rtw89_bcn_calc_timeout(struct rtw89_dev *rtwdev,
#define RTW89_BCN_TRACK_EXTEND_TIMEOUT 5
#define RTW89_BCN_TRACK_COVERAGE_TH 0 /* unit: TU */
#define RTW89_BCN_TRACK_STRONG_RSSI 80
- const struct rtw89_chan *chan = rtw89_chan_get(rtwdev, rtwvif_link->chanctx_idx);
- struct rtw89_pkt_stat *pkt_stat = &rtwdev->phystat.cur_pkt_stat;
+ struct rtw89_bb_ctx *bb = rtw89_get_bb_ctx(rtwdev, rtwvif_link->phy_idx);
struct rtw89_beacon_stat *bcn_stat = &rtwdev->phystat.bcn_stat;
struct rtw89_beacon_track_info *bcn_track = &rtwdev->bcn_track;
+ struct rtw89_pkt_stat *pkt_stat = &bb->cur_pkt_stat;
struct rtw89_beacon_dist *bcn_dist = &bcn_stat->bcn_dist;
u16 outlier_high_bcn_th = bcn_track->outlier_high_bcn_th;
u16 outlier_low_bcn_th = bcn_track->outlier_low_bcn_th;
- u8 rssi = ewma_rssi_read(&rtwdev->phystat.bcn_rssi);
u16 target_bcn_th = bcn_track->target_bcn_th;
+ u8 rssi = ewma_rssi_read(&bb->bcn_rssi);
u16 low_bcn_th = bcn_track->low_bcn_th;
u16 med_bcn_th = bcn_track->med_bcn_th;
u16 beacon_int = bcn_track->beacon_int;
@@ -2589,7 +2591,7 @@ static void rtw89_bcn_calc_timeout(struct rtw89_dev *rtwdev,
bcn_timeout = bcn_stat->drift[target_bcn_th];
out:
- bcn_track->bcn_timeout = bcn_timeout + rtw89_bcn_get_rx_time(rtwdev, chan);
+ bcn_track->bcn_timeout = bcn_timeout + rtw89_bcn_get_rx_time(rtwdev, rtwvif_link);
}
static void rtw89_bcn_update_timeout(struct rtw89_dev *rtwdev,
@@ -2733,7 +2735,6 @@ static void rtw89_vif_rx_stats_iter(void *data, u8 *mac,
struct rtw89_vif_rx_stats_iter_data *iter_data = data;
struct rtw89_dev *rtwdev = iter_data->rtwdev;
struct rtw89_vif *rtwvif = vif_to_rtwvif(vif);
- struct rtw89_pkt_stat *pkt_stat = &rtwdev->phystat.cur_pkt_stat;
struct rtw89_rx_desc_info *desc_info = iter_data->desc_info;
struct sk_buff *skb = iter_data->skb;
struct ieee80211_rx_status *rx_status = IEEE80211_SKB_RXCB(skb);
@@ -2743,6 +2744,8 @@ static void rtw89_vif_rx_stats_iter(void *data, u8 *mac,
struct ieee80211_bss_conf *bss_conf;
struct rtw89_vif_link *rtwvif_link;
const u8 *bssid = iter_data->bssid;
+ struct rtw89_pkt_stat *pkt_stat;
+ struct rtw89_bb_ctx *bb;
const u8 *target_bssid;
if (rtwdev->scanning &&
@@ -2776,6 +2779,9 @@ static void rtw89_vif_rx_stats_iter(void *data, u8 *mac,
rx_status->link_id = rtwvif_link->link_id;
}
+ bb = rtw89_get_bb_ctx(rtwdev, rtwvif_link->phy_idx);
+ pkt_stat = &bb->cur_pkt_stat;
+
if (ieee80211_is_beacon(hdr->frame_control)) {
if (vif->type == NL80211_IFTYPE_STATION &&
!test_bit(RTW89_FLAG_WOWLAN, rtwdev->flags)) {
@@ -2784,7 +2790,7 @@ static void rtw89_vif_rx_stats_iter(void *data, u8 *mac,
}
if (phy_ppdu) {
- ewma_rssi_add(&rtwdev->phystat.bcn_rssi, phy_ppdu->rssi_avg);
+ ewma_rssi_add(&bb->bcn_rssi, phy_ppdu->rssi_avg);
if (!test_bit(RTW89_FLAG_LOW_POWER_MODE, rtwdev->flags))
rtwvif_link->bcn_bw_idx = phy_ppdu->bw_idx;
}
@@ -4274,6 +4280,7 @@ static void rtw89_core_mlsr_link_decision(struct rtw89_dev *rtwdev,
struct rtw89_vif_link *rtwvif_link;
const struct rtw89_chan *chan;
unsigned long usable_links;
+ struct rtw89_bb_ctx *bb;
unsigned int link_id;
u8 rssi;
@@ -4283,7 +4290,8 @@ static void rtw89_core_mlsr_link_decision(struct rtw89_dev *rtwdev,
if (unlikely(!rtwvif_link))
goto select;
- rssi = ewma_rssi_read(&rtwdev->phystat.bcn_rssi);
+ bb = rtw89_get_bb_ctx(rtwdev, rtwvif_link->phy_idx);
+ rssi = ewma_rssi_read(&bb->bcn_rssi);
if (unlikely(!rssi))
return;
diff --git a/drivers/net/wireless/realtek/rtw89/core.h b/drivers/net/wireless/realtek/rtw89/core.h
index 3998a53b4ee90..4f2a9ac1ffd63 100644
--- a/drivers/net/wireless/realtek/rtw89/core.h
+++ b/drivers/net/wireless/realtek/rtw89/core.h
@@ -5136,9 +5136,6 @@ DECLARE_EWMA(thermal, 4, 4);
struct rtw89_phy_stat {
struct ewma_thermal avg_thermal[RF_PATH_MAX];
u8 last_thermal_max;
- struct ewma_rssi bcn_rssi;
- struct rtw89_pkt_stat cur_pkt_stat;
- struct rtw89_pkt_stat last_pkt_stat;
struct rtw89_beacon_stat bcn_stat;
};
@@ -6063,6 +6060,9 @@ struct rtw89_dev {
struct rtw89_dig_info dig;
struct rtw89_phy_ch_info ch_info;
struct rtw89_edcca_bak edcca_bak;
+ struct ewma_rssi bcn_rssi;
+ struct rtw89_pkt_stat cur_pkt_stat;
+ struct rtw89_pkt_stat last_pkt_stat;
} bbs[RTW89_PHY_NUM];
struct wiphy_delayed_work track_work;
diff --git a/drivers/net/wireless/realtek/rtw89/debug.c b/drivers/net/wireless/realtek/rtw89/debug.c
index 987eef8170f2b..531b8b90cb75e 100644
--- a/drivers/net/wireless/realtek/rtw89/debug.c
+++ b/drivers/net/wireless/realtek/rtw89/debug.c
@@ -3915,38 +3915,20 @@ static const struct rtw89_rx_rate_cnt_info {
{FIRST_RATE_GEV1(EHT_NSS2_MCS0), 14, 0, "EHT 2SS:"},
};
-static ssize_t rtw89_debug_priv_phy_info_get(struct rtw89_dev *rtwdev,
- struct rtw89_debugfs_priv *debugfs_priv,
- char *buf, size_t bufsz)
+static int rtw89_get_rx_pkt_stat(struct rtw89_dev *rtwdev, struct rtw89_bb_ctx *bb,
+ char *buf, size_t bufsz)
{
- struct rtw89_traffic_stats *stats = &rtwdev->stats;
- struct rtw89_pkt_stat *pkt_stat = &rtwdev->phystat.last_pkt_stat;
+ struct rtw89_pkt_stat *pkt_stat = &bb->last_pkt_stat;
const struct rtw89_chip_info *chip = rtwdev->chip;
- struct rtw89_debugfs_iter_data iter_data;
const struct rtw89_rx_rate_cnt_info *info;
- struct rtw89_hal *hal = &rtwdev->hal;
+ u8 rssi = ewma_rssi_read(&bb->bcn_rssi);
char *p = buf, *end = buf + bufsz;
enum rtw89_hw_rate first_rate;
- u8 rssi;
int i;
- rssi = ewma_rssi_read(&rtwdev->phystat.bcn_rssi);
-
- p += scnprintf(p, end - p, "TP TX: %u [%u] Mbps (lv: %d",
- stats->tx_throughput, stats->tx_throughput_raw,
- stats->tx_tfc_lv);
- if (hal->thermal_prot_lv)
- p += scnprintf(p, end - p, ", duty: %d%%",
- 100 - hal->thermal_prot_lv * RTW89_THERMAL_PROT_STEP);
- p += scnprintf(p, end - p, "), RX: %u [%u] Mbps (lv: %d)\n",
- stats->rx_throughput, stats->rx_throughput_raw,
- stats->rx_tfc_lv);
- p += scnprintf(p, end - p, "Beacon: %u (%d dBm), TF: %u\n",
+ p += scnprintf(p, end - p, "Beacon: %u (%d dBm)\n",
pkt_stat->beacon_nr,
- RTW89_RSSI_RAW_TO_DBM(rssi), stats->rx_tf_periodic);
- p += scnprintf(p, end - p, "Avg packet length: TX=%u, RX=%u\n",
- stats->tx_avg_len,
- stats->rx_avg_len);
+ RTW89_RSSI_RAW_TO_DBM(rssi));
p += scnprintf(p, end - p, "RX count:\n");
@@ -3967,6 +3949,39 @@ static ssize_t rtw89_debug_priv_phy_info_get(struct rtw89_dev *rtwdev,
p += scnprintf(p, end - p, "]\n");
}
+ return p - buf;
+}
+
+static ssize_t rtw89_debug_priv_phy_info_get(struct rtw89_dev *rtwdev,
+ struct rtw89_debugfs_priv *debugfs_priv,
+ char *buf, size_t bufsz)
+{
+ struct rtw89_traffic_stats *stats = &rtwdev->stats;
+ struct rtw89_debugfs_iter_data iter_data;
+ struct rtw89_hal *hal = &rtwdev->hal;
+ char *p = buf, *end = buf + bufsz;
+ struct rtw89_bb_ctx *bb;
+
+ p += scnprintf(p, end - p, "TP TX: %u [%u] Mbps (lv: %d",
+ stats->tx_throughput, stats->tx_throughput_raw,
+ stats->tx_tfc_lv);
+ if (hal->thermal_prot_lv)
+ p += scnprintf(p, end - p, ", duty: %d%%",
+ 100 - hal->thermal_prot_lv * RTW89_THERMAL_PROT_STEP);
+ p += scnprintf(p, end - p, "), RX: %u [%u] Mbps (lv: %d)\n",
+ stats->rx_throughput, stats->rx_throughput_raw,
+ stats->rx_tfc_lv);
+ p += scnprintf(p, end - p, "Avg packet length: TX=%u, RX=%u\n",
+ stats->tx_avg_len,
+ stats->rx_avg_len);
+ p += scnprintf(p, end - p, "TF: %u\n", stats->rx_tf_periodic);
+
+ rtw89_for_each_active_bb(rtwdev, bb) {
+ p += scnprintf(p, end - p, "\n[PHY %u]\n", bb->phy_idx);
+ p += rtw89_get_rx_pkt_stat(rtwdev, bb, p, end - p);
+ }
+ p += scnprintf(p, end - p, "\n");
+
rtw89_debugfs_iter_data_setup(&iter_data, p, end - p);
ieee80211_iterate_stations_atomic(rtwdev->hw, rtw89_sta_info_get_iter, &iter_data);
p += iter_data.written_sz;
@@ -4658,12 +4673,26 @@ rtw89_debug_priv_diag_mac_get(struct rtw89_dev *rtwdev,
return rtw89_mac_diag_iter_all(rtwdev, buf, bufsz);
}
+static int rtw89_get_beacon_info(struct rtw89_dev *rtwdev, struct rtw89_bb_ctx *bb,
+ char *buf, size_t bufsz)
+{
+ struct rtw89_pkt_stat *pkt_stat = &bb->last_pkt_stat;
+ char *p = buf, *end = buf + bufsz;
+
+ p += scnprintf(p, end - p, "[PHY %u]\n", bb->phy_idx);
+ p += scnprintf(p, end - p, "Beacon: %u\n", pkt_stat->beacon_nr);
+ p += scnprintf(p, end - p, "raw rssi: %lu\n", ewma_rssi_read(&bb->bcn_rssi));
+ p += scnprintf(p, end - p, "hw rate: %u\n", pkt_stat->beacon_rate);
+ p += scnprintf(p, end - p, "length: %u\n\n", pkt_stat->beacon_len);
+
+ return p - buf;
+}
+
static ssize_t
rtw89_debug_priv_beacon_info_get(struct rtw89_dev *rtwdev,
struct rtw89_debugfs_priv *debugfs_priv,
char *buf, size_t bufsz)
{
- struct rtw89_pkt_stat *pkt_stat = &rtwdev->phystat.last_pkt_stat;
struct rtw89_beacon_track_info *bcn_track = &rtwdev->bcn_track;
struct rtw89_beacon_stat *bcn_stat = &rtwdev->phystat.bcn_stat;
struct rtw89_beacon_dist *bcn_dist = &bcn_stat->bcn_dist;
@@ -4671,17 +4700,16 @@ rtw89_debug_priv_beacon_info_get(struct rtw89_dev *rtwdev,
char *p = buf, *end = buf + bufsz;
u16 *drift = bcn_stat->drift;
u8 bcn_num = bcn_stat->num;
+ struct rtw89_bb_ctx *bb;
u8 count;
u8 i;
+ rtw89_for_each_active_bb(rtwdev, bb)
+ p += rtw89_get_beacon_info(rtwdev, bb, p, end - p);
+
p += scnprintf(p, end - p, "[Beacon info]\n");
- p += scnprintf(p, end - p, "count: %u\n", pkt_stat->beacon_nr);
p += scnprintf(p, end - p, "interval: %u\n", bcn_track->beacon_int);
p += scnprintf(p, end - p, "dtim: %u\n", bcn_track->dtim);
- p += scnprintf(p, end - p, "raw rssi: %lu\n",
- ewma_rssi_read(&rtwdev->phystat.bcn_rssi));
- p += scnprintf(p, end - p, "hw rate: %u\n", pkt_stat->beacon_rate);
- p += scnprintf(p, end - p, "length: %u\n", pkt_stat->beacon_len);
p += scnprintf(p, end - p, "\n[Distribution]\n");
p += scnprintf(p, end - p, "tbtt\n");
diff --git a/drivers/net/wireless/realtek/rtw89/fw.c b/drivers/net/wireless/realtek/rtw89/fw.c
index 4191fbbc2161c..c6533a085c7fe 100644
--- a/drivers/net/wireless/realtek/rtw89/fw.c
+++ b/drivers/net/wireless/realtek/rtw89/fw.c
@@ -3008,14 +3008,15 @@ int rtw89_fw_h2c_lps_ml_cmn_info(struct rtw89_dev *rtwdev,
struct rtw89_vif *rtwvif)
{
const struct rtw89_phy_bb_gain_info_be *gain = &rtwdev->bb_gain.be;
- struct rtw89_pkt_stat *pkt_stat = &rtwdev->phystat.cur_pkt_stat;
static const u8 bcn_bw_ofst[] = {0, 0, 0, 3, 6, 9, 0, 12};
const struct rtw89_chip_info *chip = rtwdev->chip;
struct rtw89_efuse *efuse = &rtwdev->efuse;
struct rtw89_h2c_lps_ml_cmn_info *h2c;
struct rtw89_vif_link *rtwvif_link;
+ struct rtw89_pkt_stat *pkt_stat;
const struct rtw89_chan *chan;
u8 bw_idx = RTW89_BB_BW_20_40;
+ struct rtw89_bb_ctx *bb;
u32 len = sizeof(*h2c);
unsigned int link_id;
struct sk_buff *skb;
@@ -3046,11 +3047,14 @@ int rtw89_fw_h2c_lps_ml_cmn_info(struct rtw89_dev *rtwdev,
path = rtwvif_link->phy_idx == RTW89_PHY_1 ? RF_PATH_B : RF_PATH_A;
chan = rtw89_chan_get(rtwdev, rtwvif_link->chanctx_idx);
gain_band = rtw89_subband_to_gain_band_be(chan->subband_type);
+ bb = rtw89_get_bb_ctx(rtwdev, rtwvif_link->phy_idx);
h2c->central_ch[rtwvif_link->phy_idx] = chan->channel;
h2c->pri_ch[rtwvif_link->phy_idx] = chan->primary_channel;
h2c->band[rtwvif_link->phy_idx] = chan->band_type;
h2c->bw[rtwvif_link->phy_idx] = chan->band_width;
+
+ pkt_stat = &bb->cur_pkt_stat;
if (pkt_stat->beacon_rate < RTW89_HW_RATE_OFDM6)
h2c->bcn_rate_type[rtwvif_link->phy_idx] = 0x1;
else
diff --git a/drivers/net/wireless/realtek/rtw89/phy.c b/drivers/net/wireless/realtek/rtw89/phy.c
index 36dee482bc34b..4424dae1c7aa1 100644
--- a/drivers/net/wireless/realtek/rtw89/phy.c
+++ b/drivers/net/wireless/realtek/rtw89/phy.c
@@ -5392,6 +5392,7 @@ static void rtw89_phy_stat_rssi_update(struct rtw89_dev *rtwdev)
static void rtw89_phy_stat_init(struct rtw89_dev *rtwdev)
{
struct rtw89_phy_stat *phystat = &rtwdev->phystat;
+ struct rtw89_bb_ctx *bb;
int i;
for (i = 0; i < rtwdev->chip->rf_path_num; i++)
@@ -5399,24 +5400,28 @@ static void rtw89_phy_stat_init(struct rtw89_dev *rtwdev)
rtw89_phy_stat_thermal_update(rtwdev);
- memset(&phystat->cur_pkt_stat, 0, sizeof(phystat->cur_pkt_stat));
- memset(&phystat->last_pkt_stat, 0, sizeof(phystat->last_pkt_stat));
+ rtw89_for_each_capab_bb(rtwdev, bb) {
+ memset(&bb->cur_pkt_stat, 0, sizeof(bb->cur_pkt_stat));
+ memset(&bb->last_pkt_stat, 0, sizeof(bb->last_pkt_stat));
- ewma_rssi_init(&phystat->bcn_rssi);
+ ewma_rssi_init(&bb->bcn_rssi);
+ }
rtwdev->hal.thermal_prot_lv = 0;
}
void rtw89_phy_stat_track(struct rtw89_dev *rtwdev)
{
- struct rtw89_phy_stat *phystat = &rtwdev->phystat;
+ struct rtw89_bb_ctx *bb;
rtw89_phy_stat_thermal_update(rtwdev);
rtw89_phy_thermal_protect(rtwdev);
rtw89_phy_stat_rssi_update(rtwdev);
- phystat->last_pkt_stat = phystat->cur_pkt_stat;
- memset(&phystat->cur_pkt_stat, 0, sizeof(phystat->cur_pkt_stat));
+ rtw89_for_each_active_bb(rtwdev, bb) {
+ bb->last_pkt_stat = bb->cur_pkt_stat;
+ memset(&bb->cur_pkt_stat, 0, sizeof(bb->cur_pkt_stat));
+ }
}
static u16 rtw89_phy_ccx_us_to_idx(struct rtw89_dev *rtwdev,
diff --git a/drivers/net/wireless/realtek/rtw89/rtw8852a.c b/drivers/net/wireless/realtek/rtw89/rtw8852a.c
index 232f4c1bee1ba..a8b604adadddf 100644
--- a/drivers/net/wireless/realtek/rtw89/rtw8852a.c
+++ b/drivers/net/wireless/realtek/rtw89/rtw8852a.c
@@ -2107,13 +2107,14 @@ static void rtw8852a_query_ppdu(struct rtw89_dev *rtwdev,
struct rtw89_rx_phy_ppdu *phy_ppdu,
struct ieee80211_rx_status *status)
{
- u8 path;
+ struct rtw89_bb_ctx *bb = rtw89_get_bb_ctx(rtwdev, phy_ppdu->phy_idx);
u8 *rx_power = phy_ppdu->rssi;
+ u8 path;
u8 raw;
if (!status->signal) {
if (phy_ppdu->to_self)
- raw = ewma_rssi_read(&rtwdev->phystat.bcn_rssi);
+ raw = ewma_rssi_read(&bb->bcn_rssi);
else
raw = max(rx_power[RF_PATH_A], rx_power[RF_PATH_B]);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0338/1518] wifi: rtw89: 8852a: fix RSSI report when average beacon RSSI is not ready
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (336 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0337/1518] wifi: rtw89: phy: support per PHY RX statistics Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0339/1518] iio: accel: dmard09: Implement IIO_CHAN_INFO_SCALE Greg Kroah-Hartman
` (660 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chih-Kang Chang, Ping-Ke Shih,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chih-Kang Chang <gary.chang@realtek.com>
[ Upstream commit 9bf6bd6ed5accb57544d04ded911a2ef1642d48f ]
8852A uses the average beacon RSSI to smooth the RSSI. However, before
the average beacon RSSI is available, the RSSI should use the PPDU
status RSSI of the received packet to avoid reporting the RSSI as -110 dBm.
Fixes: f0f3bf4b370c ("wifi: rtw89: 8852a: report average RSSI to avoid unnecessary scanning")
Signed-off-by: Chih-Kang Chang <gary.chang@realtek.com>
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
Link: https://patch.msgid.link/20260707091056.42771-13-pkshih@realtek.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/realtek/rtw89/rtw8852a.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/realtek/rtw89/rtw8852a.c b/drivers/net/wireless/realtek/rtw89/rtw8852a.c
index a8b604adadddf..3defb38223e8b 100644
--- a/drivers/net/wireless/realtek/rtw89/rtw8852a.c
+++ b/drivers/net/wireless/realtek/rtw89/rtw8852a.c
@@ -2113,7 +2113,7 @@ static void rtw8852a_query_ppdu(struct rtw89_dev *rtwdev,
u8 raw;
if (!status->signal) {
- if (phy_ppdu->to_self)
+ if (phy_ppdu->to_self && ewma_rssi_read(&bb->bcn_rssi))
raw = ewma_rssi_read(&bb->bcn_rssi);
else
raw = max(rx_power[RF_PATH_A], rx_power[RF_PATH_B]);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0339/1518] iio: accel: dmard09: Implement IIO_CHAN_INFO_SCALE
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (337 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0338/1518] wifi: rtw89: 8852a: fix RSSI report when average beacon RSSI is not ready Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0340/1518] RDMA/core: Wait for RCU callbacks before unloading ib_core Greg Kroah-Hartman
` (659 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mert Seftali, Joshua Crofts,
Jonathan Cameron, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mert Seftali <mertsftl@gmail.com>
[ Upstream commit aa58ecc73466d0cb8c418de98e2225490bf600e3 ]
Reading the in_accel_scale attribute on the DMARD09 has always returned
-EINVAL: the channels advertise scale via info_mask_shared_by_type so the
IIO core exposes the attribute, but dmard09_read_raw() only handles
IIO_CHAN_INFO_RAW, so a SCALE read falls through to 'default: return
-EINVAL':
$ cat .../iio:deviceX/in_accel_scale
cat: in_accel_scale: Invalid argument
leaving userspace with raw counts it cannot convert to m/s^2.
The driver was written from a vendor source [1] without a datasheet, and
the scale was declared but never implemented. The vendor source carries
the sensitivity: its conversion is
acc = raw * GRAVITY_EARTH_1000 / sensitivity (then / 1000 -> m/s^2)
with sensitivity = 32 and GRAVITY_EARTH_1000 = 9807 ("about
(9.80665)*1000"), i.e. 32 counts correspond to 1 g.
That sensitivity applies to the value this driver already reports as raw:
the vendor reduces each 16-bit sample to a signed 9-bit value, and the
preparation in dmard09_read_raw() yields the same value. It is
self-consistent: 256 counts / 32 = 8 g full scale, matching the +/-8g
range.
Implement the scale derived from that sensitivity using standard gravity:
scale = 9.80665 / 32 = 0.3064578125 m/s^2 per LSB
Link: https://github.com/minstrelsy/mediatek/blob/1f49d8c87b839651bc89afc870277e8e0f2e2d55/custom/common/kernel/accelerometer/dmard09/dmard09.c [1]
Fixes: a4fa6509dda4 ("iio: accel: add support for the Domintech DMARD09 3-axis accelerometer")
Signed-off-by: Mert Seftali <mertsftl@gmail.com>
Reviewed-by: Joshua Crofts <joshua.crofts1@gmail.com>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/iio/accel/dmard09.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/drivers/iio/accel/dmard09.c b/drivers/iio/accel/dmard09.c
index d9290e3b9c464..5297ab2ee0bbe 100644
--- a/drivers/iio/accel/dmard09.c
+++ b/drivers/iio/accel/dmard09.c
@@ -8,6 +8,7 @@
#include <linux/unaligned.h>
#include <linux/module.h>
#include <linux/i2c.h>
+#include <linux/units.h>
#include <linux/iio/iio.h>
#define DMARD09_DRV_NAME "dmard09"
@@ -79,6 +80,12 @@ static int dmard09_read_raw(struct iio_dev *indio_dev,
*val = accel;
return IIO_VAL_INT;
+ case IIO_CHAN_INFO_SCALE:
+ *val = 0;
+ /* 1 g / 32 LSB, in m/s^2 */
+ *val2 = IIO_G_TO_M_S_2(NANO / 32);
+
+ return IIO_VAL_INT_PLUS_NANO;
default:
return -EINVAL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0340/1518] RDMA/core: Wait for RCU callbacks before unloading ib_core
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (338 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0339/1518] iio: accel: dmard09: Implement IIO_CHAN_INFO_SCALE Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0341/1518] RDMA/mlx5: Drain RCU callbacks during module teardown Greg Kroah-Hartman
` (658 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sebastian Andrzej Siewior,
Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leon Romanovsky <leonro@nvidia.com>
[ Upstream commit 7d75592114d1664623c8cf191a12b38052c04483 ]
put_gid_ndev() is queued with call_rcu() and implemented in ib_core.
Stopping the workqueues does not drain callbacks already queued, so RCU
could invoke it after the module code has been unloaded.
synchronize_rcu() does not wait for callbacks. Wait for them after all
producers have stopped.
Fixes: 943bd984b108 ("RDMA/core: Allow detaching gid attribute netdevice for RoCE")
Reported-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Closes: https://lore.kernel.org/linux-rdma/20260708092316.Qb39F_B0@linutronix.de/
Link: https://patch.msgid.link/20260709-unload-rcu-v1-1-fccd27211e5a@nvidia.com
Acked-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/core/device.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/infiniband/core/device.c b/drivers/infiniband/core/device.c
index ac9aaef1e5e61..404fc1edbe60b 100644
--- a/drivers/infiniband/core/device.c
+++ b/drivers/infiniband/core/device.c
@@ -3169,6 +3169,7 @@ static void __exit ib_core_cleanup(void)
/* Make sure that any pending umem accounting work is done. */
destroy_workqueue(ib_wq);
destroy_workqueue(ib_unreg_wq);
+ rcu_barrier();
WARN_ON(!xa_empty(&clients));
WARN_ON(!xa_empty(&devices));
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0341/1518] RDMA/mlx5: Drain RCU callbacks during module teardown
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (339 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0340/1518] RDMA/core: Wait for RCU callbacks before unloading ib_core Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0342/1518] RDMA/ipoib: " Greg Kroah-Hartman
` (657 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sebastian Andrzej Siewior,
Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leon Romanovsky <leonro@nvidia.com>
[ Upstream commit e37cdd75f8d61c1123d324ae5667ac3da562290e ]
devx_free_subscription() can remain queued after the last DevX event file
drops its module reference or an auxiliary driver detaches its devices.
mlx5_ib can then unload before the callback runs.
Registration error unwind has the same risk because driver registration
can attach existing devices before failing. Wait after all drivers have
stopped.
Fixes: 6898d1c661d7 ("RDMA/mlx5: Use RCU and direct refcounts to keep memory alive")
Reported-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Closes: https://lore.kernel.org/linux-rdma/20260708092316.Qb39F_B0@linutronix.de/
Link: https://patch.msgid.link/20260709-unload-rcu-v1-2-fccd27211e5a@nvidia.com
Acked-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/mlx5/main.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/infiniband/hw/mlx5/main.c b/drivers/infiniband/hw/mlx5/main.c
index 09709ae5bd471..433461ab6c75d 100644
--- a/drivers/infiniband/hw/mlx5/main.c
+++ b/drivers/infiniband/hw/mlx5/main.c
@@ -5225,6 +5225,7 @@ static int __init mlx5_ib_init(void)
dd_err:
mlx5r_rep_cleanup();
rep_err:
+ rcu_barrier();
mlx5_ib_qp_event_cleanup();
qp_event_err:
destroy_workqueue(mlx5_ib_event_wq);
@@ -5238,6 +5239,7 @@ static void __exit mlx5_ib_cleanup(void)
auxiliary_driver_unregister(&mlx5r_driver);
auxiliary_driver_unregister(&mlx5r_mp_driver);
mlx5r_rep_cleanup();
+ rcu_barrier();
mlx5_ib_qp_event_cleanup();
destroy_workqueue(mlx5_ib_event_wq);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0342/1518] RDMA/ipoib: Drain RCU callbacks during module teardown
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (340 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0341/1518] RDMA/mlx5: Drain RCU callbacks during module teardown Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0343/1518] RDMA/rxe: Avoid reprocessing the current packet after the QP enters the error state Greg Kroah-Hartman
` (656 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sebastian Andrzej Siewior,
Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leon Romanovsky <leonro@nvidia.com>
[ Upstream commit 31b7c700670830a0e8a4cdcd451c88a13cc5dc48 ]
IPoIB reclamation completions can be signaled from inside an RCU callback.
Teardown can wake before the callback returns and unload ib_ipoib while its
code is still executing.
Client registration failure can also remove already-added devices and queue
callbacks. Wait after client and workqueue teardown.
Fixes: b63b70d87741 ("IPoIB: Use a private hash table for path lookup in xmit path")
Reported-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Closes: https://lore.kernel.org/linux-rdma/20260708092316.Qb39F_B0@linutronix.de/
Link: https://patch.msgid.link/20260709-unload-rcu-v1-3-fccd27211e5a@nvidia.com
Acked-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/ulp/ipoib/ipoib_main.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/infiniband/ulp/ipoib/ipoib_main.c b/drivers/infiniband/ulp/ipoib/ipoib_main.c
index 5b4d76e97437d..b897c1c3e4c8d 100644
--- a/drivers/infiniband/ulp/ipoib/ipoib_main.c
+++ b/drivers/infiniband/ulp/ipoib/ipoib_main.c
@@ -2755,6 +2755,7 @@ static int __init ipoib_init_module(void)
err_sa:
ib_sa_unregister_client(&ipoib_sa_client);
destroy_workqueue(ipoib_workqueue);
+ rcu_barrier();
err_fs:
ipoib_unregister_debugfs();
@@ -2772,6 +2773,7 @@ static void __exit ipoib_cleanup_module(void)
ib_sa_unregister_client(&ipoib_sa_client);
ipoib_unregister_debugfs();
destroy_workqueue(ipoib_workqueue);
+ rcu_barrier();
}
module_init(ipoib_init_module);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0343/1518] RDMA/rxe: Avoid reprocessing the current packet after the QP enters the error state
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (341 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0342/1518] RDMA/ipoib: " Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0344/1518] drm/msm/dp: add missing drm_edid_connector_update() before add_modes on cached EDID Greg Kroah-Hartman
` (655 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Allison Henderson, Zhu Yanjun,
Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Allison Henderson <achender@kernel.org>
[ Upstream commit 15ae32c4a3551c4c9da457370bdfdd65d171e512 ]
When do_complete() finds the QP in the error state it returns
RESPST_CHK_RESOURCE. Before commit 49dc9c1f0c7e ("RDMA/rxe: Cleanup
reset state handling in rxe_resp.c") this was the flush loop:
check_resource() had an error-state branch that fetched each remaining
recv WQE and completed it with IB_WC_WR_FLUSH_ERR, without touching
the current packet. That commit removed the error-state branch from
check_resource() (draining is now done at rxe_receiver() entry) but
kept the do_complete() error-state return.
As a result, when a QP moves to the error state while a packet is
being completed - e.g. an rdma_cm disconnect racing with receive
processing - the responder state machine loops back into the request
processing chain with the already-completed packet still in hand:
check_resource() fetches a fresh recv WQE, execute()/send_data_in()
copies the same packet payload again, do_complete() posts another
IB_WC_SUCCESS CQE (qp->resp.status is still 0), and control returns
to the error-state check. The loop re-executes the same packet once
per posted recv WQE (observed: ~1000 duplicate IB_WC_SUCCESS
completions of one SEND, one per ~8us, matching the RQ occupancy)
until the RQ is exhausted, after which qp->resp.wqe is NULL and
send_data_in() dereferences it:
BUG: kernel NULL pointer dereference, address: 0000000000000014
Workqueue: rxe_wq do_work
RIP: copy_data+0x29/0x1f0
Call Trace:
send_data_in+0x25/0x50
rxe_receiver+0xf36/0x1dd0
The duplicate completions are indistinguishable from real receives to
the ULP. During an rds stress test, the message was accepted as new and
delivered the same datagram to user space hundreds of times, corrupting
the stream; any ULP that relies on RC exactly-once delivery is affected.
A live packet reaching the error-state check in do_complete() has
been executed and completed exactly once and must be consumed, not
re-processed. Return RESPST_CLEANUP for it (dequeue and free); keep
returning RESPST_CHK_RESOURCE for the pkt == NULL case.
Fixes: 49dc9c1f0c7e ("RDMA/rxe: Cleanup reset state handling in rxe_resp.c")
Assisted-by: Claude-Code:claude-fable-5
Signed-off-by: Allison Henderson <achender@kernel.org>
Link: https://patch.msgid.link/20260711165419.13486-1-achender@kernel.org
Reviewed-by: Zhu Yanjun <yanjun.zhu@linux.dev>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/sw/rxe/rxe_resp.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/drivers/infiniband/sw/rxe/rxe_resp.c b/drivers/infiniband/sw/rxe/rxe_resp.c
index 995805e16d78b..6aabf1d07ea34 100644
--- a/drivers/infiniband/sw/rxe/rxe_resp.c
+++ b/drivers/infiniband/sw/rxe/rxe_resp.c
@@ -1203,7 +1203,14 @@ static enum resp_states do_complete(struct rxe_qp *qp,
spin_lock_irqsave(&qp->state_lock, flags);
if (unlikely(qp_state(qp) == IB_QPS_ERR)) {
spin_unlock_irqrestore(&qp->state_lock, flags);
- return RESPST_CHK_RESOURCE;
+ /* The packet was executed and completed before the QP
+ * moved to ERROR; it must be consumed exactly once.
+ * Re-entering the request chain with the stale packet
+ * would copy it into every remaining recv WQE as a new
+ * completion. Remaining WQEs are flushed by the drain
+ * path at rxe_receiver() entry.
+ */
+ return pkt ? RESPST_CLEANUP : RESPST_CHK_RESOURCE;
}
spin_unlock_irqrestore(&qp->state_lock, flags);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0344/1518] drm/msm/dp: add missing drm_edid_connector_update() before add_modes on cached EDID
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (342 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0343/1518] RDMA/rxe: Avoid reprocessing the current packet after the QP enters the error state Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0345/1518] Revert "drm/msm: dsi: fix PLL init in bonded mode" Greg Kroah-Hartman
` (654 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dmitry Baryshkov, Jens Glathe,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jens Glathe <jens.glathe@oldschoolsolutions.biz>
[ Upstream commit b7088d58dccfba87fe8dd2ab7c493ee1d9d09277 ]
After the refactor to struct drm_edid, the fast path in
msm_dp_panel_get_modes() that already held a cached EDID called
drm_edid_connector_add_modes() directly without first calling
drm_edid_connector_update().
The new API requires the update step to associate the EDID with the
connector. Add the missing call. This restores correct behaviour for
the cached-EDID path.
Fixes: 5bea90ad9743 ("drm/msm/dp: switch to struct drm_edid")
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Jens Glathe <jens.glathe@oldschoolsolutions.biz>
Patchwork: https://patchwork.freedesktop.org/patch/731125/
Link: https://lore.kernel.org/r/20260608-drm_plug_flaky_edid-v3-1-1ca632938e7f@oldschoolsolutions.biz
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/dp/dp_panel.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/msm/dp/dp_panel.c b/drivers/gpu/drm/msm/dp/dp_panel.c
index 15b7f6c7146e1..9191f0fc3d81a 100644
--- a/drivers/gpu/drm/msm/dp/dp_panel.c
+++ b/drivers/gpu/drm/msm/dp/dp_panel.c
@@ -254,8 +254,10 @@ int msm_dp_panel_get_modes(struct msm_dp_panel *msm_dp_panel,
return -EINVAL;
}
- if (msm_dp_panel->drm_edid)
+ if (msm_dp_panel->drm_edid) {
+ drm_edid_connector_update(connector, msm_dp_panel->drm_edid);
return drm_edid_connector_add_modes(connector);
+ }
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0345/1518] Revert "drm/msm: dsi: fix PLL init in bonded mode"
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (343 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0344/1518] drm/msm/dp: add missing drm_edid_connector_update() before add_modes on cached EDID Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0346/1518] crypto: ccp - Fix memory leak in SEV INIT_EX path Greg Kroah-Hartman
` (653 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mohit Dsor, Neil Armstrong,
Thorsten Leemhuis, Dmitry Baryshkov, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
[ Upstream commit 44784327815b2a1ad8bb56b9236770cb538c7c27 ]
Commit 93c97bc8d85d ("drm/msm: dsi: fix PLL init in bonded mode") fixed
one of the issues with the DSI bonded mode, but broke non-bonded usecase
for DSI as reported by Mohit Dsor. Clock divider is being programmed
incorrectly, resultin in the wrong display mode being selected. Revert
the offending commit, letting Neil to work on a better fix.
Fixes: 93c97bc8d85d ("drm/msm: dsi: fix PLL init in bonded mode")
Reported-by: Mohit Dsor <mohit.dsor@oss.qualcomm.com>
Closes: https://lore.kernel.org/r/ae07cef84AmXK43H@hu-mdsor-hyd.qualcomm.com
Cc: Neil Armstrong <neil.armstrong@linaro.org>
Cc: Thorsten Leemhuis <regressions@leemhuis.info>
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/739459/
Link: https://lore.kernel.org/r/20260712-msm-revert-dsi-pll-fix-v1-1-40122689ea25@oss.qualcomm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/dsi/phy/dsi_phy.h | 1 +
drivers/gpu/drm/msm/dsi/phy/dsi_phy_7nm.c | 18 ++++++++++++++++--
2 files changed, 17 insertions(+), 2 deletions(-)
diff --git a/drivers/gpu/drm/msm/dsi/phy/dsi_phy.h b/drivers/gpu/drm/msm/dsi/phy/dsi_phy.h
index 3cbf082314924..e391505fdaf04 100644
--- a/drivers/gpu/drm/msm/dsi/phy/dsi_phy.h
+++ b/drivers/gpu/drm/msm/dsi/phy/dsi_phy.h
@@ -109,6 +109,7 @@ struct msm_dsi_phy {
struct msm_dsi_dphy_timing timing;
const struct msm_dsi_phy_cfg *cfg;
void *tuning_cfg;
+ void *pll_data;
enum msm_dsi_phy_usecase usecase;
bool regulator_ldo_mode;
diff --git a/drivers/gpu/drm/msm/dsi/phy/dsi_phy_7nm.c b/drivers/gpu/drm/msm/dsi/phy/dsi_phy_7nm.c
index c5e1d2016bcca..32f06edd21a9f 100644
--- a/drivers/gpu/drm/msm/dsi/phy/dsi_phy_7nm.c
+++ b/drivers/gpu/drm/msm/dsi/phy/dsi_phy_7nm.c
@@ -426,8 +426,11 @@ static void dsi_pll_enable_pll_bias(struct dsi_pll_7nm *pll)
u32 data;
spin_lock_irqsave(&pll->pll_enable_lock, flags);
- pll->pll_enable_cnt++;
- WARN_ON(pll->pll_enable_cnt == INT_MAX);
+ if (pll->pll_enable_cnt++) {
+ spin_unlock_irqrestore(&pll->pll_enable_lock, flags);
+ WARN_ON(pll->pll_enable_cnt == INT_MAX);
+ return;
+ }
data = readl(pll->phy->base + REG_DSI_7nm_PHY_CMN_CTRL_0);
data |= DSI_7nm_PHY_CMN_CTRL_0_PLL_SHUTDOWNB;
@@ -873,6 +876,7 @@ static int dsi_pll_7nm_init(struct msm_dsi_phy *phy)
spin_lock_init(&pll_7nm->pll_enable_lock);
pll_7nm->phy = phy;
+ phy->pll_data = pll_7nm;
ret = pll_7nm_register(pll_7nm, phy->provided_clocks->hws);
if (ret) {
@@ -961,8 +965,10 @@ static int dsi_7nm_phy_enable(struct msm_dsi_phy *phy,
u32 const delay_us = 5;
u32 const timeout_us = 1000;
struct msm_dsi_dphy_timing *timing = &phy->timing;
+ struct dsi_pll_7nm *pll = phy->pll_data;
void __iomem *base = phy->base;
bool less_than_1500_mhz;
+ unsigned long flags;
u32 vreg_ctrl_0, vreg_ctrl_1, lane_ctrl0;
u32 glbl_pemph_ctrl_0;
u32 glbl_str_swi_cal_sel_ctrl, glbl_hstx_str_ctrl_0;
@@ -1084,10 +1090,13 @@ static int dsi_7nm_phy_enable(struct msm_dsi_phy *phy,
glbl_rescode_bot_ctrl = 0x3c;
}
+ spin_lock_irqsave(&pll->pll_enable_lock, flags);
+ pll->pll_enable_cnt = 1;
/* de-assert digital and pll power down */
data = DSI_7nm_PHY_CMN_CTRL_0_DIGTOP_PWRDN_B |
DSI_7nm_PHY_CMN_CTRL_0_PLL_SHUTDOWNB;
writel(data, base + REG_DSI_7nm_PHY_CMN_CTRL_0);
+ spin_unlock_irqrestore(&pll->pll_enable_lock, flags);
/* Assert PLL core reset */
writel(0x00, base + REG_DSI_7nm_PHY_CMN_PLL_CNTRL);
@@ -1200,7 +1209,9 @@ static bool dsi_7nm_set_continuous_clock(struct msm_dsi_phy *phy, bool enable)
static void dsi_7nm_phy_disable(struct msm_dsi_phy *phy)
{
+ struct dsi_pll_7nm *pll = phy->pll_data;
void __iomem *base = phy->base;
+ unsigned long flags;
u32 data;
DBG("");
@@ -1227,8 +1238,11 @@ static void dsi_7nm_phy_disable(struct msm_dsi_phy *phy)
writel(data, base + REG_DSI_7nm_PHY_CMN_CTRL_0);
writel(0, base + REG_DSI_7nm_PHY_CMN_LANE_CTRL0);
+ spin_lock_irqsave(&pll->pll_enable_lock, flags);
+ pll->pll_enable_cnt = 0;
/* Turn off all PHY blocks */
writel(0x00, base + REG_DSI_7nm_PHY_CMN_CTRL_0);
+ spin_unlock_irqrestore(&pll->pll_enable_lock, flags);
/* make sure phy is turned off */
wmb();
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0346/1518] crypto: ccp - Fix memory leak in SEV INIT_EX path
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (344 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0345/1518] Revert "drm/msm: dsi: fix PLL init in bonded mode" Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0347/1518] hwrng: ks-sa - Fix runtime PM cleanup on registration failure Greg Kroah-Hartman
` (652 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Tom Lendacky, Atish Patra,
Herbert Xu, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Atish Patra <atishp@meta.com>
[ Upstream commit c8e53ada20d352b0f1bdc3e58405a9edab897a2e ]
allocated pages in _init_ext_path are never freed and sev_init_ex_buffer
is left pointing at the leaked memory in case of any failures during the
function..
Fix by adding an error path that frees the pages and clears
sev_init_ex_buffer. Make sure we only free the memory if the failure
happens before the conversion. Otherwise, we may end up trying to free
up converted pages in case of reclaim failure. rmp_mark_pages_firmware
failures should be rare enough to avoid more code complexity to track
down which pages were reclaimed/leaked vs which are not.
Fixes: 7364a6fbca45 ("crypto: ccp: Handle non-volatile INIT_EX data when SNP is enabled")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Reviewed-by: Tom Lendacky <thomas.lendacky@amd.com>
Signed-off-by: Atish Patra <atishp@meta.com>
Acked-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/crypto/ccp/sev-dev.c | 17 ++++++++++++++---
1 file changed, 14 insertions(+), 3 deletions(-)
diff --git a/drivers/crypto/ccp/sev-dev.c b/drivers/crypto/ccp/sev-dev.c
index 4eaad21fd8481..5aa0f158c43b8 100644
--- a/drivers/crypto/ccp/sev-dev.c
+++ b/drivers/crypto/ccp/sev-dev.c
@@ -1514,7 +1514,7 @@ static int __sev_platform_init_handle_init_ex_path(struct sev_device *sev)
if (sev_init_ex_buffer)
return 0;
- page = alloc_pages(GFP_KERNEL, get_order(NV_LENGTH));
+ page = alloc_pages(GFP_KERNEL | __GFP_ZERO, get_order(NV_LENGTH));
if (!page) {
dev_err(sev->dev, "SEV: INIT_EX NV memory allocation failed\n");
return -ENOMEM;
@@ -1524,7 +1524,7 @@ static int __sev_platform_init_handle_init_ex_path(struct sev_device *sev)
rc = sev_read_init_ex_file();
if (rc)
- return rc;
+ goto err_free;
/* If SEV-SNP is initialized, transition to firmware page. */
if (sev->snp_initialized) {
@@ -1533,11 +1533,22 @@ static int __sev_platform_init_handle_init_ex_path(struct sev_device *sev)
npages = 1UL << get_order(NV_LENGTH);
if (rmp_mark_pages_firmware(__pa(sev_init_ex_buffer), npages, false)) {
dev_err(sev->dev, "SEV: INIT_EX NV memory page state change failed.\n");
- return -ENOMEM;
+ rc = -ENOMEM;
+ /*
+ * Pages can be in an inconsistent state, don't release them back to the
+ * system.
+ */
+ goto err_reset;
}
}
return 0;
+
+err_free:
+ __free_pages(page, get_order(NV_LENGTH));
+err_reset:
+ sev_init_ex_buffer = NULL;
+ return rc;
}
static int __sev_platform_init_locked(int *error)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0347/1518] hwrng: ks-sa - Fix runtime PM cleanup on registration failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (345 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0346/1518] crypto: ccp - Fix memory leak in SEV INIT_EX path Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0348/1518] crash_dump: release keyring reference at the correct time Greg Kroah-Hartman
` (651 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yuho Choi, Herbert Xu, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuho Choi <dbgh9129@gmail.com>
[ Upstream commit 1c17b601fafb09c9ec074fd097737d20eafe7d63 ]
ks_sa_rng_probe() enables runtime PM and resumes the device before
registering the hwrng. If devm_hwrng_register() fails, probe returns
without dropping the runtime PM usage count or disabling runtime PM.
Unwind the runtime PM state on the registration failure path, matching
the cleanup done by remove().
Fixes: eb428ee0e3ca ("hwrng: ks-sa - add hw_random driver")
Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/char/hw_random/ks-sa-rng.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/drivers/char/hw_random/ks-sa-rng.c b/drivers/char/hw_random/ks-sa-rng.c
index 9e408144a10c1..4494f1e4ab4db 100644
--- a/drivers/char/hw_random/ks-sa-rng.c
+++ b/drivers/char/hw_random/ks-sa-rng.c
@@ -242,7 +242,14 @@ static int ks_sa_rng_probe(struct platform_device *pdev)
return dev_err_probe(dev, ret, "Failed to enable SA power-domain\n");
}
- return devm_hwrng_register(&pdev->dev, &ks_sa_rng->rng);
+ ret = devm_hwrng_register(dev, &ks_sa_rng->rng);
+ if (ret) {
+ pm_runtime_put_sync(dev);
+ pm_runtime_disable(dev);
+ return ret;
+ }
+
+ return 0;
}
static void ks_sa_rng_remove(struct platform_device *pdev)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0348/1518] crash_dump: release keyring reference at the correct time
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (346 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0347/1518] hwrng: ks-sa - Fix runtime PM cleanup on registration failure Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0349/1518] xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full Greg Kroah-Hartman
` (650 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Baoquan He,
Bradley Morgan, Mike Rapoport (Microsoft), Sasha Levin, Coiby Xu
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
[ Upstream commit ada2e5a44e99113e08ad9b7b71396c6c572204da ]
restore_dm_crypt_keys_to_thread_keyring() gets a reference to the user
keyring before restoring the saved dm-crypt keys.
The same keyring reference is then passed to add_key_to_keyring() for each
saved key, but add_key_to_keyring() drops that reference on every call.
This is only balanced when exactly one key is restored. With multiple
keys, the keyring reference is dropped too many times and may trigger a
refcount underflow or use-after-free.
When more than five keys are restored, a refcount underflow/use-after-free
warning can be triggered.
The early error paths after lookup_user_key() also return without dropping
the keyring reference.
Keep ownership of the keyring reference in
restore_dm_crypt_keys_to_thread_keyring(), drop it once on all exit paths,
and make add_key_to_keyring() only use the reference without consuming it.
Fixes: 62f17d9df692 ("crash_dump: retrieve dm crypt keys in kdump kernel")
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Reviewed-and-tested-by: Coiby Xu <Coiby.Xu@gmail.com>
Acked-by: Baoquan He <baoquan.he@linux.dev>
Reviewed-by: Bradley Morgan <include@grrlz.net>
Link: https://patch.msgid.link/20260704112509.3717884-1-lgs201920130244@gmail.com
Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/crash_dump_dm_crypt.c | 15 ++++++++++-----
1 file changed, 10 insertions(+), 5 deletions(-)
diff --git a/kernel/crash_dump_dm_crypt.c b/kernel/crash_dump_dm_crypt.c
index 9501b0704f19f..12e38922ca741 100644
--- a/kernel/crash_dump_dm_crypt.c
+++ b/kernel/crash_dump_dm_crypt.c
@@ -80,7 +80,6 @@ static int add_key_to_keyring(struct dm_crypt_key *dm_key,
kexec_dprintk("Error when adding key");
}
- key_ref_put(keyring_ref);
return r;
}
@@ -103,6 +102,7 @@ static int restore_dm_crypt_keys_to_thread_keyring(void)
struct dm_crypt_key *key;
size_t keys_header_size;
key_ref_t keyring_ref;
+ int ret = 0;
u64 addr;
/* find the target keyring (which must be writable) */
@@ -117,7 +117,8 @@ static int restore_dm_crypt_keys_to_thread_keyring(void)
dm_crypt_keys_read((char *)&key_count, sizeof(key_count), &addr);
if (key_count < 0 || key_count > KEY_NUM_MAX) {
kexec_dprintk("Failed to read the number of dm-crypt keys\n");
- return -1;
+ ret = -1;
+ goto out;
}
kexec_dprintk("There are %u keys\n", key_count);
@@ -125,8 +126,10 @@ static int restore_dm_crypt_keys_to_thread_keyring(void)
keys_header_size = get_keys_header_size(key_count);
keys_header = kzalloc(keys_header_size, GFP_KERNEL);
- if (!keys_header)
- return -ENOMEM;
+ if (!keys_header) {
+ ret = -ENOMEM;
+ goto out;
+ }
dm_crypt_keys_read((char *)keys_header, keys_header_size, &addr);
@@ -136,7 +139,9 @@ static int restore_dm_crypt_keys_to_thread_keyring(void)
add_key_to_keyring(key, keyring_ref);
}
- return 0;
+out:
+ key_ref_put(keyring_ref);
+ return ret;
}
static int read_key_from_user_keying(struct dm_crypt_key *dm_key)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0349/1518] xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (347 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0348/1518] crash_dump: release keyring reference at the correct time Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0350/1518] ALSA: hpi: Check transport errors during HPI6000 adapter initialization Greg Kroah-Hartman
` (649 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Weiming Shi, Xiang Mei,
Steffen Klassert, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xiang Mei <xmei5@asu.edu>
[ Upstream commit 5d9e3bf34fec9a5d237e4b7cef4a707bc2e091bc ]
The depth check in xfrm6_input_addr() is off by one:
if (1 + sp->len == XFRM_MAX_DEPTH)
goto drop;
...
sp->xvec[sp->len++] = x;
xfrm_input() can leave sp->len == XFRM_MAX_DEPTH, and the transport-mode
receive path re-enters IPv6 input via xfrm_trans_reinject() with that
secpath preserved. If the inner packet carries a destination-options HAO
option or a type-2 routing header, xfrm6_input_addr() is called with
sp->len == XFRM_MAX_DEPTH; the check (1 + 6 == 6) is false, so
sp->xvec[sp->len++] writes one slot past the 6-element xvec[]. The write
stays within the sec_path allocation (invisible to KASAN); UBSAN_BOUNDS
flags it and panics under panic_on_warn.
Use "sp->len >= XFRM_MAX_DEPTH", matching xfrm_input(). This also
restores one chain level the old check rejected at sp->len == 5.
UBSAN: array-index-out-of-bounds in net/ipv6/xfrm6_input.c:309:10
index 6 is out of range for type 'xfrm_state *[6]'
Fixes: 9473e1f631de ("[XFRM] MIPv6: Fix to input RO state correctly.")
Reported-by: Weiming Shi <bestswngs@gmail.com>
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Xiang Mei <xmei5@asu.edu>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/ipv6/xfrm6_input.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/ipv6/xfrm6_input.c b/net/ipv6/xfrm6_input.c
index 699a001ac1662..c9e208c57a6b5 100644
--- a/net/ipv6/xfrm6_input.c
+++ b/net/ipv6/xfrm6_input.c
@@ -249,7 +249,7 @@ int xfrm6_input_addr(struct sk_buff *skb, xfrm_address_t *daddr,
goto drop;
}
- if (1 + sp->len == XFRM_MAX_DEPTH) {
+ if (sp->len >= XFRM_MAX_DEPTH) {
XFRM_INC_STATS(net, LINUX_MIB_XFRMINBUFFERERROR);
goto drop;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0350/1518] ALSA: hpi: Check transport errors during HPI6000 adapter initialization
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (348 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0349/1518] xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full Greg Kroah-Hartman
@ 2026-09-12 6:41 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0351/1518] pmdomain: bcm: bcm2835: handle genpd provider registration errors Greg Kroah-Hartman
` (648 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:41 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Evgenii Burenchev, Takashi Iwai,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Evgenii Burenchev <evg28bur@yandex.ru>
[ Upstream commit cc15c329663e3ef1aeed0b68e49a5d5ce4ae0d5c ]
create_adapter_obj() retrieves adapter information by calling
hpi6000_message_response_sequence(). This function reports transport-level
errors through its return value and DSP-reported errors via hr0.error.
The current code only checks hr0.error, causing transport-level errors to
be ignored. As a result, adapter initialization may continue with an
invalid response.
Check the return value of hpi6000_message_response_sequence() before
examining hr0.error.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Fixes: 719f82d3987a ("ALSA: Add support of AudioScience ASI boards")
Signed-off-by: Evgenii Burenchev <evg28bur@yandex.ru>
Link: https://patch.msgid.link/20260708141147.18253-1-evg28bur@yandex.ru
Signed-off-by: Takashi Iwai <tiwai@suse.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/pci/asihpi/hpi6000.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/sound/pci/asihpi/hpi6000.c b/sound/pci/asihpi/hpi6000.c
index b08578c93c6a2..57a730be26745 100644
--- a/sound/pci/asihpi/hpi6000.c
+++ b/sound/pci/asihpi/hpi6000.c
@@ -537,6 +537,11 @@ static short create_adapter_obj(struct hpi_adapter_obj *pao,
hr1.size = sizeof(hr1);
error = hpi6000_message_response_sequence(pao, 0, &hm, &hr0);
+ if (error) {
+ HPI_DEBUG_LOG(ERROR, "message transport error %d\n",
+ error);
+ return error;
+ }
if (hr0.error) {
HPI_DEBUG_LOG(DEBUG, "message error %d\n", hr0.error);
return hr0.error;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0351/1518] pmdomain: bcm: bcm2835: handle genpd provider registration errors
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (349 preceding siblings ...)
2026-09-12 6:41 ` [PATCH 6.18 0350/1518] ALSA: hpi: Check transport errors during HPI6000 adapter initialization Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0352/1518] misc: rtsx_usb: avoid USB I/O in runtime autosuspend Greg Kroah-Hartman
` (647 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Stefan Wahren,
Ulf Hansson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit a1d9d3b958d69a13783613304f524f489fecdd1f ]
bcm2835_power_probe() initializes all power domains and then registers
the onecell genpd provider, but ignores of_genpd_add_provider_onecell()
failures. Probe can therefore return success even though no provider was
published.
Check the provider registration return value and jump to the existing
cleanup path on failure.
Fixes: 670c672608a1 ("soc: bcm: bcm2835-pm: Add support for power domains under a new binding.")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Reviewed-by: Stefan Wahren <wahrenst@gmx.net>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pmdomain/bcm/bcm2835-power.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/drivers/pmdomain/bcm/bcm2835-power.c b/drivers/pmdomain/bcm/bcm2835-power.c
index f2472f1e17521..f3df1198ec7e2 100644
--- a/drivers/pmdomain/bcm/bcm2835-power.c
+++ b/drivers/pmdomain/bcm/bcm2835-power.c
@@ -675,7 +675,12 @@ static int bcm2835_power_probe(struct platform_device *pdev)
if (ret)
goto fail;
- of_genpd_add_provider_onecell(dev->parent->of_node, &power->pd_xlate);
+ ret = of_genpd_add_provider_onecell(dev->parent->of_node,
+ &power->pd_xlate);
+ if (ret) {
+ dev_err_probe(dev, ret, "failed to add genpd provider\n");
+ goto fail;
+ }
dev_info(dev, "Broadcom BCM2835 power domains driver");
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0352/1518] misc: rtsx_usb: avoid USB I/O in runtime autosuspend
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (350 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0351/1518] pmdomain: bcm: bcm2835: handle genpd provider registration errors Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0353/1518] RDMA/hfi1: Preserve unit 0 on allocation failure Greg Kroah-Hartman
` (646 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sean Rhodes, Ulf Hansson,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sean Rhodes <sean@starlabs.systems>
[ Upstream commit 483c948324a3823871c004560a92545759d3253c ]
The runtime autosuspend callback currently queries card status and
clears OCP by issuing USB register accesses. This can run from the
USB runtime-PM path itself, which is the wrong place to start more
device I/O.
Keep a cached copy of the card-status bits from normal status reads
instead. During runtime autosuspend, use that cached value only to
preserve the existing Memory Stick autosuspend deferral.
Do not treat raw SD_CD as an autosuspend blocker, because tray-based
SD readers can assert SD_CD with an empty tray. A real SD card is
protected by the SD/MMC child runtime-PM usage once powered.
Also stop clearing OCP from the runtime autosuspend callback, so the
callback does not issue USB commands.
Fixes: bb400d2120bd ("mfd: rtsx_usb: Defer autosuspend while card exists")
Signed-off-by: Sean Rhodes <sean@starlabs.systems>
Acked-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/misc/cardreader/rtsx_usb.c | 26 ++++++++++++++++++++------
include/linux/rtsx_usb.h | 3 +++
2 files changed, 23 insertions(+), 6 deletions(-)
diff --git a/drivers/misc/cardreader/rtsx_usb.c b/drivers/misc/cardreader/rtsx_usb.c
index 1830e9ed25216..a127744918f42 100644
--- a/drivers/misc/cardreader/rtsx_usb.c
+++ b/drivers/misc/cardreader/rtsx_usb.c
@@ -312,6 +312,9 @@ int rtsx_usb_get_card_status(struct rtsx_ucr *ucr, u16 *status)
if (ret < 0)
return ret;
+ ucr->card_status_cache = *status;
+ ucr->card_status_valid = true;
+
return 0;
}
EXPORT_SYMBOL_GPL(rtsx_usb_get_card_status);
@@ -623,6 +626,7 @@ static int rtsx_usb_probe(struct usb_interface *intf,
{
struct usb_device *usb_dev = interface_to_usbdev(intf);
struct rtsx_ucr *ucr;
+ u16 status;
int ret;
dev_dbg(&intf->dev,
@@ -659,6 +663,9 @@ static int rtsx_usb_probe(struct usb_interface *intf,
if (ret)
goto out_init_fail;
+ /* Prime cached status for runtime autosuspend decisions. */
+ rtsx_usb_get_card_status(ucr, &status);
+
/* initialize USB SG transfer timer */
timer_setup(&ucr->sg_timer, rtsx_usb_sg_timed_out, 0);
@@ -713,22 +720,29 @@ static int rtsx_usb_suspend(struct usb_interface *intf, pm_message_t message)
struct rtsx_ucr *ucr =
(struct rtsx_ucr *)usb_get_intfdata(intf);
u16 val = 0;
+ bool valid = false;
dev_dbg(&intf->dev, "%s called with pm message 0x%04x\n",
__func__, message.event);
if (PMSG_IS_AUTO(message)) {
if (mutex_trylock(&ucr->dev_mutex)) {
- rtsx_usb_get_card_status(ucr, &val);
+ valid = ucr->card_status_valid;
+ if (valid)
+ val = ucr->card_status_cache;
mutex_unlock(&ucr->dev_mutex);
- /* Defer the autosuspend if card exists */
- if (val & (SD_CD | MS_CD)) {
+ /*
+ * Do not issue USB commands from runtime autosuspend.
+ * Raw SD_CD is not authoritative on tray-based readers,
+ * while a real SD card is protected by the SD/MMC child
+ * runtime-PM reference once the card is powered. Keep
+ * the historical Memory Stick autosuspend deferral when
+ * the cached status says MS media is present.
+ */
+ if (valid && (val & MS_CD)) {
device_for_each_child(&intf->dev, NULL, rtsx_usb_resume_child);
return -EAGAIN;
- } else {
- /* if the card does not exists, clear OCP status */
- rtsx_usb_write_register(ucr, OCPCTL, MS_OCP_CLEAR, MS_OCP_CLEAR);
}
} else {
/* There is an ongoing operation*/
diff --git a/include/linux/rtsx_usb.h b/include/linux/rtsx_usb.h
index 276b509c03e36..0fc5a74700a8b 100644
--- a/include/linux/rtsx_usb.h
+++ b/include/linux/rtsx_usb.h
@@ -61,6 +61,9 @@ struct rtsx_ucr {
struct timer_list sg_timer;
struct mutex dev_mutex;
+
+ u16 card_status_cache;
+ bool card_status_valid;
};
/* buffer size */
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0353/1518] RDMA/hfi1: Preserve unit 0 on allocation failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (351 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0352/1518] misc: rtsx_usb: avoid USB I/O in runtime autosuspend Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0354/1518] RDMA/hfi1: Free RX data on late probe failure Greg Kroah-Hartman
` (645 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leon Romanovsky <leonro@nvidia.com>
[ Upstream commit 2e3809ad8911f5d5581b3f046bd628417bface76 ]
hfi1_free_devdata() assumes that the device was inserted into the unit
table and unconditionally erases dd->unit. If xa_alloc_irq() fails, the
zero-initialized unit remains zero, so full cleanup can remove an
unrelated device from index 0.
Release only the rdmavt allocation and return immediately while the unit
table has not acquired the device.
Fixes: 03b92789e5cf ("hfi1: Convert hfi1_unit_table to XArray")
Link: https://patch.msgid.link/20260708-clean-init-one-hfi1-v1-2-b9e9641268a5@nvidia.com
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/hfi1/init.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/drivers/infiniband/hw/hfi1/init.c b/drivers/infiniband/hw/hfi1/init.c
index 7e0298c62882e..8b5b4f58aa62e 100644
--- a/drivers/infiniband/hw/hfi1/init.c
+++ b/drivers/infiniband/hw/hfi1/init.c
@@ -1227,8 +1227,9 @@ static struct hfi1_devdata *hfi1_alloc_devdata(struct pci_dev *pdev,
GFP_KERNEL);
if (ret < 0) {
dev_err(&pdev->dev,
- "Could not allocate unit ID: error %d\n", -ret);
- goto bail;
+ "Could not allocate unit ID: error %pe\n", ERR_PTR(ret));
+ rvt_dealloc_device(&dd->verbs_dev.rdi);
+ return ERR_PTR(ret);
}
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0354/1518] RDMA/hfi1: Free RX data on late probe failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (352 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0353/1518] RDMA/hfi1: Preserve unit 0 on allocation failure Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0355/1518] RDMA/hfi1: Remove redundant PCI device ID validation Greg Kroah-Hartman
` (644 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Kalesh AP, Leon Romanovsky,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leon Romanovsky <leonro@nvidia.com>
[ Upstream commit 8e17e101e04a3dc062e2719da57ff78c1c060632 ]
hfi1_init_dd() allocates the shared AIP/VNIC RX support before returning.
If hfi1_init() or hfi1_register_ib_device() later fails, init_one() tears
down the device data without calling hfi1_free_rx(). This leaks netdev_rx
and its dummy netdev.
Free the RX support after IB unregistration and before postinit_cleanup(),
as done on normal device removal.
Fixes: 4730f4a6c6b2 ("IB/hfi1: Activate the dummy netdev")
Link: https://patch.msgid.link/20260708-clean-init-one-hfi1-v1-7-b9e9641268a5@nvidia.com
Reviewed-by: Kalesh AP <kalesh-anakkur.purayil@broadcom.com>
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/hfi1/init.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/infiniband/hw/hfi1/init.c b/drivers/infiniband/hw/hfi1/init.c
index 8b5b4f58aa62e..cb6851a5df60e 100644
--- a/drivers/infiniband/hw/hfi1/init.c
+++ b/drivers/infiniband/hw/hfi1/init.c
@@ -1688,6 +1688,7 @@ static int init_one(struct pci_dev *pdev, const struct pci_device_id *ent)
hfi1_device_remove(dd);
if (!ret)
hfi1_unregister_ib_device(dd);
+ hfi1_free_rx(dd);
postinit_cleanup(dd);
if (initfail)
ret = initfail;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0355/1518] RDMA/hfi1: Remove redundant PCI device ID validation
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (353 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0354/1518] RDMA/hfi1: Free RX data on late probe failure Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0356/1518] RDMA/hfi1: Create workqueues before device initialization Greg Kroah-Hartman
` (643 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leon Romanovsky <leonro@nvidia.com>
[ Upstream commit af9117d02f50514c998714b23820de71d0aa5d24 ]
The PCI core calls init_one() only after pci_match_device() has selected
an ID. For normal probing, hfi1_pci_tbl already restricts matches to the
two supported Intel device IDs. Dynamic IDs and driver_override are
explicit requests to attempt binding, so the probe should not second-guess
the PCI core's decision.
Remove the redundant check.
Link: https://patch.msgid.link/20260708-clean-init-one-hfi1-v1-3-b9e9641268a5@nvidia.com
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Stable-dep-of: 9f674ba674a0 ("RDMA/hfi1: Allocate device data after PCI initialization")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/hfi1/init.c | 9 ---------
1 file changed, 9 deletions(-)
diff --git a/drivers/infiniband/hw/hfi1/init.c b/drivers/infiniband/hw/hfi1/init.c
index cb6851a5df60e..b20c0c0ddfa79 100644
--- a/drivers/infiniband/hw/hfi1/init.c
+++ b/drivers/infiniband/hw/hfi1/init.c
@@ -1573,15 +1573,6 @@ static int init_one(struct pci_dev *pdev, const struct pci_device_id *ent)
/* First, lock the non-writable module parameters */
HFI1_CAP_LOCK();
- /* Validate dev ids */
- if (!(ent->device == PCI_DEVICE_ID_INTEL0 ||
- ent->device == PCI_DEVICE_ID_INTEL1)) {
- dev_err(&pdev->dev, "Failing on unknown Intel deviceid 0x%x\n",
- ent->device);
- ret = -ENODEV;
- goto bail;
- }
-
/* Allocate the dd so we can get to work */
dd = hfi1_alloc_devdata(pdev, NUM_IB_PORTS *
sizeof(struct hfi1_pportdata));
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0356/1518] RDMA/hfi1: Create workqueues before device initialization
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (354 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0355/1518] RDMA/hfi1: Remove redundant PCI device ID validation Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0357/1518] RDMA/hfi1: Stop flushing the global IB workqueue Greg Kroah-Hartman
` (642 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leon Romanovsky <leonro@nvidia.com>
[ Upstream commit 0d5618c1b2fc9dd4fc086f0226acd8a077ab6c1b ]
create_workqueues() only needs fields set up by hfi1_alloc_devdata().
Call it before hfi1_init_dd() so a workqueue allocation failure happens
before chip resources are initialized.
To keep the reordered error paths safe, make init_one() own hfi1_devdata.
hfi1_init_dd() unwinds its partial setup but leaves the allocation for the
caller to free. If device initialization fails, destroy the workqueues
before freeing the device data.
Link: https://patch.msgid.link/20260708-clean-init-one-hfi1-v1-6-b9e9641268a5@nvidia.com
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Stable-dep-of: 9f674ba674a0 ("RDMA/hfi1: Allocate device data after PCI initialization")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/hfi1/chip.c | 4 +---
drivers/infiniband/hw/hfi1/hfi.h | 2 --
drivers/infiniband/hw/hfi1/init.c | 19 ++++++++++---------
3 files changed, 11 insertions(+), 14 deletions(-)
diff --git a/drivers/infiniband/hw/hfi1/chip.c b/drivers/infiniband/hw/hfi1/chip.c
index 0781ab756d441..57c70384d2107 100644
--- a/drivers/infiniband/hw/hfi1/chip.c
+++ b/drivers/infiniband/hw/hfi1/chip.c
@@ -15047,7 +15047,7 @@ int hfi1_init_dd(struct hfi1_devdata *dd)
*/
ret = hfi1_pcie_ddinit(dd, pdev);
if (ret < 0)
- goto bail_free;
+ goto bail;
/* Save PCI space registers to rewrite after device reset */
ret = save_pci_variables(dd);
@@ -15302,8 +15302,6 @@ int hfi1_init_dd(struct hfi1_devdata *dd)
bail_cleanup:
hfi1_free_rx(dd);
hfi1_pcie_ddcleanup(dd);
-bail_free:
- hfi1_free_devdata(dd);
bail:
return ret;
}
diff --git a/drivers/infiniband/hw/hfi1/hfi.h b/drivers/infiniband/hw/hfi1/hfi.h
index cb630551cf1a3..20942a8ac249e 100644
--- a/drivers/infiniband/hw/hfi1/hfi.h
+++ b/drivers/infiniband/hw/hfi1/hfi.h
@@ -2044,9 +2044,7 @@ struct cc_state *get_cc_state_protected(struct hfi1_pportdata *ppd)
/* waiting for an urgent packet to arrive */
#define HFI1_CTXT_WAITING_URG 4
-/* free up any allocated data at closes */
int hfi1_init_dd(struct hfi1_devdata *dd);
-void hfi1_free_devdata(struct hfi1_devdata *dd);
/* LED beaconing functions */
void hfi1_start_led_override(struct hfi1_pportdata *ppd, unsigned int timeon,
diff --git a/drivers/infiniband/hw/hfi1/init.c b/drivers/infiniband/hw/hfi1/init.c
index b20c0c0ddfa79..68e0aab49fb94 100644
--- a/drivers/infiniband/hw/hfi1/init.c
+++ b/drivers/infiniband/hw/hfi1/init.c
@@ -630,8 +630,6 @@ void hfi1_init_pportdata(struct pci_dev *pdev, struct hfi1_pportdata *ppd,
ppd->sm_trap_qp = 0x0;
ppd->sa_qp = 0x1;
- ppd->hfi1_wq = NULL;
-
spin_lock_init(&ppd->cca_timer_lock);
for (i = 0; i < OPA_MAX_SLS; i++) {
@@ -1163,7 +1161,7 @@ static void finalize_asic_data(struct hfi1_devdata *dd,
* It cleans up and frees all data structures set up by
* by hfi1_alloc_devdata().
*/
-void hfi1_free_devdata(struct hfi1_devdata *dd)
+static void hfi1_free_devdata(struct hfi1_devdata *dd)
{
struct hfi1_asic_data *ad;
unsigned long flags;
@@ -1626,17 +1624,17 @@ static int init_one(struct pci_dev *pdev, const struct pci_device_id *ent)
if (ret)
goto bail;
+ ret = create_workqueues(dd);
+ if (ret)
+ goto free_devdata;
+
/*
* Do device-specific initialization, function table setup, dd
* allocation, etc.
*/
ret = hfi1_init_dd(dd);
if (ret)
- goto clean_bail; /* error already printed */
-
- ret = create_workqueues(dd);
- if (ret)
- goto clean_bail;
+ goto destroy_workqueues; /* error already printed */
/* do the generic initialization */
initfail = hfi1_init(dd, 0);
@@ -1690,7 +1688,10 @@ static int init_one(struct pci_dev *pdev, const struct pci_device_id *ent)
return 0;
-clean_bail:
+destroy_workqueues:
+ destroy_workqueues(dd);
+free_devdata:
+ hfi1_free_devdata(dd);
hfi1_pcie_cleanup(pdev);
bail:
return ret;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0357/1518] RDMA/hfi1: Stop flushing the global IB workqueue
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (355 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0356/1518] RDMA/hfi1: Create workqueues before device initialization Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0358/1518] RDMA/hfi1: Initialize debugfs after probe completes Greg Kroah-Hartman
` (641 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leon Romanovsky <leonro@nvidia.com>
[ Upstream commit d43b1c17f9e1b9d34a0d742f569c00d84147ebc0 ]
hfi1 does not queue work on ib_wq. QSFP and link work run on the per-port
link_wq, while the remaining device work uses hfi1_wq or dedicated queues.
The probe failure path destroys both per-port workqueues, and normal device
removal flushes them in shutdown_device() before destroying them.
Remove the flushes of the core-owned global workqueue. Waiting for
unrelated core or other device work is not part of hfi1 teardown.
Fixes: 71d47008ca1b ("IB/hfi1: Create workqueue for link events")
Link: https://patch.msgid.link/20260708-clean-init-one-hfi1-v1-10-b9e9641268a5@nvidia.com
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/hfi1/init.c | 4 ----
1 file changed, 4 deletions(-)
diff --git a/drivers/infiniband/hw/hfi1/init.c b/drivers/infiniband/hw/hfi1/init.c
index 68e0aab49fb94..6253d8088abd6 100644
--- a/drivers/infiniband/hw/hfi1/init.c
+++ b/drivers/infiniband/hw/hfi1/init.c
@@ -1660,7 +1660,6 @@ static int init_one(struct pci_dev *pdev, const struct pci_device_id *ent)
if (initfail || ret) {
msix_clean_up_interrupts(dd);
stop_timers(dd);
- flush_workqueue(ib_wq);
for (pidx = 0; pidx < dd->num_pports; ++pidx) {
hfi1_quiet_serdes(dd->pport + pidx);
ppd = dd->pport + pidx;
@@ -1737,9 +1736,6 @@ static void remove_one(struct pci_dev *pdev)
stop_timers(dd);
- /* wait until all of our (qsfp) queue_work() calls complete */
- flush_workqueue(ib_wq);
-
postinit_cleanup(dd);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0358/1518] RDMA/hfi1: Initialize debugfs after probe completes
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (356 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0357/1518] RDMA/hfi1: Stop flushing the global IB workqueue Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0359/1518] ASoC: apple: mca: increase SERDES reset delay Greg Kroah-Hartman
` (640 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Kalesh AP, Leon Romanovsky,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leon Romanovsky <leonro@nvidia.com>
[ Upstream commit bb18740b302f6f222ce3d5a7e5c45a52a90df805 ]
Commit ed6f653fe430 ("staging/rdma/hfi1: Fix debugfs access race") moved
debugfs creation after device initialization and IB registration so users
cannot access the files before the driver is ready. However, init_one()
still creates them before character device creation and SDMA startup
finish.
Move hfi1_dbg_ibdev_init() to the end of the successful probe path,
matching hfi1_dbg_ibdev_exit() as the first action in remove_one().
Fixes: ed6f653fe430 ("staging/rdma/hfi1: Fix debugfs access race")
Link: https://patch.msgid.link/20260708-clean-init-one-hfi1-v1-12-b9e9641268a5@nvidia.com
Reviewed-by: Kalesh AP <kalesh-anakkur.purayil@broadcom.com>
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/hfi1/init.c | 6 ++----
1 file changed, 2 insertions(+), 4 deletions(-)
diff --git a/drivers/infiniband/hw/hfi1/init.c b/drivers/infiniband/hw/hfi1/init.c
index 6253d8088abd6..f0b3d53243687 100644
--- a/drivers/infiniband/hw/hfi1/init.c
+++ b/drivers/infiniband/hw/hfi1/init.c
@@ -1647,11 +1647,8 @@ static int init_one(struct pci_dev *pdev, const struct pci_device_id *ent)
* we still create devices, so diags, etc. can be used
* to determine cause of problem.
*/
- if (!initfail && !ret) {
+ if (!initfail && !ret)
dd->flags |= HFI1_INITTED;
- /* create debufs files after init and ib register */
- hfi1_dbg_ibdev_init(&dd->verbs_dev);
- }
j = hfi1_device_create(dd);
if (j)
@@ -1684,6 +1681,7 @@ static int init_one(struct pci_dev *pdev, const struct pci_device_id *ent)
}
sdma_start(dd);
+ hfi1_dbg_ibdev_init(&dd->verbs_dev);
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0359/1518] ASoC: apple: mca: increase SERDES reset delay
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (357 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0358/1518] RDMA/hfi1: Initialize debugfs after probe completes Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0360/1518] isofs: fix out-of-bounds page array access on empty zisofs block Greg Kroah-Hartman
` (639 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, James Calligeros, Mark Brown,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: James Calligeros <jcalligeros99@gmail.com>
[ Upstream commit cccd721e5aab03e92234faee72b363c9ba60611c ]
The SERDES clusters in this peripheral take a long time to warm up.
We tried polling the reset bit until cleared, however this is not
a reliable signal of readiness to be configured. Only waiting
~25 us to give the cluster a chance to settle makes it work
reliably.
Increase the 2 us delay to 25 us and hope we never have to do this
again.
Fixes: d8b3e396088d ("ASoC: apple: mca: Fix SERDES reset sequence")
Signed-off-by: James Calligeros <jcalligeros99@gmail.com>
Link: https://patch.msgid.link/20260711-apple-audio-redux-v4-1-2994d87c2f24@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/apple/mca.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/sound/soc/apple/mca.c b/sound/soc/apple/mca.c
index c4dcb2b545912..17b572ad8b99e 100644
--- a/sound/soc/apple/mca.c
+++ b/sound/soc/apple/mca.c
@@ -210,10 +210,10 @@ static void mca_fe_early_trigger(struct snd_pcm_substream *substream, int cmd,
SERDES_STATUS_EN | SERDES_STATUS_RST,
SERDES_STATUS_RST);
/*
- * Experiments suggest that it takes at most ~1 us
- * for the bit to clear, so wait 2 us for good measure.
+ * The SERDES cluster needs a bit of time to reset itself
+ * and settle before we start poking it. This is... slow...
*/
- udelay(2);
+ udelay(25);
WARN_ON(readl_relaxed(cl->base + serdes_unit + REG_SERDES_STATUS) &
SERDES_STATUS_RST);
mca_modify(cl, serdes_conf, SERDES_CONF_SYNC_SEL,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0360/1518] isofs: fix out-of-bounds page array access on empty zisofs block
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (358 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0359/1518] ASoC: apple: mca: increase SERDES reset delay Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0361/1518] iommufd/selftest: Avoid selftest dirty bitmap size wrap Greg Kroah-Hartman
` (638 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Weiming Shi, Xiang Mei, Jan Kara,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xiang Mei <xmei5@asu.edu>
[ Upstream commit 68d4d3e78150c7ed7d1195af63ad1e6ace30c661 ]
zisofs_uncompress_block()'s empty-block fast path returns
pcount << PAGE_SHIFT, ignoring the incoming poffset, unlike the
decompression path which returns bytes produced relative to poffset.
zisofs_fill_pages() uses that return to advance its page cursor, so when
the zisofs block size is below PAGE_SIZE and a sub-page block leaves
poffset partway into a page, a following empty block over-counts and
advances pages[] one element past its end, after which
"if (poffset && *pages)" reads pages[1] out of bounds. rock.c only
rejects a block-size shift > 17, so a crafted "ZF" Rock Ridge record can
set it below PAGE_SHIFT; the bug is reached by an ordinary read() of a
compressed file on such a mounted ISO9660 image.
Return the byte count relative to poffset and zero only
[poffset, PAGE_SIZE) of the first page, matching the decompression path.
The page-aligned case (poffset == 0) is unaffected.
BUG: KASAN: slab-out-of-bounds in zisofs_read_folio (fs/isofs/compress.c:290)
Read of size 8 at addr ffff88800f5eac48 by task exploit/142
zisofs_read_folio (fs/isofs/compress.c:290)
read_pages (mm/readahead.c:184)
...
filemap_read (mm/filemap.c:2814)
vfs_read (fs/read_write.c:574)
__x64_sys_pread64 (fs/read_write.c:769)
do_syscall_64 (arch/x86/entry/syscall_64.c:94)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
The buggy address is located 0 bytes to the right of the
allocated 8-byte region in the kmalloc-8 cache
Fixes: 59bc055211b8 ("zisofs: Implement reading of compressed files when PAGE_CACHE_SIZE > compress block size")
Reported-by: Weiming Shi <bestswngs@gmail.com>
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Xiang Mei <xmei5@asu.edu>
Link: https://patch.msgid.link/20260712234150.3213467-1-xmei5@asu.edu
Signed-off-by: Jan Kara <jack@suse.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/isofs/compress.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/fs/isofs/compress.c b/fs/isofs/compress.c
index 5f3b6da0e0225..172faf79a259d 100644
--- a/fs/isofs/compress.c
+++ b/fs/isofs/compress.c
@@ -65,12 +65,14 @@ static loff_t zisofs_uncompress_block(struct inode *inode, loff_t block_start,
/* Empty block? */
if (block_size == 0) {
for ( i = 0 ; i < pcount ; i++ ) {
+ unsigned int off = i ? 0 : poffset;
+
if (!pages[i])
continue;
- memzero_page(pages[i], 0, PAGE_SIZE);
+ memzero_page(pages[i], off, PAGE_SIZE - off);
SetPageUptodate(pages[i]);
}
- return ((loff_t)pcount) << PAGE_SHIFT;
+ return (((loff_t)pcount) << PAGE_SHIFT) - poffset;
}
/* Because zlib is not thread-safe, do all the I/O at the top. */
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0361/1518] iommufd/selftest: Avoid selftest dirty bitmap size wrap
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (359 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0360/1518] isofs: fix out-of-bounds page array access on empty zisofs block Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0362/1518] media: v4l2-async: Unregister sub-device if asc_list is empty Greg Kroah-Hartman
` (637 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Samuel Moelius, Jason Gunthorpe,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Samuel Moelius <sam.moelius@trailofbits.com>
[ Upstream commit 4132ba2ae2cf14c289e3fabc1c95ac244d643356 ]
IOMMU_TEST_OP_DIRTY sizes its temporary dirty bitmap from length /
page_size. Very large selftest ranges can make the DIV_ROUND_UP()
additions wrap before allocation, producing a zero-length allocation while
the later test_bit() loop still walks the original number of bits.
The selftest helper does not need to support unbounded dirty bitmap sizes.
Reject requests that would allocate more than SZ_16M for the temporary
buffer.
Fixes: 79ea4a496ab5 ("iommufd/selftest: Fix buffer read overrrun in the dirty test")
Link: https://patch.msgid.link/r/20260628152331.82122.408afd7b466c.iommufd-test-dirty-bitmap-size-wrap@trailofbits.com
Assisted-by: Codex:gpt-5.5-cyber-preview
Signed-off-by: Samuel Moelius <sam.moelius@trailofbits.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/iommu/iommufd/selftest.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/iommu/iommufd/selftest.c b/drivers/iommu/iommufd/selftest.c
index 35c42ff4355a7..cd3d1380cf6c5 100644
--- a/drivers/iommu/iommufd/selftest.c
+++ b/drivers/iommu/iommufd/selftest.c
@@ -10,6 +10,7 @@
#include <linux/iommu.h>
#include <linux/platform_device.h>
#include <linux/slab.h>
+#include <linux/sizes.h>
#include <linux/xarray.h>
#include <uapi/linux/iommufd.h>
@@ -1806,6 +1807,9 @@ static int iommufd_test_dirty(struct iommufd_ucmd *ucmd, unsigned int mockpt_id,
if (!page_size || !length || iova % page_size || length % page_size ||
!uptr)
return -EINVAL;
+ max = length / page_size;
+ if (max > SZ_16M * BITS_PER_BYTE)
+ return -EOVERFLOW;
hwpt = get_md_pagetable(ucmd, mockpt_id, &mock);
if (IS_ERR(hwpt))
@@ -1816,7 +1820,6 @@ static int iommufd_test_dirty(struct iommufd_ucmd *ucmd, unsigned int mockpt_id,
goto out_put;
}
- max = length / page_size;
tmp = kvzalloc(DIV_ROUND_UP(max, BITS_PER_LONG) * sizeof(unsigned long),
GFP_KERNEL_ACCOUNT);
if (!tmp) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0362/1518] media: v4l2-async: Unregister sub-device if asc_list is empty
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (360 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0361/1518] iommufd/selftest: Avoid selftest dirty bitmap size wrap Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0363/1518] fs/resctrl: Prevent use-after-free in rdtgroup_kn_put() Greg Kroah-Hartman
` (636 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hans Verkuil, Sakari Ailus,
Mauro Carvalho Chehab, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hans Verkuil <hverkuil+cisco@kernel.org>
[ Upstream commit 4e72f13d58c4245c177a9d5f54579345554f354d ]
When my em28xx USB device that uses the i2c tvp5150 driver is
disconnected, it crashes.
The cause is that the tvp5150 i2c module uses v4l2_async, but
the em28xx driver does not since it predates v4l2_async.
In that corner case sd->asc_list is empty, so
v4l2_async_unregister_subdev() never calls v4l2_device_unregister_subdev().
Modify the code so that, if sd->asc_list is empty,
v4l2_device_unregister_subdev() is still called.
Fixes: 28a1295795d8 ("media: v4l: async: Allow multiple connections between entities")
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Acked-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Tested-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Signed-off-by: Mauro Carvalho Chehab <mchehab+huawei@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/media/v4l2-core/v4l2-async.c | 15 ++++++++++++---
1 file changed, 12 insertions(+), 3 deletions(-)
diff --git a/drivers/media/v4l2-core/v4l2-async.c b/drivers/media/v4l2-core/v4l2-async.c
index 70284f50e1f93..5f6685e34d90f 100644
--- a/drivers/media/v4l2-core/v4l2-async.c
+++ b/drivers/media/v4l2-core/v4l2-async.c
@@ -897,9 +897,18 @@ void v4l2_async_unregister_subdev(struct v4l2_subdev *sd)
sd->subdev_notifier = NULL;
if (sd->asc_list.next) {
- list_for_each_entry_safe(asc, asc_tmp, &sd->asc_list,
- asc_subdev_entry) {
- v4l2_async_unbind_subdev_one(asc->notifier, asc);
+ if (list_empty(&sd->asc_list)) {
+ /*
+ * If the sub-device was registered through other means
+ * than v4l2-async, there are no async connections but
+ * the sub-device may still well be registered.
+ * Unregister it now.
+ */
+ v4l2_device_unregister_subdev(sd);
+ } else {
+ list_for_each_entry_safe(asc, asc_tmp, &sd->asc_list,
+ asc_subdev_entry)
+ v4l2_async_unbind_subdev_one(asc->notifier, asc);
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0363/1518] fs/resctrl: Prevent use-after-free in rdtgroup_kn_put()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (361 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0362/1518] media: v4l2-async: Unregister sub-device if asc_list is empty Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0364/1518] perf zstd: Fix compression error path in zstd_compress_stream_to_records() Greg Kroah-Hartman
` (635 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Reinette Chatre,
Borislav Petkov (AMD), Ben Horgan, Tony Luck, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Reinette Chatre <reinette.chatre@intel.com>
[ Upstream commit f5bcf539484d2d604c2f2330e09487ea090b21c7 ]
A struct rdtgroup is reference counted via rdtgroup::waitcount. Callers that
need the structure to remain valid across a sleep (while waiting on acquiring
rdtgroup_mutex) take a reference with rdtgroup_kn_get() and release it with
rdtgroup_kn_put().
The release path is intended to serve as the fallback freer: if the count
drops to zero and the group has already been marked RDT_DELETED,
rdtgroup_kn_put() frees the structure.
The bulk teardown paths free_all_child_rdtgrp() and rmdir_all_sub() resulting
from a resctrl directory remove or resctrl fs unmount act as the primary
freer: they hold rdtgroup_mutex and free each rdtgroup whose waitcount is
zero, otherwise they set RDT_DELETED and leave the freeing to the last waiter.
These two freers race. rdtgroup_kn_put() commits waitcount == 0 with
atomic_dec_and_test() outside rdtgroup_mutex, then reads rdtgroup::flags.
Between those two operations a concurrent caller of free_all_child_rdtgrp()
or rmdir_all_sub() (which holds the mutex) can observe waitcount == 0 via
atomic_read(), call rdtgroup_remove(), and kfree() the structure.
The subsequent read of rdtgroup::flags in rdtgroup_kn_put() is then
a use-after-free, and the structure may even be freed twice if the freed
memory happens to satisfy the RDT_DELETED flag check.
Replace the bare atomic_dec_and_test() with atomic_dec_and_mutex_lock() so
that the decrement-to-zero takes rdtgroup_mutex before the count becomes
globally visible. The inspection of rdtgroup::flags then runs under the same
mutex held by the bulk freers, making the two paths mutually exclusive.
The common case where the count does not reach zero remains lock-free. Defer
kernfs_unbreak_active_protection() until after the mutex is dropped since
kernfs active protections functionally wrap rdtgroup_mutex. Remove resource
group, which in turn drops its kernfs reference, after kernfs protection is
restored.
[ bp: Split the commit messsages into smaller, easier-parseable paragraphs. ]
Fixes: b8511ccc75c0 ("x86/resctrl: Fix use-after-free when deleting resource groups")
Closes: https://sashiko.dev/#/patchset/20260515193944.15114-1-tony.luck%40intel.com?part=1
Reported-by: Sashiko <sashiko-bot@kernel.org>
Assisted-by: GitHub_Copilot:gemini-3.1-pro
Signed-off-by: Reinette Chatre <reinette.chatre@intel.com>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Reviewed-by: Ben Horgan <ben.horgan@arm.com>
Reviewed-by: Tony Luck <tony.luck@intel.com>
Link: https://patch.msgid.link/8d028bbea582dc382a4cc166b235f75bd5901aea.1783963505.git.reinette.chatre@intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/resctrl/rdtgroup.c | 19 ++++++++++++++-----
1 file changed, 14 insertions(+), 5 deletions(-)
diff --git a/fs/resctrl/rdtgroup.c b/fs/resctrl/rdtgroup.c
index 08e26c0c9fb9c..1f81bd6711551 100644
--- a/fs/resctrl/rdtgroup.c
+++ b/fs/resctrl/rdtgroup.c
@@ -2528,15 +2528,24 @@ static void rdtgroup_kn_get(struct rdtgroup *rdtgrp, struct kernfs_node *kn)
static void rdtgroup_kn_put(struct rdtgroup *rdtgrp, struct kernfs_node *kn)
{
- if (atomic_dec_and_test(&rdtgrp->waitcount) &&
- (rdtgrp->flags & RDT_DELETED)) {
+ bool needs_free;
+
+ if (!atomic_dec_and_mutex_lock(&rdtgrp->waitcount, &rdtgroup_mutex)) {
+ kernfs_unbreak_active_protection(kn);
+ return;
+ }
+
+ needs_free = rdtgrp->flags & RDT_DELETED;
+
+ mutex_unlock(&rdtgroup_mutex);
+
+ kernfs_unbreak_active_protection(kn);
+
+ if (needs_free) {
if (rdtgrp->mode == RDT_MODE_PSEUDO_LOCKSETUP ||
rdtgrp->mode == RDT_MODE_PSEUDO_LOCKED)
rdtgroup_pseudo_lock_remove(rdtgrp);
- kernfs_unbreak_active_protection(kn);
rdtgroup_remove(rdtgrp);
- } else {
- kernfs_unbreak_active_protection(kn);
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0364/1518] perf zstd: Fix compression error path in zstd_compress_stream_to_records()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (362 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0363/1518] fs/resctrl: Prevent use-after-free in rdtgroup_kn_put() Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0365/1518] perf record: Return the written size from process_comp_header() Greg Kroah-Hartman
` (634 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ian Rogers, Jiri Olsa, Namhyung Kim,
Arnaldo Carvalho de Melo, Sasha Levin, sashiko-bot
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnaldo Carvalho de Melo <acme@redhat.com>
[ Upstream commit a18908b5056b8fdb2c44505f0c57ff05865740a3 ]
The error fallback does memcpy(dst, src, src_size) intending to store
uncompressed data when compression fails, but this has three bugs:
1. dst has been advanced past the record header (and potentially
past earlier compressed records), so the copy writes to the
wrong offset in the output buffer.
2. src still points to the start of the input, not to the
remaining uncompressed data at src + input.pos. On a second
or later iteration, previously compressed data would be
duplicated.
3. No check that dst_size >= src_size — if the remaining output
space is smaller, this is an out-of-bounds write.
Replace with return -1 after resetting the ZSTD compression
context via ZSTD_initCStream(). The -1 propagates through
zstd_compress() -> record__pushfn() -> perf_mmap__push() to the
recording loop, which breaks out and terminates recording.
Add an out_child_no_flush label in __cmd_record() so the
mmap-read failure path skips the final record__mmap_read_all()
flush — retrying the same read that just failed would just fail
again, and the flush is only useful when the mmap data is intact
but the control path (auxtrace, switch_output) had an error.
Consolidate all error paths through a single 'reset' label to
ensure the compression context is always reset on failure —
including the output-buffer-full path, where a bare return
without resetting would leave stale stream state that corrupts
output if the caller retries.
Also guard against process_header() writing the event header
before the buffer-full check: add a sizeof(perf_event_header)
pre-check so the callback never writes past the output buffer.
Guard against ZSTD making no progress: if output.pos is zero
after ZSTD_compressStream(), calling process_header(record, 0)
would re-trigger header initialization, double-subtracting the
header size from dst_size and underflowing the unsigned counter.
Also fix two pre-existing issues in the same function:
- Add a dst_size guard before subtracting the record header
size: if the output buffer is nearly full, the unsigned
dst_size -= size underflows to a huge value, causing
ZSTD_compressStream to write past the buffer boundary.
- Check the ZSTD_initCStream() return value and log an error
if the context reset itself fails.
Reported-by: sashiko-bot@kernel.org # Running on a local machine
Reviewed-by: Ian Rogers <irogers@google.com>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Namhyung Kim <namhyung@kernel.org>
Assisted-by: Claude:claude-opus-4.6-1m
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Stable-dep-of: ad40a000ea59 ("perf record: Fix multiple PERF_RECORD_COMPRESSED2 records per push")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/builtin-record.c | 6 +++++-
tools/perf/util/zstd.c | 27 +++++++++++++++++++++++++--
2 files changed, 30 insertions(+), 3 deletions(-)
diff --git a/tools/perf/builtin-record.c b/tools/perf/builtin-record.c
index c82b9720c9296..79603329b8897 100644
--- a/tools/perf/builtin-record.c
+++ b/tools/perf/builtin-record.c
@@ -2702,7 +2702,7 @@ static int __cmd_record(struct record *rec, int argc, const char **argv)
trigger_error(&auxtrace_snapshot_trigger);
trigger_error(&switch_output_trigger);
err = -1;
- goto out_child;
+ goto out_child_no_flush;
}
if (auxtrace_record__snapshot_started) {
@@ -2849,6 +2849,10 @@ static int __cmd_record(struct record *rec, int argc, const char **argv)
out_child:
record__stop_threads(rec);
record__mmap_read_all(rec, true);
+ goto out_free_threads;
+out_child_no_flush:
+ /* mmap read already failed — retrying would just fail again */
+ record__stop_threads(rec);
out_free_threads:
record__free_thread_data(rec);
evlist__finalize_ctlfd(rec->evlist);
diff --git a/tools/perf/util/zstd.c b/tools/perf/util/zstd.c
index 57027e0ac7b65..ecda9deb53b73 100644
--- a/tools/perf/util/zstd.c
+++ b/tools/perf/util/zstd.c
@@ -1,6 +1,7 @@
// SPDX-License-Identifier: GPL-2.0
#include <string.h>
+#include <linux/perf_event.h>
#include "util/compress.h"
#include "util/debug.h"
@@ -54,7 +55,13 @@ ssize_t zstd_compress_stream_to_records(struct zstd_data *data, void *dst, size_
while (input.pos < input.size) {
record = dst;
+ /* process_header writes the event header into record */
+ if (dst_size < sizeof(struct perf_event_header))
+ goto reset;
size = process_header(record, 0);
+ /* Output buffer full — cannot fit even the record header */
+ if (size > dst_size)
+ goto reset;
compressed += size;
dst += size;
dst_size -= size;
@@ -65,10 +72,18 @@ ssize_t zstd_compress_stream_to_records(struct zstd_data *data, void *dst, size_
if (ZSTD_isError(ret)) {
pr_err("failed to compress %ld bytes: %s\n",
(long)src_size, ZSTD_getErrorName(ret));
- memcpy(dst, src, src_size);
- return src_size;
+ goto reset;
}
size = output.pos;
+ /*
+ * No progress: ZSTD couldn't emit any bytes into the
+ * remaining output buffer. Calling process_header
+ * with size=0 would re-trigger header initialization,
+ * double-subtracting the header size from dst_size and
+ * underflowing the unsigned counter.
+ */
+ if (size == 0)
+ goto reset;
size = process_header(record, size);
compressed += size;
dst += size;
@@ -76,6 +91,14 @@ ssize_t zstd_compress_stream_to_records(struct zstd_data *data, void *dst, size_
}
return compressed;
+
+reset:
+ /* Reset so the context is usable if the caller retries */
+ ret = ZSTD_initCStream(data->cstream, data->comp_level);
+ if (ZSTD_isError(ret))
+ pr_err("failed to reset compression context: %s\n",
+ ZSTD_getErrorName(ret));
+ return -1;
}
size_t zstd_decompress_stream(struct zstd_data *data, void *src, size_t src_size,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0365/1518] perf record: Return the written size from process_comp_header()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (363 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0364/1518] perf zstd: Fix compression error path in zstd_compress_stream_to_records() Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0366/1518] perf record: Fix multiple PERF_RECORD_COMPRESSED2 records per push Greg Kroah-Hartman
` (633 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dmitry Ilvokhin, Namhyung Kim,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Ilvokhin <d@ilvokhin.com>
[ Upstream commit 757155c142f2bc9793e888ab101a5eea2d53f8f8 ]
process_comp_header() is called from zstd_compress_stream_to_records()
twice per record: once with data_size == 0 to write the record header,
and once with the payload size to finalize it. It returns the increment
it was passed, and the loop separately decides whether a record still
fits by comparing the remaining 'dst_size' against the header size.
With the fit check split from the code that writes the record,
process_comp_header() cannot reject a record on its own, so any bytes it
writes into 'dst' have to be bounds-checked by the caller instead of
where they are produced.
Pass the space left in 'dst' to process_comp_header(), let it return the
number of bytes written or -1 when the header does not fit, and account
the compressed payload in the loop.
No functional change intended.
Signed-off-by: Dmitry Ilvokhin <d@ilvokhin.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Stable-dep-of: ad40a000ea59 ("perf record: Fix multiple PERF_RECORD_COMPRESSED2 records per push")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/builtin-record.c | 17 +++++++++++++----
tools/perf/util/compress.h | 6 ++++--
tools/perf/util/zstd.c | 25 ++++++++++++++-----------
3 files changed, 31 insertions(+), 17 deletions(-)
diff --git a/tools/perf/builtin-record.c b/tools/perf/builtin-record.c
index 79603329b8897..6c558b60aa9a1 100644
--- a/tools/perf/builtin-record.c
+++ b/tools/perf/builtin-record.c
@@ -1550,16 +1550,25 @@ static void record__adjust_affinity(struct record *rec, struct mmap *map)
}
}
-static size_t process_comp_header(void *record, size_t increment)
+/*
+ * Called once with data_size == 0 to start a record, then once with
+ * data_size == compressed payload size to finalize.
+ * Returns the bytes written, or -1 if it won't fit.
+ */
+static ssize_t process_comp_header(void *record, size_t dst_size,
+ size_t data_size)
{
struct perf_record_compressed2 *event = record;
size_t size = sizeof(*event);
- if (increment) {
- event->header.size += increment;
- return increment;
+ if (data_size) {
+ event->header.size += data_size;
+ return 0;
}
+ if (size > dst_size)
+ return -1;
+
event->header.type = PERF_RECORD_COMPRESSED2;
event->header.size = size;
diff --git a/tools/perf/util/compress.h b/tools/perf/util/compress.h
index 6cfecfca16f24..ec6c38129e248 100644
--- a/tools/perf/util/compress.h
+++ b/tools/perf/util/compress.h
@@ -54,7 +54,8 @@ int zstd_fini(struct zstd_data *data);
ssize_t zstd_compress_stream_to_records(struct zstd_data *data, void *dst, size_t dst_size,
void *src, size_t src_size, size_t max_record_size,
- size_t process_header(void *record, size_t increment));
+ ssize_t process_header(void *record, size_t dst_size,
+ size_t data_size));
size_t zstd_decompress_stream(struct zstd_data *data, void *src, size_t src_size,
void *dst, size_t dst_size);
@@ -75,7 +76,8 @@ ssize_t zstd_compress_stream_to_records(struct zstd_data *data __maybe_unused,
void *dst __maybe_unused, size_t dst_size __maybe_unused,
void *src __maybe_unused, size_t src_size __maybe_unused,
size_t max_record_size __maybe_unused,
- size_t process_header(void *record, size_t increment) __maybe_unused)
+ ssize_t process_header(void *record, size_t dst_size,
+ size_t data_size) __maybe_unused)
{
return 0;
}
diff --git a/tools/perf/util/zstd.c b/tools/perf/util/zstd.c
index ecda9deb53b73..d17726b8fb50a 100644
--- a/tools/perf/util/zstd.c
+++ b/tools/perf/util/zstd.c
@@ -31,9 +31,11 @@ int zstd_fini(struct zstd_data *data)
ssize_t zstd_compress_stream_to_records(struct zstd_data *data, void *dst, size_t dst_size,
void *src, size_t src_size, size_t max_record_size,
- size_t process_header(void *record, size_t increment))
+ ssize_t process_header(void *record, size_t dst_size,
+ size_t data_size))
{
- size_t ret, size, compressed = 0;
+ size_t ret, compressed = 0;
+ ssize_t size;
ZSTD_inBuffer input = { src, src_size, 0 };
ZSTD_outBuffer output;
void *record;
@@ -55,12 +57,9 @@ ssize_t zstd_compress_stream_to_records(struct zstd_data *data, void *dst, size_
while (input.pos < input.size) {
record = dst;
- /* process_header writes the event header into record */
- if (dst_size < sizeof(struct perf_event_header))
- goto reset;
- size = process_header(record, 0);
+ size = process_header(record, dst_size, 0);
/* Output buffer full — cannot fit even the record header */
- if (size > dst_size)
+ if (size < 0)
goto reset;
compressed += size;
dst += size;
@@ -74,17 +73,21 @@ ssize_t zstd_compress_stream_to_records(struct zstd_data *data, void *dst, size_
(long)src_size, ZSTD_getErrorName(ret));
goto reset;
}
- size = output.pos;
+ compressed += output.pos;
+ dst += output.pos;
+ dst_size -= output.pos;
/*
* No progress: ZSTD couldn't emit any bytes into the
* remaining output buffer. Calling process_header
- * with size=0 would re-trigger header initialization,
+ * with output.pos=0 would re-trigger header initialization,
* double-subtracting the header size from dst_size and
* underflowing the unsigned counter.
*/
- if (size == 0)
+ if (output.pos == 0)
+ goto reset;
+ size = process_header(record, dst_size, output.pos);
+ if (size < 0)
goto reset;
- size = process_header(record, size);
compressed += size;
dst += size;
dst_size -= size;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0366/1518] perf record: Fix multiple PERF_RECORD_COMPRESSED2 records per push
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (364 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0365/1518] perf record: Return the written size from process_comp_header() Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0367/1518] rpmsg: glink: remove duplicate code for rpmsg device remove Greg Kroah-Hartman
` (632 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Farid Zakaria, Dmitry Ilvokhin,
Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Ilvokhin <d@ilvokhin.com>
[ Upstream commit ad40a000ea598f316ddc0e81e5acc77cc3b1fae0 ]
With Zstd compression enabled ('perf record -z'), a single mmap push
whose compressed output exceeds the maximum record size makes
zstd_compress_stream_to_records() emit several PERF_RECORD_COMPRESSED2
records back to back. record__pushfn() however rewrote only the first
record's header to describe the whole blob as one record:
event->data_size = compressed - sizeof(struct perf_record_compressed2);
event->header.size = PERF_ALIGN(compressed, sizeof(u64));
padding = event->header.size - compressed;
...
record__write(rec, map, &pad, padding);
perf_event_header::size is a __u16, so once the compressed blob no
longer fits in it the header.size assignment truncates and 'padding'
(size_t) underflows. write() is then handed that bogus length and fails
with EFAULT, aborting the recording:
failed to write perf data, error: Bad address
The bytes that did reach the file are mis-framed, so reading it back
cannot be decompressed.
This is easy to hit with a high event rate and a large buffer, e.g.:
perf record -z -F max -m 32M --per-thread -- perf test -w thloop 5 1
The single-record fixup is wrong by construction: because header.size is
16 bits a compressed record cannot exceed 64KB, so the compressor must
split a push into a chain of records, and the session reader already
consumes them as such.
Frame each record where it is produced instead: make
process_comp_header() set the per-record data_size, 8-byte-align
header.size and zero the trailing padding, and let record__pushfn()
write the resulting blob, as the AIO path already does. Reduce
max_record_size by sizeof(u64) so the per-record alignment padding
cannot push header.size past its u16 field. process_comp_header()
returns -1 when that padding would not fit the space left in 'dst', so
the compressor stops instead of overrunning the output buffer.
There is no on-disk format change; a perf.data written by the fixed tool
is still read by existing perf.
Fixes: 208c0e168344 ("perf record: Add 8-byte aligned event type PERF_RECORD_COMPRESSED2")
Reported-by: Farid Zakaria <fmzakari@meta.com>
Signed-off-by: Dmitry Ilvokhin <d@ilvokhin.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/builtin-record.c | 38 +++++------
.../record+zstd_comp_decomp_multi_record.sh | 63 +++++++++++++++++++
2 files changed, 83 insertions(+), 18 deletions(-)
create mode 100755 tools/perf/tests/shell/record+zstd_comp_decomp_multi_record.sh
diff --git a/tools/perf/builtin-record.c b/tools/perf/builtin-record.c
index 6c558b60aa9a1..87cff5f5a99c1 100644
--- a/tools/perf/builtin-record.c
+++ b/tools/perf/builtin-record.c
@@ -63,6 +63,7 @@
#include <poll.h>
#include <pthread.h>
#include <unistd.h>
+#include <string.h>
#ifndef HAVE_GETTID
#include <syscall.h>
#endif
@@ -652,27 +653,14 @@ static int record__pushfn(struct mmap *map, void *to, void *bf, size_t size)
struct record *rec = to;
if (record__comp_enabled(rec)) {
- struct perf_record_compressed2 *event = map->data;
- size_t padding = 0;
- u8 pad[8] = {0};
ssize_t compressed = zstd_compress(rec->session, map, map->data,
mmap__mmap_len(map), bf, size);
if (compressed < 0)
return (int)compressed;
- bf = event;
thread->samples++;
-
- /*
- * The record from `zstd_compress` is not 8 bytes aligned, which would cause asan
- * error. We make it aligned here.
- */
- event->data_size = compressed - sizeof(struct perf_record_compressed2);
- event->header.size = PERF_ALIGN(compressed, sizeof(u64));
- padding = event->header.size - compressed;
- return record__write(rec, map, bf, compressed) ||
- record__write(rec, map, &pad, padding);
+ return record__write(rec, map, map->data, compressed);
}
thread->samples++;
@@ -1552,7 +1540,8 @@ static void record__adjust_affinity(struct record *rec, struct mmap *map)
/*
* Called once with data_size == 0 to start a record, then once with
- * data_size == compressed payload size to finalize.
+ * data_size == compressed payload size to finalize and 8-byte-pad it
+ * (unaligned records trip ASan in the reader).
* Returns the bytes written, or -1 if it won't fit.
*/
static ssize_t process_comp_header(void *record, size_t dst_size,
@@ -1562,8 +1551,15 @@ static ssize_t process_comp_header(void *record, size_t dst_size,
size_t size = sizeof(*event);
if (data_size) {
- event->header.size += data_size;
- return 0;
+ size_t padding;
+
+ event->data_size = data_size;
+ event->header.size = PERF_ALIGN(size + data_size, sizeof(u64));
+ padding = event->header.size - size - data_size;
+ if (padding > dst_size)
+ return -1;
+ memset(record + size + data_size, 0, padding);
+ return padding;
}
if (size > dst_size)
@@ -1571,6 +1567,7 @@ static ssize_t process_comp_header(void *record, size_t dst_size,
event->header.type = PERF_RECORD_COMPRESSED2;
event->header.size = size;
+ event->data_size = 0;
return size;
}
@@ -1579,7 +1576,12 @@ static ssize_t zstd_compress(struct perf_session *session, struct mmap *map,
void *dst, size_t dst_size, void *src, size_t src_size)
{
ssize_t compressed;
- size_t max_record_size = PERF_SAMPLE_MAX_SIZE - sizeof(struct perf_record_compressed2) - 1;
+ /*
+ * Reserve space so per-record PERF_ALIGN() padding keeps header.size
+ * within u16.
+ */
+ size_t max_record_size = PERF_SAMPLE_MAX_SIZE
+ - sizeof(struct perf_record_compressed2) - sizeof(u64);
struct zstd_data *zstd_data = &session->zstd_data;
if (map && map->file)
diff --git a/tools/perf/tests/shell/record+zstd_comp_decomp_multi_record.sh b/tools/perf/tests/shell/record+zstd_comp_decomp_multi_record.sh
new file mode 100755
index 0000000000000..c05ace8214ca3
--- /dev/null
+++ b/tools/perf/tests/shell/record+zstd_comp_decomp_multi_record.sh
@@ -0,0 +1,63 @@
+#!/bin/bash
+# Zstd perf.data compression/decompression of multi-record data
+# SPDX-License-Identifier: GPL-2.0
+
+perfdata=$(mktemp /tmp/__perf_test.perf.data.XXXXX)
+recout=$(mktemp /tmp/__perf_test.zstd.rec.XXXXX)
+injout=$(mktemp /tmp/__perf_test.zstd.inj.XXXXX)
+perf_tool=perf
+
+cleanup() {
+ rm -f "${perfdata}" "${perfdata}".old "${perfdata}".decomp "${recout}" "${injout}"
+}
+trap cleanup EXIT TERM INT
+
+skip_if_no_z_record() {
+ $perf_tool record -h 2>&1 | grep -q -- '-z, --compression-level'
+}
+
+collect_z_record() {
+ echo "Collecting compressed record file:"
+ [ "$(uname -m)" != s390x ] && gflag='-g'
+ $perf_tool record -o "${perfdata}" $gflag -z -F max -m 32M --per-thread -- \
+ $perf_tool test -w thloop 5 1 \
+ >/dev/null 2>"${recout}"
+}
+
+check_record() {
+ echo "Checking record did not fail to write data:"
+ if grep -q "failed to write perf data" "${recout}"; then
+ cat "${recout}"
+ return 1
+ fi
+}
+
+check_decompress() {
+ echo "Checking compressed file decompresses cleanly:"
+ if ! $perf_tool inject -i "${perfdata}" -o "${perfdata}".decomp 2>"${injout}"; then
+ cat "${injout}"
+ return 1
+ fi
+ if grep -Eqi "decompress|corrupt|failed to process type" "${injout}"; then
+ cat "${injout}"
+ return 1
+ fi
+}
+
+skip_if_no_z_record || exit 2
+collect_z_record
+check_record || exit 1
+
+# Need >1 record, else the multi-record path wasn't exercised.
+# Skip rather than pass/fail spuriously.
+nr=$($perf_tool report -i "${perfdata}" --stats 2>/dev/null |
+ awk '/COMPRESSED2 events:/ { print $3 }')
+if [ -z "${nr}" ] || [ "${nr}" -lt 2 ]; then
+ echo "less than two compressed records (${nr:-0}), skipping"
+ exit 2
+fi
+echo "Produced ${nr} compressed records"
+
+check_decompress
+err=$?
+exit $err
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0367/1518] rpmsg: glink: remove duplicate code for rpmsg device remove
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (365 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0366/1518] perf record: Fix multiple PERF_RECORD_COMPRESSED2 records per push Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0368/1518] rpmsg: glink: fix deadlock in endpoint destroy during driver detach Greg Kroah-Hartman
` (631 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Srinivas Kandagatla, Bjorn Andersson,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Srinivas Kandagatla <srinivas.kandagatla@oss.qualcomm.com>
[ Upstream commit 112766cdf2e5ea0a0f72b0304d57a6f74c066670 ]
rpmsg device remove code is duplicated in at-least 2-3 places, add a
helper function to remove this duplicated code.
Signed-off-by: Srinivas Kandagatla <srinivas.kandagatla@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20250822100043.2604794-3-srinivas.kandagatla@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Stable-dep-of: 5a5a48e788e0 ("rpmsg: glink: fix deadlock in endpoint destroy during driver detach")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/rpmsg/qcom_glink_native.c | 43 ++++++++++++-------------------
1 file changed, 16 insertions(+), 27 deletions(-)
diff --git a/drivers/rpmsg/qcom_glink_native.c b/drivers/rpmsg/qcom_glink_native.c
index 833ff9cb8afe6..df9e98d76847b 100644
--- a/drivers/rpmsg/qcom_glink_native.c
+++ b/drivers/rpmsg/qcom_glink_native.c
@@ -1395,11 +1395,23 @@ static int qcom_glink_announce_create(struct rpmsg_device *rpdev)
return 0;
}
+static void qcom_glink_remove_rpmsg_device(struct qcom_glink *glink, struct glink_channel *channel)
+{
+ struct rpmsg_channel_info chinfo;
+
+ if (channel->rpdev) {
+ strscpy_pad(chinfo.name, channel->name, sizeof(chinfo.name));
+ chinfo.src = RPMSG_ADDR_ANY;
+ chinfo.dst = RPMSG_ADDR_ANY;
+ rpmsg_unregister_device(glink->dev, &chinfo);
+ }
+ channel->rpdev = NULL;
+}
+
static void qcom_glink_destroy_ept(struct rpmsg_endpoint *ept)
{
struct glink_channel *channel = to_glink_channel(ept);
struct qcom_glink *glink = channel->glink;
- struct rpmsg_channel_info chinfo;
unsigned long flags;
spin_lock_irqsave(&channel->recv_lock, flags);
@@ -1407,14 +1419,7 @@ static void qcom_glink_destroy_ept(struct rpmsg_endpoint *ept)
spin_unlock_irqrestore(&channel->recv_lock, flags);
/* Decouple the potential rpdev from the channel */
- if (channel->rpdev) {
- strscpy_pad(chinfo.name, channel->name, sizeof(chinfo.name));
- chinfo.src = RPMSG_ADDR_ANY;
- chinfo.dst = RPMSG_ADDR_ANY;
-
- rpmsg_unregister_device(glink->dev, &chinfo);
- }
- channel->rpdev = NULL;
+ qcom_glink_remove_rpmsg_device(glink, channel);
qcom_glink_send_close_req(glink, channel);
}
@@ -1704,7 +1709,6 @@ static int qcom_glink_rx_open(struct qcom_glink *glink, unsigned int rcid,
static void qcom_glink_rx_close(struct qcom_glink *glink, unsigned int rcid)
{
- struct rpmsg_channel_info chinfo;
struct glink_channel *channel;
unsigned long flags;
@@ -1720,14 +1724,7 @@ static void qcom_glink_rx_close(struct qcom_glink *glink, unsigned int rcid)
/* cancel pending rx_done work */
cancel_work_sync(&channel->intent_work);
- if (channel->rpdev) {
- strscpy_pad(chinfo.name, channel->name, sizeof(chinfo.name));
- chinfo.src = RPMSG_ADDR_ANY;
- chinfo.dst = RPMSG_ADDR_ANY;
-
- rpmsg_unregister_device(glink->dev, &chinfo);
- }
- channel->rpdev = NULL;
+ qcom_glink_remove_rpmsg_device(glink, channel);
qcom_glink_send_close_ack(glink, channel);
@@ -1741,7 +1738,6 @@ static void qcom_glink_rx_close(struct qcom_glink *glink, unsigned int rcid)
static void qcom_glink_rx_close_ack(struct qcom_glink *glink, unsigned int lcid)
{
- struct rpmsg_channel_info chinfo;
struct glink_channel *channel;
unsigned long flags;
@@ -1763,14 +1759,7 @@ static void qcom_glink_rx_close_ack(struct qcom_glink *glink, unsigned int lcid)
spin_unlock_irqrestore(&glink->idr_lock, flags);
/* Decouple the potential rpdev from the channel */
- if (channel->rpdev) {
- strscpy(chinfo.name, channel->name, sizeof(chinfo.name));
- chinfo.src = RPMSG_ADDR_ANY;
- chinfo.dst = RPMSG_ADDR_ANY;
-
- rpmsg_unregister_device(glink->dev, &chinfo);
- }
- channel->rpdev = NULL;
+ qcom_glink_remove_rpmsg_device(glink, channel);
kref_put(&channel->refcount, qcom_glink_channel_release);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0368/1518] rpmsg: glink: fix deadlock in endpoint destroy during driver detach
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (366 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0367/1518] rpmsg: glink: remove duplicate code for rpmsg device remove Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0369/1518] iommufd: Simplify iommufd_device_remove_vdev() Greg Kroah-Hartman
` (630 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Deepak Kumar Singh, Vishnu Santhosh,
Bjorn Andersson, Dmitry Baryshkov, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vishnu Santhosh <vishnu.santhosh@oss.qualcomm.com>
[ Upstream commit 5a5a48e788e02fd8a8eb7188ce440572d6c12418 ]
During driver detach, the device core holds the device mutex throughout
the driver's remove callback chain. When the rpmsg endpoint is
destroyed as part of that teardown, the GLINK endpoint destroy
implementation attempts to unregister the underlying rpmsg device.
That unregistration calls device_del(), which tries to re-acquire the
same device mutex already held higher up the stack, causing rmmod to
hang indefinitely.
The deadlock manifests with the following call chain:
[<0>] device_del+0x44/0x414 <- tries to acquire same mutex
[<0>] device_unregister+0x18/0x34
[<0>] rpmsg_unregister_device+0x28/0x4c
[<0>] qcom_glink_remove_rpmsg_device+0x70/0xc0
[<0>] qcom_glink_destroy_ept+0x58/0xbc
[<0>] rpmsg_dev_remove+0x50/0x60
[<0>] device_remove+0x4c/0x80
[<0>] device_release_driver_internal+0x1cc/0x228 <- acquires device mutex
[<0>] driver_detach+0x4c/0x98
[<0>] bus_remove_driver+0x6c/0xbc
[<0>] driver_unregister+0x30/0x60
[<0>] unregister_rpmsg_driver+0x10/0x1c
[<0>] fastrpc_exit+0x28/0x38 [fastrpc]
[<0>] __arm64_sys_delete_module+0x1b8/0x294
[<0>] invoke_syscall+0x48/0x10c
[<0>] el0_svc_common.constprop.0+0xc0/0xe0
[<0>] do_el0_svc+0x1c/0x28
[<0>] el0_svc+0x34/0x108
[<0>] el0t_64_sync_handler+0xa0/0xe4
[<0>] el0t_64_sync+0x198/0x19c
The rpmsg device unregistration inside endpoint destroy is redundant.
In both contexts where endpoint destruction is triggered:
- Driver detach path: the driver core already tears down the rpmsg
device.
- Channel close path: the rpmsg device is already unregistered before
endpoint destruction is reached.
Remove the redundant unregistration to fix the deadlock.
Co-developed-by: Deepak Kumar Singh <deepak.singh@oss.qualcomm.com>
Signed-off-by: Deepak Kumar Singh <deepak.singh@oss.qualcomm.com>
Signed-off-by: Vishnu Santhosh <vishnu.santhosh@oss.qualcomm.com>
Tested-by: Bjorn Andersson <bjorn.andersson@oss.qualcomm.com>
Fixes: a53e356df548 ("rpmsg: glink: fix rpmsg device leak")
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260604-rpmsg-glink-fix-deadlock-destroy-ept-v1-1-b8a54ad1e4fd@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/rpmsg/qcom_glink_native.c | 3 ---
1 file changed, 3 deletions(-)
diff --git a/drivers/rpmsg/qcom_glink_native.c b/drivers/rpmsg/qcom_glink_native.c
index df9e98d76847b..7605fde9e6789 100644
--- a/drivers/rpmsg/qcom_glink_native.c
+++ b/drivers/rpmsg/qcom_glink_native.c
@@ -1418,9 +1418,6 @@ static void qcom_glink_destroy_ept(struct rpmsg_endpoint *ept)
channel->ept.cb = NULL;
spin_unlock_irqrestore(&channel->recv_lock, flags);
- /* Decouple the potential rpdev from the channel */
- qcom_glink_remove_rpmsg_device(glink, channel);
-
qcom_glink_send_close_req(glink, channel);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0369/1518] iommufd: Simplify iommufd_device_remove_vdev()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (367 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0368/1518] rpmsg: glink: fix deadlock in endpoint destroy during driver detach Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0370/1518] cxl/memdev: Fix firmware upload exact-fit handling Greg Kroah-Hartman
` (629 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Peiyang He, Nicolin Chen, Kevin Tian,
Jason Gunthorpe, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jason Gunthorpe <jgg@nvidia.com>
[ Upstream commit 8062148046e1a6417d44e2ed86c04e66c2f4f2a1 ]
Peiyang reports that this function indirectly includes a fault injection
point through iommufd_get_object() that was intended to cover the uAPI use
of object IDs, not in places like this that cannot fail.
On deeper inspection this can be written using a dedicated helper to
obtain a users refcount relying entirely on the xa locking instead of
going through the whole get/put scheme. The new helper doesn't need the
fault injection point.
Fixes: 850f14f5b919 ("iommufd: Destroy vdevice on idevice destroy")
Link: https://patch.msgid.link/r/0-v1-719003d53a5b+38b-iommufd_fault_inj_vdev_jgg@nvidia.com
Reported-by: Peiyang He <peiyang_he@smail.nju.edu.cn>
Closes: https://lore.kernel.org/r/870BB9ADBBEDDD1A+37c5bfab-ad32-4fc5-a302-57c81a8432b5@smail.nju.edu.cn
Reviewed-by: Nicolin Chen <nicolinc@nvidia.com>
Reviewed-by: Kevin Tian <kevin.tian@intel.com>
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/iommu/iommufd/device.c | 13 +++----------
drivers/iommu/iommufd/iommufd_private.h | 9 +--------
drivers/iommu/iommufd/main.c | 20 ++++++++++++++++++++
3 files changed, 24 insertions(+), 18 deletions(-)
diff --git a/drivers/iommu/iommufd/device.c b/drivers/iommu/iommufd/device.c
index c40515bf5017b..3216deab98e39 100644
--- a/drivers/iommu/iommufd/device.c
+++ b/drivers/iommu/iommufd/device.c
@@ -148,29 +148,22 @@ static void iommufd_device_remove_vdev(struct iommufd_device *idev)
if (!idev->vdev)
goto out_unlock;
- vdev = iommufd_get_vdevice(idev->ictx, idev->vdev->obj.id);
+ vdev = idev->vdev;
+
/*
* An ongoing vdev destroy ioctl has removed the vdev from the object
* xarray, but has not finished iommufd_vdevice_destroy() yet as it
* needs the same mutex. We exit the locking then wait on wait_cnt
* reference for the vdev destruction.
*/
- if (IS_ERR(vdev))
- goto out_unlock;
-
- /* Should never happen */
- if (WARN_ON(vdev != idev->vdev)) {
- iommufd_put_object(idev->ictx, &vdev->obj);
+ if (iommufd_try_inc_users(idev->ictx, &vdev->obj))
goto out_unlock;
- }
/*
* vdev is still alive. Hold a users refcount to prevent racing with
* userspace destruction, then use iommufd_object_tombstone_user() to
* destroy it and leave a tombstone.
*/
- refcount_inc(&vdev->obj.users);
- iommufd_put_object(idev->ictx, &vdev->obj);
mutex_unlock(&idev->igroup->lock);
iommufd_object_tombstone_user(idev->ictx, &vdev->obj);
return;
diff --git a/drivers/iommu/iommufd/iommufd_private.h b/drivers/iommu/iommufd/iommufd_private.h
index 53d37e77c4b98..c208563eb367f 100644
--- a/drivers/iommu/iommufd/iommufd_private.h
+++ b/drivers/iommu/iommufd/iommufd_private.h
@@ -181,6 +181,7 @@ static inline bool iommufd_lock_obj(struct iommufd_object *obj)
return true;
}
+int iommufd_try_inc_users(struct iommufd_ctx *ictx, struct iommufd_object *obj);
struct iommufd_object *iommufd_get_object(struct iommufd_ctx *ictx, u32 id,
enum iommufd_object_type type);
static inline void iommufd_put_object(struct iommufd_ctx *ictx,
@@ -695,14 +696,6 @@ void iommufd_vdevice_abort(struct iommufd_object *obj);
int iommufd_hw_queue_alloc_ioctl(struct iommufd_ucmd *ucmd);
void iommufd_hw_queue_destroy(struct iommufd_object *obj);
-static inline struct iommufd_vdevice *
-iommufd_get_vdevice(struct iommufd_ctx *ictx, u32 id)
-{
- return container_of(iommufd_get_object(ictx, id,
- IOMMUFD_OBJ_VDEVICE),
- struct iommufd_vdevice, obj);
-}
-
#ifdef CONFIG_IOMMUFD_TEST
int iommufd_test(struct iommufd_ucmd *ucmd);
void iommufd_selftest_destroy(struct iommufd_object *obj);
diff --git a/drivers/iommu/iommufd/main.c b/drivers/iommu/iommufd/main.c
index ce775fbbae94e..02d06a02d5e67 100644
--- a/drivers/iommu/iommufd/main.c
+++ b/drivers/iommu/iommufd/main.c
@@ -180,6 +180,26 @@ struct iommufd_object *iommufd_get_object(struct iommufd_ctx *ictx, u32 id,
return obj;
}
+/*
+ * Increment the users count of an object outside the context of an ioctl that
+ * has already locked it. The users refcount cannot be increased on an already
+ * created object unless the object is installed in the xarray, otherwise things
+ * are racing with a parallel destruction.
+ */
+int iommufd_try_inc_users(struct iommufd_ctx *ictx, struct iommufd_object *obj)
+{
+ struct iommufd_object *cur;
+
+ xa_lock(&ictx->objects);
+ cur = xa_load(&ictx->objects, obj->id);
+ if (cur == obj)
+ refcount_inc(&obj->users);
+ xa_unlock(&ictx->objects);
+ if (cur != obj)
+ return -EBUSY;
+ return 0;
+}
+
static int iommufd_object_dec_wait(struct iommufd_ctx *ictx,
struct iommufd_object *to_destroy)
{
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0370/1518] cxl/memdev: Fix firmware upload exact-fit handling
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (368 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0369/1518] iommufd: Simplify iommufd_device_remove_vdev() Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0371/1518] cxl/mbox: Break poison list loop on an empty payload Greg Kroah-Hartman
` (628 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Guzebing, Dave Jiang, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guzebing <Guzebing1612@gmail.com>
[ Upstream commit af5035e1b3e400067bb003975936e5407377e7a3 ]
cxl_fw_prepare() classifies a firmware image as a one-shot transfer
only when its Transfer FW input payload is smaller than the mailbox
payload size. An image that exactly fills the payload is therefore
treated as a multi-part transfer.
The firmware loader invokes cxl_fw_write() only once for that image.
Since both offset == 0 and remaining == 0, the multi-part action
selection sends INITIATE, never sends END, and then attempts to activate
the target slot.
Include equality in the one-shot classification so exact-fit images use
the FULL action.
Fixes: 9521875bbe00 ("cxl: add a firmware update mechanism using the sysfs firmware loader")
Signed-off-by: Guzebing <Guzebing1612@gmail.com>
Reviewed-by: Dave Jiang <dave.jiang@intel.com>
Link: https://patch.msgid.link/20260713112744.2543829-1-guzebing1612@gmail.com
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/cxl/core/memdev.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/cxl/core/memdev.c b/drivers/cxl/core/memdev.c
index 4dff7f44d908e..3bb5835aa548e 100644
--- a/drivers/cxl/core/memdev.c
+++ b/drivers/cxl/core/memdev.c
@@ -870,7 +870,7 @@ static enum fw_upload_err cxl_fw_prepare(struct fw_upload *fwl, const u8 *data,
if (!size)
return FW_UPLOAD_ERR_INVALID_SIZE;
- mds->fw.oneshot = struct_size(transfer, data, size) <
+ mds->fw.oneshot = struct_size(transfer, data, size) <=
cxl_mbox->payload_size;
if (cxl_mem_get_fw_info(mds))
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0371/1518] cxl/mbox: Break poison list loop on an empty payload
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (369 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0370/1518] cxl/memdev: Fix firmware upload exact-fit handling Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0372/1518] cxl/pci: Honor -EPROBE_DEFER from component register setup Greg Kroah-Hartman
` (627 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alison Schofield, Dave Jiang,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dave Jiang <dave.jiang@intel.com>
[ Upstream commit 8b301c4afbce4bc3f94528441d8d5ce1366504ad ]
A device that returns count == 0 with CXL_POISON_FLAG_MORE set on every
iteration never advances nr_records, so the max_errors guard never
trips and the do/while loops forever while holding poison.mutex. That
hangs the sysfs-triggered scan thread and blocks all subsequent poison
operations on the device. The existing "Protect against an uncleared
_FLAG_MORE" guard was intended to bound a misbehaving device but does
not cover the count == 0 case.
Stop the loop on an empty payload so a malfunctioning or malicious
device cannot wedge the poison scan.
Link: https://sashiko.dev/#/patchset/20260702090849.47501-1-icheng@nvidia.com?part=3
Fixes: ed83f7ca398b ("cxl/mbox: Add GET_POISON_LIST mailbox command")
Assisted-by: Claude:claude-opus-4-8
Reviewed-by: Alison Schofield <alison.schofield@intel.com>
Link: https://patch.msgid.link/20260709155714.1893280-1-dave.jiang@intel.com
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/cxl/core/mbox.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/drivers/cxl/core/mbox.c b/drivers/cxl/core/mbox.c
index fa775f50fe75e..e1c23aae2a2ed 100644
--- a/drivers/cxl/core/mbox.c
+++ b/drivers/cxl/core/mbox.c
@@ -1449,6 +1449,11 @@ int cxl_mem_get_poison(struct cxl_memdev *cxlmd, u64 offset, u64 len,
if (rc)
break;
+ if (!le16_to_cpu(po->count)) {
+ dev_dbg(&cxlmd->dev, "Poison empty payload!\n");
+ break;
+ }
+
for (int i = 0; i < le16_to_cpu(po->count); i++)
trace_cxl_poison(cxlmd, cxlr, &po->record[i],
po->flags, po->overflow_ts,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0372/1518] cxl/pci: Honor -EPROBE_DEFER from component register setup
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (370 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0371/1518] cxl/mbox: Break poison list loop on an empty payload Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0373/1518] cxl/port: Restart port enumeration when a sibling adds the dport first Greg Kroah-Hartman
` (626 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot, Alison Schofield,
Dave Jiang, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dave Jiang <dave.jiang@intel.com>
[ Upstream commit 430c502c80e542e77bcf97db13ec0e8cdf9addb0 ]
cxl_pci_setup_regs() for CXL_REGLOC_RBI_COMPONENT can return
-EPROBE_DEFER on a Restricted CXL Host (RCD) when the upstream port
has not yet been enumerated and the Component Registers must be
extracted from the RCRB. cxl_pci_probe() treats every non-zero return
from that call as the benign "component registers not found" case,
logs a warning, and continues. The rc is then immediately overwritten
by the subsequent cxl_pci_type3_init_mailbox() call, so the deferral
is silently swallowed.
Return -EPROBE_DEFER instead of continuing so the probe is retried
once the upstream port is available.
Fixes: 733b57f262b0 ("cxl/pci: Early setup RCH dport component registers from RCRB")
Reported-by: sashiko-bot@kernel.org
Closes: https://lore.kernel.org/linux-cxl/ajzhsubot_PSYtHQ@MWDK4CY14F/T/#m063bbf76b1c9c293ade52ab311018ae6bba11a44
Assisted-by: Claude:claude-opus-4-8
Reviewed-by: Alison Schofield <alison.schofield@intel.com>
Link: https://lore.kernel.org/linux-cxl/ajzhsubot_PSYtHQ@MWDK4CY14F/T/#m063bbf76b1c9c293ade52ab311018ae6bba11a44
Link: https://patch.msgid.link/20260706224322.714934-1-dave.jiang@intel.com
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/cxl/pci.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/drivers/cxl/pci.c b/drivers/cxl/pci.c
index 24fb1b230ca02..59c6d503437be 100644
--- a/drivers/cxl/pci.c
+++ b/drivers/cxl/pci.c
@@ -946,10 +946,13 @@ static int cxl_pci_probe(struct pci_dev *pdev, const struct pci_device_id *id)
*/
rc = cxl_pci_setup_regs(pdev, CXL_REGLOC_RBI_COMPONENT,
&cxlds->reg_map);
- if (rc)
+ if (rc) {
+ if (rc == -EPROBE_DEFER)
+ return rc;
dev_warn(&pdev->dev, "No component registers (%d)\n", rc);
- else if (!cxlds->reg_map.component_map.ras.valid)
+ } else if (!cxlds->reg_map.component_map.ras.valid) {
dev_dbg(&pdev->dev, "RAS registers not found\n");
+ }
rc = cxl_map_component_regs(&cxlds->reg_map, &cxlds->regs.component,
BIT(CXL_CM_CAP_CAP_ID_RAS));
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0373/1518] cxl/port: Restart port enumeration when a sibling adds the dport first
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (371 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0372/1518] cxl/pci: Honor -EPROBE_DEFER from component register setup Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0374/1518] hfsplus: validate thread record before delete key rebuild Greg Kroah-Hartman
` (625 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alison Schofield, Li Ming,
Dave Jiang, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alison Schofield <alison.schofield@intel.com>
[ Upstream commit a623128bc2a1c257cbad97d0582f355fbe7be927 ]
Endpoint probes can race while enumerating a shared switch. If a
sibling probe adds the dport first, the losing probe finds the dport
already present, gets -EBUSY, and fails to enumerate the endpoint.
Treat this race the same as the existing port-created case by
restarting the port walk, allowing it to find the existing dport
and continue enumeration.
This race was discovered while testing a cxl_test mixed-granularity
topology, where twelve endpoints behind shared switches are probed in
parallel during module load.
Fixes: 4f06d81e7c6a ("cxl: Defer dport allocation for switch ports")
Signed-off-by: Alison Schofield <alison.schofield@intel.com>
Tested-by: Li Ming <ming.li@zohomail.com>
Reviewed-by: Li Ming <ming.li@zohomail.com>
Link: https://patch.msgid.link/20260714020438.1822669-1-alison.schofield@intel.com
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/cxl/core/port.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/cxl/core/port.c b/drivers/cxl/core/port.c
index c53a13d4f1662..2b9e166ea4e0e 100644
--- a/drivers/cxl/core/port.c
+++ b/drivers/cxl/core/port.c
@@ -1732,8 +1732,8 @@ static int add_port_attach_ep(struct cxl_memdev *cxlmd,
parent_dport, uport_dev,
dport_dev);
if (IS_ERR(dport)) {
- /* Port already exists, restart iteration */
- if (PTR_ERR(dport) == -EAGAIN)
+ /* Port or dport already exists, restart iteration */
+ if (PTR_ERR(dport) == -EAGAIN || PTR_ERR(dport) == -EBUSY)
return 0;
return PTR_ERR(dport);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0374/1518] hfsplus: validate thread record before delete key rebuild
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (372 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0373/1518] cxl/port: Restart port enumeration when a sibling adds the dport first Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0375/1518] wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate Greg Kroah-Hartman
` (624 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kyle Zeng, Viacheslav Dubeyko,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kyle Zeng <kylebot@openai.com>
[ Upstream commit e2ea5cac61acfc11dad22f1d2d4bc71d56c52a20 ]
hfsplus_delete_cat() is called with str == NULL when the last open
reference to an unlinked HFS+ hardlink backing inode is closed. In that
case, the function finds the catalog thread by CNID and rebuilds the
catalog key from thread.nodeName.
That reconstruction path reads thread.nodeName.length directly from the
catalog B-tree into fd.search_key and then copies length * 2 bytes into
fd.search_key->cat.name.unicode. It does not first check that the found
record is a thread record or that its size matches the thread name.
A corrupted image can therefore provide an oversized thread name length
and make hfs_bnode_read() write past the catalog search-key allocation.
Read the CNID record through hfsplus_brec_read_cat(), which bounds the
record read to sizeof(hfsplus_cat_entry) and verifies that a thread
record's size exactly matches nodeName.length. Together, these checks
ensure an accepted thread name fits HFSPLUS_MAX_STRLEN. Reject non-thread
records before building the delete key from the validated thread name.
Share the thread-record-type helper between hfsplus_find_cat() and
hfsplus_delete_cat().
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Assisted-by: Codex:gpt-5.6
Signed-off-by: Kyle Zeng <kylebot@openai.com>
Reviewed-by: Viacheslav Dubeyko <slava@dubeyko.com>
Signed-off-by: Viacheslav Dubeyko <slava@dubeyko.com>
Link: https://lore.kernel.org/r/20260709010203.49664-1-kylebot@openai.com
Signed-off-by: Viacheslav Dubeyko <slava@dubeyko.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/hfsplus/catalog.c | 25 ++++++++++++-------------
fs/hfsplus/hfsplus_fs.h | 6 ++++++
2 files changed, 18 insertions(+), 13 deletions(-)
diff --git a/fs/hfsplus/catalog.c b/fs/hfsplus/catalog.c
index 6c8380f7208df..32eb1283d7d05 100644
--- a/fs/hfsplus/catalog.c
+++ b/fs/hfsplus/catalog.c
@@ -204,7 +204,7 @@ int hfsplus_find_cat(struct super_block *sb, u32 cnid,
return err;
type = be16_to_cpu(tmp.type);
- if (type != HFSPLUS_FOLDER_THREAD && type != HFSPLUS_FILE_THREAD) {
+ if (!is_hfs_thread_record_type(type)) {
pr_err("found bad thread record in catalog\n");
return -EIO;
}
@@ -350,23 +350,22 @@ int hfsplus_delete_cat(u32 cnid, struct inode *dir, const struct qstr *str)
goto out;
if (!str) {
- int len;
+ hfsplus_cat_entry entry = {0};
hfsplus_cat_build_key_with_cnid(sb, fd.search_key, cnid);
- err = hfs_brec_find(&fd, hfs_find_rec_by_key);
+ err = hfsplus_brec_read_cat(&fd, &entry);
if (err)
goto out;
- off = fd.entryoffset +
- offsetof(struct hfsplus_cat_thread, nodeName);
- fd.search_key->cat.parent = cpu_to_be32(dir->i_ino);
- hfs_bnode_read(fd.bnode,
- &fd.search_key->cat.name.length, off, 2);
- len = be16_to_cpu(fd.search_key->cat.name.length) * 2;
- hfs_bnode_read(fd.bnode,
- &fd.search_key->cat.name.unicode,
- off + 2, len);
- fd.search_key->key_len = cpu_to_be16(6 + len);
+ type = be16_to_cpu(entry.type);
+ if (!is_hfs_thread_record_type(type)) {
+ pr_err("found bad thread record in catalog\n");
+ err = -EIO;
+ goto out;
+ }
+
+ hfsplus_cat_build_key_uni(fd.search_key, dir->i_ino,
+ &entry.thread.nodeName);
} else {
err = hfsplus_cat_build_key(sb, fd.search_key, dir->i_ino, str);
if (unlikely(err))
diff --git a/fs/hfsplus/hfsplus_fs.h b/fs/hfsplus/hfsplus_fs.h
index 2da2bd52d200e..e66773cbb3336 100644
--- a/fs/hfsplus/hfsplus_fs.h
+++ b/fs/hfsplus/hfsplus_fs.h
@@ -514,6 +514,12 @@ static inline u32 hfsplus_cat_thread_size(const struct hfsplus_cat_thread *threa
be16_to_cpu(thread->nodeName.length) * sizeof(hfsplus_unichr);
}
+static inline
+bool is_hfs_thread_record_type(u16 type)
+{
+ return type == HFSPLUS_FOLDER_THREAD || type == HFSPLUS_FILE_THREAD;
+}
+
int hfsplus_brec_read_cat(struct hfs_find_data *fd, hfsplus_cat_entry *entry);
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0375/1518] wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (373 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0374/1518] hfsplus: validate thread record before delete key rebuild Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0376/1518] x86/entry/fred: Encode frame pointer on entry Greg Kroah-Hartman
` (623 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Baochen Qiang, Rameshkumar Sundaram,
Jeff Johnson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
[ Upstream commit 12b09e478aa7459b7893a695ef77682202f2da83 ]
ath11k can receive HT/VHT/HE frames whose reported MCS is above the
maximum that can be expressed in the corresponding mac80211 rate space
(e.g. an HE frame reported with MCS 12, while HE tops out at MCS 11).
The frame itself is valid and decodes correctly, but for such a frame
ath11k_dp_rx_h_rate() leaves rx_status->rate_idx set to the out-of-range
value and never assigns rx_status->encoding, so it stays RX_ENC_LEGACY
from the ath11k_dp_rx_h_ppdu() initialization. Once that frame reaches
mac80211 it trips the rate sanity check and the frame is dropped with a
splat:
ath11k_pci 0000:03:00.0: Received with invalid mcs in HE mode 12
WARNING: CPU: 0 PID: 0 at net/mac80211/rx.c:5433 ieee80211_rx_list+0xb0a/0xe90 [mac80211]
Dropping the frame would discard otherwise valid data, so instead cap the
reported MCS to the maximum the rate space can express and deliver the
frame. Set rx_status->encoding before the range check and assign rate_idx
from the capped value, so a frame with an out-of-range MCS no longer
leaves partial or bogus rate metadata behind. Also downgrade the logging
level since they are not treated as invalid frames now. The only loss is
that such a frame is reported as the capped MCS in the rx rate statistics.
Tested-on: WCN6855 hw2.1 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
Fixes: d5c65159f289 ("ath11k: driver for Qualcomm IEEE 802.11ax devices")
Signed-off-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Link: https://patch.msgid.link/20260701-ath11k-invalid-he-mcs-v1-1-7d963080c079@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/ath/ath11k/dp_rx.c | 30 ++++++++++++-------------
1 file changed, 15 insertions(+), 15 deletions(-)
diff --git a/drivers/net/wireless/ath/ath11k/dp_rx.c b/drivers/net/wireless/ath/ath11k/dp_rx.c
index 330446f279cd6..05b11a1b6376c 100644
--- a/drivers/net/wireless/ath/ath11k/dp_rx.c
+++ b/drivers/net/wireless/ath/ath11k/dp_rx.c
@@ -2332,10 +2332,10 @@ static void ath11k_dp_rx_h_rate(struct ath11k *ar, struct hal_rx_desc *rx_desc,
case RX_MSDU_START_PKT_TYPE_11N:
rx_status->encoding = RX_ENC_HT;
if (rate_mcs > ATH11K_HT_MCS_MAX) {
- ath11k_warn(ar->ab,
- "Received with invalid mcs in HT mode %d\n",
- rate_mcs);
- break;
+ ath11k_dbg(ar->ab, ATH11K_DBG_DP_RX,
+ "Received HT frame with out-of-range mcs %d, capping to %d\n",
+ rate_mcs, ATH11K_HT_MCS_MAX);
+ rate_mcs = ATH11K_HT_MCS_MAX;
}
rx_status->rate_idx = rate_mcs + (8 * (nss - 1));
if (sgi)
@@ -2344,13 +2344,13 @@ static void ath11k_dp_rx_h_rate(struct ath11k *ar, struct hal_rx_desc *rx_desc,
break;
case RX_MSDU_START_PKT_TYPE_11AC:
rx_status->encoding = RX_ENC_VHT;
- rx_status->rate_idx = rate_mcs;
if (rate_mcs > ATH11K_VHT_MCS_MAX) {
- ath11k_warn(ar->ab,
- "Received with invalid mcs in VHT mode %d\n",
- rate_mcs);
- break;
+ ath11k_dbg(ar->ab, ATH11K_DBG_DP_RX,
+ "Received VHT frame with out-of-range mcs %d, capping to %d\n",
+ rate_mcs, ATH11K_VHT_MCS_MAX);
+ rate_mcs = ATH11K_VHT_MCS_MAX;
}
+ rx_status->rate_idx = rate_mcs;
rx_status->nss = nss;
if (sgi)
rx_status->enc_flags |= RX_ENC_FLAG_SHORT_GI;
@@ -2360,14 +2360,14 @@ static void ath11k_dp_rx_h_rate(struct ath11k *ar, struct hal_rx_desc *rx_desc,
rx_status->enc_flags |= RX_ENC_FLAG_LDPC;
break;
case RX_MSDU_START_PKT_TYPE_11AX:
- rx_status->rate_idx = rate_mcs;
+ rx_status->encoding = RX_ENC_HE;
if (rate_mcs > ATH11K_HE_MCS_MAX) {
- ath11k_warn(ar->ab,
- "Received with invalid mcs in HE mode %d\n",
- rate_mcs);
- break;
+ ath11k_dbg(ar->ab, ATH11K_DBG_DP_RX,
+ "Received HE frame with out-of-range mcs %d, capping to %d\n",
+ rate_mcs, ATH11K_HE_MCS_MAX);
+ rate_mcs = ATH11K_HE_MCS_MAX;
}
- rx_status->encoding = RX_ENC_HE;
+ rx_status->rate_idx = rate_mcs;
rx_status->nss = nss;
rx_status->he_gi = ath11k_mac_he_gi_to_nl80211_he_gi(sgi);
rx_status->bw = ath11k_mac_bw_to_mac80211_bw(bw);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0376/1518] x86/entry/fred: Encode frame pointer on entry
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (374 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0375/1518] wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0377/1518] firmware: arm_scmi: Publish channel state before callbacks Greg Kroah-Hartman
` (622 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Stevens, Dave Hansen,
H. Peter Anvin (Intel), Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Stevens <stevensd@google.com>
[ Upstream commit dab01c597f6bd40e0efe7da967b8374ca1971b79 ]
Add missing ENCODE_FRAME_POINTER macro invocation into FRED_ENTER macro,
to prevent the unwinder from encountering a NULL stack frame pointer
when CONFIG_UNWINDER_FRAME_POINTER is enabled
Fixes: 14619d912b65 ("x86/fred: FRED entry/exit and dispatch code")
Signed-off-by: David Stevens <stevensd@google.com>
Signed-off-by: Dave Hansen <dave.hansen@linux.intel.com>
Acked-by: H. Peter Anvin (Intel) <hpa@zytor.com>
Link: https://patch.msgid.link/20260424191456.2679717-12-stevensd@google.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/entry/entry_64_fred.S | 2 ++
1 file changed, 2 insertions(+)
diff --git a/arch/x86/entry/entry_64_fred.S b/arch/x86/entry/entry_64_fred.S
index fafbd3e68cb87..3b40519602077 100644
--- a/arch/x86/entry/entry_64_fred.S
+++ b/arch/x86/entry/entry_64_fred.S
@@ -6,6 +6,7 @@
#include <linux/export.h>
#include <asm/asm.h>
+#include <asm/frame.h>
#include <asm/fred.h>
#include <asm/segment.h>
@@ -18,6 +19,7 @@
UNWIND_HINT_END_OF_STACK
ANNOTATE_NOENDBR
PUSH_AND_CLEAR_REGS
+ ENCODE_FRAME_POINTER
movq %rsp, %rdi /* %rdi -> pt_regs */
.endm
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0377/1518] firmware: arm_scmi: Publish channel state before callbacks
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (375 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0376/1518] x86/entry/fred: Encode frame pointer on entry Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0378/1518] firmware: arm_scmi: Unregister device notifier before IDR teardown Greg Kroah-Hartman
` (621 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Sudeep Holla, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sudeep Holla <sudeep.holla@kernel.org>
[ Upstream commit 0314900dcdde044af0208fed212035dbfaa55843 ]
Transport setup can enable callbacks before the setup routine returns.
mailbox_chan_setup() registers the mailbox client with
mbox_request_channel(), and the mailbox controller startup path can enable
interrupt delivery before SCMI mailbox channel state has been published.
Similarly, smc_chan_setup() requests the optional A2P completion IRQ before
the SMC transport has made its cinfo pointer visible.
If a pending or spurious callback fires in those windows, the transport RX
callback can dereference a NULL transport cinfo pointer. Publishing only
the transport-private pointer is not sufficient either: an early callback
can enter the SCMI core before scmi_chan_setup() has assigned
cinfo->handle.
The core derives scmi_info from cinfo->handle in the RX path, so a NULL
handle can still fault even when the transport-private cinfo is valid.
Assign cinfo->handle before invoking the transport setup callback. Publish
the mailbox and SMC transport-private channel state before requesting the
mailbox channels or IRQ, and clear the early-published pointers again on
setup failure. Also unwind mailbox setup devres resources on failure so an
optional RX setup error that is ignored by the core does not leave stale
transport state behind.
Fixes: 5c8a47a5a91d ("firmware: arm_scmi: Make scmi core independent of the transport type")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://patch.msgid.link/20260714-scmi_core_fixes-v6-1-3afe499d46e3@kernel.org
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/arm_scmi/driver.c | 2 +-
drivers/firmware/arm_scmi/transports/mailbox.c | 18 +++++++++++++-----
drivers/firmware/arm_scmi/transports/smc.c | 15 +++++++++------
3 files changed, 23 insertions(+), 12 deletions(-)
diff --git a/drivers/firmware/arm_scmi/driver.c b/drivers/firmware/arm_scmi/driver.c
index 5caa9191a8d1a..f60dbaf7f3401 100644
--- a/drivers/firmware/arm_scmi/driver.c
+++ b/drivers/firmware/arm_scmi/driver.c
@@ -2693,6 +2693,7 @@ static int scmi_chan_setup(struct scmi_info *info, struct device_node *of_node,
cinfo->id = prot_id;
cinfo->dev = &tdev->dev;
+ cinfo->handle = &info->handle;
ret = info->desc->ops->chan_setup(cinfo, info->dev, tx);
if (ret) {
of_node_put(of_node);
@@ -2725,7 +2726,6 @@ static int scmi_chan_setup(struct scmi_info *info, struct device_node *of_node,
return ret;
}
- cinfo->handle = &info->handle;
return 0;
}
diff --git a/drivers/firmware/arm_scmi/transports/mailbox.c b/drivers/firmware/arm_scmi/transports/mailbox.c
index ae0f67e6cc45f..b6459fbb81513 100644
--- a/drivers/firmware/arm_scmi/transports/mailbox.c
+++ b/drivers/firmware/arm_scmi/transports/mailbox.c
@@ -211,13 +211,18 @@ static int mailbox_chan_setup(struct scmi_chan_info *cinfo, struct device *dev,
cl->tx_block = false;
cl->knows_txdone = tx;
+ cinfo->transport_info = smbox;
+ smbox->cinfo = cinfo;
+ mutex_init(&smbox->chan_lock);
+
smbox->chan = mbox_request_channel(cl, tx ? 0 : p2a_chan);
if (IS_ERR(smbox->chan)) {
ret = PTR_ERR(smbox->chan);
+ smbox->chan = NULL;
if (ret != -EPROBE_DEFER)
dev_err(cdev,
"failed to request SCMI %s mailbox\n", desc);
- return ret;
+ goto err_clear_cinfo;
}
/* Additional unidirectional channel for TX if needed */
@@ -241,11 +246,14 @@ static int mailbox_chan_setup(struct scmi_chan_info *cinfo, struct device *dev,
}
}
- cinfo->transport_info = smbox;
- smbox->cinfo = cinfo;
- mutex_init(&smbox->chan_lock);
-
return 0;
+
+err_clear_cinfo:
+ cinfo->transport_info = NULL;
+ smbox->cinfo = NULL;
+ devm_iounmap(dev, smbox->shmem);
+ devm_kfree(dev, smbox);
+ return ret;
}
static int mailbox_chan_free(int id, void *p, void *data)
diff --git a/drivers/firmware/arm_scmi/transports/smc.c b/drivers/firmware/arm_scmi/transports/smc.c
index 21abb571e4f2f..1fce3ccdeb7fc 100644
--- a/drivers/firmware/arm_scmi/transports/smc.c
+++ b/drivers/firmware/arm_scmi/transports/smc.c
@@ -172,6 +172,13 @@ static int smc_chan_setup(struct scmi_chan_info *cinfo, struct device *dev,
scmi_info->param_page = SHMEM_PAGE(res.start);
scmi_info->param_offset = SHMEM_OFFSET(res.start);
}
+
+ scmi_info->func_id = func_id;
+ scmi_info->cap_id = cap_id;
+ scmi_info->cinfo = cinfo;
+ smc_channel_lock_init(scmi_info);
+ cinfo->transport_info = scmi_info;
+
/*
* If there is an interrupt named "a2p", then the service and
* completion of a message is signaled by an interrupt rather than by
@@ -183,18 +190,14 @@ static int smc_chan_setup(struct scmi_chan_info *cinfo, struct device *dev,
IRQF_NO_SUSPEND, dev_name(dev), scmi_info);
if (ret) {
dev_err(dev, "failed to setup SCMI smc irq\n");
+ cinfo->transport_info = NULL;
+ scmi_info->cinfo = NULL;
return ret;
}
} else {
cinfo->no_completion_irq = true;
}
- scmi_info->func_id = func_id;
- scmi_info->cap_id = cap_id;
- scmi_info->cinfo = cinfo;
- smc_channel_lock_init(scmi_info);
- cinfo->transport_info = scmi_info;
-
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0378/1518] firmware: arm_scmi: Unregister device notifier before IDR teardown
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (376 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0377/1518] firmware: arm_scmi: Publish channel state before callbacks Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0379/1518] firmware: arm_scmi: Quiesce notifications before teardown Greg Kroah-Hartman
` (620 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Sudeep Holla, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sudeep Holla <sudeep.holla@kernel.org>
[ Upstream commit 66a0bbf30cc14140fe13f63cd594a7c1ee352b75 ]
The requested-devices notifier looks up protocol fwnodes from the
active_protocols IDR. During remove, unregister the notifier before
releasing and destroying active_protocols so no notifier callback can race
with the IDR teardown.
Keep the bus notifier registered until after the protocol state is torn
down, matching the existing remove ordering for SCMI bus users.
Fixes: 53b8c25df708 ("firmware: arm_scmi: Add common notifier helpers")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://patch.msgid.link/20260714-scmi_core_fixes-v6-2-3afe499d46e3@kernel.org
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/arm_scmi/driver.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/drivers/firmware/arm_scmi/driver.c b/drivers/firmware/arm_scmi/driver.c
index f60dbaf7f3401..69f88b41e2b2d 100644
--- a/drivers/firmware/arm_scmi/driver.c
+++ b/drivers/firmware/arm_scmi/driver.c
@@ -3309,6 +3309,9 @@ static void scmi_remove(struct platform_device *pdev)
list_del(&info->node);
mutex_unlock(&scmi_list_mutex);
+ blocking_notifier_chain_unregister(&scmi_requested_devices_nh,
+ &info->dev_req_nb);
+
scmi_notification_exit(&info->handle);
mutex_lock(&info->protocols_mtx);
@@ -3319,8 +3322,6 @@ static void scmi_remove(struct platform_device *pdev)
of_node_put(child);
idr_destroy(&info->active_protocols);
- blocking_notifier_chain_unregister(&scmi_requested_devices_nh,
- &info->dev_req_nb);
bus_unregister_notifier(&scmi_bus_type, &info->bus_nb);
/* Safe to free channels since no more users */
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0379/1518] firmware: arm_scmi: Quiesce notifications before teardown
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (377 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0378/1518] firmware: arm_scmi: Unregister device notifier before IDR teardown Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0380/1518] firmware: arm_scmi: Clean up channels on setup failure Greg Kroah-Hartman
` (619 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Sudeep Holla, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sudeep Holla <sudeep.holla@kernel.org>
[ Upstream commit 8e49055d0d495c9c07575ad8e111d9eaf0efb13f ]
scmi_notification_exit() clears and releases the notification instance,
but transport callbacks can still deliver incoming notifications until
the TX/RX channels are freed. During remove, an RX interrupt in that
window can enter scmi_notify() while notification state is being torn
down and then dereference freed memory. The same ordering exists on the
probe error path after notification initialization.
The notification late-init worker has a separate lifetime issue: protocol
event registration queues ni->init_work on the system workqueue, so
destroying ni->notify_wq does not drain that work. If the devres group is
released while init_work is still pending or running, the late-init worker
can dereference the freed notification instance.
Quiesce the notification core before TX/RX channels are torn down, then
clean up the channels before releasing the notification core resources.
Use disable_work_sync() so future late-init queueing is rejected and any
already queued or running late-init work has completed before channel
teardown starts.
Fixes: 1e7cbfaa66d3 ("firmware: arm_scmi: Free mailbox channels if probe fails")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://patch.msgid.link/20260714-scmi_core_fixes-v6-3-3afe499d46e3@kernel.org
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/arm_scmi/driver.c | 13 +++++++------
drivers/firmware/arm_scmi/notify.c | 21 +++++++++++++++++++++
drivers/firmware/arm_scmi/notify.h | 1 +
3 files changed, 29 insertions(+), 6 deletions(-)
diff --git a/drivers/firmware/arm_scmi/driver.c b/drivers/firmware/arm_scmi/driver.c
index 69f88b41e2b2d..529a4e5852e6e 100644
--- a/drivers/firmware/arm_scmi/driver.c
+++ b/drivers/firmware/arm_scmi/driver.c
@@ -3233,7 +3233,7 @@ static int scmi_probe(struct platform_device *pdev)
dev_err(dev, "%s", err_str);
return 0;
}
- goto notification_exit;
+ goto raw_mode_cleanup;
}
mutex_lock(&scmi_list_mutex);
@@ -3275,17 +3275,18 @@ static int scmi_probe(struct platform_device *pdev)
return 0;
-notification_exit:
+raw_mode_cleanup:
if (IS_ENABLED(CONFIG_ARM_SCMI_RAW_MODE_SUPPORT))
scmi_raw_mode_cleanup(info->raw);
- scmi_notification_exit(&info->handle);
clear_dev_req_notifier:
blocking_notifier_chain_unregister(&scmi_requested_devices_nh,
&info->dev_req_nb);
clear_bus_notifier:
bus_unregister_notifier(&scmi_bus_type, &info->bus_nb);
clear_txrx_setup:
+ scmi_notification_quiesce(&info->handle);
scmi_cleanup_txrx_channels(info);
+ scmi_notification_exit(&info->handle);
clear_ida:
ida_free(&scmi_id, info->id);
@@ -3312,6 +3313,9 @@ static void scmi_remove(struct platform_device *pdev)
blocking_notifier_chain_unregister(&scmi_requested_devices_nh,
&info->dev_req_nb);
+ /* Stop transport callbacks before tearing down notifications. */
+ scmi_notification_quiesce(&info->handle);
+ scmi_cleanup_txrx_channels(info);
scmi_notification_exit(&info->handle);
mutex_lock(&info->protocols_mtx);
@@ -3324,9 +3328,6 @@ static void scmi_remove(struct platform_device *pdev)
bus_unregister_notifier(&scmi_bus_type, &info->bus_nb);
- /* Safe to free channels since no more users */
- scmi_cleanup_txrx_channels(info);
-
ida_free(&scmi_id, info->id);
}
diff --git a/drivers/firmware/arm_scmi/notify.c b/drivers/firmware/arm_scmi/notify.c
index 9bf7f43ab868c..672c91197a68a 100644
--- a/drivers/firmware/arm_scmi/notify.c
+++ b/drivers/firmware/arm_scmi/notify.c
@@ -1706,6 +1706,25 @@ int scmi_notification_init(struct scmi_handle *handle)
return -ENOMEM;
}
+/**
+ * scmi_notification_quiesce() - Stop notification late initialization
+ * @handle: The handle identifying the platform instance to quiesce
+ *
+ * Prevent new late-init work from being queued and wait for any already queued
+ * or running late-init work to complete before transport channels are torn
+ * down.
+ */
+void scmi_notification_quiesce(struct scmi_handle *handle)
+{
+ struct scmi_notify_instance *ni;
+
+ ni = scmi_notification_instance_data_get(handle);
+ if (!ni)
+ return;
+
+ disable_work_sync(&ni->init_work);
+}
+
/**
* scmi_notification_exit() - Shutdown and clean Notification core
* @handle: The handle identifying the platform instance to shutdown
@@ -1717,6 +1736,8 @@ void scmi_notification_exit(struct scmi_handle *handle)
ni = scmi_notification_instance_data_get(handle);
if (!ni)
return;
+
+ scmi_notification_quiesce(handle);
scmi_notification_instance_data_set(handle, NULL);
/* Destroy while letting pending work complete */
diff --git a/drivers/firmware/arm_scmi/notify.h b/drivers/firmware/arm_scmi/notify.h
index 76758a736cf47..f18f98c5ab3ba 100644
--- a/drivers/firmware/arm_scmi/notify.h
+++ b/drivers/firmware/arm_scmi/notify.h
@@ -82,6 +82,7 @@ struct scmi_protocol_events {
};
int scmi_notification_init(struct scmi_handle *handle);
+void scmi_notification_quiesce(struct scmi_handle *handle);
void scmi_notification_exit(struct scmi_handle *handle);
int scmi_register_protocol_events(const struct scmi_handle *handle, u8 proto_id,
const struct scmi_protocol_handle *ph,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0380/1518] firmware: arm_scmi: Clean up channels on setup failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (378 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0379/1518] firmware: arm_scmi: Quiesce notifications before teardown Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0381/1518] firmware: arm_scmi: Free transport channel on IDR failure Greg Kroah-Hartman
` (618 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Sudeep Holla, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sudeep Holla <sudeep.holla@kernel.org>
[ Upstream commit 687d67be3d87894ef12e8a164434612e0b53cfae ]
scmi_channels_setup() can fail after the common BASE channel or earlier
protocol channels have already been registered in the TX/RX IDRs.
Route this failure through the existing channel cleanup label so the
transport channels, transport devices and IDR state created before the
failure are released before the probe error path frees the SCMI instance
ID.
Fixes: 05a2801d8b90 ("firmware: arm_scmi: Use dedicated devices to initialize channels")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://patch.msgid.link/20260714-scmi_core_fixes-v6-4-3afe499d46e3@kernel.org
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/arm_scmi/driver.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/firmware/arm_scmi/driver.c b/drivers/firmware/arm_scmi/driver.c
index 529a4e5852e6e..74a199ca4c76c 100644
--- a/drivers/firmware/arm_scmi/driver.c
+++ b/drivers/firmware/arm_scmi/driver.c
@@ -3171,7 +3171,7 @@ static int scmi_probe(struct platform_device *pdev)
ret = scmi_channels_setup(info);
if (ret) {
err_str = "failed to setup channels\n";
- goto clear_ida;
+ goto clear_txrx_setup;
}
ret = bus_register_notifier(&scmi_bus_type, &info->bus_nb);
@@ -3287,7 +3287,6 @@ static int scmi_probe(struct platform_device *pdev)
scmi_notification_quiesce(&info->handle);
scmi_cleanup_txrx_channels(info);
scmi_notification_exit(&info->handle);
-clear_ida:
ida_free(&scmi_id, info->id);
out_err:
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0381/1518] firmware: arm_scmi: Free transport channel on IDR failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (379 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0380/1518] firmware: arm_scmi: Clean up channels on setup failure Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0382/1518] firmware: arm_scmi: Avoid IDR updates while cleaning channels Greg Kroah-Hartman
` (617 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Sudeep Holla, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sudeep Holla <sudeep.holla@kernel.org>
[ Upstream commit d72e7e5f24687c0490aabf317653caffe0447aeb ]
If transport channel setup succeeds but the following IDR insertion fails,
the error path destroys the transport device and frees the channel info
without invoking the transport cleanup callback.
Call chan_free() before destroying the device so transport specific
resources such as IRQs, mailbox channels and mapped shared memory are
released consistently with the normal teardown path.
Fixes: 05a2801d8b90 ("firmware: arm_scmi: Use dedicated devices to initialize channels")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://patch.msgid.link/20260714-scmi_core_fixes-v6-5-3afe499d46e3@kernel.org
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/arm_scmi/driver.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/firmware/arm_scmi/driver.c b/drivers/firmware/arm_scmi/driver.c
index 74a199ca4c76c..5d7f090e98ea8 100644
--- a/drivers/firmware/arm_scmi/driver.c
+++ b/drivers/firmware/arm_scmi/driver.c
@@ -2719,6 +2719,7 @@ static int scmi_chan_setup(struct scmi_info *info, struct device_node *of_node,
"unable to allocate SCMI idr slot err %d\n", ret);
/* Destroy channel and device only if created by this call. */
if (tdev) {
+ info->desc->ops->chan_free(prot_id, cinfo, idr);
of_node_put(of_node);
scmi_device_destroy(info->dev, prot_id, name);
devm_kfree(info->dev, cinfo);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0382/1518] firmware: arm_scmi: Avoid IDR updates while cleaning channels
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (380 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0381/1518] firmware: arm_scmi: Free transport channel on IDR failure Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0383/1518] firmware: arm_scmi: Reject out of range DT protocol IDs Greg Kroah-Hartman
` (616 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Sudeep Holla, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sudeep Holla <sudeep.holla@kernel.org>
[ Upstream commit c38b1e19485aaa820e52cfe162525a8af67563da ]
scmi_cleanup_channels() walks the TX/RX channel IDRs with
idr_for_each() to free transport resources and destroy the dedicated
transport devices before calling idr_destroy().
The destroy callback removed each entry from the same IDR being walked.
That is not needed for this cleanup path, and it is unsafe because
idr_for_each() has not advanced its radix-tree iterator while the
callback is running. Removing the current entry from the callback can
invalidate the iterator state. The callback also cannot be protected by
rcu_read_lock(), because scmi_device_destroy() may sleep.
Leave IDR teardown to the following idr_destroy() call and keep the
callback limited to device destruction.
Fixes: 05a2801d8b90 ("firmware: arm_scmi: Use dedicated devices to initialize channels")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://patch.msgid.link/20260714-scmi_core_fixes-v6-6-3afe499d46e3@kernel.org
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/arm_scmi/driver.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
diff --git a/drivers/firmware/arm_scmi/driver.c b/drivers/firmware/arm_scmi/driver.c
index 5d7f090e98ea8..5965a9989e45b 100644
--- a/drivers/firmware/arm_scmi/driver.c
+++ b/drivers/firmware/arm_scmi/driver.c
@@ -2796,7 +2796,7 @@ static int scmi_channels_setup(struct scmi_info *info)
return 0;
}
-static int scmi_chan_destroy(int id, void *p, void *idr)
+static int scmi_chan_destroy(int id, void *p, void *data)
{
struct scmi_chan_info *cinfo = p;
@@ -2809,8 +2809,6 @@ static int scmi_chan_destroy(int id, void *p, void *idr)
cinfo->dev = NULL;
}
- idr_remove(idr, id);
-
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0383/1518] firmware: arm_scmi: Reject out of range DT protocol IDs
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (381 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0382/1518] firmware: arm_scmi: Avoid IDR updates while cleaning channels Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0384/1518] firmware: arm_scmi: Use channel ID for transport teardown Greg Kroah-Hartman
` (615 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Sudeep Holla, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sudeep Holla <sudeep.holla@kernel.org>
[ Upstream commit 59407ccb52130f2c81f4b3cbe4f14114afceb54f ]
SCMI protocol IDs carried in message headers are limited by
MSG_PROTOCOL_ID_MASK. The DT parsing paths noticed protocol IDs
outside that range, but only logged an error and then kept processing
the invalid value.
That lets a malformed 32-bit DT reg value reach helpers which take a u8
protocol ID, where it can be truncated and/or treated as a different
protocol.
For channel setup, two different out-of-range values can also be used as
distinct IDR keys while aliasing the generated SCMI protocol identity.
Skip DT protocol nodes whose reg value does not fit the SCMI protocol ID
field before setting up channels or creating protocol devices.
Fixes: 05a2801d8b90 ("firmware: arm_scmi: Use dedicated devices to initialize channels")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://patch.msgid.link/20260714-scmi_core_fixes-v6-7-3afe499d46e3@kernel.org
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/arm_scmi/driver.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
diff --git a/drivers/firmware/arm_scmi/driver.c b/drivers/firmware/arm_scmi/driver.c
index 5965a9989e45b..6fc8129dc8691 100644
--- a/drivers/firmware/arm_scmi/driver.c
+++ b/drivers/firmware/arm_scmi/driver.c
@@ -2784,9 +2784,11 @@ static int scmi_channels_setup(struct scmi_info *info)
if (of_property_read_u32(child, "reg", &prot_id))
continue;
- if (!FIELD_FIT(MSG_PROTOCOL_ID_MASK, prot_id))
+ if (!FIELD_FIT(MSG_PROTOCOL_ID_MASK, prot_id)) {
dev_err(info->dev,
"Out of range protocol %d\n", prot_id);
+ continue;
+ }
ret = scmi_txrx_setup(info, child, prot_id);
if (ret)
@@ -3247,8 +3249,10 @@ static int scmi_probe(struct platform_device *pdev)
if (of_property_read_u32(child, "reg", &prot_id))
continue;
- if (!FIELD_FIT(MSG_PROTOCOL_ID_MASK, prot_id))
+ if (!FIELD_FIT(MSG_PROTOCOL_ID_MASK, prot_id)) {
dev_err(dev, "Out of range protocol %d\n", prot_id);
+ continue;
+ }
if (!scmi_is_protocol_implemented(handle, prot_id)) {
dev_err(dev, "SCMI protocol %d not implemented\n",
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0384/1518] firmware: arm_scmi: Use channel ID for transport teardown
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (382 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0383/1518] firmware: arm_scmi: Reject out of range DT protocol IDs Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0385/1518] firmware: arm_scmi: Protect device request lookup with RCU Greg Kroah-Hartman
` (614 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Sudeep Holla, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sudeep Holla <sudeep.holla@kernel.org>
[ Upstream commit a71a3d4d8a6e9e399fd988c0e6da47a6ee21c99e ]
SCMI protocols can share the BASE transport channel when firmware does
not describe a dedicated channel for the protocol. In that case multiple
IDR entries can point at the same scmi_chan_info, whose owning transport
device was created with cinfo->id.
scmi_chan_destroy() used the IDR iterator key when destroying the
transport device. If an alias entry is visited before the owning channel
entry, the lookup can miss the device because the iterator key does not
match the protocol ID used when the transport device was created. The
code then clears cinfo->dev, so the later owning entry skips teardown and
leaks the transport device.
Destroy the transport device using cinfo->id, which is the protocol ID
that owns the channel and was used when creating the transport device.
Fixes: 05a2801d8b90 ("firmware: arm_scmi: Use dedicated devices to initialize channels")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://patch.msgid.link/20260714-scmi_core_fixes-v6-8-3afe499d46e3@kernel.org
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/arm_scmi/driver.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/firmware/arm_scmi/driver.c b/drivers/firmware/arm_scmi/driver.c
index 6fc8129dc8691..c6483b8285ae4 100644
--- a/drivers/firmware/arm_scmi/driver.c
+++ b/drivers/firmware/arm_scmi/driver.c
@@ -2807,7 +2807,7 @@ static int scmi_chan_destroy(int id, void *p, void *data)
struct scmi_device *sdev = to_scmi_dev(cinfo->dev);
of_node_put(cinfo->dev->of_node);
- scmi_device_destroy(info->dev, id, sdev->name);
+ scmi_device_destroy(info->dev, cinfo->id, sdev->name);
cinfo->dev = NULL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0385/1518] firmware: arm_scmi: Protect device request lookup with RCU
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (383 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0384/1518] firmware: arm_scmi: Use channel ID for transport teardown Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0386/1518] firmware: arm_scmi: Drop handle on protocol bind failures Greg Kroah-Hartman
` (613 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Sudeep Holla, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sudeep Holla <sudeep.holla@kernel.org>
[ Upstream commit e6a0e7a49d83e4fa4e1db68d74f99282eb97aa49 ]
The SCMI device request notifier looks up protocol OF nodes from the
active_protocols IDR. The IDR lookup can run concurrently with protocol
activation while probe is still registering protocols and creating their
SCMI devices.
Wrap the lookup in an RCU read-side critical section as required by the
IDR API for lockless readers.
Fixes: 53b8c25df708 ("firmware: arm_scmi: Add common notifier helpers")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://patch.msgid.link/20260714-scmi_core_fixes-v6-9-3afe499d46e3@kernel.org
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/arm_scmi/driver.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/firmware/arm_scmi/driver.c b/drivers/firmware/arm_scmi/driver.c
index c6483b8285ae4..a84765b7405bf 100644
--- a/drivers/firmware/arm_scmi/driver.c
+++ b/drivers/firmware/arm_scmi/driver.c
@@ -32,6 +32,7 @@
#include <linux/of.h>
#include <linux/platform_device.h>
#include <linux/processor.h>
+#include <linux/rcupdate.h>
#include <linux/refcount.h>
#include <linux/slab.h>
#include <linux/xarray.h>
@@ -2869,7 +2870,9 @@ static int scmi_device_request_notifier(struct notifier_block *nb,
struct scmi_device_id *id_table = data;
struct scmi_info *info = req_nb_to_scmi_info(nb);
+ rcu_read_lock();
np = idr_find(&info->active_protocols, id_table->protocol_id);
+ rcu_read_unlock();
if (!np)
return NOTIFY_DONE;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0386/1518] firmware: arm_scmi: Drop handle on protocol bind failures
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (384 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0385/1518] firmware: arm_scmi: Protect device request lookup with RCU Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0387/1518] firmware: arm_scmi: Unwind TX receiver mailbox setup failure Greg Kroah-Hartman
` (612 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Sudeep Holla, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sudeep Holla <sudeep.holla@kernel.org>
[ Upstream commit e3a5c30d233ca5d3e799a80da806554c703bda13 ]
The SCMI bus notifier acquires an SCMI handle when the driver core emits
BUS_NOTIFY_BIND_DRIVER, before invoking the protocol driver probe
callback. The protocol probe path only checks whether sdev->handle is
set.
If device_link_add() fails after the handle has been acquired, the
protocol device can still bind with a valid handle but without the
dependency link to the SCMI parent. A concurrent parent unbind can then
miss the child and tear down the SCMI instance while the child still
holds a handle into it.
If the protocol driver probe later fails, for example with
-EPROBE_DEFER, the driver core emits BUS_NOTIFY_DRIVER_NOT_BOUND rather
than BUS_NOTIFY_UNBOUND_DRIVER. The SCMI notifier only released the
handle on BUS_NOTIFY_UNBOUND_DRIVER, so each failed protocol-device bind
leaked the SCMI instance users refcount and left sdev->handle set after
the failed probe.
Make the link helper report failure and drop the acquired handle if the
link cannot be created. Also handle BUS_NOTIFY_DRIVER_NOT_BOUND in the
same cleanup path used for unbind so failed probes balance the earlier
BUS_NOTIFY_BIND_DRIVER acquisition.
Fixes: 971fc0665f13 ("firmware: arm_scmi: Move handle get/set helpers")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://patch.msgid.link/20260714-scmi_core_fixes-v6-10-3afe499d46e3@kernel.org
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/arm_scmi/driver.c | 31 ++++++++++++++++++++++--------
1 file changed, 23 insertions(+), 8 deletions(-)
diff --git a/drivers/firmware/arm_scmi/driver.c b/drivers/firmware/arm_scmi/driver.c
index a84765b7405bf..55f14953f2ebd 100644
--- a/drivers/firmware/arm_scmi/driver.c
+++ b/drivers/firmware/arm_scmi/driver.c
@@ -2541,21 +2541,31 @@ static int scmi_handle_put(const struct scmi_handle *handle)
return 0;
}
-static void scmi_device_link_add(struct device *consumer,
+static bool scmi_device_link_add(struct device *consumer,
struct device *supplier)
{
struct device_link *link;
link = device_link_add(consumer, supplier, DL_FLAG_AUTOREMOVE_CONSUMER);
- WARN_ON(!link);
+ return !WARN_ON(!link);
+}
+
+static void scmi_clear_handle(struct scmi_device *scmi_dev)
+{
+ if (!scmi_dev->handle)
+ return;
+
+ scmi_handle_put(scmi_dev->handle);
+ scmi_dev->handle = NULL;
}
static void scmi_set_handle(struct scmi_device *scmi_dev)
{
scmi_dev->handle = scmi_handle_get(&scmi_dev->dev);
- if (scmi_dev->handle)
- scmi_device_link_add(&scmi_dev->dev, scmi_dev->handle->dev);
+ if (scmi_dev->handle &&
+ !scmi_device_link_add(&scmi_dev->dev, scmi_dev->handle->dev))
+ scmi_clear_handle(scmi_dev);
}
static int __scmi_xfer_info_init(struct scmi_info *sinfo,
@@ -2838,6 +2848,7 @@ static int scmi_bus_notifier(struct notifier_block *nb,
{
struct scmi_info *info = bus_nb_to_scmi_info(nb);
struct scmi_device *sdev = to_scmi_dev(data);
+ const char *status;
/* Skip devices of different SCMI instances */
if (sdev->dev.parent != info->dev)
@@ -2847,18 +2858,22 @@ static int scmi_bus_notifier(struct notifier_block *nb,
case BUS_NOTIFY_BIND_DRIVER:
/* setup handle now as the transport is ready */
scmi_set_handle(sdev);
+ status = "about to be BOUND.";
+ break;
+ case BUS_NOTIFY_DRIVER_NOT_BOUND:
+ scmi_clear_handle(sdev);
+ status = "NOT BOUND.";
break;
case BUS_NOTIFY_UNBOUND_DRIVER:
- scmi_handle_put(sdev->handle);
- sdev->handle = NULL;
+ scmi_clear_handle(sdev);
+ status = "UNBOUND.";
break;
default:
return NOTIFY_DONE;
}
dev_dbg(info->dev, "Device %s (%s) is now %s\n", dev_name(&sdev->dev),
- sdev->name, action == BUS_NOTIFY_BIND_DRIVER ?
- "about to be BOUND." : "UNBOUND.");
+ sdev->name, status);
return NOTIFY_OK;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0387/1518] firmware: arm_scmi: Unwind TX receiver mailbox setup failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (385 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0386/1518] firmware: arm_scmi: Drop handle on protocol bind failures Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0388/1518] firmware: arm_scmi: Unwind P2A " Greg Kroah-Hartman
` (611 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Sudeep Holla, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sudeep Holla <sudeep.holla@kernel.org>
[ Upstream commit 6f7c06744d53dc8e047725d411d7f915d9ec35ae ]
mailbox_chan_setup() can request an additional unidirectional TX
receiver channel after successfully acquiring the primary channel. If
that second request fails, the function returns immediately and leaves
the primary channel allocated.
Unwind the primary mailbox channel before returning the error so probe
deferral or other setup failures do not leave the channel busy for later
probe attempts.
Fixes: 9f68ff79ec2c ("firmware: arm_scmi: Add support for unidirectional mailbox channels")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://patch.msgid.link/20260714-scmi_core_fixes-v6-13-3afe499d46e3@kernel.org
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/arm_scmi/transports/mailbox.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/firmware/arm_scmi/transports/mailbox.c b/drivers/firmware/arm_scmi/transports/mailbox.c
index b6459fbb81513..37e3eab529eaf 100644
--- a/drivers/firmware/arm_scmi/transports/mailbox.c
+++ b/drivers/firmware/arm_scmi/transports/mailbox.c
@@ -230,9 +230,10 @@ static int mailbox_chan_setup(struct scmi_chan_info *cinfo, struct device *dev,
smbox->chan_receiver = mbox_request_channel(cl, a2p_rx_chan);
if (IS_ERR(smbox->chan_receiver)) {
ret = PTR_ERR(smbox->chan_receiver);
+ smbox->chan_receiver = NULL;
if (ret != -EPROBE_DEFER)
dev_err(cdev, "failed to request SCMI Tx Receiver mailbox\n");
- return ret;
+ goto err_free_chan;
}
}
@@ -248,6 +249,8 @@ static int mailbox_chan_setup(struct scmi_chan_info *cinfo, struct device *dev,
return 0;
+err_free_chan:
+ mbox_free_channel(smbox->chan);
err_clear_cinfo:
cinfo->transport_info = NULL;
smbox->cinfo = NULL;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0388/1518] firmware: arm_scmi: Unwind P2A receiver mailbox setup failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (386 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0387/1518] firmware: arm_scmi: Unwind TX receiver mailbox setup failure Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0389/1518] firmware: arm_scmi: Fix transport device teardown lookup Greg Kroah-Hartman
` (610 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Sudeep Holla, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sudeep Holla <sudeep.holla@kernel.org>
[ Upstream commit f3e3773c4e5e96549d7540d8ddeb4fcd534f6f1d ]
mailbox_chan_setup() can request an additional P2A receiver channel after
successfully acquiring the primary P2A channel. If that later request
fails, the function returns immediately and leaves the primary channel
allocated.
Unwind the primary mailbox channel before returning the error so probe
deferral or other setup failures do not leave the channel busy for later
probe attempts.
Fixes: fa8b28ba22d9 ("firmware: arm_scmi: Add support for platform to agent channel completion")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://patch.msgid.link/20260714-scmi_core_fixes-v6-14-3afe499d46e3@kernel.org
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/arm_scmi/transports/mailbox.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/firmware/arm_scmi/transports/mailbox.c b/drivers/firmware/arm_scmi/transports/mailbox.c
index 37e3eab529eaf..308736c3ead9c 100644
--- a/drivers/firmware/arm_scmi/transports/mailbox.c
+++ b/drivers/firmware/arm_scmi/transports/mailbox.c
@@ -241,9 +241,10 @@ static int mailbox_chan_setup(struct scmi_chan_info *cinfo, struct device *dev,
smbox->chan_platform_receiver = mbox_request_channel(cl, p2a_rx_chan);
if (IS_ERR(smbox->chan_platform_receiver)) {
ret = PTR_ERR(smbox->chan_platform_receiver);
+ smbox->chan_platform_receiver = NULL;
if (ret != -EPROBE_DEFER)
dev_err(cdev, "failed to request SCMI P2A Receiver mailbox\n");
- return ret;
+ goto err_free_chan;
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0389/1518] firmware: arm_scmi: Fix transport device teardown lookup
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (387 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0388/1518] firmware: arm_scmi: Unwind P2A " Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0390/1518] cxl/features: Reject Get Feature count larger than the output buffer Greg Kroah-Hartman
` (609 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Sudeep Holla, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sudeep Holla <sudeep.holla@kernel.org>
[ Upstream commit a14dd8fe0a95db638c550ed984cfe2a7428c783d ]
SCMI transport devices are deliberately excluded from normal SCMI bus
matching so protocol drivers cannot bind to the internal transport
children. However, scmi_device_destroy() uses the same protocol/name
lookup to find devices that must be unregistered during channel teardown.
Split the match helper so driver matching still skips transport devices,
while explicit child lookup can find them for teardown. Use a shared
transport-device name prefix macro for both matching and name generation.
Since transport-device names are derived from direction and protocol ID,
reject duplicate protocol channel setup before creating or finding a
transport device. This prevents malformed firmware with duplicate
protocol child nodes from reusing an existing transport device and then
destroying it when the duplicate IDR insertion fails.
Fixes: 9593804c44c2 ("firmware: arm_scmi: Exclude transport devices from bus matching")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://patch.msgid.link/20260714-scmi_core_fixes-v6-16-3afe499d46e3@kernel.org
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/arm_scmi/bus.c | 22 +++++++++++++++++-----
drivers/firmware/arm_scmi/common.h | 2 ++
drivers/firmware/arm_scmi/driver.c | 5 ++++-
3 files changed, 23 insertions(+), 6 deletions(-)
diff --git a/drivers/firmware/arm_scmi/bus.c b/drivers/firmware/arm_scmi/bus.c
index c7698cfaa4e83..e5e4975b2120d 100644
--- a/drivers/firmware/arm_scmi/bus.c
+++ b/drivers/firmware/arm_scmi/bus.c
@@ -201,21 +201,33 @@ scmi_protocol_table_unregister(const struct scmi_device_id *id_table)
scmi_protocol_device_unrequest(entry);
}
-static int scmi_dev_match_by_id_table(struct scmi_device *scmi_dev,
- const struct scmi_device_id *id_table)
+static bool scmi_device_is_transport(const struct scmi_device *scmi_dev)
+{
+ return !strncmp(scmi_dev->name, SCMI_TRANSPORT_DEVNAME_PREFIX,
+ strlen(SCMI_TRANSPORT_DEVNAME_PREFIX));
+}
+
+static int __scmi_dev_match_by_id_table(struct scmi_device *scmi_dev,
+ const struct scmi_device_id *id_table,
+ bool skip_transport)
{
if (!id_table || !id_table->name)
return 0;
- /* Always skip transport devices from matching */
for (; id_table->protocol_id && id_table->name; id_table++)
if (id_table->protocol_id == scmi_dev->protocol_id &&
- strncmp(scmi_dev->name, "__scmi_transport_device", 23) &&
+ !(skip_transport && scmi_device_is_transport(scmi_dev)) &&
!strcmp(id_table->name, scmi_dev->name))
return 1;
return 0;
}
+static int scmi_dev_match_by_id_table(struct scmi_device *scmi_dev,
+ const struct scmi_device_id *id_table)
+{
+ return __scmi_dev_match_by_id_table(scmi_dev, id_table, true);
+}
+
static int scmi_dev_match_id(struct scmi_device *scmi_dev,
const struct scmi_driver *scmi_drv)
{
@@ -235,7 +247,7 @@ static int scmi_match_by_id_table(struct device *dev, const void *data)
struct scmi_device *scmi_dev = to_scmi_dev(dev);
const struct scmi_device_id *id_table = data;
- return scmi_dev_match_by_id_table(scmi_dev, id_table);
+ return __scmi_dev_match_by_id_table(scmi_dev, id_table, false);
}
static struct scmi_device *scmi_child_dev_find(struct device *parent,
diff --git a/drivers/firmware/arm_scmi/common.h b/drivers/firmware/arm_scmi/common.h
index 7c35c95fddbaf..ef803e1d25e15 100644
--- a/drivers/firmware/arm_scmi/common.h
+++ b/drivers/firmware/arm_scmi/common.h
@@ -33,6 +33,8 @@
#define SCMI_SHMEM_MAX_PAYLOAD_SIZE 104
+#define SCMI_TRANSPORT_DEVNAME_PREFIX "__scmi_transport_device"
+
enum scmi_error_codes {
SCMI_SUCCESS = 0, /* Success */
SCMI_ERR_SUPPORT = -1, /* Not supported */
diff --git a/drivers/firmware/arm_scmi/driver.c b/drivers/firmware/arm_scmi/driver.c
index 55f14953f2ebd..5a9d6df50679c 100644
--- a/drivers/firmware/arm_scmi/driver.c
+++ b/drivers/firmware/arm_scmi/driver.c
@@ -2674,6 +2674,9 @@ static int scmi_chan_setup(struct scmi_info *info, struct device_node *of_node,
idx = tx ? 0 : 1;
idr = tx ? &info->tx_idr : &info->rx_idr;
+ if (idr_find(idr, prot_id))
+ return -EEXIST;
+
if (!info->desc->ops->chan_available(of_node, idx)) {
cinfo = idr_find(idr, SCMI_PROTOCOL_BASE);
if (unlikely(!cinfo)) /* Possible only if platform has no Rx */
@@ -2690,7 +2693,7 @@ static int scmi_chan_setup(struct scmi_info *info, struct device_node *of_node,
cinfo->max_msg_size = info->desc->max_msg_size;
/* Create a unique name for this transport device */
- snprintf(name, 32, "__scmi_transport_device_%s_%02X",
+ snprintf(name, sizeof(name), SCMI_TRANSPORT_DEVNAME_PREFIX "_%s_%02X",
idx ? "rx" : "tx", prot_id);
/* Create a uniquely named, dedicated transport device for this chan */
tdev = scmi_device_create(of_node, info->dev, prot_id, name);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0390/1518] cxl/features: Reject Get Feature count larger than the output buffer
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (388 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0389/1518] firmware: arm_scmi: Fix transport device teardown lookup Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0391/1518] cxl/features: Reject Set Features output buffer smaller than the header Greg Kroah-Hartman
` (608 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kai-Heng Feng, Koba Ko, Dave Jiang,
Richard Cheng, Alison Schofield, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Richard Cheng <icheng@nvidia.com>
[ Upstream commit 4bf6bac375076ced2fa4b3fef8739bd985f93456 ]
cxlctl_get_feature() sizes its output buffer from the user's
fwctl_rpc.out_len, but the device is told to write
cxl_mbox_get_feat_in.count bytes into rpc_out->payload, which is a
separate user-controlled value. Nothing bounds count against out_len, so
a small out_len with a large count overflows the kvzalloc()'d buffer.
A heap OOB write reachable from FWCTL_RPC.
Reject requests where count exceeds the available payload room, before
allocating.
Fixes: 5908f3ed6dc2 ("cxl: Add support to handle user feature commands for get feature")
Reviewed-by: Kai-Heng Feng <kaihengf@nvidia.com>
Reviewed-by: Koba Ko <kobak@nvidia.com>
Reviewed-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Richard Cheng <icheng@nvidia.com>
Reviewed-by: Alison Schofield <alison.schofield@intel.com>
Link: https://patch.msgid.link/20260626104102.53892-2-icheng@nvidia.com
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/cxl/core/features.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/cxl/core/features.c b/drivers/cxl/core/features.c
index 7b0eeb0788d32..32bded289ebc7 100644
--- a/drivers/cxl/core/features.c
+++ b/drivers/cxl/core/features.c
@@ -471,6 +471,10 @@ static void *cxlctl_get_feature(struct cxl_features_state *cxlfs,
if (!count)
return ERR_PTR(-EINVAL);
+ if (out_size < offsetof(struct fwctl_rpc_cxl_out, payload) ||
+ count > out_size - offsetof(struct fwctl_rpc_cxl_out, payload))
+ return ERR_PTR(-EINVAL);
+
struct fwctl_rpc_cxl_out *rpc_out __free(kvfree) =
kvzalloc(out_size, GFP_KERNEL);
if (!rpc_out)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0391/1518] cxl/features: Reject Set Features output buffer smaller than the header
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (389 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0390/1518] cxl/features: Reject Get Feature count larger than the output buffer Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0392/1518] cxl/features: Clamp Get Feature output size to the remaining buffer Greg Kroah-Hartman
` (607 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Richard Cheng, Dave Jiang,
Alison Schofield, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Richard Cheng <icheng@nvidia.com>
[ Upstream commit cde18d6c1d913a67ab0afd3d9475ece4be79da50 ]
cxlctl_set_feature() sizes its output buffer from the user's
fwctl_rpc.out_len but never checks it is large enough to hold even the
fwctl_rpc_cxl_out header. With out_len == 0 , kvzalloc() returns
ZERO_SIZE_PTR, which passes the !rpc_out check, the subsequent
rpc_out->size = 0 then writes through the poison pointer.
Reject requests whose output buffer can't hold the response header,
before allocating. The Set Feature reply carries no payload, so the
header is all that is required.
Fixes: eb5dfcb9e36d ("cxl: Add support to handle user feature commands for set feature")
Signed-off-by: Richard Cheng <icheng@nvidia.com>
Reviewed-by: Dave Jiang <dave.jiang@intel.com>
Reviewed-by: Alison Schofield <alison.schofield@intel.com>
Link: https://patch.msgid.link/20260626104102.53892-3-icheng@nvidia.com
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/cxl/core/features.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/cxl/core/features.c b/drivers/cxl/core/features.c
index 32bded289ebc7..c45b6dfcc2445 100644
--- a/drivers/cxl/core/features.c
+++ b/drivers/cxl/core/features.c
@@ -520,6 +520,9 @@ static void *cxlctl_set_feature(struct cxl_features_state *cxlfs,
flags = le32_to_cpu(feat_in->flags);
out_size = *out_len;
+ if (out_size < offsetof(struct fwctl_rpc_cxl_out, payload))
+ return ERR_PTR(-EINVAL);
+
struct fwctl_rpc_cxl_out *rpc_out __free(kvfree) =
kvzalloc(out_size, GFP_KERNEL);
if (!rpc_out)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0392/1518] cxl/features: Clamp Get Feature output size to the remaining buffer
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (390 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0391/1518] cxl/features: Reject Set Features output buffer smaller than the header Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0393/1518] regulator: adp5055: Fix error code in adp5055_of_parse_cb() Greg Kroah-Hartman
` (606 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Richard Cheng, Dave Jiang,
Alison Schofield, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Richard Cheng <icheng@nvidia.com>
[ Upstream commit 2aeb21fe557ef154f0cdf4f9745ebd8d5b31ca83 ]
cxl_get_feature() reads a feature in a loop but passes a fixed size_out
as the output capacity every iteration. On the last partial iteration
the buffer has less room left, so a device that returns more than asked
can overflow feat_out.
Use the per-iter size data_to_rd_size, which already tracks the
remaining room, as the output capacity.
Fixes: 5e5ac21f629d ("cxl/mbox: Add GET_FEATURE mailbox command")
Signed-off-by: Richard Cheng <icheng@nvidia.com>
Reviewed-by: Dave Jiang <dave.jiang@intel.com>
Reviewed-by: Alison Schofield <alison.schofield@intel.com>
Link: https://patch.msgid.link/20260626104102.53892-4-icheng@nvidia.com
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/cxl/core/features.c | 5 ++---
1 file changed, 2 insertions(+), 3 deletions(-)
diff --git a/drivers/cxl/core/features.c b/drivers/cxl/core/features.c
index c45b6dfcc2445..6e25223d3409b 100644
--- a/drivers/cxl/core/features.c
+++ b/drivers/cxl/core/features.c
@@ -225,7 +225,7 @@ size_t cxl_get_feature(struct cxl_mailbox *cxl_mbox, const uuid_t *feat_uuid,
void *feat_out, size_t feat_out_size, u16 offset,
u16 *return_code)
{
- size_t data_to_rd_size, size_out;
+ size_t data_to_rd_size;
struct cxl_mbox_get_feat_in pi;
struct cxl_mbox_cmd mbox_cmd;
size_t data_rcvd_size = 0;
@@ -237,7 +237,6 @@ size_t cxl_get_feature(struct cxl_mailbox *cxl_mbox, const uuid_t *feat_uuid,
if (!feat_out || !feat_out_size)
return 0;
- size_out = min(feat_out_size, cxl_mbox->payload_size);
uuid_copy(&pi.uuid, feat_uuid);
pi.selection = selection;
do {
@@ -250,7 +249,7 @@ size_t cxl_get_feature(struct cxl_mailbox *cxl_mbox, const uuid_t *feat_uuid,
.opcode = CXL_MBOX_OP_GET_FEATURE,
.size_in = sizeof(pi),
.payload_in = &pi,
- .size_out = size_out,
+ .size_out = data_to_rd_size,
.payload_out = feat_out + data_rcvd_size,
.min_out = data_to_rd_size,
};
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0393/1518] regulator: adp5055: Fix error code in adp5055_of_parse_cb()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (391 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0392/1518] cxl/features: Clamp Get Feature output size to the remaining buffer Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0394/1518] tools/sched_ext: scx_qmap: Fix stale API name in comment Greg Kroah-Hartman
` (605 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Dan Carpenter, Mark Brown,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dan Carpenter <error27@gmail.com>
[ Upstream commit 153bc959ce0f91b4446fb6fb805b8c1d2ca20c75 ]
This code accidentally returned the wrong variable instead of a negative
error code. Return -EINVAL.
Fixes: 147b2a96f24e ("regulator: adp5055: Add driver for adp5055")
Signed-off-by: Dan Carpenter <error27@gmail.com>
Link: https://patch.msgid.link/alFJVBbiFNxhqa_1@stanley.mountain
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/regulator/adp5055-regulator.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/regulator/adp5055-regulator.c b/drivers/regulator/adp5055-regulator.c
index 4b004a6b2f84e..5b83f36351a2a 100644
--- a/drivers/regulator/adp5055-regulator.c
+++ b/drivers/regulator/adp5055-regulator.c
@@ -225,7 +225,7 @@ static int adp5055_of_parse_cb(struct device_node *np,
adp5055->dvs_limit_upper[id] = pval;
if (adp5055->dvs_limit_upper[id] > 192000 || adp5055->dvs_limit_upper[id] < 12000)
- return dev_err_probe(config->dev, adp5055->dvs_limit_upper[id],
+ return dev_err_probe(config->dev, -EINVAL,
"Out of range - dvs-limit-upper-microvolt value.");
ret = of_property_read_u32(np, "adi,dvs-limit-lower-microvolt", &pval);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0394/1518] tools/sched_ext: scx_qmap: Fix stale API name in comment
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (392 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0393/1518] regulator: adp5055: Fix error code in adp5055_of_parse_cb() Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0395/1518] libnvdimm/labels: Bound the on-media label size before the shift Greg Kroah-Hartman
` (604 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Liang Luo, Tejun Heo, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Liang Luo <luoliang@kylinos.cn>
[ Upstream commit 35f9cbbacb671e587c84e992e7b0098c39e895a4 ]
The comment above dispatch_highpri() still references
scx_bpf_dispatch[_vtime]_from_dsq(), which was renamed to
scx_bpf_dsq_move[_vtime]() in v6.13 to unload the overloaded
"dispatch" verb. The code below already uses the new names; only the
comment was left behind during the rename.
Fixes: 5cbb302880f5 ("sched_ext: Rename scx_bpf_dispatch[_vtime]_from_dsq*() -> scx_bpf_dsq_move[_vtime]*()")
Signed-off-by: Liang Luo <luoliang@kylinos.cn>
Signed-off-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/sched_ext/scx_qmap.bpf.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/sched_ext/scx_qmap.bpf.c b/tools/sched_ext/scx_qmap.bpf.c
index b76702bbf1ee8..19984b52323f5 100644
--- a/tools/sched_ext/scx_qmap.bpf.c
+++ b/tools/sched_ext/scx_qmap.bpf.c
@@ -301,7 +301,7 @@ static void update_core_sched_head_seq(struct task_struct *p)
* moving them to HIGHPRI_DSQ and then consuming them first. This makes minor
* difference only when dsp_batch is larger than 1.
*
- * scx_bpf_dispatch[_vtime]_from_dsq() are allowed both from ops.dispatch() and
+ * scx_bpf_dsq_move[_vtime]() are allowed both from ops.dispatch() and
* non-rq-lock holding BPF programs. As demonstration, this function is called
* from qmap_dispatch() and monitor_timerfn().
*/
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0395/1518] libnvdimm/labels: Bound the on-media label size before the shift
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (393 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0394/1518] tools/sched_ext: scx_qmap: Fix stale API name in comment Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0396/1518] dax: read holder_ops once in dax_holder_notify_failure() Greg Kroah-Hartman
` (603 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bryam Vargas, Alison Schofield,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bryam Vargas <hexlabsecurity@proton.me>
[ Upstream commit 18f9124248ed7a9da1c31973b629dceef76a9b0c ]
For a v1.2+ index, __nd_label_validate() computes the label size as
1 << (7 + nsindex[i]->labelsize), where labelsize is a u8 read from
the label storage medium. A value of 25 or more makes the shift count
reach or exceed the width of int -- undefined behavior -- and 24 already
shifts into the sign bit. Only 0 (128-byte) and 1 (256-byte) are valid.
Reject a labelsize above 1 before the shift. The result was rejected by
the following size comparison anyway, so this only removes the undefined
shift on a crafted or corrupted medium; conforming labels are unaffected.
Fixes: 564e871aa66f ("libnvdimm, label: add v1.2 nvdimm label definitions")
Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me>
Reviewed-by: Alison Schofield <alison.schofield@intel.com>
Link: https://patch.msgid.link/20260624-b4-disp-d8279485-v3-2-cdb6cab28b41@proton.me
Signed-off-by: Alison Schofield <alison.schofield@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/nvdimm/label.c | 15 +++++++++++++--
1 file changed, 13 insertions(+), 2 deletions(-)
diff --git a/drivers/nvdimm/label.c b/drivers/nvdimm/label.c
index 584a9c27ce4bf..93ff219d91fc5 100644
--- a/drivers/nvdimm/label.c
+++ b/drivers/nvdimm/label.c
@@ -145,10 +145,21 @@ static int __nd_label_validate(struct nvdimm_drvdata *ndd)
/* label sizes larger than 128 arrived with v1.2 */
version = __le16_to_cpu(nsindex[i]->major) * 100
+ __le16_to_cpu(nsindex[i]->minor);
- if (version >= 102)
+ if (version >= 102) {
+ /*
+ * labelsize feeds the shift below; only 0 (128-byte)
+ * and 1 (256-byte) are valid -- a larger value would
+ * overflow or exceed the width of int.
+ */
+ if (nsindex[i]->labelsize > 1) {
+ dev_dbg(dev, "nsindex%d labelsize: %d invalid\n",
+ i, nsindex[i]->labelsize);
+ continue;
+ }
labelsize = 1 << (7 + nsindex[i]->labelsize);
- else
+ } else {
labelsize = 128;
+ }
if (labelsize != sizeof_namespace_label(ndd)) {
dev_dbg(dev, "nsindex%d labelsize %d invalid\n",
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0396/1518] dax: read holder_ops once in dax_holder_notify_failure()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (394 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0395/1518] libnvdimm/labels: Bound the on-media label size before the shift Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0397/1518] cpufreq: spear: Fix an IS_ERR() vs NULL bug in spear1340_set_cpu_rate() Greg Kroah-Hartman
` (602 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Richard Cheng, John Groves,
Alison Schofield, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: John Groves <John@Groves.net>
[ Upstream commit 7ae9d15bdcde0f2955ae13b6a95587f9e23b2359 ]
dax_holder_notify_failure() reads dax_dev->holder_ops twice without
READ_ONCE() -- once for the NULL check and once for the indirect
notify_failure() call. A concurrent fs_put_dax() can clear holder_ops
between the two reads, so the check can observe a non-NULL pointer while
the call dereferences NULL. (kill_dax() also clears holder_ops, but only
after synchronize_srcu(), so it cannot race a reader that is inside
dax_read_lock(); fs_put_dax() does no such synchronization.)
Fetch holder_ops once into a local with READ_ONCE() so the NULL check and
the indirect call observe the same value.
Fixes: 8012b86608552 ("dax: introduce holder for dax_device")
Suggested-by: Richard Cheng <icheng@nvidia.com>
Reviewed-by: Richard Cheng <icheng@nvidia.com>
Signed-off-by: John Groves <john@groves.net>
Link: https://patch.msgid.link/0100019ecc09bb56-5ecc9c6b-35ba-44f8-b112-921b01b34478-000000@email.amazonses.com
Signed-off-by: Alison Schofield <alison.schofield@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dax/super.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
diff --git a/drivers/dax/super.c b/drivers/dax/super.c
index d7714d8afb0fa..efa5f61860190 100644
--- a/drivers/dax/super.c
+++ b/drivers/dax/super.c
@@ -232,6 +232,7 @@ EXPORT_SYMBOL_GPL(dax_recovery_write);
int dax_holder_notify_failure(struct dax_device *dax_dev, u64 off,
u64 len, int mf_flags)
{
+ const struct dax_holder_operations *ops;
int rc, id;
id = dax_read_lock();
@@ -240,12 +241,19 @@ int dax_holder_notify_failure(struct dax_device *dax_dev, u64 off,
goto out;
}
- if (!dax_dev->holder_ops) {
+ /*
+ * Read holder_ops once: a concurrent fs_put_dax() can clear it without
+ * synchronizing against readers. Without the single fetch the compiler
+ * could reload between the NULL check and the call and dereference a
+ * NULL ops.
+ */
+ ops = READ_ONCE(dax_dev->holder_ops);
+ if (!ops) {
rc = -EOPNOTSUPP;
goto out;
}
- rc = dax_dev->holder_ops->notify_failure(dax_dev, off, len, mf_flags);
+ rc = ops->notify_failure(dax_dev, off, len, mf_flags);
out:
dax_read_unlock(id);
return rc;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0397/1518] cpufreq: spear: Fix an IS_ERR() vs NULL bug in spear1340_set_cpu_rate()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (395 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0396/1518] dax: read holder_ops once in dax_holder_notify_failure() Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0398/1518] PCI: xgene: Drop unnecessary OF node reference Greg Kroah-Hartman
` (601 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dan Carpenter, Zhongqiu Han,
Viresh Kumar, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dan Carpenter <error27@gmail.com>
[ Upstream commit 6a9e0e0f7592313ace66303cf5eca68e04c10f30 ]
The clk_get_parent() function doesn't return error pointers, it returns
NULL on error. Update the error checking to match.
Fixes: 420993221175 ("cpufreq: SPEAr: Add CPUFreq driver")
Signed-off-by: Dan Carpenter <error27@gmail.com>
Reviewed-by: Zhongqiu Han <zhongqiu.han@oss.qualcomm.com>
Signed-off-by: Viresh Kumar <viresh.kumar@linaro.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/cpufreq/spear-cpufreq.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/cpufreq/spear-cpufreq.c b/drivers/cpufreq/spear-cpufreq.c
index 2a1550e1aa21f..6f8cd59baa36f 100644
--- a/drivers/cpufreq/spear-cpufreq.c
+++ b/drivers/cpufreq/spear-cpufreq.c
@@ -79,9 +79,9 @@ static int spear1340_set_cpu_rate(struct clk *sys_pclk, unsigned long newfreq)
int ret = 0;
sys_clk = clk_get_parent(spear_cpufreq.clk);
- if (IS_ERR(sys_clk)) {
+ if (!sys_clk) {
pr_err("failed to get cpu's parent (sys) clock\n");
- return PTR_ERR(sys_clk);
+ return -EINVAL;
}
/* Set the rate of the source clock before changing the parent */
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0398/1518] PCI: xgene: Drop unnecessary OF node reference
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (396 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0397/1518] cpufreq: spear: Fix an IS_ERR() vs NULL bug in spear1340_set_cpu_rate() Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0399/1518] irqchip/renesas-irqc: Fix generic interrupt chip leak on remove Greg Kroah-Hartman
` (600 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yuho Choi, Manivannan Sadhasivam,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuho Choi <dbgh9129@gmail.com>
[ Upstream commit 4869db344e76c9adfb1d9654df442db5371fac71 ]
xgene_pcie_probe() stores dev->of_node in port->node with
of_node_get(), but the cached node is only used during probe by
xgene_pcie_parse_map_dma_ranges(). The driver never releases the extra
reference, so the node reference is leaked.
There is no need for private OF node ownership here. Use the device's
existing of_node directly in xgene_pcie_parse_map_dma_ranges() and remove
the cached port->node pointer.
Fixes: 5f6b6ccdbe1c ("PCI: xgene: Add APM X-Gene PCIe driver")
Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
Signed-off-by: Manivannan Sadhasivam <mani@kernel.org>
Link: https://patch.msgid.link/20260630195234.1871951-1-dbgh9129@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pci/controller/pci-xgene.c | 5 +----
1 file changed, 1 insertion(+), 4 deletions(-)
diff --git a/drivers/pci/controller/pci-xgene.c b/drivers/pci/controller/pci-xgene.c
index b95afa35201d0..83c9a2930eeca 100644
--- a/drivers/pci/controller/pci-xgene.c
+++ b/drivers/pci/controller/pci-xgene.c
@@ -58,7 +58,6 @@
#define XGENE_PCIE_IP_VER_2 2
struct xgene_pcie {
- struct device_node *node;
struct device *dev;
struct clk *clk;
void __iomem *csr_base;
@@ -526,7 +525,7 @@ static void xgene_pcie_setup_ib_reg(struct xgene_pcie *port,
static int xgene_pcie_parse_map_dma_ranges(struct xgene_pcie *port)
{
- struct device_node *np = port->node;
+ struct device_node *np = port->dev->of_node;
struct of_pci_range range;
struct of_pci_range_parser parser;
struct device *dev = port->dev;
@@ -612,7 +611,6 @@ static bool xgene_check_pcie_msi_ready(void)
static int xgene_pcie_probe(struct platform_device *pdev)
{
struct device *dev = &pdev->dev;
- struct device_node *dn = dev->of_node;
struct xgene_pcie *port;
struct pci_host_bridge *bridge;
int ret;
@@ -627,7 +625,6 @@ static int xgene_pcie_probe(struct platform_device *pdev)
port = pci_host_bridge_priv(bridge);
- port->node = of_node_get(dn);
port->dev = dev;
port->version = XGENE_PCIE_IP_VER_1;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0399/1518] irqchip/renesas-irqc: Fix generic interrupt chip leak on remove
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (397 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0398/1518] PCI: xgene: Drop unnecessary OF node reference Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0400/1518] media: i2c: rdacm21: Fix missing media_entity_cleanup() Greg Kroah-Hartman
` (599 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Qingshuang Fu, Thomas Gleixner,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Qingshuang Fu <fuqingshuang@kylinos.cn>
[ Upstream commit 616dd89d81ad9a3cf1cfff4088a4c43e4e00d6ba ]
The driver allocates domain generic chips probe. However, on driver
removal, the generic chips are not automatically freed when the interrupt
domain is removed because the domain flags do not include
IRQ_DOMAIN_FLAG_DESTROY_GC.
This causes both the domain generic chips structure and the associated
generic chips to be leaked. Additionally, the generic chips remain on the
global list and may later be accessed by generic interrupt chip suspend,
resume, or shutdown callbacks after the driver has been removed,
potentially resulting in a use-after-free and kernel crash.
Fix the resource leak by setting IRQ_DOMAIN_FLAG_DESTROY_GC on the
interrupt domain; this lets the interrupt domain core automatically
release all generic chips when irq_domain_remove() is invoked, removing
the need for manual cleanup calls in error paths and remove callback.
Fixes: 99c221df33fbfa1b ("irqchip/renesas-irqc: Move over to nested generic chip")
Signed-off-by: Qingshuang Fu <fuqingshuang@kylinos.cn>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Link: https://patch.msgid.link/20260708100846.506314-1-fffsqian@163.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/irqchip/irq-renesas-irqc.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/irqchip/irq-renesas-irqc.c b/drivers/irqchip/irq-renesas-irqc.c
index a20a6471b0e48..1ff3535a4617f 100644
--- a/drivers/irqchip/irq-renesas-irqc.c
+++ b/drivers/irqchip/irq-renesas-irqc.c
@@ -176,6 +176,7 @@ static int irqc_probe(struct platform_device *pdev)
goto err_runtime_pm_disable;
}
+ p->irq_domain->flags |= IRQ_DOMAIN_FLAG_DESTROY_GC;
ret = irq_alloc_domain_generic_chips(p->irq_domain, p->number_of_irqs,
1, "irqc", handle_level_irq,
0, 0, IRQ_GC_INIT_NESTED_LOCK);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0400/1518] media: i2c: rdacm21: Fix missing media_entity_cleanup()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (398 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0399/1518] irqchip/renesas-irqc: Fix generic interrupt chip leak on remove Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0401/1518] media: bcm2835-unicam: Fix asc leaked in error/remove path Greg Kroah-Hartman
` (598 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Biren Pandya, Sakari Ailus,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Biren Pandya <birenpandya@gmail.com>
[ Upstream commit 04c053379c3a33460b581953c4f5b36de39439ac ]
The driver misses calling media_entity_cleanup() on the probe error path
and during remove, leaking resources if probe fails after entity
initialization or when the driver is unloaded.
Fix this by adding media_entity_cleanup() to the rdacm21_probe() error
handling path and to rdacm21_remove().
Fixes: a59f853b3b4b ("media: i2c: Add driver for RDACM21 camera module")
Signed-off-by: Biren Pandya <birenpandya@gmail.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/media/i2c/rdacm21.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/media/i2c/rdacm21.c b/drivers/media/i2c/rdacm21.c
index bcab462708c70..ece8a410e7ced 100644
--- a/drivers/media/i2c/rdacm21.c
+++ b/drivers/media/i2c/rdacm21.c
@@ -588,10 +588,12 @@ static int rdacm21_probe(struct i2c_client *client)
ret = v4l2_async_register_subdev(&dev->sd);
if (ret)
- goto error_free_ctrls;
+ goto error_entity_cleanup;
return 0;
+error_entity_cleanup:
+ media_entity_cleanup(&dev->sd.entity);
error_free_ctrls:
v4l2_ctrl_handler_free(&dev->ctrls);
error:
@@ -606,6 +608,7 @@ static void rdacm21_remove(struct i2c_client *client)
v4l2_async_unregister_subdev(&dev->sd);
v4l2_ctrl_handler_free(&dev->ctrls);
+ media_entity_cleanup(&dev->sd.entity);
i2c_unregister_device(dev->isp);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0401/1518] media: bcm2835-unicam: Fix asc leaked in error/remove path
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (399 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0400/1518] media: i2c: rdacm21: Fix missing media_entity_cleanup() Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0402/1518] media: ipu6: Do not free aux device pdata after init Greg Kroah-Hartman
` (597 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Eugen Hristev, Laurent Pinchart,
Sakari Ailus, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eugen Hristev <ehristev@kernel.org>
[ Upstream commit 253c9659e25131b0169f718e7d094ac1aa0d9279 ]
v4l2_async_nf_add_fwnode_remote() allocates the asc, which is freed when
v4l2_async_nf_cleanup() is called.
Call v4l2_async_nf_cleanup() properly in the driver paths.
Discovered with kmemleak after rmmod:
unreferenced object 0xffff000084526b80 (size 64):
comm "modprobe", pid 185, jiffies 4295013512
hex dump (first 32 bytes):
01 00 00 00 00 00 00 00 e8 0d ff bf 00 00 ff ff ................
40 83 bc 84 00 00 ff ff 60 83 bc 84 00 00 ff ff @.......`.......
backtrace (crc ac584083):
[<00000000ffb081a7>] kmemleak_alloc+0x38/0x44
[<00000000d2fd9301>] __kmalloc+0x1b0/0x250
[<000000004dd5354d>] __v4l2_async_nf_add_fwnode+0x28/0x9c
[<0000000067587657>] __v4l2_async_nf_add_fwnode_remote+0x3c/0x64
Fixes: 392cd78d495f ("media: bcm2835-unicam: Add support for CCP2/CSI2 camera interface")
Signed-off-by: Eugen Hristev <ehristev@kernel.org>
Reviewed-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/media/platform/broadcom/bcm2835-unicam.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/media/platform/broadcom/bcm2835-unicam.c b/drivers/media/platform/broadcom/bcm2835-unicam.c
index f10064107d543..fd862300e06f2 100644
--- a/drivers/media/platform/broadcom/bcm2835-unicam.c
+++ b/drivers/media/platform/broadcom/bcm2835-unicam.c
@@ -2594,6 +2594,7 @@ static int unicam_async_nf_init(struct unicam_device *unicam)
return 0;
error:
+ v4l2_async_nf_cleanup(&unicam->notifier);
fwnode_handle_put(ep_handle);
return ret;
}
@@ -2726,6 +2727,7 @@ static void unicam_remove(struct platform_device *pdev)
v4l2_device_unregister(&unicam->v4l2_dev);
media_device_unregister(&unicam->mdev);
v4l2_async_nf_unregister(&unicam->notifier);
+ v4l2_async_nf_cleanup(&unicam->notifier);
unicam_subdev_cleanup(unicam);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0402/1518] media: ipu6: Do not free aux device pdata after init
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (400 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0401/1518] media: bcm2835-unicam: Fix asc leaked in error/remove path Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0403/1518] drm/amd/display: Fix DM I2C teardown race Greg Kroah-Hartman
` (596 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ruoyu Wang, Sakari Ailus,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ruoyu Wang <ruoyuw560@gmail.com>
[ Upstream commit 9be07216af4cfc4813e1a46ce26407d31ea845de ]
ipu6_bus_initialize_device() stores the isys/psys pdata pointer in
struct ipu6_bus_device and initializes the auxiliary device. After that
point, error unwinding must drop the auxiliary device reference and let
ipu6_bus_release() free both the bus device and adev->pdata.
The isys and psys init paths already call put_device() when MMU
initialization fails, and ipu6_bus_add_device() calls
auxiliary_device_uninit() on auxiliary_device_add() failure. Both paths
therefore run the bus release callback. The extra kfree(pdata) in the
callers can release the same object a second time.
Remove the manual pdata frees after the auxiliary device has been
initialized.
This issue was found by a static analysis checker and confirmed by
manual source review.
Fixes: cb3117b074ae ("media: intel/ipu6: add IPU auxiliary devices")
Signed-off-by: Ruoyu Wang <ruoyuw560@gmail.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/media/pci/intel/ipu6/ipu6.c | 10 ++--------
1 file changed, 2 insertions(+), 8 deletions(-)
diff --git a/drivers/media/pci/intel/ipu6/ipu6.c b/drivers/media/pci/intel/ipu6/ipu6.c
index fab7783c664b9..f900de14ba600 100644
--- a/drivers/media/pci/intel/ipu6/ipu6.c
+++ b/drivers/media/pci/intel/ipu6/ipu6.c
@@ -400,7 +400,6 @@ ipu6_isys_init(struct pci_dev *pdev, struct device *parent,
&ipdata->hw_variant);
if (IS_ERR(isys_adev->mmu)) {
put_device(&isys_adev->auxdev.dev);
- kfree(pdata);
return dev_err_cast_probe(dev, isys_adev->mmu,
"ipu6_mmu_init(isys_adev->mmu) failed\n");
}
@@ -408,10 +407,8 @@ ipu6_isys_init(struct pci_dev *pdev, struct device *parent,
isys_adev->mmu->dev = &isys_adev->auxdev.dev;
ret = ipu6_bus_add_device(isys_adev);
- if (ret) {
- kfree(pdata);
+ if (ret)
return ERR_PTR(ret);
- }
return isys_adev;
}
@@ -444,7 +441,6 @@ ipu6_psys_init(struct pci_dev *pdev, struct device *parent,
&ipdata->hw_variant);
if (IS_ERR(psys_adev->mmu)) {
put_device(&psys_adev->auxdev.dev);
- kfree(pdata);
return dev_err_cast_probe(&pdev->dev, psys_adev->mmu,
"ipu6_mmu_init(psys_adev->mmu) failed\n");
}
@@ -452,10 +448,8 @@ ipu6_psys_init(struct pci_dev *pdev, struct device *parent,
psys_adev->mmu->dev = &psys_adev->auxdev.dev;
ret = ipu6_bus_add_device(psys_adev);
- if (ret) {
- kfree(pdata);
+ if (ret)
return ERR_PTR(ret);
- }
return psys_adev;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0403/1518] drm/amd/display: Fix DM I2C teardown race
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (401 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0402/1518] media: ipu6: Do not free aux device pdata after init Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0404/1518] drm/amd/display: Remove unused-but-set variable hubp from Greg Kroah-Hartman
` (595 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Geoffrey McRae, Alex Deucher, Leo Li,
Christian König, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Geoffrey McRae <geoffrey.mcrae@amd.com>
[ Upstream commit e4ae30a12aa95942814957d8bc1ce7366a7107d7 ]
DM I2C adapters can remain visible to userspace while DM teardown is
already in progress. A concurrent i2c-dev transfer may then enter
amdgpu_dm_i2c_xfer() after the backing DM state has been torn down,
leading to a NULL pointer dereference.
Create a devres group around the DM I2C adapter lifetime and release it
at the start of dm_hw_fini(), before HPD, IRQ, and DM state are torn
down. This removes the I2C adapters first and waits for in-flight users
to drain before the structures used by amdgpu_dm_i2c_xfer() disappear.
This fixes a teardown ordering race seen during device removal:
BUG: kernel NULL pointer dereference
RIP: amdgpu_dm_i2c_xfer+0x122/0x1c0 [amdgpu]
Call Trace:
__i2c_transfer
i2c_transfer
i2cdev_ioctl_rdwr
Fixes: 5b3eca05cfb0 ("drm/amd/display: Use devm_i2c_add_adapter to simplify i2c cleanup logic")
Signed-off-by: Geoffrey McRae <geoffrey.mcrae@amd.com>
Acked-by: Alex Deucher <alexander.deucher@amd.com>
Reviewed-by: Leo Li <sunpeng.li@amd.com>
Cc: Alex Deucher <alexander.deucher@amd.com>
Cc: Christian König <christian.koenig@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c | 14 +++++++++++++-
drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.h | 7 +++++++
2 files changed, 20 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
index 9bce65ca29b02..06eb499f13637 100644
--- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
+++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c
@@ -3040,17 +3040,26 @@ static int dm_hw_init(struct amdgpu_ip_block *ip_block)
struct amdgpu_device *adev = ip_block->adev;
int r;
+ adev->dm.i2c_devres_group = devres_open_group(adev->dev, NULL, GFP_KERNEL);
+ if (!adev->dm.i2c_devres_group)
+ return -ENOMEM;
+
/* Create DAL display manager */
r = amdgpu_dm_init(adev);
if (r)
- return r;
+ goto err_release_i2c;
amdgpu_dm_hpd_init(adev);
r = dm_oem_i2c_hw_init(adev);
if (r)
drm_info(adev_to_drm(adev), "Failed to add OEM i2c bus\n");
+ devres_close_group(adev->dev, adev->dm.i2c_devres_group);
return 0;
+
+err_release_i2c:
+ devres_release_group(adev->dev, adev->dm.i2c_devres_group);
+ return r;
}
/**
@@ -3065,6 +3074,9 @@ static int dm_hw_fini(struct amdgpu_ip_block *ip_block)
{
struct amdgpu_device *adev = ip_block->adev;
+ if (adev->dm.i2c_devres_group)
+ devres_release_group(adev->dev, adev->dm.i2c_devres_group);
+
amdgpu_dm_hpd_fini(adev);
amdgpu_dm_irq_fini(adev);
diff --git a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.h b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.h
index cd362d22a2774..caf6f7387a20a 100644
--- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.h
+++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.h
@@ -664,6 +664,13 @@ struct amdgpu_display_manager {
*/
void *bb_from_dmub;
+ /**
+ * @i2c_devres_group:
+ *
+ * Devres group for DM i2c adapter lifetime management.
+ */
+ void *i2c_devres_group;
+
/**
* @oem_i2c:
*
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0404/1518] drm/amd/display: Remove unused-but-set variable hubp from
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (402 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0403/1518] drm/amd/display: Fix DM I2C teardown race Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0405/1518] cpufreq: intel_pstate: Fix setting minimum P-state at init time Greg Kroah-Hartman
` (594 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Gleb Markov, George Zhang,
Alex Deucher, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gleb Markov <markov.gi@npc-ksb.ru>
[ Upstream commit b736792e5bd4a62f24e8d1e310bf4a75bfbeaaaa ]
The final check of hubp for NULL covers all remaining lines of code, since
the value of hubp does not change until the end of the method.
This check is redundant because hubp1 is already dereferenced within the
macro.
If it were NULL, the program would have already failed to proceed.
Remove the left part of the expression with the logical "&&".
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Fixes: be1fb44389ca ("drm/amd/display: Check null pointers before used").
Signed-off-by: Gleb Markov <markov.gi@npc-ksb.ru>
Reviewed-by: George Zhang <george.zhang@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/amd/display/dc/hubp/dcn10/dcn10_hubp.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/gpu/drm/amd/display/dc/hubp/dcn10/dcn10_hubp.c b/drivers/gpu/drm/amd/display/dc/hubp/dcn10/dcn10_hubp.c
index 9b026600b90e8..99625cba3df66 100644
--- a/drivers/gpu/drm/amd/display/dc/hubp/dcn10/dcn10_hubp.c
+++ b/drivers/gpu/drm/amd/display/dc/hubp/dcn10/dcn10_hubp.c
@@ -769,8 +769,7 @@ bool hubp1_is_flip_pending(struct hubp *hubp)
if (flip_pending)
return true;
- if (hubp &&
- earliest_inuse_address.grph.addr.quad_part != hubp->request_address.grph.addr.quad_part)
+ if (earliest_inuse_address.grph.addr.quad_part != hubp->request_address.grph.addr.quad_part)
return true;
return false;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0405/1518] cpufreq: intel_pstate: Fix setting minimum P-state at init time
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (403 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0404/1518] drm/amd/display: Remove unused-but-set variable hubp from Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0406/1518] cpufreq: schedutil: Fix self-contradictory comment in sugov_iowait_apply() Greg Kroah-Hartman
` (593 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Rafael J. Wysocki, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
[ Upstream commit db53c573d31d07d5d782c5312d37cb33be788eba ]
If HWP is enabled, writes to MSR_IA32_PERF_CTL have no effect,
so intel_pstate_get_cpu_pstates() should not attempt to call
intel_pstate_set_min_pstate() to set the minimum P-state for the
given CPU in that case.
Accordingly, remove the intel_pstate_set_min_pstate()
call from intel_pstate_get_cpu_pstates() and make both
intel_pstate_cpu_init() and intel_cpufreq_cpu_init() call
that function in their non-HWP code paths.
The HWP code path in intel_pstate_cpu_init() does not need to update
the current P-state of the CPU directly at all because it is taken
care of the processor automatically, but the HWP code path of
intel_cpufreq_cpu_init() should update it in principle to
initialize the DESIRED_PERF field in MSR_HWP_REQUEST. For this
purpose, make it call intel_cpufreq_hwp_update() and pass
the minimum P-state limit to it as the current target value along
with the current minimum and maximum limits.
Fixes: f6ebbcf08f37 ("cpufreq: intel_pstate: Implement passive mode with HWP enabled")
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/5090465.GXAFRqVoOG@rafael.j.wysocki
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/cpufreq/intel_pstate.c | 19 +++++++++++--------
1 file changed, 11 insertions(+), 8 deletions(-)
diff --git a/drivers/cpufreq/intel_pstate.c b/drivers/cpufreq/intel_pstate.c
index e6d6a30cf6c90..1de12358c0b98 100644
--- a/drivers/cpufreq/intel_pstate.c
+++ b/drivers/cpufreq/intel_pstate.c
@@ -2389,8 +2389,6 @@ static void intel_pstate_get_cpu_pstates(struct cpudata *cpu)
if (pstate_funcs.get_vid)
pstate_funcs.get_vid(cpu);
-
- intel_pstate_set_min_pstate(cpu);
}
/*
@@ -3098,6 +3096,7 @@ static int __intel_pstate_cpu_init(struct cpufreq_policy *policy)
static int intel_pstate_cpu_init(struct cpufreq_policy *policy)
{
int ret = __intel_pstate_cpu_init(policy);
+ struct cpudata *cpu;
if (ret)
return ret;
@@ -3108,11 +3107,11 @@ static int intel_pstate_cpu_init(struct cpufreq_policy *policy)
*/
policy->policy = CPUFREQ_POLICY_POWERSAVE;
- if (hwp_active) {
- struct cpudata *cpu = all_cpu_data[policy->cpu];
-
+ cpu = all_cpu_data[policy->cpu];
+ if (hwp_active)
cpu->epp_cached = intel_pstate_get_epp(cpu, 0);
- }
+ else
+ intel_pstate_set_min_pstate(cpu);
return 0;
}
@@ -3336,8 +3335,6 @@ static int intel_cpufreq_cpu_init(struct cpufreq_policy *policy)
return ret;
policy->cpuinfo.transition_latency = INTEL_CPUFREQ_TRANSITION_LATENCY;
- /* This reflects the intel_pstate_get_cpu_pstates() setting. */
- policy->cur = policy->cpuinfo.min_freq;
req = kcalloc(2, sizeof(*req), GFP_KERNEL);
if (!req) {
@@ -3358,9 +3355,15 @@ static int intel_cpufreq_cpu_init(struct cpufreq_policy *policy)
WRITE_ONCE(cpu->hwp_req_cached, value);
cpu->epp_cached = intel_pstate_get_epp(cpu, value);
+
+ intel_cpufreq_hwp_update(cpu, cpu->pstate.min_pstate,
+ cpu->pstate.max_pstate,
+ cpu->pstate.min_pstate, false);
} else {
policy->transition_delay_us = INTEL_CPUFREQ_TRANSITION_DELAY;
+ intel_pstate_set_min_pstate(cpu);
}
+ policy->cur = policy->cpuinfo.min_freq;
freq = DIV_ROUND_UP(cpu->pstate.turbo_freq * global.min_perf_pct, 100);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0406/1518] cpufreq: schedutil: Fix self-contradictory comment in sugov_iowait_apply()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (404 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0405/1518] cpufreq: intel_pstate: Fix setting minimum P-state at init time Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0407/1518] remoteproc: qcom: Fix glink->node reference leak in qcom_add_glink_subdev Greg Kroah-Hartman
` (592 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zhongqiu Han, Christian Loehle,
Rafael J. Wysocki, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhongqiu Han <zhongqiu.han@oss.qualcomm.com>
[ Upstream commit db6a017c91b774c15b1b890db45981eacfff540e ]
The kerneldoc of sugov_iowait_apply() says the IO boost value is increased
in sugov_iowait_apply() and, in the same sentence, that it is decreased by
the same function. That is self-contradictory, and the first part is wrong:
sugov_iowait_apply() only decreases the boost.
The boost is actually increased in sugov_iowait_boost(). Fix the comment to
name sugov_iowait_boost() as the place where the boost is increased, so it
matches the code.
No functional change.
Fixes: fd7d5287fd65 ("cpufreq: schedutil: Cleanup and document iowait boost")
Signed-off-by: Zhongqiu Han <zhongqiu.han@oss.qualcomm.com>
Reviewed-by: Christian Loehle <christian.loehle@arm.com>
Link: https://patch.msgid.link/20260703092433.4080165-1-zhongqiu.han@oss.qualcomm.com
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/sched/cpufreq_schedutil.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/kernel/sched/cpufreq_schedutil.c b/kernel/sched/cpufreq_schedutil.c
index 374b65940d03b..22a1fbccb929f 100644
--- a/kernel/sched/cpufreq_schedutil.c
+++ b/kernel/sched/cpufreq_schedutil.c
@@ -325,7 +325,7 @@ static void sugov_iowait_boost(struct sugov_cpu *sg_cpu, u64 time,
* A CPU running a task which woken up after an IO operation can have its
* utilization boosted to speed up the completion of those IO operations.
* The IO boost value is increased each time a task wakes up from IO, in
- * sugov_iowait_apply(), and it's instead decreased by this function,
+ * sugov_iowait_boost(), and it's instead decreased by this function,
* each time an increase has not been requested (!iowait_boost_pending).
*
* A CPU which also appears to have been idle for at least one tick has also
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0407/1518] remoteproc: qcom: Fix glink->node reference leak in qcom_add_glink_subdev
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (405 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0406/1518] cpufreq: schedutil: Fix self-contradictory comment in sugov_iowait_apply() Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0408/1518] perf: evsel: Fix error handling in tp_format lookup Greg Kroah-Hartman
` (591 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Uday Khare, Bjorn Andersson,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Uday Khare <udaykhare77@gmail.com>
[ Upstream commit 44f4911ab8e6f4d69afad5f2571bbd2da421c918 ]
In qcom_add_glink_subdev(), the device node reference acquired via
of_get_child_by_name() is stored in glink->node. If the subsequent
kstrdup_const() allocation for glink->ssr_name fails, the function
returns early without calling of_node_put() on glink->node, leaking
the reference count.
Fix this by adding of_node_put(glink->node) on the error path before
returning.
Fixes: cd9fc8f1b35b ("remoteproc: qcom: Pass ssr_name to glink subdevice")
Signed-off-by: Uday Khare <udaykhare77@gmail.com>
Link: https://lore.kernel.org/r/20260618132054.11010-1-udaykhare77@gmail.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/remoteproc/qcom_common.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/remoteproc/qcom_common.c b/drivers/remoteproc/qcom_common.c
index 5bbbe36d09640..506678d1633e1 100644
--- a/drivers/remoteproc/qcom_common.c
+++ b/drivers/remoteproc/qcom_common.c
@@ -242,8 +242,10 @@ void qcom_add_glink_subdev(struct rproc *rproc, struct qcom_rproc_glink *glink,
return;
glink->ssr_name = kstrdup_const(ssr_name, GFP_KERNEL);
- if (!glink->ssr_name)
+ if (!glink->ssr_name) {
+ of_node_put(glink->node);
return;
+ }
glink->dev = dev;
glink->subdev.start = glink_subdev_start;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0408/1518] perf: evsel: Fix error handling in tp_format lookup
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (406 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0407/1518] remoteproc: qcom: Fix glink->node reference leak in qcom_add_glink_subdev Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0409/1518] drm/bridge: tc358767: clamp the reported AUX read size to the request Greg Kroah-Hartman
` (590 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hongling Zeng, Namhyung Kim,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hongling Zeng <zenghongling@kylinos.cn>
[ Upstream commit 4968708beaad53940b67e4952e34a97d8768091d ]
In evsel__tp_format(), when trace_event__tp_format*() returns an error,
IS_ERR() checks the local variable 'tp_format', but PTR_ERR() incorrectly
uses 'evsel->tp_format' which hasn't been assigned yet.
Fix this by using PTR_ERR(tp_format) to extract the error code from the
correct variable.
Fixes: 6c8310e8380d ("perf evsel: Allow evsel__newtp without libtraceevent")
Signed-off-by: Hongling Zeng <zenghongling@kylinos.cn>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/evsel.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/perf/util/evsel.c b/tools/perf/util/evsel.c
index 22e43a57dc95f..e01103443b23f 100644
--- a/tools/perf/util/evsel.c
+++ b/tools/perf/util/evsel.c
@@ -646,7 +646,7 @@ struct tep_event *evsel__tp_format(struct evsel *evsel)
tp_format = trace_event__tp_format(evsel->tp_sys, evsel->tp_name);
if (IS_ERR(tp_format)) {
- int err = -PTR_ERR(evsel->tp_format);
+ int err = -PTR_ERR(tp_format);
errno = err;
pr_err("Error getting tracepoint format '%s': %m\n",
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0409/1518] drm/bridge: tc358767: clamp the reported AUX read size to the request
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (407 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0408/1518] perf: evsel: Fix error handling in tp_format lookup Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0410/1518] x86/mm/pat: Take cpa_lock around large-page collapse Greg Kroah-Hartman
` (589 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kaixuan Li, Maoyi Xie,
Douglas Anderson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maoyi Xie <maoyixie.tju@gmail.com>
[ Upstream commit ec6444a00c49e6c2b5e9a507272a28126677f9ee ]
tc_aux_transfer() clamps an AUX read to the payload limit:
size_t size = min_t(size_t, DP_AUX_MAX_PAYLOAD_BYTES - 1, msg->size);
After the transfer it replaces size with the byte count the controller
reports in AUX_BYTES:
if (size)
size = FIELD_GET(AUX_BYTES, auxstatus);
AUX_BYTES is GENMASK(15, 8), so it can be up to 255. Nothing clamps it
back to the request. tc_aux_read_data() reads that many bytes into the
16-byte auxrdata stack buffer, then copies them into the caller buffer. A
reported count of 255 makes the read run to 256 bytes and overruns both.
The controller should never report more than it was asked to transfer, so
this is defense in depth rather than a live hole. The reported count is
only lightly trusted, and the check is cheap. Clamp it back to the request,
the same way ti-sn65dsi86 does in commit aca58eac52b8 ("drm/bridge:
ti-sn65dsi86: Never store more than msg->size bytes in AUX xfer").
Fixes: 12dfe7c4d9c5 ("drm/bridge: tc358767: Use reported AUX transfer size")
Co-developed-by: Kaixuan Li <kaixuan.li@ntu.edu.sg>
Signed-off-by: Kaixuan Li <kaixuan.li@ntu.edu.sg>
Signed-off-by: Maoyi Xie <maoyixie.tju@gmail.com>
Reviewed-by: Douglas Anderson <dianders@chromium.org>
Signed-off-by: Douglas Anderson <dianders@chromium.org>
Link: https://patch.msgid.link/20260701064440.1541418-1-maoyixie.tju@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/bridge/tc358767.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/bridge/tc358767.c b/drivers/gpu/drm/bridge/tc358767.c
index 4097fef4b86b5..26ba5a6c1b742 100644
--- a/drivers/gpu/drm/bridge/tc358767.c
+++ b/drivers/gpu/drm/bridge/tc358767.c
@@ -527,7 +527,7 @@ static ssize_t tc_aux_transfer(struct drm_dp_aux *aux,
* address-only transfer
*/
if (size)
- size = FIELD_GET(AUX_BYTES, auxstatus);
+ size = min_t(size_t, size, FIELD_GET(AUX_BYTES, auxstatus));
msg->reply = FIELD_GET(AUX_STATUS, auxstatus);
switch (request) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0410/1518] x86/mm/pat: Take cpa_lock around large-page collapse
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (408 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0409/1518] drm/bridge: tc358767: clamp the reported AUX read size to the request Greg Kroah-Hartman
@ 2026-09-12 6:42 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0411/1518] arm64: dts: qcom: msm8996-xiaomi-gemini: Fix up ti,drv2604 enable GPIO Greg Kroah-Hartman
` (588 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:42 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Denis V. Lunev, Dave Hansen,
Kiryl Shutsemau (Meta), Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Denis V. Lunev <den@openvz.org>
[ Upstream commit 1aac65f3e651334259ecb2a5f5ddb81c01f02599 ]
Loading and unloading modules concurrently on several CPUs on a KASAN
build, with a short delay injected at the CPA page-table lookup to
widen the window, faults within minutes:
BUG: KASAN: use-after-free in __change_page_attr+0x7cc/0x7e0
Write of size 8 at addr ffff888181139718 by task modprobe
...
The buggy address belongs to the physical page:
pfn:0x181139 ... page_type: f2(table)
cpa_collapse_large_pages() rebuilds a leaf PMD from its 4K PTEs and
frees the old PTE-table pages, while __change_page_attr() fetches a
PTE pointer from a lockless lookup_address_in_pgd_attr() and writes
it with set_pte_atomic() only later. When module text is served from
a shared large ROX mapping the two run on the same PMD:
CPU A (module load) CPU B (module finalize)
------------------- -----------------------
execmem_make_temp_rw
set_memory_nx
__change_page_attr
split 2M -> 4K table P
kpte = &P[i] (lockless)
execmem_restore_rox
set_memory_rox (CPA_COLLAPSE)
cpa_collapse_large_pages
rebuild leaf PMD
flush_tlb_all
pagetable_free(P)
set_pte_atomic(kpte, ...)
-> writes into freed P
P is a page-table page (page_type: table), reused at once, so the
write corrupts whatever got the page next: a bad-pte or bad-page
splat, or a fatal fault once P has been turned into read-only text.
The flush_tlb_all() before the free does not close this: its IPI only
serializes against page-table walkers that run with interrupts off
(e.g. GUP-fast); the walk in __change_page_attr() runs with interrupts
on, so nothing stops it from holding a stale pointer into P.
Serialize the collapse - the PMD rebuild, TLB flush and PTE-table
free - under cpa_lock, the same lock __change_page_attr() now takes
unconditionally since commit ("x86/mm/pat: stop gating cpa_lock on
debug_pagealloc_enabled()"), so a concurrent walker can no longer
hold a pointer into a table the collapse is about to free.
Fixes: 41d88484c71c ("x86/mm/pat: restore large ROX pages after fragmentation")
Signed-off-by: Denis V. Lunev <den@openvz.org>
Signed-off-by: Dave Hansen <dave.hansen@linux.intel.com>
Acked-by: Kiryl Shutsemau (Meta) <kas@kernel.org>
Link: https://patch.msgid.link/20260715183453.2381141-1-den@openvz.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/mm/pat/set_memory.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/arch/x86/mm/pat/set_memory.c b/arch/x86/mm/pat/set_memory.c
index fffb6ef1997d2..de74be2e69bf7 100644
--- a/arch/x86/mm/pat/set_memory.c
+++ b/arch/x86/mm/pat/set_memory.c
@@ -409,6 +409,8 @@ static void cpa_collapse_large_pages(struct cpa_data *cpa)
int collapsed = 0;
int i;
+ spin_lock(&cpa_lock);
+
if (cpa->flags & (CPA_PAGES_ARRAY | CPA_ARRAY)) {
for (i = 0; i < cpa->numpages; i++)
collapsed += collapse_large_pages(__cpa_addr(cpa, i),
@@ -422,8 +424,10 @@ static void cpa_collapse_large_pages(struct cpa_data *cpa)
collapsed += collapse_large_pages(addr, &pgtables);
}
- if (!collapsed)
+ if (!collapsed) {
+ spin_unlock(&cpa_lock);
return;
+ }
flush_tlb_all();
@@ -431,6 +435,8 @@ static void cpa_collapse_large_pages(struct cpa_data *cpa)
list_del(&ptdesc->pt_list);
pagetable_free(ptdesc);
}
+
+ spin_unlock(&cpa_lock);
}
static void cpa_flush(struct cpa_data *cpa, int cache)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0411/1518] arm64: dts: qcom: msm8996-xiaomi-gemini: Fix up ti,drv2604 enable GPIO
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (409 preceding siblings ...)
2026-09-12 6:42 ` [PATCH 6.18 0410/1518] x86/mm/pat: Take cpa_lock around large-page collapse Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0412/1518] arm64: dts: qcom: sc8280xp-x13s: Fix the drive-strength of mclk pin Greg Kroah-Hartman
` (587 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Krzysztof Kozlowski,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
[ Upstream commit 569413a98a1761782a0770aa85d20a2c78893279 ]
Update the 'enable-gpio' property name to 'enable-gpios' to conform to
the bindings for the TI DRV2604 haptics module. While at it, use the
GPIO_ACTIVE_HIGH define instead of the raw literal.
Fixes: 4ac46b3682c5 ("arm64: dts: qcom: msm8996: xiaomi-gemini: Add support for Xiaomi Mi 5")
Signed-off-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260625-topic-ti_drv2604_dtwarn-v1-1-76e91fcafbe8@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/msm8996-xiaomi-gemini.dts | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/arm64/boot/dts/qcom/msm8996-xiaomi-gemini.dts b/arch/arm64/boot/dts/qcom/msm8996-xiaomi-gemini.dts
index bd3f39e1b98fb..9a9c674501202 100644
--- a/arch/arm64/boot/dts/qcom/msm8996-xiaomi-gemini.dts
+++ b/arch/arm64/boot/dts/qcom/msm8996-xiaomi-gemini.dts
@@ -39,7 +39,7 @@ &blsp2_i2c3 {
haptics: drv2604@5a {
compatible = "ti,drv2604";
reg = <0x5a>;
- enable-gpio = <&tlmm 93 0x00>;
+ enable-gpios = <&tlmm 93 GPIO_ACTIVE_HIGH>;
mode = <DRV260X_LRA_MODE>;
library-sel = <DRV260X_LIB_LRA>;
pinctrl-names = "default","sleep";
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0412/1518] arm64: dts: qcom: sc8280xp-x13s: Fix the drive-strength of mclk pin
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (410 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0411/1518] arm64: dts: qcom: msm8996-xiaomi-gemini: Fix up ti,drv2604 enable GPIO Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0413/1518] arm64: dts: qcom: ipq5018: Correct CMN PLL reference clock rate Greg Kroah-Hartman
` (586 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pengyu Luo, Konrad Dybcio,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengyu Luo <mitltlatltl@gmail.com>
[ Upstream commit 09531bb8e0de5081fdbe215877dd7f2ec8b2f0e1 ]
The value can be retrieve via windbg on Windows.
lkd> !dd f111000 L8
ctl_reg => 0x284
in drivers/pinctrl/qcom/pinctrl-msm.c
function msm_gpio_dbg_show_one()
...
drive = (ctl_reg >> g->drv_bit) & 7; // (0x284 >> 6) & 7 == 2
...
seq_printf(s, " %dmA", msm_regval_to_drive(drive)); // (drive + 1) * 2 == 6;
...
So the value is 6, not 16, it matches Windows now.
Fixes: 21927e94caa5 ("arm64: dts: qcom: sc8280xp-x13s: Enable RGB sensor")
Signed-off-by: Pengyu Luo <mitltlatltl@gmail.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260629065905.15651-2-mitltlatltl@gmail.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sc8280xp-lenovo-thinkpad-x13s.dts | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/arm64/boot/dts/qcom/sc8280xp-lenovo-thinkpad-x13s.dts b/arch/arm64/boot/dts/qcom/sc8280xp-lenovo-thinkpad-x13s.dts
index 637430719e6d7..a7559eb411018 100644
--- a/arch/arm64/boot/dts/qcom/sc8280xp-lenovo-thinkpad-x13s.dts
+++ b/arch/arm64/boot/dts/qcom/sc8280xp-lenovo-thinkpad-x13s.dts
@@ -1561,7 +1561,7 @@ cam_rgb_default: cam-rgb-default-state {
mclk-pins {
pins = "gpio17";
function = "cam_mclk";
- drive-strength = <16>;
+ drive-strength = <6>;
bias-disable;
};
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0413/1518] arm64: dts: qcom: ipq5018: Correct CMN PLL reference clock rate
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (411 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0412/1518] arm64: dts: qcom: sc8280xp-x13s: Fix the drive-strength of mclk pin Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0414/1518] arm64: qcom: ipq5018: Add GEPHY RX and TX clocks Greg Kroah-Hartman
` (585 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, George Moussalem, Konrad Dybcio,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: George Moussalem <george.moussalem@outlook.com>
[ Upstream commit 5e92312a1d7542be9a0e588467bfbb2ca123eaac ]
The correct CMN PLL reference clock rate for IPQ5018 is 4.8 GHz.
The CMN PLL driver did not account for the ref clock divider which is 2
for IPQ5018. Therefore, the computed rate was twice the actual output.
With the driver now accounting for the CMN PLL reference clock
divider (commit: 88c543fff756), set the correct reference clock rate.
Fixes: c006b249c544 ("arm64: dts: ipq5018: Add CMN PLL node")
Signed-off-by: George Moussalem <george.moussalem@outlook.com>
Acked-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260521-ipq5018-cmn-pll-rate-fix-v2-1-04b28a92e0f2@outlook.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/ipq5018.dtsi | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/arm64/boot/dts/qcom/ipq5018.dtsi b/arch/arm64/boot/dts/qcom/ipq5018.dtsi
index f024b3cba33f6..ed1abb41fbe47 100644
--- a/arch/arm64/boot/dts/qcom/ipq5018.dtsi
+++ b/arch/arm64/boot/dts/qcom/ipq5018.dtsi
@@ -256,7 +256,7 @@ cmn_pll: clock-controller@9b000 {
"sys";
#clock-cells = <1>;
assigned-clocks = <&cmn_pll IPQ5018_CMN_PLL_CLK>;
- assigned-clock-rates-u64 = /bits/ 64 <9600000000>;
+ assigned-clock-rates-u64 = /bits/ 64 <4800000000>;
};
qfprom: qfprom@a0000 {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0414/1518] arm64: qcom: ipq5018: Add GEPHY RX and TX clocks
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (412 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0413/1518] arm64: dts: qcom: ipq5018: Correct CMN PLL reference clock rate Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0415/1518] arm64: dts: qcom: sm8250: sort out Iris power domains Greg Kroah-Hartman
` (584 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dmitry Baryshkov, George Moussalem,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: George Moussalem <george.moussalem@outlook.com>
[ Upstream commit 742dc058588bf1233647dcd95738c0afc621435d ]
Add RX and TX clocks for the IPQ5018 GEPHY to enable the datapath.
Fixes: f5f2b835e316 ("arm64: dts: qcom: ipq5018: Add GE PHY to internal mdio bus")
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: George Moussalem <george.moussalem@outlook.com>
Link: https://lore.kernel.org/r/20260608-ipq5018-gephy-clocks-v4-3-fb2ccd56894b@outlook.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/ipq5018.dtsi | 3 +++
1 file changed, 3 insertions(+)
diff --git a/arch/arm64/boot/dts/qcom/ipq5018.dtsi b/arch/arm64/boot/dts/qcom/ipq5018.dtsi
index ed1abb41fbe47..40b5de02d5c5d 100644
--- a/arch/arm64/boot/dts/qcom/ipq5018.dtsi
+++ b/arch/arm64/boot/dts/qcom/ipq5018.dtsi
@@ -229,6 +229,9 @@ ge_phy: ethernet-phy@7 {
compatible = "ethernet-phy-id004d.d0c0";
reg = <7>;
+ clocks = <&gcc GCC_GEPHY_RX_CLK>,
+ <&gcc GCC_GEPHY_TX_CLK>;
+ clock-names = "rx", "tx";
resets = <&gcc GCC_GEPHY_MISC_ARES>;
};
};
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0415/1518] arm64: dts: qcom: sm8250: sort out Iris power domains
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (413 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0414/1518] arm64: qcom: ipq5018: Add GEPHY RX and TX clocks Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0416/1518] arm64: dts: qcom: sm8250: correct frequencies in the Iris OPP table Greg Kroah-Hartman
` (583 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Dmitry Baryshkov,
Dikshita Agarwal, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
[ Upstream commit d5c8efda722eb1f67cfe299b71f13dab93746934 ]
On SM8250 Iris core requires two power rails to function, MX (for PLLs)
and MMCX (for everything else). The commit fa245b3f06cd ("arm64: dts:
qcom: sm8250: Add venus DT node") added only MX power rail, but omitted
MMCX voltage levels.
Add MMCX domain to the Iris device node.
Fixes: fa245b3f06cd ("arm64: dts: qcom: sm8250: Add venus DT node")
Reported-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Dikshita Agarwal <dikshita.agarwal@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260604-iris-venus-fix-sm8250-v7-1-7bd2f0e5bae8@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sm8250.dtsi | 20 ++++++++++++++------
1 file changed, 14 insertions(+), 6 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sm8250.dtsi b/arch/arm64/boot/dts/qcom/sm8250.dtsi
index 79ba2c0c96b7e..bdd175392015c 100644
--- a/arch/arm64/boot/dts/qcom/sm8250.dtsi
+++ b/arch/arm64/boot/dts/qcom/sm8250.dtsi
@@ -4321,8 +4321,12 @@ venus: video-codec@aa00000 {
interrupts = <GIC_SPI 174 IRQ_TYPE_LEVEL_HIGH>;
power-domains = <&videocc MVS0C_GDSC>,
<&videocc MVS0_GDSC>,
- <&rpmhpd RPMHPD_MX>;
- power-domain-names = "venus", "vcodec0", "mx";
+ <&rpmhpd RPMHPD_MX>,
+ <&rpmhpd RPMHPD_MMCX>;
+ power-domain-names = "venus",
+ "vcodec0",
+ "mx",
+ "mmcx";
operating-points-v2 = <&venus_opp_table>;
clocks = <&gcc GCC_VIDEO_AXI0_CLK>,
@@ -4348,22 +4352,26 @@ venus_opp_table: opp-table {
opp-720000000 {
opp-hz = /bits/ 64 <720000000>;
- required-opps = <&rpmhpd_opp_low_svs>;
+ required-opps = <&rpmhpd_opp_svs>,
+ <&rpmhpd_opp_low_svs>;
};
opp-1014000000 {
opp-hz = /bits/ 64 <1014000000>;
- required-opps = <&rpmhpd_opp_svs>;
+ required-opps = <&rpmhpd_opp_svs>,
+ <&rpmhpd_opp_svs>;
};
opp-1098000000 {
opp-hz = /bits/ 64 <1098000000>;
- required-opps = <&rpmhpd_opp_svs_l1>;
+ required-opps = <&rpmhpd_opp_svs_l1>,
+ <&rpmhpd_opp_svs_l1>;
};
opp-1332000000 {
opp-hz = /bits/ 64 <1332000000>;
- required-opps = <&rpmhpd_opp_nom>;
+ required-opps = <&rpmhpd_opp_svs_l1>,
+ <&rpmhpd_opp_nom>;
};
};
};
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0416/1518] arm64: dts: qcom: sm8250: correct frequencies in the Iris OPP table
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (414 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0415/1518] arm64: dts: qcom: sm8250: sort out Iris power domains Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0417/1518] perf jevents: Add more components to the metric sorting order Greg Kroah-Hartman
` (582 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Dikshita Agarwal,
Dmitry Baryshkov, Vishnu Reddy, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
[ Upstream commit 68ea007df9293fcb29d38219d73094bbf4b59673 ]
The OPP table for the Iris core is wrong, it copies the VDD table from
the downstream kernel, but that table is written for the
video_cc_mvs0_clk_src, while the upstream uses video_cc_mvs0_clk for OPP
rate setting (which is clk_src divided by 3). Specify correct
frequencies in the OPP table.
Fixes: fa245b3f06cd ("arm64: dts: qcom: sm8250: Add venus DT node")
Reported-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Dikshita Agarwal <dikshita.agarwal@oss.qualcomm.com>
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Reviewed-by: Vishnu Reddy <busanna.reddy@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260604-iris-venus-fix-sm8250-v7-2-7bd2f0e5bae8@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sm8250.dtsi | 16 ++++++++--------
1 file changed, 8 insertions(+), 8 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sm8250.dtsi b/arch/arm64/boot/dts/qcom/sm8250.dtsi
index bdd175392015c..dfba5bc3ba7cf 100644
--- a/arch/arm64/boot/dts/qcom/sm8250.dtsi
+++ b/arch/arm64/boot/dts/qcom/sm8250.dtsi
@@ -4350,26 +4350,26 @@ venus: video-codec@aa00000 {
venus_opp_table: opp-table {
compatible = "operating-points-v2";
- opp-720000000 {
- opp-hz = /bits/ 64 <720000000>;
+ opp-240000000 {
+ opp-hz = /bits/ 64 <240000000>;
required-opps = <&rpmhpd_opp_svs>,
<&rpmhpd_opp_low_svs>;
};
- opp-1014000000 {
- opp-hz = /bits/ 64 <1014000000>;
+ opp-338000000 {
+ opp-hz = /bits/ 64 <338000000>;
required-opps = <&rpmhpd_opp_svs>,
<&rpmhpd_opp_svs>;
};
- opp-1098000000 {
- opp-hz = /bits/ 64 <1098000000>;
+ opp-366000000 {
+ opp-hz = /bits/ 64 <366000000>;
required-opps = <&rpmhpd_opp_svs_l1>,
<&rpmhpd_opp_svs_l1>;
};
- opp-1332000000 {
- opp-hz = /bits/ 64 <1332000000>;
+ opp-444000000 {
+ opp-hz = /bits/ 64 <444000000>;
required-opps = <&rpmhpd_opp_svs_l1>,
<&rpmhpd_opp_nom>;
};
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0417/1518] perf jevents: Add more components to the metric sorting order
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (415 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0416/1518] arm64: dts: qcom: sm8250: correct frequencies in the Iris OPP table Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0418/1518] clk: qcom: gcc-glymur: Enable runtime PM Greg Kroah-Hartman
` (581 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nazar Kazakov, Ian Rogers,
Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ian Rogers <irogers@google.com>
[ Upstream commit 557f8b3ca8c8e58d5bc3084734bc7a470b043922 ]
Nazar Kazakov reported non-deterministic builds due to the metrics
being reordered in the jevents.py output. The metrics were largely
only being sorted by name, add in the expressions and descriptions.
Reported-by: Nazar Kazakov <nazar.kazakov@codethink.co.uk>
Closes: https://lore.kernel.org/linux-perf-users/20260706175624.692736-1-nazar.kazakov@codethink.co.uk/
Fixes: 40769665b63d ("perf jevents: Parse metrics during conversion")
Tested-by: Nazar Kazakov <nazar.kazakov@codethink.co.uk>
Signed-off-by: Ian Rogers <irogers@google.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/pmu-events/jevents.py | 5 +++--
tools/perf/pmu-events/metric.py | 6 +++++-
2 files changed, 8 insertions(+), 3 deletions(-)
diff --git a/tools/perf/pmu-events/jevents.py b/tools/perf/pmu-events/jevents.py
index 168c044dd7cc3..59426ba68de55 100755
--- a/tools/perf/pmu-events/jevents.py
+++ b/tools/perf/pmu-events/jevents.py
@@ -559,13 +559,14 @@ const struct pmu_table_entry {_pending_events_tblname}[] = {{
def print_pending_metrics() -> None:
"""Optionally close metrics table."""
- def metric_cmp_key(j: JsonEvent) -> Tuple[bool, str, str]:
+ def metric_cmp_key(j: JsonEvent) -> Tuple[str, str, str, str]:
def fix_none(s: Optional[str]) -> str:
if s is None:
return ''
return s
- return (j.desc is not None, fix_none(j.pmu), fix_none(j.metric_name))
+ return (fix_none(j.pmu), fix_none(j.metric_name), j.metric_expr.ToPerfJson(),
+ fix_none(j.desc))
global _pending_metrics
if not _pending_metrics:
diff --git a/tools/perf/pmu-events/metric.py b/tools/perf/pmu-events/metric.py
index 92acd89ed97aa..ac322891c4f1b 100644
--- a/tools/perf/pmu-events/metric.py
+++ b/tools/perf/pmu-events/metric.py
@@ -445,7 +445,11 @@ class Metric:
def __lt__(self, other):
"""Sort order."""
- return self.name < other.name
+ if self.name != other.name:
+ return self.name < other.name
+ if not self.expr.Equals(other.expr):
+ return self.expr.ToPerfJson() < other.expr.ToPerfJson()
+ return self.description < other.description
def AddToMetricGroup(self, group):
"""Callback used when being added to a MetricGroup."""
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0418/1518] clk: qcom: gcc-glymur: Enable runtime PM
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (416 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0417/1518] perf jevents: Add more components to the metric sorting order Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0419/1518] soc: renesas: r8a78000: Drop duplicate "default ARCH_RENESAS" Greg Kroah-Hartman
` (580 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Abel Vesa, Bjorn Andersson,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Abel Vesa <abel.vesa@oss.qualcomm.com>
[ Upstream commit 8d4f342369d0d77f32a0211692442d3b6d455872 ]
Enable runtime PM for the controller so the common GCC probe path resumes
the attached domain while registering clocks, resets and GDSCs.
This lets GDSC consumers propagate their votes through the GCC provider to
the CX parent domain.
Fixes: efe504300a17 ("clk: qcom: gcc: Add support for Global Clock Controller")
Signed-off-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260715-glymur-fix-gcc-cx-scaling-v3-2-72eb5adad156@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/qcom/gcc-glymur.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/clk/qcom/gcc-glymur.c b/drivers/clk/qcom/gcc-glymur.c
index 9e84f3e7c6a9b..7adbe59915f0f 100644
--- a/drivers/clk/qcom/gcc-glymur.c
+++ b/drivers/clk/qcom/gcc-glymur.c
@@ -8551,6 +8551,7 @@ static const struct qcom_cc_desc gcc_glymur_desc = {
.num_resets = ARRAY_SIZE(gcc_glymur_resets),
.gdscs = gcc_glymur_gdscs,
.num_gdscs = ARRAY_SIZE(gcc_glymur_gdscs),
+ .use_rpm = true,
.driver_data = &gcc_glymur_driver_data,
};
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0419/1518] soc: renesas: r8a78000: Drop duplicate "default ARCH_RENESAS"
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (417 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0418/1518] clk: qcom: gcc-glymur: Enable runtime PM Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0420/1518] spi: geni-qcom: Fix sticky ret causing wrong return value on invalid proto Greg Kroah-Hartman
` (579 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Marek Vasut, Geert Uytterhoeven,
Marek Vasut, Kuninori Morimoto, Duy Nguyen, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Geert Uytterhoeven <geert+renesas@glider.be>
[ Upstream commit 07231087d5e24c4d9c578c824b96f8af913f7324 ]
The Kconfig entry for ARCH_R8A78000 contains both "default y if
ARCH_RENESAS" and "default ARCH_RENESAS", which are sort-of duplicates.
Drop the latter, to restore consistency with the other ARM64 entries.
Fixes: 5284d0b09d1bdc69 ("soc: renesas: Identify R-Car X5H")
Reported-by: Marek Vasut <marek.vasut@mailbox.org>
Closes: https://lore.kernel.org/a069d50d-030d-4189-ae9d-37f989829da4@mailbox.org
Signed-off-by: Geert Uytterhoeven <geert+renesas@glider.be>
Reviewed-by: Marek Vasut <marek.vasut+renesas@mailbox.org>
Reviewed-by: Kuninori Morimoto <kuninori.morimoto.gx@renesas.com>
Reviewed-by: Duy Nguyen <duy.nguyen.rh@renesas.com>
Link: https://patch.msgid.link/64de6e95719a6dec7412cf7e917a42749e738b99.1783593775.git.geert+renesas@glider.be
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/soc/renesas/Kconfig | 1 -
1 file changed, 1 deletion(-)
diff --git a/drivers/soc/renesas/Kconfig b/drivers/soc/renesas/Kconfig
index 340a1ff7e92b4..f151b05fbb8fa 100644
--- a/drivers/soc/renesas/Kconfig
+++ b/drivers/soc/renesas/Kconfig
@@ -355,7 +355,6 @@ config ARCH_R8A779H0
config ARCH_R8A78000
bool "ARM64 Platform support for R8A78000 (R-Car X5H)"
default y if ARCH_RENESAS
- default ARCH_RENESAS
select ARCH_RCAR_GEN5
help
This enables support for the Renesas R-Car X5H SoC.
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0420/1518] spi: geni-qcom: Fix sticky ret causing wrong return value on invalid proto
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (418 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0419/1518] soc: renesas: r8a78000: Drop duplicate "default ARCH_RENESAS" Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0421/1518] wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs Greg Kroah-Hartman
` (578 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, kernel test robot, Dan Carpenter,
Praveen Talari, Konrad Dybcio, Mukesh Kumar Savaliya, Mark Brown,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Praveen Talari <praveen.talari@oss.qualcomm.com>
[ Upstream commit 2c1c13da3a3a639d2ac7221e1a5e57945cbc7235 ]
spi_geni_init() reuses 'ret' after it has already been set by the
runtime PM acquire check earlier in the function. When an invalid
protocol is later detected, the function returns this stale 'ret'
value instead of a proper error code, so it can end up returning 0
(or some other non-error value) even though the protocol check
failed.
Fix this by returning -EINVAL directly on both invalid-proto paths.
Fixes: d8e9ea989acb ("spi: qcom-geni: Fix missing error check on pm_runtime_get_sync()")
Reported-by: kernel test robot <lkp@intel.com>
Reported-by: Dan Carpenter <error27@gmail.com>
Closes: https://lore.kernel.org/r/202607122241.qzP3QAXF-lkp@intel.com/
Signed-off-by: Praveen Talari <praveen.talari@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Acked-by: Mukesh Kumar Savaliya <mukesh.savaliya@oss.qualcomm.com>
Link: https://patch.msgid.link/20260716-fix_return_error_code-v1-1-3295003aacd5@oss.qualcomm.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/spi/spi-geni-qcom.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/spi/spi-geni-qcom.c b/drivers/spi/spi-geni-qcom.c
index 117ff94df9430..ec40fcb1067b7 100644
--- a/drivers/spi/spi-geni-qcom.c
+++ b/drivers/spi/spi-geni-qcom.c
@@ -669,7 +669,7 @@ static int spi_geni_init(struct spi_geni_master *mas)
if (spi->target) {
if (proto != GENI_SE_SPI_SLAVE) {
dev_err(mas->dev, "Invalid proto %d\n", proto);
- return ret;
+ return -EINVAL;
}
spi_slv_setup(mas);
} else if (proto == GENI_SE_INVALID_PROTO) {
@@ -680,7 +680,7 @@ static int spi_geni_init(struct spi_geni_master *mas)
}
} else if (proto != GENI_SE_SPI) {
dev_err(mas->dev, "Invalid proto %d\n", proto);
- return ret;
+ return -EINVAL;
}
mas->tx_fifo_depth = geni_se_get_tx_fifo_depth(se);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0421/1518] wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (419 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0420/1518] spi: geni-qcom: Fix sticky ret causing wrong return value on invalid proto Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0422/1518] wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser Greg Kroah-Hartman
` (577 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Emmanuel Grumbach, Miri Korenblit,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
[ Upstream commit 71e67b4b59337b2f9f4fef976a27de2dad7aabf2 ]
The loop counter 'count' was declared as u8 while num_pc is u32.
If firmware advertises more than 255 PC entries the counter wraps
back to zero and the loop never terminates potentially causing an
infinite loop or reading past the allocated pc_data array.
Change the declaration to u32 to match num_pc.
Fixes: 2b69d242e29b ("wifi: iwlwifi: fw: print PC register value instead of address")
Assisted-by: GitHubCopilot:gpt-5.3-codex
Signed-off-by: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
Signed-off-by: Miri Korenblit <miriam.rachel.korenblit@intel.com>
Link: https://patch.msgid.link/20260715220243.a61c65f34e87.Ie5f1a7ca43e0cc5a0ddc8305b0448ddffc09cd18@changeid
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/intel/iwlwifi/fw/dump.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/intel/iwlwifi/fw/dump.c b/drivers/net/wireless/intel/iwlwifi/fw/dump.c
index ddd714cff2f4d..87acbb482435a 100644
--- a/drivers/net/wireless/intel/iwlwifi/fw/dump.c
+++ b/drivers/net/wireless/intel/iwlwifi/fw/dump.c
@@ -436,7 +436,7 @@ static void iwl_fwrt_dump_fseq_regs(struct iwl_fw_runtime *fwrt)
void iwl_fwrt_dump_error_logs(struct iwl_fw_runtime *fwrt)
{
struct iwl_pc_data *pc_data;
- u8 count;
+ u32 count;
if (!iwl_trans_device_enabled(fwrt->trans)) {
IWL_ERR(fwrt,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0422/1518] wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (420 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0421/1518] wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0423/1518] wifi: iwlwifi: mei: check SAP message length before reading it Greg Kroah-Hartman
` (576 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Emmanuel Grumbach, Miri Korenblit,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
[ Upstream commit f6a6c01cbc046f68e6916a7e047a1bc881c8c9ab ]
iwl_mvm_frob_txf_key_iter() tracks the last matched byte position
in loop variable 'i'. When a full key match is found (match ==
keylen), 'i' points at the last byte of the matched key. The
memset start offset should therefore be i + 1 - keylen, not
i - keylen; the current code zeroes one byte before the match
and leaves the final key byte un-sanitised.
Fixes: 12d60c1efc29 ("iwlwifi: mvm: scrub key material in firmware dumps")
Assisted-by: GitHubCopilot:gpt-5.3-codex
Signed-off-by: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
Signed-off-by: Miri Korenblit <miriam.rachel.korenblit@intel.com>
Link: https://patch.msgid.link/20260715220243.355998ec4fbe.I40f3427657b897e911bdf4ebf8e494745508d126@changeid
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/intel/iwlwifi/mvm/ops.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/intel/iwlwifi/mvm/ops.c b/drivers/net/wireless/intel/iwlwifi/mvm/ops.c
index 8e6913c7712f0..d6a13174b5617 100644
--- a/drivers/net/wireless/intel/iwlwifi/mvm/ops.c
+++ b/drivers/net/wireless/intel/iwlwifi/mvm/ops.c
@@ -954,7 +954,7 @@ static void iwl_mvm_frob_txf_key_iter(struct ieee80211_hw *hw,
}
match++;
if (match == keylen) {
- memset(txf->buf + i - keylen, 0xAA, keylen);
+ memset(txf->buf + i + 1 - keylen, 0xAA, keylen);
match = 0;
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0423/1518] wifi: iwlwifi: mei: check SAP message length before reading it
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (421 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0422/1518] wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0424/1518] wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments Greg Kroah-Hartman
` (575 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Avraham Stern, Miri Korenblit,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Avraham Stern <avraham.stern@intel.com>
[ Upstream commit 7d8cc301bcba233f31b589a45f4c1c97f2bb90d6 ]
Verify the SAP message size is not larger than the local buffer before
reading the message to avoid buffer overflow.
Fixes: bcd68b3dbe78 ("wifi: iwlwifi: mei: fix tx DHCP packet for devices with new Tx API")
Signed-off-by: Avraham Stern <avraham.stern@intel.com>
Signed-off-by: Miri Korenblit <miriam.rachel.korenblit@intel.com>
Link: https://patch.msgid.link/20260715220243.f0026ce26218.I00a856d3aacae1caac605c708f7362689b734234@changeid
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/intel/iwlwifi/mei/main.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/net/wireless/intel/iwlwifi/mei/main.c b/drivers/net/wireless/intel/iwlwifi/mei/main.c
index dce0b7cf7b265..c083af5240593 100644
--- a/drivers/net/wireless/intel/iwlwifi/mei/main.c
+++ b/drivers/net/wireless/intel/iwlwifi/mei/main.c
@@ -1,6 +1,7 @@
// SPDX-License-Identifier: GPL-2.0-only
/*
* Copyright (C) 2021-2024 Intel Corporation
+ * Copyright (C) 2026 Intel Corporation
*/
#include <linux/etherdevice.h>
@@ -1147,6 +1148,11 @@ static void iwl_mei_handle_sap_rx_cmd(struct mei_cl_device *cldev,
iwl_mei_read_from_q(q_head, q_sz, &rd, wr, hdr, sizeof(*hdr));
valid_rx_sz -= sizeof(*hdr);
len = le16_to_cpu(hdr->len);
+ if (len + sizeof(*hdr) > PAGE_SIZE) {
+ dev_err(&cldev->dev,
+ "SAP message is too big: %u\n", len);
+ break;
+ }
if (valid_rx_sz < len)
break;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0424/1518] wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (422 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0423/1518] wifi: iwlwifi: mei: check SAP message length before reading it Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0425/1518] wifi: iwlwifi: mei: pass correct argument to function Greg Kroah-Hartman
` (574 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Emmanuel Grumbach, Miri Korenblit,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
[ Upstream commit 9318bc0c41b24705690cf80d1596cf6b711e7027 ]
Make sure we don't end-up with a num_frags = 0 situation.
For that, check that the required size is not 0 and put a checker on
num_frags as well.
Fixes: 14124b25780d ("iwlwifi: dbg_ini: implement monitor allocation flow")
Assisted-by: GitHubCopilot:gpt-5.3-codex
Signed-off-by: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
Signed-off-by: Miri Korenblit <miriam.rachel.korenblit@intel.com>
Link: https://patch.msgid.link/20260715220243.60121deecf2c.Iebc891c95a7bd1b2a093b0bb88532db446a758ee@changeid
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/intel/iwlwifi/iwl-dbg-tlv.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/intel/iwlwifi/iwl-dbg-tlv.c b/drivers/net/wireless/intel/iwlwifi/iwl-dbg-tlv.c
index 5240dacf13607..fe37c8f75c71d 100644
--- a/drivers/net/wireless/intel/iwlwifi/iwl-dbg-tlv.c
+++ b/drivers/net/wireless/intel/iwlwifi/iwl-dbg-tlv.c
@@ -1,6 +1,6 @@
// SPDX-License-Identifier: GPL-2.0 OR BSD-3-Clause
/*
- * Copyright (C) 2018-2025 Intel Corporation
+ * Copyright (C) 2018-2026 Intel Corporation
*/
#include <linux/firmware.h>
#include "iwl-drv.h"
@@ -602,6 +602,9 @@ static int iwl_dbg_tlv_alloc_fragments(struct iwl_fw_runtime *fwrt,
cpu_to_le32(IWL_FW_INI_LOCATION_DRAM_PATH))
return 0;
+ if (!fw_mon_cfg->req_size)
+ return -EIO;
+
num_frags = le32_to_cpu(fw_mon_cfg->max_frags_num);
if (fwrt->trans->mac_cfg->device_family < IWL_DEVICE_FAMILY_AX210) {
if (alloc_id != IWL_FW_INI_ALLOCATION_ID_DBGC1)
@@ -612,6 +615,9 @@ static int iwl_dbg_tlv_alloc_fragments(struct iwl_fw_runtime *fwrt,
return -EIO;
}
+ if (!num_frags)
+ return -EIO;
+
remain_pages = DIV_ROUND_UP(le32_to_cpu(fw_mon_cfg->req_size),
PAGE_SIZE);
num_frags = min_t(u32, num_frags, BUF_ALLOC_MAX_NUM_FRAGS);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0425/1518] wifi: iwlwifi: mei: pass correct argument to function
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (423 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0424/1518] wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0426/1518] gpu: host1x: Fix offset calculation in trace_write_gather Greg Kroah-Hartman
` (573 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Avraham Stern, Miri Korenblit,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Avraham Stern <avraham.stern@intel.com>
[ Upstream commit 905f57aefde4f4092a411c8a55856182fb1c7598 ]
The first argument to iwl_mei_write_cyclic_buf() should be the cldev
but the q_head pointer is passed instead. Fix it.
Fixes: 652291601459 ("iwlwifi: mei: don't rely on the size from the shared area")
Signed-off-by: Avraham Stern <avraham.stern@intel.com>
Signed-off-by: Miri Korenblit <miriam.rachel.korenblit@intel.com>
Link: https://patch.msgid.link/20260715220243.24cea60c6428.I42301010c31487b1458faa967b22c8320b0cfd23@changeid
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/intel/iwlwifi/mei/main.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/intel/iwlwifi/mei/main.c b/drivers/net/wireless/intel/iwlwifi/mei/main.c
index c083af5240593..1486702d37e75 100644
--- a/drivers/net/wireless/intel/iwlwifi/mei/main.c
+++ b/drivers/net/wireless/intel/iwlwifi/mei/main.c
@@ -458,7 +458,7 @@ static int iwl_mei_send_sap_msg_payload(struct mei_cl_device *cldev,
notif_q = &dir->q_ctrl_blk[SAP_QUEUE_IDX_NOTIF];
q_head = mei->shared_mem.q_head[SAP_DIRECTION_HOST_TO_ME][SAP_QUEUE_IDX_NOTIF];
q_sz = mei->shared_mem.q_size[SAP_DIRECTION_HOST_TO_ME][SAP_QUEUE_IDX_NOTIF];
- ret = iwl_mei_write_cyclic_buf(q_head, notif_q, q_head, hdr, q_sz);
+ ret = iwl_mei_write_cyclic_buf(cldev, notif_q, q_head, hdr, q_sz);
if (ret < 0)
return ret;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0426/1518] gpu: host1x: Fix offset calculation in trace_write_gather
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (424 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0425/1518] wifi: iwlwifi: mei: pass correct argument to function Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0427/1518] gpu: host1x: Avoid stack over-read in debug output helpers Greg Kroah-Hartman
` (572 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mikko Perttunen, Thierry Reding,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mikko Perttunen <mperttunen@nvidia.com>
[ Upstream commit eb896850964d3dfce291b4fdff9c2d42d85e564b ]
When a gather longer than 2*TRACE_MAX_LENGTH (256) words is traced
through host1x_cdma_push_gather, the reported BO offset drifts from
the third iteration onward.
Fix the calculation by properly calculating the value on each loop
rather than accumulating.
In reality, gathers tend to be pretty short so this is unlikely to
ever have been observed.
Fixes: b40d02bf96e0 ("gpu: host1x: Use struct host1x_bo pointers in traces")
Signed-off-by: Mikko Perttunen <mperttunen@nvidia.com>
Signed-off-by: Thierry Reding <treding@nvidia.com>
Link: https://patch.msgid.link/20260609-b4-host1x-small-fixes-a-v1-3-7c1131c0b3ad@nvidia.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/host1x/hw/channel_hw.c | 5 ++---
1 file changed, 2 insertions(+), 3 deletions(-)
diff --git a/drivers/gpu/host1x/hw/channel_hw.c b/drivers/gpu/host1x/hw/channel_hw.c
index d44b8de890be0..46b6494768b4d 100644
--- a/drivers/gpu/host1x/hw/channel_hw.c
+++ b/drivers/gpu/host1x/hw/channel_hw.c
@@ -36,10 +36,9 @@ static void trace_write_gather(struct host1x_cdma *cdma, struct host1x_bo *bo,
for (i = 0; i < words; i += TRACE_MAX_LENGTH) {
u32 num_words = min(words - i, TRACE_MAX_LENGTH);
- offset += i * sizeof(u32);
-
trace_host1x_cdma_push_gather(dev_name(dev), bo,
- num_words, offset,
+ num_words,
+ offset + i * sizeof(u32),
mem);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0427/1518] gpu: host1x: Avoid stack over-read in debug output helpers
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (425 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0426/1518] gpu: host1x: Fix offset calculation in trace_write_gather Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0428/1518] drm/msm/a6xx: Fix stale rpmh votes after suspend Greg Kroah-Hartman
` (571 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mikko Perttunen, Thierry Reding,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mikko Perttunen <mperttunen@nvidia.com>
[ Upstream commit bc17ac285fb708f22a8fa2c0ed32eceb1d37e6d6 ]
host1x_debug_output() and host1x_debug_cont() used vsnprintf(), which
returns the length the formatted string would have reached with an
unbounded buffer. That return value was passed straight to o->fn as
the number of bytes to emit.
This could cause a read past end of the output buffer if a call to
host1x_debug_* produced a string longer than 256 bytes. This only
affected the debugfs files as the printk debug sink ignores the
number of bytes. In practice, this is very unlikely to occur.
Fix by switching to vscnprintf(), which returns the number of bytes
actually written.
Fixes: 6236451d83a7 ("gpu: host1x: Add debug support")
Signed-off-by: Mikko Perttunen <mperttunen@nvidia.com>
Signed-off-by: Thierry Reding <treding@nvidia.com>
Link: https://patch.msgid.link/20260609-b4-host1x-small-fixes-a-v1-4-7c1131c0b3ad@nvidia.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/host1x/debug.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/gpu/host1x/debug.c b/drivers/gpu/host1x/debug.c
index 6433c00d5d7e0..b828f773fc065 100644
--- a/drivers/gpu/host1x/debug.c
+++ b/drivers/gpu/host1x/debug.c
@@ -31,7 +31,7 @@ void host1x_debug_output(struct output *o, const char *fmt, ...)
int len;
va_start(args, fmt);
- len = vsnprintf(o->buf, sizeof(o->buf), fmt, args);
+ len = vscnprintf(o->buf, sizeof(o->buf), fmt, args);
va_end(args);
o->fn(o->ctx, o->buf, len, false);
@@ -43,7 +43,7 @@ void host1x_debug_cont(struct output *o, const char *fmt, ...)
int len;
va_start(args, fmt);
- len = vsnprintf(o->buf, sizeof(o->buf), fmt, args);
+ len = vscnprintf(o->buf, sizeof(o->buf), fmt, args);
va_end(args);
o->fn(o->ctx, o->buf, len, true);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0428/1518] drm/msm/a6xx: Fix stale rpmh votes after suspend
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (426 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0427/1518] gpu: host1x: Avoid stack over-read in debug output helpers Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0429/1518] drm/msm: Recover HW before retire hung submit Greg Kroah-Hartman
` (570 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shivam Rawat, Akhil P Oommen,
Dmitry Baryshkov, Konrad Dybcio, Rob Clark, Sasha Levin,
Neil Armstrong
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shivam Rawat <shivrawa@qti.qualcomm.com>
[ Upstream commit d9108bfdb746edacdb05bd27959a4ae63c6c7f3f ]
There are stale RPMH votes (BCM votes) observed after GMU suspend. This
is because the rpmh stop sequences are skipped during gmu suspend. Fix
this and also move GMU to reset state to avoid any further activity.
Fixes: f248d5d5159a ("drm/msm/a6xx: Fix PDC sleep sequence")
Signed-off-by: Shivam Rawat <shivrawa@qti.qualcomm.com>
Signed-off-by: Akhil P Oommen <akhilpo@oss.qualcomm.com>
Tested-by: Neil Armstrong <neil.armstrong@linaro.org> # on SM8650-HDK
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/730652/
Message-ID: <20260605-assorted-fixes-june-v1-1-2caa04f7287c@oss.qualcomm.com>
Signed-off-by: Rob Clark <robin.clark@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/adreno/a6xx_gmu.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/msm/adreno/a6xx_gmu.c b/drivers/gpu/drm/msm/adreno/a6xx_gmu.c
index 21a3f9b0ab4c2..d06d874e19773 100644
--- a/drivers/gpu/drm/msm/adreno/a6xx_gmu.c
+++ b/drivers/gpu/drm/msm/adreno/a6xx_gmu.c
@@ -564,7 +564,7 @@ static void a6xx_rpmh_stop(struct a6xx_gmu *gmu)
int ret;
u32 val;
- if (test_and_clear_bit(GMU_STATUS_FW_START, &gmu->status))
+ if (!test_and_clear_bit(GMU_STATUS_FW_START, &gmu->status))
return;
gmu_write(gmu, REG_A6XX_GMU_RSCC_CONTROL_REQ, 1);
@@ -1256,6 +1256,9 @@ static void a6xx_gmu_shutdown(struct a6xx_gmu *gmu)
/* Stop the interrupts and mask the hardware */
a6xx_gmu_irq_disable(gmu);
+ /* Halt the gmu cm3 core */
+ gmu_write(gmu, REG_A6XX_GMU_CM3_SYSRESET, 1);
+
/* Tell RPMh to power off the GPU */
a6xx_rpmh_stop(gmu);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0429/1518] drm/msm: Recover HW before retire hung submit
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (427 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0428/1518] drm/msm/a6xx: Fix stale rpmh votes after suspend Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0430/1518] drm/msm/a6xx: Fix A663 GPUCC register list for state capture Greg Kroah-Hartman
` (569 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jie Zhang, Akhil P Oommen,
Konrad Dybcio, Rob Clark, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jie Zhang <jie.zhang@oss.qualcomm.com>
[ Upstream commit b303e1d52811de7d1bcf793560754d4df68d4a1c ]
During recovery, it is not safe to retire the hung submit before we
recover the GPU. Retiring the submit triggers BO free and that can
result in GPU pagefaults since the GPU may be actively accessing those
BOs.
To fix this, retire the submits after gpu recovery is complete in
recover_worker().
Fixes: 1a370be9ac51 ("drm/msm: restart queued submits after hang")
Signed-off-by: Jie Zhang <jie.zhang@oss.qualcomm.com>
Signed-off-by: Akhil P Oommen <akhilpo@oss.qualcomm.com>
Acked-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/730655/
Message-ID: <20260605-assorted-fixes-june-v1-2-2caa04f7287c@oss.qualcomm.com>
Signed-off-by: Rob Clark <robin.clark@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/msm_gpu.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/gpu/drm/msm/msm_gpu.c b/drivers/gpu/drm/msm/msm_gpu.c
index a4377ee84c723..c78f5738bfdeb 100644
--- a/drivers/gpu/drm/msm/msm_gpu.c
+++ b/drivers/gpu/drm/msm/msm_gpu.c
@@ -548,11 +548,11 @@ static void recover_worker(struct kthread_work *work)
msm_update_fence(ring->fctx, fence);
}
+ gpu->funcs->recover(gpu);
+
/* retire completed submits, plus the one that hung: */
retire_submits(gpu);
- gpu->funcs->recover(gpu);
-
/*
* Replay all remaining submits starting with highest priority
* ring
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0430/1518] drm/msm/a6xx: Fix A663 GPUCC register list for state capture
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (428 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0429/1518] drm/msm: Recover HW before retire hung submit Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0431/1518] drm/msm/a6xx: Rebase GMU register offsets Greg Kroah-Hartman
` (568 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jie Zhang, Akhil P Oommen,
Dmitry Baryshkov, Rob Clark, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jie Zhang <jie.zhang@oss.qualcomm.com>
[ Upstream commit fc7ccbc6174b79ffab5be5dca5b6e253df22f030 ]
The GPUCC register list for A663 is incorrect, which can cause
out-of-bounds register access during GPU state capture.
Update it to use the correct register ranges.
Fixes: 5773cce8615c ("drm/msm/a6xx: Add support for A663")
Signed-off-by: Jie Zhang <jie.zhang@oss.qualcomm.com>
Signed-off-by: Akhil P Oommen <akhilpo@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/730656/
Message-ID: <20260605-assorted-fixes-june-v1-3-2caa04f7287c@oss.qualcomm.com>
Signed-off-by: Rob Clark <robin.clark@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/adreno/a6xx_gpu_state.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/msm/adreno/a6xx_gpu_state.c b/drivers/gpu/drm/msm/adreno/a6xx_gpu_state.c
index 918d2e504adec..8a412b7d3129f 100644
--- a/drivers/gpu/drm/msm/adreno/a6xx_gpu_state.c
+++ b/drivers/gpu/drm/msm/adreno/a6xx_gpu_state.c
@@ -1244,7 +1244,9 @@ static void a6xx_get_gmu_registers(struct msm_gpu *gpu,
_a6xx_get_gmu_registers(gpu, a6xx_state, &a6xx_gmu_reglist[1],
&a6xx_state->gmu_registers[1], true);
- if (adreno_is_a621(adreno_gpu) || adreno_is_a623(adreno_gpu))
+ if (adreno_is_a621(adreno_gpu) ||
+ adreno_is_a623(adreno_gpu) ||
+ adreno_is_a663(adreno_gpu))
_a6xx_get_gmu_registers(gpu, a6xx_state, &a621_gpucc_reg,
&a6xx_state->gmu_registers[2], false);
else
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0431/1518] drm/msm/a6xx: Rebase GMU register offsets
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (429 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0430/1518] drm/msm/a6xx: Fix A663 GPUCC register list for state capture Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0432/1518] drm/msm/a6xx: Fix A621 GPUCC register list for state capture Greg Kroah-Hartman
` (567 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Akhil P Oommen, Rob Clark,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Akhil P Oommen <akhilpo@oss.qualcomm.com>
[ Upstream commit 188db3d7fe66ca0f865a4f5608d00b961cc8b2d9 ]
GMU registers are always at a fixed offset from the GPU base address,
a consistency maintained at least within a given architecture generation.
In A8x family, the base address of the GMU has changed, but the offsets
of the gmu registers remain largely the same. To enable reuse of the gmu
code for A8x chipsets, update the gmu register offsets to be relative
to the GPU's base address instead of GMU's.
Signed-off-by: Akhil P Oommen <akhilpo@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/689010/
Message-ID: <20251118-kaana-gpu-support-v4-10-86eeb8e93fb6@oss.qualcomm.com>
Signed-off-by: Rob Clark <robin.clark@oss.qualcomm.com>
Stable-dep-of: d052d0358fb8 ("drm/msm/a6xx: Fix A621 GPUCC register list for state capture")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/adreno/a6xx_gmu.c | 100 ++++---
drivers/gpu/drm/msm/adreno/a6xx_gmu.h | 20 +-
drivers/gpu/drm/msm/adreno/a6xx_gpu_state.h | 56 ++--
.../gpu/drm/msm/registers/adreno/a6xx_gmu.xml | 248 +++++++++---------
4 files changed, 221 insertions(+), 203 deletions(-)
diff --git a/drivers/gpu/drm/msm/adreno/a6xx_gmu.c b/drivers/gpu/drm/msm/adreno/a6xx_gmu.c
index d06d874e19773..3f17cfaca8b47 100644
--- a/drivers/gpu/drm/msm/adreno/a6xx_gmu.c
+++ b/drivers/gpu/drm/msm/adreno/a6xx_gmu.c
@@ -584,22 +584,19 @@ static inline void pdc_write(void __iomem *ptr, u32 offset, u32 value)
writel(value, ptr + (offset << 2));
}
-static void __iomem *a6xx_gmu_get_mmio(struct platform_device *pdev,
- const char *name);
-
static void a6xx_gmu_rpmh_init(struct a6xx_gmu *gmu)
{
struct a6xx_gpu *a6xx_gpu = container_of(gmu, struct a6xx_gpu, gmu);
struct adreno_gpu *adreno_gpu = &a6xx_gpu->base;
struct platform_device *pdev = to_platform_device(gmu->dev);
- void __iomem *pdcptr = a6xx_gmu_get_mmio(pdev, "gmu_pdc");
+ void __iomem *pdcptr = devm_platform_ioremap_resource_byname(pdev, "gmu_pdc");
u32 seqmem0_drv0_reg = REG_A6XX_RSCC_SEQ_MEM_0_DRV0;
void __iomem *seqptr = NULL;
uint32_t pdc_address_offset;
bool pdc_in_aop = false;
if (IS_ERR(pdcptr))
- goto err;
+ return;
if (adreno_is_a650_family(adreno_gpu) ||
adreno_is_a7xx(adreno_gpu))
@@ -612,9 +609,9 @@ static void a6xx_gmu_rpmh_init(struct a6xx_gmu *gmu)
pdc_address_offset = 0x30080;
if (!pdc_in_aop) {
- seqptr = a6xx_gmu_get_mmio(pdev, "gmu_pdc_seq");
+ seqptr = devm_platform_ioremap_resource_byname(pdev, "gmu_pdc_seq");
if (IS_ERR(seqptr))
- goto err;
+ return;
}
/* Disable SDE clock gating */
@@ -704,12 +701,6 @@ static void a6xx_gmu_rpmh_init(struct a6xx_gmu *gmu)
/* ensure no writes happen before the uCode is fully written */
wmb();
-
-err:
- if (!IS_ERR_OR_NULL(pdcptr))
- iounmap(pdcptr);
- if (!IS_ERR_OR_NULL(seqptr))
- iounmap(seqptr);
}
/*
@@ -1802,27 +1793,6 @@ static int a6xx_gmu_clocks_probe(struct a6xx_gmu *gmu)
return 0;
}
-static void __iomem *a6xx_gmu_get_mmio(struct platform_device *pdev,
- const char *name)
-{
- void __iomem *ret;
- struct resource *res = platform_get_resource_byname(pdev,
- IORESOURCE_MEM, name);
-
- if (!res) {
- DRM_DEV_ERROR(&pdev->dev, "Unable to find the %s registers\n", name);
- return ERR_PTR(-EINVAL);
- }
-
- ret = ioremap(res->start, resource_size(res));
- if (!ret) {
- DRM_DEV_ERROR(&pdev->dev, "Unable to map the %s registers\n", name);
- return ERR_PTR(-EINVAL);
- }
-
- return ret;
-}
-
static int a6xx_gmu_get_irq(struct a6xx_gmu *gmu, struct platform_device *pdev,
const char *name, irq_handler_t handler)
{
@@ -1873,7 +1843,6 @@ void a6xx_gmu_remove(struct a6xx_gpu *a6xx_gpu)
{
struct adreno_gpu *adreno_gpu = &a6xx_gpu->base;
struct a6xx_gmu *gmu = &a6xx_gpu->gmu;
- struct platform_device *pdev = to_platform_device(gmu->dev);
mutex_lock(&gmu->lock);
if (!gmu->initialized) {
@@ -1902,8 +1871,6 @@ void a6xx_gmu_remove(struct a6xx_gpu *a6xx_gpu)
qmp_put(gmu->qmp);
iounmap(gmu->mmio);
- if (platform_get_resource_byname(pdev, IORESOURCE_MEM, "rscc"))
- iounmap(gmu->rscc);
gmu->mmio = NULL;
gmu->rscc = NULL;
@@ -1929,10 +1896,38 @@ static int cxpd_notifier_cb(struct notifier_block *nb,
return 0;
}
+static void __iomem *a6xx_gmu_get_mmio(struct platform_device *pdev,
+ const char *name, resource_size_t *start)
+{
+ void __iomem *ret;
+ struct resource *res = platform_get_resource_byname(pdev,
+ IORESOURCE_MEM, name);
+
+ if (!res) {
+ DRM_DEV_ERROR(&pdev->dev, "Unable to find the %s registers\n", name);
+ return ERR_PTR(-EINVAL);
+ }
+
+ ret = ioremap(res->start, resource_size(res));
+ if (!ret) {
+ DRM_DEV_ERROR(&pdev->dev, "Unable to map the %s registers\n", name);
+ return ERR_PTR(-EINVAL);
+ }
+
+ if (start)
+ *start = res->start;
+
+ return ret;
+}
+
int a6xx_gmu_wrapper_init(struct a6xx_gpu *a6xx_gpu, struct device_node *node)
{
struct platform_device *pdev = of_find_device_by_node(node);
+ struct adreno_gpu *adreno_gpu = &a6xx_gpu->base;
+ struct msm_gpu *gpu = &adreno_gpu->base;
struct a6xx_gmu *gmu = &a6xx_gpu->gmu;
+ resource_size_t start;
+ struct resource *res;
int ret;
if (!pdev)
@@ -1950,12 +1945,21 @@ int a6xx_gmu_wrapper_init(struct a6xx_gpu *a6xx_gpu, struct device_node *node)
gmu->legacy = true;
/* Map the GMU registers */
- gmu->mmio = a6xx_gmu_get_mmio(pdev, "gmu");
+ gmu->mmio = a6xx_gmu_get_mmio(pdev, "gmu", &start);
if (IS_ERR(gmu->mmio)) {
ret = PTR_ERR(gmu->mmio);
goto err_mmio;
}
+ res = platform_get_resource_byname(gpu->pdev, IORESOURCE_MEM, "kgsl_3d0_reg_memory");
+ if (!res) {
+ ret = -EINVAL;
+ goto err_mmio;
+ }
+
+ /* Identify gmu base offset from gpu base address */
+ gmu->mmio_offset = (u32)(start - res->start);
+
gmu->cxpd = dev_pm_domain_attach_by_name(gmu->dev, "cx");
if (IS_ERR(gmu->cxpd)) {
ret = PTR_ERR(gmu->cxpd);
@@ -1996,10 +2000,13 @@ int a6xx_gmu_wrapper_init(struct a6xx_gpu *a6xx_gpu, struct device_node *node)
int a6xx_gmu_init(struct a6xx_gpu *a6xx_gpu, struct device_node *node)
{
+ struct platform_device *pdev = of_find_device_by_node(node);
struct adreno_gpu *adreno_gpu = &a6xx_gpu->base;
+ struct msm_gpu *gpu = &adreno_gpu->base;
struct a6xx_gmu *gmu = &a6xx_gpu->gmu;
- struct platform_device *pdev = of_find_device_by_node(node);
struct device_link *link;
+ resource_size_t start;
+ struct resource *res;
int ret;
if (!pdev)
@@ -2094,15 +2101,24 @@ int a6xx_gmu_init(struct a6xx_gpu *a6xx_gpu, struct device_node *node)
goto err_memory;
/* Map the GMU registers */
- gmu->mmio = a6xx_gmu_get_mmio(pdev, "gmu");
+ gmu->mmio = a6xx_gmu_get_mmio(pdev, "gmu", &start);
if (IS_ERR(gmu->mmio)) {
ret = PTR_ERR(gmu->mmio);
goto err_memory;
}
+ res = platform_get_resource_byname(gpu->pdev, IORESOURCE_MEM, "kgsl_3d0_reg_memory");
+ if (!res) {
+ ret = -EINVAL;
+ goto err_mmio;
+ }
+
+ /* Identify gmu base offset from gpu base address */
+ gmu->mmio_offset = (u32)(start - res->start);
+
if (adreno_is_a650_family(adreno_gpu) ||
adreno_is_a7xx(adreno_gpu)) {
- gmu->rscc = a6xx_gmu_get_mmio(pdev, "rscc");
+ gmu->rscc = devm_platform_ioremap_resource_byname(pdev, "rscc");
if (IS_ERR(gmu->rscc)) {
ret = -ENODEV;
goto err_mmio;
@@ -2180,8 +2196,6 @@ int a6xx_gmu_init(struct a6xx_gpu *a6xx_gpu, struct device_node *node)
err_mmio:
iounmap(gmu->mmio);
- if (platform_get_resource_byname(pdev, IORESOURCE_MEM, "rscc"))
- iounmap(gmu->rscc);
free_irq(gmu->gmu_irq, gmu);
free_irq(gmu->hfi_irq, gmu);
diff --git a/drivers/gpu/drm/msm/adreno/a6xx_gmu.h b/drivers/gpu/drm/msm/adreno/a6xx_gmu.h
index 06cfc294016f5..55b1c78daa8b5 100644
--- a/drivers/gpu/drm/msm/adreno/a6xx_gmu.h
+++ b/drivers/gpu/drm/msm/adreno/a6xx_gmu.h
@@ -68,6 +68,7 @@ struct a6xx_gmu {
struct drm_gpuvm *vm;
void __iomem *mmio;
+ u32 mmio_offset;
void __iomem *rscc;
int hfi_irq;
@@ -130,20 +131,23 @@ struct a6xx_gmu {
unsigned long status;
};
+#define GMU_BYTE_OFFSET(gmu, offset) (((offset) << 2) - (gmu)->mmio_offset)
+
static inline u32 gmu_read(struct a6xx_gmu *gmu, u32 offset)
{
- return readl(gmu->mmio + (offset << 2));
+ /* The 'offset' is based on GPU's start address. Adjust it */
+ return readl(gmu->mmio + GMU_BYTE_OFFSET(gmu, offset));
}
static inline void gmu_write(struct a6xx_gmu *gmu, u32 offset, u32 value)
{
- writel(value, gmu->mmio + (offset << 2));
+ writel(value, gmu->mmio + GMU_BYTE_OFFSET(gmu, offset));
}
static inline void
gmu_write_bulk(struct a6xx_gmu *gmu, u32 offset, const u32 *data, u32 size)
{
- memcpy_toio(gmu->mmio + (offset << 2), data, size);
+ memcpy_toio(gmu->mmio + GMU_BYTE_OFFSET(gmu, offset), data, size);
wmb();
}
@@ -160,17 +164,17 @@ static inline u64 gmu_read64(struct a6xx_gmu *gmu, u32 lo, u32 hi)
{
u64 val;
- val = (u64) readl(gmu->mmio + (lo << 2));
- val |= ((u64) readl(gmu->mmio + (hi << 2)) << 32);
+ val = gmu_read(gmu, lo);
+ val |= ((u64) gmu_read(gmu, hi) << 32);
return val;
}
#define gmu_poll_timeout(gmu, addr, val, cond, interval, timeout) \
- readl_poll_timeout((gmu)->mmio + ((addr) << 2), val, cond, \
- interval, timeout)
+ readl_poll_timeout((gmu)->mmio + (GMU_BYTE_OFFSET(gmu, addr)), val, \
+ cond, interval, timeout)
#define gmu_poll_timeout_atomic(gmu, addr, val, cond, interval, timeout) \
- readl_poll_timeout_atomic((gmu)->mmio + ((addr) << 2), val, cond, \
+ readl_poll_timeout_atomic((gmu)->mmio + (GMU_BYTE_OFFSET(gmu, addr)), val, cond, \
interval, timeout)
static inline u32 gmu_read_rscc(struct a6xx_gmu *gmu, u32 offset)
diff --git a/drivers/gpu/drm/msm/adreno/a6xx_gpu_state.h b/drivers/gpu/drm/msm/adreno/a6xx_gpu_state.h
index 1c18499b60bb9..4753b71837f33 100644
--- a/drivers/gpu/drm/msm/adreno/a6xx_gpu_state.h
+++ b/drivers/gpu/drm/msm/adreno/a6xx_gpu_state.h
@@ -343,48 +343,48 @@ static const struct a6xx_registers a6xx_gbif_reglist =
static const u32 a6xx_gmu_gx_registers[] = {
/* GMU GX */
- 0x0000, 0x0000, 0x0010, 0x0013, 0x0016, 0x0016, 0x0018, 0x001b,
- 0x001e, 0x001e, 0x0020, 0x0023, 0x0026, 0x0026, 0x0028, 0x002b,
- 0x002e, 0x002e, 0x0030, 0x0033, 0x0036, 0x0036, 0x0038, 0x003b,
- 0x003e, 0x003e, 0x0040, 0x0043, 0x0046, 0x0046, 0x0080, 0x0084,
- 0x0100, 0x012b, 0x0140, 0x0140,
+ 0x1a800, 0x1a800, 0x1a810, 0x1a813, 0x1a816, 0x1a816, 0x1a818, 0x1a81b,
+ 0x1a81e, 0x1a81e, 0x1a820, 0x1a823, 0x1a826, 0x1a826, 0x1a828, 0x1a82b,
+ 0x1a82e, 0x1a82e, 0x1a830, 0x1a833, 0x1a836, 0x1a836, 0x1a838, 0x1a83b,
+ 0x1a83e, 0x1a83e, 0x1a840, 0x1a843, 0x1a846, 0x1a846, 0x1a880, 0x1a884,
+ 0x1a900, 0x1a92b, 0x1a940, 0x1a940,
};
static const u32 a6xx_gmu_cx_registers[] = {
/* GMU CX */
- 0x4c00, 0x4c07, 0x4c10, 0x4c12, 0x4d00, 0x4d00, 0x4d07, 0x4d0a,
- 0x5000, 0x5004, 0x5007, 0x5008, 0x500b, 0x500c, 0x500f, 0x501c,
- 0x5024, 0x502a, 0x502d, 0x5030, 0x5040, 0x5053, 0x5087, 0x5089,
- 0x50a0, 0x50a2, 0x50a4, 0x50af, 0x50c0, 0x50c3, 0x50d0, 0x50d0,
- 0x50e4, 0x50e4, 0x50e8, 0x50ec, 0x5100, 0x5103, 0x5140, 0x5140,
- 0x5142, 0x5144, 0x514c, 0x514d, 0x514f, 0x5151, 0x5154, 0x5154,
- 0x5157, 0x5158, 0x515d, 0x515d, 0x5162, 0x5162, 0x5164, 0x5165,
- 0x5180, 0x5186, 0x5190, 0x519e, 0x51c0, 0x51c0, 0x51c5, 0x51cc,
- 0x51e0, 0x51e2, 0x51f0, 0x51f0, 0x5200, 0x5201,
+ 0x1f400, 0x1f407, 0x1f410, 0x1f412, 0x1f500, 0x1f500, 0x1f507, 0x1f50a,
+ 0x1f800, 0x1f804, 0x1f807, 0x1f808, 0x1f80b, 0x1f80c, 0x1f80f, 0x1f81c,
+ 0x1f824, 0x1f82a, 0x1f82d, 0x1f830, 0x1f840, 0x1f853, 0x1f887, 0x1f889,
+ 0x1f8a0, 0x1f8a2, 0x1f8a4, 0x1f8af, 0x1f8c0, 0x1f8c3, 0x1f8d0, 0x1f8d0,
+ 0x1f8e4, 0x1f8e4, 0x1f8e8, 0x1f8ec, 0x1f900, 0x1f903, 0x1f940, 0x1f940,
+ 0x1f942, 0x1f944, 0x1f94c, 0x1f94d, 0x1f94f, 0x1f951, 0x1f954, 0x1f954,
+ 0x1f957, 0x1f958, 0x1f95d, 0x1f95d, 0x1f962, 0x1f962, 0x1f964, 0x1f965,
+ 0x1f980, 0x1f986, 0x1f990, 0x1f99e, 0x1f9c0, 0x1f9c0, 0x1f9c5, 0x1f9cc,
+ 0x1f9e0, 0x1f9e2, 0x1f9f0, 0x1f9f0, 0x1fa00, 0x1fa01,
/* GMU AO */
- 0x9300, 0x9316, 0x9400, 0x9400,
+ 0x23b00, 0x23b16, 0x23c00, 0x23c00,
};
static const u32 a6xx_gmu_gpucc_registers[] = {
/* GPU CC */
- 0x9800, 0x9812, 0x9840, 0x9852, 0x9c00, 0x9c04, 0x9c07, 0x9c0b,
- 0x9c15, 0x9c1c, 0x9c1e, 0x9c2d, 0x9c3c, 0x9c3d, 0x9c3f, 0x9c40,
- 0x9c42, 0x9c49, 0x9c58, 0x9c5a, 0x9d40, 0x9d5e, 0xa000, 0xa002,
- 0xa400, 0xa402, 0xac00, 0xac02, 0xb000, 0xb002, 0xb400, 0xb402,
- 0xb800, 0xb802,
+ 0x24000, 0x24012, 0x24040, 0x24052, 0x24400, 0x24404, 0x24407, 0x2440b,
+ 0x24415, 0x2441c, 0x2441e, 0x2442d, 0x2443c, 0x2443d, 0x2443f, 0x24440,
+ 0x24442, 0x24449, 0x24458, 0x2445a, 0x24540, 0x2455e, 0x24800, 0x24802,
+ 0x24c00, 0x24c02, 0x25400, 0x25402, 0x25800, 0x25802, 0x25c00, 0x25c02,
+ 0x26000, 0x26002,
/* GPU CC ACD */
- 0xbc00, 0xbc16, 0xbc20, 0xbc27,
+ 0x26400, 0x26416, 0x26420, 0x26427,
};
static const u32 a621_gmu_gpucc_registers[] = {
/* GPU CC */
- 0x9800, 0x980e, 0x9c00, 0x9c0e, 0xb000, 0xb004, 0xb400, 0xb404,
- 0xb800, 0xb804, 0xbc00, 0xbc05, 0xbc14, 0xbc1d, 0xbc2a, 0xbc30,
- 0xbc32, 0xbc32, 0xbc41, 0xbc55, 0xbc66, 0xbc68, 0xbc78, 0xbc7a,
- 0xbc89, 0xbc8a, 0xbc9c, 0xbc9e, 0xbca0, 0xbca3, 0xbcb3, 0xbcb5,
- 0xbcc5, 0xbcc7, 0xbcd6, 0xbcd8, 0xbce8, 0xbce9, 0xbcf9, 0xbcfc,
- 0xbd0b, 0xbd0c, 0xbd1c, 0xbd1e, 0xbd40, 0xbd70, 0xbe00, 0xbe16,
- 0xbe20, 0xbe2d,
+ 0x24000, 0x2400e, 0x24400, 0x2440e, 0x25800, 0x25804, 0x25c00, 0x25c04,
+ 0x26000, 0x26004, 0x26400, 0x26405, 0x26414, 0x2641d, 0x2642a, 0x26430,
+ 0x26432, 0x26432, 0x26441, 0x26455, 0x26466, 0x26468, 0x26478, 0x2647a,
+ 0x26489, 0x2648a, 0x2649c, 0x2649e, 0x264a0, 0x264a3, 0x264b3, 0x264b5,
+ 0x264c5, 0x264c7, 0x264d6, 0x264d8, 0x264e8, 0x264e9, 0x264f9, 0x264fc,
+ 0x2650b, 0x2650c, 0x2651c, 0x2651e, 0x26540, 0x26570, 0x26600, 0x26616,
+ 0x26620, 0x2662d,
};
static const u32 a6xx_gmu_cx_rscc_registers[] = {
diff --git a/drivers/gpu/drm/msm/registers/adreno/a6xx_gmu.xml b/drivers/gpu/drm/msm/registers/adreno/a6xx_gmu.xml
index b15a242d974d6..09b8a0b9c0de7 100644
--- a/drivers/gpu/drm/msm/registers/adreno/a6xx_gmu.xml
+++ b/drivers/gpu/drm/msm/registers/adreno/a6xx_gmu.xml
@@ -40,56 +40,56 @@ xsi:schemaLocation="https://gitlab.freedesktop.org/freedreno/ rules-fd.xsd">
<bitfield name="IRQ_MASK_BIT" pos="0" />
</bitset>
- <reg32 offset="0x80" name="GPU_GMU_GX_SPTPRAC_CLOCK_CONTROL"/>
- <reg32 offset="0x81" name="GMU_GX_SPTPRAC_POWER_CONTROL"/>
- <reg32 offset="0xc00" name="GMU_CM3_ITCM_START"/>
- <reg32 offset="0x1c00" name="GMU_CM3_DTCM_START"/>
- <reg32 offset="0x23f0" name="GMU_NMI_CONTROL_STATUS"/>
- <reg32 offset="0x23f8" name="GMU_BOOT_SLUMBER_OPTION"/>
- <reg32 offset="0x23f9" name="GMU_GX_VOTE_IDX"/>
- <reg32 offset="0x23fa" name="GMU_MX_VOTE_IDX"/>
- <reg32 offset="0x23fc" name="GMU_DCVS_ACK_OPTION"/>
- <reg32 offset="0x23fd" name="GMU_DCVS_PERF_SETTING"/>
- <reg32 offset="0x23fe" name="GMU_DCVS_BW_SETTING"/>
- <reg32 offset="0x23ff" name="GMU_DCVS_RETURN"/>
- <reg32 offset="0x2bf8" name="GMU_CORE_FW_VERSION">
+ <reg32 offset="0x1a880" name="GPU_GMU_GX_SPTPRAC_CLOCK_CONTROL"/>
+ <reg32 offset="0x1a881" name="GMU_GX_SPTPRAC_POWER_CONTROL"/>
+ <reg32 offset="0x1b400" name="GMU_CM3_ITCM_START"/>
+ <reg32 offset="0x1c400" name="GMU_CM3_DTCM_START"/>
+ <reg32 offset="0x1cbf0" name="GMU_NMI_CONTROL_STATUS"/>
+ <reg32 offset="0x1cbf8" name="GMU_BOOT_SLUMBER_OPTION"/>
+ <reg32 offset="0x1cbf9" name="GMU_GX_VOTE_IDX"/>
+ <reg32 offset="0x1cbfa" name="GMU_MX_VOTE_IDX"/>
+ <reg32 offset="0x1cbfc" name="GMU_DCVS_ACK_OPTION"/>
+ <reg32 offset="0x1cbfd" name="GMU_DCVS_PERF_SETTING"/>
+ <reg32 offset="0x1cbfe" name="GMU_DCVS_BW_SETTING"/>
+ <reg32 offset="0x1cbff" name="GMU_DCVS_RETURN"/>
+ <reg32 offset="0x1d3f8" name="GMU_CORE_FW_VERSION">
<bitfield name="MAJOR" low="28" high="31"/>
<bitfield name="MINOR" low="16" high="27"/>
<bitfield name="STEP" low="0" high="15"/>
</reg32>
- <reg32 offset="0x4c00" name="GMU_ICACHE_CONFIG"/>
- <reg32 offset="0x4c01" name="GMU_DCACHE_CONFIG"/>
- <reg32 offset="0x4c0f" name="GMU_SYS_BUS_CONFIG"/>
- <reg32 offset="0x5000" name="GMU_CM3_SYSRESET"/>
- <reg32 offset="0x5001" name="GMU_CM3_BOOT_CONFIG"/>
- <reg32 offset="0x501a" name="GMU_CM3_FW_BUSY"/>
- <reg32 offset="0x501c" name="GMU_CM3_FW_INIT_RESULT"/>
- <reg32 offset="0x502d" name="GMU_CM3_CFG"/>
- <reg32 offset="0x5040" name="GMU_CX_GMU_POWER_COUNTER_ENABLE"/>
- <reg32 offset="0x5041" name="GMU_CX_GMU_POWER_COUNTER_SELECT_0"/>
- <reg32 offset="0x5042" name="GMU_CX_GMU_POWER_COUNTER_SELECT_1"/>
- <reg32 offset="0x5044" name="GMU_CX_GMU_POWER_COUNTER_XOCLK_0_L"/>
- <reg32 offset="0x5045" name="GMU_CX_GMU_POWER_COUNTER_XOCLK_0_H"/>
- <reg32 offset="0x5046" name="GMU_CX_GMU_POWER_COUNTER_XOCLK_1_L"/>
- <reg32 offset="0x5047" name="GMU_CX_GMU_POWER_COUNTER_XOCLK_1_H"/>
- <reg32 offset="0x5048" name="GMU_CX_GMU_POWER_COUNTER_XOCLK_2_L"/>
- <reg32 offset="0x5049" name="GMU_CX_GMU_POWER_COUNTER_XOCLK_2_H"/>
- <reg32 offset="0x504a" name="GMU_CX_GMU_POWER_COUNTER_XOCLK_3_L"/>
- <reg32 offset="0x504b" name="GMU_CX_GMU_POWER_COUNTER_XOCLK_3_H"/>
- <reg32 offset="0x504c" name="GMU_CX_GMU_POWER_COUNTER_XOCLK_4_L"/>
- <reg32 offset="0x504d" name="GMU_CX_GMU_POWER_COUNTER_XOCLK_4_H"/>
- <reg32 offset="0x504e" name="GMU_CX_GMU_POWER_COUNTER_XOCLK_5_L"/>
- <reg32 offset="0x504f" name="GMU_CX_GMU_POWER_COUNTER_XOCLK_5_H"/>
- <reg32 offset="0x50c0" name="GMU_PWR_COL_INTER_FRAME_CTRL">
+ <reg32 offset="0x1f400" name="GMU_ICACHE_CONFIG"/>
+ <reg32 offset="0x1f401" name="GMU_DCACHE_CONFIG"/>
+ <reg32 offset="0x1f40f" name="GMU_SYS_BUS_CONFIG"/>
+ <reg32 offset="0x1f800" name="GMU_CM3_SYSRESET"/>
+ <reg32 offset="0x1f801" name="GMU_CM3_BOOT_CONFIG"/>
+ <reg32 offset="0x1f81a" name="GMU_CM3_FW_BUSY"/>
+ <reg32 offset="0x1f81c" name="GMU_CM3_FW_INIT_RESULT"/>
+ <reg32 offset="0x1f82d" name="GMU_CM3_CFG"/>
+ <reg32 offset="0x1f840" name="GMU_CX_GMU_POWER_COUNTER_ENABLE"/>
+ <reg32 offset="0x1f841" name="GMU_CX_GMU_POWER_COUNTER_SELECT_0"/>
+ <reg32 offset="0x1f842" name="GMU_CX_GMU_POWER_COUNTER_SELECT_1"/>
+ <reg32 offset="0x1f844" name="GMU_CX_GMU_POWER_COUNTER_XOCLK_0_L"/>
+ <reg32 offset="0x1f845" name="GMU_CX_GMU_POWER_COUNTER_XOCLK_0_H"/>
+ <reg32 offset="0x1f846" name="GMU_CX_GMU_POWER_COUNTER_XOCLK_1_L"/>
+ <reg32 offset="0x1f847" name="GMU_CX_GMU_POWER_COUNTER_XOCLK_1_H"/>
+ <reg32 offset="0x1f848" name="GMU_CX_GMU_POWER_COUNTER_XOCLK_2_L"/>
+ <reg32 offset="0x1f849" name="GMU_CX_GMU_POWER_COUNTER_XOCLK_2_H"/>
+ <reg32 offset="0x1f84a" name="GMU_CX_GMU_POWER_COUNTER_XOCLK_3_L"/>
+ <reg32 offset="0x1f84b" name="GMU_CX_GMU_POWER_COUNTER_XOCLK_3_H"/>
+ <reg32 offset="0x1f84c" name="GMU_CX_GMU_POWER_COUNTER_XOCLK_4_L"/>
+ <reg32 offset="0x1f84d" name="GMU_CX_GMU_POWER_COUNTER_XOCLK_4_H"/>
+ <reg32 offset="0x1f84e" name="GMU_CX_GMU_POWER_COUNTER_XOCLK_5_L"/>
+ <reg32 offset="0x1f84f" name="GMU_CX_GMU_POWER_COUNTER_XOCLK_5_H"/>
+ <reg32 offset="0x1f8c0" name="GMU_PWR_COL_INTER_FRAME_CTRL">
<bitfield name="IFPC_ENABLE" pos="0" type="boolean"/>
<bitfield name="HM_POWER_COLLAPSE_ENABLE" pos="1" type="boolean"/>
<bitfield name="SPTPRAC_POWER_CONTROL_ENABLE" pos="2" type="boolean"/>
<bitfield name="NUM_PASS_SKIPS" low="10" high="13"/>
<bitfield name="MIN_PASS_LENGTH" low="14" high="31"/>
</reg32>
- <reg32 offset="0x50c1" name="GMU_PWR_COL_INTER_FRAME_HYST"/>
- <reg32 offset="0x50c2" name="GMU_PWR_COL_SPTPRAC_HYST"/>
- <reg32 offset="0x50d0" name="GMU_SPTPRAC_PWR_CLK_STATUS">
+ <reg32 offset="0x1f8c1" name="GMU_PWR_COL_INTER_FRAME_HYST"/>
+ <reg32 offset="0x1f8c2" name="GMU_PWR_COL_SPTPRAC_HYST"/>
+ <reg32 offset="0x1f8d0" name="GMU_SPTPRAC_PWR_CLK_STATUS">
<bitfield name="SPTPRAC_GDSC_POWERING_OFF" pos="0" type="boolean"/>
<bitfield name="SPTPRAC_GDSC_POWERING_ON" pos="1" type="boolean"/>
<bitfield name="SPTPRAC_GDSC_POWER_OFF" pos="2" type="boolean"/>
@@ -99,15 +99,15 @@ xsi:schemaLocation="https://gitlab.freedesktop.org/freedreno/ rules-fd.xsd">
<bitfield name="GX_HM_GDSC_POWER_OFF" pos="6" type="boolean"/>
<bitfield name="GX_HM_CLK_OFF" pos="7" type="boolean"/>
</reg32>
- <reg32 offset="0x50d0" name="GMU_SPTPRAC_PWR_CLK_STATUS" variants="A7XX">
+ <reg32 offset="0x1f8d0" name="GMU_SPTPRAC_PWR_CLK_STATUS" variants="A7XX-">
<bitfield name="GX_HM_GDSC_POWER_OFF" pos="0" type="boolean"/>
<bitfield name="GX_HM_CLK_OFF" pos="1" type="boolean"/>
</reg32>
- <reg32 offset="0x50e4" name="GMU_GPU_NAP_CTRL">
+ <reg32 offset="0x1f8e4" name="GMU_GPU_NAP_CTRL">
<bitfield name="HW_NAP_ENABLE" pos="0"/>
<bitfield name="SID" low="4" high="8"/>
</reg32>
- <reg32 offset="0x50e8" name="GMU_RPMH_CTRL">
+ <reg32 offset="0x1f8e8" name="GMU_RPMH_CTRL">
<bitfield name="RPMH_INTERFACE_ENABLE" pos="0" type="boolean"/>
<bitfield name="LLC_VOTE_ENABLE" pos="4" type="boolean"/>
<bitfield name="DDR_VOTE_ENABLE" pos="8" type="boolean"/>
@@ -119,71 +119,71 @@ xsi:schemaLocation="https://gitlab.freedesktop.org/freedreno/ rules-fd.xsd">
<bitfield name="CX_MIN_VOTE_ENABLE" pos="14" type="boolean"/>
<bitfield name="GFX_MIN_VOTE_ENABLE" pos="15" type="boolean"/>
</reg32>
- <reg32 offset="0x50e9" name="GMU_RPMH_HYST_CTRL"/>
- <reg32 offset="0x50ec" name="GPU_GMU_CX_GMU_RPMH_POWER_STATE"/>
- <reg32 offset="0x50f0" name="GPU_GMU_CX_GMU_CX_FAL_INTF"/>
- <reg32 offset="0x50f1" name="GPU_GMU_CX_GMU_CX_FALNEXT_INTF"/>
- <reg32 offset="0x5100" name="GPU_GMU_CX_GMU_PWR_COL_CP_MSG"/>
- <reg32 offset="0x5101" name="GPU_GMU_CX_GMU_PWR_COL_CP_RESP"/>
- <reg32 offset="0x51f0" name="GMU_BOOT_KMD_LM_HANDSHAKE"/>
- <reg32 offset="0x5157" name="GMU_LLM_GLM_SLEEP_CTRL"/>
- <reg32 offset="0x5158" name="GMU_LLM_GLM_SLEEP_STATUS"/>
- <reg32 offset="0x5088" name="GMU_ALWAYS_ON_COUNTER_L"/>
- <reg32 offset="0x5089" name="GMU_ALWAYS_ON_COUNTER_H"/>
- <reg32 offset="0x50c3" name="GMU_GMU_PWR_COL_KEEPALIVE"/>
- <reg32 offset="0x50c4" name="GMU_PWR_COL_PREEMPT_KEEPALIVE"/>
- <reg32 offset="0x5180" name="GMU_HFI_CTRL_STATUS"/>
- <reg32 offset="0x5181" name="GMU_HFI_VERSION_INFO"/>
- <reg32 offset="0x5182" name="GMU_HFI_SFR_ADDR"/>
- <reg32 offset="0x5183" name="GMU_HFI_MMAP_ADDR"/>
- <reg32 offset="0x5184" name="GMU_HFI_QTBL_INFO"/>
- <reg32 offset="0x5185" name="GMU_HFI_QTBL_ADDR"/>
- <reg32 offset="0x5186" name="GMU_HFI_CTRL_INIT"/>
- <reg32 offset="0x5190" name="GMU_GMU2HOST_INTR_SET"/>
- <reg32 offset="0x5191" name="GMU_GMU2HOST_INTR_CLR"/>
- <reg32 offset="0x5192" name="GMU_GMU2HOST_INTR_INFO">
+ <reg32 offset="0x1f8e9" name="GMU_RPMH_HYST_CTRL"/>
+ <reg32 offset="0x1f8ec" name="GPU_GMU_CX_GMU_RPMH_POWER_STATE"/>
+ <reg32 offset="0x1f8f0" name="GPU_GMU_CX_GMU_CX_FAL_INTF"/>
+ <reg32 offset="0x1f8f1" name="GPU_GMU_CX_GMU_CX_FALNEXT_INTF"/>
+ <reg32 offset="0x1f900" name="GPU_GMU_CX_GMU_PWR_COL_CP_MSG"/>
+ <reg32 offset="0x1f901" name="GPU_GMU_CX_GMU_PWR_COL_CP_RESP"/>
+ <reg32 offset="0x1f9f0" name="GMU_BOOT_KMD_LM_HANDSHAKE"/>
+ <reg32 offset="0x1f957" name="GMU_LLM_GLM_SLEEP_CTRL"/>
+ <reg32 offset="0x1f958" name="GMU_LLM_GLM_SLEEP_STATUS"/>
+ <reg32 offset="0x1f888" name="GMU_ALWAYS_ON_COUNTER_L"/>
+ <reg32 offset="0x1f889" name="GMU_ALWAYS_ON_COUNTER_H"/>
+ <reg32 offset="0x1f8c3" name="GMU_GMU_PWR_COL_KEEPALIVE"/>
+ <reg32 offset="0x1f8c4" name="GMU_PWR_COL_PREEMPT_KEEPALIVE"/>
+ <reg32 offset="0x1f980" name="GMU_HFI_CTRL_STATUS"/>
+ <reg32 offset="0x1f981" name="GMU_HFI_VERSION_INFO"/>
+ <reg32 offset="0x1f982" name="GMU_HFI_SFR_ADDR"/>
+ <reg32 offset="0x1f983" name="GMU_HFI_MMAP_ADDR"/>
+ <reg32 offset="0x1f984" name="GMU_HFI_QTBL_INFO"/>
+ <reg32 offset="0x1f985" name="GMU_HFI_QTBL_ADDR"/>
+ <reg32 offset="0x1f986" name="GMU_HFI_CTRL_INIT"/>
+ <reg32 offset="0x1f990" name="GMU_GMU2HOST_INTR_SET"/>
+ <reg32 offset="0x1f991" name="GMU_GMU2HOST_INTR_CLR"/>
+ <reg32 offset="0x1f992" name="GMU_GMU2HOST_INTR_INFO">
<bitfield name="MSGQ" pos="0" type="boolean"/>
<bitfield name="CM3_FAULT" pos="23" type="boolean"/>
</reg32>
- <reg32 offset="0x5193" name="GMU_GMU2HOST_INTR_MASK"/>
- <reg32 offset="0x5194" name="GMU_HOST2GMU_INTR_SET"/>
- <reg32 offset="0x5195" name="GMU_HOST2GMU_INTR_CLR"/>
- <reg32 offset="0x5196" name="GMU_HOST2GMU_INTR_RAW_INFO"/>
- <reg32 offset="0x5197" name="GMU_HOST2GMU_INTR_EN_0"/>
- <reg32 offset="0x5198" name="GMU_HOST2GMU_INTR_EN_1"/>
- <reg32 offset="0x5199" name="GMU_HOST2GMU_INTR_EN_2"/>
- <reg32 offset="0x519a" name="GMU_HOST2GMU_INTR_EN_3"/>
- <reg32 offset="0x519b" name="GMU_HOST2GMU_INTR_INFO_0"/>
- <reg32 offset="0x519c" name="GMU_HOST2GMU_INTR_INFO_1"/>
- <reg32 offset="0x519d" name="GMU_HOST2GMU_INTR_INFO_2"/>
- <reg32 offset="0x519e" name="GMU_HOST2GMU_INTR_INFO_3"/>
- <reg32 offset="0x51c5" name="GMU_GENERAL_0"/>
- <reg32 offset="0x51c6" name="GMU_GENERAL_1"/>
- <reg32 offset="0x51cb" name="GMU_GENERAL_6"/>
- <reg32 offset="0x51cc" name="GMU_GENERAL_7"/>
- <reg32 offset="0x51cd" name="GMU_GENERAL_8" variants="A7XX"/>
- <reg32 offset="0x51ce" name="GMU_GENERAL_9" variants="A7XX"/>
- <reg32 offset="0x51cf" name="GMU_GENERAL_10" variants="A7XX"/>
- <reg32 offset="0x515d" name="GMU_ISENSE_CTRL"/>
- <reg32 offset="0x8920" name="GPU_CS_ENABLE_REG"/>
- <reg32 offset="0x515d" name="GPU_GMU_CX_GMU_ISENSE_CTRL"/>
- <reg32 offset="0x8578" name="GPU_CS_AMP_CALIBRATION_CONTROL3"/>
- <reg32 offset="0x8558" name="GPU_CS_AMP_CALIBRATION_CONTROL2"/>
- <reg32 offset="0x8580" name="GPU_CS_A_SENSOR_CTRL_0"/>
- <reg32 offset="0x27ada" name="GPU_CS_A_SENSOR_CTRL_2"/>
- <reg32 offset="0x881a" name="GPU_CS_SENSOR_GENERAL_STATUS"/>
- <reg32 offset="0x8957" name="GPU_CS_AMP_CALIBRATION_CONTROL1"/>
- <reg32 offset="0x881a" name="GPU_CS_SENSOR_GENERAL_STATUS"/>
- <reg32 offset="0x881d" name="GPU_CS_AMP_CALIBRATION_STATUS1_0"/>
- <reg32 offset="0x881f" name="GPU_CS_AMP_CALIBRATION_STATUS1_2"/>
- <reg32 offset="0x8821" name="GPU_CS_AMP_CALIBRATION_STATUS1_4"/>
- <reg32 offset="0x8965" name="GPU_CS_AMP_CALIBRATION_DONE"/>
- <reg32 offset="0x896d" name="GPU_CS_AMP_PERIOD_CTRL"/>
- <reg32 offset="0x8965" name="GPU_CS_AMP_CALIBRATION_DONE"/>
- <reg32 offset="0x514d" name="GPU_GMU_CX_GMU_PWR_THRESHOLD"/>
- <reg32 offset="0x9303" name="GMU_AO_INTERRUPT_EN"/>
- <reg32 offset="0x9304" name="GMU_AO_HOST_INTERRUPT_CLR"/>
- <reg32 offset="0x9305" name="GMU_AO_HOST_INTERRUPT_STATUS">
+ <reg32 offset="0x1f993" name="GMU_GMU2HOST_INTR_MASK"/>
+ <reg32 offset="0x1f994" name="GMU_HOST2GMU_INTR_SET"/>
+ <reg32 offset="0x1f995" name="GMU_HOST2GMU_INTR_CLR"/>
+ <reg32 offset="0x1f996" name="GMU_HOST2GMU_INTR_RAW_INFO"/>
+ <reg32 offset="0x1f997" name="GMU_HOST2GMU_INTR_EN_0"/>
+ <reg32 offset="0x1f998" name="GMU_HOST2GMU_INTR_EN_1"/>
+ <reg32 offset="0x1f999" name="GMU_HOST2GMU_INTR_EN_2"/>
+ <reg32 offset="0x1f99a" name="GMU_HOST2GMU_INTR_EN_3"/>
+ <reg32 offset="0x1f99b" name="GMU_HOST2GMU_INTR_INFO_0"/>
+ <reg32 offset="0x1f99c" name="GMU_HOST2GMU_INTR_INFO_1"/>
+ <reg32 offset="0x1f99d" name="GMU_HOST2GMU_INTR_INFO_2"/>
+ <reg32 offset="0x1f99e" name="GMU_HOST2GMU_INTR_INFO_3"/>
+ <reg32 offset="0x1f9c5" name="GMU_GENERAL_0"/>
+ <reg32 offset="0x1f9c6" name="GMU_GENERAL_1"/>
+ <reg32 offset="0x1f9cb" name="GMU_GENERAL_6"/>
+ <reg32 offset="0x1f9cc" name="GMU_GENERAL_7"/>
+ <reg32 offset="0x1f9cd" name="GMU_GENERAL_8" variants="A7XX"/>
+ <reg32 offset="0x1f9ce" name="GMU_GENERAL_9" variants="A7XX"/>
+ <reg32 offset="0x1f9cf" name="GMU_GENERAL_10" variants="A7XX"/>
+ <reg32 offset="0x1f95d" name="GMU_ISENSE_CTRL"/>
+ <reg32 offset="0x23120" name="GPU_CS_ENABLE_REG"/>
+ <reg32 offset="0x1f95d" name="GPU_GMU_CX_GMU_ISENSE_CTRL"/>
+ <reg32 offset="0x22d78" name="GPU_CS_AMP_CALIBRATION_CONTROL3"/>
+ <reg32 offset="0x22d58" name="GPU_CS_AMP_CALIBRATION_CONTROL2"/>
+ <reg32 offset="0x22d80" name="GPU_CS_A_SENSOR_CTRL_0"/>
+ <reg32 offset="0x422da" name="GPU_CS_A_SENSOR_CTRL_2"/>
+ <reg32 offset="0x2301a" name="GPU_CS_SENSOR_GENERAL_STATUS"/>
+ <reg32 offset="0x23157" name="GPU_CS_AMP_CALIBRATION_CONTROL1"/>
+ <reg32 offset="0x2301a" name="GPU_CS_SENSOR_GENERAL_STATUS"/>
+ <reg32 offset="0x2301d" name="GPU_CS_AMP_CALIBRATION_STATUS1_0"/>
+ <reg32 offset="0x2301f" name="GPU_CS_AMP_CALIBRATION_STATUS1_2"/>
+ <reg32 offset="0x23021" name="GPU_CS_AMP_CALIBRATION_STATUS1_4"/>
+ <reg32 offset="0x23165" name="GPU_CS_AMP_CALIBRATION_DONE"/>
+ <reg32 offset="0x2316d" name="GPU_CS_AMP_PERIOD_CTRL"/>
+ <reg32 offset="0x23165" name="GPU_CS_AMP_CALIBRATION_DONE"/>
+ <reg32 offset="0x1f94d" name="GPU_GMU_CX_GMU_PWR_THRESHOLD"/>
+ <reg32 offset="0x23b03" name="GMU_AO_INTERRUPT_EN"/>
+ <reg32 offset="0x23b04" name="GMU_AO_HOST_INTERRUPT_CLR"/>
+ <reg32 offset="0x23b05" name="GMU_AO_HOST_INTERRUPT_STATUS">
<bitfield name="WDOG_BITE" pos="0" type="boolean"/>
<bitfield name="RSCC_COMP" pos="1" type="boolean"/>
<bitfield name="VDROOP" pos="2" type="boolean"/>
@@ -191,27 +191,27 @@ xsi:schemaLocation="https://gitlab.freedesktop.org/freedreno/ rules-fd.xsd">
<bitfield name="DBD_WAKEUP" pos="4" type="boolean"/>
<bitfield name="HOST_AHB_BUS_ERROR" pos="5" type="boolean"/>
</reg32>
- <reg32 offset="0x9306" name="GMU_AO_HOST_INTERRUPT_MASK"/>
- <reg32 offset="0x9309" name="GPU_GMU_AO_GMU_CGC_MODE_CNTL"/>
- <reg32 offset="0x930a" name="GPU_GMU_AO_GMU_CGC_DELAY_CNTL"/>
- <reg32 offset="0x930b" name="GPU_GMU_AO_GMU_CGC_HYST_CNTL"/>
- <reg32 offset="0x930c" name="GPU_GMU_AO_GPU_CX_BUSY_STATUS">
+ <reg32 offset="0x23b06" name="GMU_AO_HOST_INTERRUPT_MASK"/>
+ <reg32 offset="0x23b09" name="GPU_GMU_AO_GMU_CGC_MODE_CNTL"/>
+ <reg32 offset="0x23b0a" name="GPU_GMU_AO_GMU_CGC_DELAY_CNTL"/>
+ <reg32 offset="0x23b0b" name="GPU_GMU_AO_GMU_CGC_HYST_CNTL"/>
+ <reg32 offset="0x23b0c" name="GPU_GMU_AO_GPU_CX_BUSY_STATUS">
<bitfield name = "GPUBUSYIGNAHB" pos="23" type="boolean"/>
</reg32>
- <reg32 offset="0x930d" name="GPU_GMU_AO_GPU_CX_BUSY_STATUS2"/>
- <reg32 offset="0x930e" name="GPU_GMU_AO_GPU_CX_BUSY_MASK"/>
- <reg32 offset="0x9310" name="GMU_AO_AHB_FENCE_CTRL"/>
- <reg32 offset="0x9313" name="GMU_AHB_FENCE_STATUS"/>
- <reg32 offset="0x9314" name="GMU_AHB_FENCE_STATUS_CLR"/>
- <reg32 offset="0x9315" name="GMU_RBBM_INT_UNMASKED_STATUS"/>
- <reg32 offset="0x9316" name="GMU_AO_SPARE_CNTL"/>
- <reg32 offset="0x9307" name="GMU_RSCC_CONTROL_REQ"/>
- <reg32 offset="0x9308" name="GMU_RSCC_CONTROL_ACK"/>
- <reg32 offset="0x9311" name="GMU_AHB_FENCE_RANGE_0"/>
- <reg32 offset="0x9312" name="GMU_AHB_FENCE_RANGE_1"/>
- <reg32 offset="0x9c03" name="GPU_CC_GX_GDSCR"/>
- <reg32 offset="0x9d42" name="GPU_CC_GX_DOMAIN_MISC"/>
- <reg32 offset="0xc001" name="GPU_CPR_FSM_CTL"/>
+ <reg32 offset="0x23b0d" name="GPU_GMU_AO_GPU_CX_BUSY_STATUS2"/>
+ <reg32 offset="0x23b0e" name="GPU_GMU_AO_GPU_CX_BUSY_MASK"/>
+ <reg32 offset="0x23b10" name="GMU_AO_AHB_FENCE_CTRL"/>
+ <reg32 offset="0x23b13" name="GMU_AHB_FENCE_STATUS"/>
+ <reg32 offset="0x23b14" name="GMU_AHB_FENCE_STATUS_CLR"/>
+ <reg32 offset="0x23b15" name="GMU_RBBM_INT_UNMASKED_STATUS"/>
+ <reg32 offset="0x23b16" name="GMU_AO_SPARE_CNTL"/>
+ <reg32 offset="0x23b07" name="GMU_RSCC_CONTROL_REQ"/>
+ <reg32 offset="0x23b08" name="GMU_RSCC_CONTROL_ACK"/>
+ <reg32 offset="0x23b11" name="GMU_AHB_FENCE_RANGE_0"/>
+ <reg32 offset="0x23b12" name="GMU_AHB_FENCE_RANGE_1"/>
+ <reg32 offset="0x24403" name="GPU_CC_GX_GDSCR"/>
+ <reg32 offset="0x24542" name="GPU_CC_GX_DOMAIN_MISC"/>
+ <reg32 offset="0x26801" name="GPU_CPR_FSM_CTL"/>
<!-- starts at offset 0x8c00 on most gpus -->
<reg32 offset="0x0004" name="GPU_RSCC_RSC_STATUS0_DRV0"/>
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0432/1518] drm/msm/a6xx: Fix A621 GPUCC register list for state capture
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (430 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0431/1518] drm/msm/a6xx: Rebase GMU register offsets Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0433/1518] drm/msm: Fix task_struct reference leak in recover_worker Greg Kroah-Hartman
` (566 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jie Zhang, Akhil P Oommen,
Dmitry Baryshkov, Rob Clark, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jie Zhang <jie.zhang@oss.qualcomm.com>
[ Upstream commit d052d0358fb89b59718b9c24871d72006d4b89b0 ]
A621 uses an incorrect GPUCC register list during state capture.
The existing list matches A623/A663. Rename it accordingly and add a
dedicated A621 GPUCC register list.
Fixes: 11cdb81b3c1b ("drm/msm/a6xx: Fix gpucc register block for A621")
Signed-off-by: Jie Zhang <jie.zhang@oss.qualcomm.com>
Signed-off-by: Akhil P Oommen <akhilpo@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/730659/
Message-ID: <20260605-assorted-fixes-june-v1-4-2caa04f7287c@oss.qualcomm.com>
Signed-off-by: Rob Clark <robin.clark@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/adreno/a6xx_gpu_state.c | 7 ++++---
drivers/gpu/drm/msm/adreno/a6xx_gpu_state.h | 12 ++++++++++++
2 files changed, 16 insertions(+), 3 deletions(-)
diff --git a/drivers/gpu/drm/msm/adreno/a6xx_gpu_state.c b/drivers/gpu/drm/msm/adreno/a6xx_gpu_state.c
index 8a412b7d3129f..cdd1a27ab8106 100644
--- a/drivers/gpu/drm/msm/adreno/a6xx_gpu_state.c
+++ b/drivers/gpu/drm/msm/adreno/a6xx_gpu_state.c
@@ -1244,11 +1244,12 @@ static void a6xx_get_gmu_registers(struct msm_gpu *gpu,
_a6xx_get_gmu_registers(gpu, a6xx_state, &a6xx_gmu_reglist[1],
&a6xx_state->gmu_registers[1], true);
- if (adreno_is_a621(adreno_gpu) ||
- adreno_is_a623(adreno_gpu) ||
- adreno_is_a663(adreno_gpu))
+ if (adreno_is_a621(adreno_gpu))
_a6xx_get_gmu_registers(gpu, a6xx_state, &a621_gpucc_reg,
&a6xx_state->gmu_registers[2], false);
+ else if (adreno_is_a623(adreno_gpu) || adreno_is_a663(adreno_gpu))
+ _a6xx_get_gmu_registers(gpu, a6xx_state, &a623_gpucc_reg,
+ &a6xx_state->gmu_registers[2], false);
else
_a6xx_get_gmu_registers(gpu, a6xx_state, &a6xx_gpucc_reg,
&a6xx_state->gmu_registers[2], false);
diff --git a/drivers/gpu/drm/msm/adreno/a6xx_gpu_state.h b/drivers/gpu/drm/msm/adreno/a6xx_gpu_state.h
index 4753b71837f33..e6fcae8d4bd34 100644
--- a/drivers/gpu/drm/msm/adreno/a6xx_gpu_state.h
+++ b/drivers/gpu/drm/msm/adreno/a6xx_gpu_state.h
@@ -377,6 +377,17 @@ static const u32 a6xx_gmu_gpucc_registers[] = {
};
static const u32 a621_gmu_gpucc_registers[] = {
+ /* GPU CC */
+ 0x24000, 0x2400e, 0x24400, 0x2440e, 0x24800, 0x24805, 0x24c00, 0x24cff,
+ 0x25800, 0x25804, 0x25c00, 0x25c04, 0x26000, 0x26004, 0x26400, 0x26405,
+ 0x26414, 0x2641d, 0x2642a, 0x26430, 0x26432, 0x26432, 0x26441, 0x26455,
+ 0x26466, 0x26468, 0x26478, 0x2647a, 0x26489, 0x2648a, 0x2649c, 0x2649e,
+ 0x264a0, 0x264a3, 0x264b3, 0x264b5, 0x264c5, 0x264c7, 0x264d6, 0x264d8,
+ 0x264e8, 0x264e9, 0x264f9, 0x264fc, 0x2650b, 0x2650c, 0x2651c, 0x2651e,
+ 0x26540, 0x26570, 0x26600, 0x26616, 0x26620, 0x2662d,
+};
+
+static const u32 a623_gmu_gpucc_registers[] = {
/* GPU CC */
0x24000, 0x2400e, 0x24400, 0x2440e, 0x25800, 0x25804, 0x25c00, 0x25c04,
0x26000, 0x26004, 0x26400, 0x26405, 0x26414, 0x2641d, 0x2642a, 0x26430,
@@ -402,6 +413,7 @@ static const struct a6xx_registers a6xx_gmu_reglist[] = {
static const struct a6xx_registers a6xx_gpucc_reg = REGS(a6xx_gmu_gpucc_registers, 0, 0);
static const struct a6xx_registers a621_gpucc_reg = REGS(a621_gmu_gpucc_registers, 0, 0);
+static const struct a6xx_registers a623_gpucc_reg = REGS(a623_gmu_gpucc_registers, 0, 0);
static u32 a6xx_get_cp_roq_size(struct msm_gpu *gpu);
static u32 a7xx_get_cp_roq_size(struct msm_gpu *gpu);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0433/1518] drm/msm: Fix task_struct reference leak in recover_worker
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (431 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0432/1518] drm/msm/a6xx: Fix A621 GPUCC register list for state capture Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0434/1518] drm/msm: Only fini scheduler after successful init Greg Kroah-Hartman
` (565 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jie Zhang, Akhil P Oommen,
Konrad Dybcio, Rob Clark, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jie Zhang <jie.zhang@oss.qualcomm.com>
[ Upstream commit 40b793714ad8f393ab3d469f9d00b20ebda46257 ]
get_pid_task() increments the task reference count, but the
corresponding put_task_struct() was missing in the else branch,
leaking a reference on every GPU hang recovery.
Fixes: 25654a1756a4 ("drm/msm: Update global fault counter when faulty process has already ended")
Signed-off-by: Jie Zhang <jie.zhang@oss.qualcomm.com>
Signed-off-by: Akhil P Oommen <akhilpo@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/730662/
Message-ID: <20260605-assorted-fixes-june-v1-6-2caa04f7287c@oss.qualcomm.com>
Signed-off-by: Rob Clark <robin.clark@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/msm_gpu.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/gpu/drm/msm/msm_gpu.c b/drivers/gpu/drm/msm/msm_gpu.c
index c78f5738bfdeb..569a1ba02e608 100644
--- a/drivers/gpu/drm/msm/msm_gpu.c
+++ b/drivers/gpu/drm/msm/msm_gpu.c
@@ -505,6 +505,8 @@ static void recover_worker(struct kthread_work *work)
*/
if (!vm->managed)
msm_gem_vm_unusable(submit->vm);
+
+ put_task_struct(task);
}
get_comm_cmdline(submit, &comm, &cmd);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0434/1518] drm/msm: Only fini scheduler after successful init
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (432 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0433/1518] drm/msm: Fix task_struct reference leak in recover_worker Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0435/1518] bpf: Sync tail_call_reachable with callee state on entry Greg Kroah-Hartman
` (564 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ruoyu Wang, Rob Clark, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ruoyu Wang <ruoyuw560@gmail.com>
[ Upstream commit e2332abed2a4d3caa59052095dc16e4ce44791ea ]
msm_ringbuffer_new() destroys a partially initialized ring through
msm_ringbuffer_destroy() when an allocation or scheduler setup step
fails.
If drm_sched_init() fails before it finishes initializing the scheduler,
the failure path still calls drm_sched_fini(). That teardown path assumes
the scheduler work items, lists, and workqueue state were initialized.
Track successful scheduler initialization and call drm_sched_fini() only
after drm_sched_init() returned 0.
This issue was found by a static analysis checker and confirmed by
manual source review.
Fixes: 1d8a5ca436ee ("drm/msm: Conversion to drm scheduler")
Signed-off-by: Ruoyu Wang <ruoyuw560@gmail.com>
Patchwork: https://patchwork.freedesktop.org/patch/738905/
Message-ID: <20260709062309.4168362-1-ruoyuw560@gmail.com>
Signed-off-by: Rob Clark <robin.clark@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/msm_ringbuffer.c | 7 ++++---
drivers/gpu/drm/msm/msm_ringbuffer.h | 1 +
2 files changed, 5 insertions(+), 3 deletions(-)
diff --git a/drivers/gpu/drm/msm/msm_ringbuffer.c b/drivers/gpu/drm/msm/msm_ringbuffer.c
index b2f612e5dc793..e09ec7f398d58 100644
--- a/drivers/gpu/drm/msm/msm_ringbuffer.c
+++ b/drivers/gpu/drm/msm/msm_ringbuffer.c
@@ -109,9 +109,9 @@ struct msm_ringbuffer *msm_ringbuffer_new(struct msm_gpu *gpu, int id,
ring->memptrs_iova = memptrs_iova;
ret = drm_sched_init(&ring->sched, &args);
- if (ret) {
+ if (ret)
goto fail;
- }
+ ring->sched_initialized = true;
INIT_LIST_HEAD(&ring->submits);
spin_lock_init(&ring->submit_lock);
@@ -133,7 +133,8 @@ void msm_ringbuffer_destroy(struct msm_ringbuffer *ring)
if (IS_ERR_OR_NULL(ring))
return;
- drm_sched_fini(&ring->sched);
+ if (ring->sched_initialized)
+ drm_sched_fini(&ring->sched);
msm_fence_context_free(ring->fctx);
diff --git a/drivers/gpu/drm/msm/msm_ringbuffer.h b/drivers/gpu/drm/msm/msm_ringbuffer.h
index d1e49f701c817..bace58a3dffbe 100644
--- a/drivers/gpu/drm/msm/msm_ringbuffer.h
+++ b/drivers/gpu/drm/msm/msm_ringbuffer.h
@@ -54,6 +54,7 @@ struct msm_ringbuffer {
* The job scheduler for this ring.
*/
struct drm_gpu_scheduler sched;
+ bool sched_initialized;
/*
* List of in-flight submits on this ring. Protected by submit_lock.
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0435/1518] bpf: Sync tail_call_reachable with callee state on entry
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (433 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0434/1518] drm/msm: Only fini scheduler after successful init Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0436/1518] crypto: sl3516 - drop invalid sg_dma_len checks before DMA mapping Greg Kroah-Hartman
` (563 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Pu Lehui, Eduard Zingerman,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pu Lehui <pulehui@huawei.com>
[ Upstream commit 3513ea9dab6c1a3d2dc8e6160c41f690206948b6 ]
Currently in check_max_stack_depth_subprog, when the verifier enters a
new callee branch, the local tail_call_reachable is not properly
synchronized with the callee's state.
Consider a main prog branching into multiple subprogs:
subprog0 -> tailcall
main <
subprog1 -> subprog2
When the verifier finishes checking subprog0 and backtracks to main
prog, the local tail_call_reachable state is left as true. As it
proceeds to subprog1, this uncleared state leaks into the new branch,
falsely marking subprog1 and subprog2 as tailcall reachable.
Fix this by explicitly syncing tail_call_reachable with the callee's
has_tail_call state on entry. The caller's state is safely preserved and
restored via the existing backtracking logic.
Fixes: ebf7d1f508a7 ("bpf, x64: rework pro/epilogue and tailcall handling in JIT")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Pu Lehui <pulehui@huawei.com>
Link: https://patch.msgid.link/20260716120157.835937-2-pulehui@huaweicloud.com
Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/verifier.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index 3be56a023a1bc..39f45a08ab83c 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -6728,8 +6728,8 @@ static int check_max_stack_depth_subprog(struct bpf_verifier_env *env, int idx,
if (!priv_stack_supported)
subprog[idx].priv_stack_mode = NO_PRIV_STACK;
- if (subprog[idx].has_tail_call)
- tail_call_reachable = true;
+ /* sync tail_call_reachable with callee state on entry */
+ tail_call_reachable = subprog[idx].has_tail_call;
frame++;
if (frame >= MAX_CALL_FRAMES) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0436/1518] crypto: sl3516 - drop invalid sg_dma_len checks before DMA mapping
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (434 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0435/1518] bpf: Sync tail_call_reachable with callee state on entry Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0437/1518] ACPI: processor: idle: Expand _LPI package sanity checks Greg Kroah-Hartman
` (562 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Thorsten Blum, Linus Walleij,
Herbert Xu, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thorsten Blum <thorsten.blum@linux.dev>
[ Upstream commit 3ae59a2eba64b3648f069aa52eeaaeefdfe4bb2f ]
sg_dma_len() is only valid after mapping the scatterlist with
dma_map_sg(). However, sl3516_ce_need_fallback() checks it before the
source and destination scatterlists are mapped. Thus, a stale DMA length
that is not a multiple of 16 could incorrectly force a software fallback
when CONFIG_NEED_SG_DMA_LENGTH=y.
Remove the invalid checks; the existing scatterlist length checks are
sufficient.
Fixes: 46c5338db7bd ("crypto: sl3516 - Add sl3516 crypto engine")
Signed-off-by: Thorsten Blum <thorsten.blum@linux.dev>
Acked-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/crypto/gemini/sl3516-ce-cipher.c | 8 --------
1 file changed, 8 deletions(-)
diff --git a/drivers/crypto/gemini/sl3516-ce-cipher.c b/drivers/crypto/gemini/sl3516-ce-cipher.c
index 583010b2d0071..02ec4282333b6 100644
--- a/drivers/crypto/gemini/sl3516-ce-cipher.c
+++ b/drivers/crypto/gemini/sl3516-ce-cipher.c
@@ -56,10 +56,6 @@ static bool sl3516_ce_need_fallback(struct skcipher_request *areq)
ce->fallback_mod16++;
return true;
}
- if ((sg_dma_len(sg) % 16) != 0) {
- ce->fallback_mod16++;
- return true;
- }
if (!IS_ALIGNED(sg->offset, 16)) {
ce->fallback_align16++;
return true;
@@ -72,10 +68,6 @@ static bool sl3516_ce_need_fallback(struct skcipher_request *areq)
ce->fallback_mod16++;
return true;
}
- if ((sg_dma_len(sg) % 16) != 0) {
- ce->fallback_mod16++;
- return true;
- }
if (!IS_ALIGNED(sg->offset, 16)) {
ce->fallback_align16++;
return true;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0437/1518] ACPI: processor: idle: Expand _LPI package sanity checks
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (435 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0436/1518] crypto: sl3516 - drop invalid sg_dma_len checks before DMA mapping Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0438/1518] usb: gadget: f_uac1_legacy: remove broken string configfs attributes Greg Kroah-Hartman
` (561 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rafael J. Wysocki, Sudeep Holla,
Huisong Li, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
[ Upstream commit d5c13047a132162d2649be876906ead691d12948 ]
The _LPI package sanity checks in acpi_processor_evaluate_lpi() miss
a couple of things, so expand them by adding a buffer size check
before retrieving a struct acpi_power_register from it (and skip the
given state if the buffer is not large enough to hold a register
structure) and making the function avoid copying the state description
from the ACPI table if there are too few elements in the package
supposed to hold it.
While at it, relocate and rephrase a comment about skipping _LPI state
package elements [7-8].
Fixes: a36a7fecfe60 ("ACPI / processor_idle: Add support for Low Power Idle(LPI) states")
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Reviewed-by: Sudeep Holla <sudeep.holla@kernel.org>
Acked-by: Huisong Li <lihuisong@huawei.com>
Link: https://patch.msgid.link/5084143.GXAFRqVoOG@rafael.j.wysocki
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/processor_idle.c | 28 +++++++++++++++++++++-------
1 file changed, 21 insertions(+), 7 deletions(-)
diff --git a/drivers/acpi/processor_idle.c b/drivers/acpi/processor_idle.c
index 2468c1d971e74..99e0a14a6201a 100644
--- a/drivers/acpi/processor_idle.c
+++ b/drivers/acpi/processor_idle.c
@@ -945,6 +945,13 @@ static int acpi_processor_evaluate_lpi(acpi_handle handle,
if (obj->type == ACPI_TYPE_BUFFER) {
struct acpi_power_register *reg;
+ if (obj->buffer.length < sizeof(*reg)) {
+ acpi_handle_debug(handle,
+ "Invalid register data for _LPI state %d\n",
+ state_idx);
+ continue;
+ }
+
reg = (struct acpi_power_register *)obj->buffer.pointer;
if (reg->space_id != ACPI_ADR_SPACE_SYSTEM_IO &&
reg->space_id != ACPI_ADR_SPACE_FIXED_HARDWARE)
@@ -961,13 +968,6 @@ static int acpi_processor_evaluate_lpi(acpi_handle handle,
continue;
}
- /* elements[7,8] skipped for now i.e. Residency/Usage counter*/
-
- obj = pkg_elem + 9;
- if (obj->type == ACPI_TYPE_STRING)
- strscpy(lpi_state->desc, obj->string.pointer,
- ACPI_CX_DESC_LEN);
-
lpi_state->index = state_idx;
if (obj_get_integer(pkg_elem + 0, &lpi_state->min_residency)) {
pr_debug("No min. residency found, assuming 10 us\n");
@@ -990,6 +990,20 @@ static int acpi_processor_evaluate_lpi(acpi_handle handle,
if (obj_get_integer(pkg_elem + 5, &lpi_state->enable_parent_state))
lpi_state->enable_parent_state = 0;
+
+ /* Skip elements [7-8] i.e. Residency/Usage counters. */
+
+ /*
+ * Avoid out-of-bounds access if the size of the package is less
+ * than expected.
+ */
+ if (element->package.count < 10)
+ continue;
+
+ obj = pkg_elem + 9;
+ if (obj->type == ACPI_TYPE_STRING)
+ strscpy(lpi_state->desc, obj->string.pointer,
+ ACPI_CX_DESC_LEN);
}
acpi_handle_debug(handle, "Found %d power states\n", state_idx);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0438/1518] usb: gadget: f_uac1_legacy: remove broken string configfs attributes
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (436 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0437/1518] ACPI: processor: idle: Expand _LPI package sanity checks Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0439/1518] tty: hvc: restrict HVC_DCC to ARMv6+ and ARM64 Greg Kroah-Hartman
` (560 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Xu Yang, Frank Li, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xu Yang <xu.yang_2@nxp.com>
[ Upstream commit 590d74ec8f488e06b9f1c0f8f0941f45531f3a55 ]
The UAC1_STR_ATTRIBUTE macro defines configfs show/store handlers for
the fn_play, fn_cap, and fn_cntl string options. The store function
contains an inverted null check on the kstrndup() return value.
This means every write attempt returns -ENOMEM on success and
dereferences a NULL pointer on allocation failure. The attributes
have been broken and unused for many years.
Remove the UAC1_STR_ATTRIBUTE macro and the three attributes it
generated. The internal defaults (FILE_PCM_PLAYBACK, FILE_PCM_CAPTURE,
FILE_CONTROL) set in f_audio_alloc_inst() are unaffected.
Fixes: 0854611a19ae ("usb: gadget: f_uac1: add configfs support")
Link: https://lore.kernel.org/linux-usb/20260625113154.1954813-1-xu.yang_2@oss.nxp.com/
Suggested-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Assisted-by: Claude:claude-sonnet-4.6
Signed-off-by: Xu Yang <xu.yang_2@nxp.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260713060845.3759673-1-xu.yang_2@oss.nxp.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../testing/configfs-usb-gadget-uac1_legacy | 3 -
Documentation/usb/gadget-testing.rst | 3 -
drivers/usb/gadget/function/f_uac1_legacy.c | 56 -------------------
drivers/usb/gadget/function/u_uac1_legacy.h | 3 -
4 files changed, 65 deletions(-)
diff --git a/Documentation/ABI/testing/configfs-usb-gadget-uac1_legacy b/Documentation/ABI/testing/configfs-usb-gadget-uac1_legacy
index b2eaefd9bc498..6a681d219f439 100644
--- a/Documentation/ABI/testing/configfs-usb-gadget-uac1_legacy
+++ b/Documentation/ABI/testing/configfs-usb-gadget-uac1_legacy
@@ -5,8 +5,5 @@ Description:
The attributes:
audio_buf_size - audio buffer size
- fn_cap - capture pcm device file name
- fn_cntl - control device file name
- fn_play - playback pcm device file name
req_buf_size - ISO OUT endpoint request buffer size
req_count - ISO OUT endpoint request count
diff --git a/Documentation/usb/gadget-testing.rst b/Documentation/usb/gadget-testing.rst
index 5f90af1fb5732..edc13740ff6b7 100644
--- a/Documentation/usb/gadget-testing.rst
+++ b/Documentation/usb/gadget-testing.rst
@@ -712,9 +712,6 @@ The uac1 function provides these attributes in its function directory:
=============== ====================================
audio_buf_size audio buffer size
- fn_cap capture pcm device file name
- fn_cntl control device file name
- fn_play playback pcm device file name
req_buf_size ISO OUT endpoint request buffer size
req_count ISO OUT endpoint request count
=============== ====================================
diff --git a/drivers/usb/gadget/function/f_uac1_legacy.c b/drivers/usb/gadget/function/f_uac1_legacy.c
index 4981af8337ab8..c234f9fea27cf 100644
--- a/drivers/usb/gadget/function/f_uac1_legacy.c
+++ b/drivers/usb/gadget/function/f_uac1_legacy.c
@@ -888,60 +888,10 @@ UAC1_INT_ATTRIBUTE(req_buf_size);
UAC1_INT_ATTRIBUTE(req_count);
UAC1_INT_ATTRIBUTE(audio_buf_size);
-#define UAC1_STR_ATTRIBUTE(name) \
-static ssize_t f_uac1_opts_##name##_show(struct config_item *item, \
- char *page) \
-{ \
- struct f_uac1_legacy_opts *opts = to_f_uac1_opts(item); \
- int result; \
- \
- mutex_lock(&opts->lock); \
- result = sprintf(page, "%s\n", opts->name); \
- mutex_unlock(&opts->lock); \
- \
- return result; \
-} \
- \
-static ssize_t f_uac1_opts_##name##_store(struct config_item *item, \
- const char *page, size_t len) \
-{ \
- struct f_uac1_legacy_opts *opts = to_f_uac1_opts(item); \
- int ret = -EBUSY; \
- char *tmp; \
- \
- mutex_lock(&opts->lock); \
- if (opts->refcnt) \
- goto end; \
- \
- tmp = kstrndup(page, len, GFP_KERNEL); \
- if (tmp) { \
- ret = -ENOMEM; \
- goto end; \
- } \
- if (opts->name##_alloc) \
- kfree(opts->name); \
- opts->name##_alloc = true; \
- opts->name = tmp; \
- ret = len; \
- \
-end: \
- mutex_unlock(&opts->lock); \
- return ret; \
-} \
- \
-CONFIGFS_ATTR(f_uac1_opts_, name)
-
-UAC1_STR_ATTRIBUTE(fn_play);
-UAC1_STR_ATTRIBUTE(fn_cap);
-UAC1_STR_ATTRIBUTE(fn_cntl);
-
static struct configfs_attribute *f_uac1_attrs[] = {
&f_uac1_opts_attr_req_buf_size,
&f_uac1_opts_attr_req_count,
&f_uac1_opts_attr_audio_buf_size,
- &f_uac1_opts_attr_fn_play,
- &f_uac1_opts_attr_fn_cap,
- &f_uac1_opts_attr_fn_cntl,
NULL,
};
@@ -956,12 +906,6 @@ static void f_audio_free_inst(struct usb_function_instance *f)
struct f_uac1_legacy_opts *opts;
opts = container_of(f, struct f_uac1_legacy_opts, func_inst);
- if (opts->fn_play_alloc)
- kfree(opts->fn_play);
- if (opts->fn_cap_alloc)
- kfree(opts->fn_cap);
- if (opts->fn_cntl_alloc)
- kfree(opts->fn_cntl);
kfree(opts);
}
diff --git a/drivers/usb/gadget/function/u_uac1_legacy.h b/drivers/usb/gadget/function/u_uac1_legacy.h
index b5df9bcbbeba7..b9ddae550ff3c 100644
--- a/drivers/usb/gadget/function/u_uac1_legacy.h
+++ b/drivers/usb/gadget/function/u_uac1_legacy.h
@@ -62,9 +62,6 @@ struct f_uac1_legacy_opts {
char *fn_cap;
char *fn_cntl;
unsigned bound:1;
- unsigned fn_play_alloc:1;
- unsigned fn_cap_alloc:1;
- unsigned fn_cntl_alloc:1;
struct mutex lock;
int refcnt;
};
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0439/1518] tty: hvc: restrict HVC_DCC to ARMv6+ and ARM64
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (437 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0438/1518] usb: gadget: f_uac1_legacy: remove broken string configfs attributes Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0440/1518] UDF symlink pathComponent header OOB read Greg Kroah-Hartman
` (559 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Arnd Bergmann,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 782f4dbd1794b4f30dc116a7ca42c5962c409be8 ]
hvc_dcc drives the JTAG DCC via the ARMv6/v7 CP14 debug registers
(mrc/mcr p14, 0, rX, c0, c1/c5, 0 in asm/dcc.h). That encoding is
undefined on older ARM cores, and also on ARMv7-M, but HVC_DCC only
depends on ARM, so it can be enabled on e.g. ARM926 (ARCH_MULTI_V5),
where hvc_dcc_console_init() runs __dcc_putchar() at boot and takes an
undefined-instruction trap before the console is up:
Internal error: Oops - undefined instruction: 0 [#1] ARM
PC is at hvc_dcc_check+0x50/0x8c
hvc_dcc_check from hvc_dcc_console_init+0x18/0x48
hvc_dcc_console_init from console_init+0x58/0x170
Kernel panic - not syncing: Fatal exception
Restrict HVC_DCC to the CPUs where that encoding is valid: the
CPU_V6 || CPU_V6K || CPU_V7 set that arch/arm/include/debug/icedcc.S
guards it with, plus ARM64.
Fixes: 16c63f8ea49c ("drivers: char: hvc: add arm JTAG DCC console support")
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Reviewed-by: Arnd Bergmann <arnd@arndb.de>
Link: https://patch.msgid.link/20260717071616.91423-1-kmehltretter@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/tty/hvc/Kconfig | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/tty/hvc/Kconfig b/drivers/tty/hvc/Kconfig
index c2a4e88b328f3..5866195de26a6 100644
--- a/drivers/tty/hvc/Kconfig
+++ b/drivers/tty/hvc/Kconfig
@@ -79,7 +79,7 @@ config HVC_UDBG
config HVC_DCC
bool "ARM JTAG DCC console"
- depends on ARM || ARM64
+ depends on (ARM && (CPU_V6 || CPU_V6K || CPU_V7)) || ARM64
select HVC_DRIVER
select SERIAL_CORE_CONSOLE
help
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0440/1518] UDF symlink pathComponent header OOB read
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (438 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0439/1518] tty: hvc: restrict HVC_DCC to ARMv6+ and ARM64 Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0441/1518] staging: rtl8723bs: Fix operator spacing in rtw_security.c Greg Kroah-Hartman
` (558 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, David Lee, Jan Kara, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Lee <david.lee@trailofbits.com>
[ Upstream commit d23eb7380d1594cda31a5dc8487dd2a5c8def8c7 ]
udf_symlink_filler() can enter udf_pc_to_char() with a partial pathComponent header.
Validate that enough input remains for a complete pathComponent header
before accessing it. Reject malformed symlink data that would otherwise
make udf_pc_to_char() perform an out-of-bounds read.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: David Lee <david.lee@trailofbits.com>
Assisted-by: Codex:gpt-5.5
Link: https://patch.msgid.link/20260717104722.41446-1-david.lee@trailofbits.com
Signed-off-by: Jan Kara <jack@suse.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/udf/symlink.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/fs/udf/symlink.c b/fs/udf/symlink.c
index fe03745d09b18..a05d1888a2bab 100644
--- a/fs/udf/symlink.c
+++ b/fs/udf/symlink.c
@@ -36,6 +36,8 @@ static int udf_pc_to_char(struct super_block *sb, unsigned char *from,
/* Reserve one byte for terminating \0 */
tolen--;
while (elen < fromlen) {
+ if (fromlen - elen < sizeof(struct pathComponent))
+ return -EIO;
pc = (struct pathComponent *)(from + elen);
elen += sizeof(struct pathComponent);
switch (pc->componentType) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0441/1518] staging: rtl8723bs: Fix operator spacing in rtw_security.c
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (439 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0440/1518] UDF symlink pathComponent header OOB read Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0442/1518] staging: rtl8723bs: use standard offsetof in cfg80211 operations Greg Kroah-Hartman
` (557 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sameeksha Sankpal, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sameeksha Sankpal <sameekshasankpal@gmail.com>
[ Upstream commit 7550f96a57c8f8b649113aaa2cc4f87a755c866e ]
This file has multiple style issues where spaces were missing around
operators. Cleaned up the entire file by adding the required spacing
around the arithmetic, logical, and comparison operators to improve
readibility and adhere to the Linux kernel coding style guidelines.
Signed-off-by: Sameeksha Sankpal <sameekshasankpal@gmail.com>
Link: https://lore.kernel.org/r/20251006042005.9778-1-sameekshasankpal@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Stable-dep-of: 41b8209376df ("staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/staging/rtl8723bs/core/rtw_security.c | 156 +++++++++---------
1 file changed, 78 insertions(+), 78 deletions(-)
diff --git a/drivers/staging/rtl8723bs/core/rtw_security.c b/drivers/staging/rtl8723bs/core/rtw_security.c
index 5406f60dd31c6..fa952ff1beedc 100644
--- a/drivers/staging/rtl8723bs/core/rtw_security.c
+++ b/drivers/staging/rtl8723bs/core/rtw_security.c
@@ -62,14 +62,14 @@ void rtw_wep_encrypt(struct adapter *padapter, u8 *pxmitframe)
keylength = psecuritypriv->dot11DefKeylen[psecuritypriv->dot11PrivacyKeyIndex];
for (curfragnum = 0; curfragnum < pattrib->nr_frags; curfragnum++) {
- iv = pframe+pattrib->hdrlen;
+ iv = pframe + pattrib->hdrlen;
memcpy(&wepkey[0], iv, 3);
memcpy(&wepkey[3], &psecuritypriv->dot11DefKey[psecuritypriv->dot11PrivacyKeyIndex].skey[0], keylength);
- payload = pframe+pattrib->iv_len+pattrib->hdrlen;
+ payload = pframe + pattrib->iv_len + pattrib->hdrlen;
- if ((curfragnum+1) == pattrib->nr_frags) { /* the last fragment */
+ if ((curfragnum + 1) == pattrib->nr_frags) { /* the last fragment */
- length = pattrib->last_txcmdsz-pattrib->hdrlen-pattrib->iv_len-pattrib->icv_len;
+ length = pattrib->last_txcmdsz - pattrib->hdrlen - pattrib->iv_len - pattrib->icv_len;
crc.f0 = cpu_to_le32(~crc32_le(~0, payload, length));
@@ -78,7 +78,7 @@ void rtw_wep_encrypt(struct adapter *padapter, u8 *pxmitframe)
arc4_crypt(ctx, payload + length, crc.f1, 4);
} else {
- length = pxmitpriv->frag_len-pattrib->hdrlen-pattrib->iv_len-pattrib->icv_len;
+ length = pxmitpriv->frag_len - pattrib->hdrlen - pattrib->iv_len - pattrib->icv_len;
crc.f0 = cpu_to_le32(~crc32_le(~0, payload, length));
arc4_setkey(ctx, wepkey, 3 + keylength);
arc4_crypt(ctx, payload, payload, length);
@@ -107,16 +107,16 @@ void rtw_wep_decrypt(struct adapter *padapter, u8 *precvframe)
/* start to decrypt recvframe */
if ((prxattrib->encrypt == _WEP40_) || (prxattrib->encrypt == _WEP104_)) {
- iv = pframe+prxattrib->hdrlen;
+ iv = pframe + prxattrib->hdrlen;
/* keyindex =(iv[3]&0x3); */
keyindex = prxattrib->key_index;
keylength = psecuritypriv->dot11DefKeylen[keyindex];
memcpy(&wepkey[0], iv, 3);
/* memcpy(&wepkey[3], &psecuritypriv->dot11DefKey[psecuritypriv->dot11PrivacyKeyIndex].skey[0], keylength); */
memcpy(&wepkey[3], &psecuritypriv->dot11DefKey[keyindex].skey[0], keylength);
- length = ((union recv_frame *)precvframe)->u.hdr.len-prxattrib->hdrlen-prxattrib->iv_len;
+ length = ((union recv_frame *)precvframe)->u.hdr.len - prxattrib->hdrlen - prxattrib->iv_len;
- payload = pframe+prxattrib->iv_len+prxattrib->hdrlen;
+ payload = pframe + prxattrib->iv_len + prxattrib->hdrlen;
/* decrypt payload include icv */
arc4_setkey(ctx, wepkey, 3 + keylength);
@@ -174,7 +174,7 @@ void rtw_secmicsetkey(struct mic_data *pmicdata, u8 *key)
void rtw_secmicappendbyte(struct mic_data *pmicdata, u8 b)
{
/* Append the byte to our word-sized buffer */
- pmicdata->M |= ((unsigned long)b) << (8*pmicdata->nBytesInM);
+ pmicdata->M |= ((unsigned long)b) << (8 * pmicdata->nBytesInM);
pmicdata->nBytesInM++;
/* Process the word if it is full. */
if (pmicdata->nBytesInM >= 4) {
@@ -261,7 +261,7 @@ void rtw_seccalctkipmic(u8 *key, u8 *header, u8 *data, u32 data_len, u8 *mic_cod
#define Mk16(hi, lo) ((lo) ^ (((u16)(hi)) << 8))
/* select the Nth 16-bit word of the temporal key unsigned char array TK[] */
-#define TK16(N) Mk16(tk[2*(N)+1], tk[2*(N)])
+#define TK16(N) Mk16(tk[2 * (N) + 1], tk[2 * (N)])
/* S-box lookup: 16 bits --> 16 bits */
#define _S_(v16) (Sbox1[0][Lo8(v16)] ^ Sbox1[1][Hi8(v16)])
@@ -375,11 +375,11 @@ static void phase1(u16 *p1k, const u8 *tk, const u8 *ta, u32 iv32)
/* size on the 80-bit block P1K[], using the 128-bit key TK[] */
for (i = 0; i < PHASE1_LOOP_CNT; i++) {
/* Each add operation here is mod 2**16 */
- p1k[0] += _S_(p1k[4] ^ TK16((i&1)+0));
- p1k[1] += _S_(p1k[0] ^ TK16((i&1)+2));
- p1k[2] += _S_(p1k[1] ^ TK16((i&1)+4));
- p1k[3] += _S_(p1k[2] ^ TK16((i&1)+6));
- p1k[4] += _S_(p1k[3] ^ TK16((i&1)+0));
+ p1k[0] += _S_(p1k[4] ^ TK16((i & 1) + 0));
+ p1k[1] += _S_(p1k[0] ^ TK16((i & 1) + 2));
+ p1k[2] += _S_(p1k[1] ^ TK16((i & 1) + 4));
+ p1k[3] += _S_(p1k[2] ^ TK16((i & 1) + 6));
+ p1k[4] += _S_(p1k[3] ^ TK16((i & 1) + 0));
p1k[4] += (unsigned short)i; /* avoid "slide attacks" */
}
}
@@ -417,7 +417,7 @@ static void phase2(u8 *rc4key, const u8 *tk, const u16 *p1k, u16 iv16)
for (i = 0; i < 5; i++)
PPK[i] = p1k[i]; /* first, copy P1K to PPK */
- PPK[5] = p1k[4]+iv16; /* next, add in IV16 */
+ PPK[5] = p1k[4] + iv16; /* next, add in IV16 */
/* Bijective non-linear mixing of the 96 bits of PPK[0..5] */
PPK[0] += _S_(PPK[5] ^ TK16(0)); /* Mix key in each "round" */
@@ -448,8 +448,8 @@ static void phase2(u8 *rc4key, const u8 *tk, const u16 *p1k, u16 iv16)
/* Copy 96 bits of PPK[0..5] to RC4KEY[4..15] (little-endian) */
for (i = 0; i < 6; i++) {
- rc4key[4+2*i] = Lo8(PPK[i]);
- rc4key[5+2*i] = Hi8(PPK[i]);
+ rc4key[4 + 2 * i] = Lo8(PPK[i]);
+ rc4key[5 + 2 * i] = Hi8(PPK[i]);
}
}
@@ -492,20 +492,20 @@ u32 rtw_tkip_encrypt(struct adapter *padapter, u8 *pxmitframe)
prwskey = pattrib->dot118021x_UncstKey.skey;
for (curfragnum = 0; curfragnum < pattrib->nr_frags; curfragnum++) {
- iv = pframe+pattrib->hdrlen;
- payload = pframe+pattrib->iv_len+pattrib->hdrlen;
+ iv = pframe + pattrib->hdrlen;
+ payload = pframe + pattrib->iv_len + pattrib->hdrlen;
GET_TKIP_PN(iv, dot11txpn);
pnl = (u16)(dot11txpn.val);
- pnh = (u32)(dot11txpn.val>>16);
+ pnh = (u32)(dot11txpn.val >> 16);
phase1((u16 *)&ttkey[0], prwskey, &pattrib->ta[0], pnh);
phase2(&rc4key[0], prwskey, (u16 *)&ttkey[0], pnl);
- if ((curfragnum+1) == pattrib->nr_frags) { /* 4 the last fragment */
- length = pattrib->last_txcmdsz-pattrib->hdrlen-pattrib->iv_len-pattrib->icv_len;
+ if ((curfragnum + 1) == pattrib->nr_frags) { /* 4 the last fragment */
+ length = pattrib->last_txcmdsz - pattrib->hdrlen - pattrib->iv_len - pattrib->icv_len;
crc.f0 = cpu_to_le32(~crc32_le(~0, payload, length));
arc4_setkey(ctx, rc4key, 16);
@@ -513,7 +513,7 @@ u32 rtw_tkip_encrypt(struct adapter *padapter, u8 *pxmitframe)
arc4_crypt(ctx, payload + length, crc.f1, 4);
} else {
- length = pxmitpriv->frag_len-pattrib->hdrlen-pattrib->iv_len-pattrib->icv_len;
+ length = pxmitpriv->frag_len - pattrib->hdrlen - pattrib->iv_len - pattrib->icv_len;
crc.f0 = cpu_to_le32(~crc32_le(~0, payload, length));
arc4_setkey(ctx, rc4key, 16);
@@ -601,14 +601,14 @@ u32 rtw_tkip_decrypt(struct adapter *padapter, u8 *precvframe)
prwskey = &stainfo->dot118021x_UncstKey.skey[0];
}
- iv = pframe+prxattrib->hdrlen;
- payload = pframe+prxattrib->iv_len+prxattrib->hdrlen;
- length = ((union recv_frame *)precvframe)->u.hdr.len-prxattrib->hdrlen-prxattrib->iv_len;
+ iv = pframe + prxattrib->hdrlen;
+ payload = pframe + prxattrib->iv_len + prxattrib->hdrlen;
+ length = ((union recv_frame *)precvframe)->u.hdr.len - prxattrib->hdrlen - prxattrib->iv_len;
GET_TKIP_PN(iv, dot11txpn);
pnl = (u16)(dot11txpn.val);
- pnh = (u32)(dot11txpn.val>>16);
+ pnh = (u32)(dot11txpn.val >> 16);
phase1((u16 *)&ttkey[0], prwskey, &prxattrib->ta[0], pnh);
phase2(&rc4key[0], prwskey, (unsigned short *)&ttkey[0], pnl);
@@ -758,7 +758,7 @@ static void construct_mic_header2(u8 *mic_header2,
if (!qc_exists && a4_exists) {
for (i = 0; i < 6; i++)
- mic_header2[8+i] = mpdu[24+i]; /* A4 */
+ mic_header2[8 + i] = mpdu[24 + i]; /* A4 */
}
if (qc_exists && !a4_exists) {
@@ -768,7 +768,7 @@ static void construct_mic_header2(u8 *mic_header2,
if (qc_exists && a4_exists) {
for (i = 0; i < 6; i++)
- mic_header2[8+i] = mpdu[24+i]; /* A4 */
+ mic_header2[8 + i] = mpdu[24 + i]; /* A4 */
mic_header2[14] = mpdu[30] & 0x0f;
mic_header2[15] = mpdu[31] & 0x00;
@@ -839,16 +839,16 @@ static signed int aes_cipher(u8 *key, uint hdrlen,
uint frtype = GetFrameType(pframe);
uint frsubtype = GetFrameSubType(pframe);
- frsubtype = frsubtype>>4;
+ frsubtype = frsubtype >> 4;
if ((hdrlen == WLAN_HDR_A3_LEN) || (hdrlen == WLAN_HDR_A3_QOS_LEN))
a4_exists = 0;
else
a4_exists = 1;
- if (((frtype|frsubtype) == WIFI_DATA_CFACK) ||
- ((frtype|frsubtype) == WIFI_DATA_CFPOLL) ||
- ((frtype|frsubtype) == WIFI_DATA_CFACKPOLL)) {
+ if (((frtype | frsubtype) == WIFI_DATA_CFACK) ||
+ ((frtype | frsubtype) == WIFI_DATA_CFPOLL) ||
+ ((frtype | frsubtype) == WIFI_DATA_CFACKPOLL)) {
qc_exists = 1;
if (hdrlen != WLAN_HDR_A3_QOS_LEN)
hdrlen += 2;
@@ -867,11 +867,11 @@ static signed int aes_cipher(u8 *key, uint hdrlen,
}
pn_vector[0] = pframe[hdrlen];
- pn_vector[1] = pframe[hdrlen+1];
- pn_vector[2] = pframe[hdrlen+4];
- pn_vector[3] = pframe[hdrlen+5];
- pn_vector[4] = pframe[hdrlen+6];
- pn_vector[5] = pframe[hdrlen+7];
+ pn_vector[1] = pframe[hdrlen + 1];
+ pn_vector[2] = pframe[hdrlen + 4];
+ pn_vector[3] = pframe[hdrlen + 5];
+ pn_vector[4] = pframe[hdrlen + 6];
+ pn_vector[5] = pframe[hdrlen + 7];
construct_mic_iv(mic_iv,
qc_exists,
@@ -927,12 +927,12 @@ static signed int aes_cipher(u8 *key, uint hdrlen,
/* Insert MIC into payload */
for (j = 0; j < 8; j++)
- pframe[payload_index+j] = mic[j];
+ pframe[payload_index + j] = mic[j];
payload_index = hdrlen + 8;
for (i = 0; i < num_blocks; i++) {
construct_ctr_preload(ctr_preload, a4_exists, qc_exists, pframe, /* message, */
- pn_vector, i+1, frtype);
+ pn_vector, i + 1, frtype);
/* add for CONFIG_IEEE80211W, none 11w also can use */
aes128k128d(key, ctr_preload, aes_out);
crypto_xor_cpy(chain_buffer, aes_out, &pframe[payload_index], 16);
@@ -944,13 +944,13 @@ static signed int aes_cipher(u8 *key, uint hdrlen,
/* If there is a short final block, then pad it,*/
/* encrypt it and copy the unpadded part back */
construct_ctr_preload(ctr_preload, a4_exists, qc_exists, pframe, /* message, */
- pn_vector, num_blocks+1, frtype);
+ pn_vector, num_blocks + 1, frtype);
/* add for CONFIG_IEEE80211W, none 11w also can use */
for (j = 0; j < 16; j++)
padded_buffer[j] = 0x00;
for (j = 0; j < payload_remainder; j++)
- padded_buffer[j] = pframe[payload_index+j];
+ padded_buffer[j] = pframe[payload_index + j];
aes128k128d(key, ctr_preload, aes_out);
crypto_xor_cpy(chain_buffer, aes_out, padded_buffer, 16);
@@ -966,7 +966,7 @@ static signed int aes_cipher(u8 *key, uint hdrlen,
for (j = 0; j < 16; j++)
padded_buffer[j] = 0x00;
for (j = 0; j < 8; j++)
- padded_buffer[j] = pframe[j+hdrlen+8+plen];
+ padded_buffer[j] = pframe[j + hdrlen + 8 + plen];
aes128k128d(key, ctr_preload, aes_out);
crypto_xor_cpy(chain_buffer, aes_out, padded_buffer, 16);
@@ -1006,12 +1006,12 @@ u32 rtw_aes_encrypt(struct adapter *padapter, u8 *pxmitframe)
prwskey = pattrib->dot118021x_UncstKey.skey;
for (curfragnum = 0; curfragnum < pattrib->nr_frags; curfragnum++) {
- if ((curfragnum+1) == pattrib->nr_frags) { /* 4 the last fragment */
- length = pattrib->last_txcmdsz-pattrib->hdrlen-pattrib->iv_len-pattrib->icv_len;
+ if ((curfragnum + 1) == pattrib->nr_frags) { /* 4 the last fragment */
+ length = pattrib->last_txcmdsz - pattrib->hdrlen - pattrib->iv_len - pattrib->icv_len;
aes_cipher(prwskey, pattrib->hdrlen, pframe, length);
} else {
- length = pxmitpriv->frag_len-pattrib->hdrlen-pattrib->iv_len-pattrib->icv_len;
+ length = pxmitpriv->frag_len - pattrib->hdrlen - pattrib->iv_len - pattrib->icv_len;
aes_cipher(prwskey, pattrib->hdrlen, pframe, length);
pframe += pxmitpriv->frag_len;
@@ -1044,13 +1044,13 @@ static signed int aes_decipher(u8 *key, uint hdrlen,
uint frtype = GetFrameType(pframe);
uint frsubtype = GetFrameSubType(pframe);
- frsubtype = frsubtype>>4;
+ frsubtype = frsubtype >> 4;
/* start to decrypt the payload */
- num_blocks = (plen-8) / 16; /* plen including LLC, payload_length and mic) */
+ num_blocks = (plen - 8) / 16; /* plen including LLC, payload_length and mic) */
- payload_remainder = (plen-8) % 16;
+ payload_remainder = (plen - 8) % 16;
pn_vector[0] = pframe[hdrlen];
pn_vector[1] = pframe[hdrlen + 1];
@@ -1064,9 +1064,9 @@ static signed int aes_decipher(u8 *key, uint hdrlen,
else
a4_exists = 1;
- if (((frtype|frsubtype) == WIFI_DATA_CFACK) ||
- ((frtype|frsubtype) == WIFI_DATA_CFPOLL) ||
- ((frtype|frsubtype) == WIFI_DATA_CFACKPOLL)) {
+ if (((frtype | frsubtype) == WIFI_DATA_CFACK) ||
+ ((frtype | frsubtype) == WIFI_DATA_CFPOLL) ||
+ ((frtype | frsubtype) == WIFI_DATA_CFACKPOLL)) {
qc_exists = 1;
if (hdrlen != WLAN_HDR_A3_QOS_LEN)
hdrlen += 2;
@@ -1105,13 +1105,13 @@ static signed int aes_decipher(u8 *key, uint hdrlen,
/* If there is a short final block, then pad it,*/
/* encrypt it and copy the unpadded part back */
construct_ctr_preload(ctr_preload, a4_exists, qc_exists, pframe, pn_vector,
- num_blocks+1, frtype);
+ num_blocks + 1, frtype);
/* add for CONFIG_IEEE80211W, none 11w also can use */
for (j = 0; j < 16; j++)
padded_buffer[j] = 0x00;
for (j = 0; j < payload_remainder; j++)
- padded_buffer[j] = pframe[payload_index+j];
+ padded_buffer[j] = pframe[payload_index + j];
aes128k128d(key, ctr_preload, aes_out);
crypto_xor_cpy(chain_buffer, aes_out, padded_buffer, 16);
@@ -1120,25 +1120,25 @@ static signed int aes_decipher(u8 *key, uint hdrlen,
}
/* start to calculate the mic */
- if ((hdrlen + plen+8) <= MAX_MSG_SIZE)
- memcpy((void *)message, pframe, (hdrlen + plen+8)); /* 8 is for ext iv len */
+ if ((hdrlen + plen + 8) <= MAX_MSG_SIZE)
+ memcpy((void *)message, pframe, (hdrlen + plen + 8)); /* 8 is for ext iv len */
pn_vector[0] = pframe[hdrlen];
- pn_vector[1] = pframe[hdrlen+1];
- pn_vector[2] = pframe[hdrlen+4];
- pn_vector[3] = pframe[hdrlen+5];
- pn_vector[4] = pframe[hdrlen+6];
- pn_vector[5] = pframe[hdrlen+7];
+ pn_vector[1] = pframe[hdrlen + 1];
+ pn_vector[2] = pframe[hdrlen + 4];
+ pn_vector[3] = pframe[hdrlen + 5];
+ pn_vector[4] = pframe[hdrlen + 6];
+ pn_vector[5] = pframe[hdrlen + 7];
- construct_mic_iv(mic_iv, qc_exists, a4_exists, message, plen-8, pn_vector, frtype);
+ construct_mic_iv(mic_iv, qc_exists, a4_exists, message, plen - 8, pn_vector, frtype);
/* add for CONFIG_IEEE80211W, none 11w also can use */
construct_mic_header1(mic_header1, hdrlen, message, frtype);
/* add for CONFIG_IEEE80211W, none 11w also can use */
construct_mic_header2(mic_header2, message, a4_exists, qc_exists);
- payload_remainder = (plen-8) % 16;
- num_blocks = (plen-8) / 16;
+ payload_remainder = (plen - 8) % 16;
+ num_blocks = (plen - 8) / 16;
/* Find start of payload */
payload_index = (hdrlen + 8);
@@ -1173,11 +1173,11 @@ static signed int aes_decipher(u8 *key, uint hdrlen,
/* Insert MIC into payload */
for (j = 0; j < 8; j++)
- message[payload_index+j] = mic[j];
+ message[payload_index + j] = mic[j];
payload_index = hdrlen + 8;
for (i = 0; i < num_blocks; i++) {
- construct_ctr_preload(ctr_preload, a4_exists, qc_exists, message, pn_vector, i+1,
+ construct_ctr_preload(ctr_preload, a4_exists, qc_exists, message, pn_vector, i + 1,
frtype);
/* add for CONFIG_IEEE80211W, none 11w also can use */
aes128k128d(key, ctr_preload, aes_out);
@@ -1190,13 +1190,13 @@ static signed int aes_decipher(u8 *key, uint hdrlen,
/* If there is a short final block, then pad it,*/
/* encrypt it and copy the unpadded part back */
construct_ctr_preload(ctr_preload, a4_exists, qc_exists, message, pn_vector,
- num_blocks+1, frtype);
+ num_blocks + 1, frtype);
/* add for CONFIG_IEEE80211W, none 11w also can use */
for (j = 0; j < 16; j++)
padded_buffer[j] = 0x00;
for (j = 0; j < payload_remainder; j++)
- padded_buffer[j] = message[payload_index+j];
+ padded_buffer[j] = message[payload_index + j];
aes128k128d(key, ctr_preload, aes_out);
crypto_xor_cpy(chain_buffer, aes_out, padded_buffer, 16);
@@ -1211,7 +1211,7 @@ static signed int aes_decipher(u8 *key, uint hdrlen,
for (j = 0; j < 16; j++)
padded_buffer[j] = 0x00;
for (j = 0; j < 8; j++)
- padded_buffer[j] = message[j+hdrlen+8+plen-8];
+ padded_buffer[j] = message[j + hdrlen + 8 + plen - 8];
aes128k128d(key, ctr_preload, aes_out);
crypto_xor_cpy(chain_buffer, aes_out, padded_buffer, 16);
@@ -1298,7 +1298,7 @@ u32 rtw_aes_decrypt(struct adapter *padapter, u8 *precvframe)
prwskey = &stainfo->dot118021x_UncstKey.skey[0];
}
- length = ((union recv_frame *)precvframe)->u.hdr.len-prxattrib->hdrlen-prxattrib->iv_len;
+ length = ((union recv_frame *)precvframe)->u.hdr.len - prxattrib->hdrlen - prxattrib->iv_len;
res = aes_decipher(prwskey, prxattrib->hdrlen, pframe, length);
@@ -1323,7 +1323,7 @@ u32 rtw_BIP_verify(struct adapter *padapter, u8 *precvframe)
__le16 le_tmp;
__le64 le_tmp64 = 0;
- ori_len = pattrib->pkt_len-WLAN_HDR_A3_LEN+BIP_AAD_SIZE;
+ ori_len = pattrib->pkt_len - WLAN_HDR_A3_LEN + BIP_AAD_SIZE;
BIP_AAD = rtw_zmalloc(ori_len);
if (!BIP_AAD)
@@ -1334,28 +1334,28 @@ u32 rtw_BIP_verify(struct adapter *padapter, u8 *precvframe)
/* mapping to wlan header */
pwlanhdr = (struct ieee80211_hdr *)pframe;
/* save the frame body + MME */
- memcpy(BIP_AAD+BIP_AAD_SIZE, pframe+WLAN_HDR_A3_LEN, pattrib->pkt_len-WLAN_HDR_A3_LEN);
+ memcpy(BIP_AAD + BIP_AAD_SIZE, pframe + WLAN_HDR_A3_LEN, pattrib->pkt_len - WLAN_HDR_A3_LEN);
/* find MME IE pointer */
- p = rtw_get_ie(BIP_AAD+BIP_AAD_SIZE, WLAN_EID_MMIE, &len, pattrib->pkt_len-WLAN_HDR_A3_LEN);
+ p = rtw_get_ie(BIP_AAD + BIP_AAD_SIZE, WLAN_EID_MMIE, &len, pattrib->pkt_len - WLAN_HDR_A3_LEN);
/* Baron */
if (p) {
u16 keyid = 0;
u64 temp_ipn = 0;
/* save packet number */
- memcpy(&le_tmp64, p+4, 6);
+ memcpy(&le_tmp64, p + 4, 6);
temp_ipn = le64_to_cpu(le_tmp64);
/* BIP packet number should bigger than previous BIP packet */
if (temp_ipn <= pmlmeext->mgnt_80211w_IPN_rx)
goto BIP_exit;
/* copy key index */
- memcpy(&le_tmp, p+2, 2);
+ memcpy(&le_tmp, p + 2, 2);
keyid = le16_to_cpu(le_tmp);
if (keyid != padapter->securitypriv.dot11wBIPKeyid)
goto BIP_exit;
/* clear the MIC field of MME to zero */
- memset(p+2+len-8, 0, 8);
+ memset(p + 2 + len - 8, 0, 8);
/* conscruct AAD, copy frame control field */
memcpy(BIP_AAD, &pwlanhdr->frame_control, 2);
@@ -1515,7 +1515,7 @@ u8 rtw_handle_tkip_countermeasure(struct adapter *adapter, const char *caller)
if (securitypriv->btkip_countermeasure) {
unsigned long passing_ms = jiffies_to_msecs(jiffies - securitypriv->btkip_countermeasure_time);
- if (passing_ms > 60*1000) {
+ if (passing_ms > 60 * 1000) {
netdev_dbg(adapter->pnetdev,
"%s(%s) countermeasure time:%lus > 60s\n",
caller, ADPT_ARG(adapter),
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0442/1518] staging: rtl8723bs: use standard offsetof in cfg80211 operations
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (440 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0441/1518] staging: rtl8723bs: Fix operator spacing in rtw_security.c Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0443/1518] staging: rtl8723bs: fix operator and type cast spacing Greg Kroah-Hartman
` (556 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Navaneeth K, Dan Carpenter,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Navaneeth K <knavaneeth786@gmail.com>
[ Upstream commit 6ddb173fcf34f4b9351a20f29e31aa2bc3f90574 ]
Replace usage of the custom FIELD_OFFSET macro with the standard
offsetof() macro in ioctl_cfg80211.c. This improves code readability
and uses the kernel's standard mechanism.
Also include <linux/stddef.h> in basic_types.h to ensure offsetof()
is available for this and future conversions.
Signed-off-by: Navaneeth K <knavaneeth786@gmail.com>
Reviewed-by: Dan Carpenter <dan.carpenter@linaro.org>
Link: https://patch.msgid.link/20251125112059.16913-3-knavaneeth786@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Stable-dep-of: 41b8209376df ("staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/staging/rtl8723bs/include/basic_types.h | 1 +
drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c | 3 ++-
2 files changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/staging/rtl8723bs/include/basic_types.h b/drivers/staging/rtl8723bs/include/basic_types.h
index 1c2da18e62100..16b270fe0203d 100644
--- a/drivers/staging/rtl8723bs/include/basic_types.h
+++ b/drivers/staging/rtl8723bs/include/basic_types.h
@@ -12,6 +12,7 @@
#define FAIL (-1)
#include <linux/types.h>
+#include <linux/stddef.h>
#define FIELD_OFFSET(s, field) ((__kernel_ssize_t)&((s *)(0))->field)
diff --git a/drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c b/drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c
index 0eb40b7bd0ba3..cc898131f5d06 100644
--- a/drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c
+++ b/drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c
@@ -1721,7 +1721,8 @@ static int cfg80211_rtw_connect(struct wiphy *wiphy, struct net_device *ndev,
if (wep_key_len > 0) {
wep_key_len = wep_key_len <= 5 ? 5 : 13;
- wep_total_len = wep_key_len + FIELD_OFFSET(struct ndis_802_11_wep, key_material);
+ wep_total_len = wep_key_len +
+ offsetof(struct ndis_802_11_wep, key_material);
pwep = rtw_malloc(wep_total_len);
if (!pwep) {
ret = -ENOMEM;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0443/1518] staging: rtl8723bs: fix operator and type cast spacing
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (441 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0442/1518] staging: rtl8723bs: use standard offsetof in cfg80211 operations Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0444/1518] staging: rtl8723bs: expand multiple assignment into separate statements Greg Kroah-Hartman
` (555 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Khushal Chitturi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Khushal Chitturi <khushalchitturi@gmail.com>
[ Upstream commit 53e0181ee7225e3a1958c51b2f00f648878e91e1 ]
Fix spacing around operators and type casts in rtw_xmit.c to
comply with the kernel coding style.
Signed-off-by: Khushal Chitturi <khushalchitturi@gmail.com>
Link: https://patch.msgid.link/20260116053052.4198-2-khushalchitturi@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Stable-dep-of: 41b8209376df ("staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/staging/rtl8723bs/core/rtw_xmit.c | 89 +++++++++++++----------
1 file changed, 50 insertions(+), 39 deletions(-)
diff --git a/drivers/staging/rtl8723bs/core/rtw_xmit.c b/drivers/staging/rtl8723bs/core/rtw_xmit.c
index 21690857fd62a..bbc42db1c8284 100644
--- a/drivers/staging/rtl8723bs/core/rtw_xmit.c
+++ b/drivers/staging/rtl8723bs/core/rtw_xmit.c
@@ -78,7 +78,7 @@ s32 _rtw_init_xmit_priv(struct xmit_priv *pxmitpriv, struct adapter *padapter)
}
pxmitpriv->pxmit_frame_buf = (u8 *)N_BYTE_ALIGMENT((SIZE_PTR)(pxmitpriv->pallocated_frame_buf), 4);
- pxframe = (struct xmit_frame *) pxmitpriv->pxmit_frame_buf;
+ pxframe = (struct xmit_frame *)pxmitpriv->pxmit_frame_buf;
for (i = 0; i < NR_XMITFRAME; i++) {
INIT_LIST_HEAD(&pxframe->list);
@@ -238,7 +238,9 @@ s32 _rtw_init_xmit_priv(struct xmit_priv *pxmitpriv, struct adapter *padapter)
pxmitbuf->padapter = padapter;
pxmitbuf->buf_tag = XMITBUF_CMD;
- res = rtw_os_xmit_resource_alloc(padapter, pxmitbuf, MAX_CMDBUF_SZ+XMITBUF_ALIGN_SZ, true);
+ res = rtw_os_xmit_resource_alloc(padapter, pxmitbuf,
+ MAX_CMDBUF_SZ + XMITBUF_ALIGN_SZ,
+ true);
if (res == _FAIL) {
res = _FAIL;
goto exit;
@@ -248,7 +250,7 @@ s32 _rtw_init_xmit_priv(struct xmit_priv *pxmitpriv, struct adapter *padapter)
pxmitbuf->pend = pxmitbuf->pbuf + MAX_CMDBUF_SZ;
pxmitbuf->len = 0;
pxmitbuf->pdata = pxmitbuf->ptail = pxmitbuf->phead;
- pxmitbuf->alloc_sz = MAX_CMDBUF_SZ+XMITBUF_ALIGN_SZ;
+ pxmitbuf->alloc_sz = MAX_CMDBUF_SZ + XMITBUF_ALIGN_SZ;
}
}
@@ -274,7 +276,7 @@ void _rtw_free_xmit_priv(struct xmit_priv *pxmitpriv)
{
int i;
struct adapter *padapter = pxmitpriv->adapter;
- struct xmit_frame *pxmitframe = (struct xmit_frame *) pxmitpriv->pxmit_frame_buf;
+ struct xmit_frame *pxmitframe = (struct xmit_frame *)pxmitpriv->pxmit_frame_buf;
struct xmit_buf *pxmitbuf = (struct xmit_buf *)pxmitpriv->pxmitbuf;
rtw_hal_free_xmit_priv(padapter);
@@ -321,7 +323,9 @@ void _rtw_free_xmit_priv(struct xmit_priv *pxmitpriv)
for (i = 0; i < CMDBUF_MAX; i++) {
pxmitbuf = &pxmitpriv->pcmd_xmitbuf[i];
if (pxmitbuf)
- rtw_os_xmit_resource_free(padapter, pxmitbuf, MAX_CMDBUF_SZ+XMITBUF_ALIGN_SZ, true);
+ rtw_os_xmit_resource_free(padapter, pxmitbuf,
+ MAX_CMDBUF_SZ + XMITBUF_ALIGN_SZ,
+ true);
}
rtw_free_hwxmits(padapter);
@@ -736,7 +740,7 @@ static s32 update_attrib(struct adapter *padapter, struct sk_buff *pkt, struct p
pattrib->subtype = WIFI_DATA_TYPE;
pattrib->priority = 0;
- if (check_fwstate(pmlmepriv, WIFI_AP_STATE|WIFI_ADHOC_STATE|WIFI_ADHOC_MASTER_STATE)) {
+ if (check_fwstate(pmlmepriv, WIFI_AP_STATE | WIFI_ADHOC_STATE | WIFI_ADHOC_MASTER_STATE)) {
if (pattrib->qos_en)
set_qos(&pktfile, pattrib);
} else {
@@ -787,15 +791,15 @@ static s32 xmitframe_addmic(struct adapter *padapter, struct xmit_frame *pxmitfr
rtw_secmicsetkey(&micdata, &pattrib->dot11tkiptxmickey.skey[0]);
}
- if (pframe[1]&1) { /* ToDS == 1 */
+ if (pframe[1] & 1) { /* ToDS == 1 */
rtw_secmicappend(&micdata, &pframe[16], 6); /* DA */
- if (pframe[1]&2) /* From Ds == 1 */
+ if (pframe[1] & 2) /* From Ds == 1 */
rtw_secmicappend(&micdata, &pframe[24], 6);
else
rtw_secmicappend(&micdata, &pframe[10], 6);
} else { /* ToDS == 0 */
rtw_secmicappend(&micdata, &pframe[4], 6); /* DA */
- if (pframe[1]&2) /* From Ds == 1 */
+ if (pframe[1] & 2) /* From Ds == 1 */
rtw_secmicappend(&micdata, &pframe[16], 6);
else
rtw_secmicappend(&micdata, &pframe[10], 6);
@@ -810,16 +814,20 @@ static s32 xmitframe_addmic(struct adapter *padapter, struct xmit_frame *pxmitfr
for (curfragnum = 0; curfragnum < pattrib->nr_frags; curfragnum++) {
payload = (u8 *)round_up((SIZE_PTR)(payload), 4);
- payload = payload+pattrib->hdrlen+pattrib->iv_len;
+ payload = payload + pattrib->hdrlen + pattrib->iv_len;
- if ((curfragnum+1) == pattrib->nr_frags) {
- length = pattrib->last_txcmdsz-pattrib->hdrlen-pattrib->iv_len-((pattrib->bswenc) ? pattrib->icv_len : 0);
+ if ((curfragnum + 1) == pattrib->nr_frags) {
+ length = pattrib->last_txcmdsz - pattrib->hdrlen -
+ pattrib->iv_len -
+ ((pattrib->bswenc) ? pattrib->icv_len : 0);
rtw_secmicappend(&micdata, payload, length);
- payload = payload+length;
+ payload = payload + length;
} else {
- length = pxmitpriv->frag_len-pattrib->hdrlen-pattrib->iv_len-((pattrib->bswenc) ? pattrib->icv_len : 0);
+ length = pxmitpriv->frag_len - pattrib->hdrlen -
+ pattrib->iv_len -
+ ((pattrib->bswenc) ? pattrib->icv_len : 0);
rtw_secmicappend(&micdata, payload, length);
- payload = payload+length+pattrib->icv_len;
+ payload = payload + length + pattrib->icv_len;
}
}
rtw_secgetmic(&micdata, &mic[0]);
@@ -1108,8 +1116,10 @@ s32 rtw_xmitframe_coalesce(struct adapter *padapter, struct sk_buff *pkt, struct
if (bmcst || (rtw_endofpktfile(&pktfile) == true)) {
pattrib->nr_frags = frg_inx;
- pattrib->last_txcmdsz = pattrib->hdrlen + pattrib->iv_len + ((pattrib->nr_frags == 1) ? llc_sz:0) +
- ((pattrib->bswenc) ? pattrib->icv_len : 0) + mem_sz;
+ pattrib->last_txcmdsz = pattrib->hdrlen + pattrib->iv_len +
+ ((pattrib->nr_frags == 1) ? llc_sz : 0) +
+ ((pattrib->bswenc) ? pattrib->icv_len : 0) +
+ mem_sz;
ClearMFrag(mem_start);
@@ -1158,7 +1168,7 @@ s32 rtw_mgmt_xmitframe_coalesce(struct adapter *padapter, struct sk_buff *pkt, s
mem_start = pframe = (u8 *)(pxmitframe->buf_addr) + TXDESC_OFFSET;
pwlanhdr = (struct ieee80211_hdr *)pframe;
- ori_len = BIP_AAD_SIZE+pattrib->pktlen;
+ ori_len = BIP_AAD_SIZE + pattrib->pktlen;
tmp_buf = BIP_AAD = rtw_zmalloc(ori_len);
subtype = GetFrameSubType(pframe); /* bit(7)~bit(2) */
@@ -1211,14 +1221,14 @@ s32 rtw_mgmt_xmitframe_coalesce(struct adapter *padapter, struct sk_buff *pkt, s
/* conscruct AAD, copy address 1 to address 3 */
memcpy(BIP_AAD + 2, &pwlanhdr->addrs, sizeof(pwlanhdr->addrs));
/* copy management fram body */
- memcpy(BIP_AAD+BIP_AAD_SIZE, MGMT_body, frame_body_len);
+ memcpy(BIP_AAD + BIP_AAD_SIZE, MGMT_body, frame_body_len);
/* calculate mic */
if (omac1_aes_128(padapter->securitypriv.dot11wBIPKey[padapter->securitypriv.dot11wBIPKeyid].skey
- , BIP_AAD, BIP_AAD_SIZE+frame_body_len, mic))
+ , BIP_AAD, BIP_AAD_SIZE + frame_body_len, mic))
goto xmitframe_coalesce_fail;
/* copy right BIP mic value, total is 128bits, we use the 0~63 bits */
- memcpy(pframe-8, mic, 8);
+ memcpy(pframe - 8, mic, 8);
} else { /* unicast mgmt frame TX */
/* start to encrypt mgmt frame */
if (subtype == WIFI_DEAUTH || subtype == WIFI_DISASSOC ||
@@ -1267,9 +1277,10 @@ s32 rtw_mgmt_xmitframe_coalesce(struct adapter *padapter, struct sk_buff *pkt, s
memcpy(pframe, pattrib->iv, pattrib->iv_len);
pframe += pattrib->iv_len;
/* copy mgmt data portion after CCMP header */
- memcpy(pframe, tmp_buf+pattrib->hdrlen, pattrib->pktlen-pattrib->hdrlen);
+ memcpy(pframe, tmp_buf + pattrib->hdrlen,
+ pattrib->pktlen - pattrib->hdrlen);
/* move pframe to end of mgmt pkt */
- pframe += pattrib->pktlen-pattrib->hdrlen;
+ pframe += pattrib->pktlen - pattrib->hdrlen;
/* add 8 bytes CCMP IV header to length */
pattrib->pktlen += pattrib->iv_len;
if ((pattrib->icv_len > 0) && (pattrib->bswenc)) {
@@ -1375,7 +1386,7 @@ void rtw_count_tx_stats(struct adapter *padapter, struct xmit_frame *pxmitframe,
struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
u8 pkt_num = 1;
- if ((pxmitframe->frame_tag&0x0f) == DATA_FRAMETAG) {
+ if ((pxmitframe->frame_tag & 0x0f) == DATA_FRAMETAG) {
pkt_num = pxmitframe->agg_num;
pmlmepriv->LinkDetectInfo.NumTxOkInPeriod += pkt_num;
@@ -2070,7 +2081,7 @@ signed int xmitframe_enqueue_for_sleeping_sta(struct adapter *padapter, struct x
spin_lock_bh(&psta->sleep_q.lock);
- if (psta->state&WIFI_SLEEP_STATE) {
+ if (psta->state & WIFI_SLEEP_STATE) {
u8 wmmps_ac = 0;
if (pstapriv->sta_dz_bitmap & BIT(psta->aid)) {
@@ -2083,20 +2094,20 @@ signed int xmitframe_enqueue_for_sleeping_sta(struct adapter *padapter, struct x
switch (pattrib->priority) {
case 1:
case 2:
- wmmps_ac = psta->uapsd_bk&BIT(0);
+ wmmps_ac = psta->uapsd_bk & BIT(0);
break;
case 4:
case 5:
- wmmps_ac = psta->uapsd_vi&BIT(0);
+ wmmps_ac = psta->uapsd_vi & BIT(0);
break;
case 6:
case 7:
- wmmps_ac = psta->uapsd_vo&BIT(0);
+ wmmps_ac = psta->uapsd_vo & BIT(0);
break;
case 0:
case 3:
default:
- wmmps_ac = psta->uapsd_be&BIT(0);
+ wmmps_ac = psta->uapsd_be & BIT(0);
break;
}
@@ -2214,20 +2225,20 @@ void wakeup_sta_to_xmit(struct adapter *padapter, struct sta_info *psta)
switch (pxmitframe->attrib.priority) {
case 1:
case 2:
- wmmps_ac = psta->uapsd_bk&BIT(1);
+ wmmps_ac = psta->uapsd_bk & BIT(1);
break;
case 4:
case 5:
- wmmps_ac = psta->uapsd_vi&BIT(1);
+ wmmps_ac = psta->uapsd_vi & BIT(1);
break;
case 6:
case 7:
- wmmps_ac = psta->uapsd_vo&BIT(1);
+ wmmps_ac = psta->uapsd_vo & BIT(1);
break;
case 0:
case 3:
default:
- wmmps_ac = psta->uapsd_be&BIT(1);
+ wmmps_ac = psta->uapsd_be & BIT(1);
break;
}
@@ -2259,7 +2270,7 @@ void wakeup_sta_to_xmit(struct adapter *padapter, struct sta_info *psta)
pstapriv->tim_bitmap &= ~BIT(psta->aid);
- if (psta->state&WIFI_SLEEP_STATE)
+ if (psta->state & WIFI_SLEEP_STATE)
psta->state ^= WIFI_SLEEP_STATE;
if (psta->state & WIFI_STA_ALIVE_CHK_STATE) {
@@ -2274,7 +2285,7 @@ void wakeup_sta_to_xmit(struct adapter *padapter, struct sta_info *psta)
if (!psta_bmc)
goto _exit;
- if ((pstapriv->sta_dz_bitmap&0xfffe) == 0x0) { /* no any sta in ps mode */
+ if ((pstapriv->sta_dz_bitmap & 0xfffe) == 0x0) { /* no any sta in ps mode */
xmitframe_phead = get_list_head(&psta_bmc->sleep_q);
list_for_each_safe(xmitframe_plist, tmp, xmitframe_phead) {
pxmitframe = list_entry(xmitframe_plist,
@@ -2327,20 +2338,20 @@ void xmit_delivery_enabled_frames(struct adapter *padapter, struct sta_info *pst
switch (pxmitframe->attrib.priority) {
case 1:
case 2:
- wmmps_ac = psta->uapsd_bk&BIT(1);
+ wmmps_ac = psta->uapsd_bk & BIT(1);
break;
case 4:
case 5:
- wmmps_ac = psta->uapsd_vi&BIT(1);
+ wmmps_ac = psta->uapsd_vi & BIT(1);
break;
case 6:
case 7:
- wmmps_ac = psta->uapsd_vo&BIT(1);
+ wmmps_ac = psta->uapsd_vo & BIT(1);
break;
case 0:
case 3:
default:
- wmmps_ac = psta->uapsd_be&BIT(1);
+ wmmps_ac = psta->uapsd_be & BIT(1);
break;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0444/1518] staging: rtl8723bs: expand multiple assignment into separate statements
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (442 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0443/1518] staging: rtl8723bs: fix operator and type cast spacing Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0445/1518] staging: rtl8723bs: replace rtw_zmalloc() with kzalloc() Greg Kroah-Hartman
` (554 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Nayana Mariyappa, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nayana Mariyappa <nayana.mariyappa@gmail.com>
[ Upstream commit 5080a15d755be4ff72bc92df97475cf69ccf5e58 ]
Split multiple assignments in a single line into separate statements in
osdep_service.c to follow kernel coding style.
No functional change.
Signed-off-by: Nayana Mariyappa <nayana.mariyappa@gmail.com>
Link: https://patch.msgid.link/20260116120511.48272-5-nayana.mariyappa@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Stable-dep-of: 41b8209376df ("staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/staging/rtl8723bs/os_dep/osdep_service.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/staging/rtl8723bs/os_dep/osdep_service.c b/drivers/staging/rtl8723bs/os_dep/osdep_service.c
index a00f9f0c85c5b..19b378b498091 100644
--- a/drivers/staging/rtl8723bs/os_dep/osdep_service.c
+++ b/drivers/staging/rtl8723bs/os_dep/osdep_service.c
@@ -226,7 +226,8 @@ struct rtw_cbuf *rtw_cbuf_alloc(u32 size)
cbuf = rtw_malloc(struct_size(cbuf, bufs, size));
if (cbuf) {
- cbuf->write = cbuf->read = 0;
+ cbuf->write = 0;
+ cbuf->read = 0;
cbuf->size = size;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0445/1518] staging: rtl8723bs: replace rtw_zmalloc() with kzalloc()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (443 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0444/1518] staging: rtl8723bs: expand multiple assignment into separate statements Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0446/1518] staging: rtl8723bs: remove multiple blank lines in core/ Greg Kroah-Hartman
` (553 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Minu Jin, Andy Shevchenko,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Minu Jin <s9430939@naver.com>
[ Upstream commit 980cd426a25747daf8ed25e2a1904b2d26ffbb3d ]
Replace the wrapper function rtw_zmalloc() with standard kzalloc().
Use kzalloc() for rtw_malloc() calls that were followed by manual
zero initialization.
About GFP Flags:
- GFP_ATOMIC is used for allocations in atomic contexts such as
spinlock-protected sections, tasklets, and timer handlers.
- GFP_KERNEL is used for process contexts where sleeping is allowed.
Additionally, use array_size() and size_add() to prevent potential
integer overflows during allocation size calculation.
Signed-off-by: Minu Jin <s9430939@naver.com>
Reviewed-by: Andy Shevchenko <andriy.shevchenko@intel.com>
Link: https://patch.msgid.link/20260204131347.3515949-4-s9430939@naver.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Stable-dep-of: 41b8209376df ("staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/staging/rtl8723bs/core/rtw_ap.c | 8 +-
drivers/staging/rtl8723bs/core/rtw_cmd.c | 81 +++++++++----------
drivers/staging/rtl8723bs/core/rtw_mlme.c | 10 +--
drivers/staging/rtl8723bs/core/rtw_mlme_ext.c | 36 ++++-----
drivers/staging/rtl8723bs/core/rtw_recv.c | 2 +-
drivers/staging/rtl8723bs/core/rtw_security.c | 3 +-
.../staging/rtl8723bs/core/rtw_wlan_util.c | 2 +-
drivers/staging/rtl8723bs/core/rtw_xmit.c | 8 +-
.../staging/rtl8723bs/hal/rtl8723bs_recv.c | 2 +-
drivers/staging/rtl8723bs/hal/sdio_ops.c | 2 +-
.../staging/rtl8723bs/os_dep/ioctl_cfg80211.c | 26 +++---
drivers/staging/rtl8723bs/os_dep/os_intfs.c | 2 +-
.../staging/rtl8723bs/os_dep/osdep_service.c | 9 +--
drivers/staging/rtl8723bs/os_dep/xmit_linux.c | 2 +-
14 files changed, 90 insertions(+), 103 deletions(-)
diff --git a/drivers/staging/rtl8723bs/core/rtw_ap.c b/drivers/staging/rtl8723bs/core/rtw_ap.c
index 0908f2234f671..98405bedf5da7 100644
--- a/drivers/staging/rtl8723bs/core/rtw_ap.c
+++ b/drivers/staging/rtl8723bs/core/rtw_ap.c
@@ -1262,13 +1262,13 @@ u8 rtw_ap_set_pairwise_key(struct adapter *padapter, struct sta_info *psta)
struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
u8 res = _SUCCESS;
- ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
+ ph2c = kzalloc(sizeof(*ph2c), GFP_KERNEL);
if (!ph2c) {
res = _FAIL;
goto exit;
}
- psetstakey_para = rtw_zmalloc(sizeof(struct set_stakey_parm));
+ psetstakey_para = kzalloc(sizeof(*psetstakey_para), GFP_KERNEL);
if (!psetstakey_para) {
kfree(ph2c);
res = _FAIL;
@@ -1304,12 +1304,12 @@ static int rtw_ap_set_key(
struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
int res = _SUCCESS;
- pcmd = rtw_zmalloc(sizeof(struct cmd_obj));
+ pcmd = kzalloc(sizeof(*pcmd), GFP_KERNEL);
if (!pcmd) {
res = _FAIL;
goto exit;
}
- psetkeyparm = rtw_zmalloc(sizeof(struct setkey_parm));
+ psetkeyparm = kzalloc(sizeof(*psetkeyparm), GFP_KERNEL);
if (!psetkeyparm) {
kfree(pcmd);
res = _FAIL;
diff --git a/drivers/staging/rtl8723bs/core/rtw_cmd.c b/drivers/staging/rtl8723bs/core/rtw_cmd.c
index ef2d92b5588ad..0091045f63f24 100644
--- a/drivers/staging/rtl8723bs/core/rtw_cmd.c
+++ b/drivers/staging/rtl8723bs/core/rtw_cmd.c
@@ -170,15 +170,13 @@ int rtw_init_cmd_priv(struct cmd_priv *pcmdpriv)
pcmdpriv->cmd_seq = 1;
- pcmdpriv->cmd_allocated_buf = rtw_zmalloc(MAX_CMDSZ + CMDBUFF_ALIGN_SZ);
-
+ pcmdpriv->cmd_allocated_buf = kzalloc(MAX_CMDSZ + CMDBUFF_ALIGN_SZ, GFP_ATOMIC);
if (!pcmdpriv->cmd_allocated_buf)
return -ENOMEM;
pcmdpriv->cmd_buf = pcmdpriv->cmd_allocated_buf + CMDBUFF_ALIGN_SZ - ((SIZE_PTR)(pcmdpriv->cmd_allocated_buf) & (CMDBUFF_ALIGN_SZ-1));
- pcmdpriv->rsp_allocated_buf = rtw_zmalloc(MAX_RSPSZ + 4);
-
+ pcmdpriv->rsp_allocated_buf = kzalloc(MAX_RSPSZ + 4, GFP_ATOMIC);
if (!pcmdpriv->rsp_allocated_buf) {
kfree(pcmdpriv->cmd_allocated_buf);
return -ENOMEM;
@@ -534,11 +532,11 @@ u8 rtw_sitesurvey_cmd(struct adapter *padapter, struct ndis_802_11_ssid *ssid,
if (check_fwstate(pmlmepriv, _FW_LINKED))
rtw_lps_ctrl_wk_cmd(padapter, LPS_CTRL_SCAN, 1);
- ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
+ ph2c = kzalloc(sizeof(*ph2c), GFP_ATOMIC);
if (!ph2c)
return _FAIL;
- psurveyPara = rtw_zmalloc(sizeof(struct sitesurvey_parm));
+ psurveyPara = kzalloc(sizeof(*psurveyPara), GFP_ATOMIC);
if (!psurveyPara) {
kfree(ph2c);
return _FAIL;
@@ -602,7 +600,7 @@ u8 rtw_createbss_cmd(struct adapter *padapter)
struct wlan_bssid_ex *pdev_network = &padapter->registrypriv.dev_network;
u8 res = _SUCCESS;
- pcmd = rtw_zmalloc(sizeof(struct cmd_obj));
+ pcmd = kzalloc(sizeof(*pcmd), GFP_ATOMIC);
if (!pcmd) {
res = _FAIL;
goto exit;
@@ -635,7 +633,7 @@ int rtw_startbss_cmd(struct adapter *padapter, int flags)
start_bss_network(padapter);
} else {
/* need enqueue, prepare cmd_obj and enqueue */
- pcmd = rtw_zmalloc(sizeof(struct cmd_obj));
+ pcmd = kzalloc(sizeof(*pcmd), GFP_KERNEL);
if (!pcmd) {
res = _FAIL;
goto exit;
@@ -687,7 +685,7 @@ u8 rtw_joinbss_cmd(struct adapter *padapter, struct wlan_network *pnetwork)
u32 tmp_len;
u8 *ptmp = NULL;
- pcmd = rtw_zmalloc(sizeof(struct cmd_obj));
+ pcmd = kzalloc(sizeof(*pcmd), GFP_KERNEL);
if (!pcmd) {
res = _FAIL;
goto exit;
@@ -796,7 +794,7 @@ u8 rtw_disassoc_cmd(struct adapter *padapter, u32 deauth_timeout_ms, bool enqueu
u8 res = _SUCCESS;
/* prepare cmd parameter */
- param = rtw_zmalloc(sizeof(*param));
+ param = kzalloc(sizeof(*param), GFP_KERNEL);
if (!param) {
res = _FAIL;
goto exit;
@@ -805,7 +803,7 @@ u8 rtw_disassoc_cmd(struct adapter *padapter, u32 deauth_timeout_ms, bool enqueu
if (enqueue) {
/* need enqueue, prepare cmd_obj and enqueue */
- cmdobj = rtw_zmalloc(sizeof(*cmdobj));
+ cmdobj = kzalloc(sizeof(*cmdobj), GFP_KERNEL);
if (!cmdobj) {
res = _FAIL;
kfree(param);
@@ -832,8 +830,7 @@ u8 rtw_setopmode_cmd(struct adapter *padapter, enum ndis_802_11_network_infrast
struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
u8 res = _SUCCESS;
- psetop = rtw_zmalloc(sizeof(struct setopmode_parm));
-
+ psetop = kzalloc(sizeof(*psetop), GFP_KERNEL);
if (!psetop) {
res = _FAIL;
goto exit;
@@ -841,7 +838,7 @@ u8 rtw_setopmode_cmd(struct adapter *padapter, enum ndis_802_11_network_infrast
psetop->mode = (u8)networktype;
if (enqueue) {
- ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
+ ph2c = kzalloc(sizeof(*ph2c), GFP_KERNEL);
if (!ph2c) {
kfree(psetop);
res = _FAIL;
@@ -868,7 +865,7 @@ u8 rtw_setstakey_cmd(struct adapter *padapter, struct sta_info *sta, u8 unicast_
struct security_priv *psecuritypriv = &padapter->securitypriv;
u8 res = _SUCCESS;
- psetstakey_para = rtw_zmalloc(sizeof(struct set_stakey_parm));
+ psetstakey_para = kzalloc(sizeof(*psetstakey_para), GFP_KERNEL);
if (!psetstakey_para) {
res = _FAIL;
goto exit;
@@ -890,14 +887,14 @@ u8 rtw_setstakey_cmd(struct adapter *padapter, struct sta_info *sta, u8 unicast_
padapter->securitypriv.busetkipkey = true;
if (enqueue) {
- ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
+ ph2c = kzalloc(sizeof(*ph2c), GFP_KERNEL);
if (!ph2c) {
kfree(psetstakey_para);
res = _FAIL;
goto exit;
}
- psetstakey_rsp = rtw_zmalloc(sizeof(struct set_stakey_rsp));
+ psetstakey_rsp = kzalloc(sizeof(*psetstakey_rsp), GFP_KERNEL);
if (!psetstakey_rsp) {
kfree(ph2c);
kfree(psetstakey_para);
@@ -935,20 +932,20 @@ u8 rtw_clearstakey_cmd(struct adapter *padapter, struct sta_info *sta, u8 enqueu
rtw_camid_free(padapter, cam_id);
}
} else {
- ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
+ ph2c = kzalloc(sizeof(*ph2c), GFP_KERNEL);
if (!ph2c) {
res = _FAIL;
goto exit;
}
- psetstakey_para = rtw_zmalloc(sizeof(struct set_stakey_parm));
+ psetstakey_para = kzalloc(sizeof(*psetstakey_para), GFP_KERNEL);
if (!psetstakey_para) {
kfree(ph2c);
res = _FAIL;
goto exit;
}
- psetstakey_rsp = rtw_zmalloc(sizeof(struct set_stakey_rsp));
+ psetstakey_rsp = kzalloc(sizeof(*psetstakey_rsp), GFP_KERNEL);
if (!psetstakey_rsp) {
kfree(ph2c);
kfree(psetstakey_para);
@@ -978,13 +975,13 @@ u8 rtw_addbareq_cmd(struct adapter *padapter, u8 tid, u8 *addr)
u8 res = _SUCCESS;
- ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
+ ph2c = kzalloc(sizeof(*ph2c), GFP_ATOMIC);
if (!ph2c) {
res = _FAIL;
goto exit;
}
- paddbareq_parm = rtw_zmalloc(sizeof(struct addBaReq_parm));
+ paddbareq_parm = kzalloc(sizeof(*paddbareq_parm), GFP_ATOMIC);
if (!paddbareq_parm) {
kfree(ph2c);
res = _FAIL;
@@ -1010,13 +1007,13 @@ u8 rtw_reset_securitypriv_cmd(struct adapter *padapter)
struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
u8 res = _SUCCESS;
- ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
+ ph2c = kzalloc(sizeof(*ph2c), GFP_ATOMIC);
if (!ph2c) {
res = _FAIL;
goto exit;
}
- pdrvextra_cmd_parm = rtw_zmalloc(sizeof(struct drvextra_cmd_parm));
+ pdrvextra_cmd_parm = kzalloc(sizeof(*pdrvextra_cmd_parm), GFP_ATOMIC);
if (!pdrvextra_cmd_parm) {
kfree(ph2c);
res = _FAIL;
@@ -1043,13 +1040,13 @@ u8 rtw_free_assoc_resources_cmd(struct adapter *padapter)
struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
u8 res = _SUCCESS;
- ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
+ ph2c = kzalloc(sizeof(*ph2c), GFP_ATOMIC);
if (!ph2c) {
res = _FAIL;
goto exit;
}
- pdrvextra_cmd_parm = rtw_zmalloc(sizeof(struct drvextra_cmd_parm));
+ pdrvextra_cmd_parm = kzalloc(sizeof(*pdrvextra_cmd_parm), GFP_ATOMIC);
if (!pdrvextra_cmd_parm) {
kfree(ph2c);
res = _FAIL;
@@ -1077,13 +1074,13 @@ u8 rtw_dynamic_chk_wk_cmd(struct adapter *padapter)
u8 res = _SUCCESS;
/* only primary padapter does this cmd */
- ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
+ ph2c = kzalloc(sizeof(*ph2c), GFP_ATOMIC);
if (!ph2c) {
res = _FAIL;
goto exit;
}
- pdrvextra_cmd_parm = rtw_zmalloc(sizeof(struct drvextra_cmd_parm));
+ pdrvextra_cmd_parm = kzalloc(sizeof(*pdrvextra_cmd_parm), GFP_ATOMIC);
if (!pdrvextra_cmd_parm) {
kfree(ph2c);
res = _FAIL;
@@ -1318,13 +1315,13 @@ u8 rtw_lps_ctrl_wk_cmd(struct adapter *padapter, u8 lps_ctrl_type, u8 enqueue)
u8 res = _SUCCESS;
if (enqueue) {
- ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
+ ph2c = kzalloc(sizeof(*ph2c), GFP_ATOMIC);
if (!ph2c) {
res = _FAIL;
goto exit;
}
- pdrvextra_cmd_parm = rtw_zmalloc(sizeof(struct drvextra_cmd_parm));
+ pdrvextra_cmd_parm = kzalloc(sizeof(*pdrvextra_cmd_parm), GFP_ATOMIC);
if (!pdrvextra_cmd_parm) {
kfree(ph2c);
res = _FAIL;
@@ -1359,13 +1356,13 @@ u8 rtw_dm_in_lps_wk_cmd(struct adapter *padapter)
struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
u8 res = _SUCCESS;
- ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
+ ph2c = kzalloc(sizeof(*ph2c), GFP_ATOMIC);
if (!ph2c) {
res = _FAIL;
goto exit;
}
- pdrvextra_cmd_parm = rtw_zmalloc(sizeof(struct drvextra_cmd_parm));
+ pdrvextra_cmd_parm = kzalloc(sizeof(*pdrvextra_cmd_parm), GFP_ATOMIC);
if (!pdrvextra_cmd_parm) {
kfree(ph2c);
res = _FAIL;
@@ -1421,13 +1418,13 @@ u8 rtw_dm_ra_mask_wk_cmd(struct adapter *padapter, u8 *psta)
struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
u8 res = _SUCCESS;
- ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
+ ph2c = kzalloc(sizeof(*ph2c), GFP_ATOMIC);
if (!ph2c) {
res = _FAIL;
goto exit;
}
- pdrvextra_cmd_parm = rtw_zmalloc(sizeof(struct drvextra_cmd_parm));
+ pdrvextra_cmd_parm = kzalloc(sizeof(*pdrvextra_cmd_parm), GFP_ATOMIC);
if (!pdrvextra_cmd_parm) {
kfree(ph2c);
res = _FAIL;
@@ -1456,13 +1453,13 @@ u8 rtw_ps_cmd(struct adapter *padapter)
struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
u8 res = _SUCCESS;
- ppscmd = rtw_zmalloc(sizeof(struct cmd_obj));
+ ppscmd = kzalloc(sizeof(*ppscmd), GFP_ATOMIC);
if (!ppscmd) {
res = _FAIL;
goto exit;
}
- pdrvextra_cmd_parm = rtw_zmalloc(sizeof(struct drvextra_cmd_parm));
+ pdrvextra_cmd_parm = kzalloc(sizeof(*pdrvextra_cmd_parm), GFP_ATOMIC);
if (!pdrvextra_cmd_parm) {
kfree(ppscmd);
res = _FAIL;
@@ -1528,13 +1525,13 @@ u8 rtw_chk_hi_queue_cmd(struct adapter *padapter)
struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
u8 res = _SUCCESS;
- ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
+ ph2c = kzalloc(sizeof(*ph2c), GFP_ATOMIC);
if (!ph2c) {
res = _FAIL;
goto exit;
}
- pdrvextra_cmd_parm = rtw_zmalloc(sizeof(struct drvextra_cmd_parm));
+ pdrvextra_cmd_parm = kzalloc(sizeof(*pdrvextra_cmd_parm), GFP_ATOMIC);
if (!pdrvextra_cmd_parm) {
kfree(ph2c);
res = _FAIL;
@@ -1620,13 +1617,13 @@ u8 rtw_c2h_packet_wk_cmd(struct adapter *padapter, u8 *pbuf, u16 length)
struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
u8 res = _SUCCESS;
- ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
+ ph2c = kzalloc(sizeof(*ph2c), GFP_ATOMIC);
if (!ph2c) {
res = _FAIL;
goto exit;
}
- pdrvextra_cmd_parm = rtw_zmalloc(sizeof(struct drvextra_cmd_parm));
+ pdrvextra_cmd_parm = kzalloc(sizeof(*pdrvextra_cmd_parm), GFP_ATOMIC);
if (!pdrvextra_cmd_parm) {
kfree(ph2c);
res = _FAIL;
@@ -1655,13 +1652,13 @@ u8 rtw_c2h_wk_cmd(struct adapter *padapter, u8 *c2h_evt)
struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
u8 res = _SUCCESS;
- ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
+ ph2c = kzalloc(sizeof(*ph2c), GFP_KERNEL);
if (!ph2c) {
res = _FAIL;
goto exit;
}
- pdrvextra_cmd_parm = rtw_zmalloc(sizeof(struct drvextra_cmd_parm));
+ pdrvextra_cmd_parm = kzalloc(sizeof(*pdrvextra_cmd_parm), GFP_KERNEL);
if (!pdrvextra_cmd_parm) {
kfree(ph2c);
res = _FAIL;
diff --git a/drivers/staging/rtl8723bs/core/rtw_mlme.c b/drivers/staging/rtl8723bs/core/rtw_mlme.c
index 28cdeed06a8e9..91cd99c835b2d 100644
--- a/drivers/staging/rtl8723bs/core/rtw_mlme.c
+++ b/drivers/staging/rtl8723bs/core/rtw_mlme.c
@@ -1901,13 +1901,13 @@ signed int rtw_set_auth(struct adapter *adapter, struct security_priv *psecurity
struct cmd_priv *pcmdpriv = &adapter->cmdpriv;
signed int res = _SUCCESS;
- pcmd = rtw_zmalloc(sizeof(struct cmd_obj));
+ pcmd = kzalloc(sizeof(*pcmd), GFP_KERNEL);
if (!pcmd) {
res = _FAIL; /* try again */
goto exit;
}
- psetauthparm = rtw_zmalloc(sizeof(struct setauth_parm));
+ psetauthparm = kzalloc(sizeof(*psetauthparm), GFP_KERNEL);
if (!psetauthparm) {
kfree(pcmd);
res = _FAIL;
@@ -1938,7 +1938,7 @@ signed int rtw_set_key(struct adapter *adapter, struct security_priv *psecurityp
struct cmd_priv *pcmdpriv = &adapter->cmdpriv;
signed int res = _SUCCESS;
- psetkeyparm = rtw_zmalloc(sizeof(struct setkey_parm));
+ psetkeyparm = kzalloc(sizeof(*psetkeyparm), GFP_KERNEL);
if (!psetkeyparm) {
res = _FAIL;
goto exit;
@@ -1980,7 +1980,7 @@ signed int rtw_set_key(struct adapter *adapter, struct security_priv *psecurityp
}
if (enqueue) {
- pcmd = rtw_zmalloc(sizeof(struct cmd_obj));
+ pcmd = kzalloc(sizeof(*pcmd), GFP_KERNEL);
if (!pcmd) {
kfree(psetkeyparm);
res = _FAIL; /* try again */
@@ -2093,7 +2093,7 @@ static void rtw_report_sec_ie(struct adapter *adapter, u8 authmode, u8 *sec_ie)
buff = NULL;
if (authmode == WLAN_EID_VENDOR_SPECIFIC) {
- buff = rtw_zmalloc(IW_CUSTOM_MAX);
+ buff = kzalloc(IW_CUSTOM_MAX, GFP_ATOMIC);
if (!buff)
return;
diff --git a/drivers/staging/rtl8723bs/core/rtw_mlme_ext.c b/drivers/staging/rtl8723bs/core/rtw_mlme_ext.c
index 9c991ef20d219..abd26ac3787a3 100644
--- a/drivers/staging/rtl8723bs/core/rtw_mlme_ext.c
+++ b/drivers/staging/rtl8723bs/core/rtw_mlme_ext.c
@@ -2376,7 +2376,7 @@ void issue_probersp(struct adapter *padapter, unsigned char *da, u8 is_valid_p2p
u8 *buf;
u8 *ies = pmgntframe->buf_addr+TXDESC_OFFSET+sizeof(struct ieee80211_hdr_3addr);
- buf = rtw_zmalloc(MAX_IE_SZ);
+ buf = kzalloc(MAX_IE_SZ, GFP_ATOMIC);
if (!buf)
return;
@@ -4435,12 +4435,12 @@ void report_survey_event(struct adapter *padapter, union recv_frame *precv_frame
pmlmeext = &padapter->mlmeextpriv;
pcmdpriv = &padapter->cmdpriv;
- pcmd_obj = rtw_zmalloc(sizeof(struct cmd_obj));
+ pcmd_obj = kzalloc(sizeof(*pcmd_obj), GFP_ATOMIC);
if (!pcmd_obj)
return;
cmdsz = (sizeof(struct survey_event) + sizeof(struct C2HEvent_Header));
- pevtcmd = rtw_zmalloc(cmdsz);
+ pevtcmd = kzalloc(cmdsz, GFP_ATOMIC);
if (!pevtcmd) {
kfree(pcmd_obj);
return;
@@ -4488,12 +4488,12 @@ void report_surveydone_event(struct adapter *padapter)
struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
- pcmd_obj = rtw_zmalloc(sizeof(struct cmd_obj));
+ pcmd_obj = kzalloc(sizeof(*pcmd_obj), GFP_ATOMIC);
if (!pcmd_obj)
return;
cmdsz = (sizeof(struct surveydone_event) + sizeof(struct C2HEvent_Header));
- pevtcmd = rtw_zmalloc(cmdsz);
+ pevtcmd = kzalloc(cmdsz, GFP_ATOMIC);
if (!pevtcmd) {
kfree(pcmd_obj);
return;
@@ -4533,12 +4533,12 @@ void report_join_res(struct adapter *padapter, int res)
struct mlme_ext_info *pmlmeinfo = &(pmlmeext->mlmext_info);
struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
- pcmd_obj = rtw_zmalloc(sizeof(struct cmd_obj));
+ pcmd_obj = kzalloc(sizeof(*pcmd_obj), GFP_ATOMIC);
if (!pcmd_obj)
return;
cmdsz = (sizeof(struct joinbss_event) + sizeof(struct C2HEvent_Header));
- pevtcmd = rtw_zmalloc(cmdsz);
+ pevtcmd = kzalloc(cmdsz, GFP_ATOMIC);
if (!pevtcmd) {
kfree(pcmd_obj);
return;
@@ -4582,12 +4582,12 @@ void report_wmm_edca_update(struct adapter *padapter)
struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
- pcmd_obj = rtw_zmalloc(sizeof(struct cmd_obj));
+ pcmd_obj = kzalloc(sizeof(*pcmd_obj), GFP_ATOMIC);
if (!pcmd_obj)
return;
cmdsz = (sizeof(struct wmm_event) + sizeof(struct C2HEvent_Header));
- pevtcmd = rtw_zmalloc(cmdsz);
+ pevtcmd = kzalloc(cmdsz, GFP_ATOMIC);
if (!pevtcmd) {
kfree(pcmd_obj);
return;
@@ -4628,12 +4628,12 @@ void report_del_sta_event(struct adapter *padapter, unsigned char *MacAddr, unsi
struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
- pcmd_obj = rtw_zmalloc(sizeof(struct cmd_obj));
+ pcmd_obj = kzalloc(sizeof(*pcmd_obj), GFP_ATOMIC);
if (!pcmd_obj)
return;
cmdsz = (sizeof(struct stadel_event) + sizeof(struct C2HEvent_Header));
- pevtcmd = rtw_zmalloc(cmdsz);
+ pevtcmd = kzalloc(cmdsz, GFP_ATOMIC);
if (!pevtcmd) {
kfree(pcmd_obj);
return;
@@ -4679,12 +4679,12 @@ void report_add_sta_event(struct adapter *padapter, unsigned char *MacAddr, int
struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
struct cmd_priv *pcmdpriv = &padapter->cmdpriv;
- pcmd_obj = rtw_zmalloc(sizeof(struct cmd_obj));
+ pcmd_obj = kzalloc(sizeof(*pcmd_obj), GFP_ATOMIC);
if (!pcmd_obj)
return;
cmdsz = (sizeof(struct stassoc_event) + sizeof(struct C2HEvent_Header));
- pevtcmd = rtw_zmalloc(cmdsz);
+ pevtcmd = kzalloc(cmdsz, GFP_ATOMIC);
if (!pevtcmd) {
kfree(pcmd_obj);
return;
@@ -5130,11 +5130,11 @@ void survey_timer_hdl(struct timer_list *t)
pmlmeext->scan_abort = false;/* reset */
}
- ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
+ ph2c = kzalloc(sizeof(*ph2c), GFP_ATOMIC);
if (!ph2c)
return;
- psurveyPara = rtw_zmalloc(sizeof(struct sitesurvey_parm));
+ psurveyPara = kzalloc(sizeof(*psurveyPara), GFP_ATOMIC);
if (!psurveyPara) {
kfree(ph2c);
return;
@@ -5748,7 +5748,7 @@ u8 chk_bmc_sleepq_cmd(struct adapter *padapter)
struct cmd_priv *pcmdpriv = &(padapter->cmdpriv);
u8 res = _SUCCESS;
- ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
+ ph2c = kzalloc(sizeof(*ph2c), GFP_ATOMIC);
if (!ph2c) {
res = _FAIL;
goto exit;
@@ -5772,13 +5772,13 @@ u8 set_tx_beacon_cmd(struct adapter *padapter)
u8 res = _SUCCESS;
int len_diff = 0;
- ph2c = rtw_zmalloc(sizeof(struct cmd_obj));
+ ph2c = kzalloc(sizeof(*ph2c), GFP_ATOMIC);
if (!ph2c) {
res = _FAIL;
goto exit;
}
- ptxBeacon_parm = rtw_zmalloc(sizeof(struct Tx_Beacon_param));
+ ptxBeacon_parm = kzalloc(sizeof(*ptxBeacon_parm), GFP_ATOMIC);
if (!ptxBeacon_parm) {
kfree(ph2c);
res = _FAIL;
diff --git a/drivers/staging/rtl8723bs/core/rtw_recv.c b/drivers/staging/rtl8723bs/core/rtw_recv.c
index e893cb6fa2732..c0dbe4db44c39 100644
--- a/drivers/staging/rtl8723bs/core/rtw_recv.c
+++ b/drivers/staging/rtl8723bs/core/rtw_recv.c
@@ -1425,7 +1425,7 @@ static signed int validate_80211w_mgmt(struct adapter *adapter, union recv_frame
memcpy(pattrib->ta, GetAddr2Ptr(ptr), ETH_ALEN);
/* actual management data frame body */
data_len = pattrib->pkt_len - pattrib->hdrlen - pattrib->iv_len - pattrib->icv_len;
- mgmt_DATA = rtw_zmalloc(data_len);
+ mgmt_DATA = kzalloc(data_len, GFP_ATOMIC);
if (!mgmt_DATA)
goto validate_80211w_fail;
precv_frame = decryptor(adapter, precv_frame);
diff --git a/drivers/staging/rtl8723bs/core/rtw_security.c b/drivers/staging/rtl8723bs/core/rtw_security.c
index fa952ff1beedc..6b5c9831af020 100644
--- a/drivers/staging/rtl8723bs/core/rtw_security.c
+++ b/drivers/staging/rtl8723bs/core/rtw_security.c
@@ -1324,8 +1324,7 @@ u32 rtw_BIP_verify(struct adapter *padapter, u8 *precvframe)
__le64 le_tmp64 = 0;
ori_len = pattrib->pkt_len - WLAN_HDR_A3_LEN + BIP_AAD_SIZE;
- BIP_AAD = rtw_zmalloc(ori_len);
-
+ BIP_AAD = kzalloc(ori_len, GFP_KERNEL);
if (!BIP_AAD)
return _FAIL;
diff --git a/drivers/staging/rtl8723bs/core/rtw_wlan_util.c b/drivers/staging/rtl8723bs/core/rtw_wlan_util.c
index 671b5a01aa72a..82624e46fbf59 100644
--- a/drivers/staging/rtl8723bs/core/rtw_wlan_util.c
+++ b/drivers/staging/rtl8723bs/core/rtw_wlan_util.c
@@ -1136,7 +1136,7 @@ int rtw_check_bcn_info(struct adapter *Adapter, u8 *pframe, u32 packet_len)
if (memcmp(cur_network->network.mac_address, pbssid, 6))
return true;
- bssid = rtw_zmalloc(sizeof(struct wlan_bssid_ex));
+ bssid = kzalloc(sizeof(*bssid), GFP_KERNEL);
if (!bssid)
return true;
diff --git a/drivers/staging/rtl8723bs/core/rtw_xmit.c b/drivers/staging/rtl8723bs/core/rtw_xmit.c
index bbc42db1c8284..c9e0b91d75d3e 100644
--- a/drivers/staging/rtl8723bs/core/rtw_xmit.c
+++ b/drivers/staging/rtl8723bs/core/rtw_xmit.c
@@ -1169,7 +1169,7 @@ s32 rtw_mgmt_xmitframe_coalesce(struct adapter *padapter, struct sk_buff *pkt, s
pwlanhdr = (struct ieee80211_hdr *)pframe;
ori_len = BIP_AAD_SIZE + pattrib->pktlen;
- tmp_buf = BIP_AAD = rtw_zmalloc(ori_len);
+ tmp_buf = BIP_AAD = kzalloc(ori_len, GFP_ATOMIC);
subtype = GetFrameSubType(pframe); /* bit(7)~bit(2) */
if (!BIP_AAD)
@@ -1673,8 +1673,7 @@ struct xmit_frame *rtw_alloc_xmitframe_once(struct xmit_priv *pxmitpriv)
struct xmit_frame *pxframe = NULL;
u8 *alloc_addr;
- alloc_addr = rtw_zmalloc(sizeof(struct xmit_frame) + 4);
-
+ alloc_addr = kzalloc(sizeof(*pxframe) + 4, GFP_ATOMIC);
if (!alloc_addr)
goto exit;
@@ -1847,8 +1846,7 @@ s32 rtw_alloc_hwxmits(struct adapter *padapter)
pxmitpriv->hwxmits = NULL;
- pxmitpriv->hwxmits = rtw_zmalloc(sizeof(struct hw_xmit) * pxmitpriv->hwxmit_entry);
-
+ pxmitpriv->hwxmits = kcalloc(pxmitpriv->hwxmit_entry, sizeof(*hwxmits), GFP_ATOMIC);
if (!pxmitpriv->hwxmits)
return _FAIL;
diff --git a/drivers/staging/rtl8723bs/hal/rtl8723bs_recv.c b/drivers/staging/rtl8723bs/hal/rtl8723bs_recv.c
index 399edfbf8ec6d..ca3fa3e399c94 100644
--- a/drivers/staging/rtl8723bs/hal/rtl8723bs_recv.c
+++ b/drivers/staging/rtl8723bs/hal/rtl8723bs_recv.c
@@ -382,7 +382,7 @@ s32 rtl8723bs_init_recv_priv(struct adapter *padapter)
spin_lock_init(&precvpriv->recv_buf_pending_queue.lock);
n = NR_RECVBUFF * sizeof(struct recv_buf) + 4;
- precvpriv->pallocated_recv_buf = rtw_zmalloc(n);
+ precvpriv->pallocated_recv_buf = kzalloc(n, GFP_KERNEL);
if (!precvpriv->pallocated_recv_buf) {
res = _FAIL;
goto exit;
diff --git a/drivers/staging/rtl8723bs/hal/sdio_ops.c b/drivers/staging/rtl8723bs/hal/sdio_ops.c
index 8736c124f8574..54228c41579ee 100644
--- a/drivers/staging/rtl8723bs/hal/sdio_ops.c
+++ b/drivers/staging/rtl8723bs/hal/sdio_ops.c
@@ -895,7 +895,7 @@ void sd_int_dpc(struct adapter *adapter)
if (hal->sdio_hisr & SDIO_HISR_C2HCMD) {
struct c2h_evt_hdr_88xx *c2h_evt;
- c2h_evt = rtw_zmalloc(16);
+ c2h_evt = kzalloc(16, GFP_ATOMIC);
if (c2h_evt) {
if (c2h_evt_read_88xx(adapter, (u8 *)c2h_evt) == _SUCCESS) {
if (c2h_id_filter_ccx_8723b((u8 *)c2h_evt)) {
diff --git a/drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c b/drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c
index cc898131f5d06..06bf5d176e7d6 100644
--- a/drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c
+++ b/drivers/staging/rtl8723bs/os_dep/ioctl_cfg80211.c
@@ -111,6 +111,7 @@ static struct ieee80211_supported_band *rtw_spt_band_alloc(
{
struct ieee80211_supported_band *spt_band = NULL;
int n_channels, n_bitrates;
+ size_t alloc_sz;
if (band == NL80211_BAND_2GHZ) {
n_channels = RTW_2G_CHANNELS_NUM;
@@ -119,9 +120,10 @@ static struct ieee80211_supported_band *rtw_spt_band_alloc(
goto exit;
}
- spt_band = rtw_zmalloc(sizeof(struct ieee80211_supported_band) +
- sizeof(struct ieee80211_channel) * n_channels +
- sizeof(struct ieee80211_rate) * n_bitrates);
+ alloc_sz = sizeof(*spt_band);
+ alloc_sz = size_add(alloc_sz, array_size(n_channels, sizeof(struct ieee80211_channel)));
+ alloc_sz = size_add(alloc_sz, array_size(n_bitrates, sizeof(struct ieee80211_rate)));
+ spt_band = kzalloc(alloc_sz, GFP_KERNEL);
if (!spt_band)
goto exit;
@@ -841,11 +843,9 @@ static int cfg80211_rtw_add_key(struct wiphy *wiphy, struct net_device *ndev,
struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
param_len = sizeof(struct ieee_param) + params->key_len;
- param = rtw_malloc(param_len);
+ param = kzalloc(param_len, GFP_KERNEL);
if (!param)
- return -1;
-
- memset(param, 0, param_len);
+ return -ENOMEM;
param->cmd = IEEE_CMD_SET_ENCRYPTION;
eth_broadcast_addr(param->sta_addr);
@@ -1431,7 +1431,7 @@ static int rtw_cfg80211_set_wpa_ie(struct adapter *padapter, u8 *pie, size_t iel
goto exit;
}
- buf = rtw_zmalloc(ielen);
+ buf = kzalloc(ielen, GFP_KERNEL);
if (!buf) {
ret = -ENOMEM;
goto exit;
@@ -1723,14 +1723,12 @@ static int cfg80211_rtw_connect(struct wiphy *wiphy, struct net_device *ndev,
wep_key_len = wep_key_len <= 5 ? 5 : 13;
wep_total_len = wep_key_len +
offsetof(struct ndis_802_11_wep, key_material);
- pwep = rtw_malloc(wep_total_len);
+ pwep = kzalloc(wep_total_len, GFP_KERNEL);
if (!pwep) {
ret = -ENOMEM;
goto exit;
}
- memset(pwep, 0, wep_total_len);
-
pwep->key_length = wep_key_len;
pwep->length = wep_total_len;
@@ -2160,7 +2158,7 @@ static int rtw_cfg80211_add_monitor_if(struct adapter *padapter, char *name, str
pnpi->sizeof_priv = sizeof(struct adapter);
/* wdev */
- mon_wdev = rtw_zmalloc(sizeof(struct wireless_dev));
+ mon_wdev = kzalloc(sizeof(*mon_wdev), GFP_KERNEL);
if (!mon_wdev) {
ret = -ENOMEM;
goto out;
@@ -2270,7 +2268,7 @@ static int rtw_add_beacon(struct adapter *adapter, const u8 *head, size_t head_l
if (head_len < 24)
return -EINVAL;
- pbuf = rtw_zmalloc(head_len + tail_len);
+ pbuf = kzalloc(head_len + tail_len, GFP_KERNEL);
if (!pbuf)
return -ENOMEM;
@@ -2741,7 +2739,7 @@ int rtw_wdev_alloc(struct adapter *padapter, struct device *dev)
goto free_wiphy;
/* wdev */
- wdev = rtw_zmalloc(sizeof(struct wireless_dev));
+ wdev = kzalloc(sizeof(*wdev), GFP_KERNEL);
if (!wdev) {
ret = -ENOMEM;
goto unregister_wiphy;
diff --git a/drivers/staging/rtl8723bs/os_dep/os_intfs.c b/drivers/staging/rtl8723bs/os_dep/os_intfs.c
index 6ca6dc5488057..9f7f6b40093c8 100644
--- a/drivers/staging/rtl8723bs/os_dep/os_intfs.c
+++ b/drivers/staging/rtl8723bs/os_dep/os_intfs.c
@@ -560,7 +560,7 @@ struct dvobj_priv *devobj_init(void)
{
struct dvobj_priv *pdvobj = NULL;
- pdvobj = rtw_zmalloc(sizeof(*pdvobj));
+ pdvobj = kzalloc(sizeof(*pdvobj), GFP_KERNEL);
if (!pdvobj)
return NULL;
diff --git a/drivers/staging/rtl8723bs/os_dep/osdep_service.c b/drivers/staging/rtl8723bs/os_dep/osdep_service.c
index 19b378b498091..24467d353bafb 100644
--- a/drivers/staging/rtl8723bs/os_dep/osdep_service.c
+++ b/drivers/staging/rtl8723bs/os_dep/osdep_service.c
@@ -223,13 +223,8 @@ struct rtw_cbuf *rtw_cbuf_alloc(u32 size)
{
struct rtw_cbuf *cbuf;
- cbuf = rtw_malloc(struct_size(cbuf, bufs, size));
-
- if (cbuf) {
- cbuf->write = 0;
- cbuf->read = 0;
- cbuf->size = size;
- }
+ cbuf = kzalloc(struct_size(cbuf, bufs, size), GFP_KERNEL);
+ cbuf->size = size;
return cbuf;
}
diff --git a/drivers/staging/rtl8723bs/os_dep/xmit_linux.c b/drivers/staging/rtl8723bs/os_dep/xmit_linux.c
index 944b9c724b32e..20d2926a4480a 100644
--- a/drivers/staging/rtl8723bs/os_dep/xmit_linux.c
+++ b/drivers/staging/rtl8723bs/os_dep/xmit_linux.c
@@ -46,7 +46,7 @@ signed int rtw_endofpktfile(struct pkt_file *pfile)
int rtw_os_xmit_resource_alloc(struct adapter *padapter, struct xmit_buf *pxmitbuf, u32 alloc_sz, u8 flag)
{
if (alloc_sz > 0) {
- pxmitbuf->pallocated_buf = rtw_zmalloc(alloc_sz);
+ pxmitbuf->pallocated_buf = kzalloc(alloc_sz, GFP_KERNEL);
if (!pxmitbuf->pallocated_buf)
return _FAIL;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0446/1518] staging: rtl8723bs: remove multiple blank lines in core/
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (444 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0445/1518] staging: rtl8723bs: replace rtw_zmalloc() with kzalloc() Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0447/1518] staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths Greg Kroah-Hartman
` (552 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mohammed Rizwan Kaniyate, Luka Gejak,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mohammed Rizwan Kaniyate <mrizwank004@gmail.com>
[ Upstream commit 7dbc9fd714387388ebe049a619513e60b5c442e8 ]
Remove multiple consecutive blank lines.
Issue reported by checkpatch.pl
Signed-off-by: Mohammed Rizwan Kaniyate <mrizwank004@gmail.com>
Reviewed-by: Luka Gejak <luka.gejak@linux.dev>
Link: https://patch.msgid.link/20260425112327.215355-1-mrizwank004@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Stable-dep-of: 41b8209376df ("staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/staging/rtl8723bs/core/rtw_efuse.c | 1 -
.../staging/rtl8723bs/core/rtw_ioctl_set.c | 1 -
drivers/staging/rtl8723bs/core/rtw_mlme_ext.c | 48 -------------------
drivers/staging/rtl8723bs/core/rtw_recv.c | 25 ----------
.../staging/rtl8723bs/core/rtw_wlan_util.c | 1 -
5 files changed, 76 deletions(-)
diff --git a/drivers/staging/rtl8723bs/core/rtw_efuse.c b/drivers/staging/rtl8723bs/core/rtw_efuse.c
index d5c53b614f616..62a40d4672d3f 100644
--- a/drivers/staging/rtl8723bs/core/rtw_efuse.c
+++ b/drivers/staging/rtl8723bs/core/rtw_efuse.c
@@ -253,7 +253,6 @@ void EFUSE_ShadowMapUpdate(struct adapter *padapter, u8 efuseType)
/* void *)&pHalData->EfuseMap[EFUSE_INIT_MAP][0], mapLen); */
} /* EFUSE_ShadowMapUpdate */
-
/*-----------------------------------------------------------------------------
* Function: EFUSE_ShadowRead
*
diff --git a/drivers/staging/rtl8723bs/core/rtw_ioctl_set.c b/drivers/staging/rtl8723bs/core/rtw_ioctl_set.c
index 587a87fbffeb4..df664efb21269 100644
--- a/drivers/staging/rtl8723bs/core/rtw_ioctl_set.c
+++ b/drivers/staging/rtl8723bs/core/rtw_ioctl_set.c
@@ -345,7 +345,6 @@ u8 rtw_set_802_11_infrastructure_mode(struct adapter *padapter,
return true;
}
-
u8 rtw_set_802_11_disassociate(struct adapter *padapter)
{
struct mlme_priv *pmlmepriv = &padapter->mlmepriv;
diff --git a/drivers/staging/rtl8723bs/core/rtw_mlme_ext.c b/drivers/staging/rtl8723bs/core/rtw_mlme_ext.c
index abd26ac3787a3..8f7b5e2dce2f5 100644
--- a/drivers/staging/rtl8723bs/core/rtw_mlme_ext.c
+++ b/drivers/staging/rtl8723bs/core/rtw_mlme_ext.c
@@ -536,7 +536,6 @@ unsigned int OnProbeReq(struct adapter *padapter, union recv_frame *precv_frame)
p = rtw_get_ie(pframe + WLAN_HDR_A3_LEN + _PROBEREQ_IE_OFFSET_, WLAN_EID_SSID, (int *)&ielen,
len - WLAN_HDR_A3_LEN - _PROBEREQ_IE_OFFSET_);
-
/* check (wildcard) SSID */
if (p) {
if (is_valid_p2p_probereq)
@@ -795,7 +794,6 @@ unsigned int OnAuth(struct adapter *padapter, union recv_frame *precv_frame)
if (pstat->auth_seq == 0)
pstat->expire_to = pstapriv->auth_to;
-
if ((pstat->auth_seq + 1) != seq) {
status = WLAN_STATUS_UNKNOWN_AUTH_TRANSACTION;
goto auth_fail;
@@ -844,7 +842,6 @@ unsigned int OnAuth(struct adapter *padapter, union recv_frame *precv_frame)
}
}
-
/* Now, we are going to issue_auth... */
pstat->auth_seq = seq + 1;
@@ -853,7 +850,6 @@ unsigned int OnAuth(struct adapter *padapter, union recv_frame *precv_frame)
if (pstat->state & WIFI_FW_AUTH_SUCCESS)
pstat->auth_seq = 0;
-
return _SUCCESS;
auth_fail:
@@ -979,7 +975,6 @@ unsigned int OnAssocReq(struct adapter *padapter, union recv_frame *precv_frame)
else /* WIFI_REASSOCREQ */
ie_offset = _REASOCREQ_IE_OFFSET_;
-
if (pkt_len < sizeof(struct ieee80211_hdr_3addr) + ie_offset)
return _FAIL;
@@ -1009,7 +1004,6 @@ unsigned int OnAssocReq(struct adapter *padapter, union recv_frame *precv_frame)
pstat->state |= WIFI_FW_ASSOC_STATE;
}
-
pstat->capability = capab_info;
/* now parse all ieee802_11 ie to point to elems */
@@ -1146,7 +1140,6 @@ unsigned int OnAssocReq(struct adapter *padapter, union recv_frame *precv_frame)
pstat->flags |= WLAN_STA_MAYBE_WPS;
}
-
/* AP support WPA/RSN, and sta is going to do WPS, but AP is not ready */
/* that the selected registrar of AP is _FLASE */
if ((psecuritypriv->wpa_psk > 0)
@@ -1181,13 +1174,11 @@ unsigned int OnAssocReq(struct adapter *padapter, union recv_frame *precv_frame)
copy_len = ((wpa_ie_len+2) > sizeof(pstat->wpa_ie)) ? (sizeof(pstat->wpa_ie)):(wpa_ie_len+2);
}
-
if (copy_len > 0)
memcpy(pstat->wpa_ie, wpa_ie-2, copy_len);
}
-
/* check if there is WMM IE & support WWM-PS */
pstat->flags &= ~WLAN_STA_WME;
pstat->qos_option = 0;
@@ -1260,13 +1251,11 @@ unsigned int OnAssocReq(struct adapter *padapter, union recv_frame *precv_frame)
} else
pstat->flags &= ~WLAN_STA_HT;
-
if ((pmlmepriv->htpriv.ht_option == false) && (pstat->flags&WLAN_STA_HT)) {
status = WLAN_STATUS_CHALLENGE_FAIL;
goto OnAssocReqFail;
}
-
if ((pstat->flags & WLAN_STA_HT) &&
((pstat->wpa2_pairwise_cipher&WPA_CIPHER_TKIP) ||
(pstat->wpa_pairwise_cipher&WPA_CIPHER_TKIP))) {
@@ -1314,13 +1303,11 @@ unsigned int OnAssocReq(struct adapter *padapter, union recv_frame *precv_frame)
goto OnAssocReqFail;
-
} else {
pstapriv->sta_aid[pstat->aid - 1] = pstat;
}
}
-
pstat->state &= (~WIFI_FW_ASSOC_STATE);
pstat->state |= WIFI_FW_ASSOC_SUCCESS;
@@ -1519,7 +1506,6 @@ unsigned int OnDeAuth(struct adapter *padapter, union recv_frame *precv_frame)
associated_clients_update(padapter, updated);
}
-
return _SUCCESS;
}
@@ -2162,7 +2148,6 @@ void issue_beacon(struct adapter *padapter, int timeout_ms)
pframe = (u8 *)(pmgntframe->buf_addr) + TXDESC_OFFSET;
pwlanhdr = (struct ieee80211_hdr *)pframe;
-
fctrl = &(pwlanhdr->frame_control);
*(fctrl) = 0;
@@ -2251,12 +2236,10 @@ void issue_beacon(struct adapter *padapter, int timeout_ms)
pframe = rtw_set_ie(pframe, WLAN_EID_ERP_INFO, 1, &erpinfo, &pattrib->pktlen);
}
-
/* EXTERNDED SUPPORTED RATE */
if (rate_len > 8)
pframe = rtw_set_ie(pframe, WLAN_EID_EXT_SUPP_RATES, (rate_len - 8), (cur_network->supported_rates + 8), &pattrib->pktlen);
-
/* todo:HT for adhoc */
_issue_bcn:
@@ -2328,7 +2311,6 @@ void issue_probersp(struct adapter *padapter, unsigned char *da, u8 is_valid_p2p
pattrib->pktlen = pattrib->hdrlen;
pframe += pattrib->hdrlen;
-
if (cur_network->ie_length > MAX_IE_SZ)
return;
@@ -2452,19 +2434,16 @@ void issue_probersp(struct adapter *padapter, unsigned char *da, u8 is_valid_p2p
pframe = rtw_set_ie(pframe, WLAN_EID_ERP_INFO, 1, &erpinfo, &pattrib->pktlen);
}
-
/* EXTERNDED SUPPORTED RATE */
if (rate_len > 8)
pframe = rtw_set_ie(pframe, WLAN_EID_EXT_SUPP_RATES, (rate_len - 8), (cur_network->supported_rates + 8), &pattrib->pktlen);
-
/* todo:HT for adhoc */
}
pattrib->last_txcmdsz = pattrib->pktlen;
-
dump_mgntframe(padapter, pmgntframe);
return;
@@ -2496,7 +2475,6 @@ static int _issue_probereq(struct adapter *padapter,
pattrib = &pmgntframe->attrib;
update_mgntframe_attrib(padapter, pattrib);
-
memset(pmgntframe->buf_addr, 0, WLANHDR_OFFSET + TXDESC_OFFSET);
pframe = (u8 *)(pmgntframe->buf_addr) + TXDESC_OFFSET;
@@ -2640,7 +2618,6 @@ void issue_auth(struct adapter *padapter, struct sta_info *psta, unsigned short
pframe += sizeof(struct ieee80211_hdr_3addr);
pattrib->pktlen = sizeof(struct ieee80211_hdr_3addr);
-
if (psta) { /* for AP mode */
memcpy(pwlanhdr->addr1, psta->hwaddr, ETH_ALEN);
memcpy(pwlanhdr->addr2, myid(&(padapter->eeprompriv)), ETH_ALEN);
@@ -2701,7 +2678,6 @@ void issue_auth(struct adapter *padapter, struct sta_info *psta, unsigned short
le_tmp = cpu_to_le16(pmlmeinfo->auth_seq);
pframe = rtw_set_fixed_ie(pframe, _AUTH_SEQ_NUM_, (unsigned char *)&le_tmp, &(pattrib->pktlen));
-
/* setting status code... */
le_tmp = cpu_to_le16(status);
pframe = rtw_set_fixed_ie(pframe, _STATUS_CODE_, (unsigned char *)&le_tmp, &(pattrib->pktlen));
@@ -2730,7 +2706,6 @@ void issue_auth(struct adapter *padapter, struct sta_info *psta, unsigned short
dump_mgntframe(padapter, pmgntframe);
}
-
void issue_asocrsp(struct adapter *padapter, unsigned short status, struct sta_info *pstat, int pkt_type)
{
struct xmit_frame *pmgntframe;
@@ -2755,7 +2730,6 @@ void issue_asocrsp(struct adapter *padapter, unsigned short status, struct sta_i
pattrib = &pmgntframe->attrib;
update_mgntframe_attrib(padapter, pattrib);
-
memset(pmgntframe->buf_addr, 0, WLANHDR_OFFSET + TXDESC_OFFSET);
pframe = (u8 *)(pmgntframe->buf_addr) + TXDESC_OFFSET;
@@ -2768,7 +2742,6 @@ void issue_asocrsp(struct adapter *padapter, unsigned short status, struct sta_i
memcpy((void *)GetAddr2Ptr(pwlanhdr), myid(&(padapter->eeprompriv)), ETH_ALEN);
memcpy((void *)GetAddr3Ptr(pwlanhdr), get_my_bssid(&(pmlmeinfo->network)), ETH_ALEN);
-
SetSeqNum(pwlanhdr, pmlmeext->mgnt_seq);
pmlmeext->mgnt_seq++;
if ((pkt_type == WIFI_ASSOCRSP) || (pkt_type == WIFI_REASSOCRSP))
@@ -2927,7 +2900,6 @@ void issue_assocreq(struct adapter *padapter)
if (pmlmeext->cur_channel == 14) /* for JAPAN, channel 14 can only uses B Mode(CCK) */
sta_bssrate_len = 4;
-
/* for (i = 0; i < sta_bssrate_len; i++) { */
/* */
@@ -2936,12 +2908,10 @@ void issue_assocreq(struct adapter *padapter)
break;
}
-
for (i = 0; i < NDIS_802_11_LENGTH_RATES_EX; i++) {
if (pmlmeinfo->network.supported_rates[i] == 0)
break;
-
/* Check if the AP's supported rates are also supported by STA. */
for (j = 0; j < sta_bssrate_len; j++) {
/* Avoid the proprietary data rate (22Mbps) of Handlink WSG-4000 AP */
@@ -2963,7 +2933,6 @@ void issue_assocreq(struct adapter *padapter)
goto exit; /* don't connect to AP if no joint supported rate */
}
-
if (bssrate_len > 8) {
pframe = rtw_set_ie(pframe, WLAN_EID_SUPP_RATES, 8, bssrate, &(pattrib->pktlen));
pframe = rtw_set_ie(pframe, WLAN_EID_EXT_SUPP_RATES, (bssrate_len - 8), (bssrate + 8), &(pattrib->pktlen));
@@ -3024,7 +2993,6 @@ void issue_assocreq(struct adapter *padapter)
if (pmlmeinfo->assoc_AP_vendor == HT_IOT_PEER_REALTEK)
pframe = rtw_set_ie(pframe, WLAN_EID_VENDOR_SPECIFIC, 6, REALTEK_96B_IE, &(pattrib->pktlen));
-
pattrib->last_txcmdsz = pattrib->pktlen;
dump_mgntframe(padapter, pmgntframe);
@@ -3121,7 +3089,6 @@ int issue_nulldata(struct adapter *padapter, unsigned char *da, unsigned int pow
struct mlme_ext_info *pmlmeinfo = &(pmlmeext->mlmext_info);
struct sta_info *psta;
-
/* da == NULL, assume it's null data for sta to ap*/
if (!da)
da = get_my_bssid(&(pmlmeinfo->network));
@@ -3171,7 +3138,6 @@ s32 issue_nulldata_in_interrupt(struct adapter *padapter, u8 *da)
struct mlme_ext_priv *pmlmeext;
struct mlme_ext_info *pmlmeinfo;
-
pmlmeext = &padapter->mlmeextpriv;
pmlmeinfo = &pmlmeext->mlmext_info;
@@ -3340,7 +3306,6 @@ static int _issue_deauth(struct adapter *padapter, unsigned char *da,
pattrib->last_txcmdsz = pattrib->pktlen;
-
if (wait_ack) {
ret = dump_mgntframe_and_wait_ack(padapter, pmgntframe);
} else {
@@ -3662,7 +3627,6 @@ static void issue_action_BSSCoexistPacket(struct adapter *padapter)
pframe = rtw_set_fixed_ie(pframe, 1, &(category), &(pattrib->pktlen));
pframe = rtw_set_fixed_ie(pframe, 1, &(action), &(pattrib->pktlen));
-
/* */
if (pmlmepriv->num_FortyMHzIntolerant > 0) {
u8 iedata = 0;
@@ -3673,7 +3637,6 @@ static void issue_action_BSSCoexistPacket(struct adapter *padapter)
}
-
/* */
memset(ICS, 0, sizeof(ICS));
if (pmlmepriv->num_sta_no_ht > 0) {
@@ -3714,7 +3677,6 @@ static void issue_action_BSSCoexistPacket(struct adapter *padapter)
spin_unlock_bh(&(pmlmepriv->scanned_queue.lock));
-
for (i = 0; i < 8; i++) {
if (ICS[i][0] == 1) {
int j, k = 0;
@@ -3742,7 +3704,6 @@ static void issue_action_BSSCoexistPacket(struct adapter *padapter)
}
-
pattrib->last_txcmdsz = pattrib->pktlen;
dump_mgntframe(padapter, pmgntframe);
@@ -4223,7 +4184,6 @@ void start_clnt_auth(struct adapter *padapter)
pmlmeinfo->link_count = 0;
pmlmeext->retry = 0;
-
netdev_dbg(padapter->pnetdev, "start auth\n");
issue_auth(padapter, NULL, 0);
@@ -4231,7 +4191,6 @@ void start_clnt_auth(struct adapter *padapter)
}
-
void start_clnt_assoc(struct adapter *padapter)
{
struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
@@ -4278,7 +4237,6 @@ static void process_80211d(struct adapter *padapter, struct wlan_bssid_ex *bssid
u8 channel;
u8 i;
-
pregistrypriv = &padapter->registrypriv;
pmlmeext = &padapter->mlmeextpriv;
@@ -4562,10 +4520,8 @@ void report_join_res(struct adapter *padapter, int res)
memcpy((unsigned char *)(&(pjoinbss_evt->network.network)), &(pmlmeinfo->network), sizeof(struct wlan_bssid_ex));
pjoinbss_evt->network.join_res = pjoinbss_evt->network.aid = res;
-
rtw_joinbss_event_prehandle(padapter, (u8 *)&pjoinbss_evt->network);
-
rtw_enqueue_cmd(pcmdpriv, pcmd_obj);
return;
@@ -4657,7 +4613,6 @@ void report_del_sta_event(struct adapter *padapter, unsigned char *MacAddr, unsi
memcpy((unsigned char *)(&(pdel_sta_evt->macaddr)), MacAddr, ETH_ALEN);
memcpy((unsigned char *)(pdel_sta_evt->rsvd), (unsigned char *)(&reason), 2);
-
psta = rtw_get_stainfo(&padapter->stapriv, MacAddr);
if (psta)
mac_id = (int)psta->mac_id;
@@ -4846,7 +4801,6 @@ void mlmeext_joinbss_event_callback(struct adapter *padapter, int join_res)
/* update bc/mc sta_info */
update_bmc_sta(padapter);
-
/* turn on dynamic functions */
Switch_DM_Func(padapter, DYNAMIC_ALL_FUNC_ENABLE, true);
@@ -5152,7 +5106,6 @@ void link_timer_hdl(struct timer_list *t)
struct mlme_ext_priv *pmlmeext = &padapter->mlmeextpriv;
struct mlme_ext_info *pmlmeinfo = &(pmlmeext->mlmext_info);
-
if (pmlmeinfo->state & WIFI_FW_AUTH_NULL) {
pmlmeinfo->state = WIFI_FW_NULL_STATE;
report_join_res(padapter, -3);
@@ -5339,7 +5292,6 @@ u8 join_cmd_hdl(struct adapter *padapter, u8 *pbuf)
/* Set_MSR(padapter, _HW_STATE_NOLINK_); */
Set_MSR(padapter, _HW_STATE_STATION_);
-
rtw_hal_set_hwreg(padapter, HW_VAR_MLME_DISCONNECT, NULL);
}
diff --git a/drivers/staging/rtl8723bs/core/rtw_recv.c b/drivers/staging/rtl8723bs/core/rtw_recv.c
index c0dbe4db44c39..4727f94df4355 100644
--- a/drivers/staging/rtl8723bs/core/rtw_recv.c
+++ b/drivers/staging/rtl8723bs/core/rtw_recv.c
@@ -60,7 +60,6 @@ signed int _rtw_init_recv_priv(struct recv_priv *precvpriv, struct adapter *pada
precvframe = (union recv_frame *) precvpriv->precv_frame_buf;
-
for (i = 0; i < NR_RECVFRAME; i++) {
INIT_LIST_HEAD(&(precvframe->u.list));
@@ -180,9 +179,6 @@ int rtw_free_recvframe(union recv_frame *precvframe, struct __queue *pfree_recv_
return _SUCCESS;
}
-
-
-
signed int _rtw_enqueue_recvframe(union recv_frame *precvframe, struct __queue *queue)
{
@@ -192,7 +188,6 @@ signed int _rtw_enqueue_recvframe(union recv_frame *precvframe, struct __queue *
/* INIT_LIST_HEAD(&(precvframe->u.hdr.list)); */
list_del_init(&(precvframe->u.hdr.list));
-
list_add_tail(&(precvframe->u.hdr.list), get_list_head(queue));
if (padapter)
@@ -257,7 +252,6 @@ u32 rtw_free_uc_swdec_pending_queue(struct adapter *adapter)
return cnt;
}
-
signed int rtw_enqueue_recvbuf_to_head(struct recv_buf *precvbuf, struct __queue *queue)
{
spin_lock_bh(&queue->lock);
@@ -405,7 +399,6 @@ static signed int recvframe_chkmic(struct adapter *adapter, union recv_frame *p
bmic_err = true;
}
-
if (bmic_err == true) {
/* double check key_index for some timing issue , */
/* cannot compare with psecuritypriv->dot118021XGrpKeyid also cause timing issue */
@@ -772,8 +765,6 @@ static signed int sta2sta_data_frame(struct adapter *adapter, union recv_frame *
} else
ret = _FAIL;
-
-
if (bmcast)
*psta = rtw_get_bcmc_stainfo(adapter);
else
@@ -817,7 +808,6 @@ static signed int ap2sta_data_frame(struct adapter *adapter, union recv_frame *p
goto exit;
}
-
/* check BSSID */
if (is_zero_ether_addr(pattrib->bssid) ||
is_zero_ether_addr(mybssid) ||
@@ -858,14 +848,12 @@ static signed int ap2sta_data_frame(struct adapter *adapter, union recv_frame *p
/* */
memcpy(pattrib->bssid, mybssid, ETH_ALEN);
-
*psta = rtw_get_stainfo(pstapriv, pattrib->bssid); /* get sta_info */
if (!*psta) {
ret = _FAIL;
goto exit;
}
-
} else if (check_fwstate(pmlmepriv, WIFI_AP_STATE) == true) {
/* Special case */
ret = RTW_RX_HANDLED;
@@ -1109,7 +1097,6 @@ static union recv_frame *recvframe_defrag(struct adapter *adapter,
pnextrframe = (union recv_frame *)plist;
pnfhdr = &pnextrframe->u.hdr;
-
/* check the fragment sequence (2nd ~n fragment frame) */
if (curfragnum != pnfhdr->attrib.frag_num) {
@@ -1197,7 +1184,6 @@ static union recv_frame *recvframe_chk_defrag(struct adapter *padapter, union re
/* free current defrag_q */
rtw_free_recvframe_queue(pdefrag_q, pfree_recv_queue);
-
/* Then enqueue the 0~(n-1) fragment into the defrag_q */
/* spin_lock(&pdefrag_q->lock); */
@@ -1236,7 +1222,6 @@ static union recv_frame *recvframe_chk_defrag(struct adapter *padapter, union re
}
-
if ((prtnframe) && (prtnframe->u.hdr.attrib.privacy)) {
/* after defrag we must check tkip mic code */
if (recvframe_chkmic(padapter, prtnframe) == _FAIL) {
@@ -1345,7 +1330,6 @@ static signed int validate_recv_data_frame(struct adapter *adapter, union recv_f
goto exit;
}
-
if (!psta) {
ret = _FAIL;
goto exit;
@@ -1355,7 +1339,6 @@ static signed int validate_recv_data_frame(struct adapter *adapter, union recv_f
/* psta->signal_quality = prxcmd->sq; */
precv_frame->u.hdr.psta = psta;
-
pattrib->amsdu = 0;
pattrib->ack_policy = 0;
/* parsing QC field */
@@ -1373,7 +1356,6 @@ static signed int validate_recv_data_frame(struct adapter *adapter, union recv_f
pattrib->hdrlen = pattrib->to_fr_ds == 3 ? 30 : 24;
}
-
if (pattrib->order)/* HT-CTRL 11n */
pattrib->hdrlen += 4;
@@ -1827,7 +1809,6 @@ static int enqueue_reorder_recvframe(struct recv_reorder_ctrl *preorder_ctrl, un
/* spin_lock_irqsave(&ppending_recvframe_queue->lock, irql); */
/* spin_lock(&ppending_recvframe_queue->lock); */
-
phead = get_list_head(ppending_recvframe_queue);
plist = get_next(phead);
@@ -1846,7 +1827,6 @@ static int enqueue_reorder_recvframe(struct recv_reorder_ctrl *preorder_ctrl, un
}
-
/* spin_lock_irqsave(&ppending_recvframe_queue->lock, irql); */
/* spin_lock(&ppending_recvframe_queue->lock); */
@@ -1975,7 +1955,6 @@ static int recv_indicatepkts_in_order(struct adapter *padapter, struct recv_reor
/* error condition; */
}
-
/* Update local variables. */
bPktInBuf = false;
@@ -2058,7 +2037,6 @@ static int recv_indicatepkt_reorder(struct adapter *padapter, union recv_frame *
goto _err_exit;
}
-
/* s4. */
/* Indication process. */
/* After Packet dropping and Sliding Window shifting as above, we can now just indicate the packets */
@@ -2086,7 +2064,6 @@ static int recv_indicatepkt_reorder(struct adapter *padapter, union recv_frame *
return _FAIL;
}
-
void rtw_reordering_ctrl_timeout_handler(struct timer_list *t)
{
struct recv_reorder_ctrl *preorder_ctrl =
@@ -2094,7 +2071,6 @@ void rtw_reordering_ctrl_timeout_handler(struct timer_list *t)
struct adapter *padapter = preorder_ctrl->padapter;
struct __queue *ppending_recvframe_queue = &preorder_ctrl->pending_recvframe_queue;
-
if (padapter->bDriverStopped || padapter->bSurpriseRemoved)
return;
@@ -2242,7 +2218,6 @@ static int recv_func(struct adapter *padapter, union recv_frame *rframe)
return ret;
}
-
s32 rtw_recv_entry(union recv_frame *precvframe)
{
struct adapter *padapter;
diff --git a/drivers/staging/rtl8723bs/core/rtw_wlan_util.c b/drivers/staging/rtl8723bs/core/rtw_wlan_util.c
index 82624e46fbf59..ccfbef80c00ca 100644
--- a/drivers/staging/rtl8723bs/core/rtw_wlan_util.c
+++ b/drivers/staging/rtl8723bs/core/rtw_wlan_util.c
@@ -341,7 +341,6 @@ void set_channel_bwmode(struct adapter *padapter, unsigned char channel, unsigne
center_ch = rtw_get_center_ch(channel, bwmode, channel_offset);
-
/* set Channel */
if (mutex_lock_interruptible(&(adapter_to_dvobj(padapter)->setch_mutex)))
return;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0447/1518] staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (445 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0446/1518] staging: rtl8723bs: remove multiple blank lines in core/ Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0448/1518] gpib: Move stuck SRQ update under lock Greg Kroah-Hartman
` (551 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Cong Nguyen, Dan Carpenter,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cong Nguyen <congnt264@gmail.com>
[ Upstream commit 41b8209376dffbd7b0b85c8bc4697d9166ac62ef ]
issue_beacon(), issue_probersp() and issue_asocrsp() obtain a management
xmit_frame together with its xmit_buf from the driver's fixed-size
management-TX pools via alloc_mgtxmitframe(). On the normal path the frame
is handed to dump_mgntframe(), which transfers ownership and eventually
returns both objects to their pools (the frame and, for beacons, the buf
in rtl8723bs_mgnt_xmit(); other bufs via the pending-xmitbuf/TX-completion
path).
Several error/edge paths return early after a successful
alloc_mgtxmitframe() but before dump_mgntframe(), so ownership is never
transferred and neither object is freed:
- issue_beacon(): beacon larger than 512 bytes
- issue_probersp(): cur_network->ie_length > MAX_IE_SZ
- issue_probersp(): kzalloc() of the SSID scratch buffer fails
- issue_asocrsp(): pkt_type is neither ASSOCRSP nor REASSOCRSP
Because alloc_mgtxmitframe() removes the frame and buf from their free
lists (list_del_init) without placing them on any pending list, an
orphaned pair is on no list and referenced by nobody, so it is only
reclaimed at driver teardown. Repeated hits progressively exhaust the
management-TX pools until alloc_mgtxmitframe() returns NULL and the
interface can no longer send beacons or probe/assoc responses.
Free the frame and buffer on these paths, matching the existing correct
error handling in issue_assocreq().
Fixes: 554c0a3abf21 ("staging: Add rtl8723bs sdio wifi driver")
Signed-off-by: Cong Nguyen <congnt264@gmail.com>
Reviewed-by: Dan Carpenter <error27@gmail.com>
Link: https://patch.msgid.link/20260715111710.295052-1-congnt264@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/staging/rtl8723bs/core/rtw_mlme_ext.c | 22 ++++++++++++++-----
1 file changed, 17 insertions(+), 5 deletions(-)
diff --git a/drivers/staging/rtl8723bs/core/rtw_mlme_ext.c b/drivers/staging/rtl8723bs/core/rtw_mlme_ext.c
index 8f7b5e2dce2f5..8d33631ab8f0f 100644
--- a/drivers/staging/rtl8723bs/core/rtw_mlme_ext.c
+++ b/drivers/staging/rtl8723bs/core/rtw_mlme_ext.c
@@ -2248,8 +2248,11 @@ void issue_beacon(struct adapter *padapter, int timeout_ms)
spin_unlock_bh(&pmlmepriv->bcn_update_lock);
- if ((pattrib->pktlen + TXDESC_SIZE) > 512)
+ if ((pattrib->pktlen + TXDESC_SIZE) > 512) {
+ rtw_free_xmitbuf(pxmitpriv, pmgntframe->pxmitbuf);
+ rtw_free_xmitframe(pxmitpriv, pmgntframe);
return;
+ }
pattrib->last_txcmdsz = pattrib->pktlen;
@@ -2311,8 +2314,11 @@ void issue_probersp(struct adapter *padapter, unsigned char *da, u8 is_valid_p2p
pattrib->pktlen = pattrib->hdrlen;
pframe += pattrib->hdrlen;
- if (cur_network->ie_length > MAX_IE_SZ)
+ if (cur_network->ie_length > MAX_IE_SZ) {
+ rtw_free_xmitbuf(pxmitpriv, pmgntframe->pxmitbuf);
+ rtw_free_xmitframe(pxmitpriv, pmgntframe);
return;
+ }
if ((pmlmeinfo->state&0x03) == WIFI_FW_AP_STATE) {
pwps_ie = rtw_get_wps_ie(cur_network->ies+_FIXED_IE_LENGTH_, cur_network->ie_length-_FIXED_IE_LENGTH_, NULL, &wps_ielen);
@@ -2359,8 +2365,11 @@ void issue_probersp(struct adapter *padapter, unsigned char *da, u8 is_valid_p2p
u8 *ies = pmgntframe->buf_addr+TXDESC_OFFSET+sizeof(struct ieee80211_hdr_3addr);
buf = kzalloc(MAX_IE_SZ, GFP_ATOMIC);
- if (!buf)
+ if (!buf) {
+ rtw_free_xmitbuf(pxmitpriv, pmgntframe->pxmitbuf);
+ rtw_free_xmitframe(pxmitpriv, pmgntframe);
return;
+ }
ssid_ie = rtw_get_ie(ies+_FIXED_IE_LENGTH_, WLAN_EID_SSID, &ssid_ielen,
(pframe-ies)-_FIXED_IE_LENGTH_);
@@ -2744,10 +2753,13 @@ void issue_asocrsp(struct adapter *padapter, unsigned short status, struct sta_i
SetSeqNum(pwlanhdr, pmlmeext->mgnt_seq);
pmlmeext->mgnt_seq++;
- if ((pkt_type == WIFI_ASSOCRSP) || (pkt_type == WIFI_REASSOCRSP))
+ if ((pkt_type == WIFI_ASSOCRSP) || (pkt_type == WIFI_REASSOCRSP)) {
SetFrameSubType(pwlanhdr, pkt_type);
- else
+ } else {
+ rtw_free_xmitbuf(pxmitpriv, pmgntframe->pxmitbuf);
+ rtw_free_xmitframe(pxmitpriv, pmgntframe);
return;
+ }
pattrib->hdrlen = sizeof(struct ieee80211_hdr_3addr);
pattrib->pktlen += pattrib->hdrlen;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0448/1518] gpib: Move stuck SRQ update under lock
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (446 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0447/1518] staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0449/1518] uio: Fix stale info pointer in failed registration path Greg Kroah-Hartman
` (550 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Gui-Dong Han, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gui-Dong Han <hanguidong02@gmail.com>
[ Upstream commit 7ddb521ab097413fbdff483b53b4a8c73a0e2b40 ]
Move the stuck SRQ state update into autopoll_all_devices() and keep it
under big_gpib_mutex. Except for initialization, keep the stuck_srq users
under this mutex.
autopoll_all_devices() is only called by autospoll_thread(), so there is
no need to return to autospoll_thread() and set this state after dropping
big_gpib_mutex.
Without the mutex, a newly opened device can clear stuck_srq and have
that clear overwritten by the previous autospoll result:
autospoll: serial_poll_all() returns 0 and unlocks big_gpib_mutex
open_dev_ioctl: open new device and clear stuck_srq
with big_gpib_mutex held
autospoll: set stuck_srq
That leaves the board marked stuck again after the new device is opened.
autospoll_wait_should_wake_up() then refuses to poll while stuck_srq is
set, so later SRQ handling can be mistakenly suppressed.
Without the mutex, atomic_set() and set_bit() only make individual
updates atomic. They do not order the two updates or make stuck_srq and
status visible as a consistent pair. Taking big_gpib_mutex serializes the
state transition with the other runtime users.
Keep the existing wakeup behavior unchanged and only move the stuck SRQ
state update under the mutex.
Fixes: 9dde4559e939 ("staging: gpib: Add GPIB common core driver")
Signed-off-by: Gui-Dong Han <hanguidong02@gmail.com>
Link: https://patch.msgid.link/20260522073447.4117690-1-hanguidong02@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/staging/gpib/common/gpib_os.c | 21 +++++++++++----------
drivers/staging/gpib/common/iblib.c | 3 ---
2 files changed, 11 insertions(+), 13 deletions(-)
diff --git a/drivers/staging/gpib/common/gpib_os.c b/drivers/staging/gpib/common/gpib_os.c
index a2bed6bd757a0..b223bd23a8422 100644
--- a/drivers/staging/gpib/common/gpib_os.c
+++ b/drivers/staging/gpib/common/gpib_os.c
@@ -289,18 +289,19 @@ int autopoll_all_devices(struct gpib_board *board)
dev_dbg(board->gpib_dev, "autopoll has board lock\n");
retval = serial_poll_all(board, serial_timeout);
- if (retval < 0) {
- mutex_unlock(&board->big_gpib_mutex);
- mutex_unlock(&board->user_mutex);
- return retval;
+ if (retval >= 0) {
+ dev_dbg(board->gpib_dev, "complete\n");
+ /*
+ * need to wake wait queue in case someone is
+ * waiting on RQS
+ */
+ wake_up_interruptible(&board->wait);
}
- dev_dbg(board->gpib_dev, "complete\n");
- /*
- * need to wake wait queue in case someone is
- * waiting on RQS
- */
- wake_up_interruptible(&board->wait);
+ if (retval <= 0) {
+ atomic_set(&board->stuck_srq, 1);
+ set_bit(SRQI_NUM, &board->status);
+ }
mutex_unlock(&board->big_gpib_mutex);
mutex_unlock(&board->user_mutex);
diff --git a/drivers/staging/gpib/common/iblib.c b/drivers/staging/gpib/common/iblib.c
index b672dd6aad25f..511e1d61c1fb2 100644
--- a/drivers/staging/gpib/common/iblib.c
+++ b/drivers/staging/gpib/common/iblib.c
@@ -193,9 +193,6 @@ static int autospoll_thread(void *board_void)
}
if (retval <= 0) {
dev_err(board->gpib_dev, "stuck SRQ\n");
-
- atomic_set(&board->stuck_srq, 1); // XXX could be better
- set_bit(SRQI_NUM, &board->status);
}
}
return retval;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0449/1518] uio: Fix stale info pointer in failed registration path
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (447 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0448/1518] gpib: Move stuck SRQ update under lock Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0450/1518] accessibility: speakup: Fix incorrect string length computation in report_char_chartab_status() Greg Kroah-Hartman
` (549 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yuho Choi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuho Choi <dbgh9129@gmail.com>
[ Upstream commit 67b6fc084b034a91c3ec7907a3fed89a2450f30b ]
After device_add(), the UIO device is visible to userspace and /dev/uioX
can be opened. If a later setup step fails, __uio_register_device()
unwinds the device but leaves idev->info pointing at the caller-owned
struct uio_info.
That is unsafe when an opener races with the failed registration path.
The open file keeps a reference to the uio_device, while the caller sees
registration failure and may free its struct uio_info. Later file
operations can then follow idev->info and dereference freed memory.
Handle post-device_add() failures like unregister: remove UIO attributes
while the info pointer is still valid, then clear idev->info under
info_lock and wake existing waiters/async users before removing the
device and minor. This makes already-open file descriptors observe the
same "device gone" state as normal uio_unregister_device().
Fixes: a93e7b331568 ("uio: Prevent device destruction while fds are open")
Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
Link: https://patch.msgid.link/20260630192714.1867170-1-dbgh9129@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/uio/uio.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/drivers/uio/uio.c b/drivers/uio/uio.c
index d93ed4e86a174..4029585bf22cd 100644
--- a/drivers/uio/uio.c
+++ b/drivers/uio/uio.c
@@ -1051,6 +1051,11 @@ int __uio_register_device(struct module *owner,
err_request_irq:
uio_dev_del_attributes(idev);
err_uio_dev_add_attributes:
+ mutex_lock(&idev->info_lock);
+ idev->info = NULL;
+ mutex_unlock(&idev->info_lock);
+ wake_up_interruptible(&idev->wait);
+ kill_fasync(&idev->async_queue, SIGIO, POLL_HUP);
device_del(&idev->dev);
err_device_create:
uio_free_minor(idev->minor);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0450/1518] accessibility: speakup: Fix incorrect string length computation in report_char_chartab_status()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (448 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0449/1518] uio: Fix stale info pointer in failed registration path Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0451/1518] speakup: keyhelp: guard letter_offsets possible out-of-range indexing Greg Kroah-Hartman
` (548 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christophe JAILLET, Samuel Thibault,
Dan Carpenter, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christophe JAILLET <christophe.jaillet@wanadoo.fr>
[ Upstream commit bce0e640623372520d9d90c42f33ddbfb576ce69 ]
snprintf() returns the "number of characters which *would* be generated for
the given input", not the size *really* generated.
In order to avoid too large values for 'len' (and potential negative
values for "sizeof(buf) - (len - 1)") use scnprintf() instead of
snprintf().
Fixes: c6e3fd22cd53 ("Staging: add speakup to the staging directory")
Signed-off-by: Christophe JAILLET <christophe.jaillet@wanadoo.fr>
Signed-off-by: Samuel Thibault <samuel.thibault@ens-lyon.org>
Reviewed-by: Samuel Thibault <samuel.thibault@ens-lyon.org>
Reviewed-by: Dan Carpenter <dan.carpenter@linaro.org>
Link: https://patch.msgid.link/20260531230804.254962-5-samuel.thibault@ens-lyon.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/accessibility/speakup/kobjects.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/accessibility/speakup/kobjects.c b/drivers/accessibility/speakup/kobjects.c
index 0dfdb6608e022..943ef71b1329b 100644
--- a/drivers/accessibility/speakup/kobjects.c
+++ b/drivers/accessibility/speakup/kobjects.c
@@ -92,9 +92,9 @@ static void report_char_chartab_status(int reset, int received, int used,
if (reset) {
pr_info("%s reset to defaults\n", object_type[do_characters]);
} else if (received) {
- len = snprintf(buf, sizeof(buf),
- " updated %d of %d %s\n",
- used, received, object_type[do_characters]);
+ len = scnprintf(buf, sizeof(buf),
+ " updated %d of %d %s\n",
+ used, received, object_type[do_characters]);
if (rejected)
snprintf(buf + (len - 1), sizeof(buf) - (len - 1),
" with %d reject%s\n",
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0451/1518] speakup: keyhelp: guard letter_offsets possible out-of-range indexing
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (449 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0450/1518] accessibility: speakup: Fix incorrect string length computation in report_char_chartab_status() Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0452/1518] misc: bcm-vk: Use acquire/release for msgq_inited Greg Kroah-Hartman
` (547 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pavel Zhigulin, Samuel Thibault,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pavel Zhigulin <Pavel.Zhigulin@kaspersky.com>
[ Upstream commit 6a19ad4d68c95185308cd9e5d169b10a2cf236c8 ]
help_init() builds letter_offsets[] by using the first byte of each
function name as an index via `(start & 31) - 1`. If function_names are
overridden from sysfs (root) with a name starting outside [a–z], the
index underflows or exceeds the array, leading to OOB write.
Function names can be overridden with the following commands as root:
modprobe speakup_soft
echo "0 _bad" > /sys/accessibility/speakup/i18n/function_names
# then press Insert+2 on /dev/tty
This fix checks the first letter in help_init(), and if it is not in the
[a–z] range the function returns an error to the caller. Eventually this
error is propagated to drivers/accessibility/speakup/main.c:2217, which
causes a bleep sound.
Fixes: c6e3fd22cd53 ("Staging: add speakup to the staging directory")
Signed-off-by: Pavel Zhigulin <Pavel.Zhigulin@kaspersky.com>
Signed-off-by: Samuel Thibault <samuel.thibault@ens-lyon.org>
Link: https://patch.msgid.link/20260531230804.254962-10-samuel.thibault@ens-lyon.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/accessibility/speakup/keyhelp.c | 17 ++++++++++++-----
1 file changed, 12 insertions(+), 5 deletions(-)
diff --git a/drivers/accessibility/speakup/keyhelp.c b/drivers/accessibility/speakup/keyhelp.c
index 822ceac830683..e632c53d6246e 100644
--- a/drivers/accessibility/speakup/keyhelp.c
+++ b/drivers/accessibility/speakup/keyhelp.c
@@ -8,6 +8,7 @@
*/
#include <linux/keyboard.h>
+#include <linux/ctype.h>
#include "spk_priv.h"
#include "speakup.h"
@@ -111,7 +112,7 @@ static void say_key(int key)
spk_msg_get(MSG_KEYNAMES_START + (key - 1)));
}
-static int help_init(void)
+static void help_init(void)
{
char start = SPACE;
int i;
@@ -120,13 +121,19 @@ static int help_init(void)
state_tbl = spk_our_keys[0] + SHIFT_TBL_SIZE + 2;
for (i = 0; i < num_funcs; i++) {
char *cur_funcname = spk_msg_get(MSG_FUNCNAMES_START + i);
+ char first_letter;
- if (start == *cur_funcname)
+ first_letter = tolower(*cur_funcname);
+
+ /* Accept only 'a'..'z' to index letter_offsets[] safely */
+ if (first_letter < 'a' || first_letter > 'z')
+ continue;
+
+ if (start == first_letter)
continue;
- start = *cur_funcname;
+ start = first_letter;
letter_offsets[(start & 31) - 1] = i;
}
- return 0;
}
int spk_handle_help(struct vc_data *vc, u_char type, u_char ch, u_short key)
@@ -144,7 +151,7 @@ int spk_handle_help(struct vc_data *vc, u_char type, u_char ch, u_short key)
synth_printf("%s\n", spk_msg_get(MSG_LEAVING_HELP));
return 1;
}
- ch |= 32; /* lower case */
+ ch = tolower(ch);
if (ch < 'a' || ch > 'z')
return -1;
if (letter_offsets[ch - 'a'] == -1) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0452/1518] misc: bcm-vk: Use acquire/release for msgq_inited
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (450 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0451/1518] speakup: keyhelp: guard letter_offsets possible out-of-range indexing Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0453/1518] misc: rtsx: add missing write register handling Greg Kroah-Hartman
` (546 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Gui-Dong Han, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gui-Dong Han <hanguidong02@gmail.com>
[ Upstream commit 61b101c6a150057b6d512421ed108aed16e822ea ]
bcm_vk_sync_msgq() fills the message queue information and then sets
msgq_inited. Readers call bcm_vk_drv_access_ok() before accessing the
message queues and their cached queue information.
atomic_set()/atomic_read() do not order those accesses. A reader can see
msgq_inited set while still seeing stale queue information. Use release
when publishing the initialized queues and acquire when checking the gate.
Keep the clear in bcm_vk_blk_drv_access() as atomic_set(). It closes the
gate and does not publish queue state to readers.
Fixes: 111d746bb476 ("misc: bcm-vk: add VK messaging support")
Signed-off-by: Gui-Dong Han <hanguidong02@gmail.com>
Link: https://patch.msgid.link/20260603021127.3285057-1-hanguidong02@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/misc/bcm-vk/bcm_vk_msg.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/misc/bcm-vk/bcm_vk_msg.c b/drivers/misc/bcm-vk/bcm_vk_msg.c
index 665a3888708ac..a36a6c7d384a9 100644
--- a/drivers/misc/bcm-vk/bcm_vk_msg.c
+++ b/drivers/misc/bcm-vk/bcm_vk_msg.c
@@ -108,7 +108,8 @@ u32 msgq_avail_space(const struct bcm_vk_msgq __iomem *msgq,
bool bcm_vk_drv_access_ok(struct bcm_vk *vk)
{
- return (!!atomic_read(&vk->msgq_inited));
+ /* Pair with the release store after message queue initialization. */
+ return !!atomic_read_acquire(&vk->msgq_inited);
}
void bcm_vk_set_host_alert(struct bcm_vk *vk, u32 bit_mask)
@@ -501,7 +502,8 @@ int bcm_vk_sync_msgq(struct bcm_vk *vk, bool force_sync)
msgq++;
}
}
- atomic_set(&vk->msgq_inited, 1);
+ /* Publish message queue info before allowing driver access. */
+ atomic_set_release(&vk->msgq_inited, 1);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0453/1518] misc: rtsx: add missing write register handling
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (451 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0452/1518] misc: bcm-vk: Use acquire/release for msgq_inited Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0454/1518] misc: ad525x_dpot: use driver core groups for sysfs files Greg Kroah-Hartman
` (545 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Gleb Markov, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gleb Markov <markov.gi@npc-ksb.ru>
[ Upstream commit 655faba1ccf195e22a7a83146ef6015e3271233c ]
If an error occurs at the stage of working with registers in conjunction
with MCU_Block, it will not be processed.
The occurrence of errors at this stage may signal an impact on writes to
the device's PCI registers and is a more global problem than a
driver-level security problem, but adding a handler would be a good
practice.
Add a missing error handling.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Fixes: c0e5f4e73a71 ("misc: rtsx: Add support for RTS5261")
Signed-off-by: Gleb Markov <markov.gi@npc-ksb.ru>
Link: https://patch.msgid.link/20260629130920.1260-1-markov.gi@npc-ksb.ru
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/misc/cardreader/rtsx_pcr.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/misc/cardreader/rtsx_pcr.c b/drivers/misc/cardreader/rtsx_pcr.c
index f9952d76d6ed7..84a49156a2475 100644
--- a/drivers/misc/cardreader/rtsx_pcr.c
+++ b/drivers/misc/cardreader/rtsx_pcr.c
@@ -1196,6 +1196,8 @@ static int rtsx_pci_init_hw(struct rtsx_pcr *pcr)
/* Gating real mcu clock */
err = rtsx_pci_write_register(pcr, RTS5261_FW_CFG1,
RTS5261_MCU_CLOCK_GATING, 0);
+ if (err < 0)
+ return err;
err = rtsx_pci_write_register(pcr, RTS5261_REG_FPDCTL,
SSC_POWER_DOWN, 0);
} else {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0454/1518] misc: ad525x_dpot: use driver core groups for sysfs files
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (452 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0453/1518] misc: rtsx: add missing write register handling Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0455/1518] misc: lan966x_pci: depopulate children on populate failure Greg Kroah-Hartman
` (544 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit e3a8557e88eb26278eda60bf64f2ef33ce7de8bf ]
ad_dpot_probe() creates per-RDAC sysfs files manually and then
optionally creates the command sysfs group. This leaves probe responsible
for rolling back partial sysfs state and makes remove responsible for
matching every file that probe created.
Move the device attributes into driver core dev_groups for the I2C and
SPI drivers and use an is_visible() callback to expose only the
attributes supported by the probed device. With this shape, the driver
core creates the sysfs files only after probe succeeds and removes them
before the remove callback frees the driver data.
Fixes: 4eb174bee6f8 ("ad525x_dpot: new driver for AD525x digital potentiometers")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260623015643.36508-1-pengpeng@iscas.ac.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/misc/ad525x_dpot-i2c.c | 1 +
drivers/misc/ad525x_dpot-spi.c | 1 +
drivers/misc/ad525x_dpot.c | 177 ++++++++++++++++++++-------------
drivers/misc/ad525x_dpot.h | 3 +
4 files changed, 112 insertions(+), 70 deletions(-)
diff --git a/drivers/misc/ad525x_dpot-i2c.c b/drivers/misc/ad525x_dpot-i2c.c
index 469478f7a1d33..896ad61bb9e17 100644
--- a/drivers/misc/ad525x_dpot-i2c.c
+++ b/drivers/misc/ad525x_dpot-i2c.c
@@ -105,6 +105,7 @@ MODULE_DEVICE_TABLE(i2c, ad_dpot_id);
static struct i2c_driver ad_dpot_i2c_driver = {
.driver = {
.name = "ad_dpot",
+ .dev_groups = ad_dpot_groups,
},
.probe = ad_dpot_i2c_probe,
.remove = ad_dpot_i2c_remove,
diff --git a/drivers/misc/ad525x_dpot-spi.c b/drivers/misc/ad525x_dpot-spi.c
index 263055bda48b7..1ebe629715a84 100644
--- a/drivers/misc/ad525x_dpot-spi.c
+++ b/drivers/misc/ad525x_dpot-spi.c
@@ -131,6 +131,7 @@ MODULE_DEVICE_TABLE(spi, ad_dpot_spi_id);
static struct spi_driver ad_dpot_spi_driver = {
.driver = {
.name = "ad_dpot",
+ .dev_groups = ad_dpot_groups,
},
.probe = ad_dpot_spi_probe,
.remove = ad_dpot_spi_remove,
diff --git a/drivers/misc/ad525x_dpot.c b/drivers/misc/ad525x_dpot.c
index 04683b981e54c..3b55b3f6c7f49 100644
--- a/drivers/misc/ad525x_dpot.c
+++ b/drivers/misc/ad525x_dpot.c
@@ -630,66 +630,132 @@ static struct attribute *ad525x_attributes_commands[] = {
NULL
};
-static const struct attribute_group ad525x_group_commands = {
- .attrs = ad525x_attributes_commands,
+static struct attribute *ad525x_attributes[] = {
+ &dev_attr_rdac0.attr,
+ &dev_attr_rdac1.attr,
+ &dev_attr_rdac2.attr,
+ &dev_attr_rdac3.attr,
+ &dev_attr_rdac4.attr,
+ &dev_attr_rdac5.attr,
+ &dev_attr_eeprom0.attr,
+ &dev_attr_eeprom1.attr,
+ &dev_attr_eeprom2.attr,
+ &dev_attr_eeprom3.attr,
+ &dev_attr_eeprom4.attr,
+ &dev_attr_eeprom5.attr,
+ &dev_attr_tolerance0.attr,
+ &dev_attr_tolerance1.attr,
+ &dev_attr_tolerance2.attr,
+ &dev_attr_tolerance3.attr,
+ &dev_attr_tolerance4.attr,
+ &dev_attr_tolerance5.attr,
+ &dev_attr_otp0.attr,
+ &dev_attr_otp1.attr,
+ &dev_attr_otp2.attr,
+ &dev_attr_otp3.attr,
+ &dev_attr_otp4.attr,
+ &dev_attr_otp5.attr,
+ &dev_attr_otp0en.attr,
+ &dev_attr_otp1en.attr,
+ &dev_attr_otp2en.attr,
+ &dev_attr_otp3en.attr,
+ &dev_attr_otp4en.attr,
+ &dev_attr_otp5en.attr,
+ &dev_attr_inc_all.attr,
+ &dev_attr_dec_all.attr,
+ &dev_attr_inc_all_6db.attr,
+ &dev_attr_dec_all_6db.attr,
+ NULL
};
-static int ad_dpot_add_files(struct device *dev,
- unsigned int features, unsigned int rdac)
+static int ad525x_attr_index(struct attribute *attr,
+ const struct attribute * const *attrs)
{
- int err = sysfs_create_file(&dev->kobj,
- dpot_attrib_wipers[rdac]);
- if (features & F_CMD_EEP)
- err |= sysfs_create_file(&dev->kobj,
- dpot_attrib_eeprom[rdac]);
- if (features & F_CMD_TOL)
- err |= sysfs_create_file(&dev->kobj,
- dpot_attrib_tolerance[rdac]);
- if (features & F_CMD_OTP) {
- err |= sysfs_create_file(&dev->kobj,
- dpot_attrib_otp_en[rdac]);
- err |= sysfs_create_file(&dev->kobj,
- dpot_attrib_otp[rdac]);
- }
+ int i;
- if (err)
- dev_err(dev, "failed to register sysfs hooks for RDAC%d\n",
- rdac);
+ for (i = 0; attrs[i]; i++)
+ if (attr == attrs[i])
+ return i;
- return err;
+ return -ENOENT;
}
-static inline void ad_dpot_remove_files(struct device *dev,
- unsigned int features, unsigned int rdac)
+static bool ad525x_is_command_attr(struct attribute *attr)
{
- sysfs_remove_file(&dev->kobj,
- dpot_attrib_wipers[rdac]);
- if (features & F_CMD_EEP)
- sysfs_remove_file(&dev->kobj,
- dpot_attrib_eeprom[rdac]);
- if (features & F_CMD_TOL)
- sysfs_remove_file(&dev->kobj,
- dpot_attrib_tolerance[rdac]);
- if (features & F_CMD_OTP) {
- sysfs_remove_file(&dev->kobj,
- dpot_attrib_otp_en[rdac]);
- sysfs_remove_file(&dev->kobj,
- dpot_attrib_otp[rdac]);
+ int i;
+
+ for (i = 0; ad525x_attributes_commands[i]; i++) {
+ if (attr == ad525x_attributes_commands[i])
+ return true;
}
+
+ return false;
+}
+
+static umode_t ad525x_is_visible(struct kobject *kobj, struct attribute *attr,
+ int n)
+{
+ struct device *dev = kobj_to_dev(kobj);
+ struct dpot_data *data = dev_get_drvdata(dev);
+ int rdac;
+
+ if (!data)
+ return 0;
+
+ rdac = ad525x_attr_index(attr, dpot_attrib_wipers);
+ if (rdac >= 0)
+ return data->wipers & BIT(rdac) ? attr->mode : 0;
+
+ rdac = ad525x_attr_index(attr, dpot_attrib_eeprom);
+ if (rdac >= 0)
+ return (data->wipers & BIT(rdac)) && (data->feat & F_CMD_EEP) ?
+ attr->mode : 0;
+
+ rdac = ad525x_attr_index(attr, dpot_attrib_tolerance);
+ if (rdac >= 0)
+ return (data->wipers & BIT(rdac)) && (data->feat & F_CMD_TOL) ?
+ attr->mode : 0;
+
+ rdac = ad525x_attr_index(attr, dpot_attrib_otp);
+ if (rdac >= 0)
+ return (data->wipers & BIT(rdac)) && (data->feat & F_CMD_OTP) ?
+ attr->mode : 0;
+
+ rdac = ad525x_attr_index(attr, dpot_attrib_otp_en);
+ if (rdac >= 0)
+ return (data->wipers & BIT(rdac)) && (data->feat & F_CMD_OTP) ?
+ attr->mode : 0;
+
+ if (ad525x_is_command_attr(attr))
+ return data->feat & F_CMD_INC ? attr->mode : 0;
+
+ return attr->mode;
}
+static const struct attribute_group ad525x_group = {
+ .attrs = ad525x_attributes,
+ .is_visible = ad525x_is_visible,
+};
+
+const struct attribute_group *ad_dpot_groups[] = {
+ &ad525x_group,
+ NULL
+};
+EXPORT_SYMBOL(ad_dpot_groups);
+
int ad_dpot_probe(struct device *dev,
struct ad_dpot_bus_data *bdata, unsigned long devid,
const char *name)
{
struct dpot_data *data;
- int i, err = 0;
+ int i;
data = kzalloc(sizeof(struct dpot_data), GFP_KERNEL);
if (!data) {
- err = -ENOMEM;
- goto exit;
+ dev_err(dev, "failed to create client for %s ID 0x%lX\n",
+ name, devid);
+ return -ENOMEM;
}
dev_set_drvdata(dev, data);
@@ -705,51 +771,22 @@ int ad_dpot_probe(struct device *dev,
data->wipers = DPOT_WIPERS(devid);
for (i = DPOT_RDAC0; i < MAX_RDACS; i++)
- if (data->wipers & (1 << i)) {
- err = ad_dpot_add_files(dev, data->feat, i);
- if (err)
- goto exit_remove_files;
+ if (data->wipers & BIT(i)) {
/* power-up midscale */
if (data->feat & F_RDACS_WONLY)
data->rdac_cache[i] = data->max_pos / 2;
}
- if (data->feat & F_CMD_INC)
- err = sysfs_create_group(&dev->kobj, &ad525x_group_commands);
-
- if (err) {
- dev_err(dev, "failed to register sysfs hooks\n");
- goto exit_free;
- }
-
dev_info(dev, "%s %d-Position Digital Potentiometer registered\n",
name, data->max_pos);
return 0;
-
-exit_remove_files:
- for (i = DPOT_RDAC0; i < MAX_RDACS; i++)
- if (data->wipers & (1 << i))
- ad_dpot_remove_files(dev, data->feat, i);
-
-exit_free:
- kfree(data);
- dev_set_drvdata(dev, NULL);
-exit:
- dev_err(dev, "failed to create client for %s ID 0x%lX\n",
- name, devid);
- return err;
}
EXPORT_SYMBOL(ad_dpot_probe);
void ad_dpot_remove(struct device *dev)
{
struct dpot_data *data = dev_get_drvdata(dev);
- int i;
-
- for (i = DPOT_RDAC0; i < MAX_RDACS; i++)
- if (data->wipers & (1 << i))
- ad_dpot_remove_files(dev, data->feat, i);
kfree(data);
}
diff --git a/drivers/misc/ad525x_dpot.h b/drivers/misc/ad525x_dpot.h
index 72a9d6801937c..2e877c89523b5 100644
--- a/drivers/misc/ad525x_dpot.h
+++ b/drivers/misc/ad525x_dpot.h
@@ -10,6 +10,8 @@
#include <linux/types.h>
+struct attribute_group;
+
#define DPOT_CONF(features, wipers, max_pos, uid) \
(((features) << 18) | (((wipers) & 0xFF) << 10) | \
((max_pos & 0xF) << 6) | (uid & 0x3F))
@@ -210,5 +212,6 @@ struct ad_dpot_bus_data {
int ad_dpot_probe(struct device *dev, struct ad_dpot_bus_data *bdata,
unsigned long devid, const char *name);
void ad_dpot_remove(struct device *dev);
+extern const struct attribute_group *ad_dpot_groups[];
#endif
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0455/1518] misc: lan966x_pci: depopulate children on populate failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (453 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0454/1518] misc: ad525x_dpot: use driver core groups for sysfs files Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0456/1518] cacheinfo: dont propagate DT/ACPI error when arch supplies info (arm64) Greg Kroah-Hartman
` (543 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Herve Codina, Pengpeng Hou,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit f6e2ed54db95286d9512b1cff38264e2f6299814 ]
lan966x_pci_probe() applies a device-tree overlay and then populates
platform children from the overlaid node. If
of_platform_default_populate() creates some children and then fails, the
current error path only unloads the overlay.
Depopulate the children before unloading the overlay on that failure
path, matching the remove path order.
Fixes: 185686beb464 ("misc: Add support for LAN966x PCI device")
Reviewed-by: Herve Codina <herve.codina@bootlin.com>
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260623015248.22721-1-pengpeng@iscas.ac.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/misc/lan966x_pci.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/misc/lan966x_pci.c b/drivers/misc/lan966x_pci.c
index 9c79b58137e52..f6e358389af77 100644
--- a/drivers/misc/lan966x_pci.c
+++ b/drivers/misc/lan966x_pci.c
@@ -183,6 +183,7 @@ static int lan966x_pci_probe(struct pci_dev *pdev, const struct pci_device_id *i
return 0;
err_unload_overlay:
+ of_platform_depopulate(dev);
lan966x_pci_unload_overlay(data);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0456/1518] cacheinfo: dont propagate DT/ACPI error when arch supplies info (arm64)
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (454 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0455/1518] misc: lan966x_pci: depopulate children on populate failure Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0457/1518] ppdev: prevent overflow when setting port timeout Greg Kroah-Hartman
` (542 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pierre Gondois, Breno Leitao,
Sudeep Holla, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Breno Leitao <leitao@debian.org>
[ Upstream commit 274259391c14166fcabae74f9fc0104223ff27a1 ]
cache_setup_properties() sets use_arch_info = true when DT/ACPI
provide no cache nodes and the arch can derive the topology from
CPU registers (e.g. arm64 reading CLIDR_EL1), but still returns the
original -ENOENT. cache_shared_cpu_map_setup() bails on that error
before the new flag can take effect, so the first CPU brought online
always trips a misleading warning:
cacheinfo: Unable to detect cache hierarchy for CPU 0
Subsequent CPUs skip cache_setup_properties() entirely because
use_arch_info is now true, which is why only CPU0 hits it. This is
reproducible on arm64 with the QEMU 'virt' machine, whose default DT
has no cache nodes.
Clear ret after setting use_arch_info so the caller proceeds and
populates the shared cpu map via the arch-supplied leaves.
Fixes: ef9f643a9f8b ("cacheinfo: Add use_arch[|_cache]_info field/function")
Reviewed-by: Pierre Gondois <pierre.gondois@arm.com>
Signed-off-by: Breno Leitao <leitao@debian.org>
Reviewed-by: Sudeep Holla <sudeep.holla@kernel.org>
Link: https://patch.msgid.link/20260611-cacheinfo-v2-1-6069ef066cf3@debian.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/base/cacheinfo.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/drivers/base/cacheinfo.c b/drivers/base/cacheinfo.c
index 613410705a47e..338804742dce3 100644
--- a/drivers/base/cacheinfo.c
+++ b/drivers/base/cacheinfo.c
@@ -382,9 +382,14 @@ static int cache_setup_properties(unsigned int cpu)
else if (!acpi_disabled)
ret = cache_setup_acpi(cpu);
- // Assume there is no cache information available in DT/ACPI from now.
- if (ret && use_arch_cache_info())
+ /*
+ * No DT/ACPI cache nodes; fall back to arch-derived topology (e.g.
+ * arm64 CLIDR_EL1) and clear the error to avoid a spurious warning.
+ */
+ if (ret && use_arch_cache_info()) {
use_arch_info = true;
+ ret = 0;
+ }
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0457/1518] ppdev: prevent overflow when setting port timeout
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (455 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0456/1518] cacheinfo: dont propagate DT/ACPI error when arch supplies info (arm64) Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0458/1518] ipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on remove Greg Kroah-Hartman
` (541 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Linmao Li, Arnd Bergmann,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linmao Li <lilinmao@kylinos.cn>
[ Upstream commit 3c0cf801ea2fa40daa5e7d1e6d32adca5ff75ad9 ]
PPSETTIME64 supplies the timeval fields as s64 values, but
pp_set_timeout() narrows tv_usec to int and calculates tv_sec * HZ in a
signed long. Large positive values can therefore be truncated or overflow
and install an unintended timeout.
Keep both fields as s64, reject a non-canonical microsecond value, and
use timespec64_to_jiffies() to cap excessively large timeouts at
MAX_JIFFY_OFFSET. This is a behavior change because both PPSETTIME
ioctls could previously accept values with tv_usec >= USEC_PER_SEC.
The validation follows the precedent set by sock_set_timeout().
Fixes: 3b9ab374a1e6 ("ppdev: convert to y2038 safe")
Signed-off-by: Linmao Li <lilinmao@kylinos.cn>
Reviewed-by: Arnd Bergmann <arnd@arndb.de>
Link: https://patch.msgid.link/20260716013923.19494-1-lilinmao@kylinos.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/char/ppdev.c | 10 ++++++----
1 file changed, 6 insertions(+), 4 deletions(-)
diff --git a/drivers/char/ppdev.c b/drivers/char/ppdev.c
index d1dfbd8d4d426..3dec6516a5eb1 100644
--- a/drivers/char/ppdev.c
+++ b/drivers/char/ppdev.c
@@ -340,15 +340,17 @@ static enum ieee1284_phase init_phase(int mode)
return IEEE1284_PH_FWD_IDLE;
}
-static int pp_set_timeout(struct pardevice *pdev, long tv_sec, int tv_usec)
+static int pp_set_timeout(struct pardevice *pdev, s64 tv_sec, s64 tv_usec)
{
+ struct timespec64 ts;
long to_jiffies;
- if ((tv_sec < 0) || (tv_usec < 0))
+ if (tv_sec < 0 || tv_usec < 0 || tv_usec >= USEC_PER_SEC)
return -EINVAL;
- to_jiffies = usecs_to_jiffies(tv_usec);
- to_jiffies += tv_sec * HZ;
+ ts.tv_sec = tv_sec;
+ ts.tv_nsec = tv_usec * NSEC_PER_USEC;
+ to_jiffies = timespec64_to_jiffies(&ts);
if (to_jiffies <= 0)
return -EINVAL;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0458/1518] ipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on remove
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (456 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0457/1518] ppdev: prevent overflow when setting port timeout Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0459/1518] char: xilinx_hwicap: unregister class on init errors Greg Kroah-Hartman
` (540 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Shuangpeng Bai, Pei Xiao,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pei Xiao <xiaopei01@kylinos.cn>
[ Upstream commit b6b5d64cb161a28347d64dc3168a636c4abb68d5 ]
Three issues arise when the device is removed while a tty session is
still active:
1. UAF of struct ipoctal: the remove callback frees ipoctal via
kfree() while tty ops may still access it. Fix by introducing
kref-based lifetime management — kref is taken in install() when
a tty is opened and released in cleanup() when the tty is finally
destroyed; remove() uses kref_put() instead of kfree().
2. NULL dereference in ipoctal_write_tty(): __ipoctal_remove()
frees xmit_buf via tty_port_free_xmit_buf() while a userspace
process may still hold the tty fd and call write(). Fix by
checking for NULL xmit_buf in ipoctal_write_tty().
3. UAF in ipoctal_cleanup(): ipack_put_carrier(ipoctal->dev)
dereferences ipoctal->dev after the ipack_device has been freed
by ipack_device_del(). Fix by caching ipoctal->carrier_owner
during probe() and calling module_put() on the cached pointer
directly in cleanup(), avoiding any access to ipoctal->dev.
Also introduce a "removed" flag in struct ipoctal, set at the start
of __ipoctal_remove(), and checked in every tty op that accesses
hardware resources (port_activate, write_tty, set_termios, hangup,
shutdown). This prevents page faults when devm_ioremap() regions
are unmapped after remove() returns.
Reported-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
Closes: https://lore.kernel.org/lkml/178144969601.60470.1257088106279546587@gmail.com/
Fixes: 05e5027efc9c ("Staging: ipack: move out of staging")
Signed-off-by: Pei Xiao <xiaopei01@kylinos.cn>
Link: https://patch.msgid.link/e3b0a90b07f079c5bcd5ca90d1dd3b79bb29adb5.1782870760.git.xiaopei01@kylinos.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/ipack/devices/ipoctal.c | 56 ++++++++++++++++++++++++++++++---
1 file changed, 52 insertions(+), 4 deletions(-)
diff --git a/drivers/ipack/devices/ipoctal.c b/drivers/ipack/devices/ipoctal.c
index ba2e9e52d72bf..474b58858dca6 100644
--- a/drivers/ipack/devices/ipoctal.c
+++ b/drivers/ipack/devices/ipoctal.c
@@ -10,6 +10,7 @@
#include <linux/device.h>
#include <linux/module.h>
#include <linux/interrupt.h>
+#include <linux/kref.h>
#include <linux/sched.h>
#include <linux/tty.h>
#include <linux/serial.h>
@@ -25,6 +26,8 @@
static const struct tty_operations ipoctal_fops;
+static void ipoctal_release(struct kref *kref);
+
struct ipoctal_channel {
struct ipoctal_stats stats;
unsigned int nb_bytes;
@@ -49,6 +52,9 @@ struct ipoctal {
struct tty_driver *tty_drv;
u8 __iomem *mem8_space;
u8 __iomem *int_space;
+ struct kref kref;
+ struct module *carrier_owner;
+ bool removed;
};
static inline struct ipoctal *chan_to_ipoctal(struct ipoctal_channel *chan,
@@ -70,8 +76,14 @@ static void ipoctal_reset_channel(struct ipoctal_channel *channel)
static int ipoctal_port_activate(struct tty_port *port, struct tty_struct *tty)
{
struct ipoctal_channel *channel;
+ struct ipoctal *ipoctal;
channel = dev_get_drvdata(tty->dev);
+ ipoctal = chan_to_ipoctal(channel, tty->index);
+
+
+ if (ipoctal->removed)
+ return -ENODEV;
/*
* Enable RX. TX will be enabled when
@@ -95,6 +107,7 @@ static int ipoctal_install(struct tty_driver *driver, struct tty_struct *tty)
if (res)
goto err_put_carrier;
+ kref_get(&ipoctal->kref);
tty->driver_data = channel;
return 0;
@@ -460,8 +473,13 @@ static ssize_t ipoctal_write_tty(struct tty_struct *tty, const u8 *buf,
size_t count)
{
struct ipoctal_channel *channel = tty->driver_data;
+ struct ipoctal *ipoctal = chan_to_ipoctal(channel, tty->index);
size_t char_copied;
+
+ if (ipoctal->removed || !channel->tty_port.xmit_buf)
+ return 0;
+
char_copied = ipoctal_copy_write_buffer(channel, buf, count);
/* As the IP-OCTAL 485 only supports half duplex, do it manually */
@@ -501,8 +519,13 @@ static void ipoctal_set_termios(struct tty_struct *tty,
unsigned char mr2 = 0;
unsigned char csr = 0;
struct ipoctal_channel *channel = tty->driver_data;
+ struct ipoctal *ipoctal = chan_to_ipoctal(channel, tty->index);
speed_t baud;
+
+ if (ipoctal->removed)
+ return;
+
cflag = tty->termios.c_cflag;
/* Disable and reset everything before change the setup */
@@ -631,10 +654,16 @@ static void ipoctal_hangup(struct tty_struct *tty)
{
unsigned long flags;
struct ipoctal_channel *channel = tty->driver_data;
+ struct ipoctal *ipoctal;
if (channel == NULL)
return;
+ ipoctal = chan_to_ipoctal(channel, tty->index);
+
+ if (ipoctal->removed)
+ return;
+
spin_lock_irqsave(&channel->lock, flags);
channel->nb_bytes = 0;
channel->pointer_read = 0;
@@ -651,10 +680,16 @@ static void ipoctal_hangup(struct tty_struct *tty)
static void ipoctal_shutdown(struct tty_struct *tty)
{
struct ipoctal_channel *channel = tty->driver_data;
+ struct ipoctal *ipoctal;
if (channel == NULL)
return;
+ ipoctal = chan_to_ipoctal(channel, tty->index);
+
+ if (ipoctal->removed)
+ return;
+
ipoctal_reset_channel(channel);
tty_port_set_initialized(&channel->tty_port, false);
}
@@ -664,8 +699,9 @@ static void ipoctal_cleanup(struct tty_struct *tty)
struct ipoctal_channel *channel = tty->driver_data;
struct ipoctal *ipoctal = chan_to_ipoctal(channel, tty->index);
- /* release the carrier driver */
- ipack_put_carrier(ipoctal->dev);
+ /* release the carrier driver via cached owner */
+ module_put(ipoctal->carrier_owner);
+ kref_put(&ipoctal->kref, ipoctal_release);
}
static const struct tty_operations ipoctal_fops = {
@@ -683,6 +719,13 @@ static const struct tty_operations ipoctal_fops = {
.cleanup = ipoctal_cleanup,
};
+static void ipoctal_release(struct kref *kref)
+{
+ struct ipoctal *ipoctal = container_of(kref, struct ipoctal, kref);
+
+ kfree(ipoctal);
+}
+
static int ipoctal_probe(struct ipack_device *dev)
{
int res;
@@ -692,7 +735,10 @@ static int ipoctal_probe(struct ipack_device *dev)
if (ipoctal == NULL)
return -ENOMEM;
+ kref_init(&ipoctal->kref);
+
ipoctal->dev = dev;
+ ipoctal->carrier_owner = dev->bus->owner;
res = ipoctal_inst_slot(ipoctal, dev->bus->bus_nr, dev->slot);
if (res)
goto out_uninst;
@@ -701,7 +747,7 @@ static int ipoctal_probe(struct ipack_device *dev)
return 0;
out_uninst:
- kfree(ipoctal);
+ kref_put(&ipoctal->kref, ipoctal_release);
return res;
}
@@ -709,6 +755,8 @@ static void __ipoctal_remove(struct ipoctal *ipoctal)
{
int i;
+ ipoctal->removed = true;
+
ipoctal->dev->bus->ops->free_irq(ipoctal->dev);
for (i = 0; i < NR_CHANNELS; i++) {
@@ -725,7 +773,7 @@ static void __ipoctal_remove(struct ipoctal *ipoctal)
tty_unregister_driver(ipoctal->tty_drv);
kfree(ipoctal->tty_drv->name);
tty_driver_kref_put(ipoctal->tty_drv);
- kfree(ipoctal);
+ kref_put(&ipoctal->kref, ipoctal_release);
}
static void ipoctal_remove(struct ipack_device *idev)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0459/1518] char: xilinx_hwicap: unregister class on init errors
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (457 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0458/1518] ipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on remove Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0460/1518] vfio/pci: clear vdev->msi_perm after freeing it on init failure Greg Kroah-Hartman
` (539 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ijae Kim, Myeonghun Pak,
Radhey Shyam Pandey, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Myeonghun Pak <mhun512@gmail.com>
[ Upstream commit e7e12b4cc0f0c3a2782aea084d4215e23f5512b3 ]
hwicap_module_init() registers icap_class before reserving the
character-device region and registering the platform driver. If either
of those later steps fails, the init path must undo the successful class
registration before returning an error.
Route the chrdev registration failure through a class unwind label, and
let the platform-driver registration failure fall through the existing
chrdev unwind before unregistering the class. The normal module exit path
is unchanged.
This issue was identified during our ongoing static-analysis research while
reviewing kernel code.
Fixes: ef141a0bb0dc ("[POWERPC] Xilinx: hwicap driver")
Co-developed-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
Reviewed-by: Radhey Shyam Pandey <radhey.shyam.pandey@amd.com>
Link: https://patch.msgid.link/20260623085604.89284-1-mhun512@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/char/xilinx_hwicap/xilinx_hwicap.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/char/xilinx_hwicap/xilinx_hwicap.c b/drivers/char/xilinx_hwicap/xilinx_hwicap.c
index 34a345dc5e724..9bb5fa642fd88 100644
--- a/drivers/char/xilinx_hwicap/xilinx_hwicap.c
+++ b/drivers/char/xilinx_hwicap/xilinx_hwicap.c
@@ -760,7 +760,7 @@ static int __init hwicap_module_init(void)
HWICAP_DEVICES,
DRIVER_NAME);
if (retval < 0)
- return retval;
+ goto failed_class;
retval = platform_driver_register(&hwicap_platform_driver);
if (retval)
@@ -771,6 +771,9 @@ static int __init hwicap_module_init(void)
failed:
unregister_chrdev_region(devt, HWICAP_DEVICES);
+ failed_class:
+ class_unregister(&icap_class);
+
return retval;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0460/1518] vfio/pci: clear vdev->msi_perm after freeing it on init failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (458 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0459/1518] char: xilinx_hwicap: unregister class on init errors Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0461/1518] soc: ti: knav_qmss_queue: Implement resource cleanup in remove() Greg Kroah-Hartman
` (538 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Weiming Shi, Xiang Mei,
Alex Williamson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xiang Mei <xmei5@asu.edu>
[ Upstream commit dc77acfeb979dded39b247b60fef0399536bfa77 ]
vfio_msi_cap_len() lazily allocates the per-device MSI permission table:
vdev->msi_perm = kmalloc_obj(struct perm_bits, GFP_KERNEL_ACCOUNT);
if (!vdev->msi_perm)
return -ENOMEM;
ret = init_pci_cap_msi_perm(vdev->msi_perm, len, flags);
if (ret) {
kfree(vdev->msi_perm);
return ret; /* vdev->msi_perm left dangling */
}
When init_pci_cap_msi_perm() -> alloc_perm_bits() fails with -ENOMEM, the
error path frees vdev->msi_perm but leaves the freed pointer stored in
it. vdev->msi_perm is not re-zeroed later because struct
vfio_pci_core_device is per-device and persists across open/close cycles,
and the vfio_config_init() error path returns without calling
vfio_config_free(). So the dangling pointer outlives the failed open.
That leads to two use-after-frees on the same device:
1. Reuse. The next vfio_config_init() sees the stale pointer at
"if (vdev->msi_perm) return len;" and reuses the freed object. MSI
config accesses in vfio_pci_config_rw_single() then dereference and
call the freed perm->readfn / perm->writefn function pointers.
2. Double free. A later vfio_config_free() runs free_perm_bits() and
kfree() on the already-freed object.
Fix it by NULLing vdev->msi_perm after the kfree(), matching the
NULL-after-free discipline already used in free_perm_bits() and
vfio_config_free().
BUG: KASAN: slab-use-after-free in vfio_pci_config_rw_single (drivers/vfio/pci/vfio_pci_config.c:1961)
Read of size 8 at addr ffff88800fcc88d0 by task exploit/143
Call Trace:
...
kasan_report (mm/kasan/report.c:595)
vfio_pci_config_rw_single (drivers/vfio/pci/vfio_pci_config.c:1961)
vfio_pci_config_rw (drivers/vfio/pci/vfio_pci_config.c:1986)
vfio_pci_rw (drivers/vfio/pci/vfio_pci_core.c:1599)
vfs_read (fs/read_write.c:572)
__x64_sys_pread64 (fs/read_write.c:764)
do_syscall_64 (arch/x86/entry/syscall_64.c:94)
...
Followed on device close by a double free of the same object:
Oops: general protection fault, probably for non-canonical address
0x1f63e0e8000008: 0000 [#1] SMP KASAN NOPTI
RIP: 0010:kfree (mm/slub.c:6711)
Call Trace:
vfio_config_free (drivers/vfio/pci/vfio_pci_config.c:1861)
vfio_pci_core_disable (drivers/vfio/pci/vfio_pci_core.c:685)
vfio_pci_core_close_device (drivers/vfio/pci/vfio_pci_core.c:777)
vfio_df_close (drivers/vfio/vfio_main.c:602)
vfio_device_fops_release (drivers/vfio/vfio_main.c:648)
__fput (fs/file_table.c:512)
__x64_sys_close (fs/open.c:1496)
do_syscall_64 (arch/x86/entry/syscall_64.c:94)
...
Kernel panic - not syncing: Fatal exception
Fixes: 30ea32ab1951 ("vfio/pci: Fix potential memory leak in vfio_msi_cap_len")
Reported-by: Weiming Shi <bestswngs@gmail.com>
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Xiang Mei <xmei5@asu.edu>
Link: https://lore.kernel.org/r/20260705014010.1297885-1-xmei5@asu.edu
Signed-off-by: Alex Williamson <alex@shazbot.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/vfio/pci/vfio_pci_config.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/vfio/pci/vfio_pci_config.c b/drivers/vfio/pci/vfio_pci_config.c
index 8f02f236b5b4b..1050bd7fd7ce6 100644
--- a/drivers/vfio/pci/vfio_pci_config.c
+++ b/drivers/vfio/pci/vfio_pci_config.c
@@ -1257,6 +1257,7 @@ static int vfio_msi_cap_len(struct vfio_pci_core_device *vdev, u8 pos)
ret = init_pci_cap_msi_perm(vdev->msi_perm, len, flags);
if (ret) {
kfree(vdev->msi_perm);
+ vdev->msi_perm = NULL;
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0461/1518] soc: ti: knav_qmss_queue: Implement resource cleanup in remove()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (459 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0460/1518] vfio/pci: clear vdev->msi_perm after freeing it on init failure Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0462/1518] soc: ti: knav_qmss: Remove debugfs file on teardown Greg Kroah-Hartman
` (537 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Nishanth Menon, Md Shofiqul Islam,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Md Shofiqul Islam <shofiqtest@gmail.com>
[ Upstream commit 10a1969353b20caa50c320717e054601631c0d3e ]
Implement the TODO in knav_queue_remove() by stopping PDSPs and
freeing queue regions and queue ranges before disabling runtime PM,
mirroring the cleanup performed in the probe error path.
Set device_ready to false before cleanup to prevent any further
use of the device during teardown.
This ensures resources are released on driver unbind and avoids
leaking queue/region state.
Suggested-by: Nishanth Menon <nm@ti.com>
Signed-off-by: Md Shofiqul Islam <shofiqtest@gmail.com>
Link: https://lore.kernel.org/linux-arm-kernel/20260506154114.2288-1-shofiqtest@gmail.com/
Signed-off-by: Nishanth Menon <nm@ti.com>
Stable-dep-of: 3c8178627599 ("soc: ti: knav_qmss: Remove debugfs file on teardown")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/soc/ti/knav_qmss_queue.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/drivers/soc/ti/knav_qmss_queue.c b/drivers/soc/ti/knav_qmss_queue.c
index 6e56e7609ccd3..3557ee5779b96 100644
--- a/drivers/soc/ti/knav_qmss_queue.c
+++ b/drivers/soc/ti/knav_qmss_queue.c
@@ -1884,7 +1884,12 @@ static int knav_queue_probe(struct platform_device *pdev)
static void knav_queue_remove(struct platform_device *pdev)
{
- /* TODO: Free resources */
+ struct knav_device *kdev = platform_get_drvdata(pdev);
+
+ device_ready = false;
+ knav_queue_stop_pdsps(kdev);
+ knav_queue_free_regions(kdev);
+ knav_free_queue_ranges(kdev);
pm_runtime_put_sync(&pdev->dev);
pm_runtime_disable(&pdev->dev);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0462/1518] soc: ti: knav_qmss: Remove debugfs file on teardown
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (460 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0461/1518] soc: ti: knav_qmss_queue: Implement resource cleanup in remove() Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0463/1518] mtd: intel-dg: wake card on operations Greg Kroah-Hartman
` (536 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Nishanth Menon,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit 3c817862759913097f11467ed4ed2bbf974dabaf ]
knav_queue_probe() creates the global qmss debugfs file whose show
callback reads the global knav_qdev state. knav_queue_remove() tears
down the queue manager resources but leaves the debugfs file published.
Save the debugfs dentry in struct knav_device and remove it during
teardown before the resources used by the show callback are released.
While touching the debugfs_create_file() call, spell the unchanged read-
only file mode as 0444.
Fixes: 41f93af900a2 ("soc: ti: add Keystone Navigator QMSS driver")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260706144706.96313-1-pengpeng@iscas.ac.cn
Signed-off-by: Nishanth Menon <nm@ti.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/soc/ti/knav_qmss.h | 1 +
drivers/soc/ti/knav_qmss_queue.c | 7 +++++--
2 files changed, 6 insertions(+), 2 deletions(-)
diff --git a/drivers/soc/ti/knav_qmss.h b/drivers/soc/ti/knav_qmss.h
index 9325e8ce2e25c..bd3426a30d958 100644
--- a/drivers/soc/ti/knav_qmss.h
+++ b/drivers/soc/ti/knav_qmss.h
@@ -304,6 +304,7 @@ struct knav_device {
struct list_head pools;
struct list_head pdsps;
struct list_head qmgrs;
+ struct dentry *debugfs_file;
enum qmss_version version;
};
diff --git a/drivers/soc/ti/knav_qmss_queue.c b/drivers/soc/ti/knav_qmss_queue.c
index 3557ee5779b96..6d775a261737c 100644
--- a/drivers/soc/ti/knav_qmss_queue.c
+++ b/drivers/soc/ti/knav_qmss_queue.c
@@ -1868,8 +1868,9 @@ static int knav_queue_probe(struct platform_device *pdev)
goto err;
}
- debugfs_create_file("qmss", S_IFREG | S_IRUGO, NULL, NULL,
- &knav_queue_debug_fops);
+ knav_qdev->debugfs_file =
+ debugfs_create_file("qmss", 0444, NULL, NULL,
+ &knav_queue_debug_fops);
device_ready = true;
return 0;
@@ -1887,6 +1888,8 @@ static void knav_queue_remove(struct platform_device *pdev)
struct knav_device *kdev = platform_get_drvdata(pdev);
device_ready = false;
+ debugfs_remove(kdev->debugfs_file);
+ kdev->debugfs_file = NULL;
knav_queue_stop_pdsps(kdev);
knav_queue_free_regions(kdev);
knav_free_queue_ranges(kdev);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0463/1518] mtd: intel-dg: wake card on operations
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (461 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0462/1518] soc: ti: knav_qmss: Remove debugfs file on teardown Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0464/1518] mtd: intel-dg: Fix runtime PM error path in probe Greg Kroah-Hartman
` (535 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alexander Usyskin, Miquel Raynal,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexander Usyskin <alexander.usyskin@intel.com>
[ Upstream commit 3e9c49d4c3063dcf7ddcdea4c5e3aa21eae359d0 ]
The Intel DG cards do not have separate power control for
persistent memory.
The memory is available when the whole card is awake.
Enable runtime PM in mtd driver to notify parent graphics driver
that whole card should be kept awake while nvm operations are
performed through this driver.
Signed-off-by: Alexander Usyskin <alexander.usyskin@intel.com>
Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com>
Stable-dep-of: df6f582df337 ("mtd: intel-dg: Fix runtime PM error path in probe")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/mtd/devices/mtd_intel_dg.c | 74 +++++++++++++++++++++++++-----
1 file changed, 62 insertions(+), 12 deletions(-)
diff --git a/drivers/mtd/devices/mtd_intel_dg.c b/drivers/mtd/devices/mtd_intel_dg.c
index 114e69135b8d9..7f751c48a76d4 100644
--- a/drivers/mtd/devices/mtd_intel_dg.c
+++ b/drivers/mtd/devices/mtd_intel_dg.c
@@ -15,14 +15,18 @@
#include <linux/module.h>
#include <linux/mtd/mtd.h>
#include <linux/mtd/partitions.h>
+#include <linux/pm_runtime.h>
#include <linux/string.h>
#include <linux/slab.h>
#include <linux/sizes.h>
#include <linux/types.h>
+#define INTEL_DG_NVM_RPM_TIMEOUT_MS 500
+
struct intel_dg_nvm {
struct kref refcnt;
struct mtd_info mtd;
+ struct device *dev;
struct mutex lock; /* region access lock */
void __iomem *base;
void __iomem *base2;
@@ -421,6 +425,8 @@ static int intel_dg_nvm_init(struct intel_dg_nvm *nvm, struct device *device,
unsigned int i, n;
int ret;
+ nvm->dev = device;
+
/* clean error register, previous errors are ignored */
idg_nvm_error(nvm);
@@ -498,6 +504,7 @@ static int intel_dg_mtd_erase(struct mtd_info *mtd, struct erase_info *info)
size_t len;
u8 region;
u64 addr;
+ int ret;
if (WARN_ON(!nvm))
return -EINVAL;
@@ -512,20 +519,29 @@ static int intel_dg_mtd_erase(struct mtd_info *mtd, struct erase_info *info)
total_len = info->len;
addr = info->addr;
+ ret = pm_runtime_resume_and_get(nvm->dev);
+ if (ret < 0) {
+ dev_err(&mtd->dev, "rpm: get failed %d\n", ret);
+ return ret;
+ }
+
+ ret = 0;
guard(mutex)(&nvm->lock);
while (total_len > 0) {
if (!IS_ALIGNED(addr, SZ_4K) || !IS_ALIGNED(total_len, SZ_4K)) {
dev_err(&mtd->dev, "unaligned erase %llx %zx\n", addr, total_len);
info->fail_addr = addr;
- return -ERANGE;
+ ret = -ERANGE;
+ break;
}
idx = idg_nvm_get_region(nvm, addr);
if (idx >= nvm->nregions) {
dev_err(&mtd->dev, "out of range");
info->fail_addr = MTD_FAIL_ADDR_UNKNOWN;
- return -ERANGE;
+ ret = -ERANGE;
+ break;
}
from = addr - nvm->regions[idx].offset;
@@ -541,14 +557,16 @@ static int intel_dg_mtd_erase(struct mtd_info *mtd, struct erase_info *info)
if (bytes < 0) {
dev_dbg(&mtd->dev, "erase failed with %zd\n", bytes);
info->fail_addr += nvm->regions[idx].offset;
- return bytes;
+ ret = bytes;
+ break;
}
addr += len;
total_len -= len;
}
- return 0;
+ pm_runtime_put_autosuspend(nvm->dev);
+ return ret;
}
static int intel_dg_mtd_read(struct mtd_info *mtd, loff_t from, size_t len,
@@ -577,17 +595,24 @@ static int intel_dg_mtd_read(struct mtd_info *mtd, loff_t from, size_t len,
if (len > nvm->regions[idx].size - from)
len = nvm->regions[idx].size - from;
+ ret = pm_runtime_resume_and_get(nvm->dev);
+ if (ret < 0) {
+ dev_err(&mtd->dev, "rpm: get failed %zd\n", ret);
+ return ret;
+ }
+
guard(mutex)(&nvm->lock);
ret = idg_read(nvm, region, from, len, buf);
if (ret < 0) {
dev_dbg(&mtd->dev, "read failed with %zd\n", ret);
- return ret;
+ } else {
+ *retlen = ret;
+ ret = 0;
}
- *retlen = ret;
-
- return 0;
+ pm_runtime_put_autosuspend(nvm->dev);
+ return ret;
}
static int intel_dg_mtd_write(struct mtd_info *mtd, loff_t to, size_t len,
@@ -616,17 +641,24 @@ static int intel_dg_mtd_write(struct mtd_info *mtd, loff_t to, size_t len,
if (len > nvm->regions[idx].size - to)
len = nvm->regions[idx].size - to;
+ ret = pm_runtime_resume_and_get(nvm->dev);
+ if (ret < 0) {
+ dev_err(&mtd->dev, "rpm: get failed %zd\n", ret);
+ return ret;
+ }
+
guard(mutex)(&nvm->lock);
ret = idg_write(nvm, region, to, len, buf);
if (ret < 0) {
dev_dbg(&mtd->dev, "write failed with %zd\n", ret);
- return ret;
+ } else {
+ *retlen = ret;
+ ret = 0;
}
- *retlen = ret;
-
- return 0;
+ pm_runtime_put_autosuspend(nvm->dev);
+ return ret;
}
static void intel_dg_nvm_release(struct kref *kref)
@@ -756,6 +788,21 @@ static int intel_dg_mtd_probe(struct auxiliary_device *aux_dev,
n++;
}
+ ret = devm_pm_runtime_enable(device);
+ if (ret < 0) {
+ dev_err(device, "rpm: enable failed %d\n", ret);
+ goto err_norpm;
+ }
+
+ pm_runtime_set_autosuspend_delay(device, INTEL_DG_NVM_RPM_TIMEOUT_MS);
+ pm_runtime_use_autosuspend(device);
+
+ ret = pm_runtime_resume_and_get(device);
+ if (ret < 0) {
+ dev_err(device, "rpm: get failed %d\n", ret);
+ goto err_norpm;
+ }
+
nvm->base = devm_ioremap_resource(device, &invm->bar);
if (IS_ERR(nvm->base)) {
ret = PTR_ERR(nvm->base);
@@ -784,9 +831,12 @@ static int intel_dg_mtd_probe(struct auxiliary_device *aux_dev,
dev_set_drvdata(&aux_dev->dev, nvm);
+ pm_runtime_put(device);
return 0;
err:
+ pm_runtime_put(device);
+err_norpm:
kref_put(&nvm->refcnt, intel_dg_nvm_release);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0464/1518] mtd: intel-dg: Fix runtime PM error path in probe
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (462 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0463/1518] mtd: intel-dg: wake card on operations Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0465/1518] mtd: mtdswap: Avoid freeing registered blktrans device twice Greg Kroah-Hartman
` (534 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Raag Jadav,
Miquel Raynal, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
[ Upstream commit df6f582df3377af316a60ca8ee0d590b2d03924d ]
intel_dg_mtd_probe() allocates region names before enabling runtime PM
and before calling pm_runtime_resume_and_get().
If kasprintf() fails while building a region name, the error path jumps
to err, which calls pm_runtime_put(). At that point there has not been a
successful pm_runtime_resume_and_get() call to balance, so the runtime PM
usage count can underflow.
Jump to err_norpm from the kasprintf() failure path, as the runtime PM
reference has not been acquired yet.
Fixes: 779c59274d03 ("mtd: intel-dg: Fix accessing regions before setting nregions")
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Reviewed-by: Raag Jadav <raag.jadav@intel.com>
Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/mtd/devices/mtd_intel_dg.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/mtd/devices/mtd_intel_dg.c b/drivers/mtd/devices/mtd_intel_dg.c
index 7f751c48a76d4..c9855d6f1f95e 100644
--- a/drivers/mtd/devices/mtd_intel_dg.c
+++ b/drivers/mtd/devices/mtd_intel_dg.c
@@ -780,7 +780,7 @@ static int intel_dg_mtd_probe(struct auxiliary_device *aux_dev,
dev_name(&aux_dev->dev), invm->regions[i].name);
if (!name) {
ret = -ENOMEM;
- goto err;
+ goto err_norpm;
}
nvm->regions[n].name = name;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0465/1518] mtd: mtdswap: Avoid freeing registered blktrans device twice
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (463 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0464/1518] mtd: intel-dg: Fix runtime PM error path in probe Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0466/1518] mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() Greg Kroah-Hartman
` (533 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ruoyu Wang, Miquel Raynal,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ruoyu Wang <ruoyuw560@gmail.com>
[ Upstream commit 779aa4c66a96bf43d2d62982ea1a9096a9128d87 ]
In mtdswap_add_mtd(), debugfs setup failure after successful blktrans
registration can free mbd_dev twice.
add_mtd_blktrans_dev() initializes the blktrans device reference and
publishes the disk. Once that succeeds, del_mtd_blktrans_dev() tears the
disk down and drops the blktrans reference; when that reference reaches
zero, blktrans_dev_release() frees the mtd_blktrans_dev.
The debugfs failure path called del_mtd_blktrans_dev(mbd_dev), then fell
through the common cleanup label and called kfree(mbd_dev) again. Clear
the local pointer after deregistration so the common cleanup can still
release the mtdswap state without freeing the blktrans object twice.
This issue was found by a static analysis checker and confirmed by
manual source review.
Fixes: e8e3edb95ce6 ("mtd: create per-device and module-scope debugfs entries")
Signed-off-by: Ruoyu Wang <ruoyuw560@gmail.com>
Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/mtd/mtdswap.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/mtd/mtdswap.c b/drivers/mtd/mtdswap.c
index 42ff7deace80c..d38528210350c 100644
--- a/drivers/mtd/mtdswap.c
+++ b/drivers/mtd/mtdswap.c
@@ -1452,6 +1452,7 @@ static void mtdswap_add_mtd(struct mtd_blktrans_ops *tr, struct mtd_info *mtd)
debugfs_failed:
del_mtd_blktrans_dev(mbd_dev);
+ mbd_dev = NULL;
cleanup:
mtdswap_cleanup(d);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0466/1518] mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (464 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0465/1518] mtd: mtdswap: Avoid freeing registered blktrans device twice Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0467/1518] perf ui hists: Fix uninitialized stack memory free on pstack allocation failure Greg Kroah-Hartman
` (532 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, zhouminqiang, Zhihao Cheng,
Miquel Raynal, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: zhouminqiang <zhouminqiang2@huawei.com>
[ Upstream commit b759d5bb6265419344ee9729fd0dc07ad85719d8 ]
mtd_add_partition() does not reject the special offset value
MTDPART_OFS_RETAIN (-3), which leads to a WARN_ON in
add_mtd_device() when called through the BLKPG ioctl on NAND
devices. The RETAIN value depends on cur_offset being the end of
the previous partition, but in the dynamic partition path
cur_offset equals the offset argument itself, causing undefined
behavior.
Commit 5daa7b21496a ("mtd: prepare partition add and del functions
for ioctl requests") introduced mtd_add_partition() and correctly
rejected MTDPART_OFS_APPEND (-1) and MTDPART_OFS_NXTBLK (-2),
since those special offsets rely on cur_offset tracking the
previous partition's end. However, commit 1a31368bf92e ("mtd: add a flags
for partitions which should just leave smth. after them")
later added MTDPART_OFS_RETAIN (-3) for the static
partition table path without updating mtd_add_partition() to
also reject this value.
With offset=-3 passed via BLKPG, the RETAIN size calculation in
allocate_partition() underflows (parent_size - 0xFFFFFFFFFFFFFFFD
= parent_size + 3). If the underflow result does not appear to
leave enough space, allocate_partition() jumps to out_register via
goto, skipping erasesize initialization. This results in
erasesize=0, which triggers:
WARN_ON((!mtd->erasesize || !master->_erase) &&
!(mtd->flags & MTD_NO_ERASE))
in add_mtd_device(). If the underflow result appears to leave
enough space, a bogus partition size is calculated, but the
"out of reach" sanity check catches the invalid offset and
creates a disabled empty partition (offset=0, size=0) instead
of returning an error.
Fix this by adding MTDPART_OFS_RETAIN to the rejection list in
mtd_add_partition(), consistent with the existing handling of
APPEND and NXTBLK.
Fixes: 1a31368bf92e ("mtd: add a flags for partitions which should just leave smth. after them")
Signed-off-by: zhouminqiang <zhouminqiang2@huawei.com>
Reviewed-by: Zhihao Cheng <chengzhihao1@huawei.com>
Signed-off-by: Miquel Raynal <miquel.raynal@bootlin.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/mtd/mtdpart.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/mtd/mtdpart.c b/drivers/mtd/mtdpart.c
index 2876501a78145..fb92b7a0ed5f7 100644
--- a/drivers/mtd/mtdpart.c
+++ b/drivers/mtd/mtdpart.c
@@ -254,7 +254,8 @@ int mtd_add_partition(struct mtd_info *parent, const char *name,
/* the direct offset is expected */
if (offset == MTDPART_OFS_APPEND ||
- offset == MTDPART_OFS_NXTBLK)
+ offset == MTDPART_OFS_NXTBLK ||
+ offset == MTDPART_OFS_RETAIN)
return -EINVAL;
if (length == MTDPART_SIZ_FULL)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0467/1518] perf ui hists: Fix uninitialized stack memory free on pstack allocation failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (465 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0466/1518] mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0468/1518] software node: Fix software_node_get_reference_args() with index -1 Greg Kroah-Hartman
` (531 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot, Ian Rogers,
Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ian Rogers <irogers@google.com>
[ Upstream commit d5fdde1c426922efabe86a515f0782b3eba40577 ]
Fixes heap corruption by initializing the options and actions arrays before
the pstack allocation check, preventing an uninitialized stack pointer from
being passed to free_popup_options() if the allocation fails.
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/linux-perf-users/20260709035230.6DBEE1F000E9@smtp.kernel.org/
Fixes: f2b487db45f2 ("perf hists browser: Fix possible memory leak")
Assisted-by: Antigravity:gemini-3.5-flash
Signed-off-by: Ian Rogers <irogers@google.com>
Link: https://lore.kernel.org/linux-perf-users/20260709035230.6DBEE1F000E9@smtp.kernel.org/
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/ui/browsers/hists.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/tools/perf/ui/browsers/hists.c b/tools/perf/ui/browsers/hists.c
index 487c0b08c0038..9c371b262b3b8 100644
--- a/tools/perf/ui/browsers/hists.c
+++ b/tools/perf/ui/browsers/hists.c
@@ -3064,15 +3064,15 @@ static int evsel__hists_browse(struct evsel *evsel, int nr_events, const char *h
browser->min_pcnt = min_pcnt;
hist_browser__update_nr_entries(browser);
+ memset(options, 0, sizeof(options));
+ memset(actions, 0, sizeof(actions));
+
browser->pstack = pstack__new(3);
if (browser->pstack == NULL)
goto out;
ui_helpline__push(helpline);
- memset(options, 0, sizeof(options));
- memset(actions, 0, sizeof(actions));
-
if (symbol_conf.col_width_list_str)
perf_hpp__set_user_width(symbol_conf.col_width_list_str);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0468/1518] software node: Fix software_node_get_reference_args() with index -1
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (466 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0467/1518] perf ui hists: Fix uninitialized stack memory free on pstack allocation failure Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0469/1518] driver core: soc: Unregister bus on early device registration failure Greg Kroah-Hartman
` (530 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Alban Bedel, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alban Bedel <alban.bedel@lht.dlh.de>
[ Upstream commit ba3dedcf3bd47017307595a7e54924198f018246 ]
The bounds check for the index passed to
software_node_get_reference_args() was failing when passed UINT_MAX,
this in turn would lead to an out of bound access in the property
array. Fix the bound check to also cover the UINT_MAX case.
Fixes: 31e4e12e0e960 ("software node: Correct a OOB check in software_node_get_reference_args()")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/linux-devicetree/20260611103904.7CB131F00893@smtp.kernel.org/
Signed-off-by: Alban Bedel <alban.bedel@lht.dlh.de>
Link: https://patch.msgid.link/20260611164005.2930205-1-alban.bedel@lht.dlh.de
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/base/swnode.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/base/swnode.c b/drivers/base/swnode.c
index be1e9e61a7bf4..1e08492935eeb 100644
--- a/drivers/base/swnode.c
+++ b/drivers/base/swnode.c
@@ -529,7 +529,7 @@ software_node_get_reference_args(const struct fwnode_handle *fwnode,
if (prop->is_inline)
return -EINVAL;
- if ((index + 1) * sizeof(*ref) > prop->length)
+ if (index >= prop->length / sizeof(*ref))
return -ENOENT;
ref_array = prop->pointer;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0469/1518] driver core: soc: Unregister bus on early device registration failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (467 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0468/1518] software node: Fix software_node_get_reference_args() with index -1 Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0470/1518] drm/msm/a6xx: Fix RBBM_CLOCK_CNTL3_TP0 value in a730_hwcg Greg Kroah-Hartman
` (529 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yuho Choi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuho Choi <dbgh9129@gmail.com>
[ Upstream commit 45dfa004893dfeae182ec27eddbd153c6d4ddbf9 ]
soc_bus_register() registers the SoC bus before registering a deferred
early SoC device. If soc_device_register() fails in that path, the
function returns the error directly and leaves the bus registered.
Store the returned SoC device pointer explicitly so the success and
error cases are handled separately. On failure, clear soc_bus_registered
and unregister the bus before returning the error.
Fixes: 6e12db376b60 ("base: soc: Allow early registration of a single SoC device")
Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
Link: https://patch.msgid.link/20260615180746.713540-1-dbgh9129@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/base/soc.c | 15 +++++++++++++--
1 file changed, 13 insertions(+), 2 deletions(-)
diff --git a/drivers/base/soc.c b/drivers/base/soc.c
index 282c38aece0de..c43940940aa34 100644
--- a/drivers/base/soc.c
+++ b/drivers/base/soc.c
@@ -194,6 +194,7 @@ EXPORT_SYMBOL_GPL(soc_device_unregister);
static int __init soc_bus_register(void)
{
+ struct soc_device *soc_dev;
int ret;
ret = bus_register(&soc_bus_type);
@@ -201,10 +202,20 @@ static int __init soc_bus_register(void)
return ret;
soc_bus_registered = true;
- if (early_soc_dev_attr)
- return PTR_ERR(soc_device_register(early_soc_dev_attr));
+ if (early_soc_dev_attr) {
+ soc_dev = soc_device_register(early_soc_dev_attr);
+ if (IS_ERR(soc_dev)) {
+ ret = PTR_ERR(soc_dev);
+ goto err_unregister_bus;
+ }
+ }
return 0;
+
+err_unregister_bus:
+ soc_bus_registered = false;
+ bus_unregister(&soc_bus_type);
+ return ret;
}
core_initcall(soc_bus_register);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0470/1518] drm/msm/a6xx: Fix RBBM_CLOCK_CNTL3_TP0 value in a730_hwcg
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (468 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0469/1518] driver core: soc: Unregister bus on early device registration failure Greg Kroah-Hartman
@ 2026-09-12 6:43 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0471/1518] bpf: Reject arena frees below the arena base Greg Kroah-Hartman
` (528 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:43 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Puranam V G Tejaswi, Konrad Dybcio,
Akhil P Oommen, Rob Clark, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Puranam V G Tejaswi <puranam.tejaswi@oss.qualcomm.com>
[ Upstream commit 01bcc0398f43099acb407a6067481e635c3e1b84 ]
The RBBM_CLOCK_CNTL3_TP0 entry in a730_hwcg has bits[19:16] set to 2
(clock gating enabled for that TP0 stage). As per the latest
recommendation, clear this nibble to disable clock gating for this
particular stage.
Fixes: 9588d2f860a4 ("drm/msm/a6xx: Add A730 support")
Signed-off-by: Puranam V G Tejaswi <puranam.tejaswi@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Akhil P Oommen <akhilpo@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/740955/
Message-ID: <20260718-eliza-gpu-v2-1-64379dbebd7a@oss.qualcomm.com>
Signed-off-by: Rob Clark <robin.clark@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/adreno/a6xx_catalog.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/msm/adreno/a6xx_catalog.c b/drivers/gpu/drm/msm/adreno/a6xx_catalog.c
index 31974a4d7e14b..b43850966a5f6 100644
--- a/drivers/gpu/drm/msm/adreno/a6xx_catalog.c
+++ b/drivers/gpu/drm/msm/adreno/a6xx_catalog.c
@@ -1167,7 +1167,7 @@ static const struct adreno_reglist a730_hwcg[] = {
{ REG_A6XX_RBBM_CLOCK_DELAY_SP0, 0x00000080 },
{ REG_A6XX_RBBM_CLOCK_CNTL_TP0, 0x22222220 },
{ REG_A6XX_RBBM_CLOCK_CNTL2_TP0, 0x22222222 },
- { REG_A6XX_RBBM_CLOCK_CNTL3_TP0, 0x22222222 },
+ { REG_A6XX_RBBM_CLOCK_CNTL3_TP0, 0x22220222 },
{ REG_A6XX_RBBM_CLOCK_CNTL4_TP0, 0x00222222 },
{ REG_A6XX_RBBM_CLOCK_HYST_TP0, 0x77777777 },
{ REG_A6XX_RBBM_CLOCK_HYST2_TP0, 0x77777777 },
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0471/1518] bpf: Reject arena frees below the arena base
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (469 preceding siblings ...)
2026-09-12 6:43 ` [PATCH 6.18 0470/1518] drm/msm/a6xx: Fix RBBM_CLOCK_CNTL3_TP0 value in a730_hwcg Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0472/1518] dmaengine: dw-edma: Terminate all descriptors without callbacks Greg Kroah-Hartman
` (527 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yiyang Chen, Emil Tsalapatis,
Kumar Kartikeya Dwivedi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yiyang Chen <chenyy23@mails.tsinghua.edu.cn>
[ Upstream commit b5a71cb2db6d84ac0042549dcec266b18429d41e ]
bpf_arena_free_pages() accepts scalar arena addresses. The runtime
masks the address to the low 32 bits and reconstructs a full user
address from the arena base before returning the range to the arena
free tree.
When the scalar value is below the low 32 bits of the arena base,
full_uaddr falls below user_vm_start. The existing upper-end clipping
then turns this into an out-of-range free-tree offset. A later
allocation can reuse that offset and return an address below the arena
mapping.
Reject such frees before computing the clipped range.
Fixes: 317460317a02a ("bpf: Introduce bpf_arena.")
Signed-off-by: Yiyang Chen <chenyy23@mails.tsinghua.edu.cn>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Link: https://lore.kernel.org/bpf/20260717-c10-031-public-bpf-next-v2-b4-v2-1-54b555443a7c@mails.tsinghua.edu.cn
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/arena.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/kernel/bpf/arena.c b/kernel/bpf/arena.c
index dafa179da0c9c..51227c8d2b1e4 100644
--- a/kernel/bpf/arena.c
+++ b/kernel/bpf/arena.c
@@ -534,6 +534,8 @@ static void arena_free_pages(struct bpf_arena *arena, long uaddr, long page_cnt)
uaddr = (u32)uaddr;
uaddr &= PAGE_MASK;
full_uaddr = clear_lo32(arena->user_vm_start) + uaddr;
+ if (full_uaddr < arena->user_vm_start)
+ return;
uaddr_end = min(arena->user_vm_end, full_uaddr + (page_cnt << PAGE_SHIFT));
if (full_uaddr >= uaddr_end)
return;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0472/1518] dmaengine: dw-edma: Terminate all descriptors without callbacks
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (470 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0471/1518] bpf: Reject arena frees below the arena base Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0473/1518] dmaengine: dw-edma: Serialize abort state updates Greg Kroah-Hartman
` (526 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Li, Koichiro Den, Vinod Koul,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Koichiro Den <den@valinux.co.jp>
[ Upstream commit 99109a51efd28c9a661fbfb9469b023c517b31d1 ]
The DMA Engine client documentation says in the "Terminate APIs" section
of Documentation/driver-api/dmaengine/client.rst:
"No callback functions will be called for any incomplete transfers."
dw-edma instead calls vchan_cookie_complete() when a deferred STOP reaches
the interrupt handler. This schedules a callback for the active descriptor
and leaves other issued or submitted descriptors queued. A late callback
after dmaengine_terminate_sync() can dereference client state that has
already been freed, while leftover descriptors may later restart into
reused buffers or leak.
Move all issued and submitted descriptors to the terminated list whenever
termination completes. For a pending STOP, do this from both the DONE and
ABORT paths. Complete their cookies in order without scheduling callbacks.
A STOP can remain pending until the running transfer raises an
interrupt. Make device_synchronize() wait for such a pending STOP to
complete before releasing terminated descriptors. Reuse it from
free_chan_resources(), then release the remaining virt-dma resources.
Sleep instead of busy-polling while waiting, and warn if the existing
timeout expires.
Fixes: e63d79d1ffcd ("dmaengine: Add Synopsys eDMA IP core driver")
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Koichiro Den <den@valinux.co.jp>
Link: https://patch.msgid.link/20260717180639.2643243-3-den@valinux.co.jp
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/dw-edma/dw-edma-core.c | 90 +++++++++++++++++++++++++-----
1 file changed, 76 insertions(+), 14 deletions(-)
diff --git a/drivers/dma/dw-edma/dw-edma-core.c b/drivers/dma/dw-edma/dw-edma-core.c
index 5b35faf567bb8..b4f9d67726aad 100644
--- a/drivers/dma/dw-edma/dw-edma-core.c
+++ b/drivers/dma/dw-edma/dw-edma-core.c
@@ -7,6 +7,7 @@
*/
#include <linux/module.h>
+#include <linux/delay.h>
#include <linux/device.h>
#include <linux/kernel.h>
#include <linux/dmaengine.h>
@@ -201,6 +202,35 @@ static int dw_edma_start_transfer(struct dw_edma_chan *chan)
return 1;
}
+static void dw_edma_terminate_vdesc(struct virt_dma_desc *vd)
+{
+ list_del(&vd->node);
+ dma_cookie_complete(&vd->tx);
+ vchan_terminate_vdesc(vd);
+}
+
+static void dw_edma_terminate_vdesc_list(struct list_head *head)
+{
+ struct virt_dma_desc *vd, *_vd;
+
+ list_for_each_entry_safe(vd, _vd, head, node)
+ dw_edma_terminate_vdesc(vd);
+}
+
+/* Must be called with vc.lock held. */
+static void dw_edma_terminate_all_descs(struct dw_edma_chan *chan)
+{
+ /*
+ * This order must not be reversed. Cookies are assigned when
+ * descriptors are submitted, so desc_issued contains older cookies
+ * than desc_submitted. Completing desc_submitted first could move
+ * chan->vc.chan.completed_cookie backwards when desc_issued is
+ * terminated afterwards.
+ */
+ dw_edma_terminate_vdesc_list(&chan->vc.desc_issued);
+ dw_edma_terminate_vdesc_list(&chan->vc.desc_submitted);
+}
+
static void dw_edma_device_caps(struct dma_chan *dchan,
struct dma_slave_caps *caps)
{
@@ -272,20 +302,22 @@ static int dw_edma_device_terminate_all(struct dma_chan *dchan)
struct dw_edma_chan *chan = dchan2dw_edma_chan(dchan);
int err = 0;
+ guard(spinlock_irqsave)(&chan->vc.lock);
+
if (!chan->configured) {
- /* Do nothing */
+ dw_edma_terminate_all_descs(chan);
} else if (chan->status == EDMA_ST_PAUSE) {
+ dw_edma_terminate_all_descs(chan);
chan->status = EDMA_ST_IDLE;
- chan->configured = false;
} else if (chan->status == EDMA_ST_IDLE) {
- chan->configured = false;
+ dw_edma_terminate_all_descs(chan);
} else if (dw_edma_core_ch_status(chan) == DMA_COMPLETE) {
/*
* The channel is in a false BUSY state, probably didn't
* receive or lost an interrupt
*/
+ dw_edma_terminate_all_descs(chan);
chan->status = EDMA_ST_IDLE;
- chan->configured = false;
} else if (chan->request > EDMA_REQ_PAUSE) {
err = -EPERM;
} else {
@@ -641,8 +673,7 @@ static void dw_edma_done_interrupt(struct dw_edma_chan *chan)
break;
case EDMA_REQ_STOP:
- list_del(&vd->node);
- vchan_cookie_complete(vd);
+ dw_edma_terminate_all_descs(chan);
chan->request = EDMA_REQ_NONE;
chan->status = EDMA_ST_IDLE;
break;
@@ -661,7 +692,9 @@ static void dw_edma_abort_interrupt(struct dw_edma_chan *chan)
spin_lock_irqsave(&chan->vc.lock, flags);
vd = vchan_next_desc(&chan->vc);
- if (vd) {
+ if (vd && chan->request == EDMA_REQ_STOP) {
+ dw_edma_terminate_all_descs(chan);
+ } else if (vd) {
dw_hdma_set_callback_result(vd, DMA_TRANS_ABORTED);
list_del(&vd->node);
vchan_cookie_complete(vd);
@@ -709,21 +742,49 @@ static int dw_edma_alloc_chan_resources(struct dma_chan *dchan)
return 0;
}
-static void dw_edma_free_chan_resources(struct dma_chan *dchan)
+static void dw_edma_wait_termination(struct dma_chan *dchan)
{
+ struct dw_edma_chan *chan = dchan2dw_edma_chan(dchan);
unsigned long timeout = jiffies + msecs_to_jiffies(5000);
- int ret;
+ bool stopping;
+ /*
+ * A STOP may be deferred to a later interrupt while the channel is still
+ * running. Wait until that handler completes the termination.
+ */
while (time_before(jiffies, timeout)) {
- ret = dw_edma_device_terminate_all(dchan);
- if (!ret)
- break;
+ scoped_guard(spinlock_irqsave, &chan->vc.lock)
+ stopping = chan->request == EDMA_REQ_STOP;
- if (time_after_eq(jiffies, timeout))
+ if (!stopping)
return;
- cpu_relax();
+ fsleep(1000);
}
+
+ dev_warn(chan->dw->chip->dev,
+ "timeout waiting for channel termination\n");
+}
+
+static void dw_edma_device_synchronize(struct dma_chan *dchan)
+{
+ struct dw_edma_chan *chan = dchan2dw_edma_chan(dchan);
+
+ dw_edma_wait_termination(dchan);
+ vchan_synchronize(&chan->vc);
+}
+
+static void dw_edma_free_chan_resources(struct dma_chan *dchan)
+{
+ struct dw_edma_chan *chan = dchan2dw_edma_chan(dchan);
+
+ dw_edma_device_terminate_all(dchan);
+ dw_edma_device_synchronize(dchan);
+
+ scoped_guard(spinlock_irqsave, &chan->vc.lock)
+ chan->configured = false;
+
+ vchan_free_chan_resources(&chan->vc);
}
static int dw_edma_channel_setup(struct dw_edma *dw, u32 wr_alloc, u32 rd_alloc)
@@ -820,6 +881,7 @@ static int dw_edma_channel_setup(struct dw_edma *dw, u32 wr_alloc, u32 rd_alloc)
dma->device_pause = dw_edma_device_pause;
dma->device_resume = dw_edma_device_resume;
dma->device_terminate_all = dw_edma_device_terminate_all;
+ dma->device_synchronize = dw_edma_device_synchronize;
dma->device_issue_pending = dw_edma_device_issue_pending;
dma->device_tx_status = dw_edma_device_tx_status;
dma->device_prep_slave_sg = dw_edma_device_prep_slave_sg;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0473/1518] dmaengine: dw-edma: Serialize abort state updates
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (471 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0472/1518] dmaengine: dw-edma: Terminate all descriptors without callbacks Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0474/1518] dmaengine: dw-edma: Serialize channel state checks Greg Kroah-Hartman
` (525 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Li, Koichiro Den, Vinod Koul,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Koichiro Den <den@valinux.co.jp>
[ Upstream commit dd80e259f65d932634e26d366570d71669ef6654 ]
dw_edma_abort_interrupt() drops vc.lock before changing request and
status. issue_pending() can acquire the lock in that small window,
observe the old busy state, and skip starting queued descriptors. Then
the abort handler overwrites the channel status as idle, leaving the new
descriptors stranded for good.
Keep descriptor completion and the state transition in the same critical
section.
Fixes: e63d79d1ffcd ("dmaengine: Add Synopsys eDMA IP core driver")
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Koichiro Den <den@valinux.co.jp>
Link: https://patch.msgid.link/20260717180639.2643243-4-den@valinux.co.jp
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/dw-edma/dw-edma-core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/dma/dw-edma/dw-edma-core.c b/drivers/dma/dw-edma/dw-edma-core.c
index b4f9d67726aad..bbbfdadfe3e6f 100644
--- a/drivers/dma/dw-edma/dw-edma-core.c
+++ b/drivers/dma/dw-edma/dw-edma-core.c
@@ -699,9 +699,9 @@ static void dw_edma_abort_interrupt(struct dw_edma_chan *chan)
list_del(&vd->node);
vchan_cookie_complete(vd);
}
- spin_unlock_irqrestore(&chan->vc.lock, flags);
chan->request = EDMA_REQ_NONE;
chan->status = EDMA_ST_IDLE;
+ spin_unlock_irqrestore(&chan->vc.lock, flags);
}
static inline irqreturn_t dw_edma_interrupt_write(int irq, void *data)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0474/1518] dmaengine: dw-edma: Serialize channel state checks
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (472 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0473/1518] dmaengine: dw-edma: Serialize abort state updates Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0475/1518] dmaengine: dw-edma: Clear stale requests on termination Greg Kroah-Hartman
` (524 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Li, Koichiro Den, Vinod Koul,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Koichiro Den <den@valinux.co.jp>
[ Upstream commit f7d1619f3e10c619b62c6cd6d95371b5c526c85a ]
pause() and resume() read and update channel state without holding vc.lock,
while the interrupt handlers update the same state under it. Take the same
lock around those state checks so that request, status, and configured stay
consistent.
For example, pause() can observe EDMA_ST_BUSY right before the interrupt
handler completes the final descriptor and moves the channel to
EDMA_ST_IDLE, and then record EDMA_REQ_PAUSE on an already idle channel. No
further interrupt will acknowledge the request, and since issue_pending()
requires EDMA_REQ_NONE, the channel is wedged for good: terminate_all()
leaves the stale request behind, so even reconfiguring the channel does not
recover it.
issue_pending() already runs under vc.lock, but it tests configured before
taking it. Move that test under the lock as well, so configured, request,
and status are evaluated as one channel-state snapshot.
Fixes: e63d79d1ffcd ("dmaengine: Add Synopsys eDMA IP core driver")
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Koichiro Den <den@valinux.co.jp>
Link: https://patch.msgid.link/20260717180639.2643243-6-den@valinux.co.jp
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/dw-edma/dw-edma-core.c | 10 ++++++----
1 file changed, 6 insertions(+), 4 deletions(-)
diff --git a/drivers/dma/dw-edma/dw-edma-core.c b/drivers/dma/dw-edma/dw-edma-core.c
index bbbfdadfe3e6f..352c2f475ba03 100644
--- a/drivers/dma/dw-edma/dw-edma-core.c
+++ b/drivers/dma/dw-edma/dw-edma-core.c
@@ -265,6 +265,8 @@ static int dw_edma_device_pause(struct dma_chan *dchan)
struct dw_edma_chan *chan = dchan2dw_edma_chan(dchan);
int err = 0;
+ guard(spinlock_irqsave)(&chan->vc.lock);
+
if (!chan->configured)
err = -EPERM;
else if (chan->status != EDMA_ST_BUSY)
@@ -282,6 +284,8 @@ static int dw_edma_device_resume(struct dma_chan *dchan)
struct dw_edma_chan *chan = dchan2dw_edma_chan(dchan);
int err = 0;
+ guard(spinlock_irqsave)(&chan->vc.lock);
+
if (!chan->configured) {
err = -EPERM;
} else if (chan->status != EDMA_ST_PAUSE) {
@@ -332,11 +336,9 @@ static void dw_edma_device_issue_pending(struct dma_chan *dchan)
struct dw_edma_chan *chan = dchan2dw_edma_chan(dchan);
unsigned long flags;
- if (!chan->configured)
- return;
-
spin_lock_irqsave(&chan->vc.lock, flags);
- if (vchan_issue_pending(&chan->vc) && chan->request == EDMA_REQ_NONE &&
+ if (chan->configured && vchan_issue_pending(&chan->vc) &&
+ chan->request == EDMA_REQ_NONE &&
chan->status == EDMA_ST_IDLE) {
chan->status = EDMA_ST_BUSY;
dw_edma_start_transfer(chan);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0475/1518] dmaengine: dw-edma: Clear stale requests on termination
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (473 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0474/1518] dmaengine: dw-edma: Serialize channel state checks Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0476/1518] ASoC: meson: Keep link pointers valid on realloc failure Greg Kroah-Hartman
` (523 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Frank Li, Koichiro Den, Vinod Koul,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Koichiro Den <den@valinux.co.jp>
[ Upstream commit c0d9c6275adcca7c0ca5f4270bf88026f9864bd1 ]
terminate_all() can finish immediately when the channel is unconfigured,
paused, idle, or already stopped in hardware. A pending PAUSE request can
survive these paths and block issue_pending() even after termination.
Clear the request whenever termination leaves the channel idle. A running
channel keeps its STOP request until the interrupt handler consumes it.
Fixes: e63d79d1ffcd ("dmaengine: Add Synopsys eDMA IP core driver")
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Koichiro Den <den@valinux.co.jp>
Link: https://patch.msgid.link/20260717180639.2643243-7-den@valinux.co.jp
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/dma/dw-edma/dw-edma-core.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/dma/dw-edma/dw-edma-core.c b/drivers/dma/dw-edma/dw-edma-core.c
index 352c2f475ba03..cb34385d605e3 100644
--- a/drivers/dma/dw-edma/dw-edma-core.c
+++ b/drivers/dma/dw-edma/dw-edma-core.c
@@ -327,6 +327,8 @@ static int dw_edma_device_terminate_all(struct dma_chan *dchan)
} else {
chan->request = EDMA_REQ_STOP;
}
+ if (chan->status == EDMA_ST_IDLE)
+ chan->request = EDMA_REQ_NONE;
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0476/1518] ASoC: meson: Keep link pointers valid on realloc failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (474 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0475/1518] dmaengine: dw-edma: Clear stale requests on termination Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0477/1518] phy: starfive: Fix runtime PM cleanup in JH7110 DPHY TX probe Greg Kroah-Hartman
` (522 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Linmao Li, Jerome Brunet, Mark Brown,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linmao Li <lilinmao@kylinos.cn>
[ Upstream commit 2aaa41cf974f83a6fb105422bac4e2f107150774 ]
meson_card_reallocate_links() grows the DAI link and private data
arrays with two consecutive krealloc() calls and updates the owner
pointers only after both calls have succeeded.
A successful krealloc() may move the data: it frees the old block and
returns a new one. When that happens for the link array and the second
krealloc() then fails, card->dai_link still points to the block that
krealloc() already freed, and the error path frees the new block too.
The probe error path then calls meson_card_clean_references(), which
dereferences card->dai_link and kfree()s it again, resulting in a
use-after-free and a double free.
Commit card->dai_link and card->num_links right after the first
krealloc() succeeds, so the pointer always refers to a valid allocation
that meson_card_clean_references() can walk and free. krealloc() with
__GFP_ZERO zero-initializes the added entries, so walking them on the
error path is safe. With both failure paths reduced to a plain return,
drop the goto labels and the error message.
Fixes: 7864a79f37b5 ("ASoC: meson: add axg sound card support")
Signed-off-by: Linmao Li <lilinmao@kylinos.cn>
Reviewed-by: Jerome Brunet <jbrunet@baylibre.com>
Link: https://patch.msgid.link/20260717012433.1432285-1-lilinmao@kylinos.cn
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/meson/meson-card-utils.c | 17 ++++++-----------
1 file changed, 6 insertions(+), 11 deletions(-)
diff --git a/sound/soc/meson/meson-card-utils.c b/sound/soc/meson/meson-card-utils.c
index cdb759b466ad4..8617a4661a339 100644
--- a/sound/soc/meson/meson-card-utils.c
+++ b/sound/soc/meson/meson-card-utils.c
@@ -50,25 +50,20 @@ int meson_card_reallocate_links(struct snd_soc_card *card,
num_links * sizeof(*priv->card.dai_link),
GFP_KERNEL | __GFP_ZERO);
if (!links)
- goto err_links;
+ return -ENOMEM;
+
+ priv->card.dai_link = links;
+ priv->card.num_links = num_links;
ldata = krealloc(priv->link_data,
num_links * sizeof(*priv->link_data),
GFP_KERNEL | __GFP_ZERO);
+ /* meson_card_clean_references() will free the links on this error path */
if (!ldata)
- goto err_ldata;
+ return -ENOMEM;
- priv->card.dai_link = links;
priv->link_data = ldata;
- priv->card.num_links = num_links;
return 0;
-
-err_ldata:
- kfree(links);
-err_links:
- dev_err(priv->card.dev, "failed to allocate links\n");
- return -ENOMEM;
-
}
EXPORT_SYMBOL_GPL(meson_card_reallocate_links);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0477/1518] phy: starfive: Fix runtime PM cleanup in JH7110 DPHY TX probe
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (475 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0476/1518] ASoC: meson: Keep link pointers valid on realloc failure Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0478/1518] phy: starfive: Fix runtime PM cleanup in JH7110 DPHY RX probe Greg Kroah-Hartman
` (521 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Can Peng, Changhuang Liang,
Vinod Koul, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Can Peng <pengcan@kylinos.cn>
[ Upstream commit f40b0241f3a382e99c14de2f28f14a44973407c1 ]
stf_dphy_probe() enables runtime PM before getting the clock and
reset controls, creating the PHY and registering the PHY provider. If
any of those steps fails, probe returns with runtime PM still enabled.
The driver also has no remove callback, so runtime PM is left enabled
on driver unbind after a successful probe.
Use devm_pm_runtime_enable() so runtime PM is disabled automatically
on later probe failures and on driver unbind.
Fixes: d3ab79553308 ("phy: starfive: Add mipi dphy tx support")
Signed-off-by: Can Peng <pengcan@kylinos.cn>
Reviewed-by: Changhuang Liang <changhuang.liang@starfivetech.com>
Link: https://patch.msgid.link/20260718090054.444513-2-pengcan@kylinos.cn
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/phy/starfive/phy-jh7110-dphy-tx.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/phy/starfive/phy-jh7110-dphy-tx.c b/drivers/phy/starfive/phy-jh7110-dphy-tx.c
index c64d1c91b1307..181491a938079 100644
--- a/drivers/phy/starfive/phy-jh7110-dphy-tx.c
+++ b/drivers/phy/starfive/phy-jh7110-dphy-tx.c
@@ -392,6 +392,7 @@ static int stf_dphy_probe(struct platform_device *pdev)
{
struct phy_provider *phy_provider;
struct stf_dphy *dphy;
+ int ret;
dphy = devm_kzalloc(&pdev->dev, sizeof(*dphy), GFP_KERNEL);
if (!dphy)
@@ -406,7 +407,9 @@ static int stf_dphy_probe(struct platform_device *pdev)
if (IS_ERR(dphy->topsys))
return PTR_ERR(dphy->topsys);
- pm_runtime_enable(&pdev->dev);
+ ret = devm_pm_runtime_enable(&pdev->dev);
+ if (ret)
+ return ret;
dphy->txesc_clk = devm_clk_get(&pdev->dev, "txesc");
if (IS_ERR(dphy->txesc_clk))
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0478/1518] phy: starfive: Fix runtime PM cleanup in JH7110 DPHY RX probe
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (476 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0477/1518] phy: starfive: Fix runtime PM cleanup in JH7110 DPHY TX probe Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0479/1518] arm64: dts: amlogic: meson-axg: Add missing nand_rb0 pin to nand_all_pins Greg Kroah-Hartman
` (520 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Can Peng, Changhuang Liang,
Vinod Koul, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Can Peng <pengcan@kylinos.cn>
[ Upstream commit 97bed336f6a25c9d1115ca95e3aa00e05c3bc271 ]
stf_dphy_probe() enables runtime PM before registering the PHY provider.
If devm_of_phy_provider_register() fails, probe returns with runtime PM
still enabled.
The driver also has no remove callback, so runtime PM is left enabled
on driver unbind after a successful probe.
Use devm_pm_runtime_enable() so runtime PM is disabled automatically
on later probe failures and on driver unbind.
Fixes: f8aa660841bc ("phy: starfive: Add mipi dphy rx support")
Signed-off-by: Can Peng <pengcan@kylinos.cn>
Reviewed-by: Changhuang Liang <changhuang.liang@starfivetech.com>
Link: https://patch.msgid.link/20260718090054.444513-3-pengcan@kylinos.cn
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/phy/starfive/phy-jh7110-dphy-rx.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/phy/starfive/phy-jh7110-dphy-rx.c b/drivers/phy/starfive/phy-jh7110-dphy-rx.c
index 0b039e1f71c55..d06f21ad63325 100644
--- a/drivers/phy/starfive/phy-jh7110-dphy-rx.c
+++ b/drivers/phy/starfive/phy-jh7110-dphy-rx.c
@@ -150,6 +150,7 @@ static int stf_dphy_probe(struct platform_device *pdev)
{
struct phy_provider *phy_provider;
struct stf_dphy *dphy;
+ int ret;
dphy = devm_kzalloc(&pdev->dev, sizeof(*dphy), GFP_KERNEL);
if (!dphy)
@@ -190,7 +191,9 @@ static int stf_dphy_probe(struct platform_device *pdev)
return PTR_ERR(dphy->phy);
}
- pm_runtime_enable(&pdev->dev);
+ ret = devm_pm_runtime_enable(&pdev->dev);
+ if (ret)
+ return ret;
phy_set_drvdata(dphy->phy, dphy);
phy_provider = devm_of_phy_provider_register(&pdev->dev,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0479/1518] arm64: dts: amlogic: meson-axg: Add missing nand_rb0 pin to nand_all_pins
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (477 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0478/1518] phy: starfive: Fix runtime PM cleanup in JH7110 DPHY RX probe Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0480/1518] arm64: dts: amlogic: meson-axg-s400: enable mipi_pcie_analog_dphy for PCIe Greg Kroah-Hartman
` (519 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jun Yan, Martin Blumenstingl,
Neil Armstrong, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jun Yan <jerrysteve1101@gmail.com>
[ Upstream commit 45eb76f9ab6854f79690d56d04df227429a536b8 ]
The nand_all_pins pinctrl node was missing the nand_rb0 (ready/busy)
pin description, which is required for NAND controller operation.
Add it to the pinmux list.
Fixes: be18d53c32b2 ("arm64: dts: amlogic: meson-axg: pinctrl node for NAND")
Signed-off-by: Jun Yan <jerrysteve1101@gmail.com>
Reviewed-by: Martin Blumenstingl <martin.blumenstingl@googlemail.com>
Link: https://patch.msgid.link/20260624135650.727077-3-jerrysteve1101@gmail.com
Signed-off-by: Neil Armstrong <neil.armstrong@linaro.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/amlogic/meson-axg.dtsi | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/arch/arm64/boot/dts/amlogic/meson-axg.dtsi b/arch/arm64/boot/dts/amlogic/meson-axg.dtsi
index 3058b60338dbf..e9c1aae95fe7c 100644
--- a/arch/arm64/boot/dts/amlogic/meson-axg.dtsi
+++ b/arch/arm64/boot/dts/amlogic/meson-axg.dtsi
@@ -481,7 +481,8 @@ mux {
"nand_ale",
"nand_cle",
"nand_wen_clk",
- "nand_ren_wr";
+ "nand_ren_wr",
+ "nand_rb0";
function = "nand";
input-enable;
bias-pull-up;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0480/1518] arm64: dts: amlogic: meson-axg-s400: enable mipi_pcie_analog_dphy for PCIe
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (478 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0479/1518] arm64: dts: amlogic: meson-axg: Add missing nand_rb0 pin to nand_all_pins Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0481/1518] RDMA/hfi1: Propagate sdma_txinit_ahg() errors Greg Kroah-Hartman
` (518 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jun Yan, Martin Blumenstingl,
Neil Armstrong, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jun Yan <jerrysteve1101@gmail.com>
[ Upstream commit 7f1d0cc86cb70fa550163b6f70fd1d484c03218e ]
The PCIe PHY node references mipi_pcie_analog_dphy via its phys property.
Enable this analog PHY node to make PCIe functionally viable.
Fixes: 9715b01da6cf ("arm64: dts: meson-axg-s400: enable PCIe M.2 Key E slots")
Signed-off-by: Jun Yan <jerrysteve1101@gmail.com>
Reviewed-by: Martin Blumenstingl <martin.blumenstingl@googlemail.com>
Link: https://patch.msgid.link/20260624135650.727077-5-jerrysteve1101@gmail.com
Signed-off-by: Neil Armstrong <neil.armstrong@linaro.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/amlogic/meson-axg-s400.dts | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/arch/arm64/boot/dts/amlogic/meson-axg-s400.dts b/arch/arm64/boot/dts/amlogic/meson-axg-s400.dts
index 9611775b81eee..7c8a8529dbc5f 100644
--- a/arch/arm64/boot/dts/amlogic/meson-axg-s400.dts
+++ b/arch/arm64/boot/dts/amlogic/meson-axg-s400.dts
@@ -432,6 +432,10 @@ gpio_speaker: gpio-controller@1f {
};
};
+&mipi_pcie_analog_dphy {
+ status = "okay";
+};
+
&pdm {
pinctrl-0 = <&pdm_dclk_a14_pins>, <&pdm_din0_pins>,
<&pdm_din1_pins>, <&pdm_din2_pins>, <&pdm_din3_pins>;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0481/1518] RDMA/hfi1: Propagate sdma_txinit_ahg() errors
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (479 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0480/1518] arm64: dts: amlogic: meson-axg-s400: enable mipi_pcie_analog_dphy for PCIe Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0482/1518] RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[] Greg Kroah-Hartman
` (517 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Danila Chernetsov, Leon Romanovsky,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Danila Chernetsov <listdansp@mail.ru>
[ Upstream commit 091c6162c022cbdfb64219708a71728cfd1d4600 ]
set_txreq_header_ahg() ignores the return value of sdma_txinit_ahg().
If sdma_txinit_ahg() fails, it returns before initializing tx->txreq.
However, set_txreq_header_ahg() ignores the error and returns the AHG
change count, causing the caller to continue processing the request as
though initialization had succeeded.
Propagate sdma_txinit_ahg() failures to the caller and abort request
processing when initialization fails.
Found by Linux Verification Center (linuxtesting.org) with SVACE.
Fixes: e3304b7cc4f1 ("IB/hfi1: Optimize cachelines for user SDMA request structure")
Signed-off-by: Danila Chernetsov <listdansp@mail.ru>
Link: https://patch.msgid.link/20260708162252.936634-1-listdansp@mail.ru
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/hfi1/user_sdma.c | 13 ++++++++-----
1 file changed, 8 insertions(+), 5 deletions(-)
diff --git a/drivers/infiniband/hw/hfi1/user_sdma.c b/drivers/infiniband/hw/hfi1/user_sdma.c
index 9b1aece1b0800..ae8ff7d5a37ce 100644
--- a/drivers/infiniband/hw/hfi1/user_sdma.c
+++ b/drivers/infiniband/hw/hfi1/user_sdma.c
@@ -1028,6 +1028,7 @@ static int set_txreq_header_ahg(struct user_sdma_request *req,
struct user_sdma_txreq *tx, u32 datalen)
{
u32 ahg[AHG_KDETH_ARRAY_SIZE];
+ int ret;
int idx = 0;
u8 omfactor; /* KDETH.OM */
struct hfi1_user_sdma_pkt_q *pq = req->pq;
@@ -1132,11 +1133,13 @@ static int set_txreq_header_ahg(struct user_sdma_request *req,
trace_hfi1_sdma_user_header_ahg(pq->dd, pq->ctxt, pq->subctxt,
req->info.comp_idx, req->sde->this_idx,
req->ahg_idx, ahg, idx, tidval);
- sdma_txinit_ahg(&tx->txreq,
- SDMA_TXREQ_F_USE_AHG,
- datalen, req->ahg_idx, idx,
- ahg, sizeof(req->hdr),
- user_sdma_txreq_cb);
+ ret = sdma_txinit_ahg(&tx->txreq,
+ SDMA_TXREQ_F_USE_AHG,
+ datalen, req->ahg_idx, idx,
+ ahg, sizeof(req->hdr),
+ user_sdma_txreq_cb);
+ if (ret)
+ return ret;
return idx;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0482/1518] RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[]
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (480 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0481/1518] RDMA/hfi1: Propagate sdma_txinit_ahg() errors Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0483/1518] RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters Greg Kroah-Hartman
` (516 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zhu Yanjun, Ibrahim Hashimov,
Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ibrahim Hashimov <security@auditcode.ai>
[ Upstream commit 126c757e4cd46f866ddc283143b58eb4d9bf52cd ]
For a user QP, qp->sq.queue is a ring the application writes directly,
so rxe_post_send() takes the is_user branch and only schedules send_task
without validating the WQE. rxe_requester() consumes it in place via
req_next_wqe() and calls copy_data(), which indexes
&wqe->dma.sge[cur_sge] with the attacker-controlled num_sge/cur_sge.
Only the kernel path bounds num_sge (validate_send_wr()); the user WQE
is never checked, so a local unprivileged user can post a WQE with an
out-of-range cur_sge or oversized num_sge and force an out-of-bounds
read of the per-WQE sge array in copy_data() (vmalloc OOB read, local
DoS).
Bound num_sge to qp->sq.max_sge in rxe_requester() before use, the way
get_srq_wqe() already guards SRQ entries, and bound cur_sge only when
the WQE carries payload (dma.resid): copy_data() returns early on a
zero-length copy before touching dma->sge[], so a zero-payload WQE --
the only kind a max_sge == 0 QP can post -- stays valid.
Reproduced under KASAN; the vmalloc-out-of-bounds in copy_data() is gone.
Fixes: 8700e3e7c485 ("Soft RoCE driver")
Reviewed-by: Zhu Yanjun <yanjun.zhu@linux.dev>
Signed-off-by: Ibrahim Hashimov <security@auditcode.ai>
Link: https://patch.msgid.link/20260712122149.78142-1-security@auditcode.ai
Assisted-by: AuditCode-AI:2026.07
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/sw/rxe/rxe_req.c | 15 +++++++++++++++
1 file changed, 15 insertions(+)
diff --git a/drivers/infiniband/sw/rxe/rxe_req.c b/drivers/infiniband/sw/rxe/rxe_req.c
index 12d03f390b097..24f5c044363f7 100644
--- a/drivers/infiniband/sw/rxe/rxe_req.c
+++ b/drivers/infiniband/sw/rxe/rxe_req.c
@@ -701,6 +701,21 @@ int rxe_requester(struct rxe_qp *qp)
if (unlikely(!wqe))
goto exit;
+ /*
+ * Don't trust user space data: a user QP's WQE comes from an mmap'd
+ * ring, so num_sge/cur_sge are attacker-controlled. Bound num_sge like
+ * get_srq_wqe(); bound cur_sge only when payload exists (dma.resid),
+ * since copy_data() skips dma->sge[] on a zero-length copy (all a
+ * max_sge == 0 QP can post).
+ */
+ if (unlikely(wqe->dma.num_sge > qp->sq.max_sge ||
+ (wqe->dma.resid &&
+ wqe->dma.cur_sge >= qp->sq.max_sge))) {
+ rxe_dbg_qp(qp, "invalid num_sge/cur_sge in send wqe\n");
+ wqe->status = IB_WC_LOC_QP_OP_ERR;
+ goto err;
+ }
+
if (rxe_wqe_is_fenced(qp, wqe)) {
qp->req.wait_fence = 1;
goto exit;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0483/1518] RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (481 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0482/1518] RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[] Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0484/1518] kcsan: avoid unintended access checking in NMIs Greg Kroah-Hartman
` (515 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, TanZheng, Leon Romanovsky,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: TanZheng <tanzheng@kylinos.cn>
[ Upstream commit b38f98e176050850f41bb6415f3a71400056623e ]
When srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect
descriptor, the unwind path destroys RDMA contexts but leaves stale
n_rw_ctx and n_rdma values (and a dangling rw_ctxs pointer). Later
sq_wr_avail accounting in srpt_queue_response() or srpt_write_pending()
can then subtract the wrong number of send queue credits.
Reset the counters and clear rw_ctxs after freeing the heap
allocation before returning an error.
Fixes: b99f8e4d7bcd ("IB/srpt: convert to the generic RDMA READ/WRITE API")
Signed-off-by: TanZheng <tanzheng@kylinos.cn>
Link: https://patch.msgid.link/20260715101550.45345-1-kensanya@163.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/ulp/srpt/ib_srpt.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/drivers/infiniband/ulp/srpt/ib_srpt.c b/drivers/infiniband/ulp/srpt/ib_srpt.c
index ba70c64a0aa9e..81efda7840aab 100644
--- a/drivers/infiniband/ulp/srpt/ib_srpt.c
+++ b/drivers/infiniband/ulp/srpt/ib_srpt.c
@@ -959,6 +959,7 @@ static int srpt_alloc_rw_ctxs(struct srpt_send_ioctx *ioctx,
struct srpt_rdma_ch *ch = ioctx->ch;
struct scatterlist *prev = NULL;
unsigned prev_nents;
+ u8 n_rdma, n_rw_ctx;
int ret, i;
if (nbufs == 1) {
@@ -970,6 +971,9 @@ static int srpt_alloc_rw_ctxs(struct srpt_send_ioctx *ioctx,
return -ENOMEM;
}
+ n_rw_ctx = ioctx->n_rw_ctx;
+ n_rdma = ioctx->n_rdma;
+
for (i = ioctx->n_rw_ctx; i < nbufs; i++, db++) {
struct srpt_rw_ctx *ctx = &ioctx->rw_ctxs[i];
u64 remote_addr = be64_to_cpu(db->va);
@@ -1016,6 +1020,9 @@ static int srpt_alloc_rw_ctxs(struct srpt_send_ioctx *ioctx,
}
if (ioctx->rw_ctxs != &ioctx->s_rw_ctx)
kfree(ioctx->rw_ctxs);
+ ioctx->rw_ctxs = NULL;
+ ioctx->n_rw_ctx = n_rw_ctx;
+ ioctx->n_rdma = n_rdma;
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0484/1518] kcsan: avoid unintended access checking in NMIs
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (482 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0483/1518] RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0485/1518] arm64: dts: imx8-ss-audio: Fix LPCG clock indices for ASRC0 Greg Kroah-Hartman
` (514 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Marco Elver, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Marco Elver <elver@google.com>
[ Upstream commit a8488ecbd7ba44d65b912dfe88a73f438eba2447 ]
If a watcher deliberately disables interrupts (either by user choice, or
because we're dealing with a scoped reordered access) to avoid detecting
any data races in interrupts, NMIs are still able to fire.
When we set up a watchpoint on a scoped reordered access, we disabled
interrupts because the same CPU cannot observe reordering of its own
accesses. To ensure we observe no false positives from NMIs, disable
access checking for interrupt contexts as well.
Fixes: 69562e4983d9 ("kcsan: Add core support for a subset of weak memory modeling")
Signed-off-by: Marco Elver <elver@google.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/kcsan/core.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
diff --git a/kernel/kcsan/core.c b/kernel/kcsan/core.c
index 8a7baf4e332e3..2db82661cd60a 100644
--- a/kernel/kcsan/core.c
+++ b/kernel/kcsan/core.c
@@ -585,8 +585,14 @@ kcsan_setup_watchpoint(const volatile void *ptr, size_t size, int type, unsigned
* information is lost if dirtied by KCSAN.
*/
kcsan_save_irqtrace(current);
- if (!interrupt_watcher)
+ if (!interrupt_watcher) {
local_irq_save(irq_flags);
+ /*
+ * NMIs can still fire, disable checking for all interrupt
+ * contexts.
+ */
+ raw_cpu_ptr(&kcsan_cpu_ctx)->disable_count++;
+ }
watchpoint = insert_watchpoint((unsigned long)ptr, size, is_write);
if (watchpoint == NULL) {
@@ -699,8 +705,10 @@ kcsan_setup_watchpoint(const volatile void *ptr, size_t size, int type, unsigned
atomic_long_dec(&kcsan_counters[KCSAN_COUNTER_USED_WATCHPOINTS]);
out_unlock:
- if (!interrupt_watcher)
+ if (!interrupt_watcher) {
+ raw_cpu_ptr(&kcsan_cpu_ctx)->disable_count--;
local_irq_restore(irq_flags);
+ }
kcsan_restore_irqtrace(current);
ctx->disable_scoped--;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0485/1518] arm64: dts: imx8-ss-audio: Fix LPCG clock indices for ASRC0
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (483 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0484/1518] kcsan: avoid unintended access checking in NMIs Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0486/1518] x86/bugs: Dont use cpu-type matching in cpu_vuln_blacklist Greg Kroah-Hartman
` (513 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Frank Li, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Frank Li <Frank.Li@nxp.com>
[ Upstream commit 8563591f76ca02c1a6fd70ce986df1d0dde8d249 ]
The LPCG clock indices for ASRC0 and AUD_PLL_DIV0 are swapped. The ASRC0
LPCG provides only IMX_LPCG_CLK_4, so update the ASRC0 clock consumer to
use IMX_LPCG_CLK_4 instead of the non-existent IMX_LPCG_CLK_0.
Likewise, the AUD_PLL_DIV0 LPCG provides only IMX_LPCG_CLK_0, so update its
clock consumer to use IMX_LPCG_CLK_0 instead of the non-existent
IMX_LPCG_CLK_4.
Fixes: 5125617c7a4d3 ("arm64: dts: imx8qxp: add asrc[0,1], esai0, spdif0 and sai[4,5]")
Signed-off-by: Frank Li <Frank.Li@nxp.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/freescale/imx8-ss-audio.dtsi | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/arch/arm64/boot/dts/freescale/imx8-ss-audio.dtsi b/arch/arm64/boot/dts/freescale/imx8-ss-audio.dtsi
index c32a6947ae9c4..5ddb90be54608 100644
--- a/arch/arm64/boot/dts/freescale/imx8-ss-audio.dtsi
+++ b/arch/arm64/boot/dts/freescale/imx8-ss-audio.dtsi
@@ -124,10 +124,10 @@ asrc0: asrc@59000000 {
compatible = "fsl,imx8qm-asrc";
reg = <0x59000000 0x10000>;
interrupts = <GIC_SPI 372 IRQ_TYPE_LEVEL_HIGH>;
- clocks = <&asrc0_lpcg IMX_LPCG_CLK_0>,
- <&asrc0_lpcg IMX_LPCG_CLK_0>,
- <&aud_pll_div0_lpcg IMX_LPCG_CLK_4>,
- <&aud_pll_div1_lpcg IMX_LPCG_CLK_4>,
+ clocks = <&asrc0_lpcg IMX_LPCG_CLK_4>,
+ <&asrc0_lpcg IMX_LPCG_CLK_4>,
+ <&aud_pll_div0_lpcg IMX_LPCG_CLK_0>,
+ <&aud_pll_div1_lpcg IMX_LPCG_CLK_0>,
<&acm IMX_ADMA_ACM_AUD_CLK0_SEL>,
<&acm IMX_ADMA_ACM_AUD_CLK1_SEL>,
<&clk_dummy>,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0486/1518] x86/bugs: Dont use cpu-type matching in cpu_vuln_blacklist
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (484 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0485/1518] arm64: dts: imx8-ss-audio: Fix LPCG clock indices for ASRC0 Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0487/1518] selftests/bpf: Check malloc result with ASSERT_NEQ in test_sha256 Greg Kroah-Hartman
` (512 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pawan Gupta, Borislav Petkov (AMD),
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pawan Gupta <pawan.kumar.gupta@linux.intel.com>
[ Upstream commit a4c714fe9746bf5a434bb798b26ebba278b798c1 ]
Thomas Gleixner pointed out that cpu-type is a per-CPU property while hybrid
is a system property; conflating the two in the CPU matching infrastructure is
wrong. Currently, on a hybrid system x86_match_cpu() matches any cpu-type.
This works if the intent is to find the possibility of a cpu-type in a system.
But fails if matching for the cpu-type of a given CPU.
Borislav posted a cleanup here:
https://lore.kernel.org/all/20260703193222.GFakgORjvxwnZTPRnI@fat_crate.local
To make way for the cleanup stop matching cpu-type in cpu_vuln_blacklist.
RFDS is the only user, so drop the VULNBL_INTEL_TYPE entries and fold their
RFDS bit into the base Alder Lake (0x97) and Raptor Lake (0xB7) blacklist
entries. For now open-code cpu-type check in vulnerable_to_rfds(). In the
future, if more vulnerabilities need cpu-type matching a helper can be added.
No functional change intended.
Fixes: 722fa0dba74f ("x86/rfds: Exclude P-only parts from the RFDS affected list")
Signed-off-by: Pawan Gupta <pawan.kumar.gupta@linux.intel.com>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Link: https://patch.msgid.link/20260708-cpu-type-vuln-v1-1-85c1d3c704db@linux.intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/kernel/cpu/common.c | 25 +++++++++++++++++--------
1 file changed, 17 insertions(+), 8 deletions(-)
diff --git a/arch/x86/kernel/cpu/common.c b/arch/x86/kernel/cpu/common.c
index 6cf7c2d0dc59c..3ffeadad02447 100644
--- a/arch/x86/kernel/cpu/common.c
+++ b/arch/x86/kernel/cpu/common.c
@@ -1210,9 +1210,6 @@ static const __initconst struct x86_cpu_id cpu_vuln_whitelist[] = {
#define VULNBL_INTEL_STEPS(vfm, max_stepping, issues) \
X86_MATCH_VFM_STEPS(vfm, X86_STEP_MIN, max_stepping, issues)
-#define VULNBL_INTEL_TYPE(vfm, cpu_type, issues) \
- X86_MATCH_VFM_CPU_TYPE(vfm, INTEL_CPU_TYPE_##cpu_type, issues)
-
#define VULNBL_AMD(family, blacklist) \
VULNBL(AMD, family, X86_MODEL_ANY, blacklist)
@@ -1275,11 +1272,9 @@ static const struct x86_cpu_id cpu_vuln_blacklist[] __initconst = {
VULNBL_INTEL_STEPS(INTEL_TIGERLAKE, X86_STEP_MAX, GDS | ITS | ITS_NATIVE_ONLY),
VULNBL_INTEL_STEPS(INTEL_LAKEFIELD, X86_STEP_MAX, MMIO | MMIO_SBDS | RETBLEED),
VULNBL_INTEL_STEPS(INTEL_ROCKETLAKE, X86_STEP_MAX, MMIO | RETBLEED | GDS | ITS | ITS_NATIVE_ONLY),
- VULNBL_INTEL_TYPE(INTEL_ALDERLAKE, ATOM, RFDS | VMSCAPE),
- VULNBL_INTEL_STEPS(INTEL_ALDERLAKE, X86_STEP_MAX, VMSCAPE),
+ VULNBL_INTEL_STEPS(INTEL_ALDERLAKE, X86_STEP_MAX, RFDS | VMSCAPE),
VULNBL_INTEL_STEPS(INTEL_ALDERLAKE_L, X86_STEP_MAX, RFDS | VMSCAPE),
- VULNBL_INTEL_TYPE(INTEL_RAPTORLAKE, ATOM, RFDS | VMSCAPE),
- VULNBL_INTEL_STEPS(INTEL_RAPTORLAKE, X86_STEP_MAX, VMSCAPE),
+ VULNBL_INTEL_STEPS(INTEL_RAPTORLAKE, X86_STEP_MAX, RFDS | VMSCAPE),
VULNBL_INTEL_STEPS(INTEL_RAPTORLAKE_P, X86_STEP_MAX, RFDS | VMSCAPE),
VULNBL_INTEL_STEPS(INTEL_RAPTORLAKE_S, X86_STEP_MAX, RFDS | VMSCAPE),
VULNBL_INTEL_STEPS(INTEL_METEORLAKE_L, X86_STEP_MAX, VMSCAPE),
@@ -1347,7 +1342,21 @@ static bool __init vulnerable_to_rfds(u64 x86_arch_cap_msr)
return true;
/* Only consult the blacklist when there is no enumeration: */
- return cpu_matches(cpu_vuln_blacklist, RFDS);
+ if (!cpu_matches(cpu_vuln_blacklist, RFDS))
+ return false;
+
+ /*
+ * ADL and RPL are affected only if they have Atom CPUs. Hybrids have
+ * both Core and Atom CPUs. Mark unaffected when Atom CPUs are not
+ * present.
+ */
+ if ((boot_cpu_data.x86_model == 0x97 ||
+ boot_cpu_data.x86_model == 0xB7) &&
+ boot_cpu_data.topo.intel_type != INTEL_CPU_TYPE_ATOM &&
+ !boot_cpu_has(X86_FEATURE_HYBRID_CPU))
+ return false;
+
+ return true;
}
static bool __init vulnerable_to_its(u64 x86_arch_cap_msr)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0487/1518] selftests/bpf: Check malloc result with ASSERT_NEQ in test_sha256
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (485 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0486/1518] x86/bugs: Dont use cpu-type matching in cpu_vuln_blacklist Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0488/1518] selftests/bpf: Silence array bounds warning in global_map_resize Greg Kroah-Hartman
` (511 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Viktor Malik,
Kumar Kartikeya Dwivedi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Viktor Malik <vmalik@redhat.com>
[ Upstream commit eb5cd154f174f42079a45f4bd7ee8bc20f2ba6f3 ]
Replace ASSERT_OK_PTR by ASSERT_NEQ(res, NULL, ...) when checking the
result of malloc. It is more accurate since malloc returns NULL, not an
error code, on failure and it also prevents the following false GCC
warning when compiling BPF selftests with -O2:
In file included from /bpf-next/tools/testing/selftests/bpf/prog_tests/sha256.c:4:
/bpf-next/tools/testing/selftests/bpf/prog_tests/sha256.c: In function ‘test_sha256’:
./test_progs.h:393:22: error: ‘data’ may be used uninitialized [-Werror=maybe-uninitialized]
393 | int ___err = libbpf_get_error(___res); \
| ^~~~~~~~~~~~~~~~~~~~~~~~
/bpf-next/tools/testing/selftests/bpf/prog_tests/sha256.c:28:14: note: in expansion of macro ‘ASSERT_OK_PTR’
28 | if (!ASSERT_OK_PTR(data, "malloc"))
| ^~~~~~~~~~~~~
In file included from /bpf-next/tools/testing/selftests/bpf/tools/include/bpf/bpf.h:32,
from ./test_progs.h:37:
/bpf-next/tools/testing/selftests/bpf/tools/include/bpf/libbpf_legacy.h:113:17: note: by argument 1 of type ‘const void *’ to ‘libbpf_get_error’ declared here
113 | LIBBPF_API long libbpf_get_error(const void *ptr);
| ^~~~~~~~~~~~~~~~
Fixes: f09f57c74677 ("selftests/bpf: Add test for libbpf_sha256()")
Signed-off-by: Viktor Malik <vmalik@redhat.com>
Link: https://lore.kernel.org/bpf/f9dec09cca0c2aa5eeb4fdcd400a13aa19e2c073.1784112948.git.vmalik@redhat.com
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/bpf/prog_tests/sha256.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/tools/testing/selftests/bpf/prog_tests/sha256.c b/tools/testing/selftests/bpf/prog_tests/sha256.c
index 604a0b1423d55..5edbc6194b071 100644
--- a/tools/testing/selftests/bpf/prog_tests/sha256.c
+++ b/tools/testing/selftests/bpf/prog_tests/sha256.c
@@ -25,10 +25,10 @@ void test_sha256(void)
size_t i;
data = malloc(MAX_LEN);
- if (!ASSERT_OK_PTR(data, "malloc"))
+ if (!ASSERT_NEQ(data, NULL, "malloc"))
goto out;
digests = malloc((MAX_LEN + 1) * SHA256_DIGEST_LENGTH);
- if (!ASSERT_OK_PTR(digests, "malloc"))
+ if (!ASSERT_NEQ(digests, NULL, "malloc"))
goto out;
/* Generate MAX_LEN bytes of "random" data deterministically. */
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0488/1518] selftests/bpf: Silence array bounds warning in global_map_resize
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (486 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0487/1518] selftests/bpf: Check malloc result with ASSERT_NEQ in test_sha256 Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0489/1518] irqchip/gic-v3-its: Prevent leak in its_vpe_irq_domain_alloc() Greg Kroah-Hartman
` (510 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Viktor Malik,
Kumar Kartikeya Dwivedi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Viktor Malik <vmalik@redhat.com>
[ Upstream commit dcd164ec67f89e0db5ee025ee9e91280052eb737 ]
When compiling BPF selftests with -O2, GCC reports an array bounds
violation warning in global_map_resize test:
In function ‘global_map_resize_bss_subtest’,
inlined from ‘test_global_map_resize’ at /bpf-next/tools/testing/selftests/bpf/prog_tests/global_map_resize.c:228:3:
/bpf-next/tools/testing/selftests/bpf/prog_tests/global_map_resize.c:64:33: error: array subscript 1 is above array bounds of ‘int[1]’ [-Werror=array-bounds=]
64 | skel->bss->array[i] = 1;
| ~~~~~~~~~~~~~~~~^~~
In file included from /bpf-next/tools/testing/selftests/bpf/prog_tests/global_map_resize.c:6:
./test_global_map_resize.skel.h: In function ‘test_global_map_resize’:
./test_global_map_resize.skel.h:44:21: note: while referencing ‘array’
44 | int array[1];
| ^~~~~
This is a false positive because `array` (a BPF map) has been resized
from within the BPF program. GCC doesn't know that so let us silence the
warning by accessing the array via a plain pointer.
Fixes: 08b089567573 ("libbpf: Selftests for resizing datasec maps")
Signed-off-by: Viktor Malik <vmalik@redhat.com>
Link: https://lore.kernel.org/bpf/57765bc465a27923c3c093eba222cc24d08d8c40.1784112948.git.vmalik@redhat.com
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../testing/selftests/bpf/prog_tests/global_map_resize.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
diff --git a/tools/testing/selftests/bpf/prog_tests/global_map_resize.c b/tools/testing/selftests/bpf/prog_tests/global_map_resize.c
index 56b5baef35c8c..602ce30f1720c 100644
--- a/tools/testing/selftests/bpf/prog_tests/global_map_resize.c
+++ b/tools/testing/selftests/bpf/prog_tests/global_map_resize.c
@@ -23,6 +23,7 @@ static void global_map_resize_bss_subtest(void)
struct bpf_map *map;
const __u32 desired_sz = sizeof(skel->bss->sum) + sysconf(_SC_PAGE_SIZE) * 2;
size_t array_len, actual_sz, new_sz;
+ int *array;
skel = test_global_map_resize__open();
if (!ASSERT_OK_PTR(skel, "test_global_map_resize__open"))
@@ -58,10 +59,13 @@ static void global_map_resize_bss_subtest(void)
goto teardown;
/* fill the newly resized array with ones,
- * skipping the first element which was previously set
+ * skipping the first element which was previously set;
+ * access through a plain pointer to avoid -Warray-bounds
+ * since the array was resized beyond its declared length.
*/
+ array = skel->bss->array;
for (int i = 1; i < array_len; i++)
- skel->bss->array[i] = 1;
+ array[i] = 1;
/* set global const values before loading */
skel->rodata->pid = getpid();
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0489/1518] irqchip/gic-v3-its: Prevent leak in its_vpe_irq_domain_alloc()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (487 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0488/1518] selftests/bpf: Silence array bounds warning in global_map_resize Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0490/1518] RDMA/nldev: validate dynamic counter attribute length Greg Kroah-Hartman
` (509 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kemeng Shi, Thomas Gleixner,
Marc Zyngier, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kemeng Shi <shikemeng@huaweicloud.com>
[ Upstream commit 325ff3e78c64cd619d52b99f7c8b09a3f31e1495 ]
When its_irq_gic_domain_alloc() fails, the following
its_vpe_irq_domain_free() fails to invoke its_vep_teardown() for the
corresponding interrupt, which leaks the resource.
Invoke its_vpe_teardown() in the error handling path to avoid the leak.
[ tglx: Massaged change log ]
Fixes: 7d75bbb4bc1ad ("irqchip/gic-v3-its: Add VPE irq domain allocation/teardown")
Signed-off-by: Kemeng Shi <shikemeng@huaweicloud.com>
Signed-off-by: Thomas Gleixner <tglx@kernel.org>
Acked-by: Marc Zyngier <maz@kernel.org>
Link: https://patch.msgid.link/20260721063241.52549-2-shikemeng@huaweicloud.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/irqchip/irq-gic-v3-its.c | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
diff --git a/drivers/irqchip/irq-gic-v3-its.c b/drivers/irqchip/irq-gic-v3-its.c
index 627b708c96264..93ad36c7a73e8 100644
--- a/drivers/irqchip/irq-gic-v3-its.c
+++ b/drivers/irqchip/irq-gic-v3-its.c
@@ -4593,6 +4593,13 @@ static int its_vpe_init(struct its_vpe *vpe)
static void its_vpe_teardown(struct its_vpe *vpe)
{
+ /*
+ * If vpt_page is NULL, then its_vpe_init() has failed, and
+ * there is nothing to do as no resource has been allocated.
+ */
+ if (vpe->vpt_page == NULL)
+ return;
+
its_vpe_db_proxy_unmap(vpe);
its_vpe_id_free(vpe->vpe_id);
its_free_pending_table(vpe->vpt_page);
@@ -4673,8 +4680,10 @@ static int its_vpe_irq_domain_alloc(struct irq_domain *domain, unsigned int virq
irqd_set_resend_when_in_progress(irq_get_irq_data(virq + i));
}
- if (err)
+ if (err) {
+ its_vpe_teardown(vm->vpes[i]);
its_vpe_irq_domain_free(domain, virq, i);
+ }
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0490/1518] RDMA/nldev: validate dynamic counter attribute length
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (488 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0489/1518] irqchip/gic-v3-its: Prevent leak in its_vpe_irq_domain_alloc() Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0491/1518] ACPI: EC: Avoid _REG disconnect on GPIO IRQ defer Greg Kroah-Hartman
` (508 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zhu Yanjun, Pengpeng Hou,
Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit 74f49255492a62658f36bf2578d7916f1c6ffad1 ]
RDMA_NLDEV_ATTR_STAT_HWCOUNTERS is a nested attribute whose children are
consumed directly with nla_get_u32(). The top-level policy validates only
the container, so it does not establish the fixed shape of each child.
Require every child payload to be exactly one u32 before reading it.
Fixes: 3c3c1f141639 ("RDMA/nldev: Allow optional-counter status configuration through RDMA netlink")
Reviewed-by: Zhu Yanjun <yanjun.zhu@linux.dev>
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260720114918.70323-1-pengpeng@iscas.ac.cn
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/core/nldev.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/drivers/infiniband/core/nldev.c b/drivers/infiniband/core/nldev.c
index 2220a2dfab240..79fa29883349f 100644
--- a/drivers/infiniband/core/nldev.c
+++ b/drivers/infiniband/core/nldev.c
@@ -2100,6 +2100,11 @@ static int nldev_stat_set_counter_dynamic_doit(struct nlattr *tb[],
nla_for_each_nested(entry_attr, tb[RDMA_NLDEV_ATTR_STAT_HWCOUNTERS],
rem) {
+ if (nla_len(entry_attr) != sizeof(u32)) {
+ ret = -EINVAL;
+ goto out;
+ }
+
index = nla_get_u32(entry_attr);
if ((index >= stats->num_counters) ||
!(stats->descs[index].flags & IB_STAT_FLAG_OPTIONAL)) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0491/1518] ACPI: EC: Avoid _REG disconnect on GPIO IRQ defer
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (489 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0490/1518] RDMA/nldev: validate dynamic counter attribute length Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0492/1518] ACPI: processor: validate MADT IOAPIC entry bounds Greg Kroah-Hartman
` (507 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zhu Ling, Rafael J. Wysocki,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhu Ling <zhuling2709@phytium.com.cn>
[ Upstream commit e71bdbce27dcaa7f467a3a198cbe723924f05569 ]
EC event delivery uses either a GPE or, on ACPI reduced hardware
platforms, a GpioInt resource. The GPE path does not have a provider
lookup that can defer, but acpi_dev_gpio_irq_get() can return
-EPROBE_DEFER for the GpioInt path.
ec_install_handlers() currently installs the EC address space handler and
executes _REG before looking up the GPIO IRQ. If the GPIO lookup then
defers, acpi_ec_setup() tears the handlers down again. Removing the EC
address space handler causes ACPICA to execute _REG for disconnect, so
firmware may observe an EC OpRegion connected -> disconnected transition
during one failed probe attempt.
This is observable when the namespace EC reuses a boot EC that has already
installed the EC address space handler. A deferred namespace EC probe can
disconnect the already usable boot EC OpRegion until a later reprobe
connects it again. AML that gates EC field accesses on _REG state can
then return fallback values to other drivers during that window.
Prepare the GPIOInt IRQ before publishing EC OpRegion availability to AML.
This leaves the GPE path unchanged, keeps non-deferred GPIO lookup errors
non-fatal as before, and still lets the existing acpi_ec_setup() error
path clean up real handler installation failures.
Fixes: f6484cadbcaf ("ACPI: EC: clean up handlers on probe failure in acpi_ec_setup()")
Signed-off-by: Zhu Ling <zhuling2709@phytium.com.cn>
[ rjw: Added an empty code line after a conditional ]
Link: https://patch.msgid.link/20260715012556.12043-1-zhuling2709@phytium.com.cn
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/ec.c | 40 ++++++++++++++++++++++++++--------------
1 file changed, 26 insertions(+), 14 deletions(-)
diff --git a/drivers/acpi/ec.c b/drivers/acpi/ec.c
index 1f4fc78a124fa..16213dfb3aabf 100644
--- a/drivers/acpi/ec.c
+++ b/drivers/acpi/ec.c
@@ -1512,6 +1512,24 @@ static bool install_gpio_irq_event_handler(struct acpi_ec *ec)
IRQF_SHARED | IRQF_ONESHOT, "ACPI EC", ec) >= 0;
}
+static int ec_prepare_gpio_irq(struct acpi_ec *ec, struct acpi_device *device)
+{
+ int irq;
+
+ if (!device || ec->gpe >= 0 || ec->irq >= 0)
+ return 0;
+
+ /* ACPI reduced hardware platforms use a GpioInt from _CRS. */
+ irq = acpi_dev_gpio_irq_get(device, 0);
+ if (irq == -EPROBE_DEFER)
+ return irq;
+
+ if (irq >= 0)
+ ec->irq = irq;
+
+ return 0;
+}
+
/**
* ec_install_handlers - Install service callbacks and register query methods.
* @ec: Target EC.
@@ -1526,7 +1544,6 @@ static bool install_gpio_irq_event_handler(struct acpi_ec *ec)
* Return:
* -ENODEV if the address space handler cannot be installed, which means
* "unable to handle transactions",
- * -EPROBE_DEFER if GPIO IRQ acquisition needs to be deferred,
* or 0 (success) otherwise.
*/
static int ec_install_handlers(struct acpi_ec *ec, struct acpi_device *device,
@@ -1559,19 +1576,6 @@ static int ec_install_handlers(struct acpi_ec *ec, struct acpi_device *device,
if (!device)
return 0;
- if (ec->gpe < 0) {
- /* ACPI reduced hardware platforms use a GpioInt from _CRS. */
- int irq = acpi_dev_gpio_irq_get(device, 0);
- /*
- * Bail out right away for deferred probing or complete the
- * initialization regardless of any other errors.
- */
- if (irq == -EPROBE_DEFER)
- return -EPROBE_DEFER;
- else if (irq >= 0)
- ec->irq = irq;
- }
-
if (!test_bit(EC_FLAGS_QUERY_METHODS_INSTALLED, &ec->flags)) {
/* Find and register all query methods */
acpi_walk_namespace(ACPI_TYPE_METHOD, ec->handle, 1,
@@ -1649,6 +1653,14 @@ static int acpi_ec_setup(struct acpi_ec *ec, struct acpi_device *device, bool ca
{
int ret;
+ /*
+ * GPIO IRQ lookup can defer. Do it before publishing the EC
+ * OpRegion to AML to avoid a spurious _REG(disconnect).
+ */
+ ret = ec_prepare_gpio_irq(ec, device);
+ if (ret)
+ return ret;
+
/* First EC capable of handling transactions */
if (!first_ec)
first_ec = ec;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0492/1518] ACPI: processor: validate MADT IOAPIC entry bounds
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (490 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0491/1518] ACPI: EC: Avoid _REG disconnect on GPIO IRQ defer Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0493/1518] ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root Greg Kroah-Hartman
` (506 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Rafael J. Wysocki,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit 2c50ffdc73f3a70d745d249f509fc290754121e6 ]
The IOAPIC hotplug lookup parses both MADT and _MAT records directly.
The MADT walk previously used a subtable's declared length to advance
the cursor after only locating a generic header. The _MAT path likewise
passed a generic header to the IOAPIC helper.
Validate that a current record has a complete generic header, that its
declared length is contained in the available record range, and that a
typed IOAPIC record contains the full fixed IOAPIC body before reading
its fields. Use the same relation for both MADT and _MAT provider
paths.
Fixes: ecf5636dcd59 ("ACPI: Add interfaces to parse IOAPIC ID for IOAPIC hotplug")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260715083253.22831-1-pengpeng@iscas.ac.cn
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/processor_core.c | 31 +++++++++++++++++++++++++------
1 file changed, 25 insertions(+), 6 deletions(-)
diff --git a/drivers/acpi/processor_core.c b/drivers/acpi/processor_core.c
index a4498357bd165..3bf076c150fa1 100644
--- a/drivers/acpi/processor_core.c
+++ b/drivers/acpi/processor_core.c
@@ -336,11 +336,26 @@ int acpi_get_cpuid(acpi_handle handle, int type, u32 acpi_id)
EXPORT_SYMBOL_GPL(acpi_get_cpuid);
#ifdef CONFIG_ACPI_HOTPLUG_IOAPIC
-static int get_ioapic_id(struct acpi_subtable_header *entry, u32 gsi_base,
+static bool madt_entry_is_valid(struct acpi_subtable_header *entry,
+ unsigned long end)
+{
+ unsigned long start = (unsigned long)entry;
+
+ if (start >= end || end - start < sizeof(*entry))
+ return false;
+
+ return entry->length >= sizeof(*entry) && entry->length <= end - start;
+}
+
+static int get_ioapic_id(struct acpi_subtable_header *entry,
+ const unsigned long end, u32 gsi_base,
u64 *phys_addr, int *ioapic_id)
{
struct acpi_madt_io_apic *ioapic = (struct acpi_madt_io_apic *)entry;
+ if (!madt_entry_is_valid(entry, end) || BAD_MADT_ENTRY(ioapic, end))
+ return 0;
+
if (ioapic->global_irq_base != gsi_base)
return 0;
@@ -361,17 +376,19 @@ static int parse_madt_ioapic_entry(u32 gsi_base, u64 *phys_addr)
return apic_id;
entry = (unsigned long)madt;
+ if (madt->header.length < sizeof(*madt))
+ return apic_id;
madt_end = entry + madt->header.length;
/* Parse all entries looking for a match. */
entry += sizeof(struct acpi_table_madt);
- while (entry + sizeof(struct acpi_subtable_header) < madt_end) {
+ while (madt_entry_is_valid((struct acpi_subtable_header *)entry,
+ madt_end)) {
hdr = (struct acpi_subtable_header *)entry;
if (hdr->type == ACPI_MADT_TYPE_IO_APIC &&
- get_ioapic_id(hdr, gsi_base, phys_addr, &apic_id))
+ get_ioapic_id(hdr, madt_end, gsi_base, phys_addr, &apic_id))
break;
- else
- entry += hdr->length;
+ entry += hdr->length;
}
return apic_id;
@@ -398,7 +415,9 @@ static int parse_mat_ioapic_entry(acpi_handle handle, u32 gsi_base,
header = (struct acpi_subtable_header *)obj->buffer.pointer;
if (header->type == ACPI_MADT_TYPE_IO_APIC)
- get_ioapic_id(header, gsi_base, phys_addr, &apic_id);
+ get_ioapic_id(header,
+ (unsigned long)header + obj->buffer.length,
+ gsi_base, phys_addr, &apic_id);
exit:
kfree(buffer.pointer);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0493/1518] ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (491 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0492/1518] ACPI: processor: validate MADT IOAPIC entry bounds Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0494/1518] ext4: fix circular lock dependency in ext4_ext_migrate Greg Kroah-Hartman
` (505 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko AI review, Chen Pei,
Rafael J. Wysocki, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chen Pei <cp0613@linux.alibaba.com>
[ Upstream commit 8a742141f7ab84975aa758b775567ef4740ef0cf ]
acpi_pci_root_add() assigns the freshly allocated root to
device->driver_data before dmar_device_add() and pci_acpi_scan_root().
Both failure paths reach the end: label where root is kfree()'d, but
only the pci_acpi_scan_root() path clears driver_data first.
When dmar_device_add() fails during a hot-add, root is freed while
device->driver_data still points at it. The ACPI core does not clear
driver_data on attach failure, so a later acpi_pci_find_root() call may
dereference this dangling pointer.
acpi_pci_root_remove() has the same problem: it frees root without
clearing device->driver_data, leaving a dangling pointer behind after
the root bridge is removed.
Move the NULL assignment to the shared end: label so every error path in
acpi_pci_root_add() clears driver_data before freeing root, and clear it
in acpi_pci_root_remove() as well, so the object is never left reachable
through driver_data after being freed.
Fixes: db89b4f0dbab ("ACPI: catch calls of acpi_driver_data on pointer of wrong type")
Reported-by: Sashiko AI review <sashiko-bot@kernel.org>
Link: https://sashiko.dev/#/patchset/20260526025118.38935-1-cp0613@linux.alibaba.com
Link: https://sashiko.dev/#/patchset/20260707121258.11640-1-cp0613@linux.alibaba.com
Signed-off-by: Chen Pei <cp0613@linux.alibaba.com>
Link: https://patch.msgid.link/20260715135048.3278-1-cp0613@linux.alibaba.com
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/pci_root.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/acpi/pci_root.c b/drivers/acpi/pci_root.c
index 74ade41603145..32b868bd8487b 100644
--- a/drivers/acpi/pci_root.c
+++ b/drivers/acpi/pci_root.c
@@ -730,7 +730,6 @@ static int acpi_pci_root_add(struct acpi_device *device,
dev_err(&device->dev,
"Bus %04x:%02x not present in PCI namespace\n",
root->segment, (unsigned int)root->secondary.start);
- device->driver_data = NULL;
result = -ENODEV;
goto remove_dmar;
}
@@ -766,6 +765,7 @@ static int acpi_pci_root_add(struct acpi_device *device,
if (hotadd)
dmar_device_remove(handle);
end:
+ device->driver_data = NULL;
kfree(root);
return result;
}
@@ -789,6 +789,7 @@ static void acpi_pci_root_remove(struct acpi_device *device)
pci_unlock_rescan_remove();
+ device->driver_data = NULL;
kfree(root);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0494/1518] ext4: fix circular lock dependency in ext4_ext_migrate
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (492 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0493/1518] ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0495/1518] ext4: fix out-of-bounds read in ext4_read_inline_dir() Greg Kroah-Hartman
` (504 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+212e8f62790f8e0bc63b,
Yun Zhou, Jan Kara, Theodore Tso, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yun Zhou <yun.zhou@windriver.com>
[ Upstream commit a897682793eba5de51ee6f3152760374afa629cf ]
Move iput(tmp_inode) after ext4_writepages_up_write() to avoid a
circular lock dependency between s_writepages_rwsem and sb_internal
(freeze protection).
The deadlock scenario:
CPU0 (EXT4_IOC_MIGRATE) CPU1 (orphan cleanup during mount)
---- ----
ext4_ext_migrate()
ext4_writepages_down_write()
s_writepages_rwsem (write)
ext4_evict_inode()
sb_start_intwrite() [sb_internal]
...
ext4_writepages()
s_writepages_rwsem (read) [BLOCKED]
iput(tmp_inode)
ext4_evict_inode()
sb_start_intwrite() [BLOCKED]
The tmp_inode is a temporary inode with nlink=0 created solely for
building the extent tree. Its eviction does not require
s_writepages_rwsem protection, so deferring iput() until after
releasing the rwsem is safe.
Reported-by: syzbot+212e8f62790f8e0bc63b@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=212e8f62790f8e0bc63b
Fixes: cb85f4d23f79 ("ext4: fix race between writepages and enabling EXT4_EXTENTS_FL")
Signed-off-by: Yun Zhou <yun.zhou@windriver.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Link: https://patch.msgid.link/20260612005330.1930804-1-yun.zhou@windriver.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ext4/migrate.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/fs/ext4/migrate.c b/fs/ext4/migrate.c
index 1b0dfd963d3f0..84e3b703ab463 100644
--- a/fs/ext4/migrate.c
+++ b/fs/ext4/migrate.c
@@ -458,6 +458,7 @@ int ext4_ext_migrate(struct inode *inode)
if (IS_ERR(tmp_inode)) {
retval = PTR_ERR(tmp_inode);
ext4_journal_stop(handle);
+ tmp_inode = NULL;
goto out_unlock;
}
/*
@@ -585,9 +586,9 @@ int ext4_ext_migrate(struct inode *inode)
ext4_journal_stop(handle);
out_tmp_inode:
unlock_new_inode(tmp_inode);
- iput(tmp_inode);
out_unlock:
ext4_writepages_up_write(inode->i_sb, alloc_ctx);
+ iput(tmp_inode);
return retval;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0495/1518] ext4: fix out-of-bounds read in ext4_read_inline_dir()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (493 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0494/1518] ext4: fix circular lock dependency in ext4_ext_migrate Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0496/1518] ext4: skip extra isize expansion during mount to prevent deadlock Greg Kroah-Hartman
` (503 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Weiming Shi, Xiang Mei, Jan Kara,
Theodore Tso, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xiang Mei <xmei5@asu.edu>
[ Upstream commit 9333cc809f0a89e001b814155a6cb8903a6274df ]
ext4_read_inline_dir() can read a dirent header past the end of its inline
buffer, triggering a slab-out-of-bounds read during getdents64():
BUG: KASAN: slab-out-of-bounds in __ext4_check_dir_entry
Read of size 2 at addr ffff88800f3dd23c by task exploit/148
...
__ext4_check_dir_entry
ext4_read_inline_dir
iterate_dir
The dirent payload lives in a buffer of exactly inline_size bytes:
dir_buf = kmalloc(inline_size, GFP_NOFS);
but iteration runs in a position space extra_offset bytes larger
(extra_size = extra_offset + inline_size) so the synthetic "." and ".."
land at their block-dir offsets. A dirent is formed at "dir_buf + pos -
extra_offset", yet the ext4_check_dir_entry() length argument uses the
larger extra_size. A position whose dirent header would extend past
extra_size is therefore accepted, and the rescan loop's rec_len probe and
ext4_check_dir_entry() dereference de->rec_len before the entry is rejected.
Reject a position whose minimum-size dirent header would not fit within
extra_size before forming de, in both the rescan and main loops, and pass
inline_size rather than extra_size to ext4_check_dir_entry() so the length
check matches the physical buffer.
Fixes: c4d8b0235aa9 ("ext4: fix readdir error in case inline_data+^dir_index.")
Reported-by: Weiming Shi <bestswngs@gmail.com>
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Xiang Mei <xmei5@asu.edu>
Reviewed-by: Jan Kara <jack@suse.cz>
Link: https://patch.msgid.link/20260615190519.946736-1-xmei5@asu.edu
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ext4/inline.c | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
diff --git a/fs/ext4/inline.c b/fs/ext4/inline.c
index 408677fa81967..1a48ccaa364dc 100644
--- a/fs/ext4/inline.c
+++ b/fs/ext4/inline.c
@@ -1454,6 +1454,8 @@ int ext4_read_inline_dir(struct file *file,
/* for other entry, the real offset in
* the buf has to be tuned accordingly.
*/
+ if (i + ext4_dir_rec_len(1, NULL) > extra_size)
+ break;
de = (struct ext4_dir_entry_2 *)
(dir_buf + i - extra_offset);
/* It's too expensive to do a full
@@ -1488,10 +1490,17 @@ int ext4_read_inline_dir(struct file *file,
continue;
}
+ /*
+ * de lives at dir_buf + ctx->pos - extra_offset, within the
+ * kmalloc(inline_size) buffer. Make sure its header fits before
+ * ext4_check_dir_entry() dereferences de->rec_len.
+ */
+ if (ctx->pos + ext4_dir_rec_len(1, NULL) > extra_size)
+ goto out;
de = (struct ext4_dir_entry_2 *)
(dir_buf + ctx->pos - extra_offset);
if (ext4_check_dir_entry(inode, file, de, iloc.bh, dir_buf,
- extra_size, ctx->pos))
+ inline_size, ctx->pos))
goto out;
if (le32_to_cpu(de->inode)) {
if (!dir_emit(ctx, de->name, de->name_len,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0496/1518] ext4: skip extra isize expansion during mount to prevent deadlock
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (494 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0495/1518] ext4: fix out-of-bounds read in ext4_read_inline_dir() Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0497/1518] platform/x86: acer-wmi: reject missing gaming WMI results Greg Kroah-Hartman
` (502 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+5d19358d7eb30ffb0cc5,
Yun Zhou, Jan Kara, Theodore Tso, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yun Zhou <yun.zhou@windriver.com>
[ Upstream commit 7461c60b9c6a839b13ad4c3490681a0cf5aa0637 ]
ext4_try_to_expand_extra_isize() is called from __ext4_mark_inode_dirty()
while holding an active jbd2 handle. During mount (!SB_ACTIVE), the
expand path may move xattrs to external blocks and release ea_inodes via
iput(). When !SB_ACTIVE, iput() calls write_inode_now() which acquires
s_writepages_rwsem, creating a circular lock dependency:
s_writepages_rwsem --> jbd2_handle --> xattr_sem --> s_writepages_rwsem
This can be triggered via:
ext4_process_orphan() -> ext4_truncate() -> ext4_mark_inode_dirty()
-> ext4_try_to_expand_extra_isize()
or:
ext4_evict_inode() -> ext4_mark_inode_dirty()
-> ext4_try_to_expand_extra_isize()
Skip expansion when !SB_ACTIVE. This is a minor loss of functionality
(extra isize won't grow for these inodes during mount), which e2fsck
can resolve later if needed.
Reported-by: syzbot+5d19358d7eb30ffb0cc5@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=5d19358d7eb30ffb0cc5
Fixes: c8585c6fcaf2 ("ext4: fix races between changing inode journal mode and ext4_writepages")
Signed-off-by: Yun Zhou <yun.zhou@windriver.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Link: https://patch.msgid.link/20260623061903.2148767-1-yun.zhou@windriver.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ext4/inode.c | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/fs/ext4/inode.c b/fs/ext4/inode.c
index 2fd18dd19eeff..e03c749772f38 100644
--- a/fs/ext4/inode.c
+++ b/fs/ext4/inode.c
@@ -6434,6 +6434,16 @@ static int ext4_try_to_expand_extra_isize(struct inode *inode,
if (ext4_test_inode_state(inode, EXT4_STATE_NO_EXPAND))
return -EOVERFLOW;
+ /*
+ * Skip expansion during mount (!SB_ACTIVE). Expanding extra isize
+ * may move xattrs to external blocks and release ea_inodes via iput.
+ * When !SB_ACTIVE, iput triggers write_inode_now() which acquires
+ * s_writepages_rwsem, causing a deadlock with the caller's active
+ * jbd2 handle (lock order: s_writepages_rwsem -> jbd2_handle).
+ */
+ if (unlikely(!(inode->i_sb->s_flags & SB_ACTIVE)))
+ return -EBUSY;
+
/*
* In nojournal mode, we can immediately attempt to expand
* the inode. When journaled, we first need to obtain extra
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0497/1518] platform/x86: acer-wmi: reject missing gaming WMI results
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (495 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0496/1518] ext4: skip extra isize expansion during mount to prevent deadlock Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0498/1518] bpf: Zero queue and stack outputs on lock failure Greg Kroah-Hartman
` (501 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yousef Alhouseen, Ilpo Järvinen,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yousef Alhouseen <alhouseenyousef@gmail.com>
[ Upstream commit caf8342512c3056005f475d350eeca089c3c6623 ]
WMI_gaming_execute_u32_u64() returns success when firmware supplies
no output object, leaving the caller output untouched. Gaming getters
then inspect an uninitialized result value.
When the caller requests an output value, return -ENOMSG if firmware
supplies no object. Preserve a NULL output pointer as the supported way
for callers to ignore the result.
Fixes: 2d76708c2221 ("platform/x86: acer-wmi: use WMI calls for platform profile handling")
Signed-off-by: Yousef Alhouseen <alhouseenyousef@gmail.com>
Link: https://patch.msgid.link/20260701164208.8998-1-alhouseenyousef@gmail.com
Reviewed-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Ilpo Järvinen <ilpo.jarvinen@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/platform/x86/acer-wmi.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/platform/x86/acer-wmi.c b/drivers/platform/x86/acer-wmi.c
index d848afc91f87d..55b1980313542 100644
--- a/drivers/platform/x86/acer-wmi.c
+++ b/drivers/platform/x86/acer-wmi.c
@@ -1530,7 +1530,9 @@ static int WMI_gaming_execute_u32_u64(u32 method_id, u32 in, u64 *out)
return -EIO;
obj = result.pointer;
- if (obj && out) {
+ if (!obj && out) {
+ ret = -ENOMSG;
+ } else if (obj && out) {
switch (obj->type) {
case ACPI_TYPE_INTEGER:
*out = obj->integer.value;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0498/1518] bpf: Zero queue and stack outputs on lock failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (496 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0497/1518] platform/x86: acer-wmi: reject missing gaming WMI results Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0499/1518] libbpf: Search /lib64 and /lib in resolve_full_path() Greg Kroah-Hartman
` (500 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kumar Kartikeya Dwivedi,
Emil Tsalapatis, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kumar Kartikeya Dwivedi <memxor@gmail.com>
[ Upstream commit 7ac6e1ae41a09f1dd4baeeff1d028ae49ee01232 ]
Queue and stack pop/peek helpers accept an uninitialized output buffer
because the verifier expects the helper to initialize it. The empty-map
error path clears the buffer, but a failed lock acquisition returns
-EBUSY without writing it.
Clear the output before returning -EBUSY so BPF programs cannot observe
uninitialized stack contents after a failed helper call.
Fixes: a34a9f1a19af ("bpf: Avoid deadlock when using queue and stack maps from NMI")
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Link: https://lore.kernel.org/bpf/20260719125419.1782196-1-memxor@gmail.com
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/queue_stack_maps.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
diff --git a/kernel/bpf/queue_stack_maps.c b/kernel/bpf/queue_stack_maps.c
index 9a5f94371e506..c1c9dee4dcdd0 100644
--- a/kernel/bpf/queue_stack_maps.c
+++ b/kernel/bpf/queue_stack_maps.c
@@ -99,8 +99,10 @@ static long __queue_map_get(struct bpf_map *map, void *value, bool delete)
int err = 0;
void *ptr;
- if (raw_res_spin_lock_irqsave(&qs->lock, flags))
+ if (raw_res_spin_lock_irqsave(&qs->lock, flags)) {
+ memset(value, 0, qs->map.value_size);
return -EBUSY;
+ }
if (queue_stack_map_is_empty(qs)) {
memset(value, 0, qs->map.value_size);
@@ -130,8 +132,10 @@ static long __stack_map_get(struct bpf_map *map, void *value, bool delete)
void *ptr;
u32 index;
- if (raw_res_spin_lock_irqsave(&qs->lock, flags))
+ if (raw_res_spin_lock_irqsave(&qs->lock, flags)) {
+ memset(value, 0, qs->map.value_size);
return -EBUSY;
+ }
if (queue_stack_map_is_empty(qs)) {
memset(value, 0, qs->map.value_size);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0499/1518] libbpf: Search /lib64 and /lib in resolve_full_path()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (497 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0498/1518] bpf: Zero queue and stack outputs on lock failure Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0500/1518] riscv, bpf: Fix memory leak in bpf_jit_free Greg Kroah-Hartman
` (499 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ricardo B . Marlière,
Ihor Solodrai, Kumar Kartikeya Dwivedi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ricardo B. Marlière <rbm@suse.com>
[ Upstream commit 7b5ae0481efdac040cea72b4fabd1398109f975b ]
attach_probe/uprobe-lib and uprobe_autoattach selftests fail with "failed
to resolve full path for libc.so.6" on older non-usrmerged distros, where
libc.so.6 lives under a top-level /lib64 or /lib rather than /usr/lib64 or
/usr/lib. Add /lib64:/lib to the search paths, alongside the existing
/usr/lib64:/usr/lib and Debian multiarch entries.
Fixes: 1ce3a60e3c28 ("libbpf: auto-resolve programs/libraries when necessary for uprobes")
Signed-off-by: Ricardo B. Marlière <rbm@suse.com>
Acked-by: Ihor Solodrai <ihor.solodrai@linux.dev>
Link: https://lore.kernel.org/bpf/20260720-selftests-bpf_fixes-v2-3-b450eda93dfe@suse.com
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/lib/bpf/libbpf.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/tools/lib/bpf/libbpf.c b/tools/lib/bpf/libbpf.c
index 3baa6025ecba0..94ee5f52b8661 100644
--- a/tools/lib/bpf/libbpf.c
+++ b/tools/lib/bpf/libbpf.c
@@ -12148,13 +12148,14 @@ static const char *arch_specific_lib_paths(void)
/* Get full path to program/shared library. */
static int resolve_full_path(const char *file, char *result, size_t result_sz)
{
- const char *search_paths[3] = {};
+ const char *search_paths[4] = {};
int i, perm;
if (str_has_sfx(file, ".so") || strstr(file, ".so.")) {
search_paths[0] = getenv("LD_LIBRARY_PATH");
search_paths[1] = "/usr/lib64:/usr/lib";
search_paths[2] = arch_specific_lib_paths();
+ search_paths[3] = "/lib64:/lib";
perm = R_OK;
} else {
search_paths[0] = getenv("PATH");
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0500/1518] riscv, bpf: Fix memory leak in bpf_jit_free
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (498 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0499/1518] libbpf: Search /lib64 and /lib in resolve_full_path() Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0501/1518] riscv, bpf: Fix kernel stack corruption in tailcall with CFI Greg Kroah-Hartman
` (498 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Pu Lehui,
Björn Töpel, Kumar Kartikeya Dwivedi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pu Lehui <pulehui@huawei.com>
[ Upstream commit 369e4635d04801f394d5bd42556f21029e95ff93 ]
When bpf_int_jit_compile() is called for subprograms, it returns early
during the first pass (!prog->is_func || extra_pass is false), keeping
ctx->offset alive for the subsequent extra pass.
If JIT compilation fails for a later subprogram, the BPF core aborts
and calls bpf_jit_free() to clean up the first subprogram. However,
bpf_jit_free() fails to free jit_data->ctx.offset, which causes a
memory leak of the JIT context offsets array.
Fix this by adding the missing kfree(jit_data->ctx.offset) in
bpf_jit_free().
Fixes: 48a8f78c50bd ("bpf, riscv: use prog pack allocator in the BPF JIT")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Pu Lehui <pulehui@huawei.com>
Reviewed-by: Björn Töpel <bjorn@kernel.org>
Acked-by: Björn Töpel <bjorn@kernel.org>
Link: https://lore.kernel.org/bpf/20260708064436.2971933-3-pulehui@huaweicloud.com
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/riscv/net/bpf_jit_core.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/arch/riscv/net/bpf_jit_core.c b/arch/riscv/net/bpf_jit_core.c
index e4ab5bb9c9f64..09bd4eaac63e8 100644
--- a/arch/riscv/net/bpf_jit_core.c
+++ b/arch/riscv/net/bpf_jit_core.c
@@ -251,6 +251,7 @@ void bpf_jit_free(struct bpf_prog *prog)
*/
if (jit_data) {
bpf_jit_binary_pack_finalize(jit_data->ro_header, jit_data->header);
+ kfree(jit_data->ctx.offset);
kfree(jit_data);
}
hdr = bpf_jit_binary_pack_hdr(prog);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0501/1518] riscv, bpf: Fix kernel stack corruption in tailcall with CFI
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (499 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0500/1518] riscv, bpf: Fix memory leak in bpf_jit_free Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0502/1518] bpf, riscv: Fix extable handling for arena load_acquire Greg Kroah-Hartman
` (497 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Pu Lehui,
Björn Töpel, Kumar Kartikeya Dwivedi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pu Lehui <pulehui@huawei.com>
[ Upstream commit 52fb1756ea1d2759dfef2d86245be00b05dac3a2 ]
When CONFIG_CFI_CLANG is enabled, prog->bpf_func already skips the kcfi
instruction during setup. Including it again in the tailcall jump offset
causes it to jump over an extra 4 bytes, skipping the stack pointer
adjustment, which will result in kernel stack corruption.
Fixes: 30a59cc79754 ("riscv, bpf: Fix possible infinite tailcall when CONFIG_CFI_CLANG is enabled")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Pu Lehui <pulehui@huawei.com>
Reviewed-by: Björn Töpel <bjorn@kernel.org>
Acked-by: Björn Töpel <bjorn@kernel.org>
Link: https://lore.kernel.org/bpf/20260708064436.2971933-5-pulehui@huaweicloud.com
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/riscv/net/bpf_jit_comp64.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/arch/riscv/net/bpf_jit_comp64.c b/arch/riscv/net/bpf_jit_comp64.c
index 9e9e6dcfc4825..1e9b2475f514c 100644
--- a/arch/riscv/net/bpf_jit_comp64.c
+++ b/arch/riscv/net/bpf_jit_comp64.c
@@ -18,7 +18,6 @@
#define RV_MAX_REG_ARGS 8
#define RV_FENTRY_NINSNS 2
#define RV_FENTRY_NBYTES (RV_FENTRY_NINSNS * 4)
-#define RV_KCFI_NINSNS (IS_ENABLED(CONFIG_CFI) ? 1 : 0)
/* imm that allows emit_imm to emit max count insns */
#define RV_MAX_COUNT_IMM 0x7FFF7FF7FF7FF7FF
@@ -272,8 +271,8 @@ static void __build_epilogue(bool is_tail_call, struct rv_jit_context *ctx)
if (!is_tail_call)
emit_addiw(RV_REG_A0, RV_REG_A5, 0, ctx);
emit_jalr(RV_REG_ZERO, is_tail_call ? RV_REG_T3 : RV_REG_RA,
- /* kcfi, fentry and TCC init insns will be skipped on tailcall */
- is_tail_call ? (RV_KCFI_NINSNS + RV_FENTRY_NINSNS + 1) * 4 : 0,
+ /* fentry and TCC init insns will be skipped on tailcall */
+ is_tail_call ? (RV_FENTRY_NINSNS + 1) * 4 : 0,
ctx);
}
@@ -1973,6 +1972,8 @@ void bpf_jit_build_prologue(struct rv_jit_context *ctx, bool is_subprog)
/* emit kcfi type preamble immediately before the first insn */
emit_kcfi(is_subprog ? cfi_bpf_subprog_hash : cfi_bpf_hash, ctx);
+ /* bpf prog starts here as kcfi skipped during prog->bpf_func setup */
+
/* nops reserved for auipc+jalr pair */
for (i = 0; i < RV_FENTRY_NINSNS; i++)
emit(rv_nop(), ctx);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0502/1518] bpf, riscv: Fix extable handling for arena load_acquire
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (500 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0501/1518] riscv, bpf: Fix kernel stack corruption in tailcall with CFI Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0503/1518] ACPI: battery: Adjust charging status validation check Greg Kroah-Hartman
` (496 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pu Lehui, Feng Jiang,
Björn Töpel, Kumar Kartikeya Dwivedi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Feng Jiang <jiangfeng@kylinos.cn>
[ Upstream commit 5eb8921371c6fd117d4a328b6053dfda38707df8 ]
emit_atomic_ld_st() returns 1 to have build_body() skip the zext after
a sub-word load_acquire. The caller does "ret = ret ?:
add_exception_handler(...)", which skips add_exception_handler() on any
non-zero ret, so the extable entry is missing and a faulting
PROBE_ATOMIC load_acquire oopses.
REG_DONT_CLEAR_MARKER leaves rd stale on fault, and the verifier still
thinks the load overwrote it, so a program can leak it through a map.
Check ret >= 0 before calling add_exception_handler(), and pass rd for
LOAD_ACQ so the fault zeroes rd like a PROBE_MEM load. Return ret
unchanged for the zext skip.
Fixes: fb7cefabae81 ("riscv, bpf: Add support arena atomics for RV64")
Suggested-by: Pu Lehui <pulehui@huawei.com>
Signed-off-by: Feng Jiang <jiangfeng@kylinos.cn>
Reviewed-by: Pu Lehui <pulehui@huawei.com>
Reviewed-by: Björn Töpel <bjorn@kernel.org>
Acked-by: Björn Töpel <bjorn@kernel.org>
Link: https://lore.kernel.org/bpf/20260720-bpf-riscv-fix-extable-v4-1-165c0b3b07d5@kylinos.cn
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/riscv/net/bpf_jit_comp64.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/arch/riscv/net/bpf_jit_comp64.c b/arch/riscv/net/bpf_jit_comp64.c
index 1e9b2475f514c..93beb95d0a886 100644
--- a/arch/riscv/net/bpf_jit_comp64.c
+++ b/arch/riscv/net/bpf_jit_comp64.c
@@ -1925,7 +1925,12 @@ int bpf_jit_emit_insn(const struct bpf_insn *insn, struct rv_jit_context *ctx,
else
ret = emit_atomic_rmw(rd, rs, insn, ctx);
- ret = ret ?: add_exception_handler(insn, REG_DONT_CLEAR_MARKER, ctx);
+ /* ret can be 1 (skip-zext); extable entry still needs to be added */
+ if (ret >= 0)
+ ret = add_exception_handler(insn,
+ insn->imm == BPF_LOAD_ACQ ? rd : REG_DONT_CLEAR_MARKER,
+ ctx) ?: ret;
+
if (ret)
return ret;
break;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0503/1518] ACPI: battery: Adjust charging status validation check
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (501 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0502/1518] bpf, riscv: Fix extable handling for arena load_acquire Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0504/1518] virt: arm-cca-guest: use migrate_disable() for attestation token requests Greg Kroah-Hartman
` (495 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, golne tree, Rafael J. Wysocki,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
[ Upstream commit 77ce4be0d8d53c528d1663ab62a14d93d5853f11 ]
Commit bb1256e0ddc7 ("ACPI: battery: fix incorrect charging status when
current is zero") added a charge rate check to validate the "charging"
status of the battery, but that check is reported to cause some systems
to misbehave [1]. Namely, it causes the "not charging" status to be
reported on them while the battery is in fact charging (and they were
correctly reporting the "charging" status in that case previously).
To address that, check if the battery is full in addition to checking
the charge rate when the "charging" status is reported by the platform
firmware and only change it to "not charging" if the battery is full and
its charge rate is zero or it is unknown.
Fixes: bb1256e0ddc7 ("ACPI: battery: fix incorrect charging status when current is zero")
Reported-by: golne tree <lrepper@outlook.de>
Tested-by: golne tree <lrepper@outlook.de>
Closes: https://lore.kernel.org/linux-acpi/AM9P193MB158895CFE0DDFA62FCD1DA5ED0F22@AM9P193MB1588.EURP193.PROD.OUTLOOK.COM/ [1]
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/6286911.lOV4Wx5bFT@rafael.j.wysocki
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/battery.c | 36 +++++++++++++++++++-----------------
1 file changed, 19 insertions(+), 17 deletions(-)
diff --git a/drivers/acpi/battery.c b/drivers/acpi/battery.c
index 8196c17b5a970..296c2981b1a73 100644
--- a/drivers/acpi/battery.c
+++ b/drivers/acpi/battery.c
@@ -151,27 +151,28 @@ static int acpi_battery_technology(struct acpi_battery *battery)
static int acpi_battery_get_state(struct acpi_battery *battery);
-static int acpi_battery_is_charged(struct acpi_battery *battery)
+static bool acpi_battery_is_full(struct acpi_battery *battery)
{
- /* charging, discharging, critical low or charge limited */
- if (battery->state != 0)
- return 0;
-
/* battery not reporting charge */
if (battery->capacity_now == ACPI_BATTERY_VALUE_UNKNOWN ||
battery->capacity_now == 0)
- return 0;
+ return false;
/* good batteries update full_charge as the batteries degrade */
if (battery->full_charge_capacity == battery->capacity_now)
- return 1;
+ return true;
/* fallback to using design values for broken batteries */
- if (battery->design_capacity <= battery->capacity_now)
- return 1;
+ return battery->design_capacity <= battery->capacity_now;
+}
- /* we don't do any sort of metric based on percentages */
- return 0;
+static int acpi_battery_is_charged(struct acpi_battery *battery)
+{
+ /* charging, discharging, critical low or charge limited */
+ if (battery->state != 0)
+ return 0;
+
+ return acpi_battery_is_full(battery);
}
static bool acpi_battery_is_degraded(struct acpi_battery *battery)
@@ -212,13 +213,14 @@ static int acpi_battery_get_property(struct power_supply *psy,
if (battery->state & ACPI_BATTERY_STATE_DISCHARGING)
val->intval = acpi_battery_handle_discharging(battery);
else if (battery->state & ACPI_BATTERY_STATE_CHARGING)
- /* Validate the status by checking the current. */
- if (battery->rate_now != ACPI_BATTERY_VALUE_UNKNOWN &&
- battery->rate_now == 0) {
- /* On charge but no current (0W/0mA). */
- val->intval = POWER_SUPPLY_STATUS_NOT_CHARGING;
- } else {
+ /* Check the rate and capacity to validate the status. */
+ if (!acpi_battery_is_full(battery) ||
+ (battery->rate_now != ACPI_BATTERY_VALUE_UNKNOWN &&
+ battery->rate_now > 0)) {
val->intval = POWER_SUPPLY_STATUS_CHARGING;
+ } else {
+ /* Full and zero rate. */
+ val->intval = POWER_SUPPLY_STATUS_NOT_CHARGING;
}
else if (battery->state & ACPI_BATTERY_STATE_CHARGE_LIMITING)
val->intval = POWER_SUPPLY_STATUS_NOT_CHARGING;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0504/1518] virt: arm-cca-guest: use migrate_disable() for attestation token requests
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (502 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0503/1518] ACPI: battery: Adjust charging status validation check Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0505/1518] bpf: Fix offset warn check for bpf_res_spin_lock Greg Kroah-Hartman
` (494 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kohei Enju, Suzuki K Poulose,
Gavin Shan, Steven Price, Will Deacon, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kohei Enju <enju.kohei@fujitsu.com>
[ Upstream commit 24f55f511b9e1c19dc48d11bfe0dc60c86bdb376 ]
The RSI attestation token init and continue calls must be issued from
the same CPU. arm_cca_report_new() currently snapshots the CPU number
and uses smp_call_function_single() to issue those calls on that CPU.
With CONFIG_DEBUG_PREEMPT=y, the smp_processor_id() call used for the
snapshot triggers a debug splat [0] because it runs in preemptible
context. The snapshot does not pin the task to that CPU; it is only used
to choose the target CPU for smp_call_function_single(), which can fail
if that CPU is no longer available.
Use migrate_disable() and issue the token init and continue operations
directly, without the smp_call_function_single() callbacks. This keeps
the token request sequence on the same CPU while preserving a sleepable
context for the GFP_KERNEL allocations needed after the init call.
[0]
BUG: using smp_processor_id() in preemptible [00000000] code: cca-workload-at/264
caller is debug_smp_processor_id+0x20/0x30
CPU: 0 UID: 0 PID: 264 Comm: cca-workload-at Not tainted 7.1.0-rc1-00044-g55542ab273f2 #80 PREEMPT(lazy)
Hardware name: linux,dummy-virt (DT)
Call trace:
[...]
check_preemption_disabled+0xd8/0xf8
debug_smp_processor_id+0x20/0x30
arm_cca_report_new+0x48/0x278
tsm_report_read+0x154/0x1f8
tsm_report_outblob_read+0x20/0x38
configfs_bin_read_iter+0x118/0x208
vfs_read+0x220/0x318
[...]
Fixes: 7999edc484ca ("virt: arm-cca-guest: TSM_REPORT support for realms")
Signed-off-by: Kohei Enju <enju.kohei@fujitsu.com>
Reviewed-by: Suzuki K Poulose <suzuki.poulose@arm.com>
Tested-by: Suzuki K Poulose <suzuki.poulose@arm.com>
Reviewed-by: Gavin Shan <gshan@redhat.com>
Reviewed-by: Steven Price <steven.price@arm.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../virt/coco/arm-cca-guest/arm-cca-guest.c | 97 +++++++------------
1 file changed, 36 insertions(+), 61 deletions(-)
diff --git a/drivers/virt/coco/arm-cca-guest/arm-cca-guest.c b/drivers/virt/coco/arm-cca-guest/arm-cca-guest.c
index 66d00b6ceb789..a38df08da6fa0 100644
--- a/drivers/virt/coco/arm-cca-guest/arm-cca-guest.c
+++ b/drivers/virt/coco/arm-cca-guest/arm-cca-guest.c
@@ -16,54 +16,38 @@
/**
* struct arm_cca_token_info - a descriptor for the token buffer.
- * @challenge: Pointer to the challenge data
- * @challenge_size: Size of the challenge data
* @granule: PA of the granule to which the token will be written
* @offset: Offset within granule to start of buffer in bytes
- * @result: result of rsi_attestation_token_continue operation
*/
struct arm_cca_token_info {
- void *challenge;
- unsigned long challenge_size;
phys_addr_t granule;
unsigned long offset;
- unsigned long result;
};
-static void arm_cca_attestation_init(void *param)
-{
- struct arm_cca_token_info *info;
-
- info = (struct arm_cca_token_info *)param;
-
- info->result = rsi_attestation_token_init(info->challenge,
- info->challenge_size);
-}
-
/**
* arm_cca_attestation_continue - Retrieve the attestation token data.
*
- * @param: pointer to the arm_cca_token_info
+ * @info: pointer to the arm_cca_token_info
*
* Attestation token generation is a long running operation and therefore
* the token data may not be retrieved in a single call. Moreover, the
* token retrieval operation must be requested on the same CPU on which the
* attestation token generation was initialised.
- * This helper function is therefore scheduled on the same CPU multiple
+ * This helper function must therefore be executed on the same CPU multiple
* times until the entire token data is retrieved.
*/
-static void arm_cca_attestation_continue(void *param)
+static unsigned long
+arm_cca_attestation_continue(struct arm_cca_token_info *info)
{
+ unsigned long ret;
unsigned long len;
unsigned long size;
- struct arm_cca_token_info *info;
-
- info = (struct arm_cca_token_info *)param;
size = RSI_GRANULE_SIZE - info->offset;
- info->result = rsi_attestation_token_continue(info->granule,
- info->offset, size, &len);
+ ret = rsi_attestation_token_continue(info->granule, info->offset, size,
+ &len);
info->offset += len;
+ return ret;
}
/**
@@ -74,8 +58,8 @@ static void arm_cca_attestation_continue(void *param)
*
* Initialise the attestation token generation using the challenge data
* passed in the TSM descriptor. Allocate memory for the attestation token
- * and schedule calls to retrieve the attestation token on the same CPU
- * on which the attestation token generation was initialised.
+ * and retrieve the attestation token on the same CPU on which the
+ * attestation token generation was initialised.
*
* The challenge data must be at least 32 bytes and no more than 64 bytes. If
* less than 64 bytes are provided it will be zero padded to 64 bytes.
@@ -85,12 +69,11 @@ static void arm_cca_attestation_continue(void *param)
* * %-EINVAL - A parameter was not valid.
* * %-ENOMEM - Out of memory.
* * %-EFAULT - Failed to get IPA for memory page(s).
- * * A negative status code as returned by smp_call_function_single().
*/
static int arm_cca_report_new(struct tsm_report *report, void *data)
{
- int ret;
- int cpu;
+ int ret = 0;
+ unsigned long rsi_result;
long max_size;
unsigned long token_size = 0;
struct arm_cca_token_info info;
@@ -103,37 +86,33 @@ static int arm_cca_report_new(struct tsm_report *report, void *data)
/*
* The attestation token 'init' and 'continue' calls must be
- * performed on the same CPU. smp_call_function_single() is used
- * instead of simply calling get_cpu() because of the need to
- * allocate outblob based on the returned value from the 'init'
- * call and that cannot be done in an atomic context.
+ * performed on the same CPU, so disable CPU migration around
+ * those operations.
*/
- cpu = smp_processor_id();
+ migrate_disable();
- info.challenge = desc->inblob;
- info.challenge_size = desc->inblob_len;
-
- ret = smp_call_function_single(cpu, arm_cca_attestation_init,
- &info, true);
- if (ret)
- return ret;
- max_size = info.result;
-
- if (max_size <= 0)
- return -EINVAL;
+ max_size = rsi_attestation_token_init(desc->inblob, desc->inblob_len);
+ if (max_size <= 0) {
+ ret = -EINVAL;
+ goto exit_migrate_enable;
+ }
/* Allocate outblob */
token = kvzalloc(max_size, GFP_KERNEL);
- if (!token)
- return -ENOMEM;
+ if (!token) {
+ ret = -ENOMEM;
+ goto exit_migrate_enable;
+ }
/*
* Since the outblob may not be physically contiguous, use a page
* to bounce the buffer from RMM.
*/
buf = alloc_pages_exact(RSI_GRANULE_SIZE, GFP_KERNEL);
- if (!buf)
- return -ENOMEM;
+ if (!buf) {
+ ret = -ENOMEM;
+ goto exit_migrate_enable;
+ }
/* Get the PA of the memory page(s) that were allocated */
info.granule = (unsigned long)virt_to_phys(buf);
@@ -144,21 +123,15 @@ static int arm_cca_report_new(struct tsm_report *report, void *data)
info.offset = 0;
do {
/*
- * Schedule a call to retrieve a sub-granule chunk
- * of data per loop iteration.
+ * Retrieve a sub-granule chunk of data per loop
+ * iteration.
*/
- ret = smp_call_function_single(cpu,
- arm_cca_attestation_continue,
- (void *)&info, true);
- if (ret != 0) {
- token_size = 0;
- goto exit_free_granule_page;
- }
- } while (info.result == RSI_INCOMPLETE &&
+ rsi_result = arm_cca_attestation_continue(&info);
+ } while (rsi_result == RSI_INCOMPLETE &&
info.offset < RSI_GRANULE_SIZE);
/* Break out in case of failure */
- if (info.result != RSI_SUCCESS && info.result != RSI_INCOMPLETE) {
+ if (rsi_result != RSI_SUCCESS && rsi_result != RSI_INCOMPLETE) {
ret = -ENXIO;
token_size = 0;
goto exit_free_granule_page;
@@ -173,12 +146,14 @@ static int arm_cca_report_new(struct tsm_report *report, void *data)
break;
memcpy(&token[token_size], buf, info.offset);
token_size += info.offset;
- } while (info.result == RSI_INCOMPLETE);
+ } while (rsi_result == RSI_INCOMPLETE);
report->outblob = no_free_ptr(token);
exit_free_granule_page:
report->outblob_len = token_size;
free_pages_exact(buf, RSI_GRANULE_SIZE);
+exit_migrate_enable:
+ migrate_enable();
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0505/1518] bpf: Fix offset warn check for bpf_res_spin_lock
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (503 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0504/1518] virt: arm-cca-guest: use migrate_disable() for attestation token requests Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0506/1518] bpf: Preserve unique-field state across nested structs Greg Kroah-Hartman
` (493 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kumar Kartikeya Dwivedi,
Eduard Zingerman, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kumar Kartikeya Dwivedi <memxor@gmail.com>
[ Upstream commit 04e19012efaec2bfd8c3b37fd8a6c3f1fe731ffc ]
Sashiko pointed out correctly that the case statement for
BPF_RES_SPIN_LOCK incorrectly checks offset for BPF_SPIN_LOCK.
Fix it by checking res_spin_lock_off instead.
Fixes: 0de2046137f9 ("bpf: Implement verifier support for rqspinlock")
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Link: https://patch.msgid.link/20260719153634.2908692-2-memxor@gmail.com
Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/btf.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/kernel/bpf/btf.c b/kernel/bpf/btf.c
index 7a4618c054075..e576b3eda5ea7 100644
--- a/kernel/bpf/btf.c
+++ b/kernel/bpf/btf.c
@@ -4003,7 +4003,7 @@ struct btf_record *btf_parse_fields(const struct btf *btf, const struct btf_type
rec->spin_lock_off = rec->fields[i].offset;
break;
case BPF_RES_SPIN_LOCK:
- WARN_ON_ONCE(rec->spin_lock_off >= 0);
+ WARN_ON_ONCE(rec->res_spin_lock_off >= 0);
/* Cache offset for faster lookup at runtime */
rec->res_spin_lock_off = rec->fields[i].offset;
break;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0506/1518] bpf: Preserve unique-field state across nested structs
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (504 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0505/1518] bpf: Fix offset warn check for bpf_res_spin_lock Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0507/1518] bpf: Mark bpf_refcount field as unique Greg Kroah-Hartman
` (492 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kumar Kartikeya Dwivedi,
Eduard Zingerman, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kumar Kartikeya Dwivedi <memxor@gmail.com>
[ Upstream commit f08619f060468076e4acbdc10e0713af20d60e65 ]
btf_find_struct_field() initializes a fresh seen mask for every recursive
descent. Unique special fields in different levels of the same aggregate
therefore do not see one another. The duplicate fields can reach
btf_parse_fields(), where they trigger an invariant WARN_ON_ONCE(). A
crafted user BTF can consequently trigger the warning before map creation
checks capabilities.
Initialize the seen mask once in btf_find_field() and pass the same pointer
through struct, datasec, and nested-struct walks. This gives the entire field
traversal one shared uniqueness state.
Fixes: 64e8ee814819 ("bpf: look into the types of the fields of a struct type recursively.")
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Link: https://patch.msgid.link/20260719153634.2908692-3-memxor@gmail.com
Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/btf.c | 26 ++++++++++++++------------
1 file changed, 14 insertions(+), 12 deletions(-)
diff --git a/kernel/bpf/btf.c b/kernel/bpf/btf.c
index e576b3eda5ea7..6d616a67aa40c 100644
--- a/kernel/bpf/btf.c
+++ b/kernel/bpf/btf.c
@@ -3586,7 +3586,7 @@ static int btf_repeat_fields(struct btf_field_info *info, int info_cnt,
static int btf_find_struct_field(const struct btf *btf,
const struct btf_type *t, u32 field_mask,
struct btf_field_info *info, int info_cnt,
- u32 level);
+ u32 level, u32 *seen_mask);
/* Find special fields in the struct type of a field.
*
@@ -3597,7 +3597,7 @@ static int btf_find_struct_field(const struct btf *btf,
static int btf_find_nested_struct(const struct btf *btf, const struct btf_type *t,
u32 off, u32 nelems,
u32 field_mask, struct btf_field_info *info,
- int info_cnt, u32 level)
+ int info_cnt, u32 level, u32 *seen_mask)
{
int ret, err, i;
@@ -3605,7 +3605,7 @@ static int btf_find_nested_struct(const struct btf *btf, const struct btf_type *
if (level >= MAX_RESOLVE_DEPTH)
return -E2BIG;
- ret = btf_find_struct_field(btf, t, field_mask, info, info_cnt, level);
+ ret = btf_find_struct_field(btf, t, field_mask, info, info_cnt, level, seen_mask);
if (ret <= 0)
return ret;
@@ -3662,7 +3662,7 @@ static int btf_find_field_one(const struct btf *btf,
if (expected_size && expected_size != sz * nelems)
return 0;
ret = btf_find_nested_struct(btf, var_type, off, nelems, field_mask,
- &info[0], info_cnt, level);
+ &info[0], info_cnt, level, seen_mask);
return ret;
}
@@ -3727,11 +3727,11 @@ static int btf_find_field_one(const struct btf *btf,
static int btf_find_struct_field(const struct btf *btf,
const struct btf_type *t, u32 field_mask,
struct btf_field_info *info, int info_cnt,
- u32 level)
+ u32 level, u32 *seen_mask)
{
int ret, idx = 0;
const struct btf_member *member;
- u32 i, off, seen_mask = 0;
+ u32 i, off;
for_each_member(i, t, member) {
const struct btf_type *member_type = btf_type_by_id(btf,
@@ -3745,7 +3745,7 @@ static int btf_find_struct_field(const struct btf *btf,
ret = btf_find_field_one(btf, t, member_type, i,
off, 0,
- field_mask, &seen_mask,
+ field_mask, seen_mask,
&info[idx], info_cnt - idx, level);
if (ret < 0)
return ret;
@@ -3756,11 +3756,11 @@ static int btf_find_struct_field(const struct btf *btf,
static int btf_find_datasec_var(const struct btf *btf, const struct btf_type *t,
u32 field_mask, struct btf_field_info *info,
- int info_cnt, u32 level)
+ int info_cnt, u32 level, u32 *seen_mask)
{
int ret, idx = 0;
const struct btf_var_secinfo *vsi;
- u32 i, off, seen_mask = 0;
+ u32 i, off;
for_each_vsi(i, t, vsi) {
const struct btf_type *var = btf_type_by_id(btf, vsi->type);
@@ -3768,7 +3768,7 @@ static int btf_find_datasec_var(const struct btf *btf, const struct btf_type *t,
off = vsi->offset;
ret = btf_find_field_one(btf, var, var_type, -1, off, vsi->size,
- field_mask, &seen_mask,
+ field_mask, seen_mask,
&info[idx], info_cnt - idx,
level);
if (ret < 0)
@@ -3782,10 +3782,12 @@ static int btf_find_field(const struct btf *btf, const struct btf_type *t,
u32 field_mask, struct btf_field_info *info,
int info_cnt)
{
+ u32 seen_mask = 0;
+
if (__btf_type_is_struct(t))
- return btf_find_struct_field(btf, t, field_mask, info, info_cnt, 0);
+ return btf_find_struct_field(btf, t, field_mask, info, info_cnt, 0, &seen_mask);
else if (btf_type_is_datasec(t))
- return btf_find_datasec_var(btf, t, field_mask, info, info_cnt, 0);
+ return btf_find_datasec_var(btf, t, field_mask, info, info_cnt, 0, &seen_mask);
return -EINVAL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0507/1518] bpf: Mark bpf_refcount field as unique
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (505 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0506/1518] bpf: Preserve unique-field state across nested structs Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0508/1518] RDMA/srpt: Pass the mapped task attribute to target_init_cmd() Greg Kroah-Hartman
` (491 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kumar Kartikeya Dwivedi,
Eduard Zingerman, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kumar Kartikeya Dwivedi <memxor@gmail.com>
[ Upstream commit 61e655391cb19c31f94ecd4354f624c81ce4cf75 ]
BPF_REFCOUNT is not marked as a unique field, while it should be. Fix
this oversight.
Fixes: d54730b50bae ("bpf: Introduce opaque bpf_refcount struct and add btf_record plumbing")
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Link: https://patch.msgid.link/20260719153634.2908692-4-memxor@gmail.com
Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/btf.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/kernel/bpf/btf.c b/kernel/bpf/btf.c
index 6d616a67aa40c..f0b865afa9d16 100644
--- a/kernel/bpf/btf.c
+++ b/kernel/bpf/btf.c
@@ -3504,7 +3504,7 @@ static int btf_get_field_type(const struct btf *btf, const struct btf_type *var_
{ BPF_LIST_NODE, "bpf_list_node", false },
{ BPF_RB_ROOT, "bpf_rb_root", false },
{ BPF_RB_NODE, "bpf_rb_node", false },
- { BPF_REFCOUNT, "bpf_refcount", false },
+ { BPF_REFCOUNT, "bpf_refcount", true },
};
int type = 0, i;
const char *name = __btf_name_by_offset(btf, var_type->name_off);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0508/1518] RDMA/srpt: Pass the mapped task attribute to target_init_cmd()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (506 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0507/1518] bpf: Mark bpf_refcount field as unique Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0509/1518] PCI: j721e: Fix incorrect max_lanes for J7200 Greg Kroah-Hartman
` (490 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bart Van Assche, Leon Romanovsky,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leon Romanovsky <leonro@nvidia.com>
[ Upstream commit ef63cc441703412628a517dda354f3e51fe2dc92 ]
srpt_handle_cmd() maps the initiator-supplied srp_cmd->task_attr into
cmd->sam_task_attr, but then hands a hardcoded TCM_SIMPLE_TAG to
target_init_cmd().
Pass the already mapped cmd->sam_task_attr instead, so target core sees the
attribute the initiator requested.
Fixes: 9474b043132f ("ib_srpt: Convert I/O path to target_submit_cmd + drop legacy ioctx->kref")
Link: https://patch.msgid.link/20260721-b4-scsi-ordering-violation-due-to-hardc-v1-1-07205aab71bb@nvidia.com
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/ulp/srpt/ib_srpt.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/infiniband/ulp/srpt/ib_srpt.c b/drivers/infiniband/ulp/srpt/ib_srpt.c
index 81efda7840aab..212d4c7662c8a 100644
--- a/drivers/infiniband/ulp/srpt/ib_srpt.c
+++ b/drivers/infiniband/ulp/srpt/ib_srpt.c
@@ -1603,7 +1603,7 @@ static void srpt_handle_cmd(struct srpt_rdma_ch *ch,
rc = target_init_cmd(cmd, ch->sess, &send_ioctx->sense_data[0],
scsilun_to_int(&srp_cmd->lun), data_len,
- TCM_SIMPLE_TAG, dir, TARGET_SCF_ACK_KREF);
+ cmd->sam_task_attr, dir, TARGET_SCF_ACK_KREF);
if (rc != 0) {
pr_debug("target_submit_cmd() returned %d for tag %#llx\n", rc,
srp_cmd->tag);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0509/1518] PCI: j721e: Fix incorrect max_lanes for J7200
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (507 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0508/1518] RDMA/srpt: Pass the mapped task attribute to target_init_cmd() Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0510/1518] RDMA/erdma: Fix CEQ tasklet use-after-free on removal Greg Kroah-Hartman
` (489 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Takuma Fujiwara,
Manivannan Sadhasivam, Siddharth Vadapalli, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Takuma Fujiwara <t-fujiwara1@ti.com>
[ Upstream commit 7147a7bfce47acd48c3738130bf0bd692bfd80de ]
The PCIe Controller in the J7200 SoC supports a 4-lane configuration.
However, j7200_pcie_rc_data and j7200_pcie_ep_data incorrectly set
.max_lanes = 2, limiting operation to fewer lanes than the hardware
supports.
Set .max_lanes = 4 for both j7200_pcie_rc_data and j7200_pcie_ep_data to
match the hardware capability.
See J7200 Technical Reference Manual (SPRUIU1D), section 12.2.3.1.1
for further details: https://www.ti.com/lit/pdf/spruiu1d
Fixes: 3ac7f14084f5 ("PCI: j721e: Add per platform maximum lane settings")
Signed-off-by: Takuma Fujiwara <t-fujiwara1@ti.com>
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Reviewed-by: Siddharth Vadapalli <s-vadapalli@ti.com>
Link: https://patch.msgid.link/20260721155743.3347659-1-t-fujiwara1@ti.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pci/controller/cadence/pci-j721e.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/pci/controller/cadence/pci-j721e.c b/drivers/pci/controller/cadence/pci-j721e.c
index 0413d163cfea0..e2ec684cc54ca 100644
--- a/drivers/pci/controller/cadence/pci-j721e.c
+++ b/drivers/pci/controller/cadence/pci-j721e.c
@@ -381,7 +381,7 @@ static const struct j721e_pcie_data j7200_pcie_rc_data = {
.quirk_detect_quiet_flag = true,
.linkdown_irq_regfield = J7200_LINK_DOWN,
.byte_access_allowed = true,
- .max_lanes = 2,
+ .max_lanes = 4,
};
static const struct j721e_pcie_data j7200_pcie_ep_data = {
@@ -389,7 +389,7 @@ static const struct j721e_pcie_data j7200_pcie_ep_data = {
.quirk_detect_quiet_flag = true,
.linkdown_irq_regfield = J7200_LINK_DOWN,
.quirk_disable_flr = true,
- .max_lanes = 2,
+ .max_lanes = 4,
};
static const struct j721e_pcie_data am64_pcie_rc_data = {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0510/1518] RDMA/erdma: Fix CEQ tasklet use-after-free on removal
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (508 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0509/1518] PCI: j721e: Fix incorrect max_lanes for J7200 Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0511/1518] RDMA/mana_ib: drain QP references after partial table insertion Greg Kroah-Hartman
` (488 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ijae Kim, Myeonghun Pak, Cheng Xu,
Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Myeonghun Pak <mhun512@gmail.com>
[ Upstream commit 0ca79979384f031d710c4b3bae065dcb5d95aca3 ]
Each CEQ interrupt handler only schedules eqc->tasklet. The tasklet calls
erdma_ceq_completion_handler(), which reads the DMA-coherent EQ ring
through get_next_valid_eqe() and updates eq->dbrec through notify_eq().
erdma_ceqs_uninit() frees each CEQ IRQ and then destroys its EQ.
free_irq() prevents another hard IRQ and waits for an in-flight handler,
but it does not drain a tasklet that the handler already scheduled. The
tasklet can therefore access eq->qbuf or eq->dbrec after
erdma_eq_destroy() frees them.
Clearing ceq_cb->ready does not synchronize with a tasklet that already
passed the check at the start of erdma_ceq_completion_handler().
Kill the tasklet after free_irq(), when no handler can schedule it again,
and before erdma_ceq_uninit_one() releases the EQ buffers.
Fixes: f2a0a630b953 ("RDMA/erdma: Add event queue implementation")
Co-developed-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
Link: https://patch.msgid.link/20260721082545.47395-1-mhun512@gmail.com
Acked-by: Cheng Xu <chengyou@linux.alibaba.com>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/erdma/erdma_eq.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/infiniband/hw/erdma/erdma_eq.c b/drivers/infiniband/hw/erdma/erdma_eq.c
index 6486234a23600..5610e7f4c6bf7 100644
--- a/drivers/infiniband/hw/erdma/erdma_eq.c
+++ b/drivers/infiniband/hw/erdma/erdma_eq.c
@@ -219,6 +219,7 @@ static void erdma_free_ceq_irq(struct erdma_dev *dev, u16 ceqn)
irq_set_affinity_hint(eqc->irq.msix_vector, NULL);
free_irq(eqc->irq.msix_vector, eqc);
+ tasklet_kill(&eqc->tasklet);
}
static int create_eq_cmd(struct erdma_dev *dev, u32 eqn, struct erdma_eq *eq)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0511/1518] RDMA/mana_ib: drain QP references after partial table insertion
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (509 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0510/1518] RDMA/erdma: Fix CEQ tasklet use-after-free on removal Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0512/1518] RDMA/restrack: Fix typos in the comments Greg Kroah-Hartman
` (487 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Konstantin Taranov, Long Li,
Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leon Romanovsky <leonro@nvidia.com>
[ Upstream commit 97f7c2262c28ebcae64fc957ee978646684a5ed9 ]
mana_table_store_ud_qp() publishes a QP at its send-queue id before
inserting the receive-queue id, dropping the XArray lock between the two
xa_insert_irq() calls. A concurrent completion handler can look up the QP
and take a transient reference. When the second insertion fails, the
rollback erased only the send-queue entry and returned, leaving both the
initial table reference and the transient reference outstanding while RDMA
core frees the QP, causing a use-after-free.
Drain the reference as normal destruction does: drop the initial reference
and wait for qp->free, releasing the QP only after every concurrent lookup
returns its reference.
Fixes: 8001e9257eca ("RDMA/mana_ib: extend mana QP table")
Link: https://patch.msgid.link/20260721-if-mana-table-store-qp-qids-partiall-v1-1-8fb3d2d2b559@nvidia.com
Reviewed-by: Konstantin Taranov <kotaranov@microsoft.com>
Reviewed-by: Long Li <longli@microsoft.com>
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/mana/qp.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/drivers/infiniband/hw/mana/qp.c b/drivers/infiniband/hw/mana/qp.c
index f00bf3b015e73..285b3702198b7 100644
--- a/drivers/infiniband/hw/mana/qp.c
+++ b/drivers/infiniband/hw/mana/qp.c
@@ -459,6 +459,12 @@ static void mana_table_remove_rc_qp(struct mana_ib_dev *mdev, struct mana_ib_qp
xa_erase_irq(&mdev->qp_table_wq, qp->ibqp.qp_num);
}
+static void mana_table_drain_qp_ref(struct mana_ib_qp *qp)
+{
+ mana_put_qp_ref(qp);
+ wait_for_completion(&qp->free);
+}
+
static int mana_table_store_ud_qp(struct mana_ib_dev *mdev, struct mana_ib_qp *qp)
{
u32 qids = qp->ud_qp.queues[MANA_UD_SEND_QUEUE].id | MANA_SENDQ_MASK;
@@ -477,6 +483,7 @@ static int mana_table_store_ud_qp(struct mana_ib_dev *mdev, struct mana_ib_qp *q
remove_sq:
xa_erase_irq(&mdev->qp_table_wq, qids);
+ mana_table_drain_qp_ref(qp);
return err;
}
@@ -524,8 +531,7 @@ static void mana_table_remove_qp(struct mana_ib_dev *mdev,
qp->ibqp.qp_type);
return;
}
- mana_put_qp_ref(qp);
- wait_for_completion(&qp->free);
+ mana_table_drain_qp_ref(qp);
}
static int mana_ib_create_rc_qp(struct ib_qp *ibqp, struct ib_pd *ibpd,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0512/1518] RDMA/restrack: Fix typos in the comments
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (510 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0511/1518] RDMA/mana_ib: drain QP references after partial table insertion Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0513/1518] RDMA/nldev: Fix locking when accessing mr->pd Greg Kroah-Hartman
` (486 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Kalesh AP, Leon Romanovsky,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kalesh AP <kalesh-anakkur.purayil@broadcom.com>
[ Upstream commit d43358cda7c4696e08880aaa58a7df82e471fa7c ]
Fix couple of occurrences of the misspelled word "reource"
in the comments with the correct spelling "resource".
Signed-off-by: Kalesh AP <kalesh-anakkur.purayil@broadcom.com>
Link: https://patch.msgid.link/20251113105457.879903-1-kalesh-anakkur.purayil@broadcom.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Stable-dep-of: 709ba0e5311b ("RDMA/core: Fix use after free in ib_query_qp()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/core/restrack.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/infiniband/core/restrack.c b/drivers/infiniband/core/restrack.c
index a7de6f403fcaf..b097cfcade1cb 100644
--- a/drivers/infiniband/core/restrack.c
+++ b/drivers/infiniband/core/restrack.c
@@ -175,7 +175,7 @@ void rdma_restrack_new(struct rdma_restrack_entry *res,
EXPORT_SYMBOL(rdma_restrack_new);
/**
- * rdma_restrack_add() - add object to the reource tracking database
+ * rdma_restrack_add() - add object to the resource tracking database
* @res: resource entry
*/
void rdma_restrack_add(struct rdma_restrack_entry *res)
@@ -277,7 +277,7 @@ int rdma_restrack_put(struct rdma_restrack_entry *res)
EXPORT_SYMBOL(rdma_restrack_put);
/**
- * rdma_restrack_del() - delete object from the reource tracking database
+ * rdma_restrack_del() - delete object from the resource tracking database
* @res: resource entry
*/
void rdma_restrack_del(struct rdma_restrack_entry *res)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0513/1518] RDMA/nldev: Fix locking when accessing mr->pd
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (511 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0512/1518] RDMA/restrack: Fix typos in the comments Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0514/1518] RDMA/core: Add rdma_restrack_begin/abort/commit_del() operations Greg Kroah-Hartman
` (485 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jason Gunthorpe, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jason Gunthorpe <jgg@nvidia.com>
[ Upstream commit 50d5c02ab8e62325548bd3a6e6b758a9dcd6e7c3 ]
Sashiko points out that, due to rereg_mr, the PD is actually variable and
all the touches in nldev are racy.
Use mr->device instead of mr->pd->device.
Getting the PD restrack ID is more tricky. To avoid disturbing all the
happy paths, add an rdma_restrack_sync() operation which is sort of like
flush_workqueue() or synchronize_irq(): after it returns, all the old
nldev touches to the mr are gone and everything sees the new PD. This
makes it safe to reach into the PD pointer.
Fixes: da5c85078215 ("RDMA/nldev: add driver-specific resource tracking")
Link: https://patch.msgid.link/r/4-v1-29ebd2c229b5+fd5-ib_mr_pd_jgg@nvidia.com
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
Stable-dep-of: 709ba0e5311b ("RDMA/core: Fix use after free in ib_query_qp()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/core/nldev.c | 15 +++++----
drivers/infiniband/core/restrack.c | 49 ++++++++++++++++++++++++++++
drivers/infiniband/core/restrack.h | 1 +
drivers/infiniband/core/uverbs_cmd.c | 10 ++++--
include/rdma/ib_verbs.h | 5 +++
5 files changed, 72 insertions(+), 8 deletions(-)
diff --git a/drivers/infiniband/core/nldev.c b/drivers/infiniband/core/nldev.c
index 79fa29883349f..c92c24e681f11 100644
--- a/drivers/infiniband/core/nldev.c
+++ b/drivers/infiniband/core/nldev.c
@@ -679,7 +679,7 @@ static int fill_res_mr_entry(struct sk_buff *msg, bool has_cap_net_admin,
struct rdma_restrack_entry *res, uint32_t port)
{
struct ib_mr *mr = container_of(res, struct ib_mr, res);
- struct ib_device *dev = mr->pd->device;
+ struct ib_device *dev = mr->device;
if (has_cap_net_admin) {
if (nla_put_u32(msg, RDMA_NLDEV_ATTR_RES_RKEY, mr->rkey))
@@ -695,9 +695,12 @@ static int fill_res_mr_entry(struct sk_buff *msg, bool has_cap_net_admin,
if (nla_put_u32(msg, RDMA_NLDEV_ATTR_RES_MRN, res->id))
return -EMSGSIZE;
- if (!rdma_is_kernel_res(res) &&
- nla_put_u32(msg, RDMA_NLDEV_ATTR_RES_PDN, mr->pd->res.id))
- return -EMSGSIZE;
+ if (!rdma_is_kernel_res(res)) {
+ struct ib_pd *pd = READ_ONCE(mr->pd);
+
+ if (nla_put_u32(msg, RDMA_NLDEV_ATTR_RES_PDN, pd->res.id))
+ return -EMSGSIZE;
+ }
if (fill_res_name_pid(msg, res))
return -EMSGSIZE;
@@ -711,7 +714,7 @@ static int fill_res_mr_raw_entry(struct sk_buff *msg, bool has_cap_net_admin,
struct rdma_restrack_entry *res, uint32_t port)
{
struct ib_mr *mr = container_of(res, struct ib_mr, res);
- struct ib_device *dev = mr->pd->device;
+ struct ib_device *dev = mr->device;
if (!dev->ops.fill_res_mr_entry_raw)
return -EINVAL;
@@ -1001,7 +1004,7 @@ static int fill_stat_mr_entry(struct sk_buff *msg, bool has_cap_net_admin,
struct rdma_restrack_entry *res, uint32_t port)
{
struct ib_mr *mr = container_of(res, struct ib_mr, res);
- struct ib_device *dev = mr->pd->device;
+ struct ib_device *dev = mr->device;
if (nla_put_u32(msg, RDMA_NLDEV_ATTR_RES_MRN, res->id))
goto err;
diff --git a/drivers/infiniband/core/restrack.c b/drivers/infiniband/core/restrack.c
index b097cfcade1cb..2a9636443d254 100644
--- a/drivers/infiniband/core/restrack.c
+++ b/drivers/infiniband/core/restrack.c
@@ -71,6 +71,8 @@ int rdma_restrack_count(struct ib_device *dev, enum rdma_restrack_type type,
xa_lock(&rt->xa);
xas_for_each(&xas, e, U32_MAX) {
+ if (xa_is_zero(e))
+ continue;
if (xa_get_mark(&rt->xa, e->id, RESTRACK_DD) && !show_details)
continue;
cnt++;
@@ -276,6 +278,53 @@ int rdma_restrack_put(struct rdma_restrack_entry *res)
}
EXPORT_SYMBOL(rdma_restrack_put);
+/**
+ * rdma_restrack_sync() - Fence concurrent netlink dumps on an entry
+ * @res: resource entry
+ *
+ * After this returns any concurrent netlink dump threads will see the current
+ * value of the object. This is useful if the object has to be changed and there
+ * is not locking to protect the nl side. Eg for mr->pd. This effectively
+ * destroys the object from a kref/xarray perspective and then immediately
+ * restores it. The kref is acting like a lock to barrier concurrent nl threads.
+ * Callers must ensure rdma_restrack_del() is not concurrently called.
+ */
+void rdma_restrack_sync(struct rdma_restrack_entry *res)
+{
+ struct rdma_restrack_entry *old;
+ struct rdma_restrack_root *rt;
+ struct task_struct *task;
+ struct ib_device *dev;
+
+ if (!res->valid || res->no_track)
+ return;
+
+ dev = res_to_dev(res);
+ if (WARN_ON(!dev))
+ return;
+
+ rt = &dev->res[res->type];
+ if (WARN_ON(xa_get_mark(&rt->xa, res->id, RESTRACK_DD)))
+ return;
+
+ old = xa_cmpxchg(&rt->xa, res->id, res, XA_ZERO_ENTRY, GFP_KERNEL);
+ if (WARN_ON(old != res))
+ return;
+
+ task = res->task;
+ if (task)
+ get_task_struct(task);
+ rdma_restrack_put(res);
+ wait_for_completion(&res->comp);
+ reinit_completion(&res->comp);
+ if (task)
+ res->task = task;
+ kref_init(&res->kref);
+
+ xa_cmpxchg(&rt->xa, res->id, XA_ZERO_ENTRY, res, GFP_KERNEL);
+}
+EXPORT_SYMBOL(rdma_restrack_sync);
+
/**
* rdma_restrack_del() - delete object from the resource tracking database
* @res: resource entry
diff --git a/drivers/infiniband/core/restrack.h b/drivers/infiniband/core/restrack.h
index 6a04fc41f7380..75b8d1005a984 100644
--- a/drivers/infiniband/core/restrack.h
+++ b/drivers/infiniband/core/restrack.h
@@ -27,6 +27,7 @@ int rdma_restrack_init(struct ib_device *dev);
void rdma_restrack_clean(struct ib_device *dev);
void rdma_restrack_add(struct rdma_restrack_entry *res);
void rdma_restrack_del(struct rdma_restrack_entry *res);
+void rdma_restrack_sync(struct rdma_restrack_entry *res);
void rdma_restrack_new(struct rdma_restrack_entry *res,
enum rdma_restrack_type type);
void rdma_restrack_set_name(struct rdma_restrack_entry *res,
diff --git a/drivers/infiniband/core/uverbs_cmd.c b/drivers/infiniband/core/uverbs_cmd.c
index f4616deeca545..95c1974e02661 100644
--- a/drivers/infiniband/core/uverbs_cmd.c
+++ b/drivers/infiniband/core/uverbs_cmd.c
@@ -47,6 +47,7 @@
#include "uverbs.h"
#include "core_priv.h"
+#include "restrack.h"
/*
* Copy a response to userspace. If the provided 'resp' is larger than the
@@ -830,6 +831,10 @@ static int ib_uverbs_rereg_mr(struct uverbs_attr_bundle *attrs)
ret = PTR_ERR(new_pd);
goto put_uobjs;
}
+ if (new_pd == orig_pd) {
+ uobj_put_obj_read(new_pd);
+ cmd.flags &= ~IB_MR_REREG_PD;
+ }
} else {
new_pd = mr->pd;
}
@@ -875,9 +880,10 @@ static int ib_uverbs_rereg_mr(struct uverbs_attr_bundle *attrs)
mr = new_mr;
} else {
if (cmd.flags & IB_MR_REREG_PD) {
- atomic_dec(&orig_pd->usecnt);
- mr->pd = new_pd;
atomic_inc(&new_pd->usecnt);
+ WRITE_ONCE(mr->pd, new_pd);
+ rdma_restrack_sync(&mr->res);
+ atomic_dec(&orig_pd->usecnt);
}
if (cmd.flags & IB_MR_REREG_TRANS) {
mr->iova = cmd.hca_va;
diff --git a/include/rdma/ib_verbs.h b/include/rdma/ib_verbs.h
index eaeec00ef4c15..0a1be798255bb 100644
--- a/include/rdma/ib_verbs.h
+++ b/include/rdma/ib_verbs.h
@@ -1870,6 +1870,11 @@ struct ib_dmah {
struct ib_mr {
struct ib_device *device;
+ /*
+ * Due to IB_MR_REREG_PD pd is not a fixed pointer and can change. For a
+ * user MR, this value should only be read from a system call that holds
+ * the uobject lock, or the driver should disable in-place REREG_PD.
+ */
struct ib_pd *pd;
u32 lkey;
u32 rkey;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0514/1518] RDMA/core: Add rdma_restrack_begin/abort/commit_del() operations
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (512 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0513/1518] RDMA/nldev: Fix locking when accessing mr->pd Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0515/1518] RDMA/core: Fix use after free in ib_query_qp() Greg Kroah-Hartman
` (484 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Patrisious Haddad, Michael Guralnik,
Edward Srouji, Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Patrisious Haddad <phaddad@nvidia.com>
[ Upstream commit 8d186210677c0322db886973bcec9aa4d21b51cd ]
Add rdma_restrack_abort_del(), rdma_restrack_begin_del() and
rdma_restrack_commit_del() functions to allow deleting a resource from
the xarray to effectively prevent future access to it and wait for all
current users to finish while preserving its index in the xarray to
allow to re-insert it if needed with guaranteed success.
This is a preparatory change for subsequent patches in the series
which will use these functions to fix the cleanup flow.
Signed-off-by: Patrisious Haddad <phaddad@nvidia.com>
Reviewed-by: Michael Guralnik <michaelgur@nvidia.com>
Signed-off-by: Edward Srouji <edwards@nvidia.com>
Link: https://patch.msgid.link/20260713-restrack-uaf-fix-resub-v2-1-bbe8bb270d51@nvidia.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Stable-dep-of: 709ba0e5311b ("RDMA/core: Fix use after free in ib_query_qp()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/core/restrack.c | 165 +++++++++++++++++++++++------
drivers/infiniband/core/restrack.h | 3 +
2 files changed, 135 insertions(+), 33 deletions(-)
diff --git a/drivers/infiniband/core/restrack.c b/drivers/infiniband/core/restrack.c
index 2a9636443d254..56aa1def56fac 100644
--- a/drivers/infiniband/core/restrack.c
+++ b/drivers/infiniband/core/restrack.c
@@ -129,6 +129,46 @@ static void rdma_restrack_attach_task(struct rdma_restrack_entry *res,
res->user = true;
}
+static struct rdma_restrack_root *res_to_rt(struct rdma_restrack_entry *res)
+{
+ struct ib_device *dev = res_to_dev(res);
+
+ if (WARN_ON(!dev))
+ return NULL;
+
+ return &dev->res[res->type];
+}
+
+static void restrack_drain_res(struct rdma_restrack_root *rt,
+ struct rdma_restrack_entry *res)
+{
+ if (rt) {
+ struct rdma_restrack_entry *old;
+
+ old = xa_cmpxchg(&rt->xa, res->id, res, XA_ZERO_ENTRY,
+ GFP_KERNEL);
+ WARN_ON(old != res);
+ }
+
+ rdma_restrack_put(res);
+ wait_for_completion(&res->comp);
+}
+
+static void restrack_restore_res(struct rdma_restrack_root *rt,
+ struct rdma_restrack_entry *res)
+{
+ reinit_completion(&res->comp);
+ kref_init(&res->kref);
+
+ if (rt) {
+ struct rdma_restrack_entry *old;
+
+ old = xa_cmpxchg(&rt->xa, res->id, XA_ZERO_ENTRY, res,
+ GFP_KERNEL);
+ WARN_ON(old);
+ }
+}
+
/**
* rdma_restrack_set_name() - set the task for this resource
* @res: resource entry
@@ -177,22 +217,23 @@ void rdma_restrack_new(struct rdma_restrack_entry *res,
EXPORT_SYMBOL(rdma_restrack_new);
/**
- * rdma_restrack_add() - add object to the resource tracking database
+ * rdma_restrack_add() - add object to the resource tracking database.
+ * If this resource reuses an ID of a resource that was already destroyed
+ * after calling rdma_restrack_begin() but didn't yet call
+ * rdma_restrack_commit_del() it can result in an untracked QP.
* @res: resource entry
*/
void rdma_restrack_add(struct rdma_restrack_entry *res)
{
- struct ib_device *dev = res_to_dev(res);
struct rdma_restrack_root *rt;
int ret = 0;
- if (!dev)
- return;
-
if (res->no_track)
goto out;
- rt = &dev->res[res->type];
+ rt = res_to_rt(res);
+ if (!rt)
+ return;
if (res->type == RDMA_RESTRACK_QP) {
/* Special case to ensure that LQPN points to right QP */
@@ -229,6 +270,28 @@ void rdma_restrack_add(struct rdma_restrack_entry *res)
}
EXPORT_SYMBOL(rdma_restrack_add);
+/**
+ * rdma_restrack_abort_del() - re-add object to the resource tracking database
+ * it can only be used after rdma_restrack_begin_del().
+ * @res: resource entry
+ */
+void rdma_restrack_abort_del(struct rdma_restrack_entry *res)
+{
+ struct rdma_restrack_root *rt = NULL;
+
+ if (!res->valid)
+ return;
+
+ if (!res->no_track) {
+ rt = res_to_rt(res);
+ if (!rt)
+ return;
+ }
+
+ restrack_restore_res(rt, res);
+}
+EXPORT_SYMBOL(rdma_restrack_abort_del);
+
int __must_check rdma_restrack_get(struct rdma_restrack_entry *res)
{
return kref_get_unless_zero(&res->kref);
@@ -265,7 +328,7 @@ static void restrack_release(struct kref *kref)
struct rdma_restrack_entry *res;
res = container_of(kref, struct rdma_restrack_entry, kref);
- if (res->task) {
+ if (res->task && !res->valid) {
put_task_struct(res->task);
res->task = NULL;
}
@@ -291,37 +354,20 @@ EXPORT_SYMBOL(rdma_restrack_put);
*/
void rdma_restrack_sync(struct rdma_restrack_entry *res)
{
- struct rdma_restrack_entry *old;
struct rdma_restrack_root *rt;
- struct task_struct *task;
- struct ib_device *dev;
if (!res->valid || res->no_track)
return;
- dev = res_to_dev(res);
- if (WARN_ON(!dev))
+ rt = res_to_rt(res);
+ if (!rt)
return;
- rt = &dev->res[res->type];
if (WARN_ON(xa_get_mark(&rt->xa, res->id, RESTRACK_DD)))
return;
- old = xa_cmpxchg(&rt->xa, res->id, res, XA_ZERO_ENTRY, GFP_KERNEL);
- if (WARN_ON(old != res))
- return;
-
- task = res->task;
- if (task)
- get_task_struct(task);
- rdma_restrack_put(res);
- wait_for_completion(&res->comp);
- reinit_completion(&res->comp);
- if (task)
- res->task = task;
- kref_init(&res->kref);
-
- xa_cmpxchg(&rt->xa, res->id, XA_ZERO_ENTRY, res, GFP_KERNEL);
+ restrack_drain_res(rt, res);
+ restrack_restore_res(rt, res);
}
EXPORT_SYMBOL(rdma_restrack_sync);
@@ -333,7 +379,6 @@ void rdma_restrack_del(struct rdma_restrack_entry *res)
{
struct rdma_restrack_entry *old;
struct rdma_restrack_root *rt;
- struct ib_device *dev;
if (!res->valid) {
if (res->task) {
@@ -346,12 +391,10 @@ void rdma_restrack_del(struct rdma_restrack_entry *res)
if (res->no_track)
goto out;
- dev = res_to_dev(res);
- if (WARN_ON(!dev))
+ rt = res_to_rt(res);
+ if (!rt)
return;
- rt = &dev->res[res->type];
-
old = xa_erase(&rt->xa, res->id);
WARN_ON(old != res);
@@ -359,5 +402,61 @@ void rdma_restrack_del(struct rdma_restrack_entry *res)
res->valid = false;
rdma_restrack_put(res);
wait_for_completion(&res->comp);
+ if (res->task) {
+ put_task_struct(res->task);
+ res->task = NULL;
+ }
}
EXPORT_SYMBOL(rdma_restrack_del);
+
+/**
+ * rdma_restrack_begin_del() - invalidate the object from the resource tracking
+ * database but preserve its index in the array.
+ * Since this preserves the index in the array until rdma_restrack_commit_del()
+ * is called, if rdma_restrack_add() is called in between with an old QP ID it
+ * can result in an untracked QP.
+ * @res: resource entry
+ */
+void rdma_restrack_begin_del(struct rdma_restrack_entry *res)
+{
+ struct rdma_restrack_root *rt = NULL;
+
+ if (!res->valid)
+ return;
+
+ if (!res->no_track) {
+ rt = res_to_rt(res);
+ if (!rt)
+ return;
+ }
+
+ restrack_drain_res(rt, res);
+}
+EXPORT_SYMBOL(rdma_restrack_begin_del);
+
+/**
+ * rdma_restrack_commit_del() - delete object from the resource tracking
+ * database and free the task.
+ * @res: resource entry
+ */
+void rdma_restrack_commit_del(struct rdma_restrack_entry *res)
+{
+ struct rdma_restrack_root *rt;
+
+ if (!res->valid || res->no_track)
+ goto out;
+
+ rt = res_to_rt(res);
+ if (!rt)
+ return;
+
+ xa_erase(&rt->xa, res->id);
+
+out:
+ res->valid = false;
+ if (res->task) {
+ put_task_struct(res->task);
+ res->task = NULL;
+ }
+}
+EXPORT_SYMBOL(rdma_restrack_commit_del);
diff --git a/drivers/infiniband/core/restrack.h b/drivers/infiniband/core/restrack.h
index 75b8d1005a984..2df78e084e107 100644
--- a/drivers/infiniband/core/restrack.h
+++ b/drivers/infiniband/core/restrack.h
@@ -26,8 +26,11 @@ struct rdma_restrack_root {
int rdma_restrack_init(struct ib_device *dev);
void rdma_restrack_clean(struct ib_device *dev);
void rdma_restrack_add(struct rdma_restrack_entry *res);
+void rdma_restrack_abort_del(struct rdma_restrack_entry *res);
void rdma_restrack_del(struct rdma_restrack_entry *res);
void rdma_restrack_sync(struct rdma_restrack_entry *res);
+void rdma_restrack_begin_del(struct rdma_restrack_entry *res);
+void rdma_restrack_commit_del(struct rdma_restrack_entry *res);
void rdma_restrack_new(struct rdma_restrack_entry *res,
enum rdma_restrack_type type);
void rdma_restrack_set_name(struct rdma_restrack_entry *res,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0515/1518] RDMA/core: Fix use after free in ib_query_qp()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (513 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0514/1518] RDMA/core: Add rdma_restrack_begin/abort/commit_del() operations Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0516/1518] RDMA/core: Fix potential use after free in ib_destroy_cq_user() Greg Kroah-Hartman
` (483 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Patrisious Haddad, Michael Guralnik,
Edward Srouji, Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Patrisious Haddad <phaddad@nvidia.com>
[ Upstream commit 709ba0e5311bd034eb4d9c1c00cc4e1109d6dc3e ]
When querying a QP via the netlink flow the only synchronization
mechanism for the said QP is rdma_restrack_get(), meanwhile during the
QP destroy path rdma_restrack_del() is called at the end of the
ib_destroy_qp_user() function which is too late, since by then the
vendor specific resources for said QP would already be destroyed, and
till the rdma_restrack_del() is called this QP can still be accessed,
which could cause the use after free below.
Fix this by moving the rdma_restrack_begin_del() to the start of the
ib_destroy_qp_user(), which in turn waits for all usages of the QP to be
done then removes it from the database to prevent access to it while it
is being destroyed.
RIP: 0010:ib_query_qp+0x15/0x50 [ib_core]
Code: 48 83 05 5d 8e b9 ff 01 eb b5 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 c7 46 40 00 00 00 00 48 c7 46 78 00 00 00 00 <48> 8b 07 48 8b 80 88 01 00 00 48 85 c0 74 1a 48 83 05 54 91 b9 ff
RSP: 0018:ff11000108a8f2f0 EFLAGS: 00010202
RAX: 0000000000000000 RBX: ff11000108a8f370 RCX: ff11000108a8f370
RDX: 0000000000000000 RSI: ff11000108a8f3d8 RDI: 0000000000000000
RBP: ff1100010de5a000 R08: 0000000000000e80 R09: 0000000000000004
R10: ff110001057a604c R11: 0000000000000000 R12: ff11000108a8f370
R13: ff110001090e8000 R14: 0000000000000000 R15: ff110001057a602c
FS: 00007f2ffd8db6c0(0000) GS:ff110008dc90b000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000000000 CR3: 000000010b9a7004 CR4: 0000000000373eb0
Call Trace:
<TASK>
mlx5_ib_gsi_query_qp+0x21/0x50 [mlx5_ib]
mlx5_ib_query_qp+0x689/0x9d0 [mlx5_ib]
ib_query_qp+0x35/0x50 [ib_core]
fill_res_qp_entry_query.isra.0+0x47/0x280 [ib_core]
? __wake_up+0x40/0x50
? netlink_broadcast_filtered+0x15a/0x550
? kobject_uevent_env+0x562/0x710
? ep_poll_callback+0x242/0x270
? __nla_put+0xc/0x20
? nla_put+0x28/0x40
? nla_put_string+0x2e/0x40 [ib_core]
fill_res_qp_entry+0x138/0x190 [ib_core]
res_get_common_dumpit+0x4a5/0x800 [ib_core]
? fill_res_qp_entry_query.isra.0+0x280/0x280 [ib_core]
nldev_res_get_qp_dumpit+0x1e/0x30 [ib_core]
netlink_dump+0x16f/0x450
__netlink_dump_start+0x1ce/0x2e0
rdma_nl_rcv_msg+0x1d3/0x330 [ib_core]
? nldev_res_get_qp_raw_dumpit+0x30/0x30 [ib_core]
rdma_nl_rcv_skb.constprop.0.isra.0+0x108/0x180 [ib_core]
rdma_nl_rcv+0x12/0x20 [ib_core]
netlink_unicast+0x255/0x380
? __alloc_skb+0xfa/0x1e0
netlink_sendmsg+0x1f3/0x420
__sock_sendmsg+0x38/0x60
____sys_sendmsg+0x1e8/0x230
? copy_msghdr_from_user+0xea/0x170
___sys_sendmsg+0x7c/0xb0
? __futex_wait+0x95/0xf0
? __futex_wake_mark+0x40/0x40
? futex_wait+0x67/0x100
? futex_wake+0xac/0x1b0
__sys_sendmsg+0x5f/0xb0
do_syscall_64+0x55/0xb90
entry_SYSCALL_64_after_hwframe+0x4b/0x53
Fixes: 514aee660df4 ("RDMA: Globally allocate and release QP memory")
Signed-off-by: Patrisious Haddad <phaddad@nvidia.com>
Reviewed-by: Michael Guralnik <michaelgur@nvidia.com>
Signed-off-by: Edward Srouji <edwards@nvidia.com>
Link: https://patch.msgid.link/20260713-restrack-uaf-fix-resub-v2-2-bbe8bb270d51@nvidia.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/core/verbs.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/infiniband/core/verbs.c b/drivers/infiniband/core/verbs.c
index bc1878da55cd7..7e663ce509ab1 100644
--- a/drivers/infiniband/core/verbs.c
+++ b/drivers/infiniband/core/verbs.c
@@ -2098,6 +2098,8 @@ int ib_destroy_qp_user(struct ib_qp *qp, struct ib_udata *udata)
if (qp->real_qp != qp)
return __ib_destroy_shared_qp(qp);
+ rdma_restrack_begin_del(&qp->res);
+
sec = qp->qp_sec;
if (sec)
ib_destroy_qp_security_begin(sec);
@@ -2110,6 +2112,7 @@ int ib_destroy_qp_user(struct ib_qp *qp, struct ib_udata *udata)
if (ret) {
if (sec)
ib_destroy_qp_security_abort(sec);
+ rdma_restrack_abort_del(&qp->res);
return ret;
}
@@ -2122,7 +2125,7 @@ int ib_destroy_qp_user(struct ib_qp *qp, struct ib_udata *udata)
if (sec)
ib_destroy_qp_security_end(sec);
- rdma_restrack_del(&qp->res);
+ rdma_restrack_commit_del(&qp->res);
kfree(qp);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0516/1518] RDMA/core: Fix potential use after free in ib_destroy_cq_user()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (514 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0515/1518] RDMA/core: Fix use after free in ib_query_qp() Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0517/1518] RDMA/core: Fix potential use after free in ib_destroy_srq_user() Greg Kroah-Hartman
` (482 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Patrisious Haddad, Michael Guralnik,
Edward Srouji, Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Patrisious Haddad <phaddad@nvidia.com>
[ Upstream commit 3481bec4dfc4aee24ffea5a547ee95b70b67d9d5 ]
When accessing a CQ via the netlink path the only synchronization
mechanism for the said CQ is rdma_restrack_get().
Currently, rdma_restrack_del() is invoked at the end of
ib_destroy_cq_user(), which is too late, since by that point
vendor-specific resources associated with the CQ might already be
freed. This can leave a short window where the CQ remains accessible
through restrack, leading to a potential use-after-free.
Fix this by moving the rdma_restrack_begin_del() call to the start of
ib_destroy_cq_user(), ensuring that the CQ is removed from restrack
before its internal resources are released. This guarantees that no new
users hold references to a CQ that is in the process of destruction.
In addition, this change preserves the intended inverted order
between create and destroy routines: resources are added to
restrack at the end of successful creation, and hence shall be removed
from the restrack first thing during the destruction flow, which keeps
the lifecycle management consistent and predictable.
Fixes: 08f294a1524b ("RDMA/core: Add resource tracking for create and destroy CQs")
Signed-off-by: Patrisious Haddad <phaddad@nvidia.com>
Reviewed-by: Michael Guralnik <michaelgur@nvidia.com>
Signed-off-by: Edward Srouji <edwards@nvidia.com>
Link: https://patch.msgid.link/20260713-restrack-uaf-fix-resub-v2-3-bbe8bb270d51@nvidia.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/core/verbs.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
diff --git a/drivers/infiniband/core/verbs.c b/drivers/infiniband/core/verbs.c
index 7e663ce509ab1..0404fc9bd1da4 100644
--- a/drivers/infiniband/core/verbs.c
+++ b/drivers/infiniband/core/verbs.c
@@ -2190,11 +2190,15 @@ int ib_destroy_cq_user(struct ib_cq *cq, struct ib_udata *udata)
if (atomic_read(&cq->usecnt))
return -EBUSY;
+ rdma_restrack_begin_del(&cq->res);
+
ret = cq->device->ops.destroy_cq(cq, udata);
- if (ret)
+ if (ret) {
+ rdma_restrack_abort_del(&cq->res);
return ret;
+ }
- rdma_restrack_del(&cq->res);
+ rdma_restrack_commit_del(&cq->res);
kfree(cq);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0517/1518] RDMA/core: Fix potential use after free in ib_destroy_srq_user()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (515 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0516/1518] RDMA/core: Fix potential use after free in ib_destroy_cq_user() Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0518/1518] RDMA/core: Fix potential use after free in counter_release() Greg Kroah-Hartman
` (481 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Patrisious Haddad, Michael Guralnik,
Edward Srouji, Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Patrisious Haddad <phaddad@nvidia.com>
[ Upstream commit 88244ecc71cc0b3ed200f5ef7ddea6686adfd730 ]
When accessing a SRQ via the netlink path the only synchronization
mechanism for the said SRQ is rdma_restrack_get().
Currently, rdma_restrack_del() is invoked at the end of
ib_destroy_srq_user(), which is too late, since by that point
vendor-specific resources associated with the SRQ might already be
freed. This can leave a short window where the SRQ remains accessible
through restrack, leading to a potential use-after-free.
Fix this by moving the rdma_restrack_begin_del() call to the start of
ib_destroy_srq_user(), ensuring that the SRQ is removed from restrack
before its internal resources are released. This guarantees that no new
users hold references to a SRQ that is in the process of destruction.
In addition, this change preserves the intended inverted order
between create and destroy routines: resources are added to
restrack at the end of successful creation, and hence shall be removed
from the restrack first thing during the destruction flow, which keeps
the lifecycle management consistent and predictable.
Fixes: 48f8a70e899f ("RDMA/restrack: Add support to get resource tracking for SRQ")
Signed-off-by: Patrisious Haddad <phaddad@nvidia.com>
Reviewed-by: Michael Guralnik <michaelgur@nvidia.com>
Signed-off-by: Edward Srouji <edwards@nvidia.com>
Link: https://patch.msgid.link/20260713-restrack-uaf-fix-resub-v2-4-bbe8bb270d51@nvidia.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/core/verbs.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
diff --git a/drivers/infiniband/core/verbs.c b/drivers/infiniband/core/verbs.c
index 0404fc9bd1da4..480a2b1898619 100644
--- a/drivers/infiniband/core/verbs.c
+++ b/drivers/infiniband/core/verbs.c
@@ -1083,16 +1083,20 @@ int ib_destroy_srq_user(struct ib_srq *srq, struct ib_udata *udata)
if (atomic_read(&srq->usecnt))
return -EBUSY;
+ rdma_restrack_begin_del(&srq->res);
+
ret = srq->device->ops.destroy_srq(srq, udata);
- if (ret)
+ if (ret) {
+ rdma_restrack_abort_del(&srq->res);
return ret;
+ }
atomic_dec(&srq->pd->usecnt);
if (srq->srq_type == IB_SRQT_XRC && srq->ext.xrc.xrcd)
atomic_dec(&srq->ext.xrc.xrcd->usecnt);
if (ib_srq_has_cq(srq->srq_type))
atomic_dec(&srq->ext.cq->usecnt);
- rdma_restrack_del(&srq->res);
+ rdma_restrack_commit_del(&srq->res);
kfree(srq);
return ret;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0518/1518] RDMA/core: Fix potential use after free in counter_release()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (516 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0517/1518] RDMA/core: Fix potential use after free in ib_destroy_srq_user() Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0519/1518] RDMA/core: Fix potential use after free in ib_free_cq() Greg Kroah-Hartman
` (480 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Patrisious Haddad, Michael Guralnik,
Edward Srouji, Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Patrisious Haddad <phaddad@nvidia.com>
[ Upstream commit 235ef2d0e750885c29340b0fc40620a7a4f52e12 ]
When accessing a counter via the netlink path the only synchronization
mechanism for the said counter is rdma_restrack_get().
Currently, rdma_restrack_del() is invoked at the end of
counter_release(), which is too late, since by that point
vendor-specific resources associated with the counter might already be
freed. This can leave a short window where the counter remains
accessible through restrack, leading to a potential use-after-free.
Fix this by moving the rdma_restrack_del() call to be before the
freeing of the vendor-specific resources, ensuring that the counter is
removed from restrack before its internal resources are released.
This guarantees that no new users hold references to a counter that is
in the process of destruction.
Fixes: 99fa331dc862 ("RDMA/counter: Add "auto" configuration mode support")
Signed-off-by: Patrisious Haddad <phaddad@nvidia.com>
Reviewed-by: Michael Guralnik <michaelgur@nvidia.com>
Signed-off-by: Edward Srouji <edwards@nvidia.com>
Link: https://patch.msgid.link/20260713-restrack-uaf-fix-resub-v2-5-bbe8bb270d51@nvidia.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/core/counters.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/drivers/infiniband/core/counters.c b/drivers/infiniband/core/counters.c
index 5dad5d77ce274..5dfd64b0449dc 100644
--- a/drivers/infiniband/core/counters.c
+++ b/drivers/infiniband/core/counters.c
@@ -226,7 +226,6 @@ static void rdma_counter_free(struct rdma_counter *counter)
mutex_unlock(&port_counter->lock);
- rdma_restrack_del(&counter->res);
rdma_free_hw_stats_struct(counter->stats);
kfree(counter);
}
@@ -321,6 +320,7 @@ static void counter_release(struct kref *kref)
counter = container_of(kref, struct rdma_counter, kref);
counter_history_stat_update(counter);
+ rdma_restrack_del(&counter->res);
counter->device->ops.counter_dealloc(counter);
rdma_counter_free(counter);
}
@@ -482,7 +482,8 @@ static struct rdma_counter *rdma_get_counter_by_id(struct ib_device *dev,
return NULL;
counter = container_of(res, struct rdma_counter, res);
- kref_get(&counter->kref);
+ if (!kref_get_unless_zero(&counter->kref))
+ counter = NULL;
rdma_restrack_put(res);
return counter;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0519/1518] RDMA/core: Fix potential use after free in ib_free_cq()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (517 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0518/1518] RDMA/core: Fix potential use after free in counter_release() Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0520/1518] RDMA/core: Fix potential use after free in uverbs_free_dmah() Greg Kroah-Hartman
` (479 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Patrisious Haddad, Michael Guralnik,
Edward Srouji, Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Patrisious Haddad <phaddad@nvidia.com>
[ Upstream commit 29dc2f8e1c97372c2871a70088707933515fbd5b ]
When accessing a CQ via the netlink path the only synchronization
mechanism for the said CQ is rdma_restrack_get().
Currently, rdma_restrack_del() is invoked at the end of
ib_free_cq(), which is too late, since by that point
vendor-specific resources associated with the CQ might already be
freed. This can leave a short window where the CQ remains accessible
through restrack, leading to a potential use-after-free.
Fix this by moving the rdma_restrack_del() call to be before the freeing
of the vendor-specific resources ensuring that the CQ is removed from
restrack before its internal resources are released.
This guarantees that no new users hold references to a CQ that is in
the process of destruction.
Fixes: 43d781b9fa56 ("RDMA: Allow fail of destroy CQ")
Signed-off-by: Patrisious Haddad <phaddad@nvidia.com>
Reviewed-by: Michael Guralnik <michaelgur@nvidia.com>
Signed-off-by: Edward Srouji <edwards@nvidia.com>
Link: https://patch.msgid.link/20260713-restrack-uaf-fix-resub-v2-6-bbe8bb270d51@nvidia.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/core/cq.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/infiniband/core/cq.c b/drivers/infiniband/core/cq.c
index 584537c71545c..4ea0dfcff95ea 100644
--- a/drivers/infiniband/core/cq.c
+++ b/drivers/infiniband/core/cq.c
@@ -324,6 +324,7 @@ void ib_free_cq(struct ib_cq *cq)
if (WARN_ON_ONCE(cq->cqe_used))
return;
+ rdma_restrack_del(&cq->res);
if (cq->device->ops.pre_destroy_cq) {
ret = cq->device->ops.pre_destroy_cq(cq);
WARN_ONCE(ret, "Disable of kernel CQ shouldn't fail");
@@ -350,7 +351,6 @@ void ib_free_cq(struct ib_cq *cq)
else
ret = cq->device->ops.destroy_cq(cq, NULL);
WARN_ONCE(ret, "Destroy of kernel CQ shouldn't fail");
- rdma_restrack_del(&cq->res);
kfree(cq->wc);
kfree(cq);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0520/1518] RDMA/core: Fix potential use after free in uverbs_free_dmah()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (518 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0519/1518] RDMA/core: Fix potential use after free in ib_free_cq() Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0521/1518] RDMA/core: Fix potential use after free in ib_dealloc_pd_user() Greg Kroah-Hartman
` (478 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Patrisious Haddad, Michael Guralnik,
Edward Srouji, Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Patrisious Haddad <phaddad@nvidia.com>
[ Upstream commit 2696626a0be5877f445fb647c25ef43930c777e6 ]
When accessing a dmah via the netlink path the only synchronization
mechanism for the said dmah is rdma_restrack_get().
Currently, rdma_restrack_del() is invoked at the end of
uverbs_free_dmah(), which is too late, since by that point
vendor-specific resources associated with the dmah might already be
freed. This can leave a short window where the dmah remains accessible
through restrack, leading to a potential use-after-free.
Fix this by moving the rdma_restrack_begin_del() call to the start of
uverbs_free_dmah(), ensuring that the dmah is removed from restrack
before its internal resources are released. This guarantees that no new
users hold references to a dmah that is in the process of destruction.
In addition, this change preserves the intended inverted order
between create and destroy routines: resources are added to
restrack at the end of successful creation, and hence shall be removed
from the restrack first thing during the destruction flow, which keeps
the lifecycle management consistent and predictable.
Fixes: d83edab562a4 ("RDMA/core: Introduce a DMAH object and its alloc/free APIs")
Signed-off-by: Patrisious Haddad <phaddad@nvidia.com>
Reviewed-by: Michael Guralnik <michaelgur@nvidia.com>
Signed-off-by: Edward Srouji <edwards@nvidia.com>
Link: https://patch.msgid.link/20260713-restrack-uaf-fix-resub-v2-7-bbe8bb270d51@nvidia.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/core/uverbs_std_types_dmah.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/drivers/infiniband/core/uverbs_std_types_dmah.c b/drivers/infiniband/core/uverbs_std_types_dmah.c
index 97101e0938263..9873ab49a6013 100644
--- a/drivers/infiniband/core/uverbs_std_types_dmah.c
+++ b/drivers/infiniband/core/uverbs_std_types_dmah.c
@@ -18,11 +18,14 @@ static int uverbs_free_dmah(struct ib_uobject *uobject,
if (atomic_read(&dmah->usecnt))
return -EBUSY;
+ rdma_restrack_begin_del(&dmah->res);
ret = dmah->device->ops.dealloc_dmah(dmah, attrs);
- if (ret)
+ if (ret) {
+ rdma_restrack_abort_del(&dmah->res);
return ret;
+ }
- rdma_restrack_del(&dmah->res);
+ rdma_restrack_commit_del(&dmah->res);
kfree(dmah);
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0521/1518] RDMA/core: Fix potential use after free in ib_dealloc_pd_user()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (519 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0520/1518] RDMA/core: Fix potential use after free in uverbs_free_dmah() Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0522/1518] firmware: arm_scmi: Fix requested device removal race Greg Kroah-Hartman
` (477 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Patrisious Haddad, Michael Guralnik,
Edward Srouji, Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Patrisious Haddad <phaddad@nvidia.com>
[ Upstream commit 8b90e701342275f414e36e7421c502237df241ad ]
When accessing a PD via the netlink path the only synchronization
mechanism for the said PD is rdma_restrack_get().
Currently, rdma_restrack_del() is invoked at the end of
ib_dealloc_pd_user(), which is too late, since by that point
vendor-specific resources associated with the PD might already be
freed. This can leave a short window where the PD remains accessible
through restrack, leading to a potential use-after-free.
Fix this by moving the rdma_restrack_begin_del() call to the start of
ib_dealloc_pd_user(), ensuring that the PD is removed from restrack
before its internal resources are released. This guarantees that no new
users hold references to a PD that is in the process of destruction.
In addition, this change preserves the intended inverted order
between create and destroy routines: resources are added to
restrack at the end of successful creation, and hence shall be removed
from the restrack first thing during the destruction flow, which keeps
the lifecycle management consistent and predictable.
Fixes: 91a7c58fce06 ("RDMA: Restore ability to fail on PD deallocate")
Signed-off-by: Patrisious Haddad <phaddad@nvidia.com>
Reviewed-by: Michael Guralnik <michaelgur@nvidia.com>
Signed-off-by: Edward Srouji <edwards@nvidia.com>
Link: https://patch.msgid.link/20260713-restrack-uaf-fix-resub-v2-8-bbe8bb270d51@nvidia.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/core/verbs.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/drivers/infiniband/core/verbs.c b/drivers/infiniband/core/verbs.c
index 480a2b1898619..2ef4358b01c52 100644
--- a/drivers/infiniband/core/verbs.c
+++ b/drivers/infiniband/core/verbs.c
@@ -335,6 +335,7 @@ int ib_dealloc_pd_user(struct ib_pd *pd, struct ib_udata *udata)
{
int ret;
+ rdma_restrack_begin_del(&pd->res);
if (pd->__internal_mr) {
ret = pd->device->ops.dereg_mr(pd->__internal_mr, NULL);
WARN_ON(ret);
@@ -342,10 +343,12 @@ int ib_dealloc_pd_user(struct ib_pd *pd, struct ib_udata *udata)
}
ret = pd->device->ops.dealloc_pd(pd, udata);
- if (ret)
+ if (ret) {
+ rdma_restrack_abort_del(&pd->res);
return ret;
+ }
- rdma_restrack_del(&pd->res);
+ rdma_restrack_commit_del(&pd->res);
kfree(pd);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0522/1518] firmware: arm_scmi: Fix requested device removal race
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (520 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0521/1518] RDMA/core: Fix potential use after free in ib_dealloc_pd_user() Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0523/1518] iommu/amd: Fix undefined behavior in devid_write debugfs function Greg Kroah-Hartman
` (476 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Sudeep Holla, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sudeep Holla <sudeep.holla@kernel.org>
[ Upstream commit 2c4097e6c4aed276c5e9ec2ab331ab397ea780bf ]
scmi_protocol_device_unrequest() drops scmi_requested_devices_mtx while
notifying listeners but continues to retain the per-protocol list head.
When two SCMI drivers for the same protocol unregister concurrently, one
thread can remove the final request and free the list head while the other
is running its notifier. The latter then dereferences the freed list head
after reacquiring the mutex and can free it a second time.
Complete the list and IDR updates, including freeing an empty list head,
before dropping the mutex. Keep the blocking notifier outside the critical
section and retain only the detached request across the callback.
Fixes: d3cd7c525fd2 ("firmware: arm_scmi: Refactor protocol device creation")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://patch.msgid.link/20260722095250.2011630-1-sudeep.holla@kernel.org
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/arm_scmi/bus.c | 26 +++++++++++++-------------
1 file changed, 13 insertions(+), 13 deletions(-)
diff --git a/drivers/firmware/arm_scmi/bus.c b/drivers/firmware/arm_scmi/bus.c
index e5e4975b2120d..150ea30d0481a 100644
--- a/drivers/firmware/arm_scmi/bus.c
+++ b/drivers/firmware/arm_scmi/bus.c
@@ -159,6 +159,7 @@ static int scmi_protocol_table_register(const struct scmi_device_id *id_table)
*/
static void scmi_protocol_device_unrequest(const struct scmi_device_id *id_table)
{
+ struct scmi_requested_dev *rdev, *victim = NULL;
struct list_head *phead;
pr_debug("Unrequesting SCMI device (%s) for protocol %x\n",
@@ -167,29 +168,28 @@ static void scmi_protocol_device_unrequest(const struct scmi_device_id *id_table
mutex_lock(&scmi_requested_devices_mtx);
phead = idr_find(&scmi_requested_devices, id_table->protocol_id);
if (phead) {
- struct scmi_requested_dev *victim, *tmp;
-
- list_for_each_entry_safe(victim, tmp, phead, node) {
- if (!strcmp(victim->id_table->name, id_table->name)) {
- list_del(&victim->node);
-
- mutex_unlock(&scmi_requested_devices_mtx);
- blocking_notifier_call_chain(&scmi_requested_devices_nh,
- SCMI_BUS_NOTIFY_DEVICE_UNREQUEST,
- (void *)victim->id_table);
- kfree(victim);
- mutex_lock(&scmi_requested_devices_mtx);
+ list_for_each_entry(rdev, phead, node) {
+ if (!strcmp(rdev->id_table->name, id_table->name)) {
+ victim = rdev;
+ list_del(&rdev->node);
break;
}
}
- if (list_empty(phead)) {
+ if (victim && list_empty(phead)) {
idr_remove(&scmi_requested_devices,
id_table->protocol_id);
kfree(phead);
}
}
mutex_unlock(&scmi_requested_devices_mtx);
+
+ if (victim) {
+ blocking_notifier_call_chain(&scmi_requested_devices_nh,
+ SCMI_BUS_NOTIFY_DEVICE_UNREQUEST,
+ (void *)victim->id_table);
+ kfree(victim);
+ }
}
static void
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0523/1518] iommu/amd: Fix undefined behavior in devid_write debugfs function
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (521 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0522/1518] firmware: arm_scmi: Fix requested device removal race Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0524/1518] iommu/qcom: Remove sysfs device on probe failure path Greg Kroah-Hartman
` (475 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Li RongQing, Ankit Soni, Will Deacon,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Li RongQing <lirongqing@baidu.com>
[ Upstream commit 843e149989665f8309ad2efe6048dc76591e1f94 ]
When for_each_pci_segment() loop completes without finding a matching
segment, the pci_seg pointer is not NULL but points to an invalid memory
location (the list head). Accessing pci_seg->id after the loop causes
undefined behavior.
Fix this by handling the successful case inside the loop and returning
-EINVAL after the loop if no matching segment is found.
Fixes: 2e98940f123d9 ("iommu/amd: Add support for device id user input")
Signed-off-by: Li RongQing <lirongqing@baidu.com>
Reviewed-by: Ankit Soni <Ankit.Soni@amd.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/iommu/amd/debugfs.c | 12 +++---------
1 file changed, 3 insertions(+), 9 deletions(-)
diff --git a/drivers/iommu/amd/debugfs.c b/drivers/iommu/amd/debugfs.c
index 3909a1fb218e9..f7bb551d285f6 100644
--- a/drivers/iommu/amd/debugfs.c
+++ b/drivers/iommu/amd/debugfs.c
@@ -176,19 +176,13 @@ static ssize_t devid_write(struct file *filp, const char __user *ubuf,
kfree(srcid_ptr);
return -ENODEV;
}
- break;
- }
-
- if (pci_seg->id != seg) {
+ sbdf = PCI_SEG_DEVID_TO_SBDF(seg, devid);
kfree(srcid_ptr);
- return -EINVAL;
+ return cnt;
}
- sbdf = PCI_SEG_DEVID_TO_SBDF(seg, devid);
-
kfree(srcid_ptr);
-
- return cnt;
+ return -EINVAL;
}
static int devid_show(struct seq_file *m, void *unused)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0524/1518] iommu/qcom: Remove sysfs device on probe failure path
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (522 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0523/1518] iommu/amd: Fix undefined behavior in devid_write debugfs function Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0525/1518] iommu/qcom: Fix inverted fault report check in qcom_iommu_fault() Greg Kroah-Hartman
` (474 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Haoxiang Li, Konrad Dybcio,
Mukesh Ojha, Will Deacon, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Haoxiang Li <haoxiang_li2024@163.com>
[ Upstream commit c579f18e79599c16168925cb149e1db3f29eea5f ]
In qcom_iommu_device_probe(), if iommu_device_register()
fails, the sysfs device created by iommu_device_sysfs_add()
is not released. Add a goto label to do the cleanup.
Fixes: 0ae349a0f33f ("iommu/qcom: Add qcom_iommu")
Signed-off-by: Haoxiang Li <haoxiang_li2024@163.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/iommu/arm/arm-smmu/qcom_iommu.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/iommu/arm/arm-smmu/qcom_iommu.c b/drivers/iommu/arm/arm-smmu/qcom_iommu.c
index 9c1166a3af6c9..0a1255cacdb06 100644
--- a/drivers/iommu/arm/arm-smmu/qcom_iommu.c
+++ b/drivers/iommu/arm/arm-smmu/qcom_iommu.c
@@ -858,7 +858,7 @@ static int qcom_iommu_device_probe(struct platform_device *pdev)
ret = iommu_device_register(&qcom_iommu->iommu, &qcom_iommu_ops, dev);
if (ret) {
dev_err(dev, "Failed to register iommu\n");
- goto err_pm_disable;
+ goto err_sysfs_remove;
}
if (qcom_iommu->local_base) {
@@ -869,6 +869,8 @@ static int qcom_iommu_device_probe(struct platform_device *pdev)
return 0;
+err_sysfs_remove:
+ iommu_device_sysfs_remove(&qcom_iommu->iommu);
err_pm_disable:
pm_runtime_disable(dev);
return ret;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0525/1518] iommu/qcom: Fix inverted fault report check in qcom_iommu_fault()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (523 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0524/1518] iommu/qcom: Remove sysfs device on probe failure path Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0526/1518] iommu/arm-smmu-v3: Declare eats_s1chk and eats_trans as host-endian u64 Greg Kroah-Hartman
` (473 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Mukesh Ojha,
Will Deacon, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
[ Upstream commit 1f33b8208a1978b0c0d6ad60a47fe4bb7a235e58 ]
report_iommu_fault() returns 0 when a fault handler successfully handles
the fault, and -ENOSYS when no handler is installed. The condition
'!report_iommu_fault()' evaluates to true (printing "Unhandled context
fault") precisely when the fault *was* handled, and stays silent when no
handler is present — the opposite of what is intended.
Remove the '!' so the driver logs unhandled faults correctly.
Fixes: 049541e178d5 ("iommu: qcom: wire up fault handler")
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/iommu/arm/arm-smmu/qcom_iommu.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/iommu/arm/arm-smmu/qcom_iommu.c b/drivers/iommu/arm/arm-smmu/qcom_iommu.c
index 0a1255cacdb06..82c3ffe0c7836 100644
--- a/drivers/iommu/arm/arm-smmu/qcom_iommu.c
+++ b/drivers/iommu/arm/arm-smmu/qcom_iommu.c
@@ -200,7 +200,7 @@ static irqreturn_t qcom_iommu_fault(int irq, void *dev)
fsynr = iommu_readl(ctx, ARM_SMMU_CB_FSYNR0);
iova = iommu_readq(ctx, ARM_SMMU_CB_FAR);
- if (!report_iommu_fault(ctx->domain, ctx->dev, iova, 0)) {
+ if (report_iommu_fault(ctx->domain, ctx->dev, iova, 0)) {
dev_err_ratelimited(ctx->dev,
"Unhandled context fault: fsr=0x%x, "
"iova=0x%016llx, fsynr=0x%x, cb=%d\n",
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0526/1518] iommu/arm-smmu-v3: Declare eats_s1chk and eats_trans as host-endian u64
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (524 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0525/1518] iommu/qcom: Fix inverted fault report check in qcom_iommu_fault() Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0527/1518] thermal: intel: int3400: clean up ODVP on probe failures Greg Kroah-Hartman
` (472 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, kernel test robot, Nicolin Chen,
Jason Gunthorpe, Pranjal Shrivastava, Will Deacon, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolin Chen <nicolinc@nvidia.com>
[ Upstream commit 4455286274474e95f223c68c215d32c864404889 ]
arm_smmu_get_ste_update_safe() declares the eats_s1chk and eats_trans
locals as __le64, but initializes them from FIELD_PREP(), which returns a
host-endian value, and passes them through cpu_to_le64() at the use sites.
Sparse reports the following warnings:
>> drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c:1122:38: sparse: sparse: cast from restricted __le64
drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c:1124:33: sparse: sparse: cast from restricted __le64
Declare both locals as u64 so the type matches FIELD_PREP() and the
existing cpu_to_le64() at the use sites performs the host-to-little-endian
conversion. No functional change.
Fixes: 7cad80048595 ("iommu/arm-smmu-v3: Mark EATS_TRANS safe when computing the update sequence")
Reported-by: kernel test robot <lkp@intel.com>
Closes: https://lore.kernel.org/all/202606151017.QU0evpH9-lkp@intel.com/
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Nicolin Chen <nicolinc@nvidia.com>
Reviewed-by: Jason Gunthorpe <jgg@nvidia.com>
Reviewed-by: Pranjal Shrivastava <praan@google.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c
index 01f448acd8dce..d645f7edbd107 100644
--- a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c
+++ b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c
@@ -1097,9 +1097,9 @@ VISIBLE_IF_KUNIT
void arm_smmu_get_ste_update_safe(const __le64 *cur, const __le64 *target,
__le64 *safe_bits)
{
- const __le64 eats_s1chk =
+ const u64 eats_s1chk =
FIELD_PREP(STRTAB_STE_1_EATS, STRTAB_STE_1_EATS_S1CHK);
- const __le64 eats_trans =
+ const u64 eats_trans =
FIELD_PREP(STRTAB_STE_1_EATS, STRTAB_STE_1_EATS_TRANS);
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0527/1518] thermal: intel: int3400: clean up ODVP on probe failures
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (525 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0526/1518] iommu/arm-smmu-v3: Declare eats_s1chk and eats_trans as host-endian u64 Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0528/1518] ext4: clear stale xarray tags on folios skipped during writeback Greg Kroah-Hartman
` (471 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Rafael J. Wysocki,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit d83dc9ce57a746a6dca28439bcc0575d26fa6986 ]
evaluate_odvp() creates per-ODVP sysfs files before the thermal zone
and later probe resources are registered. The current unwind path only
calls cleanup_odvp() from the late sysfs failure path, so failures after
evaluate_odvp() but before that label, including
thermal_tripless_zone_device_register() failures, leave the ODVP files
and storage behind.
Move the ODVP cleanup to the common ART/TRT unwind path so every failure
after evaluate_odvp() releases the ODVP state. Also clear the cached
ODVP pointers in cleanup_odvp(), because evaluate_odvp() can already call
it for partial setup failures while probe continues.
Fixes: 006f006f1e5c ("thermal/int340x_thermal: Export OEM vendor variables")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260623015140.19300-1-pengpeng@iscas.ac.cn
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/thermal/intel/int340x_thermal/int3400_thermal.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/thermal/intel/int340x_thermal/int3400_thermal.c b/drivers/thermal/intel/int340x_thermal/int3400_thermal.c
index 908cc1bf57f19..2aa03ceb570e7 100644
--- a/drivers/thermal/intel/int340x_thermal/int3400_thermal.c
+++ b/drivers/thermal/intel/int340x_thermal/int3400_thermal.c
@@ -354,8 +354,10 @@ static void cleanup_odvp(struct int3400_thermal_priv *priv)
kfree(priv->odvp_attrs[i].attr.attr.name);
}
kfree(priv->odvp_attrs);
+ priv->odvp_attrs = NULL;
}
kfree(priv->odvp);
+ priv->odvp = NULL;
priv->odvp_count = 0;
}
@@ -635,7 +637,6 @@ static int int3400_thermal_probe(struct platform_device *pdev)
acpi_remove_notify_handler(priv->adev->handle, ACPI_DEVICE_NOTIFY,
int3400_notify);
free_sysfs:
- cleanup_odvp(priv);
if (!ZERO_OR_NULL_PTR(priv->data_vault)) {
device_remove_bin_file(&pdev->dev, &bin_attr_data_vault);
kfree(priv->data_vault);
@@ -649,6 +650,7 @@ static int int3400_thermal_probe(struct platform_device *pdev)
acpi_thermal_rel_misc_device_remove(priv->adev->handle);
thermal_zone_device_unregister(priv->thermal);
free_art_trt:
+ cleanup_odvp(priv);
kfree(priv->trts);
kfree(priv->arts);
free_priv:
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0528/1518] ext4: clear stale xarray tags on folios skipped during writeback
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (526 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0527/1518] thermal: intel: int3400: clean up ODVP on probe failures Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0529/1518] ext4: drain in-flight DIO before buffered write fallback Greg Kroah-Hartman
` (470 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Gerald Yang, Jan Kara, Theodore Tso,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gerald Yang <gerald.yang@canonical.com>
[ Upstream commit ec524aae479b4b2078c47492b90ec21200bce434 ]
In data=journal mode, the writeback thread can hit the
WARN_ON_ONCE(sb_rdonly(sb)) in ext4_journal_check_start() while the
superblock is being remounted read-only during reboot:
Workqueue: writeback wb_workfn (flush-253:0)
RIP: 0010:ext4_journal_check_start+0x8b/0xd0
Call Trace:
__ext4_journal_start_sb+0x3c/0x1e0
mpage_prepare_extent_to_map+0x4af/0x580
ext4_do_writepages+0x3c0/0x1080
ext4_writepages+0xc8/0x1a0
do_writepages+0xc4/0x180
__writeback_single_inode+0x45/0x2f0
writeback_sb_inodes+0x26b/0x5d0
__writeback_inodes_wb+0x54/0x100
wb_writeback+0x1ac/0x320
wb_workfn+0x394/0x470
And followed by the warning:
EXT4-fs warning (device vda1): ext4_evict_inode:195: inode #6263:
comm (sd-umount): data will be lost
This issue is not reproduced every time, but frequently.
The reproduction step is to create a VM with 8 CPUs, 16G memory and
setup data=journal:
sudo tune2fs -o journal_data /dev/vda1
Run fio:
rm -f fiotest
fio --name=fiotest --rw=randwrite --bs=4k --runtime=6 --ioengine=libaio
--iodepth=256 --numjobs=8 --filename=fiotest --filesize=30G
--group_reporting
Reboot the VM, and check the console output from:
virsh console testvm
But there is no dirty inode, folio_clear_dirty_for_io clears PG_dirty
but leaves tags PAGECACHE_TAG_DIRTY and PAGECACHE_TAG_TOWRITE set which
are only cleared by __folio_start_writeback.
In data=journal mode, jbd2 checkpoints the journalled data to its final
location and clears its own dirty flag without touching folio PG_dirty
or xarray dirty flags.
The commit f4a2b42e7891 ("ext4: fix stale xarray tags after writeback")
fixes when PG_dirty is still set but there is no dirty page.
Another case is PG_dirty is cleared, but PAGECACHE_TAG_DIRTY and
PAGECACHE_TAG_TOWRITE is still set. In this case, writeback thread
checks clean folio and skips it in mpage_prepare_extent_to_map:
if (!folio_test_dirty(folio) ||
...
folio_unlcok(folio);
continue
And never reaches ext4_bio_write_folio where the commit f4a2b42e7891
clears the stale xarray tags. Print debug logs after the filesystem
is remounted read-only:
writepages RDONLY nrpages=2048 dirtytag=1 wbtag=0 towrite=1 sync=0
And all folios are actually clean:
folio idx=3 dirty=0 wb=0 checked=0 dirtybuf=0 jbddirty=0 mapped=1
...
We need to clear the xarray stale tags for such clean folios by
cycling them through writeback in the skip path, the same way
f4a2b42e7891 does in ext4_bio_write_folio.
Fixes: dff4ac75eeee ("ext4: move keep_towrite handling to ext4_bio_write_page()")
Signed-off-by: Gerald Yang <gerald.yang@canonical.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Link: https://patch.msgid.link/20260625160127.162272-1-gerald.yang@canonical.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ext4/inode.c | 18 +++++++++++++++---
1 file changed, 15 insertions(+), 3 deletions(-)
diff --git a/fs/ext4/inode.c b/fs/ext4/inode.c
index e03c749772f38..3fcb5c446c6b6 100644
--- a/fs/ext4/inode.c
+++ b/fs/ext4/inode.c
@@ -2687,13 +2687,25 @@ static int mpage_prepare_extent_to_map(struct mpage_da_data *mpd)
* page is already under writeback and we are not doing
* a data integrity writeback, skip the page
*/
- if (!folio_test_dirty(folio) ||
- (folio_test_writeback(folio) &&
- (mpd->wbc->sync_mode == WB_SYNC_NONE)) ||
+ if ((folio_test_writeback(folio) &&
+ mpd->wbc->sync_mode == WB_SYNC_NONE) ||
unlikely(folio->mapping != mapping)) {
folio_unlock(folio);
continue;
}
+ /*
+ * If the folio is clean, skip writing it back.
+ * Cycle the folio through the writeback state
+ * though, to clear stale xarray tags.
+ */
+ if (!folio_test_dirty(folio)) {
+ if (!folio_test_writeback(folio)) {
+ __folio_start_writeback(folio, false);
+ folio_end_writeback(folio);
+ }
+ folio_unlock(folio);
+ continue;
+ }
folio_wait_writeback(folio);
BUG_ON(folio_test_writeback(folio));
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0529/1518] ext4: drain in-flight DIO before buffered write fallback
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (527 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0528/1518] ext4: clear stale xarray tags on folios skipped during writeback Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0530/1518] ext4: use fsdata to track inline data write state and fix race Greg Kroah-Hartman
` (469 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zhang Yi, Jan Kara, Baokun Li,
Theodore Tso, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Baokun Li <libaokun@linux.alibaba.com>
[ Upstream commit 15cdefd0c0522f9d5e12d947fa04f4c11649b699 ]
generic/746 started failing intermittently on ext3 (no-extent inodes).
The test triggers 'Page cache invalidation failure on direct I/O'
warnings and subsequent fsync returns -EIO. Adding a 50ms delay
between ext4_buffered_write_iter() and filemap_write_and_wait_range()
in ext4_dio_write_iter() makes the race almost always reproducible.
On no-extent inodes, DIO writes to holes cannot use unwritten extents,
so ext4_iomap_alloc() leaves m_flags=0 and ext4_map_blocks() returns 0.
The iomap layer then returns -ENOTBLK, causing fallback to buffered I/O.
The fallback path in ext4_dio_write_iter() calls
ext4_buffered_write_iter() which dirties pages, then does flush and
invalidate. However, there's an unprotected window between
ext4_buffered_write_iter() returning (with inode lock released) and
the subsequent flush+invalidate.
Concurrent async DIO completions from other threads can run
kiocb_invalidate_post_direct_write() during this window. If pages have
been re-dirtied, post-invalidation finds dirty pages and triggers the
warning, setting -EIO in the error sequence.
Consider a file with two 4k extents: [hole][written]. Thread A does
DIO to the written extent, while thread B does DIO spanning both:
kworker A (4k DIO, allocated block) kworker B (8k DIO, fallback)
----------------------------------- ----------------------------
inode_lock_shared() inode_lock_shared()
iomap_dio_rw(): iomap_dio_rw():
kiocb_invalidate_pages -> clean iomap_begin -> -ENOTBLK
submit_bio (async) dio->size = 0
inode_unlock_shared() inode_unlock_shared()
[bio pending in block layer] /* fallback: lock released */
ext4_buffered_write_iter()
inode_lock(exclusive)
generic_perform_write()
-> dirty pages [0, 8k]
inode_unlock(exclusive)
/* pages dirty, no lock */
[bio completes] filemap_write_and_wait_range()
iomap_dio_complete() -> flush dirty pages
kiocb_invalidate_post_direct_write() invalidate_mapping_pages()
invalidate_inode_pages2_range()
-> finds dirty page!
-> dio_warn_stale_pagecache()
-> errseq_set(-EIO)
This issue can be triggered through normal I/O paths, not just
intentionally overlapping DIO writes from userspace. For example,
generic/746 uses a loop device where multiple kworkers issue concurrent
I/O to the backing file. Additionally, when block_size < folio_size,
non-overlapping DIO writes that share a large folio can also trigger
the race.
Add inode_dio_wait() in ext4_buffered_write_iter() before
ext4_write_checks() to drain all in-flight DIO. This ensures that
all DIO clears existing pages before submitting IO (via
kiocb_invalidate_pages()), all BIO waits for all DIO to complete
(via inode_dio_wait()), and ext4_write_checks() observes the inode
size after all completed DIO so that ext4_block_zero_eof() does not
race with in-flight DIO, thus eliminating the race.
Fixes: 378f32bab371 ("ext4: introduce direct I/O write using iomap infrastructure")
Suggested-by: Zhang Yi <yi.zhang@huawei.com>
Link: https://patch.msgid.link/d1adcf7c-c276-458d-9cac-68a4410f7626@gmail.com
Reviewed-by: Zhang Yi <yi.zhang@huawei.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Signed-off-by: Baokun Li <libaokun@linux.alibaba.com>
Link: https://patch.msgid.link/20260629113827.4074335-3-libaokun@linux.alibaba.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ext4/file.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/fs/ext4/file.c b/fs/ext4/file.c
index 7a8b309321892..149a7fe5a0962 100644
--- a/fs/ext4/file.c
+++ b/fs/ext4/file.c
@@ -292,6 +292,13 @@ static ssize_t ext4_buffered_write_iter(struct kiocb *iocb,
return -EOPNOTSUPP;
inode_lock(inode);
+
+ /*
+ * Prevent concurrent direct I/O and buffered I/O to the same file
+ * range. Wait for in-flight DIO to finish before dirtying pages.
+ */
+ inode_dio_wait(inode);
+
ret = ext4_write_checks(iocb, from);
if (ret <= 0)
goto out;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0530/1518] ext4: use fsdata to track inline data write state and fix race
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (528 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0529/1518] ext4: drain in-flight DIO before buffered write fallback Greg Kroah-Hartman
@ 2026-09-12 6:44 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0531/1518] ext4: validate readdir offset before accessing dirent Greg Kroah-Hartman
` (468 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:44 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+0c89d865531d053abb2d,
Jan Kara, Aditya Prakash Srivastava, Theodore Tso, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aditya Prakash Srivastava <aditya.ansh182@gmail.com>
[ Upstream commit 7edbb323bab2b2a609016014caafdb651c898249 ]
Instead of checking the live inode state (ext4_has_inline_data(inode)
and ext4_test_inode_state(inode, EXT4_STATE_MAY_INLINE_DATA)) in the
write_end handlers, use the fsdata parameter of the address space
operations to explicitly pass down the state in which write_begin
prepared the write.
A concurrent thread (such as ext4_page_mkwrite()) can convert the
inline data to an extent between write_begin and write_end. If this
happens, the write_end handlers would previously miss the inline
write_end path and fall through to extent-based write_end logic.
However, since block buffers were never allocated in write_begin,
this resulted in NULL pointer dereferences or data loss because
folio_buffers(folio) was NULL.
Define EXT4_WRITE_DATA_INLINE (4) as a bit flag (Bit 2), treating
fsdata as bitwise flags rather than mutually exclusive enums to keep
states of the write path independent. Communicate this state via
fsdata:
1) ext4_write_begin() and ext4_da_write_begin() set the
EXT4_WRITE_DATA_INLINE bit in *fsdata via bitwise OR when an inline
write is successfully prepared.
2) On entry, ext4_write_begin() clears the EXT4_WRITE_DATA_INLINE bit
to safely handle VFS retries (where generic_perform_write() bypasses
the fsdata initialization on its retry jump).
3) The write_end handlers perform a bitwise AND to check if the
EXT4_WRITE_DATA_INLINE bit is set and invoke the inline write_end
helper accordingly.
Furthermore, during a buffered write, ext4_write_inline_data_end()
acquires the xattr lock after preparing the write. If a concurrent
page fault (ext4_page_mkwrite()) converts the inline data to an extent
after the write_end handlers check the state but before
ext4_write_inline_data_end() acquires the xattr write lock, the
subsequent check will trigger a kernel panic via
BUG_ON(!ext4_has_inline_data(inode)).
To keep git history working and bisectability clean, replace the
BUG_ON check in ext4_write_inline_data_end() with a graceful error-
handling retry path in this same commit. If the inline data is cleared
after locking the xattr, we safely release all resources (releasing
iloc.bh, unlocking/putting the folio, stopping the active journal
transaction handle) and return 0 (VFS retry) to let the generic write
path retry the operation safely.
Reported-by: syzbot+0c89d865531d053abb2d@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=0c89d865531d053abb2d
Fixes: 3fdcfb668fd7 ("ext4: add journalled write support for inline data")
Suggested-by: Jan Kara <jack@suse.cz>
Signed-off-by: Aditya Prakash Srivastava <aditya.ansh182@gmail.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Link: https://patch.msgid.link/20260703045414.1768-1-aditya.ansh182@gmail.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ext4/ext4.h | 1 +
fs/ext4/inline.c | 14 +++++++++++++-
fs/ext4/inode.c | 24 +++++++++++++-----------
3 files changed, 27 insertions(+), 12 deletions(-)
diff --git a/fs/ext4/ext4.h b/fs/ext4/ext4.h
index 54be698b9a1c1..996ffdc2dd13d 100644
--- a/fs/ext4/ext4.h
+++ b/fs/ext4/ext4.h
@@ -3074,6 +3074,7 @@ int do_journal_get_write_access(handle_t *handle, struct inode *inode,
void ext4_set_inode_mapping_order(struct inode *inode);
#define FALL_BACK_TO_NONDELALLOC 1
#define CONVERT_INLINE_DATA 2
+#define EXT4_WRITE_DATA_INLINE 4
typedef enum {
EXT4_IGET_NORMAL = 0,
diff --git a/fs/ext4/inline.c b/fs/ext4/inline.c
index 1a48ccaa364dc..672085e4ec24f 100644
--- a/fs/ext4/inline.c
+++ b/fs/ext4/inline.c
@@ -812,7 +812,19 @@ int ext4_write_inline_data_end(struct inode *inode, loff_t pos, unsigned len,
goto out;
}
ext4_write_lock_xattr(inode, &no_expand);
- BUG_ON(!ext4_has_inline_data(inode));
+ /*
+ * We could have raced with ext4_page_mkwrite() converting
+ * the inode and clearing the inline data flag, so we just
+ * release resources and retry the whole write.
+ */
+ if (unlikely(!ext4_has_inline_data(inode))) {
+ ext4_write_unlock_xattr(inode, &no_expand);
+ brelse(iloc.bh);
+ folio_unlock(folio);
+ folio_put(folio);
+ ext4_journal_stop(handle);
+ return 0;
+ }
/*
* ei->i_inline_off may have changed since
diff --git a/fs/ext4/inode.c b/fs/ext4/inode.c
index 3fcb5c446c6b6..3b2891f185409 100644
--- a/fs/ext4/inode.c
+++ b/fs/ext4/inode.c
@@ -1300,6 +1300,8 @@ static int ext4_write_begin(const struct kiocb *iocb,
if (unlikely(ret))
return ret;
+ *fsdata = (void *)((unsigned long)*fsdata & ~EXT4_WRITE_DATA_INLINE);
+
trace_ext4_write_begin(inode, pos, len);
/*
* Reserve one block more for addition to orphan list in case
@@ -1314,8 +1316,10 @@ static int ext4_write_begin(const struct kiocb *iocb,
foliop);
if (ret < 0)
return ret;
- if (ret == 1)
+ if (ret == 1) {
+ *fsdata = (void *)((unsigned long)*fsdata | EXT4_WRITE_DATA_INLINE);
return 0;
+ }
}
/*
@@ -1451,8 +1455,7 @@ static int ext4_write_end(const struct kiocb *iocb,
trace_ext4_write_end(inode, pos, len, copied);
- if (ext4_has_inline_data(inode) &&
- ext4_test_inode_state(inode, EXT4_STATE_MAY_INLINE_DATA))
+ if ((unsigned long)fsdata & EXT4_WRITE_DATA_INLINE)
return ext4_write_inline_data_end(inode, pos, len, copied,
folio);
@@ -1562,8 +1565,7 @@ static int ext4_journalled_write_end(const struct kiocb *iocb,
BUG_ON(!ext4_handle_valid(handle));
- if (ext4_has_inline_data(inode) &&
- ext4_test_inode_state(inode, EXT4_STATE_MAY_INLINE_DATA))
+ if ((unsigned long)fsdata & EXT4_WRITE_DATA_INLINE)
return ext4_write_inline_data_end(inode, pos, len, copied,
folio);
@@ -3161,8 +3163,10 @@ static int ext4_da_write_begin(const struct kiocb *iocb,
foliop, fsdata, true);
if (ret < 0)
return ret;
- if (ret == 1)
+ if (ret == 1) {
+ *fsdata = (void *)((unsigned long)*fsdata | EXT4_WRITE_DATA_INLINE);
return 0;
+ }
}
retry:
@@ -3295,17 +3299,15 @@ static int ext4_da_write_end(const struct kiocb *iocb,
struct folio *folio, void *fsdata)
{
struct inode *inode = mapping->host;
- int write_mode = (int)(unsigned long)fsdata;
+ unsigned long write_mode = (unsigned long)fsdata;
- if (write_mode == FALL_BACK_TO_NONDELALLOC)
+ if (write_mode & FALL_BACK_TO_NONDELALLOC)
return ext4_write_end(iocb, mapping, pos,
len, copied, folio, fsdata);
trace_ext4_da_write_end(inode, pos, len, copied);
- if (write_mode != CONVERT_INLINE_DATA &&
- ext4_test_inode_state(inode, EXT4_STATE_MAY_INLINE_DATA) &&
- ext4_has_inline_data(inode))
+ if (write_mode & EXT4_WRITE_DATA_INLINE)
return ext4_write_inline_data_end(inode, pos, len, copied,
folio);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0531/1518] ext4: validate readdir offset before accessing dirent
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (529 preceding siblings ...)
2026-09-12 6:44 ` [PATCH 6.18 0530/1518] ext4: use fsdata to track inline data write state and fix race Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0532/1518] wifi: ath6kl: avoid buffer overreads in WMI event handlers Greg Kroah-Hartman
` (467 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+5322c5c260eb44d209ed, Yao Kai,
Zhihao Cheng, Jan Kara, Zhang Yi, Theodore Tso, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yao Kai <yaokai34@huawei.com>
[ Upstream commit bc4b7b0414c33b2c8898eb04386df0d21a13dad8 ]
A corrupted directory can trigger the following KASAN report when
ext4_readdir() resumes from an invalid position:
BUG: KASAN: use-after-free in __ext4_check_dir_entry+0x5ef/0x820
Read of size 2 at addr ffff88810a646000 by task repro_linear/509
Call Trace:
<TASK>
dump_stack_lvl+0x53/0x70
print_report+0xd0/0x630
kasan_report+0xce/0x100
__ext4_check_dir_entry+0x5ef/0x820
ext4_readdir+0xcde/0x2b70
iterate_dir+0x1a1/0x520
__x64_sys_getdents64+0x12b/0x220
do_syscall_64+0xf9/0x540
entry_SYSCALL_64_after_hwframe+0x77/0x7f
</TASK>
KASAN reports use-after-free because the out-of-bounds access lands in an
adjacent freed page. The directory buffer itself is still referenced.
ext4_dir_llseek() invalidates the directory cookie so that ext4_readdir()
rescans directory entries from the start of the block. The rescan checks
only the lower bound of rec_len before advancing. A corrupted rec_len can
therefore place the offset where the block has insufficient space for a
complete directory entry. The rescan itself may dereference that truncated
entry, or the main loop may pass it to __ext4_check_dir_entry(). The latter
reads de->rec_len before validating the range. For example:
block offset 0 4092 4096
|---- de1.rec_len = 4092 -----|----|
de2.inode
| de2.rec_len
^ OOB, reported as UAF
de2 starts at offset 4092 in this 4 KiB block. Its four-byte inode fits in
the block, but its rec_len starts at offset 4096 and crosses the boundary.
The minimum safe length is inode-dependent. Encrypted and casefolded
directory entries need eight additional hash bytes, while a valid metadata
checksum tail is only 12 bytes.
Cache the metadata checksum feature state and derive the minimum directory
entry length from the on-disk format. Use it to bound both the rescan and
the offset passed to the main loop. Report an offset in a truncated block
tail and skip the remainder of the block, while continuing to accept an
offset exactly at the block boundary.
Reported-by: syzbot+5322c5c260eb44d209ed@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=5322c5c260eb44d209ed
Fixes: ac27a0ec112a ("[PATCH] ext4: initial copy of files from ext3")
Signed-off-by: Yao Kai <yaokai34@huawei.com>
Reviewed-by: Zhihao Cheng <chengzhihao1@huawei.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Reviewed-by: Zhang Yi <yi.zhang@huawei.com>
Link: https://patch.msgid.link/20260706041313.708346-1-yaokai34@huawei.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ext4/dir.c | 20 ++++++++++++++++++--
1 file changed, 18 insertions(+), 2 deletions(-)
diff --git a/fs/ext4/dir.c b/fs/ext4/dir.c
index d4164c507a907..290a9aeac15f1 100644
--- a/fs/ext4/dir.c
+++ b/fs/ext4/dir.c
@@ -137,6 +137,7 @@ static int ext4_readdir(struct file *file, struct dir_context *ctx)
struct buffer_head *bh = NULL;
struct fscrypt_str fstr = FSTR_INIT(NULL, 0);
struct dir_private_info *info = file->private_data;
+ bool has_csum = ext4_has_feature_metadata_csum(sb);
err = fscrypt_prepare_readdir(inode);
if (err)
@@ -148,7 +149,7 @@ static int ext4_readdir(struct file *file, struct dir_context *ctx)
return err;
/* Can we just clear INDEX flag to ignore htree information? */
- if (!ext4_has_feature_metadata_csum(sb)) {
+ if (!has_csum) {
/*
* We don't set the inode dirty flag since it's not
* critical that it gets flushed back to the disk.
@@ -234,7 +235,10 @@ static int ext4_readdir(struct file *file, struct dir_context *ctx)
* dirent right now. Scan from the start of the block
* to make sure. */
if (!inode_eq_iversion(inode, info->cookie)) {
- for (i = 0; i < sb->s_blocksize && i < offset; ) {
+ for (i = 0;
+ i <= sb->s_blocksize -
+ ext4_dir_rec_len(1, has_csum ? NULL : inode) &&
+ i < offset;) {
de = (struct ext4_dir_entry_2 *)
(bh->b_data + i);
/* It's too expensive to do a full
@@ -256,6 +260,17 @@ static int ext4_readdir(struct file *file, struct dir_context *ctx)
info->cookie = inode_query_iversion(inode);
}
+ if (unlikely(offset < sb->s_blocksize &&
+ offset > sb->s_blocksize -
+ ext4_dir_rec_len(1, has_csum ? NULL : inode))) {
+ EXT4_ERROR_FILE(file, bh->b_blocknr,
+ "bad entry in directory: %s - offset=%u, size=%lu",
+ "directory entry too close to block end",
+ offset, sb->s_blocksize);
+ ctx->pos = round_up(ctx->pos, sb->s_blocksize);
+ goto next_block;
+ }
+
while (ctx->pos < inode->i_size
&& offset < sb->s_blocksize) {
de = (struct ext4_dir_entry_2 *) (bh->b_data + offset);
@@ -311,6 +326,7 @@ static int ext4_readdir(struct file *file, struct dir_context *ctx)
ctx->pos += ext4_rec_len_from_disk(de->rec_len,
sb->s_blocksize);
}
+next_block:
if ((ctx->pos < inode->i_size) && !dir_relax_shared(inode))
goto done;
brelse(bh);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0532/1518] wifi: ath6kl: avoid buffer overreads in WMI event handlers
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (530 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0531/1518] ext4: validate readdir offset before accessing dirent Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0533/1518] wifi: ath12k: switch to name-based reserved memory lookup Greg Kroah-Hartman
` (466 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Baochen Qiang, Jeff Johnson,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
[ Upstream commit f57314aade9d74d30f3360ec5ef85a83654748be ]
The following WMI event handlers currently read from the event buffer
without first verifying that the message was large enough to hold the
expected event:
ath6kl_wmi_scan_complete_rx()
ath6kl_wmi_addba_req_event_rx()
ath6kl_wmi_delba_req_event_rx()
Add length checks to prevent overread.
Fixes: bdcd81707973 ("Add ath6kl cleaned up driver")
Assisted-by: Claude:claude-sonnet-4-6
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Link: https://patch.msgid.link/20260711-ath6kl_wmi_scan_complete_rx-v2-1-22dc0f7f45e7@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/ath/ath6kl/wmi.c | 17 +++++++++++++++--
1 file changed, 15 insertions(+), 2 deletions(-)
diff --git a/drivers/net/wireless/ath/ath6kl/wmi.c b/drivers/net/wireless/ath/ath6kl/wmi.c
index 0cdcbc3c77966..2353b6d18c6c4 100644
--- a/drivers/net/wireless/ath/ath6kl/wmi.c
+++ b/drivers/net/wireless/ath/ath6kl/wmi.c
@@ -1296,6 +1296,9 @@ static int ath6kl_wmi_scan_complete_rx(struct wmi *wmi, u8 *datap, int len,
{
struct wmi_scan_complete_event *ev;
+ if (len < sizeof(*ev))
+ return -EINVAL;
+
ev = (struct wmi_scan_complete_event *) datap;
ath6kl_scan_complete_evt(vif, a_sle32_to_cpu(ev->status));
@@ -3372,7 +3375,12 @@ static int ath6kl_wmi_get_pmkid_list_event_rx(struct wmi *wmi, u8 *datap,
static int ath6kl_wmi_addba_req_event_rx(struct wmi *wmi, u8 *datap, int len,
struct ath6kl_vif *vif)
{
- struct wmi_addba_req_event *cmd = (struct wmi_addba_req_event *) datap;
+ struct wmi_addba_req_event *cmd;
+
+ if (len < sizeof(*cmd))
+ return -EINVAL;
+
+ cmd = (struct wmi_addba_req_event *)datap;
aggr_recv_addba_req_evt(vif, cmd->tid,
le16_to_cpu(cmd->st_seq_no), cmd->win_sz);
@@ -3383,7 +3391,12 @@ static int ath6kl_wmi_addba_req_event_rx(struct wmi *wmi, u8 *datap, int len,
static int ath6kl_wmi_delba_req_event_rx(struct wmi *wmi, u8 *datap, int len,
struct ath6kl_vif *vif)
{
- struct wmi_delba_event *cmd = (struct wmi_delba_event *) datap;
+ struct wmi_delba_event *cmd;
+
+ if (len < sizeof(*cmd))
+ return -EINVAL;
+
+ cmd = (struct wmi_delba_event *)datap;
aggr_recv_delba_req_evt(vif, cmd->tid);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0533/1518] wifi: ath12k: switch to name-based reserved memory lookup
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (531 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0532/1518] wifi: ath6kl: avoid buffer overreads in WMI event handlers Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0534/1518] wifi: ath12k: refactor QMI memory assignment Greg Kroah-Hartman
` (465 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rameshkumar Sundaram, Baochen Qiang,
Aaradhana Sahu, Jeff Johnson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aaradhana Sahu <aaradhana.sahu@oss.qualcomm.com>
[ Upstream commit 3fe59edd1901c040e5b8e9d2428bf9ec6b4ce630 ]
The driver currently retrieves reserved memory regions using index-based
lookup, which depends on the ordering of reserved-memory nodes in the
device tree. Since different platforms define these regions in varying
orders and combinations, this approach is not compatible and can result
in incorrect memory region access.
Switch to looking up memory regions by name instead of index so it does
not depend on node order.
Use names already defined in qcom,ipq5332-wifi.yaml, so there are no
backward compatibility issues.
Tested-on: IPQ5332 hw1.0 AHB WLAN.WBE.1.6-01275-QCAHKSWPL_SILICONZ-1
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Signed-off-by: Aaradhana Sahu <aaradhana.sahu@oss.qualcomm.com>
Link: https://patch.msgid.link/20260630062048.1615178-2-aaradhana.sahu@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Stable-dep-of: 42399be44b13 ("wifi: ath12k: allocate HOST_DDR and BDF regions after Q6 RO region")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/ath/ath12k/ahb.c | 18 ++++++------
drivers/net/wireless/ath/ath12k/core.c | 25 -----------------
drivers/net/wireless/ath/ath12k/core.h | 2 --
drivers/net/wireless/ath/ath12k/qmi.c | 38 +++++++++++++-------------
4 files changed, 29 insertions(+), 54 deletions(-)
diff --git a/drivers/net/wireless/ath/ath12k/ahb.c b/drivers/net/wireless/ath/ath12k/ahb.c
index b30527c402f6c..af68d5cd6a9d7 100644
--- a/drivers/net/wireless/ath/ath12k/ahb.c
+++ b/drivers/net/wireless/ath/ath12k/ahb.c
@@ -12,6 +12,7 @@
#include <linux/remoteproc.h>
#include <linux/soc/qcom/mdt_loader.h>
#include <linux/soc/qcom/smem_state.h>
+#include <linux/of_reserved_mem.h>
#include "ahb.h"
#include "debug.h"
#include "hif.h"
@@ -345,24 +346,25 @@ static int ath12k_ahb_power_up(struct ath12k_base *ab)
char fw2_name[ATH12K_USERPD_FW_NAME_LEN];
struct device *dev = ab->dev;
const struct firmware *fw, *fw2;
- struct reserved_mem *rmem = NULL;
unsigned long time_left;
phys_addr_t mem_phys;
+ struct resource res;
void *mem_region;
size_t mem_size;
u32 pasid;
int ret;
- rmem = ath12k_core_get_reserved_mem(ab, 0);
- if (!rmem)
- return -ENODEV;
+ ret = of_reserved_mem_region_to_resource_byname(dev->of_node, "q6-region",
+ &res);
+ if (ret)
+ return ret;
- mem_phys = rmem->base;
- mem_size = rmem->size;
+ mem_phys = res.start;
+ mem_size = resource_size(&res);
mem_region = devm_memremap(dev, mem_phys, mem_size, MEMREMAP_WC);
if (IS_ERR(mem_region)) {
- ath12k_err(ab, "unable to map memory region: %pa+%pa\n",
- &rmem->base, &rmem->size);
+ ath12k_err(ab, "unable to map memory region: %pa+%zx\n",
+ &res.start, mem_size);
return PTR_ERR(mem_region);
}
diff --git a/drivers/net/wireless/ath/ath12k/core.c b/drivers/net/wireless/ath/ath12k/core.c
index 5fed8d1bcadb3..a02db6fd23549 100644
--- a/drivers/net/wireless/ath/ath12k/core.c
+++ b/drivers/net/wireless/ath/ath12k/core.c
@@ -633,31 +633,6 @@ u32 ath12k_core_get_max_peers_per_radio(struct ath12k_base *ab)
return ath12k_core_get_max_station_per_radio(ab) + TARGET_NUM_VDEVS(ab);
}
-struct reserved_mem *ath12k_core_get_reserved_mem(struct ath12k_base *ab,
- int index)
-{
- struct device *dev = ab->dev;
- struct reserved_mem *rmem;
- struct device_node *node;
-
- node = of_parse_phandle(dev->of_node, "memory-region", index);
- if (!node) {
- ath12k_dbg(ab, ATH12K_DBG_BOOT,
- "failed to parse memory-region for index %d\n", index);
- return NULL;
- }
-
- rmem = of_reserved_mem_lookup(node);
- of_node_put(node);
- if (!rmem) {
- ath12k_dbg(ab, ATH12K_DBG_BOOT,
- "unable to get memory-region for index %d\n", index);
- return NULL;
- }
-
- return rmem;
-}
-
static inline
void ath12k_core_to_group_ref_get(struct ath12k_base *ab)
{
diff --git a/drivers/net/wireless/ath/ath12k/core.h b/drivers/net/wireless/ath/ath12k/core.h
index d7688b383f62c..93cdfcaf95bd2 100644
--- a/drivers/net/wireless/ath/ath12k/core.h
+++ b/drivers/net/wireless/ath/ath12k/core.h
@@ -1369,8 +1369,6 @@ void ath12k_fw_stats_init(struct ath12k *ar);
void ath12k_fw_stats_bcn_free(struct list_head *head);
void ath12k_fw_stats_free(struct ath12k_fw_stats *stats);
void ath12k_fw_stats_reset(struct ath12k *ar);
-struct reserved_mem *ath12k_core_get_reserved_mem(struct ath12k_base *ab,
- int index);
enum ath12k_qmi_mem_mode ath12k_core_get_memory_mode(struct ath12k_base *ab);
static inline const char *ath12k_scan_state_str(enum ath12k_scan_state state)
diff --git a/drivers/net/wireless/ath/ath12k/qmi.c b/drivers/net/wireless/ath/ath12k/qmi.c
index 8de9aee2498ec..bb90b7c360cf8 100644
--- a/drivers/net/wireless/ath/ath12k/qmi.c
+++ b/drivers/net/wireless/ath/ath12k/qmi.c
@@ -13,6 +13,7 @@
#include <linux/firmware.h>
#include <linux/of_address.h>
#include <linux/ioport.h>
+#include <linux/of_reserved_mem.h>
#define SLEEP_CLOCK_SELECT_INTERNAL_BIT 0x02
#define HOST_CSTATE_BIT 0x04
@@ -2685,20 +2686,20 @@ static int ath12k_qmi_alloc_target_mem_chunk(struct ath12k_base *ab)
static int ath12k_qmi_assign_target_mem_chunk(struct ath12k_base *ab)
{
- struct reserved_mem *rmem;
+ struct device_node *np = ab->dev->of_node;
size_t avail_rmem_size;
+ struct resource res;
int i, idx, ret;
for (i = 0, idx = 0; i < ab->qmi.mem_seg_count; i++) {
switch (ab->qmi.target_mem[i].type) {
case HOST_DDR_REGION_TYPE:
- rmem = ath12k_core_get_reserved_mem(ab, 0);
- if (!rmem) {
- ret = -ENODEV;
+ ret = of_reserved_mem_region_to_resource_byname(np, "q6-region",
+ &res);
+ if (ret)
goto out;
- }
- avail_rmem_size = rmem->size;
+ avail_rmem_size = resource_size(&res);
if (avail_rmem_size < ab->qmi.target_mem[i].size) {
ath12k_dbg(ab, ATH12K_DBG_QMI,
"failed to assign mem type %u req size %u avail size %zu\n",
@@ -2709,7 +2710,7 @@ static int ath12k_qmi_assign_target_mem_chunk(struct ath12k_base *ab)
goto out;
}
- ab->qmi.target_mem[idx].paddr = rmem->base;
+ ab->qmi.target_mem[idx].paddr = res.start;
ab->qmi.target_mem[idx].v.ioaddr =
ioremap(ab->qmi.target_mem[idx].paddr,
ab->qmi.target_mem[i].size);
@@ -2722,13 +2723,13 @@ static int ath12k_qmi_assign_target_mem_chunk(struct ath12k_base *ab)
idx++;
break;
case BDF_MEM_REGION_TYPE:
- rmem = ath12k_core_get_reserved_mem(ab, 0);
- if (!rmem) {
- ret = -ENODEV;
+ ret = of_reserved_mem_region_to_resource_byname(np, "q6-region",
+ &res);
+ if (ret)
goto out;
- }
- avail_rmem_size = rmem->size - ab->hw_params->bdf_addr_offset;
+ avail_rmem_size = resource_size(&res) -
+ ab->hw_params->bdf_addr_offset;
if (avail_rmem_size < ab->qmi.target_mem[i].size) {
ath12k_dbg(ab, ATH12K_DBG_QMI,
"failed to assign mem type %u req size %u avail size %zu\n",
@@ -2739,7 +2740,7 @@ static int ath12k_qmi_assign_target_mem_chunk(struct ath12k_base *ab)
goto out;
}
ab->qmi.target_mem[idx].paddr =
- rmem->base + ab->hw_params->bdf_addr_offset;
+ res.start + ab->hw_params->bdf_addr_offset;
ab->qmi.target_mem[idx].v.ioaddr =
ioremap(ab->qmi.target_mem[idx].paddr,
ab->qmi.target_mem[i].size);
@@ -2764,13 +2765,12 @@ static int ath12k_qmi_assign_target_mem_chunk(struct ath12k_base *ab)
idx++;
break;
case M3_DUMP_REGION_TYPE:
- rmem = ath12k_core_get_reserved_mem(ab, 1);
- if (!rmem) {
- ret = -EINVAL;
+ ret = of_reserved_mem_region_to_resource_byname(np, "m3-dump",
+ &res);
+ if (ret)
goto out;
- }
- avail_rmem_size = rmem->size;
+ avail_rmem_size = resource_size(&res);
if (avail_rmem_size < ab->qmi.target_mem[i].size) {
ath12k_dbg(ab, ATH12K_DBG_QMI,
"failed to assign mem type %u req size %u avail size %zu\n",
@@ -2781,7 +2781,7 @@ static int ath12k_qmi_assign_target_mem_chunk(struct ath12k_base *ab)
goto out;
}
- ab->qmi.target_mem[idx].paddr = rmem->base;
+ ab->qmi.target_mem[idx].paddr = res.start;
ab->qmi.target_mem[idx].v.ioaddr =
ioremap(ab->qmi.target_mem[idx].paddr,
ab->qmi.target_mem[i].size);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0534/1518] wifi: ath12k: refactor QMI memory assignment
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (532 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0533/1518] wifi: ath12k: switch to name-based reserved memory lookup Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0535/1518] wifi: ath12k: allocate HOST_DDR and BDF regions after Q6 RO region Greg Kroah-Hartman
` (464 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rameshkumar Sundaram, Baochen Qiang,
Aaradhana Sahu, Jeff Johnson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aaradhana Sahu <aaradhana.sahu@oss.qualcomm.com>
[ Upstream commit ecb517f97e629d3b8c360cbb5db3fed4d599ea2e ]
ath12k_qmi_assign_target_mem_chunk() uses a large switch-case to handle
both memory region identification and allocation for each memory request
type, leading to redundant allocation logic.
Refactor this by introducing ath12k_qmi_get_mem_reg_name() to map memory
request types to their corresponding reserved memory region names.
Tested-on: IPQ5332 hw1.0 AHB WLAN.WBE.1.6-01275-QCAHKSWPL_SILICONZ-1
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Signed-off-by: Aaradhana Sahu <aaradhana.sahu@oss.qualcomm.com>
Link: https://patch.msgid.link/20260630062048.1615178-3-aaradhana.sahu@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Stable-dep-of: 42399be44b13 ("wifi: ath12k: allocate HOST_DDR and BDF regions after Q6 RO region")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/ath/ath12k/qmi.c | 157 ++++++++++----------------
1 file changed, 61 insertions(+), 96 deletions(-)
diff --git a/drivers/net/wireless/ath/ath12k/qmi.c b/drivers/net/wireless/ath/ath12k/qmi.c
index bb90b7c360cf8..36048dc721935 100644
--- a/drivers/net/wireless/ath/ath12k/qmi.c
+++ b/drivers/net/wireless/ath/ath12k/qmi.c
@@ -2684,120 +2684,85 @@ static int ath12k_qmi_alloc_target_mem_chunk(struct ath12k_base *ab)
return ret;
}
+static const char *ath12k_qmi_get_mem_reg_name(int mem_type)
+{
+ switch (mem_type) {
+ case HOST_DDR_REGION_TYPE:
+ case BDF_MEM_REGION_TYPE:
+ return "q6-region";
+ case M3_DUMP_REGION_TYPE:
+ return "m3-dump";
+ case CALDB_MEM_REGION_TYPE:
+ return "q6-caldb";
+ case MLO_GLOBAL_MEM_REGION_TYPE:
+ return "mlo-global-mem";
+ default:
+ return NULL;
+ }
+}
+
static int ath12k_qmi_assign_target_mem_chunk(struct ath12k_base *ab)
{
struct device_node *np = ab->dev->of_node;
+ struct target_mem_chunk *chunk;
size_t avail_rmem_size;
struct resource res;
+ const char *rname;
int i, idx, ret;
for (i = 0, idx = 0; i < ab->qmi.mem_seg_count; i++) {
- switch (ab->qmi.target_mem[i].type) {
- case HOST_DDR_REGION_TYPE:
- ret = of_reserved_mem_region_to_resource_byname(np, "q6-region",
- &res);
- if (ret)
- goto out;
-
- avail_rmem_size = resource_size(&res);
- if (avail_rmem_size < ab->qmi.target_mem[i].size) {
- ath12k_dbg(ab, ATH12K_DBG_QMI,
- "failed to assign mem type %u req size %u avail size %zu\n",
- ab->qmi.target_mem[i].type,
- ab->qmi.target_mem[i].size,
- avail_rmem_size);
- ret = -EINVAL;
- goto out;
- }
-
- ab->qmi.target_mem[idx].paddr = res.start;
- ab->qmi.target_mem[idx].v.ioaddr =
- ioremap(ab->qmi.target_mem[idx].paddr,
- ab->qmi.target_mem[i].size);
- if (!ab->qmi.target_mem[idx].v.ioaddr) {
- ret = -EIO;
- goto out;
- }
- ab->qmi.target_mem[idx].size = ab->qmi.target_mem[i].size;
- ab->qmi.target_mem[idx].type = ab->qmi.target_mem[i].type;
- idx++;
- break;
- case BDF_MEM_REGION_TYPE:
- ret = of_reserved_mem_region_to_resource_byname(np, "q6-region",
- &res);
- if (ret)
- goto out;
-
- avail_rmem_size = resource_size(&res) -
- ab->hw_params->bdf_addr_offset;
- if (avail_rmem_size < ab->qmi.target_mem[i].size) {
- ath12k_dbg(ab, ATH12K_DBG_QMI,
- "failed to assign mem type %u req size %u avail size %zu\n",
- ab->qmi.target_mem[i].type,
- ab->qmi.target_mem[i].size,
- avail_rmem_size);
- ret = -EINVAL;
- goto out;
- }
- ab->qmi.target_mem[idx].paddr =
- res.start + ab->hw_params->bdf_addr_offset;
- ab->qmi.target_mem[idx].v.ioaddr =
- ioremap(ab->qmi.target_mem[idx].paddr,
- ab->qmi.target_mem[i].size);
- if (!ab->qmi.target_mem[idx].v.ioaddr) {
- ret = -EIO;
- goto out;
- }
- ab->qmi.target_mem[idx].size = ab->qmi.target_mem[i].size;
- ab->qmi.target_mem[idx].type = ab->qmi.target_mem[i].type;
- idx++;
- break;
- case CALDB_MEM_REGION_TYPE:
- /* Cold boot calibration is not enabled in Ath12k. Hence,
+ chunk = &ab->qmi.target_mem[i];
+ if (chunk->type == CALDB_MEM_REGION_TYPE) {
+ /*
+ * Cold boot calibration is not enabled in Ath12k. Hence,
* assign paddr = 0.
* Once cold boot calibration is enabled add support to
* assign reserved memory from DT.
*/
ab->qmi.target_mem[idx].paddr = 0;
ab->qmi.target_mem[idx].v.ioaddr = NULL;
- ab->qmi.target_mem[idx].size = ab->qmi.target_mem[i].size;
- ab->qmi.target_mem[idx].type = ab->qmi.target_mem[i].type;
+ ab->qmi.target_mem[idx].size = chunk->size;
+ ab->qmi.target_mem[idx].type = chunk->type;
idx++;
- break;
- case M3_DUMP_REGION_TYPE:
- ret = of_reserved_mem_region_to_resource_byname(np, "m3-dump",
- &res);
- if (ret)
- goto out;
-
- avail_rmem_size = resource_size(&res);
- if (avail_rmem_size < ab->qmi.target_mem[i].size) {
- ath12k_dbg(ab, ATH12K_DBG_QMI,
- "failed to assign mem type %u req size %u avail size %zu\n",
- ab->qmi.target_mem[i].type,
- ab->qmi.target_mem[i].size,
- avail_rmem_size);
- ret = -EINVAL;
- goto out;
- }
+ continue;
+ }
- ab->qmi.target_mem[idx].paddr = res.start;
- ab->qmi.target_mem[idx].v.ioaddr =
- ioremap(ab->qmi.target_mem[idx].paddr,
- ab->qmi.target_mem[i].size);
- if (!ab->qmi.target_mem[idx].v.ioaddr) {
- ret = -EIO;
- goto out;
- }
- ab->qmi.target_mem[idx].size = ab->qmi.target_mem[i].size;
- ab->qmi.target_mem[idx].type = ab->qmi.target_mem[i].type;
- idx++;
- break;
- default:
+ rname = ath12k_qmi_get_mem_reg_name(chunk->type);
+ if (!rname) {
ath12k_warn(ab, "qmi ignore invalid mem req type %u\n",
- ab->qmi.target_mem[i].type);
- break;
+ chunk->type);
+ continue;
+ }
+
+ ret = of_reserved_mem_region_to_resource_byname(np, rname, &res);
+ if (ret)
+ goto out;
+
+ avail_rmem_size = resource_size(&res);
+ if (chunk->type == BDF_MEM_REGION_TYPE) {
+ avail_rmem_size -= ab->hw_params->bdf_addr_offset;
+ res.start += ab->hw_params->bdf_addr_offset;
}
+
+ if (avail_rmem_size < chunk->size) {
+ ath12k_dbg(ab, ATH12K_DBG_QMI,
+ "failed to assign mem type %u req size %u avail size %zu\n",
+ chunk->type, chunk->size, avail_rmem_size);
+ ret = -EINVAL;
+ goto out;
+ }
+
+ ab->qmi.target_mem[idx].paddr = res.start;
+ ab->qmi.target_mem[idx].v.ioaddr = ioremap(ab->qmi.target_mem[idx].paddr,
+ chunk->size);
+ if (!ab->qmi.target_mem[idx].v.ioaddr) {
+ ret = -EIO;
+ goto out;
+ }
+
+ ab->qmi.target_mem[idx].size = chunk->size;
+ ab->qmi.target_mem[idx].type = chunk->type;
+ idx++;
}
ab->qmi.mem_seg_count = idx;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0535/1518] wifi: ath12k: allocate HOST_DDR and BDF regions after Q6 RO region
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (533 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0534/1518] wifi: ath12k: refactor QMI memory assignment Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0536/1518] wifi: ath12k: Correctly copy the hint BSSID in WMI scan request Greg Kroah-Hartman
` (463 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rameshkumar Sundaram, Baochen Qiang,
Aaradhana Sahu, Jeff Johnson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aaradhana Sahu <aaradhana.sahu@oss.qualcomm.com>
[ Upstream commit 42399be44b13eafb45c56b1c7d7c92107e50c289 ]
Currently, the Q6 region contains a read-only firmware region along with
the BDF_MEM_REGION_TYPE and HOST_DDR_REGION_TYPE memory areas. The firmware
expects these writable memory regions to be assigned after the Q6 read-only
section.
However, the ath12k driver currently allocates the HOST_DDR_REGION_TYPE
starting from the base of the Q6 region, which includes the read-only
firmware area. As a result, the allocated memory regions overlap with the
read-only section, causing the firmware to assert during QMI memory
allocation. The Q6 memory region layout is as follows:
Q6 Reserved Memory
+--------------------------------------+
| |
| Read-only Firmware Region |
| (Q6 RO Region) |
| |
+--------------------------------------+ <--- bdf_addr_offset
| Writable Memory Region |
| (BDF + HOST_DDR allocations) |
| |
+--------------------------------------+
Fix this by allocating the required memory regions only after the end of
the read-only region in the Q6 address space. The bdf_addr_offset parameter
indicates where the writable region starts. Both HOST_DDR and BDF regions
are allocated sequentially after this offset, with each region placed
immediately after the previous one to avoid gaps and overlaps.
Tested-on: IPQ5332 hw1.0 AHB WLAN.WBE.1.6-01275-QCAHKSWPL_SILICONZ-1
Fixes: 6757079c5890 ("wifi: ath12k: add support for fixed QMI firmware memory")
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Signed-off-by: Aaradhana Sahu <aaradhana.sahu@oss.qualcomm.com>
Link: https://patch.msgid.link/20260630062048.1615178-4-aaradhana.sahu@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/ath/ath12k/qmi.c | 19 +++++++++++++++----
1 file changed, 15 insertions(+), 4 deletions(-)
diff --git a/drivers/net/wireless/ath/ath12k/qmi.c b/drivers/net/wireless/ath/ath12k/qmi.c
index 36048dc721935..b66cff3c70e22 100644
--- a/drivers/net/wireless/ath/ath12k/qmi.c
+++ b/drivers/net/wireless/ath/ath12k/qmi.c
@@ -2704,8 +2704,8 @@ static const char *ath12k_qmi_get_mem_reg_name(int mem_type)
static int ath12k_qmi_assign_target_mem_chunk(struct ath12k_base *ab)
{
struct device_node *np = ab->dev->of_node;
+ size_t avail_rmem_size, offset = 0;
struct target_mem_chunk *chunk;
- size_t avail_rmem_size;
struct resource res;
const char *rname;
int i, idx, ret;
@@ -2739,9 +2739,20 @@ static int ath12k_qmi_assign_target_mem_chunk(struct ath12k_base *ab)
goto out;
avail_rmem_size = resource_size(&res);
- if (chunk->type == BDF_MEM_REGION_TYPE) {
- avail_rmem_size -= ab->hw_params->bdf_addr_offset;
- res.start += ab->hw_params->bdf_addr_offset;
+ if (chunk->type == BDF_MEM_REGION_TYPE ||
+ chunk->type == HOST_DDR_REGION_TYPE) {
+ if (ab->hw_params->bdf_addr_offset > avail_rmem_size ||
+ offset > avail_rmem_size - ab->hw_params->bdf_addr_offset) {
+ ath12k_err(ab, "qmi mem offset overflow: bdf_offset=%u offset=%zu size=%zu\n",
+ ab->hw_params->bdf_addr_offset, offset,
+ avail_rmem_size);
+ ret = -EINVAL;
+ goto out;
+ }
+
+ avail_rmem_size -= ab->hw_params->bdf_addr_offset + offset;
+ res.start += ab->hw_params->bdf_addr_offset + offset;
+ offset += chunk->size;
}
if (avail_rmem_size < chunk->size) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0536/1518] wifi: ath12k: Correctly copy the hint BSSID in WMI scan request
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (534 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0535/1518] wifi: ath12k: allocate HOST_DDR and BDF regions after Q6 RO region Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0537/1518] wifi: ath11k: " Greg Kroah-Hartman
` (462 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Baochen Qiang, Rameshkumar Sundaram,
Jeff Johnson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
[ Upstream commit 7b0bd40e97a00991122122d5888ae455fb2bfc7a ]
Currently, in ath12k_wmi_send_scan_start_cmd(), the logic to populate
the hint_bssid copies the BSSID in the wrong direction, from the
firmware message to the argument buffer. Swap the parameters so that
the BSSID is correctly populated in the firmware message from the
argument buffer.
Compile tested only.
Reported-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Closes: https://lore.kernel.org/linux-wireless/afbff608-a005-43c4-af76-968a58bf0cc3@oss.qualcomm.com/
Fixes: d889913205cf ("wifi: ath12k: driver for Qualcomm Wi-Fi 7 devices")
Assisted-by: Claude:claude-sonnet-4-6
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Link: https://patch.msgid.link/20260713-ath12k_wmi_send_scan_start_cmd-bad-hint_bssid-v1-1-4ffc4a472992@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/ath/ath12k/wmi.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/net/wireless/ath/ath12k/wmi.c b/drivers/net/wireless/ath/ath12k/wmi.c
index f3474a13e32aa..aa99e07226103 100644
--- a/drivers/net/wireless/ath/ath12k/wmi.c
+++ b/drivers/net/wireless/ath/ath12k/wmi.c
@@ -2816,8 +2816,8 @@ int ath12k_wmi_send_scan_start_cmd(struct ath12k *ar,
for (i = 0; i < arg->num_hint_bssid; ++i) {
hint_bssid->freq_flags =
arg->hint_bssid[i].freq_flags;
- ether_addr_copy(&arg->hint_bssid[i].bssid.addr[0],
- &hint_bssid->bssid.addr[0]);
+ ether_addr_copy(&hint_bssid->bssid.addr[0],
+ &arg->hint_bssid[i].bssid.addr[0]);
hint_bssid++;
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0537/1518] wifi: ath11k: Correctly copy the hint BSSID in WMI scan request
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (535 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0536/1518] wifi: ath12k: Correctly copy the hint BSSID in WMI scan request Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0538/1518] wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() Greg Kroah-Hartman
` (461 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Baochen Qiang, Rameshkumar Sundaram,
Jeff Johnson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
[ Upstream commit 6fe2dddf59bbb2a96be0fcf23a205807b25ac173 ]
Currently, in ath11k_wmi_send_scan_start_cmd(), the logic to populate
the hint_bssid copies the BSSID in the wrong direction, from the
firmware message to the argument buffer. Swap the parameters so that
the BSSID is correctly populated in the firmware message from the
argument buffer.
This issue was reported on ath12k, but exists in ath11k as well.
Compile tested only.
Reported-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Closes: https://lore.kernel.org/linux-wireless/afbff608-a005-43c4-af76-968a58bf0cc3@oss.qualcomm.com/
Fixes: 74601ecfef6e ("ath11k: Add support for 6g scan hint")
Assisted-by: Claude:claude-sonnet-4-6
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Link: https://patch.msgid.link/20260713-ath12k_wmi_send_scan_start_cmd-bad-hint_bssid-v1-2-4ffc4a472992@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/ath/ath11k/wmi.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/net/wireless/ath/ath11k/wmi.c b/drivers/net/wireless/ath/ath11k/wmi.c
index e1b00dc811e7b..fd38069c962a2 100644
--- a/drivers/net/wireless/ath/ath11k/wmi.c
+++ b/drivers/net/wireless/ath/ath11k/wmi.c
@@ -2411,8 +2411,8 @@ int ath11k_wmi_send_scan_start_cmd(struct ath11k *ar,
for (i = 0; i < params->num_hint_bssid; ++i) {
hint_bssid->freq_flags =
params->hint_bssid[i].freq_flags;
- ether_addr_copy(¶ms->hint_bssid[i].bssid.addr[0],
- &hint_bssid->bssid.addr[0]);
+ ether_addr_copy(&hint_bssid->bssid.addr[0],
+ ¶ms->hint_bssid[i].bssid.addr[0]);
hint_bssid++;
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0538/1518] wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (536 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0537/1518] wifi: ath11k: " Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0539/1518] wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() Greg Kroah-Hartman
` (460 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rameshkumar Sundaram, Baochen Qiang,
Jeff Johnson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
[ Upstream commit 7698656a2f7b045af5a6859766238cefea1b1945 ]
Currently, in ath12k_wmi_op_rx(), the firmware buffer is read without
first verifying that the buffer has enough data to hold a header. This
could result in a buffer overread.
Update the logic to verify the buffer contains at least enough data to
hold a wmi_cmd_hdr before reading from the buffer.
Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3
Fixes: d889913205cf ("wifi: ath12k: driver for Qualcomm Wi-Fi 7 devices")
Assisted-by: Claude:claude-sonnet-4-6
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Link: https://patch.msgid.link/20260716-ath12k_wmi_op_rx-overread-v1-1-327a4b1c2372@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/ath/ath12k/wmi.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/drivers/net/wireless/ath/ath12k/wmi.c b/drivers/net/wireless/ath/ath12k/wmi.c
index aa99e07226103..077154b564aeb 100644
--- a/drivers/net/wireless/ath/ath12k/wmi.c
+++ b/drivers/net/wireless/ath/ath12k/wmi.c
@@ -9739,12 +9739,12 @@ static void ath12k_wmi_op_rx(struct ath12k_base *ab, struct sk_buff *skb)
struct wmi_cmd_hdr *cmd_hdr;
enum wmi_tlv_event_id id;
- cmd_hdr = (struct wmi_cmd_hdr *)skb->data;
- id = le32_get_bits(cmd_hdr->cmd_id, WMI_CMD_HDR_CMD_ID);
-
- if (!skb_pull(skb, sizeof(struct wmi_cmd_hdr)))
+ cmd_hdr = skb_pull_data(skb, sizeof(*cmd_hdr));
+ if (!cmd_hdr)
goto out;
+ id = le32_get_bits(cmd_hdr->cmd_id, WMI_CMD_HDR_CMD_ID);
+
switch (id) {
/* Process all the WMI events here */
case WMI_SERVICE_READY_EVENTID:
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0539/1518] wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (537 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0538/1518] wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0540/1518] RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap Greg Kroah-Hartman
` (459 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rameshkumar Sundaram, Baochen Qiang,
Jeff Johnson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
[ Upstream commit 9ef9dd30058cc9223c72f711dca1a28a5947d0c5 ]
Currently, in ath11k_wmi_tlv_op_rx(), the firmware buffer is read
without first verifying that the buffer has enough data to hold a
header. This could result in a buffer overread.
Add an upfront length check before dereferencing skb->data as a
wmi_cmd_hdr. The check is placed before the trace_ath11k_wmi_event()
call to preserve the existing trace semantics (tracing the full raw
WMI event including the header), unlike the analogous ath12k fix which
could use skb_pull_data() directly.
Compile tested only.
Fixes: d5c65159f289 ("ath11k: driver for Qualcomm IEEE 802.11ax devices")
Assisted-by: Claude:claude-sonnet-4-6
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Link: https://patch.msgid.link/20260716-ath11k_wmi_tlv_op_rx-overread-v1-1-0b972b3f1368@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/ath/ath11k/wmi.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/net/wireless/ath/ath11k/wmi.c b/drivers/net/wireless/ath/ath11k/wmi.c
index fd38069c962a2..1303931f97663 100644
--- a/drivers/net/wireless/ath/ath11k/wmi.c
+++ b/drivers/net/wireless/ath/ath11k/wmi.c
@@ -8757,13 +8757,15 @@ static void ath11k_wmi_tlv_op_rx(struct ath11k_base *ab, struct sk_buff *skb)
struct wmi_cmd_hdr *cmd_hdr;
enum wmi_tlv_event_id id;
+ if (skb->len < sizeof(*cmd_hdr))
+ goto out;
+
cmd_hdr = (struct wmi_cmd_hdr *)skb->data;
id = FIELD_GET(WMI_CMD_HDR_CMD_ID, (cmd_hdr->cmd_id));
trace_ath11k_wmi_event(ab, id, skb->data, skb->len);
- if (skb_pull(skb, sizeof(struct wmi_cmd_hdr)) == NULL)
- goto out;
+ skb_pull(skb, sizeof(*cmd_hdr));
switch (id) {
/* Process all the WMI events here */
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0540/1518] RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (538 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0539/1518] wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0541/1518] ext4: fix buffer_head leak in ext4_init_orphan_info Greg Kroah-Hartman
` (458 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yousef Alhouseen, Selvin Xavier,
Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Selvin Xavier <selvin.xavier@broadcom.com>
[ Upstream commit 9b66c9af7172ffcf727214fa0ebe9a5e1ed6eb16 ]
bnxt_re_mmap() rejects VM_WRITE for the DBR_PAGE and TOGGLE_PAGE mmap
flags, but a read-only mapping can still retain VM_MAYWRITE. nd later
be upgraded with mprotect(PROT_WRITE). This can bypass the write check
that only runs at mmap time.
Clear VM_MAYWRITE before vm_insert_page() in the shared DBR/toggle-page
branch, matching the existing policy that userspace writes are not
expected for these pages.
Fixes: ea222485788208 ("RDMA/bnxt_re: Update alloc_page uapi for pacing")
Suggested-by: Yousef Alhouseen <alhouseenyousef@gmail.com>
Signed-off-by: Selvin Xavier <selvin.xavier@broadcom.com>
Link: https://patch.msgid.link/20260721115440.24021-5-selvin.xavier@broadcom.com
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/bnxt_re/ib_verbs.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/infiniband/hw/bnxt_re/ib_verbs.c b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
index 25d88c2c5735f..64b6e572e7047 100644
--- a/drivers/infiniband/hw/bnxt_re/ib_verbs.c
+++ b/drivers/infiniband/hw/bnxt_re/ib_verbs.c
@@ -4570,11 +4570,13 @@ int bnxt_re_mmap(struct ib_ucontext *ib_uctx, struct vm_area_struct *vma)
case BNXT_RE_MMAP_DBR_PAGE:
case BNXT_RE_MMAP_TOGGLE_PAGE:
/* Driver doesn't expect write access for user space */
- if (vma->vm_flags & VM_WRITE)
+ if (vma->vm_flags & VM_WRITE) {
ret = -EFAULT;
- else
+ } else {
+ vm_flags_clear(vma, VM_MAYWRITE);
ret = vm_insert_page(vma, vma->vm_start,
virt_to_page((void *)bnxt_entry->mem_offset));
+ }
break;
default:
ret = -EINVAL;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0541/1518] ext4: fix buffer_head leak in ext4_init_orphan_info
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (539 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0540/1518] RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0542/1518] ext4: check dir entry fits before reading the hash trailer in ext4_search_dir() Greg Kroah-Hartman
` (457 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Guanghui Yang, Jan Kara,
Theodore Tso, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guanghui Yang <3497809730@qq.com>
[ Upstream commit 05704335803b69c1bfa8637b7ada942bf2ee8a41 ]
ext4_init_orphan_info() reads orphan file blocks with ext4_bread()
and stores the returned buffer_head in oi->of_binfo[i].ob_bh.
If ext4_bread() succeeds but the orphan block magic or checksum
validation fails, the function jumps to out_free. However, the old
out_free loop starts releasing buffers from i - 1, so the current
buffer_head at index i is skipped.
This leaks the buffer_head reference obtained by ext4_bread() on the
bad magic and bad checksum error paths.
Fix this by tracking the number of successfully read buffer_heads and
releasing exactly those buffer_heads on the error path.
Fixes: 02f310fcf47f ("ext4: Speedup ext4 orphan inode handling")
Signed-off-by: Guanghui Yang <3497809730@qq.com>
Reviewed-by: Jan Kara <jack@suse.cz>
Link: https://patch.msgid.link/tencent_B38798612A159E21450ECF959016371B0807@qq.com
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ext4/orphan.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
diff --git a/fs/ext4/orphan.c b/fs/ext4/orphan.c
index fb57bba0d19d1..89c24c4f97846 100644
--- a/fs/ext4/orphan.c
+++ b/fs/ext4/orphan.c
@@ -572,6 +572,7 @@ int ext4_init_orphan_info(struct super_block *sb)
int i, j;
int ret;
int free;
+ int loaded = 0;
__le32 *bdata;
int inodes_per_ob = ext4_inodes_per_orphan_block(sb);
struct ext4_orphan_block_tail *ot;
@@ -615,6 +616,7 @@ int ext4_init_orphan_info(struct super_block *sb)
ret = -EIO;
goto out_free;
}
+ loaded++;
ot = ext4_orphan_block_tail(sb, oi->of_binfo[i].ob_bh);
if (le32_to_cpu(ot->ob_magic) != EXT4_ORPHAN_BLOCK_MAGIC) {
ext4_error(sb, "orphan file block %d: bad magic", i);
@@ -637,8 +639,10 @@ int ext4_init_orphan_info(struct super_block *sb)
iput(inode);
return 0;
out_free:
- for (i--; i >= 0; i--)
- brelse(oi->of_binfo[i].ob_bh);
+ while (loaded > 0) {
+ loaded--;
+ brelse(oi->of_binfo[loaded].ob_bh);
+ }
kvfree(oi->of_binfo);
out_put:
iput(inode);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0542/1518] ext4: check dir entry fits before reading the hash trailer in ext4_search_dir()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (540 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0541/1518] ext4: fix buffer_head leak in ext4_init_orphan_info Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0543/1518] ARM: dts: allwinner: a10: Fix PMU interrupt Greg Kroah-Hartman
` (456 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Weiming Shi, Xiang Mei,
Andreas Dilger, Jan Kara, Theodore Tso, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xiang Mei <xmei5@asu.edu>
[ Upstream commit c7e6b863d298f56522d0d08554bbea7f142e6588 ]
For casefolded encrypted directories ext4 stores an 8-byte hash trailer
after the name (EXT4_DIRENT_HASHES()), at an offset derived from
de->name_len. On the sb_no_casefold_compat_fallback() path ext4_match()
reads that trailer, but ext4_search_dir()'s by-hand pre-check only tests
de->name + de->name_len <= dlimit, which proves the name fits, not the
rounded trailer. A crafted entry whose name ends at the block boundary
passes the check while EXT4_DIRENT_HASHES(de) lands past the block end,
so ext4_match() reads out of bounds on an ordinary lookup. KASAN reports
it as a use-after-free when the page after the directory block holds a
freed object:
BUG: KASAN: use-after-free in ext4_match (fs/ext4/namei.c:1435)
Read of size 4 at addr ffff888010458000 by task exploit
Call Trace:
ext4_match (fs/ext4/namei.c:1435)
ext4_search_dir (fs/ext4/namei.c:1470)
__ext4_find_entry (fs/ext4/namei.c:1268 fs/ext4/namei.c:1632)
ext4_lookup (fs/ext4/namei.c:1703 fs/ext4/namei.c:1769)
...
filename_lookup (fs/namei.c:2842)
vfs_statx (fs/stat.c:353)
__do_sys_newfstatat (fs/stat.c:538)
do_syscall_64 (arch/x86/entry/syscall_64.c:94)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
Require, for hash-in-dirent directories, that the whole entry including
the rounded trailer fits before calling ext4_match(). This is the same
bound ext4_check_dir_entry() already enforces via ext4_dir_rec_len(), so
no well-formed entry is rejected. The other caller, ext4_find_dest_de(),
runs ext4_check_dir_entry() first and is unaffected.
Fixes: 471fbbea7ff7 ("ext4: handle casefolding with encryption")
Reported-by: Weiming Shi <bestswngs@gmail.com>
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Xiang Mei <xmei5@asu.edu>
Reviewed-by: Andreas Dilger <adilger@dilger.ca>
Reviewed-by: Jan Kara <jack@suse.cz>
Link: https://patch.msgid.link/20260709184101.441348-1-xmei5@asu.edu
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ext4/namei.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/fs/ext4/namei.c b/fs/ext4/namei.c
index 2e35453a56f28..2c661155158f8 100644
--- a/fs/ext4/namei.c
+++ b/fs/ext4/namei.c
@@ -1467,6 +1467,8 @@ int ext4_search_dir(struct buffer_head *bh, char *search_buf, int buf_size,
/* this code is executed quadratically often */
/* do minimal checking `by hand' */
if (de->name + de->name_len <= dlimit &&
+ (!ext4_hash_in_dirent(dir) ||
+ (char *)de + ext4_dir_rec_len(de->name_len, dir) <= dlimit) &&
ext4_match(dir, fname, de)) {
/* found a match - just to be sure, do
* a full check */
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0543/1518] ARM: dts: allwinner: a10: Fix PMU interrupt
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (541 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0542/1518] ext4: check dir entry fits before reading the hash trailer in ext4_search_dir() Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0544/1518] cpufreq: amd-pstate-ut: Skip tests when amd-pstate driver is not active Greg Kroah-Hartman
` (455 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Andre Przywara, Chen-Yu Tsai,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Andre Przywara <andre.przywara@arm.com>
[ Upstream commit eb7051f756460d7b951e94d9656e31ebb631ba28 ]
The Performance Monitoring Unit of the Cortex-A8 cores in the Allwinner
A10 SoC is connected to interrupt line 66, not 3. This is shown in the
manual (where interrupt 3 is assigned to UART2, also in our .dtsi), but
has also been confirmed by triggering an PMU overflow interrupt and
inspecting the IRQ controller status registers (from U-Boot).
Please note that "perf stat" does not use interrupts, this might explain
why this evaded the initial testing.
Fixes: 7e345d25c796 ("ARM: dts: sun4i-a10: Add PMU node")
Signed-off-by: Andre Przywara <andre.przywara@arm.com>
Link: https://patch.msgid.link/20260720215128.5761-1-andre.przywara@arm.com
Signed-off-by: Chen-Yu Tsai <wens@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm/boot/dts/allwinner/sun4i-a10.dtsi | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/arm/boot/dts/allwinner/sun4i-a10.dtsi b/arch/arm/boot/dts/allwinner/sun4i-a10.dtsi
index 51a6464aab9a3..cabf619c2e217 100644
--- a/arch/arm/boot/dts/allwinner/sun4i-a10.dtsi
+++ b/arch/arm/boot/dts/allwinner/sun4i-a10.dtsi
@@ -185,7 +185,7 @@ de: display-engine {
pmu {
compatible = "arm,cortex-a8-pmu";
- interrupts = <3>;
+ interrupts = <66>;
};
reserved-memory {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0544/1518] cpufreq: amd-pstate-ut: Skip tests when amd-pstate driver is not active
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (542 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0543/1518] ARM: dts: allwinner: a10: Fix PMU interrupt Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0545/1518] cpufreq/amd-pstate: Use sysfs_match_string() for epp Greg Kroah-Hartman
` (454 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Li Xiong, Xibo Wang, Qianheng Peng,
Zhongqiu Han, Mario Limonciello, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Qianheng Peng <pengqh1@chinatelecom.cn>
[ Upstream commit 8d31bb1451643f328db0cea0e21e63ef54b4faf2 ]
The crash issue may occur when modprobe amd_pstate_ut on intel platform.
amd_pstate_ut: 1 amd_pstate_ut_acpi_cpc_valid success!
amd_pstate_ut: 2 amd_pstate_ut_check_enabled success!
BUG: kernel NULL pointer dereference, address: 0000000000000080
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0
Oops: 0000 [#1] SMP NOPTI
CPU: 0 PID: 20300 Comm: modprobe
Kdump: loaded Tainted: G O 6.6.0-0010.rc1.ctl4.x86_64 #1
Hardware name: FiberHome R2200 V5/Xeon Boards, BIOS 3.1a 02/24/2020
RIP: 0010:amd_pstate_ut_check_perf+0x141/0x280 [amd_pstate_ut]
Call Trace:
<TASK>
amd_pstate_ut_init+0x1b/0xff0 [amd_pstate_ut]
? __pfx_amd_pstate_ut_init+0x10/0x10 [amd_pstate_ut]
do_one_initcall+0x42/0x2e0
? kmalloc_trace+0x26/0x90
do_init_module+0x60/0x240
__se_sys_init_module+0x185/0x1c0
do_syscall_64+0x62/0x190
entry_SYSCALL_64_after_hwframe+0x76/0x7e
</TASK>
Add state detection to amd pstate driver to prevent amd_pstate_ut driver
from testing on non-AMD platforms.
Fixes: 14eb1c96e3a3 ("cpufreq: amd-pstate: Add test module for amd-pstate driver")
Suggested-by: Li Xiong <xiongl24@chinatelecom.cn>
Suggested-by: Xibo Wang <wangxb12@chinatelecom.cn>
Signed-off-by: Qianheng Peng <pengqh1@chinatelecom.cn>
Reviewed-by: Zhongqiu Han <zhongqiu.han@oss.qualcomm.com>
Link: https://lore.kernel.org/r/1784191899-28957-1-git-send-email-pengqh1@chinatelecom.cn
(ML: adjust title)
Signed-off-by: Mario Limonciello <superm1@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/cpufreq/amd-pstate-ut.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/drivers/cpufreq/amd-pstate-ut.c b/drivers/cpufreq/amd-pstate-ut.c
index 447b9aa5ce40b..93b80bf992a6a 100644
--- a/drivers/cpufreq/amd-pstate-ut.c
+++ b/drivers/cpufreq/amd-pstate-ut.c
@@ -273,6 +273,11 @@ static int amd_pstate_ut_check_driver(u32 index)
static int __init amd_pstate_ut_init(void)
{
u32 i = 0, arr_size = ARRAY_SIZE(amd_pstate_ut_cases);
+ enum amd_pstate_mode mode = amd_pstate_get_status();
+
+ /* don't test if no running amd-pstate driver */
+ if (mode == AMD_PSTATE_UNDEFINED || mode == AMD_PSTATE_DISABLE)
+ return -EOPNOTSUPP;
for (i = 0; i < arr_size; i++) {
int ret = amd_pstate_ut_cases[i].func(i);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0545/1518] cpufreq/amd-pstate: Use sysfs_match_string() for epp
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (543 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0544/1518] cpufreq: amd-pstate-ut: Skip tests when amd-pstate driver is not active Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0546/1518] amd-pstate: Make certain freq_attrs conditionally visible Greg Kroah-Hartman
` (453 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Gautham R. Shenoy,
Mario Limonciello (AMD), Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mario Limonciello (AMD) <superm1@kernel.org>
[ Upstream commit 7e17f48667b6707593fc215cbe025157920934f1 ]
Rather than scanning the buffer and manually matching the string
use the sysfs macros.
Reviewed-by: Gautham R. Shenoy <gautham.shenoy@amd.com>
Signed-off-by: Mario Limonciello (AMD) <superm1@kernel.org>
Stable-dep-of: 57476909c300 ("cpufreq/amd-pstate: Fix EPP return type and handle errors during initialization")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/cpufreq/amd-pstate.c | 15 ++++-----------
1 file changed, 4 insertions(+), 11 deletions(-)
diff --git a/drivers/cpufreq/amd-pstate.c b/drivers/cpufreq/amd-pstate.c
index ce6d6b3ff58a3..6a7621b776831 100644
--- a/drivers/cpufreq/amd-pstate.c
+++ b/drivers/cpufreq/amd-pstate.c
@@ -118,7 +118,6 @@ static const char * const energy_perf_strings[] = {
[EPP_INDEX_BALANCE_PERFORMANCE] = "balance_performance",
[EPP_INDEX_BALANCE_POWERSAVE] = "balance_power",
[EPP_INDEX_POWERSAVE] = "power",
- NULL
};
static unsigned int epp_values[] = {
@@ -1135,16 +1134,15 @@ static ssize_t show_amd_pstate_hw_prefcore(struct cpufreq_policy *policy,
static ssize_t show_energy_performance_available_preferences(
struct cpufreq_policy *policy, char *buf)
{
- int i = 0;
- int offset = 0;
+ int offset = 0, i;
struct amd_cpudata *cpudata = policy->driver_data;
if (cpudata->policy == CPUFREQ_POLICY_PERFORMANCE)
return sysfs_emit_at(buf, offset, "%s\n",
energy_perf_strings[EPP_INDEX_PERFORMANCE]);
- while (energy_perf_strings[i] != NULL)
- offset += sysfs_emit_at(buf, offset, "%s ", energy_perf_strings[i++]);
+ for (i = 0; i < ARRAY_SIZE(energy_perf_strings); i++)
+ offset += sysfs_emit_at(buf, offset, "%s ", energy_perf_strings[i]);
offset += sysfs_emit_at(buf, offset, "\n");
@@ -1155,15 +1153,10 @@ static ssize_t store_energy_performance_preference(
struct cpufreq_policy *policy, const char *buf, size_t count)
{
struct amd_cpudata *cpudata = policy->driver_data;
- char str_preference[21];
ssize_t ret;
u8 epp;
- ret = sscanf(buf, "%20s", str_preference);
- if (ret != 1)
- return -EINVAL;
-
- ret = match_string(energy_perf_strings, -1, str_preference);
+ ret = sysfs_match_string(energy_perf_strings, buf);
if (ret < 0)
return -EINVAL;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0546/1518] amd-pstate: Make certain freq_attrs conditionally visible
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (544 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0545/1518] cpufreq/amd-pstate: Use sysfs_match_string() for epp Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0547/1518] cpufreq/amd-pstate: Add dynamic energy performance preference Greg Kroah-Hartman
` (452 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mario Limonciello (AMD),
Gautham R. Shenoy, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gautham R. Shenoy <gautham.shenoy@amd.com>
[ Upstream commit e67a5b6541831bbf1c40b6042a867a4594ec6b55 ]
Certain amd_pstate freq_attrs such as amd_pstate_hw_prefcore and
amd_pstate_prefcore_ranking are enabled even when preferred core is
not supported on the platform.
Similarly there are common freq_attrs between the amd-pstate and the
amd-pstate-epp drivers (eg: amd_pstate_max_freq,
amd_pstate_lowest_nonlinear_freq, etc.) but are duplicated in two
different freq_attr structs.
Unify all the attributes in a single place and associate each of them
with a visibility function that determines whether the attribute
should be visible based on the underlying platform support and the
current amd_pstate mode.
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Signed-off-by: Gautham R. Shenoy <gautham.shenoy@amd.com>
Signed-off-by: Mario Limonciello (AMD) <superm1@kernel.org>
Stable-dep-of: 57476909c300 ("cpufreq/amd-pstate: Fix EPP return type and handle errors during initialization")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/cpufreq/amd-pstate.c | 124 ++++++++++++++++++++++++++---------
1 file changed, 93 insertions(+), 31 deletions(-)
diff --git a/drivers/cpufreq/amd-pstate.c b/drivers/cpufreq/amd-pstate.c
index 6a7621b776831..6ba3d4e4951a0 100644
--- a/drivers/cpufreq/amd-pstate.c
+++ b/drivers/cpufreq/amd-pstate.c
@@ -1203,12 +1203,87 @@ static ssize_t show_energy_performance_preference(
return sysfs_emit(buf, "%s\n", energy_perf_strings[preference]);
}
+cpufreq_freq_attr_ro(amd_pstate_max_freq);
+cpufreq_freq_attr_ro(amd_pstate_lowest_nonlinear_freq);
+
+cpufreq_freq_attr_ro(amd_pstate_highest_perf);
+cpufreq_freq_attr_ro(amd_pstate_prefcore_ranking);
+cpufreq_freq_attr_ro(amd_pstate_hw_prefcore);
+cpufreq_freq_attr_rw(energy_performance_preference);
+cpufreq_freq_attr_ro(energy_performance_available_preferences);
+
+struct freq_attr_visibility {
+ struct freq_attr *attr;
+ bool (*visibility_fn)(void);
+};
+
+/* For attributes which are always visible */
+static bool always_visible(void)
+{
+ return true;
+}
+
+/* Determines whether prefcore related attributes should be visible */
+static bool prefcore_visibility(void)
+{
+ return amd_pstate_prefcore;
+}
+
+/* Determines whether energy performance preference should be visible */
+static bool epp_visibility(void)
+{
+ return cppc_state == AMD_PSTATE_ACTIVE;
+}
+
+static struct freq_attr_visibility amd_pstate_attr_visibility[] = {
+ {&amd_pstate_max_freq, always_visible},
+ {&amd_pstate_lowest_nonlinear_freq, always_visible},
+ {&amd_pstate_highest_perf, always_visible},
+ {&amd_pstate_prefcore_ranking, prefcore_visibility},
+ {&amd_pstate_hw_prefcore, prefcore_visibility},
+ {&energy_performance_preference, epp_visibility},
+ {&energy_performance_available_preferences, epp_visibility},
+};
+
+static struct freq_attr **get_freq_attrs(void)
+{
+ bool attr_visible[ARRAY_SIZE(amd_pstate_attr_visibility)];
+ struct freq_attr **attrs;
+ int i, j, count;
+
+ for (i = 0, count = 0; i < ARRAY_SIZE(amd_pstate_attr_visibility); i++) {
+ struct freq_attr_visibility *v = &amd_pstate_attr_visibility[i];
+
+ attr_visible[i] = v->visibility_fn();
+ if (attr_visible[i])
+ count++;
+ }
+
+ /* amd_pstate_{max_freq, lowest_nonlinear_freq, highest_perf} should always be visible */
+ BUG_ON(!count);
+
+ attrs = kcalloc(count + 1, sizeof(struct freq_attr *), GFP_KERNEL);
+ if (!attrs)
+ return ERR_PTR(-ENOMEM);
+
+ for (i = 0, j = 0; i < ARRAY_SIZE(amd_pstate_attr_visibility); i++) {
+ if (!attr_visible[i])
+ continue;
+
+ attrs[j++] = amd_pstate_attr_visibility[i].attr;
+ }
+
+ return attrs;
+}
+
static void amd_pstate_driver_cleanup(void)
{
if (amd_pstate_prefcore)
sched_clear_itmt_support();
cppc_state = AMD_PSTATE_DISABLE;
+ kfree(current_pstate_driver->attr);
+ current_pstate_driver->attr = NULL;
current_pstate_driver = NULL;
}
@@ -1233,6 +1308,7 @@ static int amd_pstate_set_driver(int mode_idx)
static int amd_pstate_register_driver(int mode)
{
+ struct freq_attr **attr = NULL;
int ret;
ret = amd_pstate_set_driver(mode);
@@ -1241,6 +1317,22 @@ static int amd_pstate_register_driver(int mode)
cppc_state = mode;
+ /*
+ * Note: It is important to compute the attrs _after_
+ * re-initializing the cppc_state. Some attributes become
+ * visible only when cppc_state is AMD_PSTATE_ACTIVE.
+ */
+ attr = get_freq_attrs();
+ if (IS_ERR(attr)) {
+ ret = (int) PTR_ERR(attr);
+ pr_err("Couldn't compute freq_attrs for current mode %s [%d]\n",
+ amd_pstate_get_mode_string(cppc_state), ret);
+ amd_pstate_driver_cleanup();
+ return ret;
+ }
+
+ current_pstate_driver->attr = attr;
+
/* at least one CPU supports CPB */
current_pstate_driver->boost_enabled = cpu_feature_enabled(X86_FEATURE_CPB);
@@ -1383,37 +1475,9 @@ static ssize_t prefcore_show(struct device *dev,
return sysfs_emit(buf, "%s\n", str_enabled_disabled(amd_pstate_prefcore));
}
-cpufreq_freq_attr_ro(amd_pstate_max_freq);
-cpufreq_freq_attr_ro(amd_pstate_lowest_nonlinear_freq);
-
-cpufreq_freq_attr_ro(amd_pstate_highest_perf);
-cpufreq_freq_attr_ro(amd_pstate_prefcore_ranking);
-cpufreq_freq_attr_ro(amd_pstate_hw_prefcore);
-cpufreq_freq_attr_rw(energy_performance_preference);
-cpufreq_freq_attr_ro(energy_performance_available_preferences);
static DEVICE_ATTR_RW(status);
static DEVICE_ATTR_RO(prefcore);
-static struct freq_attr *amd_pstate_attr[] = {
- &amd_pstate_max_freq,
- &amd_pstate_lowest_nonlinear_freq,
- &amd_pstate_highest_perf,
- &amd_pstate_prefcore_ranking,
- &amd_pstate_hw_prefcore,
- NULL,
-};
-
-static struct freq_attr *amd_pstate_epp_attr[] = {
- &amd_pstate_max_freq,
- &amd_pstate_lowest_nonlinear_freq,
- &amd_pstate_highest_perf,
- &amd_pstate_prefcore_ranking,
- &amd_pstate_hw_prefcore,
- &energy_performance_preference,
- &energy_performance_available_preferences,
- NULL,
-};
-
static struct attribute *pstate_global_attributes[] = {
&dev_attr_status.attr,
&dev_attr_prefcore.attr,
@@ -1680,7 +1744,6 @@ static struct cpufreq_driver amd_pstate_driver = {
.set_boost = amd_pstate_set_boost,
.update_limits = amd_pstate_update_limits,
.name = "amd-pstate",
- .attr = amd_pstate_attr,
};
static struct cpufreq_driver amd_pstate_epp_driver = {
@@ -1696,7 +1759,6 @@ static struct cpufreq_driver amd_pstate_epp_driver = {
.update_limits = amd_pstate_update_limits,
.set_boost = amd_pstate_set_boost,
.name = "amd-pstate-epp",
- .attr = amd_pstate_epp_attr,
};
/*
@@ -1842,7 +1904,7 @@ static int __init amd_pstate_init(void)
return ret;
global_attr_free:
- cpufreq_unregister_driver(current_pstate_driver);
+ amd_pstate_unregister_driver(0);
return ret;
}
device_initcall(amd_pstate_init);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0547/1518] cpufreq/amd-pstate: Add dynamic energy performance preference
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (545 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0546/1518] amd-pstate: Make certain freq_attrs conditionally visible Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0548/1518] cpufreq/amd-pstate: Add support for platform profile class Greg Kroah-Hartman
` (451 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Gautham R. Shenoy,
Mario Limonciello (AMD), Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mario Limonciello (AMD) <superm1@kernel.org>
[ Upstream commit e30ca6dd5345c5b8ba05f346a8e81105352fe571 ]
Dynamic energy performance preference changes the EPP profile based on
whether the machine is running on AC or DC power.
A notification chain from the power supply core is used to adjust EPP
values on plug in or plug out events.
When enabled, the driver exposes a sysfs toggle for dynamic EPP, blocks
manual writes to energy_performance_preference while it "owns" the EPP
updates.
For non-server systems:
* the default EPP for AC mode is `performance`.
* the default EPP for DC mode is `balance_performance`.
For server systems dynamic EPP is mostly a no-op.
Reviewed-by: Gautham R. Shenoy <gautham.shenoy@amd.com>
Signed-off-by: Mario Limonciello (AMD) <superm1@kernel.org>
Stable-dep-of: 57476909c300 ("cpufreq/amd-pstate: Fix EPP return type and handle errors during initialization")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
Documentation/admin-guide/pm/amd-pstate.rst | 18 ++-
drivers/cpufreq/Kconfig.x86 | 12 ++
drivers/cpufreq/amd-pstate.c | 128 +++++++++++++++++++-
drivers/cpufreq/amd-pstate.h | 10 +-
4 files changed, 160 insertions(+), 8 deletions(-)
diff --git a/Documentation/admin-guide/pm/amd-pstate.rst b/Documentation/admin-guide/pm/amd-pstate.rst
index e1771f2225d5f..1132e983cabfe 100644
--- a/Documentation/admin-guide/pm/amd-pstate.rst
+++ b/Documentation/admin-guide/pm/amd-pstate.rst
@@ -289,7 +289,7 @@ and user can change current preference according to energy or performance needs
Please get all support profiles list from
``energy_performance_available_preferences`` attribute, all the profiles are
integer values defined between 0 to 255 when EPP feature is enabled by platform
-firmware, if EPP feature is disabled, driver will ignore the written value
+firmware, but if the dynamic EPP feature is enabled, driver will block writes.
This attribute is read-write.
``boost``
@@ -311,6 +311,22 @@ boost or `1` to enable it, for the respective CPU using the sysfs path
Other performance and frequency values can be read back from
``/sys/devices/system/cpu/cpuX/acpi_cppc/``, see :ref:`cppc_sysfs`.
+Dynamic energy performance profile
+==================================
+The amd-pstate driver supports dynamically selecting the energy performance
+profile based on whether the machine is running on AC or DC power.
+
+Whether this behavior is enabled by default depends on the kernel
+config option `CONFIG_X86_AMD_PSTATE_DYNAMIC_EPP`. This behavior can also be overridden
+at runtime by the sysfs file ``/sys/devices/system/cpu/cpufreq/policyX/dynamic_epp``.
+
+When set to enabled, the driver will select a different energy performance
+profile when the machine is running on battery or AC power.
+When set to disabled, the driver will not change the energy performance profile
+based on the power source and will not react to user desired power state.
+
+Attempting to manually write to the ``energy_performance_preference`` sysfs
+file will fail when ``dynamic_epp`` is enabled.
``amd-pstate`` vs ``acpi-cpufreq``
======================================
diff --git a/drivers/cpufreq/Kconfig.x86 b/drivers/cpufreq/Kconfig.x86
index 2c5c228408bf2..cdaa8d858045a 100644
--- a/drivers/cpufreq/Kconfig.x86
+++ b/drivers/cpufreq/Kconfig.x86
@@ -68,6 +68,18 @@ config X86_AMD_PSTATE_DEFAULT_MODE
For details, take a look at:
<file:Documentation/admin-guide/pm/amd-pstate.rst>.
+config X86_AMD_PSTATE_DYNAMIC_EPP
+ bool "AMD Processor P-State dynamic EPP support"
+ depends on X86_AMD_PSTATE
+ default n
+ help
+ Allow the kernel to dynamically change the energy performance
+ value from events like ACPI platform profile and AC adapter plug
+ events.
+
+ This feature can also be changed at runtime, this configuration
+ option only sets the kernel default value behavior.
+
config X86_AMD_PSTATE_UT
tristate "selftest for AMD Processor P-State driver"
depends on X86 && ACPI_PROCESSOR
diff --git a/drivers/cpufreq/amd-pstate.c b/drivers/cpufreq/amd-pstate.c
index 6ba3d4e4951a0..299875696b5c0 100644
--- a/drivers/cpufreq/amd-pstate.c
+++ b/drivers/cpufreq/amd-pstate.c
@@ -36,6 +36,7 @@
#include <linux/io.h>
#include <linux/delay.h>
#include <linux/uaccess.h>
+#include <linux/power_supply.h>
#include <linux/static_call.h>
#include <linux/topology.h>
@@ -86,6 +87,11 @@ static struct cpufreq_driver amd_pstate_driver;
static struct cpufreq_driver amd_pstate_epp_driver;
static int cppc_state = AMD_PSTATE_UNDEFINED;
static bool amd_pstate_prefcore = true;
+#ifdef CONFIG_X86_AMD_PSTATE_DYNAMIC_EPP
+static bool dynamic_epp = CONFIG_X86_AMD_PSTATE_DYNAMIC_EPP;
+#else
+static bool dynamic_epp;
+#endif
static struct quirk_entry *quirks;
/*
@@ -1062,6 +1068,73 @@ static void amd_pstate_cpu_exit(struct cpufreq_policy *policy)
kfree(cpudata);
}
+static int amd_pstate_get_balanced_epp(struct cpufreq_policy *policy)
+{
+ struct amd_cpudata *cpudata = policy->driver_data;
+
+ if (power_supply_is_system_supplied())
+ return cpudata->epp_default_ac;
+ else
+ return cpudata->epp_default_dc;
+}
+
+static int amd_pstate_power_supply_notifier(struct notifier_block *nb,
+ unsigned long event, void *data)
+{
+ struct amd_cpudata *cpudata = container_of(nb, struct amd_cpudata, power_nb);
+ struct cpufreq_policy *policy __free(put_cpufreq_policy) = cpufreq_cpu_get(cpudata->cpu);
+ u8 epp;
+ int ret;
+
+ if (event != PSY_EVENT_PROP_CHANGED)
+ return NOTIFY_OK;
+
+ epp = amd_pstate_get_balanced_epp(policy);
+
+ ret = amd_pstate_set_epp(policy, epp);
+ if (ret)
+ pr_warn("Failed to set CPU %d EPP %u: %d\n", cpudata->cpu, epp, ret);
+
+ return NOTIFY_OK;
+}
+static void amd_pstate_clear_dynamic_epp(struct cpufreq_policy *policy)
+{
+ struct amd_cpudata *cpudata = policy->driver_data;
+
+ if (cpudata->power_nb.notifier_call)
+ power_supply_unreg_notifier(&cpudata->power_nb);
+ cpudata->dynamic_epp = false;
+}
+
+static int amd_pstate_set_dynamic_epp(struct cpufreq_policy *policy)
+{
+ struct amd_cpudata *cpudata = policy->driver_data;
+ int ret;
+ u8 epp;
+
+ epp = amd_pstate_get_balanced_epp(policy);
+ ret = amd_pstate_set_epp(policy, epp);
+ if (ret)
+ return ret;
+
+ /* only enable notifier if things will actually change */
+ if (cpudata->epp_default_ac != cpudata->epp_default_dc) {
+ cpudata->power_nb.notifier_call = amd_pstate_power_supply_notifier;
+ ret = power_supply_reg_notifier(&cpudata->power_nb);
+ if (ret)
+ goto cleanup;
+ }
+
+ cpudata->dynamic_epp = true;
+
+ return 0;
+
+cleanup:
+ amd_pstate_clear_dynamic_epp(policy);
+
+ return ret;
+}
+
/* Sysfs attributes */
/*
@@ -1156,14 +1229,19 @@ static ssize_t store_energy_performance_preference(
ssize_t ret;
u8 epp;
+ if (cpudata->dynamic_epp) {
+ pr_debug("EPP cannot be set when dynamic EPP is enabled\n");
+ return -EBUSY;
+ }
+
ret = sysfs_match_string(energy_perf_strings, buf);
if (ret < 0)
return -EINVAL;
- if (!ret)
- epp = cpudata->epp_default;
- else
+ if (ret)
epp = epp_values[ret];
+ else
+ epp = amd_pstate_get_balanced_epp(policy);
if (epp > 0 && policy->policy == CPUFREQ_POLICY_PERFORMANCE) {
pr_debug("EPP cannot be set under performance policy\n");
@@ -1171,6 +1249,8 @@ static ssize_t store_energy_performance_preference(
}
ret = amd_pstate_set_epp(policy, epp);
+ if (ret)
+ return ret;
return ret ? ret : count;
}
@@ -1475,12 +1555,42 @@ static ssize_t prefcore_show(struct device *dev,
return sysfs_emit(buf, "%s\n", str_enabled_disabled(amd_pstate_prefcore));
}
+static ssize_t dynamic_epp_show(struct device *dev,
+ struct device_attribute *attr, char *buf)
+{
+ return sysfs_emit(buf, "%s\n", str_enabled_disabled(dynamic_epp));
+}
+
+static ssize_t dynamic_epp_store(struct device *a, struct device_attribute *b,
+ const char *buf, size_t count)
+{
+ bool enabled;
+ int ret;
+
+ ret = kstrtobool(buf, &enabled);
+ if (ret)
+ return ret;
+
+ if (dynamic_epp == enabled)
+ return -EINVAL;
+
+ /* reinitialize with desired dynamic EPP value */
+ dynamic_epp = enabled;
+ ret = amd_pstate_change_driver_mode(cppc_state);
+ if (ret)
+ dynamic_epp = false;
+
+ return ret ? ret : count;
+}
+
static DEVICE_ATTR_RW(status);
static DEVICE_ATTR_RO(prefcore);
+static DEVICE_ATTR_RW(dynamic_epp);
static struct attribute *pstate_global_attributes[] = {
&dev_attr_status.attr,
&dev_attr_prefcore.attr,
+ &dev_attr_dynamic_epp.attr,
NULL
};
@@ -1572,13 +1682,17 @@ static int amd_pstate_epp_cpu_init(struct cpufreq_policy *policy)
if (amd_pstate_acpi_pm_profile_server() ||
amd_pstate_acpi_pm_profile_undefined()) {
policy->policy = CPUFREQ_POLICY_PERFORMANCE;
- cpudata->epp_default = amd_pstate_get_epp(cpudata);
+ cpudata->epp_default_ac = cpudata->epp_default_dc = amd_pstate_get_epp(cpudata);
} else {
policy->policy = CPUFREQ_POLICY_POWERSAVE;
- cpudata->epp_default = AMD_CPPC_EPP_BALANCE_PERFORMANCE;
+ cpudata->epp_default_ac = AMD_CPPC_EPP_PERFORMANCE;
+ cpudata->epp_default_dc = AMD_CPPC_EPP_BALANCE_PERFORMANCE;
}
- ret = amd_pstate_set_epp(policy, cpudata->epp_default);
+ if (dynamic_epp)
+ ret = amd_pstate_set_dynamic_epp(policy);
+ else
+ ret = amd_pstate_set_epp(policy, amd_pstate_get_balanced_epp(policy));
if (ret)
goto free_cpudata1;
@@ -1602,6 +1716,8 @@ static void amd_pstate_epp_cpu_exit(struct cpufreq_policy *policy)
/* Reset CPPC_REQ MSR to the BIOS value */
amd_pstate_update_perf(policy, perf.bios_min_perf, 0U, 0U, 0U, false);
+ if (cpudata->dynamic_epp)
+ amd_pstate_clear_dynamic_epp(policy);
kfree(cpudata);
policy->driver_data = NULL;
}
diff --git a/drivers/cpufreq/amd-pstate.h b/drivers/cpufreq/amd-pstate.h
index 75136d2250c1a..f6806cb3abfab 100644
--- a/drivers/cpufreq/amd-pstate.h
+++ b/drivers/cpufreq/amd-pstate.h
@@ -77,6 +77,11 @@ struct amd_aperf_mperf {
* Only when hw_prefcore and early prefcore param are true,
* AMD P-State driver supports preferred core featue.
* @policy: Cpufreq policy value
+ * @suspended: If CPU core if offlined
+ * @epp_default_ac: Default EPP value for AC power source
+ * @epp_default_dc: Default EPP value for DC power source
+ * @dynamic_epp: Whether dynamic EPP is enabled
+ * @power_nb: Notifier block for power events
*
* The amd_cpudata is key private data for each CPU thread in AMD P-State, and
* represents all the attributes and goals that AMD P-State requests at runtime.
@@ -105,7 +110,10 @@ struct amd_cpudata {
/* EPP feature related attributes*/
u32 policy;
bool suspended;
- u8 epp_default;
+ u8 epp_default_ac;
+ u8 epp_default_dc;
+ bool dynamic_epp;
+ struct notifier_block power_nb;
};
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0548/1518] cpufreq/amd-pstate: Add support for platform profile class
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (546 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0547/1518] cpufreq/amd-pstate: Add dynamic energy performance preference Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0549/1518] cpufreq/amd-pstate: Fix EPP return type and handle errors during initialization Greg Kroah-Hartman
` (450 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Gautham R. Shenoy,
Mario Limonciello (AMD), Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mario Limonciello (AMD) <superm1@kernel.org>
[ Upstream commit 798c47593ccae7dd36c033e557f3f364a2056b9e ]
The platform profile core allows multiple drivers and devices to
register platform profile support.
When the legacy platform profile interface is used all drivers will
adjust the platform profile as well.
Add support for registering every CPU with the platform profile handler
when dynamic EPP is enabled.
The end result will be that changing the platform profile will modify
EPP accordingly.
Reviewed-by: Gautham R. Shenoy <gautham.shenoy@amd.com>
Signed-off-by: Mario Limonciello (AMD) <superm1@kernel.org>
Stable-dep-of: 57476909c300 ("cpufreq/amd-pstate: Fix EPP return type and handle errors during initialization")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
Documentation/admin-guide/pm/amd-pstate.rst | 4 +-
drivers/cpufreq/Kconfig.x86 | 1 +
drivers/cpufreq/amd-pstate.c | 106 ++++++++++++++++++--
drivers/cpufreq/amd-pstate.h | 6 ++
4 files changed, 110 insertions(+), 7 deletions(-)
diff --git a/Documentation/admin-guide/pm/amd-pstate.rst b/Documentation/admin-guide/pm/amd-pstate.rst
index 1132e983cabfe..d3a6c25ee040a 100644
--- a/Documentation/admin-guide/pm/amd-pstate.rst
+++ b/Documentation/admin-guide/pm/amd-pstate.rst
@@ -321,7 +321,9 @@ config option `CONFIG_X86_AMD_PSTATE_DYNAMIC_EPP`. This behavior can also be ove
at runtime by the sysfs file ``/sys/devices/system/cpu/cpufreq/policyX/dynamic_epp``.
When set to enabled, the driver will select a different energy performance
-profile when the machine is running on battery or AC power.
+profile when the machine is running on battery or AC power. The driver will
+also register with the platform profile handler to receive notifications of
+user desired power state and react to those.
When set to disabled, the driver will not change the energy performance profile
based on the power source and will not react to user desired power state.
diff --git a/drivers/cpufreq/Kconfig.x86 b/drivers/cpufreq/Kconfig.x86
index cdaa8d858045a..a0dbb9808ae99 100644
--- a/drivers/cpufreq/Kconfig.x86
+++ b/drivers/cpufreq/Kconfig.x86
@@ -40,6 +40,7 @@ config X86_AMD_PSTATE
select ACPI_PROCESSOR
select ACPI_CPPC_LIB if X86_64
select CPU_FREQ_GOV_SCHEDUTIL if SMP
+ select ACPI_PLATFORM_PROFILE
help
This driver adds a CPUFreq driver which utilizes a fine grain
processor performance frequency control range instead of legacy
diff --git a/drivers/cpufreq/amd-pstate.c b/drivers/cpufreq/amd-pstate.c
index 299875696b5c0..9bec26f4e842d 100644
--- a/drivers/cpufreq/amd-pstate.c
+++ b/drivers/cpufreq/amd-pstate.c
@@ -1089,6 +1089,10 @@ static int amd_pstate_power_supply_notifier(struct notifier_block *nb,
if (event != PSY_EVENT_PROP_CHANGED)
return NOTIFY_OK;
+ /* dynamic actions are only applied while platform profile is in balanced */
+ if (cpudata->current_profile != PLATFORM_PROFILE_BALANCED)
+ return 0;
+
epp = amd_pstate_get_balanced_epp(policy);
ret = amd_pstate_set_epp(policy, epp);
@@ -1097,12 +1101,77 @@ static int amd_pstate_power_supply_notifier(struct notifier_block *nb,
return NOTIFY_OK;
}
+
+static int amd_pstate_profile_probe(void *drvdata, unsigned long *choices)
+{
+ set_bit(PLATFORM_PROFILE_LOW_POWER, choices);
+ set_bit(PLATFORM_PROFILE_BALANCED, choices);
+ set_bit(PLATFORM_PROFILE_PERFORMANCE, choices);
+
+ return 0;
+}
+
+static int amd_pstate_profile_get(struct device *dev,
+ enum platform_profile_option *profile)
+{
+ struct amd_cpudata *cpudata = dev_get_drvdata(dev);
+
+ *profile = cpudata->current_profile;
+
+ return 0;
+}
+
+static int amd_pstate_profile_set(struct device *dev,
+ enum platform_profile_option profile)
+{
+ struct amd_cpudata *cpudata = dev_get_drvdata(dev);
+ struct cpufreq_policy *policy __free(put_cpufreq_policy) = cpufreq_cpu_get(cpudata->cpu);
+ int ret;
+
+ switch (profile) {
+ case PLATFORM_PROFILE_LOW_POWER:
+ ret = amd_pstate_set_epp(policy, AMD_CPPC_EPP_POWERSAVE);
+ if (ret)
+ return ret;
+ break;
+ case PLATFORM_PROFILE_BALANCED:
+ ret = amd_pstate_set_epp(policy,
+ amd_pstate_get_balanced_epp(policy));
+ if (ret)
+ return ret;
+ break;
+ case PLATFORM_PROFILE_PERFORMANCE:
+ ret = amd_pstate_set_epp(policy, AMD_CPPC_EPP_PERFORMANCE);
+ if (ret)
+ return ret;
+ break;
+ default:
+ pr_err("Unknown Platform Profile %d\n", profile);
+ return -EOPNOTSUPP;
+ }
+
+ cpudata->current_profile = profile;
+
+ return 0;
+}
+
+static const struct platform_profile_ops amd_pstate_profile_ops = {
+ .probe = amd_pstate_profile_probe,
+ .profile_set = amd_pstate_profile_set,
+ .profile_get = amd_pstate_profile_get,
+};
+
static void amd_pstate_clear_dynamic_epp(struct cpufreq_policy *policy)
{
struct amd_cpudata *cpudata = policy->driver_data;
if (cpudata->power_nb.notifier_call)
power_supply_unreg_notifier(&cpudata->power_nb);
+ if (cpudata->ppdev) {
+ platform_profile_remove(cpudata->ppdev);
+ cpudata->ppdev = NULL;
+ }
+ kfree(cpudata->profile_name);
cpudata->dynamic_epp = false;
}
@@ -1112,11 +1181,35 @@ static int amd_pstate_set_dynamic_epp(struct cpufreq_policy *policy)
int ret;
u8 epp;
- epp = amd_pstate_get_balanced_epp(policy);
+ switch (cpudata->current_profile) {
+ case PLATFORM_PROFILE_PERFORMANCE:
+ epp = AMD_CPPC_EPP_PERFORMANCE;
+ break;
+ case PLATFORM_PROFILE_LOW_POWER:
+ epp = AMD_CPPC_EPP_POWERSAVE;
+ break;
+ case PLATFORM_PROFILE_BALANCED:
+ epp = amd_pstate_get_balanced_epp(policy);
+ break;
+ default:
+ pr_err("Unknown Platform Profile %d\n", cpudata->current_profile);
+ return -EOPNOTSUPP;
+ }
ret = amd_pstate_set_epp(policy, epp);
if (ret)
return ret;
+ cpudata->profile_name = kasprintf(GFP_KERNEL, "amd-pstate-epp-cpu%d", cpudata->cpu);
+
+ cpudata->ppdev = platform_profile_register(get_cpu_device(policy->cpu),
+ cpudata->profile_name,
+ policy->driver_data,
+ &amd_pstate_profile_ops);
+ if (IS_ERR(cpudata->ppdev)) {
+ ret = PTR_ERR(cpudata->ppdev);
+ goto cleanup;
+ }
+
/* only enable notifier if things will actually change */
if (cpudata->epp_default_ac != cpudata->epp_default_dc) {
cpudata->power_nb.notifier_call = amd_pstate_power_supply_notifier;
@@ -1222,8 +1315,8 @@ static ssize_t show_energy_performance_available_preferences(
return offset;
}
-static ssize_t store_energy_performance_preference(
- struct cpufreq_policy *policy, const char *buf, size_t count)
+static ssize_t store_energy_performance_preference(struct cpufreq_policy *policy,
+ const char *buf, size_t count)
{
struct amd_cpudata *cpudata = policy->driver_data;
ssize_t ret;
@@ -1243,7 +1336,7 @@ static ssize_t store_energy_performance_preference(
else
epp = amd_pstate_get_balanced_epp(policy);
- if (epp > 0 && policy->policy == CPUFREQ_POLICY_PERFORMANCE) {
+ if (cpudata->policy == CPUFREQ_POLICY_PERFORMANCE) {
pr_debug("EPP cannot be set under performance policy\n");
return -EBUSY;
}
@@ -1255,8 +1348,7 @@ static ssize_t store_energy_performance_preference(
return ret ? ret : count;
}
-static ssize_t show_energy_performance_preference(
- struct cpufreq_policy *policy, char *buf)
+static ssize_t show_energy_performance_preference(struct cpufreq_policy *policy, char *buf)
{
struct amd_cpudata *cpudata = policy->driver_data;
u8 preference, epp;
@@ -1683,10 +1775,12 @@ static int amd_pstate_epp_cpu_init(struct cpufreq_policy *policy)
amd_pstate_acpi_pm_profile_undefined()) {
policy->policy = CPUFREQ_POLICY_PERFORMANCE;
cpudata->epp_default_ac = cpudata->epp_default_dc = amd_pstate_get_epp(cpudata);
+ cpudata->current_profile = PLATFORM_PROFILE_PERFORMANCE;
} else {
policy->policy = CPUFREQ_POLICY_POWERSAVE;
cpudata->epp_default_ac = AMD_CPPC_EPP_PERFORMANCE;
cpudata->epp_default_dc = AMD_CPPC_EPP_BALANCE_PERFORMANCE;
+ cpudata->current_profile = PLATFORM_PROFILE_BALANCED;
}
if (dynamic_epp)
diff --git a/drivers/cpufreq/amd-pstate.h b/drivers/cpufreq/amd-pstate.h
index f6806cb3abfab..45958df4992d6 100644
--- a/drivers/cpufreq/amd-pstate.h
+++ b/drivers/cpufreq/amd-pstate.h
@@ -9,6 +9,7 @@
#define _LINUX_AMD_PSTATE_H
#include <linux/pm_qos.h>
+#include <linux/platform_profile.h>
/*********************************************************************
* AMD P-state INTERFACE *
@@ -114,6 +115,11 @@ struct amd_cpudata {
u8 epp_default_dc;
bool dynamic_epp;
struct notifier_block power_nb;
+
+ /* platform profile */
+ enum platform_profile_option current_profile;
+ struct device *ppdev;
+ char *profile_name;
};
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0549/1518] cpufreq/amd-pstate: Fix EPP return type and handle errors during initialization
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (547 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0548/1518] cpufreq/amd-pstate: Add support for platform profile class Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0550/1518] cpufreq/amd-pstate: Toggle auto_sel in active mode on shared memory systems Greg Kroah-Hartman
` (449 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, K Prateek Nayak, Marco Scardovi,
K Prateek Nayak, Mario Limonciello, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Marco Scardovi <scardracs@disroot.org>
[ Upstream commit 57476909c3000a04e84a1d6018d63ba1b2aa20ab ]
Currently, the EPP getter helper functions (msr_get_epp, shmem_get_epp, and
the static call wrapper amd_pstate_get_epp) return u8 or s16. This makes it
difficult to correctly propagate negative error values returned by the
underlying MSR read or CPPC helpers (such as rdmsrq_on_cpu or
cppc_get_epp_perf).
Modify the return type of these functions to int, allowing them to return
negative error codes properly.
Additionally, in amd_pstate_epp_cpu_init(), fetch the firmware-programmed
default EPP value and validate it before assigning it to the EPP variables.
If amd_pstate_get_epp() returns an error code, propagate the error and abort
the CPU initialization to prevent subsequent configuration failures.
Fixes: 555bbe67a622 ("cpufreq/amd-pstate: Convert all perf values to u8")
Assisted-by: Antigravity:gemini-3.5-flash
Reviewed-by: K Prateek Nayak <kprateek.nayak@amd.com>
Tested-by: K Prateek Nayak <kprateek.nayak@amd.com>
Signed-off-by: Marco Scardovi <scardracs@disroot.org>
Reviewed-by: K Prateek Nayak <kprateek.anayk@amd.com>
Link: https://lore.kernel.org/r/20260609073042.81275-2-scardracs@disroot.org
Signed-off-by: Mario Limonciello <superm1@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/cpufreq/amd-pstate.c | 16 ++++++++++++----
1 file changed, 12 insertions(+), 4 deletions(-)
diff --git a/drivers/cpufreq/amd-pstate.c b/drivers/cpufreq/amd-pstate.c
index 9bec26f4e842d..259f04d89a79c 100644
--- a/drivers/cpufreq/amd-pstate.c
+++ b/drivers/cpufreq/amd-pstate.c
@@ -197,7 +197,7 @@ static inline int get_mode_idx_from_str(const char *str, size_t size)
static DEFINE_MUTEX(amd_pstate_driver_lock);
-static u8 msr_get_epp(struct amd_cpudata *cpudata)
+static int msr_get_epp(struct amd_cpudata *cpudata)
{
u64 value;
int ret;
@@ -213,12 +213,12 @@ static u8 msr_get_epp(struct amd_cpudata *cpudata)
DEFINE_STATIC_CALL(amd_pstate_get_epp, msr_get_epp);
-static inline s16 amd_pstate_get_epp(struct amd_cpudata *cpudata)
+static inline int amd_pstate_get_epp(struct amd_cpudata *cpudata)
{
return static_call(amd_pstate_get_epp)(cpudata);
}
-static u8 shmem_get_epp(struct amd_cpudata *cpudata)
+static int shmem_get_epp(struct amd_cpudata *cpudata)
{
u64 epp;
int ret;
@@ -1716,6 +1716,7 @@ static int amd_pstate_epp_cpu_init(struct cpufreq_policy *policy)
struct amd_cpudata *cpudata;
union perf_cached perf;
struct device *dev;
+ int default_epp;
int ret;
/*
@@ -1767,6 +1768,13 @@ static int amd_pstate_epp_cpu_init(struct cpufreq_policy *policy)
policy->boost_supported = READ_ONCE(cpudata->boost_supported);
+ /* Fetch the firmware programmed default EPP value */
+ default_epp = amd_pstate_get_epp(cpudata);
+ if (default_epp < 0) {
+ ret = default_epp;
+ goto free_cpudata1;
+ }
+
/*
* Set the policy to provide a valid fallback value in case
* the default cpufreq governor is neither powersave nor performance.
@@ -1774,7 +1782,7 @@ static int amd_pstate_epp_cpu_init(struct cpufreq_policy *policy)
if (amd_pstate_acpi_pm_profile_server() ||
amd_pstate_acpi_pm_profile_undefined()) {
policy->policy = CPUFREQ_POLICY_PERFORMANCE;
- cpudata->epp_default_ac = cpudata->epp_default_dc = amd_pstate_get_epp(cpudata);
+ cpudata->epp_default_ac = cpudata->epp_default_dc = default_epp;
cpudata->current_profile = PLATFORM_PROFILE_PERFORMANCE;
} else {
policy->policy = CPUFREQ_POLICY_POWERSAVE;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0550/1518] cpufreq/amd-pstate: Toggle auto_sel in active mode on shared memory systems
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (548 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0549/1518] cpufreq/amd-pstate: Fix EPP return type and handle errors during initialization Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0551/1518] firmware: arm_scmi: Roll back partial protocol table registration Greg Kroah-Hartman
` (448 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, K Prateek Nayak, Marco Scardovi,
K Prateek Nayak, Mario Limonciello, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Marco Scardovi <scardracs@disroot.org>
[ Upstream commit 9dfd13f80c856eab79130403a13fa3b83199346b ]
On shared memory systems, the EPP configuration path (handled via
cppc_set_epp_perf()) is responsible for toggling on the CPPC autonomous
selection register (auto_sel).
Currently, shmem_init_perf() returns early without doing any of the auto_sel
configuration steps if cppc_state is AMD_PSTATE_ACTIVE. This skips enabling
auto_sel, leaving the CPU in non-autonomous mode.
Remove the early return check in shmem_init_perf() when cppc_state is
AMD_PSTATE_ACTIVE. Toggling auto_sel is necessary for the active mode on
shared memory systems to function based on the ACPI spec for CPPC v2 and
below.
Fixes: 2dd6d0ebf740 ("cpufreq: amd-pstate: Add guided autonomous mode")
Assisted-by: Antigravity:gemini-3.5-flash
Reviewed-by: K Prateek Nayak <kprateek.nayak@amd.com>
Tested-by: K Prateek Nayak <kprateek.nayak@amd.com>
Signed-off-by: Marco Scardovi <scardracs@disroot.org>
Reviewed-by: K Prateek Nayak <kprateek.anayk@amd.com>
Link: https://lore.kernel.org/r/20260609073042.81275-3-scardracs@disroot.org
Signed-off-by: Mario Limonciello <superm1@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/cpufreq/amd-pstate.c | 3 ---
1 file changed, 3 deletions(-)
diff --git a/drivers/cpufreq/amd-pstate.c b/drivers/cpufreq/amd-pstate.c
index 259f04d89a79c..081d2e60a21e6 100644
--- a/drivers/cpufreq/amd-pstate.c
+++ b/drivers/cpufreq/amd-pstate.c
@@ -457,9 +457,6 @@ static int shmem_init_perf(struct amd_cpudata *cpudata)
WRITE_ONCE(cpudata->perf, perf);
WRITE_ONCE(cpudata->prefcore_ranking, cppc_perf.highest_perf);
- if (cppc_state == AMD_PSTATE_ACTIVE)
- return 0;
-
ret = cppc_get_auto_sel(cpudata->cpu, &auto_sel);
if (ret) {
pr_warn("failed to get auto_sel, ret: %d\n", ret);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0551/1518] firmware: arm_scmi: Roll back partial protocol table registration
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (549 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0550/1518] cpufreq/amd-pstate: Toggle auto_sel in active mode on shared memory systems Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0552/1518] firmware: arm_scmi: Unrequest devices if driver registration fails Greg Kroah-Hartman
` (447 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Sudeep Holla, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sudeep Holla <sudeep.holla@kernel.org>
[ Upstream commit 2224b622260ba590ab56ea1585d6bf7610be25b2 ]
scmi_protocol_table_register() can leave earlier requests registered when
a later entry in the same ID table fails. Each request retains a pointer
to the driver's ID table, so a failed module load can leave a dangling
pointer after the module storage is released.
Unrequest only the successfully registered prefix, in reverse order,
before returning the failure. Leave the failed entry and the remaining
entries untouched because matching requests can be owned by another
driver.
Fixes: 2858f6e5f064 ("firmware: arm_scmi: Add multiple protocols registration support")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://patch.msgid.link/20260722173521.2184378-1-sudeep.holla@kernel.org
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/arm_scmi/bus.c | 31 ++++++++++++++++++++-----------
1 file changed, 20 insertions(+), 11 deletions(-)
diff --git a/drivers/firmware/arm_scmi/bus.c b/drivers/firmware/arm_scmi/bus.c
index 150ea30d0481a..dabde487e7420 100644
--- a/drivers/firmware/arm_scmi/bus.c
+++ b/drivers/firmware/arm_scmi/bus.c
@@ -136,17 +136,6 @@ static int scmi_protocol_device_request(const struct scmi_device_id *id_table)
return ret;
}
-static int scmi_protocol_table_register(const struct scmi_device_id *id_table)
-{
- int ret = 0;
- const struct scmi_device_id *entry;
-
- for (entry = id_table; entry->name && ret == 0; entry++)
- ret = scmi_protocol_device_request(entry);
-
- return ret;
-}
-
/**
* scmi_protocol_device_unrequest - Helper to unrequest a device
*
@@ -192,6 +181,26 @@ static void scmi_protocol_device_unrequest(const struct scmi_device_id *id_table
}
}
+static int scmi_protocol_table_register(const struct scmi_device_id *id_table)
+{
+ const struct scmi_device_id *entry;
+ int ret;
+
+ for (entry = id_table; entry->name; entry++) {
+ ret = scmi_protocol_device_request(entry);
+ if (ret)
+ goto err_unrequest;
+ }
+
+ return 0;
+
+err_unrequest:
+ while (entry != id_table)
+ scmi_protocol_device_unrequest(--entry);
+
+ return ret;
+}
+
static void
scmi_protocol_table_unregister(const struct scmi_device_id *id_table)
{
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0552/1518] firmware: arm_scmi: Unrequest devices if driver registration fails
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (550 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0551/1518] firmware: arm_scmi: Roll back partial protocol table registration Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0553/1518] riscv: dts: spacemit: add MusePi Pro board device tree Greg Kroah-Hartman
` (446 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Sashiko, Sudeep Holla, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sudeep Holla <sudeep.holla@kernel.org>
[ Upstream commit 9f7cd6a62aa754ed6b48cbd5d50de40add1bcc86 ]
scmi_driver_register() requests protocol devices before registering the
driver. If driver_register() fails, those requests remain in the global
IDR and retain pointers to the module's ID table. Once the failed module
load releases that storage, later request matching or SCMI device creation
can dereference the stale pointers.
Unrequest the complete protocol table before returning the registration
failure. At this point table registration succeeded, so every entry is
owned by the current registration attempt.
Fixes: d3cd7c525fd2 ("firmware: arm_scmi: Refactor protocol device creation")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://patch.msgid.link/20260722173521.2184378-2-sudeep.holla@kernel.org
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/arm_scmi/bus.c | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
diff --git a/drivers/firmware/arm_scmi/bus.c b/drivers/firmware/arm_scmi/bus.c
index dabde487e7420..290047b46d51d 100644
--- a/drivers/firmware/arm_scmi/bus.c
+++ b/drivers/firmware/arm_scmi/bus.c
@@ -398,10 +398,14 @@ int scmi_driver_register(struct scmi_driver *driver, struct module *owner,
driver->driver.mod_name = mod_name;
retval = driver_register(&driver->driver);
- if (!retval)
- pr_debug("Registered new scmi driver %s\n", driver->name);
+ if (retval) {
+ scmi_protocol_table_unregister(driver->id_table);
+ return retval;
+ }
- return retval;
+ pr_debug("Registered new scmi driver %s\n", driver->name);
+
+ return 0;
}
EXPORT_SYMBOL_GPL(scmi_driver_register);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0553/1518] riscv: dts: spacemit: add MusePi Pro board device tree
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (551 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0552/1518] firmware: arm_scmi: Unrequest devices if driver registration fails Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0554/1518] riscv: dts: spacemit: Add OrangePi R2S " Greg Kroah-Hartman
` (445 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Troy Mitchell, Yixun Lan,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Troy Mitchell <troy.mitchell@linux.spacemit.com>
[ Upstream commit 0ee59934662dfb89b43a8392e64ac4880c2fca88 ]
Add initial device tree support for the MusePi Pro board [1].
The board is using the SpacemiT K1/M1 SoC.
This device tree is adapted from the SpacemiT vendor tree [2] and
enables basic board functionality, including UART console, LED, eMMC,
Ethernet, and PDMA.
Link: https://developer.spacemit.com/documentation?token=YJtdwnvvViPVcmkoPDpcvwfVnrh&type=pdf [1]
Link: https://gitee.com/bianbu-linux/linux-6.6/blob/k1-bl-v2.2.y/arch/riscv/boot/dts/spacemit/k1-x_MUSE-Pi-Pro.dts [2]
Signed-off-by: Troy Mitchell <troy.mitchell@linux.spacemit.com>
Link: https://lore.kernel.org/r/20251023-k1-musepi-pro-dts-v4-2-01836303e10f@linux.spacemit.com
Signed-off-by: Yixun Lan <dlan@gentoo.org>
Stable-dep-of: 8270311d70fd ("riscv: dts: spacemit: k1: Split gmac_clk_ref into independent pinctrl groups")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/riscv/boot/dts/spacemit/Makefile | 1 +
.../riscv/boot/dts/spacemit/k1-musepi-pro.dts | 79 +++++++++++++++++++
2 files changed, 80 insertions(+)
create mode 100644 arch/riscv/boot/dts/spacemit/k1-musepi-pro.dts
diff --git a/arch/riscv/boot/dts/spacemit/Makefile b/arch/riscv/boot/dts/spacemit/Makefile
index 1528326448706..942ecb38bea03 100644
--- a/arch/riscv/boot/dts/spacemit/Makefile
+++ b/arch/riscv/boot/dts/spacemit/Makefile
@@ -1,4 +1,5 @@
# SPDX-License-Identifier: GPL-2.0
dtb-$(CONFIG_ARCH_SPACEMIT) += k1-bananapi-f3.dtb
dtb-$(CONFIG_ARCH_SPACEMIT) += k1-milkv-jupiter.dtb
+dtb-$(CONFIG_ARCH_SPACEMIT) += k1-musepi-pro.dtb
dtb-$(CONFIG_ARCH_SPACEMIT) += k1-orangepi-rv2.dtb
diff --git a/arch/riscv/boot/dts/spacemit/k1-musepi-pro.dts b/arch/riscv/boot/dts/spacemit/k1-musepi-pro.dts
new file mode 100644
index 0000000000000..29e333b670cf0
--- /dev/null
+++ b/arch/riscv/boot/dts/spacemit/k1-musepi-pro.dts
@@ -0,0 +1,79 @@
+// SPDX-License-Identifier: (GPL-2.0 OR MIT)
+/*
+ * Copyright (C) 2024 Yangyu Chen <cyy@cyyself.name>
+ * Copyright (C) 2025 SpacemiT, Inc
+ * Copyright (C) 2025 Troy Mitchell <troy.mitchell@linux.spacemit.com>
+ */
+
+/dts-v1/;
+
+#include "k1.dtsi"
+#include "k1-pinctrl.dtsi"
+
+/ {
+ model = "SpacemiT MusePi Pro";
+ compatible = "spacemit,musepi-pro", "spacemit,k1";
+
+ aliases {
+ ethernet0 = ð0;
+ serial0 = &uart0;
+ };
+
+ chosen {
+ stdout-path = "serial0";
+ };
+
+ leds {
+ compatible = "gpio-leds";
+
+ led1 {
+ label = "sys-led";
+ gpios = <&gpio K1_GPIO(96) GPIO_ACTIVE_HIGH>;
+ linux,default-trigger = "heartbeat";
+ default-state = "on";
+ };
+ };
+};
+
+&emmc {
+ bus-width = <8>;
+ mmc-hs400-1_8v;
+ mmc-hs400-enhanced-strobe;
+ non-removable;
+ no-sd;
+ no-sdio;
+ status = "okay";
+};
+
+ð0 {
+ phy-handle = <&rgmii0>;
+ phy-mode = "rgmii-id";
+ pinctrl-0 = <&gmac0_cfg>;
+ pinctrl-names = "default";
+ rx-internal-delay-ps = <0>;
+ tx-internal-delay-ps = <0>;
+ status = "okay";
+
+ mdio-bus {
+ #address-cells = <0x1>;
+ #size-cells = <0x0>;
+
+ reset-gpios = <&gpio K1_GPIO(110) GPIO_ACTIVE_LOW>;
+ reset-delay-us = <10000>;
+ reset-post-delay-us = <100000>;
+
+ rgmii0: phy@1 {
+ reg = <0x1>;
+ };
+ };
+};
+
+&pdma {
+ status = "okay";
+};
+
+&uart0 {
+ pinctrl-0 = <&uart0_2_cfg>;
+ pinctrl-names = "default";
+ status = "okay";
+};
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0554/1518] riscv: dts: spacemit: Add OrangePi R2S board device tree
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (552 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0553/1518] riscv: dts: spacemit: add MusePi Pro board device tree Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0555/1518] riscv: dts: spacemit: k1: Split gmac_clk_ref into independent pinctrl groups Greg Kroah-Hartman
` (444 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Opdenacker, Yixun Lan,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michael Opdenacker <michael.opdenacker@rootcommit.com>
[ Upstream commit 63e572b11464a233f45ad469ba64b8b9e68a9cd1 ]
Add initial device tree support for the OrangePi RV2 board [1], which is
marketed as using the Ky X1 SoC but is identical in die and package
to the SpacemiT K1 SoC [2].
Enable UART0, to boot into a serial console
Two Gigabit Ethernet ports with RGMII interface standard support
are enabled, each port is connected to an external
Motorcomm YT8531C PHY chip which uses the GPIO for reset control.
Enable PDMA.
Enable 8 GB eMMC chip for storage.
Link: http://www.orangepi.org/html/hardWare/computerAndMicrocontrollers/details/Orange-Pi-R2S.html [1]
Link: https://www.spacemit.com/en/key-stone-k1 [2]
Signed-off-by: Michael Opdenacker <michael.opdenacker@rootcommit.com>
Reviewed-by: Yixun Lan <dlan@gentoo.org>
Link: https://lore.kernel.org/r/20251112044426.2351999-3-michael.opdenacker@rootcommit.com
Signed-off-by: Yixun Lan <dlan@gentoo.org>
Stable-dep-of: 8270311d70fd ("riscv: dts: spacemit: k1: Split gmac_clk_ref into independent pinctrl groups")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/riscv/boot/dts/spacemit/Makefile | 1 +
.../boot/dts/spacemit/k1-orangepi-r2s.dts | 90 +++++++++++++++++++
2 files changed, 91 insertions(+)
create mode 100644 arch/riscv/boot/dts/spacemit/k1-orangepi-r2s.dts
diff --git a/arch/riscv/boot/dts/spacemit/Makefile b/arch/riscv/boot/dts/spacemit/Makefile
index 942ecb38bea03..95889e7269d1b 100644
--- a/arch/riscv/boot/dts/spacemit/Makefile
+++ b/arch/riscv/boot/dts/spacemit/Makefile
@@ -2,4 +2,5 @@
dtb-$(CONFIG_ARCH_SPACEMIT) += k1-bananapi-f3.dtb
dtb-$(CONFIG_ARCH_SPACEMIT) += k1-milkv-jupiter.dtb
dtb-$(CONFIG_ARCH_SPACEMIT) += k1-musepi-pro.dtb
+dtb-$(CONFIG_ARCH_SPACEMIT) += k1-orangepi-r2s.dtb
dtb-$(CONFIG_ARCH_SPACEMIT) += k1-orangepi-rv2.dtb
diff --git a/arch/riscv/boot/dts/spacemit/k1-orangepi-r2s.dts b/arch/riscv/boot/dts/spacemit/k1-orangepi-r2s.dts
new file mode 100644
index 0000000000000..58098c4a2aabd
--- /dev/null
+++ b/arch/riscv/boot/dts/spacemit/k1-orangepi-r2s.dts
@@ -0,0 +1,90 @@
+// SPDX-License-Identifier: (GPL-2.0 OR MIT)
+/*
+ * Copyright (C) 2025 Michael Opdenacker <michael.opdenacker@rootcommit.com>
+ */
+
+/dts-v1/;
+
+#include "k1.dtsi"
+#include "k1-pinctrl.dtsi"
+
+/ {
+ model = "OrangePi R2S";
+ compatible = "xunlong,orangepi-r2s", "spacemit,k1";
+
+ aliases {
+ serial0 = &uart0;
+ ethernet0 = ð0;
+ ethernet1 = ð1;
+ };
+
+ chosen {
+ stdout-path = "serial0";
+ };
+};
+
+&emmc {
+ bus-width = <8>;
+ mmc-hs400-1_8v;
+ mmc-hs400-enhanced-strobe;
+ non-removable;
+ no-sd;
+ no-sdio;
+ status = "okay";
+};
+
+ð0 {
+ phy-handle = <&rgmii0>;
+ phy-mode = "rgmii-id";
+ pinctrl-names = "default";
+ pinctrl-0 = <&gmac0_cfg>;
+ rx-internal-delay-ps = <0>;
+ tx-internal-delay-ps = <0>;
+ status = "okay";
+
+ mdio-bus {
+ #address-cells = <0x1>;
+ #size-cells = <0x0>;
+
+ reset-gpios = <&gpio K1_GPIO(110) GPIO_ACTIVE_LOW>;
+ reset-delay-us = <10000>;
+ reset-post-delay-us = <100000>;
+
+ rgmii0: phy@1 {
+ reg = <0x1>;
+ };
+ };
+};
+
+ð1 {
+ phy-handle = <&rgmii1>;
+ phy-mode = "rgmii-id";
+ pinctrl-names = "default";
+ pinctrl-0 = <&gmac1_cfg>;
+ rx-internal-delay-ps = <0>;
+ tx-internal-delay-ps = <250>;
+ status = "okay";
+
+ mdio-bus {
+ #address-cells = <0x1>;
+ #size-cells = <0x0>;
+
+ reset-gpios = <&gpio K1_GPIO(115) GPIO_ACTIVE_LOW>;
+ reset-delay-us = <10000>;
+ reset-post-delay-us = <100000>;
+
+ rgmii1: phy@1 {
+ reg = <0x1>;
+ };
+ };
+};
+
+&pdma {
+ status = "okay";
+};
+
+&uart0 {
+ pinctrl-names = "default";
+ pinctrl-0 = <&uart0_2_cfg>;
+ status = "okay";
+};
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0555/1518] riscv: dts: spacemit: k1: Split gmac_clk_ref into independent pinctrl groups
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (553 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0554/1518] riscv: dts: spacemit: Add OrangePi R2S " Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0556/1518] perf cs-etm: Flush thread stacks after decoder reset Greg Kroah-Hartman
` (443 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Junhui Liu, Yixun Lan, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Junhui Liu <junhui.liu@pigmoral.tech>
[ Upstream commit 8270311d70fdf36bc8aab1e52b554e654a8839ff ]
The gmac_clk_ref signal is optional for the GMAC controller and is not
strictly required for all hardware designs. The pins for gmac0_clk_ref
(GPIO 45) and gmac1_clk_ref (GPIO 46) may also be used as GPIOs for
other functions even when the Ethernet controller is active.
Split the refclk pins into independent pinctrl groups so boards can
request them only when the reference clock path is actually needed.
Among the already mainlined boards, BPI-F3, Jupiter and MusePi Pro have
optional hardware paths for the GMAC refclk pins. BPI-F3 and Jupiter
route both GMAC refclk pins to the PHYs through NC/0R option resistors,
while MusePi Pro only does so for GMAC0. Keep referencing the new
clk-ref pinctrl groups on these boards so the optional hardware paths
remain usable if the option resistors are populated.
OrangePi R2S has no publicly available schematic, so also keep the
clk-ref groups there to preserve the previous pinmux behavior.
Fixes: 60775f28cfb7 ("riscv: dts: spacemit: Add Ethernet support for K1")
Signed-off-by: Junhui Liu <junhui.liu@pigmoral.tech>
Reviewed-by: Yixun Lan <dlan@kernel.org>
Link: https://patch.msgid.link/20260712-bpi-cm6-v3-2-8d1e2045179d@pigmoral.tech
Signed-off-by: Yixun Lan <dlan@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../boot/dts/spacemit/k1-bananapi-f3.dts | 4 ++--
.../boot/dts/spacemit/k1-milkv-jupiter.dts | 4 ++--
.../riscv/boot/dts/spacemit/k1-musepi-pro.dts | 2 +-
.../boot/dts/spacemit/k1-orangepi-r2s.dts | 4 ++--
arch/riscv/boot/dts/spacemit/k1-pinctrl.dtsi | 24 +++++++++++++++----
5 files changed, 27 insertions(+), 11 deletions(-)
diff --git a/arch/riscv/boot/dts/spacemit/k1-bananapi-f3.dts b/arch/riscv/boot/dts/spacemit/k1-bananapi-f3.dts
index a58192ba67b2c..b2c40bae60945 100644
--- a/arch/riscv/boot/dts/spacemit/k1-bananapi-f3.dts
+++ b/arch/riscv/boot/dts/spacemit/k1-bananapi-f3.dts
@@ -46,7 +46,7 @@ ð0 {
phy-handle = <&rgmii0>;
phy-mode = "rgmii-id";
pinctrl-names = "default";
- pinctrl-0 = <&gmac0_cfg>;
+ pinctrl-0 = <&gmac0_cfg>, <&gmac0_clk_ref_cfg>;
rx-internal-delay-ps = <0>;
tx-internal-delay-ps = <0>;
status = "okay";
@@ -69,7 +69,7 @@ ð1 {
phy-handle = <&rgmii1>;
phy-mode = "rgmii-id";
pinctrl-names = "default";
- pinctrl-0 = <&gmac1_cfg>;
+ pinctrl-0 = <&gmac1_cfg>, <&gmac1_clk_ref_cfg>;
rx-internal-delay-ps = <0>;
tx-internal-delay-ps = <250>;
status = "okay";
diff --git a/arch/riscv/boot/dts/spacemit/k1-milkv-jupiter.dts b/arch/riscv/boot/dts/spacemit/k1-milkv-jupiter.dts
index a01f69f202e37..695af4919b94a 100644
--- a/arch/riscv/boot/dts/spacemit/k1-milkv-jupiter.dts
+++ b/arch/riscv/boot/dts/spacemit/k1-milkv-jupiter.dts
@@ -26,7 +26,7 @@ ð0 {
phy-handle = <&rgmii0>;
phy-mode = "rgmii-id";
pinctrl-names = "default";
- pinctrl-0 = <&gmac0_cfg>;
+ pinctrl-0 = <&gmac0_cfg>, <&gmac0_clk_ref_cfg>;
rx-internal-delay-ps = <0>;
tx-internal-delay-ps = <0>;
status = "okay";
@@ -49,7 +49,7 @@ ð1 {
phy-handle = <&rgmii1>;
phy-mode = "rgmii-id";
pinctrl-names = "default";
- pinctrl-0 = <&gmac1_cfg>;
+ pinctrl-0 = <&gmac1_cfg>, <&gmac1_clk_ref_cfg>;
rx-internal-delay-ps = <0>;
tx-internal-delay-ps = <250>;
status = "okay";
diff --git a/arch/riscv/boot/dts/spacemit/k1-musepi-pro.dts b/arch/riscv/boot/dts/spacemit/k1-musepi-pro.dts
index 29e333b670cf0..42efc8c1a5818 100644
--- a/arch/riscv/boot/dts/spacemit/k1-musepi-pro.dts
+++ b/arch/riscv/boot/dts/spacemit/k1-musepi-pro.dts
@@ -48,7 +48,7 @@ &emmc {
ð0 {
phy-handle = <&rgmii0>;
phy-mode = "rgmii-id";
- pinctrl-0 = <&gmac0_cfg>;
+ pinctrl-0 = <&gmac0_cfg>, <&gmac0_clk_ref_cfg>;
pinctrl-names = "default";
rx-internal-delay-ps = <0>;
tx-internal-delay-ps = <0>;
diff --git a/arch/riscv/boot/dts/spacemit/k1-orangepi-r2s.dts b/arch/riscv/boot/dts/spacemit/k1-orangepi-r2s.dts
index 58098c4a2aabd..312d5bc860722 100644
--- a/arch/riscv/boot/dts/spacemit/k1-orangepi-r2s.dts
+++ b/arch/riscv/boot/dts/spacemit/k1-orangepi-r2s.dts
@@ -37,7 +37,7 @@ ð0 {
phy-handle = <&rgmii0>;
phy-mode = "rgmii-id";
pinctrl-names = "default";
- pinctrl-0 = <&gmac0_cfg>;
+ pinctrl-0 = <&gmac0_cfg>, <&gmac0_clk_ref_cfg>;
rx-internal-delay-ps = <0>;
tx-internal-delay-ps = <0>;
status = "okay";
@@ -60,7 +60,7 @@ ð1 {
phy-handle = <&rgmii1>;
phy-mode = "rgmii-id";
pinctrl-names = "default";
- pinctrl-0 = <&gmac1_cfg>;
+ pinctrl-0 = <&gmac1_cfg>, <&gmac1_clk_ref_cfg>;
rx-internal-delay-ps = <0>;
tx-internal-delay-ps = <250>;
status = "okay";
diff --git a/arch/riscv/boot/dts/spacemit/k1-pinctrl.dtsi b/arch/riscv/boot/dts/spacemit/k1-pinctrl.dtsi
index aff19c86d5ff3..48c4b41311646 100644
--- a/arch/riscv/boot/dts/spacemit/k1-pinctrl.dtsi
+++ b/arch/riscv/boot/dts/spacemit/k1-pinctrl.dtsi
@@ -27,8 +27,16 @@ gmac0-pins {
<K1_PADCONF(11, 1)>, /* gmac0_tx_en */
<K1_PADCONF(12, 1)>, /* gmac0_mdc */
<K1_PADCONF(13, 1)>, /* gmac0_mdio */
- <K1_PADCONF(14, 1)>, /* gmac0_int_n */
- <K1_PADCONF(45, 1)>; /* gmac0_clk_ref */
+ <K1_PADCONF(14, 1)>; /* gmac0_int_n */
+
+ bias-pull-up = <0>;
+ drive-strength = <21>;
+ };
+ };
+
+ gmac0_clk_ref_cfg: gmac0-clk-ref-cfg {
+ gmac0-clk-ref-pins {
+ pinmux = <K1_PADCONF(45, 1)>; /* gmac0_clk_ref */
bias-pull-up = <0>;
drive-strength = <21>;
@@ -51,8 +59,16 @@ gmac1-pins {
<K1_PADCONF(40, 1)>, /* gmac1_tx_en */
<K1_PADCONF(41, 1)>, /* gmac1_mdc */
<K1_PADCONF(42, 1)>, /* gmac1_mdio */
- <K1_PADCONF(43, 1)>, /* gmac1_int_n */
- <K1_PADCONF(46, 1)>; /* gmac1_clk_ref */
+ <K1_PADCONF(43, 1)>; /* gmac1_int_n */
+
+ bias-pull-up = <0>;
+ drive-strength = <21>;
+ };
+ };
+
+ gmac1_clk_ref_cfg: gmac1-clk-ref-cfg {
+ gmac1-clk-ref-pins {
+ pinmux = <K1_PADCONF(46, 1)>; /* gmac1_clk_ref */
bias-pull-up = <0>;
drive-strength = <21>;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0556/1518] perf cs-etm: Flush thread stacks after decoder reset
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (554 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0555/1518] riscv: dts: spacemit: k1: Split gmac_clk_ref into independent pinctrl groups Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0557/1518] perf cs-etm: Avoid truncating AUX buffer sizes to int Greg Kroah-Hartman
` (442 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, James Clark, Leo Yan, Namhyung Kim,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leo Yan <leo.yan@arm.com>
[ Upstream commit ea5075e3776846d4941dddf1549426ebd3feb81f ]
Perf resets the CoreSight decoder when moving to a new AUX trace buffer,
this causes trace discontinunity globally.
For callchain synthesis, keeping thread-stack state after decoder reset
can leave stale call/return history attached to threads that are decoded
later, producing incorrect synthesized callchains.
Flush all host thread stacks after a decoder reset. When virtualization
is present, flush the guest thread stacks as well.
Reviewed-by: James Clark <james.clark@linaro.org>
Signed-off-by: Leo Yan <leo.yan@arm.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Stable-dep-of: ec99be8a31db ("perf cs-etm: Avoid truncating AUX buffer sizes to int")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/cs-etm.c | 45 ++++++++++++++++++++++++++++++++++++++++
1 file changed, 45 insertions(+)
diff --git a/tools/perf/util/cs-etm.c b/tools/perf/util/cs-etm.c
index 66dbead2c03bc..215414a8f61f1 100644
--- a/tools/perf/util/cs-etm.c
+++ b/tools/perf/util/cs-etm.c
@@ -2066,6 +2066,45 @@ static int cs_etm__end_block(struct cs_etm_queue *etmq,
return 0;
}
+
+static int cs_etm__flush_stack_cb(struct thread *thread,
+ void *data __maybe_unused)
+{
+ thread_stack__flush(thread);
+ return 0;
+}
+
+static void cs_etm__flush_machine_stack(struct cs_etm_queue *etmq, pid_t pid)
+{
+ struct machine *machine;
+
+ machine = machines__find(&etmq->etm->session->machines, pid);
+ if (machine)
+ machine__for_each_thread(machine, cs_etm__flush_stack_cb, NULL);
+}
+
+static void cs_etm__flush_all_stack(struct cs_etm_queue *etmq)
+{
+ enum cs_etm_pid_fmt pid_fmt = cs_etm__get_pid_fmt(etmq);
+
+ if (!etmq->etm->synth_opts.last_branch)
+ return;
+
+ switch (pid_fmt) {
+ case CS_ETM_PIDFMT_CTXTID2:
+ /* Clear the guest stack if virtualization is supported */
+ cs_etm__flush_machine_stack(etmq, DEFAULT_GUEST_KERNEL_ID);
+ fallthrough;
+ case CS_ETM_PIDFMT_CTXTID:
+ cs_etm__flush_machine_stack(etmq, HOST_KERNEL_ID);
+ break;
+ case CS_ETM_PIDFMT_NONE:
+ default:
+ break;
+
+ }
+}
+
/*
* cs_etm__get_data_block: Fetch a block from the auxtrace_buffer queue
* if need be.
@@ -2088,6 +2127,12 @@ static int cs_etm__get_data_block(struct cs_etm_queue *etmq)
ret = cs_etm_decoder__reset(etmq->decoder);
if (ret)
return ret;
+
+ /*
+ * Since the decoder is reset, this causes a global trace
+ * discontinuity. Flush all thread stacks.
+ */
+ cs_etm__flush_all_stack(etmq);
}
return etmq->buf_len;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0557/1518] perf cs-etm: Avoid truncating AUX buffer sizes to int
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (555 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0556/1518] perf cs-etm: Flush thread stacks after decoder reset Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0558/1518] xfrm: Fix skb double-free in xfrm_dev_direct_output() Greg Kroah-Hartman
` (441 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Suyash Mahar, Leo Yan, James Clark,
Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leo Yan <leo.yan@arm.com>
[ Upstream commit ec99be8a31db999a4f866be74ea7db61dbb19f24 ]
cs_etm__get_trace() returns an int, but it used to return etmq->buf_len
on success. That value comes from auxtrace_buffer::size, which is a
size_t. For a large AUX trace block, returning the byte count through an
int can overflow and make a valid buffer look like a negative error.
The callers do not need the actual byte count from cs_etm__get_trace().
The buffer length is already stored in the etmq->buf_len. The callers
only need to distinguish three states:
< 0: error
= 0: no more AUX buffers
> 0: data is available
Make cs_etm__get_trace() return 0 for all non-error cases and use
etmq->buf_len to indicate whether a new buffer was found. Then make
cs_etm__get_data_block() return 1 whenever data is available, instead of
returning the buffer length.
Also refactor cs_etm__get_data_block() to make its return value
semantics clearer.
Reported-by: Suyash Mahar <smahar@meta.com>
Fixes: 8224531cf5a1 ("perf cs-etm: Modularize auxtrace_buffer fetch function")
Signed-off-by: Leo Yan <leo.yan@arm.com>
Reviewed-by: James Clark <james.clark@linaro.org>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/cs-etm.c | 46 +++++++++++++++++++++++-----------------
1 file changed, 26 insertions(+), 20 deletions(-)
diff --git a/tools/perf/util/cs-etm.c b/tools/perf/util/cs-etm.c
index 215414a8f61f1..15f99c2c2775a 100644
--- a/tools/perf/util/cs-etm.c
+++ b/tools/perf/util/cs-etm.c
@@ -1509,8 +1509,7 @@ cs_etm__get_trace(struct cs_etm_queue *etmq)
etmq->buf_used = 0;
etmq->buf_len = aux_buffer->size;
etmq->buf = aux_buffer->data;
-
- return etmq->buf_len;
+ return 0;
}
/*
@@ -2116,26 +2115,33 @@ static int cs_etm__get_data_block(struct cs_etm_queue *etmq)
{
int ret;
- if (!etmq->buf_len) {
- ret = cs_etm__get_trace(etmq);
- if (ret <= 0)
- return ret;
- /*
- * We cannot assume consecutive blocks in the data file
- * are contiguous, reset the decoder to force re-sync.
- */
- ret = cs_etm_decoder__reset(etmq->decoder);
- if (ret)
- return ret;
+ /* The current block is not finished */
+ if (etmq->buf_len)
+ return 1;
- /*
- * Since the decoder is reset, this causes a global trace
- * discontinuity. Flush all thread stacks.
- */
- cs_etm__flush_all_stack(etmq);
- }
+ ret = cs_etm__get_trace(etmq);
+ if (ret < 0)
+ return ret;
+
+ /* No more buffer to read */
+ if (!etmq->buf_len)
+ return 0;
+
+ /*
+ * We cannot assume consecutive blocks in the data file
+ * are contiguous, reset the decoder to force re-sync.
+ */
+ ret = cs_etm_decoder__reset(etmq->decoder);
+ if (ret)
+ return ret;
+
+ /*
+ * Since the decoder is reset, this causes a global trace
+ * discontinuity. Flush all thread stacks.
+ */
+ cs_etm__flush_all_stack(etmq);
- return etmq->buf_len;
+ return 1;
}
static bool cs_etm__is_svc_instr(struct cs_etm_queue *etmq,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0558/1518] xfrm: Fix skb double-free in xfrm_dev_direct_output()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (556 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0557/1518] perf cs-etm: Avoid truncating AUX buffer sizes to int Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0559/1518] RDMA/erdma: complete object teardown when the destroy command fails Greg Kroah-Hartman
` (440 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sanghyun Park, Steffen Klassert,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sanghyun Park <sanghyun.park.cnu@gmail.com>
[ Upstream commit 2aed51fc58d9ce450e2c116efb956160fd06fa02 ]
A return value other than 1 from local_out() means that the skb has been
consumed or its ownership was transferred. xfrm_dev_direct_output()
nevertheless frees the skb on this path, causing a double-free when
netfilter drops the packet and invalidating any other owner.
Return the local_out() result directly, matching the ownership handling
in xfrm_output_resume().
Fixes: 5eddd76ec2fd ("xfrm: fix tunnel mode TX datapath in packet offload mode")
Signed-off-by: Sanghyun Park <sanghyun.park.cnu@gmail.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/xfrm/xfrm_output.c | 4 +---
1 file changed, 1 insertion(+), 3 deletions(-)
diff --git a/net/xfrm/xfrm_output.c b/net/xfrm/xfrm_output.c
index 54222fcbd7fd8..b152edf50feca 100644
--- a/net/xfrm/xfrm_output.c
+++ b/net/xfrm/xfrm_output.c
@@ -629,10 +629,8 @@ static int xfrm_dev_direct_output(struct sock *sk, struct xfrm_state *x,
nf_reset_ct(skb);
err = skb_dst(skb)->ops->local_out(net, sk, skb);
- if (unlikely(err != 1)) {
- kfree_skb(skb);
+ if (unlikely(err != 1))
return err;
- }
/* In transport mode, network destination is
* directly reachable, while in tunnel mode,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0559/1518] RDMA/erdma: complete object teardown when the destroy command fails
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (557 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0558/1518] xfrm: Fix skb double-free in xfrm_dev_direct_output() Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0560/1518] PM: hibernate: Fix memory leak in snapshot_write_next() error path Greg Kroah-Hartman
` (439 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Leon Romanovsky, Cheng Xu,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leon Romanovsky <leonro@nvidia.com>
[ Upstream commit 652befcba956ef357f480525ccbe25c59bc81d4d ]
erdma_destroy_qp(), erdma_destroy_cq(), erdma_dereg_mr(), and
erdma_destroy_ah() returned early when erdma_post_cmd_wait() failed,
leaking the queue buffers, MTTs, doorbells and the STAG, QPN, CQN and AHN
identifiers. A command timeout clears ERDMA_CMDQ_STATE_OK_BIT and
permanently disables the command queue, so no retry can succeed; the RDMA
core keeps the object after a failed destructor and forced uverbs cleanup
then nulls the pointers, making the resources unreachable.
Warn on failure but release every software-owned resource and return
success, since during terminal destruction the hardware command result is
only diagnostic.
Fixes: 155055771704 ("RDMA/erdma: Add verbs implementation")
Link: https://patch.msgid.link/20260722-b4-qp-and-cq-memory-are-leaked-if-the-d-v1-1-97e223dc1c96@nvidia.com
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Acked-by: Cheng Xu <chengyou@linux.alibaba.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/erdma/erdma_verbs.c | 21 +++++++++++++++++----
1 file changed, 17 insertions(+), 4 deletions(-)
diff --git a/drivers/infiniband/hw/erdma/erdma_verbs.c b/drivers/infiniband/hw/erdma/erdma_verbs.c
index 058edc42de58b..4c78013b056fa 100644
--- a/drivers/infiniband/hw/erdma/erdma_verbs.c
+++ b/drivers/infiniband/hw/erdma/erdma_verbs.c
@@ -1303,8 +1303,15 @@ int erdma_dereg_mr(struct ib_mr *ibmr, struct ib_udata *udata)
ret = erdma_post_cmd_wait(&dev->cmdq, &req, sizeof(req), NULL, NULL,
true);
+ /*
+ * A timeout disables the command queue, so retry cannot succeed. Treat
+ * terminal command failures as diagnostic; propagating them can make
+ * forced uverbs cleanup discard the last software resource pointers.
+ */
if (ret)
- return ret;
+ ibdev_warn_ratelimited(&dev->ibdev,
+ "failed to deregister MR 0x%x: %d\n",
+ ibmr->lkey, ret);
erdma_free_idx(&dev->res_cb[ERDMA_RES_TYPE_STAG_IDX], ibmr->lkey >> 8);
@@ -1330,7 +1337,9 @@ int erdma_destroy_cq(struct ib_cq *ibcq, struct ib_udata *udata)
err = erdma_post_cmd_wait(&dev->cmdq, &req, sizeof(req), NULL, NULL,
true);
if (err)
- return err;
+ ibdev_warn_ratelimited(&dev->ibdev,
+ "failed to destroy CQ %u: %d\n",
+ cq->cqn, err);
if (rdma_is_kernel_res(&cq->ibcq.res)) {
dma_free_coherent(&dev->pdev->dev, cq->depth << CQE_SHIFT,
@@ -1378,7 +1387,9 @@ int erdma_destroy_qp(struct ib_qp *ibqp, struct ib_udata *udata)
err = erdma_post_cmd_wait(&dev->cmdq, &req, sizeof(req), NULL, NULL,
true);
if (err)
- return err;
+ ibdev_warn_ratelimited(&dev->ibdev,
+ "failed to destroy QP %u: %d\n",
+ QP_ID(qp), err);
erdma_qp_put(qp);
wait_for_completion(&qp->safe_free);
@@ -2282,7 +2293,9 @@ int erdma_destroy_ah(struct ib_ah *ibah, u32 flags)
ret = erdma_post_cmd_wait(&dev->cmdq, &req, sizeof(req), NULL, NULL,
flags & RDMA_DESTROY_AH_SLEEPABLE);
if (ret)
- return ret;
+ ibdev_warn_ratelimited(&dev->ibdev,
+ "failed to destroy AH %u: %d\n",
+ ah->ahn, ret);
erdma_free_idx(&dev->res_cb[ERDMA_RES_TYPE_AH], ah->ahn);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0560/1518] PM: hibernate: Fix memory leak in snapshot_write_next() error path
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (558 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0559/1518] RDMA/erdma: complete object teardown when the destroy command fails Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0561/1518] leds: pca9532: Fix phantom device registration on missing hardware Greg Kroah-Hartman
` (438 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Malaya Kumar Rout, Brian Geffon,
Rafael J. Wysocki, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Malaya Kumar Rout <malayarout91@gmail.com>
[ Upstream commit 21d5c4cee31c5ce78f6decc7fafc7e7759af391f ]
When memory_bm_create() succeeds for copy_bm but fails for zero_bm,
the function returns without freeing the resources allocated for
copy_bm. This results in a memory leak that includes radix tree nodes,
zone structures, and page lists.
Fix this by calling memory_bm_free() to release copy_bm's resources
before returning the error code when zero_bm allocation fails.
Fixes: 005e8dddd497 ("PM: hibernate: don't store zero pages in the image file")
Signed-off-by: Malaya Kumar Rout <malayarout91@gmail.com>
Acked-by: Brian Geffon <bgeffon@google.com>
Link: https://patch.msgid.link/20260711145246.8625-1-malayarout91@gmail.com
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/power/snapshot.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/kernel/power/snapshot.c b/kernel/power/snapshot.c
index e249e5786fbcd..b691e2a047b57 100644
--- a/kernel/power/snapshot.c
+++ b/kernel/power/snapshot.c
@@ -2798,9 +2798,10 @@ int snapshot_write_next(struct snapshot_handle *handle)
return error;
error = memory_bm_create(&zero_bm, GFP_ATOMIC, PG_ANY);
- if (error)
+ if (error) {
+ memory_bm_free(©_bm, PG_UNSAFE_CLEAR);
return error;
-
+ }
nr_zero_pages = 0;
hibernate_restore_protection_begin();
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0561/1518] leds: pca9532: Fix phantom device registration on missing hardware
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (559 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0560/1518] PM: hibernate: Fix memory leak in snapshot_write_next() error path Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0562/1518] perf cap: Remove used_root parameter and simplify capability checks Greg Kroah-Hartman
` (437 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Cosmo Chou, Bartosz Golaszewski,
Lee Jones, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cosmo Chou <chou.cosmo@gmail.com>
[ Upstream commit 8d6b6c05b8e33d11e3fb3203309385e1a9cceecd ]
The initial PWM and PSC register writes in pca9532_configure() do not
check the return values of i2c_smbus_write_byte_data(). If the I2C
device is physically absent from the bus, the write fails with -ENXIO.
However, the driver ignores this error and allows probe() to complete
successfully.
This results in the registration of phantom LED class devices and
gpiochips backed by non-existent hardware. Subsequent GPIO reads from
these phantom chips return bogus values (due to -ENXIO being truncated
to an unsigned char in pca9532_gpio_get_value()), silently corrupting
hardware state tracking in userspace.
Propagate the I2C write failures back to probe() so the driver core
can gracefully abort binding and release devres-managed resources.
Fixes: e14fa82439d3 ("leds: Add pca9532 led driver")
Signed-off-by: Cosmo Chou <chou.cosmo@gmail.com>
Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Link: https://patch.msgid.link/20260715080747.1638097-1-chou.cosmo@gmail.com
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/leds/leds-pca9532.c | 12 ++++++++----
1 file changed, 8 insertions(+), 4 deletions(-)
diff --git a/drivers/leds/leds-pca9532.c b/drivers/leds/leds-pca9532.c
index 80bf94e699d41..af141dec4b927 100644
--- a/drivers/leds/leds-pca9532.c
+++ b/drivers/leds/leds-pca9532.c
@@ -395,10 +395,14 @@ static int pca9532_configure(struct i2c_client *client,
for (i = 0; i < 2; i++) {
data->pwm[i] = pdata->pwm[i];
data->psc[i] = pdata->psc[i];
- i2c_smbus_write_byte_data(client, PCA9532_REG_PWM(maxleds, i),
- data->pwm[i]);
- i2c_smbus_write_byte_data(client, PCA9532_REG_PSC(maxleds, i),
- data->psc[i]);
+ err = i2c_smbus_write_byte_data(client, PCA9532_REG_PWM(maxleds, i),
+ data->pwm[i]);
+ if (err < 0)
+ return err;
+ err = i2c_smbus_write_byte_data(client, PCA9532_REG_PSC(maxleds, i),
+ data->psc[i]);
+ if (err < 0)
+ return err;
}
data->hw_blink = true;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0562/1518] perf cap: Remove used_root parameter and simplify capability checks
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (560 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0561/1518] leds: pca9532: Fix phantom device registration on missing hardware Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0563/1518] drm/tve200: add OF module alias for autoloading Greg Kroah-Hartman
` (436 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Namhyung Kim, Ian Rogers,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ian Rogers <irogers@google.com>
[ Upstream commit 87ec3437f37b9fe44c524ba967cb12e78de06f15 ]
Refactor perf_cap__capable() to completely remove the used_root out-parameter
as requested by the maintainer. Relying on an explicit used_root boolean
poisoned sequential capability checks (e.g. failing CAP_SYS_ADMIN checks
poisoning the flag for subsequent CAP_PERFMON evaluations for unprivileged
users) and created redundant complexity across check_ftrace_capable(),
symbol__read_kptr_restrict(), and perf_event_paranoid_check().
Streamline the capability API to perform a pure true/false boolean
evaluation. The function checks the Effective set using SYS_capget; if
the syscall is missing or fails on legacy kernels, it cleanly falls back
to checking EUID == 0. This perfectly preserves modern capability-aware host
sessions, guarantees transparent fallback for older kernels, and correctly
rejects privileged operations for containerized root processes that have
explicitly dropped their capability bounding and permitted sets.
Fixes: e25ebda78e23 ("perf cap: Tidy up and improve capability testing")
Suggested-by: Namhyung Kim <namhyung@kernel.org>
Assisted-by: Antigravity:gemini-3.5-flash
Signed-off-by: Ian Rogers <irogers@google.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/builtin-ftrace.c | 13 +++----------
tools/perf/util/bpf-filter.c | 22 +++++++++-------------
tools/perf/util/cap.c | 4 +---
tools/perf/util/cap.h | 3 +--
tools/perf/util/symbol.c | 3 +--
tools/perf/util/util.c | 12 +++---------
6 files changed, 18 insertions(+), 39 deletions(-)
diff --git a/tools/perf/builtin-ftrace.c b/tools/perf/builtin-ftrace.c
index 4cc33452d79b6..d8118256243e2 100644
--- a/tools/perf/builtin-ftrace.c
+++ b/tools/perf/builtin-ftrace.c
@@ -71,18 +71,11 @@ static void ftrace__workload_exec_failed_signal(int signo __maybe_unused,
static bool check_ftrace_capable(void)
{
- bool used_root;
-
- if (perf_cap__capable(CAP_PERFMON, &used_root))
- return true;
-
- if (!used_root && perf_cap__capable(CAP_SYS_ADMIN, &used_root))
+ if (perf_cap__capable(CAP_PERFMON) ||
+ perf_cap__capable(CAP_SYS_ADMIN))
return true;
- pr_err("ftrace only works for %s!\n",
- used_root ? "root"
- : "users with the CAP_PERFMON or CAP_SYS_ADMIN capability"
- );
+ pr_err("ftrace only works for users with the CAP_PERFMON or CAP_SYS_ADMIN capability!\n");
return false;
}
diff --git a/tools/perf/util/bpf-filter.c b/tools/perf/util/bpf-filter.c
index 1a2e7b388d57d..bcd81084e3420 100644
--- a/tools/perf/util/bpf-filter.c
+++ b/tools/perf/util/bpf-filter.c
@@ -629,24 +629,20 @@ struct perf_bpf_filter_expr *perf_bpf_filter_expr__new(enum perf_bpf_filter_term
static bool check_bpf_filter_capable(void)
{
- bool used_root;
+ int fd;
- if (perf_cap__capable(CAP_BPF, &used_root))
+ if (perf_cap__capable(CAP_BPF))
return true;
- if (!used_root) {
- /* Check if root already pinned the filter programs and maps */
- int fd = get_pinned_fd("filters");
-
- if (fd >= 0) {
- close(fd);
- return true;
- }
+ /* Check if root already pinned the filter programs and maps */
+ fd = get_pinned_fd("filters");
+ if (fd >= 0) {
+ close(fd);
+ return true;
}
- pr_err("Error: BPF filter only works for %s!\n"
- "\tPlease run 'perf record --setup-filter pin' as root first.\n",
- used_root ? "root" : "users with the CAP_BPF capability");
+ pr_err("Error: BPF filter only works for users with the CAP_BPF capability!\n"
+ "\tPlease run 'perf record --setup-filter pin' as root first.\n");
return false;
}
diff --git a/tools/perf/util/cap.c b/tools/perf/util/cap.c
index ac6d1d9a523d9..272bd8255ff12 100644
--- a/tools/perf/util/cap.c
+++ b/tools/perf/util/cap.c
@@ -12,7 +12,7 @@
#define MAX_LINUX_CAPABILITY_U32S _LINUX_CAPABILITY_U32S_3
-bool perf_cap__capable(int cap, bool *used_root)
+bool perf_cap__capable(int cap)
{
struct __user_cap_header_struct header = {
.version = _LINUX_CAPABILITY_VERSION_3,
@@ -21,7 +21,6 @@ bool perf_cap__capable(int cap, bool *used_root)
struct __user_cap_data_struct data[MAX_LINUX_CAPABILITY_U32S] = {};
__u32 cap_val;
- *used_root = false;
while (syscall(SYS_capget, &header, &data[0]) == -1) {
/* Retry, first attempt has set the header.version correctly. */
if (errno == EINVAL && header.version != _LINUX_CAPABILITY_VERSION_3 &&
@@ -29,7 +28,6 @@ bool perf_cap__capable(int cap, bool *used_root)
continue;
pr_debug2("capget syscall failed (%m) fall back on root check\n");
- *used_root = true;
return geteuid() == 0;
}
diff --git a/tools/perf/util/cap.h b/tools/perf/util/cap.h
index c1b8ac033ccc5..bf09fb20c7793 100644
--- a/tools/perf/util/cap.h
+++ b/tools/perf/util/cap.h
@@ -18,7 +18,6 @@
#define CAP_BPF 39
#endif
-/* Query if a capability is supported, used_root is set if the fallback root check was used. */
-bool perf_cap__capable(int cap, bool *used_root);
+bool perf_cap__capable(int cap);
#endif /* __PERF_CAP_H */
diff --git a/tools/perf/util/symbol.c b/tools/perf/util/symbol.c
index af0df841d640c..0d4f1f29b3356 100644
--- a/tools/perf/util/symbol.c
+++ b/tools/perf/util/symbol.c
@@ -2326,8 +2326,7 @@ static bool symbol__read_kptr_restrict(void)
{
bool value = false;
FILE *fp = fopen("/proc/sys/kernel/kptr_restrict", "r");
- bool used_root;
- bool cap_syslog = perf_cap__capable(CAP_SYSLOG, &used_root);
+ bool cap_syslog = perf_cap__capable(CAP_SYSLOG);
if (fp != NULL) {
char line[8];
diff --git a/tools/perf/util/util.c b/tools/perf/util/util.c
index 0f031eb80b4c5..452c691991ae1 100644
--- a/tools/perf/util/util.c
+++ b/tools/perf/util/util.c
@@ -331,15 +331,9 @@ int perf_event_paranoid(void)
bool perf_event_paranoid_check(int max_level)
{
- bool used_root;
-
- if (perf_cap__capable(CAP_SYS_ADMIN, &used_root))
- return true;
-
- if (!used_root && perf_cap__capable(CAP_PERFMON, &used_root))
- return true;
-
- return perf_event_paranoid() <= max_level;
+ return perf_cap__capable(CAP_SYS_ADMIN) ||
+ perf_cap__capable(CAP_PERFMON) ||
+ perf_event_paranoid() <= max_level;
}
int perf_tip(char **strp, const char *dirpath)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0563/1518] drm/tve200: add OF module alias for autoloading
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (561 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0562/1518] perf cap: Remove used_root parameter and simplify capability checks Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0564/1518] netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet Greg Kroah-Hartman
` (435 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Can Peng, Linus Walleij, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Can Peng <pengcan@kylinos.cn>
[ Upstream commit b6c3585f2058e0fbfa8cb403458f5cc6cf5c5e06 ]
The TVE200 DRM driver can be built as a module and uses tve200_of_match
as its OF match table, but the table is not exported for module alias
generation.
Add the MODULE_DEVICE_TABLE(of, ...) entry so modpost can generate OF
module aliases for OF based module autoloading.
Fixes: 179c02fe90a4 ("drm/tve200: Add new driver for TVE200")
Signed-off-by: Can Peng <pengcan@kylinos.cn>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260715024130.186416-1-pengcan@kylinos.cn
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/tve200/tve200_drv.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/gpu/drm/tve200/tve200_drv.c b/drivers/gpu/drm/tve200/tve200_drv.c
index a048e37f1c2c1..7d0329292ef6d 100644
--- a/drivers/gpu/drm/tve200/tve200_drv.c
+++ b/drivers/gpu/drm/tve200/tve200_drv.c
@@ -259,6 +259,7 @@ static const struct of_device_id tve200_of_match[] = {
},
{},
};
+MODULE_DEVICE_TABLE(of, tve200_of_match);
static struct platform_driver tve200_driver = {
.driver = {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0564/1518] netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (562 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0563/1518] drm/tve200: add OF module alias for autoloading Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0565/1518] fs/ntfs3: fix out-of-bounds read of INDEX_ROOT in reparse/objid init Greg Kroah-Hartman
` (434 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Florian Westphal, Pablo Neira Ayuso,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Florian Westphal <fw@strlen.de>
[ Upstream commit 16aecbe3036f6097c26b51b12e4c1cf207769690 ]
sashiko says:
If map_addr() changes the packet length, such as when the public NAT IP
string is shorter or longer than the internal IP, coff will still point to
the offset relative to the pre-mangled packet.
If the packet shrinks, coff could overshoot the correct position,
potentially causing the next ct_sip_parse_header_uri() call to silently
skip bytes and miss subsequent Contact headers. Could this lead to a
failure to NAT those subsequent headers and leak internal network details?
Fixes: c978cd3a9371 ("[NETFILTER]: nf_nat_sip: translate all Contact headers")
Assisted-by: Claude:claude-sonnet-4-6
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/netfilter/nf_nat_sip.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/net/netfilter/nf_nat_sip.c b/net/netfilter/nf_nat_sip.c
index a1c41defaf22d..6b00c81084fe2 100644
--- a/net/netfilter/nf_nat_sip.c
+++ b/net/netfilter/nf_nat_sip.c
@@ -267,12 +267,17 @@ static unsigned int nf_nat_sip(struct sk_buff *skb, unsigned int protoff,
SIP_HDR_CONTACT, &in_header,
&matchoff, &matchlen,
&addr, &port) > 0) {
+ int old_len = skb->len, delta;
+
if (!map_addr(skb, protoff, dataoff, dptr, datalen,
matchoff, matchlen,
&addr, port)) {
nf_ct_helper_log(skb, ct, "cannot mangle contact");
return NF_DROP;
}
+
+ delta = (int)skb->len - old_len;
+ coff += delta;
}
if (!map_sip_addr(skb, protoff, dataoff, dptr, datalen, SIP_HDR_FROM) ||
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0565/1518] fs/ntfs3: fix out-of-bounds read of INDEX_ROOT in reparse/objid init
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (563 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0564/1518] netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0566/1518] drm/panthor: return PTR_ERR() from devm_drm_dev_alloc() Greg Kroah-Hartman
` (433 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Xiang Mei, Weiming Wu,
Konstantin Komarov, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Weiming Wu <weiming3@asu.edu>
[ Upstream commit 2064bc663f89e61b8681c1fb9d1ce445de72063d ]
ntfs_reparse_init() and ntfs_objid_init() parse the index root of the
$Extend/$Reparse and $Extend/$ObjId metafiles (the INDEX_ROOT attributes
named $R and $O). They read its type and rule fields through
resident_data(), which does not check that the resident attribute is
large enough to hold them.
mi_enum_attr() accepts a resident attribute with data_off == asize and
data_size == 0. For such an attribute placed last in its MFT record,
resident_data() returns a pointer to the end of the record_size buffer,
so reading root->type / root->rule reads past the allocation.
Use resident_data_ex(attr, sizeof(struct INDEX_ROOT)) and bail out when
it returns NULL, as ntfs_security_init() already does for $SDH / $SII.
The attribute is only parsed while mounting a crafted image, so this
needs CAP_SYS_ADMIN.
BUG: KASAN: slab-out-of-bounds in ntfs_reparse_init (fs/ntfs3/fsntfs.c:2306)
Read of size 4 at addr ffff88801219dc00 by task mount
ntfs_reparse_init (fs/ntfs3/fsntfs.c:2306)
ntfs_fill_super (fs/ntfs3/super.c:1604)
get_tree_bdev_flags (fs/super.c:1703)
vfs_get_tree (fs/super.c:1758)
path_mount (fs/namespace.c:4131)
__x64_sys_mount (fs/namespace.c:4360)
Fixes: 82cae269cfa9 ("fs/ntfs3: Add initialization of super block")
Reported-by: Xiang Mei <xmei5@asu.edu>
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Weiming Wu <weiming3@asu.edu>
Signed-off-by: Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ntfs3/fsntfs.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/fs/ntfs3/fsntfs.c b/fs/ntfs3/fsntfs.c
index 83df92df1ee0c..5e3506815c279 100644
--- a/fs/ntfs3/fsntfs.c
+++ b/fs/ntfs3/fsntfs.c
@@ -2293,8 +2293,8 @@ int ntfs_reparse_init(struct ntfs_sb_info *sbi)
goto out;
}
- root_r = resident_data(attr);
- if (root_r->type != ATTR_ZERO ||
+ root_r = resident_data_ex(attr, sizeof(struct INDEX_ROOT));
+ if (!root_r || root_r->type != ATTR_ZERO ||
root_r->rule != NTFS_COLLATION_TYPE_UINTS) {
err = -EINVAL;
goto out;
@@ -2331,8 +2331,8 @@ int ntfs_objid_init(struct ntfs_sb_info *sbi)
goto out;
}
- root = resident_data(attr);
- if (root->type != ATTR_ZERO ||
+ root = resident_data_ex(attr, sizeof(struct INDEX_ROOT));
+ if (!root || root->type != ATTR_ZERO ||
root->rule != NTFS_COLLATION_TYPE_UINTS) {
err = -EINVAL;
goto out;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0566/1518] drm/panthor: return PTR_ERR() from devm_drm_dev_alloc()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (564 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0565/1518] fs/ntfs3: fix out-of-bounds read of INDEX_ROOT in reparse/objid init Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0567/1518] arm64: dts: rockchip: Add missing hclk for RK3588 eDP0 Greg Kroah-Hartman
` (432 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Osama Abdelkader, Steven Price,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Osama Abdelkader <osama.abdelkader@gmail.com>
[ Upstream commit abc1e559f8e5996eee506dfdc8e3781c2a1e04f9 ]
devm_drm_dev_alloc() returns an ERR_PTR() on failure, but panthor_probe()
always converts that failure to -ENOMEM. Preserve the actual error code
returned by the DRM core instead.
Fixes: 4bdca1150792 ("drm/panthor: Add the driver frontend block")
Signed-off-by: Osama Abdelkader <osama.abdelkader@gmail.com>
Reviewed-by: Steven Price <steven.price@arm.com>
Signed-off-by: Steven Price <steven.price@arm.com>
Link: https://patch.msgid.link/20260716140337.10679-1-osama.abdelkader@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/panthor/panthor_drv.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/panthor/panthor_drv.c b/drivers/gpu/drm/panthor/panthor_drv.c
index 4c202fc5ce050..687fa282b093d 100644
--- a/drivers/gpu/drm/panthor/panthor_drv.c
+++ b/drivers/gpu/drm/panthor/panthor_drv.c
@@ -1630,7 +1630,7 @@ static int panthor_probe(struct platform_device *pdev)
ptdev = devm_drm_dev_alloc(&pdev->dev, &panthor_drm_driver,
struct panthor_device, base);
if (IS_ERR(ptdev))
- return -ENOMEM;
+ return PTR_ERR(ptdev);
platform_set_drvdata(pdev, ptdev);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0567/1518] arm64: dts: rockchip: Add missing hclk for RK3588 eDP0
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (565 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0566/1518] drm/panthor: return PTR_ERR() from devm_drm_dev_alloc() Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0568/1518] arm64: dts: rockchip: Add missing hclk for RK3588 eDP1 Greg Kroah-Hartman
` (431 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Damon Ding, Heiko Stuebner,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Damon Ding <damon.ding@rock-chips.com>
[ Upstream commit ede2ee37f0a445cacbf24760f53befa10f64994a ]
Add the required HCLK_VO1 bus clock to RK3588 eDP0 node with
corresponding clock-name "hclk". This clock is necessary for the
eDP controller to access video output GRF and work properly.
Previously the clock was enabled implicitly via GRF phandle
reference. Add it explicitly now to align with updated binding.
Fixes: dc79d3d5e7c7 ("arm64: dts: rockchip: Add eDP0 node for RK3588")
Signed-off-by: Damon Ding <damon.ding@rock-chips.com>
Link: https://patch.msgid.link/20260605022305.3058853-2-damon.ding@rock-chips.com
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/rockchip/rk3588-base.dtsi | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/arm64/boot/dts/rockchip/rk3588-base.dtsi b/arch/arm64/boot/dts/rockchip/rk3588-base.dtsi
index 7e74e04057cfd..a031f42c558ed 100644
--- a/arch/arm64/boot/dts/rockchip/rk3588-base.dtsi
+++ b/arch/arm64/boot/dts/rockchip/rk3588-base.dtsi
@@ -1648,8 +1648,8 @@ hdmi0_out: port@1 {
edp0: edp@fdec0000 {
compatible = "rockchip,rk3588-edp";
reg = <0x0 0xfdec0000 0x0 0x1000>;
- clocks = <&cru CLK_EDP0_24M>, <&cru PCLK_EDP0>;
- clock-names = "dp", "pclk";
+ clocks = <&cru CLK_EDP0_24M>, <&cru PCLK_EDP0>, <&cru HCLK_VO1>;
+ clock-names = "dp", "pclk", "hclk";
interrupts = <GIC_SPI 163 IRQ_TYPE_LEVEL_HIGH 0>;
phys = <&hdptxphy0>;
phy-names = "dp";
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0568/1518] arm64: dts: rockchip: Add missing hclk for RK3588 eDP1
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (566 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0567/1518] arm64: dts: rockchip: Add missing hclk for RK3588 eDP0 Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0569/1518] arm64: dts: rockchip: Fix Gru WLAN sideband interrupt Greg Kroah-Hartman
` (430 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Damon Ding, Heiko Stuebner,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Damon Ding <damon.ding@rock-chips.com>
[ Upstream commit 09820811c549ee2c408defe36b210b13c7a85fcf ]
Add the required HCLK_VO1 bus clock to RK3588 eDP1 node with
corresponding clock-name "hclk". This clock is necessary for
the eDP controller to access video output GRF and work properly.
Previously the clock was enabled implicitly via GRF phandle
reference. Add it explicitly now to align with updated binding.
Fixes: a481bb0b1ad9 ("arm64: dts: rockchip: Add eDP1 dt node for rk3588")
Signed-off-by: Damon Ding <damon.ding@rock-chips.com>
Link: https://patch.msgid.link/20260605022305.3058853-3-damon.ding@rock-chips.com
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
| 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
--git a/arch/arm64/boot/dts/rockchip/rk3588-extra.dtsi b/arch/arm64/boot/dts/rockchip/rk3588-extra.dtsi
index a2640014ee042..b251bb129cdbf 100644
--- a/arch/arm64/boot/dts/rockchip/rk3588-extra.dtsi
+++ b/arch/arm64/boot/dts/rockchip/rk3588-extra.dtsi
@@ -285,8 +285,8 @@ hdmi1_out: port@1 {
edp1: edp@fded0000 {
compatible = "rockchip,rk3588-edp";
reg = <0x0 0xfded0000 0x0 0x1000>;
- clocks = <&cru CLK_EDP1_24M>, <&cru PCLK_EDP1>;
- clock-names = "dp", "pclk";
+ clocks = <&cru CLK_EDP1_24M>, <&cru PCLK_EDP1>, <&cru HCLK_VO1>;
+ clock-names = "dp", "pclk", "hclk";
interrupts = <GIC_SPI 164 IRQ_TYPE_LEVEL_HIGH 0>;
phys = <&hdptxphy1>;
phy-names = "dp";
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0569/1518] arm64: dts: rockchip: Fix Gru WLAN sideband interrupt
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (567 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0568/1518] arm64: dts: rockchip: Add missing hclk for RK3588 eDP1 Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0570/1518] arm64: dts: rockchip: Fix rk3566-bigtreetech-cb2 touchscreen property Greg Kroah-Hartman
` (429 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Fabio Estevam, Heiko Stuebner,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fabio Estevam <festevam@gmail.com>
[ Upstream commit a761818d9ee11183df0aefd16bf9fe46cc1c4c6d ]
The Marvell WLAN host wake interrupt is wired to GPIO0 8 and is not
one of the PCI INTx interrupts. The PCI device schema therefore
interprets the two-cell GPIO interrupt specifier as an invalid PCI
interrupt and reports dtbs_check warnings:
pcie@0,0: wifi@0,0:interrupts:0:0: 8 is not one of [1, 2, 3, 4]
pcie@0,0: wifi@0,0:interrupts:0: [8, 8] is too long
Describe the sideband interrupt with interrupts-extended, which
explicitly carries the interrupt controller and removes the ambiguity.
Fixes: 48f4d9796d99 ("arm64: dts: rockchip: add Gru/Kevin DTS")
Signed-off-by: Fabio Estevam <festevam@gmail.com>
Link: https://patch.msgid.link/20260721133445.44283-1-festevam@gmail.com
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/rockchip/rk3399-gru-chromebook.dtsi | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/arch/arm64/boot/dts/rockchip/rk3399-gru-chromebook.dtsi b/arch/arm64/boot/dts/rockchip/rk3399-gru-chromebook.dtsi
index 9d07353df52c8..b44668c902b79 100644
--- a/arch/arm64/boot/dts/rockchip/rk3399-gru-chromebook.dtsi
+++ b/arch/arm64/boot/dts/rockchip/rk3399-gru-chromebook.dtsi
@@ -503,8 +503,7 @@ &pci_rootport {
mvl_wifi: wifi@0,0 {
compatible = "pci1b4b,2b42";
reg = <0x0000 0x0 0x0 0x0 0x0>;
- interrupt-parent = <&gpio0>;
- interrupts = <8 IRQ_TYPE_LEVEL_LOW>;
+ interrupts-extended = <&gpio0 8 IRQ_TYPE_LEVEL_LOW>;
pinctrl-names = "default";
pinctrl-0 = <&wlan_host_wake_l>;
wakeup-source;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0570/1518] arm64: dts: rockchip: Fix rk3566-bigtreetech-cb2 touchscreen property
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (568 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0569/1518] arm64: dts: rockchip: Fix Gru WLAN sideband interrupt Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0571/1518] bpf: Fix CFI mismatch in task work callback Greg Kroah-Hartman
` (428 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Fabio Estevam, Heiko Stuebner,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fabio Estevam <festevam@gmail.com>
[ Upstream commit 7707e4555cf1d52689621e3206df8ad2debaa0dd ]
The TSC2007 driver uses the ti,max-rt property to specify the maximum
touch resistance, but the rk3566-bigtreetech-cb2 device tree uses the
undocumented ti,rt-thr property instead.
As a result, the configured value is ignored and the driver falls back
to its default maximum resistance value of 4095.
Replace ti,rt-thr with ti,max-rt to preserve the intended resistance
threshold of 3000.
Fixes: bfbc663d2733 ("arm64: dts: rockchip: Add BigTreeTech CB2 and Pi2")
Signed-off-by: Fabio Estevam <festevam@gmail.com>
Link: https://patch.msgid.link/20260721135450.45286-1-festevam@gmail.com
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/rockchip/rk3566-bigtreetech-cb2.dtsi | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/arm64/boot/dts/rockchip/rk3566-bigtreetech-cb2.dtsi b/arch/arm64/boot/dts/rockchip/rk3566-bigtreetech-cb2.dtsi
index b6cf03a7ba66b..04cf285e6c2af 100644
--- a/arch/arm64/boot/dts/rockchip/rk3566-bigtreetech-cb2.dtsi
+++ b/arch/arm64/boot/dts/rockchip/rk3566-bigtreetech-cb2.dtsi
@@ -569,7 +569,7 @@ tft_tp: touchscreen@48 {
reg = <0x48>;
status = "okay";
ti,x-plate-ohms = <660>;
- ti,rt-thr = <3000>;
+ ti,max-rt = <3000>;
ti,fuzzx = <32>;
ti,fuzzy = <16>;
};
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0571/1518] bpf: Fix CFI mismatch in task work callback
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (569 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0570/1518] arm64: dts: rockchip: Fix rk3566-bigtreetech-cb2 touchscreen property Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0572/1518] ARM: lpc32xx: only run SoC init on LPC32xx hardware Greg Kroah-Hartman
` (427 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mykyta Yatsenko,
Kumar Kartikeya Dwivedi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mykyta Yatsenko <yatsenko@meta.com>
[ Upstream commit 2805abd089576799b15092949420e3f8ba97fabd ]
BPF subprograms use the bpf_callback_t ABI, but task work invokes the
callback through a three-argument function pointer. This trips kCFI.
Store and invoke the callback as bpf_callback_t.
Fixes: 38aa7003e369 ("bpf: task work scheduling kfuncs")
Signed-off-by: Mykyta Yatsenko <yatsenko@meta.com>
Link: https://lore.kernel.org/bpf/20260724-task_work_cfi-v1-1-2616691781ed@meta.com
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/helpers.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
diff --git a/kernel/bpf/helpers.c b/kernel/bpf/helpers.c
index 5aed5659822f1..72757f7290ec2 100644
--- a/kernel/bpf/helpers.c
+++ b/kernel/bpf/helpers.c
@@ -3960,7 +3960,7 @@ struct bpf_task_work_ctx {
struct bpf_map *map;
void *map_val;
enum task_work_notify_mode mode;
- bpf_task_work_callback_t callback_fn;
+ bpf_callback_t callback_fn;
struct rcu_head rcu;
} __aligned(8);
@@ -4035,7 +4035,8 @@ static void bpf_task_work_callback(struct callback_head *cb)
key = (void *)map_key_from_value(ctx->map, ctx->map_val, &idx);
migrate_disable();
- ctx->callback_fn(ctx->map, key, ctx->map_val);
+ ctx->callback_fn((u64)(long)ctx->map, (u64)(long)key,
+ (u64)(long)ctx->map_val, 0, 0);
migrate_enable();
bpf_task_work_ctx_reset(ctx);
@@ -4148,7 +4149,7 @@ static struct bpf_task_work_ctx *bpf_task_work_acquire_ctx(struct bpf_task_work
}
static int bpf_task_work_schedule(struct task_struct *task, struct bpf_task_work *tw,
- struct bpf_map *map, bpf_task_work_callback_t callback_fn,
+ struct bpf_map *map, void *callback_fn,
struct bpf_prog_aux *aux, enum task_work_notify_mode mode)
{
struct bpf_prog *prog;
@@ -4173,7 +4174,7 @@ static int bpf_task_work_schedule(struct task_struct *task, struct bpf_task_work
}
ctx->task = task;
- ctx->callback_fn = callback_fn;
+ ctx->callback_fn = (bpf_callback_t)callback_fn;
ctx->prog = prog;
ctx->mode = mode;
ctx->map = map;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0572/1518] ARM: lpc32xx: only run SoC init on LPC32xx hardware
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (570 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0571/1518] bpf: Fix CFI mismatch in task work callback Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0573/1518] selftests/bpf: Fix incorrect error checking for pthread_create Greg Kroah-Hartman
` (426 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Arnd Bergmann, Karl Mehltretter,
Vladimir Zapolskiy, Vladimir Zapolskiy, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 717ea4000867e6dffee5e1ed92150a9704ae9f68 ]
lpc32xx_check_uid() and lpc32xx_pm_init() are arch_initcalls that poke
LPC32xx-only registers. Since the multiplatform conversion they also
run on other ARCH_MULTI_V5 boards where access faults e.g. on versatile:
Unable to handle kernel paging request at virtual address f4004130
PC is at lpc32xx_check_uid+0x2c/0x9c
Drop the arch_initcall() registrations and call both functions directly
from lpc3250_machine_init(), the machine's .init_machine hook.
The calls are placed in link order (common.c, pm.c, phy3250.c) to
keep their previous relative ordering.
Fixes: 75bf1bd7d2f9 ("ARM: lpc32xx: allow multiplatform build")
Suggested-by: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Reviewed-by: Vladimir Zapolskiy <vz@kernel.org>
Reviewed-by: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Vladimir Zapolskiy <vz@mleia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm/mach-lpc32xx/common.c | 5 +----
arch/arm/mach-lpc32xx/common.h | 2 ++
arch/arm/mach-lpc32xx/phy3250.c | 2 ++
arch/arm/mach-lpc32xx/pm.c | 5 +----
4 files changed, 6 insertions(+), 8 deletions(-)
diff --git a/arch/arm/mach-lpc32xx/common.c b/arch/arm/mach-lpc32xx/common.c
index 304ea61a07160..35ed3569c5a35 100644
--- a/arch/arm/mach-lpc32xx/common.c
+++ b/arch/arm/mach-lpc32xx/common.c
@@ -106,7 +106,7 @@ void __init lpc32xx_map_io(void)
iotable_init(lpc32xx_io_desc, ARRAY_SIZE(lpc32xx_io_desc));
}
-static int __init lpc32xx_check_uid(void)
+void __init lpc32xx_check_uid(void)
{
u32 uid[4];
@@ -119,7 +119,4 @@ static int __init lpc32xx_check_uid(void)
system_serial_low = uid[0];
system_serial_high = uid[1];
}
-
- return 1;
}
-arch_initcall(lpc32xx_check_uid);
diff --git a/arch/arm/mach-lpc32xx/common.h b/arch/arm/mach-lpc32xx/common.h
index 32f0ad2178077..06b20bea324e1 100644
--- a/arch/arm/mach-lpc32xx/common.h
+++ b/arch/arm/mach-lpc32xx/common.h
@@ -16,6 +16,8 @@
* Other arch specific structures and functions
*/
extern void __init lpc32xx_map_io(void);
+extern void __init lpc32xx_check_uid(void);
+extern void __init lpc32xx_pm_init(void);
extern void __init lpc32xx_serial_init(void);
/*
diff --git a/arch/arm/mach-lpc32xx/phy3250.c b/arch/arm/mach-lpc32xx/phy3250.c
index 66701bf432488..ddc6333ca55da 100644
--- a/arch/arm/mach-lpc32xx/phy3250.c
+++ b/arch/arm/mach-lpc32xx/phy3250.c
@@ -71,6 +71,8 @@ static const struct of_dev_auxdata lpc32xx_auxdata_lookup[] __initconst = {
static void __init lpc3250_machine_init(void)
{
+ lpc32xx_check_uid();
+ lpc32xx_pm_init();
lpc32xx_serial_init();
of_platform_default_populate(NULL, lpc32xx_auxdata_lookup, NULL);
diff --git a/arch/arm/mach-lpc32xx/pm.c b/arch/arm/mach-lpc32xx/pm.c
index 2572bd89a5e8d..9b5c5e1462ed3 100644
--- a/arch/arm/mach-lpc32xx/pm.c
+++ b/arch/arm/mach-lpc32xx/pm.c
@@ -120,7 +120,7 @@ static const struct platform_suspend_ops lpc32xx_pm_ops = {
#define EMC_DYN_MEM_CTRL_OFS 0x20
#define EMC_SRMMC (1 << 3)
#define EMC_CTRL_REG io_p2v(LPC32XX_EMC_BASE + EMC_DYN_MEM_CTRL_OFS)
-static int __init lpc32xx_pm_init(void)
+void __init lpc32xx_pm_init(void)
{
/*
* Setup SDRAM self-refresh clock to automatically disable o
@@ -129,7 +129,4 @@ static int __init lpc32xx_pm_init(void)
__raw_writel(__raw_readl(EMC_CTRL_REG) | EMC_SRMMC, EMC_CTRL_REG);
suspend_set_ops(&lpc32xx_pm_ops);
-
- return 0;
}
-arch_initcall(lpc32xx_pm_init);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0573/1518] selftests/bpf: Fix incorrect error checking for pthread_create
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (571 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0572/1518] ARM: lpc32xx: only run SoC init on LPC32xx hardware Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0574/1518] selftests/bpf: Fix memory leak on subtest_states reallocation Greg Kroah-Hartman
` (425 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Feng Yang, Kumar Kartikeya Dwivedi,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Feng Yang <yangfeng@kylinos.cn>
[ Upstream commit b04b8d4e198aefc863e7b702ececb957845b0c25 ]
pthread_create returns 0 on success and a positive error code on failure;
it never returns a negative value. The current conditional branch can never be taken.
Failures during thread creation are silently ignored, which will lead to
invalid memory access when waiting on threads or dereferencing thread handles later.
Fixes: 91b2c0afd00c ("selftests/bpf: Add parallelism to test_progs")
Signed-off-by: Feng Yang <yangfeng@kylinos.cn>
Link: https://lore.kernel.org/bpf/20260723085100.482147-3-yangfeng59949@163.com
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/bpf/test_progs.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/testing/selftests/bpf/test_progs.c b/tools/testing/selftests/bpf/test_progs.c
index 02a85dda30e64..082f05f341e58 100644
--- a/tools/testing/selftests/bpf/test_progs.c
+++ b/tools/testing/selftests/bpf/test_progs.c
@@ -1690,7 +1690,7 @@ static void server_main(void)
data[i].worker_id = i;
data[i].sock_fd = env.worker_socks[i];
rc = pthread_create(&dispatcher_threads[i], NULL, dispatch_thread, &data[i]);
- if (rc < 0) {
+ if (rc) {
perror("Failed to launch dispatcher thread");
exit(EXIT_ERR_SETUP_INFRA);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0574/1518] selftests/bpf: Fix memory leak on subtest_states reallocation
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (572 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0573/1518] selftests/bpf: Fix incorrect error checking for pthread_create Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0575/1518] cxl/region: Fix use-after-free in find_pos_and_ways() error path Greg Kroah-Hartman
` (424 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Feng Yang, Kumar Kartikeya Dwivedi,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Feng Yang <yangfeng@kylinos.cn>
[ Upstream commit 06efb01c6530e9cfc247178cb96aa8adb3beaf61 ]
Fix memory leak in subtest_states reallocation,
and revert subtest_num if allocation fails.
Fixes: 0925225956bb ("bpf/selftests: Add granular subtest output for prog_test")
Signed-off-by: Feng Yang <yangfeng@kylinos.cn>
Link: https://lore.kernel.org/bpf/20260723085100.482147-6-yangfeng59949@163.com
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/bpf/test_progs.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
diff --git a/tools/testing/selftests/bpf/test_progs.c b/tools/testing/selftests/bpf/test_progs.c
index 082f05f341e58..eda3fcf72095f 100644
--- a/tools/testing/selftests/bpf/test_progs.c
+++ b/tools/testing/selftests/bpf/test_progs.c
@@ -550,18 +550,19 @@ bool test__start_subtest(const char *subtest_name)
struct test_state *state = env.test_state;
struct subtest_state *subtest_state;
size_t sub_state_size = sizeof(*subtest_state);
+ void *tmp;
if (env.subtest_state)
test__end_subtest();
state->subtest_num++;
- state->subtest_states =
- realloc(state->subtest_states,
- state->subtest_num * sub_state_size);
- if (!state->subtest_states) {
+ tmp = realloc(state->subtest_states, state->subtest_num * sub_state_size);
+ if (!tmp) {
+ state->subtest_num--;
fprintf(stderr, "Not enough memory to allocate subtest result\n");
return false;
}
+ state->subtest_states = tmp;
subtest_state = &state->subtest_states[state->subtest_num - 1];
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0575/1518] cxl/region: Fix use-after-free in find_pos_and_ways() error path
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (573 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0574/1518] selftests/bpf: Fix memory leak on subtest_states reallocation Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0576/1518] pinctrl: mediatek: free EINT resources on unbind Greg Kroah-Hartman
` (423 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Li Ming, Jonathan Cameron,
Alison Schofield, Dave Jiang, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alison Schofield <alison.schofield@intel.com>
[ Upstream commit 15da704b732332cc1e8f121f624e5e6c05124c5d ]
The error path releases its reference to a switch decoder before
logging an error that includes the decoder name. If the released
reference is the last one, the decoder can be freed before the error
message accesses its name.
Drop the reference after the error is reported.
Fixes: d90acdf49e18 ("cxl/region: Add a dev_err() on missing target list entries")
Reviewed-by: Li Ming <ming.li@zohomail.com>
Reviewed-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Alison Schofield <alison.schofield@intel.com>
Link: https://patch.msgid.link/10deb519b543ef693ce23148b509a03fe1c07d0c.1784931354.git.alison.schofield@intel.com
Signed-off-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/cxl/core/region.c | 7 +++----
1 file changed, 3 insertions(+), 4 deletions(-)
diff --git a/drivers/cxl/core/region.c b/drivers/cxl/core/region.c
index a1141471b4586..d518d463b28c4 100644
--- a/drivers/cxl/core/region.c
+++ b/drivers/cxl/core/region.c
@@ -1815,14 +1815,13 @@ static int find_pos_and_ways(struct cxl_port *port, struct range *range,
break;
}
}
- put_device(dev);
-
if (rc)
dev_err(port->uport_dev,
"failed to find %s:%s in target list of %s\n",
dev_name(&port->dev),
- dev_name(port->parent_dport->dport_dev),
- dev_name(&cxlsd->cxld.dev));
+ dev_name(port->parent_dport->dport_dev), dev_name(dev));
+
+ put_device(dev);
return rc;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0576/1518] pinctrl: mediatek: free EINT resources on unbind
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (574 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0575/1518] cxl/region: Fix use-after-free in find_pos_and_ways() error path Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0577/1518] tools/build: Allow versioning of all LLVM tools defined in Makefile.include Greg Kroah-Hartman
` (422 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Justin Yeh,
AngeloGioacchino Del Regno, Linus Walleij, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Justin Yeh <justin.yeh@mediatek.com>
[ Upstream commit 88292b7103d260e3e606eb3bb2794060a5fde48e ]
mtk_eint_do_init() creates an IRQ domain, populates it with a mapping for
every EINT line and installs a chained handler on the parent interrupt,
but none of these are ever released. This was harmless while the drivers
were built-in, but now that they can be built as modules and
unbound/rmmod'd it leaves behind a dangling IRQ domain, interrupt mappings
whose chip data points at freed memory, and a chained handler that keeps
firing into that freed data.
The plain allocations in mtk_eint_do_init() already use the device-managed
devm_*() helpers, so tear the remaining resources down the same way:
register a devm action that detaches the chained handler, waits for any
in-flight handler to finish, disposes of the per-line mappings and removes
the IRQ domain. This mirrors the device-managed lifecycle adopted for the
GPIO chip and keeps the whole EINT setup self-cleaning on unbind.
Fixes: e46df235b4e6 ("pinctrl: mediatek: refactor EINT related code for all MediaTek pinctrl can fit")
Signed-off-by: Justin Yeh <justin.yeh@mediatek.com>
Reviewed-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pinctrl/mediatek/mtk-eint.c | 25 ++++++++++++++++++++++++-
1 file changed, 24 insertions(+), 1 deletion(-)
diff --git a/drivers/pinctrl/mediatek/mtk-eint.c b/drivers/pinctrl/mediatek/mtk-eint.c
index 5f12af59a91b5..df99401c0b7d7 100644
--- a/drivers/pinctrl/mediatek/mtk-eint.c
+++ b/drivers/pinctrl/mediatek/mtk-eint.c
@@ -12,8 +12,10 @@
*/
#include <linux/delay.h>
+#include <linux/device.h>
#include <linux/err.h>
#include <linux/gpio/driver.h>
+#include <linux/interrupt.h>
#include <linux/io.h>
#include <linux/irqchip/chained_irq.h>
#include <linux/irqdomain.h>
@@ -504,6 +506,27 @@ int mtk_eint_find_irq(struct mtk_eint *eint, unsigned long eint_n)
}
EXPORT_SYMBOL_GPL(mtk_eint_find_irq);
+static void mtk_eint_teardown(void *data)
+{
+ struct mtk_eint *eint = data;
+ unsigned int i, virq;
+
+ /* Detach the demux handler so it can no longer reference freed data. */
+ irq_set_chained_handler_and_data(eint->irq, NULL, NULL);
+
+ /* Wait for any in-flight handler to finish before tearing down. */
+ synchronize_irq(eint->irq);
+
+ /* Dispose of all child mappings before the domain is removed. */
+ for (i = 0; i < eint->hw->ap_num; i++) {
+ virq = irq_find_mapping(eint->domain, i);
+ if (virq)
+ irq_dispose_mapping(virq);
+ }
+
+ irq_domain_remove(eint->domain);
+}
+
int mtk_eint_do_init(struct mtk_eint *eint, struct mtk_eint_pin *eint_pin)
{
unsigned int size, i, port, virq, inst = 0;
@@ -596,7 +619,7 @@ int mtk_eint_do_init(struct mtk_eint *eint, struct mtk_eint_pin *eint_pin)
irq_set_chained_handler_and_data(eint->irq, mtk_eint_irq_handler,
eint);
- return 0;
+ return devm_add_action_or_reset(eint->dev, mtk_eint_teardown, eint);
err_eint:
for (i = 0; i < eint->nbase; i++) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0577/1518] tools/build: Allow versioning of all LLVM tools defined in Makefile.include
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (575 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0576/1518] pinctrl: mediatek: free EINT resources on unbind Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0578/1518] arm64: RSI: fix field-spanning write warning in attestation token init Greg Kroah-Hartman
` (421 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, James Clark, Ian Rogers,
Kumar Kartikeya Dwivedi, Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: James Clark <james.clark@linaro.org>
[ Upstream commit d5a1d1270c898057afc5b51fb6d0f2defa89d56d ]
The version of LLVM tools can be given on the build command with
LLVM=-15, but this isn't applied to all tools. For example $(CC) gets
versioned, but $(CLANG) doesn't. This causes a Perf build with LTO=1 to
fail with an error about mixed clang versions:
ld.lld: error: libperf/core.o: Unknown attribute kind (86)
(Producer: 'LLVM18.1.8' Reader: 'LLVM 15.0.7')
This file has two "ifneq ($(LLVM),)" blocks adjacent to each other, so
merge these blocks making it obvious that all tools should be versioned
consistently and there is nothing special about each block.
This also reveals that ?= and "allow-override" are used inconsistently
between the blocks. "allow-override" is technically only required for
builtin variables, but isn't only used on them, and doesn't do any harm
if used on a non-builtin. Make them all "allow-override" for
consistency. The only functional difference this will cause is if there
is a file level definition of one of the variables followed by an
"#include of Makefile.include" which will now overwrite. But this isn't
done and in a later commit some of the duplicate definitions will be
removed for good measure.
There are also some other LLVM tools that are not defined here and will
be moved in a later commit.
Signed-off-by: James Clark <james.clark@linaro.org>
Reviewed-by: Ian Rogers <irogers@google.com>
Acked-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Fixes: e9c281928c24 ("kbuild: Make $(LLVM) more flexible")
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/scripts/Makefile.include | 37 ++++++++++++++++++----------------
1 file changed, 20 insertions(+), 17 deletions(-)
diff --git a/tools/scripts/Makefile.include b/tools/scripts/Makefile.include
index ded48263dd5e0..c5bb7bf42f430 100644
--- a/tools/scripts/Makefile.include
+++ b/tools/scripts/Makefile.include
@@ -59,10 +59,18 @@ LLVM_SUFFIX := $(LLVM)
endif
$(call allow-override,CC,$(LLVM_PREFIX)clang$(LLVM_SUFFIX))
+$(call allow-override,CLANG,$(LLVM_PREFIX)clang$(LLVM_SUFFIX))
+$(call allow-override,HOSTCC,$(LLVM_PREFIX)clang$(LLVM_SUFFIX))
$(call allow-override,AR,$(LLVM_PREFIX)llvm-ar$(LLVM_SUFFIX))
+$(call allow-override,HOSTAR,$(LLVM_PREFIX)llvm-ar$(LLVM_SUFFIX))
$(call allow-override,LD,$(LLVM_PREFIX)ld.lld$(LLVM_SUFFIX))
+$(call allow-override,HOSTLD,$(LLVM_PREFIX)ld.lld$(LLVM_SUFFIX))
$(call allow-override,CXX,$(LLVM_PREFIX)clang++$(LLVM_SUFFIX))
$(call allow-override,STRIP,$(LLVM_PREFIX)llvm-strip$(LLVM_SUFFIX))
+$(call allow-override,LLVM_STRIP,$(LLVM_PREFIX)llvm-strip$(LLVM_SUFFIX))
+$(call allow-override,LLC,$(LLVM_PREFIX)llc$(LLVM_SUFFIX))
+$(call allow-override,LLVM_CONFIG,$(LLVM_PREFIX)llvm-config$(LLVM_SUFFIX))
+$(call allow-override,LLVM_OBJCOPY,$(LLVM_PREFIX)llvm-objcopy$(LLVM_SUFFIX))
else
# Allow setting various cross-compile vars or setting CROSS_COMPILE as a prefix.
$(call allow-override,CC,$(CROSS_COMPILE)gcc)
@@ -70,26 +78,21 @@ $(call allow-override,AR,$(CROSS_COMPILE)ar)
$(call allow-override,LD,$(CROSS_COMPILE)ld)
$(call allow-override,CXX,$(CROSS_COMPILE)g++)
$(call allow-override,STRIP,$(CROSS_COMPILE)strip)
-endif
-
-CC_NO_CLANG := $(shell $(CC) -dM -E -x c /dev/null | grep -Fq "__clang__"; echo $$?)
-ifneq ($(LLVM),)
-HOSTAR ?= $(LLVM_PREFIX)llvm-ar$(LLVM_SUFFIX)
-HOSTCC ?= $(LLVM_PREFIX)clang$(LLVM_SUFFIX)
-HOSTLD ?= $(LLVM_PREFIX)ld.lld$(LLVM_SUFFIX)
-else
-HOSTAR ?= ar
-HOSTCC ?= gcc
-HOSTLD ?= ld
+# Host versions aren't prefixed
+$(call allow-override,HOSTAR,ar)
+$(call allow-override,HOSTCC,gcc)
+$(call allow-override,HOSTLD,ld)
+
+# Some tools still require Clang, LLC and/or LLVM utils
+$(call allow-override,CLANG,clang)
+$(call allow-override,LLC,llc)
+$(call allow-override,LLVM_CONFIG,llvm-config)
+$(call allow-override,LLVM_OBJCOPY,llvm-objcopy)
+$(call allow-override,LLVM_STRIP,llvm-strip)
endif
-# Some tools require Clang, LLC and/or LLVM utils
-CLANG ?= clang
-LLC ?= llc
-LLVM_CONFIG ?= llvm-config
-LLVM_OBJCOPY ?= llvm-objcopy
-LLVM_STRIP ?= llvm-strip
+CC_NO_CLANG := $(shell $(CC) -dM -E -x c /dev/null | grep -Fq "__clang__"; echo $$?)
# Some tools require bpftool
SYSTEM_BPFTOOL ?= bpftool
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0578/1518] arm64: RSI: fix field-spanning write warning in attestation token init
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (576 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0577/1518] tools/build: Allow versioning of all LLVM tools defined in Makefile.include Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0579/1518] power: supply: sbs-battery: Use a per-device serial number buffer Greg Kroah-Hartman
` (420 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Kohei Enju, Will Deacon, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kohei Enju <enju.kohei@fujitsu.com>
[ Upstream commit 221049874b6a78c7d87bc826581b0695cd338e2b ]
The challenge is passed in registers a1 through a8. However, copying to
®s.a1 makes FORTIFY treat the destination as the single a1 field,
resulting in a field-spanning write warning. [1]
Overlay the SMCCC register structure with an RSI-specific argument
layout and copy the challenge into an explicit 64-byte array. This keeps
the existing a1-a8 argument encoding while giving the copy a correctly
sized destination object.
[1]
memcpy: detected field-spanning write (size 64) of single field "®s.a1" at ./arch/arm64/include/asm/rsi_cmds.h:119 (size 8)
WARNING: ./arch/arm64/include/asm/rsi_cmds.h:119 at rsi_attestation_token_init+0xdc/0xf8 [arm_cca_guest], CPU#0: cat/3314
Fixes: b880a80011f5 ("arm64: rsi: Add RSI definitions")
Signed-off-by: Kohei Enju <enju.kohei@fujitsu.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/include/asm/rsi_cmds.h | 27 +++++++++++++++++++--------
1 file changed, 19 insertions(+), 8 deletions(-)
diff --git a/arch/arm64/include/asm/rsi_cmds.h b/arch/arm64/include/asm/rsi_cmds.h
index 2c8763876dfb7..c1fab41f671ec 100644
--- a/arch/arm64/include/asm/rsi_cmds.h
+++ b/arch/arm64/include/asm/rsi_cmds.h
@@ -88,6 +88,14 @@ static inline long rsi_set_addr_range_state(phys_addr_t start,
return res.a0;
}
+#define RSI_ATTEST_CHALLENGE_MIN_SIZE 32
+#define RSI_ATTEST_CHALLENGE_MAX_SIZE 64
+
+struct rsi_attestation_token_init_args {
+ unsigned long fid;
+ u8 challenge[RSI_ATTEST_CHALLENGE_MAX_SIZE];
+};
+
/**
* rsi_attestation_token_init - Initialise the operation to retrieve an
* attestation token.
@@ -109,18 +117,21 @@ static inline long rsi_set_addr_range_state(phys_addr_t start,
static inline long
rsi_attestation_token_init(const u8 *challenge, unsigned long size)
{
- struct arm_smccc_1_2_regs regs = { 0 };
+ union {
+ struct arm_smccc_1_2_regs regs;
+ struct rsi_attestation_token_init_args init;
+ } args = { 0 };
- /* The challenge must be at least 32bytes and at most 64bytes */
- if (!challenge || size < 32 || size > 64)
+ if (!challenge || size < RSI_ATTEST_CHALLENGE_MIN_SIZE ||
+ size > RSI_ATTEST_CHALLENGE_MAX_SIZE)
return -EINVAL;
- regs.a0 = SMC_RSI_ATTESTATION_TOKEN_INIT;
- memcpy(®s.a1, challenge, size);
- arm_smccc_1_2_smc(®s, ®s);
+ args.init.fid = SMC_RSI_ATTESTATION_TOKEN_INIT;
+ memcpy(args.init.challenge, challenge, size);
+ arm_smccc_1_2_smc(&args.regs, &args.regs);
- if (regs.a0 == RSI_SUCCESS)
- return regs.a1;
+ if (args.regs.a0 == RSI_SUCCESS)
+ return args.regs.a1;
return -EINVAL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0579/1518] power: supply: sbs-battery: Use a per-device serial number buffer
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (577 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0578/1518] arm64: RSI: fix field-spanning write warning in attestation token init Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0580/1518] scsi: ufs: debugfs: Reserve space for a string terminator Greg Kroah-Hartman
` (419 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Babanpreet Singh, Sebastian Reichel,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Babanpreet Singh <bbnpreetsingh@gmail.com>
[ Upstream commit 6027892925b8d19d2245c2d077e2ae35b49cc2b1 ]
sbs_get_battery_serial_number() formats the battery serial number into
sbs_serial[], a single file-scope buffer shared by every sbs-battery
instance, and points val->strval at it.
Nothing restricts this driver to one instance. It binds per I2C client,
and sbs-manager registers one muxed I2C channel per supported battery
specifically so that the smart battery driver can be bound to each of
them, so several sbs-battery instances on one system is a supported
configuration.
The power supply core reads strval after the driver's get_property()
callback has returned: power_supply_show_property() fills a local
union power_supply_propval, then formats it with sysfs_emit(). Two
concurrent POWER_SUPPLY_PROP_SERIAL_NUMBER reads on different batteries
therefore race for the shared buffer - battery B's sprintf() can land
between battery A filling the buffer and the core reading it, and
battery A then reports battery B's serial number.
Move the buffer into struct sbs_info so that each battery formats into
its own storage. It is deliberately not added to the chip->strings[]
array: those entries hold the cached constant strings that
sbs_invalidate_cached_props() clears on presence changes, whereas the
serial number is re-read from its word register on every access.
Fixes: d3ab61ecbab2 ("bq20z75: Add support for more power supply properties")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Babanpreet Singh <bbnpreetsingh@gmail.com>
Link: https://patch.msgid.link/20260726072206.7-2-bbnpreetsingh@gmail.com
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/power/supply/sbs-battery.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/drivers/power/supply/sbs-battery.c b/drivers/power/supply/sbs-battery.c
index 43c48196c1674..3947429f6f819 100644
--- a/drivers/power/supply/sbs-battery.c
+++ b/drivers/power/supply/sbs-battery.c
@@ -217,6 +217,7 @@ struct sbs_info {
u32 flags;
int technology;
char strings[NR_STRING_BUFFERS][I2C_SMBUS_BLOCK_MAX + 1];
+ char serial[5];
};
static char *sbs_get_string_buf(struct sbs_info *chip,
@@ -821,18 +822,18 @@ static int sbs_get_battery_capacity(struct i2c_client *client,
return 0;
}
-static char sbs_serial[5];
static int sbs_get_battery_serial_number(struct i2c_client *client,
union power_supply_propval *val)
{
+ struct sbs_info *chip = i2c_get_clientdata(client);
int ret;
ret = sbs_read_word_data(client, sbs_data[REG_SERIAL_NUMBER].addr);
if (ret < 0)
return ret;
- sprintf(sbs_serial, "%04x", ret);
- val->strval = sbs_serial;
+ sprintf(chip->serial, "%04x", ret);
+ val->strval = chip->serial;
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0580/1518] scsi: ufs: debugfs: Reserve space for a string terminator
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (578 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0579/1518] power: supply: sbs-battery: Use a per-device serial number buffer Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0581/1518] crypto: keembay - Initialize completion before requesting IRQ Greg Kroah-Hartman
` (418 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Li Qiang, Bart Van Assche,
Peter Wang, Martin K. Petersen, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Li Qiang <liqiang01@kylinos.cn>
[ Upstream commit abd26e6b53c4169122d61fdd4cabe09bdd916aac ]
ufs_saved_err_write() copies user input into a zero-initialized stack
buffer and passes it to kstrtoint(). A write that fills the entire buffer
overwrites its only terminator.
Reject an input whose length leaves no room for the trailing NUL.
Fixes: 7340faae9474 ("scsi: ufs: core: Add debugfs attributes for triggering the UFS EH")
Signed-off-by: Li Qiang <liqiang01@kylinos.cn>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Reviewed-by: Peter Wang <peter.wang@mediatek.com>
Link: https://patch.msgid.link/20260717153914.26321-7-liqiang01@kylinos.cn
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/ufs/core/ufs-debugfs.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/ufs/core/ufs-debugfs.c b/drivers/ufs/core/ufs-debugfs.c
index e3baed6c70bd9..6dece24baad15 100644
--- a/drivers/ufs/core/ufs-debugfs.c
+++ b/drivers/ufs/core/ufs-debugfs.c
@@ -165,7 +165,7 @@ static ssize_t ufs_saved_err_write(struct file *file, const char __user *buf,
char val_str[16] = { };
int val, ret;
- if (count > sizeof(val_str))
+ if (count >= sizeof(val_str))
return -EINVAL;
if (copy_from_user(val_str, buf, count))
return -EFAULT;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0581/1518] crypto: keembay - Initialize completion before requesting IRQ
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (579 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0580/1518] scsi: ufs: debugfs: Reserve space for a string terminator Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0582/1518] crypto: keembay - publish OF module alias for OCS AES/SM4 Greg Kroah-Hartman
` (417 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Linmao Li, Herbert Xu, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linmao Li <lilinmao@kylinos.cn>
[ Upstream commit fce20289dd622cc7ab78d72c8a979a9f8b7cb10e ]
kmb_ocs_aes_probe() requests the device IRQ before initializing
irq_completion. Once the handler is registered it can run immediately,
and ocs_aes_irq_handler() unconditionally calls complete(). An
interrupt in this window would therefore use an uninitialized
completion.
Initialize the completion before requesting the IRQ, as the sibling
OCS HCU and ECC drivers already do.
Fixes: 885743324513 ("crypto: keembay - Add support for Keem Bay OCS AES/SM4")
Signed-off-by: Linmao Li <lilinmao@kylinos.cn>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/crypto/intel/keembay/keembay-ocs-aes-core.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/crypto/intel/keembay/keembay-ocs-aes-core.c b/drivers/crypto/intel/keembay/keembay-ocs-aes-core.c
index 0e424024224e5..460a943cca227 100644
--- a/drivers/crypto/intel/keembay/keembay-ocs-aes-core.c
+++ b/drivers/crypto/intel/keembay/keembay-ocs-aes-core.c
@@ -1602,6 +1602,8 @@ static int kmb_ocs_aes_probe(struct platform_device *pdev)
if (IS_ERR(aes_dev->base_reg))
return PTR_ERR(aes_dev->base_reg);
+ init_completion(&aes_dev->irq_completion);
+
/* Get and request IRQ */
aes_dev->irq = platform_get_irq(pdev, 0);
if (aes_dev->irq < 0)
@@ -1619,8 +1621,6 @@ static int kmb_ocs_aes_probe(struct platform_device *pdev)
list_add_tail(&aes_dev->list, &ocs_aes.dev_list);
spin_unlock(&ocs_aes.lock);
- init_completion(&aes_dev->irq_completion);
-
/* Initialize crypto engine */
aes_dev->engine = crypto_engine_alloc_init(dev, true);
if (!aes_dev->engine) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0582/1518] crypto: keembay - publish OF module alias for OCS AES/SM4
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (580 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0581/1518] crypto: keembay - Initialize completion before requesting IRQ Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0583/1518] RDMA/mlx5: Fix integer overflow of user QP buffer size Greg Kroah-Hartman
` (416 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Can Peng, Herbert Xu, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Can Peng <pengcan@kylinos.cn>
[ Upstream commit 0a94091e29f914e4f233a208599ca4055882c01b ]
The Keem Bay OCS AES/SM4 driver has an OF match table wired to
.of_match_table, but does not export the table with MODULE_DEVICE_TABLE().
Although the match table lives in keembay-ocs-aes-core.o, that object is
part of the composite keembay-ocs-aes module. Add the missing
MODULE_DEVICE_TABLE(of, ...) entry so modpost can generate OF module alias
information for OF based module autoloading.
This is a source-level fix. It does not claim dynamic hardware
reproduction; the evidence is the driver-owned match table, its use by the
platform driver, and the missing module alias publication.
Fixes: 885743324513 ("crypto: keembay - Add support for Keem Bay OCS AES/SM4")
Signed-off-by: Can Peng <pengcan@kylinos.cn>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/crypto/intel/keembay/keembay-ocs-aes-core.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/crypto/intel/keembay/keembay-ocs-aes-core.c b/drivers/crypto/intel/keembay/keembay-ocs-aes-core.c
index 460a943cca227..419f88af1031b 100644
--- a/drivers/crypto/intel/keembay/keembay-ocs-aes-core.c
+++ b/drivers/crypto/intel/keembay/keembay-ocs-aes-core.c
@@ -1561,6 +1561,7 @@ static const struct of_device_id kmb_ocs_aes_of_match[] = {
},
{}
};
+MODULE_DEVICE_TABLE(of, kmb_ocs_aes_of_match);
static void kmb_ocs_aes_remove(struct platform_device *pdev)
{
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0583/1518] RDMA/mlx5: Fix integer overflow of user QP buffer size
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (581 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0582/1518] crypto: keembay - publish OF module alias for OCS AES/SM4 Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0584/1518] thermal/drivers/airoha: Fix copy paste error on clamp_t low temp Greg Kroah-Hartman
` (415 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Maher Sanalla, Edward Srouji,
Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Maher Sanalla <msanalla@nvidia.com>
[ Upstream commit dec47e4b0fe34afdf38caa72b4408ba95502e5de ]
set_user_buf_size() computes the QP buffer size by left-shifting the
user-supplied rq.wqe_cnt and rq.wqe_shift values as signed integers.
A sufficiently large rq.wqe_cnt causes signed integer overflow, which
is undefined behavior, and yields a small or negative buf_size, causing
ib_umem_get() to map a buffer smaller than the hardware will actually
write into.
Replace the shifts and addition with check_shl_overflow() and
check_add_overflow(), rejecting invalid user inputs.
Moreover, guard the identical shift computing qp->sq.offset in
_create_user_qp() before set_user_buf_size() is reached.
Fixes: e126ba97dba9 ("mlx5: Add driver for Mellanox Connect-IB adapters")
Signed-off-by: Maher Sanalla <msanalla@nvidia.com>
Signed-off-by: Edward Srouji <edwards@nvidia.com>
Link: https://patch.msgid.link/20260723-fix-qp-buf-size-overflow-v1-1-ccb05ee43a7b@nvidia.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/mlx5/qp.c | 25 ++++++++++++++++++++-----
1 file changed, 20 insertions(+), 5 deletions(-)
diff --git a/drivers/infiniband/hw/mlx5/qp.c b/drivers/infiniband/hw/mlx5/qp.c
index 02a0f4920cabf..50b20264c4bdd 100644
--- a/drivers/infiniband/hw/mlx5/qp.c
+++ b/drivers/infiniband/hw/mlx5/qp.c
@@ -637,6 +637,7 @@ static int set_user_buf_size(struct mlx5_ib_dev *dev,
struct ib_qp_init_attr *attr)
{
int desc_sz = 1 << qp->sq.wqe_shift;
+ int rq_buf_size, sq_buf_size;
if (desc_sz > MLX5_CAP_GEN(dev->mdev, max_wqe_sz_sq)) {
mlx5_ib_warn(dev, "desc_sz %d, max_sq_desc_sz %d\n",
@@ -661,11 +662,21 @@ static int set_user_buf_size(struct mlx5_ib_dev *dev,
if (attr->qp_type == IB_QPT_RAW_PACKET ||
qp->flags & IB_QP_CREATE_SOURCE_QPN) {
- base->ubuffer.buf_size = qp->rq.wqe_cnt << qp->rq.wqe_shift;
- qp->raw_packet_qp.sq.ubuffer.buf_size = qp->sq.wqe_cnt << 6;
+ if (check_shl_overflow(qp->rq.wqe_cnt, qp->rq.wqe_shift,
+ &base->ubuffer.buf_size))
+ return -EINVAL;
+ if (check_shl_overflow(qp->sq.wqe_cnt, 6,
+ &qp->raw_packet_qp.sq.ubuffer.buf_size))
+ return -EINVAL;
} else {
- base->ubuffer.buf_size = (qp->rq.wqe_cnt << qp->rq.wqe_shift) +
- (qp->sq.wqe_cnt << 6);
+ if (check_shl_overflow(qp->rq.wqe_cnt, qp->rq.wqe_shift,
+ &rq_buf_size))
+ return -EINVAL;
+ if (check_shl_overflow(qp->sq.wqe_cnt, 6, &sq_buf_size))
+ return -EINVAL;
+ if (check_add_overflow(rq_buf_size, sq_buf_size,
+ &base->ubuffer.buf_size))
+ return -EINVAL;
}
return 0;
@@ -989,7 +1000,11 @@ static int _create_user_qp(struct mlx5_ib_dev *dev, struct ib_pd *pd,
qp->rq.offset = 0;
qp->sq.wqe_shift = ilog2(MLX5_SEND_WQE_BB);
- qp->sq.offset = qp->rq.wqe_cnt << qp->rq.wqe_shift;
+ if (check_shl_overflow(qp->rq.wqe_cnt, qp->rq.wqe_shift,
+ &qp->sq.offset)) {
+ err = -EINVAL;
+ goto err_bfreg;
+ }
err = set_user_buf_size(dev, qp, ucmd, base, attr);
if (err)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0584/1518] thermal/drivers/airoha: Fix copy paste error on clamp_t low temp
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (582 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0583/1518] RDMA/mlx5: Fix integer overflow of user QP buffer size Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0585/1518] thermal/drivers/airoha: Fix copy paste error for sen internal Greg Kroah-Hartman
` (414 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Marangi, Daniel Lezcano,
Wayen Yan, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Marangi <ansuelsmth@gmail.com>
[ Upstream commit 251621813fb4275e24431f9a0690aec9b15823e7 ]
In airoha_thermal_set_trips, there is a copy paste error on clamping the
value for the low trip temp point. Fix it to the correct value and actually
clamp for the low variable.
Fixes: 42de37f40e1b ("thermal/drivers: Add support for Airoha EN7581 thermal sensor")
Signed-off-by: Christian Marangi <ansuelsmth@gmail.com>
Signed-off-by: Daniel Lezcano <daniel.lezcano@kernel.org>
Reviewed-by: Wayen Yan <win847@gmail.com>
Link: https://patch.msgid.link/20260702094846.17325-2-ansuelsmth@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/thermal/airoha_thermal.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/thermal/airoha_thermal.c b/drivers/thermal/airoha_thermal.c
index b9fd6bfc88e5e..439aa011b75c7 100644
--- a/drivers/thermal/airoha_thermal.c
+++ b/drivers/thermal/airoha_thermal.c
@@ -273,7 +273,7 @@ static int airoha_thermal_set_trips(struct thermal_zone_device *tz, int low,
if (low != -INT_MAX) {
/* Validate low and clamp it to a supported value */
- low = clamp_t(int, high, RAW_TO_TEMP(priv, 0),
+ low = clamp_t(int, low, RAW_TO_TEMP(priv, 0),
RAW_TO_TEMP(priv, FIELD_MAX(EN7581_DOUT_TADC_MASK)));
/* We offset the low temp of 1°C to trigger correct event */
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0585/1518] thermal/drivers/airoha: Fix copy paste error for sen internal
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (583 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0584/1518] thermal/drivers/airoha: Fix copy paste error on clamp_t low temp Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0586/1518] thermal/drivers/qcom-spmi-adc-tm5: Drop IIO_VAL_INT check in adc_tm5_get_temp Greg Kroah-Hartman
` (413 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christian Marangi, Daniel Lezcano,
Wayen Yan, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christian Marangi <ansuelsmth@gmail.com>
[ Upstream commit 6791265d609549be55bb35b747c9648d0b570c12 ]
In airoha_thermal_setup_monitor there is a copy paste error on configuring
the internval for temp monitor. Fix the error and use the correct mask for
the sen interval for the EN7581_TEMPMONCTL2 register.
Fixes: 42de37f40e1b ("thermal/drivers: Add support for Airoha EN7581 thermal sensor")
Signed-off-by: Christian Marangi <ansuelsmth@gmail.com>
Signed-off-by: Daniel Lezcano <daniel.lezcano@kernel.org>
Reviewed-by: Wayen Yan <win847@gmail.com>
Link: https://patch.msgid.link/20260702094846.17325-3-ansuelsmth@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/thermal/airoha_thermal.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/thermal/airoha_thermal.c b/drivers/thermal/airoha_thermal.c
index 439aa011b75c7..829a7327fc403 100644
--- a/drivers/thermal/airoha_thermal.c
+++ b/drivers/thermal/airoha_thermal.c
@@ -403,7 +403,7 @@ static void airoha_thermal_setup_monitor(struct airoha_thermal_priv *priv)
* sen interval is 379 * 52.715us = 19.97ms
*/
writel(FIELD_PREP(EN7581_FILT_INTERVAL, 1) |
- FIELD_PREP(EN7581_FILT_INTERVAL, 379),
+ FIELD_PREP(EN7581_SEN_INTERVAL, 379),
priv->base + EN7581_TEMPMONCTL2);
/* AHB poll is set to 146 * 68.64 = 10.02us */
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0586/1518] thermal/drivers/qcom-spmi-adc-tm5: Drop IIO_VAL_INT check in adc_tm5_get_temp
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (584 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0585/1518] thermal/drivers/airoha: Fix copy paste error for sen internal Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0587/1518] powercap: intel_rapl_tpmi: Handle PMU registration failure during probe Greg Kroah-Hartman
` (412 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rakesh Kota, Daniel Lezcano,
Jonathan Cameron, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rakesh Kota <rakesh.kota@oss.qualcomm.com>
[ Upstream commit 0c569e22020f53ddfac0099b0aa193907bfbcd6f ]
Commit bb21ee31f575 ("iio: Fix iio_multiply_value use in
iio_read_channel_processed_scale") fixed the
iio_read_channel_processed_scale to return 0 on success instead
of IIO_VAL_INT (1). The existing check in adc_tm5_get_temp()
treated a successful return as an error because it expected
IIO_VAL_INT. Drop the redundant `ret != IIO_VAL_INT` condition
and rely solely on the negative error check.
Fixes: bb21ee31f575 ("iio: Fix iio_multiply_value use in iio_read_channel_processed_scale")
Signed-off-by: Rakesh Kota <rakesh.kota@oss.qualcomm.com>
Signed-off-by: Daniel Lezcano <daniel.lezcano@kernel.org>
Reviewed-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Link: https://patch.msgid.link/20260724-adc-tm5-drop-iio-val-int-check-v1-1-0b85a0895dd7@oss.qualcomm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/thermal/qcom/qcom-spmi-adc-tm5.c | 3 ---
1 file changed, 3 deletions(-)
diff --git a/drivers/thermal/qcom/qcom-spmi-adc-tm5.c b/drivers/thermal/qcom/qcom-spmi-adc-tm5.c
index d7f2e6ca92c2c..d1b086737bcd2 100644
--- a/drivers/thermal/qcom/qcom-spmi-adc-tm5.c
+++ b/drivers/thermal/qcom/qcom-spmi-adc-tm5.c
@@ -369,9 +369,6 @@ static int adc_tm5_get_temp(struct thermal_zone_device *tz, int *temp)
if (ret < 0)
return ret;
- if (ret != IIO_VAL_INT)
- return -EINVAL;
-
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0587/1518] powercap: intel_rapl_tpmi: Handle PMU registration failure during probe
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (585 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0586/1518] thermal/drivers/qcom-spmi-adc-tm5: Drop IIO_VAL_INT check in adc_tm5_get_temp Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0588/1518] isofs: release zisofs block pointer buffer head Greg Kroah-Hartman
` (411 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sumeet Pawnikar, Rafael J. Wysocki,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sumeet Pawnikar <sumeet4linux@gmail.com>
[ Upstream commit 9229916d59918ec9d3639e7263e1e97be638e361 ]
intel_rapl_tpmi_probe() invokes rapl_package_add_pmu() but ignores its
return value, so a PMU registration failure would leave the driver
reporting probe success despite the PMU being absent, with no log
trace.
Since PMU registration is an optional auxiliary feature for perf energy
counters, its failure should not break the primary powercap functionality.
Check the return value and log a warning to ensure graceful degradation.
Fixes: 963a9ad3c589 ("powercap: intel_rapl_tpmi: Enable PMU support")
Signed-off-by: Sumeet Pawnikar <sumeet4linux@gmail.com>
[ rjw: Changed the log level of the new message to "info" ]
Link: https://patch.msgid.link/20260723172321.5960-1-sumeet4linux@gmail.com
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/powercap/intel_rapl_tpmi.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/powercap/intel_rapl_tpmi.c b/drivers/powercap/intel_rapl_tpmi.c
index 34c0bd1edd61a..ee2a5e8397871 100644
--- a/drivers/powercap/intel_rapl_tpmi.c
+++ b/drivers/powercap/intel_rapl_tpmi.c
@@ -314,7 +314,10 @@ static int intel_rapl_tpmi_probe(struct auxiliary_device *auxdev,
goto err;
}
- rapl_package_add_pmu(trp->rp);
+ ret = rapl_package_add_pmu(trp->rp);
+ if (ret)
+ dev_info(&auxdev->dev, "Failed to add RAPL PMU for Package%d, %d\n",
+ info->package_id, ret);
auxiliary_set_drvdata(auxdev, trp);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0588/1518] isofs: release zisofs block pointer buffer head
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (586 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0587/1518] powercap: intel_rapl_tpmi: Handle PMU registration failure during probe Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0589/1518] clk: mediatek: mt6735: Unregister PLLs on probe failure Greg Kroah-Hartman
` (410 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yichong Chen, Jan Kara, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yichong Chen <chenyichong@uniontech.com>
[ Upstream commit 2f7dd9b86fe4076059e6a4a2a2c5d565afd76b9e ]
zisofs_fill_pages() reads the compressed block pointer table. The error
paths release the current buffer_head, the loop also releases the old
buffer_head when it advances. However, the success path leaves the last
buffer_head referenced. Release it before returning success.
Fixes: 59bc055211b8 ("zisofs: Implement reading of compressed files when PAGE_CACHE_SIZE > compress block size")
Signed-off-by: Yichong Chen <chenyichong@uniontech.com>
Link: https://patch.msgid.link/20260721091152.1450622-1-chenyichong@uniontech.com
Signed-off-by: Jan Kara <jack@suse.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/isofs/compress.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/fs/isofs/compress.c b/fs/isofs/compress.c
index 172faf79a259d..4500b14f802a6 100644
--- a/fs/isofs/compress.c
+++ b/fs/isofs/compress.c
@@ -293,6 +293,7 @@ static int zisofs_fill_pages(struct inode *inode, int full_page, int pcount,
memzero_page(*pages, poffset, PAGE_SIZE - poffset);
SetPageUptodate(*pages);
}
+ brelse(bh);
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0589/1518] clk: mediatek: mt6735: Unregister PLLs on probe failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (587 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0588/1518] isofs: release zisofs block pointer buffer head Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0590/1518] spi: oc-tiny: switch to managed controller allocation Greg Kroah-Hartman
` (409 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ijae Kim, Myeonghun Pak,
Brian Masney, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Myeonghun Pak <mhun512@gmail.com>
[ Upstream commit 935ad6242c47b37380d0cb7ec366516fe11855b4 ]
mtk_clk_register_plls() registers the apmixedsys PLL clocks manually, while
clk_mt6735_apmixed_remove() unregisters them on driver removal.
If devm_of_clk_add_hw_provider() fails after the PLL registration succeeds,
probe returns the error directly and the remove callback is not run. This
leaves the registered PLL clocks behind on the probe failure path.
Unregister the PLLs in that failure branch before returning the error.
Fixes: 43c04ed79189 ("clk: mediatek: Add drivers for MediaTek MT6735 main clock and reset drivers")
Co-developed-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
Reviewed-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/mediatek/clk-mt6735-apmixedsys.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/clk/mediatek/clk-mt6735-apmixedsys.c b/drivers/clk/mediatek/clk-mt6735-apmixedsys.c
index e0949911e8f7d..be51b97cab1f3 100644
--- a/drivers/clk/mediatek/clk-mt6735-apmixedsys.c
+++ b/drivers/clk/mediatek/clk-mt6735-apmixedsys.c
@@ -102,9 +102,12 @@ static int clk_mt6735_apmixed_probe(struct platform_device *pdev)
ret = devm_of_clk_add_hw_provider(&pdev->dev, of_clk_hw_onecell_get,
clk_data);
- if (ret)
+ if (ret) {
dev_err(&pdev->dev,
"Failed to register clock provider: %d\n", ret);
+ mtk_clk_unregister_plls(apmixedsys_plls, ARRAY_SIZE(apmixedsys_plls),
+ clk_data);
+ }
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0590/1518] spi: oc-tiny: switch to managed controller allocation
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (588 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0589/1518] clk: mediatek: mt6735: Unregister PLLs on probe failure Greg Kroah-Hartman
@ 2026-09-12 6:45 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0591/1518] w1: ds2482: Fix signedness bug in ds2482_w1_triplet() Greg Kroah-Hartman
` (408 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:45 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Fan Wu, Mark Brown, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fan Wu <fanwu01@zju.edu.cn>
[ Upstream commit d710f43ce30975d197f73c543bfe47b958d8ba17 ]
The controller is allocated with the non-managed spi_alloc_host() while
the interrupt is registered with devm_request_irq(). During removal,
spi_bitbang_stop() only unregisters the controller; the subsequent
spi_controller_put() then frees the controller together with its
embedded driver-private devdata, which is the IRQ handler's dev_id. The
devm_request_irq() release action (free_irq()), which drains the
handler, does not run until after .remove() returns. A late or latched
interrupt can therefore reach tiny_spi_irq() and dereference
already-freed memory (e.g. hw->base).
Switch to devm_spi_alloc_host() so that the devres LIFO order releases
the controller only after free_irq() has drained the handler, and drop
the now-redundant spi_controller_put() from .remove(). The probe error
path is simplified to direct returns.
This issue was found by an in-house static analysis tool.
Fixes: ce792580ea2c ("spi: add OpenCores tiny SPI driver")
Assisted-by: Codex:gpt-5.6
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Link: https://patch.msgid.link/20260719010014.3163356-1-fanwu01@zju.edu.cn
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/spi/spi-oc-tiny.c | 24 ++++++++----------------
1 file changed, 8 insertions(+), 16 deletions(-)
diff --git a/drivers/spi/spi-oc-tiny.c b/drivers/spi/spi-oc-tiny.c
index cba2299203573..cc5bceb1cc88b 100644
--- a/drivers/spi/spi-oc-tiny.c
+++ b/drivers/spi/spi-oc-tiny.c
@@ -211,11 +211,11 @@ static int tiny_spi_probe(struct platform_device *pdev)
struct tiny_spi_platform_data *platp = dev_get_platdata(&pdev->dev);
struct tiny_spi *hw;
struct spi_controller *host;
- int err = -ENODEV;
+ int err;
- host = spi_alloc_host(&pdev->dev, sizeof(struct tiny_spi));
+ host = devm_spi_alloc_host(&pdev->dev, sizeof(struct tiny_spi));
if (!host)
- return err;
+ return -ENOMEM;
/* setup the host state. */
host->bus_num = pdev->id;
@@ -233,10 +233,8 @@ static int tiny_spi_probe(struct platform_device *pdev)
/* find and map our resources */
hw->base = devm_platform_ioremap_resource(pdev, 0);
- if (IS_ERR(hw->base)) {
- err = PTR_ERR(hw->base);
- goto exit;
- }
+ if (IS_ERR(hw->base))
+ return PTR_ERR(hw->base);
/* irq is optional */
hw->irq = platform_get_irq(pdev, 0);
if (hw->irq >= 0) {
@@ -244,7 +242,7 @@ static int tiny_spi_probe(struct platform_device *pdev)
err = devm_request_irq(&pdev->dev, hw->irq, tiny_spi_irq, 0,
pdev->name, hw);
if (err)
- goto exit;
+ return err;
}
/* find platform data */
if (platp) {
@@ -253,29 +251,23 @@ static int tiny_spi_probe(struct platform_device *pdev)
} else {
err = tiny_spi_of_probe(pdev);
if (err)
- goto exit;
+ return err;
}
/* register our spi controller */
err = spi_bitbang_start(&hw->bitbang);
if (err)
- goto exit;
+ return err;
dev_info(&pdev->dev, "base %p, irq %d\n", hw->base, hw->irq);
return 0;
-
-exit:
- spi_controller_put(host);
- return err;
}
static void tiny_spi_remove(struct platform_device *pdev)
{
struct tiny_spi *hw = platform_get_drvdata(pdev);
- struct spi_controller *host = hw->bitbang.ctlr;
spi_bitbang_stop(&hw->bitbang);
- spi_controller_put(host);
}
#ifdef CONFIG_OF
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0591/1518] w1: ds2482: Fix signedness bug in ds2482_w1_triplet()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (589 preceding siblings ...)
2026-09-12 6:45 ` [PATCH 6.18 0590/1518] spi: oc-tiny: switch to managed controller allocation Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0592/1518] cpufreq/amd-pstate: Add comment explaining nominal_perf usage for performance policy Greg Kroah-Hartman
` (407 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Babanpreet Singh,
Krzysztof Kozlowski, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Babanpreet Singh <bbnpreetsingh@gmail.com>
[ Upstream commit 4d3721b204f961e905714954ff95633337b768e3 ]
ds2482_wait_1wire_idle() returns the status register value (0..255) on
success, or a negative value on I2C failure: -1 when selecting the
status register fails, or a negative errno from i2c_smbus_read_byte().
ds2482_w1_triplet() feeds that result into "return (status >> 5);"
without checking for errors, and the function returns u8. For a
negative status the arithmetic shift keeps the sign and the u8
truncation fabricates a triplet result whose meaning depends on the
errno value: -1 and -EIO happen to become 0xff, whose set low bits make
w1_search() abort, but -ETIMEDOUT (-110 >> 5 = -4) becomes 0xfc -
"devices responded on both branches, wrote 1" - and -EOPNOTSUPP
(-95 >> 5 = -3) becomes 0xfd - "only the zero branch responded".
w1_search() then continues the ROM search with a fabricated direction
bit instead of aborting, and the corrupted id is either rejected by the
ROM CRC (existing device missed) or registers a phantom slave.
The function already defines an in-band error value: status is
initialized to (3 << 5), which decodes to 3 (both branch bits set, "no
device responded") and makes w1_search() terminate the search when
sending the triplet command fails. Decode a negative status to the same
value.
Found by smatch:
drivers/w1/masters/ds2482.c:314 ds2482_w1_triplet() warn: signedness bug returning '(-67108864)'
Fixes: baf12ae29ab4 ("[PATCH] W1: Add the DS2482 I2C-to-w1 bridge driver.")
Assisted-by: Claude:claude-sonnet-5
Signed-off-by: Babanpreet Singh <bbnpreetsingh@gmail.com>
Link: https://patch.msgid.link/20260714041011.7-1-bbnpreetsingh@gmail.com
Signed-off-by: Krzysztof Kozlowski <krzk@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/w1/masters/ds2482.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/w1/masters/ds2482.c b/drivers/w1/masters/ds2482.c
index e2a568c9a43aa..0c93bf338a6ef 100644
--- a/drivers/w1/masters/ds2482.c
+++ b/drivers/w1/masters/ds2482.c
@@ -310,6 +310,10 @@ static u8 ds2482_w1_triplet(void *data, u8 dbit)
mutex_unlock(&pdev->access_lock);
+ /* On bus error, decode to 3 (no device responded) to abort the search */
+ if (status < 0)
+ status = 3 << 5;
+
/* Decode the status */
return (status >> 5);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0592/1518] cpufreq/amd-pstate: Add comment explaining nominal_perf usage for performance policy
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (590 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0591/1518] w1: ds2482: Fix signedness bug in ds2482_w1_triplet() Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0593/1518] cpufreq/amd-pstate: Set min_limit_freq based on bios_min_perf Greg Kroah-Hartman
` (406 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Juan Martinez, Viresh Kumar,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Juan Martinez <juan.martinez@amd.com>
[ Upstream commit 94dbce6c13cd7634f9bdb402248991c95a8c3d57 ]
Add comment explaining why nominal_perf is used for MinPerf when the
CPU frequency policy is set to CPUFREQ_POLICY_PERFORMANCE, rather than
using highest_perf or lowest_nonlinear_perf.
Signed-off-by: Juan Martinez <juan.martinez@amd.com>
Signed-off-by: Viresh Kumar <viresh.kumar@linaro.org>
Stable-dep-of: 5c3ecf36d291 ("cpufreq/amd-pstate: Set min_limit_freq based on bios_min_perf")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/cpufreq/amd-pstate.c | 13 +++++++++++++
1 file changed, 13 insertions(+)
diff --git a/drivers/cpufreq/amd-pstate.c b/drivers/cpufreq/amd-pstate.c
index 081d2e60a21e6..17e8435d85ac5 100644
--- a/drivers/cpufreq/amd-pstate.c
+++ b/drivers/cpufreq/amd-pstate.c
@@ -635,6 +635,19 @@ static void amd_pstate_update_min_max_limit(struct cpufreq_policy *policy)
WRITE_ONCE(cpudata->max_limit_freq, policy->max);
if (cpudata->policy == CPUFREQ_POLICY_PERFORMANCE) {
+ /*
+ * For performance policy, set MinPerf to nominal_perf rather than
+ * highest_perf or lowest_nonlinear_perf.
+ *
+ * Per commit 0c411b39e4f4c, using highest_perf was observed
+ * to cause frequency throttling on power-limited platforms, leading to
+ * performance regressions. Using lowest_nonlinear_perf would limit
+ * performance too much for HPC workloads requiring high frequency
+ * operation and minimal wakeup latency from idle states.
+ *
+ * nominal_perf therefore provides a balance by avoiding throttling
+ * while still maintaining enough performance for HPC workloads.
+ */
perf.min_limit_perf = min(perf.nominal_perf, perf.max_limit_perf);
WRITE_ONCE(cpudata->min_limit_freq, min(cpudata->nominal_freq, cpudata->max_limit_freq));
} else {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0593/1518] cpufreq/amd-pstate: Set min_limit_freq based on bios_min_perf
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (591 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0592/1518] cpufreq/amd-pstate: Add comment explaining nominal_perf usage for performance policy Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0594/1518] remoteproc: core: Drop redundant initialization of ret in rproc_shutdown() Greg Kroah-Hartman
` (405 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mario Limonciello (AMD),
K Prateek Nayak, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: K Prateek Nayak <kprateek.nayak@amd.com>
[ Upstream commit 5c3ecf36d2918facff40548ee6ae28eef0865266 ]
amd_pstate_update_min_max_limit() sets the min_limit_perf to the
nominal_perf to avoid frequency throttling when the system is idling.
This was found to be an ideal default but is suboptimal for users who
have profiled their workload at different operating frequencies and have
configured the optimal idling frequency via bios_min_perf.
Use the bios_min_perf (if configured) as the min_limit_perf when running
with performance governor. In absence of bios_min_perf, continue using
nominal_perf as the default min_limit_perf to avoid throttling.
Fixes: 608a76b65288 ("cpufreq/amd-pstate: Add support for the "Requested CPU Min frequency" BIOS option")
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Signed-off-by: K Prateek Nayak <kprateek.nayak@amd.com>
Link: https://lore.kernel.org/r/20260727072056.1248-2-kprateek.nayak@amd.com
Signed-off-by: Mario Limonciello <superm1@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/cpufreq/amd-pstate.c | 22 ++++++++++++++++------
1 file changed, 16 insertions(+), 6 deletions(-)
diff --git a/drivers/cpufreq/amd-pstate.c b/drivers/cpufreq/amd-pstate.c
index 17e8435d85ac5..0b29213a019f5 100644
--- a/drivers/cpufreq/amd-pstate.c
+++ b/drivers/cpufreq/amd-pstate.c
@@ -635,9 +635,12 @@ static void amd_pstate_update_min_max_limit(struct cpufreq_policy *policy)
WRITE_ONCE(cpudata->max_limit_freq, policy->max);
if (cpudata->policy == CPUFREQ_POLICY_PERFORMANCE) {
+ u8 min_limit_perf = perf.bios_min_perf ?: perf.nominal_perf;
+ u32 min_limit_freq;
+
/*
- * For performance policy, set MinPerf to nominal_perf rather than
- * highest_perf or lowest_nonlinear_perf.
+ * For performance policy, set MinPerf to nominal_perf / bios_min_perf
+ * rather than highest_perf or lowest_nonlinear_perf.
*
* Per commit 0c411b39e4f4c, using highest_perf was observed
* to cause frequency throttling on power-limited platforms, leading to
@@ -645,11 +648,18 @@ static void amd_pstate_update_min_max_limit(struct cpufreq_policy *policy)
* performance too much for HPC workloads requiring high frequency
* operation and minimal wakeup latency from idle states.
*
- * nominal_perf therefore provides a balance by avoiding throttling
- * while still maintaining enough performance for HPC workloads.
+ * nominal_perf therefore provides a balanced default by avoiding
+ * throttling while still maintaining enough performance for HPC
+ * workloads when bios_min_perf is not available.
+ *
+ * When bios_min_perf is available, users have profiled their workloads
+ * to understand the best idling frequency. Use that instead.
*/
- perf.min_limit_perf = min(perf.nominal_perf, perf.max_limit_perf);
- WRITE_ONCE(cpudata->min_limit_freq, min(cpudata->nominal_freq, cpudata->max_limit_freq));
+ min_limit_perf = min(min_limit_perf, perf.max_limit_perf);
+ min_limit_freq = perf_to_freq(perf, cpudata->nominal_freq, min_limit_perf);
+ perf.min_limit_perf = min_limit_perf;
+
+ WRITE_ONCE(cpudata->min_limit_freq, min(min_limit_freq, cpudata->max_limit_freq));
} else {
perf.min_limit_perf = freq_to_perf(perf, cpudata->nominal_freq, policy->min);
WRITE_ONCE(cpudata->min_limit_freq, policy->min);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0594/1518] remoteproc: core: Drop redundant initialization of ret in rproc_shutdown()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (592 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0593/1518] cpufreq/amd-pstate: Set min_limit_freq based on bios_min_perf Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0595/1518] remoteproc: Allow shutdown of crashed processors Greg Kroah-Hartman
` (404 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Peng Fan, Andrew Davis,
Mathieu Poirier, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Peng Fan <peng.fan@nxp.com>
[ Upstream commit 4531b6bad5af669511c348ad5225d9f697af221b ]
The variable ret is immediately assigned the return value of
mutex_lock_interruptible(), making its prior initialization to zero
unnecessary. Remove the redundant assignment
No functional changes.
Signed-off-by: Peng Fan <peng.fan@nxp.com>
Acked-by: Andrew Davis <afd@ti.com>
Link: https://lore.kernel.org/r/20251016-rproc-cleanup-v3-v3-1-774083716e8a@nxp.com
Signed-off-by: Mathieu Poirier <mathieu.poirier@linaro.org>
Stable-dep-of: 2482ca875ef5 ("remoteproc: Allow shutdown of crashed processors")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/remoteproc/remoteproc_core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/remoteproc/remoteproc_core.c b/drivers/remoteproc/remoteproc_core.c
index 8256721005289..29bbaa349e340 100644
--- a/drivers/remoteproc/remoteproc_core.c
+++ b/drivers/remoteproc/remoteproc_core.c
@@ -1989,7 +1989,7 @@ EXPORT_SYMBOL(rproc_boot);
int rproc_shutdown(struct rproc *rproc)
{
struct device *dev = &rproc->dev;
- int ret = 0;
+ int ret;
ret = mutex_lock_interruptible(&rproc->lock);
if (ret) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0595/1518] remoteproc: Allow shutdown of crashed processors
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (593 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0594/1518] remoteproc: core: Drop redundant initialization of ret in rproc_shutdown() Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0596/1518] remoteproc: core: Attach rproc asynchronously in rproc_add() path via schedule_work() Greg Kroah-Hartman
` (403 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bjorn Andersson, Mukesh Ojha,
Konrad Dybcio, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bjorn Andersson <bjorn.andersson@oss.qualcomm.com>
[ Upstream commit 2482ca875ef5993df8daee563033d70e2523a25f ]
rproc_shutdown() rejects a remoteproc in RPROC_CRASHED state, and
rproc_del() ignores that error. The result of these two decisions is
that a user cannot stop a remoteproc that with recovery disabled that
has entered a crash state, and removal of an associated remoteproc
driver will release resources without first stopping the remoteproc.
Allow rproc_shutdown() to stop crashed processors. Propagate the crash
state to subdevice teardown, to allow subdevices to dismantle things
appropriately.
Assisted-by: OpenCode:GPT-5.5
Fixes: 5e6a0e05270e ("remoteproc: core: Move state checking to remoteproc_core")
Signed-off-by: Bjorn Andersson <bjorn.andersson@oss.qualcomm.com>
Reviewed-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260723-rproc-rmmod-not-crashing-v1-1-546dfd5de0e6@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/remoteproc/remoteproc_core.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/drivers/remoteproc/remoteproc_core.c b/drivers/remoteproc/remoteproc_core.c
index 29bbaa349e340..321ec76d20521 100644
--- a/drivers/remoteproc/remoteproc_core.c
+++ b/drivers/remoteproc/remoteproc_core.c
@@ -1989,6 +1989,7 @@ EXPORT_SYMBOL(rproc_boot);
int rproc_shutdown(struct rproc *rproc)
{
struct device *dev = &rproc->dev;
+ bool crashed;
int ret;
ret = mutex_lock_interruptible(&rproc->lock);
@@ -1998,16 +1999,18 @@ int rproc_shutdown(struct rproc *rproc)
}
if (rproc->state != RPROC_RUNNING &&
- rproc->state != RPROC_ATTACHED) {
+ rproc->state != RPROC_ATTACHED &&
+ rproc->state != RPROC_CRASHED) {
ret = -EINVAL;
goto out;
}
+ crashed = rproc->state == RPROC_CRASHED;
/* if the remote proc is still needed, bail out */
if (!atomic_dec_and_test(&rproc->power))
goto out;
- ret = rproc_stop(rproc, false);
+ ret = rproc_stop(rproc, crashed);
if (ret) {
atomic_inc(&rproc->power);
goto out;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0596/1518] remoteproc: core: Attach rproc asynchronously in rproc_add() path via schedule_work()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (594 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0595/1518] remoteproc: Allow shutdown of crashed processors Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0597/1518] remoteproc: Prevent crash handling to race with rproc_del() Greg Kroah-Hartman
` (402 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jingyi Wang, Bjorn Andersson,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jingyi Wang <jingyi.wang@oss.qualcomm.com>
[ Upstream commit 026a3fada43261e403c6c4d9bda9501547e3f108 ]
Unlike the remoteproc firmware load path where rproc_add() call
rproc_auto_boot_callback() asynchronously and ignores the return value of
rproc_boot(), the attach path calls rproc_boot() synchronously and
propagates its return value back to rproc_add(). This means a failure
during rproc_attach() causes rproc_add() to fail and triggers resource
release, removing the remoteproc from sysfs and making it unavailable for
recovery or further boot attempts.
Align the remoteproc attach path with the firmware load path by
introducing attach_work and scheduling rproc_boot() asynchronously via
schedule_work(). This keeps the remoteproc registered and available in
sysfs even if the initial attach attempt fails, and avoids blocking
rproc_add() on the attach result.
Signed-off-by: Jingyi Wang <jingyi.wang@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260623-rproc-attach-issue-v3-1-8e24310707ce@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Stable-dep-of: 74ee3b2f5767 ("remoteproc: Prevent crash handling to race with rproc_del()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/remoteproc/remoteproc_core.c | 20 ++++++++++++--------
include/linux/remoteproc.h | 2 ++
2 files changed, 14 insertions(+), 8 deletions(-)
diff --git a/drivers/remoteproc/remoteproc_core.c b/drivers/remoteproc/remoteproc_core.c
index 321ec76d20521..9a2208a2ffbca 100644
--- a/drivers/remoteproc/remoteproc_core.c
+++ b/drivers/remoteproc/remoteproc_core.c
@@ -1678,18 +1678,21 @@ static void rproc_auto_boot_callback(const struct firmware *fw, void *context)
release_firmware(fw);
}
+static void rproc_attach_work(struct work_struct *work)
+{
+ struct rproc *rproc = container_of(work, struct rproc, attach_work);
+
+ rproc_boot(rproc);
+}
+
static int rproc_trigger_auto_boot(struct rproc *rproc)
{
int ret;
- /*
- * Since the remote processor is in a detached state, it has already
- * been booted by another entity. As such there is no point in waiting
- * for a firmware image to be loaded, we can simply initiate the process
- * of attaching to it immediately.
- */
- if (rproc->state == RPROC_DETACHED)
- return rproc_boot(rproc);
+ if (rproc->state == RPROC_DETACHED) {
+ schedule_work(&rproc->attach_work);
+ return 0;
+ }
/*
* We're initiating an asynchronous firmware loading, so we can
@@ -2520,6 +2523,7 @@ struct rproc *rproc_alloc(struct device *dev, const char *name,
INIT_LIST_HEAD(&rproc->dump_segments);
INIT_WORK(&rproc->crash_handler, rproc_crash_handler_work);
+ INIT_WORK(&rproc->attach_work, rproc_attach_work);
rproc->state = RPROC_OFFLINE;
diff --git a/include/linux/remoteproc.h b/include/linux/remoteproc.h
index b4795698d8c2a..580d324a1e8ff 100644
--- a/include/linux/remoteproc.h
+++ b/include/linux/remoteproc.h
@@ -526,6 +526,7 @@ enum rproc_features {
* @subdevs: list of subdevices, to following the running state
* @notifyids: idr for dynamically assigning rproc-wide unique notify ids
* @index: index of this rproc device
+ * @attach_work: workqueue for attaching rproc
* @crash_handler: workqueue for handling a crash
* @crash_cnt: crash counter
* @recovery_disabled: flag that state if recovery was disabled
@@ -568,6 +569,7 @@ struct rproc {
struct list_head subdevs;
struct idr notifyids;
int index;
+ struct work_struct attach_work;
struct work_struct crash_handler;
unsigned int crash_cnt;
bool recovery_disabled;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0597/1518] remoteproc: Prevent crash handling to race with rproc_del()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (595 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0596/1518] remoteproc: core: Attach rproc asynchronously in rproc_add() path via schedule_work() Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0598/1518] firmware: qcom_scm: Introduce PAS context allocator helper function Greg Kroah-Hartman
` (401 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bjorn Andersson, Pradnya Dahiwale,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bjorn Andersson <bjorn.andersson@oss.qualcomm.com>
[ Upstream commit 74ee3b2f5767447c57959994341e5b95f1079977 ]
There's no synchronization between rproc_crash_handler_work() and
rproc_del(), as such it's possible for a driver to be removed while
crash-handler work is scheduled, or even executing - resulting in
use-after-free issues.
To avoid this the scheduled work need to be cancelled and synchronized
against before the removal proceeds.
In order to ensure that this doesn't race with the reporting, and
thereby scheduling new work, a "deleting" flag is introduced. This is
similar to the RPROC_DELETE state that was introduced to ensure that
"start" didn't race with rproc_del(), but the existing mechanism can not
be used as it's valid to call rproc_report_crash() in atomic context -
and the "state" is protected by a mutex.
In the event that work is cancelled the pm_stay_awake() is left
unbalanced and need to be unrolled.
The blocking and cancelling of crash-handler work prior to the actual
rproc_shutdown() call does have the explicit side-effect that crashes
resulting from the shutdown process will not enter the crash-handling
path, and as such will not generate devcoredumps etc. Due to the
existing mutual exclusion between these code paths there's no concrete
reduction in functionality, but further work would be needed to handle
this case.
Assisted-by: OpenCode:GPT-5.5
Fixes: 8afd519c3470 ("remoteproc: add rproc_report_crash function to notify rproc crashes")
Signed-off-by: Bjorn Andersson <bjorn.andersson@oss.qualcomm.com>
Reviewed-by: Pradnya Dahiwale <pradnya.dahiwale@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260723-rproc-rmmod-not-crashing-v1-2-546dfd5de0e6@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/remoteproc/remoteproc_core.c | 42 +++++++++++++++++++++------
drivers/remoteproc/remoteproc_sysfs.c | 1 -
include/linux/remoteproc.h | 13 +++++----
3 files changed, 41 insertions(+), 15 deletions(-)
diff --git a/drivers/remoteproc/remoteproc_core.c b/drivers/remoteproc/remoteproc_core.c
index 9a2208a2ffbca..157d5603f2bad 100644
--- a/drivers/remoteproc/remoteproc_core.c
+++ b/drivers/remoteproc/remoteproc_core.c
@@ -1841,6 +1841,11 @@ int rproc_trigger_recovery(struct rproc *rproc)
if (ret)
return ret;
+ if (READ_ONCE(rproc->deleting)) {
+ ret = -ENODEV;
+ goto unlock_mutex;
+ }
+
/* State could have changed before we got the mutex */
if (rproc->state != RPROC_CRASHED)
goto unlock_mutex;
@@ -1873,6 +1878,11 @@ static void rproc_crash_handler_work(struct work_struct *work)
mutex_lock(&rproc->lock);
+ if (READ_ONCE(rproc->deleting)) {
+ mutex_unlock(&rproc->lock);
+ goto out;
+ }
+
if (rproc->state == RPROC_CRASHED) {
/* handle only the first crash detected */
mutex_unlock(&rproc->lock);
@@ -1928,9 +1938,9 @@ int rproc_boot(struct rproc *rproc)
return ret;
}
- if (rproc->state == RPROC_DELETED) {
+ if (READ_ONCE(rproc->deleting)) {
ret = -ENODEV;
- dev_err(dev, "can't boot deleted rproc %s\n", rproc->name);
+ dev_err(dev, "can't boot deleting rproc %s\n", rproc->name);
goto unlock_mutex;
}
@@ -2522,8 +2532,9 @@ struct rproc *rproc_alloc(struct device *dev, const char *name,
INIT_LIST_HEAD(&rproc->subdevs);
INIT_LIST_HEAD(&rproc->dump_segments);
- INIT_WORK(&rproc->crash_handler, rproc_crash_handler_work);
INIT_WORK(&rproc->attach_work, rproc_attach_work);
+ INIT_WORK(&rproc->crash_handler, rproc_crash_handler_work);
+ spin_lock_init(&rproc->crash_handler_lock);
rproc->state = RPROC_OFFLINE;
@@ -2587,16 +2598,21 @@ EXPORT_SYMBOL(rproc_put);
*/
int rproc_del(struct rproc *rproc)
{
+ unsigned long flags;
+
if (!rproc)
return -EINVAL;
+ spin_lock_irqsave(&rproc->crash_handler_lock, flags);
+ WRITE_ONCE(rproc->deleting, true);
+ spin_unlock_irqrestore(&rproc->crash_handler_lock, flags);
+
+ if (cancel_work_sync(&rproc->crash_handler))
+ pm_relax(rproc->dev.parent);
+
/* TODO: make sure this works with rproc->power > 1 */
rproc_shutdown(rproc);
- mutex_lock(&rproc->lock);
- rproc->state = RPROC_DELETED;
- mutex_unlock(&rproc->lock);
-
rproc_delete_debug_dir(rproc);
/* the rproc is downref'ed as soon as it's removed from the klist */
@@ -2708,18 +2724,26 @@ EXPORT_SYMBOL(rproc_get_by_child);
*/
void rproc_report_crash(struct rproc *rproc, enum rproc_crash_type type)
{
+ unsigned long flags;
+
if (!rproc) {
pr_err("NULL rproc pointer\n");
return;
}
+ spin_lock_irqsave(&rproc->crash_handler_lock, flags);
+ if (READ_ONCE(rproc->deleting)) {
+ spin_unlock_irqrestore(&rproc->crash_handler_lock, flags);
+ return;
+ }
+
/* Prevent suspend while the remoteproc is being recovered */
pm_stay_awake(rproc->dev.parent);
+ queue_work(rproc_recovery_wq, &rproc->crash_handler);
+ spin_unlock_irqrestore(&rproc->crash_handler_lock, flags);
dev_err(&rproc->dev, "crash detected in %s: type %s\n",
rproc->name, rproc_crash_to_string(type));
-
- queue_work(rproc_recovery_wq, &rproc->crash_handler);
}
EXPORT_SYMBOL(rproc_report_crash);
diff --git a/drivers/remoteproc/remoteproc_sysfs.c b/drivers/remoteproc/remoteproc_sysfs.c
index 138e752c5e4e0..925b0cdbe5778 100644
--- a/drivers/remoteproc/remoteproc_sysfs.c
+++ b/drivers/remoteproc/remoteproc_sysfs.c
@@ -168,7 +168,6 @@ static const char * const rproc_state_string[] = {
[RPROC_SUSPENDED] = "suspended",
[RPROC_RUNNING] = "running",
[RPROC_CRASHED] = "crashed",
- [RPROC_DELETED] = "deleted",
[RPROC_ATTACHED] = "attached",
[RPROC_DETACHED] = "detached",
[RPROC_LAST] = "invalid",
diff --git a/include/linux/remoteproc.h b/include/linux/remoteproc.h
index 580d324a1e8ff..023fa91bd2a48 100644
--- a/include/linux/remoteproc.h
+++ b/include/linux/remoteproc.h
@@ -37,6 +37,7 @@
#include <linux/types.h>
#include <linux/mutex.h>
+#include <linux/spinlock.h>
#include <linux/virtio.h>
#include <linux/cdev.h>
#include <linux/completion.h>
@@ -412,7 +413,6 @@ struct rproc_ops {
* a message.
* @RPROC_RUNNING: device is up and running
* @RPROC_CRASHED: device has crashed; need to start recovery
- * @RPROC_DELETED: device is deleted
* @RPROC_ATTACHED: device has been booted by another entity and the core
* has attached to it
* @RPROC_DETACHED: device has been booted by another entity and waiting
@@ -430,10 +430,9 @@ enum rproc_state {
RPROC_SUSPENDED = 1,
RPROC_RUNNING = 2,
RPROC_CRASHED = 3,
- RPROC_DELETED = 4,
- RPROC_ATTACHED = 5,
- RPROC_DETACHED = 6,
- RPROC_LAST = 7,
+ RPROC_ATTACHED = 4,
+ RPROC_DETACHED = 5,
+ RPROC_LAST = 6,
};
/**
@@ -528,6 +527,8 @@ enum rproc_features {
* @index: index of this rproc device
* @attach_work: workqueue for attaching rproc
* @crash_handler: workqueue for handling a crash
+ * @crash_handler_lock: serializes crash handler queueing and deletion
+ * @deleting: remoteproc deletion has begun
* @crash_cnt: crash counter
* @recovery_disabled: flag that state if recovery was disabled
* @max_notifyid: largest allocated notify id.
@@ -571,6 +572,8 @@ struct rproc {
int index;
struct work_struct attach_work;
struct work_struct crash_handler;
+ spinlock_t crash_handler_lock;
+ bool deleting;
unsigned int crash_cnt;
bool recovery_disabled;
int max_notifyid;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0598/1518] firmware: qcom_scm: Introduce PAS context allocator helper function
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (596 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0597/1518] remoteproc: Prevent crash handling to race with rproc_del() Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0599/1518] staging: rtl8723bs: use kfree_sensitive() for key material Greg Kroah-Hartman
` (400 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mukesh Ojha, Bjorn Andersson,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
[ Upstream commit ccb7bde5f7cc794dee0cd66fd451cb0e0715712d ]
When the Peripheral Authentication Service (PAS) method runs on a SoC
where Linux operates at EL2 (i.e., without the Gunyah hypervisor), the
reset sequences are handled by TrustZone. In such cases, Linux must
perform additional steps before invoking PAS SMC calls, such as creating
a SHM bridge. Therefore, PAS SMC calls require awareness and handling of
these additional steps when Linux runs at EL2.
To support this, there is a need for a data structure that can be
initialized prior to invoking any SMC or MDT functions. This structure
allows those functions to determine whether they are operating in the
presence or absence of the Gunyah hypervisor and behave accordingly.
Currently, remoteproc and non-remoteproc subsystems use different
variants of the MDT loader helper API, primarily due to differences in
metadata context handling. Remoteproc subsystems retain the metadata
context until authentication and reset are completed, while
non-remoteproc subsystems (e.g., video, graphics, IPA, etc.) do not
retain the metadata context and can free it within the
qcom_scm_pas_init() call by passing a NULL context parameter and due to
these differences, it is not possible to extend metadata context
handling to support remoteproc and non remoteproc subsystem use PAS
operations, when Linux operates at EL2.
Add PAS context data structure allocator helper function.
Signed-off-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260105-kvmrprocv10-v10-4-022e96815380@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Stable-dep-of: 0ea50486978f ("remoteproc: qcom: q6v5: Request shutdown if crash is triggered host-side")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/qcom/qcom_scm.c | 34 ++++++++++++++++++++++++++
include/linux/firmware/qcom/qcom_scm.h | 14 +++++++++++
2 files changed, 48 insertions(+)
diff --git a/drivers/firmware/qcom/qcom_scm.c b/drivers/firmware/qcom/qcom_scm.c
index 3379607eaf94f..2e51c4d80fdce 100644
--- a/drivers/firmware/qcom/qcom_scm.c
+++ b/drivers/firmware/qcom/qcom_scm.c
@@ -558,6 +558,40 @@ static void qcom_scm_set_download_mode(u32 dload_mode)
dev_err(__scm->dev, "failed to set download mode: %d\n", ret);
}
+/**
+ * devm_qcom_scm_pas_context_alloc() - Allocate peripheral authentication service
+ * context for a given peripheral
+ *
+ * PAS context is device-resource managed, so the caller does not need
+ * to worry about freeing the context memory.
+ *
+ * @dev: PAS firmware device
+ * @pas_id: peripheral authentication service id
+ * @mem_phys: Subsystem reserve memory start address
+ * @mem_size: Subsystem reserve memory size
+ *
+ * Returns: The new PAS context, or ERR_PTR() on failure.
+ */
+struct qcom_scm_pas_context *devm_qcom_scm_pas_context_alloc(struct device *dev,
+ u32 pas_id,
+ phys_addr_t mem_phys,
+ size_t mem_size)
+{
+ struct qcom_scm_pas_context *ctx;
+
+ ctx = devm_kzalloc(dev, sizeof(*ctx), GFP_KERNEL);
+ if (!ctx)
+ return ERR_PTR(-ENOMEM);
+
+ ctx->dev = dev;
+ ctx->pas_id = pas_id;
+ ctx->mem_phys = mem_phys;
+ ctx->mem_size = mem_size;
+
+ return ctx;
+}
+EXPORT_SYMBOL_GPL(devm_qcom_scm_pas_context_alloc);
+
/**
* qcom_scm_pas_init_image() - Initialize peripheral authentication service
* state machine for a given peripheral, using the
diff --git a/include/linux/firmware/qcom/qcom_scm.h b/include/linux/firmware/qcom/qcom_scm.h
index a13f703b16cd4..5045f8fe876da 100644
--- a/include/linux/firmware/qcom/qcom_scm.h
+++ b/include/linux/firmware/qcom/qcom_scm.h
@@ -72,6 +72,20 @@ struct qcom_scm_pas_metadata {
ssize_t size;
};
+struct qcom_scm_pas_context {
+ struct device *dev;
+ u32 pas_id;
+ phys_addr_t mem_phys;
+ size_t mem_size;
+ void *ptr;
+ dma_addr_t phys;
+ ssize_t size;
+};
+
+struct qcom_scm_pas_context *devm_qcom_scm_pas_context_alloc(struct device *dev,
+ u32 pas_id,
+ phys_addr_t mem_phys,
+ size_t mem_size);
int qcom_scm_pas_init_image(u32 pas_id, const void *metadata, size_t size,
struct qcom_scm_pas_metadata *ctx);
void qcom_scm_pas_metadata_release(struct qcom_scm_pas_metadata *ctx);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0599/1518] staging: rtl8723bs: use kfree_sensitive() for key material
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (597 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0598/1518] firmware: qcom_scm: Introduce PAS context allocator helper function Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0600/1518] fs/ntfs3: reject restart table growth beyond U16_MAX entries Greg Kroah-Hartman
` (399 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Ivy Lopez, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ivy Lopez <skunkolee@gmail.com>
[ Upstream commit d205dfa8cb825f1954ca1cfa474fc50bf06ee4aa ]
The set_stakey_parm struct contains a 16-byte encryption key.
Use kfree_sensitive() instead of kfree() to ensure the key
material is zeroed before the memory is freed, preventing
potential information leaks.
Fixes: 554c0a3abf21 ("staging: Add rtl8723bs sdio wifi driver")
Signed-off-by: Ivy Lopez <skunkolee@gmail.com>
Link: https://patch.msgid.link/20260717220135.17836-1-skunkolee@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/staging/rtl8723bs/core/rtw_cmd.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/drivers/staging/rtl8723bs/core/rtw_cmd.c b/drivers/staging/rtl8723bs/core/rtw_cmd.c
index 0091045f63f24..2701a80ad07de 100644
--- a/drivers/staging/rtl8723bs/core/rtw_cmd.c
+++ b/drivers/staging/rtl8723bs/core/rtw_cmd.c
@@ -889,7 +889,7 @@ u8 rtw_setstakey_cmd(struct adapter *padapter, struct sta_info *sta, u8 unicast_
if (enqueue) {
ph2c = kzalloc(sizeof(*ph2c), GFP_KERNEL);
if (!ph2c) {
- kfree(psetstakey_para);
+ kfree_sensitive(psetstakey_para);
res = _FAIL;
goto exit;
}
@@ -897,7 +897,7 @@ u8 rtw_setstakey_cmd(struct adapter *padapter, struct sta_info *sta, u8 unicast_
psetstakey_rsp = kzalloc(sizeof(*psetstakey_rsp), GFP_KERNEL);
if (!psetstakey_rsp) {
kfree(ph2c);
- kfree(psetstakey_para);
+ kfree_sensitive(psetstakey_para);
res = _FAIL;
goto exit;
}
@@ -908,7 +908,7 @@ u8 rtw_setstakey_cmd(struct adapter *padapter, struct sta_info *sta, u8 unicast_
res = rtw_enqueue_cmd(pcmdpriv, ph2c);
} else {
set_stakey_hdl(padapter, (u8 *)psetstakey_para);
- kfree(psetstakey_para);
+ kfree_sensitive(psetstakey_para);
}
exit:
return res;
@@ -948,7 +948,7 @@ u8 rtw_clearstakey_cmd(struct adapter *padapter, struct sta_info *sta, u8 enqueu
psetstakey_rsp = kzalloc(sizeof(*psetstakey_rsp), GFP_KERNEL);
if (!psetstakey_rsp) {
kfree(ph2c);
- kfree(psetstakey_para);
+ kfree_sensitive(psetstakey_para);
res = _FAIL;
goto exit;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0600/1518] fs/ntfs3: reject restart table growth beyond U16_MAX entries
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (598 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0599/1518] staging: rtl8723bs: use kfree_sensitive() for key material Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0601/1518] iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized Greg Kroah-Hartman
` (398 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Xiang Mei, Weiming Shi,
Konstantin Komarov, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Weiming Shi <bestswngs@gmail.com>
[ Upstream commit 111f8d74a19d85942ecbb3aba78f6f3c88e59391 ]
During $LogFile replay, log_replay() indexes the transaction table by the
transact_id taken from the log record header. check_log_rec() only
verifies that transact_id is non-zero and properly aligned, not its
magnitude, so a crafted image can request an arbitrarily large index.
alloc_rsttbl_from_idx() grows the table to cover that index via
extend_rsttbl(), which passes the new entry count to init_rsttbl():
rt = init_rsttbl(esize, used + add);
used + add is computed as u32 but init_rsttbl() takes a u16, and the
count is stored in struct RESTART_TABLE as a __le16. When used + add
exceeds U16_MAX it is truncated, init_rsttbl() allocates a table far
smaller than the index requires, and alloc_rsttbl_from_idx() then
dereferences and writes at the original, untruncated offset -- an
out-of-bounds access past the allocation, reachable by mounting a
crafted NTFS image.
BUG: KASAN: use-after-free in alloc_rsttbl_from_idx (fs/ntfs3/fslog.c:950)
Read of size 4 at addr ffff8880327ffff8 by task exploit
alloc_rsttbl_from_idx (fs/ntfs3/fslog.c:950)
log_replay (fs/ntfs3/fslog.c:4562)
ntfs_loadlog_and_replay (fs/ntfs3/fsntfs.c:324)
ntfs_fill_super (fs/ntfs3/super.c:1393)
get_tree_bdev_flags
vfs_get_tree
path_mount
__x64_sys_mount
A restart table is limited to U16_MAX entries by its __le16 count, so a
larger growth request is invalid input. Reject it in extend_rsttbl();
all callers already handle a NULL return.
Fixes: b46acd6a6a62 ("fs/ntfs3: Add NTFS journal")
Reported-by: Xiang Mei <xmei5@asu.edu>
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Weiming Shi <bestswngs@gmail.com>
Signed-off-by: Konstantin Komarov <almaz.alexandrovich@paragon-software.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ntfs3/fslog.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/fs/ntfs3/fslog.c b/fs/ntfs3/fslog.c
index 5437dc78209e5..5d66a5c3b507a 100644
--- a/fs/ntfs3/fslog.c
+++ b/fs/ntfs3/fslog.c
@@ -875,6 +875,9 @@ static inline struct RESTART_TABLE *extend_rsttbl(struct RESTART_TABLE *tbl,
u32 used = le16_to_cpu(tbl->used);
struct RESTART_TABLE *rt;
+ if (used + add > U16_MAX)
+ return NULL;
+
rt = init_rsttbl(esize, used + add);
if (!rt)
return NULL;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0601/1518] iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (599 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0600/1518] fs/ntfs3: reject restart table growth beyond U16_MAX entries Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0602/1518] iommu/tegra241-cmdqv: Synchronize the error ISR against VINTF (de)init Greg Kroah-Hartman
` (397 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Nicolin Chen, Will Deacon,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolin Chen <nicolinc@nvidia.com>
[ Upstream commit cbc41aacd49e695338940196e7084770365e1b68 ]
tegra241_vintf_init_lvcmdq() stores the freshly allocated vcmdq pointer to
the vintf->lvcmdqs[] array, before tegra241_vcmdq_alloc_smmu_cmdq() builds
the vcmdq->cmdq. The error ISR dereferences that cmdq, so a latched LVCMDQ
error (e.g. one inherited across a kexec) firing in this window would make
tegra241_vintf0_handle_error() pass the still-zeroed arm_smmu_cmdq down to
__arm_smmu_cmdq_skip_err(), dereferencing NULL queue register pointers.
Drop the store from tegra241_vintf_init_lvcmdq() and publish the vcmdq at
the end of the allocation instead, with an smp_store_release() that pairs
with an smp_load_acquire() in the ISR, which can see a fully built LVCMDQ
or NULL.
The user-owned LVCMDQ allocation moves accordingly, publishing the vcmdq
once tegra241_vcmdq_hw_init_user() succeeds, using a plain store since a
user VINTF's lvcmdqs[] has no lockless reader -- the error ISR only walks
the VINTF0 array.
Fixes: 918eb5c856f6 ("iommu/arm-smmu-v3: Add in-kernel support for NVIDIA Tegra241 (Grace) CMDQV")
Assisted-by: Claude:claude-fable-5
Signed-off-by: Nicolin Chen <nicolinc@nvidia.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../iommu/arm/arm-smmu-v3/tegra241-cmdqv.c | 25 +++++++++++++------
1 file changed, 17 insertions(+), 8 deletions(-)
diff --git a/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c b/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c
index cee489855311c..3c4465289b44a 100644
--- a/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c
+++ b/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c
@@ -322,12 +322,19 @@ static void tegra241_vintf0_handle_error(struct tegra241_vintf *vintf)
while (map) {
unsigned long lidx = __ffs64(map);
- struct tegra241_vcmdq *vcmdq = vintf->lvcmdqs[lidx];
- u32 gerror = readl_relaxed(REG_VCMDQ_PAGE0(vcmdq, GERROR));
+ struct tegra241_vcmdq *vcmdq;
+ u32 gerror;
+ map &= ~BIT_ULL(lidx);
+
+ /* Pairs with smp_store_release() publishing it */
+ vcmdq = smp_load_acquire(&vintf->lvcmdqs[lidx]);
+ if (!vcmdq)
+ continue;
+
+ gerror = readl_relaxed(REG_VCMDQ_PAGE0(vcmdq, GERROR));
__arm_smmu_cmdq_skip_err(&vintf->cmdqv->smmu, &vcmdq->cmdq);
writel(gerror, REG_VCMDQ_PAGE0(vcmdq, GERRORN));
- map &= ~BIT_ULL(lidx);
}
}
}
@@ -670,7 +677,6 @@ static int tegra241_vintf_init_lvcmdq(struct tegra241_vintf *vintf, u16 lidx,
vcmdq->page0 = cmdqv->base + TEGRA241_VINTFi_LVCMDQ_PAGE0(idx, lidx);
vcmdq->page1 = cmdqv->base + TEGRA241_VINTFi_LVCMDQ_PAGE1(idx, lidx);
- vintf->lvcmdqs[lidx] = vcmdq;
return 0;
}
@@ -709,14 +715,15 @@ tegra241_vintf_alloc_lvcmdq(struct tegra241_vintf *vintf, u16 lidx)
/* Build an arm_smmu_cmdq for each LVCMDQ */
ret = tegra241_vcmdq_alloc_smmu_cmdq(vcmdq);
if (ret)
- goto deinit_lvcmdq;
+ goto free_vcmdq;
+
+ /* Pairs with the smp_load_acquire() in the error ISR */
+ smp_store_release(&vintf->lvcmdqs[lidx], vcmdq);
dev_dbg(cmdqv->dev,
"%sallocated\n", lvcmdq_error_header(vcmdq, header, 64));
return vcmdq;
-deinit_lvcmdq:
- tegra241_vintf_deinit_lvcmdq(vintf, lidx);
free_vcmdq:
kfree(vcmdq);
return ERR_PTR(ret);
@@ -1202,13 +1209,15 @@ static int tegra241_vintf_alloc_lvcmdq_user(struct iommufd_hw_queue *hw_queue,
if (ret)
goto unmap_lvcmdq;
+ /* No lockless reader of a user VINTF's lvcmdqs[]; mutex-serialized */
+ vintf->lvcmdqs[lidx] = vcmdq;
+
hw_queue->destroy = &tegra241_vintf_destroy_lvcmdq_user;
mutex_unlock(&vintf->lvcmdq_mutex);
return 0;
unmap_lvcmdq:
tegra241_vcmdq_unmap_lvcmdq(vcmdq);
- tegra241_vintf_deinit_lvcmdq(vintf, lidx);
undepend_vcmdq:
if (vcmdq->prev)
iommufd_hw_queue_undepend(vcmdq, vcmdq->prev, core);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0602/1518] iommu/tegra241-cmdqv: Synchronize the error ISR against VINTF (de)init
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (600 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0601/1518] iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0603/1518] iommu/tegra241-cmdqv: Dont run the error ISR before probe sets up vintfs Greg Kroah-Hartman
` (396 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Nicolin Chen, Will Deacon,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolin Chen <nicolinc@nvidia.com>
[ Upstream commit a491be376abd1c80a314cdd658632c85cd660b73 ]
A user VINTF is torn down by tegra241_cmdqv_deinit_vintf(), which runs from
the destroy callback and from the init-failure unwind in the alloc handler.
It clears the cmdqv->vintfs[] slot and lets the iommufd core free it, but
nothing serializes that against the error interrupt: tegra241_cmdqv_isr()
reads cmdqv->vintfs[idx] and dereferences the vintf. A concurrent error can
make the ISR read a slot mid-clear (a NULL deref) or use a vintf which is
about to be freed (a use-after-free).
deinit_vintf() also returns idx to the IDA before clearing the slot, so a
concurrent create that reuses idx can publish its new vintf into the slot,
only for this teardown to erase it again with the stale NULL store.
On the other end, tegra241_cmdqv_init_vintf() publishes a new vintf with a
plain store to the cmdqv->vintfs[] slot, and the ISR dereferences fields of
a published vintf such as vintf->base. A plain store gives no ordering on a
weakly-ordered CPU, and a stale VINTF_ERR_MAP bit on a reused idx can make
the ISR pick a vintf the moment it is published, before its fields are set
or tegra241_vintf_hw_init() runs.
The cmdqv->vintfs[0] slot stays NULL until tegra241_cmdqv_init_structures()
first creates VINTF0, so the slot 0 read needs the same NULL check.
Publish every slot with an smp_store_release(), and read each slot in the
ISR with an smp_load_acquire() under a NULL check, so the ISR always sees
a fully built vintf or NULL. Also make deinit_vintf() clear the slot, and
synchronize_irq() prior to returning idx to the IDA, so no vintf is freed
under a running handler and no reused idx is clobbered.
Fixes: 4dc0d12474f9 ("iommu/tegra241-cmdqv: Add user-space use support")
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Nicolin Chen <nicolinc@nvidia.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../iommu/arm/arm-smmu-v3/tegra241-cmdqv.c | 37 +++++++++++++++++--
1 file changed, 33 insertions(+), 4 deletions(-)
diff --git a/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c b/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c
index 3c4465289b44a..c9f6729c98588 100644
--- a/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c
+++ b/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c
@@ -339,6 +339,13 @@ static void tegra241_vintf0_handle_error(struct tegra241_vintf *vintf)
}
}
+/*
+ * The CMDQV error interrupt is edge-triggered, so a pending VINTF error fires
+ * this ISR once and does not re-assert. An unacked guest therefore cannot
+ * storm the host. The HW latches and forwards each new error event on its
+ * own, so an already-set ERR_MAP bit does not suppress the interrupt for a
+ * new error.
+ */
static irqreturn_t tegra241_cmdqv_isr(int irq, void *devid)
{
struct tegra241_cmdqv *cmdqv = (struct tegra241_cmdqv *)devid;
@@ -361,16 +368,27 @@ static irqreturn_t tegra241_cmdqv_isr(int irq, void *devid)
/* Handle VINTF0 and its LVCMDQs */
if (vintf_map & BIT_ULL(0)) {
- tegra241_vintf0_handle_error(cmdqv->vintfs[0]);
+ struct tegra241_vintf *vintf0;
+
vintf_map &= ~BIT_ULL(0);
+
+ /* NULL until tegra241_cmdqv_init_structures() publishes it */
+ vintf0 = smp_load_acquire(&cmdqv->vintfs[0]);
+ if (vintf0)
+ tegra241_vintf0_handle_error(vintf0);
}
/* Handle other user VINTFs and their LVCMDQs */
while (vintf_map) {
unsigned long idx = __ffs64(vintf_map);
+ struct tegra241_vintf *vintf;
- tegra241_vintf_user_handle_error(cmdqv->vintfs[idx]);
vintf_map &= ~BIT_ULL(idx);
+
+ /* The slot may be published or torn down (NULL'd) concurrently */
+ vintf = smp_load_acquire(&cmdqv->vintfs[idx]);
+ if (vintf)
+ tegra241_vintf_user_handle_error(vintf);
}
return IRQ_HANDLED;
@@ -734,8 +752,18 @@ tegra241_vintf_alloc_lvcmdq(struct tegra241_vintf *vintf, u16 lidx)
static void tegra241_cmdqv_deinit_vintf(struct tegra241_cmdqv *cmdqv, u16 idx)
{
kfree(cmdqv->vintfs[idx]->lvcmdqs);
+ /*
+ * Clear the slot and drain any in-flight ISR before returning idx to
+ * the IDA, so a concurrent create that reuses idx cannot have its
+ * freshly published VINTF erased here. A plain WRITE_ONCE() suffices
+ * since clearing the slot publishes no data. This also covers the
+ * init-failure unwind, which reaches deinit_vintf() without the
+ * destroy callback.
+ */
+ WRITE_ONCE(cmdqv->vintfs[idx], NULL);
+ if (cmdqv->irq > 0)
+ synchronize_irq(cmdqv->irq);
ida_free(&cmdqv->vintf_ids, idx);
- cmdqv->vintfs[idx] = NULL;
}
static int tegra241_cmdqv_init_vintf(struct tegra241_cmdqv *cmdqv, u16 max_idx,
@@ -761,7 +789,8 @@ static int tegra241_cmdqv_init_vintf(struct tegra241_cmdqv *cmdqv, u16 max_idx,
return -ENOMEM;
}
- cmdqv->vintfs[idx] = vintf;
+ /* Pairs with the smp_load_acquire() in tegra241_cmdqv_isr() */
+ smp_store_release(&cmdqv->vintfs[idx], vintf);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0603/1518] iommu/tegra241-cmdqv: Dont run the error ISR before probe sets up vintfs
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (601 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0602/1518] iommu/tegra241-cmdqv: Synchronize the error ISR against VINTF (de)init Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0604/1518] iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs Greg Kroah-Hartman
` (395 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Nicolin Chen, Will Deacon,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolin Chen <nicolinc@nvidia.com>
[ Upstream commit 5acd67ceb38debe2fbf70ea35e2dec9f7ab01bbd ]
__tegra241_cmdqv_probe() requests the error IRQ before it has allocated the
cmdqv->vintfs array and set cmdqv->num_vintfs. A CMDQV left enabled with a
latched error across a kexec fires the IRQ as soon as it is requested, and
tegra241_cmdqv_isr() then walks the uninitialized cmdqv->vintfs array.
Request the IRQ only after cmdqv->vintfs is allocated and zeroed, so that
a latched interrupt firing early runs the ISR against a valid array of NULL
slots that it safely skips.
Fixes: 918eb5c856f6 ("iommu/arm-smmu-v3: Add in-kernel support for NVIDIA Tegra241 (Grace) CMDQV")
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Nicolin Chen <nicolinc@nvidia.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../iommu/arm/arm-smmu-v3/tegra241-cmdqv.c | 34 +++++++++++--------
1 file changed, 19 insertions(+), 15 deletions(-)
diff --git a/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c b/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c
index c9f6729c98588..b614fd5ee7219 100644
--- a/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c
+++ b/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c
@@ -1042,17 +1042,6 @@ __tegra241_cmdqv_probe(struct arm_smmu_device *smmu, struct resource *res,
cmdqv->dev = smmu->impl_dev;
cmdqv->base_phys = res->start;
- if (cmdqv->irq > 0) {
- ret = request_threaded_irq(irq, NULL, tegra241_cmdqv_isr,
- IRQF_ONESHOT, "tegra241-cmdqv",
- cmdqv);
- if (ret) {
- dev_err(cmdqv->dev, "failed to request irq (%d): %d\n",
- cmdqv->irq, ret);
- goto iounmap;
- }
- }
-
regval = readl_relaxed(REG_CMDQV(cmdqv, PARAM));
cmdqv->num_vintfs = 1 << FIELD_GET(CMDQV_NUM_VINTF_LOG2, regval);
cmdqv->num_vcmdqs = 1 << FIELD_GET(CMDQV_NUM_VCMDQ_LOG2, regval);
@@ -1063,10 +1052,25 @@ __tegra241_cmdqv_probe(struct arm_smmu_device *smmu, struct resource *res,
cmdqv->vintfs =
kcalloc(cmdqv->num_vintfs, sizeof(*cmdqv->vintfs), GFP_KERNEL);
if (!cmdqv->vintfs)
- goto free_irq;
+ goto iounmap;
ida_init(&cmdqv->vintf_ids);
+ /*
+ * Request the IRQ only after cmdqv->vintfs is allocated and zeroed, so
+ * the ISR would not walk an uninitialized array.
+ */
+ if (cmdqv->irq > 0) {
+ ret = request_threaded_irq(irq, NULL, tegra241_cmdqv_isr,
+ IRQF_ONESHOT, "tegra241-cmdqv",
+ cmdqv);
+ if (ret) {
+ dev_err(cmdqv->dev, "failed to request irq (%d): %d\n",
+ cmdqv->irq, ret);
+ goto free_vintfs;
+ }
+ }
+
#ifdef CONFIG_IOMMU_DEBUGFS
if (!cmdqv_debugfs_dir) {
cmdqv_debugfs_dir =
@@ -1081,9 +1085,9 @@ __tegra241_cmdqv_probe(struct arm_smmu_device *smmu, struct resource *res,
return new_smmu;
-free_irq:
- if (cmdqv->irq > 0)
- free_irq(cmdqv->irq, cmdqv);
+free_vintfs:
+ ida_destroy(&cmdqv->vintf_ids);
+ kfree(cmdqv->vintfs);
iounmap:
iounmap(base);
return NULL;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0604/1518] iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (602 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0603/1518] iommu/tegra241-cmdqv: Dont run the error ISR before probe sets up vintfs Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0605/1518] iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID Greg Kroah-Hartman
` (394 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Nicolin Chen, Will Deacon,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolin Chen <nicolinc@nvidia.com>
[ Upstream commit 61f0d437988e5730b04442f6a7d30a9907339f2a ]
tegra241_cmdqv_remove() tears each VINTF down first, then calls free_irq().
Tearing a VINTF down frees vintf0 and clears cmdqv->vintfs[0]. An error in
that window makes tegra241_cmdqv_isr() read the stale slot and hand it to
tegra241_vintf0_handle_error(), which dereferences a NULL or freed pointer.
Free the IRQ before tearing the VINTFs down. free_irq() waits for in-flight
handlers to finish and blocks new ones, so no ISR can observe a VINTF as it
is torn down.
Note: a user-owned VINTF (viommu) could outlive this teardown, which unmaps
cmdqv->base and frees cmdqv->vintfs, so a later viommu close then touches
freed memory. This is neither introduced nor fixed here: a physical IOMMU
is not a pluggable device, so iommufd by design holds no reference on the
one behind a viommu, and this teardown is not expected while that viommu is
still alive.
Fixes: 918eb5c856f6 ("iommu/arm-smmu-v3: Add in-kernel support for NVIDIA Tegra241 (Grace) CMDQV")
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Nicolin Chen <nicolinc@nvidia.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c b/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c
index b614fd5ee7219..5d5aa956e5b9f 100644
--- a/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c
+++ b/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c
@@ -834,6 +834,14 @@ static void tegra241_cmdqv_remove(struct arm_smmu_device *smmu)
container_of(smmu, struct tegra241_cmdqv, smmu);
u16 idx;
+ /*
+ * Free the IRQ before tearing down the VINTFs. free_irq() waits for any
+ * in-flight tegra241_cmdqv_isr() to finish and blocks new ones, so the
+ * ISR cannot dereference a VINTF that is freed by the loop below.
+ */
+ if (cmdqv->irq > 0)
+ free_irq(cmdqv->irq, cmdqv);
+
/* Remove VINTF resources */
for (idx = 0; idx < cmdqv->num_vintfs; idx++) {
if (cmdqv->vintfs[idx]) {
@@ -846,8 +854,6 @@ static void tegra241_cmdqv_remove(struct arm_smmu_device *smmu)
/* Remove cmdqv resources */
ida_destroy(&cmdqv->vintf_ids);
- if (cmdqv->irq > 0)
- free_irq(cmdqv->irq, cmdqv);
iounmap(cmdqv->base);
kfree(cmdqv->vintfs);
put_device(cmdqv->dev); /* smmu->impl_dev */
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0605/1518] iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (603 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0604/1518] iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0606/1518] iommu/tegra241-cmdqv: Fix VINTF0 leak on the init-failure path Greg Kroah-Hartman
` (393 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Nicolin Chen, Will Deacon,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolin Chen <nicolinc@nvidia.com>
[ Upstream commit fb292bfc9be936dade7eef7ec5762de1201983d8 ]
tegra241_vintf_init_vsid() maps a guest vSID to a single physical Stream ID
taken from master->streams[0], and only warns when the device does not have
exactly one stream. A device with several streams gets only its first one
mapped, so a guest vSID invalidation cannot reach the others' ATC and IOTLB
entries; a device with none makes master->streams a ZERO_SIZE_PTR, read out
of bounds.
Reject the mapping with -EOPNOTSUPP if master->num_streams is not one.
Fixes: 4dc0d12474f9 ("iommu/tegra241-cmdqv: Add user-space use support")
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Nicolin Chen <nicolinc@nvidia.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c b/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c
index 5d5aa956e5b9f..29aa7acd194b9 100644
--- a/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c
+++ b/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c
@@ -1302,7 +1302,8 @@ static int tegra241_vintf_init_vsid(struct iommufd_vdevice *vdev)
if (virt_sid > FIELD_MAX(VINTF_SID_MATCH_VIRT_SID))
return -EINVAL;
- WARN_ON_ONCE(master->num_streams != 1);
+ if (master->num_streams != 1)
+ return -EOPNOTSUPP;
/* Find an empty pair of SID_REPLACE and SID_MATCH */
sidx = ida_alloc_max(&vintf->sids, vintf->cmdqv->num_sids_per_vintf - 1,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0606/1518] iommu/tegra241-cmdqv: Fix VINTF0 leak on the init-failure path
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (604 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0605/1518] iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0607/1518] RDMA/rxe: Fix UAF in ODP init error-handling path Greg Kroah-Hartman
` (392 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Nicolin Chen, Will Deacon,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolin Chen <nicolinc@nvidia.com>
[ Upstream commit f40f3144477314b489e4bc209c06cb51679fe82b ]
tegra241_cmdqv_init_structures() allocates VINTF0 with kzalloc_obj(), inits
it, and preallocates its logical VCMDQs. Two of its error paths leak.
When tegra241_cmdqv_init_vintf() fails it returns before VINTF0 reaches the
cmdqv->vintfs[] array, so the devres unwind on probe failure cannot reach
it; free it directly there.
A later VCMDQ preallocation failure instead leaves VINTF0 published, and so
this time the unwind does reach tegra241_cmdqv_remove_vintf(), which then
frees it from vintf->hyp_own. But tegra241_vintf_hw_init() sets that flag
only afterward, from a HW read-back, so the still-uninited VINTF0 reads as
guest-owned and leaks, with mutex_destroy() and ida_destroy() run on fields
it never set up.
Decide ownership from vintf->idx instead, the index assigned when its id is
allocated: idx 0 is the kernel-owned VINTF0, while idx >= 1 marks a guest
VINTF. So the in-kernel free decision in tegra241_cmdqv_remove_vintf() and
tegra241_vintf_free_lvcmdq() now keys on idx too, and hyp_own stays a pure
HW-readback state.
Fixes: 918eb5c856f6 ("iommu/arm-smmu-v3: Add in-kernel support for NVIDIA Tegra241 (Grace) CMDQV")
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Nicolin Chen <nicolinc@nvidia.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c b/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c
index 29aa7acd194b9..2b55a221c35a6 100644
--- a/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c
+++ b/drivers/iommu/arm/arm-smmu-v3/tegra241-cmdqv.c
@@ -710,7 +710,7 @@ static void tegra241_vintf_free_lvcmdq(struct tegra241_vintf *vintf, u16 lidx)
dev_dbg(vintf->cmdqv->dev,
"%sdeallocated\n", lvcmdq_error_header(vcmdq, header, 64));
/* Guest-owned VCMDQ is free-ed with hw_queue by iommufd core */
- if (vcmdq->vintf->hyp_own)
+ if (!vcmdq->vintf->idx)
kfree(vcmdq);
}
@@ -808,7 +808,7 @@ static void tegra241_cmdqv_remove_vintf(struct tegra241_cmdqv *cmdqv, u16 idx)
dev_dbg(cmdqv->dev, "VINTF%u: deallocated\n", vintf->idx);
tegra241_cmdqv_deinit_vintf(cmdqv, idx);
- if (!vintf->hyp_own) {
+ if (vintf->idx) {
mutex_destroy(&vintf->lvcmdq_mutex);
ida_destroy(&vintf->sids);
/* Guest-owned VINTF is free-ed with viommu by iommufd core */
@@ -988,6 +988,12 @@ static int tegra241_cmdqv_init_structures(struct arm_smmu_device *smmu)
ret = tegra241_cmdqv_init_vintf(cmdqv, 0, vintf);
if (ret) {
dev_err(cmdqv->dev, "failed to init vintf0: %d\n", ret);
+ /*
+ * tegra241_cmdqv_init_vintf() failed to publish the vintf0 to
+ * cmdqv->vintfs[], so the probe unwind path that goes through
+ * cmdqv->vintfs[] would miss it. Free it here.
+ */
+ kfree(vintf);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0607/1518] RDMA/rxe: Fix UAF in ODP init error-handling path
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (605 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0606/1518] iommu/tegra241-cmdqv: Fix VINTF0 leak on the init-failure path Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0608/1518] RDMA/efa: Fix PBL chunk length computation Greg Kroah-Hartman
` (391 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Peiyang He, Leon Romanovsky,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Peiyang He <peiyang_he@smail.nju.edu.cn>
[ Upstream commit 51f2c8d2c99fc1f452f7113c08a35edcc4bf8732 ]
rxe_odp_mr_init_user() stores &umem_odp->umem in mr->umem before
calling rxe_odp_init_pages(). If rxe_odp_init_pages() fails,
rxe_odp_mr_init_user() releases umem_odp and returns an error.
rxe_reg_user_mr() then unwinds the error through rxe_cleanup(),
rxe_mr_cleanup(), ib_umem_release(mr->umem). There is an
IS_ERR_OR_NULL(umem) check at the start of ib_umem_release().
But since mr->umem is NOT reset to NULL in the error handling
path of rxe_odp_mr_init_user(), the check passes and it reads
already-freed fields like umem->is_dmabuf, causing UAF.
Fix the UAF by clearing mr->umem after releasing the failed
ODP umem so the MR cleanup path does not release it again.
Fixes: d03fb5c6599e ("RDMA/rxe: Allow registering MRs for On-Demand Paging")
Assisted-by: Codex:gpt-5.6-sol
Signed-off-by: Peiyang He <peiyang_he@smail.nju.edu.cn>
Link: https://patch.msgid.link/70CB6DBCB19624C7+20260727050659.1543627-1-peiyang_he@smail.nju.edu.cn
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/sw/rxe/rxe_odp.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/infiniband/sw/rxe/rxe_odp.c b/drivers/infiniband/sw/rxe/rxe_odp.c
index 4d4e3b324dd29..16b3fbdf2f867 100644
--- a/drivers/infiniband/sw/rxe/rxe_odp.c
+++ b/drivers/infiniband/sw/rxe/rxe_odp.c
@@ -115,6 +115,7 @@ int rxe_odp_mr_init_user(struct rxe_dev *rxe, u64 start, u64 length,
err = rxe_odp_init_pages(mr);
if (err) {
ib_umem_odp_release(umem_odp);
+ mr->umem = NULL;
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0608/1518] RDMA/efa: Fix PBL chunk length computation
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (606 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0607/1518] RDMA/rxe: Fix UAF in ODP init error-handling path Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0609/1518] wifi: mac80211: fix per-STA profile length in cross-link CSA parsing Greg Kroah-Hartman
` (390 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Firas Jahjah, Michael Margolin,
Yonatan Nachum, Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yonatan Nachum <ynachum@amazon.com>
[ Upstream commit 229b42d7450c1cf96f45ec39ebb69211b06bc036 ]
On register MR, when creating the PBL, if it's an indirect PBL we create
a chunk list to hold the PBL pages pointers. Each chunk is 4KB in size
and can hold 510 addresses (EFA_PTRS_PER_CHUNK) and has a 12-byte
control buffer at the end of it holding the next chunk's pointer and its
length.
If the PBL number of pages is a multiple of EFA_PTRS_PER_CHUNK, the
calculated last chunk length is wrongly computed as 0, even though that
chunk is fully populated with 510 real page pointers. This wrong length
is used both to DMA map the chunk and is propagated to the device,
causing the device to see the chunk as empty and reject the memory
registration.
Fix the calculation so it will be performed only if the number of pages
isn't a multiple of EFA_PTRS_PER_CHUNK, if it is, its already handled in
the above loop correctly.
Also prevent out-of-bounds reach in the chunks array in such scenario.
Fixes: 40909f664d27 ("RDMA/efa: Add EFA verbs implementation")
Reviewed-by: Firas Jahjah <firasj@amazon.com>
Reviewed-by: Michael Margolin <mrgolin@amazon.com>
Signed-off-by: Yonatan Nachum <ynachum@amazon.com>
Link: https://patch.msgid.link/20260727090255.1175120-1-ynachum@amazon.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/efa/efa_verbs.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
diff --git a/drivers/infiniband/hw/efa/efa_verbs.c b/drivers/infiniband/hw/efa/efa_verbs.c
index 0bb3389d761f3..18db10741cee6 100644
--- a/drivers/infiniband/hw/efa/efa_verbs.c
+++ b/drivers/infiniband/hw/efa/efa_verbs.c
@@ -1392,9 +1392,11 @@ static int pbl_chunk_list_create(struct efa_dev *dev, struct pbl_context *pbl)
chunk_list->chunks[i].length = EFA_CHUNK_USED_SIZE;
}
- chunk_list->chunks[chunk_list_size - 1].length =
- ((page_cnt % EFA_PTRS_PER_CHUNK) * EFA_CHUNK_PAYLOAD_PTR_SIZE) +
- EFA_CHUNK_PTR_SIZE;
+
+ if (page_cnt % EFA_PTRS_PER_CHUNK != 0)
+ chunk_list->chunks[chunk_list_size - 1].length =
+ ((page_cnt % EFA_PTRS_PER_CHUNK) * EFA_CHUNK_PAYLOAD_PTR_SIZE) +
+ EFA_CHUNK_PTR_SIZE;
/* fill the dma addresses of sg list pages to chunks: */
chunk_idx = 0;
@@ -1406,9 +1408,12 @@ static int pbl_chunk_list_create(struct efa_dev *dev, struct pbl_context *pbl)
rdma_block_iter_dma_address(&biter);
if (payload_idx == EFA_PTRS_PER_CHUNK) {
+ payload_idx = 0;
chunk_idx++;
+ if (chunk_idx >= chunk_list_size)
+ break;
+
cur_chunk_buf = chunk_list->chunks[chunk_idx].buf;
- payload_idx = 0;
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0609/1518] wifi: mac80211: fix per-STA profile length in cross-link CSA parsing
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (607 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0608/1518] RDMA/efa: Fix PBL chunk length computation Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0610/1518] arm64: dts: allwinner: sun50i-a64-pinephone: Fix mpu6050 mount matrix Greg Kroah-Hartman
` (389 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zhao Li, Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhao Li <enderaoelyther@gmail.com>
[ Upstream commit 4a0bd262df757b25fc4e2a53c947317c119ced4e ]
ieee80211_mgd_check_cross_link_csa() starts parsing elements after the
fixed per-STA profile header and the STA Info field, but subtracts only
the STA Info length from the profile length. As a result,
ieee802_11_parse_elems() is given sizeof(*prof) == 3 bytes beyond the
current profile's element area, and data following the profile may be
interpreted as belonging to it.
Subtract the fixed profile header as well. The preceding
ieee80211_mle_basic_sta_prof_size_ok() check guarantees that the
corrected calculation cannot underflow, and
ieee80211_rx_uhr_link_reconfig_req() uses the same calculation.
The call site currently states that cross-link CSA parsing has no effect
because the broader parsing is still incorrect. This patch does not
address that broader problem; it only makes the per-STA profile parser
stop at the end of that profile. No production allocation over-read or
user-visible failure has been demonstrated.
Fixes: 7ef8f6821d16 ("wifi: mac80211: mlme: handle cross-link CSA")
Assisted-by: Codex:gpt-5.6-sol
Assisted-by: Kimi:K3
Signed-off-by: Zhao Li <enderaoelyther@gmail.com>
Link: https://patch.msgid.link/20260728111326.63087-1-enderaoelyther@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/mlme.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/mac80211/mlme.c b/net/mac80211/mlme.c
index 9ec4125c06d19..8d782c8782f98 100644
--- a/net/mac80211/mlme.c
+++ b/net/mac80211/mlme.c
@@ -7303,7 +7303,7 @@ ieee80211_mgd_check_cross_link_csa(struct ieee80211_sub_if_data *sdata,
prof = (void *)sta_profiles[link_id];
prof_elems = ieee802_11_parse_elems(prof->variable +
(prof->sta_info_len - 1),
- len -
+ len - sizeof(*prof) -
(prof->sta_info_len - 1),
false, NULL);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0610/1518] arm64: dts: allwinner: sun50i-a64-pinephone: Fix mpu6050 mount matrix
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (608 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0609/1518] wifi: mac80211: fix per-STA profile length in cross-link CSA parsing Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0611/1518] clk: tegra: tegra124-emc: put EMC node on register failure Greg Kroah-Hartman
` (388 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ondrej Jirman, Chen-Yu Tsai,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ondrej Jirman <megi@xff.cz>
[ Upstream commit dfc735fd93e4814e65894916ec5f807f25a391d1 ]
The current mount matrix for mpu6050 is wrong. The mount matrix is a
simple transform from the sensor coordinate space to the device
coordinate space described in DT, where, looking at the screen, X
points to the right, Y to the top, and Z towards the user.
The mpu6050 is mounted like this (looking at the screen from the
front; the sensor is on the near side of the PCB, so its Z axis
points towards the user; o marks the pin 1 corner):
+Xs
^
|
+------+
+Ys <--| |
| o |
+------+
so this gives:
Xd = -Ys [0, -1, 0]
Yd = Xs [1, 0, 0]
Zd = Zs [0, 0, 1]
Fixes: 2496b2aaacf1 ("arm64: dts: allwinner: pinephone: Add mount matrix to accelerometer")
Signed-off-by: Ondrej Jirman <megi@xff.cz>
Link: https://patch.msgid.link/20260725111909.2244868-1-megi@xff.cz
Signed-off-by: Chen-Yu Tsai <wens@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/allwinner/sun50i-a64-pinephone.dtsi | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/arm64/boot/dts/allwinner/sun50i-a64-pinephone.dtsi b/arch/arm64/boot/dts/allwinner/sun50i-a64-pinephone.dtsi
index 4bc6c1ef2cde4..f958bdbb0d333 100644
--- a/arch/arm64/boot/dts/allwinner/sun50i-a64-pinephone.dtsi
+++ b/arch/arm64/boot/dts/allwinner/sun50i-a64-pinephone.dtsi
@@ -230,8 +230,8 @@ accelerometer@68 {
interrupts = <7 5 IRQ_TYPE_EDGE_RISING>; /* PH5 */
vdd-supply = <®_dldo1>;
vddio-supply = <®_dldo1>;
- mount-matrix = "0", "1", "0",
- "-1", "0", "0",
+ mount-matrix = "0", "-1", "0",
+ "1", "0", "0",
"0", "0", "1";
};
};
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0611/1518] clk: tegra: tegra124-emc: put EMC node on register failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (609 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0610/1518] arm64: dts: allwinner: sun50i-a64-pinephone: Fix mpu6050 mount matrix Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0612/1518] clk: mediatek: Refactor pll registration to pass device Greg Kroah-Hartman
` (387 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Brian Masney,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
[ Upstream commit f726279f5eab813f9a8b6f38ddf2a4b062d038ff ]
tegra124_clk_register_emc() stores a device node reference returned by
of_parse_phandle() in tegra->emc_node.
If clk_register() fails, the function returns an error before that
reference can be consumed and released by the normal runtime path. The
tegra_clk_emc object is freed on this failure path, but freeing the
object does not drop the OF node reference stored in it.
Drop the EMC node reference before freeing the tegra_clk_emc object.
of_node_put() is safe for a NULL node, so this also covers the case where
the phandle is absent.
Fixes: 2db04f16b589 ("clk: tegra: Add EMC clock driver")
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Reviewed-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/tegra/clk-tegra124-emc.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/clk/tegra/clk-tegra124-emc.c b/drivers/clk/tegra/clk-tegra124-emc.c
index 5f1af6dfe7154..674aef2785394 100644
--- a/drivers/clk/tegra/clk-tegra124-emc.c
+++ b/drivers/clk/tegra/clk-tegra124-emc.c
@@ -539,6 +539,7 @@ struct clk *tegra124_clk_register_emc(void __iomem *base, struct device_node *np
clk = clk_register(NULL, &tegra->hw);
if (IS_ERR(clk)) {
+ of_node_put(tegra->emc_node);
kfree(tegra);
return clk;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0612/1518] clk: mediatek: Refactor pll registration to pass device
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (610 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0611/1518] clk: tegra: tegra124-emc: put EMC node on register failure Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0613/1518] clk: mediatek: Pass device to clk_hw_register for PLLs Greg Kroah-Hartman
` (386 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, AngeloGioacchino Del Regno,
Chen-Yu Tsai, Nicolas Frattaroli, Stephen Boyd, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolas Frattaroli <nicolas.frattaroli@collabora.com>
[ Upstream commit c9ced38af56fe6411118c6bc6522eab80849326d ]
As it stands, mtk_clk_register_plls takes a struct device_node pointer
as its first argument. This is a tragic happenstance, as it's trivial to
get the device_node from a struct device, but the opposite not so much.
The struct device is a much more useful thing to have passed down.
Refactor mtk_clk_register_plls to take a struct device pointer instead
of a struct device_node pointer, and fix up all users of this function.
Reviewed-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
Reviewed-by: Chen-Yu Tsai <wenst@chromium.org>
Signed-off-by: Nicolas Frattaroli <nicolas.frattaroli@collabora.com>
Signed-off-by: Stephen Boyd <sboyd@kernel.org>
Stable-dep-of: 540d91480bcb ("clk: mediatek: pllfh: Fix IO remapping leak in register_pllfhs error path")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/mediatek/clk-mt2701.c | 2 +-
drivers/clk/mediatek/clk-mt2712-apmixedsys.c | 2 +-
drivers/clk/mediatek/clk-mt6735-apmixedsys.c | 4 ++--
drivers/clk/mediatek/clk-mt6765.c | 2 +-
drivers/clk/mediatek/clk-mt6779.c | 2 +-
drivers/clk/mediatek/clk-mt6797.c | 2 +-
drivers/clk/mediatek/clk-mt7622-apmixedsys.c | 2 +-
drivers/clk/mediatek/clk-mt7629.c | 2 +-
drivers/clk/mediatek/clk-mt7981-apmixed.c | 2 +-
drivers/clk/mediatek/clk-mt7986-apmixed.c | 2 +-
drivers/clk/mediatek/clk-mt7988-apmixed.c | 2 +-
drivers/clk/mediatek/clk-mt8135-apmixedsys.c | 3 ++-
drivers/clk/mediatek/clk-mt8167-apmixedsys.c | 2 +-
drivers/clk/mediatek/clk-mt8183-apmixedsys.c | 2 +-
drivers/clk/mediatek/clk-mt8188-apmixedsys.c | 2 +-
drivers/clk/mediatek/clk-mt8195-apusys_pll.c | 3 ++-
drivers/clk/mediatek/clk-mt8196-apmixedsys.c | 3 ++-
drivers/clk/mediatek/clk-mt8196-mcu.c | 2 +-
drivers/clk/mediatek/clk-mt8196-mfg.c | 2 +-
drivers/clk/mediatek/clk-mt8196-vlpckgen.c | 2 +-
drivers/clk/mediatek/clk-mt8365-apmixedsys.c | 2 +-
drivers/clk/mediatek/clk-mt8516-apmixedsys.c | 2 +-
drivers/clk/mediatek/clk-pll.c | 7 ++++---
drivers/clk/mediatek/clk-pll.h | 10 ++++------
24 files changed, 34 insertions(+), 32 deletions(-)
diff --git a/drivers/clk/mediatek/clk-mt2701.c b/drivers/clk/mediatek/clk-mt2701.c
index 1e88ad8b93f44..d9f40fda73d1a 100644
--- a/drivers/clk/mediatek/clk-mt2701.c
+++ b/drivers/clk/mediatek/clk-mt2701.c
@@ -978,7 +978,7 @@ static int mtk_apmixedsys_init(struct platform_device *pdev)
if (!clk_data)
return -ENOMEM;
- mtk_clk_register_plls(node, apmixed_plls, ARRAY_SIZE(apmixed_plls),
+ mtk_clk_register_plls(&pdev->dev, apmixed_plls, ARRAY_SIZE(apmixed_plls),
clk_data);
mtk_clk_register_factors(apmixed_fixed_divs, ARRAY_SIZE(apmixed_fixed_divs),
clk_data);
diff --git a/drivers/clk/mediatek/clk-mt2712-apmixedsys.c b/drivers/clk/mediatek/clk-mt2712-apmixedsys.c
index a60622d251ff3..54b18e9f83f8f 100644
--- a/drivers/clk/mediatek/clk-mt2712-apmixedsys.c
+++ b/drivers/clk/mediatek/clk-mt2712-apmixedsys.c
@@ -119,7 +119,7 @@ static int clk_mt2712_apmixed_probe(struct platform_device *pdev)
if (!clk_data)
return -ENOMEM;
- r = mtk_clk_register_plls(node, plls, ARRAY_SIZE(plls), clk_data);
+ r = mtk_clk_register_plls(&pdev->dev, plls, ARRAY_SIZE(plls), clk_data);
if (r)
goto free_clk_data;
diff --git a/drivers/clk/mediatek/clk-mt6735-apmixedsys.c b/drivers/clk/mediatek/clk-mt6735-apmixedsys.c
index be51b97cab1f3..b6eb6a581c31e 100644
--- a/drivers/clk/mediatek/clk-mt6735-apmixedsys.c
+++ b/drivers/clk/mediatek/clk-mt6735-apmixedsys.c
@@ -93,8 +93,8 @@ static int clk_mt6735_apmixed_probe(struct platform_device *pdev)
return -ENOMEM;
platform_set_drvdata(pdev, clk_data);
- ret = mtk_clk_register_plls(pdev->dev.of_node, apmixedsys_plls,
- ARRAY_SIZE(apmixedsys_plls), clk_data);
+ ret = mtk_clk_register_plls(&pdev->dev, apmixedsys_plls,
+ ARRAY_SIZE(apmixedsys_plls), clk_data);
if (ret) {
dev_err(&pdev->dev, "Failed to register PLLs: %d\n", ret);
return ret;
diff --git a/drivers/clk/mediatek/clk-mt6765.c b/drivers/clk/mediatek/clk-mt6765.c
index d53731e7933f4..60f6f9fa7dcf2 100644
--- a/drivers/clk/mediatek/clk-mt6765.c
+++ b/drivers/clk/mediatek/clk-mt6765.c
@@ -740,7 +740,7 @@ static int clk_mt6765_apmixed_probe(struct platform_device *pdev)
if (!clk_data)
return -ENOMEM;
- mtk_clk_register_plls(node, plls, ARRAY_SIZE(plls), clk_data);
+ mtk_clk_register_plls(&pdev->dev, plls, ARRAY_SIZE(plls), clk_data);
mtk_clk_register_gates(&pdev->dev, node, apmixed_clks,
ARRAY_SIZE(apmixed_clks), clk_data);
diff --git a/drivers/clk/mediatek/clk-mt6779.c b/drivers/clk/mediatek/clk-mt6779.c
index 86732f5acf934..4b9dcb910b03f 100644
--- a/drivers/clk/mediatek/clk-mt6779.c
+++ b/drivers/clk/mediatek/clk-mt6779.c
@@ -1220,7 +1220,7 @@ static int clk_mt6779_apmixed_probe(struct platform_device *pdev)
if (!clk_data)
return -ENOMEM;
- mtk_clk_register_plls(node, plls, ARRAY_SIZE(plls), clk_data);
+ mtk_clk_register_plls(&pdev->dev, plls, ARRAY_SIZE(plls), clk_data);
mtk_clk_register_gates(&pdev->dev, node, apmixed_clks,
ARRAY_SIZE(apmixed_clks), clk_data);
diff --git a/drivers/clk/mediatek/clk-mt6797.c b/drivers/clk/mediatek/clk-mt6797.c
index fb59e71af58e3..ebf850ac57f54 100644
--- a/drivers/clk/mediatek/clk-mt6797.c
+++ b/drivers/clk/mediatek/clk-mt6797.c
@@ -655,7 +655,7 @@ static int mtk_apmixedsys_init(struct platform_device *pdev)
if (!clk_data)
return -ENOMEM;
- mtk_clk_register_plls(node, plls, ARRAY_SIZE(plls), clk_data);
+ mtk_clk_register_plls(&pdev->dev, plls, ARRAY_SIZE(plls), clk_data);
return of_clk_add_hw_provider(node, of_clk_hw_onecell_get, clk_data);
}
diff --git a/drivers/clk/mediatek/clk-mt7622-apmixedsys.c b/drivers/clk/mediatek/clk-mt7622-apmixedsys.c
index 2350592d9a934..8a29eaab0cfcb 100644
--- a/drivers/clk/mediatek/clk-mt7622-apmixedsys.c
+++ b/drivers/clk/mediatek/clk-mt7622-apmixedsys.c
@@ -96,7 +96,7 @@ static int clk_mt7622_apmixed_probe(struct platform_device *pdev)
if (!clk_data)
return -ENOMEM;
- ret = mtk_clk_register_plls(node, plls, ARRAY_SIZE(plls), clk_data);
+ ret = mtk_clk_register_plls(dev, plls, ARRAY_SIZE(plls), clk_data);
if (ret)
return ret;
diff --git a/drivers/clk/mediatek/clk-mt7629.c b/drivers/clk/mediatek/clk-mt7629.c
index baf94e7bea373..e154771b1b8bb 100644
--- a/drivers/clk/mediatek/clk-mt7629.c
+++ b/drivers/clk/mediatek/clk-mt7629.c
@@ -634,7 +634,7 @@ static int mtk_apmixedsys_init(struct platform_device *pdev)
if (!clk_data)
return -ENOMEM;
- mtk_clk_register_plls(node, plls, ARRAY_SIZE(plls),
+ mtk_clk_register_plls(&pdev->dev, plls, ARRAY_SIZE(plls),
clk_data);
mtk_clk_register_gates(&pdev->dev, node, apmixed_clks,
diff --git a/drivers/clk/mediatek/clk-mt7981-apmixed.c b/drivers/clk/mediatek/clk-mt7981-apmixed.c
index e8211eb4e09e1..6606b54fb3769 100644
--- a/drivers/clk/mediatek/clk-mt7981-apmixed.c
+++ b/drivers/clk/mediatek/clk-mt7981-apmixed.c
@@ -76,7 +76,7 @@ static int clk_mt7981_apmixed_probe(struct platform_device *pdev)
if (!clk_data)
return -ENOMEM;
- mtk_clk_register_plls(node, plls, ARRAY_SIZE(plls), clk_data);
+ mtk_clk_register_plls(&pdev->dev, plls, ARRAY_SIZE(plls), clk_data);
r = of_clk_add_hw_provider(node, of_clk_hw_onecell_get, clk_data);
if (r) {
diff --git a/drivers/clk/mediatek/clk-mt7986-apmixed.c b/drivers/clk/mediatek/clk-mt7986-apmixed.c
index 93751abe6be89..1c79418d08a77 100644
--- a/drivers/clk/mediatek/clk-mt7986-apmixed.c
+++ b/drivers/clk/mediatek/clk-mt7986-apmixed.c
@@ -74,7 +74,7 @@ static int clk_mt7986_apmixed_probe(struct platform_device *pdev)
if (!clk_data)
return -ENOMEM;
- mtk_clk_register_plls(node, plls, ARRAY_SIZE(plls), clk_data);
+ mtk_clk_register_plls(&pdev->dev, plls, ARRAY_SIZE(plls), clk_data);
r = of_clk_add_hw_provider(node, of_clk_hw_onecell_get, clk_data);
if (r) {
diff --git a/drivers/clk/mediatek/clk-mt7988-apmixed.c b/drivers/clk/mediatek/clk-mt7988-apmixed.c
index 63d33a78cb488..416a4b88d100b 100644
--- a/drivers/clk/mediatek/clk-mt7988-apmixed.c
+++ b/drivers/clk/mediatek/clk-mt7988-apmixed.c
@@ -86,7 +86,7 @@ static int clk_mt7988_apmixed_probe(struct platform_device *pdev)
if (!clk_data)
return -ENOMEM;
- r = mtk_clk_register_plls(node, plls, ARRAY_SIZE(plls), clk_data);
+ r = mtk_clk_register_plls(&pdev->dev, plls, ARRAY_SIZE(plls), clk_data);
if (r)
goto free_apmixed_data;
diff --git a/drivers/clk/mediatek/clk-mt8135-apmixedsys.c b/drivers/clk/mediatek/clk-mt8135-apmixedsys.c
index bdadc35c64cbd..19e4ee489ec39 100644
--- a/drivers/clk/mediatek/clk-mt8135-apmixedsys.c
+++ b/drivers/clk/mediatek/clk-mt8135-apmixedsys.c
@@ -57,7 +57,8 @@ static int clk_mt8135_apmixed_probe(struct platform_device *pdev)
if (!clk_data)
return -ENOMEM;
- ret = mtk_clk_register_plls(node, plls, ARRAY_SIZE(plls), clk_data);
+ ret = mtk_clk_register_plls(&pdev->dev, plls, ARRAY_SIZE(plls),
+ clk_data);
if (ret)
goto free_clk_data;
diff --git a/drivers/clk/mediatek/clk-mt8167-apmixedsys.c b/drivers/clk/mediatek/clk-mt8167-apmixedsys.c
index adf576786696e..fb6c21bbeef81 100644
--- a/drivers/clk/mediatek/clk-mt8167-apmixedsys.c
+++ b/drivers/clk/mediatek/clk-mt8167-apmixedsys.c
@@ -105,7 +105,7 @@ static int clk_mt8167_apmixed_probe(struct platform_device *pdev)
if (!clk_data)
return -ENOMEM;
- ret = mtk_clk_register_plls(node, plls, ARRAY_SIZE(plls), clk_data);
+ ret = mtk_clk_register_plls(dev, plls, ARRAY_SIZE(plls), clk_data);
if (ret)
return ret;
diff --git a/drivers/clk/mediatek/clk-mt8183-apmixedsys.c b/drivers/clk/mediatek/clk-mt8183-apmixedsys.c
index 551adbfd7ac93..6242d4f5376e7 100644
--- a/drivers/clk/mediatek/clk-mt8183-apmixedsys.c
+++ b/drivers/clk/mediatek/clk-mt8183-apmixedsys.c
@@ -155,7 +155,7 @@ static int clk_mt8183_apmixed_probe(struct platform_device *pdev)
if (!clk_data)
return -ENOMEM;
- ret = mtk_clk_register_plls(node, plls, ARRAY_SIZE(plls), clk_data);
+ ret = mtk_clk_register_plls(dev, plls, ARRAY_SIZE(plls), clk_data);
if (ret)
return ret;
diff --git a/drivers/clk/mediatek/clk-mt8188-apmixedsys.c b/drivers/clk/mediatek/clk-mt8188-apmixedsys.c
index 21d7a9a2ab1af..a1de596bff994 100644
--- a/drivers/clk/mediatek/clk-mt8188-apmixedsys.c
+++ b/drivers/clk/mediatek/clk-mt8188-apmixedsys.c
@@ -106,7 +106,7 @@ static int clk_mt8188_apmixed_probe(struct platform_device *pdev)
if (!clk_data)
return -ENOMEM;
- r = mtk_clk_register_plls(node, plls, ARRAY_SIZE(plls), clk_data);
+ r = mtk_clk_register_plls(&pdev->dev, plls, ARRAY_SIZE(plls), clk_data);
if (r)
goto free_apmixed_data;
diff --git a/drivers/clk/mediatek/clk-mt8195-apusys_pll.c b/drivers/clk/mediatek/clk-mt8195-apusys_pll.c
index 8b45a3fad02f1..a2d98ed58e348 100644
--- a/drivers/clk/mediatek/clk-mt8195-apusys_pll.c
+++ b/drivers/clk/mediatek/clk-mt8195-apusys_pll.c
@@ -66,7 +66,8 @@ static int clk_mt8195_apusys_pll_probe(struct platform_device *pdev)
if (!clk_data)
return -ENOMEM;
- r = mtk_clk_register_plls(node, apusys_plls, ARRAY_SIZE(apusys_plls), clk_data);
+ r = mtk_clk_register_plls(&pdev->dev, apusys_plls,
+ ARRAY_SIZE(apusys_plls), clk_data);
if (r)
goto free_apusys_pll_data;
diff --git a/drivers/clk/mediatek/clk-mt8196-apmixedsys.c b/drivers/clk/mediatek/clk-mt8196-apmixedsys.c
index 617f5449b88b8..c4ebb0170b82b 100644
--- a/drivers/clk/mediatek/clk-mt8196-apmixedsys.c
+++ b/drivers/clk/mediatek/clk-mt8196-apmixedsys.c
@@ -152,7 +152,8 @@ static int clk_mt8196_apmixed_probe(struct platform_device *pdev)
if (!clk_data)
return -ENOMEM;
- r = mtk_clk_register_plls(node, mcd->clks, mcd->num_clks, clk_data);
+ r = mtk_clk_register_plls(&pdev->dev, mcd->clks, mcd->num_clks,
+ clk_data);
if (r)
goto free_apmixed_data;
diff --git a/drivers/clk/mediatek/clk-mt8196-mcu.c b/drivers/clk/mediatek/clk-mt8196-mcu.c
index 5cbcc411ae734..13642fc673c26 100644
--- a/drivers/clk/mediatek/clk-mt8196-mcu.c
+++ b/drivers/clk/mediatek/clk-mt8196-mcu.c
@@ -122,7 +122,7 @@ static int clk_mt8196_mcu_probe(struct platform_device *pdev)
if (!clk_data)
return -ENOMEM;
- r = mtk_clk_register_plls(node, plls, num_plls, clk_data);
+ r = mtk_clk_register_plls(&pdev->dev, plls, num_plls, clk_data);
if (r)
goto free_clk_data;
diff --git a/drivers/clk/mediatek/clk-mt8196-mfg.c b/drivers/clk/mediatek/clk-mt8196-mfg.c
index f40795b47ff1f..a317183f1681b 100644
--- a/drivers/clk/mediatek/clk-mt8196-mfg.c
+++ b/drivers/clk/mediatek/clk-mt8196-mfg.c
@@ -106,7 +106,7 @@ static int clk_mt8196_mfg_probe(struct platform_device *pdev)
if (!clk_data)
return -ENOMEM;
- r = mtk_clk_register_plls(node, plls, num_plls, clk_data);
+ r = mtk_clk_register_plls(&pdev->dev, plls, num_plls, clk_data);
if (r)
goto free_clk_data;
diff --git a/drivers/clk/mediatek/clk-mt8196-vlpckgen.c b/drivers/clk/mediatek/clk-mt8196-vlpckgen.c
index d59a8a9d98550..7dcc164627c57 100644
--- a/drivers/clk/mediatek/clk-mt8196-vlpckgen.c
+++ b/drivers/clk/mediatek/clk-mt8196-vlpckgen.c
@@ -664,7 +664,7 @@ static int clk_mt8196_vlp_probe(struct platform_device *pdev)
if (r)
goto unregister_factors;
- r = mtk_clk_register_plls(node, vlp_plls, ARRAY_SIZE(vlp_plls),
+ r = mtk_clk_register_plls(dev, vlp_plls, ARRAY_SIZE(vlp_plls),
clk_data);
if (r)
goto unregister_muxes;
diff --git a/drivers/clk/mediatek/clk-mt8365-apmixedsys.c b/drivers/clk/mediatek/clk-mt8365-apmixedsys.c
index f41b991a0178a..e331aa28a4bd5 100644
--- a/drivers/clk/mediatek/clk-mt8365-apmixedsys.c
+++ b/drivers/clk/mediatek/clk-mt8365-apmixedsys.c
@@ -133,7 +133,7 @@ static int clk_mt8365_apmixed_probe(struct platform_device *pdev)
return PTR_ERR(hw);
clk_data->hws[CLK_APMIXED_USB20_EN] = hw;
- ret = mtk_clk_register_plls(node, plls, ARRAY_SIZE(plls), clk_data);
+ ret = mtk_clk_register_plls(dev, plls, ARRAY_SIZE(plls), clk_data);
if (ret)
return ret;
diff --git a/drivers/clk/mediatek/clk-mt8516-apmixedsys.c b/drivers/clk/mediatek/clk-mt8516-apmixedsys.c
index edd9174d2f2ff..2a6206cae2f08 100644
--- a/drivers/clk/mediatek/clk-mt8516-apmixedsys.c
+++ b/drivers/clk/mediatek/clk-mt8516-apmixedsys.c
@@ -87,7 +87,7 @@ static int clk_mt8516_apmixed_probe(struct platform_device *pdev)
if (!clk_data)
return -ENOMEM;
- ret = mtk_clk_register_plls(node, plls, ARRAY_SIZE(plls), clk_data);
+ ret = mtk_clk_register_plls(dev, plls, ARRAY_SIZE(plls), clk_data);
if (ret)
return ret;
diff --git a/drivers/clk/mediatek/clk-pll.c b/drivers/clk/mediatek/clk-pll.c
index de3eb02670554..6aec24bab8e6a 100644
--- a/drivers/clk/mediatek/clk-pll.c
+++ b/drivers/clk/mediatek/clk-pll.c
@@ -11,6 +11,7 @@
#include <linux/io.h>
#include <linux/module.h>
#include <linux/of_address.h>
+#include <linux/platform_device.h>
#include <linux/slab.h>
#include "clk-pll.h"
@@ -407,7 +408,7 @@ void mtk_clk_unregister_pll(struct clk_hw *hw)
kfree(pll);
}
-int mtk_clk_register_plls(struct device_node *node,
+int mtk_clk_register_plls(struct device *dev,
const struct mtk_pll_data *plls, int num_plls,
struct clk_hw_onecell_data *clk_data)
{
@@ -415,7 +416,7 @@ int mtk_clk_register_plls(struct device_node *node,
int i;
struct clk_hw *hw;
- base = of_iomap(node, 0);
+ base = of_iomap(dev->of_node, 0);
if (!base) {
pr_err("%s(): ioremap failed\n", __func__);
return -EINVAL;
@@ -426,7 +427,7 @@ int mtk_clk_register_plls(struct device_node *node,
if (!IS_ERR_OR_NULL(clk_data->hws[pll->id])) {
pr_warn("%pOF: Trying to register duplicate clock ID: %d\n",
- node, pll->id);
+ dev->of_node, pll->id);
continue;
}
diff --git a/drivers/clk/mediatek/clk-pll.h b/drivers/clk/mediatek/clk-pll.h
index de5a8fb7cbcfe..fe9f4c81c8b51 100644
--- a/drivers/clk/mediatek/clk-pll.h
+++ b/drivers/clk/mediatek/clk-pll.h
@@ -10,9 +10,7 @@
#include <linux/clk-provider.h>
#include <linux/types.h>
-struct clk_ops;
-struct clk_hw_onecell_data;
-struct device_node;
+struct device;
struct mtk_pll_div_table {
u32 div;
@@ -79,9 +77,9 @@ struct mtk_clk_pll {
const struct mtk_pll_data *data;
};
-int mtk_clk_register_plls(struct device_node *node,
- const struct mtk_pll_data *plls, int num_plls,
- struct clk_hw_onecell_data *clk_data);
+int mtk_clk_register_plls(struct device *dev, const struct mtk_pll_data *plls,
+ int num_plls, struct clk_hw_onecell_data *clk_data);
+
void mtk_clk_unregister_plls(const struct mtk_pll_data *plls, int num_plls,
struct clk_hw_onecell_data *clk_data);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0613/1518] clk: mediatek: Pass device to clk_hw_register for PLLs
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (611 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0612/1518] clk: mediatek: Refactor pll registration to pass device Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0614/1518] clk: mediatek: Refactor pllfh registration to pass device Greg Kroah-Hartman
` (385 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chen-Yu Tsai,
AngeloGioacchino Del Regno, Nicolas Frattaroli, Stephen Boyd,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolas Frattaroli <nicolas.frattaroli@collabora.com>
[ Upstream commit ecffd05839b32f17bde1f3701b68ab182a837b07 ]
Passing the struct device pointer to clk_hw_register allows for runtime
power management to work for the registered clock controllers. However,
the mediatek PLL clocks do not do this.
Change this by adding a struct device pointer argument to
mtk_clk_register_pll, and fix up the only other user of it. Also add a
new member to the struct mtk_clk_pll for the struct device pointer,
which is set by mtk_clk_register_pll and is used by
mtk_clk_register_pll_ops.
If mtk_clk_register_pll is called with a NULL struct device pointer,
then everything still works as expected; the clock core will simply
treat them as previously, i.e. without runtime power management.
Reviewed-by: Chen-Yu Tsai <wenst@chromium.org>
Reviewed-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
Signed-off-by: Nicolas Frattaroli <nicolas.frattaroli@collabora.com>
Signed-off-by: Stephen Boyd <sboyd@kernel.org>
Stable-dep-of: 540d91480bcb ("clk: mediatek: pllfh: Fix IO remapping leak in register_pllfhs error path")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/mediatek/clk-pll.c | 9 ++++++---
drivers/clk/mediatek/clk-pll.h | 4 +++-
drivers/clk/mediatek/clk-pllfh.c | 2 +-
3 files changed, 10 insertions(+), 5 deletions(-)
diff --git a/drivers/clk/mediatek/clk-pll.c b/drivers/clk/mediatek/clk-pll.c
index 6aec24bab8e6a..0f3759fcd9d02 100644
--- a/drivers/clk/mediatek/clk-pll.c
+++ b/drivers/clk/mediatek/clk-pll.c
@@ -369,7 +369,7 @@ struct clk_hw *mtk_clk_register_pll_ops(struct mtk_clk_pll *pll,
init.parent_names = &parent_name;
init.num_parents = 1;
- ret = clk_hw_register(NULL, &pll->hw);
+ ret = clk_hw_register(pll->dev, &pll->hw);
if (ret)
return ERR_PTR(ret);
@@ -377,7 +377,8 @@ struct clk_hw *mtk_clk_register_pll_ops(struct mtk_clk_pll *pll,
return &pll->hw;
}
-struct clk_hw *mtk_clk_register_pll(const struct mtk_pll_data *data,
+struct clk_hw *mtk_clk_register_pll(struct device *dev,
+ const struct mtk_pll_data *data,
void __iomem *base)
{
struct mtk_clk_pll *pll;
@@ -388,6 +389,8 @@ struct clk_hw *mtk_clk_register_pll(const struct mtk_pll_data *data,
if (!pll)
return ERR_PTR(-ENOMEM);
+ pll->dev = dev;
+
hw = mtk_clk_register_pll_ops(pll, data, base, pll_ops);
if (IS_ERR(hw))
kfree(pll);
@@ -431,7 +434,7 @@ int mtk_clk_register_plls(struct device *dev,
continue;
}
- hw = mtk_clk_register_pll(pll, base);
+ hw = mtk_clk_register_pll(dev, pll, base);
if (IS_ERR(hw)) {
pr_err("Failed to register clk %s: %pe\n", pll->name,
diff --git a/drivers/clk/mediatek/clk-pll.h b/drivers/clk/mediatek/clk-pll.h
index fe9f4c81c8b51..f49dc2732ffee 100644
--- a/drivers/clk/mediatek/clk-pll.h
+++ b/drivers/clk/mediatek/clk-pll.h
@@ -62,6 +62,7 @@ struct mtk_pll_data {
*/
struct mtk_clk_pll {
+ struct device *dev;
struct clk_hw hw;
void __iomem *base_addr;
void __iomem *pd_addr;
@@ -109,7 +110,8 @@ struct clk_hw *mtk_clk_register_pll_ops(struct mtk_clk_pll *pll,
const struct mtk_pll_data *data,
void __iomem *base,
const struct clk_ops *pll_ops);
-struct clk_hw *mtk_clk_register_pll(const struct mtk_pll_data *data,
+struct clk_hw *mtk_clk_register_pll(struct device *dev,
+ const struct mtk_pll_data *data,
void __iomem *base);
void mtk_clk_unregister_pll(struct clk_hw *hw);
diff --git a/drivers/clk/mediatek/clk-pllfh.c b/drivers/clk/mediatek/clk-pllfh.c
index 83630ee07ee97..62bfe4a480f14 100644
--- a/drivers/clk/mediatek/clk-pllfh.c
+++ b/drivers/clk/mediatek/clk-pllfh.c
@@ -220,7 +220,7 @@ int mtk_clk_register_pllfhs(struct device_node *node,
if (use_fhctl)
hw = mtk_clk_register_pllfh(pll, pllfh, base);
else
- hw = mtk_clk_register_pll(pll, base);
+ hw = mtk_clk_register_pll(NULL, pll, base);
if (IS_ERR(hw)) {
pr_err("Failed to register %s clk %s: %ld\n",
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0614/1518] clk: mediatek: Refactor pllfh registration to pass device
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (612 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0613/1518] clk: mediatek: Pass device to clk_hw_register for PLLs Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0615/1518] clk: mediatek: pllfh: Fix IO remapping leak in register_pllfhs error path Greg Kroah-Hartman
` (384 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, AngeloGioacchino Del Regno,
Nicolas Frattaroli, Stephen Boyd, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Nicolas Frattaroli <nicolas.frattaroli@collabora.com>
[ Upstream commit 483f364bb0014495da19c1ccb1a6e2423fc37d95 ]
After refactoring all of PLL to pass the device, it's now fairly easy to
refactor pllfh and its users, as pllfh registration wraps PLL
registration.
Do this refactor and move all of the pllfh users to pass the device as
well.
Reviewed-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
Signed-off-by: Nicolas Frattaroli <nicolas.frattaroli@collabora.com>
Signed-off-by: Stephen Boyd <sboyd@kernel.org>
Stable-dep-of: 540d91480bcb ("clk: mediatek: pllfh: Fix IO remapping leak in register_pllfhs error path")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/mediatek/clk-mt6795-apmixedsys.c | 2 +-
drivers/clk/mediatek/clk-mt8173-apmixedsys.c | 14 +++++++-------
drivers/clk/mediatek/clk-mt8186-apmixedsys.c | 2 +-
drivers/clk/mediatek/clk-mt8192-apmixedsys.c | 2 +-
drivers/clk/mediatek/clk-mt8195-apmixedsys.c | 2 +-
drivers/clk/mediatek/clk-pllfh.c | 13 ++++++++-----
drivers/clk/mediatek/clk-pllfh.h | 2 +-
7 files changed, 20 insertions(+), 17 deletions(-)
diff --git a/drivers/clk/mediatek/clk-mt6795-apmixedsys.c b/drivers/clk/mediatek/clk-mt6795-apmixedsys.c
index 91665d7f125ef..123d5d7fea855 100644
--- a/drivers/clk/mediatek/clk-mt6795-apmixedsys.c
+++ b/drivers/clk/mediatek/clk-mt6795-apmixedsys.c
@@ -152,7 +152,7 @@ static int clk_mt6795_apmixed_probe(struct platform_device *pdev)
return -ENOMEM;
fhctl_parse_dt(fhctl_node, pllfhs, ARRAY_SIZE(pllfhs));
- ret = mtk_clk_register_pllfhs(node, plls, ARRAY_SIZE(plls),
+ ret = mtk_clk_register_pllfhs(dev, plls, ARRAY_SIZE(plls),
pllfhs, ARRAY_SIZE(pllfhs), clk_data);
if (ret)
goto free_clk_data;
diff --git a/drivers/clk/mediatek/clk-mt8173-apmixedsys.c b/drivers/clk/mediatek/clk-mt8173-apmixedsys.c
index 95385bb67d551..d7d416172ab35 100644
--- a/drivers/clk/mediatek/clk-mt8173-apmixedsys.c
+++ b/drivers/clk/mediatek/clk-mt8173-apmixedsys.c
@@ -140,13 +140,13 @@ MODULE_DEVICE_TABLE(of, of_match_clk_mt8173_apmixed);
static int clk_mt8173_apmixed_probe(struct platform_device *pdev)
{
const u8 *fhctl_node = "mediatek,mt8173-fhctl";
- struct device_node *node = pdev->dev.of_node;
struct clk_hw_onecell_data *clk_data;
+ struct device *dev = &pdev->dev;
void __iomem *base;
struct clk_hw *hw;
int r;
- base = of_iomap(node, 0);
+ base = of_iomap(dev->of_node, 0);
if (!base)
return -ENOMEM;
@@ -157,25 +157,25 @@ static int clk_mt8173_apmixed_probe(struct platform_device *pdev)
}
fhctl_parse_dt(fhctl_node, pllfhs, ARRAY_SIZE(pllfhs));
- r = mtk_clk_register_pllfhs(node, plls, ARRAY_SIZE(plls),
- pllfhs, ARRAY_SIZE(pllfhs), clk_data);
+ r = mtk_clk_register_pllfhs(dev, plls, ARRAY_SIZE(plls), pllfhs,
+ ARRAY_SIZE(pllfhs), clk_data);
if (r)
goto free_clk_data;
hw = mtk_clk_register_ref2usb_tx("ref2usb_tx", "clk26m", base + REGOFF_REF2USB);
if (IS_ERR(hw)) {
r = PTR_ERR(hw);
- dev_err(&pdev->dev, "Failed to register ref2usb_tx: %d\n", r);
+ dev_err(dev, "Failed to register ref2usb_tx: %d\n", r);
goto unregister_plls;
}
clk_data->hws[CLK_APMIXED_REF2USB_TX] = hw;
- hw = devm_clk_hw_register_divider(&pdev->dev, "hdmi_ref", "tvdpll_594m", 0,
+ hw = devm_clk_hw_register_divider(dev, "hdmi_ref", "tvdpll_594m", 0,
base + REGOFF_HDMI_REF, 16, 3,
CLK_DIVIDER_POWER_OF_TWO, NULL);
clk_data->hws[CLK_APMIXED_HDMI_REF] = hw;
- r = of_clk_add_hw_provider(node, of_clk_hw_onecell_get, clk_data);
+ r = of_clk_add_hw_provider(dev->of_node, of_clk_hw_onecell_get, clk_data);
if (r)
goto unregister_ref2usb;
diff --git a/drivers/clk/mediatek/clk-mt8186-apmixedsys.c b/drivers/clk/mediatek/clk-mt8186-apmixedsys.c
index 4b2b16578232d..d35dd2632e43a 100644
--- a/drivers/clk/mediatek/clk-mt8186-apmixedsys.c
+++ b/drivers/clk/mediatek/clk-mt8186-apmixedsys.c
@@ -151,7 +151,7 @@ static int clk_mt8186_apmixed_probe(struct platform_device *pdev)
fhctl_parse_dt(fhctl_node, pllfhs, ARRAY_SIZE(pllfhs));
- r = mtk_clk_register_pllfhs(node, plls, ARRAY_SIZE(plls),
+ r = mtk_clk_register_pllfhs(&pdev->dev, plls, ARRAY_SIZE(plls),
pllfhs, ARRAY_SIZE(pllfhs), clk_data);
if (r)
goto free_apmixed_data;
diff --git a/drivers/clk/mediatek/clk-mt8192-apmixedsys.c b/drivers/clk/mediatek/clk-mt8192-apmixedsys.c
index 0b66a27e4d5ac..b0563a285bd66 100644
--- a/drivers/clk/mediatek/clk-mt8192-apmixedsys.c
+++ b/drivers/clk/mediatek/clk-mt8192-apmixedsys.c
@@ -162,7 +162,7 @@ static int clk_mt8192_apmixed_probe(struct platform_device *pdev)
fhctl_parse_dt(fhctl_node, pllfhs, ARRAY_SIZE(pllfhs));
- r = mtk_clk_register_pllfhs(node, plls, ARRAY_SIZE(plls),
+ r = mtk_clk_register_pllfhs(&pdev->dev, plls, ARRAY_SIZE(plls),
pllfhs, ARRAY_SIZE(pllfhs), clk_data);
if (r)
goto free_clk_data;
diff --git a/drivers/clk/mediatek/clk-mt8195-apmixedsys.c b/drivers/clk/mediatek/clk-mt8195-apmixedsys.c
index 282a3137dc894..44917ab034c56 100644
--- a/drivers/clk/mediatek/clk-mt8195-apmixedsys.c
+++ b/drivers/clk/mediatek/clk-mt8195-apmixedsys.c
@@ -181,7 +181,7 @@ static int clk_mt8195_apmixed_probe(struct platform_device *pdev)
fhctl_parse_dt(fhctl_node, pllfhs, ARRAY_SIZE(pllfhs));
- r = mtk_clk_register_pllfhs(node, plls, ARRAY_SIZE(plls),
+ r = mtk_clk_register_pllfhs(&pdev->dev, plls, ARRAY_SIZE(plls),
pllfhs, ARRAY_SIZE(pllfhs), clk_data);
if (r)
goto free_apmixed_data;
diff --git a/drivers/clk/mediatek/clk-pllfh.c b/drivers/clk/mediatek/clk-pllfh.c
index 62bfe4a480f14..8ad11023d9112 100644
--- a/drivers/clk/mediatek/clk-pllfh.c
+++ b/drivers/clk/mediatek/clk-pllfh.c
@@ -10,6 +10,7 @@
#include <linux/slab.h>
#include <linux/clkdev.h>
#include <linux/delay.h>
+#include <linux/device.h>
#include "clk-mtk.h"
#include "clk-pllfh.h"
@@ -149,7 +150,7 @@ static bool fhctl_is_supported_and_enabled(const struct mtk_pllfh_data *pllfh)
}
static struct clk_hw *
-mtk_clk_register_pllfh(const struct mtk_pll_data *pll_data,
+mtk_clk_register_pllfh(struct device *dev, const struct mtk_pll_data *pll_data,
struct mtk_pllfh_data *pllfh_data, void __iomem *base)
{
struct clk_hw *hw;
@@ -166,6 +167,8 @@ mtk_clk_register_pllfh(const struct mtk_pll_data *pll_data,
goto out;
}
+ fh->clk_pll.dev = dev;
+
hw = mtk_clk_register_pll_ops(&fh->clk_pll, pll_data, base,
&mtk_pllfh_ops);
@@ -194,7 +197,7 @@ static void mtk_clk_unregister_pllfh(struct clk_hw *hw)
kfree(fh);
}
-int mtk_clk_register_pllfhs(struct device_node *node,
+int mtk_clk_register_pllfhs(struct device *dev,
const struct mtk_pll_data *plls, int num_plls,
struct mtk_pllfh_data *pllfhs, int num_fhs,
struct clk_hw_onecell_data *clk_data)
@@ -203,7 +206,7 @@ int mtk_clk_register_pllfhs(struct device_node *node,
int i;
struct clk_hw *hw;
- base = of_iomap(node, 0);
+ base = of_iomap(dev->of_node, 0);
if (!base) {
pr_err("%s(): ioremap failed\n", __func__);
return -EINVAL;
@@ -218,9 +221,9 @@ int mtk_clk_register_pllfhs(struct device_node *node,
use_fhctl = fhctl_is_supported_and_enabled(pllfh);
if (use_fhctl)
- hw = mtk_clk_register_pllfh(pll, pllfh, base);
+ hw = mtk_clk_register_pllfh(dev, pll, pllfh, base);
else
- hw = mtk_clk_register_pll(NULL, pll, base);
+ hw = mtk_clk_register_pll(dev, pll, base);
if (IS_ERR(hw)) {
pr_err("Failed to register %s clk %s: %ld\n",
diff --git a/drivers/clk/mediatek/clk-pllfh.h b/drivers/clk/mediatek/clk-pllfh.h
index 5f419c2ec01f9..a4f337acad713 100644
--- a/drivers/clk/mediatek/clk-pllfh.h
+++ b/drivers/clk/mediatek/clk-pllfh.h
@@ -68,7 +68,7 @@ struct fh_operation {
int (*ssc_enable)(struct mtk_fh *fh, u32 rate);
};
-int mtk_clk_register_pllfhs(struct device_node *node,
+int mtk_clk_register_pllfhs(struct device *dev,
const struct mtk_pll_data *plls, int num_plls,
struct mtk_pllfh_data *pllfhs, int num_pllfhs,
struct clk_hw_onecell_data *clk_data);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0615/1518] clk: mediatek: pllfh: Fix IO remapping leak in register_pllfhs error path
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (613 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0614/1518] clk: mediatek: Refactor pllfh registration to pass device Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0616/1518] clk: palmas: Manage external-control prepare with devm Greg Kroah-Hartman
` (383 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Louis-Alexis Eyraud, Brian Masney,
AngeloGioacchino Del Regno, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Louis-Alexis Eyraud <louisalexis.eyraud@collabora.com>
[ Upstream commit 540d91480bcb1b28a62d7023aa70947ea44c55b9 ]
When mtk_clk_register_pllfhs function fails to register a PLL, it
unregisters all PLLs and cleans up itself in its error path before
returning, so the function callers don't need to do it.
But contrary to mtk_clk_unregister_pllfhs function, that does almost
the same sequence, it does not free the IO memory mapped on fhctl node,
leading to a leak.
Fix this leak by factorizing the cleanup sequence in a new private
function and use it both mtk_clk_register_pllfhs and
mtk_clk_unregister_pllfhs functions.
Also, change the loop index start value to avoid the -1 operation on
index at each loop.
Fixes: d7964de8a8ea ("clk: mediatek: Add new clock driver to handle FHCTL hardware")
Signed-off-by: Louis-Alexis Eyraud <louisalexis.eyraud@collabora.com>
Reviewed-by: Brian Masney <bmasney@redhat.com>
Reviewed-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
Signed-off-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/mediatek/clk-pllfh.c | 98 ++++++++++++++++----------------
1 file changed, 49 insertions(+), 49 deletions(-)
diff --git a/drivers/clk/mediatek/clk-pllfh.c b/drivers/clk/mediatek/clk-pllfh.c
index 8ad11023d9112..d8b7eb6d18e1c 100644
--- a/drivers/clk/mediatek/clk-pllfh.c
+++ b/drivers/clk/mediatek/clk-pllfh.c
@@ -197,12 +197,56 @@ static void mtk_clk_unregister_pllfh(struct clk_hw *hw)
kfree(fh);
}
+static void mtk_clk_cleanup_pllfhs(void __iomem *iomem_base,
+ const struct mtk_pll_data *plls, int num_plls,
+ void __iomem *iomem_fhctl_base,
+ struct mtk_pllfh_data *pllfhs, int num_fhs,
+ struct clk_hw_onecell_data *clk_data)
+{
+ void __iomem *base = iomem_base;
+ void __iomem *fhctl_base = iomem_fhctl_base;
+ int i;
+
+ for (i = num_plls - 1; i >= 0; i--) {
+ const struct mtk_pll_data *pll = &plls[i];
+ struct mtk_pllfh_data *pllfh;
+ bool use_fhctl;
+
+ if (IS_ERR_OR_NULL(clk_data->hws[pll->id]))
+ continue;
+
+ pllfh = get_pllfh_by_id(pllfhs, num_fhs, pll->id);
+ use_fhctl = fhctl_is_supported_and_enabled(pllfh);
+
+ if (!base)
+ base = mtk_clk_pll_get_base(clk_data->hws[pll->id],
+ pll);
+
+ if (use_fhctl) {
+ if (!fhctl_base)
+ fhctl_base = pllfh->state.base;
+ mtk_clk_unregister_pllfh(clk_data->hws[pll->id]);
+ } else {
+ mtk_clk_unregister_pll(clk_data->hws[pll->id]);
+ }
+
+ clk_data->hws[pll->id] = ERR_PTR(-ENOENT);
+ }
+
+ if (fhctl_base)
+ iounmap(fhctl_base);
+
+ if (base)
+ iounmap(base);
+}
+
+
int mtk_clk_register_pllfhs(struct device *dev,
const struct mtk_pll_data *plls, int num_plls,
struct mtk_pllfh_data *pllfhs, int num_fhs,
struct clk_hw_onecell_data *clk_data)
{
- void __iomem *base;
+ void __iomem *base, *fhctl_base = NULL;
int i;
struct clk_hw *hw;
@@ -238,24 +282,8 @@ int mtk_clk_register_pllfhs(struct device *dev,
return 0;
err:
- while (--i >= 0) {
- const struct mtk_pll_data *pll = &plls[i];
- struct mtk_pllfh_data *pllfh;
- bool use_fhctl;
-
- pllfh = get_pllfh_by_id(pllfhs, num_fhs, pll->id);
- use_fhctl = fhctl_is_supported_and_enabled(pllfh);
-
- if (use_fhctl)
- mtk_clk_unregister_pllfh(clk_data->hws[pll->id]);
- else
- mtk_clk_unregister_pll(clk_data->hws[pll->id]);
-
- clk_data->hws[pll->id] = ERR_PTR(-ENOENT);
- }
-
- iounmap(base);
-
+ mtk_clk_cleanup_pllfhs(base, plls, i, fhctl_base, pllfhs, num_fhs,
+ clk_data);
return PTR_ERR(hw);
}
EXPORT_SYMBOL_GPL(mtk_clk_register_pllfhs);
@@ -264,38 +292,10 @@ void mtk_clk_unregister_pllfhs(const struct mtk_pll_data *plls, int num_plls,
struct mtk_pllfh_data *pllfhs, int num_fhs,
struct clk_hw_onecell_data *clk_data)
{
- void __iomem *base = NULL, *fhctl_base = NULL;
- int i;
-
if (!clk_data)
return;
- for (i = num_plls; i > 0; i--) {
- const struct mtk_pll_data *pll = &plls[i - 1];
- struct mtk_pllfh_data *pllfh;
- bool use_fhctl;
-
- if (IS_ERR_OR_NULL(clk_data->hws[pll->id]))
- continue;
-
- pllfh = get_pllfh_by_id(pllfhs, num_fhs, pll->id);
- use_fhctl = fhctl_is_supported_and_enabled(pllfh);
-
- if (use_fhctl) {
- fhctl_base = pllfh->state.base;
- mtk_clk_unregister_pllfh(clk_data->hws[pll->id]);
- } else {
- base = mtk_clk_pll_get_base(clk_data->hws[pll->id],
- pll);
- mtk_clk_unregister_pll(clk_data->hws[pll->id]);
- }
-
- clk_data->hws[pll->id] = ERR_PTR(-ENOENT);
- }
-
- if (fhctl_base)
- iounmap(fhctl_base);
-
- iounmap(base);
+ mtk_clk_cleanup_pllfhs(NULL, plls, num_plls, NULL, pllfhs,
+ num_fhs, clk_data);
}
EXPORT_SYMBOL_GPL(mtk_clk_unregister_pllfhs);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0616/1518] clk: palmas: Manage external-control prepare with devm
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (614 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0615/1518] clk: mediatek: pllfh: Fix IO remapping leak in register_pllfhs error path Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0617/1518] clk/x86: pmc_atom: add kasprintf return value check Greg Kroah-Hartman
` (382 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ijae Kim, Myeonghun Pak,
Brian Masney, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Myeonghun Pak <mhun512@gmail.com>
[ Upstream commit ccda84fcbf3a972973f772384935928f41817b3a ]
palmas_clks_init_configure() prepares the clock when an external control
pin is configured. The current driver only drops that prepare reference
when external control configuration fails.
If provider registration fails after that point, or if the driver is later
removed, the prepare reference remains held.
Register a device-managed action after clk_prepare() succeeds. This
balances the prepare reference on subsequent probe failure and driver
removal.
Fixes: 942d1d674931 ("clk: Add driver for Palmas clk32kg and clk32kgaudio clocks")
Co-developed-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Ijae Kim <ae878000@gmail.com>
Signed-off-by: Myeonghun Pak <mhun512@gmail.com>
Reviewed-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/clk-palmas.c | 14 +++++++++++++-
1 file changed, 13 insertions(+), 1 deletion(-)
diff --git a/drivers/clk/clk-palmas.c b/drivers/clk/clk-palmas.c
index 39049f62dbbb3..86a51edac8272 100644
--- a/drivers/clk/clk-palmas.c
+++ b/drivers/clk/clk-palmas.c
@@ -194,6 +194,13 @@ static void palmas_clks_get_clk_data(struct platform_device *pdev,
cinfo->ext_control_pin = prop;
}
+static void palmas_clks_unprepare_ext_control(void *data)
+{
+ struct palmas_clock_info *cinfo = data;
+
+ clk_unprepare(cinfo->hw.clk);
+}
+
static int palmas_clks_init_configure(struct palmas_clock_info *cinfo)
{
int ret;
@@ -214,13 +221,18 @@ static int palmas_clks_init_configure(struct palmas_clock_info *cinfo)
return ret;
}
+ ret = devm_add_action_or_reset(cinfo->dev,
+ palmas_clks_unprepare_ext_control,
+ cinfo);
+ if (ret)
+ return ret;
+
ret = palmas_ext_control_req_config(cinfo->palmas,
cinfo->clk_desc->sleep_reqstr_id,
cinfo->ext_control_pin, true);
if (ret < 0) {
dev_err(cinfo->dev, "Ext config for %s failed, %d\n",
cinfo->clk_desc->clk_name, ret);
- clk_unprepare(cinfo->hw.clk);
return ret;
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0617/1518] clk/x86: pmc_atom: add kasprintf return value check
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (615 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0616/1518] clk: palmas: Manage external-control prepare with devm Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0618/1518] clk: mediatek: mt8135: Fix inverted gate control for devapc_ck Greg Kroah-Hartman
` (381 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, longlong yan, Brian Masney,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: longlong yan <yanlonglong@kylinos.cn>
[ Upstream commit 18e9d14cbac33db1c1fb933c26a736eef53dd538 ]
The kasprintf() function returns NULL on memory allocation failure, but
the code in plt_clk_register() was not checking this return value. If
kasprintf fails, init.name would be NULL and could cause NULL pointer
dereference when clkdev_hw_create() uses it.
Add proper error checking for the kasprintf() return value and return
ERR_PTR(-ENOMEM) on failure.
Fixes: 1141d9d08184 ("clk: x86: Add Atom PMC platform clocks")
Signed-off-by: longlong yan <yanlonglong@kylinos.cn>
Reviewed-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/x86/clk-pmc-atom.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/clk/x86/clk-pmc-atom.c b/drivers/clk/x86/clk-pmc-atom.c
index 99291ba65da73..08c83e0abc41d 100644
--- a/drivers/clk/x86/clk-pmc-atom.c
+++ b/drivers/clk/x86/clk-pmc-atom.c
@@ -160,6 +160,9 @@ static struct clk_plt *plt_clk_register(struct platform_device *pdev, int id,
return ERR_PTR(-ENOMEM);
init.name = kasprintf(GFP_KERNEL, "%s_%d", PLT_CLK_NAME_BASE, id);
+ if (!init.name)
+ return ERR_PTR(-ENOMEM);
+
init.ops = &plt_clk_ops;
init.flags = 0;
init.parent_names = parent_names;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0618/1518] clk: mediatek: mt8135: Fix inverted gate control for devapc_ck
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (616 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0617/1518] clk/x86: pmc_atom: add kasprintf return value check Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0619/1518] clk: rockchip: Fix the fractional part denominator on RK3588/RK3576 PLLs Greg Kroah-Hartman
` (380 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Akari Tsuyukusa, Brian Masney,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Akari Tsuyukusa <akkun11.open@gmail.com>
[ Upstream commit fd0e3e4edea6a3e4da91be608ca2fb9b348f9e32 ]
The devapc_ck (CLK_INFRA_DEVAPC) on MT8135 is currently using
"mtk_clk_gate_ops_setclr". However, checking the downstream kernel reveals
that this clock is configured with set:enable and clr:disable making
"mtk_clk_gate_ops_setclr_inv" the appropriate choice.
But, it is strange that some downstream kernels are not like that.
Amazon: INV
ChromiumOS (early): not INV
ChromiumOS 3.16 to 3.18-revew-v2: INV
ChromiumOS 3.18-review-v3 and later (sent to kernel.org): not INV
Link: https://github.com/amazon-oss/android_kernel_amazon_mt8135/blob/e2b2163a8ec4a7c8d961c89003a15b4ba0f0e371/arch/arm/mach-mt8135/mt_clkmgr.c#L1022-L1028
Link: https://github.com/mtk09422/chromiumos-third_party-kernel-mediatek/blob/4b624ee66e65d5dcd43fca36b313086efae8922a/arch/arm/boot/dts/mt8135-clocks.dtsi#L944-L948
Link: https://github.com/mtk09422/chromiumos-third_party-kernel-mediatek/blob/decd80c01d0dbe9f3afa8ff72273b5618b418180/drivers/clk/mediatek/clk-mt8135.c#L881-L882
Link: https://github.com/mtk09422/chromiumos-third_party-kernel-mediatek/blob/9b6f06cb7637100aa1a42e1fc351b36b384a1c54/drivers/clk/mediatek/clk-mt8135.c#L450
Fixes: a8aede794843 ("clk: mediatek: Add basic clocks for Mediatek MT8135.")
Signed-off-by: Akari Tsuyukusa <akkun11.open@gmail.com>
Signed-off-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/mediatek/clk-mt8135.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/clk/mediatek/clk-mt8135.c b/drivers/clk/mediatek/clk-mt8135.c
index 084e48a554c26..1d20e15608f77 100644
--- a/drivers/clk/mediatek/clk-mt8135.c
+++ b/drivers/clk/mediatek/clk-mt8135.c
@@ -409,6 +409,9 @@ static const struct mtk_gate_regs infra_cg_regs = {
GATE_MTK_FLAGS(_id, _name, _parent, &infra_cg_regs, _shift, \
&mtk_clk_gate_ops_setclr, CLK_IS_CRITICAL)
+#define GATE_ICG_INV(_id, _name, _parent, _shift) \
+ GATE_MTK(_id, _name, _parent, &infra_cg_regs, _shift, &mtk_clk_gate_ops_setclr_inv)
+
static const struct mtk_gate infra_clks[] = {
GATE_DUMMY(CLK_DUMMY, "infra_dummy"),
GATE_ICG(CLK_INFRA_PMIC_WRAP, "pmic_wrap_ck", "axi_sel", 23),
@@ -419,7 +422,7 @@ static const struct mtk_gate infra_clks[] = {
GATE_ICG(CLK_INFRA_CPUM, "cpum_ck", "cpum_tck_in", 15),
GATE_ICG_AO(CLK_INFRA_M4U, "m4u_ck", "mem_sel", 8),
GATE_ICG(CLK_INFRA_MFGAXI, "mfgaxi_ck", "axi_sel", 7),
- GATE_ICG(CLK_INFRA_DEVAPC, "devapc_ck", "axi_sel", 6),
+ GATE_ICG_INV(CLK_INFRA_DEVAPC, "devapc_ck", "axi_sel", 6),
GATE_ICG(CLK_INFRA_AUDIO, "audio_ck", "aud_intbus_sel", 5),
GATE_ICG(CLK_INFRA_MFG_BUS, "mfg_bus_ck", "axi_sel", 2),
GATE_ICG(CLK_INFRA_SMI, "smi_ck", "smi_sel", 1),
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0619/1518] clk: rockchip: Fix the fractional part denominator on RK3588/RK3576 PLLs
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (617 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0618/1518] clk: mediatek: mt8135: Fix inverted gate control for devapc_ck Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0620/1518] nilfs2: fix infinite loop in nilfs_clean_segments() Greg Kroah-Hartman
` (379 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alexey Charkov, Quentin Schulz,
Heiko Stuebner, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexey Charkov <alchark@flipper.net>
[ Upstream commit 52aef653c3d0c24013dfa9eccf692594eacdbe17 ]
According to the TRM, the fractional PLL coefficient should be divided by
65536 rather than 65535 to obtain the output rate.
Fix the denominator and add a comment with the TRM provided clock formulae
for future reference.
See RK3576 TRM Part 1 V1.2 section 2.13.1.4 Setting Guide on P, M, S and K
or equivalently RK3588 TRM part 1 V1.0 section 2.17.1.4 Setting Guide on P,
M, S and K.
Fractional PLL rates don't seem to be used by any current mainline
consumers, so this is purely a correctness fix. It will also be important
to properly support DisplayPort output going forward, as the video output
controller derives its pixel clock from system PLLs with no dedicated PHY
PLL option for DP unlike HDMI, and some display modes are only achievable
with fractional PLL rates.
Fixes: 8f6594494b1c ("clk: rockchip: add pll type for RK3588")
Signed-off-by: Alexey Charkov <alchark@flipper.net>
Reviewed-by: Quentin Schulz <quentin.schulz@cherry.de>
Link: https://patch.msgid.link/20260723-rk3588-fracpll-v2-1-3adfb9dda235@flipper.net
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/rockchip/clk-pll.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/drivers/clk/rockchip/clk-pll.c b/drivers/clk/rockchip/clk-pll.c
index 86dba3826a77e..0dada00b375fa 100644
--- a/drivers/clk/rockchip/clk-pll.c
+++ b/drivers/clk/rockchip/clk-pll.c
@@ -900,6 +900,13 @@ static void rockchip_rk3588_pll_get_params(struct rockchip_clk_pll *pll,
rate->k = ((pllcon >> RK3588_PLLCON2_K_SHIFT) & RK3588_PLLCON2_K_MASK);
}
+/*
+ * 2250 MHz <= Fvco <= 4500 MHz
+ * For Fvco > 3 GHz: period jitter +-1% frac PLL, +-0.75% int PLL
+ * For Fvco < 3 GHz: period jitter +-2% frac PLL, +-1.50% int PLL
+ * Fvco = ((m + k / 65536) * Fin) / p
+ * Fout = ((m + k / 65536) * Fin) / (p * 2^s)
+ */
static unsigned long rockchip_rk3588_pll_recalc_rate(struct clk_hw *hw, unsigned long prate)
{
struct rockchip_clk_pll *pll = to_rockchip_clk_pll(hw);
@@ -915,7 +922,7 @@ static unsigned long rockchip_rk3588_pll_recalc_rate(struct clk_hw *hw, unsigned
/* fractional mode */
u64 frac_rate64 = prate * cur.k;
- postdiv = cur.p * 65535;
+ postdiv = cur.p * 65536;
do_div(frac_rate64, postdiv);
rate64 += frac_rate64;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0620/1518] nilfs2: fix infinite loop in nilfs_clean_segments()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (618 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0619/1518] clk: rockchip: Fix the fractional part denominator on RK3588/RK3576 PLLs Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0621/1518] nilfs2: prevent out-of-bounds read in super root block parsing Greg Kroah-Hartman
` (378 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+cae54346a70bbceeff2c,
Joshua Crofts, Ryusuke Konishi, Viacheslav Dubeyko, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Joshua Crofts <joshua.crofts1@gmail.com>
[ Upstream commit ce5a5ad1a8330a2fcfdd9ec2ab341be739e89a18 ]
syzbot reported a hung task in nilfs_transaction_begin(). This occurs
because the cleaner ioctl falls into an infinite loop if
nilfs_segctor_construct() repeatedly returns -EROFS (e.g. the device
is remounted as read-only after an I/O error).
Currently in nilfs_clean_segments(), if err is non-zero, it logs the
error and sleeps but doesn't abort when it encounters a terminal error
like -EROFS. This causes the thread to loop forever.
Fix this by breaking out of the loop if nilfs_segctor_construct()
returns -EROFS. This matches the behaviour in
nilfs_segctor_write_out(), which also handles -EROFS.
Reported-by: syzbot+cae54346a70bbceeff2c@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=cae54346a70bbceeff2c
Fixes: 9ff05123e3bf ("nilfs2: segment constructor")
Assisted-by: gemini:gemini-3.1-pro
Signed-off-by: Joshua Crofts <joshua.crofts1@gmail.com>
Acked-by: Ryusuke Konishi <konishi.ryusuke@gmail.com>
Signed-off-by: Viacheslav Dubeyko <slava@dubeyko.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/nilfs2/segment.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/fs/nilfs2/segment.c b/fs/nilfs2/segment.c
index 0bc1f0f02f31d..c20340f4e0dc3 100644
--- a/fs/nilfs2/segment.c
+++ b/fs/nilfs2/segment.c
@@ -2561,6 +2561,10 @@ int nilfs_clean_segments(struct super_block *sb, struct nilfs_argv *argv,
break;
nilfs_warn(sb, "error %d cleaning segments", err);
+
+ if (unlikely(err == -EROFS))
+ goto out_unlock;
+
set_current_state(TASK_INTERRUPTIBLE);
schedule_timeout(sci->sc_interval);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0621/1518] nilfs2: prevent out-of-bounds read in super root block parsing
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (619 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0620/1518] nilfs2: fix infinite loop in nilfs_clean_segments() Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0622/1518] nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state mismatch Greg Kroah-Hartman
` (377 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Lee, Ryusuke Konishi,
Viacheslav Dubeyko, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Lee <david.lee@trailofbits.com>
[ Upstream commit 7cb2f76a6a2ba2130b577cb8ac13e1e46c4fc689 ]
super-root inode metadata size is trusted before nilfs_read_inode_common().
Reject super-root inode sizes whose computed on-disk footprint exceeds the
filesystem block size. This prevents malformed filesystem images from
making nilfs_read_inode_common() read past the end of the super-root block.
[ryusuke: clarify the commit title]
Fixes: 8a9d2191e9f4 ("nilfs2: operations for the_nilfs core object")
Signed-off-by: David Lee <david.lee@trailofbits.com>
Assisted-by: Codex:gpt-5.5
Signed-off-by: Ryusuke Konishi <konishi.ryusuke@gmail.com>
Signed-off-by: Viacheslav Dubeyko <slava@dubeyko.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/nilfs2/the_nilfs.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/fs/nilfs2/the_nilfs.c b/fs/nilfs2/the_nilfs.c
index d0bcf744c553a..9911a484398a0 100644
--- a/fs/nilfs2/the_nilfs.c
+++ b/fs/nilfs2/the_nilfs.c
@@ -461,6 +461,12 @@ static int nilfs_store_disk_layout(struct the_nilfs *nilfs,
nilfs->ns_inode_size);
return -EINVAL;
}
+ if (NILFS_SR_BYTES(nilfs->ns_inode_size) > nilfs->ns_blocksize) {
+ nilfs_err(nilfs->ns_sb,
+ "too large inode size for super root: %d bytes",
+ nilfs->ns_inode_size);
+ return -EINVAL;
+ }
nilfs->ns_first_ino = le32_to_cpu(sbp->s_first_ino);
if (nilfs->ns_first_ino < NILFS_USER_INO) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0622/1518] nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state mismatch
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (620 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0621/1518] nilfs2: prevent out-of-bounds read in super root block parsing Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0623/1518] scsi: smartpqi: Fix AIO retry marker cleared by SCSI core between dispatches Greg Kroah-Hartman
` (376 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+8baf9a79a3ffc6271cb6,
Ryusuke Konishi, Viacheslav Dubeyko, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ryusuke Konishi <konishi.ryusuke@gmail.com>
[ Upstream commit 66f4ad3ce158902e5f98afea93189972ed8750c2 ]
Syzbot reported a kernel BUG triggered within nilfs_copy_dirty_pages(),
which copies dirty DAT file folios/pages to its shadow page cache. The
BUG occurs when a retrieved dirty folio/page unexpectedly loses its
'dirty' status.
This issue arises because, since the commit referenced below, the 'dirty'
flag of a folio/page can be cleared asynchronously after the filesystem
detects metadata corruption and transitions to read-only mode.
Resolve the issue by returning an -EROFS error if the filesystem has
transitioned to read-only mode. Also change the behavior to issue a
kernel warning only once instead of triggering a kernel BUG when this
unexpected 'dirty' state is detected while the filesystem is not in
read-only mode.
Reported-by: syzbot+8baf9a79a3ffc6271cb6@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=8baf9a79a3ffc6271cb6
Fixes: 8c26c4e2694a ("nilfs2: fix issue with flush kernel thread after remount in RO mode because of driver's internal error or metadata corruption")
Signed-off-by: Ryusuke Konishi <konishi.ryusuke@gmail.com>
Signed-off-by: Viacheslav Dubeyko <slava@dubeyko.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/nilfs2/page.c | 17 +++++++++++++++--
1 file changed, 15 insertions(+), 2 deletions(-)
diff --git a/fs/nilfs2/page.c b/fs/nilfs2/page.c
index 56c4da417b6a1..89180e2f59fef 100644
--- a/fs/nilfs2/page.c
+++ b/fs/nilfs2/page.c
@@ -243,6 +243,7 @@ static void nilfs_copy_folio(struct folio *dst, struct folio *src,
int nilfs_copy_dirty_pages(struct address_space *dmap,
struct address_space *smap)
{
+ struct inode *smap_inode = smap->host;
struct folio_batch fbatch;
unsigned int i;
pgoff_t index = 0;
@@ -258,8 +259,19 @@ int nilfs_copy_dirty_pages(struct address_space *dmap,
struct folio *folio = fbatch.folios[i], *dfolio;
folio_lock(folio);
- if (unlikely(!folio_test_dirty(folio)))
- NILFS_FOLIO_BUG(folio, "inconsistent dirty state");
+ if (unlikely(!folio_test_dirty(folio))) {
+ if (WARN_ONCE(!sb_rdonly(smap_inode->i_sb),
+ "inconsistent dirty state\n"))
+ goto unlock_folio;
+
+ /*
+ * If the filesystem has been forced to read-only
+ * due to metadata corruption.
+ */
+ folio_unlock(folio);
+ err = -EROFS;
+ break;
+ }
dfolio = filemap_grab_folio(dmap, folio->index);
if (IS_ERR(dfolio)) {
@@ -277,6 +289,7 @@ int nilfs_copy_dirty_pages(struct address_space *dmap,
folio_unlock(dfolio);
folio_put(dfolio);
+unlock_folio:
folio_unlock(folio);
}
folio_batch_release(&fbatch);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0623/1518] scsi: smartpqi: Fix AIO retry marker cleared by SCSI core between dispatches.
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (621 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0622/1518] nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state mismatch Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0624/1518] RDMA/mlx5: Fix stack out-of-bounds read in cc_params debugfs Greg Kroah-Hartman
` (375 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mike McGowen, Don Brace,
David Strahan, Martin K. Petersen, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: David Strahan <David.Strahan@microchip.com>
[ Upstream commit 225548863f0a2350c6f34231ca56710c3dd1a5d5 ]
On recent Linux kernels the driver can enter a retry loop on the AIO fast
path when a request is retried, looping until timeout. A diagnostic path
that takes a physical drive offline on AIO-bypass failure is also never
entered on affected kernels.
Register a per-command initialization callback with the SCSI core. Its
presence causes the core to skip the per-dispatch clear, so the retry
marker now survives across the requeue and the AIO-to-RAID fallback
proceeds as intended. The driver takes over the marker's lifetime: it is
zeroed at tag allocation, preserved across the retry requeue so the error
path can act on it, and cleared on terminal completion so the tag starts
clean on its next use.
Fixes: dce5c4afd035 ("scsi: core: Clear driver private data when retrying request")
Co-developed-by: Mike McGowen <mike.mcgowen@microchip.com>
Signed-off-by: Mike McGowen <mike.mcgowen@microchip.com>
Acked-by: Don Brace <don.brace@microchip.com>
Signed-off-by: David Strahan <david.strahan@microchip.com>
Link: https://lore.kernel.org/linux-scsi/20260722220401.6357-1-david.strahan@microchip.com/
Link: https://patch.msgid.link/20260722220401.6357-2-david.strahan@microchip.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/smartpqi/smartpqi_init.c | 18 ++++++++++++++++++
1 file changed, 18 insertions(+)
diff --git a/drivers/scsi/smartpqi/smartpqi_init.c b/drivers/scsi/smartpqi/smartpqi_init.c
index 090e786470b39..88cffb1fb59ce 100644
--- a/drivers/scsi/smartpqi/smartpqi_init.c
+++ b/drivers/scsi/smartpqi/smartpqi_init.c
@@ -66,6 +66,12 @@ static struct pqi_cmd_priv *pqi_cmd_priv(struct scsi_cmnd *cmd)
return scsi_cmd_priv(cmd);
}
+static int pqi_init_cmd_priv(struct Scsi_Host *shost, struct scsi_cmnd *cmd)
+{
+ memset(pqi_cmd_priv(cmd), 0, sizeof(struct pqi_cmd_priv));
+ return 0;
+}
+
static void pqi_verify_structures(void);
static void pqi_take_ctrl_offline(struct pqi_ctrl_info *ctrl_info,
enum pqi_ctrl_shutdown_reason ctrl_shutdown_reason);
@@ -5943,6 +5949,17 @@ void pqi_prep_for_scsi_done(struct scsi_cmnd *scmd)
struct pqi_scsi_dev *device;
struct completion *wait;
+ /*
+ * Clear the AIO-retry marker on final completion so the tag
+ * starts clean on its next dispatch. On DID_IMM_RETRY leave
+ * it intact: pqi_aio_io_complete() sets DID_IMM_RETRY and
+ * bumps the marker to steer the requeue onto the RAID path,
+ * and pqi_process_raid_io_error() consumes the non-zero
+ * marker to offline a misbehaving drive.
+ */
+ if (host_byte(scmd->result) != DID_IMM_RETRY)
+ pqi_cmd_priv(scmd)->this_residual = 0;
+
if (!scmd->device) {
set_host_byte(scmd, DID_NO_CONNECT);
return;
@@ -7596,6 +7613,7 @@ static const struct scsi_host_template pqi_driver_template = {
.sdev_groups = pqi_sdev_groups,
.shost_groups = pqi_shost_groups,
.cmd_size = sizeof(struct pqi_cmd_priv),
+ .init_cmd_priv = pqi_init_cmd_priv,
};
static int pqi_register_scsi(struct pqi_ctrl_info *ctrl_info)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0624/1518] RDMA/mlx5: Fix stack out-of-bounds read in cc_params debugfs
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (622 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0623/1518] scsi: smartpqi: Fix AIO retry marker cleared by SCSI core between dispatches Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0625/1518] RDMA/mlx5: Send cong param changes to the resolved port mdev Greg Kroah-Hartman
` (374 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leon Romanovsky <leonro@nvidia.com>
[ Upstream commit 03826bc1fa6c90405bf05831f2b501a8368dcd27 ]
get_param() reads a congestion parameter as a u32 but formats it with the
signed "%d" into an 11-byte stack buffer. A value with bit 31 set, such as
0x80000000, renders as "-2147483648\n" whose full length is 12. snprintf()
stores only 11 bytes yet returns 12, so simple_read_from_buffer() treats 12
bytes as valid and reads one byte past lbuf[].
Size the buffer for the widest unsigned decimal, format with "%u" to match
the u32, and use scnprintf() so the length passed to
simple_read_from_buffer() reflects the bytes actually stored.
Fixes: 4a2da0b8c0782 ("IB/mlx5: Add debug control parameters for congestion control")
Link: https://patch.msgid.link/20260726-get-param-leaks-kernel-stack-memory-v1-1-d61a4d39662d@nvidia.com
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/mlx5/cong.c | 6 ++----
1 file changed, 2 insertions(+), 4 deletions(-)
diff --git a/drivers/infiniband/hw/mlx5/cong.c b/drivers/infiniband/hw/mlx5/cong.c
index a78a067e3ce7f..88ac5fd1038ed 100644
--- a/drivers/infiniband/hw/mlx5/cong.c
+++ b/drivers/infiniband/hw/mlx5/cong.c
@@ -399,15 +399,13 @@ static ssize_t get_param(struct file *filp, char __user *buf, size_t count,
int offset = param->offset;
u32 var = 0;
int ret;
- char lbuf[11];
+ char lbuf[12];
ret = mlx5_ib_get_cc_params(param->dev, param->port_num, offset, &var);
if (ret)
return ret;
- ret = snprintf(lbuf, sizeof(lbuf), "%d\n", var);
- if (ret < 0)
- return ret;
+ ret = scnprintf(lbuf, sizeof(lbuf), "%u\n", var);
return simple_read_from_buffer(buf, count, pos, lbuf, ret);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0625/1518] RDMA/mlx5: Send cong param changes to the resolved port mdev
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (623 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0624/1518] RDMA/mlx5: Fix stack out-of-bounds read in cc_params debugfs Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0626/1518] RDMA/cxgb4: free STAG index when TPT entry write fails Greg Kroah-Hartman
` (373 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leon Romanovsky <leonro@nvidia.com>
[ Upstream commit 033a79e308e4fe832b0924347eda8c4364055174 ]
mlx5_ib_set_cc_params() resolves the port-specific mlx5_core_dev via
mlx5_ib_get_native_port_mdev() but issued MLX5_CMD_OP_MODIFY_CONG_PARAMS
through dev->mdev. On an affiliated secondary RoCE port those pointers
refer to different devices, so a write to the secondary port's cc_params
debugfs file either altered the master port or failed with a master-side
command error, while the read path already used the resolved mdev and
returned the unchanged secondary value.
Issue the command to the resolved mdev, the same device whose capabilities
were checked when its debugfs directory was created. It is already
referenced by the get/put pair, so its lifetime is safe.
Fixes: 31578defe4eb ("RDMA/mlx5: Update mlx5_ib to use new cmd interface")
Link: https://patch.msgid.link/20260726-mlx5-ib-set-cc-params-applies-conges-v1-1-a253edafe1f3@nvidia.com
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/mlx5/cong.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/infiniband/hw/mlx5/cong.c b/drivers/infiniband/hw/mlx5/cong.c
index 88ac5fd1038ed..e3c4b1c928169 100644
--- a/drivers/infiniband/hw/mlx5/cong.c
+++ b/drivers/infiniband/hw/mlx5/cong.c
@@ -361,7 +361,7 @@ static int mlx5_ib_set_cc_params(struct mlx5_ib_dev *dev, u32 port_num,
MLX5_SET(field_select_r_roce_rp, field, field_select_r_roce_rp,
attr_mask);
- err = mlx5_cmd_exec_in(dev->mdev, modify_cong_params, in);
+ err = mlx5_cmd_exec_in(mdev, modify_cong_params, in);
kvfree(in);
alloc_err:
mlx5_ib_put_native_port_mdev(dev, port_num + 1);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0626/1518] RDMA/cxgb4: free STAG index when TPT entry write fails
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (624 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0625/1518] RDMA/mlx5: Send cong param changes to the resolved port mdev Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0627/1518] media: staging/ipu7: fix async notifier leak on init error Greg Kroah-Hartman
` (372 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leon Romanovsky <leonro@nvidia.com>
[ Upstream commit fdfb5cea4bf070cdb31d997efd87bb684df041fd ]
write_tpt_entry() allocates a new STAG index with c4iw_get_resource() and
bumps stats.stag.cur before programming the entry. When
write_adapter_mem() fails, it returns the error without releasing the index
or reversing the statistic. No MR is inserted into rhp->mrs, so
deregistration never reclaims it, leaking the index until device teardown.
Record whether this call allocated the index and, on a failed write, return
it to tpt_table and decrement stats.stag.cur. Key the rollback on both the
write error and that flag, not the error alone: a non-reset update carries
a caller-owned STAG that this call did not allocate and must not free.
Fixes: ec3eead21718 ("RDMA/cxgb4: Remove kfifo usage")
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/cxgb4/mem.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/infiniband/hw/cxgb4/mem.c b/drivers/infiniband/hw/cxgb4/mem.c
index 40dd6ac5f91af..ac349de9d2e44 100644
--- a/drivers/infiniband/hw/cxgb4/mem.c
+++ b/drivers/infiniband/hw/cxgb4/mem.c
@@ -277,6 +277,7 @@ static int write_tpt_entry(struct c4iw_rdev *rdev, u32 reset_tpt_entry,
int err;
struct fw_ri_tpte *tpt;
u32 stag_idx;
+ bool stag_idx_allocated = false;
static atomic_t key;
if (c4iw_fatal_error(rdev))
@@ -299,6 +300,7 @@ static int write_tpt_entry(struct c4iw_rdev *rdev, u32 reset_tpt_entry,
return -ENOMEM;
}
mutex_lock(&rdev->stats.lock);
+ stag_idx_allocated = true;
rdev->stats.stag.cur += 32;
if (rdev->stats.stag.cur > rdev->stats.stag.max)
rdev->stats.stag.max = rdev->stats.stag.cur;
@@ -333,7 +335,7 @@ static int write_tpt_entry(struct c4iw_rdev *rdev, u32 reset_tpt_entry,
(rdev->lldi.vr->stag.start >> 5),
sizeof(*tpt), tpt, skb, wr_waitp);
- if (reset_tpt_entry) {
+ if (reset_tpt_entry || (err && stag_idx_allocated)) {
c4iw_put_resource(&rdev->resource.tpt_table, stag_idx);
mutex_lock(&rdev->stats.lock);
rdev->stats.stag.cur -= 32;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0627/1518] media: staging/ipu7: fix async notifier leak on init error
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (625 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0626/1518] RDMA/cxgb4: free STAG index when TPT entry write fails Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0628/1518] IB/isert: reject PDUs declaring more data than was received Greg Kroah-Hartman
` (371 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Cong Nguyen, Sakari Ailus,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cong Nguyen <congnt264@gmail.com>
[ Upstream commit 11ccf31a657f9f95260a22848b7d324d3c6cf113 ]
isys_notifier_init() initialises a v4l2 async notifier and then, for
each CSI-2 port, adds a remote sensor subdev to the notifier's
waiting_list via v4l2_async_nf_add_fwnode_remote(), which allocates a
sensor_async_sd descriptor and takes a fwnode reference.
If parsing or adding a later port fails, the code jumps to the
"err_parse" label, which only drops the current endpoint fwnode
reference and returns, without calling v4l2_async_nf_cleanup(). Any
descriptors already added to the notifier for earlier ports are
therefore leaked, and the caller's error path does not clean up the
notifier either.
Call v4l2_async_nf_cleanup() on the error path, matching the cleanup
already performed when v4l2_async_nf_register() fails. This is safe as
the notifier is always initialised before the loop is entered.
Fixes: a516d36bdc3d ("media: staging/ipu7: add IPU7 input system device driver")
Signed-off-by: Cong Nguyen <congnt264@gmail.com>
Signed-off-by: Sakari Ailus <sakari.ailus@linux.intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/staging/media/ipu7/ipu7-isys.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/staging/media/ipu7/ipu7-isys.c b/drivers/staging/media/ipu7/ipu7-isys.c
index bf262c01a2b80..601e5a79ef8ec 100644
--- a/drivers/staging/media/ipu7/ipu7-isys.c
+++ b/drivers/staging/media/ipu7/ipu7-isys.c
@@ -233,6 +233,7 @@ static int isys_notifier_init(struct ipu7_isys *isys)
err_parse:
fwnode_handle_put(ep);
+ v4l2_async_nf_cleanup(&isys->notifier);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0628/1518] IB/isert: reject PDUs declaring more data than was received
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (626 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0627/1518] media: staging/ipu7: fix async notifier leak on init error Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0629/1518] IB/isert: reject login " Greg Kroah-Hartman
` (370 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yehyeong Lee, Leon Romanovsky,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
[ Upstream commit 957f92ea4022fb6af4618271615a2a21a7b5bef9 ]
isert_recv_done() hands each received PDU to the opcode handlers without
ever looking at wc->byte_len, the number of bytes the HCA actually placed
in the receive descriptor. The handlers then copy that many bytes - the
data-segment length the initiator declared in the BHS
(ntoh24(hdr->dlength), via the derived unsol_data_len / imm_data_len) -
out of the fixed-size descriptor:
isert_handle_iscsi_dataout():
sg_copy_from_buffer(sg_start, sg_nents, isert_get_data(rx_desc),
unsol_data_len);
isert_handle_scsi_cmd():
sg_copy_from_buffer(cmd->se_cmd.t_data_sg, sg_nents,
isert_get_data(rx_desc), imm_data_len);
Because the declared length is never checked against wc->byte_len, an
initiator can declare a data segment larger than the bytes it actually
sent (and larger than the descriptor) and cause an out-of-bounds read of
the receive buffer.
Nothing upstream of isert closes this door:
- __iscsit_check_dataout_hdr() bounds the inbound payload against
conn_ops->MaxXmitDataSegmentLength (MXDSL) - a transmit parameter,
used here for the inbound check.
- iscsi_set_connection_parameters() sets
ops->MaxXmitDataSegmentLength = ops->TargetRecvDataSegmentLength;
and TARGETRECVDATASEGMENTLENGTH is absent from the min()-clamp list in
iscsi_check_acceptor_state(), so the value the initiator declares is
adopted verbatim (type range 512..16777215). The initiator effectively
raises its own ceiling.
- isert never clamps the negotiated value to its own fixed receive
descriptor (ISER_RX_SIZE, 9216 bytes), so the target core's bound and
the descriptor size are unrelated.
The imm_data_len == data_len path is more than an over-read: it aliases
the receive descriptor via sg_set_buf() and passes it to the backend as
the data source for the SCSI WRITE, so an over-declared length causes heap
contents past the descriptor to be written through the backend to the
backing store. The backend is the victim of the oversized scatterlist
isert hands it, not the cause; no read-back of the written bytes was
demonstrated.
Trigger: after login completes (full feature phase), an initiator that has
declared a large TargetRecvDataSegmentLength and a FirstBurstLength that
permits unsolicited/immediate data sends a PDU whose declared data-segment
length exceeds what was received. With KASAN:
BUG: KASAN: slab-out-of-bounds in sg_copy_buffer+0x150/0x1c0
Read of size 4096 at addr ffff888109720800 by task kworker/1:0H/25
Workqueue: ib-comp-wq ib_cq_poll_work
Call Trace:
sg_copy_buffer+0x150/0x1c0
isert_recv_done+0xba6/0x2390
__ib_process_cq+0xe1/0x390
ib_cq_poll_work+0x46/0x150
isert_recv_done+0xba6 resolves to isert_handle_iscsi_dataout()
(ib_isert.c:1160), inlined through isert_rx_opcode().
Validate wc->byte_len against the framing in isert_recv_done() before the
PDU reaches any handler, and reinstate the connection if it is short.
Because the test compares without subtracting the header length, it also
rejects PDUs shorter than the iSER and iSCSI headers, which would otherwise
be parsed out of stale descriptor contents. The login handler rejects PDUs
shorter than ISER_HEADERS_LEN (commit 29e7b925ae6d ("IB/isert: Reject login
PDUs shorter than ISER_HEADERS_LEN")) but does not bound the declared
length either; that is fixed in the next patch. The data handlers had no
length check at all.
isert reads the data segment from a fixed offset: isert_get_data()
returns the iSER header plus ISER_HEADERS_LEN and makes no adjustment for
an AHS. The bytes the handlers touch are therefore exactly
[ISER_HEADERS_LEN, ISER_HEADERS_LEN + dlength), and comparing that sum
against wc->byte_len bounds precisely the region that is read. An AHS
term would only make the test stricter without bounding anything further,
and cannot cause a false reject: a PDU carrying an AHS is longer, not
shorter.
This is a memory-safety fix that verifies the bytes that were actually
received; it does not touch RFC 7145 length negotiation and is not the
MaxXmitDataSegmentLength negotiation redesign raised in the 2017 "[Query]
iSER-Target: QP errors observed on increasing MaxXmitDataSegmentLength"
discussion. That redesign is explicitly out of scope here.
The patched kernel rejects the malformed DataOut PDU and both
immediate-data variants with "PDU declares ... bytes were received" and
continues to pass normal traffic with no regression.
Reproduced with soft-RoCE (rdma_rxe) and a raw rdma_cm/ibv initiator; no
kernel-side test hooks were needed.
Fixes: b8d26b3be8b3 ("iser-target: Add iSCSI Extensions for RDMA (iSER) target driver")
Signed-off-by: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
Link: https://patch.msgid.link/20260726163931.971063-2-yhlee@isslab.korea.ac.kr
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/ulp/isert/ib_isert.c | 15 +++++++++++++++
1 file changed, 15 insertions(+)
diff --git a/drivers/infiniband/ulp/isert/ib_isert.c b/drivers/infiniband/ulp/isert/ib_isert.c
index 640634f96d72a..9426aeeaddecc 100644
--- a/drivers/infiniband/ulp/isert/ib_isert.c
+++ b/drivers/infiniband/ulp/isert/ib_isert.c
@@ -1335,6 +1335,21 @@ isert_recv_done(struct ib_cq *cq, struct ib_wc *wc)
ib_dma_sync_single_for_cpu(ib_dev, rx_desc->dma_addr,
ISER_RX_SIZE, DMA_FROM_DEVICE);
+ /*
+ * The data segment length declared in the BHS is attacker controlled
+ * and is used further down to read that many bytes out of the fixed
+ * size receive descriptor, so it has to be checked against the number
+ * of bytes that were actually received. Comparing without subtracting
+ * also rejects PDUs shorter than the iSER and iSCSI headers, which
+ * would otherwise be parsed out of stale descriptor contents.
+ */
+ if (unlikely(wc->byte_len < ISER_HEADERS_LEN + ntoh24(hdr->dlength))) {
+ isert_err("PDU declares %u data bytes but only %u bytes were received\n",
+ ntoh24(hdr->dlength), wc->byte_len);
+ iscsit_cause_connection_reinstatement(isert_conn->conn, 0);
+ return;
+ }
+
isert_dbg("DMA: 0x%llx, iSCSI opcode: 0x%02x, ITT: 0x%08x, flags: 0x%02x dlen: %d\n",
rx_desc->dma_addr, hdr->opcode, hdr->itt, hdr->flags,
(int)(wc->byte_len - ISER_HEADERS_LEN));
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0629/1518] IB/isert: reject login PDUs declaring more data than was received
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (627 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0628/1518] IB/isert: reject PDUs declaring more data than was received Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0630/1518] nvme-fc: unmap cmd_iu DMA on rsp_iu mapping failure in init_request Greg Kroah-Hartman
` (369 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Leon Romanovsky, Yehyeong Lee,
Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
[ Upstream commit 2488b5b4827e5415768afc8daf097e8eb83c98df ]
isert_login_recv_done() records how many bytes the HCA actually placed in
the login buffer, but nothing compares that against the length the login
PDU's BHS declares. isert_rx_login_req() copies min(login_req_len,
MAX_KEY_VALUE_PAIRS) bytes into login->req_buf, and the login code then
reads the declared length back out of that buffer - for the first PDU in
iscsi_target_locate_portal(),
payload_length = ntoh24(login_req->dlength);
tmpbuf = kmemdup_nul(login->req_buf, payload_length, GFP_KERNEL);
and for the ones after it in iscsi_decode_text_input(), reached from
iscsi_target_do_login().
login->req_buf is a fixed MAX_KEY_VALUE_PAIRS (8192) byte allocation, so
an initiator that declares more than it sends reads off the end of it,
before authentication and with the length under its control:
BUG: KASAN: slab-out-of-bounds in kmemdup_nul+0x43/0x80
Read of size 8193 at addr ffff8881056a8000 by task iscsi_np/167
__asan_memcpy+0x23/0x60
kmemdup_nul+0x43/0x80
iscsi_target_locate_portal+0x48d/0x1180
iscsi_target_login_thread+0x19a9/0x3350
Allocated by task 167:
__kmalloc_cache_noprof+0x158/0x370
iscsi_target_login_thread+0x971/0x3350
which belongs to the cache kmalloc-8k of size 8192
allocated 8192-byte region
Falsifying the second login PDU instead reaches the other reader, on the
same buffer:
BUG: KASAN: slab-out-of-bounds in kmemdup_nul+0x43/0x80
Read of size 8193 at addr ffff888104d10000 by task kworker/1:1/50
Workqueue: isert_login_wq iscsi_target_do_login_rx
__asan_memcpy+0x23/0x60
kmemdup_nul+0x43/0x80
iscsi_decode_text_input+0xc6/0x11c0
iscsi_target_do_login+0x261/0x1470
iscsi_target_do_login_rx+0x51d/0x7d0
iscsit over TCP is not exposed: iscsit_get_login_rx() validates the
declared length with iscsi_target_check_login_request() and then reads
exactly that many bytes off the socket, so the declared length governs
how much arrives rather than how much is copied out of an already-filled
buffer. isert does not call iscsi_target_check_login_request() at all.
Reject a login PDU whose declared DataSegmentLength exceeds what was
received, in both paths that reach isert_rx_login_req():
isert_get_login_rx() for the first login PDU and isert_login_recv_done()
for the ones after it. dlength <= login_req_len is allowed because the
received count can include up to three bytes of iSCSI padding.
Once the check is in place the copy out can no longer exceed the copy in:
the posted login SGE is ISER_RX_PAYLOAD_SIZE, so login_req_len cannot
exceed MAX_KEY_VALUE_PAIRS and the min() in isert_rx_login_req() is
login_req_len.
Like the existing short-PDU check added by 29e7b925ae6d, the reject in
isert_login_recv_done() returns without completing login_req_comp, so a
malformed subsequent PDU leaves the login to be torn down by the login
timer rather than failing immediately. The first-PDU path returns an
error and fails straight away.
Reproduced on 7.2.0-rc4 with soft-RoCE (rdma_rxe) under KASAN, using an
initiator that sends the real key=value payload while declaring 8193 in
the BHS, on the first login PDU and on the second in separate runs. The
reported read size tracks the declared value exactly; 16384 and 61440
behave the same. Unpatched 3 of 3 runs report on each of the two paths,
patched 0 of 3 on both, run alternately in a single session, and a normal
login still completes on the patched build.
Fixes: b8d26b3be8b3 ("iser-target: Add iSCSI Extensions for RDMA (iSER) target driver")
Suggested-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
Link: https://patch.msgid.link/20260726163931.971063-3-yhlee@isslab.korea.ac.kr
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/ulp/isert/ib_isert.c | 25 ++++++++++++++++++++++++-
1 file changed, 24 insertions(+), 1 deletion(-)
diff --git a/drivers/infiniband/ulp/isert/ib_isert.c b/drivers/infiniband/ulp/isert/ib_isert.c
index 9426aeeaddecc..1fcaf7df8b398 100644
--- a/drivers/infiniband/ulp/isert/ib_isert.c
+++ b/drivers/infiniband/ulp/isert/ib_isert.c
@@ -973,6 +973,21 @@ isert_put_login_tx(struct iscsit_conn *conn, struct iscsi_login *login,
return 0;
}
+static int
+isert_check_login_req(struct isert_conn *isert_conn)
+{
+ struct iscsi_hdr *hdr = isert_get_iscsi_hdr(isert_conn->login_desc);
+ u32 dlength = ntoh24(hdr->dlength);
+
+ if (unlikely(dlength > (u32)isert_conn->login_req_len)) {
+ isert_dbg("login PDU declares %u data bytes but only %d were received\n",
+ dlength, isert_conn->login_req_len);
+ return -EINVAL;
+ }
+
+ return 0;
+}
+
static void
isert_rx_login_req(struct isert_conn *isert_conn)
{
@@ -1411,8 +1426,12 @@ isert_login_recv_done(struct ib_cq *cq, struct ib_wc *wc)
if (isert_conn->conn) {
struct iscsi_login *login = isert_conn->conn->conn_login;
- if (login && !login->first_request)
+ if (login && !login->first_request) {
+ if (isert_check_login_req(isert_conn))
+ return;
+
isert_rx_login_req(isert_conn);
+ }
}
mutex_lock(&isert_conn->mutex);
@@ -2377,6 +2396,10 @@ isert_get_login_rx(struct iscsit_conn *conn, struct iscsi_login *login)
if (!login->first_request)
return 0;
+ ret = isert_check_login_req(isert_conn);
+ if (ret)
+ return ret;
+
isert_rx_login_req(isert_conn);
isert_info("before login_comp conn: %p\n", conn);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0630/1518] nvme-fc: unmap cmd_iu DMA on rsp_iu mapping failure in init_request
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (628 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0629/1518] IB/isert: reject login " Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0631/1518] spi: davinci: switch to managed controller allocation Greg Kroah-Hartman
` (368 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christoph Hellwig, Guixin Liu,
Keith Busch, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guixin Liu <kanie@linux.alibaba.com>
[ Upstream commit f49d0c3a8d56a7cda1628ae17341a4a42063563c ]
__nvme_fc_init_request() maps cmd_iu and then rsp_iu for DMA. If the
rsp_iu mapping fails, the original code only recorded the error and fell
through: it left the already-mapped cmd_iu unmapped and still marked the
op as FCPOP_STATE_IDLE before returning. Since blk-mq does not call
.exit_request() when .init_request() fails, the cmd_iu mapping is leaked
for every op whose rsp_iu mapping fails.
Jump to an error path on rsp_iu mapping failure that unmaps cmd_iu and
returns the error without marking the op idle, so it stays in the
FCPOP_STATE_UNINIT state set by the initial memset().
Fixes: e399441de911 ("nvme-fabrics: Add host support for FC transport")
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Guixin Liu <kanie@linux.alibaba.com>
Signed-off-by: Keith Busch <kbusch@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/nvme/host/fc.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/nvme/host/fc.c b/drivers/nvme/host/fc.c
index bdfbd5701ba60..5a6ef2d1830e3 100644
--- a/drivers/nvme/host/fc.c
+++ b/drivers/nvme/host/fc.c
@@ -2098,9 +2098,15 @@ __nvme_fc_init_request(struct nvme_fc_ctrl *ctrl,
dev_err(ctrl->dev,
"FCP Op failed - rspiu dma mapping failed.\n");
ret = -EFAULT;
+ goto out_unmap;
}
atomic_set(&op->state, FCPOP_STATE_IDLE);
+ return 0;
+
+out_unmap:
+ fc_dma_unmap_single(ctrl->lport->dev, op->fcp_req.cmddma,
+ sizeof(op->cmd_iu), DMA_TO_DEVICE);
out_on_error:
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0631/1518] spi: davinci: switch to managed controller allocation
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (629 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0630/1518] nvme-fc: unmap cmd_iu DMA on rsp_iu mapping failure in init_request Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0632/1518] wifi: ath11k: fix overreads in ath11k_wmi_process_csa_switch_count_event() Greg Kroah-Hartman
` (367 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Fan Wu, Mark Brown, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fan Wu <fanwu01@zju.edu.cn>
[ Upstream commit ea408a05dc8f18b4a184b88d6e19d2fd1acc1527 ]
The controller is allocated with the non-managed spi_alloc_host() while
the interrupt is registered with devm_request_threaded_irq(). During
removal, spi_bitbang_stop() only unregisters the controller; the
subsequent spi_controller_put() then frees the controller together with
its embedded davinci_spi devdata, which is the IRQ handler's dev_id.
The devm_request_threaded_irq() release action (free_irq()), which
drains the handler, does not run until after .remove() returns. A late
or latched interrupt can therefore reach davinci_spi_irq() and
dereference already-freed memory.
Switch to devm_spi_alloc_host() so that the devres LIFO order releases
the controller only after free_irq() has drained the handler, and drop
the now-redundant spi_controller_put() from .remove(). The probe error
path is simplified to direct returns.
The clock is acquired with devm_clk_get_enabled(), which is registered
after the IRQ and thus released before it by the devres LIFO order.
Drain the interrupt explicitly with devm_free_irq() before disabling the
controller so that a late interrupt cannot access the registers of a
clock-gated controller.
This issue was found by an in-house static analysis tool.
Fixes: 5b3bb5963ff2 ("spi: davinci: Use devm_*() functions")
Assisted-by: Codex:gpt-5.6
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Link: https://patch.msgid.link/20260719010014.3163356-2-fanwu01@zju.edu.cn
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/spi/spi-davinci.c | 7 +++----
1 file changed, 3 insertions(+), 4 deletions(-)
diff --git a/drivers/spi/spi-davinci.c b/drivers/spi/spi-davinci.c
index a29934422356b..c0963483e05c8 100644
--- a/drivers/spi/spi-davinci.c
+++ b/drivers/spi/spi-davinci.c
@@ -868,7 +868,7 @@ static int davinci_spi_probe(struct platform_device *pdev)
int ret = 0;
u32 spipc0;
- host = spi_alloc_host(&pdev->dev, sizeof(struct davinci_spi));
+ host = devm_spi_alloc_host(&pdev->dev, sizeof(struct davinci_spi));
if (host == NULL) {
ret = -ENOMEM;
goto err;
@@ -998,7 +998,6 @@ static int davinci_spi_probe(struct platform_device *pdev)
dma_release_channel(dspi->dma_tx);
}
free_host:
- spi_controller_put(host);
err:
return ret;
}
@@ -1022,6 +1021,8 @@ static void davinci_spi_remove(struct platform_device *pdev)
spi_bitbang_stop(&dspi->bitbang);
+ devm_free_irq(&pdev->dev, dspi->irq, dspi);
+
/* This bit needs to be cleared to disable dpsi->clk */
clear_io_bits(dspi->base + SPIGCR1, SPIGCR1_POWERDOWN_MASK);
@@ -1029,8 +1030,6 @@ static void davinci_spi_remove(struct platform_device *pdev)
dma_release_channel(dspi->dma_rx);
dma_release_channel(dspi->dma_tx);
}
-
- spi_controller_put(host);
}
static struct platform_driver davinci_spi_driver = {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0632/1518] wifi: ath11k: fix overreads in ath11k_wmi_process_csa_switch_count_event()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (630 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0631/1518] spi: davinci: switch to managed controller allocation Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0633/1518] wifi: ath12k: validate TLV length in process_tpc_stats() Greg Kroah-Hartman
` (366 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rameshkumar Sundaram, Baochen Qiang,
Jeff Johnson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
[ Upstream commit 208d7fdb85976a737a715b81d54efaff6703880c ]
There is no policy entry for WMI_TAG_PDEV_CSA_SWITCH_COUNT_STATUS_EVENT, so
the parse infrastructure does not enforce a minimum length for the event
struct. Additionally, the num_vdevs field is taken directly from firmware
and used as a loop bound over the vdev_ids array without checking that it
fits within the TLV payload. Either condition can cause an out-of-bounds
read.
Add a TLV policy entry for WMI_TAG_PDEV_CSA_SWITCH_COUNT_STATUS_EVENT so
the parse infrastructure enforces a minimum length for the fixed-size event
struct. Add a helper ath11k_wmi_tlv_data_len() to recover the payload
length of a parsed TLV from the header preceding its data pointer. Use it
in ath11k_wmi_process_csa_switch_count_event() to bound num_vdevs before
the loop.
Compile tested only.
Fixes: d5c65159f289 ("ath11k: driver for Qualcomm IEEE 802.11ax devices")
Assisted-by: Claude:claude-sonnet-4-6
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Link: https://patch.msgid.link/20260724-ath12k_wmi_process_csa_switch_count_event-cleanup-v2-2-02a45d7246c0@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/ath/ath11k/wmi.c | 21 +++++++++++++++++++--
1 file changed, 19 insertions(+), 2 deletions(-)
diff --git a/drivers/net/wireless/ath/ath11k/wmi.c b/drivers/net/wireless/ath/ath11k/wmi.c
index 1303931f97663..8fb91586abd5e 100644
--- a/drivers/net/wireless/ath/ath11k/wmi.c
+++ b/drivers/net/wireless/ath/ath11k/wmi.c
@@ -159,6 +159,8 @@ static const struct wmi_tlv_policy wmi_tlv_policies[] = {
.min_len = sizeof(struct ath11k_wmi_p2p_noa_info) },
[WMI_TAG_P2P_NOA_EVENT] = {
.min_len = sizeof(struct wmi_p2p_noa_event) },
+ [WMI_TAG_PDEV_CSA_SWITCH_COUNT_STATUS_EVENT] = {
+ .min_len = sizeof(struct wmi_pdev_csa_switch_ev) },
};
#define PRIMAP(_hw_mode_) \
@@ -262,6 +264,13 @@ const void **ath11k_wmi_tlv_parse_alloc(struct ath11k_base *ab,
return tb;
}
+static u32 ath11k_wmi_tlv_data_len(const void *data)
+{
+ const struct wmi_tlv *tlv = (const struct wmi_tlv *)data - 1;
+
+ return FIELD_GET(WMI_TLV_LEN, tlv->header);
+}
+
static int ath11k_wmi_cmd_send_nowait(struct ath11k_pdev_wmi *wmi, struct sk_buff *skb,
u32 cmd_id)
{
@@ -8302,15 +8311,23 @@ ath11k_wmi_process_csa_switch_count_event(struct ath11k_base *ab,
const struct wmi_pdev_csa_switch_ev *ev,
const u32 *vdev_ids)
{
- int i;
+ u32 vdev_ids_len = ath11k_wmi_tlv_data_len(vdev_ids);
+ u32 num_vdevs = ev->num_vdevs;
struct ath11k_vif *arvif;
+ int i;
/* Finish CSA once the switch count becomes NULL */
if (ev->current_switch_count)
return;
+ if (num_vdevs > vdev_ids_len / sizeof(*vdev_ids)) {
+ ath11k_warn(ab, "csa switch count num_vdevs %u exceeds tlv array length %u\n",
+ num_vdevs, vdev_ids_len);
+ return;
+ }
+
rcu_read_lock();
- for (i = 0; i < ev->num_vdevs; i++) {
+ for (i = 0; i < num_vdevs; i++) {
arvif = ath11k_mac_get_arvif_by_vdev_id(ab, vdev_ids[i]);
if (!arvif) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0633/1518] wifi: ath12k: validate TLV length in process_tpc_stats()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (631 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0632/1518] wifi: ath11k: fix overreads in ath11k_wmi_process_csa_switch_count_event() Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0634/1518] PCI: starfive: Fix Runtime PM handling and teardown ordering Greg Kroah-Hartman
` (365 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Baochen Qiang, Rameshkumar Sundaram,
Jeff Johnson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
[ Upstream commit 8e415b8068480d51a057197ded974e2637e8c42b ]
The outer skb->len guard only confirms the SKB is large enough
to hold the full fixed_param struct, but the TLV's own WMI_TLV_LEN
field is never checked. Firmware advertising a TLV length shorter
than sizeof(*fixed_param) causes reads of pdev_id and event_count
beyond the declared TLV payload.
Add a check that the TLV length is at least sizeof(*fixed_param)
before casting and dereferencing the pointer.
Fixes: d889913205cf ("wifi: ath12k: driver for Qualcomm Wi-Fi 7 devices")
Assisted-by: Claude:claude-sonnet-4-6
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Link: https://patch.msgid.link/20260726-ath12k_wmi_process_tpc_stats-len-check-v1-1-c4ba2f84d9c6@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/ath/ath12k/wmi.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/drivers/net/wireless/ath/ath12k/wmi.c b/drivers/net/wireless/ath/ath12k/wmi.c
index 077154b564aeb..6221bf43936bc 100644
--- a/drivers/net/wireless/ath/ath12k/wmi.c
+++ b/drivers/net/wireless/ath/ath12k/wmi.c
@@ -9410,6 +9410,7 @@ static void ath12k_wmi_process_tpc_stats(struct ath12k_base *ab,
void *ptr = skb->data;
struct ath12k *ar;
u16 tlv_tag;
+ u16 tlv_len;
u32 event_count;
int ret;
@@ -9425,6 +9426,7 @@ static void ath12k_wmi_process_tpc_stats(struct ath12k_base *ab,
tlv = (struct wmi_tlv *)ptr;
tlv_tag = le32_get_bits(tlv->header, WMI_TLV_TAG);
+ tlv_len = le32_get_bits(tlv->header, WMI_TLV_LEN);
ptr += sizeof(*tlv);
if (tlv_tag != WMI_TAG_HALPHY_CTRL_PATH_EVENT_FIXED_PARAM) {
@@ -9432,6 +9434,12 @@ static void ath12k_wmi_process_tpc_stats(struct ath12k_base *ab,
return;
}
+ if (tlv_len < sizeof(*fixed_param)) {
+ ath12k_warn(ab, "TPC stats fixed param tlv len %u too short\n",
+ tlv_len);
+ return;
+ }
+
fixed_param = (struct ath12k_wmi_pdev_tpc_stats_event_fixed_params *)ptr;
rcu_read_lock();
ar = ath12k_mac_get_ar_by_pdev_id(ab, le32_to_cpu(fixed_param->pdev_id) + 1);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0634/1518] PCI: starfive: Fix Runtime PM handling and teardown ordering
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (632 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0633/1518] wifi: ath12k: validate TLV length in process_tpc_stats() Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0635/1518] PCI: starfive: Fix unchecked pm_runtime_get_sync() in probe Greg Kroah-Hartman
` (364 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ali Tariq, Manivannan Sadhasivam,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ali Tariq <alitariq45892@gmail.com>
[ Upstream commit fb9f7973473fc30d62e0f5f90d59df8ef5223777 ]
The starfive_pcie_remove() path incorrectly disabled runtime PM
before executing plda_pcie_host_deinit(), which can cause unmanaged
hardware register access in plda_pcie_host_deinit() while power domains or
clocks are disabled.
Fix this by restructuring starfive_pcie_remove() to deinitialize the host
controller first while runtime PM is active, followed by a synchronous
pm_runtime_put_sync() and pm_runtime_disable().
This bug was found in automated AI review by sashiko-bot.
Fixes: 39b91eb40c6a ("PCI: starfive: Add JH7110 PCIe controller")
Closes: https://lore.kernel.org/linux-pci/20260712180440.423421F000E9@smtp.kernel.org/
Signed-off-by: Ali Tariq <alitariq45892@gmail.com>
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Link: https://patch.msgid.link/20260718133825.445041-1-alitariq45892@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pci/controller/plda/pcie-starfive.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/pci/controller/plda/pcie-starfive.c b/drivers/pci/controller/plda/pcie-starfive.c
index 628f8c8d67471..0ca39f3fa1d4f 100644
--- a/drivers/pci/controller/plda/pcie-starfive.c
+++ b/drivers/pci/controller/plda/pcie-starfive.c
@@ -445,9 +445,9 @@ static void starfive_pcie_remove(struct platform_device *pdev)
{
struct starfive_jh7110_pcie *pcie = platform_get_drvdata(pdev);
- pm_runtime_put(&pdev->dev);
- pm_runtime_disable(&pdev->dev);
plda_pcie_host_deinit(&pcie->plda);
+ pm_runtime_put_sync(&pdev->dev);
+ pm_runtime_disable(&pdev->dev);
platform_set_drvdata(pdev, NULL);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0635/1518] PCI: starfive: Fix unchecked pm_runtime_get_sync() in probe
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (633 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0634/1518] PCI: starfive: Fix Runtime PM handling and teardown ordering Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0636/1518] drm/msm: remove objects from evit list after pinning them Greg Kroah-Hartman
` (363 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ali Tariq, Manivannan Sadhasivam,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ali Tariq <alitariq45892@gmail.com>
[ Upstream commit aaae917990623a6ca6b638557056606a1ae4a8d6 ]
pm_runtime_get_sync() is called in starfive_pcie_probe() without
checking its return value. If runtime resume fails, the driver
proceeds to configure PCIe hardware through regmap_update_bits(),
enable clocks and resets, and power on the PHY, even though the
device may not actually be powered.
pm_runtime_get_sync() also increments the usage counter even when
resume fails, which would leave the counter unbalanced if this
error path were later handled without additional cleanup.
Switch to pm_runtime_resume_and_get(), which balances the usage
counter internally on failure, and bail out of probe before any
hardware is touched if resume does not succeed.
Tested on StarFive VisionFive 2 v1.2A board.
Fixes: 6168efbebace ("PCI: starfive: Enable controller runtime PM before probing host bridge")
Signed-off-by: Ali Tariq <alitariq45892@gmail.com>
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Link: https://patch.msgid.link/20260718153352.661930-1-alitariq45892@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pci/controller/plda/pcie-starfive.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/drivers/pci/controller/plda/pcie-starfive.c b/drivers/pci/controller/plda/pcie-starfive.c
index 0ca39f3fa1d4f..fab44054a5de2 100644
--- a/drivers/pci/controller/plda/pcie-starfive.c
+++ b/drivers/pci/controller/plda/pcie-starfive.c
@@ -419,7 +419,11 @@ static int starfive_pcie_probe(struct platform_device *pdev)
return ret;
pm_runtime_enable(&pdev->dev);
- pm_runtime_get_sync(&pdev->dev);
+ ret = pm_runtime_resume_and_get(&pdev->dev);
+ if (ret < 0) {
+ pm_runtime_disable(&pdev->dev);
+ return dev_err_probe(dev, ret, "failed to resume device\n");
+ }
plda->host_ops = &sf_host_ops;
plda->num_events = PLDA_MAX_EVENT_NUM;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0636/1518] drm/msm: remove objects from evit list after pinning them
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (634 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0635/1518] PCI: starfive: Fix unchecked pm_runtime_get_sync() in probe Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0637/1518] media: qcom: iris: Fix bitmask test in iris_allow_cmd() Greg Kroah-Hartman
` (362 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Anna Maniscalco, Rob Clark,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Anna Maniscalco <anna.maniscalco2000@gmail.com>
[ Upstream commit 83723f32cb3de23d45c1ac09241b5e0cfb32cc9b ]
Once objects are pinned they should not be kept in the evict list as
that will cause drm_gpuvm_validate to keep ieterating a growing list of
objects needlessly.
Once an object is pinned remove it from the list.
Fixes: 2e6a8a1fe2b2 ("drm/msm: Add VM_BIND ioctl")
Signed-off-by: Anna Maniscalco <anna.maniscalco2000@gmail.com>
Patchwork: https://patchwork.freedesktop.org/patch/742166/
Message-ID: <20260723-evict_list_fix-v2-1-bd0725e56253@gmail.com>
Signed-off-by: Rob Clark <robin.clark@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/msm_gem_vma.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/gpu/drm/msm/msm_gem_vma.c b/drivers/gpu/drm/msm/msm_gem_vma.c
index 9016ef978be5e..701fe4a0b73c9 100644
--- a/drivers/gpu/drm/msm/msm_gem_vma.c
+++ b/drivers/gpu/drm/msm/msm_gem_vma.c
@@ -452,6 +452,8 @@ msm_gem_vm_bo_validate(struct drm_gpuvm_bo *vm_bo, struct drm_exec *exec)
return ret;
}
+ drm_gpuvm_bo_evict(vm_bo, false);
+
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0637/1518] media: qcom: iris: Fix bitmask test in iris_allow_cmd()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (635 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0636/1518] drm/msm: remove objects from evit list after pinning them Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0638/1518] media: qcom: iris: handle runtime PM resume failure in core deinit Greg Kroah-Hartman
` (361 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bryan ODonoghue, Dikshita Agarwal,
Vishnu Reddy, Bryan ODonoghue, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dikshita Agarwal <dikshita.agarwal@oss.qualcomm.com>
[ Upstream commit 0ac05c4d9f1fa25d0692fb154de36bd3baf2e7ce ]
iris_allow_cmd() incorrectly checks a sub‑state flag using a logical
equality comparison. Since sub_state is a bitmask, this allows STOP to
pass when IRIS_INST_SUB_DRAIN is set alongside other bits, violating the
intended drain semantics. Fix this by using a proper bitmask test.
Fixes: d09100763bed ("media: iris: add support for drain sequence")
Reviewed-by: Bryan O'Donoghue <bryan.odonoghue@linaro.org>
Signed-off-by: Dikshita Agarwal <dikshita.agarwal@oss.qualcomm.com>
Signed-off-by: Vishnu Reddy <busanna.reddy@oss.qualcomm.com>
Signed-off-by: Bryan O'Donoghue <bod@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/media/platform/qcom/iris/iris_state.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/media/platform/qcom/iris/iris_state.c b/drivers/media/platform/qcom/iris/iris_state.c
index e991f34916ec6..5552725c614ea 100644
--- a/drivers/media/platform/qcom/iris/iris_state.c
+++ b/drivers/media/platform/qcom/iris/iris_state.c
@@ -269,7 +269,7 @@ bool iris_allow_cmd(struct iris_inst *inst, u32 cmd)
return true;
} else if (cmd == V4L2_DEC_CMD_STOP || cmd == V4L2_ENC_CMD_STOP) {
if (vb2_is_streaming(src_q))
- if (inst->sub_state != IRIS_INST_SUB_DRAIN)
+ if (!(inst->sub_state & IRIS_INST_SUB_DRAIN))
return true;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0638/1518] media: qcom: iris: handle runtime PM resume failure in core deinit
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (636 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0637/1518] media: qcom: iris: Fix bitmask test in iris_allow_cmd() Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0639/1518] s390/ptrace: Rename psw_t32 to psw32_t Greg Kroah-Hartman
` (360 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hungyu Lin, Bryan ODonoghue,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hungyu Lin <dennylin0707@gmail.com>
[ Upstream commit 75d79879ec3cbfd288144b0ae4c3e3fa7700c5fc ]
Check the return value of pm_runtime_resume_and_get() in
iris_core_deinit().
If runtime PM resume fails, skip hardware power-off operations but
still perform software teardown and state transition. Also skip the
corresponding pm_runtime_put_sync() call to avoid unbalanced runtime
PM references.
Fixes: bb8a95aa038e ("media: iris: implement power management")
Signed-off-by: Hungyu Lin <dennylin0707@gmail.com>
Signed-off-by: Bryan O'Donoghue <bod@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/media/platform/qcom/iris/iris_core.c | 12 +++++++++---
1 file changed, 9 insertions(+), 3 deletions(-)
diff --git a/drivers/media/platform/qcom/iris/iris_core.c b/drivers/media/platform/qcom/iris/iris_core.c
index 8406c48d635b6..e337f8b7e6f07 100644
--- a/drivers/media/platform/qcom/iris/iris_core.c
+++ b/drivers/media/platform/qcom/iris/iris_core.c
@@ -12,18 +12,24 @@
void iris_core_deinit(struct iris_core *core)
{
- pm_runtime_resume_and_get(core->dev);
+ int ret;
+
+ ret = pm_runtime_resume_and_get(core->dev);
mutex_lock(&core->lock);
if (core->state != IRIS_CORE_DEINIT) {
iris_fw_unload(core);
- iris_vpu_power_off(core);
+
+ if (!ret)
+ iris_vpu_power_off(core);
+
iris_hfi_queues_deinit(core);
core->state = IRIS_CORE_DEINIT;
}
mutex_unlock(&core->lock);
- pm_runtime_put_sync(core->dev);
+ if (!ret)
+ pm_runtime_put_sync(core->dev);
}
static int iris_wait_for_system_response(struct iris_core *core)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0639/1518] s390/ptrace: Rename psw_t32 to psw32_t
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (637 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0638/1518] media: qcom: iris: handle runtime PM resume failure in core deinit Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0640/1518] s390/syscalls: Add pt_regs parameter to SYSCALL_DEFINE0() syscall wrapper Greg Kroah-Hartman
` (359 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Arnd Bergmann, Heiko Carstens,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Heiko Carstens <hca@linux.ibm.com>
[ Upstream commit 8c633c78c23a85a9efbabbe47d815ebdd7739905 ]
Use a standard "_t" suffix for psw_t32 and rename it to psw32_t.
Reviewed-by: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Stable-dep-of: dc161efb6df8 ("s390/vdso: Pass --eh-frame-hdr to the linker")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/s390/boot/ipl_data.c | 2 +-
arch/s390/include/asm/ptrace.h | 2 +-
arch/s390/kernel/compat_linux.h | 2 +-
3 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/arch/s390/boot/ipl_data.c b/arch/s390/boot/ipl_data.c
index c4130a80b058e..7957cc6554e77 100644
--- a/arch/s390/boot/ipl_data.c
+++ b/arch/s390/boot/ipl_data.c
@@ -12,7 +12,7 @@
#define PSW_MASK_DISABLED (PSW_MASK_WAIT | PSW_MASK_EA | PSW_MASK_BA)
struct ipl_lowcore {
- psw_t32 ipl_psw; /* 0x0000 */
+ psw32_t ipl_psw; /* 0x0000 */
struct ccw0 ccwpgm[2]; /* 0x0008 */
u8 fill[56]; /* 0x0018 */
struct ccw0 ccwpgmcc[20]; /* 0x0050 */
diff --git a/arch/s390/include/asm/ptrace.h b/arch/s390/include/asm/ptrace.h
index dfa770b15fadb..f2ecc013a48a5 100644
--- a/arch/s390/include/asm/ptrace.h
+++ b/arch/s390/include/asm/ptrace.h
@@ -99,7 +99,7 @@ enum {
typedef struct {
unsigned int mask;
unsigned int addr;
-} psw_t32 __aligned(8);
+} psw32_t __aligned(8);
#define PGM_INT_CODE_MASK 0x7f
#define PGM_INT_CODE_PER 0x80
diff --git a/arch/s390/kernel/compat_linux.h b/arch/s390/kernel/compat_linux.h
index ef23739b277c7..133f22b5deebc 100644
--- a/arch/s390/kernel/compat_linux.h
+++ b/arch/s390/kernel/compat_linux.h
@@ -33,7 +33,7 @@ typedef struct {
} _s390_fp_regs32;
typedef struct {
- psw_t32 psw;
+ psw32_t psw;
__u32 gprs[__NUM_GPRS];
__u32 acrs[__NUM_ACRS];
} _s390_regs_common32;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0640/1518] s390/syscalls: Add pt_regs parameter to SYSCALL_DEFINE0() syscall wrapper
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (638 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0639/1518] s390/ptrace: Rename psw_t32 to psw32_t Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0641/1518] s390: Remove compat support Greg Kroah-Hartman
` (358 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Arnd Bergmann, Heiko Carstens,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Heiko Carstens <hca@linux.ibm.com>
[ Upstream commit 7afb095df3e3c2f0d2f27d2d27bbe574ca9479f0 ]
All system call wrappers should match the sys_call_ptr_t type. This is not
the case for system calls without parameters. Add the missing pt_regs
parameter there too.
Note: this is currently not a problem, since the parameter is unused.
However it prevents to create a correctly typed system call table in
C. With the current assembler implementation this works because of
missing type checking.
Reviewed-by: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Stable-dep-of: dc161efb6df8 ("s390/vdso: Pass --eh-frame-hdr to the linker")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/s390/include/asm/syscall_wrapper.h | 16 ++++++++--------
1 file changed, 8 insertions(+), 8 deletions(-)
diff --git a/arch/s390/include/asm/syscall_wrapper.h b/arch/s390/include/asm/syscall_wrapper.h
index 35c1d1b860d88..bf1ff5e9242d4 100644
--- a/arch/s390/include/asm/syscall_wrapper.h
+++ b/arch/s390/include/asm/syscall_wrapper.h
@@ -38,22 +38,22 @@
* named __s390x_sys_*()
*/
#define COMPAT_SYSCALL_DEFINE0(sname) \
- long __s390_compat_sys_##sname(void); \
+ long __s390_compat_sys_##sname(struct pt_regs *__unused); \
ALLOW_ERROR_INJECTION(__s390_compat_sys_##sname, ERRNO); \
- long __s390_compat_sys_##sname(void)
+ long __s390_compat_sys_##sname(struct pt_regs *__unused)
#define SYSCALL_DEFINE0(sname) \
SYSCALL_METADATA(_##sname, 0); \
- long __s390_sys_##sname(void); \
+ long __s390_sys_##sname(struct pt_regs *__unused); \
ALLOW_ERROR_INJECTION(__s390_sys_##sname, ERRNO); \
- long __s390x_sys_##sname(void); \
+ long __s390x_sys_##sname(struct pt_regs *__unused); \
ALLOW_ERROR_INJECTION(__s390x_sys_##sname, ERRNO); \
static inline long __do_sys_##sname(void); \
- long __s390_sys_##sname(void) \
+ long __s390_sys_##sname(struct pt_regs *__unused) \
{ \
return __do_sys_##sname(); \
} \
- long __s390x_sys_##sname(void) \
+ long __s390x_sys_##sname(struct pt_regs *__unused) \
{ \
return __do_sys_##sname(); \
} \
@@ -104,10 +104,10 @@
#define SYSCALL_DEFINE0(sname) \
SYSCALL_METADATA(_##sname, 0); \
- long __s390x_sys_##sname(void); \
+ long __s390x_sys_##sname(struct pt_regs *__unused); \
ALLOW_ERROR_INJECTION(__s390x_sys_##sname, ERRNO); \
static inline long __do_sys_##sname(void); \
- long __s390x_sys_##sname(void) \
+ long __s390x_sys_##sname(struct pt_regs *__unused) \
{ \
return __do_sys_##sname(); \
} \
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0641/1518] s390: Remove compat support
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (639 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0640/1518] s390/syscalls: Add pt_regs parameter to SYSCALL_DEFINE0() syscall wrapper Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0642/1518] s390: Add stackprotector support Greg Kroah-Hartman
` (357 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Arnd Bergmann, Heiko Carstens,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Heiko Carstens <hca@linux.ibm.com>
[ Upstream commit 8e0b986c59c67e08ada646249f834655a9e6da16 ]
There shouldn't be any 31 bit code around anymore that matters.
Remove the compat layer support required to run 31 bit code.
Reason for removal is code simplification and reduced test effort.
Note that this comes without any deprecation warnings added to config
options, or kernel messages, since most likely those would be ignored
anyway.
If it turns out there is still a reason to keep the compat layer this
can be reverted at any time in the future.
Reviewed-by: Arnd Bergmann <arnd@arndb.de>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Stable-dep-of: dc161efb6df8 ("s390/vdso: Pass --eh-frame-hdr to the linker")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/s390/Kconfig | 16 -
arch/s390/Makefile | 3 -
arch/s390/boot/ipl_data.c | 1 -
arch/s390/configs/compat.config | 3 -
arch/s390/hypfs/hypfs_sprp.c | 6 +-
arch/s390/include/asm/compat.h | 140 ------
arch/s390/include/asm/elf.h | 46 +-
arch/s390/include/asm/ftrace.h | 19 +-
arch/s390/include/asm/processor.h | 12 +-
arch/s390/include/asm/seccomp.h | 5 -
arch/s390/include/asm/syscall.h | 19 +-
arch/s390/include/asm/syscall_wrapper.h | 91 ----
arch/s390/include/asm/thread_info.h | 2 -
arch/s390/include/asm/unistd.h | 5 -
arch/s390/include/asm/vdso-symbols.h | 8 -
arch/s390/kernel/Makefile | 4 -
arch/s390/kernel/audit.c | 16 -
arch/s390/kernel/audit.h | 16 -
arch/s390/kernel/compat_audit.c | 48 --
arch/s390/kernel/compat_linux.c | 289 -----------
arch/s390/kernel/compat_linux.h | 101 ----
arch/s390/kernel/compat_ptrace.h | 64 ---
arch/s390/kernel/compat_signal.c | 420 ----------------
arch/s390/kernel/entry.S | 9 -
arch/s390/kernel/perf_cpum_cf.c | 1 -
arch/s390/kernel/perf_event.c | 1 -
arch/s390/kernel/perf_regs.c | 3 -
arch/s390/kernel/process.c | 9 +-
arch/s390/kernel/ptrace.c | 524 --------------------
arch/s390/kernel/setup.c | 1 -
arch/s390/kernel/signal.c | 23 +-
arch/s390/kernel/stacktrace.c | 3 -
arch/s390/kernel/uprobes.c | 6 +-
arch/s390/kernel/vdso.c | 26 +-
arch/s390/kernel/vdso32/.gitignore | 2 -
arch/s390/kernel/vdso32/Makefile | 64 ---
arch/s390/kernel/vdso32/gen_vdso_offsets.sh | 15 -
arch/s390/kernel/vdso32/note.S | 13 -
arch/s390/kernel/vdso32/vdso32.lds.S | 140 ------
arch/s390/kernel/vdso32/vdso32_wrapper.S | 15 -
arch/s390/kernel/vdso32/vdso_user_wrapper.S | 22 -
arch/s390/mm/fault.c | 1 -
arch/s390/mm/mmap.c | 1 -
arch/s390/pci/pci_clp.c | 4 +-
drivers/s390/block/dasd.c | 1 -
drivers/s390/block/dasd_eckd.c | 11 -
drivers/s390/block/dasd_ioctl.c | 6 +-
drivers/s390/char/con3270.c | 19 -
drivers/s390/char/fs3270.c | 7 +-
drivers/s390/char/sclp_ctl.c | 12 +-
drivers/s390/char/tape_char.c | 26 -
drivers/s390/char/vmcp.c | 7 +-
drivers/s390/cio/chsc_sch.c | 7 +-
drivers/s390/crypto/zcrypt_api.c | 195 --------
drivers/s390/crypto/zcrypt_card.c | 1 -
drivers/s390/crypto/zcrypt_queue.c | 1 -
drivers/s390/net/qeth_core_main.c | 4 +-
57 files changed, 30 insertions(+), 2484 deletions(-)
delete mode 100644 arch/s390/configs/compat.config
delete mode 100644 arch/s390/include/asm/compat.h
delete mode 100644 arch/s390/kernel/audit.h
delete mode 100644 arch/s390/kernel/compat_audit.c
delete mode 100644 arch/s390/kernel/compat_linux.c
delete mode 100644 arch/s390/kernel/compat_linux.h
delete mode 100644 arch/s390/kernel/compat_ptrace.h
delete mode 100644 arch/s390/kernel/compat_signal.c
delete mode 100644 arch/s390/kernel/vdso32/.gitignore
delete mode 100644 arch/s390/kernel/vdso32/Makefile
delete mode 100755 arch/s390/kernel/vdso32/gen_vdso_offsets.sh
delete mode 100644 arch/s390/kernel/vdso32/note.S
delete mode 100644 arch/s390/kernel/vdso32/vdso32.lds.S
delete mode 100644 arch/s390/kernel/vdso32/vdso32_wrapper.S
delete mode 100644 arch/s390/kernel/vdso32/vdso_user_wrapper.S
diff --git a/arch/s390/Kconfig b/arch/s390/Kconfig
index f43a6570fd6f7..8a42762cc2b1b 100644
--- a/arch/s390/Kconfig
+++ b/arch/s390/Kconfig
@@ -504,22 +504,6 @@ config COMMAND_LINE_SIZE
This allows you to specify the maximum length of the kernel command
line.
-config COMPAT
- def_bool n
- prompt "Kernel support for 31 bit emulation"
- select ARCH_WANT_OLD_COMPAT_IPC
- select COMPAT_OLD_SIGACTION
- select HAVE_UID16
- depends on MULTIUSER
- depends on !CC_IS_CLANG && !LD_IS_LLD
- help
- Select this option if you want to enable your system kernel to
- handle system-calls from ELF binaries for 31 bit ESA. This option
- (and some other stuff like libraries and such) is needed for
- executing 31 bit applications.
-
- If unsure say N.
-
config SMP
def_bool y
diff --git a/arch/s390/Makefile b/arch/s390/Makefile
index b4769241332bb..f41b8c5c4e560 100644
--- a/arch/s390/Makefile
+++ b/arch/s390/Makefile
@@ -149,11 +149,8 @@ ifeq ($(KBUILD_EXTMOD),)
prepare: vdso_prepare
vdso_prepare: prepare0
$(Q)$(MAKE) $(build)=arch/s390/kernel/vdso64 include/generated/vdso64-offsets.h
- $(if $(CONFIG_COMPAT),$(Q)$(MAKE) \
- $(build)=arch/s390/kernel/vdso32 include/generated/vdso32-offsets.h)
vdso-install-y += arch/s390/kernel/vdso64/vdso64.so.dbg
-vdso-install-$(CONFIG_COMPAT) += arch/s390/kernel/vdso32/vdso32.so.dbg
endif
diff --git a/arch/s390/boot/ipl_data.c b/arch/s390/boot/ipl_data.c
index 7957cc6554e77..b0fd8a526b42b 100644
--- a/arch/s390/boot/ipl_data.c
+++ b/arch/s390/boot/ipl_data.c
@@ -1,6 +1,5 @@
// SPDX-License-Identifier: GPL-2.0
-#include <linux/compat.h>
#include <linux/ptrace.h>
#include <asm/cio.h>
#include <asm/asm-offsets.h>
diff --git a/arch/s390/configs/compat.config b/arch/s390/configs/compat.config
deleted file mode 100644
index 6fd051453ae82..0000000000000
--- a/arch/s390/configs/compat.config
+++ /dev/null
@@ -1,3 +0,0 @@
-# Help: Enable compat support
-CONFIG_COMPAT=y
-CONFIG_COMPAT_32BIT_TIME=y
diff --git a/arch/s390/hypfs/hypfs_sprp.c b/arch/s390/hypfs/hypfs_sprp.c
index a2952ed5518ba..a72576221cab9 100644
--- a/arch/s390/hypfs/hypfs_sprp.c
+++ b/arch/s390/hypfs/hypfs_sprp.c
@@ -7,7 +7,6 @@
* Author(s): Martin Schwidefsky <schwidefsky@de.ibm.com>
*/
-#include <linux/compat.h>
#include <linux/errno.h>
#include <linux/gfp.h>
#include <linux/string.h>
@@ -116,10 +115,7 @@ static long hypfs_sprp_ioctl(struct file *file, unsigned int cmd,
if (!capable(CAP_SYS_ADMIN))
return -EACCES;
- if (is_compat_task())
- argp = compat_ptr(arg);
- else
- argp = (void __user *) arg;
+ argp = (void __user *)arg;
switch (cmd) {
case HYPFS_DIAG304:
return __hypfs_sprp_ioctl(argp);
diff --git a/arch/s390/include/asm/compat.h b/arch/s390/include/asm/compat.h
deleted file mode 100644
index 3cb9d813f022b..0000000000000
--- a/arch/s390/include/asm/compat.h
+++ /dev/null
@@ -1,140 +0,0 @@
-/* SPDX-License-Identifier: GPL-2.0 */
-#ifndef _ASM_S390X_COMPAT_H
-#define _ASM_S390X_COMPAT_H
-/*
- * Architecture specific compatibility types
- */
-#include <linux/types.h>
-#include <linux/sched.h>
-#include <linux/sched/task_stack.h>
-#include <linux/thread_info.h>
-#include <asm/ptrace.h>
-
-#define compat_mode_t compat_mode_t
-typedef u16 compat_mode_t;
-
-#define __compat_uid_t __compat_uid_t
-typedef u16 __compat_uid_t;
-typedef u16 __compat_gid_t;
-
-#define compat_dev_t compat_dev_t
-typedef u16 compat_dev_t;
-
-#define compat_ipc_pid_t compat_ipc_pid_t
-typedef u16 compat_ipc_pid_t;
-
-#define compat_statfs compat_statfs
-
-#include <asm-generic/compat.h>
-
-#define __TYPE_IS_PTR(t) (!__builtin_types_compatible_p( \
- typeof(0?(__force t)0:0ULL), u64))
-
-#define __SC_DELOUSE(t,v) ({ \
- BUILD_BUG_ON(sizeof(t) > 4 && !__TYPE_IS_PTR(t)); \
- (__force t)(__TYPE_IS_PTR(t) ? ((v) & 0x7fffffff) : (v)); \
-})
-
-#define PSW32_MASK_USER 0x0000FF00UL
-
-#define PSW32_USER_BITS (PSW32_MASK_DAT | PSW32_MASK_IO | PSW32_MASK_EXT | \
- PSW32_DEFAULT_KEY | PSW32_MASK_BASE | \
- PSW32_MASK_MCHECK | PSW32_MASK_PSTATE | \
- PSW32_ASC_PRIMARY)
-
-#define COMPAT_UTS_MACHINE "s390\0\0\0\0"
-
-typedef u16 compat_nlink_t;
-
-typedef struct {
- u32 mask;
- u32 addr;
-} __aligned(8) psw_compat_t;
-
-typedef struct {
- psw_compat_t psw;
- u32 gprs[NUM_GPRS];
- u32 acrs[NUM_ACRS];
- u32 orig_gpr2;
-} s390_compat_regs;
-
-typedef struct {
- u32 gprs_high[NUM_GPRS];
-} s390_compat_regs_high;
-
-struct compat_stat {
- compat_dev_t st_dev;
- u16 __pad1;
- compat_ino_t st_ino;
- compat_mode_t st_mode;
- compat_nlink_t st_nlink;
- __compat_uid_t st_uid;
- __compat_gid_t st_gid;
- compat_dev_t st_rdev;
- u16 __pad2;
- u32 st_size;
- u32 st_blksize;
- u32 st_blocks;
- u32 st_atime;
- u32 st_atime_nsec;
- u32 st_mtime;
- u32 st_mtime_nsec;
- u32 st_ctime;
- u32 st_ctime_nsec;
- u32 __unused4;
- u32 __unused5;
-};
-
-struct compat_statfs {
- u32 f_type;
- u32 f_bsize;
- u32 f_blocks;
- u32 f_bfree;
- u32 f_bavail;
- u32 f_files;
- u32 f_ffree;
- compat_fsid_t f_fsid;
- u32 f_namelen;
- u32 f_frsize;
- u32 f_flags;
- u32 f_spare[4];
-};
-
-struct compat_statfs64 {
- u32 f_type;
- u32 f_bsize;
- u64 f_blocks;
- u64 f_bfree;
- u64 f_bavail;
- u64 f_files;
- u64 f_ffree;
- compat_fsid_t f_fsid;
- u32 f_namelen;
- u32 f_frsize;
- u32 f_flags;
- u32 f_spare[5];
-};
-
-/*
- * A pointer passed in from user mode. This should not
- * be used for syscall parameters, just declare them
- * as pointers because the syscall entry code will have
- * appropriately converted them already.
- */
-
-static inline void __user *compat_ptr(compat_uptr_t uptr)
-{
- return (void __user *)(unsigned long)(uptr & 0x7fffffffUL);
-}
-#define compat_ptr(uptr) compat_ptr(uptr)
-
-#ifdef CONFIG_COMPAT
-
-static inline int is_compat_task(void)
-{
- return test_thread_flag(TIF_31BIT);
-}
-
-#endif
-
-#endif /* _ASM_S390X_COMPAT_H */
diff --git a/arch/s390/include/asm/elf.h b/arch/s390/include/asm/elf.h
index a03df312081ef..2b6ab483b1cab 100644
--- a/arch/s390/include/asm/elf.h
+++ b/arch/s390/include/asm/elf.h
@@ -162,8 +162,6 @@ enum {
* ELF register definitions..
*/
-#include <linux/compat.h>
-
#include <asm/ptrace.h>
#include <asm/syscall.h>
#include <asm/user.h>
@@ -171,9 +169,6 @@ enum {
typedef s390_fp_regs elf_fpregset_t;
typedef s390_regs elf_gregset_t;
-typedef s390_fp_regs compat_elf_fpregset_t;
-typedef s390_compat_regs compat_elf_gregset_t;
-
#include <linux/sched/mm.h> /* for task_struct */
#include <asm/mmu_context.h>
@@ -183,10 +178,6 @@ typedef s390_compat_regs compat_elf_gregset_t;
#define elf_check_arch(x) \
(((x)->e_machine == EM_S390 || (x)->e_machine == EM_S390_OLD) \
&& (x)->e_ident[EI_CLASS] == ELF_CLASS)
-#define compat_elf_check_arch(x) \
- (((x)->e_machine == EM_S390 || (x)->e_machine == EM_S390_OLD) \
- && (x)->e_ident[EI_CLASS] == ELF_CLASS)
-#define compat_start_thread start_thread31
/* For SVR4/S390 the function pointer to be registered with `atexit` is
passed in R14. */
@@ -203,9 +194,7 @@ typedef s390_compat_regs compat_elf_gregset_t;
the loader. We need to make sure that it is out of the way of the program
that it will "exec", and that there is sufficient room for the brk. 64-bit
tasks are aligned to 4GB. */
-#define ELF_ET_DYN_BASE (is_compat_task() ? \
- (STACK_TOP / 3 * 2) : \
- (STACK_TOP / 3 * 2) & ~((1UL << 32) - 1))
+#define ELF_ET_DYN_BASE ((STACK_TOP / 3 * 2) & ~((1UL << 32) - 1))
/* This yields a mask that user programs can use to figure out what
instruction set this CPU supports. */
@@ -224,43 +213,22 @@ extern unsigned long elf_hwcap;
extern char elf_platform[];
#define ELF_PLATFORM (elf_platform)
-#ifndef CONFIG_COMPAT
#define SET_PERSONALITY(ex) \
do { \
set_personality(PER_LINUX | \
(current->personality & (~PER_MASK))); \
current->thread.sys_call_table = sys_call_table; \
} while (0)
-#else /* CONFIG_COMPAT */
-#define SET_PERSONALITY(ex) \
-do { \
- if (personality(current->personality) != PER_LINUX32) \
- set_personality(PER_LINUX | \
- (current->personality & ~PER_MASK)); \
- if ((ex).e_ident[EI_CLASS] == ELFCLASS32) { \
- set_thread_flag(TIF_31BIT); \
- current->thread.sys_call_table = \
- sys_call_table_emu; \
- } else { \
- clear_thread_flag(TIF_31BIT); \
- current->thread.sys_call_table = \
- sys_call_table; \
- } \
-} while (0)
-#endif /* CONFIG_COMPAT */
/*
* Cache aliasing on the latest machines calls for a mapping granularity
- * of 512KB for the anonymous mapping base. For 64-bit processes use a
- * 512KB alignment and a randomization of up to 1GB. For 31-bit processes
- * the virtual address space is limited, use no alignment and limit the
- * randomization to 8MB.
- * For the additional randomization of the program break use 32MB for
- * 64-bit and 8MB for 31-bit.
+ * of 512KB for the anonymous mapping base. Use a 512KB alignment and a
+ * randomization of up to 1GB.
+ * For the additional randomization of the program break use 32MB.
*/
-#define BRK_RND_MASK (is_compat_task() ? 0x7ffUL : 0x1fffUL)
-#define MMAP_RND_MASK (is_compat_task() ? 0x7ffUL : 0x3ff80UL)
-#define MMAP_ALIGN_MASK (is_compat_task() ? 0 : 0x7fUL)
+#define BRK_RND_MASK (0x1fffUL)
+#define MMAP_RND_MASK (0x3ff80UL)
+#define MMAP_ALIGN_MASK (0x7fUL)
#define STACK_RND_MASK MMAP_RND_MASK
/* update AT_VECTOR_SIZE_ARCH if the number of NEW_AUX_ENT entries changes */
diff --git a/arch/s390/include/asm/ftrace.h b/arch/s390/include/asm/ftrace.h
index bee2d16c29517..692c484ec1630 100644
--- a/arch/s390/include/asm/ftrace.h
+++ b/arch/s390/include/asm/ftrace.h
@@ -105,28 +105,11 @@ static inline void arch_ftrace_set_direct_caller(struct ftrace_regs *fregs, unsi
}
#endif /* CONFIG_DYNAMIC_FTRACE_WITH_DIRECT_CALLS */
-/*
- * Even though the system call numbers are identical for s390/s390x a
- * different system call table is used for compat tasks. This may lead
- * to e.g. incorrect or missing trace event sysfs files.
- * Therefore simply do not trace compat system calls at all.
- * See kernel/trace/trace_syscalls.c.
- */
-#define ARCH_TRACE_IGNORE_COMPAT_SYSCALLS
-static inline bool arch_trace_is_compat_syscall(struct pt_regs *regs)
-{
- return is_compat_task();
-}
-
#define ARCH_HAS_SYSCALL_MATCH_SYM_NAME
static inline bool arch_syscall_match_sym_name(const char *sym,
const char *name)
{
- /*
- * Skip __s390_ and __s390x_ prefix - due to compat wrappers
- * and aliasing some symbols of 64 bit system call functions
- * may get the __s390_ prefix instead of the __s390x_ prefix.
- */
+ /* Skip the __s390x_ prefix. */
return !strcmp(sym + 7, name) || !strcmp(sym + 8, name);
}
diff --git a/arch/s390/include/asm/processor.h b/arch/s390/include/asm/processor.h
index 70010bba27e79..89b2ca57da13f 100644
--- a/arch/s390/include/asm/processor.h
+++ b/arch/s390/include/asm/processor.h
@@ -119,18 +119,12 @@ extern void execve_tail(void);
unsigned long vdso_text_size(void);
unsigned long vdso_size(void);
-/*
- * User space process size: 2GB for 31 bit, 4TB or 8PT for 64 bit.
- */
-
-#define TASK_SIZE (test_thread_flag(TIF_31BIT) ? \
- _REGION3_SIZE : TASK_SIZE_MAX)
-#define TASK_UNMAPPED_BASE (test_thread_flag(TIF_31BIT) ? \
- (_REGION3_SIZE >> 1) : (_REGION2_SIZE >> 1))
+#define TASK_SIZE (TASK_SIZE_MAX)
+#define TASK_UNMAPPED_BASE (_REGION2_SIZE >> 1)
#define TASK_SIZE_MAX (-PAGE_SIZE)
#define VDSO_BASE (STACK_TOP + PAGE_SIZE)
-#define VDSO_LIMIT (test_thread_flag(TIF_31BIT) ? _REGION3_SIZE : _REGION2_SIZE)
+#define VDSO_LIMIT (_REGION2_SIZE)
#define STACK_TOP (VDSO_LIMIT - vdso_size() - PAGE_SIZE)
#define STACK_TOP_MAX (_REGION2_SIZE - vdso_size() - PAGE_SIZE)
diff --git a/arch/s390/include/asm/seccomp.h b/arch/s390/include/asm/seccomp.h
index 71d46f0ba97b5..f904b674fee07 100644
--- a/arch/s390/include/asm/seccomp.h
+++ b/arch/s390/include/asm/seccomp.h
@@ -19,10 +19,5 @@
#define SECCOMP_ARCH_NATIVE AUDIT_ARCH_S390X
#define SECCOMP_ARCH_NATIVE_NR NR_syscalls
#define SECCOMP_ARCH_NATIVE_NAME "s390x"
-#ifdef CONFIG_COMPAT
-# define SECCOMP_ARCH_COMPAT AUDIT_ARCH_S390
-# define SECCOMP_ARCH_COMPAT_NR NR_syscalls
-# define SECCOMP_ARCH_COMPAT_NAME "s390"
-#endif
#endif /* _ASM_S390_SECCOMP_H */
diff --git a/arch/s390/include/asm/syscall.h b/arch/s390/include/asm/syscall.h
index 10ce5c4ccbd6d..4271e4169f45b 100644
--- a/arch/s390/include/asm/syscall.h
+++ b/arch/s390/include/asm/syscall.h
@@ -15,7 +15,6 @@
#include <asm/ptrace.h>
extern const sys_call_ptr_t sys_call_table[];
-extern const sys_call_ptr_t sys_call_table_emu[];
static inline long syscall_get_nr(struct task_struct *task,
struct pt_regs *regs)
@@ -46,15 +45,7 @@ static inline long syscall_get_error(struct task_struct *task,
struct pt_regs *regs)
{
unsigned long error = regs->gprs[2];
-#ifdef CONFIG_COMPAT
- if (test_tsk_thread_flag(task, TIF_31BIT)) {
- /*
- * Sign-extend the value so (int)-EFOO becomes (long)-EFOO
- * and will match correctly in comparisons.
- */
- error = (long)(int)error;
- }
-#endif
+
return IS_ERR_VALUE(error) ? error : 0;
}
@@ -78,10 +69,6 @@ static inline void syscall_get_arguments(struct task_struct *task,
{
unsigned long mask = -1UL;
-#ifdef CONFIG_COMPAT
- if (test_tsk_thread_flag(task, TIF_31BIT))
- mask = 0xffffffff;
-#endif
for (int i = 1; i < 6; i++)
args[i] = regs->gprs[2 + i] & mask;
@@ -99,10 +86,6 @@ static inline void syscall_set_arguments(struct task_struct *task,
static inline int syscall_get_arch(struct task_struct *task)
{
-#ifdef CONFIG_COMPAT
- if (test_tsk_thread_flag(task, TIF_31BIT))
- return AUDIT_ARCH_S390;
-#endif
return AUDIT_ARCH_S390X;
}
diff --git a/arch/s390/include/asm/syscall_wrapper.h b/arch/s390/include/asm/syscall_wrapper.h
index bf1ff5e9242d4..9eb58d5348d85 100644
--- a/arch/s390/include/asm/syscall_wrapper.h
+++ b/arch/s390/include/asm/syscall_wrapper.h
@@ -13,95 +13,6 @@
,, regs->orig_gpr2,, regs->gprs[3],, regs->gprs[4] \
,, regs->gprs[5],, regs->gprs[6],, regs->gprs[7])
-#ifdef CONFIG_COMPAT
-
-#define __SC_COMPAT_CAST(t, a) \
-({ \
- long __ReS = a; \
- \
- BUILD_BUG_ON((sizeof(t) > 4) && !__TYPE_IS_L(t) && \
- !__TYPE_IS_UL(t) && !__TYPE_IS_PTR(t) && \
- !__TYPE_IS_LL(t)); \
- if (__TYPE_IS_L(t)) \
- __ReS = (s32)a; \
- if (__TYPE_IS_UL(t)) \
- __ReS = (u32)a; \
- if (__TYPE_IS_PTR(t)) \
- __ReS = a & 0x7fffffff; \
- if (__TYPE_IS_LL(t)) \
- return -ENOSYS; \
- (t)__ReS; \
-})
-
-/*
- * To keep the naming coherent, re-define SYSCALL_DEFINE0 to create an alias
- * named __s390x_sys_*()
- */
-#define COMPAT_SYSCALL_DEFINE0(sname) \
- long __s390_compat_sys_##sname(struct pt_regs *__unused); \
- ALLOW_ERROR_INJECTION(__s390_compat_sys_##sname, ERRNO); \
- long __s390_compat_sys_##sname(struct pt_regs *__unused)
-
-#define SYSCALL_DEFINE0(sname) \
- SYSCALL_METADATA(_##sname, 0); \
- long __s390_sys_##sname(struct pt_regs *__unused); \
- ALLOW_ERROR_INJECTION(__s390_sys_##sname, ERRNO); \
- long __s390x_sys_##sname(struct pt_regs *__unused); \
- ALLOW_ERROR_INJECTION(__s390x_sys_##sname, ERRNO); \
- static inline long __do_sys_##sname(void); \
- long __s390_sys_##sname(struct pt_regs *__unused) \
- { \
- return __do_sys_##sname(); \
- } \
- long __s390x_sys_##sname(struct pt_regs *__unused) \
- { \
- return __do_sys_##sname(); \
- } \
- static inline long __do_sys_##sname(void)
-
-#define COND_SYSCALL(name) \
- cond_syscall(__s390x_sys_##name); \
- cond_syscall(__s390_sys_##name)
-
-#define COMPAT_SYSCALL_DEFINEx(x, name, ...) \
- long __s390_compat_sys##name(struct pt_regs *regs); \
- ALLOW_ERROR_INJECTION(__s390_compat_sys##name, ERRNO); \
- static inline long __se_compat_sys##name(__MAP(x, __SC_LONG, __VA_ARGS__)); \
- static inline long __do_compat_sys##name(__MAP(x, __SC_DECL, __VA_ARGS__)); \
- long __s390_compat_sys##name(struct pt_regs *regs) \
- { \
- return __se_compat_sys##name(SC_S390_REGS_TO_ARGS(x, __VA_ARGS__)); \
- } \
- static inline long __se_compat_sys##name(__MAP(x, __SC_LONG, __VA_ARGS__)) \
- { \
- __MAP(x, __SC_TEST, __VA_ARGS__); \
- return __do_compat_sys##name(__MAP(x, __SC_DELOUSE, __VA_ARGS__)); \
- } \
- static inline long __do_compat_sys##name(__MAP(x, __SC_DECL, __VA_ARGS__))
-
-/*
- * As some compat syscalls may not be implemented, we need to expand
- * COND_SYSCALL_COMPAT in kernel/sys_ni.c to cover this case as well.
- */
-#define COND_SYSCALL_COMPAT(name) \
- cond_syscall(__s390_compat_sys_##name)
-
-#define __S390_SYS_STUBx(x, name, ...) \
- long __s390_sys##name(struct pt_regs *regs); \
- ALLOW_ERROR_INJECTION(__s390_sys##name, ERRNO); \
- static inline long ___se_sys##name(__MAP(x, __SC_LONG, __VA_ARGS__)); \
- long __s390_sys##name(struct pt_regs *regs) \
- { \
- return ___se_sys##name(SC_S390_REGS_TO_ARGS(x, __VA_ARGS__)); \
- } \
- static inline long ___se_sys##name(__MAP(x, __SC_LONG, __VA_ARGS__)) \
- { \
- __MAP(x, __SC_TEST, __VA_ARGS__); \
- return __do_sys##name(__MAP(x, __SC_COMPAT_CAST, __VA_ARGS__)); \
- }
-
-#else /* CONFIG_COMPAT */
-
#define SYSCALL_DEFINE0(sname) \
SYSCALL_METADATA(_##sname, 0); \
long __s390x_sys_##sname(struct pt_regs *__unused); \
@@ -118,8 +29,6 @@
#define __S390_SYS_STUBx(x, fullname, name, ...)
-#endif /* CONFIG_COMPAT */
-
#define __SYSCALL_DEFINEx(x, name, ...) \
long __s390x_sys##name(struct pt_regs *regs); \
ALLOW_ERROR_INJECTION(__s390x_sys##name, ERRNO); \
diff --git a/arch/s390/include/asm/thread_info.h b/arch/s390/include/asm/thread_info.h
index 7878e9bfbf072..6a548a8194006 100644
--- a/arch/s390/include/asm/thread_info.h
+++ b/arch/s390/include/asm/thread_info.h
@@ -69,7 +69,6 @@ void arch_setup_new_exec(void);
#define TIF_GUARDED_STORAGE 17 /* load guarded storage control block */
#define TIF_ISOLATE_BP_GUEST 18 /* Run KVM guests with isolated BP */
#define TIF_PER_TRAP 19 /* Need to handle PER trap on exit to usermode */
-#define TIF_31BIT 20 /* 32bit process */
#define TIF_SINGLE_STEP 21 /* This task is single stepped */
#define TIF_BLOCK_STEP 22 /* This task is block stepped */
#define TIF_UPROBE_SINGLESTEP 23 /* This task is uprobe single stepped */
@@ -78,7 +77,6 @@ void arch_setup_new_exec(void);
#define _TIF_GUARDED_STORAGE BIT(TIF_GUARDED_STORAGE)
#define _TIF_ISOLATE_BP_GUEST BIT(TIF_ISOLATE_BP_GUEST)
#define _TIF_PER_TRAP BIT(TIF_PER_TRAP)
-#define _TIF_31BIT BIT(TIF_31BIT)
#define _TIF_SINGLE_STEP BIT(TIF_SINGLE_STEP)
#define _TIF_BLOCK_STEP BIT(TIF_BLOCK_STEP)
#define _TIF_UPROBE_SINGLESTEP BIT(TIF_UPROBE_SINGLESTEP)
diff --git a/arch/s390/include/asm/unistd.h b/arch/s390/include/asm/unistd.h
index 70fc671397dad..252d7ac7a6b2a 100644
--- a/arch/s390/include/asm/unistd.h
+++ b/arch/s390/include/asm/unistd.h
@@ -27,11 +27,6 @@
#define __ARCH_WANT_SYS_OLDUMOUNT
#define __ARCH_WANT_SYS_SIGPENDING
#define __ARCH_WANT_SYS_SIGPROCMASK
-# ifdef CONFIG_COMPAT
-# define __ARCH_WANT_COMPAT_STAT
-# define __ARCH_WANT_SYS_TIME32
-# define __ARCH_WANT_SYS_UTIME32
-# endif
#define __ARCH_WANT_SYS_FORK
#define __ARCH_WANT_SYS_VFORK
#define __ARCH_WANT_SYS_CLONE
diff --git a/arch/s390/include/asm/vdso-symbols.h b/arch/s390/include/asm/vdso-symbols.h
index 0df17574d7889..205da2c565c26 100644
--- a/arch/s390/include/asm/vdso-symbols.h
+++ b/arch/s390/include/asm/vdso-symbols.h
@@ -3,15 +3,7 @@
#define __S390_VDSO_SYMBOLS_H__
#include <generated/vdso64-offsets.h>
-#ifdef CONFIG_COMPAT
-#include <generated/vdso32-offsets.h>
-#endif
#define VDSO64_SYMBOL(tsk, name) ((tsk)->mm->context.vdso_base + (vdso64_offset_##name))
-#ifdef CONFIG_COMPAT
-#define VDSO32_SYMBOL(tsk, name) ((tsk)->mm->context.vdso_base + (vdso32_offset_##name))
-#else
-#define VDSO32_SYMBOL(tsk, name) (-1UL)
-#endif
#endif /* __S390_VDSO_SYMBOLS_H__ */
diff --git a/arch/s390/kernel/Makefile b/arch/s390/kernel/Makefile
index eb06ff888314b..c949ed394e72f 100644
--- a/arch/s390/kernel/Makefile
+++ b/arch/s390/kernel/Makefile
@@ -56,9 +56,6 @@ obj-$(CONFIG_MODULES) += module.o
obj-$(CONFIG_SCHED_TOPOLOGY) += topology.o hiperdispatch.o
obj-$(CONFIG_NUMA) += numa.o
obj-$(CONFIG_AUDIT) += audit.o
-compat-obj-$(CONFIG_AUDIT) += compat_audit.o
-obj-$(CONFIG_COMPAT) += compat_linux.o compat_signal.o
-obj-$(CONFIG_COMPAT) += $(compat-obj-y)
obj-$(CONFIG_EARLY_PRINTK) += early_printk.o
obj-$(CONFIG_KPROBES) += kprobes.o
obj-$(CONFIG_KPROBES) += mcount.o
@@ -85,4 +82,3 @@ obj-$(CONFIG_TRACEPOINTS) += trace.o
# vdso
obj-y += vdso64/
-obj-$(CONFIG_COMPAT) += vdso32/
diff --git a/arch/s390/kernel/audit.c b/arch/s390/kernel/audit.c
index 02051a596b87c..7897d9411e130 100644
--- a/arch/s390/kernel/audit.c
+++ b/arch/s390/kernel/audit.c
@@ -3,7 +3,6 @@
#include <linux/types.h>
#include <linux/audit.h>
#include <asm/unistd.h>
-#include "audit.h"
static unsigned dir_class[] = {
#include <asm-generic/audit_dir_write.h>
@@ -32,19 +31,11 @@ static unsigned signal_class[] = {
int audit_classify_arch(int arch)
{
-#ifdef CONFIG_COMPAT
- if (arch == AUDIT_ARCH_S390)
- return 1;
-#endif
return 0;
}
int audit_classify_syscall(int abi, unsigned syscall)
{
-#ifdef CONFIG_COMPAT
- if (abi == AUDIT_ARCH_S390)
- return s390_classify_syscall(syscall);
-#endif
switch(syscall) {
case __NR_open:
return AUDITSC_OPEN;
@@ -63,13 +54,6 @@ int audit_classify_syscall(int abi, unsigned syscall)
static int __init audit_classes_init(void)
{
-#ifdef CONFIG_COMPAT
- audit_register_class(AUDIT_CLASS_WRITE_32, s390_write_class);
- audit_register_class(AUDIT_CLASS_READ_32, s390_read_class);
- audit_register_class(AUDIT_CLASS_DIR_WRITE_32, s390_dir_class);
- audit_register_class(AUDIT_CLASS_CHATTR_32, s390_chattr_class);
- audit_register_class(AUDIT_CLASS_SIGNAL_32, s390_signal_class);
-#endif
audit_register_class(AUDIT_CLASS_WRITE, write_class);
audit_register_class(AUDIT_CLASS_READ, read_class);
audit_register_class(AUDIT_CLASS_DIR_WRITE, dir_class);
diff --git a/arch/s390/kernel/audit.h b/arch/s390/kernel/audit.h
deleted file mode 100644
index 4d4b596412ec2..0000000000000
--- a/arch/s390/kernel/audit.h
+++ /dev/null
@@ -1,16 +0,0 @@
-/* SPDX-License-Identifier: GPL-2.0 */
-#ifndef __ARCH_S390_KERNEL_AUDIT_H
-#define __ARCH_S390_KERNEL_AUDIT_H
-
-#include <linux/types.h>
-
-#ifdef CONFIG_COMPAT
-extern int s390_classify_syscall(unsigned);
-extern __u32 s390_dir_class[];
-extern __u32 s390_write_class[];
-extern __u32 s390_read_class[];
-extern __u32 s390_chattr_class[];
-extern __u32 s390_signal_class[];
-#endif /* CONFIG_COMPAT */
-
-#endif /* __ARCH_S390_KERNEL_AUDIT_H */
diff --git a/arch/s390/kernel/compat_audit.c b/arch/s390/kernel/compat_audit.c
deleted file mode 100644
index a7c46e8310f03..0000000000000
--- a/arch/s390/kernel/compat_audit.c
+++ /dev/null
@@ -1,48 +0,0 @@
-// SPDX-License-Identifier: GPL-2.0
-#undef __s390x__
-#include <linux/audit_arch.h>
-#include <asm/unistd.h>
-#include "audit.h"
-
-unsigned s390_dir_class[] = {
-#include <asm-generic/audit_dir_write.h>
-~0U
-};
-
-unsigned s390_chattr_class[] = {
-#include <asm-generic/audit_change_attr.h>
-~0U
-};
-
-unsigned s390_write_class[] = {
-#include <asm-generic/audit_write.h>
-~0U
-};
-
-unsigned s390_read_class[] = {
-#include <asm-generic/audit_read.h>
-~0U
-};
-
-unsigned s390_signal_class[] = {
-#include <asm-generic/audit_signal.h>
-~0U
-};
-
-int s390_classify_syscall(unsigned syscall)
-{
- switch(syscall) {
- case __NR_open:
- return AUDITSC_OPEN;
- case __NR_openat:
- return AUDITSC_OPENAT;
- case __NR_socketcall:
- return AUDITSC_SOCKETCALL;
- case __NR_execve:
- return AUDITSC_EXECVE;
- case __NR_openat2:
- return AUDITSC_OPENAT2;
- default:
- return AUDITSC_COMPAT;
- }
-}
diff --git a/arch/s390/kernel/compat_linux.c b/arch/s390/kernel/compat_linux.c
deleted file mode 100644
index f9d418d1b6192..0000000000000
--- a/arch/s390/kernel/compat_linux.c
+++ /dev/null
@@ -1,289 +0,0 @@
-// SPDX-License-Identifier: GPL-2.0
-/*
- * S390 version
- * Copyright IBM Corp. 2000
- * Author(s): Martin Schwidefsky (schwidefsky@de.ibm.com),
- * Gerhard Tonn (ton@de.ibm.com)
- * Thomas Spatzier (tspat@de.ibm.com)
- *
- * Conversion between 31bit and 64bit native syscalls.
- *
- * Heavily inspired by the 32-bit Sparc compat code which is
- * Copyright (C) 1997,1998 Jakub Jelinek (jj@sunsite.mff.cuni.cz)
- * Copyright (C) 1997 David S. Miller (davem@caip.rutgers.edu)
- *
- */
-
-
-#include <linux/kernel.h>
-#include <linux/sched.h>
-#include <linux/fs.h>
-#include <linux/mm.h>
-#include <linux/file.h>
-#include <linux/signal.h>
-#include <linux/resource.h>
-#include <linux/times.h>
-#include <linux/smp.h>
-#include <linux/sem.h>
-#include <linux/msg.h>
-#include <linux/shm.h>
-#include <linux/uio.h>
-#include <linux/quota.h>
-#include <linux/poll.h>
-#include <linux/personality.h>
-#include <linux/stat.h>
-#include <linux/filter.h>
-#include <linux/highmem.h>
-#include <linux/mman.h>
-#include <linux/ipv6.h>
-#include <linux/in.h>
-#include <linux/icmpv6.h>
-#include <linux/syscalls.h>
-#include <linux/sysctl.h>
-#include <linux/binfmts.h>
-#include <linux/capability.h>
-#include <linux/compat.h>
-#include <linux/vfs.h>
-#include <linux/ptrace.h>
-#include <linux/fadvise.h>
-#include <linux/ipc.h>
-#include <linux/slab.h>
-
-#include <asm/types.h>
-#include <linux/uaccess.h>
-
-#include <net/scm.h>
-#include <net/sock.h>
-
-#include "compat_linux.h"
-
-#ifdef CONFIG_SYSVIPC
-COMPAT_SYSCALL_DEFINE5(s390_ipc, uint, call, int, first, compat_ulong_t, second,
- compat_ulong_t, third, compat_uptr_t, ptr)
-{
- if (call >> 16) /* hack for backward compatibility */
- return -EINVAL;
- return compat_ksys_ipc(call, first, second, third, ptr, third);
-}
-#endif
-
-COMPAT_SYSCALL_DEFINE3(s390_truncate64, const char __user *, path, u32, high, u32, low)
-{
- return ksys_truncate(path, (unsigned long)high << 32 | low);
-}
-
-COMPAT_SYSCALL_DEFINE3(s390_ftruncate64, unsigned int, fd, u32, high, u32, low)
-{
- return ksys_ftruncate(fd, (unsigned long)high << 32 | low);
-}
-
-COMPAT_SYSCALL_DEFINE5(s390_pread64, unsigned int, fd, char __user *, ubuf,
- compat_size_t, count, u32, high, u32, low)
-{
- if ((compat_ssize_t) count < 0)
- return -EINVAL;
- return ksys_pread64(fd, ubuf, count, (unsigned long)high << 32 | low);
-}
-
-COMPAT_SYSCALL_DEFINE5(s390_pwrite64, unsigned int, fd, const char __user *, ubuf,
- compat_size_t, count, u32, high, u32, low)
-{
- if ((compat_ssize_t) count < 0)
- return -EINVAL;
- return ksys_pwrite64(fd, ubuf, count, (unsigned long)high << 32 | low);
-}
-
-COMPAT_SYSCALL_DEFINE4(s390_readahead, int, fd, u32, high, u32, low, s32, count)
-{
- return ksys_readahead(fd, (unsigned long)high << 32 | low, count);
-}
-
-struct stat64_emu31 {
- unsigned long long st_dev;
- unsigned int __pad1;
-#define STAT64_HAS_BROKEN_ST_INO 1
- u32 __st_ino;
- unsigned int st_mode;
- unsigned int st_nlink;
- u32 st_uid;
- u32 st_gid;
- unsigned long long st_rdev;
- unsigned int __pad3;
- long st_size;
- u32 st_blksize;
- unsigned char __pad4[4];
- u32 __pad5; /* future possible st_blocks high bits */
- u32 st_blocks; /* Number 512-byte blocks allocated. */
- u32 st_atime;
- u32 __pad6;
- u32 st_mtime;
- u32 __pad7;
- u32 st_ctime;
- u32 __pad8; /* will be high 32 bits of ctime someday */
- unsigned long st_ino;
-};
-
-static int cp_stat64(struct stat64_emu31 __user *ubuf, struct kstat *stat)
-{
- struct stat64_emu31 tmp;
-
- memset(&tmp, 0, sizeof(tmp));
-
- tmp.st_dev = huge_encode_dev(stat->dev);
- tmp.st_ino = stat->ino;
- tmp.__st_ino = (u32)stat->ino;
- tmp.st_mode = stat->mode;
- tmp.st_nlink = (unsigned int)stat->nlink;
- tmp.st_uid = from_kuid_munged(current_user_ns(), stat->uid);
- tmp.st_gid = from_kgid_munged(current_user_ns(), stat->gid);
- tmp.st_rdev = huge_encode_dev(stat->rdev);
- tmp.st_size = stat->size;
- tmp.st_blksize = (u32)stat->blksize;
- tmp.st_blocks = (u32)stat->blocks;
- tmp.st_atime = (u32)stat->atime.tv_sec;
- tmp.st_mtime = (u32)stat->mtime.tv_sec;
- tmp.st_ctime = (u32)stat->ctime.tv_sec;
-
- return copy_to_user(ubuf,&tmp,sizeof(tmp)) ? -EFAULT : 0;
-}
-
-COMPAT_SYSCALL_DEFINE2(s390_stat64, const char __user *, filename, struct stat64_emu31 __user *, statbuf)
-{
- struct kstat stat;
- int ret = vfs_stat(filename, &stat);
- if (!ret)
- ret = cp_stat64(statbuf, &stat);
- return ret;
-}
-
-COMPAT_SYSCALL_DEFINE2(s390_lstat64, const char __user *, filename, struct stat64_emu31 __user *, statbuf)
-{
- struct kstat stat;
- int ret = vfs_lstat(filename, &stat);
- if (!ret)
- ret = cp_stat64(statbuf, &stat);
- return ret;
-}
-
-COMPAT_SYSCALL_DEFINE2(s390_fstat64, unsigned int, fd, struct stat64_emu31 __user *, statbuf)
-{
- struct kstat stat;
- int ret = vfs_fstat(fd, &stat);
- if (!ret)
- ret = cp_stat64(statbuf, &stat);
- return ret;
-}
-
-COMPAT_SYSCALL_DEFINE4(s390_fstatat64, unsigned int, dfd, const char __user *, filename,
- struct stat64_emu31 __user *, statbuf, int, flag)
-{
- struct kstat stat;
- int error;
-
- error = vfs_fstatat(dfd, filename, &stat, flag);
- if (error)
- return error;
- return cp_stat64(statbuf, &stat);
-}
-
-/*
- * Linux/i386 didn't use to be able to handle more than
- * 4 system call parameters, so these system calls used a memory
- * block for parameter passing..
- */
-
-struct mmap_arg_struct_emu31 {
- compat_ulong_t addr;
- compat_ulong_t len;
- compat_ulong_t prot;
- compat_ulong_t flags;
- compat_ulong_t fd;
- compat_ulong_t offset;
-};
-
-COMPAT_SYSCALL_DEFINE1(s390_old_mmap, struct mmap_arg_struct_emu31 __user *, arg)
-{
- struct mmap_arg_struct_emu31 a;
-
- if (copy_from_user(&a, arg, sizeof(a)))
- return -EFAULT;
- if (a.offset & ~PAGE_MASK)
- return -EINVAL;
- return ksys_mmap_pgoff(a.addr, a.len, a.prot, a.flags, a.fd,
- a.offset >> PAGE_SHIFT);
-}
-
-COMPAT_SYSCALL_DEFINE1(s390_mmap2, struct mmap_arg_struct_emu31 __user *, arg)
-{
- struct mmap_arg_struct_emu31 a;
-
- if (copy_from_user(&a, arg, sizeof(a)))
- return -EFAULT;
- return ksys_mmap_pgoff(a.addr, a.len, a.prot, a.flags, a.fd, a.offset);
-}
-
-COMPAT_SYSCALL_DEFINE3(s390_read, unsigned int, fd, char __user *, buf, compat_size_t, count)
-{
- if ((compat_ssize_t) count < 0)
- return -EINVAL;
-
- return ksys_read(fd, buf, count);
-}
-
-COMPAT_SYSCALL_DEFINE3(s390_write, unsigned int, fd, const char __user *, buf, compat_size_t, count)
-{
- if ((compat_ssize_t) count < 0)
- return -EINVAL;
-
- return ksys_write(fd, buf, count);
-}
-
-/*
- * 31 bit emulation wrapper functions for sys_fadvise64/fadvise64_64.
- * These need to rewrite the advise values for POSIX_FADV_{DONTNEED,NOREUSE}
- * because the 31 bit values differ from the 64 bit values.
- */
-
-COMPAT_SYSCALL_DEFINE5(s390_fadvise64, int, fd, u32, high, u32, low, compat_size_t, len, int, advise)
-{
- if (advise == 4)
- advise = POSIX_FADV_DONTNEED;
- else if (advise == 5)
- advise = POSIX_FADV_NOREUSE;
- return ksys_fadvise64_64(fd, (unsigned long)high << 32 | low, len,
- advise);
-}
-
-struct fadvise64_64_args {
- int fd;
- long long offset;
- long long len;
- int advice;
-};
-
-COMPAT_SYSCALL_DEFINE1(s390_fadvise64_64, struct fadvise64_64_args __user *, args)
-{
- struct fadvise64_64_args a;
-
- if ( copy_from_user(&a, args, sizeof(a)) )
- return -EFAULT;
- if (a.advice == 4)
- a.advice = POSIX_FADV_DONTNEED;
- else if (a.advice == 5)
- a.advice = POSIX_FADV_NOREUSE;
- return ksys_fadvise64_64(a.fd, a.offset, a.len, a.advice);
-}
-
-COMPAT_SYSCALL_DEFINE6(s390_sync_file_range, int, fd, u32, offhigh, u32, offlow,
- u32, nhigh, u32, nlow, unsigned int, flags)
-{
- return ksys_sync_file_range(fd, ((loff_t)offhigh << 32) + offlow,
- ((u64)nhigh << 32) + nlow, flags);
-}
-
-COMPAT_SYSCALL_DEFINE6(s390_fallocate, int, fd, int, mode, u32, offhigh, u32, offlow,
- u32, lenhigh, u32, lenlow)
-{
- return ksys_fallocate(fd, mode, ((loff_t)offhigh << 32) + offlow,
- ((u64)lenhigh << 32) + lenlow);
-}
diff --git a/arch/s390/kernel/compat_linux.h b/arch/s390/kernel/compat_linux.h
deleted file mode 100644
index 133f22b5deebc..0000000000000
--- a/arch/s390/kernel/compat_linux.h
+++ /dev/null
@@ -1,101 +0,0 @@
-/* SPDX-License-Identifier: GPL-2.0 */
-#ifndef _ASM_S390X_S390_H
-#define _ASM_S390X_S390_H
-
-#include <linux/compat.h>
-#include <linux/socket.h>
-#include <linux/syscalls.h>
-#include <asm/ptrace.h>
-
-/*
- * Macro that masks the high order bit of a 32 bit pointer and
- * converts it to a 64 bit pointer.
- */
-#define A(__x) ((unsigned long)((__x) & 0x7FFFFFFFUL))
-#define AA(__x) ((unsigned long)(__x))
-
-/* Now 32bit compatibility types */
-struct ipc_kludge_32 {
- __u32 msgp; /* pointer */
- __s32 msgtyp;
-};
-
-/* asm/sigcontext.h */
-typedef union {
- __u64 d;
- __u32 f;
-} freg_t32;
-
-typedef struct {
- unsigned int fpc;
- unsigned int pad;
- freg_t32 fprs[__NUM_FPRS];
-} _s390_fp_regs32;
-
-typedef struct {
- psw32_t psw;
- __u32 gprs[__NUM_GPRS];
- __u32 acrs[__NUM_ACRS];
-} _s390_regs_common32;
-
-typedef struct {
- _s390_regs_common32 regs;
- _s390_fp_regs32 fpregs;
-} _sigregs32;
-
-typedef struct {
- __u32 gprs_high[__NUM_GPRS];
- __u64 vxrs_low[__NUM_VXRS_LOW];
- __vector128 vxrs_high[__NUM_VXRS_HIGH];
- __u8 __reserved[128];
-} _sigregs_ext32;
-
-#define _SIGCONTEXT_NSIG32 64
-#define _SIGCONTEXT_NSIG_BPW32 32
-#define __SIGNAL_FRAMESIZE32 96
-#define _SIGMASK_COPY_SIZE32 (sizeof(u32) * 2)
-
-struct sigcontext32 {
- __u32 oldmask[_COMPAT_NSIG_WORDS];
- __u32 sregs; /* pointer */
-};
-
-/* asm/signal.h */
-
-/* asm/ucontext.h */
-struct ucontext32 {
- __u32 uc_flags;
- __u32 uc_link; /* pointer */
- compat_stack_t uc_stack;
- _sigregs32 uc_mcontext;
- compat_sigset_t uc_sigmask;
- /* Allow for uc_sigmask growth. Glibc uses a 1024-bit sigset_t. */
- unsigned char __unused[128 - sizeof(compat_sigset_t)];
- _sigregs_ext32 uc_mcontext_ext;
-};
-
-struct stat64_emu31;
-struct mmap_arg_struct_emu31;
-struct fadvise64_64_args;
-
-long compat_sys_s390_truncate64(const char __user *path, u32 high, u32 low);
-long compat_sys_s390_ftruncate64(unsigned int fd, u32 high, u32 low);
-long compat_sys_s390_pread64(unsigned int fd, char __user *ubuf, compat_size_t count, u32 high, u32 low);
-long compat_sys_s390_pwrite64(unsigned int fd, const char __user *ubuf, compat_size_t count, u32 high, u32 low);
-long compat_sys_s390_readahead(int fd, u32 high, u32 low, s32 count);
-long compat_sys_s390_stat64(const char __user *filename, struct stat64_emu31 __user *statbuf);
-long compat_sys_s390_lstat64(const char __user *filename, struct stat64_emu31 __user *statbuf);
-long compat_sys_s390_fstat64(unsigned int fd, struct stat64_emu31 __user *statbuf);
-long compat_sys_s390_fstatat64(unsigned int dfd, const char __user *filename, struct stat64_emu31 __user *statbuf, int flag);
-long compat_sys_s390_old_mmap(struct mmap_arg_struct_emu31 __user *arg);
-long compat_sys_s390_mmap2(struct mmap_arg_struct_emu31 __user *arg);
-long compat_sys_s390_read(unsigned int fd, char __user *buf, compat_size_t count);
-long compat_sys_s390_write(unsigned int fd, const char __user *buf, compat_size_t count);
-long compat_sys_s390_fadvise64(int fd, u32 high, u32 low, compat_size_t len, int advise);
-long compat_sys_s390_fadvise64_64(struct fadvise64_64_args __user *args);
-long compat_sys_s390_sync_file_range(int fd, u32 offhigh, u32 offlow, u32 nhigh, u32 nlow, unsigned int flags);
-long compat_sys_s390_fallocate(int fd, int mode, u32 offhigh, u32 offlow, u32 lenhigh, u32 lenlow);
-long compat_sys_sigreturn(void);
-long compat_sys_rt_sigreturn(void);
-
-#endif /* _ASM_S390X_S390_H */
diff --git a/arch/s390/kernel/compat_ptrace.h b/arch/s390/kernel/compat_ptrace.h
deleted file mode 100644
index 3c400fc7e987b..0000000000000
--- a/arch/s390/kernel/compat_ptrace.h
+++ /dev/null
@@ -1,64 +0,0 @@
-/* SPDX-License-Identifier: GPL-2.0 */
-#ifndef _PTRACE32_H
-#define _PTRACE32_H
-
-#include <asm/ptrace.h> /* needed for NUM_CR_WORDS */
-#include "compat_linux.h" /* needed for psw_compat_t */
-
-struct compat_per_struct_kernel {
- __u32 cr9; /* PER control bits */
- __u32 cr10; /* PER starting address */
- __u32 cr11; /* PER ending address */
- __u32 bits; /* Obsolete software bits */
- __u32 starting_addr; /* User specified start address */
- __u32 ending_addr; /* User specified end address */
- __u16 perc_atmid; /* PER trap ATMID */
- __u32 address; /* PER trap instruction address */
- __u8 access_id; /* PER trap access identification */
-};
-
-struct compat_user_regs_struct
-{
- psw_compat_t psw;
- u32 gprs[NUM_GPRS];
- u32 acrs[NUM_ACRS];
- u32 orig_gpr2;
- /* nb: there's a 4-byte hole here */
- s390_fp_regs fp_regs;
- /*
- * These per registers are in here so that gdb can modify them
- * itself as there is no "official" ptrace interface for hardware
- * watchpoints. This is the way intel does it.
- */
- struct compat_per_struct_kernel per_info;
- u32 ieee_instruction_pointer; /* obsolete, always 0 */
-};
-
-struct compat_user {
- /* We start with the registers, to mimic the way that "memory"
- is returned from the ptrace(3,...) function. */
- struct compat_user_regs_struct regs;
- /* The rest of this junk is to help gdb figure out what goes where */
- u32 u_tsize; /* Text segment size (pages). */
- u32 u_dsize; /* Data segment size (pages). */
- u32 u_ssize; /* Stack segment size (pages). */
- u32 start_code; /* Starting virtual address of text. */
- u32 start_stack; /* Starting virtual address of stack area.
- This is actually the bottom of the stack,
- the top of the stack is always found in the
- esp register. */
- s32 signal; /* Signal that caused the core dump. */
- u32 u_ar0; /* Used by gdb to help find the values for */
- /* the registers. */
- u32 magic; /* To uniquely identify a core file */
- char u_comm[32]; /* User command that was responsible */
-};
-
-typedef struct
-{
- __u32 len;
- __u32 kernel_addr;
- __u32 process_addr;
-} compat_ptrace_area;
-
-#endif /* _PTRACE32_H */
diff --git a/arch/s390/kernel/compat_signal.c b/arch/s390/kernel/compat_signal.c
deleted file mode 100644
index 5a86b9d1da716..0000000000000
--- a/arch/s390/kernel/compat_signal.c
+++ /dev/null
@@ -1,420 +0,0 @@
-// SPDX-License-Identifier: GPL-2.0
-/*
- * Copyright IBM Corp. 2000, 2006
- * Author(s): Denis Joseph Barrow (djbarrow@de.ibm.com,barrow_dj@yahoo.com)
- * Gerhard Tonn (ton@de.ibm.com)
- *
- * Copyright (C) 1991, 1992 Linus Torvalds
- *
- * 1997-11-28 Modified for POSIX.1b signals by Richard Henderson
- */
-
-#include <linux/compat.h>
-#include <linux/sched.h>
-#include <linux/sched/task_stack.h>
-#include <linux/mm.h>
-#include <linux/smp.h>
-#include <linux/kernel.h>
-#include <linux/signal.h>
-#include <linux/errno.h>
-#include <linux/wait.h>
-#include <linux/ptrace.h>
-#include <linux/unistd.h>
-#include <linux/stddef.h>
-#include <linux/tty.h>
-#include <linux/personality.h>
-#include <linux/binfmts.h>
-#include <asm/vdso-symbols.h>
-#include <asm/access-regs.h>
-#include <asm/ucontext.h>
-#include <linux/uaccess.h>
-#include <asm/lowcore.h>
-#include <asm/fpu.h>
-#include "compat_linux.h"
-#include "compat_ptrace.h"
-#include "entry.h"
-
-typedef struct
-{
- __u8 callee_used_stack[__SIGNAL_FRAMESIZE32];
- struct sigcontext32 sc;
- _sigregs32 sregs;
- int signo;
- _sigregs_ext32 sregs_ext;
- __u16 svc_insn; /* Offset of svc_insn is NOT fixed! */
-} sigframe32;
-
-typedef struct
-{
- __u8 callee_used_stack[__SIGNAL_FRAMESIZE32];
- __u16 svc_insn;
- compat_siginfo_t info;
- struct ucontext32 uc;
-} rt_sigframe32;
-
-/* Store registers needed to create the signal frame */
-static void store_sigregs(void)
-{
- save_access_regs(current->thread.acrs);
- save_user_fpu_regs();
-}
-
-/* Load registers after signal return */
-static void load_sigregs(void)
-{
- restore_access_regs(current->thread.acrs);
-}
-
-static int save_sigregs32(struct pt_regs *regs, _sigregs32 __user *sregs)
-{
- _sigregs32 user_sregs;
- int i;
-
- user_sregs.regs.psw.mask = (__u32)(regs->psw.mask >> 32);
- user_sregs.regs.psw.mask &= PSW32_MASK_USER | PSW32_MASK_RI;
- user_sregs.regs.psw.mask |= PSW32_USER_BITS;
- user_sregs.regs.psw.addr = (__u32) regs->psw.addr |
- (__u32)(regs->psw.mask & PSW_MASK_BA);
- for (i = 0; i < NUM_GPRS; i++)
- user_sregs.regs.gprs[i] = (__u32) regs->gprs[i];
- memcpy(&user_sregs.regs.acrs, current->thread.acrs,
- sizeof(user_sregs.regs.acrs));
- fpregs_store((_s390_fp_regs *) &user_sregs.fpregs, ¤t->thread.ufpu);
- if (__copy_to_user(sregs, &user_sregs, sizeof(_sigregs32)))
- return -EFAULT;
- return 0;
-}
-
-static int restore_sigregs32(struct pt_regs *regs,_sigregs32 __user *sregs)
-{
- _sigregs32 user_sregs;
- int i;
-
- /* Always make any pending restarted system call return -EINTR */
- current->restart_block.fn = do_no_restart_syscall;
-
- if (__copy_from_user(&user_sregs, &sregs->regs, sizeof(user_sregs)))
- return -EFAULT;
-
- if (!is_ri_task(current) && (user_sregs.regs.psw.mask & PSW32_MASK_RI))
- return -EINVAL;
-
- /* Use regs->psw.mask instead of PSW_USER_BITS to preserve PER bit. */
- regs->psw.mask = (regs->psw.mask & ~(PSW_MASK_USER | PSW_MASK_RI)) |
- (__u64)(user_sregs.regs.psw.mask & PSW32_MASK_USER) << 32 |
- (__u64)(user_sregs.regs.psw.mask & PSW32_MASK_RI) << 32 |
- (__u64)(user_sregs.regs.psw.addr & PSW32_ADDR_AMODE);
- /* Check for invalid user address space control. */
- if ((regs->psw.mask & PSW_MASK_ASC) == PSW_ASC_HOME)
- regs->psw.mask = PSW_ASC_PRIMARY |
- (regs->psw.mask & ~PSW_MASK_ASC);
- regs->psw.addr = (__u64)(user_sregs.regs.psw.addr & PSW32_ADDR_INSN);
- for (i = 0; i < NUM_GPRS; i++)
- regs->gprs[i] = (__u64) user_sregs.regs.gprs[i];
- memcpy(¤t->thread.acrs, &user_sregs.regs.acrs,
- sizeof(current->thread.acrs));
- fpregs_load((_s390_fp_regs *)&user_sregs.fpregs, ¤t->thread.ufpu);
-
- clear_pt_regs_flag(regs, PIF_SYSCALL); /* No longer in a system call */
- return 0;
-}
-
-static int save_sigregs_ext32(struct pt_regs *regs,
- _sigregs_ext32 __user *sregs_ext)
-{
- __u32 gprs_high[NUM_GPRS];
- __u64 vxrs[__NUM_VXRS_LOW];
- int i;
-
- /* Save high gprs to signal stack */
- for (i = 0; i < NUM_GPRS; i++)
- gprs_high[i] = regs->gprs[i] >> 32;
- if (__copy_to_user(&sregs_ext->gprs_high, &gprs_high,
- sizeof(sregs_ext->gprs_high)))
- return -EFAULT;
-
- /* Save vector registers to signal stack */
- if (cpu_has_vx()) {
- for (i = 0; i < __NUM_VXRS_LOW; i++)
- vxrs[i] = current->thread.ufpu.vxrs[i].low;
- if (__copy_to_user(&sregs_ext->vxrs_low, vxrs,
- sizeof(sregs_ext->vxrs_low)) ||
- __copy_to_user(&sregs_ext->vxrs_high,
- current->thread.ufpu.vxrs + __NUM_VXRS_LOW,
- sizeof(sregs_ext->vxrs_high)))
- return -EFAULT;
- }
- return 0;
-}
-
-static int restore_sigregs_ext32(struct pt_regs *regs,
- _sigregs_ext32 __user *sregs_ext)
-{
- __u32 gprs_high[NUM_GPRS];
- __u64 vxrs[__NUM_VXRS_LOW];
- int i;
-
- /* Restore high gprs from signal stack */
- if (__copy_from_user(&gprs_high, &sregs_ext->gprs_high,
- sizeof(sregs_ext->gprs_high)))
- return -EFAULT;
- for (i = 0; i < NUM_GPRS; i++)
- *(__u32 *)®s->gprs[i] = gprs_high[i];
-
- /* Restore vector registers from signal stack */
- if (cpu_has_vx()) {
- if (__copy_from_user(vxrs, &sregs_ext->vxrs_low,
- sizeof(sregs_ext->vxrs_low)) ||
- __copy_from_user(current->thread.ufpu.vxrs + __NUM_VXRS_LOW,
- &sregs_ext->vxrs_high,
- sizeof(sregs_ext->vxrs_high)))
- return -EFAULT;
- for (i = 0; i < __NUM_VXRS_LOW; i++)
- current->thread.ufpu.vxrs[i].low = vxrs[i];
- }
- return 0;
-}
-
-COMPAT_SYSCALL_DEFINE0(sigreturn)
-{
- struct pt_regs *regs = task_pt_regs(current);
- sigframe32 __user *frame = (sigframe32 __user *)regs->gprs[15];
- sigset_t set;
-
- if (get_compat_sigset(&set, (compat_sigset_t __user *)frame->sc.oldmask))
- goto badframe;
- set_current_blocked(&set);
- save_user_fpu_regs();
- if (restore_sigregs32(regs, &frame->sregs))
- goto badframe;
- if (restore_sigregs_ext32(regs, &frame->sregs_ext))
- goto badframe;
- load_sigregs();
- return regs->gprs[2];
-badframe:
- force_sig(SIGSEGV);
- return 0;
-}
-
-COMPAT_SYSCALL_DEFINE0(rt_sigreturn)
-{
- struct pt_regs *regs = task_pt_regs(current);
- rt_sigframe32 __user *frame = (rt_sigframe32 __user *)regs->gprs[15];
- sigset_t set;
-
- if (get_compat_sigset(&set, &frame->uc.uc_sigmask))
- goto badframe;
- set_current_blocked(&set);
- if (compat_restore_altstack(&frame->uc.uc_stack))
- goto badframe;
- save_user_fpu_regs();
- if (restore_sigregs32(regs, &frame->uc.uc_mcontext))
- goto badframe;
- if (restore_sigregs_ext32(regs, &frame->uc.uc_mcontext_ext))
- goto badframe;
- load_sigregs();
- return regs->gprs[2];
-badframe:
- force_sig(SIGSEGV);
- return 0;
-}
-
-/*
- * Set up a signal frame.
- */
-
-
-/*
- * Determine which stack to use..
- */
-static inline void __user *
-get_sigframe(struct k_sigaction *ka, struct pt_regs * regs, size_t frame_size)
-{
- unsigned long sp;
-
- /* Default to using normal stack */
- sp = (unsigned long) A(regs->gprs[15]);
-
- /* Overflow on alternate signal stack gives SIGSEGV. */
- if (on_sig_stack(sp) && !on_sig_stack((sp - frame_size) & -8UL))
- return (void __user *) -1UL;
-
- /* This is the X/Open sanctioned signal stack switching. */
- if (ka->sa.sa_flags & SA_ONSTACK) {
- if (! sas_ss_flags(sp))
- sp = current->sas_ss_sp + current->sas_ss_size;
- }
-
- return (void __user *)((sp - frame_size) & -8ul);
-}
-
-static int setup_frame32(struct ksignal *ksig, sigset_t *set,
- struct pt_regs *regs)
-{
- int sig = ksig->sig;
- sigframe32 __user *frame;
- unsigned long restorer;
- size_t frame_size;
-
- /*
- * gprs_high are always present for 31-bit compat tasks.
- * The space for vector registers is only allocated if
- * the machine supports it
- */
- frame_size = sizeof(*frame) - sizeof(frame->sregs_ext.__reserved);
- if (!cpu_has_vx())
- frame_size -= sizeof(frame->sregs_ext.vxrs_low) +
- sizeof(frame->sregs_ext.vxrs_high);
- frame = get_sigframe(&ksig->ka, regs, frame_size);
- if (frame == (void __user *) -1UL)
- return -EFAULT;
-
- /* Set up backchain. */
- if (__put_user(regs->gprs[15], (unsigned int __user *) frame))
- return -EFAULT;
-
- /* Create struct sigcontext32 on the signal stack */
- if (put_compat_sigset((compat_sigset_t __user *)frame->sc.oldmask,
- set, sizeof(compat_sigset_t)))
- return -EFAULT;
- if (__put_user(ptr_to_compat(&frame->sregs), &frame->sc.sregs))
- return -EFAULT;
-
- /* Store registers needed to create the signal frame */
- store_sigregs();
-
- /* Create _sigregs32 on the signal stack */
- if (save_sigregs32(regs, &frame->sregs))
- return -EFAULT;
-
- /* Place signal number on stack to allow backtrace from handler. */
- if (__put_user(regs->gprs[2], (int __force __user *) &frame->signo))
- return -EFAULT;
-
- /* Create _sigregs_ext32 on the signal stack */
- if (save_sigregs_ext32(regs, &frame->sregs_ext))
- return -EFAULT;
-
- /* Set up to return from userspace. If provided, use a stub
- already in userspace. */
- if (ksig->ka.sa.sa_flags & SA_RESTORER) {
- restorer = (unsigned long __force)
- ksig->ka.sa.sa_restorer | PSW32_ADDR_AMODE;
- } else {
- restorer = VDSO32_SYMBOL(current, sigreturn);
- }
-
- /* Set up registers for signal handler */
- regs->gprs[14] = restorer;
- regs->gprs[15] = (__force __u64) frame;
- /* Force 31 bit amode and default user address space control. */
- regs->psw.mask = PSW_MASK_BA |
- (PSW_USER_BITS & PSW_MASK_ASC) |
- (regs->psw.mask & ~PSW_MASK_ASC);
- regs->psw.addr = (__force __u64) ksig->ka.sa.sa_handler;
-
- regs->gprs[2] = sig;
- regs->gprs[3] = (__force __u64) &frame->sc;
-
- /* We forgot to include these in the sigcontext.
- To avoid breaking binary compatibility, they are passed as args. */
- if (sig == SIGSEGV || sig == SIGBUS || sig == SIGILL ||
- sig == SIGTRAP || sig == SIGFPE) {
- /* set extra registers only for synchronous signals */
- regs->gprs[4] = regs->int_code & 127;
- regs->gprs[5] = regs->int_parm_long;
- regs->gprs[6] = current->thread.last_break;
- }
-
- return 0;
-}
-
-static int setup_rt_frame32(struct ksignal *ksig, sigset_t *set,
- struct pt_regs *regs)
-{
- rt_sigframe32 __user *frame;
- unsigned long restorer;
- size_t frame_size;
- u32 uc_flags;
-
- frame_size = sizeof(*frame) -
- sizeof(frame->uc.uc_mcontext_ext.__reserved);
- /*
- * gprs_high are always present for 31-bit compat tasks.
- * The space for vector registers is only allocated if
- * the machine supports it
- */
- uc_flags = UC_GPRS_HIGH;
- if (cpu_has_vx()) {
- uc_flags |= UC_VXRS;
- } else {
- frame_size -= sizeof(frame->uc.uc_mcontext_ext.vxrs_low) +
- sizeof(frame->uc.uc_mcontext_ext.vxrs_high);
- }
- frame = get_sigframe(&ksig->ka, regs, frame_size);
- if (frame == (void __user *) -1UL)
- return -EFAULT;
-
- /* Set up backchain. */
- if (__put_user(regs->gprs[15], (unsigned int __force __user *) frame))
- return -EFAULT;
-
- /* Set up to return from userspace. If provided, use a stub
- already in userspace. */
- if (ksig->ka.sa.sa_flags & SA_RESTORER) {
- restorer = (unsigned long __force)
- ksig->ka.sa.sa_restorer | PSW32_ADDR_AMODE;
- } else {
- restorer = VDSO32_SYMBOL(current, rt_sigreturn);
- }
-
- /* Create siginfo on the signal stack */
- if (copy_siginfo_to_user32(&frame->info, &ksig->info))
- return -EFAULT;
-
- /* Store registers needed to create the signal frame */
- store_sigregs();
-
- /* Create ucontext on the signal stack. */
- if (__put_user(uc_flags, &frame->uc.uc_flags) ||
- __put_user(0, &frame->uc.uc_link) ||
- __compat_save_altstack(&frame->uc.uc_stack, regs->gprs[15]) ||
- save_sigregs32(regs, &frame->uc.uc_mcontext) ||
- put_compat_sigset(&frame->uc.uc_sigmask, set, sizeof(compat_sigset_t)) ||
- save_sigregs_ext32(regs, &frame->uc.uc_mcontext_ext))
- return -EFAULT;
-
- /* Set up registers for signal handler */
- regs->gprs[14] = restorer;
- regs->gprs[15] = (__force __u64) frame;
- /* Force 31 bit amode and default user address space control. */
- regs->psw.mask = PSW_MASK_BA |
- (PSW_USER_BITS & PSW_MASK_ASC) |
- (regs->psw.mask & ~PSW_MASK_ASC);
- regs->psw.addr = (__u64 __force) ksig->ka.sa.sa_handler;
-
- regs->gprs[2] = ksig->sig;
- regs->gprs[3] = (__force __u64) &frame->info;
- regs->gprs[4] = (__force __u64) &frame->uc;
- regs->gprs[5] = current->thread.last_break;
- return 0;
-}
-
-/*
- * OK, we're invoking a handler
- */
-
-void handle_signal32(struct ksignal *ksig, sigset_t *oldset,
- struct pt_regs *regs)
-{
- int ret;
-
- /* Set up the stack frame */
- if (ksig->ka.sa.sa_flags & SA_SIGINFO)
- ret = setup_rt_frame32(ksig, oldset, regs);
- else
- ret = setup_frame32(ksig, oldset, regs);
-
- signal_setup_done(ret, ksig, test_thread_flag(TIF_SINGLE_STEP));
-}
-
diff --git a/arch/s390/kernel/entry.S b/arch/s390/kernel/entry.S
index 68e770e3a7dce..55139e4786c23 100644
--- a/arch/s390/kernel/entry.S
+++ b/arch/s390/kernel/entry.S
@@ -617,12 +617,3 @@ SYM_DATA_START(sys_call_table)
#include <asm/syscall_table.h>
SYM_DATA_END(sys_call_table)
#undef SYSCALL
-
-#ifdef CONFIG_COMPAT
-
-#define SYSCALL(esame,emu) .quad __s390_ ## emu
-SYM_DATA_START(sys_call_table_emu)
-#include <asm/syscall_table.h>
-SYM_DATA_END(sys_call_table_emu)
-#undef SYSCALL
-#endif
diff --git a/arch/s390/kernel/perf_cpum_cf.c b/arch/s390/kernel/perf_cpum_cf.c
index d866562cae383..2c64e1dc18790 100644
--- a/arch/s390/kernel/perf_cpum_cf.c
+++ b/arch/s390/kernel/perf_cpum_cf.c
@@ -1761,7 +1761,6 @@ static const struct file_operations cfset_fops = {
.open = cfset_open,
.release = cfset_release,
.unlocked_ioctl = cfset_ioctl,
- .compat_ioctl = cfset_ioctl,
};
static struct miscdevice cfset_dev = {
diff --git a/arch/s390/kernel/perf_event.c b/arch/s390/kernel/perf_event.c
index 91b8716c883a5..2de1574d95b2d 100644
--- a/arch/s390/kernel/perf_event.c
+++ b/arch/s390/kernel/perf_event.c
@@ -15,7 +15,6 @@
#include <linux/seq_file.h>
#include <linux/spinlock.h>
#include <linux/uaccess.h>
-#include <linux/compat.h>
#include <linux/sysfs.h>
#include <asm/stacktrace.h>
#include <asm/irq.h>
diff --git a/arch/s390/kernel/perf_regs.c b/arch/s390/kernel/perf_regs.c
index a6b058ee4a36c..7b305f1456f82 100644
--- a/arch/s390/kernel/perf_regs.c
+++ b/arch/s390/kernel/perf_regs.c
@@ -44,9 +44,6 @@ int perf_reg_validate(u64 mask)
u64 perf_reg_abi(struct task_struct *task)
{
- if (test_tsk_thread_flag(task, TIF_31BIT))
- return PERF_SAMPLE_REGS_ABI_32;
-
return PERF_SAMPLE_REGS_ABI_64;
}
diff --git a/arch/s390/kernel/process.c b/arch/s390/kernel/process.c
index f18d7716c4342..e4bd273e31f4e 100644
--- a/arch/s390/kernel/process.c
+++ b/arch/s390/kernel/process.c
@@ -24,7 +24,6 @@
#include <linux/tick.h>
#include <linux/personality.h>
#include <linux/syscalls.h>
-#include <linux/compat.h>
#include <linux/kprobes.h>
#include <linux/random.h>
#include <linux/init_task.h>
@@ -166,12 +165,8 @@ int copy_thread(struct task_struct *p, const struct kernel_clone_args *args)
/* Set a new TLS ? */
if (clone_flags & CLONE_SETTLS) {
- if (is_compat_task()) {
- p->thread.acrs[0] = (unsigned int)tls;
- } else {
- p->thread.acrs[0] = (unsigned int)(tls >> 32);
- p->thread.acrs[1] = (unsigned int)tls;
- }
+ p->thread.acrs[0] = (unsigned int)(tls >> 32);
+ p->thread.acrs[1] = (unsigned int)tls;
}
/*
* s390 stores the svc return address in arch_data when calling
diff --git a/arch/s390/kernel/ptrace.c b/arch/s390/kernel/ptrace.c
index 494216c4b4f3d..ceaa1726e3285 100644
--- a/arch/s390/kernel/ptrace.c
+++ b/arch/s390/kernel/ptrace.c
@@ -22,7 +22,6 @@
#include <linux/elf.h>
#include <linux/regset.h>
#include <linux/seccomp.h>
-#include <linux/compat.h>
#include <trace/syscall.h>
#include <asm/guarded_storage.h>
#include <asm/access-regs.h>
@@ -38,10 +37,6 @@
#include "entry.h"
-#ifdef CONFIG_COMPAT
-#include "compat_ptrace.h"
-#endif
-
void update_cr_regs(struct task_struct *task)
{
struct pt_regs *regs = task_pt_regs(task);
@@ -507,308 +502,6 @@ long arch_ptrace(struct task_struct *child, long request,
}
}
-#ifdef CONFIG_COMPAT
-/*
- * Now the fun part starts... a 31 bit program running in the
- * 31 bit emulation tracing another program. PTRACE_PEEKTEXT,
- * PTRACE_PEEKDATA, PTRACE_POKETEXT and PTRACE_POKEDATA are easy
- * to handle, the difference to the 64 bit versions of the requests
- * is that the access is done in multiples of 4 byte instead of
- * 8 bytes (sizeof(unsigned long) on 31/64 bit).
- * The ugly part are PTRACE_PEEKUSR, PTRACE_PEEKUSR_AREA,
- * PTRACE_POKEUSR and PTRACE_POKEUSR_AREA. If the traced program
- * is a 31 bit program too, the content of struct user can be
- * emulated. A 31 bit program peeking into the struct user of
- * a 64 bit program is a no-no.
- */
-
-/*
- * Same as peek_user_per but for a 31 bit program.
- */
-static inline __u32 __peek_user_per_compat(struct task_struct *child,
- addr_t addr)
-{
- if (addr == offsetof(struct compat_per_struct_kernel, cr9))
- /* Control bits of the active per set. */
- return (__u32) test_thread_flag(TIF_SINGLE_STEP) ?
- PER_EVENT_IFETCH : child->thread.per_user.control;
- else if (addr == offsetof(struct compat_per_struct_kernel, cr10))
- /* Start address of the active per set. */
- return (__u32) test_thread_flag(TIF_SINGLE_STEP) ?
- 0 : child->thread.per_user.start;
- else if (addr == offsetof(struct compat_per_struct_kernel, cr11))
- /* End address of the active per set. */
- return test_thread_flag(TIF_SINGLE_STEP) ?
- PSW32_ADDR_INSN : child->thread.per_user.end;
- else if (addr == offsetof(struct compat_per_struct_kernel, bits))
- /* Single-step bit. */
- return (__u32) test_thread_flag(TIF_SINGLE_STEP) ?
- 0x80000000 : 0;
- else if (addr == offsetof(struct compat_per_struct_kernel, starting_addr))
- /* Start address of the user specified per set. */
- return (__u32) child->thread.per_user.start;
- else if (addr == offsetof(struct compat_per_struct_kernel, ending_addr))
- /* End address of the user specified per set. */
- return (__u32) child->thread.per_user.end;
- else if (addr == offsetof(struct compat_per_struct_kernel, perc_atmid))
- /* PER code, ATMID and AI of the last PER trap */
- return (__u32) child->thread.per_event.cause << 16;
- else if (addr == offsetof(struct compat_per_struct_kernel, address))
- /* Address of the last PER trap */
- return (__u32) child->thread.per_event.address;
- else if (addr == offsetof(struct compat_per_struct_kernel, access_id))
- /* Access id of the last PER trap */
- return (__u32) child->thread.per_event.paid << 24;
- return 0;
-}
-
-/*
- * Same as peek_user but for a 31 bit program.
- */
-static u32 __peek_user_compat(struct task_struct *child, addr_t addr)
-{
- addr_t offset;
- __u32 tmp;
-
- if (addr < offsetof(struct compat_user, regs.acrs)) {
- struct pt_regs *regs = task_pt_regs(child);
- /*
- * psw and gprs are stored on the stack
- */
- if (addr == offsetof(struct compat_user, regs.psw.mask)) {
- /* Fake a 31 bit psw mask. */
- tmp = (__u32)(regs->psw.mask >> 32);
- tmp &= PSW32_MASK_USER | PSW32_MASK_RI;
- tmp |= PSW32_USER_BITS;
- } else if (addr == offsetof(struct compat_user, regs.psw.addr)) {
- /* Fake a 31 bit psw address. */
- tmp = (__u32) regs->psw.addr |
- (__u32)(regs->psw.mask & PSW_MASK_BA);
- } else {
- /* gpr 0-15 */
- tmp = *(__u32 *)((addr_t) ®s->psw + addr*2 + 4);
- }
- } else if (addr < offsetof(struct compat_user, regs.orig_gpr2)) {
- /*
- * access registers are stored in the thread structure
- */
- offset = addr - offsetof(struct compat_user, regs.acrs);
- tmp = *(__u32*)((addr_t) &child->thread.acrs + offset);
-
- } else if (addr == offsetof(struct compat_user, regs.orig_gpr2)) {
- /*
- * orig_gpr2 is stored on the kernel stack
- */
- tmp = *(__u32*)((addr_t) &task_pt_regs(child)->orig_gpr2 + 4);
-
- } else if (addr < offsetof(struct compat_user, regs.fp_regs)) {
- /*
- * prevent reads of padding hole between
- * orig_gpr2 and fp_regs on s390.
- */
- tmp = 0;
-
- } else if (addr == offsetof(struct compat_user, regs.fp_regs.fpc)) {
- /*
- * floating point control reg. is in the thread structure
- */
- tmp = child->thread.ufpu.fpc;
-
- } else if (addr < offsetof(struct compat_user, regs.fp_regs) + sizeof(s390_fp_regs)) {
- /*
- * floating point regs. are in the child->thread.ufpu.vxrs array
- */
- offset = addr - offsetof(struct compat_user, regs.fp_regs.fprs);
- tmp = *(__u32 *)((addr_t)child->thread.ufpu.vxrs + 2 * offset);
- } else if (addr < offsetof(struct compat_user, regs.per_info) + sizeof(struct compat_per_struct_kernel)) {
- /*
- * Handle access to the per_info structure.
- */
- addr -= offsetof(struct compat_user, regs.per_info);
- tmp = __peek_user_per_compat(child, addr);
-
- } else
- tmp = 0;
-
- return tmp;
-}
-
-static int peek_user_compat(struct task_struct *child,
- addr_t addr, addr_t data)
-{
- __u32 tmp;
-
- if (!is_compat_task() || (addr & 3) || addr > sizeof(struct user) - 3)
- return -EIO;
-
- tmp = __peek_user_compat(child, addr);
- return put_user(tmp, (__u32 __user *) data);
-}
-
-/*
- * Same as poke_user_per but for a 31 bit program.
- */
-static inline void __poke_user_per_compat(struct task_struct *child,
- addr_t addr, __u32 data)
-{
- if (addr == offsetof(struct compat_per_struct_kernel, cr9))
- /* PER event mask of the user specified per set. */
- child->thread.per_user.control =
- data & (PER_EVENT_MASK | PER_CONTROL_MASK);
- else if (addr == offsetof(struct compat_per_struct_kernel, starting_addr))
- /* Starting address of the user specified per set. */
- child->thread.per_user.start = data;
- else if (addr == offsetof(struct compat_per_struct_kernel, ending_addr))
- /* Ending address of the user specified per set. */
- child->thread.per_user.end = data;
-}
-
-/*
- * Same as poke_user but for a 31 bit program.
- */
-static int __poke_user_compat(struct task_struct *child,
- addr_t addr, addr_t data)
-{
- __u32 tmp = (__u32) data;
- addr_t offset;
-
- if (addr < offsetof(struct compat_user, regs.acrs)) {
- struct pt_regs *regs = task_pt_regs(child);
- /*
- * psw, gprs, acrs and orig_gpr2 are stored on the stack
- */
- if (addr == offsetof(struct compat_user, regs.psw.mask)) {
- __u32 mask = PSW32_MASK_USER;
-
- mask |= is_ri_task(child) ? PSW32_MASK_RI : 0;
- /* Build a 64 bit psw mask from 31 bit mask. */
- if ((tmp ^ PSW32_USER_BITS) & ~mask)
- /* Invalid psw mask. */
- return -EINVAL;
- if ((data & PSW32_MASK_ASC) == PSW32_ASC_HOME)
- /* Invalid address-space-control bits */
- return -EINVAL;
- regs->psw.mask = (regs->psw.mask & ~PSW_MASK_USER) |
- (regs->psw.mask & PSW_MASK_BA) |
- (__u64)(tmp & mask) << 32;
- } else if (addr == offsetof(struct compat_user, regs.psw.addr)) {
- /* Build a 64 bit psw address from 31 bit address. */
- regs->psw.addr = (__u64) tmp & PSW32_ADDR_INSN;
- /* Transfer 31 bit amode bit to psw mask. */
- regs->psw.mask = (regs->psw.mask & ~PSW_MASK_BA) |
- (__u64)(tmp & PSW32_ADDR_AMODE);
- } else {
- if (test_pt_regs_flag(regs, PIF_SYSCALL) &&
- addr == offsetof(struct compat_user, regs.gprs[2])) {
- struct pt_regs *regs = task_pt_regs(child);
-
- regs->int_code = 0x20000 | (data & 0xffff);
- }
- /* gpr 0-15 */
- *(__u32*)((addr_t) ®s->psw + addr*2 + 4) = tmp;
- }
- } else if (addr < offsetof(struct compat_user, regs.orig_gpr2)) {
- /*
- * access registers are stored in the thread structure
- */
- offset = addr - offsetof(struct compat_user, regs.acrs);
- *(__u32*)((addr_t) &child->thread.acrs + offset) = tmp;
-
- } else if (addr == offsetof(struct compat_user, regs.orig_gpr2)) {
- /*
- * orig_gpr2 is stored on the kernel stack
- */
- *(__u32*)((addr_t) &task_pt_regs(child)->orig_gpr2 + 4) = tmp;
-
- } else if (addr < offsetof(struct compat_user, regs.fp_regs)) {
- /*
- * prevent writess of padding hole between
- * orig_gpr2 and fp_regs on s390.
- */
- return 0;
-
- } else if (addr == offsetof(struct compat_user, regs.fp_regs.fpc)) {
- /*
- * floating point control reg. is in the thread structure
- */
- child->thread.ufpu.fpc = data;
-
- } else if (addr < offsetof(struct compat_user, regs.fp_regs) + sizeof(s390_fp_regs)) {
- /*
- * floating point regs. are in the child->thread.ufpu.vxrs array
- */
- offset = addr - offsetof(struct compat_user, regs.fp_regs.fprs);
- *(__u32 *)((addr_t)child->thread.ufpu.vxrs + 2 * offset) = tmp;
- } else if (addr < offsetof(struct compat_user, regs.per_info) + sizeof(struct compat_per_struct_kernel)) {
- /*
- * Handle access to the per_info structure.
- */
- addr -= offsetof(struct compat_user, regs.per_info);
- __poke_user_per_compat(child, addr, data);
- }
-
- return 0;
-}
-
-static int poke_user_compat(struct task_struct *child,
- addr_t addr, addr_t data)
-{
- if (!is_compat_task() || (addr & 3) ||
- addr > sizeof(struct compat_user) - 3)
- return -EIO;
-
- return __poke_user_compat(child, addr, data);
-}
-
-long compat_arch_ptrace(struct task_struct *child, compat_long_t request,
- compat_ulong_t caddr, compat_ulong_t cdata)
-{
- unsigned long addr = caddr;
- unsigned long data = cdata;
- compat_ptrace_area parea;
- int copied, ret;
-
- switch (request) {
- case PTRACE_PEEKUSR:
- /* read the word at location addr in the USER area. */
- return peek_user_compat(child, addr, data);
-
- case PTRACE_POKEUSR:
- /* write the word at location addr in the USER area */
- return poke_user_compat(child, addr, data);
-
- case PTRACE_PEEKUSR_AREA:
- case PTRACE_POKEUSR_AREA:
- if (copy_from_user(&parea, (void __force __user *) addr,
- sizeof(parea)))
- return -EFAULT;
- addr = parea.kernel_addr;
- data = parea.process_addr;
- copied = 0;
- while (copied < parea.len) {
- if (request == PTRACE_PEEKUSR_AREA)
- ret = peek_user_compat(child, addr, data);
- else {
- __u32 utmp;
- if (get_user(utmp,
- (__u32 __force __user *) data))
- return -EFAULT;
- ret = poke_user_compat(child, addr, utmp);
- }
- if (ret)
- return ret;
- addr += sizeof(unsigned int);
- data += sizeof(unsigned int);
- copied += sizeof(unsigned int);
- }
- return 0;
- case PTRACE_GET_LAST_BREAK:
- return put_user(child->thread.last_break, (unsigned int __user *)data);
- }
- return compat_ptrace_request(child, request, addr, data);
-}
-#endif
-
/*
* user_regset definitions.
*/
@@ -1297,225 +990,8 @@ static const struct user_regset_view user_s390_view = {
.n = ARRAY_SIZE(s390_regsets)
};
-#ifdef CONFIG_COMPAT
-static int s390_compat_regs_get(struct task_struct *target,
- const struct user_regset *regset,
- struct membuf to)
-{
- unsigned n;
-
- if (target == current)
- save_access_regs(target->thread.acrs);
-
- for (n = 0; n < sizeof(s390_compat_regs); n += sizeof(compat_ulong_t))
- membuf_store(&to, __peek_user_compat(target, n));
- return 0;
-}
-
-static int s390_compat_regs_set(struct task_struct *target,
- const struct user_regset *regset,
- unsigned int pos, unsigned int count,
- const void *kbuf, const void __user *ubuf)
-{
- int rc = 0;
-
- if (target == current)
- save_access_regs(target->thread.acrs);
-
- if (kbuf) {
- const compat_ulong_t *k = kbuf;
- while (count > 0 && !rc) {
- rc = __poke_user_compat(target, pos, *k++);
- count -= sizeof(*k);
- pos += sizeof(*k);
- }
- } else {
- const compat_ulong_t __user *u = ubuf;
- while (count > 0 && !rc) {
- compat_ulong_t word;
- rc = __get_user(word, u++);
- if (rc)
- break;
- rc = __poke_user_compat(target, pos, word);
- count -= sizeof(*u);
- pos += sizeof(*u);
- }
- }
-
- if (rc == 0 && target == current)
- restore_access_regs(target->thread.acrs);
-
- return rc;
-}
-
-static int s390_compat_regs_high_get(struct task_struct *target,
- const struct user_regset *regset,
- struct membuf to)
-{
- compat_ulong_t *gprs_high;
- int i;
-
- gprs_high = (compat_ulong_t *)task_pt_regs(target)->gprs;
- for (i = 0; i < NUM_GPRS; i++, gprs_high += 2)
- membuf_store(&to, *gprs_high);
- return 0;
-}
-
-static int s390_compat_regs_high_set(struct task_struct *target,
- const struct user_regset *regset,
- unsigned int pos, unsigned int count,
- const void *kbuf, const void __user *ubuf)
-{
- compat_ulong_t *gprs_high;
- int rc = 0;
-
- gprs_high = (compat_ulong_t *)
- &task_pt_regs(target)->gprs[pos / sizeof(compat_ulong_t)];
- if (kbuf) {
- const compat_ulong_t *k = kbuf;
- while (count > 0) {
- *gprs_high = *k++;
- *gprs_high += 2;
- count -= sizeof(*k);
- }
- } else {
- const compat_ulong_t __user *u = ubuf;
- while (count > 0 && !rc) {
- unsigned long word;
- rc = __get_user(word, u++);
- if (rc)
- break;
- *gprs_high = word;
- *gprs_high += 2;
- count -= sizeof(*u);
- }
- }
-
- return rc;
-}
-
-static int s390_compat_last_break_get(struct task_struct *target,
- const struct user_regset *regset,
- struct membuf to)
-{
- compat_ulong_t last_break = target->thread.last_break;
-
- return membuf_store(&to, (unsigned long)last_break);
-}
-
-static int s390_compat_last_break_set(struct task_struct *target,
- const struct user_regset *regset,
- unsigned int pos, unsigned int count,
- const void *kbuf, const void __user *ubuf)
-{
- return 0;
-}
-
-static const struct user_regset s390_compat_regsets[] = {
- {
- USER_REGSET_NOTE_TYPE(PRSTATUS),
- .n = sizeof(s390_compat_regs) / sizeof(compat_long_t),
- .size = sizeof(compat_long_t),
- .align = sizeof(compat_long_t),
- .regset_get = s390_compat_regs_get,
- .set = s390_compat_regs_set,
- },
- {
- USER_REGSET_NOTE_TYPE(PRFPREG),
- .n = sizeof(s390_fp_regs) / sizeof(compat_long_t),
- .size = sizeof(compat_long_t),
- .align = sizeof(compat_long_t),
- .regset_get = s390_fpregs_get,
- .set = s390_fpregs_set,
- },
- {
- USER_REGSET_NOTE_TYPE(S390_SYSTEM_CALL),
- .n = 1,
- .size = sizeof(compat_uint_t),
- .align = sizeof(compat_uint_t),
- .regset_get = s390_system_call_get,
- .set = s390_system_call_set,
- },
- {
- USER_REGSET_NOTE_TYPE(S390_LAST_BREAK),
- .n = 1,
- .size = sizeof(long),
- .align = sizeof(long),
- .regset_get = s390_compat_last_break_get,
- .set = s390_compat_last_break_set,
- },
- {
- USER_REGSET_NOTE_TYPE(S390_TDB),
- .n = 1,
- .size = 256,
- .align = 1,
- .regset_get = s390_tdb_get,
- .set = s390_tdb_set,
- },
- {
- USER_REGSET_NOTE_TYPE(S390_VXRS_LOW),
- .n = __NUM_VXRS_LOW,
- .size = sizeof(__u64),
- .align = sizeof(__u64),
- .regset_get = s390_vxrs_low_get,
- .set = s390_vxrs_low_set,
- },
- {
- USER_REGSET_NOTE_TYPE(S390_VXRS_HIGH),
- .n = __NUM_VXRS_HIGH,
- .size = sizeof(__vector128),
- .align = sizeof(__vector128),
- .regset_get = s390_vxrs_high_get,
- .set = s390_vxrs_high_set,
- },
- {
- USER_REGSET_NOTE_TYPE(S390_HIGH_GPRS),
- .n = sizeof(s390_compat_regs_high) / sizeof(compat_long_t),
- .size = sizeof(compat_long_t),
- .align = sizeof(compat_long_t),
- .regset_get = s390_compat_regs_high_get,
- .set = s390_compat_regs_high_set,
- },
- {
- USER_REGSET_NOTE_TYPE(S390_GS_CB),
- .n = sizeof(struct gs_cb) / sizeof(__u64),
- .size = sizeof(__u64),
- .align = sizeof(__u64),
- .regset_get = s390_gs_cb_get,
- .set = s390_gs_cb_set,
- },
- {
- USER_REGSET_NOTE_TYPE(S390_GS_BC),
- .n = sizeof(struct gs_cb) / sizeof(__u64),
- .size = sizeof(__u64),
- .align = sizeof(__u64),
- .regset_get = s390_gs_bc_get,
- .set = s390_gs_bc_set,
- },
- {
- USER_REGSET_NOTE_TYPE(S390_RI_CB),
- .n = sizeof(struct runtime_instr_cb) / sizeof(__u64),
- .size = sizeof(__u64),
- .align = sizeof(__u64),
- .regset_get = s390_runtime_instr_get,
- .set = s390_runtime_instr_set,
- },
-};
-
-static const struct user_regset_view user_s390_compat_view = {
- .name = "s390",
- .e_machine = EM_S390,
- .regsets = s390_compat_regsets,
- .n = ARRAY_SIZE(s390_compat_regsets)
-};
-#endif
-
const struct user_regset_view *task_user_regset_view(struct task_struct *task)
{
-#ifdef CONFIG_COMPAT
- if (test_tsk_thread_flag(task, TIF_31BIT))
- return &user_s390_compat_view;
-#endif
return &user_s390_view;
}
diff --git a/arch/s390/kernel/setup.c b/arch/s390/kernel/setup.c
index 892fce2b75497..3c50246dc8c5d 100644
--- a/arch/s390/kernel/setup.c
+++ b/arch/s390/kernel/setup.c
@@ -47,7 +47,6 @@
#include <linux/kexec.h>
#include <linux/crash_dump.h>
#include <linux/memory.h>
-#include <linux/compat.h>
#include <linux/start_kernel.h>
#include <linux/hugetlb.h>
#include <linux/kmemleak.h>
diff --git a/arch/s390/kernel/signal.c b/arch/s390/kernel/signal.c
index e48013cd832c1..e7775d121fa14 100644
--- a/arch/s390/kernel/signal.c
+++ b/arch/s390/kernel/signal.c
@@ -27,7 +27,6 @@
#include <linux/personality.h>
#include <linux/binfmts.h>
#include <linux/syscalls.h>
-#include <linux/compat.h>
#include <asm/ucontext.h>
#include <linux/uaccess.h>
#include <asm/vdso-symbols.h>
@@ -290,12 +289,6 @@ static int setup_frame(int sig, struct k_sigaction *ka,
unsigned long restorer;
size_t frame_size;
- /*
- * gprs_high are only present for a 31-bit task running on
- * a 64-bit kernel (see compat_signal.c) but the space for
- * gprs_high need to be allocated if vector registers are
- * included in the signal frame on a 31-bit system.
- */
frame_size = sizeof(*frame) - sizeof(frame->sregs_ext);
if (cpu_has_vx())
frame_size += sizeof(frame->sregs_ext);
@@ -367,12 +360,6 @@ static int setup_rt_frame(struct ksignal *ksig, sigset_t *set,
size_t frame_size;
frame_size = sizeof(struct rt_sigframe) - sizeof(_sigregs_ext);
- /*
- * gprs_high are only present for a 31-bit task running on
- * a 64-bit kernel (see compat_signal.c) but the space for
- * gprs_high need to be allocated if vector registers are
- * included in the signal frame on a 31-bit system.
- */
uc_flags = 0;
if (cpu_has_vx()) {
frame_size += sizeof(_sigregs_ext);
@@ -490,10 +477,7 @@ void arch_do_signal_or_restart(struct pt_regs *regs)
clear_pt_regs_flag(regs, PIF_SYSCALL);
rseq_signal_deliver(&ksig, regs);
- if (is_compat_task())
- handle_signal32(&ksig, oldset, regs);
- else
- handle_signal(&ksig, oldset, regs);
+ handle_signal(&ksig, oldset, regs);
return;
}
@@ -506,10 +490,7 @@ void arch_do_signal_or_restart(struct pt_regs *regs)
/* Restart with sys_restart_syscall */
regs->gprs[2] = regs->orig_gpr2;
current->restart_block.arch_data = regs->psw.addr;
- if (is_compat_task())
- regs->psw.addr = VDSO32_SYMBOL(current, restart_syscall);
- else
- regs->psw.addr = VDSO64_SYMBOL(current, restart_syscall);
+ regs->psw.addr = VDSO64_SYMBOL(current, restart_syscall);
if (test_thread_flag(TIF_SINGLE_STEP))
clear_thread_flag(TIF_PER_TRAP);
break;
diff --git a/arch/s390/kernel/stacktrace.c b/arch/s390/kernel/stacktrace.c
index b153a395f46d2..3aae7f70e6ab1 100644
--- a/arch/s390/kernel/stacktrace.c
+++ b/arch/s390/kernel/stacktrace.c
@@ -8,7 +8,6 @@
#include <linux/perf_event.h>
#include <linux/stacktrace.h>
#include <linux/uaccess.h>
-#include <linux/compat.h>
#include <asm/asm-offsets.h>
#include <asm/stacktrace.h>
#include <asm/unwind.h>
@@ -107,8 +106,6 @@ void arch_stack_walk_user_common(stack_trace_consume_fn consume_entry, void *coo
unsigned long ip, sp;
bool first = true;
- if (is_compat_task())
- return;
if (!current->mm)
return;
ip = instruction_pointer(regs);
diff --git a/arch/s390/kernel/uprobes.c b/arch/s390/kernel/uprobes.c
index 5b0633ea8d93d..baa462fae6225 100644
--- a/arch/s390/kernel/uprobes.c
+++ b/arch/s390/kernel/uprobes.c
@@ -8,7 +8,6 @@
#include <linux/uaccess.h>
#include <linux/uprobes.h>
-#include <linux/compat.h>
#include <linux/kdebug.h>
#include <linux/sched/task_stack.h>
@@ -29,7 +28,7 @@ int arch_uprobe_pre_xol(struct arch_uprobe *auprobe, struct pt_regs *regs)
{
if (psw_bits(regs->psw).eaba == PSW_BITS_AMODE_24BIT)
return -EINVAL;
- if (!is_compat_task() && psw_bits(regs->psw).eaba == PSW_BITS_AMODE_31BIT)
+ if (psw_bits(regs->psw).eaba == PSW_BITS_AMODE_31BIT)
return -EINVAL;
clear_thread_flag(TIF_PER_TRAP);
auprobe->saved_per = psw_bits(regs->psw).per;
@@ -373,8 +372,7 @@ static void handle_insn_ril(struct arch_uprobe *auprobe, struct pt_regs *regs)
bool arch_uprobe_skip_sstep(struct arch_uprobe *auprobe, struct pt_regs *regs)
{
if ((psw_bits(regs->psw).eaba == PSW_BITS_AMODE_24BIT) ||
- ((psw_bits(regs->psw).eaba == PSW_BITS_AMODE_31BIT) &&
- !is_compat_task())) {
+ (psw_bits(regs->psw).eaba == PSW_BITS_AMODE_31BIT)) {
regs->psw.addr = __rewind_psw(regs->psw, UPROBE_SWBP_INSN_SIZE);
do_report_trap(regs, SIGILL, ILL_ILLADR, NULL);
return true;
diff --git a/arch/s390/kernel/vdso.c b/arch/s390/kernel/vdso.c
index 430feb1a50136..83cc67cf21c83 100644
--- a/arch/s390/kernel/vdso.c
+++ b/arch/s390/kernel/vdso.c
@@ -7,7 +7,6 @@
*/
#include <linux/binfmts.h>
-#include <linux/compat.h>
#include <linux/elf.h>
#include <linux/errno.h>
#include <linux/init.h>
@@ -24,7 +23,6 @@
#include <asm/vdso.h>
extern char vdso64_start[], vdso64_end[];
-extern char vdso32_start[], vdso32_end[];
static int vdso_mremap(const struct vm_special_mapping *sm,
struct vm_area_struct *vma)
@@ -38,11 +36,6 @@ static struct vm_special_mapping vdso64_mapping = {
.mremap = vdso_mremap,
};
-static struct vm_special_mapping vdso32_mapping = {
- .name = "[vdso]",
- .mremap = vdso_mremap,
-};
-
int vdso_getcpu_init(void)
{
set_tod_programmable_field(smp_processor_id());
@@ -62,13 +55,8 @@ static int map_vdso(unsigned long addr, unsigned long vdso_mapping_len)
if (mmap_write_lock_killable(mm))
return -EINTR;
- if (is_compat_task()) {
- vdso_text_len = vdso32_end - vdso32_start;
- vdso_mapping = &vdso32_mapping;
- } else {
- vdso_text_len = vdso64_end - vdso64_start;
- vdso_mapping = &vdso64_mapping;
- }
+ vdso_text_len = vdso64_end - vdso64_start;
+ vdso_mapping = &vdso64_mapping;
vvar_start = get_unmapped_area(NULL, addr, vdso_mapping_len, 0, 0);
rc = vvar_start;
if (IS_ERR_VALUE(vvar_start))
@@ -122,13 +110,7 @@ static unsigned long vdso_addr(unsigned long start, unsigned long len)
unsigned long vdso_text_size(void)
{
- unsigned long size;
-
- if (is_compat_task())
- size = vdso32_end - vdso32_start;
- else
- size = vdso64_end - vdso64_start;
- return PAGE_ALIGN(size);
+ return PAGE_ALIGN(vdso64_end - vdso64_start);
}
unsigned long vdso_size(void)
@@ -180,8 +162,6 @@ static int __init vdso_init(void)
{
vdso_apply_alternatives();
vdso64_mapping.pages = vdso_setup_pages(vdso64_start, vdso64_end);
- if (IS_ENABLED(CONFIG_COMPAT))
- vdso32_mapping.pages = vdso_setup_pages(vdso32_start, vdso32_end);
return 0;
}
arch_initcall(vdso_init);
diff --git a/arch/s390/kernel/vdso32/.gitignore b/arch/s390/kernel/vdso32/.gitignore
deleted file mode 100644
index 5167384843b92..0000000000000
--- a/arch/s390/kernel/vdso32/.gitignore
+++ /dev/null
@@ -1,2 +0,0 @@
-# SPDX-License-Identifier: GPL-2.0-only
-vdso32.lds
diff --git a/arch/s390/kernel/vdso32/Makefile b/arch/s390/kernel/vdso32/Makefile
deleted file mode 100644
index 1e4ddd1a683ff..0000000000000
--- a/arch/s390/kernel/vdso32/Makefile
+++ /dev/null
@@ -1,64 +0,0 @@
-# SPDX-License-Identifier: GPL-2.0
-# List of files in the vdso
-
-# Include the generic Makefile to check the built vdso.
-include $(srctree)/lib/vdso/Makefile.include
-obj-vdso32 = vdso_user_wrapper-32.o note-32.o
-
-# Build rules
-
-targets := $(obj-vdso32) vdso32.so vdso32.so.dbg
-obj-vdso32 := $(addprefix $(obj)/, $(obj-vdso32))
-
-KBUILD_AFLAGS += -DBUILD_VDSO
-KBUILD_CFLAGS += -DBUILD_VDSO -DDISABLE_BRANCH_PROFILING
-
-KBUILD_AFLAGS_32 := $(filter-out -m64,$(KBUILD_AFLAGS))
-KBUILD_AFLAGS_32 += -m31 -s
-
-KBUILD_CFLAGS_32 := $(filter-out -m64,$(KBUILD_CFLAGS))
-KBUILD_CFLAGS_32 := $(filter-out -mpacked-stack,$(KBUILD_CFLAGS))
-KBUILD_CFLAGS_32 := $(filter-out -mno-pic-data-is-text-relative,$(KBUILD_CFLAGS_32))
-KBUILD_CFLAGS_32 := $(filter-out -fno-asynchronous-unwind-tables,$(KBUILD_CFLAGS_32))
-KBUILD_CFLAGS_32 += -m31 -fPIC -shared -fno-common -fno-builtin -fasynchronous-unwind-tables
-
-LDFLAGS_vdso32.so.dbg += -shared -soname=linux-vdso32.so.1 \
- --hash-style=both --build-id=sha1 -melf_s390 -T
-
-$(targets:%=$(obj)/%.dbg): KBUILD_CFLAGS = $(KBUILD_CFLAGS_32)
-$(targets:%=$(obj)/%.dbg): KBUILD_AFLAGS = $(KBUILD_AFLAGS_32)
-
-obj-y += vdso32_wrapper.o
-targets += vdso32.lds
-CPPFLAGS_vdso32.lds += -P -C -U$(ARCH)
-
-# Force dependency (incbin is bad)
-$(obj)/vdso32_wrapper.o : $(obj)/vdso32.so
-
-quiet_cmd_vdso_and_check = VDSO $@
- cmd_vdso_and_check = $(cmd_ld); $(cmd_vdso_check)
-
-$(obj)/vdso32.so.dbg: $(obj)/vdso32.lds $(obj-vdso32) FORCE
- $(call if_changed,vdso_and_check)
-
-# strip rule for the .so file
-$(obj)/%.so: OBJCOPYFLAGS := -S
-$(obj)/%.so: $(obj)/%.so.dbg FORCE
- $(call if_changed,objcopy)
-
-$(obj-vdso32): %-32.o: %.S FORCE
- $(call if_changed_dep,vdso32as)
-
-# actual build commands
-quiet_cmd_vdso32as = VDSO32A $@
- cmd_vdso32as = $(CC) $(a_flags) -c -o $@ $<
-quiet_cmd_vdso32cc = VDSO32C $@
- cmd_vdso32cc = $(CC) $(c_flags) -c -o $@ $<
-
-# Generate VDSO offsets using helper script
-gen-vdsosym := $(src)/gen_vdso_offsets.sh
-quiet_cmd_vdsosym = VDSOSYM $@
- cmd_vdsosym = $(NM) $< | $(gen-vdsosym) | LC_ALL=C sort > $@
-
-include/generated/vdso32-offsets.h: $(obj)/vdso32.so.dbg FORCE
- $(call if_changed,vdsosym)
diff --git a/arch/s390/kernel/vdso32/gen_vdso_offsets.sh b/arch/s390/kernel/vdso32/gen_vdso_offsets.sh
deleted file mode 100755
index 9c4f951e227d6..0000000000000
--- a/arch/s390/kernel/vdso32/gen_vdso_offsets.sh
+++ /dev/null
@@ -1,15 +0,0 @@
-#!/bin/sh
-# SPDX-License-Identifier: GPL-2.0
-
-#
-# Match symbols in the DSO that look like VDSO_*; produce a header file
-# of constant offsets into the shared object.
-#
-# Doing this inside the Makefile will break the $(filter-out) function,
-# causing Kbuild to rebuild the vdso-offsets header file every time.
-#
-# Inspired by arm64 version.
-#
-
-LC_ALL=C
-sed -n 's/\([0-9a-f]*\) . __kernel_compat_\(.*\)/\#define vdso32_offset_\2\t0x\1/p'
diff --git a/arch/s390/kernel/vdso32/note.S b/arch/s390/kernel/vdso32/note.S
deleted file mode 100644
index db19d0680a0af..0000000000000
--- a/arch/s390/kernel/vdso32/note.S
+++ /dev/null
@@ -1,13 +0,0 @@
-/* SPDX-License-Identifier: GPL-2.0 */
-/*
- * This supplies .note.* sections to go into the PT_NOTE inside the vDSO text.
- * Here we can supply some information useful to userland.
- */
-
-#include <linux/uts.h>
-#include <linux/version.h>
-#include <linux/elfnote.h>
-
-ELFNOTE_START(Linux, 0, "a")
- .long LINUX_VERSION_CODE
-ELFNOTE_END
diff --git a/arch/s390/kernel/vdso32/vdso32.lds.S b/arch/s390/kernel/vdso32/vdso32.lds.S
deleted file mode 100644
index 9630d58c20806..0000000000000
--- a/arch/s390/kernel/vdso32/vdso32.lds.S
+++ /dev/null
@@ -1,140 +0,0 @@
-/* SPDX-License-Identifier: GPL-2.0 */
-/*
- * This is the infamous ld script for the 64 bits vdso
- * library
- */
-
-#include <asm/page.h>
-#include <asm/vdso.h>
-#include <vdso/datapage.h>
-
-OUTPUT_FORMAT("elf32-s390", "elf32-s390", "elf32-s390")
-OUTPUT_ARCH(s390:31-bit)
-
-SECTIONS
-{
- VDSO_VVAR_SYMS
-
- . = SIZEOF_HEADERS;
-
- .hash : { *(.hash) } :text
- .gnu.hash : { *(.gnu.hash) }
- .dynsym : { *(.dynsym) }
- .dynstr : { *(.dynstr) }
- .gnu.version : { *(.gnu.version) }
- .gnu.version_d : { *(.gnu.version_d) }
- .gnu.version_r : { *(.gnu.version_r) }
-
- .note : { *(.note.*) } :text :note
-
- . = ALIGN(16);
- .text : {
- *(.text .stub .text.* .gnu.linkonce.t.*)
- } :text
- PROVIDE(__etext = .);
- PROVIDE(_etext = .);
- PROVIDE(etext = .);
-
- /*
- * Other stuff is appended to the text segment:
- */
- .rodata : { *(.rodata .rodata.* .gnu.linkonce.r.*) }
- .rodata1 : { *(.rodata1) }
-
- .dynamic : { *(.dynamic) } :text :dynamic
-
- .eh_frame_hdr : { *(.eh_frame_hdr) } :text :eh_frame_hdr
- .eh_frame : { KEEP (*(.eh_frame)) } :text
- .gcc_except_table : { *(.gcc_except_table .gcc_except_table.*) }
-
- .rela.dyn ALIGN(8) : { *(.rela.dyn) }
- .got ALIGN(8) : { *(.got .toc) }
- .got.plt ALIGN(8) : { *(.got.plt) }
-
- _end = .;
- PROVIDE(end = .);
-
- /*
- * Stabs debugging sections are here too.
- */
- .stab 0 : { *(.stab) }
- .stabstr 0 : { *(.stabstr) }
- .stab.excl 0 : { *(.stab.excl) }
- .stab.exclstr 0 : { *(.stab.exclstr) }
- .stab.index 0 : { *(.stab.index) }
- .stab.indexstr 0 : { *(.stab.indexstr) }
- .comment 0 : { *(.comment) }
-
- /*
- * DWARF debug sections.
- * Symbols in the DWARF debugging sections are relative to the
- * beginning of the section so we begin them at 0.
- */
- /* DWARF 1 */
- .debug 0 : { *(.debug) }
- .line 0 : { *(.line) }
- /* GNU DWARF 1 extensions */
- .debug_srcinfo 0 : { *(.debug_srcinfo) }
- .debug_sfnames 0 : { *(.debug_sfnames) }
- /* DWARF 1.1 and DWARF 2 */
- .debug_aranges 0 : { *(.debug_aranges) }
- .debug_pubnames 0 : { *(.debug_pubnames) }
- /* DWARF 2 */
- .debug_info 0 : { *(.debug_info .gnu.linkonce.wi.*) }
- .debug_abbrev 0 : { *(.debug_abbrev) }
- .debug_line 0 : { *(.debug_line) }
- .debug_frame 0 : { *(.debug_frame) }
- .debug_str 0 : { *(.debug_str) }
- .debug_loc 0 : { *(.debug_loc) }
- .debug_macinfo 0 : { *(.debug_macinfo) }
- /* SGI/MIPS DWARF 2 extensions */
- .debug_weaknames 0 : { *(.debug_weaknames) }
- .debug_funcnames 0 : { *(.debug_funcnames) }
- .debug_typenames 0 : { *(.debug_typenames) }
- .debug_varnames 0 : { *(.debug_varnames) }
- /* DWARF 3 */
- .debug_pubtypes 0 : { *(.debug_pubtypes) }
- .debug_ranges 0 : { *(.debug_ranges) }
- .gnu.attributes 0 : { KEEP (*(.gnu.attributes)) }
-
- /DISCARD/ : {
- *(.note.GNU-stack)
- *(.branch_lt)
- *(.data .data.* .gnu.linkonce.d.* .sdata*)
- *(.bss .sbss .dynbss .dynsbss)
- }
-}
-
-/*
- * Very old versions of ld do not recognize this name token; use the constant.
- */
-#define PT_GNU_EH_FRAME 0x6474e550
-
-/*
- * We must supply the ELF program headers explicitly to get just one
- * PT_LOAD segment, and set the flags explicitly to make segments read-only.
- */
-PHDRS
-{
- text PT_LOAD FILEHDR PHDRS FLAGS(5); /* PF_R|PF_X */
- dynamic PT_DYNAMIC FLAGS(4); /* PF_R */
- note PT_NOTE FLAGS(4); /* PF_R */
- eh_frame_hdr PT_GNU_EH_FRAME;
-}
-
-/*
- * This controls what symbols we export from the DSO.
- */
-VERSION
-{
- VDSO_VERSION_STRING {
- global:
- /*
- * Has to be there for the kernel to find
- */
- __kernel_compat_restart_syscall;
- __kernel_compat_rt_sigreturn;
- __kernel_compat_sigreturn;
- local: *;
- };
-}
diff --git a/arch/s390/kernel/vdso32/vdso32_wrapper.S b/arch/s390/kernel/vdso32/vdso32_wrapper.S
deleted file mode 100644
index de2fb930471af..0000000000000
--- a/arch/s390/kernel/vdso32/vdso32_wrapper.S
+++ /dev/null
@@ -1,15 +0,0 @@
-/* SPDX-License-Identifier: GPL-2.0 */
-#include <linux/init.h>
-#include <linux/linkage.h>
-#include <asm/page.h>
-
- __PAGE_ALIGNED_DATA
-
- .globl vdso32_start, vdso32_end
- .balign PAGE_SIZE
-vdso32_start:
- .incbin "arch/s390/kernel/vdso32/vdso32.so"
- .balign PAGE_SIZE
-vdso32_end:
-
- .previous
diff --git a/arch/s390/kernel/vdso32/vdso_user_wrapper.S b/arch/s390/kernel/vdso32/vdso_user_wrapper.S
deleted file mode 100644
index 2e645003fdafc..0000000000000
--- a/arch/s390/kernel/vdso32/vdso_user_wrapper.S
+++ /dev/null
@@ -1,22 +0,0 @@
-/* SPDX-License-Identifier: GPL-2.0 */
-
-#include <linux/linkage.h>
-#include <asm/unistd.h>
-#include <asm/dwarf.h>
-
-.macro vdso_syscall func,syscall
- .globl __kernel_compat_\func
- .type __kernel_compat_\func,@function
- __ALIGN
-__kernel_compat_\func:
- CFI_STARTPROC
- svc \syscall
- /* Make sure we notice when a syscall returns, which shouldn't happen */
- .word 0
- CFI_ENDPROC
- .size __kernel_compat_\func,.-__kernel_compat_\func
-.endm
-
-vdso_syscall restart_syscall,__NR_restart_syscall
-vdso_syscall sigreturn,__NR_sigreturn
-vdso_syscall rt_sigreturn,__NR_rt_sigreturn
diff --git a/arch/s390/mm/fault.c b/arch/s390/mm/fault.c
index 069f72703a915..96799582919f4 100644
--- a/arch/s390/mm/fault.c
+++ b/arch/s390/mm/fault.c
@@ -23,7 +23,6 @@
#include <linux/ptrace.h>
#include <linux/mman.h>
#include <linux/mm.h>
-#include <linux/compat.h>
#include <linux/smp.h>
#include <linux/kdebug.h>
#include <linux/init.h>
diff --git a/arch/s390/mm/mmap.c b/arch/s390/mm/mmap.c
index 53c5ba2c963e1..ef7bfc87758c8 100644
--- a/arch/s390/mm/mmap.c
+++ b/arch/s390/mm/mmap.c
@@ -15,7 +15,6 @@
#include <linux/sched/signal.h>
#include <linux/sched/mm.h>
#include <linux/random.h>
-#include <linux/compat.h>
#include <linux/security.h>
#include <linux/hugetlb.h>
#include <asm/elf.h>
diff --git a/arch/s390/pci/pci_clp.c b/arch/s390/pci/pci_clp.c
index 241f7251c8730..02b73d4b6c7e8 100644
--- a/arch/s390/pci/pci_clp.c
+++ b/arch/s390/pci/pci_clp.c
@@ -9,7 +9,6 @@
#define KMSG_COMPONENT "zpci"
#define pr_fmt(fmt) KMSG_COMPONENT ": " fmt
-#include <linux/compat.h>
#include <linux/kernel.h>
#include <linux/miscdevice.h>
#include <linux/slab.h>
@@ -651,7 +650,7 @@ static long clp_misc_ioctl(struct file *filp, unsigned int cmd,
if (cmd != CLP_SYNC)
return -EINVAL;
- argp = is_compat_task() ? compat_ptr(arg) : (void __user *) arg;
+ argp = (void __user *)arg;
if (copy_from_user(&req, argp, sizeof(req)))
return -EFAULT;
if (req.r != 0)
@@ -669,7 +668,6 @@ static const struct file_operations clp_misc_fops = {
.open = nonseekable_open,
.release = clp_misc_release,
.unlocked_ioctl = clp_misc_ioctl,
- .compat_ioctl = clp_misc_ioctl,
};
static struct miscdevice clp_misc_device = {
diff --git a/drivers/s390/block/dasd.c b/drivers/s390/block/dasd.c
index e7845c8ccc9ff..b2ac84c96c850 100644
--- a/drivers/s390/block/dasd.c
+++ b/drivers/s390/block/dasd.c
@@ -3352,7 +3352,6 @@ dasd_device_operations = {
.open = dasd_open,
.release = dasd_release,
.ioctl = dasd_ioctl,
- .compat_ioctl = dasd_ioctl,
.getgeo = dasd_getgeo,
.set_read_only = dasd_set_read_only,
};
diff --git a/drivers/s390/block/dasd_eckd.c b/drivers/s390/block/dasd_eckd.c
index 8947fbd2797ab..566f09b1a61fa 100644
--- a/drivers/s390/block/dasd_eckd.c
+++ b/drivers/s390/block/dasd_eckd.c
@@ -16,7 +16,6 @@
#include <linux/hdreg.h> /* HDIO_GETGEO */
#include <linux/bio.h>
#include <linux/module.h>
-#include <linux/compat.h>
#include <linux/init.h>
#include <linux/seq_file.h>
#include <linux/uaccess.h>
@@ -5422,16 +5421,6 @@ static int dasd_symm_io(struct dasd_device *device, void __user *argp)
rc = -EFAULT;
if (copy_from_user(&usrparm, argp, sizeof(usrparm)))
goto out;
- if (is_compat_task()) {
- /* Make sure pointers are sane even on 31 bit. */
- rc = -EINVAL;
- if ((usrparm.psf_data >> 32) != 0)
- goto out;
- if ((usrparm.rssd_result >> 32) != 0)
- goto out;
- usrparm.psf_data &= 0x7fffffffULL;
- usrparm.rssd_result &= 0x7fffffffULL;
- }
/* at least 2 bytes are accessed and should be allocated */
if (usrparm.psf_data_len < 2) {
DBF_DEV_EVENT(DBF_WARNING, device,
diff --git a/drivers/s390/block/dasd_ioctl.c b/drivers/s390/block/dasd_ioctl.c
index a9edc0468a314..b1d962ef7abcc 100644
--- a/drivers/s390/block/dasd_ioctl.c
+++ b/drivers/s390/block/dasd_ioctl.c
@@ -11,7 +11,6 @@
*/
#include <linux/interrupt.h>
-#include <linux/compat.h>
#include <linux/export.h>
#include <linux/major.h>
#include <linux/fs.h>
@@ -616,10 +615,7 @@ int dasd_ioctl(struct block_device *bdev, blk_mode_t mode,
void __user *argp;
int rc;
- if (is_compat_task())
- argp = compat_ptr(arg);
- else
- argp = (void __user *)arg;
+ argp = (void __user *)arg;
if ((_IOC_DIR(cmd) != _IOC_NONE) && !arg)
return -EINVAL;
diff --git a/drivers/s390/char/con3270.c b/drivers/s390/char/con3270.c
index a367f95c7c536..bf3333231ab86 100644
--- a/drivers/s390/char/con3270.c
+++ b/drivers/s390/char/con3270.c
@@ -21,7 +21,6 @@
#include <linux/reboot.h>
#include <linux/slab.h>
#include <linux/memblock.h>
-#include <linux/compat.h>
#include <asm/machine.h>
#include <asm/ccwdev.h>
@@ -1947,21 +1946,6 @@ static int tty3270_ioctl(struct tty_struct *tty, unsigned int cmd,
return kbd_ioctl(tp->kbd, cmd, arg);
}
-#ifdef CONFIG_COMPAT
-static long tty3270_compat_ioctl(struct tty_struct *tty,
- unsigned int cmd, unsigned long arg)
-{
- struct tty3270 *tp;
-
- tp = tty->driver_data;
- if (!tp)
- return -ENODEV;
- if (tty_io_error(tty))
- return -EIO;
- return kbd_ioctl(tp->kbd, cmd, (unsigned long)compat_ptr(arg));
-}
-#endif
-
static const struct tty_operations tty3270_ops = {
.install = tty3270_install,
.cleanup = tty3270_cleanup,
@@ -1976,9 +1960,6 @@ static const struct tty_operations tty3270_ops = {
.hangup = tty3270_hangup,
.wait_until_sent = tty3270_wait_until_sent,
.ioctl = tty3270_ioctl,
-#ifdef CONFIG_COMPAT
- .compat_ioctl = tty3270_compat_ioctl,
-#endif
.set_termios = tty3270_set_termios
};
diff --git a/drivers/s390/char/fs3270.c b/drivers/s390/char/fs3270.c
index cfe7efd5b5da9..73555dbe30d03 100644
--- a/drivers/s390/char/fs3270.c
+++ b/drivers/s390/char/fs3270.c
@@ -12,7 +12,6 @@
#include <linux/console.h>
#include <linux/init.h>
#include <linux/interrupt.h>
-#include <linux/compat.h>
#include <linux/sched/signal.h>
#include <linux/module.h>
#include <linux/list.h>
@@ -330,10 +329,7 @@ static long fs3270_ioctl(struct file *filp, unsigned int cmd, unsigned long arg)
fp = filp->private_data;
if (!fp)
return -ENODEV;
- if (is_compat_task())
- argp = compat_ptr(arg);
- else
- argp = (char __user *)arg;
+ argp = (char __user *)arg;
rc = 0;
mutex_lock(&fs3270_mutex);
switch (cmd) {
@@ -512,7 +508,6 @@ static const struct file_operations fs3270_fops = {
.read = fs3270_read, /* read */
.write = fs3270_write, /* write */
.unlocked_ioctl = fs3270_ioctl, /* ioctl */
- .compat_ioctl = fs3270_ioctl, /* ioctl */
.open = fs3270_open, /* open */
.release = fs3270_close, /* release */
};
diff --git a/drivers/s390/char/sclp_ctl.c b/drivers/s390/char/sclp_ctl.c
index dd6051602070b..e23a97359286b 100644
--- a/drivers/s390/char/sclp_ctl.c
+++ b/drivers/s390/char/sclp_ctl.c
@@ -7,7 +7,6 @@
* Author: Michael Holzheu <holzheu@linux.vnet.ibm.com>
*/
-#include <linux/compat.h>
#include <linux/uaccess.h>
#include <linux/miscdevice.h>
#include <linux/gfp.h>
@@ -43,10 +42,7 @@ static int sclp_ctl_cmdw_supported(unsigned int cmdw)
static void __user *u64_to_uptr(u64 value)
{
- if (is_compat_task())
- return compat_ptr(value);
- else
- return (void __user *)(unsigned long)value;
+ return (void __user *)(unsigned long)value;
}
/*
@@ -95,10 +91,7 @@ static long sclp_ctl_ioctl(struct file *filp, unsigned int cmd,
{
void __user *argp;
- if (is_compat_task())
- argp = compat_ptr(arg);
- else
- argp = (void __user *) arg;
+ argp = (void __user *)arg;
switch (cmd) {
case SCLP_CTL_SCCB:
return sclp_ctl_ioctl_sccb(argp);
@@ -114,7 +107,6 @@ static const struct file_operations sclp_ctl_fops = {
.owner = THIS_MODULE,
.open = nonseekable_open,
.unlocked_ioctl = sclp_ctl_ioctl,
- .compat_ioctl = sclp_ctl_ioctl,
};
/*
diff --git a/drivers/s390/char/tape_char.c b/drivers/s390/char/tape_char.c
index 89778d922d9f0..195e247a74f5b 100644
--- a/drivers/s390/char/tape_char.c
+++ b/drivers/s390/char/tape_char.c
@@ -17,7 +17,6 @@
#include <linux/types.h>
#include <linux/proc_fs.h>
#include <linux/mtio.h>
-#include <linux/compat.h>
#include <linux/uaccess.h>
@@ -37,9 +36,6 @@ static ssize_t tapechar_write(struct file *, const char __user *, size_t, loff_t
static int tapechar_open(struct inode *,struct file *);
static int tapechar_release(struct inode *,struct file *);
static long tapechar_ioctl(struct file *, unsigned int, unsigned long);
-#ifdef CONFIG_COMPAT
-static long tapechar_compat_ioctl(struct file *, unsigned int, unsigned long);
-#endif
static const struct file_operations tape_fops =
{
@@ -47,9 +43,6 @@ static const struct file_operations tape_fops =
.read = tapechar_read,
.write = tapechar_write,
.unlocked_ioctl = tapechar_ioctl,
-#ifdef CONFIG_COMPAT
- .compat_ioctl = tapechar_compat_ioctl,
-#endif
.open = tapechar_open,
.release = tapechar_release,
};
@@ -442,25 +435,6 @@ tapechar_ioctl(struct file *filp, unsigned int no, unsigned long data)
return rc;
}
-#ifdef CONFIG_COMPAT
-static long
-tapechar_compat_ioctl(struct file *filp, unsigned int no, unsigned long data)
-{
- struct tape_device *device = filp->private_data;
- long rc;
-
- if (no == MTIOCPOS32)
- no = MTIOCPOS;
- else if (no == MTIOCGET32)
- no = MTIOCGET;
-
- mutex_lock(&device->mutex);
- rc = __tapechar_ioctl(device, no, compat_ptr(data));
- mutex_unlock(&device->mutex);
- return rc;
-}
-#endif /* CONFIG_COMPAT */
-
/*
* Initialize character device frontend.
*/
diff --git a/drivers/s390/char/vmcp.c b/drivers/s390/char/vmcp.c
index 69899bb86b3ef..bde6c9e591668 100644
--- a/drivers/s390/char/vmcp.c
+++ b/drivers/s390/char/vmcp.c
@@ -14,7 +14,6 @@
#include <linux/fs.h>
#include <linux/init.h>
-#include <linux/compat.h>
#include <linux/kernel.h>
#include <linux/miscdevice.h>
#include <linux/slab.h>
@@ -204,10 +203,7 @@ static long vmcp_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
int __user *argp;
session = file->private_data;
- if (is_compat_task())
- argp = compat_ptr(arg);
- else
- argp = (int __user *)arg;
+ argp = (int __user *)arg;
if (mutex_lock_interruptible(&session->mutex))
return -ERESTARTSYS;
switch (cmd) {
@@ -241,7 +237,6 @@ static const struct file_operations vmcp_fops = {
.read = vmcp_read,
.write = vmcp_write,
.unlocked_ioctl = vmcp_ioctl,
- .compat_ioctl = vmcp_ioctl,
};
static struct miscdevice vmcp_dev = {
diff --git a/drivers/s390/cio/chsc_sch.c b/drivers/s390/cio/chsc_sch.c
index 9131ce3af1b8e..7a865b3ef88d4 100644
--- a/drivers/s390/cio/chsc_sch.c
+++ b/drivers/s390/cio/chsc_sch.c
@@ -9,7 +9,6 @@
*/
#include <linux/slab.h>
-#include <linux/compat.h>
#include <linux/device.h>
#include <linux/io.h>
#include <linux/module.h>
@@ -845,10 +844,7 @@ static long chsc_ioctl(struct file *filp, unsigned int cmd,
void __user *argp;
CHSC_MSG(2, "chsc_ioctl called, cmd=%x\n", cmd);
- if (is_compat_task())
- argp = compat_ptr(arg);
- else
- argp = (void __user *)arg;
+ argp = (void __user *)arg;
switch (cmd) {
case CHSC_START:
return chsc_ioctl_start(argp);
@@ -923,7 +919,6 @@ static const struct file_operations chsc_fops = {
.open = chsc_open,
.release = chsc_release,
.unlocked_ioctl = chsc_ioctl,
- .compat_ioctl = chsc_ioctl,
};
static struct miscdevice chsc_misc_device = {
diff --git a/drivers/s390/crypto/zcrypt_api.c b/drivers/s390/crypto/zcrypt_api.c
index a25b58e06f923..a7aa746c205b8 100644
--- a/drivers/s390/crypto/zcrypt_api.c
+++ b/drivers/s390/crypto/zcrypt_api.c
@@ -21,7 +21,6 @@
#include <linux/interrupt.h>
#include <linux/miscdevice.h>
#include <linux/fs.h>
-#include <linux/compat.h>
#include <linux/slab.h>
#include <linux/atomic.h>
#include <linux/uaccess.h>
@@ -1729,197 +1728,6 @@ static long zcrypt_unlocked_ioctl(struct file *filp, unsigned int cmd,
}
}
-#ifdef CONFIG_COMPAT
-/*
- * ioctl32 conversion routines
- */
-struct compat_ica_rsa_modexpo {
- compat_uptr_t inputdata;
- unsigned int inputdatalength;
- compat_uptr_t outputdata;
- unsigned int outputdatalength;
- compat_uptr_t b_key;
- compat_uptr_t n_modulus;
-};
-
-static long trans_modexpo32(struct ap_perms *perms, struct file *filp,
- unsigned int cmd, unsigned long arg)
-{
- struct compat_ica_rsa_modexpo __user *umex32 = compat_ptr(arg);
- struct compat_ica_rsa_modexpo mex32;
- struct ica_rsa_modexpo mex64;
- struct zcrypt_track tr;
- long rc;
-
- memset(&tr, 0, sizeof(tr));
- if (copy_from_user(&mex32, umex32, sizeof(mex32)))
- return -EFAULT;
- mex64.inputdata = compat_ptr(mex32.inputdata);
- mex64.inputdatalength = mex32.inputdatalength;
- mex64.outputdata = compat_ptr(mex32.outputdata);
- mex64.outputdatalength = mex32.outputdatalength;
- mex64.b_key = compat_ptr(mex32.b_key);
- mex64.n_modulus = compat_ptr(mex32.n_modulus);
- do {
- rc = zcrypt_rsa_modexpo(perms, &tr, &mex64);
- } while (rc == -EAGAIN && ++tr.again_counter < TRACK_AGAIN_MAX);
-
- /* on ENODEV failure: retry once again after a requested rescan */
- if (rc == -ENODEV && zcrypt_process_rescan())
- do {
- rc = zcrypt_rsa_modexpo(perms, &tr, &mex64);
- } while (rc == -EAGAIN && ++tr.again_counter < TRACK_AGAIN_MAX);
- if (rc == -EAGAIN && tr.again_counter >= TRACK_AGAIN_MAX)
- rc = -EIO;
- if (rc)
- return rc;
- return put_user(mex64.outputdatalength,
- &umex32->outputdatalength);
-}
-
-struct compat_ica_rsa_modexpo_crt {
- compat_uptr_t inputdata;
- unsigned int inputdatalength;
- compat_uptr_t outputdata;
- unsigned int outputdatalength;
- compat_uptr_t bp_key;
- compat_uptr_t bq_key;
- compat_uptr_t np_prime;
- compat_uptr_t nq_prime;
- compat_uptr_t u_mult_inv;
-};
-
-static long trans_modexpo_crt32(struct ap_perms *perms, struct file *filp,
- unsigned int cmd, unsigned long arg)
-{
- struct compat_ica_rsa_modexpo_crt __user *ucrt32 = compat_ptr(arg);
- struct compat_ica_rsa_modexpo_crt crt32;
- struct ica_rsa_modexpo_crt crt64;
- struct zcrypt_track tr;
- long rc;
-
- memset(&tr, 0, sizeof(tr));
- if (copy_from_user(&crt32, ucrt32, sizeof(crt32)))
- return -EFAULT;
- crt64.inputdata = compat_ptr(crt32.inputdata);
- crt64.inputdatalength = crt32.inputdatalength;
- crt64.outputdata = compat_ptr(crt32.outputdata);
- crt64.outputdatalength = crt32.outputdatalength;
- crt64.bp_key = compat_ptr(crt32.bp_key);
- crt64.bq_key = compat_ptr(crt32.bq_key);
- crt64.np_prime = compat_ptr(crt32.np_prime);
- crt64.nq_prime = compat_ptr(crt32.nq_prime);
- crt64.u_mult_inv = compat_ptr(crt32.u_mult_inv);
- do {
- rc = zcrypt_rsa_crt(perms, &tr, &crt64);
- } while (rc == -EAGAIN && ++tr.again_counter < TRACK_AGAIN_MAX);
-
- /* on ENODEV failure: retry once again after a requested rescan */
- if (rc == -ENODEV && zcrypt_process_rescan())
- do {
- rc = zcrypt_rsa_crt(perms, &tr, &crt64);
- } while (rc == -EAGAIN && ++tr.again_counter < TRACK_AGAIN_MAX);
- if (rc == -EAGAIN && tr.again_counter >= TRACK_AGAIN_MAX)
- rc = -EIO;
- if (rc)
- return rc;
- return put_user(crt64.outputdatalength,
- &ucrt32->outputdatalength);
-}
-
-struct compat_ica_xcrb {
- unsigned short agent_ID;
- unsigned int user_defined;
- unsigned short request_ID;
- unsigned int request_control_blk_length;
- unsigned char padding1[16 - sizeof(compat_uptr_t)];
- compat_uptr_t request_control_blk_addr;
- unsigned int request_data_length;
- char padding2[16 - sizeof(compat_uptr_t)];
- compat_uptr_t request_data_address;
- unsigned int reply_control_blk_length;
- char padding3[16 - sizeof(compat_uptr_t)];
- compat_uptr_t reply_control_blk_addr;
- unsigned int reply_data_length;
- char padding4[16 - sizeof(compat_uptr_t)];
- compat_uptr_t reply_data_addr;
- unsigned short priority_window;
- unsigned int status;
-} __packed;
-
-static long trans_xcrb32(struct ap_perms *perms, struct file *filp,
- unsigned int cmd, unsigned long arg)
-{
- struct compat_ica_xcrb __user *uxcrb32 = compat_ptr(arg);
- u32 xflags = ZCRYPT_XFLAG_USERSPACE;
- struct compat_ica_xcrb xcrb32;
- struct zcrypt_track tr;
- struct ica_xcRB xcrb64;
- long rc;
-
- memset(&tr, 0, sizeof(tr));
- if (copy_from_user(&xcrb32, uxcrb32, sizeof(xcrb32)))
- return -EFAULT;
- xcrb64.agent_ID = xcrb32.agent_ID;
- xcrb64.user_defined = xcrb32.user_defined;
- xcrb64.request_ID = xcrb32.request_ID;
- xcrb64.request_control_blk_length =
- xcrb32.request_control_blk_length;
- xcrb64.request_control_blk_addr =
- compat_ptr(xcrb32.request_control_blk_addr);
- xcrb64.request_data_length =
- xcrb32.request_data_length;
- xcrb64.request_data_address =
- compat_ptr(xcrb32.request_data_address);
- xcrb64.reply_control_blk_length =
- xcrb32.reply_control_blk_length;
- xcrb64.reply_control_blk_addr =
- compat_ptr(xcrb32.reply_control_blk_addr);
- xcrb64.reply_data_length = xcrb32.reply_data_length;
- xcrb64.reply_data_addr =
- compat_ptr(xcrb32.reply_data_addr);
- xcrb64.priority_window = xcrb32.priority_window;
- xcrb64.status = xcrb32.status;
- do {
- rc = _zcrypt_send_cprb(xflags, perms, &tr, &xcrb64);
- } while (rc == -EAGAIN && ++tr.again_counter < TRACK_AGAIN_MAX);
-
- /* on ENODEV failure: retry once again after a requested rescan */
- if (rc == -ENODEV && zcrypt_process_rescan())
- do {
- rc = _zcrypt_send_cprb(xflags, perms, &tr, &xcrb64);
- } while (rc == -EAGAIN && ++tr.again_counter < TRACK_AGAIN_MAX);
- if (rc == -EAGAIN && tr.again_counter >= TRACK_AGAIN_MAX)
- rc = -EIO;
- xcrb32.reply_control_blk_length = xcrb64.reply_control_blk_length;
- xcrb32.reply_data_length = xcrb64.reply_data_length;
- xcrb32.status = xcrb64.status;
- if (copy_to_user(uxcrb32, &xcrb32, sizeof(xcrb32)))
- return -EFAULT;
- return rc;
-}
-
-static long zcrypt_compat_ioctl(struct file *filp, unsigned int cmd,
- unsigned long arg)
-{
- int rc;
- struct ap_perms *perms =
- (struct ap_perms *)filp->private_data;
-
- rc = zcrypt_check_ioctl(perms, cmd);
- if (rc)
- return rc;
-
- if (cmd == ICARSAMODEXPO)
- return trans_modexpo32(perms, filp, cmd, arg);
- if (cmd == ICARSACRT)
- return trans_modexpo_crt32(perms, filp, cmd, arg);
- if (cmd == ZSECSENDCPRB)
- return trans_xcrb32(perms, filp, cmd, arg);
- return zcrypt_unlocked_ioctl(filp, cmd, arg);
-}
-#endif
-
/*
* Misc device file operations.
*/
@@ -1928,9 +1736,6 @@ static const struct file_operations zcrypt_fops = {
.read = zcrypt_read,
.write = zcrypt_write,
.unlocked_ioctl = zcrypt_unlocked_ioctl,
-#ifdef CONFIG_COMPAT
- .compat_ioctl = zcrypt_compat_ioctl,
-#endif
.open = zcrypt_open,
.release = zcrypt_release,
};
diff --git a/drivers/s390/crypto/zcrypt_card.c b/drivers/s390/crypto/zcrypt_card.c
index aa2c8ff2740ef..6dea702a5cac9 100644
--- a/drivers/s390/crypto/zcrypt_card.c
+++ b/drivers/s390/crypto/zcrypt_card.c
@@ -19,7 +19,6 @@
#include <linux/fs.h>
#include <linux/proc_fs.h>
#include <linux/seq_file.h>
-#include <linux/compat.h>
#include <linux/slab.h>
#include <linux/atomic.h>
#include <linux/uaccess.h>
diff --git a/drivers/s390/crypto/zcrypt_queue.c b/drivers/s390/crypto/zcrypt_queue.c
index 76a8678bdad65..a173d32eb6e82 100644
--- a/drivers/s390/crypto/zcrypt_queue.c
+++ b/drivers/s390/crypto/zcrypt_queue.c
@@ -19,7 +19,6 @@
#include <linux/fs.h>
#include <linux/proc_fs.h>
#include <linux/seq_file.h>
-#include <linux/compat.h>
#include <linux/slab.h>
#include <linux/atomic.h>
#include <linux/uaccess.h>
diff --git a/drivers/s390/net/qeth_core_main.c b/drivers/s390/net/qeth_core_main.c
index c524b4b0a328e..c6a120d54a715 100644
--- a/drivers/s390/net/qeth_core_main.c
+++ b/drivers/s390/net/qeth_core_main.c
@@ -10,7 +10,6 @@
#define KMSG_COMPONENT "qeth"
#define pr_fmt(fmt) KMSG_COMPONENT ": " fmt
-#include <linux/compat.h>
#include <linux/export.h>
#include <linux/module.h>
#include <linux/moduleparam.h>
@@ -4808,8 +4807,7 @@ static int qeth_query_oat_command(struct qeth_card *card, char __user *udata)
rc = qeth_send_ipa_cmd(card, iob, qeth_setadpparms_query_oat_cb, &priv);
if (!rc) {
- tmp = is_compat_task() ? compat_ptr(oat_data.ptr) :
- u64_to_user_ptr(oat_data.ptr);
+ tmp = u64_to_user_ptr(oat_data.ptr);
oat_data.response_len = priv.response_len;
if (copy_to_user(tmp, priv.buffer, priv.response_len) ||
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0642/1518] s390: Add stackprotector support
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (640 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0641/1518] s390: Remove compat support Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0643/1518] s390/vdso: Rename vdso64 to vdso Greg Kroah-Hartman
` (356 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sven Schnelle, Heiko Carstens,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Heiko Carstens <hca@linux.ibm.com>
[ Upstream commit f5730d44e05efb43a5cb64e5eb04e24994bbb50f ]
Stackprotector support was previously unavailable on s390 because by
default compilers generate code which is not suitable for the kernel:
the canary value is accessed via thread local storage, where the address
of thread local storage is within access registers 0 and 1.
Using those registers also for the kernel would come with a significant
performance impact and more complicated kernel entry/exit code, since
access registers contents would have to be exchanged on every kernel entry
and exit.
With the upcoming gcc 16 release new compiler options will become available
which allow to generate code suitable for the kernel. [1]
Compiler option -mstack-protector-guard=global instructs gcc to generate
stackprotector code that refers to a global stackprotector canary value via
symbol __stack_chk_guard. Access to this value is guaranteed to occur via
larl and lgrl instructions.
Furthermore, compiler option -mstack-protector-guard-record generates a
section containing all code addresses that reference the canary value.
To allow for per task canary values the instructions which load the address
of __stack_chk_guard are patched so they access a lowcore field instead: a
per task canary value is available within the task_struct of each task, and
is written to the per-cpu lowcore location on each context switch.
Also add sanity checks and debugging option to be consistent with other
kernel code patching mechanisms.
Full debugging output can be enabled with the following kernel command line
options:
debug_stackprotector
bootdebug
ignore_loglevel
earlyprintk
dyndbg="file stackprotector.c +p"
Example debug output:
stackprot: 0000021e402d4eda: c010005a9ae3 -> c01f00070240
where "<insn address>: <old insn> -> <new insn>".
[1] gcc commit 0cd1f03939d5 ("s390: Support global stack protector")
Reviewed-by: Sven Schnelle <svens@linux.ibm.com>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Stable-dep-of: dc161efb6df8 ("s390/vdso: Pass --eh-frame-hdr to the linker")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/s390/Kconfig | 4 +
arch/s390/Makefile | 4 +
arch/s390/boot/Makefile | 1 +
arch/s390/boot/boot.h | 4 +
arch/s390/boot/ipl_parm.c | 6 +
arch/s390/boot/stackprotector.c | 6 +
arch/s390/boot/startup.c | 8 +
arch/s390/include/asm/arch-stackprotector.h | 25 ++++
arch/s390/include/asm/lowcore.h | 3 +-
arch/s390/include/asm/stackprotector.h | 16 ++
arch/s390/kernel/Makefile | 2 +-
arch/s390/kernel/asm-offsets.c | 4 +
arch/s390/kernel/entry.S | 8 +-
arch/s390/kernel/module.c | 9 ++
arch/s390/kernel/smp.c | 3 +
arch/s390/kernel/stackprotector.c | 156 ++++++++++++++++++++
arch/s390/kernel/vdso64/Makefile | 1 +
arch/s390/kernel/vmlinux.lds.S | 13 ++
18 files changed, 269 insertions(+), 4 deletions(-)
create mode 100644 arch/s390/boot/stackprotector.c
create mode 100644 arch/s390/include/asm/arch-stackprotector.h
create mode 100644 arch/s390/include/asm/stackprotector.h
create mode 100644 arch/s390/kernel/stackprotector.c
diff --git a/arch/s390/Kconfig b/arch/s390/Kconfig
index 8a42762cc2b1b..97a522dcb2b25 100644
--- a/arch/s390/Kconfig
+++ b/arch/s390/Kconfig
@@ -69,6 +69,9 @@ config CC_HAS_ASM_AOR_FORMAT_FLAGS
Clang versions before 19.1.0 do not support A,
O, and R inline assembly format flags.
+config CC_HAS_STACKPROTECTOR_GLOBAL
+ def_bool $(cc-option, -mstack-protector-guard=global -mstack-protector-guard-record)
+
config S390
def_bool y
#
@@ -244,6 +247,7 @@ config S390
select HAVE_SAMPLE_FTRACE_DIRECT_MULTI
select HAVE_SETUP_PER_CPU_AREA
select HAVE_SOFTIRQ_ON_OWN_STACK
+ select HAVE_STACKPROTECTOR if CC_HAS_STACKPROTECTOR_GLOBAL
select HAVE_SYSCALL_TRACEPOINTS
select HAVE_VIRT_CPU_ACCOUNTING
select HAVE_VIRT_CPU_ACCOUNTING_IDLE
diff --git a/arch/s390/Makefile b/arch/s390/Makefile
index f41b8c5c4e560..a205c929e6630 100644
--- a/arch/s390/Makefile
+++ b/arch/s390/Makefile
@@ -89,6 +89,10 @@ ifdef CONFIG_EXPOLINE
aflags-y += -DCC_USING_EXPOLINE
endif
+ifeq ($(CONFIG_STACKPROTECTOR),y)
+ KBUILD_CFLAGS += -mstack-protector-guard=global -mstack-protector-guard-record
+endif
+
ifdef CONFIG_FUNCTION_TRACER
ifeq ($(call cc-option,-mfentry -mnop-mcount),)
# make use of hotpatch feature if the compiler supports it
diff --git a/arch/s390/boot/Makefile b/arch/s390/boot/Makefile
index 1768424a1824f..a1e719a79d38c 100644
--- a/arch/s390/boot/Makefile
+++ b/arch/s390/boot/Makefile
@@ -33,6 +33,7 @@ obj-$(CONFIG_RANDOMIZE_BASE) += kaslr.o
obj-y += $(if $(CONFIG_KERNEL_UNCOMPRESSED),,decompressor.o) info.o
obj-$(CONFIG_KERNEL_ZSTD) += clz_ctz.o
obj-$(CONFIG_KMSAN) += kmsan.o
+obj-$(CONFIG_STACKPROTECTOR) += stackprotector.o
obj-all := $(obj-y) piggy.o syms.o
targets := bzImage section_cmp.boot.data section_cmp.boot.preserved.data $(obj-y)
diff --git a/arch/s390/boot/boot.h b/arch/s390/boot/boot.h
index 37d5b097ede5f..61a205b489fb0 100644
--- a/arch/s390/boot/boot.h
+++ b/arch/s390/boot/boot.h
@@ -28,6 +28,10 @@ struct vmlinux_info {
unsigned long invalid_pg_dir_off;
unsigned long alt_instructions;
unsigned long alt_instructions_end;
+#ifdef CONFIG_STACKPROTECTOR
+ unsigned long stack_prot_start;
+ unsigned long stack_prot_end;
+#endif
#ifdef CONFIG_KASAN
unsigned long kasan_early_shadow_page_off;
unsigned long kasan_early_shadow_pte_off;
diff --git a/arch/s390/boot/ipl_parm.c b/arch/s390/boot/ipl_parm.c
index f584d7da29cb2..6bc950b92be76 100644
--- a/arch/s390/boot/ipl_parm.c
+++ b/arch/s390/boot/ipl_parm.c
@@ -3,6 +3,7 @@
#include <linux/init.h>
#include <linux/ctype.h>
#include <linux/pgtable.h>
+#include <asm/arch-stackprotector.h>
#include <asm/abs_lowcore.h>
#include <asm/page-states.h>
#include <asm/machine.h>
@@ -294,6 +295,11 @@ void parse_boot_command_line(void)
cmma_flag = 0;
}
+#ifdef CONFIG_STACKPROTECTOR
+ if (!strcmp(param, "debug_stackprotector"))
+ stack_protector_debug = 1;
+#endif
+
#if IS_ENABLED(CONFIG_KVM)
if (!strcmp(param, "prot_virt")) {
rc = kstrtobool(val, &enabled);
diff --git a/arch/s390/boot/stackprotector.c b/arch/s390/boot/stackprotector.c
new file mode 100644
index 0000000000000..68494940c12ac
--- /dev/null
+++ b/arch/s390/boot/stackprotector.c
@@ -0,0 +1,6 @@
+// SPDX-License-Identifier: GPL-2.0
+
+#define boot_fmt(fmt) "stackprot: " fmt
+
+#include "boot.h"
+#include "../kernel/stackprotector.c"
diff --git a/arch/s390/boot/startup.c b/arch/s390/boot/startup.c
index 3fbd25b9498f3..f77067dfc2a84 100644
--- a/arch/s390/boot/startup.c
+++ b/arch/s390/boot/startup.c
@@ -20,6 +20,9 @@
#include <asm/uv.h>
#include <asm/abs_lowcore.h>
#include <asm/physmem_info.h>
+#include <asm/stacktrace.h>
+#include <asm/asm-offsets.h>
+#include <asm/arch-stackprotector.h>
#include "decompressor.h"
#include "boot.h"
#include "uv.h"
@@ -477,6 +480,10 @@ static void kaslr_adjust_vmlinux_info(long offset)
vmlinux.invalid_pg_dir_off += offset;
vmlinux.alt_instructions += offset;
vmlinux.alt_instructions_end += offset;
+#ifdef CONFIG_STACKPROTECTOR
+ vmlinux.stack_prot_start += offset;
+ vmlinux.stack_prot_end += offset;
+#endif
#ifdef CONFIG_KASAN
vmlinux.kasan_early_shadow_page_off += offset;
vmlinux.kasan_early_shadow_pte_off += offset;
@@ -622,6 +629,7 @@ void startup_kernel(void)
__apply_alternatives((struct alt_instr *)_vmlinux_info.alt_instructions,
(struct alt_instr *)_vmlinux_info.alt_instructions_end,
ALT_CTX_EARLY);
+ stack_protector_apply_early(text_lma);
/*
* Save KASLR offset for early dumps, before vmcore_info is set.
diff --git a/arch/s390/include/asm/arch-stackprotector.h b/arch/s390/include/asm/arch-stackprotector.h
new file mode 100644
index 0000000000000..953627259e91f
--- /dev/null
+++ b/arch/s390/include/asm/arch-stackprotector.h
@@ -0,0 +1,25 @@
+/* SPDX-License-Identifier: GPL-2.0 */
+
+#ifndef _ASM_S390_ARCH_STACKPROTECTOR_H
+#define _ASM_S390_ARCH_STACKPROTECTOR_H
+
+extern unsigned long __stack_chk_guard;
+extern int stack_protector_debug;
+
+void __stack_protector_apply_early(unsigned long kernel_start);
+int __stack_protector_apply(unsigned long *start, unsigned long *end, unsigned long kernel_start);
+
+static inline void stack_protector_apply_early(unsigned long kernel_start)
+{
+ if (IS_ENABLED(CONFIG_STACKPROTECTOR))
+ __stack_protector_apply_early(kernel_start);
+}
+
+static inline int stack_protector_apply(unsigned long *start, unsigned long *end)
+{
+ if (IS_ENABLED(CONFIG_STACKPROTECTOR))
+ return __stack_protector_apply(start, end, 0);
+ return 0;
+}
+
+#endif /* _ASM_S390_ARCH_STACKPROTECTOR_H */
diff --git a/arch/s390/include/asm/lowcore.h b/arch/s390/include/asm/lowcore.h
index d9c853db9a40b..50ffe75adeb47 100644
--- a/arch/s390/include/asm/lowcore.h
+++ b/arch/s390/include/asm/lowcore.h
@@ -100,7 +100,8 @@ struct lowcore {
/* Save areas. */
__u64 save_area[8]; /* 0x0200 */
- __u8 pad_0x0240[0x0280-0x0240]; /* 0x0240 */
+ __u64 stack_canary; /* 0x0240 */
+ __u8 pad_0x0248[0x0280-0x0248]; /* 0x0248 */
__u64 save_area_restart[1]; /* 0x0280 */
__u64 pcpu; /* 0x0288 */
diff --git a/arch/s390/include/asm/stackprotector.h b/arch/s390/include/asm/stackprotector.h
new file mode 100644
index 0000000000000..0497850103dd9
--- /dev/null
+++ b/arch/s390/include/asm/stackprotector.h
@@ -0,0 +1,16 @@
+/* SPDX-License-Identifier: GPL-2.0 */
+
+#ifndef _ASM_S390_STACKPROTECTOR_H
+#define _ASM_S390_STACKPROTECTOR_H
+
+#include <linux/sched.h>
+#include <asm/current.h>
+#include <asm/lowcore.h>
+
+static __always_inline void boot_init_stack_canary(void)
+{
+ current->stack_canary = get_random_canary();
+ get_lowcore()->stack_canary = current->stack_canary;
+}
+
+#endif /* _ASM_S390_STACKPROTECTOR_H */
diff --git a/arch/s390/kernel/Makefile b/arch/s390/kernel/Makefile
index c949ed394e72f..6e37afb7187a2 100644
--- a/arch/s390/kernel/Makefile
+++ b/arch/s390/kernel/Makefile
@@ -67,7 +67,7 @@ obj-$(CONFIG_KEXEC_CORE) += machine_kexec.o relocate_kernel.o
obj-$(CONFIG_VMCORE_INFO) += vmcore_info.o
obj-$(CONFIG_UPROBES) += uprobes.o
obj-$(CONFIG_JUMP_LABEL) += jump_label.o
-
+obj-$(CONFIG_STACKPROTECTOR) += stackprotector.o
obj-$(CONFIG_KEXEC_FILE) += machine_kexec_file.o kexec_image.o
obj-$(CONFIG_KEXEC_FILE) += kexec_elf.o
obj-$(CONFIG_CERT_STORE) += cert_store.o
diff --git a/arch/s390/kernel/asm-offsets.c b/arch/s390/kernel/asm-offsets.c
index a8915663e917f..cfe27f6579e33 100644
--- a/arch/s390/kernel/asm-offsets.c
+++ b/arch/s390/kernel/asm-offsets.c
@@ -21,6 +21,9 @@ int main(void)
OFFSET(__TASK_stack, task_struct, stack);
OFFSET(__TASK_thread, task_struct, thread);
OFFSET(__TASK_pid, task_struct, pid);
+#ifdef CONFIG_STACKPROTECTOR
+ OFFSET(__TASK_stack_canary, task_struct, stack_canary);
+#endif
BLANK();
/* thread struct offsets */
OFFSET(__THREAD_ksp, thread_struct, ksp);
@@ -139,6 +142,7 @@ int main(void)
OFFSET(__LC_CURRENT_PID, lowcore, current_pid);
OFFSET(__LC_LAST_BREAK, lowcore, last_break);
/* software defined ABI-relevant lowcore locations 0xe00 - 0xe20 */
+ OFFSET(__LC_STACK_CANARY, lowcore, stack_canary);
OFFSET(__LC_DUMP_REIPL, lowcore, ipib);
OFFSET(__LC_VMCORE_INFO, lowcore, vmcore_info);
OFFSET(__LC_OS_INFO, lowcore, os_info);
diff --git a/arch/s390/kernel/entry.S b/arch/s390/kernel/entry.S
index 55139e4786c23..114f25e9cf23f 100644
--- a/arch/s390/kernel/entry.S
+++ b/arch/s390/kernel/entry.S
@@ -162,9 +162,13 @@ SYM_FUNC_START(__switch_to_asm)
stg %r3,__LC_CURRENT(%r13) # store task struct of next
stg %r15,__LC_KERNEL_STACK(%r13) # store end of kernel stack
lg %r15,__THREAD_ksp(%r1,%r3) # load kernel stack of next
- aghi %r3,__TASK_pid
- mvc __LC_CURRENT_PID(4,%r13),0(%r3) # store pid of next
+ aghik %r4,%r3,__TASK_pid
+ mvc __LC_CURRENT_PID(4,%r13),0(%r4) # store pid of next
ALTERNATIVE "nop", "lpp _LPP_OFFSET(%r13)", ALT_FACILITY(40)
+#ifdef CONFIG_STACKPROTECTOR
+ lg %r3,__TASK_stack_canary(%r3)
+ stg %r3,__LC_STACK_CANARY(%r13)
+#endif
lmg %r6,%r15,__SF_GPRS(%r15) # load gprs of next task
BR_EX %r14
SYM_FUNC_END(__switch_to_asm)
diff --git a/arch/s390/kernel/module.c b/arch/s390/kernel/module.c
index 91e207b503943..cd438a75ab239 100644
--- a/arch/s390/kernel/module.c
+++ b/arch/s390/kernel/module.c
@@ -22,12 +22,14 @@
#include <linux/bug.h>
#include <linux/memory.h>
#include <linux/execmem.h>
+#include <asm/arch-stackprotector.h>
#include <asm/alternative.h>
#include <asm/nospec-branch.h>
#include <asm/facility.h>
#include <asm/ftrace.lds.h>
#include <asm/set_memory.h>
#include <asm/setup.h>
+#include <asm/asm-offsets.h>
#if 0
#define DEBUGP printk
@@ -527,6 +529,13 @@ int module_finalize(const Elf_Ehdr *hdr,
(str_has_prefix(secname, ".s390_return")))
nospec_revert(aseg, aseg + s->sh_size);
+ if (IS_ENABLED(CONFIG_STACKPROTECTOR) &&
+ (str_has_prefix(secname, "__stack_protector_loc"))) {
+ rc = stack_protector_apply(aseg, aseg + s->sh_size);
+ if (rc)
+ break;
+ }
+
#ifdef CONFIG_FUNCTION_TRACER
if (!strcmp(FTRACE_CALLSITE_SECTION, secname)) {
ret = module_alloc_ftrace_hotpatch_trampolines(me, s);
diff --git a/arch/s390/kernel/smp.c b/arch/s390/kernel/smp.c
index 70df4ca5d4436..49ec8c03536a1 100644
--- a/arch/s390/kernel/smp.c
+++ b/arch/s390/kernel/smp.c
@@ -281,6 +281,9 @@ static void pcpu_attach_task(int cpu, struct task_struct *tsk)
lc->hardirq_timer = tsk->thread.hardirq_timer;
lc->softirq_timer = tsk->thread.softirq_timer;
lc->steal_timer = 0;
+#ifdef CONFIG_STACKPROTECTOR
+ lc->stack_canary = tsk->stack_canary;
+#endif
}
static void pcpu_start_fn(int cpu, void (*func)(void *), void *data)
diff --git a/arch/s390/kernel/stackprotector.c b/arch/s390/kernel/stackprotector.c
new file mode 100644
index 0000000000000..d4e40483f0088
--- /dev/null
+++ b/arch/s390/kernel/stackprotector.c
@@ -0,0 +1,156 @@
+// SPDX-License-Identifier: GPL-2.0
+
+#ifndef pr_fmt
+#define pr_fmt(fmt) "stackprot: " fmt
+#endif
+
+#include <linux/export.h>
+#include <linux/uaccess.h>
+#include <linux/printk.h>
+#include <asm/abs_lowcore.h>
+#include <asm/sections.h>
+#include <asm/machine.h>
+#include <asm/asm-offsets.h>
+#include <asm/arch-stackprotector.h>
+
+#ifdef __DECOMPRESSOR
+
+#define DEBUGP boot_debug
+#define EMERGP boot_emerg
+#define PANIC boot_panic
+
+#else /* __DECOMPRESSOR */
+
+#define DEBUGP pr_debug
+#define EMERGP pr_emerg
+#define PANIC panic
+
+#endif /* __DECOMPRESSOR */
+
+int __bootdata_preserved(stack_protector_debug);
+
+unsigned long __stack_chk_guard;
+EXPORT_SYMBOL(__stack_chk_guard);
+
+struct insn_ril {
+ u8 opc1 : 8;
+ u8 r1 : 4;
+ u8 opc2 : 4;
+ u32 imm;
+} __packed;
+
+/*
+ * Convert a virtual instruction address to a real instruction address. The
+ * decompressor needs to patch instructions within the kernel image based on
+ * their virtual addresses, while dynamic address translation is still
+ * disabled. Therefore a translation from virtual kernel image addresses to
+ * the corresponding physical addresses is required.
+ *
+ * After dynamic address translation is enabled and when the kernel needs to
+ * patch instructions such a translation is not required since the addresses
+ * are identical.
+ */
+static struct insn_ril *vaddress_to_insn(unsigned long vaddress)
+{
+#ifdef __DECOMPRESSOR
+ return (struct insn_ril *)__kernel_pa(vaddress);
+#else
+ return (struct insn_ril *)vaddress;
+#endif
+}
+
+static unsigned long insn_to_vaddress(struct insn_ril *insn)
+{
+#ifdef __DECOMPRESSOR
+ return (unsigned long)__kernel_va(insn);
+#else
+ return (unsigned long)insn;
+#endif
+}
+
+#define INSN_RIL_STRING_SIZE (sizeof(struct insn_ril) * 2 + 1)
+
+static void insn_ril_to_string(char *str, struct insn_ril *insn)
+{
+ u8 *ptr = (u8 *)insn;
+ int i;
+
+ for (i = 0; i < sizeof(*insn); i++)
+ hex_byte_pack(&str[2 * i], ptr[i]);
+ str[2 * i] = 0;
+}
+
+static void stack_protector_dump(struct insn_ril *old, struct insn_ril *new)
+{
+ char ostr[INSN_RIL_STRING_SIZE];
+ char nstr[INSN_RIL_STRING_SIZE];
+
+ insn_ril_to_string(ostr, old);
+ insn_ril_to_string(nstr, new);
+ DEBUGP("%016lx: %s -> %s\n", insn_to_vaddress(old), ostr, nstr);
+}
+
+static int stack_protector_verify(struct insn_ril *insn, unsigned long kernel_start)
+{
+ char istr[INSN_RIL_STRING_SIZE];
+ unsigned long vaddress, offset;
+
+ /* larl */
+ if (insn->opc1 == 0xc0 && insn->opc2 == 0x0)
+ return 0;
+ /* lgrl */
+ if (insn->opc1 == 0xc4 && insn->opc2 == 0x8)
+ return 0;
+ insn_ril_to_string(istr, insn);
+ vaddress = insn_to_vaddress(insn);
+ if (__is_defined(__DECOMPRESSOR)) {
+ offset = (unsigned long)insn - kernel_start + TEXT_OFFSET;
+ EMERGP("Unexpected instruction at %016lx/%016lx: %s\n", vaddress, offset, istr);
+ PANIC("Stackprotector error\n");
+ } else {
+ EMERGP("Unexpected instruction at %016lx: %s\n", vaddress, istr);
+ }
+ return -EINVAL;
+}
+
+int __stack_protector_apply(unsigned long *start, unsigned long *end, unsigned long kernel_start)
+{
+ unsigned long canary, *loc;
+ struct insn_ril *insn, new;
+ int rc;
+
+ /*
+ * Convert LARL/LGRL instructions to LLILF so register R1 contains the
+ * address of the per-cpu / per-process stack canary:
+ *
+ * LARL/LGRL R1,__stack_chk_guard => LLILF R1,__lc_stack_canary
+ */
+ canary = __LC_STACK_CANARY;
+ if (machine_has_relocated_lowcore())
+ canary += LOWCORE_ALT_ADDRESS;
+ for (loc = start; loc < end; loc++) {
+ insn = vaddress_to_insn(*loc);
+ rc = stack_protector_verify(insn, kernel_start);
+ if (rc)
+ return rc;
+ new = *insn;
+ new.opc1 = 0xc0;
+ new.opc2 = 0xf;
+ new.imm = canary;
+ if (stack_protector_debug)
+ stack_protector_dump(insn, &new);
+ s390_kernel_write(insn, &new, sizeof(*insn));
+ }
+ return 0;
+}
+
+#ifdef __DECOMPRESSOR
+void __stack_protector_apply_early(unsigned long kernel_start)
+{
+ unsigned long *start, *end;
+
+ start = (unsigned long *)vmlinux.stack_prot_start;
+ end = (unsigned long *)vmlinux.stack_prot_end;
+ __stack_protector_apply(start, end, kernel_start);
+}
+#endif
diff --git a/arch/s390/kernel/vdso64/Makefile b/arch/s390/kernel/vdso64/Makefile
index d8f0df7428096..49ad8dfc7c790 100644
--- a/arch/s390/kernel/vdso64/Makefile
+++ b/arch/s390/kernel/vdso64/Makefile
@@ -32,6 +32,7 @@ KBUILD_CFLAGS_64 := $(filter-out -mno-pic-data-is-text-relative,$(KBUILD_CFLAGS_
KBUILD_CFLAGS_64 := $(filter-out -munaligned-symbols,$(KBUILD_CFLAGS_64))
KBUILD_CFLAGS_64 := $(filter-out -fno-asynchronous-unwind-tables,$(KBUILD_CFLAGS_64))
KBUILD_CFLAGS_64 += -m64 -fPIC -fno-common -fno-builtin -fasynchronous-unwind-tables
+KBUILD_CFLAGS_64 += -fno-stack-protector
ldflags-y := -shared -soname=linux-vdso64.so.1 \
--hash-style=both --build-id=sha1 -T
diff --git a/arch/s390/kernel/vmlinux.lds.S b/arch/s390/kernel/vmlinux.lds.S
index 9289e9e535c70..c5040caa8e1aa 100644
--- a/arch/s390/kernel/vmlinux.lds.S
+++ b/arch/s390/kernel/vmlinux.lds.S
@@ -150,6 +150,15 @@ SECTIONS
*(.altinstr_replacement)
}
+#ifdef CONFIG_STACKPROTECTOR
+ . = ALIGN(8);
+ .stack_prot_table : {
+ __stack_prot_start = .;
+ KEEP(*(__stack_protector_loc))
+ __stack_prot_end = .;
+ }
+#endif
+
/*
* Table with the patch locations to undo expolines
*/
@@ -258,6 +267,10 @@ SECTIONS
QUAD(invalid_pg_dir)
QUAD(__alt_instructions)
QUAD(__alt_instructions_end)
+#ifdef CONFIG_STACKPROTECTOR
+ QUAD(__stack_prot_start)
+ QUAD(__stack_prot_end)
+#endif
#ifdef CONFIG_KASAN
QUAD(kasan_early_shadow_page)
QUAD(kasan_early_shadow_pte)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0643/1518] s390/vdso: Rename vdso64 to vdso
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (641 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0642/1518] s390: Add stackprotector support Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0644/1518] s390/vdso: Pass --eh-frame-hdr to the linker Greg Kroah-Hartman
` (355 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jens Remus, Heiko Carstens,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Heiko Carstens <hca@linux.ibm.com>
[ Upstream commit c0087d807ae86cc82cc356e366d2dccf0e3bb225 ]
Since compat is gone there is only a 64 bit vdso left.
Remove the superfluous "64" suffix everywhere.
Reviewed-by: Jens Remus <jremus@linux.ibm.com>
Signed-off-by: Heiko Carstens <hca@linux.ibm.com>
Stable-dep-of: dc161efb6df8 ("s390/vdso: Pass --eh-frame-hdr to the linker")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/s390/Makefile | 4 +-
arch/s390/include/asm/vdso-symbols.h | 4 +-
arch/s390/kernel/Makefile | 2 +-
arch/s390/kernel/signal.c | 6 +-
arch/s390/kernel/vdso.c | 16 ++--
arch/s390/kernel/{vdso64 => vdso}/.gitignore | 2 +-
arch/s390/kernel/vdso/Makefile | 80 +++++++++++++++++++
.../{vdso64 => vdso}/gen_vdso_offsets.sh | 2 +-
arch/s390/kernel/{vdso64 => vdso}/getcpu.c | 0
arch/s390/kernel/{vdso64 => vdso}/note.S | 0
arch/s390/kernel/{vdso64 => vdso}/vdso.h | 6 +-
.../{vdso64/vdso64.lds.S => vdso/vdso.lds.S} | 0
.../vdso64_generic.c => vdso/vdso_generic.c} | 0
.../{vdso64 => vdso}/vdso_user_wrapper.S | 0
.../vdso64_wrapper.S => vdso/vdso_wrapper.S} | 8 +-
.../{vdso64 => vdso}/vgetrandom-chacha.S | 0
.../s390/kernel/{vdso64 => vdso}/vgetrandom.c | 0
arch/s390/kernel/vdso64/Makefile | 80 -------------------
18 files changed, 104 insertions(+), 106 deletions(-)
rename arch/s390/kernel/{vdso64 => vdso}/.gitignore (78%)
create mode 100644 arch/s390/kernel/vdso/Makefile
rename arch/s390/kernel/{vdso64 => vdso}/gen_vdso_offsets.sh (82%)
rename arch/s390/kernel/{vdso64 => vdso}/getcpu.c (100%)
rename arch/s390/kernel/{vdso64 => vdso}/note.S (100%)
rename arch/s390/kernel/{vdso64 => vdso}/vdso.h (80%)
rename arch/s390/kernel/{vdso64/vdso64.lds.S => vdso/vdso.lds.S} (100%)
rename arch/s390/kernel/{vdso64/vdso64_generic.c => vdso/vdso_generic.c} (100%)
rename arch/s390/kernel/{vdso64 => vdso}/vdso_user_wrapper.S (100%)
rename arch/s390/kernel/{vdso64/vdso64_wrapper.S => vdso/vdso_wrapper.S} (64%)
rename arch/s390/kernel/{vdso64 => vdso}/vgetrandom-chacha.S (100%)
rename arch/s390/kernel/{vdso64 => vdso}/vgetrandom.c (100%)
delete mode 100644 arch/s390/kernel/vdso64/Makefile
diff --git a/arch/s390/Makefile b/arch/s390/Makefile
index a205c929e6630..8ccc127870904 100644
--- a/arch/s390/Makefile
+++ b/arch/s390/Makefile
@@ -152,9 +152,9 @@ ifeq ($(KBUILD_EXTMOD),)
# this hack.
prepare: vdso_prepare
vdso_prepare: prepare0
- $(Q)$(MAKE) $(build)=arch/s390/kernel/vdso64 include/generated/vdso64-offsets.h
+ $(Q)$(MAKE) $(build)=arch/s390/kernel/vdso include/generated/vdso-offsets.h
-vdso-install-y += arch/s390/kernel/vdso64/vdso64.so.dbg
+vdso-install-y += arch/s390/kernel/vdso/vdso.so.dbg
endif
diff --git a/arch/s390/include/asm/vdso-symbols.h b/arch/s390/include/asm/vdso-symbols.h
index 205da2c565c26..e3561e67c4e31 100644
--- a/arch/s390/include/asm/vdso-symbols.h
+++ b/arch/s390/include/asm/vdso-symbols.h
@@ -2,8 +2,8 @@
#ifndef __S390_VDSO_SYMBOLS_H__
#define __S390_VDSO_SYMBOLS_H__
-#include <generated/vdso64-offsets.h>
+#include <generated/vdso-offsets.h>
-#define VDSO64_SYMBOL(tsk, name) ((tsk)->mm->context.vdso_base + (vdso64_offset_##name))
+#define VDSO_SYMBOL(tsk, name) ((tsk)->mm->context.vdso_base + (vdso_offset_##name))
#endif /* __S390_VDSO_SYMBOLS_H__ */
diff --git a/arch/s390/kernel/Makefile b/arch/s390/kernel/Makefile
index 6e37afb7187a2..8d5ca89cd482b 100644
--- a/arch/s390/kernel/Makefile
+++ b/arch/s390/kernel/Makefile
@@ -81,4 +81,4 @@ obj-$(CONFIG_PERF_EVENTS) += perf_pai_crypto.o perf_pai_ext.o
obj-$(CONFIG_TRACEPOINTS) += trace.o
# vdso
-obj-y += vdso64/
+obj-y += vdso/
diff --git a/arch/s390/kernel/signal.c b/arch/s390/kernel/signal.c
index e7775d121fa14..4874de5edea0a 100644
--- a/arch/s390/kernel/signal.c
+++ b/arch/s390/kernel/signal.c
@@ -326,7 +326,7 @@ static int setup_frame(int sig, struct k_sigaction *ka,
if (ka->sa.sa_flags & SA_RESTORER)
restorer = (unsigned long) ka->sa.sa_restorer;
else
- restorer = VDSO64_SYMBOL(current, sigreturn);
+ restorer = VDSO_SYMBOL(current, sigreturn);
/* Set up registers for signal handler */
regs->gprs[14] = restorer;
@@ -378,7 +378,7 @@ static int setup_rt_frame(struct ksignal *ksig, sigset_t *set,
if (ksig->ka.sa.sa_flags & SA_RESTORER)
restorer = (unsigned long) ksig->ka.sa.sa_restorer;
else
- restorer = VDSO64_SYMBOL(current, rt_sigreturn);
+ restorer = VDSO_SYMBOL(current, rt_sigreturn);
/* Create siginfo on the signal stack */
if (copy_siginfo_to_user(&frame->info, &ksig->info))
@@ -490,7 +490,7 @@ void arch_do_signal_or_restart(struct pt_regs *regs)
/* Restart with sys_restart_syscall */
regs->gprs[2] = regs->orig_gpr2;
current->restart_block.arch_data = regs->psw.addr;
- regs->psw.addr = VDSO64_SYMBOL(current, restart_syscall);
+ regs->psw.addr = VDSO_SYMBOL(current, restart_syscall);
if (test_thread_flag(TIF_SINGLE_STEP))
clear_thread_flag(TIF_PER_TRAP);
break;
diff --git a/arch/s390/kernel/vdso.c b/arch/s390/kernel/vdso.c
index 83cc67cf21c83..a27a90a199be7 100644
--- a/arch/s390/kernel/vdso.c
+++ b/arch/s390/kernel/vdso.c
@@ -22,7 +22,7 @@
#include <asm/alternative.h>
#include <asm/vdso.h>
-extern char vdso64_start[], vdso64_end[];
+extern char vdso_start[], vdso_end[];
static int vdso_mremap(const struct vm_special_mapping *sm,
struct vm_area_struct *vma)
@@ -31,7 +31,7 @@ static int vdso_mremap(const struct vm_special_mapping *sm,
return 0;
}
-static struct vm_special_mapping vdso64_mapping = {
+static struct vm_special_mapping vdso_mapping = {
.name = "[vdso]",
.mremap = vdso_mremap,
};
@@ -46,7 +46,6 @@ early_initcall(vdso_getcpu_init); /* Must be called before SMP init */
static int map_vdso(unsigned long addr, unsigned long vdso_mapping_len)
{
unsigned long vvar_start, vdso_text_start, vdso_text_len;
- struct vm_special_mapping *vdso_mapping;
struct mm_struct *mm = current->mm;
struct vm_area_struct *vma;
int rc;
@@ -55,8 +54,7 @@ static int map_vdso(unsigned long addr, unsigned long vdso_mapping_len)
if (mmap_write_lock_killable(mm))
return -EINTR;
- vdso_text_len = vdso64_end - vdso64_start;
- vdso_mapping = &vdso64_mapping;
+ vdso_text_len = vdso_end - vdso_start;
vvar_start = get_unmapped_area(NULL, addr, vdso_mapping_len, 0, 0);
rc = vvar_start;
if (IS_ERR_VALUE(vvar_start))
@@ -70,7 +68,7 @@ static int map_vdso(unsigned long addr, unsigned long vdso_mapping_len)
vma = _install_special_mapping(mm, vdso_text_start, vdso_text_len,
VM_READ|VM_EXEC|VM_SEALED_SYSMAP|
VM_MAYREAD|VM_MAYWRITE|VM_MAYEXEC,
- vdso_mapping);
+ &vdso_mapping);
if (IS_ERR(vma)) {
do_munmap(mm, vvar_start, PAGE_SIZE, NULL);
rc = PTR_ERR(vma);
@@ -110,7 +108,7 @@ static unsigned long vdso_addr(unsigned long start, unsigned long len)
unsigned long vdso_text_size(void)
{
- return PAGE_ALIGN(vdso64_end - vdso64_start);
+ return PAGE_ALIGN(vdso_end - vdso_start);
}
unsigned long vdso_size(void)
@@ -148,7 +146,7 @@ static void vdso_apply_alternatives(void)
struct alt_instr *start, *end;
const struct elf64_hdr *hdr;
- hdr = (struct elf64_hdr *)vdso64_start;
+ hdr = (struct elf64_hdr *)vdso_start;
shdr = (void *)hdr + hdr->e_shoff;
alt = find_section(hdr, shdr, ".altinstructions");
if (!alt)
@@ -161,7 +159,7 @@ static void vdso_apply_alternatives(void)
static int __init vdso_init(void)
{
vdso_apply_alternatives();
- vdso64_mapping.pages = vdso_setup_pages(vdso64_start, vdso64_end);
+ vdso_mapping.pages = vdso_setup_pages(vdso_start, vdso_end);
return 0;
}
arch_initcall(vdso_init);
diff --git a/arch/s390/kernel/vdso64/.gitignore b/arch/s390/kernel/vdso/.gitignore
similarity index 78%
rename from arch/s390/kernel/vdso64/.gitignore
rename to arch/s390/kernel/vdso/.gitignore
index 4ec80685feccc..652e31d825820 100644
--- a/arch/s390/kernel/vdso64/.gitignore
+++ b/arch/s390/kernel/vdso/.gitignore
@@ -1,2 +1,2 @@
# SPDX-License-Identifier: GPL-2.0-only
-vdso64.lds
+vdso.lds
diff --git a/arch/s390/kernel/vdso/Makefile b/arch/s390/kernel/vdso/Makefile
new file mode 100644
index 0000000000000..924be0a6a2df3
--- /dev/null
+++ b/arch/s390/kernel/vdso/Makefile
@@ -0,0 +1,80 @@
+# SPDX-License-Identifier: GPL-2.0
+# List of files in the vdso
+
+# Include the generic Makefile to check the built vdso.
+include $(srctree)/lib/vdso/Makefile.include
+obj-vdso = vdso_user_wrapper.o note.o vgetrandom-chacha.o
+obj-cvdso = vdso_generic.o getcpu.o vgetrandom.o
+VDSO_CFLAGS_REMOVE := -pg $(CC_FLAGS_FTRACE) $(CC_FLAGS_EXPOLINE)
+CFLAGS_REMOVE_getcpu.o = $(VDSO_CFLAGS_REMOVE)
+CFLAGS_REMOVE_vgetrandom.o = $(VDSO_CFLAGS_REMOVE)
+CFLAGS_REMOVE_vdso_generic.o = $(VDSO_CFLAGS_REMOVE)
+
+ifneq ($(c-getrandom-y),)
+ CFLAGS_vgetrandom.o += -include $(c-getrandom-y)
+endif
+
+# Build rules
+
+targets := $(obj-vdso) $(obj-cvdso) vdso.so vdso.so.dbg
+obj-vdso := $(addprefix $(obj)/, $(obj-vdso))
+obj-cvdso := $(addprefix $(obj)/, $(obj-cvdso))
+
+KBUILD_AFLAGS += -DBUILD_VDSO
+KBUILD_CFLAGS += -DBUILD_VDSO -DDISABLE_BRANCH_PROFILING
+
+KBUILD_AFLAGS_VDSO := $(filter-out -m64,$(KBUILD_AFLAGS))
+KBUILD_AFLAGS_VDSO += -m64
+
+KBUILD_CFLAGS_VDSO := $(filter-out -m64,$(KBUILD_CFLAGS))
+KBUILD_CFLAGS_VDSO := $(filter-out -mpacked-stack,$(KBUILD_CFLAGS_VDSO))
+KBUILD_CFLAGS_VDSO := $(filter-out -mno-pic-data-is-text-relative,$(KBUILD_CFLAGS_VDSO))
+KBUILD_CFLAGS_VDSO := $(filter-out -munaligned-symbols,$(KBUILD_CFLAGS_VDSO))
+KBUILD_CFLAGS_VDSO := $(filter-out -fno-asynchronous-unwind-tables,$(KBUILD_CFLAGS_VDSO))
+KBUILD_CFLAGS_VDSO += -m64 -fPIC -fno-common -fno-builtin -fasynchronous-unwind-tables
+KBUILD_CFLAGS_VDSO += -fno-stack-protector
+ldflags-y := -shared -soname=linux-vdso.so.1 \
+ --hash-style=both --build-id=sha1 -T
+
+$(targets:%=$(obj)/%.dbg): KBUILD_CFLAGS = $(KBUILD_CFLAGS_VDSO)
+$(targets:%=$(obj)/%.dbg): KBUILD_AFLAGS = $(KBUILD_AFLAGS_VDSO)
+
+obj-y += vdso_wrapper.o
+targets += vdso.lds
+CPPFLAGS_vdso.lds += -P -C -U$(ARCH)
+
+# Force dependency (incbin is bad)
+$(obj)/vdso_wrapper.o : $(obj)/vdso.so
+
+quiet_cmd_vdso_and_check = VDSO $@
+ cmd_vdso_and_check = $(cmd_ld); $(cmd_vdso_check)
+
+# link rule for the .so file, .lds has to be first
+$(obj)/vdso.so.dbg: $(obj)/vdso.lds $(obj-vdso) $(obj-cvdso) FORCE
+ $(call if_changed,vdso_and_check)
+
+# strip rule for the .so file
+$(obj)/%.so: OBJCOPYFLAGS := -S
+$(obj)/%.so: $(obj)/%.so.dbg FORCE
+ $(call if_changed,objcopy)
+
+# assembly rules for the .S files
+$(obj-vdso): %.o: %.S FORCE
+ $(call if_changed_dep,vdsoas)
+
+$(obj-cvdso): %.o: %.c FORCE
+ $(call if_changed_dep,vdsocc)
+
+# actual build commands
+quiet_cmd_vdsoas = VDSOA $@
+ cmd_vdsoas = $(CC) $(a_flags) -c -o $@ $<
+quiet_cmd_vdsocc = VDSOC $@
+ cmd_vdsocc = $(CC) $(c_flags) -c -o $@ $<
+
+# Generate VDSO offsets using helper script
+gen-vdsosym := $(src)/gen_vdso_offsets.sh
+quiet_cmd_vdsosym = VDSOSYM $@
+ cmd_vdsosym = $(NM) $< | $(gen-vdsosym) | LC_ALL=C sort > $@
+
+include/generated/vdso-offsets.h: $(obj)/vdso.so.dbg FORCE
+ $(call if_changed,vdsosym)
diff --git a/arch/s390/kernel/vdso64/gen_vdso_offsets.sh b/arch/s390/kernel/vdso/gen_vdso_offsets.sh
similarity index 82%
rename from arch/s390/kernel/vdso64/gen_vdso_offsets.sh
rename to arch/s390/kernel/vdso/gen_vdso_offsets.sh
index 37f05cb38dad4..359982fb002d4 100755
--- a/arch/s390/kernel/vdso64/gen_vdso_offsets.sh
+++ b/arch/s390/kernel/vdso/gen_vdso_offsets.sh
@@ -12,4 +12,4 @@
#
LC_ALL=C
-sed -n 's/\([0-9a-f]*\) . __kernel_\(.*\)/\#define vdso64_offset_\2\t0x\1/p'
+sed -n 's/\([0-9a-f]*\) . __kernel_\(.*\)/\#define vdso_offset_\2\t0x\1/p'
diff --git a/arch/s390/kernel/vdso64/getcpu.c b/arch/s390/kernel/vdso/getcpu.c
similarity index 100%
rename from arch/s390/kernel/vdso64/getcpu.c
rename to arch/s390/kernel/vdso/getcpu.c
diff --git a/arch/s390/kernel/vdso64/note.S b/arch/s390/kernel/vdso/note.S
similarity index 100%
rename from arch/s390/kernel/vdso64/note.S
rename to arch/s390/kernel/vdso/note.S
diff --git a/arch/s390/kernel/vdso64/vdso.h b/arch/s390/kernel/vdso/vdso.h
similarity index 80%
rename from arch/s390/kernel/vdso64/vdso.h
rename to arch/s390/kernel/vdso/vdso.h
index 9e5397e7b590a..8cff033dd854c 100644
--- a/arch/s390/kernel/vdso64/vdso.h
+++ b/arch/s390/kernel/vdso/vdso.h
@@ -1,6 +1,6 @@
/* SPDX-License-Identifier: GPL-2.0 */
-#ifndef __ARCH_S390_KERNEL_VDSO64_VDSO_H
-#define __ARCH_S390_KERNEL_VDSO64_VDSO_H
+#ifndef __ARCH_S390_KERNEL_VDSO_VDSO_H
+#define __ARCH_S390_KERNEL_VDSO_VDSO_H
#include <vdso/datapage.h>
@@ -12,4 +12,4 @@ int __s390_vdso_clock_gettime(clockid_t clock, struct __kernel_timespec *ts);
int __s390_vdso_clock_getres(clockid_t clock, struct __kernel_timespec *ts);
ssize_t __kernel_getrandom(void *buffer, size_t len, unsigned int flags, void *opaque_state, size_t opaque_len);
-#endif /* __ARCH_S390_KERNEL_VDSO64_VDSO_H */
+#endif /* __ARCH_S390_KERNEL_VDSO_VDSO_H */
diff --git a/arch/s390/kernel/vdso64/vdso64.lds.S b/arch/s390/kernel/vdso/vdso.lds.S
similarity index 100%
rename from arch/s390/kernel/vdso64/vdso64.lds.S
rename to arch/s390/kernel/vdso/vdso.lds.S
diff --git a/arch/s390/kernel/vdso64/vdso64_generic.c b/arch/s390/kernel/vdso/vdso_generic.c
similarity index 100%
rename from arch/s390/kernel/vdso64/vdso64_generic.c
rename to arch/s390/kernel/vdso/vdso_generic.c
diff --git a/arch/s390/kernel/vdso64/vdso_user_wrapper.S b/arch/s390/kernel/vdso/vdso_user_wrapper.S
similarity index 100%
rename from arch/s390/kernel/vdso64/vdso_user_wrapper.S
rename to arch/s390/kernel/vdso/vdso_user_wrapper.S
diff --git a/arch/s390/kernel/vdso64/vdso64_wrapper.S b/arch/s390/kernel/vdso/vdso_wrapper.S
similarity index 64%
rename from arch/s390/kernel/vdso64/vdso64_wrapper.S
rename to arch/s390/kernel/vdso/vdso_wrapper.S
index 672184998623b..f69e62a149784 100644
--- a/arch/s390/kernel/vdso64/vdso64_wrapper.S
+++ b/arch/s390/kernel/vdso/vdso_wrapper.S
@@ -5,11 +5,11 @@
__PAGE_ALIGNED_DATA
- .globl vdso64_start, vdso64_end
+ .globl vdso_start, vdso_end
.balign PAGE_SIZE
-vdso64_start:
- .incbin "arch/s390/kernel/vdso64/vdso64.so"
+vdso_start:
+ .incbin "arch/s390/kernel/vdso/vdso.so"
.balign PAGE_SIZE
-vdso64_end:
+vdso_end:
.previous
diff --git a/arch/s390/kernel/vdso64/vgetrandom-chacha.S b/arch/s390/kernel/vdso/vgetrandom-chacha.S
similarity index 100%
rename from arch/s390/kernel/vdso64/vgetrandom-chacha.S
rename to arch/s390/kernel/vdso/vgetrandom-chacha.S
diff --git a/arch/s390/kernel/vdso64/vgetrandom.c b/arch/s390/kernel/vdso/vgetrandom.c
similarity index 100%
rename from arch/s390/kernel/vdso64/vgetrandom.c
rename to arch/s390/kernel/vdso/vgetrandom.c
diff --git a/arch/s390/kernel/vdso64/Makefile b/arch/s390/kernel/vdso64/Makefile
deleted file mode 100644
index 49ad8dfc7c790..0000000000000
--- a/arch/s390/kernel/vdso64/Makefile
+++ /dev/null
@@ -1,80 +0,0 @@
-# SPDX-License-Identifier: GPL-2.0
-# List of files in the vdso
-
-# Include the generic Makefile to check the built vdso.
-include $(srctree)/lib/vdso/Makefile.include
-obj-vdso64 = vdso_user_wrapper.o note.o vgetrandom-chacha.o
-obj-cvdso64 = vdso64_generic.o getcpu.o vgetrandom.o
-VDSO_CFLAGS_REMOVE := -pg $(CC_FLAGS_FTRACE) $(CC_FLAGS_EXPOLINE)
-CFLAGS_REMOVE_getcpu.o = $(VDSO_CFLAGS_REMOVE)
-CFLAGS_REMOVE_vgetrandom.o = $(VDSO_CFLAGS_REMOVE)
-CFLAGS_REMOVE_vdso64_generic.o = $(VDSO_CFLAGS_REMOVE)
-
-ifneq ($(c-getrandom-y),)
- CFLAGS_vgetrandom.o += -include $(c-getrandom-y)
-endif
-
-# Build rules
-
-targets := $(obj-vdso64) $(obj-cvdso64) vdso64.so vdso64.so.dbg
-obj-vdso64 := $(addprefix $(obj)/, $(obj-vdso64))
-obj-cvdso64 := $(addprefix $(obj)/, $(obj-cvdso64))
-
-KBUILD_AFLAGS += -DBUILD_VDSO
-KBUILD_CFLAGS += -DBUILD_VDSO -DDISABLE_BRANCH_PROFILING
-
-KBUILD_AFLAGS_64 := $(filter-out -m64,$(KBUILD_AFLAGS))
-KBUILD_AFLAGS_64 += -m64
-
-KBUILD_CFLAGS_64 := $(filter-out -m64,$(KBUILD_CFLAGS))
-KBUILD_CFLAGS_64 := $(filter-out -mpacked-stack,$(KBUILD_CFLAGS_64))
-KBUILD_CFLAGS_64 := $(filter-out -mno-pic-data-is-text-relative,$(KBUILD_CFLAGS_64))
-KBUILD_CFLAGS_64 := $(filter-out -munaligned-symbols,$(KBUILD_CFLAGS_64))
-KBUILD_CFLAGS_64 := $(filter-out -fno-asynchronous-unwind-tables,$(KBUILD_CFLAGS_64))
-KBUILD_CFLAGS_64 += -m64 -fPIC -fno-common -fno-builtin -fasynchronous-unwind-tables
-KBUILD_CFLAGS_64 += -fno-stack-protector
-ldflags-y := -shared -soname=linux-vdso64.so.1 \
- --hash-style=both --build-id=sha1 -T
-
-$(targets:%=$(obj)/%.dbg): KBUILD_CFLAGS = $(KBUILD_CFLAGS_64)
-$(targets:%=$(obj)/%.dbg): KBUILD_AFLAGS = $(KBUILD_AFLAGS_64)
-
-obj-y += vdso64_wrapper.o
-targets += vdso64.lds
-CPPFLAGS_vdso64.lds += -P -C -U$(ARCH)
-
-# Force dependency (incbin is bad)
-$(obj)/vdso64_wrapper.o : $(obj)/vdso64.so
-
-quiet_cmd_vdso_and_check = VDSO $@
- cmd_vdso_and_check = $(cmd_ld); $(cmd_vdso_check)
-
-# link rule for the .so file, .lds has to be first
-$(obj)/vdso64.so.dbg: $(obj)/vdso64.lds $(obj-vdso64) $(obj-cvdso64) FORCE
- $(call if_changed,vdso_and_check)
-
-# strip rule for the .so file
-$(obj)/%.so: OBJCOPYFLAGS := -S
-$(obj)/%.so: $(obj)/%.so.dbg FORCE
- $(call if_changed,objcopy)
-
-# assembly rules for the .S files
-$(obj-vdso64): %.o: %.S FORCE
- $(call if_changed_dep,vdso64as)
-
-$(obj-cvdso64): %.o: %.c FORCE
- $(call if_changed_dep,vdso64cc)
-
-# actual build commands
-quiet_cmd_vdso64as = VDSO64A $@
- cmd_vdso64as = $(CC) $(a_flags) -c -o $@ $<
-quiet_cmd_vdso64cc = VDSO64C $@
- cmd_vdso64cc = $(CC) $(c_flags) -c -o $@ $<
-
-# Generate VDSO offsets using helper script
-gen-vdsosym := $(src)/gen_vdso_offsets.sh
-quiet_cmd_vdsosym = VDSOSYM $@
- cmd_vdsosym = $(NM) $< | $(gen-vdsosym) | LC_ALL=C sort > $@
-
-include/generated/vdso64-offsets.h: $(obj)/vdso64.so.dbg FORCE
- $(call if_changed,vdsosym)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0644/1518] s390/vdso: Pass --eh-frame-hdr to the linker
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (642 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0643/1518] s390/vdso: Rename vdso64 to vdso Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0645/1518] platform/chrome: cros_ec_debugfs: Clean up console log on probe failure Greg Kroah-Hartman
` (354 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ilya Leoshkevich, Heiko Carstens,
Jens Remus, Vasily Gorbik, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jens Remus <jremus@linux.ibm.com>
[ Upstream commit dc161efb6df8518b3cfa7f0a5efdc16a1aee815b ]
Commit 2b2a25845d53 ("s390/vdso: Use $(LD) instead of $(CC) to link
vDSO") accidentally broke the GNU_EH_FRAME program table entry in
the vDSO, causing it to be empty:
$ readelf --program-headers arch/s390/kernel/vdso/vdso.so
...
Program Headers:
Type Offset VirtAddr PhysAddr
FileSiz MemSiz Flags Align
...
GNU_EH_FRAME 0x0000000000000000 0x0000000000000000 0x0000000000000000
0x0000000000000000 0x0000000000000000 0x8
...
Originally, the compiler would implicitly add --eh-frame-hdr when
invoking the linker, but when this Makefile was converted from invoking
the linker via the compiler, to invoking it directly, the option was
missed.
This is the s390 variant of x86 commit cd01544a268a ("x86/vdso: Pass
--eh-frame-hdr to the linker").
Fixes: 2b2a25845d53 ("s390/vdso: Use $(LD) instead of $(CC) to link vDSO")
Reviewed-by: Ilya Leoshkevich <iii@linux.ibm.com>
Acked-by: Heiko Carstens <hca@linux.ibm.com>
Signed-off-by: Jens Remus <jremus@linux.ibm.com>
Signed-off-by: Vasily Gorbik <gor@linux.ibm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/s390/kernel/vdso/Makefile | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/arch/s390/kernel/vdso/Makefile b/arch/s390/kernel/vdso/Makefile
index 924be0a6a2df3..548ed3baf5a8a 100644
--- a/arch/s390/kernel/vdso/Makefile
+++ b/arch/s390/kernel/vdso/Makefile
@@ -34,7 +34,8 @@ KBUILD_CFLAGS_VDSO := $(filter-out -fno-asynchronous-unwind-tables,$(KBUILD_CFLA
KBUILD_CFLAGS_VDSO += -m64 -fPIC -fno-common -fno-builtin -fasynchronous-unwind-tables
KBUILD_CFLAGS_VDSO += -fno-stack-protector
ldflags-y := -shared -soname=linux-vdso.so.1 \
- --hash-style=both --build-id=sha1 -T
+ --hash-style=both --build-id=sha1 \
+ $(call ld-option, --eh-frame-hdr) -T
$(targets:%=$(obj)/%.dbg): KBUILD_CFLAGS = $(KBUILD_CFLAGS_VDSO)
$(targets:%=$(obj)/%.dbg): KBUILD_AFLAGS = $(KBUILD_AFLAGS_VDSO)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0645/1518] platform/chrome: cros_ec_debugfs: Clean up console log on probe failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (643 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0644/1518] s390/vdso: Pass --eh-frame-hdr to the linker Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0646/1518] platform/chrome: cros_ec_debugfs: Unregister panic notifier Greg Kroah-Hartman
` (353 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Hongyan Xu, Tzung-Bi Shih,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hongyan Xu <getshell@seu.edu.cn>
[ Upstream commit 5d187600c4603b8f7812b12ce359a11ad7a7fd3a ]
Add a dedicated error label for failures after successful console log
setup.
Fixes: d90fa2c64d59 ("platform/chrome: cros_ec: Poll EC log on EC panic")
Signed-off-by: Hongyan Xu <getshell@seu.edu.cn>
Link: https://lore.kernel.org/r/c00974953a1b952f51f0f021d7f9fad134159909.1785320940.git.getshell@seu.edu.cn
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/platform/chrome/cros_ec_debugfs.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/platform/chrome/cros_ec_debugfs.c b/drivers/platform/chrome/cros_ec_debugfs.c
index d10f9561990c8..01993ad696b04 100644
--- a/drivers/platform/chrome/cros_ec_debugfs.c
+++ b/drivers/platform/chrome/cros_ec_debugfs.c
@@ -513,7 +513,7 @@ static int cros_ec_debugfs_probe(struct platform_device *pd)
ret = blocking_notifier_chain_register(&ec->ec_dev->panic_notifier,
&debug_info->notifier_panic);
if (ret)
- goto remove_debugfs;
+ goto cleanup_console_log;
ec->debug_info = debug_info;
@@ -521,6 +521,8 @@ static int cros_ec_debugfs_probe(struct platform_device *pd)
return 0;
+cleanup_console_log:
+ cros_ec_cleanup_console_log(debug_info);
remove_debugfs:
debugfs_remove_recursive(debug_info->dir);
return ret;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0646/1518] platform/chrome: cros_ec_debugfs: Unregister panic notifier
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (644 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0645/1518] platform/chrome: cros_ec_debugfs: Clean up console log on probe failure Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0647/1518] wifi: rtlwifi: pci: fix error path in rtl_pci_probe() Greg Kroah-Hartman
` (352 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Hongyan Xu, Tzung-Bi Shih,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hongyan Xu <getshell@seu.edu.cn>
[ Upstream commit e5954d3031fb55dd31aa59bae477d63c68e941c0 ]
cros_ec_debugfs_probe() registers notifier_panic with the EC panic
notifier chain. The remove path tears down debugfs and the console log,
but leaves the notifier registered. A later panic notification can call
back into the removed instance and queue work that accesses released
data.
Unregister the panic notifier before tearing down the debugfs and
console log state.
This issue was found by a static analysis tool.
Fixes: d90fa2c64d59 ("platform/chrome: cros_ec: Poll EC log on EC panic")
Signed-off-by: Hongyan Xu <getshell@seu.edu.cn>
Link: https://lore.kernel.org/r/f3ab74ef8034be63bb45a325f3d54656d658817f.1785320940.git.getshell@seu.edu.cn
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/platform/chrome/cros_ec_debugfs.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/platform/chrome/cros_ec_debugfs.c b/drivers/platform/chrome/cros_ec_debugfs.c
index 01993ad696b04..e482b23b9f635 100644
--- a/drivers/platform/chrome/cros_ec_debugfs.c
+++ b/drivers/platform/chrome/cros_ec_debugfs.c
@@ -532,6 +532,8 @@ static void cros_ec_debugfs_remove(struct platform_device *pd)
{
struct cros_ec_dev *ec = dev_get_drvdata(pd->dev.parent);
+ blocking_notifier_chain_unregister(&ec->ec_dev->panic_notifier,
+ &ec->debug_info->notifier_panic);
debugfs_remove_recursive(ec->debug_info->dir);
cros_ec_cleanup_console_log(ec->debug_info);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0647/1518] wifi: rtlwifi: pci: fix error path in rtl_pci_probe()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (645 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0646/1518] platform/chrome: cros_ec_debugfs: Unregister panic notifier Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0648/1518] bus: mhi: host: Flush the posted write after writing to MHI_SOC_RESET_REQ_OFFSET Greg Kroah-Hartman
` (351 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Abdun Nihaal, Ping-Ke Shih,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Abdun Nihaal <nihaal@cse.iitm.ac.in>
[ Upstream commit 3c2999d13eeb222ae56631aeb7ca248090f2b210 ]
In the last error path in rtl_pci_probe(), the cleanup functions are
skipped due to a wrong goto label. Moreover, the successful call to
rtl_init_rfkill(), ieee80211_register_hw(), rtl_debug_add_one() have to
be reverted. Fix this issue by updating the labels and adding the
relevant cleanup functions to the last error path.
Fixes: 0c8173385e54 ("rtl8192ce: Add new driver")
Signed-off-by: Abdun Nihaal <nihaal@cse.iitm.ac.in>
Acked-by: Ping-Ke Shih <pkshih@realtek.com>
Signed-off-by: Ping-Ke Shih <pkshih@realtek.com>
Link: https://patch.msgid.link/20260723120118.145383-1-nihaal@cse.iitm.ac.in
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/realtek/rtlwifi/pci.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/realtek/rtlwifi/pci.c b/drivers/net/wireless/realtek/rtlwifi/pci.c
index f0010336e78c1..8fb9604c3c533 100644
--- a/drivers/net/wireless/realtek/rtlwifi/pci.c
+++ b/drivers/net/wireless/realtek/rtlwifi/pci.c
@@ -2226,13 +2226,17 @@ int rtl_pci_probe(struct pci_dev *pdev,
rtl_dbg(rtlpriv, COMP_INIT, DBG_DMESG,
"%s: failed to register IRQ handler\n",
wiphy_name(hw->wiphy));
- goto fail3;
+ goto fail6;
}
rtlpci->irq_alloc = 1;
set_bit(RTL_STATUS_INTERFACE_START, &rtlpriv->status);
return 0;
+fail6:
+ rtl_deinit_rfkill(hw);
+ rtl_debug_remove_one(hw);
+ ieee80211_unregister_hw(hw);
fail5:
rtl_pci_deinit(hw);
fail4:
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0648/1518] bus: mhi: host: Flush the posted write after writing to MHI_SOC_RESET_REQ_OFFSET
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (646 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0647/1518] wifi: rtlwifi: pci: fix error path in rtl_pci_probe() Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0649/1518] bus: mhi: host: Fix controller cleanup on EDL sysfs failure Greg Kroah-Hartman
` (350 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alex Williamson,
Manivannan Sadhasivam, Manivannan Sadhasivam, Jeff Hugo,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
[ Upstream commit 24f4423cbc89548def2b05ae86de6175086dbf94 ]
mhi_soc_reset() tries to reset the device by writing to the
MHI_SOC_RESET_REQ_OFFSET register. But it doesn't do a read-back to ensure
that the write gets flushed to the device before returning to the caller.
This may lead to the delay (if implemented) on the caller to be
insufficient, if the posted write doesn't reach the device before the
delay.
So add a read-back after writing to the MHI_SOC_RESET_REQ_OFFSET register.
Fixes: b5a8d233a588 ("bus: mhi: core: Add device hardware reset support")
Reported-by: Alex Williamson <alex@shazbot.org>
Closes: https://lore.kernel.org/linux-pci/20260622160822.09350246@shazbot.org
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Signed-off-by: Manivannan Sadhasivam <mani@kernel.org>
Reviewed-by: Jeff Hugo <jeff.hugo@oss.qualcomm.com>
Link: https://patch.msgid.link/20260623145134.43976-1-manivannan.sadhasivam@oss.qualcomm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bus/mhi/host/main.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/bus/mhi/host/main.c b/drivers/bus/mhi/host/main.c
index 8615512743199..eeb277dee7486 100644
--- a/drivers/bus/mhi/host/main.c
+++ b/drivers/bus/mhi/host/main.c
@@ -170,6 +170,9 @@ EXPORT_SYMBOL_GPL(mhi_get_mhi_state);
void mhi_soc_reset(struct mhi_controller *mhi_cntrl)
{
+ int __maybe_unused ret;
+ u32 tmp;
+
if (mhi_cntrl->reset) {
mhi_cntrl->reset(mhi_cntrl);
return;
@@ -178,6 +181,9 @@ void mhi_soc_reset(struct mhi_controller *mhi_cntrl)
/* Generic MHI SoC reset */
mhi_write_reg(mhi_cntrl, mhi_cntrl->regs, MHI_SOC_RESET_REQ_OFFSET,
MHI_SOC_RESET_REQ);
+ /* Flush the posted write to the device (ignore return value) */
+ ret = mhi_read_reg(mhi_cntrl, mhi_cntrl->regs, MHI_SOC_RESET_REQ_OFFSET,
+ &tmp);
}
EXPORT_SYMBOL_GPL(mhi_soc_reset);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0649/1518] bus: mhi: host: Fix controller cleanup on EDL sysfs failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (647 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0648/1518] bus: mhi: host: Flush the posted write after writing to MHI_SOC_RESET_REQ_OFFSET Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0650/1518] md/raid5: protect bitmap batch counters aka seq_flush/seq_write consistency Greg Kroah-Hartman
` (349 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yuho Choi, Manivannan Sadhasivam,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuho Choi <dbgh9129@gmail.com>
[ Upstream commit 0d5b9e66591d4e2a4376ac82c8cda889a29ba3ee ]
mhi_register_controller() adds the controller device before creating the
optional trigger_edl sysfs file. If sysfs_create_file() fails, the error
path only drops the device reference and leaves the device registered.
Hence, call device_del() in the error path before put_device().
Fixes: 17553ba8e19d ("bus: mhi: host: Add sysfs entry to force device to enter EDL")
Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bus/mhi/host/init.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/bus/mhi/host/init.c b/drivers/bus/mhi/host/init.c
index 099be8dd19007..504a5d3f78309 100644
--- a/drivers/bus/mhi/host/init.c
+++ b/drivers/bus/mhi/host/init.c
@@ -1042,7 +1042,7 @@ int mhi_register_controller(struct mhi_controller *mhi_cntrl,
if (mhi_cntrl->edl_trigger) {
ret = sysfs_create_file(&mhi_dev->dev.kobj, &dev_attr_trigger_edl.attr);
if (ret)
- goto err_release_dev;
+ goto err_del_dev;
}
mhi_cntrl->mhi_dev = mhi_dev;
@@ -1051,6 +1051,8 @@ int mhi_register_controller(struct mhi_controller *mhi_cntrl,
return 0;
+err_del_dev:
+ device_del(&mhi_dev->dev);
err_release_dev:
put_device(&mhi_dev->dev);
error_setup_irq:
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0650/1518] md/raid5: protect bitmap batch counters aka seq_flush/seq_write consistency
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (648 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0649/1518] bus: mhi: host: Fix controller cleanup on EDL sysfs failure Greg Kroah-Hartman
@ 2026-09-12 6:46 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0651/1518] md/raid5-ppl: fix use-after-free in ppl_do_flush() Greg Kroah-Hartman
` (348 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:46 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Chen Cheng, Yu Kuai, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chen Cheng <chencheng@fnnas.com>
[ Upstream commit f565925810cb8bc799421485770e15d922ef766a ]
kcsan detect race :
- raid5d() closes the current bitmap batch by updating
conf->seq_flush under conf->device_lock.
- __add_stripe_bio() read conf->seq_flush without that
lock when assigning sh->bm_seq.
so, protect seq_flush/seq_write consistency for multiple CPUs by
READ_ONCE()/WRITE_ONCE() under the path without held device_lock.
re-explain the stripe batch sequence number update flow:
1. sh->bm_seq declare which batch number the stripe belongs to
when perform bitmap-related write.
==> bm_seq = seq_flush+1
2. stripe be handled,
* if sh->bm_seq - conf->seq_write > 0, means the
batch stripes **newer than** the last written
batch, it cannot proceed yet, queued on bitmap_list.
* otherwise , has already proceed.
3. raid5d() `++seq_flush` to closes the current batch, means
* no more stripes join that old batch
* just-closed batch ready to write-out to disk
4. raid5d() calls bitmap hooks unplug() or writeout, then,
`++seq_write` to the same as bm_seq.
- seq_flush - for producer, to close batches.
- seq_write - for consumer, the checkpoint number.
the report:
====================================
BUG: KCSAN: data-race in __add_stripe_bio / raid5d
write to 0xffff88ba5625d470 of 4 bytes by task 82401 on cpu 0:
raid5d+0x1d9/0xba0
[.....]
read to 0xffff88ba5625d470 of 4 bytes by task 82421 on cpu 8:
__add_stripe_bio+0x332/0x400
raid5_make_request+0x6ac/0x2930
md_handle_request+0x4a2/0xa40
md_submit_bio+0x109/0x1a0
__submit_bio+0x2ec/0x390
[.....]
Fixes: 7c13edc87510 ("md: incorporate new plugging into raid5.")
v1 -> v2:
- remove WRITE_ONCE(conf->seq_write) in held device_lock path.
- remove READ_ONCE(conf->seq_flush) in held device_lock path.
Signed-off-by: Chen Cheng <chencheng@fnnas.com>
Reviewed-by: Yu Kuai <yukuai@fygo.io>
Link: https://patch.msgid.link/20260622124649.1780233-1-chencheng@fnnas.com
Signed-off-by: Yu Kuai <yukuai@fygo.io>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/md/raid5.c | 10 ++++++----
1 file changed, 6 insertions(+), 4 deletions(-)
diff --git a/drivers/md/raid5.c b/drivers/md/raid5.c
index b19d870e41719..98763a349fba0 100644
--- a/drivers/md/raid5.c
+++ b/drivers/md/raid5.c
@@ -3541,7 +3541,7 @@ static void __add_stripe_bio(struct stripe_head *sh, struct bio *bi,
sh->dev[dd_idx].sector);
if (conf->mddev->bitmap && firstwrite && !sh->batch_head) {
- sh->bm_seq = conf->seq_flush+1;
+ sh->bm_seq = READ_ONCE(conf->seq_flush) + 1;
set_bit(STRIPE_BIT_DELAY, &sh->state);
}
}
@@ -5767,7 +5767,7 @@ static void make_discard_request(struct mddev *mddev, struct bio *bi)
}
spin_unlock_irq(&sh->stripe_lock);
if (conf->mddev->bitmap) {
- sh->bm_seq = conf->seq_flush + 1;
+ sh->bm_seq = READ_ONCE(conf->seq_flush) + 1;
set_bit(STRIPE_BIT_DELAY, &sh->state);
}
@@ -6802,12 +6802,14 @@ static void raid5d(struct md_thread *thread)
if (
!list_empty(&conf->bitmap_list)) {
/* Now is a good time to flush some bitmap updates */
- conf->seq_flush++;
+ int seq = conf->seq_flush + 1;
+
+ WRITE_ONCE(conf->seq_flush, seq);
spin_unlock_irq(&conf->device_lock);
if (md_bitmap_enabled(mddev, true))
mddev->bitmap_ops->unplug(mddev, true);
spin_lock_irq(&conf->device_lock);
- conf->seq_write = conf->seq_flush;
+ conf->seq_write = seq;
activate_bit_delay(conf, conf->temp_inactive_list);
}
raid5_activate_delayed(conf);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0651/1518] md/raid5-ppl: fix use-after-free in ppl_do_flush()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (649 preceding siblings ...)
2026-09-12 6:46 ` [PATCH 6.18 0650/1518] md/raid5: protect bitmap batch counters aka seq_flush/seq_write consistency Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0652/1518] md/raid5: protect lockless recovery_offset accesses during reshape Greg Kroah-Hartman
` (347 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dan Carpenter, Sajal Gupta, Yu Kuai,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sajal Gupta <sajal2005gupta@gmail.com>
[ Upstream commit 371f7a1b392edc8b7cf449cc7713179b588f2d0e ]
The loop in ppl_do_flush() continues iterating after calling
ppl_io_unit_finished(), touching io->pending_flushes and leading to a
use-after-free.
Add a break statement to stop the loop once io is freed.
Fixes: 1532d9e87e8b ("raid5-ppl: PPL support for disks with write-back cache enabled")
Reported-by: Dan Carpenter <error27@gmail.com>
Closes: https://lore.kernel.org/all/ajJF2wKYWRk4GGCK@stanley.mountain/
Signed-off-by: Sajal Gupta <sajal2005gupta@gmail.com>
Reviewed-by: Yu Kuai <yukuai@fygo.io>
Link: https://patch.msgid.link/20260622142146.56637-1-sajal2005gupta@gmail.com
Signed-off-by: Yu Kuai <yukuai@fygo.io>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/md/raid5-ppl.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/md/raid5-ppl.c b/drivers/md/raid5-ppl.c
index 56b234683ee6b..2678e82bfa52d 100644
--- a/drivers/md/raid5-ppl.c
+++ b/drivers/md/raid5-ppl.c
@@ -643,8 +643,10 @@ static void ppl_do_flush(struct ppl_io_unit *io)
log->disk_flush_bitmap = 0;
for (i = flushed_disks ; i < raid_disks; i++) {
- if (atomic_dec_and_test(&io->pending_flushes))
+ if (atomic_dec_and_test(&io->pending_flushes)) {
ppl_io_unit_finished(io);
+ break;
+ }
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0652/1518] md/raid5: protect lockless recovery_offset accesses during reshape
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (650 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0651/1518] md/raid5-ppl: fix use-after-free in ppl_do_flush() Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0653/1518] fanotify: stop permission watchdog when timeout is zero Greg Kroah-Hartman
` (346 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Chen Cheng, Yu Kuai, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chen Cheng <chencheng@fnnas.com>
[ Upstream commit a47431dfb3538a1485f65b68a0605a05307b5b2d ]
During reshape:
- reshape_request() advances rdev->recovery_offset for non-In_sync
devices locklessly.
- analyse_stripe() reads rdev->recovery_offset locklessly to decide:
a. use a replacement device to read ?
b. a device can already be treated as in-sync for the current
stripe ?
one possible scenario is:
CPU1 CPU2
reshape_request()
-> mddev->curr_resync_completed = sector_nr
-> if (!mddev->reshape_backwards)
-> rdev->recovery_offset = sector_nr
analyse_stripe(sh)
-> rdev = conf->disks[i].replacement
-> if (rdev->recovery_offset >=
sh->sector + stripe_sectors)
set_bit(R5_ReadRepl)
-> or
-> if (sh->sector + stripe_sectors <=
rdev->recovery_offset)
set_bit(R5_Insync)
And it could be:
- reading from a replacement before it is recovered far enough; or
- treating a not-yet-recovered device as in-sync for the current stripe.
Fixes: db0505d32066 ("md: be cautious about using ->curr_resync_completed for ->recovery_offset")
The race report:
==================================================================
BUG: KCSAN: data-race in ops_run_io / reshape_request
write to 0xffff8bdee168b270 of 8 bytes by task 1704 on cpu 10:
reshape_request+0x1292/0x17b0
raid5_sync_request+0x815/0xa00
md_do_sync.cold+0xf8d/0x1516
[......]
read to 0xffff8bdee168b270 of 8 bytes by task 1696 on cpu 9:
ops_run_io+0xc25/0x1960
handle_stripe+0x2273/0x4570
handle_active_stripes.isra.0+0x6e0/0xa50
raid5d+0x7d5/0xb90
[......]
value changed: 0x0000000000091a00 -> 0x0000000000091b00
==================================================================
Signed-off-by: Chen Cheng <chencheng@fnnas.com>
Reviewed-by: Yu Kuai <yukuai@fygo.io>
Link: https://patch.msgid.link/20260627102519.136940-1-chencheng@fnnas.com
Signed-off-by: Yu Kuai <yukuai@fygo.io>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/md/raid5.c | 50 +++++++++++++++++++++++-----------------------
1 file changed, 25 insertions(+), 25 deletions(-)
diff --git a/drivers/md/raid5.c b/drivers/md/raid5.c
index 98763a349fba0..3fbf66c9b45ed 100644
--- a/drivers/md/raid5.c
+++ b/drivers/md/raid5.c
@@ -3740,11 +3740,10 @@ static int want_replace(struct stripe_head *sh, int disk_idx)
int rv = 0;
rdev = sh->raid_conf->disks[disk_idx].replacement;
- if (rdev
- && !test_bit(Faulty, &rdev->flags)
- && !test_bit(In_sync, &rdev->flags)
- && (rdev->recovery_offset <= sh->sector
- || rdev->mddev->resync_offset <= sh->sector))
+ if (rdev && !test_bit(Faulty, &rdev->flags) &&
+ !test_bit(In_sync, &rdev->flags) &&
+ (READ_ONCE(rdev->recovery_offset) <= sh->sector ||
+ rdev->mddev->resync_offset <= sh->sector))
rv = 1;
return rv;
}
@@ -4673,7 +4672,8 @@ static void analyse_stripe(struct stripe_head *sh, struct stripe_head_state *s)
*/
rdev = conf->disks[i].replacement;
if (rdev && !test_bit(Faulty, &rdev->flags) &&
- rdev->recovery_offset >= sh->sector + RAID5_STRIPE_SECTORS(conf) &&
+ READ_ONCE(rdev->recovery_offset) >=
+ sh->sector + RAID5_STRIPE_SECTORS(conf) &&
!rdev_has_badblock(rdev, sh->sector,
RAID5_STRIPE_SECTORS(conf)))
set_bit(R5_ReadRepl, &dev->flags);
@@ -4715,7 +4715,7 @@ static void analyse_stripe(struct stripe_head *sh, struct stripe_head_state *s)
} else if (test_bit(In_sync, &rdev->flags))
set_bit(R5_Insync, &dev->flags);
else if (sh->sector + RAID5_STRIPE_SECTORS(conf) <=
- rdev->recovery_offset) {
+ READ_ONCE(rdev->recovery_offset)) {
/*
* in sync if:
* - normal IO, or
@@ -5448,13 +5448,13 @@ static int raid5_read_one_chunk(struct mddev *mddev, struct bio *raid_bio)
rdev = conf->disks[dd_idx].replacement;
if (!rdev || test_bit(Faulty, &rdev->flags) ||
- rdev->recovery_offset < end_sector) {
+ READ_ONCE(rdev->recovery_offset) < end_sector) {
rdev = conf->disks[dd_idx].rdev;
if (!rdev)
return 0;
if (test_bit(Faulty, &rdev->flags) ||
!(test_bit(In_sync, &rdev->flags) ||
- rdev->recovery_offset >= end_sector))
+ READ_ONCE(rdev->recovery_offset) >= end_sector))
return 0;
}
@@ -6380,8 +6380,8 @@ static sector_t reshape_request(struct mddev *mddev, sector_t sector_nr, int *sk
if (rdev->raid_disk >= 0 &&
!test_bit(Journal, &rdev->flags) &&
!test_bit(In_sync, &rdev->flags) &&
- rdev->recovery_offset < sector_nr)
- rdev->recovery_offset = sector_nr;
+ READ_ONCE(rdev->recovery_offset) < sector_nr)
+ WRITE_ONCE(rdev->recovery_offset, sector_nr);
conf->reshape_checkpoint = jiffies;
set_bit(MD_SB_CHANGE_DEVS, &mddev->sb_flags);
@@ -6489,8 +6489,8 @@ static sector_t reshape_request(struct mddev *mddev, sector_t sector_nr, int *sk
if (rdev->raid_disk >= 0 &&
!test_bit(Journal, &rdev->flags) &&
!test_bit(In_sync, &rdev->flags) &&
- rdev->recovery_offset < sector_nr)
- rdev->recovery_offset = sector_nr;
+ READ_ONCE(rdev->recovery_offset) < sector_nr)
+ WRITE_ONCE(rdev->recovery_offset, sector_nr);
conf->reshape_checkpoint = jiffies;
set_bit(MD_SB_CHANGE_DEVS, &mddev->sb_flags);
md_wakeup_thread(mddev->thread);
@@ -8001,9 +8001,9 @@ static int raid5_run(struct mddev *mddev)
/* Hack because v0.91 doesn't store recovery_offset properly. */
if (mddev->major_version == 0 &&
mddev->minor_version > 90)
- rdev->recovery_offset = reshape_offset;
+ WRITE_ONCE(rdev->recovery_offset, reshape_offset);
- if (rdev->recovery_offset < reshape_offset) {
+ if (READ_ONCE(rdev->recovery_offset) < reshape_offset) {
/* We need to check old and new layout */
if (!only_parity(rdev->raid_disk,
conf->algorithm,
@@ -8154,10 +8154,10 @@ static int raid5_spare_active(struct mddev *mddev)
for (i = 0; i < conf->raid_disks; i++) {
rdev = conf->disks[i].rdev;
replacement = conf->disks[i].replacement;
- if (replacement
- && replacement->recovery_offset == MaxSector
- && !test_bit(Faulty, &replacement->flags)
- && !test_and_set_bit(In_sync, &replacement->flags)) {
+ if (replacement &&
+ READ_ONCE(replacement->recovery_offset) == MaxSector &&
+ !test_bit(Faulty, &replacement->flags) &&
+ !test_and_set_bit(In_sync, &replacement->flags)) {
/* Replacement has just become active. */
if (!rdev
|| !test_and_clear_bit(In_sync, &rdev->flags))
@@ -8172,10 +8172,10 @@ static int raid5_spare_active(struct mddev *mddev)
rdev->sysfs_state);
}
sysfs_notify_dirent_safe(replacement->sysfs_state);
- } else if (rdev
- && rdev->recovery_offset == MaxSector
- && !test_bit(Faulty, &rdev->flags)
- && !test_and_set_bit(In_sync, &rdev->flags)) {
+ } else if (rdev &&
+ READ_ONCE(rdev->recovery_offset) == MaxSector &&
+ !test_bit(Faulty, &rdev->flags) &&
+ !test_and_set_bit(In_sync, &rdev->flags)) {
count++;
sysfs_notify_dirent_safe(rdev->sysfs_state);
}
@@ -8547,7 +8547,7 @@ static int raid5_start_reshape(struct mddev *mddev)
>= conf->previous_raid_disks)
set_bit(In_sync, &rdev->flags);
else
- rdev->recovery_offset = 0;
+ WRITE_ONCE(rdev->recovery_offset, 0);
/* Failure here is OK */
sysfs_link_rdev(mddev, rdev);
@@ -8599,7 +8599,7 @@ static void end_reshape(struct r5conf *conf)
if (rdev->raid_disk >= 0 &&
!test_bit(Journal, &rdev->flags) &&
!test_bit(In_sync, &rdev->flags))
- rdev->recovery_offset = MaxSector;
+ WRITE_ONCE(rdev->recovery_offset, MaxSector);
spin_unlock_irq(&conf->device_lock);
wake_up(&conf->wait_for_reshape);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0653/1518] fanotify: stop permission watchdog when timeout is zero
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (651 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0652/1518] md/raid5: protect lockless recovery_offset accesses during reshape Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0654/1518] tools/nolibc/powerpc: mark ctr and xer as clobbered by system call Greg Kroah-Hartman
` (345 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yichong Chen, Jan Kara, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yichong Chen <chenyichong@uniontech.com>
[ Upstream commit 17463fe751309330b74618560f181426f643aa3d ]
The fanotify permission watchdog can be disabled by writing zero to
fs/fanotify/watchdog_timeout. fanotify_perm_watchdog_group_add() already
checks for a zero timeout before scheduling the watchdog.
However, once the watchdog work has been scheduled, perm_group_watchdog()
unconditionally schedules itself again with the current timeout. If the
sysctl is changed to zero while the work is active, secs_to_jiffies(0)
causes the work to be rescheduled immediately, resulting in a kworker
busy loop.
Read the timeout once in perm_group_watchdog_schedule() and do not
schedule the work when it is zero. This lets a running watchdog stop
after the next execution when the sysctl is set to zero.
Fixes: b8cf8fda522d ("fanotify: add watchdog for permission events")
Signed-off-by: Yichong Chen <chenyichong@uniontech.com>
Link: https://patch.msgid.link/20260730070648.549458-1-chenyichong@uniontech.com
Signed-off-by: Jan Kara <jack@suse.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/notify/fanotify/fanotify_user.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/fs/notify/fanotify/fanotify_user.c b/fs/notify/fanotify/fanotify_user.c
index eb808eda11f2f..9dbe33cf2ceaa 100644
--- a/fs/notify/fanotify/fanotify_user.c
+++ b/fs/notify/fanotify/fanotify_user.c
@@ -111,7 +111,12 @@ static DECLARE_DELAYED_WORK(perm_group_work, perm_group_watchdog);
static void perm_group_watchdog_schedule(void)
{
- schedule_delayed_work(&perm_group_work, secs_to_jiffies(perm_group_timeout));
+ int timeout = READ_ONCE(perm_group_timeout);
+
+ if (!timeout)
+ return;
+
+ schedule_delayed_work(&perm_group_work, secs_to_jiffies(timeout));
}
static void perm_group_watchdog(struct work_struct *work)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0654/1518] tools/nolibc/powerpc: mark ctr and xer as clobbered by system call
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (652 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0653/1518] fanotify: stop permission watchdog when timeout is zero Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0655/1518] md: recheck spare changes before starting sync Greg Kroah-Hartman
` (344 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Thomas Weißschuh,
Thomas Weißschuh, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Weißschuh <thomas.weissschuh@linutronix.de>
[ Upstream commit b9fc5a1742b0c8fb7edf066cc17fa0b18b7be623 ]
The system call can clobber the ctr and xer registers.
Make sure the compiler takes this into account.
The missing clobbers only seem to be an issue with newer compilers.
Fixes: 0cb0675ec37e ("tools/nolibc: add support for powerpc")
Signed-off-by: Thomas Weißschuh <thomas.weissschuh@linutronix.de>
Link: https://patch.msgid.link/20260727-nolibc-powerpc-clobber-v1-1-e0911cc99ce1@linutronix.de
Signed-off-by: Thomas Weißschuh <linux@weissschuh.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/include/nolibc/arch-powerpc.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/include/nolibc/arch-powerpc.h b/tools/include/nolibc/arch-powerpc.h
index 204564bbcd328..c7d7a72c16dc6 100644
--- a/tools/include/nolibc/arch-powerpc.h
+++ b/tools/include/nolibc/arch-powerpc.h
@@ -23,7 +23,7 @@
*/
#define _NOLIBC_SYSCALL_CLOBBERLIST \
- "memory", "cr0", "r12", "r11", "r10", "r9"
+ "memory", "cr0", "ctr", "xer", "r12", "r11", "r10", "r9"
#define my_syscall0(num) \
({ \
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0655/1518] md: recheck spare changes before starting sync
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (653 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0654/1518] tools/nolibc/powerpc: mark ctr and xer as clobbered by system call Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0656/1518] selftests/zram: fix kernel_gte() for POSIX sh Greg Kroah-Hartman
` (343 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot, Abd-Alrhman Masalkhi,
Yu Kuai, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com>
[ Upstream commit c7d34d17ea43ebc86b45d439ebb435e11ca44bca ]
remove_spares() and remove_and_add_spares() modify the array's rdev
configuration. These operations are only safe after the array has been
suspended.
md_start_sync() checks whether spare configuration changes are needed
before taking reconfig_mutex. However, the rdev state can change before
the mutex is acquired, so the initial check can become stale. In that
case, md_choose_sync_action() may remove or replace rdevs while normal
I/O is still accessing them.
The race can occur as follows:
raid10d Worker Normal IO
____________ _______________________ ______________________
raid10_write_request()
wait_blocked_dev()
set Blocked
set Faulty
Skip Faulty rdev
rrdev->nr_pending++
.repl_bio = bio
removeable_rdev = false .
array not suspended .
lock mddev goto err_handle
lock mddev (wait)
.
update sb .
clear Blocked .
.
unlock mddev .
lock mddev (acquires)
remove_spares()
removeable_rdev = true
raid10_remove_disk()
rdev = replacement
replacement = NULL
rdev_dec_pending(NULL)
unlock mddev (NULL)->nr_pending--
In this case, rdev_dec_pending() is called with a NULL pointer,
resulting in a NULL pointer dereference when attempting to decrement
nr_pending.
Fix this by suspending the array when spare configuration changes are
needed, including for non-read-write arrays, and checking again after
taking reconfig_mutex. If the array was not already suspended and a
change is now needed, release the mutex, suspend the array, and
reacquire the mutex before continuing.
Fixes: bc08041b32ab ("md: suspend array in md_start_sync() if array need reconfiguration")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/20260628142420.1051027-1-abd.masalkhi@gmail.com?part=3
Signed-off-by: Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com>
Reviewed-by: Yu Kuai <yukuai@fygo.io>
Link: https://patch.msgid.link/20260708112003.474537-1-abd.masalkhi@gmail.com
Signed-off-by: Yu Kuai <yukuai@fygo.io>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/md/md.c | 14 +++++++++++++-
1 file changed, 13 insertions(+), 1 deletion(-)
diff --git a/drivers/md/md.c b/drivers/md/md.c
index 5304e920dbcc5..36862dbaf253f 100644
--- a/drivers/md/md.c
+++ b/drivers/md/md.c
@@ -10077,13 +10077,25 @@ static void md_start_sync(struct work_struct *ws)
* If reshape is still in progress, spares won't be added or removed
* from conf until reshape is done.
*/
- if (mddev->reshape_position == MaxSector &&
+ if ((mddev->reshape_position == MaxSector || !md_is_rdwr(mddev)) &&
md_spares_need_change(mddev)) {
suspend = true;
mddev_suspend(mddev, false);
}
mddev_lock_nointr(mddev);
+
+ /*
+ * The spare configuration can change before reconfig_mutex is acquired.
+ * Recheck while holding the lock and suspend if needed.
+ */
+ if (!suspend && (mddev->reshape_position == MaxSector || !md_is_rdwr(mddev)) &&
+ md_spares_need_change(mddev)) {
+ mddev_unlock(mddev);
+ mddev_suspend_and_lock_nointr(mddev);
+ suspend = true;
+ }
+
if (!md_is_rdwr(mddev)) {
/*
* On a read-only array we can:
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0656/1518] selftests/zram: fix kernel_gte() for POSIX sh
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (654 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0655/1518] md: recheck spare changes before starting sync Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0657/1518] Revert "serial: 8250: Clear CON_PRINTBUFFER on port re-registration" Greg Kroah-Hartman
` (342 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Cheng-Han Wu, Shuah Khan,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cheng-Han Wu <hank20010209@gmail.com>
[ Upstream commit 649ba27dfac784427a01f9c95c09ecbcb88900d8 ]
Commit fc4eb486a59d ("selftests/zram: Skip max_comp_streams
interface on newer kernel") added kernel_gte() to zram_lib.sh.
The function uses the bash-specific [[ ... ]] conditional, but
zram selftests source this file while running under /bin/sh.
On systems where /bin/sh is dash, such as Debian, the following
test fails:
dash -c '
kernel_major=6; kernel_minor=1; major=6; minor=0
if [ $kernel_major -gt $major ]; then
echo ok
elif [[ $kernel_major -eq $major && $kernel_minor -ge $minor ]]; then
echo ok
fi'
with:
dash: 5: [[: not found
Use separate POSIX test expressions joined by && instead.
Fixes: fc4eb486a59d ("selftests/zram: Skip max_comp_streams interface on newer kernel")
Signed-off-by: Cheng-Han Wu <hank20010209@gmail.com>
Signed-off-by: Shuah Khan <skhan@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/zram/zram_lib.sh | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/testing/selftests/zram/zram_lib.sh b/tools/testing/selftests/zram/zram_lib.sh
index 21ec1966de76c..0d44d83888f9d 100755
--- a/tools/testing/selftests/zram/zram_lib.sh
+++ b/tools/testing/selftests/zram/zram_lib.sh
@@ -37,7 +37,7 @@ kernel_gte()
if [ $kernel_major -gt $major ]; then
return 0
- elif [[ $kernel_major -eq $major && $kernel_minor -ge $minor ]]; then
+ elif [ $kernel_major -eq $major ] && [ $kernel_minor -ge $minor ]; then
return 0
fi
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0657/1518] Revert "serial: 8250: Clear CON_PRINTBUFFER on port re-registration"
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (655 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0656/1518] selftests/zram: fix kernel_gte() for POSIX sh Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0658/1518] wifi: ath12k: fix stride mismatch in mac_phy_caps_parse() Greg Kroah-Hartman
` (341 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mark Brown, Anirudh Srinivasan,
Fushuai Wang, John Ogness, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Fushuai Wang <wangfushuai@baidu.com>
[ Upstream commit 57c0741b8c15b93ba4aa92c6618cde6f3f4115b2 ]
This reverts commit d338ab1d90603f875c4f7ed223406535378173a5.
uart_console() only indicates that the port is selected as the console.
It does not mean that the console has already been registered or has
printed the buffered messages.
On platforms where an initial 8250 port is replaced when the real UART
device is registered, clearing CON_PRINTBUFFER causes the console to
start at the end of the printk ring buffer. Without earlycon, all
messages logged before UART registration are therefore lost.
Fixes: d338ab1d9060 ("serial: 8250: Clear CON_PRINTBUFFER on port re-registration")
Reported-by: Mark Brown <broonie@kernel.org>
Reported-by: Anirudh Srinivasan <asrinivasan@oss.tenstorrent.com>
Link: https://lore.kernel.org/all/20260522101042.21976-1-fushuai.wang@linux.dev/
Signed-off-by: Fushuai Wang <wangfushuai@baidu.com>
Reviewed-by: John Ogness <john.ogness@linutronix.de>
Link: https://patch.msgid.link/20260724093151.53216-1-fushuai.wang@linux.dev
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/tty/serial/8250/8250_core.c | 6 +-----
1 file changed, 1 insertion(+), 5 deletions(-)
diff --git a/drivers/tty/serial/8250/8250_core.c b/drivers/tty/serial/8250/8250_core.c
index b6568880f750d..ccd5a18f53356 100644
--- a/drivers/tty/serial/8250/8250_core.c
+++ b/drivers/tty/serial/8250/8250_core.c
@@ -716,12 +716,8 @@ int serial8250_register_8250_port(const struct uart_8250_port *up)
/* Preserve specified console flow control. */
cons_flow = uart_cons_flow_enabled(&uart->port);
- if (uart->port.dev) {
- if (uart_console(&uart->port))
- uart->port.cons->flags &= ~CON_PRINTBUFFER;
-
+ if (uart->port.dev)
uart_remove_one_port(&serial8250_reg, &uart->port);
- }
uart->port.ctrl_id = up->port.ctrl_id;
uart->port.port_id = up->port.port_id;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0658/1518] wifi: ath12k: fix stride mismatch in mac_phy_caps_parse()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (656 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0657/1518] Revert "serial: 8250: Clear CON_PRINTBUFFER on port re-registration" Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0659/1518] wifi: ath11k: " Greg Kroah-Hartman
` (340 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Baochen Qiang, Rameshkumar Sundaram,
Jeff Johnson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
[ Upstream commit 4c6eb712a91fa079be6f9f1419c96e0ad2227081 ]
Currently, in ath12k_wmi_mac_phy_caps_parse(), kzalloc() sizes the
mac_phy_caps buffer as tot_phy_id * len, where len is clamped to
min(firmware_len, sizeof(struct ath12k_wmi_mac_phy_caps_params)). The
subsequent memcpy() destination advances by sizeof(full struct) per slot
via C pointer arithmetic, not by the clamped len. When firmware sends
short TLVs, the second and later slots are written past the end of the
allocation.
The reader in ath12k_pull_mac_phy_cap_svc_ready_ext() also indexes the
buffer with full-struct pointer arithmetic, so the allocation must match
that stride.
Fix by using kzalloc_objs(), which derives the element size from the
pointer type, making allocation size and pointer stride provably
consistent regardless of what len the firmware provides.
Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3
Fixes: d889913205cf ("wifi: ath12k: driver for Qualcomm Wi-Fi 7 devices")
Assisted-by: Claude:claude-sonnet-4-6
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Link: https://patch.msgid.link/20260728-mac_phy_caps_parse-stride-mismatch-v1-1-27a9c1a3fbd0@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/ath/ath12k/wmi.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
diff --git a/drivers/net/wireless/ath/ath12k/wmi.c b/drivers/net/wireless/ath/ath12k/wmi.c
index 6221bf43936bc..f4392462ae3a2 100644
--- a/drivers/net/wireless/ath/ath12k/wmi.c
+++ b/drivers/net/wireless/ath/ath12k/wmi.c
@@ -4525,14 +4525,16 @@ static int ath12k_wmi_mac_phy_caps_parse(struct ath12k_base *soc,
if (svc_rdy_ext->n_mac_phy_caps >= svc_rdy_ext->tot_phy_id)
return -ENOBUFS;
- len = min_t(u16, len, sizeof(struct ath12k_wmi_mac_phy_caps_params));
if (!svc_rdy_ext->n_mac_phy_caps) {
- svc_rdy_ext->mac_phy_caps = kzalloc((svc_rdy_ext->tot_phy_id) * len,
- GFP_ATOMIC);
+ svc_rdy_ext->mac_phy_caps =
+ kzalloc_objs(*svc_rdy_ext->mac_phy_caps,
+ svc_rdy_ext->tot_phy_id,
+ GFP_ATOMIC);
if (!svc_rdy_ext->mac_phy_caps)
return -ENOMEM;
}
+ len = min_t(u16, len, sizeof(struct ath12k_wmi_mac_phy_caps_params));
memcpy(svc_rdy_ext->mac_phy_caps + svc_rdy_ext->n_mac_phy_caps, ptr, len);
svc_rdy_ext->n_mac_phy_caps++;
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0659/1518] wifi: ath11k: fix stride mismatch in mac_phy_caps_parse()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (657 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0658/1518] wifi: ath12k: fix stride mismatch in mac_phy_caps_parse() Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0660/1518] md/raid10: consistently fail atomic writes that require splitting Greg Kroah-Hartman
` (339 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Baochen Qiang, Rameshkumar Sundaram,
Jeff Johnson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
[ Upstream commit 7a246c72132eb943b5844ba79dad597b47429dba ]
Currently, in ath11k_wmi_tlv_mac_phy_caps_parse(), kcalloc() sizes the
mac_phy_caps buffer as tot_phy_id * len, where len is clamped to
min(firmware_len, sizeof(struct wmi_mac_phy_capabilities)). The subsequent
memcpy() destination advances by sizeof(full struct) per slot via C
pointer arithmetic, not by the clamped len. When firmware sends short
TLVs, the second and later slots are written past the end of the
allocation.
The reader in ath11k_pull_mac_phy_cap_svc_ready_ext() also indexes the
buffer with full-struct pointer arithmetic, so the allocation must match
that stride.
Fix by using kzalloc_objs(), which derives the element size from the
pointer type, making allocation size and pointer stride provably
consistent regardless of what len the firmware provides.
Compile tested only.
Fixes: 5b90fc760db5 ("ath11k: fix wmi service ready ext tlv parsing")
Assisted-by: Claude:claude-sonnet-4-6
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Link: https://patch.msgid.link/20260728-mac_phy_caps_parse-stride-mismatch-v1-2-27a9c1a3fbd0@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/ath/ath11k/wmi.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
diff --git a/drivers/net/wireless/ath/ath11k/wmi.c b/drivers/net/wireless/ath/ath11k/wmi.c
index 8fb91586abd5e..e5583cc78ba09 100644
--- a/drivers/net/wireless/ath/ath11k/wmi.c
+++ b/drivers/net/wireless/ath/ath11k/wmi.c
@@ -4756,14 +4756,16 @@ static int ath11k_wmi_tlv_mac_phy_caps_parse(struct ath11k_base *soc,
if (svc_rdy_ext->n_mac_phy_caps >= svc_rdy_ext->tot_phy_id)
return -ENOBUFS;
- len = min_t(u16, len, sizeof(struct wmi_mac_phy_capabilities));
if (!svc_rdy_ext->n_mac_phy_caps) {
- svc_rdy_ext->mac_phy_caps = kcalloc(svc_rdy_ext->tot_phy_id,
- len, GFP_ATOMIC);
+ svc_rdy_ext->mac_phy_caps =
+ kzalloc_objs(*svc_rdy_ext->mac_phy_caps,
+ svc_rdy_ext->tot_phy_id,
+ GFP_ATOMIC);
if (!svc_rdy_ext->mac_phy_caps)
return -ENOMEM;
}
+ len = min_t(u16, len, sizeof(struct wmi_mac_phy_capabilities));
memcpy(svc_rdy_ext->mac_phy_caps + svc_rdy_ext->n_mac_phy_caps, ptr, len);
svc_rdy_ext->n_mac_phy_caps++;
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0660/1518] md/raid10: consistently fail atomic writes that require splitting
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (658 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0659/1518] wifi: ath11k: " Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0661/1518] rcu: Mark accesses to ->rcu_urgent_qs and ->rcu_need_heavy_qs Greg Kroah-Hartman
` (338 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Abd-Alrhman Masalkhi, Yu Kuai,
John Garry, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com>
[ Upstream commit 3409bf2f9678d769a4c33bd232a3571c51fac481 ]
RAID10 currently handles one badblock path explicitly by failing atomic
writes with EIO. However, another badblock path can also reduce the
writable range and force the bio through bio_submit_split_bioset(),
which implicitly completes the bio with EINVAL.
Fix this by handling atomic writes in the common split check. If RAID10
determines that an atomic write would require splitting, complete the
bio with EIO.
Fixes: a1d9b4fd42d9 ("md/raid10: Atomic write support")
Signed-off-by: Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com>
Reviewed-by: Yu Kuai <yukuai@fygo.io>
Reviewed-by: John Garry <john.g.garry@oracle.com>
Link: https://patch.msgid.link/20260710101521.1714-4-abd.masalkhi@gmail.com
Signed-off-by: Yu Kuai <yukuai@fygo.io>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/md/raid10.c | 14 ++++----------
1 file changed, 4 insertions(+), 10 deletions(-)
diff --git a/drivers/md/raid10.c b/drivers/md/raid10.c
index 1ae9a587a9599..c4c01619bf7e1 100644
--- a/drivers/md/raid10.c
+++ b/drivers/md/raid10.c
@@ -1348,6 +1348,7 @@ static void raid10_write_request(struct mddev *mddev, struct bio *bio,
int i, k;
sector_t sectors;
int max_sectors;
+ bool atomic = bio->bi_opf & REQ_ATOMIC;
if ((mddev_is_clustered(mddev) &&
mddev->cluster_ops->area_resyncing(mddev, WRITE,
@@ -1454,16 +1455,6 @@ static void raid10_write_request(struct mddev *mddev, struct bio *bio,
if (is_bad) {
int good_sectors;
- /*
- * We cannot atomically write this, so just
- * error in that case. It could be possible to
- * atomically write other mirrors, but the
- * complexity of supporting that is not worth
- * the benefit.
- */
- if (bio->bi_opf & REQ_ATOMIC)
- goto err_handle;
-
good_sectors = first_bad - dev_sector;
if (good_sectors < max_sectors)
max_sectors = good_sectors;
@@ -1483,6 +1474,9 @@ static void raid10_write_request(struct mddev *mddev, struct bio *bio,
r10_bio->sectors = max_sectors;
if (r10_bio->sectors < bio_sectors(bio)) {
+ if (atomic)
+ goto err_handle;
+
allow_barrier(conf);
bio = bio_submit_split_bioset(bio, r10_bio->sectors,
&conf->bio_split);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0661/1518] rcu: Mark accesses to ->rcu_urgent_qs and ->rcu_need_heavy_qs
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (659 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0660/1518] md/raid10: consistently fail atomic writes that require splitting Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0662/1518] arm64: dts: qcom: msm8998: Dont pull-up I2C pins by default in sleep Greg Kroah-Hartman
` (337 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Itai Handler, Paul E. McKenney,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Itai Handler <itai.handler@gmail.com>
[ Upstream commit 27d73e81195b395270117ff77c47be2ed9b09b12 ]
rcu_all_qs() and rcu_note_context_switch() read/clear the per-CPU
->rcu_urgent_qs and ->rcu_need_heavy_qs flags with plain raw_cpu_read()
and this_cpu_write(), while the RCU core clears them with WRITE_ONCE() in
rcu_disable_urgency_upon_qs(). KCSAN flags the resulting same-CPU race:
BUG: KCSAN: data-race in rcu_all_qs / rcu_disable_urgency_upon_qs
It is benign -- the flags are advisory and rcu_all_qs() re-reads
->rcu_urgent_qs with smp_load_acquire() before acting on it -- but these
are the last unmarked accesses to the two flags; every other access
already uses READ_ONCE()/WRITE_ONCE()/smp_*. Mark them to match. No
functional change.
Reproduced on a PREEMPT_NONE, CONFIG_KCSAN_INTERRUPT_WATCHER=y kernel with
a pthreads program whose threads (two per CPU) loop reading a large file:
for (;;) {
int fd = open("/proc/kallsyms", O_RDONLY);
while (read(fd, buf, sizeof(buf)) > 0)
;
close(fd);
}
The read()s drive cond_resched() -> rcu_all_qs() while the busy CPUs keep
the grace period urgent, so the RCU core clears the flags concurrently.
Fixes: 2dba13f0b6c2 ("rcu: Switch urgent quiescent-state requests to rcu_data structure")
Signed-off-by: Itai Handler <itai.handler@gmail.com>
Signed-off-by: Paul E. McKenney <paulmck@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/rcu/tree_plugin.h | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
diff --git a/kernel/rcu/tree_plugin.h b/kernel/rcu/tree_plugin.h
index cafb1cc8eff84..41e32b015a64e 100644
--- a/kernel/rcu/tree_plugin.h
+++ b/kernel/rcu/tree_plugin.h
@@ -973,7 +973,7 @@ void rcu_all_qs(void)
{
unsigned long flags;
- if (!raw_cpu_read(rcu_data.rcu_urgent_qs))
+ if (!READ_ONCE(*raw_cpu_ptr(&rcu_data.rcu_urgent_qs)))
return;
preempt_disable(); // For CONFIG_PREEMPT_COUNT=y kernels
/* Load rcu_urgent_qs before other flags. */
@@ -981,8 +981,8 @@ void rcu_all_qs(void)
preempt_enable();
return;
}
- this_cpu_write(rcu_data.rcu_urgent_qs, false);
- if (unlikely(raw_cpu_read(rcu_data.rcu_need_heavy_qs))) {
+ WRITE_ONCE(*this_cpu_ptr(&rcu_data.rcu_urgent_qs), false);
+ if (unlikely(READ_ONCE(*this_cpu_ptr(&rcu_data.rcu_need_heavy_qs)))) {
local_irq_save(flags);
rcu_momentary_eqs();
local_irq_restore(flags);
@@ -1002,8 +1002,8 @@ void rcu_note_context_switch(bool preempt)
/* Load rcu_urgent_qs before other flags. */
if (!smp_load_acquire(this_cpu_ptr(&rcu_data.rcu_urgent_qs)))
goto out;
- this_cpu_write(rcu_data.rcu_urgent_qs, false);
- if (unlikely(raw_cpu_read(rcu_data.rcu_need_heavy_qs)))
+ WRITE_ONCE(*this_cpu_ptr(&rcu_data.rcu_urgent_qs), false);
+ if (unlikely(READ_ONCE(*this_cpu_ptr(&rcu_data.rcu_need_heavy_qs))))
rcu_momentary_eqs();
out:
rcu_tasks_qs(current, preempt);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0662/1518] arm64: dts: qcom: msm8998: Dont pull-up I2C pins by default in sleep
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (660 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0661/1518] rcu: Mark accesses to ->rcu_urgent_qs and ->rcu_need_heavy_qs Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0663/1518] arm64: dts: qcom: msm8976-longcheer-l9360: Fix accidental node override Greg Kroah-Hartman
` (336 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Bjorn Andersson,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
[ Upstream commit 58ce9a2b9099bb26aed55d4e350c32af94930532 ]
When the I2C controller is disabled, no communication is expected to
take place. Without traffic on the bus, the pull-up is unnecessary.
Both the vendor kernel for this platform and DTs of other SoCs in
upstream concur this logic. Change the default and clean up now-NOP
overrides.
Fixes: 0fee55fc0de7 ("arm64: dts: qcom: msm8998: Add I2C pinctrl and fix BLSP2_I2C naming")
Signed-off-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260717-topic-june26_dts_fixes-v2-1-797cd46e5d9f@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../dts/qcom/msm8998-sony-xperia-yoshino.dtsi | 4 ----
.../boot/dts/qcom/msm8998-xiaomi-sagit.dts | 5 ----
arch/arm64/boot/dts/qcom/msm8998.dtsi | 24 +++++++++----------
3 files changed, 12 insertions(+), 21 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/msm8998-sony-xperia-yoshino.dtsi b/arch/arm64/boot/dts/qcom/msm8998-sony-xperia-yoshino.dtsi
index 3650f2501886b..04d4741cdb5f0 100644
--- a/arch/arm64/boot/dts/qcom/msm8998-sony-xperia-yoshino.dtsi
+++ b/arch/arm64/boot/dts/qcom/msm8998-sony-xperia-yoshino.dtsi
@@ -229,10 +229,6 @@ rmi4-f11@11 {
};
};
-&blsp1_i2c5_sleep {
- bias-disable;
-};
-
&blsp1_uart3 {
status = "okay";
diff --git a/arch/arm64/boot/dts/qcom/msm8998-xiaomi-sagit.dts b/arch/arm64/boot/dts/qcom/msm8998-xiaomi-sagit.dts
index 0cac06f25a77a..2ceeec827f8e2 100644
--- a/arch/arm64/boot/dts/qcom/msm8998-xiaomi-sagit.dts
+++ b/arch/arm64/boot/dts/qcom/msm8998-xiaomi-sagit.dts
@@ -217,11 +217,6 @@ rmi4-f1a@1a {
};
};
-&blsp1_i2c5_sleep {
- /delete-property/ bias-pull-up;
- bias-disable;
-};
-
&blsp1_uart3 {
status = "okay";
diff --git a/arch/arm64/boot/dts/qcom/msm8998.dtsi b/arch/arm64/boot/dts/qcom/msm8998.dtsi
index 5c75fba16ce2c..515aa844a3e37 100644
--- a/arch/arm64/boot/dts/qcom/msm8998.dtsi
+++ b/arch/arm64/boot/dts/qcom/msm8998.dtsi
@@ -1183,7 +1183,7 @@ blsp1_i2c1_sleep: blsp1-i2c1-sleep-state-state {
pins = "gpio2", "gpio3";
function = "blsp_i2c1";
drive-strength = <2>;
- bias-pull-up;
+ bias-disable;
};
blsp1_i2c2_default: blsp1-i2c2-default-state {
@@ -1197,7 +1197,7 @@ blsp1_i2c2_sleep: blsp1-i2c2-sleep-state-state {
pins = "gpio32", "gpio33";
function = "blsp_i2c2";
drive-strength = <2>;
- bias-pull-up;
+ bias-disable;
};
blsp1_i2c3_default: blsp1-i2c3-default-state {
@@ -1211,7 +1211,7 @@ blsp1_i2c3_sleep: blsp1-i2c3-sleep-state {
pins = "gpio47", "gpio48";
function = "blsp_i2c3";
drive-strength = <2>;
- bias-pull-up;
+ bias-disable;
};
blsp1_i2c4_default: blsp1-i2c4-default-state {
@@ -1225,7 +1225,7 @@ blsp1_i2c4_sleep: blsp1-i2c4-sleep-state {
pins = "gpio10", "gpio11";
function = "blsp_i2c4";
drive-strength = <2>;
- bias-pull-up;
+ bias-disable;
};
blsp1_i2c5_default: blsp1-i2c5-default-state {
@@ -1239,7 +1239,7 @@ blsp1_i2c5_sleep: blsp1-i2c5-sleep-state {
pins = "gpio87", "gpio88";
function = "blsp_i2c5";
drive-strength = <2>;
- bias-pull-up;
+ bias-disable;
};
blsp1_i2c6_default: blsp1-i2c6-default-state {
@@ -1253,7 +1253,7 @@ blsp1_i2c6_sleep: blsp1-i2c6-sleep-state {
pins = "gpio43", "gpio44";
function = "blsp_i2c6";
drive-strength = <2>;
- bias-pull-up;
+ bias-disable;
};
blsp1_spi_b_default: blsp1-spi-b-default-state {
@@ -1318,7 +1318,7 @@ blsp2_i2c1_sleep: blsp2-i2c1-sleep-state {
pins = "gpio55", "gpio56";
function = "blsp_i2c7";
drive-strength = <2>;
- bias-pull-up;
+ bias-disable;
};
blsp2_i2c2_default: blsp2-i2c2-default-state {
@@ -1332,7 +1332,7 @@ blsp2_i2c2_sleep: blsp2-i2c2-sleep-state {
pins = "gpio6", "gpio7";
function = "blsp_i2c8";
drive-strength = <2>;
- bias-pull-up;
+ bias-disable;
};
blsp2_i2c3_default: blsp2-i2c3-default-state {
@@ -1346,7 +1346,7 @@ blsp2_i2c3_sleep: blsp2-i2c3-sleep-state {
pins = "gpio51", "gpio52";
function = "blsp_i2c9";
drive-strength = <2>;
- bias-pull-up;
+ bias-disable;
};
blsp2_i2c4_default: blsp2-i2c4-default-state {
@@ -1360,7 +1360,7 @@ blsp2_i2c4_sleep: blsp2-i2c4-sleep-state {
pins = "gpio67", "gpio68";
function = "blsp_i2c10";
drive-strength = <2>;
- bias-pull-up;
+ bias-disable;
};
blsp2_i2c5_default: blsp2-i2c5-default-state {
@@ -1374,7 +1374,7 @@ blsp2_i2c5_sleep: blsp2-i2c5-sleep-state {
pins = "gpio60", "gpio61";
function = "blsp_i2c11";
drive-strength = <2>;
- bias-pull-up;
+ bias-disable;
};
blsp2_i2c6_default: blsp2-i2c6-default-state {
@@ -1388,7 +1388,7 @@ blsp2_i2c6_sleep: blsp2-i2c6-sleep-state {
pins = "gpio83", "gpio84";
function = "blsp_i2c12";
drive-strength = <2>;
- bias-pull-up;
+ bias-disable;
};
blsp2_spi1_default: blsp2-spi1-default-state {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0663/1518] arm64: dts: qcom: msm8976-longcheer-l9360: Fix accidental node override
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (661 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0662/1518] arm64: dts: qcom: msm8998: Dont pull-up I2C pins by default in sleep Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0664/1518] arm64: dts: qcom: sdm632-motorola-ocean: Fix LED default trigger property Greg Kroah-Hartman
` (335 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Krzysztof Kozlowski, Konrad Dybcio,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
[ Upstream commit bd0bb7d97773026c9f5d5f8ff1dcf987f8051045 ]
The active and sleep pinctrl states for the touchscreen interrupt pin
shared the same node name, creating a single node, accidentally
overridden immediately after the definition. Alter the names to make
them distinct and to silence DT checker warnings.
Fixes: 79b896e7da7e ("arm64: dts: qcom: msm8976-longcheer-l9360: Add initial device tree")
Reviewed-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Signed-off-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260717-topic-june26_dts_fixes-v2-2-797cd46e5d9f@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/msm8976-longcheer-l9360.dts | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/msm8976-longcheer-l9360.dts b/arch/arm64/boot/dts/qcom/msm8976-longcheer-l9360.dts
index 18832a3b9a1c3..57f549f06f73c 100644
--- a/arch/arm64/boot/dts/qcom/msm8976-longcheer-l9360.dts
+++ b/arch/arm64/boot/dts/qcom/msm8976-longcheer-l9360.dts
@@ -455,14 +455,14 @@ sdc2_cd_sleep: sdc2-cd-sleep-state {
bias-disable;
};
- ts_int_default: ts-int-state {
+ ts_int_default: ts-int-default-state {
pins = "gpio65";
function = "gpio";
drive-strength = <2>;
bias-pull-down;
};
- ts_int_sleep: ts-int-state {
+ ts_int_sleep: ts-int-sleep-state {
pins = "gpio65";
function = "gpio";
drive-strength = <2>;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0664/1518] arm64: dts: qcom: sdm632-motorola-ocean: Fix LED default trigger property
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (662 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0663/1518] arm64: dts: qcom: msm8976-longcheer-l9360: Fix accidental node override Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0665/1518] arm64: dts: qcom: qcs404: Fix DTBS Check errors in usb controller nodes Greg Kroah-Hartman
` (334 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Krzysztof Kozlowski, Konrad Dybcio,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
[ Upstream commit c82ea31fb783d9ce4080eca1a7bb855f4648fc28 ]
The correct property name is "linux,default-trigger", not
"default-trigger". Fix it to avoid DT checker warnings and let the OSes
consume the intended information.
Fixes: 3176c4d6b9be ("arm64: dts: qcom: sdm632: Add device tree for Motorola G7 Power")
Reviewed-by: Krzysztof Kozlowski <krzysztof.kozlowski@oss.qualcomm.com>
Signed-off-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260717-topic-june26_dts_fixes-v2-3-797cd46e5d9f@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sdm632-motorola-ocean.dts | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/arm64/boot/dts/qcom/sdm632-motorola-ocean.dts b/arch/arm64/boot/dts/qcom/sdm632-motorola-ocean.dts
index 2f55db0c8ce35..9ea3e5e76bf9e 100644
--- a/arch/arm64/boot/dts/qcom/sdm632-motorola-ocean.dts
+++ b/arch/arm64/boot/dts/qcom/sdm632-motorola-ocean.dts
@@ -130,7 +130,7 @@ led-controller@36 {
led: led@1 {
reg = <1>;
- default-trigger = "backlight";
+ linux,default-trigger = "backlight";
function = LED_FUNCTION_BACKLIGHT;
led-sources = <0 1 2>;
};
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0665/1518] arm64: dts: qcom: qcs404: Fix DTBS Check errors in usb controller nodes
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (663 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0664/1518] arm64: dts: qcom: sdm632-motorola-ocean: Fix LED default trigger property Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0666/1518] clk: qcom: gcc-qcm2290: dont park QUP RCGs upon registration Greg Kroah-Hartman
` (333 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Krishna Kurapati, Konrad Dybcio,
Dmitry Baryshkov, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Krishna Kurapati <krishna.kurapati@oss.qualcomm.com>
[ Upstream commit 9812d0a3077489f67afaca84dcc7e01a440ee106 ]
The following errors pop up when DTBS check is done for qcs404 based
platforms:
arch/arm64/boot/dts/qcom/qcs404-evb-4000.dtb: usb@79b8800 (qcom,qcs404-
dwc3): interrupt-names:1: 'qusb2_phy' was expected
from schema $id: http://devicetree.org/schemas/usb/qcom,dwc3.yaml
arch/arm64/boot/dts/qcom/qcs404-evb-4000.dtb: usb@79b8800 (qcom,qcs404-
dwc3): interrupt-names:2: 'hs_phy_irq' was expected
from schema $id: http://devicetree.org/schemas/usb/qcom,dwc3.yaml
arch/arm64/boot/dts/qcom/qcs404-evb-4000.dtb: usb@7678800 (qcom,qcs404-
dwc3): interrupt-names:2: 'hs_phy_irq' was expected
from schema $id: http://devicetree.org/schemas/usb/qcom,dwc3.yaml
arch/arm64/boot/dts/qcom/qcs404-evb-4000.dtb: usb@7678800 (qcom,qcs404-
dwc3): interrupt-names:1: 'qusb2_phy' was expected
from schema $id: http://devicetree.org/schemas/usb/qcom,dwc3.yaml
Modify ordering of hs_phy and qusb2_phy interrupts to fix the errors.
Fixes: 927173bf8a0e ("arm64: dts: qcom: Add missing interrupts for qcs404/ipq5332")
Signed-off-by: Krishna Kurapati <krishna.kurapati@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260723-qcs404_dtbs_fix-v1-1-c9ca0dd69f23@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/qcs404.dtsi | 16 ++++++++--------
1 file changed, 8 insertions(+), 8 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/qcs404.dtsi b/arch/arm64/boot/dts/qcom/qcs404.dtsi
index 4328c1dda898c..736accfc34f90 100644
--- a/arch/arm64/boot/dts/qcom/qcs404.dtsi
+++ b/arch/arm64/boot/dts/qcom/qcs404.dtsi
@@ -677,11 +677,11 @@ usb3: usb@7678800 {
assigned-clock-rates = <19200000>, <200000000>;
interrupts = <GIC_SPI 25 IRQ_TYPE_LEVEL_HIGH>,
- <GIC_SPI 24 IRQ_TYPE_LEVEL_HIGH>,
- <GIC_SPI 319 IRQ_TYPE_LEVEL_HIGH>;
+ <GIC_SPI 319 IRQ_TYPE_LEVEL_HIGH>,
+ <GIC_SPI 24 IRQ_TYPE_LEVEL_HIGH>;
interrupt-names = "pwr_event",
- "hs_phy_irq",
- "qusb2_phy";
+ "qusb2_phy",
+ "hs_phy_irq";
status = "disabled";
@@ -716,11 +716,11 @@ usb2: usb@79b8800 {
assigned-clock-rates = <19200000>, <133333333>;
interrupts = <GIC_SPI 32 IRQ_TYPE_LEVEL_HIGH>,
- <GIC_SPI 31 IRQ_TYPE_LEVEL_HIGH>,
- <GIC_SPI 318 IRQ_TYPE_LEVEL_HIGH>;
+ <GIC_SPI 318 IRQ_TYPE_LEVEL_HIGH>,
+ <GIC_SPI 31 IRQ_TYPE_LEVEL_HIGH>;
interrupt-names = "pwr_event",
- "hs_phy_irq",
- "qusb2_phy";
+ "qusb2_phy",
+ "hs_phy_irq";
status = "disabled";
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0666/1518] clk: qcom: gcc-qcm2290: dont park QUP RCGs upon registration
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (664 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0665/1518] arm64: dts: qcom: qcs404: Fix DTBS Check errors in usb controller nodes Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0667/1518] arm64: dts: qcom: sc8280xp-crd: Fix the pin index for misc_3p3_reg_en Greg Kroah-Hartman
` (332 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dmitry Baryshkov, Konrad Dybcio,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
[ Upstream commit 9c4cee964e0ccc155e4ab8fa6cec88fffc262c63 ]
The gcc_qupv3_wrap0_s[0-5]_clk_src RCGs feed the QUP serial engines
(UART/I2C/SPI). Since shared RCGs are parked to XO at registration time,
binding the gcc-qcm2290 driver reprograms these clocks away from the
rate configured by the bootloader. For the UART used as the boot console
this drops early console output until the serial driver later
reconfigures the clock.
Switch the QUP wrap0 clock sources over to
clk_rcg2_shared_no_init_park_ops so their frequency is left unchanged at
registration time, keeping the bootloader-configured console working
across the gcc driver probe.
Fixes: 01a0a6cc8cfd ("clk: qcom: Park shared RCGs upon registration")
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260722-agatti-no-park-v1-1-31ae3a4774e5@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/qcom/gcc-qcm2290.c | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
diff --git a/drivers/clk/qcom/gcc-qcm2290.c b/drivers/clk/qcom/gcc-qcm2290.c
index 690f23793af6b..77cff0e9af93b 100644
--- a/drivers/clk/qcom/gcc-qcm2290.c
+++ b/drivers/clk/qcom/gcc-qcm2290.c
@@ -1082,7 +1082,7 @@ static struct clk_init_data gcc_qupv3_wrap0_s0_clk_src_init = {
.name = "gcc_qupv3_wrap0_s0_clk_src",
.parent_data = gcc_parents_1,
.num_parents = ARRAY_SIZE(gcc_parents_1),
- .ops = &clk_rcg2_shared_ops,
+ .ops = &clk_rcg2_shared_no_init_park_ops,
};
static struct clk_rcg2 gcc_qupv3_wrap0_s0_clk_src = {
@@ -1098,7 +1098,7 @@ static struct clk_init_data gcc_qupv3_wrap0_s1_clk_src_init = {
.name = "gcc_qupv3_wrap0_s1_clk_src",
.parent_data = gcc_parents_1,
.num_parents = ARRAY_SIZE(gcc_parents_1),
- .ops = &clk_rcg2_shared_ops,
+ .ops = &clk_rcg2_shared_no_init_park_ops,
};
static struct clk_rcg2 gcc_qupv3_wrap0_s1_clk_src = {
@@ -1114,7 +1114,7 @@ static struct clk_init_data gcc_qupv3_wrap0_s2_clk_src_init = {
.name = "gcc_qupv3_wrap0_s2_clk_src",
.parent_data = gcc_parents_1,
.num_parents = ARRAY_SIZE(gcc_parents_1),
- .ops = &clk_rcg2_shared_ops,
+ .ops = &clk_rcg2_shared_no_init_park_ops,
};
static struct clk_rcg2 gcc_qupv3_wrap0_s2_clk_src = {
@@ -1130,7 +1130,7 @@ static struct clk_init_data gcc_qupv3_wrap0_s3_clk_src_init = {
.name = "gcc_qupv3_wrap0_s3_clk_src",
.parent_data = gcc_parents_1,
.num_parents = ARRAY_SIZE(gcc_parents_1),
- .ops = &clk_rcg2_shared_ops,
+ .ops = &clk_rcg2_shared_no_init_park_ops,
};
static struct clk_rcg2 gcc_qupv3_wrap0_s3_clk_src = {
@@ -1146,7 +1146,7 @@ static struct clk_init_data gcc_qupv3_wrap0_s4_clk_src_init = {
.name = "gcc_qupv3_wrap0_s4_clk_src",
.parent_data = gcc_parents_1,
.num_parents = ARRAY_SIZE(gcc_parents_1),
- .ops = &clk_rcg2_shared_ops,
+ .ops = &clk_rcg2_shared_no_init_park_ops,
};
static struct clk_rcg2 gcc_qupv3_wrap0_s4_clk_src = {
@@ -1162,7 +1162,7 @@ static struct clk_init_data gcc_qupv3_wrap0_s5_clk_src_init = {
.name = "gcc_qupv3_wrap0_s5_clk_src",
.parent_data = gcc_parents_1,
.num_parents = ARRAY_SIZE(gcc_parents_1),
- .ops = &clk_rcg2_shared_ops,
+ .ops = &clk_rcg2_shared_no_init_park_ops,
};
static struct clk_rcg2 gcc_qupv3_wrap0_s5_clk_src = {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0667/1518] arm64: dts: qcom: sc8280xp-crd: Fix the pin index for misc_3p3_reg_en
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (665 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0666/1518] clk: qcom: gcc-qcm2290: dont park QUP RCGs upon registration Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0668/1518] firmware: qcom_scm: Add API to get waitqueue IRQ info Greg Kroah-Hartman
` (331 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Dmitry Baryshkov,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
[ Upstream commit 0e05c183f3b97427f00d619132ba5984494f6886 ]
The correct pin is GPIO1. Fix it.
Fixes: ccd3517faf18 ("arm64: dts: qcom: sc8280xp: Add reference device")
Signed-off-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260701-topic-8280crd_fixups-v1-2-3fe92ee9636b@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sc8280xp-crd.dts | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sc8280xp-crd.dts b/arch/arm64/boot/dts/qcom/sc8280xp-crd.dts
index 490e970c54a24..5b2692bb1564e 100644
--- a/arch/arm64/boot/dts/qcom/sc8280xp-crd.dts
+++ b/arch/arm64/boot/dts/qcom/sc8280xp-crd.dts
@@ -182,7 +182,7 @@ vreg_misc_3p3: regulator-misc-3p3 {
regulator-min-microvolt = <3300000>;
regulator-max-microvolt = <3300000>;
- gpio = <&pmc8280_1_gpios 2 GPIO_ACTIVE_HIGH>;
+ gpio = <&pmc8280_1_gpios 1 GPIO_ACTIVE_HIGH>;
enable-active-high;
pinctrl-names = "default";
@@ -921,7 +921,7 @@ kypd_vol_up_n: kypd-vol-up-n-state {
};
misc_3p3_reg_en: misc-3p3-reg-en-state {
- pins = "gpio2";
+ pins = "gpio1";
function = "normal";
};
};
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0668/1518] firmware: qcom_scm: Add API to get waitqueue IRQ info
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (666 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0667/1518] arm64: dts: qcom: sc8280xp-crd: Fix the pin index for misc_3p3_reg_en Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0669/1518] firmware: qcom_scm: Support multiple waitq contexts Greg Kroah-Hartman
` (330 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bartosz Golaszewski,
Unnathi Chalicheemala, Shivendra Pratap, Mukesh Ojha,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Unnathi Chalicheemala <unnathi.chalicheemala@oss.qualcomm.com>
[ Upstream commit da9e6b1a96b1eef47542ec46b67e3f4f883fed3b ]
Bootloader and firmware for SM8650 and older chipsets expect node
name as "qcom_scm", in order to patch the wait queue IRQ information.
However, DeviceTree uses node name "scm" and this mismatch prevents
firmware from correctly identifying waitqueue IRQ information. Waitqueue
IRQ is used for signaling between secure and non-secure worlds.
To resolve this, introduce qcom_scm_get_waitq_irq() that'll get the
hardware IRQ number to be used from firmware instead of relying on data
provided by devicetree, thereby bypassing the DeviceTree node name
mismatch.
This hardware IRQ number is converted to a Linux IRQ number using newly
qcom_scm_fill_irq_fwspec_params(). This Linux IRQ number is then
supplied to the threaded_irq call.
Reviewed-by: Bartosz Golaszewski <brgl@kernel.org>
Signed-off-by: Unnathi Chalicheemala <unnathi.chalicheemala@oss.qualcomm.com>
Signed-off-by: Shivendra Pratap <shivendra.pratap@oss.qualcomm.com>
Reviewed-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20251217-multi_waitq_scm-v11-1-f21e50e792b8@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Stable-dep-of: 966d23c7e68e ("firmware: qcom: scm: Fix NULL dereference in IRQ handler before __scm is published")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/qcom/qcom_scm.c | 62 +++++++++++++++++++++++++++++++-
drivers/firmware/qcom/qcom_scm.h | 1 +
2 files changed, 62 insertions(+), 1 deletion(-)
diff --git a/drivers/firmware/qcom/qcom_scm.c b/drivers/firmware/qcom/qcom_scm.c
index 2e51c4d80fdce..10edb6579f052 100644
--- a/drivers/firmware/qcom/qcom_scm.c
+++ b/drivers/firmware/qcom/qcom_scm.c
@@ -30,11 +30,18 @@
#include <linux/sizes.h>
#include <linux/types.h>
+#include <dt-bindings/interrupt-controller/arm-gic.h>
+
#include "qcom_scm.h"
#include "qcom_tzmem.h"
static u32 download_mode;
+#define GIC_SPI_BASE 32
+#define GIC_MAX_SPI 1019 // SPIs in GICv3 spec range from 32..1019
+#define GIC_ESPI_BASE 4096
+#define GIC_MAX_ESPI 5119 // ESPIs in GICv3 spec range from 4096..5119
+
struct qcom_scm {
struct device *dev;
struct clk *core_clk;
@@ -2257,6 +2264,56 @@ bool qcom_scm_is_available(void)
}
EXPORT_SYMBOL_GPL(qcom_scm_is_available);
+static int qcom_scm_fill_irq_fwspec_params(struct irq_fwspec *fwspec, u32 hwirq)
+{
+ if (hwirq >= GIC_SPI_BASE && hwirq <= GIC_MAX_SPI) {
+ fwspec->param[0] = GIC_SPI;
+ fwspec->param[1] = hwirq - GIC_SPI_BASE;
+ } else if (hwirq >= GIC_ESPI_BASE && hwirq <= GIC_MAX_ESPI) {
+ fwspec->param[0] = GIC_ESPI;
+ fwspec->param[1] = hwirq - GIC_ESPI_BASE;
+ } else {
+ WARN(1, "Unexpected hwirq: %d\n", hwirq);
+ return -ENXIO;
+ }
+
+ fwspec->param[2] = IRQ_TYPE_EDGE_RISING;
+ fwspec->param_count = 3;
+
+ return 0;
+}
+
+static int qcom_scm_get_waitq_irq(struct qcom_scm *scm)
+{
+ struct qcom_scm_desc desc = {
+ .svc = QCOM_SCM_SVC_WAITQ,
+ .cmd = QCOM_SCM_WAITQ_GET_INFO,
+ .owner = ARM_SMCCC_OWNER_SIP
+ };
+ struct device_node *parent_irq_node;
+ struct irq_fwspec fwspec;
+ struct qcom_scm_res res;
+ u32 hwirq;
+ int ret;
+
+ ret = qcom_scm_call_atomic(scm->dev, &desc, &res);
+ if (ret)
+ return ret;
+
+ hwirq = res.result[1] & GENMASK(15, 0);
+ ret = qcom_scm_fill_irq_fwspec_params(&fwspec, hwirq);
+ if (ret)
+ return ret;
+
+ parent_irq_node = of_irq_find_parent(scm->dev->of_node);
+ if (!parent_irq_node)
+ return -ENODEV;
+
+ fwspec.fwnode = of_fwnode_handle(parent_irq_node);
+
+ return irq_create_fwspec_mapping(&fwspec);
+}
+
static int qcom_scm_assert_valid_wq_ctx(u32 wq_ctx)
{
/* FW currently only supports a single wq_ctx (zero).
@@ -2430,7 +2487,10 @@ static int qcom_scm_probe(struct platform_device *pdev)
return dev_err_probe(scm->dev, PTR_ERR(scm->mempool),
"Failed to create the SCM memory pool\n");
- irq = platform_get_irq_optional(pdev, 0);
+ irq = qcom_scm_get_waitq_irq(scm);
+ if (irq < 0)
+ irq = platform_get_irq_optional(pdev, 0);
+
if (irq < 0) {
if (irq != -ENXIO)
return irq;
diff --git a/drivers/firmware/qcom/qcom_scm.h b/drivers/firmware/qcom/qcom_scm.h
index a56c8212cc0c4..8b1e2ea18a59a 100644
--- a/drivers/firmware/qcom/qcom_scm.h
+++ b/drivers/firmware/qcom/qcom_scm.h
@@ -152,6 +152,7 @@ int qcom_scm_shm_bridge_enable(struct device *scm_dev);
#define QCOM_SCM_SVC_WAITQ 0x24
#define QCOM_SCM_WAITQ_RESUME 0x02
#define QCOM_SCM_WAITQ_GET_WQ_CTX 0x03
+#define QCOM_SCM_WAITQ_GET_INFO 0x04
#define QCOM_SCM_SVC_GPU 0x28
#define QCOM_SCM_SVC_GPU_INIT_REGS 0x01
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0669/1518] firmware: qcom_scm: Support multiple waitq contexts
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (667 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0668/1518] firmware: qcom_scm: Add API to get waitqueue IRQ info Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0670/1518] firmware: qcom: scm: add trace events for the SMC call interface Greg Kroah-Hartman
` (329 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bartosz Golaszewski,
Unnathi Chalicheemala, Shivendra Pratap, Mukesh Ojha,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Unnathi Chalicheemala <unnathi.chalicheemala@oss.qualcomm.com>
[ Upstream commit ccd207ec848e768da41465352a0f52081eec6bb1 ]
Currently, only a single waitqueue context exists in the driver.
Multi-waitqueue mechanism is added in firmware to support the case,
when multiple VMs make SMC calls or single VM making multiple calls on
same CPU. Enhance the driver to support multiple waitqueue when
support is present in the firmware.
When VMs make a SMC call, firmware allocates a waitqueue context,
assuming the SMC call to be a blocking call. The SMC calls that cannot
acquire resources, while execution in firmware, are returned to sleep
in the calling VM. When the resource becomes available in the
firmware, the VM gets notified to wake the sleeping thread and resume
SMC call. The current qcom_scm driver supports single waitqueue as the
old firmwares support only single waitqueue with waitqueue id zero.
Multi-waitqueue mechanism is added in firmware starting SM8650 to
support the case when multiple VMs make SMC calls or single VM making
multiple calls on same CPU. To enable this support in qcom_scm driver,
add support for handling multiple waitqueues. For instance, SM8650
firmware can allocate two such waitq contexts, so the driver needs to
implement two waitqueue contexts. For a generalized approach, the
number of supported waitqueues can be queried from the firmware using
a SMC call.
Introduce qcom_scm_query_waitq_count to get the number of waitqueue
contexts supported by the firmware and allocate “N” unique waitqueue
contexts with a dynamic sized array where each unique wq_ctx is
associated with a struct completion variable for easy lookup. Older
targets which support only a single waitqueue, may return an error for
qcom_scm_query_waitq_count, set the wq_cnt to one for such failures.
Reviewed-by: Bartosz Golaszewski <brgl@kernel.org>
Signed-off-by: Unnathi Chalicheemala <unnathi.chalicheemala@oss.qualcomm.com>
Signed-off-by: Shivendra Pratap <shivendra.pratap@oss.qualcomm.com>
Reviewed-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20251217-multi_waitq_scm-v11-2-f21e50e792b8@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Stable-dep-of: 966d23c7e68e ("firmware: qcom: scm: Fix NULL dereference in IRQ handler before __scm is published")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/qcom/qcom_scm.c | 72 ++++++++++++++++++++++----------
1 file changed, 50 insertions(+), 22 deletions(-)
diff --git a/drivers/firmware/qcom/qcom_scm.c b/drivers/firmware/qcom/qcom_scm.c
index 10edb6579f052..99a06b3b1b629 100644
--- a/drivers/firmware/qcom/qcom_scm.c
+++ b/drivers/firmware/qcom/qcom_scm.c
@@ -48,7 +48,7 @@ struct qcom_scm {
struct clk *iface_clk;
struct clk *bus_clk;
struct icc_path *path;
- struct completion waitq_comp;
+ struct completion *waitq_comps;
struct reset_controller_dev reset;
/* control access to the interconnect path */
@@ -58,6 +58,7 @@ struct qcom_scm {
u64 dload_mode_addr;
struct qcom_tzmem_pool *mempool;
+ unsigned int wq_cnt;
};
struct qcom_scm_current_perm_info {
@@ -137,6 +138,8 @@ static const u8 qcom_scm_cpu_warm_bits[QCOM_SCM_BOOT_MAX_CPUS] = {
#define QCOM_DLOAD_MINIDUMP 2
#define QCOM_DLOAD_BOTHDUMP 3
+#define QCOM_SCM_DEFAULT_WAITQ_COUNT 1
+
static const char * const qcom_scm_convention_names[] = {
[SMC_CONVENTION_UNKNOWN] = "unknown",
[SMC_CONVENTION_ARM_32] = "smc arm 32",
@@ -2283,6 +2286,23 @@ static int qcom_scm_fill_irq_fwspec_params(struct irq_fwspec *fwspec, u32 hwirq)
return 0;
}
+static int qcom_scm_query_waitq_count(struct qcom_scm *scm)
+{
+ struct qcom_scm_desc desc = {
+ .svc = QCOM_SCM_SVC_WAITQ,
+ .cmd = QCOM_SCM_WAITQ_GET_INFO,
+ .owner = ARM_SMCCC_OWNER_SIP
+ };
+ struct qcom_scm_res res;
+ int ret;
+
+ ret = qcom_scm_call_atomic(scm->dev, &desc, &res);
+ if (ret)
+ return ret;
+
+ return res.result[0] & GENMASK(7, 0);
+}
+
static int qcom_scm_get_waitq_irq(struct qcom_scm *scm)
{
struct qcom_scm_desc desc = {
@@ -2314,42 +2334,40 @@ static int qcom_scm_get_waitq_irq(struct qcom_scm *scm)
return irq_create_fwspec_mapping(&fwspec);
}
-static int qcom_scm_assert_valid_wq_ctx(u32 wq_ctx)
+static struct completion *qcom_scm_get_completion(u32 wq_ctx)
{
- /* FW currently only supports a single wq_ctx (zero).
- * TODO: Update this logic to include dynamic allocation and lookup of
- * completion structs when FW supports more wq_ctx values.
- */
- if (wq_ctx != 0) {
- dev_err(__scm->dev, "Firmware unexpectedly passed non-zero wq_ctx\n");
- return -EINVAL;
- }
+ struct completion *wq;
- return 0;
+ if (WARN_ON_ONCE(wq_ctx >= __scm->wq_cnt))
+ return ERR_PTR(-EINVAL);
+
+ wq = &__scm->waitq_comps[wq_ctx];
+
+ return wq;
}
int qcom_scm_wait_for_wq_completion(u32 wq_ctx)
{
- int ret;
+ struct completion *wq;
- ret = qcom_scm_assert_valid_wq_ctx(wq_ctx);
- if (ret)
- return ret;
+ wq = qcom_scm_get_completion(wq_ctx);
+ if (IS_ERR(wq))
+ return PTR_ERR(wq);
- wait_for_completion(&__scm->waitq_comp);
+ wait_for_completion(wq);
return 0;
}
static int qcom_scm_waitq_wakeup(unsigned int wq_ctx)
{
- int ret;
+ struct completion *wq;
- ret = qcom_scm_assert_valid_wq_ctx(wq_ctx);
- if (ret)
- return ret;
+ wq = qcom_scm_get_completion(wq_ctx);
+ if (IS_ERR(wq))
+ return PTR_ERR(wq);
- complete(&__scm->waitq_comp);
+ complete(wq);
return 0;
}
@@ -2425,6 +2443,7 @@ static int qcom_scm_probe(struct platform_device *pdev)
struct qcom_tzmem_pool_config pool_config;
struct qcom_scm *scm;
int irq, ret;
+ int i;
scm = devm_kzalloc(&pdev->dev, sizeof(*scm), GFP_KERNEL);
if (!scm)
@@ -2435,7 +2454,6 @@ static int qcom_scm_probe(struct platform_device *pdev)
if (ret < 0)
return ret;
- init_completion(&scm->waitq_comp);
mutex_init(&scm->scm_bw_lock);
scm->path = devm_of_icc_get(&pdev->dev, NULL);
@@ -2487,6 +2505,16 @@ static int qcom_scm_probe(struct platform_device *pdev)
return dev_err_probe(scm->dev, PTR_ERR(scm->mempool),
"Failed to create the SCM memory pool\n");
+ ret = qcom_scm_query_waitq_count(scm);
+ scm->wq_cnt = ret < 0 ? QCOM_SCM_DEFAULT_WAITQ_COUNT : ret;
+ scm->waitq_comps = devm_kcalloc(&pdev->dev, scm->wq_cnt, sizeof(*scm->waitq_comps),
+ GFP_KERNEL);
+ if (!scm->waitq_comps)
+ return -ENOMEM;
+
+ for (i = 0; i < scm->wq_cnt; i++)
+ init_completion(&scm->waitq_comps[i]);
+
irq = qcom_scm_get_waitq_irq(scm);
if (irq < 0)
irq = platform_get_irq_optional(pdev, 0);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0670/1518] firmware: qcom: scm: add trace events for the SMC call interface
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (668 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0669/1518] firmware: qcom_scm: Support multiple waitq contexts Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0671/1518] firmware: qcom: scm: instrument SMC call path with tracepoints Greg Kroah-Hartman
` (328 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Yuvaraj Ranganathan,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuvaraj Ranganathan <yuvaraj.ranganathan@oss.qualcomm.com>
[ Upstream commit f6bb2daa4584229af155c2488b83151999315293 ]
The SCM SMC call path is opaque at runtime. Stalls caused by firmware
congestion, QCOM_SCM_WAITQ_SLEEP/RESUME cycles, and EBUSY retry loops
are invisible without recompiling the kernel with temporary printk
statements or attaching a hardware debugger.
Add five TRACE_EVENTs covering the complete lifecycle of an SCM call:
scm_smc_request
Emit before each arm_smccc_smc_quirk() invocation. Records the
SMC function ID, decoded service and command identifiers, argument
count, and up to six register arguments in hex and decimal. Because
the caller loops on QCOM_SCM_INTERRUPTED, this event fires once per
physical SMC instruction including inte
scm_smc_done
Emit after the outer __scm_smc_do() returns, pairing each
request with its final outcome. Records the SMC function ID, the
kernel error code returned to the caller, and the four firmware
result registers a0-a3.
scm_waitq_sleep
Emit when the firmware returns QCOM_SCM_WAITQ_SLEEP. Records
the wait-queue context and the SMC call context handles required
to issue the matching WAITQ_RESUME.
scm_waitq_resume
Emit just before constructing and sending the WAITQ_RESUME
follow-up call. Records the SMC call context handle being resumed.
scm_waitq_get_wq_ctx
Emit after a successful WAITQ_GET_WQ_CTX fast-call. Records
the returned wait-queue context, flags, and more_pending indicator.
These events let ftrace and perf reconstruct the full sequence of
firmware interactions, measure per-call and end-to-end latency, and
attribute waitqueue stalls to specific service/command pairs without
modifying driver source.
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Yuvaraj Ranganathan <yuvaraj.ranganathan@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260522-scm-tracepoints-v2-1-e27cdbe0c585@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Stable-dep-of: 966d23c7e68e ("firmware: qcom: scm: Fix NULL dereference in IRQ handler before __scm is published")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/qcom/qcom_scm_trace.h | 143 +++++++++++++++++++++++++
1 file changed, 143 insertions(+)
create mode 100644 drivers/firmware/qcom/qcom_scm_trace.h
diff --git a/drivers/firmware/qcom/qcom_scm_trace.h b/drivers/firmware/qcom/qcom_scm_trace.h
new file mode 100644
index 0000000000000..6c911124fc56b
--- /dev/null
+++ b/drivers/firmware/qcom/qcom_scm_trace.h
@@ -0,0 +1,143 @@
+/* SPDX-License-Identifier: GPL-2.0-only */
+/*
+ * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries.
+ */
+
+#undef TRACE_SYSTEM
+#define TRACE_SYSTEM qcom_scm
+
+#if !defined(_TRACE_SCM_SMC_INTERFACE_H) || defined(TRACE_HEADER_MULTI_READ)
+
+#define _TRACE_SCM_SMC_INTERFACE_H
+
+#include <linux/tracepoint.h>
+
+TRACE_EVENT(scm_smc_request,
+
+ TP_PROTO(unsigned long a0, const struct arm_smccc_args *smc),
+
+ TP_ARGS(a0, smc),
+
+ TP_STRUCT__entry(
+ __field(u64, smc_id)
+ __field(u8, svc_id)
+ __field(u8, cmd_id)
+ __field(u8, args_cnt)
+ __dynamic_array(unsigned long, args,
+ min_t(u8, (smc->args[1] & 0xF), (u8)6))
+ ),
+
+ TP_fast_assign(
+ __entry->smc_id = a0;
+ __entry->svc_id = (smc->args[0] >> 8) & 0xFF;
+ __entry->cmd_id = smc->args[0] & 0xFF;
+ u8 n = min_t(u8, (smc->args[1] & 0xF), (u8)6);
+
+ __entry->args_cnt = n;
+
+ unsigned long *dst = __get_dynamic_array(args);
+
+ for (int i = 0; i < n; i++)
+ dst[i] = smc->args[2 + i];
+ ),
+
+ TP_printk("smc_id:0x%08llx svc_id:0x%02x cmd_id:0x%02x args_cnt:%u args:%s",
+ __entry->smc_id, __entry->svc_id, __entry->cmd_id, __entry->args_cnt,
+ __print_dynamic_array(args, sizeof(unsigned long)))
+);
+
+TRACE_EVENT(scm_waitq_sleep,
+
+ TP_PROTO(u32 wq_ctx, u32 smc_ctx),
+
+ TP_ARGS(wq_ctx, smc_ctx),
+
+ TP_STRUCT__entry(
+ __field(u32, wq_ctx)
+ __field(u32, smc_call_ctx)
+ ),
+
+ TP_fast_assign(
+ __entry->wq_ctx = wq_ctx;
+ __entry->smc_call_ctx = smc_ctx;
+ ),
+
+ TP_printk("wq_ctx:%u, smc_call_ctx:%u", __entry->wq_ctx, __entry->smc_call_ctx)
+);
+
+TRACE_EVENT(scm_waitq_resume,
+
+ TP_PROTO(u32 smc_ctx),
+
+ TP_ARGS(smc_ctx),
+
+ TP_STRUCT__entry(
+ __field(u32, smc_call_ctx)
+ ),
+
+ TP_fast_assign(
+ __entry->smc_call_ctx = smc_ctx;
+ ),
+
+ TP_printk("smc_call_ctx:%u", __entry->smc_call_ctx)
+);
+
+TRACE_EVENT(scm_waitq_get_wq_ctx,
+
+ TP_PROTO(u32 wq_ctx, u32 flags, u32 pending),
+
+ TP_ARGS(wq_ctx, flags, pending),
+
+ TP_STRUCT__entry(
+ __field(u32, wq_ctx)
+ __field(u32, flags)
+ __field(u32, more_pending)
+ ),
+
+ TP_fast_assign(
+ __entry->wq_ctx = wq_ctx;
+ __entry->flags = flags;
+ __entry->more_pending = pending;
+ ),
+
+ TP_printk("wq_ctx:%u, flags:%u, more_pending:%u",
+ __entry->wq_ctx, __entry->flags, __entry->more_pending)
+);
+
+TRACE_EVENT(scm_smc_done,
+
+ TP_PROTO(int ret, u64 smc_id, struct arm_smccc_res *smc_res),
+
+ TP_ARGS(ret, smc_id, smc_res),
+
+ TP_STRUCT__entry(
+ __field(int, ret)
+ __field(u64, smc_id)
+ __field(unsigned long, res)
+ __field(unsigned long, res0)
+ __field(unsigned long, res1)
+ __field(unsigned long, res2)
+ ),
+
+ TP_fast_assign(
+ __entry->ret = ret;
+ __entry->smc_id = smc_id;
+ __entry->res = smc_res->a0;
+ __entry->res0 = smc_res->a1;
+ __entry->res1 = smc_res->a2;
+ __entry->res2 = smc_res->a3;
+ ),
+
+ TP_printk("smc_id:0x%08llx, ret:%d res_to_callee:0x%lx res0:0x%lx res1:0x%lx res2:0x%lx",
+ __entry->smc_id, __entry->ret, __entry->res,
+ __entry->res0, __entry->res1, __entry->res2)
+);
+
+#endif /* _TRACE_SCM_SMC_INTERFACE_H */
+
+#undef TRACE_INCLUDE_PATH
+#define TRACE_INCLUDE_PATH .
+#define TRACE_INCLUDE_FILE qcom_scm_trace
+
+#include <trace/define_trace.h>
+
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0671/1518] firmware: qcom: scm: instrument SMC call path with tracepoints
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (669 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0670/1518] firmware: qcom: scm: add trace events for the SMC call interface Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0672/1518] firmware: qcom: scm: Fix NULL dereference in IRQ handler before __scm is published Greg Kroah-Hartman
` (327 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Yuvaraj Ranganathan,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuvaraj Ranganathan <yuvaraj.ranganathan@oss.qualcomm.com>
[ Upstream commit 41329e72363c02facfeae063ef304aa7ced68c3b ]
Wire the five tracepoints defined in qcom_scm_trace.h into the SMC
execution path by including the header with CREATE_TRACE_POINTS.
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Yuvaraj Ranganathan <yuvaraj.ranganathan@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260522-scm-tracepoints-v2-2-e27cdbe0c585@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Stable-dep-of: 966d23c7e68e ("firmware: qcom: scm: Fix NULL dereference in IRQ handler before __scm is published")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/qcom/Makefile | 1 +
drivers/firmware/qcom/qcom_scm-smc.c | 10 ++++++++++
2 files changed, 11 insertions(+)
diff --git a/drivers/firmware/qcom/Makefile b/drivers/firmware/qcom/Makefile
index 0be40a1abc13c..b679d3fc2c267 100644
--- a/drivers/firmware/qcom/Makefile
+++ b/drivers/firmware/qcom/Makefile
@@ -5,6 +5,7 @@
obj-$(CONFIG_QCOM_SCM) += qcom-scm.o
qcom-scm-objs += qcom_scm.o qcom_scm-smc.o qcom_scm-legacy.o
+CFLAGS_qcom_scm-smc.o := -I$(src)
obj-$(CONFIG_QCOM_TZMEM) += qcom_tzmem.o
obj-$(CONFIG_QCOM_QSEECOM) += qcom_qseecom.o
obj-$(CONFIG_QCOM_QSEECOM_UEFISECAPP) += qcom_qseecom_uefisecapp.o
diff --git a/drivers/firmware/qcom/qcom_scm-smc.c b/drivers/firmware/qcom/qcom_scm-smc.c
index 574930729ddd7..01999c22659cb 100644
--- a/drivers/firmware/qcom/qcom_scm-smc.c
+++ b/drivers/firmware/qcom/qcom_scm-smc.c
@@ -24,6 +24,9 @@ struct arm_smccc_args {
unsigned long args[8];
};
+#define CREATE_TRACE_POINTS
+#include "qcom_scm_trace.h"
+
static DEFINE_MUTEX(qcom_scm_lock);
#define QCOM_SCM_EBUSY_WAIT_MS 30
@@ -44,6 +47,7 @@ static void __scm_smc_do_quirk(const struct arm_smccc_args *smc,
quirk.state.a6 = 0;
do {
+ trace_scm_smc_request(a0, smc);
arm_smccc_smc_quirk(a0, smc->args[1], smc->args[2],
smc->args[3], smc->args[4], smc->args[5],
quirk.state.a6, smc->args[7], res, &quirk);
@@ -83,6 +87,7 @@ int scm_get_wq_ctx(u32 *wq_ctx, u32 *flags, u32 *more_pending)
if (ret)
return ret;
+ trace_scm_waitq_get_wq_ctx(get_wq_res.a1, get_wq_res.a2, get_wq_res.a3);
*wq_ctx = get_wq_res.a1;
*flags = get_wq_res.a2;
*more_pending = get_wq_res.a3;
@@ -105,10 +110,12 @@ static int __scm_smc_do_quirk_handle_waitq(struct device *dev, struct arm_smccc_
wq_ctx = res->a1;
smc_call_ctx = res->a2;
+ trace_scm_waitq_sleep(wq_ctx, smc_call_ctx);
ret = qcom_scm_wait_for_wq_completion(wq_ctx);
if (ret)
return ret;
+ trace_scm_waitq_resume(smc_call_ctx);
fill_wq_resume_args(&resume, smc_call_ctx);
smc = &resume;
}
@@ -201,6 +208,9 @@ int __scm_smc_call(struct device *dev, const struct qcom_scm_desc *desc,
}
ret = __scm_smc_do(dev, &smc, &smc_res, atomic);
+
+ trace_scm_smc_done(ret, smc.args[0], &smc_res);
+
if (ret)
return ret;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0672/1518] firmware: qcom: scm: Fix NULL dereference in IRQ handler before __scm is published
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (670 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0671/1518] firmware: qcom: scm: instrument SMC call path with tracepoints Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0673/1518] firmware: qcom: scm: Fix reserved memory cleanup on probe failure Greg Kroah-Hartman
` (326 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bartosz Golaszewski, Konrad Dybcio,
Mukesh Ojha, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
[ Upstream commit 966d23c7e68ea32679275a7e3d2383181002c868 ]
In qcom_scm_probe(), devm_request_threaded_irq() is called before
smp_store_release(&__scm, scm). Two paths can dereference __scm before
it is published, both causing a NULL pointer dereference.
The IRQ handler receives scm via its data argument but passes only wq_ctx
to qcom_scm_waitq_wakeup() and qcom_scm_get_completion(), which then
dereference __scm directly. Thread scm through both functions so the IRQ
handler path never touches __scm.
Non-atomic SMC calls made during probe (e.g. from qcom_tzmem_init via
qcom_scm_shm_bridge_enable) can return WAITQ_SLEEP, causing
qcom_scm_wait_for_wq_completion() to run before __scm is published and
dereference it. Add platform_set_drvdata(pdev, scm) early in probe and
change qcom_scm_wait_for_wq_completion() to take the device pointer and
use dev_get_drvdata() to reach scm, removing any dependency on __scm.
Fixes: 6bf325992236 ("firmware: qcom: scm: Add wait-queue handling logic")
Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260724094939.613844-2-mukesh.ojha@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/qcom/qcom_scm-smc.c | 2 +-
drivers/firmware/qcom/qcom_scm.c | 22 ++++++++++------------
drivers/firmware/qcom/qcom_scm.h | 2 +-
3 files changed, 12 insertions(+), 14 deletions(-)
diff --git a/drivers/firmware/qcom/qcom_scm-smc.c b/drivers/firmware/qcom/qcom_scm-smc.c
index 01999c22659cb..127365ab11fc2 100644
--- a/drivers/firmware/qcom/qcom_scm-smc.c
+++ b/drivers/firmware/qcom/qcom_scm-smc.c
@@ -111,7 +111,7 @@ static int __scm_smc_do_quirk_handle_waitq(struct device *dev, struct arm_smccc_
smc_call_ctx = res->a2;
trace_scm_waitq_sleep(wq_ctx, smc_call_ctx);
- ret = qcom_scm_wait_for_wq_completion(wq_ctx);
+ ret = qcom_scm_wait_for_wq_completion(dev, wq_ctx);
if (ret)
return ret;
diff --git a/drivers/firmware/qcom/qcom_scm.c b/drivers/firmware/qcom/qcom_scm.c
index 99a06b3b1b629..73179a99935ba 100644
--- a/drivers/firmware/qcom/qcom_scm.c
+++ b/drivers/firmware/qcom/qcom_scm.c
@@ -2334,23 +2334,20 @@ static int qcom_scm_get_waitq_irq(struct qcom_scm *scm)
return irq_create_fwspec_mapping(&fwspec);
}
-static struct completion *qcom_scm_get_completion(u32 wq_ctx)
+static struct completion *qcom_scm_get_completion(struct qcom_scm *scm, u32 wq_ctx)
{
- struct completion *wq;
-
- if (WARN_ON_ONCE(wq_ctx >= __scm->wq_cnt))
+ if (WARN_ON_ONCE(wq_ctx >= scm->wq_cnt))
return ERR_PTR(-EINVAL);
- wq = &__scm->waitq_comps[wq_ctx];
-
- return wq;
+ return &scm->waitq_comps[wq_ctx];
}
-int qcom_scm_wait_for_wq_completion(u32 wq_ctx)
+int qcom_scm_wait_for_wq_completion(struct device *dev, u32 wq_ctx)
{
+ struct qcom_scm *scm = dev_get_drvdata(dev);
struct completion *wq;
- wq = qcom_scm_get_completion(wq_ctx);
+ wq = qcom_scm_get_completion(scm, wq_ctx);
if (IS_ERR(wq))
return PTR_ERR(wq);
@@ -2359,11 +2356,11 @@ int qcom_scm_wait_for_wq_completion(u32 wq_ctx)
return 0;
}
-static int qcom_scm_waitq_wakeup(unsigned int wq_ctx)
+static int qcom_scm_waitq_wakeup(struct qcom_scm *scm, unsigned int wq_ctx)
{
struct completion *wq;
- wq = qcom_scm_get_completion(wq_ctx);
+ wq = qcom_scm_get_completion(scm, wq_ctx);
if (IS_ERR(wq))
return PTR_ERR(wq);
@@ -2390,7 +2387,7 @@ static irqreturn_t qcom_scm_irq_handler(int irq, void *data)
goto out;
}
- ret = qcom_scm_waitq_wakeup(wq_ctx);
+ ret = qcom_scm_waitq_wakeup(scm, wq_ctx);
if (ret)
goto out;
} while (more_pending);
@@ -2450,6 +2447,7 @@ static int qcom_scm_probe(struct platform_device *pdev)
return -ENOMEM;
scm->dev = &pdev->dev;
+ platform_set_drvdata(pdev, scm);
ret = qcom_scm_find_dload_address(&pdev->dev, &scm->dload_mode_addr);
if (ret < 0)
return ret;
diff --git a/drivers/firmware/qcom/qcom_scm.h b/drivers/firmware/qcom/qcom_scm.h
index 8b1e2ea18a59a..2111188f9fad0 100644
--- a/drivers/firmware/qcom/qcom_scm.h
+++ b/drivers/firmware/qcom/qcom_scm.h
@@ -66,7 +66,7 @@ struct qcom_scm_res {
u64 result[MAX_QCOM_SCM_RETS];
};
-int qcom_scm_wait_for_wq_completion(u32 wq_ctx);
+int qcom_scm_wait_for_wq_completion(struct device *dev, u32 wq_ctx);
int scm_get_wq_ctx(u32 *wq_ctx, u32 *flags, u32 *more_pending);
#define SCM_SMC_FNID(s, c) ((((s) & 0xFF) << 8) | ((c) & 0xFF))
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0673/1518] firmware: qcom: scm: Fix reserved memory cleanup on probe failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (671 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0672/1518] firmware: qcom: scm: Fix NULL dereference in IRQ handler before __scm is published Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0674/1518] firmware: qcom: scm: Fix tzmem state on probe retry Greg Kroah-Hartman
` (325 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bartosz Golaszewski, Konrad Dybcio,
Mukesh Ojha, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
[ Upstream commit b697b20cea4374d27e2134da4bb7b0ea39f36c8b ]
of_reserved_mem_device_init() adds an entry to a global list with no
devres counterpart. If qcom_scm_probe() fails after the call the
assignment is never cleaned up. A probe retry would add a duplicate
entry, leaking the original one permanently.
Add an err_rmem label that calls of_reserved_mem_device_release() and
route all error paths after of_reserved_mem_device_init() through it.
of_reserved_mem_device_release() is safe to call unconditionally as it
simply walks an empty list when nothing was assigned.
Fixes: a33b2579c8d3 ("firmware: qcom: scm: add support for SHM bridge memory carveout")
Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260724094939.613844-3-mukesh.ojha@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/qcom/qcom_scm.c | 20 ++++++++++++++------
1 file changed, 14 insertions(+), 6 deletions(-)
diff --git a/drivers/firmware/qcom/qcom_scm.c b/drivers/firmware/qcom/qcom_scm.c
index 73179a99935ba..226265b311fe9 100644
--- a/drivers/firmware/qcom/qcom_scm.c
+++ b/drivers/firmware/qcom/qcom_scm.c
@@ -2489,9 +2489,11 @@ static int qcom_scm_probe(struct platform_device *pdev)
"Failed to setup the reserved memory region for TZ mem\n");
ret = qcom_tzmem_enable(scm->dev);
- if (ret)
- return dev_err_probe(scm->dev, ret,
- "Failed to enable the TrustZone memory allocator\n");
+ if (ret) {
+ ret = dev_err_probe(scm->dev, ret,
+ "Failed to enable the TrustZone memory allocator\n");
+ goto err_rmem;
+ }
memset(&pool_config, 0, sizeof(pool_config));
pool_config.initial_size = 0;
@@ -2499,9 +2501,11 @@ static int qcom_scm_probe(struct platform_device *pdev)
pool_config.max_size = SZ_256K;
scm->mempool = devm_qcom_tzmem_pool_new(scm->dev, &pool_config);
- if (IS_ERR(scm->mempool))
- return dev_err_probe(scm->dev, PTR_ERR(scm->mempool),
- "Failed to create the SCM memory pool\n");
+ if (IS_ERR(scm->mempool)) {
+ ret = dev_err_probe(scm->dev, PTR_ERR(scm->mempool),
+ "Failed to create the SCM memory pool\n");
+ goto err_rmem;
+ }
ret = qcom_scm_query_waitq_count(scm);
scm->wq_cnt = ret < 0 ? QCOM_SCM_DEFAULT_WAITQ_COUNT : ret;
@@ -2569,6 +2573,10 @@ static int qcom_scm_probe(struct platform_device *pdev)
qcom_scm_qtee_init(scm);
return 0;
+
+err_rmem:
+ of_reserved_mem_device_release(scm->dev);
+ return ret;
}
static void qcom_scm_shutdown(struct platform_device *pdev)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0674/1518] firmware: qcom: scm: Fix tzmem state on probe retry
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (672 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0673/1518] firmware: qcom: scm: Fix reserved memory cleanup on probe failure Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0675/1518] blk-crypto: submit the encrypted bio in blk_crypto_fallback_bio_prep Greg Kroah-Hartman
` (324 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bartosz Golaszewski, Konrad Dybcio,
Mukesh Ojha, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
[ Upstream commit 9941fe8a04f3d258e07eb5899db3027252a4190f ]
qcom_tzmem_enable() returns -EBUSY if called a second time, but this
causes probe retries to fail permanently if a later step in
qcom_scm_probe() defers after qcom_tzmem_enable() has already succeeded.
Use DO_ONCE() to ensure qcom_tzmem_init() runs exactly once across all
calls in a thread-safe manner. qcom_tzmem_dev is set on every call since
probe retries use the same device pointer. The result of the first
initialisation is cached and returned to every subsequent caller.
Fixes: 40289e35ca52 ("firmware: qcom: scm: enable the TZ mem allocator")
Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260724094939.613844-4-mukesh.ojha@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/qcom/qcom_tzmem.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
diff --git a/drivers/firmware/qcom/qcom_tzmem.c b/drivers/firmware/qcom/qcom_tzmem.c
index 9f232e53115ea..b867b9d8122a6 100644
--- a/drivers/firmware/qcom/qcom_tzmem.c
+++ b/drivers/firmware/qcom/qcom_tzmem.c
@@ -15,6 +15,7 @@
#include <linux/kernel.h>
#include <linux/list.h>
#include <linux/mm.h>
+#include <linux/once.h>
#include <linux/radix-tree.h>
#include <linux/slab.h>
#include <linux/spinlock.h>
@@ -508,14 +509,18 @@ phys_addr_t qcom_tzmem_to_phys(void *vaddr)
}
EXPORT_SYMBOL_GPL(qcom_tzmem_to_phys);
+static void qcom_tzmem_do_init(int *result)
+{
+ *result = qcom_tzmem_init();
+}
+
int qcom_tzmem_enable(struct device *dev)
{
- if (qcom_tzmem_dev)
- return -EBUSY;
+ static int result;
qcom_tzmem_dev = dev;
-
- return qcom_tzmem_init();
+ DO_ONCE(qcom_tzmem_do_init, &result);
+ return result;
}
EXPORT_SYMBOL_GPL(qcom_tzmem_enable);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0675/1518] blk-crypto: submit the encrypted bio in blk_crypto_fallback_bio_prep
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (673 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0674/1518] firmware: qcom: scm: Fix tzmem state on probe retry Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0676/1518] blk-crypto: optimize bio splitting in blk_crypto_fallback_encrypt_bio Greg Kroah-Hartman
` (323 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christoph Hellwig, Eric Biggers,
Jens Axboe, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christoph Hellwig <hch@lst.de>
[ Upstream commit aefc2a1fa2edc2a486aaf857e48b3fd13062b0eb ]
Restructure blk_crypto_fallback_bio_prep so that it always submits the
encrypted bio instead of passing it back to the caller, which allows
to simplify the calling conventions for blk_crypto_fallback_bio_prep and
blk_crypto_bio_prep so that they never have to return a bio, and can
use a true return value to indicate that the caller should submit the
bio, and false that the blk-crypto code consumed it.
The submission is handled by the on-stack bio list in the current
task_struct by the block layer and does not cause additional stack
usage or major overhead. It also prepares for the following optimization
and fixes for the blk-crypto fallback write path.
Signed-off-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Eric Biggers <ebiggers@kernel.org>
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Stable-dep-of: 702a2a9f3dfe ("block: fix dio leak on metadata mapping error")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
block/blk-core.c | 2 +-
block/blk-crypto-fallback.c | 70 +++++++++++++++++--------------------
block/blk-crypto-internal.h | 19 ++++------
block/blk-crypto.c | 53 ++++++++++++++--------------
4 files changed, 67 insertions(+), 77 deletions(-)
diff --git a/block/blk-core.c b/block/blk-core.c
index 14ae73eebe0d7..db8b5100c483d 100644
--- a/block/blk-core.c
+++ b/block/blk-core.c
@@ -628,7 +628,7 @@ static void __submit_bio(struct bio *bio)
/* If plug is not used, add new plug here to cache nsecs time. */
struct blk_plug plug;
- if (unlikely(!blk_crypto_bio_prep(&bio)))
+ if (unlikely(!blk_crypto_bio_prep(bio)))
return;
blk_start_plug(&plug);
diff --git a/block/blk-crypto-fallback.c b/block/blk-crypto-fallback.c
index 86b27f96051ae..cc9e90be23b7f 100644
--- a/block/blk-crypto-fallback.c
+++ b/block/blk-crypto-fallback.c
@@ -250,14 +250,14 @@ static void blk_crypto_dun_to_iv(const u64 dun[BLK_CRYPTO_DUN_ARRAY_SIZE],
/*
* The crypto API fallback's encryption routine.
- * Allocate a bounce bio for encryption, encrypt the input bio using crypto API,
- * and replace *bio_ptr with the bounce bio. May split input bio if it's too
- * large. Returns true on success. Returns false and sets bio->bi_status on
- * error.
+ *
+ * Allocate one or more bios for encryption, encrypt the input bio using the
+ * crypto API, and submit the encrypted bios. Sets bio->bi_status and
+ * completes the source bio on error
*/
-static bool blk_crypto_fallback_encrypt_bio(struct bio **bio_ptr)
+static void blk_crypto_fallback_encrypt_bio(struct bio *src_bio)
{
- struct bio *src_bio, *enc_bio;
+ struct bio *enc_bio;
struct bio_crypt_ctx *bc;
struct blk_crypto_keyslot *slot;
int data_unit_size;
@@ -267,14 +267,12 @@ static bool blk_crypto_fallback_encrypt_bio(struct bio **bio_ptr)
struct scatterlist src, dst;
union blk_crypto_iv iv;
unsigned int i, j;
- bool ret = false;
blk_status_t blk_st;
/* Split the bio if it's too big for single page bvec */
- if (!blk_crypto_fallback_split_bio_if_needed(bio_ptr))
- return false;
+ if (!blk_crypto_fallback_split_bio_if_needed(&src_bio))
+ goto out_endio;
- src_bio = *bio_ptr;
bc = src_bio->bi_crypt_context;
data_unit_size = bc->bc_key->crypto_cfg.data_unit_size;
@@ -282,7 +280,7 @@ static bool blk_crypto_fallback_encrypt_bio(struct bio **bio_ptr)
enc_bio = blk_crypto_fallback_clone_bio(src_bio);
if (!enc_bio) {
src_bio->bi_status = BLK_STS_RESOURCE;
- return false;
+ goto out_endio;
}
/*
@@ -345,25 +343,23 @@ static bool blk_crypto_fallback_encrypt_bio(struct bio **bio_ptr)
enc_bio->bi_private = src_bio;
enc_bio->bi_end_io = blk_crypto_fallback_encrypt_endio;
- *bio_ptr = enc_bio;
- ret = true;
-
- enc_bio = NULL;
- goto out_free_ciph_req;
+ skcipher_request_free(ciph_req);
+ blk_crypto_put_keyslot(slot);
+ submit_bio(enc_bio);
+ return;
out_free_bounce_pages:
while (i > 0)
mempool_free(enc_bio->bi_io_vec[--i].bv_page,
blk_crypto_bounce_page_pool);
-out_free_ciph_req:
skcipher_request_free(ciph_req);
out_release_keyslot:
blk_crypto_put_keyslot(slot);
out_put_enc_bio:
- if (enc_bio)
- bio_uninit(enc_bio);
+ bio_uninit(enc_bio);
kfree(enc_bio);
- return ret;
+out_endio:
+ bio_endio(src_bio);
}
/*
@@ -466,44 +462,44 @@ static void blk_crypto_fallback_decrypt_endio(struct bio *bio)
/**
* blk_crypto_fallback_bio_prep - Prepare a bio to use fallback en/decryption
+ * @bio: bio to prepare
*
- * @bio_ptr: pointer to the bio to prepare
- *
- * If bio is doing a WRITE operation, this splits the bio into two parts if it's
- * too big (see blk_crypto_fallback_split_bio_if_needed()). It then allocates a
- * bounce bio for the first part, encrypts it, and updates bio_ptr to point to
- * the bounce bio.
+ * If bio is doing a WRITE operation, allocate one or more bios to contain the
+ * encrypted payload and submit them.
*
- * For a READ operation, we mark the bio for decryption by using bi_private and
+ * For a READ operation, mark the bio for decryption by using bi_private and
* bi_end_io.
*
- * In either case, this function will make the bio look like a regular bio (i.e.
- * as if no encryption context was ever specified) for the purposes of the rest
- * of the stack except for blk-integrity (blk-integrity and blk-crypto are not
- * currently supported together).
+ * In either case, this function will make the submitted bio(s) look like
+ * regular bios (i.e. as if no encryption context was ever specified) for the
+ * purposes of the rest of the stack except for blk-integrity (blk-integrity and
+ * blk-crypto are not currently supported together).
*
- * Return: true on success. Sets bio->bi_status and returns false on error.
+ * Return: true if @bio should be submitted to the driver by the caller, else
+ * false. Sets bio->bi_status, calls bio_endio and returns false on error.
*/
-bool blk_crypto_fallback_bio_prep(struct bio **bio_ptr)
+bool blk_crypto_fallback_bio_prep(struct bio *bio)
{
- struct bio *bio = *bio_ptr;
struct bio_crypt_ctx *bc = bio->bi_crypt_context;
struct bio_fallback_crypt_ctx *f_ctx;
if (WARN_ON_ONCE(!tfms_inited[bc->bc_key->crypto_cfg.crypto_mode])) {
/* User didn't call blk_crypto_start_using_key() first */
- bio->bi_status = BLK_STS_IOERR;
+ bio_io_error(bio);
return false;
}
if (!__blk_crypto_cfg_supported(blk_crypto_fallback_profile,
&bc->bc_key->crypto_cfg)) {
bio->bi_status = BLK_STS_NOTSUPP;
+ bio_endio(bio);
return false;
}
- if (bio_data_dir(bio) == WRITE)
- return blk_crypto_fallback_encrypt_bio(bio_ptr);
+ if (bio_data_dir(bio) == WRITE) {
+ blk_crypto_fallback_encrypt_bio(bio);
+ return false;
+ }
/*
* bio READ case: Set up a f_ctx in the bio's bi_private and set the
diff --git a/block/blk-crypto-internal.h b/block/blk-crypto-internal.h
index ccf6dff6ff6be..d650231203411 100644
--- a/block/blk-crypto-internal.h
+++ b/block/blk-crypto-internal.h
@@ -165,11 +165,11 @@ static inline void bio_crypt_do_front_merge(struct request *rq,
#endif
}
-bool __blk_crypto_bio_prep(struct bio **bio_ptr);
-static inline bool blk_crypto_bio_prep(struct bio **bio_ptr)
+bool __blk_crypto_bio_prep(struct bio *bio);
+static inline bool blk_crypto_bio_prep(struct bio *bio)
{
- if (bio_has_crypt_ctx(*bio_ptr))
- return __blk_crypto_bio_prep(bio_ptr);
+ if (bio_has_crypt_ctx(bio))
+ return __blk_crypto_bio_prep(bio);
return true;
}
@@ -215,12 +215,12 @@ static inline int blk_crypto_rq_bio_prep(struct request *rq, struct bio *bio,
return 0;
}
+bool blk_crypto_fallback_bio_prep(struct bio *bio);
+
#ifdef CONFIG_BLK_INLINE_ENCRYPTION_FALLBACK
int blk_crypto_fallback_start_using_mode(enum blk_crypto_mode_num mode_num);
-bool blk_crypto_fallback_bio_prep(struct bio **bio_ptr);
-
int blk_crypto_fallback_evict_key(const struct blk_crypto_key *key);
#else /* CONFIG_BLK_INLINE_ENCRYPTION_FALLBACK */
@@ -232,13 +232,6 @@ blk_crypto_fallback_start_using_mode(enum blk_crypto_mode_num mode_num)
return -ENOPKG;
}
-static inline bool blk_crypto_fallback_bio_prep(struct bio **bio_ptr)
-{
- pr_warn_once("crypto API fallback disabled; failing request.\n");
- (*bio_ptr)->bi_status = BLK_STS_NOTSUPP;
- return false;
-}
-
static inline int
blk_crypto_fallback_evict_key(const struct blk_crypto_key *key)
{
diff --git a/block/blk-crypto.c b/block/blk-crypto.c
index 3e7bf1974cbd8..69e869d1c9bd8 100644
--- a/block/blk-crypto.c
+++ b/block/blk-crypto.c
@@ -260,54 +260,55 @@ void __blk_crypto_free_request(struct request *rq)
/**
* __blk_crypto_bio_prep - Prepare bio for inline encryption
- *
- * @bio_ptr: pointer to original bio pointer
+ * @bio: bio to prepare
*
* If the bio crypt context provided for the bio is supported by the underlying
* device's inline encryption hardware, do nothing.
*
* Otherwise, try to perform en/decryption for this bio by falling back to the
- * kernel crypto API. When the crypto API fallback is used for encryption,
- * blk-crypto may choose to split the bio into 2 - the first one that will
- * continue to be processed and the second one that will be resubmitted via
- * submit_bio_noacct. A bounce bio will be allocated to encrypt the contents
- * of the aforementioned "first one", and *bio_ptr will be updated to this
- * bounce bio.
+ * kernel crypto API. For encryption this means submitting newly allocated
+ * bios for the encrypted payload while keeping back the source bio until they
+ * complete, while for reads the decryption happens in-place by a hooked in
+ * completion handler.
*
* Caller must ensure bio has bio_crypt_ctx.
*
- * Return: true on success; false on error (and bio->bi_status will be set
- * appropriately, and bio_endio() will have been called so bio
- * submission should abort).
+ * Return: true if @bio should be submitted to the driver by the caller, else
+ * false. Sets bio->bi_status, calls bio_endio and returns false on error.
*/
-bool __blk_crypto_bio_prep(struct bio **bio_ptr)
+bool __blk_crypto_bio_prep(struct bio *bio)
{
- struct bio *bio = *bio_ptr;
const struct blk_crypto_key *bc_key = bio->bi_crypt_context->bc_key;
+ struct block_device *bdev = bio->bi_bdev;
/* Error if bio has no data. */
if (WARN_ON_ONCE(!bio_has_data(bio))) {
- bio->bi_status = BLK_STS_IOERR;
- goto fail;
+ bio_io_error(bio);
+ return false;
}
if (!bio_crypt_check_alignment(bio)) {
bio->bi_status = BLK_STS_INVAL;
- goto fail;
+ bio_endio(bio);
+ return false;
}
/*
- * Success if device supports the encryption context, or if we succeeded
- * in falling back to the crypto API.
+ * If the device does not natively support the encryption context, try to use
+ * the fallback if available.
*/
- if (blk_crypto_config_supported_natively(bio->bi_bdev,
- &bc_key->crypto_cfg))
- return true;
- if (blk_crypto_fallback_bio_prep(bio_ptr))
- return true;
-fail:
- bio_endio(*bio_ptr);
- return false;
+ if (!blk_crypto_config_supported_natively(bdev, &bc_key->crypto_cfg)) {
+ if (!IS_ENABLED(CONFIG_BLK_INLINE_ENCRYPTION_FALLBACK)) {
+ pr_warn_once("%pg: crypto API fallback disabled; failing request.\n",
+ bdev);
+ bio->bi_status = BLK_STS_NOTSUPP;
+ bio_endio(bio);
+ return false;
+ }
+ return blk_crypto_fallback_bio_prep(bio);
+ }
+
+ return true;
}
int __blk_crypto_rq_bio_prep(struct request *rq, struct bio *bio,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0676/1518] blk-crypto: optimize bio splitting in blk_crypto_fallback_encrypt_bio
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (674 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0675/1518] blk-crypto: submit the encrypted bio in blk_crypto_fallback_bio_prep Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0677/1518] blk-crypto: use on-stack skcipher requests for fallback en/decryption Greg Kroah-Hartman
` (322 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christoph Hellwig, Eric Biggers,
Jens Axboe, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christoph Hellwig <hch@lst.de>
[ Upstream commit b37fbce460ad60b0c4449c1c7566cf24f3016713 ]
The current code in blk_crypto_fallback_encrypt_bio is inefficient and
prone to deadlocks under memory pressure: It first walks the passed in
plaintext bio to see how much of it can fit into a single encrypted
bio using up to BIO_MAX_VEC PAGE_SIZE segments, and then allocates a
plaintext clone that fits the size, only to allocate another bio for
the ciphertext later. While the plaintext clone uses a bioset to avoid
deadlocks when allocations could fail, the ciphertex one uses bio_kmalloc
which is a no-go in the file system I/O path.
Switch blk_crypto_fallback_encrypt_bio to walk the source plaintext bio
while consuming bi_iter without cloning it, and instead allocate a
ciphertext bio at the beginning and whenever we fille up the previous
one. The existing bio_set for the plaintext clones is reused for the
ciphertext bios to remove the deadlock risk.
Signed-off-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Eric Biggers <ebiggers@kernel.org>
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Stable-dep-of: 702a2a9f3dfe ("block: fix dio leak on metadata mapping error")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
block/blk-crypto-fallback.c | 189 +++++++++++++++---------------------
1 file changed, 80 insertions(+), 109 deletions(-)
diff --git a/block/blk-crypto-fallback.c b/block/blk-crypto-fallback.c
index cc9e90be23b7f..4ec7da3422805 100644
--- a/block/blk-crypto-fallback.c
+++ b/block/blk-crypto-fallback.c
@@ -81,7 +81,7 @@ static struct blk_crypto_fallback_keyslot {
static struct blk_crypto_profile *blk_crypto_fallback_profile;
static struct workqueue_struct *blk_crypto_wq;
static mempool_t *blk_crypto_bounce_page_pool;
-static struct bio_set crypto_bio_split;
+static struct bio_set enc_bio_set;
/*
* This is the key we set when evicting a keyslot. This *should* be the all 0's
@@ -150,37 +150,29 @@ static void blk_crypto_fallback_encrypt_endio(struct bio *enc_bio)
mempool_free(enc_bio->bi_io_vec[i].bv_page,
blk_crypto_bounce_page_pool);
- src_bio->bi_status = enc_bio->bi_status;
+ if (enc_bio->bi_status)
+ cmpxchg(&src_bio->bi_status, 0, enc_bio->bi_status);
- bio_uninit(enc_bio);
- kfree(enc_bio);
+ bio_put(enc_bio);
bio_endio(src_bio);
}
-static struct bio *blk_crypto_fallback_clone_bio(struct bio *bio_src)
+static struct bio *blk_crypto_alloc_enc_bio(struct bio *bio_src,
+ unsigned int nr_segs)
{
- unsigned int nr_segs = bio_segments(bio_src);
- struct bvec_iter iter;
- struct bio_vec bv;
struct bio *bio;
- bio = bio_kmalloc(nr_segs, GFP_NOIO);
- if (!bio)
- return NULL;
- bio_init_inline(bio, bio_src->bi_bdev, nr_segs, bio_src->bi_opf);
+ bio = bio_alloc_bioset(bio_src->bi_bdev, nr_segs, bio_src->bi_opf,
+ GFP_NOIO, &enc_bio_set);
if (bio_flagged(bio_src, BIO_REMAPPED))
bio_set_flag(bio, BIO_REMAPPED);
+ bio->bi_private = bio_src;
+ bio->bi_end_io = blk_crypto_fallback_encrypt_endio;
bio->bi_ioprio = bio_src->bi_ioprio;
bio->bi_write_hint = bio_src->bi_write_hint;
bio->bi_write_stream = bio_src->bi_write_stream;
bio->bi_iter.bi_sector = bio_src->bi_iter.bi_sector;
- bio->bi_iter.bi_size = bio_src->bi_iter.bi_size;
-
- bio_for_each_segment(bv, bio_src, iter)
- bio->bi_io_vec[bio->bi_vcnt++] = bv;
-
bio_clone_blkg_association(bio, bio_src);
-
return bio;
}
@@ -208,32 +200,6 @@ blk_crypto_fallback_alloc_cipher_req(struct blk_crypto_keyslot *slot,
return true;
}
-static bool blk_crypto_fallback_split_bio_if_needed(struct bio **bio_ptr)
-{
- struct bio *bio = *bio_ptr;
- unsigned int i = 0;
- unsigned int num_sectors = 0;
- struct bio_vec bv;
- struct bvec_iter iter;
-
- bio_for_each_segment(bv, bio, iter) {
- num_sectors += bv.bv_len >> SECTOR_SHIFT;
- if (++i == BIO_MAX_VECS)
- break;
- }
-
- if (num_sectors < bio_sectors(bio)) {
- bio = bio_submit_split_bioset(bio, num_sectors,
- &crypto_bio_split);
- if (!bio)
- return false;
-
- *bio_ptr = bio;
- }
-
- return true;
-}
-
union blk_crypto_iv {
__le64 dun[BLK_CRYPTO_DUN_ARRAY_SIZE];
u8 bytes[BLK_CRYPTO_MAX_IV_SIZE];
@@ -257,46 +223,35 @@ static void blk_crypto_dun_to_iv(const u64 dun[BLK_CRYPTO_DUN_ARRAY_SIZE],
*/
static void blk_crypto_fallback_encrypt_bio(struct bio *src_bio)
{
- struct bio *enc_bio;
- struct bio_crypt_ctx *bc;
- struct blk_crypto_keyslot *slot;
- int data_unit_size;
+ struct bio_crypt_ctx *bc = src_bio->bi_crypt_context;
+ int data_unit_size = bc->bc_key->crypto_cfg.data_unit_size;
struct skcipher_request *ciph_req = NULL;
+ struct blk_crypto_keyslot *slot;
DECLARE_CRYPTO_WAIT(wait);
u64 curr_dun[BLK_CRYPTO_DUN_ARRAY_SIZE];
struct scatterlist src, dst;
union blk_crypto_iv iv;
- unsigned int i, j;
- blk_status_t blk_st;
-
- /* Split the bio if it's too big for single page bvec */
- if (!blk_crypto_fallback_split_bio_if_needed(&src_bio))
- goto out_endio;
-
- bc = src_bio->bi_crypt_context;
- data_unit_size = bc->bc_key->crypto_cfg.data_unit_size;
-
- /* Allocate bounce bio for encryption */
- enc_bio = blk_crypto_fallback_clone_bio(src_bio);
- if (!enc_bio) {
- src_bio->bi_status = BLK_STS_RESOURCE;
- goto out_endio;
- }
+ unsigned int nr_enc_pages, enc_idx;
+ struct bio *enc_bio;
+ blk_status_t status;
+ unsigned int i;
/*
* Get a blk-crypto-fallback keyslot that contains a crypto_skcipher for
* this bio's algorithm and key.
*/
- blk_st = blk_crypto_get_keyslot(blk_crypto_fallback_profile,
+ status = blk_crypto_get_keyslot(blk_crypto_fallback_profile,
bc->bc_key, &slot);
- if (blk_st != BLK_STS_OK) {
- src_bio->bi_status = blk_st;
- goto out_put_enc_bio;
+ if (status != BLK_STS_OK) {
+ src_bio->bi_status = status;
+ bio_endio(src_bio);
+ return;
}
/* and then allocate an skcipher_request for it */
if (!blk_crypto_fallback_alloc_cipher_req(slot, &ciph_req, &wait)) {
src_bio->bi_status = BLK_STS_RESOURCE;
+ bio_endio(src_bio);
goto out_release_keyslot;
}
@@ -307,59 +262,75 @@ static void blk_crypto_fallback_encrypt_bio(struct bio *src_bio)
skcipher_request_set_crypt(ciph_req, &src, &dst, data_unit_size,
iv.bytes);
- /* Encrypt each page in the bounce bio */
- for (i = 0; i < enc_bio->bi_vcnt; i++) {
- struct bio_vec *enc_bvec = &enc_bio->bi_io_vec[i];
- struct page *plaintext_page = enc_bvec->bv_page;
- struct page *ciphertext_page =
- mempool_alloc(blk_crypto_bounce_page_pool, GFP_NOIO);
-
- enc_bvec->bv_page = ciphertext_page;
-
- if (!ciphertext_page) {
- src_bio->bi_status = BLK_STS_RESOURCE;
- goto out_free_bounce_pages;
- }
-
- sg_set_page(&src, plaintext_page, data_unit_size,
- enc_bvec->bv_offset);
- sg_set_page(&dst, ciphertext_page, data_unit_size,
- enc_bvec->bv_offset);
-
- /* Encrypt each data unit in this page */
- for (j = 0; j < enc_bvec->bv_len; j += data_unit_size) {
+ /*
+ * Encrypt each page in the source bio. Because the source bio could
+ * have bio_vecs that span more than a single page, but the encrypted
+ * bios are limited to a single page per bio_vec, this can generate
+ * more than a single encrypted bio per source bio.
+ */
+new_bio:
+ nr_enc_pages = min(bio_segments(src_bio), BIO_MAX_VECS);
+ enc_bio = blk_crypto_alloc_enc_bio(src_bio, nr_enc_pages);
+ enc_idx = 0;
+ for (;;) {
+ struct bio_vec src_bv =
+ bio_iter_iovec(src_bio, src_bio->bi_iter);
+ struct page *enc_page;
+
+ enc_page = mempool_alloc(blk_crypto_bounce_page_pool,
+ GFP_NOIO);
+ __bio_add_page(enc_bio, enc_page, src_bv.bv_len,
+ src_bv.bv_offset);
+
+ sg_set_page(&src, src_bv.bv_page, data_unit_size,
+ src_bv.bv_offset);
+ sg_set_page(&dst, enc_page, data_unit_size, src_bv.bv_offset);
+
+ /*
+ * Increment the index now that the encrypted page is added to
+ * the bio. This is important for the error unwind path.
+ */
+ enc_idx++;
+
+ /*
+ * Encrypt each data unit in this page.
+ */
+ for (i = 0; i < src_bv.bv_len; i += data_unit_size) {
blk_crypto_dun_to_iv(curr_dun, &iv);
if (crypto_wait_req(crypto_skcipher_encrypt(ciph_req),
&wait)) {
- i++;
- src_bio->bi_status = BLK_STS_IOERR;
- goto out_free_bounce_pages;
+ bio_io_error(enc_bio);
+ goto out_free_request;
}
bio_crypt_dun_increment(curr_dun, 1);
src.offset += data_unit_size;
dst.offset += data_unit_size;
}
+
+ bio_advance_iter_single(src_bio, &src_bio->bi_iter,
+ src_bv.bv_len);
+ if (!src_bio->bi_iter.bi_size)
+ break;
+
+ if (enc_idx == nr_enc_pages) {
+ /*
+ * For each additional encrypted bio submitted,
+ * increment the source bio's remaining count. Each
+ * encrypted bio's completion handler calls bio_endio on
+ * the source bio, so this keeps the source bio from
+ * completing until the last encrypted bio does.
+ */
+ bio_inc_remaining(src_bio);
+ submit_bio(enc_bio);
+ goto new_bio;
+ }
}
- enc_bio->bi_private = src_bio;
- enc_bio->bi_end_io = blk_crypto_fallback_encrypt_endio;
- skcipher_request_free(ciph_req);
- blk_crypto_put_keyslot(slot);
submit_bio(enc_bio);
- return;
-
-out_free_bounce_pages:
- while (i > 0)
- mempool_free(enc_bio->bi_io_vec[--i].bv_page,
- blk_crypto_bounce_page_pool);
+out_free_request:
skcipher_request_free(ciph_req);
out_release_keyslot:
blk_crypto_put_keyslot(slot);
-out_put_enc_bio:
- bio_uninit(enc_bio);
- kfree(enc_bio);
-out_endio:
- bio_endio(src_bio);
}
/*
@@ -533,7 +504,7 @@ static int blk_crypto_fallback_init(void)
get_random_bytes(blank_key, sizeof(blank_key));
- err = bioset_init(&crypto_bio_split, 64, 0, 0);
+ err = bioset_init(&enc_bio_set, 64, 0, BIOSET_NEED_BVECS);
if (err)
goto out;
@@ -603,7 +574,7 @@ static int blk_crypto_fallback_init(void)
fail_free_profile:
kfree(blk_crypto_fallback_profile);
fail_free_bioset:
- bioset_exit(&crypto_bio_split);
+ bioset_exit(&enc_bio_set);
out:
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0677/1518] blk-crypto: use on-stack skcipher requests for fallback en/decryption
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (675 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0676/1518] blk-crypto: optimize bio splitting in blk_crypto_fallback_encrypt_bio Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0678/1518] block: dont set BIO_QUIET for BLK_STS_AGAIN Greg Kroah-Hartman
` (321 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christoph Hellwig, Eric Biggers,
Jens Axboe, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christoph Hellwig <hch@lst.de>
[ Upstream commit 2f655dcb2d925b55deb8c1ec8f42b522c6bc5698 ]
Allocating a skcipher request dynamically can deadlock or cause
unexpected I/O failures when called from writeback context. Avoid the
allocation entirely by using on-stack skciphers, similar to what the
non-blk-crypto fscrypt path already does.
This drops the incomplete support for asynchronous algorithms, which
previously could be used, but only synchronously.
Signed-off-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Eric Biggers <ebiggers@kernel.org>
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Stable-dep-of: 702a2a9f3dfe ("block: fix dio leak on metadata mapping error")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
block/blk-crypto-fallback.c | 179 ++++++++++++++++--------------------
1 file changed, 79 insertions(+), 100 deletions(-)
diff --git a/block/blk-crypto-fallback.c b/block/blk-crypto-fallback.c
index 4ec7da3422805..4a682230c2783 100644
--- a/block/blk-crypto-fallback.c
+++ b/block/blk-crypto-fallback.c
@@ -75,7 +75,7 @@ static bool tfms_inited[BLK_ENCRYPTION_MODE_MAX];
static struct blk_crypto_fallback_keyslot {
enum blk_crypto_mode_num crypto_mode;
- struct crypto_skcipher *tfms[BLK_ENCRYPTION_MODE_MAX];
+ struct crypto_sync_skcipher *tfms[BLK_ENCRYPTION_MODE_MAX];
} *blk_crypto_keyslots;
static struct blk_crypto_profile *blk_crypto_fallback_profile;
@@ -98,7 +98,7 @@ static void blk_crypto_fallback_evict_keyslot(unsigned int slot)
WARN_ON(slotp->crypto_mode == BLK_ENCRYPTION_MODE_INVALID);
/* Clear the key in the skcipher */
- err = crypto_skcipher_setkey(slotp->tfms[crypto_mode], blank_key,
+ err = crypto_sync_skcipher_setkey(slotp->tfms[crypto_mode], blank_key,
blk_crypto_modes[crypto_mode].keysize);
WARN_ON(err);
slotp->crypto_mode = BLK_ENCRYPTION_MODE_INVALID;
@@ -119,7 +119,7 @@ blk_crypto_fallback_keyslot_program(struct blk_crypto_profile *profile,
blk_crypto_fallback_evict_keyslot(slot);
slotp->crypto_mode = crypto_mode;
- err = crypto_skcipher_setkey(slotp->tfms[crypto_mode], key->bytes,
+ err = crypto_sync_skcipher_setkey(slotp->tfms[crypto_mode], key->bytes,
key->size);
if (err) {
blk_crypto_fallback_evict_keyslot(slot);
@@ -176,28 +176,13 @@ static struct bio *blk_crypto_alloc_enc_bio(struct bio *bio_src,
return bio;
}
-static bool
-blk_crypto_fallback_alloc_cipher_req(struct blk_crypto_keyslot *slot,
- struct skcipher_request **ciph_req_ret,
- struct crypto_wait *wait)
+static struct crypto_sync_skcipher *
+blk_crypto_fallback_tfm(struct blk_crypto_keyslot *slot)
{
- struct skcipher_request *ciph_req;
- const struct blk_crypto_fallback_keyslot *slotp;
- int keyslot_idx = blk_crypto_keyslot_index(slot);
-
- slotp = &blk_crypto_keyslots[keyslot_idx];
- ciph_req = skcipher_request_alloc(slotp->tfms[slotp->crypto_mode],
- GFP_NOIO);
- if (!ciph_req)
- return false;
-
- skcipher_request_set_callback(ciph_req,
- CRYPTO_TFM_REQ_MAY_BACKLOG |
- CRYPTO_TFM_REQ_MAY_SLEEP,
- crypto_req_done, wait);
- *ciph_req_ret = ciph_req;
+ const struct blk_crypto_fallback_keyslot *slotp =
+ &blk_crypto_keyslots[blk_crypto_keyslot_index(slot)];
- return true;
+ return slotp->tfms[slotp->crypto_mode];
}
union blk_crypto_iv {
@@ -214,46 +199,22 @@ static void blk_crypto_dun_to_iv(const u64 dun[BLK_CRYPTO_DUN_ARRAY_SIZE],
iv->dun[i] = cpu_to_le64(dun[i]);
}
-/*
- * The crypto API fallback's encryption routine.
- *
- * Allocate one or more bios for encryption, encrypt the input bio using the
- * crypto API, and submit the encrypted bios. Sets bio->bi_status and
- * completes the source bio on error
- */
-static void blk_crypto_fallback_encrypt_bio(struct bio *src_bio)
+static void __blk_crypto_fallback_encrypt_bio(struct bio *src_bio,
+ struct crypto_sync_skcipher *tfm)
{
struct bio_crypt_ctx *bc = src_bio->bi_crypt_context;
int data_unit_size = bc->bc_key->crypto_cfg.data_unit_size;
- struct skcipher_request *ciph_req = NULL;
- struct blk_crypto_keyslot *slot;
- DECLARE_CRYPTO_WAIT(wait);
+ SYNC_SKCIPHER_REQUEST_ON_STACK(ciph_req, tfm);
u64 curr_dun[BLK_CRYPTO_DUN_ARRAY_SIZE];
struct scatterlist src, dst;
union blk_crypto_iv iv;
unsigned int nr_enc_pages, enc_idx;
struct bio *enc_bio;
- blk_status_t status;
unsigned int i;
- /*
- * Get a blk-crypto-fallback keyslot that contains a crypto_skcipher for
- * this bio's algorithm and key.
- */
- status = blk_crypto_get_keyslot(blk_crypto_fallback_profile,
- bc->bc_key, &slot);
- if (status != BLK_STS_OK) {
- src_bio->bi_status = status;
- bio_endio(src_bio);
- return;
- }
-
- /* and then allocate an skcipher_request for it */
- if (!blk_crypto_fallback_alloc_cipher_req(slot, &ciph_req, &wait)) {
- src_bio->bi_status = BLK_STS_RESOURCE;
- bio_endio(src_bio);
- goto out_release_keyslot;
- }
+ skcipher_request_set_callback(ciph_req,
+ CRYPTO_TFM_REQ_MAY_BACKLOG | CRYPTO_TFM_REQ_MAY_SLEEP,
+ NULL, NULL);
memcpy(curr_dun, bc->bc_dun, sizeof(curr_dun));
sg_init_table(&src, 1);
@@ -297,10 +258,9 @@ static void blk_crypto_fallback_encrypt_bio(struct bio *src_bio)
*/
for (i = 0; i < src_bv.bv_len; i += data_unit_size) {
blk_crypto_dun_to_iv(curr_dun, &iv);
- if (crypto_wait_req(crypto_skcipher_encrypt(ciph_req),
- &wait)) {
+ if (crypto_skcipher_encrypt(ciph_req)) {
bio_io_error(enc_bio);
- goto out_free_request;
+ return;
}
bio_crypt_dun_increment(curr_dun, 1);
src.offset += data_unit_size;
@@ -327,50 +287,48 @@ static void blk_crypto_fallback_encrypt_bio(struct bio *src_bio)
}
submit_bio(enc_bio);
-out_free_request:
- skcipher_request_free(ciph_req);
-out_release_keyslot:
- blk_crypto_put_keyslot(slot);
}
/*
- * The crypto API fallback's main decryption routine.
- * Decrypts input bio in place, and calls bio_endio on the bio.
+ * The crypto API fallback's encryption routine.
+ *
+ * Allocate one or more bios for encryption, encrypt the input bio using the
+ * crypto API, and submit the encrypted bios. Sets bio->bi_status and
+ * completes the source bio on error
*/
-static void blk_crypto_fallback_decrypt_bio(struct work_struct *work)
+static void blk_crypto_fallback_encrypt_bio(struct bio *src_bio)
{
- struct bio_fallback_crypt_ctx *f_ctx =
- container_of(work, struct bio_fallback_crypt_ctx, work);
- struct bio *bio = f_ctx->bio;
- struct bio_crypt_ctx *bc = &f_ctx->crypt_ctx;
+ struct bio_crypt_ctx *bc = src_bio->bi_crypt_context;
struct blk_crypto_keyslot *slot;
- struct skcipher_request *ciph_req = NULL;
- DECLARE_CRYPTO_WAIT(wait);
+ blk_status_t status;
+
+ status = blk_crypto_get_keyslot(blk_crypto_fallback_profile,
+ bc->bc_key, &slot);
+ if (status != BLK_STS_OK) {
+ src_bio->bi_status = status;
+ bio_endio(src_bio);
+ return;
+ }
+ __blk_crypto_fallback_encrypt_bio(src_bio,
+ blk_crypto_fallback_tfm(slot));
+ blk_crypto_put_keyslot(slot);
+}
+
+static blk_status_t __blk_crypto_fallback_decrypt_bio(struct bio *bio,
+ struct bio_crypt_ctx *bc, struct bvec_iter iter,
+ struct crypto_sync_skcipher *tfm)
+{
+ SYNC_SKCIPHER_REQUEST_ON_STACK(ciph_req, tfm);
u64 curr_dun[BLK_CRYPTO_DUN_ARRAY_SIZE];
union blk_crypto_iv iv;
struct scatterlist sg;
struct bio_vec bv;
- struct bvec_iter iter;
const int data_unit_size = bc->bc_key->crypto_cfg.data_unit_size;
unsigned int i;
- blk_status_t blk_st;
-
- /*
- * Get a blk-crypto-fallback keyslot that contains a crypto_skcipher for
- * this bio's algorithm and key.
- */
- blk_st = blk_crypto_get_keyslot(blk_crypto_fallback_profile,
- bc->bc_key, &slot);
- if (blk_st != BLK_STS_OK) {
- bio->bi_status = blk_st;
- goto out_no_keyslot;
- }
- /* and then allocate an skcipher_request for it */
- if (!blk_crypto_fallback_alloc_cipher_req(slot, &ciph_req, &wait)) {
- bio->bi_status = BLK_STS_RESOURCE;
- goto out;
- }
+ skcipher_request_set_callback(ciph_req,
+ CRYPTO_TFM_REQ_MAY_BACKLOG | CRYPTO_TFM_REQ_MAY_SLEEP,
+ NULL, NULL);
memcpy(curr_dun, bc->bc_dun, sizeof(curr_dun));
sg_init_table(&sg, 1);
@@ -378,7 +336,7 @@ static void blk_crypto_fallback_decrypt_bio(struct work_struct *work)
iv.bytes);
/* Decrypt each segment in the bio */
- __bio_for_each_segment(bv, bio, iter, f_ctx->crypt_iter) {
+ __bio_for_each_segment(bv, bio, iter, iter) {
struct page *page = bv.bv_page;
sg_set_page(&sg, page, data_unit_size, bv.bv_offset);
@@ -386,21 +344,41 @@ static void blk_crypto_fallback_decrypt_bio(struct work_struct *work)
/* Decrypt each data unit in the segment */
for (i = 0; i < bv.bv_len; i += data_unit_size) {
blk_crypto_dun_to_iv(curr_dun, &iv);
- if (crypto_wait_req(crypto_skcipher_decrypt(ciph_req),
- &wait)) {
- bio->bi_status = BLK_STS_IOERR;
- goto out;
- }
+ if (crypto_skcipher_decrypt(ciph_req))
+ return BLK_STS_IOERR;
bio_crypt_dun_increment(curr_dun, 1);
sg.offset += data_unit_size;
}
}
-out:
- skcipher_request_free(ciph_req);
- blk_crypto_put_keyslot(slot);
-out_no_keyslot:
+ return BLK_STS_OK;
+}
+
+/*
+ * The crypto API fallback's main decryption routine.
+ *
+ * Decrypts input bio in place, and calls bio_endio on the bio.
+ */
+static void blk_crypto_fallback_decrypt_bio(struct work_struct *work)
+{
+ struct bio_fallback_crypt_ctx *f_ctx =
+ container_of(work, struct bio_fallback_crypt_ctx, work);
+ struct bio *bio = f_ctx->bio;
+ struct bio_crypt_ctx *bc = &f_ctx->crypt_ctx;
+ struct blk_crypto_keyslot *slot;
+ blk_status_t status;
+
+ status = blk_crypto_get_keyslot(blk_crypto_fallback_profile,
+ bc->bc_key, &slot);
+ if (status == BLK_STS_OK) {
+ status = __blk_crypto_fallback_decrypt_bio(bio, bc,
+ f_ctx->crypt_iter,
+ blk_crypto_fallback_tfm(slot));
+ blk_crypto_put_keyslot(slot);
+ }
mempool_free(f_ctx, bio_fallback_crypt_ctx_pool);
+
+ bio->bi_status = status;
bio_endio(bio);
}
@@ -608,7 +586,8 @@ int blk_crypto_fallback_start_using_mode(enum blk_crypto_mode_num mode_num)
for (i = 0; i < blk_crypto_num_keyslots; i++) {
slotp = &blk_crypto_keyslots[i];
- slotp->tfms[mode_num] = crypto_alloc_skcipher(cipher_str, 0, 0);
+ slotp->tfms[mode_num] = crypto_alloc_sync_skcipher(cipher_str,
+ 0, 0);
if (IS_ERR(slotp->tfms[mode_num])) {
err = PTR_ERR(slotp->tfms[mode_num]);
if (err == -ENOENT) {
@@ -620,7 +599,7 @@ int blk_crypto_fallback_start_using_mode(enum blk_crypto_mode_num mode_num)
goto out_free_tfms;
}
- crypto_skcipher_set_flags(slotp->tfms[mode_num],
+ crypto_sync_skcipher_set_flags(slotp->tfms[mode_num],
CRYPTO_TFM_REQ_FORBID_WEAK_KEYS);
}
@@ -634,7 +613,7 @@ int blk_crypto_fallback_start_using_mode(enum blk_crypto_mode_num mode_num)
out_free_tfms:
for (i = 0; i < blk_crypto_num_keyslots; i++) {
slotp = &blk_crypto_keyslots[i];
- crypto_free_skcipher(slotp->tfms[mode_num]);
+ crypto_free_sync_skcipher(slotp->tfms[mode_num]);
slotp->tfms[mode_num] = NULL;
}
out:
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0678/1518] block: dont set BIO_QUIET for BLK_STS_AGAIN
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (676 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0677/1518] blk-crypto: use on-stack skcipher requests for fallback en/decryption Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0679/1518] block: add a bio_endio_status helper Greg Kroah-Hartman
` (320 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christoph Hellwig, Damien Le Moal,
Jan Kara, Jens Axboe, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christoph Hellwig <hch@lst.de>
[ Upstream commit a148d0a5af1ab60253994047403f9eb41ef709a4 ]
Commit abb30460bda2 ("block: mark bio_wouldblock_error() bio with
BIO_QUIET") added this to suppress buffer_head warnings, but neither
when this commit was added nor now any buffer_head using code actually
ever sets REQ_NOWAIT which can lead to BLK_STS_AGAIN.
Remove the special handling for now. If we ever plan to use REQ_NOWAIT
for buffer_head based I/O we're better off handling BLK_STS_AGAIN in
the completion handler as it actually needs to retry the I/O as well.
Signed-off-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Reviewed-by: Jan Kara <jack@suse.cz>
Link: https://patch.msgid.link/20260518063336.507369-3-hch@lst.de
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Stable-dep-of: 702a2a9f3dfe ("block: fix dio leak on metadata mapping error")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/bio.h | 1 -
1 file changed, 1 deletion(-)
diff --git a/include/linux/bio.h b/include/linux/bio.h
index 16c1c85613b76..257ff84dbd56b 100644
--- a/include/linux/bio.h
+++ b/include/linux/bio.h
@@ -384,7 +384,6 @@ static inline void bio_io_error(struct bio *bio)
static inline void bio_wouldblock_error(struct bio *bio)
{
- bio_set_flag(bio, BIO_QUIET);
bio->bi_status = BLK_STS_AGAIN;
bio_endio(bio);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0679/1518] block: add a bio_endio_status helper
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (677 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0678/1518] block: dont set BIO_QUIET for BLK_STS_AGAIN Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0680/1518] block: fix dio leak on metadata mapping error Greg Kroah-Hartman
` (319 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christoph Hellwig, Keith Busch,
Md Haris Iqbal, Damien Le Moal, Hannes Reinecke, Jens Axboe,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christoph Hellwig <hch@lst.de>
[ Upstream commit a7d8eaee7fafe2e2c58aef9579bdef778c144029 ]
Add a helper that sets bi_status and call bio_endio() as that is a very
common pattern and convert the core block code over to it.
Signed-off-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Keith Busch <kbusch@kernel.org>
Reviewed-by: Md Haris Iqbal <haris.iqbal@linux.dev>
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Link: https://patch.msgid.link/20260528084632.2505277-1-hch@lst.de
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Stable-dep-of: 702a2a9f3dfe ("block: fix dio leak on metadata mapping error")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
block/blk-core.c | 11 ++++-------
block/blk-crypto-fallback.c | 9 +++------
block/blk-crypto.c | 3 +--
block/blk-merge.c | 6 ++----
block/blk-mq.c | 6 ++----
block/fops.c | 3 +--
include/linux/bio.h | 19 +++++++++++++++----
7 files changed, 28 insertions(+), 29 deletions(-)
diff --git a/block/blk-core.c b/block/blk-core.c
index db8b5100c483d..c2300b201d4ff 100644
--- a/block/blk-core.c
+++ b/block/blk-core.c
@@ -639,12 +639,10 @@ static void __submit_bio(struct bio *bio)
struct gendisk *disk = bio->bi_bdev->bd_disk;
if ((bio->bi_opf & REQ_POLLED) &&
- !(disk->queue->limits.features & BLK_FEAT_POLL)) {
- bio->bi_status = BLK_STS_NOTSUPP;
- bio_endio(bio);
- } else {
+ !(disk->queue->limits.features & BLK_FEAT_POLL))
+ bio_endio_status(bio, BLK_STS_NOTSUPP);
+ else
disk->fops->submit_bio(bio);
- }
blk_queue_exit(disk->queue);
}
@@ -882,8 +880,7 @@ void submit_bio_noacct(struct bio *bio)
not_supported:
status = BLK_STS_NOTSUPP;
end_io:
- bio->bi_status = status;
- bio_endio(bio);
+ bio_endio_status(bio, status);
}
EXPORT_SYMBOL(submit_bio_noacct);
diff --git a/block/blk-crypto-fallback.c b/block/blk-crypto-fallback.c
index 4a682230c2783..f523b0cf143af 100644
--- a/block/blk-crypto-fallback.c
+++ b/block/blk-crypto-fallback.c
@@ -305,8 +305,7 @@ static void blk_crypto_fallback_encrypt_bio(struct bio *src_bio)
status = blk_crypto_get_keyslot(blk_crypto_fallback_profile,
bc->bc_key, &slot);
if (status != BLK_STS_OK) {
- src_bio->bi_status = status;
- bio_endio(src_bio);
+ bio_endio_status(src_bio, status);
return;
}
__blk_crypto_fallback_encrypt_bio(src_bio,
@@ -378,8 +377,7 @@ static void blk_crypto_fallback_decrypt_bio(struct work_struct *work)
}
mempool_free(f_ctx, bio_fallback_crypt_ctx_pool);
- bio->bi_status = status;
- bio_endio(bio);
+ bio_endio_status(bio, status);
}
/**
@@ -440,8 +438,7 @@ bool blk_crypto_fallback_bio_prep(struct bio *bio)
if (!__blk_crypto_cfg_supported(blk_crypto_fallback_profile,
&bc->bc_key->crypto_cfg)) {
- bio->bi_status = BLK_STS_NOTSUPP;
- bio_endio(bio);
+ bio_endio_status(bio, BLK_STS_NOTSUPP);
return false;
}
diff --git a/block/blk-crypto.c b/block/blk-crypto.c
index 69e869d1c9bd8..9792e7273110b 100644
--- a/block/blk-crypto.c
+++ b/block/blk-crypto.c
@@ -301,8 +301,7 @@ bool __blk_crypto_bio_prep(struct bio *bio)
if (!IS_ENABLED(CONFIG_BLK_INLINE_ENCRYPTION_FALLBACK)) {
pr_warn_once("%pg: crypto API fallback disabled; failing request.\n",
bdev);
- bio->bi_status = BLK_STS_NOTSUPP;
- bio_endio(bio);
+ bio_endio_status(bio, BLK_STS_NOTSUPP);
return false;
}
return blk_crypto_fallback_bio_prep(bio);
diff --git a/block/blk-merge.c b/block/blk-merge.c
index 03b61923cf109..7b984e01f7be7 100644
--- a/block/blk-merge.c
+++ b/block/blk-merge.c
@@ -122,8 +122,7 @@ struct bio *bio_submit_split_bioset(struct bio *bio, unsigned int split_sectors,
struct bio *split = bio_split(bio, split_sectors, GFP_NOIO, bs);
if (IS_ERR(split)) {
- bio->bi_status = errno_to_blk_status(PTR_ERR(split));
- bio_endio(bio);
+ bio_endio_status(bio, errno_to_blk_status(PTR_ERR(split)));
return NULL;
}
@@ -143,8 +142,7 @@ EXPORT_SYMBOL_GPL(bio_submit_split_bioset);
static struct bio *bio_submit_split(struct bio *bio, int split_sectors)
{
if (unlikely(split_sectors < 0)) {
- bio->bi_status = errno_to_blk_status(split_sectors);
- bio_endio(bio);
+ bio_endio_status(bio, errno_to_blk_status(split_sectors));
return NULL;
}
diff --git a/block/blk-mq.c b/block/blk-mq.c
index 56158b70d0c72..6b4643a279dbf 100644
--- a/block/blk-mq.c
+++ b/block/blk-mq.c
@@ -3149,8 +3149,7 @@ void blk_mq_submit_bio(struct bio *bio)
}
if ((bio->bi_opf & REQ_POLLED) && !blk_mq_can_poll(q)) {
- bio->bi_status = BLK_STS_NOTSUPP;
- bio_endio(bio);
+ bio_endio_status(bio, BLK_STS_NOTSUPP);
goto queue_exit;
}
@@ -3193,8 +3192,7 @@ void blk_mq_submit_bio(struct bio *bio)
ret = blk_crypto_rq_get_keyslot(rq);
if (ret != BLK_STS_OK) {
- bio->bi_status = ret;
- bio_endio(bio);
+ bio_endio_status(bio, ret);
blk_mq_free_request(rq);
return;
}
diff --git a/block/fops.c b/block/fops.c
index 5e3db9fead77c..56ade36fb6564 100644
--- a/block/fops.c
+++ b/block/fops.c
@@ -221,8 +221,7 @@ static ssize_t __blkdev_direct_IO(struct kiocb *iocb, struct iov_iter *iter,
ret = blkdev_iov_iter_get_pages(bio, iter, bdev);
if (unlikely(ret)) {
- bio->bi_status = BLK_STS_IOERR;
- bio_endio(bio);
+ bio_endio_status(bio, BLK_STS_IOERR);
break;
}
if (iocb->ki_flags & IOCB_NOWAIT) {
diff --git a/include/linux/bio.h b/include/linux/bio.h
index 257ff84dbd56b..eb60727fd21e8 100644
--- a/include/linux/bio.h
+++ b/include/linux/bio.h
@@ -376,16 +376,27 @@ void submit_bio(struct bio *bio);
extern void bio_endio(struct bio *);
-static inline void bio_io_error(struct bio *bio)
+/**
+ * bio_endio_status - end I/O on a bio with a specific status
+ * @bio: bio
+ * @status: status to set
+ *
+ * Set @bio->bi_status to @status and call bio_endio().
+ **/
+static inline void bio_endio_status(struct bio *bio, blk_status_t status)
{
- bio->bi_status = BLK_STS_IOERR;
+ bio->bi_status = status;
bio_endio(bio);
}
+static inline void bio_io_error(struct bio *bio)
+{
+ bio_endio_status(bio, BLK_STS_IOERR);
+}
+
static inline void bio_wouldblock_error(struct bio *bio)
{
- bio->bi_status = BLK_STS_AGAIN;
- bio_endio(bio);
+ bio_endio_status(bio, BLK_STS_AGAIN);
}
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0680/1518] block: fix dio leak on metadata mapping error
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (678 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0679/1518] block: add a bio_endio_status helper Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0681/1518] arm64: dts: qcom: sm8250-xiaomi-elish: correct the board ID Greg Kroah-Hartman
` (318 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hannes Reinecke, Christoph Hellwig,
Keith Busch, Jens Axboe, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Keith Busch <kbusch@kernel.org>
[ Upstream commit 702a2a9f3dfe066a7481698c858371112f3cb697 ]
A failed integrity mapping holds a dio reference, so we need to go
through the full bio ending in case there were previously submitted
bio's in the sequence.
Fixes: 2729a60bbfb92 ("block: don't silently ignore metadata for sync read/write")
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Keith Busch <kbusch@kernel.org>
Link: https://patch.msgid.link/20260720201057.1862857-3-kbusch@meta.com
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
block/fops.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/block/fops.c b/block/fops.c
index 56ade36fb6564..bbc89773e07f8 100644
--- a/block/fops.c
+++ b/block/fops.c
@@ -241,8 +241,10 @@ static ssize_t __blkdev_direct_IO(struct kiocb *iocb, struct iov_iter *iter,
}
if (iocb->ki_flags & IOCB_HAS_METADATA) {
ret = bio_integrity_map_iter(bio, iocb->private);
- if (unlikely(ret))
- goto fail;
+ if (unlikely(ret)) {
+ bio_endio_status(bio, errno_to_blk_status(ret));
+ break;
+ }
}
if (is_read) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0681/1518] arm64: dts: qcom: sm8250-xiaomi-elish: correct the board ID
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (679 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0680/1518] block: fix dio leak on metadata mapping error Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0682/1518] arm64: dts: qcom: kodiak: Fix the PCIe iommu-map entries Greg Kroah-Hartman
` (317 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dawid Wróbel, Konrad Dybcio,
Dmitry Baryshkov, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dawid Wróbel <me@dawidwrobel.com>
[ Upstream commit 299731d4fbeaaa141ce2e8226ca00cb30d6ab647 ]
elish declares the same qcom,msm-id and qcom,board-id pair as
sm8250-sony-xperia-edo.dtsi, so a bootloader choosing between appended
device trees cannot tell the two boards apart.
0x10008 is Sony's value. The downstream device tree for this board,
elish-sm8250-overlay.dts, uses qcom,board-id = <47 0>, i.e. platform
type 0x2f.
Fixes: a41b617530bf ("arm64: dts: qcom: sm8250: Add device tree for Xiaomi Mi Pad 5 Pro")
Signed-off-by: Dawid Wróbel <me@dawidwrobel.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260730-elish-board-id-v1-1-92f99e9722ec@dawidwrobel.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sm8250-xiaomi-elish-common.dtsi | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/arm64/boot/dts/qcom/sm8250-xiaomi-elish-common.dtsi b/arch/arm64/boot/dts/qcom/sm8250-xiaomi-elish-common.dtsi
index 465fd6e954a34..a2ced6611c40d 100644
--- a/arch/arm64/boot/dts/qcom/sm8250-xiaomi-elish-common.dtsi
+++ b/arch/arm64/boot/dts/qcom/sm8250-xiaomi-elish-common.dtsi
@@ -28,7 +28,7 @@ / {
/* required for bootloader to select correct board */
qcom,msm-id = <QCOM_ID_SM8250 0x20001>; /* SM8250 v2.1 */
- qcom,board-id = <0x10008 0>;
+ qcom,board-id = <0x2f 0>;
aliases {
serial0 = &uart6;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0682/1518] arm64: dts: qcom: kodiak: Fix the PCIe iommu-map entries
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (680 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0681/1518] arm64: dts: qcom: sm8250-xiaomi-elish: correct the board ID Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0683/1518] arm64: dts: qcom: sar2130p: " Greg Kroah-Hartman
` (316 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Manivannan Sadhasivam, Konrad Dybcio,
Dmitry Baryshkov, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
[ Upstream commit 52dac5bda29a3acd896fab2567605683d34970db ]
The IOMMU provider apps_smmu uses '#iommu-cells = <2>', but the PCIe
iommu-map entries specify only one cell for the SID, omitting the SID
mask. This went unnoticed until the OF core started warning with commit
ccb2fd725d41 ("of: Respect #{iommu,msi}-cells in maps"):
iommu-map has 1-cell entries targeting 2-cell #iommu-cells, treating as 1-cell output
So fix the entries to match the provider's '#iommu-cells' property.
Fixes: f8328b7549e1 ("arm64: dts: qcom: sc7280: Describe the first PCIe controller and PHY")
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260730-iommu-map-fix-v1-2-83405d37ba41@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sc7280.dtsi | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sc7280.dtsi b/arch/arm64/boot/dts/qcom/sc7280.dtsi
index 0f566dd75c964..7d53e06e97b07 100644
--- a/arch/arm64/boot/dts/qcom/sc7280.dtsi
+++ b/arch/arm64/boot/dts/qcom/sc7280.dtsi
@@ -2273,8 +2273,8 @@ pcie0: pcie@1c00000 {
"aggre0",
"aggre1";
- iommu-map = <0x0 &apps_smmu 0x1c00 0x1>,
- <0x100 &apps_smmu 0x1c01 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1c00 0x0 0x1>,
+ <0x100 &apps_smmu 0x1c01 0x0 0x1>;
resets = <&gcc GCC_PCIE_0_BCR>;
reset-names = "pci";
@@ -2419,8 +2419,8 @@ pcie1: pcie@1c08000 {
dma-coherent;
- iommu-map = <0x0 &apps_smmu 0x1c80 0x1>,
- <0x100 &apps_smmu 0x1c81 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1c80 0x0 0x1>,
+ <0x100 &apps_smmu 0x1c81 0x0 0x1>;
status = "disabled";
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0683/1518] arm64: dts: qcom: sar2130p: Fix the PCIe iommu-map entries
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (681 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0682/1518] arm64: dts: qcom: kodiak: Fix the PCIe iommu-map entries Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0684/1518] arm64: dts: qcom: sc8180x: " Greg Kroah-Hartman
` (315 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Manivannan Sadhasivam, Konrad Dybcio,
Dmitry Baryshkov, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
[ Upstream commit f605087abc70ecac53757a7ae0d2d8068342ec4b ]
The IOMMU provider apps_smmu uses '#iommu-cells = <2>', but the PCIe
iommu-map entries specify only one cell for the SID, omitting the SID
mask. This went unnoticed until the OF core started warning with commit
ccb2fd725d41 ("of: Respect #{iommu,msi}-cells in maps"):
iommu-map has 1-cell entries targeting 2-cell #iommu-cells, treating as 1-cell output
So fix the entries to match the provider's '#iommu-cells' property.
Fixes: be9115bfe5bf ("arm64: dts: qcom: sar2130p: add support for SAR2130P")
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260730-iommu-map-fix-v1-3-83405d37ba41@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sar2130p.dtsi | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sar2130p.dtsi b/arch/arm64/boot/dts/qcom/sar2130p.dtsi
index d65ad0df68652..d7a80d832f080 100644
--- a/arch/arm64/boot/dts/qcom/sar2130p.dtsi
+++ b/arch/arm64/boot/dts/qcom/sar2130p.dtsi
@@ -1329,8 +1329,8 @@ &mc_virt SLAVE_EBI1 QCOM_ICC_TAG_ALWAYS>,
&config_noc SLAVE_PCIE_0 QCOM_ICC_TAG_ALWAYS>;
interconnect-names = "pcie-mem", "cpu-pcie";
- iommu-map = <0x0 &apps_smmu 0x1c00 0x1>,
- <0x100 &apps_smmu 0x1c01 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1c00 0x0 0x1>,
+ <0x100 &apps_smmu 0x1c01 0x0 0x1>;
resets = <&gcc GCC_PCIE_0_BCR>;
reset-names = "pci";
@@ -1455,8 +1455,8 @@ &mc_virt SLAVE_EBI1 QCOM_ICC_TAG_ALWAYS>,
&config_noc SLAVE_PCIE_1 QCOM_ICC_TAG_ALWAYS>;
interconnect-names = "pcie-mem", "cpu-pcie";
- iommu-map = <0x0 &apps_smmu 0x1e00 0x1>,
- <0x100 &apps_smmu 0x1e01 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1e00 0x0 0x1>,
+ <0x100 &apps_smmu 0x1e01 0x0 0x1>;
resets = <&gcc GCC_PCIE_1_BCR>,
<&gcc GCC_PCIE_1_LINK_DOWN_BCR>;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0684/1518] arm64: dts: qcom: sc8180x: Fix the PCIe iommu-map entries
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (682 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0683/1518] arm64: dts: qcom: sar2130p: " Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0685/1518] arm64: dts: qcom: sdm845: " Greg Kroah-Hartman
` (314 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Manivannan Sadhasivam, Konrad Dybcio,
Dmitry Baryshkov, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
[ Upstream commit a4548204821a56c23cd711cfad2a637ca055ff47 ]
The IOMMU provider apps_smmu uses '#iommu-cells = <2>', but the PCIe
iommu-map entries specify only one cell for the SID, omitting the SID
mask. This went unnoticed until the OF core started warning with commit
ccb2fd725d41 ("of: Respect #{iommu,msi}-cells in maps"):
iommu-map has 1-cell entries targeting 2-cell #iommu-cells, treating as 1-cell output
So fix the entries to match the provider's '#iommu-cells' property.
Fixes: d20b6c84f56a ("arm64: dts: qcom: sc8180x: Add PCIe instances")
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260730-iommu-map-fix-v1-4-83405d37ba41@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sc8180x.dtsi | 16 ++++++++--------
1 file changed, 8 insertions(+), 8 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sc8180x.dtsi b/arch/arm64/boot/dts/qcom/sc8180x.dtsi
index c6d96022c666d..faf12c6e679cb 100644
--- a/arch/arm64/boot/dts/qcom/sc8180x.dtsi
+++ b/arch/arm64/boot/dts/qcom/sc8180x.dtsi
@@ -1762,8 +1762,8 @@ pcie0: pcie@1c00000 {
assigned-clocks = <&gcc GCC_PCIE_0_AUX_CLK>;
assigned-clock-rates = <19200000>;
- iommu-map = <0x0 &apps_smmu 0x1d80 0x1>,
- <0x100 &apps_smmu 0x1d81 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1d80 0x0 0x1>,
+ <0x100 &apps_smmu 0x1d81 0x0 0x1>;
resets = <&gcc GCC_PCIE_0_BCR>;
reset-names = "pci";
@@ -1881,8 +1881,8 @@ pcie3: pcie@1c08000 {
assigned-clocks = <&gcc GCC_PCIE_3_AUX_CLK>;
assigned-clock-rates = <19200000>;
- iommu-map = <0x0 &apps_smmu 0x1e00 0x1>,
- <0x100 &apps_smmu 0x1e01 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1e00 0x0 0x1>,
+ <0x100 &apps_smmu 0x1e01 0x0 0x1>;
resets = <&gcc GCC_PCIE_3_BCR>;
reset-names = "pci";
@@ -2001,8 +2001,8 @@ pcie1: pcie@1c10000 {
assigned-clocks = <&gcc GCC_PCIE_1_AUX_CLK>;
assigned-clock-rates = <19200000>;
- iommu-map = <0x0 &apps_smmu 0x1c80 0x1>,
- <0x100 &apps_smmu 0x1c81 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1c80 0x0 0x1>,
+ <0x100 &apps_smmu 0x1c81 0x0 0x1>;
resets = <&gcc GCC_PCIE_1_BCR>;
reset-names = "pci";
@@ -2121,8 +2121,8 @@ pcie2: pcie@1c18000 {
assigned-clocks = <&gcc GCC_PCIE_2_AUX_CLK>;
assigned-clock-rates = <19200000>;
- iommu-map = <0x0 &apps_smmu 0x1d00 0x1>,
- <0x100 &apps_smmu 0x1d01 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1d00 0x0 0x1>,
+ <0x100 &apps_smmu 0x1d01 0x0 0x1>;
resets = <&gcc GCC_PCIE_2_BCR>;
reset-names = "pci";
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0685/1518] arm64: dts: qcom: sdm845: Fix the PCIe iommu-map entries
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (683 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0684/1518] arm64: dts: qcom: sc8180x: " Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0686/1518] arm64: dts: qcom: sm8150: " Greg Kroah-Hartman
` (313 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Manivannan Sadhasivam, Konrad Dybcio,
Dmitry Baryshkov, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
[ Upstream commit deaea7e982bc353c8d3c406774970f16ed901adb ]
The IOMMU provider apps_smmu uses '#iommu-cells = <2>', but the PCIe
iommu-map entries specify only one cell for the SID, omitting the SID
mask. This went unnoticed until the OF core started warning with commit
ccb2fd725d41 ("of: Respect #{iommu,msi}-cells in maps"):
iommu-map has 1-cell entries targeting 2-cell #iommu-cells, treating as 1-cell output
So fix the entries to match the provider's '#iommu-cells' property.
Fixes: 5c538e09cb19 ("arm64: dts: qcom: sdm845: Add first PCIe controller and PHY")
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260730-iommu-map-fix-v1-5-83405d37ba41@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sdm845.dtsi | 64 ++++++++++++++--------------
1 file changed, 32 insertions(+), 32 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sdm845.dtsi b/arch/arm64/boot/dts/qcom/sdm845.dtsi
index 13c9515260ef1..c49ef738d0947 100644
--- a/arch/arm64/boot/dts/qcom/sdm845.dtsi
+++ b/arch/arm64/boot/dts/qcom/sdm845.dtsi
@@ -2367,22 +2367,22 @@ pcie0: pcie@1c00000 {
"slave_q2a",
"tbu";
- iommu-map = <0x0 &apps_smmu 0x1c10 0x1>,
- <0x100 &apps_smmu 0x1c11 0x1>,
- <0x200 &apps_smmu 0x1c12 0x1>,
- <0x300 &apps_smmu 0x1c13 0x1>,
- <0x400 &apps_smmu 0x1c14 0x1>,
- <0x500 &apps_smmu 0x1c15 0x1>,
- <0x600 &apps_smmu 0x1c16 0x1>,
- <0x700 &apps_smmu 0x1c17 0x1>,
- <0x800 &apps_smmu 0x1c18 0x1>,
- <0x900 &apps_smmu 0x1c19 0x1>,
- <0xa00 &apps_smmu 0x1c1a 0x1>,
- <0xb00 &apps_smmu 0x1c1b 0x1>,
- <0xc00 &apps_smmu 0x1c1c 0x1>,
- <0xd00 &apps_smmu 0x1c1d 0x1>,
- <0xe00 &apps_smmu 0x1c1e 0x1>,
- <0xf00 &apps_smmu 0x1c1f 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1c10 0x0 0x1>,
+ <0x100 &apps_smmu 0x1c11 0x0 0x1>,
+ <0x200 &apps_smmu 0x1c12 0x0 0x1>,
+ <0x300 &apps_smmu 0x1c13 0x0 0x1>,
+ <0x400 &apps_smmu 0x1c14 0x0 0x1>,
+ <0x500 &apps_smmu 0x1c15 0x0 0x1>,
+ <0x600 &apps_smmu 0x1c16 0x0 0x1>,
+ <0x700 &apps_smmu 0x1c17 0x0 0x1>,
+ <0x800 &apps_smmu 0x1c18 0x0 0x1>,
+ <0x900 &apps_smmu 0x1c19 0x0 0x1>,
+ <0xa00 &apps_smmu 0x1c1a 0x0 0x1>,
+ <0xb00 &apps_smmu 0x1c1b 0x0 0x1>,
+ <0xc00 &apps_smmu 0x1c1c 0x0 0x1>,
+ <0xd00 &apps_smmu 0x1c1d 0x0 0x1>,
+ <0xe00 &apps_smmu 0x1c1e 0x0 0x1>,
+ <0xf00 &apps_smmu 0x1c1f 0x0 0x1>;
resets = <&gcc GCC_PCIE_0_BCR>;
reset-names = "pci";
@@ -2497,22 +2497,22 @@ pcie1: pcie@1c08000 {
assigned-clocks = <&gcc GCC_PCIE_1_AUX_CLK>;
assigned-clock-rates = <19200000>;
- iommu-map = <0x0 &apps_smmu 0x1c00 0x1>,
- <0x100 &apps_smmu 0x1c01 0x1>,
- <0x200 &apps_smmu 0x1c02 0x1>,
- <0x300 &apps_smmu 0x1c03 0x1>,
- <0x400 &apps_smmu 0x1c04 0x1>,
- <0x500 &apps_smmu 0x1c05 0x1>,
- <0x600 &apps_smmu 0x1c06 0x1>,
- <0x700 &apps_smmu 0x1c07 0x1>,
- <0x800 &apps_smmu 0x1c08 0x1>,
- <0x900 &apps_smmu 0x1c09 0x1>,
- <0xa00 &apps_smmu 0x1c0a 0x1>,
- <0xb00 &apps_smmu 0x1c0b 0x1>,
- <0xc00 &apps_smmu 0x1c0c 0x1>,
- <0xd00 &apps_smmu 0x1c0d 0x1>,
- <0xe00 &apps_smmu 0x1c0e 0x1>,
- <0xf00 &apps_smmu 0x1c0f 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1c00 0x0 0x1>,
+ <0x100 &apps_smmu 0x1c01 0x0 0x1>,
+ <0x200 &apps_smmu 0x1c02 0x0 0x1>,
+ <0x300 &apps_smmu 0x1c03 0x0 0x1>,
+ <0x400 &apps_smmu 0x1c04 0x0 0x1>,
+ <0x500 &apps_smmu 0x1c05 0x0 0x1>,
+ <0x600 &apps_smmu 0x1c06 0x0 0x1>,
+ <0x700 &apps_smmu 0x1c07 0x0 0x1>,
+ <0x800 &apps_smmu 0x1c08 0x0 0x1>,
+ <0x900 &apps_smmu 0x1c09 0x0 0x1>,
+ <0xa00 &apps_smmu 0x1c0a 0x0 0x1>,
+ <0xb00 &apps_smmu 0x1c0b 0x0 0x1>,
+ <0xc00 &apps_smmu 0x1c0c 0x0 0x1>,
+ <0xd00 &apps_smmu 0x1c0d 0x0 0x1>,
+ <0xe00 &apps_smmu 0x1c0e 0x0 0x1>,
+ <0xf00 &apps_smmu 0x1c0f 0x0 0x1>;
resets = <&gcc GCC_PCIE_1_BCR>;
reset-names = "pci";
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0686/1518] arm64: dts: qcom: sm8150: Fix the PCIe iommu-map entries
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (684 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0685/1518] arm64: dts: qcom: sdm845: " Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0687/1518] arm64: dts: qcom: sm8250: " Greg Kroah-Hartman
` (312 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Manivannan Sadhasivam, Konrad Dybcio,
Dmitry Baryshkov, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
[ Upstream commit d2e56fb42e3d10d7e711063cdc00523ddb31d544 ]
The IOMMU provider apps_smmu uses '#iommu-cells = <2>', but the PCIe
iommu-map entries specify only one cell for the SID, omitting the SID
mask. This went unnoticed until the OF core started warning with commit
ccb2fd725d41 ("of: Respect #{iommu,msi}-cells in maps"):
iommu-map has 1-cell entries targeting 2-cell #iommu-cells, treating as 1-cell output
So fix the entries to match the provider's '#iommu-cells' property.
Fixes: a1c86c680533 ("arm64: dts: qcom: sm8150: Add PCIe nodes")
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260730-iommu-map-fix-v1-6-83405d37ba41@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sm8150.dtsi | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sm8150.dtsi b/arch/arm64/boot/dts/qcom/sm8150.dtsi
index e1f480e3ed0b7..35981d6026b3c 100644
--- a/arch/arm64/boot/dts/qcom/sm8150.dtsi
+++ b/arch/arm64/boot/dts/qcom/sm8150.dtsi
@@ -1884,8 +1884,8 @@ pcie0: pcie@1c00000 {
"bus_slave",
"slave_q2a";
- iommu-map = <0x0 &apps_smmu 0x1d80 0x1>,
- <0x100 &apps_smmu 0x1d81 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1d80 0x0 0x1>,
+ <0x100 &apps_smmu 0x1d81 0x0 0x1>;
resets = <&gcc GCC_PCIE_0_BCR>;
reset-names = "pci";
@@ -2002,8 +2002,8 @@ pcie1: pcie@1c08000 {
assigned-clocks = <&gcc GCC_PCIE_1_AUX_CLK>;
assigned-clock-rates = <19200000>;
- iommu-map = <0x0 &apps_smmu 0x1e00 0x1>,
- <0x100 &apps_smmu 0x1e01 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1e00 0x0 0x1>,
+ <0x100 &apps_smmu 0x1e01 0x0 0x1>;
resets = <&gcc GCC_PCIE_1_BCR>;
reset-names = "pci";
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0687/1518] arm64: dts: qcom: sm8250: Fix the PCIe iommu-map entries
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (685 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0686/1518] arm64: dts: qcom: sm8150: " Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0688/1518] arm64: dts: qcom: sm8350: " Greg Kroah-Hartman
` (311 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Manivannan Sadhasivam, Konrad Dybcio,
Dmitry Baryshkov, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
[ Upstream commit c41749e9554d4e03e7074f5d1e46140bc4ac77bd ]
The IOMMU provider apps_smmu uses '#iommu-cells = <2>', but the PCIe
iommu-map entries specify only one cell for the SID, omitting the SID
mask. This went unnoticed until the OF core started warning with commit
ccb2fd725d41 ("of: Respect #{iommu,msi}-cells in maps"):
iommu-map has 1-cell entries targeting 2-cell #iommu-cells, treating as 1-cell output
So fix the entries to match the provider's '#iommu-cells' property.
Fixes: e53bdfc00977 ("arm64: dts: qcom: sm8250: Add PCIe support")
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260730-iommu-map-fix-v1-7-83405d37ba41@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sm8250.dtsi | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sm8250.dtsi b/arch/arm64/boot/dts/qcom/sm8250.dtsi
index dfba5bc3ba7cf..26ae05ab663c6 100644
--- a/arch/arm64/boot/dts/qcom/sm8250.dtsi
+++ b/arch/arm64/boot/dts/qcom/sm8250.dtsi
@@ -2190,8 +2190,8 @@ pcie0: pcie@1c00000 {
"tbu",
"ddrss_sf_tbu";
- iommu-map = <0x0 &apps_smmu 0x1c00 0x1>,
- <0x100 &apps_smmu 0x1c01 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1c00 0x0 0x1>,
+ <0x100 &apps_smmu 0x1c01 0x0 0x1>;
resets = <&gcc GCC_PCIE_0_BCR>;
reset-names = "pci";
@@ -2317,8 +2317,8 @@ pcie1: pcie@1c08000 {
assigned-clocks = <&gcc GCC_PCIE_1_AUX_CLK>;
assigned-clock-rates = <19200000>;
- iommu-map = <0x0 &apps_smmu 0x1c80 0x1>,
- <0x100 &apps_smmu 0x1c81 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1c80 0x0 0x1>,
+ <0x100 &apps_smmu 0x1c81 0x0 0x1>;
resets = <&gcc GCC_PCIE_1_BCR>;
reset-names = "pci";
@@ -2444,8 +2444,8 @@ pcie2: pcie@1c10000 {
assigned-clocks = <&gcc GCC_PCIE_2_AUX_CLK>;
assigned-clock-rates = <19200000>;
- iommu-map = <0x0 &apps_smmu 0x1d00 0x1>,
- <0x100 &apps_smmu 0x1d01 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1d00 0x0 0x1>,
+ <0x100 &apps_smmu 0x1d01 0x0 0x1>;
resets = <&gcc GCC_PCIE_2_BCR>;
reset-names = "pci";
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0688/1518] arm64: dts: qcom: sm8350: Fix the PCIe iommu-map entries
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (686 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0687/1518] arm64: dts: qcom: sm8250: " Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0689/1518] arm64: dts: qcom: sm8450: " Greg Kroah-Hartman
` (310 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Manivannan Sadhasivam, Konrad Dybcio,
Dmitry Baryshkov, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
[ Upstream commit 80337ea3a154230621c0b4e3c831f5d81712ba18 ]
The IOMMU provider apps_smmu uses '#iommu-cells = <2>', but the PCIe
iommu-map entries specify only one cell for the SID, omitting the SID
mask. This went unnoticed until the OF core started warning with commit
ccb2fd725d41 ("of: Respect #{iommu,msi}-cells in maps"):
iommu-map has 1-cell entries targeting 2-cell #iommu-cells, treating as 1-cell output
So fix the entries to match the provider's '#iommu-cells' property.
Fixes: 6daee40678a0 ("arm64: dts: qcom: sm8350: add PCIe devices")
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260730-iommu-map-fix-v1-8-83405d37ba41@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sm8350.dtsi | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sm8350.dtsi b/arch/arm64/boot/dts/qcom/sm8350.dtsi
index af892b76322fd..2bbc1f28be88b 100644
--- a/arch/arm64/boot/dts/qcom/sm8350.dtsi
+++ b/arch/arm64/boot/dts/qcom/sm8350.dtsi
@@ -1575,8 +1575,8 @@ pcie0: pcie@1c00000 {
"aggre1",
"aggre0";
- iommu-map = <0x0 &apps_smmu 0x1c00 0x1>,
- <0x100 &apps_smmu 0x1c01 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1c00 0x0 0x1>,
+ <0x100 &apps_smmu 0x1c01 0x0 0x1>;
resets = <&gcc GCC_PCIE_0_BCR>;
reset-names = "pci";
@@ -1684,8 +1684,8 @@ pcie1: pcie@1c08000 {
"ddrss_sf_tbu",
"aggre1";
- iommu-map = <0x0 &apps_smmu 0x1c80 0x1>,
- <0x100 &apps_smmu 0x1c81 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1c80 0x0 0x1>,
+ <0x100 &apps_smmu 0x1c81 0x0 0x1>;
resets = <&gcc GCC_PCIE_1_BCR>;
reset-names = "pci";
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0689/1518] arm64: dts: qcom: sm8450: Fix the PCIe iommu-map entries
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (687 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0688/1518] arm64: dts: qcom: sm8350: " Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0690/1518] arm64: dts: qcom: sm8550: " Greg Kroah-Hartman
` (309 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Manivannan Sadhasivam, Konrad Dybcio,
Dmitry Baryshkov, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
[ Upstream commit 9b10e56647fa8f7ab62c7e45ebf4b168f7befa7f ]
The IOMMU provider apps_smmu uses '#iommu-cells = <2>', but the PCIe
iommu-map entries specify only one cell for the SID, omitting the SID
mask. This went unnoticed until the OF core started warning with commit
ccb2fd725d41 ("of: Respect #{iommu,msi}-cells in maps"):
iommu-map has 1-cell entries targeting 2-cell #iommu-cells, treating as 1-cell output
So fix the entries to match the provider's '#iommu-cells' property.
Fixes: 7b09b1b47335 ("arm64: dts: qcom: sm8450: add PCIe0 RC device")
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260730-iommu-map-fix-v1-9-83405d37ba41@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sm8450.dtsi | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sm8450.dtsi b/arch/arm64/boot/dts/qcom/sm8450.dtsi
index 991f3cbde1c8d..cabd90b5024a3 100644
--- a/arch/arm64/boot/dts/qcom/sm8450.dtsi
+++ b/arch/arm64/boot/dts/qcom/sm8450.dtsi
@@ -2023,8 +2023,8 @@ &mc_virt SLAVE_EBI1 QCOM_ICC_TAG_ALWAYS>,
"aggre0",
"aggre1";
- iommu-map = <0x0 &apps_smmu 0x1c00 0x1>,
- <0x100 &apps_smmu 0x1c01 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1c00 0x0 0x1>,
+ <0x100 &apps_smmu 0x1c01 0x0 0x1>;
resets = <&gcc GCC_PCIE_0_BCR>;
reset-names = "pci";
@@ -2185,8 +2185,8 @@ &mc_virt SLAVE_EBI1 QCOM_ICC_TAG_ALWAYS>,
"ddrss_sf_tbu",
"aggre1";
- iommu-map = <0x0 &apps_smmu 0x1c80 0x1>,
- <0x100 &apps_smmu 0x1c81 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1c80 0x0 0x1>,
+ <0x100 &apps_smmu 0x1c81 0x0 0x1>;
resets = <&gcc GCC_PCIE_1_BCR>;
reset-names = "pci";
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0690/1518] arm64: dts: qcom: sm8550: Fix the PCIe iommu-map entries
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (688 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0689/1518] arm64: dts: qcom: sm8450: " Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0691/1518] arm64: dts: qcom: sm8650: " Greg Kroah-Hartman
` (308 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Manivannan Sadhasivam,
Neil Armstrong, Konrad Dybcio, Dmitry Baryshkov, Bjorn Andersson,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
[ Upstream commit 16d98ee918d63018eaa6cc260791b71319aa4faa ]
The IOMMU provider apps_smmu uses '#iommu-cells = <2>', but the PCIe
iommu-map entries specify only one cell for the SID, omitting the SID
mask. This went unnoticed until the OF core started warning with commit
ccb2fd725d41 ("of: Respect #{iommu,msi}-cells in maps"):
iommu-map has 1-cell entries targeting 2-cell #iommu-cells, treating as 1-cell output
So fix the entries to match the provider's '#iommu-cells' property.
Fixes: 7d1158c984d3 ("arm64: dts: qcom: sm8550: Add PCIe PHYs and controllers nodes")
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Reviewed-by: Neil Armstrong <neil.armstrong@linaro.org>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260730-iommu-map-fix-v1-10-83405d37ba41@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sm8550.dtsi | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sm8550.dtsi b/arch/arm64/boot/dts/qcom/sm8550.dtsi
index 479c94f5066f3..e38d3ea19e7dd 100644
--- a/arch/arm64/boot/dts/qcom/sm8550.dtsi
+++ b/arch/arm64/boot/dts/qcom/sm8550.dtsi
@@ -2009,8 +2009,8 @@ &mc_virt SLAVE_EBI1 QCOM_ICC_TAG_ALWAYS>,
msi-map = <0x0 &gic_its 0x1400 0x1>,
<0x100 &gic_its 0x1401 0x1>;
- iommu-map = <0x0 &apps_smmu 0x1400 0x1>,
- <0x100 &apps_smmu 0x1401 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1400 0x0 0x1>,
+ <0x100 &apps_smmu 0x1401 0x0 0x1>;
resets = <&gcc GCC_PCIE_0_BCR>;
reset-names = "pci";
@@ -2175,8 +2175,8 @@ &mc_virt SLAVE_EBI1 QCOM_ICC_TAG_ALWAYS>,
msi-map = <0x0 &gic_its 0x1480 0x1>,
<0x100 &gic_its 0x1481 0x1>;
- iommu-map = <0x0 &apps_smmu 0x1480 0x1>,
- <0x100 &apps_smmu 0x1481 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1480 0x0 0x1>,
+ <0x100 &apps_smmu 0x1481 0x0 0x1>;
resets = <&gcc GCC_PCIE_1_BCR>,
<&gcc GCC_PCIE_1_LINK_DOWN_BCR>;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0691/1518] arm64: dts: qcom: sm8650: Fix the PCIe iommu-map entries
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (689 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0690/1518] arm64: dts: qcom: sm8550: " Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0692/1518] arm64: dts: qcom: sm8750: " Greg Kroah-Hartman
` (307 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Manivannan Sadhasivam,
Neil Armstrong, Konrad Dybcio, Dmitry Baryshkov, Bjorn Andersson,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
[ Upstream commit 8ccba7b44609d58db088447a771f6f30cfa8739e ]
The IOMMU provider apps_smmu uses '#iommu-cells = <2>', but the PCIe
iommu-map entries specify only one cell for the SID, omitting the SID
mask. This went unnoticed until the OF core started warning with commit
ccb2fd725d41 ("of: Respect #{iommu,msi}-cells in maps"):
iommu-map has 1-cell entries targeting 2-cell #iommu-cells, treating as 1-cell output
So fix the entries to match the provider's '#iommu-cells' property.
Fixes: 10e024671295 ("arm64: dts: qcom: sm8650: add interconnect dependent device nodes")
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Reviewed-by: Neil Armstrong <neil.armstrong@linaro.org>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260730-iommu-map-fix-v1-11-83405d37ba41@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sm8650.dtsi | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sm8650.dtsi b/arch/arm64/boot/dts/qcom/sm8650.dtsi
index 6c775ef20cb0a..349ce22c6b686 100644
--- a/arch/arm64/boot/dts/qcom/sm8650.dtsi
+++ b/arch/arm64/boot/dts/qcom/sm8650.dtsi
@@ -3626,8 +3626,8 @@ &mc_virt SLAVE_EBI1 QCOM_ICC_TAG_ALWAYS>,
operating-points-v2 = <&pcie0_opp_table>;
- iommu-map = <0 &apps_smmu 0x1400 0x1>,
- <0x100 &apps_smmu 0x1401 0x1>;
+ iommu-map = <0 &apps_smmu 0x1400 0x0 0x1>,
+ <0x100 &apps_smmu 0x1401 0x0 0x1>;
interrupt-map = <0 0 0 1 &intc 0 0 GIC_SPI 149 IRQ_TYPE_LEVEL_HIGH 0>,
<0 0 0 2 &intc 0 0 GIC_SPI 150 IRQ_TYPE_LEVEL_HIGH 0>,
@@ -3806,8 +3806,8 @@ &mc_virt SLAVE_EBI1 QCOM_ICC_TAG_ALWAYS>,
operating-points-v2 = <&pcie1_opp_table>;
- iommu-map = <0 &apps_smmu 0x1480 0x1>,
- <0x100 &apps_smmu 0x1481 0x1>;
+ iommu-map = <0 &apps_smmu 0x1480 0x0 0x1>,
+ <0x100 &apps_smmu 0x1481 0x0 0x1>;
interrupt-map = <0 0 0 1 &intc 0 0 GIC_SPI 434 IRQ_TYPE_LEVEL_HIGH 0>,
<0 0 0 2 &intc 0 0 GIC_SPI 435 IRQ_TYPE_LEVEL_HIGH 0>,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0692/1518] arm64: dts: qcom: sm8750: Fix the PCIe iommu-map entries
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (690 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0691/1518] arm64: dts: qcom: sm8650: " Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0693/1518] arm64: dts: qcom: talos: " Greg Kroah-Hartman
` (306 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Manivannan Sadhasivam, Konrad Dybcio,
Dmitry Baryshkov, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
[ Upstream commit 366a540432a38c1c1533a319bc07b333f53752b6 ]
The IOMMU provider apps_smmu uses '#iommu-cells = <2>', but the PCIe
iommu-map entries specify only one cell for the SID, omitting the SID
mask. This went unnoticed until the OF core started warning with commit
ccb2fd725d41 ("of: Respect #{iommu,msi}-cells in maps"):
iommu-map has 1-cell entries targeting 2-cell #iommu-cells, treating as 1-cell output
So fix the entries to match the provider's '#iommu-cells' property.
Fixes: 19f1395333f8 ("arm64: dts: qcom: sm8750: Add PCIe PHY and controller node")
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260730-iommu-map-fix-v1-12-83405d37ba41@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sm8750.dtsi | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sm8750.dtsi b/arch/arm64/boot/dts/qcom/sm8750.dtsi
index b714207e4c158..c6f4a43ff133e 100644
--- a/arch/arm64/boot/dts/qcom/sm8750.dtsi
+++ b/arch/arm64/boot/dts/qcom/sm8750.dtsi
@@ -3393,8 +3393,8 @@ &mc_virt SLAVE_EBI1 QCOM_ICC_TAG_ALWAYS>,
interconnect-names = "pcie-mem",
"cpu-pcie";
- iommu-map = <0x0 &apps_smmu 0x1400 0x1>,
- <0x100 &apps_smmu 0x1401 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1400 0x0 0x1>,
+ <0x100 &apps_smmu 0x1401 0x0 0x1>;
resets = <&gcc GCC_PCIE_0_BCR>;
reset-names = "pci";
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0693/1518] arm64: dts: qcom: talos: Fix the PCIe iommu-map entries
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (691 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0692/1518] arm64: dts: qcom: sm8750: " Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0694/1518] arm64: dts: qcom: lemans: move USB PHYs to a proper place Greg Kroah-Hartman
` (305 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Manivannan Sadhasivam, Konrad Dybcio,
Dmitry Baryshkov, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
[ Upstream commit f7e687d6050f27a03847abadc12d6821576d06ee ]
The IOMMU provider apps_smmu uses '#iommu-cells = <2>', but the PCIe
iommu-map entries specify only one cell for the SID, omitting the SID
mask. This went unnoticed until the OF core started warning with commit
ccb2fd725d41 ("of: Respect #{iommu,msi}-cells in maps"):
iommu-map has 1-cell entries targeting 2-cell #iommu-cells, treating as 1-cell output
So fix the entries to match the provider's '#iommu-cells' property.
Fixes: 718cc7542a00 ("arm64: dts: qcom: qcs615: enable pcie")
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260730-iommu-map-fix-v1-13-83405d37ba41@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sm6150.dtsi | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sm6150.dtsi b/arch/arm64/boot/dts/qcom/sm6150.dtsi
index a066ad5ffde57..ff3ae5688f03e 100644
--- a/arch/arm64/boot/dts/qcom/sm6150.dtsi
+++ b/arch/arm64/boot/dts/qcom/sm6150.dtsi
@@ -1175,8 +1175,8 @@ &mc_virt SLAVE_EBI1 QCOM_ICC_TAG_ALWAYS>,
&config_noc SLAVE_PCIE_0 QCOM_ICC_TAG_ACTIVE_ONLY>;
interconnect-names = "pcie-mem", "cpu-pcie";
- iommu-map = <0x0 &apps_smmu 0x400 0x1>,
- <0x100 &apps_smmu 0x401 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x400 0x0 0x1>,
+ <0x100 &apps_smmu 0x401 0x0 0x1>;
resets = <&gcc GCC_PCIE_0_BCR>;
reset-names = "pci";
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0694/1518] arm64: dts: qcom: lemans: move USB PHYs to a proper place
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (692 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0693/1518] arm64: dts: qcom: talos: " Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0695/1518] arm64: dts: qcom: lemans: add refgen regulator and use it for DSI Greg Kroah-Hartman
` (304 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dmitry Baryshkov, Konrad Dybcio,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
[ Upstream commit 883e20433fe586a6d3e1332d25f5e675921fefd9 ]
Sort the lemans.dtsi, moving USB1 and USB2 PHYs to a proper place,
making the DT file sorted by the address.
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20250921-refgen-v1-2-9d93e64133ea@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Stable-dep-of: 19b4c47fc973 ("arm64: dts: qcom: lemans: Fix the PCIe iommu-map entries")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/lemans.dtsi | 100 +++++++++++++--------------
1 file changed, 50 insertions(+), 50 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/lemans.dtsi b/arch/arm64/boot/dts/qcom/lemans.dtsi
index 496e319d7b111..085129870e42a 100644
--- a/arch/arm64/boot/dts/qcom/lemans.dtsi
+++ b/arch/arm64/boot/dts/qcom/lemans.dtsi
@@ -3905,6 +3905,32 @@ usb_0_hsphy: phy@88e4000 {
status = "disabled";
};
+ usb_1_hsphy: phy@88e6000 {
+ compatible = "qcom,sa8775p-usb-hs-phy",
+ "qcom,usb-snps-hs-5nm-phy";
+ reg = <0 0x088e6000 0 0x120>;
+ clocks = <&gcc GCC_USB_CLKREF_EN>;
+ clock-names = "ref";
+ resets = <&gcc GCC_USB2_PHY_SEC_BCR>;
+
+ #phy-cells = <0>;
+
+ status = "disabled";
+ };
+
+ usb_2_hsphy: phy@88e7000 {
+ compatible = "qcom,sa8775p-usb-hs-phy",
+ "qcom,usb-snps-hs-5nm-phy";
+ reg = <0 0x088e7000 0 0x120>;
+ clocks = <&gcc GCC_USB_CLKREF_EN>;
+ clock-names = "ref";
+ resets = <&gcc GCC_USB3_PHY_TERT_BCR>;
+
+ #phy-cells = <0>;
+
+ status = "disabled";
+ };
+
usb_0_qmpphy: phy@88e8000 {
compatible = "qcom,sa8775p-qmp-usb3-uni-phy";
reg = <0 0x088e8000 0 0x2000>;
@@ -3929,6 +3955,30 @@ usb_0_qmpphy: phy@88e8000 {
status = "disabled";
};
+ usb_1_qmpphy: phy@88ea000 {
+ compatible = "qcom,sa8775p-qmp-usb3-uni-phy";
+ reg = <0 0x088ea000 0 0x2000>;
+
+ clocks = <&gcc GCC_USB3_SEC_PHY_AUX_CLK>,
+ <&gcc GCC_USB_CLKREF_EN>,
+ <&gcc GCC_USB3_SEC_PHY_COM_AUX_CLK>,
+ <&gcc GCC_USB3_SEC_PHY_PIPE_CLK>;
+ clock-names = "aux", "ref", "com_aux", "pipe";
+
+ resets = <&gcc GCC_USB3_PHY_SEC_BCR>,
+ <&gcc GCC_USB3PHY_PHY_SEC_BCR>;
+ reset-names = "phy", "phy_phy";
+
+ power-domains = <&gcc USB30_SEC_GDSC>;
+
+ #clock-cells = <0>;
+ clock-output-names = "usb3_sec_phy_pipe_clk_src";
+
+ #phy-cells = <0>;
+
+ status = "disabled";
+ };
+
usb_0: usb@a600000 {
compatible = "qcom,sa8775p-dwc3", "qcom,snps-dwc3";
reg = <0 0x0a600000 0 0xfc100>;
@@ -3977,43 +4027,6 @@ usb_0: usb@a600000 {
status = "disabled";
};
- usb_1_hsphy: phy@88e6000 {
- compatible = "qcom,sa8775p-usb-hs-phy",
- "qcom,usb-snps-hs-5nm-phy";
- reg = <0 0x088e6000 0 0x120>;
- clocks = <&gcc GCC_USB_CLKREF_EN>;
- clock-names = "ref";
- resets = <&gcc GCC_USB2_PHY_SEC_BCR>;
-
- #phy-cells = <0>;
-
- status = "disabled";
- };
-
- usb_1_qmpphy: phy@88ea000 {
- compatible = "qcom,sa8775p-qmp-usb3-uni-phy";
- reg = <0 0x088ea000 0 0x2000>;
-
- clocks = <&gcc GCC_USB3_SEC_PHY_AUX_CLK>,
- <&gcc GCC_USB_CLKREF_EN>,
- <&gcc GCC_USB3_SEC_PHY_COM_AUX_CLK>,
- <&gcc GCC_USB3_SEC_PHY_PIPE_CLK>;
- clock-names = "aux", "ref", "com_aux", "pipe";
-
- resets = <&gcc GCC_USB3_PHY_SEC_BCR>,
- <&gcc GCC_USB3PHY_PHY_SEC_BCR>;
- reset-names = "phy", "phy_phy";
-
- power-domains = <&gcc USB30_SEC_GDSC>;
-
- #clock-cells = <0>;
- clock-output-names = "usb3_sec_phy_pipe_clk_src";
-
- #phy-cells = <0>;
-
- status = "disabled";
- };
-
usb_1: usb@a800000 {
compatible = "qcom,sa8775p-dwc3", "qcom,snps-dwc3";
reg = <0 0x0a800000 0 0xfc100>;
@@ -4062,19 +4075,6 @@ usb_1: usb@a800000 {
status = "disabled";
};
- usb_2_hsphy: phy@88e7000 {
- compatible = "qcom,sa8775p-usb-hs-phy",
- "qcom,usb-snps-hs-5nm-phy";
- reg = <0 0x088e7000 0 0x120>;
- clocks = <&gcc GCC_USB_CLKREF_EN>;
- clock-names = "ref";
- resets = <&gcc GCC_USB3_PHY_TERT_BCR>;
-
- #phy-cells = <0>;
-
- status = "disabled";
- };
-
usb_2: usb@a400000 {
compatible = "qcom,sa8775p-dwc3", "qcom,snps-dwc3";
reg = <0 0x0a400000 0 0xfc100>;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0695/1518] arm64: dts: qcom: lemans: add refgen regulator and use it for DSI
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (693 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0694/1518] arm64: dts: qcom: lemans: move USB PHYs to a proper place Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0696/1518] arm64: dts: qcom: lemans: add QCrypto node Greg Kroah-Hartman
` (303 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dmitry Baryshkov, Bjorn Andersson,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
[ Upstream commit 7522c9ffaa97041a1a5dfdcb460d2a2b89f860b1 ]
Add the refgen regulator block and use it for the DSI controllers.
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20250921-refgen-v1-3-9d93e64133ea@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Stable-dep-of: 19b4c47fc973 ("arm64: dts: qcom: lemans: Fix the PCIe iommu-map entries")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/lemans.dtsi | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/arch/arm64/boot/dts/qcom/lemans.dtsi b/arch/arm64/boot/dts/qcom/lemans.dtsi
index 085129870e42a..9ea0bf47851b1 100644
--- a/arch/arm64/boot/dts/qcom/lemans.dtsi
+++ b/arch/arm64/boot/dts/qcom/lemans.dtsi
@@ -3979,6 +3979,12 @@ usb_1_qmpphy: phy@88ea000 {
status = "disabled";
};
+ refgen: regulator@891c000 {
+ compatible = "qcom,sa8775p-refgen-regulator",
+ "qcom,sm8250-refgen-regulator";
+ reg = <0x0 0x0891c000 0x0 0x84>;
+ };
+
usb_0: usb@a600000 {
compatible = "qcom,sa8775p-dwc3", "qcom,snps-dwc3";
reg = <0 0x0a600000 0 0xfc100>;
@@ -4904,6 +4910,8 @@ mdss0_dsi0: dsi@ae94000 {
operating-points-v2 = <&mdss_dsi_opp_table>;
power-domains = <&rpmhpd SA8775P_MMCX>;
+ refgen-supply = <&refgen>;
+
#address-cells = <1>;
#size-cells = <0>;
@@ -4986,6 +4994,8 @@ mdss0_dsi1: dsi@ae96000 {
operating-points-v2 = <&mdss_dsi_opp_table>;
power-domains = <&rpmhpd SA8775P_MMCX>;
+ refgen-supply = <&refgen>;
+
#address-cells = <1>;
#size-cells = <0>;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0696/1518] arm64: dts: qcom: lemans: add QCrypto node
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (694 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0695/1518] arm64: dts: qcom: lemans: add refgen regulator and use it for DSI Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0697/1518] arm64: dts: qcom: sa8775p: Add reg and clocks for QoS configuration Greg Kroah-Hartman
` (302 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dmitry Baryshkov, Abhinaba Rakshit,
Konrad Dybcio, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Abhinaba Rakshit <abhinaba.rakshit@oss.qualcomm.com>
[ Upstream commit 173c43d0e4a435a95568d6b912d0d45c37d6d75f ]
Add Qualcomm Crypto Engine device node for LeMans platform.
QCE and Crypto DMA nodes patch was applied as part of the
commit 7ff3da43ef44 ("arm64: dts: qcom: sa8775p: add QCrypto nodes"),
however was partially reverted by commit 92979f12a201 ("arm64: dts: qcom:
sa8775p: Partially revert "arm64: dts: qcom: sa8775p: add QCrypto nodes"")
due to compatible-string being miss-matched against schema.
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Abhinaba Rakshit <abhinaba.rakshit@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20251224-enable-qualcomm-crypto-engine-for-lemans-v2-1-a707e3d38765@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Stable-dep-of: 19b4c47fc973 ("arm64: dts: qcom: lemans: Fix the PCIe iommu-map entries")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/lemans.dtsi | 12 ++++++++++++
1 file changed, 12 insertions(+)
diff --git a/arch/arm64/boot/dts/qcom/lemans.dtsi b/arch/arm64/boot/dts/qcom/lemans.dtsi
index 9ea0bf47851b1..72d8270cf3af0 100644
--- a/arch/arm64/boot/dts/qcom/lemans.dtsi
+++ b/arch/arm64/boot/dts/qcom/lemans.dtsi
@@ -2773,6 +2773,18 @@ cryptobam: dma-controller@1dc4000 {
<&apps_smmu 0x481 0x00>;
};
+ crypto: crypto@1dfa000 {
+ compatible = "qcom,sa8775p-qce", "qcom,sm8150-qce", "qcom,qce";
+ reg = <0x0 0x01dfa000 0x0 0x6000>;
+ dmas = <&cryptobam 4>, <&cryptobam 5>;
+ dma-names = "rx", "tx";
+ iommus = <&apps_smmu 0x480 0x0>,
+ <&apps_smmu 0x481 0x0>;
+ interconnects = <&aggre2_noc MASTER_CRYPTO_CORE0 QCOM_ICC_TAG_ALWAYS
+ &mc_virt SLAVE_EBI1 QCOM_ICC_TAG_ALWAYS>;
+ interconnect-names = "memory";
+ };
+
ctcu@4001000 {
compatible = "qcom,sa8775p-ctcu";
reg = <0x0 0x04001000 0x0 0x1000>;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0697/1518] arm64: dts: qcom: sa8775p: Add reg and clocks for QoS configuration
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (695 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0696/1518] arm64: dts: qcom: lemans: add QCrypto node Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0698/1518] arm64: dts: qcom: lemans: Move PCIe devices into soc node Greg Kroah-Hartman
` (301 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Odelu Kukatla, Dmitry Baryshkov,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Odelu Kukatla <odelu.kukatla@oss.qualcomm.com>
[ Upstream commit e7fc2fee4212714485d0efb12cdd9fbb51dde078 ]
Add register addresses and clocks which need to be enabled for
configuring QoS on sa8775p SoC.
Signed-off-by: Odelu Kukatla <odelu.kukatla@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20251001073344.6599-4-odelu.kukatla@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Stable-dep-of: 19b4c47fc973 ("arm64: dts: qcom: lemans: Fix the PCIe iommu-map entries")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/lemans.dtsi | 163 +++++++++++++++------------
1 file changed, 91 insertions(+), 72 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/lemans.dtsi b/arch/arm64/boot/dts/qcom/lemans.dtsi
index 72d8270cf3af0..7dbd31a238d44 100644
--- a/arch/arm64/boot/dts/qcom/lemans.dtsi
+++ b/arch/arm64/boot/dts/qcom/lemans.dtsi
@@ -518,90 +518,18 @@ scm {
};
};
- aggre1_noc: interconnect-aggre1-noc {
- compatible = "qcom,sa8775p-aggre1-noc";
- #interconnect-cells = <2>;
- qcom,bcm-voters = <&apps_bcm_voter>;
- };
-
- aggre2_noc: interconnect-aggre2-noc {
- compatible = "qcom,sa8775p-aggre2-noc";
- #interconnect-cells = <2>;
- qcom,bcm-voters = <&apps_bcm_voter>;
- };
-
clk_virt: interconnect-clk-virt {
compatible = "qcom,sa8775p-clk-virt";
#interconnect-cells = <2>;
qcom,bcm-voters = <&apps_bcm_voter>;
};
- config_noc: interconnect-config-noc {
- compatible = "qcom,sa8775p-config-noc";
- #interconnect-cells = <2>;
- qcom,bcm-voters = <&apps_bcm_voter>;
- };
-
- dc_noc: interconnect-dc-noc {
- compatible = "qcom,sa8775p-dc-noc";
- #interconnect-cells = <2>;
- qcom,bcm-voters = <&apps_bcm_voter>;
- };
-
- gem_noc: interconnect-gem-noc {
- compatible = "qcom,sa8775p-gem-noc";
- #interconnect-cells = <2>;
- qcom,bcm-voters = <&apps_bcm_voter>;
- };
-
- gpdsp_anoc: interconnect-gpdsp-anoc {
- compatible = "qcom,sa8775p-gpdsp-anoc";
- #interconnect-cells = <2>;
- qcom,bcm-voters = <&apps_bcm_voter>;
- };
-
- lpass_ag_noc: interconnect-lpass-ag-noc {
- compatible = "qcom,sa8775p-lpass-ag-noc";
- #interconnect-cells = <2>;
- qcom,bcm-voters = <&apps_bcm_voter>;
- };
-
mc_virt: interconnect-mc-virt {
compatible = "qcom,sa8775p-mc-virt";
#interconnect-cells = <2>;
qcom,bcm-voters = <&apps_bcm_voter>;
};
- mmss_noc: interconnect-mmss-noc {
- compatible = "qcom,sa8775p-mmss-noc";
- #interconnect-cells = <2>;
- qcom,bcm-voters = <&apps_bcm_voter>;
- };
-
- nspa_noc: interconnect-nspa-noc {
- compatible = "qcom,sa8775p-nspa-noc";
- #interconnect-cells = <2>;
- qcom,bcm-voters = <&apps_bcm_voter>;
- };
-
- nspb_noc: interconnect-nspb-noc {
- compatible = "qcom,sa8775p-nspb-noc";
- #interconnect-cells = <2>;
- qcom,bcm-voters = <&apps_bcm_voter>;
- };
-
- pcie_anoc: interconnect-pcie-anoc {
- compatible = "qcom,sa8775p-pcie-anoc";
- #interconnect-cells = <2>;
- qcom,bcm-voters = <&apps_bcm_voter>;
- };
-
- system_noc: interconnect-system-noc {
- compatible = "qcom,sa8775p-system-noc";
- #interconnect-cells = <2>;
- qcom,bcm-voters = <&apps_bcm_voter>;
- };
-
/* Will be updated by the bootloader. */
memory@80000000 {
device_type = "memory";
@@ -2689,6 +2617,62 @@ rng: rng@10d2000 {
reg = <0 0x010d2000 0 0x1000>;
};
+ config_noc: interconnect@14c0000 {
+ compatible = "qcom,sa8775p-config-noc";
+ reg = <0x0 0x014c0000 0x0 0x13080>;
+ #interconnect-cells = <2>;
+ qcom,bcm-voters = <&apps_bcm_voter>;
+ };
+
+ system_noc: interconnect@1680000 {
+ compatible = "qcom,sa8775p-system-noc";
+ reg = <0x0 0x01680000 0x0 0x15080>;
+ #interconnect-cells = <2>;
+ qcom,bcm-voters = <&apps_bcm_voter>;
+ };
+
+ aggre1_noc: interconnect@16c0000 {
+ compatible = "qcom,sa8775p-aggre1-noc";
+ reg = <0x0 0x016c0000 0x0 0x18080>;
+ #interconnect-cells = <2>;
+ qcom,bcm-voters = <&apps_bcm_voter>;
+ clocks = <&gcc GCC_AGGRE_UFS_PHY_AXI_CLK>,
+ <&gcc GCC_AGGRE_NOC_QUPV3_AXI_CLK>,
+ <&gcc GCC_AGGRE_USB2_PRIM_AXI_CLK>,
+ <&gcc GCC_AGGRE_USB3_PRIM_AXI_CLK>,
+ <&gcc GCC_AGGRE_USB3_SEC_AXI_CLK>;
+ };
+
+ aggre2_noc: interconnect@1700000 {
+ compatible = "qcom,sa8775p-aggre2-noc";
+ reg = <0x0 0x01700000 0x0 0x1b080>;
+ #interconnect-cells = <2>;
+ qcom,bcm-voters = <&apps_bcm_voter>;
+ clocks = <&gcc GCC_AGGRE_UFS_CARD_AXI_CLK>,
+ <&rpmhcc RPMH_IPA_CLK>;
+ };
+
+ pcie_anoc: interconnect@1760000 {
+ compatible = "qcom,sa8775p-pcie-anoc";
+ reg = <0x0 0x01760000 0x0 0xc080>;
+ #interconnect-cells = <2>;
+ qcom,bcm-voters = <&apps_bcm_voter>;
+ };
+
+ gpdsp_anoc: interconnect@1780000 {
+ compatible = "qcom,sa8775p-gpdsp-anoc";
+ reg = <0x0 0x01780000 0x0 0xe080>;
+ #interconnect-cells = <2>;
+ qcom,bcm-voters = <&apps_bcm_voter>;
+ };
+
+ mmss_noc: interconnect@17a0000 {
+ compatible = "qcom,sa8775p-mmss-noc";
+ reg = <0x0 0x017a0000 0x0 0x40000>;
+ #interconnect-cells = <2>;
+ qcom,bcm-voters = <&apps_bcm_voter>;
+ };
+
ufs_mem_hc: ufshc@1d84000 {
compatible = "qcom,sa8775p-ufshc", "qcom,ufshc", "jedec,ufs-2.0";
reg = <0x0 0x01d84000 0x0 0x3000>;
@@ -2785,6 +2769,13 @@ crypto: crypto@1dfa000 {
interconnect-names = "memory";
};
+ lpass_ag_noc: interconnect@3c40000 {
+ compatible = "qcom,sa8775p-lpass-ag-noc";
+ reg = <0x0 0x03c40000 0x0 0x17200>;
+ #interconnect-cells = <2>;
+ qcom,bcm-voters = <&apps_bcm_voter>;
+ };
+
ctcu@4001000 {
compatible = "qcom,sa8775p-ctcu";
reg = <0x0 0x04001000 0x0 0x1000>;
@@ -3997,6 +3988,20 @@ refgen: regulator@891c000 {
reg = <0x0 0x0891c000 0x0 0x84>;
};
+ dc_noc: interconnect@90e0000 {
+ compatible = "qcom,sa8775p-dc-noc";
+ reg = <0x0 0x090e0000 0x0 0x5080>;
+ #interconnect-cells = <2>;
+ qcom,bcm-voters = <&apps_bcm_voter>;
+ };
+
+ gem_noc: interconnect@9100000 {
+ compatible = "qcom,sa8775p-gem-noc";
+ reg = <0x0 0x09100000 0x0 0xf6080>;
+ #interconnect-cells = <2>;
+ qcom,bcm-voters = <&apps_bcm_voter>;
+ };
+
usb_0: usb@a600000 {
compatible = "qcom,sa8775p-dwc3", "qcom,snps-dwc3";
reg = <0 0x0a600000 0 0xfc100>;
@@ -6906,6 +6911,13 @@ &mc_virt SLAVE_EBI1 QCOM_ICC_TAG_ALWAYS>,
status = "disabled";
};
+ nspa_noc: interconnect@260c0000 {
+ compatible = "qcom,sa8775p-nspa-noc";
+ reg = <0x0 0x260c0000 0x0 0x16080>;
+ #interconnect-cells = <2>;
+ qcom,bcm-voters = <&apps_bcm_voter>;
+ };
+
remoteproc_cdsp0: remoteproc@26300000 {
compatible = "qcom,sa8775p-cdsp0-pas";
reg = <0x0 0x26300000 0x0 0x10000>;
@@ -7038,6 +7050,13 @@ compute-cb@11 {
};
};
+ nspb_noc: interconnect@2a0c0000 {
+ compatible = "qcom,sa8775p-nspb-noc";
+ reg = <0x0 0x2a0c0000 0x0 0x16080>;
+ #interconnect-cells = <2>;
+ qcom,bcm-voters = <&apps_bcm_voter>;
+ };
+
remoteproc_cdsp1: remoteproc@2a300000 {
compatible = "qcom,sa8775p-cdsp1-pas";
reg = <0x0 0x2A300000 0x0 0x10000>;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0698/1518] arm64: dts: qcom: lemans: Move PCIe devices into soc node
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (696 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0697/1518] arm64: dts: qcom: sa8775p: Add reg and clocks for QoS configuration Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0699/1518] arm64: dts: qcom: lemans: Fix the PCIe iommu-map entries Greg Kroah-Hartman
` (300 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shawn Guo, Konrad Dybcio,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shawn Guo <shengchao.guo@oss.qualcomm.com>
[ Upstream commit 8222873cd4698627c08bffb2e40ba6f5a008fe32 ]
These PCIe devices with MMIO address should be inside soc node rather
than outside.
Fixes: 489f14be0e0a ("arm64: dts: qcom: sa8775p: Add pcie0 and pcie1 nodes")
Signed-off-by: Shawn Guo <shengchao.guo@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260331090147.18522-1-shengchao.guo@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Stable-dep-of: 19b4c47fc973 ("arm64: dts: qcom: lemans: Fix the PCIe iommu-map entries")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/lemans.dtsi | 692 +++++++++++++--------------
1 file changed, 346 insertions(+), 346 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/lemans.dtsi b/arch/arm64/boot/dts/qcom/lemans.dtsi
index 7dbd31a238d44..0861e4ead93eb 100644
--- a/arch/arm64/boot/dts/qcom/lemans.dtsi
+++ b/arch/arm64/boot/dts/qcom/lemans.dtsi
@@ -2673,6 +2673,352 @@ mmss_noc: interconnect@17a0000 {
qcom,bcm-voters = <&apps_bcm_voter>;
};
+ pcie0: pcie@1c00000 {
+ compatible = "qcom,pcie-sa8775p";
+ reg = <0x0 0x01c00000 0x0 0x3000>,
+ <0x0 0x40000000 0x0 0xf20>,
+ <0x0 0x40000f20 0x0 0xa8>,
+ <0x0 0x40001000 0x0 0x4000>,
+ <0x0 0x40100000 0x0 0x100000>,
+ <0x0 0x01c03000 0x0 0x1000>;
+ reg-names = "parf", "dbi", "elbi", "atu", "config", "mhi";
+ device_type = "pci";
+
+ #address-cells = <3>;
+ #size-cells = <2>;
+ ranges = <0x01000000 0x0 0x00000000 0x0 0x40200000 0x0 0x100000>,
+ <0x02000000 0x0 0x40300000 0x0 0x40300000 0x0 0x1fd00000>;
+ bus-range = <0x00 0xff>;
+
+ dma-coherent;
+
+ linux,pci-domain = <0>;
+ num-lanes = <2>;
+
+ interrupts = <GIC_SPI 307 IRQ_TYPE_LEVEL_HIGH>,
+ <GIC_SPI 308 IRQ_TYPE_LEVEL_HIGH>,
+ <GIC_SPI 309 IRQ_TYPE_LEVEL_HIGH>,
+ <GIC_SPI 312 IRQ_TYPE_LEVEL_HIGH>,
+ <GIC_SPI 313 IRQ_TYPE_LEVEL_HIGH>,
+ <GIC_SPI 314 IRQ_TYPE_LEVEL_HIGH>,
+ <GIC_SPI 374 IRQ_TYPE_LEVEL_HIGH>,
+ <GIC_SPI 375 IRQ_TYPE_LEVEL_HIGH>,
+ <GIC_SPI 306 IRQ_TYPE_LEVEL_HIGH>;
+ interrupt-names = "msi0",
+ "msi1",
+ "msi2",
+ "msi3",
+ "msi4",
+ "msi5",
+ "msi6",
+ "msi7",
+ "global";
+ #interrupt-cells = <1>;
+ interrupt-map-mask = <0 0 0 0x7>;
+ interrupt-map = <0 0 0 1 &intc GIC_SPI 434 IRQ_TYPE_LEVEL_HIGH>,
+ <0 0 0 2 &intc GIC_SPI 435 IRQ_TYPE_LEVEL_HIGH>,
+ <0 0 0 3 &intc GIC_SPI 438 IRQ_TYPE_LEVEL_HIGH>,
+ <0 0 0 4 &intc GIC_SPI 439 IRQ_TYPE_LEVEL_HIGH>;
+
+ clocks = <&gcc GCC_PCIE_0_AUX_CLK>,
+ <&gcc GCC_PCIE_0_CFG_AHB_CLK>,
+ <&gcc GCC_PCIE_0_MSTR_AXI_CLK>,
+ <&gcc GCC_PCIE_0_SLV_AXI_CLK>,
+ <&gcc GCC_PCIE_0_SLV_Q2A_AXI_CLK>;
+
+ clock-names = "aux",
+ "cfg",
+ "bus_master",
+ "bus_slave",
+ "slave_q2a";
+
+ assigned-clocks = <&gcc GCC_PCIE_0_AUX_CLK>;
+ assigned-clock-rates = <19200000>;
+
+ interconnects = <&pcie_anoc MASTER_PCIE_0 0 &mc_virt SLAVE_EBI1 0>,
+ <&gem_noc MASTER_APPSS_PROC 0 &config_noc SLAVE_PCIE_0 0>;
+ interconnect-names = "pcie-mem", "cpu-pcie";
+
+ iommu-map = <0x0 &pcie_smmu 0x0000 0x1>,
+ <0x100 &pcie_smmu 0x0001 0x1>;
+
+ resets = <&gcc GCC_PCIE_0_BCR>,
+ <&gcc GCC_PCIE_0_LINK_DOWN_BCR>;
+ reset-names = "pci",
+ "link_down";
+
+ power-domains = <&gcc PCIE_0_GDSC>;
+
+ phys = <&pcie0_phy>;
+ phy-names = "pciephy";
+
+ eq-presets-8gts = /bits/ 16 <0x5555 0x5555>;
+ eq-presets-16gts = /bits/ 8 <0x55 0x55>;
+
+ status = "disabled";
+
+ pcieport0: pcie@0 {
+ device_type = "pci";
+ reg = <0x0 0x0 0x0 0x0 0x0>;
+ bus-range = <0x01 0xff>;
+
+ #address-cells = <3>;
+ #size-cells = <2>;
+ ranges;
+ };
+ };
+
+ pcie0_ep: pcie-ep@1c00000 {
+ compatible = "qcom,sa8775p-pcie-ep";
+ reg = <0x0 0x01c00000 0x0 0x3000>,
+ <0x0 0x40000000 0x0 0xf20>,
+ <0x0 0x40000f20 0x0 0xa8>,
+ <0x0 0x40001000 0x0 0x4000>,
+ <0x0 0x40200000 0x0 0x1fe00000>,
+ <0x0 0x01c03000 0x0 0x1000>,
+ <0x0 0x40005000 0x0 0x2000>;
+ reg-names = "parf", "dbi", "elbi", "atu", "addr_space",
+ "mmio", "dma";
+
+ clocks = <&gcc GCC_PCIE_0_AUX_CLK>,
+ <&gcc GCC_PCIE_0_CFG_AHB_CLK>,
+ <&gcc GCC_PCIE_0_MSTR_AXI_CLK>,
+ <&gcc GCC_PCIE_0_SLV_AXI_CLK>,
+ <&gcc GCC_PCIE_0_SLV_Q2A_AXI_CLK>;
+
+ clock-names = "aux",
+ "cfg",
+ "bus_master",
+ "bus_slave",
+ "slave_q2a";
+
+ interrupts = <GIC_SPI 306 IRQ_TYPE_LEVEL_HIGH>,
+ <GIC_SPI 147 IRQ_TYPE_LEVEL_HIGH>,
+ <GIC_SPI 630 IRQ_TYPE_LEVEL_HIGH>;
+
+ interrupt-names = "global", "doorbell", "dma";
+
+ interconnects = <&pcie_anoc MASTER_PCIE_0 0 &mc_virt SLAVE_EBI1 0>,
+ <&gem_noc MASTER_APPSS_PROC 0 &config_noc SLAVE_PCIE_0 0>;
+ interconnect-names = "pcie-mem", "cpu-pcie";
+
+ dma-coherent;
+ iommus = <&pcie_smmu 0x0000 0x7f>;
+ resets = <&gcc GCC_PCIE_0_BCR>;
+ reset-names = "core";
+ power-domains = <&gcc PCIE_0_GDSC>;
+ phys = <&pcie0_phy>;
+ phy-names = "pciephy";
+ num-lanes = <2>;
+ linux,pci-domain = <0>;
+
+ status = "disabled";
+ };
+
+ pcie0_phy: phy@1c04000 {
+ compatible = "qcom,sa8775p-qmp-gen4x2-pcie-phy";
+ reg = <0x0 0x1c04000 0x0 0x2000>;
+
+ clocks = <&gcc GCC_PCIE_0_PHY_AUX_CLK>,
+ <&gcc GCC_PCIE_0_CFG_AHB_CLK>,
+ <&gcc GCC_PCIE_CLKREF_EN>,
+ <&gcc GCC_PCIE_0_PHY_RCHNG_CLK>,
+ <&gcc GCC_PCIE_0_PIPE_CLK>,
+ <&gcc GCC_PCIE_0_PIPEDIV2_CLK>;
+ clock-names = "aux",
+ "cfg_ahb",
+ "ref",
+ "rchng",
+ "pipe",
+ "pipediv2";
+
+ assigned-clocks = <&gcc GCC_PCIE_0_PHY_RCHNG_CLK>;
+ assigned-clock-rates = <100000000>;
+
+ resets = <&gcc GCC_PCIE_0_PHY_BCR>;
+ reset-names = "phy";
+
+ #clock-cells = <0>;
+ clock-output-names = "pcie_0_pipe_clk";
+
+ #phy-cells = <0>;
+
+ status = "disabled";
+ };
+
+ pcie1: pcie@1c10000 {
+ compatible = "qcom,pcie-sa8775p";
+ reg = <0x0 0x01c10000 0x0 0x3000>,
+ <0x0 0x60000000 0x0 0xf20>,
+ <0x0 0x60000f20 0x0 0xa8>,
+ <0x0 0x60001000 0x0 0x4000>,
+ <0x0 0x60100000 0x0 0x100000>,
+ <0x0 0x01c13000 0x0 0x1000>;
+ reg-names = "parf", "dbi", "elbi", "atu", "config", "mhi";
+ device_type = "pci";
+
+ #address-cells = <3>;
+ #size-cells = <2>;
+ ranges = <0x01000000 0x0 0x00000000 0x0 0x60200000 0x0 0x100000>,
+ <0x02000000 0x0 0x60300000 0x0 0x60300000 0x0 0x1fd00000>;
+ bus-range = <0x00 0xff>;
+
+ dma-coherent;
+
+ linux,pci-domain = <1>;
+ num-lanes = <4>;
+
+ interrupts = <GIC_SPI 519 IRQ_TYPE_LEVEL_HIGH>,
+ <GIC_SPI 140 IRQ_TYPE_LEVEL_HIGH>,
+ <GIC_SPI 141 IRQ_TYPE_LEVEL_HIGH>,
+ <GIC_SPI 142 IRQ_TYPE_LEVEL_HIGH>,
+ <GIC_SPI 143 IRQ_TYPE_LEVEL_HIGH>,
+ <GIC_SPI 144 IRQ_TYPE_LEVEL_HIGH>,
+ <GIC_SPI 145 IRQ_TYPE_LEVEL_HIGH>,
+ <GIC_SPI 146 IRQ_TYPE_LEVEL_HIGH>,
+ <GIC_SPI 518 IRQ_TYPE_LEVEL_HIGH>;
+ interrupt-names = "msi0",
+ "msi1",
+ "msi2",
+ "msi3",
+ "msi4",
+ "msi5",
+ "msi6",
+ "msi7",
+ "global";
+ #interrupt-cells = <1>;
+ interrupt-map-mask = <0 0 0 0x7>;
+ interrupt-map = <0 0 0 1 &intc GIC_SPI 148 IRQ_TYPE_LEVEL_HIGH>,
+ <0 0 0 2 &intc GIC_SPI 149 IRQ_TYPE_LEVEL_HIGH>,
+ <0 0 0 3 &intc GIC_SPI 150 IRQ_TYPE_LEVEL_HIGH>,
+ <0 0 0 4 &intc GIC_SPI 151 IRQ_TYPE_LEVEL_HIGH>;
+
+ clocks = <&gcc GCC_PCIE_1_AUX_CLK>,
+ <&gcc GCC_PCIE_1_CFG_AHB_CLK>,
+ <&gcc GCC_PCIE_1_MSTR_AXI_CLK>,
+ <&gcc GCC_PCIE_1_SLV_AXI_CLK>,
+ <&gcc GCC_PCIE_1_SLV_Q2A_AXI_CLK>;
+
+ clock-names = "aux",
+ "cfg",
+ "bus_master",
+ "bus_slave",
+ "slave_q2a";
+
+ assigned-clocks = <&gcc GCC_PCIE_1_AUX_CLK>;
+ assigned-clock-rates = <19200000>;
+
+ interconnects = <&pcie_anoc MASTER_PCIE_1 0 &mc_virt SLAVE_EBI1 0>,
+ <&gem_noc MASTER_APPSS_PROC 0 &config_noc SLAVE_PCIE_1 0>;
+ interconnect-names = "pcie-mem", "cpu-pcie";
+
+ iommu-map = <0x0 &pcie_smmu 0x0080 0x1>,
+ <0x100 &pcie_smmu 0x0081 0x1>;
+
+ resets = <&gcc GCC_PCIE_1_BCR>,
+ <&gcc GCC_PCIE_1_LINK_DOWN_BCR>;
+ reset-names = "pci",
+ "link_down";
+
+ power-domains = <&gcc PCIE_1_GDSC>;
+
+ phys = <&pcie1_phy>;
+ phy-names = "pciephy";
+
+ eq-presets-8gts = /bits/ 16 <0x5555 0x5555 0x5555 0x5555>;
+ eq-presets-16gts = /bits/ 8 <0x55 0x55 0x55 0x55>;
+
+ status = "disabled";
+
+ pcie@0 {
+ device_type = "pci";
+ reg = <0x0 0x0 0x0 0x0 0x0>;
+ bus-range = <0x01 0xff>;
+
+ #address-cells = <3>;
+ #size-cells = <2>;
+ ranges;
+ };
+ };
+
+ pcie1_ep: pcie-ep@1c10000 {
+ compatible = "qcom,sa8775p-pcie-ep";
+ reg = <0x0 0x01c10000 0x0 0x3000>,
+ <0x0 0x60000000 0x0 0xf20>,
+ <0x0 0x60000f20 0x0 0xa8>,
+ <0x0 0x60001000 0x0 0x4000>,
+ <0x0 0x60200000 0x0 0x1fe00000>,
+ <0x0 0x01c13000 0x0 0x1000>,
+ <0x0 0x60005000 0x0 0x2000>;
+ reg-names = "parf", "dbi", "elbi", "atu", "addr_space",
+ "mmio", "dma";
+
+ clocks = <&gcc GCC_PCIE_1_AUX_CLK>,
+ <&gcc GCC_PCIE_1_CFG_AHB_CLK>,
+ <&gcc GCC_PCIE_1_MSTR_AXI_CLK>,
+ <&gcc GCC_PCIE_1_SLV_AXI_CLK>,
+ <&gcc GCC_PCIE_1_SLV_Q2A_AXI_CLK>;
+
+ clock-names = "aux",
+ "cfg",
+ "bus_master",
+ "bus_slave",
+ "slave_q2a";
+
+ interrupts = <GIC_SPI 518 IRQ_TYPE_LEVEL_HIGH>,
+ <GIC_SPI 152 IRQ_TYPE_LEVEL_HIGH>,
+ <GIC_SPI 474 IRQ_TYPE_LEVEL_HIGH>;
+
+ interrupt-names = "global", "doorbell", "dma";
+
+ interconnects = <&pcie_anoc MASTER_PCIE_1 0 &mc_virt SLAVE_EBI1 0>,
+ <&gem_noc MASTER_APPSS_PROC 0 &config_noc SLAVE_PCIE_1 0>;
+ interconnect-names = "pcie-mem", "cpu-pcie";
+
+ dma-coherent;
+ iommus = <&pcie_smmu 0x80 0x7f>;
+ resets = <&gcc GCC_PCIE_1_BCR>;
+ reset-names = "core";
+ power-domains = <&gcc PCIE_1_GDSC>;
+ phys = <&pcie1_phy>;
+ phy-names = "pciephy";
+ num-lanes = <4>;
+ linux,pci-domain = <1>;
+
+ status = "disabled";
+ };
+
+ pcie1_phy: phy@1c14000 {
+ compatible = "qcom,sa8775p-qmp-gen4x4-pcie-phy";
+ reg = <0x0 0x1c14000 0x0 0x4000>;
+
+ clocks = <&gcc GCC_PCIE_1_PHY_AUX_CLK>,
+ <&gcc GCC_PCIE_1_CFG_AHB_CLK>,
+ <&gcc GCC_PCIE_CLKREF_EN>,
+ <&gcc GCC_PCIE_1_PHY_RCHNG_CLK>,
+ <&gcc GCC_PCIE_1_PIPE_CLK>,
+ <&gcc GCC_PCIE_1_PIPEDIV2_CLK>;
+ clock-names = "aux",
+ "cfg_ahb",
+ "ref",
+ "rchng",
+ "pipe",
+ "pipediv2";
+
+ assigned-clocks = <&gcc GCC_PCIE_1_PHY_RCHNG_CLK>;
+ assigned-clock-rates = <100000000>;
+
+ resets = <&gcc GCC_PCIE_1_PHY_BCR>;
+ reset-names = "phy";
+
+ #clock-cells = <0>;
+ clock-output-names = "pcie_1_pipe_clk";
+
+ #phy-cells = <0>;
+
+ status = "disabled";
+ };
+
ufs_mem_hc: ufshc@1d84000 {
compatible = "qcom,sa8775p-ufshc", "qcom,ufshc", "jedec,ufs-2.0";
reg = <0x0 0x01d84000 0x0 0x3000>;
@@ -8305,350 +8651,4 @@ arch_timer: timer {
<GIC_PPI 11 (GIC_CPU_MASK_SIMPLE(8) | IRQ_TYPE_LEVEL_LOW)>,
<GIC_PPI 10 (GIC_CPU_MASK_SIMPLE(8) | IRQ_TYPE_LEVEL_LOW)>;
};
-
- pcie0: pcie@1c00000 {
- compatible = "qcom,pcie-sa8775p";
- reg = <0x0 0x01c00000 0x0 0x3000>,
- <0x0 0x40000000 0x0 0xf20>,
- <0x0 0x40000f20 0x0 0xa8>,
- <0x0 0x40001000 0x0 0x4000>,
- <0x0 0x40100000 0x0 0x100000>,
- <0x0 0x01c03000 0x0 0x1000>;
- reg-names = "parf", "dbi", "elbi", "atu", "config", "mhi";
- device_type = "pci";
-
- #address-cells = <3>;
- #size-cells = <2>;
- ranges = <0x01000000 0x0 0x00000000 0x0 0x40200000 0x0 0x100000>,
- <0x02000000 0x0 0x40300000 0x0 0x40300000 0x0 0x1fd00000>;
- bus-range = <0x00 0xff>;
-
- dma-coherent;
-
- linux,pci-domain = <0>;
- num-lanes = <2>;
-
- interrupts = <GIC_SPI 307 IRQ_TYPE_LEVEL_HIGH>,
- <GIC_SPI 308 IRQ_TYPE_LEVEL_HIGH>,
- <GIC_SPI 309 IRQ_TYPE_LEVEL_HIGH>,
- <GIC_SPI 312 IRQ_TYPE_LEVEL_HIGH>,
- <GIC_SPI 313 IRQ_TYPE_LEVEL_HIGH>,
- <GIC_SPI 314 IRQ_TYPE_LEVEL_HIGH>,
- <GIC_SPI 374 IRQ_TYPE_LEVEL_HIGH>,
- <GIC_SPI 375 IRQ_TYPE_LEVEL_HIGH>,
- <GIC_SPI 306 IRQ_TYPE_LEVEL_HIGH>;
- interrupt-names = "msi0",
- "msi1",
- "msi2",
- "msi3",
- "msi4",
- "msi5",
- "msi6",
- "msi7",
- "global";
- #interrupt-cells = <1>;
- interrupt-map-mask = <0 0 0 0x7>;
- interrupt-map = <0 0 0 1 &intc GIC_SPI 434 IRQ_TYPE_LEVEL_HIGH>,
- <0 0 0 2 &intc GIC_SPI 435 IRQ_TYPE_LEVEL_HIGH>,
- <0 0 0 3 &intc GIC_SPI 438 IRQ_TYPE_LEVEL_HIGH>,
- <0 0 0 4 &intc GIC_SPI 439 IRQ_TYPE_LEVEL_HIGH>;
-
- clocks = <&gcc GCC_PCIE_0_AUX_CLK>,
- <&gcc GCC_PCIE_0_CFG_AHB_CLK>,
- <&gcc GCC_PCIE_0_MSTR_AXI_CLK>,
- <&gcc GCC_PCIE_0_SLV_AXI_CLK>,
- <&gcc GCC_PCIE_0_SLV_Q2A_AXI_CLK>;
-
- clock-names = "aux",
- "cfg",
- "bus_master",
- "bus_slave",
- "slave_q2a";
-
- assigned-clocks = <&gcc GCC_PCIE_0_AUX_CLK>;
- assigned-clock-rates = <19200000>;
-
- interconnects = <&pcie_anoc MASTER_PCIE_0 0 &mc_virt SLAVE_EBI1 0>,
- <&gem_noc MASTER_APPSS_PROC 0 &config_noc SLAVE_PCIE_0 0>;
- interconnect-names = "pcie-mem", "cpu-pcie";
-
- iommu-map = <0x0 &pcie_smmu 0x0000 0x1>,
- <0x100 &pcie_smmu 0x0001 0x1>;
-
- resets = <&gcc GCC_PCIE_0_BCR>,
- <&gcc GCC_PCIE_0_LINK_DOWN_BCR>;
- reset-names = "pci",
- "link_down";
-
- power-domains = <&gcc PCIE_0_GDSC>;
-
- phys = <&pcie0_phy>;
- phy-names = "pciephy";
-
- eq-presets-8gts = /bits/ 16 <0x5555 0x5555>;
- eq-presets-16gts = /bits/ 8 <0x55 0x55>;
-
- status = "disabled";
-
- pcieport0: pcie@0 {
- device_type = "pci";
- reg = <0x0 0x0 0x0 0x0 0x0>;
- bus-range = <0x01 0xff>;
-
- #address-cells = <3>;
- #size-cells = <2>;
- ranges;
- };
- };
-
- pcie0_ep: pcie-ep@1c00000 {
- compatible = "qcom,sa8775p-pcie-ep";
- reg = <0x0 0x01c00000 0x0 0x3000>,
- <0x0 0x40000000 0x0 0xf20>,
- <0x0 0x40000f20 0x0 0xa8>,
- <0x0 0x40001000 0x0 0x4000>,
- <0x0 0x40200000 0x0 0x1fe00000>,
- <0x0 0x01c03000 0x0 0x1000>,
- <0x0 0x40005000 0x0 0x2000>;
- reg-names = "parf", "dbi", "elbi", "atu", "addr_space",
- "mmio", "dma";
-
- clocks = <&gcc GCC_PCIE_0_AUX_CLK>,
- <&gcc GCC_PCIE_0_CFG_AHB_CLK>,
- <&gcc GCC_PCIE_0_MSTR_AXI_CLK>,
- <&gcc GCC_PCIE_0_SLV_AXI_CLK>,
- <&gcc GCC_PCIE_0_SLV_Q2A_AXI_CLK>;
-
- clock-names = "aux",
- "cfg",
- "bus_master",
- "bus_slave",
- "slave_q2a";
-
- interrupts = <GIC_SPI 306 IRQ_TYPE_LEVEL_HIGH>,
- <GIC_SPI 147 IRQ_TYPE_LEVEL_HIGH>,
- <GIC_SPI 630 IRQ_TYPE_LEVEL_HIGH>;
-
- interrupt-names = "global", "doorbell", "dma";
-
- interconnects = <&pcie_anoc MASTER_PCIE_0 0 &mc_virt SLAVE_EBI1 0>,
- <&gem_noc MASTER_APPSS_PROC 0 &config_noc SLAVE_PCIE_0 0>;
- interconnect-names = "pcie-mem", "cpu-pcie";
-
- dma-coherent;
- iommus = <&pcie_smmu 0x0000 0x7f>;
- resets = <&gcc GCC_PCIE_0_BCR>;
- reset-names = "core";
- power-domains = <&gcc PCIE_0_GDSC>;
- phys = <&pcie0_phy>;
- phy-names = "pciephy";
- num-lanes = <2>;
- linux,pci-domain = <0>;
-
- status = "disabled";
- };
-
- pcie0_phy: phy@1c04000 {
- compatible = "qcom,sa8775p-qmp-gen4x2-pcie-phy";
- reg = <0x0 0x1c04000 0x0 0x2000>;
-
- clocks = <&gcc GCC_PCIE_0_PHY_AUX_CLK>,
- <&gcc GCC_PCIE_0_CFG_AHB_CLK>,
- <&gcc GCC_PCIE_CLKREF_EN>,
- <&gcc GCC_PCIE_0_PHY_RCHNG_CLK>,
- <&gcc GCC_PCIE_0_PIPE_CLK>,
- <&gcc GCC_PCIE_0_PIPEDIV2_CLK>;
- clock-names = "aux",
- "cfg_ahb",
- "ref",
- "rchng",
- "pipe",
- "pipediv2";
-
- assigned-clocks = <&gcc GCC_PCIE_0_PHY_RCHNG_CLK>;
- assigned-clock-rates = <100000000>;
-
- resets = <&gcc GCC_PCIE_0_PHY_BCR>;
- reset-names = "phy";
-
- #clock-cells = <0>;
- clock-output-names = "pcie_0_pipe_clk";
-
- #phy-cells = <0>;
-
- status = "disabled";
- };
-
- pcie1: pcie@1c10000 {
- compatible = "qcom,pcie-sa8775p";
- reg = <0x0 0x01c10000 0x0 0x3000>,
- <0x0 0x60000000 0x0 0xf20>,
- <0x0 0x60000f20 0x0 0xa8>,
- <0x0 0x60001000 0x0 0x4000>,
- <0x0 0x60100000 0x0 0x100000>,
- <0x0 0x01c13000 0x0 0x1000>;
- reg-names = "parf", "dbi", "elbi", "atu", "config", "mhi";
- device_type = "pci";
-
- #address-cells = <3>;
- #size-cells = <2>;
- ranges = <0x01000000 0x0 0x00000000 0x0 0x60200000 0x0 0x100000>,
- <0x02000000 0x0 0x60300000 0x0 0x60300000 0x0 0x1fd00000>;
- bus-range = <0x00 0xff>;
-
- dma-coherent;
-
- linux,pci-domain = <1>;
- num-lanes = <4>;
-
- interrupts = <GIC_SPI 519 IRQ_TYPE_LEVEL_HIGH>,
- <GIC_SPI 140 IRQ_TYPE_LEVEL_HIGH>,
- <GIC_SPI 141 IRQ_TYPE_LEVEL_HIGH>,
- <GIC_SPI 142 IRQ_TYPE_LEVEL_HIGH>,
- <GIC_SPI 143 IRQ_TYPE_LEVEL_HIGH>,
- <GIC_SPI 144 IRQ_TYPE_LEVEL_HIGH>,
- <GIC_SPI 145 IRQ_TYPE_LEVEL_HIGH>,
- <GIC_SPI 146 IRQ_TYPE_LEVEL_HIGH>,
- <GIC_SPI 518 IRQ_TYPE_LEVEL_HIGH>;
- interrupt-names = "msi0",
- "msi1",
- "msi2",
- "msi3",
- "msi4",
- "msi5",
- "msi6",
- "msi7",
- "global";
- #interrupt-cells = <1>;
- interrupt-map-mask = <0 0 0 0x7>;
- interrupt-map = <0 0 0 1 &intc GIC_SPI 148 IRQ_TYPE_LEVEL_HIGH>,
- <0 0 0 2 &intc GIC_SPI 149 IRQ_TYPE_LEVEL_HIGH>,
- <0 0 0 3 &intc GIC_SPI 150 IRQ_TYPE_LEVEL_HIGH>,
- <0 0 0 4 &intc GIC_SPI 151 IRQ_TYPE_LEVEL_HIGH>;
-
- clocks = <&gcc GCC_PCIE_1_AUX_CLK>,
- <&gcc GCC_PCIE_1_CFG_AHB_CLK>,
- <&gcc GCC_PCIE_1_MSTR_AXI_CLK>,
- <&gcc GCC_PCIE_1_SLV_AXI_CLK>,
- <&gcc GCC_PCIE_1_SLV_Q2A_AXI_CLK>;
-
- clock-names = "aux",
- "cfg",
- "bus_master",
- "bus_slave",
- "slave_q2a";
-
- assigned-clocks = <&gcc GCC_PCIE_1_AUX_CLK>;
- assigned-clock-rates = <19200000>;
-
- interconnects = <&pcie_anoc MASTER_PCIE_1 0 &mc_virt SLAVE_EBI1 0>,
- <&gem_noc MASTER_APPSS_PROC 0 &config_noc SLAVE_PCIE_1 0>;
- interconnect-names = "pcie-mem", "cpu-pcie";
-
- iommu-map = <0x0 &pcie_smmu 0x0080 0x1>,
- <0x100 &pcie_smmu 0x0081 0x1>;
-
- resets = <&gcc GCC_PCIE_1_BCR>,
- <&gcc GCC_PCIE_1_LINK_DOWN_BCR>;
- reset-names = "pci",
- "link_down";
-
- power-domains = <&gcc PCIE_1_GDSC>;
-
- phys = <&pcie1_phy>;
- phy-names = "pciephy";
-
- eq-presets-8gts = /bits/ 16 <0x5555 0x5555 0x5555 0x5555>;
- eq-presets-16gts = /bits/ 8 <0x55 0x55 0x55 0x55>;
-
- status = "disabled";
-
- pcie@0 {
- device_type = "pci";
- reg = <0x0 0x0 0x0 0x0 0x0>;
- bus-range = <0x01 0xff>;
-
- #address-cells = <3>;
- #size-cells = <2>;
- ranges;
- };
- };
-
- pcie1_ep: pcie-ep@1c10000 {
- compatible = "qcom,sa8775p-pcie-ep";
- reg = <0x0 0x01c10000 0x0 0x3000>,
- <0x0 0x60000000 0x0 0xf20>,
- <0x0 0x60000f20 0x0 0xa8>,
- <0x0 0x60001000 0x0 0x4000>,
- <0x0 0x60200000 0x0 0x1fe00000>,
- <0x0 0x01c13000 0x0 0x1000>,
- <0x0 0x60005000 0x0 0x2000>;
- reg-names = "parf", "dbi", "elbi", "atu", "addr_space",
- "mmio", "dma";
-
- clocks = <&gcc GCC_PCIE_1_AUX_CLK>,
- <&gcc GCC_PCIE_1_CFG_AHB_CLK>,
- <&gcc GCC_PCIE_1_MSTR_AXI_CLK>,
- <&gcc GCC_PCIE_1_SLV_AXI_CLK>,
- <&gcc GCC_PCIE_1_SLV_Q2A_AXI_CLK>;
-
- clock-names = "aux",
- "cfg",
- "bus_master",
- "bus_slave",
- "slave_q2a";
-
- interrupts = <GIC_SPI 518 IRQ_TYPE_LEVEL_HIGH>,
- <GIC_SPI 152 IRQ_TYPE_LEVEL_HIGH>,
- <GIC_SPI 474 IRQ_TYPE_LEVEL_HIGH>;
-
- interrupt-names = "global", "doorbell", "dma";
-
- interconnects = <&pcie_anoc MASTER_PCIE_1 0 &mc_virt SLAVE_EBI1 0>,
- <&gem_noc MASTER_APPSS_PROC 0 &config_noc SLAVE_PCIE_1 0>;
- interconnect-names = "pcie-mem", "cpu-pcie";
-
- dma-coherent;
- iommus = <&pcie_smmu 0x80 0x7f>;
- resets = <&gcc GCC_PCIE_1_BCR>;
- reset-names = "core";
- power-domains = <&gcc PCIE_1_GDSC>;
- phys = <&pcie1_phy>;
- phy-names = "pciephy";
- num-lanes = <4>;
- linux,pci-domain = <1>;
-
- status = "disabled";
- };
-
- pcie1_phy: phy@1c14000 {
- compatible = "qcom,sa8775p-qmp-gen4x4-pcie-phy";
- reg = <0x0 0x1c14000 0x0 0x4000>;
-
- clocks = <&gcc GCC_PCIE_1_PHY_AUX_CLK>,
- <&gcc GCC_PCIE_1_CFG_AHB_CLK>,
- <&gcc GCC_PCIE_CLKREF_EN>,
- <&gcc GCC_PCIE_1_PHY_RCHNG_CLK>,
- <&gcc GCC_PCIE_1_PIPE_CLK>,
- <&gcc GCC_PCIE_1_PIPEDIV2_CLK>;
- clock-names = "aux",
- "cfg_ahb",
- "ref",
- "rchng",
- "pipe",
- "pipediv2";
-
- assigned-clocks = <&gcc GCC_PCIE_1_PHY_RCHNG_CLK>;
- assigned-clock-rates = <100000000>;
-
- resets = <&gcc GCC_PCIE_1_PHY_BCR>;
- reset-names = "phy";
-
- #clock-cells = <0>;
- clock-output-names = "pcie_1_pipe_clk";
-
- #phy-cells = <0>;
-
- status = "disabled";
- };
};
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0699/1518] arm64: dts: qcom: lemans: Fix the PCIe iommu-map entries
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (697 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0698/1518] arm64: dts: qcom: lemans: Move PCIe devices into soc node Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0700/1518] arm64: dts: qcom: qcs6490-rb3gen2: " Greg Kroah-Hartman
` (299 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Manivannan Sadhasivam, Konrad Dybcio,
Dmitry Baryshkov, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
[ Upstream commit 19b4c47fc9733a953e9586bc0906a3be378b4cd5 ]
The IOMMU provider pcie_smmu uses '#iommu-cells = <2>', but the PCIe
iommu-map entries specify only one cell for the SID, omitting the SID
mask. This went unnoticed until the OF core started warning with commit
ccb2fd725d41 ("of: Respect #{iommu,msi}-cells in maps"):
iommu-map has 1-cell entries targeting 2-cell #iommu-cells, treating as 1-cell output
So fix the entries to match the provider's '#iommu-cells' property.
Fixes: 489f14be0e0a ("arm64: dts: qcom: sa8775p: Add pcie0 and pcie1 nodes")
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260730-iommu-map-fix-v1-14-83405d37ba41@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/lemans.dtsi | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/lemans.dtsi b/arch/arm64/boot/dts/qcom/lemans.dtsi
index 0861e4ead93eb..806b6b5d4b205 100644
--- a/arch/arm64/boot/dts/qcom/lemans.dtsi
+++ b/arch/arm64/boot/dts/qcom/lemans.dtsi
@@ -2739,8 +2739,8 @@ pcie0: pcie@1c00000 {
<&gem_noc MASTER_APPSS_PROC 0 &config_noc SLAVE_PCIE_0 0>;
interconnect-names = "pcie-mem", "cpu-pcie";
- iommu-map = <0x0 &pcie_smmu 0x0000 0x1>,
- <0x100 &pcie_smmu 0x0001 0x1>;
+ iommu-map = <0x0 &pcie_smmu 0x0000 0x0 0x1>,
+ <0x100 &pcie_smmu 0x0001 0x0 0x1>;
resets = <&gcc GCC_PCIE_0_BCR>,
<&gcc GCC_PCIE_0_LINK_DOWN_BCR>;
@@ -2912,8 +2912,8 @@ pcie1: pcie@1c10000 {
<&gem_noc MASTER_APPSS_PROC 0 &config_noc SLAVE_PCIE_1 0>;
interconnect-names = "pcie-mem", "cpu-pcie";
- iommu-map = <0x0 &pcie_smmu 0x0080 0x1>,
- <0x100 &pcie_smmu 0x0081 0x1>;
+ iommu-map = <0x0 &pcie_smmu 0x0080 0x0 0x1>,
+ <0x100 &pcie_smmu 0x0081 0x0 0x1>;
resets = <&gcc GCC_PCIE_1_BCR>,
<&gcc GCC_PCIE_1_LINK_DOWN_BCR>;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0700/1518] arm64: dts: qcom: qcs6490-rb3gen2: Fix the PCIe iommu-map entries
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (698 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0699/1518] arm64: dts: qcom: lemans: Fix the PCIe iommu-map entries Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0701/1518] power: supply: isp1704_charger: cancel work on remove Greg Kroah-Hartman
` (298 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Manivannan Sadhasivam, Konrad Dybcio,
Dmitry Baryshkov, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
[ Upstream commit 485dc5e557a8fef1374669f4ebe027c947187325 ]
The IOMMU provider apps_smmu uses '#iommu-cells = <2>', but the PCIe
iommu-map entries specify only one cell for the SID, omitting the SID
mask. This went unnoticed until the OF core started warning with commit
ccb2fd725d41 ("of: Respect #{iommu,msi}-cells in maps"):
iommu-map has 1-cell entries targeting 2-cell #iommu-cells, treating as 1-cell output
So fix the entries to match the provider's '#iommu-cells' property.
Fixes: 267643b3e3a4 ("arm64: dts: qcom: qcs6490-rb3gen2: Add PCIe nodes")
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260730-iommu-map-fix-v1-21-83405d37ba41@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/qcs6490-rb3gen2.dts | 18 +++++++++---------
1 file changed, 9 insertions(+), 9 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/qcs6490-rb3gen2.dts b/arch/arm64/boot/dts/qcom/qcs6490-rb3gen2.dts
index 18cea88120014..6be927c18482f 100644
--- a/arch/arm64/boot/dts/qcom/qcs6490-rb3gen2.dts
+++ b/arch/arm64/boot/dts/qcom/qcs6490-rb3gen2.dts
@@ -823,15 +823,15 @@ &pcie1 {
pinctrl-0 = <&pcie1_reset_n>, <&pcie1_wake_n>, <&pcie1_clkreq_n>;
pinctrl-names = "default";
- iommu-map = <0x0 &apps_smmu 0x1c80 0x1>,
- <0x100 &apps_smmu 0x1c81 0x1>,
- <0x208 &apps_smmu 0x1c84 0x1>,
- <0x210 &apps_smmu 0x1c85 0x1>,
- <0x218 &apps_smmu 0x1c86 0x1>,
- <0x300 &apps_smmu 0x1c87 0x1>,
- <0x400 &apps_smmu 0x1c88 0x1>,
- <0x500 &apps_smmu 0x1c89 0x1>,
- <0x501 &apps_smmu 0x1c90 0x1>;
+ iommu-map = <0x0 &apps_smmu 0x1c80 0x0 0x1>,
+ <0x100 &apps_smmu 0x1c81 0x0 0x1>,
+ <0x208 &apps_smmu 0x1c84 0x0 0x1>,
+ <0x210 &apps_smmu 0x1c85 0x0 0x1>,
+ <0x218 &apps_smmu 0x1c86 0x0 0x1>,
+ <0x300 &apps_smmu 0x1c87 0x0 0x1>,
+ <0x400 &apps_smmu 0x1c88 0x0 0x1>,
+ <0x500 &apps_smmu 0x1c89 0x0 0x1>,
+ <0x501 &apps_smmu 0x1c90 0x0 0x1>;
status = "okay";
};
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0701/1518] power: supply: isp1704_charger: cancel work on remove
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (699 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0700/1518] arm64: dts: qcom: qcs6490-rb3gen2: " Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0702/1518] power: supply: sc2731_charger: " Greg Kroah-Hartman
` (297 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hongyan Xu, Sebastian Reichel,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hongyan Xu <getshell@seu.edu.cn>
[ Upstream commit 60c5b8a9ef4dbc5d69bbc1a960fe55826cb3b643 ]
The USB notifier and initial VBUS detection can schedule isp->work. The
remove path unregisters the notifier and power supply, but does not wait
for queued or running work before tearing down the power supply state.
Cancel the work after unregistering the notifier. Do this before
unregistering the power supply.
This issue was found by a static analysis tool.
Signed-off-by: Hongyan Xu <getshell@seu.edu.cn>
Link: https://patch.msgid.link/20260728123423.781-5-getshell@seu.edu.cn
Fixes: ec46475f3e31 ("power_supply: Add isp1704 charger detection driver")
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/power/supply/isp1704_charger.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/power/supply/isp1704_charger.c b/drivers/power/supply/isp1704_charger.c
index 237912a922724..e329321d06dbd 100644
--- a/drivers/power/supply/isp1704_charger.c
+++ b/drivers/power/supply/isp1704_charger.c
@@ -482,6 +482,7 @@ static void isp1704_charger_remove(struct platform_device *pdev)
struct isp1704_charger *isp = platform_get_drvdata(pdev);
usb_unregister_notifier(isp->phy, &isp->nb);
+ cancel_work_sync(&isp->work);
power_supply_unregister(isp->psy);
isp1704_charger_set_power(isp, 0);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0702/1518] power: supply: sc2731_charger: cancel work on remove
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (700 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0701/1518] power: supply: isp1704_charger: cancel work on remove Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0703/1518] bpf: Fix potential UAF in bpf_netns_link_update_prog Greg Kroah-Hartman
` (296 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Baolin Wang, Hongyan Xu,
Sebastian Reichel, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hongyan Xu <getshell@seu.edu.cn>
[ Upstream commit dfc859bb8d332c525872f1a44028137724fa1998 ]
The USB notifier and initial charger detection can schedule info->work.
The remove path unregisters the notifier, but does not cancel queued or
running work before the devm-allocated driver data is released.
Set the platform drvdata used by remove, then cancel the work after
unregistering the notifier.
This issue was found by a static analysis tool.
Fixes: 8ac1091ed18b ("power: supply: sc2731_charger: Add one work to charge/discharge")
Reviewed-by: Baolin Wang <baolin.wang@linux.alibaba.com>
Signed-off-by: Hongyan Xu <getshell@seu.edu.cn>
Link: https://patch.msgid.link/5d48b827687168cb1b1bfe85f17945566b42829d.1785321763.git.getshell@seu.edu.cn
Signed-off-by: Sebastian Reichel <sebastian.reichel@collabora.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/power/supply/sc2731_charger.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/power/supply/sc2731_charger.c b/drivers/power/supply/sc2731_charger.c
index 58b86fd787713..2b25e44da7978 100644
--- a/drivers/power/supply/sc2731_charger.c
+++ b/drivers/power/supply/sc2731_charger.c
@@ -466,6 +466,7 @@ static int sc2731_charger_probe(struct platform_device *pdev)
mutex_init(&info->lock);
info->dev = &pdev->dev;
INIT_WORK(&info->work, sc2731_charger_work);
+ platform_set_drvdata(pdev, info);
info->regmap = dev_get_regmap(pdev->dev.parent, NULL);
if (!info->regmap) {
@@ -516,6 +517,7 @@ static void sc2731_charger_remove(struct platform_device *pdev)
struct sc2731_charger_info *info = platform_get_drvdata(pdev);
usb_unregister_notifier(info->usb_phy, &info->usb_notify);
+ cancel_work_sync(&info->work);
}
static const struct of_device_id sc2731_charger_of_match[] = {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0703/1518] bpf: Fix potential UAF in bpf_netns_link_update_prog
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (701 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0702/1518] power: supply: sc2731_charger: " Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0704/1518] bpf: Fix potential UAF when reading bpf link info Greg Kroah-Hartman
` (295 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Pu Lehui, Andrii Nakryiko,
Amery Hung, Emil Tsalapatis, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pu Lehui <pulehui@huawei.com>
[ Upstream commit 5c5997836381010fc5907b36bc17d3b19407e933 ]
In bpf_netns_link_update_prog, the checks for old_prog and prog type
are currently performed locklessly before acquiring netns_bpf_mutex.
This creates a race condition that can lead to a UAF issue.
If two threads concurrently execute BPF_LINK_UPDATE on the same netns
link, the following execution path can trigger a UAF:
CPU0 CPU1
bpf_netns_link_update_prog
if (old_prog && old_prog != link->prog)
return -EPERM;
bpf_netns_link_update_prog
if (old_prog && old_prog != link->prog)
...
old_prog = xchg(&link->prog, new_prog);
bpf_prog_put(old_prog);
if (new_prog->type != link->prog->type) <-- trigger UAF
Fix this by moving the old_prog and prog->type checks inside the
netns_bpf_mutex critical section. Meanwhile, use guard() to simplify
lock management and avoid all the goto jumping.
Fixes: 7f045a49fee0 ("bpf: Add link-based BPF program attachment to network namespace")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Pu Lehui <pulehui@huawei.com>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Reviewed-by: Amery Hung <ameryhung@gmail.com>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Link: https://lore.kernel.org/bpf/f87b53c0-8f00-45a6-82db-8242fa9b143f@huaweicloud.com [0]
Link: https://lore.kernel.org/bpf/20260728023259.2813482-1-pulehui@huaweicloud.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/net_namespace.c | 17 ++++++-----------
1 file changed, 6 insertions(+), 11 deletions(-)
diff --git a/kernel/bpf/net_namespace.c b/kernel/bpf/net_namespace.c
index 8e88201c98bfe..6599d771e4812 100644
--- a/kernel/bpf/net_namespace.c
+++ b/kernel/bpf/net_namespace.c
@@ -171,33 +171,28 @@ static int bpf_netns_link_update_prog(struct bpf_link *link,
struct net *net;
int idx, ret;
+ guard(mutex)(&netns_bpf_mutex);
+
if (old_prog && old_prog != link->prog)
return -EPERM;
if (new_prog->type != link->prog->type)
return -EINVAL;
- mutex_lock(&netns_bpf_mutex);
-
net = net_link->net;
- if (!net || !check_net(net)) {
+ if (!net || !check_net(net))
/* Link auto-detached or netns dying */
- ret = -ENOLINK;
- goto out_unlock;
- }
+ return -ENOLINK;
run_array = rcu_dereference_protected(net->bpf.run_array[type],
lockdep_is_held(&netns_bpf_mutex));
idx = link_index(net, type, net_link);
ret = bpf_prog_array_update_at(run_array, idx, new_prog);
if (ret)
- goto out_unlock;
+ return ret;
old_prog = xchg(&link->prog, new_prog);
bpf_prog_put(old_prog);
-
-out_unlock:
- mutex_unlock(&netns_bpf_mutex);
- return ret;
+ return 0;
}
static int bpf_netns_link_fill_info(const struct bpf_link *link,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0704/1518] bpf: Fix potential UAF when reading bpf link info
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (702 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0703/1518] bpf: Fix potential UAF in bpf_netns_link_update_prog Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0705/1518] lib/test_hmm: fail dmirror_fault() when the mirrored mm is gone Greg Kroah-Hartman
` (294 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Pu Lehui, Andrii Nakryiko,
Emil Tsalapatis, Amery Hung, Leon Hwang, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pu Lehui <pulehui@huawei.com>
[ Upstream commit 863f3ddd0b8ac65abfb50d3be0869268ac0e277b ]
In bpf_link_show_fdinfo and bpf_link_get_info_by_fd, link->prog is
accessed without holding any locks. If the prog is concurrently replaced
via bpf_link_update, the old prog can be freed, leading to a potential
UAF issue.
Fix this by accessing link->prog under RCU protection to safely fetch
the pointer and guarantee its lifetime while reading its fields.
Fixes: 0c991ebc8c69 ("bpf: Implement bpf_prog replacement for an active bpf_cgroup_link")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Pu Lehui <pulehui@huawei.com>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Reviewed-by: Amery Hung <ameryhung@gmail.com>
Acked-by: Leon Hwang <leon.hwang@linux.dev>
Link: https://lore.kernel.org/bpf/f87b53c0-8f00-45a6-82db-8242fa9b143f@huaweicloud.com [0]
Link: https://lore.kernel.org/bpf/20260728025457.2814876-1-pulehui@huaweicloud.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/syscall.c | 21 +++++++++++++++++----
1 file changed, 17 insertions(+), 4 deletions(-)
diff --git a/kernel/bpf/syscall.c b/kernel/bpf/syscall.c
index b8937bebf5b81..bab472152d64d 100644
--- a/kernel/bpf/syscall.c
+++ b/kernel/bpf/syscall.c
@@ -3343,9 +3343,10 @@ static const char *bpf_link_type_strs[] = {
static void bpf_link_show_fdinfo(struct seq_file *m, struct file *filp)
{
const struct bpf_link *link = filp->private_data;
- const struct bpf_prog *prog = link->prog;
+ const struct bpf_prog *prog;
enum bpf_link_type type = link->type;
char prog_tag[sizeof(prog->tag) * 2 + 1] = { };
+ u32 prog_id = 0;
if (type < ARRAY_SIZE(bpf_link_type_strs) && bpf_link_type_strs[type]) {
if (link->type == BPF_LINK_TYPE_KPROBE_MULTI)
@@ -3362,13 +3363,20 @@ static void bpf_link_show_fdinfo(struct seq_file *m, struct file *filp)
}
seq_printf(m, "link_id:\t%u\n", link->id);
+ rcu_read_lock();
+ prog = READ_ONCE(link->prog);
if (prog) {
bin2hex(prog_tag, prog->tag, sizeof(prog->tag));
+ prog_id = prog->aux->id;
+ }
+ rcu_read_unlock();
+
+ if (prog) {
seq_printf(m,
"prog_tag:\t%s\n"
"prog_id:\t%u\n",
prog_tag,
- prog->aux->id);
+ prog_id);
}
if (link->ops->show_fdinfo)
link->ops->show_fdinfo(link, m);
@@ -5372,6 +5380,7 @@ static int bpf_link_get_info_by_fd(struct file *file,
{
struct bpf_link_info __user *uinfo = u64_to_user_ptr(attr->info.info);
struct bpf_link_info info;
+ const struct bpf_prog *prog;
u32 info_len = attr->info.info_len;
int err;
@@ -5386,8 +5395,12 @@ static int bpf_link_get_info_by_fd(struct file *file,
info.type = link->type;
info.id = link->id;
- if (link->prog)
- info.prog_id = link->prog->aux->id;
+
+ rcu_read_lock();
+ prog = READ_ONCE(link->prog);
+ if (prog)
+ info.prog_id = prog->aux->id;
+ rcu_read_unlock();
if (link->ops->fill_link_info) {
err = link->ops->fill_link_info(link, &info);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0705/1518] lib/test_hmm: fail dmirror_fault() when the mirrored mm is gone
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (703 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0704/1518] bpf: Fix potential UAF when reading bpf link info Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0706/1518] clk: qcom: gpucc-qcm2290: Park RCGs clk source at XO during disable Greg Kroah-Hartman
` (293 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Stanislav Kinsburskii,
Jason Gunthorpe, Leon Romanovsky, Ralph Campbell, Andrew Morton,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Stanislav Kinsburskii <skinsburskii@linux.microsoft.com>
[ Upstream commit 6a8024511ddf4877435c34fb3d6028aa8e590649 ]
dmirror_fault() is called from the dmirror_read() and dmirror_write()
retry loops after dmirror_do_read() or dmirror_do_write() finds a missing
device page table entry.
If the mirrored mm has already exited, mmget_not_zero() fails. The
current code returns 0 in that case, which tells the caller that faulting
succeeded even though no page was faulted and no device page table entry
was installed. The caller then retries the same address, hits -ENOENT
again, and can loop forever without making progress.
Return -EFAULT instead, so the ioctl fails when the mirrored mm is no
longer faultable.
Link: https://lore.kernel.org/178294308408.327222.3319445682023999403.stgit@skinsburskii
Fixes: b2ef9f5a5cb37 ("mm/hmm/test: add selftest driver for HMM")
Signed-off-by: Stanislav Kinsburskii <skinsburskii@linux.microsoft.com>
Cc: Jason Gunthorpe <jgg@ziepe.ca>
Cc: Leon Romanovsky <leon@kernel.org>
Cc: Ralph Campbell <rcampbell@nvidia.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
lib/test_hmm.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/lib/test_hmm.c b/lib/test_hmm.c
index 00d34a6c6276b..ec1df4cd84807 100644
--- a/lib/test_hmm.c
+++ b/lib/test_hmm.c
@@ -392,7 +392,7 @@ static int dmirror_fault(struct dmirror *dmirror, unsigned long start,
/* Since the mm is for the mirrored process, get a reference first. */
if (!mmget_not_zero(mm))
- return 0;
+ return -EFAULT;
for (addr = start; addr < end; addr = range.end) {
range.start = addr;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0706/1518] clk: qcom: gpucc-qcm2290: Park RCGs clk source at XO during disable
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (704 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0705/1518] lib/test_hmm: fail dmirror_fault() when the mirrored mm is gone Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0707/1518] clk: qcom: Return expected ENOMEM error on dynamic allocation failure Greg Kroah-Hartman
` (292 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dmitry Baryshkov, Konrad Dybcio,
Imran Shaik, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Imran Shaik <imran.shaik@oss.qualcomm.com>
[ Upstream commit ab46b5fb668b8b9b848a8f036fc4c06ce86b7e3b ]
The RCG's clk src has to be parked at XO while disabling as per hardware
team's recommendation, hence use clk_rcg2_shared_ops to achieve the same.
Fixes: 8cab033628b1 ("clk: qcom: Add QCM2290 GPU clock controller driver")
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Imran Shaik <imran.shaik@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260718-shikra-dispcc-gpucc-v6-11-62703e05ef0f@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/qcom/gpucc-qcm2290.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/clk/qcom/gpucc-qcm2290.c b/drivers/clk/qcom/gpucc-qcm2290.c
index dc369dff882e6..3ccab8f3b4e0f 100644
--- a/drivers/clk/qcom/gpucc-qcm2290.c
+++ b/drivers/clk/qcom/gpucc-qcm2290.c
@@ -144,7 +144,7 @@ static struct clk_rcg2 gpu_cc_gx_gfx3d_clk_src = {
.parent_data = gpu_cc_parent_data_1,
.num_parents = ARRAY_SIZE(gpu_cc_parent_data_1),
.flags = CLK_SET_RATE_PARENT,
- .ops = &clk_rcg2_ops,
+ .ops = &clk_rcg2_shared_ops,
},
};
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0707/1518] clk: qcom: Return expected ENOMEM error on dynamic allocation failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (705 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0706/1518] clk: qcom: gpucc-qcm2290: Park RCGs clk source at XO during disable Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0708/1518] md/bitmap: resume array on backlog_store() error path Greg Kroah-Hartman
` (291 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vladimir Zapolskiy, Konrad Dybcio,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vladimir Zapolskiy <vz@kernel.org>
[ Upstream commit 22d9257f08913b6eec3e8ece4d13d9c41f14428b ]
If a dynamic memory allocation fails, the returned error code in clock
controller driver probe functions on a few legacy platforms should be
set to -ENOMEM instead of -EINVAL.
Fixes: ee15faffef11 ("clk: qcom: common: Add API to register board clocks backwards compatibly")
Signed-off-by: Vladimir Zapolskiy <vz@kernel.org>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260629162127.3910603-1-vz@kernel.org
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/qcom/common.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/clk/qcom/common.c b/drivers/clk/qcom/common.c
index eec369d2173b5..0e8f380873af0 100644
--- a/drivers/clk/qcom/common.c
+++ b/drivers/clk/qcom/common.c
@@ -169,7 +169,7 @@ static int _qcom_cc_register_board_clk(struct device *dev, const char *path,
if (!node) {
fixed = devm_kzalloc(dev, sizeof(*fixed), GFP_KERNEL);
if (!fixed)
- return -EINVAL;
+ return -ENOMEM;
fixed->fixed_rate = rate;
fixed->hw.init = &init_data;
@@ -186,7 +186,7 @@ static int _qcom_cc_register_board_clk(struct device *dev, const char *path,
if (add_factor) {
factor = devm_kzalloc(dev, sizeof(*factor), GFP_KERNEL);
if (!factor)
- return -EINVAL;
+ return -ENOMEM;
factor->mult = factor->div = 1;
factor->hw.init = &init_data;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0708/1518] md/bitmap: resume array on backlog_store() error path
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (706 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0707/1518] clk: qcom: Return expected ENOMEM error on dynamic allocation failure Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0709/1518] md: remove unused mddev argument from export_rdev Greg Kroah-Hartman
` (290 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Chen Cheng, Yu Kuai, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chen Cheng <chencheng@fnnas.com>
[ Upstream commit 2911cd0a0f4366a7e06832bc5f0a7fdcc138e4dc ]
backlog_store() suspends the array before checking whether a write-mostly
device exists. If no such device exists, the error path only unlocks
reconfig_mutex and leaves the array suspended, blocking subsequent I/O.
Use mddev_unlock_and_resume() to release both states.
Fixes: 58226942ad3d ("md: use new apis to suspend array before mddev_create/destroy_serial_pool")
Signed-off-by: Chen Cheng <chencheng@fnnas.com>
Reviewed-by: Yu Kuai <yukuai@fygo.io>
Link: https://patch.msgid.link/20260718034236.4119093-1-chencheng@fnnas.com
Signed-off-by: Yu Kuai <yukuai@fygo.io>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/md/md-bitmap.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/md/md-bitmap.c b/drivers/md/md-bitmap.c
index 2a95840782927..110c236045dcc 100644
--- a/drivers/md/md-bitmap.c
+++ b/drivers/md/md-bitmap.c
@@ -2862,7 +2862,7 @@ backlog_store(struct mddev *mddev, const char *buf, size_t len)
if (!has_write_mostly) {
pr_warn_ratelimited("%s: can't set backlog, no write mostly device available\n",
mdname(mddev));
- mddev_unlock(mddev);
+ mddev_unlock_and_resume(mddev);
return -EINVAL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0709/1518] md: remove unused mddev argument from export_rdev
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (707 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0708/1518] md/bitmap: resume array on backlog_store() error path Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0710/1518] md: skip redundant raid_disks update when value is unchanged Greg Kroah-Hartman
` (289 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chen Cheng, Paul Menzel, Yu Kuai,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chen Cheng <chencheng@fnnas.com>
[ Upstream commit 6f507eb2bb5491327fe634dc23558d4ca5d710b8 ]
The mddev argument in export_rdev() is never used. Remove it to
simplify callers.
Signed-off-by: Chen Cheng <chencheng@fnnas.com>
Reviewed-by: Paul Menzel <pmenzel@molgen.mpg.de>
Link: https://lore.kernel.org/linux-raid/20260304111417.20777-1-chencheng@fnnas.com/
Signed-off-by: Yu Kuai <yukuai3@huawei.com>
Stable-dep-of: bace2010dd7a ("md: scope memalloc_noio to allocation critical sections")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/md/md.c | 28 ++++++++++++++--------------
1 file changed, 14 insertions(+), 14 deletions(-)
diff --git a/drivers/md/md.c b/drivers/md/md.c
index 36862dbaf253f..93e5774618126 100644
--- a/drivers/md/md.c
+++ b/drivers/md/md.c
@@ -97,7 +97,7 @@ static struct workqueue_struct *md_misc_wq;
static int remove_and_add_spares(struct mddev *mddev,
struct md_rdev *this);
static void mddev_detach(struct mddev *mddev);
-static void export_rdev(struct md_rdev *rdev, struct mddev *mddev);
+static void export_rdev(struct md_rdev *rdev);
static void md_wakeup_thread_directly(struct md_thread __rcu **thread);
/*
@@ -972,7 +972,7 @@ void mddev_unlock(struct mddev *mddev)
list_for_each_entry_safe(rdev, tmp, &delete, same_set) {
list_del_init(&rdev->same_set);
kobject_del(&rdev->kobj);
- export_rdev(rdev, mddev);
+ export_rdev(rdev);
}
if (!legacy_async_del_gendisk) {
@@ -2647,7 +2647,7 @@ void md_autodetect_dev(dev_t dev);
/* just for claiming the bdev */
static struct md_rdev claim_rdev;
-static void export_rdev(struct md_rdev *rdev, struct mddev *mddev)
+static void export_rdev(struct md_rdev *rdev)
{
pr_debug("md: export_rdev(%pg)\n", rdev->bdev);
md_rdev_clear(rdev);
@@ -4862,7 +4862,7 @@ new_dev_store(struct mddev *mddev, const char *buf, size_t len)
err = bind_rdev_to_array(rdev, mddev);
out:
if (err)
- export_rdev(rdev, mddev);
+ export_rdev(rdev);
mddev_unlock_and_resume(mddev);
if (!err)
md_new_event();
@@ -7188,7 +7188,7 @@ static void autorun_devices(int part)
rdev_for_each_list(rdev, tmp, &candidates) {
list_del_init(&rdev->same_set);
if (bind_rdev_to_array(rdev, mddev))
- export_rdev(rdev, mddev);
+ export_rdev(rdev);
}
autorun_array(mddev);
mddev_unlock_and_resume(mddev);
@@ -7198,7 +7198,7 @@ static void autorun_devices(int part)
*/
rdev_for_each_list(rdev, tmp, &candidates) {
list_del_init(&rdev->same_set);
- export_rdev(rdev, mddev);
+ export_rdev(rdev);
}
mddev_put(mddev);
}
@@ -7386,13 +7386,13 @@ int md_add_new_disk(struct mddev *mddev, struct mdu_disk_info_s *info)
pr_warn("md: %pg has different UUID to %pg\n",
rdev->bdev,
rdev0->bdev);
- export_rdev(rdev, mddev);
+ export_rdev(rdev);
return -EINVAL;
}
}
err = bind_rdev_to_array(rdev, mddev);
if (err)
- export_rdev(rdev, mddev);
+ export_rdev(rdev);
return err;
}
@@ -7435,7 +7435,7 @@ int md_add_new_disk(struct mddev *mddev, struct mdu_disk_info_s *info)
/* This was a hot-add request, but events doesn't
* match, so reject it.
*/
- export_rdev(rdev, mddev);
+ export_rdev(rdev);
return -EINVAL;
}
@@ -7461,7 +7461,7 @@ int md_add_new_disk(struct mddev *mddev, struct mdu_disk_info_s *info)
}
}
if (has_journal || mddev->bitmap) {
- export_rdev(rdev, mddev);
+ export_rdev(rdev);
return -EBUSY;
}
set_bit(Journal, &rdev->flags);
@@ -7476,7 +7476,7 @@ int md_add_new_disk(struct mddev *mddev, struct mdu_disk_info_s *info)
/* --add initiated by this node */
err = mddev->cluster_ops->add_new_disk(mddev, rdev);
if (err) {
- export_rdev(rdev, mddev);
+ export_rdev(rdev);
return err;
}
}
@@ -7486,7 +7486,7 @@ int md_add_new_disk(struct mddev *mddev, struct mdu_disk_info_s *info)
err = bind_rdev_to_array(rdev, mddev);
if (err)
- export_rdev(rdev, mddev);
+ export_rdev(rdev);
if (mddev_is_clustered(mddev)) {
if (info->state & (1 << MD_DISK_CANDIDATE)) {
@@ -7549,7 +7549,7 @@ int md_add_new_disk(struct mddev *mddev, struct mdu_disk_info_s *info)
err = bind_rdev_to_array(rdev, mddev);
if (err) {
- export_rdev(rdev, mddev);
+ export_rdev(rdev);
return err;
}
}
@@ -7661,7 +7661,7 @@ static int hot_add_disk(struct mddev *mddev, dev_t dev)
return 0;
abort_export:
- export_rdev(rdev, mddev);
+ export_rdev(rdev);
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0710/1518] md: skip redundant raid_disks update when value is unchanged
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (708 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0709/1518] md: remove unused mddev argument from export_rdev Greg Kroah-Hartman
@ 2026-09-12 6:47 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0711/1518] md: scope memalloc_noio to allocation critical sections Greg Kroah-Hartman
` (288 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:47 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Abd-Alrhman Masalkhi, Yu Kuai,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com>
[ Upstream commit abaf4783822851678632e5cea98aa5aead99852f ]
Calling update_raid_disks() with the same value as the current one
can trigger unnecessary work. For example, RAID1 will reallocate
resources such as the mempool for r1bio.
Signed-off-by: Abd-Alrhman Masalkhi <abd.masalkhi@gmail.com>
Link: https://patch.msgid.link/20260428130524.448063-1-abd.masalkhi@gmail.com
Signed-off-by: Yu Kuai <yukuai@fygo.io>
Stable-dep-of: bace2010dd7a ("md: scope memalloc_noio to allocation critical sections")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/md/md.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/drivers/md/md.c b/drivers/md/md.c
index 93e5774618126..debe07631d6ba 100644
--- a/drivers/md/md.c
+++ b/drivers/md/md.c
@@ -4421,9 +4421,10 @@ raid_disks_store(struct mddev *mddev, const char *buf, size_t len)
err = mddev_suspend_and_lock(mddev);
if (err)
return err;
- if (mddev->pers)
- err = update_raid_disks(mddev, n);
- else if (mddev->reshape_position != MaxSector) {
+ if (mddev->pers) {
+ if (n != mddev->raid_disks)
+ err = update_raid_disks(mddev, n);
+ } else if (mddev->reshape_position != MaxSector) {
struct md_rdev *rdev;
int olddisks = mddev->raid_disks - mddev->delta_disks;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0711/1518] md: scope memalloc_noio to allocation critical sections
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (709 preceding siblings ...)
2026-09-12 6:47 ` [PATCH 6.18 0710/1518] md: skip redundant raid_disks update when value is unchanged Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0712/1518] iommu/dma: Check atomic pool allocation result directly Greg Kroah-Hartman
` (287 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Chen Cheng, Yu Kuai, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chen Cheng <chencheng@fnnas.com>
[ Upstream commit bace2010dd7ac07bc980575afb135c406730a7fe ]
Storing a memalloc_noio_save() token in mddev->noio_flags lets one task
save the token and another task restore it. With concurrent suspend sysfs
writes, task A can enter PF_MEMALLOC_NOIO, return to userspace still in
that scope, and later task B can restore A's saved token.
Avoid tying the token lifetime to mddev. Keep mddev_suspend() and
mddev_resume() only responsible for array suspension, and enter
PF_MEMALLOC_NOIO only in the MD paths that allocate memory after the array
has been suspended. Restore the token before resuming the array.
A reproducer repeatedly writes suspend_lo and suspend_hi from concurrent
workers and checks each worker's /proc/self/stat flags before and after the
sysfs write.
Link: https://github.com/chencheng-fnnas/reproducer/blob/main/repro-md-noio-token-leak.sh
Fixes: 78f57ef9d50a ("md: use memalloc scope APIs in mddev_suspend()/mddev_resume()")
Signed-off-by: Chen Cheng <chencheng@fnnas.com>
Reviewed-by: Yu Kuai <yukuai@fygo.io>
Link: https://patch.msgid.link/20260718084218.417895-1-chencheng@fnnas.com
Signed-off-by: Yu Kuai <yukuai@fygo.io>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/md/md-bitmap.c | 3 +++
drivers/md/md.c | 53 ++++++++++++++++++++++++++++--------------
drivers/md/md.h | 1 -
drivers/md/raid5.c | 14 +++++++----
4 files changed, 48 insertions(+), 23 deletions(-)
diff --git a/drivers/md/md-bitmap.c b/drivers/md/md-bitmap.c
index 110c236045dcc..781cbfb2d3481 100644
--- a/drivers/md/md-bitmap.c
+++ b/drivers/md/md-bitmap.c
@@ -2629,10 +2629,12 @@ static ssize_t
location_store(struct mddev *mddev, const char *buf, size_t len)
{
int rv;
+ unsigned int noio_flags;
rv = mddev_suspend_and_lock(mddev);
if (rv)
return rv;
+ noio_flags = memalloc_noio_save();
if (mddev->pers) {
if (mddev->recovery || mddev->sync_thread) {
@@ -2719,6 +2721,7 @@ location_store(struct mddev *mddev, const char *buf, size_t len)
}
rv = 0;
out:
+ memalloc_noio_restore(noio_flags);
mddev_unlock_and_resume(mddev);
if (rv)
return rv;
diff --git a/drivers/md/md.c b/drivers/md/md.c
index debe07631d6ba..89965f96f3bba 100644
--- a/drivers/md/md.c
+++ b/drivers/md/md.c
@@ -234,23 +234,21 @@ static int rdev_need_serial(struct md_rdev *rdev)
void mddev_create_serial_pool(struct mddev *mddev, struct md_rdev *rdev)
{
int ret = 0;
+ unsigned int noio_flags;
if (rdev && !rdev_need_serial(rdev) &&
!test_bit(CollisionCheck, &rdev->flags))
return;
+ noio_flags = memalloc_noio_save();
if (!rdev)
ret = rdevs_init_serial(mddev);
else
ret = rdev_init_serial(rdev);
if (ret)
- return;
+ goto out;
if (mddev->serial_info_pool == NULL) {
- /*
- * already in memalloc noio context by
- * mddev_suspend()
- */
mddev->serial_info_pool =
mempool_create_kmalloc_pool(NR_SERIAL_INFOS,
sizeof(struct serial_info));
@@ -259,6 +257,8 @@ void mddev_create_serial_pool(struct mddev *mddev, struct md_rdev *rdev)
pr_err("can't alloc memory pool for serialization\n");
}
}
+out:
+ memalloc_noio_restore(noio_flags);
}
/*
@@ -517,9 +517,6 @@ int mddev_suspend(struct mddev *mddev, bool interruptible)
*/
WRITE_ONCE(mddev->suspended, mddev->suspended + 1);
- /* restrict memory reclaim I/O during raid array is suspend */
- mddev->noio_flag = memalloc_noio_save();
-
mutex_unlock(&mddev->suspend_mutex);
return 0;
}
@@ -536,9 +533,6 @@ static void __mddev_resume(struct mddev *mddev, bool recovery_needed)
return;
}
- /* entred the memalloc scope from mddev_suspend() */
- memalloc_noio_restore(mddev->noio_flag);
-
percpu_ref_resurrect(&mddev->active_io);
wake_up(&mddev->sb_wait);
@@ -4047,6 +4041,7 @@ level_store(struct mddev *mddev, const char *buf, size_t len)
char clevel[16];
ssize_t rv;
size_t slen = len;
+ unsigned int noio_flags;
struct md_personality *pers, *oldpers;
long level;
void *priv, *oldpriv;
@@ -4058,6 +4053,7 @@ level_store(struct mddev *mddev, const char *buf, size_t len)
rv = mddev_suspend_and_lock(mddev);
if (rv)
return rv;
+ noio_flags = memalloc_noio_save();
if (mddev->pers == NULL) {
memcpy(mddev->clevel, buf, slen);
@@ -4233,6 +4229,7 @@ level_store(struct mddev *mddev, const char *buf, size_t len)
md_new_event();
rv = len;
out_unlock:
+ memalloc_noio_restore(noio_flags);
mddev_unlock_and_resume(mddev);
return rv;
}
@@ -4412,6 +4409,7 @@ static ssize_t
raid_disks_store(struct mddev *mddev, const char *buf, size_t len)
{
unsigned int n;
+ unsigned int noio_flags;
int err;
err = kstrtouint(buf, 10, &n);
@@ -4421,6 +4419,7 @@ raid_disks_store(struct mddev *mddev, const char *buf, size_t len)
err = mddev_suspend_and_lock(mddev);
if (err)
return err;
+ noio_flags = memalloc_noio_save();
if (mddev->pers) {
if (n != mddev->raid_disks)
err = update_raid_disks(mddev, n);
@@ -4444,6 +4443,7 @@ raid_disks_store(struct mddev *mddev, const char *buf, size_t len)
} else
mddev->raid_disks = n;
out_unlock:
+ memalloc_noio_restore(noio_flags);
mddev_unlock_and_resume(mddev);
return err ? err : len;
}
@@ -4824,6 +4824,7 @@ new_dev_store(struct mddev *mddev, const char *buf, size_t len)
int minor;
dev_t dev;
struct md_rdev *rdev;
+ unsigned int noio_flags;
int err;
if (!*buf || *e != ':' || !e[1] || e[1] == '\n')
@@ -4839,6 +4840,7 @@ new_dev_store(struct mddev *mddev, const char *buf, size_t len)
err = mddev_suspend_and_lock(mddev);
if (err)
return err;
+ noio_flags = memalloc_noio_save();
if (mddev->persistent) {
rdev = md_import_device(dev, mddev->major_version,
mddev->minor_version);
@@ -4857,6 +4859,7 @@ new_dev_store(struct mddev *mddev, const char *buf, size_t len)
rdev = md_import_device(dev, -1, -1);
if (IS_ERR(rdev)) {
+ memalloc_noio_restore(noio_flags);
mddev_unlock_and_resume(mddev);
return PTR_ERR(rdev);
}
@@ -4864,6 +4867,7 @@ new_dev_store(struct mddev *mddev, const char *buf, size_t len)
out:
if (err)
export_rdev(rdev);
+ memalloc_noio_restore(noio_flags);
mddev_unlock_and_resume(mddev);
if (!err)
md_new_event();
@@ -8210,8 +8214,10 @@ static int md_ioctl(struct block_device *bdev, blk_mode_t mode,
unsigned int cmd, unsigned long arg)
{
int err = 0;
+ unsigned int noio_flags = 0;
void __user *argp = (void __user *)arg;
struct mddev *mddev = NULL;
+ bool suspend;
err = md_ioctl_valid(cmd);
if (err)
@@ -8261,13 +8267,15 @@ static int md_ioctl(struct block_device *bdev, blk_mode_t mode,
if (!md_is_rdwr(mddev))
flush_work(&mddev->sync_work);
- err = md_ioctl_need_suspend(cmd) ? mddev_suspend_and_lock(mddev) :
- mddev_lock(mddev);
+ suspend = md_ioctl_need_suspend(cmd);
+ err = suspend ? mddev_suspend_and_lock(mddev) : mddev_lock(mddev);
if (err) {
pr_debug("md: ioctl lock interrupted, reason %d, cmd %d\n",
err, cmd);
goto out;
}
+ if (suspend)
+ noio_flags = memalloc_noio_save();
if (cmd == SET_ARRAY_INFO) {
err = __md_set_array_info(mddev, argp);
@@ -8392,8 +8400,12 @@ static int md_ioctl(struct block_device *bdev, blk_mode_t mode,
err != -EINVAL)
mddev->hold_active = 0;
- md_ioctl_need_suspend(cmd) ? mddev_unlock_and_resume(mddev) :
- mddev_unlock(mddev);
+ if (suspend) {
+ memalloc_noio_restore(noio_flags);
+ mddev_unlock_and_resume(mddev);
+ } else {
+ mddev_unlock(mddev);
+ }
out:
if (cmd == STOP_ARRAY_RO || (err && cmd == STOP_ARRAY))
@@ -10072,6 +10084,7 @@ static void md_start_sync(struct work_struct *ws)
struct mddev *mddev = container_of(ws, struct mddev, sync_work);
int spares = 0;
bool suspend = false;
+ unsigned int noio_flags = 0;
char *name;
/*
@@ -10082,6 +10095,7 @@ static void md_start_sync(struct work_struct *ws)
md_spares_need_change(mddev)) {
suspend = true;
mddev_suspend(mddev, false);
+ noio_flags = memalloc_noio_save();
}
mddev_lock_nointr(mddev);
@@ -10095,6 +10109,7 @@ static void md_start_sync(struct work_struct *ws)
mddev_unlock(mddev);
mddev_suspend_and_lock_nointr(mddev);
suspend = true;
+ noio_flags = memalloc_noio_save();
}
if (!md_is_rdwr(mddev)) {
@@ -10140,8 +10155,10 @@ static void md_start_sync(struct work_struct *ws)
* https://bugzilla.kernel.org/show_bug.cgi?id=218200
* Therefore, use __mddev_resume(mddev, false).
*/
- if (suspend)
+ if (suspend) {
+ memalloc_noio_restore(noio_flags);
__mddev_resume(mddev, false);
+ }
md_wakeup_thread(mddev->sync_thread);
sysfs_notify_dirent_safe(mddev->sysfs_action);
md_new_event();
@@ -10160,8 +10177,10 @@ static void md_start_sync(struct work_struct *ws)
* https://bugzilla.kernel.org/show_bug.cgi?id=218200
* Therefore, use __mddev_resume(mddev, false).
*/
- if (suspend)
+ if (suspend) {
+ memalloc_noio_restore(noio_flags);
__mddev_resume(mddev, false);
+ }
wake_up(&resync_wait);
if (test_and_clear_bit(MD_RECOVERY_RECOVER, &mddev->recovery) &&
diff --git a/drivers/md/md.h b/drivers/md/md.h
index 2960a98747607..7400f7739d2e6 100644
--- a/drivers/md/md.h
+++ b/drivers/md/md.h
@@ -617,7 +617,6 @@ struct mddev {
struct md_cluster_info *cluster_info;
struct md_cluster_operations *cluster_ops;
unsigned int good_device_nr; /* good device num within cluster raid */
- unsigned int noio_flag; /* for memalloc scope API */
/*
* Temporarily store rdev that will be finally removed when
diff --git a/drivers/md/raid5.c b/drivers/md/raid5.c
index 3fbf66c9b45ed..0a0e241e3979b 100644
--- a/drivers/md/raid5.c
+++ b/drivers/md/raid5.c
@@ -2456,11 +2456,6 @@ static int scribble_alloc(struct raid5_percpu *percpu,
sizeof(unsigned int) * (num + 2);
void *scribble;
- /*
- * If here is in raid array suspend context, it is in memalloc noio
- * context as well, there is no potential recursive memory reclaim
- * I/Os with the GFP_KERNEL flag.
- */
scribble = kvmalloc_array(cnt, obj_size, GFP_KERNEL);
if (!scribble)
return -ENOMEM;
@@ -2475,6 +2470,7 @@ static int scribble_alloc(struct raid5_percpu *percpu,
static int resize_chunks(struct r5conf *conf, int new_disks, int new_sectors)
{
unsigned long cpu;
+ unsigned int noio_flags;
int err = 0;
/* Never shrink. */
@@ -2483,6 +2479,7 @@ static int resize_chunks(struct r5conf *conf, int new_disks, int new_sectors)
return 0;
raid5_quiesce(conf->mddev, true);
+ noio_flags = memalloc_noio_save();
cpus_read_lock();
for_each_present_cpu(cpu) {
@@ -2496,6 +2493,7 @@ static int resize_chunks(struct r5conf *conf, int new_disks, int new_sectors)
}
cpus_read_unlock();
+ memalloc_noio_restore(noio_flags);
raid5_quiesce(conf->mddev, false);
if (!err) {
@@ -6994,6 +6992,7 @@ raid5_store_stripe_size(struct mddev *mddev, const char *page, size_t len)
{
struct r5conf *conf;
unsigned long new;
+ unsigned int noio_flags = 0;
int err;
int size;
@@ -7034,6 +7033,7 @@ raid5_store_stripe_size(struct mddev *mddev, const char *page, size_t len)
goto out_unlock;
}
+ noio_flags = memalloc_noio_save();
mutex_lock(&conf->cache_size_mutex);
size = conf->max_nr_stripes;
@@ -7050,6 +7050,7 @@ raid5_store_stripe_size(struct mddev *mddev, const char *page, size_t len)
mutex_unlock(&conf->cache_size_mutex);
out_unlock:
+ memalloc_noio_restore(noio_flags);
mddev_unlock_and_resume(mddev);
return err ?: len;
}
@@ -8919,6 +8920,7 @@ static void *raid6_takeover(struct mddev *mddev)
static int raid5_change_consistency_policy(struct mddev *mddev, const char *buf)
{
struct r5conf *conf;
+ unsigned int noio_flags;
int err;
err = mddev_suspend_and_lock(mddev);
@@ -8930,6 +8932,7 @@ static int raid5_change_consistency_policy(struct mddev *mddev, const char *buf)
return -ENODEV;
}
+ noio_flags = memalloc_noio_save();
if (strncmp(buf, "ppl", 3) == 0) {
/* ppl only works with RAID 5 */
if (!raid5_has_ppl(conf) && conf->level == 5) {
@@ -8969,6 +8972,7 @@ static int raid5_change_consistency_policy(struct mddev *mddev, const char *buf)
if (!err)
md_update_sb(mddev, 1);
+ memalloc_noio_restore(noio_flags);
mddev_unlock_and_resume(mddev);
return err;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0712/1518] iommu/dma: Check atomic pool allocation result directly
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (710 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0711/1518] md: scope memalloc_noio to allocation critical sections Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0713/1518] swiotlb: Preserve allocation virtual address for dynamic pools Greg Kroah-Hartman
` (286 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jason Gunthorpe, Michael Kelley,
Mostafa Saleh, Petr Tesarik, Aneesh Kumar K.V (Arm),
Marek Szyprowski, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aneesh Kumar K.V (Arm) <aneesh.kumar@kernel.org>
[ Upstream commit af95a0ebc0a0db0762be75f51eadf770bad01aaa ]
The non-blocking, non-coherent allocation path uses dma_alloc_from_pool(),
which returns the allocated page and fills cpu_addr only on success.
Do not rely on cpu_addr to detect allocation failure in this path. Check
the returned page directly before using it for the IOMMU mapping.
Fixes: 9420139f516d ("dma-pool: fix coherent pool allocations for IOMMU mappings")
Reviewed-by: Jason Gunthorpe <jgg@nvidia.com>
Tested-by: Michael Kelley <mhklinux@outlook.com>
Tested-by: Mostafa Saleh <smostafa@google.com>
Reviewed-by: Petr Tesarik <ptesarik@suse.com>
Signed-off-by: Aneesh Kumar K.V (Arm) <aneesh.kumar@kernel.org>
Link: https://lore.kernel.org/r/20260717180442.110954-4-aneesh.kumar@kernel.org
Signed-off-by: Marek Szyprowski <m.szyprowski@samsung.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/iommu/dma-iommu.c | 13 ++++++++-----
1 file changed, 8 insertions(+), 5 deletions(-)
diff --git a/drivers/iommu/dma-iommu.c b/drivers/iommu/dma-iommu.c
index b0dca7e7429a6..3773984068684 100644
--- a/drivers/iommu/dma-iommu.c
+++ b/drivers/iommu/dma-iommu.c
@@ -1647,13 +1647,16 @@ void *iommu_dma_alloc(struct device *dev, size_t size, dma_addr_t *handle,
}
if (IS_ENABLED(CONFIG_DMA_DIRECT_REMAP) &&
- !gfpflags_allow_blocking(gfp) && !coherent)
+ !gfpflags_allow_blocking(gfp) && !coherent) {
page = dma_alloc_from_pool(dev, PAGE_ALIGN(size), &cpu_addr,
- gfp, NULL);
- else
+ gfp, NULL);
+ if (!page)
+ return NULL;
+ } else {
cpu_addr = iommu_dma_alloc_pages(dev, size, &page, gfp, attrs);
- if (!cpu_addr)
- return NULL;
+ if (!cpu_addr)
+ return NULL;
+ }
*handle = __iommu_dma_map(dev, page_to_phys(page), size, ioprot,
dev->coherent_dma_mask);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0713/1518] swiotlb: Preserve allocation virtual address for dynamic pools
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (711 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0712/1518] iommu/dma: Check atomic pool allocation result directly Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0714/1518] i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices Greg Kroah-Hartman
` (285 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jason Gunthorpe, Michael Kelley,
Mostafa Saleh, Petr Tesarik, Aneesh Kumar K.V (Arm),
Marek Szyprowski, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Aneesh Kumar K.V (Arm) <aneesh.kumar@kernel.org>
[ Upstream commit 57d29044d0f29a76c6ec0c112c8c7371d5608dc7 ]
swiotlb_alloc_tlb() can allocate from the DMA atomic pool when a decrypted
pool is needed from atomic context. With CONFIG_DMA_DIRECT_REMAP, the
atomic pool is backed by remapped virtual addresses, which are not the same
as the direct-map addresses returned by phys_to_virt().
swiotlb_init_io_tlb_pool() currently reconstructs the pool virtual address
from the physical start address. For atomic-pool backed allocations this
stores the wrong address in pool->vaddr. Later, swiotlb_free_tlb() passes
that address to dma_free_from_pool(), which will fail to recognize the
chunk
Pass the virtual address returned by the allocation path into
swiotlb_init_io_tlb_pool(), and store that address in pool->vaddr. This
keeps the pool free path using the same virtual address as the allocator.
Fixes: 79636caad361 ("swiotlb: if swiotlb is full, fall back to a transient memory pool")
Reviewed-by: Jason Gunthorpe <jgg@nvidia.com>
Tested-by: Michael Kelley <mhklinux@outlook.com>
Tested-by: Mostafa Saleh <smostafa@google.com>
Reviewed-by: Petr Tesarik <ptesarik@suse.com>
Signed-off-by: Aneesh Kumar K.V (Arm) <aneesh.kumar@kernel.org>
Reviewed-by: Mostafa Saleh <smostafa@google.com>
Link: https://lore.kernel.org/r/20260717180442.110954-6-aneesh.kumar@kernel.org
Signed-off-by: Marek Szyprowski <m.szyprowski@samsung.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/dma/swiotlb.c | 31 +++++++++++++++++++------------
1 file changed, 19 insertions(+), 12 deletions(-)
diff --git a/kernel/dma/swiotlb.c b/kernel/dma/swiotlb.c
index e27225f8aeb27..2945433166224 100644
--- a/kernel/dma/swiotlb.c
+++ b/kernel/dma/swiotlb.c
@@ -268,9 +268,9 @@ void __init swiotlb_update_mem_attributes(void)
}
static void swiotlb_init_io_tlb_pool(struct io_tlb_pool *mem, phys_addr_t start,
- unsigned long nslabs, bool late_alloc, unsigned int nareas)
+ void *vaddr, unsigned long nslabs, bool late_alloc,
+ unsigned int nareas)
{
- void *vaddr = phys_to_virt(start);
unsigned long bytes = nslabs << IO_TLB_SHIFT, i;
mem->nslabs = nslabs;
@@ -411,7 +411,7 @@ void __init swiotlb_init_remap(bool addressing_limit, unsigned int flags,
return;
}
- swiotlb_init_io_tlb_pool(mem, __pa(tlb), nslabs, false, nareas);
+ swiotlb_init_io_tlb_pool(mem, __pa(tlb), tlb, nslabs, false, nareas);
add_mem_pool(&io_tlb_default_mem, mem);
if (flags & SWIOTLB_VERBOSE)
@@ -509,7 +509,7 @@ int swiotlb_init_late(size_t size, gfp_t gfp_mask,
set_memory_decrypted((unsigned long)vstart,
(nslabs << IO_TLB_SHIFT) >> PAGE_SHIFT);
- swiotlb_init_io_tlb_pool(mem, virt_to_phys(vstart), nslabs, true,
+ swiotlb_init_io_tlb_pool(mem, virt_to_phys(vstart), vstart, nslabs, true,
nareas);
add_mem_pool(&io_tlb_default_mem, mem);
@@ -607,25 +607,26 @@ static struct page *alloc_dma_pages(gfp_t gfp, size_t bytes, u64 phys_limit)
* @bytes: Size of the buffer.
* @phys_limit: Maximum allowed physical address of the buffer.
* @gfp: GFP flags for the allocation.
+ * @vaddr: Receives the virtual address for the allocated buffer.
*
* Return: Allocated pages, or %NULL on allocation failure.
*/
static struct page *swiotlb_alloc_tlb(struct device *dev, size_t bytes,
- u64 phys_limit, gfp_t gfp)
+ u64 phys_limit, gfp_t gfp, void **vaddr)
{
struct page *page;
+ *vaddr = NULL;
+
/*
* Allocate from the atomic pools if memory is encrypted and
* the allocation is atomic, because decrypting may block.
*/
if (!gfpflags_allow_blocking(gfp) && dev && force_dma_unencrypted(dev)) {
- void *vaddr;
-
if (!IS_ENABLED(CONFIG_DMA_COHERENT_POOL))
return NULL;
- return dma_alloc_from_pool(dev, bytes, &vaddr, gfp,
+ return dma_alloc_from_pool(dev, bytes, vaddr, gfp,
dma_coherent_ok);
}
@@ -647,6 +648,8 @@ static struct page *swiotlb_alloc_tlb(struct device *dev, size_t bytes,
return NULL;
}
+ if (page)
+ *vaddr = phys_to_virt(page_to_phys(page));
return page;
}
@@ -687,6 +690,7 @@ static struct io_tlb_pool *swiotlb_alloc_pool(struct device *dev,
{
struct io_tlb_pool *pool;
unsigned int slot_order;
+ void *tlb_vaddr;
struct page *tlb;
size_t pool_size;
size_t tlb_size;
@@ -703,7 +707,8 @@ static struct io_tlb_pool *swiotlb_alloc_pool(struct device *dev,
pool->areas = (void *)pool + sizeof(*pool);
tlb_size = nslabs << IO_TLB_SHIFT;
- while (!(tlb = swiotlb_alloc_tlb(dev, tlb_size, phys_limit, gfp))) {
+ while (!(tlb = swiotlb_alloc_tlb(dev, tlb_size, phys_limit, gfp,
+ &tlb_vaddr))) {
if (nslabs <= minslabs)
goto error_tlb;
nslabs = ALIGN(nslabs >> 1, IO_TLB_SEGSIZE);
@@ -717,11 +722,12 @@ static struct io_tlb_pool *swiotlb_alloc_pool(struct device *dev,
if (!pool->slots)
goto error_slots;
- swiotlb_init_io_tlb_pool(pool, page_to_phys(tlb), nslabs, true, nareas);
+ swiotlb_init_io_tlb_pool(pool, page_to_phys(tlb), tlb_vaddr, nslabs,
+ true, nareas);
return pool;
error_slots:
- swiotlb_free_tlb(page_address(tlb), tlb_size);
+ swiotlb_free_tlb(tlb_vaddr, tlb_size);
error_tlb:
kfree(pool);
error:
@@ -1849,7 +1855,8 @@ static int rmem_swiotlb_device_init(struct reserved_mem *rmem,
set_memory_decrypted((unsigned long)phys_to_virt(rmem->base),
rmem->size >> PAGE_SHIFT);
- swiotlb_init_io_tlb_pool(pool, rmem->base, nslabs,
+ swiotlb_init_io_tlb_pool(pool, rmem->base, phys_to_virt(rmem->base),
+ nslabs,
false, nareas);
mem->force_bounce = true;
mem->for_alloc = true;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0714/1518] i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (712 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0713/1518] swiotlb: Preserve allocation virtual address for dynamic pools Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0715/1518] i3c: master: adi: add OF module alias for autoloading Greg Kroah-Hartman
` (284 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jakub Kicinski, Frank Li,
Alexandre Belloni, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jakub Kicinski <kuba@kernel.org>
[ Upstream commit 038cf48b3170af26a70bf2dee4f8c3ac910f5176 ]
On an empty bus ENTDAA assigns nothing, so cmd->rx_len (the count
of addresses left unassigned) equals master->maxdevs.
The GENMASK() index master->maxdevs - cmd->rx_len - 1 then becomes -1,
which trips up UBSAN. This happens every time on boot on a Gigabyte/AMD
server:
UBSAN: shift-out-of-bounds in drivers/i3c/master/dw-i3c-master.c:905:12
shift exponent 64 is too large for 64-bit type 'long unsigned int'
CPU: 7 UID: 0 PID: 963 Comm: (udev-worker) Not tainted 7.0.11-200.fc44.x86_64 #1 PREEMPT(lazy)
Hardware name: Giga Computing E163-Z34-AAH1-000/MZ33-DC1-000, BIOS R32_F45 04/01/2026
Call Trace:
<TASK>
dump_stack_lvl+0x5d/0x80
ubsan_epilogue+0x5/0x2b
__ubsan_handle_shift_out_of_bounds.cold+0xd7/0x1ab
dw_i3c_master_daa.cold+0x1b/0x96 [dw_i3c_master]
i3c_master_do_daa_ext.part.0+0x3e/0xf0 [i3c]
Skip the mask when no new device was assigned.
Fixes: 1dd728f5d4d4 ("i3c: master: Add driver for Synopsys DesignWare IP")
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260630172904.2662160-1-kuba@kernel.org
Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/i3c/master/dw-i3c-master.c | 10 +++++++++-
1 file changed, 9 insertions(+), 1 deletion(-)
diff --git a/drivers/i3c/master/dw-i3c-master.c b/drivers/i3c/master/dw-i3c-master.c
index 675c257ebe2c2..4a4fae96be370 100644
--- a/drivers/i3c/master/dw-i3c-master.c
+++ b/drivers/i3c/master/dw-i3c-master.c
@@ -883,7 +883,15 @@ static int dw_i3c_master_daa(struct i3c_master_controller *m)
if (!wait_for_completion_timeout(&xfer->comp, XFER_TIMEOUT))
dw_i3c_master_dequeue_xfer(master, xfer);
- newdevs = GENMASK(master->maxdevs - cmd->rx_len - 1, 0);
+ /*
+ * cmd->rx_len holds the number of addresses ENTDAA left unassigned.
+ * On an empty bus rx_len == maxdevs, so avoid GENMASK(-1, 0).
+ */
+ if (cmd->rx_len >= master->maxdevs)
+ newdevs = 0;
+ else
+ newdevs = GENMASK(master->maxdevs - cmd->rx_len - 1, 0);
+
newdevs &= ~olddevs;
for (pos = 0; pos < master->maxdevs; pos++) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0715/1518] i3c: master: adi: add OF module alias for autoloading
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (713 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0714/1518] i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0716/1518] fs: annotate inode timestamp accessors Greg Kroah-Hartman
` (283 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Can Peng, Frank Li,
Alexandre Belloni, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Can Peng <pengcan@kylinos.cn>
[ Upstream commit a733069a1943f30922b90bde5eef3cb25b010f8b ]
The Analog Devices I3C master driver can be built as a module and uses
adi_i3c_master_of_match as its OF match table, but the table is not
exported for module alias generation.
Add the MODULE_DEVICE_TABLE(of, ...) entry so modpost can generate OF
module aliases for OF based module autoloading.
Fixes: a79ac2cdc91d ("i3c: master: Add driver for Analog Devices I3C Controller IP")
Signed-off-by: Can Peng <pengcan@kylinos.cn>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260715012949.180245-1-pengcan@kylinos.cn
Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/i3c/master/adi-i3c-master.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/i3c/master/adi-i3c-master.c b/drivers/i3c/master/adi-i3c-master.c
index f0c2ddb2f4b21..178029769bab4 100644
--- a/drivers/i3c/master/adi-i3c-master.c
+++ b/drivers/i3c/master/adi-i3c-master.c
@@ -932,6 +932,7 @@ static const struct of_device_id adi_i3c_master_of_match[] = {
{ .compatible = "adi,i3c-master-v1" },
{}
};
+MODULE_DEVICE_TABLE(of, adi_i3c_master_of_match);
static int adi_i3c_master_probe(struct platform_device *pdev)
{
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0716/1518] fs: annotate inode timestamp accessors
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (714 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0715/1518] i3c: master: adi: add OF module alias for autoloading Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0717/1518] md/raid1: create serial pool adding rdev to array with serialize_policy=1 Greg Kroah-Hartman
` (282 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+8b3bd9f8a06658479d4a, Yu Peng,
Jeff Layton, Christian Brauner (Amutable), Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yu Peng <pengyu@kylinos.cn>
[ Upstream commit c610d2d0787961cdd6fc1de69d9be1ff3687e1a6 ]
syzbot reported a KCSAN race between fill_mg_cmtime() and
inode_set_ctime_to_ts() on inode->i_ctime_{sec,nsec}.
stat/getattr can sample inode timestamps while update paths store new
values concurrently, so KCSAN can report benign races on these fields.
Annotate the timestamp accessors with READ_ONCE()/WRITE_ONCE(), and use
the ctime accessor for the remaining ctime loads. This avoids the KCSAN
reports without changing timestamp semantics.
Fixes: 4e40eff0b573 ("fs: add infrastructure for multigrain timestamps")
Reported-by: syzbot+8b3bd9f8a06658479d4a@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=8b3bd9f8a06658479d4a
Signed-off-by: Yu Peng <pengyu@kylinos.cn>
Link: https://patch.msgid.link/20260708080232.2564807-1-pengyu@kylinos.cn
Reviewed-by: Jeff Layton <jlayton@kernel.org>
Signed-off-by: Christian Brauner (Amutable) <brauner@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/inode.c | 18 +++++++++---------
fs/stat.c | 2 +-
include/linux/fs.h | 20 ++++++++++----------
3 files changed, 20 insertions(+), 20 deletions(-)
diff --git a/fs/inode.c b/fs/inode.c
index 2c55ec49b0239..a931126398ced 100644
--- a/fs/inode.c
+++ b/fs/inode.c
@@ -2703,8 +2703,8 @@ struct timespec64 inode_set_ctime_to_ts(struct inode *inode, struct timespec64 t
{
trace_inode_set_ctime_to_ts(inode, &ts);
set_normalized_timespec64(&ts, ts.tv_sec, ts.tv_nsec);
- inode->i_ctime_sec = ts.tv_sec;
- inode->i_ctime_nsec = ts.tv_nsec;
+ WRITE_ONCE(inode->i_ctime_sec, ts.tv_sec);
+ WRITE_ONCE(inode->i_ctime_nsec, ts.tv_nsec);
return ts;
}
EXPORT_SYMBOL(inode_set_ctime_to_ts);
@@ -2778,7 +2778,7 @@ struct timespec64 inode_set_ctime_current(struct inode *inode)
*/
cns = smp_load_acquire(&inode->i_ctime_nsec);
if (cns & I_CTIME_QUERIED) {
- struct timespec64 ctime = { .tv_sec = inode->i_ctime_sec,
+ struct timespec64 ctime = { .tv_sec = inode_get_ctime_sec(inode),
.tv_nsec = cns & ~I_CTIME_QUERIED };
if (timespec64_compare(&now, &ctime) <= 0) {
@@ -2790,7 +2790,7 @@ struct timespec64 inode_set_ctime_current(struct inode *inode)
mgtime_counter_inc(mg_ctime_updates);
/* No need to cmpxchg if it's exactly the same */
- if (cns == now.tv_nsec && inode->i_ctime_sec == now.tv_sec) {
+ if (cns == now.tv_nsec && inode_get_ctime_sec(inode) == now.tv_sec) {
trace_ctime_xchg_skip(inode, &now);
goto out;
}
@@ -2799,7 +2799,7 @@ struct timespec64 inode_set_ctime_current(struct inode *inode)
/* Try to swap the nsec value into place. */
if (try_cmpxchg(&inode->i_ctime_nsec, &cur, now.tv_nsec)) {
/* If swap occurred, then we're (mostly) done */
- inode->i_ctime_sec = now.tv_sec;
+ WRITE_ONCE(inode->i_ctime_sec, now.tv_sec);
trace_ctime_ns_xchg(inode, cns, now.tv_nsec, cur);
mgtime_counter_inc(mg_ctime_swaps);
} else {
@@ -2814,7 +2814,7 @@ struct timespec64 inode_set_ctime_current(struct inode *inode)
goto retry;
}
/* Otherwise, keep the existing ctime */
- now.tv_sec = inode->i_ctime_sec;
+ now.tv_sec = inode_get_ctime_sec(inode);
now.tv_nsec = cur & ~I_CTIME_QUERIED;
}
out:
@@ -2847,7 +2847,7 @@ struct timespec64 inode_set_ctime_deleg(struct inode *inode, struct timespec64 u
/* pairs with try_cmpxchg below */
cur = smp_load_acquire(&inode->i_ctime_nsec);
cur_ts.tv_nsec = cur & ~I_CTIME_QUERIED;
- cur_ts.tv_sec = inode->i_ctime_sec;
+ cur_ts.tv_sec = inode_get_ctime_sec(inode);
/* If the update is older than the existing value, skip it. */
if (timespec64_compare(&update, &cur_ts) <= 0)
@@ -2873,7 +2873,7 @@ struct timespec64 inode_set_ctime_deleg(struct inode *inode, struct timespec64 u
retry:
old = cur;
if (try_cmpxchg(&inode->i_ctime_nsec, &cur, update.tv_nsec)) {
- inode->i_ctime_sec = update.tv_sec;
+ WRITE_ONCE(inode->i_ctime_sec, update.tv_sec);
mgtime_counter_inc(mg_ctime_swaps);
return update;
}
@@ -2889,7 +2889,7 @@ struct timespec64 inode_set_ctime_deleg(struct inode *inode, struct timespec64 u
goto retry;
/* Otherwise, it was a new timestamp. */
- cur_ts.tv_sec = inode->i_ctime_sec;
+ cur_ts.tv_sec = inode_get_ctime_sec(inode);
cur_ts.tv_nsec = cur & ~I_CTIME_QUERIED;
return cur_ts;
}
diff --git a/fs/stat.c b/fs/stat.c
index 6c79661e1b961..8c110555b3d7b 100644
--- a/fs/stat.c
+++ b/fs/stat.c
@@ -53,7 +53,7 @@ void fill_mg_cmtime(struct kstat *stat, u32 request_mask, struct inode *inode)
}
stat->mtime = inode_get_mtime(inode);
- stat->ctime.tv_sec = inode->i_ctime_sec;
+ stat->ctime.tv_sec = inode_get_ctime_sec(inode);
stat->ctime.tv_nsec = (u32)atomic_read(pcn);
if (!(stat->ctime.tv_nsec & I_CTIME_QUERIED))
stat->ctime.tv_nsec = ((u32)atomic_fetch_or(I_CTIME_QUERIED, pcn));
diff --git a/include/linux/fs.h b/include/linux/fs.h
index 14f5accc97b74..55ecd9d26b4fb 100644
--- a/include/linux/fs.h
+++ b/include/linux/fs.h
@@ -1783,12 +1783,12 @@ struct timespec64 inode_set_ctime_deleg(struct inode *inode,
static inline time64_t inode_get_atime_sec(const struct inode *inode)
{
- return inode->i_atime_sec;
+ return READ_ONCE(inode->i_atime_sec);
}
static inline long inode_get_atime_nsec(const struct inode *inode)
{
- return inode->i_atime_nsec;
+ return READ_ONCE(inode->i_atime_nsec);
}
static inline struct timespec64 inode_get_atime(const struct inode *inode)
@@ -1802,8 +1802,8 @@ static inline struct timespec64 inode_get_atime(const struct inode *inode)
static inline struct timespec64 inode_set_atime_to_ts(struct inode *inode,
struct timespec64 ts)
{
- inode->i_atime_sec = ts.tv_sec;
- inode->i_atime_nsec = ts.tv_nsec;
+ WRITE_ONCE(inode->i_atime_sec, ts.tv_sec);
+ WRITE_ONCE(inode->i_atime_nsec, ts.tv_nsec);
return ts;
}
@@ -1818,12 +1818,12 @@ static inline struct timespec64 inode_set_atime(struct inode *inode,
static inline time64_t inode_get_mtime_sec(const struct inode *inode)
{
- return inode->i_mtime_sec;
+ return READ_ONCE(inode->i_mtime_sec);
}
static inline long inode_get_mtime_nsec(const struct inode *inode)
{
- return inode->i_mtime_nsec;
+ return READ_ONCE(inode->i_mtime_nsec);
}
static inline struct timespec64 inode_get_mtime(const struct inode *inode)
@@ -1836,8 +1836,8 @@ static inline struct timespec64 inode_get_mtime(const struct inode *inode)
static inline struct timespec64 inode_set_mtime_to_ts(struct inode *inode,
struct timespec64 ts)
{
- inode->i_mtime_sec = ts.tv_sec;
- inode->i_mtime_nsec = ts.tv_nsec;
+ WRITE_ONCE(inode->i_mtime_sec, ts.tv_sec);
+ WRITE_ONCE(inode->i_mtime_nsec, ts.tv_nsec);
return ts;
}
@@ -1862,12 +1862,12 @@ static inline struct timespec64 inode_set_mtime(struct inode *inode,
static inline time64_t inode_get_ctime_sec(const struct inode *inode)
{
- return inode->i_ctime_sec;
+ return READ_ONCE(inode->i_ctime_sec);
}
static inline long inode_get_ctime_nsec(const struct inode *inode)
{
- return inode->i_ctime_nsec & ~I_CTIME_QUERIED;
+ return READ_ONCE(inode->i_ctime_nsec) & ~I_CTIME_QUERIED;
}
static inline struct timespec64 inode_get_ctime(const struct inode *inode)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0717/1518] md/raid1: create serial pool adding rdev to array with serialize_policy=1
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (715 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0716/1518] fs: annotate inode timestamp accessors Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0718/1518] locking/lockdep: Fix NULL pointer dereference in __lock_set_class() Greg Kroah-Hartman
` (281 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Martin Wilck, Mykola Marzhan,
Yu Kuai, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Martin Wilck <mwilck@suse.com>
[ Upstream commit 140234b2380ffb8ffb0cfc46fee0e822f43adef7 ]
The following bug has been observed with kernel 7.1.3 after adding a new
rdev to an existing RAID1 array with serialize_policy enabled:
Oops: 0002 [#1]
CPU: 0 UID: 0 PID: 19639 Comm: ext4lazyinit Not tainted 7.1.3-1-default
RIP: _raw_spin_lock_irqsave+0x27/0x50
CR2: 0000000000004960
Call Trace:
wait_for_serialization+0xb9/0x260 [raid1]
raid1_make_request+0x762/0xaff [raid1]
md_handle_request+0x1c9/0x2e0 [md_mod]
The raid1.c code calls wait_for_serialization() if the MD_SERIALIZE_POLICY
is set, and wait_for_serialization assumes that rdev->serial is
initialized. Normally this will be the case for arrays that have
the serialize_policy sysfs attribute set to 1.
But when a new rdev is added to an existing array in bind_rdev_to_array(),
the condition at mddev_create_serial_pool() causes creation of rdev->serial
to be skipped. Fix it.
Fixes: 69b00b5bb235 ("md: introduce a new struct for IO serialization")
Signed-off-by: Martin Wilck <mwilck@suse.com>
Reviewed-by: Mykola Marzhan <mykola@meshstor.io>
Link: https://patch.msgid.link/20260723112741.1206836-1-mwilck@suse.com
Signed-off-by: Yu Kuai <yukuai@fygo.io>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/md/md.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/md/md.c b/drivers/md/md.c
index 89965f96f3bba..7b7e085885183 100644
--- a/drivers/md/md.c
+++ b/drivers/md/md.c
@@ -236,7 +236,8 @@ void mddev_create_serial_pool(struct mddev *mddev, struct md_rdev *rdev)
int ret = 0;
unsigned int noio_flags;
- if (rdev && !rdev_need_serial(rdev) &&
+ if (!test_bit(MD_SERIALIZE_POLICY, &mddev->flags) &&
+ rdev && !rdev_need_serial(rdev) &&
!test_bit(CollisionCheck, &rdev->flags))
return;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0718/1518] locking/lockdep: Fix NULL pointer dereference in __lock_set_class()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (716 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0717/1518] md/raid1: create serial pool adding rdev to array with serialize_policy=1 Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0719/1518] powerpc: implement get_direction() in cpm2 Greg Kroah-Hartman
` (280 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Naveen Kumar Chaudhary,
Peter Zijlstra (Intel), Waiman Long, Dmitry Ilvokhin, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Naveen Kumar Chaudhary <naveen.osdev@gmail.com>
[ Upstream commit 7577e00b9ab506202b9f1a33de3cc8cc6413a4db ]
register_lock_class() can return NULL when the lock class pool is
exhausted, graph_lock() fails, or key validation fails. However,
__lock_set_class() uses the return value directly in pointer arithmetic
without a NULL check:
class = register_lock_class(lock, subclass, 0);
hlock->class_idx = class - lock_classes;
If class is NULL, this computes a wild offset that corrupts
hlock->class_idx. The subsequent reacquire_held_locks() call will
invoke hlock_class() with this corrupted index, leading to a NULL or
out-of-bounds pointer dereference.
Add the missing NULL check, consistent with how __lock_acquire() already
handles this case at the same call site.
Fixes: 64aa348edc61 ("lockdep: lock_set_subclass - reset a held lock's subclass")
Signed-off-by: Naveen Kumar Chaudhary <naveen.osdev@gmail.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Reviewed-by: Waiman Long <longman@redhat.com>
Reviewed-by: Dmitry Ilvokhin <d@ilvokhin.com>
Link: https://patch.msgid.link/h2kfw43n4527x6mgi2lwpz2rieqnfzgictpv4wr5nyfjkc47co@2r5vz4uz44db
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/locking/lockdep.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/kernel/locking/lockdep.c b/kernel/locking/lockdep.c
index 2d4c5bab5af88..e0de811148242 100644
--- a/kernel/locking/lockdep.c
+++ b/kernel/locking/lockdep.c
@@ -5437,6 +5437,8 @@ __lock_set_class(struct lockdep_map *lock, const char *name,
lock->wait_type_outer,
lock->lock_type);
class = register_lock_class(lock, subclass, 0);
+ if (!class)
+ return 0;
hlock->class_idx = class - lock_classes;
curr->lockdep_depth = i;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0719/1518] powerpc: implement get_direction() in cpm2
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (717 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0718/1518] locking/lockdep: Fix NULL pointer dereference in __lock_set_class() Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0720/1518] powerpc/44x: Set GPIO chip parent Greg Kroah-Hartman
` (279 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Christophe Leroy (CS GROUP),
Bartosz Golaszewski, Madhavan Srinivasan, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christophe Leroy (CS GROUP) <chleroy@kernel.org>
[ Upstream commit ca16219e9babc874349a6ac307d56523871a9137 ]
The lack of get_direction() callback in this driver causes GPIOLIB to
emit a warning. Implement it.
Fixes: e623c4303ed1 ("gpiolib: sanitize the return value of gpio_chip::get_direction()")
Signed-off-by: Christophe Leroy (CS GROUP) <chleroy@kernel.org>
Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Link: https://patch.msgid.link/c6eb70aa0e1ba6e15f947c827006aa79edace05c.1785318836.git.chleroy@kernel.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/powerpc/sysdev/cpm_common.c | 13 +++++++++++++
1 file changed, 13 insertions(+)
diff --git a/arch/powerpc/sysdev/cpm_common.c b/arch/powerpc/sysdev/cpm_common.c
index 07ea605ab0e62..b5d200e3ad684 100644
--- a/arch/powerpc/sysdev/cpm_common.c
+++ b/arch/powerpc/sysdev/cpm_common.c
@@ -181,6 +181,18 @@ static int cpm2_gpio32_dir_in(struct gpio_chip *gc, unsigned int gpio)
return 0;
}
+static int cpm2_gpio32_get_direction(struct gpio_chip *gc, unsigned int gpio)
+{
+ struct cpm2_gpio32_chip *cpm2_gc = gpiochip_get_data(gc);
+ struct cpm2_ioports __iomem *iop = cpm2_gc->regs;
+ u32 pin_mask = 1 << (31 - gpio);
+
+ if (in_be32(&iop->dir) & pin_mask)
+ return GPIO_LINE_DIRECTION_OUT;
+
+ return GPIO_LINE_DIRECTION_IN;
+}
+
int cpm2_gpiochip_add32(struct device *dev)
{
struct device_node *np = dev->of_node;
@@ -199,6 +211,7 @@ int cpm2_gpiochip_add32(struct device *dev)
gc->ngpio = 32;
gc->direction_input = cpm2_gpio32_dir_in;
gc->direction_output = cpm2_gpio32_dir_out;
+ gc->get_direction = cpm2_gpio32_get_direction;
gc->get = cpm2_gpio32_get;
gc->set = cpm2_gpio32_set;
gc->parent = dev;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0720/1518] powerpc/44x: Set GPIO chip parent
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (718 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0719/1518] powerpc: implement get_direction() in cpm2 Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0721/1518] powerpc/crash: Fix possible memory leak in update_crash_elfcorehdr() Greg Kroah-Hartman
` (278 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rosen Penev,
Christophe Leroy (CS GROUP), Linus Walleij, Madhavan Srinivasan,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rosen Penev <rosenp@gmail.com>
[ Upstream commit b9254d222d0b38cc6f7b73119fad6316f65278be ]
The PPC4xx GPIO driver stopped assigning an explicit parent
to the gpio_chip when it moved away from of_mm_gpiochip_add_data().
Restore that association from the platform device so OF GPIO lookup
can match phandles to the registered gpiochip.
Tested on: Cisco MX60W. No more probe deferral.
Assisted-by: Codex:GPT-5.5
Fixes: 1044dbaf2a77 ("powerpc/44x: Change GPIO driver to a proper platform driver")
Signed-off-by: Rosen Penev <rosenp@gmail.com>
Reviewed-by: Christophe Leroy (CS GROUP) <chleroy@kernel.org>
Reviewed-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Link: https://patch.msgid.link/20260517063754.21819-1-rosenp@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/powerpc/platforms/44x/gpio.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/arch/powerpc/platforms/44x/gpio.c b/arch/powerpc/platforms/44x/gpio.c
index aea0d913b59d0..4413a94cf7a6a 100644
--- a/arch/powerpc/platforms/44x/gpio.c
+++ b/arch/powerpc/platforms/44x/gpio.c
@@ -169,6 +169,7 @@ static int ppc4xx_gpio_probe(struct platform_device *ofdev)
gc = &chip->gc;
+ gc->parent = dev;
gc->base = -1;
gc->ngpio = 32;
gc->direction_input = ppc4xx_gpio_dir_in;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0721/1518] powerpc/crash: Fix possible memory leak in update_crash_elfcorehdr()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (719 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0720/1518] powerpc/44x: Set GPIO chip parent Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0722/1518] misc: vmc_vmci: Fix potential memory leak in vmci_event_subscribe() Greg Kroah-Hartman
` (277 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sourabh Jain, Jinjie Ruan,
Madhavan Srinivasan, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jinjie Ruan <ruanjinjie@huawei.com>
[ Upstream commit 4cc4b586007fbbf8edba4f1d0849e9a06b0cf6c3 ]
In get_crash_memory_ranges(), if crash_exclude_mem_range() failed
after realloc_mem_ranges() has successfully allocated the cmem
memory, it just returns an error but leaves cmem pointing to
the allocated memory, nor is it freed in the caller
update_crash_elfcorehdr(), which cause a memory leak, goto out
to free the cmem.
Fixes: 849599b702ef ("powerpc/crash: add crash memory hotplug support")
Reviewed-by: Sourabh Jain <sourabhjain@linux.ibm.com>
Signed-off-by: Jinjie Ruan <ruanjinjie@huawei.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Link: https://patch.msgid.link/20260729012948.2797865-2-ruanjinjie@huawei.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/powerpc/kexec/crash.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/powerpc/kexec/crash.c b/arch/powerpc/kexec/crash.c
index e6539f213b3d1..a520f851c3a6b 100644
--- a/arch/powerpc/kexec/crash.c
+++ b/arch/powerpc/kexec/crash.c
@@ -502,7 +502,7 @@ static void update_crash_elfcorehdr(struct kimage *image, struct memory_notify *
ret = get_crash_memory_ranges(&cmem);
if (ret) {
pr_err("Failed to get crash mem range\n");
- return;
+ goto out;
}
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0722/1518] misc: vmc_vmci: Fix potential memory leak in vmci_event_subscribe()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (720 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0721/1518] powerpc/crash: Fix possible memory leak in update_crash_elfcorehdr() Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0723/1518] misc: sgi-gru: remove interrupt-context page-table walks Greg Kroah-Hartman
` (276 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Abdun Nihaal, Vishnu Dasa,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Abdun Nihaal <nihaal@cse.iitm.ac.in>
[ Upstream commit 210854a96ef18b09b45a2a59ff14ca06dfe5ad4d ]
The memory allocated for struct vmci_subscription (sub) is not freed
in the error path when have_new_id is false. Fix that by adding a
kfree() call, and moving the read of sub->id to a point before freeing.
Fixes: 1d990201f9bb ("VMCI: event handling implementation.")
Signed-off-by: Abdun Nihaal <nihaal@cse.iitm.ac.in>
Acked-by: Vishnu Dasa <vishnu.dasa@broadcom.com>
Link: https://patch.msgid.link/20260722101215.76680-1-nihaal@cse.iitm.ac.in
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/misc/vmw_vmci/vmci_event.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/misc/vmw_vmci/vmci_event.c b/drivers/misc/vmw_vmci/vmci_event.c
index 9a41ab65378de..89ab9f05b88c5 100644
--- a/drivers/misc/vmw_vmci/vmci_event.c
+++ b/drivers/misc/vmw_vmci/vmci_event.c
@@ -179,16 +179,16 @@ int vmci_event_subscribe(u32 event,
}
}
+ *new_subscription_id = sub->id;
if (have_new_id) {
list_add_rcu(&sub->node, &subscriber_array[event]);
retval = VMCI_SUCCESS;
} else {
+ kfree(sub);
retval = VMCI_ERROR_NO_RESOURCES;
}
mutex_unlock(&subscriber_mutex);
-
- *new_subscription_id = sub->id;
return retval;
}
EXPORT_SYMBOL_GPL(vmci_event_subscribe);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0723/1518] misc: sgi-gru: remove interrupt-context page-table walks
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (721 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0722/1518] misc: vmc_vmci: Fix potential memory leak in vmci_event_subscribe() Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0724/1518] fanotify: report full event length for FIONREAD Greg Kroah-Hartman
` (275 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Muhammad Usama Anjum, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Muhammad Usama Anjum <usama.anjum@arm.com>
[ Upstream commit 928a8e9f523df845fc496bcb9811013b67aabec5 ]
The GRU TLB miss handler walks a process's page tables without holding
page-table locks or a reference to the mapped page. It also uses a kernel
page-table accessor on user page tables and supports only PMD-level large
mappings on x86-64.
Remove the direct walker. Send interrupt faults directly to user polling
mode so the existing call-OS fallback retries them in process context.
Remove the mmap-lock failure statistic that can no longer be incremented.
Fixes: 142586409c8b ("GRU Driver: page faults & exceptions")
Signed-off-by: Muhammad Usama Anjum <usama.anjum@arm.com>
Link: https://patch.msgid.link/20260730111316.3672672-2-usama.anjum@arm.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/misc/sgi-gru/grufault.c | 101 ++++---------------------------
drivers/misc/sgi-gru/gruprocfs.c | 1 -
drivers/misc/sgi-gru/grutables.h | 1 -
3 files changed, 12 insertions(+), 91 deletions(-)
diff --git a/drivers/misc/sgi-gru/grufault.c b/drivers/misc/sgi-gru/grufault.c
index 3557d78ee47a2..5a87c12f444a3 100644
--- a/drivers/misc/sgi-gru/grufault.c
+++ b/drivers/misc/sgi-gru/grufault.c
@@ -166,13 +166,8 @@ static void get_clear_fault_map(struct gru_state *gru,
}
/*
- * Atomic (interrupt context) & non-atomic (user context) functions to
- * convert a vaddr into a physical address. The size of the page
- * is returned in pageshift.
- * returns:
- * 0 - successful
- * < 0 - error code
- * 1 - (atomic only) try again in non-atomic context
+ * Convert a user virtual address to a physical address in process context.
+ * The size of the page is returned in pageshift.
*/
static int non_atomic_pte_lookup(struct vm_area_struct *vma,
unsigned long vaddr, int write,
@@ -192,87 +187,25 @@ static int non_atomic_pte_lookup(struct vm_area_struct *vma,
return 0;
}
-/*
- * atomic_pte_lookup
- *
- * Convert a user virtual address to a physical address
- * Only supports Intel large pages (2MB only) on x86_64.
- * ZZZ - hugepage support is incomplete
- *
- * NOTE: mmap_lock is already held on entry to this function. This
- * guarantees existence of the page tables.
- */
-static int atomic_pte_lookup(struct vm_area_struct *vma, unsigned long vaddr,
- int write, unsigned long *paddr, int *pageshift)
-{
- pgd_t *pgdp;
- p4d_t *p4dp;
- pud_t *pudp;
- pmd_t *pmdp;
- pte_t pte;
-
- pgdp = pgd_offset(vma->vm_mm, vaddr);
- if (unlikely(pgd_none(*pgdp)))
- goto err;
-
- p4dp = p4d_offset(pgdp, vaddr);
- if (unlikely(p4d_none(*p4dp)))
- goto err;
-
- pudp = pud_offset(p4dp, vaddr);
- if (unlikely(pud_none(*pudp)))
- goto err;
-
- pmdp = pmd_offset(pudp, vaddr);
- if (unlikely(pmd_none(*pmdp)))
- goto err;
-#ifdef CONFIG_X86_64
- if (unlikely(pmd_leaf(*pmdp)))
- pte = ptep_get((pte_t *)pmdp);
- else
-#endif
- pte = *pte_offset_kernel(pmdp, vaddr);
-
- if (unlikely(!pte_present(pte) ||
- (write && (!pte_write(pte) || !pte_dirty(pte)))))
- return 1;
-
- *paddr = pte_pfn(pte) << PAGE_SHIFT;
-#ifdef CONFIG_HUGETLB_PAGE
- *pageshift = is_vm_hugetlb_page(vma) ? HPAGE_SHIFT : PAGE_SHIFT;
-#else
- *pageshift = PAGE_SHIFT;
-#endif
- return 0;
-
-err:
- return 1;
-}
-
static int gru_vtop(struct gru_thread_state *gts, unsigned long vaddr,
int write, int atomic, unsigned long *gpa, int *pageshift)
{
struct mm_struct *mm = gts->ts_mm;
struct vm_area_struct *vma;
unsigned long paddr;
- int ret, ps;
+ int ps;
vma = find_vma(mm, vaddr);
if (!vma)
goto inval;
- /*
- * Atomic lookup is faster & usually works even if called in non-atomic
- * context.
- */
- rmb(); /* Must/check ms_range_active before loading PTEs */
- ret = atomic_pte_lookup(vma, vaddr, write, &paddr, &ps);
- if (ret) {
- if (atomic)
- goto upm;
- if (non_atomic_pte_lookup(vma, vaddr, write, &paddr, &ps))
- goto inval;
- }
+ if (atomic)
+ goto upm;
+
+ /* Order the caller's ms_range_active check before loading PTEs. */
+ rmb();
+ if (non_atomic_pte_lookup(vma, vaddr, write, &paddr, &ps))
+ goto inval;
if (is_gru_paddr(paddr))
goto inval;
paddr = paddr & ~((1UL << ps) - 1);
@@ -569,19 +502,9 @@ static irqreturn_t gru_intr(int chiplet, int blade)
continue;
}
- /*
- * This is running in interrupt context. Trylock the mmap_lock.
- * If it fails, retry the fault in user context.
- */
+ /* Address translation may sleep, so retry the fault in user context. */
gts->ustats.fmm_tlbmiss++;
- if (!gts->ts_force_cch_reload &&
- mmap_read_trylock(gts->ts_mm)) {
- gru_try_dropin(gru, gts, tfh, NULL);
- mmap_read_unlock(gts->ts_mm);
- } else {
- tfh_user_polling_mode(tfh);
- STAT(intr_mm_lock_failed);
- }
+ tfh_user_polling_mode(tfh);
}
return IRQ_HANDLED;
}
diff --git a/drivers/misc/sgi-gru/gruprocfs.c b/drivers/misc/sgi-gru/gruprocfs.c
index 97b8b38ab47df..b8139c27bc7f8 100644
--- a/drivers/misc/sgi-gru/gruprocfs.c
+++ b/drivers/misc/sgi-gru/gruprocfs.c
@@ -54,7 +54,6 @@ static int statistics_show(struct seq_file *s, void *p)
printstat(s, intr_cbr);
printstat(s, intr_tfh);
printstat(s, intr_spurious);
- printstat(s, intr_mm_lock_failed);
printstat(s, call_os);
printstat(s, call_os_wait_queue);
printstat(s, user_flush_tlb);
diff --git a/drivers/misc/sgi-gru/grutables.h b/drivers/misc/sgi-gru/grutables.h
index 640daf1994df7..3348552925c61 100644
--- a/drivers/misc/sgi-gru/grutables.h
+++ b/drivers/misc/sgi-gru/grutables.h
@@ -182,7 +182,6 @@ struct gru_stats_s {
atomic_long_t intr_cbr;
atomic_long_t intr_tfh;
atomic_long_t intr_spurious;
- atomic_long_t intr_mm_lock_failed;
atomic_long_t call_os;
atomic_long_t call_os_wait_queue;
atomic_long_t user_flush_tlb;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0724/1518] fanotify: report full event length for FIONREAD
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (722 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0723/1518] misc: sgi-gru: remove interrupt-context page-table walks Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0725/1518] wifi: mt76: connac: add MT7991A (0x7991) to is_mt7996() Greg Kroah-Hartman
` (274 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yichong Chen, Jan Kara, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yichong Chen <chenyichong@uniontech.com>
[ Upstream commit 68615158c12de36220446dfea5cfdf9ba6c19690 ]
fanotify_ioctl(FIONREAD) reports the number of bytes available to read
from the event queue. It currently accounts only FAN_EVENT_METADATA_LEN
for each queued event.
That underestimates events that carry additional information records, such
as FAN_REPORT_DFID_NAME events. A userspace program that uses FIONREAD to
size its read buffer can receive a length that is smaller than the next
event. Reading with that buffer then fails with -EINVAL, while a larger
buffer succeeds and reports a larger metadata.event_len.
Use fanotify_event_len() when summing queued events so FIONREAD includes
all info records.
Fixes: 5e469c830fdb ("fanotify: copy event fid info to user")
Signed-off-by: Yichong Chen <chenyichong@uniontech.com>
Link: https://patch.msgid.link/20260731021827.602479-1-chenyichong@uniontech.com
Signed-off-by: Jan Kara <jack@suse.cz>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/notify/fanotify/fanotify_user.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/fs/notify/fanotify/fanotify_user.c b/fs/notify/fanotify/fanotify_user.c
index 9dbe33cf2ceaa..629407c3e8737 100644
--- a/fs/notify/fanotify/fanotify_user.c
+++ b/fs/notify/fanotify/fanotify_user.c
@@ -1158,11 +1158,13 @@ static long fanotify_ioctl(struct file *file, unsigned int cmd, unsigned long ar
{
struct fsnotify_group *group;
struct fsnotify_event *fsn_event;
+ unsigned int info_mode;
void __user *p;
int ret = -ENOTTY;
size_t send_len = 0;
group = file->private_data;
+ info_mode = FAN_GROUP_FLAG(group, FANOTIFY_INFO_MODES);
p = (void __user *) arg;
@@ -1170,7 +1172,8 @@ static long fanotify_ioctl(struct file *file, unsigned int cmd, unsigned long ar
case FIONREAD:
spin_lock(&group->notification_lock);
list_for_each_entry(fsn_event, &group->notification_list, list)
- send_len += FAN_EVENT_METADATA_LEN;
+ send_len += fanotify_event_len(info_mode,
+ FANOTIFY_E(fsn_event));
spin_unlock(&group->notification_lock);
ret = put_user(send_len, (int __user *) p);
break;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0725/1518] wifi: mt76: connac: add MT7991A (0x7991) to is_mt7996()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (723 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0724/1518] fanotify: report full event length for FIONREAD Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0726/1518] wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length Greg Kroah-Hartman
` (273 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dmitry Gomzyakov, Felix Fietkau,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Gomzyakov <nicerok11@gmail.com>
[ Upstream commit 574bd79955d166c00c2b1531fed591ee70b6ba04 ]
The MT7991A chipset uses PCI device ID 0x7991 (MT7996_DEVICE_ID_2),
but is_mt7996() only checks for 0x7990. This causes MT7991A devices
to use incorrect chip-specific settings, such as:
- MSDU_CNT_V2 instead of MSDU_CNT in TX descriptors
- Wrong WTBL BMC size (32 instead of 64)
- Incorrect prefetch depth for MCU queues
Fixes: 7014fe535860 ("wifi: mt76: mt7996: add macros for pci device ids")
Signed-off-by: Dmitry Gomzyakov <nicerok11@gmail.com>
Link: https://patch.msgid.link/20260510102911.1883849-2-kyoto1337@protonmail.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt76_connac.h | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt76_connac.h b/drivers/net/wireless/mediatek/mt76/mt76_connac.h
index 192dcc374a642..670f59f55605a 100644
--- a/drivers/net/wireless/mediatek/mt76/mt76_connac.h
+++ b/drivers/net/wireless/mediatek/mt76/mt76_connac.h
@@ -224,7 +224,8 @@ static inline bool is_mt798x(struct mt76_dev *dev)
static inline bool is_mt7996(struct mt76_dev *dev)
{
- return mt76_chip(dev) == 0x7990;
+ u16 chip = mt76_chip(dev);
+ return chip == 0x7990 || chip == 0x7991;
}
static inline bool is_mt7992(struct mt76_dev *dev)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0726/1518] wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (724 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0725/1518] wifi: mt76: connac: add MT7991A (0x7991) to is_mt7996() Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0727/1518] wifi: mt76: mt7921: validate CLC firmware records Greg Kroah-Hartman
` (272 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Devin Wittmayer, Felix Fietkau,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Devin Wittmayer <lucid_duck@justthetip.ca>
[ Upstream commit 81497634d9f872fd3e8b03aada55574afff6f174 ]
The MPDU length in the rx descriptor comes from the hardware. In
monitor mode with the fcsfail filter enabled, the hardware passes up
corrupted frames, and a corrupted frame can report a length larger
than the received buffer. The bounds check correctly discards such
frames, but its WARN_ON_ONCE wrapper means any over-the-air garbage
frame taints the kernel, and panics it on the first such frame when
panic_on_warn is set.
Drop the WARN and discard the frame silently, matching what
commit c2d4c8723dbf ("mt76x2: remove some harmless WARN_ONs in tx
status and rx path") did for the neighboring rx and tx status paths.
Observed immediately on rx with an MT7612U in fcsfail monitor mode
on a busy channel.
Fixes: 7bc04215a66b ("mt76: add driver code for MT76x2e")
Signed-off-by: Devin Wittmayer <lucid_duck@justthetip.ca>
Link: https://patch.msgid.link/20260613002544.27750-2-lucid_duck@justthetip.ca
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt76x02_mac.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt76x02_mac.c b/drivers/net/wireless/mediatek/mt76/mt76x02_mac.c
index 83488b2d6efb9..06f17da2c0106 100644
--- a/drivers/net/wireless/mediatek/mt76/mt76x02_mac.c
+++ b/drivers/net/wireless/mediatek/mt76/mt76x02_mac.c
@@ -848,7 +848,7 @@ int mt76x02_mac_process_rx(struct mt76x02_dev *dev, struct sk_buff *skb,
}
}
- if (WARN_ON_ONCE(len > skb->len))
+ if (len > skb->len)
return -EINVAL;
if (pskb_trim(skb, len))
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0727/1518] wifi: mt76: mt7921: validate CLC firmware records
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (725 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0726/1518] wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0728/1518] wifi: mt76: mt7915: fix net_fill_forward_path for non-DBDC mt7986 Greg Kroah-Hartman
` (271 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Laxman Acharya Padhya, Felix Fietkau,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
[ Upstream commit 9417c5818a0146980c2608fda94c908e604eb033 ]
The CLC region is supplied by firmware, but the loader trusts the
region count and each record length. A malformed image can make the
region table pointer precede the firmware buffer, make the record loop
fail to advance, or index phy->clc past its end. Validate the table and
record bounds before dereferencing or copying.
Fixes: 23bdc5d8cadf ("wifi: mt76: mt7921: introduce Country Location Control support")
Signed-off-by: Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
Link: https://patch.msgid.link/CAMyXUJmh=WfwC4_KHupNxYR5e2Gy5QhBDL5TSG6XEW-XLa+X4Q@mail.gmail.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../net/wireless/mediatek/mt76/mt7921/mcu.c | 28 ++++++++++++++++---
1 file changed, 24 insertions(+), 4 deletions(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7921/mcu.c b/drivers/net/wireless/mediatek/mt76/mt7921/mcu.c
index 663b245f2891f..ad0a7ebb2f3aa 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7921/mcu.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7921/mcu.c
@@ -418,7 +418,8 @@ static int mt7921_load_clc(struct mt792x_dev *dev, const char *fw_name)
struct mt76_dev *mdev = &dev->mt76;
struct mt792x_phy *phy = &dev->phy;
const struct firmware *fw;
- int ret, i, len, offset = 0;
+ size_t clc_len, fw_data_len, len, offset = 0;
+ int ret, i;
u8 *clc_base = NULL, hw_encap = 0;
dev->phy.clc_chan_conf = 0xff;
@@ -444,13 +445,21 @@ static int mt7921_load_clc(struct mt792x_dev *dev, const char *fw_name)
}
hdr = (const void *)(fw->data + fw->size - sizeof(*hdr));
+ if (hdr->n_region > (fw->size - sizeof(*hdr)) / sizeof(*region)) {
+ dev_err(mdev->dev, "Invalid firmware region table\n");
+ ret = -EINVAL;
+ goto out;
+ }
+ fw_data_len = fw->size - sizeof(*hdr) -
+ hdr->n_region * sizeof(*region);
+
for (i = 0; i < hdr->n_region; i++) {
region = (const void *)((const u8 *)hdr -
(hdr->n_region - i) * sizeof(*region));
len = le32_to_cpu(region->len);
/* check if we have valid buffer size */
- if (offset + len > fw->size) {
+ if (len > fw_data_len - offset) {
dev_err(mdev->dev, "Invalid firmware region\n");
ret = -EINVAL;
goto out;
@@ -467,8 +476,19 @@ static int mt7921_load_clc(struct mt792x_dev *dev, const char *fw_name)
if (!clc_base)
goto out;
- for (offset = 0; offset < len; offset += le32_to_cpu(clc->len)) {
+ for (offset = 0; offset < len; offset += clc_len) {
+ if (len - offset < sizeof(*clc)) {
+ ret = -EINVAL;
+ goto out;
+ }
+
clc = (const struct mt7921_clc *)(clc_base + offset);
+ clc_len = le32_to_cpu(clc->len);
+ if (clc_len < sizeof(*clc) || clc_len > len - offset ||
+ clc->idx >= ARRAY_SIZE(phy->clc)) {
+ ret = -EINVAL;
+ goto out;
+ }
/* do not init buf again if chip reset triggered */
if (phy->clc[clc->idx])
@@ -480,7 +500,7 @@ static int mt7921_load_clc(struct mt792x_dev *dev, const char *fw_name)
continue;
phy->clc[clc->idx] = devm_kmemdup(mdev->dev, clc,
- le32_to_cpu(clc->len),
+ clc_len,
GFP_KERNEL);
if (!phy->clc[clc->idx]) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0728/1518] wifi: mt76: mt7915: fix net_fill_forward_path for non-DBDC mt7986
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (726 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0727/1518] wifi: mt76: mt7921: validate CLC firmware records Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0729/1518] wifi: mt76: Move Q_READ/Q_WRITE definitions in dma.h Greg Kroah-Hartman
` (270 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Benjamin Larsson, Zhi-Jun You,
Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhi-Jun You <hujy652@gmail.com>
[ Upstream commit bade0d238b60c29dafcc7da17501fa489495d6ae ]
Current implementation assumes that the hardware supports DBDC or single
band and binds to band0.
This causes net_fill_forward_path to select the wrong queue for non-DBDC
mt7986 because it binds to band1 and getting the following in dmesg:
ieee80211 phy2: WA: --> drop by reaseon:1, msdu id = 0xc002 but failed!
mtk_wed1: error status=00000002
ieee80211 phy2: WA: txblk
10324e00
len = 128
DW0 : 10 00 00 00
DW1 : 00 00 00 00
DW2 : 00 00 00 00
DW3 : 72 0f 94 68
DW4 : 00 00 00 00
DW5 : ff 03 00 00
DW6 : 00 00 3c 40
DW7 : 00 17 dd 14
DW8 : 79 6f 00 00
DW9 : 02 c0 00 00
DW10 : 58 c5 34 10
DW11 : 00 00 00 00
DW12 : 00 06 3e 00
DW13 : 00 00 00 80
DW14 : 10 8c 00 00
DW15 : 00 00 00 00
DW16 : 00 00 00 00
DW17 : 00 00 00 00
DW18 : 00 00 00 00
DW19 : 00 00 00 00
DW20 : 00 00 00 00
DW21 : 00 00 00 00
DW22 : 00 00 00 00
DW23 : 00 00 00 00
DW24 : 00 00 00 00
DW25 : 00 00 00 00
DW26 : 00 00 00 00
DW27 : 00 00 00 00
DW28 : 00 00 00 00
DW29 : 00 00 00 00
DW30 : 00 00 00 00
DW31 : 00 00 00 00
Fix it by using phy->mt76->band_idx for queue which works for both
non-DBDC and DBDC devices.
Fixes: f68d67623dec ("mt76: mt7915: add Wireless Ethernet Dispatch support")
Suggested-by: Benjamin Larsson <benjamin.larsson@genexis.eu>
Signed-off-by: Zhi-Jun You <hujy652@gmail.com>
Link: https://patch.msgid.link/20260715152113.553-2-hujy652@gmail.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7915/main.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7915/main.c b/drivers/net/wireless/mediatek/mt76/mt7915/main.c
index 6f594677474b0..8e69df105c5ae 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7915/main.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7915/main.c
@@ -1738,7 +1738,7 @@ mt7915_net_fill_forward_path(struct ieee80211_hw *hw,
path->mtk_wdma.wdma_idx = wed->wdma_idx;
path->mtk_wdma.bss = mvif->mt76.idx;
path->mtk_wdma.wcid = is_mt7915(&dev->mt76) ? msta->wcid.idx : 0x3ff;
- path->mtk_wdma.queue = phy != &dev->phy;
+ path->mtk_wdma.queue = phy->mt76->band_idx;
ctx->dev = NULL;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0729/1518] wifi: mt76: Move Q_READ/Q_WRITE definitions in dma.h
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (727 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0728/1518] wifi: mt76: mt7915: fix net_fill_forward_path for non-DBDC mt7986 Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0730/1518] wifi: mt76: Introduce the NPU generic layer Greg Kroah-Hartman
` (269 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Bianconi, Felix Fietkau,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lorenzo Bianconi <lorenzo@kernel.org>
[ Upstream commit e627439aecf358944261cf2ffb4449c61a7e5e9f ]
This is a preliminary patch to enable traffic forward offloading between
the MT76 NIC and the Airoha ethernet one via the Airoha NPU module
available on the Airoha EN7581 SoC.
Signed-off-by: Lorenzo Bianconi <lorenzo@kernel.org>
Link: https://patch.msgid.link/20251017-mt76-npu-devel-v2-1-ddaa90901723@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Stable-dep-of: 915672c5ae32 ("wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/dma.c | 31 ------------------------
drivers/net/wireless/mediatek/mt76/dma.h | 31 ++++++++++++++++++++++++
2 files changed, 31 insertions(+), 31 deletions(-)
diff --git a/drivers/net/wireless/mediatek/mt76/dma.c b/drivers/net/wireless/mediatek/mt76/dma.c
index 9ef073c27f309..2e1048838c09b 100644
--- a/drivers/net/wireless/mediatek/mt76/dma.c
+++ b/drivers/net/wireless/mediatek/mt76/dma.c
@@ -7,37 +7,6 @@
#include "mt76.h"
#include "dma.h"
-#if IS_ENABLED(CONFIG_NET_MEDIATEK_SOC_WED)
-
-#define Q_READ(_q, _field) ({ \
- u32 _offset = offsetof(struct mt76_queue_regs, _field); \
- u32 _val; \
- if ((_q)->flags & MT_QFLAG_WED) \
- _val = mtk_wed_device_reg_read((_q)->wed, \
- ((_q)->wed_regs + \
- _offset)); \
- else \
- _val = readl(&(_q)->regs->_field); \
- _val; \
-})
-
-#define Q_WRITE(_q, _field, _val) do { \
- u32 _offset = offsetof(struct mt76_queue_regs, _field); \
- if ((_q)->flags & MT_QFLAG_WED) \
- mtk_wed_device_reg_write((_q)->wed, \
- ((_q)->wed_regs + _offset), \
- _val); \
- else \
- writel(_val, &(_q)->regs->_field); \
-} while (0)
-
-#else
-
-#define Q_READ(_q, _field) readl(&(_q)->regs->_field)
-#define Q_WRITE(_q, _field, _val) writel(_val, &(_q)->regs->_field)
-
-#endif
-
static struct mt76_txwi_cache *
mt76_alloc_txwi(struct mt76_dev *dev)
{
diff --git a/drivers/net/wireless/mediatek/mt76/dma.h b/drivers/net/wireless/mediatek/mt76/dma.h
index 17a80e1757fcc..56bd53bf97bd3 100644
--- a/drivers/net/wireless/mediatek/mt76/dma.h
+++ b/drivers/net/wireless/mediatek/mt76/dma.h
@@ -46,6 +46,37 @@
#define MT_FCE_INFO_LEN 4
#define MT_RX_RXWI_LEN 32
+#if IS_ENABLED(CONFIG_NET_MEDIATEK_SOC_WED)
+
+#define Q_READ(_q, _field) ({ \
+ u32 _offset = offsetof(struct mt76_queue_regs, _field); \
+ u32 _val; \
+ if ((_q)->flags & MT_QFLAG_WED) \
+ _val = mtk_wed_device_reg_read((_q)->wed, \
+ ((_q)->wed_regs + \
+ _offset)); \
+ else \
+ _val = readl(&(_q)->regs->_field); \
+ _val; \
+})
+
+#define Q_WRITE(_q, _field, _val) do { \
+ u32 _offset = offsetof(struct mt76_queue_regs, _field); \
+ if ((_q)->flags & MT_QFLAG_WED) \
+ mtk_wed_device_reg_write((_q)->wed, \
+ ((_q)->wed_regs + _offset), \
+ _val); \
+ else \
+ writel(_val, &(_q)->regs->_field); \
+} while (0)
+
+#else
+
+#define Q_READ(_q, _field) readl(&(_q)->regs->_field)
+#define Q_WRITE(_q, _field, _val) writel(_val, &(_q)->regs->_field)
+
+#endif
+
struct mt76_desc {
__le32 buf0;
__le32 ctrl;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0730/1518] wifi: mt76: Introduce the NPU generic layer
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (728 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0729/1518] wifi: mt76: Move Q_READ/Q_WRITE definitions in dma.h Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0731/1518] wifi: mt76: always enable RRO queues for non-MT7992 chipset Greg Kroah-Hartman
` (268 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Bianconi, Felix Fietkau,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lorenzo Bianconi <lorenzo@kernel.org>
[ Upstream commit 7fb554b1b623c7da845521604bd05fa9570d07bc ]
Add the NPU generic layer in mt76 module. NPU will be used to enable
traffic forward offloading between the MT76 NIC and the Airoha ethernet one
available on the Airoha EN7581 SoC using Netfilter Flowtable APIs.
Signed-off-by: Lorenzo Bianconi <lorenzo@kernel.org>
Link: https://patch.msgid.link/20251017-mt76-npu-devel-v2-4-ddaa90901723@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Stable-dep-of: 915672c5ae32 ("wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/Kconfig | 4 +
drivers/net/wireless/mediatek/mt76/Makefile | 1 +
drivers/net/wireless/mediatek/mt76/dma.c | 41 +-
drivers/net/wireless/mediatek/mt76/dma.h | 36 ++
drivers/net/wireless/mediatek/mt76/mac80211.c | 6 +-
drivers/net/wireless/mediatek/mt76/mt76.h | 135 +++++
drivers/net/wireless/mediatek/mt76/npu.c | 501 ++++++++++++++++++
include/linux/soc/airoha/airoha_offload.h | 1 +
8 files changed, 718 insertions(+), 7 deletions(-)
create mode 100644 drivers/net/wireless/mediatek/mt76/npu.c
diff --git a/drivers/net/wireless/mediatek/mt76/Kconfig b/drivers/net/wireless/mediatek/mt76/Kconfig
index a86f800b8bf54..274709a0f8879 100644
--- a/drivers/net/wireless/mediatek/mt76/Kconfig
+++ b/drivers/net/wireless/mediatek/mt76/Kconfig
@@ -37,6 +37,10 @@ config MT792x_USB
tristate
select MT76_USB
+config MT76_NPU
+ bool
+ depends on MT76_CORE
+
source "drivers/net/wireless/mediatek/mt76/mt76x0/Kconfig"
source "drivers/net/wireless/mediatek/mt76/mt76x2/Kconfig"
source "drivers/net/wireless/mediatek/mt76/mt7603/Kconfig"
diff --git a/drivers/net/wireless/mediatek/mt76/Makefile b/drivers/net/wireless/mediatek/mt76/Makefile
index 87512d101a919..83759d7587454 100644
--- a/drivers/net/wireless/mediatek/mt76/Makefile
+++ b/drivers/net/wireless/mediatek/mt76/Makefile
@@ -12,6 +12,7 @@ mt76-y := \
mmio.o util.o trace.o dma.o mac80211.o debugfs.o eeprom.o \
tx.o agg-rx.o mcu.o wed.o scan.o channel.o
+mt76-$(CONFIG_MT76_NPU) += npu.o
mt76-$(CONFIG_PCI) += pci.o
mt76-$(CONFIG_NL80211_TESTMODE) += testmode.o
diff --git a/drivers/net/wireless/mediatek/mt76/dma.c b/drivers/net/wireless/mediatek/mt76/dma.c
index 2e1048838c09b..b36ceec45c4d7 100644
--- a/drivers/net/wireless/mediatek/mt76/dma.c
+++ b/drivers/net/wireless/mediatek/mt76/dma.c
@@ -189,10 +189,15 @@ static void
mt76_dma_sync_idx(struct mt76_dev *dev, struct mt76_queue *q)
{
Q_WRITE(q, desc_base, q->desc_dma);
- if (q->flags & MT_QFLAG_WED_RRO_EN)
+ if ((q->flags & MT_QFLAG_WED_RRO_EN) && !mt76_npu_device_active(dev))
Q_WRITE(q, ring_size, MT_DMA_RRO_EN | q->ndesc);
else
Q_WRITE(q, ring_size, q->ndesc);
+
+ if (mt76_queue_is_npu_tx(q)) {
+ writel(q->desc_dma, &q->regs->desc_base);
+ writel(q->ndesc, &q->regs->ring_size);
+ }
q->head = Q_READ(q, dma_idx);
q->tail = q->head;
}
@@ -204,7 +209,7 @@ void mt76_dma_queue_reset(struct mt76_dev *dev, struct mt76_queue *q,
return;
if (!mt76_queue_is_wed_rro_ind(q) &&
- !mt76_queue_is_wed_rro_rxdmad_c(q)) {
+ !mt76_queue_is_wed_rro_rxdmad_c(q) && !mt76_queue_is_npu(q)) {
int i;
/* clear descriptors */
@@ -415,6 +420,7 @@ mt76_dma_tx_cleanup(struct mt76_dev *dev, struct mt76_queue *q, bool flush)
while (q->queued > 0 && q->tail != last) {
mt76_dma_tx_cleanup_idx(dev, q, q->tail, &entry);
+ mt76_npu_txdesc_cleanup(q, q->tail);
mt76_queue_tx_complete(dev, q, &entry);
if (entry.txwi) {
@@ -649,6 +655,10 @@ mt76_dma_tx_queue_skb(struct mt76_phy *phy, struct mt76_queue *q,
if (test_bit(MT76_RESET, &phy->state))
goto free_skb;
+ /* TODO: Take into account unlinear skbs */
+ if (mt76_npu_device_active(dev) && skb_linearize(skb))
+ goto free_skb;
+
t = mt76_get_txwi(dev);
if (!t)
goto free_skb;
@@ -696,6 +706,9 @@ mt76_dma_tx_queue_skb(struct mt76_phy *phy, struct mt76_queue *q,
if (ret < 0)
goto unmap;
+ if (mt76_npu_device_active(dev))
+ return mt76_npu_dma_add_buf(phy, q, skb, &tx_info.buf[1], txwi);
+
return mt76_dma_add_buf(dev, q, tx_info.buf, tx_info.nbuf,
tx_info.info, tx_info.skb, t);
@@ -795,8 +808,15 @@ mt76_dma_alloc_queue(struct mt76_dev *dev, struct mt76_queue *q,
q->buf_size = bufsize;
q->hw_idx = idx;
- size = mt76_queue_is_wed_rro_ind(q) ? sizeof(struct mt76_wed_rro_desc)
- : sizeof(struct mt76_desc);
+ if (mt76_queue_is_wed_rro_ind(q))
+ size = sizeof(struct mt76_wed_rro_desc);
+ else if (mt76_queue_is_npu_tx(q))
+ size = sizeof(struct airoha_npu_tx_dma_desc);
+ else if (mt76_queue_is_npu_rx(q))
+ size = sizeof(struct airoha_npu_rx_dma_desc);
+ else
+ size = sizeof(struct mt76_desc);
+
q->desc = dmam_alloc_coherent(dev->dma_dev, q->ndesc * size,
&q->desc_dma, GFP_KERNEL);
if (!q->desc)
@@ -812,6 +832,7 @@ mt76_dma_alloc_queue(struct mt76_dev *dev, struct mt76_queue *q,
if (ret)
return ret;
+ mt76_npu_queue_setup(dev, q);
ret = mt76_wed_dma_setup(dev, q, false);
if (ret)
return ret;
@@ -839,6 +860,11 @@ mt76_dma_rx_cleanup(struct mt76_dev *dev, struct mt76_queue *q)
if (!q->ndesc)
return;
+ if (mt76_queue_is_npu(q)) {
+ mt76_npu_queue_cleanup(dev, q);
+ return;
+ }
+
do {
spin_lock_bh(&q->lock);
buf = mt76_dma_dequeue(dev, q, true, NULL, NULL, &more, NULL);
@@ -874,7 +900,7 @@ mt76_dma_rx_reset(struct mt76_dev *dev, enum mt76_rxq_id qid)
return;
if (!mt76_queue_is_wed_rro_ind(q) &&
- !mt76_queue_is_wed_rro_rxdmad_c(q)) {
+ !mt76_queue_is_wed_rro_rxdmad_c(q) && !mt76_queue_is_npu(q)) {
int i;
for (i = 0; i < q->ndesc; i++)
@@ -894,7 +920,10 @@ mt76_dma_rx_reset(struct mt76_dev *dev, enum mt76_rxq_id qid)
return;
mt76_dma_sync_idx(dev, q);
- mt76_dma_rx_fill_buf(dev, q, false);
+ if (mt76_queue_is_npu(q))
+ mt76_npu_fill_rx_queue(dev, q);
+ else
+ mt76_dma_rx_fill(dev, q, false);
}
static void
diff --git a/drivers/net/wireless/mediatek/mt76/dma.h b/drivers/net/wireless/mediatek/mt76/dma.h
index 56bd53bf97bd3..27eefc9e56f22 100644
--- a/drivers/net/wireless/mediatek/mt76/dma.h
+++ b/drivers/net/wireless/mediatek/mt76/dma.h
@@ -70,6 +70,42 @@
writel(_val, &(_q)->regs->_field); \
} while (0)
+#elif IS_ENABLED(CONFIG_MT76_NPU)
+
+#define Q_READ(_q, _field) ({ \
+ u32 _offset = offsetof(struct mt76_queue_regs, _field); \
+ u32 _val = 0; \
+ if ((_q)->flags & MT_QFLAG_NPU) { \
+ struct airoha_npu *npu; \
+ \
+ rcu_read_lock(); \
+ npu = rcu_dereference(q->dev->mmio.npu); \
+ if (npu) \
+ regmap_read(npu->regmap, \
+ ((_q)->wed_regs + _offset), &_val); \
+ rcu_read_unlock(); \
+ } else { \
+ _val = readl(&(_q)->regs->_field); \
+ } \
+ _val; \
+})
+
+#define Q_WRITE(_q, _field, _val) do { \
+ u32 _offset = offsetof(struct mt76_queue_regs, _field); \
+ if ((_q)->flags & MT_QFLAG_NPU) { \
+ struct airoha_npu *npu; \
+ \
+ rcu_read_lock(); \
+ npu = rcu_dereference(q->dev->mmio.npu); \
+ if (npu) \
+ regmap_write(npu->regmap, \
+ ((_q)->wed_regs + _offset), _val); \
+ rcu_read_unlock(); \
+ } else { \
+ writel(_val, &(_q)->regs->_field); \
+ } \
+} while (0)
+
#else
#define Q_READ(_q, _field) readl(&(_q)->regs->_field)
diff --git a/drivers/net/wireless/mediatek/mt76/mac80211.c b/drivers/net/wireless/mediatek/mt76/mac80211.c
index 7348ac5cf7e60..030e9103283f3 100644
--- a/drivers/net/wireless/mediatek/mt76/mac80211.c
+++ b/drivers/net/wireless/mediatek/mt76/mac80211.c
@@ -632,6 +632,8 @@ int mt76_create_page_pool(struct mt76_dev *dev, struct mt76_queue *q)
case MT_RXQ_MAIN:
case MT_RXQ_BAND1:
case MT_RXQ_BAND2:
+ case MT_RXQ_NPU0:
+ case MT_RXQ_NPU1:
pp_params.pool_size = 256;
break;
default:
@@ -817,6 +819,7 @@ void mt76_free_device(struct mt76_dev *dev)
destroy_workqueue(dev->wq);
dev->wq = NULL;
}
+ mt76_npu_deinit(dev);
ieee80211_free_hw(dev->hw);
}
EXPORT_SYMBOL_GPL(mt76_free_device);
@@ -1554,7 +1557,8 @@ void mt76_rx_poll_complete(struct mt76_dev *dev, enum mt76_rxq_id q,
while ((skb = __skb_dequeue(&dev->rx_skb[q])) != NULL) {
mt76_check_sta(dev, skb);
- if (mtk_wed_device_active(&dev->mmio.wed))
+ if (mtk_wed_device_active(&dev->mmio.wed) ||
+ mt76_npu_device_active(dev))
__skb_queue_tail(&frames, skb);
else
mt76_rx_aggr_reorder(skb, &frames);
diff --git a/drivers/net/wireless/mediatek/mt76/mt76.h b/drivers/net/wireless/mediatek/mt76/mt76.h
index 125ac1eb2d541..03e53a6a23b31 100644
--- a/drivers/net/wireless/mediatek/mt76/mt76.h
+++ b/drivers/net/wireless/mediatek/mt76/mt76.h
@@ -13,6 +13,7 @@
#include <linux/leds.h>
#include <linux/usb.h>
#include <linux/average.h>
+#include <linux/soc/airoha/airoha_offload.h>
#include <linux/soc/mediatek/mtk_wed.h>
#include <net/mac80211.h>
#include <net/page_pool/helpers.h>
@@ -34,6 +35,7 @@
#define MT_QFLAG_WED_RRO BIT(6)
#define MT_QFLAG_WED_RRO_EN BIT(7)
#define MT_QFLAG_EMI_EN BIT(8)
+#define MT_QFLAG_NPU BIT(9)
#define __MT_WED_Q(_type, _n) (MT_QFLAG_WED | \
FIELD_PREP(MT_QFLAG_WED_TYPE, _type) | \
@@ -48,6 +50,12 @@
#define MT_WED_RRO_Q_IND __MT_WED_RRO_Q(MT76_WED_RRO_Q_IND, 0)
#define MT_WED_RRO_Q_RXDMAD_C __MT_WED_RRO_Q(MT76_WED_RRO_Q_RXDMAD_C, 0)
+#define __MT_NPU_Q(_type, _n) (MT_QFLAG_NPU | \
+ FIELD_PREP(MT_QFLAG_WED_TYPE, _type) | \
+ FIELD_PREP(MT_QFLAG_WED_RING, _n))
+#define MT_NPU_Q_TX(_n) __MT_NPU_Q(MT76_WED_Q_TX, _n)
+#define MT_NPU_Q_RX(_n) __MT_NPU_Q(MT76_WED_Q_RX, _n)
+
struct mt76_dev;
struct mt76_phy;
struct mt76_wcid;
@@ -139,6 +147,8 @@ enum mt76_rxq_id {
MT_RXQ_TXFREE_BAND2,
MT_RXQ_RRO_IND,
MT_RXQ_RRO_RXDMAD_C,
+ MT_RXQ_NPU0,
+ MT_RXQ_NPU1,
__MT_RXQ_MAX
};
@@ -706,6 +716,11 @@ struct mt76_mmio {
struct mtk_wed_device wed_hif2;
struct completion wed_reset;
struct completion wed_reset_complete;
+
+ struct airoha_ppe_dev __rcu *ppe_dev;
+ struct airoha_npu __rcu *npu;
+ phys_addr_t phy_addr;
+ int npu_type;
};
struct mt76_rx_status {
@@ -1611,6 +1626,109 @@ int mt76_testmode_dump(struct ieee80211_hw *hw, struct sk_buff *skb,
int mt76_testmode_set_state(struct mt76_phy *phy, enum mt76_testmode_state state);
int mt76_testmode_alloc_skb(struct mt76_phy *phy, u32 len);
+#ifdef CONFIG_MT76_NPU
+void mt76_npu_check_ppe(struct mt76_dev *dev, struct sk_buff *skb,
+ u32 info);
+int mt76_npu_dma_add_buf(struct mt76_phy *phy, struct mt76_queue *q,
+ struct sk_buff *skb, struct mt76_queue_buf *buf,
+ void *txwi_ptr);
+int mt76_npu_rx_queue_init(struct mt76_dev *dev, struct mt76_queue *q);
+int mt76_npu_fill_rx_queue(struct mt76_dev *dev, struct mt76_queue *q);
+void mt76_npu_queue_cleanup(struct mt76_dev *dev, struct mt76_queue *q);
+void mt76_npu_disable_irqs(struct mt76_dev *dev);
+int mt76_npu_init(struct mt76_dev *dev, phys_addr_t phy_addr, int type);
+void mt76_npu_deinit(struct mt76_dev *dev);
+void mt76_npu_queue_setup(struct mt76_dev *dev, struct mt76_queue *q);
+void mt76_npu_txdesc_cleanup(struct mt76_queue *q, int index);
+int mt76_npu_net_setup_tc(struct ieee80211_hw *hw, struct ieee80211_vif *vif,
+ struct net_device *dev, enum tc_setup_type type,
+ void *type_data);
+#else
+static inline void mt76_npu_check_ppe(struct mt76_dev *dev,
+ struct sk_buff *skb, u32 info)
+{
+}
+
+static inline int mt76_npu_dma_add_buf(struct mt76_phy *phy,
+ struct mt76_queue *q,
+ struct sk_buff *skb,
+ struct mt76_queue_buf *buf,
+ void *txwi_ptr)
+{
+ return -EOPNOTSUPP;
+}
+
+static inline int mt76_npu_fill_rx_queue(struct mt76_dev *dev,
+ struct mt76_queue *q)
+{
+ return 0;
+}
+
+static inline void mt76_npu_queue_cleanup(struct mt76_dev *dev,
+ struct mt76_queue *q)
+{
+}
+
+static inline void mt76_npu_disable_irqs(struct mt76_dev *dev)
+{
+}
+
+static inline int mt76_npu_init(struct mt76_dev *dev, phys_addr_t phy_addr,
+ int type)
+{
+ return 0;
+}
+
+static inline void mt76_npu_deinit(struct mt76_dev *dev)
+{
+}
+
+static inline void mt76_npu_queue_setup(struct mt76_dev *dev,
+ struct mt76_queue *q)
+{
+}
+
+static inline void mt76_npu_txdesc_cleanup(struct mt76_queue *q,
+ int index)
+{
+}
+
+static inline int mt76_npu_net_setup_tc(struct ieee80211_hw *hw,
+ struct ieee80211_vif *vif,
+ struct net_device *dev,
+ enum tc_setup_type type,
+ void *type_data)
+{
+ return -EOPNOTSUPP;
+}
+#endif /* CONFIG_MT76_NPU */
+
+static inline bool mt76_npu_device_active(struct mt76_dev *dev)
+{
+ return !!rcu_access_pointer(dev->mmio.npu);
+}
+
+static inline bool mt76_ppe_device_active(struct mt76_dev *dev)
+{
+ return !!rcu_access_pointer(dev->mmio.ppe_dev);
+}
+
+static inline int mt76_npu_send_msg(struct airoha_npu *npu, int ifindex,
+ enum airoha_npu_wlan_set_cmd cmd,
+ u32 val, gfp_t gfp)
+{
+ return airoha_npu_wlan_send_msg(npu, ifindex, cmd, &val, sizeof(val),
+ gfp);
+}
+
+static inline int mt76_npu_get_msg(struct airoha_npu *npu, int ifindex,
+ enum airoha_npu_wlan_get_cmd cmd,
+ u32 *val, gfp_t gfp)
+{
+ return airoha_npu_wlan_get_msg(npu, ifindex, cmd, val, sizeof(*val),
+ gfp);
+}
+
static inline void mt76_testmode_reset(struct mt76_phy *phy, bool disable)
{
#ifdef CONFIG_NL80211_TESTMODE
@@ -1852,6 +1970,23 @@ static inline bool mt76_queue_is_emi(struct mt76_queue *q)
return q->flags & MT_QFLAG_EMI_EN;
}
+static inline bool mt76_queue_is_npu(struct mt76_queue *q)
+{
+ return q->flags & MT_QFLAG_NPU;
+}
+
+static inline bool mt76_queue_is_npu_tx(struct mt76_queue *q)
+{
+ return mt76_queue_is_npu(q) &&
+ FIELD_GET(MT_QFLAG_WED_TYPE, q->flags) == MT76_WED_Q_TX;
+}
+
+static inline bool mt76_queue_is_npu_rx(struct mt76_queue *q)
+{
+ return mt76_queue_is_npu(q) &&
+ FIELD_GET(MT_QFLAG_WED_TYPE, q->flags) == MT76_WED_Q_RX;
+}
+
struct mt76_txwi_cache *
mt76_token_release(struct mt76_dev *dev, int token, bool *wake);
int mt76_token_consume(struct mt76_dev *dev, struct mt76_txwi_cache **ptxwi);
diff --git a/drivers/net/wireless/mediatek/mt76/npu.c b/drivers/net/wireless/mediatek/mt76/npu.c
new file mode 100644
index 0000000000000..ec36975f6dc94
--- /dev/null
+++ b/drivers/net/wireless/mediatek/mt76/npu.c
@@ -0,0 +1,501 @@
+// SPDX-License-Identifier: GPL-2.0-only
+/*
+ * Copyright (c) 2025 AIROHA Inc
+ * Author: Lorenzo Bianconi <lorenzo@kernel.org>
+ */
+#include <linux/kernel.h>
+#include <net/flow_offload.h>
+#include <net/pkt_cls.h>
+
+#include "mt76.h"
+#include "dma.h"
+#include "mt76_connac.h"
+
+#define MT76_NPU_RX_BUF_SIZE (1800 + \
+ SKB_DATA_ALIGN(sizeof(struct skb_shared_info)))
+
+int mt76_npu_fill_rx_queue(struct mt76_dev *dev, struct mt76_queue *q)
+{
+ int nframes = 0;
+
+ while (q->queued < q->ndesc - 1) {
+ struct airoha_npu_rx_dma_desc *desc = (void *)q->desc;
+ struct mt76_queue_entry *e = &q->entry[q->head];
+ struct page *page;
+ int offset;
+
+ e->buf = mt76_get_page_pool_buf(q, &offset, q->buf_size);
+ if (!e->buf)
+ break;
+
+ e->dma_len[0] = SKB_WITH_OVERHEAD(q->buf_size);
+ page = virt_to_head_page(e->buf);
+ e->dma_addr[0] = page_pool_get_dma_addr(page) + offset;
+
+ memset(&desc[q->head], 0, sizeof(*desc));
+ desc[q->head].addr = e->dma_addr[0];
+
+ q->head = (q->head + 1) % q->ndesc;
+ q->queued++;
+ nframes++;
+ }
+
+ return nframes;
+}
+
+void mt76_npu_queue_cleanup(struct mt76_dev *dev, struct mt76_queue *q)
+{
+ spin_lock_bh(&q->lock);
+ while (q->queued > 0) {
+ struct mt76_queue_entry *e = &q->entry[q->tail];
+
+ dma_sync_single_for_cpu(dev->dma_dev, e->dma_addr[0],
+ e->dma_len[0],
+ page_pool_get_dma_dir(q->page_pool));
+ mt76_put_page_pool_buf(e->buf, false);
+ q->tail = (q->tail + 1) % q->ndesc;
+ q->queued--;
+ }
+ spin_unlock_bh(&q->lock);
+}
+
+static struct sk_buff *mt76_npu_dequeue(struct mt76_dev *dev,
+ struct mt76_queue *q,
+ u32 *info)
+{
+ struct airoha_npu_rx_dma_desc *desc = (void *)q->desc;
+ int i, nframes, index = q->tail;
+ struct sk_buff *skb = NULL;
+
+ nframes = FIELD_GET(NPU_RX_DMA_PKT_COUNT_MASK, desc[index].info);
+ nframes = max_t(int, nframes, 1);
+
+ for (i = 0; i < nframes; i++) {
+ struct mt76_queue_entry *e = &q->entry[index];
+ int len = FIELD_GET(NPU_RX_DMA_DESC_CUR_LEN_MASK,
+ desc[index].ctrl);
+
+ if (!FIELD_GET(NPU_RX_DMA_DESC_DONE_MASK, desc[index].ctrl)) {
+ dev_kfree_skb(skb);
+ return NULL;
+ }
+
+ dma_sync_single_for_cpu(dev->dma_dev, e->dma_addr[0],
+ e->dma_len[0],
+ page_pool_get_dma_dir(q->page_pool));
+
+ if (!skb) {
+ skb = napi_build_skb(e->buf, q->buf_size);
+ if (!skb)
+ return NULL;
+
+ __skb_put(skb, len);
+ skb_reset_mac_header(skb);
+ skb_mark_for_recycle(skb);
+ } else {
+ struct skb_shared_info *shinfo = skb_shinfo(skb);
+ struct page *page = virt_to_head_page(e->buf);
+ int nr_frags = shinfo->nr_frags;
+
+ if (nr_frags < ARRAY_SIZE(shinfo->frags))
+ skb_add_rx_frag(skb, nr_frags, page,
+ e->buf - page_address(page),
+ len, q->buf_size);
+ }
+
+ *info = desc[index].info;
+ index = (index + 1) % q->ndesc;
+ }
+ q->tail = index;
+ q->queued -= i;
+ Q_WRITE(q, dma_idx, q->tail);
+
+ return skb;
+}
+
+void mt76_npu_check_ppe(struct mt76_dev *dev, struct sk_buff *skb,
+ u32 info)
+{
+ struct airoha_ppe_dev *ppe_dev;
+ u16 reason, hash;
+
+ if (!mt76_npu_device_active(dev))
+ return;
+
+ rcu_read_lock();
+
+ ppe_dev = rcu_dereference(dev->mmio.ppe_dev);
+ if (!ppe_dev)
+ goto out;
+
+ hash = FIELD_GET(NPU_RX_DMA_FOE_ID_MASK, info);
+ skb_set_hash(skb, hash, PKT_HASH_TYPE_L4);
+
+ reason = FIELD_GET(NPU_RX_DMA_CRSN_MASK, info);
+ if (reason == PPE_CPU_REASON_HIT_UNBIND_RATE_REACHED) {
+ skb_set_mac_header(skb, 0);
+ airoha_ppe_dev_check_skb(ppe_dev, skb, hash, true);
+ }
+out:
+ rcu_read_unlock();
+}
+EXPORT_SYMBOL_GPL(mt76_npu_check_ppe);
+
+static int mt76_npu_rx_poll(struct napi_struct *napi, int budget)
+{
+ struct mt76_dev *dev = mt76_priv(napi->dev);
+ enum mt76_rxq_id qid = napi - dev->napi;
+ struct airoha_npu *npu;
+ int done = 0;
+
+ rcu_read_lock();
+
+ npu = rcu_dereference(dev->mmio.npu);
+ if (!npu)
+ goto out;
+
+ while (done < budget) {
+ struct sk_buff *skb;
+ u32 info = 0;
+
+ skb = mt76_npu_dequeue(dev, &dev->q_rx[qid], &info);
+ if (!skb)
+ break;
+
+ dev->drv->rx_skb(dev, qid, skb, &info);
+ mt76_rx_poll_complete(dev, qid, napi);
+ done++;
+ }
+
+ mt76_npu_fill_rx_queue(dev, &dev->q_rx[qid]);
+out:
+ if (done < budget && napi_complete(napi))
+ dev->drv->rx_poll_complete(dev, qid);
+
+ rcu_read_unlock();
+
+ return done;
+}
+
+static irqreturn_t mt76_npu_irq_handler(int irq, void *q_instance)
+{
+ struct mt76_queue *q = q_instance;
+ struct mt76_dev *dev = q->dev;
+ int qid = q - &dev->q_rx[0];
+ int index = qid - MT_RXQ_NPU0;
+ struct airoha_npu *npu;
+ u32 status;
+
+ rcu_read_lock();
+
+ npu = rcu_dereference(dev->mmio.npu);
+ if (!npu)
+ goto out;
+
+ status = airoha_npu_wlan_get_irq_status(npu, index);
+ airoha_npu_wlan_set_irq_status(npu, status);
+
+ airoha_npu_wlan_disable_irq(npu, index);
+ napi_schedule(&dev->napi[qid]);
+out:
+ rcu_read_unlock();
+
+ return IRQ_HANDLED;
+}
+
+int mt76_npu_dma_add_buf(struct mt76_phy *phy, struct mt76_queue *q,
+ struct sk_buff *skb, struct mt76_queue_buf *buf,
+ void *txwi_ptr)
+{
+ u16 txwi_len = min_t(u16, phy->dev->drv->txwi_size, NPU_TXWI_LEN);
+ struct airoha_npu_tx_dma_desc *desc = (void *)q->desc;
+ int ret;
+
+ /* TODO: Take into account unlinear skbs */
+ memcpy(desc[q->head].txwi, txwi_ptr, txwi_len);
+ desc[q->head].addr = buf->addr;
+ desc[q->head].ctrl = FIELD_PREP(NPU_TX_DMA_DESC_VEND_LEN_MASK, txwi_len) |
+ FIELD_PREP(NPU_TX_DMA_DESC_LEN_MASK, skb->len) |
+ NPU_TX_DMA_DESC_DONE_MASK;
+
+ ret = q->head;
+ q->entry[q->head].skip_buf0 = true;
+ q->entry[q->head].skip_buf1 = true;
+ q->entry[q->head].txwi = NULL;
+ q->entry[q->head].skb = NULL;
+ q->entry[q->head].wcid = 0xffff;
+
+ q->head = (q->head + 1) % q->ndesc;
+ q->queued++;
+
+ return ret;
+}
+
+void mt76_npu_txdesc_cleanup(struct mt76_queue *q, int index)
+{
+ struct airoha_npu_tx_dma_desc *desc = (void *)q->desc;
+
+ if (!mt76_queue_is_npu_tx(q))
+ return;
+
+ desc[index].ctrl &= ~NPU_TX_DMA_DESC_DONE_MASK;
+}
+
+void mt76_npu_queue_setup(struct mt76_dev *dev, struct mt76_queue *q)
+{
+ int qid = FIELD_GET(MT_QFLAG_WED_RING, q->flags);
+ bool xmit = mt76_queue_is_npu_tx(q);
+ struct airoha_npu *npu;
+
+ if (!mt76_queue_is_npu(q))
+ return;
+
+ npu = rcu_dereference_protected(dev->mmio.npu, &dev->mutex);
+ if (npu)
+ q->wed_regs = airoha_npu_wlan_get_queue_addr(npu, qid, xmit);
+}
+
+int mt76_npu_rx_queue_init(struct mt76_dev *dev, struct mt76_queue *q)
+{
+ int err, irq, qid = q - &dev->q_rx[0];
+ int size, index = qid - MT_RXQ_NPU0;
+ struct airoha_npu *npu;
+ const char *name;
+
+ mutex_lock(&dev->mutex);
+
+ npu = rcu_dereference_protected(dev->mmio.npu, &dev->mutex);
+ irq = npu && index < ARRAY_SIZE(npu->irqs) ? npu->irqs[index]
+ : -EINVAL;
+ if (irq < 0) {
+ err = irq;
+ goto out;
+ }
+
+ q->flags = MT_NPU_Q_RX(index);
+ size = qid == MT_RXQ_NPU1 ? NPU_RX1_DESC_NUM : NPU_RX0_DESC_NUM;
+ err = dev->queue_ops->alloc(dev, q, 0, size,
+ MT76_NPU_RX_BUF_SIZE, 0);
+ if (err)
+ goto out;
+
+ name = devm_kasprintf(dev->dev, GFP_KERNEL, "mt76-npu.%d", index);
+ if (!name) {
+ err = -ENOMEM;
+ goto out;
+ }
+
+ err = devm_request_irq(dev->dev, irq, mt76_npu_irq_handler,
+ IRQF_SHARED, name, q);
+ if (err)
+ goto out;
+
+ netif_napi_add(dev->napi_dev, &dev->napi[qid], mt76_npu_rx_poll);
+ mt76_npu_fill_rx_queue(dev, q);
+ napi_enable(&dev->napi[qid]);
+out:
+ mutex_unlock(&dev->mutex);
+
+ return err;
+}
+EXPORT_SYMBOL_GPL(mt76_npu_rx_queue_init);
+
+static int mt76_npu_setup_tc_block_cb(enum tc_setup_type type,
+ void *type_data, void *cb_priv)
+{
+ struct mt76_phy *phy = cb_priv;
+ struct mt76_dev *dev = phy->dev;
+ struct airoha_ppe_dev *ppe_dev;
+ int err = -EOPNOTSUPP;
+
+ if (type != TC_SETUP_CLSFLOWER)
+ return -EOPNOTSUPP;
+
+ mutex_lock(&dev->mutex);
+
+ ppe_dev = rcu_dereference_protected(dev->mmio.ppe_dev, &dev->mutex);
+ if (ppe_dev)
+ err = airoha_ppe_dev_setup_tc_block_cb(ppe_dev, type_data);
+
+ mutex_unlock(&dev->mutex);
+
+ return err;
+}
+
+static int mt76_npu_setup_tc_block(struct mt76_phy *phy,
+ struct net_device *dev,
+ struct flow_block_offload *f)
+{
+ flow_setup_cb_t *cb = mt76_npu_setup_tc_block_cb;
+ static LIST_HEAD(block_cb_list);
+ struct flow_block_cb *block_cb;
+
+ if (f->binder_type != FLOW_BLOCK_BINDER_TYPE_CLSACT_INGRESS)
+ return -EOPNOTSUPP;
+
+ if (!tc_can_offload(dev))
+ return -EOPNOTSUPP;
+
+ f->driver_block_list = &block_cb_list;
+ switch (f->command) {
+ case FLOW_BLOCK_BIND:
+ block_cb = flow_block_cb_lookup(f->block, cb, dev);
+ if (block_cb) {
+ flow_block_cb_incref(block_cb);
+ return 0;
+ }
+
+ block_cb = flow_block_cb_alloc(cb, dev, phy, NULL);
+ if (IS_ERR(block_cb))
+ return PTR_ERR(block_cb);
+
+ flow_block_cb_incref(block_cb);
+ flow_block_cb_add(block_cb, f);
+ list_add_tail(&block_cb->driver_list, &block_cb_list);
+ return 0;
+ case FLOW_BLOCK_UNBIND:
+ block_cb = flow_block_cb_lookup(f->block, cb, dev);
+ if (!block_cb)
+ return -ENOENT;
+
+ if (!flow_block_cb_decref(block_cb)) {
+ flow_block_cb_remove(block_cb, f);
+ list_del(&block_cb->driver_list);
+ }
+ return 0;
+ default:
+ return -EOPNOTSUPP;
+ }
+}
+
+int mt76_npu_net_setup_tc(struct ieee80211_hw *hw, struct ieee80211_vif *vif,
+ struct net_device *dev, enum tc_setup_type type,
+ void *type_data)
+{
+ struct mt76_phy *phy = hw->priv;
+
+ if (!tc_can_offload(dev))
+ return -EOPNOTSUPP;
+
+ if (!mt76_npu_device_active(phy->dev))
+ return -EOPNOTSUPP;
+
+ switch (type) {
+ case TC_SETUP_BLOCK:
+ case TC_SETUP_FT:
+ return mt76_npu_setup_tc_block(phy, dev, type_data);
+ default:
+ return -EOPNOTSUPP;
+ }
+}
+EXPORT_SYMBOL_GPL(mt76_npu_net_setup_tc);
+
+void mt76_npu_disable_irqs(struct mt76_dev *dev)
+{
+ struct airoha_npu *npu;
+ int i;
+
+ rcu_read_lock();
+
+ npu = rcu_dereference(dev->mmio.npu);
+ if (!npu)
+ goto unlock;
+
+ for (i = MT_RXQ_NPU0; i <= MT_RXQ_NPU1; i++) {
+ int qid = i - MT_RXQ_NPU0;
+ u32 status;
+
+ status = airoha_npu_wlan_get_irq_status(npu, qid);
+ airoha_npu_wlan_set_irq_status(npu, status);
+ airoha_npu_wlan_disable_irq(npu, qid);
+ }
+unlock:
+ rcu_read_unlock();
+}
+EXPORT_SYMBOL_GPL(mt76_npu_disable_irqs);
+
+int mt76_npu_init(struct mt76_dev *dev, phys_addr_t phy_addr, int type)
+{
+ struct airoha_ppe_dev *ppe_dev;
+ struct airoha_npu *npu;
+ int err = 0;
+
+ /* NPU offloading is only supported by MT7992 */
+ if (!is_mt7992(dev))
+ return 0;
+
+ mutex_lock(&dev->mutex);
+
+ npu = airoha_npu_get(dev->dev);
+ if (IS_ERR(npu)) {
+ request_module("airoha-npu");
+ npu = airoha_npu_get(dev->dev);
+ }
+
+ if (IS_ERR(npu)) {
+ err = PTR_ERR(npu);
+ goto error_unlock;
+ }
+
+ ppe_dev = airoha_ppe_get_dev(dev->dev);
+ if (IS_ERR(ppe_dev)) {
+ request_module("airoha-eth");
+ ppe_dev = airoha_ppe_get_dev(dev->dev);
+ }
+
+ if (IS_ERR(ppe_dev)) {
+ err = PTR_ERR(ppe_dev);
+ goto error_npu_put;
+ }
+
+ err = airoha_npu_wlan_init_reserved_memory(npu);
+ if (err)
+ goto error_ppe_put;
+
+ dev->dma_dev = npu->dev;
+ dev->mmio.phy_addr = phy_addr;
+ dev->mmio.npu_type = type;
+ /* NPU offloading requires HW-RRO for RX packet reordering. */
+ dev->hwrro_mode = MT76_HWRRO_V3_1;
+
+ rcu_assign_pointer(dev->mmio.npu, npu);
+ rcu_assign_pointer(dev->mmio.ppe_dev, ppe_dev);
+ synchronize_rcu();
+
+ mutex_unlock(&dev->mutex);
+
+ return 0;
+
+error_ppe_put:
+ airoha_ppe_put_dev(ppe_dev);
+error_npu_put:
+ airoha_npu_put(npu);
+error_unlock:
+ mutex_unlock(&dev->mutex);
+
+ return err;
+}
+EXPORT_SYMBOL_GPL(mt76_npu_init);
+
+void mt76_npu_deinit(struct mt76_dev *dev)
+{
+ struct airoha_ppe_dev *ppe_dev;
+ struct airoha_npu *npu;
+
+ mutex_lock(&dev->mutex);
+
+ npu = rcu_replace_pointer(dev->mmio.npu, NULL,
+ lockdep_is_held(&dev->mutex));
+ if (npu)
+ airoha_npu_put(npu);
+
+ ppe_dev = rcu_replace_pointer(dev->mmio.ppe_dev, NULL,
+ lockdep_is_held(&dev->mutex));
+ if (ppe_dev)
+ airoha_ppe_put_dev(ppe_dev);
+
+ mutex_unlock(&dev->mutex);
+
+ mt76_npu_queue_cleanup(dev, &dev->q_rx[MT_RXQ_NPU0]);
+ mt76_npu_queue_cleanup(dev, &dev->q_rx[MT_RXQ_NPU1]);
+}
diff --git a/include/linux/soc/airoha/airoha_offload.h b/include/linux/soc/airoha/airoha_offload.h
index d4f6e8124a493..7589fccfeef6d 100644
--- a/include/linux/soc/airoha/airoha_offload.h
+++ b/include/linux/soc/airoha/airoha_offload.h
@@ -6,6 +6,7 @@
#ifndef AIROHA_OFFLOAD_H
#define AIROHA_OFFLOAD_H
+#include <linux/skbuff.h>
#include <linux/spinlock.h>
#include <linux/workqueue.h>
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0731/1518] wifi: mt76: always enable RRO queues for non-MT7992 chipset
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (729 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0730/1518] wifi: mt76: Introduce the NPU generic layer Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0732/1518] wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash Greg Kroah-Hartman
` (267 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Kang Yang, Lorenzo Bianconi,
Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lorenzo Bianconi <lorenzo@kernel.org>
[ Upstream commit f801fec3f0850ac00073bc322c0e4ea446d938ae ]
MT7990 NPU binary requires to initialize NPU desc_base after configuring
ring_size. This is a preliminary patch to enable NPU offload for MT7996
(Eagle) chipset.
Tested-by: Kang Yang <kang.yang@airoha.com>
Signed-off-by: Lorenzo Bianconi <lorenzo@kernel.org>
Link: https://patch.msgid.link/20260122-mt76-npu-eagle-offload-v2-3-2374614c0de6@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Stable-dep-of: 915672c5ae32 ("wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/dma.c | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)
diff --git a/drivers/net/wireless/mediatek/mt76/dma.c b/drivers/net/wireless/mediatek/mt76/dma.c
index b36ceec45c4d7..66df27480f39a 100644
--- a/drivers/net/wireless/mediatek/mt76/dma.c
+++ b/drivers/net/wireless/mediatek/mt76/dma.c
@@ -6,6 +6,7 @@
#include <linux/dma-mapping.h>
#include "mt76.h"
#include "dma.h"
+#include "mt76_connac.h"
static struct mt76_txwi_cache *
mt76_alloc_txwi(struct mt76_dev *dev)
@@ -188,16 +189,18 @@ mt76_dma_queue_magic_cnt_init(struct mt76_dev *dev, struct mt76_queue *q)
static void
mt76_dma_sync_idx(struct mt76_dev *dev, struct mt76_queue *q)
{
- Q_WRITE(q, desc_base, q->desc_dma);
- if ((q->flags & MT_QFLAG_WED_RRO_EN) && !mt76_npu_device_active(dev))
+ if ((q->flags & MT_QFLAG_WED_RRO_EN) &&
+ (!is_mt7992(dev) || !mt76_npu_device_active(dev)))
Q_WRITE(q, ring_size, MT_DMA_RRO_EN | q->ndesc);
else
Q_WRITE(q, ring_size, q->ndesc);
if (mt76_queue_is_npu_tx(q)) {
- writel(q->desc_dma, &q->regs->desc_base);
writel(q->ndesc, &q->regs->ring_size);
+ writel(q->desc_dma, &q->regs->desc_base);
}
+
+ Q_WRITE(q, desc_base, q->desc_dma);
q->head = Q_READ(q, dma_idx);
q->tail = q->head;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0732/1518] wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (730 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0731/1518] wifi: mt76: always enable RRO queues for non-MT7992 chipset Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0733/1518] wifi: mt76: mt7925: update clc before setting sar power table Greg Kroah-Hartman
` (266 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sean Wang, Jeff Hsu, Eason Lai,
Felix Fietkau, Sasha Levin, Michael Lo
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eason Lai <Eason.Lai@mediatek.com>
[ Upstream commit 915672c5ae32deeb72f4572856d123f314791136 ]
When an AER error occurs and the bus is hung, the register reads return
0xFFFFFFFF, causing the DMA queue state to be corrupted and resulting in
an invalid memory access when accessing q->desc[] or q->entry[].
Unable to handle kernel paging request at virtual address
ffffffc01099eac0
pc : mt76_dma_add_buf+0x124/0x188 [mt76]
lr : mt76_dma_rx_fill+0x11c/0x1d8 [mt76]
sp : ffffffc016d9bbf0
x29: ffffffc016d9bc10 x28: 0000000000000000
x27: 0000000000000000 x26: ffffffb7855e50b8
x25: ffffffb80d04f000 x24: 0000000000000000
x23: 0000000000000ec0 x22: ffffffb796803648
x21: ffffffb796801f80 x20: ffffffb7968035f8
x19: 0000000000000ec0 x18: 0000000000000000
x17: 000000004ec00000 x16: 000000000ec00000
x15: ffffffc01099eac0 x14: 000000004ec00000
x13: 00000000ffc5a000 x12: ffffffc016d9bc32
x11: 00000000ffffffff x10: 0000000000000002
x9 : 0000000000000000 x8 : 000000000000b4ac
x7 : 0000000000000a20 x6 : ffffffb6c1806400
x5 : 0000000000000000 x4 : ffffffb80d04f000
x3 : 0000000000000000 x2 : 0000000000000001
x1 : 000000000ec04000 x0 : ffffffb7968035f8
Call trace:
mt76_dma_add_buf+0x124/0x188 [mt76 (HASH:1029 4)]
mt76_dma_rx_reset+0xe8/0xfc [mt76 (HASH:1029 4)]
mt7921_wpdma_reset+0x188/0x1b0 [mt7921e (HASH:ee48 5)]
mt7921e_mac_reset+0x128/0x418 [mt7921e (HASH:ee48 5)]
mt7921_mac_reset_work+0xac/0x1a8 [mt7921_common (HASH:f721 6)]
process_one_work+0x188/0x514
worker_thread+0x12c/0x300
kthread+0x140/0x1fc
ret_from_fork+0x10/0x30
Fix the invalid memory access by validating the DMA index read from the
hardware before it is used as a queue index. An out-of-range value, such
as the 0xFFFFFFFF returned while the bus is hung, is now clamped so it can
no longer corrupt q->head or q->tail. In addition, check the bus_hung flag
in mt7921_mac_reset_work() before attempting the reset sequence, reject MCU
messages while the bus is hung, and install no-op bus operations when an
unrecoverable AER error is detected, preventing further invalid hardware
accesses.
Due to hardware limitations - such as the lack of a connected hardware
reset pin or the absence of host re-probe functionality - affected Wi-Fi
devices may not fully recover to a normal operational state after
certain errors, even with AER enabled.
Fixes: 17f1de56df05 ("mt76: add common code shared between multiple chipsets")
Co-developed-by: Sean Wang <sean.wang@mediatek.com>
Signed-off-by: Sean Wang <sean.wang@mediatek.com>
Co-developed-by: Jeff Hsu <jeff.hsu@mediatek.com>
Signed-off-by: Jeff Hsu <jeff.hsu@mediatek.com>
Signed-off-by: Eason Lai <Eason.Lai@mediatek.com>
Co-developed-by: Michael Lo <michael.lo@mediatek.com>
Link: https://patch.msgid.link/20260506070458.3096180-1-jb.tsai@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/dma.c | 27 +++--
drivers/net/wireless/mediatek/mt76/mcu.c | 12 +-
.../net/wireless/mediatek/mt76/mt76_connac.h | 5 +
.../net/wireless/mediatek/mt76/mt7921/mac.c | 3 +
.../net/wireless/mediatek/mt76/mt7921/pci.c | 103 ++++++++++++++++++
5 files changed, 139 insertions(+), 11 deletions(-)
diff --git a/drivers/net/wireless/mediatek/mt76/dma.c b/drivers/net/wireless/mediatek/mt76/dma.c
index 66df27480f39a..0ba93290b00d3 100644
--- a/drivers/net/wireless/mediatek/mt76/dma.c
+++ b/drivers/net/wireless/mediatek/mt76/dma.c
@@ -186,6 +186,18 @@ mt76_dma_queue_magic_cnt_init(struct mt76_dev *dev, struct mt76_queue *q)
}
}
+/* A hung bus (e.g. after a PCIe AER error) reads 0xffffffff from every
+ * register, so clamp an out-of-range index to the fallback to keep it from
+ * corrupting q->head/q->tail.
+ */
+static int
+mt76_dma_read_dma_idx(struct mt76_queue *q, int fallback)
+{
+ u32 idx = Q_READ(q, dma_idx);
+
+ return idx < q->ndesc ? idx : fallback;
+}
+
static void
mt76_dma_sync_idx(struct mt76_dev *dev, struct mt76_queue *q)
{
@@ -201,7 +213,8 @@ mt76_dma_sync_idx(struct mt76_dev *dev, struct mt76_queue *q)
}
Q_WRITE(q, desc_base, q->desc_dma);
- q->head = Q_READ(q, dma_idx);
+
+ q->head = mt76_dma_read_dma_idx(q, 0);
q->tail = q->head;
}
@@ -419,7 +432,7 @@ mt76_dma_tx_cleanup(struct mt76_dev *dev, struct mt76_queue *q, bool flush)
if (flush)
last = -1;
else
- last = Q_READ(q, dma_idx);
+ last = mt76_dma_read_dma_idx(q, -1);
while (q->queued > 0 && q->tail != last) {
mt76_dma_tx_cleanup_idx(dev, q, q->tail, &entry);
@@ -432,7 +445,7 @@ mt76_dma_tx_cleanup(struct mt76_dev *dev, struct mt76_queue *q, bool flush)
}
if (!flush && q->tail == last)
- last = Q_READ(q, dma_idx);
+ last = mt76_dma_read_dma_idx(q, -1);
}
spin_unlock_bh(&q->cleanup_lock);
@@ -625,8 +638,8 @@ mt76_dma_tx_queue_skb_raw(struct mt76_dev *dev, struct mt76_queue *q,
buf.len = skb->len;
spin_lock_bh(&q->lock);
- mt76_dma_add_buf(dev, q, &buf, 1, tx_info, skb, NULL);
- mt76_dma_kick_queue(dev, q);
+ if (mt76_dma_add_buf(dev, q, &buf, 1, tx_info, skb, NULL) >= 0)
+ mt76_dma_kick_queue(dev, q);
spin_unlock_bh(&q->lock);
return 0;
@@ -969,7 +982,7 @@ mt76_dma_rx_process(struct mt76_dev *dev, struct mt76_queue *q, int budget)
if ((q->flags & MT_QFLAG_WED_RRO_EN) ||
(IS_ENABLED(CONFIG_NET_MEDIATEK_SOC_WED) &&
mt76_queue_is_wed_tx_free(q))) {
- dma_idx = Q_READ(q, dma_idx);
+ dma_idx = mt76_dma_read_dma_idx(q, q->tail);
check_ddone = true;
}
@@ -979,7 +992,7 @@ mt76_dma_rx_process(struct mt76_dev *dev, struct mt76_queue *q, int budget)
if (check_ddone) {
if (q->tail == dma_idx)
- dma_idx = Q_READ(q, dma_idx);
+ dma_idx = mt76_dma_read_dma_idx(q, q->tail);
if (q->tail == dma_idx)
break;
diff --git a/drivers/net/wireless/mediatek/mt76/mcu.c b/drivers/net/wireless/mediatek/mt76/mcu.c
index 65d4c2adb5386..951781dcf0ade 100644
--- a/drivers/net/wireless/mediatek/mt76/mcu.c
+++ b/drivers/net/wireless/mediatek/mt76/mcu.c
@@ -78,15 +78,19 @@ int mt76_mcu_skb_send_and_get_msg(struct mt76_dev *dev, struct sk_buff *skb,
unsigned long expires;
int ret, seq;
- if (mt76_is_sdio(dev))
- if (test_bit(MT76_RESET, &dev->phy.state) && atomic_read(&dev->bus_hung))
- return -EIO;
-
if (ret_skb)
*ret_skb = NULL;
mutex_lock(&dev->mcu.mutex);
+ if ((mt76_is_mmio(dev) && atomic_read(&dev->bus_hung)) ||
+ (mt76_is_sdio(dev) && test_bit(MT76_RESET, &dev->phy.state) &&
+ atomic_read(&dev->bus_hung))) {
+ orig_skb = skb;
+ ret = -EIO;
+ goto out;
+ }
+
if (dev->mcu_ops->mcu_skb_prepare_msg) {
orig_skb = skb;
ret = dev->mcu_ops->mcu_skb_prepare_msg(dev, skb, cmd, &seq);
diff --git a/drivers/net/wireless/mediatek/mt76/mt76_connac.h b/drivers/net/wireless/mediatek/mt76/mt76_connac.h
index 670f59f55605a..d504bf0c5f168 100644
--- a/drivers/net/wireless/mediatek/mt76/mt76_connac.h
+++ b/drivers/net/wireless/mediatek/mt76/mt76_connac.h
@@ -48,6 +48,11 @@ enum rx_pkt_type {
#define MT_TXD_LEN_MSDU_LAST BIT(14)
#define MT_TXD_LEN_AMSDU_LAST BIT(15)
+/* PCIE part */
+#define PCIE_AER_UNC_STATUS_OFFSET 0x204
+#define PCIE_AER_UNC_MASK_OFFSET 0x208
+#define PCIE_AER_CO_STATUS_OFFSET 0x210
+
enum {
CMD_CBW_20MHZ = IEEE80211_STA_RX_BW_20,
CMD_CBW_40MHZ = IEEE80211_STA_RX_BW_40,
diff --git a/drivers/net/wireless/mediatek/mt76/mt7921/mac.c b/drivers/net/wireless/mediatek/mt76/mt7921/mac.c
index 251a9a1f664d5..0d48dbb2354f3 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7921/mac.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7921/mac.c
@@ -673,6 +673,9 @@ void mt7921_mac_reset_work(struct work_struct *work)
cancel_work_sync(&pm->wake_work);
for (i = 0; i < 10; i++) {
+ if (atomic_read(&dev->mt76.bus_hung))
+ return;
+
mutex_lock(&dev->mt76.mutex);
ret = mt792x_dev_reset(dev);
mutex_unlock(&dev->mt76.mutex);
diff --git a/drivers/net/wireless/mediatek/mt76/mt7921/pci.c b/drivers/net/wireless/mediatek/mt76/mt7921/pci.c
index a0c9df3c2cc75..85caa2fbb78f0 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7921/pci.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7921/pci.c
@@ -554,6 +554,108 @@ static int mt7921_pci_resume(struct device *device)
return err;
}
+static u32 mt7921_aer_rr(struct mt76_dev *mdev, u32 offset)
+{
+ return 0;
+}
+
+static void mt7921_aer_wr(struct mt76_dev *mdev, u32 offset, u32 val)
+{
+ ;
+}
+
+static u32 mt791_aer_rmw(struct mt76_dev *mdev, u32 offset, u32 mask, u32 val)
+{
+ return 0;
+}
+
+static const struct mt76_bus_ops mt7921_aer_bus_hung_ops = {
+ .rr = mt7921_aer_rr,
+ .wr = mt7921_aer_wr,
+ .rmw = mt791_aer_rmw,
+ .type = MT76_BUS_MMIO
+};
+
+static void mt7921_pci_set_aer_bus_hung_ops(struct mt792x_dev *dev)
+{
+ if (READ_ONCE(dev->mt76.bus) == &mt7921_aer_bus_hung_ops)
+ return;
+
+ atomic_set(&dev->mt76.bus_hung, true);
+ WRITE_ONCE(dev->mt76.bus, &mt7921_aer_bus_hung_ops);
+}
+
+static pci_ers_result_t mt7921_error_detected(struct pci_dev *pdev,
+ pci_channel_state_t state)
+{
+ struct mt76_dev *mdev = pci_get_drvdata(pdev);
+ struct mt792x_dev *dev = container_of(mdev, struct mt792x_dev, mt76);
+ u32 aer_unc_val = 0, aer_co_val = 0;
+
+ dev_err(mdev->dev, "PCIE error detect state: %d\n", state);
+
+ /* Clear SW IRQ tasklet first */
+ tasklet_kill(&mdev->irq_tasklet);
+
+ if (state == pci_channel_io_perm_failure) {
+ mt7921_pci_set_aer_bus_hung_ops(dev);
+ return PCI_ERS_RESULT_DISCONNECT;
+ }
+
+ pci_read_config_dword(pdev, PCIE_AER_UNC_STATUS_OFFSET, &aer_unc_val);
+ pci_read_config_dword(pdev, PCIE_AER_CO_STATUS_OFFSET, &aer_co_val);
+
+ dev_warn(mdev->dev, "PCIE_AER_UNC_STATUS_OFFSET: 0x%x\n", aer_unc_val);
+ dev_warn(mdev->dev, "PCIE_AER_CO_STATUS_OFFSET: 0x%x\n", aer_co_val);
+
+ /**
+ * Due to this error is from link error and this AER is un-correctable,
+ * so can't covered by device
+ **/
+ if (aer_unc_val != 0) {
+ mt7921_pci_set_aer_bus_hung_ops(dev);
+ return PCI_ERS_RESULT_DISCONNECT;
+ }
+
+ /**
+ * Try to recover it when state is pci_channel_io_frozen or
+ * AER is correctable error
+ **/
+ if (state == pci_channel_io_frozen || aer_co_val != 0) {
+ /* Disable PCIE activity first. */
+ pci_disable_device(pdev);
+ return PCI_ERS_RESULT_NEED_RESET;
+ }
+
+ return PCI_ERS_RESULT_NONE;
+}
+
+static pci_ers_result_t mt7921_slot_reset(struct pci_dev *pdev)
+{
+ struct mt76_dev *mdev = pci_get_drvdata(pdev);
+ int ret = 0;
+
+ ret = pci_enable_device_mem(pdev);
+
+ if (ret) {
+ dev_err(mdev->dev, "pci_enable_device_mem failed: %d\n", ret);
+ return PCI_ERS_RESULT_DISCONNECT;
+ }
+
+ pci_set_master(pdev);
+ pci_restore_state(pdev);
+ pci_save_state(pdev);
+ /* Also try do the vendor reset to let it more clear. */
+ mt792x_reset(mdev);
+
+ return PCI_ERS_RESULT_RECOVERED;
+}
+
+static const struct pci_error_handlers mt7921_err_handler = {
+ .error_detected = mt7921_error_detected,
+ .slot_reset = mt7921_slot_reset,
+};
+
static void mt7921_pci_shutdown(struct pci_dev *pdev)
{
mt7921_pci_remove(pdev);
@@ -568,6 +670,7 @@ static struct pci_driver mt7921_pci_driver = {
.remove = mt7921_pci_remove,
.shutdown = mt7921_pci_shutdown,
.driver.pm = pm_sleep_ptr(&mt7921_pm_ops),
+ .err_handler = &mt7921_err_handler,
};
module_pci_driver(mt7921_pci_driver);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0733/1518] wifi: mt76: mt7925: update clc before setting sar power table
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (731 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0732/1518] wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0734/1518] wifi: mt76: mt7925: fix msg len mismatch between driver and firmware Greg Kroah-Hartman
` (265 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jared.Huang, Felix Fietkau,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jared.Huang <jared.huang@mediatek.com>
[ Upstream commit 8a27c5c764040fbc990cc416a927b1d7eadf559f ]
Fix the power table update sequence to ensure CLC is loaded before
setting SAR power table.
The firmware requires CLC baseline to be established first
to properly calculate the final power limit as min(clc_limit, rate_limit,sar_limit).
Fixes: 9557b6fe0c8b ("wifi: mt76: mt7925: refine the txpower initialization flow")
Signed-off-by: Jared.Huang <jared.huang@mediatek.com>
Link: https://patch.msgid.link/20260617071305.1808394-1-jb.tsai@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7925/main.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7925/main.c b/drivers/net/wireless/mediatek/mt76/mt7925/main.c
index 8ef0d981adc9a..cb1046c59cf6c 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7925/main.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7925/main.c
@@ -1688,9 +1688,15 @@ static int mt7925_set_sar_specs(struct ieee80211_hw *hw,
int err;
mt792x_mutex_acquire(dev);
+ err = mt7925_mcu_set_clc(dev, dev->mt76.alpha2,
+ dev->country_ie_env);
+ if (err < 0)
+ goto out;
+
err = mt7925_set_tx_sar_pwr(hw, sar);
- mt792x_mutex_release(dev);
+out:
+ mt792x_mutex_release(dev);
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0734/1518] wifi: mt76: mt7925: fix msg len mismatch between driver and firmware
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (732 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0733/1518] wifi: mt76: mt7925: update clc before setting sar power table Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0735/1518] wifi: mt76: mt792x: Fix memory leak in SDIO TX path Greg Kroah-Hartman
` (264 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Jared.Huang, Felix Fietkau,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jared.Huang <jared.huang@mediatek.com>
[ Upstream commit 9ddb7487aa7cccb6e1880b4151ab5895109eb8d6 ]
The mt7925_tx_power_limit_tlv struct begins with a 4-byte rsv[] field
that acts as a UNI command header prefix. The firmware dispatcher did
not use the 4-byte rsv[] and will only check the payloads after the
4-byte rsv[] As a result, the total message length minus the 4-byte
prefix. Fix this by setting len to msg_len - 4.
Fixes: ccb186326bb6 ("wifi: mt76: mt7925: fix incorrect length field in txpower command")
Signed-off-by: Jared.Huang <jared.huang@mediatek.com>
Link: https://patch.msgid.link/20260617071320.1808499-1-jb.tsai@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7925/mcu.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7925/mcu.c b/drivers/net/wireless/mediatek/mt76/mt7925/mcu.c
index bc19e800b41c9..d11c7ff14bc8f 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7925/mcu.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7925/mcu.c
@@ -3733,7 +3733,7 @@ mt7925_mcu_rate_txpower_band(struct mt76_phy *phy,
memcpy(tx_power_tlv->alpha2, dev->alpha2, sizeof(dev->alpha2));
tx_power_tlv->n_chan = num_ch;
tx_power_tlv->tag = cpu_to_le16(0x1);
- tx_power_tlv->len = cpu_to_le16(msg_len);
+ tx_power_tlv->len = cpu_to_le16(msg_len - 4);
switch (band) {
case NL80211_BAND_2GHZ:
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0735/1518] wifi: mt76: mt792x: Fix memory leak in SDIO TX path
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (733 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0734/1518] wifi: mt76: mt7925: fix msg len mismatch between driver and firmware Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0736/1518] wifi: mt76: mt7996: fix EAPOL source BSS for non-MLD stations Greg Kroah-Hartman
` (263 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Eason Lai, Felix Fietkau,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Eason Lai <Eason.Lai@mediatek.com>
[ Upstream commit 808f2767d4217a5b96f674288573b9b89d432eed ]
When tx_prepare_skb() returns an error in the SDIO TX path, the
skb is not freed, leading to a memory leak. This can occur when
zero-length frames (such as WNM NULL frames) are dropped to prevent
potential hardware TX hangs.
Fix this by properly releasing the skb with ieee80211_tx_status_ext()
when tx_prepare_skb() fails.
Fixes: b747fa343817 ("mt76: mt7915: drop zero-length packet to avoid Tx hang")
Signed-off-by: Eason Lai <Eason.Lai@mediatek.com>
Link: https://patch.msgid.link/20260703005945.2244533-1-eason.lai@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/sdio.c | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/sdio.c b/drivers/net/wireless/mediatek/mt76/sdio.c
index 8e9576747052d..e4c3dcc34f68a 100644
--- a/drivers/net/wireless/mediatek/mt76/sdio.c
+++ b/drivers/net/wireless/mediatek/mt76/sdio.c
@@ -519,6 +519,10 @@ mt76s_tx_queue_skb(struct mt76_phy *phy, struct mt76_queue *q,
enum mt76_txq_id qid, struct sk_buff *skb,
struct mt76_wcid *wcid, struct ieee80211_sta *sta)
{
+ struct ieee80211_tx_status status = {
+ .sta = sta,
+ };
+
struct mt76_tx_info tx_info = {
.skb = skb,
};
@@ -531,8 +535,13 @@ mt76s_tx_queue_skb(struct mt76_phy *phy, struct mt76_queue *q,
skb->prev = skb->next = NULL;
err = dev->drv->tx_prepare_skb(dev, NULL, qid, wcid, sta, &tx_info);
- if (err < 0)
+ if (err < 0) {
+ status.skb = tx_info.skb;
+ spin_lock_bh(&dev->rx_lock);
+ ieee80211_tx_status_ext(dev->hw, &status);
+ spin_unlock_bh(&dev->rx_lock);
return err;
+ }
q->entry[q->head].skb = tx_info.skb;
q->entry[q->head].buf_sz = len;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0736/1518] wifi: mt76: mt7996: fix EAPOL source BSS for non-MLD stations
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (734 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0735/1518] wifi: mt76: mt792x: Fix memory leak in SDIO TX path Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0737/1518] wifi: mt76: mt7996: fix capability of EHT-MCS 15 in MRU Greg Kroah-Hartman
` (262 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Chad Monroe, Felix Fietkau,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chad Monroe <chad@monroe.io>
[ Upstream commit 6bb5066cfcd4296ac5e0b6872f43f96a43bfe566 ]
A non-MLD station's EAPOL and data frames are tagged with link_id ==
IEEE80211_LINK_UNSPECIFIED, which now skips the per-link lookup in
mt7996_mac_write_txwi() and leaves omac_idx/band_idx/wmm_idx at slot
0. When the radio also runs AP VAPs the station's omac is non-zero
(get_omac_idx() prefers HW BSSID slots 1-3), so its EAPOL frames
egress from the wrong BSS and the 4-way handshake times out even
though association succeeds.
In mt7996_tx_prepare_skb(), resolve the link from the peer wcid when
link_id is UNSPECIFIED and the wcid is not the global entry, restoring
the pre-MLO behaviour for station traffic.
Fixes: 729c83a3330c ("wifi: mt76: mt7996: fix reading zeroed info->control.flags after mt76_tx_status_skb_add()")
Signed-off-by: Chad Monroe <chad@monroe.io>
Link: https://patch.msgid.link/20260721185333.2419297-1-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7996/mac.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/mac.c b/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
index e55bb232bdebc..60687064f7368 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
@@ -1069,6 +1069,11 @@ int mt7996_tx_prepare_skb(struct mt76_dev *mdev, void *txwi_ptr,
IEEE80211_TX_CTRL_MLO_LINK);
}
+ /* non-MLD frames are LINK_UNSPECIFIED; use the wcid's own link */
+ if (link_id == IEEE80211_LINK_UNSPECIFIED &&
+ wcid != &dev->mt76.global_wcid)
+ link_id = wcid->link_id;
+
if (link_id != wcid->link_id && link_id != IEEE80211_LINK_UNSPECIFIED) {
if (msta) {
struct mt7996_sta_link *msta_link =
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0737/1518] wifi: mt76: mt7996: fix capability of EHT-MCS 15 in MRU
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (735 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0736/1518] wifi: mt76: mt7996: fix EAPOL source BSS for non-MLD stations Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0738/1518] wifi: mt76: fix RX data queuing of RRO 3.0 Greg Kroah-Hartman
` (261 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Shayne Chen, Felix Fietkau,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shayne Chen <shayne.chen@mediatek.com>
[ Upstream commit 29e889c4ada83c69d10a3937f5ae2934306e2e3d ]
According to the definition in IEEE Std 802.11be-2024, Table 9-417r:
- If 80 MHz is not supported, bit 1-3 are set to 0.
- If 160 MHz is not supported, bit 2-3 are set to 0.
- If 320 MHz is not supported, bit 3 is set to 0.
Fixes: 348533eb968d ("wifi: mt76: mt7996: add EHT capability init")
Signed-off-by: Shayne Chen <shayne.chen@mediatek.com>
Link: https://patch.msgid.link/20260313062150.3165433-2-shayne.chen@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7996/init.c | 16 ++++++++++------
1 file changed, 10 insertions(+), 6 deletions(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/init.c b/drivers/net/wireless/mediatek/mt76/mt7996/init.c
index efbd46d649017..462322896b474 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/init.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/init.c
@@ -1502,7 +1502,6 @@ mt7996_init_eht_caps(struct mt7996_phy *phy, enum nl80211_band band,
struct ieee80211_sta_eht_cap *eht_cap = &data->eht_cap;
struct ieee80211_eht_cap_elem_fixed *eht_cap_elem = &eht_cap->eht_cap_elem;
struct ieee80211_eht_mcs_nss_supp *eht_nss = &eht_cap->eht_mcs_nss_supp;
- enum nl80211_chan_width width = phy->mt76->chandef.width;
int nss = hweight8(phy->mt76->antenna_mask);
int sts = hweight16(phy->mt76->chainmask);
u8 val;
@@ -1578,11 +1577,16 @@ mt7996_init_eht_caps(struct mt7996_phy *phy, enum nl80211_band band,
u8_encode_bits(u8_get_bits(1, GENMASK(1, 0)),
IEEE80211_EHT_PHY_CAP5_MAX_NUM_SUPP_EHT_LTF_MASK);
- val = width == NL80211_CHAN_WIDTH_320 ? 0xf :
- width == NL80211_CHAN_WIDTH_160 ? 0x7 :
- width == NL80211_CHAN_WIDTH_80 ? 0x3 : 0x1;
- eht_cap_elem->phy_cap_info[6] =
- u8_encode_bits(val, IEEE80211_EHT_PHY_CAP6_MCS15_SUPP_MASK);
+ eht_cap_elem->phy_cap_info[6] = IEEE80211_EHT_PHY_CAP6_MCS15_SUPP_MASK;
+ if (band != NL80211_BAND_6GHZ) {
+ eht_cap_elem->phy_cap_info[6] &=
+ ~IEEE80211_EHT_PHY_CAP6_MCS15_SUPP_320MHZ;
+
+ if (band != NL80211_BAND_5GHZ)
+ eht_cap_elem->phy_cap_info[6] &=
+ ~(IEEE80211_EHT_PHY_CAP6_MCS15_SUPP_160MHZ |
+ IEEE80211_EHT_PHY_CAP6_MCS15_SUPP_80MHZ);
+ }
val = u8_encode_bits(nss, IEEE80211_EHT_MCS_NSS_RX) |
u8_encode_bits(nss, IEEE80211_EHT_MCS_NSS_TX);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0738/1518] wifi: mt76: fix RX data queuing of RRO 3.0
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (736 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0737/1518] wifi: mt76: mt7996: fix capability of EHT-MCS 15 in MRU Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0739/1518] wifi: mt76: mt7996: support fixed rate for link station Greg Kroah-Hartman
` (260 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rex Lu, Shayne Chen, Felix Fietkau,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rex Lu <rex.lu@mediatek.com>
[ Upstream commit 86897f106669c07eea4c34b54c3268d448d41426 ]
For RRO 3.0, RX data released from a RRO data queue should be put to
the indicator queue. The frames are processed and completed in the
context of the indicator queue NAPI, which only polls skbs queued on
the MT_RXQ_RRO_IND list; frames queued under the data queue id are
left sitting on that list until the data queue NAPI happens to run,
stalling and reordering RX data.
Fixes: b1e58e137b61 ("wifi: mt76: mt7996: Introduce RRO MSDU callbacks")
Signed-off-by: Rex Lu <rex.lu@mediatek.com>
Signed-off-by: Shayne Chen <shayne.chen@mediatek.com>
Link: https://patch.msgid.link/20260722082610.2699628-1-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mac80211.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/drivers/net/wireless/mediatek/mt76/mac80211.c b/drivers/net/wireless/mediatek/mt76/mac80211.c
index 030e9103283f3..2d8cd627ef4c6 100644
--- a/drivers/net/wireless/mediatek/mt76/mac80211.c
+++ b/drivers/net/wireless/mediatek/mt76/mac80211.c
@@ -886,6 +886,7 @@ static void mt76_rx_release_amsdu(struct mt76_phy *phy, enum mt76_rxq_id q)
struct sk_buff *skb = phy->rx_amsdu[q].head;
struct mt76_rx_status *status = (struct mt76_rx_status *)skb->cb;
struct mt76_dev *dev = phy->dev;
+ struct mt76_queue *rxq = &dev->q_rx[q];
phy->rx_amsdu[q].head = NULL;
phy->rx_amsdu[q].tail = NULL;
@@ -914,6 +915,13 @@ static void mt76_rx_release_amsdu(struct mt76_phy *phy, enum mt76_rxq_id q)
return;
}
}
+
+ /* RRO 3.0 data queue skbs are processed and completed in the context
+ * of the indicator queue NAPI, which only polls its own skb list
+ */
+ if (mt76_queue_is_wed_rro_data(rxq) && dev->hwrro_mode == MT76_HWRRO_V3)
+ q = MT_RXQ_RRO_IND;
+
__skb_queue_tail(&dev->rx_skb[q], skb);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0739/1518] wifi: mt76: mt7996: support fixed rate for link station
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (737 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0738/1518] wifi: mt76: fix RX data queuing of RRO 3.0 Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0740/1518] wifi: mt76: mt7996: set specific BSSINFO and STAREC commands after channel switch Greg Kroah-Hartman
` (259 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Howard Hsu, Shayne Chen,
Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shayne Chen <shayne.chen@mediatek.com>
[ Upstream commit feb06d4556203cd27cf3fa31147d43f28f329653 ]
Introduce mt7996_link_sta_add_debugfs() to extend fixed rate support for
MLO link station.
Co-developed-by: Howard Hsu <howard-yh.hsu@mediatek.com>
Signed-off-by: Howard Hsu <howard-yh.hsu@mediatek.com>
Signed-off-by: Shayne Chen <shayne.chen@mediatek.com>
Link: https://patch.msgid.link/20251106064203.1000505-4-shayne.chen@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Stable-dep-of: ce35ecffc96e ("wifi: mt76: mt7996: fix MLD ID in MAC TXD and HIF TXP")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../wireless/mediatek/mt76/mt7996/debugfs.c | 72 +++++++++++--------
.../net/wireless/mediatek/mt76/mt7996/main.c | 1 +
.../wireless/mediatek/mt76/mt7996/mt7996.h | 3 +
3 files changed, 48 insertions(+), 28 deletions(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/debugfs.c b/drivers/net/wireless/mediatek/mt76/mt7996/debugfs.c
index 0ab827f52fd7d..0526fa1c26ad2 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/debugfs.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/debugfs.c
@@ -953,16 +953,34 @@ bool mt7996_debugfs_rx_log(struct mt7996_dev *dev, const void *data, int len)
#ifdef CONFIG_MAC80211_DEBUGFS
/** per-station debugfs **/
-static ssize_t mt7996_sta_fixed_rate_set(struct file *file,
- const char __user *user_buf,
- size_t count, loff_t *ppos)
+static int
+mt7996_queues_show(struct seq_file *s, void *data)
+{
+ struct ieee80211_sta *sta = s->private;
+
+ mt7996_sta_hw_queue_read(s, sta);
+
+ return 0;
+}
+
+DEFINE_SHOW_ATTRIBUTE(mt7996_queues);
+
+void mt7996_sta_add_debugfs(struct ieee80211_hw *hw, struct ieee80211_vif *vif,
+ struct ieee80211_sta *sta, struct dentry *dir)
+{
+ debugfs_create_file("hw-queues", 0400, dir, sta, &mt7996_queues_fops);
+}
+
+static ssize_t mt7996_link_sta_fixed_rate_set(struct file *file,
+ const char __user *user_buf,
+ size_t count, loff_t *ppos)
{
#define SHORT_PREAMBLE 0
#define LONG_PREAMBLE 1
- struct ieee80211_sta *sta = file->private_data;
- struct mt7996_sta *msta = (struct mt7996_sta *)sta->drv_priv;
+ struct ieee80211_link_sta *link_sta = file->private_data;
+ struct mt7996_sta *msta = (struct mt7996_sta *)link_sta->sta->drv_priv;
struct mt7996_dev *dev = msta->vif->deflink.phy->dev;
- struct mt7996_sta_link *msta_link = &msta->deflink;
+ struct mt7996_sta_link *msta_link;
struct ra_rate phy = {};
char buf[100];
int ret;
@@ -981,12 +999,13 @@ static ssize_t mt7996_sta_fixed_rate_set(struct file *file,
/* mode - cck: 0, ofdm: 1, ht: 2, gf: 3, vht: 4, he_su: 8, he_er: 9 EHT: 15
* bw - bw20: 0, bw40: 1, bw80: 2, bw160: 3, BW320: 4
- * nss - vht: 1~4, he: 1~4, eht: 1~4, others: ignore
* mcs - cck: 0~4, ofdm: 0~7, ht: 0~32, vht: 0~9, he_su: 0~11, he_er: 0~2, eht: 0~13
+ * nss - vht: 1~4, he: 1~4, eht: 1~4, others: ignore
* gi - (ht/vht) lgi: 0, sgi: 1; (he) 0.8us: 0, 1.6us: 1, 3.2us: 2
* preamble - short: 1, long: 0
- * ldpc - off: 0, on: 1
* stbc - off: 0, on: 1
+ * ldpc - off: 0, on: 1
+ * spe - off: 0, on: 1
* ltf - 1xltf: 0, 2xltf: 1, 4xltf: 2
*/
if (sscanf(buf, "%hhu %hhu %hhu %hhu %hu %hhu %hhu %hhu %hhu %hu",
@@ -994,9 +1013,16 @@ static ssize_t mt7996_sta_fixed_rate_set(struct file *file,
&phy.preamble, &phy.stbc, &phy.ldpc, &phy.spe, <f) != 10) {
dev_warn(dev->mt76.dev,
"format: Mode BW MCS NSS GI Preamble STBC LDPC SPE ltf\n");
- goto out;
+ return -EINVAL;
}
+ mutex_lock(&dev->mt76.mutex);
+
+ msta_link = mt76_dereference(msta->link[link_sta->link_id], &dev->mt76);
+ if (!msta_link) {
+ ret = -EINVAL;
+ goto out;
+ }
phy.wlan_idx = cpu_to_le16(msta_link->wcid.idx);
phy.gi = cpu_to_le16(gi);
phy.ltf = cpu_to_le16(ltf);
@@ -1005,36 +1031,26 @@ static ssize_t mt7996_sta_fixed_rate_set(struct file *file,
ret = mt7996_mcu_set_fixed_rate_ctrl(dev, &phy, 0);
if (ret)
- return -EFAULT;
+ goto out;
+ ret = count;
out:
- return count;
+ mutex_unlock(&dev->mt76.mutex);
+ return ret;
}
static const struct file_operations fops_fixed_rate = {
- .write = mt7996_sta_fixed_rate_set,
+ .write = mt7996_link_sta_fixed_rate_set,
.open = simple_open,
.owner = THIS_MODULE,
.llseek = default_llseek,
};
-static int
-mt7996_queues_show(struct seq_file *s, void *data)
-{
- struct ieee80211_sta *sta = s->private;
-
- mt7996_sta_hw_queue_read(s, sta);
-
- return 0;
-}
-
-DEFINE_SHOW_ATTRIBUTE(mt7996_queues);
-
-void mt7996_sta_add_debugfs(struct ieee80211_hw *hw, struct ieee80211_vif *vif,
- struct ieee80211_sta *sta, struct dentry *dir)
+void mt7996_link_sta_add_debugfs(struct ieee80211_hw *hw, struct ieee80211_vif *vif,
+ struct ieee80211_link_sta *link_sta,
+ struct dentry *dir)
{
- debugfs_create_file("fixed_rate", 0600, dir, sta, &fops_fixed_rate);
- debugfs_create_file("hw-queues", 0400, dir, sta, &mt7996_queues_fops);
+ debugfs_create_file("fixed_rate", 0600, dir, link_sta, &fops_fixed_rate);
}
#endif
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/main.c b/drivers/net/wireless/mediatek/mt76/mt7996/main.c
index 20da0c10669a9..fd4e9112cccc5 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/main.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/main.c
@@ -2371,6 +2371,7 @@ const struct ieee80211_ops mt7996_ops = {
.twt_teardown_request = mt7996_twt_teardown_request,
#ifdef CONFIG_MAC80211_DEBUGFS
.sta_add_debugfs = mt7996_sta_add_debugfs,
+ .link_sta_add_debugfs = mt7996_link_sta_add_debugfs,
#endif
.set_radar_background = mt7996_set_radar_background,
#ifdef CONFIG_NET_MEDIATEK_SOC_WED
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/mt7996.h b/drivers/net/wireless/mediatek/mt76/mt7996/mt7996.h
index b8ffa42c5a1da..9f46d39e1e2cf 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mt7996.h
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mt7996.h
@@ -867,6 +867,9 @@ int mt7996_mcu_cp_support(struct mt7996_dev *dev, u8 mode);
#ifdef CONFIG_MAC80211_DEBUGFS
void mt7996_sta_add_debugfs(struct ieee80211_hw *hw, struct ieee80211_vif *vif,
struct ieee80211_sta *sta, struct dentry *dir);
+void mt7996_link_sta_add_debugfs(struct ieee80211_hw *hw, struct ieee80211_vif *vif,
+ struct ieee80211_link_sta *link_sta,
+ struct dentry *dir);
#endif
int mt7996_mmio_wed_init(struct mt7996_dev *dev, void *pdev_ptr,
bool hif2, int *irq);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0740/1518] wifi: mt76: mt7996: set specific BSSINFO and STAREC commands after channel switch
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (738 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0739/1518] wifi: mt76: mt7996: support fixed rate for link station Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0741/1518] wifi: mt76: mt7996: fix out-of-bounds array access during hardware restart Greg Kroah-Hartman
` (258 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shayne Chen, StanleyYP Wang,
Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: StanleyYP Wang <StanleyYP.Wang@mediatek.com>
[ Upstream commit 7247037a016ed4bc8a50507d74d0bae98409ae3f ]
After channel switch, some tags of BSSINFO (rfch) and STAREC (bfer,
rate_ctrl) commands should also be updated. Otherwise, a BSS might not be
able to transmit with its peer using correct bandwidth.
Co-developed-by: Shayne Chen <shayne.chen@mediatek.com>
Signed-off-by: Shayne Chen <shayne.chen@mediatek.com>
Signed-off-by: StanleyYP Wang <StanleyYP.Wang@mediatek.com>
Link: https://patch.msgid.link/20251215063728.3013365-3-shayne.chen@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Stable-dep-of: ce35ecffc96e ("wifi: mt76: mt7996: fix MLD ID in MAC TXD and HIF TXP")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../net/wireless/mediatek/mt76/mt7996/main.c | 14 ++++-
.../net/wireless/mediatek/mt76/mt7996/mcu.c | 59 +++++++++++++++++++
.../wireless/mediatek/mt76/mt7996/mt7996.h | 3 +
3 files changed, 75 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/main.c b/drivers/net/wireless/mediatek/mt76/mt7996/main.c
index fd4e9112cccc5..d363f9022c4a6 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/main.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/main.c
@@ -950,12 +950,24 @@ mt7996_post_channel_switch(struct ieee80211_hw *hw, struct ieee80211_vif *vif,
struct cfg80211_chan_def *chandef = &link_conf->chanreq.oper;
struct mt7996_dev *dev = mt7996_hw_dev(hw);
struct mt7996_phy *phy = mt7996_band_phy(dev, chandef->chan->band);
- int ret;
+ struct mt7996_vif_link *link;
+ int ret = -EINVAL;
mutex_lock(&dev->mt76.mutex);
+ link = mt7996_vif_conf_link(dev, vif, link_conf);
+ if (!link)
+ goto out;
+
+ ret = mt7996_mcu_update_bss_rfch(phy, link);
+ if (ret)
+ goto out;
+
+ ieee80211_iterate_stations_mtx(hw, mt7996_mcu_update_sta_rec_bw, link);
+
ret = mt7996_mcu_rdd_resume_tx(phy);
+out:
mutex_unlock(&dev->mt76.mutex);
return ret;
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/mcu.c b/drivers/net/wireless/mediatek/mt76/mt7996/mcu.c
index ee9716868c907..c591606c1765c 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mcu.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mcu.c
@@ -1177,6 +1177,22 @@ int mt7996_mcu_add_bss_info(struct mt7996_phy *phy, struct ieee80211_vif *vif,
MCU_WMWA_UNI_CMD(BSS_INFO_UPDATE), true);
}
+int mt7996_mcu_update_bss_rfch(struct mt7996_phy *phy, struct mt7996_vif_link *link)
+{
+ struct mt7996_dev *dev = phy->dev;
+ struct sk_buff *skb;
+
+ skb = __mt7996_mcu_alloc_bss_req(&dev->mt76, &link->mt76,
+ MT7996_BSS_UPDATE_MAX_SIZE);
+ if (IS_ERR(skb))
+ return PTR_ERR(skb);
+
+ mt7996_mcu_bss_rfch_tlv(skb, phy);
+
+ return mt76_mcu_skb_send_msg(&dev->mt76, skb,
+ MCU_WMWA_UNI_CMD(BSS_INFO_UPDATE), true);
+}
+
int mt7996_mcu_set_timing(struct mt7996_phy *phy, struct ieee80211_vif *vif,
struct ieee80211_bss_conf *link_conf)
{
@@ -2541,6 +2557,49 @@ int mt7996_mcu_teardown_mld_sta(struct mt7996_dev *dev,
MCU_WMWA_UNI_CMD(STA_REC_UPDATE), true);
}
+void mt7996_mcu_update_sta_rec_bw(void *data, struct ieee80211_sta *sta)
+{
+ struct mt7996_vif_link *link = (struct mt7996_vif_link *)data;
+ struct mt7996_sta *msta = (struct mt7996_sta *)sta->drv_priv;
+ struct mt7996_sta_link *msta_link;
+ struct mt7996_dev *dev;
+ struct ieee80211_bss_conf *link_conf;
+ struct ieee80211_link_sta *link_sta;
+ struct ieee80211_vif *vif;
+ struct sk_buff *skb;
+ int link_id;
+
+ if (link->mt76.mvif != &msta->vif->mt76)
+ return;
+
+ dev = link->phy->dev;
+ link_id = link->msta_link.wcid.link_id;
+ link_sta = link_sta_dereference_protected(sta, link_id);
+ if (!link_sta)
+ return;
+
+ msta_link = mt76_dereference(msta->link[link_id], &dev->mt76);
+ if (!msta_link)
+ return;
+
+ vif = container_of((void *)msta->vif, struct ieee80211_vif, drv_priv);
+ link_conf = link_conf_dereference_protected(vif, link_id);
+ if (!link_conf)
+ return;
+
+ skb = __mt76_connac_mcu_alloc_sta_req(&dev->mt76, &link->mt76,
+ &msta_link->wcid,
+ MT7996_STA_UPDATE_MAX_SIZE);
+ if (IS_ERR(skb))
+ return;
+
+ mt7996_mcu_sta_bfer_tlv(dev, skb, link_conf, link_sta, link);
+ mt7996_mcu_sta_rate_ctrl_tlv(skb, dev, vif, link_conf, link_sta, link);
+
+ mt76_mcu_skb_send_msg(&dev->mt76, skb,
+ MCU_WMWA_UNI_CMD(STA_REC_UPDATE), true);
+}
+
static int
mt7996_mcu_sta_key_tlv(struct mt76_dev *dev, struct mt76_wcid *wcid,
struct sk_buff *skb,
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/mt7996.h b/drivers/net/wireless/mediatek/mt76/mt7996/mt7996.h
index 9f46d39e1e2cf..26c04cd08caea 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mt7996.h
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mt7996.h
@@ -670,6 +670,8 @@ int mt7996_mcu_add_bss_info(struct mt7996_phy *phy, struct ieee80211_vif *vif,
struct ieee80211_bss_conf *link_conf,
struct mt76_vif_link *mlink,
struct mt7996_sta_link *msta_link, int enable);
+int mt7996_mcu_update_bss_rfch(struct mt7996_phy *phy,
+ struct mt7996_vif_link *link);
int mt7996_mcu_add_sta(struct mt7996_dev *dev,
struct ieee80211_bss_conf *link_conf,
struct ieee80211_link_sta *link_sta,
@@ -679,6 +681,7 @@ int mt7996_mcu_add_sta(struct mt7996_dev *dev,
int mt7996_mcu_teardown_mld_sta(struct mt7996_dev *dev,
struct mt7996_vif_link *link,
struct mt7996_sta_link *msta_link);
+void mt7996_mcu_update_sta_rec_bw(void *data, struct ieee80211_sta *sta);
int mt7996_mcu_add_tx_ba(struct mt7996_dev *dev,
struct ieee80211_ampdu_params *params,
struct ieee80211_vif *vif, bool enable);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0741/1518] wifi: mt76: mt7996: fix out-of-bounds array access during hardware restart
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (739 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0740/1518] wifi: mt76: mt7996: set specific BSSINFO and STAREC commands after channel switch Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0742/1518] wifi: mt76: mt7996: fix MLD ID in MAC TXD and HIF TXP Greg Kroah-Hartman
` (257 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Chad Monroe, Felix Fietkau,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit 7ec087fef32a88410488b764b0f5eef68e51175f ]
During hardware restart, link_id can be IEEE80211_LINK_UNSPECIFIED,
causing an out-of-bounds array access on msta->link[].
Add mt7996_sta_link() and mt7996_sta_link_protected() helper functions
for accessing sta links with proper RCU handling and bounds checking.
Use them for any sta link RCU access.
Reported-by: Chad Monroe <chad@monroe.io>
Link: https://patch.msgid.link/20260324154904.2555603-1-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Stable-dep-of: ce35ecffc96e ("wifi: mt76: mt7996: fix MLD ID in MAC TXD and HIF TXP")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../wireless/mediatek/mt76/mt7996/debugfs.c | 4 ++--
.../net/wireless/mediatek/mt76/mt7996/mac.c | 6 ++---
.../net/wireless/mediatek/mt76/mt7996/main.c | 17 +++++++-------
.../net/wireless/mediatek/mt76/mt7996/mcu.c | 22 +++++++++----------
.../wireless/mediatek/mt76/mt7996/mt7996.h | 19 ++++++++++++++++
5 files changed, 43 insertions(+), 25 deletions(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/debugfs.c b/drivers/net/wireless/mediatek/mt76/mt7996/debugfs.c
index 0526fa1c26ad2..1d8b8bec8e0e5 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/debugfs.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/debugfs.c
@@ -645,7 +645,7 @@ mt7996_sta_hw_queue_read(void *data, struct ieee80211_sta *sta)
if (!mlink)
continue;
- msta_link = rcu_dereference(msta->link[link_id]);
+ msta_link = mt7996_sta_link(msta, link_id);
if (!msta_link)
continue;
@@ -1018,7 +1018,7 @@ static ssize_t mt7996_link_sta_fixed_rate_set(struct file *file,
mutex_lock(&dev->mt76.mutex);
- msta_link = mt76_dereference(msta->link[link_sta->link_id], &dev->mt76);
+ msta_link = mt7996_sta_link_protected(dev, msta, link_sta->link_id);
if (!msta_link) {
ret = -EINVAL;
goto out;
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/mac.c b/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
index 60687064f7368..1b695823533d3 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
@@ -87,7 +87,7 @@ static struct mt76_wcid *mt7996_rx_get_wcid(struct mt7996_dev *dev,
if (mlink->band_idx != band_idx)
continue;
- msta_link = rcu_dereference(msta->link[i]);
+ msta_link = mt7996_sta_link(msta, i);
break;
}
@@ -1077,7 +1077,7 @@ int mt7996_tx_prepare_skb(struct mt76_dev *mdev, void *txwi_ptr,
if (link_id != wcid->link_id && link_id != IEEE80211_LINK_UNSPECIFIED) {
if (msta) {
struct mt7996_sta_link *msta_link =
- rcu_dereference(msta->link[link_id]);
+ mt7996_sta_link(msta, link_id);
if (msta_link)
wcid = &msta_link->wcid;
@@ -1413,7 +1413,7 @@ mt7996_mac_tx_free(struct mt7996_dev *dev, void *data, int len)
IEEE80211_MLD_MAX_NUM_LINKS) {
struct mt7996_sta_link *msta_link;
- msta_link = rcu_dereference(msta->link[id]);
+ msta_link = mt7996_sta_link(msta, id);
if (!msta_link)
continue;
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/main.c b/drivers/net/wireless/mediatek/mt76/mt7996/main.c
index d363f9022c4a6..58bc6f30ab772 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/main.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/main.c
@@ -207,8 +207,7 @@ mt7996_set_hw_key(struct ieee80211_hw *hw, enum set_key_cmd cmd,
struct mt7996_sta *msta;
msta = (struct mt7996_sta *)sta->drv_priv;
- msta_link = mt76_dereference(msta->link[link_id],
- &dev->mt76);
+ msta_link = mt7996_sta_link_protected(dev, msta, link_id);
if (!msta_link)
return 0;
@@ -1236,7 +1235,7 @@ mt7996_mac_sta_event(struct mt7996_dev *dev, struct ieee80211_vif *vif,
if (!link)
continue;
- msta_link = mt76_dereference(msta->link[link_id], &dev->mt76);
+ msta_link = mt7996_sta_link_protected(dev, msta, link_id);
if (!msta_link)
continue;
@@ -1426,7 +1425,7 @@ static void mt7996_tx(struct ieee80211_hw *hw,
if (msta) {
struct mt7996_sta_link *msta_link;
- msta_link = rcu_dereference(msta->link[link_id]);
+ msta_link = mt7996_sta_link(msta, link_id);
if (msta_link)
wcid = &msta_link->wcid;
}
@@ -1792,7 +1791,7 @@ static void mt7996_link_sta_rc_update(struct ieee80211_hw *hw,
rcu_read_lock();
- msta_link = rcu_dereference(msta->link[link_sta->link_id]);
+ msta_link = mt7996_sta_link(msta, link_sta->link_id);
if (msta_link) {
struct mt7996_dev *dev = mt7996_hw_dev(hw);
@@ -1813,7 +1812,7 @@ static void mt7996_sta_rate_ctrl_update(void *data, struct ieee80211_sta *sta)
if (msta->vif != mvif)
return;
- msta_link = rcu_dereference(msta->link[msta->deflink_id]);
+ msta_link = mt7996_sta_link(msta, msta->deflink_id);
if (msta_link)
mt7996_link_rate_ctrl_update(&changed, msta_link);
}
@@ -1862,7 +1861,7 @@ static void mt7996_sta_set_4addr(struct ieee80211_hw *hw,
if (!link)
continue;
- msta_link = mt76_dereference(msta->link[link_id], &dev->mt76);
+ msta_link = mt7996_sta_link_protected(dev, msta, link_id);
if (!msta_link)
continue;
@@ -1900,7 +1899,7 @@ static void mt7996_sta_set_decap_offload(struct ieee80211_hw *hw,
if (!link)
continue;
- msta_link = mt76_dereference(msta->link[link_id], &dev->mt76);
+ msta_link = mt7996_sta_link_protected(dev, msta, link_id);
if (!msta_link)
continue;
@@ -2242,7 +2241,7 @@ mt7996_net_fill_forward_path(struct ieee80211_hw *hw,
if (!mlink)
return -EIO;
- msta_link = rcu_dereference(msta->link[msta->deflink_id]);
+ msta_link = mt7996_sta_link(msta, msta->deflink_id);
if (!msta_link)
return -EIO;
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/mcu.c b/drivers/net/wireless/mediatek/mt76/mt7996/mcu.c
index c591606c1765c..5df5c3a2121f5 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mcu.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mcu.c
@@ -1063,7 +1063,7 @@ mt7996_mcu_bss_basic_tlv(struct sk_buff *skb,
struct mt7996_sta_link *msta_link;
int link_id = link_conf->link_id;
- msta_link = rcu_dereference(msta->link[link_id]);
+ msta_link = mt7996_sta_link(msta, link_id);
if (msta_link)
sta_wlan_idx = msta_link->wcid.idx;
}
@@ -1255,7 +1255,7 @@ int mt7996_mcu_add_tx_ba(struct mt7996_dev *dev,
struct mt7996_sta_link *msta_link;
struct mt7996_vif_link *link;
- msta_link = mt76_dereference(msta->link[link_id], &dev->mt76);
+ msta_link = mt7996_sta_link_protected(dev, msta, link_id);
if (!msta_link)
continue;
@@ -1289,7 +1289,7 @@ int mt7996_mcu_add_rx_ba(struct mt7996_dev *dev,
struct mt7996_sta_link *msta_link;
struct mt7996_vif_link *link;
- msta_link = mt76_dereference(msta->link[link_id], &dev->mt76);
+ msta_link = mt7996_sta_link_protected(dev, msta, link_id);
if (!msta_link)
continue;
@@ -2023,7 +2023,7 @@ int mt7996_mcu_set_fixed_field(struct mt7996_dev *dev, struct mt7996_sta *msta,
if (!mlink)
goto error_unlock;
- msta_link = rcu_dereference(msta->link[link_id]);
+ msta_link = mt7996_sta_link(msta, link_id);
if (!msta_link)
goto error_unlock;
@@ -2112,7 +2112,7 @@ mt7996_mcu_add_rate_ctrl_fixed(struct mt7996_dev *dev, struct mt7996_sta *msta,
if (!link)
goto error_unlock;
- msta_link = rcu_dereference(msta->link[link_id]);
+ msta_link = mt7996_sta_link(msta, link_id);
if (!msta_link)
goto error_unlock;
@@ -2319,7 +2319,7 @@ int mt7996_mcu_add_rate_ctrl(struct mt7996_dev *dev, struct mt7996_sta *msta,
if (!link)
goto error_unlock;
- msta_link = rcu_dereference(msta->link[link_id]);
+ msta_link = mt7996_sta_link(msta, link_id);
if (!msta_link)
goto error_unlock;
@@ -2408,7 +2408,7 @@ mt7996_mcu_sta_mld_setup_tlv(struct mt7996_dev *dev, struct sk_buff *skb,
unsigned int link_id;
struct tlv *tlv;
- msta_link = mt76_dereference(msta->link[msta->deflink_id], &dev->mt76);
+ msta_link = mt7996_sta_link_protected(dev, msta, msta->deflink_id);
if (!msta_link)
return;
@@ -2422,8 +2422,8 @@ mt7996_mcu_sta_mld_setup_tlv(struct mt7996_dev *dev, struct sk_buff *skb,
mld_setup->primary_id = cpu_to_le16(msta_link->wcid.idx);
if (nlinks > 1) {
- msta_link = mt76_dereference(msta->link[msta->seclink_id],
- &dev->mt76);
+ msta_link = mt7996_sta_link_protected(dev, msta,
+ msta->seclink_id);
if (!msta_link)
return;
}
@@ -2434,7 +2434,7 @@ mt7996_mcu_sta_mld_setup_tlv(struct mt7996_dev *dev, struct sk_buff *skb,
for_each_sta_active_link(vif, sta, link_sta, link_id) {
struct mt7996_vif_link *link;
- msta_link = mt76_dereference(msta->link[link_id], &dev->mt76);
+ msta_link = mt7996_sta_link_protected(dev, msta, link_id);
if (!msta_link)
continue;
@@ -2578,7 +2578,7 @@ void mt7996_mcu_update_sta_rec_bw(void *data, struct ieee80211_sta *sta)
if (!link_sta)
return;
- msta_link = mt76_dereference(msta->link[link_id], &dev->mt76);
+ msta_link = mt7996_sta_link_protected(dev, msta, link_id);
if (!msta_link)
return;
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/mt7996.h b/drivers/net/wireless/mediatek/mt76/mt7996/mt7996.h
index 26c04cd08caea..e1af2a2b24bda 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mt7996.h
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mt7996.h
@@ -618,6 +618,25 @@ mt7996_vif_conf_link(struct mt7996_dev *dev, struct ieee80211_vif *vif,
link_conf);
}
+static inline struct mt7996_sta_link *
+mt7996_sta_link(struct mt7996_sta *msta, u8 link_id)
+{
+ if (link_id >= IEEE80211_MLD_MAX_NUM_LINKS)
+ return NULL;
+
+ return rcu_dereference(msta->link[link_id]);
+}
+
+static inline struct mt7996_sta_link *
+mt7996_sta_link_protected(struct mt7996_dev *dev, struct mt7996_sta *msta,
+ u8 link_id)
+{
+ if (link_id >= IEEE80211_MLD_MAX_NUM_LINKS)
+ return NULL;
+
+ return mt76_dereference(msta->link[link_id], &dev->mt76);
+}
+
#define mt7996_for_each_phy(dev, phy) \
for (int __i = 0; __i < ARRAY_SIZE((dev)->radio_phy); __i++) \
if (((phy) = (dev)->radio_phy[__i]) != NULL)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0742/1518] wifi: mt76: mt7996: fix MLD ID in MAC TXD and HIF TXP
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (740 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0741/1518] wifi: mt76: mt7996: fix out-of-bounds array access during hardware restart Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0743/1518] wifi: mt76: fix non-AQL packet accounting for MLO stations Greg Kroah-Hartman
` (256 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Chiu, Felix Fietkau,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Peter Chiu <chui-hao.chiu@mediatek.com>
[ Upstream commit ce35ecffc96e6d097d27b6fe30677a2cfe2e0461 ]
Problem:
MCU command timeout while the firmware state is normal, and the
firmware keeps showing the error log "ERROR!! NO PAUSE...".
Root cause:
If the MLD_ID field in the TXD is neither the primary link id nor the
secondary link id, it may lead to a firmware busy loop when the third
link is in power saving mode.
Remap frames directed to a third link to the primary link wcid. Since
TX status events and txfree completions carry the wcid the firmware
saw, use the remapped wcid for packet id tracking and non-AQL packet
accounting as well, while the frame keeps its original link context
for addressing, band and OMAC selection.
Fixes: 85cd5534a3f2 ("wifi: mt76: mt7996: use correct link_id when filling TXD and TXP")
Signed-off-by: Peter Chiu <chui-hao.chiu@mediatek.com>
Link: https://patch.msgid.link/20260722082610.2699628-3-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../net/wireless/mediatek/mt76/mt7996/mac.c | 29 +++++++++++++++++++
.../net/wireless/mediatek/mt76/mt7996/main.c | 2 +-
.../wireless/mediatek/mt76/mt7996/mt7996.h | 1 +
3 files changed, 31 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/mac.c b/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
index 1b695823533d3..21b3e0b20888f 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
@@ -893,6 +893,33 @@ mt7996_mac_write_txwi_80211(struct mt7996_dev *dev, __le32 *txwi,
txwi[6] |= cpu_to_le32(MT_TXD6_DIS_MAT);
}
+/* The WLAN_IDX in the TXD and TXP must belong to the primary or secondary
+ * link of an MLD station; any other link id can make the firmware spin when
+ * that link is in powersave. Completion events carry the same index, so the
+ * wcid used for status tracking and accounting must match it
+ */
+struct mt76_wcid *mt7996_get_tx_wcid(struct mt76_wcid *wcid)
+{
+ struct mt7996_sta_link *msta_link;
+ struct mt7996_sta *msta;
+
+ if (!wcid->sta)
+ return wcid;
+
+ msta_link = container_of(wcid, struct mt7996_sta_link, wcid);
+ msta = msta_link->sta;
+
+ if (!msta || wcid->link_id == msta->seclink_id ||
+ wcid->link_id == msta->deflink_id)
+ return wcid;
+
+ msta_link = mt7996_sta_link(msta, msta->deflink_id);
+ if (msta_link)
+ return &msta_link->wcid;
+
+ return wcid;
+}
+
void mt7996_mac_write_txwi(struct mt7996_dev *dev, __le32 *txwi,
struct sk_buff *skb, struct mt76_wcid *wcid,
struct ieee80211_key_conf *key, int pid,
@@ -1130,6 +1157,8 @@ int mt7996_tx_prepare_skb(struct mt76_dev *mdev, void *txwi_ptr,
tx_info->buf[1].len, DMA_TO_DEVICE);
}
+ wcid = mt7996_get_tx_wcid(wcid);
+
pid = mt76_tx_status_skb_add(mdev, wcid, tx_info->skb);
memset(txwi_ptr, 0, MT_TXD_SIZE);
/* Transmit non qos data by 802.11 header and need to fill txd by host*/
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/main.c b/drivers/net/wireless/mediatek/mt76/mt7996/main.c
index 58bc6f30ab772..103851e011583 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/main.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/main.c
@@ -1429,7 +1429,7 @@ static void mt7996_tx(struct ieee80211_hw *hw,
if (msta_link)
wcid = &msta_link->wcid;
}
- mt76_tx(mphy, control->sta, wcid, skb);
+ mt76_tx(mphy, control->sta, mt7996_get_tx_wcid(wcid), skb);
unlock:
rcu_read_unlock();
}
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/mt7996.h b/drivers/net/wireless/mediatek/mt76/mt7996/mt7996.h
index e1af2a2b24bda..e371b2f174e58 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mt7996.h
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mt7996.h
@@ -832,6 +832,7 @@ bool mt7996_mac_wtbl_update(struct mt7996_dev *dev, int idx, u32 mask);
void mt7996_mac_reset_counters(struct mt7996_phy *phy);
void mt7996_mac_cca_stats_reset(struct mt7996_phy *phy);
void mt7996_mac_enable_nf(struct mt7996_dev *dev, u8 band);
+struct mt76_wcid *mt7996_get_tx_wcid(struct mt76_wcid *wcid);
void mt7996_mac_write_txwi(struct mt7996_dev *dev, __le32 *txwi,
struct sk_buff *skb, struct mt76_wcid *wcid,
struct ieee80211_key_conf *key, int pid,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0743/1518] wifi: mt76: fix non-AQL packet accounting for MLO stations
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (741 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0742/1518] wifi: mt76: mt7996: fix MLD ID in MAC TXD and HIF TXP Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0744/1518] wifi: mt76: assign link_id when sending probe request during scan Greg Kroah-Hartman
` (255 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael-CY Lee, Felix Fietkau,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michael-CY Lee <michael-cy.lee@mediatek.com>
[ Upstream commit 8ae659743ba936b22ecb4620815887728e2820d6 ]
__mt76_tx_queue_skb() overrides the wcid passed by the driver with
sta->drv_priv, so the wcid might incorrectly be changed after TX,
causing wcid->non_aql_packets to be counted on the wrong wcid. For
example, on the AP side, if a station's setup link is the 5G link and
the station uses 2G to transmit a frame, the value of non_aql_packets
is increased on the 5G wcid but decreased on the 2G wcid. Once the
inflated counter exceeds MT_MAX_NON_AQL_PKT, the TX scheduler
permanently refuses to service the station.
Drop the reassignment and account on the wcid used for transmission.
This also records the actual wcid in the queue entry.
Fixes: e1378e5228aa ("mt76: rely on AQL for burst size limits on tx queueing")
Signed-off-by: Michael-CY Lee <michael-cy.lee@mediatek.com>
Link: https://patch.msgid.link/20260722082610.2699628-4-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/tx.c | 4 ----
1 file changed, 4 deletions(-)
diff --git a/drivers/net/wireless/mediatek/mt76/tx.c b/drivers/net/wireless/mediatek/mt76/tx.c
index 9fb0cca5524a4..ac6c0ca092931 100644
--- a/drivers/net/wireless/mediatek/mt76/tx.c
+++ b/drivers/net/wireless/mediatek/mt76/tx.c
@@ -311,10 +311,6 @@ __mt76_tx_queue_skb(struct mt76_phy *phy, int qid, struct sk_buff *skb,
if (idx < 0 || !sta)
return idx;
- wcid = (struct mt76_wcid *)sta->drv_priv;
- if (!wcid->sta)
- return idx;
-
q->entry[idx].wcid = wcid->idx;
if (!non_aql)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0744/1518] wifi: mt76: assign link_id when sending probe request during scan
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (742 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0743/1518] wifi: mt76: fix non-AQL packet accounting for MLO stations Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0745/1518] wifi: mt76: mt7996: validate RX band_idx before dereferencing phys[] Greg Kroah-Hartman
` (254 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael-CY Lee, Felix Fietkau,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michael-CY Lee <michael-cy.lee@mediatek.com>
[ Upstream commit f137fabc1313427e08af06a414d929ebd9fd37d6 ]
The link_id in info->control.flags is required by mt7996 to select the
correct mt76_wcid for transmission.
Not assigning the link_id in info->control.flags is equivalent to
assigning the link_id to 0, causing mt7996 to select link_id 0 for
transmission, so probe requests sent on behalf of an MLD vif scanning
via a different link were transmitted with the wrong per-link wcid.
Fixes: 31083e38548f ("wifi: mt76: add code for emulating hardware scanning")
Signed-off-by: Michael-CY Lee <michael-cy.lee@mediatek.com>
Link: https://patch.msgid.link/20260722082610.2699628-5-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/scan.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/drivers/net/wireless/mediatek/mt76/scan.c b/drivers/net/wireless/mediatek/mt76/scan.c
index 6cfca5108bc7e..2faa84c516e7b 100644
--- a/drivers/net/wireless/mediatek/mt76/scan.c
+++ b/drivers/net/wireless/mediatek/mt76/scan.c
@@ -46,6 +46,7 @@ mt76_scan_send_probe(struct mt76_dev *dev, struct cfg80211_ssid *ssid)
struct mt76_phy *phy = dev->scan.phy;
struct ieee80211_tx_info *info;
struct sk_buff *skb;
+ u8 link_id;
skb = ieee80211_probereq_get(phy->hw, vif->addr, ssid->ssid,
ssid->ssid_len, req->ie_len);
@@ -75,6 +76,10 @@ mt76_scan_send_probe(struct mt76_dev *dev, struct cfg80211_ssid *ssid)
info->flags |= IEEE80211_TX_CTL_NO_CCK_RATE;
info->control.flags |= IEEE80211_TX_CTRL_DONT_USE_RATE_MASK;
+ link_id = mvif->wcid ? mvif->wcid->link_id : IEEE80211_LINK_UNSPECIFIED;
+ info->control.flags &= ~IEEE80211_TX_CTRL_MLO_LINK;
+ info->control.flags |= u32_encode_bits(link_id, IEEE80211_TX_CTRL_MLO_LINK);
+
mt76_tx(phy, NULL, mvif->wcid, skb);
out:
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0745/1518] wifi: mt76: mt7996: validate RX band_idx before dereferencing phys[]
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (743 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0744/1518] wifi: mt76: assign link_id when sending probe request during scan Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0746/1518] wifi: mt76: mt7996: set MT76_MCU_RESET before waking MCU waiters on full reset Greg Kroah-Hartman
` (253 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit 2243778a5fae8329ab5f18e7adcd7e03b911a1b7 ]
band_idx comes from a 2-bit descriptor field (0-3) and was used directly
to index dev->mt76.phys[] (size __MT_MAX_BAND == 3) and dereference the
result. A corrupt or reserved descriptor value could index out of bounds
or hit a NULL phy on parts with fewer bands. Reject invalid band indices,
mirroring mt7996_rx_get_wcid().
Fixes: 98686cd21624 ("wifi: mt76: mt7996: add driver for MediaTek Wi-Fi 7 (802.11be) devices")
Link: https://patch.msgid.link/20260722082610.2699628-6-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7996/mac.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/mac.c b/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
index 21b3e0b20888f..648c27c1bf66f 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
@@ -480,7 +480,13 @@ mt7996_mac_fill_rx(struct mt7996_dev *dev, enum mt76_rxq_id q,
memset(status, 0, sizeof(*status));
band_idx = FIELD_GET(MT_RXD1_NORMAL_BAND_IDX, rxd1);
+ if (!mt7996_band_valid(dev, band_idx))
+ return -EINVAL;
+
mphy = dev->mt76.phys[band_idx];
+ if (!mphy)
+ return -EINVAL;
+
phy = mphy->priv;
status->phy_idx = mphy->band_idx;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0746/1518] wifi: mt76: mt7996: set MT76_MCU_RESET before waking MCU waiters on full reset
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (744 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0745/1518] wifi: mt76: mt7996: validate RX band_idx before dereferencing phys[] Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0747/1518] wifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear Greg Kroah-Hartman
` (252 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit 6469ae71e7e5d0132c934972f628f346ad0379cd ]
mt7996_mac_full_reset() called wake_up(&dev->mt76.mcu.wait) without first
setting MT76_MCU_RESET. The MCU response wait condition only checks the
response queue and that bit, so the wake-up released nobody: a thread
blocked in an MCU command against the dead firmware (typically holding
dev->mt76.mutex) stayed asleep until its multi-second timeout, stalling
recovery. Set the bit before the wake-up, as mt7915 does.
Fixes: 27015b6fbcca ("wifi: mt76: mt7996: enable full system reset support")
Link: https://patch.msgid.link/20260722082610.2699628-7-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7996/mac.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/mac.c b/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
index 648c27c1bf66f..11d56fdb7f26b 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
@@ -2516,6 +2516,7 @@ mt7996_mac_full_reset(struct mt7996_dev *dev)
dev->recovery.hw_full_reset = true;
+ set_bit(MT76_MCU_RESET, &dev->mphy.state);
wake_up(&dev->mt76.mcu.wait);
ieee80211_stop_queues(hw);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0747/1518] wifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (745 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0746/1518] wifi: mt76: mt7996: set MT76_MCU_RESET before waking MCU waiters on full reset Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0748/1518] wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss Greg Kroah-Hartman
` (251 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit 6486e11a6e2f679597af2d5bb48c3b07a2b2a7ba ]
mt7915_remove_interface() cleared the wcid mask bit with no lock held and
before clearing the RCU wcid pointer. The mask is a non-atomic RMW shared
with the allocators, which all run under dev->mt76.mutex; on DBDC the two
wiphys share one mt76_dev, so this raced add_interface/sta_add on the
other band and could leak or double-hand-out a wcid. Clearing the bit
before the RCU pointer also let a concurrent allocation reuse the index
and publish its wcid, which the subsequent NULL assignment then wiped.
Move the clear into the existing mutex section, after the RCU pointer is
cleared.
Fixes: f3049b88b2b3 ("wifi: mt76: mt7915: allocate vif wcid in the same range as stations")
Link: https://patch.msgid.link/20260722082610.2699628-8-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7915/main.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7915/main.c b/drivers/net/wireless/mediatek/mt76/mt7915/main.c
index 8e69df105c5ae..d6d90d305ab91 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7915/main.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7915/main.c
@@ -294,7 +294,6 @@ static void mt7915_remove_interface(struct ieee80211_hw *hw,
mt7915_mcu_add_bss_info(phy, vif, false);
mt7915_mcu_add_sta(dev, vif, NULL, CONN_STATE_DISCONNECT, false);
- mt76_wcid_mask_clear(dev->mt76.wcid_mask, mvif->sta.wcid.idx);
mutex_lock(&dev->mt76.mutex);
mt76_testmode_reset(phy->mt76, true);
@@ -310,6 +309,7 @@ static void mt7915_remove_interface(struct ieee80211_hw *hw,
mutex_lock(&dev->mt76.mutex);
dev->mt76.vif_mask &= ~BIT_ULL(mvif->mt76.idx);
phy->omac_mask &= ~BIT_ULL(mvif->mt76.omac_idx);
+ mt76_wcid_mask_clear(dev->mt76.wcid_mask, mvif->sta.wcid.idx);
mutex_unlock(&dev->mt76.mutex);
spin_lock_bh(&dev->mt76.sta_poll_lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0748/1518] wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (746 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0747/1518] wifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0749/1518] wifi: mt76: mt7996: dont report a zero TX bitrate Greg Kroah-Hartman
` (250 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit 4a2f4be532e3ea4e2b536e411793a05aaa51af25 ]
If a peer's VHT/HE MCS map has no supported spatial stream (all fields
0x3), the loop exits with nss == 0 and the function returned (u8)-1 (255),
which was then written into the firmware sta_rec_bf beamforming fields.
Clamp the result to 0.
Fixes: 89029a85482c ("mt76: mt7915: add Tx beamformer support")
Link: https://patch.msgid.link/20260722082610.2699628-9-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7915/mcu.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7915/mcu.c b/drivers/net/wireless/mediatek/mt76/mt7915/mcu.c
index 1646b9ba29805..01d6ea6332440 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7915/mcu.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7915/mcu.c
@@ -51,7 +51,7 @@ mt7915_mcu_get_sta_nss(u16 mcs_map)
break;
}
- return nss - 1;
+ return nss ? nss - 1 : 0;
}
static void
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0749/1518] wifi: mt76: mt7996: dont report a zero TX bitrate
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (747 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0748/1518] wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0750/1518] wifi: mt76: mt7915: write RX header translation bit to the correct register Greg Kroah-Hartman
` (249 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit d4d92ccded678c92c390003926097ddbb6516bc7 ]
mt7996_sta_statistics() set NL80211_STA_INFO_TX_BITRATE unconditionally
after the block that already sets it, so a station with no rate info yet
was reported to userspace with a valid-but-zero TX rate. Drop the
redundant unconditional assignments; the in-block ones are sufficient.
Fixes: b34f346b917e ("wifi: mt76: mt7996: drop return in mt7996_sta_statistics")
Link: https://patch.msgid.link/20260722082610.2699628-10-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7996/main.c | 2 --
1 file changed, 2 deletions(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/main.c b/drivers/net/wireless/mediatek/mt76/mt7996/main.c
index 103851e011583..840a0b7dd20c5 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/main.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/main.c
@@ -1733,8 +1733,6 @@ static void mt7996_sta_statistics(struct ieee80211_hw *hw,
sinfo->txrate.flags = txrate->flags;
sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_BITRATE);
}
- sinfo->txrate.flags = txrate->flags;
- sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_BITRATE);
sinfo->tx_failed = msta_link->wcid.stats.tx_failed;
sinfo->filled |= BIT_ULL(NL80211_STA_INFO_TX_FAILED);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0750/1518] wifi: mt76: mt7915: write RX header translation bit to the correct register
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (748 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0749/1518] wifi: mt76: mt7996: dont report a zero TX bitrate Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0751/1518] wifi: mt76: fix stranded frames in mt76_txq_schedule_pending Greg Kroah-Hartman
` (248 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit 236145737480c4c0c515e09061d0d5f77cf52d3f ]
MT_MDP_DCR0_RX_HDR_TRANS_EN is a field of MT_MDP_DCR0, but monitor-mode
handling applied it to the per-band MT_DMA_DCR0 register instead. As a
result RX header translation was never disabled in the MDP when entering
monitor mode, and an undocumented bit of MT_DMA_DCR0 was toggled. Target
MT_MDP_DCR0, matching the mt7996 driver.
Fixes: b2491018587a ("wifi: mt76: mt7915: fix monitor mode issues")
Link: https://patch.msgid.link/20260722082610.2699628-11-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7915/main.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7915/main.c b/drivers/net/wireless/mediatek/mt76/mt7915/main.c
index d6d90d305ab91..4b11e0845f568 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7915/main.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7915/main.c
@@ -493,7 +493,7 @@ static int mt7915_config(struct ieee80211_hw *hw, int radio_idx,
mt76_rmw_field(dev, MT_DMA_DCR0(band), MT_DMA_DCR0_RXD_G5_EN,
enabled);
- mt76_rmw_field(dev, MT_DMA_DCR0(band), MT_MDP_DCR0_RX_HDR_TRANS_EN,
+ mt76_rmw_field(dev, MT_MDP_DCR0, MT_MDP_DCR0_RX_HDR_TRANS_EN,
!dev->monitor_mask);
mt76_testmode_reset(phy->mt76, true);
mt76_wr(dev, MT_WF_RFCR(band), rxfilter);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0751/1518] wifi: mt76: fix stranded frames in mt76_txq_schedule_pending
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (749 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0750/1518] wifi: mt76: mt7915: write RX header translation bit to the correct register Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0752/1518] wifi: mt76: fix uninitialised RXDMAD_C descriptor info Greg Kroah-Hartman
` (247 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit 422dd2db28ae27c35a586acd9ad482f30000c090 ]
A wcid is added to phy->tx_list whenever either tx_pending or
tx_offchannel becomes non-empty, but the requeue check after a partial
schedule required BOTH queues to be non-empty. When
mt76_txq_schedule_pending_wcid() returns -1 (queue stopped or
MT76_RESET) it leaves frames in tx_pending while tx_offchannel is empty,
so the wcid is dropped from every scheduling list and its frames stall
until the next mt76_tx() for that wcid or wcid cleanup. This strands
EAPOL/mgmt/nullfunc frames under momentary queue-full or across
scan/channel-switch, causing association and 4-way-handshake timeouts.
Requeue when either queue still holds frames, matching the enqueue
condition.
Fixes: 0b3be9d1d34e ("wifi: mt76: add separate tx scheduling queue for off-channel tx")
Link: https://patch.msgid.link/20260722082610.2699628-14-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/tx.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/net/wireless/mediatek/mt76/tx.c b/drivers/net/wireless/mediatek/mt76/tx.c
index ac6c0ca092931..26463d84b7898 100644
--- a/drivers/net/wireless/mediatek/mt76/tx.c
+++ b/drivers/net/wireless/mediatek/mt76/tx.c
@@ -666,8 +666,8 @@ static void mt76_txq_schedule_pending(struct mt76_phy *phy)
ret = mt76_txq_schedule_pending_wcid(phy, wcid, &wcid->tx_pending);
spin_lock(&phy->tx_lock);
- if (!skb_queue_empty(&wcid->tx_pending) &&
- !skb_queue_empty(&wcid->tx_offchannel) &&
+ if ((!skb_queue_empty(&wcid->tx_pending) ||
+ !skb_queue_empty(&wcid->tx_offchannel)) &&
list_empty(&wcid->tx_list))
list_add_tail(&wcid->tx_list, &phy->tx_list);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0752/1518] wifi: mt76: fix uninitialised RXDMAD_C descriptor info
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (750 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0751/1518] wifi: mt76: fix stranded frames in mt76_txq_schedule_pending Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0753/1518] wifi: mt76: fix RXDMAD_C buffer recycling race Greg Kroah-Hartman
` (246 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit d3ecac68f73b11828e72eaf7952a9beb5caea12b ]
Unlike other WED-RRO queues, RXDMAD_C frames continue into the skb build
path, but mt76_dma_get_buf() skips the desc->info read for RRO queues, so
the uninitialised on-stack info was stored into skb->cb and passed to
rx_skb(); initialise it to zero.
Fixes: e50d4d710efd ("wifi: mt76: Add mt76_dma_get_rxdmad_c_buf utility routione")
Link: https://patch.msgid.link/20260722082610.2699628-16-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/dma.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/dma.c b/drivers/net/wireless/mediatek/mt76/dma.c
index 0ba93290b00d3..3fcd0c46ecd94 100644
--- a/drivers/net/wireless/mediatek/mt76/dma.c
+++ b/drivers/net/wireless/mediatek/mt76/dma.c
@@ -988,7 +988,7 @@ mt76_dma_rx_process(struct mt76_dev *dev, struct mt76_queue *q, int budget)
while (done < budget) {
bool drop = false;
- u32 info;
+ u32 info = 0;
if (check_ddone) {
if (q->tail == dma_idx)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0753/1518] wifi: mt76: fix RXDMAD_C buffer recycling race
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (751 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0752/1518] wifi: mt76: fix uninitialised RXDMAD_C descriptor info Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0754/1518] wifi: mt76: mt7915: poll the correct SLP CTRL register for the second adie Greg Kroah-Hartman
` (245 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit e1f97c10a4ec2b9db69a134b757304399ca903ce ]
The RXDMAD_C buffers come from the RRO data queues' page pools, which are
bound to a different NAPI, so the direct page-pool recycle used here could
race the owning NAPI; take the non-direct path as is already done for WED
RX queues.
Fixes: e50d4d710efd ("wifi: mt76: Add mt76_dma_get_rxdmad_c_buf utility routione")
Link: https://patch.msgid.link/20260722082610.2699628-17-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/dma.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/dma.c b/drivers/net/wireless/mediatek/mt76/dma.c
index 3fcd0c46ecd94..f1048e3dff1d3 100644
--- a/drivers/net/wireless/mediatek/mt76/dma.c
+++ b/drivers/net/wireless/mediatek/mt76/dma.c
@@ -976,7 +976,8 @@ mt76_dma_rx_process(struct mt76_dev *dev, struct mt76_queue *q, int budget)
struct sk_buff *skb;
unsigned char *data;
bool check_ddone = false;
- bool allow_direct = !mt76_queue_is_wed_rx(q);
+ bool allow_direct = !mt76_queue_is_wed_rx(q) &&
+ !mt76_queue_is_wed_rro_rxdmad_c(q);
bool more;
if ((q->flags & MT_QFLAG_WED_RRO_EN) ||
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0754/1518] wifi: mt76: mt7915: poll the correct SLP CTRL register for the second adie
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (752 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0753/1518] wifi: mt76: fix RXDMAD_C buffer recycling race Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0755/1518] wifi: mt76: check txfree done event on the WED hw path Greg Kroah-Hartman
` (244 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit dd59a6126a8f1bd52bf6bd057bf0c8307f76a74b ]
The clock enable path for the second adie sets MT_ADIE_SLP_CTRL_CK0(1)
but polled the busy bit of MT_ADIE_SLP_CTRL_CK0(0), so dual-adie
bring-up could proceed before the adie1 clock was stable.
Fixes: 99ad32a4ca3a ("mt76: mt7915: add support for MT7986")
Link: https://patch.msgid.link/20260722082610.2699628-18-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7915/soc.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7915/soc.c b/drivers/net/wireless/mediatek/mt76/mt7915/soc.c
index c823a7554a3ac..df641c1334809 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7915/soc.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7915/soc.c
@@ -913,7 +913,7 @@ static void mt7986_wmac_clock_enable(struct mt7915_dev *dev, u32 adie_type)
read_poll_timeout(mt76_rr, cur, !(cur & MT_SLP_CTRL_BSY_MASK),
USEC_PER_MSEC, 50 * USEC_PER_MSEC, false,
- dev, MT_ADIE_SLP_CTRL_CK0(0));
+ dev, MT_ADIE_SLP_CTRL_CK0(1));
}
mt76_wmac_spi_unlock(dev);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0755/1518] wifi: mt76: check txfree done event on the WED hw path
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (753 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0754/1518] wifi: mt76: mt7915: poll the correct SLP CTRL register for the second adie Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0756/1518] wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config Greg Kroah-Hartman
` (243 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rex Lu, Shayne Chen, Felix Fietkau,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rex Lu <rex.lu@mediatek.com>
[ Upstream commit 3310e71a74b176d3613dfb42b6bc630d99e90cbb ]
Check the txfree done event DW1 bit 15 when WED is enabled, to avoid
the driver reading a txfree done event before WED has finished reading
it. No need to check this flag on WED v2, otherwise SER will occur.
The bit position was previously defined as MT_DMA_CTL_BURST, which is
unused; rename it to match its function on the txfree ring.
Fixes: 83eafc9251d6 ("wifi: mt76: mt7996: add wed tx support")
Signed-off-by: Rex Lu <rex.lu@mediatek.com>
Signed-off-by: Shayne Chen <shayne.chen@mediatek.com>
Link: https://patch.msgid.link/20260722082610.2699628-2-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/dma.c | 9 +++++++++
drivers/net/wireless/mediatek/mt76/dma.h | 2 +-
2 files changed, 10 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/dma.c b/drivers/net/wireless/mediatek/mt76/dma.c
index f1048e3dff1d3..13a3885a0a92d 100644
--- a/drivers/net/wireless/mediatek/mt76/dma.c
+++ b/drivers/net/wireless/mediatek/mt76/dma.c
@@ -608,6 +608,15 @@ mt76_dma_dequeue(struct mt76_dev *dev, struct mt76_queue *q, bool flush,
q->desc[idx].ctrl |= cpu_to_le32(MT_DMA_CTL_DMA_DONE);
else if (!(q->desc[idx].ctrl & cpu_to_le32(MT_DMA_CTL_DMA_DONE)))
return NULL;
+#ifdef CONFIG_NET_MEDIATEK_SOC_WED
+ /* on WED v3 the M_DONE bit signals that WED is done reading
+ * the txfree descriptor; WED v2 does not set it
+ */
+ else if (dev->mmio.wed.version > 2 &&
+ mt76_queue_is_wed_tx_free(q) &&
+ !(q->desc[idx].ctrl & cpu_to_le32(MT_DMA_CTL_M_DONE)))
+ return NULL;
+#endif
}
done:
q->tail = (q->tail + 1) % q->ndesc;
diff --git a/drivers/net/wireless/mediatek/mt76/dma.h b/drivers/net/wireless/mediatek/mt76/dma.h
index 27eefc9e56f22..1c556c8c86347 100644
--- a/drivers/net/wireless/mediatek/mt76/dma.h
+++ b/drivers/net/wireless/mediatek/mt76/dma.h
@@ -11,7 +11,7 @@
#define MT_DMA_CTL_SD_LEN1 GENMASK(13, 0)
#define MT_DMA_CTL_LAST_SEC1 BIT(14)
-#define MT_DMA_CTL_BURST BIT(15)
+#define MT_DMA_CTL_M_DONE BIT(15)
#define MT_DMA_CTL_SD_LEN0 GENMASK(29, 16)
#define MT_DMA_CTL_LAST_SEC0 BIT(30)
#define MT_DMA_CTL_DMA_DONE BIT(31)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0756/1518] wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (754 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0755/1518] wifi: mt76: check txfree done event on the WED hw path Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0757/1518] wifi: mt76: mt7915: unwind state on add_interface failure Greg Kroah-Hartman
` (242 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit 44af52467e72094351a362bf69effd52f1d9c186 ]
The response TLV loop advanced by tlv->len without a minimum, so a
theoretical firmware response containing a zero-length TLV could spin
forever, hanging the CPU during device probe.
The u32 payload was also read without bounds checking.
Reject a short fixed field, stop on a TLV whose length underruns the
header or overruns the skb.
Fixes: 5d33053be609 ("wifi: mt76: mt7996: add variants support")
Link: https://patch.msgid.link/20260724124813.3961474-2-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7996/mcu.c | 16 +++++++++++++---
1 file changed, 13 insertions(+), 3 deletions(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/mcu.c b/drivers/net/wireless/mediatek/mt76/mt7996/mcu.c
index 5df5c3a2121f5..95c2a2a5f5bcf 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mcu.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mcu.c
@@ -4001,21 +4001,31 @@ int mt7996_mcu_get_chip_config(struct mt7996_dev *dev, u32 *cap)
return ret;
/* fixed field */
+ if (skb->len < 4) {
+ dev_kfree_skb(skb);
+ return -EINVAL;
+ }
skb_pull(skb, 4);
buf = skb->data;
- while (buf - skb->data < skb->len) {
+ while (buf - skb->data + sizeof(struct tlv) <= skb->len) {
struct tlv *tlv = (struct tlv *)buf;
+ u16 tlv_len = le16_to_cpu(tlv->len);
+
+ if (tlv_len < sizeof(*tlv) ||
+ tlv_len > skb->len - (buf - skb->data))
+ break;
switch (le16_to_cpu(tlv->tag)) {
case UNI_EVENT_CHIP_CONFIG_EFUSE_VERSION:
- *cap = le32_to_cpu(*(__le32 *)(buf + sizeof(*tlv)));
+ if (tlv_len >= sizeof(*tlv) + sizeof(__le32))
+ *cap = le32_to_cpu(*(__le32 *)(buf + sizeof(*tlv)));
break;
default:
break;
}
- buf += le16_to_cpu(tlv->len);
+ buf += tlv_len;
}
dev_kfree_skb(skb);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0757/1518] wifi: mt76: mt7915: unwind state on add_interface failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (755 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0756/1518] wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0758/1518] wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER Greg Kroah-Hartman
` (241 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit 2fb6480c52f611338e1b0abe5e6219be1fc9ab75 ]
When mt76_wcid_alloc() fails, mt7915_add_interface() returned without
clearing the vif_mask/omac_mask bits it had already set, without removing
the firmware dev info added earlier, and without clearing a monitor_vif
pointer to the vif mac80211 is about to free. mac80211 does not call
remove_interface() for a failed add, so the indices and firmware dev
entry leaked permanently and testmode could dereference the stale
monitor_vif. Add a proper error unwind.
Fixes: b619e01380ee ("mt76: fix MBSS index condition in DBDC mode")
Link: https://patch.msgid.link/20260724124813.3961474-4-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7915/main.c | 12 +++++++++++-
1 file changed, 11 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7915/main.c b/drivers/net/wireless/mediatek/mt76/mt7915/main.c
index 4b11e0845f568..3c1d388b200a0 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7915/main.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7915/main.c
@@ -249,7 +249,7 @@ static int mt7915_add_interface(struct ieee80211_hw *hw,
idx = mt76_wcid_alloc(dev->mt76.wcid_mask, mt7915_wtbl_size(dev));
if (idx < 0) {
ret = -ENOSPC;
- goto out;
+ goto err;
}
INIT_LIST_HEAD(&mvif->sta.rc_list);
@@ -277,7 +277,17 @@ static int mt7915_add_interface(struct ieee80211_hw *hw,
mt7915_mcu_add_sta(dev, vif, NULL, CONN_STATE_PORT_SECURE, true);
rcu_assign_pointer(dev->mt76.wcid[idx], &mvif->sta.wcid);
+ mutex_unlock(&dev->mt76.mutex);
+
+ return 0;
+
+err:
+ dev->mt76.vif_mask &= ~BIT_ULL(mvif->mt76.idx);
+ phy->omac_mask &= ~BIT_ULL(mvif->mt76.omac_idx);
+ mt7915_mcu_add_dev_info(phy, vif, false);
out:
+ if (phy->monitor_vif == vif)
+ phy->monitor_vif = NULL;
mutex_unlock(&dev->mt76.mutex);
return ret;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0758/1518] wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (756 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0757/1518] wifi: mt76: mt7915: unwind state on add_interface failure Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0759/1518] wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV Greg Kroah-Hartman
` (240 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit 6190db312b8230813f529f014b26247c6d9800d0 ]
mt7996_mac_reset_work() parked the tx worker and disabled the RX/TX NAPIs
before taking dev->mt76.mutex. mt76_worker_disable()/_enable() are plain
kthread park/unpark, not refcounted, and __mt76_set_channel() toggles the
same worker and the MT76_RESET bit under the mutex. An L1 SER racing a
channel switch could therefore have the worker unparked and MT76_RESET
cleared while the reset path resets the DMA rings, corrupting descriptors
or tokens. Take the mutex before disabling the worker, as mt7915 does.
Fixes: 27015b6fbcca ("wifi: mt76: mt7996: enable full system reset support")
Link: https://patch.msgid.link/20260724124813.3961474-5-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7996/mac.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/mac.c b/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
index 11d56fdb7f26b..cafdbd27f1e48 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
@@ -2630,6 +2630,8 @@ void mt7996_mac_reset_work(struct work_struct *work)
cancel_delayed_work_sync(&phy->mt76->mac_work);
}
+ mutex_lock(&dev->mt76.mutex);
+
mt76_worker_disable(&dev->mt76.tx_worker);
mt76_for_each_q_rx(&dev->mt76, i) {
if (mtk_wed_device_active(&dev->mt76.mmio.wed) &&
@@ -2640,8 +2642,6 @@ void mt7996_mac_reset_work(struct work_struct *work)
}
napi_disable(&dev->mt76.tx_napi);
- mutex_lock(&dev->mt76.mutex);
-
mt76_wr(dev, MT_MCU_INT_EVENT, MT_MCU_INT_EVENT_DMA_STOPPED);
if (mt7996_wait_reset_state(dev, MT_MCU_CMD_RESET_DONE)) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0759/1518] wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (757 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0758/1518] wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0760/1518] wifi: mt76: mt7996: dont leak MLD group index on remap alloc failure Greg Kroah-Hartman
` (239 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit 50c66bab321140c49aa2ed779a3ec9d2f085b458 ]
When a CSA countdown is active, mt7996_mcu_beacon_cntdwn() emits two
bss_bcn_cntdwn_tlv entries (the CSA countdown and the CCA-abort BCC), but
MT7996_BEACON_UPDATE_SIZE only reserved one. With MBSSID enabled and a
near-maximum beacon template the extra 8 bytes could push the offload
command past MT7996_MAX_BSS_OFFLOAD_SIZE and trigger skb_over_panic().
Reserve room for both countdown TLVs.
Fixes: 98686cd21624 ("wifi: mt76: mt7996: add driver for MediaTek Wi-Fi 7 (802.11be) devices")
Link: https://patch.msgid.link/20260724124813.3961474-8-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7996/mcu.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/mcu.h b/drivers/net/wireless/mediatek/mt76/mt7996/mcu.h
index 7b51d7346bcaa..848c6c5751155 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mcu.h
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mcu.h
@@ -828,7 +828,7 @@ enum {
#define MT7996_BEACON_UPDATE_SIZE (sizeof(struct bss_req_hdr) + \
sizeof(struct bss_bcn_content_tlv) + \
4 + MT_TXD_SIZE + \
- sizeof(struct bss_bcn_cntdwn_tlv) + \
+ sizeof(struct bss_bcn_cntdwn_tlv) * 2 + \
sizeof(struct bss_bcn_mbss_tlv))
#define MT7996_MAX_BSS_OFFLOAD_SIZE 2048
#define MT7996_MAX_BEACON_SIZE (MT7996_MAX_BSS_OFFLOAD_SIZE - \
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0760/1518] wifi: mt76: mt7996: dont leak MLD group index on remap alloc failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (758 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0759/1518] wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0761/1518] wifi: mt76: mt7915: use little-endian for bss_info_ra wire fields Greg Kroah-Hartman
` (238 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit 151a6cf0d12f5d333b93b634dbe5834ea0b77ce7 ]
mt7996_change_vif_links() sets the mld_idx_mask group bit before
allocating the remap index. If the remap allocation fails it jumped to
the exit without clearing that bit, permanently consuming one of the 16
MLD group slots. Release the group bit on the error path.
Fixes: 4fb3b4e7d1ca ("wifi: mt76: mt7996: fix MLD group index assignment")
Link: https://patch.msgid.link/20260724124813.3961474-9-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7996/main.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/main.c b/drivers/net/wireless/mediatek/mt76/mt7996/main.c
index 840a0b7dd20c5..45cdbe727c8b7 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/main.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/main.c
@@ -2297,6 +2297,7 @@ mt7996_change_vif_links(struct ieee80211_hw *hw, struct ieee80211_vif *vif,
idx = get_free_idx(dev->mld_remap_idx_mask, 0, 15) - 1;
if (idx < 0) {
+ dev->mld_idx_mask &= ~BIT_ULL(mvif->mld_group_idx);
ret = -ENOSPC;
goto out;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0761/1518] wifi: mt76: mt7915: use little-endian for bss_info_ra wire fields
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (759 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0760/1518] wifi: mt76: mt7996: dont leak MLD group index on remap alloc failure Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0762/1518] wifi: mt76: mt7996: add missing rdd_idx check when enabling background radar Greg Kroah-Hartman
` (237 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit 04280d0a56be4264720e7b205daaa332c715e5ec ]
train_up_high_thres, train_up_rule_rssi and low_traffic_thres were
declared as host-native short in a firmware-facing TLV and assigned
host-order constants, so on a big-endian host the firmware received
byte-swapped rate-adaptation thresholds. Declare them __le16 and convert
with cpu_to_le16().
Fixes: e57b7901469f ("mt76: add mac80211 driver for MT7915 PCIe-based chipsets")
Link: https://patch.msgid.link/20260724124813.3961474-12-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7915/mcu.c | 6 +++---
drivers/net/wireless/mediatek/mt76/mt7915/mcu.h | 6 +++---
2 files changed, 6 insertions(+), 6 deletions(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7915/mcu.c b/drivers/net/wireless/mediatek/mt76/mt7915/mcu.c
index 01d6ea6332440..f3abc0de167a3 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7915/mcu.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7915/mcu.c
@@ -576,9 +576,9 @@ mt7915_mcu_bss_ra_tlv(struct sk_buff *skb, struct ieee80211_vif *vif,
ra->rx_streams = max_nss;
ra->algo = 4;
ra->train_up_rule = 2;
- ra->train_up_high_thres = 110;
- ra->train_up_rule_rssi = -70;
- ra->low_traffic_thres = 2;
+ ra->train_up_high_thres = cpu_to_le16(110);
+ ra->train_up_rule_rssi = cpu_to_le16(-70);
+ ra->low_traffic_thres = cpu_to_le16(2);
ra->phy_cap = cpu_to_le32(0xfdf);
ra->interval = cpu_to_le32(500);
ra->fast_interval = cpu_to_le32(100);
diff --git a/drivers/net/wireless/mediatek/mt76/mt7915/mcu.h b/drivers/net/wireless/mediatek/mt76/mt7915/mcu.h
index 4049ed864003d..4c25abb0297de 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7915/mcu.h
+++ b/drivers/net/wireless/mediatek/mt76/mt7915/mcu.h
@@ -318,9 +318,9 @@ struct bss_info_ra {
u8 antenna_idx;
u8 train_up_rule;
u8 rsv[3];
- unsigned short train_up_high_thres;
- short train_up_rule_rssi;
- unsigned short low_traffic_thres;
+ __le16 train_up_high_thres;
+ __le16 train_up_rule_rssi;
+ __le16 low_traffic_thres;
__le16 max_phyrate;
__le32 phy_cap;
__le32 interval;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0762/1518] wifi: mt76: mt7996: add missing rdd_idx check when enabling background radar
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (760 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0761/1518] wifi: mt76: mt7915: use little-endian for bss_info_ra wire fields Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0763/1518] wifi: mt76: only consume the WO drop bit on WED v2 devices Greg Kroah-Hartman
` (236 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, StanleyYP Wang, Felix Fietkau,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: StanleyYP Wang <StanleyYP.Wang@mediatek.com>
[ Upstream commit dbca5c4d29826cecd3185fb1ae2746205ab55127 ]
Add the missing rdd idx check (< 0) in
mt7996_mcu_rdd_background_enable(). mt7996_get_rdd_idx() returns -1
for phys without 5 GHz support, and the negative index was passed to
the RDD MCU command unchecked.
Fixes: 1529e335f93d ("wifi: mt76: mt7996: rework radar HWRDD idx")
Signed-off-by: StanleyYP Wang <StanleyYP.Wang@mediatek.com>
Link: https://patch.msgid.link/20260724124813.3961474-13-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7996/mcu.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/mcu.c b/drivers/net/wireless/mediatek/mt76/mt7996/mcu.c
index 95c2a2a5f5bcf..92f8a28cd4a51 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mcu.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mcu.c
@@ -3735,6 +3735,9 @@ int mt7996_mcu_rdd_background_enable(struct mt7996_phy *phy,
struct mt7996_dev *dev = phy->dev;
int err, region, rdd_idx = mt7996_get_rdd_idx(phy, true);
+ if (rdd_idx < 0)
+ return -EINVAL;
+
if (!chandef) { /* disable offchain */
err = mt7996_mcu_rdd_cmd(dev, RDD_STOP, rdd_idx, 0);
if (err)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0763/1518] wifi: mt76: only consume the WO drop bit on WED v2 devices
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (761 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0762/1518] wifi: mt76: mt7996: add missing rdd_idx check when enabling background radar Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0764/1518] ACPI: processor: idle: Optimize ACPI idle driver registration Greg Kroah-Hartman
` (235 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit 1df54335590bb025c3bd706a9ba9c6e73a1d3000 ]
The RX path is handled by the WO MCU only on WED v2 hardware. On WED
v3 the same buf1 bit does not carry drop information, so evaluating it
there causes spurious RX drops.
Fixes: e4d2b8bcac11 ("wifi: mt76: drop the incorrect scatter and gather frame")
Link: https://patch.msgid.link/20260724124813.3961474-14-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/dma.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/dma.c b/drivers/net/wireless/mediatek/mt76/dma.c
index 13a3885a0a92d..a487887ef5444 100644
--- a/drivers/net/wireless/mediatek/mt76/dma.c
+++ b/drivers/net/wireless/mediatek/mt76/dma.c
@@ -547,8 +547,13 @@ mt76_dma_get_buf(struct mt76_dev *dev, struct mt76_queue *q, int idx,
t->ptr = NULL;
mt76_put_rxwi(dev, t);
- if (drop)
+#ifdef CONFIG_NET_MEDIATEK_SOC_WED
+ /* the WO MCU owns the RX path only on WED v2, on newer
+ * versions this buf1 bit carries no drop information
+ */
+ if (drop && dev->mmio.wed.version == 2)
*drop |= !!(buf1 & MT_DMA_CTL_WO_DROP);
+#endif
} else {
dma_sync_single_for_cpu(dev->dma_dev, e->dma_addr[0],
SKB_WITH_OVERHEAD(q->buf_size),
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0764/1518] ACPI: processor: idle: Optimize ACPI idle driver registration
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (762 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0763/1518] wifi: mt76: only consume the WO drop bit on WED v2 devices Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0765/1518] ACPI: processor: Unregister cpufreq notifier on init failure Greg Kroah-Hartman
` (234 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Huisong Li, Borislav Petkov (AMD),
Rafael J. Wysocki, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Huisong Li <lihuisong@huawei.com>
[ Upstream commit 13ebeef6a1b9c4e5c9789f835cc4ec34873f0bb1 ]
Currently, the ACPI idle driver is registered from within a CPU
hotplug callback. Although this didn't cause any functional issues,
this is questionable and confusing. And it is better to register
the cpuidle driver when all of the CPUs have been brought up.
So add a new function to initialize acpi_idle_driver based on the
power management information of an available CPU and register cpuidle
driver in acpi_processor_driver_init().
This commit has four changes under the commit 7a8c994cbb2d (ACPI:
processor: idle: Optimize ACPI idle driver registration):
1) move acpi_processor_register_idle_driver() ahead of the
driver_register().
2) add acpi_processor_cstate_first_run_checks() before calling
acpi_processor_get_power_info().
3) squash the commit 9d68320b2bca (ACPI: processor: idle: Fix
function defined but not used warning) into this change.
4) use for_each_possible_cpu(cpu) to scan all possible cpus.
Signed-off-by: Huisong Li <lihuisong@huawei.com>
Tested-by: Borislav Petkov (AMD) <bp@alien8.de>
[ rjw: New comment edits, changelog tweak ]
Link: https://patch.msgid.link/20251223100914.2407069-2-lihuisong@huawei.com
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Stable-dep-of: 06f32dd67e6b ("ACPI: processor: Unregister cpufreq notifier on init failure")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/processor_driver.c | 10 ++++-
drivers/acpi/processor_idle.c | 66 +++++++++++++++++++++------------
include/acpi/processor.h | 2 +
3 files changed, 54 insertions(+), 24 deletions(-)
diff --git a/drivers/acpi/processor_driver.c b/drivers/acpi/processor_driver.c
index 65e779be64ffc..311863e00ffd5 100644
--- a/drivers/acpi/processor_driver.c
+++ b/drivers/acpi/processor_driver.c
@@ -259,9 +259,11 @@ static int __init acpi_processor_driver_init(void)
acpi_processor_ignore_ppc_init();
}
+ acpi_processor_register_idle_driver();
+
result = driver_register(&acpi_processor_driver);
if (result < 0)
- return result;
+ goto unregister_idle_drv;
result = cpuhp_setup_state(CPUHP_AP_ONLINE_DYN,
"acpi/cpu-drv:online",
@@ -283,8 +285,13 @@ static int __init acpi_processor_driver_init(void)
acpi_idle_rescan_dead_smt_siblings();
return 0;
+
err:
driver_unregister(&acpi_processor_driver);
+
+unregister_idle_drv:
+ acpi_processor_unregister_idle_driver();
+
return result;
}
@@ -302,6 +309,7 @@ static void __exit acpi_processor_driver_exit(void)
cpuhp_remove_state_nocalls(hp_online);
cpuhp_remove_state_nocalls(CPUHP_ACPI_CPUDRV_DEAD);
driver_unregister(&acpi_processor_driver);
+ acpi_processor_unregister_idle_driver();
}
module_init(acpi_processor_driver_init);
diff --git a/drivers/acpi/processor_idle.c b/drivers/acpi/processor_idle.c
index 99e0a14a6201a..a8a3c6229e9f4 100644
--- a/drivers/acpi/processor_idle.c
+++ b/drivers/acpi/processor_idle.c
@@ -1371,7 +1371,49 @@ int acpi_processor_power_state_has_changed(struct acpi_processor *pr)
return 0;
}
-static int acpi_processor_registered;
+void acpi_processor_register_idle_driver(void)
+{
+ struct acpi_processor *pr;
+ int ret = -ENODEV;
+ int cpu;
+
+ /*
+ * ACPI idle driver is used by all possible CPUs.
+ * Use the processor power info of one in them to set up idle states.
+ * Note that the existing idle handler will be used on platforms that
+ * only support C1.
+ */
+ for_each_possible_cpu(cpu) {
+ pr = per_cpu(processors, cpu);
+ if (!pr)
+ continue;
+
+ acpi_processor_cstate_first_run_checks();
+ ret = acpi_processor_get_power_info(pr);
+ if (!ret) {
+ pr->flags.power_setup_done = 1;
+ acpi_processor_setup_cpuidle_states(pr);
+ break;
+ }
+ }
+
+ if (ret) {
+ pr_debug("No ACPI power information from any CPUs.\n");
+ return;
+ }
+
+ ret = cpuidle_register_driver(&acpi_idle_driver);
+ if (ret) {
+ pr_debug("register %s failed.\n", acpi_idle_driver.name);
+ return;
+ }
+ pr_debug("%s registered with cpuidle.\n", acpi_idle_driver.name);
+}
+
+void acpi_processor_unregister_idle_driver(void)
+{
+ cpuidle_unregister_driver(&acpi_idle_driver);
+}
int acpi_processor_power_init(struct acpi_processor *pr)
{
@@ -1386,22 +1428,7 @@ int acpi_processor_power_init(struct acpi_processor *pr)
if (!acpi_processor_get_power_info(pr))
pr->flags.power_setup_done = 1;
- /*
- * Install the idle handler if processor power management is supported.
- * Note that we use previously set idle handler will be used on
- * platforms that only support C1.
- */
if (pr->flags.power) {
- /* Register acpi_idle_driver if not already registered */
- if (!acpi_processor_registered) {
- acpi_processor_setup_cpuidle_states(pr);
- retval = cpuidle_register_driver(&acpi_idle_driver);
- if (retval)
- return retval;
- pr_debug("%s registered with cpuidle\n",
- acpi_idle_driver.name);
- }
-
dev = kzalloc(sizeof(*dev), GFP_KERNEL);
if (!dev)
return -ENOMEM;
@@ -1414,14 +1441,11 @@ int acpi_processor_power_init(struct acpi_processor *pr)
*/
retval = cpuidle_register_device(dev);
if (retval) {
- if (acpi_processor_registered == 0)
- cpuidle_unregister_driver(&acpi_idle_driver);
per_cpu(acpi_cpuidle_device, pr->id) = NULL;
kfree(dev);
return retval;
}
- acpi_processor_registered++;
}
return 0;
}
@@ -1435,10 +1459,6 @@ int acpi_processor_power_exit(struct acpi_processor *pr)
if (pr->flags.power) {
cpuidle_unregister_device(dev);
- acpi_processor_registered--;
- if (acpi_processor_registered == 0)
- cpuidle_unregister_driver(&acpi_idle_driver);
-
kfree(dev);
}
diff --git a/include/acpi/processor.h b/include/acpi/processor.h
index d0eccbd920e5c..ff864c1cee3a4 100644
--- a/include/acpi/processor.h
+++ b/include/acpi/processor.h
@@ -423,6 +423,8 @@ int acpi_processor_power_init(struct acpi_processor *pr);
int acpi_processor_power_exit(struct acpi_processor *pr);
int acpi_processor_power_state_has_changed(struct acpi_processor *pr);
int acpi_processor_hotplug(struct acpi_processor *pr);
+void acpi_processor_register_idle_driver(void);
+void acpi_processor_unregister_idle_driver(void);
#else
static inline int acpi_processor_power_init(struct acpi_processor *pr)
{
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0765/1518] ACPI: processor: Unregister cpufreq notifier on init failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (763 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0764/1518] ACPI: processor: idle: Optimize ACPI idle driver registration Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0766/1518] drm/msm: dont tear down KMS twice when KMS init fails Greg Kroah-Hartman
` (233 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Can Peng, Rafael J. Wysocki,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Can Peng <pengcan@kylinos.cn>
[ Upstream commit 06f32dd67e6b23a05bef0d8183c5335af91c0c3b ]
acpi_processor_driver_init() registers the cpufreq policy notifier before
registering the ACPI processor driver and setting up CPU hotplug state.
If driver_register() or cpuhp_setup_state() fails, the error path only
unregisters the ACPI processor driver and the idle driver. The cpufreq
notifier remains registered even though initialization failed.
Mirror the module exit path on the init failure path and unregister the
cpufreq notifier when it has been registered.
Fixes: c0e0421a60bf ("ACPI: processor: Reorder acpi_processor_driver_init()")
Signed-off-by: Can Peng <pengcan@kylinos.cn>
Link: https://patch.msgid.link/20260729023605.197367-1-pengcan@kylinos.cn
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/processor_driver.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/acpi/processor_driver.c b/drivers/acpi/processor_driver.c
index 311863e00ffd5..06589bf488f74 100644
--- a/drivers/acpi/processor_driver.c
+++ b/drivers/acpi/processor_driver.c
@@ -292,6 +292,12 @@ static int __init acpi_processor_driver_init(void)
unregister_idle_drv:
acpi_processor_unregister_idle_driver();
+ if (acpi_processor_cpufreq_init) {
+ cpufreq_unregister_notifier(&acpi_processor_notifier_block,
+ CPUFREQ_POLICY_NOTIFIER);
+ acpi_processor_cpufreq_init = false;
+ }
+
return result;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0766/1518] drm/msm: dont tear down KMS twice when KMS init fails
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (764 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0765/1518] ACPI: processor: Unregister cpufreq notifier on init failure Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0767/1518] drm/msm/dp: reject YUV420-only modes without VSC SDP support Greg Kroah-Hartman
` (232 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dmitry Baryshkov, Konrad Dybcio,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
[ Upstream commit 93c125e4ea98fb25f927ba5a334d85845127d667 ]
When priv->kms_init() (mdp4_kms_init() / mdp5_kms_init()) fails partway
through, both display drivers already tear their KMS state down via
mdp4_destroy() / mdp5_kms_destroy() before returning the error. The
common error path in msm_drm_init() then runs msm_drm_uninit() ->
msm_drm_kms_uninit(), which tries to destroy the very same KMS a second
time, which causes a use-after-free crash.
Bring MDP4/MDP5 in line with the DPU driver whose dpu_kms_init() doesn't
perform error cleanup on the failure. Let the common path own the
cleanup, instead of freeing the KMS from their error paths.
The crash trace for the reference:
__lock_acquire from lock_acquire (kernel/locking/lockdep.c:5906 kernel/locking/lockdep.c:5863)
lock_acquire from touch_wq_lockdep_map (kernel/workqueue.c:4094 (discriminator 1))
touch_wq_lockdep_map from __flush_workqueue (kernel/workqueue.c:4136)
__flush_workqueue from msm_drm_kms_uninit (drivers/gpu/drm/msm/msm_kms.c:243 (discriminator 33))
msm_drm_kms_uninit from msm_drm_uninit (drivers/gpu/drm/msm/msm_drv.c:93)
msm_drm_uninit from msm_drm_init (drivers/gpu/drm/msm/msm_drv.c:184)
msm_drm_init from try_to_bring_up_aggregate_device (drivers/base/component.c:249 drivers/base/component.c:227)
try_to_bring_up_aggregate_device from __component_add (drivers/base/component.c:269 drivers/base/component.c:748)
__component_add from dsi_host_attach (drivers/gpu/drm/msm/dsi/dsi_host.c:1739)
dsi_host_attach from mipi_dsi_attach (drivers/gpu/drm/drm_mipi_dsi.c:383)
mipi_dsi_attach from sharp_nt_panel_probe (drivers/gpu/drm/panel/panel-sharp-ls043t1le01.c:247)
Fixes: 506efcba3129 ("drm/msm: carve out KMS code from msm_drv.c")
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/742068/
Link: https://lore.kernel.org/r/20260723-msm-fix-crash-v1-1-78fb4721c2d9@oss.qualcomm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/disp/mdp4/mdp4_kms.c | 22 ++++++++--------------
drivers/gpu/drm/msm/disp/mdp5/mdp5_kms.c | 11 +++--------
2 files changed, 11 insertions(+), 22 deletions(-)
diff --git a/drivers/gpu/drm/msm/disp/mdp4/mdp4_kms.c b/drivers/gpu/drm/msm/disp/mdp4/mdp4_kms.c
index 809ca191e9de7..c5cd19d1a486a 100644
--- a/drivers/gpu/drm/msm/disp/mdp4/mdp4_kms.c
+++ b/drivers/gpu/drm/msm/disp/mdp4/mdp4_kms.c
@@ -405,7 +405,7 @@ static int mdp4_kms_init(struct drm_device *dev)
ret = mdp_kms_init(&mdp4_kms->base, &kms_funcs);
if (ret) {
DRM_DEV_ERROR(dev->dev, "failed to init kms\n");
- goto fail;
+ return ret;
}
kms = priv->kms;
@@ -416,7 +416,7 @@ static int mdp4_kms_init(struct drm_device *dev)
ret = regulator_enable(mdp4_kms->vdd);
if (ret) {
DRM_DEV_ERROR(dev->dev, "failed to enable regulator vdd: %d\n", ret);
- goto fail;
+ return ret;
}
}
@@ -428,7 +428,7 @@ static int mdp4_kms_init(struct drm_device *dev)
DRM_DEV_ERROR(dev->dev, "unexpected MDP version: v%d.%d\n",
major, minor);
ret = -ENXIO;
- goto fail;
+ return ret;
}
mdp4_kms->rev = minor;
@@ -437,7 +437,7 @@ static int mdp4_kms_init(struct drm_device *dev)
if (!mdp4_kms->lut_clk) {
DRM_DEV_ERROR(dev->dev, "failed to get lut_clk\n");
ret = -ENODEV;
- goto fail;
+ return ret;
}
clk_set_rate(mdp4_kms->lut_clk, max_clk);
}
@@ -459,7 +459,7 @@ static int mdp4_kms_init(struct drm_device *dev)
vm = msm_kms_init_vm(mdp4_kms->dev, NULL);
if (IS_ERR(vm)) {
ret = PTR_ERR(vm);
- goto fail;
+ return ret;
}
kms->vm = vm;
@@ -467,7 +467,7 @@ static int mdp4_kms_init(struct drm_device *dev)
ret = modeset_init(mdp4_kms);
if (ret) {
DRM_DEV_ERROR(dev->dev, "modeset_init failed: %d\n", ret);
- goto fail;
+ return ret;
}
mdp4_kms->blank_cursor_bo = msm_gem_new(dev, SZ_16K, MSM_BO_WC | MSM_BO_SCANOUT);
@@ -475,14 +475,14 @@ static int mdp4_kms_init(struct drm_device *dev)
ret = PTR_ERR(mdp4_kms->blank_cursor_bo);
DRM_DEV_ERROR(dev->dev, "could not allocate blank-cursor bo: %d\n", ret);
mdp4_kms->blank_cursor_bo = NULL;
- goto fail;
+ return ret;
}
ret = msm_gem_get_and_pin_iova(mdp4_kms->blank_cursor_bo, kms->vm,
&mdp4_kms->blank_cursor_iova);
if (ret) {
DRM_DEV_ERROR(dev->dev, "could not pin blank-cursor bo: %d\n", ret);
- goto fail;
+ return ret;
}
dev->mode_config.min_width = 0;
@@ -491,12 +491,6 @@ static int mdp4_kms_init(struct drm_device *dev)
dev->mode_config.max_height = 2048;
return 0;
-
-fail:
- if (kms)
- mdp4_destroy(kms);
-
- return ret;
}
static const struct dev_pm_ops mdp4_pm_ops = {
diff --git a/drivers/gpu/drm/msm/disp/mdp5/mdp5_kms.c b/drivers/gpu/drm/msm/disp/mdp5/mdp5_kms.c
index 61edf68640926..0b6b97be3ce93 100644
--- a/drivers/gpu/drm/msm/disp/mdp5/mdp5_kms.c
+++ b/drivers/gpu/drm/msm/disp/mdp5/mdp5_kms.c
@@ -514,7 +514,7 @@ static int mdp5_kms_init(struct drm_device *dev)
ret = mdp_kms_init(&mdp5_kms->base, &kms_funcs);
if (ret) {
DRM_DEV_ERROR(&pdev->dev, "failed to init kms\n");
- goto fail;
+ return ret;
}
config = mdp5_cfg_get_config(mdp5_kms->cfg);
@@ -537,7 +537,7 @@ static int mdp5_kms_init(struct drm_device *dev)
vm = msm_kms_init_vm(mdp5_kms->dev, pdev->dev.parent);
if (IS_ERR(vm)) {
ret = PTR_ERR(vm);
- goto fail;
+ return ret;
}
kms->vm = vm;
@@ -547,7 +547,7 @@ static int mdp5_kms_init(struct drm_device *dev)
ret = modeset_init(mdp5_kms);
if (ret) {
DRM_DEV_ERROR(&pdev->dev, "modeset_init failed: %d\n", ret);
- goto fail;
+ return ret;
}
dev->mode_config.min_width = 0;
@@ -559,11 +559,6 @@ static int mdp5_kms_init(struct drm_device *dev)
dev->vblank_disable_immediate = true;
return 0;
-fail:
- if (kms)
- mdp5_kms_destroy(kms);
-
- return ret;
}
static void mdp5_destroy(struct mdp5_kms *mdp5_kms)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0767/1518] drm/msm/dp: reject YUV420-only modes without VSC SDP support
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (765 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0766/1518] drm/msm: dont tear down KMS twice when KMS init fails Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0768/1518] drm/msm/dp: do not reject wide-bus modes while a YUV420 mode is active Greg Kroah-Hartman
` (231 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Dmitry Baryshkov, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
[ Upstream commit 684f95fb4e9ad10aac39fbb1fa7592a59d7f54ea ]
DP conveys YUV 420 colorimetry through a VSC SDP. A sink that advertises
a mode as YUV-420-only therefore cannot be driven at all unless the panel
supports VSC SDP, yet msm_dp_bridge_mode_valid() only used the VSC SDP
capability to decide whether to halve the pixel clock, otherwise letting
such modes through to be validated (and possibly accepted) at the full
RGB clock the sink cannot display.
Reject 420-only modes with MODE_NO_420 when the panel does not support
VSC SDP. With those modes filtered out, being a 420-only mode implies VSC
SDP support, so the YUV-420 test reduces to drm_mode_is_420_only(): drop
msm_dp_is_yuv_420_enabled() and call the DRM helper directly at its two
callers (the DPU encoder already has the connector from the atomic state).
Fixes: df9cf852ca30 ("drm/msm/dp: account for widebus and yuv420 during mode validation")
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/741713/
Link: https://lore.kernel.org/r/20260722-drm-msm-display-interface-v1-1-368c10fe62fd@oss.qualcomm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/disp/dpu1/dpu_encoder.c | 3 +--
drivers/gpu/drm/msm/dp/dp_display.c | 28 +++++++++------------
drivers/gpu/drm/msm/msm_drv.h | 8 ------
3 files changed, 13 insertions(+), 26 deletions(-)
diff --git a/drivers/gpu/drm/msm/disp/dpu1/dpu_encoder.c b/drivers/gpu/drm/msm/disp/dpu1/dpu_encoder.c
index 777eab5ad844e..e21aa5cdbaf29 100644
--- a/drivers/gpu/drm/msm/disp/dpu1/dpu_encoder.c
+++ b/drivers/gpu/drm/msm/disp/dpu1/dpu_encoder.c
@@ -709,8 +709,7 @@ void dpu_encoder_update_topology(struct drm_encoder *drm_enc,
if (fb && MSM_FORMAT_IS_YUV(msm_framebuffer_format(fb)))
topology->num_cdm++;
} else if (disp_info->intf_type == INTF_DP) {
- if (msm_dp_is_yuv_420_enabled(priv->kms->dp[disp_info->h_tile_instance[0]],
- adj_mode))
+ if (drm_mode_is_420_only(&connector->display_info, adj_mode))
topology->num_cdm++;
}
}
diff --git a/drivers/gpu/drm/msm/dp/dp_display.c b/drivers/gpu/drm/msm/dp/dp_display.c
index c6f5422b60ddb..5b630dbb16952 100644
--- a/drivers/gpu/drm/msm/dp/dp_display.c
+++ b/drivers/gpu/drm/msm/dp/dp_display.c
@@ -930,6 +930,7 @@ enum drm_mode_status msm_dp_bridge_mode_valid(struct drm_bridge *bridge,
u32 mode_rate_khz = 0, supported_rate_khz = 0, mode_bpp = 0;
struct msm_dp *dp;
int mode_pclk_khz = mode->clock;
+ bool is_yuv_420;
dp = to_dp_bridge(bridge)->msm_dp_display;
@@ -941,9 +942,16 @@ enum drm_mode_status msm_dp_bridge_mode_valid(struct drm_bridge *bridge,
msm_dp_display = container_of(dp, struct msm_dp_display_private, msm_dp_display);
link_info = &msm_dp_display->panel->link_info;
- if ((drm_mode_is_420_only(&dp->connector->display_info, mode) &&
- msm_dp_display->panel->vsc_sdp_supported) ||
- msm_dp_wide_bus_available(dp))
+ is_yuv_420 = drm_mode_is_420_only(&dp->connector->display_info, mode);
+
+ /*
+ * YUV 420 is carried over DP by signalling the colorimetry through a
+ * VSC SDP, so a 420-only mode cannot be driven without VSC SDP support.
+ */
+ if (is_yuv_420 && !msm_dp_display->panel->vsc_sdp_supported)
+ return MODE_NO_420;
+
+ if (is_yuv_420 || msm_dp_wide_bus_available(dp))
mode_pclk_khz /= 2;
if (mode_pclk_khz > DP_MAX_PIXEL_CLK_KHZ)
@@ -1506,22 +1514,10 @@ void __exit msm_dp_unregister(void)
platform_driver_unregister(&msm_dp_display_driver);
}
-bool msm_dp_is_yuv_420_enabled(const struct msm_dp *msm_dp_display,
- const struct drm_display_mode *mode)
-{
- struct msm_dp_display_private *dp;
- const struct drm_display_info *info;
-
- dp = container_of(msm_dp_display, struct msm_dp_display_private, msm_dp_display);
- info = &msm_dp_display->connector->display_info;
-
- return dp->panel->vsc_sdp_supported && drm_mode_is_420_only(info, mode);
-}
-
bool msm_dp_needs_periph_flush(const struct msm_dp *msm_dp_display,
const struct drm_display_mode *mode)
{
- return msm_dp_is_yuv_420_enabled(msm_dp_display, mode);
+ return drm_mode_is_420_only(&msm_dp_display->connector->display_info, mode);
}
bool msm_dp_wide_bus_available(const struct msm_dp *msm_dp_display)
diff --git a/drivers/gpu/drm/msm/msm_drv.h b/drivers/gpu/drm/msm/msm_drv.h
index 6d847d593f1ae..d40793845541e 100644
--- a/drivers/gpu/drm/msm/msm_drv.h
+++ b/drivers/gpu/drm/msm/msm_drv.h
@@ -357,8 +357,6 @@ void __exit msm_dp_unregister(void);
int msm_dp_modeset_init(struct msm_dp *dp_display, struct drm_device *dev,
struct drm_encoder *encoder, bool yuv_supported);
void msm_dp_snapshot(struct msm_disp_state *disp_state, struct msm_dp *dp_display);
-bool msm_dp_is_yuv_420_enabled(const struct msm_dp *dp_display,
- const struct drm_display_mode *mode);
bool msm_dp_needs_periph_flush(const struct msm_dp *dp_display,
const struct drm_display_mode *mode);
bool msm_dp_wide_bus_available(const struct msm_dp *dp_display);
@@ -383,12 +381,6 @@ static inline void msm_dp_snapshot(struct msm_disp_state *disp_state, struct msm
{
}
-static inline bool msm_dp_is_yuv_420_enabled(const struct msm_dp *dp_display,
- const struct drm_display_mode *mode)
-{
- return false;
-}
-
static inline bool msm_dp_needs_periph_flush(const struct msm_dp *dp_display,
const struct drm_display_mode *mode)
{
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0768/1518] drm/msm/dp: do not reject wide-bus modes while a YUV420 mode is active
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (766 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0767/1518] drm/msm/dp: reject YUV420-only modes without VSC SDP support Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0769/1518] perf: arm_spe: Make wakeup range check overflow safe Greg Kroah-Hartman
` (230 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Dmitry Baryshkov, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
[ Upstream commit bd926e62d355879133452bc3889447f8e89757f2 ]
msm_dp_bridge_mode_valid() halves the candidate mode's pixel clock when
the sink either uses YUV 420 output or drives the wide bus, so that modes
relying on those to stay under DP_MAX_PIXEL_CLK_KHZ are accepted. The
wide bus part is queried through msm_dp_wide_bus_available(), which
returns false whenever the currently committed mode uses YUV 420 output:
it inspects the stored msm_dp_mode.out_fmt_is_yuv_420 of the active mode,
not the mode being validated.
Consequently, while a YUV 420 mode is active, an RGB mode that needs the
wide bus to fit under DP_MAX_PIXEL_CLK_KHZ has its pixel clock left
un-halved and is wrongly rejected as MODE_CLOCK_HIGH.
The candidate mode's YUV 420 status is already evaluated as is_yuv_420,
and the wide bus is disabled precisely for YUV 420 output, so halving the
pixel clock for either case is equivalent to halving it when the
candidate is YUV 420 or the controller supports the wide bus. Test
wide_bus_supported directly, so the decision no longer depends on the
format of the active mode.
Fixes: df9cf852ca30 ("drm/msm/dp: account for widebus and yuv420 during mode validation")
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/741740/
Link: https://lore.kernel.org/r/20260722-drm-msm-display-interface-v1-15-368c10fe62fd@oss.qualcomm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/dp/dp_display.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/msm/dp/dp_display.c b/drivers/gpu/drm/msm/dp/dp_display.c
index 5b630dbb16952..68043dbe72bfa 100644
--- a/drivers/gpu/drm/msm/dp/dp_display.c
+++ b/drivers/gpu/drm/msm/dp/dp_display.c
@@ -951,7 +951,7 @@ enum drm_mode_status msm_dp_bridge_mode_valid(struct drm_bridge *bridge,
if (is_yuv_420 && !msm_dp_display->panel->vsc_sdp_supported)
return MODE_NO_420;
- if (is_yuv_420 || msm_dp_wide_bus_available(dp))
+ if (is_yuv_420 || msm_dp_display->wide_bus_supported)
mode_pclk_khz /= 2;
if (mode_pclk_khz > DP_MAX_PIXEL_CLK_KHZ)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0769/1518] perf: arm_spe: Make wakeup range check overflow safe
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (767 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0768/1518] drm/msm/dp: do not reject wide-bus modes while a YUV420 mode is active Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0770/1518] drm/msm/dpu: Drop sneaky dev_pm_opp_set_rate(0) Greg Kroah-Hartman
` (229 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Leo Yan, Will Deacon, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leo Yan <leo.yan@arm.com>
[ Upstream commit fcc5eaea2d234162dfb8258372dd897bc2a1b862 ]
The current code checks whether the wakeup point is in the current
writable range by comparing it with handle->head + handle->size.
The perf AUX head is a monotonically increasing index, so that addition
can overflow when head is close to ULONG_MAX. In that case, a wakeup
point which is still inside the free space range can be missed.
Use unsigned subtraction to compare the distance from head to wakeup
against the handle->size. This can dismiss the issue when addition
overflow.
This is unlikely to happen in practice, but the change makes the
watermark check logically correct.
Fixes: d5d9696b0380 ("drivers/perf: Add support for ARMv8.2 Statistical Profiling Extension")
Signed-off-by: Leo Yan <leo.yan@arm.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/perf/arm_spe_pmu.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/perf/arm_spe_pmu.c b/drivers/perf/arm_spe_pmu.c
index e4e4e63c64c42..7bc24db50d1ff 100644
--- a/drivers/perf/arm_spe_pmu.c
+++ b/drivers/perf/arm_spe_pmu.c
@@ -552,7 +552,7 @@ static u64 __arm_spe_pmu_next_off(struct perf_output_handle *handle)
* the page boundary following it. Keep the tail boundary if
* that's lower.
*/
- if (handle->wakeup < (handle->head + handle->size) && head <= wakeup)
+ if ((handle->wakeup - handle->head) < handle->size && head <= wakeup)
limit = min(limit, round_up(wakeup, PAGE_SIZE));
if (limit > head)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0770/1518] drm/msm/dpu: Drop sneaky dev_pm_opp_set_rate(0)
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (768 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0769/1518] perf: arm_spe: Make wakeup range check overflow safe Greg Kroah-Hartman
@ 2026-09-12 6:48 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0771/1518] drm/msm/dp: Drop dev_pm_opp_set_rate(0) Greg Kroah-Hartman
` (228 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:48 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Dmitry Baryshkov,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
[ Upstream commit 811c38907eab0f66c22c5e5708e6f8eab14d76fa ]
dev_pm_opp_set_rate(0) removes the vote specified in required-opps but
does not actually park the clock, making it run without the necessary
power backing. Prevent that from happening when
_dpu_core_perf_get_core_clk_rate() returns 0.
Fixes: 25fdd5933e4c ("drm/msm: Add SDM845 DPU support")
Signed-off-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/742779/
Link: https://lore.kernel.org/r/20260728-topic-dpu_power-v1-1-e7783b859a70@oss.qualcomm.com
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/disp/dpu1/dpu_core_perf.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/gpu/drm/msm/disp/dpu1/dpu_core_perf.c b/drivers/gpu/drm/msm/disp/dpu1/dpu_core_perf.c
index 13cc658065c56..6524531bd8bdc 100644
--- a/drivers/gpu/drm/msm/disp/dpu1/dpu_core_perf.c
+++ b/drivers/gpu/drm/msm/disp/dpu1/dpu_core_perf.c
@@ -394,6 +394,10 @@ int dpu_core_perf_crtc_update(struct drm_crtc *crtc,
trace_dpu_core_perf_update_clk(kms->dev, !crtc->enabled, clk_rate);
+ /* If we're going offline, PM callbacks will disable the clocks instead */
+ if (!clk_rate)
+ return 0;
+
clk_rate = min(clk_rate, kms->perf.max_core_clk_rate);
ret = dev_pm_opp_set_rate(&kms->pdev->dev, clk_rate);
if (ret) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0771/1518] drm/msm/dp: Drop dev_pm_opp_set_rate(0)
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (769 preceding siblings ...)
2026-09-12 6:48 ` [PATCH 6.18 0770/1518] drm/msm/dpu: Drop sneaky dev_pm_opp_set_rate(0) Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0772/1518] drm/msm/dsi: " Greg Kroah-Hartman
` (227 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Dmitry Baryshkov,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
[ Upstream commit cebfa9909e27ec7b7cbaec25ee5516cf886baa39 ]
dev_pm_opp_set_rate(0) removes the vote specified in required-opps but
does not actually park the clock, making it run without the necessary
power backing. Drop the explicit calls to it.
Fixes: c943b4948b58 ("drm/msm/dp: add displayPort driver support")
Signed-off-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/742781/
Link: https://lore.kernel.org/r/20260728-topic-dpu_power-v1-2-e7783b859a70@oss.qualcomm.com
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/dp/dp_ctrl.c | 5 +----
1 file changed, 1 insertion(+), 4 deletions(-)
diff --git a/drivers/gpu/drm/msm/dp/dp_ctrl.c b/drivers/gpu/drm/msm/dp/dp_ctrl.c
index 38ed4de8313e3..2ff7db77a82b6 100644
--- a/drivers/gpu/drm/msm/dp/dp_ctrl.c
+++ b/drivers/gpu/drm/msm/dp/dp_ctrl.c
@@ -1941,13 +1941,12 @@ static int msm_dp_ctrl_reinitialize_mainlink(struct msm_dp_ctrl_private *ctrl)
msm_dp_ctrl_mainlink_disable(ctrl);
ctrl->phy_opts.dp.lanes = ctrl->link->link_params.num_lanes;
phy_configure(phy, &ctrl->phy_opts);
+
/*
* Disable and re-enable the mainlink clock since the
* link clock might have been adjusted as part of the
* link maintenance.
*/
- dev_pm_opp_set_rate(ctrl->dev, 0);
-
msm_dp_ctrl_link_clk_disable(&ctrl->msm_dp_ctrl);
phy_power_off(phy);
@@ -1973,7 +1972,6 @@ static int msm_dp_ctrl_deinitialize_mainlink(struct msm_dp_ctrl_private *ctrl)
msm_dp_ctrl_reset(&ctrl->msm_dp_ctrl);
- dev_pm_opp_set_rate(ctrl->dev, 0);
msm_dp_ctrl_link_clk_disable(&ctrl->msm_dp_ctrl);
phy_power_off(phy);
@@ -2620,7 +2618,6 @@ void msm_dp_ctrl_off(struct msm_dp_ctrl *msm_dp_ctrl)
ctrl->stream_clks_on = false;
}
- dev_pm_opp_set_rate(ctrl->dev, 0);
msm_dp_ctrl_link_clk_disable(&ctrl->msm_dp_ctrl);
phy_power_off(phy);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0772/1518] drm/msm/dsi: Drop dev_pm_opp_set_rate(0)
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (770 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0771/1518] drm/msm/dp: Drop dev_pm_opp_set_rate(0) Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0773/1518] wifi: ath11k: fix leak in ath11k_service_ready_ext_event() Greg Kroah-Hartman
` (226 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Dmitry Baryshkov,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
[ Upstream commit 06b7ba206561619bb34116f49e0ef26b867ce3aa ]
dev_pm_opp_set_rate(0) removes the vote specified in required-opps but
does not actually park the clock, making it run without the necessary
power backing. Drop the explicit call to it.
Every call site of ops->link_clk_disable() is followed by
pm_runtime_put(), so the power vote will be rescinded if deemed safe.
Fixes: 32d3e0feccfe ("drm/msm: dsi: Use OPP API to set clk/perf state")
Signed-off-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Patchwork: https://patchwork.freedesktop.org/patch/742783/
Link: https://lore.kernel.org/r/20260728-topic-dpu_power-v1-3-e7783b859a70@oss.qualcomm.com
Signed-off-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/msm/dsi/dsi_host.c | 2 --
1 file changed, 2 deletions(-)
diff --git a/drivers/gpu/drm/msm/dsi/dsi_host.c b/drivers/gpu/drm/msm/dsi/dsi_host.c
index 2350934f270a2..5110fe05ca841 100644
--- a/drivers/gpu/drm/msm/dsi/dsi_host.c
+++ b/drivers/gpu/drm/msm/dsi/dsi_host.c
@@ -549,8 +549,6 @@ int dsi_link_clk_enable_v2(struct msm_dsi_host *msm_host)
void dsi_link_clk_disable_6g(struct msm_dsi_host *msm_host)
{
- /* Drop the performance state vote */
- dev_pm_opp_set_rate(&msm_host->pdev->dev, 0);
clk_disable_unprepare(msm_host->esc_clk);
clk_disable_unprepare(msm_host->pixel_clk);
clk_disable_unprepare(msm_host->byte_intf_clk);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0773/1518] wifi: ath11k: fix leak in ath11k_service_ready_ext_event()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (771 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0772/1518] drm/msm/dsi: " Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0774/1518] soundwire: Add a helper function to wait for device initialisation Greg Kroah-Hartman
` (225 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rameshkumar Sundaram, Baochen Qiang,
Jeff Johnson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
[ Upstream commit 0293be2212d319d59589082461abf2a9b626cd1c ]
Currently, during ath11k_service_ready_ext_event() processing,
svc_rdy_ext.mac_phy_caps can be allocated during TLV parsing. This is a
temporary allocation that is freed on the success path, but not on the
error path. If parsing succeeds far enough to allocate mac_phy_caps and
then fails on a later TLV, the allocation leaks. So free the allocation
on the error path.
Compile tested only.
Fixes: 5b90fc760db5 ("ath11k: fix wmi service ready ext tlv parsing")
Assisted-by: Claude:claude-sonnet-4-6
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Link: https://patch.msgid.link/20260727-ath11k_service_ready_ext_event-memleak-v1-1-e8373d27bdd1@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/ath/ath11k/wmi.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/net/wireless/ath/ath11k/wmi.c b/drivers/net/wireless/ath/ath11k/wmi.c
index e5583cc78ba09..3305ec66ddbf2 100644
--- a/drivers/net/wireless/ath/ath11k/wmi.c
+++ b/drivers/net/wireless/ath/ath11k/wmi.c
@@ -5077,6 +5077,7 @@ static int ath11k_service_ready_ext_event(struct ath11k_base *ab,
return 0;
err:
+ kfree(svc_rdy_ext.mac_phy_caps);
ath11k_wmi_free_dbring_caps(ab);
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0774/1518] soundwire: Add a helper function to wait for device initialisation
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (772 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0773/1518] wifi: ath11k: fix leak in ath11k_service_ready_ext_event() Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0775/1518] ASoC: tas2783: Use new SoundWire enumeration helper Greg Kroah-Hartman
` (224 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vinod Koul, Charles Keepax,
Mark Brown, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Charles Keepax <ckeepax@opensource.cirrus.com>
[ Upstream commit 3492e8b494c18028044d4a2e03db5c7331fbd789 ]
Add a new helper function to wait for the device to enumerate
and be initialised by the SoundWire core. Most of the SoundWire
drivers have very similar boiler plate code in their runtime
resume, and that boiler plate tends to access various internals
of the SoundWire structs which is a mild layering violation.
Adding a new core helper function greatly eases both of these
issues.
Acked-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Charles Keepax <ckeepax@opensource.cirrus.com>
Link: https://patch.msgid.link/20260512103022.1154645-2-ckeepax@opensource.cirrus.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Stable-dep-of: b627da430357 ("ASoC: tas2783-sdw: drop stale regcache on uninitialized re-attach")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/soundwire/bus.c | 31 +++++++++++++++++++++++++++++++
include/linux/soundwire/sdw.h | 8 ++++++++
2 files changed, 39 insertions(+)
diff --git a/drivers/soundwire/bus.c b/drivers/soundwire/bus.c
index 14e1351a3f8ae..45d786f379d84 100644
--- a/drivers/soundwire/bus.c
+++ b/drivers/soundwire/bus.c
@@ -1372,6 +1372,37 @@ int sdw_slave_get_current_bank(struct sdw_slave *slave)
}
EXPORT_SYMBOL_GPL(sdw_slave_get_current_bank);
+/**
+ * sdw_slave_wait_for_init - Wait for device initialisation
+ * @slave: Pointer to the SoundWire peripheral.
+ * @timeout_ms: Timeout in milliseconds.
+ *
+ * Wait for a peripheral device to enumerate and be initialised by the
+ * SoundWire core.
+ *
+ * Return: Zero on success, and a negative error code on failure.
+ */
+int sdw_slave_wait_for_init(struct sdw_slave *slave, int timeout_ms)
+{
+ unsigned long time;
+
+ if (!slave->unattach_request)
+ return 0;
+
+ time = wait_for_completion_timeout(&slave->initialization_complete,
+ msecs_to_jiffies(timeout_ms));
+ if (!time) {
+ dev_err(&slave->dev, "Initialization not complete\n");
+ sdw_show_ping_status(slave->bus, true);
+ return -ETIMEDOUT;
+ }
+
+ slave->unattach_request = 0;
+
+ return 0;
+}
+EXPORT_SYMBOL_GPL(sdw_slave_wait_for_init);
+
static int sdw_slave_set_frequency(struct sdw_slave *slave)
{
int scale_index;
diff --git a/include/linux/soundwire/sdw.h b/include/linux/soundwire/sdw.h
index e6a3476bcef1a..bf2ddd429620f 100644
--- a/include/linux/soundwire/sdw.h
+++ b/include/linux/soundwire/sdw.h
@@ -1093,6 +1093,8 @@ int sdw_slave_get_current_bank(struct sdw_slave *sdev);
int sdw_slave_get_scale_index(struct sdw_slave *slave, u8 *base);
+int sdw_slave_wait_for_init(struct sdw_slave *slave, int timeout_ms);
+
/* messaging and data APIs */
int sdw_read(struct sdw_slave *slave, u32 addr);
int sdw_write(struct sdw_slave *slave, u32 addr, u8 value);
@@ -1136,6 +1138,12 @@ static inline int sdw_slave_get_current_bank(struct sdw_slave *sdev)
return -EINVAL;
}
+static inline int sdw_slave_wait_for_init(struct sdw_slave *slave, int timeout_ms)
+{
+ WARN_ONCE(1, "SoundWire API is disabled");
+ return -EINVAL;
+}
+
/* messaging and data APIs */
static inline int sdw_read(struct sdw_slave *slave, u32 addr)
{
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0775/1518] ASoC: tas2783: Use new SoundWire enumeration helper
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (773 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0774/1518] soundwire: Add a helper function to wait for device initialisation Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0776/1518] ASoC: codecs: tas2783-sdw: Propagate regcache_sync() errors Greg Kroah-Hartman
` (223 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Charles Keepax, Mark Brown,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Charles Keepax <ckeepax@opensource.cirrus.com>
[ Upstream commit ac6d4f298160bebf6979e63c2758414af5266f28 ]
Update the driver to use the new core helper that waits for the device
to enumerate on SoundWire and be initialised by the SoundWire core.
Signed-off-by: Charles Keepax <ckeepax@opensource.cirrus.com>
Link: https://patch.msgid.link/20260512103022.1154645-19-ckeepax@opensource.cirrus.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Stable-dep-of: b627da430357 ("ASoC: tas2783-sdw: drop stale regcache on uninitialized re-attach")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/codecs/tas2783-sdw.c | 18 ++++--------------
1 file changed, 4 insertions(+), 14 deletions(-)
diff --git a/sound/soc/codecs/tas2783-sdw.c b/sound/soc/codecs/tas2783-sdw.c
index e273b80d033e1..9203ddb4086ab 100644
--- a/sound/soc/codecs/tas2783-sdw.c
+++ b/sound/soc/codecs/tas2783-sdw.c
@@ -1175,22 +1175,12 @@ static s32 tas2783_sdca_dev_resume(struct device *dev)
{
struct sdw_slave *slave = dev_to_sdw_dev(dev);
struct tas2783_prv *tas_dev = dev_get_drvdata(dev);
- unsigned long t;
+ int ret;
- if (!slave->unattach_request)
- goto regmap_sync;
-
- t = wait_for_completion_timeout(&slave->initialization_complete,
- msecs_to_jiffies(TAS2783_PROBE_TIMEOUT));
- if (!t) {
- dev_err(&slave->dev, "resume: initialization timed out\n");
- sdw_show_ping_status(slave->bus, true);
- return -ETIMEDOUT;
- }
-
- slave->unattach_request = 0;
+ ret = sdw_slave_wait_for_init(slave, TAS2783_PROBE_TIMEOUT);
+ if (ret)
+ return ret;
-regmap_sync:
regcache_cache_only(tas_dev->regmap, false);
regcache_sync(tas_dev->regmap);
return 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0776/1518] ASoC: codecs: tas2783-sdw: Propagate regcache_sync() errors
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (774 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0775/1518] ASoC: tas2783: Use new SoundWire enumeration helper Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0777/1518] ASoC: tas2783-sdw: drop stale regcache on uninitialized re-attach Greg Kroah-Hartman
` (222 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Mark Brown,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit 0d6b2d6f93a6715827a9b3c027cd8448d76e0e47 ]
regcache_sync() can fail while replaying cached register state after
SoundWire resume or attach handling. tas2783 currently ignores that
failure.
Propagate the error and restore cache-only/dirty state on failure.
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://patch.msgid.link/20260704035746.82560-1-pengpeng@iscas.ac.cn
Signed-off-by: Mark Brown <broonie@kernel.org>
Stable-dep-of: b627da430357 ("ASoC: tas2783-sdw: drop stale regcache on uninitialized re-attach")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/codecs/tas2783-sdw.c | 16 ++++++++++++++--
1 file changed, 14 insertions(+), 2 deletions(-)
diff --git a/sound/soc/codecs/tas2783-sdw.c b/sound/soc/codecs/tas2783-sdw.c
index 9203ddb4086ab..2659e8b0c30ca 100644
--- a/sound/soc/codecs/tas2783-sdw.c
+++ b/sound/soc/codecs/tas2783-sdw.c
@@ -1182,7 +1182,13 @@ static s32 tas2783_sdca_dev_resume(struct device *dev)
return ret;
regcache_cache_only(tas_dev->regmap, false);
- regcache_sync(tas_dev->regmap);
+ ret = regcache_sync(tas_dev->regmap);
+ if (ret) {
+ regcache_cache_only(tas_dev->regmap, true);
+ regcache_mark_dirty(tas_dev->regmap);
+ return ret;
+ }
+
return 0;
}
@@ -1234,6 +1240,7 @@ static s32 tas_update_status(struct sdw_slave *slave,
{
struct tas2783_prv *tas_dev = dev_get_drvdata(&slave->dev);
struct device *dev = &slave->dev;
+ int ret;
dev_dbg(dev, "Peripheral status = %s",
status == SDW_SLAVE_UNATTACHED ? "unattached" :
@@ -1251,7 +1258,12 @@ static s32 tas_update_status(struct sdw_slave *slave,
/* updated the cache data to device */
regcache_cache_only(tas_dev->regmap, false);
- regcache_sync(tas_dev->regmap);
+ ret = regcache_sync(tas_dev->regmap);
+ if (ret) {
+ regcache_cache_only(tas_dev->regmap, true);
+ regcache_mark_dirty(tas_dev->regmap);
+ return ret;
+ }
/* perform I/O transfers required for Slave initialization */
return tas_io_init(&slave->dev, slave);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0777/1518] ASoC: tas2783-sdw: drop stale regcache on uninitialized re-attach
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (775 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0776/1518] ASoC: codecs: tas2783-sdw: Propagate regcache_sync() errors Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0778/1518] regulator: core: use system_freezable_wq for init complete work Greg Kroah-Hartman
` (221 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Antoine Monnet, Andrey Golovko,
Mark Brown, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Andrey Golovko <andrey.golovko@gmail.com>
[ Upstream commit b627da43035744ca4d691fbf56eef60268319873 ]
When the peripheral re-attaches after the SoundWire controller was
power-gated during system suspend (s2idle reaching S0i3 on AMD ACP), the
amplifier has lost all of its register and DSP state. tas_update_status()
handles that by re-running tas_io_init(), which writes the device's
TAS2783_SW_RESET register - a vendor register write that clears the
device's register file and DSP state, not a SoundWire reset, so no
re-enumeration is involved - and re-downloads the firmware. Before doing
any of that, it syncs back a register cache that still holds the
pre-suspend values.
That sync is useless, since the reset immediately wipes whatever it
wrote, and it leaves the cache claiming that the amplifier is already
powered up and unmuted. Subsequent read-modify-write updates - DAPM
amplifier power-up, SDCA PDE transitions at stream start - then see "no
change" and skip the hardware write. Playback runs without a single
error while the speakers stay silent. Unbinding and rebinding the driver
restores audio, since probe starts from a fresh cache.
Drop the cache instead of syncing it when an uninitialized device
attaches, so that later accesses see the real hardware state.
Reordering the sync after tas_io_init() and marking the cache dirty is
not a workable alternative here: tas_regmap has no .writeable_reg, so
the cache accepts every register up to .max_register, including ones for
which tas2783_sdca_mbq_size() returns 0. regmap_sdw_mbq_size() rejects
those with -EINVAL, so the replay fails on the first such register and
takes initialization down with it.
Cached user settings fall back to hardware defaults across such a power
loss, which seems clearly preferable to a silent amplifier - the device
is being reset and its firmware reloaded at this point anyway.
Tested on an ASUS ProArt PX13 HN7306EAC (AMD Strix Halo, ACP7.0, two
TAS2783 amplifiers plus RT721 on SoundWire link 1): the speakers work
after an s2idle resume with ~51 s of S0i3 residency, where previously
they stayed silent despite a complete firmware re-download.
Fixes: 4cc9bd8d7b32 ("ASoc: tas2783A: Add soundwire based codec driver")
Reported-by: Antoine Monnet <antoine@montane.tech>
Closes: https://lore.kernel.org/all/c66ae00a-e878-4af0-a05a-272e9574eaa5@montane.tech/
Signed-off-by: Andrey Golovko <andrey.golovko@gmail.com>
Link: https://patch.msgid.link/3e2751d1fb027bed0f09c88e5e56da8f@gmail.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
sound/soc/codecs/tas2783-sdw.c | 24 ++++++++++++++++--------
1 file changed, 16 insertions(+), 8 deletions(-)
diff --git a/sound/soc/codecs/tas2783-sdw.c b/sound/soc/codecs/tas2783-sdw.c
index 2659e8b0c30ca..b7f7b025efd37 100644
--- a/sound/soc/codecs/tas2783-sdw.c
+++ b/sound/soc/codecs/tas2783-sdw.c
@@ -1240,7 +1240,6 @@ static s32 tas_update_status(struct sdw_slave *slave,
{
struct tas2783_prv *tas_dev = dev_get_drvdata(&slave->dev);
struct device *dev = &slave->dev;
- int ret;
dev_dbg(dev, "Peripheral status = %s",
status == SDW_SLAVE_UNATTACHED ? "unattached" :
@@ -1256,14 +1255,23 @@ static s32 tas_update_status(struct sdw_slave *slave,
if (tas_dev->hw_init || tas_dev->status != SDW_SLAVE_ATTACHED)
return 0;
- /* updated the cache data to device */
regcache_cache_only(tas_dev->regmap, false);
- ret = regcache_sync(tas_dev->regmap);
- if (ret) {
- regcache_cache_only(tas_dev->regmap, true);
- regcache_mark_dirty(tas_dev->regmap);
- return ret;
- }
+
+ /*
+ * The device is attaching uninitialized: either this is the first
+ * attach, or it lost power (and with it all register and DSP state)
+ * while the controller was power-gated during system suspend. The
+ * cache still holds the pre-suspend values, and tas_io_init() below
+ * resets the device via TAS2783_SW_RESET anyway, so syncing it back
+ * is both useless and harmful: later read-modify-write updates would
+ * compare against stale data and skip the hardware write.
+ *
+ * Drop the cache instead, so that subsequent accesses see the real
+ * hardware state. Syncing after the reset is not an option either:
+ * the cache accepts registers for which tas2783_sdca_mbq_size()
+ * returns 0, and writing those back fails with -EINVAL.
+ */
+ regcache_drop_region(tas_dev->regmap, 0, UINT_MAX);
/* perform I/O transfers required for Slave initialization */
return tas_io_init(&slave->dev, slave);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0778/1518] regulator: core: use system_freezable_wq for init complete work
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (776 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0777/1518] ASoC: tas2783-sdw: drop stale regcache on uninitialized re-attach Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0779/1518] perf machine: Fix fd leak on bounds check in maps__set_modules_path_dir() Greg Kroah-Hartman
` (220 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Joy Zou, Frank Li, Mark Brown,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Joy Zou <joy.zou@oss.nxp.com>
[ Upstream commit 03eab318cedd6ae34ecd34533cd986edf5237164 ]
schedule_delayed_work() uses system_wq, which is non-freezable, allowing
regulator_init_complete_work to run concurrently with system suspend. This
work fires ~30s after boot to disable unused regulators via I2C. When it
races with PM suspend, the I2C adapter may already be suspended, triggering
a -ESHUTDOWN warning in __i2c_transfer():
WARNING: ... at __i2c_transfer+0x36c/0x3c8
Call trace:
__i2c_transfer
i2c_transfer
regmap_i2c_write
_regmap_update_bits
regulator_disable_regmap
_regulator_do_disable
regulator_late_cleanup
regulator_init_complete_work_function
process_one_work
Switch to system_freezable_wq so the work is frozen before any device
is suspended, eliminating the race.
Fixes: 55576cf18537 ("regulator: Defer init completion for a while after late_initcall")
Signed-off-by: Joy Zou <joy.zou@oss.nxp.com>
Reviewed-by: Frank Li <Frank.Li@nxp.com>
Link: https://patch.msgid.link/20260731-b4-regulator-pf01-v2-1-a406c8737fdb@oss.nxp.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/regulator/core.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/regulator/core.c b/drivers/regulator/core.c
index 019606bc36b9c..97b4ee5d29902 100644
--- a/drivers/regulator/core.c
+++ b/drivers/regulator/core.c
@@ -27,6 +27,7 @@
#include <linux/regulator/driver.h>
#include <linux/regulator/machine.h>
#include <linux/module.h>
+#include <linux/workqueue.h>
#define CREATE_TRACE_POINTS
#include <trace/events/regulator.h>
@@ -6604,8 +6605,9 @@ static int __init regulator_init_complete(void)
* we'd only do this on systems that need it, and a kernel
* command line option might be useful.
*/
- schedule_delayed_work(®ulator_init_complete_work,
- msecs_to_jiffies(30000));
+ queue_delayed_work(system_freezable_wq,
+ ®ulator_init_complete_work,
+ msecs_to_jiffies(30000));
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0779/1518] perf machine: Fix fd leak on bounds check in maps__set_modules_path_dir()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (777 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0778/1518] regulator: core: use system_freezable_wq for init complete work Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0780/1518] perf machine: Fix NULL parent dereference in fork event processing Greg Kroah-Hartman
` (219 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot, Ian Rogers,
Arnaldo Carvalho de Melo, Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnaldo Carvalho de Melo <acme@redhat.com>
[ Upstream commit 23010160bb9fd6e7ce940e232cd660b37ab9b20b ]
The bounds check for root_len >= path_size returns -1 directly without
closing the directory fd opened by io_dir__init() a few lines above.
Jump to the out label instead, which calls close(iod.dirfd).
Fixes: e7af1946818b ("perf machine: Reuse module path buffer")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Ian Rogers <irogers@google.com>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/machine.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/tools/perf/util/machine.c b/tools/perf/util/machine.c
index 9331b4cc19f18..a2f5ca35141bb 100644
--- a/tools/perf/util/machine.c
+++ b/tools/perf/util/machine.c
@@ -1390,8 +1390,10 @@ static int maps__set_modules_path_dir(struct maps *maps, char *path, size_t path
return -1;
}
/* Bounds check, should never happen. */
- if (root_len >= path_size)
- return -1;
+ if (root_len >= path_size) {
+ ret = -1;
+ goto out;
+ }
path[root_len++] = '/';
while ((dent = io_dir__readdir(&iod)) != NULL) {
if (io_dir__is_dir(&iod, dent)) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0780/1518] perf machine: Fix NULL parent dereference in fork event processing
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (778 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0779/1518] perf machine: Fix fd leak on bounds check in maps__set_modules_path_dir() Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0781/1518] perf machine: Guard against NULL strlist in machines__findnew() Greg Kroah-Hartman
` (218 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot, Adrian Hunter,
Arnaldo Carvalho de Melo, Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnaldo Carvalho de Melo <acme@redhat.com>
[ Upstream commit 73ac546bd6ba8ed4dc8d7a90fcb9bb8236de1568 ]
machine__process_fork_event() calls machine__findnew_thread() for the
parent thread, which can return NULL on allocation failure. The code
then dereferences parent via thread__pid(parent) without a NULL check
when validating whether the parent PID matches. The later NULL check
at thread__fork() does not prevent this earlier dereference.
Add a NULL guard before accessing the parent thread.
Fixes: 5cb73340d92a ("perf tools: Make fork event processing more resilient")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/machine.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/tools/perf/util/machine.c b/tools/perf/util/machine.c
index a2f5ca35141bb..8b6869582b076 100644
--- a/tools/perf/util/machine.c
+++ b/tools/perf/util/machine.c
@@ -1880,7 +1880,8 @@ int machine__process_fork_event(struct machine *machine, union perf_event *event
* (fork) event that would have removed the thread was lost. Assume the
* latter case and continue on as best we can.
*/
- if (thread__pid(parent) != (pid_t)event->fork.ppid) {
+ if (parent != NULL &&
+ thread__pid(parent) != (pid_t)event->fork.ppid) {
dump_printf("removing erroneous parent thread %d/%d\n",
thread__pid(parent), thread__tid(parent));
machine__remove_thread(machine, parent);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0781/1518] perf machine: Guard against NULL strlist in machines__findnew()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (779 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0780/1518] perf machine: Fix NULL parent dereference in fork event processing Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0782/1518] perf machine: Check snprintf truncation " Greg Kroah-Hartman
` (217 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot, David Ahern,
Arnaldo Carvalho de Melo, Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnaldo Carvalho de Melo <acme@redhat.com>
[ Upstream commit e27b96d0a34e1dc87affecf221a99fee8f6c5afc ]
The static 'seen' strlist caches guestmount paths that have already
been reported as inaccessible, to avoid repeating the error message.
If strlist__new() fails (OOM), 'seen' stays NULL and the next call
dereferences it via strlist__has_entry() and strlist__add().
Guard both calls so that on allocation failure the error message is
still printed (just not deduplicated) instead of crashing.
Fixes: c80c3c269011 ("perf kvm: Limit repetitive guestmount message to once per directory")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: David Ahern <dsahern@gmail.com>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/machine.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/tools/perf/util/machine.c b/tools/perf/util/machine.c
index 8b6869582b076..25591f9969e15 100644
--- a/tools/perf/util/machine.c
+++ b/tools/perf/util/machine.c
@@ -334,9 +334,10 @@ struct machine *machines__findnew(struct machines *machines, pid_t pid)
if (!seen)
seen = strlist__new(NULL, NULL);
- if (!strlist__has_entry(seen, path)) {
+ if (!seen || !strlist__has_entry(seen, path)) {
pr_err("Can't access file %s\n", path);
- strlist__add(seen, path);
+ if (seen)
+ strlist__add(seen, path);
}
machine = NULL;
goto out;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0782/1518] perf machine: Check snprintf truncation in machines__findnew()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (780 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0781/1518] perf machine: Guard against NULL strlist in machines__findnew() Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0783/1518] perf machine: Dont abort guest map creation on first inaccessible dir Greg Kroah-Hartman
` (216 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot, Zhang, Yanmin,
Arnaldo Carvalho de Melo, Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnaldo Carvalho de Melo <acme@redhat.com>
[ Upstream commit cc6abe0012bf8c04af8275266f8ed7c55ba4a5fb ]
The guestmount path is built with snprintf() into a PATH_MAX buffer
without checking the return value. If symbol_conf.guestmount is long
enough to cause truncation, the truncated path could match a different
directory, causing the wrong guest to be associated with the pid.
Check for truncation and bail out early.
Fixes: a1645ce12adb ("perf: 'perf kvm' tool for monitoring guest performance from host")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Zhang, Yanmin <yanmin_zhang@linux.intel.com>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/machine.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/tools/perf/util/machine.c b/tools/perf/util/machine.c
index 25591f9969e15..8455cd94756e1 100644
--- a/tools/perf/util/machine.c
+++ b/tools/perf/util/machine.c
@@ -327,7 +327,12 @@ struct machine *machines__findnew(struct machines *machines, pid_t pid)
if ((pid != HOST_KERNEL_ID) &&
(pid != DEFAULT_GUEST_KERNEL_ID) &&
(symbol_conf.guestmount)) {
- snprintf(path, sizeof(path), "%s/%d", symbol_conf.guestmount, pid);
+ if (snprintf(path, sizeof(path), "%s/%d",
+ symbol_conf.guestmount, pid) >= (int)sizeof(path)) {
+ pr_err("Guest path too long for pid %d\n", pid);
+ machine = NULL;
+ goto out;
+ }
if (access(path, R_OK)) {
static struct strlist *seen;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0783/1518] perf machine: Dont abort guest map creation on first inaccessible dir
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (781 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0782/1518] perf machine: Check snprintf truncation " Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0784/1518] perf machine: Reset errno before strtol in guest kernel map creation Greg Kroah-Hartman
` (215 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot, Zhang, Yanmin,
Arnaldo Carvalho de Melo, Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnaldo Carvalho de Melo <acme@redhat.com>
[ Upstream commit b687e1a418fb819ef83c362d84c216a6a841e3b0 ]
machines__create_guest_kernel_maps() jumps to the failure label when one
guest directory's kallsyms file fails access(), skipping all remaining
valid guest directories. An inaccessible directory is not fatal — other
guests may still be reachable.
Replace 'goto failure' with 'continue' so the loop processes all
directories, and remove the now-unreferenced failure label.
Fixes: a1645ce12adb ("perf: 'perf kvm' tool for monitoring guest performance from host")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Zhang, Yanmin <yanmin_zhang@linux.intel.com>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/machine.c | 6 ++----
1 file changed, 2 insertions(+), 4 deletions(-)
diff --git a/tools/perf/util/machine.c b/tools/perf/util/machine.c
index 8455cd94756e1..b35c73618ea02 100644
--- a/tools/perf/util/machine.c
+++ b/tools/perf/util/machine.c
@@ -1248,14 +1248,12 @@ int machines__create_guest_kernel_maps(struct machines *machines)
snprintf(path, sizeof(path), "%s/%s/proc/kallsyms",
symbol_conf.guestmount,
namelist[i]->d_name);
- ret = access(path, R_OK);
- if (ret) {
+ if (access(path, R_OK)) {
pr_debug("Can't access file %s\n", path);
- goto failure;
+ continue;
}
machines__create_kernel_maps(machines, pid);
}
-failure:
free(namelist);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0784/1518] perf machine: Reset errno before strtol in guest kernel map creation
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (782 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0783/1518] perf machine: Dont abort guest map creation on first inaccessible dir Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0785/1518] perf machine: Free scandir entries " Greg Kroah-Hartman
` (214 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot, Zhang, Yanmin,
Arnaldo Carvalho de Melo, Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnaldo Carvalho de Melo <acme@redhat.com>
[ Upstream commit 29ec46e43f6ca7d6a6651db724d4ffd820f46e8b ]
machines__create_guest_kernel_maps() checks errno == ERANGE after
strtol() to detect overflow, but does not clear errno first. A stale
ERANGE from an earlier library call (e.g. scandir internals) causes
valid numeric directory names to be incorrectly skipped.
Set errno = 0 before strtol() so only the current conversion can
trigger the ERANGE check.
Fixes: a1645ce12adb ("perf: 'perf kvm' tool for monitoring guest performance from host")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Zhang, Yanmin <yanmin_zhang@linux.intel.com>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/machine.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/tools/perf/util/machine.c b/tools/perf/util/machine.c
index b35c73618ea02..7489bc84a3d39 100644
--- a/tools/perf/util/machine.c
+++ b/tools/perf/util/machine.c
@@ -1237,6 +1237,7 @@ int machines__create_guest_kernel_maps(struct machines *machines)
/* Filter out . and .. */
continue;
}
+ errno = 0;
pid = (pid_t)strtol(namelist[i]->d_name, &endp, 10);
if ((*endp != '\0') ||
(endp == namelist[i]->d_name) ||
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0785/1518] perf machine: Free scandir entries in guest kernel map creation
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (783 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0784/1518] perf machine: Reset errno before strtol in guest kernel map creation Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0786/1518] perf machine: Check snprintf truncation for guest kallsyms path Greg Kroah-Hartman
` (213 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot, Zhang, Yanmin,
Arnaldo Carvalho de Melo, Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnaldo Carvalho de Melo <acme@redhat.com>
[ Upstream commit f53bf58dcd11e1cb088d3b91a035fef77062094b ]
machines__create_guest_kernel_maps() calls scandir() which allocates
both the namelist array and each individual dirent entry. The code
frees the namelist array but not the individual entries, leaking memory
proportional to the number of directories under guestmount.
Free each namelist[i] after it is no longer needed.
Fixes: a1645ce12adb ("perf: 'perf kvm' tool for monitoring guest performance from host")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Zhang, Yanmin <yanmin_zhang@linux.intel.com>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/machine.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/tools/perf/util/machine.c b/tools/perf/util/machine.c
index 7489bc84a3d39..5deeb41753717 100644
--- a/tools/perf/util/machine.c
+++ b/tools/perf/util/machine.c
@@ -1235,6 +1235,7 @@ int machines__create_guest_kernel_maps(struct machines *machines)
for (i = 0; i < items; i++) {
if (!isdigit(namelist[i]->d_name[0])) {
/* Filter out . and .. */
+ free(namelist[i]);
continue;
}
errno = 0;
@@ -1244,6 +1245,7 @@ int machines__create_guest_kernel_maps(struct machines *machines)
(errno == ERANGE)) {
pr_debug("invalid directory (%s). Skipping.\n",
namelist[i]->d_name);
+ free(namelist[i]);
continue;
}
snprintf(path, sizeof(path), "%s/%s/proc/kallsyms",
@@ -1251,9 +1253,11 @@ int machines__create_guest_kernel_maps(struct machines *machines)
namelist[i]->d_name);
if (access(path, R_OK)) {
pr_debug("Can't access file %s\n", path);
+ free(namelist[i]);
continue;
}
machines__create_kernel_maps(machines, pid);
+ free(namelist[i]);
}
free(namelist);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0786/1518] perf machine: Check snprintf truncation for guest kallsyms path
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (784 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0785/1518] perf machine: Free scandir entries " Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0787/1518] bpf, x86: Fix trampoline stack size for 128-bit arguments Greg Kroah-Hartman
` (212 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot, Zhang, Yanmin,
Arnaldo Carvalho de Melo, Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnaldo Carvalho de Melo <acme@redhat.com>
[ Upstream commit d04ef71492fad7230d474efe33d05f4c0563d409 ]
machines__create_guest_kernel_maps() builds the guest kallsyms path
with snprintf() without checking the return value. A truncated path
could pass the access() check if a prefix directory happens to contain
a file named "kallsyms", leading to the wrong file being used for
symbol resolution.
Check for truncation and skip the directory.
Fixes: a1645ce12adb ("perf: 'perf kvm' tool for monitoring guest performance from host")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Zhang, Yanmin <yanmin_zhang@linux.intel.com>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/machine.c | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
diff --git a/tools/perf/util/machine.c b/tools/perf/util/machine.c
index 5deeb41753717..cb138d1bdd7b9 100644
--- a/tools/perf/util/machine.c
+++ b/tools/perf/util/machine.c
@@ -1248,9 +1248,14 @@ int machines__create_guest_kernel_maps(struct machines *machines)
free(namelist[i]);
continue;
}
- snprintf(path, sizeof(path), "%s/%s/proc/kallsyms",
- symbol_conf.guestmount,
- namelist[i]->d_name);
+ if (snprintf(path, sizeof(path), "%s/%s/proc/kallsyms",
+ symbol_conf.guestmount,
+ namelist[i]->d_name) >= (int)sizeof(path)) {
+ pr_debug("Guest kallsyms path too long for %s. Skipping.\n",
+ namelist[i]->d_name);
+ free(namelist[i]);
+ continue;
+ }
if (access(path, R_OK)) {
pr_debug("Can't access file %s\n", path);
free(namelist[i]);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0787/1518] bpf, x86: Fix trampoline stack size for 128-bit arguments
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (785 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0786/1518] perf machine: Check snprintf truncation for guest kallsyms path Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0788/1518] wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement Greg Kroah-Hartman
` (211 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yonghong Song, Leon Hwang,
Kumar Kartikeya Dwivedi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yonghong Song <yonghong.song@linux.dev>
[ Upstream commit 814cba835ef648e0c5eb79505c96c0493b29eea6 ]
btf_distill_func_proto() accepts a function argument up to 16 bytes, so a
128-bit scalar such as __int128 reaches the x86 trampoline with
arg_size == 16. But the current implementation assumes an __int128
argument only needs one register, so the register save area is
under-allocated and save_args() overwrites adjacent stack slots.
Compute the register count from arg_size for all arguments to fix it.
Fixes: a9c5ad31fbdc ("bpf: x86: Support in-register struct arguments in trampoline programs")
Signed-off-by: Yonghong Song <yonghong.song@linux.dev>
Acked-by: Leon Hwang <leon.hwang@linux.dev>
Link: https://lore.kernel.org/bpf/20260729050204.2586457-1-yonghong.song@linux.dev
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/net/bpf_jit_comp.c | 7 ++-----
1 file changed, 2 insertions(+), 5 deletions(-)
diff --git a/arch/x86/net/bpf_jit_comp.c b/arch/x86/net/bpf_jit_comp.c
index 88a1bbfa918fa..cfd44906c31dd 100644
--- a/arch/x86/net/bpf_jit_comp.c
+++ b/arch/x86/net/bpf_jit_comp.c
@@ -3187,11 +3187,8 @@ static int __arch_prepare_bpf_trampoline(struct bpf_tramp_image *im, void *rw_im
WARN_ON_ONCE((flags & BPF_TRAMP_F_INDIRECT) &&
(flags & ~(BPF_TRAMP_F_INDIRECT | BPF_TRAMP_F_RET_FENTRY_RET)));
- /* extra registers for struct arguments */
- for (i = 0; i < m->nr_args; i++) {
- if (m->arg_flags[i] & BTF_FMODEL_STRUCT_ARG)
- nr_regs += (m->arg_size[i] + 7) / 8 - 1;
- }
+ for (i = 0; i < m->nr_args; i++)
+ nr_regs += (m->arg_size[i] + 7) / 8 - 1;
/* x86-64 supports up to MAX_BPF_FUNC_ARGS arguments. 1-6
* are passed through regs, the remains are through stack.
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0788/1518] wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (786 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0787/1518] bpf, x86: Fix trampoline stack size for 128-bit arguments Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0789/1518] wifi: mt76: mt7996: skip key upload when adding an offchannel link Greg Kroah-Hartman
` (210 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit 16a04441eab0dcd4d7126a6f66b370adbf28f96d ]
The flow is added to dev->twt_list before sending the agreement to the
firmware, but the error path leaves it linked while flowid_mask is
never set. The flow slot can then be reused and memset while still on
the list, corrupting twt_list, and station removal leaves a dangling
entry behind that mt7915_mac_twt_sched_list_add() later walks.
Fixes: 3782b69d03e7 ("mt76: mt7915: introduce mt7915_mac_add_twt_setup routine")
Link: https://patch.msgid.link/20260724124813.3961474-17-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7915/mac.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7915/mac.c b/drivers/net/wireless/mediatek/mt76/mt7915/mac.c
index 50af0d9f240b6..d79af9321ec79 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7915/mac.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7915/mac.c
@@ -2345,8 +2345,10 @@ void mt7915_mac_add_twt_setup(struct ieee80211_hw *hw,
}
flow->tsf = le64_to_cpu(twt_agrt->twt);
- if (mt7915_mcu_twt_agrt_update(dev, msta->vif, flow, MCU_TWT_AGRT_ADD))
+ if (mt7915_mcu_twt_agrt_update(dev, msta->vif, flow, MCU_TWT_AGRT_ADD)) {
+ list_del(&flow->list);
goto unlock;
+ }
setup_cmd = TWT_SETUP_CMD_ACCEPT;
dev->twt.table_mask |= BIT(table_id);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0789/1518] wifi: mt76: mt7996: skip key upload when adding an offchannel link
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (787 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0788/1518] wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0790/1518] wifi: mt76: mt7996: wake MCU waiters before aborting scan in L1 SER Greg Kroah-Hartman
` (209 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit ccb4bda277999959bc852480d8684b13b926e657 ]
No hw keys are ever uploaded for scanning/roc links and the link remove
path already skips the key iteration for them. The add path still runs
it, and since mt7996_set_hw_key() resolves the target through
mvif->link[link_id] rather than the offchannel link, starting a scan on
another band re-uploads the group keys of the link sharing the same
link_id, re-sending its BSS cipher info and, for BIGTK with beacon
protection on an AP link, toggling its beacons off and on.
Skip the key iteration for offchannel links, mirroring the remove path.
Fixes: 69d54ce7491d ("wifi: mt76: mt7996: switch to single multi-radio wiphy")
Link: https://patch.msgid.link/20260724124813.3961474-18-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7996/main.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/main.c b/drivers/net/wireless/mediatek/mt76/mt7996/main.c
index 45cdbe727c8b7..a319a99b5056e 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/main.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/main.c
@@ -362,7 +362,8 @@ int mt7996_vif_link_add(struct mt76_phy *mphy, struct ieee80211_vif *vif,
CONN_STATE_PORT_SECURE, true);
rcu_assign_pointer(dev->mt76.wcid[idx], &msta_link->wcid);
- ieee80211_iter_keys(mphy->hw, vif, mt7996_key_iter, &it);
+ if (!mlink->wcid->offchannel)
+ ieee80211_iter_keys(mphy->hw, vif, mt7996_key_iter, &it);
if (vif->txq && !mlink->wcid->offchannel &&
mvif->mt76.deflink_id == IEEE80211_LINK_UNSPECIFIED) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0790/1518] wifi: mt76: mt7996: wake MCU waiters before aborting scan in L1 SER
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (788 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0789/1518] wifi: mt76: mt7996: skip key upload when adding an offchannel link Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0791/1518] wifi: mt76: mt7996: free vif links after clearing wcid entries on full reset Greg Kroah-Hartman
` (208 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit 6f8d8c458010b597bf4114e6fb3162bff7050041 ]
The L1 reset path calls mt76_abort_scan() between setting MT76_MCU_RESET
and waking mcu.wait. A scan work blocked on an in-flight MCU command
does not re-evaluate its wait condition until woken, so the
cancel_delayed_work_sync() inside the abort sleeps out the full MCU
timeout before recovery can proceed, adding several seconds of SER
latency. mt7996_mac_full_reset() and the mt7915 counterpart already
order the wake-up first.
Wake mcu.wait immediately after setting MT76_MCU_RESET so in-flight
commands bail out before the abort synchronises against them.
Fixes: b36d55610215 ("wifi: mt76: abort scan/roc on hw restart")
Link: https://patch.msgid.link/20260724124813.3961474-19-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7996/mac.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/mac.c b/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
index cafdbd27f1e48..35a34fc346eb7 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
@@ -2620,8 +2620,8 @@ void mt7996_mac_reset_work(struct work_struct *work)
set_bit(MT76_RESET, &dev->mphy.state);
set_bit(MT76_MCU_RESET, &dev->mphy.state);
- mt76_abort_scan(&dev->mt76);
wake_up(&dev->mt76.mcu.wait);
+ mt76_abort_scan(&dev->mt76);
cancel_work_sync(&dev->wed_rro.work);
mt7996_for_each_phy(dev, phy) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0791/1518] wifi: mt76: mt7996: free vif links after clearing wcid entries on full reset
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (789 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0790/1518] wifi: mt76: mt7996: wake MCU waiters before aborting scan in L1 SER Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0792/1518] wifi: mt76: mt7996: fix MIB TX aggregation counter registers for mt7990 Greg Kroah-Hartman
` (207 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit 7e4208e9f6a876c2b7d28fdb6b86dff3b05db2f7 ]
mt7996_mac_reset_vif_iter() queues non-default vif links for kfree_rcu
while dev->wcid[] still holds pointers to the wcid embedded in each
freed link; mt76_reset_device() then dereferences those entries and
runs mt76_wcid_cleanup() on them. If a grace period elapses in between,
the cleanup operates on freed memory.
Run mt76_reset_device() first, so the wcid entries are cleaned up and
cleared while the links are still valid.
Fixes: ace5d3b6b49e ("wifi: mt76: mt7996: improve hardware restart reliability")
Link: https://patch.msgid.link/20260724124813.3961474-25-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7996/mac.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/mac.c b/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
index 35a34fc346eb7..dc1a3e91218ad 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mac.c
@@ -2539,10 +2539,10 @@ mt7996_mac_full_reset(struct mt7996_dev *dev)
phy->omac_mask = 0;
ieee80211_iterate_stations_atomic(hw, mt7996_mac_reset_sta_iter, dev);
+ mt76_reset_device(&dev->mt76);
ieee80211_iterate_active_interfaces_atomic(hw,
IEEE80211_IFACE_SKIP_SDATA_NOT_IN_DRIVER,
mt7996_mac_reset_vif_iter, dev);
- mt76_reset_device(&dev->mt76);
INIT_LIST_HEAD(&dev->sta_rc_list);
INIT_LIST_HEAD(&dev->twt_list);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0792/1518] wifi: mt76: mt7996: fix MIB TX aggregation counter registers for mt7990
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (790 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0791/1518] wifi: mt76: mt7996: free vif links after clearing wcid entries on full reset Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0793/1518] wifi: mt76: mt7915: fix double hif2 init on the non-WED path Greg Kroah-Hartman
` (206 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit d0b750072a29c8ff0504c3bc28c411c402f26716 ]
The MIB_TSCR0-7 counters read by mt7996_mac_update_stats() are
hardcoded at the mt7996/mt7992 offsets 0x6b0-0x6d0, but mt7990 moved
them to 0x750-0x770, so TX AMPDU statistics were read from unrelated
registers on that chip. Move the offsets into the per-chip register
tables.
Fixes: f6c87411d15f ("wifi: mt76: mt7996: rework register mapping for mt7990")
Link: https://patch.msgid.link/20260727150434.1778520-1-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../net/wireless/mediatek/mt76/mt7996/mmio.c | 24 +++++++++++++++++++
.../net/wireless/mediatek/mt76/mt7996/regs.h | 24 ++++++++++++-------
2 files changed, 40 insertions(+), 8 deletions(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/mmio.c b/drivers/net/wireless/mediatek/mt76/mt7996/mmio.c
index 80db102ed809c..ed292c617168c 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mmio.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mmio.c
@@ -54,6 +54,14 @@ static const u32 mt7996_offs[] = {
[MIB_BSCR7] = 0x9e8,
[MIB_BSCR17] = 0xa10,
[MIB_TRDR1] = 0xa28,
+ [MIB_TSCR0] = 0x6b0,
+ [MIB_TSCR1] = 0x6b4,
+ [MIB_TSCR2] = 0x6b8,
+ [MIB_TSCR3] = 0x6bc,
+ [MIB_TSCR4] = 0x6c0,
+ [MIB_TSCR5] = 0x6c4,
+ [MIB_TSCR6] = 0x6c8,
+ [MIB_TSCR7] = 0x6d0,
[HIF_REMAP_L1] = 0x24,
[HIF_REMAP_BASE_L1] = 0x130000,
[HIF_REMAP_L2] = 0x1b4,
@@ -91,6 +99,14 @@ static const u32 mt7992_offs[] = {
[MIB_BSCR7] = 0xae4,
[MIB_BSCR17] = 0xb0c,
[MIB_TRDR1] = 0xb24,
+ [MIB_TSCR0] = 0x6b0,
+ [MIB_TSCR1] = 0x6b4,
+ [MIB_TSCR2] = 0x6b8,
+ [MIB_TSCR3] = 0x6bc,
+ [MIB_TSCR4] = 0x6c0,
+ [MIB_TSCR5] = 0x6c4,
+ [MIB_TSCR6] = 0x6c8,
+ [MIB_TSCR7] = 0x6d0,
[HIF_REMAP_L1] = 0x8,
[HIF_REMAP_BASE_L1] = 0x40000,
[HIF_REMAP_L2] = 0x1b4,
@@ -128,6 +144,14 @@ static const u32 mt7990_offs[] = {
[MIB_BSCR7] = 0xbd4,
[MIB_BSCR17] = 0xbfc,
[MIB_TRDR1] = 0xc14,
+ [MIB_TSCR0] = 0x750,
+ [MIB_TSCR1] = 0x754,
+ [MIB_TSCR2] = 0x758,
+ [MIB_TSCR3] = 0x75c,
+ [MIB_TSCR4] = 0x760,
+ [MIB_TSCR5] = 0x764,
+ [MIB_TSCR6] = 0x768,
+ [MIB_TSCR7] = 0x770,
[HIF_REMAP_L1] = 0x8,
[HIF_REMAP_BASE_L1] = 0x40000,
[HIF_REMAP_L2] = 0x1b8,
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/regs.h b/drivers/net/wireless/mediatek/mt76/mt7996/regs.h
index 0fa325f87fcd9..a46c790550c62 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/regs.h
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/regs.h
@@ -64,6 +64,14 @@ enum offs_rev {
MIB_BSCR7,
MIB_BSCR17,
MIB_TRDR1,
+ MIB_TSCR0,
+ MIB_TSCR1,
+ MIB_TSCR2,
+ MIB_TSCR3,
+ MIB_TSCR4,
+ MIB_TSCR5,
+ MIB_TSCR6,
+ MIB_TSCR7,
HIF_REMAP_L1,
HIF_REMAP_BASE_L1,
HIF_REMAP_L2,
@@ -247,9 +255,9 @@ enum offs_rev {
#define MT_MIB_BSCR7(_band) MT_WF_MIB(_band, __OFFS(MIB_BSCR7))
#define MT_MIB_BSCR17(_band) MT_WF_MIB(_band, __OFFS(MIB_BSCR17))
-#define MT_MIB_TSCR5(_band) MT_WF_MIB(_band, 0x6c4)
-#define MT_MIB_TSCR6(_band) MT_WF_MIB(_band, 0x6c8)
-#define MT_MIB_TSCR7(_band) MT_WF_MIB(_band, 0x6d0)
+#define MT_MIB_TSCR5(_band) MT_WF_MIB(_band, __OFFS(MIB_TSCR5))
+#define MT_MIB_TSCR6(_band) MT_WF_MIB(_band, __OFFS(MIB_TSCR6))
+#define MT_MIB_TSCR7(_band) MT_WF_MIB(_band, __OFFS(MIB_TSCR7))
#define MT_MIB_RSCR1(_band) MT_WF_MIB(_band, __OFFS(MIB_RSCR1))
/* rx mpdu counter, full 32 bits */
@@ -265,14 +273,14 @@ enum offs_rev {
#define MT_MIB_RSCR36(_band) MT_WF_MIB(_band, __OFFS(MIB_RSCR36))
/* tx ampdu cnt, full 32 bits */
-#define MT_MIB_TSCR0(_band) MT_WF_MIB(_band, 0x6b0)
-#define MT_MIB_TSCR2(_band) MT_WF_MIB(_band, 0x6b8)
+#define MT_MIB_TSCR0(_band) MT_WF_MIB(_band, __OFFS(MIB_TSCR0))
+#define MT_MIB_TSCR2(_band) MT_WF_MIB(_band, __OFFS(MIB_TSCR2))
/* counts all mpdus in ampdu, regardless of success */
-#define MT_MIB_TSCR3(_band) MT_WF_MIB(_band, 0x6bc)
+#define MT_MIB_TSCR3(_band) MT_WF_MIB(_band, __OFFS(MIB_TSCR3))
/* counts all successfully tx'd mpdus in ampdu */
-#define MT_MIB_TSCR4(_band) MT_WF_MIB(_band, 0x6c0)
+#define MT_MIB_TSCR4(_band) MT_WF_MIB(_band, __OFFS(MIB_TSCR4))
/* rx ampdu count, 32-bit */
#define MT_MIB_RSCR27(_band) MT_WF_MIB(_band, __OFFS(MIB_RSCR27))
@@ -296,7 +304,7 @@ enum offs_rev {
#define MT_MIB_RVSR1(_band) MT_WF_MIB(_band, __OFFS(MIB_RVSR1))
/* rx blockack count, 32 bits */
-#define MT_MIB_TSCR1(_band) MT_WF_MIB(_band, 0x6b4)
+#define MT_MIB_TSCR1(_band) MT_WF_MIB(_band, __OFFS(MIB_TSCR1))
#define MT_MIB_BTSCR0(_band) MT_WF_MIB(_band, 0x5e0)
#define MT_MIB_BTSCR5(_band) MT_WF_MIB(_band, __OFFS(MIB_BTSCR5))
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0793/1518] wifi: mt76: mt7915: fix double hif2 init on the non-WED path
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (791 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0792/1518] wifi: mt76: mt7996: fix MIB TX aggregation counter registers for mt7990 Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0794/1518] wifi: mt76: mt7915: fix ext PHY use-after-free on register error path Greg Kroah-Hartman
` (205 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit 3ae8ad277e2819a281b0e36b55633c8515c16ce7 ]
mt7915_pci_init_hif2() was called unconditionally and again inside the
WED-inactive branch. The helper increments the global hif_idx, writes the
PCIe RECOG_ID register and takes a get_device() reference via
mt7915_pci_get_hif2(), while removal only drops one reference. On non-WED
dual-hif hardware this double-incremented hif_idx, wrote RECOG_ID twice and
leaked a device reference. Only the call inside the WED-inactive branch is
correct; drop the unconditional one. hif2 is already initialised to NULL.
Fixes: cacdd67812c6 ("mt76: mt7915: add mt7915_mmio_probe() as a common probing function")
Link: https://patch.msgid.link/20260727150434.1778520-2-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7915/pci.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7915/pci.c b/drivers/net/wireless/mediatek/mt76/mt7915/pci.c
index 07b0a5766eab7..5a0c9eeb2c4e2 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7915/pci.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7915/pci.c
@@ -135,7 +135,6 @@ static int mt7915_pci_probe(struct pci_dev *pdev,
mdev = &dev->mt76;
mt7915_wfsys_reset(dev);
- hif2 = mt7915_pci_init_hif2(pdev);
ret = mt7915_mmio_wed_init(dev, pdev, true, &irq);
if (ret < 0)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0794/1518] wifi: mt76: mt7915: fix ext PHY use-after-free on register error path
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (792 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0793/1518] wifi: mt76: mt7915: fix double hif2 init on the non-WED path Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0795/1518] wifi: mt76: mt7915: release hif2 reference on probe IRQ failure Greg Kroah-Hartman
` (204 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit 15b960014f24dce5388d4a2e7274e6490cb3c421 ]
After mt7915_register_ext_phy() succeeded, a failure of the main PHY
mt7915_init_debugfs() or mt7915_coredump_register() unwound through
free_phy2, which called ieee80211_free_hw() on the ext PHY hw while it
was still registered with mac80211, since mt76_unregister_device() only
unregisters the main hw. Unregister the ext PHY (thermal + phy + hw)
first and skip the redundant free.
Fixes: 7b8e1ae886e4 ("mt76: mt7915: rework hardware/phy initialization")
Link: https://patch.msgid.link/20260727150434.1778520-3-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7915/init.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7915/init.c b/drivers/net/wireless/mediatek/mt76/mt7915/init.c
index d2b163a5fce5b..f247846520138 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7915/init.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7915/init.c
@@ -1265,14 +1265,19 @@ int mt7915_register_device(struct mt7915_dev *dev)
ret = mt7915_init_debugfs(&dev->phy);
if (ret)
- goto unreg_thermal;
+ goto unreg_ext_phy;
ret = mt7915_coredump_register(dev);
if (ret)
- goto unreg_thermal;
+ goto unreg_ext_phy;
return 0;
+unreg_ext_phy:
+ if (phy2) {
+ mt7915_unregister_ext_phy(dev);
+ phy2 = NULL;
+ }
unreg_thermal:
mt7915_unregister_thermal(&dev->phy);
unreg_dev:
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0795/1518] wifi: mt76: mt7915: release hif2 reference on probe IRQ failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (793 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0794/1518] wifi: mt76: mt7915: fix ext PHY use-after-free on register error path Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0796/1518] wifi: mt76: mt7996: fix reg addr remap when addr is 0 Greg Kroah-Hartman
` (203 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit 8370aebd26a9dfa2e0de665e3ab504c0e97ee730 ]
The hif2 reference obtained by mt7915_pci_init_hif2() is only released on
error paths that key off dev->hif2, which is not assigned until after the
IRQ setup. If pci_alloc_irq_vectors() or the primary devm_request_irq()
fails, the reference leaks. Drop it explicitly on those paths via
mt7915_put_hif2().
Fixes: f68d67623dec ("mt76: mt7915: add Wireless Ethernet Dispatch support")
Link: https://patch.msgid.link/20260727150434.1778520-4-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7915/pci.c | 8 ++++++--
1 file changed, 6 insertions(+), 2 deletions(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7915/pci.c b/drivers/net/wireless/mediatek/mt76/mt7915/pci.c
index 5a0c9eeb2c4e2..c24f1b12f064f 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7915/pci.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7915/pci.c
@@ -144,16 +144,20 @@ static int mt7915_pci_probe(struct pci_dev *pdev,
hif2 = mt7915_pci_init_hif2(pdev);
ret = pci_alloc_irq_vectors(pdev, 1, 1, PCI_IRQ_ALL_TYPES);
- if (ret < 0)
+ if (ret < 0) {
+ mt7915_put_hif2(hif2);
goto free_device;
+ }
irq = pdev->irq;
}
ret = devm_request_irq(mdev->dev, irq, mt7915_irq_handler,
IRQF_SHARED, KBUILD_MODNAME, dev);
- if (ret)
+ if (ret) {
+ mt7915_put_hif2(hif2);
goto free_wed_or_irq_vector;
+ }
/* master switch of PCIe tnterrupt enable */
mt76_wr(dev, MT_PCIE_MAC_INT_ENABLE, 0xff);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0796/1518] wifi: mt76: mt7996: fix reg addr remap when addr is 0
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (794 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0795/1518] wifi: mt76: mt7915: release hif2 reference on probe IRQ failure Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0797/1518] wifi: mt76: mt7996: do not attach hif2 WED when the main WED attach failed Greg Kroah-Hartman
` (202 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, StanleyYP Wang, Felix Fietkau,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: StanleyYP Wang <StanleyYP.Wang@mediatek.com>
[ Upstream commit eb906eeff2d1e84b628dc210dada325269c71383 ]
When addr is less than the hardcoded threshold in __mt7996_reg_addr,
it indicates that remapping is unnecessary.
Currently, the flow remaps address 0x0 to MT_HIF_REMAP_BASE_L2,
which is incorrect.
To address this, modify __mt7996_reg_addr to return INVALID_REG_ADDR
if the address is not below the hardcoded value or is not present in
the mt7996_reg_map array.
Additionally, update the remap condition to check if addr is equal to
INVALID_REG_ADDR.
Fixes: 3687854d3e7e ("wifi: mt76: mt7996: add locking for accessing mapped registers")
Signed-off-by: StanleyYP Wang <StanleyYP.Wang@mediatek.com>
Link: https://patch.msgid.link/20260727150434.1778520-5-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7996/mmio.c | 12 +++++++-----
1 file changed, 7 insertions(+), 5 deletions(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/mmio.c b/drivers/net/wireless/mediatek/mt76/mt7996/mmio.c
index ed292c617168c..4f63dcb19b259 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mmio.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mmio.c
@@ -17,6 +17,8 @@
static bool wed_enable;
module_param(wed_enable, bool, 0644);
+#define INVALID_REG_ADDR 0xffffffff
+
static const struct __base mt7996_reg_base[] = {
[WF_AGG_BASE] = { { 0x820e2000, 0x820f2000, 0x830e2000 } },
[WF_ARB_BASE] = { { 0x820e3000, 0x820f3000, 0x830e3000 } },
@@ -358,7 +360,7 @@ static u32 __mt7996_reg_addr(struct mt7996_dev *dev, u32 addr)
return dev->reg.map[i].mapped + ofs;
}
- return 0;
+ return INVALID_REG_ADDR;
}
static u32 __mt7996_reg_remap_addr(struct mt7996_dev *dev, u32 addr)
@@ -390,7 +392,7 @@ void mt7996_memcpy_fromio(struct mt7996_dev *dev, void *buf, u32 offset,
{
u32 addr = __mt7996_reg_addr(dev, offset);
- if (addr) {
+ if (addr != INVALID_REG_ADDR) {
memcpy_fromio(buf, dev->mt76.mmio.regs + addr, len);
return;
}
@@ -406,7 +408,7 @@ static u32 mt7996_rr(struct mt76_dev *mdev, u32 offset)
struct mt7996_dev *dev = container_of(mdev, struct mt7996_dev, mt76);
u32 addr = __mt7996_reg_addr(dev, offset), val;
- if (addr)
+ if (addr != INVALID_REG_ADDR)
return dev->bus_ops->rr(mdev, addr);
spin_lock_bh(&dev->reg_lock);
@@ -421,7 +423,7 @@ static void mt7996_wr(struct mt76_dev *mdev, u32 offset, u32 val)
struct mt7996_dev *dev = container_of(mdev, struct mt7996_dev, mt76);
u32 addr = __mt7996_reg_addr(dev, offset);
- if (addr) {
+ if (addr != INVALID_REG_ADDR) {
dev->bus_ops->wr(mdev, addr, val);
return;
}
@@ -436,7 +438,7 @@ static u32 mt7996_rmw(struct mt76_dev *mdev, u32 offset, u32 mask, u32 val)
struct mt7996_dev *dev = container_of(mdev, struct mt7996_dev, mt76);
u32 addr = __mt7996_reg_addr(dev, offset);
- if (addr)
+ if (addr != INVALID_REG_ADDR)
return dev->bus_ops->rmw(mdev, addr, mask, val);
spin_lock_bh(&dev->reg_lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0797/1518] wifi: mt76: mt7996: do not attach hif2 WED when the main WED attach failed
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (795 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0796/1518] wifi: mt76: mt7996: fix reg addr remap when addr is 0 Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0798/1518] wifi: mt76: mt7915: fix chainmask handling for non-dbdc phys on band 1 Greg Kroah-Hartman
` (201 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit 7c1924332e986019c6bcddf55c843361cccac73f ]
If the WED attach for the primary PCIe function fails, the probe path
still attached wed_hif2 for the secondary function, leaving the device
in an inconsistent half-WED configuration that crashes later. The hif2
call also re-enabled hwrro_mode, which the failed primary attach had
just turned off.
Skip the hif2 WED setup when the primary WED device is not active.
Fixes: 83eafc9251d6 ("wifi: mt76: mt7996: add wed tx support")
Link: https://patch.msgid.link/20260727150434.1778520-6-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7996/mmio.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/mmio.c b/drivers/net/wireless/mediatek/mt76/mt7996/mmio.c
index 4f63dcb19b259..e37b95f5b00b8 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/mmio.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/mmio.c
@@ -490,6 +490,9 @@ int mt7996_mmio_wed_init(struct mt7996_dev *dev, void *pdev_ptr,
if (!wed_enable)
return 0;
+ if (hif2 && !mtk_wed_device_active(&dev->mt76.mmio.wed))
+ return 0;
+
dev->mt76.hwrro_mode = is_mt7996(&dev->mt76) ? MT76_HWRRO_V3
: MT76_HWRRO_V3_1;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0798/1518] wifi: mt76: mt7915: fix chainmask handling for non-dbdc phys on band 1
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (796 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0797/1518] wifi: mt76: mt7996: do not attach hif2 WED when the main WED attach failed Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0799/1518] wifi: mt76: mt7915: report RX chain signal for all RX paths Greg Kroah-Hartman
` (200 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit ea891799eccc9e43ebba0dc157d4b197ad6c1a0e ]
On single-adie mt7986 the only phy is bound to band 1, but its chainmask
is stored unshifted, because dev->chainshift is still zero while the
eeprom is parsed for the main phy. mt7915_set_antenna() on the other
hand shifts by chainshift * band_idx, so the representation of the
chainmask changed as soon as the antenna configuration was touched.
Until then, mt7915_mcu_set_chan_info() passed rx_path = 0 to the
firmware, since shifting the unshifted mask down clears all bits.
Keep the unshifted form for that case and add helpers for the band local
chainmask, so that only the band 1 phy of a dbdc device uses the shifted
form.
Fixes: 3eb50cc90534 ("wifi: mt76: mt7915: rely on band_idx of mt76_phy")
Link: https://patch.msgid.link/20260727150434.1778520-8-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../net/wireless/mediatek/mt76/mt7915/eeprom.c | 2 +-
.../net/wireless/mediatek/mt76/mt7915/main.c | 6 +++---
.../net/wireless/mediatek/mt76/mt7915/mcu.c | 2 +-
.../net/wireless/mediatek/mt76/mt7915/mt7915.h | 18 ++++++++++++++++++
.../wireless/mediatek/mt76/mt7915/testmode.c | 5 +----
5 files changed, 24 insertions(+), 9 deletions(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7915/eeprom.c b/drivers/net/wireless/mediatek/mt76/mt7915/eeprom.c
index 38dfd5de365ca..14c0770229bc5 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7915/eeprom.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7915/eeprom.c
@@ -257,7 +257,7 @@ void mt7915_eeprom_parse_hw_cap(struct mt7915_dev *dev,
nss = min_t(u8, min_t(u8, nss_max, nss), path);
mphy->chainmask = BIT(path) - 1;
- if (band)
+ if (band && dev->dbdc_support)
mphy->chainmask <<= dev->chainshift;
mphy->antenna_mask = BIT(nss) - 1;
dev->chainmask |= mphy->chainmask;
diff --git a/drivers/net/wireless/mediatek/mt76/mt7915/main.c b/drivers/net/wireless/mediatek/mt76/mt7915/main.c
index 3c1d388b200a0..9d546eb8022ac 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7915/main.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7915/main.c
@@ -1133,7 +1133,7 @@ mt7915_set_antenna(struct ieee80211_hw *hw, int radio_idx, u32 tx_ant, u32 rx_an
struct mt7915_dev *dev = mt7915_hw_dev(hw);
struct mt7915_phy *phy = mt7915_hw_phy(hw);
int max_nss = hweight8(hw->wiphy->available_antennas_tx);
- u8 chainshift = dev->chainshift;
+ u8 shift = mt7915_band_chainshift(phy);
u8 band = phy->mt76->band_idx;
if (!tx_ant || tx_ant != rx_ant || ffs(tx_ant) > max_nss)
@@ -1146,9 +1146,9 @@ mt7915_set_antenna(struct ieee80211_hw *hw, int radio_idx, u32 tx_ant, u32 rx_an
/* handle a variant of mt7916/mt7981 which has 3T3R but nss2 on 5 GHz band */
if ((is_mt7916(&dev->mt76) || is_mt7981(&dev->mt76)) &&
band && hweight8(tx_ant) == max_nss)
- phy->mt76->chainmask = (dev->chainmask >> chainshift) << chainshift;
+ phy->mt76->chainmask = (dev->chainmask >> shift) << shift;
else
- phy->mt76->chainmask = tx_ant << (chainshift * band);
+ phy->mt76->chainmask = tx_ant << shift;
mt76_set_stream_caps(phy->mt76, true);
mt7915_set_stream_vht_txbf_caps(phy);
diff --git a/drivers/net/wireless/mediatek/mt76/mt7915/mcu.c b/drivers/net/wireless/mediatek/mt76/mt7915/mcu.c
index f3abc0de167a3..29b3f0cda1ce7 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7915/mcu.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7915/mcu.c
@@ -2804,7 +2804,7 @@ int mt7915_mcu_set_chan_info(struct mt7915_phy *phy, int cmd)
.center_ch = ieee80211_frequency_to_channel(freq1),
.bw = mt76_connac_chan_bw(chandef),
.tx_path_num = hweight16(phy->mt76->chainmask),
- .rx_path = phy->mt76->chainmask >> (dev->chainshift * band),
+ .rx_path = mt7915_band_chainmask(phy),
.band_idx = band,
.channel_band = ch_band[chandef->chan->band],
};
diff --git a/drivers/net/wireless/mediatek/mt76/mt7915/mt7915.h b/drivers/net/wireless/mediatek/mt76/mt7915/mt7915.h
index f1194d147dc89..27857347f05f4 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7915/mt7915.h
+++ b/drivers/net/wireless/mediatek/mt76/mt7915/mt7915.h
@@ -393,6 +393,24 @@ mt7915_ext_phy(struct mt7915_dev *dev)
return phy->priv;
}
+/* without dbdc, the chainmask is stored unshifted, even if the phy is
+ * bound to band 1
+ */
+static inline u8 mt7915_band_chainshift(struct mt7915_phy *phy)
+{
+ struct mt7915_dev *dev = phy->dev;
+
+ if (!dev->dbdc_support)
+ return 0;
+
+ return phy->mt76->band_idx * dev->chainshift;
+}
+
+static inline u16 mt7915_band_chainmask(struct mt7915_phy *phy)
+{
+ return phy->mt76->chainmask >> mt7915_band_chainshift(phy);
+}
+
static inline u32 mt7915_check_adie(struct mt7915_dev *dev, bool sku)
{
u32 mask = sku ? MT_CONNINFRA_SKU_MASK : MT_ADIE_TYPE_MASK;
diff --git a/drivers/net/wireless/mediatek/mt76/mt7915/testmode.c b/drivers/net/wireless/mediatek/mt76/mt7915/testmode.c
index d534fff5c952b..2a9e5d9ff101c 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7915/testmode.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7915/testmode.c
@@ -694,9 +694,7 @@ mt7915_tm_set_params(struct mt76_phy *mphy, struct nlattr **tb,
{
struct mt76_testmode_data *td = &mphy->test;
struct mt7915_phy *phy = mphy->priv;
- struct mt7915_dev *dev = phy->dev;
- u32 chainmask = mphy->chainmask, changed = 0;
- bool ext_phy = phy != &dev->phy;
+ u32 chainmask = mt7915_band_chainmask(phy), changed = 0;
int i;
BUILD_BUG_ON(NUM_TM_CHANGED >= 32);
@@ -705,7 +703,6 @@ mt7915_tm_set_params(struct mt76_phy *mphy, struct nlattr **tb,
td->state == MT76_TM_STATE_OFF)
return 0;
- chainmask = ext_phy ? chainmask >> dev->chainshift : chainmask;
if (td->tx_antenna_mask > chainmask)
return -EINVAL;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0799/1518] wifi: mt76: mt7915: report RX chain signal for all RX paths
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (797 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0798/1518] wifi: mt76: mt7915: fix chainmask handling for non-dbdc phys on band 1 Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0800/1518] wifi: mt76: fix queue assignment for disassoc packets Greg Kroah-Hartman
` (199 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit b53c44fe65792608f58028c7b0953e610ad652ee ]
status->chains was set from the antenna mask, which is derived from the
number of spatial streams, while the chain_signal array is filled from
all RCPI fields. On boards where the number of RX paths exceeds the
stream count, e.g. the 3T3R mt7916/mt7981 variant with 2 streams on the
5 GHz band, the RSSI of the extra chains was never reported.
Use the band local RX path chainmask instead.
Fixes: e57b7901469f ("mt76: add mac80211 driver for MT7915 PCIe-based chipsets")
Link: https://patch.msgid.link/20260727150434.1778520-9-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7915/mac.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7915/mac.c b/drivers/net/wireless/mediatek/mt76/mt7915/mac.c
index d79af9321ec79..dda4e7d179536 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7915/mac.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7915/mac.c
@@ -437,7 +437,7 @@ mt7915_mac_fill_rx(struct mt7915_dev *dev, struct sk_buff *skb,
if (v0 & MT_PRXV_HT_AD_CODE)
status->enc_flags |= RX_ENC_FLAG_LDPC;
- status->chains = mphy->antenna_mask;
+ status->chains = mt7915_band_chainmask(phy);
status->chain_signal[0] = to_rssi(MT_PRXV_RCPI0, v1);
status->chain_signal[1] = to_rssi(MT_PRXV_RCPI1, v1);
status->chain_signal[2] = to_rssi(MT_PRXV_RCPI2, v1);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0800/1518] wifi: mt76: fix queue assignment for disassoc packets
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (798 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0799/1518] wifi: mt76: mt7915: report RX chain signal for all RX paths Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0801/1518] wifi: mt76: mt7925: advertise EHT 320MHz capabilities for 6GHz band Greg Kroah-Hartman
` (198 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Peter Chiu, Felix Fietkau,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Peter Chiu <chui-hao.chiu@mediatek.com>
[ Upstream commit 3999d15cfcc72a946ec419c4059b0e0cd7860053 ]
Like deauth, a disassoc frame sent to a client in powersave mode can get
stuck in a tx queue along with other buffered frames, filling up hardware
queues with frames that are only released after the WTBL slot is reused
for another client.
Move disassoc packets to the ALTX queue, matching the existing deauth
handling.
Fixes: dedf2ec30fe4 ("wifi: mt76: fix queue assignment for deauth packets")
Signed-off-by: Peter Chiu <chui-hao.chiu@mediatek.com>
Link: https://patch.msgid.link/20260727150434.1778520-11-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/tx.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/net/wireless/mediatek/mt76/tx.c b/drivers/net/wireless/mediatek/mt76/tx.c
index 26463d84b7898..28630d75bdb21 100644
--- a/drivers/net/wireless/mediatek/mt76/tx.c
+++ b/drivers/net/wireless/mediatek/mt76/tx.c
@@ -615,6 +615,7 @@ mt76_txq_schedule_pending_wcid(struct mt76_phy *phy, struct mt76_wcid *wcid,
!ieee80211_is_data(hdr->frame_control) &&
(!ieee80211_is_bufferable_mmpdu(skb) ||
ieee80211_is_deauth(hdr->frame_control) ||
+ ieee80211_is_disassoc(hdr->frame_control) ||
head == &wcid->tx_offchannel))
qid = MT_TXQ_PSD;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0801/1518] wifi: mt76: mt7925: advertise EHT 320MHz capabilities for 6GHz band
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (799 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0800/1518] wifi: mt76: fix queue assignment for disassoc packets Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0802/1518] wifi: mt76: mt7925: Fix EHT Beamformee SS subfields to meet 802.11be minimum Greg Kroah-Hartman
` (197 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Marcin FM, Cristian-Florin Radoi,
George Salukvadze, Evgeny Kapusta, Samu Toljamo, Ariel Rosenfeld,
Chapuis Dario, Thibaut François, 张旭涵,
Sean Wang, Javier Tia, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Javier Tia <floss@jetm.me>
[ Upstream commit 77833c57a33450c0409e4b90d7721d255ea23a9e ]
mt7925_init_eht_caps() only populates EHT MCS/NSS maps for BW <= 80
and BW = 160, but never sets BW = 320. This means iw phy shows no
320MHz MCS map entries even though the hardware supports 320MHz
operation in the 6GHz band.
Add the missing 320MHz capability bits for 6GHz:
- PHY_CAP0: IEEE80211_EHT_PHY_CAP0_320MHZ_IN_6GHZ
- PHY_CAP1: beamformee SS for 320MHz
- PHY_CAP2: sounding dimensions for 320MHz
- PHY_CAP6: MCS15 support for 320MHz width
- MCS/NSS: populate bw._320 maps for 6GHz band
Introduce is_320mhz_supported() to gate 320MHz on MT7927 only, since
MT7925 does not support 320MHz operation.
Tested-by: Marcin FM <marcin@lgic.pl>
Tested-by: Cristian-Florin Radoi <radoi.chris@gmail.com>
Tested-by: George Salukvadze <giosal90@gmail.com>
Tested-by: Evgeny Kapusta <3193631@gmail.com>
Tested-by: Samu Toljamo <samu.toljamo@gmail.com>
Tested-by: Ariel Rosenfeld <ariel.rosenfeld.750@gmail.com>
Tested-by: Chapuis Dario <chapuisdario4@gmail.com>
Tested-by: Thibaut François <tibo@humeurlibre.fr>
Tested-by: 张旭涵 <Loong.0x00@gmail.com>
Reviewed-by: Sean Wang <sean.wang@mediatek.com>
Signed-off-by: Javier Tia <floss@jetm.me>
Link: https://patch.msgid.link/20260425195011.790265-6-sean.wang@kernel.org
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Stable-dep-of: 404c4e564f6b ("wifi: mt76: mt7925: Fix EHT Beamformee SS subfields to meet 802.11be minimum")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../net/wireless/mediatek/mt76/mt76_connac.h | 5 +++++
.../net/wireless/mediatek/mt76/mt7925/main.c | 22 ++++++++++++++++++-
2 files changed, 26 insertions(+), 1 deletion(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt76_connac.h b/drivers/net/wireless/mediatek/mt76/mt76_connac.h
index d504bf0c5f168..ba7eaf3ebe988 100644
--- a/drivers/net/wireless/mediatek/mt76/mt76_connac.h
+++ b/drivers/net/wireless/mediatek/mt76/mt76_connac.h
@@ -182,6 +182,11 @@ static inline bool is_mt7925(struct mt76_dev *dev)
return mt76_chip(dev) == 0x7925;
}
+static inline bool is_320mhz_supported(struct mt76_dev *dev)
+{
+ return mt76_chip(dev) == 0x7927;
+}
+
static inline bool is_mt7920(struct mt76_dev *dev)
{
return mt76_chip(dev) == 0x7920;
diff --git a/drivers/net/wireless/mediatek/mt76/mt7925/main.c b/drivers/net/wireless/mediatek/mt76/mt7925/main.c
index cb1046c59cf6c..c291e05496b47 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7925/main.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7925/main.c
@@ -178,6 +178,10 @@ mt7925_init_eht_caps(struct mt792x_phy *phy, enum nl80211_band band,
IEEE80211_EHT_PHY_CAP0_SU_BEAMFORMER |
IEEE80211_EHT_PHY_CAP0_SU_BEAMFORMEE;
+ if (band == NL80211_BAND_6GHZ && is_320mhz_supported(&phy->dev->mt76))
+ eht_cap_elem->phy_cap_info[0] |=
+ IEEE80211_EHT_PHY_CAP0_320MHZ_IN_6GHZ;
+
eht_cap_elem->phy_cap_info[0] |=
u8_encode_bits(u8_get_bits(sts - 1, BIT(0)),
IEEE80211_EHT_PHY_CAP0_BEAMFORMEE_SS_80MHZ_MASK);
@@ -188,10 +192,20 @@ mt7925_init_eht_caps(struct mt792x_phy *phy, enum nl80211_band band,
u8_encode_bits(sts - 1,
IEEE80211_EHT_PHY_CAP1_BEAMFORMEE_SS_160MHZ_MASK);
+ if (band == NL80211_BAND_6GHZ && is_320mhz_supported(&phy->dev->mt76))
+ eht_cap_elem->phy_cap_info[1] |=
+ u8_encode_bits(sts - 1,
+ IEEE80211_EHT_PHY_CAP1_BEAMFORMEE_SS_320MHZ_MASK);
+
eht_cap_elem->phy_cap_info[2] =
u8_encode_bits(sts - 1, IEEE80211_EHT_PHY_CAP2_SOUNDING_DIM_80MHZ_MASK) |
u8_encode_bits(sts - 1, IEEE80211_EHT_PHY_CAP2_SOUNDING_DIM_160MHZ_MASK);
+ if (band == NL80211_BAND_6GHZ && is_320mhz_supported(&phy->dev->mt76))
+ eht_cap_elem->phy_cap_info[2] |=
+ u8_encode_bits(sts - 1,
+ IEEE80211_EHT_PHY_CAP2_SOUNDING_DIM_320MHZ_MASK);
+
eht_cap_elem->phy_cap_info[3] =
IEEE80211_EHT_PHY_CAP3_NG_16_SU_FEEDBACK |
IEEE80211_EHT_PHY_CAP3_NG_16_MU_FEEDBACK |
@@ -212,7 +226,8 @@ mt7925_init_eht_caps(struct mt792x_phy *phy, enum nl80211_band band,
u8_encode_bits(u8_get_bits(0x11, GENMASK(1, 0)),
IEEE80211_EHT_PHY_CAP5_MAX_NUM_SUPP_EHT_LTF_MASK);
- val = width == NL80211_CHAN_WIDTH_160 ? 0x7 :
+ val = width == NL80211_CHAN_WIDTH_320 ? 0xf :
+ width == NL80211_CHAN_WIDTH_160 ? 0x7 :
width == NL80211_CHAN_WIDTH_80 ? 0x3 : 0x1;
eht_cap_elem->phy_cap_info[6] =
u8_encode_bits(u8_get_bits(0x11, GENMASK(4, 2)),
@@ -234,6 +249,11 @@ mt7925_init_eht_caps(struct mt792x_phy *phy, enum nl80211_band band,
eht_nss->bw._160.rx_tx_mcs9_max_nss = val;
eht_nss->bw._160.rx_tx_mcs11_max_nss = val;
eht_nss->bw._160.rx_tx_mcs13_max_nss = val;
+ if (band == NL80211_BAND_6GHZ && is_320mhz_supported(&phy->dev->mt76)) {
+ eht_nss->bw._320.rx_tx_mcs9_max_nss = val;
+ eht_nss->bw._320.rx_tx_mcs11_max_nss = val;
+ eht_nss->bw._320.rx_tx_mcs13_max_nss = val;
+ }
}
int mt7925_init_mlo_caps(struct mt792x_phy *phy)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0802/1518] wifi: mt76: mt7925: Fix EHT Beamformee SS subfields to meet 802.11be minimum
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (800 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0801/1518] wifi: mt76: mt7925: advertise EHT 320MHz capabilities for 6GHz band Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0803/1518] wifi: mt76: reject out-of-range link ids in mt76_vif_link() Greg Kroah-Hartman
` (196 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, shengwei.lu, Felix Fietkau,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: shengwei.lu <shengwei.lu@mediatek.com>
[ Upstream commit 404c4e564f6b1eeffd10bf2b2d3b86620f5794c3 ]
Per IEEE 802.11be, the Beamformee SS <= 80/160/320 MHz 3-bit subfields
in the EHT PHY Capabilities are encoded as (Nss - 1) and are required
to be >= 3 (i.e. at least 4 SS receive capability) whenever SU
Beamformee is advertised.
MT7925 is a 2x2 STA (sts = 2), so directly filling (sts - 1) = 1
violates the spec minimum. Clamp the encoded value to 3 when sts <= 3,
otherwise use (sts - 1). This is applied consistently to the
BEAMFORMEE_SS <= 80 MHz (split across phy_cap_info[0]/[1]), <= 160 MHz
and <= 320 MHz (6 GHz only) subfields.
Fixes: c948b5da6bbe ("wifi: mt76: mt7925: add Mediatek Wi-Fi7 driver for mt7925 chips")
Signed-off-by: shengwei.lu <shengwei.lu@mediatek.com>
Link: https://patch.msgid.link/20260723031108.2017653-1-jb.tsai@mediatek.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7925/main.c | 10 ++++++----
1 file changed, 6 insertions(+), 4 deletions(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7925/main.c b/drivers/net/wireless/mediatek/mt76/mt7925/main.c
index c291e05496b47..1eeb33981c743 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7925/main.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7925/main.c
@@ -182,19 +182,21 @@ mt7925_init_eht_caps(struct mt792x_phy *phy, enum nl80211_band band,
eht_cap_elem->phy_cap_info[0] |=
IEEE80211_EHT_PHY_CAP0_320MHZ_IN_6GHZ;
+ val = (sts > 3) ? sts - 1 : 3;
+
eht_cap_elem->phy_cap_info[0] |=
- u8_encode_bits(u8_get_bits(sts - 1, BIT(0)),
+ u8_encode_bits(u8_get_bits(val, BIT(0)),
IEEE80211_EHT_PHY_CAP0_BEAMFORMEE_SS_80MHZ_MASK);
eht_cap_elem->phy_cap_info[1] =
- u8_encode_bits(u8_get_bits(sts - 1, GENMASK(2, 1)),
+ u8_encode_bits(u8_get_bits(val, GENMASK(2, 1)),
IEEE80211_EHT_PHY_CAP1_BEAMFORMEE_SS_80MHZ_MASK) |
- u8_encode_bits(sts - 1,
+ u8_encode_bits(val,
IEEE80211_EHT_PHY_CAP1_BEAMFORMEE_SS_160MHZ_MASK);
if (band == NL80211_BAND_6GHZ && is_320mhz_supported(&phy->dev->mt76))
eht_cap_elem->phy_cap_info[1] |=
- u8_encode_bits(sts - 1,
+ u8_encode_bits(val,
IEEE80211_EHT_PHY_CAP1_BEAMFORMEE_SS_320MHZ_MASK);
eht_cap_elem->phy_cap_info[2] =
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0803/1518] wifi: mt76: reject out-of-range link ids in mt76_vif_link()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (801 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0802/1518] wifi: mt76: mt7925: Fix EHT Beamformee SS subfields to meet 802.11be minimum Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0804/1518] wifi: mt76: mt7996: fix out-of-bounds link array access in mt7996_tx() Greg Kroah-Hartman
` (195 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit 9ba744a28c26eaa5cae930688a22e01888395308 ]
mt76_vif_link() indexes mvif->link[] without validating link_id, but
callers pass mvif->deflink_id / msta->deflink_id, which hold
IEEE80211_LINK_UNSPECIFIED (0xf) until the first link has been added.
Since IEEE80211_MLD_MAX_NUM_LINKS is 15, that reads one element past the
end of the array, aliasing mt76_vif_data.offchannel_link.
Reachable via mt7996_set_tsf()/mt7996_offset_tsf() and
mt7996_net_fill_forward_path(). Bounds check link_id and return NULL,
matching mt7996_sta_link() and mt7996_sta_link_protected().
Fixes: a9384b36a42a ("wifi: mt76: mt7996: rework set/get_tsf callabcks to support MLO")
Link: https://patch.msgid.link/20260801145334.1166751-9-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt76.h | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/net/wireless/mediatek/mt76/mt76.h b/drivers/net/wireless/mediatek/mt76/mt76.h
index 03e53a6a23b31..5560787718599 100644
--- a/drivers/net/wireless/mediatek/mt76/mt76.h
+++ b/drivers/net/wireless/mediatek/mt76/mt76.h
@@ -2071,6 +2071,9 @@ mt76_vif_link(struct mt76_dev *dev, struct ieee80211_vif *vif, int link_id)
if (!link_id)
return mlink;
+ if (link_id >= IEEE80211_MLD_MAX_NUM_LINKS)
+ return NULL;
+
return mt76_dereference(mvif->link[link_id], dev);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0804/1518] wifi: mt76: mt7996: fix out-of-bounds link array access in mt7996_tx()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (802 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0803/1518] wifi: mt76: reject out-of-range link ids in mt76_vif_link() Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0805/1518] wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump Greg Kroah-Hartman
` (194 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit 4330a0ef9f75a54fde3548432a9a698f06bab635 ]
When mac80211 leaves the link unspecified, mt7996_tx() substitutes the
primary link id of the station or vif. That value is
IEEE80211_LINK_UNSPECIFIED (0xf) until the first link has been added,
and it is then used unchecked to index vif->link_conf[],
mvif->mt76.link[] and sta->link[], all of which hold
IEEE80211_MLD_MAX_NUM_LINKS (15) entries.
Clamp the primary link id to the default link before using it, and use
the clamped value for the link_sta fallback as well.
Fixes: 1609b014aa29 ("wifi: mt76: mt7996: Overwrite unspecified link_id in mt7996_tx()")
Link: https://patch.msgid.link/20260801145334.1166751-10-nbd@nbd.name
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../net/wireless/mediatek/mt76/mt7996/main.c | 20 ++++++++++++-------
1 file changed, 13 insertions(+), 7 deletions(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/main.c b/drivers/net/wireless/mediatek/mt76/mt7996/main.c
index a319a99b5056e..c6d7088b15cab 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/main.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/main.c
@@ -1361,20 +1361,26 @@ static void mt7996_tx(struct ieee80211_hw *hw,
struct ieee80211_vif *vif = info->control.vif;
struct mt7996_vif *mvif = vif ? (void *)vif->drv_priv : NULL;
struct mt76_wcid *wcid = &dev->mt76.global_wcid;
+ u8 deflink_id = IEEE80211_LINK_UNSPECIFIED;
u8 link_id = u32_get_bits(info->control.flags,
IEEE80211_TX_CTRL_MLO_LINK);
rcu_read_lock();
+ if (msta)
+ deflink_id = msta->deflink_id;
+ else if (mvif)
+ deflink_id = mvif->mt76.deflink_id;
+
+ /* the primary link is unset until the first link has been added */
+ if (deflink_id >= IEEE80211_MLD_MAX_NUM_LINKS)
+ deflink_id = 0;
+
/* Use primary link_id if the value from mac80211 is set to
* IEEE80211_LINK_UNSPECIFIED.
*/
- if (link_id == IEEE80211_LINK_UNSPECIFIED) {
- if (msta)
- link_id = msta->deflink_id;
- else if (mvif)
- link_id = mvif->mt76.deflink_id;
- }
+ if (link_id == IEEE80211_LINK_UNSPECIFIED)
+ link_id = deflink_id;
if (vif && ieee80211_vif_is_mld(vif)) {
struct ieee80211_bss_conf *link_conf;
@@ -1384,7 +1390,7 @@ static void mt7996_tx(struct ieee80211_hw *hw,
link_sta = rcu_dereference(sta->link[link_id]);
if (!link_sta)
- link_sta = rcu_dereference(sta->link[msta->deflink_id]);
+ link_sta = rcu_dereference(sta->link[deflink_id]);
if (link_sta) {
memcpy(hdr->addr1, link_sta->addr, ETH_ALEN);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0805/1518] wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (803 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0804/1518] wifi: mt76: mt7996: fix out-of-bounds link array access in mt7996_tx() Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0806/1518] wifi: mt76: mt7996: remove beacon_int_min_gcd from ADHOC interface combinations Greg Kroah-Hartman
` (193 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Linghui Wu, Rameshkumar Sundaram,
Baochen Qiang, Jeff Johnson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linghui Wu <linghui.wu@oss.qualcomm.com>
[ Upstream commit 4f25071afe9218aaae1c63fbf75e229aa6405319 ]
On WCN3990/SNOC the MSA region is mapped with devm_memremap(MEMREMAP_WT).
On arm64 such a mapping is not Normal-cacheable, so unaligned accesses to
it are not permitted. ath10k_msa_dump_memory() copies the region with a
plain memcpy(), whose optimized __pi_memcpy_generic implementation issues
wide/unaligned loads. This triggers an alignment fault (FSC=0x21) Oops in
ath10k_snoc_fw_crashed_dump() while collecting the devcoredump:
Unable to handle kernel paging request ... FSC=0x21: alignment fault
pc : __pi_memcpy_generic
lr : ath10k_snoc_fw_crashed_dump [ath10k_snoc]
The Oops both leaves the firmware RAM dump buffer zeroed (no dump is
captured) and crashes the kernel, which in turn breaks modem SSR
recovery.
Use memcpy_fromio(), which only performs accesses that are valid for such
a device-memory mapping. The generic memcpy_fromio() implementation aligns
the source before issuing word-sized reads and stores the destination with
put_unaligned(), so it is also safe for the coherent DMA allocation used on
the non-reserved-memory path. ath11k and ath12k use the same pattern
when copying target memory into crash dumps, so call it unconditionally
here too.
The MEMREMAP_WT pointer is a plain void *, so an explicit __iomem cast is
needed; use __force to keep sparse happy.
Tested-on: WCN3990 hw1.0 SNOC WLAN.HL.3.3.7.c5-00107-QCAHLSWMTPL-1
Fixes: 3f14b73c3843 ("ath10k: Enable MSA region dump support for WCN3990")
Signed-off-by: Linghui Wu <linghui.wu@oss.qualcomm.com>
Reviewed-by: Rameshkumar Sundaram <rameshkumar.sundaram@oss.qualcomm.com>
Reviewed-by: Baochen Qiang <baochen.qiang@oss.qualcomm.com>
Link: https://patch.msgid.link/20260727072629.2297208-1-linghui.wu@oss.qualcomm.com
Signed-off-by: Jeff Johnson <jeff.johnson@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/ath/ath10k/snoc.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/drivers/net/wireless/ath/ath10k/snoc.c b/drivers/net/wireless/ath/ath10k/snoc.c
index b3f6424c17d36..0785ea2b8270f 100644
--- a/drivers/net/wireless/ath/ath10k/snoc.c
+++ b/drivers/net/wireless/ath/ath10k/snoc.c
@@ -5,6 +5,7 @@
#include <linux/bits.h>
#include <linux/clk.h>
+#include <linux/io.h>
#include <linux/kernel.h>
#include <linux/module.h>
#include <linux/of.h>
@@ -1456,11 +1457,15 @@ static void ath10k_msa_dump_memory(struct ath10k *ar,
hdr->length = cpu_to_le32(ar->msa.mem_size);
if (current_region->len < ar->msa.mem_size) {
- memcpy(buf, ar->msa.vaddr, current_region->len);
+ memcpy_fromio(buf,
+ (const void __iomem __force *)ar->msa.vaddr,
+ current_region->len);
ath10k_warn(ar, "msa dump length is less than msa size %x, %x\n",
current_region->len, ar->msa.mem_size);
} else {
- memcpy(buf, ar->msa.vaddr, ar->msa.mem_size);
+ memcpy_fromio(buf,
+ (const void __iomem __force *)ar->msa.vaddr,
+ ar->msa.mem_size);
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0806/1518] wifi: mt76: mt7996: remove beacon_int_min_gcd from ADHOC interface combinations
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (804 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0805/1518] wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0807/1518] arm64: smp: Fix IPI teardown for GICv5 flow Greg Kroah-Hartman
` (192 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jose Ignacio Tornos Martinez,
Alex Gavin, Felix Fietkau, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jose Ignacio Tornos Martinez <jtornosm@redhat.com>
[ Upstream commit 4df22710a77d2365e56d720bc4106e54c1dfa2ff ]
The driver fails to register with error -22 (EINVAL) due to a cfg80211
validation failure in wiphy_verify_iface_combinations().
Commit 5ef0e8e2653b ("wifi: mt76: mt7996: fix iface combination for
different chipsets") added beacon_int_min_gcd to if_comb_global and
if_comb_global_7992, but these combinations include ADHOC (IBSS)
interface type. This violates a cfg80211 rule from commit 56271da29c52
("cfg80211: disallow beacon_int_min_gcd with IBSS") that explicitly
forbids combining ADHOC with beacon_int_min_gcd.
The restriction exists because beacon_int_min_gcd requires static,
predictable beacon intervals to coordinate multiple beaconing interfaces,
but ADHOC interfaces have dynamic beacon intervals that change when
joining different networks, making the GCD constraint unenforceable.
Remove beacon_int_min_gcd from the interface combinations that include
ADHOC because they are not necessary for ADHOC operation. The if_comb
combination (AP/MESH/STA only, without ADHOC) correctly retains
beacon_int_min_gcd for multi-AP coordination.
Fixes: 5ef0e8e2653b ("wifi: mt76: mt7996: fix iface combination for different chipsets")
Signed-off-by: Jose Ignacio Tornos Martinez <jtornosm@redhat.com>
Tested-by: Alex Gavin <alex.gavin@candelatech.com>
Link: https://patch.msgid.link/20260702104337.679536-1-jtornosm@redhat.com
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/mediatek/mt76/mt7996/init.c | 2 --
1 file changed, 2 deletions(-)
diff --git a/drivers/net/wireless/mediatek/mt76/mt7996/init.c b/drivers/net/wireless/mediatek/mt76/mt7996/init.c
index 462322896b474..d0a4530db1cf7 100644
--- a/drivers/net/wireless/mediatek/mt76/mt7996/init.c
+++ b/drivers/net/wireless/mediatek/mt76/mt7996/init.c
@@ -34,7 +34,6 @@ static const struct ieee80211_iface_combination if_comb_global = {
BIT(NL80211_CHAN_WIDTH_40) |
BIT(NL80211_CHAN_WIDTH_80) |
BIT(NL80211_CHAN_WIDTH_160),
- .beacon_int_min_gcd = 100,
};
static const struct ieee80211_iface_combination if_comb_global_7992 = {
@@ -47,7 +46,6 @@ static const struct ieee80211_iface_combination if_comb_global_7992 = {
BIT(NL80211_CHAN_WIDTH_40) |
BIT(NL80211_CHAN_WIDTH_80) |
BIT(NL80211_CHAN_WIDTH_160),
- .beacon_int_min_gcd = 100,
};
static const struct ieee80211_iface_limit if_limits[] = {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0807/1518] arm64: smp: Fix IPI teardown for GICv5 flow
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (805 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0806/1518] wifi: mt76: mt7996: remove beacon_int_min_gcd from ADHOC interface combinations Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0808/1518] arm64/fpsimd: ptrace: Fix inactive SVE and SSVE regsets Greg Kroah-Hartman
` (191 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vladimir Murzin, Will Deacon,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vladimir Murzin <vladimir.murzin@arm.com>
[ Upstream commit 4c9c81a0860415284e9d260f998fbd755d3a7469 ]
Sashiko reported that during CPU offlining, __cpu_disable() is
executed by the stopper thread via take_cpu_down() with local
interrupts disabled. __cpu_disable() calls ipi_teardown(), which
invokes ipi_lpi_disable(). For the GICv5 flow, this eventually calls
the sleepable disable_irq().
This can be reproduced easily with CONFIG_DEBUG_ATOMIC_SLEEP=y by
offlining a CPU:
BUG: sleeping function called from invalid context at kernel/irq/manage.c:702
in_atomic(): 1, irqs_disabled(): 1, non_block: 0, pid: 20, name: migration/1
preempt_count: 1, expected: 0
no locks held by migration/1/20.
irq event stamp: 186
hardirqs last enabled at (185): [<ffff800080b084c8>] _raw_spin_unlock_irq+0x38/0x68
hardirqs last disabled at (186): [<ffff8000801f8e08>] multi_cpu_stop+0xc8/0x190
softirqs last enabled at (80): [<ffff8000800c48b8>] handle_softirqs+0x410/0x468
softirqs last disabled at (75): [<ffff8000800102f4>] __do_softirq+0x1c/0x28
Fix this by using disable_irq_nosync() instead, which is safe in this
atomic context.
Fixes: ba1004f861d1 ("arm64: smp: Support non-SGIs for IPIs")
Signed-off-by: Vladimir Murzin <vladimir.murzin@arm.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/kernel/smp.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/arm64/kernel/smp.c b/arch/arm64/kernel/smp.c
index 92b57fc87ee96..6af97292e3692 100644
--- a/arch/arm64/kernel/smp.c
+++ b/arch/arm64/kernel/smp.c
@@ -1081,7 +1081,7 @@ static void ipi_teardown(int cpu)
disable_percpu_irq(ipi_irq_base + i);
}
} else {
- disable_irq(irq_desc_get_irq(get_ipi_desc(cpu, i)));
+ disable_irq_nosync(irq_desc_get_irq(get_ipi_desc(cpu, i)));
}
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0808/1518] arm64/fpsimd: ptrace: Fix inactive SVE and SSVE regsets
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (806 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0807/1518] arm64: smp: Fix IPI teardown for GICv5 flow Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0809/1518] kselftest/arm64: fp-ptrace: Fix checks for " Greg Kroah-Hartman
` (190 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Will Deacon,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit c3f83d021162571bcd87b062ec9e587828d2b7f3 ]
sve_init_header_from_task() takes header as a pointer, so for the
inactive mode
header->size = sizeof(header);
stores 8 rather than sizeof(struct user_sve_header), which is 16.
Userspace sees an impossible size smaller than the header it
describes.
The inactive-mode check in sve_get_common() compares header.size
against sizeof(header) as well, but there header is a struct, so the
check can never fire. Reads of NT_ARM_SVE and NT_ARM_SSVE for the
inactive mode therefore still return the other mode's FPSIMD data,
exactly the situation the check was added to prevent.
Fix the size, and make the check return the remaining membuf space
instead of 0, which regset_get() would interpret as the entire
(zero-filled) buffer having been populated.
Fixes: b93e685ecff7 ("arm64/fpsimd: ptrace: Do not present register data for inactive mode")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/kernel/ptrace.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/arm64/kernel/ptrace.c b/arch/arm64/kernel/ptrace.c
index 2acc2c3dd033e..ceb047e7d49f2 100644
--- a/arch/arm64/kernel/ptrace.c
+++ b/arch/arm64/kernel/ptrace.c
@@ -801,7 +801,7 @@ static void sve_init_header_from_task(struct user_sve_header *header,
if (active)
header->size = SVE_PT_SIZE(vq, header->flags);
else
- header->size = sizeof(header);
+ header->size = sizeof(*header);
header->max_size = SVE_PT_SIZE(sve_vq_from_vl(header->max_vl),
SVE_PT_REGS_SVE);
}
@@ -837,7 +837,7 @@ static int sve_get_common(struct task_struct *target,
* from the other mode to userspace.
*/
if (header.size == sizeof(header))
- return 0;
+ return to.left;
switch ((header.flags & SVE_PT_REGS_MASK)) {
case SVE_PT_REGS_FPSIMD:
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0809/1518] kselftest/arm64: fp-ptrace: Fix checks for inactive SVE and SSVE regsets
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (807 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0808/1518] arm64/fpsimd: ptrace: Fix inactive SVE and SSVE regsets Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0810/1518] kselftest/arm64: Dont write to P0 in irritator on SME only systems Greg Kroah-Hartman
` (189 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Will Deacon,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit bd290e7fc245f9f85607f305fe8213c6c47a416c ]
The checks on the header size reported for the inactive regset of the
NT_ARM_SVE/NT_ARM_SSVE pair compare it against sizeof(sve), but sve is
a struct user_sve_header *, so this is 8 rather than the intended 16.
The kernel carried the identical typo when filling in the header, so
kernel and test agreed on the wrong value and the test passed.
Compare against sizeof(*sve), stop after the header checks for an
inactive regset since it has no payload to compare, and prefill the
buffer with a sentinel to verify that reading an inactive regset
leaves everything after the header untouched. This also covers the
getter's return value, which determines how many bytes ptrace copies
back to userspace.
Fixes: 864f3ddcd715 ("kselftest/arm64: fp-ptrace: Adjust to new inactive mode behaviour")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/arm64/fp/fp-ptrace.c | 47 +++++++++++++++++---
1 file changed, 41 insertions(+), 6 deletions(-)
diff --git a/tools/testing/selftests/arm64/fp/fp-ptrace.c b/tools/testing/selftests/arm64/fp/fp-ptrace.c
index a85c19e9524e1..c3fcd47e33968 100644
--- a/tools/testing/selftests/arm64/fp/fp-ptrace.c
+++ b/tools/testing/selftests/arm64/fp/fp-ptrace.c
@@ -65,6 +65,9 @@
/* VL 128..2048 in powers of 2 */
#define MAX_NUM_VLS 5
+/* Sentinel for detecting buffer bytes the kernel did not write */
+#define REGSET_SENTINEL 0xa5
+
/*
* FPMR bits we can set without doing feature checks to see if values
* are valid.
@@ -181,6 +184,20 @@ static bool compare_buffer(const char *name, void *out,
return false;
}
+static bool buffer_is_filled(const void *buffer, size_t size,
+ unsigned char value)
+{
+ const unsigned char *bytes = buffer;
+ size_t i;
+
+ for (i = 0; i < size; i++) {
+ if (bytes[i] != value)
+ return false;
+ }
+
+ return true;
+}
+
struct test_config {
int sve_vl_in;
int sve_vl_expected;
@@ -401,6 +418,7 @@ static bool check_ptrace_values_sve(pid_t child, struct test_config *config)
struct user_sve_header *sve;
struct user_fpsimd_state *fpsimd;
struct iovec iov;
+ size_t buf_size;
int ret, vq;
bool pass = true;
@@ -409,14 +427,16 @@ static bool check_ptrace_values_sve(pid_t child, struct test_config *config)
vq = __sve_vq_from_vl(config->sve_vl_in);
- iov.iov_len = SVE_PT_SVE_OFFSET + SVE_PT_SVE_SIZE(vq, SVE_PT_REGS_SVE);
- iov.iov_base = malloc(iov.iov_len);
+ buf_size = SVE_PT_SVE_OFFSET + SVE_PT_SVE_SIZE(vq, SVE_PT_REGS_SVE);
+ iov.iov_len = buf_size;
+ iov.iov_base = malloc(buf_size);
if (!iov.iov_base) {
ksft_print_msg("OOM allocating %lu byte SVE buffer\n",
iov.iov_len);
return false;
}
+ memset(iov.iov_base, REGSET_SENTINEL, buf_size);
ret = ptrace(PTRACE_GETREGSET, child, NT_ARM_SVE, &iov);
if (ret != 0) {
ksft_print_msg("Failed to read initial SVE: %s (%d)\n",
@@ -440,10 +460,16 @@ static bool check_ptrace_values_sve(pid_t child, struct test_config *config)
}
if (svcr_in & SVCR_SM) {
- if (sve->size != sizeof(sve)) {
+ if (sve->size != sizeof(*sve)) {
ksft_print_msg("NT_ARM_SVE reports data with PSTATE.SM\n");
pass = false;
}
+ if (!buffer_is_filled(iov.iov_base + sizeof(*sve),
+ buf_size - sizeof(*sve), REGSET_SENTINEL)) {
+ ksft_print_msg("NT_ARM_SVE wrote beyond its header with PSTATE.SM\n");
+ pass = false;
+ }
+ goto out;
} else {
if (sve->size != SVE_PT_SIZE(vq, sve->flags)) {
ksft_print_msg("Mismatch in SVE header size: %d != %lu\n",
@@ -485,6 +511,7 @@ static bool check_ptrace_values_ssve(pid_t child, struct test_config *config)
struct user_sve_header *sve;
struct user_fpsimd_state *fpsimd;
struct iovec iov;
+ size_t buf_size;
int ret, vq;
bool pass = true;
@@ -493,14 +520,16 @@ static bool check_ptrace_values_ssve(pid_t child, struct test_config *config)
vq = __sve_vq_from_vl(config->sme_vl_in);
- iov.iov_len = SVE_PT_SVE_OFFSET + SVE_PT_SVE_SIZE(vq, SVE_PT_REGS_SVE);
- iov.iov_base = malloc(iov.iov_len);
+ buf_size = SVE_PT_SVE_OFFSET + SVE_PT_SVE_SIZE(vq, SVE_PT_REGS_SVE);
+ iov.iov_len = buf_size;
+ iov.iov_base = malloc(buf_size);
if (!iov.iov_base) {
ksft_print_msg("OOM allocating %lu byte SSVE buffer\n",
iov.iov_len);
return false;
}
+ memset(iov.iov_base, REGSET_SENTINEL, buf_size);
ret = ptrace(PTRACE_GETREGSET, child, NT_ARM_SSVE, &iov);
if (ret != 0) {
ksft_print_msg("Failed to read initial SSVE: %s (%d)\n",
@@ -523,10 +552,16 @@ static bool check_ptrace_values_ssve(pid_t child, struct test_config *config)
}
if (!(svcr_in & SVCR_SM)) {
- if (sve->size != sizeof(sve)) {
+ if (sve->size != sizeof(*sve)) {
ksft_print_msg("NT_ARM_SSVE reports data without PSTATE.SM\n");
pass = false;
}
+ if (!buffer_is_filled(iov.iov_base + sizeof(*sve),
+ buf_size - sizeof(*sve), REGSET_SENTINEL)) {
+ ksft_print_msg("NT_ARM_SSVE wrote beyond its header without PSTATE.SM\n");
+ pass = false;
+ }
+ goto out;
} else {
if (sve->size != SVE_PT_SIZE(vq, sve->flags)) {
ksft_print_msg("Mismatch in SSVE header size: %d != %lu\n",
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0810/1518] kselftest/arm64: Dont write to P0 in irritator on SME only systems
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (808 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0809/1518] kselftest/arm64: fp-ptrace: Fix checks for " Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0811/1518] iommu/arm-smmu-v3: Convert to use atomic poll timeout Greg Kroah-Hartman
` (188 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mark Rutland, Mark Brown,
Will Deacon, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mark Brown <broonie@kernel.org>
[ Upstream commit 2b989c411ab98fa76b7bb3b87ba7a2a4c3b5e946 ]
Commit 3e360ef0c0a1f ("kselftest/arm64: Corrupt P0 in the irritator when
testing SSVE") added corruption of P0 to the sve-test case in order to
ensure that the predicate registers were covered as part of the
corruption. On SME only systems this results in an illegal instruction
since signal handlers are run out of streaming mode and the predicate
registers do not exist out of streaming mode without SVE. Switch to
entering and exiting streaming mode in the irritator, this will reset
all relevant registers to 0 if they somehow weren't already by the
signal entry.
Fixes: 3e360ef0c0a1f ("kselftest/arm64: Corrupt P0 in the irritator when testing SSVE")
Reported-by: Mark Rutland <mark.rutland@arm.com>
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/arm64/fp/sve-test.S | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/tools/testing/selftests/arm64/fp/sve-test.S b/tools/testing/selftests/arm64/fp/sve-test.S
index 80e072f221cde..7ef7835389e76 100644
--- a/tools/testing/selftests/arm64/fp/sve-test.S
+++ b/tools/testing/selftests/arm64/fp/sve-test.S
@@ -298,15 +298,20 @@ function irritator_handler
add x0, x0, #1
str x0, [x2, #ucontext_regs + 8 * 23]
+#ifndef SSVE
// Corrupt some random Z-regs
movi v0.8b, #1
movi v9.16b, #2
movi v31.8b, #3
// And P0
ptrue p0.d
-#ifndef SSVE
// And FFR
wrffr p15.b
+#else
+ // Enter and exit streaming mode, will reset all of the V, Z, P
+ // and FFR registers that the system has.
+ smstart_sm
+ smstop
#endif
ret
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0811/1518] iommu/arm-smmu-v3: Convert to use atomic poll timeout
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (809 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0810/1518] kselftest/arm64: Dont write to P0 in irritator on SME only systems Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0812/1518] perf/cxlpmu: Fix 64-bit write to 32-bit HDM filter register Greg Kroah-Hartman
` (187 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Pranjal Shrivastava,
Will Deacon, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pranjal Shrivastava <praan@google.com>
[ Upstream commit eced8058c82a3a81ae480a6546e2da32100dddfa ]
The arm_smmu_write_reg_sync() helper is currently implemented using
readl_relaxed_poll_timeout() (that relies on usleep_range() internally)
which becomes a critical issue when used in the gerror irq handler.
If the SMMU hits a gerror and enters Service Failure Mode
(GERROR_SFM_ERR), the gerror handler calls arm_smmu_device_disable() in
hard-irq context. This becomes a problem as arm_smmu_device_disable()
inevitably calls arm_smmu_write_reg_sync() which might attempt to sleep
inside a hard-irq context.
Fix this by converting the arm_smmu_write_reg_sync to use the
readl_relaxed_poll_timeout_atomic() polling helper.
(Discovered while running Sashiko locally on another patch series).
Reported-by: Sashiko <sashiko-bot@kernel.org>
Fixes: 48ec83bcbcf5 ("iommu/arm-smmu: Add initial driver support for ARM SMMUv3 devices")
Signed-off-by: Pranjal Shrivastava <praan@google.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c
index d645f7edbd107..b677390e95bb9 100644
--- a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c
+++ b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c
@@ -3992,8 +3992,9 @@ static int arm_smmu_write_reg_sync(struct arm_smmu_device *smmu, u32 val,
u32 reg;
writel_relaxed(val, smmu->base + reg_off);
- return readl_relaxed_poll_timeout(smmu->base + ack_off, reg, reg == val,
- 1, ARM_SMMU_POLL_TIMEOUT_US);
+ return readl_relaxed_poll_timeout_atomic(smmu->base + ack_off, reg,
+ reg == val, 1,
+ ARM_SMMU_POLL_TIMEOUT_US);
}
/* GBPA is "special" */
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0812/1518] perf/cxlpmu: Fix 64-bit write to 32-bit HDM filter register
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (810 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0811/1518] iommu/arm-smmu-v3: Convert to use atomic poll timeout Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0813/1518] wifi: mac80211: send TWT teardown to peer after setup TX failure Greg Kroah-Hartman
` (186 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Davidlohr Bueso, Richard Cheng,
Dave Jiang, Will Deacon, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Davidlohr Bueso <dave@stgolabs.net>
[ Upstream commit ea434e8fd3a539e9c53285b10d3c7e539e228591 ]
The HDM decoder filter configuration register is 32 bits wide, but the
driver programs it with a 64-bit writeq(). The filter value never
exceeds 32 bits, so the upper half of the write is always zero and
lands in the adjacent Filter ID 1 (Channel/Rank/Bank) configuration
register at offset+4.
Fixes: 5d7107c72796 ("perf: CXL Performance Monitoring Unit driver")
Signed-off-by: Davidlohr Bueso <dave@stgolabs.net>
Reviewed-by: Richard Cheng <icheng@nvidia.com>
Reviewed-by: Dave Jiang <dave.jiang@intel.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/perf/cxl_pmu.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/perf/cxl_pmu.c b/drivers/perf/cxl_pmu.c
index 68a54d97d2a8a..39b46550a5109 100644
--- a/drivers/perf/cxl_pmu.c
+++ b/drivers/perf/cxl_pmu.c
@@ -635,7 +635,7 @@ static void cxl_pmu_event_start(struct perf_event *event, int flags)
cfg = cxl_pmu_config2_get_hdm_decoder(event);
else
cfg = GENMASK(31, 0); /* No filtering if 0xFFFF_FFFF */
- writeq(cfg, base + CXL_PMU_FILTER_CFG_REG(hwc->idx, 0));
+ writel(cfg, base + CXL_PMU_FILTER_CFG_REG(hwc->idx, 0));
}
cfg = readq(base + CXL_PMU_COUNTER_CFG_REG(hwc->idx));
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0813/1518] wifi: mac80211: send TWT teardown to peer after setup TX failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (811 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0812/1518] perf/cxlpmu: Fix 64-bit write to 32-bit HDM filter register Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0814/1518] wifi: zd1211rw: reject secondary interfaces to prevent conflicts Greg Kroah-Hartman
` (185 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zhao Li, Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhao Li <enderaoelyther@gmail.com>
[ Upstream commit a28fcce6ee74be8a4526e6cfa16dc7786d62a784 ]
When an AP's TWT Setup response is not acknowledged,
ieee80211_s1g_tx_twt_setup_fail() asks the driver to tear down the local
agreement and sends a TWT teardown action as the peer notification. It
uses the response SA as the destination, but
ieee80211_s1g_send_twt_setup() built that response with SA set to the
AP's address. The teardown is therefore queued with DA, SA and BSSID all
set to the AP address and never reaches the station.
The in-tree driver callbacks update local hardware state and emit no
action frame. The station receives no notification that mac80211 asked
the driver to remove the agreement and can keep following the TWT
schedule, leaving the peers' power-save state desynchronized.
Address the teardown to the response DA, the station to which the failed
response was sent. This also matches the station lookup the transmit
status path already performs on the same frame.
Fixes: f5a4c24e689f ("mac80211: introduce individual TWT support in AP mode")
Assisted-by: Codex:gpt-5.6-sol
Assisted-by: Kimi:K3
Signed-off-by: Zhao Li <enderaoelyther@gmail.com>
Link: https://patch.msgid.link/20260729173607.13340-1-enderaoelyther@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/s1g.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/mac80211/s1g.c b/net/mac80211/s1g.c
index 7702cff84d546..1e2f07090a436 100644
--- a/net/mac80211/s1g.c
+++ b/net/mac80211/s1g.c
@@ -147,7 +147,7 @@ ieee80211_s1g_tx_twt_setup_fail(struct ieee80211_sub_if_data *sdata,
drv_twt_teardown_request(sdata->local, sdata, &sta->sta, flowid);
- ieee80211_s1g_send_twt_teardown(sdata, mgmt->sa, sdata->vif.addr,
+ ieee80211_s1g_send_twt_teardown(sdata, mgmt->da, sdata->vif.addr,
flowid);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0814/1518] wifi: zd1211rw: reject secondary interfaces to prevent conflicts
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (812 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0813/1518] wifi: mac80211: send TWT teardown to peer after setup TX failure Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0815/1518] wifi: mac80211: skip unused probe response countdown offsets Greg Kroah-Hartman
` (184 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+0ec3d1a6cf1fbe79c153,
Slawomir Stepien, Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Slawomir Stepien <sst@poczta.fm>
[ Upstream commit 0e4532ec658606f76f62eb277e7a933919d36cbb ]
The zd1211rw driver is designed for single-function Wi-Fi dongles and
hardcodes its USB endpoints. When a malformed USB device exposes multiple
interfaces that match the driver's device ID, the driver blindly binds to
all of them.
During probe(), the driver calls usb_reset_device(), which iterates over
all interfaces and invokes the pre_reset() callback for each bound
interface. Since multiple interfaces are bound to zd1211rw, pre_reset() is
called sequentially for each instance, acquiring their respective
&mac->chip.mutex. Because all instances initialize their mutexes with the
same lock class, lockdep detects a task acquiring a lock of the same class
it already holds and flags it as a possible recursive deadlock:
WARNING: possible recursive locking detected
kworker/0:1/11 is trying to acquire lock:
ffff88810371dde0 (&chip->mutex){+.+.}-{4:4}, at:
zd_chip_disable_rxtx+0x20/0x50
drivers/net/wireless/zydas/zd1211rw/zd_chip.c:1465
but task is already holding lock:
ffff8881138ddde0 (&chip->mutex){+.+.}-{4:4}, at: pre_reset+0x28c/0x380
drivers/net/wireless/zydas/zd1211rw/zd_usb.c:1505
Fix this by explicitly rejecting secondary interfaces (bInterfaceNumber !=
0) during probe(). This ensures that only a single instance of the driver
binds to the device, eliminating the recursive locking scenario.
Fixes: e85d0918b54f ("[PATCH] ZyDAS ZD1211 USB-WLAN driver")
Assisted-by: Gemini:gemini-3.5-flash Gemini:gemini-3.1-pro-preview syzbot
Reported-by: syzbot+0ec3d1a6cf1fbe79c153@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=0ec3d1a6cf1fbe79c153
Link: https://syzkaller.appspot.com/ai_job?id=00724ef7-fd77-4cde-9779-895b8f63c2f6
Signed-off-by: Slawomir Stepien <sst@poczta.fm>
Link: https://patch.msgid.link/20260730065231.1644030-1-sst@poczta.fm
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/wireless/zydas/zd1211rw/zd_usb.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/drivers/net/wireless/zydas/zd1211rw/zd_usb.c b/drivers/net/wireless/zydas/zd1211rw/zd_usb.c
index 8ee15a15f4ca2..ebf4e29c566c8 100644
--- a/drivers/net/wireless/zydas/zd1211rw/zd_usb.c
+++ b/drivers/net/wireless/zydas/zd1211rw/zd_usb.c
@@ -1353,6 +1353,14 @@ static int probe(struct usb_interface *intf, const struct usb_device_id *id)
struct zd_usb *usb;
struct ieee80211_hw *hw = NULL;
+ /*
+ * ZD1211 devices are single-function. Reject secondary interfaces
+ * to prevent multiple instances from conflicting on hardcoded endpoints
+ * and triggering recursive locking warnings.
+ */
+ if (intf->cur_altsetting->desc.bInterfaceNumber != 0)
+ return -ENODEV;
+
print_id(udev);
if (id->driver_info & DEVICE_INSTALLER)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0815/1518] wifi: mac80211: skip unused probe response countdown offsets
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (813 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0814/1518] wifi: zd1211rw: reject secondary interfaces to prevent conflicts Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0816/1518] wifi: mac80211: disconnect on CSA to channel 0 Greg Kroah-Hartman
` (183 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zhao Li, Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhao Li <enderaoelyther@gmail.com>
[ Upstream commit fd2bf5e718108c00732eb07fd94a5d8830f62a9f ]
mac80211 copies cfg80211's variable-length countdown offset list into a
zero-initialized fixed-size array, leaving unused entries at zero. The
beacon branch already skips those zero entries, but the AP probe-response
branch writes through them unconditionally.
When a probe-response template has no countdown offset, the write through
an unused zero entry overwrites resp->data[0], corrupting the first byte of
the template. cfg80211 already bounds explicitly supplied non-zero offsets
in nl80211_parse_counter_offsets(), so this is a zero-sentinel bug, not an
out-of-bounds write.
Skip zero probe-response offsets, matching the beacon path.
Fixes: af296bdb8da4 ("mac80211: move csa counters from sdata to beacon/presp")
Link: https://lore.kernel.org/all/20260708195911.84365-6-enderaoelyther@gmail.com/
Assisted-by: Codex:gpt-5
Assisted-by: Claude:opus-4.8
Signed-off-by: Zhao Li <enderaoelyther@gmail.com>
Link: https://patch.msgid.link/20260723011001.76851-1-enderaoelyther@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/tx.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/net/mac80211/tx.c b/net/mac80211/tx.c
index c125871adb62b..89eb340e982b2 100644
--- a/net/mac80211/tx.c
+++ b/net/mac80211/tx.c
@@ -5140,7 +5140,8 @@ static void ieee80211_set_beacon_cntdwn(struct ieee80211_sub_if_data *sdata,
if (sdata->vif.type == NL80211_IFTYPE_AP && resp) {
u16 *resp_offsets = resp->cntdwn_counter_offsets;
- resp->data[resp_offsets[i]] = count;
+ if (resp_offsets[i])
+ resp->data[resp_offsets[i]] = count;
}
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0816/1518] wifi: mac80211: disconnect on CSA to channel 0
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (814 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0815/1518] wifi: mac80211: skip unused probe response countdown offsets Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0817/1518] wifi: cfg80211: include S1G_NO_PRIMARY flag when sending channel Greg Kroah-Hartman
` (182 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Johannes Berg, Emmanuel Grumbach,
Miri Korenblit, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit cf57f0a674cc3e3cda1a789359cc1238b61b9d7d ]
The refactor for the CSA parsing erroneously equates channel
zero and no information present, leading it to ignore a CSA
on an AP that advertises a switch to that (invalid) channel.
This leads to not disconnecting, which we should. For Intel
devices, this can lead to a firmware crash.
Fix this by using an int type for the channel number as well
as the opclass, and using a (negative) value that cannot be
encoded in the element to indicate it's not present.
Fixes: 21c3f8f95554 ("wifi: mac80211: refactor STA CSA parsing flows")
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Reviewed-by: Emmanuel Grumbach <emmanuel.grumbach@intel.com>
Signed-off-by: Miri Korenblit <miriam.rachel.korenblit@intel.com>
Link: https://patch.msgid.link/20260802111213.3bc833515e40.I255c37c31ca8b0b34e351cf254e16b6071dd8fb3@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/spectmgmt.c | 11 ++++++-----
1 file changed, 6 insertions(+), 5 deletions(-)
diff --git a/net/mac80211/spectmgmt.c b/net/mac80211/spectmgmt.c
index 7422888d36409..080235ca23fc5 100644
--- a/net/mac80211/spectmgmt.c
+++ b/net/mac80211/spectmgmt.c
@@ -227,7 +227,7 @@ int ieee80211_parse_ch_switch_ie(struct ieee80211_sub_if_data *sdata,
{
enum nl80211_band new_band = current_band;
int new_freq;
- u8 new_chan_no = 0, new_op_class = 0;
+ int new_chan_no = -1, new_op_class = -1;
struct ieee80211_channel *new_chan;
struct cfg80211_chan_def new_chandef = {};
const struct ieee80211_sec_chan_offs_ie *sec_chan_offs;
@@ -256,7 +256,7 @@ int ieee80211_parse_ch_switch_ie(struct ieee80211_sub_if_data *sdata,
new_op_class = ext_chansw_elem->new_operating_class;
if (!ieee80211_operating_class_to_band(new_op_class, &new_band)) {
- new_op_class = 0;
+ new_op_class = -1;
if (!unprot_action)
sdata_info(sdata,
"cannot understand ECSA IE operating class, %d, ignoring\n",
@@ -268,14 +268,14 @@ int ieee80211_parse_ch_switch_ie(struct ieee80211_sub_if_data *sdata,
}
}
- if (!new_op_class && elems->ch_switch_ie) {
+ if (new_op_class < 0 && elems->ch_switch_ie) {
new_chan_no = elems->ch_switch_ie->new_ch_num;
csa_ie->count = elems->ch_switch_ie->count;
csa_ie->mode = elems->ch_switch_ie->mode;
}
/* nothing here we understand */
- if (!new_chan_no)
+ if (new_chan_no < 0)
return 1;
/* Mesh Channel Switch Parameters Element */
@@ -359,7 +359,8 @@ int ieee80211_parse_ch_switch_ie(struct ieee80211_sub_if_data *sdata,
get_unaligned_le16(bwi->info.optional);
} else if (!wide_bw_chansw_ie || !wbcs_elem_to_chandef(wide_bw_chansw_ie,
&new_chandef)) {
- if (!ieee80211_operating_class_to_chandef(new_op_class, new_chan,
+ if (new_op_class < 0 ||
+ !ieee80211_operating_class_to_chandef(new_op_class, new_chan,
&new_chandef))
new_chandef = csa_ie->chanreq.oper;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0817/1518] wifi: cfg80211: include S1G_NO_PRIMARY flag when sending channel
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (815 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0816/1518] wifi: mac80211: disconnect on CSA to channel 0 Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0818/1518] wifi: nl80211: Add support for EPP peer indication Greg Kroah-Hartman
` (181 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lachlan Hodges, Johannes Berg,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lachlan Hodges <lachlan.hodges@morsemicro.com>
[ Upstream commit e1cbdf78f60c35a1a320ca401852fd6a73624a4a ]
When sending a channel ensure we include the IEEE80211_CHAN_S1G_NO_PRIMARY
flag.
Signed-off-by: Lachlan Hodges <lachlan.hodges@morsemicro.com>
Link: https://patch.msgid.link/20260109081439.3168-1-lachlan.hodges@morsemicro.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Stable-dep-of: 6c5fc504d0d6 ("wifi: cfg80211: stop PMSR before P2P and NAN teardown")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/uapi/linux/nl80211.h | 4 ++++
net/wireless/nl80211.c | 3 +++
2 files changed, 7 insertions(+)
diff --git a/include/uapi/linux/nl80211.h b/include/uapi/linux/nl80211.h
index 8134f10e4e6c0..964e1c779cdd3 100644
--- a/include/uapi/linux/nl80211.h
+++ b/include/uapi/linux/nl80211.h
@@ -4444,6 +4444,9 @@ enum nl80211_wmm_rule {
* channel in current regulatory domain.
* @NL80211_FREQUENCY_ATTR_NO_16MHZ: 16 MHz operation is not allowed on this
* channel in current regulatory domain.
+ * @NL80211_FREQUENCY_ATTR_S1G_NO_PRIMARY: Channel is not permitted for use
+ * as a primary channel. Does not prevent the channel from existing
+ * as a non-primary subchannel. Only applicable to S1G channels.
* @NL80211_FREQUENCY_ATTR_MAX: highest frequency attribute number
* currently defined
* @__NL80211_FREQUENCY_ATTR_AFTER_LAST: internal use
@@ -4492,6 +4495,7 @@ enum nl80211_frequency_attr {
NL80211_FREQUENCY_ATTR_NO_4MHZ,
NL80211_FREQUENCY_ATTR_NO_8MHZ,
NL80211_FREQUENCY_ATTR_NO_16MHZ,
+ NL80211_FREQUENCY_ATTR_S1G_NO_PRIMARY,
/* keep last */
__NL80211_FREQUENCY_ATTR_AFTER_LAST,
diff --git a/net/wireless/nl80211.c b/net/wireless/nl80211.c
index 776dcf8835d71..541d86cc6018a 100644
--- a/net/wireless/nl80211.c
+++ b/net/wireless/nl80211.c
@@ -1316,6 +1316,9 @@ static int nl80211_msg_put_channel(struct sk_buff *msg, struct wiphy *wiphy,
if ((chan->flags & IEEE80211_CHAN_NO_16MHZ) &&
nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_16MHZ))
goto nla_put_failure;
+ if ((chan->flags & IEEE80211_CHAN_S1G_NO_PRIMARY) &&
+ nla_put_flag(msg, NL80211_FREQUENCY_ATTR_S1G_NO_PRIMARY))
+ goto nla_put_failure;
}
if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0818/1518] wifi: nl80211: Add support for EPP peer indication
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (816 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0817/1518] wifi: cfg80211: include S1G_NO_PRIMARY flag when sending channel Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0819/1518] wifi: ieee80211: add some initial UHR definitions Greg Kroah-Hartman
` (180 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rohan Dutta, Sai Pratyusha Magam,
Kavita Kavita, Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sai Pratyusha Magam <sai.magam@oss.qualcomm.com>
[ Upstream commit 6ee3a22c61cdf57d71592ec9f3b9439cd5d0c75f ]
Introduce a new netlink attribute NL80211_ATTR_EPP_PEER
to be used with NL80211_CMD_NEW_STA and
NL80211_CMD_ADD_LINK_STA for the userspace to indicate
that a non-AP STA is an Enhanced Privacy Protection (EPP)
peer.
Co-developed-by: Rohan Dutta <quic_drohan@quicinc.com>
Signed-off-by: Rohan Dutta <quic_drohan@quicinc.com>
Signed-off-by: Sai Pratyusha Magam <sai.magam@oss.qualcomm.com>
Signed-off-by: Kavita Kavita <kavita.kavita@oss.qualcomm.com>
Link: https://patch.msgid.link/20260114111900.2196941-5-kavita.kavita@oss.qualcomm.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Stable-dep-of: 6c5fc504d0d6 ("wifi: cfg80211: stop PMSR before P2P and NAN teardown")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/cfg80211.h | 2 ++
include/uapi/linux/nl80211.h | 5 +++++
net/wireless/nl80211.c | 5 +++++
3 files changed, 12 insertions(+)
diff --git a/include/net/cfg80211.h b/include/net/cfg80211.h
index 1509be85139ec..99d6508a36ba8 100644
--- a/include/net/cfg80211.h
+++ b/include/net/cfg80211.h
@@ -1784,6 +1784,7 @@ struct cfg80211_ttlm_params {
* present/updated
* @eml_cap: EML capabilities of this station
* @link_sta_params: link related params.
+ * @epp_peer: EPP peer indication
*/
struct station_parameters {
struct net_device *vlan;
@@ -1810,6 +1811,7 @@ struct station_parameters {
bool eml_cap_present;
u16 eml_cap;
struct link_station_parameters link_sta_params;
+ bool epp_peer;
};
/**
diff --git a/include/uapi/linux/nl80211.h b/include/uapi/linux/nl80211.h
index 964e1c779cdd3..19e32a1b9a7fd 100644
--- a/include/uapi/linux/nl80211.h
+++ b/include/uapi/linux/nl80211.h
@@ -2973,6 +2973,9 @@ enum nl80211_commands {
* primary channel is 2 MHz wide, and the control channel designates
* the 1 MHz primary subchannel within that 2 MHz primary.
*
+ * @NL80211_ATTR_EPP_PEER: A flag attribute to indicate if the peer is an EPP
+ * STA. Used with %NL80211_CMD_NEW_STA and %NL80211_CMD_ADD_LINK_STA
+ *
* @NUM_NL80211_ATTR: total number of nl80211_attrs available
* @NL80211_ATTR_MAX: highest attribute number currently defined
* @__NL80211_ATTR_AFTER_LAST: internal use
@@ -3541,6 +3544,8 @@ enum nl80211_attrs {
NL80211_ATTR_S1G_PRIMARY_2MHZ,
+ NL80211_ATTR_EPP_PEER,
+
/* add attributes here, update the policy in nl80211.c */
__NL80211_ATTR_AFTER_LAST,
diff --git a/net/wireless/nl80211.c b/net/wireless/nl80211.c
index 541d86cc6018a..fa877abe6de50 100644
--- a/net/wireless/nl80211.c
+++ b/net/wireless/nl80211.c
@@ -934,6 +934,7 @@ static const struct nla_policy nl80211_policy[NUM_NL80211_ATTR] = {
NLA_POLICY_NESTED(nl80211_s1g_short_beacon),
[NL80211_ATTR_BSS_PARAM] = { .type = NLA_FLAG },
[NL80211_ATTR_S1G_PRIMARY_2MHZ] = { .type = NLA_FLAG },
+ [NL80211_ATTR_EPP_PEER] = { .type = NLA_FLAG },
};
/* policy for the key attributes */
@@ -8791,6 +8792,10 @@ static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
goto out;
}
}
+
+ params.epp_peer =
+ nla_get_flag(info->attrs[NL80211_ATTR_EPP_PEER]);
+
err = rdev_add_station(rdev, dev, mac_addr, ¶ms);
out:
dev_put(params.vlan);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0819/1518] wifi: ieee80211: add some initial UHR definitions
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (817 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0818/1518] wifi: nl80211: Add support for EPP peer indication Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0820/1518] wifi: cfg80211: add initial UHR support Greg Kroah-Hartman
` (179 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit a7cb50156e8206562b001b3bb625045a0ee0f651 ]
This is based on Draft P802.11bn_D1.2, but that's still very
incomplete, so don't handle a number of things and make some
local decisions such as using 40 bits for MAC capabilities
and 8 bits for PHY capabilities.
Link: https://patch.msgid.link/20260130164259.b28c9456ff94.I5b11fb0345a933bf497fd802aecc72932d58dd68@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Stable-dep-of: 6c5fc504d0d6 ("wifi: cfg80211: stop PMSR before P2P and NAN teardown")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/ieee80211-uhr.h | 220 ++++++++++++++++++++++++++++++++++
include/linux/ieee80211.h | 33 ++++-
2 files changed, 251 insertions(+), 2 deletions(-)
create mode 100644 include/linux/ieee80211-uhr.h
diff --git a/include/linux/ieee80211-uhr.h b/include/linux/ieee80211-uhr.h
new file mode 100644
index 0000000000000..132acced7d798
--- /dev/null
+++ b/include/linux/ieee80211-uhr.h
@@ -0,0 +1,220 @@
+/* SPDX-License-Identifier: GPL-2.0-only */
+/*
+ * IEEE 802.11 UHR definitions
+ *
+ * Copyright (c) 2025-2026 Intel Corporation
+ */
+#ifndef LINUX_IEEE80211_UHR_H
+#define LINUX_IEEE80211_UHR_H
+
+#include <linux/types.h>
+#include <linux/if_ether.h>
+
+#define IEEE80211_UHR_OPER_PARAMS_DPS_ENA 0x0001
+#define IEEE80211_UHR_OPER_PARAMS_NPCA_ENA 0x0002
+#define IEEE80211_UHR_OPER_PARAMS_DBE_ENA 0x0004
+#define IEEE80211_UHR_OPER_PARAMS_PEDCA_ENA 0x0008
+
+struct ieee80211_uhr_operation {
+ __le16 params;
+ u8 basic_mcs_nss_set[4];
+ u8 variable[];
+} __packed;
+
+#define IEEE80211_UHR_NPCA_PARAMS_PRIMARY_CHAN_OFFS 0x0000000F
+#define IEEE80211_UHR_NPCA_PARAMS_MIN_DUR_THRESH 0x000000F0
+#define IEEE80211_UHR_NPCA_PARAMS_SWITCH_DELAY 0x00003F00
+#define IEEE80211_UHR_NPCA_PARAMS_SWITCH_BACK_DELAY 0x000FC000
+#define IEEE80211_UHR_NPCA_PARAMS_INIT_QSRC 0x00300000
+#define IEEE80211_UHR_NPCA_PARAMS_MOPLEN 0x00400000
+#define IEEE80211_UHR_NPCA_PARAMS_DIS_SUBCH_BMAP_PRES 0x00800000
+
+struct ieee80211_uhr_npca_info {
+ __le32 params;
+ __le16 dis_subch_bmap[];
+} __packed;
+
+static inline bool ieee80211_uhr_oper_size_ok(const u8 *data, u8 len,
+ bool beacon)
+{
+ const struct ieee80211_uhr_operation *oper = (const void *)data;
+ u8 needed = sizeof(*oper);
+
+ if (len < needed)
+ return false;
+
+ /* nothing else present in beacons */
+ if (beacon)
+ return true;
+
+ /* FIXME: DPS, DBE, P-EDCA (consider order, also relative to NPCA) */
+
+ if (oper->params & cpu_to_le16(IEEE80211_UHR_OPER_PARAMS_NPCA_ENA)) {
+ const struct ieee80211_uhr_npca_info *npca =
+ (const void *)oper->variable;
+
+ needed += sizeof(*npca);
+
+ if (len < needed)
+ return false;
+
+ if (npca->params & cpu_to_le32(IEEE80211_UHR_NPCA_PARAMS_DIS_SUBCH_BMAP_PRES))
+ needed += sizeof(npca->dis_subch_bmap[0]);
+ }
+
+ return len >= needed;
+}
+
+/*
+ * Note: cannot call this on the element coming from a beacon,
+ * must ensure ieee80211_uhr_oper_size_ok(..., false) first
+ */
+static inline const struct ieee80211_uhr_npca_info *
+ieee80211_uhr_npca_info(const struct ieee80211_uhr_operation *oper)
+{
+ if (!(oper->params & cpu_to_le16(IEEE80211_UHR_OPER_PARAMS_NPCA_ENA)))
+ return NULL;
+
+ /* FIXME: DPS */
+
+ return (const void *)oper->variable;
+}
+
+static inline const __le16 *
+ieee80211_uhr_npca_dis_subch_bitmap(const struct ieee80211_uhr_operation *oper)
+{
+ const struct ieee80211_uhr_npca_info *npca;
+
+ npca = ieee80211_uhr_npca_info(oper);
+ if (!npca)
+ return NULL;
+ if (!(npca->params & cpu_to_le32(IEEE80211_UHR_NPCA_PARAMS_DIS_SUBCH_BMAP_PRES)))
+ return NULL;
+ return npca->dis_subch_bmap;
+}
+
+#define IEEE80211_UHR_MAC_CAP0_DPS_SUPP 0x01
+#define IEEE80211_UHR_MAC_CAP0_DPS_ASSIST_SUPP 0x02
+#define IEEE80211_UHR_MAC_CAP0_DPS_AP_STATIC_HCM_SUPP 0x04
+#define IEEE80211_UHR_MAC_CAP0_NPCA_SUPP 0x10
+#define IEEE80211_UHR_MAC_CAP0_ENH_BSR_SUPP 0x20
+#define IEEE80211_UHR_MAC_CAP0_ADD_MAP_TID_SUPP 0x40
+#define IEEE80211_UHR_MAC_CAP0_EOTSP_SUPP 0x80
+
+#define IEEE80211_UHR_MAC_CAP1_DSO_SUPP 0x01
+#define IEEE80211_UHR_MAC_CAP1_PEDCA_SUPP 0x02
+#define IEEE80211_UHR_MAC_CAP1_DBE_SUPP 0x04
+#define IEEE80211_UHR_MAC_CAP1_UL_LLI_SUPP 0x08
+#define IEEE80211_UHR_MAC_CAP1_P2P_LLI_SUPP 0x10
+#define IEEE80211_UHR_MAC_CAP1_PUO_SUPP 0x20
+#define IEEE80211_UHR_MAC_CAP1_AP_PUO_SUPP 0x40
+#define IEEE80211_UHR_MAC_CAP1_DUO_SUPP 0x80
+
+#define IEEE80211_UHR_MAC_CAP2_OMC_UL_MU_DIS_RX_SUPP 0x01
+#define IEEE80211_UHR_MAC_CAP2_AOM_SUPP 0x02
+#define IEEE80211_UHR_MAC_CAP2_IFCS_LOC_SUPP 0x04
+#define IEEE80211_UHR_MAC_CAP2_UHR_TRS_SUPP 0x08
+#define IEEE80211_UHR_MAC_CAP2_TXSPG_SUPP 0x10
+#define IEEE80211_UHR_MAC_CAP2_TXOP_RET_IN_TXSPG 0x20
+#define IEEE80211_UHR_MAC_CAP2_UHR_OM_PU_TO_LOW 0xC0
+
+#define IEEE80211_UHR_MAC_CAP3_UHR_OM_PU_TO_HIGH 0x03
+#define IEEE80211_UHR_MAC_CAP3_PARAM_UPD_ADV_NOTIF_INTV 0x1C
+#define IEEE80211_UHR_MAC_CAP3_UPD_IND_TIM_INTV_LOW 0xE0
+
+#define IEEE80211_UHR_MAC_CAP4_UPD_IND_TIM_INTV_HIGH 0x03
+#define IEEE80211_UHR_MAC_CAP4_BOUNDED_ESS 0x04
+#define IEEE80211_UHR_MAC_CAP4_BTM_ASSURANCE 0x08
+#define IEEE80211_UHR_MAC_CAP4_CO_BF_SUPP 0x10
+
+#define IEEE80211_UHR_MAC_CAP_DBE_MAX_BW 0x07
+#define IEEE80211_UHR_MAC_CAP_DBE_EHT_MCS_MAP_160_PRES 0x08
+#define IEEE80211_UHR_MAC_CAP_DBE_EHT_MCS_MAP_320_PRES 0x10
+
+struct ieee80211_uhr_cap_mac {
+ u8 mac_cap[5];
+} __packed;
+
+struct ieee80211_uhr_cap {
+ struct ieee80211_uhr_cap_mac mac;
+ /* DBE, PHY capabilities */
+ u8 variable[];
+} __packed;
+
+#define IEEE80211_UHR_PHY_CAP_MAX_NSS_RX_SND_NDP_LE80 0x01
+#define IEEE80211_UHR_PHY_CAP_MAX_NSS_RX_DL_MU_LE80 0x02
+#define IEEE80211_UHR_PHY_CAP_MAX_NSS_RX_SND_NDP_160 0x04
+#define IEEE80211_UHR_PHY_CAP_MAX_NSS_RX_DL_MU_160 0x08
+#define IEEE80211_UHR_PHY_CAP_MAX_NSS_RX_SND_NDP_320 0x10
+#define IEEE80211_UHR_PHY_CAP_MAX_NSS_RX_DL_MU_320 0x20
+#define IEEE80211_UHR_PHY_CAP_ELR_RX 0x40
+#define IEEE80211_UHR_PHY_CAP_ELR_TX 0x80
+
+struct ieee80211_uhr_cap_phy {
+ u8 cap;
+} __packed;
+
+static inline bool ieee80211_uhr_capa_size_ok(const u8 *data, u8 len,
+ bool from_ap)
+{
+ const struct ieee80211_uhr_cap *cap = (const void *)data;
+ size_t needed = sizeof(*cap) + sizeof(struct ieee80211_uhr_cap_phy);
+
+ if (len < needed)
+ return false;
+
+ /*
+ * A non-AP STA does not include the DBE Capability Parameters field
+ * in the UHR MAC Capabilities Information field.
+ */
+ if (from_ap && cap->mac.mac_cap[1] & IEEE80211_UHR_MAC_CAP1_DBE_SUPP) {
+ u8 dbe;
+
+ needed += 1;
+ if (len < needed)
+ return false;
+
+ dbe = cap->variable[0];
+
+ if (dbe & IEEE80211_UHR_MAC_CAP_DBE_EHT_MCS_MAP_160_PRES)
+ needed += 3;
+
+ if (dbe & IEEE80211_UHR_MAC_CAP_DBE_EHT_MCS_MAP_320_PRES)
+ needed += 3;
+ }
+
+ return len >= needed;
+}
+
+static inline const struct ieee80211_uhr_cap_phy *
+ieee80211_uhr_phy_cap(const struct ieee80211_uhr_cap *cap, bool from_ap)
+{
+ u8 offs = 0;
+
+ if (from_ap && cap->mac.mac_cap[1] & IEEE80211_UHR_MAC_CAP1_DBE_SUPP) {
+ u8 dbe = cap->variable[0];
+
+ offs += 1;
+
+ if (dbe & IEEE80211_UHR_MAC_CAP_DBE_EHT_MCS_MAP_160_PRES)
+ offs += 3;
+
+ if (dbe & IEEE80211_UHR_MAC_CAP_DBE_EHT_MCS_MAP_320_PRES)
+ offs += 3;
+ }
+
+ return (const void *)&cap->variable[offs];
+}
+
+#define IEEE80211_SMD_INFO_CAPA_DL_DATA_FWD 0x01
+#define IEEE80211_SMD_INFO_CAPA_MAX_NUM_PREP 0x0E
+#define IEEE80211_SMD_INFO_CAPA_TYPE 0x10
+#define IEEE80211_SMD_INFO_CAPA_PTK_PER_AP_MLD 0x20
+
+struct ieee80211_smd_info {
+ u8 id[ETH_ALEN];
+ u8 capa;
+ __le16 timeout;
+} __packed;
+
+#endif /* LINUX_IEEE80211_UHR_H */
diff --git a/include/linux/ieee80211.h b/include/linux/ieee80211.h
index 992a0c09c1e53..2526ccd8a4a06 100644
--- a/include/linux/ieee80211.h
+++ b/include/linux/ieee80211.h
@@ -9,7 +9,7 @@
* Copyright (c) 2006, Michael Wu <flamingice@sourmilk.net>
* Copyright (c) 2013 - 2014 Intel Mobile Communications GmbH
* Copyright (c) 2016 - 2017 Intel Deutschland GmbH
- * Copyright (c) 2018 - 2025 Intel Corporation
+ * Copyright (c) 2018 - 2026 Intel Corporation
*/
#ifndef LINUX_IEEE80211_H
@@ -1381,8 +1381,9 @@ struct ieee80211_mgmt {
#define BSS_MEMBERSHIP_SELECTOR_SAE_H2E 123
#define BSS_MEMBERSHIP_SELECTOR_HE_PHY 122
#define BSS_MEMBERSHIP_SELECTOR_EHT_PHY 121
+#define BSS_MEMBERSHIP_SELECTOR_UHR_PHY 120
-#define BSS_MEMBERSHIP_SELECTOR_MIN BSS_MEMBERSHIP_SELECTOR_EHT_PHY
+#define BSS_MEMBERSHIP_SELECTOR_MIN BSS_MEMBERSHIP_SELECTOR_UHR_PHY
/* mgmt header + 1 byte category code */
#define IEEE80211_MIN_ACTION_SIZE offsetof(struct ieee80211_mgmt, u.action.u)
@@ -2117,6 +2118,15 @@ enum ieee80211_eid_ext {
WLAN_EID_EXT_BANDWIDTH_INDICATION = 135,
WLAN_EID_EXT_KNOWN_STA_IDENTIFCATION = 136,
WLAN_EID_EXT_NON_AP_STA_REG_CON = 137,
+ WLAN_EID_EXT_UHR_OPER = 151,
+ WLAN_EID_EXT_UHR_CAPA = 152,
+ WLAN_EID_EXT_MACP = 153,
+ WLAN_EID_EXT_SMD = 154,
+ WLAN_EID_EXT_BSS_SMD_TRANS_PARAMS = 155,
+ WLAN_EID_EXT_CHAN_USAGE = 156,
+ WLAN_EID_EXT_UHR_MODE_CHG = 157,
+ WLAN_EID_EXT_UHR_PARAM_UPD = 158,
+ WLAN_EID_EXT_TXPI = 159,
};
/* Action category code */
@@ -3352,6 +3362,22 @@ static inline bool for_each_element_completed(const struct element *element,
#define WLAN_RSNX_CAPA_PROTECTED_TWT BIT(4)
#define WLAN_RSNX_CAPA_SAE_H2E BIT(5)
+/* EBPCC = Enhanced BSS Parameter Change Count */
+#define IEEE80211_ENH_CRIT_UPD_EBPCC 0x0F
+#define IEEE80211_ENH_CRIT_UPD_TYPE 0x70
+#define IEEE80211_ENH_CRIT_UPD_TYPE_NO_UHR 0
+#define IEEE80211_ENH_CRIT_UPD_TYPE_UHR 1
+#define IEEE80211_ENH_CRIT_UPD_ALL 0x80
+
+/**
+ * struct ieee80211_enh_crit_upd - enhanced critical update (UHR)
+ * @v: value of the enhanced critical update data,
+ * see %IEEE80211_ENH_CRIT_UPD_* to parse the bits
+ */
+struct ieee80211_enh_crit_upd {
+ u8 v;
+} __packed;
+
/*
* reduced neighbor report, based on Draft P802.11ax_D6.1,
* section 9.4.2.170 and accepted contributions.
@@ -3370,6 +3396,7 @@ static inline bool for_each_element_completed(const struct element *element,
#define IEEE80211_RNR_TBTT_PARAMS_COLOC_ESS 0x10
#define IEEE80211_RNR_TBTT_PARAMS_PROBE_ACTIVE 0x20
#define IEEE80211_RNR_TBTT_PARAMS_COLOC_AP 0x40
+#define IEEE80211_RNR_TBTT_PARAMS_SAME_SMD 0x80
#define IEEE80211_RNR_TBTT_PARAMS_PSD_NO_LIMIT 127
#define IEEE80211_RNR_TBTT_PARAMS_PSD_RESERVED -128
@@ -3422,6 +3449,7 @@ struct ieee80211_tbtt_info_ge_11 {
u8 bss_params;
s8 psd_20;
struct ieee80211_rnr_mld_params mld_params;
+ struct ieee80211_enh_crit_upd enh_crit_upd;
} __packed;
/* NAN operation mode, as defined in Wi-Fi Aware (TM) specification Table 81 */
@@ -3445,6 +3473,7 @@ struct ieee80211_tbtt_info_ge_11 {
#include "ieee80211-vht.h"
#include "ieee80211-he.h"
#include "ieee80211-eht.h"
+#include "ieee80211-uhr.h"
#include "ieee80211-mesh.h"
#endif /* LINUX_IEEE80211_H */
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0820/1518] wifi: cfg80211: add initial UHR support
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (818 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0819/1518] wifi: ieee80211: add some initial UHR definitions Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0821/1518] wifi: cfg80211: add support to handle incumbent signal detected event from mac80211/driver Greg Kroah-Hartman
` (178 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit 072e6f7f416f5d17be71000b31fb108651ad360d ]
Add initial support for making UHR connections (or suppressing
that), adding UHR capable stations on the AP side, encoding
and decoding UHR MCSes (except rate calculation for the new
MCSes 17, 19, 20 and 23) as well as regulatory support.
Link: https://patch.msgid.link/20260130164259.54cc12fbb307.I26126bebd83c7ab17e99827489f946ceabb3521f@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Stable-dep-of: 6c5fc504d0d6 ("wifi: cfg80211: stop PMSR before P2P and NAN teardown")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/cfg80211.h | 58 ++++++++++++++++++--
include/uapi/linux/nl80211.h | 30 +++++++++++
net/wireless/nl80211.c | 102 +++++++++++++++++++++++++++++++++--
net/wireless/reg.c | 4 +-
net/wireless/util.c | 101 ++++++++++++++++++++++++++--------
5 files changed, 265 insertions(+), 30 deletions(-)
diff --git a/include/net/cfg80211.h b/include/net/cfg80211.h
index 99d6508a36ba8..3cb8d45579d42 100644
--- a/include/net/cfg80211.h
+++ b/include/net/cfg80211.h
@@ -7,7 +7,7 @@
* Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
* Copyright 2013-2014 Intel Mobile Communications GmbH
* Copyright 2015-2017 Intel Deutschland GmbH
- * Copyright (C) 2018-2025 Intel Corporation
+ * Copyright (C) 2018-2026 Intel Corporation
*/
#include <linux/ethtool.h>
@@ -126,6 +126,7 @@ struct wiphy;
* @IEEE80211_CHAN_NO_4MHZ: 4 MHz bandwidth is not permitted on this channel.
* @IEEE80211_CHAN_NO_8MHZ: 8 MHz bandwidth is not permitted on this channel.
* @IEEE80211_CHAN_NO_16MHZ: 16 MHz bandwidth is not permitted on this channel.
+ * @IEEE80211_CHAN_NO_UHR: UHR operation is not permitted on this channel.
*/
enum ieee80211_channel_flags {
IEEE80211_CHAN_DISABLED = BIT(0),
@@ -143,6 +144,7 @@ enum ieee80211_channel_flags {
IEEE80211_CHAN_NO_10MHZ = BIT(12),
IEEE80211_CHAN_NO_HE = BIT(13),
/* can use free bits here */
+ IEEE80211_CHAN_NO_UHR = BIT(18),
IEEE80211_CHAN_NO_320MHZ = BIT(19),
IEEE80211_CHAN_NO_EHT = BIT(20),
IEEE80211_CHAN_DFS_CONCURRENT = BIT(21),
@@ -429,6 +431,18 @@ struct ieee80211_sta_eht_cap {
u8 eht_ppe_thres[IEEE80211_EHT_PPE_THRES_MAX_LEN];
};
+/**
+ * struct ieee80211_sta_uhr_cap - STA's UHR capabilities
+ * @has_uhr: true iff UHR is supported and data is valid
+ * @mac: fixed MAC capabilities
+ * @phy: fixed PHY capabilities
+ */
+struct ieee80211_sta_uhr_cap {
+ bool has_uhr;
+ struct ieee80211_uhr_cap_mac mac;
+ struct ieee80211_uhr_cap_phy phy;
+};
+
/* sparse defines __CHECKER__; see Documentation/dev-tools/sparse.rst */
#ifdef __CHECKER__
/*
@@ -454,6 +468,7 @@ struct ieee80211_sta_eht_cap {
* @he_6ghz_capa: HE 6 GHz capabilities, must be filled in for a
* 6 GHz band channel (and 0 may be valid value).
* @eht_cap: STA's EHT capabilities
+ * @uhr_cap: STA's UHR capabilities
* @vendor_elems: vendor element(s) to advertise
* @vendor_elems.data: vendor element(s) data
* @vendor_elems.len: vendor element(s) length
@@ -463,6 +478,7 @@ struct ieee80211_sband_iftype_data {
struct ieee80211_sta_he_cap he_cap;
struct ieee80211_he_6ghz_capa he_6ghz_capa;
struct ieee80211_sta_eht_cap eht_cap;
+ struct ieee80211_sta_uhr_cap uhr_cap;
struct {
const u8 *data;
unsigned int len;
@@ -704,6 +720,26 @@ ieee80211_get_eht_iftype_cap(const struct ieee80211_supported_band *sband,
return NULL;
}
+/**
+ * ieee80211_get_uhr_iftype_cap - return UHR capabilities for an sband's iftype
+ * @sband: the sband to search for the iftype on
+ * @iftype: enum nl80211_iftype
+ *
+ * Return: pointer to the struct ieee80211_sta_uhr_cap, or NULL is none found
+ */
+static inline const struct ieee80211_sta_uhr_cap *
+ieee80211_get_uhr_iftype_cap(const struct ieee80211_supported_band *sband,
+ enum nl80211_iftype iftype)
+{
+ const struct ieee80211_sband_iftype_data *data =
+ ieee80211_get_sband_iftype_data(sband, iftype);
+
+ if (data && data->uhr_cap.has_uhr)
+ return &data->uhr_cap;
+
+ return NULL;
+}
+
/**
* wiphy_read_of_freq_limits - read frequency limits from device tree
*
@@ -1485,6 +1521,7 @@ struct cfg80211_s1g_short_beacon {
* @he_cap: HE capabilities (or %NULL if HE isn't enabled)
* @eht_cap: EHT capabilities (or %NULL if EHT isn't enabled)
* @eht_oper: EHT operation IE (or %NULL if EHT isn't enabled)
+ * @uhr_oper: UHR operation (or %NULL if UHR isn't enabled)
* @ht_required: stations must support HT
* @vht_required: stations must support VHT
* @twt_responder: Enable Target Wait Time
@@ -1524,6 +1561,7 @@ struct cfg80211_ap_settings {
const struct ieee80211_he_operation *he_oper;
const struct ieee80211_eht_cap_elem *eht_cap;
const struct ieee80211_eht_operation *eht_oper;
+ const struct ieee80211_uhr_operation *uhr_oper;
bool ht_required, vht_required, he_required, sae_h2e_required;
bool twt_responder;
u32 flags;
@@ -1697,6 +1735,8 @@ struct sta_txpwr {
* @eht_capa: EHT capabilities of station
* @eht_capa_len: the length of the EHT capabilities
* @s1g_capa: S1G capabilities of station
+ * @uhr_capa: UHR capabilities of the station
+ * @uhr_capa_len: the length of the UHR capabilities
*/
struct link_station_parameters {
const u8 *mld_mac;
@@ -1716,6 +1756,8 @@ struct link_station_parameters {
const struct ieee80211_eht_cap_elem *eht_capa;
u8 eht_capa_len;
const struct ieee80211_s1g_cap *s1g_capa;
+ const struct ieee80211_uhr_cap *uhr_capa;
+ u8 uhr_capa_len;
};
/**
@@ -1897,6 +1939,11 @@ int cfg80211_check_station_change(struct wiphy *wiphy,
* @RATE_INFO_FLAGS_EXTENDED_SC_DMG: 60GHz extended SC MCS
* @RATE_INFO_FLAGS_EHT_MCS: EHT MCS information
* @RATE_INFO_FLAGS_S1G_MCS: MCS field filled with S1G MCS
+ * @RATE_INFO_FLAGS_UHR_MCS: UHR MCS information
+ * @RATE_INFO_FLAGS_UHR_ELR_MCS: UHR ELR MCS was used
+ * (set together with @RATE_INFO_FLAGS_UHR_MCS)
+ * @RATE_INFO_FLAGS_UHR_IM: UHR Interference Mitigation
+ * was used
*/
enum rate_info_flags {
RATE_INFO_FLAGS_MCS = BIT(0),
@@ -1908,6 +1955,9 @@ enum rate_info_flags {
RATE_INFO_FLAGS_EXTENDED_SC_DMG = BIT(6),
RATE_INFO_FLAGS_EHT_MCS = BIT(7),
RATE_INFO_FLAGS_S1G_MCS = BIT(8),
+ RATE_INFO_FLAGS_UHR_MCS = BIT(9),
+ RATE_INFO_FLAGS_UHR_ELR_MCS = BIT(10),
+ RATE_INFO_FLAGS_UHR_IM = BIT(11),
};
/**
@@ -1923,7 +1973,7 @@ enum rate_info_flags {
* @RATE_INFO_BW_160: 160 MHz bandwidth
* @RATE_INFO_BW_HE_RU: bandwidth determined by HE RU allocation
* @RATE_INFO_BW_320: 320 MHz bandwidth
- * @RATE_INFO_BW_EHT_RU: bandwidth determined by EHT RU allocation
+ * @RATE_INFO_BW_EHT_RU: bandwidth determined by EHT/UHR RU allocation
* @RATE_INFO_BW_1: 1 MHz bandwidth
* @RATE_INFO_BW_2: 2 MHz bandwidth
* @RATE_INFO_BW_4: 4 MHz bandwidth
@@ -1954,7 +2004,7 @@ enum rate_info_bw {
*
* @flags: bitflag of flags from &enum rate_info_flags
* @legacy: bitrate in 100kbit/s for 802.11abg
- * @mcs: mcs index if struct describes an HT/VHT/HE/EHT/S1G rate
+ * @mcs: mcs index if struct describes an HT/VHT/HE/EHT/S1G/UHR rate
* @nss: number of streams (VHT & HE only)
* @bw: bandwidth (from &enum rate_info_bw)
* @he_gi: HE guard interval (from &enum nl80211_he_gi)
@@ -3264,6 +3314,7 @@ struct cfg80211_ml_reconf_req {
* Drivers shall disable MLO features for the current association if this
* flag is not set.
* @ASSOC_REQ_SPP_AMSDU: SPP A-MSDUs will be used on this connection (if any)
+ * @ASSOC_REQ_DISABLE_UHR: Disable UHR
*/
enum cfg80211_assoc_req_flags {
ASSOC_REQ_DISABLE_HT = BIT(0),
@@ -3274,6 +3325,7 @@ enum cfg80211_assoc_req_flags {
ASSOC_REQ_DISABLE_EHT = BIT(5),
CONNECT_REQ_MLO_SUPPORT = BIT(6),
ASSOC_REQ_SPP_AMSDU = BIT(7),
+ ASSOC_REQ_DISABLE_UHR = BIT(8),
};
/**
diff --git a/include/uapi/linux/nl80211.h b/include/uapi/linux/nl80211.h
index 19e32a1b9a7fd..4bb3d32838989 100644
--- a/include/uapi/linux/nl80211.h
+++ b/include/uapi/linux/nl80211.h
@@ -2976,6 +2976,13 @@ enum nl80211_commands {
* @NL80211_ATTR_EPP_PEER: A flag attribute to indicate if the peer is an EPP
* STA. Used with %NL80211_CMD_NEW_STA and %NL80211_CMD_ADD_LINK_STA
*
+ * @NL80211_ATTR_UHR_CAPABILITY: UHR Capability information element (from
+ * association request when used with NL80211_CMD_NEW_STATION). Can be set
+ * only if HE/EHT are also available.
+ * @NL80211_ATTR_DISABLE_UHR: Force UHR capable interfaces to disable
+ * this feature during association. This is a flag attribute.
+ * Currently only supported in mac80211 drivers.
+ *
* @NUM_NL80211_ATTR: total number of nl80211_attrs available
* @NL80211_ATTR_MAX: highest attribute number currently defined
* @__NL80211_ATTR_AFTER_LAST: internal use
@@ -3546,6 +3553,9 @@ enum nl80211_attrs {
NL80211_ATTR_EPP_PEER,
+ NL80211_ATTR_UHR_CAPABILITY,
+ NL80211_ATTR_DISABLE_UHR,
+
/* add attributes here, update the policy in nl80211.c */
__NL80211_ATTR_AFTER_LAST,
@@ -3898,6 +3908,12 @@ enum nl80211_eht_ru_alloc {
* @NL80211_RATE_INFO_4_MHZ_WIDTH: 4 MHz S1G rate
* @NL80211_RATE_INFO_8_MHZ_WIDTH: 8 MHz S1G rate
* @NL80211_RATE_INFO_16_MHZ_WIDTH: 16 MHz S1G rate
+ * @NL80211_RATE_INFO_UHR_MCS: UHR MCS index (u8, 0-15, 17, 19, 20, 23)
+ * Note that the other EHT attributes (such as @NL80211_RATE_INFO_EHT_NSS)
+ * are used in conjunction with this where applicable
+ * @NL80211_RATE_INFO_UHR_ELR: UHR ELR flag, which restricts NSS to 1,
+ * MCS to 0 or 1, and GI to %NL80211_RATE_INFO_EHT_GI_1_6.
+ * @NL80211_RATE_INFO_UHR_IM: UHR Interference Mitigation flag
* @__NL80211_RATE_INFO_AFTER_LAST: internal use
*/
enum nl80211_rate_info {
@@ -3931,6 +3947,9 @@ enum nl80211_rate_info {
NL80211_RATE_INFO_4_MHZ_WIDTH,
NL80211_RATE_INFO_8_MHZ_WIDTH,
NL80211_RATE_INFO_16_MHZ_WIDTH,
+ NL80211_RATE_INFO_UHR_MCS,
+ NL80211_RATE_INFO_UHR_ELR,
+ NL80211_RATE_INFO_UHR_IM,
/* keep last */
__NL80211_RATE_INFO_AFTER_LAST,
@@ -4253,6 +4272,10 @@ enum nl80211_mpath_info {
* capabilities element
* @NL80211_BAND_IFTYPE_ATTR_EHT_CAP_PPE: EHT PPE thresholds information as
* defined in EHT capabilities element
+ * @NL80211_BAND_IFTYPE_ATTR_UHR_CAP_MAC: UHR MAC capabilities as in UHR
+ * capabilities element
+ * @NL80211_BAND_IFTYPE_ATTR_UHR_CAP_PHY: UHR PHY capabilities as in UHR
+ * capabilities element
* @__NL80211_BAND_IFTYPE_ATTR_AFTER_LAST: internal use
* @NL80211_BAND_IFTYPE_ATTR_MAX: highest band attribute currently defined
*/
@@ -4270,6 +4293,8 @@ enum nl80211_band_iftype_attr {
NL80211_BAND_IFTYPE_ATTR_EHT_CAP_PHY,
NL80211_BAND_IFTYPE_ATTR_EHT_CAP_MCS_SET,
NL80211_BAND_IFTYPE_ATTR_EHT_CAP_PPE,
+ NL80211_BAND_IFTYPE_ATTR_UHR_CAP_MAC,
+ NL80211_BAND_IFTYPE_ATTR_UHR_CAP_PHY,
/* keep last */
__NL80211_BAND_IFTYPE_ATTR_AFTER_LAST,
@@ -4452,6 +4477,8 @@ enum nl80211_wmm_rule {
* @NL80211_FREQUENCY_ATTR_S1G_NO_PRIMARY: Channel is not permitted for use
* as a primary channel. Does not prevent the channel from existing
* as a non-primary subchannel. Only applicable to S1G channels.
+ * @NL80211_FREQUENCY_ATTR_NO_UHR: UHR operation is not allowed on this channel
+ * in current regulatory domain.
* @NL80211_FREQUENCY_ATTR_MAX: highest frequency attribute number
* currently defined
* @__NL80211_FREQUENCY_ATTR_AFTER_LAST: internal use
@@ -4501,6 +4528,7 @@ enum nl80211_frequency_attr {
NL80211_FREQUENCY_ATTR_NO_8MHZ,
NL80211_FREQUENCY_ATTR_NO_16MHZ,
NL80211_FREQUENCY_ATTR_S1G_NO_PRIMARY,
+ NL80211_FREQUENCY_ATTR_NO_UHR,
/* keep last */
__NL80211_FREQUENCY_ATTR_AFTER_LAST,
@@ -4714,6 +4742,7 @@ enum nl80211_sched_scan_match_attr {
* despite NO_IR configuration.
* @NL80211_RRF_ALLOW_20MHZ_ACTIVITY: Allow activity in 20 MHz bandwidth,
* despite NO_IR configuration.
+ * @NL80211_RRF_NO_UHR: UHR operation not allowed
*/
enum nl80211_reg_rule_flags {
NL80211_RRF_NO_OFDM = 1 << 0,
@@ -4740,6 +4769,7 @@ enum nl80211_reg_rule_flags {
NL80211_RRF_NO_6GHZ_AFC_CLIENT = 1 << 23,
NL80211_RRF_ALLOW_6GHZ_VLP_AP = 1 << 24,
NL80211_RRF_ALLOW_20MHZ_ACTIVITY = 1 << 25,
+ NL80211_RRF_NO_UHR = 1 << 26,
};
#define NL80211_RRF_PASSIVE_SCAN NL80211_RRF_NO_IR
diff --git a/net/wireless/nl80211.c b/net/wireless/nl80211.c
index fa877abe6de50..1227a2055d6f1 100644
--- a/net/wireless/nl80211.c
+++ b/net/wireless/nl80211.c
@@ -332,6 +332,15 @@ static int validate_nan_cluster_id(const struct nlattr *attr,
return 0;
}
+static int validate_uhr_capa(const struct nlattr *attr,
+ struct netlink_ext_ack *extack)
+{
+ const u8 *data = nla_data(attr);
+ unsigned int len = nla_len(attr);
+
+ return ieee80211_uhr_capa_size_ok(data, len, false);
+}
+
/* policy for the attributes */
static const struct nla_policy nl80211_policy[NUM_NL80211_ATTR];
@@ -935,6 +944,9 @@ static const struct nla_policy nl80211_policy[NUM_NL80211_ATTR] = {
[NL80211_ATTR_BSS_PARAM] = { .type = NLA_FLAG },
[NL80211_ATTR_S1G_PRIMARY_2MHZ] = { .type = NLA_FLAG },
[NL80211_ATTR_EPP_PEER] = { .type = NLA_FLAG },
+ [NL80211_ATTR_UHR_CAPABILITY] =
+ NLA_POLICY_VALIDATE_FN(NLA_BINARY, validate_uhr_capa, 255),
+ [NL80211_ATTR_DISABLE_UHR] = { .type = NLA_FLAG },
};
/* policy for the key attributes */
@@ -1320,6 +1332,9 @@ static int nl80211_msg_put_channel(struct sk_buff *msg, struct wiphy *wiphy,
if ((chan->flags & IEEE80211_CHAN_S1G_NO_PRIMARY) &&
nla_put_flag(msg, NL80211_FREQUENCY_ATTR_S1G_NO_PRIMARY))
goto nla_put_failure;
+ if ((chan->flags & IEEE80211_CHAN_NO_UHR) &&
+ nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_UHR))
+ goto nla_put_failure;
}
if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
@@ -1953,6 +1968,7 @@ nl80211_send_iftype_data(struct sk_buff *msg,
{
const struct ieee80211_sta_he_cap *he_cap = &iftdata->he_cap;
const struct ieee80211_sta_eht_cap *eht_cap = &iftdata->eht_cap;
+ const struct ieee80211_sta_uhr_cap *uhr_cap = &iftdata->uhr_cap;
if (nl80211_put_iftypes(msg, NL80211_BAND_IFTYPE_ATTR_IFTYPES,
iftdata->types_mask))
@@ -2004,6 +2020,14 @@ nl80211_send_iftype_data(struct sk_buff *msg,
return -ENOBUFS;
}
+ if (uhr_cap->has_uhr) {
+ if (nla_put(msg, NL80211_BAND_IFTYPE_ATTR_UHR_CAP_MAC,
+ sizeof(uhr_cap->mac), &uhr_cap->mac) ||
+ nla_put(msg, NL80211_BAND_IFTYPE_ATTR_UHR_CAP_PHY,
+ sizeof(uhr_cap->phy), &uhr_cap->phy))
+ return -ENOBUFS;
+ }
+
if (sband->band == NL80211_BAND_6GHZ &&
nla_put(msg, NL80211_BAND_IFTYPE_ATTR_HE_6GHZ_CAPA,
sizeof(iftdata->he_6ghz_capa),
@@ -6442,6 +6466,17 @@ static int nl80211_calculate_ap_params(struct cfg80211_ap_settings *params)
cap->datalen - 1))
return -EINVAL;
}
+
+ cap = cfg80211_find_ext_elem(WLAN_EID_EXT_UHR_OPER, ies, ies_len);
+ if (cap) {
+ if (!cap->datalen)
+ return -EINVAL;
+ params->uhr_oper = (void *)(cap->data + 1);
+ if (!ieee80211_uhr_oper_size_ok((const u8 *)params->uhr_oper,
+ cap->datalen - 1, true))
+ return -EINVAL;
+ }
+
return 0;
}
@@ -6565,6 +6600,9 @@ static int nl80211_validate_ap_phy_operation(struct cfg80211_ap_settings *params
(channel->flags & IEEE80211_CHAN_NO_EHT))
return -EOPNOTSUPP;
+ if (params->uhr_oper && (channel->flags & IEEE80211_CHAN_NO_UHR))
+ return -EOPNOTSUPP;
+
return 0;
}
@@ -7147,7 +7185,8 @@ bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info, int attr)
break;
case RATE_INFO_BW_EHT_RU:
rate_flg = 0;
- WARN_ON(!(info->flags & RATE_INFO_FLAGS_EHT_MCS));
+ WARN_ON(!(info->flags & RATE_INFO_FLAGS_EHT_MCS) &&
+ !(info->flags & RATE_INFO_FLAGS_UHR_MCS));
break;
}
@@ -7200,6 +7239,23 @@ bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info, int attr)
nla_put_u8(msg, NL80211_RATE_INFO_EHT_RU_ALLOC,
info->eht_ru_alloc))
return false;
+ } else if (info->flags & RATE_INFO_FLAGS_UHR_MCS) {
+ if (nla_put_u8(msg, NL80211_RATE_INFO_UHR_MCS, info->mcs))
+ return false;
+ if (nla_put_u8(msg, NL80211_RATE_INFO_EHT_NSS, info->nss))
+ return false;
+ if (nla_put_u8(msg, NL80211_RATE_INFO_EHT_GI, info->eht_gi))
+ return false;
+ if (info->bw == RATE_INFO_BW_EHT_RU &&
+ nla_put_u8(msg, NL80211_RATE_INFO_EHT_RU_ALLOC,
+ info->eht_ru_alloc))
+ return false;
+ if (info->flags & RATE_INFO_FLAGS_UHR_ELR_MCS &&
+ nla_put_flag(msg, NL80211_RATE_INFO_UHR_ELR))
+ return false;
+ if (info->flags & RATE_INFO_FLAGS_UHR_IM &&
+ nla_put_flag(msg, NL80211_RATE_INFO_UHR_IM))
+ return false;
}
nla_nest_end(msg, rate);
@@ -8073,7 +8129,8 @@ int cfg80211_check_station_change(struct wiphy *wiphy,
if (params->ext_capab || params->link_sta_params.ht_capa ||
params->link_sta_params.vht_capa ||
params->link_sta_params.he_capa ||
- params->link_sta_params.eht_capa)
+ params->link_sta_params.eht_capa ||
+ params->link_sta_params.uhr_capa)
return -EINVAL;
if (params->sta_flags_mask & BIT(NL80211_STA_FLAG_SPP_AMSDU))
return -EINVAL;
@@ -8293,6 +8350,16 @@ static int nl80211_set_station_tdls(struct genl_info *info,
}
}
+ if (info->attrs[NL80211_ATTR_UHR_CAPABILITY]) {
+ if (!params->link_sta_params.eht_capa)
+ return -EINVAL;
+
+ params->link_sta_params.uhr_capa =
+ nla_data(info->attrs[NL80211_ATTR_UHR_CAPABILITY]);
+ params->link_sta_params.uhr_capa_len =
+ nla_len(info->attrs[NL80211_ATTR_UHR_CAPABILITY]);
+ }
+
if (info->attrs[NL80211_ATTR_S1G_CAPABILITY])
params->link_sta_params.s1g_capa =
nla_data(info->attrs[NL80211_ATTR_S1G_CAPABILITY]);
@@ -8613,6 +8680,16 @@ static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
}
}
+ if (info->attrs[NL80211_ATTR_UHR_CAPABILITY]) {
+ if (!params.link_sta_params.eht_capa)
+ return -EINVAL;
+
+ params.link_sta_params.uhr_capa =
+ nla_data(info->attrs[NL80211_ATTR_UHR_CAPABILITY]);
+ params.link_sta_params.uhr_capa_len =
+ nla_len(info->attrs[NL80211_ATTR_UHR_CAPABILITY]);
+ }
+
if (info->attrs[NL80211_ATTR_EML_CAPABILITY]) {
params.eml_cap_present = true;
params.eml_cap =
@@ -8672,10 +8749,11 @@ static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
params.link_sta_params.ht_capa = NULL;
params.link_sta_params.vht_capa = NULL;
- /* HE and EHT require WME */
+ /* HE, EHT and UHR require WME */
if (params.link_sta_params.he_capa_len ||
params.link_sta_params.he_6ghz_capa ||
- params.link_sta_params.eht_capa_len)
+ params.link_sta_params.eht_capa_len ||
+ params.link_sta_params.uhr_capa_len)
return -EINVAL;
}
@@ -12349,6 +12427,9 @@ static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_EHT]))
req.flags |= ASSOC_REQ_DISABLE_EHT;
+ if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_UHR]))
+ req.flags |= ASSOC_REQ_DISABLE_UHR;
+
if (info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
memcpy(&req.vht_capa_mask,
nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]),
@@ -13228,6 +13309,9 @@ static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_EHT]))
connect.flags |= ASSOC_REQ_DISABLE_EHT;
+ if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_UHR]))
+ connect.flags |= ASSOC_REQ_DISABLE_UHR;
+
if (info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
memcpy(&connect.vht_capa_mask,
nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]),
@@ -17653,6 +17737,16 @@ nl80211_add_mod_link_station(struct sk_buff *skb, struct genl_info *info,
}
}
+ if (info->attrs[NL80211_ATTR_UHR_CAPABILITY]) {
+ if (!params.eht_capa)
+ return -EINVAL;
+
+ params.uhr_capa =
+ nla_data(info->attrs[NL80211_ATTR_UHR_CAPABILITY]);
+ params.uhr_capa_len =
+ nla_len(info->attrs[NL80211_ATTR_UHR_CAPABILITY]);
+ }
+
if (info->attrs[NL80211_ATTR_HE_6GHZ_CAPABILITY])
params.he_6ghz_capa =
nla_data(info->attrs[NL80211_ATTR_HE_6GHZ_CAPABILITY]);
diff --git a/net/wireless/reg.c b/net/wireless/reg.c
index 73cab51f63790..15e56dfad00f7 100644
--- a/net/wireless/reg.c
+++ b/net/wireless/reg.c
@@ -5,7 +5,7 @@
* Copyright 2008-2011 Luis R. Rodriguez <mcgrof@qca.qualcomm.com>
* Copyright 2013-2014 Intel Mobile Communications GmbH
* Copyright 2017 Intel Deutschland GmbH
- * Copyright (C) 2018 - 2025 Intel Corporation
+ * Copyright (C) 2018 - 2026 Intel Corporation
*
* Permission to use, copy, modify, and/or distribute this software for any
* purpose with or without fee is hereby granted, provided that the above
@@ -1605,6 +1605,8 @@ static u32 map_regdom_flags(u32 rd_flags)
channel_flags |= IEEE80211_CHAN_ALLOW_6GHZ_VLP_AP;
if (rd_flags & NL80211_RRF_ALLOW_20MHZ_ACTIVITY)
channel_flags |= IEEE80211_CHAN_ALLOW_20MHZ_ACTIVITY;
+ if (rd_flags & NL80211_RRF_NO_UHR)
+ channel_flags |= IEEE80211_CHAN_NO_UHR;
return channel_flags;
}
diff --git a/net/wireless/util.c b/net/wireless/util.c
index 81d6d27d273cc..918d8f8468bdb 100644
--- a/net/wireless/util.c
+++ b/net/wireless/util.c
@@ -5,7 +5,7 @@
* Copyright 2007-2009 Johannes Berg <johannes@sipsolutions.net>
* Copyright 2013-2014 Intel Mobile Communications GmbH
* Copyright 2017 Intel Deutschland GmbH
- * Copyright (C) 2018-2023, 2025 Intel Corporation
+ * Copyright (C) 2018-2023, 2025-2026 Intel Corporation
*/
#include <linux/export.h>
#include <linux/bitops.h>
@@ -1573,26 +1573,30 @@ static u32 cfg80211_calculate_bitrate_he(struct rate_info *rate)
return result / 10000;
}
-static u32 cfg80211_calculate_bitrate_eht(struct rate_info *rate)
+static u32 _cfg80211_calculate_bitrate_eht_uhr(struct rate_info *rate)
{
#define SCALE 6144
- static const u32 mcs_divisors[16] = {
- 102399, /* 16.666666... */
- 51201, /* 8.333333... */
- 34134, /* 5.555555... */
- 25599, /* 4.166666... */
- 17067, /* 2.777777... */
- 12801, /* 2.083333... */
- 11377, /* 1.851725... */
- 10239, /* 1.666666... */
- 8532, /* 1.388888... */
- 7680, /* 1.250000... */
- 6828, /* 1.111111... */
- 6144, /* 1.000000... */
- 5690, /* 0.926106... */
- 5120, /* 0.833333... */
- 409600, /* 66.666666... */
- 204800, /* 33.333333... */
+ static const u32 mcs_divisors[] = {
+ [ 0] = 102399, /* 16.666666... */
+ [ 1] = 51201, /* 8.333333... */
+ [ 2] = 34134, /* 5.555555... */
+ [ 3] = 25599, /* 4.166666... */
+ [ 4] = 17067, /* 2.777777... */
+ [ 5] = 12801, /* 2.083333... */
+ [ 6] = 11377, /* 1.851725... */
+ [ 7] = 10239, /* 1.666666... */
+ [ 8] = 8532, /* 1.388888... */
+ [ 9] = 7680, /* 1.250000... */
+ [10] = 6828, /* 1.111111... */
+ [11] = 6144, /* 1.000000... */
+ [12] = 5690, /* 0.926106... */
+ [13] = 5120, /* 0.833333... */
+ [14] = 409600, /* 66.666666... */
+ [15] = 204800, /* 33.333333... */
+ [17] = 38400, /* 6.250180... */
+ [19] = 19200, /* 3.125090... */
+ [20] = 15360, /* 2.500000... */
+ [23] = 9600, /* 1.562545... */
};
static const u32 rates_996[3] = { 480388888, 453700000, 408333333 };
static const u32 rates_484[3] = { 229411111, 216666666, 195000000 };
@@ -1603,8 +1607,6 @@ static u32 cfg80211_calculate_bitrate_eht(struct rate_info *rate)
u64 tmp;
u32 result;
- if (WARN_ON_ONCE(rate->mcs > 15))
- return 0;
if (WARN_ON_ONCE(rate->eht_gi > NL80211_RATE_INFO_EHT_GI_3_2))
return 0;
if (WARN_ON_ONCE(rate->eht_ru_alloc >
@@ -1685,7 +1687,7 @@ static u32 cfg80211_calculate_bitrate_eht(struct rate_info *rate)
rate->eht_ru_alloc == NL80211_RATE_INFO_EHT_RU_ALLOC_26)
result = rates_26[rate->eht_gi];
else {
- WARN(1, "invalid EHT MCS: bw:%d, ru:%d\n",
+ WARN(1, "invalid EHT or UHR MCS: bw:%d, ru:%d\n",
rate->bw, rate->eht_ru_alloc);
return 0;
}
@@ -1699,11 +1701,64 @@ static u32 cfg80211_calculate_bitrate_eht(struct rate_info *rate)
tmp *= rate->nss;
do_div(tmp, 8);
+ /* and handle interference mitigation - 0.9x */
+ if (rate->flags & RATE_INFO_FLAGS_UHR_IM) {
+ if (WARN(rate->nss != 1 || rate->mcs == 15,
+ "invalid NSS or MCS for UHR IM\n"))
+ return 0;
+ tmp *= 9000;
+ do_div(tmp, 10000);
+ }
+
result = tmp;
return result / 10000;
}
+static u32 cfg80211_calculate_bitrate_eht(struct rate_info *rate)
+{
+ if (WARN_ONCE(rate->mcs > 15, "bad EHT MCS %d\n", rate->mcs))
+ return 0;
+
+ if (WARN_ONCE(rate->flags & (RATE_INFO_FLAGS_UHR_ELR_MCS |
+ RATE_INFO_FLAGS_UHR_IM),
+ "bad EHT MCS flags 0x%x\n", rate->flags))
+ return 0;
+
+ return _cfg80211_calculate_bitrate_eht_uhr(rate);
+}
+
+static u32 cfg80211_calculate_bitrate_uhr(struct rate_info *rate)
+{
+ if (rate->flags & RATE_INFO_FLAGS_UHR_ELR_MCS) {
+ WARN_ONCE(rate->eht_gi != NL80211_RATE_INFO_EHT_GI_1_6,
+ "bad UHR ELR guard interval %d\n",
+ rate->eht_gi);
+ WARN_ONCE(rate->mcs > 1, "bad UHR ELR MCS %d\n", rate->mcs);
+ WARN_ONCE(rate->nss != 1, "bad UHR ELR NSS %d\n", rate->nss);
+ WARN_ONCE(rate->bw != RATE_INFO_BW_20,
+ "bad UHR ELR bandwidth %d\n",
+ rate->bw);
+ WARN_ONCE(rate->flags & RATE_INFO_FLAGS_UHR_IM,
+ "bad UHR MCS flags 0x%x\n", rate->flags);
+ if (rate->mcs == 0)
+ return 17;
+ return 33;
+ }
+
+ switch (rate->mcs) {
+ case 0 ... 15:
+ case 17:
+ case 19:
+ case 20:
+ case 23:
+ return _cfg80211_calculate_bitrate_eht_uhr(rate);
+ }
+
+ WARN_ONCE(1, "bad UHR MCS %d\n", rate->mcs);
+ return 0;
+}
+
static u32 cfg80211_calculate_bitrate_s1g(struct rate_info *rate)
{
/* For 1, 2, 4, 8 and 16 MHz channels */
@@ -1828,6 +1883,8 @@ u32 cfg80211_calculate_bitrate(struct rate_info *rate)
return cfg80211_calculate_bitrate_he(rate);
if (rate->flags & RATE_INFO_FLAGS_EHT_MCS)
return cfg80211_calculate_bitrate_eht(rate);
+ if (rate->flags & RATE_INFO_FLAGS_UHR_MCS)
+ return cfg80211_calculate_bitrate_uhr(rate);
if (rate->flags & RATE_INFO_FLAGS_S1G_MCS)
return cfg80211_calculate_bitrate_s1g(rate);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0821/1518] wifi: cfg80211: add support to handle incumbent signal detected event from mac80211/driver
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (819 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0820/1518] wifi: cfg80211: add initial UHR support Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0822/1518] wifi: nl80211: refactor nl80211_parse_chandef Greg Kroah-Hartman
` (177 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Hari Chandrakanthan, Amith A,
Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Hari Chandrakanthan <quic_haric@quicinc.com>
[ Upstream commit 6a584e336cefb230e2d981a464f4d85562eb750c ]
When any incumbent signal is detected by an AP/mesh interface operating
in 6 GHz band, FCC mandates the AP/mesh to vacate the channels affected
by it [1].
Add a new API cfg80211_incumbent_signal_notify() that can be used
by mac80211 or drivers to notify the higher layers about the signal
interference event with the interference bitmap in which each bit
denotes the affected 20 MHz in the operating channel.
Add support for the new nl80211 event and nl80211 attribute as well to
notify userspace on the details about the interference event. Userspace is
expected to process it and take further action - vacate the channel, or
reduce the bandwidth.
[1] - https://apps.fcc.gov/kdb/GetAttachment.html?id=nXQiRC%2B4mfiA54Zha%2BrW4Q%3D%3D&desc=987594%20D02%20U-NII%206%20GHz%20EMC%20Measurement%20v03&tracking_number=277034
Signed-off-by: Hari Chandrakanthan <quic_haric@quicinc.com>
Signed-off-by: Amith A <amith.a@oss.qualcomm.com>
Link: https://patch.msgid.link/20260216032027.2310956-2-amith.a@oss.qualcomm.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Stable-dep-of: 6c5fc504d0d6 ("wifi: cfg80211: stop PMSR before P2P and NAN teardown")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/cfg80211.h | 23 +++++++++++++++++++++
include/uapi/linux/nl80211.h | 19 +++++++++++++++++
net/wireless/nl80211.c | 40 ++++++++++++++++++++++++++++++++++++
net/wireless/trace.h | 19 +++++++++++++++++
4 files changed, 101 insertions(+)
diff --git a/include/net/cfg80211.h b/include/net/cfg80211.h
index 3cb8d45579d42..c44c35dedc589 100644
--- a/include/net/cfg80211.h
+++ b/include/net/cfg80211.h
@@ -10382,4 +10382,27 @@ cfg80211_s1g_get_primary_sibling(struct wiphy *wiphy,
return ieee80211_get_channel_khz(wiphy, sibling_1mhz_khz);
}
+
+/**
+ * cfg80211_incumbent_signal_notify - Notify userspace of incumbent signal detection
+ * @wiphy: the wiphy to use
+ * @chandef: channel definition in which the interference was detected
+ * @signal_interference_bitmap: bitmap indicating interference across 20 MHz segments
+ * @gfp: allocation context for message creation and multicast; pass GFP_ATOMIC
+ * if called from atomic context (e.g. firmware event handler), otherwise
+ * GFP_KERNEL
+ *
+ * Use this function to notify userspace when an incumbent signal is detected on
+ * the operating channel in the 6 GHz band. The notification includes the
+ * current channel definition and a bitmap representing interference across
+ * the operating bandwidth. Each bit in the bitmap corresponds to a 20 MHz
+ * segment, with the lowest bit representing the lowest frequency segment.
+ * Punctured sub-channels are included in the bitmap structure but are always
+ * set to zero since interference detection is not performed on them.
+ */
+void cfg80211_incumbent_signal_notify(struct wiphy *wiphy,
+ const struct cfg80211_chan_def *chandef,
+ u32 signal_interference_bitmap,
+ gfp_t gfp);
+
#endif /* __NET_CFG80211_H */
diff --git a/include/uapi/linux/nl80211.h b/include/uapi/linux/nl80211.h
index 4bb3d32838989..69152abd64b9a 100644
--- a/include/uapi/linux/nl80211.h
+++ b/include/uapi/linux/nl80211.h
@@ -1361,6 +1361,12 @@
* user space that the NAN new cluster has been joined. The cluster ID is
* indicated by %NL80211_ATTR_MAC.
*
+ * @NL80211_CMD_INCUMBENT_SIGNAL_DETECT: Once any incumbent signal is detected
+ * on the operating channel in 6 GHz band, userspace is notified with the
+ * signal interference bitmap using
+ * %NL80211_ATTR_INCUMBENT_SIGNAL_INTERFERENCE_BITMAP. The current channel
+ * definition is also sent.
+ *
* @NL80211_CMD_MAX: highest used command number
* @__NL80211_CMD_AFTER_LAST: internal use
*/
@@ -1624,6 +1630,8 @@ enum nl80211_commands {
NL80211_CMD_NAN_NEXT_DW_NOTIFICATION,
NL80211_CMD_NAN_CLUSTER_JOINED,
+ NL80211_CMD_INCUMBENT_SIGNAL_DETECT,
+
/* add new commands above here */
/* used to define NL80211_CMD_MAX below */
@@ -2983,6 +2991,15 @@ enum nl80211_commands {
* this feature during association. This is a flag attribute.
* Currently only supported in mac80211 drivers.
*
+ * @NL80211_ATTR_INCUMBENT_SIGNAL_INTERFERENCE_BITMAP: u32 attribute specifying
+ * the signal interference bitmap detected on the operating bandwidth for
+ * %NL80211_CMD_INCUMBENT_SIGNAL_DETECT. Each bit represents a 20 MHz
+ * segment, lowest bit corresponds to the lowest 20 MHz segment, in the
+ * operating bandwidth where the interference is detected. Punctured
+ * sub-channels are included in the bitmap structure; however, since
+ * interference detection is not performed on these sub-channels, their
+ * corresponding bits are consistently set to zero.
+ *
* @NUM_NL80211_ATTR: total number of nl80211_attrs available
* @NL80211_ATTR_MAX: highest attribute number currently defined
* @__NL80211_ATTR_AFTER_LAST: internal use
@@ -3556,6 +3573,8 @@ enum nl80211_attrs {
NL80211_ATTR_UHR_CAPABILITY,
NL80211_ATTR_DISABLE_UHR,
+ NL80211_ATTR_INCUMBENT_SIGNAL_INTERFERENCE_BITMAP,
+
/* add attributes here, update the policy in nl80211.c */
__NL80211_ATTR_AFTER_LAST,
diff --git a/net/wireless/nl80211.c b/net/wireless/nl80211.c
index 1227a2055d6f1..86848602c85b1 100644
--- a/net/wireless/nl80211.c
+++ b/net/wireless/nl80211.c
@@ -21102,6 +21102,46 @@ void cfg80211_ch_switch_notify(struct net_device *dev,
}
EXPORT_SYMBOL(cfg80211_ch_switch_notify);
+void cfg80211_incumbent_signal_notify(struct wiphy *wiphy,
+ const struct cfg80211_chan_def *chandef,
+ u32 signal_interference_bitmap,
+ gfp_t gfp)
+{
+ struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
+ struct sk_buff *msg;
+ void *hdr;
+
+ trace_cfg80211_incumbent_signal_notify(wiphy, chandef, signal_interference_bitmap);
+
+ msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
+ if (!msg)
+ return;
+
+ hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_INCUMBENT_SIGNAL_DETECT);
+ if (!hdr)
+ goto nla_put_failure;
+
+ if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
+ goto nla_put_failure;
+
+ if (nl80211_send_chandef(msg, chandef))
+ goto nla_put_failure;
+
+ if (nla_put_u32(msg, NL80211_ATTR_INCUMBENT_SIGNAL_INTERFERENCE_BITMAP,
+ signal_interference_bitmap))
+ goto nla_put_failure;
+
+ genlmsg_end(msg, hdr);
+
+ genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
+ NL80211_MCGRP_MLME, gfp);
+ return;
+
+nla_put_failure:
+ nlmsg_free(msg);
+}
+EXPORT_SYMBOL(cfg80211_incumbent_signal_notify);
+
void cfg80211_ch_switch_started_notify(struct net_device *dev,
struct cfg80211_chan_def *chandef,
unsigned int link_id, u8 count,
diff --git a/net/wireless/trace.h b/net/wireless/trace.h
index 2b71f1d867a08..27779d11b3733 100644
--- a/net/wireless/trace.h
+++ b/net/wireless/trace.h
@@ -4222,6 +4222,25 @@ TRACE_EVENT(cfg80211_nan_cluster_joined,
WDEV_PR_ARG, __entry->cluster_id,
__entry->new_cluster ? " [new]" : "")
);
+
+TRACE_EVENT(cfg80211_incumbent_signal_notify,
+ TP_PROTO(struct wiphy *wiphy,
+ const struct cfg80211_chan_def *chandef,
+ u32 signal_interference_bitmap),
+ TP_ARGS(wiphy, chandef, signal_interference_bitmap),
+ TP_STRUCT__entry(
+ WIPHY_ENTRY
+ CHAN_DEF_ENTRY
+ __field(u32, signal_interference_bitmap)
+ ),
+ TP_fast_assign(
+ WIPHY_ASSIGN;
+ CHAN_DEF_ASSIGN(chandef);
+ __entry->signal_interference_bitmap = signal_interference_bitmap;
+ ),
+ TP_printk(WIPHY_PR_FMT ", " CHAN_DEF_PR_FMT ", signal_interference_bitmap=0x%x",
+ WIPHY_PR_ARG, CHAN_DEF_PR_ARG, __entry->signal_interference_bitmap)
+);
#endif /* !__RDEV_OPS_TRACE || TRACE_HEADER_MULTI_READ */
#undef TRACE_INCLUDE_PATH
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0822/1518] wifi: nl80211: refactor nl80211_parse_chandef
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (820 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0821/1518] wifi: cfg80211: add support to handle incumbent signal detected event from mac80211/driver Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0823/1518] wifi: nl80211: split out UHR operation information Greg Kroah-Hartman
` (176 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Johannes Berg, Miri Korenblit,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Miri Korenblit <miriam.rachel.korenblit@intel.com>
[ Upstream commit 49a1e65c6d706703a8fcd54a5c5ca1f11f7e319b ]
In order to be able to use this function also for nested attributes,
change this function to receive a pointer to extack and to the
attributes array, instead of receiving the info and extracting them out
of it.
While at it, use NL_SET_ERR_MSG_ATTR with the frequency of the chandef.
Reviewed-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Miri Korenblit <miriam.rachel.korenblit@intel.com>
Link: https://patch.msgid.link/20260219114327.2b994566a63b.I6c2b6f4c7e2e09f4c47285ca4ac8a37b20700e19@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Stable-dep-of: 6c5fc504d0d6 ("wifi: cfg80211: stop PMSR before P2P and NAN teardown")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/nl80211.c | 67 ++++++++++++++++++++++++------------------
net/wireless/nl80211.h | 5 ++--
net/wireless/pmsr.c | 5 ++--
3 files changed, 44 insertions(+), 33 deletions(-)
diff --git a/net/wireless/nl80211.c b/net/wireless/nl80211.c
index 86848602c85b1..53b784cc8a3fd 100644
--- a/net/wireless/nl80211.c
+++ b/net/wireless/nl80211.c
@@ -3541,11 +3541,10 @@ static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
}
static int _nl80211_parse_chandef(struct cfg80211_registered_device *rdev,
- struct genl_info *info, bool monitor,
+ struct netlink_ext_ack *extack,
+ struct nlattr **attrs, bool monitor,
struct cfg80211_chan_def *chandef)
{
- struct netlink_ext_ack *extack = info->extack;
- struct nlattr **attrs = info->attrs;
u32 control_freq;
if (!attrs[NL80211_ATTR_WIPHY_FREQ]) {
@@ -3555,10 +3554,10 @@ static int _nl80211_parse_chandef(struct cfg80211_registered_device *rdev,
}
control_freq = MHZ_TO_KHZ(
- nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
- if (info->attrs[NL80211_ATTR_WIPHY_FREQ_OFFSET])
+ nla_get_u32(attrs[NL80211_ATTR_WIPHY_FREQ]));
+ if (attrs[NL80211_ATTR_WIPHY_FREQ_OFFSET])
control_freq +=
- nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ_OFFSET]);
+ nla_get_u32(attrs[NL80211_ATTR_WIPHY_FREQ_OFFSET]);
memset(chandef, 0, sizeof(*chandef));
chandef->chan = ieee80211_get_channel_khz(&rdev->wiphy, control_freq);
@@ -3626,40 +3625,43 @@ static int _nl80211_parse_chandef(struct cfg80211_registered_device *rdev,
attrs[NL80211_ATTR_S1G_PRIMARY_2MHZ]);
}
- if (info->attrs[NL80211_ATTR_WIPHY_EDMG_CHANNELS]) {
+ if (attrs[NL80211_ATTR_WIPHY_EDMG_CHANNELS]) {
chandef->edmg.channels =
- nla_get_u8(info->attrs[NL80211_ATTR_WIPHY_EDMG_CHANNELS]);
+ nla_get_u8(attrs[NL80211_ATTR_WIPHY_EDMG_CHANNELS]);
- if (info->attrs[NL80211_ATTR_WIPHY_EDMG_BW_CONFIG])
+ if (attrs[NL80211_ATTR_WIPHY_EDMG_BW_CONFIG])
chandef->edmg.bw_config =
- nla_get_u8(info->attrs[NL80211_ATTR_WIPHY_EDMG_BW_CONFIG]);
+ nla_get_u8(attrs[NL80211_ATTR_WIPHY_EDMG_BW_CONFIG]);
} else {
chandef->edmg.bw_config = 0;
chandef->edmg.channels = 0;
}
- if (info->attrs[NL80211_ATTR_PUNCT_BITMAP]) {
+ if (attrs[NL80211_ATTR_PUNCT_BITMAP]) {
chandef->punctured =
- nla_get_u32(info->attrs[NL80211_ATTR_PUNCT_BITMAP]);
+ nla_get_u32(attrs[NL80211_ATTR_PUNCT_BITMAP]);
if (chandef->punctured &&
!wiphy_ext_feature_isset(&rdev->wiphy,
NL80211_EXT_FEATURE_PUNCT)) {
- NL_SET_ERR_MSG(extack,
- "driver doesn't support puncturing");
+ NL_SET_ERR_MSG_ATTR(extack,
+ attrs[NL80211_ATTR_WIPHY_FREQ],
+ "driver doesn't support puncturing");
return -EINVAL;
}
}
if (!cfg80211_chandef_valid(chandef)) {
- NL_SET_ERR_MSG(extack, "invalid channel definition");
+ NL_SET_ERR_MSG_ATTR(extack, attrs[NL80211_ATTR_WIPHY_FREQ],
+ "invalid channel definition");
return -EINVAL;
}
if (!_cfg80211_chandef_usable(&rdev->wiphy, chandef,
IEEE80211_CHAN_DISABLED,
monitor ? IEEE80211_CHAN_CAN_MONITOR : 0)) {
- NL_SET_ERR_MSG(extack, "(extension) channel is disabled");
+ NL_SET_ERR_MSG_ATTR(extack, attrs[NL80211_ATTR_WIPHY_FREQ],
+ "(extension) channel is disabled");
return -EINVAL;
}
@@ -3674,10 +3676,11 @@ static int _nl80211_parse_chandef(struct cfg80211_registered_device *rdev,
}
int nl80211_parse_chandef(struct cfg80211_registered_device *rdev,
- struct genl_info *info,
+ struct netlink_ext_ack *extack,
+ struct nlattr **attrs,
struct cfg80211_chan_def *chandef)
{
- return _nl80211_parse_chandef(rdev, info, false, chandef);
+ return _nl80211_parse_chandef(rdev, extack, attrs, false, chandef);
}
static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
@@ -3704,7 +3707,7 @@ static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
link_id = 0;
}
- result = _nl80211_parse_chandef(rdev, info,
+ result = _nl80211_parse_chandef(rdev, info->extack, info->attrs,
iftype == NL80211_IFTYPE_MONITOR,
&chandef);
if (result)
@@ -6784,7 +6787,8 @@ static int nl80211_start_ap(struct sk_buff *skb, struct genl_info *info)
}
if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
- err = nl80211_parse_chandef(rdev, info, ¶ms->chandef);
+ err = nl80211_parse_chandef(rdev, info->extack, info->attrs,
+ ¶ms->chandef);
if (err)
goto out;
} else if (wdev->valid_links) {
@@ -11260,7 +11264,7 @@ static int nl80211_start_radar_detection(struct sk_buff *skb,
if (dfs_region == NL80211_DFS_UNSET)
return -EINVAL;
- err = nl80211_parse_chandef(rdev, info, &chandef);
+ err = nl80211_parse_chandef(rdev, info->extack, info->attrs, &chandef);
if (err)
return err;
@@ -11348,7 +11352,7 @@ static int nl80211_notify_radar_detection(struct sk_buff *skb,
return -EINVAL;
}
- err = nl80211_parse_chandef(rdev, info, &chandef);
+ err = nl80211_parse_chandef(rdev, info->extack, info->attrs, &chandef);
if (err) {
GENL_SET_ERR_MSG(info, "Unable to extract chandef info");
return err;
@@ -11534,7 +11538,8 @@ static int nl80211_channel_switch(struct sk_buff *skb, struct genl_info *info)
goto free;
skip_beacons:
- err = nl80211_parse_chandef(rdev, info, ¶ms.chandef);
+ err = nl80211_parse_chandef(rdev, info->extack, info->attrs,
+ ¶ms.chandef);
if (err)
goto free;
@@ -12763,7 +12768,8 @@ static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
}
- err = nl80211_parse_chandef(rdev, info, &ibss.chandef);
+ err = nl80211_parse_chandef(rdev, info->extack, info->attrs,
+ &ibss.chandef);
if (err)
return err;
@@ -13762,7 +13768,7 @@ static int nl80211_remain_on_channel(struct sk_buff *skb,
duration > rdev->wiphy.max_remain_on_channel_duration)
return -EINVAL;
- err = nl80211_parse_chandef(rdev, info, &chandef);
+ err = nl80211_parse_chandef(rdev, info->extack, info->attrs, &chandef);
if (err)
return err;
@@ -13978,7 +13984,8 @@ static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
*/
chandef.chan = NULL;
if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
- err = nl80211_parse_chandef(rdev, info, &chandef);
+ err = nl80211_parse_chandef(rdev, info->extack, info->attrs,
+ &chandef);
if (err)
return err;
}
@@ -14381,7 +14388,8 @@ static int nl80211_join_ocb(struct sk_buff *skb, struct genl_info *info)
struct ocb_setup setup = {};
int err;
- err = nl80211_parse_chandef(rdev, info, &setup.chandef);
+ err = nl80211_parse_chandef(rdev, info->extack, info->attrs,
+ &setup.chandef);
if (err)
return err;
@@ -14456,7 +14464,8 @@ static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
cfg.auto_open_plinks = false;
if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
- err = nl80211_parse_chandef(rdev, info, &setup.chandef);
+ err = nl80211_parse_chandef(rdev, info->extack, info->attrs,
+ &setup.chandef);
if (err)
return err;
} else {
@@ -16928,7 +16937,7 @@ static int nl80211_tdls_channel_switch(struct sk_buff *skb,
!info->attrs[NL80211_ATTR_OPER_CLASS])
return -EINVAL;
- err = nl80211_parse_chandef(rdev, info, &chandef);
+ err = nl80211_parse_chandef(rdev, info->extack, info->attrs, &chandef);
if (err)
return err;
diff --git a/net/wireless/nl80211.h b/net/wireless/nl80211.h
index 5e25782af1e07..048ba92c3e429 100644
--- a/net/wireless/nl80211.h
+++ b/net/wireless/nl80211.h
@@ -1,7 +1,7 @@
/* SPDX-License-Identifier: GPL-2.0 */
/*
* Portions of this file
- * Copyright (C) 2018, 2020-2024 Intel Corporation
+ * Copyright (C) 2018, 2020-2025 Intel Corporation
*/
#ifndef __NET_WIRELESS_NL80211_H
#define __NET_WIRELESS_NL80211_H
@@ -23,7 +23,8 @@ static inline u64 wdev_id(struct wireless_dev *wdev)
}
int nl80211_parse_chandef(struct cfg80211_registered_device *rdev,
- struct genl_info *info,
+ struct netlink_ext_ack *extack,
+ struct nlattr **attrs,
struct cfg80211_chan_def *chandef);
int nl80211_parse_random_mac(struct nlattr **attrs,
u8 *mac_addr, u8 *mac_addr_mask);
diff --git a/net/wireless/pmsr.c b/net/wireless/pmsr.c
index 06563f6084870..6882c39b73a46 100644
--- a/net/wireless/pmsr.c
+++ b/net/wireless/pmsr.c
@@ -1,6 +1,6 @@
/* SPDX-License-Identifier: GPL-2.0 */
/*
- * Copyright (C) 2018 - 2021, 2023 - 2024 Intel Corporation
+ * Copyright (C) 2018 - 2021, 2023 - 2026 Intel Corporation
*/
#include <net/cfg80211.h>
#include "core.h"
@@ -224,7 +224,8 @@ static int pmsr_parse_peer(struct cfg80211_registered_device *rdev,
if (err)
return err;
- err = nl80211_parse_chandef(rdev, info, &out->chandef);
+ err = nl80211_parse_chandef(rdev, info->extack, info->attrs,
+ &out->chandef);
if (err)
return err;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0823/1518] wifi: nl80211: split out UHR operation information
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (821 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0822/1518] wifi: nl80211: refactor nl80211_parse_chandef Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0824/1518] wifi: cfg80211: Add an API to configure local NAN schedule Greg Kroah-Hartman
` (175 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johannes Berg <johannes.berg@intel.com>
[ Upstream commit e4b993f2bca78357b430170574f8de7bc7874088 ]
The beacon doesn't contain the full UHR operation, a number
of fields (such as NPCA) are only partially there. Add a new
attribute to contain the full information, so it's available
to the driver/mac80211.
Link: https://patch.msgid.link/20260303221710.866bacf82639.Iafdf37fb0f4304bdcdb824977d61e17b38c47685@changeid
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Stable-dep-of: 6c5fc504d0d6 ("wifi: cfg80211: stop PMSR before P2P and NAN teardown")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/uapi/linux/nl80211.h | 6 ++++++
net/wireless/nl80211.c | 26 ++++++++++++++++----------
2 files changed, 22 insertions(+), 10 deletions(-)
diff --git a/include/uapi/linux/nl80211.h b/include/uapi/linux/nl80211.h
index 69152abd64b9a..66440f40d144c 100644
--- a/include/uapi/linux/nl80211.h
+++ b/include/uapi/linux/nl80211.h
@@ -3000,6 +3000,10 @@ enum nl80211_commands {
* interference detection is not performed on these sub-channels, their
* corresponding bits are consistently set to zero.
*
+ * @NL80211_ATTR_UHR_OPERATION: Full UHR Operation element, as it appears in
+ * association response etc., since it's abridged in the beacon. Used
+ * for START_AP etc.
+ *
* @NUM_NL80211_ATTR: total number of nl80211_attrs available
* @NL80211_ATTR_MAX: highest attribute number currently defined
* @__NL80211_ATTR_AFTER_LAST: internal use
@@ -3575,6 +3579,8 @@ enum nl80211_attrs {
NL80211_ATTR_INCUMBENT_SIGNAL_INTERFERENCE_BITMAP,
+ NL80211_ATTR_UHR_OPERATION,
+
/* add attributes here, update the policy in nl80211.c */
__NL80211_ATTR_AFTER_LAST,
diff --git a/net/wireless/nl80211.c b/net/wireless/nl80211.c
index 53b784cc8a3fd..cbf1fcc81ae2f 100644
--- a/net/wireless/nl80211.c
+++ b/net/wireless/nl80211.c
@@ -341,6 +341,17 @@ static int validate_uhr_capa(const struct nlattr *attr,
return ieee80211_uhr_capa_size_ok(data, len, false);
}
+static int validate_uhr_operation(const struct nlattr *attr,
+ struct netlink_ext_ack *extack)
+{
+ const u8 *data = nla_data(attr);
+ unsigned int len = nla_len(attr);
+
+ if (!ieee80211_uhr_oper_size_ok(data, len, false))
+ return -EINVAL;
+ return 0;
+}
+
/* policy for the attributes */
static const struct nla_policy nl80211_policy[NUM_NL80211_ATTR];
@@ -947,6 +958,8 @@ static const struct nla_policy nl80211_policy[NUM_NL80211_ATTR] = {
[NL80211_ATTR_UHR_CAPABILITY] =
NLA_POLICY_VALIDATE_FN(NLA_BINARY, validate_uhr_capa, 255),
[NL80211_ATTR_DISABLE_UHR] = { .type = NLA_FLAG },
+ [NL80211_ATTR_UHR_OPERATION] =
+ NLA_POLICY_VALIDATE_FN(NLA_BINARY, validate_uhr_operation),
};
/* policy for the key attributes */
@@ -6470,16 +6483,6 @@ static int nl80211_calculate_ap_params(struct cfg80211_ap_settings *params)
return -EINVAL;
}
- cap = cfg80211_find_ext_elem(WLAN_EID_EXT_UHR_OPER, ies, ies_len);
- if (cap) {
- if (!cap->datalen)
- return -EINVAL;
- params->uhr_oper = (void *)(cap->data + 1);
- if (!ieee80211_uhr_oper_size_ok((const u8 *)params->uhr_oper,
- cap->datalen - 1, true))
- return -EINVAL;
- }
-
return 0;
}
@@ -6905,6 +6908,9 @@ static int nl80211_start_ap(struct sk_buff *skb, struct genl_info *info)
if (err)
goto out;
+ if (info->attrs[NL80211_ATTR_UHR_OPERATION])
+ params->uhr_oper = nla_data(info->attrs[NL80211_ATTR_UHR_OPERATION]);
+
err = nl80211_validate_ap_phy_operation(params);
if (err)
goto out;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0824/1518] wifi: cfg80211: Add an API to configure local NAN schedule
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (822 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0823/1518] wifi: nl80211: split out UHR operation information Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0825/1518] wifi: cfg80211: stop PMSR before P2P and NAN teardown Greg Kroah-Hartman
` (174 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Miri Korenblit, Johannes Berg,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Miri Korenblit <miriam.rachel.korenblit@intel.com>
[ Upstream commit 6e78b70c9a3d2a627229801f93e3f62869922587 ]
Add an nl80211 API to allow user space to configure the local NAN
schedule.
The local schedule consists of a list of channel definitions and a schedule
map, in which each element covers a time slot and indicates on what
channel the device should be in that time slot.
Channels can be added to schedule even without being scheduled, for
reservation purposes.
A schedule can be configured either immedietally or be deferred, in case
there are already connected peers.
When the deferred flag is set, the command is a request from the device
to perform an announced schedule update: send the updated NAN
Availability - as set in this command - to the peers, and do the
actual switch to the new schedule on the right time (i.e. at the end of
the slot after the slot in which the update was sent to the peers).
In addition, a notification will be sent to indicate a deferred update
completion.
Signed-off-by: Miri Korenblit <miriam.rachel.korenblit@intel.com>
Link: https://patch.msgid.link/20260219114327.ecca178a2de0.Ic977ab08b4ed5cf9b849e55d3a59b01ad3fbd08e@changeid
Link: https://patch.msgid.link/20260318123926.206536-2-miriam.rachel.korenblit@intel.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Stable-dep-of: 6c5fc504d0d6 ("wifi: cfg80211: stop PMSR before P2P and NAN teardown")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/net/cfg80211.h | 73 +++++++++-
include/uapi/linux/nl80211.h | 76 ++++++++++
net/wireless/core.c | 54 ++++++-
net/wireless/core.h | 4 +
net/wireless/nl80211.c | 266 +++++++++++++++++++++++++++++++++++
net/wireless/rdev-ops.h | 16 +++
net/wireless/trace.h | 38 +++++
7 files changed, 525 insertions(+), 2 deletions(-)
diff --git a/include/net/cfg80211.h b/include/net/cfg80211.h
index c44c35dedc589..634743ba5fa66 100644
--- a/include/net/cfg80211.h
+++ b/include/net/cfg80211.h
@@ -4050,6 +4050,54 @@ struct cfg80211_nan_conf {
u16 vendor_elems_len;
};
+#define CFG80211_NAN_SCHED_NUM_TIME_SLOTS 32
+
+/**
+ * struct cfg80211_nan_channel - NAN channel configuration
+ *
+ * This struct defines a NAN channel configuration
+ *
+ * @chandef: the channel definition
+ * @channel_entry: pointer to the Channel Entry blob as defined in Wi-Fi Aware
+ * (TM) 4.0 specification Table 100 (Channel Entry format for the NAN
+ * Availability attribute).
+ * @rx_nss: number of spatial streams supported on this channel
+ */
+struct cfg80211_nan_channel {
+ struct cfg80211_chan_def chandef;
+ const u8 *channel_entry;
+ u8 rx_nss;
+};
+
+/**
+ * struct cfg80211_nan_local_sched - NAN local schedule
+ *
+ * This struct defines NAN local schedule parameters
+ *
+ * @schedule: a mapping of time slots to chandef indexes in %nan_channels.
+ * An unscheduled slot will be set to %NL80211_NAN_SCHED_NOT_AVAIL_SLOT.
+ * @n_channels: number of channel definitions in %nan_channels.
+ * @nan_avail_blob: pointer to NAN Availability attribute blob.
+ * See %NL80211_ATTR_NAN_AVAIL_BLOB for more details.
+ * @nan_avail_blob_len: length of the @nan_avail_blob in bytes.
+ * @deferred: if true, the command containing this schedule configuration is a
+ * request from the device to perform an announced schedule update. This
+ * means that it needs to send the updated NAN availability to the peers,
+ * and do the actual switch on the right time (i.e. at the end of the slot
+ * after the slot in which the updated NAN Availability was sent).
+ * See %NL80211_ATTR_NAN_SCHED_DEFERRED for more details.
+ * If false, the schedule is applied immediately.
+ * @nan_channels: array of NAN channel definitions that can be scheduled.
+ */
+struct cfg80211_nan_local_sched {
+ u8 schedule[CFG80211_NAN_SCHED_NUM_TIME_SLOTS];
+ u8 n_channels;
+ const u8 *nan_avail_blob;
+ u16 nan_avail_blob_len;
+ bool deferred;
+ struct cfg80211_nan_channel nan_channels[] __counted_by(n_channels);
+};
+
/**
* enum cfg80211_nan_conf_changes - indicates changed fields in NAN
* configuration
@@ -4823,6 +4871,12 @@ struct mgmt_frame_regs {
* @nan_change_conf: changes NAN configuration. The changed parameters must
* be specified in @changes (using &enum cfg80211_nan_conf_changes);
* All other parameters must be ignored.
+ * @nan_set_local_sched: configure the local schedule for NAN. The schedule
+ * consists of an array of %cfg80211_nan_channel and the schedule itself,
+ * in which each entry maps each time slot to the channel on which the
+ * radio should operate on. If the chandef of a NAN channel is not
+ * changed, the channel entry must also remain unchanged. It is the
+ * driver's responsibility to verify this.
*
* @set_multicast_to_unicast: configure multicast to unicast conversion for BSS
*
@@ -5200,7 +5254,9 @@ struct cfg80211_ops {
struct wireless_dev *wdev,
struct cfg80211_nan_conf *conf,
u32 changes);
-
+ int (*nan_set_local_sched)(struct wiphy *wiphy,
+ struct wireless_dev *wdev,
+ struct cfg80211_nan_local_sched *sched);
int (*set_multicast_to_unicast)(struct wiphy *wiphy,
struct net_device *dev,
const bool enabled);
@@ -6828,6 +6884,9 @@ struct wireless_dev {
} ocb;
struct {
u8 cluster_id[ETH_ALEN] __aligned(2);
+ u8 n_channels;
+ struct cfg80211_chan_def *chandefs;
+ bool sched_update_pending;
} nan;
} u;
@@ -9954,6 +10013,18 @@ void cfg80211_nan_func_terminated(struct wireless_dev *wdev,
enum nl80211_nan_func_term_reason reason,
u64 cookie, gfp_t gfp);
+/**
+ * cfg80211_nan_sched_update_done - notify deferred schedule update completion
+ * @wdev: the wireless device reporting the event
+ * @success: whether or not the schedule update was successful
+ * @gfp: allocation flags
+ *
+ * This function notifies user space that a deferred local NAN schedule update
+ * (requested with %NL80211_ATTR_NAN_SCHED_DEFERRED) has been completed.
+ */
+void cfg80211_nan_sched_update_done(struct wireless_dev *wdev, bool success,
+ gfp_t gfp);
+
/* ethtool helper */
void cfg80211_get_drvinfo(struct net_device *dev, struct ethtool_drvinfo *info);
diff --git a/include/uapi/linux/nl80211.h b/include/uapi/linux/nl80211.h
index 66440f40d144c..857d1f66bf353 100644
--- a/include/uapi/linux/nl80211.h
+++ b/include/uapi/linux/nl80211.h
@@ -1367,6 +1367,20 @@
* %NL80211_ATTR_INCUMBENT_SIGNAL_INTERFERENCE_BITMAP. The current channel
* definition is also sent.
*
+ * @NL80211_CMD_NAN_SET_LOCAL_SCHED: Set the local NAN schedule. NAN must be
+ * operational (%NL80211_CMD_START_NAN was executed). Must contain
+ * %NL80211_ATTR_NAN_TIME_SLOTS and %NL80211_ATTR_NAN_AVAIL_BLOB, but
+ * %NL80211_ATTR_NAN_CHANNEL is optional (for example in case of a channel
+ * removal, that channel won't be provided).
+ * If %NL80211_ATTR_NAN_SCHED_DEFERRED is set, the command is a request
+ * from the device to perform an announced schedule update. See
+ * %NL80211_ATTR_NAN_SCHED_DEFERRED for more details.
+ * If not set, the schedule should be applied immediately.
+ * @NL80211_CMD_NAN_SCHED_UPDATE_DONE: Event sent to user space to notify that
+ * a deferred local NAN schedule update (requested with
+ * %NL80211_CMD_NAN_SET_LOCAL_SCHED and %NL80211_ATTR_NAN_SCHED_DEFERRED)
+ * has been completed. The presence of %NL80211_ATTR_NAN_SCHED_UPDATE_SUCCESS
+ * indicates that the update was successful.
* @NL80211_CMD_MAX: highest used command number
* @__NL80211_CMD_AFTER_LAST: internal use
*/
@@ -1632,6 +1646,10 @@ enum nl80211_commands {
NL80211_CMD_INCUMBENT_SIGNAL_DETECT,
+ NL80211_CMD_NAN_SET_LOCAL_SCHED,
+
+ NL80211_CMD_NAN_SCHED_UPDATE_DONE,
+
/* add new commands above here */
/* used to define NL80211_CMD_MAX below */
@@ -2990,6 +3008,54 @@ enum nl80211_commands {
* @NL80211_ATTR_DISABLE_UHR: Force UHR capable interfaces to disable
* this feature during association. This is a flag attribute.
* Currently only supported in mac80211 drivers.
+ * @NL80211_ATTR_NAN_CHANNEL: This is a nested attribute. There can be multiple
+ * attributes of this type, each one represents a channel definition and
+ * consists of top-level attributes like %NL80211_ATTR_WIPHY_FREQ. Must
+ * contain %NL80211_ATTR_NAN_CHANNEL_ENTRY and
+ * %NL80211_ATTR_NAN_RX_NSS.
+ * This attribute is used with %NL80211_CMD_NAN_SET_LOCAL_SCHED to specify
+ * the channel definitions on which the radio needs to operate during
+ * specific time slots. All of the channel definitions should be mutually
+ * incompatible. The number of channels should fit the current
+ * configuration of channels and the possible interface combinations.
+ * If an existing NAN channel is changed but the chandef isn't, the
+ * channel entry must also remain unchanged.
+ * @NL80211_ATTR_NAN_CHANNEL_ENTRY: a byte array of 6 bytes. contains the
+ * Channel Entry as defined in Wi-Fi Aware (TM) 4.0 specification Table
+ * 100 (Channel Entry format for the NAN Availability attribute).
+ * @NL80211_ATTR_NAN_RX_NSS: (u8) RX NSS used for a NAN channel. This is
+ * used with %NL80211_ATTR_NAN_CHANNEL when configuring NAN channels with
+ * %NL80211_CMD_NAN_SET_LOCAL_SCHED.
+ * @NL80211_ATTR_NAN_TIME_SLOTS: an array of u8 values and 32 cells. each value
+ * maps a time slot to the chandef on which the radio should operate on in
+ * that time. %NL80211_NAN_SCHED_NOT_AVAIL_SLOT indicates unscheduled.
+ * The chandef is represented using its index, where the index is the
+ * sequential number of the %NL80211_ATTR_NAN_CHANNEL attribute within all
+ * the attributes of this type.
+ * Each slots spans over 16TUs, hence the entire schedule spans over
+ * 512TUs. Other slot durations and periods are currently not supported.
+ * @NL80211_ATTR_NAN_AVAIL_BLOB: (Binary) The NAN Availability attribute blob,
+ * including the attribute header, as defined in Wi-Fi Aware (TM) 4.0
+ * specification Table 93 (NAN Availability attribute format). Required with
+ * %NL80211_CMD_NAN_SET_LOCAL_SCHED to provide the raw NAN Availability
+ * attribute. Used by the device to publish Schedule Update NAFs.
+ * @NL80211_ATTR_NAN_SCHED_DEFERRED: Flag attribute used with
+ * %NL80211_CMD_NAN_SET_LOCAL_SCHED. When present, the command is a
+ * request from the device to perform an announced schedule update. This
+ * means that it needs to send the updated NAN availability to the peers,
+ * and do the actual switch on the right time (i.e. at the end of the slot
+ * after the slot in which the updated NAN Availability was sent). Since
+ * the slots management is done in the device, the update to the peers
+ * needs to be sent by the device, so it knows the actual switch time.
+ * If the flag is not set, the schedule should be applied immediately.
+ * When this flag is set, the total number of NAN channels from both the
+ * old and new schedules must not exceed the allowed number of local NAN
+ * channels, because with deferred scheduling the old channels cannot be
+ * removed before adding the new ones to free up space.
+ * @NL80211_ATTR_NAN_SCHED_UPDATE_SUCCESS: flag attribute used with
+ * %NL80211_CMD_NAN_SCHED_UPDATE_DONE to indicate that the deferred
+ * schedule update completed successfully. If this flag is not present,
+ * the update failed.
*
* @NL80211_ATTR_INCUMBENT_SIGNAL_INTERFERENCE_BITMAP: u32 attribute specifying
* the signal interference bitmap detected on the operating bandwidth for
@@ -3581,6 +3647,14 @@ enum nl80211_attrs {
NL80211_ATTR_UHR_OPERATION,
+ NL80211_ATTR_NAN_CHANNEL,
+ NL80211_ATTR_NAN_CHANNEL_ENTRY,
+ NL80211_ATTR_NAN_TIME_SLOTS,
+ NL80211_ATTR_NAN_RX_NSS,
+ NL80211_ATTR_NAN_AVAIL_BLOB,
+ NL80211_ATTR_NAN_SCHED_DEFERRED,
+ NL80211_ATTR_NAN_SCHED_UPDATE_SUCCESS,
+
/* add attributes here, update the policy in nl80211.c */
__NL80211_ATTR_AFTER_LAST,
@@ -8496,4 +8570,6 @@ enum nl80211_nan_capabilities {
NL80211_NAN_CAPABILITIES_MAX = __NL80211_NAN_CAPABILITIES_LAST - 1,
};
+#define NL80211_NAN_SCHED_NOT_AVAIL_SLOT 0xff
+
#endif /* __LINUX_NL80211_H */
diff --git a/net/wireless/core.c b/net/wireless/core.c
index efbf7b3046342..4d4c42db732e9 100644
--- a/net/wireless/core.c
+++ b/net/wireless/core.c
@@ -5,7 +5,7 @@
* Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
* Copyright 2013-2014 Intel Mobile Communications GmbH
* Copyright 2015-2017 Intel Deutschland GmbH
- * Copyright (C) 2018-2025 Intel Corporation
+ * Copyright (C) 2018-2026 Intel Corporation
*/
#define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
@@ -251,6 +251,8 @@ void cfg80211_stop_p2p_device(struct cfg80211_registered_device *rdev,
void cfg80211_stop_nan(struct cfg80211_registered_device *rdev,
struct wireless_dev *wdev)
{
+ struct cfg80211_nan_local_sched empty_sched = {};
+
lockdep_assert_held(&rdev->wiphy.mtx);
if (WARN_ON(wdev->iftype != NL80211_IFTYPE_NAN))
@@ -259,12 +261,62 @@ void cfg80211_stop_nan(struct cfg80211_registered_device *rdev,
if (!wdev_running(wdev))
return;
+ /*
+ * If there is a scheduled update pending, mark it as canceled, so the
+ * empty schedule will be accepted
+ */
+ wdev->u.nan.sched_update_pending = false;
+
+ /* Unschedule all */
+ cfg80211_nan_set_local_schedule(rdev, wdev, &empty_sched);
+
rdev_stop_nan(rdev, wdev);
wdev->is_running = false;
rdev->opencount--;
}
+int cfg80211_nan_set_local_schedule(struct cfg80211_registered_device *rdev,
+ struct wireless_dev *wdev,
+ struct cfg80211_nan_local_sched *sched)
+{
+ int ret;
+
+ lockdep_assert_held(&rdev->wiphy.mtx);
+
+ if (wdev->iftype != NL80211_IFTYPE_NAN || !wdev_running(wdev))
+ return -EINVAL;
+
+ if (wdev->u.nan.sched_update_pending)
+ return -EBUSY;
+
+ ret = rdev_nan_set_local_sched(rdev, wdev, sched);
+ if (ret)
+ return ret;
+
+ wdev->u.nan.sched_update_pending = sched->deferred;
+
+ kfree(wdev->u.nan.chandefs);
+ wdev->u.nan.chandefs = NULL;
+ wdev->u.nan.n_channels = 0;
+
+ if (!sched->n_channels)
+ return 0;
+
+ wdev->u.nan.chandefs = kcalloc(sched->n_channels,
+ sizeof(*wdev->u.nan.chandefs),
+ GFP_KERNEL);
+ if (!wdev->u.nan.chandefs)
+ return -ENOMEM;
+
+ for (int i = 0; i < sched->n_channels; i++)
+ wdev->u.nan.chandefs[i] = sched->nan_channels[i].chandef;
+
+ wdev->u.nan.n_channels = sched->n_channels;
+
+ return 0;
+}
+
void cfg80211_shutdown_all_interfaces(struct wiphy *wiphy)
{
struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
diff --git a/net/wireless/core.h b/net/wireless/core.h
index 9bfd39af1742e..1086aa1a44f42 100644
--- a/net/wireless/core.h
+++ b/net/wireless/core.h
@@ -545,6 +545,10 @@ void cfg80211_stop_p2p_device(struct cfg80211_registered_device *rdev,
void cfg80211_stop_nan(struct cfg80211_registered_device *rdev,
struct wireless_dev *wdev);
+int cfg80211_nan_set_local_schedule(struct cfg80211_registered_device *rdev,
+ struct wireless_dev *wdev,
+ struct cfg80211_nan_local_sched *sched);
+
struct cfg80211_internal_bss *
cfg80211_bss_update(struct cfg80211_registered_device *rdev,
struct cfg80211_internal_bss *tmp,
diff --git a/net/wireless/nl80211.c b/net/wireless/nl80211.c
index cbf1fcc81ae2f..9c713094f0a5c 100644
--- a/net/wireless/nl80211.c
+++ b/net/wireless/nl80211.c
@@ -332,6 +332,40 @@ static int validate_nan_cluster_id(const struct nlattr *attr,
return 0;
}
+static int validate_nan_avail_blob(const struct nlattr *attr,
+ struct netlink_ext_ack *extack)
+{
+ const u8 *data = nla_data(attr);
+ unsigned int len = nla_len(attr);
+ u16 attr_len;
+
+ /* Need at least: Attr ID (1) + Length (2) */
+ if (len < 3) {
+ NL_SET_ERR_MSG_FMT(extack,
+ "NAN Availability: Too short (need at least 3 bytes, have %u)",
+ len);
+ return -EINVAL;
+ }
+
+ if (data[0] != 0x12) {
+ NL_SET_ERR_MSG_FMT(extack,
+ "NAN Availability: Invalid Attribute ID 0x%02x (expected 0x12)",
+ data[0]);
+ return -EINVAL;
+ }
+
+ attr_len = get_unaligned_le16(&data[1]);
+
+ if (attr_len != len - 3) {
+ NL_SET_ERR_MSG_FMT(extack,
+ "NAN Availability: Length field (%u) doesn't match data length (%u)",
+ attr_len, len - 3);
+ return -EINVAL;
+ }
+
+ return 0;
+}
+
static int validate_uhr_capa(const struct nlattr *attr,
struct netlink_ext_ack *extack)
{
@@ -960,6 +994,14 @@ static const struct nla_policy nl80211_policy[NUM_NL80211_ATTR] = {
[NL80211_ATTR_DISABLE_UHR] = { .type = NLA_FLAG },
[NL80211_ATTR_UHR_OPERATION] =
NLA_POLICY_VALIDATE_FN(NLA_BINARY, validate_uhr_operation),
+ [NL80211_ATTR_NAN_CHANNEL] = NLA_POLICY_NESTED(nl80211_policy),
+ [NL80211_ATTR_NAN_CHANNEL_ENTRY] = NLA_POLICY_EXACT_LEN(6),
+ [NL80211_ATTR_NAN_RX_NSS] = { .type = NLA_U8 },
+ [NL80211_ATTR_NAN_TIME_SLOTS] =
+ NLA_POLICY_EXACT_LEN(CFG80211_NAN_SCHED_NUM_TIME_SLOTS),
+ [NL80211_ATTR_NAN_AVAIL_BLOB] =
+ NLA_POLICY_VALIDATE_FN(NLA_BINARY, validate_nan_avail_blob),
+ [NL80211_ATTR_NAN_SCHED_DEFERRED] = { .type = NLA_FLAG },
};
/* policy for the key attributes */
@@ -16353,6 +16395,224 @@ void cfg80211_nan_func_terminated(struct wireless_dev *wdev,
}
EXPORT_SYMBOL(cfg80211_nan_func_terminated);
+void cfg80211_nan_sched_update_done(struct wireless_dev *wdev, bool success,
+ gfp_t gfp)
+{
+ struct wiphy *wiphy = wdev->wiphy;
+ struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
+ struct sk_buff *msg;
+ void *hdr;
+
+ trace_cfg80211_nan_sched_update_done(wiphy, wdev, success);
+
+ /* Can happen if we stopped NAN */
+ if (!wdev->u.nan.sched_update_pending)
+ return;
+
+ wdev->u.nan.sched_update_pending = false;
+
+ if (!wdev->owner_nlportid)
+ return;
+
+ msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
+ if (!msg)
+ return;
+
+ hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NAN_SCHED_UPDATE_DONE);
+ if (!hdr)
+ goto nla_put_failure;
+
+ if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
+ nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
+ NL80211_ATTR_PAD) ||
+ (success &&
+ nla_put_flag(msg, NL80211_ATTR_NAN_SCHED_UPDATE_SUCCESS)))
+ goto nla_put_failure;
+
+ genlmsg_end(msg, hdr);
+
+ genlmsg_unicast(wiphy_net(wiphy), msg, wdev->owner_nlportid);
+
+ return;
+
+nla_put_failure:
+ nlmsg_free(msg);
+}
+EXPORT_SYMBOL(cfg80211_nan_sched_update_done);
+
+static int nl80211_parse_nan_channel(struct cfg80211_registered_device *rdev,
+ struct nlattr *channel,
+ struct genl_info *info,
+ struct cfg80211_nan_local_sched *sched,
+ u8 index)
+{
+ struct nlattr **channel_parsed __free(kfree) = NULL;
+ struct cfg80211_chan_def chandef;
+ u8 n_rx_nss;
+ int ret;
+
+ channel_parsed = kcalloc(NL80211_ATTR_MAX + 1, sizeof(*channel_parsed),
+ GFP_KERNEL);
+ if (!channel_parsed)
+ return -ENOMEM;
+
+ ret = nla_parse_nested(channel_parsed, NL80211_ATTR_MAX, channel, NULL,
+ info->extack);
+ if (ret)
+ return ret;
+
+ ret = nl80211_parse_chandef(rdev, info->extack, channel_parsed,
+ &chandef);
+ if (ret)
+ return ret;
+
+ if (chandef.chan->band == NL80211_BAND_6GHZ) {
+ NL_SET_ERR_MSG(info->extack,
+ "6 GHz band is not supported");
+ return -EOPNOTSUPP;
+ }
+
+ if (!cfg80211_reg_can_beacon(&rdev->wiphy, &chandef,
+ NL80211_IFTYPE_NAN)) {
+ NL_SET_ERR_MSG_ATTR(info->extack, channel,
+ "Channel in NAN schedule is not allowed for NAN operation");
+ return -EINVAL;
+ }
+
+ for (int i = 0; i < index; i++) {
+ if (cfg80211_chandef_compatible(&sched->nan_channels[i].chandef,
+ &chandef)) {
+ NL_SET_ERR_MSG_ATTR(info->extack, channel,
+ "Channels in NAN schedule must be mutually incompatible");
+ return -EINVAL;
+ }
+ }
+
+ if (!channel_parsed[NL80211_ATTR_NAN_CHANNEL_ENTRY])
+ return -EINVAL;
+
+ sched->nan_channels[index].channel_entry =
+ nla_data(channel_parsed[NL80211_ATTR_NAN_CHANNEL_ENTRY]);
+
+ if (!channel_parsed[NL80211_ATTR_NAN_RX_NSS])
+ return -EINVAL;
+
+ sched->nan_channels[index].rx_nss =
+ nla_get_u8(channel_parsed[NL80211_ATTR_NAN_RX_NSS]);
+
+ n_rx_nss = u8_get_bits(rdev->wiphy.nan_capa.n_antennas, 0x03);
+ if (sched->nan_channels[index].rx_nss > n_rx_nss ||
+ !sched->nan_channels[index].rx_nss) {
+ NL_SET_ERR_MSG_ATTR(info->extack, channel,
+ "Invalid RX NSS in NAN channel definition");
+ return -EINVAL;
+ }
+
+ sched->nan_channels[index].chandef = chandef;
+
+ return 0;
+}
+
+static bool nl80211_nan_is_sched_empty(struct cfg80211_nan_local_sched *sched)
+{
+ if (!sched->n_channels)
+ return true;
+
+ for (int i = 0; i < ARRAY_SIZE(sched->schedule); i++) {
+ if (sched->schedule[i] != NL80211_NAN_SCHED_NOT_AVAIL_SLOT)
+ return false;
+ }
+
+ return true;
+}
+
+static int nl80211_nan_set_local_sched(struct sk_buff *skb,
+ struct genl_info *info)
+{
+ struct cfg80211_registered_device *rdev = info->user_ptr[0];
+ struct cfg80211_nan_local_sched *sched __free(kfree) = NULL;
+ struct wireless_dev *wdev = info->user_ptr[1];
+ int rem, i = 0, n_channels = 0;
+ struct nlattr *channel;
+ bool sched_empty;
+
+ if (wdev->iftype != NL80211_IFTYPE_NAN)
+ return -EOPNOTSUPP;
+
+ if (!wdev_running(wdev))
+ return -ENOTCONN;
+
+ if (!info->attrs[NL80211_ATTR_NAN_TIME_SLOTS])
+ return -EINVAL;
+
+ /* First count how many channel attributes we got */
+ nlmsg_for_each_attr_type(channel, NL80211_ATTR_NAN_CHANNEL,
+ info->nlhdr, GENL_HDRLEN, rem)
+ n_channels++;
+
+ sched = kzalloc(struct_size(sched, nan_channels, n_channels),
+ GFP_KERNEL);
+ if (!sched)
+ return -ENOMEM;
+
+ sched->n_channels = n_channels;
+
+ nlmsg_for_each_attr_type(channel, NL80211_ATTR_NAN_CHANNEL,
+ info->nlhdr, GENL_HDRLEN, rem) {
+ int ret = nl80211_parse_nan_channel(rdev, channel, info, sched,
+ i);
+
+ if (ret)
+ return ret;
+ i++;
+ }
+
+ memcpy(sched->schedule,
+ nla_data(info->attrs[NL80211_ATTR_NAN_TIME_SLOTS]),
+ nla_len(info->attrs[NL80211_ATTR_NAN_TIME_SLOTS]));
+
+ for (int slot = 0; slot < ARRAY_SIZE(sched->schedule); slot++) {
+ if (sched->schedule[slot] != NL80211_NAN_SCHED_NOT_AVAIL_SLOT &&
+ sched->schedule[slot] >= sched->n_channels) {
+ NL_SET_ERR_MSG(info->extack,
+ "Invalid time slot in NAN schedule");
+ return -EINVAL;
+ }
+ }
+
+ sched_empty = nl80211_nan_is_sched_empty(sched);
+
+ sched->deferred =
+ nla_get_flag(info->attrs[NL80211_ATTR_NAN_SCHED_DEFERRED]);
+
+ if (sched_empty) {
+ if (sched->deferred) {
+ NL_SET_ERR_MSG(info->extack,
+ "Schedule cannot be deferred if all time slots are unavailable");
+ return -EINVAL;
+ }
+
+ if (info->attrs[NL80211_ATTR_NAN_AVAIL_BLOB]) {
+ NL_SET_ERR_MSG(info->extack,
+ "NAN Availability blob must be empty if all time slots are unavailable");
+ return -EINVAL;
+ }
+ } else {
+ if (!info->attrs[NL80211_ATTR_NAN_AVAIL_BLOB]) {
+ NL_SET_ERR_MSG(info->extack,
+ "NAN Availability blob attribute is required");
+ return -EINVAL;
+ }
+
+ sched->nan_avail_blob =
+ nla_data(info->attrs[NL80211_ATTR_NAN_AVAIL_BLOB]);
+ sched->nan_avail_blob_len =
+ nla_len(info->attrs[NL80211_ATTR_NAN_AVAIL_BLOB]);
+ }
+
+ return cfg80211_nan_set_local_schedule(rdev, wdev, sched);
+}
+
static int nl80211_get_protocol_features(struct sk_buff *skb,
struct genl_info *info)
{
@@ -19157,6 +19417,12 @@ static const struct genl_small_ops nl80211_small_ops[] = {
.flags = GENL_UNS_ADMIN_PERM,
.internal_flags = IFLAGS(NL80211_FLAG_NEED_NETDEV_UP),
},
+ {
+ .cmd = NL80211_CMD_NAN_SET_LOCAL_SCHED,
+ .doit = nl80211_nan_set_local_sched,
+ .flags = GENL_ADMIN_PERM,
+ .internal_flags = IFLAGS(NL80211_FLAG_NEED_WDEV_UP),
+ },
};
static struct genl_family nl80211_fam __ro_after_init = {
diff --git a/net/wireless/rdev-ops.h b/net/wireless/rdev-ops.h
index ac6884bacf3fa..f4c06282b2e15 100644
--- a/net/wireless/rdev-ops.h
+++ b/net/wireless/rdev-ops.h
@@ -1060,6 +1060,22 @@ rdev_nan_change_conf(struct cfg80211_registered_device *rdev,
return ret;
}
+static inline int
+rdev_nan_set_local_sched(struct cfg80211_registered_device *rdev,
+ struct wireless_dev *wdev,
+ struct cfg80211_nan_local_sched *sched)
+{
+ int ret;
+
+ trace_rdev_nan_set_local_sched(&rdev->wiphy, wdev, sched);
+ if (rdev->ops->nan_set_local_sched)
+ ret = rdev->ops->nan_set_local_sched(&rdev->wiphy, wdev, sched);
+ else
+ ret = -EOPNOTSUPP;
+ trace_rdev_return_int(&rdev->wiphy, ret);
+ return ret;
+}
+
static inline int rdev_set_mac_acl(struct cfg80211_registered_device *rdev,
struct net_device *dev,
struct cfg80211_acl_data *params)
diff --git a/net/wireless/trace.h b/net/wireless/trace.h
index 27779d11b3733..30d3619f702cd 100644
--- a/net/wireless/trace.h
+++ b/net/wireless/trace.h
@@ -2393,6 +2393,27 @@ TRACE_EVENT(rdev_del_nan_func,
WIPHY_PR_ARG, WDEV_PR_ARG, __entry->cookie)
);
+TRACE_EVENT(rdev_nan_set_local_sched,
+ TP_PROTO(struct wiphy *wiphy, struct wireless_dev *wdev,
+ struct cfg80211_nan_local_sched *sched),
+ TP_ARGS(wiphy, wdev, sched),
+ TP_STRUCT__entry(
+ WIPHY_ENTRY
+ WDEV_ENTRY
+ __array(u8, schedule, CFG80211_NAN_SCHED_NUM_TIME_SLOTS)
+ ),
+ TP_fast_assign(
+ WIPHY_ASSIGN;
+ WDEV_ASSIGN;
+ memcpy(__entry->schedule, sched->schedule,
+ CFG80211_NAN_SCHED_NUM_TIME_SLOTS);
+ ),
+ TP_printk(WIPHY_PR_FMT ", " WDEV_PR_FMT ", schedule: %s",
+ WIPHY_PR_ARG, WDEV_PR_ARG,
+ __print_array(__entry->schedule,
+ CFG80211_NAN_SCHED_NUM_TIME_SLOTS, 1))
+);
+
TRACE_EVENT(rdev_set_mac_acl,
TP_PROTO(struct wiphy *wiphy, struct net_device *netdev,
struct cfg80211_acl_data *params),
@@ -4241,6 +4262,23 @@ TRACE_EVENT(cfg80211_incumbent_signal_notify,
TP_printk(WIPHY_PR_FMT ", " CHAN_DEF_PR_FMT ", signal_interference_bitmap=0x%x",
WIPHY_PR_ARG, CHAN_DEF_PR_ARG, __entry->signal_interference_bitmap)
);
+
+TRACE_EVENT(cfg80211_nan_sched_update_done,
+ TP_PROTO(struct wiphy *wiphy, struct wireless_dev *wdev, bool success),
+ TP_ARGS(wiphy, wdev, success),
+ TP_STRUCT__entry(
+ WIPHY_ENTRY
+ WDEV_ENTRY
+ __field(bool, success)
+ ),
+ TP_fast_assign(
+ WIPHY_ASSIGN;
+ WDEV_ASSIGN;
+ __entry->success = success;
+ ),
+ TP_printk(WIPHY_PR_FMT ", " WDEV_PR_FMT " success=%d",
+ WIPHY_PR_ARG, WDEV_PR_ARG, __entry->success)
+);
#endif /* !__RDEV_OPS_TRACE || TRACE_HEADER_MULTI_READ */
#undef TRACE_INCLUDE_PATH
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0825/1518] wifi: cfg80211: stop PMSR before P2P and NAN teardown
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (823 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0824/1518] wifi: cfg80211: Add an API to configure local NAN schedule Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0826/1518] firmware: google: Add bounds checks in coreboot_table_populate() Greg Kroah-Hartman
` (173 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Zhao Li, Johannes Berg, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zhao Li <enderaoelyther@gmail.com>
[ Upstream commit 6c5fc504d0d6934132637aa3db4b9b58148eaa78 ]
PMSR request teardown must abort active measurements while the
wireless_dev is still present in the driver. cfg80211_leave_locked() and
cfg80211_stop_pd() already do this before invoking the driver's stop
callback, but cfg80211_stop_p2p_device() and cfg80211_stop_nan() do not.
Those helpers are also called directly by nl80211, rfkill shutdown, and
wireless_dev unregister paths. If one of these paths stops a P2P device
or NAN interface with a pending request, it removes the mac80211
subinterface from the driver first. Subsequent request cleanup cannot
reach the lower driver's abort callback, but cfg80211 frees the request
regardless. Driver state can then retain a stale request and use it when
it later reports a result.
Call cfg80211_pmsr_wdev_down() before stopping the P2P device or NAN
interface. This keeps lower-driver request state and cfg80211 request
ownership in sync for all of the helpers' callers.
Fixes: 9bb7e0f24e7e ("cfg80211: add peer measurement with FTM initiator API")
Assisted-by: Codex:gpt-5.6-sol
Signed-off-by: Zhao Li <enderaoelyther@gmail.com>
Link: https://patch.msgid.link/20260731071103.73563-1-enderaoelyther@gmail.com
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/wireless/core.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/net/wireless/core.c b/net/wireless/core.c
index 4d4c42db732e9..6a9ba151b09fe 100644
--- a/net/wireless/core.c
+++ b/net/wireless/core.c
@@ -234,6 +234,7 @@ void cfg80211_stop_p2p_device(struct cfg80211_registered_device *rdev,
if (!wdev_running(wdev))
return;
+ cfg80211_pmsr_wdev_down(wdev);
rdev_stop_p2p_device(rdev, wdev);
wdev->is_running = false;
@@ -261,6 +262,8 @@ void cfg80211_stop_nan(struct cfg80211_registered_device *rdev,
if (!wdev_running(wdev))
return;
+ cfg80211_pmsr_wdev_down(wdev);
+
/*
* If there is a scheduled update pending, mark it as canceled, so the
* empty schedule will be accepted
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0826/1518] firmware: google: Add bounds checks in coreboot_table_populate()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (824 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0825/1518] wifi: cfg80211: stop PMSR before P2P and NAN teardown Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0827/1518] firmware: coreboot: Validate table bounds Greg Kroah-Hartman
` (172 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Titouan Ameline de Cadeville,
Julius Werner, Tzung-Bi Shih, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Titouan Ameline de Cadeville <titouan.ameline@gmail.com>
[ Upstream commit 7b1a1af4556a4f95ef273e91435fe804cbfcd223 ]
coreboot_table_populate() iterates over firmware-provided table entries
with no validation that the entries stay within the mapped memory
region. A corrupt table with a large `entry->size` advances `ptr_entry`
past the mapped region, causing an out-of-bounds read on the next
iteration.
Add a check before dereferencing `ptr_entry` to ensure the entry header
is readable, and a second check after reading `entry->size` to ensure
the full entry stays within the mapped region.
Pass `len` from coreboot_table_probe() into coreboot_table_populate() to
make the mapped region size available for validation.
Signed-off-by: Titouan Ameline de Cadeville <titouan.ameline@gmail.com>
Reviewed-by: Julius Werner <jwerner@chromium.org>
Link: https://lore.kernel.org/r/20260426214739.117131-1-titouan.ameline@gmail.com
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Stable-dep-of: a58a57a1076f ("firmware: coreboot: Validate table bounds")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/google/coreboot_table.c | 11 +++++++++--
1 file changed, 9 insertions(+), 2 deletions(-)
diff --git a/drivers/firmware/google/coreboot_table.c b/drivers/firmware/google/coreboot_table.c
index 882db32e51be9..f212b84ee2f93 100644
--- a/drivers/firmware/google/coreboot_table.c
+++ b/drivers/firmware/google/coreboot_table.c
@@ -101,16 +101,20 @@ void coreboot_driver_unregister(struct coreboot_driver *driver)
}
EXPORT_SYMBOL(coreboot_driver_unregister);
-static int coreboot_table_populate(struct device *dev, void *ptr)
+static int coreboot_table_populate(struct device *dev, void *ptr, resource_size_t len)
{
int i, ret;
void *ptr_entry;
struct coreboot_device *device;
struct coreboot_table_entry *entry;
struct coreboot_table_header *header = ptr;
+ void *ptr_end;
+ ptr_end = ptr + len;
ptr_entry = ptr + header->header_bytes;
for (i = 0; i < header->table_entries; i++) {
+ if (ptr_entry + sizeof(*entry) > ptr_end)
+ return -EINVAL;
entry = ptr_entry;
if (entry->size < sizeof(*entry)) {
@@ -118,6 +122,9 @@ static int coreboot_table_populate(struct device *dev, void *ptr)
return -EINVAL;
}
+ if (ptr_entry + entry->size > ptr_end)
+ return -EINVAL;
+
device = kzalloc(sizeof(device->dev) + entry->size, GFP_KERNEL);
if (!device)
return -ENOMEM;
@@ -183,7 +190,7 @@ static int coreboot_table_probe(struct platform_device *pdev)
if (!ptr)
return -ENOMEM;
- ret = coreboot_table_populate(dev, ptr);
+ ret = coreboot_table_populate(dev, ptr, len);
memunmap(ptr);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0827/1518] firmware: coreboot: Validate table bounds
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (825 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0826/1518] firmware: google: Add bounds checks in coreboot_table_populate() Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0828/1518] pinctrl: eswin: Fix Handling of PIN_CONFIG_PERSIST_STATE Greg Kroah-Hartman
` (171 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Laxman Acharya Padhya, Tzung-Bi Shih,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
[ Upstream commit a58a57a1076f8c5dae0327e3710899478c3be901 ]
The existing coreboot_table_populate() bounds checks limit individual
entries to the mapped length. However, coreboot_table_probe() replaces
the platform resource length with header and table sizes supplied by
firmware before mapping the full table.
A malformed table can overflow the 32-bit size addition or advertise an
extent beyond the resource, causing the driver to map and parse memory
outside the resource. A resource shorter than the fixed header is also
mapped as though it contained a complete header.
Reject resources shorter than the fixed header. After validating the
signature, require a complete header, calculate the advertised extent
with overflow checking, and reject extents beyond the resource before
remapping the table.
Fixes: d384d6f43d1e ("firmware: google memconsole: Add coreboot support")
Signed-off-by: Laxman Acharya Padhya <acharyalaxman8848@gmail.com>
Link: https://lore.kernel.org/r/20260801165651.42172-1-acharyalaxman8848@gmail.com
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/firmware/google/coreboot_table.c | 17 +++++++++++++----
1 file changed, 13 insertions(+), 4 deletions(-)
diff --git a/drivers/firmware/google/coreboot_table.c b/drivers/firmware/google/coreboot_table.c
index f212b84ee2f93..2f1122635098b 100644
--- a/drivers/firmware/google/coreboot_table.c
+++ b/drivers/firmware/google/coreboot_table.c
@@ -159,6 +159,7 @@ static int coreboot_table_populate(struct device *dev, void *ptr, resource_size_
static int coreboot_table_probe(struct platform_device *pdev)
{
resource_size_t len;
+ resource_size_t table_span;
struct coreboot_table_header *header;
struct resource *res;
struct device *dev = &pdev->dev;
@@ -170,7 +171,7 @@ static int coreboot_table_probe(struct platform_device *pdev)
return -EINVAL;
len = resource_size(res);
- if (!res->start || !len)
+ if (!res->start || len < sizeof(*header))
return -EINVAL;
/* Check just the header first to make sure things are sane */
@@ -178,19 +179,27 @@ static int coreboot_table_probe(struct platform_device *pdev)
if (!header)
return -ENOMEM;
- len = header->header_bytes + header->table_bytes;
ret = strncmp(header->signature, "LBIO", sizeof(header->signature));
+
+ if (!ret &&
+ (header->header_bytes < sizeof(*header) ||
+ check_add_overflow((resource_size_t)header->header_bytes,
+ (resource_size_t)header->table_bytes,
+ &table_span) ||
+ table_span > len))
+ ret = -EINVAL;
+
memunmap(header);
if (ret) {
dev_warn(dev, "coreboot table missing or corrupt!\n");
return -ENODEV;
}
- ptr = memremap(res->start, len, MEMREMAP_WB);
+ ptr = memremap(res->start, table_span, MEMREMAP_WB);
if (!ptr)
return -ENOMEM;
- ret = coreboot_table_populate(dev, ptr, len);
+ ret = coreboot_table_populate(dev, ptr, table_span);
memunmap(ptr);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0828/1518] pinctrl: eswin: Fix Handling of PIN_CONFIG_PERSIST_STATE
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (826 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0827/1518] firmware: coreboot: Validate table bounds Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0829/1518] pinctrl: spacemit: validate pins in pinconf callbacks Greg Kroah-Hartman
` (170 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Yulin Lu, Linus Walleij, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yulin Lu <luyulin@eswincomputing.com>
[ Upstream commit f9af1329b98a478f4bba605ec6db429ef0e38d54 ]
The EIC7700 pinctrl driver does not handle PIN_CONFIG_PERSIST_STATE
specifically, and returns -EOPNOTSUPP from the default case.
Since all pins on the EIC7700 SoC are persistent over suspend, the
correct behaviour is to accept this parameter and return success.
Add an explicit case for PIN_CONFIG_PERSIST_STATE that returns 0 to
prevent errors when this parameter is set.
Signed-off-by: Yulin Lu <luyulin@eswincomputing.com>
Fixes: 5b797bcc00ef ("pinctrl: eswin: Add EIC7700 pinctrl driver")
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pinctrl/pinctrl-eic7700.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/pinctrl/pinctrl-eic7700.c b/drivers/pinctrl/pinctrl-eic7700.c
index ffcd0ec5c2dc6..1e72931feca56 100644
--- a/drivers/pinctrl/pinctrl-eic7700.c
+++ b/drivers/pinctrl/pinctrl-eic7700.c
@@ -423,6 +423,9 @@ static int eic7700_pin_config_set(struct pinctrl_dev *pctldev, unsigned int pin,
else
value &= ~EIC7700_ST;
break;
+ /* All pins are persistent over suspend */
+ case PIN_CONFIG_PERSIST_STATE:
+ return 0;
default:
return -EOPNOTSUPP;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0829/1518] pinctrl: spacemit: validate pins in pinconf callbacks
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (827 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0828/1518] pinctrl: eswin: Fix Handling of PIN_CONFIG_PERSIST_STATE Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0830/1518] powerpc/smp: add NULL guard for cause_ipi in smp_muxed_ipi_message_pass Greg Kroah-Hartman
` (169 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Troy Mitchell, Yixun Lan,
Linus Walleij, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Troy Mitchell <troy.mitchell@linux.spacemit.com>
[ Upstream commit 41c59b22370d2e1785e0e80f8ad7bd9946a1ca82 ]
Pin 0 is a valid pin ID, but spacemit_pinconf_get() rejects it by
testing the numeric ID rather than the result of the descriptor lookup.
It also fails to reject nonzero IDs absent from the SoC pin table before
computing their register addresses. Check the descriptor and use its pin
ID for the register lookup.
spacemit_pinconf_group_set() validates only the first group member when
generating the configuration. If a later member is invalid,
spacemit_pin_set_config() returns -EINVAL, but the callback ignores it
and reports success after partially updating the group.
Validate every group member before writing any registers so malformed
groups fail without being partially applied.
Fixes: a83c29e1d145 ("pinctrl: spacemit: add support for SpacemiT K1 SoC")
Signed-off-by: Troy Mitchell <troy.mitchell@linux.spacemit.com>
Reviewed-by: Yixun Lan <dlan@kernel.org>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pinctrl/spacemit/pinctrl-k1.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/drivers/pinctrl/spacemit/pinctrl-k1.c b/drivers/pinctrl/spacemit/pinctrl-k1.c
index 8d797bf24b778..813f86865dcd6 100644
--- a/drivers/pinctrl/spacemit/pinctrl-k1.c
+++ b/drivers/pinctrl/spacemit/pinctrl-k1.c
@@ -475,13 +475,14 @@ static int spacemit_pinconf_get(struct pinctrl_dev *pctldev,
unsigned int pin, unsigned long *config)
{
struct spacemit_pinctrl *pctrl = pinctrl_dev_get_drvdata(pctldev);
+ const struct spacemit_pin *spin = spacemit_get_pin(pctrl, pin);
int param = pinconf_to_config_param(*config);
u32 value, arg = 0;
- if (!pin)
+ if (!spin)
return -EINVAL;
- value = readl(spacemit_pin_to_reg(pctrl, pin));
+ value = readl(spacemit_pin_to_reg(pctrl, spin->pin));
switch (param) {
case PIN_CONFIG_SLEW_RATE:
@@ -654,6 +655,11 @@ static int spacemit_pinconf_group_set(struct pinctrl_dev *pctldev,
if (spacemit_pinconf_generate_config(spin, configs, num_configs, &value))
return -EINVAL;
+ for (i = 0; i < group->grp.npins; i++) {
+ if (!spacemit_get_pin(pctrl, group->grp.pins[i]))
+ return -EINVAL;
+ }
+
for (i = 0; i < group->grp.npins; i++)
spacemit_pin_set_config(pctrl, group->grp.pins[i], value);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0830/1518] powerpc/smp: add NULL guard for cause_ipi in smp_muxed_ipi_message_pass
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (828 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0829/1518] pinctrl: spacemit: validate pins in pinconf callbacks Greg Kroah-Hartman
@ 2026-09-12 6:49 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0831/1518] powerpc/irq: Fix missing r2 clobber in PCREL inline assembly Greg Kroah-Hartman
` (168 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:49 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Gou Hao, jiazhenyuan,
Madhavan Srinivasan, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gou Hao <gouhao@uniontech.com>
[ Upstream commit 5aabc192702defb8950e7c81b05c3f4ca8ee43ec ]
smp_muxed_ipi_message_pass() calls smp_ops->cause_ipi() without
checking whether it has been set.
On platforms using muxed IPI (e.g. powernv/pseries), smp_ops->cause_ipi
is initialized to NULL in the static smp_ops and only assigned during
the platform smp_probe() handler. If the IPI subsystem fails to
initialize -- for example when xive_init_ipis() fails and
xive_smp_probe() returns an error -- the probe handler returns early
and cause_ipi is never set. Any subsequent IPI send (e.g.
arch_smp_send_reschedule()) would dereference the NULL pointer.
Add a NULL check to avoid the crash in that situation.
Fixes: 23d72bfd8f9f ("powerpc: Consolidate ipi message mux and demux")
Signed-off-by: Gou Hao <gouhao@uniontech.com>
Reviewed-by: jiazhenyuan <jiazhenyuan@uniontech.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Link: https://patch.msgid.link/20260727104215.184786-6-gouhao@uniontech.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/powerpc/kernel/smp.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/arch/powerpc/kernel/smp.c b/arch/powerpc/kernel/smp.c
index 0cd9c0c21af3e..b5518fba3b92e 100644
--- a/arch/powerpc/kernel/smp.c
+++ b/arch/powerpc/kernel/smp.c
@@ -289,6 +289,9 @@ void smp_muxed_ipi_set_message(int cpu, int msg)
void smp_muxed_ipi_message_pass(int cpu, int msg)
{
+ if (!smp_ops->cause_ipi)
+ return;
+
smp_muxed_ipi_set_message(cpu, msg);
/*
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0831/1518] powerpc/irq: Fix missing r2 clobber in PCREL inline assembly
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (829 preceding siblings ...)
2026-09-12 6:49 ` [PATCH 6.18 0830/1518] powerpc/smp: add NULL guard for cause_ipi in smp_muxed_ipi_message_pass Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0832/1518] soc: fsl: qe: properly scan GPIO nodes at startup Greg Kroah-Hartman
` (167 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Saket Kumar Bhaskar,
Christophe Leroy (CS GROUP), Hari Bathini, Madhavan Srinivasan,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Saket Kumar Bhaskar <skb99@linux.ibm.com>
[ Upstream commit 00be69070d91d2be978e752bb117a0a4db0e1281 ]
In CONFIG_PPC_KERNEL_PCREL mode, r2 is no longer reserved for the TOC
pointer and is available as a caller-saved register [0].
Both call_do_irq() and call_do_softirq() use inline assembly to call
functions with stack switching, but fail to list r2 in their clobber
lists. This causes the compiler to assume r2 is preserved across these
calls, leading to register corruption when the called functions
(__do_irq and __do_softirq) clobber r2.
As a result of this kernel crash during interrupt handling is seen and
the kernel fails to boot:
BUG: Unable to handle kernel data access on write at 0xc000000404697638
Faulting instruction address: 0xc0000000000181ec
Oops: Kernel access of bad area, sig: 11 [#1]
NIP [c0000000000181ec] __do_IRQ+0x6c/0xc0
With older GCC, the compiler would conservatively allocate
callee-saved registers (like r31) for values spanning function calls,
accidentally avoiding the bug:
<__do_IRQ>:
00 00 00 60 nop
a6 02 08 7c mflr r0
f8 ff e1 fb std r31,-8(r1)
f0 ff c1 fb std r30,-16(r1)
2d 03 10 06 pla r31,53297316
...
3d e8 ff 4b bl c0000000000165ac <__do_irq>
00 00 21 e8 ld r1,0(r1)
28 00 4d e9 ld r10,40(r13)
40 00 21 38 addi r1,r1,64
2a f9 aa 7f stdx r29,r10,r31
With newer GCC 14, the compiler uses r2 for such values, exposing the
missing clobber specification:
<__do_IRQ>:
00 00 00 60 nop
a6 02 08 7c mflr r0
f0 ff c1 fb std r30,-16(r1)
f8 ff e1 fb std r31,-8(r1)
29 02 10 06 pla r2,36252592 # c0000000022aadc0 <__irq_regs>
...
85 dc ff 4b bl c000000000015ee0 <__do_irq>
00 00 21 e8 ld r1,0(r1)
28 00 2d e9 ld r9,40(r13)
30 00 21 38 addi r1,r1,48
2a 11 c9 7f stdx r30,r9,r2
Fix this by adding r2 to the clobber list for both call_do_irq() and
call_do_softirq() when CONFIG_PPC_KERNEL_PCREL is enabled.
[0]: https://www.mail-archive.com/gcc-patches@gcc.gnu.org/msg313226.html
Fixes: 7e3a68be42e1 ("powerpc/64: vmlinux support building with PCREL addresing")
Signed-off-by: Saket Kumar Bhaskar <skb99@linux.ibm.com>
Reviewed-by: Christophe Leroy (CS GROUP) <chleroy@kernel.org>
Reviewed-by: Hari Bathini <hbathini@linux.ibm.com>
Signed-off-by: Madhavan Srinivasan <maddy@linux.ibm.com>
Link: https://patch.msgid.link/10fc2cda485cd22e209a31d786bed1984bdf3982.1785732393.git.skb99@linux.ibm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/powerpc/kernel/irq.c | 16 ++++++++++++----
1 file changed, 12 insertions(+), 4 deletions(-)
diff --git a/arch/powerpc/kernel/irq.c b/arch/powerpc/kernel/irq.c
index a0e8b998c9b52..cb010830c1c4d 100644
--- a/arch/powerpc/kernel/irq.c
+++ b/arch/powerpc/kernel/irq.c
@@ -217,8 +217,12 @@ static __always_inline void call_do_softirq(const void *sp)
[sp] "b" (sp), [offset] "i" (THREAD_SIZE - STACK_FRAME_MIN_SIZE),
[callee] "i" (__do_softirq)
: // Clobbers
- "lr", "xer", "ctr", "memory", "cr0", "cr1", "cr5", "cr6",
- "cr7", "r0", "r3", "r4", "r5", "r6", "r7", "r8", "r9", "r10",
+ "lr", "xer", "ctr", "memory", "cr0", "cr1", "cr5", "cr6", "cr7", "r0",
+ /* r2 may be clobbered by the callee when using PCREL mode in the ELFv2 ABI. */
+#ifdef CONFIG_PPC_KERNEL_PCREL
+ "r2",
+#endif
+ "r3", "r4", "r5", "r6", "r7", "r8", "r9", "r10",
"r11", "r12"
);
}
@@ -275,8 +279,12 @@ static __always_inline void call_do_irq(struct pt_regs *regs, void *sp)
[sp] "b" (sp), [offset] "i" (THREAD_SIZE - STACK_FRAME_MIN_SIZE),
[callee] "i" (__do_irq)
: // Clobbers
- "lr", "xer", "ctr", "memory", "cr0", "cr1", "cr5", "cr6",
- "cr7", "r0", "r4", "r5", "r6", "r7", "r8", "r9", "r10",
+ "lr", "xer", "ctr", "memory", "cr0", "cr1", "cr5", "cr6", "cr7", "r0",
+ /* r2 may be clobbered by the callee when using PCREL mode in the ELFv2 ABI. */
+#ifdef CONFIG_PPC_KERNEL_PCREL
+ "r2",
+#endif
+ "r4", "r5", "r6", "r7", "r8", "r9", "r10",
"r11", "r12"
);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0832/1518] soc: fsl: qe: properly scan GPIO nodes at startup
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (830 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0831/1518] powerpc/irq: Fix missing r2 clobber in PCREL inline assembly Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0833/1518] soc: fsl: qe: implement get_direction() Greg Kroah-Hartman
` (166 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Herve Codina,
Christophe Leroy (CS GROUP), Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christophe Leroy (CS GROUP) <chleroy@kernel.org>
[ Upstream commit e2414b289c2b68afab361def612ca3791cd70d12 ]
Before commit 156460811def ("soc: fsl: qe: Change GPIO driver to a
proper platform driver") qe_add_gpiochips() was walking the device
tree to find all nodes with compatible "fsl,mpc8323-qe-pario-bank".
After that commit the discovery is handled by the platform core,
therefore it is necessary to call of_platform_default_populate() on
the par_io node.
Fixes: 156460811def ("soc: fsl: qe: Change GPIO driver to a proper platform driver")
Reviewed-by: Herve Codina <herve.codina@bootlin.com>
Link: https://lore.kernel.org/r/a1db12ef75bf881dd5fba893a37db0c8517eca1b.1785414349.git.chleroy@kernel.org
Signed-off-by: Christophe Leroy (CS GROUP) <chleroy@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/soc/fsl/qe/qe_io.c | 15 +++++++++++++++
1 file changed, 15 insertions(+)
diff --git a/drivers/soc/fsl/qe/qe_io.c b/drivers/soc/fsl/qe/qe_io.c
index a5e2d0e5ab511..150913fce9818 100644
--- a/drivers/soc/fsl/qe/qe_io.c
+++ b/drivers/soc/fsl/qe/qe_io.c
@@ -15,6 +15,7 @@
#include <linux/errno.h>
#include <linux/module.h>
#include <linux/ioport.h>
+#include <linux/of_platform.h>
#include <asm/io.h>
#include <soc/fsl/qe/qe.h>
@@ -184,3 +185,17 @@ int par_io_of_config(struct device_node *np)
return 0;
}
EXPORT_SYMBOL(par_io_of_config);
+
+static int __init par_io_populate(void)
+{
+ struct device_node *np = of_find_node_by_type(NULL, "par_io");
+
+ if (!np)
+ return 0;
+
+ of_platform_default_populate(np, NULL, NULL);
+ of_node_put(np);
+
+ return 0;
+}
+arch_initcall(par_io_populate);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0833/1518] soc: fsl: qe: implement get_direction()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (831 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0832/1518] soc: fsl: qe: properly scan GPIO nodes at startup Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0834/1518] MIPS: ptrace: Fix syscall skipping via PTRACE_SYSCALL Greg Kroah-Hartman
` (165 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bartosz Golaszewski,
Christophe Leroy (CS GROUP), Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Christophe Leroy (CS GROUP) <chleroy@kernel.org>
[ Upstream commit e460ef309f44b39480209970f1dd462f051d6f30 ]
The lack of get_direction() callback in this driver causes GPIOLIB to
emit a warning. Implement it.
Fixes: e623c4303ed1 ("gpiolib: sanitize the return value of gpio_chip::get_direction()")
Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Link: https://lore.kernel.org/r/30b3f278a10b46252783458c81dc438df176f86c.1785405882.git.chleroy@kernel.org
Signed-off-by: Christophe Leroy (CS GROUP) <chleroy@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/soc/fsl/qe/gpio.c | 25 +++++++++++++++++++++++++
1 file changed, 25 insertions(+)
diff --git a/drivers/soc/fsl/qe/gpio.c b/drivers/soc/fsl/qe/gpio.c
index c54154b404dfd..e6ef713726549 100644
--- a/drivers/soc/fsl/qe/gpio.c
+++ b/drivers/soc/fsl/qe/gpio.c
@@ -135,6 +135,30 @@ static int qe_gpio_dir_out(struct gpio_chip *gc, unsigned int gpio, int val)
return 0;
}
+static int qe_gpio_get_direction(struct gpio_chip *gc, unsigned int gpio)
+{
+ struct qe_gpio_chip *qe_gc = gpiochip_get_data(gc);
+ struct qe_pio_regs __iomem *regs = qe_gc->regs;
+ unsigned long flags;
+ u32 val, mask;
+
+ spin_lock_irqsave(&qe_gc->lock, flags);
+
+ if (gpio < QE_PIO_PINS / 2)
+ val = ioread32be(®s->cpdir1);
+ else
+ val = ioread32be(®s->cpdir2);
+
+ spin_unlock_irqrestore(&qe_gc->lock, flags);
+
+ mask = (u32)QE_PIO_DIR_OUT << (QE_PIO_PINS - 2 - (gpio % (QE_PIO_PINS / 2)) * 2);
+
+ if (val & mask)
+ return GPIO_LINE_DIRECTION_OUT;
+ else
+ return GPIO_LINE_DIRECTION_IN;
+}
+
struct qe_pin {
/*
* The qe_gpio_chip name is unfortunate, we should change that to
@@ -308,6 +332,7 @@ static int qe_gpio_probe(struct platform_device *ofdev)
gc->ngpio = QE_PIO_PINS;
gc->direction_input = qe_gpio_dir_in;
gc->direction_output = qe_gpio_dir_out;
+ gc->get_direction = qe_gpio_get_direction;
gc->get = qe_gpio_get;
gc->set = qe_gpio_set;
gc->set_multiple = qe_gpio_set_multiple;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0834/1518] MIPS: ptrace: Fix syscall skipping via PTRACE_SYSCALL
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (832 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0833/1518] soc: fsl: qe: implement get_direction() Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0835/1518] serial: amba-pl011: unprepare console clock on unregister Greg Kroah-Hartman
` (164 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Philippe Mathieu-Daudé,
Thomas Bogendoerfer, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Thomas Bogendoerfer <tsbogend@alpha.franken.de>
[ Upstream commit 5475c03fa25f31cfd5f8c7e552f8d10347bbaad9 ]
If tracer wanted to skip a syscall return value was always
overwritten with -ENOSYS. Fix this by checking against original
syscall number and only return -ENOSYS, if it is negative.
Fixes: b6318a903d06 ("MIPS/ptrace: Pick up ptrace/seccomp changed syscalls")
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Thomas Bogendoerfer <tsbogend@alpha.franken.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/mips/kernel/ptrace.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/arch/mips/kernel/ptrace.c b/arch/mips/kernel/ptrace.c
index 3f4c94c881241..87102a03b6eaf 100644
--- a/arch/mips/kernel/ptrace.c
+++ b/arch/mips/kernel/ptrace.c
@@ -1321,8 +1321,12 @@ long arch_ptrace(struct task_struct *child, long request,
*/
asmlinkage long syscall_trace_enter(struct pt_regs *regs)
{
+ long syscall;
+
user_exit();
+ syscall = current_thread_info()->syscall;
+
if (test_thread_flag(TIF_SYSCALL_TRACE)) {
if (ptrace_report_syscall_entry(regs))
return -1;
@@ -1342,7 +1346,7 @@ asmlinkage long syscall_trace_enter(struct pt_regs *regs)
* Negative syscall numbers are mistaken for rejected syscalls, but
* won't have had the return value set appropriately, so we do so now.
*/
- if (current_thread_info()->syscall < 0)
+ if (syscall < 0)
syscall_set_return_value(current, regs, -ENOSYS, 0);
return current_thread_info()->syscall;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0835/1518] serial: amba-pl011: unprepare console clock on unregister
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (833 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0834/1518] MIPS: ptrace: Fix syscall skipping via PTRACE_SYSCALL Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0836/1518] serial: amba-pl011: keep console clock enabled for atomic writes Greg Kroah-Hartman
` (163 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 7f93da9d78d433c37836d85de475c5d884ad58ed ]
pl011_console_setup() calls clk_prepare() on the UART clock, but the
console provides no matching teardown, so the clock is never unprepared
when the console is unregistered -- via the sysfs "console" attribute or
a driver unbind. Each re-registration prepares the clock again, leaking
one prepare reference per cycle.
Even where preparing the clock has no hardware effect, the stale
reference leaves the clock framework's prepare count unbalanced. For
providers with prepare/unprepare operations or runtime-PM integration,
it may also retain resources after the console is unregistered.
Add a console .exit() callback that clk_unprepare()s the clock,
balancing the clk_prepare() in pl011_console_setup().
Fixes: 4b4851c65d92 ("clk: amba-pl011: convert to clk_prepare()/clk_unprepare()")
Assisted-by: Claude:claude-fable-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Link: https://patch.msgid.link/20260724213348.77418-2-kmehltretter@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/tty/serial/amba-pl011.c | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/drivers/tty/serial/amba-pl011.c b/drivers/tty/serial/amba-pl011.c
index 9bfccb0213836..66a6d336255bd 100644
--- a/drivers/tty/serial/amba-pl011.c
+++ b/drivers/tty/serial/amba-pl011.c
@@ -2475,6 +2475,15 @@ static int pl011_console_setup(struct console *co, char *options)
return uart_set_options(&uap->port, co, baud, parity, bits, flow);
}
+static int pl011_console_exit(struct console *co)
+{
+ struct uart_amba_port *uap = amba_ports[co->index];
+
+ clk_unprepare(uap->clk);
+
+ return 0;
+}
+
/**
* pl011_console_match - non-standard console matching
* @co: registering console
@@ -2628,6 +2637,7 @@ static struct console amba_console = {
.name = "ttyAMA",
.device = uart_console_device,
.setup = pl011_console_setup,
+ .exit = pl011_console_exit,
.match = pl011_console_match,
.write_atomic = pl011_console_write_atomic,
.write_thread = pl011_console_write_thread,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0836/1518] serial: amba-pl011: keep console clock enabled for atomic writes
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (834 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0835/1518] serial: amba-pl011: unprepare console clock on unregister Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0837/1518] tty: clear cdev pointer after cdev_add() failure Greg Kroah-Hartman
` (162 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, John Ogness, Karl Mehltretter,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit c0e8cfef754645856374e82c8effd54b7d82002b ]
pl011_console_write_atomic() runs from nbcon atomic context, where
sleeping is not allowed. It calls clk_enable(), which takes the common-clk
enable_lock. Under PREEMPT_RT that is a sleeping lock:
clk_enable_lock() first tries spin_trylock_irqsave(), but on contention
falls back to spin_lock_irqsave(). Therefore, an atomic-context printk on
an RT kernel with a clk-backed pl011 can trip:
BUG: sleeping function called from invalid context at spinlock_rt.c:48
__might_resched from rt_spin_lock
rt_spin_lock from clk_enable_lock
clk_enable_lock from clk_enable
clk_enable from pl011_console_write_atomic
... from vprintk_emit
This was found and reproduced on PREEMPT_RT. Arm32 and arm64 DT SoCs are
affected; arm64 SBSA/ACPI has no clk, so clk_enable(NULL) short-circuits
before the lock. In addition, write_atomic() may be invoked from NMI
context and is documented to avoid locking. Removing clk_enable() from
the callback also avoids a potentially unsafe NMI acquisition of the
common-clock enable_lock.
An nbcon atomic-capable console must be printable from any context, so
the clock cannot be gated between writes. Enable the clock while the
console is available for output: use clk_prepare_enable() in
pl011_console_setup(), release it via clk_disable_unprepare() in the
console .exit() callback, and drop the per-write clk_enable()/clk_disable()
pairs from write_atomic() and write_thread().
When printk suspends consoles, drop the reference after
uart_suspend_port() stops console access and restore it before
uart_resume_port() -- but only if suspend actually marked the port
suspended (a wake-capable tty stays running and must keep its clock), and
keep it when console_suspend_enabled is false so no_console_suspend works.
The active power cost of keeping the clock enabled is platform-dependent:
none where the UART clock is a fixed always-on oscillator, real where it
is a gateable clock branch, which then cannot be gated (nor possibly can
its parent clocks) while the console is available for output. When serial
core actually suspends the port, the reference is released so the clock
provider can gate the clock tree.
Fixes: 2eb2608618ce ("serial: amba-pl011: Implement nbcon console")
Suggested-by: John Ogness <john.ogness@linutronix.de>
Link: https://lore.kernel.org/all/8733xeaxix.fsf@jogness.linutronix.de/
Assisted-by: Claude:claude-fable-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Link: https://patch.msgid.link/20260724213348.77418-3-kmehltretter@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/tty/serial/amba-pl011.c | 40 +++++++++++++++++++++++----------
1 file changed, 28 insertions(+), 12 deletions(-)
diff --git a/drivers/tty/serial/amba-pl011.c b/drivers/tty/serial/amba-pl011.c
index 66a6d336255bd..4b213d0c61336 100644
--- a/drivers/tty/serial/amba-pl011.c
+++ b/drivers/tty/serial/amba-pl011.c
@@ -2446,7 +2446,7 @@ static int pl011_console_setup(struct console *co, char *options)
/* Allow pins to be muxed in and configured */
pinctrl_pm_select_default_state(uap->port.dev);
- ret = clk_prepare(uap->clk);
+ ret = clk_prepare_enable(uap->clk);
if (ret)
return ret;
@@ -2479,7 +2479,7 @@ static int pl011_console_exit(struct console *co)
{
struct uart_amba_port *uap = amba_ports[co->index];
- clk_unprepare(uap->clk);
+ clk_disable_unprepare(uap->clk);
return 0;
}
@@ -2553,8 +2553,6 @@ pl011_console_write_atomic(struct console *co, struct nbcon_write_context *wctxt
if (!nbcon_enter_unsafe(wctxt))
return;
- clk_enable(uap->clk);
-
if (!uap->vendor->always_enabled) {
old_cr = pl011_read(uap, REG_CR);
pl011_write((old_cr & ~UART011_CR_CTSEN) | (UART01x_CR_UARTEN | UART011_CR_TXE),
@@ -2571,8 +2569,6 @@ pl011_console_write_atomic(struct console *co, struct nbcon_write_context *wctxt
if (!uap->vendor->always_enabled)
pl011_write(old_cr, uap, REG_CR);
- clk_disable(uap->clk);
-
nbcon_exit_unsafe(wctxt);
}
@@ -2585,8 +2581,6 @@ pl011_console_write_thread(struct console *co, struct nbcon_write_context *wctxt
if (!nbcon_enter_unsafe(wctxt))
return;
- clk_enable(uap->clk);
-
if (!uap->vendor->always_enabled) {
old_cr = pl011_read(uap, REG_CR);
pl011_write((old_cr & ~UART011_CR_CTSEN) | (UART01x_CR_UARTEN | UART011_CR_TXE),
@@ -2615,8 +2609,6 @@ pl011_console_write_thread(struct console *co, struct nbcon_write_context *wctxt
if (!uap->vendor->always_enabled)
pl011_write(old_cr, uap, REG_CR);
- clk_disable(uap->clk);
-
nbcon_exit_unsafe(wctxt);
}
@@ -2976,21 +2968,45 @@ static void pl011_remove(struct amba_device *dev)
static int pl011_suspend(struct device *dev)
{
struct uart_amba_port *uap = dev_get_drvdata(dev);
+ int ret;
if (!uap)
return -EINVAL;
- return uart_suspend_port(&amba_reg, &uap->port);
+ ret = uart_suspend_port(&amba_reg, &uap->port);
+ if (ret)
+ return ret;
+
+ if (console_suspend_enabled && uap->port.suspended &&
+ uart_console_registered(&uap->port))
+ clk_disable_unprepare(uap->clk);
+
+ return 0;
}
static int pl011_resume(struct device *dev)
{
struct uart_amba_port *uap = dev_get_drvdata(dev);
+ bool resume_console;
+ int ret;
if (!uap)
return -EINVAL;
- return uart_resume_port(&amba_reg, &uap->port);
+ resume_console = console_suspend_enabled &&
+ uap->port.suspended &&
+ uart_console_registered(&uap->port);
+ if (resume_console) {
+ ret = clk_prepare_enable(uap->clk);
+ if (ret)
+ return ret;
+ }
+
+ ret = uart_resume_port(&amba_reg, &uap->port);
+ if (ret && resume_console)
+ clk_disable_unprepare(uap->clk);
+
+ return ret;
}
#endif
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0837/1518] tty: clear cdev pointer after cdev_add() failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (835 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0836/1518] serial: amba-pl011: keep console clock enabled for atomic writes Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0838/1518] dm-integrity: replace forgeable discard filler with a keyed sector marker Greg Kroah-Hartman
` (161 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 6645856f0df3aeecd45519cb611415b4b89c2223 ]
tty_cdev_add() drops the cdev reference when cdev_add() fails, but
leaves driver->cdevs[index] pointing to freed memory.
tty_unregister_device() later passes that stale pointer to cdev_del(),
causing a use-after-free.
Clear the slot after dropping the reference.
Fixes: c1a752ba2d6b ("tty: don't leak cdev in tty_cdev_add()")
Assisted-by: Claude:claude-fable-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Link: https://patch.msgid.link/20260731181844.11330-5-kmehltretter@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/tty/tty_io.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/tty/tty_io.c b/drivers/tty/tty_io.c
index e2d92cf70eb78..f779f8fb138e8 100644
--- a/drivers/tty/tty_io.c
+++ b/drivers/tty/tty_io.c
@@ -3167,8 +3167,10 @@ static int tty_cdev_add(struct tty_driver *driver, dev_t dev,
driver->cdevs[index]->ops = &tty_fops;
driver->cdevs[index]->owner = driver->owner;
err = cdev_add(driver->cdevs[index], dev, count);
- if (err)
+ if (err) {
kobject_put(&driver->cdevs[index]->kobj);
+ driver->cdevs[index] = NULL;
+ }
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0838/1518] dm-integrity: replace forgeable discard filler with a keyed sector marker
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (836 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0837/1518] tty: clear cdev pointer after cdev_add() failure Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0839/1518] misc: pci_endpoint_test: Check SUCCESS bit for doorbell status Greg Kroah-Hartman
` (160 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jo Van Bulck, Shukai Ni,
Mikulas Patocka, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shukai Ni <shukai.ni@kuleuven.be>
[ Upstream commit 68c5c42567bc462139128968ebbfadd0aefff519 ]
The discard-block check in dm_integrity_rw_tag() treats a stored tag
of all 0xf6 bytes (DISCARD_FILLER) as proof a block was discarded and
skips HMAC verification. allow_discards is only accepted in
dm-integrity's standalone mode. An attacker with raw write access to
the backing device, but without the integrity key, can stamp any block
with an all-0xf6 tag and have it served as authentic.
Add a new "allow_discards_keyed" target argument that marks discarded
blocks with a keyed checksum of (salt || sector) instead, computed by
integrity_discard_checksum().
Fixes: 84597a44a9d8 ("dm integrity: add optional discard support")
Co-developed-by: Jo Van Bulck <jo.vanbulck@cs.kuleuven.be>
Signed-off-by: Jo Van Bulck <jo.vanbulck@cs.kuleuven.be>
Signed-off-by: Shukai Ni <shukai.ni@kuleuven.be>
Signed-off-by: Mikulas Patocka <mpatocka@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../admin-guide/device-mapper/dm-ima.rst | 7 +-
.../device-mapper/dm-integrity.rst | 13 ++
drivers/md/dm-integrity.c | 137 +++++++++++++++---
3 files changed, 133 insertions(+), 24 deletions(-)
diff --git a/Documentation/admin-guide/device-mapper/dm-ima.rst b/Documentation/admin-guide/device-mapper/dm-ima.rst
index a4aa50a828e00..2a3b50ffbee4e 100644
--- a/Documentation/admin-guide/device-mapper/dm-ima.rst
+++ b/Documentation/admin-guide/device-mapper/dm-ima.rst
@@ -424,7 +424,8 @@ section above) has the following data format for 'integrity' target.
target_attributes := <target_name> "," <target_version> "," <dev_name> "," <start>
<tag_size> "," <mode> "," [<meta_device> ","] [<block_size> ","] <recalculate> ","
- <allow_discards> "," <fix_padding> "," <fix_hmac> "," <legacy_recalculate> ","
+ <allow_discards> "," <allow_discards_keyed> "," <fix_padding> "," <fix_hmac> ","
+ <legacy_recalculate> ","
<journal_sectors> "," <interleave_sectors> "," <buffer_sectors> ";"
target_name := "target_name=integrity"
@@ -438,6 +439,7 @@ section above) has the following data format for 'integrity' target.
block_size := "block_size=" <N>
recalculate := "recalculate=" <yes_no>
allow_discards := "allow_discards=" <yes_no>
+ allow_discards_keyed := "allow_discards_keyed=" <yes_no>
fix_padding := "fix_padding=" <yes_no>
fix_hmac := "fix_hmac=" <yes_no>
legacy_recalculate := "legacy_recalculate=" <yes_no>
@@ -455,7 +457,8 @@ section above) has the following data format for 'integrity' target.
dm_version=4.45.0;
name=integrity1,uuid=,major=253,minor=1,minor_count=1,num_targets=1;
target_index=0,target_begin=0,target_len=7856,target_name=integrity,target_version=1.10.0,
- dev_name=253:0,start=0,tag_size=32,mode=J,recalculate=n,allow_discards=n,fix_padding=n,
+ dev_name=253:0,start=0,tag_size=32,mode=J,recalculate=n,allow_discards=n,
+ allow_discards_keyed=n,fix_padding=n,
fix_hmac=n,legacy_recalculate=n,journal_sectors=88,interleave_sectors=32768,buffer_sectors=128;
diff --git a/Documentation/admin-guide/device-mapper/dm-integrity.rst b/Documentation/admin-guide/device-mapper/dm-integrity.rst
index c2e18ecc065c9..9c21301423c9e 100644
--- a/Documentation/admin-guide/device-mapper/dm-integrity.rst
+++ b/Documentation/admin-guide/device-mapper/dm-integrity.rst
@@ -190,6 +190,19 @@ allow_discards
Allow block discard requests (a.k.a. TRIM) for the integrity device.
Discards are only allowed to devices using internal hash.
+ A discarded block is marked with a constant filler tag that anyone
+ with raw write access to the backing device can forge without the
+ key. Use allow_discards_keyed instead on new volumes.
+
+allow_discards_keyed
+ Like allow_discards, but marks a discarded block with a keyed
+ checksum of the sector number, HMAC_key(salt || sector), instead of
+ the constant filler tag, so it can't be forged without the
+ integrity key.
+
+ Not compatible with volumes that already have discarded blocks
+ marked the old way; only use on a freshly formatted volume.
+
fix_padding
Use a smaller padding of the tag area that is more
space-efficient. If this option is not present, large padding is
diff --git a/drivers/md/dm-integrity.c b/drivers/md/dm-integrity.c
index 46a815f20b095..e79ae49073857 100644
--- a/drivers/md/dm-integrity.c
+++ b/drivers/md/dm-integrity.c
@@ -65,6 +65,7 @@
#define SB_VERSION_4 4
#define SB_VERSION_5 5
#define SB_VERSION_6 6
+#define SB_VERSION_7 7
#define SB_SECTORS 8
#define MAX_SECTORS_PER_BLOCK 8
@@ -90,6 +91,7 @@ struct superblock {
#define SB_FLAG_FIXED_PADDING 0x8
#define SB_FLAG_FIXED_HMAC 0x10
#define SB_FLAG_INLINE 0x20
+#define SB_FLAG_DISCARD_KEYED 0x40
#define JOURNAL_ENTRY_ROUNDUP 8
@@ -276,6 +278,7 @@ struct dm_integrity_c {
bool recalculate_flag;
bool reset_recalculate_flag;
bool discard;
+ bool discard_keyed;
bool fix_padding;
bool fix_hmac;
bool legacy_recalculate;
@@ -482,7 +485,9 @@ static void wraparound_section(struct dm_integrity_c *ic, unsigned int *sec_ptr)
static void sb_set_version(struct dm_integrity_c *ic)
{
- if (ic->sb->flags & cpu_to_le32(SB_FLAG_INLINE))
+ if (ic->sb->flags & cpu_to_le32(SB_FLAG_DISCARD_KEYED))
+ ic->sb->version = SB_VERSION_7;
+ else if (ic->sb->flags & cpu_to_le32(SB_FLAG_INLINE))
ic->sb->version = SB_VERSION_6;
else if (ic->sb->flags & cpu_to_le32(SB_FLAG_FIXED_HMAC))
ic->sb->version = SB_VERSION_5;
@@ -1415,7 +1420,7 @@ static int dm_integrity_rw_tag(struct dm_integrity_c *ic, unsigned char *tag, se
{
unsigned int hash_offset = 0;
unsigned char mismatch_hash = 0;
- unsigned char mismatch_filler = !ic->discard;
+ unsigned char mismatch_filler = !ic->discard || ic->discard_keyed;
do {
unsigned char *data, *dp;
@@ -1467,7 +1472,7 @@ static int dm_integrity_rw_tag(struct dm_integrity_c *ic, unsigned char *tag, se
}
hash_offset = 0;
mismatch_hash = 0;
- mismatch_filler = !ic->discard;
+ mismatch_filler = !ic->discard || ic->discard_keyed;
}
}
}
@@ -1645,7 +1650,8 @@ static void integrity_end_io(struct bio *bio)
}
static void integrity_sector_checksum_shash(struct dm_integrity_c *ic, sector_t sector,
- const char *data, unsigned offset, char *result)
+ const char *data, unsigned offset,
+ unsigned int len, char *result)
{
__le64 sector_le = cpu_to_le64(sector);
SHASH_DESC_ON_STACK(req, ic->internal_shash);
@@ -1674,10 +1680,12 @@ static void integrity_sector_checksum_shash(struct dm_integrity_c *ic, sector_t
goto failed;
}
- r = crypto_shash_update(req, data + offset, ic->sectors_per_block << SECTOR_SHIFT);
- if (unlikely(r < 0)) {
- dm_integrity_io_error(ic, "crypto_shash_update", r);
- goto failed;
+ if (likely(len)) {
+ r = crypto_shash_update(req, data + offset, len);
+ if (unlikely(r < 0)) {
+ dm_integrity_io_error(ic, "crypto_shash_update", r);
+ goto failed;
+ }
}
r = crypto_shash_final(req, result);
@@ -1698,7 +1706,8 @@ static void integrity_sector_checksum_shash(struct dm_integrity_c *ic, sector_t
}
static void integrity_sector_checksum_ahash(struct dm_integrity_c *ic, struct ahash_request **ahash_req,
- sector_t sector, struct page *page, unsigned offset, char *result)
+ sector_t sector, struct page *page, unsigned offset,
+ unsigned int len, char *result)
{
__le64 sector_le = cpu_to_le64(sector);
struct ahash_request *req;
@@ -1707,6 +1716,7 @@ static void integrity_sector_checksum_ahash(struct dm_integrity_c *ic, struct ah
int r;
unsigned int digest_size;
unsigned int nbytes = 0;
+ unsigned int nents = 1 + (len ? 1 : 0);
might_sleep();
@@ -1720,12 +1730,12 @@ static void integrity_sector_checksum_ahash(struct dm_integrity_c *ic, struct ah
ahash_request_set_callback(req, CRYPTO_TFM_REQ_MAY_SLEEP, crypto_req_done, &wait);
if (ic->sb->flags & cpu_to_le32(SB_FLAG_FIXED_HMAC)) {
- sg_init_table(sg, 3);
+ sg_init_table(sg, nents + 1);
sg_set_buf(s, (const __u8 *)&ic->sb->salt, SALT_SIZE);
nbytes += SALT_SIZE;
s++;
} else {
- sg_init_table(sg, 2);
+ sg_init_table(sg, nents);
}
if (likely(!is_vmalloc_addr(§or_le))) {
@@ -1738,8 +1748,10 @@ static void integrity_sector_checksum_ahash(struct dm_integrity_c *ic, struct ah
nbytes += sizeof(sector_le);
s++;
- sg_set_page(s, page, ic->sectors_per_block << SECTOR_SHIFT, offset);
- nbytes += ic->sectors_per_block << SECTOR_SHIFT;
+ if (likely(len)) {
+ sg_set_page(s, page, len, offset);
+ nbytes += len;
+ }
ahash_request_set_crypt(req, sg, result, nbytes);
@@ -1762,11 +1774,41 @@ static void integrity_sector_checksum_ahash(struct dm_integrity_c *ic, struct ah
static void integrity_sector_checksum(struct dm_integrity_c *ic, struct ahash_request **ahash_req,
sector_t sector, const char *data, unsigned offset, char *result)
+{
+ unsigned int len = ic->sectors_per_block << SECTOR_SHIFT;
+
+ if (likely(ic->internal_shash != NULL))
+ integrity_sector_checksum_shash(ic, sector, data, offset, len, result);
+ else
+ integrity_sector_checksum_ahash(ic, ahash_req, sector, (struct page *)data,
+ offset, len, result);
+}
+
+/*
+ * Authenticated marker for a discarded block: HMAC_key(salt || sector), with
+ * no data payload. Because a real data tag's input always covers a full
+ * block, its length differs from this marker's, so the two can never
+ * collide structurally, regardless of block content.
+ */
+static void integrity_discard_checksum(struct dm_integrity_c *ic, struct ahash_request **ahash_req,
+ sector_t sector, char *result)
{
if (likely(ic->internal_shash != NULL))
- integrity_sector_checksum_shash(ic, sector, data, offset, result);
+ integrity_sector_checksum_shash(ic, sector, NULL, 0, 0, result);
else
- integrity_sector_checksum_ahash(ic, ahash_req, sector, (struct page *)data, offset, result);
+ integrity_sector_checksum_ahash(ic, ahash_req, sector, NULL, 0, 0, result);
+}
+
+static void integrity_discard_fill_tags(struct dm_integrity_c *ic, struct ahash_request **ahash_req,
+ unsigned char *checksums, sector_t *sector,
+ unsigned int blocks)
+{
+ unsigned int i;
+
+ for (i = 0; i < blocks; i++) {
+ integrity_discard_checksum(ic, ahash_req, *sector, checksums + i * ic->tag_size);
+ *sector += ic->sectors_per_block;
+ }
}
static void *integrity_kmap(struct dm_integrity_c *ic, struct page *p)
@@ -1795,6 +1837,29 @@ static void *integrity_identity(struct dm_integrity_c *ic, void *data)
return virt_to_page(data);
}
+static int integrity_recheck_verify_tag(struct dm_integrity_io *dio, char *checksum,
+ char *on_disk_tag, sector_t logical_sector)
+{
+ struct dm_integrity_c *ic = dio->ic;
+ int r;
+
+ if (!ic->discard_keyed)
+ return dm_integrity_rw_tag(ic, checksum, &dio->metadata_block,
+ &dio->metadata_offset, ic->tag_size, TAG_CMP);
+
+ r = dm_integrity_rw_tag(ic, on_disk_tag, &dio->metadata_block,
+ &dio->metadata_offset, ic->tag_size, TAG_READ);
+ if (unlikely(r))
+ return r;
+
+ r = crypto_memneq(on_disk_tag, checksum, ic->tag_size);
+ if (unlikely(r)) {
+ integrity_discard_checksum(ic, &dio->ahash_req, logical_sector, checksum);
+ r = crypto_memneq(on_disk_tag, checksum, ic->tag_size);
+ }
+ return r;
+}
+
static noinline void integrity_recheck(struct dm_integrity_io *dio, char *checksum)
{
struct bio *bio = dm_bio_from_per_bio_data(dio, sizeof(struct dm_integrity_io));
@@ -1820,6 +1885,7 @@ static noinline void integrity_recheck(struct dm_integrity_io *dio, char *checks
char *mem;
char *buffer = page_to_virt(page);
unsigned int buffer_offset;
+ char on_disk_tag[MAX_T(size_t, HASH_MAX_DIGESTSIZE, MAX_TAG_SIZE)];
int r;
struct dm_io_request io_req;
struct dm_io_region io_loc;
@@ -1847,8 +1913,8 @@ static noinline void integrity_recheck(struct dm_integrity_io *dio, char *checks
}
integrity_sector_checksum(ic, &dio->ahash_req, logical_sector, integrity_identity(ic, buffer), buffer_offset, checksum);
- r = dm_integrity_rw_tag(ic, checksum, &dio->metadata_block,
- &dio->metadata_offset, ic->tag_size, TAG_CMP);
+ r = integrity_recheck_verify_tag(dio, checksum, on_disk_tag,
+ logical_sector);
if (r) {
if (r > 0) {
DMERR_LIMIT("%pg: Checksum failed at sector 0x%llx",
@@ -1914,13 +1980,18 @@ static void integrity_metadata(struct work_struct *w)
unsigned int bi_size = dio->bio_details.bi_iter.bi_size;
unsigned int max_size = likely(checksums != checksums_onstack) ? PAGE_SIZE : HASH_MAX_DIGESTSIZE;
unsigned int max_blocks = max_size / ic->tag_size;
+ sector_t sector = dio->range.logical_sector;
- memset(checksums, DISCARD_FILLER, max_size);
+ if (!ic->discard_keyed)
+ memset(checksums, DISCARD_FILLER, max_size);
while (bi_size) {
unsigned int this_step_blocks = bi_size >> (SECTOR_SHIFT + ic->sb->log2_sectors_per_block);
this_step_blocks = min(this_step_blocks, max_blocks);
+ if (ic->discard_keyed)
+ integrity_discard_fill_tags(ic, &dio->ahash_req, checksums,
+ §or, this_step_blocks);
r = dm_integrity_rw_tag(ic, checksums, &dio->metadata_block, &dio->metadata_offset,
this_step_blocks * ic->tag_size, TAG_WRITE);
if (unlikely(r)) {
@@ -3797,6 +3868,8 @@ static void dm_integrity_resume(struct dm_target *ti)
ic->wrote_to_journal = false;
flags = ic->sb->flags & cpu_to_le32(SB_FLAG_RECALCULATING);
+ if (ic->discard_keyed)
+ flags |= cpu_to_le32(SB_FLAG_DISCARD_KEYED);
r = sync_rw_sb(ic, REQ_OP_READ);
if (r)
dm_integrity_io_error(ic, "reading superblock", r);
@@ -3944,7 +4017,8 @@ static void dm_integrity_status(struct dm_target *ti, status_type_t type,
arg_count += ic->sectors_per_block != 1;
arg_count += !!(ic->sb->flags & cpu_to_le32(SB_FLAG_RECALCULATING));
arg_count += ic->reset_recalculate_flag;
- arg_count += ic->discard;
+ arg_count += ic->discard && !ic->discard_keyed;
+ arg_count += ic->discard_keyed;
arg_count += ic->mode != 'I'; /* interleave_sectors */
arg_count += ic->mode == 'J'; /* journal_sectors */
arg_count += ic->mode == 'J'; /* journal_watermark */
@@ -3967,8 +4041,10 @@ static void dm_integrity_status(struct dm_target *ti, status_type_t type,
DMEMIT(" recalculate");
if (ic->reset_recalculate_flag)
DMEMIT(" reset_recalculate");
- if (ic->discard)
+ if (ic->discard && !ic->discard_keyed)
DMEMIT(" allow_discards");
+ if (ic->discard_keyed)
+ DMEMIT(" allow_discards_keyed");
if (ic->mode != 'I')
DMEMIT(" interleave_sectors:%u", 1U << ic->sb->log2_interleave_sectors);
DMEMIT(" buffer_sectors:%u", 1U << ic->log2_buffer_sectors);
@@ -4018,6 +4094,7 @@ static void dm_integrity_status(struct dm_target *ti, status_type_t type,
DMEMIT(",recalculate=%c", (ic->sb->flags & cpu_to_le32(SB_FLAG_RECALCULATING)) ?
'y' : 'n');
DMEMIT(",allow_discards=%c", ic->discard ? 'y' : 'n');
+ DMEMIT(",allow_discards_keyed=%c", ic->discard_keyed ? 'y' : 'n');
DMEMIT(",fix_padding=%c",
((ic->sb->flags & cpu_to_le32(SB_FLAG_FIXED_PADDING)) != 0) ? 'y' : 'n');
DMEMIT(",fix_hmac=%c",
@@ -4179,6 +4256,9 @@ static int initialize_superblock(struct dm_integrity_c *ic,
get_random_bytes(ic->sb->salt, SALT_SIZE);
}
+ if (ic->discard_keyed)
+ ic->sb->flags |= cpu_to_le32(SB_FLAG_DISCARD_KEYED);
+
if (!ic->meta_dev) {
if (ic->fix_padding)
ic->sb->flags |= cpu_to_le32(SB_FLAG_FIXED_PADDING);
@@ -4838,6 +4918,9 @@ static int dm_integrity_ctr(struct dm_target *ti, unsigned int argc, char **argv
ic->reset_recalculate_flag = true;
} else if (!strcmp(opt_string, "allow_discards")) {
ic->discard = true;
+ } else if (!strcmp(opt_string, "allow_discards_keyed")) {
+ ic->discard = true;
+ ic->discard_keyed = true;
} else if (!strcmp(opt_string, "fix_padding")) {
ic->fix_padding = true;
} else if (!strcmp(opt_string, "fix_hmac")) {
@@ -4966,6 +5049,11 @@ static int dm_integrity_ctr(struct dm_target *ti, unsigned int argc, char **argv
ti->error = "Discard can be only used with internal hash";
goto bad;
}
+ if (ic->discard_keyed && !ic->internal_hash_alg.key) {
+ r = -EINVAL;
+ ti->error = "Keyed discard can only be used with keyed internal hash";
+ goto bad;
+ }
ic->autocommit_jiffies = msecs_to_jiffies(sync_msec);
ic->autocommit_msec = sync_msec;
@@ -5084,7 +5172,7 @@ static int dm_integrity_ctr(struct dm_target *ti, unsigned int argc, char **argv
should_write_sb = true;
}
- if (!ic->sb->version || ic->sb->version > SB_VERSION_6) {
+ if (!ic->sb->version || ic->sb->version > SB_VERSION_7) {
r = -EINVAL;
ti->error = "Unknown version";
goto bad;
@@ -5132,6 +5220,11 @@ static int dm_integrity_ctr(struct dm_target *ti, unsigned int argc, char **argv
goto bad;
}
}
+ if (!ic->discard_keyed && (ic->sb->flags & cpu_to_le32(SB_FLAG_DISCARD_KEYED))) {
+ r = -EINVAL;
+ ti->error = "Keyed discard cannot be disabled once enabled";
+ goto bad;
+ }
if (!!(ic->sb->flags & cpu_to_le32(SB_FLAG_HAVE_JOURNAL_MAC)) != !!ic->journal_mac_alg.alg_string) {
r = -EINVAL;
ti->error = "Journal mac mismatch";
@@ -5432,7 +5525,7 @@ static void dm_integrity_dtr(struct dm_target *ti)
static struct target_type integrity_target = {
.name = "integrity",
- .version = {1, 14, 0},
+ .version = {1, 15, 0},
.module = THIS_MODULE,
.features = DM_TARGET_SINGLETON | DM_TARGET_INTEGRITY,
.ctr = dm_integrity_ctr,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0839/1518] misc: pci_endpoint_test: Check SUCCESS bit for doorbell status
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (837 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0838/1518] dm-integrity: replace forgeable discard filler with a keyed sector marker Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0840/1518] HID: i2c-hid: Refactor _DSM helper and add i2c-hid-acpi-prp0001 driver Greg Kroah-Hartman
` (159 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Niklas Cassel, Manivannan Sadhasivam,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Niklas Cassel <cassel@kernel.org>
[ Upstream commit 37ddcce6904c20c6a7debe4751f6a82f218c3bae ]
The pci-epf driver sets STATUS_DOORBELL_ENABLE_SUCCESS as the final step of
pci_epf_test_enable_doorbell(), and STATUS_DOORBELL_DISABLE_SUCCESS as the
final step of pci_epf_test_disable_doorbell(). A missing SUCCESS bit
therefore unambiguously means that the operation did not complete, whereas
the FAIL bit is only set on an explicit failure path.
The host side test in pci_endpoint_test_doorbell() currently keys off
the FAIL bit. That covers explicit failures but misses two cases.
The first case is when the wait for the completion IRQ times out. No IRQ
arrives, the Endpoint never updates STATUS, and neither SUCCESS nor FAIL
is set. The enable path already handles this correctly because it also
fails when the wait times out without an IRQ. The disable path does not
have that extra guard and would wrongly treat the timeout as success.
The second is a buggy EPC that raises two IRQs in response to a single
DOORBELL_ENABLE command. The second wait_for_completion_timeout()
returns immediately with 'left' non zero, but the endpoint has not yet
written STATUS, so SUCCESS is clear and FAIL is also clear. The current
FAIL only check treats this as success.
So check the SUCCESS bit instead. That matches the Endpoint's contract
because SUCCESS is the last write on the success path, and it correctly
reports failure for both timeouts and the spurious IRQ case without
relying on the FAIL bit being set.
Fixes: eefb83790a0d ("misc: pci_endpoint_test: Add doorbell test case")
Signed-off-by: Niklas Cassel <cassel@kernel.org>
[mani: commit log]
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Link: https://patch.msgid.link/20260730122045.1382749-5-cassel@kernel.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/misc/pci_endpoint_test.c | 11 ++++++-----
1 file changed, 6 insertions(+), 5 deletions(-)
diff --git a/drivers/misc/pci_endpoint_test.c b/drivers/misc/pci_endpoint_test.c
index 1c0fd185114fc..fdce31f9fa43d 100644
--- a/drivers/misc/pci_endpoint_test.c
+++ b/drivers/misc/pci_endpoint_test.c
@@ -859,6 +859,7 @@ static int pci_endpoint_test_doorbell(struct pci_endpoint_test *test)
struct pci_dev *pdev = test->pdev;
struct device *dev = &pdev->dev;
int irq_type = test->irq_type;
+ int ret = 0;
enum pci_barno bar;
u32 data, status;
u32 addr;
@@ -900,8 +901,11 @@ static int pci_endpoint_test_doorbell(struct pci_endpoint_test *test)
status = pci_endpoint_test_readl(test, PCI_ENDPOINT_TEST_STATUS);
- if (!left || !(status & STATUS_DOORBELL_SUCCESS))
+ if (!left || !(status & STATUS_DOORBELL_SUCCESS)) {
dev_err(dev, "Failed to trigger doorbell in endpoint\n");
+ /* Store error code, but continue to disable doorbell. */
+ ret = -EINVAL;
+ }
pci_endpoint_test_writel(test, PCI_ENDPOINT_TEST_COMMAND,
COMMAND_DISABLE_DOORBELL);
@@ -915,10 +919,7 @@ static int pci_endpoint_test_doorbell(struct pci_endpoint_test *test)
return -EINVAL;
}
- if (!(status & STATUS_DOORBELL_SUCCESS))
- return -EINVAL;
-
- return 0;
+ return ret;
}
static long pci_endpoint_test_ioctl(struct file *file, unsigned int cmd,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0840/1518] HID: i2c-hid: Refactor _DSM helper and add i2c-hid-acpi-prp0001 driver
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (838 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0839/1518] misc: pci_endpoint_test: Check SUCCESS bit for doorbell status Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0841/1518] HID: synchronize input before cleaning up a failed probe Greg Kroah-Hartman
` (158 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, 谢致邦 ,
Jiri Kosina, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: 谢致邦 (XIE Zhibang) <Yeking@Red54.com>
[ Upstream commit fd7c67d05fb695b1deb07f9e213dd7e80e3a8427 ]
Move the _DSM call that gets the HID descriptor address from
i2c-hid-acpi.c into i2c-hid-acpi.h as a static inline so both the ACPI
and the new PRP0001 driver can use it. While refactoring, move the
blacklist check and the _DSM call to the top of probe() to avoid a
pointless alloc when the device is blacklisted or does not implement the
_DSM.
Some devices, for example the Lenovo KaiTian N60d and Inspur CP300L3,
are declared with _HID "PRP0001" and _DSD compatible "hid-over-i2c" but
lack "hid-descr-addr" from the _DSD and provide the HID descriptor
address only through an ACPI _DSM. The OF driver fails to probe them
because it requires hid-descr-addr. Add a new driver that handles these
devices by calling the shared _DSM helper.
Link: https://lore.kernel.org/tencent_F6FC553D1BB737FC00062AD0FEF43C580F0A@qq.com
Fixes: b33752c30023 ("HID: i2c-hid: Reorganize so ACPI and OF are separate modules")
Signed-off-by: 谢致邦 (XIE Zhibang) <Yeking@Red54.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hid/i2c-hid/Makefile | 2 +-
drivers/hid/i2c-hid/i2c-hid-acpi-prp0001.c | 104 +++++++++++++++++++++
drivers/hid/i2c-hid/i2c-hid-acpi.c | 52 +++--------
drivers/hid/i2c-hid/i2c-hid-acpi.h | 33 +++++++
4 files changed, 152 insertions(+), 39 deletions(-)
create mode 100644 drivers/hid/i2c-hid/i2c-hid-acpi-prp0001.c
create mode 100644 drivers/hid/i2c-hid/i2c-hid-acpi.h
diff --git a/drivers/hid/i2c-hid/Makefile b/drivers/hid/i2c-hid/Makefile
index 55bd5e0f35af3..38d5d827f3ce4 100644
--- a/drivers/hid/i2c-hid/Makefile
+++ b/drivers/hid/i2c-hid/Makefile
@@ -8,7 +8,7 @@ obj-$(CONFIG_I2C_HID_CORE) += i2c-hid.o
i2c-hid-objs = i2c-hid-core.o
i2c-hid-$(CONFIG_DMI) += i2c-hid-dmi-quirks.o
-obj-$(CONFIG_I2C_HID_ACPI) += i2c-hid-acpi.o
+obj-$(CONFIG_I2C_HID_ACPI) += i2c-hid-acpi.o i2c-hid-acpi-prp0001.o
obj-$(CONFIG_I2C_HID_OF) += i2c-hid-of.o
obj-$(CONFIG_I2C_HID_OF_ELAN) += i2c-hid-of-elan.o
obj-$(CONFIG_I2C_HID_OF_GOODIX) += i2c-hid-of-goodix.o
diff --git a/drivers/hid/i2c-hid/i2c-hid-acpi-prp0001.c b/drivers/hid/i2c-hid/i2c-hid-acpi-prp0001.c
new file mode 100644
index 0000000000000..d2cf4714ae7f1
--- /dev/null
+++ b/drivers/hid/i2c-hid/i2c-hid-acpi-prp0001.c
@@ -0,0 +1,104 @@
+// SPDX-License-Identifier: GPL-2.0-only
+/*
+ * HID over I2C driver for PRP0001 devices missing hid-descr-addr
+ *
+ * Some devices, for example the Lenovo KaiTian N60d and Inspur CP300L3, use
+ * _HID "PRP0001" with _DSD compatible "hid-over-i2c" but lack "hid-descr-addr"
+ * from the _DSD. The HID descriptor address is provided only through an ACPI
+ * _DSM. The TPD0 node in the DSDT shows _DSM Function 1 returning 0x20.
+ *
+ * Copyright (C) 2026 谢致邦 (XIE Zhibang) <Yeking@Red54.com>
+ */
+
+#include <linux/delay.h>
+#include <linux/device.h>
+#include <linux/i2c.h>
+#include <linux/module.h>
+#include <linux/of.h>
+
+#include "i2c-hid.h"
+#include "i2c-hid-acpi.h"
+
+static int i2c_hid_acpi_prp0001_power_up(struct i2chid_ops *ops)
+{
+ /* give the device time to power up */
+ msleep(750);
+ return 0;
+}
+
+static struct i2chid_ops i2c_hid_acpi_prp0001_ops = {
+ .power_up = i2c_hid_acpi_prp0001_power_up,
+ /*
+ * No .restore_sequence needed: the _DSM on these devices returns a
+ * constant (0x20) with no side effects, unlike some PNP0C50 _DSM
+ * implementations that switch the hardware between PS/2 and I2C modes.
+ */
+};
+
+static int i2c_hid_acpi_prp0001_probe(struct i2c_client *client)
+{
+ struct device *dev = &client->dev;
+ struct acpi_device *adev;
+ u16 hid_descriptor_address;
+ int ret;
+
+ /* If hid-descr-addr is present, let i2c-hid-of handle it */
+ if (device_property_present(dev, "hid-descr-addr"))
+ return -ENODEV;
+
+ adev = ACPI_COMPANION(dev);
+ if (!adev)
+ return -ENODEV;
+
+ ret = i2c_hid_acpi_get_descriptor(adev);
+ if (ret < 0)
+ return ret;
+ dev_warn(dev,
+ "hid-descr-addr device property NOT found, using ACPI _DSM fallback. Contact vendor for firmware update!\n");
+ hid_descriptor_address = ret;
+
+ /*
+ * No acpi_device_fix_up_power() needed: TPD0 has no _PS0, _PS3, _PSC
+ * or _PRx methods and follows I2C bus power.
+ */
+ return i2c_hid_core_probe(client, &i2c_hid_acpi_prp0001_ops,
+ hid_descriptor_address, 0);
+}
+
+static const struct of_device_id i2c_hid_acpi_prp0001_of_match[] = {
+ { .compatible = "hid-over-i2c" },
+ {},
+};
+MODULE_DEVICE_TABLE(of, i2c_hid_acpi_prp0001_of_match);
+
+static const struct i2c_device_id i2c_hid_acpi_prp0001_id[] = {
+ { .name = "hid-over-i2c" },
+ { }
+};
+MODULE_DEVICE_TABLE(i2c, i2c_hid_acpi_prp0001_id);
+
+static struct i2c_driver i2c_hid_acpi_prp0001_driver = {
+ .driver = {
+ .name = "i2c_hid_acpi_prp0001",
+ .pm = &i2c_hid_core_pm,
+ .probe_type = PROBE_PREFER_ASYNCHRONOUS,
+ /*
+ * of_match_ptr() makes this NULL when CONFIG_OF=n, but that's
+ * fine: the I2C id_table with "hid-over-i2c" handles matching
+ * via client->name (set by acpi_set_modalias() from the _DSD
+ * compatible property).
+ */
+ .of_match_table = of_match_ptr(i2c_hid_acpi_prp0001_of_match),
+ },
+
+ .probe = i2c_hid_acpi_prp0001_probe,
+ .remove = i2c_hid_core_remove,
+ .shutdown = i2c_hid_core_shutdown,
+ .id_table = i2c_hid_acpi_prp0001_id,
+};
+
+module_i2c_driver(i2c_hid_acpi_prp0001_driver);
+
+MODULE_DESCRIPTION("HID over I2C driver for PRP0001 devices missing hid-descr-addr");
+MODULE_AUTHOR("谢致邦 (XIE Zhibang) <Yeking@Red54.com>");
+MODULE_LICENSE("GPL");
diff --git a/drivers/hid/i2c-hid/i2c-hid-acpi.c b/drivers/hid/i2c-hid/i2c-hid-acpi.c
index abd700a101f46..13f977d6aab61 100644
--- a/drivers/hid/i2c-hid/i2c-hid-acpi.c
+++ b/drivers/hid/i2c-hid/i2c-hid-acpi.c
@@ -25,9 +25,9 @@
#include <linux/kernel.h>
#include <linux/module.h>
#include <linux/pm.h>
-#include <linux/uuid.h>
#include "i2c-hid.h"
+#include "i2c-hid-acpi.h"
struct i2c_hid_acpi {
struct i2chid_ops ops;
@@ -48,39 +48,11 @@ static const struct acpi_device_id i2c_hid_acpi_blacklist[] = {
{ }
};
-/* HID I²C Device: 3cdff6f7-4267-4555-ad05-b30a3d8938de */
-static guid_t i2c_hid_guid =
- GUID_INIT(0x3CDFF6F7, 0x4267, 0x4555,
- 0xAD, 0x05, 0xB3, 0x0A, 0x3D, 0x89, 0x38, 0xDE);
-
-static int i2c_hid_acpi_get_descriptor(struct i2c_hid_acpi *ihid_acpi)
-{
- struct acpi_device *adev = ihid_acpi->adev;
- acpi_handle handle = acpi_device_handle(adev);
- union acpi_object *obj;
- u16 hid_descriptor_address;
-
- if (acpi_match_device_ids(adev, i2c_hid_acpi_blacklist) == 0)
- return -ENODEV;
-
- obj = acpi_evaluate_dsm_typed(handle, &i2c_hid_guid, 1, 1, NULL,
- ACPI_TYPE_INTEGER);
- if (!obj) {
- acpi_handle_err(handle, "Error _DSM call to get HID descriptor address failed\n");
- return -ENODEV;
- }
-
- hid_descriptor_address = obj->integer.value;
- ACPI_FREE(obj);
-
- return hid_descriptor_address;
-}
-
static void i2c_hid_acpi_restore_sequence(struct i2chid_ops *ops)
{
struct i2c_hid_acpi *ihid_acpi = container_of(ops, struct i2c_hid_acpi, ops);
- i2c_hid_acpi_get_descriptor(ihid_acpi);
+ i2c_hid_acpi_get_descriptor(ihid_acpi->adev);
}
static void i2c_hid_acpi_shutdown_tail(struct i2chid_ops *ops)
@@ -93,24 +65,28 @@ static void i2c_hid_acpi_shutdown_tail(struct i2chid_ops *ops)
static int i2c_hid_acpi_probe(struct i2c_client *client)
{
struct device *dev = &client->dev;
+ struct acpi_device *adev = ACPI_COMPANION(dev);
struct i2c_hid_acpi *ihid_acpi;
u16 hid_descriptor_address;
int ret;
- ihid_acpi = devm_kzalloc(&client->dev, sizeof(*ihid_acpi), GFP_KERNEL);
+ if (acpi_match_device_ids(adev, i2c_hid_acpi_blacklist) == 0)
+ return -ENODEV;
+
+ ret = i2c_hid_acpi_get_descriptor(adev);
+ if (ret < 0)
+ return ret;
+ hid_descriptor_address = ret;
+
+ ihid_acpi = devm_kzalloc(dev, sizeof(*ihid_acpi), GFP_KERNEL);
if (!ihid_acpi)
return -ENOMEM;
- ihid_acpi->adev = ACPI_COMPANION(dev);
+ ihid_acpi->adev = adev;
ihid_acpi->ops.shutdown_tail = i2c_hid_acpi_shutdown_tail;
ihid_acpi->ops.restore_sequence = i2c_hid_acpi_restore_sequence;
- ret = i2c_hid_acpi_get_descriptor(ihid_acpi);
- if (ret < 0)
- return ret;
- hid_descriptor_address = ret;
-
- acpi_device_fix_up_power(ihid_acpi->adev);
+ acpi_device_fix_up_power(adev);
return i2c_hid_core_probe(client, &ihid_acpi->ops,
hid_descriptor_address, 0);
diff --git a/drivers/hid/i2c-hid/i2c-hid-acpi.h b/drivers/hid/i2c-hid/i2c-hid-acpi.h
new file mode 100644
index 0000000000000..0bbed1853313d
--- /dev/null
+++ b/drivers/hid/i2c-hid/i2c-hid-acpi.h
@@ -0,0 +1,33 @@
+/* SPDX-License-Identifier: GPL-2.0-only */
+
+#ifndef _I2C_HID_ACPI_H
+#define _I2C_HID_ACPI_H
+
+#include <linux/acpi.h>
+#include <linux/uuid.h>
+
+static inline int i2c_hid_acpi_get_descriptor(struct acpi_device *adev)
+{
+ /* HID I²C Device: 3cdff6f7-4267-4555-ad05-b30a3d8938de */
+ static const guid_t i2c_hid_guid =
+ GUID_INIT(0x3CDFF6F7, 0x4267, 0x4555,
+ 0xAD, 0x05, 0xB3, 0x0A, 0x3D, 0x89, 0x38, 0xDE);
+
+ acpi_handle handle = acpi_device_handle(adev);
+ union acpi_object *obj;
+ u16 addr;
+
+ obj = acpi_evaluate_dsm_typed(handle, &i2c_hid_guid,
+ 1, 1, NULL, ACPI_TYPE_INTEGER);
+ if (!obj) {
+ acpi_handle_err(handle,
+ "Error _DSM call to get HID descriptor address failed\n");
+ return -ENODEV;
+ }
+
+ addr = obj->integer.value;
+ ACPI_FREE(obj);
+ return addr;
+}
+
+#endif
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0841/1518] HID: synchronize input before cleaning up a failed probe
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (839 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0840/1518] HID: i2c-hid: Refactor _DSM helper and add i2c-hid-acpi-prp0001 driver Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0842/1518] HID: i2c-hid: Fix "(null)" output when reading report descriptor fails Greg Kroah-Hartman
` (157 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+9eebf5f6544c5e873858,
Yousef Alhouseen, Jiri Kosina, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yousef Alhouseen <alhouseenyousef@gmail.com>
[ Upstream commit 207853d46f7ef2e28042344a1468da8754c3ddbf ]
hid_device_io_start() allows reports to run concurrently with probe. If
the probe subsequently fails, __hid_device_probe() releases driver
resources and clears hdev->driver without first excluding those report
callbacks.
For example, a report may enter hidraw_report_event() while the failure
path frees the associated hidraw object, leading to a use-after-free when
the report takes the object's list lock.
Stop input before performing failed-probe cleanup. This reacquires
driver_input_lock and waits for any report callback already in progress.
Fixes: c849a6143bec ("HID: Separate struct hid_device's driver_lock into two locks.")
Reported-by: syzbot+9eebf5f6544c5e873858@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=9eebf5f6544c5e873858
Signed-off-by: Yousef Alhouseen <alhouseenyousef@gmail.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hid/hid-core.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/hid/hid-core.c b/drivers/hid/hid-core.c
index 55990d17c5669..78adb5a48a612 100644
--- a/drivers/hid/hid-core.c
+++ b/drivers/hid/hid-core.c
@@ -2852,6 +2852,8 @@ static int __hid_device_probe(struct hid_device *hdev, struct hid_driver *hdrv)
*/
if (ret) {
+ if (hdev->io_started)
+ hid_device_io_stop(hdev);
devres_release_group(&hdev->dev, hdev->devres_group_id);
hid_close_report(hdev);
hdev->driver = NULL;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0842/1518] HID: i2c-hid: Fix "(null)" output when reading report descriptor fails
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (840 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0841/1518] HID: synchronize input before cleaning up a failed probe Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0843/1518] HID: steam: Refactor and clean up report parsing Greg Kroah-Hartman
` (156 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ai Chao, Mario Limonciello (AMD),
Jiri Kosina, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ai Chao <aichao@kylinos.cn>
[ Upstream commit 8da0f0951deec9f0728ed2d9c54ded1c344b7542 ]
When i2c-hid fails to read the HID report descriptor during device
initialization, the error message prints as:
hid (null): reading report descriptor failed
The HID device name is set in hid_add_device() after calling
hdev->ll_driver->parse(), so when i2c_hid_parse() fails and calls
hid_err(), the device name has not been set yet, resulting in "(null)"
output.
Use dev_err(&client->dev, ...) instead of hid_err(hid, ...) because
the I2C client device is fully initialized with a proper name, providing
meaningful error messages for debugging.
Before: hid (null): reading report descriptor failed
After: i2c_hid i2c-TPD0001:00: reading report descriptor failed
Fixes: 4a200c3b9a40 ("HID: i2c-hid: introduce HID over i2c specification implementation")
Signed-off-by: Ai Chao <aichao@kylinos.cn>
Reviewed-by: Mario Limonciello (AMD) <superm1@kernel.org>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hid/i2c-hid/i2c-hid-core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/hid/i2c-hid/i2c-hid-core.c b/drivers/hid/i2c-hid/i2c-hid-core.c
index e0a302544cef4..6d407cbed1886 100644
--- a/drivers/hid/i2c-hid/i2c-hid-core.c
+++ b/drivers/hid/i2c-hid/i2c-hid-core.c
@@ -790,7 +790,7 @@ static int i2c_hid_parse(struct hid_device *hid)
ihid->hdesc.wReportDescRegister,
rdesc, rsize);
if (ret) {
- hid_err(hid, "reading report descriptor failed\n");
+ dev_err(&client->dev, "reading report descriptor failed\n");
goto out;
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0843/1518] HID: steam: Refactor and clean up report parsing
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (841 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0842/1518] HID: i2c-hid: Fix "(null)" output when reading report descriptor fails Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0844/1518] HID: steam: Rename some constants that got renamed upstream Greg Kroah-Hartman
` (155 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Vicki Pfau, Jiri Kosina, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vicki Pfau <vi@endrift.com>
[ Upstream commit 3d3c6ab5b07e16ed73070076e4b7f5130da2404f ]
This switches from a parsing style where each button or axis is parsed
individually out of a report using !!(byte & BIT(x)) style. This commit
switches it to a mostly unified approach of defining a list of individual
mappings in an array and passing it to a function that handles all of the
extraction. Theoretically this is more lines, but in practice it results in
(subjectively) cleaner code. Some exceptions still need to be made for
things like handling the lizard mode toggle key, but in general there's a
lot less manual code.
Signed-off-by: Vicki Pfau <vi@endrift.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Stable-dep-of: 33ff7b49c38b ("HID: steam: Reject short reads")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hid/hid-steam.c | 211 ++++++++++++++++++++++++----------------
1 file changed, 128 insertions(+), 83 deletions(-)
diff --git a/drivers/hid/hid-steam.c b/drivers/hid/hid-steam.c
index 197126d6e0810..349d4930451ab 100644
--- a/drivers/hid/hid-steam.c
+++ b/drivers/hid/hid-steam.c
@@ -43,6 +43,7 @@
#include <linux/rcupdate.h>
#include <linux/delay.h>
#include <linux/power_supply.h>
+#include <linux/unaligned.h>
#include "hid-ids.h"
MODULE_DESCRIPTION("HID driver for Valve Steam Controller");
@@ -1354,13 +1355,45 @@ static void steam_do_connect_event(struct steam_device *steam, bool connected)
* Clamp the values to 32767..-32767 so that the range is
* symmetrical and can be negated safely.
*/
-static inline s16 steam_le16(u8 *data)
+static inline s16 steam_le16(const u8 *data)
{
- s16 x = (s16) le16_to_cpup((__le16 *)data);
+ s16 x = (s16) get_unaligned_le16((const __le16 *)data);
return x == -32768 ? -32767 : x;
}
+struct steam_button_mapping {
+ int code;
+ u8 byte;
+ u8 bit;
+};
+
+struct steam_axis_mapping {
+ int code;
+ s8 sign;
+ u8 byte;
+};
+
+static void steam_map_buttons(struct input_dev *input,
+ const struct steam_button_mapping *mappings, const u8 *data)
+{
+ const struct steam_button_mapping *mapping;
+
+ for (mapping = mappings; mapping->code; mapping++)
+ input_report_key(input, mapping->code,
+ data[mapping->byte] & BIT(mapping->bit));
+}
+
+static void steam_map_axes(struct input_dev *input,
+ const struct steam_axis_mapping *mappings, const u8 *data)
+{
+ const struct steam_axis_mapping *mapping;
+
+ for (mapping = mappings; mapping->sign; mapping++)
+ input_report_abs(input, mapping->code,
+ mapping->sign * steam_le16(&data[mapping->byte]));
+}
+
/*
* The size for this message payload is 60.
* The known values are:
@@ -1427,18 +1460,42 @@ static inline s16 steam_le16(u8 *data)
* 10.7 | -- | lpad_and_joy
*/
+static const struct steam_button_mapping steam_controller_button_mappings[] = {
+ { BTN_TR2, 8, 0 },
+ { BTN_TL2, 8, 1 },
+ { BTN_TR, 8, 2 },
+ { BTN_TL, 8, 3 },
+ { BTN_Y, 8, 4 },
+ { BTN_B, 8, 5 },
+ { BTN_X, 8, 6 },
+ { BTN_A, 8, 7 },
+ { BTN_SELECT, 9, 4 },
+ { BTN_MODE, 9, 5 },
+ { BTN_START, 9, 6 },
+ { BTN_GRIPL, 9, 7 },
+ { BTN_GRIPR, 10, 0 },
+ { BTN_THUMBR, 10, 2 },
+ { BTN_THUMBL, 10, 6 },
+ { BTN_THUMB2, 10, 4 },
+ { BTN_DPAD_UP, 9, 0 },
+ { BTN_DPAD_RIGHT, 9, 1 },
+ { BTN_DPAD_LEFT, 9, 2 },
+ { BTN_DPAD_DOWN, 9, 3 },
+ { /* sentinel */ },
+};
+
+static const struct steam_axis_mapping steam_controller_axis_mappings[] = {
+ { ABS_RX, 1, 20 },
+ { ABS_RY, -1, 22 },
+ { /* sentinel */ },
+};
+
static void steam_do_input_event(struct steam_device *steam,
struct input_dev *input, u8 *data)
{
- /* 24 bits of buttons */
- u8 b8, b9, b10;
s16 x, y;
bool lpad_touched, lpad_and_joy;
- b8 = data[8];
- b9 = data[9];
- b10 = data[10];
-
input_report_abs(input, ABS_HAT2Y, data[11]);
input_report_abs(input, ABS_HAT2X, data[12]);
@@ -1450,8 +1507,8 @@ static void steam_do_input_event(struct steam_device *steam,
* joystick values.
* (lpad_touched || lpad_and_joy) tells if the lpad is really touched.
*/
- lpad_touched = b10 & BIT(3);
- lpad_and_joy = b10 & BIT(7);
+ lpad_touched = data[10] & BIT(3);
+ lpad_and_joy = data[10] & BIT(7);
x = steam_le16(data + 16);
y = -steam_le16(data + 18);
@@ -1467,31 +1524,10 @@ static void steam_do_input_event(struct steam_device *steam,
input_report_abs(input, ABS_HAT0X, 0);
input_report_abs(input, ABS_HAT0Y, 0);
}
+ input_report_key(input, BTN_THUMB, lpad_touched || lpad_and_joy);
- input_report_abs(input, ABS_RX, steam_le16(data + 20));
- input_report_abs(input, ABS_RY, -steam_le16(data + 22));
-
- input_event(input, EV_KEY, BTN_TR2, !!(b8 & BIT(0)));
- input_event(input, EV_KEY, BTN_TL2, !!(b8 & BIT(1)));
- input_event(input, EV_KEY, BTN_TR, !!(b8 & BIT(2)));
- input_event(input, EV_KEY, BTN_TL, !!(b8 & BIT(3)));
- input_event(input, EV_KEY, BTN_Y, !!(b8 & BIT(4)));
- input_event(input, EV_KEY, BTN_B, !!(b8 & BIT(5)));
- input_event(input, EV_KEY, BTN_X, !!(b8 & BIT(6)));
- input_event(input, EV_KEY, BTN_A, !!(b8 & BIT(7)));
- input_event(input, EV_KEY, BTN_SELECT, !!(b9 & BIT(4)));
- input_event(input, EV_KEY, BTN_MODE, !!(b9 & BIT(5)));
- input_event(input, EV_KEY, BTN_START, !!(b9 & BIT(6)));
- input_event(input, EV_KEY, BTN_GRIPL, !!(b9 & BIT(7)));
- input_event(input, EV_KEY, BTN_GRIPR, !!(b10 & BIT(0)));
- input_event(input, EV_KEY, BTN_THUMBR, !!(b10 & BIT(2)));
- input_event(input, EV_KEY, BTN_THUMBL, !!(b10 & BIT(6)));
- input_event(input, EV_KEY, BTN_THUMB, lpad_touched || lpad_and_joy);
- input_event(input, EV_KEY, BTN_THUMB2, !!(b10 & BIT(4)));
- input_event(input, EV_KEY, BTN_DPAD_UP, !!(b9 & BIT(0)));
- input_event(input, EV_KEY, BTN_DPAD_RIGHT, !!(b9 & BIT(1)));
- input_event(input, EV_KEY, BTN_DPAD_LEFT, !!(b9 & BIT(2)));
- input_event(input, EV_KEY, BTN_DPAD_DOWN, !!(b9 & BIT(3)));
+ steam_map_buttons(input, steam_controller_button_mappings, data);
+ steam_map_axes(input, steam_controller_axis_mappings, data);
input_sync(input);
}
@@ -1594,23 +1630,67 @@ static void steam_do_input_event(struct steam_device *steam,
* 15.6 | -- | unknown
* 15.7 | -- | unknown
*/
+
+static const struct steam_button_mapping steam_deck_button_mappings[] = {
+ { BTN_TR2, 8, 0 },
+ { BTN_TL2, 8, 1 },
+ { BTN_TR, 8, 2 },
+ { BTN_TL, 8, 3 },
+ { BTN_Y, 8, 4 },
+ { BTN_B, 8, 5 },
+ { BTN_X, 8, 6 },
+ { BTN_A, 8, 7 },
+ { BTN_SELECT, 9, 4 },
+ { BTN_MODE, 9, 5 },
+ { BTN_START, 9, 6 },
+ { BTN_GRIPL2, 9, 7 },
+ { BTN_GRIPR2, 10, 0 },
+ { BTN_THUMBL, 10, 6 },
+ { BTN_THUMBR, 11, 2 },
+ { BTN_DPAD_UP, 9, 0 },
+ { BTN_DPAD_RIGHT, 9, 1 },
+ { BTN_DPAD_LEFT, 9, 2 },
+ { BTN_DPAD_DOWN, 9, 3 },
+ { BTN_THUMB, 10, 1 },
+ { BTN_THUMB2, 10, 2 },
+ { BTN_GRIPL, 13, 1 },
+ { BTN_GRIPR, 13, 2 },
+ { BTN_BASE, 14, 2 },
+ { /* sentinel */ },
+};
+
+static const struct steam_axis_mapping steam_deck_axis_mappings[] = {
+ { ABS_X, 1, 48 },
+ { ABS_Y, -1, 50 },
+ { ABS_RX, 1, 52 },
+ { ABS_RY, -1, 54 },
+ { ABS_HAT2Y, 1, 44 },
+ { ABS_HAT2X, 1, 46 },
+ { /* sentinel */ },
+};
+
+static const struct steam_axis_mapping steam_deck_imu_mappings[] = {
+ { ABS_X, 1, 24 },
+ { ABS_Z, -1, 26 },
+ { ABS_Y, 1, 28 },
+ { ABS_RX, 1, 30 },
+ { ABS_RZ, -1, 32 },
+ { ABS_RY, 1, 34 },
+ { /* sentinel */ },
+};
+
static void steam_do_deck_input_event(struct steam_device *steam,
struct input_dev *input, u8 *data)
{
- u8 b8, b9, b10, b11, b13, b14;
+ bool start_pressed;
bool lpad_touched, rpad_touched;
- b8 = data[8];
- b9 = data[9];
- b10 = data[10];
- b11 = data[11];
- b13 = data[13];
- b14 = data[14];
+ start_pressed = data[9] & BIT(6);
- if (!(b9 & BIT(6)) && steam->did_mode_switch) {
+ if (!start_pressed && steam->did_mode_switch) {
steam->did_mode_switch = false;
cancel_delayed_work(&steam->mode_switch);
- } else if (!steam->client_opened && (b9 & BIT(6)) && !steam->did_mode_switch) {
+ } else if (!steam->client_opened && start_pressed && !steam->did_mode_switch) {
steam->did_mode_switch = true;
schedule_delayed_work(&steam->mode_switch, 45 * HZ / 100);
}
@@ -1618,8 +1698,8 @@ static void steam_do_deck_input_event(struct steam_device *steam,
if (!steam->gamepad_mode && lizard_mode)
return;
- lpad_touched = b10 & BIT(3);
- rpad_touched = b10 & BIT(4);
+ lpad_touched = data[10] & BIT(3);
+ rpad_touched = data[10] & BIT(4);
if (lpad_touched) {
input_report_abs(input, ABS_HAT0X, steam_le16(data + 16));
@@ -1637,38 +1717,8 @@ static void steam_do_deck_input_event(struct steam_device *steam,
input_report_abs(input, ABS_HAT1Y, 0);
}
- input_report_abs(input, ABS_X, steam_le16(data + 48));
- input_report_abs(input, ABS_Y, -steam_le16(data + 50));
- input_report_abs(input, ABS_RX, steam_le16(data + 52));
- input_report_abs(input, ABS_RY, -steam_le16(data + 54));
-
- input_report_abs(input, ABS_HAT2Y, steam_le16(data + 44));
- input_report_abs(input, ABS_HAT2X, steam_le16(data + 46));
-
- input_event(input, EV_KEY, BTN_TR2, !!(b8 & BIT(0)));
- input_event(input, EV_KEY, BTN_TL2, !!(b8 & BIT(1)));
- input_event(input, EV_KEY, BTN_TR, !!(b8 & BIT(2)));
- input_event(input, EV_KEY, BTN_TL, !!(b8 & BIT(3)));
- input_event(input, EV_KEY, BTN_Y, !!(b8 & BIT(4)));
- input_event(input, EV_KEY, BTN_B, !!(b8 & BIT(5)));
- input_event(input, EV_KEY, BTN_X, !!(b8 & BIT(6)));
- input_event(input, EV_KEY, BTN_A, !!(b8 & BIT(7)));
- input_event(input, EV_KEY, BTN_SELECT, !!(b9 & BIT(4)));
- input_event(input, EV_KEY, BTN_MODE, !!(b9 & BIT(5)));
- input_event(input, EV_KEY, BTN_START, !!(b9 & BIT(6)));
- input_event(input, EV_KEY, BTN_GRIPL2, !!(b9 & BIT(7)));
- input_event(input, EV_KEY, BTN_GRIPR2, !!(b10 & BIT(0)));
- input_event(input, EV_KEY, BTN_THUMBL, !!(b10 & BIT(6)));
- input_event(input, EV_KEY, BTN_THUMBR, !!(b11 & BIT(2)));
- input_event(input, EV_KEY, BTN_DPAD_UP, !!(b9 & BIT(0)));
- input_event(input, EV_KEY, BTN_DPAD_RIGHT, !!(b9 & BIT(1)));
- input_event(input, EV_KEY, BTN_DPAD_LEFT, !!(b9 & BIT(2)));
- input_event(input, EV_KEY, BTN_DPAD_DOWN, !!(b9 & BIT(3)));
- input_event(input, EV_KEY, BTN_THUMB, !!(b10 & BIT(1)));
- input_event(input, EV_KEY, BTN_THUMB2, !!(b10 & BIT(2)));
- input_event(input, EV_KEY, BTN_GRIPL, !!(b13 & BIT(1)));
- input_event(input, EV_KEY, BTN_GRIPR, !!(b13 & BIT(2)));
- input_event(input, EV_KEY, BTN_BASE, !!(b14 & BIT(2)));
+ steam_map_buttons(input, steam_deck_button_mappings, data);
+ steam_map_axes(input, steam_deck_axis_mappings, data);
input_sync(input);
}
@@ -1689,12 +1739,7 @@ static void steam_do_deck_sensors_event(struct steam_device *steam,
return;
input_event(sensors, EV_MSC, MSC_TIMESTAMP, steam->sensor_timestamp_us);
- input_report_abs(sensors, ABS_X, steam_le16(data + 24));
- input_report_abs(sensors, ABS_Z, -steam_le16(data + 26));
- input_report_abs(sensors, ABS_Y, steam_le16(data + 28));
- input_report_abs(sensors, ABS_RX, steam_le16(data + 30));
- input_report_abs(sensors, ABS_RZ, -steam_le16(data + 32));
- input_report_abs(sensors, ABS_RY, steam_le16(data + 34));
+ steam_map_axes(sensors, steam_deck_imu_mappings, data);
input_sync(sensors);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0844/1518] HID: steam: Rename some constants that got renamed upstream
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (842 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0843/1518] HID: steam: Refactor and clean up report parsing Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0845/1518] HID: steam: Add support for sensor events on the Steam Controller (2015) Greg Kroah-Hartman
` (154 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Vicki Pfau, Jiri Kosina, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vicki Pfau <vi@endrift.com>
[ Upstream commit 6afec3c8fff2af0050ca802c9b731303ce0e2b8e ]
SETTING_MOUSE_POINTER_ENABLED was renamed to SETTING_LIZARD_MODE upstream.
SETTING_GYRO_MODE was renamed to SETTING_IMU_MODE in an older commit, but
the associated enum was overlooked.
Signed-off-by: Vicki Pfau <vi@endrift.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Stable-dep-of: 33ff7b49c38b ("HID: steam: Reject short reads")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hid/hid-steam.c | 16 ++++++++--------
1 file changed, 8 insertions(+), 8 deletions(-)
diff --git a/drivers/hid/hid-steam.c b/drivers/hid/hid-steam.c
index 349d4930451ab..3eff6d0b13b2c 100644
--- a/drivers/hid/hid-steam.c
+++ b/drivers/hid/hid-steam.c
@@ -150,7 +150,7 @@ enum {
SETTING_USB_DEBUG_MODE,
SETTING_LEFT_TRACKPAD_MODE,
SETTING_RIGHT_TRACKPAD_MODE,
- SETTING_MOUSE_POINTER_ENABLED,
+ SETTING_LIZARD_MODE,
/* 10 */
SETTING_DPAD_DEADZONE,
@@ -260,14 +260,14 @@ enum {
ATTRIB_STR_UNIT_SERIAL,
};
-/* Values for GYRO_MODE (bitmask) */
+/* Values for IMU_MODE (bitmask) */
enum {
- SETTING_GYRO_MODE_OFF = 0,
- SETTING_GYRO_MODE_STEERING = BIT(0),
- SETTING_GYRO_MODE_TILT = BIT(1),
- SETTING_GYRO_MODE_SEND_ORIENTATION = BIT(2),
- SETTING_GYRO_MODE_SEND_RAW_ACCEL = BIT(3),
- SETTING_GYRO_MODE_SEND_RAW_GYRO = BIT(4),
+ SETTING_IMU_MODE_OFF = 0,
+ SETTING_IMU_MODE_STEERING = BIT(0),
+ SETTING_IMU_MODE_TILT = BIT(1),
+ SETTING_IMU_MODE_SEND_ORIENTATION = BIT(2),
+ SETTING_IMU_MODE_SEND_RAW_ACCEL = BIT(3),
+ SETTING_IMU_MODE_SEND_RAW_GYRO = BIT(4),
};
/* Trackpad modes */
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0845/1518] HID: steam: Add support for sensor events on the Steam Controller (2015)
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (843 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0844/1518] HID: steam: Rename some constants that got renamed upstream Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0846/1518] HID: steam: Improve logging and other cleanup Greg Kroah-Hartman
` (153 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Vicki Pfau, Jiri Kosina, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vicki Pfau <vi@endrift.com>
[ Upstream commit 2eb7cf02b52156ebd19c7c14a7f5228c6adfcf97 ]
Sensor support was added for the Steam Deck previously, but Steam
Controller sensor events were never added. This adds that missing support,
bringing Steam Controller support much closer to feature parity with things
like SDL and Steam itself.
Signed-off-by: Vicki Pfau <vi@endrift.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Stable-dep-of: 33ff7b49c38b ("HID: steam: Reject short reads")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hid/hid-steam.c | 214 ++++++++++++++++++++++++++++++++--------
1 file changed, 175 insertions(+), 39 deletions(-)
diff --git a/drivers/hid/hid-steam.c b/drivers/hid/hid-steam.c
index 3eff6d0b13b2c..efecbc9d8e014 100644
--- a/drivers/hid/hid-steam.c
+++ b/drivers/hid/hid-steam.c
@@ -69,13 +69,14 @@ static LIST_HEAD(steam_devices);
/* Joystick runs are about 5 mm and 32768 units */
#define STEAM_DECK_JOYSTICK_RESOLUTION 6553
/* Accelerometer has 16 bit resolution and a range of +/- 2g */
-#define STEAM_DECK_ACCEL_RES_PER_G 16384
-#define STEAM_DECK_ACCEL_RANGE 32768
+#define STEAM_ACCEL_RES_PER_G 16384
+#define STEAM_ACCEL_RANGE 32768
+#define STEAM_ACCEL_FUZZ 128
#define STEAM_DECK_ACCEL_FUZZ 32
/* Gyroscope has 16 bit resolution and a range of +/- 2000 dps */
-#define STEAM_DECK_GYRO_RES_PER_DPS 16
-#define STEAM_DECK_GYRO_RANGE 32768
-#define STEAM_DECK_GYRO_FUZZ 1
+#define STEAM_GYRO_RES_PER_DPS 16
+#define STEAM_GYRO_RANGE 32768
+#define STEAM_GYRO_FUZZ 0
#define STEAM_PAD_FUZZ 256
@@ -254,6 +255,31 @@ enum
ID_CONTROLLER_DECK_STATE = 9
};
+/* Read-only attributes */
+enum {
+ ATTRIB_UNIQUE_ID, // deprecated
+ ATTRIB_PRODUCT_ID,
+ ATTRIB_PRODUCT_REVISON, // deprecated
+ ATTRIB_CAPABILITIES = ATTRIB_PRODUCT_REVISON, // intentional aliasing
+ ATTRIB_FIRMWARE_VERSION, // deprecated
+ ATTRIB_FIRMWARE_BUILD_TIME,
+ ATTRIB_RADIO_FIRMWARE_BUILD_TIME,
+ ATTRIB_RADIO_DEVICE_ID0,
+ ATTRIB_RADIO_DEVICE_ID1,
+ ATTRIB_DONGLE_FIRMWARE_BUILD_TIME,
+ ATTRIB_HW_ID, // AKA BOARD_REVISION,
+ ATTRIB_BOOTLOADER_BUILD_TIME,
+ ATTRIB_CONNECTION_INTERVAL_IN_US,
+ ATTRIB_SECONDARY_FIRMWARE_BUILD_TIME,
+ ATTRIB_SECONDARY_BOOTLOADER_BUILD_TIME,
+ ATTRIB_SECONDARY_HW_ID, // AKA BOARD_REVISION,
+ ATTRIB_STREAMING,
+ ATTRIB_TRACKPAD_ID,
+ ATTRIB_SECONDARY_TRACKPAD_ID,
+
+ ATTRIB_COUNT
+};
+
/* String attribute identifiers */
enum {
ATTRIB_STR_BOARD_SERIAL,
@@ -283,6 +309,11 @@ enum {
TRACKPAD_GESTURE_KEYBOARD,
};
+struct steam_controller_attribute {
+ unsigned char tag;
+ __le32 value;
+} __packed;
+
/* Pad identifiers for the deck */
#define STEAM_PAD_LEFT 0
#define STEAM_PAD_RIGHT 1
@@ -314,6 +345,7 @@ struct steam_device {
u16 rumble_left;
u16 rumble_right;
unsigned int sensor_timestamp_us;
+ unsigned int sensor_update_rate_us;
struct work_struct unregister_work;
};
@@ -467,6 +499,38 @@ static int steam_get_serial(struct steam_device *steam)
return ret;
}
+static int steam_get_attributes(struct steam_device *steam)
+{
+ int ret = 0;
+ u8 cmd[] = {ID_GET_ATTRIBUTES_VALUES, 0};
+ u8 reply[64] = {};
+ u8 size;
+ int i;
+ struct steam_controller_attribute *attr;
+
+ guard(mutex)(&steam->report_mutex);
+ ret = steam_send_report(steam, cmd, sizeof(cmd));
+ if (ret < 0)
+ return ret;
+ ret = steam_recv_report(steam, reply, sizeof(reply));
+ if (ret < 0)
+ return ret;
+ if (reply[0] != ID_GET_ATTRIBUTES_VALUES || reply[1] < 2)
+ return -EIO;
+
+ size = min(reply[1], sizeof(reply) - 2);
+ for (i = 0; i + sizeof(*attr) <= size; i += sizeof(*attr)) {
+ attr = (struct steam_controller_attribute *)&reply[i + 2];
+ if (attr->tag == ATTRIB_CONNECTION_INTERVAL_IN_US) {
+ steam->sensor_update_rate_us = get_unaligned_le32(&attr->value);
+ hid_dbg(steam->hdev, "Sensor update rate: %uus\n",
+ steam->sensor_update_rate_us);
+ }
+ }
+
+ return 0;
+}
+
/*
* This command requests the wireless adaptor to post an event
* with the connection status. Useful if this driver is loaded when
@@ -625,6 +689,42 @@ static void steam_input_close(struct input_dev *dev)
}
}
+static int steam_sensor_open(struct input_dev *dev)
+{
+ struct steam_device *steam = input_get_drvdata(dev);
+ unsigned long flags;
+ bool client_opened;
+
+ spin_lock_irqsave(&steam->lock, flags);
+ client_opened = steam->client_opened;
+ spin_unlock_irqrestore(&steam->lock, flags);
+ if (client_opened)
+ return 0;
+
+ guard(mutex)(&steam->report_mutex);
+ steam_write_settings(steam, SETTING_IMU_MODE,
+ SETTING_IMU_MODE_SEND_RAW_ACCEL | SETTING_IMU_MODE_SEND_RAW_GYRO,
+ 0);
+
+ return 0;
+}
+
+static void steam_sensor_close(struct input_dev *dev)
+{
+ struct steam_device *steam = input_get_drvdata(dev);
+ unsigned long flags;
+ bool client_opened;
+
+ spin_lock_irqsave(&steam->lock, flags);
+ client_opened = steam->client_opened;
+ spin_unlock_irqrestore(&steam->lock, flags);
+ if (client_opened)
+ return;
+
+ guard(mutex)(&steam->report_mutex);
+ steam_write_settings(steam, SETTING_IMU_MODE, 0, 0);
+}
+
static enum power_supply_property steam_battery_props[] = {
POWER_SUPPLY_PROP_PRESENT,
POWER_SUPPLY_PROP_SCOPE,
@@ -838,9 +938,6 @@ static int steam_sensors_register(struct steam_device *steam)
struct input_dev *sensors;
int ret;
- if (!(steam->quirks & STEAM_QUIRK_DECK))
- return 0;
-
rcu_read_lock();
sensors = rcu_dereference(steam->sensors);
rcu_read_unlock();
@@ -855,8 +952,14 @@ static int steam_sensors_register(struct steam_device *steam)
input_set_drvdata(sensors, steam);
sensors->dev.parent = &hdev->dev;
+ if (!(steam->quirks & STEAM_QUIRK_DECK)) {
+ sensors->open = steam_sensor_open;
+ sensors->close = steam_sensor_close;
+ }
- sensors->name = "Steam Deck Motion Sensors";
+ sensors->name = steam->quirks & STEAM_QUIRK_DECK ?
+ "Steam Deck Motion Sensors" :
+ "Steam Controller Motion Sensors";
sensors->phys = hdev->phys;
sensors->uniq = steam->serial_no;
sensors->id.bustype = hdev->bus;
@@ -868,25 +971,34 @@ static int steam_sensors_register(struct steam_device *steam)
__set_bit(EV_MSC, sensors->evbit);
__set_bit(MSC_TIMESTAMP, sensors->mscbit);
- input_set_abs_params(sensors, ABS_X, -STEAM_DECK_ACCEL_RANGE,
- STEAM_DECK_ACCEL_RANGE, STEAM_DECK_ACCEL_FUZZ, 0);
- input_set_abs_params(sensors, ABS_Y, -STEAM_DECK_ACCEL_RANGE,
- STEAM_DECK_ACCEL_RANGE, STEAM_DECK_ACCEL_FUZZ, 0);
- input_set_abs_params(sensors, ABS_Z, -STEAM_DECK_ACCEL_RANGE,
- STEAM_DECK_ACCEL_RANGE, STEAM_DECK_ACCEL_FUZZ, 0);
- input_abs_set_res(sensors, ABS_X, STEAM_DECK_ACCEL_RES_PER_G);
- input_abs_set_res(sensors, ABS_Y, STEAM_DECK_ACCEL_RES_PER_G);
- input_abs_set_res(sensors, ABS_Z, STEAM_DECK_ACCEL_RES_PER_G);
-
- input_set_abs_params(sensors, ABS_RX, -STEAM_DECK_GYRO_RANGE,
- STEAM_DECK_GYRO_RANGE, STEAM_DECK_GYRO_FUZZ, 0);
- input_set_abs_params(sensors, ABS_RY, -STEAM_DECK_GYRO_RANGE,
- STEAM_DECK_GYRO_RANGE, STEAM_DECK_GYRO_FUZZ, 0);
- input_set_abs_params(sensors, ABS_RZ, -STEAM_DECK_GYRO_RANGE,
- STEAM_DECK_GYRO_RANGE, STEAM_DECK_GYRO_FUZZ, 0);
- input_abs_set_res(sensors, ABS_RX, STEAM_DECK_GYRO_RES_PER_DPS);
- input_abs_set_res(sensors, ABS_RY, STEAM_DECK_GYRO_RES_PER_DPS);
- input_abs_set_res(sensors, ABS_RZ, STEAM_DECK_GYRO_RES_PER_DPS);
+ if (steam->quirks & STEAM_QUIRK_DECK) {
+ input_set_abs_params(sensors, ABS_X, -STEAM_ACCEL_RANGE,
+ STEAM_ACCEL_RANGE, STEAM_DECK_ACCEL_FUZZ, 0);
+ input_set_abs_params(sensors, ABS_Y, -STEAM_ACCEL_RANGE,
+ STEAM_ACCEL_RANGE, STEAM_DECK_ACCEL_FUZZ, 0);
+ input_set_abs_params(sensors, ABS_Z, -STEAM_ACCEL_RANGE,
+ STEAM_ACCEL_RANGE, STEAM_DECK_ACCEL_FUZZ, 0);
+ } else {
+ input_set_abs_params(sensors, ABS_X, -STEAM_ACCEL_RANGE,
+ STEAM_ACCEL_RANGE, STEAM_ACCEL_FUZZ, 0);
+ input_set_abs_params(sensors, ABS_Y, -STEAM_ACCEL_RANGE,
+ STEAM_ACCEL_RANGE, STEAM_ACCEL_FUZZ, 0);
+ input_set_abs_params(sensors, ABS_Z, -STEAM_ACCEL_RANGE,
+ STEAM_ACCEL_RANGE, STEAM_ACCEL_FUZZ, 0);
+ }
+ input_abs_set_res(sensors, ABS_X, STEAM_ACCEL_RES_PER_G);
+ input_abs_set_res(sensors, ABS_Y, STEAM_ACCEL_RES_PER_G);
+ input_abs_set_res(sensors, ABS_Z, STEAM_ACCEL_RES_PER_G);
+
+ input_set_abs_params(sensors, ABS_RX, -STEAM_GYRO_RANGE,
+ STEAM_GYRO_RANGE, STEAM_GYRO_FUZZ, 0);
+ input_set_abs_params(sensors, ABS_RY, -STEAM_GYRO_RANGE,
+ STEAM_GYRO_RANGE, STEAM_GYRO_FUZZ, 0);
+ input_set_abs_params(sensors, ABS_RZ, -STEAM_GYRO_RANGE,
+ STEAM_GYRO_RANGE, STEAM_GYRO_FUZZ, 0);
+ input_abs_set_res(sensors, ABS_RX, STEAM_GYRO_RES_PER_DPS);
+ input_abs_set_res(sensors, ABS_RY, STEAM_GYRO_RES_PER_DPS);
+ input_abs_set_res(sensors, ABS_RZ, STEAM_GYRO_RES_PER_DPS);
ret = input_register_device(sensors);
if (ret)
@@ -917,9 +1029,6 @@ static void steam_sensors_unregister(struct steam_device *steam)
{
struct input_dev *sensors;
- if (!(steam->quirks & STEAM_QUIRK_DECK))
- return;
-
rcu_read_lock();
sensors = rcu_dereference(steam->sensors);
rcu_read_unlock();
@@ -967,6 +1076,12 @@ static int steam_register(struct steam_device *steam)
strscpy(steam->serial_no, "XXXXXXXXXX",
sizeof(steam->serial_no));
+ ret = steam_get_attributes(steam);
+ if (ret < 0)
+ hid_err(steam->hdev,
+ "%s:steam_get_attributes failed with error %d\n",
+ __func__, ret);
+
hid_info(steam->hdev, "Steam Controller '%s' connected",
steam->serial_no);
@@ -1245,6 +1360,10 @@ static int steam_probe(struct hid_device *hdev,
INIT_LIST_HEAD(&steam->list);
INIT_WORK(&steam->rumble_work, steam_haptic_rumble_cb);
steam->sensor_timestamp_us = 0;
+ if (steam->quirks & STEAM_QUIRK_DECK)
+ steam->sensor_update_rate_us = 4000;
+ else
+ steam->sensor_update_rate_us = 9000;
INIT_WORK(&steam->unregister_work, steam_work_unregister_cb);
/*
@@ -1490,6 +1609,16 @@ static const struct steam_axis_mapping steam_controller_axis_mappings[] = {
{ /* sentinel */ },
};
+static const struct steam_axis_mapping steam_controller_imu_mappings[] = {
+ { ABS_X, 1, 28 },
+ { ABS_Z, -1, 30 },
+ { ABS_Y, 1, 32 },
+ { ABS_RX, 1, 34 },
+ { ABS_RZ, 1, 36 },
+ { ABS_RY, 1, 38 },
+ { /* sentinel */ },
+};
+
static void steam_do_input_event(struct steam_device *steam,
struct input_dev *input, u8 *data)
{
@@ -1532,6 +1661,17 @@ static void steam_do_input_event(struct steam_device *steam,
input_sync(input);
}
+static void steam_do_sensors_event(struct steam_device *steam,
+ struct input_dev *sensors, u8 *data)
+{
+ steam->sensor_timestamp_us += steam->sensor_update_rate_us;
+
+ input_event(sensors, EV_MSC, MSC_TIMESTAMP, steam->sensor_timestamp_us);
+ steam_map_axes(sensors, steam_controller_imu_mappings, data);
+
+ input_sync(sensors);
+}
+
/*
* The size for this message payload is 56.
* The known values are:
@@ -1726,14 +1866,7 @@ static void steam_do_deck_input_event(struct steam_device *steam,
static void steam_do_deck_sensors_event(struct steam_device *steam,
struct input_dev *sensors, u8 *data)
{
- /*
- * The deck input report is received every 4 ms on average,
- * with a jitter of +/- 4 ms even though the USB descriptor claims
- * that it uses 1 kHz.
- * Since the HID report does not include a sensor timestamp,
- * use a fixed increment here.
- */
- steam->sensor_timestamp_us += 4000;
+ steam->sensor_timestamp_us += steam->sensor_update_rate_us;
if (!steam->gamepad_mode && lizard_mode)
return;
@@ -1818,6 +1951,9 @@ static int steam_raw_event(struct hid_device *hdev,
input = rcu_dereference(steam->input);
if (likely(input))
steam_do_input_event(steam, input, data);
+ sensors = rcu_dereference(steam->sensors);
+ if (likely(sensors))
+ steam_do_sensors_event(steam, sensors, data);
rcu_read_unlock();
break;
case ID_CONTROLLER_DECK_STATE:
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0846/1518] HID: steam: Improve logging and other cleanup
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (844 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0845/1518] HID: steam: Add support for sensor events on the Steam Controller (2015) Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0847/1518] HID: steam: Reject short reads Greg Kroah-Hartman
` (152 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Vicki Pfau, Jiri Kosina, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vicki Pfau <vi@endrift.com>
[ Upstream commit de435b770cd9492b803346b84df69fe345b845f2 ]
Adds more logging as appropriate, reindents an enum to match surrounding
style, as well as cleaning up some places where we can use guard() instead
of doing locking and unlocking manually.
Signed-off-by: Vicki Pfau <vi@endrift.com>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Stable-dep-of: 33ff7b49c38b ("HID: steam: Reject short reads")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hid/hid-steam.c | 56 ++++++++++++++++++++++++-----------------
1 file changed, 33 insertions(+), 23 deletions(-)
diff --git a/drivers/hid/hid-steam.c b/drivers/hid/hid-steam.c
index efecbc9d8e014..3383a62646f9e 100644
--- a/drivers/hid/hid-steam.c
+++ b/drivers/hid/hid-steam.c
@@ -245,14 +245,14 @@ enum {
/* Input report identifiers */
enum
{
- ID_CONTROLLER_STATE = 1,
- ID_CONTROLLER_DEBUG = 2,
- ID_CONTROLLER_WIRELESS = 3,
- ID_CONTROLLER_STATUS = 4,
- ID_CONTROLLER_DEBUG2 = 5,
- ID_CONTROLLER_SECONDARY_STATE = 6,
- ID_CONTROLLER_BLE_STATE = 7,
- ID_CONTROLLER_DECK_STATE = 9
+ ID_CONTROLLER_STATE = 1,
+ ID_CONTROLLER_DEBUG = 2,
+ ID_CONTROLLER_WIRELESS = 3,
+ ID_CONTROLLER_STATUS = 4,
+ ID_CONTROLLER_DEBUG2 = 5,
+ ID_CONTROLLER_SECONDARY_STATE = 6,
+ ID_CONTROLLER_BLE_STATE = 7,
+ ID_CONTROLLER_DECK_STATE = 9,
};
/* Read-only attributes */
@@ -378,9 +378,16 @@ static int steam_recv_report(struct steam_device *steam,
ret = hid_hw_raw_request(steam->hdev, 0x00,
buf, hid_report_len(r) + 1,
HID_FEATURE_REPORT, HID_REQ_GET_REPORT);
- if (ret > 0)
- memcpy(data, buf + 1, min(size, ret - 1));
+ if (ret > 0) {
+ ret = min(size, ret - 1);
+ memcpy(data, buf + 1, ret);
+ }
kfree(buf);
+
+ if (ret < 0)
+ hid_err(steam->hdev, "%s: error %d\n", __func__, ret);
+ else
+ hid_dbg(steam->hdev, "Received report %*ph\n", ret, data);
return ret;
}
@@ -408,6 +415,8 @@ static int steam_send_report(struct steam_device *steam,
/* The report ID is always 0 */
memcpy(buf + 1, cmd, size);
+ hid_dbg(steam->hdev, "Sending report %*ph\n", size, cmd);
+
/*
* Sometimes the wireless controller fails with EPIPE
* when sending a feature report.
@@ -480,22 +489,21 @@ static int steam_get_serial(struct steam_device *steam)
u8 cmd[] = {ID_GET_STRING_ATTRIBUTE, sizeof(steam->serial_no), ATTRIB_STR_UNIT_SERIAL};
u8 reply[3 + STEAM_SERIAL_LEN + 1];
- mutex_lock(&steam->report_mutex);
+ guard(mutex)(&steam->report_mutex);
ret = steam_send_report(steam, cmd, sizeof(cmd));
if (ret < 0)
- goto out;
+ return ret;
ret = steam_recv_report(steam, reply, sizeof(reply));
if (ret < 0)
- goto out;
+ return ret;
if (reply[0] != ID_GET_STRING_ATTRIBUTE || reply[1] < 1 ||
reply[1] > sizeof(steam->serial_no) || reply[2] != ATTRIB_STR_UNIT_SERIAL) {
- ret = -EIO;
- goto out;
+ hid_err(steam->hdev, "%s: invalid reply (%*ph)\n", __func__,
+ (int)sizeof(reply), reply);
+ return -EIO;
}
reply[3 + STEAM_SERIAL_LEN] = 0;
strscpy(steam->serial_no, reply + 3, reply[1]);
-out:
- mutex_unlock(&steam->report_mutex);
return ret;
}
@@ -515,8 +523,11 @@ static int steam_get_attributes(struct steam_device *steam)
ret = steam_recv_report(steam, reply, sizeof(reply));
if (ret < 0)
return ret;
- if (reply[0] != ID_GET_ATTRIBUTES_VALUES || reply[1] < 2)
+ if (reply[0] != ID_GET_ATTRIBUTES_VALUES || reply[1] < 2) {
+ hid_err(steam->hdev, "%s: invalid reply (%*ph)\n", __func__,
+ (int)sizeof(reply), reply);
return -EIO;
+ }
size = min(reply[1], sizeof(reply) - 2);
for (i = 0; i + sizeof(*attr) <= size; i += sizeof(*attr)) {
@@ -538,11 +549,8 @@ static int steam_get_attributes(struct steam_device *steam)
*/
static inline int steam_request_conn_status(struct steam_device *steam)
{
- int ret;
- mutex_lock(&steam->report_mutex);
- ret = steam_send_report_byte(steam, ID_DONGLE_GET_WIRELESS_STATE);
- mutex_unlock(&steam->report_mutex);
- return ret;
+ guard(mutex)(&steam->report_mutex);
+ return steam_send_report_byte(steam, ID_DONGLE_GET_WIRELESS_STATE);
}
/*
@@ -1165,6 +1173,7 @@ static void steam_mode_switch_cb(struct work_struct *work)
return;
steam->gamepad_mode = !steam->gamepad_mode;
+ hid_dbg(steam->hdev, "%s: switching gamepad mode to %i\n", __func__, steam->gamepad_mode);
if (steam->gamepad_mode)
steam_set_lizard_mode(steam, false);
else {
@@ -1831,6 +1840,7 @@ static void steam_do_deck_input_event(struct steam_device *steam,
steam->did_mode_switch = false;
cancel_delayed_work(&steam->mode_switch);
} else if (!steam->client_opened && start_pressed && !steam->did_mode_switch) {
+ hid_dbg(steam->hdev, "%s: doing mode switch\n", __func__);
steam->did_mode_switch = true;
schedule_delayed_work(&steam->mode_switch, 45 * HZ / 100);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0847/1518] HID: steam: Reject short reads
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (845 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0846/1518] HID: steam: Improve logging and other cleanup Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0848/1518] HID: i2c-hid: goodix: Disable VDD on VDDIO enable failure Greg Kroah-Hartman
` (151 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, syzbot+75f3f9bff8c510602d36,
Vicki Pfau, Jiri Kosina, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vicki Pfau <vi@endrift.com>
[ Upstream commit 33ff7b49c38b39b1f3d27db508ac0720fb25c08a ]
Steam Controller FEATURE reports encode the size of the message in the
message itself. Previously we were trusting that the size reported matched
the size we actually read, leading to a potential issue with short reads.
Instead, we should actually verify the length of the read.
Fixes: c164d6abf384 ("HID: add driver for Valve Steam Controller")
Reported-by: syzbot+75f3f9bff8c510602d36@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=75f3f9bff8c510602d36
Signed-off-by: Vicki Pfau <vi@endrift.com>
Link: https://syzkaller.appspot.com/bug?extid=75f3f9bff8c510602d36
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hid/hid-steam.c | 29 +++++++++++++++++++++++++----
1 file changed, 25 insertions(+), 4 deletions(-)
diff --git a/drivers/hid/hid-steam.c b/drivers/hid/hid-steam.c
index 3383a62646f9e..80d2eabc930ec 100644
--- a/drivers/hid/hid-steam.c
+++ b/drivers/hid/hid-steam.c
@@ -356,6 +356,13 @@ static int steam_recv_report(struct steam_device *steam,
u8 *buf;
int ret;
+ /*
+ * All reports start with a two byte header.
+ * We must read at least two bytes to get a sensible output.
+ */
+ if (size < 2)
+ return -EINVAL;
+
r = steam->hdev->report_enum[HID_FEATURE_REPORT].report_id_hash[0];
if (!r) {
hid_err(steam->hdev, "No HID_FEATURE_REPORT submitted - nothing to read\n");
@@ -379,16 +386,30 @@ static int steam_recv_report(struct steam_device *steam,
buf, hid_report_len(r) + 1,
HID_FEATURE_REPORT, HID_REQ_GET_REPORT);
if (ret > 0) {
- ret = min(size, ret - 1);
- memcpy(data, buf + 1, ret);
+ /* Remove the report ID from the return buffer */
+ ret--;
+ size = min(size, ret);
+ memcpy(data, buf + 1, size);
}
kfree(buf);
if (ret < 0)
hid_err(steam->hdev, "%s: error %d\n", __func__, ret);
else
- hid_dbg(steam->hdev, "Received report %*ph\n", ret, data);
- return ret;
+ hid_dbg(steam->hdev, "Received report %*ph\n", size, data);
+ if (ret < 0)
+ return ret;
+
+ if (ret < 2) {
+ hid_err(steam->hdev, "%s: reply too short\n", __func__);
+ return -EPROTO;
+ }
+ if (ret < data[1] + 2) {
+ hid_err(steam->hdev, "%s: expected %u bytes, read %i\n",
+ __func__, data[1] + 2, ret);
+ return -EPROTO;
+ }
+ return size;
}
static int steam_send_report(struct steam_device *steam,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0848/1518] HID: i2c-hid: goodix: Disable VDD on VDDIO enable failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (846 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0847/1518] HID: steam: Reject short reads Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0849/1518] HID: lg4ff: validate report length before fixed offsets Greg Kroah-Hartman
` (150 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chao Huang, Douglas Anderson,
Jiri Kosina, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Chao Huang <huangchao@kylinos.cn>
[ Upstream commit 8e2c560faea0220664169f7be4b498915ea1469f ]
If enabling VDDIO fails after VDD has been enabled, the power-up
path returns without disabling VDD. This leaves the regulator enabled
and its enable count unbalanced.
Disable VDD before returning the VDDIO error.
Fixes: eb16f59e8e58 ("HID: i2c-hid: goodix: Add mainboard-vddio-supply")
Signed-off-by: Chao Huang <huangchao@kylinos.cn>
Reviewed-by: Douglas Anderson <dianders@chromium.org>
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hid/i2c-hid/i2c-hid-of-goodix.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/hid/i2c-hid/i2c-hid-of-goodix.c b/drivers/hid/i2c-hid/i2c-hid-of-goodix.c
index f1597ad67e7c8..f4dbcd1d1d472 100644
--- a/drivers/hid/i2c-hid/i2c-hid-of-goodix.c
+++ b/drivers/hid/i2c-hid/i2c-hid-of-goodix.c
@@ -51,8 +51,10 @@ static int goodix_i2c_hid_power_up(struct i2chid_ops *ops)
return ret;
ret = regulator_enable(ihid_goodix->vddio);
- if (ret)
+ if (ret) {
+ regulator_disable(ihid_goodix->vdd);
return ret;
+ }
if (ihid_goodix->timings->post_power_delay_ms)
msleep(ihid_goodix->timings->post_power_delay_ms);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0849/1518] HID: lg4ff: validate report length before fixed offsets
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (847 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0848/1518] HID: i2c-hid: goodix: Disable VDD on VDDIO enable failure Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0850/1518] perf thread-stack: Fix heap buffer overflow on branch stack wrap copy Greg Kroah-Hartman
` (149 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jiancheng Huang, Jiri Kosina,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jiancheng Huang <jchuang@seu.edu.cn>
[ Upstream commit be00988cce4ed44db1e61231d0ab71a64bab44cd ]
lg4ff_raw_event() rewrites fixed report offsets when combined pedals are
enabled. It currently assumes that each product report contains every
source and destination byte used by the rewrite.
Return without rewriting a short report before each product-specific
access. Apply the same bound to the computed offset path.
Fixes: c832f86effbc ("HID: hid-logitech: Add combined pedal support Logitech wheels")
Signed-off-by: Jiancheng Huang <jchuang@seu.edu.cn>
Assisted-by: Codex:gpt-5.6-luna
Signed-off-by: Jiri Kosina <jkosina@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hid/hid-lg4ff.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/drivers/hid/hid-lg4ff.c b/drivers/hid/hid-lg4ff.c
index 32b711723f2aa..9ddd669d88f16 100644
--- a/drivers/hid/hid-lg4ff.c
+++ b/drivers/hid/hid-lg4ff.c
@@ -336,6 +336,8 @@ int lg4ff_raw_event(struct hid_device *hdev, struct hid_report *report,
if (entry->wdata.combine) {
switch (entry->wdata.product_id) {
case USB_DEVICE_ID_LOGITECH_WHEEL:
+ if (size < 7)
+ return 0;
rd[5] = rd[3];
rd[6] = 0x7F;
return 1;
@@ -343,10 +345,14 @@ int lg4ff_raw_event(struct hid_device *hdev, struct hid_report *report,
case USB_DEVICE_ID_LOGITECH_WINGMAN_FFG:
case USB_DEVICE_ID_LOGITECH_MOMO_WHEEL:
case USB_DEVICE_ID_LOGITECH_MOMO_WHEEL2:
+ if (size < 6)
+ return 0;
rd[4] = rd[3];
rd[5] = 0x7F;
return 1;
case USB_DEVICE_ID_LOGITECH_DFP_WHEEL:
+ if (size < 7)
+ return 0;
rd[5] = rd[4];
rd[6] = 0x7F;
return 1;
@@ -366,6 +372,8 @@ int lg4ff_raw_event(struct hid_device *hdev, struct hid_report *report,
}
/* Compute a combined axis when wheel does not supply it */
+ if (size <= offset + 1)
+ return 0;
rd[offset] = (0xFF + rd[offset] - rd[offset+1]) >> 1;
rd[offset+1] = 0x7F;
return 1;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0850/1518] perf thread-stack: Fix heap buffer overflow on branch stack wrap copy
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (848 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0849/1518] HID: lg4ff: validate report length before fixed offsets Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0851/1518] perf auxtrace: Fix queue grow overflow and old array leak Greg Kroah-Hartman
` (148 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot,
Arnaldo Carvalho de Melo, James Clark, Adrian Hunter,
Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnaldo Carvalho de Melo <acme@redhat.com>
[ Upstream commit ab9c84d1cd59e6b3b73de34982a35a76e3a9b032 ]
thread_stack__br_sample() copies the wrap-around portion of the branch
stack ring buffer with:
nr = min(ts->br_stack_pos, sz);
memcpy(be, &src->entries[0], bsz * ts->br_stack_pos);
'nr' is correctly bounded to min(br_stack_pos, sz) but the memcpy uses
the unbounded ts->br_stack_pos directly. When br_stack_pos exceeds
the remaining destination space 'sz', this writes past the destination
buffer.
Use 'nr' (the bounded value) in the memcpy size, matching the pattern
of the first memcpy in the same function.
Fixes: 86d67180b920 ("perf thread-stack: Add branch stack support")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Reviewed-by: James Clark <james.clark@linaro.org>
Reviewed-by: Adrian Hunter <adrian.hunter@intel.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/thread-stack.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/perf/util/thread-stack.c b/tools/perf/util/thread-stack.c
index c6a0a27b12c2a..47d5922efdee3 100644
--- a/tools/perf/util/thread-stack.c
+++ b/tools/perf/util/thread-stack.c
@@ -642,7 +642,7 @@ void thread_stack__br_sample(struct thread *thread, int cpu,
sz -= nr;
be = &dst->entries[nr];
nr = min(ts->br_stack_pos, sz);
- memcpy(be, &src->entries[0], bsz * ts->br_stack_pos);
+ memcpy(be, &src->entries[0], bsz * nr);
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0851/1518] perf auxtrace: Fix queue grow overflow and old array leak
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (849 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0850/1518] perf thread-stack: Fix heap buffer overflow on branch stack wrap copy Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0852/1518] perf intel-pt: Fix off-by-one in auxtrace_info minimum size check Greg Kroah-Hartman
` (147 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot,
Arnaldo Carvalho de Melo, James Clark, Adrian Hunter,
Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnaldo Carvalho de Melo <acme@redhat.com>
[ Upstream commit 96fcc9ea5f18c083a1fa73da23afef7e953f7dca ]
auxtrace_queues__grow() has two bugs:
1. When idx is UINT_MAX, the caller passes new_nr_queues = idx + 1 = 0.
The function skips growing (since any nr_queues >= 0), returns
success, and the caller accesses queue_array[UINT_MAX] — an OOB
heap write. Fix by rejecting new_nr_queues == 0 up front.
2. The function allocates a new queue_array via calloc and copies
elements from the old array, but never frees the old array. Fix
by saving the old pointer and freeing it after the copy.
Fixes: e502789302a6ece9 ("perf auxtrace: Add helpers for queuing AUX area tracing data")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Reviewed-by: James Clark <james.clark@linaro.org>
Reviewed-by: Adrian Hunter <adrian.hunter@intel.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/auxtrace.c | 15 ++++++++++-----
1 file changed, 10 insertions(+), 5 deletions(-)
diff --git a/tools/perf/util/auxtrace.c b/tools/perf/util/auxtrace.c
index 1539c1dc823c2..1749359aa9a20 100644
--- a/tools/perf/util/auxtrace.c
+++ b/tools/perf/util/auxtrace.c
@@ -235,8 +235,12 @@ static int auxtrace_queues__grow(struct auxtrace_queues *queues,
{
unsigned int nr_queues = queues->nr_queues;
struct auxtrace_queue *queue_array;
+ struct auxtrace_queue *old_array = queues->queue_array;
unsigned int i;
+ if (!new_nr_queues)
+ return -EINVAL;
+
if (!nr_queues)
nr_queues = AUXTRACE_INIT_NR_QUEUES;
@@ -251,16 +255,17 @@ static int auxtrace_queues__grow(struct auxtrace_queues *queues,
return -ENOMEM;
for (i = 0; i < queues->nr_queues; i++) {
- list_splice_tail(&queues->queue_array[i].head,
+ list_splice_tail(&old_array[i].head,
&queue_array[i].head);
- queue_array[i].tid = queues->queue_array[i].tid;
- queue_array[i].cpu = queues->queue_array[i].cpu;
- queue_array[i].set = queues->queue_array[i].set;
- queue_array[i].priv = queues->queue_array[i].priv;
+ queue_array[i].tid = old_array[i].tid;
+ queue_array[i].cpu = old_array[i].cpu;
+ queue_array[i].set = old_array[i].set;
+ queue_array[i].priv = old_array[i].priv;
}
queues->nr_queues = nr_queues;
queues->queue_array = queue_array;
+ free(old_array);
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0852/1518] perf intel-pt: Fix off-by-one in auxtrace_info minimum size check
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (850 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0851/1518] perf auxtrace: Fix queue grow overflow and old array leak Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0853/1518] perf intel-bts: " Greg Kroah-Hartman
` (146 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot,
Arnaldo Carvalho de Melo, James Clark, Adrian Hunter,
Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnaldo Carvalho de Melo <acme@redhat.com>
[ Upstream commit c4362d5e1a5ed4ce2098798f655a636c4340fa20 ]
min_sz is set to sizeof(u64) * INTEL_PT_PER_CPU_MMAPS, but the code
accesses auxtrace_info->priv[INTEL_PT_PER_CPU_MMAPS], which requires
at least INTEL_PT_PER_CPU_MMAPS + 1 elements. A file with exactly
min_sz bytes of priv data passes the size check but the access reads
one u64 past the validated region.
Use (INTEL_PT_PER_CPU_MMAPS + 1) to ensure the highest accessed index
is within bounds.
Fixes: 90e457f7be087005 ("perf tools: Add Intel PT support")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Reviewed-by: James Clark <james.clark@linaro.org>
Reviewed-by: Adrian Hunter <adrian.hunter@intel.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/intel-pt.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/perf/util/intel-pt.c b/tools/perf/util/intel-pt.c
index 9b1011fe48267..fd636f5639cab 100644
--- a/tools/perf/util/intel-pt.c
+++ b/tools/perf/util/intel-pt.c
@@ -4411,7 +4411,7 @@ int intel_pt_process_auxtrace_info(union perf_event *event,
struct perf_session *session)
{
struct perf_record_auxtrace_info *auxtrace_info = &event->auxtrace_info;
- size_t min_sz = sizeof(u64) * INTEL_PT_PER_CPU_MMAPS;
+ size_t min_sz = sizeof(u64) * (INTEL_PT_PER_CPU_MMAPS + 1);
struct intel_pt *pt;
void *info_end;
__u64 *info;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0853/1518] perf intel-bts: Fix off-by-one in auxtrace_info minimum size check
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (851 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0852/1518] perf intel-pt: Fix off-by-one in auxtrace_info minimum size check Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0854/1518] perf arm-spe: Reject zero nr_cpu in metadata to prevent division by zero Greg Kroah-Hartman
` (145 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot,
Arnaldo Carvalho de Melo, James Clark, Adrian Hunter,
Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnaldo Carvalho de Melo <acme@redhat.com>
[ Upstream commit b9fb8225951ce27e62a2235a71f3ab01137aaec3 ]
Same pattern as the Intel PT fix: min_sz is set to
sizeof(u64) * INTEL_BTS_SNAPSHOT_MODE, but the code accesses
auxtrace_info->priv[INTEL_BTS_SNAPSHOT_MODE], which requires at least
INTEL_BTS_SNAPSHOT_MODE + 1 elements.
Use (INTEL_BTS_SNAPSHOT_MODE + 1) to ensure the highest accessed index
is within bounds.
Fixes: d0170af7004dce9c ("perf tools: Add Intel BTS support")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Reviewed-by: James Clark <james.clark@linaro.org>
Reviewed-by: Adrian Hunter <adrian.hunter@intel.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/intel-bts.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/tools/perf/util/intel-bts.c b/tools/perf/util/intel-bts.c
index 3625c62247502..9f5f378cf7743 100644
--- a/tools/perf/util/intel-bts.c
+++ b/tools/perf/util/intel-bts.c
@@ -831,7 +831,7 @@ int intel_bts_process_auxtrace_info(union perf_event *event,
struct perf_session *session)
{
struct perf_record_auxtrace_info *auxtrace_info = &event->auxtrace_info;
- size_t min_sz = sizeof(u64) * INTEL_BTS_SNAPSHOT_MODE;
+ size_t min_sz = sizeof(u64) * (INTEL_BTS_SNAPSHOT_MODE + 1);
struct intel_bts *bts;
int err;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0854/1518] perf arm-spe: Reject zero nr_cpu in metadata to prevent division by zero
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (852 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0853/1518] perf intel-bts: " Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0855/1518] iio: light: tsl2772: fix ALS calibscale readback Greg Kroah-Hartman
` (144 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot,
Arnaldo Carvalho de Melo, James Clark, Adrian Hunter,
Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnaldo Carvalho de Melo <acme@redhat.com>
[ Upstream commit d67241d43b709af4d13051bb8494892b654aba41 ]
arm_spe__alloc_metadata() reads nr_cpu from the auxtrace_info priv
array without validation. When a crafted perf.data provides nr_cpu=0,
the per_cpu_sz calculation divides by zero:
per_cpu_sz = (metadata_size - (hdr_sz * sizeof(u64))) / (*nr_cpu);
Reject nr_cpu <= 0 early, before the division. The caller already
treats NULL return with metadata_ver != 1 as a parse failure.
Fixes: 7842a4b6ff698 ("perf arm-spe: Support metadata version 2")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Reviewed-by: James Clark <james.clark@linaro.org>
Reviewed-by: Adrian Hunter <adrian.hunter@intel.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/arm-spe.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/tools/perf/util/arm-spe.c b/tools/perf/util/arm-spe.c
index 71be979f50771..cc99b06e59802 100644
--- a/tools/perf/util/arm-spe.c
+++ b/tools/perf/util/arm-spe.c
@@ -1543,6 +1543,10 @@ static u64 **arm_spe__alloc_metadata(struct perf_record_auxtrace_info *info,
hdr_sz = ptr[ARM_SPE_HEADER_SIZE];
*nr_cpu = ptr[ARM_SPE_CPUS_NUM];
+ /* nr_cpu is used as a divisor below */
+ if (*nr_cpu <= 0)
+ return NULL;
+
metadata = calloc(*nr_cpu, sizeof(*metadata));
if (!metadata)
return NULL;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0855/1518] iio: light: tsl2772: fix ALS calibscale readback
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (853 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0854/1518] perf arm-spe: Reject zero nr_cpu in metadata to prevent division by zero Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0856/1518] iio: light: isl29028: return zero in write_raw() on success Greg Kroah-Hartman
` (143 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yuanshen Cao, David Lechner,
Jonathan Cameron, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuanshen Cao <alex.caoys@gmail.com>
[ Upstream commit ac75550ab5b5d73649bffea245c2075fd9249bd0 ]
The read_raw() implementation uses IIO_LIGHT to distinguish between the
ambient light and proximity channels when handling
IIO_CHAN_INFO_CALIBSCALE.
However, the ALS channel is registered as IIO_INTENSITY, while
write_raw() correctly writes to IIO_INTENSITY. As a result, reading
in_intensity0_calibscale incorrectly returns the proximity gain instead
of the ALS gain.
This causes the following user-visible behavior:
- Writing in_intensity0_calibscale appears to have no effect because the
readback reports the proximity gain.
- Writing in_proximity0_calibscale causes both in_proximity0_calibscale
and in_intensity0_calibscale to report the same value.
Fix this by checking for IIO_INTENSITY in read_raw(), matching the
channel definition and the existing write_raw() implementation.
Fixes: 3c97c08b5735 ("staging: iio: add TAOS tsl2x7x driver")
Signed-off-by: Yuanshen Cao <alex.caoys@gmail.com>
Reviewed-by: David Lechner <dlechner@baylibre.com>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/iio/light/tsl2772.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/iio/light/tsl2772.c b/drivers/iio/light/tsl2772.c
index 0b171106441ab..ffbde15401141 100644
--- a/drivers/iio/light/tsl2772.c
+++ b/drivers/iio/light/tsl2772.c
@@ -1263,7 +1263,7 @@ static int tsl2772_read_raw(struct iio_dev *indio_dev,
}
break;
case IIO_CHAN_INFO_CALIBSCALE:
- if (chan->type == IIO_LIGHT)
+ if (chan->type == IIO_INTENSITY)
*val = tsl2772_als_gain[chip->settings.als_gain];
else
*val = tsl2772_prox_gain[chip->settings.prox_gain];
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0856/1518] iio: light: isl29028: return zero in write_raw() on success
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (854 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0855/1518] iio: light: tsl2772: fix ALS calibscale readback Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0857/1518] iio: light: tsl2583: " Greg Kroah-Hartman
` (142 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sang-Heon Jeon, Brian Masney,
Jonathan Cameron, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sang-Heon Jeon <ekffu200098@gmail.com>
[ Upstream commit 55b75622829779223b9e32aa9600a8651d3e2df4 ]
isl29028_write_raw() returns the value of pm_runtime_put_autosuspend(),
which is 1 if the device is already runtime suspended.
In that case write() on the sysfs attribute returns 1 instead of the
number of bytes written. Make isl29028_write_raw() always return zero
on success.
Fixes: 2db5054ac28d ("staging: iio: isl29028: add runtime power management support")
Signed-off-by: Sang-Heon Jeon <ekffu200098@gmail.com>
Reviewed-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/iio/light/isl29028.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/iio/light/isl29028.c b/drivers/iio/light/isl29028.c
index 374bccad9119a..f89c5d9ee5240 100644
--- a/drivers/iio/light/isl29028.c
+++ b/drivers/iio/light/isl29028.c
@@ -409,7 +409,7 @@ static int isl29028_write_raw(struct iio_dev *indio_dev,
if (ret < 0)
return ret;
- return ret;
+ return 0;
}
static int isl29028_read_raw(struct iio_dev *indio_dev,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0857/1518] iio: light: tsl2583: return zero in write_raw() on success
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (855 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0856/1518] iio: light: isl29028: return zero in write_raw() on success Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0858/1518] net: stmmac: Skip PHY attach if custom PCS is in use Greg Kroah-Hartman
` (141 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sang-Heon Jeon, Brian Masney,
Jonathan Cameron, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sang-Heon Jeon <ekffu200098@gmail.com>
[ Upstream commit 42e8791841e0677418a3ccc97fa5c22a1455f417 ]
tsl2583_write_raw() returns the value of pm_runtime_put_autosuspend(),
which is 1 if the device is already runtime suspended.
In that case write() on the sysfs attribute returns 1 instead of the
number of bytes written. Make tsl2583_write_raw() always return zero
on success.
Fixes: 371894f5d1a0 ("iio: tsl2583: add runtime power management support")
Signed-off-by: Sang-Heon Jeon <ekffu200098@gmail.com>
Reviewed-by: Brian Masney <bmasney@redhat.com>
Signed-off-by: Jonathan Cameron <jonathan.cameron@oss.qualcomm.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/iio/light/tsl2583.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/iio/light/tsl2583.c b/drivers/iio/light/tsl2583.c
index 8801a491de77b..15693bc3e8e85 100644
--- a/drivers/iio/light/tsl2583.c
+++ b/drivers/iio/light/tsl2583.c
@@ -794,7 +794,7 @@ static int tsl2583_write_raw(struct iio_dev *indio_dev,
if (ret < 0)
return ret;
- return ret;
+ return 0;
}
static const struct iio_info tsl2583_info = {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0858/1518] net: stmmac: Skip PHY attach if custom PCS is in use
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (856 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0857/1518] iio: light: tsl2583: " Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0859/1518] phonet: pep: do not write beyond optlen in getsockopt Greg Kroah-Hartman
` (140 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zxyan Zhu, Maxime Chevallier,
Jakub Kicinski, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zxyan Zhu <zxyan0222@gmail.com>
[ Upstream commit af4d934164457f0578bf90e92ae0fcc5348260cb ]
When a platform provides a custom PCS via the pcs_init callback,
the MAC's phylink_pcs is already configured. In this case, no
traditional PHY device is needed.
Without this, stmmac_init_phy() falls through to the no-phy-node
path and errors out with "no phy found" when the DT has no
phy-handle for such interfaces.
Skip the PHY attach when priv->hw->phylink_pcs is set and
phy_addr is invalid.
Fixes: f0ef433fc264 ("net: stmmac: introduce pcs_init/pcs_exit stmmac operations")
Signed-off-by: Zxyan Zhu <zxyan0222@gmail.com>
Reviewed-by: Maxime Chevallier <maxime.chevallier@bootlin.com>
Link: https://patch.msgid.link/20260729074237.2624940-2-zxyan0222@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/net/ethernet/stmicro/stmmac/stmmac_main.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c b/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
index bf2fa56b861be..4b458a39ab9f5 100644
--- a/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
+++ b/drivers/net/ethernet/stmicro/stmmac/stmmac_main.c
@@ -1126,6 +1126,10 @@ static int stmmac_init_phy(struct net_device *dev)
struct phy_device *phydev;
if (addr < 0) {
+ /* If a custom PCS is in use, no PHY is needed */
+ if (priv->hw->phylink_pcs)
+ return 0;
+
netdev_err(priv->dev, "no phy found\n");
return -ENODEV;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0859/1518] phonet: pep: do not write beyond optlen in getsockopt
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (857 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0858/1518] net: stmmac: Skip PHY attach if custom PCS is in use Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0860/1518] blk-cgroup: fix race between policy activation and blkg destruction Greg Kroah-Hartman
` (139 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Rémi Denis-Courmont, Joe Damato,
Stanislav Fomichev, Breno Leitao, Jakub Kicinski, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Breno Leitao <leitao@debian.org>
[ Upstream commit 77e5eb0e192aec6710c03ca8144582fd2af36ca4 ]
pep_getsockopt() clamps the reported length to the caller's buffer with
min_t(), but then stores the value with put_user(val, (int __user *)
optval), which always writes sizeof(int) bytes. A getsockopt() call with
an optlen smaller than sizeof(int) thus reports the clamped length yet
writes a full int, one to three bytes past the user buffer.
Write the value with copy_to_user() bounded by len, so at most optlen
bytes are copied, matching the length reported back to userspace.
Fixes: 02a47617cdce ("Phonet: implement GPRS virtual interface over PEP socket")
Acked-by: Rémi Denis-Courmont <remi@remlab.net>
Reviewed-by: Joe Damato <joe@dama.to>
Acked-by: Stanislav Fomichev <sdf@fomichev.me>
Signed-off-by: Breno Leitao <leitao@debian.org>
Link: https://patch.msgid.link/20260729-getsockopt_phase4-v4-4-c44576757c17@debian.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/phonet/pep.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/phonet/pep.c b/net/phonet/pep.c
index 5910dcd26555e..36c85811fd08b 100644
--- a/net/phonet/pep.c
+++ b/net/phonet/pep.c
@@ -1116,7 +1116,7 @@ static int pep_getsockopt(struct sock *sk, int level, int optname,
len = min_t(unsigned int, sizeof(int), len);
if (put_user(len, optlen))
return -EFAULT;
- if (put_user(val, (int __user *) optval))
+ if (copy_to_user(optval, &val, len))
return -EFAULT;
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0860/1518] blk-cgroup: fix race between policy activation and blkg destruction
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (858 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0859/1518] phonet: pep: do not write beyond optlen in getsockopt Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0861/1518] blk-cgroup: skip dying blkg in blkcg_activate_policy() Greg Kroah-Hartman
` (138 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zheng Qixing, Tang Yizhou, Yu Kuai,
Tao Cui, Nilay Shroff, Jens Axboe, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zheng Qixing <zhengqixing@huawei.com>
[ Upstream commit 5313d4d41739b0cb63000747c97bb1217ac45f3e ]
When switching an IO scheduler on a block device, blkcg_activate_policy()
allocates blkg_policy_data (pd) for all blkgs attached to the queue.
However, blkcg_activate_policy() may race with concurrent blkcg deletion,
leading to use-after-free and memory leak issues.
The use-after-free occurs in the following race:
T1 (blkcg_activate_policy):
- Successfully allocates pd for blkg1 (loop0->queue, blkcgA)
- Fails to allocate pd for blkg2 (loop0->queue, blkcgB)
- Enters the enomem rollback path to release blkg1 resources
T2 (blkcg deletion):
- blkcgA is deleted concurrently
- blkg1 is freed via blkg_free_workfn()
- blkg1->pd is freed
T1 (continued):
- Rollback path accesses blkg1->pd->online after pd is freed
- Triggers use-after-free
In addition, blkg_free_workfn() frees pd before removing the blkg from
q->blkg_list. This allows blkcg_activate_policy() to allocate a new pd
for a blkg that is being destroyed, leaving the newly allocated pd
unreachable when the blkg is finally freed.
Fix these races by extending blkcg_mutex coverage to serialize
blkcg_activate_policy() rollback and blkg destruction, ensuring pd
lifecycle is synchronized with blkg list visibility.
Fixes: f1c006f1c685 ("blk-cgroup: synchronize pd_free_fn() from blkg_free_workfn() and blkcg_deactivate_policy()")
Signed-off-by: Zheng Qixing <zhengqixing@huawei.com>
Reviewed-by: Tang Yizhou <yizhou.tang@shopee.com>
Signed-off-by: Yu Kuai <yukuai@fygo.io>
Reviewed-by: Tao Cui <cuitao@kylinos.cn>
Reviewed-by: Nilay Shroff <nilay@linux.ibm.com>
Link: https://patch.msgid.link/20260802112525.3933753-3-yukuai@kernel.org
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
block/blk-cgroup.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/block/blk-cgroup.c b/block/blk-cgroup.c
index a2347b5795874..36aebc5c8b7b7 100644
--- a/block/blk-cgroup.c
+++ b/block/blk-cgroup.c
@@ -1612,6 +1612,8 @@ int blkcg_activate_policy(struct gendisk *disk, const struct blkcg_policy *pol)
if (queue_is_mq(q))
memflags = blk_mq_freeze_queue(q);
+
+ mutex_lock(&q->blkcg_mutex);
retry:
spin_lock_irq(&q->queue_lock);
@@ -1674,6 +1676,7 @@ int blkcg_activate_policy(struct gendisk *disk, const struct blkcg_policy *pol)
spin_unlock_irq(&q->queue_lock);
out:
+ mutex_unlock(&q->blkcg_mutex);
if (queue_is_mq(q))
blk_mq_unfreeze_queue(q, memflags);
if (pinned_blkg)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0861/1518] blk-cgroup: skip dying blkg in blkcg_activate_policy()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (859 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0860/1518] blk-cgroup: fix race between policy activation and blkg destruction Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0862/1518] block/blk-stat: drain per-cpu callback stats over possible CPUs Greg Kroah-Hartman
` (137 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zheng Qixing, Tang Yizhou, Yu Kuai,
Tao Cui, Nilay Shroff, Jens Axboe, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zheng Qixing <zhengqixing@huawei.com>
[ Upstream commit 5e9220389920f33b6a804d50c548cd0cd1b04634 ]
When switching IO schedulers on a block device, blkcg_activate_policy()
can race with concurrent blkcg deletion, leading to a use-after-free in
rcu_accelerate_cbs.
T1: T2:
blkg_destroy
kill(&blkg->refcnt) // blkg->refcnt=1->0
blkg_release // call_rcu(__blkg_release)
...
blkg_free_workfn
->pd_free_fn(pd)
elv_iosched_store
elevator_switch
...
iterate blkg list
blkg_get(blkg) // blkg->refcnt=0->1
list_del_init(&blkg->q_node)
blkg_put(pinned_blkg) // blkg->refcnt=1->0
blkg_release // call_rcu again
rcu_accelerate_cbs // uaf
Fix this by checking hlist_unhashed(&blkg->blkcg_node) before getting
a reference to the blkg. This is the same check used in blkg_destroy()
to detect if a blkg has already been destroyed. If the blkg is already
unhashed, skip processing it since it's being destroyed.
Fixes: f1c006f1c685 ("blk-cgroup: synchronize pd_free_fn() from blkg_free_workfn() and blkcg_deactivate_policy()")
Signed-off-by: Zheng Qixing <zhengqixing@huawei.com>
Reviewed-by: Tang Yizhou <yizhou.tang@shopee.com>
Signed-off-by: Yu Kuai <yukuai@fygo.io>
Reviewed-by: Tao Cui <cuitao@kylinos.cn>
Reviewed-by: Nilay Shroff <nilay@linux.ibm.com>
Link: https://patch.msgid.link/20260802112525.3933753-4-yukuai@kernel.org
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
block/blk-cgroup.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/block/blk-cgroup.c b/block/blk-cgroup.c
index 36aebc5c8b7b7..f605df3991c38 100644
--- a/block/blk-cgroup.c
+++ b/block/blk-cgroup.c
@@ -1623,6 +1623,8 @@ int blkcg_activate_policy(struct gendisk *disk, const struct blkcg_policy *pol)
if (blkg->pd[pol->plid])
continue;
+ if (hlist_unhashed(&blkg->blkcg_node))
+ continue;
/* If prealloc matches, use it; otherwise try GFP_NOWAIT */
if (blkg == pinned_blkg) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0862/1518] block/blk-stat: drain per-cpu callback stats over possible CPUs
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (860 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0861/1518] blk-cgroup: skip dying blkg in blkcg_activate_policy() Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0863/1518] block/blk-iocost: collect per-cpu latency " Greg Kroah-Hartman
` (136 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tao Cui, Yu Kuai, Jens Axboe,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tao Cui <cuitao@kylinos.cn>
[ Upstream commit 9d617828cfc4d9a4d385daa2cd61f9db0592c53f ]
blk_stat_timer_fn() sums and resets a callback's per-cpu buckets using
for_each_online_cpu(). A CPU that goes offline with pending samples is
skipped, so its samples are neither accumulated into the window nor
cleared; they sit in the bucket until the CPU comes back online, at
which point the stale values are flushed into whatever window is then
running.
This silently corrupts the latency picture that consumers (notably
writeback throttling via wbt, and blk-mq latency tracking) base
decisions on around CPU hotplug: under-counting while the CPU is
offline, then a burst of stale data on re-online.
Fixes: 34dbad5d26e2 ("blk-stat: convert to callback-based statistics reporting")
Signed-off-by: Tao Cui <cuitao@kylinos.cn>
Reviewed-by: Yu Kuai <yukuai@fygo.io>
Link: https://patch.msgid.link/20260720093726.28965-2-cui.tao@linux.dev
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
block/blk-stat.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/block/blk-stat.c b/block/blk-stat.c
index 682a8ddb11734..5c5289b085504 100644
--- a/block/blk-stat.c
+++ b/block/blk-stat.c
@@ -83,7 +83,7 @@ static void blk_stat_timer_fn(struct timer_list *t)
for (bucket = 0; bucket < cb->buckets; bucket++)
blk_rq_stat_init(&cb->stat[bucket]);
- for_each_online_cpu(cpu) {
+ for_each_possible_cpu(cpu) {
struct blk_rq_stat *cpu_stat;
cpu_stat = per_cpu_ptr(cb->cpu_stat, cpu);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0863/1518] block/blk-iocost: collect per-cpu latency stats over possible CPUs
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (861 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0862/1518] block/blk-stat: drain per-cpu callback stats over possible CPUs Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0864/1518] block/kyber-iosched: flush per-cpu latency buckets " Greg Kroah-Hartman
` (135 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tao Cui, Yu Kuai, Jens Axboe,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tao Cui <cuitao@kylinos.cn>
[ Upstream commit 4e050c5b92c1600415b2cd452583e543036f3d73 ]
ioc_lat_stat() walks ioc->pcpu_stat with for_each_online_cpu() to
compute missed-ppm and rq_wait deltas. An offlined CPU is skipped, so
its delta is dropped from the period and its last_* watermark is not
advanced; on re-online the next collection sees a delta spanning the
whole offline interval, corrupting the latency/vrate picture.
Fixes: 7caa47151ab2 ("blkcg: implement blk-iocost")
Signed-off-by: Tao Cui <cuitao@kylinos.cn>
Reviewed-by: Yu Kuai <yukuai@fygo.io>
Link: https://patch.msgid.link/20260720093726.28965-4-cui.tao@linux.dev
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
block/blk-iocost.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/block/blk-iocost.c b/block/blk-iocost.c
index 5bfd70311359c..ecf4969125050 100644
--- a/block/blk-iocost.c
+++ b/block/blk-iocost.c
@@ -1603,7 +1603,7 @@ static void ioc_lat_stat(struct ioc *ioc, u32 *missed_ppm_ar, u32 *rq_wait_pct_p
u64 rq_wait_ns = 0;
int cpu, rw;
- for_each_online_cpu(cpu) {
+ for_each_possible_cpu(cpu) {
struct ioc_pcpu_stat *stat = per_cpu_ptr(ioc->pcpu_stat, cpu);
u64 this_rq_wait_ns;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0864/1518] block/kyber-iosched: flush per-cpu latency buckets over possible CPUs
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (862 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0863/1518] block/blk-iocost: collect per-cpu latency " Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0865/1518] ublk: check import_ubuf() return value Greg Kroah-Hartman
` (134 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tao Cui, Yu Kuai, Jens Axboe,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tao Cui <cuitao@kylinos.cn>
[ Upstream commit 482fc257de95ab181688e9d1dfcc6b6a58857b1e ]
kyber_timer_fn() sums the per-cpu latency histograms with
for_each_online_cpu(). A CPU that goes offline mid-interval leaves its
bucket un-flushed; the samples are lost from the current decision and
re-appear (stale) when the CPU is onlined again.
Fixes: 6e25cb01ea20 ("kyber: implement improved heuristics")
Signed-off-by: Tao Cui <cuitao@kylinos.cn>
Reviewed-by: Yu Kuai <yukuai@fygo.io>
Link: https://patch.msgid.link/20260720093726.28965-5-cui.tao@linux.dev
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
block/kyber-iosched.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/block/kyber-iosched.c b/block/kyber-iosched.c
index e3eaeea62e24d..927df06e6b940 100644
--- a/block/kyber-iosched.c
+++ b/block/kyber-iosched.c
@@ -279,7 +279,7 @@ static void kyber_timer_fn(struct timer_list *t)
bool bad = false;
/* Sum all of the per-cpu latency histograms. */
- for_each_online_cpu(cpu) {
+ for_each_possible_cpu(cpu) {
struct kyber_cpu_latency *cpu_latency;
cpu_latency = per_cpu_ptr(kqd->cpu_latency, cpu);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0865/1518] ublk: check import_ubuf() return value
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (863 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0864/1518] block/kyber-iosched: flush per-cpu latency buckets " Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0866/1518] ublk: check for ublk_unmap_io() returning 0 Greg Kroah-Hartman
` (133 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ming Lei, Caleb Sander Mateos,
Jens Axboe, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Caleb Sander Mateos <csander@purestorage.com>
[ Upstream commit 3831568792af75b6523fa93bb91560e29189cf55 ]
import_ubuf() can fail if the address range (provided by the userspace
ublk server) is outside the allowed user address space. Return that 0
bytes were copied if import_ubuf() fails rather than passing an
uninitialized struct iov_iter to ublk_copy_user_pages().
Fixes: 981f95a571e3 ("ublk: cleanup ublk_copy_user_pages")
Reported-by: Ming Lei <tom.leiming@gmail.com>
Signed-off-by: Caleb Sander Mateos <csander@purestorage.com>
Link: https://patch.msgid.link/20260729171041.45061-2-csander@purestorage.com
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/block/ublk_drv.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/drivers/block/ublk_drv.c b/drivers/block/ublk_drv.c
index e7a77f27555ed..755add69fb8a8 100644
--- a/drivers/block/ublk_drv.c
+++ b/drivers/block/ublk_drv.c
@@ -1050,7 +1050,10 @@ static int ublk_map_io(const struct ublk_queue *ubq, const struct request *req,
struct iov_iter iter;
const int dir = ITER_DEST;
- import_ubuf(dir, u64_to_user_ptr(io->buf.addr), rq_bytes, &iter);
+ if (import_ubuf(dir, u64_to_user_ptr(io->buf.addr), rq_bytes,
+ &iter) < 0)
+ return 0;
+
return ublk_copy_user_pages(req, 0, &iter, dir);
}
return rq_bytes;
@@ -1071,7 +1074,10 @@ static int ublk_unmap_io(bool need_map,
WARN_ON_ONCE(io->res > rq_bytes);
- import_ubuf(dir, u64_to_user_ptr(io->buf.addr), io->res, &iter);
+ if (import_ubuf(dir, u64_to_user_ptr(io->buf.addr), io->res,
+ &iter) < 0)
+ return 0;
+
return ublk_copy_user_pages(req, 0, &iter, dir);
}
return rq_bytes;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0866/1518] ublk: check for ublk_unmap_io() returning 0
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (864 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0865/1518] ublk: check import_ubuf() return value Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0867/1518] ocfs2/cluster: keep heartbeat local node stable Greg Kroah-Hartman
` (132 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Caleb Sander Mateos, Jens Axboe,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Caleb Sander Mateos <csander@purestorage.com>
[ Upstream commit 24fd3706178f1ae5501fd1ff9036e170ed0665ba ]
If the userspace ublk server passes an unmapped address as the data
buffer for a completed ublk read, ublk_unmap_io() will return 0
indicating no bytes could be copied. Currently, this will result in
calling blk_update_request() with nr_bytes=0, which doesn't seem
supported. Fail the I/O with BLK_STS_IOERR in this case instead.
Fixes: 71f28f3136af ("ublk_drv: add io_uring based userspace block driver")
Signed-off-by: Caleb Sander Mateos <csander@purestorage.com>
Link: https://patch.msgid.link/20260729171041.45061-3-csander@purestorage.com
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/block/ublk_drv.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/drivers/block/ublk_drv.c b/drivers/block/ublk_drv.c
index 755add69fb8a8..d71407fc1f4c8 100644
--- a/drivers/block/ublk_drv.c
+++ b/drivers/block/ublk_drv.c
@@ -1196,8 +1196,14 @@ static inline void __ublk_complete_rq(struct request *req, struct ublk_io *io,
*
* Re-read simply for this unlikely case.
*/
- if (unlikely(unmapped_bytes < io->res))
+ if (unlikely(unmapped_bytes < io->res)) {
+ if (unlikely(!unmapped_bytes)) {
+ res = BLK_STS_IOERR;
+ goto exit;
+ }
+
io->res = unmapped_bytes;
+ }
/*
* Run bio->bi_end_io() with softirqs disabled. If the final fput
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0867/1518] ocfs2/cluster: keep heartbeat local node stable
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (865 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0866/1518] ublk: check for ublk_unmap_io() returning 0 Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0868/1518] lib/string: fix memchr_inv() for large ranges Greg Kroah-Hartman
` (131 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Cen Zhang, Joseph Qi, Mark Fasheh,
Joel Becker, Junxiao Bi, Changwei Ge, Jun Piao, Heming Zhao,
Andrew Morton, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cen Zhang <zzzccc427@gmail.com>
[ Upstream commit 688bc88e2046dd6ce81ce18079b5254cb8dadc0e ]
o2nm_node_local_store() handles local=0 by stopping o2net and setting
cl_local_node to O2NM_INVALID_NODE_NUM, but it leaves cl_has_local set.
That stale state makes o2nm_this_node() return 255, blocks a later local=1
attempt with -EBUSY, and can feed 255 to heartbeat users that call
o2nm_this_node() dynamically.
Clearing cl_has_local is required when the local node is reset. But
heartbeat threads can still be running at that point. They pin the local
node config item at startup, yet o2hb_do_disk_heartbeat() and thread
teardown re-read o2nm_this_node() for the local slot and for
o2nm_undepend_this_node(). Once local=0 has cleared the live local-node
state, those dynamic reads return O2NM_MAX_NODES, which is also the
invalid node number 255.
Store the local node number in the heartbeat region when the region
starts. Use that stable node for heartbeat slot writes/checks,
negotiation messages, and the final configfs undepend. Stop the heartbeat
loop when the current local node no longer matches the stored node, and
clear cl_has_local together with cl_local_node in the local=0 path so
nodemanager state matches node removal.
Validation reproduced this kernel report:
KASAN slab-out-of-bounds in o2hb_do_disk_heartbeat+0x372/0xb30
RIP: 0010:memset+0xf/0x20
Read of size 8
Call trace:
dump_stack_lvl+0x66/0xa0
print_report+0xd0/0x630
o2hb_do_disk_heartbeat+0x372/0xb30 (fs/ocfs2/cluster/heartbeat.c:1079)
srso_alias_return_thunk+0x5/0xfbef5
__virt_addr_valid+0x188/0x2f0
kasan_report+0xe4/0x120
o2hb_do_disk_heartbeat+0x5/0xb30 (fs/ocfs2/cluster/heartbeat.c:1079)
o2hb_thread+0x14e/0x770
kthread_affine_node+0x139/0x180
lockdep_hardirqs_on_prepare+0xda/0x190
trace_hardirqs_on+0x18/0x130
kthread+0x19d/0x1e0
ret_from_fork+0x37a/0x4d0
__switch_to+0x2d5/0x6f0
ret_from_fork_asm+0x1a/0x30
Link: https://lore.kernel.org/20260616074931.3774929-1-zzzccc427@gmail.com
Fixes: a7f6a5fb4bde ("[PATCH] OCFS2: The Second Oracle Cluster Filesystem")
Assisted-by: Codex:gpt-5.5
Signed-off-by: Cen Zhang <zzzccc427@gmail.com>
Suggested-by: Joseph Qi <joseph.qi@linux.alibaba.com>
Reviewed-by: Joseph Qi <joseph.qi@linux.alibaba.com>
Cc: Mark Fasheh <mark@fasheh.com>
Cc: Joel Becker <jlbec@evilplan.org>
Cc: Junxiao Bi <junxiao.bi@oracle.com>
Cc: Changwei Ge <gechangwei@live.cn>
Cc: Jun Piao <piaojun@huawei.com>
Cc: Heming Zhao <heming.zhao@suse.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ocfs2/cluster/heartbeat.c | 43 +++++++++++++++++++++++-----------
fs/ocfs2/cluster/nodemanager.c | 19 +++++++++++----
fs/ocfs2/cluster/nodemanager.h | 2 ++
3 files changed, 46 insertions(+), 18 deletions(-)
diff --git a/fs/ocfs2/cluster/heartbeat.c b/fs/ocfs2/cluster/heartbeat.c
index 798d76f479d0b..9eeab95fe89b4 100644
--- a/fs/ocfs2/cluster/heartbeat.c
+++ b/fs/ocfs2/cluster/heartbeat.c
@@ -211,6 +211,7 @@ struct o2hb_region {
/* protected by the hr_callback_sem */
struct task_struct *hr_task;
+ u8 hr_node_num;
unsigned int hr_blocks;
unsigned long long hr_start_block;
@@ -358,12 +359,12 @@ static void o2hb_disarm_timeout(struct o2hb_region *reg)
cancel_delayed_work_sync(®->hr_nego_timeout_work);
}
-static int o2hb_send_nego_msg(int key, int type, u8 target)
+static int o2hb_send_nego_msg(int key, int type, u8 target, u8 node_num)
{
struct o2hb_nego_msg msg;
int status, ret;
- msg.node_num = o2nm_this_node();
+ msg.node_num = node_num;
again:
ret = o2net_send_message(type, key, &msg, sizeof(msg),
target, &status);
@@ -381,8 +382,10 @@ static void o2hb_nego_timeout(struct work_struct *work)
unsigned long live_node_bitmap[BITS_TO_LONGS(O2NM_MAX_NODES)];
int master_node, i, ret;
struct o2hb_region *reg;
+ u8 node_num;
reg = container_of(work, struct o2hb_region, hr_nego_timeout_work.work);
+ node_num = reg->hr_node_num;
/* don't negotiate timeout if last hb failed since it is very
* possible io failed. Should let write timeout fence self.
*/
@@ -393,10 +396,10 @@ static void o2hb_nego_timeout(struct work_struct *work)
/* lowest node as master node to make negotiate decision. */
master_node = find_first_bit(live_node_bitmap, O2NM_MAX_NODES);
- if (master_node == o2nm_this_node()) {
+ if (master_node == node_num) {
if (!test_bit(master_node, reg->hr_nego_node_bitmap)) {
printk(KERN_NOTICE "o2hb: node %d hb write hung for %ds on region %s (%pg).\n",
- o2nm_this_node(), O2HB_NEGO_TIMEOUT_MS/1000,
+ node_num, O2HB_NEGO_TIMEOUT_MS / 1000,
config_item_name(®->hr_item), reg_bdev(reg));
set_bit(master_node, reg->hr_nego_node_bitmap);
}
@@ -425,7 +428,7 @@ static void o2hb_nego_timeout(struct work_struct *work)
mlog(ML_HEARTBEAT, "send NEGO_APPROVE msg to node %d\n", i);
ret = o2hb_send_nego_msg(reg->hr_key,
- O2HB_NEGO_APPROVE_MSG, i);
+ O2HB_NEGO_APPROVE_MSG, i, node_num);
if (ret)
mlog(ML_ERROR, "send NEGO_APPROVE msg to node %d fail %d\n",
i, ret);
@@ -433,10 +436,10 @@ static void o2hb_nego_timeout(struct work_struct *work)
} else {
/* negotiate timeout with master node. */
printk(KERN_NOTICE "o2hb: node %d hb write hung for %ds on region %s (%pg), negotiate timeout with node %d.\n",
- o2nm_this_node(), O2HB_NEGO_TIMEOUT_MS/1000, config_item_name(®->hr_item),
+ node_num, O2HB_NEGO_TIMEOUT_MS / 1000, config_item_name(®->hr_item),
reg_bdev(reg), master_node);
ret = o2hb_send_nego_msg(reg->hr_key, O2HB_NEGO_TIMEOUT_MSG,
- master_node);
+ master_node, node_num);
if (ret)
mlog(ML_ERROR, "send NEGO_TIMEOUT msg to node %d fail %d\n",
master_node, ret);
@@ -609,7 +612,9 @@ static int o2hb_issue_node_write(struct o2hb_region *reg,
o2hb_bio_wait_init(write_wc);
- slot = o2nm_this_node();
+ slot = reg->hr_node_num;
+ if (slot >= O2NM_MAX_NODES)
+ return -EINVAL;
bio = o2hb_setup_one_bio(reg, write_wc, &slot, slot+1,
REQ_OP_WRITE | REQ_SYNC);
@@ -678,8 +683,12 @@ static int o2hb_check_own_slot(struct o2hb_region *reg)
struct o2hb_disk_slot *slot;
struct o2hb_disk_heartbeat_block *hb_block;
char *errstr;
+ u8 node_num = reg->hr_node_num;
+
+ if (node_num >= O2NM_MAX_NODES)
+ return 0;
- slot = ®->hr_slots[o2nm_this_node()];
+ slot = ®->hr_slots[node_num];
/* Don't check on our 1st timestamp */
if (!slot->ds_last_time)
return 0;
@@ -720,7 +729,10 @@ static inline void o2hb_prepare_block(struct o2hb_region *reg,
struct o2hb_disk_slot *slot;
struct o2hb_disk_heartbeat_block *hb_block;
- node_num = o2nm_this_node();
+ node_num = reg->hr_node_num;
+ if (node_num >= O2NM_MAX_NODES)
+ return;
+
slot = ®->hr_slots[node_num];
hb_block = (struct o2hb_disk_heartbeat_block *)slot->ds_raw_block;
@@ -1214,7 +1226,7 @@ static int o2hb_thread(void *data)
set_user_nice(current, MIN_NICE);
/* Pin node */
- ret = o2nm_depend_this_node();
+ ret = o2nm_depend_node(reg->hr_node_num);
if (ret) {
mlog(ML_ERROR, "Node has been deleted, ret = %d\n", ret);
reg->hr_node_deleted = 1;
@@ -1223,7 +1235,8 @@ static int o2hb_thread(void *data)
}
while (!kthread_should_stop() &&
- !reg->hr_unclean_stop && !reg->hr_aborted_start) {
+ !reg->hr_unclean_stop && !reg->hr_aborted_start &&
+ o2nm_this_node() == reg->hr_node_num) {
/* We track the time spent inside
* o2hb_do_disk_heartbeat so that we avoid more than
* hr_timeout_ms between disk writes. On busy systems
@@ -1272,7 +1285,7 @@ static int o2hb_thread(void *data)
}
/* Unpin node */
- o2nm_undepend_this_node();
+ o2nm_undepend_node(reg->hr_node_num);
mlog(ML_HEARTBEAT|ML_KTHREAD, "o2hb thread exiting\n");
@@ -1784,7 +1797,8 @@ static ssize_t o2hb_region_dev_store(struct config_item *item,
/* We can't heartbeat without having had our node number
* configured yet. */
- if (o2nm_this_node() == O2NM_MAX_NODES)
+ reg->hr_node_num = o2nm_this_node();
+ if (reg->hr_node_num == O2NM_MAX_NODES)
return -EINVAL;
ret = kstrtol(p, 0, &fd);
@@ -2017,6 +2031,7 @@ static struct config_item *o2hb_heartbeat_group_make_item(struct config_group *g
ret = -ENAMETOOLONG;
goto free;
}
+ reg->hr_node_num = O2NM_MAX_NODES;
spin_lock(&o2hb_live_lock);
reg->hr_region_num = 0;
diff --git a/fs/ocfs2/cluster/nodemanager.c b/fs/ocfs2/cluster/nodemanager.c
index 5fffbed779da7..46e0c9ba8a4ff 100644
--- a/fs/ocfs2/cluster/nodemanager.c
+++ b/fs/ocfs2/cluster/nodemanager.c
@@ -366,6 +366,7 @@ static ssize_t o2nm_node_local_store(struct config_item *item, const char *page,
if (!tmp && cluster->cl_has_local &&
cluster->cl_local_node == node->nd_num) {
o2net_stop_listening(node);
+ cluster->cl_has_local = 0;
cluster->cl_local_node = O2NM_INVALID_NODE_NUM;
}
@@ -787,12 +788,12 @@ void o2nm_undepend_item(struct config_item *item)
configfs_undepend_item(item);
}
-int o2nm_depend_this_node(void)
+int o2nm_depend_node(u8 node_num)
{
int ret = 0;
struct o2nm_node *local_node;
- local_node = o2nm_get_node_by_num(o2nm_this_node());
+ local_node = o2nm_get_node_by_num(node_num);
if (!local_node) {
ret = -EINVAL;
goto out;
@@ -805,17 +806,27 @@ int o2nm_depend_this_node(void)
return ret;
}
-void o2nm_undepend_this_node(void)
+void o2nm_undepend_node(u8 node_num)
{
struct o2nm_node *local_node;
- local_node = o2nm_get_node_by_num(o2nm_this_node());
+ local_node = o2nm_get_node_by_num(node_num);
BUG_ON(!local_node);
o2nm_undepend_item(&local_node->nd_item);
o2nm_node_put(local_node);
}
+int o2nm_depend_this_node(void)
+{
+ return o2nm_depend_node(o2nm_this_node());
+}
+
+void o2nm_undepend_this_node(void)
+{
+ o2nm_undepend_node(o2nm_this_node());
+}
+
static void __exit exit_o2nm(void)
{
diff --git a/fs/ocfs2/cluster/nodemanager.h b/fs/ocfs2/cluster/nodemanager.h
index 2f72f56996bd9..ca3483fb54504 100644
--- a/fs/ocfs2/cluster/nodemanager.h
+++ b/fs/ocfs2/cluster/nodemanager.h
@@ -66,6 +66,8 @@ void o2nm_node_put(struct o2nm_node *node);
int o2nm_depend_item(struct config_item *item);
int o2nm_depend_item_unlocked(struct config_item *item);
void o2nm_undepend_item(struct config_item *item);
+int o2nm_depend_node(u8 node_num);
+void o2nm_undepend_node(u8 node_num);
int o2nm_depend_this_node(void);
void o2nm_undepend_this_node(void);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0868/1518] lib/string: fix memchr_inv() for large ranges
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (866 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0867/1518] ocfs2/cluster: keep heartbeat local node stable Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0869/1518] pps: dont try to wait for negative timeouts in PPS_FETCH Greg Kroah-Hartman
` (130 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bradley Morgan, Akinbou Mita,
Andy Shevchenko, Christoph Lameer, Joern Engel, Kees Cook,
Pekka Enberg, Andrew Morton, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bradley Morgan <include@grrlz.net>
[ Upstream commit c04cffb8c51618538f0c05c478a931eb6e1a806b ]
memchr_inv() takes a size_t length but counts 8 byte words in an unsigned
int. At 32GiB that count wraps, so the scan can quietly miss most of the
range.
Use size_t for the word count.
Link: https://lore.kernel.org/20260621121133.16460-1-include@grrlz.net
Fixes: 798248206b59 ("lib/string.c: introduce memchr_inv()")
Signed-off-by: Bradley Morgan <include@grrlz.net>
Cc: Akinbou Mita <akinobu.mita@gmail.com>
Cc: Andy Shevchenko <andy@kernel.org>
Cc: Christoph Lameer <cl@linux-foundation.org>
Cc: Joern Engel <joern@logfs.org>
Cc: Kees Cook <kees@kernel.org>
Cc: Pekka Enberg <penberg@kernel.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
lib/string.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/lib/string.c b/lib/string.c
index b632c71df1a50..01c9845024b85 100644
--- a/lib/string.c
+++ b/lib/string.c
@@ -839,7 +839,8 @@ void *memchr_inv(const void *start, int c, size_t bytes)
{
u8 value = c;
u64 value64;
- unsigned int words, prefix;
+ size_t words;
+ unsigned int prefix;
if (bytes <= 16)
return check_bytes8(start, value, bytes);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0869/1518] pps: dont try to wait for negative timeouts in PPS_FETCH
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (867 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0868/1518] lib/string: fix memchr_inv() for large ranges Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0870/1518] pps: pps-gpio: split IRQ handler into hardirq timestamper + threaded handler Greg Kroah-Hartman
` (129 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Calvin Owens, Sashiko,
Rodolfo Giometti, Andrew Morton, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Calvin Owens <calvin@wbinvd.org>
[ Upstream commit 45217e98987a87ff2372386dbf82fd5325db28ea ]
If userspace passes a negative timeout to PPS_FETCH, it triggers a kernel
splat from schedule_timeout():
schedule_timeout: wrong timeout value fffffffffff0bfb4
CPU: 17 UID: 0 PID: 4720 Comm: a.out Not tainted 7.1.0-rc5-x86-kvm-00150-g331d97e36b37 #1 PREEMPT_RT
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-20240910_120124-localhost 04/01/2014
Call Trace:
<TASK>
dump_stack_lvl+0x4b/0x70
schedule_timeout+0xb7/0xe0
pps_cdev_pps_fetch.isra.0+0x93/0x150
pps_cdev_ioctl+0x70/0x310
__x64_sys_ioctl+0x7b/0xc0
do_syscall_64+0xb6/0xfc0
entry_SYSCALL_64_after_hwframe+0x4b/0x53
Here is a trivial reproducer that works with the PPS_CLIENT_KTIMER test
device enabled in the kernel:
#include <stdlib.h>
#include <fcntl.h>
#include <unistd.h>
#include <sys/ioctl.h>
#include <linux/pps.h>
#include <err.h>
int main() {
struct pps_fdata fdata;
int fd;
fd = open("/dev/pps0", O_RDWR);
if (fd == -1)
err(1, "Failed to open /dev/pps0");
fdata.timeout.sec = -1;
fdata.timeout.nsec = 0;
if (ioctl(fd, PPS_FETCH, &fdata))
err(2, "PPS_FETCH failed");
close(fd);
return 0;
}
Sashiko imagines this to be some sort of security problem, which is
obviously really silly. But I think it is still worth fixing, so buggy
userspace code can't trigger the splat.
Silence the splat by using timespec64_to_jiffies(), which hard limits the
timeout to LONG_MAX jiffies. To be safe, explicitly preserve the
-ETIMEDOUT return value userspace sees today if it passes a negative
timeout.
If you really squint, this is still a slight behavior change in that there
are "denormalized" combinations of tv_sec and tv_nsec which used to work
but will now return -ETIMEDOUT. I can't imagine anybody will care about
that...
Link: https://lore.kernel.org/c5c97c3b3c9d66010382094fd538e59a38f4aacf.1781289959.git.calvin@wbinvd.org
Fixes: eae9d2ba0cfc ("LinuxPPS: core support")
Signed-off-by: Calvin Owens <calvin@wbinvd.org>
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://sashiko.dev/#/patchset/cover.1779733602.git.calvin%40wbinvd.org?part=3
Acked-by: Rodolfo Giometti <giometti@enneenne.com>
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pps/pps.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/drivers/pps/pps.c b/drivers/pps/pps.c
index c6b8b64782761..2e04636f43805 100644
--- a/drivers/pps/pps.c
+++ b/drivers/pps/pps.c
@@ -63,13 +63,19 @@ static int pps_cdev_pps_fetch(struct pps_device *pps, struct pps_fdata *fdata)
err = wait_event_interruptible(pps->queue,
ev != pps->last_ev);
else {
+ struct timespec64 ts;
unsigned long ticks;
dev_dbg(&pps->dev, "timeout %lld.%09d\n",
(long long) fdata->timeout.sec,
fdata->timeout.nsec);
- ticks = fdata->timeout.sec * HZ;
- ticks += fdata->timeout.nsec / (NSEC_PER_SEC / HZ);
+
+ if (fdata->timeout.sec < 0)
+ return -ETIMEDOUT;
+
+ ts.tv_sec = fdata->timeout.sec;
+ ts.tv_nsec = fdata->timeout.nsec;
+ ticks = timespec64_to_jiffies(&ts);
if (ticks != 0) {
err = wait_event_interruptible_timeout(
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0870/1518] pps: pps-gpio: split IRQ handler into hardirq timestamper + threaded handler
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (868 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0869/1518] pps: dont try to wait for negative timeouts in PPS_FETCH Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0871/1518] pps-gpio: remove dead capture_clear code Greg Kroah-Hartman
` (128 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Byczkowski, Calvin Owens,
Sebastian Andrzej Siewior, Rodolfo Giometti, Andrew Morton,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Michael Byczkowski <by@by-online.de>
[ Upstream commit 93781560b2fdd26fa8499d64db8a95a07e1dc902 ]
Split the pps-gpio interrupt handler into a primary (hardirq) handler that
captures the PPS timestamp at interrupt entry, and a threaded handler that
processes the event. This produces the same two-part handler structure on
both PREEMPT_RT and non-RT kernels.
On non-RT kernels the threaded portion runs immediately after the primary,
with no behavioral change compared to the previous single-handler
implementation.
On PREEMPT_RT, where interrupt handlers are force-threaded by default, the
previous single-handler implementation captured the timestamp inside the
threaded portion, after IRQ-thread scheduling delay. With the split, the
timestamp is captured in true hardirq context as it is on non-RT kernels,
eliminating a significant source of PPS jitter on RT systems.
Link: https://lore.kernel.org/2e32729029fbf6977ecf04665eb00f2efd3e2c17.1780359378.git.calvin@wbinvd.org
Signed-off-by: Michael Byczkowski <by@by-online.de>
Signed-off-by: Calvin Owens <calvin@wbinvd.org>
Reviewed-by: Sebastian Andrzej Siewior <bigeasy@linutronix.de>
Tested-by: Michael Byczkowski <by@by-online.de>
Tested-by: Calvin Owens <calvin@wbinvd.org>
Acked-by: Rodolfo Giometti <giometti@enneenne.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Stable-dep-of: b899e0279f90 ("pps-gpio: remove dead capture_clear code")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pps/clients/pps-gpio.c | 37 +++++++++++++++++++++++-----------
1 file changed, 25 insertions(+), 12 deletions(-)
diff --git a/drivers/pps/clients/pps-gpio.c b/drivers/pps/clients/pps-gpio.c
index 935da68610c70..ed111621ee5f9 100644
--- a/drivers/pps/clients/pps-gpio.c
+++ b/drivers/pps/clients/pps-gpio.c
@@ -35,33 +35,44 @@ struct pps_gpio_device_data {
bool capture_clear;
unsigned int echo_active_ms; /* PPS echo active duration */
unsigned long echo_timeout; /* timer timeout value in jiffies */
+ struct pps_event_time ts; /* timestamp captured in hardirq */
};
/*
* Report the PPS event
*/
-static irqreturn_t pps_gpio_irq_handler(int irq, void *data)
+/*
+ * Primary hardirq handler -- runs in hardirq context even on PREEMPT_RT.
+ * Only captures the timestamp; all other work is deferred to the thread.
+ */
+static irqreturn_t pps_gpio_irq_hardirq(int irq, void *data)
{
- const struct pps_gpio_device_data *info;
- struct pps_event_time ts;
- int rising_edge;
+ struct pps_gpio_device_data *info = data;
+
+ pps_get_ts(&info->ts);
- /* Get the time stamp first */
- pps_get_ts(&ts);
+ return IRQ_WAKE_THREAD;
+}
- info = data;
+/*
+ * Threaded handler -- processes the PPS event using the timestamp
+ * captured in hardirq context above.
+ */
+static irqreturn_t pps_gpio_irq_thread(int irq, void *data)
+{
+ struct pps_gpio_device_data *info = data;
+ int rising_edge;
- /* Small trick to bypass the check on edge's direction when capture_clear is unset */
rising_edge = info->capture_clear ?
gpiod_get_value(info->gpio_pin) : !info->assert_falling_edge;
if ((rising_edge && !info->assert_falling_edge) ||
(!rising_edge && info->assert_falling_edge))
- pps_event(info->pps, &ts, PPS_CAPTUREASSERT, data);
+ pps_event(info->pps, &info->ts, PPS_CAPTUREASSERT, data);
else if (info->capture_clear &&
((rising_edge && info->assert_falling_edge) ||
(!rising_edge && !info->assert_falling_edge)))
- pps_event(info->pps, &ts, PPS_CAPTURECLEAR, data);
+ pps_event(info->pps, &info->ts, PPS_CAPTURECLEAR, data);
else
dev_warn_ratelimited(&info->pps->dev, "IRQ did not trigger any PPS event\n");
@@ -210,8 +221,10 @@ static int pps_gpio_probe(struct platform_device *pdev)
}
/* register IRQ interrupt handler */
- ret = request_irq(data->irq, pps_gpio_irq_handler,
- get_irqf_trigger_flags(data), data->info.name, data);
+ ret = request_threaded_irq(data->irq,
+ pps_gpio_irq_hardirq, pps_gpio_irq_thread,
+ get_irqf_trigger_flags(data) | IRQF_ONESHOT,
+ data->info.name, data);
if (ret) {
pps_unregister_source(data->pps);
dev_err(dev, "failed to acquire IRQ %d\n", data->irq);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0871/1518] pps-gpio: remove dead capture_clear code
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (869 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0870/1518] pps: pps-gpio: split IRQ handler into hardirq timestamper + threaded handler Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0872/1518] rapidio: clear mport->net when rio_add_net() fails Greg Kroah-Hartman
` (127 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Calvin Owens, Rodolfo Giometti,
Andrew Morton, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Calvin Owens <calvin@wbinvd.org>
[ Upstream commit b899e0279f90c3ce4099d68b989dd27861cc5c4f ]
The capture_clear field is never set, and all code conditional on it being
set has been unreachable since the platform data logic was removed from
pps-gpio in ee89646619ba ("pps: clients: gpio: Get rid of legacy platform
data").
I think the only logical thing to do here is to remove it all, since no
in-tree code ever actually used it in the first place, and it has been
completely dead code for over five years (since v5.13).
Sashiko asked some questions about the gpiod_get_value() call which caused
me to look deeper and figure this out, but it did not actually notice
capture_clear is never set.
Link: https://lore.kernel.org/f70196bafcf75d9782dd36ed784e42345b6e8a1b.1783355507.git.calvin@wbinvd.org
Fixes: ee89646619ba ("pps: clients: gpio: Get rid of legacy platform data")
Signed-off-by: Calvin Owens <calvin@wbinvd.org>
Closes: https://sashiko.dev/#/patchset/cover.1779733602.git.calvin%40wbinvd.org?part=1
Acked-by: Rodolfo Giometti <giometti@enneenne.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pps/clients/pps-gpio.c | 37 ++++------------------------------
1 file changed, 4 insertions(+), 33 deletions(-)
diff --git a/drivers/pps/clients/pps-gpio.c b/drivers/pps/clients/pps-gpio.c
index ed111621ee5f9..1eba112afeb80 100644
--- a/drivers/pps/clients/pps-gpio.c
+++ b/drivers/pps/clients/pps-gpio.c
@@ -32,7 +32,6 @@ struct pps_gpio_device_data {
struct gpio_desc *echo_pin;
struct timer_list echo_timer; /* timer to reset echo active state */
bool assert_falling_edge;
- bool capture_clear;
unsigned int echo_active_ms; /* PPS echo active duration */
unsigned long echo_timeout; /* timer timeout value in jiffies */
struct pps_event_time ts; /* timestamp captured in hardirq */
@@ -62,19 +61,8 @@ static irqreturn_t pps_gpio_irq_hardirq(int irq, void *data)
static irqreturn_t pps_gpio_irq_thread(int irq, void *data)
{
struct pps_gpio_device_data *info = data;
- int rising_edge;
-
- rising_edge = info->capture_clear ?
- gpiod_get_value(info->gpio_pin) : !info->assert_falling_edge;
- if ((rising_edge && !info->assert_falling_edge) ||
- (!rising_edge && info->assert_falling_edge))
- pps_event(info->pps, &info->ts, PPS_CAPTUREASSERT, data);
- else if (info->capture_clear &&
- ((rising_edge && info->assert_falling_edge) ||
- (!rising_edge && !info->assert_falling_edge)))
- pps_event(info->pps, &info->ts, PPS_CAPTURECLEAR, data);
- else
- dev_warn_ratelimited(&info->pps->dev, "IRQ did not trigger any PPS event\n");
+
+ pps_event(info->pps, &info->ts, PPS_CAPTUREASSERT, data);
return IRQ_HANDLED;
}
@@ -90,11 +78,6 @@ static void pps_gpio_echo(struct pps_device *pps, int event, void *data)
if (pps->params.mode & PPS_ECHOASSERT)
gpiod_set_value(info->echo_pin, 1);
break;
-
- case PPS_CAPTURECLEAR:
- if (pps->params.mode & PPS_ECHOCLEAR)
- gpiod_set_value(info->echo_pin, 1);
- break;
}
/* fire the timer */
@@ -156,15 +139,8 @@ static int pps_gpio_setup(struct device *dev)
static unsigned long
get_irqf_trigger_flags(const struct pps_gpio_device_data *data)
{
- unsigned long flags = data->assert_falling_edge ?
- IRQF_TRIGGER_FALLING : IRQF_TRIGGER_RISING;
-
- if (data->capture_clear) {
- flags |= ((flags & IRQF_TRIGGER_RISING) ?
- IRQF_TRIGGER_FALLING : IRQF_TRIGGER_RISING);
- }
-
- return flags;
+ return data->assert_falling_edge ? IRQF_TRIGGER_FALLING :
+ IRQF_TRIGGER_RISING;
}
static int pps_gpio_probe(struct platform_device *pdev)
@@ -197,9 +173,6 @@ static int pps_gpio_probe(struct platform_device *pdev)
/* initialize PPS specific parts of the bookkeeping data structure. */
data->info.mode = PPS_CAPTUREASSERT | PPS_OFFSETASSERT |
PPS_ECHOASSERT | PPS_CANWAIT | PPS_TSFMT_TSPEC;
- if (data->capture_clear)
- data->info.mode |= PPS_CAPTURECLEAR | PPS_OFFSETCLEAR |
- PPS_ECHOCLEAR;
data->info.owner = THIS_MODULE;
snprintf(data->info.name, PPS_MAX_NAME_LEN - 1, "%s.%d",
pdev->name, pdev->id);
@@ -211,8 +184,6 @@ static int pps_gpio_probe(struct platform_device *pdev)
/* register PPS source */
pps_default_params = PPS_CAPTUREASSERT | PPS_OFFSETASSERT;
- if (data->capture_clear)
- pps_default_params |= PPS_CAPTURECLEAR | PPS_OFFSETCLEAR;
data->pps = pps_register_source(&data->info, pps_default_params);
if (IS_ERR(data->pps)) {
dev_err(dev, "failed to register IRQ %d as PPS source\n",
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0872/1518] rapidio: clear mport->net when rio_add_net() fails
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (870 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0871/1518] pps-gpio: remove dead capture_clear code Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0873/1518] fat: release buffer head after rebuilding parent Greg Kroah-Hartman
` (126 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Guangshuo Li, Alexandre Bounine,
Matt Porter, Yang yingliang, Andrew Morton, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Guangshuo Li <lgs201920130244@gmail.com>
[ Upstream commit b74030fbf187b43c1f85b66a7082e9946511cb5d ]
rio_alloc_net() stores the newly allocated rio_net in mport->net before
rio_scan_alloc_net() registers the device.
If rio_add_net() fails, rio_scan_alloc_net() drops the device reference
with put_device(), which releases the rio_net through the device release
callback. However, mport->net is left pointing at the freed object.
A later mport unregister path can then dereference the dangling mport->net
pointer and may try to free the same rio_net again.
Clear mport->net in the rio_add_net() failure path, matching the cleanup
done for the destID table allocation failure path.
Link: https://lore.kernel.org/20260708070628.721010-1-lgs201920130244@gmail.com
Fixes: e842f9a1edf3 ("rapidio: add check for rio_add_net() in rio_scan_alloc_net()")
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Cc: Alexandre Bounine <alex.bou9@gmail.com>
Cc: Matt Porter <mporter@kernel.crashing.org>
Cc: Yang yingliang <yangyingliang@huawei.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/rapidio/rio-scan.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/rapidio/rio-scan.c b/drivers/rapidio/rio-scan.c
index dcd6619a4b027..3cc25d0534513 100644
--- a/drivers/rapidio/rio-scan.c
+++ b/drivers/rapidio/rio-scan.c
@@ -874,6 +874,7 @@ static struct rio_net *rio_scan_alloc_net(struct rio_mport *mport,
net->dev.release = rio_scan_release_dev;
if (rio_add_net(net)) {
put_device(&net->dev);
+ mport->net = NULL;
net = NULL;
}
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0873/1518] fat: release buffer head after rebuilding parent
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (871 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0872/1518] rapidio: clear mport->net when rio_add_net() fails Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0874/1518] riscv: dts: sophgo: cv180x: Allow the DMA multiplexer to set channel number for DMA controller Greg Kroah-Hartman
` (125 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yichong Chen, OGAWA Hirofumi,
Christian Brauner, Amit Sahrawat, Namjae Jeon, Ravishankar N,
Andrew Morton, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yichong Chen <chenyichong@uniontech.com>
[ Upstream commit 83e98dbf19ab64e8528e101e20f8d50e1aaa68a8 ]
fat_scan_logstart() leaves the matching directory entry's buffer head in
sinfo.bh for the caller to release, just like fat_scan().
fat_rebuild_parent() uses the directory entry to rebuild the parent inode
for the nostale_ro NFS export path, but does not release sinfo.bh after a
successful scan. Release it once fat_build_inode() has consumed the
directory entry data.
Link: https://lore.kernel.org/20260715020957.1096309-1-chenyichong@uniontech.com
Fixes: f1e6fb0ab451 ("fat (exportfs): rebuild directory-inode if fat_dget()")
Signed-off-by: Yichong Chen <chenyichong@uniontech.com>
Acked-by: OGAWA Hirofumi <hirofumi@mail.parknet.co.jp>
Cc: Christian Brauner <brauner@kernel.org>
Cc: Amit Sahrawat <a.sahrawat@samsung.com>
Cc: chenyichong <chenyichong@uniontech.com>
Cc: Namjae Jeon <namjae.jeon@samsung.com>
Cc: Ravishankar N <ravi.n1@samsung.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/fat/nfs.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/fs/fat/nfs.c b/fs/fat/nfs.c
index 509eea96a457d..6e1b371711edd 100644
--- a/fs/fat/nfs.c
+++ b/fs/fat/nfs.c
@@ -250,8 +250,10 @@ struct inode *fat_rebuild_parent(struct super_block *sb, int parent_logstart)
MSDOS_I(dummy_grand_parent)->i_pos = -1;
}
- if (!fat_scan_logstart(dummy_grand_parent, clus_to_match, &sinfo))
+ if (!fat_scan_logstart(dummy_grand_parent, clus_to_match, &sinfo)) {
parent = fat_build_inode(sb, sinfo.de, sinfo.i_pos);
+ brelse(sinfo.bh);
+ }
brelse(parent_bh);
iput(dummy_grand_parent);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0874/1518] riscv: dts: sophgo: cv180x: Allow the DMA multiplexer to set channel number for DMA controller
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (872 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0873/1518] fat: release buffer head after rebuilding parent Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0875/1518] drm/omap: dsi: Do not copy isr table Greg Kroah-Hartman
` (124 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Anton D. Stavinskii, Inochi Amaoto,
Chen Wang, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Inochi Amaoto <inochiama@gmail.com>
[ Upstream commit 5011466bade64483bb52bc4a926719d6794e6dab ]
Change the DMA controller compatible to the sophgo,cv1800b-axi-dma,
which supports setting DMA channel number in DMA phandle args.
This dts change does not break backward compatibility as a fallback
compatiable string is added.
Fixes: 514951a81a5e ("riscv: dts: sophgo: cv18xx: add DMA controller")
Reported-by: Anton D. Stavinskii <stavinsky@gmail.com>
Closes: https://github.com/sophgo/linux/issues/9
Tested-by: Anton D. Stavinskii <stavinsky@gmail.com>
Link: https://patch.msgid.link/20260511063818.463877-3-inochiama@gmail.com
Signed-off-by: Inochi Amaoto <inochiama@gmail.com>
Signed-off-by: Chen Wang <chen.wang@linux.dev>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/riscv/boot/dts/sophgo/cv180x.dtsi | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/riscv/boot/dts/sophgo/cv180x.dtsi b/arch/riscv/boot/dts/sophgo/cv180x.dtsi
index ccdb454986535..b2453ae452164 100644
--- a/arch/riscv/boot/dts/sophgo/cv180x.dtsi
+++ b/arch/riscv/boot/dts/sophgo/cv180x.dtsi
@@ -391,7 +391,7 @@ sdhci1: mmc@4320000 {
};
dmac: dma-controller@4330000 {
- compatible = "snps,axi-dma-1.01a";
+ compatible = "sophgo,cv1800b-axi-dma", "snps,axi-dma-1.01a";
reg = <0x04330000 0x1000>;
interrupts = <SOC_PERIPHERAL_IRQ(13) IRQ_TYPE_LEVEL_HIGH>;
clocks = <&clk CLK_SDMA_AXI>, <&clk CLK_SDMA_AXI>;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0875/1518] drm/omap: dsi: Do not copy isr table
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (873 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0874/1518] riscv: dts: sophgo: cv180x: Allow the DMA multiplexer to set channel number for DMA controller Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0876/1518] arm64: dts: qcom: agatti: Add missing CX power domain to DISPCC Greg Kroah-Hartman
` (123 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Andreas Kemnade, Tomi Valkeinen,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Andreas Kemnade <andreas@kemnade.info>
[ Upstream commit 97c03b32b28a9f7f13f768f2b06e1eaafe850e66 ]
To be able to unregister stuff from isrs, the corresponding table was
copied. Nobody seems to unregister stuff that way, so it does not help.
But there are stack-allocated objects passed to these isrs giving chances
of UAF of these objects if irqs are unregistered while they are handled,
so better do not copy that table.
Fixes: 4ae2ddddf44cd ("OMAP: DSS2: DSI: Add ISR support")
Signed-off-by: Andreas Kemnade <andreas@kemnade.info>
Link: https://patch.msgid.link/20260702-dsi-uaf-v2-1-dbb4aa0f0b8e@kemnade.info
Signed-off-by: Tomi Valkeinen <tomi.valkeinen@ideasonboard.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/omapdrm/dss/dsi.c | 7 +------
drivers/gpu/drm/omapdrm/dss/dsi.h | 2 --
2 files changed, 1 insertion(+), 8 deletions(-)
diff --git a/drivers/gpu/drm/omapdrm/dss/dsi.c b/drivers/gpu/drm/omapdrm/dss/dsi.c
index b129e5a8d7915..7bfd7eb32eba3 100644
--- a/drivers/gpu/drm/omapdrm/dss/dsi.c
+++ b/drivers/gpu/drm/omapdrm/dss/dsi.c
@@ -455,15 +455,10 @@ static irqreturn_t omap_dsi_irq_handler(int irq, void *arg)
timer_delete(&dsi->te_timer);
#endif
- /* make a copy and unlock, so that isrs can unregister
- * themselves */
- memcpy(&dsi->isr_tables_copy, &dsi->isr_tables,
- sizeof(dsi->isr_tables));
+ dsi_handle_isrs(&dsi->isr_tables, irqstatus, vcstatus, ciostatus);
spin_unlock(&dsi->irq_lock);
- dsi_handle_isrs(&dsi->isr_tables_copy, irqstatus, vcstatus, ciostatus);
-
dsi_handle_irq_errors(dsi, irqstatus, vcstatus, ciostatus);
dsi_collect_irq_stats(dsi, irqstatus, vcstatus, ciostatus);
diff --git a/drivers/gpu/drm/omapdrm/dss/dsi.h b/drivers/gpu/drm/omapdrm/dss/dsi.h
index 601707c0ecc4e..2b25247ea8935 100644
--- a/drivers/gpu/drm/omapdrm/dss/dsi.h
+++ b/drivers/gpu/drm/omapdrm/dss/dsi.h
@@ -379,8 +379,6 @@ struct dsi_data {
spinlock_t irq_lock;
struct dsi_isr_tables isr_tables;
- /* space for a copy used by the interrupt handler */
- struct dsi_isr_tables isr_tables_copy;
int update_vc;
#ifdef DSI_PERF_MEASURE
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0876/1518] arm64: dts: qcom: agatti: Add missing CX power domain to DISPCC
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (874 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0875/1518] drm/omap: dsi: Do not copy isr table Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0877/1518] remoteproc: Move resource table data structure to its own header Greg Kroah-Hartman
` (122 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dmitry Baryshkov, Konrad Dybcio,
Imran Shaik, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Imran Shaik <imran.shaik@oss.qualcomm.com>
[ Upstream commit 26d7b23caa4b1d8208e28c5981a85cf83e658e7c ]
Add the missing power-domains property to associate DISPCC with CX rail.
This is to ensure the genpd performance state votes on the GDSC to get
propagated to the CX rail and to avoid the rail under-voltage conditions.
Fixes: a2b32096709d ("arm64: dts: qcom: qcm2290: Add display nodes")
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Imran Shaik <imran.shaik@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260718-shikra-dispcc-gpucc-v6-12-62703e05ef0f@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/qcm2290.dtsi | 1 +
1 file changed, 1 insertion(+)
diff --git a/arch/arm64/boot/dts/qcom/qcm2290.dtsi b/arch/arm64/boot/dts/qcom/qcm2290.dtsi
index e0e400fdd2497..5a817824f924b 100644
--- a/arch/arm64/boot/dts/qcom/qcm2290.dtsi
+++ b/arch/arm64/boot/dts/qcom/qcm2290.dtsi
@@ -2006,6 +2006,7 @@ dispcc: clock-controller@5f00000 {
"gcc_disp_gpll0_div_clk_src",
"dsi0_phy_pll_out_byteclk",
"dsi0_phy_pll_out_dsiclk";
+ power-domains = <&rpmpd QCM2290_VDDCX>;
#power-domain-cells = <1>;
#clock-cells = <1>;
#reset-cells = <1>;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0877/1518] remoteproc: Move resource table data structure to its own header
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (875 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0876/1518] arm64: dts: qcom: agatti: Add missing CX power domain to DISPCC Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0878/1518] remoteproc: use rsc_table_for_each_entry() in rproc_handle_resources() Greg Kroah-Hartman
` (121 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Mukesh Ojha, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
[ Upstream commit 0590420c2f90de497d342c9a41a618f46f4d09ab ]
The resource table data structure has traditionally been associated with
the remoteproc framework, where the resource table is included as a
section within the remote processor firmware binary. However, it is also
possible to obtain the resource table through other means—such as from a
reserved memory region populated by the boot firmware, statically
maintained driver data, or via a secure SMC call—when it is not embedded
in the firmware.
There are multiple Qualcomm remote processors (e.g., Venus, Iris, GPU,
etc.) in the upstream kernel that do not use the remoteproc framework to
manage their lifecycle for various reasons.
When Linux is running at EL2, similar to the Qualcomm PAS driver
(qcom_q6v5_pas.c), client drivers for subsystems like video and GPU may
also want to use the resource table SMC call to retrieve and map
resources before they are used by the remote processor.
In such cases, the resource table data structure is no longer tightly
coupled with the remoteproc headers. Client drivers that do not use the
remoteproc framework should still be able to parse the resource table
obtained through alternative means. Therefore, there is a need to
decouple the resource table definitions from the remoteproc headers.
Signed-off-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260506050107.1985033-2-mukesh.ojha@oss.qualcomm.com
Stable-dep-of: bb840ea69347 ("remoteproc: fix OOB read via signed offset in rsc_table_for_each_entry()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/remoteproc.h | 269 +-------------------------------
include/linux/rsc_table.h | 306 +++++++++++++++++++++++++++++++++++++
2 files changed, 307 insertions(+), 268 deletions(-)
create mode 100644 include/linux/rsc_table.h
diff --git a/include/linux/remoteproc.h b/include/linux/remoteproc.h
index 023fa91bd2a48..de98462d58889 100644
--- a/include/linux/remoteproc.h
+++ b/include/linux/remoteproc.h
@@ -43,274 +43,7 @@
#include <linux/completion.h>
#include <linux/idr.h>
#include <linux/of.h>
-
-/**
- * struct resource_table - firmware resource table header
- * @ver: version number
- * @num: number of resource entries
- * @reserved: reserved (must be zero)
- * @offset: array of offsets pointing at the various resource entries
- *
- * A resource table is essentially a list of system resources required
- * by the remote processor. It may also include configuration entries.
- * If needed, the remote processor firmware should contain this table
- * as a dedicated ".resource_table" ELF section.
- *
- * Some resources entries are mere announcements, where the host is informed
- * of specific remoteproc configuration. Other entries require the host to
- * do something (e.g. allocate a system resource). Sometimes a negotiation
- * is expected, where the firmware requests a resource, and once allocated,
- * the host should provide back its details (e.g. address of an allocated
- * memory region).
- *
- * The header of the resource table, as expressed by this structure,
- * contains a version number (should we need to change this format in the
- * future), the number of available resource entries, and their offsets
- * in the table.
- *
- * Immediately following this header are the resource entries themselves,
- * each of which begins with a resource entry header (as described below).
- */
-struct resource_table {
- u32 ver;
- u32 num;
- u32 reserved[2];
- u32 offset[];
-} __packed;
-
-/**
- * struct fw_rsc_hdr - firmware resource entry header
- * @type: resource type
- * @data: resource data
- *
- * Every resource entry begins with a 'struct fw_rsc_hdr' header providing
- * its @type. The content of the entry itself will immediately follow
- * this header, and it should be parsed according to the resource type.
- */
-struct fw_rsc_hdr {
- u32 type;
- u8 data[];
-} __packed;
-
-/**
- * enum fw_resource_type - types of resource entries
- *
- * @RSC_CARVEOUT: request for allocation of a physically contiguous
- * memory region.
- * @RSC_DEVMEM: request to iommu_map a memory-based peripheral.
- * @RSC_TRACE: announces the availability of a trace buffer into which
- * the remote processor will be writing logs.
- * @RSC_VDEV: declare support for a virtio device, and serve as its
- * virtio header.
- * @RSC_LAST: just keep this one at the end of standard resources
- * @RSC_VENDOR_START: start of the vendor specific resource types range
- * @RSC_VENDOR_END: end of the vendor specific resource types range
- *
- * For more details regarding a specific resource type, please see its
- * dedicated structure below.
- *
- * Please note that these values are used as indices to the rproc_handle_rsc
- * lookup table, so please keep them sane. Moreover, @RSC_LAST is used to
- * check the validity of an index before the lookup table is accessed, so
- * please update it as needed.
- */
-enum fw_resource_type {
- RSC_CARVEOUT = 0,
- RSC_DEVMEM = 1,
- RSC_TRACE = 2,
- RSC_VDEV = 3,
- RSC_LAST = 4,
- RSC_VENDOR_START = 128,
- RSC_VENDOR_END = 512,
-};
-
-#define FW_RSC_ADDR_ANY (-1)
-
-/**
- * struct fw_rsc_carveout - physically contiguous memory request
- * @da: device address
- * @pa: physical address
- * @len: length (in bytes)
- * @flags: iommu protection flags
- * @reserved: reserved (must be zero)
- * @name: human-readable name of the requested memory region
- *
- * This resource entry requests the host to allocate a physically contiguous
- * memory region.
- *
- * These request entries should precede other firmware resource entries,
- * as other entries might request placing other data objects inside
- * these memory regions (e.g. data/code segments, trace resource entries, ...).
- *
- * Allocating memory this way helps utilizing the reserved physical memory
- * (e.g. CMA) more efficiently, and also minimizes the number of TLB entries
- * needed to map it (in case @rproc is using an IOMMU). Reducing the TLB
- * pressure is important; it may have a substantial impact on performance.
- *
- * If the firmware is compiled with static addresses, then @da should specify
- * the expected device address of this memory region. If @da is set to
- * FW_RSC_ADDR_ANY, then the host will dynamically allocate it, and then
- * overwrite @da with the dynamically allocated address.
- *
- * We will always use @da to negotiate the device addresses, even if it
- * isn't using an iommu. In that case, though, it will obviously contain
- * physical addresses.
- *
- * Some remote processors needs to know the allocated physical address
- * even if they do use an iommu. This is needed, e.g., if they control
- * hardware accelerators which access the physical memory directly (this
- * is the case with OMAP4 for instance). In that case, the host will
- * overwrite @pa with the dynamically allocated physical address.
- * Generally we don't want to expose physical addresses if we don't have to
- * (remote processors are generally _not_ trusted), so we might want to
- * change this to happen _only_ when explicitly required by the hardware.
- *
- * @flags is used to provide IOMMU protection flags, and @name should
- * (optionally) contain a human readable name of this carveout region
- * (mainly for debugging purposes).
- */
-struct fw_rsc_carveout {
- u32 da;
- u32 pa;
- u32 len;
- u32 flags;
- u32 reserved;
- u8 name[32];
-} __packed;
-
-/**
- * struct fw_rsc_devmem - iommu mapping request
- * @da: device address
- * @pa: physical address
- * @len: length (in bytes)
- * @flags: iommu protection flags
- * @reserved: reserved (must be zero)
- * @name: human-readable name of the requested region to be mapped
- *
- * This resource entry requests the host to iommu map a physically contiguous
- * memory region. This is needed in case the remote processor requires
- * access to certain memory-based peripherals; _never_ use it to access
- * regular memory.
- *
- * This is obviously only needed if the remote processor is accessing memory
- * via an iommu.
- *
- * @da should specify the required device address, @pa should specify
- * the physical address we want to map, @len should specify the size of
- * the mapping and @flags is the IOMMU protection flags. As always, @name may
- * (optionally) contain a human readable name of this mapping (mainly for
- * debugging purposes).
- *
- * Note: at this point we just "trust" those devmem entries to contain valid
- * physical addresses, but this isn't safe and will be changed: eventually we
- * want remoteproc implementations to provide us ranges of physical addresses
- * the firmware is allowed to request, and not allow firmwares to request
- * access to physical addresses that are outside those ranges.
- */
-struct fw_rsc_devmem {
- u32 da;
- u32 pa;
- u32 len;
- u32 flags;
- u32 reserved;
- u8 name[32];
-} __packed;
-
-/**
- * struct fw_rsc_trace - trace buffer declaration
- * @da: device address
- * @len: length (in bytes)
- * @reserved: reserved (must be zero)
- * @name: human-readable name of the trace buffer
- *
- * This resource entry provides the host information about a trace buffer
- * into which the remote processor will write log messages.
- *
- * @da specifies the device address of the buffer, @len specifies
- * its size, and @name may contain a human readable name of the trace buffer.
- *
- * After booting the remote processor, the trace buffers are exposed to the
- * user via debugfs entries (called trace0, trace1, etc..).
- */
-struct fw_rsc_trace {
- u32 da;
- u32 len;
- u32 reserved;
- u8 name[32];
-} __packed;
-
-/**
- * struct fw_rsc_vdev_vring - vring descriptor entry
- * @da: device address
- * @align: the alignment between the consumer and producer parts of the vring
- * @num: num of buffers supported by this vring (must be power of two)
- * @notifyid: a unique rproc-wide notify index for this vring. This notify
- * index is used when kicking a remote processor, to let it know that this
- * vring is triggered.
- * @pa: physical address
- *
- * This descriptor is not a resource entry by itself; it is part of the
- * vdev resource type (see below).
- *
- * Note that @da should either contain the device address where
- * the remote processor is expecting the vring, or indicate that
- * dynamically allocation of the vring's device address is supported.
- */
-struct fw_rsc_vdev_vring {
- u32 da;
- u32 align;
- u32 num;
- u32 notifyid;
- u32 pa;
-} __packed;
-
-/**
- * struct fw_rsc_vdev - virtio device header
- * @id: virtio device id (as in virtio_ids.h)
- * @notifyid: a unique rproc-wide notify index for this vdev. This notify
- * index is used when kicking a remote processor, to let it know that the
- * status/features of this vdev have changes.
- * @dfeatures: specifies the virtio device features supported by the firmware
- * @gfeatures: a place holder used by the host to write back the
- * negotiated features that are supported by both sides.
- * @config_len: the size of the virtio config space of this vdev. The config
- * space lies in the resource table immediate after this vdev header.
- * @status: a place holder where the host will indicate its virtio progress.
- * @num_of_vrings: indicates how many vrings are described in this vdev header
- * @reserved: reserved (must be zero)
- * @vring: an array of @num_of_vrings entries of 'struct fw_rsc_vdev_vring'.
- *
- * This resource is a virtio device header: it provides information about
- * the vdev, and is then used by the host and its peer remote processors
- * to negotiate and share certain virtio properties.
- *
- * By providing this resource entry, the firmware essentially asks remoteproc
- * to statically allocate a vdev upon registration of the rproc (dynamic vdev
- * allocation is not yet supported).
- *
- * Note:
- * 1. unlike virtualization systems, the term 'host' here means
- * the Linux side which is running remoteproc to control the remote
- * processors. We use the name 'gfeatures' to comply with virtio's terms,
- * though there isn't really any virtualized guest OS here: it's the host
- * which is responsible for negotiating the final features.
- * Yeah, it's a bit confusing.
- *
- * 2. immediately following this structure is the virtio config space for
- * this vdev (which is specific to the vdev; for more info, read the virtio
- * spec). The size of the config space is specified by @config_len.
- */
-struct fw_rsc_vdev {
- u32 id;
- u32 notifyid;
- u32 dfeatures;
- u32 gfeatures;
- u32 config_len;
- u8 status;
- u8 num_of_vrings;
- u8 reserved[2];
- struct fw_rsc_vdev_vring vring[];
-} __packed;
+#include <linux/rsc_table.h>
struct rproc;
diff --git a/include/linux/rsc_table.h b/include/linux/rsc_table.h
new file mode 100644
index 0000000000000..c32c8b6cd2a77
--- /dev/null
+++ b/include/linux/rsc_table.h
@@ -0,0 +1,306 @@
+/*
+ * Resource table and its types data structure
+ *
+ * Copyright(c) 2011 Texas Instruments, Inc.
+ * Copyright(c) 2011 Google, Inc.
+ * All rights reserved.
+ *
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted provided that the following conditions
+ * are met:
+ *
+ * * Redistributions of source code must retain the above copyright
+ * notice, this list of conditions and the following disclaimer.
+ * * Redistributions in binary form must reproduce the above copyright
+ * notice, this list of conditions and the following disclaimer in
+ * the documentation and/or other materials provided with the
+ * distribution.
+ * * Neither the name Texas Instruments nor the names of its
+ * contributors may be used to endorse or promote products derived
+ * from this software without specific prior written permission.
+ *
+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
+ * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
+ * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
+ * OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
+ * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
+ * LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
+ * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
+ * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
+ * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
+ * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+ */
+
+#ifndef RSC_TABLE_H
+#define RSC_TABLE_H
+
+/**
+ * struct resource_table - firmware resource table header
+ * @ver: version number
+ * @num: number of resource entries
+ * @reserved: reserved (must be zero)
+ * @offset: array of offsets pointing at the various resource entries
+ *
+ * A resource table is essentially a list of system resources required
+ * by the remote processor. It may also include configuration entries.
+ * If needed, the remote processor firmware should contain this table
+ * as a dedicated ".resource_table" ELF section.
+ *
+ * Some resources entries are mere announcements, where the host is informed
+ * of specific remoteproc configuration. Other entries require the host to
+ * do something (e.g. allocate a system resource). Sometimes a negotiation
+ * is expected, where the firmware requests a resource, and once allocated,
+ * the host should provide back its details (e.g. address of an allocated
+ * memory region).
+ *
+ * The header of the resource table, as expressed by this structure,
+ * contains a version number (should we need to change this format in the
+ * future), the number of available resource entries, and their offsets
+ * in the table.
+ *
+ * Immediately following this header are the resource entries themselves,
+ * each of which begins with a resource entry header (as described below).
+ */
+struct resource_table {
+ u32 ver;
+ u32 num;
+ u32 reserved[2];
+ u32 offset[];
+} __packed;
+
+/**
+ * struct fw_rsc_hdr - firmware resource entry header
+ * @type: resource type
+ * @data: resource data
+ *
+ * Every resource entry begins with a 'struct fw_rsc_hdr' header providing
+ * its @type. The content of the entry itself will immediately follow
+ * this header, and it should be parsed according to the resource type.
+ */
+struct fw_rsc_hdr {
+ u32 type;
+ u8 data[];
+} __packed;
+
+/**
+ * enum fw_resource_type - types of resource entries
+ *
+ * @RSC_CARVEOUT: request for allocation of a physically contiguous
+ * memory region.
+ * @RSC_DEVMEM: request to iommu_map a memory-based peripheral.
+ * @RSC_TRACE: announces the availability of a trace buffer into which
+ * the remote processor will be writing logs.
+ * @RSC_VDEV: declare support for a virtio device, and serve as its
+ * virtio header.
+ * @RSC_LAST: just keep this one at the end of standard resources
+ * @RSC_VENDOR_START: start of the vendor specific resource types range
+ * @RSC_VENDOR_END: end of the vendor specific resource types range
+ *
+ * For more details regarding a specific resource type, please see its
+ * dedicated structure below.
+ *
+ * Please note that these values are used as indices to the rproc_handle_rsc
+ * lookup table, so please keep them sane. Moreover, @RSC_LAST is used to
+ * check the validity of an index before the lookup table is accessed, so
+ * please update it as needed.
+ */
+enum fw_resource_type {
+ RSC_CARVEOUT = 0,
+ RSC_DEVMEM = 1,
+ RSC_TRACE = 2,
+ RSC_VDEV = 3,
+ RSC_LAST = 4,
+ RSC_VENDOR_START = 128,
+ RSC_VENDOR_END = 512,
+};
+
+#define FW_RSC_ADDR_ANY (-1)
+
+/**
+ * struct fw_rsc_carveout - physically contiguous memory request
+ * @da: device address
+ * @pa: physical address
+ * @len: length (in bytes)
+ * @flags: iommu protection flags
+ * @reserved: reserved (must be zero)
+ * @name: human-readable name of the requested memory region
+ *
+ * This resource entry requests the host to allocate a physically contiguous
+ * memory region.
+ *
+ * These request entries should precede other firmware resource entries,
+ * as other entries might request placing other data objects inside
+ * these memory regions (e.g. data/code segments, trace resource entries, ...).
+ *
+ * Allocating memory this way helps utilizing the reserved physical memory
+ * (e.g. CMA) more efficiently, and also minimizes the number of TLB entries
+ * needed to map it (in case @rproc is using an IOMMU). Reducing the TLB
+ * pressure is important; it may have a substantial impact on performance.
+ *
+ * If the firmware is compiled with static addresses, then @da should specify
+ * the expected device address of this memory region. If @da is set to
+ * FW_RSC_ADDR_ANY, then the host will dynamically allocate it, and then
+ * overwrite @da with the dynamically allocated address.
+ *
+ * We will always use @da to negotiate the device addresses, even if it
+ * isn't using an iommu. In that case, though, it will obviously contain
+ * physical addresses.
+ *
+ * Some remote processors needs to know the allocated physical address
+ * even if they do use an iommu. This is needed, e.g., if they control
+ * hardware accelerators which access the physical memory directly (this
+ * is the case with OMAP4 for instance). In that case, the host will
+ * overwrite @pa with the dynamically allocated physical address.
+ * Generally we don't want to expose physical addresses if we don't have to
+ * (remote processors are generally _not_ trusted), so we might want to
+ * change this to happen _only_ when explicitly required by the hardware.
+ *
+ * @flags is used to provide IOMMU protection flags, and @name should
+ * (optionally) contain a human readable name of this carveout region
+ * (mainly for debugging purposes).
+ */
+struct fw_rsc_carveout {
+ u32 da;
+ u32 pa;
+ u32 len;
+ u32 flags;
+ u32 reserved;
+ u8 name[32];
+} __packed;
+
+/**
+ * struct fw_rsc_devmem - iommu mapping request
+ * @da: device address
+ * @pa: physical address
+ * @len: length (in bytes)
+ * @flags: iommu protection flags
+ * @reserved: reserved (must be zero)
+ * @name: human-readable name of the requested region to be mapped
+ *
+ * This resource entry requests the host to iommu map a physically contiguous
+ * memory region. This is needed in case the remote processor requires
+ * access to certain memory-based peripherals; _never_ use it to access
+ * regular memory.
+ *
+ * This is obviously only needed if the remote processor is accessing memory
+ * via an iommu.
+ *
+ * @da should specify the required device address, @pa should specify
+ * the physical address we want to map, @len should specify the size of
+ * the mapping and @flags is the IOMMU protection flags. As always, @name may
+ * (optionally) contain a human readable name of this mapping (mainly for
+ * debugging purposes).
+ *
+ * Note: at this point we just "trust" those devmem entries to contain valid
+ * physical addresses, but this isn't safe and will be changed: eventually we
+ * want remoteproc implementations to provide us ranges of physical addresses
+ * the firmware is allowed to request, and not allow firmwares to request
+ * access to physical addresses that are outside those ranges.
+ */
+struct fw_rsc_devmem {
+ u32 da;
+ u32 pa;
+ u32 len;
+ u32 flags;
+ u32 reserved;
+ u8 name[32];
+} __packed;
+
+/**
+ * struct fw_rsc_trace - trace buffer declaration
+ * @da: device address
+ * @len: length (in bytes)
+ * @reserved: reserved (must be zero)
+ * @name: human-readable name of the trace buffer
+ *
+ * This resource entry provides the host information about a trace buffer
+ * into which the remote processor will write log messages.
+ *
+ * @da specifies the device address of the buffer, @len specifies
+ * its size, and @name may contain a human readable name of the trace buffer.
+ *
+ * After booting the remote processor, the trace buffers are exposed to the
+ * user via debugfs entries (called trace0, trace1, etc..).
+ */
+struct fw_rsc_trace {
+ u32 da;
+ u32 len;
+ u32 reserved;
+ u8 name[32];
+} __packed;
+
+/**
+ * struct fw_rsc_vdev_vring - vring descriptor entry
+ * @da: device address
+ * @align: the alignment between the consumer and producer parts of the vring
+ * @num: num of buffers supported by this vring (must be power of two)
+ * @notifyid: a unique rproc-wide notify index for this vring. This notify
+ * index is used when kicking a remote processor, to let it know that this
+ * vring is triggered.
+ * @pa: physical address
+ *
+ * This descriptor is not a resource entry by itself; it is part of the
+ * vdev resource type (see below).
+ *
+ * Note that @da should either contain the device address where
+ * the remote processor is expecting the vring, or indicate that
+ * dynamically allocation of the vring's device address is supported.
+ */
+struct fw_rsc_vdev_vring {
+ u32 da;
+ u32 align;
+ u32 num;
+ u32 notifyid;
+ u32 pa;
+} __packed;
+
+/**
+ * struct fw_rsc_vdev - virtio device header
+ * @id: virtio device id (as in virtio_ids.h)
+ * @notifyid: a unique rproc-wide notify index for this vdev. This notify
+ * index is used when kicking a remote processor, to let it know that the
+ * status/features of this vdev have changes.
+ * @dfeatures: specifies the virtio device features supported by the firmware
+ * @gfeatures: a place holder used by the host to write back the
+ * negotiated features that are supported by both sides.
+ * @config_len: the size of the virtio config space of this vdev. The config
+ * space lies in the resource table immediate after this vdev header.
+ * @status: a place holder where the host will indicate its virtio progress.
+ * @num_of_vrings: indicates how many vrings are described in this vdev header
+ * @reserved: reserved (must be zero)
+ * @vring: an array of @num_of_vrings entries of 'struct fw_rsc_vdev_vring'.
+ *
+ * This resource is a virtio device header: it provides information about
+ * the vdev, and is then used by the host and its peer remote processors
+ * to negotiate and share certain virtio properties.
+ *
+ * By providing this resource entry, the firmware essentially asks remoteproc
+ * to statically allocate a vdev upon registration of the rproc (dynamic vdev
+ * allocation is not yet supported).
+ *
+ * Note:
+ * 1. unlike virtualization systems, the term 'host' here means
+ * the Linux side which is running remoteproc to control the remote
+ * processors. We use the name 'gfeatures' to comply with virtio's terms,
+ * though there isn't really any virtualized guest OS here: it's the host
+ * which is responsible for negotiating the final features.
+ * Yeah, it's a bit confusing.
+ *
+ * 2. immediately following this structure is the virtio config space for
+ * this vdev (which is specific to the vdev; for more info, read the virtio
+ * spec). The size of the config space is specified by @config_len.
+ */
+struct fw_rsc_vdev {
+ u32 id;
+ u32 notifyid;
+ u32 dfeatures;
+ u32 gfeatures;
+ u32 config_len;
+ u8 status;
+ u8 num_of_vrings;
+ u8 reserved[2];
+ struct fw_rsc_vdev_vring vring[];
+} __packed;
+
+#endif /* RSC_TABLE_H */
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0878/1518] remoteproc: use rsc_table_for_each_entry() in rproc_handle_resources()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (876 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0877/1518] remoteproc: Move resource table data structure to its own header Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0879/1518] remoteproc: fix OOB read via signed offset in rsc_table_for_each_entry() Greg Kroah-Hartman
` (120 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Mukesh Ojha, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
[ Upstream commit 49abb5d6e1ac8169cdfc0c3aa4408e0d90ee5696 ]
Replace the open-coded resource table iteration loop in
rproc_handle_resources() with the rsc_table_for_each_entry() helper.
The remoteproc-specific dispatch logic (vendor resource handling via
rproc_handle_rsc(), RSC_LAST bounds check, handler table lookup) is
moved into a local callback rproc_handle_rsc_entry(), keeping the
iteration mechanics in one canonical place.
The callback receives the payload offset within the table so that
handlers which write back into the resource table (e.g.
rproc_handle_carveout() recording a dynamically allocated address via
rsc_offset) continue to work correctly.
No functional change.
Signed-off-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260506050107.1985033-3-mukesh.ojha@oss.qualcomm.com
Stable-dep-of: bb840ea69347 ("remoteproc: fix OOB read via signed offset in rsc_table_for_each_entry()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/remoteproc/remoteproc_core.c | 81 +++++++++++++---------------
include/linux/rsc_table.h | 53 ++++++++++++++++++
2 files changed, 91 insertions(+), 43 deletions(-)
diff --git a/drivers/remoteproc/remoteproc_core.c b/drivers/remoteproc/remoteproc_core.c
index 157d5603f2bad..bbc781e41a1b8 100644
--- a/drivers/remoteproc/remoteproc_core.c
+++ b/drivers/remoteproc/remoteproc_core.c
@@ -1016,60 +1016,55 @@ static rproc_handle_resource_t rproc_loading_handlers[RSC_LAST] = {
[RSC_VDEV] = rproc_handle_vdev,
};
-/* handle firmware resource entries before booting the remote processor */
-static int rproc_handle_resources(struct rproc *rproc,
- rproc_handle_resource_t handlers[RSC_LAST])
+struct rproc_rsc_cb_data {
+ struct rproc *rproc;
+ rproc_handle_resource_t *handlers;
+};
+
+static int rproc_handle_rsc_entry(u32 type, void *rsc, int offset,
+ int avail, void *data)
{
+ struct rproc_rsc_cb_data *d = data;
+ struct rproc *rproc = d->rproc;
struct device *dev = &rproc->dev;
rproc_handle_resource_t handler;
- int ret = 0, i;
-
- if (!rproc->table_ptr)
- return 0;
+ int ret;
- for (i = 0; i < rproc->table_ptr->num; i++) {
- int offset = rproc->table_ptr->offset[i];
- struct fw_rsc_hdr *hdr = (void *)rproc->table_ptr + offset;
- int avail = rproc->table_sz - offset - sizeof(*hdr);
- void *rsc = (void *)hdr + sizeof(*hdr);
+ dev_dbg(dev, "rsc: type %d\n", type);
- /* make sure table isn't truncated */
- if (avail < 0) {
- dev_err(dev, "rsc table is truncated\n");
- return -EINVAL;
- }
-
- dev_dbg(dev, "rsc: type %d\n", hdr->type);
+ if (type >= RSC_VENDOR_START && type <= RSC_VENDOR_END) {
+ ret = rproc_handle_rsc(rproc, type, rsc, offset, avail);
+ if (ret == RSC_HANDLED)
+ return 0;
+ if (ret < 0)
+ return ret;
+ dev_warn(dev, "unsupported vendor resource %d\n", type);
+ return 0;
+ }
- if (hdr->type >= RSC_VENDOR_START &&
- hdr->type <= RSC_VENDOR_END) {
- ret = rproc_handle_rsc(rproc, hdr->type, rsc,
- offset + sizeof(*hdr), avail);
- if (ret == RSC_HANDLED)
- continue;
- else if (ret < 0)
- break;
+ if (type >= RSC_LAST) {
+ dev_warn(dev, "unsupported resource %d\n", type);
+ return 0;
+ }
- dev_warn(dev, "unsupported vendor resource %d\n",
- hdr->type);
- continue;
- }
+ handler = d->handlers[type];
+ if (!handler)
+ return 0;
- if (hdr->type >= RSC_LAST) {
- dev_warn(dev, "unsupported resource %d\n", hdr->type);
- continue;
- }
+ return handler(rproc, rsc, offset, avail);
+}
- handler = handlers[hdr->type];
- if (!handler)
- continue;
+/* handle firmware resource entries before booting the remote processor */
+static int rproc_handle_resources(struct rproc *rproc,
+ rproc_handle_resource_t handlers[RSC_LAST])
+{
+ struct rproc_rsc_cb_data d = { .rproc = rproc, .handlers = handlers };
- ret = handler(rproc, rsc, offset + sizeof(*hdr), avail);
- if (ret)
- break;
- }
+ if (!rproc->table_ptr)
+ return 0;
- return ret;
+ return rsc_table_for_each_entry(rproc->table_ptr, rproc->table_sz,
+ &rproc->dev, rproc_handle_rsc_entry, &d);
}
static int rproc_prepare_subdevices(struct rproc *rproc)
diff --git a/include/linux/rsc_table.h b/include/linux/rsc_table.h
index c32c8b6cd2a77..c6d6d553d8f11 100644
--- a/include/linux/rsc_table.h
+++ b/include/linux/rsc_table.h
@@ -303,4 +303,57 @@ struct fw_rsc_vdev {
struct fw_rsc_vdev_vring vring[];
} __packed;
+/**
+ * rsc_table_for_each_entry() - iterate over all entries in a resource table
+ * @table: pointer to the resource table
+ * @table_sz: total size of the table buffer in bytes
+ * @dev: device used for error logging
+ * @cb: callback invoked for each entry:
+ * @type - value from enum fw_resource_type
+ * @rsc - pointer to the entry payload (past struct fw_rsc_hdr)
+ * @offset - byte offset of the payload within the table; callers
+ * that write back into the table (e.g. to record a
+ * dynamically allocated address) use this to locate the
+ * entry for later update
+ * @avail - bytes available in the payload
+ * @data - caller-supplied private pointer
+ * Return 0 to continue iteration, non-zero to stop.
+ * @data: private pointer forwarded to @cb on every call
+ *
+ * Iterates over every resource entry in @table, performing the standard
+ * truncation check, and invokes @cb for each one. Iteration stops on the
+ * first non-zero return from @cb or on a malformed table.
+ *
+ * Returns 0 after a complete iteration, -EINVAL if the table is truncated,
+ * or the first non-zero value returned by @cb.
+ */
+static inline int rsc_table_for_each_entry(struct resource_table *table,
+ size_t table_sz,
+ struct device *dev,
+ int (*cb)(u32 type, void *rsc,
+ int offset, int avail,
+ void *data),
+ void *data) {
+ int i, ret;
+
+ for (i = 0; i < table->num; i++) {
+ int offset = table->offset[i];
+ struct fw_rsc_hdr *hdr = (void *)table + offset;
+ int avail = table_sz - offset - sizeof(*hdr);
+ int rsc_offset = offset + sizeof(*hdr);
+ void *rsc = (void *)hdr + sizeof(*hdr);
+
+ if (avail < 0) {
+ dev_err(dev, "rsc table is truncated\n");
+ return -EINVAL;
+ }
+
+ ret = cb(hdr->type, rsc, rsc_offset, avail, data);
+ if (ret)
+ return ret;
+ }
+
+ return 0;
+}
+
#endif /* RSC_TABLE_H */
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0879/1518] remoteproc: fix OOB read via signed offset in rsc_table_for_each_entry()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (877 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0878/1518] remoteproc: use rsc_table_for_each_entry() in rproc_handle_resources() Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0880/1518] bpf, cgroup: Fix invalid storage access after __cgroup_bpf_attach failed Greg Kroah-Hartman
` (119 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mukesh Ojha, Bjorn Andersson,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
[ Upstream commit bb840ea69347aff7bde5a208e7b5b180669a7656 ]
table->offset[i] is a u32 from firmware, but was stored into a signed
int. A crafted offset like 0xFFFFFFF0 becomes -16, placing hdr 16 bytes
before the table buffer. The subsequent avail check was bypassed
because the negative int was promoted to a large size_t in the
expression "table_sz - offset - sizeof(*hdr)", yielding a large positive
avail and letting the out-of-bounds hdr->type read proceed undetected.
Store the offset as u32 and validate it with unsigned comparisons before
any pointer arithmetic.
Signed-off-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
Fixes: fd2c15ec1dd3 ("remoteproc: resource table overhaul")
Link: https://lore.kernel.org/r/20260803114331.3277263-6-mukesh.ojha@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/rsc_table.h | 17 +++++++++++------
1 file changed, 11 insertions(+), 6 deletions(-)
diff --git a/include/linux/rsc_table.h b/include/linux/rsc_table.h
index c6d6d553d8f11..4cef11a2e3a2c 100644
--- a/include/linux/rsc_table.h
+++ b/include/linux/rsc_table.h
@@ -337,17 +337,22 @@ static inline int rsc_table_for_each_entry(struct resource_table *table,
int i, ret;
for (i = 0; i < table->num; i++) {
- int offset = table->offset[i];
- struct fw_rsc_hdr *hdr = (void *)table + offset;
- int avail = table_sz - offset - sizeof(*hdr);
- int rsc_offset = offset + sizeof(*hdr);
- void *rsc = (void *)hdr + sizeof(*hdr);
+ u32 offset = table->offset[i];
+ struct fw_rsc_hdr *hdr;
+ int avail, rsc_offset;
+ void *rsc;
- if (avail < 0) {
+ if (offset < sizeof(*table) || offset >= table_sz ||
+ table_sz - offset < sizeof(*hdr)) {
dev_err(dev, "rsc table is truncated\n");
return -EINVAL;
}
+ hdr = (void *)table + offset;
+ avail = table_sz - offset - sizeof(*hdr);
+ rsc_offset = offset + sizeof(*hdr);
+ rsc = (void *)hdr + sizeof(*hdr);
+
ret = cb(hdr->type, rsc, rsc_offset, avail, data);
if (ret)
return ret;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0880/1518] bpf, cgroup: Fix invalid storage access after __cgroup_bpf_attach failed
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (878 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0879/1518] remoteproc: fix OOB read via signed offset in rsc_table_for_each_entry() Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0881/1518] selftests/mm: ksm_tests: use kselftest framework Greg Kroah-Hartman
` (118 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sashiko, Pu Lehui, Andrii Nakryiko,
Emil Tsalapatis, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pu Lehui <pulehui@huawei.com>
[ Upstream commit 6655c409707ec8ce9ce0850ffe4fe02331fd4d9c ]
A potential invalid storage access issue can occur after replacing a
cgroup bpf prog.
This occurs in the following scenario:
1. prog1 with storage is attached to a cgroup in multi-attach mode.
2. prog1 is replaced with prog2 using BPF_F_REPLACE in multi-attach
mode, but fails midway (e.g. in bpf_trampoline_link_cgroup_shim or
update_effective_progs).
3. A new prog3 is attached to the cgroup in multi-attach mode.
The reason is that __cgroup_bpf_attach overwrites pl->storage with the
new storage prior to attachment completion. When attachment fails
midway, the cleanup path calls bpf_cgroup_storages_free(new_storage) to
free the newly allocated storage, but fails to restore pl->storage back
to old_storage.
Consequently, the still-active prog1 holds invalid or dangling storage
pointers, leading to an invalid memory access when prog1 executes and
calls bpf_get_local_storage. Additionally, original pl->flags and
cgrp->bpf.flags[atype] are left unrestored.
Fix this by saving old_pl_flags, old_storage, and old_flags prior to the
update, and properly restoring all of them in the cleanup path on error.
Fixes: 7d9c3427894f ("bpf: Make cgroup storages shared between programs on the same cgroup")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Signed-off-by: Pu Lehui <pulehui@huawei.com>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Link: https://lore.kernel.org/bpf/20260803013934.4036646-1-pulehui@huaweicloud.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/cgroup.c | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/kernel/bpf/cgroup.c b/kernel/bpf/cgroup.c
index fc2f44b60a551..e5fa91515c563 100644
--- a/kernel/bpf/cgroup.c
+++ b/kernel/bpf/cgroup.c
@@ -813,8 +813,10 @@ static int __cgroup_bpf_attach(struct cgroup *cgrp,
struct bpf_prog *old_prog = NULL;
struct bpf_cgroup_storage *storage[MAX_BPF_CGROUP_STORAGE_TYPE] = {};
struct bpf_cgroup_storage *new_storage[MAX_BPF_CGROUP_STORAGE_TYPE] = {};
+ struct bpf_cgroup_storage *old_storage[MAX_BPF_CGROUP_STORAGE_TYPE] = {};
struct bpf_prog *new_prog = prog ? : link->link.prog;
enum cgroup_bpf_attach_type atype;
+ u32 old_flags, old_pl_flags;
struct bpf_prog_list *pl;
struct hlist_head *progs;
int err;
@@ -865,6 +867,8 @@ static int __cgroup_bpf_attach(struct cgroup *cgrp,
if (pl) {
old_prog = pl->prog;
+ old_pl_flags = pl->flags;
+ bpf_cgroup_storages_assign(old_storage, pl->storage);
} else {
pl = kmalloc(sizeof(*pl), GFP_KERNEL);
if (!pl) {
@@ -884,6 +888,7 @@ static int __cgroup_bpf_attach(struct cgroup *cgrp,
pl->link = link;
pl->flags = flags;
bpf_cgroup_storages_assign(pl->storage, storage);
+ old_flags = cgrp->bpf.flags[atype];
cgrp->bpf.flags[atype] = saved_flags;
if (type == BPF_LSM_CGROUP) {
@@ -915,12 +920,15 @@ static int __cgroup_bpf_attach(struct cgroup *cgrp,
if (old_prog) {
pl->prog = old_prog;
pl->link = NULL;
+ pl->flags = old_pl_flags;
+ bpf_cgroup_storages_assign(pl->storage, old_storage);
}
bpf_cgroup_storages_free(new_storage);
if (!old_prog) {
hlist_del(&pl->node);
kfree(pl);
}
+ cgrp->bpf.flags[atype] = old_flags;
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0881/1518] selftests/mm: ksm_tests: use kselftest framework
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (879 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0880/1518] bpf, cgroup: Fix invalid storage access after __cgroup_bpf_attach failed Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0882/1518] selftests/mm: fix ksm NUMA merge test for systems with memoryless NUMA nodes Greg Kroah-Hartman
` (117 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mike Rapoport (Microsoft), Donet Tom,
Mark Brown, Sarthak Sharma, Luiz Capitulino, Baolin Wang,
Barry Song, David Hildenbrand, Dev Jain, Jason Gunthorpe,
John Hubbard, Lance Yang, Leon Romanovsky, Liam Howlett, Li Wang,
Lorenzo Stoakes, Michal Hocko, Nico Pache, Peter Xu, Ryan Roberts,
Shuah Khan, Suren Baghdasaryan, Vlastimil Babka, Zi Yan,
Andrew Morton, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mike Rapoport (Microsoft) <rppt@kernel.org>
[ Upstream commit 4cc68d5f52de9614e2db70f43c52f012d1ebb5ad ]
Convert ksm_tests to use kselftest framework for reporting and tracking
successful and failing runs.
Link: https://lore.kernel.org/20260511162840.375890-16-rppt@kernel.org
Signed-off-by: Mike Rapoport (Microsoft) <rppt@kernel.org>
Reviewed-by: Donet Tom <donettom@linux.ibm.com>
Reviewed-by: Mark Brown <broonie@kernel.org>
Tested-by: Sarthak Sharma <sarthak.sharma@arm.com>
Tested-by: Luiz Capitulino <luizcap@redhat.com>
Cc: Baolin Wang <baolin.wang@linux.alibaba.com>
Cc: Barry Song <baohua@kernel.org>
Cc: David Hildenbrand <david@kernel.org>
Cc: Dev Jain <dev.jain@arm.com>
Cc: Jason Gunthorpe <jgg@ziepe.ca>
Cc: John Hubbard <jhubbard@nvidia.com>
Cc: Lance Yang <lance.yang@linux.dev>
Cc: Leon Romanovsky <leon@kernel.org>
Cc: Liam Howlett <liam@infradead.org>
Cc: Li Wang <li.wang@linux.dev>
Cc: Lorenzo Stoakes <ljs@kernel.org>
Cc: Michal Hocko <mhocko@suse.com>
Cc: Nico Pache <npache@redhat.com>
Cc: Peter Xu <peterx@redhat.com>
Cc: Ryan Roberts <ryan.roberts@arm.com>
Cc: Shuah Khan <shuah@kernel.org>
Cc: Suren Baghdasaryan <surenb@google.com>
Cc: Vlastimil Babka <vbabka@kernel.org>
Cc: Zi Yan <ziy@nvidia.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Stable-dep-of: 15828a150c58 ("selftests/mm: fix ksm NUMA merge test for systems with memoryless NUMA nodes")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/mm/ksm_tests.c | 180 +++++++++++--------------
1 file changed, 81 insertions(+), 99 deletions(-)
diff --git a/tools/testing/selftests/mm/ksm_tests.c b/tools/testing/selftests/mm/ksm_tests.c
index b77462b5c240b..fb62a36f9a786 100644
--- a/tools/testing/selftests/mm/ksm_tests.c
+++ b/tools/testing/selftests/mm/ksm_tests.c
@@ -175,12 +175,12 @@ static void *allocate_memory(void *ptr, int prot, int mapping, char data, size_
void *map_ptr = mmap(ptr, map_size, PROT_WRITE, mapping, -1, 0);
if (!map_ptr) {
- perror("mmap");
+ ksft_perror("mmap");
return NULL;
}
memset(map_ptr, data, map_size);
if (mprotect(map_ptr, map_size, prot)) {
- perror("mprotect");
+ ksft_perror("mprotect");
munmap(map_ptr, map_size);
return NULL;
}
@@ -201,11 +201,11 @@ static int ksm_do_scan(int scan_count, struct timespec start_time, int timeout)
if (ksm_read_sysfs(KSM_FP("full_scans"), &cur_scan))
return 1;
if (clock_gettime(CLOCK_MONOTONIC_RAW, &cur_time)) {
- perror("clock_gettime");
+ ksft_perror("clock_gettime");
return 1;
}
if ((cur_time.tv_sec - start_time.tv_sec) > timeout) {
- printf("Scan time limit exceeded\n");
+ ksft_print_msg("Scan time limit exceeded\n");
return 1;
}
}
@@ -218,12 +218,12 @@ static int ksm_merge_pages(int merge_type, void *addr, size_t size,
{
if (merge_type == KSM_MERGE_MADVISE) {
if (madvise(addr, size, MADV_MERGEABLE)) {
- perror("madvise");
+ ksft_perror("madvise");
return 1;
}
} else if (merge_type == KSM_MERGE_PRCTL) {
if (prctl(PR_SET_MEMORY_MERGE, 1, 0, 0, 0)) {
- perror("prctl");
+ ksft_perror("prctl");
return 1;
}
}
@@ -242,7 +242,7 @@ static int ksm_unmerge_pages(void *addr, size_t size,
struct timespec start_time, int timeout)
{
if (madvise(addr, size, MADV_UNMERGEABLE)) {
- perror("madvise");
+ ksft_perror("madvise");
return 1;
}
return 0;
@@ -324,7 +324,7 @@ static int check_ksm_merge(int merge_type, int mapping, int prot,
struct timespec start_time;
if (clock_gettime(CLOCK_MONOTONIC_RAW, &start_time)) {
- perror("clock_gettime");
+ ksft_perror("clock_gettime");
return KSFT_FAIL;
}
@@ -338,7 +338,6 @@ static int check_ksm_merge(int merge_type, int mapping, int prot,
/* verify that the right number of pages are merged */
if (assert_ksm_pages_count(page_count)) {
- printf("OK\n");
munmap(map_ptr, page_size * page_count);
if (merge_type == KSM_MERGE_PRCTL)
prctl(PR_SET_MEMORY_MERGE, 0, 0, 0, 0);
@@ -346,7 +345,6 @@ static int check_ksm_merge(int merge_type, int mapping, int prot,
}
err_out:
- printf("Not OK\n");
munmap(map_ptr, page_size * page_count);
return KSFT_FAIL;
}
@@ -358,7 +356,7 @@ static int check_ksm_unmerge(int merge_type, int mapping, int prot, int timeout,
int page_count = 2;
if (clock_gettime(CLOCK_MONOTONIC_RAW, &start_time)) {
- perror("clock_gettime");
+ ksft_perror("clock_gettime");
return KSFT_FAIL;
}
@@ -380,13 +378,11 @@ static int check_ksm_unmerge(int merge_type, int mapping, int prot, int timeout,
/* check that unmerging was successful and 0 pages are currently merged */
if (assert_ksm_pages_count(0)) {
- printf("OK\n");
munmap(map_ptr, page_size * page_count);
return KSFT_PASS;
}
err_out:
- printf("Not OK\n");
munmap(map_ptr, page_size * page_count);
return KSFT_FAIL;
}
@@ -398,7 +394,7 @@ static int check_ksm_zero_page_merge(int merge_type, int mapping, int prot, long
struct timespec start_time;
if (clock_gettime(CLOCK_MONOTONIC_RAW, &start_time)) {
- perror("clock_gettime");
+ ksft_perror("clock_gettime");
return KSFT_FAIL;
}
@@ -425,12 +421,10 @@ static int check_ksm_zero_page_merge(int merge_type, int mapping, int prot, long
else if (!use_zero_pages && !assert_ksm_pages_count(page_count))
goto err_out;
- printf("OK\n");
munmap(map_ptr, page_size * page_count);
return KSFT_PASS;
err_out:
- printf("Not OK\n");
munmap(map_ptr, page_size * page_count);
return KSFT_FAIL;
}
@@ -465,16 +459,16 @@ static int check_ksm_numa_merge(int merge_type, int mapping, int prot, int timeo
int first_node;
if (clock_gettime(CLOCK_MONOTONIC_RAW, &start_time)) {
- perror("clock_gettime");
+ ksft_perror("clock_gettime");
return KSFT_FAIL;
}
if (numa_available() < 0) {
- perror("NUMA support not enabled");
+ ksft_print_msg("NUMA support not enabled\n");
return KSFT_SKIP;
}
if (numa_num_configured_nodes() <= 1) {
- printf("At least 2 NUMA nodes must be available\n");
+ ksft_print_msg("At least 2 NUMA nodes must be available\n");
return KSFT_SKIP;
}
if (ksm_write_sysfs(KSM_FP("merge_across_nodes"), merge_across_nodes))
@@ -485,7 +479,7 @@ static int check_ksm_numa_merge(int merge_type, int mapping, int prot, int timeo
numa1_map_ptr = numa_alloc_onnode(page_size, first_node);
numa2_map_ptr = numa_alloc_onnode(page_size, get_next_mem_node(first_node));
if (!numa1_map_ptr || !numa2_map_ptr) {
- perror("numa_alloc_onnode");
+ ksft_perror("numa_alloc_onnode");
return KSFT_FAIL;
}
@@ -510,13 +504,11 @@ static int check_ksm_numa_merge(int merge_type, int mapping, int prot, int timeo
numa_free(numa1_map_ptr, page_size);
numa_free(numa2_map_ptr, page_size);
- printf("OK\n");
return KSFT_PASS;
err_out:
numa_free(numa1_map_ptr, page_size);
numa_free(numa2_map_ptr, page_size);
- printf("Not OK\n");
return KSFT_FAIL;
}
@@ -529,7 +521,7 @@ static int ksm_merge_hugepages_time(int merge_type, int mapping, int prot,
int pagemap_fd, n_normal_pages, n_huge_pages;
if (!thp_is_enabled()) {
- printf("Transparent Hugepages not available\n");
+ ksft_print_msg("Transparent Hugepages not available\n");
return KSFT_SKIP;
}
@@ -559,36 +551,35 @@ static int ksm_merge_hugepages_time(int merge_type, int mapping, int prot,
else
n_huge_pages++;
}
- printf("Number of normal pages: %d\n", n_normal_pages);
- printf("Number of huge pages: %d\n", n_huge_pages);
+ ksft_print_msg("Number of normal pages: %d\n", n_normal_pages);
+ ksft_print_msg("Number of huge pages: %d\n", n_huge_pages);
memset(map_ptr, '*', len);
if (clock_gettime(CLOCK_MONOTONIC_RAW, &start_time)) {
- perror("clock_gettime");
+ ksft_perror("clock_gettime");
goto err_out;
}
if (ksm_merge_pages(merge_type, map_ptr, map_size, start_time, timeout))
goto err_out;
if (clock_gettime(CLOCK_MONOTONIC_RAW, &end_time)) {
- perror("clock_gettime");
+ ksft_perror("clock_gettime");
goto err_out;
}
scan_time_ns = (end_time.tv_sec - start_time.tv_sec) * NSEC_PER_SEC +
(end_time.tv_nsec - start_time.tv_nsec);
- printf("Total size: %lu MiB\n", map_size / MB);
- printf("Total time: %ld.%09ld s\n", scan_time_ns / NSEC_PER_SEC,
+ ksft_print_msg("Total size: %lu MiB\n", map_size / MB);
+ ksft_print_msg("Total time: %ld.%09ld s\n", scan_time_ns / NSEC_PER_SEC,
scan_time_ns % NSEC_PER_SEC);
- printf("Average speed: %.3f MiB/s\n", (map_size / MB) /
+ ksft_print_msg("Average speed: %.3f MiB/s\n", (map_size / MB) /
((double)scan_time_ns / NSEC_PER_SEC));
munmap(map_ptr_orig, len + HPAGE_SIZE);
return KSFT_PASS;
err_out:
- printf("Not OK\n");
munmap(map_ptr_orig, len + HPAGE_SIZE);
return KSFT_FAIL;
}
@@ -606,30 +597,29 @@ static int ksm_merge_time(int merge_type, int mapping, int prot, int timeout, si
return KSFT_FAIL;
if (clock_gettime(CLOCK_MONOTONIC_RAW, &start_time)) {
- perror("clock_gettime");
+ ksft_perror("clock_gettime");
goto err_out;
}
if (ksm_merge_pages(merge_type, map_ptr, map_size, start_time, timeout))
goto err_out;
if (clock_gettime(CLOCK_MONOTONIC_RAW, &end_time)) {
- perror("clock_gettime");
+ ksft_perror("clock_gettime");
goto err_out;
}
scan_time_ns = (end_time.tv_sec - start_time.tv_sec) * NSEC_PER_SEC +
(end_time.tv_nsec - start_time.tv_nsec);
- printf("Total size: %lu MiB\n", map_size / MB);
- printf("Total time: %ld.%09ld s\n", scan_time_ns / NSEC_PER_SEC,
+ ksft_print_msg("Total size: %lu MiB\n", map_size / MB);
+ ksft_print_msg("Total time: %ld.%09ld s\n", scan_time_ns / NSEC_PER_SEC,
scan_time_ns % NSEC_PER_SEC);
- printf("Average speed: %.3f MiB/s\n", (map_size / MB) /
+ ksft_print_msg("Average speed: %.3f MiB/s\n", (map_size / MB) /
((double)scan_time_ns / NSEC_PER_SEC));
munmap(map_ptr, map_size);
return KSFT_PASS;
err_out:
- printf("Not OK\n");
munmap(map_ptr, map_size);
return KSFT_FAIL;
}
@@ -646,37 +636,36 @@ static int ksm_unmerge_time(int merge_type, int mapping, int prot, int timeout,
if (!map_ptr)
return KSFT_FAIL;
if (clock_gettime(CLOCK_MONOTONIC_RAW, &start_time)) {
- perror("clock_gettime");
+ ksft_perror("clock_gettime");
goto err_out;
}
if (ksm_merge_pages(merge_type, map_ptr, map_size, start_time, timeout))
goto err_out;
if (clock_gettime(CLOCK_MONOTONIC_RAW, &start_time)) {
- perror("clock_gettime");
+ ksft_perror("clock_gettime");
goto err_out;
}
if (ksm_unmerge_pages(map_ptr, map_size, start_time, timeout))
goto err_out;
if (clock_gettime(CLOCK_MONOTONIC_RAW, &end_time)) {
- perror("clock_gettime");
+ ksft_perror("clock_gettime");
goto err_out;
}
scan_time_ns = (end_time.tv_sec - start_time.tv_sec) * NSEC_PER_SEC +
(end_time.tv_nsec - start_time.tv_nsec);
- printf("Total size: %lu MiB\n", map_size / MB);
- printf("Total time: %ld.%09ld s\n", scan_time_ns / NSEC_PER_SEC,
+ ksft_print_msg("Total size: %lu MiB\n", map_size / MB);
+ ksft_print_msg("Total time: %ld.%09ld s\n", scan_time_ns / NSEC_PER_SEC,
scan_time_ns % NSEC_PER_SEC);
- printf("Average speed: %.3f MiB/s\n", (map_size / MB) /
+ ksft_print_msg("Average speed: %.3f MiB/s\n", (map_size / MB) /
((double)scan_time_ns / NSEC_PER_SEC));
munmap(map_ptr, map_size);
return KSFT_PASS;
err_out:
- printf("Not OK\n");
munmap(map_ptr, map_size);
return KSFT_FAIL;
}
@@ -695,24 +684,24 @@ static int ksm_cow_time(int merge_type, int mapping, int prot, int timeout, size
return KSFT_FAIL;
if (clock_gettime(CLOCK_MONOTONIC_RAW, &start_time)) {
- perror("clock_gettime");
+ ksft_perror("clock_gettime");
return KSFT_FAIL;
}
for (size_t i = 0; i < page_count - 1; i = i + 2)
memset(map_ptr + page_size * i, '-', 1);
if (clock_gettime(CLOCK_MONOTONIC_RAW, &end_time)) {
- perror("clock_gettime");
+ ksft_perror("clock_gettime");
return KSFT_FAIL;
}
cow_time_ns = (end_time.tv_sec - start_time.tv_sec) * NSEC_PER_SEC +
(end_time.tv_nsec - start_time.tv_nsec);
- printf("Total size: %lu MiB\n\n", (page_size * page_count) / MB);
- printf("Not merged pages:\n");
- printf("Total time: %ld.%09ld s\n", cow_time_ns / NSEC_PER_SEC,
+ ksft_print_msg("Total size: %lu MiB\n\n", (page_size * page_count) / MB);
+ ksft_print_msg("Not merged pages:\n");
+ ksft_print_msg("Total time: %ld.%09ld s\n", cow_time_ns / NSEC_PER_SEC,
cow_time_ns % NSEC_PER_SEC);
- printf("Average speed: %.3f MiB/s\n\n", ((page_size * (page_count / 2)) / MB) /
+ ksft_print_msg("Average speed: %.3f MiB/s\n\n", ((page_size * (page_count / 2)) / MB) /
((double)cow_time_ns / NSEC_PER_SEC));
/* Create 2000 pairs of duplicate pages */
@@ -724,30 +713,29 @@ static int ksm_cow_time(int merge_type, int mapping, int prot, int timeout, size
goto err_out;
if (clock_gettime(CLOCK_MONOTONIC_RAW, &start_time)) {
- perror("clock_gettime");
+ ksft_perror("clock_gettime");
goto err_out;
}
for (size_t i = 0; i < page_count - 1; i = i + 2)
memset(map_ptr + page_size * i, '-', 1);
if (clock_gettime(CLOCK_MONOTONIC_RAW, &end_time)) {
- perror("clock_gettime");
+ ksft_perror("clock_gettime");
goto err_out;
}
cow_time_ns = (end_time.tv_sec - start_time.tv_sec) * NSEC_PER_SEC +
(end_time.tv_nsec - start_time.tv_nsec);
- printf("Merged pages:\n");
- printf("Total time: %ld.%09ld s\n", cow_time_ns / NSEC_PER_SEC,
+ ksft_print_msg("Merged pages:\n");
+ ksft_print_msg("Total time: %ld.%09ld s\n", cow_time_ns / NSEC_PER_SEC,
cow_time_ns % NSEC_PER_SEC);
- printf("Average speed: %.3f MiB/s\n", ((page_size * (page_count / 2)) / MB) /
+ ksft_print_msg("Average speed: %.3f MiB/s\n", ((page_size * (page_count / 2)) / MB) /
((double)cow_time_ns / NSEC_PER_SEC));
munmap(map_ptr, page_size * page_count);
return KSFT_PASS;
err_out:
- printf("Not OK\n");
munmap(map_ptr, page_size * page_count);
return KSFT_FAIL;
}
@@ -765,6 +753,10 @@ int main(int argc, char *argv[])
bool use_zero_pages = KSM_USE_ZERO_PAGES_DEFAULT;
bool merge_across_nodes = KSM_MERGE_ACROSS_NODES_DEFAULT;
long size_MB = 0;
+ const char *test_descr = "KSM merging";
+
+ ksft_print_header();
+ ksft_set_plan(1);
while ((opt = getopt(argc, argv, "dha:p:l:z:m:s:t:MUZNPCHD")) != -1) {
switch (opt) {
@@ -773,17 +765,13 @@ int main(int argc, char *argv[])
break;
case 'p':
page_count = atol(optarg);
- if (page_count <= 0) {
- printf("The number of pages must be greater than 0\n");
- return KSFT_FAIL;
- }
+ if (page_count <= 0)
+ ksft_exit_fail_msg("The number of pages must be greater than 0\n");
break;
case 'l':
ksm_scan_limit_sec = atoi(optarg);
- if (ksm_scan_limit_sec <= 0) {
- printf("Timeout value must be greater than 0\n");
- return KSFT_FAIL;
- }
+ if (ksm_scan_limit_sec <= 0)
+ ksft_exit_fail_msg("Timeout value must be greater than 0\n");
break;
case 'h':
print_help();
@@ -805,19 +793,15 @@ int main(int argc, char *argv[])
break;
case 's':
size_MB = atoi(optarg);
- if (size_MB <= 0) {
- printf("Size must be greater than 0\n");
- return KSFT_FAIL;
- }
+ if (size_MB <= 0)
+ ksft_exit_fail_msg("Size must be greater than 0\n");
break;
case 't':
{
int tmp = atoi(optarg);
- if (tmp < 0 || tmp > KSM_MERGE_LAST) {
- printf("Invalid merge type\n");
- return KSFT_FAIL;
- }
+ if (tmp < 0 || tmp > KSM_MERGE_LAST)
+ ksft_exit_fail_msg("Invalid merge type\n");
merge_type = tmp;
}
break;
@@ -845,82 +829,80 @@ int main(int argc, char *argv[])
test_name = KSM_COW_TIME;
break;
default:
- return KSFT_FAIL;
+ ksft_exit_fail_msg("Unknown option\n");
}
}
if (prot == 0)
prot = str_to_prot(KSM_PROT_STR_DEFAULT);
- if (access(KSM_SYSFS_PATH, F_OK)) {
- printf("Config KSM not enabled\n");
- return KSFT_SKIP;
- }
+ if (access(KSM_SYSFS_PATH, F_OK))
+ ksft_exit_skip("Config KSM not enabled\n");
- if (ksm_save_def(&ksm_sysfs_old)) {
- printf("Cannot save default tunables\n");
- return KSFT_FAIL;
- }
+ if (ksm_save_def(&ksm_sysfs_old))
+ ksft_exit_fail_msg("Cannot save default tunables\n");
if (ksm_write_sysfs(KSM_FP("run"), 2) ||
ksm_write_sysfs(KSM_FP("sleep_millisecs"), 0) ||
numa_available() ? 0 :
ksm_write_sysfs(KSM_FP("merge_across_nodes"), 1) ||
ksm_write_sysfs(KSM_FP("pages_to_scan"), page_count))
- return KSFT_FAIL;
+ ksft_exit_fail_msg("Cannot set up KSM tunables\n");
switch (test_name) {
case CHECK_KSM_MERGE:
+ test_descr = "KSM merging";
ret = check_ksm_merge(merge_type, MAP_PRIVATE | MAP_ANONYMOUS, prot, page_count,
ksm_scan_limit_sec, page_size);
break;
case CHECK_KSM_UNMERGE:
+ test_descr = "KSM unmerging";
ret = check_ksm_unmerge(merge_type, MAP_PRIVATE | MAP_ANONYMOUS, prot,
ksm_scan_limit_sec, page_size);
break;
case CHECK_KSM_ZERO_PAGE_MERGE:
+ test_descr = "KSM zero page merging";
ret = check_ksm_zero_page_merge(merge_type, MAP_PRIVATE | MAP_ANONYMOUS, prot,
page_count, ksm_scan_limit_sec, use_zero_pages,
page_size);
break;
case CHECK_KSM_NUMA_MERGE:
+ test_descr = "KSM NUMA merging";
ret = check_ksm_numa_merge(merge_type, MAP_PRIVATE | MAP_ANONYMOUS, prot,
ksm_scan_limit_sec, merge_across_nodes, page_size);
break;
case KSM_MERGE_TIME:
- if (size_MB == 0) {
- printf("Option '-s' is required.\n");
- return KSFT_FAIL;
- }
+ if (size_MB == 0)
+ ksft_exit_fail_msg("Option '-s' is required\n");
+ test_descr = "KSM merge time";
ret = ksm_merge_time(merge_type, MAP_PRIVATE | MAP_ANONYMOUS, prot,
ksm_scan_limit_sec, size_MB);
break;
case KSM_MERGE_TIME_HUGE_PAGES:
- if (size_MB == 0) {
- printf("Option '-s' is required.\n");
- return KSFT_FAIL;
- }
+ if (size_MB == 0)
+ ksft_exit_fail_msg("Option '-s' is required\n");
+ test_descr = "KSM merge time with huge pages";
ret = ksm_merge_hugepages_time(merge_type, MAP_PRIVATE | MAP_ANONYMOUS, prot,
ksm_scan_limit_sec, size_MB);
break;
case KSM_UNMERGE_TIME:
- if (size_MB == 0) {
- printf("Option '-s' is required.\n");
- return KSFT_FAIL;
- }
+ if (size_MB == 0)
+ ksft_exit_fail_msg("Option '-s' is required\n");
+ test_descr = "KSM unmerge time";
ret = ksm_unmerge_time(merge_type, MAP_PRIVATE | MAP_ANONYMOUS, prot,
ksm_scan_limit_sec, size_MB);
break;
case KSM_COW_TIME:
+ test_descr = "KSM COW time";
ret = ksm_cow_time(merge_type, MAP_PRIVATE | MAP_ANONYMOUS, prot,
ksm_scan_limit_sec, page_size);
break;
}
- if (ksm_restore(&ksm_sysfs_old)) {
- printf("Cannot restore default tunables\n");
- return KSFT_FAIL;
- }
+ if (ksm_restore(&ksm_sysfs_old))
+ ksft_print_msg("Cannot restore default tunables\n");
+
+ ksft_test_result_report(ret, "%s\n", test_descr);
- return ret;
+ ksft_finished();
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0882/1518] selftests/mm: fix ksm NUMA merge test for systems with memoryless NUMA nodes
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (880 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0881/1518] selftests/mm: ksm_tests: use kselftest framework Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0883/1518] selftests/mm: fix ternary operator precedence in ksm_tests Greg Kroah-Hartman
` (116 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, David Hildenbrand (Arm),
Sayali Patil, Dev Jain, Liam Howlett, Miaohe Lin, Michal Hocko,
Oscar Salvador, Ritesh Harjani (IBM), Shuah Khan, Zi Yan,
Andrew Morton, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sayali Patil <sayalip@linux.ibm.com>
[ Upstream commit 15828a150c5806869b7feb9e38ad2c0284fbf18a ]
The KSM NUMA merge test allocates identical pages on different NUMA nodes
and verifies KSM behavior with merge_across_nodes enabled and disabled.
On systems with memoryless NUMA nodes, for example:
#numactl -H
available: 2 nodes (0,4)
.....
node 0 cpus: 0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15
node 0 size: 14825 MB
node 0 free: 1382 MB
node 4 cpus:
node 4 size: 0 MB
node 4 free: 0 MB
the test may attempt to allocate memory on a node without memory, causing
numa_alloc_onnode() to fail and resulting in a spurious test failure.
The test currently checks numa_num_configured_nodes() to determine whether
sufficient NUMA nodes are available. However, configured nodes do not
necessarily have memory.
Reuse the existing get_first_mem_node() and get_next_mem_node() helpers to
locate NUMA nodes that actually contain memory, and skip the test when
fewer than two such nodes are available.
Before patch:
---------------------------
running ./ksm_tests -N -m 1
---------------------------
mbind: Invalid argument
ok 1 KSM NUMA merging
Totals: pass:1 fail:0 xfail:0 xpass:0 skip:0 error:0
[PASS]
ok 1 ksm_tests -N -m 1
---------------------------
running ./ksm_tests -N -m 0
---------------------------
mbind: Invalid argument
not ok 1 KSM NUMA merging
Totals: pass:0 fail:1 xfail:0 xpass:0 skip:0 error:0
[FAIL]
not ok 2 ksm_tests -N -m 0 # exit=1
After patch:
---------------------------
running ./ksm_tests -N -m 1
---------------------------
At least 2 NUMA nodes with memory must be available
ok 1
SKIP KSM NUMA merging
Totals: pass:0 fail:0 xfail:0 xpass:0 skip:1 error:0
[PASS]
ok 1 ksm_tests -N -m 1
---------------------------
running ./ksm_tests -N -m 0
---------------------------
At least 2 NUMA nodes with memory must be available
ok 1
SKIP KSM NUMA merging
Totals: pass:0 fail:0 xfail:0 xpass:0 skip:1 error:0
[PASS]
ok 2 ksm_tests -N -m 0
Link: https://lore.kernel.org/78a3b0e3fb94004c0710872c5bab6f7381b7d63c.1783446924.git.sayalip@linux.ibm.com
Fixes: e3820ab252dd ("selftest/vm: fix ksm selftest to run with different NUMA topologies")
Co-developed-by: David Hildenbrand (Arm) <david@kernel.org>
Signed-off-by: David Hildenbrand (Arm) <david@kernel.org>
Signed-off-by: Sayali Patil <sayalip@linux.ibm.com>
Cc: Dev Jain <dev.jain@arm.com>
Cc: Liam Howlett <liam@infradead.org>
Cc: Miaohe Lin <linmiaohe@huawei.com>
Cc: Michal Hocko <mhocko@kernel.org>
Cc: Oscar Salvador <osalvador@suse.de>
Cc: "Ritesh Harjani (IBM)" <ritesh.list@gmail.com>
Cc: Shuah Khan <shuah@kernel.org>
Cc: Zi Yan <ziy@nvidia.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/mm/ksm_tests.c | 16 +++++++++-------
1 file changed, 9 insertions(+), 7 deletions(-)
diff --git a/tools/testing/selftests/mm/ksm_tests.c b/tools/testing/selftests/mm/ksm_tests.c
index fb62a36f9a786..69ee916740434 100644
--- a/tools/testing/selftests/mm/ksm_tests.c
+++ b/tools/testing/selftests/mm/ksm_tests.c
@@ -440,9 +440,9 @@ static int get_next_mem_node(int node)
mem_node = i % (max_node + 1);
node_size = numa_node_size(mem_node, NULL);
if (node_size > 0)
- break;
+ return mem_node;
}
- return mem_node;
+ return -ENODEV;
}
static int get_first_mem_node(void)
@@ -455,8 +455,8 @@ static int check_ksm_numa_merge(int merge_type, int mapping, int prot, int timeo
{
void *numa1_map_ptr, *numa2_map_ptr;
struct timespec start_time;
+ int first_node, second_node;
int page_count = 2;
- int first_node;
if (clock_gettime(CLOCK_MONOTONIC_RAW, &start_time)) {
ksft_perror("clock_gettime");
@@ -467,17 +467,19 @@ static int check_ksm_numa_merge(int merge_type, int mapping, int prot, int timeo
ksft_print_msg("NUMA support not enabled\n");
return KSFT_SKIP;
}
- if (numa_num_configured_nodes() <= 1) {
- ksft_print_msg("At least 2 NUMA nodes must be available\n");
+ first_node = get_first_mem_node();
+ second_node = get_next_mem_node(first_node);
+
+ if (second_node < 0) {
+ ksft_print_msg("At least 2 NUMA nodes with memory must be available\n");
return KSFT_SKIP;
}
if (ksm_write_sysfs(KSM_FP("merge_across_nodes"), merge_across_nodes))
return KSFT_FAIL;
/* allocate 2 pages in 2 different NUMA nodes and fill them with the same data */
- first_node = get_first_mem_node();
numa1_map_ptr = numa_alloc_onnode(page_size, first_node);
- numa2_map_ptr = numa_alloc_onnode(page_size, get_next_mem_node(first_node));
+ numa2_map_ptr = numa_alloc_onnode(page_size, second_node);
if (!numa1_map_ptr || !numa2_map_ptr) {
ksft_perror("numa_alloc_onnode");
return KSFT_FAIL;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0883/1518] selftests/mm: fix ternary operator precedence in ksm_tests
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (881 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0882/1518] selftests/mm: fix ksm NUMA merge test for systems with memoryless NUMA nodes Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0884/1518] arm64: dts: qcom: sc8280xp-blackrock: Fix swapped USB QMP PHY vdda-phy/vdda-pll supplies Greg Kroah-Hartman
` (115 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sayali Patil,
David Hildenbrand (Arm), Dev Jain, Liam Howlett, Miaohe Lin,
Michal Hocko, Oscar Salvador, Ritesh Harjani (IBM), Shuah Khan,
Zi Yan, Andrew Morton, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sayali Patil <sayalip@linux.ibm.com>
[ Upstream commit 4e1fbffb3333626682a011db7c4b4e9e40ba96d4 ]
The KSM selftest uses conditional expressions to skip accesses to
merge_across_nodes on systems without NUMA support. However, the ternary
operator is combined with logical OR without parentheses:
a || numa_available() ? 0 : b || c
Due to operator precedence rules, this is parsed as:
(a || numa_available()) ? 0 : (b || c)
instead of the intended:
a || (numa_available() ? 0 : b) || c
Add parentheses around the conditional expressions to ensure the
correct evaluation order.
Link: https://lore.kernel.org/ce859430287ed2642848c933a90eb9a69da361f0.1783446924.git.sayalip@linux.ibm.com
Fixes: 9aa1af954db0 ("selftests: vm: check numa_available() before operating "merge_across_nodes" in ksm_tests")
Signed-off-by: Sayali Patil <sayalip@linux.ibm.com>
Acked-by: David Hildenbrand (Arm) <david@kernel.org>
Cc: Dev Jain <dev.jain@arm.com>
Cc: Liam Howlett <liam@infradead.org>
Cc: Miaohe Lin <linmiaohe@huawei.com>
Cc: Michal Hocko <mhocko@kernel.org>
Cc: Oscar Salvador <osalvador@suse.de>
Cc: "Ritesh Harjani (IBM)" <ritesh.list@gmail.com>
Cc: Shuah Khan <shuah@kernel.org>
Cc: Zi Yan <ziy@nvidia.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/testing/selftests/mm/ksm_tests.c | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
diff --git a/tools/testing/selftests/mm/ksm_tests.c b/tools/testing/selftests/mm/ksm_tests.c
index 69ee916740434..e763295b5b2ae 100644
--- a/tools/testing/selftests/mm/ksm_tests.c
+++ b/tools/testing/selftests/mm/ksm_tests.c
@@ -288,8 +288,8 @@ static bool assert_ksm_pages_count(long dupl_page_count)
static int ksm_save_def(struct ksm_sysfs *ksm_sysfs)
{
if (ksm_read_sysfs(KSM_FP("max_page_sharing"), &ksm_sysfs->max_page_sharing) ||
- numa_available() ? 0 :
- ksm_read_sysfs(KSM_FP("merge_across_nodes"), &ksm_sysfs->merge_across_nodes) ||
+ (numa_available() ? 0 :
+ ksm_read_sysfs(KSM_FP("merge_across_nodes"), &ksm_sysfs->merge_across_nodes)) ||
ksm_read_sysfs(KSM_FP("sleep_millisecs"), &ksm_sysfs->sleep_millisecs) ||
ksm_read_sysfs(KSM_FP("pages_to_scan"), &ksm_sysfs->pages_to_scan) ||
ksm_read_sysfs(KSM_FP("run"), &ksm_sysfs->run) ||
@@ -304,8 +304,8 @@ static int ksm_save_def(struct ksm_sysfs *ksm_sysfs)
static int ksm_restore(struct ksm_sysfs *ksm_sysfs)
{
if (ksm_write_sysfs(KSM_FP("max_page_sharing"), ksm_sysfs->max_page_sharing) ||
- numa_available() ? 0 :
- ksm_write_sysfs(KSM_FP("merge_across_nodes"), ksm_sysfs->merge_across_nodes) ||
+ (numa_available() ? 0 :
+ ksm_write_sysfs(KSM_FP("merge_across_nodes"), ksm_sysfs->merge_across_nodes)) ||
ksm_write_sysfs(KSM_FP("pages_to_scan"), ksm_sysfs->pages_to_scan) ||
ksm_write_sysfs(KSM_FP("run"), ksm_sysfs->run) ||
ksm_write_sysfs(KSM_FP("sleep_millisecs"), ksm_sysfs->sleep_millisecs) ||
@@ -846,8 +846,8 @@ int main(int argc, char *argv[])
if (ksm_write_sysfs(KSM_FP("run"), 2) ||
ksm_write_sysfs(KSM_FP("sleep_millisecs"), 0) ||
- numa_available() ? 0 :
- ksm_write_sysfs(KSM_FP("merge_across_nodes"), 1) ||
+ (numa_available() ? 0 :
+ ksm_write_sysfs(KSM_FP("merge_across_nodes"), 1)) ||
ksm_write_sysfs(KSM_FP("pages_to_scan"), page_count))
ksft_exit_fail_msg("Cannot set up KSM tunables\n");
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0884/1518] arm64: dts: qcom: sc8280xp-blackrock: Fix swapped USB QMP PHY vdda-phy/vdda-pll supplies
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (882 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0883/1518] selftests/mm: fix ternary operator precedence in ksm_tests Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0885/1518] arm64: dts: qcom: qcs8550-aim300: " Greg Kroah-Hartman
` (114 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Manivannan Sadhasivam,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
[ Upstream commit ff7155df9a9543af1eb9722563e6dcda33c1a97d ]
The QMP PHY expects the vdda-phy supply to be around 0.88V and the
vdda-pll supply to be 1.2V. But these two supplies are swapped for the
USB QMP PHYs on this board, feeding 1.2V to vdda-phy and 0.9V to
vdda-pll.
Fix it by swapping the two supplies back.
Fixes: 16a7fed11714 ("arm64: dts: qcom: sc8280xp-blackrock: dt definition for WDK2023")
Reported-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Assisted-by: Claude:opus-4-8
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260803-phy-supply-fix-v1-2-5880630cde3e@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sc8280xp-microsoft-blackrock.dts | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sc8280xp-microsoft-blackrock.dts b/arch/arm64/boot/dts/qcom/sc8280xp-microsoft-blackrock.dts
index 3c3607929c2f2..454defd259560 100644
--- a/arch/arm64/boot/dts/qcom/sc8280xp-microsoft-blackrock.dts
+++ b/arch/arm64/boot/dts/qcom/sc8280xp-microsoft-blackrock.dts
@@ -1000,8 +1000,8 @@ &usb_0_hsphy {
};
&usb_0_qmpphy {
- vdda-phy-supply = <&vreg_l4d>;
- vdda-pll-supply = <&vreg_l9d>;
+ vdda-phy-supply = <&vreg_l9d>;
+ vdda-pll-supply = <&vreg_l4d>;
orientation-switch;
@@ -1037,8 +1037,8 @@ &usb_1_hsphy {
};
&usb_1_qmpphy {
- vdda-phy-supply = <&vreg_l3b>;
- vdda-pll-supply = <&vreg_l4b>;
+ vdda-phy-supply = <&vreg_l4b>;
+ vdda-pll-supply = <&vreg_l3b>;
orientation-switch;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0885/1518] arm64: dts: qcom: qcs8550-aim300: Fix swapped USB QMP PHY vdda-phy/vdda-pll supplies
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (883 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0884/1518] arm64: dts: qcom: sc8280xp-blackrock: Fix swapped USB QMP PHY vdda-phy/vdda-pll supplies Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0886/1518] arm64: dts: qcom: sm7225-fairphone-fp4: " Greg Kroah-Hartman
` (113 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Manivannan Sadhasivam,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
[ Upstream commit c0ea3b6339881c2a5fff0830557b1279d9681036 ]
The QMP PHY expects the vdda-phy supply to be around 0.88V and the
vdda-pll supply to be 1.2V. But these two supplies are swapped for the
USB QMP PHY on this board, feeding 1.2V to vdda-phy and 0.88V to
vdda-pll.
Fix it by swapping the two supplies back.
Fixes: 0b12da4e28d8 ("arm64: dts: qcom: add base AIM300 dtsi")
Reported-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Assisted-by: Claude:opus-4-8
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260803-phy-supply-fix-v1-11-5880630cde3e@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/qcs8550-aim300.dtsi | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/qcs8550-aim300.dtsi b/arch/arm64/boot/dts/qcom/qcs8550-aim300.dtsi
index e6ac529e6b721..3ead078246f48 100644
--- a/arch/arm64/boot/dts/qcom/qcs8550-aim300.dtsi
+++ b/arch/arm64/boot/dts/qcom/qcs8550-aim300.dtsi
@@ -396,8 +396,8 @@ &usb_1_hsphy {
};
&usb_dp_qmpphy {
- vdda-phy-supply = <&vreg_l3e_1p2>;
- vdda-pll-supply = <&vreg_l3f_0p88>;
+ vdda-phy-supply = <&vreg_l3f_0p88>;
+ vdda-pll-supply = <&vreg_l3e_1p2>;
};
&xo_board {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0886/1518] arm64: dts: qcom: sm7225-fairphone-fp4: Fix swapped USB QMP PHY vdda-phy/vdda-pll supplies
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (884 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0885/1518] arm64: dts: qcom: qcs8550-aim300: " Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0887/1518] arm64: dts: qcom: sar2130p: " Greg Kroah-Hartman
` (112 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Manivannan Sadhasivam,
Luca Weiss, Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
[ Upstream commit a3b3a060b696d964c769a7d9dc5835c79e4fe964 ]
The QMP PHY expects the vdda-phy supply to be around 0.88V and the
vdda-pll supply to be 1.2V. But these two supplies are swapped for the
USB QMP PHY on this board, feeding 1.2V to vdda-phy and 0.9V to
vdda-pll.
Fix it by swapping the two supplies back.
Fixes: 4cbea668767d ("arm64: dts: qcom: sm7225: Add device tree for Fairphone 4")
Reported-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Assisted-by: Claude:opus-4-8
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Reviewed-by: Luca Weiss <luca.weiss@fairphone.com>
Link: https://lore.kernel.org/r/20260803-phy-supply-fix-v1-14-5880630cde3e@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sm7225-fairphone-fp4.dts | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sm7225-fairphone-fp4.dts b/arch/arm64/boot/dts/qcom/sm7225-fairphone-fp4.dts
index b353de2bc37ad..b6d2a5d0c1c88 100644
--- a/arch/arm64/boot/dts/qcom/sm7225-fairphone-fp4.dts
+++ b/arch/arm64/boot/dts/qcom/sm7225-fairphone-fp4.dts
@@ -1179,8 +1179,8 @@ &usb_1_hsphy {
};
&usb_1_qmpphy {
- vdda-phy-supply = <&vreg_l22a>;
- vdda-pll-supply = <&vreg_l16a>;
+ vdda-phy-supply = <&vreg_l16a>;
+ vdda-pll-supply = <&vreg_l22a>;
status = "okay";
};
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0887/1518] arm64: dts: qcom: sar2130p: Fix swapped USB QMP PHY vdda-phy/vdda-pll supplies
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (885 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0886/1518] arm64: dts: qcom: sm7225-fairphone-fp4: " Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0888/1518] bpf: Check load-acquire src ptr type before the load Greg Kroah-Hartman
` (111 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Konrad Dybcio, Manivannan Sadhasivam,
Bjorn Andersson, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
[ Upstream commit 9d883d21fc12c873eee2f864f706c38a289bef59 ]
The QMP PHY expects the vdda-phy supply to be around 0.88V and the
vdda-pll supply to be 1.2V. But these two supplies are swapped for the
USB QMP PHY on this board, feeding 1.2V to vdda-phy and 0.9V to
vdda-pll.
Fix it by swapping the two supplies back.
Fixes: 6339e41fa39b ("arm64: dts: qcom: sar2130p: add QAR2130P board file")
Reported-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Assisted-by: Claude:opus-4-8
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Link: https://lore.kernel.org/r/20260803-phy-supply-fix-v1-22-5880630cde3e@oss.qualcomm.com
Signed-off-by: Bjorn Andersson <andersson@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/qcom/sar2130p-qar2130p.dts | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/arm64/boot/dts/qcom/sar2130p-qar2130p.dts b/arch/arm64/boot/dts/qcom/sar2130p-qar2130p.dts
index 74778a5b19ba6..80428c0b3b4e6 100644
--- a/arch/arm64/boot/dts/qcom/sar2130p-qar2130p.dts
+++ b/arch/arm64/boot/dts/qcom/sar2130p-qar2130p.dts
@@ -551,8 +551,8 @@ &usb_1_hsphy {
};
&usb_dp_qmpphy {
- vdda-phy-supply = <&vreg_l3a_1p2>;
- vdda-pll-supply = <&vreg_l1a_0p91>;
+ vdda-phy-supply = <&vreg_l1a_0p91>;
+ vdda-pll-supply = <&vreg_l3a_1p2>;
status = "okay";
};
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0888/1518] bpf: Check load-acquire src ptr type before the load
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (886 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0887/1518] arm64: dts: qcom: sar2130p: " Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0889/1518] intel_idle: Initialize sysfs after cpuidle driver initialization Greg Kroah-Hartman
` (110 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, STAR Labs SG, Daniel Borkmann,
Eduard Zingerman, Kumar Kartikeya Dwivedi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel Borkmann <daniel@iogearbox.net>
[ Upstream commit b87803391baa7e0bef60549d8841f12e549ad057 ]
check_atomic_load() calls check_load_mem() before atomic_ptr_type_ok().
For a load-acquire that fetches into its own source register (dst_reg ==
src_reg), check_load_mem() overwrites src_reg's type with the type of the
loaded value, so the subsequent atomic_ptr_type_ok() no longer sees the
source pointer and fails to reject the disallowed types (ctx, pkt,
flow_keys, sock).
Since bpf_convert_ctx_accesses() does not rewrite atomic loads, the raw
access to the underlying kernel object is left in place. The destination
type is taken from the ctx access itself, so a load-acquire of the sk
field of struct __sk_buff for example leaves the register typed as
PTR_TO_SOCK_COMMON_OR_NULL, which type_is_sk_pointer() does not match
either, while it actually holds unconverted struct sk_buff bytes. Once
the NULL check has passed this is a type confusion, not just a leak of
kernel data.
Validate src_reg with check_reg_arg() and check the source pointer type
with atomic_ptr_type_ok() before the load again, mirroring
check_atomic_rmw(). Out-of-range register numbers are already rejected
earlier by check_and_resolve_insns() (commit 503d21ef8eac ("bpf: Do
register range validation early")), and the only exemption there,
is_stack_arg_ldx(), requires BPF_LDX | BPF_MEM | BPF_DW and thus never
matches a BPF_ATOMIC insn. atomic_ptr_type_ok() can therefore not
dereference register state out of bounds, that is, the out-of-bounds
read addressed by the Fixes commit below does not reappear (as proven
also via selftest).
Fixes: c03bb2fa327e ("bpf: Fix out-of-bounds read in check_atomic_load/store()")
Reported-by: STAR Labs SG <info@starlabs.sg>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Eduard Zingerman <eddyz87@gmail.com>
Link: https://lore.kernel.org/bpf/20260804201917.253491-1-daniel@iogearbox.net
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/verifier.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index 39f45a08ab83c..23c9f7b5f522a 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -7975,7 +7975,7 @@ static int check_atomic_load(struct bpf_verifier_env *env,
{
int err;
- err = check_load_mem(env, insn, true, false, false, "atomic_load");
+ err = check_reg_arg(env, insn->src_reg, SRC_OP);
if (err)
return err;
@@ -7986,7 +7986,7 @@ static int check_atomic_load(struct bpf_verifier_env *env,
return -EACCES;
}
- return 0;
+ return check_load_mem(env, insn, true, false, false, "atomic_load");
}
static int check_atomic_store(struct bpf_verifier_env *env,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0889/1518] intel_idle: Initialize sysfs after cpuidle driver initialization
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (887 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0888/1518] bpf: Check load-acquire src ptr type before the load Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0890/1518] intel_idle: Add cmdline option to adjust C-states table Greg Kroah-Hartman
` (109 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Artem Bityutskiy, Rafael J. Wysocki,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Artem Bityutskiy <artem.bityutskiy@linux.intel.com>
[ Upstream commit ff24f314447a25164bac85cb310c382e289afdbe ]
Reorder initialization calls to initialize the internal driver data before
sysfs:
Was:
intel_idle_sysfs_init();
intel_idle_cpuidle_driver_init();
Now:
intel_idle_cpuidle_driver_init();
intel_idle_sysfs_init();
Follow the general principle that drivers should initialize internal state
before registering external interfaces like sysfs, avoiding potential usage
before full initialization.
Signed-off-by: Artem Bityutskiy <artem.bityutskiy@linux.intel.com>
Link: https://patch.msgid.link/20251216080402.156988-2-dedekind1@gmail.com
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Stable-dep-of: 9eadbed788df ("intel_idle: Avoid using deep idle states during initialization")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/idle/intel_idle.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/idle/intel_idle.c b/drivers/idle/intel_idle.c
index 9ba83954c2555..45903685fe680 100644
--- a/drivers/idle/intel_idle.c
+++ b/drivers/idle/intel_idle.c
@@ -2485,12 +2485,12 @@ static int __init intel_idle_init(void)
if (!intel_idle_cpuidle_devices)
return -ENOMEM;
+ intel_idle_cpuidle_driver_init(&intel_idle_driver);
+
retval = intel_idle_sysfs_init();
if (retval)
pr_warn("failed to initialized sysfs");
- intel_idle_cpuidle_driver_init(&intel_idle_driver);
-
retval = cpuidle_register_driver(&intel_idle_driver);
if (retval) {
struct cpuidle_driver *drv = cpuidle_get_driver();
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0890/1518] intel_idle: Add cmdline option to adjust C-states table
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (888 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0889/1518] intel_idle: Initialize sysfs after cpuidle driver initialization Greg Kroah-Hartman
@ 2026-09-12 6:50 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0891/1518] intel_idle: Avoid using deep idle states during initialization Greg Kroah-Hartman
` (108 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:50 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Artem Bityutskiy, Rafael J. Wysocki,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Artem Bityutskiy <artem.bityutskiy@linux.intel.com>
[ Upstream commit 111f77a233484cf39a6317f4d0306387e9ffda7b ]
Add a new module parameter that allows adjusting the C-states table used by
the driver.
Currently, the C-states table is hardcoded in the driver based on the CPU
model. The goal is to have good enough defaults for most users.
However, C-state characteristics, such as exit latency and residency, can
vary between different variants of the same CPU model and BIOS settings.
Moreover, different platform usage models and user preferences may benefit
from different C-state target_residency values.
Provide a way for users to adjust the C-states table via a module parameter
"table". The general format is:
"state1:latency1:target_residency1,state2:latency2:target_residency2,..."
In other words, represent each C-state by its name, exit latency (in
microseconds), and target residency (in microseconds), separated by colons.
Separate multiple C-states by commas.
For example, suppose a CPU has 3 C-states with the following
characteristics:
C1: exit_latency=1, target_residency=2
C1E: exit_latency=10, target_residency=10
C6: exit_latency=100, target_residency=500
Users can specify a custom C-states table as follows:
1. intel_idle.table="C1:2:2,C1E:5:20,C6:150:600"
Result: C1: exit_latency=2, target_residency=2
C1E: exit_latency=5, target_residency=20
C6: exit_latency=150, target_residency=600
2. intel_idle.table="C6::400"
Result: C1: exit_latency=1, target_residency=2 (unchanged)
C1E: exit_latency=10, target_residency=10 (unchanged)
C6: exit_latency=100, target_residency=400
(only target_residency changed)
Signed-off-by: Artem Bityutskiy <artem.bityutskiy@linux.intel.com>
Link: https://patch.msgid.link/20251216080402.156988-3-dedekind1@gmail.com
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Stable-dep-of: 9eadbed788df ("intel_idle: Avoid using deep idle states during initialization")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/idle/intel_idle.c | 169 ++++++++++++++++++++++++++++++++++++++
1 file changed, 169 insertions(+)
diff --git a/drivers/idle/intel_idle.c b/drivers/idle/intel_idle.c
index 45903685fe680..f5e301faa4761 100644
--- a/drivers/idle/intel_idle.c
+++ b/drivers/idle/intel_idle.c
@@ -76,6 +76,10 @@ static unsigned int preferred_states_mask __read_mostly;
static bool force_irq_on __read_mostly;
static bool ibrs_off __read_mostly;
+/* The maximum allowed length for the 'table' module parameter */
+#define MAX_CMDLINE_TABLE_LEN 256
+static char cmdline_table_str[MAX_CMDLINE_TABLE_LEN] __read_mostly;
+
static struct cpuidle_device __percpu *intel_idle_cpuidle_devices;
static unsigned long auto_demotion_disable_flags;
@@ -107,6 +111,9 @@ static struct device *sysfs_root __initdata;
static const struct idle_cpu *icpu __initdata;
static struct cpuidle_state *cpuidle_state_table __initdata;
+/* C-states data from the 'intel_idle.table' cmdline parameter */
+static struct cpuidle_state cmdline_states[CPUIDLE_STATE_MAX] __initdata;
+
static unsigned int mwait_substates __initdata;
/*
@@ -2420,6 +2427,149 @@ static void __init intel_idle_sysfs_uninit(void)
put_device(sysfs_root);
}
+ /**
+ * get_cmdline_field - Get the current field from a cmdline string.
+ * @args: The cmdline string to get the current field from.
+ * @field: Pointer to the current field upon return.
+ * @sep: The fields separator character.
+ *
+ * Examples:
+ * Input: args="C1:1:1,C1E:2:10", sep=':'
+ * Output: field="C1", return "1:1,C1E:2:10"
+ * Input: args="C1:1:1,C1E:2:10", sep=','
+ * Output: field="C1:1:1", return "C1E:2:10"
+ * Ipnut: args="::", sep=':'
+ * Output: field="", return ":"
+ *
+ * Return: The continuation of the cmdline string after the field or NULL.
+ */
+static char *get_cmdline_field(char *args, char **field, char sep)
+{
+ unsigned int i;
+
+ for (i = 0; args[i] && !isspace(args[i]); i++) {
+ if (args[i] == sep)
+ break;
+ }
+
+ *field = args;
+
+ if (args[i] != sep)
+ return NULL;
+
+ args[i] = '\0';
+ return args + i + 1;
+}
+
+/**
+ * cmdline_table_adjust - Adjust the C-states table with data from cmdline.
+ * @drv: cpuidle driver (assumed to point to intel_idle_driver).
+ *
+ * Adjust the C-states table with data from the 'intel_idle.table' module
+ * parameter (if specified).
+ */
+static void __init cmdline_table_adjust(struct cpuidle_driver *drv)
+{
+ char *args = cmdline_table_str;
+ struct cpuidle_state *state;
+ int i;
+
+ if (args[0] == '\0')
+ /* The 'intel_idle.table' module parameter was not specified */
+ return;
+
+ /* Create a copy of the C-states table */
+ for (i = 0; i < drv->state_count; i++)
+ cmdline_states[i] = drv->states[i];
+
+ /*
+ * Adjust the C-states table copy with data from the 'intel_idle.table'
+ * module parameter.
+ */
+ while (args) {
+ char *fields, *name, *val;
+
+ /*
+ * Get the next C-state definition, which is expected to be
+ * '<name>:<latency_us>:<target_residency_us>'. Treat "empty"
+ * fields as unchanged. For example,
+ * '<name>::<target_residency_us>' leaves the latency unchanged.
+ */
+ args = get_cmdline_field(args, &fields, ',');
+
+ /* name */
+ fields = get_cmdline_field(fields, &name, ':');
+ if (!fields)
+ goto error;
+
+ if (!strcmp(name, "POLL")) {
+ pr_err("Cannot adjust POLL\n");
+ continue;
+ }
+
+ /* Find the C-state by its name */
+ state = NULL;
+ for (i = 0; i < drv->state_count; i++) {
+ if (!strcmp(name, drv->states[i].name)) {
+ state = &cmdline_states[i];
+ break;
+ }
+ }
+
+ if (!state) {
+ pr_err("C-state '%s' was not found\n", name);
+ continue;
+ }
+
+ /* Latency */
+ fields = get_cmdline_field(fields, &val, ':');
+ if (!fields)
+ goto error;
+
+ if (*val) {
+ if (kstrtouint(val, 0, &state->exit_latency))
+ goto error;
+ }
+
+ /* Target residency */
+ fields = get_cmdline_field(fields, &val, ':');
+
+ if (*val) {
+ if (kstrtouint(val, 0, &state->target_residency))
+ goto error;
+ }
+
+ /*
+ * Allow for 3 more fields, but ignore them. Helps to make
+ * possible future extensions of the cmdline format backward
+ * compatible.
+ */
+ for (i = 0; fields && i < 3; i++) {
+ fields = get_cmdline_field(fields, &val, ':');
+ if (!fields)
+ break;
+ }
+
+ if (fields) {
+ pr_err("Too many fields for C-state '%s'\n", state->name);
+ goto error;
+ }
+
+ pr_info("C-state from cmdline: name=%s, latency=%u, residency=%u\n",
+ state->name, state->exit_latency, state->target_residency);
+ }
+
+ /* Copy the adjusted C-states table back */
+ for (i = 1; i < drv->state_count; i++)
+ drv->states[i] = cmdline_states[i];
+
+ pr_info("Adjusted C-states with data from 'intel_idle.table'\n");
+ return;
+
+error:
+ pr_info("Failed to adjust C-states with data from 'intel_idle.table'\n");
+}
+
static int __init intel_idle_init(void)
{
const struct x86_cpu_id *id;
@@ -2486,6 +2636,7 @@ static int __init intel_idle_init(void)
return -ENOMEM;
intel_idle_cpuidle_driver_init(&intel_idle_driver);
+ cmdline_table_adjust(&intel_idle_driver);
retval = intel_idle_sysfs_init();
if (retval)
@@ -2560,3 +2711,21 @@ module_param(force_irq_on, bool, 0444);
*/
module_param(ibrs_off, bool, 0444);
MODULE_PARM_DESC(ibrs_off, "Disable IBRS when idle");
+
+/*
+ * Define the C-states table from a user input string. Expected format is
+ * 'name:latency:residency', where:
+ * - name: The C-state name.
+ * - latency: The C-state exit latency in us.
+ * - residency: The C-state target residency in us.
+ *
+ * Multiple C-states can be defined by separating them with commas:
+ * 'name1:latency1:residency1,name2:latency2:residency2'
+ *
+ * Example: intel_idle.table=C1:1:1,C1E:5:10,C6:100:600
+ *
+ * To leave latency or residency unchanged, use an empty field, for example:
+ * 'C1:1:1,C1E::10' - leaves C1E latency unchanged.
+ */
+module_param_string(table, cmdline_table_str, MAX_CMDLINE_TABLE_LEN, 0444);
+MODULE_PARM_DESC(table, "Build the C-states table from a user input string");
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0891/1518] intel_idle: Avoid using deep idle states during initialization
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (889 preceding siblings ...)
2026-09-12 6:50 ` [PATCH 6.18 0890/1518] intel_idle: Add cmdline option to adjust C-states table Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0892/1518] scripts/tags.sh: Prevent binary files appearing in cscope.files Greg Kroah-Hartman
` (107 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Julian Silver, Rafael J. Wysocki,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
[ Upstream commit 9eadbed788df453289b5927327bd22edb542f472 ]
Commit c0f691388992 ("intel_idle: Use subsys_initcall_sync() for
initialization") effectively made intel_idle initialize earlier which
turns out to interfere with USB EHCI probing on some platforms [1].
Investigation led to the conclusion that this was related to allowing
package idle states to be used earlier than before.
Work around that issue by making intel_idle set a CPU latency QoS
request to prevent package idle states from being used on all platforms
supported by it for the duration of the device_initcall() initialization
phase.
Fixes: c0f691388992 ("intel_idle: Use subsys_initcall_sync() for initialization")
Reported-by: Julian Silver <mendaxca@gmail.com>
Tested-by: Julian Silver <mendaxca@gmail.com>
Closes: https://lore.kernel.org/linux-acpi/3353bdf3-4f33-44b1-809b-b0378bee5816@gmail.com/
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Link: https://patch.msgid.link/5120454.31r3eYUQgx@rafael.j.wysocki
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/idle/intel_idle.c | 23 +++++++++++++++++++++++
1 file changed, 23 insertions(+)
diff --git a/drivers/idle/intel_idle.c b/drivers/idle/intel_idle.c
index f5e301faa4761..922ed32f73ed0 100644
--- a/drivers/idle/intel_idle.c
+++ b/drivers/idle/intel_idle.c
@@ -52,6 +52,7 @@
#include <linux/notifier.h>
#include <linux/cpu.h>
#include <linux/moduleparam.h>
+#include <linux/pm_qos.h>
#include <linux/sysfs.h>
#include <asm/cpuid/api.h>
#include <asm/cpu_device_id.h>
@@ -2570,6 +2571,9 @@ static void __init cmdline_table_adjust(struct cpuidle_driver *drv)
pr_info("Failed to adjust C-states with data from 'intel_idle.table'\n");
}
+#define INTEL_IDLE_INIT_QOS 20
+static struct pm_qos_request qos_req __initdata;
+
static int __init intel_idle_init(void)
{
const struct x86_cpu_id *id;
@@ -2642,6 +2646,13 @@ static int __init intel_idle_init(void)
if (retval)
pr_warn("failed to initialized sysfs");
+ /*
+ * Some platforms, in particular the Intel S1200BTL motherboard, have a
+ * problem with using package idle states too early, so prevent that
+ * from taking place until the device_initcall() phase is over.
+ */
+ cpu_latency_qos_add_request(&qos_req, INTEL_IDLE_INIT_QOS);
+
retval = cpuidle_register_driver(&intel_idle_driver);
if (retval) {
struct cpuidle_driver *drv = cpuidle_get_driver();
@@ -2666,6 +2677,9 @@ static int __init intel_idle_init(void)
intel_idle_cpuidle_devices_uninit();
cpuidle_unregister_driver(&intel_idle_driver);
init_driver_fail:
+ if (cpu_latency_qos_request_active((&qos_req)))
+ cpu_latency_qos_remove_request(&qos_req);
+
intel_idle_sysfs_uninit();
free_percpu(intel_idle_cpuidle_devices);
return retval;
@@ -2673,6 +2687,15 @@ static int __init intel_idle_init(void)
}
subsys_initcall_sync(intel_idle_init);
+static int __init intel_idle_init_complete(void)
+{
+ if (cpu_latency_qos_request_active((&qos_req)))
+ cpu_latency_qos_remove_request(&qos_req);
+
+ return 0;
+}
+device_initcall_sync(intel_idle_init_complete);
+
/*
* We are not really modular, but we used to support that. Meaning we also
* support "intel_idle.max_cstate=..." at boot and also a read-only export of
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0892/1518] scripts/tags.sh: Prevent binary files appearing in cscope.files
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (890 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0891/1518] intel_idle: Avoid using deep idle states during initialization Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0893/1518] modpost: prevent leak when early return no suffix .o in read_symbols() Greg Kroah-Hartman
` (106 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Sergei Litvin, Miguel Ojeda,
Nicolas Schier, Nicolas Schier, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sergei Litvin <litvindev@gmail.com>
[ Upstream commit a9b93c34625a27bed5dc0f80ee2a359ceb955172 ]
When executing the command `make COMPILED_SOURCE=1 cscope`, the resulting
`cscope.files` file contains filenames with the extensions *.rlib, *.rmeta,
and *.so.
To fix this, modify the regular expression in the `all_compiled_sources()`
function so that only files with the extensions *.h, *.c, *.S, and *.rs are
accepted.
The issue has been introduced by commit 4f491bb6ea2a ("scripts/tags.sh:
collect compiled source precisely") which implemented the parsing of
compiled sources from *.cmd files instead of using the "find" command.
Fixes: 4f491bb6ea2a ("scripts/tags.sh: collect compiled source precisely")
Signed-off-by: Sergei Litvin <litvindev@gmail.com>
Acked-by: Miguel Ojeda <ojeda@kernel.org>
Tested-by: Nicolas Schier <n.schier@fritz.com>
Reviewed-by: Nicolas Schier <n.schier@fritz.com>
Link: https://patch.msgid.link/20260714083331.69482-1-litvindev@gmail.com
[nsc: cleaned-up commit message line breaks and removed cc trailers]
Signed-off-by: Nicolas Schier <nsc@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
scripts/tags.sh | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/scripts/tags.sh b/scripts/tags.sh
index 99ce427d9a69d..173f5d23c4dc0 100755
--- a/scripts/tags.sh
+++ b/scripts/tags.sh
@@ -100,7 +100,7 @@ all_compiled_sources()
{
echo include/generated/autoconf.h
find $ignore -name "*.cmd" -exec \
- grep -Poh '(?<=^ )\S+|(?<== )\S+[^\\](?=$)' {} \+ |
+ grep -Poh '(?<=^ )\S+\.([chS]|rs)(?=\s)|(?<== )\S+\.(?1)(?=$)' {} \+ |
awk '!a[$0]++'
} | xargs realpath -esq $([ -z "$KBUILD_ABS_SRCTREE" ] && echo --relative-to=.) |
sort -u
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0893/1518] modpost: prevent leak when early return no suffix .o in read_symbols()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (891 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0892/1518] scripts/tags.sh: Prevent binary files appearing in cscope.files Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0894/1518] kbuild: fix modules.builtin(.modinfo) targets in the top-level Makefile Greg Kroah-Hartman
` (105 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Robertus Diawan Chris,
Nathan Chancellor, Nicolas Schier, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Robertus Diawan Chris <robertusdchris@gmail.com>
[ Upstream commit 9a5b76027ed91680e10f90111d9cba300f96d1ab ]
The allocation for elf info symsearch and hdr from parse_elf() haven't
been released when return because of modname didn't have suffix ".o".
And it seems like the suffix ".o" check did not depends on parse_elf()
to succeed first. So, move the suffix ".o" check before checking
parse_elf() result to prevent resource leak when the modname didn't have
suffix ".o" and return early.
This is reported by Coverity Scan as "Resource leak".
Fixes: 8c9ce89c5b63 ("modpost: simplify mod->name allocation")
Signed-off-by: Robertus Diawan Chris <robertusdchris@gmail.com>
Reviewed-by: Nathan Chancellor <nathan@kernel.org>
Link: https://patch.msgid.link/20260624044742.144852-1-robertusdchris@gmail.com
Signed-off-by: Nicolas Schier <nsc@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
scripts/mod/modpost.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/scripts/mod/modpost.c b/scripts/mod/modpost.c
index 010c398f6a705..31f81f25968fa 100644
--- a/scripts/mod/modpost.c
+++ b/scripts/mod/modpost.c
@@ -1570,14 +1570,14 @@ static void read_symbols(const char *modname)
struct elf_info info = { };
Elf_Sym *sym;
- if (!parse_elf(&info, modname))
- return;
-
if (!strends(modname, ".o")) {
error("%s: filename must be suffixed with .o\n", modname);
return;
}
+ if (!parse_elf(&info, modname))
+ return;
+
/* strip trailing .o */
mod = new_module(modname, strlen(modname) - strlen(".o"));
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0894/1518] kbuild: fix modules.builtin(.modinfo) targets in the top-level Makefile
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (892 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0893/1518] modpost: prevent leak when early return no suffix .o in read_symbols() Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0895/1518] RDMA/erdma: Hold CQ references when processing EQ events Greg Kroah-Hartman
` (104 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yuntao Wang, Nathan Chancellor,
Nicolas Schier, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuntao Wang <yuntao.wang@linux.dev>
[ Upstream commit 69ef27076d19297c0bf3bd22171fab8d87464a09 ]
Commit 7a342e6c7735 ("kbuild: move modules.builtin(.modinfo) rules to
Makefile.vmlinux_o") moved the modules.builtin(.modinfo) rules from
link-vmlinux.sh to Makefile.vmlinux_o, and added the corresponding
targets to the top-level Makefile.
Commit 39cfd5b12160 ("kbuild: extract modules.builtin.modinfo from
vmlinux.unstripped") later moved these rules from Makefile.vmlinux_o to
Makefile.vmlinux, but left the corresponding targets in the top-level
Makefile unchanged.
These modules.builtin(.modinfo) targets in the top-level Makefile should
be moved alongside the vmlinux target, since they are now generated by
Makefile.vmlinux.
However, simply removing these trivial targets might be a better choice,
as it makes the Makefile cleaner and avoids the need to keep them in sync
across multiple files, reducing the chance of future mistakes.
Fixes: 39cfd5b12160 ("kbuild: extract modules.builtin.modinfo from vmlinux.unstripped")
Signed-off-by: Yuntao Wang <yuntao.wang@linux.dev>
Reviewed-by: Nathan Chancellor <nathan@kernel.org>
Link: https://patch.msgid.link/20260729071737.818007-1-yuntao.wang@linux.dev
Signed-off-by: Nicolas Schier <nsc@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
Makefile | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/Makefile b/Makefile
index 392e92c29d42e..a04fe733e1648 100644
--- a/Makefile
+++ b/Makefile
@@ -1252,7 +1252,7 @@ PHONY += vmlinux_o
vmlinux_o: vmlinux.a $(KBUILD_VMLINUX_LIBS)
$(Q)$(MAKE) -f $(srctree)/scripts/Makefile.vmlinux_o
-vmlinux.o modules.builtin.modinfo modules.builtin: vmlinux_o
+vmlinux.o: vmlinux_o
@:
PHONY += vmlinux
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0895/1518] RDMA/erdma: Hold CQ references when processing EQ events
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (893 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0894/1518] kbuild: fix modules.builtin(.modinfo) targets in the top-level Makefile Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0896/1518] RDMA/erdma: Hold QP references for AE and CM processing Greg Kroah-Hartman
` (103 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Cheng Xu, Leon Romanovsky,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cheng Xu <chengyou@linux.alibaba.com>
[ Upstream commit 98df2aee1459ee1c62c70cbe9b370d2a532aea36 ]
EQ handlers look up CQs from dev->cq_xa and invoke CQ completion or
error callbacks outside the xarray lock. erdma_destroy_cq() can erase the
CQ from the xarray and free its queue buffer and doorbell record while a
previously scheduled EQ handler is still using the CQ.
Add a CQ refcount and take a reference under the xarray lock with
refcount_inc_not_zero(). Remove the CQ from the xarray before dropping
the destroy-path reference, then wait for in-flight EQ users before
releasing CQ resources.
Fixes: 155055771704 ("RDMA/erdma: Add verbs implementation")
Signed-off-by: Cheng Xu <chengyou@linux.alibaba.com>
Link: https://patch.msgid.link/20260730124357.12976-1-chengyou@linux.alibaba.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/erdma/erdma_eq.c | 6 ++++--
drivers/infiniband/hw/erdma/erdma_verbs.c | 12 +++++++++--
drivers/infiniband/hw/erdma/erdma_verbs.h | 25 +++++++++++++++++++++--
3 files changed, 37 insertions(+), 6 deletions(-)
diff --git a/drivers/infiniband/hw/erdma/erdma_eq.c b/drivers/infiniband/hw/erdma/erdma_eq.c
index 5610e7f4c6bf7..6bffbc1b543be 100644
--- a/drivers/infiniband/hw/erdma/erdma_eq.c
+++ b/drivers/infiniband/hw/erdma/erdma_eq.c
@@ -52,7 +52,7 @@ void erdma_aeq_event_handler(struct erdma_dev *dev)
if (FIELD_GET(ERDMA_AEQE_HDR_TYPE_MASK,
le32_to_cpu(aeqe->hdr)) == ERDMA_AE_TYPE_CQ_ERR) {
cqn = le32_to_cpu(aeqe->event_data0);
- cq = find_cq_by_cqn(dev, cqn);
+ cq = erdma_cq_get_by_cqn(dev, cqn);
if (!cq)
continue;
@@ -62,6 +62,7 @@ void erdma_aeq_event_handler(struct erdma_dev *dev)
if (cq->ibcq.event_handler)
cq->ibcq.event_handler(&event,
cq->ibcq.cq_context);
+ erdma_cq_put(cq);
} else {
qpn = le32_to_cpu(aeqe->event_data0);
qp = find_qp_by_qpn(dev, qpn);
@@ -157,7 +158,7 @@ void erdma_ceq_completion_handler(struct erdma_eq_cb *ceq_cb)
poll_cnt++;
cqn = FIELD_GET(ERDMA_CEQE_HDR_CQN_MASK, READ_ONCE(*ceqe));
- cq = find_cq_by_cqn(dev, cqn);
+ cq = erdma_cq_get_by_cqn(dev, cqn);
if (!cq)
continue;
@@ -166,6 +167,7 @@ void erdma_ceq_completion_handler(struct erdma_eq_cb *ceq_cb)
if (cq->ibcq.comp_handler)
cq->ibcq.comp_handler(&cq->ibcq, cq->ibcq.cq_context);
+ erdma_cq_put(cq);
}
notify_eq(&ceq_cb->eq);
diff --git a/drivers/infiniband/hw/erdma/erdma_verbs.c b/drivers/infiniband/hw/erdma/erdma_verbs.c
index 4c78013b056fa..e70a95897581a 100644
--- a/drivers/infiniband/hw/erdma/erdma_verbs.c
+++ b/drivers/infiniband/hw/erdma/erdma_verbs.c
@@ -1327,6 +1327,7 @@ int erdma_destroy_cq(struct ib_cq *ibcq, struct ib_udata *udata)
struct erdma_dev *dev = to_edev(ibcq->device);
struct erdma_ucontext *ctx = rdma_udata_to_drv_context(
udata, struct erdma_ucontext, ibucontext);
+ unsigned long flags;
int err;
struct erdma_cmdq_destroy_cq_req req;
@@ -1341,6 +1342,13 @@ int erdma_destroy_cq(struct ib_cq *ibcq, struct ib_udata *udata)
"failed to destroy CQ %u: %d\n",
cq->cqn, err);
+ xa_lock_irqsave(&dev->cq_xa, flags);
+ __xa_erase(&dev->cq_xa, cq->cqn);
+ xa_unlock_irqrestore(&dev->cq_xa, flags);
+
+ erdma_cq_put(cq);
+ wait_for_completion(&cq->free);
+
if (rdma_is_kernel_res(&cq->ibcq.res)) {
dma_free_coherent(&dev->pdev->dev, cq->depth << CQE_SHIFT,
cq->kern_cq.qbuf, cq->kern_cq.qbuf_dma_addr);
@@ -1351,8 +1359,6 @@ int erdma_destroy_cq(struct ib_cq *ibcq, struct ib_udata *udata)
put_mtt_entries(dev, &cq->user_cq.qbuf_mem);
}
- xa_erase(&dev->cq_xa, cq->cqn);
-
return 0;
}
@@ -1981,6 +1987,8 @@ int erdma_create_cq(struct ib_cq *ibcq, const struct ib_cq_init_attr *attr,
cq->ibcq.cqe = depth;
cq->depth = depth;
cq->assoc_eqn = attr->comp_vector + 1;
+ refcount_set(&cq->refcount, 1);
+ init_completion(&cq->free);
ret = xa_alloc_cyclic(&dev->cq_xa, &cq->cqn, cq,
XA_LIMIT(1, dev->attrs.max_cq - 1),
diff --git a/drivers/infiniband/hw/erdma/erdma_verbs.h b/drivers/infiniband/hw/erdma/erdma_verbs.h
index 7d8d3fe501d5c..894e080435fbf 100644
--- a/drivers/infiniband/hw/erdma/erdma_verbs.h
+++ b/drivers/infiniband/hw/erdma/erdma_verbs.h
@@ -7,6 +7,9 @@
#ifndef __ERDMA_VERBS_H__
#define __ERDMA_VERBS_H__
+#include <linux/completion.h>
+#include <linux/refcount.h>
+
#include "erdma.h"
/* RDMA Capability. */
@@ -341,6 +344,8 @@ struct erdma_cq {
u32 depth;
u32 assoc_eqn;
+ refcount_t refcount;
+ struct completion free;
union {
struct erdma_kcq_info kern_cq;
@@ -355,9 +360,25 @@ static inline struct erdma_qp *find_qp_by_qpn(struct erdma_dev *dev, int id)
return (struct erdma_qp *)xa_load(&dev->qp_xa, id);
}
-static inline struct erdma_cq *find_cq_by_cqn(struct erdma_dev *dev, int id)
+static inline struct erdma_cq *erdma_cq_get_by_cqn(struct erdma_dev *dev,
+ int id)
+{
+ struct erdma_cq *cq;
+ unsigned long flags;
+
+ xa_lock_irqsave(&dev->cq_xa, flags);
+ cq = xa_load(&dev->cq_xa, id);
+ if (cq && !refcount_inc_not_zero(&cq->refcount))
+ cq = NULL;
+ xa_unlock_irqrestore(&dev->cq_xa, flags);
+
+ return cq;
+}
+
+static inline void erdma_cq_put(struct erdma_cq *cq)
{
- return (struct erdma_cq *)xa_load(&dev->cq_xa, id);
+ if (refcount_dec_and_test(&cq->refcount))
+ complete(&cq->free);
}
void erdma_qp_get(struct erdma_qp *qp);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0896/1518] RDMA/erdma: Hold QP references for AE and CM processing
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (894 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0895/1518] RDMA/erdma: Hold CQ references when processing EQ events Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0897/1518] RDMA/srp: fix heap information leak on a truncated SRP_CRED_REQ Greg Kroah-Hartman
` (102 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Cheng Xu, Leon Romanovsky,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cheng Xu <chengyou@linux.alibaba.com>
[ Upstream commit a52eeff32024f190b3bdc99088c7becccd4fa60b ]
AE QP fatal events and iWARP CM paths load QPs from dev->qp_xa
and then use or reference them outside the xarray lock.
erdma_destroy_qp() can drop the destroy-path reference and free QP
resources while such a lookup is in flight.
Add erdma_qp_get_by_qpn() to acquire a kref under the xarray
lock with kref_get_unless_zero(). Remove the QP from the xarray
before dropping the destroy-path reference so no new lookup can acquire
it while destruction waits for existing users.
Fixes: 155055771704 ("RDMA/erdma: Add verbs implementation")
Signed-off-by: Cheng Xu <chengyou@linux.alibaba.com>
Link: https://patch.msgid.link/20260730124357.12976-2-chengyou@linux.alibaba.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/erdma/erdma_cm.c | 6 ++----
drivers/infiniband/hw/erdma/erdma_eq.c | 3 ++-
drivers/infiniband/hw/erdma/erdma_verbs.c | 6 +++++-
drivers/infiniband/hw/erdma/erdma_verbs.h | 15 +++++++++++++++
4 files changed, 24 insertions(+), 6 deletions(-)
diff --git a/drivers/infiniband/hw/erdma/erdma_cm.c b/drivers/infiniband/hw/erdma/erdma_cm.c
index e0acc185e7193..f0c8ebf62a057 100644
--- a/drivers/infiniband/hw/erdma/erdma_cm.c
+++ b/drivers/infiniband/hw/erdma/erdma_cm.c
@@ -1021,10 +1021,9 @@ int erdma_connect(struct iw_cm_id *id, struct iw_cm_conn_param *params)
if (laddr->sa_family != AF_INET || raddr->sa_family != AF_INET)
return -EAFNOSUPPORT;
- qp = find_qp_by_qpn(dev, params->qpn);
+ qp = erdma_qp_get_by_qpn(dev, params->qpn);
if (!qp)
return -ENOENT;
- erdma_qp_get(qp);
ret = sock_create(AF_INET, SOCK_STREAM, IPPROTO_TCP, &s);
if (ret < 0)
@@ -1154,10 +1153,9 @@ int erdma_accept(struct iw_cm_id *id, struct iw_cm_conn_param *params)
return -ECONNRESET;
}
- qp = find_qp_by_qpn(dev, params->qpn);
+ qp = erdma_qp_get_by_qpn(dev, params->qpn);
if (!qp)
return -ENOENT;
- erdma_qp_get(qp);
down_write(&qp->state_lock);
if (qp->attrs.iwarp.state > ERDMA_QPS_IWARP_RTR) {
diff --git a/drivers/infiniband/hw/erdma/erdma_eq.c b/drivers/infiniband/hw/erdma/erdma_eq.c
index 6bffbc1b543be..e4161e85422c6 100644
--- a/drivers/infiniband/hw/erdma/erdma_eq.c
+++ b/drivers/infiniband/hw/erdma/erdma_eq.c
@@ -65,7 +65,7 @@ void erdma_aeq_event_handler(struct erdma_dev *dev)
erdma_cq_put(cq);
} else {
qpn = le32_to_cpu(aeqe->event_data0);
- qp = find_qp_by_qpn(dev, qpn);
+ qp = erdma_qp_get_by_qpn(dev, qpn);
if (!qp)
continue;
@@ -75,6 +75,7 @@ void erdma_aeq_event_handler(struct erdma_dev *dev)
if (qp->ibqp.event_handler)
qp->ibqp.event_handler(&event,
qp->ibqp.qp_context);
+ erdma_qp_put(qp);
}
}
diff --git a/drivers/infiniband/hw/erdma/erdma_verbs.c b/drivers/infiniband/hw/erdma/erdma_verbs.c
index e70a95897581a..fdd67756f3bc3 100644
--- a/drivers/infiniband/hw/erdma/erdma_verbs.c
+++ b/drivers/infiniband/hw/erdma/erdma_verbs.c
@@ -1370,6 +1370,7 @@ int erdma_destroy_qp(struct ib_qp *ibqp, struct ib_udata *udata)
udata, struct erdma_ucontext, ibucontext);
struct erdma_cmdq_destroy_qp_req req;
union erdma_mod_qp_params params;
+ unsigned long flags;
int err;
down_write(&qp->state_lock);
@@ -1397,6 +1398,10 @@ int erdma_destroy_qp(struct ib_qp *ibqp, struct ib_udata *udata)
"failed to destroy QP %u: %d\n",
QP_ID(qp), err);
+ xa_lock_irqsave(&dev->qp_xa, flags);
+ __xa_erase(&dev->qp_xa, QP_ID(qp));
+ xa_unlock_irqrestore(&dev->qp_xa, flags);
+
erdma_qp_put(qp);
wait_for_completion(&qp->safe_free);
@@ -1410,7 +1415,6 @@ int erdma_destroy_qp(struct ib_qp *ibqp, struct ib_udata *udata)
if (qp->cep)
erdma_cep_put(qp->cep);
- xa_erase(&dev->qp_xa, QP_ID(qp));
return 0;
}
diff --git a/drivers/infiniband/hw/erdma/erdma_verbs.h b/drivers/infiniband/hw/erdma/erdma_verbs.h
index 894e080435fbf..c73cecf92f611 100644
--- a/drivers/infiniband/hw/erdma/erdma_verbs.h
+++ b/drivers/infiniband/hw/erdma/erdma_verbs.h
@@ -360,6 +360,21 @@ static inline struct erdma_qp *find_qp_by_qpn(struct erdma_dev *dev, int id)
return (struct erdma_qp *)xa_load(&dev->qp_xa, id);
}
+static inline struct erdma_qp *erdma_qp_get_by_qpn(struct erdma_dev *dev,
+ int id)
+{
+ struct erdma_qp *qp;
+ unsigned long flags;
+
+ xa_lock_irqsave(&dev->qp_xa, flags);
+ qp = xa_load(&dev->qp_xa, id);
+ if (qp && !kref_get_unless_zero(&qp->ref))
+ qp = NULL;
+ xa_unlock_irqrestore(&dev->qp_xa, flags);
+
+ return qp;
+}
+
static inline struct erdma_cq *erdma_cq_get_by_cqn(struct erdma_dev *dev,
int id)
{
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0897/1518] RDMA/srp: fix heap information leak on a truncated SRP_CRED_REQ
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (895 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0896/1518] RDMA/erdma: Hold QP references for AE and CM processing Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0898/1518] ARM: 9481/2: breakpoint: CFI breakpoints only on demand Greg Kroah-Hartman
` (101 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yehyeong Lee, Bart Van Assche,
Leon Romanovsky, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
[ Upstream commit 961ac0f0c5e414abdd6b33fae84b311d9fde0bd0 ]
srp_recv_done() passes wc->byte_len to srp_process_rsp(). It passes
nothing to srp_process_cred_req() and srp_process_aer_req(), which read
fixed-size fields from the receive buffer without checking that those
fields were received.
The buffer size is max_ti_iu_len, which comes from the login response
and is not validated. A target that advertises 8 and then sends an
8-byte SRP_CRED_REQ makes the initiator read req->tag from beyond the
end of the buffer. req->tag is copied into the SRP_CRED_RSP and sent
back, so those bytes reach the target. SRP_AER_REQ behaves the same way
and also reads req->lun.
The leak is 8 bytes per response. max_ti_iu_len also decides which slab
cache the buffer comes from. With 8 the buffer is a kmalloc-8 object and
the read is entirely outside it:
BUG: KASAN: slab-out-of-bounds in srp_recv_done+0x172b/0x1aa0
Read of size 8 at addr ffff888104714da8 by task kworker/u8:3/50
which belongs to the cache kmalloc-8 of size 8
The buggy address is located 0 bytes to the right of
allocated 8-byte region [ffff888104714da0, ffff888104714da8)
Without KASAN the returned bytes are whatever is next in the slab. One
run returned ".strtab".
rsp->data[3] in srp_process_rsp() has the same problem: only
resp_data_len is checked before it is read.
Drop a request that is shorter than the structure being parsed, and
check byte_len before the tsk_mgmt read.
Fixes: bb12588a38e6 ("IB/srp: Implement SRP_CRED_REQ and SRP_AER_REQ")
Signed-off-by: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
Link: https://patch.msgid.link/20260729093203.1503201-1-yhlee@isslab.korea.ac.kr
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/ulp/srp/ib_srp.c | 45 +++++++++++++++++++----------
1 file changed, 30 insertions(+), 15 deletions(-)
diff --git a/drivers/infiniband/ulp/srp/ib_srp.c b/drivers/infiniband/ulp/srp/ib_srp.c
index 7b696a07e6033..99131492abf70 100644
--- a/drivers/infiniband/ulp/srp/ib_srp.c
+++ b/drivers/infiniband/ulp/srp/ib_srp.c
@@ -1943,7 +1943,8 @@ static void srp_process_rsp(struct srp_rdma_ch *ch, struct srp_rsp *rsp,
ch->req_lim += be32_to_cpu(rsp->req_lim_delta);
if (rsp->tag == ch->tsk_mgmt_tag) {
ch->tsk_mgmt_status = -1;
- if (be32_to_cpu(rsp->resp_data_len) >= 4)
+ if (be32_to_cpu(rsp->resp_data_len) >= 4 &&
+ byte_len >= sizeof(*rsp) + 4)
ch->tsk_mgmt_status = rsp->data[3];
complete(&ch->tsk_mgmt_done);
} else {
@@ -2043,13 +2044,20 @@ static int srp_response_common(struct srp_rdma_ch *ch, s32 req_delta,
}
static void srp_process_cred_req(struct srp_rdma_ch *ch,
- struct srp_cred_req *req)
+ struct srp_cred_req *req, u32 byte_len)
{
- struct srp_cred_rsp rsp = {
- .opcode = SRP_CRED_RSP,
- .tag = req->tag,
- };
- s32 delta = be32_to_cpu(req->req_lim_delta);
+ struct srp_cred_rsp rsp = { .opcode = SRP_CRED_RSP };
+ s32 delta;
+
+ if (byte_len < sizeof(*req)) {
+ shost_printk(KERN_ERR, ch->target->scsi_host, PFX
+ "dropping truncated SRP_CRED_REQ (%u bytes received, %zu expected)\n",
+ byte_len, sizeof(*req));
+ return;
+ }
+
+ rsp.tag = req->tag;
+ delta = be32_to_cpu(req->req_lim_delta);
if (srp_response_common(ch, delta, &rsp, sizeof(rsp)))
shost_printk(KERN_ERR, ch->target->scsi_host, PFX
@@ -2057,14 +2065,21 @@ static void srp_process_cred_req(struct srp_rdma_ch *ch,
}
static void srp_process_aer_req(struct srp_rdma_ch *ch,
- struct srp_aer_req *req)
+ struct srp_aer_req *req, u32 byte_len)
{
struct srp_target_port *target = ch->target;
- struct srp_aer_rsp rsp = {
- .opcode = SRP_AER_RSP,
- .tag = req->tag,
- };
- s32 delta = be32_to_cpu(req->req_lim_delta);
+ struct srp_aer_rsp rsp = { .opcode = SRP_AER_RSP };
+ s32 delta;
+
+ if (byte_len < sizeof(*req)) {
+ shost_printk(KERN_ERR, target->scsi_host, PFX
+ "dropping truncated SRP_AER_REQ (%u bytes received, %zu expected)\n",
+ byte_len, sizeof(*req));
+ return;
+ }
+
+ rsp.tag = req->tag;
+ delta = be32_to_cpu(req->req_lim_delta);
shost_printk(KERN_ERR, target->scsi_host, PFX
"ignoring AER for LUN %llu\n", scsilun_to_int(&req->lun));
@@ -2106,11 +2121,11 @@ static void srp_recv_done(struct ib_cq *cq, struct ib_wc *wc)
break;
case SRP_CRED_REQ:
- srp_process_cred_req(ch, iu->buf);
+ srp_process_cred_req(ch, iu->buf, wc->byte_len);
break;
case SRP_AER_REQ:
- srp_process_aer_req(ch, iu->buf);
+ srp_process_aer_req(ch, iu->buf, wc->byte_len);
break;
case SRP_T_LOGOUT:
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0898/1518] ARM: 9481/2: breakpoint: CFI breakpoints only on demand
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (896 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0897/1518] RDMA/srp: fix heap information leak on a truncated SRP_CRED_REQ Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0899/1518] ARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults Greg Kroah-Hartman
` (100 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, slipher, Mark Rutland, Linus Walleij,
Russell King, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linus Walleij <linusw@kernel.org>
[ Upstream commit 8ed9bff906cf8036531d1559f10e82733a52b41f ]
This removes the stub hw_breakpoint_cfi_handler() from ARM, making
it not steal breakpoint type 0x03 (ARM_ENTRY_CFI_BREAKPOINT) unless
CFI is actively used in the kernel.
When not instrumenting with CFI, or when a breakpoint is issued in
userspace, we fall through to return 1 from hw_breakpoint_pending()
"unhandled fault" so userspace can make use of this breakpoint.
Tested with LKDTM and this command line:
echo CFI_FORWARD_PROTO > /sys/kernel/debug/provoke-crash/DIRECT
still works as expected.
Closes: https://lore.kernel.org/lkml/kJqktbpLphg_Pk5I5SPptgTLjl3E3eq5mN5UzCslyFj7Q1Irp-wDid4mj5eQVd2iZtRGXgeZd8goq195EkXdjyt864YMc8mVb2B9NGH91NQ=@protonmail.com/
Fixes: c3f89986fde7 ("ARM: 9391/2: hw_breakpoint: Handle CFI breakpoints")
Reported-by: slipher <slipher@protonmail.com>
Suggested-by: Mark Rutland <mark.rutland@arm.com>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Russell King <rmk+kernel@armlinux.org.uk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm/kernel/hw_breakpoint.c | 11 ++++++-----
1 file changed, 6 insertions(+), 5 deletions(-)
diff --git a/arch/arm/kernel/hw_breakpoint.c b/arch/arm/kernel/hw_breakpoint.c
index cd4b34c96e35e..38feb30dfb5f8 100644
--- a/arch/arm/kernel/hw_breakpoint.c
+++ b/arch/arm/kernel/hw_breakpoint.c
@@ -929,10 +929,6 @@ static void hw_breakpoint_cfi_handler(struct pt_regs *regs)
break;
}
}
-#else
-static void hw_breakpoint_cfi_handler(struct pt_regs *regs)
-{
-}
#endif
/*
@@ -964,9 +960,14 @@ static int hw_breakpoint_pending(unsigned long addr, unsigned int fsr,
case ARM_ENTRY_SYNC_WATCHPOINT:
watchpoint_handler(addr, fsr, regs);
break;
+#ifdef CONFIG_CFI
case ARM_ENTRY_CFI_BREAKPOINT:
- hw_breakpoint_cfi_handler(regs);
+ if (user_mode(regs))
+ ret = 1; /* Don't handle userspace BKPT */
+ else
+ hw_breakpoint_cfi_handler(regs);
break;
+#endif
default:
ret = 1; /* Unhandled fault. */
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0899/1518] ARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (897 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0898/1518] ARM: 9481/2: breakpoint: CFI breakpoints only on demand Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0900/1518] perf libbfd: Validate BPF prog info arrays before pointer cast Greg Kroah-Hartman
` (99 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lorenzo Stoakes (ARM), Linus Walleij,
Qi Xi, Xie Yuanbin, Russell King, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Xie Yuanbin <xieyuanbin1@huawei.com>
[ Upstream commit 1039bffd6ae9c75b42b7d148d6c1106134107b66 ]
When CONFIG_DEBUG_USER=y, and cmdline "user_debug=31" is set,
a user fault may trigger show_pte() without any lock.
If another thread in the same process concurrently calls munmap(),
the page table pages may be freed while show_pte() is still traversing
them, causing a use-after-free in show_pte().
If CONFIG_ARM_LPAE=y, this may cause a kernel panic if the pages table
of PMD are freed when show_pte() is running.
Acquire mmap_write_lock() around show_pte() for user faults to fix the
contention.
For user faults, additionally restrict that show_pte() is called only
when the addr is a user-space address (addr < TASK_SIZE). This is because
the lock of tsk->mm only protects the virtual memory of user address space,
furthermore, dumping the page tables of a kernel-space address for user
faults is unnecessary and may have security implications.
Keep everything unchanged for kernel faults, because the kernel is
already in the "oops" state, acquiring a lock may risk a deadlock.
Co-developed-by: Qi Xi <xiqi2@huawei.com>
Fixes: 6d021b724481 ("ARM: dump pgd, pmd and pte states on unhandled data abort faults")
Link: https://lore.kernel.org/20260716014022.2823-1-xieyuanbin1@huawei.com
Acked-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
Reviewed-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Qi Xi <xiqi2@huawei.com>
Signed-off-by: Xie Yuanbin <xieyuanbin1@huawei.com>
Signed-off-by: Russell King <rmk+kernel@armlinux.org.uk>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm/mm/fault.c | 16 ++++++++++++++--
1 file changed, 14 insertions(+), 2 deletions(-)
diff --git a/arch/arm/mm/fault.c b/arch/arm/mm/fault.c
index ed4330cc3f4e6..65b652b4dec3d 100644
--- a/arch/arm/mm/fault.c
+++ b/arch/arm/mm/fault.c
@@ -204,7 +204,11 @@ __do_user_fault(unsigned long addr, unsigned int fsr, unsigned int sig,
pr_err("8<--- cut here ---\n");
pr_err("%s: unhandled page fault (%d) at 0x%08lx, code 0x%03x\n",
tsk->comm, sig, addr, fsr);
- show_pte(KERN_ERR, tsk->mm, addr);
+ if (likely(addr < TASK_SIZE)) {
+ mmap_write_lock(tsk->mm);
+ show_pte(KERN_ERR, tsk->mm, addr);
+ mmap_write_unlock(tsk->mm);
+ }
show_regs(regs);
}
#endif
@@ -648,7 +652,15 @@ do_DataAbort(unsigned long addr, unsigned int fsr, struct pt_regs *regs)
pr_alert("8<--- cut here ---\n");
pr_alert("Unhandled fault: %s (0x%03x) at 0x%08lx\n",
inf->name, fsr, addr);
- show_pte(KERN_ALERT, current->mm, addr);
+ if (likely(user_mode(regs))) {
+ if (addr < TASK_SIZE) {
+ mmap_write_lock(current->mm);
+ show_pte(KERN_ALERT, current->mm, addr);
+ mmap_write_unlock(current->mm);
+ }
+ } else {
+ show_pte(KERN_ALERT, current->mm, addr);
+ }
arm_notify_die("", regs, inf->sig, inf->code, (void __user *)addr,
fsr, 0);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0900/1518] perf libbfd: Validate BPF prog info arrays before pointer cast
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (898 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0899/1518] ARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0901/1518] perf bpf: Add PROG_TAGS to required arrays in __bpf_event__print_bpf_prog_info() Greg Kroah-Hartman
` (98 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot, Song Liu, Ian Rogers,
Arnaldo Carvalho de Melo, Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnaldo Carvalho de Melo <acme@redhat.com>
[ Upstream commit 01765b456f850aed7475b37111f1c50bf76aaf51 ]
symbol__disassemble_bpf_libbfd() casts info_linear->info.jited_prog_insns
and info_linear->info.jited_ksyms to pointers without checking whether
bpil_offs_to_addr() actually converted the file offsets. A crafted
perf.data with PERF_BPIL_* bits unset but non-zero counts causes raw
file offsets to be dereferenced as pointers.
Add bitmask checks for PERF_BPIL_JITED_INSNS and PERF_BPIL_JITED_KSYMS
before the casts, matching the validation added to bpf-event.c call
sites.
Fixes: 6987561c9e86 ("perf annotate: Enable annotation of BPF programs")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Song Liu <songliubraving@fb.com>
Reviewed-by: Ian Rogers <irogers@google.com>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/libbfd.c | 11 +++++++++++
1 file changed, 11 insertions(+)
diff --git a/tools/perf/util/libbfd.c b/tools/perf/util/libbfd.c
index 63ea3fb53e77d..cbd4adb8a1c43 100644
--- a/tools/perf/util/libbfd.c
+++ b/tools/perf/util/libbfd.c
@@ -552,6 +552,11 @@ int symbol__disassemble_bpf_libbfd(struct symbol *sym __maybe_unused,
info_linear = info_node->info_linear;
sub_id = dso__bpf_prog(dso)->sub_id;
+ /* jited_prog_insns is only valid if bpil_offs_to_addr() converted it */
+ if (!(info_linear->arrays & (1UL << PERF_BPIL_JITED_INSNS))) {
+ ret = SYMBOL_ANNOTATE_ERRNO__BPF_MISSING_BTF;
+ goto out;
+ }
info.buffer = (void *)(uintptr_t)(info_linear->info.jited_prog_insns);
info.buffer_length = info_linear->info.jited_prog_len;
@@ -581,6 +586,12 @@ int symbol__disassemble_bpf_libbfd(struct symbol *sym __maybe_unused,
if (disassemble == NULL)
abort();
+ /* jited_ksyms is only valid if bpil_offs_to_addr() converted it */
+ if (!(info_linear->arrays & (1UL << PERF_BPIL_JITED_KSYMS))) {
+ ret = SYMBOL_ANNOTATE_ERRNO__BPF_MISSING_BTF;
+ goto out;
+ }
+
fflush(s);
do {
const struct bpf_line_info *linfo = NULL;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0901/1518] perf bpf: Add PROG_TAGS to required arrays in __bpf_event__print_bpf_prog_info()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (899 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0900/1518] perf libbfd: Validate BPF prog info arrays before pointer cast Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0902/1518] perf libbfd: Fix memory leaks and NULL fclose in BPF disassembly Greg Kroah-Hartman
` (97 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot, Song Liu, Ian Rogers,
Arnaldo Carvalho de Melo, Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnaldo Carvalho de Melo <acme@redhat.com>
[ Upstream commit 38ba525335c4399b15c9be0f81de304e94ccb462 ]
synthesize_bpf_prog_name() unconditionally dereferences prog_tags[sub_id]
(line: u8 (*prog_tags)[BPF_TAG_SIZE] = (void *)(uintptr_t)(info->prog_tags))
but __bpf_event__print_bpf_prog_info() only requires JITED_KSYMS and
JITED_FUNC_LENS in its required_arrays bitmask.
If a crafted perf.data has the PROG_TAGS bit cleared (or the array was
invalidated by bpil_offs_to_addr() bounds checking), info->prog_tags
contains either zero or a raw file offset. Dereferencing it causes a
NULL pointer dereference or an arbitrary memory read.
Add PERF_BPIL_PROG_TAGS to required_arrays so the function returns early
when prog_tags was not present or failed validation.
Fixes: f8dfeae009effc0b ("perf bpf: Show more BPF program info in print_bpf_prog_info()")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Song Liu <songliubraving@fb.com>
Reviewed-by: Ian Rogers <irogers@google.com>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/bpf-event.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/tools/perf/util/bpf-event.c b/tools/perf/util/bpf-event.c
index 2294336f6e60b..195516356f62b 100644
--- a/tools/perf/util/bpf-event.c
+++ b/tools/perf/util/bpf-event.c
@@ -969,7 +969,8 @@ void __bpf_event__print_bpf_prog_info(struct perf_bpil *info_linear,
{
struct bpf_prog_info *info = &info_linear->info;
__u64 required_arrays = (1UL << PERF_BPIL_JITED_KSYMS) |
- (1UL << PERF_BPIL_JITED_FUNC_LENS);
+ (1UL << PERF_BPIL_JITED_FUNC_LENS) |
+ (1UL << PERF_BPIL_PROG_TAGS);
__u32 *prog_lens;
__u64 *prog_addrs;
char name[KSYM_NAME_LEN];
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0902/1518] perf libbfd: Fix memory leaks and NULL fclose in BPF disassembly
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (900 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0901/1518] perf bpf: Add PROG_TAGS to required arrays in __bpf_event__print_bpf_prog_info() Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0903/1518] ocfs2: synchronize heartbeat callbacks with o2net teardown Greg Kroah-Hartman
` (96 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot, Song Liu, Ian Rogers,
Arnaldo Carvalho de Melo, Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnaldo Carvalho de Melo <acme@redhat.com>
[ Upstream commit fe3ab00d55aa56b4d55cbc1150448f0aadd6732c ]
symbol__disassemble_bpf_libbfd() has four resource management bugs:
1. free(prog_linfo) leaks internal arrays. bpf_prog_linfo contains
raw_linfo, raw_jited_linfo, nr_jited_linfo_per_func, and
jited_linfo_func_idx pointers that are only freed by the proper
destructor bpf_prog_linfo__free().
2. open_memstream(&buf, &buf_size) allocates a dynamic buffer that the
caller must free after fclose(). The function calls fclose(s) but
never free(buf), leaking the stream buffer on every call.
3. args->line = strdup(srcline) is immediately consumed by
disasm_line__new(args) which internally calls strdup(args->line)
again via annotation_line__init(). The first strdup result is then
overwritten by args->line = buf + prev_buf_size without being freed.
4. If open_memstream() fails, the error path jumps to 'out:' which
calls fclose(s) with s == NULL — undefined behavior.
Fix by using bpf_prog_linfo__free(), initializing buf to NULL, adding
free(buf) after fclose(s), guarding fclose() against NULL, and removing
the redundant strdup since annotation_line__init() makes its own copy.
Fixes: 6987561c9e86eace ("perf annotate: Enable annotation of BPF programs")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Song Liu <songliubraving@fb.com>
Reviewed-by: Ian Rogers <irogers@google.com>
Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/libbfd.c | 12 ++++++++----
1 file changed, 8 insertions(+), 4 deletions(-)
diff --git a/tools/perf/util/libbfd.c b/tools/perf/util/libbfd.c
index cbd4adb8a1c43..6df72889e5075 100644
--- a/tools/perf/util/libbfd.c
+++ b/tools/perf/util/libbfd.c
@@ -15,6 +15,7 @@
#ifdef HAVE_LIBBPF_SUPPORT
#include <bpf/bpf.h>
#include <bpf/btf.h>
+#include <bpf/libbpf.h>
#endif
#include <fcntl.h>
#include <stdio.h>
@@ -510,7 +511,7 @@ int symbol__disassemble_bpf_libbfd(struct symbol *sym __maybe_unused,
char tpath[PATH_MAX];
size_t buf_size;
int nr_skip = 0;
- char *buf;
+ char *buf = NULL;
bfd *bfdf;
int ret;
FILE *s;
@@ -620,7 +621,7 @@ int symbol__disassemble_bpf_libbfd(struct symbol *sym __maybe_unused,
if (!annotate_opts.hide_src_code && srcline) {
args->offset = -1;
- args->line = strdup(srcline);
+ args->line = (char *)srcline;
args->line_nr = 0;
args->fileloc = NULL;
args->ms->sym = sym;
@@ -645,9 +646,12 @@ int symbol__disassemble_bpf_libbfd(struct symbol *sym __maybe_unused,
ret = 0;
out:
- free(prog_linfo);
+ bpf_prog_linfo__free(prog_linfo);
btf__free(btf);
- fclose(s);
+ if (s) {
+ fclose(s);
+ free(buf);
+ }
bfd_close(bfdf);
return ret;
#else
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0903/1518] ocfs2: synchronize heartbeat callbacks with o2net teardown
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (901 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0902/1518] perf libbfd: Fix memory leaks and NULL fclose in BPF disassembly Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0904/1518] clk: rockchip: rk3576: fix source muxes for SPI0..SPI4 Greg Kroah-Hartman
` (95 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Cen Zhang, Joseph Qi, Changwei Ge,
Heming Zhao, Joel Becker, Jun Piao, Junxiao Bi, Mark Fasheh,
Andrew Morton, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Cen Zhang <zzzccc427@gmail.com>
[ Upstream commit 3e326f3bf16506873777444608e8b715aab74a7a ]
Patch series "ocfs2: harden heartbeat teardown races".
This series fixes two OCFS2 heartbeat/o2net teardown races found by
KASAN.
This patch (of 2):
Heartbeat callbacks stay registered while configfs local-node teardown
enters o2net_stop_listening(). A node-down event can still run through
o2net_disconnect_node() and o2net_set_nn_state() while teardown is
destroying o2net_wq, so the later queue/flush operations can hit a dead
workqueue. KASAN has caught this as a slab-use-after-free in
__queue_work() with the call chain:
KASAN slab-use-after-free in __queue_work+0x56/0xa90
Read of size 4
Call trace:
dump_stack_lvl+0x66/0xa0
print_report+0xce/0x630
__queue_work+0x56/0xa90
srso_alias_return_thunk+0x5/0xfbef5
__virt_addr_valid+0x19f/0x330
kasan_report+0xe0/0x110
__queue_delayed_work+0x58/0x1e0
queue_delayed_work_on+0xb4/0xc0
o2net_set_nn_state+0x467/0x840
o2net_disconnect_node+0x7b/0xe0
o2net_hb_node_down_cb+0x54/0x60
o2hb_run_event_list+0x236/0x2d0
o2hb_check_slot+0xad4/0xbc0
lock_release+0xc8/0x290
o2hb_check_slot+0x9ea/0xbc0
trace_hardirqs_on+0x18/0x130
o2hb_do_disk_heartbeat+0x646/0xb30 (fs/ocfs2/cluster/heartbeat.c:1079)
__lock_acquire+0x466/0x2260
lockdep_hardirqs_on_prepare+0xea/0x1a0
ktime_get_with_offset+0xe9/0x230
o2hb_thread+0x14e/0x770
kthread+0x1ad/0x1f0
ret_from_fork+0x3c9/0x540
__switch_to+0x2e9/0x730
ret_from_fork_asm+0x1a/0x30
Allocated by task stack:
kasan_save_stack+0x33/0x60
kasan_save_track+0x14/0x30
__kasan_kmalloc+0xaa/0xb0
__kmalloc_noprof+0x292/0x760
__alloc_workqueue+0x736/0xc60
alloc_workqueue_noprof+0xb1/0x110
o2net_start_listening+0xe5/0x430
o2nm_node_local_store+0x184/0x310
configfs_write_iter+0x18a/0x210
vfs_write+0x469/0x810
ksys_write+0xd2/0x170
do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)
entry_SYSCALL_64_after_hwframe+0x77/0x7f
Freed by task stack:
kasan_save_stack+0x33/0x60
kasan_save_track+0x14/0x30
kasan_save_free_info+0x3b/0x60
__kasan_slab_free+0x5f/0x80
kfree+0x313/0x590
rcu_core+0x4f4/0x1320
handle_softirqs+0x156/0x660
queue_delayed_work_on
o2net_set_nn_state
o2net_disconnect_node
o2net_hb_node_down_cb
o2hb_run_event_list
Keep heartbeat callbacks registered so quorum state still tracks node
state, but stop them from driving o2net reconnect/disconnect work once
local teardown starts. Mark the transport offline before destroying
o2net_wq, wait for any in-flight heartbeat callback to finish, and delay
bring-up replay until the new local node is published through
o2nm_this_node().
The replay also has to stay serialized with heartbeat callback delivery.
Otherwise a live-node snapshot can be copied, a real hb_down callback
can install -ENOTCONN for a peer, and the stale replay can call
o2net_hb_node_up() for that same peer and queue reconnect work even
though heartbeat is already down.
The buggy scenario involves two paths, with each column showing the order
within that path:
local-node teardown: heartbeat node-down callback:
1. configfs local-off enters 1. o2hb_run_event_list() invokes
o2net_stop_listening(). o2net_hb_node_down_cb().
2. teardown heads for 2. the callback reaches
destroy_workqueue(o2net_wq). o2net_disconnect_node() and
o2net_set_nn_state().
3. teardown destroys and NULLs 3. the callback flushes or queues
o2net_wq. work through o2net_wq.
Link: https://lore.kernel.org/20260624095310.763763-1-zzzccc427@gmail.com
Link: https://lore.kernel.org/20260624095310.763763-2-zzzccc427@gmail.com
Fixes: 98211489d414 ("[PATCH] OCFS2: The Second Oracle Cluster Filesystem")
Signed-off-by: Cen Zhang <zzzccc427@gmail.com>
Assisted-by: Codex:gpt-5.5
Reviewed-by: Joseph Qi <joseph.qi@linux.alibaba.com>
Cc: Changwei Ge <gechangwei@live.cn>
Cc: Heming Zhao <heming.zhao@suse.com>
Cc: Joel Becker <jlbec@evilplan.org>
Cc: Jun Piao <piaojun@huawei.com>
Cc: Junxiao Bi <junxiao.bi@oracle.com>
Cc: Mark Fasheh <mark@fasheh.com>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ocfs2/cluster/heartbeat.c | 43 ++++++++++++++----
fs/ocfs2/cluster/heartbeat.h | 5 ++
fs/ocfs2/cluster/nodemanager.c | 4 ++
fs/ocfs2/cluster/tcp.c | 83 +++++++++++++++++++++++++++-------
fs/ocfs2/cluster/tcp.h | 1 +
5 files changed, 109 insertions(+), 27 deletions(-)
diff --git a/fs/ocfs2/cluster/heartbeat.c b/fs/ocfs2/cluster/heartbeat.c
index 9eeab95fe89b4..38bf8fadb346e 100644
--- a/fs/ocfs2/cluster/heartbeat.c
+++ b/fs/ocfs2/cluster/heartbeat.c
@@ -1477,13 +1477,38 @@ void o2hb_init(void)
o2hb_debug_init();
}
-/* if we're already in a callback then we're already serialized by the sem */
-static void o2hb_fill_node_map_from_callback(unsigned long *map,
- unsigned int bits)
+static void __o2hb_fill_node_map(unsigned long *map, unsigned int bits)
{
bitmap_copy(map, o2hb_live_node_bitmap, bits);
}
+void o2hb_callback_read_lock(void)
+{
+ down_read(&o2hb_callback_sem);
+}
+
+void o2hb_callback_read_unlock(void)
+{
+ up_read(&o2hb_callback_sem);
+}
+
+void o2hb_synchronize_callbacks(void)
+{
+ down_write(&o2hb_callback_sem);
+ up_write(&o2hb_callback_sem);
+}
+
+/*
+ * Callers must already hold o2hb_callback_sem for read or write so the copy
+ * stays serialized with callback delivery.
+ */
+void o2hb_fill_node_map_locked(unsigned long *map, unsigned int bits)
+{
+ spin_lock(&o2hb_live_lock);
+ __o2hb_fill_node_map(map, bits);
+ spin_unlock(&o2hb_live_lock);
+}
+
/*
* get a map of all nodes that are heartbeating in any regions
*/
@@ -1491,11 +1516,9 @@ void o2hb_fill_node_map(unsigned long *map, unsigned int bits)
{
/* callers want to serialize this map and callbacks so that they
* can trust that they don't miss nodes coming to the party */
- down_read(&o2hb_callback_sem);
- spin_lock(&o2hb_live_lock);
- o2hb_fill_node_map_from_callback(map, bits);
- spin_unlock(&o2hb_live_lock);
- up_read(&o2hb_callback_sem);
+ o2hb_callback_read_lock();
+ o2hb_fill_node_map_locked(map, bits);
+ o2hb_callback_read_unlock();
}
EXPORT_SYMBOL_GPL(o2hb_fill_node_map);
@@ -2567,7 +2590,7 @@ int o2hb_check_node_heartbeating_no_sem(u8 node_num)
unsigned long testing_map[BITS_TO_LONGS(O2NM_MAX_NODES)];
spin_lock(&o2hb_live_lock);
- o2hb_fill_node_map_from_callback(testing_map, O2NM_MAX_NODES);
+ __o2hb_fill_node_map(testing_map, O2NM_MAX_NODES);
spin_unlock(&o2hb_live_lock);
if (!test_bit(node_num, testing_map)) {
mlog(ML_HEARTBEAT,
@@ -2584,7 +2607,7 @@ int o2hb_check_node_heartbeating_from_callback(u8 node_num)
{
unsigned long testing_map[BITS_TO_LONGS(O2NM_MAX_NODES)];
- o2hb_fill_node_map_from_callback(testing_map, O2NM_MAX_NODES);
+ o2hb_fill_node_map_locked(testing_map, O2NM_MAX_NODES);
if (!test_bit(node_num, testing_map)) {
mlog(ML_HEARTBEAT,
"node (%u) does not have heartbeating enabled.\n",
diff --git a/fs/ocfs2/cluster/heartbeat.h b/fs/ocfs2/cluster/heartbeat.h
index 8ef8c1b9eeb76..2ca2b657583c0 100644
--- a/fs/ocfs2/cluster/heartbeat.h
+++ b/fs/ocfs2/cluster/heartbeat.h
@@ -58,6 +58,11 @@ int o2hb_register_callback(const char *region_uuid,
struct o2hb_callback_func *hc);
void o2hb_unregister_callback(const char *region_uuid,
struct o2hb_callback_func *hc);
+void o2hb_callback_read_lock(void);
+void o2hb_callback_read_unlock(void);
+void o2hb_synchronize_callbacks(void);
+void o2hb_fill_node_map_locked(unsigned long *map,
+ unsigned int bits);
void o2hb_fill_node_map(unsigned long *map,
unsigned int bits);
void o2hb_exit(void);
diff --git a/fs/ocfs2/cluster/nodemanager.c b/fs/ocfs2/cluster/nodemanager.c
index 46e0c9ba8a4ff..b65fc6eeae6e0 100644
--- a/fs/ocfs2/cluster/nodemanager.c
+++ b/fs/ocfs2/cluster/nodemanager.c
@@ -325,6 +325,7 @@ static ssize_t o2nm_node_local_store(struct config_item *item, const char *page,
struct o2nm_node *node = to_o2nm_node(item);
struct o2nm_cluster *cluster;
unsigned long tmp;
+ bool starting = false;
char *p = (char *)page;
ssize_t ret;
@@ -361,6 +362,7 @@ static ssize_t o2nm_node_local_store(struct config_item *item, const char *page,
ret = o2net_start_listening(node);
if (ret)
goto out;
+ starting = true;
}
if (!tmp && cluster->cl_has_local &&
@@ -374,6 +376,8 @@ static ssize_t o2nm_node_local_store(struct config_item *item, const char *page,
if (node->nd_local) {
cluster->cl_has_local = tmp;
cluster->cl_local_node = node->nd_num;
+ if (starting)
+ o2net_complete_start_listening(node);
}
ret = count;
diff --git a/fs/ocfs2/cluster/tcp.c b/fs/ocfs2/cluster/tcp.c
index b05d4e9d13b28..822553530e746 100644
--- a/fs/ocfs2/cluster/tcp.c
+++ b/fs/ocfs2/cluster/tcp.c
@@ -105,6 +105,8 @@ static struct socket *o2net_listen_sock;
* destroying the work queue.
*/
static struct workqueue_struct *o2net_wq;
+/* Heartbeat callbacks stay registered across local-node off/on. */
+static bool o2net_listening;
static struct work_struct o2net_listen_work;
static struct o2hb_callback_func o2net_hb_up, o2net_hb_down;
@@ -1692,6 +1694,19 @@ static void o2net_still_up(struct work_struct *work)
/* ------------------------------------------------------------ */
+static void o2net_hb_node_up(struct o2net_node *nn)
+{
+ /* ensure an immediate connect attempt */
+ nn->nn_last_connect_attempt = jiffies -
+ (msecs_to_jiffies(o2net_reconnect_delay()) + 1);
+
+ spin_lock(&nn->nn_lock);
+ atomic_set(&nn->nn_timeout, 0);
+ if (nn->nn_persistent_error)
+ o2net_set_nn_state(nn, NULL, 0, 0);
+ spin_unlock(&nn->nn_lock);
+}
+
void o2net_disconnect_node(struct o2nm_node *node)
{
struct o2net_node *nn = o2net_nn_from_num(node->nd_num);
@@ -1713,41 +1728,39 @@ void o2net_disconnect_node(struct o2nm_node *node)
static void o2net_hb_node_down_cb(struct o2nm_node *node, int node_num,
void *data)
{
+ u8 this_node;
+
o2quo_hb_down(node_num);
if (!node)
- return;
+ goto out;
- if (node_num != o2nm_this_node())
+ this_node = o2nm_this_node();
+ if (!READ_ONCE(o2net_listening) || this_node == O2NM_MAX_NODES)
+ goto out;
+
+ if (node_num != this_node)
o2net_disconnect_node(node);
+out:
BUG_ON(atomic_read(&o2net_connected_peers) < 0);
}
static void o2net_hb_node_up_cb(struct o2nm_node *node, int node_num,
void *data)
{
- struct o2net_node *nn = o2net_nn_from_num(node_num);
+ u8 this_node;
o2quo_hb_up(node_num);
BUG_ON(!node);
- /* ensure an immediate connect attempt */
- nn->nn_last_connect_attempt = jiffies -
- (msecs_to_jiffies(o2net_reconnect_delay()) + 1);
+ this_node = o2nm_this_node();
+ if (!READ_ONCE(o2net_listening) || this_node == O2NM_MAX_NODES)
+ return;
- if (node_num != o2nm_this_node()) {
- /* believe it or not, accept and node heartbeating testing
- * can succeed for this node before we got here.. so
- * only use set_nn_state to clear the persistent error
- * if that hasn't already happened */
- spin_lock(&nn->nn_lock);
- atomic_set(&nn->nn_timeout, 0);
- if (nn->nn_persistent_error)
- o2net_set_nn_state(nn, NULL, 0, 0);
- spin_unlock(&nn->nn_lock);
- }
+ if (node_num != this_node)
+ o2net_hb_node_up(o2net_nn_from_num(node_num));
}
void o2net_unregister_hb_callbacks(void)
@@ -1756,6 +1769,37 @@ void o2net_unregister_hb_callbacks(void)
o2hb_unregister_callback(NULL, &o2net_hb_down);
}
+/*
+ * Delay heartbeat-driven network work until the local node is fully published
+ * through o2nm_this_node(), then replay the nodes that are already live while
+ * callback delivery stays blocked.
+ */
+void o2net_complete_start_listening(struct o2nm_node *node)
+{
+ unsigned long live_nodes[BITS_TO_LONGS(O2NM_MAX_NODES)];
+ unsigned long node_num;
+ u8 local_node;
+
+ local_node = o2nm_this_node();
+ if (WARN_ON_ONCE(local_node == O2NM_MAX_NODES))
+ return;
+ if (WARN_ON_ONCE(local_node != node->nd_num))
+ return;
+ if (WARN_ON_ONCE(!o2net_wq))
+ return;
+
+ o2hb_callback_read_lock();
+ WRITE_ONCE(o2net_listening, true);
+ o2hb_fill_node_map_locked(live_nodes, O2NM_MAX_NODES);
+ for_each_set_bit(node_num, live_nodes, O2NM_MAX_NODES) {
+ if (node_num == local_node)
+ continue;
+
+ o2net_hb_node_up(o2net_nn_from_num(node_num));
+ }
+ o2hb_callback_read_unlock();
+}
+
int o2net_register_hb_callbacks(void)
{
int ret;
@@ -2034,6 +2078,8 @@ int o2net_start_listening(struct o2nm_node *node)
{
int ret = 0;
+ if (WARN_ON_ONCE(READ_ONCE(o2net_listening)))
+ return -EBUSY;
BUG_ON(o2net_wq != NULL);
BUG_ON(o2net_listen_sock != NULL);
@@ -2065,6 +2111,9 @@ void o2net_stop_listening(struct o2nm_node *node)
BUG_ON(o2net_wq == NULL);
BUG_ON(o2net_listen_sock == NULL);
+ WRITE_ONCE(o2net_listening, false);
+ o2hb_synchronize_callbacks();
+
/* stop the listening socket from generating work */
write_lock_bh(&sock->sk->sk_callback_lock);
sock->sk->sk_data_ready = sock->sk->sk_user_data;
diff --git a/fs/ocfs2/cluster/tcp.h b/fs/ocfs2/cluster/tcp.h
index a75b551d31c7b..2e86d42b5faf9 100644
--- a/fs/ocfs2/cluster/tcp.h
+++ b/fs/ocfs2/cluster/tcp.h
@@ -96,6 +96,7 @@ struct o2nm_node;
int o2net_register_hb_callbacks(void);
void o2net_unregister_hb_callbacks(void);
int o2net_start_listening(struct o2nm_node *node);
+void o2net_complete_start_listening(struct o2nm_node *node);
void o2net_stop_listening(struct o2nm_node *node);
void o2net_disconnect_node(struct o2nm_node *node);
int o2net_num_connected_peers(void);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0904/1518] clk: rockchip: rk3576: fix source muxes for SPI0..SPI4
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (902 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0903/1518] ocfs2: synchronize heartbeat callbacks with o2net teardown Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0905/1518] perf c2c: Add annotation support to perf c2c report Greg Kroah-Hartman
` (94 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Alexey Charkov, Heiko Stuebner,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Alexey Charkov <alchark@flipper.net>
[ Upstream commit 586ff159ec02533c17dd928641529cb0b52e9c62 ]
The TRM defines available source muxes for SPI0..SPI4 as
- b00: clk_gpll_div6_src
- b01: clk_gpll_div8_src
- b10: clk_cpll_div10_src
- b11: clk_xin_osc0_func
Which doesn't match what the current clock driver implements, making it
impossible to derive some SPI clock rates such as 37.125 MHz (which
requires clk_gpll_div8_src as the source mux).
Add a correct mux definition per TRM and point SPI0..SPI4 clocks at it.
Fixes: cc40f5baa91b ("clk: rockchip: Add clock controller for the RK3576")
Signed-off-by: Alexey Charkov <alchark@flipper.net>
Link: https://patch.msgid.link/20260805-rk3576-spi-clk-v1-1-2f040d0d163b@flipper.net
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/clk/rockchip/clk-rk3576.c | 11 ++++++-----
1 file changed, 6 insertions(+), 5 deletions(-)
diff --git a/drivers/clk/rockchip/clk-rk3576.c b/drivers/clk/rockchip/clk-rk3576.c
index 9bc0ef51ef682..95693e4381430 100644
--- a/drivers/clk/rockchip/clk-rk3576.c
+++ b/drivers/clk/rockchip/clk-rk3576.c
@@ -315,6 +315,7 @@ PNAME(mux_100m_24m_lclk0_p) = { "clk_cpll_div10", "xin24m", "lclk_asrc_src_0" }
PNAME(mux_100m_24m_lclk1_p) = { "clk_cpll_div10", "xin24m", "lclk_asrc_src_1" };
PNAME(mux_150m_100m_50m_24m_p) = { "clk_gpll_div8", "clk_cpll_div10", "clk_cpll_div20", "xin24m" };
PNAME(mux_200m_100m_50m_24m_p) = { "clk_gpll_div6", "clk_cpll_div10", "clk_cpll_div20", "xin24m" };
+PNAME(mux_200m_150m_100m_24m_p) = { "clk_gpll_div6", "clk_gpll_div8", "clk_cpll_div10", "xin24m" };
PNAME(mux_400m_200m_100m_24m_p) = { "clk_gpll_div3", "clk_gpll_div6", "clk_cpll_div10", "xin24m" };
PNAME(mux_500m_250m_100m_24m_p) = { "clk_cpll_div2", "clk_cpll_div4", "clk_cpll_div10", "xin24m" };
PNAME(mux_600m_400m_300m_24m_p) = { "clk_gpll_div2", "clk_gpll_div3", "clk_gpll_div4", "xin24m" };
@@ -706,19 +707,19 @@ static struct rockchip_clk_branch rk3576_clk_branches[] __initdata = {
RK3576_CLKGATE_CON(16), 0, GFLAGS),
GATE(PCLK_SPI4, "pclk_spi4", "pclk_bus_root", 0,
RK3576_CLKGATE_CON(16), 1, GFLAGS),
- COMPOSITE_NODIV(CLK_SPI0, "clk_spi0", mux_200m_100m_50m_24m_p, 0,
+ COMPOSITE_NODIV(CLK_SPI0, "clk_spi0", mux_200m_150m_100m_24m_p, 0,
RK3576_CLKSEL_CON(70), 13, 2, MFLAGS,
RK3576_CLKGATE_CON(16), 2, GFLAGS),
- COMPOSITE_NODIV(CLK_SPI1, "clk_spi1", mux_200m_100m_50m_24m_p, 0,
+ COMPOSITE_NODIV(CLK_SPI1, "clk_spi1", mux_200m_150m_100m_24m_p, 0,
RK3576_CLKSEL_CON(71), 0, 2, MFLAGS,
RK3576_CLKGATE_CON(16), 3, GFLAGS),
- COMPOSITE_NODIV(CLK_SPI2, "clk_spi2", mux_200m_100m_50m_24m_p, 0,
+ COMPOSITE_NODIV(CLK_SPI2, "clk_spi2", mux_200m_150m_100m_24m_p, 0,
RK3576_CLKSEL_CON(71), 2, 2, MFLAGS,
RK3576_CLKGATE_CON(16), 4, GFLAGS),
- COMPOSITE_NODIV(CLK_SPI3, "clk_spi3", mux_200m_100m_50m_24m_p, 0,
+ COMPOSITE_NODIV(CLK_SPI3, "clk_spi3", mux_200m_150m_100m_24m_p, 0,
RK3576_CLKSEL_CON(71), 4, 2, MFLAGS,
RK3576_CLKGATE_CON(16), 5, GFLAGS),
- COMPOSITE_NODIV(CLK_SPI4, "clk_spi4", mux_200m_100m_50m_24m_p, 0,
+ COMPOSITE_NODIV(CLK_SPI4, "clk_spi4", mux_200m_150m_100m_24m_p, 0,
RK3576_CLKSEL_CON(71), 6, 2, MFLAGS,
RK3576_CLKGATE_CON(16), 6, GFLAGS),
GATE(PCLK_WDT0, "pclk_wdt0", "pclk_bus_root", 0,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0905/1518] perf c2c: Add annotation support to perf c2c report
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (903 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0904/1518] clk: rockchip: rk3576: fix source muxes for SPI0..SPI4 Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0906/1518] perf report: Fix histogram entry collapsing for -F option Greg Kroah-Hartman
` (93 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tianyou Li, Dapeng Mi, Thomas Falcon,
Jiebin Sun, Pan Deng, Zhiguo Zhou, Wangyang Guo, Ravi Bangoria,
Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tianyou Li <tianyou.li@intel.com>
[ Upstream commit cd3466cd2639783da563253f1f9e3fb2ba936317 ]
Perf c2c report currently specified the code address and source:line
information in the cacheline browser, while it is lack of annotation
support like perf report to directly show the disassembly code for
the particular symbol shared that same cacheline. This patches add
a key 'a' binding to the cacheline browser which reuse the annotation
browser to show the disassembly view for easier analysis of cacheline
contentions.
Signed-off-by: Tianyou Li <tianyou.li@intel.com>
Reviewed-by: Dapeng Mi <dapeng1.mi@linux.intel.com>
Reviewed-by: Thomas Falcon <thomas.falcon@intel.com>
Reviewed-by: Jiebin Sun <jiebin.sun@intel.com>
Reviewed-by: Pan Deng <pan.deng@intel.com>
Reviewed-by: Zhiguo Zhou <zhiguo.zhou@intel.com>
Reviewed-by: Wangyang Guo <wangyang.guo@intel.com>
Tested-by: Ravi Bangoria <ravi.bangoria@amd.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Stable-dep-of: f53f5c2437c1 ("perf c2c: Fix error masking, OOM, and unchecked caller errors in hpp_list__parse()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/Documentation/perf-c2c.txt | 7 ++
tools/perf/builtin-c2c.c | 155 +++++++++++++++++++++++++-
2 files changed, 157 insertions(+), 5 deletions(-)
diff --git a/tools/perf/Documentation/perf-c2c.txt b/tools/perf/Documentation/perf-c2c.txt
index f4af2dd6ab318..40b0f71a2c44e 100644
--- a/tools/perf/Documentation/perf-c2c.txt
+++ b/tools/perf/Documentation/perf-c2c.txt
@@ -143,6 +143,13 @@ REPORT OPTIONS
feature, which causes cacheline sharing to behave like the cacheline
size is doubled.
+-M::
+--disassembler-style=::
+ Set disassembler style for objdump.
+
+--objdump=<path>::
+ Path to objdump binary.
+
C2C RECORD
----------
The perf c2c record command setup options related to HITM cacheline analysis
diff --git a/tools/perf/builtin-c2c.c b/tools/perf/builtin-c2c.c
index 0849092ef5fc1..0851f1e184b11 100644
--- a/tools/perf/builtin-c2c.c
+++ b/tools/perf/builtin-c2c.c
@@ -45,6 +45,8 @@
#include "pmus.h"
#include "string2.h"
#include "util/util.h"
+#include "util/symbol.h"
+#include "util/annotate.h"
struct c2c_hists {
struct hists hists;
@@ -62,6 +64,7 @@ struct compute_stats {
struct c2c_hist_entry {
struct c2c_hists *hists;
+ struct evsel *evsel;
struct c2c_stats stats;
unsigned long *cpuset;
unsigned long *nodeset;
@@ -226,6 +229,12 @@ he__get_c2c_hists(struct hist_entry *he,
return hists;
}
+static void c2c_he__set_evsel(struct c2c_hist_entry *c2c_he,
+ struct evsel *evsel)
+{
+ c2c_he->evsel = evsel;
+}
+
static void c2c_he__set_cpu(struct c2c_hist_entry *c2c_he,
struct perf_sample *sample)
{
@@ -284,6 +293,33 @@ static void compute_stats(struct c2c_hist_entry *c2c_he,
update_stats(&cstats->load, weight);
}
+/*
+ * Return true if annotation is possible. When list is NULL,
+ * it means that we are called at the c2c_browser level,
+ * in that case we allow annotation to be initialized. When list
+ * is non-NULL, it means that we are called at the cacheline_browser
+ * level, in that case we allow annotation only if use_browser
+ * is set and symbol information is available.
+ */
+static bool perf_c2c__has_annotation(struct perf_hpp_list *list)
+{
+ if (use_browser != 1)
+ return false;
+ return !list || list->sym;
+}
+
+static void perf_c2c__evsel_hists_inc_stats(struct evsel *evsel,
+ struct hist_entry *he,
+ struct perf_sample *sample)
+{
+ struct hists *evsel_hists = evsel__hists(evsel);
+
+ hists__inc_nr_samples(evsel_hists, he->filtered);
+ evsel_hists->stats.total_period += sample->period;
+ if (!he->filtered)
+ evsel_hists->stats.total_non_filtered_period += sample->period;
+}
+
static int process_sample_event(const struct perf_tool *tool __maybe_unused,
union perf_event *event,
struct perf_sample *sample,
@@ -343,8 +379,15 @@ static int process_sample_event(const struct perf_tool *tool __maybe_unused,
c2c_he__set_cpu(c2c_he, sample);
c2c_he__set_node(c2c_he, sample);
+ c2c_he__set_evsel(c2c_he, evsel);
hists__inc_nr_samples(&c2c_hists->hists, he->filtered);
+
+ if (perf_c2c__has_annotation(NULL)) {
+ perf_c2c__evsel_hists_inc_stats(evsel, he, sample);
+ addr_map_symbol__inc_samples(mem_info__iaddr(mi), sample, evsel);
+ }
+
ret = hist_entry__append_callchain(he, sample);
if (!ret) {
@@ -387,6 +430,7 @@ static int process_sample_event(const struct perf_tool *tool __maybe_unused,
c2c_he__set_cpu(c2c_he, sample);
c2c_he__set_node(c2c_he, sample);
+ c2c_he__set_evsel(c2c_he, evsel);
hists__inc_nr_samples(&c2c_hists->hists, he->filtered);
ret = hist_entry__append_callchain(he, sample);
@@ -2013,6 +2057,9 @@ static int c2c_hists__init_sort(struct perf_hpp_list *hpp_list, char *name, stru
if (dim == &dim_dso)
hpp_list->dso = 1;
+ if (dim == &dim_symbol || dim == &dim_iaddr)
+ hpp_list->sym = 1;
+
perf_hpp_list__register_sort_field(hpp_list, &c2c_fmt->fmt);
return 0;
}
@@ -2570,6 +2617,40 @@ static void perf_c2c__hists_fprintf(FILE *out, struct perf_session *session)
}
#ifdef HAVE_SLANG_SUPPORT
+
+static int perf_c2c__toggle_annotation(struct hist_browser *browser)
+{
+ struct hist_entry *he = browser->he_selection;
+ struct symbol *sym = NULL;
+ struct annotated_source *src = NULL;
+ struct c2c_hist_entry *c2c_he = NULL;
+
+ if (!perf_c2c__has_annotation(he->hists->hpp_list)) {
+ ui_browser__help_window(&browser->b, "No annotation support");
+ return 0;
+ }
+
+ if (he == NULL) {
+ ui_browser__help_window(&browser->b, "No entry selected for annotation");
+ return 0;
+ }
+
+ sym = he->ms.sym;
+ if (sym == NULL) {
+ ui_browser__help_window(&browser->b, "Can not annotate, no symbol found");
+ return 0;
+ }
+
+ src = symbol__hists(sym, 0);
+ if (src == NULL) {
+ ui_browser__help_window(&browser->b, "Failed to initialize annotation source");
+ return 0;
+ }
+
+ c2c_he = container_of(he, struct c2c_hist_entry, he);
+ return hist_entry__tui_annotate(he, c2c_he->evsel, NULL);
+}
+
static void c2c_browser__update_nr_entries(struct hist_browser *hb)
{
u64 nr_entries = 0;
@@ -2637,6 +2718,7 @@ static int perf_c2c__browse_cacheline(struct hist_entry *he)
" ENTER Toggle callchains (if present) \n"
" n Toggle Node details info \n"
" s Toggle full length of symbol and source line columns \n"
+ " a Toggle annotation view \n"
" q Return back to cacheline list \n";
if (!he)
@@ -2671,6 +2753,9 @@ static int perf_c2c__browse_cacheline(struct hist_entry *he)
c2c.node_info = (c2c.node_info + 1) % 3;
setup_nodes_header();
break;
+ case 'a':
+ perf_c2c__toggle_annotation(browser);
+ break;
case 'q':
goto out;
case '?':
@@ -3026,6 +3111,7 @@ static int perf_c2c__report(int argc, const char **argv)
const char *display = NULL;
const char *coalesce = NULL;
bool no_source = false;
+ const char *disassembler_style = NULL, *objdump_path = NULL;
const struct option options[] = {
OPT_STRING('k', "vmlinux", &symbol_conf.vmlinux_name,
"file", "vmlinux pathname"),
@@ -3053,6 +3139,10 @@ static int perf_c2c__report(int argc, const char **argv)
OPT_BOOLEAN(0, "stitch-lbr", &c2c.stitch_lbr,
"Enable LBR callgraph stitching approach"),
OPT_BOOLEAN(0, "double-cl", &chk_double_cl, "Detect adjacent cacheline false sharing"),
+ OPT_STRING('M', "disassembler-style", &disassembler_style, "disassembler style",
+ "Specify disassembler style (e.g. -M intel for intel syntax)"),
+ OPT_STRING(0, "objdump", &objdump_path, "path",
+ "objdump binary to use for disassembly and annotations"),
OPT_PARENT(c2c_options),
OPT_END()
};
@@ -3060,6 +3150,12 @@ static int perf_c2c__report(int argc, const char **argv)
const char *output_str, *sort_str = NULL;
struct perf_env *env;
+ annotation_options__init();
+
+ err = hists__init();
+ if (err < 0)
+ goto out;
+
argc = parse_options(argc, argv, options, report_c2c_usage,
PARSE_OPT_STOP_AT_NON_OPTION);
if (argc)
@@ -3072,6 +3168,27 @@ static int perf_c2c__report(int argc, const char **argv)
if (c2c.stats_only)
c2c.use_stdio = true;
+ /**
+ * Annotation related options disassembler_style, objdump_path are set
+ * in the c2c_options, so we can use them here.
+ */
+ if (disassembler_style) {
+ annotate_opts.disassembler_style = strdup(disassembler_style);
+ if (!annotate_opts.disassembler_style) {
+ err = -ENOMEM;
+ pr_err("Failed to allocate memory for annotation options\n");
+ goto out;
+ }
+ }
+ if (objdump_path) {
+ annotate_opts.objdump_path = strdup(objdump_path);
+ if (!annotate_opts.objdump_path) {
+ err = -ENOMEM;
+ pr_err("Failed to allocate memory for annotation options\n");
+ goto out;
+ }
+ }
+
err = symbol__validate_sym_arguments();
if (err)
goto out;
@@ -3146,6 +3263,38 @@ static int perf_c2c__report(int argc, const char **argv)
if (err)
goto out_mem2node;
+ if (c2c.use_stdio)
+ use_browser = 0;
+ else
+ use_browser = 1;
+
+ /*
+ * Only in the TUI browser we are doing integrated annotation,
+ * so don't allocate extra space that won't be used in the stdio
+ * implementation.
+ */
+ if (perf_c2c__has_annotation(NULL)) {
+ int ret = symbol__annotation_init();
+
+ if (ret < 0)
+ goto out_mem2node;
+ /*
+ * For searching by name on the "Browse map details".
+ * providing it only in verbose mode not to bloat too
+ * much struct symbol.
+ */
+ if (verbose > 0) {
+ /*
+ * XXX: Need to provide a less kludgy way to ask for
+ * more space per symbol, the u32 is for the index on
+ * the ui browser.
+ * See symbol__browser_index.
+ */
+ symbol_conf.priv_size += sizeof(u32);
+ }
+ annotation_config__init();
+ }
+
if (symbol__init(env) < 0)
goto out_mem2node;
@@ -3155,11 +3304,6 @@ static int perf_c2c__report(int argc, const char **argv)
goto out_mem2node;
}
- if (c2c.use_stdio)
- use_browser = 0;
- else
- use_browser = 1;
-
setup_browser(false);
err = perf_session__process_events(session);
@@ -3230,6 +3374,7 @@ static int perf_c2c__report(int argc, const char **argv)
out_session:
perf_session__delete(session);
out:
+ annotation_options__exit();
return err;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0906/1518] perf report: Fix histogram entry collapsing for -F option
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (904 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0905/1518] perf c2c: Add annotation support to perf c2c report Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0907/1518] perf report: Update sort key state from " Greg Kroah-Hartman
` (92 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ian Rogers, Namhyung Kim,
Arnaldo Carvalho de Melo, Adrian Hunter, Ingo Molnar, James Clark,
Jiri Olsa, Peter Zijlstra, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namhyung Kim <namhyung@kernel.org>
[ Upstream commit 5d35d829bb0b19ee51be9732e3b5f81abc7ef3bb ]
Users can use -F/--fields option to set output fields and sort keys
together.
But it missed to set perf_hpp_list->need_collapse for sort entries that
have se_collapse callbacks.
So it ends up with having duplicated entries separately.
For example, let's run this command first.
$ perf mem record -t load -U -- perf test -w datasym
This will record samples for memory access (load) to struct 'buf' and a
loop condition ('sig_atomic_t') types.
So the following two commands should have identical output.
$ perf report -s type --stdio --percent-limit=1 -q
87.80% perf buf
12.17% perf sig_atomic_t
But using -F option didn't collapse the entries based on types so the
result looked like below:
$ perf report -F overhead,type --stdio --percent-limit=1 -q
23.31% perf buf
22.84% perf buf
21.26% perf buf
20.39% perf buf
12.17% perf sig_atomic_t
Reviewed-by: Ian Rogers <irogers@google.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Tested-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Cc: Ingo Molnar <mingo@kernel.org>
Cc: James Clark <james.clark@linaro.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Stable-dep-of: f53f5c2437c1 ("perf c2c: Fix error masking, OOM, and unchecked caller errors in hpp_list__parse()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/sort.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/tools/perf/util/sort.c b/tools/perf/util/sort.c
index f3a565b0e2307..3d4b68fd6e445 100644
--- a/tools/perf/util/sort.c
+++ b/tools/perf/util/sort.c
@@ -3585,6 +3585,9 @@ static int __sort_dimension__add_output(struct perf_hpp_list *list,
if (__sort_dimension__add_hpp_output(sd, list, level) < 0)
return -1;
+ if (sd->entry->se_collapse)
+ list->need_collapse = 1;
+
sd->taken = 1;
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0907/1518] perf report: Update sort key state from -F option
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (905 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0906/1518] perf report: Fix histogram entry collapsing for -F option Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0908/1518] perf c2c: Use perf_env e_machine rather than arch Greg Kroah-Hartman
` (91 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ian Rogers, Namhyung Kim,
Arnaldo Carvalho de Melo, Adrian Hunter, Ingo Molnar, James Clark,
Jiri Olsa, Peter Zijlstra, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Namhyung Kim <namhyung@kernel.org>
[ Upstream commit cbd41c6d4c26c161a2b0e70ad411d3885ff13507 ]
Factor out __sort_dimension__update() so that it can be called from -s
and -F option parsing logics. Otherwise the following command cannot go
into the annotation mode.
$ perf report -F overhead,type,sym
Warning: Annotation is only available for symbolic views, include "sym*" in --sort to use it.
Reviewed-by: Ian Rogers <irogers@google.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Tested-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Cc: Adrian Hunter <adrian.hunter@intel.com>
Cc: Ingo Molnar <mingo@kernel.org>
Cc: James Clark <james.clark@linaro.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Cc: Peter Zijlstra <peterz@infradead.org>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Stable-dep-of: f53f5c2437c1 ("perf c2c: Fix error masking, OOM, and unchecked caller errors in hpp_list__parse()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/sort.c | 100 ++++++++++++++++++++++-------------------
1 file changed, 54 insertions(+), 46 deletions(-)
diff --git a/tools/perf/util/sort.c b/tools/perf/util/sort.c
index 3d4b68fd6e445..f963d61ac166f 100644
--- a/tools/perf/util/sort.c
+++ b/tools/perf/util/sort.c
@@ -3538,6 +3538,56 @@ static int add_dynamic_entry(struct evlist *evlist, const char *tok,
return ret;
}
+static int __sort_dimension__update(struct sort_dimension *sd,
+ struct perf_hpp_list *list)
+{
+ if (sd->entry == &sort_parent && parent_pattern) {
+ int ret = regcomp(&parent_regex, parent_pattern, REG_EXTENDED);
+ if (ret) {
+ char err[BUFSIZ];
+
+ regerror(ret, &parent_regex, err, sizeof(err));
+ pr_err("Invalid regex: %s\n%s", parent_pattern, err);
+ return -EINVAL;
+ }
+ list->parent = 1;
+ } else if (sd->entry == &sort_sym) {
+ list->sym = 1;
+ /*
+ * perf diff displays the performance difference amongst
+ * two or more perf.data files. Those files could come
+ * from different binaries. So we should not compare
+ * their ips, but the name of symbol.
+ */
+ if (sort__mode == SORT_MODE__DIFF)
+ sd->entry->se_collapse = sort__sym_sort;
+
+ } else if (sd->entry == &sort_sym_offset) {
+ list->sym = 1;
+ } else if (sd->entry == &sort_dso) {
+ list->dso = 1;
+ } else if (sd->entry == &sort_socket) {
+ list->socket = 1;
+ } else if (sd->entry == &sort_thread) {
+ list->thread = 1;
+ } else if (sd->entry == &sort_comm) {
+ list->comm = 1;
+ } else if (sd->entry == &sort_type_offset) {
+ symbol_conf.annotate_data_member = true;
+ } else if (sd->entry == &sort_sym_from || sd->entry == &sort_sym_to) {
+ list->sym = 1;
+ } else if (sd->entry == &sort_mem_dcacheline && cacheline_size() == 0) {
+ return -EINVAL;
+ } else if (sd->entry == &sort_mem_daddr_sym) {
+ list->sym = 1;
+ }
+
+ if (sd->entry->se_collapse)
+ list->need_collapse = 1;
+
+ return 0;
+}
+
static int __sort_dimension__add(struct sort_dimension *sd,
struct perf_hpp_list *list,
int level)
@@ -3548,8 +3598,8 @@ static int __sort_dimension__add(struct sort_dimension *sd,
if (__sort_dimension__add_hpp_sort(sd, list, level) < 0)
return -1;
- if (sd->entry->se_collapse)
- list->need_collapse = 1;
+ if (__sort_dimension__update(sd, list) < 0)
+ return -1;
sd->taken = 1;
@@ -3585,8 +3635,8 @@ static int __sort_dimension__add_output(struct perf_hpp_list *list,
if (__sort_dimension__add_hpp_output(sd, list, level) < 0)
return -1;
- if (sd->entry->se_collapse)
- list->need_collapse = 1;
+ if (__sort_dimension__update(sd, list) < 0)
+ return -1;
sd->taken = 1;
return 0;
@@ -3651,39 +3701,6 @@ int sort_dimension__add(struct perf_hpp_list *list, const char *tok,
sort_dimension_add_dynamic_header(sd, env);
}
- if (sd->entry == &sort_parent && parent_pattern) {
- int ret = regcomp(&parent_regex, parent_pattern, REG_EXTENDED);
- if (ret) {
- char err[BUFSIZ];
-
- regerror(ret, &parent_regex, err, sizeof(err));
- pr_err("Invalid regex: %s\n%s", parent_pattern, err);
- return -EINVAL;
- }
- list->parent = 1;
- } else if (sd->entry == &sort_sym) {
- list->sym = 1;
- /*
- * perf diff displays the performance difference amongst
- * two or more perf.data files. Those files could come
- * from different binaries. So we should not compare
- * their ips, but the name of symbol.
- */
- if (sort__mode == SORT_MODE__DIFF)
- sd->entry->se_collapse = sort__sym_sort;
-
- } else if (sd->entry == &sort_dso) {
- list->dso = 1;
- } else if (sd->entry == &sort_socket) {
- list->socket = 1;
- } else if (sd->entry == &sort_thread) {
- list->thread = 1;
- } else if (sd->entry == &sort_comm) {
- list->comm = 1;
- } else if (sd->entry == &sort_type_offset) {
- symbol_conf.annotate_data_member = true;
- }
-
return __sort_dimension__add(sd, list, level);
}
@@ -3702,9 +3719,6 @@ int sort_dimension__add(struct perf_hpp_list *list, const char *tok,
strlen(tok)))
return -EINVAL;
- if (sd->entry == &sort_sym_from || sd->entry == &sort_sym_to)
- list->sym = 1;
-
__sort_dimension__add(sd, list, level);
return 0;
}
@@ -3718,12 +3732,6 @@ int sort_dimension__add(struct perf_hpp_list *list, const char *tok,
if (sort__mode != SORT_MODE__MEMORY)
return -EINVAL;
- if (sd->entry == &sort_mem_dcacheline && cacheline_size() == 0)
- return -EINVAL;
-
- if (sd->entry == &sort_mem_daddr_sym)
- list->sym = 1;
-
__sort_dimension__add(sd, list, level);
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0908/1518] perf c2c: Use perf_env e_machine rather than arch
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (906 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0907/1518] perf report: Update sort key state from " Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0909/1518] perf c2c: Fix error masking, OOM, and unchecked caller errors in hpp_list__parse() Greg Kroah-Hartman
` (90 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ian Rogers, Namhyung Kim,
Alexander Gordeev, Heiko Carstens, Honglei Wang, Jan Polensky,
Sumanth Korikkar, Thomas Richter, Vasily Gorbik,
Arnaldo Carvalho de Melo, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ian Rogers <irogers@google.com>
[ Upstream commit 70b3c4f734bbfd5664cd6e4eb007c108bf2b1c43 ]
Use the e_machine rather than arch string matching for AARCH64.
Add include of dwarf-regs.h in case the EM_AARCH64 isn't defined, sort
the headers given this include.
Signed-off-by: Ian Rogers <irogers@google.com>
Acked-by: Namhyung Kim <namhyung@kernel.org>
Cc: Alexander Gordeev <agordeev@linux.ibm.com>
Cc: Heiko Carstens <hca@linux.ibm.com>
Cc: Honglei Wang <jameshongleiwang@126.com>
Cc: Jan Polensky <japo@linux.ibm.com>
Cc: Sumanth Korikkar <sumanthk@linux.ibm.com>
Cc: Thomas Richter <tmricht@linux.ibm.com>
Cc: Vasily Gorbik <gor@linux.ibm.com>
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Stable-dep-of: f53f5c2437c1 ("perf c2c: Fix error masking, OOM, and unchecked caller errors in hpp_list__parse()")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/builtin-c2c.c | 40 ++++++++++++++++++++++------------------
1 file changed, 22 insertions(+), 18 deletions(-)
diff --git a/tools/perf/builtin-c2c.c b/tools/perf/builtin-c2c.c
index 0851f1e184b11..0a0ca054f115c 100644
--- a/tools/perf/builtin-c2c.c
+++ b/tools/perf/builtin-c2c.c
@@ -12,41 +12,45 @@
*/
#include <errno.h>
#include <inttypes.h>
+
+#include <asm/bug.h>
#include <linux/compiler.h>
#include <linux/err.h>
#include <linux/kernel.h>
#include <linux/stringify.h>
#include <linux/zalloc.h>
-#include <asm/bug.h>
#include <sys/param.h>
-#include "debug.h"
-#include "builtin.h"
+
+#include <dwarf-regs.h>
#include <perf/cpumap.h>
#include <subcmd/pager.h>
#include <subcmd/parse-options.h>
-#include "map_symbol.h"
-#include "mem-events.h"
-#include "session.h"
-#include "hist.h"
-#include "sort.h"
-#include "tool.h"
+
+#include "builtin.h"
#include "cacheline.h"
#include "data.h"
+#include "debug.h"
#include "event.h"
#include "evlist.h"
#include "evsel.h"
-#include "ui/browsers/hists.h"
-#include "thread.h"
-#include "mem2node.h"
+#include "hist.h"
+#include "map_symbol.h"
+#include "mem-events.h"
#include "mem-info.h"
-#include "symbol.h"
-#include "ui/ui.h"
-#include "ui/progress.h"
+#include "mem2node.h"
#include "pmus.h"
+#include "session.h"
+#include "sort.h"
#include "string2.h"
-#include "util/util.h"
-#include "util/symbol.h"
+#include "symbol.h"
+#include "thread.h"
+#include "tool.h"
+#include "ui/browsers/hists.h"
+#include "ui/progress.h"
+#include "ui/ui.h"
#include "util/annotate.h"
+#include "util/symbol.h"
+#include "util/util.h"
struct c2c_hists {
struct hists hists;
@@ -3225,7 +3229,7 @@ static int perf_c2c__report(int argc, const char **argv)
* default display type.
*/
if (!display) {
- if (!strcmp(perf_env__arch(env), "arm64"))
+ if (perf_env__e_machine(env, /*e_flags=*/NULL) == EM_AARCH64)
display = "peer";
else
display = "tot";
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0909/1518] perf c2c: Fix error masking, OOM, and unchecked caller errors in hpp_list__parse()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (907 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0908/1518] perf c2c: Use perf_env e_machine rather than arch Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0910/1518] perf c2c: Clean up registered formats on c2c_hists__init() and c2c_hists__reinit() failure Greg Kroah-Hartman
` (89 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot, Jiri Olsa,
Arnaldo Carvalho de Melo, Ian Rogers, Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnaldo Carvalho de Melo <acme@redhat.com>
[ Upstream commit f53f5c2437c1bd76fc0063a30a069a5207de8802 ]
hpp_list__parse() has three bugs:
1. The PARSE_LIST macro resets ret = 0 at the start of each invocation,
so an error from output parsing is silently overwritten when the sort
parsing block runs. The function returns success with partially
initialized state.
2. When the caller passes a non-NULL output_ or sort_ string, but
strdup() returns NULL due to OOM, NULL is passed to PARSE_LIST which
treats it as empty input (the "if (!_list) break" branch). No error
is returned.
3. When the called _fn function fails and returns something other than
-ESRCH or -EINVAL (-ENOMEM, for instance) it was not bailing out of
the strtok loop.
Fix them by checking strdup() return values before proceeding and adding
a cleanup label so that ret from each PARSE_LIST call is checked before
the next runs, preserving the first error.
The early exits now skip perf_hpp__setup_output_field(), which means
c2c_hists__reinit() can return a non-zero value in cases that previously
always succeeded silently. Both callers discarded its return:
resort_cl_cb() continued into hists__collapse_resort() on a broken list,
and perf_c2c__report() proceeded with uninitialised hists. Fix the full
chain: check and propagate the error in resort_cl_cb() -- hists__iterate_cb()
already stops iteration and returns the callback error -- and check both
c2c_hists__reinit() and hists__iterate_cb() in perf_c2c__report().
Also turn PARSE_LIST into a function, using a switch to catch other
errors, converting the called functions to return an appropriate errno
instead of -1 on failure.
Also make the two callers that iterate sort_dimension__add() and
output_field_add() handle the newly propagated errors: setup_sort_list()
and setup_output_list() only checked for -EINVAL and -ESRCH, so an
-ENOMEM from a failed allocation was silently overwritten by the next
loop iteration. Break out of the loop and propagate any other error.
The hpp_list__parse() fixes were developed with AI assistance from
Claude:claude-sonnet-4.6, and the setup_sort_list()/setup_output_list()
caller fixes with AI assistance from Opencode:mimo-v2.5-free and
Opencode:DeepSeek-V4-Flash-free.
Fixes: 2d388bd0c9d3 ("perf c2c report: Add stdio output support")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Assisted-by: Claude:claude-sonnet-4.6
Assisted-by: Opencode:mimo-v2.5-free
Assisted-by: Opencode:DeepSeek-V4-Flash-free
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Reviewed-by: Ian Rogers <irogers@google.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/builtin-c2c.c | 85 ++++++++++++++++++++++++++++------------
tools/perf/util/sort.c | 76 +++++++++++++++++++++++------------
2 files changed, 112 insertions(+), 49 deletions(-)
diff --git a/tools/perf/builtin-c2c.c b/tools/perf/builtin-c2c.c
index 0a0ca054f115c..dd4e6e40538f6 100644
--- a/tools/perf/builtin-c2c.c
+++ b/tools/perf/builtin-c2c.c
@@ -12,11 +12,14 @@
*/
#include <errno.h>
#include <inttypes.h>
+#include <stdlib.h>
+#include <string.h>
#include <asm/bug.h>
#include <linux/compiler.h>
#include <linux/err.h>
#include <linux/kernel.h>
+#include <linux/string.h>
#include <linux/stringify.h>
#include <linux/zalloc.h>
#include <sys/param.h>
@@ -2068,26 +2071,38 @@ static int c2c_hists__init_sort(struct perf_hpp_list *hpp_list, char *name, stru
return 0;
}
-#define PARSE_LIST(_list, _fn) \
- do { \
- char *tmp, *tok; \
- ret = 0; \
- \
- if (!_list) \
- break; \
- \
- for (tok = strtok_r((char *)_list, ", ", &tmp); \
- tok; tok = strtok_r(NULL, ", ", &tmp)) { \
- ret = _fn(hpp_list, tok, env); \
- if (ret == -EINVAL) { \
- pr_err("Invalid --fields key: `%s'", tok); \
- break; \
- } else if (ret == -ESRCH) { \
- pr_err("Unknown --fields key: `%s'", tok); \
- break; \
- } \
- } \
- } while (0)
+static int __hpp_list__parse(struct perf_hpp_list *hpp_list, char *_list, struct perf_env *env,
+ int (*_fn)(struct perf_hpp_list *hpp_list, char *name, struct perf_env *env))
+{
+ char *tmp, *tok;
+ int ret = 0;
+
+ if (!_list)
+ return 0;
+
+ for (tok = strtok_r(_list, ", ", &tmp); tok; tok = strtok_r(NULL, ", ", &tmp)) {
+ ret = _fn(hpp_list, tok, env);
+ switch (ret) {
+ case 0:
+ continue;
+ case -EINVAL:
+ pr_err("Invalid --fields key: `%s'", tok);
+ goto out;
+ case -ESRCH:
+ pr_err("Unknown --fields key: `%s'", tok);
+ goto out;
+ default: {
+ char buf[STRERR_BUFSIZE];
+
+ pr_err("%s for --fields key: `%s'",
+ str_error_r(-ret, buf, sizeof(buf)), tok);
+ goto out;
+ }
+ }
+ }
+out:
+ return ret;
+}
static int hpp_list__parse(struct perf_hpp_list *hpp_list,
const char *output_,
@@ -2098,8 +2113,18 @@ static int hpp_list__parse(struct perf_hpp_list *hpp_list,
char *sort = sort_ ? strdup(sort_) : NULL;
int ret;
- PARSE_LIST(output, c2c_hists__init_output);
- PARSE_LIST(sort, c2c_hists__init_sort);
+ /* strdup() returns NULL on OOM, don't silently treat as empty */
+ if ((output_ && !output) || (sort_ && !sort)) {
+ ret = -ENOMEM;
+ goto out;
+ }
+
+ ret = __hpp_list__parse(hpp_list, output, env, c2c_hists__init_output);
+ if (ret)
+ goto out;
+ ret = __hpp_list__parse(hpp_list, sort, env, c2c_hists__init_sort);
+ if (ret)
+ goto out;
/* copy sort keys to output fields */
perf_hpp__setup_output_field(hpp_list);
@@ -2116,6 +2141,7 @@ static int hpp_list__parse(struct perf_hpp_list *hpp_list,
perf_hpp__append_sort_keys(&hists->list);
#endif
+out:
free(output);
free(sort);
return ret;
@@ -2286,6 +2312,7 @@ static int resort_cl_cb(struct hist_entry *he, void *arg)
struct c2c_hist_entry *c2c_he;
struct c2c_hists *c2c_hists;
bool display = he__display(he, &c2c.shared_clines_stats);
+ int ret;
c2c_he = container_of(he, struct c2c_hist_entry, he);
c2c_hists = c2c_he->hists;
@@ -2296,7 +2323,9 @@ static int resort_cl_cb(struct hist_entry *he, void *arg)
c2c_he->cacheline_idx = idx++;
calc_width(c2c_he);
- c2c_hists__reinit(c2c_hists, c2c.cl_output, c2c.cl_resort, env);
+ ret = c2c_hists__reinit(c2c_hists, c2c.cl_output, c2c.cl_resort, env);
+ if (ret)
+ return ret;
hists__collapse_resort(&c2c_hists->hists, NULL);
hists__output_resort_cb(&c2c_hists->hists, NULL, filter_cb);
@@ -3356,13 +3385,19 @@ static int perf_c2c__report(int argc, const char **argv)
else if (c2c.display == DISPLAY_SNP_PEER)
sort_str = "tot_peer";
- c2c_hists__reinit(&c2c.hists, output_str, sort_str, perf_session__env(session));
+ err = c2c_hists__reinit(&c2c.hists, output_str, sort_str, perf_session__env(session));
+ if (err) {
+ pr_err("Failed to reinitialize hists\n");
+ goto out_mem2node;
+ }
ui_progress__init(&prog, c2c.hists.hists.nr_entries, "Sorting...");
hists__collapse_resort(&c2c.hists.hists, NULL);
hists__output_resort_cb(&c2c.hists.hists, &prog, resort_shared_cl_cb);
- hists__iterate_cb(&c2c.hists.hists, resort_cl_cb, perf_session__env(session));
+ err = hists__iterate_cb(&c2c.hists.hists, resort_cl_cb, perf_session__env(session));
+ if (err)
+ goto out_mem2node;
ui_progress__finish();
diff --git a/tools/perf/util/sort.c b/tools/perf/util/sort.c
index f963d61ac166f..ceabfca862407 100644
--- a/tools/perf/util/sort.c
+++ b/tools/perf/util/sort.c
@@ -2957,7 +2957,7 @@ static int __sort_dimension__add_hpp_sort(struct sort_dimension *sd,
struct hpp_sort_entry *hse = __sort_dimension__alloc_hpp(sd, level);
if (hse == NULL)
- return -1;
+ return -ENOMEM;
perf_hpp_list__register_sort_field(list, &hse->hpp);
return 0;
@@ -2970,7 +2970,7 @@ static int __sort_dimension__add_hpp_output(struct sort_dimension *sd,
struct hpp_sort_entry *hse = __sort_dimension__alloc_hpp(sd, level);
if (hse == NULL)
- return -1;
+ return -ENOMEM;
perf_hpp_list__column_register(list, &hse->hpp);
return 0;
@@ -3592,14 +3592,18 @@ static int __sort_dimension__add(struct sort_dimension *sd,
struct perf_hpp_list *list,
int level)
{
+ int ret;
+
if (sd->taken)
return 0;
- if (__sort_dimension__add_hpp_sort(sd, list, level) < 0)
- return -1;
+ ret = __sort_dimension__add_hpp_sort(sd, list, level);
+ if (ret < 0)
+ return ret;
- if (__sort_dimension__update(sd, list) < 0)
- return -1;
+ ret = __sort_dimension__update(sd, list);
+ if (ret < 0)
+ return ret;
sd->taken = 1;
@@ -3617,7 +3621,7 @@ static int __hpp_dimension__add(struct hpp_dimension *hd,
fmt = __hpp_dimension__alloc_hpp(hd, level);
if (!fmt)
- return -1;
+ return -ENOMEM;
hd->taken = 1;
hd->was_taken = 1;
@@ -3629,14 +3633,18 @@ static int __sort_dimension__add_output(struct perf_hpp_list *list,
struct sort_dimension *sd,
int level)
{
+ int ret;
+
if (sd->taken)
return 0;
- if (__sort_dimension__add_hpp_output(sd, list, level) < 0)
- return -1;
+ ret = __sort_dimension__add_hpp_output(sd, list, level);
+ if (ret < 0)
+ return ret;
- if (__sort_dimension__update(sd, list) < 0)
- return -1;
+ ret = __sort_dimension__update(sd, list);
+ if (ret < 0)
+ return ret;
sd->taken = 1;
return 0;
@@ -3653,7 +3661,7 @@ static int __hpp_dimension__add_output(struct perf_hpp_list *list,
fmt = __hpp_dimension__alloc_hpp(hd, level);
if (!fmt)
- return -1;
+ return -ENOMEM;
hd->taken = 1;
perf_hpp_list__column_register(list, fmt);
@@ -3719,8 +3727,7 @@ int sort_dimension__add(struct perf_hpp_list *list, const char *tok,
strlen(tok)))
return -EINVAL;
- __sort_dimension__add(sd, list, level);
- return 0;
+ return __sort_dimension__add(sd, list, level);
}
for (i = 0; i < ARRAY_SIZE(memory_sort_dimensions); i++) {
@@ -3732,8 +3739,7 @@ int sort_dimension__add(struct perf_hpp_list *list, const char *tok,
if (sort__mode != SORT_MODE__MEMORY)
return -EINVAL;
- __sort_dimension__add(sd, list, level);
- return 0;
+ return __sort_dimension__add(sd, list, level);
}
for (i = 0; i < ARRAY_SIZE(hpp_sort_dimensions); i++) {
@@ -3823,15 +3829,25 @@ static int setup_sort_list(struct perf_hpp_list *list, char *str,
}
ret = sort_dimension__add(list, tok, evlist, env, level);
- if (ret == -EINVAL) {
+ switch (ret) {
+ case 0:
+ break;
+ case -EINVAL:
if (!cacheline_size() && !strncasecmp(tok, "dcacheline", strlen(tok)))
ui__error("The \"dcacheline\" --sort key needs to know the cacheline size and it couldn't be determined on this system");
else
ui__error("Invalid --sort key: `%s'", tok);
- break;
- } else if (ret == -ESRCH) {
+ goto out;
+ case -ESRCH:
ui__error("Unknown --sort key: `%s'", tok);
- break;
+ goto out;
+ default: {
+ char buf[STRERR_BUFSIZE];
+
+ ui__error("%s for --sort key: `%s'",
+ str_error_r(-ret, buf, sizeof(buf)), tok);
+ goto out;
+ }
}
prev_level = level;
}
@@ -3839,6 +3855,7 @@ static int setup_sort_list(struct perf_hpp_list *list, char *str,
level = next_level;
} while (tmp);
+out:
return ret;
}
@@ -4164,15 +4181,26 @@ static int setup_output_list(struct perf_hpp_list *list, char *str)
for (tok = strtok_r(str, ", ", &tmp);
tok; tok = strtok_r(NULL, ", ", &tmp)) {
ret = output_field_add(list, tok, &level);
- if (ret == -EINVAL) {
- ui__error("Invalid --fields key: `%s'", tok);
+ switch (ret) {
+ case 0:
break;
- } else if (ret == -ESRCH) {
+ case -EINVAL:
+ ui__error("Invalid --fields key: `%s'", tok);
+ goto out;
+ case -ESRCH:
ui__error("Unknown --fields key: `%s'", tok);
- break;
+ goto out;
+ default: {
+ char buf[STRERR_BUFSIZE];
+
+ ui__error("%s for --fields key: `%s'",
+ str_error_r(-ret, buf, sizeof(buf)), tok);
+ goto out;
+ }
}
}
+out:
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0910/1518] perf c2c: Clean up registered formats on c2c_hists__init() and c2c_hists__reinit() failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (908 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0909/1518] perf c2c: Fix error masking, OOM, and unchecked caller errors in hpp_list__parse() Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0911/1518] drm/sun4i: vi scaler: Fix coefficient selection Greg Kroah-Hartman
` (88 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, sashiko-bot, Jiri Olsa,
Arnaldo Carvalho de Melo, Ian Rogers, Namhyung Kim, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnaldo Carvalho de Melo <acme@redhat.com>
[ Upstream commit 6d421f609bba7b0b1a11741ec4b19feadfd27051 ]
When c2c_hists__init() or c2c_hists__reinit() calls hpp_list__parse()
and it fails partway through, format structures registered via
perf_hpp_list__column_register() and perf_hpp_list__register_sort_field()
are left on the hpp_list.
In c2c_hists__init(), only one of the callers, c2c_he__alloc_hists(),
handled this with perf_hpp__reset_output_field(), while perf_c2c_report()
did not, leaking the partially registered entries.
In c2c_hists__reinit(), neither perf_c2c_report() nor resort_cl_cb()
clean up on failure.
Fix by adding cleanup inside both functions themselves, so all callers
are protected, and remove the now redundant reset in c2c_he__alloc_hists().
Fixes: 78b275437873 ("perf c2c report: Add sample processing")
Reported-by: sashiko-bot <sashiko-bot@kernel.org>
Cc: Jiri Olsa <jolsa@kernel.org>
Assisted-by: Claude:claude-opus-4.6
Assisted-by: Opencode:mimo-v2.5-free
Assisted-by: Opencode:DeepSeek-V4-Flash-free
Signed-off-by: Arnaldo Carvalho de Melo <acme@redhat.com>
Reviewed-by: Ian Rogers <irogers@google.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/builtin-c2c.c | 20 ++++++++++++++++++--
1 file changed, 18 insertions(+), 2 deletions(-)
diff --git a/tools/perf/builtin-c2c.c b/tools/perf/builtin-c2c.c
index dd4e6e40538f6..f6fcb1d3a2090 100644
--- a/tools/perf/builtin-c2c.c
+++ b/tools/perf/builtin-c2c.c
@@ -2152,6 +2152,8 @@ static int c2c_hists__init(struct c2c_hists *hists,
int nr_header_lines,
struct perf_env *env)
{
+ int ret;
+
__hists__init(&hists->hists, &hists->list);
/*
@@ -2164,7 +2166,13 @@ static int c2c_hists__init(struct c2c_hists *hists,
/* Overload number of header lines.*/
hists->list.nr_header_lines = nr_header_lines;
- return hpp_list__parse(&hists->list, /*output=*/NULL, sort, env);
+ ret = hpp_list__parse(&hists->list, /*output=*/NULL, sort, env);
+
+ /* Unregister any formats added before the failure point */
+ if (ret)
+ perf_hpp__reset_output_field(&hists->list);
+
+ return ret;
}
static int c2c_hists__reinit(struct c2c_hists *c2c_hists,
@@ -2172,8 +2180,16 @@ static int c2c_hists__reinit(struct c2c_hists *c2c_hists,
const char *sort,
struct perf_env *env)
{
+ int ret;
+
perf_hpp__reset_output_field(&c2c_hists->list);
- return hpp_list__parse(&c2c_hists->list, output, sort, env);
+ ret = hpp_list__parse(&c2c_hists->list, output, sort, env);
+
+ /* Unregister any formats added before the failure point */
+ if (ret)
+ perf_hpp__reset_output_field(&c2c_hists->list);
+
+ return ret;
}
#define DISPLAY_LINE_LIMIT 0.001
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0911/1518] drm/sun4i: vi scaler: Fix coefficient selection
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (909 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0910/1518] perf c2c: Clean up registered formats on c2c_hists__init() and c2c_hists__reinit() failure Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0912/1518] drm/sun4i: tcon: Set output mux for DSI and LVDS Greg Kroah-Hartman
` (87 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jernej Skrabec, Chen-Yu Tsai,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jernej Skrabec <jernej.skrabec@gmail.com>
[ Upstream commit 5c31990b21f0b535732deb2b658b78b07464f56c ]
Currently, vertical coefficients are selected based on horizontal
scaling, which is wrong. Additionally, chroma coefficients should be
selected based on format subsampling.
Fix all that.
Fixes: b862a648de3b ("drm/sun4i: Add support for HW scaling to DE2")
Signed-off-by: Jernej Skrabec <jernej.skrabec@gmail.com>
Reviewed-by: Chen-Yu Tsai <wens@kernel.org>
Link: https://patch.msgid.link/263a4a41442a3c8b072b170256b72658f1b90802.1785772659.git.jernej.skrabec@gmail.com
Signed-off-by: Chen-Yu Tsai <wens@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/sun4i/sun8i_vi_scaler.c | 18 ++++++++++++------
1 file changed, 12 insertions(+), 6 deletions(-)
diff --git a/drivers/gpu/drm/sun4i/sun8i_vi_scaler.c b/drivers/gpu/drm/sun4i/sun8i_vi_scaler.c
index 82df6244af885..695491b7739bd 100644
--- a/drivers/gpu/drm/sun4i/sun8i_vi_scaler.c
+++ b/drivers/gpu/drm/sun4i/sun8i_vi_scaler.c
@@ -893,20 +893,26 @@ static void sun8i_vi_scaler_set_coeff(struct regmap *map, u32 base,
lan3coefftab32_left[offset + i]);
regmap_write(map, SUN8I_SCALER_VSU_YHCOEFF1(base, i),
lan3coefftab32_right[offset + i]);
+ }
+ offset = sun8i_vi_scaler_coef_index(vstep) *
+ SUN8I_VI_SCALER_COEFF_COUNT;
+ for (i = 0; i < SUN8I_VI_SCALER_COEFF_COUNT; i++)
+ regmap_write(map, SUN8I_SCALER_VSU_YVCOEFF(base, i),
+ lan2coefftab32[offset + i]);
+
+ offset = sun8i_vi_scaler_coef_index(hstep / format->hsub) *
+ SUN8I_VI_SCALER_COEFF_COUNT;
+ for (i = 0; i < SUN8I_VI_SCALER_COEFF_COUNT; i++) {
regmap_write(map, SUN8I_SCALER_VSU_CHCOEFF0(base, i),
ch_left[offset + i]);
regmap_write(map, SUN8I_SCALER_VSU_CHCOEFF1(base, i),
ch_right[offset + i]);
}
-
- offset = sun8i_vi_scaler_coef_index(hstep) *
+ offset = sun8i_vi_scaler_coef_index(vstep / format->vsub) *
SUN8I_VI_SCALER_COEFF_COUNT;
- for (i = 0; i < SUN8I_VI_SCALER_COEFF_COUNT; i++) {
- regmap_write(map, SUN8I_SCALER_VSU_YVCOEFF(base, i),
- lan2coefftab32[offset + i]);
+ for (i = 0; i < SUN8I_VI_SCALER_COEFF_COUNT; i++)
regmap_write(map, SUN8I_SCALER_VSU_CVCOEFF(base, i),
cy[offset + i]);
- }
}
void sun8i_vi_scaler_enable(struct sun8i_mixer *mixer, int layer, bool enable)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0912/1518] drm/sun4i: tcon: Set output mux for DSI and LVDS
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (910 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0911/1518] drm/sun4i: vi scaler: Fix coefficient selection Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0913/1518] drm/sun4i: tcon: Drop TCON TOP device reference Greg Kroah-Hartman
` (86 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jernej Skrabec, Chen-Yu Tsai,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jernej Skrabec <jernej.skrabec@gmail.com>
[ Upstream commit 9c90199b39637ad94253c4fd8e7b1333ca1d3e0d ]
DSI and LVDS skip output mux setup, so TCON TOP cannot route the selected
mixer. Configure them like other channel 0 outputs.
In practice this matters for D1, where channel 0 TCONs are fed through
TCON TOP. The remaining set_mux implementations only handle TMDS and
return an error for other encoder types, as before.
Fixes: b9b52d2f4aaf ("drm/sun4i: Add support for D1 TCONs")
Signed-off-by: Jernej Skrabec <jernej.skrabec@gmail.com>
Acked-by: Chen-Yu Tsai <wens@kernel.org>
Link: https://patch.msgid.link/7e9dad9eed2e91a79c4e1202caa8fed7c2427531.1785772659.git.jernej.skrabec@gmail.com
Signed-off-by: Chen-Yu Tsai <wens@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/sun4i/sun4i_tcon.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/gpu/drm/sun4i/sun4i_tcon.c b/drivers/gpu/drm/sun4i/sun4i_tcon.c
index 960e83c8291da..ea7c90fef316b 100644
--- a/drivers/gpu/drm/sun4i/sun4i_tcon.c
+++ b/drivers/gpu/drm/sun4i/sun4i_tcon.c
@@ -717,9 +717,11 @@ void sun4i_tcon_mode_set(struct sun4i_tcon *tcon,
case DRM_MODE_ENCODER_DSI:
/* DSI is tied to special case of CPU interface */
sun4i_tcon0_mode_set_cpu(tcon, encoder, mode);
+ sun4i_tcon_set_mux(tcon, 0, encoder);
break;
case DRM_MODE_ENCODER_LVDS:
sun4i_tcon0_mode_set_lvds(tcon, encoder, mode);
+ sun4i_tcon_set_mux(tcon, 0, encoder);
break;
case DRM_MODE_ENCODER_NONE:
sun4i_tcon0_mode_set_rgb(tcon, encoder, mode);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0913/1518] drm/sun4i: tcon: Drop TCON TOP device reference
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (911 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0912/1518] drm/sun4i: tcon: Set output mux for DSI and LVDS Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0914/1518] drm/sun4i: hdmi: Dont leak sync polarity bits into packet control Greg Kroah-Hartman
` (85 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jernej Skrabec, Chen-Yu Tsai,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jernej Skrabec <jernej.skrabec@gmail.com>
[ Upstream commit 8208832a38ff3d2560eb8a77a9d7a2f17d8ebcdc ]
of_find_device_by_node() takes a device reference. Drop it after mux
configuration succeeds.
Fixes: 0305189afb32 ("drm/sun4i: tcon: Add support for R40 TCON")
Signed-off-by: Jernej Skrabec <jernej.skrabec@gmail.com>
Acked-by: Chen-Yu Tsai <wens@kernel.org>
Link: https://patch.msgid.link/871a3108086c15a483eef23301984c8d2254dfa7.1785772659.git.jernej.skrabec@gmail.com
Signed-off-by: Chen-Yu Tsai <wens@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/sun4i/sun4i_tcon.c | 19 +++++++++----------
1 file changed, 9 insertions(+), 10 deletions(-)
diff --git a/drivers/gpu/drm/sun4i/sun4i_tcon.c b/drivers/gpu/drm/sun4i/sun4i_tcon.c
index ea7c90fef316b..de2d66623f7a2 100644
--- a/drivers/gpu/drm/sun4i/sun4i_tcon.c
+++ b/drivers/gpu/drm/sun4i/sun4i_tcon.c
@@ -1409,7 +1409,7 @@ static int sun8i_r40_tcon_tv_set_mux(struct sun4i_tcon *tcon,
{
struct device_node *port, *remote;
struct platform_device *pdev;
- int id, ret;
+ int id, ret = 0;
/* find TCON TOP platform device and TCON id */
@@ -1432,21 +1432,20 @@ static int sun8i_r40_tcon_tv_set_mux(struct sun4i_tcon *tcon,
if (IS_ENABLED(CONFIG_DRM_SUN8I_TCON_TOP) &&
encoder->encoder_type == DRM_MODE_ENCODER_TMDS) {
ret = sun8i_tcon_top_set_hdmi_src(&pdev->dev, id);
- if (ret) {
- put_device(&pdev->dev);
- return ret;
- }
+ if (ret)
+ goto out_put_device;
}
if (IS_ENABLED(CONFIG_DRM_SUN8I_TCON_TOP)) {
ret = sun8i_tcon_top_de_config(&pdev->dev, tcon->id, id);
- if (ret) {
- put_device(&pdev->dev);
- return ret;
- }
+ if (ret)
+ goto out_put_device;
}
- return 0;
+out_put_device:
+ put_device(&pdev->dev);
+
+ return ret;
}
static const struct sun4i_tcon_quirks sun4i_a10_quirks = {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0914/1518] drm/sun4i: hdmi: Dont leak sync polarity bits into packet control
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (912 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0913/1518] drm/sun4i: tcon: Drop TCON TOP device reference Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0915/1518] drm/sun4i: crtc: Propagate layer initialization error Greg Kroah-Hartman
` (84 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jernej Skrabec, Chen-Yu Tsai,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jernej Skrabec <jernej.skrabec@gmail.com>
[ Upstream commit f5c3b1b0d228624786d22973a20c908c84e1a576 ]
sun4i_hdmi_enable() keeps using the same variable after it programmed
the video timing polarity register with it. The leftover TX_CLK, HSYNC
and VSYNC bits are then ORed into the packet control register, where
each nibble selects the packet type sent in one slot.
As a result, slot 0 selects packet type 3 instead of the AVI infoframe
whenever the mode has positive HSYNC polarity, and the TX_CLK bits set
nibbles which the driver never programs.
Assign the packet types instead of ORing them into the stale value.
Fixes: 9ca6bc246035 ("drm/sun4i: hdmi: Move mode_set into enable")
Signed-off-by: Jernej Skrabec <jernej.skrabec@gmail.com>
Acked-by: Chen-Yu Tsai <wens@kernel.org>
Link: https://patch.msgid.link/51ba0918ce016a4b45313d5df1b6ce31b8c8731e.1785772659.git.jernej.skrabec@gmail.com
Signed-off-by: Chen-Yu Tsai <wens@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/sun4i/sun4i_hdmi_enc.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/sun4i/sun4i_hdmi_enc.c b/drivers/gpu/drm/sun4i/sun4i_hdmi_enc.c
index ab0938ba61f7d..c7b539b3497f6 100644
--- a/drivers/gpu/drm/sun4i/sun4i_hdmi_enc.c
+++ b/drivers/gpu/drm/sun4i/sun4i_hdmi_enc.c
@@ -146,7 +146,7 @@ static void sun4i_hdmi_enable(struct drm_encoder *encoder,
drm_atomic_helper_connector_hdmi_update_infoframes(connector, state);
- val |= SUN4I_HDMI_PKT_CTRL_TYPE(0, SUN4I_HDMI_PKT_AVI);
+ val = SUN4I_HDMI_PKT_CTRL_TYPE(0, SUN4I_HDMI_PKT_AVI);
val |= SUN4I_HDMI_PKT_CTRL_TYPE(1, SUN4I_HDMI_PKT_END);
writel(val, hdmi->base + SUN4I_HDMI_PKT_CTRL_REG(0));
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0915/1518] drm/sun4i: crtc: Propagate layer initialization error
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (913 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0914/1518] drm/sun4i: hdmi: Dont leak sync polarity bits into packet control Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0916/1518] drm/sun4i: tcon: Drop remote endpoint reference Greg Kroah-Hartman
` (83 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jernej Skrabec, Chen-Yu Tsai,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jernej Skrabec <jernej.skrabec@gmail.com>
[ Upstream commit 7061ff05ed4a3cf16e83f7e3ad09cbd212508a32 ]
sun4i_crtc_init() returns plain NULL when layer initialization fails,
while all its other error paths return an error pointer. The only
caller, sun4i_tcon_bind(), checks the result with IS_ERR() and happily
continues with tcon->crtc set to NULL. sun4i_rgb_init() and
sun4i_lvds_init() then dereference it in drm_crtc_mask(), which
oopses.
Return the error pointer instead.
Fixes: dcd215801b02 ("drm/sun4i: Drop primary layer pointer from sun4i_drv")
Signed-off-by: Jernej Skrabec <jernej.skrabec@gmail.com>
Acked-by: Chen-Yu Tsai <wens@kernel.org>
Link: https://patch.msgid.link/b26a0d427d9dfae9c82e3ca90a67d24d8ece5a28.1785772659.git.jernej.skrabec@gmail.com
Signed-off-by: Chen-Yu Tsai <wens@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/sun4i/sun4i_crtc.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/sun4i/sun4i_crtc.c b/drivers/gpu/drm/sun4i/sun4i_crtc.c
index 18e74047b0f56..3e90aeb68c480 100644
--- a/drivers/gpu/drm/sun4i/sun4i_crtc.c
+++ b/drivers/gpu/drm/sun4i/sun4i_crtc.c
@@ -208,7 +208,7 @@ struct sun4i_crtc *sun4i_crtc_init(struct drm_device *drm,
planes = sunxi_engine_layers_init(drm, engine);
if (IS_ERR(planes)) {
dev_err(drm->dev, "Couldn't create the planes\n");
- return NULL;
+ return ERR_CAST(planes);
}
/* find primary and cursor planes for drm_crtc_init_with_planes */
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0916/1518] drm/sun4i: tcon: Drop remote endpoint reference
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (914 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0915/1518] drm/sun4i: crtc: Propagate layer initialization error Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0917/1518] drm/sun4i: dw-hdmi: Drop TCON TOP port reference Greg Kroah-Hartman
` (82 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jernej Skrabec, Chen-Yu Tsai,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jernej Skrabec <jernej.skrabec@gmail.com>
[ Upstream commit 3f77e4072630e2301efdbe521e7fca10311043ec ]
sun4i_tcon_of_get_id_from_port() never drops the reference taken by
of_graph_get_remote_endpoint(). The function is not only called during
bind, but also on every mode set through sun8i_r40_tcon_tv_set_mux(),
so the leak accumulates.
Fixes: e8d5bbf7f4c4 ("drm/sun4i: tcon: get TCON ID and matching engine with remote endpoint ID")
Signed-off-by: Jernej Skrabec <jernej.skrabec@gmail.com>
Acked-by: Chen-Yu Tsai <wens@kernel.org>
Reviewed-by: Jernej Skrabec <jernej.skrabec@gmail.com>
Link: https://patch.msgid.link/3f5ec952ad80cb51efebf2fe230df50259041a23.1785772659.git.jernej.skrabec@gmail.com
Signed-off-by: Chen-Yu Tsai <wens@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/sun4i/sun4i_tcon.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/gpu/drm/sun4i/sun4i_tcon.c b/drivers/gpu/drm/sun4i/sun4i_tcon.c
index de2d66623f7a2..67047e3b657ff 100644
--- a/drivers/gpu/drm/sun4i/sun4i_tcon.c
+++ b/drivers/gpu/drm/sun4i/sun4i_tcon.c
@@ -972,6 +972,7 @@ static int sun4i_tcon_of_get_id_from_port(struct device_node *port)
continue;
ret = of_property_read_u32(remote, "reg", ®);
+ of_node_put(remote);
if (ret)
continue;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0917/1518] drm/sun4i: dw-hdmi: Drop TCON TOP port reference
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (915 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0916/1518] drm/sun4i: tcon: Drop remote endpoint reference Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0918/1518] drm/sun4i: hdmi-phy: Fix H6 8-bit MPLL config at 594 MHz Greg Kroah-Hartman
` (81 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jernej Skrabec, Chen-Yu Tsai,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jernej Skrabec <jernej.skrabec@gmail.com>
[ Upstream commit d2a242e5688a17b79c89cd966cd31820c5096d80 ]
When the HDMI controller is fed by TCON TOP, the port node used to
enumerate the possible CRTCs is never released.
Fixes: 57e23de02f48 ("drm/sun4i: DW HDMI: Expand algorithm for possible crtcs")
Signed-off-by: Jernej Skrabec <jernej.skrabec@gmail.com>
Acked-by: Chen-Yu Tsai <wens@kernel.org>
Link: https://patch.msgid.link/43ffcc17f7c3f94c1d7bd1ee89134c766e84df35.1785772659.git.jernej.skrabec@gmail.com
Signed-off-by: Chen-Yu Tsai <wens@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/sun4i/sun8i_dw_hdmi.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/gpu/drm/sun4i/sun8i_dw_hdmi.c b/drivers/gpu/drm/sun4i/sun8i_dw_hdmi.c
index 96532709c2a7e..51cdfa1ae3bf4 100644
--- a/drivers/gpu/drm/sun4i/sun8i_dw_hdmi.c
+++ b/drivers/gpu/drm/sun4i/sun8i_dw_hdmi.c
@@ -83,6 +83,8 @@ static u32 sun8i_dw_hdmi_find_possible_crtcs(struct drm_device *drm,
of_node_put(remote_port);
}
}
+
+ of_node_put(port);
} else {
crtcs = drm_of_find_possible_crtcs(drm, node);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0918/1518] drm/sun4i: hdmi-phy: Fix H6 8-bit MPLL config at 594 MHz
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (916 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0917/1518] drm/sun4i: dw-hdmi: Drop TCON TOP port reference Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0919/1518] rust: cpufreq: Add CPUFREQ_TABLE_END as last table entry in TableBuilder::to_table Greg Kroah-Hartman
` (80 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jernej Skrabec, Chen-Yu Tsai,
Chen-Yu Tsai, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jernej Skrabec <jernej.skrabec@gmail.com>
[ Upstream commit 0ba6deddaae74f0539c0303bfb5f860adbe1a68b ]
The 8-bit entry of the last MPLL row (594 MHz) doesn't lock reliably on
H6. 4K@60 RGB/YUV444, which is the mode that reaches this entry, doesn't
come up.
Align the value with the vendor driver. Other entries are left alone,
they are used by lower pixel clocks which work fine.
Tested with 4K@60 on a LG TV.
Fixes: 0fb4b858b102 ("drm/sun4i: Add support for H6 HDMI PHY")
Signed-off-by: Jernej Skrabec <jernej.skrabec@gmail.com>
Acked-by: Chen-Yu Tsai <wens@kernel.org>
Reviewed-by: Chen-Yu Tsai <wens@csie.org>
Link: https://patch.msgid.link/aec9060209473b8176eb43bc7c63c20b21306adf.1785772659.git.jernej.skrabec@gmail.com
Signed-off-by: Chen-Yu Tsai <wens@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/sun4i/sun8i_hdmi_phy.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/sun4i/sun8i_hdmi_phy.c b/drivers/gpu/drm/sun4i/sun8i_hdmi_phy.c
index 4fa69c463dc46..489ea94693ffa 100644
--- a/drivers/gpu/drm/sun4i/sun8i_hdmi_phy.c
+++ b/drivers/gpu/drm/sun4i/sun8i_hdmi_phy.c
@@ -91,7 +91,7 @@ static const struct dw_hdmi_mpll_config sun50i_h6_mpll_cfg[] = {
},
}, {
594000000, {
- { 0x1a40, 0x0003 },
+ { 0x1a7c, 0x0003 },
{ 0x3b4c, 0x0003 },
{ 0x5a64, 0x0003 },
},
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0919/1518] rust: cpufreq: Add CPUFREQ_TABLE_END as last table entry in TableBuilder::to_table
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (917 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0918/1518] drm/sun4i: hdmi-phy: Fix H6 8-bit MPLL config at 594 MHz Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0920/1518] rust: cpufreq: Fix temporary write in Registration::bios_limit_callback Greg Kroah-Hartman
` (79 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dylan Zueck, Yuan Tan,
Priya Bala Govindasamy, Viresh Kumar, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Priya Bala Govindasamy <pgovind2@uci.edu>
[ Upstream commit b5e4771f20a37fdf19eac0824bf062dffb4e291f ]
The `TableBuilder::to_table` function adds `Hertz(c_ulong::MAX).as_khz()`
as the last frequency entry in the frequency table.
But the C API expects the last entry to have frequency set to
`CPUFREQ_TABLE_END` which is `~1u` as per include/linux/cpufreq.h.
Fix this by setting the last frequency entry to `CPUFREQ_TABLE_END`
instead of `Hertz(c_ulong::MAX).as_khz()`.
Fixes: 2207856ff0bc8d953d6e89bda70b8978c2de8bab ("rust: cpufreq: Add initial abstractions for cpufreq framework")
Reported-by: Dylan Zueck<dzueck@uci.edu>
Reported-by: Yuan Tan<ytan089@ucr.edu>
Assisted-by: ChatGPT:gpt-5.6-terra
Signed-off-by: Priya Bala Govindasamy<pgovind2@uci.edu>
Signed-off-by: Viresh Kumar <viresh.kumar@linaro.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
rust/kernel/cpufreq.rs | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
diff --git a/rust/kernel/cpufreq.rs b/rust/kernel/cpufreq.rs
index a509d09ca4523..ccf22811c9f6c 100644
--- a/rust/kernel/cpufreq.rs
+++ b/rust/kernel/cpufreq.rs
@@ -361,23 +361,28 @@ impl TableBuilder {
}
}
- /// Adds a new entry to the table.
- pub fn add(&mut self, freq: Hertz, flags: u32, driver_data: u32) -> Result {
+ /// Adds a raw frequency-table entry.
+ fn push(&mut self, frequency: u32, flags: u32, driver_data: u32) -> Result {
// Adds the new entry at the end of the vector.
Ok(self.entries.push(
bindings::cpufreq_frequency_table {
flags,
driver_data,
- frequency: freq.as_khz() as u32,
+ frequency,
},
GFP_KERNEL,
)?)
}
+ /// Adds a new entry to the table.
+ pub fn add(&mut self, freq: Hertz, flags: u32, driver_data: u32) -> Result {
+ self.push(freq.as_khz() as u32, flags, driver_data)
+ }
+
/// Consumes the [`TableBuilder`] and returns [`TableBox`].
pub fn to_table(mut self) -> Result<TableBox> {
// Add last entry to the table.
- self.add(Hertz(c_ulong::MAX), 0, 0)?;
+ self.push(bindings::CPUFREQ_TABLE_END as u32, 0, 0)?;
TableBox::new(self.entries)
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0920/1518] rust: cpufreq: Fix temporary write in Registration::bios_limit_callback
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (918 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0919/1518] rust: cpufreq: Add CPUFREQ_TABLE_END as last table entry in TableBuilder::to_table Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0921/1518] cpufreq: imx6q: fix devres accumulation across driver rebind Greg Kroah-Hartman
` (78 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dylan Zueck, Yuan Tan,
Priya Bala Govindasamy, Viresh Kumar, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Priya Bala Govindasamy <pgovind2@uci.edu>
[ Upstream commit 19c76bdd3fc02475c73c8576f6f4a55ff07886f1 ]
In `Registration::bios_limit_callback`, the expression
`&mut (unsafe { *limit })` creates a reference to a temporary copy
of the value pointed to by `limit` on the stack.
Therefore, writes made by `T::bios_limit` go to this temporary
instead of the memory location pointed to by `limit`.
Additionally, `limit` may be uninitialized, such as when
`Registration::bios_limit_callback` is invoked by `show_bios_limit`
in drivers/cpufreq/cpufreq.c. Therefore creating a reference to
`limit` is unsound.
Fix this by changing the signature of `T::bios_limit` to return the limit
value.
`Registration::bios_limit_callback` can then update `limit` directly.
Fixes: c6af9a1191d042839e56abff69e8b0302d117988 ("rust: cpufreq: Extend abstractions for driver registration")
Reported-by: Dylan Zueck<dzueck@uci.edu>
Reported-by: Yuan Tan<ytan089@ucr.edu>
Assisted-by: ChatGPT:gpt-5.4
Signed-off-by: Priya Bala Govindasamy<pgovind2@uci.edu>
[ Viresh: Fix rustfmtcheck warning ]
Signed-off-by: Viresh Kumar <viresh.kumar@linaro.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
rust/kernel/cpufreq.rs | 11 ++++++++---
1 file changed, 8 insertions(+), 3 deletions(-)
diff --git a/rust/kernel/cpufreq.rs b/rust/kernel/cpufreq.rs
index ccf22811c9f6c..1c378350f7ea1 100644
--- a/rust/kernel/cpufreq.rs
+++ b/rust/kernel/cpufreq.rs
@@ -821,7 +821,9 @@ pub trait Driver {
}
/// Driver's `bios_limit` callback.
- fn bios_limit(_policy: &mut Policy, _limit: &mut u32) -> Result {
+ ///
+ /// Returns HW/BIOS max frequency limitations for the CPU.
+ fn bios_limit(_policy: &mut Policy) -> Result<u32> {
build_error!(VTABLE_DEFAULT_ERROR)
}
@@ -1356,9 +1358,12 @@ impl<T: Driver> Registration<T> {
from_result(|| {
let mut policy = PolicyCpu::from_cpu(cpu_id)?;
-
+ let val = T::bios_limit(&mut policy)?;
// SAFETY: `limit` is guaranteed by the C code to be valid.
- T::bios_limit(&mut policy, &mut (unsafe { *limit })).map(|()| 0)
+ unsafe {
+ *limit = val;
+ }
+ Ok(0)
})
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0921/1518] cpufreq: imx6q: fix devres accumulation across driver rebind
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (919 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0920/1518] rust: cpufreq: Fix temporary write in Registration::bios_limit_callback Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0922/1518] cpufreq: imx6q: fix out-of-bounds write when probed more than once Greg Kroah-Hartman
` (77 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Viresh Kumar,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 22c23c72c3b21fa3ec3db5070dfc0582794e0ef9 ]
imx6_soc_volt is allocated with devm_kcalloc(cpu_dev, ...), where cpu_dev
is the CPU device from get_cpu_device(0). That device is never unbound, so
its devres list is never released, and imx6q_cpufreq_remove() does not free
the array either. Every probe therefore adds an allocation that stays for
the lifetime of the system.
Allocate against the platform device instead. Its devres is released when
the driver is unbound, which is exactly the lifetime the array wants:
imx6q_set_target() reads it, and nothing may reach that after
cpufreq_unregister_driver().
That makes the array actually go away on unbind, so also clear the
file-scope pointer in remove and on the failed-probe path, rather than
leave it pointing at memory devres is about to release.
Tested by rebinding the driver on qemu's mcimx6ul-evk.
Fixes: b4573d1d657a ("cpufreq: imx6q: correct VDDSOC/PU voltage scaling when cpufreq is changed")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Signed-off-by: Viresh Kumar <viresh.kumar@linaro.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/cpufreq/imx6q-cpufreq.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/cpufreq/imx6q-cpufreq.c b/drivers/cpufreq/imx6q-cpufreq.c
index e93697d3edfd9..8110c95059e0e 100644
--- a/drivers/cpufreq/imx6q-cpufreq.c
+++ b/drivers/cpufreq/imx6q-cpufreq.c
@@ -400,7 +400,7 @@ static int imx6q_cpufreq_probe(struct platform_device *pdev)
}
/* Make imx6_soc_volt array's size same as arm opp number */
- imx6_soc_volt = devm_kcalloc(cpu_dev, num, sizeof(*imx6_soc_volt),
+ imx6_soc_volt = devm_kcalloc(&pdev->dev, num, sizeof(*imx6_soc_volt),
GFP_KERNEL);
if (imx6_soc_volt == NULL) {
ret = -ENOMEM;
@@ -485,6 +485,7 @@ static int imx6q_cpufreq_probe(struct platform_device *pdev)
return 0;
free_freq_table:
+ imx6_soc_volt = NULL;
dev_pm_opp_free_cpufreq_table(cpu_dev, &freq_table);
out_free_opp:
dev_pm_opp_of_remove_table(cpu_dev);
@@ -506,6 +507,7 @@ static int imx6q_cpufreq_probe(struct platform_device *pdev)
static void imx6q_cpufreq_remove(struct platform_device *pdev)
{
cpufreq_unregister_driver(&imx6q_cpufreq_driver);
+ imx6_soc_volt = NULL;
dev_pm_opp_free_cpufreq_table(cpu_dev, &freq_table);
dev_pm_opp_of_remove_table(cpu_dev);
regulator_put(arm_reg);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0922/1518] cpufreq: imx6q: fix out-of-bounds write when probed more than once
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (920 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0921/1518] cpufreq: imx6q: fix devres accumulation across driver rebind Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0923/1518] IB/isert: delay the final Login Response until the session is registered Greg Kroah-Hartman
` (76 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Karl Mehltretter, Viresh Kumar,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Karl Mehltretter <kmehltretter@gmail.com>
[ Upstream commit 8c3afcf27fa4582c1ab912503dc8a4ebb8dc0f82 ]
imx6_soc_volt is allocated fresh on every probe, sized to the number of
ARM OPPs:
imx6_soc_volt = devm_kcalloc(cpu_dev, num, sizeof(*imx6_soc_volt),
GFP_KERNEL);
but it is filled through soc_opp_count, which has static storage and is
never reset. A second bind after an unbind keeps indexing from where the
first one stopped, and writes past the end of the new array.
Unbinding and rebinding the driver on qemu's mcimx6ul-evk, under KASAN:
BUG: KASAN: slab-out-of-bounds in imx6q_cpufreq_probe+0x3b0/0xa34
Write of size 4 at addr c5e90480 by task binder/73
imx6q_cpufreq_probe from platform_probe+0x88/0xe4
platform_probe from really_probe+0x108/0x384
bind_store from kernfs_fop_write_iter+0x1b4/0x28c
The write lands one u32 past the end of the allocation.
soc_opp_count is only read a few lines below the loop that fills it, so it
never needed static storage. Make it a local.
Fixes: b4573d1d657a ("cpufreq: imx6q: correct VDDSOC/PU voltage scaling when cpufreq is changed")
Assisted-by: Claude:claude-opus-5
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
Signed-off-by: Viresh Kumar <viresh.kumar@linaro.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/cpufreq/imx6q-cpufreq.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/cpufreq/imx6q-cpufreq.c b/drivers/cpufreq/imx6q-cpufreq.c
index 8110c95059e0e..731f5721ff1ed 100644
--- a/drivers/cpufreq/imx6q-cpufreq.c
+++ b/drivers/cpufreq/imx6q-cpufreq.c
@@ -55,7 +55,6 @@ static unsigned int max_freq;
static unsigned int transition_latency;
static u32 *imx6_soc_volt;
-static u32 soc_opp_count;
static int imx6q_set_target(struct cpufreq_policy *policy, unsigned int index)
{
@@ -330,6 +329,7 @@ static int imx6q_cpufreq_probe(struct platform_device *pdev)
const struct property *prop;
const __be32 *val;
u32 nr, i, j;
+ u32 soc_opp_count = 0;
cpu_dev = get_cpu_device(0);
if (!cpu_dev) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0923/1518] IB/isert: delay the final Login Response until the session is registered
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (921 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0922/1518] cpufreq: imx6q: fix out-of-bounds write when probed more than once Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0924/1518] IB/isert: post the full-feature receive buffers after session registration Greg Kroah-Hartman
` (75 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yehyeong Lee, Leon Romanovsky,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
[ Upstream commit 464f5afa92d071a226f88424803b0fcf88093ede ]
isert_put_login_tx() puts the final Login Response on the wire before
__transport_register_session(), which iscsi_post_login_handler() reaches
only after iscsi_target_do_login() returns. An initiator that issues a
SCSI command as soon as it sees that response can have it executed against
an se_session whose se_tpg is still NULL, and the ib-comp-wq worker oopses
on the NULL dereference.
Oops: general protection fault, probably for non-canonical address 0xdffffc000000000f: 0000 [#1] SMP KASAN NOPTI
KASAN: null-ptr-deref in range [0x0000000000000078-0x000000000000007f]
CPU: 0 UID: 0 PID: 178 Comm: kworker/0:1H Not tainted 7.2.0-rc5-V2CTL-gf5098b6bae76 #10 PREEMPT(lazy)
Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
Workqueue: ib-comp-wq ib_cq_poll_work
RIP: 0010:target_submit+0xbe/0x390
Code: fa 48 c1 ea 03 80 3c 02 00 0f 85 89 02 00 00 48 b8 00 00 00 00 00 fc ff df 4d 8b 64 24 18 49 8d 7c 24 78 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 5a 02 00 00 48 8d 7b 78 4d 8b 6c 24 78 48 b8 00
RSP: 0018:ffff8881058cfa78 EFLAGS: 00010206
RAX: dffffc0000000000 RBX: ffff88810c78c6f0 RCX: ffffffff964bb363
RDX: 000000000000000f RSI: 00000000fffffe00 RDI: 0000000000000078
RBP: 1ffff11020b19f52 R08: 0000000000000001 R09: ffffed1020b19f52
R10: 0000000000000003 R11: ffff88810596c000 R12: 0000000000000000
R13: ffff88810c61b000 R14: ffff88810c6a3400 R15: ffff88810c61b044
FS: 0000000000000000(0000) GS:ffff8881822b2000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f1f1b83c000 CR3: 000000006fe72001 CR4: 0000000000770ef0
PKRU: 55555554
Call Trace:
<TASK>
? __pfx__raw_spin_lock_bh+0x10/0x10
? __pfx_target_submit+0x10/0x10
? mutex_lock+0x81/0xe0
? __pfx_mutex_lock+0x10/0x10
? iscsit_execute_cmd+0x650/0x850
iscsit_sequence_cmd+0x186/0x3d0
iscsit_process_scsi_cmd+0x87/0x300
isert_recv_done+0x1002/0x2390
? __pfx_isert_recv_done+0x10/0x10
? rxe_poll_cq+0x253/0x3d0
? finish_task_switch.isra.0+0x1dc/0xa70
__ib_process_cq+0xe1/0x390
ib_cq_poll_work+0x46/0x150
process_one_work+0x633/0x1030
? assign_work+0x11d/0x370
worker_thread+0x45b/0xd10
? __pfx_worker_thread+0x10/0x10
? __pfx_worker_thread+0x10/0x10
kthread+0x2c6/0x3b0
? recalc_sigpending+0x15c/0x1e0
? __pfx_kthread+0x10/0x10
ret_from_fork+0x36e/0x5a0
? __pfx_ret_from_fork+0x10/0x10
? __switch_to+0x572/0xdd0
? __pfx_kthread+0x10/0x10
ret_from_fork_asm+0x1a/0x30
</TASK>
Modules linked in:
---[ end trace 0000000000000000 ]---
Delay the final Login Response instead. isert_get_rx_pdu() runs from
iscsi_target_rx_thread() after conn->rx_login_comp, completed by
iscsi_post_login_handler() after __transport_register_session(); iscsi-TCP
and cxgbit already take PDUs from that thread, isert alone does not. The
buffers are still posted first, so the initiator's first command does not
meet an empty receive queue and nothing depends on RNR flow control, and
the header and payload live in isert_conn, not in the struct iscsi_login
that iscsi_target_nego_release() frees first.
Over rxe, 400 login cycles per run, the oops appeared in 10 of 20
unpatched runs and in none of 20 runs with this patch. An
initiator that never waits is handled by the next patch.
Not tested: iWARP, discovery sessions over iSER, and real HCAs.
Fixes: b8d26b3be8b3 ("iser-target: Add iSCSI Extensions for RDMA (iSER) target driver")
Signed-off-by: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
Link: https://patch.msgid.link/20260731041212.1733364-1-yhlee@isslab.korea.ac.kr
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/ulp/isert/ib_isert.c | 20 ++++++++++++++++++--
drivers/infiniband/ulp/isert/ib_isert.h | 1 +
2 files changed, 19 insertions(+), 2 deletions(-)
diff --git a/drivers/infiniband/ulp/isert/ib_isert.c b/drivers/infiniband/ulp/isert/ib_isert.c
index 1fcaf7df8b398..d0e3d1cf5b41b 100644
--- a/drivers/infiniband/ulp/isert/ib_isert.c
+++ b/drivers/infiniband/ulp/isert/ib_isert.c
@@ -59,6 +59,8 @@ static void isert_recv_done(struct ib_cq *cq, struct ib_wc *wc);
static void isert_send_done(struct ib_cq *cq, struct ib_wc *wc);
static void isert_login_recv_done(struct ib_cq *cq, struct ib_wc *wc);
static void isert_login_send_done(struct ib_cq *cq, struct ib_wc *wc);
+static void isert_unmap_tx_desc(struct iser_tx_desc *tx_desc,
+ struct ib_device *ib_dev);
static int isert_sg_tablesize_set(const char *val, const struct kernel_param *kp)
{
@@ -498,6 +500,8 @@ isert_connect_release(struct isert_conn *isert_conn)
if (isert_conn->qp)
isert_destroy_qp(isert_conn);
+ isert_unmap_tx_desc(&isert_conn->login_tx_desc, device->ib_device);
+
if (isert_conn->login_desc)
isert_free_login_buf(isert_conn);
@@ -958,14 +962,17 @@ isert_put_login_tx(struct iscsit_conn *conn, struct iscsi_login *login,
mutex_lock(&isert_conn->mutex);
isert_conn->state = ISER_CONN_FULL_FEATURE;
mutex_unlock(&isert_conn->mutex);
- goto post_send;
+
+ /* Sent from isert_get_rx_pdu() after registration. */
+ isert_conn->login_rsp_pending = true;
+ return 0;
}
ret = isert_login_post_recv(isert_conn);
if (ret)
return ret;
}
-post_send:
+
ret = isert_login_post_send(isert_conn, tx_desc);
if (ret)
return ret;
@@ -2625,8 +2632,17 @@ static void isert_free_conn(struct iscsit_conn *conn)
static void isert_get_rx_pdu(struct iscsit_conn *conn)
{
+ struct isert_conn *isert_conn = conn->context;
struct completion comp;
+ /* The session is registered by now; see isert_put_login_tx(). */
+ if (isert_conn->login_rsp_pending) {
+ isert_conn->login_rsp_pending = false;
+ if (isert_login_post_send(isert_conn,
+ &isert_conn->login_tx_desc))
+ return;
+ }
+
init_completion(&comp);
wait_for_completion_interruptible(&comp);
diff --git a/drivers/infiniband/ulp/isert/ib_isert.h b/drivers/infiniband/ulp/isert/ib_isert.h
index 0b2dfd6e7e270..0bac5aa66c802 100644
--- a/drivers/infiniband/ulp/isert/ib_isert.h
+++ b/drivers/infiniband/ulp/isert/ib_isert.h
@@ -178,6 +178,7 @@ struct isert_conn {
struct completion login_comp;
struct completion login_req_comp;
struct iser_tx_desc login_tx_desc;
+ bool login_rsp_pending;
struct rdma_cm_id *cm_id;
struct ib_qp *qp;
struct ib_cq *cq;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0924/1518] IB/isert: post the full-feature receive buffers after session registration
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (922 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0923/1518] IB/isert: delay the final Login Response until the session is registered Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0925/1518] RDMA/siw: Fix use-after-free in siw_accept() Greg Kroah-Hartman
` (74 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yehyeong Lee, Leon Romanovsky,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
[ Upstream commit 5247dde9daac7e107853b6fea043f7f47be033f7 ]
isert_put_login_tx() posts the full-feature receive buffers before
__transport_register_session() runs, so an initiator that does not wait
for the final Login Response can still have a SCSI command executed
against an se_session whose se_tpg is NULL - the same oops as the
previous patch, at target_submit+0xbe.
Post them from isert_get_rx_pdu(), which the previous patch already uses
to send that response, and post them before that send: the receive queue
is filled at the moment the initiator is told it may use it. Allocating
there keeps the existing property that a memory allocation failure cannot
happen once the final Login Response is on the wire.
The receive queue is already empty between the final Login Request and
isert_post_recvm(); this moves the second point later, from a median of
92 us to 172 us over 1200 logins. Only an initiator that sends before it
has been told to can reach that window, and on IB and RoCE its send is
retried there until the buffers appear - isert_rdma_accept() asks for
rnr_retry_count = 7. iWARP has no RNR flow control, so there the same
send terminates the connection instead.
Measured over rxe, 400 login cycles per run, with an initiator that does
not wait: an instrumented build counted no entries to isert_recv_done()
before the buffers are posted in 10 runs, where that initiator oopsed
8 of 10 unpatched runs and 5 of 10 with only the previous patch.
Not tested: iWARP, discovery sessions over iSER, and real HCAs.
Fixes: b8d26b3be8b3 ("iser-target: Add iSCSI Extensions for RDMA (iSER) target driver")
Signed-off-by: Yehyeong Lee <yhlee@isslab.korea.ac.kr>
Link: https://patch.msgid.link/20260731041212.1733364-2-yhlee@isslab.korea.ac.kr
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/ulp/isert/ib_isert.c | 41 ++++++++++++-------------
1 file changed, 20 insertions(+), 21 deletions(-)
diff --git a/drivers/infiniband/ulp/isert/ib_isert.c b/drivers/infiniband/ulp/isert/ib_isert.c
index d0e3d1cf5b41b..6483a55170cd1 100644
--- a/drivers/infiniband/ulp/isert/ib_isert.c
+++ b/drivers/infiniband/ulp/isert/ib_isert.c
@@ -949,21 +949,7 @@ isert_put_login_tx(struct iscsit_conn *conn, struct iscsi_login *login,
}
if (!login->login_failed) {
if (login->login_complete) {
- ret = isert_alloc_rx_descriptors(isert_conn);
- if (ret)
- return ret;
-
- ret = isert_post_recvm(isert_conn,
- ISERT_QP_MAX_RECV_DTOS);
- if (ret)
- return ret;
-
- /* Now we are in FULL_FEATURE phase */
- mutex_lock(&isert_conn->mutex);
- isert_conn->state = ISER_CONN_FULL_FEATURE;
- mutex_unlock(&isert_conn->mutex);
-
- /* Sent from isert_get_rx_pdu() after registration. */
+ /* Posted and sent from isert_get_rx_pdu(). */
isert_conn->login_rsp_pending = true;
return 0;
}
@@ -2635,13 +2621,26 @@ static void isert_get_rx_pdu(struct iscsit_conn *conn)
struct isert_conn *isert_conn = conn->context;
struct completion comp;
+ /* The login timeout timer can fail the login after isert_put_login_tx(). */
+ if (!isert_conn->login_rsp_pending)
+ return;
+
+ isert_conn->login_rsp_pending = false;
+
/* The session is registered by now; see isert_put_login_tx(). */
- if (isert_conn->login_rsp_pending) {
- isert_conn->login_rsp_pending = false;
- if (isert_login_post_send(isert_conn,
- &isert_conn->login_tx_desc))
- return;
- }
+ if (isert_alloc_rx_descriptors(isert_conn))
+ return;
+
+ if (isert_post_recvm(isert_conn, ISERT_QP_MAX_RECV_DTOS))
+ return;
+
+ /* Now we are in FULL_FEATURE phase */
+ mutex_lock(&isert_conn->mutex);
+ isert_conn->state = ISER_CONN_FULL_FEATURE;
+ mutex_unlock(&isert_conn->mutex);
+
+ if (isert_login_post_send(isert_conn, &isert_conn->login_tx_desc))
+ return;
init_completion(&comp);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0925/1518] RDMA/siw: Fix use-after-free in siw_accept()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (923 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0924/1518] IB/isert: post the full-feature receive buffers after session registration Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0926/1518] module: replace use of system_wq with system_dfl_wq Greg Kroah-Hartman
` (73 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Shuangpeng Bai, Leon Romanovsky,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
[ Upstream commit a9394971825933074032794a5feee5211509c774 ]
siw_accept() looks up the QP supplied by userspace. If that QP is
already in RTS, the function jumps to error cleanup before associating
the incoming CEP with it.
The cleanup tests whether qp->cep is non-NULL and assumes the current
call installed the association. However, qp->cep can point to the CEP
of an existing connection. The cleanup then drops a reference from the
incoming cep, not qp->cep. Once the incoming endpoint loses its
remaining references, this can free it before the subsequent cep->qp
store, causing a use-after-free. It also clears the existing QP
association.
Only release the association reference when qp->cep is the incoming
CEP. This preserves an existing association and avoids accessing the
freed endpoint.
Fixes: 6c52fdc244b5 ("rdma/siw: connection management")
Signed-off-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
Link: https://patch.msgid.link/20260801213632.1086548-1-shuangpeng.kernel@gmail.com
Signed-off-by: Leon Romanovsky <leon@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/sw/siw/siw_cm.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/infiniband/sw/siw/siw_cm.c b/drivers/infiniband/sw/siw/siw_cm.c
index 49ff121f77fe4..bb7d909639071 100644
--- a/drivers/infiniband/sw/siw/siw_cm.c
+++ b/drivers/infiniband/sw/siw/siw_cm.c
@@ -1701,7 +1701,7 @@ int siw_accept(struct iw_cm_id *id, struct iw_cm_conn_param *params)
cep->state = SIW_EPSTATE_CLOSED;
siw_free_cm_id(cep);
- if (qp->cep) {
+ if (qp->cep == cep) {
siw_cep_put(cep);
qp->cep = NULL;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0926/1518] module: replace use of system_wq with system_dfl_wq
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (924 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0925/1518] RDMA/siw: Fix use-after-free in siw_accept() Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0927/1518] module: use strscpy() to copy module names in stats and dup tracking Greg Kroah-Hartman
` (72 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tejun Heo, Marco Crivellari,
Petr Pavlu, Sami Tolvanen, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Marco Crivellari <marco.crivellari@suse.com>
[ Upstream commit 581ac2d4a58b81669cc6abf645a558bce5cf14ab ]
Currently if a user enqueues a work item using schedule_delayed_work() the
used wq is "system_wq" (per-cpu wq) while queue_delayed_work() use
WORK_CPU_UNBOUND (used when a cpu is not specified). The same applies to
schedule_work() that is using system_wq and queue_work(), that makes use
again of WORK_CPU_UNBOUND.
This lack of consistency cannot be addressed without refactoring the API.
This continues the effort to refactor workqueue APIs, which began with
the introduction of new workqueues and a new alloc_workqueue flag in:
commit 128ea9f6ccfb ("workqueue: Add system_percpu_wq and system_dfl_wq")
commit 930c2ea566af ("workqueue: Add new WQ_PERCPU flag")
Switch to using system_dfl_wq, the new unbound workqueue, because the
users do not benefit from a per-cpu workqueue.
Suggested-by: Tejun Heo <tj@kernel.org>
Signed-off-by: Marco Crivellari <marco.crivellari@suse.com>
Reviewed-by: Petr Pavlu <petr.pavlu@suse.com>
Signed-off-by: Sami Tolvanen <samitolvanen@google.com>
Stable-dep-of: 5eecb11b543f ("module/dups: Fix use-after-free in kmod_dup_req lifetime handling")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/module/dups.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/kernel/module/dups.c b/kernel/module/dups.c
index bd2149fbe1173..0b633f2edda6b 100644
--- a/kernel/module/dups.c
+++ b/kernel/module/dups.c
@@ -113,7 +113,7 @@ static void kmod_dup_request_complete(struct work_struct *work)
* let this linger forever as this is just a boot optimization for
* possible abuses of vmalloc() incurred by finit_module() thrashing.
*/
- queue_delayed_work(system_wq, &kmod_req->delete_work, 60 * HZ);
+ queue_delayed_work(system_dfl_wq, &kmod_req->delete_work, 60 * HZ);
}
bool kmod_dup_request_exists_wait(char *module_name, bool wait, int *dup_ret)
@@ -240,7 +240,7 @@ void kmod_dup_request_announce(char *module_name, int ret)
* There is no rush. But we also don't want to hold the
* caller up forever or introduce any boot delays.
*/
- queue_work(system_wq, &kmod_req->complete_work);
+ queue_work(system_dfl_wq, &kmod_req->complete_work);
out:
mutex_unlock(&kmod_dup_mutex);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0927/1518] module: use strscpy() to copy module names in stats and dup tracking
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (925 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0926/1518] module: replace use of system_wq with system_dfl_wq Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0928/1518] module/dups: Inform duplicate requests about the result directly Greg Kroah-Hartman
` (71 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Naveen Kumar Chaudhary, Petr Pavlu,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Naveen Kumar Chaudhary <naveen.osdev@gmail.com>
[ Upstream commit 93c29ebd1622fb0670701e1c1b3a978a5cac08b7 ]
Both try_add_failed_module() and kmod_dup_request_exists_wait() use
memcpy() with strlen() to copy module names into fixed-size
char[MODULE_NAME_LEN] buffers. Neither performs a bounds check on the
copy. Current callers always pass names originating from
mod->name (itself char[MODULE_NAME_LEN]), so this is not exploitable
today. However both functions accept a plain const char * with no
documented length contract, making them latent buffer overflows if a
future caller passes a longer string.
Replace memcpy() with strscpy() in both sites, which bounds the copy
to MODULE_NAME_LEN and always NUL-terminates.
Signed-off-by: Naveen Kumar Chaudhary <naveen.osdev@gmail.com>
Reviewed-by: Petr Pavlu <petr.pavlu@suse.com>
Signed-off-by: Petr Pavlu <petr.pavlu@suse.com>
Stable-dep-of: 5eecb11b543f ("module/dups: Fix use-after-free in kmod_dup_req lifetime handling")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/module/dups.c | 2 +-
kernel/module/stats.c | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/kernel/module/dups.c b/kernel/module/dups.c
index 0b633f2edda6b..6ecc42193de24 100644
--- a/kernel/module/dups.c
+++ b/kernel/module/dups.c
@@ -129,7 +129,7 @@ bool kmod_dup_request_exists_wait(char *module_name, bool wait, int *dup_ret)
if (!new_kmod_req)
return false;
- memcpy(new_kmod_req->name, module_name, strlen(module_name));
+ strscpy(new_kmod_req->name, module_name);
INIT_WORK(&new_kmod_req->complete_work, kmod_dup_request_complete);
INIT_DELAYED_WORK(&new_kmod_req->delete_work, kmod_dup_request_delete);
init_completion(&new_kmod_req->first_req_done);
diff --git a/kernel/module/stats.c b/kernel/module/stats.c
index 3ba0e98b3c910..2a4e2f6708965 100644
--- a/kernel/module/stats.c
+++ b/kernel/module/stats.c
@@ -253,7 +253,7 @@ int try_add_failed_module(const char *name, enum fail_dup_mod_reason reason)
mod_fail = kzalloc(sizeof(*mod_fail), GFP_KERNEL);
if (!mod_fail)
return -ENOMEM;
- memcpy(mod_fail->name, name, strlen(name));
+ strscpy(mod_fail->name, name);
__set_bit(reason, &mod_fail->dup_fail_mask);
atomic_long_inc(&mod_fail->count);
list_add_rcu(&mod_fail->list, &dup_failed_modules);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0928/1518] module/dups: Inform duplicate requests about the result directly
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (926 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0927/1518] module: use strscpy() to copy module names in stats and dup tracking Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0929/1518] module/dups: Fix use-after-free in kmod_dup_req lifetime handling Greg Kroah-Hartman
` (70 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Petr Pavlu, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Petr Pavlu <petr.pavlu@suse.com>
[ Upstream commit d258ed8a86bb46bbbbc84fb914478259a1e694a4 ]
When kmod_dup_request_announce() announces the completion of
a request_module() call to duplicate waiters, it queues a work item to
invoke kmod_dup_request_complete(), and only that function calls
complete_all().
This adds an arbitrary delay that is unnecessary and provides little
benefit. Call complete_all() directly from kmod_dup_request_announce()
instead.
Signed-off-by: Petr Pavlu <petr.pavlu@suse.com>
Stable-dep-of: 5eecb11b543f ("module/dups: Fix use-after-free in kmod_dup_req lifetime handling")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/module/dups.c | 43 +++++++++----------------------------------
1 file changed, 9 insertions(+), 34 deletions(-)
diff --git a/kernel/module/dups.c b/kernel/module/dups.c
index 6ecc42193de24..7b9b08031d7d2 100644
--- a/kernel/module/dups.c
+++ b/kernel/module/dups.c
@@ -48,7 +48,6 @@ struct kmod_dup_req {
struct list_head list;
char name[MODULE_NAME_LEN];
struct completion first_req_done;
- struct work_struct complete_work;
struct delayed_work delete_work;
int dup_ret;
};
@@ -93,29 +92,6 @@ static void kmod_dup_request_delete(struct work_struct *work)
kfree(kmod_req);
}
-static void kmod_dup_request_complete(struct work_struct *work)
-{
- struct kmod_dup_req *kmod_req;
-
- kmod_req = container_of(work, struct kmod_dup_req, complete_work);
-
- /*
- * This will ensure that the kernel will let all the waiters get
- * informed its time to check the return value. It's time to
- * go home.
- */
- complete_all(&kmod_req->first_req_done);
-
- /*
- * Now that we have allowed prior request_module() calls to go on
- * with life, let's schedule deleting this entry. We don't have
- * to do it right away, but we *eventually* want to do it so to not
- * let this linger forever as this is just a boot optimization for
- * possible abuses of vmalloc() incurred by finit_module() thrashing.
- */
- queue_delayed_work(system_dfl_wq, &kmod_req->delete_work, 60 * HZ);
-}
-
bool kmod_dup_request_exists_wait(char *module_name, bool wait, int *dup_ret)
{
struct kmod_dup_req *kmod_req, *new_kmod_req;
@@ -130,7 +106,6 @@ bool kmod_dup_request_exists_wait(char *module_name, bool wait, int *dup_ret)
return false;
strscpy(new_kmod_req->name, module_name);
- INIT_WORK(&new_kmod_req->complete_work, kmod_dup_request_complete);
INIT_DELAYED_WORK(&new_kmod_req->delete_work, kmod_dup_request_delete);
init_completion(&new_kmod_req->first_req_done);
@@ -230,17 +205,17 @@ void kmod_dup_request_announce(char *module_name, int ret)
kmod_req->dup_ret = ret;
+ /* Inform all duplicate waiters to check the return value. */
+ complete_all(&kmod_req->first_req_done);
+
/*
- * If we complete() here we may allow duplicate threads
- * to continue before the first one that submitted the
- * request. We're in no rush also, given that each and
- * every bounce back to userspace is slow we avoid that
- * with a slight delay here. So queueue up the completion
- * and let duplicates suffer, just wait a tad bit longer.
- * There is no rush. But we also don't want to hold the
- * caller up forever or introduce any boot delays.
+ * Now that we have allowed prior request_module() calls to go on
+ * with life, let's schedule deleting this entry. We don't have
+ * to do it right away, but we *eventually* want to do it so to not
+ * let this linger forever as this is just a boot optimization for
+ * possible abuses of vmalloc() incurred by finit_module() thrashing.
*/
- queue_work(system_dfl_wq, &kmod_req->complete_work);
+ queue_delayed_work(system_dfl_wq, &kmod_req->delete_work, 60 * HZ);
out:
mutex_unlock(&kmod_dup_mutex);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0929/1518] module/dups: Fix use-after-free in kmod_dup_req lifetime handling
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (927 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0928/1518] module/dups: Inform duplicate requests about the result directly Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0930/1518] RDMA/erdma: restrict the driver to little-endian systems Greg Kroah-Hartman
` (69 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Aaron Tomlin, Petr Pavlu,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Petr Pavlu <petr.pavlu@suse.com>
[ Upstream commit 5eecb11b543f9f417bcf0dea239ff99c6af65dbd ]
The kmod dups code uses RCU to ensure that a kmod_dup_req instance is freed
only after it is no longer referenced. When releasing an instance, the
kmod_dup_request_delete() function removes the kmod_dup_req from the
dup_kmod_reqs list, waits via synchronize_rcu() and finally frees it.
However, this doesn't work correctly because parallel users referencing the
instance in kmod_dup_request_exists_wait() don't enter an RCU read-side
critical section. This can result in a use-after-free.
The kmod_dup_request_exists_wait() function may need to hold a valid
reference to a kmod_dup_req instance across a blocking wait until the
corresponding modprobe command completes. This makes it unsuitable for RCU.
Fix the issue by changing the lifecycle management of kmod_dup_req to use
reference counting.
Fixes: 8660484ed1cf ("module: add debugging auto-load duplicate module support")
Reviewed-by: Aaron Tomlin <atomlin@atomlin.com>
Signed-off-by: Petr Pavlu <petr.pavlu@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/module/dups.c | 56 +++++++++++++++++++++++++++++++-------------
1 file changed, 40 insertions(+), 16 deletions(-)
diff --git a/kernel/module/dups.c b/kernel/module/dups.c
index 7b9b08031d7d2..c21b675c239b7 100644
--- a/kernel/module/dups.c
+++ b/kernel/module/dups.c
@@ -30,6 +30,7 @@
#include <linux/ptrace.h>
#include <linux/async.h>
#include <linux/uaccess.h>
+#include <linux/refcount.h>
#include "internal.h"
@@ -38,13 +39,12 @@
static bool enable_dups_trace = IS_ENABLED(CONFIG_MODULE_DEBUG_AUTOLOAD_DUPS_TRACE);
module_param(enable_dups_trace, bool_enable_only, 0644);
-/*
- * Protects dup_kmod_reqs list, adds / removals with RCU.
- */
+/* A mutex-protected list of active kmod requests. */
static DEFINE_MUTEX(kmod_dup_mutex);
static LIST_HEAD(dup_kmod_reqs);
struct kmod_dup_req {
+ refcount_t refcount;
struct list_head list;
char name[MODULE_NAME_LEN];
struct completion first_req_done;
@@ -52,12 +52,24 @@ struct kmod_dup_req {
int dup_ret;
};
+static void get_kmod_req(struct kmod_dup_req *kmod_req)
+{
+ refcount_inc(&kmod_req->refcount);
+}
+
+static void put_kmod_req(struct kmod_dup_req *kmod_req)
+{
+ if (refcount_dec_and_test(&kmod_req->refcount))
+ kfree(kmod_req);
+}
+
static struct kmod_dup_req *kmod_dup_request_lookup(char *module_name)
{
struct kmod_dup_req *kmod_req;
- list_for_each_entry_rcu(kmod_req, &dup_kmod_reqs, list,
- lockdep_is_held(&kmod_dup_mutex)) {
+ lockdep_assert_held(&kmod_dup_mutex);
+
+ list_for_each_entry(kmod_req, &dup_kmod_reqs, list) {
if (strlen(kmod_req->name) == strlen(module_name) &&
!memcmp(kmod_req->name, module_name, strlen(module_name))) {
return kmod_req;
@@ -86,10 +98,10 @@ static void kmod_dup_request_delete(struct work_struct *work)
* just returning 0.
*/
mutex_lock(&kmod_dup_mutex);
- list_del_rcu(&kmod_req->list);
- synchronize_rcu();
+ list_del(&kmod_req->list);
mutex_unlock(&kmod_dup_mutex);
- kfree(kmod_req);
+
+ put_kmod_req(kmod_req);
}
bool kmod_dup_request_exists_wait(char *module_name, bool wait, int *dup_ret)
@@ -105,6 +117,7 @@ bool kmod_dup_request_exists_wait(char *module_name, bool wait, int *dup_ret)
if (!new_kmod_req)
return false;
+ refcount_set(&new_kmod_req->refcount, 1);
strscpy(new_kmod_req->name, module_name);
INIT_DELAYED_WORK(&new_kmod_req->delete_work, kmod_dup_request_delete);
init_completion(&new_kmod_req->first_req_done);
@@ -136,10 +149,12 @@ bool kmod_dup_request_exists_wait(char *module_name, bool wait, int *dup_ret)
* keep tab on duplicates later.
*/
pr_debug("New request_module() for %s\n", module_name);
- list_add_rcu(&new_kmod_req->list, &dup_kmod_reqs);
+ list_add(&new_kmod_req->list, &dup_kmod_reqs);
mutex_unlock(&kmod_dup_mutex);
return false;
}
+
+ get_kmod_req(kmod_req);
mutex_unlock(&kmod_dup_mutex);
/* We are dealing with a duplicate request now */
@@ -169,7 +184,7 @@ bool kmod_dup_request_exists_wait(char *module_name, bool wait, int *dup_ret)
* calls bail out right away.
*/
*dup_ret = 0;
- return true;
+ goto out;
}
/*
@@ -184,12 +199,14 @@ bool kmod_dup_request_exists_wait(char *module_name, bool wait, int *dup_ret)
TASK_KILLABLE);
if (ret) {
*dup_ret = ret;
- return true;
+ goto out;
}
/* Now the duplicate request has the same exact return value as the first request */
*dup_ret = kmod_req->dup_ret;
+out:
+ put_kmod_req(kmod_req);
return true;
}
@@ -199,15 +216,25 @@ void kmod_dup_request_announce(char *module_name, int ret)
mutex_lock(&kmod_dup_mutex);
+ /*
+ * Look for a kmod_dup_req previously added in
+ * kmod_dup_request_exists_wait(). Note that a request_module_nowait()
+ * without its own kmod_dup_req entry can announce a result of
+ * a concurrent request_module() call.
+ */
kmod_req = kmod_dup_request_lookup(module_name);
- if (!kmod_req)
- goto out;
+ if (!kmod_req || completion_done(&kmod_req->first_req_done)) {
+ mutex_unlock(&kmod_dup_mutex);
+ return;
+ }
kmod_req->dup_ret = ret;
/* Inform all duplicate waiters to check the return value. */
complete_all(&kmod_req->first_req_done);
+ mutex_unlock(&kmod_dup_mutex);
+
/*
* Now that we have allowed prior request_module() calls to go on
* with life, let's schedule deleting this entry. We don't have
@@ -216,7 +243,4 @@ void kmod_dup_request_announce(char *module_name, int ret)
* possible abuses of vmalloc() incurred by finit_module() thrashing.
*/
queue_delayed_work(system_dfl_wq, &kmod_req->delete_work, 60 * HZ);
-
-out:
- mutex_unlock(&kmod_dup_mutex);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0930/1518] RDMA/erdma: restrict the driver to little-endian systems
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (928 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0929/1518] module/dups: Fix use-after-free in kmod_dup_req lifetime handling Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0931/1518] wifi: mac80211: skip default WMM setup for AP_VLAN links Greg Kroah-Hartman
` (68 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Cheng Xu, Leon Romanovsky,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Leon Romanovsky <leonro@nvidia.com>
[ Upstream commit a12d9145145b21c50531afb6e3f711b1f34e1465 ]
The eRDMA device interface requires explicit byte ordering, but several
DMA-visible values that should be little-endian remain native-endian.
Command request payloads are copied verbatim, data-path SQE headers are
written without cpu_to_le64(), and kernel doorbell records are assigned
plain u64 values. The command completion path also reads a little-endian
SQE header without conversion.
These paths are byte-swapped on big-endian kernels and can break command
processing during probe. Since complete big-endian support requires
converting every device-visible structure, depend on !CPU_BIG_ENDIAN.
Fixes: ca7fd6cff3b8 ("RDMA/erdma: Add driver to kernel build environment")
Link: https://patch.msgid.link/20260806-missing-endianness-conversion-for-64-v1-1-896327c1aff1@nvidia.com
Acked-by: Cheng Xu <chengyou@linux.alibaba.com>
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/infiniband/hw/erdma/Kconfig | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/infiniband/hw/erdma/Kconfig b/drivers/infiniband/hw/erdma/Kconfig
index 267fc1f3c42af..745e5551773f5 100644
--- a/drivers/infiniband/hw/erdma/Kconfig
+++ b/drivers/infiniband/hw/erdma/Kconfig
@@ -1,7 +1,7 @@
# SPDX-License-Identifier: GPL-2.0-only
config INFINIBAND_ERDMA
tristate "Alibaba Elastic RDMA Adapter (ERDMA) support"
- depends on PCI_MSI && 64BIT
+ depends on PCI_MSI && 64BIT && !CPU_BIG_ENDIAN
depends on INFINIBAND_ADDR_TRANS
depends on INFINIBAND_USER_ACCESS
help
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0931/1518] wifi: mac80211: skip default WMM setup for AP_VLAN links
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (929 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0930/1518] RDMA/erdma: restrict the driver to little-endian systems Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0932/1518] arm64: hibernate: mask DAIF before restoring hibernated kernel Greg Kroah-Hartman
` (67 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Felix Fietkau, Johannes Berg,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Fietkau <nbd@nbd.name>
[ Upstream commit 4d8cfff012aaa971d50b01823b1015c1073c3ff6 ]
AP_VLAN interfaces are never passed to the driver, so setting default WMM
parameters on their links trips the check-sdata-in-driver warning in
drv_conf_tx(), as well as in the BSS_CHANGED_QOS link info notification.
Skip it, matching the existing AP_VLAN handling in this function.
Fixes: 2259d14499d1 ("wifi: mac80211: set default WMM parameters on all links")
Signed-off-by: Felix Fietkau <nbd@nbd.name>
Link: https://patch.msgid.link/20260804082608.2011433-1-nbd@nbd.name
Signed-off-by: Johannes Berg <johannes.berg@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
net/mac80211/link.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/net/mac80211/link.c b/net/mac80211/link.c
index 235e370c2b59e..cd02053ff5063 100644
--- a/net/mac80211/link.c
+++ b/net/mac80211/link.c
@@ -343,7 +343,8 @@ static int ieee80211_vif_update_links(struct ieee80211_sub_if_data *sdata,
link = links[link_id];
ieee80211_link_init(sdata, link_id, &link->data, &link->conf);
ieee80211_link_setup(&link->data);
- ieee80211_set_wmm_default(&link->data, true, non_sta);
+ if (sdata->vif.type != NL80211_IFTYPE_AP_VLAN)
+ ieee80211_set_wmm_default(&link->data, true, non_sta);
}
if (new_links == 0)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0932/1518] arm64: hibernate: mask DAIF before restoring hibernated kernel
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (930 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0931/1518] wifi: mac80211: skip default WMM setup for AP_VLAN links Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0933/1518] arm64: hibernate: Restore DAIF state on error Greg Kroah-Hartman
` (66 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ada Couprie Diaz, Vladimir Murzin,
Jinjie Ruan, Will Deacon, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ada Couprie Diaz <ada.coupriediaz@arm.com>
[ Upstream commit 684bde100117931f4c51c644a95f42f2dab041bc ]
The arm64 hibernate code manages the exception masking in an unsound
way, leading to potential crashes and/or warnings during resume.
When a hibernation image is saved in `swsusp_arch_suspend()`, all DAIF
exceptions are masked (by virtue of `local_daif_save()`), and the
suspended image is saved assuming that all DAIF exceptions will remain
masked when the image is restored.
When a hibernation image is resumed by `swsusp_arch_resume()`, only
interrupts are masked (by virtue of `local_irq_disable()` in
`resume_target_kernel()`). When pseudo-NMI is enabled the DAIF.IF bits
will be clear, and regardless of pseudo-NMI the DAIF.DA bits will be
clear.
This means that there are two problems:
(1) It is possible to take Debug, SError, or pseudo-NMI exceptions
during the resume process. This is unsafe, as during the resume
process both the old ane new kernels will tranisently be in an
inconsistent state, and swsusp_arch_suspend_exit() won't retain
an executable mapping of any exception vectors.
Any exception taken here will be fatal and silent.
(2) When re-entering the resumed kernel, some DAIF bits will be clear
unexpectedly. This permits Debug, SError, or pseudo-NMI exceptions
to be taken for a short period while the resumed kernel is not yet
in a consistent state.
This is detected by CONFIG_ARM64_DEBUG_PRIORITY_MASKING.
Avoid these issues by masking all DAIF exceptions during resume.
Fixes: 82869ac57b5d ("arm64: kernel: Add support for hibernate/suspend-to-disk")
Signed-off-by: Ada Couprie Diaz <ada.coupriediaz@arm.com>
Signed-off-by: Vladimir Murzin <vladimir.murzin@arm.com>
Reviewed-by: Jinjie Ruan <ruanjinjie@huawei.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/kernel/hibernate.c | 12 ++++++++++++
1 file changed, 12 insertions(+)
diff --git a/arch/arm64/kernel/hibernate.c b/arch/arm64/kernel/hibernate.c
index 9717568518ba7..1eb1c1074c5b0 100644
--- a/arch/arm64/kernel/hibernate.c
+++ b/arch/arm64/kernel/hibernate.c
@@ -465,9 +465,21 @@ int __nocfi swsusp_arch_resume(void)
if (el2_reset_needed())
__hyp_set_vectors(el2_vectors);
+ /*
+ * It is necessary to mask all DAIF exceptions here as:
+ *
+ * - The copy of swsusp_arch_suspend_exit() in the hibernation
+ * text cannot handle taking any exceptions.
+ *
+ * - The suspended kernel masked all DAIF exceptions in
+ * swsusp_arch_resume(), and expects to be re-entered in the
+ * same state : with all DAIF exceptions masked.
+ */
+ local_daif_save();
hibernate_exit(virt_to_phys(tmp_pg_dir), resume_hdr.ttbr1_el1,
resume_hdr.reenter_kernel, restore_pblist,
resume_hdr.__hyp_stub_vectors, virt_to_phys(zero_page));
+ unreachable();
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0933/1518] arm64: hibernate: Restore DAIF state on error
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (931 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0932/1518] arm64: hibernate: mask DAIF before restoring hibernated kernel Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0934/1518] mfd: rave-sp: validate received frame payload lengths Greg Kroah-Hartman
` (65 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Vladimir Murzin, Jinjie Ruan,
Will Deacon, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Vladimir Murzin <vladimir.murzin@arm.com>
[ Upstream commit 541549827889d0380fd73f8aacb5de6ef7a5a1ac ]
Sashiko AI has reported that if swsusp_mte_save_tags() for some reason
fails we return from swsusp_arch_suspend() with DAIF being masked -
that is not what we'd expect. Restore the saved DAIF state before
returning from the error path.
Fixes: ee11f332af96 ("arm64: mte: Save tags when hibernating")
Signed-off-by: Vladimir Murzin <vladimir.murzin@arm.com>
Reviewed-by: Jinjie Ruan <ruanjinjie@huawei.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/kernel/hibernate.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/arch/arm64/kernel/hibernate.c b/arch/arm64/kernel/hibernate.c
index 1eb1c1074c5b0..7bf1174277772 100644
--- a/arch/arm64/kernel/hibernate.c
+++ b/arch/arm64/kernel/hibernate.c
@@ -348,8 +348,10 @@ int swsusp_arch_suspend(void)
crash_prepare_suspend();
ret = swsusp_mte_save_tags();
- if (ret)
+ if (ret) {
+ local_daif_restore(flags);
return ret;
+ }
sleep_cpu = smp_processor_id();
ret = swsusp_save();
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0934/1518] mfd: rave-sp: validate received frame payload lengths
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (932 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0933/1518] arm64: hibernate: Restore DAIF state on error Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0935/1518] mfd: iqs62x: Reject zero-length firmware records Greg Kroah-Hartman
` (64 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Lee Jones, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit 0be718b5451bd83865d6e2a8d750ca7886c4772a ]
A received RAVE-SP frame contains protocol data followed by a
variant-specific one- or two-byte checksum. rave_sp_receive_frame() derives
a checksum pointer before proving that the frame contains the checksum,
then passes the checksum-inclusive length to handlers that index the
command, acknowledgment ID and event-data bytes or derive a reply payload
length.
Name those protocol field offsets, prove the checksum extent before
deriving the protocol-data length, pass only that data length to the
handlers, and require the complete event or reply prefix before consuming
it.
Fixes: 538ee27290fa ("mfd: Add driver for RAVE Supervisory Processor")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://lore.kernel.org/all/20260706092337.78754-1-pengpeng@iscas.ac.cn/
Link: https://patch.msgid.link/20260720115523.99956-1-pengpeng@iscas.ac.cn
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/mfd/rave-sp.c | 64 +++++++++++++++++++++++++++++--------------
1 file changed, 44 insertions(+), 20 deletions(-)
diff --git a/drivers/mfd/rave-sp.c b/drivers/mfd/rave-sp.c
index c1b78d127a261..05d26d92df03e 100644
--- a/drivers/mfd/rave-sp.c
+++ b/drivers/mfd/rave-sp.c
@@ -63,6 +63,12 @@
#define RAVE_SP_TX_BUFFER_SIZE \
(RAVE_SP_STX_ETX_SIZE + 2 * RAVE_SP_RX_BUFFER_SIZE)
+enum rave_sp_frame_offset {
+ RAVE_SP_FRAME_CODE_OFFSET,
+ RAVE_SP_FRAME_ACK_ID_OFFSET,
+ RAVE_SP_FRAME_DATA_OFFSET,
+};
+
/**
* enum rave_sp_deframer_state - Possible state for de-framer
*
@@ -352,7 +358,7 @@ int rave_sp_exec(struct rave_sp *sp,
int command, ret = 0;
u8 ackid;
- command = sp->variant->cmd.translate(data[0]);
+ command = sp->variant->cmd.translate(data[RAVE_SP_FRAME_CODE_OFFSET]);
if (command < 0)
return command;
@@ -366,8 +372,8 @@ int rave_sp_exec(struct rave_sp *sp,
sp->reply = &reply;
mutex_unlock(&sp->reply_lock);
- data[0] = command;
- data[1] = ackid;
+ data[RAVE_SP_FRAME_CODE_OFFSET] = command;
+ data[RAVE_SP_FRAME_ACK_ID_OFFSET] = ackid;
rave_sp_write(sp, data, data_size);
@@ -388,16 +394,23 @@ EXPORT_SYMBOL_GPL(rave_sp_exec);
static void rave_sp_receive_event(struct rave_sp *sp,
const unsigned char *data, size_t length)
{
- u8 cmd[] = {
- [0] = rave_sp_reply_code(data[0]),
- [1] = data[1],
- };
+ unsigned long action;
+ u8 cmd[RAVE_SP_FRAME_DATA_OFFSET];
+
+ if (length < RAVE_SP_FRAME_DATA_OFFSET + 1) {
+ dev_warn(&sp->serdev->dev, "Dropping short event frame\n");
+ return;
+ }
+
+ cmd[RAVE_SP_FRAME_CODE_OFFSET] =
+ rave_sp_reply_code(data[RAVE_SP_FRAME_CODE_OFFSET]);
+ cmd[RAVE_SP_FRAME_ACK_ID_OFFSET] = data[RAVE_SP_FRAME_ACK_ID_OFFSET];
rave_sp_write(sp, cmd, sizeof(cmd));
- blocking_notifier_call_chain(&sp->event_notifier_list,
- rave_sp_action_pack(data[0], data[2]),
- NULL);
+ action = rave_sp_action_pack(data[RAVE_SP_FRAME_CODE_OFFSET],
+ data[RAVE_SP_FRAME_DATA_OFFSET]);
+ blocking_notifier_call_chain(&sp->event_notifier_list, action, NULL);
}
static void rave_sp_receive_reply(struct rave_sp *sp,
@@ -405,27 +418,35 @@ static void rave_sp_receive_reply(struct rave_sp *sp,
{
struct device *dev = &sp->serdev->dev;
struct rave_sp_reply *reply;
- const size_t payload_length = length - 2;
+ size_t payload_length;
+
+ if (length < RAVE_SP_FRAME_DATA_OFFSET) {
+ dev_warn(dev, "Dropping short reply frame\n");
+ return;
+ }
+ payload_length = length - RAVE_SP_FRAME_DATA_OFFSET;
mutex_lock(&sp->reply_lock);
reply = sp->reply;
if (reply) {
- if (reply->code == data[0] && reply->ackid == data[1] &&
+ if (reply->code == data[RAVE_SP_FRAME_CODE_OFFSET] &&
+ reply->ackid == data[RAVE_SP_FRAME_ACK_ID_OFFSET] &&
payload_length >= reply->length) {
/*
* We are relying on memcpy(dst, src, 0) to be a no-op
* when handling commands that have a no-payload reply
*/
- memcpy(reply->data, &data[2], reply->length);
+ memcpy(reply->data, &data[RAVE_SP_FRAME_DATA_OFFSET],
+ reply->length);
complete(&reply->received);
sp->reply = NULL;
} else {
dev_err(dev, "Ignoring incorrect reply\n");
dev_dbg(dev, "Code: expected = 0x%08x received = 0x%08x\n",
- reply->code, data[0]);
+ reply->code, data[RAVE_SP_FRAME_CODE_OFFSET]);
dev_dbg(dev, "ACK ID: expected = 0x%08x received = 0x%08x\n",
- reply->ackid, data[1]);
+ reply->ackid, data[RAVE_SP_FRAME_ACK_ID_OFFSET]);
dev_dbg(dev, "Length: expected = %zu received = %zu\n",
reply->length, payload_length);
}
@@ -439,10 +460,10 @@ static void rave_sp_receive_frame(struct rave_sp *sp,
size_t length)
{
const size_t checksum_length = sp->variant->checksum->length;
- const size_t payload_length = length - checksum_length;
- const u8 *crc_reported = &data[payload_length];
struct device *dev = &sp->serdev->dev;
u8 crc_calculated[RAVE_SP_CHECKSUM_SIZE];
+ const u8 *crc_reported;
+ size_t payload_length;
if (unlikely(checksum_length > sizeof(crc_calculated))) {
dev_warn(dev, "Checksum too long, dropping\n");
@@ -457,6 +478,9 @@ static void rave_sp_receive_frame(struct rave_sp *sp,
return;
}
+ payload_length = length - checksum_length;
+ crc_reported = &data[payload_length];
+
sp->variant->checksum->subroutine(data, payload_length,
crc_calculated);
@@ -465,10 +489,10 @@ static void rave_sp_receive_frame(struct rave_sp *sp,
return;
}
- if (rave_sp_id_is_event(data[0]))
- rave_sp_receive_event(sp, data, length);
+ if (rave_sp_id_is_event(data[RAVE_SP_FRAME_CODE_OFFSET]))
+ rave_sp_receive_event(sp, data, payload_length);
else
- rave_sp_receive_reply(sp, data, length);
+ rave_sp_receive_reply(sp, data, payload_length);
}
static size_t rave_sp_receive_buf(struct serdev_device *serdev,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0935/1518] mfd: iqs62x: Reject zero-length firmware records
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (933 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0934/1518] mfd: rave-sp: validate received frame payload lengths Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0936/1518] mfd: macsmc: Fix key count endianness annotation Greg Kroah-Hartman
` (63 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Pengpeng Hou, Lee Jones, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Pengpeng Hou <pengpeng@iscas.ac.cn>
[ Upstream commit 08ea045e0b82cbcadb7a2efc43a23561489a00f2 ]
struct iqs62x_fw_rec includes the first data byte in its fixed-size header,
so the parser advances by len - 1 bytes after that header. A zero len makes
the size_t cursor update move back by one byte, so the next record overlaps
the current record instead of following a valid declared extent.
Reject zero-length records and express the remaining-size check without an
offset addition.
Fixes: 4d9cf7df8d35 ("mfd: Add support for Azoteq IQS620A/621/622/624/625")
Signed-off-by: Pengpeng Hou <pengpeng@iscas.ac.cn>
Link: https://lore.kernel.org/all/20260706091034.75865-1-pengpeng@iscas.ac.cn/
Link: https://patch.msgid.link/20260720115423.94994-1-pengpeng@iscas.ac.cn
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/mfd/iqs62x.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/mfd/iqs62x.c b/drivers/mfd/iqs62x.c
index ee017617d1d1b..412ae7777f729 100644
--- a/drivers/mfd/iqs62x.c
+++ b/drivers/mfd/iqs62x.c
@@ -237,7 +237,7 @@ static int iqs62x_firmware_parse(struct iqs62x_core *iqs62x,
fw_rec = (struct iqs62x_fw_rec *)(fw->data + pos);
pos += sizeof(*fw_rec);
- if (pos + fw_rec->len - 1 > fw->size) {
+ if (!fw_rec->len || fw_rec->len - 1 > fw->size - pos) {
ret = -EINVAL;
break;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0936/1518] mfd: macsmc: Fix key count endianness annotation
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (934 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0935/1518] mfd: iqs62x: Reject zero-length firmware records Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0937/1518] gpiolib: move legacy interface into linux/gpio/legacy.h Greg Kroah-Hartman
` (62 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, kernel test robot, Sven Peter,
Janne Grunau, Joshua Peisach, Lee Jones, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Sven Peter <sven@kernel.org>
[ Upstream commit 0a29aa605286bcd01632eb6b61f59b9053312347 ]
SMC firmware returns the value of the #KEY key in big-endian unlike most
other keys. Reading it through apple_smc_read_u32() into a plain u32
and then converting with be32_to_cpu() makes sparse complain:
drivers/mfd/macsmc.c:462:26: sparse: cast to restricted __be32
Read the raw value into a __be32 using apple_smc_read() instead.
Fixes: e038d985c982 ("mfd: Add Apple Silicon System Management Controller")
Reported-by: kernel test robot <lkp@intel.com>
Closes: https://lore.kernel.org/oe-kbuild-all/202607181046.OANjIoqR-lkp@intel.com/
Signed-off-by: Sven Peter <sven@kernel.org>
Reviewed-by: Janne Grunau <j@jannau.net>
Reviewed-by: Joshua Peisach <jpeisach@ubuntu.com>
Link: https://patch.msgid.link/20260719-b4-macsmc-be32-fix-v1-1-c7b1936307fa@kernel.org
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/mfd/macsmc.c | 8 +++++---
1 file changed, 5 insertions(+), 3 deletions(-)
diff --git a/drivers/mfd/macsmc.c b/drivers/mfd/macsmc.c
index 3228e79c86eb5..90c434c9215bb 100644
--- a/drivers/mfd/macsmc.c
+++ b/drivers/mfd/macsmc.c
@@ -406,7 +406,7 @@ static int apple_smc_probe(struct platform_device *pdev)
{
struct device *dev = &pdev->dev;
struct apple_smc *smc;
- u32 count;
+ __be32 count;
int ret;
smc = devm_kzalloc(dev, sizeof(*smc), GFP_KERNEL);
@@ -457,8 +457,10 @@ static int apple_smc_probe(struct platform_device *pdev)
dev_set_drvdata(&pdev->dev, smc);
BLOCKING_INIT_NOTIFIER_HEAD(&smc->event_handlers);
- ret = apple_smc_read_u32(smc, SMC_KEY(#KEY), &count);
- if (ret)
+ ret = apple_smc_read(smc, SMC_KEY(#KEY), &count, sizeof(count));
+ if (ret >= 0 && ret != sizeof(count))
+ ret = -EINVAL;
+ if (ret < 0)
return dev_err_probe(smc->dev, ret, "Failed to get key count");
smc->key_count = be32_to_cpu(count);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0937/1518] gpiolib: move legacy interface into linux/gpio/legacy.h
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (935 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0936/1518] mfd: macsmc: Fix key count endianness annotation Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0938/1518] leds: gpio: Make legacy gpiolib interface optional Greg Kroah-Hartman
` (61 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Arnd Bergmann, Bartosz Golaszewski,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnd Bergmann <arnd@arndb.de>
[ Upstream commit bfdc854ba63bc815cf710701f889544a9d27df83 ]
Split the old contents from gpio.h for clarity. Ideally any driver
that still includes linux/gpio.h can now be ported over to use
either linux/gpio/legacy.h or linux/gpio/consumer.h, with the
original file getting removed once that is complete.
No functional changes intended for now.
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Link: https://patch.msgid.link/20260428154522.2861492-1-arnd@kernel.org
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Stable-dep-of: 942901eeda93 ("leds: gpio: Clear error pointers for skipped LEDs")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
include/linux/gpio.h | 162 +--------------------------------
include/linux/gpio/legacy.h | 173 ++++++++++++++++++++++++++++++++++++
2 files changed, 177 insertions(+), 158 deletions(-)
create mode 100644 include/linux/gpio/legacy.h
diff --git a/include/linux/gpio.h b/include/linux/gpio.h
index 8f85ddb264295..b0d4942a65de2 100644
--- a/include/linux/gpio.h
+++ b/include/linux/gpio.h
@@ -2,13 +2,11 @@
/*
* NOTE: This header *must not* be included.
*
- * This is the LEGACY GPIO bulk include file, including legacy APIs. It is
- * used for GPIO drivers still referencing the global GPIO numberspace,
- * and should not be included in new code.
- *
* If you're implementing a GPIO driver, only include <linux/gpio/driver.h>
* If you're implementing a GPIO consumer, only include <linux/gpio/consumer.h>
+ * If you're using the legacy interfaces, include <linux/gpio/legacy.h>
*/
+
#ifndef __LINUX_GPIO_H
#define __LINUX_GPIO_H
@@ -18,159 +16,7 @@
#endif
#ifdef CONFIG_GPIOLIB_LEGACY
-
-struct device;
-
-/* make these flag values available regardless of GPIO kconfig options */
-#define GPIOF_IN ((1 << 0))
-#define GPIOF_OUT_INIT_LOW ((0 << 0) | (0 << 1))
-#define GPIOF_OUT_INIT_HIGH ((0 << 0) | (1 << 1))
-
-#ifdef CONFIG_GPIOLIB
-/*
- * "valid" GPIO numbers are nonnegative and may be passed to
- * setup routines like gpio_request(). Only some valid numbers
- * can successfully be requested and used.
- *
- * Invalid GPIO numbers are useful for indicating no-such-GPIO in
- * platform data and other tables.
- */
-static inline bool gpio_is_valid(int number)
-{
- /* only non-negative numbers are valid */
- return number >= 0;
-}
-
-/*
- * Platforms may implement their GPIO interface with library code,
- * at a small performance cost for non-inlined operations and some
- * extra memory (for code and for per-GPIO table entries).
- */
-
-/* Always use the library code for GPIO management calls,
- * or when sleeping may be involved.
- */
-int gpio_request(unsigned gpio, const char *label);
-void gpio_free(unsigned gpio);
-
-static inline int gpio_direction_input(unsigned gpio)
-{
- return gpiod_direction_input(gpio_to_desc(gpio));
-}
-static inline int gpio_direction_output(unsigned gpio, int value)
-{
- return gpiod_direction_output_raw(gpio_to_desc(gpio), value);
-}
-
-static inline int gpio_get_value_cansleep(unsigned gpio)
-{
- return gpiod_get_raw_value_cansleep(gpio_to_desc(gpio));
-}
-static inline void gpio_set_value_cansleep(unsigned gpio, int value)
-{
- gpiod_set_raw_value_cansleep(gpio_to_desc(gpio), value);
-}
-
-static inline int gpio_get_value(unsigned gpio)
-{
- return gpiod_get_raw_value(gpio_to_desc(gpio));
-}
-static inline void gpio_set_value(unsigned gpio, int value)
-{
- gpiod_set_raw_value(gpio_to_desc(gpio), value);
-}
-
-static inline int gpio_to_irq(unsigned gpio)
-{
- return gpiod_to_irq(gpio_to_desc(gpio));
-}
-
-int gpio_request_one(unsigned gpio, unsigned long flags, const char *label);
-
-int devm_gpio_request_one(struct device *dev, unsigned gpio,
- unsigned long flags, const char *label);
-
-#else /* ! CONFIG_GPIOLIB */
-
-#include <linux/kernel.h>
-
-#include <asm/bug.h>
-#include <asm/errno.h>
-
-static inline bool gpio_is_valid(int number)
-{
- return false;
-}
-
-static inline int gpio_request(unsigned gpio, const char *label)
-{
- return -ENOSYS;
-}
-
-static inline int gpio_request_one(unsigned gpio,
- unsigned long flags, const char *label)
-{
- return -ENOSYS;
-}
-
-static inline void gpio_free(unsigned gpio)
-{
- might_sleep();
-
- /* GPIO can never have been requested */
- WARN_ON(1);
-}
-
-static inline int gpio_direction_input(unsigned gpio)
-{
- return -ENOSYS;
-}
-
-static inline int gpio_direction_output(unsigned gpio, int value)
-{
- return -ENOSYS;
-}
-
-static inline int gpio_get_value(unsigned gpio)
-{
- /* GPIO can never have been requested or set as {in,out}put */
- WARN_ON(1);
- return 0;
-}
-
-static inline void gpio_set_value(unsigned gpio, int value)
-{
- /* GPIO can never have been requested or set as output */
- WARN_ON(1);
-}
-
-static inline int gpio_get_value_cansleep(unsigned gpio)
-{
- /* GPIO can never have been requested or set as {in,out}put */
- WARN_ON(1);
- return 0;
-}
-
-static inline void gpio_set_value_cansleep(unsigned gpio, int value)
-{
- /* GPIO can never have been requested or set as output */
- WARN_ON(1);
-}
-
-static inline int gpio_to_irq(unsigned gpio)
-{
- /* GPIO can never have been requested or set as input */
- WARN_ON(1);
- return -EINVAL;
-}
-
-static inline int devm_gpio_request_one(struct device *dev, unsigned gpio,
- unsigned long flags, const char *label)
-{
- WARN_ON(1);
- return -EINVAL;
-}
-
-#endif /* ! CONFIG_GPIOLIB */
+#include <linux/gpio/legacy.h>
#endif /* CONFIG_GPIOLIB_LEGACY */
+
#endif /* __LINUX_GPIO_H */
diff --git a/include/linux/gpio/legacy.h b/include/linux/gpio/legacy.h
new file mode 100644
index 0000000000000..557ef635935ea
--- /dev/null
+++ b/include/linux/gpio/legacy.h
@@ -0,0 +1,173 @@
+/* SPDX-License-Identifier: GPL-2.0 */
+/*
+ * This is the LEGACY GPIO include file, used only for legacy APIs.
+ *
+ * No new code should use this, but instead use the linux/gpio/consumer.h
+ * interfaces directly.
+ */
+
+#ifndef __LINUX_GPIO_LEGACY_H
+#define __LINUX_GPIO_LEGACY_H
+
+#include <linux/types.h>
+
+#ifdef CONFIG_GPIOLIB_LEGACY
+
+struct device;
+
+/* make these flag values available regardless of GPIO kconfig options */
+#define GPIOF_IN ((1 << 0))
+#define GPIOF_OUT_INIT_LOW ((0 << 0) | (0 << 1))
+#define GPIOF_OUT_INIT_HIGH ((0 << 0) | (1 << 1))
+
+#ifdef CONFIG_GPIOLIB
+
+#include <linux/gpio/consumer.h>
+
+/*
+ * "valid" GPIO numbers are nonnegative and may be passed to
+ * setup routines like gpio_request(). Only some valid numbers
+ * can successfully be requested and used.
+ *
+ * Invalid GPIO numbers are useful for indicating no-such-GPIO in
+ * platform data and other tables.
+ */
+static inline bool gpio_is_valid(int number)
+{
+ /* only non-negative numbers are valid */
+ return number >= 0;
+}
+
+/*
+ * Platforms may implement their GPIO interface with library code,
+ * at a small performance cost for non-inlined operations and some
+ * extra memory (for code and for per-GPIO table entries).
+ */
+
+/* Always use the library code for GPIO management calls,
+ * or when sleeping may be involved.
+ */
+int gpio_request(unsigned gpio, const char *label);
+void gpio_free(unsigned gpio);
+
+static inline int gpio_direction_input(unsigned gpio)
+{
+ return gpiod_direction_input(gpio_to_desc(gpio));
+}
+static inline int gpio_direction_output(unsigned gpio, int value)
+{
+ return gpiod_direction_output_raw(gpio_to_desc(gpio), value);
+}
+
+static inline int gpio_get_value_cansleep(unsigned gpio)
+{
+ return gpiod_get_raw_value_cansleep(gpio_to_desc(gpio));
+}
+static inline void gpio_set_value_cansleep(unsigned gpio, int value)
+{
+ gpiod_set_raw_value_cansleep(gpio_to_desc(gpio), value);
+}
+
+static inline int gpio_get_value(unsigned gpio)
+{
+ return gpiod_get_raw_value(gpio_to_desc(gpio));
+}
+static inline void gpio_set_value(unsigned gpio, int value)
+{
+ gpiod_set_raw_value(gpio_to_desc(gpio), value);
+}
+
+static inline int gpio_to_irq(unsigned gpio)
+{
+ return gpiod_to_irq(gpio_to_desc(gpio));
+}
+
+int gpio_request_one(unsigned gpio, unsigned long flags, const char *label);
+
+int devm_gpio_request_one(struct device *dev, unsigned gpio,
+ unsigned long flags, const char *label);
+
+#else /* ! CONFIG_GPIOLIB */
+
+#include <linux/kernel.h>
+
+#include <asm/bug.h>
+#include <asm/errno.h>
+
+static inline bool gpio_is_valid(int number)
+{
+ return false;
+}
+
+static inline int gpio_request(unsigned gpio, const char *label)
+{
+ return -ENOSYS;
+}
+
+static inline int gpio_request_one(unsigned gpio,
+ unsigned long flags, const char *label)
+{
+ return -ENOSYS;
+}
+
+static inline void gpio_free(unsigned gpio)
+{
+ might_sleep();
+
+ /* GPIO can never have been requested */
+ WARN_ON(1);
+}
+
+static inline int gpio_direction_input(unsigned gpio)
+{
+ return -ENOSYS;
+}
+
+static inline int gpio_direction_output(unsigned gpio, int value)
+{
+ return -ENOSYS;
+}
+
+static inline int gpio_get_value(unsigned gpio)
+{
+ /* GPIO can never have been requested or set as {in,out}put */
+ WARN_ON(1);
+ return 0;
+}
+
+static inline void gpio_set_value(unsigned gpio, int value)
+{
+ /* GPIO can never have been requested or set as output */
+ WARN_ON(1);
+}
+
+static inline int gpio_get_value_cansleep(unsigned gpio)
+{
+ /* GPIO can never have been requested or set as {in,out}put */
+ WARN_ON(1);
+ return 0;
+}
+
+static inline void gpio_set_value_cansleep(unsigned gpio, int value)
+{
+ /* GPIO can never have been requested or set as output */
+ WARN_ON(1);
+}
+
+static inline int gpio_to_irq(unsigned gpio)
+{
+ /* GPIO can never have been requested or set as input */
+ WARN_ON(1);
+ return -EINVAL;
+}
+
+static inline int devm_gpio_request_one(struct device *dev, unsigned gpio,
+ unsigned long flags, const char *label)
+{
+ WARN_ON(1);
+ return -EINVAL;
+}
+
+#endif /* ! CONFIG_GPIOLIB */
+#endif /* CONFIG_GPIOLIB_LEGACY */
+#endif /* __LINUX_GPIO_LEGAGY_H */
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0938/1518] leds: gpio: Make legacy gpiolib interface optional
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (936 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0937/1518] gpiolib: move legacy interface into linux/gpio/legacy.h Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0939/1518] leds: gpio: Clear error pointers for skipped LEDs Greg Kroah-Hartman
` (60 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Arnd Bergmann, Linus Walleij,
Bartosz Golaszewski, Andy Shevchenko, Lee Jones, Sasha Levin,
Dmitry Torokhov
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Arnd Bergmann <arnd@arndb.de>
[ Upstream commit 98c5c7b0d4269ecabfc86b8b49ffcfa47979e99d ]
There are still a handful of ancient mips/armv5/sh boards that use the
gpio_led:gpio member to pass an old-style gpio number, but all modern
users have been converted to gpio descriptors.
While the CONFIG_GPIOLIB_LEGACY option that guards devm_gpio_request_one()
and related helpers is currently turned on in all kernel builds,
the plan is to only enable it on the few platforms that actually
pass gpio numbers in any platform_data.
Split out the legacy portion of the platform_data handling into a custom
helper function that is guarded with in #ifdef block, to allow the
the leds-gpio driver to compile cleanly when CONFIG_GPIOLIB_LEGACY
gets turned off. Once the last user is converted, this function can
be removed.
Link: https://lore.kernel.org/all/e9252384-a55c-4a91-9c61-06e05a0b2ce4@app.fastmail.com/
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
Reviewed-by: Linus Walleij <linusw@kernel.org>
Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Reviewed-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
Acked-by: Dmitry Torokhov <dmitry.torokhov@gmail.com> # for input
Link: https://patch.msgid.link/20260710211854.1371746-4-arnd@kernel.org
Signed-off-by: Lee Jones <lee@kernel.org>
Stable-dep-of: 942901eeda93 ("leds: gpio: Clear error pointers for skipped LEDs")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/leds/leds-gpio.c | 52 +++++++++++++++++++++++++++-------------
include/linux/leds.h | 2 ++
2 files changed, 37 insertions(+), 17 deletions(-)
diff --git a/drivers/leds/leds-gpio.c b/drivers/leds/leds-gpio.c
index a3428b22de3a1..9cbcf7e40a159 100644
--- a/drivers/leds/leds-gpio.c
+++ b/drivers/leds/leds-gpio.c
@@ -9,8 +9,8 @@
#include <linux/container_of.h>
#include <linux/device.h>
#include <linux/err.h>
-#include <linux/gpio.h>
#include <linux/gpio/consumer.h>
+#include <linux/gpio/legacy.h>
#include <linux/leds.h>
#include <linux/mod_devicetable.h>
#include <linux/module.h>
@@ -212,7 +212,6 @@ static struct gpio_desc *gpio_led_get_gpiod(struct device *dev, int idx,
const struct gpio_led *template)
{
struct gpio_desc *gpiod;
- int ret;
/*
* This means the LED does not come from the device tree
@@ -223,16 +222,29 @@ static struct gpio_desc *gpio_led_get_gpiod(struct device *dev, int idx,
gpiod = devm_gpiod_get_index_optional(dev, NULL, idx, GPIOD_OUT_LOW);
if (IS_ERR(gpiod))
return gpiod;
- if (gpiod) {
- gpiod_set_consumer_name(gpiod, template->name);
- return gpiod;
- }
- /*
- * This is the legacy code path for platform code that
- * still uses GPIO numbers. Ultimately we would like to get
- * rid of this block completely.
- */
+ gpiod_set_consumer_name(gpiod, template->name);
+ return gpiod;
+}
+
+#ifdef CONFIG_GPIOLIB_LEGACY
+/*
+ * This is the legacy code path for platform code that still uses
+ * GPIO numbers, mainly MIPS and SuperH board files.
+ * Ultimately we would like to get rid of this block completely.
+ *
+ * ppc44x-warp sets the template->gpiod directly instead of
+ * adding a lookup table or device properties. This is not
+ * much better.
+ */
+static struct gpio_desc *gpio_led_get_legacy_gpiod(struct device *dev, int idx,
+ const struct gpio_led *template)
+{
+ struct gpio_desc *gpiod;
+ int ret;
+
+ if (template->gpiod)
+ return template->gpiod;
/* skip leds that aren't available */
if (!gpio_is_valid(template->gpio))
@@ -252,6 +264,13 @@ static struct gpio_desc *gpio_led_get_gpiod(struct device *dev, int idx,
return gpiod;
}
+#else
+static struct gpio_desc *gpio_led_get_legacy_gpiod(struct device *dev, int idx,
+ const struct gpio_led *template)
+{
+ return template->gpiod ?: ERR_PTR(-ENOENT);
+}
+#endif
static int gpio_led_probe(struct platform_device *pdev)
{
@@ -270,14 +289,13 @@ static int gpio_led_probe(struct platform_device *pdev)
const struct gpio_led *template = &pdata->leds[i];
struct gpio_led_data *led_dat = &priv->leds[i];
- if (template->gpiod)
- led_dat->gpiod = template->gpiod;
- else
+ led_dat->gpiod = gpio_led_get_gpiod(dev, i, template);
+ if (!led_dat->gpiod)
led_dat->gpiod =
- gpio_led_get_gpiod(dev, i, template);
+ gpio_led_get_legacy_gpiod(dev, i, template);
if (IS_ERR(led_dat->gpiod)) {
- dev_info(dev, "Skipping unavailable LED gpio %d (%s)\n",
- template->gpio, template->name);
+ dev_info(dev, "Skipping unavailable LED gpio %s\n",
+ template->name);
continue;
}
diff --git a/include/linux/leds.h b/include/linux/leds.h
index b16b803cc1ac5..e646bffcd8e74 100644
--- a/include/linux/leds.h
+++ b/include/linux/leds.h
@@ -676,8 +676,10 @@ typedef int (*gpio_blink_set_t)(struct gpio_desc *desc, int state,
struct gpio_led {
const char *name;
const char *default_trigger;
+#ifdef CONFIG_GPIOLIB_LEGACY
unsigned gpio;
unsigned active_low : 1;
+#endif
unsigned retain_state_suspended : 1;
unsigned panic_indicator : 1;
unsigned default_state : 2;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0939/1518] leds: gpio: Clear error pointers for skipped LEDs
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (937 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0938/1518] leds: gpio: Make legacy gpiolib interface optional Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0940/1518] drm/amdgpu/gfx6: Fixup emit_cntxcntl() Greg Kroah-Hartman
` (59 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Lee Jones, Steve Dunnagan,
Linus Walleij, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Steve Dunnagan <sdunnaga@redhat.com>
[ Upstream commit 942901eeda934f1bebf2605a781155e9d6bc7f6e ]
gpio_led_get_gpiod() returns an error pointer when a platform-data
LED's GPIO is unavailable. gpio_led_probe() skips registration in that
case, but leaves the error pointer in led_dat->gpiod.
The skipped entry remains included in priv->num_leds. During shutdown,
gpio_led_shutdown() walks those entries and passes the error pointer to
gpio_led_set(), producing:
gpiod_set_value: invalid GPIO (errorpointer: -ENOENT)
Clear led_dat->gpiod before skipping the LED so skipped entries do not
retain error-valued descriptors.
Fixes: 45d4c6de4e49 ("leds: gpio: Try to lookup gpiod from device")
Suggested-by: Lee Jones <lee@kernel.org>
Assisted-by: ChatGPT:GPT-5.5-Thinking
Signed-off-by: Steve Dunnagan <sdunnaga@redhat.com>
Reviewed-by: Linus Walleij <linusw@kernel.org>
Link: https://patch.msgid.link/20260724180412.43150-1-sdunnaga@redhat.com
Signed-off-by: Lee Jones <lee@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/leds/leds-gpio.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/leds/leds-gpio.c b/drivers/leds/leds-gpio.c
index 9cbcf7e40a159..df7be79dbf242 100644
--- a/drivers/leds/leds-gpio.c
+++ b/drivers/leds/leds-gpio.c
@@ -296,6 +296,7 @@ static int gpio_led_probe(struct platform_device *pdev)
if (IS_ERR(led_dat->gpiod)) {
dev_info(dev, "Skipping unavailable LED gpio %s\n",
template->name);
+ led_dat->gpiod = NULL;
continue;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0940/1518] drm/amdgpu/gfx6: Fixup emit_cntxcntl()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (938 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0939/1518] leds: gpio: Clear error pointers for skipped LEDs Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0941/1518] ext4: fix spurious message about orphan cleanup on RO fs Greg Kroah-Hartman
` (58 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Timur Kristóf, Alex Deucher,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Timur Kristóf <timur.kristof@gmail.com>
[ Upstream commit 1edb323406aaf05739804d2faa2561f2d43bcd09 ]
Set bits on dword 2 like GFX7-8 except load_global_uconfig
which doesn't exist on GFX6.
Emit VS_PARTIAL_FLUSH before VGT_FLUSH like GFX7-8.
For reference see old PAL which explains the bit fields in
this register and that load_global_uconfig doesn't exist on GFX6
and also see gfx_v7_ring_emit_cntxcntl() for the GFX7 code
which this commit follows.
Fixes: 2cd46ad22383 ("drm/amdgpu: add graphic pipeline implementation for si v8")
Signed-off-by: Timur Kristóf <timur.kristof@gmail.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/amd/amdgpu/gfx_v6_0.c | 28 ++++++++++++++++++++-------
1 file changed, 21 insertions(+), 7 deletions(-)
diff --git a/drivers/gpu/drm/amd/amdgpu/gfx_v6_0.c b/drivers/gpu/drm/amd/amdgpu/gfx_v6_0.c
index 066cdf6863e11..8b2bb61ca6c92 100644
--- a/drivers/gpu/drm/amd/amdgpu/gfx_v6_0.c
+++ b/drivers/gpu/drm/amd/amdgpu/gfx_v6_0.c
@@ -1881,11 +1881,13 @@ static int gfx_v6_0_ring_test_ring(struct amdgpu_ring *ring)
return r;
}
-static void gfx_v6_0_ring_emit_vgt_flush(struct amdgpu_ring *ring)
+static void gfx_v6_0_ring_emit_event_write(struct amdgpu_ring *ring,
+ uint32_t event_type,
+ uint32_t event_index)
{
amdgpu_ring_write(ring, PACKET3(PACKET3_EVENT_WRITE, 0));
- amdgpu_ring_write(ring, EVENT_TYPE(VGT_FLUSH) |
- EVENT_INDEX(0));
+ amdgpu_ring_write(ring, EVENT_TYPE(event_type) |
+ EVENT_INDEX(event_index));
}
static void gfx_v6_0_ring_emit_fence(struct amdgpu_ring *ring, u64 addr,
@@ -2998,10 +3000,22 @@ static uint64_t gfx_v6_0_get_gpu_clock_counter(struct amdgpu_device *adev)
static void gfx_v6_ring_emit_cntxcntl(struct amdgpu_ring *ring, uint32_t flags)
{
- if (flags & AMDGPU_HAVE_CTX_SWITCH)
- gfx_v6_0_ring_emit_vgt_flush(ring);
+ u32 dw2 = 0x80000000; /* set load_enable otherwise this package is just NOPs */
+
+ if (flags & AMDGPU_HAVE_CTX_SWITCH) {
+ gfx_v6_0_ring_emit_event_write(ring, VS_PARTIAL_FLUSH, 4);
+ gfx_v6_0_ring_emit_event_write(ring, VGT_FLUSH, 0);
+
+ /* set load_global_config (load_global_uconfig doesn't exist on GFX6) */
+ dw2 |= 0x1;
+ /* set load_cs_sh_regs */
+ dw2 |= 0x01000000;
+ /* set load_per_context_state & load_gfx_sh_regs */
+ dw2 |= 0x10002;
+ }
+
amdgpu_ring_write(ring, PACKET3(PACKET3_CONTEXT_CONTROL, 1));
- amdgpu_ring_write(ring, 0x80000000);
+ amdgpu_ring_write(ring, dw2);
amdgpu_ring_write(ring, 0);
}
@@ -3529,7 +3543,7 @@ static const struct amdgpu_ring_funcs gfx_v6_0_ring_funcs_gfx = {
14 + 14 + 14 + /* gfx_v6_0_ring_emit_fence x3 for user fence, vm fence */
7 + 4 + /* gfx_v6_0_ring_emit_pipeline_sync */
SI_FLUSH_GPU_TLB_NUM_WREG * 5 + 7 + 6 + /* gfx_v6_0_ring_emit_vm_flush */
- 3 + 2 + /* gfx_v6_ring_emit_cntxcntl including vgt flush */
+ 3 + 2 + 2 + /* gfx_v6_ring_emit_cntxcntl including VGT flush */
5, /* SURFACE_SYNC */
.emit_ib_size = 6, /* gfx_v6_0_ring_emit_ib */
.emit_ib = gfx_v6_0_ring_emit_ib,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0941/1518] ext4: fix spurious message about orphan cleanup on RO fs
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (939 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0940/1518] drm/amdgpu/gfx6: Fixup emit_cntxcntl() Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0942/1518] arm64: dts: ti: k3-am64: Fix MDIO clock reference for ICSSG0 node Greg Kroah-Hartman
` (57 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tigran Aivazian, Jan Kara, Baokun Li,
Theodore Tso, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Jan Kara <jack@suse.cz>
[ Upstream commit 5aa98f874c013bcce9bb84ffded2f0ef886e4e33 ]
When orphan_file feature is enabled, ext4_orphan_cleanup() was always
walking through the orphan file looking for orphan inodes. This is
mostly harmless but for read-only filesystem it results in spurious
"orphan cleanup on readonly fs" message and in other cornercases it
could result in similar somewhat misleading messages. Skip orphan
cleanup if the orphan file is empty to avoid confusing messages.
Fixes: 02f310fcf47f ("ext4: Speedup ext4 orphan inode handling")
Reported-by: Tigran Aivazian <aivazian.tigran@gmail.com>
Signed-off-by: Jan Kara <jack@suse.cz>
Reviewed-by: Baokun Li <libaokun@linux.alibaba.com>
Link: https://patch.msgid.link/20260803160037.64285-2-jack@suse.cz
Signed-off-by: Theodore Ts'o <tytso@mit.edu>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/ext4/orphan.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/fs/ext4/orphan.c b/fs/ext4/orphan.c
index 89c24c4f97846..47289d17152b8 100644
--- a/fs/ext4/orphan.c
+++ b/fs/ext4/orphan.c
@@ -388,7 +388,7 @@ void ext4_orphan_cleanup(struct super_block *sb, struct ext4_super_block *es)
struct ext4_orphan_info *oi = &EXT4_SB(sb)->s_orphan_info;
int inodes_per_ob = ext4_inodes_per_orphan_block(sb);
- if (!es->s_last_orphan && !oi->of_blocks) {
+ if (!es->s_last_orphan && ext4_orphan_file_empty(sb)) {
ext4_debug("no orphan inodes to clean up\n");
return;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0942/1518] arm64: dts: ti: k3-am64: Fix MDIO clock reference for ICSSG0 node
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (940 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0941/1518] ext4: fix spurious message about orphan cleanup on RO fs Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0943/1518] phy: renesas: rcar-gen3-usb2: Factor out VBUS control logic Greg Kroah-Hartman
` (56 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Meghana Malladi, Vignesh Raghavendra,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Meghana Malladi <m-malladi@ti.com>
[ Upstream commit 197df050a10fe216971b45a79f07195c86a02236 ]
MDIO clock index changed from 62:3 to 81:0 to match proper clock
definition in the SoC device tree. Clock Id 81:0 belongs to ICSSG0
core clock, where as 62 belongs to EQEP2 device.
See: https://software-dl.ti.com/tisci/esd/latest/5_soc_doc/am64x/clocks.html
Fixes: c9087e3898a1d0 ("arm64: dts: ti: k3-am64-main: Add ICSSG nodes")
Signed-off-by: Meghana Malladi <m-malladi@ti.com>
Link: https://patch.msgid.link/20260706092229.82674-1-m-malladi@ti.com
Signed-off-by: Vignesh Raghavendra <vigneshr@ti.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/boot/dts/ti/k3-am64-main.dtsi | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/arm64/boot/dts/ti/k3-am64-main.dtsi b/arch/arm64/boot/dts/ti/k3-am64-main.dtsi
index d872cc671094f..b7e5de3669ad6 100644
--- a/arch/arm64/boot/dts/ti/k3-am64-main.dtsi
+++ b/arch/arm64/boot/dts/ti/k3-am64-main.dtsi
@@ -1401,7 +1401,7 @@ tx_pru0_1: txpru@c000 {
icssg0_mdio: mdio@32400 {
compatible = "ti,davinci_mdio";
reg = <0x32400 0x100>;
- clocks = <&k3_clks 62 3>;
+ clocks = <&k3_clks 81 0>;
clock-names = "fck";
#address-cells = <1>;
#size-cells = <0>;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0943/1518] phy: renesas: rcar-gen3-usb2: Factor out VBUS control logic
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (941 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0942/1518] arm64: dts: ti: k3-am64: Fix MDIO clock reference for ICSSG0 node Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0944/1518] phy: renesas: rcar-gen3-usb2: Add regulator for OTG VBUS control Greg Kroah-Hartman
` (55 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tommaso Merciai, Vinod Koul,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tommaso Merciai <tommaso.merciai.xr@bp.renesas.com>
[ Upstream commit d6db3b3af74a26b65d1ec1e86f9738c784e7ae29 ]
Refactor the VBUS control logic into a new helper function to improve
code clarity and reduce duplication. This makes it easier to handle
different VBUS control register cases and aids future maintenance.
Signed-off-by: Tommaso Merciai <tommaso.merciai.xr@bp.renesas.com>
Link: https://patch.msgid.link/2d94c9876b965bdf7cd74cdbbc0c54689e122798.1766405010.git.tommaso.merciai.xr@bp.renesas.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Stable-dep-of: 49c9b71b4508 ("phy: renesas: phy-rcar-gen3-usb2: Fix devm action registration for disabled VBUS regulator")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/phy/renesas/phy-rcar-gen3-usb2.c | 34 +++++++++++++++---------
1 file changed, 22 insertions(+), 12 deletions(-)
diff --git a/drivers/phy/renesas/phy-rcar-gen3-usb2.c b/drivers/phy/renesas/phy-rcar-gen3-usb2.c
index a38ead7c8055d..d4588a936f92d 100644
--- a/drivers/phy/renesas/phy-rcar-gen3-usb2.c
+++ b/drivers/phy/renesas/phy-rcar-gen3-usb2.c
@@ -203,28 +203,38 @@ static void rcar_gen3_set_linectrl(struct rcar_gen3_chan *ch, int dp, int dm)
writel(val, usb2_base + USB2_LINECTRL1);
}
-static void rcar_gen3_enable_vbus_ctrl(struct rcar_gen3_chan *ch, int vbus)
+static void rcar_gen3_phy_usb2_set_vbus(struct rcar_gen3_chan *ch,
+ u32 vbus_ctrl_reg,
+ u32 vbus_ctrl_val,
+ bool enable)
{
void __iomem *usb2_base = ch->base;
- u32 vbus_ctrl_reg = USB2_ADPCTRL;
- u32 vbus_ctrl_val = USB2_ADPCTRL_DRVVBUS;
u32 val;
+ val = readl(usb2_base + vbus_ctrl_reg);
+ if (enable)
+ val |= vbus_ctrl_val;
+ else
+ val &= ~vbus_ctrl_val;
+ writel(val, usb2_base + vbus_ctrl_reg);
+
+ dev_vdbg(ch->dev, "%s: reg=0x%08x, val=%08x, enable=%d\n",
+ __func__, vbus_ctrl_reg, val, enable);
+}
+
+static void rcar_gen3_enable_vbus_ctrl(struct rcar_gen3_chan *ch, int vbus)
+{
if (ch->phy_data->no_adp_ctrl || ch->phy_data->vblvl_ctrl) {
if (ch->vbus)
regulator_hardware_enable(ch->vbus, vbus);
- vbus_ctrl_reg = USB2_VBCTRL;
- vbus_ctrl_val = USB2_VBCTRL_VBOUT;
+ rcar_gen3_phy_usb2_set_vbus(ch, USB2_VBCTRL,
+ USB2_VBCTRL_VBOUT, vbus);
+ return;
}
- val = readl(usb2_base + vbus_ctrl_reg);
- if (vbus)
- val |= vbus_ctrl_val;
- else
- val &= ~vbus_ctrl_val;
- dev_vdbg(ch->dev, "%s: %08x, %d\n", __func__, val, vbus);
- writel(val, usb2_base + vbus_ctrl_reg);
+ rcar_gen3_phy_usb2_set_vbus(ch, USB2_ADPCTRL,
+ USB2_ADPCTRL_DRVVBUS, vbus);
}
static void rcar_gen3_control_otg_irq(struct rcar_gen3_chan *ch, int enable)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0944/1518] phy: renesas: rcar-gen3-usb2: Add regulator for OTG VBUS control
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (942 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0943/1518] phy: renesas: rcar-gen3-usb2: Factor out VBUS control logic Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0945/1518] phy: renesas: phy-rcar-gen3-usb2: Fix devm action registration for disabled VBUS regulator Greg Kroah-Hartman
` (54 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tommaso Merciai, Vinod Koul,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tommaso Merciai <tommaso.merciai.xr@bp.renesas.com>
[ Upstream commit b6d7dd157763e0c8937f60241fb4af9eb546a7fb ]
Enable OTG VBUS control on R-Car Gen3 USB2 PHY by registering a regulator
driver that manages the VBOUT line. This change allows the controller to
handle VBUS output for OTG ports using the regulator framework when the
platform requires hardware-based VBUS control.
Without this, some platforms cannot properly manage VBUS power on OTG-
capable ports, leading to potential USB functionality issues.
Signed-off-by: Tommaso Merciai <tommaso.merciai.xr@bp.renesas.com>
Link: https://patch.msgid.link/6c1aebf60b4d8ff0c51a8243c68b397c1a384867.1766405010.git.tommaso.merciai.xr@bp.renesas.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Stable-dep-of: 49c9b71b4508 ("phy: renesas: phy-rcar-gen3-usb2: Fix devm action registration for disabled VBUS regulator")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/phy/renesas/phy-rcar-gen3-usb2.c | 142 ++++++++++++++++++++++-
1 file changed, 137 insertions(+), 5 deletions(-)
diff --git a/drivers/phy/renesas/phy-rcar-gen3-usb2.c b/drivers/phy/renesas/phy-rcar-gen3-usb2.c
index d4588a936f92d..03ea292bbfd4c 100644
--- a/drivers/phy/renesas/phy-rcar-gen3-usb2.c
+++ b/drivers/phy/renesas/phy-rcar-gen3-usb2.c
@@ -22,6 +22,7 @@
#include <linux/platform_device.h>
#include <linux/pm_runtime.h>
#include <linux/regulator/consumer.h>
+#include <linux/regulator/driver.h>
#include <linux/reset.h>
#include <linux/string.h>
#include <linux/usb/of.h>
@@ -140,6 +141,7 @@ struct rcar_gen3_chan {
bool extcon_host;
bool is_otg_channel;
bool uses_otg_pins;
+ bool otg_internal_reg;
};
struct rcar_gen3_phy_drv_data {
@@ -224,6 +226,11 @@ static void rcar_gen3_phy_usb2_set_vbus(struct rcar_gen3_chan *ch,
static void rcar_gen3_enable_vbus_ctrl(struct rcar_gen3_chan *ch, int vbus)
{
+ if (ch->otg_internal_reg) {
+ regulator_hardware_enable(ch->vbus, vbus);
+ return;
+ }
+
if (ch->phy_data->no_adp_ctrl || ch->phy_data->vblvl_ctrl) {
if (ch->vbus)
regulator_hardware_enable(ch->vbus, vbus);
@@ -592,7 +599,7 @@ static int rcar_gen3_phy_usb2_power_on(struct phy *p)
u32 val;
int ret = 0;
- if (channel->vbus) {
+ if (channel->vbus && !channel->otg_internal_reg) {
ret = regulator_enable(channel->vbus);
if (ret)
return ret;
@@ -633,7 +640,7 @@ static int rcar_gen3_phy_usb2_power_off(struct phy *p)
}
}
- if (channel->vbus)
+ if (channel->vbus && !channel->otg_internal_reg)
ret = regulator_disable(channel->vbus);
return ret;
@@ -819,6 +826,128 @@ static int rcar_gen3_phy_usb2_init_bus(struct rcar_gen3_chan *channel)
return ret;
}
+static int rcar_gen3_phy_usb2_regulator_endisable(struct regulator_dev *rdev,
+ bool enable)
+{
+ struct rcar_gen3_chan *channel = rdev_get_drvdata(rdev);
+ struct device *dev = channel->dev;
+ int ret;
+
+ ret = pm_runtime_resume_and_get(dev);
+ if (ret < 0) {
+ dev_warn(dev, "pm_runtime_get failed: %i\n", ret);
+ return ret;
+ }
+
+ rcar_gen3_phy_usb2_set_vbus(channel, USB2_VBCTRL,
+ USB2_VBCTRL_VBOUT, enable);
+ pm_runtime_put_noidle(dev);
+
+ return ret;
+}
+
+static int rcar_gen3_phy_usb2_regulator_enable(struct regulator_dev *rdev)
+{
+ return rcar_gen3_phy_usb2_regulator_endisable(rdev, true);
+}
+
+static int rcar_gen3_phy_usb2_regulator_disable(struct regulator_dev *rdev)
+{
+ return rcar_gen3_phy_usb2_regulator_endisable(rdev, false);
+}
+
+static int rcar_gen3_phy_usb2_regulator_is_enabled(struct regulator_dev *rdev)
+{
+ struct rcar_gen3_chan *channel = rdev_get_drvdata(rdev);
+ void __iomem *usb2_base = channel->base;
+ struct device *dev = channel->dev;
+ u32 vbus_ctrl_reg = USB2_VBCTRL;
+ u32 val;
+ int ret;
+
+ ret = pm_runtime_resume_and_get(dev);
+ if (ret < 0) {
+ dev_warn(dev, "pm_runtime_get failed: %i\n", ret);
+ return ret;
+ }
+
+ val = readl(usb2_base + vbus_ctrl_reg);
+
+ pm_runtime_put_noidle(dev);
+ dev_dbg(channel->dev, "%s: %08x\n", __func__, val);
+
+ return (val & USB2_VBCTRL_VBOUT) ? 1 : 0;
+}
+
+static const struct regulator_ops rcar_gen3_phy_usb2_regulator_ops = {
+ .enable = rcar_gen3_phy_usb2_regulator_enable,
+ .disable = rcar_gen3_phy_usb2_regulator_disable,
+ .is_enabled = rcar_gen3_phy_usb2_regulator_is_enabled,
+};
+
+static const struct regulator_desc rcar_gen3_phy_usb2_regulator = {
+ .name = "otg-vbus-regulator",
+ .of_match = of_match_ptr("vbus-regulator"),
+ .ops = &rcar_gen3_phy_usb2_regulator_ops,
+ .type = REGULATOR_VOLTAGE,
+ .owner = THIS_MODULE,
+ .fixed_uV = 5000000,
+ .n_voltages = 1,
+};
+
+static void rcar_gen3_phy_usb2_vbus_disable_action(void *data)
+{
+ struct regulator *vbus = data;
+
+ regulator_disable(vbus);
+}
+
+static int rcar_gen3_phy_usb2_vbus_regulator_get_exclusive_enable(struct rcar_gen3_chan *channel,
+ bool enable)
+{
+ struct device *dev = channel->dev;
+ int ret;
+
+ channel->vbus = devm_regulator_get_exclusive(dev, "vbus");
+ if (IS_ERR(channel->vbus))
+ return PTR_ERR(channel->vbus);
+
+ if (!enable)
+ return 0;
+
+ ret = regulator_enable(channel->vbus);
+ if (ret)
+ return ret;
+
+ return devm_add_action_or_reset(dev, rcar_gen3_phy_usb2_vbus_disable_action,
+ channel->vbus);
+}
+
+static int rcar_gen3_phy_usb2_vbus_regulator_register(struct rcar_gen3_chan *channel)
+{
+ struct device *dev = channel->dev;
+ struct regulator_config rcfg = { .dev = dev, };
+ struct regulator_dev *rdev;
+ bool enable = false;
+
+ rcfg.of_node = of_get_available_child_by_name(dev->of_node,
+ "vbus-regulator");
+ if (rcfg.of_node) {
+ rcfg.driver_data = channel;
+ rdev = devm_regulator_register(dev, &rcar_gen3_phy_usb2_regulator,
+ &rcfg);
+ of_node_put(rcfg.of_node);
+ if (IS_ERR(rdev))
+ return dev_err_probe(dev, PTR_ERR(rdev),
+ "Failed to create vbus-regulator\n");
+
+ channel->otg_internal_reg = true;
+ enable = true;
+ }
+
+ return rcar_gen3_phy_usb2_vbus_regulator_get_exclusive_enable(channel, enable);
+}
+
static int rcar_gen3_phy_usb2_probe(struct platform_device *pdev)
{
struct device *dev = &pdev->dev;
@@ -891,10 +1020,13 @@ static int rcar_gen3_phy_usb2_probe(struct platform_device *pdev)
phy_set_drvdata(channel->rphys[i].phy, &channel->rphys[i]);
}
- if (channel->phy_data->no_adp_ctrl && channel->is_otg_channel)
- channel->vbus = devm_regulator_get_exclusive(dev, "vbus");
- else
+ if (channel->phy_data->no_adp_ctrl && channel->is_otg_channel) {
+ ret = rcar_gen3_phy_usb2_vbus_regulator_register(channel);
+ if (ret)
+ return ret;
+ } else {
channel->vbus = devm_regulator_get_optional(dev, "vbus");
+ }
if (IS_ERR(channel->vbus)) {
if (PTR_ERR(channel->vbus) == -EPROBE_DEFER) {
ret = PTR_ERR(channel->vbus);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0945/1518] phy: renesas: phy-rcar-gen3-usb2: Fix devm action registration for disabled VBUS regulator
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (943 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0944/1518] phy: renesas: rcar-gen3-usb2: Add regulator for OTG VBUS control Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0946/1518] phy: sunplus: fix error handling in sp_uphy_init() Greg Kroah-Hartman
` (53 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Biju Das, Vinod Koul, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Biju Das <biju.das.jz@bp.renesas.com>
[ Upstream commit 49c9b71b45081e5e5eeb507a2d6edb80d332dc59 ]
devm_regulator_get_exclusive() initialises the regulator with
enable_count = 1, requiring the consumer to disable it before release.
The devm disable action was previously only registered when the caller
explicitly requested enable, so when the regulator was left in its initial
enabled state without an explicit enable call, the cleanup path skipped
decrementing enable_count, triggering a WARN_ON during regulator
release on device removal.
Fix this by always registering the devm disable action based on the actual
enabled state via regulator_is_enabled(), regardless of whether the
caller requested an explicit enable. This covers both the explicitly
enabled case and the initial state set by devm_regulator_get_exclusive().
Fixes: 24843404efe4 ("phy: renesas: phy-rcar-gen3-usb2: Control VBUS for RZ/G2L SoCs")
Signed-off-by: Biju Das <biju.das.jz@bp.renesas.com>
Link: https://patch.msgid.link/20260806102236.149159-9-biju.das.jz@bp.renesas.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/phy/renesas/phy-rcar-gen3-usb2.c | 16 +++++++++-------
1 file changed, 9 insertions(+), 7 deletions(-)
diff --git a/drivers/phy/renesas/phy-rcar-gen3-usb2.c b/drivers/phy/renesas/phy-rcar-gen3-usb2.c
index 03ea292bbfd4c..547d61ccb85a4 100644
--- a/drivers/phy/renesas/phy-rcar-gen3-usb2.c
+++ b/drivers/phy/renesas/phy-rcar-gen3-usb2.c
@@ -912,15 +912,17 @@ static int rcar_gen3_phy_usb2_vbus_regulator_get_exclusive_enable(struct rcar_ge
if (IS_ERR(channel->vbus))
return PTR_ERR(channel->vbus);
- if (!enable)
- return 0;
+ if (enable) {
+ ret = regulator_enable(channel->vbus);
+ if (ret)
+ return ret;
+ }
- ret = regulator_enable(channel->vbus);
- if (ret)
- return ret;
+ if (regulator_is_enabled(channel->vbus))
+ return devm_add_action_or_reset(dev, rcar_gen3_phy_usb2_vbus_disable_action,
+ channel->vbus);
- return devm_add_action_or_reset(dev, rcar_gen3_phy_usb2_vbus_disable_action,
- channel->vbus);
+ return 0;
}
static int rcar_gen3_phy_usb2_vbus_regulator_register(struct rcar_gen3_chan *channel)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0946/1518] phy: sunplus: fix error handling in sp_uphy_init()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (944 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0945/1518] phy: renesas: phy-rcar-gen3-usb2: Fix devm action registration for disabled VBUS regulator Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0947/1518] phy: rockchip: phy-rockchip-inno-csidphy: fix rk1808 hsfreq table Greg Kroah-Hartman
` (52 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Felix Gu, Philipp Zabel, Vinod Koul,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Felix Gu <ustc.gu@gmail.com>
[ Upstream commit 8b2683bc4cc18c581b7cd24f227cbe61abca7f4d ]
Fix the error paths of sp_uphy_init() to undo exactly what each stage
did: return directly if clk_prepare_enable() fails, release only the clock
if reset_control_deassert() fails, and jump to err_reset if
update_disc_vol() fails so the clock and reset are not leaked.
Fixes: 99d9ccd97385 ("phy: usb: Add USB2.0 phy driver for Sunplus SP7021")
Signed-off-by: Felix Gu <ustc.gu@gmail.com>
Reviewed-by: Philipp Zabel <p.zabel@pengutronix.de>
Link: https://patch.msgid.link/20260803-sunplus-usb3-v1-1-5a562524c869@gmail.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/phy/sunplus/phy-sunplus-usb2.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
diff --git a/drivers/phy/sunplus/phy-sunplus-usb2.c b/drivers/phy/sunplus/phy-sunplus-usb2.c
index 637a5fbae6d9a..0ad4c7160d17c 100644
--- a/drivers/phy/sunplus/phy-sunplus-usb2.c
+++ b/drivers/phy/sunplus/phy-sunplus-usb2.c
@@ -116,11 +116,11 @@ static int sp_uphy_init(struct phy *phy)
ret = clk_prepare_enable(usbphy->phy_clk);
if (ret)
- goto err_clk;
+ return ret;
ret = reset_control_deassert(usbphy->rstc);
if (ret)
- goto err_reset;
+ goto err_clk;
/* Default value modification */
writel(HIGH_MASK_BITS | 0x4002, usbphy->moon4_regs + UPHY_CONTROL0);
@@ -129,7 +129,7 @@ static int sp_uphy_init(struct phy *phy)
/* disconnect voltage */
ret = update_disc_vol(usbphy);
if (ret < 0)
- return ret;
+ goto err_reset;
/* board uphy 0 internal register modification for tid certification */
val = readl(usbphy->phy_regs + CONFIG9);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0947/1518] phy: rockchip: phy-rockchip-inno-csidphy: fix rk1808 hsfreq table
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (945 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0946/1518] phy: sunplus: fix error handling in sp_uphy_init() Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0948/1518] perf trace-event: Fix buffer overflow in read_string() Greg Kroah-Hartman
` (51 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Michael Riesch, Gerald Loacker,
Vinod Koul, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Gerald Loacker <gerald.loacker@wolfvision.net>
[ Upstream commit 4fae43e33a7c10951fbdc6baf409d51bd66aaefb ]
The rk1808 hsfreq table capped at 2499 Mbps, preventing a data rate of
exactly 2500 Mbps. Extend the final entry to 2500 Mbps to support this
rate.
This is essential for RK3588 reusing this array and fully supporting
rates up to 2500 Mbps.
Fixes: bd1f775d6027 ("phy/rockchip: add Innosilicon-based CSI dphy")
Reviewed-by: Michael Riesch <michael.riesch@collabora.com>
Signed-off-by: Gerald Loacker <gerald.loacker@wolfvision.net>
Link: https://patch.msgid.link/20260725-feature-mipi-csi-dphy-4k60-v4-1-5b2c4626d31e@wolfvision.net
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/phy/rockchip/phy-rockchip-inno-csidphy.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/phy/rockchip/phy-rockchip-inno-csidphy.c b/drivers/phy/rockchip/phy-rockchip-inno-csidphy.c
index c79fb53d8ee5c..5281f8dea0ad3 100644
--- a/drivers/phy/rockchip/phy-rockchip-inno-csidphy.c
+++ b/drivers/phy/rockchip/phy-rockchip-inno-csidphy.c
@@ -170,7 +170,7 @@ static const struct hsfreq_range rk1808_mipidphy_hsfreq_ranges[] = {
{ 299, 0x06}, { 399, 0x08}, { 499, 0x0b}, { 599, 0x0e},
{ 699, 0x10}, { 799, 0x12}, { 999, 0x16}, {1199, 0x1e},
{1399, 0x23}, {1599, 0x2d}, {1799, 0x32}, {1999, 0x37},
- {2199, 0x3c}, {2399, 0x41}, {2499, 0x46}
+ {2199, 0x3c}, {2399, 0x41}, {2500, 0x46}
};
static const struct hsfreq_range rk3326_mipidphy_hsfreq_ranges[] = {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0948/1518] perf trace-event: Fix buffer overflow in read_string()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (946 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0947/1518] phy: rockchip: phy-rockchip-inno-csidphy: fix rk1808 hsfreq table Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0949/1518] drm/amdgpu/gfx6: Fixup emitting SWITCH_BUFFER packets Greg Kroah-Hartman
` (50 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tanushree Shah, Namhyung Kim,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tanushree Shah <tshah@linux.ibm.com>
[ Upstream commit 1121a7af1833f8b5723f1e32685b461614353d5d ]
read_string() writes into buf[BUFSIZ] one byte at a time without
checking 'size' against the buffer bound before each write. A
string longer than BUFSIZ in the input overflows the stack buffer.
Add a bounds check before each write to prevent overflow. On
overflow the function returns NULL, matching its other error paths.
Fixes: 9215545e99d8 ("perf: Convert perf tracing data into a tracing_data event")
Signed-off-by: Tanushree Shah <tshah@linux.ibm.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/trace-event-read.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/tools/perf/util/trace-event-read.c b/tools/perf/util/trace-event-read.c
index ecbbb93f01853..afd458cf1387d 100644
--- a/tools/perf/util/trace-event-read.c
+++ b/tools/perf/util/trace-event-read.c
@@ -127,6 +127,11 @@ static char *read_string(void)
}
}
+ if (size >= (int)sizeof(buf) - 1) {
+ pr_debug("string too long (max %zu bytes)", sizeof(buf) - 1);
+ goto out;
+ }
+
buf[size++] = c;
if (!c)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0949/1518] drm/amdgpu/gfx6: Fixup emitting SWITCH_BUFFER packets
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (947 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0948/1518] perf trace-event: Fix buffer overflow in read_string() Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0950/1518] drm/amdgpu/gfx6: Use PFP on the compute queues too Greg Kroah-Hartman
` (49 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Timur Kristóf, Alex Deucher,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Timur Kristóf <timur.kristof@gmail.com>
[ Upstream commit 7aac4242a11991d530eee3e141d6e445d5f11c22 ]
Implement the emit_switch_buffer() function instead of emitting
them duing emit_ib, emit_pipeline_sync and emit_vm_flush.
Note that it isn't necessary to emit these in both
emit_pipeline_sync() and emit_vm_flush() because
amdgpu_vm_flush() already calls these when calling
either of those functions.
Fixes: 2cd46ad22383 ("drm/amdgpu: add graphic pipeline implementation for si v8")
Signed-off-by: Timur Kristóf <timur.kristof@gmail.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/amd/amdgpu/gfx_v6_0.c | 38 ++++++++++-----------------
1 file changed, 14 insertions(+), 24 deletions(-)
diff --git a/drivers/gpu/drm/amd/amdgpu/gfx_v6_0.c b/drivers/gpu/drm/amd/amdgpu/gfx_v6_0.c
index 8b2bb61ca6c92..935610635bff0 100644
--- a/drivers/gpu/drm/amd/amdgpu/gfx_v6_0.c
+++ b/drivers/gpu/drm/amd/amdgpu/gfx_v6_0.c
@@ -1926,12 +1926,6 @@ static void gfx_v6_0_ring_emit_ib(struct amdgpu_ring *ring,
unsigned vmid = AMDGPU_JOB_GET_VMID(job);
u32 header, control = 0;
- /* insert SWITCH_BUFFER packet before first IB in the ring frame */
- if (flags & AMDGPU_HAVE_CTX_SWITCH) {
- amdgpu_ring_write(ring, PACKET3(PACKET3_SWITCH_BUFFER, 0));
- amdgpu_ring_write(ring, 0);
- }
-
if (ib->flags & AMDGPU_IB_FLAG_CE)
header = PACKET3(PACKET3_INDIRECT_BUFFER_CONST, 2);
else
@@ -2366,14 +2360,6 @@ static void gfx_v6_0_ring_emit_pipeline_sync(struct amdgpu_ring *ring)
amdgpu_ring_write(ring, seq);
amdgpu_ring_write(ring, 0xffffffff);
amdgpu_ring_write(ring, 4); /* poll interval */
-
- if (usepfp) {
- /* synce CE with ME to prevent CE fetch CEIB before context switch done */
- amdgpu_ring_write(ring, PACKET3(PACKET3_SWITCH_BUFFER, 0));
- amdgpu_ring_write(ring, 0);
- amdgpu_ring_write(ring, PACKET3(PACKET3_SWITCH_BUFFER, 0));
- amdgpu_ring_write(ring, 0);
- }
}
static void gfx_v6_0_ring_emit_vm_flush(struct amdgpu_ring *ring,
@@ -2397,12 +2383,6 @@ static void gfx_v6_0_ring_emit_vm_flush(struct amdgpu_ring *ring,
/* sync PFP to ME, otherwise we might get invalid PFP reads */
amdgpu_ring_write(ring, PACKET3(PACKET3_PFP_SYNC_ME, 0));
amdgpu_ring_write(ring, 0x0);
-
- /* synce CE with ME to prevent CE fetch CEIB before context switch done */
- amdgpu_ring_write(ring, PACKET3(PACKET3_SWITCH_BUFFER, 0));
- amdgpu_ring_write(ring, 0);
- amdgpu_ring_write(ring, PACKET3(PACKET3_SWITCH_BUFFER, 0));
- amdgpu_ring_write(ring, 0);
}
}
@@ -2998,6 +2978,12 @@ static uint64_t gfx_v6_0_get_gpu_clock_counter(struct amdgpu_device *adev)
return clock;
}
+static void gfx_v6_0_ring_emit_sb(struct amdgpu_ring *ring)
+{
+ amdgpu_ring_write(ring, PACKET3(PACKET3_SWITCH_BUFFER, 0));
+ amdgpu_ring_write(ring, 0);
+}
+
static void gfx_v6_ring_emit_cntxcntl(struct amdgpu_ring *ring, uint32_t flags)
{
u32 dw2 = 0x80000000; /* set load_enable otherwise this package is just NOPs */
@@ -3541,11 +3527,12 @@ static const struct amdgpu_ring_funcs gfx_v6_0_ring_funcs_gfx = {
.emit_frame_size =
5 + 5 + /* hdp flush / invalidate */
14 + 14 + 14 + /* gfx_v6_0_ring_emit_fence x3 for user fence, vm fence */
- 7 + 4 + /* gfx_v6_0_ring_emit_pipeline_sync */
- SI_FLUSH_GPU_TLB_NUM_WREG * 5 + 7 + 6 + /* gfx_v6_0_ring_emit_vm_flush */
+ 7 + /* gfx_v6_0_ring_emit_pipeline_sync */
+ SI_FLUSH_GPU_TLB_NUM_WREG * 5 + 7 + 2 + /* gfx_v6_0_ring_emit_vm_flush */
+ 3 * 2 + /* gfx_v6_0_ring_emit_sb x3 (from amdgpu_vm_flush, amdgpu_ib_schedule) */
3 + 2 + 2 + /* gfx_v6_ring_emit_cntxcntl including VGT flush */
5, /* SURFACE_SYNC */
- .emit_ib_size = 6, /* gfx_v6_0_ring_emit_ib */
+ .emit_ib_size = 4, /* gfx_v6_0_ring_emit_ib */
.emit_ib = gfx_v6_0_ring_emit_ib,
.emit_fence = gfx_v6_0_ring_emit_fence,
.emit_pipeline_sync = gfx_v6_0_ring_emit_pipeline_sync,
@@ -3553,6 +3540,7 @@ static const struct amdgpu_ring_funcs gfx_v6_0_ring_funcs_gfx = {
.test_ring = gfx_v6_0_ring_test_ring,
.test_ib = gfx_v6_0_ring_test_ib,
.insert_nop = amdgpu_ring_insert_nop,
+ .emit_switch_buffer = gfx_v6_0_ring_emit_sb,
.emit_cntxcntl = gfx_v6_ring_emit_cntxcntl,
.emit_wreg = gfx_v6_0_ring_emit_wreg,
.emit_mem_sync = gfx_v6_0_emit_mem_sync,
@@ -3570,8 +3558,9 @@ static const struct amdgpu_ring_funcs gfx_v6_0_ring_funcs_compute = {
7 + /* gfx_v6_0_ring_emit_pipeline_sync */
SI_FLUSH_GPU_TLB_NUM_WREG * 5 + 7 + /* gfx_v6_0_ring_emit_vm_flush */
14 + 14 + 14 + /* gfx_v6_0_ring_emit_fence x3 for user fence, vm fence */
+ 3 * 2 + /* gfx_v6_0_ring_emit_sb x3 (from amdgpu_vm_flush, amdgpu_ib_schedule) */
5, /* SURFACE_SYNC */
- .emit_ib_size = 6, /* gfx_v6_0_ring_emit_ib */
+ .emit_ib_size = 4, /* gfx_v6_0_ring_emit_ib */
.emit_ib = gfx_v6_0_ring_emit_ib,
.emit_fence = gfx_v6_0_ring_emit_fence,
.emit_pipeline_sync = gfx_v6_0_ring_emit_pipeline_sync,
@@ -3579,6 +3568,7 @@ static const struct amdgpu_ring_funcs gfx_v6_0_ring_funcs_compute = {
.test_ring = gfx_v6_0_ring_test_ring,
.test_ib = gfx_v6_0_ring_test_ib,
.insert_nop = amdgpu_ring_insert_nop,
+ .emit_switch_buffer = gfx_v6_0_ring_emit_sb,
.emit_wreg = gfx_v6_0_ring_emit_wreg,
.emit_mem_sync = gfx_v6_0_emit_mem_sync,
};
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0950/1518] drm/amdgpu/gfx6: Use PFP on the compute queues too
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (948 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0949/1518] drm/amdgpu/gfx6: Fixup emitting SWITCH_BUFFER packets Greg Kroah-Hartman
@ 2026-09-12 6:51 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0951/1518] scsi: qla2xxx: Remove redundant VPD flash read in sysfs read path Greg Kroah-Hartman
` (48 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:51 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Timur Kristóf, Alex Deucher,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Timur Kristóf <timur.kristof@gmail.com>
[ Upstream commit 60f20946cd318518ddc2c0da12103c666b2b9564 ]
On GFX6, the compute rings use the same CP path as
the graphics ring. The only difference is that they
don't support draw commands. (As opposed to GFX7 and
newer which have a separate command parser that is
called MEC for compute queues.)
This means that we have to take into consideration
that the PFP also exists on compute queues on GFX6:
Use PFP for register writes on both graphics and
compute queues.
In the pipeline sync, use the PFP to wait for the
previous fence (and not the ME) to prevent the PFP
from starting to execute the next submission while
the ME is still in the previous submission.
After a VM flush, emit PFP_SYNC_ME on compute
queues as well.
Fixes: 2cd46ad22383 ("drm/amdgpu: add graphic pipeline implementation for si v8")
Signed-off-by: Timur Kristóf <timur.kristof@gmail.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/gpu/drm/amd/amdgpu/gfx_v6_0.c | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/drivers/gpu/drm/amd/amdgpu/gfx_v6_0.c b/drivers/gpu/drm/amd/amdgpu/gfx_v6_0.c
index 935610635bff0..ef399fce3ef3e 100644
--- a/drivers/gpu/drm/amd/amdgpu/gfx_v6_0.c
+++ b/drivers/gpu/drm/amd/amdgpu/gfx_v6_0.c
@@ -2347,7 +2347,7 @@ static int gfx_v6_0_cp_resume(struct amdgpu_device *adev)
static void gfx_v6_0_ring_emit_pipeline_sync(struct amdgpu_ring *ring)
{
- int usepfp = (ring->funcs->type == AMDGPU_RING_TYPE_GFX);
+ int usepfp = 1;
uint32_t seq = ring->fence_drv.sync_seq;
uint64_t addr = ring->fence_drv.gpu_addr;
@@ -2365,7 +2365,7 @@ static void gfx_v6_0_ring_emit_pipeline_sync(struct amdgpu_ring *ring)
static void gfx_v6_0_ring_emit_vm_flush(struct amdgpu_ring *ring,
unsigned vmid, uint64_t pd_addr)
{
- int usepfp = (ring->funcs->type == AMDGPU_RING_TYPE_GFX);
+ int usepfp = 1;
amdgpu_gmc_emit_flush_gpu_tlb(ring, vmid, pd_addr);
@@ -2389,7 +2389,7 @@ static void gfx_v6_0_ring_emit_vm_flush(struct amdgpu_ring *ring,
static void gfx_v6_0_ring_emit_wreg(struct amdgpu_ring *ring,
uint32_t reg, uint32_t val)
{
- int usepfp = (ring->funcs->type == AMDGPU_RING_TYPE_GFX);
+ int usepfp = 1;
amdgpu_ring_write(ring, PACKET3(PACKET3_WRITE_DATA, 3));
amdgpu_ring_write(ring, (WRITE_DATA_ENGINE_SEL(usepfp) |
@@ -3556,7 +3556,7 @@ static const struct amdgpu_ring_funcs gfx_v6_0_ring_funcs_compute = {
.emit_frame_size =
5 + 5 + /* hdp flush / invalidate */
7 + /* gfx_v6_0_ring_emit_pipeline_sync */
- SI_FLUSH_GPU_TLB_NUM_WREG * 5 + 7 + /* gfx_v6_0_ring_emit_vm_flush */
+ SI_FLUSH_GPU_TLB_NUM_WREG * 5 + 7 + 2 + /* gfx_v6_0_ring_emit_vm_flush */
14 + 14 + 14 + /* gfx_v6_0_ring_emit_fence x3 for user fence, vm fence */
3 * 2 + /* gfx_v6_0_ring_emit_sb x3 (from amdgpu_vm_flush, amdgpu_ib_schedule) */
5, /* SURFACE_SYNC */
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0951/1518] scsi: qla2xxx: Remove redundant VPD flash read in sysfs read path
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (949 preceding siblings ...)
2026-09-12 6:51 ` [PATCH 6.18 0950/1518] drm/amdgpu/gfx6: Use PFP on the compute queues too Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0952/1518] firmware_loader: do not queue completed sysfs fallback requests Greg Kroah-Hartman
` (47 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Manish Rangankar, Nilesh Javali,
Hannes Reinecke, Martin K. Petersen (Oracle), Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Manish Rangankar <mrangankar@marvell.com>
[ Upstream commit 5cbc49d5c4cd20c18041e86958103045216d2190 ]
qla2x00_sysfs_read_vpd() called ha->isp_ops->read_optrom() a second time
after releasing optrom_mutex. The repeated read is redundant and, unlike
the first, runs without optrom_mutex held, exposing flash access to
concurrent optrom operations. Drop the duplicate call.
Fixes: 5fa8774c7f38 ("scsi: qla2xxx: Add 28xx flash primary/secondary status/image mechanism")
Signed-off-by: Manish Rangankar <mrangankar@marvell.com>
Signed-off-by: Nilesh Javali <njavali@marvell.com>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Link: https://patch.msgid.link/20260723050413.3897522-7-njavali@marvell.com
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/qla2xxx/qla_attr.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/drivers/scsi/qla2xxx/qla_attr.c b/drivers/scsi/qla2xxx/qla_attr.c
index b103e3b1056af..0768b3aad50b5 100644
--- a/drivers/scsi/qla2xxx/qla_attr.c
+++ b/drivers/scsi/qla2xxx/qla_attr.c
@@ -580,7 +580,6 @@ qla2x00_sysfs_read_vpd(struct file *filp, struct kobject *kobj,
ha->isp_ops->read_optrom(vha, ha->vpd, faddr, ha->vpd_size);
mutex_unlock(&ha->optrom_mutex);
- ha->isp_ops->read_optrom(vha, ha->vpd, faddr, ha->vpd_size);
skip:
return memory_read_from_buffer(buf, count, &off, ha->vpd, ha->vpd_size);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0952/1518] firmware_loader: do not queue completed sysfs fallback requests
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (950 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0951/1518] scsi: qla2xxx: Remove redundant VPD flash read in sysfs read path Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0953/1518] pinctrl: rockchip: Reset the pin count when recalculating SoC data Greg Kroah-Hartman
` (46 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mukesh Ojha, Danilo Krummrich,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
[ Upstream commit b48373c901951fad1a26bd7c33ad91172b3945b5 ]
fw_load_sysfs_fallback() calls device_add() before adding the fw_priv to
pending_fw_head. device_add() publishes the fallback loading interface, so
a userspace helper which discovers the device by scanning sysfs can write 0
to the loading attribute and complete the request before it is queued as
pending.
In that interleaving firmware_loading_store() calls fw_state_done() while
pending_list still points to itself, so it cannot remove an entry from
pending_fw_head. The subsequent unconditional list_add() then queues an
already-completed fw_priv. Once the request is released, pending_fw_head
can retain a pointer to freed memory and the next fallback request can
fault while validating the list.
Only in-flight fallback requests need suspend or reboot abort handling. If
the request is already DONE after device_add(), return success from the
fallback path without sending another uevent, waiting again, or queueing it
as pending. This preserves the invariant that pending_fw_head contains only
active fallback requests.
Fixes: 75d95e2e39b2 ("firmware_loader: fix use-after-free in firmware_fallback_sysfs")
Signed-off-by: Mukesh Ojha <mukesh.ojha@oss.qualcomm.com>
Link: https://patch.msgid.link/20260716081601.1674470-1-mukesh.ojha@oss.qualcomm.com
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/base/firmware_loader/fallback.c | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/drivers/base/firmware_loader/fallback.c b/drivers/base/firmware_loader/fallback.c
index 3ef0b312ae719..00d6b6e594616 100644
--- a/drivers/base/firmware_loader/fallback.c
+++ b/drivers/base/firmware_loader/fallback.c
@@ -95,6 +95,16 @@ static int fw_load_sysfs_fallback(struct fw_sysfs *fw_sysfs, long timeout)
retval = -EINTR;
goto out;
}
+
+ /*
+ * device_add() exposes the loading interface before pending_list is
+ * linked into pending_fw_head, so fw_state_done() may run first.
+ */
+ if (fw_state_is_done(fw_priv)) {
+ mutex_unlock(&fw_lock);
+ goto out;
+ }
+
list_add(&fw_priv->pending_list, &pending_fw_head);
mutex_unlock(&fw_lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0953/1518] pinctrl: rockchip: Reset the pin count when recalculating SoC data
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (951 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0952/1518] firmware_loader: do not queue completed sysfs fallback requests Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0954/1518] hugetlbfs: release subpool on fill_super failure Greg Kroah-Hartman
` (45 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Simon Glass, Linus Walleij,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Simon Glass <sjg@chromium.org>
[ Upstream commit 5b695c191cc85f0fd62eec885b55d01468dc9f2c ]
rockchip_pinctrl_get_soc_data() mutates the static per-SoC data. The
iomux and drive offsets are recalculated idempotently, since a rerun
anchors at the values calculated before, but the total pin count only
accumulates: each run adds every bank's pins again. When the probe is
deferred and runs a second time, nr_pins doubles and every bank's
pin_base shifts, so later pin lookups resolve to the wrong bank and
the wrong registers.
Reset the pin count at the start of the calculation, so that a rerun
produces the same values.
This is verified on a Luckfox Pico Mini B (RV1103, with the pending
RV1106 series applied) by forcing the probe to defer once: without
this patch the second probe calculates nr_pins=304 instead of 152 and
no GPIO bank comes up; with it the recalculation matches the first
run and all banks work.
Fixes: d3e5116119bd ("pinctrl: add pinctrl driver for Rockchip SoCs")
Link: https://sashiko.dev/#/patchset/20260729132736.3807082-1-sjg@chromium.org?part=4
Assisted-by: Claude:claude-opus-5
Signed-off-by: Simon Glass <sjg@chromium.org>
Signed-off-by: Linus Walleij <linusw@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/pinctrl/pinctrl-rockchip.c | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/drivers/pinctrl/pinctrl-rockchip.c b/drivers/pinctrl/pinctrl-rockchip.c
index f1cba3d2367a3..834229831de99 100644
--- a/drivers/pinctrl/pinctrl-rockchip.c
+++ b/drivers/pinctrl/pinctrl-rockchip.c
@@ -3675,6 +3675,16 @@ static struct rockchip_pin_ctrl *rockchip_pinctrl_get_soc_data(
pmu_offs = ctrl->pmu_mux_offset;
drv_pmu_offs = ctrl->pmu_drv_offset;
drv_grf_offs = ctrl->grf_drv_offset;
+
+ /*
+ * This function mutates the static per-SoC data. Most of it is
+ * idempotent: recalculated iomux and drv offsets anchor at the
+ * values calculated by a previous run. The pin count is not, so
+ * reset it here; otherwise it accumulates when the probe runs
+ * again after a probe deferral, shifting every bank's pin_base.
+ */
+ ctrl->nr_pins = 0;
+
bank = ctrl->pin_banks;
for (i = 0; i < ctrl->nr_banks; ++i, ++bank) {
int bank_pins = 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0954/1518] hugetlbfs: release subpool on fill_super failure
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (952 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0953/1518] pinctrl: rockchip: Reset the pin count when recalculating SoC data Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0955/1518] soc: fsl: qe: check platform_driver_register() in qe_ic_of_init() Greg Kroah-Hartman
` (44 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yichong Chen, David Hildenbrand,
Muchun Song, Oscar Salvador, Andrew Morton, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yichong Chen <chenyichong@uniontech.com>
[ Upstream commit 308ab73e97c87bd0e142b11758faab7f88d82854 ]
hugetlbfs_fill_super() allocates a hugepage subpool when size or min_size
mount options are specified. hugepage_new_subpool() may also reserve huge
pages for min_size.
If root dentry creation fails after the subpool is created, the failure
path frees the subpool with kfree(). This bypasses hugepage_put_subpool()
and can leave min_size reservations charged.
Use hugepage_put_subpool() on the failure path, matching the normal
put_super path.
Link: https://lore.kernel.org/20260720021900.1376309-1-chenyichong@uniontech.com
Fixes: 7ca02d0ae586 ("hugetlbfs: accept subpool min_size mount option and setup accordingly")
Signed-off-by: Yichong Chen <chenyichong@uniontech.com>
Cc: David Hildenbrand <david@kernel.org>
Cc: Muchun Song <muchun.song@linux.dev>
Cc: Oscar Salvador <osalvador@suse.de>
Signed-off-by: Andrew Morton <akpm@linux-foundation.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/hugetlbfs/inode.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/fs/hugetlbfs/inode.c b/fs/hugetlbfs/inode.c
index f42548ee9083c..34ed9966f2ea8 100644
--- a/fs/hugetlbfs/inode.c
+++ b/fs/hugetlbfs/inode.c
@@ -1433,7 +1433,8 @@ hugetlbfs_fill_super(struct super_block *sb, struct fs_context *fc)
goto out_free;
return 0;
out_free:
- kfree(sbinfo->spool);
+ if (sbinfo->spool)
+ hugepage_put_subpool(sbinfo->spool);
kfree(sbinfo);
return -ENOMEM;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0955/1518] soc: fsl: qe: check platform_driver_register() in qe_ic_of_init()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (953 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0954/1518] hugetlbfs: release subpool on fill_super failure Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0956/1518] phy: qcom-sgmii-eth: relax order of .power_on() vs .set_mode*() Greg Kroah-Hartman
` (43 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Linkai Gong, Maxim Kochetkov,
Christophe Leroy (CS GROUP), Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Linkai Gong <gonglinkai@kylinos.cn>
[ Upstream commit fbdba2a67fa7c0e7570bcbf9f28b782d6100270d ]
qe_ic_of_init() ignored the return value of platform_driver_register()
and always returned success. Propagate the error to the initcall.
Fixes: be7ecbd240b2 ("soc: fsl: qe: convert QE interrupt controller to platform_device")
Signed-off-by: Linkai Gong <gonglinkai@kylinos.cn>
Reviewed-by: Maxim Kochetkov <fido_max@inbox.ru>
Link: https://lore.kernel.org/r/20260731094608.1883391-1-gonglinkai@kylinos.cn
Signed-off-by: Christophe Leroy (CS GROUP) <chleroy@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/soc/fsl/qe/qe_ic.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/soc/fsl/qe/qe_ic.c b/drivers/soc/fsl/qe/qe_ic.c
index 943911053af68..bccc7d612009b 100644
--- a/drivers/soc/fsl/qe/qe_ic.c
+++ b/drivers/soc/fsl/qe/qe_ic.c
@@ -473,7 +473,6 @@ static struct platform_driver qe_ic_driver =
static int __init qe_ic_of_init(void)
{
- platform_driver_register(&qe_ic_driver);
- return 0;
+ return platform_driver_register(&qe_ic_driver);
}
subsys_initcall(qe_ic_of_init);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0956/1518] phy: qcom-sgmii-eth: relax order of .power_on() vs .set_mode*()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (954 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0955/1518] soc: fsl: qe: check platform_driver_register() in qe_ic_of_init() Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0957/1518] phy: qcom: sgmii-eth: vote for both voltage rails with correct current loads Greg Kroah-Hartman
` (42 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mohd Ayaan Anwar, Vinod Koul,
Vladimir Oltean, Russell King (Oracle), Jakub Kicinski,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Russell King (Oracle) <rmk+kernel@armlinux.org.uk>
[ Upstream commit ebe8b48b88ad012cf6067226e184e9173b7ea9d6 ]
Allow any order of the .power_on() and .set_mode*() methods as per the
recent discussion. This means phy_power_on() with this SerDes will now
restore the previous setup without requiring a subsequent
phy_set_mode*() call.
Tested-by: Mohd Ayaan Anwar <mohd.anwar@oss.qualcomm.com>
Acked-by: Vinod Koul <vkoul@kernel.org>
Reviewed-by: Vladimir Oltean <vladimir.oltean@nxp.com>
Signed-off-by: Russell King (Oracle) <rmk+kernel@armlinux.org.uk>
Link: https://patch.msgid.link/E1vxS4P-0000000BQXs-0vGB@rmk-PC.armlinux.org.uk
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 4f81684a1d10 ("phy: qcom: sgmii-eth: vote for both voltage rails with correct current loads")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/phy/qualcomm/phy-qcom-sgmii-eth.c | 14 +++++++++++++-
1 file changed, 13 insertions(+), 1 deletion(-)
diff --git a/drivers/phy/qualcomm/phy-qcom-sgmii-eth.c b/drivers/phy/qualcomm/phy-qcom-sgmii-eth.c
index 5b1c82459c126..d46a5e4df830a 100644
--- a/drivers/phy/qualcomm/phy-qcom-sgmii-eth.c
+++ b/drivers/phy/qualcomm/phy-qcom-sgmii-eth.c
@@ -267,8 +267,17 @@ static int qcom_dwmac_sgmii_phy_calibrate(struct phy *phy)
static int qcom_dwmac_sgmii_phy_power_on(struct phy *phy)
{
struct qcom_dwmac_sgmii_phy_data *data = phy_get_drvdata(phy);
+ int ret;
- return clk_prepare_enable(data->refclk);
+ ret = clk_prepare_enable(data->refclk);
+ if (ret < 0)
+ return ret;
+
+ ret = qcom_dwmac_sgmii_phy_calibrate(phy);
+ if (ret < 0)
+ clk_disable_unprepare(data->refclk);
+
+ return ret;
}
static int qcom_dwmac_sgmii_phy_power_off(struct phy *phy)
@@ -293,6 +302,9 @@ static int qcom_dwmac_sgmii_phy_set_speed(struct phy *phy, int speed)
if (speed != data->speed)
data->speed = speed;
+ if (phy->power_count == 0)
+ return 0;
+
return qcom_dwmac_sgmii_phy_calibrate(phy);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0957/1518] phy: qcom: sgmii-eth: vote for both voltage rails with correct current loads
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (955 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0956/1518] phy: qcom-sgmii-eth: relax order of .power_on() vs .set_mode*() Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0958/1518] phy: qcom: qmp-usb-legacy: Fix possible NULL-deref on early runtime suspend Greg Kroah-Hartman
` (41 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mohd Ayaan Anwar,
Manivannan Sadhasivam, Vinod Koul, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Mohd Ayaan Anwar <mohd.anwar@oss.qualcomm.com>
[ Upstream commit 4f81684a1d1018d7d0e5579f08d95e7701279358 ]
The SerDes PHY has two voltage supply rails, vdda-0p9 and vdda-1p2,
that must both be enabled for calibration to succeed. Without them:
qcom-dwmac-sgmii-phy 8909000.phy: QSERDES_COM_C_READY_STATUS timed-out
qcom-ethqos 23040000.ethernet eth0: __stmmac_open: Serdes powerup failed
The driver relied solely on the PHY framework's implicit enable of
'phy-supply', which only voted for a single rail and set no current
load. Use devm_regulator_bulk_get_const() to acquire both supplies and
set the peak current loads (46 mA for vdda-0p9, 15 mA for vdda-1p2)
as required by the hardware.
Fixes: 601d06277007 ("phy: qcom: add the SGMII SerDes PHY driver")
Signed-off-by: Mohd Ayaan Anwar <mohd.anwar@oss.qualcomm.com>
Reviewed-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Link: https://patch.msgid.link/20260804-b4-sgmiieth_serdes_regulator-v2-2-c4bc688177dd@oss.qualcomm.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/phy/qualcomm/phy-qcom-sgmii-eth.c | 37 ++++++++++++++++++++---
1 file changed, 33 insertions(+), 4 deletions(-)
diff --git a/drivers/phy/qualcomm/phy-qcom-sgmii-eth.c b/drivers/phy/qualcomm/phy-qcom-sgmii-eth.c
index d46a5e4df830a..8de0fba25ecff 100644
--- a/drivers/phy/qualcomm/phy-qcom-sgmii-eth.c
+++ b/drivers/phy/qualcomm/phy-qcom-sgmii-eth.c
@@ -10,6 +10,7 @@
#include <linux/phy/phy.h>
#include <linux/platform_device.h>
#include <linux/regmap.h>
+#include <linux/regulator/consumer.h>
#include "phy-qcom-qmp-pcs-sgmii.h"
#include "phy-qcom-qmp-qserdes-com-v5.h"
@@ -25,7 +26,15 @@
#define QSERDES_PCS_SGMIIPHY_READY BIT(7)
#define QSERDES_COM_C_PLL_LOCKED BIT(1)
+static const struct regulator_bulk_data qcom_dwmac_sgmii_phy_vregs[] = {
+ { .supply = "vdda-0p9", .init_load_uA = 46000 },
+ { .supply = "vdda-1p2", .init_load_uA = 15000 },
+};
+
+#define QCOM_SGMII_NUM_SUPPLIES ARRAY_SIZE(qcom_dwmac_sgmii_phy_vregs)
+
struct qcom_dwmac_sgmii_phy_data {
+ struct regulator_bulk_data *vregs;
struct regmap *regmap;
struct clk *refclk;
int speed;
@@ -269,13 +278,24 @@ static int qcom_dwmac_sgmii_phy_power_on(struct phy *phy)
struct qcom_dwmac_sgmii_phy_data *data = phy_get_drvdata(phy);
int ret;
- ret = clk_prepare_enable(data->refclk);
- if (ret < 0)
+ ret = regulator_bulk_enable(QCOM_SGMII_NUM_SUPPLIES, data->vregs);
+ if (ret)
return ret;
+ ret = clk_prepare_enable(data->refclk);
+ if (ret)
+ goto err_disable_regulators;
+
ret = qcom_dwmac_sgmii_phy_calibrate(phy);
- if (ret < 0)
- clk_disable_unprepare(data->refclk);
+ if (ret)
+ goto err_disable_clk;
+
+ return 0;
+
+err_disable_clk:
+ clk_disable_unprepare(data->refclk);
+err_disable_regulators:
+ regulator_bulk_disable(QCOM_SGMII_NUM_SUPPLIES, data->vregs);
return ret;
}
@@ -292,6 +312,8 @@ static int qcom_dwmac_sgmii_phy_power_off(struct phy *phy)
clk_disable_unprepare(data->refclk);
+ regulator_bulk_disable(QCOM_SGMII_NUM_SUPPLIES, data->vregs);
+
return 0;
}
@@ -331,6 +353,7 @@ static int qcom_dwmac_sgmii_phy_probe(struct platform_device *pdev)
struct phy_provider *provider;
void __iomem *base;
struct phy *phy;
+ int ret;
data = devm_kzalloc(dev, sizeof(*data), GFP_KERNEL);
if (!data)
@@ -355,6 +378,12 @@ static int qcom_dwmac_sgmii_phy_probe(struct platform_device *pdev)
if (IS_ERR(data->refclk))
return PTR_ERR(data->refclk);
+ ret = devm_regulator_bulk_get_const(dev, QCOM_SGMII_NUM_SUPPLIES,
+ qcom_dwmac_sgmii_phy_vregs,
+ &data->vregs);
+ if (ret)
+ return ret;
+
provider = devm_of_phy_provider_register(dev, of_phy_simple_xlate);
if (IS_ERR(provider))
return PTR_ERR(provider);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0958/1518] phy: qcom: qmp-usb-legacy: Fix possible NULL-deref on early runtime suspend
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (956 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0957/1518] phy: qcom: sgmii-eth: vote for both voltage rails with correct current loads Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0959/1518] phy: qcom: snps-femto-v2: " Greg Kroah-Hartman
` (40 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Abel Vesa, Dmitry Baryshkov,
Loic Poulain, Vinod Koul, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Loic Poulain <loic.poulain@oss.qualcomm.com>
[ Upstream commit 8e3687f7e18fe84372e86875709d56c37e7525a8 ]
There is a small window where the runtime suspend callback may run
after pm_runtime_enable() and before pm_runtime_forbid(). In this
case, a crash occurs because runtime suspend/resume dereferences
qmp->phy pointer, which is not yet initialized:
`if (!qmp->phy->init_count) {`
This can also happen if user re-enables runtime-pm via the sysfs
attribute before qmp phy is initialized.
Similarly to other qcom phy drivers, introduce a qmp->phy_initialized
variable that can be used to avoid relying on the possibly uninitialized
phy pointer.
Fixes: e464a3180a43 ("phy: qcom-qmp-usb: split off the legacy USB+dp_com support")
Reviewed-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Signed-off-by: Loic Poulain <loic.poulain@oss.qualcomm.com>
Link: https://patch.msgid.link/20260722-qcom-usb-phy-fix-null-v6-3-534f7e61b9a6@oss.qualcomm.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/phy/qualcomm/phy-qcom-qmp-usb-legacy.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
diff --git a/drivers/phy/qualcomm/phy-qcom-qmp-usb-legacy.c b/drivers/phy/qualcomm/phy-qcom-qmp-usb-legacy.c
index 8bf951b0490cf..fc490589c8e48 100644
--- a/drivers/phy/qualcomm/phy-qcom-qmp-usb-legacy.c
+++ b/drivers/phy/qualcomm/phy-qcom-qmp-usb-legacy.c
@@ -542,6 +542,8 @@ struct qmp_usb {
enum phy_mode mode;
+ bool phy_initialized;
+
struct phy *phy;
struct clk_fixed_rate pipe_clk_fixed;
@@ -895,6 +897,7 @@ static int qmp_usb_legacy_power_off(struct phy *phy)
static int qmp_usb_legacy_enable(struct phy *phy)
{
+ struct qmp_usb *qmp = phy_get_drvdata(phy);
int ret;
ret = qmp_usb_legacy_init(phy);
@@ -904,14 +907,19 @@ static int qmp_usb_legacy_enable(struct phy *phy)
ret = qmp_usb_legacy_power_on(phy);
if (ret)
qmp_usb_legacy_exit(phy);
+ else
+ qmp->phy_initialized = true;
return ret;
}
static int qmp_usb_legacy_disable(struct phy *phy)
{
+ struct qmp_usb *qmp = phy_get_drvdata(phy);
int ret;
+ qmp->phy_initialized = false;
+
ret = qmp_usb_legacy_power_off(phy);
if (ret)
return ret;
@@ -988,7 +996,7 @@ static int __maybe_unused qmp_usb_legacy_runtime_suspend(struct device *dev)
dev_vdbg(dev, "Suspending QMP phy, mode:%d\n", qmp->mode);
- if (!qmp->phy->init_count) {
+ if (!qmp->phy_initialized) {
dev_vdbg(dev, "PHY not initialized, bailing out\n");
return 0;
}
@@ -1009,7 +1017,7 @@ static int __maybe_unused qmp_usb_legacy_runtime_resume(struct device *dev)
dev_vdbg(dev, "Resuming QMP phy, mode:%d\n", qmp->mode);
- if (!qmp->phy->init_count) {
+ if (!qmp->phy_initialized) {
dev_vdbg(dev, "PHY not initialized, bailing out\n");
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0959/1518] phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (957 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0958/1518] phy: qcom: qmp-usb-legacy: Fix possible NULL-deref on early runtime suspend Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0960/1518] phy: qcom: qmp-usb: " Greg Kroah-Hartman
` (39 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dmitry Baryshkov, Konrad Dybcio,
Abel Vesa, Loic Poulain, Vinod Koul, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Loic Poulain <loic.poulain@oss.qualcomm.com>
[ Upstream commit c271a6926ea7d3c9566b033d63fd4e8c488dc860 ]
Runtime PM must be enabled before creating the PHY, since phy_create()
only enables runtime PM on the PHY device if it is already enabled on
this parent device. However, the runtime PM callbacks dereference the
hsphy instance, which is not yet ready, leaving a window where a suspend
callback may trigger a NULL pointer dereference.
Take a runtime PM usage reference with pm_runtime_get_noresume() before
enabling runtime PM and release it once the PHY has been created, so that
no runtime suspend can run before the PHY is ready. This also prevents a
short window where an unnecessary runtime suspend can occur.
Use the devres-managed version to ensure PM runtime is symmetrically
disabled during driver removal for proper cleanup.
Fixes: 0d75f508a9d5 ("phy: qcom-snps: Add runtime suspend and resume handlers")
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Reviewed-by: Abel Vesa <abel.vesa@oss.qualcomm.com>
Signed-off-by: Loic Poulain <loic.poulain@oss.qualcomm.com>
Link: https://patch.msgid.link/20260722-qcom-usb-phy-fix-null-v6-5-534f7e61b9a6@oss.qualcomm.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/phy/qualcomm/phy-qcom-snps-femto-v2.c | 26 ++++++++++++++-----
1 file changed, 20 insertions(+), 6 deletions(-)
diff --git a/drivers/phy/qualcomm/phy-qcom-snps-femto-v2.c b/drivers/phy/qualcomm/phy-qcom-snps-femto-v2.c
index eb0b0f61d98e0..980ad1fb1e2e3 100644
--- a/drivers/phy/qualcomm/phy-qcom-snps-femto-v2.c
+++ b/drivers/phy/qualcomm/phy-qcom-snps-femto-v2.c
@@ -599,8 +599,18 @@ static int qcom_snps_hsphy_probe(struct platform_device *pdev)
return dev_err_probe(dev, ret,
"failed to get regulator supplies\n");
+ /*
+ * Enable runtime PM before creating the PHY, phy_create() only enables
+ * it on the PHY device if already enabled on the parent. Hold a usage
+ * reference so callbacks cannot run before the PHY is ready.
+ */
+ pm_runtime_get_noresume(dev);
pm_runtime_set_active(dev);
- pm_runtime_enable(dev);
+ ret = devm_pm_runtime_enable(dev);
+ if (ret) {
+ pm_runtime_put_noidle(dev);
+ return ret;
+ }
/*
* Prevent runtime pm from being ON by default. Users can enable
* it using power/control in sysfs.
@@ -611,6 +621,7 @@ static int qcom_snps_hsphy_probe(struct platform_device *pdev)
if (IS_ERR(generic_phy)) {
ret = PTR_ERR(generic_phy);
dev_err(dev, "failed to create phy, %d\n", ret);
+ pm_runtime_put_noidle(dev);
return ret;
}
hsphy->phy = generic_phy;
@@ -620,12 +631,15 @@ static int qcom_snps_hsphy_probe(struct platform_device *pdev)
qcom_snps_hsphy_read_override_param_seq(dev);
phy_provider = devm_of_phy_provider_register(dev, of_phy_simple_xlate);
- if (!IS_ERR(phy_provider))
- dev_dbg(dev, "Registered Qcom-SNPS HS phy\n");
- else
- pm_runtime_disable(dev);
+ if (IS_ERR(phy_provider)) {
+ pm_runtime_put_noidle(dev);
+ return PTR_ERR(phy_provider);
+ }
- return PTR_ERR_OR_ZERO(phy_provider);
+ dev_dbg(dev, "Registered Qcom-SNPS HS phy\n");
+ pm_runtime_put(dev);
+
+ return 0;
}
static struct platform_driver qcom_snps_hsphy_driver = {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0960/1518] phy: qcom: qmp-usb: Fix possible NULL-deref on early runtime suspend
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (958 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0959/1518] phy: qcom: snps-femto-v2: " Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0961/1518] phy: qcom: qmp-pcie: Add pcs_lane1 offset to V5 offsets Greg Kroah-Hartman
` (38 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Loic Poulain, Vinod Koul,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Loic Poulain <loic.poulain@oss.qualcomm.com>
[ Upstream commit 142c5593379273264474f31d5956b1a0065cd576 ]
There is a small window where the runtime suspend callback may run
after pm_runtime_enable() and before pm_runtime_forbid(). In this
case, a crash occurs because runtime suspend/resume dereferences
qmp->phy pointer, which is not yet initialized:
`if (!qmp->phy->init_count) {`
This can also happen if user re-enables runtime-pm via the sysfs
attribute before qmp phy is initialized.
Similarly to other qcom phy drivers, introduce a qmp->phy_initialized
variable that can be used to avoid relying on the possibly uninitialized
phy pointer.
Fixes: e464a3180a43 ("phy: qcom-qmp-usb: split off the legacy USB+dp_com support")
Signed-off-by: Loic Poulain <loic.poulain@oss.qualcomm.com>
Link: https://patch.msgid.link/20260722-qcom-usb-phy-fix-null-v6-6-534f7e61b9a6@oss.qualcomm.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/phy/qualcomm/phy-qcom-qmp-usb.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)
diff --git a/drivers/phy/qualcomm/phy-qcom-qmp-usb.c b/drivers/phy/qualcomm/phy-qcom-qmp-usb.c
index ed646a7e705ba..e7dd140ad29e7 100644
--- a/drivers/phy/qualcomm/phy-qcom-qmp-usb.c
+++ b/drivers/phy/qualcomm/phy-qcom-qmp-usb.c
@@ -1300,6 +1300,8 @@ struct qmp_usb {
enum phy_mode mode;
+ bool phy_initialized;
+
struct phy *phy;
struct clk_fixed_rate pipe_clk_fixed;
@@ -1848,6 +1850,7 @@ static int qmp_usb_power_off(struct phy *phy)
static int qmp_usb_enable(struct phy *phy)
{
+ struct qmp_usb *qmp = phy_get_drvdata(phy);
int ret;
ret = qmp_usb_init(phy);
@@ -1857,14 +1860,19 @@ static int qmp_usb_enable(struct phy *phy)
ret = qmp_usb_power_on(phy);
if (ret)
qmp_usb_exit(phy);
+ else
+ qmp->phy_initialized = true;
return ret;
}
static int qmp_usb_disable(struct phy *phy)
{
+ struct qmp_usb *qmp = phy_get_drvdata(phy);
int ret;
+ qmp->phy_initialized = false;
+
ret = qmp_usb_power_off(phy);
if (ret)
return ret;
@@ -1940,7 +1948,7 @@ static int __maybe_unused qmp_usb_runtime_suspend(struct device *dev)
dev_vdbg(dev, "Suspending QMP phy, mode:%d\n", qmp->mode);
- if (!qmp->phy->init_count) {
+ if (!qmp->phy_initialized) {
dev_vdbg(dev, "PHY not initialized, bailing out\n");
return 0;
}
@@ -1960,7 +1968,7 @@ static int __maybe_unused qmp_usb_runtime_resume(struct device *dev)
dev_vdbg(dev, "Resuming QMP phy, mode:%d\n", qmp->mode);
- if (!qmp->phy->init_count) {
+ if (!qmp->phy_initialized) {
dev_vdbg(dev, "PHY not initialized, bailing out\n");
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0961/1518] phy: qcom: qmp-pcie: Add pcs_lane1 offset to V5 offsets
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (959 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0960/1518] phy: qcom: qmp-usb: " Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0962/1518] md/raid5: round bitmap stripes with sector division Greg Kroah-Hartman
` (37 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Esteban Urrutia, Dmitry Baryshkov,
Vinod Koul, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Esteban Urrutia <esteuwu@proton.me>
[ Upstream commit f8b4493d5e7e19682abcf538a9faad012b5ef69e ]
Some SoCs such as SM8475 write data to registers using this offset,
specifically SW_CTRL2 and MX_CTRL2.
Add pcs_lane1 offset to V5 offsets to support this.
Signed-off-by: Esteban Urrutia <esteuwu@proton.me>
Fixes: 0fd0b31965b0 ("phy: qualcomm: qmp-pcie: add support for SAR2130P")
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Link: https://patch.msgid.link/20260715-sm8475-bup-pcie-v2-2-48bd91a19abf@proton.me
Signed-off-by: Vinod Koul <vkoul@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/phy/qualcomm/phy-qcom-qmp-pcie.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/phy/qualcomm/phy-qcom-qmp-pcie.c b/drivers/phy/qualcomm/phy-qcom-qmp-pcie.c
index 62b1c845b6275..456cdb6e7213c 100644
--- a/drivers/phy/qualcomm/phy-qcom-qmp-pcie.c
+++ b/drivers/phy/qualcomm/phy-qcom-qmp-pcie.c
@@ -3288,6 +3288,7 @@ static const struct qmp_pcie_offsets qmp_pcie_offsets_v5 = {
.pcs_misc = 0x0600,
.tx = 0x0e00,
.rx = 0x1000,
+ .pcs_lane1 = 0x1400,
.tx2 = 0x1600,
.rx2 = 0x1800,
};
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0962/1518] md/raid5: round bitmap stripes with sector division
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (960 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0961/1518] phy: qcom: qmp-pcie: Add pcs_lane1 offset to V5 offsets Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0963/1518] md: wait for behind writes before destroying bitmap Greg Kroah-Hartman
` (36 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Mykola Marzhan, Yu Kuai, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yu Kuai <yukuai@fygo.io>
[ Upstream commit 17ea021ae74987d6064c8195c4922fa025753892 ]
raid5_bitmap_sector_map() aligns the array range to full RAID5 stripe
widths before converting it to component sectors. That width is
chunk_sectors multiplied by the number of data disks, and it is not
always a power of two.
Reproduce with a 4-disk RAID5, 1024-sector chunks, and three data disks.
The full-stripe width is 3072 sectors. For a one-sector write at array
sector 3072, correct rounding gives array range [3072, 6144), which maps
to component range [1024, 2048). The old round_down()/round_up() logic
instead gives [1024, 4096), which maps to [0, 1024).
Use sector_div() based arithmetic so the rounded range is aligned to the
actual RAID5 stripe width.
The deterministic mapper test now reports the fixed component range as
[1024, 2048), while the old mask-based range was [0, 1024).
Fixes: 9c89f604476c ("md/raid5: implement pers->bitmap_sector()")
Reported-by: Mykola Marzhan <mykola@meshstor.io>
Link: https://lore.kernel.org/all/20260726185916.2223460-1-mykola@meshstor.io/
Tested-by: Mykola Marzhan <mykola@meshstor.io>
Link: https://patch.msgid.link/20260802195038.164272-6-yukuai@kernel.org
Signed-off-by: Yu Kuai <yukuai@fygo.io>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/md/raid5.c | 13 +++++++++----
1 file changed, 9 insertions(+), 4 deletions(-)
diff --git a/drivers/md/raid5.c b/drivers/md/raid5.c
index 0a0e241e3979b..8ff8cce3da7bf 100644
--- a/drivers/md/raid5.c
+++ b/drivers/md/raid5.c
@@ -5922,8 +5922,11 @@ static void raid5_bitmap_sector(struct mddev *mddev, sector_t *offset,
sectors_per_chunk = conf->chunk_sectors *
(conf->raid_disks - conf->max_degraded);
- start = round_down(start, sectors_per_chunk);
- end = round_up(end, sectors_per_chunk);
+ sector_div(start, sectors_per_chunk);
+ start *= sectors_per_chunk;
+ if (sector_div(end, sectors_per_chunk))
+ end++;
+ end *= sectors_per_chunk;
start = raid5_compute_sector(conf, start, 0, &dd_idx, NULL);
end = raid5_compute_sector(conf, end, 0, &dd_idx, NULL);
@@ -5941,8 +5944,10 @@ static void raid5_bitmap_sector(struct mddev *mddev, sector_t *offset,
sectors_per_chunk = conf->prev_chunk_sectors *
(conf->previous_raid_disks - conf->max_degraded);
- prev_start = round_down(prev_start, sectors_per_chunk);
- prev_end = round_down(prev_end, sectors_per_chunk);
+ sector_div(prev_start, sectors_per_chunk);
+ prev_start *= sectors_per_chunk;
+ sector_div(prev_end, sectors_per_chunk);
+ prev_end *= sectors_per_chunk;
prev_start = raid5_compute_sector(conf, prev_start, 1, &dd_idx, NULL);
prev_end = raid5_compute_sector(conf, prev_end, 1, &dd_idx, NULL);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0963/1518] md: wait for behind writes before destroying bitmap
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (961 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0962/1518] md/raid5: round bitmap stripes with sector division Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0964/1518] md: avoid stale clone I/O accounting timestamps Greg Kroah-Hartman
` (35 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Mykola Marzhan, Yu Kuai, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yu Kuai <yukuai@fygo.io>
[ Upstream commit 2a79365b2278f16e163e4024086105693b421601 ]
__md_stop() destroyed the bitmap before calling mddev_detach(). That made
mddev_detach() skip bitmap_ops->wait_behind_writes(), because the bitmap
was already disconnected from mddev.
This was still safe for the legacy bitmap because bitmap_destroy() waits
for behind writes itself. llbitmap keeps that wait in its
->wait_behind_writes() operation instead, while ->destroy() tears down the
llbitmap storage. With the old ordering, RAID1 behind-write completions
could still run after llbitmap storage had been freed.
Call mddev_detach() before md_bitmap_destroy() so the common detach path
can wait for behind writes while the bitmap is still alive. Only destroy
the bitmap after those users are gone.
Fixes: 5ab829f1971d ("md/md-llbitmap: introduce new lockless bitmap")
Tested-by: Mykola Marzhan <mykola@meshstor.io>
Link: https://patch.msgid.link/20260802195038.164272-7-yukuai@kernel.org
Signed-off-by: Yu Kuai <yukuai@fygo.io>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/md/md.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/md/md.c b/drivers/md/md.c
index 7b7e085885183..2e8e32e15e735 100644
--- a/drivers/md/md.c
+++ b/drivers/md/md.c
@@ -6957,8 +6957,8 @@ static void __md_stop(struct mddev *mddev)
{
struct md_personality *pers = mddev->pers;
- md_bitmap_destroy(mddev);
mddev_detach(mddev);
+ md_bitmap_destroy(mddev);
spin_lock(&mddev->lock);
mddev->pers = NULL;
spin_unlock(&mddev->lock);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0964/1518] md: avoid stale clone I/O accounting timestamps
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (962 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0963/1518] md: wait for behind writes before destroying bitmap Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0965/1518] md/md-llbitmap: prevent create failure bitmap UAF Greg Kroah-Hartman
` (34 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Mykola Marzhan, Yu Kuai, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yu Kuai <yukuai@fygo.io>
[ Upstream commit 45102fc8330525d35675b1c193242bba101df5ee ]
md_clone_bio() always allocates the clone from mddev->io_clone_set, even
when queue I/O stats are disabled. In that case it does not call
bio_start_io_acct(), but it also left md_io_clone->start_time untouched.
The clone private data comes from a mempool and can contain data from a
previous user. md_end_clone_io() checks start_time to decide whether it
needs to call bio_end_io_acct(), so a stale non-zero value can make the
completion path end accounting that was never started for this bio.
Set start_time to 0 in the no-stats branch. This keeps the end path tied
to whether bio_start_io_acct() actually ran.
Fixes: c687297b8845 ("md: also clone new io if io accounting is disabled")
Tested-by: Mykola Marzhan <mykola@meshstor.io>
Link: https://patch.msgid.link/20260802195038.164272-8-yukuai@kernel.org
Signed-off-by: Yu Kuai <yukuai@fygo.io>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/md/md.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/md/md.c b/drivers/md/md.c
index 2e8e32e15e735..d03d0fdf763db 100644
--- a/drivers/md/md.c
+++ b/drivers/md/md.c
@@ -9313,6 +9313,8 @@ static void md_clone_bio(struct mddev *mddev, struct bio **bio)
md_io_clone->mddev = mddev;
if (blk_queue_io_stat(bdev->bd_disk->queue))
md_io_clone->start_time = bio_start_io_acct(*bio);
+ else
+ md_io_clone->start_time = 0;
if (bio_data_dir(*bio) == WRITE && md_bitmap_enabled(mddev, false)) {
md_io_clone->offset = (*bio)->bi_iter.bi_sector;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0965/1518] md/md-llbitmap: prevent create failure bitmap UAF
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (963 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0964/1518] md: avoid stale clone I/O accounting timestamps Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0966/1518] md/md-llbitmap: stop daemon timer rearm on destroy Greg Kroah-Hartman
` (33 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Mykola Marzhan, Yu Kuai, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yu Kuai <yukuai@fygo.io>
[ Upstream commit 2116c2f0a0e547615886900e2ed8c529c016499b ]
llbitmap_create() publishes mddev->bitmap before reading the bitmap
superblock. This is needed because llbitmap_read_sb() can initialize a
new bitmap and flush it through helpers that use mddev->bitmap.
If llbitmap_read_sb() fails, the old cleanup dropped bitmap_info.mutex
and freed llbitmap before clearing mddev->bitmap. Readers such as
/proc/mdstat rely on bitmap_info.mutex to keep the bitmap pointer stable
while collecting bitmap stats, so they could observe the stale pointer
after the failed create path released the mutex.
Clear mddev->bitmap while still holding bitmap_info.mutex, then free the
failed llbitmap after dropping the mutex. This makes mutex-protected
readers see either a live bitmap or no bitmap.
Fixes: 5ab829f1971d ("md/md-llbitmap: introduce new lockless bitmap")
Tested-by: Mykola Marzhan <mykola@meshstor.io>
Link: https://patch.msgid.link/20260802195038.164272-9-yukuai@kernel.org
Signed-off-by: Yu Kuai <yukuai@fygo.io>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/md/md-llbitmap.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/md/md-llbitmap.c b/drivers/md/md-llbitmap.c
index dc9b72494a81a..b4738fe6e2463 100644
--- a/drivers/md/md-llbitmap.c
+++ b/drivers/md/md-llbitmap.c
@@ -999,10 +999,11 @@ static int llbitmap_create(struct mddev *mddev)
mutex_lock(&mddev->bitmap_info.mutex);
mddev->bitmap = llbitmap;
ret = llbitmap_read_sb(llbitmap);
+ if (ret)
+ mddev->bitmap = NULL;
mutex_unlock(&mddev->bitmap_info.mutex);
if (ret) {
kfree(llbitmap);
- mddev->bitmap = NULL;
}
return ret;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0966/1518] md/md-llbitmap: stop daemon timer rearm on destroy
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (964 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0965/1518] md/md-llbitmap: prevent create failure bitmap UAF Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0967/1518] md/raid1: dont set array_frozen in raid1_takeover() Greg Kroah-Hartman
` (32 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Mykola Marzhan, Yu Kuai, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yu Kuai <yukuai@fygo.io>
[ Upstream commit 5553d64e01d9a995be6c3de38501c6dd4ceede3b ]
llbitmap_destroy() deletes pending_timer before flushing
md_llbitmap_io_wq. However, daemon_work can still be queued or running
after the timer has been deleted, and the daemon path can arm
pending_timer again when it finds dirty chunks that are not ready to
flush yet.
If that happens during teardown, pending_timer can remain armed after
llbitmap is freed and later dereference freed memory.
Add a BITMAP_SHUTDOWN bit to llbitmap->flags, set it before deleting
the timer, and make the timer and daemon paths stop queueing or rearming
work once teardown starts. Cancel daemon_work before flushing the shared
workqueue so no already queued daemon instance can race with the free.
Use timer_shutdown_sync() so a daemon instance that passed the shutdown
check before teardown cannot rearm the timer afterward.
BITMAP_SHUTDOWN is a runtime-only state. Mask it out when reading and
updating the llbitmap superblock so the shutdown state is never loaded
from disk or persisted to disk.
Fixes: 5ab829f1971d ("md/md-llbitmap: introduce new lockless bitmap")
Tested-by: Mykola Marzhan <mykola@meshstor.io>
Link: https://patch.msgid.link/20260802195038.164272-10-yukuai@kernel.org
Signed-off-by: Yu Kuai <yukuai@fygo.io>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/md/md-bitmap.h | 1 +
drivers/md/md-llbitmap.c | 17 +++++++++++++----
2 files changed, 14 insertions(+), 4 deletions(-)
diff --git a/drivers/md/md-bitmap.h b/drivers/md/md-bitmap.h
index f46674bdfeb91..7535742982fc0 100644
--- a/drivers/md/md-bitmap.h
+++ b/drivers/md/md-bitmap.h
@@ -29,6 +29,7 @@ enum bitmap_state {
BITMAP_FIRST_USE = 3, /* llbitmap is just created */
BITMAP_CLEAN = 4, /* llbitmap is created with assume_clean */
BITMAP_DAEMON_BUSY = 5, /* llbitmap daemon is not finished after daemon_sleep */
+ BITMAP_SHUTDOWN = 6, /* llbitmap is being destroyed */
BITMAP_HOSTENDIAN =15,
};
diff --git a/drivers/md/md-llbitmap.c b/drivers/md/md-llbitmap.c
index b4738fe6e2463..5c60b26ad2468 100644
--- a/drivers/md/md-llbitmap.c
+++ b/drivers/md/md-llbitmap.c
@@ -662,6 +662,7 @@ static enum llbitmap_state llbitmap_state_machine(struct llbitmap *llbitmap,
if (state == BitNeedSync)
need_resync = !mddev->degraded;
else if (state == BitDirty &&
+ !test_bit(BITMAP_SHUTDOWN, &llbitmap->flags) &&
!timer_pending(&llbitmap->pending_timer))
mod_timer(&llbitmap->pending_timer,
jiffies + mddev->bitmap_info.daemon_sleep * HZ);
@@ -854,7 +855,7 @@ static int llbitmap_read_sb(struct llbitmap *llbitmap)
else
mddev->bitmap_info.space = mddev->bitmap_info.default_space;
}
- llbitmap->flags = le32_to_cpu(sb->state);
+ llbitmap->flags = le32_to_cpu(sb->state) & ~BIT(BITMAP_SHUTDOWN);
if (test_and_clear_bit(BITMAP_FIRST_USE, &llbitmap->flags)) {
ret = llbitmap_init(llbitmap);
goto out_put_page;
@@ -910,6 +911,9 @@ static void llbitmap_pending_timer_fn(struct timer_list *pending_timer)
struct llbitmap *llbitmap =
container_of(pending_timer, struct llbitmap, pending_timer);
+ if (test_bit(BITMAP_SHUTDOWN, &llbitmap->flags))
+ return;
+
if (work_busy(&llbitmap->daemon_work)) {
pr_warn("md/llbitmap: %s daemon_work not finished in %lu seconds\n",
mdname(llbitmap->mddev),
@@ -930,6 +934,9 @@ static void md_llbitmap_daemon_fn(struct work_struct *work)
bool restart;
int idx;
+ if (test_bit(BITMAP_SHUTDOWN, &llbitmap->flags))
+ return;
+
if (llbitmap->mddev->degraded)
return;
retry:
@@ -969,7 +976,7 @@ static void md_llbitmap_daemon_fn(struct work_struct *work)
goto retry;
/* If some page is dirty but not expired, setup timer again */
- if (restart)
+ if (restart && !test_bit(BITMAP_SHUTDOWN, &llbitmap->flags))
mod_timer(&llbitmap->pending_timer,
jiffies + llbitmap->mddev->bitmap_info.daemon_sleep * HZ);
}
@@ -1052,7 +1059,9 @@ static void llbitmap_destroy(struct mddev *mddev)
mutex_lock(&mddev->bitmap_info.mutex);
- timer_delete_sync(&llbitmap->pending_timer);
+ set_bit(BITMAP_SHUTDOWN, &llbitmap->flags);
+ timer_shutdown_sync(&llbitmap->pending_timer);
+ cancel_work_sync(&llbitmap->daemon_work);
flush_workqueue(md_llbitmap_io_wq);
flush_workqueue(md_llbitmap_unplug_wq);
@@ -1376,7 +1385,7 @@ static void llbitmap_update_sb(void *data)
sb = kmap_local_page(sb_page);
sb->events = cpu_to_le64(mddev->events);
- sb->state = cpu_to_le32(llbitmap->flags);
+ sb->state = cpu_to_le32(llbitmap->flags & ~BIT(BITMAP_SHUTDOWN));
sb->chunksize = cpu_to_le32(llbitmap->chunksize);
sb->sync_size = cpu_to_le64(mddev->resync_max_sectors);
sb->events_cleared = cpu_to_le64(llbitmap->events_cleared);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0967/1518] md/raid1: dont set array_frozen in raid1_takeover()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (965 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0966/1518] md/md-llbitmap: stop daemon timer rearm on destroy Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0968/1518] coresight: etm4x: fix wrong check of etm4x_sspcicrn_present() Greg Kroah-Hartman
` (31 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable; +Cc: Greg Kroah-Hartman, patches, Bruce Johnston, Yu Kuai, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bruce Johnston <bjohnsto@redhat.com>
[ Upstream commit dc386aa0ac0a3ec06c9a3ea9b064b073fb72a916 ]
raid1_takeover() sets conf->array_frozen = 1 on the newly-allocated
r1conf and nothing ever clears it, so every I/O to the array stalls
permanently once _wait_barrier() sees it stuck at 1.
This used to be harmless: level_store() called mddev_resume() right
after pers->run(), which called raid1_quiesce(mddev, 0) and cleared
array_frozen back to 0 regardless of what raid1_takeover() set. Commit
b39f35ebe86d ("md: don't quiesce in mddev_suspend()") removed that
quiesce(mddev, 0) call, so the pre-set now sticks.
setup_conf() already zero-initializes the new r1conf via kzalloc, so
just don't set array_frozen here.
Same class of bug as commit 892da88d1cd9 ("md/raid10: fix a
'conf->barrier' leakage in raid10_takeover()"), also triggered by
b39f35ebe86d.
Fixes: b39f35ebe86d ("md: don't quiesce in mddev_suspend()")
Link: https://issues.redhat.com/browse/RHEL-191802
Signed-off-by: Bruce Johnston <bjohnsto@redhat.com>
Link: https://patch.msgid.link/20260803180240.1177104-1-bjohnsto@redhat.com
Signed-off-by: Yu Kuai <yukuai@fygo.io>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/md/raid1.c | 2 --
1 file changed, 2 deletions(-)
diff --git a/drivers/md/raid1.c b/drivers/md/raid1.c
index 16625b79788bd..1370be1e5cc7b 100644
--- a/drivers/md/raid1.c
+++ b/drivers/md/raid1.c
@@ -3480,8 +3480,6 @@ static void *raid1_takeover(struct mddev *mddev)
mddev->new_chunk_sectors = 0;
conf = setup_conf(mddev);
if (!IS_ERR(conf)) {
- /* Array must appear to be quiesced */
- conf->array_frozen = 1;
mddev_clear_unsupported_flags(mddev,
UNSUPPORTED_MDDEV_FLAGS);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0968/1518] coresight: etm4x: fix wrong check of etm4x_sspcicrn_present()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (966 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0967/1518] md/raid1: dont set array_frozen in raid1_takeover() Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0969/1518] coresight: Change syncfreq to be a u8 Greg Kroah-Hartman
` (30 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Leo Yan, Yeoreum Yun,
Suzuki K Poulose, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yeoreum Yun <yeoreum.yun@arm.com>
[ Upstream commit 0e1cd4270b42a257c139165622091e1e8c7104a7 ]
According to Embedded Trace Macrocell Architecture Specification
ETMv4.0 to ETM4.6 [0], TRCSSPCICR<n> is present only if all of
the following are true:
- TRCIDR4.NUMSSCC > n.
- TRCIDR4.NUMPC > 0b0000.
- TRCSSCSR<n>.PC == 0b1.
Comment for etm4x_sspcicrn_present() is align with the specification.
However, the check should use drvdata->nr_pe_cmp to check TRCIDR4.NUMPC
not nr_pe.
Link: https://developer.arm.com/documentation/ihi0064/latest/ [0]
Fixes: f6a18f354c58 ("coresight: etm4x: Handle access to TRCSSPCICRn")
Reviewed-by: Leo Yan <leo.yan@arm.com>
Signed-off-by: Yeoreum Yun <yeoreum.yun@arm.com>
Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com>
Link: https://lore.kernel.org/r/20260725113645.57519-2-yeoreum.yun@arm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwtracing/coresight/coresight-etm4x-core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/hwtracing/coresight/coresight-etm4x-core.c b/drivers/hwtracing/coresight/coresight-etm4x-core.c
index 2271f5ea81214..318846e4dda3a 100644
--- a/drivers/hwtracing/coresight/coresight-etm4x-core.c
+++ b/drivers/hwtracing/coresight/coresight-etm4x-core.c
@@ -92,7 +92,7 @@ static int etm4_probe_cpu(unsigned int cpu);
static bool etm4x_sspcicrn_present(struct etmv4_drvdata *drvdata, int n)
{
return (n < drvdata->nr_ss_cmp) &&
- drvdata->nr_pe &&
+ drvdata->nr_pe_cmp &&
(drvdata->config.ss_status[n] & TRCSSCSRn_PC);
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0969/1518] coresight: Change syncfreq to be a u8
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (967 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0968/1518] coresight: etm4x: fix wrong check of etm4x_sspcicrn_present() Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0970/1518] coresight: etm4x: fix underflow for usage of (nrseqstate - 1) Greg Kroah-Hartman
` (29 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Mike Leach, Leo Yan, James Clark,
Suzuki K Poulose, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: James Clark <james.clark@linaro.org>
[ Upstream commit 10d4dbdc8fbce586b17be07b8138e025381453dd ]
TRCSYNCPR.PERIOD is the only functional part of TRCSYNCPR and it only
has 5 valid bits so it can be stored in a u8.
Reviewed-by: Mike Leach <mike.leach@linaro.org>
Reviewed-by: Leo Yan <leo.yan@arm.com>
Tested-by: Leo Yan <leo.yan@arm.com>
Signed-off-by: James Clark <james.clark@linaro.org>
Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com>
Link: https://lore.kernel.org/r/20251128-james-cs-syncfreq-v8-1-4d319764cc58@linaro.org
Stable-dep-of: 1674d9bff807 ("coresight: etm4x: fix underflow for usage of (nrseqstate - 1)")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwtracing/coresight/coresight-etm4x.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/hwtracing/coresight/coresight-etm4x.h b/drivers/hwtracing/coresight/coresight-etm4x.h
index 012c52fd19338..0287d19ce12ed 100644
--- a/drivers/hwtracing/coresight/coresight-etm4x.h
+++ b/drivers/hwtracing/coresight/coresight-etm4x.h
@@ -825,7 +825,6 @@ struct etmv4_config {
u32 eventctrl1;
u32 stall_ctrl;
u32 ts_ctrl;
- u32 syncfreq;
u32 ccctlr;
u32 bb_ctrl;
u32 vinst_ctrl;
@@ -833,6 +832,7 @@ struct etmv4_config {
u32 vissctlr;
u32 vipcssctlr;
u8 seq_idx;
+ u8 syncfreq;
u32 seq_ctrl[ETM_MAX_SEQ_STATES];
u32 seq_rst;
u32 seq_state;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0970/1518] coresight: etm4x: fix underflow for usage of (nrseqstate - 1)
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (968 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0969/1518] coresight: Change syncfreq to be a u8 Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0971/1518] coresight: etm4x: fix leaked trace id Greg Kroah-Hartman
` (28 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Leo Yan, Suzuki K Poulose,
Yeoreum Yun, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yeoreum Yun <yeoreum.yun@arm.com>
[ Upstream commit 1674d9bff8073bdee5dbc200f56fc3caa28d0566 ]
According to IHI006H Embedded Trace Macrocell Architecture
Specification[0], TRCSEQEVR<n> is implemented only when
TRCIDR5.NUMSEQSTATE is 0b100, in which case n ranges from 0 to 2;
otherwise, TRCIDR5.NUMSEQSTATE is 0b000.
IOW, the number of usage in the initialisation or setting
TRCSEQEVR<n> with drvdata->nrseqstate - 1 in the loop could make
underflow issue when TRCIDR5.NUMSEQSTATE is 0b000.
Therefore, introduce nr_seq_ctrls field and untie it from nrseqstate.
As part of this introduce ETM_MAX_SEQ_TRANSITIONS macro and
apply nr_seq_ctrls and above macro to TRCSEQEVR<n> relevant fields setup.
Link: https://developer.arm.com/documentation/ihi0064/latest/ [0]
Fixes: 2e1cdfe184b5 ("coresight-etm4x: Adding CoreSight ETM4x driver")
Suggested-by: Leo Yan <leo.yan@arm.com>
Suggested-by: Suzuki K Poulose <suzuki.poulose@arm.com>
Signed-off-by: Yeoreum Yun <yeoreum.yun@arm.com>
Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com>
Link: https://lore.kernel.org/r/20260725113645.57519-3-yeoreum.yun@arm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwtracing/coresight/coresight-etm4x-cfg.c | 2 +-
drivers/hwtracing/coresight/coresight-etm4x-core.c | 9 ++++++---
drivers/hwtracing/coresight/coresight-etm4x-sysfs.c | 6 ++++--
drivers/hwtracing/coresight/coresight-etm4x.h | 7 +++++--
4 files changed, 16 insertions(+), 8 deletions(-)
diff --git a/drivers/hwtracing/coresight/coresight-etm4x-cfg.c b/drivers/hwtracing/coresight/coresight-etm4x-cfg.c
index c302072b293a3..e1a59b4345052 100644
--- a/drivers/hwtracing/coresight/coresight-etm4x-cfg.c
+++ b/drivers/hwtracing/coresight/coresight-etm4x-cfg.c
@@ -76,7 +76,7 @@ static int etm4_cfg_map_reg_offset(struct etmv4_drvdata *drvdata,
} else if ((offset & GENMASK(11, 4)) == TRCSEQEVRn(0)) {
/* sequencer state control registers */
idx = (offset & GENMASK(3, 0)) / 4;
- if (idx < ETM_MAX_SEQ_STATES) {
+ if (idx < ETM_MAX_SEQ_TRANSITIONS) {
reg_csdev->driver_regval = &drvcfg->seq_ctrl[idx];
err = 0;
}
diff --git a/drivers/hwtracing/coresight/coresight-etm4x-core.c b/drivers/hwtracing/coresight/coresight-etm4x-core.c
index 318846e4dda3a..a265586020ac8 100644
--- a/drivers/hwtracing/coresight/coresight-etm4x-core.c
+++ b/drivers/hwtracing/coresight/coresight-etm4x-core.c
@@ -541,7 +541,8 @@ static int etm4_enable_hw(struct etmv4_drvdata *drvdata)
etm4x_relaxed_write32(csa, config->vissctlr, TRCVISSCTLR);
if (drvdata->nr_pe_cmp)
etm4x_relaxed_write32(csa, config->vipcssctlr, TRCVIPCSSCTLR);
- for (i = 0; i < drvdata->nrseqstate - 1; i++)
+
+ for (i = 0; i < drvdata->nr_seq_ctrls; i++)
etm4x_relaxed_write32(csa, config->seq_ctrl[i], TRCSEQEVRn(i));
if (drvdata->nrseqstate) {
etm4x_relaxed_write32(csa, config->seq_rst, TRCSEQRSTEVR);
@@ -1476,6 +1477,8 @@ static void etm4_init_arch_data(void *info)
drvdata->lpoverride = (etmidr5 & TRCIDR5_LPOVERRIDE) && (!drvdata->skip_power_up);
/* NUMSEQSTATE, bits[27:25] number of sequencer states implemented */
drvdata->nrseqstate = FIELD_GET(TRCIDR5_NUMSEQSTATE_MASK, etmidr5);
+ if (drvdata->nrseqstate)
+ drvdata->nr_seq_ctrls = ETM_MAX_SEQ_TRANSITIONS;
/* NUMCNTR, bits[30:28] number of counters available for tracing */
drvdata->nr_cntr = FIELD_GET(TRCIDR5_NUMCNTR_MASK, etmidr5);
@@ -1889,7 +1892,7 @@ static int __etm4_cpu_save(struct etmv4_drvdata *drvdata)
if (drvdata->nr_pe_cmp)
state->trcvipcssctlr = etm4x_read32(csa, TRCVIPCSSCTLR);
- for (i = 0; i < drvdata->nrseqstate - 1; i++)
+ for (i = 0; i < drvdata->nr_seq_ctrls; i++)
state->trcseqevr[i] = etm4x_read32(csa, TRCSEQEVRn(i));
if (drvdata->nrseqstate) {
@@ -2020,7 +2023,7 @@ static void __etm4_cpu_restore(struct etmv4_drvdata *drvdata)
if (drvdata->nr_pe_cmp)
etm4x_relaxed_write32(csa, state->trcvipcssctlr, TRCVIPCSSCTLR);
- for (i = 0; i < drvdata->nrseqstate - 1; i++)
+ for (i = 0; i < drvdata->nr_seq_ctrls; i++)
etm4x_relaxed_write32(csa, state->trcseqevr[i], TRCSEQEVRn(i));
if (drvdata->nrseqstate) {
diff --git a/drivers/hwtracing/coresight/coresight-etm4x-sysfs.c b/drivers/hwtracing/coresight/coresight-etm4x-sysfs.c
index e9eeea6240d55..cc6cdd3ae29d5 100644
--- a/drivers/hwtracing/coresight/coresight-etm4x-sysfs.c
+++ b/drivers/hwtracing/coresight/coresight-etm4x-sysfs.c
@@ -223,7 +223,7 @@ static ssize_t reset_store(struct device *dev,
config->vipcssctlr = 0x0;
/* Disable seq events */
- for (i = 0; i < drvdata->nrseqstate-1; i++)
+ for (i = 0; i < drvdata->nr_seq_ctrls; i++)
config->seq_ctrl[i] = 0x0;
config->seq_rst = 0x0;
config->seq_state = 0x0;
@@ -1395,9 +1395,11 @@ static ssize_t seq_idx_store(struct device *dev,
struct etmv4_drvdata *drvdata = dev_get_drvdata(dev->parent);
struct etmv4_config *config = &drvdata->config;
+ if (!drvdata->nr_seq_ctrls)
+ return -ENOTSUPP;
if (kstrtoul(buf, 16, &val))
return -EINVAL;
- if (val >= drvdata->nrseqstate - 1)
+ if (val >= drvdata->nr_seq_ctrls)
return -EINVAL;
/*
diff --git a/drivers/hwtracing/coresight/coresight-etm4x.h b/drivers/hwtracing/coresight/coresight-etm4x.h
index 0287d19ce12ed..d2ece9691d3a2 100644
--- a/drivers/hwtracing/coresight/coresight-etm4x.h
+++ b/drivers/hwtracing/coresight/coresight-etm4x.h
@@ -570,6 +570,7 @@
#define ETM_MAX_NR_PE 8
#define ETMv4_MAX_CNTR 4
#define ETM_MAX_SEQ_STATES 4
+#define ETM_MAX_SEQ_TRANSITIONS 3
#define ETM_MAX_EXT_INP_SEL 4
#define ETM_MAX_EXT_INP 256
#define ETM_MAX_EXT_OUT 4
@@ -833,7 +834,7 @@ struct etmv4_config {
u32 vipcssctlr;
u8 seq_idx;
u8 syncfreq;
- u32 seq_ctrl[ETM_MAX_SEQ_STATES];
+ u32 seq_ctrl[ETM_MAX_SEQ_TRANSITIONS];
u32 seq_rst;
u32 seq_state;
u8 cntr_idx;
@@ -884,7 +885,7 @@ struct etmv4_save_state {
u32 trcvissctlr;
u32 trcvipcssctlr;
- u32 trcseqevr[ETM_MAX_SEQ_STATES];
+ u32 trcseqevr[ETM_MAX_SEQ_TRANSITIONS];
u32 trcseqrstevr;
u32 trcseqstr;
u32 trcextinselr;
@@ -937,6 +938,7 @@ struct etmv4_save_state {
* @numcidc: Number of contextID comparators.
* @numvmidc: Number of VMID comparators.
* @nrseqstate: The number of sequencer states that are implemented.
+ * @nr_seq_ctrls: The number of sequence state transition control registers.
* @nr_event: Indicates how many events the trace unit support.
* @nr_resource:The number of resource selection pairs available for tracing.
* @nr_ss_cmp: Number of single-shot comparator controls that are available.
@@ -1002,6 +1004,7 @@ struct etmv4_drvdata {
u8 numextinsel;
u8 numvmidc;
u8 nrseqstate;
+ u8 nr_seq_ctrls;
u8 nr_event;
u8 nr_resource;
u8 nr_ss_cmp;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0971/1518] coresight: etm4x: fix leaked trace id
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (969 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0970/1518] coresight: etm4x: fix underflow for usage of (nrseqstate - 1) Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0972/1518] coresight: Refactor etm4_config_timestamp_event() Greg Kroah-Hartman
` (27 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Jie Gan, Leo Yan, Yeoreum Yun,
Suzuki K Poulose, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yeoreum Yun <yeoreum.yun@arm.com>
[ Upstream commit 467e5862ccb0eed907002f4c6d3badfe34360940 ]
If etm4_enable_sysfs() fails in cscfg_csdev_enable_active_config(),
the trace ID may be leaked because it is not released.
To address this, call etm4_release_trace_id() when etm4_enable_sysfs()
fails in cscfg_csdev_enable_active_config().
Fixes: 7ebd0ec6cf94 ("coresight: configfs: Allow configfs to activate configuration")
Reviewed-by: Jie Gan <jie.gan@oss.qualcomm.com>
Reviewed-by: Leo Yan <leo.yan@arm.com>
Signed-off-by: Yeoreum Yun <yeoreum.yun@arm.com>
Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com>
Link: https://lore.kernel.org/r/20260725113645.57519-4-yeoreum.yun@arm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/hwtracing/coresight/coresight-etm4x-core.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/hwtracing/coresight/coresight-etm4x-core.c b/drivers/hwtracing/coresight/coresight-etm4x-core.c
index a265586020ac8..ac0908a347132 100644
--- a/drivers/hwtracing/coresight/coresight-etm4x-core.c
+++ b/drivers/hwtracing/coresight/coresight-etm4x-core.c
@@ -880,8 +880,10 @@ static int etm4_enable_sysfs(struct coresight_device *csdev, struct coresight_pa
cscfg_config_sysfs_get_active_cfg(&cfg_hash, &preset);
if (cfg_hash) {
ret = cscfg_csdev_enable_active_config(csdev, cfg_hash, preset);
- if (ret)
+ if (ret) {
+ etm4_release_trace_id(drvdata);
return ret;
+ }
}
raw_spin_lock(&drvdata->spinlock);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0972/1518] coresight: Refactor etm4_config_timestamp_event()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (970 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0971/1518] coresight: etm4x: fix leaked trace id Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0973/1518] perf: arm_pmuv3: Zero initialize hw_id branch stack field Greg Kroah-Hartman
` (26 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Leo Yan, James Clark,
Suzuki K Poulose, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: James Clark <james.clark@linaro.org>
[ Upstream commit b02450de6ba6309c66e2e056ccfbfce4bd3b0352 ]
Remove some of the magic numbers and try to clarify some of the
documentation so it's clearer how this sets up the timestamp interval.
Return errors directly instead of jumping to out and returning ret,
nothing needs to be cleaned up at the end and it only obscures the flow
and return value.
Add utilities for programming resource selectors that do compile time
checks for constants or WARN_ONs for non-constant values. FIELD_PREP
includes compile time checks so we only need to add an additional
BUILD_BUG_ON for resource == 0 in pair mode.
Tested-by: Leo Yan <leo.yan@arm.com>
Signed-off-by: James Clark <james.clark@linaro.org>
Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com>
Link: https://lore.kernel.org/r/20251128-james-cs-syncfreq-v8-3-4d319764cc58@linaro.org
Stable-dep-of: 0a47f0be6557 ("coresight: etm4x: missing cscfg_csdev_disable_active_config() in perf enable")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
.../coresight/coresight-etm4x-core.c | 96 ++++++++++++-------
drivers/hwtracing/coresight/coresight-etm4x.h | 54 ++++++++++-
2 files changed, 112 insertions(+), 38 deletions(-)
diff --git a/drivers/hwtracing/coresight/coresight-etm4x-core.c b/drivers/hwtracing/coresight/coresight-etm4x-core.c
index ac0908a347132..522e128174467 100644
--- a/drivers/hwtracing/coresight/coresight-etm4x-core.c
+++ b/drivers/hwtracing/coresight/coresight-etm4x-core.c
@@ -641,18 +641,33 @@ static void etm4_enable_sysfs_smp_call(void *info)
* TRCRSCTLR1 (always true) used to get the counter to decrement. From
* there a resource selector is configured with the counter and the
* timestamp control register to use the resource selector to trigger the
- * event that will insert a timestamp packet in the stream.
+ * event that will insert a timestamp packet in the stream:
+ *
+ * +--------------+
+ * | Resource 1 | fixed "always-true" resource
+ * +--------------+
+ * |
+ * +------v-------+
+ * | Counter x | (reload to 1 on underflow)
+ * +--------------+
+ * |
+ * +------v--------------+
+ * | Resource Selector y | (trigger on counter x == 0)
+ * +---------------------+
+ * |
+ * +------v---------------+
+ * | Timestamp Generator | (timestamp on resource y)
+ * +----------------------+
*/
static int etm4_config_timestamp_event(struct etmv4_drvdata *drvdata)
{
- int ctridx, ret = -EINVAL;
- int counter, rselector;
- u32 val = 0;
+ int ctridx;
+ int rselector;
struct etmv4_config *config = &drvdata->config;
/* No point in trying if we don't have at least one counter */
if (!drvdata->nr_cntr)
- goto out;
+ return -EINVAL;
/* Find a counter that hasn't been initialised */
for (ctridx = 0; ctridx < drvdata->nr_cntr; ctridx++)
@@ -662,15 +677,19 @@ static int etm4_config_timestamp_event(struct etmv4_drvdata *drvdata)
/* All the counters have been configured already, bail out */
if (ctridx == drvdata->nr_cntr) {
pr_debug("%s: no available counter found\n", __func__);
- ret = -ENOSPC;
- goto out;
+ return -ENOSPC;
}
/*
- * Searching for an available resource selector to use, starting at
- * '2' since every implementation has at least 2 resource selector.
- * ETMIDR4 gives the number of resource selector _pairs_,
- * hence multiply by 2.
+ * Searching for an available resource selector to use, starting at '2'
+ * since resource 0 is the fixed 'always returns false' resource and 1
+ * is the fixed 'always returns true' resource. See IHI0064H_b '7.3.64
+ * TRCRSCTLRn, Resource Selection Control Registers, n=2-31'. If there
+ * are no resources, there would also be no counters so wouldn't get
+ * here.
+ *
+ * ETMIDR4 gives the number of resource selector _pairs_, hence multiply
+ * by 2.
*/
for (rselector = 2; rselector < drvdata->nr_resource * 2; rselector++)
if (!config->res_ctrl[rselector])
@@ -679,13 +698,9 @@ static int etm4_config_timestamp_event(struct etmv4_drvdata *drvdata)
if (rselector == drvdata->nr_resource * 2) {
pr_debug("%s: no available resource selector found\n",
__func__);
- ret = -ENOSPC;
- goto out;
+ return -ENOSPC;
}
- /* Remember what counter we used */
- counter = 1 << ctridx;
-
/*
* Initialise original and reload counter value to the smallest
* possible value in order to get as much precision as we can.
@@ -693,26 +708,41 @@ static int etm4_config_timestamp_event(struct etmv4_drvdata *drvdata)
config->cntr_val[ctridx] = 1;
config->cntrldvr[ctridx] = 1;
- /* Set the trace counter control register */
- val = 0x1 << 16 | /* Bit 16, reload counter automatically */
- 0x0 << 7 | /* Select single resource selector */
- 0x1; /* Resource selector 1, i.e always true */
-
- config->cntr_ctrl[ctridx] = val;
-
- val = 0x2 << 16 | /* Group 0b0010 - Counter and sequencers */
- counter << 0; /* Counter to use */
-
- config->res_ctrl[rselector] = val;
+ /*
+ * Trace Counter Control Register TRCCNTCTLRn
+ *
+ * CNTCHAIN = 0, don't reload on the previous counter
+ * RLDSELF = true, reload counter automatically on underflow
+ * RLDEVENT = RES_SEL_FALSE (0), reload on single false resource (never reload)
+ * CNTEVENT = RES_SEL_TRUE (1), count single fixed 'always true' resource (always decrement)
+ */
+ config->cntr_ctrl[ctridx] = TRCCNTCTLRn_RLDSELF |
+ FIELD_PREP(TRCCNTCTLRn_RLDEVENT_MASK,
+ etm4_res_sel_single(ETM4_RES_SEL_FALSE)) |
+ FIELD_PREP(TRCCNTCTLRn_CNTEVENT_MASK,
+ etm4_res_sel_single(ETM4_RES_SEL_TRUE));
- val = 0x0 << 7 | /* Select single resource selector */
- rselector; /* Resource selector */
+ /*
+ * Resource Selection Control Register TRCRSCTLRn
+ *
+ * PAIRINV = 0, INV = 0, don't invert
+ * GROUP = 2, SELECT = ctridx, trigger when counter 'ctridx' reaches 0
+ *
+ * Multiple counters can be selected, and each bit signifies a counter,
+ * so set bit 'ctridx' to select our counter.
+ */
+ config->res_ctrl[rselector] = FIELD_PREP(TRCRSCTLRn_GROUP_MASK, 2) |
+ FIELD_PREP(TRCRSCTLRn_SELECT_MASK, 1 << ctridx);
- config->ts_ctrl = val;
+ /*
+ * Global Timestamp Control Register TRCTSCTLR
+ *
+ * EVENT = generate timestamp on single resource 'rselector'
+ */
+ config->ts_ctrl = FIELD_PREP(TRCTSCTLR_EVENT_MASK,
+ etm4_res_sel_single(rselector));
- ret = 0;
-out:
- return ret;
+ return 0;
}
static int etm4_parse_event_config(struct coresight_device *csdev,
diff --git a/drivers/hwtracing/coresight/coresight-etm4x.h b/drivers/hwtracing/coresight/coresight-etm4x.h
index d2ece9691d3a2..0489496babb33 100644
--- a/drivers/hwtracing/coresight/coresight-etm4x.h
+++ b/drivers/hwtracing/coresight/coresight-etm4x.h
@@ -225,6 +225,50 @@
#define TRCRSCTLRn_GROUP_MASK GENMASK(19, 16)
#define TRCRSCTLRn_SELECT_MASK GENMASK(15, 0)
+#define TRCCNTCTLRn_CNTCHAIN BIT(17)
+#define TRCCNTCTLRn_RLDSELF BIT(16)
+#define TRCCNTCTLRn_RLDEVENT_MASK GENMASK(15, 8)
+#define TRCCNTCTLRn_CNTEVENT_MASK GENMASK(7, 0)
+
+#define TRCTSCTLR_EVENT_MASK GENMASK(7, 0)
+
+#define ETM4_RES_SEL_FALSE 0 /* Fixed function 'always false' resource selector */
+#define ETM4_RES_SEL_TRUE 1 /* Fixed function 'always true' resource selector */
+
+#define ETM4_RES_SEL_SINGLE_MASK GENMASK(4, 0)
+#define ETM4_RES_SEL_PAIR_MASK GENMASK(3, 0)
+#define ETM4_RES_SEL_TYPE_PAIR BIT(7)
+
+/*
+ * Utilities for programming EVENT resource selectors, e.g. TRCCNTCTLRn_RLDEVENT.
+ *
+ * Resource selectors have a common format across registers:
+ *
+ * 7 6 5 4 0
+ * +------+------+-------+
+ * | TYPE | RES0 | SEL |
+ * +------+------+-------+
+ *
+ * Where TYPE indicates whether the selector is for a single event or a pair.
+ * When TYPE is pair, SEL is 4 bits wide and using pair 0 is UNPREDICTABLE.
+ * Otherwise for single it's 5 bits wide.
+ */
+static inline u32 etm4_res_sel_single(u8 res_sel_idx)
+{
+ WARN_ON_ONCE(!FIELD_FIT(ETM4_RES_SEL_SINGLE_MASK, res_sel_idx));
+ return FIELD_PREP(ETM4_RES_SEL_SINGLE_MASK, res_sel_idx);
+}
+
+static inline u32 etm4_res_sel_pair(u8 res_sel_idx)
+{
+ if (__builtin_constant_p(res_sel_idx))
+ BUILD_BUG_ON(res_sel_idx == 0);
+ WARN_ON_ONCE(!FIELD_FIT(ETM4_RES_SEL_PAIR_MASK, res_sel_idx) ||
+ (res_sel_idx == 0));
+ return FIELD_PREP(ETM4_RES_SEL_PAIR_MASK, res_sel_idx) |
+ ETM4_RES_SEL_TYPE_PAIR;
+}
+
/*
* System instructions to access ETM registers.
* See ETMv4.4 spec ARM IHI0064F section 4.3.6 System instructions
@@ -825,7 +869,7 @@ struct etmv4_config {
u32 eventctrl0;
u32 eventctrl1;
u32 stall_ctrl;
- u32 ts_ctrl;
+ u32 ts_ctrl; /* TRCTSCTLR */
u32 ccctlr;
u32 bb_ctrl;
u32 vinst_ctrl;
@@ -838,11 +882,11 @@ struct etmv4_config {
u32 seq_rst;
u32 seq_state;
u8 cntr_idx;
- u32 cntrldvr[ETMv4_MAX_CNTR];
- u32 cntr_ctrl[ETMv4_MAX_CNTR];
- u32 cntr_val[ETMv4_MAX_CNTR];
+ u32 cntrldvr[ETMv4_MAX_CNTR]; /* TRCCNTRLDVRn */
+ u32 cntr_ctrl[ETMv4_MAX_CNTR]; /* TRCCNTCTLRn */
+ u32 cntr_val[ETMv4_MAX_CNTR]; /* TRCCNTVRn */
u8 res_idx;
- u32 res_ctrl[ETM_MAX_RES_SEL];
+ u32 res_ctrl[ETM_MAX_RES_SEL]; /* TRCRSCTLRn */
u8 ss_idx;
u32 ss_ctrl[ETM_MAX_SS_CMP];
u32 ss_status[ETM_MAX_SS_CMP];
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0973/1518] perf: arm_pmuv3: Zero initialize hw_id branch stack field
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (971 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0972/1518] coresight: Refactor etm4_config_timestamp_event() Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0974/1518] bpf: Reject load-acquire from pointers requiring fault protection Greg Kroah-Hartman
` (25 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, James Clark, Anshuman Khandual,
Will Deacon, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: James Clark <james.clark@linaro.org>
[ Upstream commit 7c3b63386c27bed8d59a4b4c283d02860420eb0a ]
PERF_SAMPLE_BRANCH_HW_INDEX is supported by BRBE so hw_id is passed to
userspace, but it's never set by the BRBE driver. Zero initialize it as
it should be according to the docs:
* For the architectures whose raw branch records are
* already stored in age order, the hw_idx should be 0.
It's probably too risky to remove PERF_SAMPLE_BRANCH_HW_INDEX from BRBE
now in case anyone is setting it and reading the value, but zero
initializing the whole struct also protects against the same issue with
new fields that are added in the future.
Fixes: 58074a0fce66 ("perf: arm_pmuv3: Add support for the Branch Record Buffer Extension (BRBE)")
Signed-off-by: James Clark <james.clark@linaro.org>
Reviewed-by: Anshuman Khandual <anshuman.khandual@arm.com>
Signed-off-by: Will Deacon <will@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/perf/arm_pmuv3.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/perf/arm_pmuv3.c b/drivers/perf/arm_pmuv3.c
index 69c5cc8f56067..265c10f2c8b07 100644
--- a/drivers/perf/arm_pmuv3.c
+++ b/drivers/perf/arm_pmuv3.c
@@ -1351,7 +1351,7 @@ static int branch_records_alloc(struct arm_pmu *armpmu)
struct pmu_hw_events *events_cpu;
events_cpu = per_cpu_ptr(armpmu->hw_events, cpu);
- events_cpu->branch_stack = kmalloc(size, GFP_KERNEL);
+ events_cpu->branch_stack = kzalloc(size, GFP_KERNEL);
if (!events_cpu->branch_stack)
return -ENOMEM;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0974/1518] bpf: Reject load-acquire from pointers requiring fault protection
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (972 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0973/1518] perf: arm_pmuv3: Zero initialize hw_id branch stack field Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0975/1518] bpf, riscv: Add and use bpf_atomic_is_load_acq() helper Greg Kroah-Hartman
` (24 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, STAR Labs SG, Daniel Borkmann,
Kumar Kartikeya Dwivedi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel Borkmann <daniel@iogearbox.net>
[ Upstream commit 7db0a00445f1a40bacfe9b747405c11cb5f10fc9 ]
A BPF_LOAD_ACQ is not rewritten to a BPF_PROBE_MEM load by the verifier,
unlike a regular BPF_LDX, so the JIT emits a plain load with no exception
table entry and a fault panics the kernel instead of being handled.
Reject the source pointer types that a BPF_LDX would have had that fault
protection applied to, i.e. the ones bpf_convert_ctx_accesses() turns
into BPF_PROBE_MEM: a bare PTR_TO_BTF_ID, PTR_TO_BTF_ID | PTR_UNTRUSTED,
PTR_TO_BTF_ID | MEM_ALLOC | PTR_UNTRUSTED and PTR_TO_MEM | MEM_RDONLY |
PTR_UNTRUSTED.
This is reachable e.g. by loading ->mm out of a trusted task_struct
yields an untrusted pointer to mm_struct, and it is NULL for a kernel
thread:
[...]
SEC("tp_btf/sched_switch")
int BPF_PROG(demo, bool preempt, struct task_struct *prev,
struct task_struct *next)
{
struct mm_struct *mm = next->mm; /* untrusted */
out_ldx = (__u64)mm->pgd; /* BPF_LDX */
out_acq = load_acquire(&mm->pgd); /* BPF_LOAD_ACQ */
return 0;
}
[...]
Both dereference the same pointer, but only the BPF_LDX is protected
(x86-64 JIT, jump targets shown prog-relative):
[...]
; out_ldx = (__u64)mm->pgd;
17: movq $-10485760, %r10
1e: movq %rsi, %r11
21: addq $184, %r11
28: subq %r10, %r11
2b: movabsq $140737498841088, %r10
35: cmpq %r10, %r11
38: ja 0x3e <-- kernel addr?
3a: xorl %edi, %edi <-- no: dst = 0, skip the load
3c: jmp 0x45
3e: movq 184(%rsi), %rdi <-- yes: load + extable entry
[...]
; load_acquire(&mm->pgd)
53: movq %rsi, %rdi
56: movq 184(%rdi), %rax <-- no check, no extable entry
[...]
Note that BPF_PROBE_MEM is not visible in a bpftool xlated dump, as
bpf_insn_prepare_dump() rewrites it back to BPF_MEM.
A PTR_TRUSTED pointer is deliberately not on the list. Such a load is
not converted either, but it does not need to be, since the pointer is
guaranteed live, so load-acquire from it stays allowed.
The check is gated on BPF_LOAD_ACQ so that atomic RMW and store-release
error messages are unchanged; writes (RMW / store-release) to such
pointers are already rejected elsewhere, so only load-acquire needs this.
Fixes: 880442305a39 ("bpf: Introduce load-acquire and store-release instructions")
Reported-by: STAR Labs SG <info@starlabs.sg>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/bpf/20260806201047.333389-1-daniel@iogearbox.net
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/bpf/verifier.c | 27 ++++++++++++++++++++++++++-
1 file changed, 26 insertions(+), 1 deletion(-)
diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index 23c9f7b5f522a..78110758ee773 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -6385,6 +6385,30 @@ static bool is_arena_reg(struct bpf_verifier_env *env, int regno)
return reg->type == PTR_TO_ARENA;
}
+static bool is_load_acq_unsafe(struct bpf_verifier_env *env, int regno,
+ struct bpf_insn *insn)
+{
+ const struct bpf_reg_state *reg = reg_state(env, regno);
+
+ /*
+ * A BPF_LOAD_ACQ is not rewritten to a BPF_PROBE_MEM load by the
+ * verifier, unlike a regular BPF_LDX. The JIT would emit a plain load
+ * with no exception table entry, so a fault (e.g. NULL deref) crashes
+ * the kernel instead of being handled.
+ *
+ * Reject the source pointer types that a BPF_LDX would have had that
+ * fault protection applied to, i.e. the ones bpf_convert_ctx_accesses()
+ * turns into BPF_PROBE_MEM: a bare PTR_TO_BTF_ID and any PTR_UNTRUSTED
+ * pointer (untrusted btf ids, untrusted MEM_ALLOC, rdonly untrusted
+ * memory). A PTR_TRUSTED pointer is not among them, is not converted,
+ * and stays allowed. Same for the other flagged PTR_TO_BTF_ID variants
+ * (MEM_ALLOC, MEM_RCU, ...), hence the exact match on the base type.
+ */
+ return insn->imm == BPF_LOAD_ACQ &&
+ (reg->type == PTR_TO_BTF_ID ||
+ (type_flag(reg->type) & PTR_UNTRUSTED));
+}
+
/* Return false if @regno contains a pointer whose type isn't supported for
* atomic instruction @insn.
*/
@@ -6401,7 +6425,8 @@ static bool atomic_ptr_type_ok(struct bpf_verifier_env *env, int regno,
return false;
if (is_arena_reg(env, regno))
return bpf_jit_supports_insn(insn, true);
-
+ if (is_load_acq_unsafe(env, regno, insn))
+ return false;
return true;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0975/1518] bpf, riscv: Add and use bpf_atomic_is_load_acq() helper
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (973 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0974/1518] bpf: Reject load-acquire from pointers requiring fault protection Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0976/1518] bpf, x86: Fix exception table metadata for arena load-acquire Greg Kroah-Hartman
` (23 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Daniel Borkmann,
Kumar Kartikeya Dwivedi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel Borkmann <daniel@iogearbox.net>
[ Upstream commit e2577cd62060be91a3d7d11a56e5a61faae4b7f7 ]
A load-acquire is the only BPF_STX class instruction that reads from
src_reg into dst_reg, that is, it has the operand roles of a BPF_LDX.
JIT code which tells loads from stores apart by instruction class alone
has to special case it, for example when deciding which register holds
the faulting address and which one to clear from an exception handler.
riscv64 already does so, open coded as a bare insn->imm test. Add a
bpf_atomic_is_load_acq() helper and convert riscv64 over to it, so that
the x86-64 and arm64 JITs can use the same helper in subsequent patches.
Unlike bpf_atomic_is_load_store(), which presumes that its argument is
already known to be a BPF_ATOMIC instruction, the new helper is called
from code which still sees all instruction classes, so it checks class
and mode itself.
Also, move bpf_atomic_is_load_store() to filter.h next to BPF_ATOMIC_OP,
so that both helpers stay together. No functional change intended.
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/bpf/20260806201047.333389-2-daniel@iogearbox.net
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Stable-dep-of: 4cf8def58b77 ("bpf, x86: Fix exception table metadata for arena load-acquire")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/riscv/net/bpf_jit_comp64.c | 2 +-
include/linux/bpf.h | 15 ---------------
include/linux/filter.h | 31 +++++++++++++++++++++++++++++++
3 files changed, 32 insertions(+), 16 deletions(-)
diff --git a/arch/riscv/net/bpf_jit_comp64.c b/arch/riscv/net/bpf_jit_comp64.c
index 93beb95d0a886..a90066cc9d58b 100644
--- a/arch/riscv/net/bpf_jit_comp64.c
+++ b/arch/riscv/net/bpf_jit_comp64.c
@@ -1928,7 +1928,7 @@ int bpf_jit_emit_insn(const struct bpf_insn *insn, struct rv_jit_context *ctx,
/* ret can be 1 (skip-zext); extable entry still needs to be added */
if (ret >= 0)
ret = add_exception_handler(insn,
- insn->imm == BPF_LOAD_ACQ ? rd : REG_DONT_CLEAR_MARKER,
+ bpf_atomic_is_load_acq(insn) ? rd : REG_DONT_CLEAR_MARKER,
ctx) ?: ret;
if (ret)
diff --git a/include/linux/bpf.h b/include/linux/bpf.h
index 84a8afc6e6df3..7052507ed4517 100644
--- a/include/linux/bpf.h
+++ b/include/linux/bpf.h
@@ -1044,21 +1044,6 @@ static inline bool bpf_pseudo_func(const struct bpf_insn *insn)
return bpf_is_ldimm64(insn) && insn->src_reg == BPF_PSEUDO_FUNC;
}
-/* Given a BPF_ATOMIC instruction @atomic_insn, return true if it is an
- * atomic load or store, and false if it is a read-modify-write instruction.
- */
-static inline bool
-bpf_atomic_is_load_store(const struct bpf_insn *atomic_insn)
-{
- switch (atomic_insn->imm) {
- case BPF_LOAD_ACQ:
- case BPF_STORE_REL:
- return true;
- default:
- return false;
- }
-}
-
struct bpf_prog_ops {
int (*test_run)(struct bpf_prog *prog, const union bpf_attr *kattr,
union bpf_attr __user *uattr);
diff --git a/include/linux/filter.h b/include/linux/filter.h
index 2469fd2e40157..260a190634055 100644
--- a/include/linux/filter.h
+++ b/include/linux/filter.h
@@ -383,6 +383,37 @@ static inline bool insn_is_cast_user(const struct bpf_insn *insn)
/* Legacy alias */
#define BPF_STX_XADD(SIZE, DST, SRC, OFF) BPF_ATOMIC_OP(SIZE, BPF_ADD, DST, SRC, OFF)
+/*
+ * Given a BPF_ATOMIC instruction @atomic_insn, return true if it is an
+ * atomic load or store, and false if it is a read-modify-write instruction.
+ */
+static inline bool
+bpf_atomic_is_load_store(const struct bpf_insn *atomic_insn)
+{
+ switch (atomic_insn->imm) {
+ case BPF_LOAD_ACQ:
+ case BPF_STORE_REL:
+ return true;
+ default:
+ return false;
+ }
+}
+
+/*
+ * A load-acquire is the only BPF_STX class instruction that reads into
+ * dst_reg from src_reg + off16, i.e. it has the operand roles of a BPF_LDX.
+ * Unlike bpf_atomic_is_load_store(), @insn is not assumed to be a BPF_ATOMIC
+ * instruction here, so that callers which walk all instruction classes can
+ * use this directly.
+ */
+static inline bool bpf_atomic_is_load_acq(const struct bpf_insn *insn)
+{
+ return BPF_CLASS(insn->code) == BPF_STX &&
+ (BPF_MODE(insn->code) == BPF_ATOMIC ||
+ BPF_MODE(insn->code) == BPF_PROBE_ATOMIC) &&
+ insn->imm == BPF_LOAD_ACQ;
+}
+
/* Memory store, *(uint *) (dst_reg + off16) = imm32 */
#define BPF_ST_MEM(SIZE, DST, OFF, IMM) \
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0976/1518] bpf, x86: Fix exception table metadata for arena load-acquire
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (974 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0975/1518] bpf, riscv: Add and use bpf_atomic_is_load_acq() helper Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0977/1518] bpf, arm64: " Greg Kroah-Hartman
` (22 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Daniel Borkmann,
Kumar Kartikeya Dwivedi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel Borkmann <daniel@iogearbox.net>
[ Upstream commit 4cf8def58b779ad2827f81760837b7a844d6c7d6 ]
A load-acquire from an arena pointer is converted to BPF_PROBE_ATOMIC and
gets an exception table entry, but the entry is filled in as if it were a
store, since populate_extable() decides based on instruction class alone
and a load-acquire is of BPF_STX class:
if (BPF_CLASS(insn->code) == BPF_LDX) {
arena_reg = reg2pt_regs[src_reg];
fixup_reg = reg2pt_regs[dst_reg];
} else {
arena_reg = reg2pt_regs[dst_reg];
fixup_reg = DONT_CLEAR;
}
For a load-acquire dst_reg holds the loaded value and src_reg holds the
address, so both assignments in the else branch are wrong. On a fault
over an unmapped arena page ex_handler_bpf() then:
- computes the reported address from the value register instead
of the address register
- reports the access as a WRITE, since it derives the direction
from fixup_reg == DONT_CLEAR
- leaves dst_reg untouched, so the program continues with a stale
value instead of the 0 that BPF_PROBE_* loads deliver
The access itself is emitted correctly, emit_atomic_ld_st_index() uses
src_reg as the address, so this is a broken probe contract and a wrong
diagnostic rather than a memory safety issue.
Use bpf_atomic_is_load_acq() helper so a load-acquire takes the load path.
Fixes: 5341c9a4d833 ("bpf, x86: Support load-acquire and store-release instructions")
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/bpf/20260806201047.333389-3-daniel@iogearbox.net
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/net/bpf_jit_comp.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/arch/x86/net/bpf_jit_comp.c b/arch/x86/net/bpf_jit_comp.c
index cfd44906c31dd..39cf6974e11e1 100644
--- a/arch/x86/net/bpf_jit_comp.c
+++ b/arch/x86/net/bpf_jit_comp.c
@@ -2175,8 +2175,13 @@ st: if (is_imm8(insn->off))
* BPF_PROBE_ATOMIC) before being used for the memory access. Pass
* the reg holding the unmodified 32-bit address to
* ex_handler_bpf().
+ *
+ * A load-acquire is of BPF_STX class, but reads from src_reg
+ * into dst_reg like a BPF_LDX does, hence it must not be
+ * treated as a store here.
*/
- if (BPF_CLASS(insn->code) == BPF_LDX) {
+ if (BPF_CLASS(insn->code) == BPF_LDX ||
+ bpf_atomic_is_load_acq(insn)) {
arena_reg = reg2pt_regs[src_reg];
fixup_reg = reg2pt_regs[dst_reg];
} else {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0977/1518] bpf, arm64: Fix exception table metadata for arena load-acquire
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (975 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0976/1518] bpf, x86: Fix exception table metadata for arena load-acquire Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0978/1518] regulator: qcom-rpmh: Fix PMIC5 BOB bypass mode handling Greg Kroah-Hartman
` (21 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Daniel Borkmann, Puranjay Mohan,
Kumar Kartikeya Dwivedi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Daniel Borkmann <daniel@iogearbox.net>
[ Upstream commit af22d273aa1f61fb86ec712b3ed785da73c3296e ]
Same problem as on x86-64: add_exception_handler() decides whether an
instruction is a load by its class, and a load-acquire is of BPF_STX
class even though it reads from src_reg into dst_reg. As a result ...
if (BPF_CLASS(insn->code) != BPF_LDX)
dst_reg = DONT_CLEAR;
... drops the register to clear, and ...
if (BPF_CLASS(insn->code) == BPF_LDX)
arena_reg = bpf2a64[insn->src_reg];
else
arena_reg = bpf2a64[insn->dst_reg];
... hands ex_handler_bpf() the value register instead of the address
register. A load-acquire from an arena pointer that faults on an
unmapped page is therefore reported as a WRITE at a bogus address,
and dst_reg keeps its previous value instead of being cleared to 0.
Note that emit_atomic_ld_st() already picks src_reg as the address
for BPF_LOAD_ACQ, so only the exception table metadata was out of sync
with the emitted access.
Same as on x86-64, use bpf_atomic_is_load_acq() so a load-acquire takes
the load path.
Fixes: 9bb12368d539 ("bpf, arm64: Support load-acquire and store-release instructions")
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Reviewed-by: Puranjay Mohan <puranjay@kernel.org>
Link: https://lore.kernel.org/bpf/20260806201047.333389-4-daniel@iogearbox.net
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/arm64/net/bpf_jit_comp.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/arch/arm64/net/bpf_jit_comp.c b/arch/arm64/net/bpf_jit_comp.c
index c563bae8fce1c..bcfadc49d2096 100644
--- a/arch/arm64/net/bpf_jit_comp.c
+++ b/arch/arm64/net/bpf_jit_comp.c
@@ -1168,7 +1168,12 @@ static int add_exception_handler(const struct bpf_insn *insn,
ex->insn = ins_offset;
- if (BPF_CLASS(insn->code) != BPF_LDX)
+ /*
+ * A load-acquire is of BPF_STX class, but reads from src_reg into
+ * dst_reg like a BPF_LDX does, hence it must not be treated as a store
+ * here.
+ */
+ if (BPF_CLASS(insn->code) != BPF_LDX && !bpf_atomic_is_load_acq(insn))
dst_reg = DONT_CLEAR;
ex->fixup = FIELD_PREP(BPF_FIXUP_REG_MASK, dst_reg);
@@ -1183,7 +1188,7 @@ static int add_exception_handler(const struct bpf_insn *insn,
* memory access. Pass the reg holding the unmodified 32-bit address to
* ex_handler_bpf.
*/
- if (BPF_CLASS(insn->code) == BPF_LDX)
+ if (BPF_CLASS(insn->code) == BPF_LDX || bpf_atomic_is_load_acq(insn))
arena_reg = bpf2a64[insn->src_reg];
else
arena_reg = bpf2a64[insn->dst_reg];
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0978/1518] regulator: qcom-rpmh: Fix PMIC5 BOB bypass mode handling
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (976 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0977/1518] bpf, arm64: " Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0979/1518] ACPI: video: Release PCI device reference after lookup Greg Kroah-Hartman
` (20 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Dmitry Baryshkov, Konrad Dybcio,
Kamal Wadhwa, Mark Brown, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Kamal Wadhwa <kamal.wadhwa@oss.qualcomm.com>
[ Upstream commit abd14bebb87e0fa2749371272c8b31d6ee5f0a36 ]
Currently, when `rpmh_regulator_set_mode_bypass()` helper function
is called to set bypass mode, it sends PMIC4's BOB bypass mode
value for even if its a PMIC5 BOB.
To fix this, introduce new hw_data parameter`pmic_bypass_mode`
to store bypass mode value. Use it to send correct PMIC bypass
mode value that corresponds to PMIC4/5 BOB regulators from the
helper function.
Fixes: 610f29e5cc0e8d58 ("regulator: qcom-rpmh: Update PMIC modes for PMIC5")
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Signed-off-by: Kamal Wadhwa <kamal.wadhwa@oss.qualcomm.com>
Link: https://patch.msgid.link/20260801-b4-read-rpmh-v5-v6-2-9fcb54928523@oss.qualcomm.com
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/regulator/qcom-rpmh-regulator.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/drivers/regulator/qcom-rpmh-regulator.c b/drivers/regulator/qcom-rpmh-regulator.c
index 109f0aae09b1d..933eb0c28fa65 100644
--- a/drivers/regulator/qcom-rpmh-regulator.c
+++ b/drivers/regulator/qcom-rpmh-regulator.c
@@ -77,6 +77,7 @@ enum rpmh_regulator_type {
* @hpm_min_load_uA: Minimum load current in microamps that requires
* high power mode (HPM) operation. This is used
* for LDO hardware type regulators only.
+ * @pmic_bypass_mode: The PMIC bypass mode value.
* @pmic_mode_map: Array indexed by regulator framework mode
* containing PMIC hardware modes. Must be large
* enough to index all framework modes supported
@@ -91,6 +92,7 @@ struct rpmh_vreg_hw_data {
int n_linear_ranges;
int n_voltages;
int hpm_min_load_uA;
+ int pmic_bypass_mode;
const int *pmic_mode_map;
unsigned int (*of_map_mode)(unsigned int mode);
};
@@ -277,7 +279,7 @@ static int rpmh_regulator_vrm_set_mode_bypass(struct rpmh_vreg *vreg,
return pmic_mode;
if (bypassed)
- cmd.data = PMIC4_BOB_MODE_PASS;
+ cmd.data = vreg->hw_data->pmic_bypass_mode;
else
cmd.data = pmic_mode;
@@ -692,6 +694,7 @@ static const struct rpmh_vreg_hw_data pmic4_bob = {
},
.n_linear_ranges = 1,
.n_voltages = 84,
+ .pmic_bypass_mode = PMIC4_BOB_MODE_PASS,
.pmic_mode_map = pmic_mode_map_pmic4_bob,
.of_map_mode = rpmh_regulator_pmic4_bob_of_map_mode,
};
@@ -900,6 +903,7 @@ static const struct rpmh_vreg_hw_data pmic5_bob = {
},
.n_linear_ranges = 1,
.n_voltages = 32,
+ .pmic_bypass_mode = PMIC5_BOB_MODE_PASS,
.pmic_mode_map = pmic_mode_map_pmic5_bob,
.of_map_mode = rpmh_regulator_pmic4_bob_of_map_mode,
};
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0979/1518] ACPI: video: Release PCI device reference after lookup
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (977 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0978/1518] regulator: qcom-rpmh: Fix PMIC5 BOB bypass mode handling Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0980/1518] perf/x86/intel/pt: Factor out pt_config_enable() Greg Kroah-Hartman
` (19 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Yuho Choi, Rafael J. Wysocki,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yuho Choi <dbgh9129@gmail.com>
[ Upstream commit 3d7ed9b8ef47b8bcae1fc3e12f7590a217862a89 ]
video_detect_portege_r100() uses pci_get_device() only as a boolean
check for the Trident CyberBlade XP4m32 device. pci_get_device() takes a
reference on a matching PCI device, but the callback returns without
releasing it.
Drop the reference after selecting the vendor backlight quirk so the PCI
device can be released normally.
Fixes: 35a341c9b25d ("ACPI: video: Add acpi_backlight=vendor quirk for Toshiba Portégé R100")
Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
Link: https://patch.msgid.link/20260807015734.913361-1-dbgh9129@gmail.com
Signed-off-by: Rafael J. Wysocki <rafael.j.wysocki@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/acpi/video_detect.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/acpi/video_detect.c b/drivers/acpi/video_detect.c
index 2c120ade8f51a..2a562cb425081 100644
--- a/drivers/acpi/video_detect.c
+++ b/drivers/acpi/video_detect.c
@@ -137,8 +137,10 @@ static int video_detect_portege_r100(const struct dmi_system_id *d)
struct pci_dev *dev;
/* Search for Trident CyberBlade XP4m32 to confirm Portégé R100 */
dev = pci_get_device(PCI_VENDOR_ID_TRIDENT, 0x2100, NULL);
- if (dev)
+ if (dev) {
acpi_backlight_dmi = acpi_backlight_vendor;
+ pci_dev_put(dev);
+ }
return 0;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0980/1518] perf/x86/intel/pt: Factor out pt_config_enable()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (978 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0979/1518] ACPI: video: Release PCI device reference after lookup Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0981/1518] perf/x86/intel/pt: Use bitwise access for PERF_HES_STOPPED Greg Kroah-Hartman
` (18 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Adrian Hunter,
Peter Zijlstra (Intel), Yi Lai, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Adrian Hunter <adrian.hunter@intel.com>
[ Upstream commit c6df517796189723ffbdd7679206c97d3642c2ef ]
pt_config() enables tracing by allowing NMIs and pause/resume, issuing
the necessary barriers, and calling pt_config_start(). A later change
needs to re-enable tracing on a (re-)start path without repeating the
full pt_config() setup (filters, RTIT_CTL, buffer configuration).
Factor that enabling sequence out into a new helper, pt_config_enable(),
so it can be called on its own.
No functional change intended.
Signed-off-by: Adrian Hunter <adrian.hunter@intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Tested-by: Yi Lai <yi1.lai@intel.com>
Link: https://patch.msgid.link/20260721070254.13557-2-adrian.hunter@intel.com
Stable-dep-of: 2e17bf3a469a ("perf/x86/intel/pt: Fix stop/start with no update")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/events/intel/pt.c | 41 ++++++++++++++++++++++----------------
1 file changed, 24 insertions(+), 17 deletions(-)
diff --git a/arch/x86/events/intel/pt.c b/arch/x86/events/intel/pt.c
index e8cf29d2b10c9..82725b11007a6 100644
--- a/arch/x86/events/intel/pt.c
+++ b/arch/x86/events/intel/pt.c
@@ -501,6 +501,29 @@ static u64 pt_config_filters(struct perf_event *event)
return rtit_ctl;
}
+static void pt_config_enable(struct perf_event *event)
+{
+ struct pt *pt = this_cpu_ptr(&pt_ctx);
+
+ /*
+ * Allow resume before starting so as not to overwrite a value set by a
+ * PMI.
+ */
+ barrier();
+ WRITE_ONCE(pt->resume_allowed, 1);
+ /* Configuration is complete, it is now OK to handle an NMI */
+ barrier();
+ WRITE_ONCE(pt->handle_nmi, 1);
+ barrier();
+ pt_config_start(event);
+ barrier();
+ /*
+ * Allow pause after starting so its pt_config_stop() doesn't race with
+ * pt_config_start().
+ */
+ WRITE_ONCE(pt->pause_allowed, 1);
+}
+
static void pt_config(struct perf_event *event)
{
struct pt *pt = this_cpu_ptr(&pt_ctx);
@@ -540,23 +563,7 @@ static void pt_config(struct perf_event *event)
event->hw.aux_config = reg;
- /*
- * Allow resume before starting so as not to overwrite a value set by a
- * PMI.
- */
- barrier();
- WRITE_ONCE(pt->resume_allowed, 1);
- /* Configuration is complete, it is now OK to handle an NMI */
- barrier();
- WRITE_ONCE(pt->handle_nmi, 1);
- barrier();
- pt_config_start(event);
- barrier();
- /*
- * Allow pause after starting so its pt_config_stop() doesn't race with
- * pt_config_start().
- */
- WRITE_ONCE(pt->pause_allowed, 1);
+ pt_config_enable(event);
}
static void pt_config_stop(struct perf_event *event)
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0981/1518] perf/x86/intel/pt: Use bitwise access for PERF_HES_STOPPED
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (979 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0980/1518] perf/x86/intel/pt: Factor out pt_config_enable() Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0982/1518] perf/x86/intel/pt: Fix stop/start with no update Greg Kroah-Hartman
` (17 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Adrian Hunter,
Peter Zijlstra (Intel), Yi Lai, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Adrian Hunter <adrian.hunter@intel.com>
[ Upstream commit 265bb4ef75fa657f4957d72087a6a246b89d5f0d ]
The Intel PT driver reads and writes event->hw.state as a whole value,
assuming it is either 0 or PERF_HES_STOPPED. That is true today, but a
subsequent fix needs to also track an open AUX output buffer using the
PERF_HES_UPTODATE bit of the same field.
When more than one bit can be set, whole-value assignments would
overwrite the other bits and whole-value comparisons would fail to match.
Convert all accesses to set, clear and test the PERF_HES_STOPPED bit
individually, in preparation for that change.
No functional change intended: event->hw.state currently only ever
holds 0 or PERF_HES_STOPPED, so the bitwise forms are equivalent.
Signed-off-by: Adrian Hunter <adrian.hunter@intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Tested-by: Yi Lai <yi1.lai@intel.com>
Link: https://patch.msgid.link/20260721070254.13557-3-adrian.hunter@intel.com
Stable-dep-of: 2e17bf3a469a ("perf/x86/intel/pt: Fix stop/start with no update")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/events/intel/pt.c | 16 ++++++++--------
1 file changed, 8 insertions(+), 8 deletions(-)
diff --git a/arch/x86/events/intel/pt.c b/arch/x86/events/intel/pt.c
index 82725b11007a6..70bee69c598bc 100644
--- a/arch/x86/events/intel/pt.c
+++ b/arch/x86/events/intel/pt.c
@@ -1539,12 +1539,12 @@ void intel_pt_interrupt(void)
perf_aux_output_end(&pt->handle, local_xchg(&buf->data_size, 0));
- if (!event->hw.state) {
+ if (!(event->hw.state & PERF_HES_STOPPED)) {
int ret;
buf = perf_aux_output_begin(&pt->handle, event);
if (!buf) {
- event->hw.state = PERF_HES_STOPPED;
+ event->hw.state |= PERF_HES_STOPPED;
WRITE_ONCE(pt->resume_allowed, 0);
return;
}
@@ -1639,7 +1639,7 @@ static void pt_event_start(struct perf_event *event, int mode)
goto fail_end_stop;
}
- hwc->state = 0;
+ hwc->state &= ~PERF_HES_STOPPED;
pt_config_buffer(buf);
pt_config(event);
@@ -1649,7 +1649,7 @@ static void pt_event_start(struct perf_event *event, int mode)
fail_end_stop:
perf_aux_output_end(&pt->handle, 0);
fail_stop:
- hwc->state = PERF_HES_STOPPED;
+ hwc->state |= PERF_HES_STOPPED;
}
static void pt_event_stop(struct perf_event *event, int mode)
@@ -1680,10 +1680,10 @@ static void pt_event_stop(struct perf_event *event, int mode)
pt_config_stop(event);
- if (event->hw.state == PERF_HES_STOPPED)
+ if (event->hw.state & PERF_HES_STOPPED)
return;
- event->hw.state = PERF_HES_STOPPED;
+ event->hw.state |= PERF_HES_STOPPED;
if (mode & PERF_EF_UPDATE) {
struct pt_buffer *buf = perf_get_aux(&pt->handle);
@@ -1778,10 +1778,10 @@ static int pt_event_add(struct perf_event *event, int mode)
if (mode & PERF_EF_START) {
pt_event_start(event, 0);
ret = -EINVAL;
- if (hwc->state == PERF_HES_STOPPED)
+ if (hwc->state & PERF_HES_STOPPED)
goto fail;
} else {
- hwc->state = PERF_HES_STOPPED;
+ hwc->state |= PERF_HES_STOPPED;
}
ret = 0;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0982/1518] perf/x86/intel/pt: Fix stop/start with no update
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (980 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0981/1518] perf/x86/intel/pt: Use bitwise access for PERF_HES_STOPPED Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0983/1518] sched/fair: Also gate overloaded status update for SD_ASYM_CPUCAPACITY Greg Kroah-Hartman
` (16 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Adrian Hunter,
Peter Zijlstra (Intel), Yi Lai, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Adrian Hunter <adrian.hunter@intel.com>
[ Upstream commit 2e17bf3a469a41457a3bc31b1f8fd66b6ce94a6d ]
If pt_event_stop() is called without PERF_EF_UPDATE flag, then
perf_aux_output_end() is not called. A subsequent call to pt_event_start()
will call perf_aux_output_begin() again which violates the rule against
nesting and triggers a WARNING in perf_aux_output_begin().
Originally, pt_event_stop() was never called without PERF_EF_UPDATE,
because the only code paths to do so are from event overflow, and Intel PT
does not do that.
However the introduction of group throttling by commit 9734e25fbf5ae
("perf: Fix the throttle logic for a group") meant that an Intel PT event
could be throttled if it was part of a group. Throttling calls PMU
->stop() / ->start() callbacks without flags.
An example is when AUX area sampling is used. The following commands
hit the issue:
echo 10000 > /proc/sys/kernel/perf_event_max_sample_rate
perf record -F32000 --aux-sample -e '{intel_pt//u,cycles:u}' \
-- bash -c 'for i in `seq 1 100000` ; do true ; done'
Use PERF_HES_UPTODATE to track whether perf_aux_output_begin() and
perf_aux_output_end() are balanced. A cleared PERF_HES_UPTODATE bit
indicates that an AUX output context is still open.
Amend pt_event_start() / pt_event_stop() accordingly so that begin/end
stay balanced:
- In non-snapshot mode, stop() always closes the buffer (the buffer may
have run out of space, and that accounting is done by the update), so
a following start() opens a fresh one as before.
- In snapshot/overwrite mode, stop() without PERF_EF_UPDATE leaves the
buffer open so that pt_event_snapshot_aux() can still copy from it,
and start() then only re-enables tracing instead of calling
perf_aux_output_begin() again.
Note that pt_event_del() calls pt_event_stop() with PERF_EF_UPDATE flag set
(as is required by the documentation), so a final call to
perf_aux_output_end() is assured.
Fixes: 52ca9ced3f707 ("perf/x86/intel/pt: Add Intel PT PMU driver")
Signed-off-by: Adrian Hunter <adrian.hunter@intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Tested-by: Yi Lai <yi1.lai@intel.com>
Link: https://patch.msgid.link/20260721070254.13557-4-adrian.hunter@intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
arch/x86/events/intel/pt.c | 45 ++++++++++++++++++++++++++++++--------
1 file changed, 36 insertions(+), 9 deletions(-)
diff --git a/arch/x86/events/intel/pt.c b/arch/x86/events/intel/pt.c
index 70bee69c598bc..a2937f82ccd44 100644
--- a/arch/x86/events/intel/pt.c
+++ b/arch/x86/events/intel/pt.c
@@ -1539,6 +1539,8 @@ void intel_pt_interrupt(void)
perf_aux_output_end(&pt->handle, local_xchg(&buf->data_size, 0));
+ event->hw.state |= PERF_HES_UPTODATE;
+
if (!(event->hw.state & PERF_HES_STOPPED)) {
int ret;
@@ -1560,6 +1562,8 @@ void intel_pt_interrupt(void)
pt_config_buffer(buf);
pt_config_start(event);
+
+ event->hw.state &= ~PERF_HES_UPTODATE;
}
}
@@ -1629,6 +1633,18 @@ static void pt_event_start(struct perf_event *event, int mode)
return;
}
+ /*
+ * Re-start subsequent to a call to pt_event_stop() without the
+ * PERF_EF_UPDATE flag. Absence of PERF_HES_UPTODATE indicates that
+ * perf_aux_output_begin() has already been called. This path can
+ * come about only in snapshot/overwrite mode - see pt_event_stop().
+ */
+ if (!(hwc->state & PERF_HES_UPTODATE)) {
+ hwc->state &= ~PERF_HES_STOPPED;
+ pt_config_enable(event);
+ return;
+ }
+
buf = perf_aux_output_begin(&pt->handle, event);
if (!buf)
goto fail_stop;
@@ -1639,7 +1655,7 @@ static void pt_event_start(struct perf_event *event, int mode)
goto fail_end_stop;
}
- hwc->state &= ~PERF_HES_STOPPED;
+ hwc->state &= ~(PERF_HES_STOPPED | PERF_HES_UPTODATE);
pt_config_buffer(buf);
pt_config(event);
@@ -1649,12 +1665,13 @@ static void pt_event_start(struct perf_event *event, int mode)
fail_end_stop:
perf_aux_output_end(&pt->handle, 0);
fail_stop:
- hwc->state |= PERF_HES_STOPPED;
+ hwc->state |= PERF_HES_STOPPED | PERF_HES_UPTODATE;
}
static void pt_event_stop(struct perf_event *event, int mode)
{
struct pt *pt = this_cpu_ptr(&pt_ctx);
+ struct pt_buffer *buf;
if (mode & PERF_EF_PAUSE) {
if (READ_ONCE(pt->pause_allowed))
@@ -1680,17 +1697,24 @@ static void pt_event_stop(struct perf_event *event, int mode)
pt_config_stop(event);
- if (event->hw.state & PERF_HES_STOPPED)
- return;
-
event->hw.state |= PERF_HES_STOPPED;
- if (mode & PERF_EF_UPDATE) {
- struct pt_buffer *buf = perf_get_aux(&pt->handle);
+ if (event->hw.state & PERF_HES_UPTODATE)
+ return;
- if (!buf)
- return;
+ buf = perf_get_aux(&pt->handle);
+ if (!buf)
+ return;
+ /*
+ * When not in snapshot/overwrite mode, there is a possibility that the
+ * buffer has run out of space. The accounting for that is handled by
+ * the update, so always update in that case. Snapshot/overwrite mode is
+ * treated differently to allow for pt_event_snapshot_aux() which can
+ * still get called if the AUX-sampling event is not stopped until after
+ * PT is stopped.
+ */
+ if ((mode & PERF_EF_UPDATE) || !buf->snapshot) {
if (WARN_ON_ONCE(pt->handle.event != event))
return;
@@ -1705,6 +1729,7 @@ static void pt_event_stop(struct perf_event *event, int mode)
local_xchg(&buf->data_size,
buf->nr_pages << PAGE_SHIFT);
perf_aux_output_end(&pt->handle, local_xchg(&buf->data_size, 0));
+ event->hw.state |= PERF_HES_UPTODATE;
}
}
@@ -1775,6 +1800,8 @@ static int pt_event_add(struct perf_event *event, int mode)
if (pt->handle.event)
goto fail;
+ event->hw.state |= PERF_HES_UPTODATE;
+
if (mode & PERF_EF_START) {
pt_event_start(event, 0);
ret = -EINVAL;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0983/1518] sched/fair: Also gate overloaded status update for SD_ASYM_CPUCAPACITY
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (981 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0982/1518] perf/x86/intel/pt: Fix stop/start with no update Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0984/1518] sched/fair: Check CPU capacity before comparing group types during load balance Greg Kroah-Hartman
` (15 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Chen Yu, Ricardo Neri,
Peter Zijlstra (Intel), Vincent Guittot, Christian Loehle,
Andrea Righi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ricardo Neri <ricardo.neri-calderon@linux.intel.com>
[ Upstream commit 6060d61d13a10da8c90da4eadf4a421825149883 ]
The argument sg_overloaded of update_sg_lb_stats() is only consumed when
balancing at the root domain. It only makes sense to update it in such a
case. Commit 3229adbe7875 ("sched/fair: Do not compute overloaded status
unnecessarily during lb") updated the logic accordingly but missed the case
in which the root domain has the SD_ASYM_CPUCAPACITY flag. Fix this.
Fixes: 3229adbe7875 ("sched/fair: Do not compute overloaded status unnecessarily during lb")
Reported-by: Chen Yu <yu.c.chen@intel.com>
Signed-off-by: Ricardo Neri <ricardo.neri-calderon@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Reviewed-by: Vincent Guittot <vincent.guittot@linaro.org>
Tested-by: Christian Loehle <christian.loehle@arm.com>
Tested-by: Andrea Righi <arighi@nvidia.com>
Link: https://patch.msgid.link/20260720-rneri-fix-cas-clusters-v6-2-bb500bf4afd4@linux.intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/sched/fair.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/kernel/sched/fair.c b/kernel/sched/fair.c
index 30ebe2823d238..5620c8d3a99a6 100644
--- a/kernel/sched/fair.c
+++ b/kernel/sched/fair.c
@@ -10680,7 +10680,9 @@ static inline void update_sg_lb_stats(struct lb_env *env,
/* Check for a misfit task on the cpu */
if (sgs->group_misfit_task_load < rq->misfit_task_load) {
sgs->group_misfit_task_load = rq->misfit_task_load;
- *sg_overloaded = 1;
+
+ if (balancing_at_rd)
+ *sg_overloaded = 1;
}
} else if (env->idle && sched_reduced_capacity(rq, env->sd)) {
/* Check for a task running on a CPU with reduced capacity */
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0984/1518] sched/fair: Check CPU capacity before comparing group types during load balance
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (982 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0983/1518] sched/fair: Also gate overloaded status update for SD_ASYM_CPUCAPACITY Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0985/1518] Bluetooth: btqca: Fix qca_set_bdaddr() waiting for wrong HCI event Greg Kroah-Hartman
` (14 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Ricardo Neri, Peter Zijlstra (Intel),
Christian Loehle, Chen Yu, Tim Chen, Vincent Guittot,
Andrea Righi, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Ricardo Neri <ricardo.neri-calderon@linux.intel.com>
[ Upstream commit 50b101f6e586b4417d060a976fd831cd87e86e2b ]
update_sd_pick_busiest() may incorrectly select a fully_busy group as the
busiest group when its per-CPU capacity exceeds that of the destination
CPU. This happens because the type of busiest group is initialized to
group_has_spare and allows the fully_busy group to win the type comparison.
update_sd_pick_busiest() should not choose a candidate scheduling group
with at most one runnable task if its per-CPU capacity is greater than that
of the destination CPU. Such a check already exists, but it is done too
late: after the type comparison, preventing a subsequent fully_busy group
of equal per-CPU capacity from being correctly selected.
Move this check to occur before comparing group types.
Fixes: 0b0695f2b34a ("sched/fair: Rework load_balance()")
Signed-off-by: Ricardo Neri <ricardo.neri-calderon@linux.intel.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Reviewed-by: Christian Loehle <christian.loehle@arm.com>
Reviewed-by: Chen Yu <yu.c.chen@intel.com>
Reviewed-by: Tim Chen <tim.c.chen@linux.intel.com>
Reviewed-by: Vincent Guittot <vincent.guittot@linaro.org>
Tested-by: Christian Loehle <christian.loehle@arm.com>
Tested-by: Andrea Righi <arighi@nvidia.com>
Link: https://patch.msgid.link/20260720-rneri-fix-cas-clusters-v6-3-bb500bf4afd4@linux.intel.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
kernel/sched/fair.c | 22 +++++++++++-----------
1 file changed, 11 insertions(+), 11 deletions(-)
diff --git a/kernel/sched/fair.c b/kernel/sched/fair.c
index 5620c8d3a99a6..4f02f823d1042 100644
--- a/kernel/sched/fair.c
+++ b/kernel/sched/fair.c
@@ -10748,6 +10748,17 @@ static bool update_sd_pick_busiest(struct lb_env *env,
sds->local_stat.group_type != group_has_spare))
return false;
+ /*
+ * Candidate sg has no more than one task per CPU and has higher
+ * per-CPU capacity. Migrating tasks to less capable CPUs may harm
+ * throughput. Maximize throughput, power/energy consequences are not
+ * considered.
+ */
+ if ((env->sd->flags & SD_ASYM_CPUCAPACITY) &&
+ (sgs->group_type <= group_fully_busy) &&
+ (capacity_greater(sg->sgc->min_capacity, capacity_of(env->dst_cpu))))
+ return false;
+
if (sgs->group_type > busiest->group_type)
return true;
@@ -10850,17 +10861,6 @@ static bool update_sd_pick_busiest(struct lb_env *env,
break;
}
- /*
- * Candidate sg has no more than one task per CPU and has higher
- * per-CPU capacity. Migrating tasks to less capable CPUs may harm
- * throughput. Maximize throughput, power/energy consequences are not
- * considered.
- */
- if ((env->sd->flags & SD_ASYM_CPUCAPACITY) &&
- (sgs->group_type <= group_fully_busy) &&
- (capacity_greater(sg->sgc->min_capacity, capacity_of(env->dst_cpu))))
- return false;
-
return true;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0985/1518] Bluetooth: btqca: Fix qca_set_bdaddr() waiting for wrong HCI event
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (983 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0984/1518] sched/fair: Check CPU capacity before comparing group types during load balance Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0986/1518] Bluetooth: btusb: Fix BD_ADDR byte order in btusb_set_bdaddr_wcn6855() Greg Kroah-Hartman
` (13 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Bartosz Golaszewski, Zijun Hu,
Luiz Augusto von Dentz, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zijun Hu <zijun.hu@oss.qualcomm.com>
[ Upstream commit cf81f0a3db2a5c34ee6e4ea379c631fab6d13e01 ]
qca_set_bdaddr() waits for HCI_EV_VENDOR when sending
EDL_WRITE_BD_ADDR_OPCODE (0xFC14), but the controller responds with
Command Complete event as confirmed by btmon on WCN7850:
< HCI Command: Vendor (0x3f|0x0014) plen 6 #3 [hci0]
11 22 33 44 55 66
> HCI Event: Command Complete (0x0e) plen 4 #4 [hci0]
Vendor (0x3f|0x0014) ncmd 1
Status: Success (0x00)
Fix by passing 0 as the event parameter to __hci_cmd_sync_ev() to
wait for the command complete event instead.
Fixes: 5c0a1001c8be ("Bluetooth: hci_qca: Add helper to set device address")
Reviewed-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Signed-off-by: Zijun Hu <zijun.hu@oss.qualcomm.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btqca.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/bluetooth/btqca.c b/drivers/bluetooth/btqca.c
index afab479ac8944..f404eefbfc85b 100644
--- a/drivers/bluetooth/btqca.c
+++ b/drivers/bluetooth/btqca.c
@@ -1014,8 +1014,7 @@ int qca_set_bdaddr(struct hci_dev *hdev, const bdaddr_t *bdaddr)
baswap(&bdaddr_swapped, bdaddr);
skb = __hci_cmd_sync_ev(hdev, EDL_WRITE_BD_ADDR_OPCODE, 6,
- &bdaddr_swapped, HCI_EV_VENDOR,
- HCI_INIT_TIMEOUT);
+ &bdaddr_swapped, 0, HCI_INIT_TIMEOUT);
if (IS_ERR(skb)) {
err = PTR_ERR(skb);
bt_dev_err(hdev, "QCA Change address cmd failed (%d)", err);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0986/1518] Bluetooth: btusb: Fix BD_ADDR byte order in btusb_set_bdaddr_wcn6855()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (984 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0985/1518] Bluetooth: btqca: Fix qca_set_bdaddr() waiting for wrong HCI event Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0987/1518] Bluetooth: btusb: refactor endpoint lookup Greg Kroah-Hartman
` (12 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zijun Hu, Luiz Augusto von Dentz,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zijun Hu <zijun.hu@oss.qualcomm.com>
[ Upstream commit d0b15d812688d3f0f3fe1c4426e12814d0c294dc ]
btusb_set_bdaddr_wcn6855() sends the address without swapping byte
order for VSC 0xFC14, but the command expects the address in reversed
byte order compared to other HCI commands like HCI_Create_Connection,
resulting in a wrong BD_ADDR being set.
btmon log on WCN6855 shows VSC 0xFC14 is sent with swapped bytes
11 22 33 44 55 66, and Read BD ADDR returns the expected address
11:22:33:44:55:66:
< HCI Command: Vendor (0x3f|0x0014) plen 6 #3 [hci0]
11 22 33 44 55 66
> HCI Event: Command Complete (0x0e) plen 4 #4 [hci0]
Vendor (0x3f|0x0014) ncmd 1
Status: Success (0x00)
< HCI Command: Read BD ADDR (0x04|0x0009) plen 0 #11 [hci0]
> HCI Event: Command Complete (0x0e) plen 10 #12 [hci0]
Read BD ADDR (0x04|0x0009) ncmd 1
Status: Success (0x00)
Address: 11:22:33:44:55:66 (OUI 11-22-33)
Fix by swapping the input address before issuing the command.
Fixes: b40f58b97386 ("Bluetooth: btusb: Add Qualcomm Bluetooth SoC WCN6855 support")
Signed-off-by: Zijun Hu <zijun.hu@oss.qualcomm.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btusb.c | 9 +++++----
1 file changed, 5 insertions(+), 4 deletions(-)
diff --git a/drivers/bluetooth/btusb.c b/drivers/bluetooth/btusb.c
index a869fd15bc896..cc972ddd09785 100644
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -3006,14 +3006,15 @@ static int btusb_set_bdaddr_ath3012(struct hci_dev *hdev,
static int btusb_set_bdaddr_wcn6855(struct hci_dev *hdev,
const bdaddr_t *bdaddr)
{
+ bdaddr_t bdaddr_swapped;
struct sk_buff *skb;
- u8 buf[6];
long ret;
- memcpy(buf, bdaddr, sizeof(bdaddr_t));
+ baswap(&bdaddr_swapped, bdaddr);
- skb = __hci_cmd_sync_ev(hdev, 0xfc14, sizeof(buf), buf,
- HCI_EV_CMD_COMPLETE, HCI_INIT_TIMEOUT);
+ skb = __hci_cmd_sync_ev(hdev, 0xfc14, sizeof(bdaddr_swapped),
+ &bdaddr_swapped, HCI_EV_CMD_COMPLETE,
+ HCI_INIT_TIMEOUT);
if (IS_ERR(skb)) {
ret = PTR_ERR(skb);
bt_dev_err(hdev, "Change address command failed (%ld)", ret);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0987/1518] Bluetooth: btusb: refactor endpoint lookup
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (985 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0986/1518] Bluetooth: btusb: Fix BD_ADDR byte order in btusb_set_bdaddr_wcn6855() Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0988/1518] Bluetooth: btusb: Record matched usb_device_id into btusb_data Greg Kroah-Hartman
` (11 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Johan Hovold, Luiz Augusto von Dentz,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Johan Hovold <johan@kernel.org>
[ Upstream commit 5c31aaa05624b54dc18c9e313bcee5a88c025593 ]
Use the common USB helper for looking up bulk and interrupt endpoints
instead of open coding.
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Stable-dep-of: 33c6a8d01889 ("Bluetooth: btusb: QCA: Fix populating devcoredump fields on unenabled devices")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btusb.c | 51 ++++++---------------------------------
1 file changed, 8 insertions(+), 43 deletions(-)
diff --git a/drivers/bluetooth/btusb.c b/drivers/bluetooth/btusb.c
index cc972ddd09785..f399599f4b3bf 100644
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -3658,31 +3658,14 @@ static inline int __set_diag_interface(struct hci_dev *hdev)
{
struct btusb_data *data = hci_get_drvdata(hdev);
struct usb_interface *intf = data->diag;
- int i;
+ int ret;
if (!data->diag)
return -ENODEV;
- data->diag_tx_ep = NULL;
- data->diag_rx_ep = NULL;
-
- for (i = 0; i < intf->cur_altsetting->desc.bNumEndpoints; i++) {
- struct usb_endpoint_descriptor *ep_desc;
-
- ep_desc = &intf->cur_altsetting->endpoint[i].desc;
-
- if (!data->diag_tx_ep && usb_endpoint_is_bulk_out(ep_desc)) {
- data->diag_tx_ep = ep_desc;
- continue;
- }
-
- if (!data->diag_rx_ep && usb_endpoint_is_bulk_in(ep_desc)) {
- data->diag_rx_ep = ep_desc;
- continue;
- }
- }
-
- if (!data->diag_tx_ep || !data->diag_rx_ep) {
+ ret = usb_find_common_endpoints(intf->cur_altsetting, &data->diag_rx_ep,
+ &data->diag_tx_ep, NULL, NULL);
+ if (ret) {
bt_dev_err(hdev, "invalid diagnostic descriptors");
return -ENODEV;
}
@@ -4013,12 +3996,11 @@ static struct hci_drv btusb_hci_drv = {
static int btusb_probe(struct usb_interface *intf,
const struct usb_device_id *id)
{
- struct usb_endpoint_descriptor *ep_desc;
struct gpio_desc *reset_gpio;
struct btusb_data *data;
struct hci_dev *hdev;
unsigned ifnum_base;
- int i, err, priv_size;
+ int err, priv_size;
BT_DBG("intf %p id %p", intf, id);
@@ -4055,26 +4037,9 @@ static int btusb_probe(struct usb_interface *intf,
if (!data)
return -ENOMEM;
- for (i = 0; i < intf->cur_altsetting->desc.bNumEndpoints; i++) {
- ep_desc = &intf->cur_altsetting->endpoint[i].desc;
-
- if (!data->intr_ep && usb_endpoint_is_int_in(ep_desc)) {
- data->intr_ep = ep_desc;
- continue;
- }
-
- if (!data->bulk_tx_ep && usb_endpoint_is_bulk_out(ep_desc)) {
- data->bulk_tx_ep = ep_desc;
- continue;
- }
-
- if (!data->bulk_rx_ep && usb_endpoint_is_bulk_in(ep_desc)) {
- data->bulk_rx_ep = ep_desc;
- continue;
- }
- }
-
- if (!data->intr_ep || !data->bulk_tx_ep || !data->bulk_rx_ep) {
+ err = usb_find_common_endpoints(intf->cur_altsetting, &data->bulk_rx_ep,
+ &data->bulk_tx_ep, &data->intr_ep, NULL);
+ if (err) {
kfree(data);
return -ENODEV;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0988/1518] Bluetooth: btusb: Record matched usb_device_id into btusb_data
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (986 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0987/1518] Bluetooth: btusb: refactor endpoint lookup Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0989/1518] Bluetooth: btusb: QCA: Fix populating devcoredump fields on unenabled devices Greg Kroah-Hartman
` (10 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zijun Hu, Luiz Augusto von Dentz,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zijun Hu <zijun.hu@oss.qualcomm.com>
[ Upstream commit ff50db7a522e7bd3bd1c4db6da715e4bdb53af97 ]
Add @match_id to btusb_data to record the matched usb_device_id
which will be used later.
Signed-off-by: Zijun Hu <zijun.hu@oss.qualcomm.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Stable-dep-of: 33c6a8d01889 ("Bluetooth: btusb: QCA: Fix populating devcoredump fields on unenabled devices")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btusb.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/bluetooth/btusb.c b/drivers/bluetooth/btusb.c
index f399599f4b3bf..68480ed7043b9 100644
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -976,6 +976,7 @@ struct btusb_data {
bool usb_alt6_packet_flow;
int isoc_altsetting;
int suspend_count;
+ const struct usb_device_id *match_id;
int (*recv_event)(struct hci_dev *hdev, struct sk_buff *skb);
int (*recv_acl)(struct hci_dev *hdev, struct sk_buff *skb);
@@ -4037,6 +4038,7 @@ static int btusb_probe(struct usb_interface *intf,
if (!data)
return -ENOMEM;
+ data->match_id = id;
err = usb_find_common_endpoints(intf->cur_altsetting, &data->bulk_rx_ep,
&data->bulk_tx_ep, &data->intr_ep, NULL);
if (err) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0989/1518] Bluetooth: btusb: QCA: Fix populating devcoredump fields on unenabled devices
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (987 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0988/1518] Bluetooth: btusb: Record matched usb_device_id into btusb_data Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0990/1518] perf trace-event: Fix integer truncation in do_read() and skip() Greg Kroah-Hartman
` (9 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Zijun Hu, Luiz Augusto von Dentz,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Zijun Hu <zijun.hu@oss.qualcomm.com>
[ Upstream commit 33c6a8d01889a84cc773c0c20c8323bce84af27d ]
Devcoredump is not enabled for ATH3012 or QCA_ROME, but they
unconditionally populate devcoredump fields in btusb_setup_qca().
Fix by populating devcoredump fields only when BTUSB_QCA_WCN6855 is
set, which marks the first generation of QCA BT SoCs for which
devcoredump is enabled.
Fixes: 20981ce2d5a5 ("Bluetooth: btusb: Add WCN6855 devcoredump support")
Signed-off-by: Zijun Hu <zijun.hu@oss.qualcomm.com>
Signed-off-by: Luiz Augusto von Dentz <luiz.von.dentz@intel.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/bluetooth/btusb.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/drivers/bluetooth/btusb.c b/drivers/bluetooth/btusb.c
index 68480ed7043b9..68054ae289c23 100644
--- a/drivers/bluetooth/btusb.c
+++ b/drivers/bluetooth/btusb.c
@@ -3631,8 +3631,10 @@ static int btusb_setup_qca(struct hci_dev *hdev)
if (err)
return err;
- btdata->qca_dump.fw_version = le32_to_cpu(ver.patch_version);
- btdata->qca_dump.controller_id = le32_to_cpu(ver.rom_version);
+ if (btdata->match_id->driver_info & BTUSB_QCA_WCN6855) {
+ btdata->qca_dump.fw_version = le32_to_cpu(ver.patch_version);
+ btdata->qca_dump.controller_id = le32_to_cpu(ver.rom_version);
+ }
if (!(status & QCA_SYSCFG_UPDATED)) {
err = btusb_setup_qca_load_nvm(hdev, &ver, info);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0990/1518] perf trace-event: Fix integer truncation in do_read() and skip()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (988 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0989/1518] Bluetooth: btusb: QCA: Fix populating devcoredump fields on unenabled devices Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0991/1518] scsi: core: Pass a struct scsi_driver to scsi_{,un}register_driver() Greg Kroah-Hartman
` (8 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Tanushree Shah, Namhyung Kim,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Tanushree Shah <tshah@linux.ibm.com>
[ Upstream commit c108c1391be0826920991d24532fbae8f6373ddc ]
The do_read() and skip() functions use 'int' for size parameters,
truncating 64-bit sizes from callers. This causes two issues:
1. Uninitialized memory dump: do_read() reads fewer bytes than
allocated, leaving uninitialized heap memory that gets written
to output files.
2. Out-of-bounds read: Parsing functions process the full 64-bit
size while only partial data was read into the buffer.
Change do_read(), __do_read(), and skip() to use size_t for size
parameters and ssize_t for return values (where applicable), matching
read()/write() system calls.
Update callers to use ssize_t for storing return values.
Fixes: 4a31e56599d4 ("perf tools: Get rid of read_or_die() in trace-event-read.c")
Signed-off-by: Tanushree Shah <tshah@linux.ibm.com>
Signed-off-by: Namhyung Kim <namhyung@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
tools/perf/util/trace-event-read.c | 28 ++++++++++++++--------------
1 file changed, 14 insertions(+), 14 deletions(-)
diff --git a/tools/perf/util/trace-event-read.c b/tools/perf/util/trace-event-read.c
index afd458cf1387d..52ed496d92c3b 100644
--- a/tools/perf/util/trace-event-read.c
+++ b/tools/perf/util/trace-event-read.c
@@ -25,18 +25,18 @@ static int input_fd;
static ssize_t trace_data_size;
static bool repipe;
-static int __do_read(int fd, void *buf, int size)
+static ssize_t __do_read(int fd, void *buf, size_t size)
{
- int rsize = size;
+ size_t rsize = size;
while (size) {
- int ret = read(fd, buf, size);
+ ssize_t ret = read(fd, buf, size);
if (ret <= 0)
return -1;
if (repipe) {
- int retw = write(STDOUT_FILENO, buf, ret);
+ ssize_t retw = write(STDOUT_FILENO, buf, ret);
if (retw <= 0 || retw != ret) {
pr_debug("repiping input file");
@@ -51,13 +51,13 @@ static int __do_read(int fd, void *buf, int size)
return rsize;
}
-static int do_read(void *data, int size)
+static ssize_t do_read(void *data, size_t size)
{
- int r;
+ ssize_t r;
r = __do_read(input_fd, data, size);
if (r <= 0) {
- pr_debug("reading input file (size expected=%d received=%d)",
+ pr_debug("reading input file (size expected=%zu received=%zd)",
size, r);
return -1;
}
@@ -68,10 +68,10 @@ static int do_read(void *data, int size)
}
/* If it fails, the next read will report it */
-static void skip(int size)
+static void skip(size_t size)
{
char buf[BUFSIZ];
- int r;
+ size_t r;
while (size) {
r = size > BUFSIZ ? BUFSIZ : size;
@@ -202,7 +202,7 @@ static int read_header_files(struct tep_handle *pevent)
unsigned long long size;
char *header_page;
char buf[BUFSIZ];
- int ret = 0;
+ ssize_t ret = 0;
if (do_read(buf, 12) < 0)
return -1;
@@ -250,7 +250,7 @@ static int read_header_files(struct tep_handle *pevent)
static int read_ftrace_file(struct tep_handle *pevent, unsigned long long size)
{
- int ret;
+ ssize_t ret;
char *buf;
buf = malloc(size);
@@ -276,7 +276,7 @@ static int read_ftrace_file(struct tep_handle *pevent, unsigned long long size)
static int read_event_file(struct tep_handle *pevent, char *sys,
unsigned long long size)
{
- int ret;
+ ssize_t ret;
char *buf;
buf = malloc(size);
@@ -322,7 +322,7 @@ static int read_event_files(struct tep_handle *pevent)
int systems;
int count;
int i,x;
- int ret;
+ ssize_t ret;
systems = read4(pevent);
@@ -350,7 +350,7 @@ static int read_saved_cmdline(struct tep_handle *pevent)
{
unsigned long long size;
char *buf;
- int ret;
+ ssize_t ret;
/* it can have 0 size */
size = read8(pevent);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0991/1518] scsi: core: Pass a struct scsi_driver to scsi_{,un}register_driver()
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (989 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0990/1518] perf trace-event: Fix integer truncation in do_read() and skip() Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0992/1518] scsi: core: sysfs: Make use of bus callbacks Greg Kroah-Hartman
` (7 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Peter Wang, Uwe Kleine-König,
Bart Van Assche, Martin K. Petersen, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Uwe Kleine-König <u.kleine-koenig@baylibre.com>
[ Upstream commit 7d42bcea57ae139e2ed754425cc5fc44e260c890 ]
This aligns with what other subsystems do, reduces boilerplate a bit for
device drivers and is less error prone.
Reviewed-by: Peter Wang <peter.wang@mediatek.com>
Signed-off-by: Uwe Kleine-König <u.kleine-koenig@baylibre.com>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/ac17fdea58e384cb514c639306d48ce0005820b0.1766133330.git.u.kleine-koenig@baylibre.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Stable-dep-of: bb31844d88b7 ("scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/ch.c | 4 ++--
drivers/scsi/scsi_sysfs.c | 4 +++-
drivers/scsi/sd.c | 4 ++--
drivers/scsi/ses.c | 4 ++--
drivers/scsi/sr.c | 4 ++--
drivers/scsi/st.c | 4 ++--
drivers/ufs/core/ufshcd.c | 4 ++--
include/scsi/scsi_driver.h | 4 ++--
8 files changed, 17 insertions(+), 15 deletions(-)
diff --git a/drivers/scsi/ch.c b/drivers/scsi/ch.c
index fa07a6f54003e..f2b63e4b9b99e 100644
--- a/drivers/scsi/ch.c
+++ b/drivers/scsi/ch.c
@@ -1014,7 +1014,7 @@ static int __init init_ch_module(void)
SCSI_CHANGER_MAJOR);
goto fail1;
}
- rc = scsi_register_driver(&ch_template.gendrv);
+ rc = scsi_register_driver(&ch_template);
if (rc < 0)
goto fail2;
return 0;
@@ -1028,7 +1028,7 @@ static int __init init_ch_module(void)
static void __exit exit_ch_module(void)
{
- scsi_unregister_driver(&ch_template.gendrv);
+ scsi_unregister_driver(&ch_template);
unregister_chrdev(SCSI_CHANGER_MAJOR, "ch");
class_unregister(&ch_sysfs_class);
idr_destroy(&ch_index_idr);
diff --git a/drivers/scsi/scsi_sysfs.c b/drivers/scsi/scsi_sysfs.c
index 15ba493d21386..f2d62f71c8af7 100644
--- a/drivers/scsi/scsi_sysfs.c
+++ b/drivers/scsi/scsi_sysfs.c
@@ -1609,8 +1609,10 @@ void scsi_remove_target(struct device *dev)
}
EXPORT_SYMBOL(scsi_remove_target);
-int __scsi_register_driver(struct device_driver *drv, struct module *owner)
+int __scsi_register_driver(struct scsi_driver *sdrv, struct module *owner)
{
+ struct device_driver *drv = &sdrv->gendrv;
+
drv->bus = &scsi_bus_type;
drv->owner = owner;
diff --git a/drivers/scsi/sd.c b/drivers/scsi/sd.c
index d9bae23cb929e..fe5252f06a30c 100644
--- a/drivers/scsi/sd.c
+++ b/drivers/scsi/sd.c
@@ -4375,7 +4375,7 @@ static int __init init_sd(void)
goto err_out_class;
}
- err = scsi_register_driver(&sd_template.gendrv);
+ err = scsi_register_driver(&sd_template);
if (err)
goto err_out_driver;
@@ -4402,7 +4402,7 @@ static void __exit exit_sd(void)
SCSI_LOG_HLQUEUE(3, printk("exit_sd: exiting sd driver\n"));
- scsi_unregister_driver(&sd_template.gendrv);
+ scsi_unregister_driver(&sd_template);
mempool_destroy(sd_page_pool);
class_unregister(&sd_disk_class);
diff --git a/drivers/scsi/ses.c b/drivers/scsi/ses.c
index 7e1f085ad350a..23d93cb110a6c 100644
--- a/drivers/scsi/ses.c
+++ b/drivers/scsi/ses.c
@@ -920,7 +920,7 @@ static int __init ses_init(void)
if (err)
return err;
- err = scsi_register_driver(&ses_template.gendrv);
+ err = scsi_register_driver(&ses_template);
if (err)
goto out_unreg;
@@ -933,7 +933,7 @@ static int __init ses_init(void)
static void __exit ses_exit(void)
{
- scsi_unregister_driver(&ses_template.gendrv);
+ scsi_unregister_driver(&ses_template);
scsi_unregister_interface(&ses_interface);
}
diff --git a/drivers/scsi/sr.c b/drivers/scsi/sr.c
index 803fc9c132298..3b71fee9cf3c7 100644
--- a/drivers/scsi/sr.c
+++ b/drivers/scsi/sr.c
@@ -994,7 +994,7 @@ static int __init init_sr(void)
rc = register_blkdev(SCSI_CDROM_MAJOR, "sr");
if (rc)
return rc;
- rc = scsi_register_driver(&sr_template.gendrv);
+ rc = scsi_register_driver(&sr_template);
if (rc)
unregister_blkdev(SCSI_CDROM_MAJOR, "sr");
@@ -1003,7 +1003,7 @@ static int __init init_sr(void)
static void __exit exit_sr(void)
{
- scsi_unregister_driver(&sr_template.gendrv);
+ scsi_unregister_driver(&sr_template);
unregister_blkdev(SCSI_CDROM_MAJOR, "sr");
}
diff --git a/drivers/scsi/st.c b/drivers/scsi/st.c
index 74a6830b7ed8e..83140b60f3fbe 100644
--- a/drivers/scsi/st.c
+++ b/drivers/scsi/st.c
@@ -4533,7 +4533,7 @@ static int __init init_st(void)
goto err_class;
}
- err = scsi_register_driver(&st_template.gendrv);
+ err = scsi_register_driver(&st_template);
if (err)
goto err_chrdev;
@@ -4549,7 +4549,7 @@ static int __init init_st(void)
static void __exit exit_st(void)
{
- scsi_unregister_driver(&st_template.gendrv);
+ scsi_unregister_driver(&st_template);
unregister_chrdev_region(MKDEV(SCSI_TAPE_MAJOR, 0),
ST_MAX_TAPE_ENTRIES);
class_unregister(&st_sysfs_class);
diff --git a/drivers/ufs/core/ufshcd.c b/drivers/ufs/core/ufshcd.c
index 504600f1e08cd..b51933b6cc826 100644
--- a/drivers/ufs/core/ufshcd.c
+++ b/drivers/ufs/core/ufshcd.c
@@ -11090,7 +11090,7 @@ static int __init ufshcd_core_init(void)
ufs_debugfs_init();
- ret = scsi_register_driver(&ufs_dev_wlun_template.gendrv);
+ ret = scsi_register_driver(&ufs_dev_wlun_template);
if (ret)
ufs_debugfs_exit();
return ret;
@@ -11099,7 +11099,7 @@ static int __init ufshcd_core_init(void)
static void __exit ufshcd_core_exit(void)
{
ufs_debugfs_exit();
- scsi_unregister_driver(&ufs_dev_wlun_template.gendrv);
+ scsi_unregister_driver(&ufs_dev_wlun_template);
}
module_init(ufshcd_core_init);
diff --git a/include/scsi/scsi_driver.h b/include/scsi/scsi_driver.h
index c0e89996bdb3f..40aba9a9349a6 100644
--- a/include/scsi/scsi_driver.h
+++ b/include/scsi/scsi_driver.h
@@ -25,9 +25,9 @@ struct scsi_driver {
#define scsi_register_driver(drv) \
__scsi_register_driver(drv, THIS_MODULE)
-int __scsi_register_driver(struct device_driver *, struct module *);
+int __scsi_register_driver(struct scsi_driver *, struct module *);
#define scsi_unregister_driver(drv) \
- driver_unregister(drv);
+ driver_unregister(&(drv)->gendrv);
extern int scsi_register_interface(struct class_interface *);
#define scsi_unregister_interface(intf) \
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0992/1518] scsi: core: sysfs: Make use of bus callbacks
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (990 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0991/1518] scsi: core: Pass a struct scsi_driver to scsi_{,un}register_driver() Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0993/1518] scsi: sd: Convert to SCSI bus methods Greg Kroah-Hartman
` (6 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Uwe Kleine-König, Peter Wang,
Bart Van Assche, Martin K. Petersen, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Uwe Kleine-König <u.kleine-koenig@baylibre.com>
[ Upstream commit f7d4f1bf5724e52de049c619beddd53c62206624 ]
Introduce a bus-specific probe, remove and shutdown function. For now
this only allows to get rid of a cast of the generic device to a SCSI
device in the drivers and changes the remove prototype to return
void---a non-zero return value is ignored anyhow.
The objective is to get rid of users of struct device_driver callbacks
.probe(), .remove() and .shutdown() to eventually remove these. Until
all SCSI drivers are converted, this results in a runtime warning about
the drivers needing an update because there is a bus probe function and
a driver probe function. The in-tree drivers are fixed by the following
commits.
Signed-off-by: Uwe Kleine-König <u.kleine-koenig@baylibre.com>
Reviewed-by: Peter Wang <peter.wang@mediatek.com>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/a54e363a3fd2054fb924afd7df44bca7f444b5f1.1766133330.git.u.kleine-koenig@baylibre.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Stable-dep-of: bb31844d88b7 ("scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/scsi_sysfs.c | 73 ++++++++++++++++++++++++++++++++++++--
include/scsi/scsi_driver.h | 3 ++
2 files changed, 74 insertions(+), 2 deletions(-)
diff --git a/drivers/scsi/scsi_sysfs.c b/drivers/scsi/scsi_sysfs.c
index f2d62f71c8af7..343c1f9098af3 100644
--- a/drivers/scsi/scsi_sysfs.c
+++ b/drivers/scsi/scsi_sysfs.c
@@ -554,10 +554,48 @@ static int scsi_bus_uevent(const struct device *dev, struct kobj_uevent_env *env
return 0;
}
+static int scsi_bus_probe(struct device *dev)
+{
+ struct scsi_device *sdp = to_scsi_device(dev);
+ struct scsi_driver *drv = to_scsi_driver(dev->driver);
+
+ if (drv->probe)
+ return drv->probe(sdp);
+ else
+ return 0;
+}
+
+static void scsi_bus_remove(struct device *dev)
+{
+ struct scsi_device *sdp = to_scsi_device(dev);
+ struct scsi_driver *drv = to_scsi_driver(dev->driver);
+
+ if (drv->remove)
+ drv->remove(sdp);
+}
+
+static void scsi_bus_shutdown(struct device *dev)
+{
+ struct scsi_device *sdp = to_scsi_device(dev);
+ struct scsi_driver *drv;
+
+ if (!dev->driver)
+ return;
+
+ drv = to_scsi_driver(dev->driver);
+
+ if (drv->shutdown)
+ drv->shutdown(sdp);
+}
+
+
const struct bus_type scsi_bus_type = {
- .name = "scsi",
- .match = scsi_bus_match,
+ .name = "scsi",
+ .match = scsi_bus_match,
.uevent = scsi_bus_uevent,
+ .probe = scsi_bus_probe,
+ .remove = scsi_bus_remove,
+ .shutdown = scsi_bus_shutdown,
#ifdef CONFIG_PM
.pm = &scsi_bus_pm_ops,
#endif
@@ -1609,6 +1647,30 @@ void scsi_remove_target(struct device *dev)
}
EXPORT_SYMBOL(scsi_remove_target);
+static int scsi_legacy_probe(struct scsi_device *sdp)
+{
+ struct device *dev = &sdp->sdev_gendev;
+ struct device_driver *driver = dev->driver;
+
+ return driver->probe(dev);
+}
+
+static void scsi_legacy_remove(struct scsi_device *sdp)
+{
+ struct device *dev = &sdp->sdev_gendev;
+ struct device_driver *driver = dev->driver;
+
+ driver->remove(dev);
+}
+
+static void scsi_legacy_shutdown(struct scsi_device *sdp)
+{
+ struct device *dev = &sdp->sdev_gendev;
+ struct device_driver *driver = dev->driver;
+
+ driver->shutdown(dev);
+}
+
int __scsi_register_driver(struct scsi_driver *sdrv, struct module *owner)
{
struct device_driver *drv = &sdrv->gendrv;
@@ -1616,6 +1678,13 @@ int __scsi_register_driver(struct scsi_driver *sdrv, struct module *owner)
drv->bus = &scsi_bus_type;
drv->owner = owner;
+ if (!sdrv->probe && drv->probe)
+ sdrv->probe = scsi_legacy_probe;
+ if (!sdrv->remove && drv->remove)
+ sdrv->remove = scsi_legacy_remove;
+ if (!sdrv->shutdown && drv->shutdown)
+ sdrv->shutdown = scsi_legacy_shutdown;
+
return driver_register(drv);
}
EXPORT_SYMBOL(__scsi_register_driver);
diff --git a/include/scsi/scsi_driver.h b/include/scsi/scsi_driver.h
index 40aba9a9349a6..249cea724abd1 100644
--- a/include/scsi/scsi_driver.h
+++ b/include/scsi/scsi_driver.h
@@ -12,6 +12,9 @@ struct request;
struct scsi_driver {
struct device_driver gendrv;
+ int (*probe)(struct scsi_device *);
+ void (*remove)(struct scsi_device *);
+ void (*shutdown)(struct scsi_device *);
int (*resume)(struct device *);
void (*rescan)(struct device *);
blk_status_t (*init_command)(struct scsi_cmnd *);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0993/1518] scsi: sd: Convert to SCSI bus methods
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (991 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0992/1518] scsi: core: sysfs: Make use of bus callbacks Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0994/1518] scsi: sd: Move the sd_remove() function definition Greg Kroah-Hartman
` (5 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Uwe Kleine-König,
Bart Van Assche, Martin K. Petersen, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Uwe Kleine-König <u.kleine-koenig@baylibre.com>
[ Upstream commit 63b541f054e7147f5a19fcd964677c189bad7cff ]
The SCSI subsystem has implemented dedicated callbacks for probe, remove
and shutdown. Make use of them. This fixes a runtime warning about the
driver needing to be converted to the bus probe method.
Signed-off-by: Uwe Kleine-König <u.kleine-koenig@baylibre.com>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/8ad5a00c2ad2a64b81350ae3fab02fbe430f306d.1766133330.git.u.kleine-koenig@baylibre.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Stable-dep-of: bb31844d88b7 ("scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/sd.c | 25 +++++++++++++------------
1 file changed, 13 insertions(+), 12 deletions(-)
diff --git a/drivers/scsi/sd.c b/drivers/scsi/sd.c
index fe5252f06a30c..1dd6fbc5e1674 100644
--- a/drivers/scsi/sd.c
+++ b/drivers/scsi/sd.c
@@ -108,7 +108,7 @@ static void sd_config_write_same(struct scsi_disk *sdkp,
struct queue_limits *lim);
static void sd_revalidate_disk(struct gendisk *);
static void sd_unlock_native_capacity(struct gendisk *disk);
-static void sd_shutdown(struct device *);
+static void sd_shutdown(struct scsi_device *);
static void scsi_disk_release(struct device *cdev);
static DEFINE_IDA(sd_index_ida);
@@ -3894,7 +3894,7 @@ static int sd_format_disk_name(char *prefix, int index, char *buf, int buflen)
* sd_probe - called during driver initialization and whenever a
* new scsi device is attached to the system. It is called once
* for each scsi device (not just disks) present.
- * @dev: pointer to device object
+ * @sdp: pointer to device object
*
* Returns 0 if successful (or not interested in this scsi device
* (e.g. scanner)); 1 when there is an error.
@@ -3908,9 +3908,9 @@ static int sd_format_disk_name(char *prefix, int index, char *buf, int buflen)
* Assume sd_probe is not re-entrant (for time being)
* Also think about sd_probe() and sd_remove() running coincidentally.
**/
-static int sd_probe(struct device *dev)
+static int sd_probe(struct scsi_device *sdp)
{
- struct scsi_device *sdp = to_scsi_device(dev);
+ struct device *dev = &sdp->sdev_gendev;
struct scsi_disk *sdkp;
struct gendisk *gd;
int index;
@@ -4051,15 +4051,16 @@ static int sd_probe(struct device *dev)
* sd_remove - called whenever a scsi disk (previously recognized by
* sd_probe) is detached from the system. It is called (potentially
* multiple times) during sd module unload.
- * @dev: pointer to device object
+ * @sdp: pointer to device object
*
* Note: this function is invoked from the scsi mid-level.
* This function potentially frees up a device name (e.g. /dev/sdc)
* that could be re-used by a subsequent sd_probe().
* This function is not called when the built-in sd driver is "exit-ed".
**/
-static int sd_remove(struct device *dev)
+static void sd_remove(struct scsi_device *sdp)
{
+ struct device *dev = &sdp->sdev_gendev;
struct scsi_disk *sdkp = dev_get_drvdata(dev);
scsi_autopm_get_device(sdkp->device);
@@ -4067,10 +4068,9 @@ static int sd_remove(struct device *dev)
device_del(&sdkp->disk_dev);
del_gendisk(sdkp->disk);
if (!sdkp->suspended)
- sd_shutdown(dev);
+ sd_shutdown(sdp);
put_disk(sdkp->disk);
- return 0;
}
static void scsi_disk_release(struct device *dev)
@@ -4157,8 +4157,9 @@ static int sd_start_stop_device(struct scsi_disk *sdkp, int start)
* the normal SCSI command structure. Wait for the command to
* complete.
*/
-static void sd_shutdown(struct device *dev)
+static void sd_shutdown(struct scsi_device *sdp)
{
+ struct device *dev = &sdp->sdev_gendev;
struct scsi_disk *sdkp = dev_get_drvdata(dev);
if (!sdkp)
@@ -4326,12 +4327,12 @@ static const struct dev_pm_ops sd_pm_ops = {
};
static struct scsi_driver sd_template = {
+ .probe = sd_probe,
+ .remove = sd_remove,
+ .shutdown = sd_shutdown,
.gendrv = {
.name = "sd",
- .probe = sd_probe,
.probe_type = PROBE_PREFER_ASYNCHRONOUS,
- .remove = sd_remove,
- .shutdown = sd_shutdown,
.pm = &sd_pm_ops,
},
.rescan = sd_rescan,
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0994/1518] scsi: sd: Move the sd_remove() function definition
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (992 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0993/1518] scsi: sd: Convert to SCSI bus methods Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0995/1518] scsi: sd: Move the sd_config_discard() " Greg Kroah-Hartman
` (4 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Damien Le Moal, Himanshu Madhani,
Johannes Thumshirn, Bart Van Assche, Martin K. Petersen,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bart Van Assche <bvanassche@acm.org>
[ Upstream commit 4f39a4870a59971797be86fed72423b83b6b4e00 ]
Move the sd_remove() function definition such that the sd_shutdown()
forward declaration can be removed.
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Reviewed-by: Himanshu Madhani <himanshu.madhani@oracle.com>
Reviewed-by: Johannes Thumshirn <johannes.thumshirn@wdc.com>
Signed-off-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/20260114175054.4118163-2-bvanassche@acm.org
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Stable-dep-of: bb31844d88b7 ("scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/sd.c | 53 +++++++++++++++++++++++------------------------
1 file changed, 26 insertions(+), 27 deletions(-)
diff --git a/drivers/scsi/sd.c b/drivers/scsi/sd.c
index 1dd6fbc5e1674..8ecf5a4781741 100644
--- a/drivers/scsi/sd.c
+++ b/drivers/scsi/sd.c
@@ -108,7 +108,6 @@ static void sd_config_write_same(struct scsi_disk *sdkp,
struct queue_limits *lim);
static void sd_revalidate_disk(struct gendisk *);
static void sd_unlock_native_capacity(struct gendisk *disk);
-static void sd_shutdown(struct scsi_device *);
static void scsi_disk_release(struct device *cdev);
static DEFINE_IDA(sd_index_ida);
@@ -4047,32 +4046,6 @@ static int sd_probe(struct scsi_device *sdp)
return error;
}
-/**
- * sd_remove - called whenever a scsi disk (previously recognized by
- * sd_probe) is detached from the system. It is called (potentially
- * multiple times) during sd module unload.
- * @sdp: pointer to device object
- *
- * Note: this function is invoked from the scsi mid-level.
- * This function potentially frees up a device name (e.g. /dev/sdc)
- * that could be re-used by a subsequent sd_probe().
- * This function is not called when the built-in sd driver is "exit-ed".
- **/
-static void sd_remove(struct scsi_device *sdp)
-{
- struct device *dev = &sdp->sdev_gendev;
- struct scsi_disk *sdkp = dev_get_drvdata(dev);
-
- scsi_autopm_get_device(sdkp->device);
-
- device_del(&sdkp->disk_dev);
- del_gendisk(sdkp->disk);
- if (!sdkp->suspended)
- sd_shutdown(sdp);
-
- put_disk(sdkp->disk);
-}
-
static void scsi_disk_release(struct device *dev)
{
struct scsi_disk *sdkp = to_scsi_disk(dev);
@@ -4184,6 +4157,32 @@ static void sd_shutdown(struct scsi_device *sdp)
}
}
+/**
+ * sd_remove - called whenever a scsi disk (previously recognized by
+ * sd_probe) is detached from the system. It is called (potentially
+ * multiple times) during sd module unload.
+ * @sdp: pointer to device object
+ *
+ * Note: this function is invoked from the scsi mid-level.
+ * This function potentially frees up a device name (e.g. /dev/sdc)
+ * that could be re-used by a subsequent sd_probe().
+ * This function is not called when the built-in sd driver is "exit-ed".
+ **/
+static void sd_remove(struct scsi_device *sdp)
+{
+ struct device *dev = &sdp->sdev_gendev;
+ struct scsi_disk *sdkp = dev_get_drvdata(dev);
+
+ scsi_autopm_get_device(sdkp->device);
+
+ device_del(&sdkp->disk_dev);
+ del_gendisk(sdkp->disk);
+ if (!sdkp->suspended)
+ sd_shutdown(sdp);
+
+ put_disk(sdkp->disk);
+}
+
static inline bool sd_do_start_stop(struct scsi_device *sdev, bool runtime)
{
return (sdev->manage_system_start_stop && !runtime) ||
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0995/1518] scsi: sd: Move the sd_config_discard() function definition
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (993 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0994/1518] scsi: sd: Move the sd_remove() function definition Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0996/1518] scsi: sd: Enable sector size > PAGE_SIZE in SCSI sd driver Greg Kroah-Hartman
` (3 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Damien Le Moal, Himanshu Madhani,
Johannes Thumshirn, Bart Van Assche, Martin K. Petersen,
Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Bart Van Assche <bvanassche@acm.org>
[ Upstream commit c0daf4836114fcbdf64bf817cab00b75ce712945 ]
Move the sd_config_discard() function definition such that its
forward declaration can be removed.
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Reviewed-by: Himanshu Madhani <himanshu.madhani@oracle.com>
Reviewed-by: Johannes Thumshirn <johannes.thumshirn@wdc.com>
Signed-off-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/20260114175054.4118163-3-bvanassche@acm.org
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Stable-dep-of: bb31844d88b7 ("scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/sd.c | 114 +++++++++++++++++++++++-----------------------
1 file changed, 56 insertions(+), 58 deletions(-)
diff --git a/drivers/scsi/sd.c b/drivers/scsi/sd.c
index 8ecf5a4781741..bf14b73a8744c 100644
--- a/drivers/scsi/sd.c
+++ b/drivers/scsi/sd.c
@@ -102,8 +102,6 @@ MODULE_ALIAS_SCSI_DEVICE(TYPE_ZBC);
#define SD_MINORS 16
-static void sd_config_discard(struct scsi_disk *sdkp, struct queue_limits *lim,
- unsigned int mode);
static void sd_config_write_same(struct scsi_disk *sdkp,
struct queue_limits *lim);
static void sd_revalidate_disk(struct gendisk *);
@@ -120,6 +118,62 @@ static const char *sd_cache_types[] = {
"write back, no read (daft)"
};
+static void sd_disable_discard(struct scsi_disk *sdkp)
+{
+ sdkp->provisioning_mode = SD_LBP_DISABLE;
+ blk_queue_disable_discard(sdkp->disk->queue);
+}
+
+static void sd_config_discard(struct scsi_disk *sdkp, struct queue_limits *lim,
+ unsigned int mode)
+{
+ unsigned int logical_block_size = sdkp->device->sector_size;
+ unsigned int max_blocks = 0;
+
+ lim->discard_alignment = sdkp->unmap_alignment * logical_block_size;
+ lim->discard_granularity = max(sdkp->physical_block_size,
+ sdkp->unmap_granularity * logical_block_size);
+ sdkp->provisioning_mode = mode;
+
+ switch (mode) {
+
+ case SD_LBP_FULL:
+ case SD_LBP_DISABLE:
+ break;
+
+ case SD_LBP_UNMAP:
+ max_blocks = min_not_zero(sdkp->max_unmap_blocks,
+ (u32)SD_MAX_WS16_BLOCKS);
+ break;
+
+ case SD_LBP_WS16:
+ if (sdkp->device->unmap_limit_for_ws)
+ max_blocks = sdkp->max_unmap_blocks;
+ else
+ max_blocks = sdkp->max_ws_blocks;
+
+ max_blocks = min_not_zero(max_blocks, (u32)SD_MAX_WS16_BLOCKS);
+ break;
+
+ case SD_LBP_WS10:
+ if (sdkp->device->unmap_limit_for_ws)
+ max_blocks = sdkp->max_unmap_blocks;
+ else
+ max_blocks = sdkp->max_ws_blocks;
+
+ max_blocks = min_not_zero(max_blocks, (u32)SD_MAX_WS10_BLOCKS);
+ break;
+
+ case SD_LBP_ZERO:
+ max_blocks = min_not_zero(sdkp->max_ws_blocks,
+ (u32)SD_MAX_WS10_BLOCKS);
+ break;
+ }
+
+ lim->max_hw_discard_sectors = max_blocks *
+ (logical_block_size >> SECTOR_SHIFT);
+}
+
static void sd_set_flush_flag(struct scsi_disk *sdkp,
struct queue_limits *lim)
{
@@ -835,62 +889,6 @@ static unsigned char sd_setup_protect_cmnd(struct scsi_cmnd *scmd,
return protect;
}
-static void sd_disable_discard(struct scsi_disk *sdkp)
-{
- sdkp->provisioning_mode = SD_LBP_DISABLE;
- blk_queue_disable_discard(sdkp->disk->queue);
-}
-
-static void sd_config_discard(struct scsi_disk *sdkp, struct queue_limits *lim,
- unsigned int mode)
-{
- unsigned int logical_block_size = sdkp->device->sector_size;
- unsigned int max_blocks = 0;
-
- lim->discard_alignment = sdkp->unmap_alignment * logical_block_size;
- lim->discard_granularity = max(sdkp->physical_block_size,
- sdkp->unmap_granularity * logical_block_size);
- sdkp->provisioning_mode = mode;
-
- switch (mode) {
-
- case SD_LBP_FULL:
- case SD_LBP_DISABLE:
- break;
-
- case SD_LBP_UNMAP:
- max_blocks = min_not_zero(sdkp->max_unmap_blocks,
- (u32)SD_MAX_WS16_BLOCKS);
- break;
-
- case SD_LBP_WS16:
- if (sdkp->device->unmap_limit_for_ws)
- max_blocks = sdkp->max_unmap_blocks;
- else
- max_blocks = sdkp->max_ws_blocks;
-
- max_blocks = min_not_zero(max_blocks, (u32)SD_MAX_WS16_BLOCKS);
- break;
-
- case SD_LBP_WS10:
- if (sdkp->device->unmap_limit_for_ws)
- max_blocks = sdkp->max_unmap_blocks;
- else
- max_blocks = sdkp->max_ws_blocks;
-
- max_blocks = min_not_zero(max_blocks, (u32)SD_MAX_WS10_BLOCKS);
- break;
-
- case SD_LBP_ZERO:
- max_blocks = min_not_zero(sdkp->max_ws_blocks,
- (u32)SD_MAX_WS10_BLOCKS);
- break;
- }
-
- lim->max_hw_discard_sectors = max_blocks *
- (logical_block_size >> SECTOR_SHIFT);
-}
-
static void *sd_set_special_bvec(struct request *rq, unsigned int data_len)
{
struct page *page;
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0996/1518] scsi: sd: Enable sector size > PAGE_SIZE in SCSI sd driver
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (994 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0995/1518] scsi: sd: Move the sd_config_discard() " Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0997/1518] scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails Greg Kroah-Hartman
` (2 subsequent siblings)
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Damien Le Moal, Swarna Prabhu,
Pankaj Raghav, Martin K. Petersen, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Swarna Prabhu <sw.prabhu6@gmail.com>
[ Upstream commit 7179e626b76eb42f2529c6f6dd6ba88ea2445372 ]
The WRITE SAME(16) and WRITE SAME(10) SCSI commands use a page from a
dedicated mempool (sd_page_pool) for their payload. This pool was
initialized to allocate single pages, which was sufficient as long as the
device sector size did not exceed the PAGE_SIZE.
Given that block layer now supports block size upto 64KB, i.e. beyond
PAGE_SIZE, initialize a large page pool in sd_probe() if a higher sector
device is attached, ensuring atomicity. Adapt sd_set_special_bvec() to use
large page pool when a higher sector size device is attached. Hence enable
sector sizes > PAGE_SIZE in SCSI sd driver.
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Signed-off-by: Swarna Prabhu <s.prabhu@samsung.com>
Co-developed-by: Pankaj Raghav <p.raghav@samsung.com>
Signed-off-by: Pankaj Raghav <p.raghav@samsung.com>
Link: https://patch.msgid.link/20260219043741.276729-2-sw.prabhu6@gmail.com
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Stable-dep-of: bb31844d88b7 ("scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails")
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/sd.c | 80 ++++++++++++++++++++++++++++++++++++++++-------
1 file changed, 68 insertions(+), 12 deletions(-)
diff --git a/drivers/scsi/sd.c b/drivers/scsi/sd.c
index bf14b73a8744c..cb84f34d6cb10 100644
--- a/drivers/scsi/sd.c
+++ b/drivers/scsi/sd.c
@@ -109,8 +109,11 @@ static void sd_unlock_native_capacity(struct gendisk *disk);
static void scsi_disk_release(struct device *cdev);
static DEFINE_IDA(sd_index_ida);
+static DEFINE_MUTEX(sd_mutex_lock);
static mempool_t *sd_page_pool;
+static mempool_t *sd_large_page_pool;
+static atomic_t sd_large_page_pool_users = ATOMIC_INIT(0);
static struct lock_class_key sd_bio_compl_lkclass;
static const char *sd_cache_types[] = {
@@ -118,6 +121,33 @@ static const char *sd_cache_types[] = {
"write back, no read (daft)"
};
+static int sd_large_pool_create(void)
+{
+ mutex_lock(&sd_mutex_lock);
+ if (!sd_large_page_pool) {
+ sd_large_page_pool = mempool_create_page_pool(
+ SD_MEMPOOL_SIZE, get_order(BLK_MAX_BLOCK_SIZE));
+ if (!sd_large_page_pool) {
+ printk(KERN_ERR "sd: can't create large page mempool\n");
+ mutex_unlock(&sd_mutex_lock);
+ return -ENOMEM;
+ }
+ }
+ atomic_inc(&sd_large_page_pool_users);
+ mutex_unlock(&sd_mutex_lock);
+ return 0;
+}
+
+static void sd_large_pool_destroy(void)
+{
+ mutex_lock(&sd_mutex_lock);
+ if (atomic_dec_and_test(&sd_large_page_pool_users)) {
+ mempool_destroy(sd_large_page_pool);
+ sd_large_page_pool = NULL;
+ }
+ mutex_unlock(&sd_mutex_lock);
+}
+
static void sd_disable_discard(struct scsi_disk *sdkp)
{
sdkp->provisioning_mode = SD_LBP_DISABLE;
@@ -889,14 +919,24 @@ static unsigned char sd_setup_protect_cmnd(struct scsi_cmnd *scmd,
return protect;
}
-static void *sd_set_special_bvec(struct request *rq, unsigned int data_len)
+static void *sd_set_special_bvec(struct scsi_cmnd *cmd, unsigned int data_len)
{
struct page *page;
+ struct request *rq = scsi_cmd_to_rq(cmd);
+ struct scsi_device *sdp = cmd->device;
+ unsigned sector_size = sdp->sector_size;
+ unsigned int nr_pages = DIV_ROUND_UP(sector_size, PAGE_SIZE);
+ int n;
- page = mempool_alloc(sd_page_pool, GFP_ATOMIC);
+ if (sector_size > PAGE_SIZE)
+ page = mempool_alloc(sd_large_page_pool, GFP_ATOMIC);
+ else
+ page = mempool_alloc(sd_page_pool, GFP_ATOMIC);
if (!page)
return NULL;
- clear_highpage(page);
+
+ for (n = 0; n < nr_pages; n++)
+ clear_highpage(page + n);
bvec_set_page(&rq->special_vec, page, data_len, 0);
rq->rq_flags |= RQF_SPECIAL_PAYLOAD;
return bvec_virt(&rq->special_vec);
@@ -912,7 +952,7 @@ static blk_status_t sd_setup_unmap_cmnd(struct scsi_cmnd *cmd)
unsigned int data_len = 24;
char *buf;
- buf = sd_set_special_bvec(rq, data_len);
+ buf = sd_set_special_bvec(cmd, data_len);
if (!buf)
return BLK_STS_RESOURCE;
@@ -1001,7 +1041,7 @@ static blk_status_t sd_setup_write_same16_cmnd(struct scsi_cmnd *cmd,
u32 nr_blocks = sectors_to_logical(sdp, blk_rq_sectors(rq));
u32 data_len = sdp->sector_size;
- if (!sd_set_special_bvec(rq, data_len))
+ if (!sd_set_special_bvec(cmd, data_len))
return BLK_STS_RESOURCE;
cmd->cmd_len = 16;
@@ -1028,7 +1068,7 @@ static blk_status_t sd_setup_write_same10_cmnd(struct scsi_cmnd *cmd,
u32 nr_blocks = sectors_to_logical(sdp, blk_rq_sectors(rq));
u32 data_len = sdp->sector_size;
- if (!sd_set_special_bvec(rq, data_len))
+ if (!sd_set_special_bvec(cmd, data_len))
return BLK_STS_RESOURCE;
cmd->cmd_len = 10;
@@ -1474,9 +1514,15 @@ static blk_status_t sd_init_command(struct scsi_cmnd *cmd)
static void sd_uninit_command(struct scsi_cmnd *SCpnt)
{
struct request *rq = scsi_cmd_to_rq(SCpnt);
+ struct scsi_device *sdp = SCpnt->device;
+ unsigned sector_size = sdp->sector_size;
- if (rq->rq_flags & RQF_SPECIAL_PAYLOAD)
- mempool_free(rq->special_vec.bv_page, sd_page_pool);
+ if (rq->rq_flags & RQF_SPECIAL_PAYLOAD) {
+ if (sector_size > PAGE_SIZE)
+ mempool_free(rq->special_vec.bv_page, sd_large_page_pool);
+ else
+ mempool_free(rq->special_vec.bv_page, sd_page_pool);
+ }
}
static bool sd_need_revalidate(struct gendisk *disk, struct scsi_disk *sdkp)
@@ -2876,10 +2922,7 @@ sd_read_capacity(struct scsi_disk *sdkp, struct queue_limits *lim,
"assuming 512.\n");
}
- if (sector_size != 512 &&
- sector_size != 1024 &&
- sector_size != 2048 &&
- sector_size != 4096) {
+ if (blk_validate_block_size(sector_size)) {
sd_printk(KERN_NOTICE, sdkp, "Unsupported sector size %d.\n",
sector_size);
/*
@@ -4001,6 +4044,12 @@ static int sd_probe(struct scsi_device *sdp)
sdkp->max_medium_access_timeouts = SD_MAX_MEDIUM_TIMEOUTS;
sd_revalidate_disk(gd);
+ if (sdp->sector_size > PAGE_SIZE) {
+ if (sd_large_pool_create()) {
+ error = -ENOMEM;
+ goto out_free_index;
+ }
+ }
if (sdp->removable) {
gd->flags |= GENHD_FL_REMOVABLE;
@@ -4018,6 +4067,8 @@ static int sd_probe(struct scsi_device *sdp)
if (error) {
device_unregister(&sdkp->disk_dev);
put_disk(gd);
+ if (sdp->sector_size > PAGE_SIZE)
+ sd_large_pool_destroy();
goto out;
}
@@ -4179,6 +4230,9 @@ static void sd_remove(struct scsi_device *sdp)
sd_shutdown(sdp);
put_disk(sdkp->disk);
+
+ if (sdp->sector_size > PAGE_SIZE)
+ sd_large_pool_destroy();
}
static inline bool sd_do_start_stop(struct scsi_device *sdev, bool runtime)
@@ -4402,6 +4456,8 @@ static void __exit exit_sd(void)
scsi_unregister_driver(&sd_template);
mempool_destroy(sd_page_pool);
+ if (sd_large_page_pool)
+ mempool_destroy(sd_large_page_pool);
class_unregister(&sd_disk_class);
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0997/1518] scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (995 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0996/1518] scsi: sd: Enable sector size > PAGE_SIZE in SCSI sd driver Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0998/1518] scsi: sd: Fix sd_done() sense handling condition Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0999/1518] btrfs: defrag: fix deadlock between defrag and delalloc space reservation Greg Kroah-Hartman
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Damien Le Moal, Yang Xiuwei,
John Garry, Martin K. Petersen (Oracle), Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yang Xiuwei <yangxiuwei@kylinos.cn>
[ Upstream commit bb31844d88b77138b67aa20c3600203baff40140 ]
sd_set_special_bvec() allocates a special payload page for UNMAP and
WRITE SAME commands. If scsi_alloc_sgtables() fails afterward in
sd_setup_unmap_cmnd() or sd_setup_write_same{10,16}_cmnd(), the SCSI
midlayer does not call uninit_command() because RQF_DONTPREP is not set
yet, leaking the page.
Call sd_uninit_command() on error, and clear RQF_SPECIAL_PAYLOAD after
freeing the page.
Fixes: 81d926e8b552 ("sd: split sd_setup_discard_cmnd")
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Signed-off-by: Yang Xiuwei <yangxiuwei@kylinos.cn>
Reviewed-by: John Garry <john.g.garry@oracle.com>
Link: https://patch.msgid.link/20260707030333.22245-3-yangxiuwei@kylinos.cn
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/sd.c | 47 ++++++++++++++++++++++++++++++-----------------
1 file changed, 30 insertions(+), 17 deletions(-)
diff --git a/drivers/scsi/sd.c b/drivers/scsi/sd.c
index cb84f34d6cb10..d44cb802a2621 100644
--- a/drivers/scsi/sd.c
+++ b/drivers/scsi/sd.c
@@ -919,6 +919,21 @@ static unsigned char sd_setup_protect_cmnd(struct scsi_cmnd *scmd,
return protect;
}
+static void sd_uninit_command(struct scsi_cmnd *cmd)
+{
+ struct request *rq = scsi_cmd_to_rq(cmd);
+ struct scsi_device *sdp = cmd->device;
+
+ if (!(rq->rq_flags & RQF_SPECIAL_PAYLOAD))
+ return;
+
+ if (sdp->sector_size > PAGE_SIZE)
+ mempool_free(rq->special_vec.bv_page, sd_large_page_pool);
+ else
+ mempool_free(rq->special_vec.bv_page, sd_page_pool);
+ rq->rq_flags &= ~RQF_SPECIAL_PAYLOAD;
+}
+
static void *sd_set_special_bvec(struct scsi_cmnd *cmd, unsigned int data_len)
{
struct page *page;
@@ -951,6 +966,7 @@ static blk_status_t sd_setup_unmap_cmnd(struct scsi_cmnd *cmd)
u32 nr_blocks = sectors_to_logical(sdp, blk_rq_sectors(rq));
unsigned int data_len = 24;
char *buf;
+ blk_status_t ret;
buf = sd_set_special_bvec(cmd, data_len);
if (!buf)
@@ -969,7 +985,10 @@ static blk_status_t sd_setup_unmap_cmnd(struct scsi_cmnd *cmd)
cmd->transfersize = data_len;
rq->timeout = SD_TIMEOUT;
- return scsi_alloc_sgtables(cmd);
+ ret = scsi_alloc_sgtables(cmd);
+ if (ret != BLK_STS_OK)
+ sd_uninit_command(cmd);
+ return ret;
}
static void sd_config_atomic(struct scsi_disk *sdkp, struct queue_limits *lim)
@@ -1040,6 +1059,7 @@ static blk_status_t sd_setup_write_same16_cmnd(struct scsi_cmnd *cmd,
u64 lba = sectors_to_logical(sdp, blk_rq_pos(rq));
u32 nr_blocks = sectors_to_logical(sdp, blk_rq_sectors(rq));
u32 data_len = sdp->sector_size;
+ blk_status_t ret;
if (!sd_set_special_bvec(cmd, data_len))
return BLK_STS_RESOURCE;
@@ -1055,7 +1075,10 @@ static blk_status_t sd_setup_write_same16_cmnd(struct scsi_cmnd *cmd,
cmd->transfersize = data_len;
rq->timeout = unmap ? SD_TIMEOUT : SD_WRITE_SAME_TIMEOUT;
- return scsi_alloc_sgtables(cmd);
+ ret = scsi_alloc_sgtables(cmd);
+ if (ret != BLK_STS_OK)
+ sd_uninit_command(cmd);
+ return ret;
}
static blk_status_t sd_setup_write_same10_cmnd(struct scsi_cmnd *cmd,
@@ -1067,6 +1090,7 @@ static blk_status_t sd_setup_write_same10_cmnd(struct scsi_cmnd *cmd,
u64 lba = sectors_to_logical(sdp, blk_rq_pos(rq));
u32 nr_blocks = sectors_to_logical(sdp, blk_rq_sectors(rq));
u32 data_len = sdp->sector_size;
+ blk_status_t ret;
if (!sd_set_special_bvec(cmd, data_len))
return BLK_STS_RESOURCE;
@@ -1082,7 +1106,10 @@ static blk_status_t sd_setup_write_same10_cmnd(struct scsi_cmnd *cmd,
cmd->transfersize = data_len;
rq->timeout = unmap ? SD_TIMEOUT : SD_WRITE_SAME_TIMEOUT;
- return scsi_alloc_sgtables(cmd);
+ ret = scsi_alloc_sgtables(cmd);
+ if (ret != BLK_STS_OK)
+ sd_uninit_command(cmd);
+ return ret;
}
static blk_status_t sd_setup_write_zeroes_cmnd(struct scsi_cmnd *cmd)
@@ -1511,20 +1538,6 @@ static blk_status_t sd_init_command(struct scsi_cmnd *cmd)
}
}
-static void sd_uninit_command(struct scsi_cmnd *SCpnt)
-{
- struct request *rq = scsi_cmd_to_rq(SCpnt);
- struct scsi_device *sdp = SCpnt->device;
- unsigned sector_size = sdp->sector_size;
-
- if (rq->rq_flags & RQF_SPECIAL_PAYLOAD) {
- if (sector_size > PAGE_SIZE)
- mempool_free(rq->special_vec.bv_page, sd_large_page_pool);
- else
- mempool_free(rq->special_vec.bv_page, sd_page_pool);
- }
-}
-
static bool sd_need_revalidate(struct gendisk *disk, struct scsi_disk *sdkp)
{
if (sdkp->device->removable || sdkp->write_prot) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0998/1518] scsi: sd: Fix sd_done() sense handling condition
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (996 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0997/1518] scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0999/1518] btrfs: defrag: fix deadlock between defrag and delalloc space reservation Greg Kroah-Hartman
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Damien Le Moal, Yang Xiuwei,
Bart Van Assche, Martin K. Petersen (Oracle), Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Yang Xiuwei <yangxiuwei@kylinos.cn>
[ Upstream commit a640d4546b11be5709a82bdc63d7dafd8ddc6c9e ]
Only enter the sense_key switch when the command returned CHECK
CONDITION with valid, non-deferred sense. The old condition let deferred
or invalid sense fall through and mis-handle the I/O.
Fixes: 03aba2f79594 ("[SCSI] sd/scsi_lib simplify sd_rw_intr and scsi_io_completion")
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Signed-off-by: Yang Xiuwei <yangxiuwei@kylinos.cn>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/20260707030333.22245-4-yangxiuwei@kylinos.cn
Signed-off-by: Martin K. Petersen (Oracle) <mkp@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/sd.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/scsi/sd.c b/drivers/scsi/sd.c
index d44cb802a2621..ff6b953da68a7 100644
--- a/drivers/scsi/sd.c
+++ b/drivers/scsi/sd.c
@@ -2384,8 +2384,8 @@ static int sd_done(struct scsi_cmnd *SCpnt)
}
sdkp->medium_access_timed_out = 0;
- if (!scsi_status_is_check_condition(result) &&
- (!sense_valid || sense_deferred))
+ if (!scsi_status_is_check_condition(result) ||
+ !sense_valid || sense_deferred)
goto out;
switch (sshdr.sense_key) {
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
* [PATCH 6.18 0999/1518] btrfs: defrag: fix deadlock between defrag and delalloc space reservation
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
` (997 preceding siblings ...)
2026-09-12 6:52 ` [PATCH 6.18 0998/1518] scsi: sd: Fix sd_done() sense handling condition Greg Kroah-Hartman
@ 2026-09-12 6:52 ` Greg Kroah-Hartman
998 siblings, 0 replies; 1544+ messages in thread
From: Greg Kroah-Hartman @ 2026-09-12 6:52 UTC (permalink / raw)
To: stable
Cc: Greg Kroah-Hartman, patches, Qu Wenruo, Filipe Manana,
David Sterba, Sasha Levin
6.18-stable review patch. If anyone has any objections, please let me know.
------------------
From: Filipe Manana <fdmanana@suse.com>
[ Upstream commit ba02eab28041f9a4bbe9fc90c7249644fef6de0f ]
While running fsstress with autodefrag and flushoncommit, hit a deadlock
due to the fact that defrag reserves delalloc space while it's holding
dirty and locked folios, besides the extent range lock. The stack traces
are the following:
[958.624] task:kworker/u50:3 state:D stack:0 pid:20365 tgid:20365 ppid:2 task_flags:0x4208060 flags:0x00080000
[958.626] Workqueue: events_unbound btrfs_async_reclaim_metadata_space [btrfs]
[958.627] Call Trace:
[958.628] <TASK>
[958.628] __schedule+0x4be/0x10f0
[958.629] ? preempt_count_add+0x69/0xa0
[958.630] schedule+0x26/0xd0
[958.631] wait_current_trans+0x102/0x160 [btrfs]
[958.632] ? __pfx_autoremove_wake_function+0x10/0x10
[958.633] start_transaction+0x374/0x900 [btrfs]
[958.634] btrfs_commit_current_transaction+0x1d/0x70 [btrfs]
[958.635] flush_space+0xca/0x5e0 [btrfs]
[958.636] ? _raw_spin_unlock+0x15/0x30
[958.637] ? btrfs_reduce_alloc_profile+0x8c/0x190 [btrfs]
[958.639] ? _raw_spin_unlock+0x15/0x30
[958.640] ? calc_available_free_space.isra.0+0x6f/0x110 [btrfs]
[958.641] do_async_reclaim_metadata_space+0x84/0x190 [btrfs]
[958.642] btrfs_async_reclaim_metadata_space+0x64/0x80 [btrfs]
[958.644] process_one_work+0x19d/0x3a0
[958.644] worker_thread+0x1c4/0x330
[958.645] ? __pfx_worker_thread+0x10/0x10
[958.646] kthread+0xfc/0x130
[958.647] ? __pfx_kthread+0x10/0x10
[958.648] ret_from_fork+0x1f7/0x2c0
[958.648] ? __pfx_kthread+0x10/0x10
[958.649] ret_from_fork_asm+0x1a/0x30
[958.650] </TASK>
[958.651] task:kworker/u49:7 state:D stack:0 pid:52990 tgid:52990 ppid:2 task_flags:0x4208060 flags:0x00080000
[958.653] Workqueue: writeback wb_workfn (flush-btrfs-334)
[958.655] Call Trace:
[958.655] <TASK>
[958.656] __schedule+0x4be/0x10f0
[958.657] ? __blk_flush_plug+0xe9/0x140
[958.658] schedule+0x26/0xd0
[958.658] io_schedule+0x42/0x70
[958.659] folio_wait_bit_common+0x12b/0x330
[958.660] ? folio_wait_bit_common+0x100/0x330
[958.662] ? __pfx_wake_page_function+0x10/0x10
[958.663] extent_write_cache_pages+0x599/0x830 [btrfs]
[958.664] ? acpi_fwnode_get_reference_args+0x1fa/0x270
[958.665] btrfs_writepages+0x77/0x130 [btrfs]
[958.666] ? __pfx_end_bbio_data_write+0x10/0x10 [btrfs]
[958.667] do_writepages+0xc6/0x160
[958.668] __writeback_single_inode+0x42/0x310
[958.669] writeback_sb_inodes+0x231/0x570
[958.670] wb_writeback+0x8a/0x340
[958.671] wb_workfn+0xbf/0x450
[958.672] ? finish_task_switch.isra.0+0xc1/0x350
[958.673] process_one_work+0x19d/0x3a0
[958.673] worker_thread+0x1c4/0x330
[958.674] ? __pfx_worker_thread+0x10/0x10
[958.675] kthread+0xfc/0x130
[958.676] ? __pfx_kthread+0x10/0x10
[958.676] ret_from_fork+0x1f7/0x2c0
[958.677] ? __pfx_kthread+0x10/0x10
[958.678] ret_from_fork_asm+0x1a/0x30
[958.679] </TASK>
[958.679] task:btrfs-cleaner state:D stack:0 pid:296750 tgid:296750 ppid:2 task_flags:0x208040 flags:0x00080000
[958.681] Call Trace:
[958.682] <TASK>
[958.682] __schedule+0x4be/0x10f0
[958.683] schedule+0x26/0xd0
[958.684] handle_reserve_ticket+0x1b9/0x2c0 [btrfs]
[958.685] ? __pfx_autoremove_wake_function+0x10/0x10
[958.686] reserve_bytes+0x283/0x4c0 [btrfs]
[958.687] btrfs_reserve_metadata_bytes+0x18/0xb0 [btrfs]
[958.688] btrfs_delalloc_reserve_metadata+0x121/0x320 [btrfs]
[958.690] btrfs_delalloc_reserve_space+0x46/0xb0 [btrfs]
[958.691] btrfs_defrag_file+0x903/0x1110 [btrfs]
[958.692] btrfs_run_defrag_inodes+0x334/0x430 [btrfs]
[958.694] cleaner_kthread+0x97/0x1c0 [btrfs]
[958.694] ? __pfx_cleaner_kthread+0x10/0x10 [btrfs]
[958.696] kthread+0xfc/0x130
[958.696] ? __pfx_kthread+0x10/0x10
[958.697] ret_from_fork+0x1f7/0x2c0
[958.698] ? __pfx_kthread+0x10/0x10
[958.699] ret_from_fork_asm+0x1a/0x30
[958.700] </TASK>
[958.716] task:fsstress state:D stack:0 pid:296769 tgid:296769 ppid:296768 task_flags:0x400140 flags:0x00080000
[958.718] Call Trace:
[958.719] <TASK>
[958.719] __schedule+0x4be/0x10f0
[958.720] ? preempt_count_add+0x69/0xa0
[958.721] schedule+0x26/0xd0
[958.722] wb_wait_for_completion+0x79/0xc0
[958.723] ? __pfx_autoremove_wake_function+0x10/0x10
[958.724] __writeback_inodes_sb_nr+0xc5/0xf0
[958.725] try_to_writeback_inodes_sb+0x55/0x70
[958.726] btrfs_commit_transaction+0x19d/0xeb0 [btrfs]
[958.727] ? start_transaction+0x343/0x900 [btrfs]
[958.728] btrfs_mksubvol+0x28b/0x4e0 [btrfs]
[958.729] btrfs_mksnapshot+0x74/0xa0 [btrfs]
[958.730] __btrfs_ioctl_snap_create+0x194/0x210 [btrfs]
[958.732] btrfs_ioctl_snap_create_v2+0xef/0x150 [btrfs]
[958.733] btrfs_ioctl+0x7ec/0x2a70 [btrfs]
[958.734] ? __virt_addr_valid+0xe4/0x180
[958.735] ? __check_object_size+0x1cd/0x1f0
[958.736] ? kmem_cache_free+0x146/0x380
[958.737] ? _raw_spin_unlock+0x15/0x30
[958.738] ? do_sys_openat2+0x83/0xd0
[958.739] __x64_sys_ioctl+0x92/0xe0
[958.740] do_syscall_64+0x60/0x590
[958.741] ? clear_bhb_loop+0x60/0xb0
[958.742] entry_SYSCALL_64_after_hwframe+0x76/0x7e
[958.743] RIP: 0033:0x7f4431e108db
[958.744] RSP: 002b:00007ffcd147db20 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
[958.746] RAX: ffffffffffffffda RBX: 0000000000000004 RCX: 00007f4431e108db
[958.747] RDX: 00007ffcd147eb90 RSI: 0000000050009417 RDI: 0000000000000005
[958.749] RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000
[958.751] R10: 0000000000000000 R11: 0000000000000246 R12: 00007ffcd147fbf0
[958.752] R13: 00007ffcd147eb90 R14: 0000000000000005 R15: 0000000000000003
[958.754] </TASK>
What happens is the following:
1) The cleaner kthread is running autodefrag, and in defrag_one_range()
it acquired all the folios for the range and locked them.
Then it locked the extent range in the inode's iotree.
It got two subranges from defrag_collect_targets(), the first one
with folio A and the second one with folio B.
After it defragged the first subrange, folio A remains locked and
dirty - it's only unlocked when defrag_one_range() returns.
When it attempts to defrag the second subrange (containing folio B),
btrfs_delalloc_reserve_space() creates a space reservation ticket,
due to lack of free metadata space and blocks waiting for the async
metadata reclaim task to free space and wake it up;
2) The async reclaim metadata task attempts to commit the current
transaction, but it blocks because there is another task that
started the commit first;
3) A task creating a snapshot is committing the transaction and
because the fs was mounted with flushoncommit, it calls
try_to_writeback_inodes_sb(), which spawns a task to flush
delalloc and waits for it to complete;
4) The task flushing delalloc (kworker/u49:7), finds that folio A for
the inode being defragged is dirty, so it tries to lock it...
But it blocks because folio A is locked by the defrag task (the
cleaner kthread) which is blocked waiting for the reservation
ticket to be served, but the async reclaim metadata task is
blocked waiting for the transaction commit, which in turn is
blocked waiting for the delalloc flush task, which is trying to
lock folio A, resulting in a deadlock.
The same type of problem can happen if the async reclaim task starts to
flush delalloc, as that requires both locking the folio and the extent
range in the inode's io tree, and in this case we don't need the fs to
be mounted with flushoncommit. This type of problem has ocurred several
times in the past with reflinks for example, where we had a dirty folio
while holding the extent range locked and then starting a transaction
blocked waiting for the async reclaim task due to lack of free metadata
space.
So fix this by reserving delalloc space before locking folios and locking
the extent range in the inode's iotree. We can not simply unlock the
folios for each subrange given by defrag_collect_targets() after we defrag
it because the same folio may be present too in the next subrange (due to
large folios).
Fixes: 22b398eeeed4 ("btrfs: defrag: introduce helper to defrag a contiguous prepared range")
Reviewed-by: Qu Wenruo <wqu@suse.com>
Signed-off-by: Filipe Manana <fdmanana@suse.com>
Signed-off-by: David Sterba <dsterba@suse.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
fs/btrfs/defrag.c | 50 +++++++++++++++++++++++++++++++----------------
1 file changed, 33 insertions(+), 17 deletions(-)
diff --git a/fs/btrfs/defrag.c b/fs/btrfs/defrag.c
index 2e3c011d410a6..c59548a0b9c53 100644
--- a/fs/btrfs/defrag.c
+++ b/fs/btrfs/defrag.c
@@ -1150,20 +1150,15 @@ static_assert(PAGE_ALIGNED(CLUSTER_SIZE));
*
* - Extent bits are locked
*/
-static int defrag_one_locked_target(struct btrfs_inode *inode,
- struct defrag_target_range *target,
- struct folio **folios, int nr_pages,
- struct extent_state **cached_state)
+static void defrag_one_locked_target(struct btrfs_inode *inode,
+ struct defrag_target_range *target,
+ struct folio **folios, int nr_pages,
+ struct extent_state **cached_state)
{
struct btrfs_fs_info *fs_info = inode->root->fs_info;
- struct extent_changeset *data_reserved = NULL;
const u64 start = target->start;
const u64 len = target->len;
- int ret = 0;
- ret = btrfs_delalloc_reserve_space(inode, &data_reserved, start, len);
- if (ret < 0)
- return ret;
btrfs_clear_extent_bit(&inode->io_tree, start, start + len - 1,
EXTENT_DELALLOC | EXTENT_DO_ACCOUNTING |
EXTENT_DEFRAG, cached_state);
@@ -1184,10 +1179,6 @@ static int defrag_one_locked_target(struct btrfs_inode *inode,
btrfs_folio_clamp_clear_checked(fs_info, folio, start, len);
btrfs_folio_clamp_set_dirty(fs_info, folio, start, len);
}
- btrfs_delalloc_release_extents(inode, len);
- extent_changeset_free(data_reserved);
-
- return ret;
}
static int defrag_one_range(struct btrfs_inode *inode, u64 start, u32 len,
@@ -1203,6 +1194,8 @@ static int defrag_one_range(struct btrfs_inode *inode, u64 start, u32 len,
u64 cur = start;
const unsigned int nr_pages = ((start + len - 1) >> PAGE_SHIFT) -
(start >> PAGE_SHIFT) + 1;
+ struct extent_changeset *data_reserved = NULL;
+ u64 last_defrag_end = start;
int ret = 0;
ASSERT(nr_pages <= CLUSTER_SIZE / PAGE_SIZE);
@@ -1212,6 +1205,22 @@ static int defrag_one_range(struct btrfs_inode *inode, u64 start, u32 len,
if (!folios)
return -ENOMEM;
+ /*
+ * Reserve delalloc space before locking the range and before locking
+ * and dirtying any folios - otherwise we could deadlock, for example
+ * after defrag of one range we dirty folios and keep them locked when
+ * we move to the next range, so reserving delalloc space right before
+ * each range could trigger flushing of delalloc and deadlock on the
+ * extent lock or trigger a transaction commit with flushoncommit, which
+ * can either deadlock on the lock of a folio made dirty in the previous
+ * range or the extent lock.
+ */
+ ret = btrfs_delalloc_reserve_space(inode, &data_reserved, start, len);
+ if (ret < 0) {
+ kfree(folios);
+ return ret;
+ }
+
/* Prepare all pages */
for (int i = 0; cur < start + len && i < nr_pages; i++) {
folios[i] = defrag_prepare_one_folio(inode, cur >> PAGE_SHIFT);
@@ -1246,10 +1255,11 @@ static int defrag_one_range(struct btrfs_inode *inode, u64 start, u32 len,
goto unlock_extent;
list_for_each_entry(entry, &target_list, list) {
- ret = defrag_one_locked_target(inode, entry, folios, nr_pages,
- &cached_state);
- if (ret < 0)
- break;
+ defrag_one_locked_target(inode, entry, folios, nr_pages, &cached_state);
+ if (entry->start > last_defrag_end)
+ btrfs_delalloc_release_space(inode, data_reserved, last_defrag_end,
+ entry->start - last_defrag_end, true);
+ last_defrag_end = entry->start + entry->len;
}
list_for_each_entry_safe(entry, tmp, &target_list, list) {
@@ -1266,6 +1276,12 @@ static int defrag_one_range(struct btrfs_inode *inode, u64 start, u32 len,
folio_put(folios[i]);
}
kfree(folios);
+ btrfs_delalloc_release_extents(inode, len);
+ if (last_defrag_end < start + len)
+ btrfs_delalloc_release_space(inode, data_reserved, last_defrag_end,
+ start + len - last_defrag_end, true);
+ extent_changeset_free(data_reserved);
+
return ret;
}
--
2.53.0
^ permalink raw reply related [flat|nested] 1544+ messages in thread
end of thread, other threads:[~2026-09-12 10:53 UTC | newest]
Thread overview: 1544+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-12 6:36 [PATCH 6.18 0000/1518] 6.18.52-rc1 review Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0001/1518] net/mlx5e: xsk: Fix unlocked writing to ICOSQ Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0002/1518] drm/amd/display: Fix backlight max_brightness to match exported range Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0003/1518] drm/amd/display: Scale custom brightness curve from full range Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0004/1518] batman-adv: dat: atomically update mac addresses Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0005/1518] batman-adv: bla: avoid CRC corruption due to parallel claim add Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0006/1518] mm/damon/sysfs: read ops_id only once in damon_sysfs_apply_inputs() Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0007/1518] batman-adv: fix TX priority extraction for BATADV_FORW_MCAST Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0008/1518] ALSA: usb-audio: Relax __free() variable declarations Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0009/1518] ASoC: tegra210_mixer: sort the register default table Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0010/1518] dma-buf: dma-heap: dont publish fd before copy_to_user() succeeds Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0011/1518] i3c: master: Fix device_register() error path Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0012/1518] mtd: rawnand: pl353: Add message about ECC mode Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0013/1518] net/mlx5e: SHAMPO, Always calculate page size Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0014/1518] nvme: fold nvme_config_discard() into nvme_update_disk_info() Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0015/1518] PCI: Introduce PCI_SLOT_PLACEHOLDER constant for slot_nr placeholder value Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0016/1518] perf/core: Fix deadlock in perf_mmap() failure path Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0017/1518] platform/x86: intel_sar: Check ACPI_HANDLE() against NULL Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0018/1518] platform/x86: ISST: Check for admin capability for write commands Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0019/1518] PM: runtime: Wrapper macros for ACQUIRE()/ACQUIRE_ERR() Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0020/1518] ring-buffer: Show persistent buffer dropped events in trace_pipe file Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0021/1518] staging: rtl8723bs: fix spacing around operators Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0022/1518] tracing/probes: ignore id update from btf_type_skip_modifiers Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0023/1518] udf: Move udf_map_block() up Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0024/1518] wifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0025/1518] compiler_types: Move lock checking attributes to compiler-context-analysis.h Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0026/1518] i2c: qcom-cci: Do not check return value of cci_init() Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0027/1518] tracing: Clean up use of trace_create_maxlat_file() Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0028/1518] io_uring: unify task_work cancelation checks Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0029/1518] nvdimm: preserve flush callback -ENOMEM Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0030/1518] ALSA: FCP: do not copy out an uninitialised init response Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0031/1518] ASoC: tegra: Fix the MIXER enable default value Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0032/1518] i3c: master: Fix recursive locking during device registration Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0033/1518] iio: light: apds9306: fix PM reference leak in apds9306_read_data() Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0034/1518] misc: fastrpc: dont publish fd before copy_to_user() succeeds Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0035/1518] mtd: rawnand: pl353: Make sure we use the monolithic helpers for raw accesses Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0036/1518] net/mlx5e: do not HW-GRO coalesce small frames Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0037/1518] nvme: skip the zoned limits update if the zone info query failed Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0038/1518] PCI: Allow per function PCI slots to fix slot reset on s390 Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0039/1518] perf: Fix use-after-free when perf mmap() revival races with the last munmap() Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0040/1518] platform/x86: int1092: Fix potential memory leak in sar_probe() Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0041/1518] platform/x86: ISST: Validate max level for set feature Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0042/1518] ring-buffer: Allow splice reads on static buffers Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0043/1518] staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie() Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0044/1518] tracing/probes: Fix BTF kflag check for anonymous struct member access Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0045/1518] udf: Fix data loss when converting inline inodes to out of line Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0046/1518] futex: Optimize futex hash bucket access patterns Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0047/1518] i2c: qcom-cci: Remove overcautious disable_irq() calls Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0048/1518] tracing: Make printk_trace global for tracing system Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0049/1518] io_uring/waitid: have io_waitid_complete() remove wait queue entry Greg Kroah-Hartman
2026-09-12 6:36 ` [PATCH 6.18 0050/1518] nvdimm: pmem: keep PREFLUSH before data writes Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0051/1518] futex: Provide rt_mutex_.*_schedule() equivalents for futex scheduling Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0052/1518] i2c: qcom-cci: fix autosuspend cleanup Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0053/1518] tracing: Take trace_array reference when opening options file Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0054/1518] io_uring: only call io_should_terminate_tw() once for ctx Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0055/1518] nvdimm: virtio_pmem: stop allocating child flush bio Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0056/1518] io_uring: add wrapper type for io_req_tw_func_t arg Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0057/1518] nvdimm: virtio_pmem: always wake -ENOSPC waiters Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0058/1518] io_uring/waitid: honor task_work cancellation Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0059/1518] nvdimm: virtio_pmem: use READ_ONCE()/WRITE_ONCE() for wait flags Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0060/1518] io_uring/waitid: avoid siginfo copy during ring teardown Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0061/1518] nvdimm: virtio_pmem: refcount requests for token lifetime Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0062/1518] accel/amdxdna: return early from a zero-length flush Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0063/1518] clk: qcom: Fix test_ctl_hi field for DEFAULT_EVO PLLs Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0064/1518] ftrace: Take trace_array reference before accessing its ftrace_ops Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0065/1518] i3c: master: Do not treat master device as a duplicate target Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0066/1518] i3c: master: Fix use-after-free of master->this Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0067/1518] mm/huge_memory: transfer the pmd dirty bit to the folio on zap Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0068/1518] mm/mremap: reset unfaulted VMA page offset for MREMAP_DONTUNMAP Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0069/1518] mm/secretmem: properly account locked pages Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0070/1518] mm: fix incorrect vm_flags usage when checking allowable orders for tmpfs Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0071/1518] perf/x86/intel: Remove anythread_deprecated bit from perf_capabilities Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0072/1518] platform/x86/amd/pmc: Fix msg_port restoration in amd_stb_debugfs_open_v2() Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0073/1518] platform/x86: hp-wmi: Add support for OMEN MAX 16-ak0xxx (8DD6) Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0074/1518] staging: sm750fb: fix mono image source stride mismatch in lynxfb_ops_imageblit() Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0075/1518] tracing/probes: Fix anon_stack check for unnamed bitfields in btf_find_struct_member Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0076/1518] usb: cdnsp: fix wakeup from S3 after controller context loss Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0077/1518] usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers() Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0078/1518] wifi: rtw89: pci: add .shutdown callback to stop rfkill polling on reboot Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0079/1518] dm-pcache: reject a kset that overruns its segment Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0080/1518] dm-pcache: bound the logical key offset from persistent memory Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0081/1518] dm-pcache: validate the persisted dirty_tail chain at load Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0082/1518] KVM: arm64: nv: Fully update VNCR fixmap state in kvm_translate_vncr() Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0083/1518] KVM: arm64: Handle VNCR TLB invalidation race with vcpu_put() VNCR unmapping Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0084/1518] media: dt-bindings: nxp,imx8-isi: Drop fsl,blk-ctrl requirement for i.MX8ULP Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0085/1518] KVM: arm64: Remove VM-wide VNCR mapping counter Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0086/1518] KVM: x86: Disallow EFER.LME and EFER.LMA if long mode is not supported Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0087/1518] KVM: s390: Zero initialize data structures for inject_pfault_token Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0088/1518] KVM: x86: Extract REGS and SREGS runtime sync code to helpers Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0089/1518] KVM: x86: Rename __{g,s}et_sregs2() => kvm_vcpu_ioctl_x86_{g,s}et_sregs2() Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0090/1518] KVM: x86: Move the bulk of register specific code from x86.c to regs.c Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0091/1518] KVM: x86: Check EFER validity on KVM_SET_SREGS* Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0092/1518] Smack: Fix error in capability bypass Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0093/1518] drm: Remove unused header in drm_dumb_buffers.c Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0094/1518] drm: lcdif: Wait for vblank before disabling DMA Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0095/1518] drm/bridge: synopsys: dw-dp: Support unregistering the AUX channel Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0096/1518] drm/bridge: synopsys: dw-dp: Set pixel mode by platform data Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0097/1518] drm/rockchip: dw_dp: Simplify error handling Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0098/1518] drm/rockchip: dw_dp: Add missing newline in dev_err_probe() message Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0099/1518] drm/rockchip: dw_dp: Release core resources Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0100/1518] drm/rockchip: vop2: Fix wrong wait target in layer cfg done check Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0101/1518] drm/rockchip: vop2: Wait for layer cfg done before switching LAYERSEL_REGDONE_SEL Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0102/1518] drm/rockchip: analogix_dp: Enable hclk for RK3588 Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0103/1518] drm/rockchip: analogix_dp: Fix OF node reference leak via auto cleanup Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0104/1518] drm/bridge: display-connector: dont autoenable HPD IRQ Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0105/1518] drm/bridge: display-connector: trigger initial HPD event for DP Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0106/1518] drm/v3d: Clear queue->active_job when v3d_fence_create() fails Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0107/1518] drm/rockchip: vop2: Add RK3576 to the RG swap special case Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0108/1518] drm/rockchip: vop2: Recognise 10-bit YUV422 as YUV format Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0109/1518] drm/bridge: cdns-dsi: Return an error pointer on allocation failure Greg Kroah-Hartman
2026-09-12 6:37 ` [PATCH 6.18 0110/1518] drm/bridge: cdns-mhdp8546: " Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0111/1518] smack: fix incorrect task context in smack_msg_queue_msgrcv Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0112/1518] smack: simplify write handlers of sysfs entries Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0113/1518] smack: deduplicate smackfs/{direct,mapped} file_operations Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0114/1518] smack: restrict smackfs/{direct,mapped} values to 0-255 Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0115/1518] sched_ext/scx_flatcg: Fix cvtime_delta race and add hweight scaling to bypass charging Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0116/1518] x86/cfi: Use symmetric SYM_START and SYM_END in __CFI_TYPE() Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0117/1518] platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0118/1518] selftests: proc: include fcntl.h in proc-pidns Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0119/1518] HID: core: quiesce input in hid_hw_stop() to prevent use-after-free Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0120/1518] HID: nintendo: Fix imu_timestamp_us double increment per report Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0121/1518] HID: roccat: bound device-supplied profile index Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0122/1518] soc: samsung: exynos-pmu: fix of_node refcount leak in exynos_get_pmu_regmap() Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0123/1518] media: cec-pin: Fix event FIFO ordering Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0124/1518] cxl/mbox: Clamp mailbox output allocation to the payload size Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0125/1518] cxl/pci: Remove incorrect mbox.valid check in cxl_pci_type3_init_mailbox() Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0126/1518] clk: versaclock7: Fix APLL clock leak on probe failure Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0127/1518] clk: moxart: remove unused variables, fix refcount leak Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0128/1518] clk: nuvoton: ma35d1: fix ignored div_u64 return values in PLL freq calculation Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0129/1518] clk: nuvoton: ma35d1: fix PLL_CTL1_FRAC bit field width and fractional calc Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0130/1518] clk: nuvoton: ma35d1: fix ma35d1_clk_pll_determine_rate logic Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0131/1518] clk: stm32: add missing bitfield.h header Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0132/1518] ASoC: rt700-sdw: always drain jack work on remove Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0133/1518] ASoC: fsl_audmix: rework runtime PM handling in probe Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0134/1518] clk: hisilicon: reset: Use devm_kzalloc to initialize hisi_reset_controller Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0135/1518] ARM: imx: fix device_node refcount leak in imx_src_init() Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0136/1518] ARM: imx: fix device_node refcount leaks in imx7_src_init() Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0137/1518] arm64: dts: imx93-kontron: set memory node to 0x80000000/1GiB Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0138/1518] clk: imx: scu: drop redundant init.ops variable assignment Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0139/1518] drm/lima: call drm_mm_init() with a valid allocation range Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0140/1518] mm/mm_init: fix incorrect node_spanned_pages Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0141/1518] sched/fair: Fix overflow in update_tg_cfs_runnable() Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0142/1518] perf/x86/intel/uncore: Keep PCI PMUs working when MMIO/MSR setup fails Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0143/1518] pinctrl: bcm2835: Dont remove an unregistered GPIO chip Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0144/1518] riscv: kexec_file: Fix crashk_low_res not exclude bug Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0145/1518] media: keymaps: Remove obsolete RC_MAP_RC5_TV keymap define Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0146/1518] media: keymaps: Remove obsolete RC_MAP_HAUPPAUGE_NEW " Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0147/1518] wifi: ath12k: correct monitor destination ring size Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0148/1518] perf test: Drain pipe after child finishes to avoid losing output Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0149/1518] perf test: Refactor parallel poll loop to drain all pipes simultaneously Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0150/1518] perf test: Show snippet failure output for verbose=1 Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0151/1518] perf test: Add summary reporting Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0152/1518] perf test: Fix subtest status alignment for multi-digit indexes Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0153/1518] perf test: Add -j/--junit option for JUnit XML test reports Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0154/1518] perf test: Truncate printed test descriptions dynamically to avoid terminal wrapping Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0155/1518] perf test: Truncate test description to fit terminal width Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0156/1518] perf test metrics: Update all metrics for possibly failing default metrics Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0157/1518] perf test all metrics: Fully ignore Default metric failures Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0158/1518] perf test: Do not skip when some metrics tests succeeded Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0159/1518] perf tests: Skip metrics validation if system-wide recording lacks permission Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0160/1518] perf test kvm: Add some basic perf kvm test coverage Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0161/1518] perf tests: Add robust record retry helper and use subsecond workloads Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0162/1518] perf tests: Fix flakiness in trace record and replay test Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0163/1518] perf test: Fix perf stat --bpf-counters on hybrid machines Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0164/1518] perf tests: Fix flakiness in BPF counters test on hybrid systems Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0165/1518] perf test: Fixes for check branch stack sampling Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0166/1518] perf tests: Fix flakiness in branch stack sampling tests Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0167/1518] regulator: tps6594: Fix device node reference leaks in multiphase loop Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0168/1518] drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0169/1518] drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup Greg Kroah-Hartman
2026-09-12 6:38 ` [PATCH 6.18 0170/1518] tools/bpf/bpftool: Reset vmlinux BTF after map commands Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0171/1518] tools/bpf/bpftool: Reset vmlinux BTF after struct_ops commands Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0172/1518] bpf: Copy per-CPU map value padding in copy_map_value_long() Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0173/1518] selftests/bpf: Systematically add SO_REUSEADDR in start_server_addr Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0174/1518] selftests/bpf: Mask socket type flags in mptcpify prog Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0175/1518] bpf,lsm: Drop bpf_prog_free from sleepable_lsm_hooks Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0176/1518] mm: convert memory block states (MEM_*) macros to enum Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0177/1518] mm: change type of state in struct memory_block Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0178/1518] mm: name the anonymous MMOP enum as enum mmop Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0179/1518] mm/mm_init: handle alloc_percpu failure in free_area_init_core_hotplug Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0180/1518] dmaengine: mediatek: mtk-uart-apdma: Return -ENOMEM on memory allocation failure Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0181/1518] dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0182/1518] dmaengine: zynqmp_dma: fix race between runtime PM and device removal Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0183/1518] dmaengine: hisilicon: Return -ENOMEM on dynamic memory allocation in probe Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0184/1518] soundwire: qcom: Fix port exhaustion check in stream_alloc_ports Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0185/1518] iio: orientation: hid-sensor-rotation: Avoid race between callback setup and device exposure Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0186/1518] csky: Fix a4/a5 restoration in syscall trace path Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0187/1518] selftests/rseq: Replace glibc-specific __GNUC_PREREQ with portable check Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0188/1518] platform/chrome: sensorhub: Fix memory overread in ring handler Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0189/1518] wifi: rtw89: fill addr cam H2C command by struct Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0190/1518] wifi: rtw89: update format of addr cam H2C command Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0191/1518] wifi: rtw89: check return values in rtw89_ops_start_ap() Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0192/1518] wifi: rtw89: fix HE extended capability length check Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0193/1518] fanotify: initialize permission event watchdog state Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0194/1518] tools/nolibc: mark arg1 operand in __nolibc_syscall0() as write-only Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0195/1518] perf cs-etm: Fix thread leaks on trace queue init failure Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0196/1518] perf/x86/amd/uncore: Add group validation Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0197/1518] perf vendor events amd: Update Zen 5 core events Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0198/1518] hwrng: core - fix rng list on registration error Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0199/1518] crypto: qat - cancel work on re-enable SR-IOV timeout Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0200/1518] crypto: qat - clear AES key schedule from stack Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0201/1518] crypto: atmel-ecc - reject hardware ECDH without a public key Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0202/1518] crypto: atmel-sha204a - fix heap info leak on I2C transfer failure Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0203/1518] crypto: sa2ul - stop probe if context pool creation fails Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0204/1518] hwrng: xilinx-trng - propagate timeout before any data is read Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0205/1518] crypto: rk3288 - fail ahash requests on HASH idle timeout Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0206/1518] crypto: keembay - Fix AEAD unregister count in error path Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0207/1518] RDMA/irdma: Deduplicate the irdma_del_memlist logic Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0208/1518] RDMA/irdma: Add a refcount to track user ring MR associations Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0209/1518] RDMA/irdma: Add irdma_cq fields to track pbl allocations Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0210/1518] RDMA/irdma: Add refcounting to user ring MRs Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0211/1518] arm64: dts: qcom: sm8750: wire UFS to ice instance Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0212/1518] nvme-apple: Use acquire/release for queue enabled state Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0213/1518] nvmet-rdma: factor out response resource cleanup Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0214/1518] nvmet-rdma: fix response resource leak on queue teardown Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0215/1518] bus: ti-sysc: Fix /chosen node reference leak Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0216/1518] PM: sleep: Fix off-by-one in wakelocks number limit check Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0217/1518] cgroup/cpuset: Make nr_deadline_tasks an atomic_t Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0218/1518] arm64: dts: qcom: sc8280xp-blackrock: switch to uefi rtc offset Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0219/1518] arm64: dts: qcom: sm7225-fairphone-fp4: Fix address in fb node name Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0220/1518] arm64: dts: qcom: hamoa: Fix clocks for HSPHYs Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0221/1518] clk: qcom: gcc-glymur: Move EVA clocks to critical clock list Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0222/1518] bus: qcom-ebi2: Simplify with scoped for each OF child loop Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0223/1518] bus: qcom-ebi2: Fix clock leak on probe failure Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0224/1518] wifi: mac80211_hwsim: avoid NULL skb in stop queue drain Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0225/1518] staging: greybus: audio: correct sscanf() return value check Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0226/1518] staging: sm750fb: gate dualview dataflow using g_dualview Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0227/1518] staging: sm750fb: Add missing Kconfig dependency Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0228/1518] greybus: audio: bound the topology section sizes against the fetched size Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0229/1518] staging: fbtft: Use sysfs_emit_at() to print to sysfs file Greg Kroah-Hartman
2026-09-12 6:39 ` [PATCH 6.18 0230/1518] staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0231/1518] staging: octeon: fix free_irq dev_id mismatch in cvm_oct_rx_shutdown Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0232/1518] staging: octeon: ethernet-mem: replace pr_warn with dev_warn in free functions Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0233/1518] staging: octeon: replace pr_warn with dev_warn in fill and rx paths Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0234/1518] staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0235/1518] staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0236/1518] ALSA: via82xx: Remove unreachable branch in snd_via686_pcm_pointer() Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0237/1518] selftests/bpf: Fix memory leak in msg_alloc_iov error path Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0238/1518] selftests/bpf: Fix memory leak in msg_alloc_iov Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0239/1518] selftests/lsm: Fix memory leak in attr_lsm_count Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0240/1518] irqchip/gic-v3-its: Fix memleak in its_probe_one() Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0241/1518] irqchip/gic-v3-its: Fix its node leak in gic_acpi_parse_madt_its() Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0242/1518] selftests: timers: leap-a-day: Fix -w option and update usage comment Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0243/1518] clocksource: Unregister subsystem on device registration failure Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0244/1518] timekeeping: Unwind aux clock sysfs children on failure Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0245/1518] timers/migration: Fix memory leak in tmigr_setup_groups() error path Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0246/1518] x86/tsx: Make tsx_ctrl_state static Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0247/1518] vdso/timens: Move functions to new file Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0248/1518] timens: Remove dependency on the vDSO Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0249/1518] timens: Add a __free() wrapper for put_time_ns() Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0250/1518] timens: Simplify some calls to put_time_ns() Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0251/1518] time/namespace: Validate nanosecond field in proc_timens_set_offset() Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0252/1518] y2038: uapi: Use 64-bit __kernel_old_timespec::tv_nsec on x32 Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0253/1518] timekeeping: Account for monotonicity adjustment in ntp_error Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0254/1518] arm64: dts: qcom: Add #{address,size}-cells to Chromium-based /firmware Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0255/1518] clk: qcom: gdsc: propagate gdsc_check_status() errors from gdsc_poll_status Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0256/1518] clk: qcom: gdsc: propagate gdsc_enable() failure for ALWAYS_ON domains Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0257/1518] clk: qcom: gdsc: tear down per-domain genpds in gdsc_unregister() Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0258/1518] arm64: dts: qcom: sc8280xp-arcata: Fix top USB-C DP alt mode Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0259/1518] arm64: dts: qcom: sc8180x-primus: Rename regulator nodes Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0260/1518] arm64: dts: qcom: sc8180x-primus: Describe the display power net Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0261/1518] arm64: dts: qcom: sc8180x-lenovo-flex-5g: Rename regulator nodes Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0262/1518] arm64: dts: qcom: sc8180x-lenovo-flex-5g: Describe the display power net Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0263/1518] clk: qcom: gcc-qcs8300: Use retention for PCIe power domains Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0264/1518] clk: qcom: gcc-qcs8300: Use retention for USB " Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0265/1518] perf data convert json: Fix trace_seq memory leak in process_sample_event() Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0266/1518] staging: media: ipu7: fix pm_runtime refcount leak in ipu7_init_fw_code_region_by_sys() Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0267/1518] staging: media: ipu7: fix pm_runtime refcount leak in ipu7_resume() Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0268/1518] thermal/drivers/rcar: Fix error checking in probe() Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0269/1518] usb: typec: ucsi: unregister debugfs entries on teardown Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0270/1518] usb: gadget: r8a66597: avoid double free of ep0_req in probe error path Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0271/1518] udf: Mark LVID buffer as uptodate before marking it dirty Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0272/1518] bpftool: Check EVP_Digest when computing excl_prog_hash Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0273/1518] perf vendor events amd: Reintroduce deprecated Zen 5 core events Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0274/1518] perf dso: Fix kallsyms DSO detection with fallback logic Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0275/1518] bpf: Fix vmlinux BTF prep race in bpf_get_btf_vmlinux Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0276/1518] efi: fix stale reference to efi_recover_from_page_fault() Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0277/1518] bpf: Fix use-after-free on mm_struct in bpf_find_vma() Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0278/1518] bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0279/1518] iommu/mediatek-v1: Fix off-by-one in MT2701_LARB_NR_MAX Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0280/1518] bpf: Fix security_bpf_map_create error handling Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0281/1518] iommu/msm: Return -ENOMEM on memory allocation failure in probe Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0282/1518] iommu/amd: Prevent SB IOAPIC from overriding IVRS validation errors Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0283/1518] iommu/amd: Add support for Hygon family 18h model 4h IOAPIC Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0284/1518] iommu/amd: Fix false positive in SB IOAPIC IVRS validation Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0285/1518] leds: pca9532: Fix inverted GPIO output polarity Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0286/1518] leds: st1202: Stop pattern sequence before reprogramming Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0287/1518] leds: st1202: Fix pattern duration prescaler and pattern_clear skip marker Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0288/1518] leds: st1202: Fix spurious pattern sequence start in setup Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0289/1518] leds: st1202: Set all pattern PWM slots to full after clearing pattern Greg Kroah-Hartman
2026-09-12 6:40 ` [PATCH 6.18 0290/1518] leds: st1202: Fix brightness having no effect while pattern mode is active Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0291/1518] leds: st1202: Disable channel when brightness is set to zero Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0292/1518] leds: st1202: Validate LED reg property against channel count Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0293/1518] printk: Introduce console_flush_one_record Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0294/1518] printk: Fix possible console use-after-free Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0295/1518] ACPI: RISC-V: Fix riscv_acpi_irq_get_dep() loop termination Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0296/1518] ACPI: RISC-V: Check acpi_get_handle() status in riscv_acpi_add_prt_dep() Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0297/1518] ACPI: RISC-V: Fix riscv_acpi_add_prt_dep() loop handling Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0298/1518] platform/x86: dell-privacy: Fix race condition Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0299/1518] platform/x86: dell-wmi-base: Fix resource leak on module load failure Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0300/1518] platform/x86: lg-laptop: Drop debug-only ACPI notify handler Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0301/1518] platform/x86: lg-laptop: Convert ACPI driver to a platform one Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0302/1518] platform/x86: lg-laptop: Fix LED resource handling Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0303/1518] remoteproc: qcom_q6v5_adsp: Fix reference leak for device node Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0304/1518] hwspinlock: propagate errno when registering single lock Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0305/1518] selftests/sched_ext: Fix bpf_link leak on early return in prog_run Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0306/1518] perf capstone: Fix kernel map reference count leak Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0307/1518] spi: qcom-geni: Fix missing error check on pm_runtime_get_sync() Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0308/1518] serial: core: Add dedicated uart_port field for console flow Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0309/1518] serial: Replace driver usage of UPF_CONS_FLOW Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0310/1518] serial: 8250: Set cons_flow on port registration Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0311/1518] serial: 8250: Add support for console flow control Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0312/1518] serial: 8250: Clear CON_PRINTBUFFER on port re-registration Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0313/1518] serial: ma35d1: Fix OF node reference leaks in console init Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0314/1518] serial: qcom-geni: do not advance stale DMA completions Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0315/1518] usb: gadget: f_fs: Fix fence cleanup in ffs_dmabuf_transfer() error paths Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0316/1518] usb: gadget: configfs: fix out-of-bounds read of qw_sign Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0317/1518] usb: ljca: bound bank_num in ljca_enumerate_gpio() Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0318/1518] usb: gadget: aspeed_udc: check endpoint DMA allocation Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0319/1518] usb: fix UAF when probe runs concurrent to dyn ID removal Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0320/1518] platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0321/1518] platform/surface: acpi-notify: Check ACPI companion before use Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0322/1518] usb: mtu3: allow system suspend during active gadget connection Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0323/1518] usb: renesas_usbhs: Fix power-off ordering on unbind Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0324/1518] usb: ucsi: huawei_gaokun: support mode switching Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0325/1518] usb: typec: ucsi: gaokun: unwind notifier on UCSI register failure Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0326/1518] drm/panel: samsung-s6d16d0: Power off on prepare failure Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0327/1518] perf metricgroup: Fix metric expression copy leaks Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0328/1518] soc: qcom: rpmh-rsc: manage PM notifiers with devres Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0329/1518] bus: qcom-ebi2: use managed resources for clocks and children Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0330/1518] clk: qcom: camcc-sc8280xp: unregister CAMCC_GDSC_CLK Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0331/1518] tools/sched_ext: Strip compatibility macros for cgroup and dispatch APIs Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0332/1518] bpf: Require a BPF cpumask for bpf_cpumask_populate() Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0333/1518] wifi: rtw89: pci: add to read PCI configuration space from common code Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0334/1518] wifi: rtw89: fw: parse firmware element of DIAG_MAC Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0335/1518] wifi: rtw89: debug: add parser to diagnose along DIAG_MAC fw element Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0336/1518] wifi: rtw89: mlo: rearrange MLSR link decision flow Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0337/1518] wifi: rtw89: phy: support per PHY RX statistics Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0338/1518] wifi: rtw89: 8852a: fix RSSI report when average beacon RSSI is not ready Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0339/1518] iio: accel: dmard09: Implement IIO_CHAN_INFO_SCALE Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0340/1518] RDMA/core: Wait for RCU callbacks before unloading ib_core Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0341/1518] RDMA/mlx5: Drain RCU callbacks during module teardown Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0342/1518] RDMA/ipoib: " Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0343/1518] RDMA/rxe: Avoid reprocessing the current packet after the QP enters the error state Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0344/1518] drm/msm/dp: add missing drm_edid_connector_update() before add_modes on cached EDID Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0345/1518] Revert "drm/msm: dsi: fix PLL init in bonded mode" Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0346/1518] crypto: ccp - Fix memory leak in SEV INIT_EX path Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0347/1518] hwrng: ks-sa - Fix runtime PM cleanup on registration failure Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0348/1518] crash_dump: release keyring reference at the correct time Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0349/1518] xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full Greg Kroah-Hartman
2026-09-12 6:41 ` [PATCH 6.18 0350/1518] ALSA: hpi: Check transport errors during HPI6000 adapter initialization Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0351/1518] pmdomain: bcm: bcm2835: handle genpd provider registration errors Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0352/1518] misc: rtsx_usb: avoid USB I/O in runtime autosuspend Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0353/1518] RDMA/hfi1: Preserve unit 0 on allocation failure Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0354/1518] RDMA/hfi1: Free RX data on late probe failure Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0355/1518] RDMA/hfi1: Remove redundant PCI device ID validation Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0356/1518] RDMA/hfi1: Create workqueues before device initialization Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0357/1518] RDMA/hfi1: Stop flushing the global IB workqueue Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0358/1518] RDMA/hfi1: Initialize debugfs after probe completes Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0359/1518] ASoC: apple: mca: increase SERDES reset delay Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0360/1518] isofs: fix out-of-bounds page array access on empty zisofs block Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0361/1518] iommufd/selftest: Avoid selftest dirty bitmap size wrap Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0362/1518] media: v4l2-async: Unregister sub-device if asc_list is empty Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0363/1518] fs/resctrl: Prevent use-after-free in rdtgroup_kn_put() Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0364/1518] perf zstd: Fix compression error path in zstd_compress_stream_to_records() Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0365/1518] perf record: Return the written size from process_comp_header() Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0366/1518] perf record: Fix multiple PERF_RECORD_COMPRESSED2 records per push Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0367/1518] rpmsg: glink: remove duplicate code for rpmsg device remove Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0368/1518] rpmsg: glink: fix deadlock in endpoint destroy during driver detach Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0369/1518] iommufd: Simplify iommufd_device_remove_vdev() Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0370/1518] cxl/memdev: Fix firmware upload exact-fit handling Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0371/1518] cxl/mbox: Break poison list loop on an empty payload Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0372/1518] cxl/pci: Honor -EPROBE_DEFER from component register setup Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0373/1518] cxl/port: Restart port enumeration when a sibling adds the dport first Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0374/1518] hfsplus: validate thread record before delete key rebuild Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0375/1518] wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0376/1518] x86/entry/fred: Encode frame pointer on entry Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0377/1518] firmware: arm_scmi: Publish channel state before callbacks Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0378/1518] firmware: arm_scmi: Unregister device notifier before IDR teardown Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0379/1518] firmware: arm_scmi: Quiesce notifications before teardown Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0380/1518] firmware: arm_scmi: Clean up channels on setup failure Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0381/1518] firmware: arm_scmi: Free transport channel on IDR failure Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0382/1518] firmware: arm_scmi: Avoid IDR updates while cleaning channels Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0383/1518] firmware: arm_scmi: Reject out of range DT protocol IDs Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0384/1518] firmware: arm_scmi: Use channel ID for transport teardown Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0385/1518] firmware: arm_scmi: Protect device request lookup with RCU Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0386/1518] firmware: arm_scmi: Drop handle on protocol bind failures Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0387/1518] firmware: arm_scmi: Unwind TX receiver mailbox setup failure Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0388/1518] firmware: arm_scmi: Unwind P2A " Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0389/1518] firmware: arm_scmi: Fix transport device teardown lookup Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0390/1518] cxl/features: Reject Get Feature count larger than the output buffer Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0391/1518] cxl/features: Reject Set Features output buffer smaller than the header Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0392/1518] cxl/features: Clamp Get Feature output size to the remaining buffer Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0393/1518] regulator: adp5055: Fix error code in adp5055_of_parse_cb() Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0394/1518] tools/sched_ext: scx_qmap: Fix stale API name in comment Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0395/1518] libnvdimm/labels: Bound the on-media label size before the shift Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0396/1518] dax: read holder_ops once in dax_holder_notify_failure() Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0397/1518] cpufreq: spear: Fix an IS_ERR() vs NULL bug in spear1340_set_cpu_rate() Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0398/1518] PCI: xgene: Drop unnecessary OF node reference Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0399/1518] irqchip/renesas-irqc: Fix generic interrupt chip leak on remove Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0400/1518] media: i2c: rdacm21: Fix missing media_entity_cleanup() Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0401/1518] media: bcm2835-unicam: Fix asc leaked in error/remove path Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0402/1518] media: ipu6: Do not free aux device pdata after init Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0403/1518] drm/amd/display: Fix DM I2C teardown race Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0404/1518] drm/amd/display: Remove unused-but-set variable hubp from Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0405/1518] cpufreq: intel_pstate: Fix setting minimum P-state at init time Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0406/1518] cpufreq: schedutil: Fix self-contradictory comment in sugov_iowait_apply() Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0407/1518] remoteproc: qcom: Fix glink->node reference leak in qcom_add_glink_subdev Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0408/1518] perf: evsel: Fix error handling in tp_format lookup Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0409/1518] drm/bridge: tc358767: clamp the reported AUX read size to the request Greg Kroah-Hartman
2026-09-12 6:42 ` [PATCH 6.18 0410/1518] x86/mm/pat: Take cpa_lock around large-page collapse Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0411/1518] arm64: dts: qcom: msm8996-xiaomi-gemini: Fix up ti,drv2604 enable GPIO Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0412/1518] arm64: dts: qcom: sc8280xp-x13s: Fix the drive-strength of mclk pin Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0413/1518] arm64: dts: qcom: ipq5018: Correct CMN PLL reference clock rate Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0414/1518] arm64: qcom: ipq5018: Add GEPHY RX and TX clocks Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0415/1518] arm64: dts: qcom: sm8250: sort out Iris power domains Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0416/1518] arm64: dts: qcom: sm8250: correct frequencies in the Iris OPP table Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0417/1518] perf jevents: Add more components to the metric sorting order Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0418/1518] clk: qcom: gcc-glymur: Enable runtime PM Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0419/1518] soc: renesas: r8a78000: Drop duplicate "default ARCH_RENESAS" Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0420/1518] spi: geni-qcom: Fix sticky ret causing wrong return value on invalid proto Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0421/1518] wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0422/1518] wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0423/1518] wifi: iwlwifi: mei: check SAP message length before reading it Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0424/1518] wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0425/1518] wifi: iwlwifi: mei: pass correct argument to function Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0426/1518] gpu: host1x: Fix offset calculation in trace_write_gather Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0427/1518] gpu: host1x: Avoid stack over-read in debug output helpers Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0428/1518] drm/msm/a6xx: Fix stale rpmh votes after suspend Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0429/1518] drm/msm: Recover HW before retire hung submit Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0430/1518] drm/msm/a6xx: Fix A663 GPUCC register list for state capture Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0431/1518] drm/msm/a6xx: Rebase GMU register offsets Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0432/1518] drm/msm/a6xx: Fix A621 GPUCC register list for state capture Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0433/1518] drm/msm: Fix task_struct reference leak in recover_worker Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0434/1518] drm/msm: Only fini scheduler after successful init Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0435/1518] bpf: Sync tail_call_reachable with callee state on entry Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0436/1518] crypto: sl3516 - drop invalid sg_dma_len checks before DMA mapping Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0437/1518] ACPI: processor: idle: Expand _LPI package sanity checks Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0438/1518] usb: gadget: f_uac1_legacy: remove broken string configfs attributes Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0439/1518] tty: hvc: restrict HVC_DCC to ARMv6+ and ARM64 Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0440/1518] UDF symlink pathComponent header OOB read Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0441/1518] staging: rtl8723bs: Fix operator spacing in rtw_security.c Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0442/1518] staging: rtl8723bs: use standard offsetof in cfg80211 operations Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0443/1518] staging: rtl8723bs: fix operator and type cast spacing Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0444/1518] staging: rtl8723bs: expand multiple assignment into separate statements Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0445/1518] staging: rtl8723bs: replace rtw_zmalloc() with kzalloc() Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0446/1518] staging: rtl8723bs: remove multiple blank lines in core/ Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0447/1518] staging: rtl8723bs: fix xmit_frame/xmit_buf leaks on mgnt-frame error paths Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0448/1518] gpib: Move stuck SRQ update under lock Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0449/1518] uio: Fix stale info pointer in failed registration path Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0450/1518] accessibility: speakup: Fix incorrect string length computation in report_char_chartab_status() Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0451/1518] speakup: keyhelp: guard letter_offsets possible out-of-range indexing Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0452/1518] misc: bcm-vk: Use acquire/release for msgq_inited Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0453/1518] misc: rtsx: add missing write register handling Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0454/1518] misc: ad525x_dpot: use driver core groups for sysfs files Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0455/1518] misc: lan966x_pci: depopulate children on populate failure Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0456/1518] cacheinfo: dont propagate DT/ACPI error when arch supplies info (arm64) Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0457/1518] ppdev: prevent overflow when setting port timeout Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0458/1518] ipack: ipoctal: fix UAF, null-ptr-deref, and use-after-free in cleanup on remove Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0459/1518] char: xilinx_hwicap: unregister class on init errors Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0460/1518] vfio/pci: clear vdev->msi_perm after freeing it on init failure Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0461/1518] soc: ti: knav_qmss_queue: Implement resource cleanup in remove() Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0462/1518] soc: ti: knav_qmss: Remove debugfs file on teardown Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0463/1518] mtd: intel-dg: wake card on operations Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0464/1518] mtd: intel-dg: Fix runtime PM error path in probe Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0465/1518] mtd: mtdswap: Avoid freeing registered blktrans device twice Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0466/1518] mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0467/1518] perf ui hists: Fix uninitialized stack memory free on pstack allocation failure Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0468/1518] software node: Fix software_node_get_reference_args() with index -1 Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0469/1518] driver core: soc: Unregister bus on early device registration failure Greg Kroah-Hartman
2026-09-12 6:43 ` [PATCH 6.18 0470/1518] drm/msm/a6xx: Fix RBBM_CLOCK_CNTL3_TP0 value in a730_hwcg Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0471/1518] bpf: Reject arena frees below the arena base Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0472/1518] dmaengine: dw-edma: Terminate all descriptors without callbacks Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0473/1518] dmaengine: dw-edma: Serialize abort state updates Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0474/1518] dmaengine: dw-edma: Serialize channel state checks Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0475/1518] dmaengine: dw-edma: Clear stale requests on termination Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0476/1518] ASoC: meson: Keep link pointers valid on realloc failure Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0477/1518] phy: starfive: Fix runtime PM cleanup in JH7110 DPHY TX probe Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0478/1518] phy: starfive: Fix runtime PM cleanup in JH7110 DPHY RX probe Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0479/1518] arm64: dts: amlogic: meson-axg: Add missing nand_rb0 pin to nand_all_pins Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0480/1518] arm64: dts: amlogic: meson-axg-s400: enable mipi_pcie_analog_dphy for PCIe Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0481/1518] RDMA/hfi1: Propagate sdma_txinit_ahg() errors Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0482/1518] RDMA/rxe: Validate num_sge/cur_sge before indexing wqe->dma.sge[] Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0483/1518] RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0484/1518] kcsan: avoid unintended access checking in NMIs Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0485/1518] arm64: dts: imx8-ss-audio: Fix LPCG clock indices for ASRC0 Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0486/1518] x86/bugs: Dont use cpu-type matching in cpu_vuln_blacklist Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0487/1518] selftests/bpf: Check malloc result with ASSERT_NEQ in test_sha256 Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0488/1518] selftests/bpf: Silence array bounds warning in global_map_resize Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0489/1518] irqchip/gic-v3-its: Prevent leak in its_vpe_irq_domain_alloc() Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0490/1518] RDMA/nldev: validate dynamic counter attribute length Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0491/1518] ACPI: EC: Avoid _REG disconnect on GPIO IRQ defer Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0492/1518] ACPI: processor: validate MADT IOAPIC entry bounds Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0493/1518] ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0494/1518] ext4: fix circular lock dependency in ext4_ext_migrate Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0495/1518] ext4: fix out-of-bounds read in ext4_read_inline_dir() Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0496/1518] ext4: skip extra isize expansion during mount to prevent deadlock Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0497/1518] platform/x86: acer-wmi: reject missing gaming WMI results Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0498/1518] bpf: Zero queue and stack outputs on lock failure Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0499/1518] libbpf: Search /lib64 and /lib in resolve_full_path() Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0500/1518] riscv, bpf: Fix memory leak in bpf_jit_free Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0501/1518] riscv, bpf: Fix kernel stack corruption in tailcall with CFI Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0502/1518] bpf, riscv: Fix extable handling for arena load_acquire Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0503/1518] ACPI: battery: Adjust charging status validation check Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0504/1518] virt: arm-cca-guest: use migrate_disable() for attestation token requests Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0505/1518] bpf: Fix offset warn check for bpf_res_spin_lock Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0506/1518] bpf: Preserve unique-field state across nested structs Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0507/1518] bpf: Mark bpf_refcount field as unique Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0508/1518] RDMA/srpt: Pass the mapped task attribute to target_init_cmd() Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0509/1518] PCI: j721e: Fix incorrect max_lanes for J7200 Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0510/1518] RDMA/erdma: Fix CEQ tasklet use-after-free on removal Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0511/1518] RDMA/mana_ib: drain QP references after partial table insertion Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0512/1518] RDMA/restrack: Fix typos in the comments Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0513/1518] RDMA/nldev: Fix locking when accessing mr->pd Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0514/1518] RDMA/core: Add rdma_restrack_begin/abort/commit_del() operations Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0515/1518] RDMA/core: Fix use after free in ib_query_qp() Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0516/1518] RDMA/core: Fix potential use after free in ib_destroy_cq_user() Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0517/1518] RDMA/core: Fix potential use after free in ib_destroy_srq_user() Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0518/1518] RDMA/core: Fix potential use after free in counter_release() Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0519/1518] RDMA/core: Fix potential use after free in ib_free_cq() Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0520/1518] RDMA/core: Fix potential use after free in uverbs_free_dmah() Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0521/1518] RDMA/core: Fix potential use after free in ib_dealloc_pd_user() Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0522/1518] firmware: arm_scmi: Fix requested device removal race Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0523/1518] iommu/amd: Fix undefined behavior in devid_write debugfs function Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0524/1518] iommu/qcom: Remove sysfs device on probe failure path Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0525/1518] iommu/qcom: Fix inverted fault report check in qcom_iommu_fault() Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0526/1518] iommu/arm-smmu-v3: Declare eats_s1chk and eats_trans as host-endian u64 Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0527/1518] thermal: intel: int3400: clean up ODVP on probe failures Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0528/1518] ext4: clear stale xarray tags on folios skipped during writeback Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0529/1518] ext4: drain in-flight DIO before buffered write fallback Greg Kroah-Hartman
2026-09-12 6:44 ` [PATCH 6.18 0530/1518] ext4: use fsdata to track inline data write state and fix race Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0531/1518] ext4: validate readdir offset before accessing dirent Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0532/1518] wifi: ath6kl: avoid buffer overreads in WMI event handlers Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0533/1518] wifi: ath12k: switch to name-based reserved memory lookup Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0534/1518] wifi: ath12k: refactor QMI memory assignment Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0535/1518] wifi: ath12k: allocate HOST_DDR and BDF regions after Q6 RO region Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0536/1518] wifi: ath12k: Correctly copy the hint BSSID in WMI scan request Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0537/1518] wifi: ath11k: " Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0538/1518] wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0539/1518] wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0540/1518] RDMA/bnxt_re: Clear VM_MAYWRITE on DBR/toggle page mmap Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0541/1518] ext4: fix buffer_head leak in ext4_init_orphan_info Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0542/1518] ext4: check dir entry fits before reading the hash trailer in ext4_search_dir() Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0543/1518] ARM: dts: allwinner: a10: Fix PMU interrupt Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0544/1518] cpufreq: amd-pstate-ut: Skip tests when amd-pstate driver is not active Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0545/1518] cpufreq/amd-pstate: Use sysfs_match_string() for epp Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0546/1518] amd-pstate: Make certain freq_attrs conditionally visible Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0547/1518] cpufreq/amd-pstate: Add dynamic energy performance preference Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0548/1518] cpufreq/amd-pstate: Add support for platform profile class Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0549/1518] cpufreq/amd-pstate: Fix EPP return type and handle errors during initialization Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0550/1518] cpufreq/amd-pstate: Toggle auto_sel in active mode on shared memory systems Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0551/1518] firmware: arm_scmi: Roll back partial protocol table registration Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0552/1518] firmware: arm_scmi: Unrequest devices if driver registration fails Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0553/1518] riscv: dts: spacemit: add MusePi Pro board device tree Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0554/1518] riscv: dts: spacemit: Add OrangePi R2S " Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0555/1518] riscv: dts: spacemit: k1: Split gmac_clk_ref into independent pinctrl groups Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0556/1518] perf cs-etm: Flush thread stacks after decoder reset Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0557/1518] perf cs-etm: Avoid truncating AUX buffer sizes to int Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0558/1518] xfrm: Fix skb double-free in xfrm_dev_direct_output() Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0559/1518] RDMA/erdma: complete object teardown when the destroy command fails Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0560/1518] PM: hibernate: Fix memory leak in snapshot_write_next() error path Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0561/1518] leds: pca9532: Fix phantom device registration on missing hardware Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0562/1518] perf cap: Remove used_root parameter and simplify capability checks Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0563/1518] drm/tve200: add OF module alias for autoloading Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0564/1518] netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0565/1518] fs/ntfs3: fix out-of-bounds read of INDEX_ROOT in reparse/objid init Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0566/1518] drm/panthor: return PTR_ERR() from devm_drm_dev_alloc() Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0567/1518] arm64: dts: rockchip: Add missing hclk for RK3588 eDP0 Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0568/1518] arm64: dts: rockchip: Add missing hclk for RK3588 eDP1 Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0569/1518] arm64: dts: rockchip: Fix Gru WLAN sideband interrupt Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0570/1518] arm64: dts: rockchip: Fix rk3566-bigtreetech-cb2 touchscreen property Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0571/1518] bpf: Fix CFI mismatch in task work callback Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0572/1518] ARM: lpc32xx: only run SoC init on LPC32xx hardware Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0573/1518] selftests/bpf: Fix incorrect error checking for pthread_create Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0574/1518] selftests/bpf: Fix memory leak on subtest_states reallocation Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0575/1518] cxl/region: Fix use-after-free in find_pos_and_ways() error path Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0576/1518] pinctrl: mediatek: free EINT resources on unbind Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0577/1518] tools/build: Allow versioning of all LLVM tools defined in Makefile.include Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0578/1518] arm64: RSI: fix field-spanning write warning in attestation token init Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0579/1518] power: supply: sbs-battery: Use a per-device serial number buffer Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0580/1518] scsi: ufs: debugfs: Reserve space for a string terminator Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0581/1518] crypto: keembay - Initialize completion before requesting IRQ Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0582/1518] crypto: keembay - publish OF module alias for OCS AES/SM4 Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0583/1518] RDMA/mlx5: Fix integer overflow of user QP buffer size Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0584/1518] thermal/drivers/airoha: Fix copy paste error on clamp_t low temp Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0585/1518] thermal/drivers/airoha: Fix copy paste error for sen internal Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0586/1518] thermal/drivers/qcom-spmi-adc-tm5: Drop IIO_VAL_INT check in adc_tm5_get_temp Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0587/1518] powercap: intel_rapl_tpmi: Handle PMU registration failure during probe Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0588/1518] isofs: release zisofs block pointer buffer head Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0589/1518] clk: mediatek: mt6735: Unregister PLLs on probe failure Greg Kroah-Hartman
2026-09-12 6:45 ` [PATCH 6.18 0590/1518] spi: oc-tiny: switch to managed controller allocation Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0591/1518] w1: ds2482: Fix signedness bug in ds2482_w1_triplet() Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0592/1518] cpufreq/amd-pstate: Add comment explaining nominal_perf usage for performance policy Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0593/1518] cpufreq/amd-pstate: Set min_limit_freq based on bios_min_perf Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0594/1518] remoteproc: core: Drop redundant initialization of ret in rproc_shutdown() Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0595/1518] remoteproc: Allow shutdown of crashed processors Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0596/1518] remoteproc: core: Attach rproc asynchronously in rproc_add() path via schedule_work() Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0597/1518] remoteproc: Prevent crash handling to race with rproc_del() Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0598/1518] firmware: qcom_scm: Introduce PAS context allocator helper function Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0599/1518] staging: rtl8723bs: use kfree_sensitive() for key material Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0600/1518] fs/ntfs3: reject restart table growth beyond U16_MAX entries Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0601/1518] iommu/tegra241-cmdqv: Publish an LVCMDQ only after it is fully initialized Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0602/1518] iommu/tegra241-cmdqv: Synchronize the error ISR against VINTF (de)init Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0603/1518] iommu/tegra241-cmdqv: Dont run the error ISR before probe sets up vintfs Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0604/1518] iommu/tegra241-cmdqv: Free the error IRQ before tearing down VINTFs Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0605/1518] iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0606/1518] iommu/tegra241-cmdqv: Fix VINTF0 leak on the init-failure path Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0607/1518] RDMA/rxe: Fix UAF in ODP init error-handling path Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0608/1518] RDMA/efa: Fix PBL chunk length computation Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0609/1518] wifi: mac80211: fix per-STA profile length in cross-link CSA parsing Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0610/1518] arm64: dts: allwinner: sun50i-a64-pinephone: Fix mpu6050 mount matrix Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0611/1518] clk: tegra: tegra124-emc: put EMC node on register failure Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0612/1518] clk: mediatek: Refactor pll registration to pass device Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0613/1518] clk: mediatek: Pass device to clk_hw_register for PLLs Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0614/1518] clk: mediatek: Refactor pllfh registration to pass device Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0615/1518] clk: mediatek: pllfh: Fix IO remapping leak in register_pllfhs error path Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0616/1518] clk: palmas: Manage external-control prepare with devm Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0617/1518] clk/x86: pmc_atom: add kasprintf return value check Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0618/1518] clk: mediatek: mt8135: Fix inverted gate control for devapc_ck Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0619/1518] clk: rockchip: Fix the fractional part denominator on RK3588/RK3576 PLLs Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0620/1518] nilfs2: fix infinite loop in nilfs_clean_segments() Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0621/1518] nilfs2: prevent out-of-bounds read in super root block parsing Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0622/1518] nilfs2: fix BUG in nilfs_copy_dirty_pages() on dirty state mismatch Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0623/1518] scsi: smartpqi: Fix AIO retry marker cleared by SCSI core between dispatches Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0624/1518] RDMA/mlx5: Fix stack out-of-bounds read in cc_params debugfs Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0625/1518] RDMA/mlx5: Send cong param changes to the resolved port mdev Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0626/1518] RDMA/cxgb4: free STAG index when TPT entry write fails Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0627/1518] media: staging/ipu7: fix async notifier leak on init error Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0628/1518] IB/isert: reject PDUs declaring more data than was received Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0629/1518] IB/isert: reject login " Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0630/1518] nvme-fc: unmap cmd_iu DMA on rsp_iu mapping failure in init_request Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0631/1518] spi: davinci: switch to managed controller allocation Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0632/1518] wifi: ath11k: fix overreads in ath11k_wmi_process_csa_switch_count_event() Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0633/1518] wifi: ath12k: validate TLV length in process_tpc_stats() Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0634/1518] PCI: starfive: Fix Runtime PM handling and teardown ordering Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0635/1518] PCI: starfive: Fix unchecked pm_runtime_get_sync() in probe Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0636/1518] drm/msm: remove objects from evit list after pinning them Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0637/1518] media: qcom: iris: Fix bitmask test in iris_allow_cmd() Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0638/1518] media: qcom: iris: handle runtime PM resume failure in core deinit Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0639/1518] s390/ptrace: Rename psw_t32 to psw32_t Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0640/1518] s390/syscalls: Add pt_regs parameter to SYSCALL_DEFINE0() syscall wrapper Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0641/1518] s390: Remove compat support Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0642/1518] s390: Add stackprotector support Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0643/1518] s390/vdso: Rename vdso64 to vdso Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0644/1518] s390/vdso: Pass --eh-frame-hdr to the linker Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0645/1518] platform/chrome: cros_ec_debugfs: Clean up console log on probe failure Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0646/1518] platform/chrome: cros_ec_debugfs: Unregister panic notifier Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0647/1518] wifi: rtlwifi: pci: fix error path in rtl_pci_probe() Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0648/1518] bus: mhi: host: Flush the posted write after writing to MHI_SOC_RESET_REQ_OFFSET Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0649/1518] bus: mhi: host: Fix controller cleanup on EDL sysfs failure Greg Kroah-Hartman
2026-09-12 6:46 ` [PATCH 6.18 0650/1518] md/raid5: protect bitmap batch counters aka seq_flush/seq_write consistency Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0651/1518] md/raid5-ppl: fix use-after-free in ppl_do_flush() Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0652/1518] md/raid5: protect lockless recovery_offset accesses during reshape Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0653/1518] fanotify: stop permission watchdog when timeout is zero Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0654/1518] tools/nolibc/powerpc: mark ctr and xer as clobbered by system call Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0655/1518] md: recheck spare changes before starting sync Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0656/1518] selftests/zram: fix kernel_gte() for POSIX sh Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0657/1518] Revert "serial: 8250: Clear CON_PRINTBUFFER on port re-registration" Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0658/1518] wifi: ath12k: fix stride mismatch in mac_phy_caps_parse() Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0659/1518] wifi: ath11k: " Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0660/1518] md/raid10: consistently fail atomic writes that require splitting Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0661/1518] rcu: Mark accesses to ->rcu_urgent_qs and ->rcu_need_heavy_qs Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0662/1518] arm64: dts: qcom: msm8998: Dont pull-up I2C pins by default in sleep Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0663/1518] arm64: dts: qcom: msm8976-longcheer-l9360: Fix accidental node override Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0664/1518] arm64: dts: qcom: sdm632-motorola-ocean: Fix LED default trigger property Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0665/1518] arm64: dts: qcom: qcs404: Fix DTBS Check errors in usb controller nodes Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0666/1518] clk: qcom: gcc-qcm2290: dont park QUP RCGs upon registration Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0667/1518] arm64: dts: qcom: sc8280xp-crd: Fix the pin index for misc_3p3_reg_en Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0668/1518] firmware: qcom_scm: Add API to get waitqueue IRQ info Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0669/1518] firmware: qcom_scm: Support multiple waitq contexts Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0670/1518] firmware: qcom: scm: add trace events for the SMC call interface Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0671/1518] firmware: qcom: scm: instrument SMC call path with tracepoints Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0672/1518] firmware: qcom: scm: Fix NULL dereference in IRQ handler before __scm is published Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0673/1518] firmware: qcom: scm: Fix reserved memory cleanup on probe failure Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0674/1518] firmware: qcom: scm: Fix tzmem state on probe retry Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0675/1518] blk-crypto: submit the encrypted bio in blk_crypto_fallback_bio_prep Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0676/1518] blk-crypto: optimize bio splitting in blk_crypto_fallback_encrypt_bio Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0677/1518] blk-crypto: use on-stack skcipher requests for fallback en/decryption Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0678/1518] block: dont set BIO_QUIET for BLK_STS_AGAIN Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0679/1518] block: add a bio_endio_status helper Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0680/1518] block: fix dio leak on metadata mapping error Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0681/1518] arm64: dts: qcom: sm8250-xiaomi-elish: correct the board ID Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0682/1518] arm64: dts: qcom: kodiak: Fix the PCIe iommu-map entries Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0683/1518] arm64: dts: qcom: sar2130p: " Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0684/1518] arm64: dts: qcom: sc8180x: " Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0685/1518] arm64: dts: qcom: sdm845: " Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0686/1518] arm64: dts: qcom: sm8150: " Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0687/1518] arm64: dts: qcom: sm8250: " Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0688/1518] arm64: dts: qcom: sm8350: " Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0689/1518] arm64: dts: qcom: sm8450: " Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0690/1518] arm64: dts: qcom: sm8550: " Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0691/1518] arm64: dts: qcom: sm8650: " Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0692/1518] arm64: dts: qcom: sm8750: " Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0693/1518] arm64: dts: qcom: talos: " Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0694/1518] arm64: dts: qcom: lemans: move USB PHYs to a proper place Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0695/1518] arm64: dts: qcom: lemans: add refgen regulator and use it for DSI Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0696/1518] arm64: dts: qcom: lemans: add QCrypto node Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0697/1518] arm64: dts: qcom: sa8775p: Add reg and clocks for QoS configuration Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0698/1518] arm64: dts: qcom: lemans: Move PCIe devices into soc node Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0699/1518] arm64: dts: qcom: lemans: Fix the PCIe iommu-map entries Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0700/1518] arm64: dts: qcom: qcs6490-rb3gen2: " Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0701/1518] power: supply: isp1704_charger: cancel work on remove Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0702/1518] power: supply: sc2731_charger: " Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0703/1518] bpf: Fix potential UAF in bpf_netns_link_update_prog Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0704/1518] bpf: Fix potential UAF when reading bpf link info Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0705/1518] lib/test_hmm: fail dmirror_fault() when the mirrored mm is gone Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0706/1518] clk: qcom: gpucc-qcm2290: Park RCGs clk source at XO during disable Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0707/1518] clk: qcom: Return expected ENOMEM error on dynamic allocation failure Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0708/1518] md/bitmap: resume array on backlog_store() error path Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0709/1518] md: remove unused mddev argument from export_rdev Greg Kroah-Hartman
2026-09-12 6:47 ` [PATCH 6.18 0710/1518] md: skip redundant raid_disks update when value is unchanged Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0711/1518] md: scope memalloc_noio to allocation critical sections Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0712/1518] iommu/dma: Check atomic pool allocation result directly Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0713/1518] swiotlb: Preserve allocation virtual address for dynamic pools Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0714/1518] i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0715/1518] i3c: master: adi: add OF module alias for autoloading Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0716/1518] fs: annotate inode timestamp accessors Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0717/1518] md/raid1: create serial pool adding rdev to array with serialize_policy=1 Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0718/1518] locking/lockdep: Fix NULL pointer dereference in __lock_set_class() Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0719/1518] powerpc: implement get_direction() in cpm2 Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0720/1518] powerpc/44x: Set GPIO chip parent Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0721/1518] powerpc/crash: Fix possible memory leak in update_crash_elfcorehdr() Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0722/1518] misc: vmc_vmci: Fix potential memory leak in vmci_event_subscribe() Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0723/1518] misc: sgi-gru: remove interrupt-context page-table walks Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0724/1518] fanotify: report full event length for FIONREAD Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0725/1518] wifi: mt76: connac: add MT7991A (0x7991) to is_mt7996() Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0726/1518] wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0727/1518] wifi: mt76: mt7921: validate CLC firmware records Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0728/1518] wifi: mt76: mt7915: fix net_fill_forward_path for non-DBDC mt7986 Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0729/1518] wifi: mt76: Move Q_READ/Q_WRITE definitions in dma.h Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0730/1518] wifi: mt76: Introduce the NPU generic layer Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0731/1518] wifi: mt76: always enable RRO queues for non-MT7992 chipset Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0732/1518] wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0733/1518] wifi: mt76: mt7925: update clc before setting sar power table Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0734/1518] wifi: mt76: mt7925: fix msg len mismatch between driver and firmware Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0735/1518] wifi: mt76: mt792x: Fix memory leak in SDIO TX path Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0736/1518] wifi: mt76: mt7996: fix EAPOL source BSS for non-MLD stations Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0737/1518] wifi: mt76: mt7996: fix capability of EHT-MCS 15 in MRU Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0738/1518] wifi: mt76: fix RX data queuing of RRO 3.0 Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0739/1518] wifi: mt76: mt7996: support fixed rate for link station Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0740/1518] wifi: mt76: mt7996: set specific BSSINFO and STAREC commands after channel switch Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0741/1518] wifi: mt76: mt7996: fix out-of-bounds array access during hardware restart Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0742/1518] wifi: mt76: mt7996: fix MLD ID in MAC TXD and HIF TXP Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0743/1518] wifi: mt76: fix non-AQL packet accounting for MLO stations Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0744/1518] wifi: mt76: assign link_id when sending probe request during scan Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0745/1518] wifi: mt76: mt7996: validate RX band_idx before dereferencing phys[] Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0746/1518] wifi: mt76: mt7996: set MT76_MCU_RESET before waking MCU waiters on full reset Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0747/1518] wifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0748/1518] wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0749/1518] wifi: mt76: mt7996: dont report a zero TX bitrate Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0750/1518] wifi: mt76: mt7915: write RX header translation bit to the correct register Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0751/1518] wifi: mt76: fix stranded frames in mt76_txq_schedule_pending Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0752/1518] wifi: mt76: fix uninitialised RXDMAD_C descriptor info Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0753/1518] wifi: mt76: fix RXDMAD_C buffer recycling race Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0754/1518] wifi: mt76: mt7915: poll the correct SLP CTRL register for the second adie Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0755/1518] wifi: mt76: check txfree done event on the WED hw path Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0756/1518] wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0757/1518] wifi: mt76: mt7915: unwind state on add_interface failure Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0758/1518] wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0759/1518] wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0760/1518] wifi: mt76: mt7996: dont leak MLD group index on remap alloc failure Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0761/1518] wifi: mt76: mt7915: use little-endian for bss_info_ra wire fields Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0762/1518] wifi: mt76: mt7996: add missing rdd_idx check when enabling background radar Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0763/1518] wifi: mt76: only consume the WO drop bit on WED v2 devices Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0764/1518] ACPI: processor: idle: Optimize ACPI idle driver registration Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0765/1518] ACPI: processor: Unregister cpufreq notifier on init failure Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0766/1518] drm/msm: dont tear down KMS twice when KMS init fails Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0767/1518] drm/msm/dp: reject YUV420-only modes without VSC SDP support Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0768/1518] drm/msm/dp: do not reject wide-bus modes while a YUV420 mode is active Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0769/1518] perf: arm_spe: Make wakeup range check overflow safe Greg Kroah-Hartman
2026-09-12 6:48 ` [PATCH 6.18 0770/1518] drm/msm/dpu: Drop sneaky dev_pm_opp_set_rate(0) Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0771/1518] drm/msm/dp: Drop dev_pm_opp_set_rate(0) Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0772/1518] drm/msm/dsi: " Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0773/1518] wifi: ath11k: fix leak in ath11k_service_ready_ext_event() Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0774/1518] soundwire: Add a helper function to wait for device initialisation Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0775/1518] ASoC: tas2783: Use new SoundWire enumeration helper Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0776/1518] ASoC: codecs: tas2783-sdw: Propagate regcache_sync() errors Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0777/1518] ASoC: tas2783-sdw: drop stale regcache on uninitialized re-attach Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0778/1518] regulator: core: use system_freezable_wq for init complete work Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0779/1518] perf machine: Fix fd leak on bounds check in maps__set_modules_path_dir() Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0780/1518] perf machine: Fix NULL parent dereference in fork event processing Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0781/1518] perf machine: Guard against NULL strlist in machines__findnew() Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0782/1518] perf machine: Check snprintf truncation " Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0783/1518] perf machine: Dont abort guest map creation on first inaccessible dir Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0784/1518] perf machine: Reset errno before strtol in guest kernel map creation Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0785/1518] perf machine: Free scandir entries " Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0786/1518] perf machine: Check snprintf truncation for guest kallsyms path Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0787/1518] bpf, x86: Fix trampoline stack size for 128-bit arguments Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0788/1518] wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0789/1518] wifi: mt76: mt7996: skip key upload when adding an offchannel link Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0790/1518] wifi: mt76: mt7996: wake MCU waiters before aborting scan in L1 SER Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0791/1518] wifi: mt76: mt7996: free vif links after clearing wcid entries on full reset Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0792/1518] wifi: mt76: mt7996: fix MIB TX aggregation counter registers for mt7990 Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0793/1518] wifi: mt76: mt7915: fix double hif2 init on the non-WED path Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0794/1518] wifi: mt76: mt7915: fix ext PHY use-after-free on register error path Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0795/1518] wifi: mt76: mt7915: release hif2 reference on probe IRQ failure Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0796/1518] wifi: mt76: mt7996: fix reg addr remap when addr is 0 Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0797/1518] wifi: mt76: mt7996: do not attach hif2 WED when the main WED attach failed Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0798/1518] wifi: mt76: mt7915: fix chainmask handling for non-dbdc phys on band 1 Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0799/1518] wifi: mt76: mt7915: report RX chain signal for all RX paths Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0800/1518] wifi: mt76: fix queue assignment for disassoc packets Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0801/1518] wifi: mt76: mt7925: advertise EHT 320MHz capabilities for 6GHz band Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0802/1518] wifi: mt76: mt7925: Fix EHT Beamformee SS subfields to meet 802.11be minimum Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0803/1518] wifi: mt76: reject out-of-range link ids in mt76_vif_link() Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0804/1518] wifi: mt76: mt7996: fix out-of-bounds link array access in mt7996_tx() Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0805/1518] wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0806/1518] wifi: mt76: mt7996: remove beacon_int_min_gcd from ADHOC interface combinations Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0807/1518] arm64: smp: Fix IPI teardown for GICv5 flow Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0808/1518] arm64/fpsimd: ptrace: Fix inactive SVE and SSVE regsets Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0809/1518] kselftest/arm64: fp-ptrace: Fix checks for " Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0810/1518] kselftest/arm64: Dont write to P0 in irritator on SME only systems Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0811/1518] iommu/arm-smmu-v3: Convert to use atomic poll timeout Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0812/1518] perf/cxlpmu: Fix 64-bit write to 32-bit HDM filter register Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0813/1518] wifi: mac80211: send TWT teardown to peer after setup TX failure Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0814/1518] wifi: zd1211rw: reject secondary interfaces to prevent conflicts Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0815/1518] wifi: mac80211: skip unused probe response countdown offsets Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0816/1518] wifi: mac80211: disconnect on CSA to channel 0 Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0817/1518] wifi: cfg80211: include S1G_NO_PRIMARY flag when sending channel Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0818/1518] wifi: nl80211: Add support for EPP peer indication Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0819/1518] wifi: ieee80211: add some initial UHR definitions Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0820/1518] wifi: cfg80211: add initial UHR support Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0821/1518] wifi: cfg80211: add support to handle incumbent signal detected event from mac80211/driver Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0822/1518] wifi: nl80211: refactor nl80211_parse_chandef Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0823/1518] wifi: nl80211: split out UHR operation information Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0824/1518] wifi: cfg80211: Add an API to configure local NAN schedule Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0825/1518] wifi: cfg80211: stop PMSR before P2P and NAN teardown Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0826/1518] firmware: google: Add bounds checks in coreboot_table_populate() Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0827/1518] firmware: coreboot: Validate table bounds Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0828/1518] pinctrl: eswin: Fix Handling of PIN_CONFIG_PERSIST_STATE Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0829/1518] pinctrl: spacemit: validate pins in pinconf callbacks Greg Kroah-Hartman
2026-09-12 6:49 ` [PATCH 6.18 0830/1518] powerpc/smp: add NULL guard for cause_ipi in smp_muxed_ipi_message_pass Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0831/1518] powerpc/irq: Fix missing r2 clobber in PCREL inline assembly Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0832/1518] soc: fsl: qe: properly scan GPIO nodes at startup Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0833/1518] soc: fsl: qe: implement get_direction() Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0834/1518] MIPS: ptrace: Fix syscall skipping via PTRACE_SYSCALL Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0835/1518] serial: amba-pl011: unprepare console clock on unregister Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0836/1518] serial: amba-pl011: keep console clock enabled for atomic writes Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0837/1518] tty: clear cdev pointer after cdev_add() failure Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0838/1518] dm-integrity: replace forgeable discard filler with a keyed sector marker Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0839/1518] misc: pci_endpoint_test: Check SUCCESS bit for doorbell status Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0840/1518] HID: i2c-hid: Refactor _DSM helper and add i2c-hid-acpi-prp0001 driver Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0841/1518] HID: synchronize input before cleaning up a failed probe Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0842/1518] HID: i2c-hid: Fix "(null)" output when reading report descriptor fails Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0843/1518] HID: steam: Refactor and clean up report parsing Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0844/1518] HID: steam: Rename some constants that got renamed upstream Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0845/1518] HID: steam: Add support for sensor events on the Steam Controller (2015) Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0846/1518] HID: steam: Improve logging and other cleanup Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0847/1518] HID: steam: Reject short reads Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0848/1518] HID: i2c-hid: goodix: Disable VDD on VDDIO enable failure Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0849/1518] HID: lg4ff: validate report length before fixed offsets Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0850/1518] perf thread-stack: Fix heap buffer overflow on branch stack wrap copy Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0851/1518] perf auxtrace: Fix queue grow overflow and old array leak Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0852/1518] perf intel-pt: Fix off-by-one in auxtrace_info minimum size check Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0853/1518] perf intel-bts: " Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0854/1518] perf arm-spe: Reject zero nr_cpu in metadata to prevent division by zero Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0855/1518] iio: light: tsl2772: fix ALS calibscale readback Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0856/1518] iio: light: isl29028: return zero in write_raw() on success Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0857/1518] iio: light: tsl2583: " Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0858/1518] net: stmmac: Skip PHY attach if custom PCS is in use Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0859/1518] phonet: pep: do not write beyond optlen in getsockopt Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0860/1518] blk-cgroup: fix race between policy activation and blkg destruction Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0861/1518] blk-cgroup: skip dying blkg in blkcg_activate_policy() Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0862/1518] block/blk-stat: drain per-cpu callback stats over possible CPUs Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0863/1518] block/blk-iocost: collect per-cpu latency " Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0864/1518] block/kyber-iosched: flush per-cpu latency buckets " Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0865/1518] ublk: check import_ubuf() return value Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0866/1518] ublk: check for ublk_unmap_io() returning 0 Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0867/1518] ocfs2/cluster: keep heartbeat local node stable Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0868/1518] lib/string: fix memchr_inv() for large ranges Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0869/1518] pps: dont try to wait for negative timeouts in PPS_FETCH Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0870/1518] pps: pps-gpio: split IRQ handler into hardirq timestamper + threaded handler Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0871/1518] pps-gpio: remove dead capture_clear code Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0872/1518] rapidio: clear mport->net when rio_add_net() fails Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0873/1518] fat: release buffer head after rebuilding parent Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0874/1518] riscv: dts: sophgo: cv180x: Allow the DMA multiplexer to set channel number for DMA controller Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0875/1518] drm/omap: dsi: Do not copy isr table Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0876/1518] arm64: dts: qcom: agatti: Add missing CX power domain to DISPCC Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0877/1518] remoteproc: Move resource table data structure to its own header Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0878/1518] remoteproc: use rsc_table_for_each_entry() in rproc_handle_resources() Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0879/1518] remoteproc: fix OOB read via signed offset in rsc_table_for_each_entry() Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0880/1518] bpf, cgroup: Fix invalid storage access after __cgroup_bpf_attach failed Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0881/1518] selftests/mm: ksm_tests: use kselftest framework Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0882/1518] selftests/mm: fix ksm NUMA merge test for systems with memoryless NUMA nodes Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0883/1518] selftests/mm: fix ternary operator precedence in ksm_tests Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0884/1518] arm64: dts: qcom: sc8280xp-blackrock: Fix swapped USB QMP PHY vdda-phy/vdda-pll supplies Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0885/1518] arm64: dts: qcom: qcs8550-aim300: " Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0886/1518] arm64: dts: qcom: sm7225-fairphone-fp4: " Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0887/1518] arm64: dts: qcom: sar2130p: " Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0888/1518] bpf: Check load-acquire src ptr type before the load Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0889/1518] intel_idle: Initialize sysfs after cpuidle driver initialization Greg Kroah-Hartman
2026-09-12 6:50 ` [PATCH 6.18 0890/1518] intel_idle: Add cmdline option to adjust C-states table Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0891/1518] intel_idle: Avoid using deep idle states during initialization Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0892/1518] scripts/tags.sh: Prevent binary files appearing in cscope.files Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0893/1518] modpost: prevent leak when early return no suffix .o in read_symbols() Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0894/1518] kbuild: fix modules.builtin(.modinfo) targets in the top-level Makefile Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0895/1518] RDMA/erdma: Hold CQ references when processing EQ events Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0896/1518] RDMA/erdma: Hold QP references for AE and CM processing Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0897/1518] RDMA/srp: fix heap information leak on a truncated SRP_CRED_REQ Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0898/1518] ARM: 9481/2: breakpoint: CFI breakpoints only on demand Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0899/1518] ARM: 9485/1: mm: acquire mmap write lock around show_pte() for user faults Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0900/1518] perf libbfd: Validate BPF prog info arrays before pointer cast Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0901/1518] perf bpf: Add PROG_TAGS to required arrays in __bpf_event__print_bpf_prog_info() Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0902/1518] perf libbfd: Fix memory leaks and NULL fclose in BPF disassembly Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0903/1518] ocfs2: synchronize heartbeat callbacks with o2net teardown Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0904/1518] clk: rockchip: rk3576: fix source muxes for SPI0..SPI4 Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0905/1518] perf c2c: Add annotation support to perf c2c report Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0906/1518] perf report: Fix histogram entry collapsing for -F option Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0907/1518] perf report: Update sort key state from " Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0908/1518] perf c2c: Use perf_env e_machine rather than arch Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0909/1518] perf c2c: Fix error masking, OOM, and unchecked caller errors in hpp_list__parse() Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0910/1518] perf c2c: Clean up registered formats on c2c_hists__init() and c2c_hists__reinit() failure Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0911/1518] drm/sun4i: vi scaler: Fix coefficient selection Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0912/1518] drm/sun4i: tcon: Set output mux for DSI and LVDS Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0913/1518] drm/sun4i: tcon: Drop TCON TOP device reference Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0914/1518] drm/sun4i: hdmi: Dont leak sync polarity bits into packet control Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0915/1518] drm/sun4i: crtc: Propagate layer initialization error Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0916/1518] drm/sun4i: tcon: Drop remote endpoint reference Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0917/1518] drm/sun4i: dw-hdmi: Drop TCON TOP port reference Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0918/1518] drm/sun4i: hdmi-phy: Fix H6 8-bit MPLL config at 594 MHz Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0919/1518] rust: cpufreq: Add CPUFREQ_TABLE_END as last table entry in TableBuilder::to_table Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0920/1518] rust: cpufreq: Fix temporary write in Registration::bios_limit_callback Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0921/1518] cpufreq: imx6q: fix devres accumulation across driver rebind Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0922/1518] cpufreq: imx6q: fix out-of-bounds write when probed more than once Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0923/1518] IB/isert: delay the final Login Response until the session is registered Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0924/1518] IB/isert: post the full-feature receive buffers after session registration Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0925/1518] RDMA/siw: Fix use-after-free in siw_accept() Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0926/1518] module: replace use of system_wq with system_dfl_wq Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0927/1518] module: use strscpy() to copy module names in stats and dup tracking Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0928/1518] module/dups: Inform duplicate requests about the result directly Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0929/1518] module/dups: Fix use-after-free in kmod_dup_req lifetime handling Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0930/1518] RDMA/erdma: restrict the driver to little-endian systems Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0931/1518] wifi: mac80211: skip default WMM setup for AP_VLAN links Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0932/1518] arm64: hibernate: mask DAIF before restoring hibernated kernel Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0933/1518] arm64: hibernate: Restore DAIF state on error Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0934/1518] mfd: rave-sp: validate received frame payload lengths Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0935/1518] mfd: iqs62x: Reject zero-length firmware records Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0936/1518] mfd: macsmc: Fix key count endianness annotation Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0937/1518] gpiolib: move legacy interface into linux/gpio/legacy.h Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0938/1518] leds: gpio: Make legacy gpiolib interface optional Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0939/1518] leds: gpio: Clear error pointers for skipped LEDs Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0940/1518] drm/amdgpu/gfx6: Fixup emit_cntxcntl() Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0941/1518] ext4: fix spurious message about orphan cleanup on RO fs Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0942/1518] arm64: dts: ti: k3-am64: Fix MDIO clock reference for ICSSG0 node Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0943/1518] phy: renesas: rcar-gen3-usb2: Factor out VBUS control logic Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0944/1518] phy: renesas: rcar-gen3-usb2: Add regulator for OTG VBUS control Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0945/1518] phy: renesas: phy-rcar-gen3-usb2: Fix devm action registration for disabled VBUS regulator Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0946/1518] phy: sunplus: fix error handling in sp_uphy_init() Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0947/1518] phy: rockchip: phy-rockchip-inno-csidphy: fix rk1808 hsfreq table Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0948/1518] perf trace-event: Fix buffer overflow in read_string() Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0949/1518] drm/amdgpu/gfx6: Fixup emitting SWITCH_BUFFER packets Greg Kroah-Hartman
2026-09-12 6:51 ` [PATCH 6.18 0950/1518] drm/amdgpu/gfx6: Use PFP on the compute queues too Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0951/1518] scsi: qla2xxx: Remove redundant VPD flash read in sysfs read path Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0952/1518] firmware_loader: do not queue completed sysfs fallback requests Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0953/1518] pinctrl: rockchip: Reset the pin count when recalculating SoC data Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0954/1518] hugetlbfs: release subpool on fill_super failure Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0955/1518] soc: fsl: qe: check platform_driver_register() in qe_ic_of_init() Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0956/1518] phy: qcom-sgmii-eth: relax order of .power_on() vs .set_mode*() Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0957/1518] phy: qcom: sgmii-eth: vote for both voltage rails with correct current loads Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0958/1518] phy: qcom: qmp-usb-legacy: Fix possible NULL-deref on early runtime suspend Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0959/1518] phy: qcom: snps-femto-v2: " Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0960/1518] phy: qcom: qmp-usb: " Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0961/1518] phy: qcom: qmp-pcie: Add pcs_lane1 offset to V5 offsets Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0962/1518] md/raid5: round bitmap stripes with sector division Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0963/1518] md: wait for behind writes before destroying bitmap Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0964/1518] md: avoid stale clone I/O accounting timestamps Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0965/1518] md/md-llbitmap: prevent create failure bitmap UAF Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0966/1518] md/md-llbitmap: stop daemon timer rearm on destroy Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0967/1518] md/raid1: dont set array_frozen in raid1_takeover() Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0968/1518] coresight: etm4x: fix wrong check of etm4x_sspcicrn_present() Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0969/1518] coresight: Change syncfreq to be a u8 Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0970/1518] coresight: etm4x: fix underflow for usage of (nrseqstate - 1) Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0971/1518] coresight: etm4x: fix leaked trace id Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0972/1518] coresight: Refactor etm4_config_timestamp_event() Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0973/1518] perf: arm_pmuv3: Zero initialize hw_id branch stack field Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0974/1518] bpf: Reject load-acquire from pointers requiring fault protection Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0975/1518] bpf, riscv: Add and use bpf_atomic_is_load_acq() helper Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0976/1518] bpf, x86: Fix exception table metadata for arena load-acquire Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0977/1518] bpf, arm64: " Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0978/1518] regulator: qcom-rpmh: Fix PMIC5 BOB bypass mode handling Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0979/1518] ACPI: video: Release PCI device reference after lookup Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0980/1518] perf/x86/intel/pt: Factor out pt_config_enable() Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0981/1518] perf/x86/intel/pt: Use bitwise access for PERF_HES_STOPPED Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0982/1518] perf/x86/intel/pt: Fix stop/start with no update Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0983/1518] sched/fair: Also gate overloaded status update for SD_ASYM_CPUCAPACITY Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0984/1518] sched/fair: Check CPU capacity before comparing group types during load balance Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0985/1518] Bluetooth: btqca: Fix qca_set_bdaddr() waiting for wrong HCI event Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0986/1518] Bluetooth: btusb: Fix BD_ADDR byte order in btusb_set_bdaddr_wcn6855() Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0987/1518] Bluetooth: btusb: refactor endpoint lookup Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0988/1518] Bluetooth: btusb: Record matched usb_device_id into btusb_data Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0989/1518] Bluetooth: btusb: QCA: Fix populating devcoredump fields on unenabled devices Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0990/1518] perf trace-event: Fix integer truncation in do_read() and skip() Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0991/1518] scsi: core: Pass a struct scsi_driver to scsi_{,un}register_driver() Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0992/1518] scsi: core: sysfs: Make use of bus callbacks Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0993/1518] scsi: sd: Convert to SCSI bus methods Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0994/1518] scsi: sd: Move the sd_remove() function definition Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0995/1518] scsi: sd: Move the sd_config_discard() " Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0996/1518] scsi: sd: Enable sector size > PAGE_SIZE in SCSI sd driver Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0997/1518] scsi: sd: Fix special_vec mempool leak when scsi_alloc_sgtables() fails Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0998/1518] scsi: sd: Fix sd_done() sense handling condition Greg Kroah-Hartman
2026-09-12 6:52 ` [PATCH 6.18 0999/1518] btrfs: defrag: fix deadlock between defrag and delalloc space reservation Greg Kroah-Hartman
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).